Changes for version 0.6.0. Publication status and date are recorded on the GitHub release and npm.
OpenRig 0.6.0 requires Node.js 22 or 24. It adds per-seat permission choices, a per-seat typing guard for seats where you type by hand, and a one-step way to open a whole rig in Herdr. It fixes Pi seat activity and clarifies the kernel starter's runtime choice.
It also includes two experimental features: Slack app manifest and setup assistance, and an optional stream classifier (Jev with Rig Stream) that is off by default. They may be incomplete or not work in your setup. See Report experimental problems.
OpenRig 0.6.0 supports Node.js 22 and 24 only, and uses better-sqlite3 13, which requires Node 22 or newer. Node 20 is no longer supported: the install check refuses it with an explanation. Node 26 and other versions are untested.
If you run OpenRig on Node 20, switch Node first, then reinstall the CLI under the new Node. Your existing data stays where it is; the daemon reopens the same database and applies pending migrations in place. See Moving off Node 20.
OpenRig runs on macOS or Linux. Native Windows is not supported yet, and WSL2 has not been tested. On a Mac with Apple silicon, use Node.js 22 (see the compatibility history).
rig seat set-permissions <seat> --mode <mode> --reason <text> records an audited
permission choice for a seat's future launches: floor, full_bypass, or
inherit to clear the override. Codex full_bypass now passes
-s danger-full-access -a never, so it bypasses approvals as well as the
sandbox. Additional Claude Code modes such as auto are accepted only when the
seat's managed Claude executable advertises them; OpenRig checks this at
selection and again at launch, and refuses without a fallback.
The choice does not relaunch the seat or change its current process, history,
rules or hooks. rig seat status shows the selected mode and the last launch
arguments; neither proves the native permission behavior, so check the running
session before relying on it. Rig-level policy moves to
rig policy permissions list|show|current|apply; the old rig policy verbs
remain as aliases. See the permission guide.
rig seat set-typing-guard <seat> --enabled true --reason <text> pauses all
automatic terminal input to that seat, even at an empty prompt. Messages and
wakes are kept in the outbox instead of being typed in; read them with
rig seat held-messages <seat> and retire reviewed ones with
rig seat retire-held-message <seat> <id> --reason <text>. Turning the guard off
allows new sends; it never replays held messages.
The guard is off by default, and other seats keep automatic delivery. Wait for
rig seat status <seat> to report it as effective before relying on it. It covers
OpenRig's own input paths, not other tools writing directly to the terminal.
rig seat set-typing-guard --help lists the retention limits.
rig slack manifest prints the Slack app manifest for the app you create in your
own workspace. It runs offline, before any daemon or token exists; --url
prints Slack's create-app link with the manifest prefilled, and --json lists
each requested scope with its reason. The TUI Connections page shows the same
link while Slack is not configured. OpenRig does not host an app, open a
browser or accept tokens here.
This manifest and the Slack setup guide are
experimental. The guide's creation steps follow Slack's manifest documentation
and have not been confirmed against a real app creation: we have not observed
which fields Slack prefills or a complete set of granted scopes. You still
create the tokens and the private env file by hand. The existing Slack connector
and its rig slack setup, verify, enable, disable and status commands are
not experimental; setup and status now also point you to the manifest.
rig slack verify checks only the baseline scopes, so a READY result does not
prove attachments or mentions work.
In the TUI, a rig's detail view has a term ▸ rig <name> link, and the command
bar accepts terminal <view>. With Herdr, every running seat of the rig opens in
a workspace named after the rig, up to 16 seats per tab (cmux keeps its own
limits). The empty starting tab is closed only when OpenRig can confirm the rig's
own tabs opened; otherwise it is kept, and the result says so. Seats that are not
running are reported as absent or degraded rather than opened.
- Pi seat activity reports now carry the seat's occupant generation, and the daemon accepts them only when that generation matches the seat's current occupant. Reports with a missing, earlier or foreign generation are refused instead of being attributed to the seat.
- The kernel starter's summary now says when it shows the library preview, explains that the runtime variant is chosen automatically, and points to the seats actually running.
- Codex seats launch with
--no-daemonwhen the installed Codex supports it, so each seat's tools run in its own app-server instead of a shared daemon. OpenRig checks support before each launch and refuses the launch if the check fails. - Missions and slices created with
rig scopeno longer fail the readiness reader when their manifest has nometadatablock. - Choosing
CLAUDE.local.mdfor Claude Code managed blocks, added in 0.5.16, is included unchanged.
OpenRig 0.6.0 includes an optional, experimental way for a classifier seat to have Jev, through OpenRouter, label Rig Stream observations. It may be incomplete or not work. It is off by default; turn it on for a local configuration file:
rig project experimental status --config ./experiment.json --json
rig project experimental enable --config ./experiment.json --max-requests 3 --timeout-ms 10000 --json
rig project experimental disable --config ./experiment.json --jsonEnabling starts no processing, capture, daemon or agent. Work happens only when
the classifier seat runs one foreground command, rig project wake … --experiment ./experiment.json, which allows 1–20 requests (default 3) and never retries in
the background. The run needs OPENROUTER_API_KEY in that process's environment
and sends the selected items' text, the taxonomy questions, scope IDs and roster
destinations to OpenRouter. Disable stops further calls and discards late
results; Ctrl-C cancels the run, though a request already forwarded may still be
charged.
The labels are advisory. They have no demonstrated accuracy or calibrated
confidence, and this release adds no delivery, watchdog or routing consumer for
them. rig project experimental capture applies the same client to an existing
shadow-capture archive, and rig project shadow-status, shadow-drain and
shadow-stop manage capture, which needs its own separately configured daemon
start; rig project shadow-stop stops it. See
stream classification for the taxonomy
format, request limits and error handling.
If the Slack manifest, the setup guide or the stream classifier does not work as described, please open an issue with the bug template, or send a pull request following CONTRIBUTING.md. A problem with the existing Slack connector or any other existing feature is a regular bug report.
- Per-seat permissions: authenticated native enforcement across fresh launch, resume and same-seat fork was not verified before release. Status output and launch arguments do not prove a selected mode's effective permissions; inspect the running session.
- Slack manifest and setup assistance (experimental): creating the app in a real workspace, Slack's prefilled fields and the complete granted scopes have not been observed against the published steps.
- Herdr: check that the rig opened as expected in your Herdr version.
- Pi: activity reporting from an installed Pi seat has not been verified end to end.
- Stream classification (experimental): an installed run and real OpenRouter access have not been verified, and its output may be incomplete or wrong. No accuracy or production-reliability claim is made.
- The Codex hook-trust dialog report in #17 has not been reproduced, and this release does not change it.
- Node 26 and odd-numbered Node versions are not supported or tested.
Release preparation is tracked in #109. An ordinary candidate-tarball installation passed on a fresh macOS 15.7.3 ARM64 VM with Node.js 22.22.1 and the real npm postinstall. Checks covered better-sqlite3 13.0.3, all 89 migrations, database writes and close/reopen, and normal unauthenticated daemon startup and shutdown.
Prior candidate checks on Node 24 covered installed SQLite, migrations and allocation-driven garbage collection. The relevant install and database mechanisms are unchanged. That installation used a staged offline postinstall; it was not a fresh-machine install. A fresh Node 24 VM installation was not performed because of host resource pressure.
These checks do not establish an authenticated first-agent launch, a fresh Linux or Windows installation, installation without compiler tools, or an installation downloaded from the npm registry. The final artifact will be separately bound to the merged release commit.
Thanks to:
- @jimallen for reporting the Node 26 installation failure and proposing the better-sqlite3 13 upgrade in #16.
- @shravansumanthanan for the mission readiness fix in #91, and @kainne44 for reporting it in #72.
- @mvdpoel for repairing two daemon test fixtures in #84.
- @reisalbuquerque for reporting the shared Codex app-server identity problem in #69, fixed in #77.
- @DoowanKang for #29 and #30, @djogss for #33, @some-marketing for #48, @shintaii for #26 and @tgrundtvig for #21.
The platform statement in #94 answers the Windows question in #88; native Windows support is not part of this release.