Ir para o conteúdo

← Blog

Releasesv0.64.2

v0.64.2

Esta é a nota de release como foi publicada, não uma reescrita dela. As notas de release são publicadas no idioma em que foram escritas.

Security

  • Every chat bot answers only the ids its owner listed (#746). The Discord, Telegram, Slack and Signal adapters accepted an allowlist and nothing filled it, so a bot answered anyone who could write in a channel it read, with the owner's tools and spend. CHIMERA_DISCORD_ALLOWED_USERS, _TELEGRAM_, _SLACK_, _SIGNAL_ and CHIMERA_WHATSAPP_ALLOWED_NUMBERS now reach every bot, from chimera serve and from the app's Messaging card. An empty list keeps today's behaviour and says so loudly at start and in the card.
  • A page policy so an answer cannot make the window fetch another host (#750). The desktop window had no Content Security Policy, so an image in an answer (![x](https://host/?d=…)) was fetched by the window, outside the taint ledger and the egress allowlist. The app page, the guest page and the HTML preview now carry policies, and answers render remote images as a link naming the host. Measured in Edge 154 (the WebView2 engine): an outside host received every probe before and none after. WebRTC still escapes a CSP; the preview note says so.
  • A SKILL.md imported by path cannot vouch for itself (#747). Its own frontmatter decided whether it was trusted; now an import by path or URL always lands tainted and pending, and only the packaged cards keep what they declare.

Added

  • A scheduled job that could not run says so where its answers go (#751). Chimera's own scheduler posts one short line when a job with a destination enters failure (error, timeout, spend cap, brake) and one when it recovers, never the raw error text. A job that flaps is one notice, not one per tick. CHIMERA_CRON_NOTIFY_FAILURES=0 silences it; chimera cron add --deliver-to URL records the destination. This covers Chimera's scheduler only, not the VPS sidecar scripts.
  • Answer a pending approval from the chat bot, with a one-time code (#753), off by default (CHIMERA_APPROVE_VIA_CHAT). It works only with the setting on, a non-empty allowlist for that bot and an approval webhook. Each request gets a 6-digit code, valid once, shown only in the question the webhook delivers; only its hash is stored. A message shaped like an answer is intercepted before it becomes a turn, even with the setting off, so the code never reaches the model, the history or memory. Every refusal gets the same neutral line, and failed attempts are rate-limited. Silence is still a refusal.
  • Cron jobs post only what is worth posting, and hold only their tools (#736).
    • A scheduled run is told it is unattended, where its answer goes, and to assume rather than ask. It may answer with a fixed "nothing new" sentinel, which is never delivered.
    • Each job takes notify (always, the default and today's behaviour; on_change, which skips an answer identical to the last one delivered; failures_only) and a tools allowlist that reaches the registry. Old jobs.json files load unchanged; a webhook job refuses both fields, because the webhook path cannot enforce them.
  • chimera review --effort low|medium|high (#743). medium cuts findings below the finder's confidence 0.8; low is the finder alone. The default stays high, today's behaviour: the 0.8 cut was selected on one bench and not confirmed on the other (bench/review_confidence_cut/RESULTS.md).
  • A one-page multi-agent policy (docs/multi-agent-policy.md, #744): a flat topology by default, four sanctioned forms, what is out and the measurement that put it out, and the invariants that must be code. bench/PROTOCOL.md now requires every multi-agent arm to meet a single agent at equal cost.
  • Two pre-registered censuses, both without a product change (#741, #742). The Manager never decided an attempt alone in the stored runs, so no advisory mode ships (bench/manager_advisory). The explorer's regime is not common enough on attended turns to turn it on in the Code screen (bench/explorer_census).

Fixed

  • deepseek-v4-flash keeps its price row honest on a third route. On 2026-10-03 the live index quoted 0.028/0.056, a third figure after 0.0886/0.1772 and 0.04844/0.09688. The row keeps the highest, so a fallback never reads low, and accepts the new one as seen.

  • A "safety" or "flagged" in a server error no longer aborts the turn (#748). Such an error was classified as a content-policy refusal, which aborts, instead of falling back to CHIMERA_FALLBACK_MODELS.

  • The interface stops sending people to fields and importers that do not exist (#749): reserved keys are labelled as such, the SMTP/IMAP hint names the .env, and the cost chip opens the Usage tab.

  • The chat bot knows who it works for and where it is talking (#735). The Discord, Telegram, Slack and Signal bots, and the app's messaging bot, now get the owner's profile, recalled facts with the "possibly stale" header, and remember_from_chat as set. Each turn names the platform, chat and sender as quoted data that grants no authority, in the turn notes, never in the cached system prompt. The HTTP /chat route is unchanged.

  • The project's rules reach the prompt whole (#737). AGENTS.md files were cut in the middle at 2,000 characters, so Chimera's own lost four of its six hard rules. The cap is now 6,000; a longer file is cut at a section or paragraph boundary, keeping the head, with a marker for the model and an instructions_truncated notice for the person.

  • The harness's own "Task:" no longer picks a skill, and echo leaves the default registry (#738). The autonomous runner's prefix matched "data task" in a skill description, so nearly every cron, solve and run turn got the data-analysis skill. Retrieval now needs two content words and ignores the harness's own words.

  • The clock closes the turn context (#739), so a provider's prefix cache can reuse everything before it; the header no longer claims the user's message follows it when it does not.

  • The crew lands one approved worker's tree whole, then re-verifies it (#740). It used to copy every non-conflicting file from EACH approved worker, fusing two verified solutions into a hybrid nobody verified.

  • The browser works in the installed desktop app.

    • What was wrong: the browser tool runs Playwright's own driver (a bundled node and its CLI), and in the frozen sidecar that driver is package data, which the freeze did not collect. The installed app could neither launch Chromium nor install it, and nothing said so until a page was opened.
    • Now: the freeze collects Playwright whole (~36 MB per installer), and two tests guard both halves: the install command starts at the bundled driver, and the recipe keeps collecting it.

Ler a release no GitHub →