chore(release): v0.32.0

Version bump via changesets.
This commit is contained in:
gsxdsm
2026-05-19 22:09:26 -07:00
parent a164e84b46
commit 959f7cd4eb
288 changed files with 1539 additions and 1347 deletions

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Add reliability stats reset support with a new `/api/health/reliability/reset` endpoint and enhance the Reliability dashboard view with drill-down details, empty-day filtering, and reset baseline visibility.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Chat rooms now show the same Latest jump-to-bottom button as direct chats.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Fix Mission Manager mission detail refresh behavior so expanded milestones/slices are preserved and selected milestone acceptance criteria remain visible across live updates.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Planning mode, mission interview, and milestone/slice interview AI sessions now have read-only access to `fn_task_list` and `fn_task_get` so they can reference existing backlog tasks while interviewing the user.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Add internal `SandboxBackend` abstraction to the engine command-execution path (native passthrough only; no behavior change). Foundation for FN-4637 (bubblewrap), FN-4638 (sandbox-exec), FN-4639 (settings), FN-4640 (audit), FN-4641 (action-gate), FN-4642 (container) follow-ups.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Add an opt-in Linux `bubblewrap` sandbox backend with policy-to-`bwrap` argument translation, backend availability detection, and native fallback support.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Add opt-in macOS `sandbox-exec` backend for the engine `SandboxBackend` abstraction. Default backend remains `native`; enable via `sandbox.backend = "sandbox-exec"`. Honors `failureMode: "fail-hard" | "fallback-native"`. Port 4040 and `.fusion/` are denied unconditionally.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Add `sandbox` run-audit domain with `sandbox:prepare`/`sandbox:run`/`sandbox:failure`/`sandbox:fallback` lifecycle events emitted from the engine's `SandboxBackend` wiring sites, and surface them through the dashboard's run-audit API (filter parser, normalized event domain, timeline `auditByDomain.sandbox` bucket).

View File

@@ -1,9 +0,0 @@
---
"@runfusion/fusion": patch
---
Add `sandbox_provisioning` action-gate category, `sandboxProvisioning` project setting,
`resolveSandboxProvisioningPolicy` in @fusion/core, and a
`requireSandboxProvisioningApproval` engine helper. Lays the approval seam that future
bubblewrap (FN-4637), sandbox-exec (FN-4638), and container (FN-4642) backends use to
gate first-time host bootstrap.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Prototype optional rootless container `SandboxBackend` (Podman-first, Docker-compatible) behind the FN-4636 seam. Off by default; reachable only via explicit `resolveSandboxBackend({ backendId: "podman" | "docker" })`. No settings, audit, or action-gate wiring yet (FN-4639/FN-4640/FN-4641).

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Extend internal `SandboxBackend` abstraction to cover the spawn-based verification runner (`runVerificationCommand` / `execWithProcessGroup`) via a new `runStreaming` method on the backend. Native passthrough only — no behavior change. Foundation for FN-4637/FN-4638 to wrap the verification path the same way they wrap `runConfiguredCommand`.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Auto-finalize in-review tasks when self-healing or merge fast-path logic can prove task content already landed on the base branch, clearing soft blockers (`paused`, stale `failed` status, and residual error) while still preserving hard-blocker guardrails for incomplete steps, awaiting-user-review states, and pre-merge workflow failures.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
GitHub tracking issues are now created for every task-creation path (pi extension tools, CLI commands, agent delegation, and mission/feature triage), not only dashboard HTTP routes.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Gate sandbox backend settings behind `experimentalFeatures.sandbox` until the rollout completes.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Missions UI: surface per-feature acceptance criteria in the milestone Assertions panel even when the milestone itself has acceptance text. Fixes FN-4652 (refinement of FN-4613).

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
GitHub Copilot login (Settings and Onboarding) now shows the device code and auto-copies it to the clipboard before opening the GitHub verification page — users click "Open GitHub" when ready instead of having the new tab steal focus immediately. The device-code panel now spans the full width of the provider card.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Persist `mergeDetails.rebaseBaseSha` whenever a rebase merge base is captured, and update self-healing landed-commit stats lookup to use rebase range shortstat (`base..sha`) when available so stale tip-only merge stats are automatically repaired.

View File

@@ -1,4 +0,0 @@
---
"@runfusion/fusion": patch
---
Routine-runner now threads a `RunAuditor` through `resolveSandboxBackend()` so user-configured routine commands emit `sandbox:prepare`/`sandbox:run`/`sandbox:failure` lifecycle events alongside executor and merger commands, closing the FN-4640 observability gap.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Ensure duplicate/refine API task creation paths also attempt GitHub tracking issue creation as best-effort behavior.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Suppress false `missing-evidence` warnings on verification-only / no-code follow-up tasks by classifying branch-absent no-owned-commit finalizes as benign `no-changes-finalized` and clearing stale `modifiedFiles` snapshots.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Right-align the linked GitHub issue chip on in-review TaskCards, matching the in-progress placement.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Add a new project setting `doneAutoArchiveDays` (default `0`) to control done-task auto-archive retention in days. When set to a value greater than `0`, it takes precedence over `autoArchiveDoneAfterMs` for periodic self-healing auto-archive sweeps.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": minor
---
Add a new project setting, `chatAutoCleanupDays` (default off), to automatically remove idle chat sessions and chat rooms during periodic self-healing maintenance.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": minor
---
Add a new project setting, `mailAutoCleanupDays`, to auto-prune old inbox/outbox messages during self-healing maintenance. The setting defaults to `0` (off) and supports retention windows of 7, 14, 30, 60, or 90 days.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Annotate wake-on-message heartbeat runs whose inbox snapshot is already empty with consumed-message wake reasons, plus wake-delta inbox snapshot context.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Fix settings sync push/receive payload contract: the push endpoint now includes `sourceNodeId` so the inbound `/api/settings/sync-receive` validator no longer rejects round-trips with a 400.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Add a new dashboard `PrCreateModal` component with AI metadata generation, preflight checks, base-branch selection, draft mode, reviewer/assignee/label pickers, commit/file preview, and retryable PR creation errors. Also add dashboard client API wrappers for PR metadata, preflight, and options endpoints.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Sync GitHub PR reviews and review comments into Fusion task comments, expose a PR reviews API for dashboard threading, and auto-move in-review tasks back to todo when GitHub review decision changes to CHANGES_REQUESTED while preserving progress/worktree and saving reviewer feedback context.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Structured surfacing of GitHub CLI / API errors with retry affordances in the dashboard PR UI and `fn pr create` CLI flow.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
GitHub tracking-issue creation no longer blocks `POST /api/planning/create-task` and `POST /api/planning/create-tasks` responses; it now runs in the background.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Wire `HybridExecutor` into serve/dashboard/daemon startup behind `shouldUseHybridExecutor` gating. This adds optional multi-project runtime orchestration (project runtimes + node health monitoring) while preserving default single-project local behavior unless the gate enables it.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Add a triage `fn_task_search` tool that searches across task history (including done and archived tasks) and strengthen duplicate-check guidance to require keyword search before filing new tasks.

View File

@@ -1,8 +0,0 @@
---
"@runfusion/fusion": patch
---
GitHub tracking-issue creation now searches the target repo (open and closed
issues) for likely duplicates before opening a new issue, keyed on the task's
File Scope paths and symptom keywords. Matches link the existing issue to the
Fusion task. Opt out with project setting `githubTrackingDedupEnabled: false`.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Dashboard reload no longer briefly hides the UI behind a full-screen loader when project data is already cached.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Add `oauth-token-expired` notification event so users are notified when a provider OAuth token (Codex, Claude, etc.) expires and needs re-authentication.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Internal: add AES-256-GCM secret cipher primitive in @fusion/core (foundation for upcoming secrets subsystem; no user-visible behavior yet).

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Internal: introduce `SecretAccessPolicy` vocabulary (`auto`/`prompt`/`deny`) and `resolveSecretAccessPolicy()` resolver plus a global `secretsAccessPolicy` default setting. Foundation for the upcoming secrets subsystem; no user-visible behavior yet.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": minor
---
Documented Fusion secrets management across architecture, storage, settings, and agent guidance, including encrypted project/global secret stores and access-policy behavior. Added secrets subsystem reference docs plus planned integration notes for agent secret reads, worktree env materialization, and cross-node sync endpoints.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Dashboard top progress bar now also reflects task list revalidation, not just project loading.

View File

@@ -1,7 +0,0 @@
---
"@runfusion/fusion": patch
---
Dashboard Settings → Project → General → GitHub Tracking now exposes a
toggle for `githubTrackingDedupEnabled`, so users can opt out of the
pre-creation duplicate search without editing `.fusion/config.json`.

View File

@@ -1,7 +0,0 @@
---
"@runfusion/fusion": patch
---
fix(FN-4806): silently recover when worktree/branch reclaimed mid-retry
When the executor's no-`fn_task_done` retry loop detects that a task's worktree or branch was reclaimed by an engine-side housekeeping path (FN-4546 stale-active-branch reclaim, FN-4742 self-healing removals, session-start unusable-worktree), it now requeues the task to `todo` silently with preserved progress. The task is no longer marked `failed`, `taskDoneRetryCount` is no longer burned, and `onError` is no longer surfaced — this is engine self-heal, not an agent failure. The genuine "agent finished without calling fn_task_done after N retries" exhaustion path is unchanged.

View File

@@ -1,20 +0,0 @@
---
"@runfusion/fusion": patch
---
fix(FN-4811): refuse to force-remove worktrees actively bound to live sessions
Adds a hard liveness gate to the executor's conflict-recovery paths so that
`cleanupConflictingWorktree` and `handleBranchConflict` refuse to remove a
worktree that is currently bound to an active executor session — either via
the in-memory `activeWorktrees` map or via a non-done, non-paused
`in-progress` task in the store. When the requesting task has
`executorAllowSiblingBranchRename`, the recovery flow now falls through to
the suffix-rename path instead of force-removing the live owner's worktree.
This is the canonical fix for the FN-4781/FN-4804 cascade:
"assigned worktree path disappeared mid-task", two parallel runs for the
same task alive simultaneously, cross-task contamination, and post-merge
"branch tip misbound but content found on main" rescues firing on every
successful merge. The new `findActiveWorktreeOwner()` helper centralizes
the liveness check across both gating points.

View File

@@ -1,19 +0,0 @@
---
"@runfusion/fusion": patch
---
fix(FN-4811): close concurrent-execute race that produced parallel runs for the same task
`TaskExecutor.execute()` had an async race: after the synchronous `this.executing.has(task.id)` check, the code awaited `shouldDeferForHeartbeat(...)` BEFORE adding to the `executing` Set. Two concurrent `execute()` calls (scheduler dispatch + `task:moved` listener + restart-recovery) could both pass the check, both yield on the await, then both add to the Set and both proceed to create the same worktree.
Production signature (FN-4814, FN-4811):
```
01:30:56 [runA-caoe] Worktree created at /Users/eclipxe/Projects/kb/.worktrees/bright-mesa
01:30:56 [runB-w23q] Worktree created at /Users/eclipxe/Projects/kb/.worktrees/bright-mesa
01:30:58 worktree liveness assertion failed: not_usable_task_worktree
```
This is the canonical source of FN-4781/FN-4804/FN-4814/FN-4811 mid-task worktree disappearance and cross-task contamination — every other guard in the stack (FN-4811 active-session gate, self-healing reclaim defer, etc.) was patching the *symptoms* of the duplicate-run race.
Fix: claim the executing slot synchronously immediately after the `has()` check, release it on the heartbeat-defer early return. Closes the race window entirely.

View File

@@ -1,13 +0,0 @@
---
"@runfusion/fusion": patch
---
fix(FN-4811): unblock `@fusion/engine` typecheck so verification bootstrap can run
Restores `pnpm --filter @fusion/engine build` after a stack of TypeScript regressions blocked every merge. Symptoms: every task hitting pre-merge verification failed with "Verification bootstrap preamble failed — workspace dist artifact rebuild did not complete" because the bootstrap shells `pnpm --filter @fusion/engine build` and that compile was erroring on 17 type issues.
Fixes:
- Remove duplicate `RemovalReason` re-export in `worktree-pool.ts` (`export type` + `export` for the same identifier produced TS2300 "Duplicate identifier").
- Add `worktree:removal-refused-active-session` and `worktree:removal-forced-over-active-session` to the `GitMutationType` union in `run-audit.ts` so the new FN-4811 audit events are accepted.
- Update `self-healing.test.ts` `vi.mock("../worktree-pool.js")` to mirror the production `RemovalReason` const exactly (was missing keys, causing `reason: undefined` to flow into mock calls and confusing error messages).
- Add `reason: RemovalReason.MergerCleanup` to existing `worktree-backend.test.ts` `removeWorktree` calls now that `reason` is a required parameter.

View File

@@ -1,18 +0,0 @@
---
"@runfusion/fusion": patch
---
fix(FN-4811): persist done-task integrity warnings across engine restarts
`SelfHealingManager.reconcileDoneTaskIntegrity()` previously deduped its
"Integrity warning: done-task finalize evidence is unproven" emissions via an
in-memory `Set<string>` per manager instance. Every engine restart created a
fresh manager, so the periodic sweep re-emitted the same warning for the same
task on every cycle — producing significant log noise on done tasks legitimately
lacking on-main evidence (often FN-4811 contamination residue).
Adds an optional `integrityWarning: { warnedAt, reason }` field on
`MergeDetails` and persists it on the first warning. Subsequent sweeps (within
the same process or after restart) check the persisted reason and skip
re-emitting an identical warning. A different classification reason still
re-warns and updates the persisted record.

View File

@@ -1,11 +0,0 @@
---
"@runfusion/fusion": patch
---
fix(FN-4811): use process-wide executingTaskLock to block parallel execute() across instances
After commit 82f80e72f added a per-instance `this.executing.add()` synchronous claim, production STILL produced two `execute()` invocations for the same task ID that both reached "Executor detected stale merge state" and both generated runIds within 1 second of each other (FN-4809: y2nb + 9gde at 02:48:1718 UTC; FN-4814 / FN-4811 cascade). The only viable explanation is that there is more than one `TaskExecutor` instance in the process (engine restart race, multi-project hybrid runtime, etc.).
Adds a module-level singleton `executingTaskLock` in `active-session-registry.ts` shared across all `TaskExecutor` instances. `TaskExecutor.execute()` synchronously claims the lock immediately after the `executorLog.log` entry; if `tryClaim()` returns false (someone else owns the lock), the call bails. Every existing `this.executing.delete()` site also releases the lock. Per-instance `this.executing` is kept for back-compat with the many `this.executing.has()` checks throughout `executor.ts`.
Test setup in `executor-test-helpers.ts` clears the process-wide lock in `resetExecutorMocks()` so it doesn't leak across tests.

View File

@@ -1,9 +0,0 @@
---
"@runfusion/fusion": patch
---
fix(FN-4811): defer self-healing reclaim when worktree has an active session
The `reclaimSelfOwnedBranchConflicts` sweep was force-pausing actively-running tasks. When a task's branch tip was already on `main` (the `tip-already-merged` inspection), the sweep tried `removeWorktree({ reason: SelfHealingBranchConflict })`. The FN-4811 active-session gate correctly refused (the worktree was still bound to a live executor session), but the outer catch escalated the thrown error to `AutoRecoveryDispatcher` with class `branch-conflict-unrecoverable`. The dispatcher's `pause` decision then marked the task `failed + paused + pausedReason="branch-conflict-unrecoverable"` — even though the executor was making real progress (FN-4819 reproduction).
Fix: at the top of the per-task reclaim loop, check `activeSessionRegistry.isPathActive(task.worktree)` and `continue` for any task whose worktree is currently bound to a live executor/merger/step session. The reclaim retries on the next sweep when the session has finished and the worktree is genuinely free.

View File

@@ -1,7 +0,0 @@
---
"@runfusion/fusion": patch
---
fix(FN-4811): scope-leak guard always allows `.changeset/` paths
The `[scope-leak]` warning was firing on many in-progress tasks for off-scope `.changeset/FN-XXXX-*.md` files (the reproducible signature on FN-4789, FN-4801, FN-4818). By convention every task may add its own changeset entry under `.changeset/` per AGENTS.md's "Finalizing Changes" section, so changeset files are now treated as always-allowed by the scope-leak guard regardless of the task's declared file scope. Cross-task changeset leakage is still caught by stronger downstream guards (file-scope invariant at squash, post-merge audit) at a much higher signal-to-noise ratio.

View File

@@ -1,11 +0,0 @@
---
"@runfusion/fusion": patch
---
fix(FN-4811): recover from "validation failed, cannot remove working tree" + collapse broken FN-4806 nested branches
Two follow-ups stacked on the FN-4811 active-worktree liveness gate:
1. **Stale conflict-path recovery (was breaking real tasks).** When `git worktree remove --force` fails with `fatal: validation failed, cannot remove working tree`, the worktree directory is missing on disk and the git admin entry is stale. `cleanupConflictingWorktree` now catches that specific error, runs `git worktree prune`, best-effort deletes the branch, and returns success — so the caller can proceed with worktree creation instead of failing 3× with "automatic cleanup failed" (FN-4813 production failure).
2. **Collapsed broken FN-4806 nested branches.** The previous FN-4806 refactor accidentally nested the genuine "agent finished without calling fn_task_done" failure path inside the silent-recovery branch, so ordinary failures were being silently requeued instead of marked failed. Restored the clean two-branch structure: `else if (retryAbortedDueToReclaim)` silent-recovers, `else` marks failed/onError/burns budget. Also clears `baseCommitSha` on silent recovery (matches the parallel session-start-failure path).

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Add multi-node coordination hardening for task execution: distributed checkout claim mutex (`tryClaimCheckout`) with node/epoch preconditions, configurable `owningNodeHandoffPolicy` behavior for unavailable owners, and a supported `transitionProjectIsolation` path that can restart project runtimes (with rollback when active-task restart is blocked). Reaffirm scheduler failover and live process migration as explicit non-goals in mesh/multi-project docs.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Add central `taskClaims` table (central DB schema v13) and route `AgentStore.checkoutTask` through it when a `CentralClaimStore` is configured, providing the authoritative cross-node task-claim mutex required by FN-4819 §2. Single-node behavior is unchanged when no claim store is wired.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Add a new `task:auto-recover-node-unreachable` run-audit mutation type and emit it across unreachable-owner recovery flows, including mesh lease recovery outcomes and scheduler owning-node handoff decisions.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Add create-time duplicate detection to dashboard task creation. The dashboard now exposes `POST /api/tasks/duplicate-check`, returns `409 duplicate_candidates` for conflicting `POST /api/tasks` requests unless callers acknowledge matches, and supports `bypassDuplicateCheck` for opt-out callers.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
GitHub Copilot now appears as logged-in in the dashboard usage dropdown when authenticated via Fusion's Settings → Authentication OAuth flow, in addition to the existing `gh` CLI detection.

View File

@@ -1,15 +0,0 @@
---
"@runfusion/fusion": patch
---
fix(FN-4847): discard foreign branch and recreate on `branch-conflict-unrecoverable`
Branch conflicts where the existing `fusion/<task-id>` branch has stranded commits NOT attributed to the task (cross-task contamination residue from the FN-4781/FN-4804/FN-4814 worktree-race era) previously paused the task with `pausedReason: "branch-conflict-unrecoverable"` and the error message `Auto-recovery failed: branch conflict unrecoverable — Branch fusion/fn-XXX is already checked out at /.../ (tip ..., N stranded commits since ...)`. The task got stuck forever waiting for human adjudication.
The user has explicitly opted into discard-and-recreate for this case: those stranded commits aren't this task's work, just delete them and move on.
Changes:
- `auto-recovery.ts:actionForMode` — in `deterministic-only` mode, `branch-conflict-unrecoverable` now returns `"retry"` (was `"pause"`), routing the failure to the handler instead of the pause path.
- `auto-recovery-handlers/branch-worktree.ts``live-foreign` inspection no longer emits `irreducible-pause`. Instead: force-delete the foreign branch + worktree (safely respecting the FN-4811 active-session gate to avoid yanking live sessions), then requeue the task. The executor's next pickup creates a fresh `fusion/<task-id>` worktree with no conflict.
- New audit event `branch-worktree:foreign-branch-discarded` records the discard with stranded-commit count and live-ownership status.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Dashboard's Agents, Documents, Todos, and Chat views now hydrate from a local cache on reload, eliminating the brief empty-state flash before data arrives.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Dashboard's Missions, Insights, Research, Evals, and Mailbox views now hydrate from a local cache on reload, eliminating the empty-state flash before data arrives.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Reconcile docs/secrets.md and docs/architecture.md with the FN-4867 secrets sync surfaces that now ship (push/pull/receive/sync-export + fn_secret_get + secrets-env materialization), and add a reliability-interaction backstop for cross-node secrets sync route contracts.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Add intake-side auto-archive safeguards: ghost-bug preflight on triage finalize and same-agent duplicate detection at task creation. Both paths are fail-open on errors/timeouts and emit structured activity/audit events when auto-archive triggers.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Normalize task titles to strip foreign embedded `FN-<id>` tokens during create/update/duplicate/refine flows while preserving duplicate/refine provenance metadata. Also adds schema version 84 migration coverage to clean existing active/archived title-ID drift rows idempotently.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Improve duplicate source traceability by preserving and surfacing canonical duplicate lineage fields (`sourceType`, `sourceParentTaskId`, and `sourceMetadata.duplicateOfTaskIds`) in task provenance flows used by CLI and dashboard task detail surfaces.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Fix: ntfy notifications for `in-review` and merged task events now fire even when notification settings were enabled after the engine started.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Fix `/api/health/reliability` per-day rows silently truncating older days on busy projects. Per-day in-review entered/bounced counts and duration samples are now aggregated at the SQL layer instead of pulling up to 50,000 activity-log rows in memory, so the Reliability view shows accurate data for every day in the rolling window.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": minor
---
Implement `.env` secrets materialization pipeline: honor `secretsEnv` project settings (enabled/filename/overwritePolicy/keyPrefix/requireGitignored), gate writes behind `git check-ignore`, emit `secret:env-write` / `secret:env-write-skipped` / `secret:env-cleanup` / `secret:env-cleanup-skipped` run-audit events, and clean up fingerprint-matching `.env` files on worktree teardown.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": minor
---
Add cross-node secrets sync endpoints (`POST /api/nodes/:id/secrets/push`, `POST /api/nodes/:id/secrets/pull`, `POST /api/secrets/sync-receive`, `GET /api/secrets/sync-export`) with shared-passphrase envelope (scrypt → AES-256-GCM) and Bearer-apiKey auth on inbound routes. Passphrase is stored locally encrypted under the master key (reserved `__sync_passphrase__` row, `access_policy="deny"`) and is never transmitted or echoed.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Add deterministic duplicate guard at task intake: identical-content POSTs within a 60s window are rejected with `409 duplicate_candidates` or auto-archived with a `source.sourceMetadata.deterministicDuplicateOf` lineage marker. Complements the existing FN-4829 similarity warning.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Dashboard reload no longer shows multi-day-old cached boards. The local stale-while-revalidate cache now respects a 10-minute freshness window for list payloads (tasks, projects, agents, documents, etc.); older entries are skipped and the normal fetch path runs, surfacing the existing top progress indicator. Failed background refreshes keep the indicator visible so the user knows the data hasn't been confirmed fresh.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Fix "Copy code" button on the GitHub Copilot device-code panel (Settings and Onboarding) when the dashboard is served from a non-secure origin (e.g. LAN/HTTP `fn serve`). The button now falls back to a `document.execCommand("copy")` path when `navigator.clipboard` is unavailable and surfaces success/failure via a toast instead of silently no-opping. The auto-copy-on-first-show effect uses the same fallback silently.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Harden merge conflict arbitration so Layer 3 AI resolution respects task File Scope by resolving out-of-scope conflicted files to main before AI handling and emitting scope-partition audit events.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Add a merger auto-prerebase policy that can rebase task branches onto local main before the existing Stage 1/2 rebase cascade when divergence from `task.baseCommitSha` crosses a threshold or touches configured shared-infra hot files. This introduces project settings `prerebaseAutoEnabled`, `prerebaseHotFiles`, and `prerebaseDivergenceThreshold`, and emits run-audit events `merge:auto-prerebase:applied`, `merge:auto-prerebase:skipped`, and `merge:auto-prerebase:failed`.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": minor
---
Add `priority` field to `fn_task_update` MCP tool so agents can rebalance task urgency after triage.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Reconcile stale task worktree/branch metadata after orphan recovery so the dashboard Changes view shows the correct diffs.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
`fn pr create` (and the `fn task pr-create` alias) now support `--draft`, `--no-ai`, and repeatable `--reviewer <login>` flags. Adds a top-level `fn pr` subcommand router. When `--no-ai` is not set, the CLI now reuses the dashboard's AI metadata pipeline to generate the PR title/body — parity with the dashboard `PrCreateModal`. `GitHubClient.createPr` accepts `draft` and `reviewers`.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Fix: ntfy 'merged' notifications now fire for every merge-success path (auto-finalize no-op merges, mergeConfirmed fast-path, PR-strategy merges, and self-healing finalize).

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Aligned the no-task heartbeat system prompt and procedures with the ambient tool set injected for no-task runs, and added regression tests to prevent forbidden task-scoped tool references from reappearing.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Extend the FN-4918 deterministic duplicate guard to the remaining task-creation surfaces: CLI `fn task add` (direct-store, with a new `--no-dedup` flag), engine `createAgentTask` (powers `fn_task_create` and triage subtask splits — duplicate detections now report `Linked existing ...`), and mission feature triage (links to the canonical task on duplicate). Dashboard `POST /api/tasks` now consumes the same shared helper so behavior is identical across surfaces. `InlineCreateCard` gains the duplicate-warning modal already shipped on `QuickEntryBox`.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Auto-recover stale pending/running insight runs at dashboard startup and on a periodic sweep so manual runs never hang indefinitely.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Make the FN-4918 deterministic duplicate pre-check fail open: transient store query errors, mutex bookkeeping failures, and leader-lock rejections no longer 500 the `POST /tasks` endpoint. Legitimate 409 `duplicate_candidates` responses are unchanged.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Agent-filed tasks now persist `githubTracking.enabled` when tracking defaults are enabled, so pi/engine-created tasks consistently appear as tracked and trigger GitHub tracking hooks like UI-created tasks.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Add an optimistic submit lock to QuickEntryBox so Save/Enter cannot trigger duplicate task creation while duplicate checks or create requests are in flight.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Soft-delete terminology cleanup: `fn_task_delete` and Fusion skill docs now describe `deleteTask` as a soft delete (row + artifacts preserved, ID reserved) and point users to archive cleanup for the actual hard-removal path.

View File

@@ -1,12 +0,0 @@
---
"@runfusion/fusion": patch
---
Add near-duplicate intent guard at task intake: dashboard `POST /api/tasks`
now rejects new tasks whose route paths, file paths, or identifier tokens
substantially overlap with an existing active task created in the last 7
days, returning `409 duplicate_candidates` with `reason: "near-duplicate-intent"`.
Triage `finalizeApprovedTask` backstops with a File-Scope-aware re-check
after PROMPT.md is written, auto-archiving the loser with a
`sourceMetadata.nearDuplicateOf` lineage marker. Layered on top of the
FN-4918 deterministic and FN-4829 similarity gates; fails open on any error.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": minor
---
Add deterministic automated follow-up dedup for verification failures and related engine-created recovery tasks.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Fix Fusion pre-commit identity-guard hook leaking install-time task ID across shared git hooks dir; hook is now driven entirely by per-worktree fusion-task-id metadata (lowercased to match canonicalFusionBranchName), so a stale install no longer refuses valid sibling-worktree commits.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Make CLI test suite ~3× faster: add a `replyTimeoutMs` option to `runChatInteractive` so the `--once` timeout test no longer waits a real 30s for "No reply within 30s", and gate the heavyweight esbuild-bundled-plugin integration test behind `FUSION_RUN_SLOW_TESTS=1` (the same install/upgrade logic is covered by mocked unit tests in the same file).

View File

@@ -1,5 +0,0 @@
---
"@fusion/core": patch
---
Stop `MasterKeyManager` from probing the real macOS/Linux keychain during tests. A new `FUSION_MASTER_KEY_DISABLE_KEYCHAIN=1` env var forces the file backend, and the core vitest setup sets it so tests no longer hang for 15s in `keytar.getPassword(...)` on machines without a usable keychain.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Fix slow `fusion` startup that hung on "Starting engine…" while every registered project's engine initialized serially in `Promise.allSettled`. Engine startup now runs in the background — the TUI proceeds immediately, and the existing reconciliation loop plus the server's on-access fast path bring each project's engine up before it's actually needed.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": minor
---
Add a "Connection → Change Launch Mode…" menu item to the Fusion desktop app so users can switch between Run Locally and Connect to Remote after the initial chooser. It resets the persisted desktop mode, stops the embedded runtime, and reloads the dashboard so the launch gate re-prompts.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": minor
---
Add a desktop launch gate so the packaged Fusion app prompts the user to either run Fusion locally (starts the embedded runtime and points the dashboard at it via `?serverBaseUrl=…`) or connect to a remote Fusion server, instead of immediately showing a "can't reach backend" error.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Fix Fusion desktop (Electron) packaged builds opening a blank window — or no window at all — on macOS. `run()` is now invoked in packaged builds (where `process.argv[1]` is unset by Electron), and the dashboard client is built with a relative `--base ./` so its `file://`-loaded `index.html` can resolve `./assets/*` from inside the asar.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Fix activity-log triple-write caused by multiple TaskStore instances polling the same SQLite DB. When the dashboard, engine runtime, and per-project stores each `watch()` the same database, every column move was previously recorded once per instance — inflating `task:moved` rows ~3x (146k+/day) and amplifying failure noise. TaskStore now suppresses activity-log writes for events re-emitted from its polling loop, leaving the originating instance as the sole audit writer.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Fix the main chat composer (ChatView) so the textarea grows in height as the message gets longer, matching QuickChat's behavior. The autosize now runs before the controlled `setMessageInput` (so the height assignment lands in the same frame as the user's keystroke), and the height clamp now has a 40px floor so a 0-scrollHeight measurement never collapses the composer to zero.

View File

@@ -1,5 +0,0 @@
---
"@fusion/dashboard": patch
---
Fix dashboard occasionally serving a blank/broken page until the server is restarted. The server cached `index.html` and the Vite view-chunk manifest forever with no invalidation, so any on-disk change (release upgrade, rebuild) left the server handing out stale HTML referencing chunk hashes that no longer existed. Both caches now invalidate automatically when the underlying file's mtime changes. The `serveIndexHtml` catch path also now logs the failure and clears the templated cache so a subsequent request can recover, instead of silently returning 404 forever.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Fire GitHub tracking-issue creation for duplicated and refined tasks. Previously the duplicate/refine routes returned without calling `createTrackingIssueForTask`, relying on TaskStore's hook — but mocked stores in tests (and certain race conditions) could bypass the hook, leaving the new task with no linked tracking issue. The routes now invoke tracking explicitly as a best-effort step after creation, matching the PATCH-with-githubTracking path's behavior.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": minor
---
Add `worktreesDir` project setting to place task worktrees outside the project root. Supports absolute paths, paths relative to the project root, `~` expansion, and the `{repo}` token. Defaults to the existing `<projectRoot>/.worktrees` behavior when unset.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
QuickChat session picker now uses the themed dropdown style and includes chat rooms in the switch list.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": minor
---
Make OpenRouter a first-class provider: send HTTP-Referer/X-Title attribution headers, prefer /api/v1/models/user when an API key is configured, expose openrouterModelFilters and openrouterProviderPreferences in settings, and forward provider routing prefs into chat completion requests.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Inline the in-review TaskCard Move dropdown into the meta row when badges are present, while preserving the existing bottom-row fallback when no meta row is rendered.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": patch
---
Fix Planning Mode so the loading view can show streamed thinking output during the initial question turn, including buffered SSE thinking events that arrive before the first question event.

View File

@@ -1,5 +0,0 @@
---
"@runfusion/fusion": minor
---
Add `worktrunk` settings group (`worktrunk.enabled`, `worktrunk.binaryPath`, `worktrunk.onFailure`) to both global (`~/.fusion/settings.json`) and project (`.fusion/config.json`) tiers, with field-level project-overrides-global precedence. CLI `fn settings set worktrunk.<field>` is supported in both scopes. This is settings plumbing only; the worktree backend that consumes these keys ships in a follow-up.

Some files were not shown because too many files have changed in this diff Show More