This release candidate is not yet admitted. The v0.8.5 install command below is unavailable until its immutable GitHub artifact passes exact release admission. An optional exact-byte npm mirror requires separate admission. The last admitted release is v0.8.4; use its verified archive. Current daemon startup and command-writer rollout remain blocked by authority_reduction_hard_quota. Artifact admission does not clear that block, authorize daemon upgrades or prove intended-target availability.
-
v0.8.5 restores active Devin provider support. The ACP v1 client, isolated process custody, fact reduction, foreground login and the local
devin_usage_panelusage source return under ordinary authority guards. Devin sessions are selectable through the existing provider-neutral seam; the panel source is local only and reaches no stored table, hosted payload or browser. -
v0.8.5 names the
oompacommand in the restored Devin login, recovery and next-command builders.oompa account login --provider devinno longer fails with a generic internal error before Devin's own login starts. -
v0.8.5 repairs the schema-61 upgrade for state roots that v0.8.4 migrated to schema 60. The schema-61 step treats v0.8.4's joined
queue_transcript_finalization_guardas a replaceable predecessor and recreates it, sooompa daemon startno longer fails withJOINED_QUEUE_TRANSCRIPT_GUARD_INVALID. The post-migration assertion stays strict: only the Devin-admitting form is valid at schema 61. -
v0.8.4 repairs the upgrade migration from pre-authority state roots. A Codex usage cloud upload anchor whose snapshot was pruned by retention no longer refuses the whole schema-41 step with
CODEX_USAGE_UPLOAD_AUTHORITY_INVALID, andoompa daemon startnames the refused invariant on a migration failure. It changes no schema, provider, or activation authority. -
v0.8.3 adds optional product updates and development support to CLI discovery, explicit support commands, the native menu and the public footer. It preserves machine-readable task output and all operational activation gates.
-
The candidate retains the compact ASCII orange-circle introduction added in v0.8.2, only on interactive root help. Machine-readable, redirected, nested-help, version and error output stays unchanged. The provider-usage foundation below is inherited from the canonically admitted v0.8.1 source; the v0.8.3 and v0.8.4 patches passed their own exact admissions recorded below, and this candidate requires its own.
-
The browser grid keeps each conversation inside its card. Earlier responses start collapsed, the latest stays open, and each card has its own scroll position and multiline composer. New sessions use a prompt and machine selection. Approved browsers open automatically; there is no manual or idle lock. Device approval and encrypted sync remain required. See the web app guide.
-
oompa account list --provider codex|claudereads separately versioned cached order, default marker, readiness and observation times. It neither refreshes providers nor changes selection; unqualifiedoompa account listis unchanged. -
oompa usage auto status|on|off|inheritexposes local inherited policy and per-provider overrides. Every change requires the revision from status and a caller-owned idempotency key. Effective Codex disable suppresses new reset-credit dispatches and retries without discarding uncertain attempts or cancelling an already admitted operation. See provider accounts and automatic usage settings for exact commands and replay behavior. -
Provider, queued-input and attachment recovery preserve exact historical authority. The additive storage foundation follows admitted schema 50 through schema 60; historical migration fixtures distinguish actual captured writer evidence from explicitly synthetic compatibility cases. Starting the current daemon remains a no-downgrade boundary.
-
Automatic account movement, managed-send forwarding, account order and activation commands, Claude native fallback, and the planned hosted/browser usage view remain unavailable. This candidate neither claims new authenticated provider acceptance nor changes platform support.
-
Read-only exact Codex default-profile observation and a browser-safe projection decoder that does not require CSP-blocked dynamic code generation are retained from the admitted v0.7.1 predecessor. The default-profile display remains unavailable until a matching fresh companion is published by the intended daemon after the relevant rollout. This observation does not change Ultra defaults, admit models, select a route, or authorize a command.
The immutable v0.8.4 GitHub release and exact-byte npm mirror passed release run 35136703343, attempt 2, on 2026-09-16. It binds source f79fd9b0bc0498b53af28878dba94b8db18900e5, archive hraness-oompa-0.8.4.tgz (1,722,209 bytes), and SHA-256 988ed30b0f6932e6b5a53be60c9e97d0ed5f1a055f29c995476bbe0ae9703996. Linux and macOS installed-package checks and public cryptographic provenance admission passed. Attempt 1 published the same canonical GitHub artifacts, but its optional npm mirror readback did not observe the publication; the documented same-run recovery on attempt 2 admitted the exact bytes without replacing any GitHub artifact. The complete release record preserves the tag, release and asset identities, checksum file, and npm integrity. These are artifact checks; the operational restrictions above remain in force.
The immutable v0.8.3 GitHub release and exact-byte npm mirror passed release run 35066335703, attempt 1, on 2026-09-16. It binds source ca5b064dabd918c2038920038bf83383f99a2e28, archive hraness-oompa-0.8.3.tgz (1,721,327 bytes), and SHA-256 b44a73461b49d970e13eb74a60c4c3bbaeaf06f42e25a26565e7e87c7f68d086. Linux and macOS installed-package checks and public cryptographic provenance admission passed. The complete release record preserves the tag, release and asset identities, checksum file, and npm integrity. These are artifact checks; the operational restrictions above remain in force.
The v0.8.1 GitHub artifact passed canonical release admission in release run 34781400584, attempt 1. The immutable release binds source 135a69bd592e41c3c1649241f3310ff41fc7e81e, archive hraness-oompa-0.8.1.tgz (1,707,906 bytes), and SHA-256 e84d6efe6779c359bf013663e50c8d9e4a43e380d837e92ac755e55e8c559208. The optional npm job failed before publication; no npm admission is claimed. This evidence does not admit v0.8.5 or authorize daemon startup or hosted command writers.
The v0.8.0 GitHub artifact passed canonical release admission in release run 34560340100, attempt 1. The immutable release binds source 2dae06babe263b22bd6f382b3f92018ebb80a25a, archive hraness-oompa-0.8.0.tgz (1,707,411 bytes), and SHA-256 c1aed1aa132f37e29c52a571d3d1ab6b8657e3a2078643ca2eb464e374a6de78. The optional npm job failed before publication; no npm admission is claimed. This evidence does not admit v0.8.5 or authorize daemon startup or hosted command writers.
Use the exact tagged transactional installer with Bun 1.3.14, then verify the installed version and offline health. It preserves the runtime, source and normalizer checks and the existing installation. These commands do not start the daemon:
test "$(unset BUN_OPTIONS NODE_OPTIONS LD_AUDIT LD_LIBRARY_PATH LD_ORIGIN_PATH LD_PRELOAD DYLD_FALLBACK_FRAMEWORK_PATH DYLD_FALLBACK_LIBRARY_PATH DYLD_FRAMEWORK_PATH DYLD_IMAGE_SUFFIX DYLD_INSERT_LIBRARIES DYLD_LIBRARY_PATH DYLD_ROOT_PATH DYLD_VERSIONED_FRAMEWORK_PATH DYLD_VERSIONED_LIBRARY_PATH && curl -fsSL --connect-timeout 10 --max-time 60 --max-filesize 524288 --retry 3 --retry-delay 1 --retry-max-time 60 --proto '=https' --tlsv1.2 https://raw.githubusercontent.com/hraness/oompa/v0.8.1/src/install-preflight-runtime.ts | command bun --no-env-file --config=/dev/null -e 'const n=["BUN_OPTIONS","NODE_OPTIONS","LD_AUDIT","LD_LIBRARY_PATH","LD_ORIGIN_PATH","LD_PRELOAD","DYLD_FALLBACK_FRAMEWORK_PATH","DYLD_FALLBACK_LIBRARY_PATH","DYLD_FRAMEWORK_PATH","DYLD_IMAGE_SUFFIX","DYLD_INSERT_LIBRARIES","DYLD_LIBRARY_PATH","DYLD_ROOT_PATH","DYLD_VERSIONED_FRAMEWORK_PATH","DYLD_VERSIONED_LIBRARY_PATH"],x=process.execArgv;const c=x.filter(v=>v==="-c"||v.startsWith("--config"));if(n.some(k=>process.env[k]!==undefined)||x.filter(v=>v==="--no-env-file").length!==1||c.length!==1||c[0]!=="--config=/dev/null"||x.some(v=>v.startsWith("-r")||v==="--preload"||v.startsWith("--preload=")||v==="--require"||v.startsWith("--require=")||v==="--import"||v.startsWith("--import=")||v==="--env-file"||v.startsWith("--env-file=")))throw new Error("The tagged Oompa preflight requires a neutral Bun stage zero.");const[a,h]=process.argv.slice(1);const r=Bun.stdin.stream().getReader(),q=[];let z=0;try{for(;;){const o=await r.read();if(o.done)break;z+=o.value.byteLength;if(z>524288)throw new Error("The tagged Oompa preflight exceeds its byte limit.");q.push(o.value)}}finally{r.releaseLock()}const b=new Uint8Array(z);let p=0;for(const v of q){b.set(v,p);p+=v.byteLength}const d=new Bun.CryptoHasher("sha256").update(b).digest("hex");if(d!==h)throw new Error("The tagged Oompa preflight digest is invalid.");const j=new Bun.Transpiler({loader:"ts",target:"bun"}).transformSync(b);const u=URL.createObjectURL(new Blob([j],{type:"text/javascript"}));try{const m=await import(u);await m.installOompaRelease(a);process.stdout.write(`${m.OOMPA_INSTALL_SUCCESS}\n`);}finally{URL.revokeObjectURL(u)}' -- https://github.com/hraness/oompa/releases/download/v0.8.1/hraness-oompa-0.8.1.tgz 8945fab8bbf4685681915fe1d0045c3847e2c1ad5ce1e1ee2bb73ed012cd353f)" = hra-install-safe
oompa --version
oompa doctor --offlineThe v0.7.1 local CLI artifacts are fully admitted through release run 34367591503, attempt 2. The exact release record binds the source, bytes and cryptographic provenance, including the initial visibility failure and successful same-run recovery without republication. That evidence does not admit v0.8.5 or clear operational rollout gates. Its immutable README supplies the exact admitted installation command.
The v0.7.0 local CLI artifacts completed admission through release run 34278486095, attempt 2, and remain an admitted predecessor. That evidence does not admit v0.7.1 or v0.8.5. The exact release record preserves the initial post-publication failure and successful same-run recovery. The v0.6.3 artifacts remain an admitted predecessor; the v0.6.0 artifacts remain an immutable partial publication. Current daemon startup and command-writer rollout remain blocked by authority_reduction_hard_quota. Artifact admission, downloading, or installation does not clear that gate. Before starting a current daemon, require the protected two-pass zero-debt capacity evidence and its exact .activated readback receipt from the hosted rollout runbook. After startup, prove each intended target's marker before declaring command availability. Do not reclaim account data or raise quotas without separate authority.
Automatic approvals reserve their shared budget before dispatch and recheck current consent after asynchronous review. Older display-log retention no longer controls hourly or daily limits. The first upgrade to local schema 44 places existing sessions on a durable 24-hour automatic-approval hold because their older budget history may be incomplete. It also closes the consecutive budget until the next real human message, which can be sent during that hold. Manual approvals remain available, and oompa autorespond status --session <session> reports the hold's end and counters. New sessions have no migration hold. Prepared and uncertain approvals remain charged; do not downgrade the migrated state root.
The history_unavailable refusal can also mean that the local clock moved behind a retained approval or that unresolved prose recovery filled the bounded reservation ledger. A hold timestamp describes only the upgrade hold. Wait for the clock to catch up or complete the exact pending recovery; do not clear the ledger or the audit log to reopen automatic approvals.
Oompa is a persistent multi-provider CLI for isolated accounts and live local session control. Codex runs on macOS and Linux; Claude Code runs on Linux. Optional hosted encrypted sync has been live since 2026-09-03 and is now an open beta.
The v0.6.3 artifacts passed immutable GitHub and npm release admission through release run 34165802848, attempt 2. Its immutable README supplies the admitted installer. v0.6.3 admission does not admit v0.7.0. Its after-hours policy is not included in the admitted v0.6.2 predecessor. The release adds a separate local
default-off policy, not notification consent. Once the rollout gates and an
explicit owner opt-in are satisfied, otherwise eligible protocol approvals may
use 6 consecutive, 20 rolling-hour, and 80 rolling-day reservations outside the
configured notification hours. Prose remains at 3/10/40, and both paths use the
same accounting. Policy changes and time boundaries never reset counters or
refund reservations. Schema 46 conservatively requires a newly finalized human
message before any pre-44 session can use the higher tier. This work does
not enable workspace attestations or alter the existing hosted rollout hold. The exact release record binds the admitted source and bytes; later source-only additions are not included in that artifact. The separately admitted v0.7.0 release retains this policy without enabling it. The commands below and in the current README name the unadmitted v0.8.5 candidate and are unavailable until its own immutable GitHub release admission; daemon startup still requires the rollout prerequisite. The admitted predecessor's exact release record is above. The historical v0.7.0 installer remains in its immutable README. For historical v0.6.1 recovery, use that release's immutable notes.
The admitted v0.6.2 release hardens Codex cancellation and exact recovery authority, Claude status and interrupted-login cleanup, and the web sign-in experience. Its additive schema 45 preserves schema 44's automatic-approval budget. Release workflow 34156958618, attempt 2, completed successfully for exact source 5c5c02ee5964167fb85e92da53cdb80c87991890. The immutable v0.6.2 README supplies its admitted installer; its artifact-admission prerequisite is satisfied, but its daemon-rollout prerequisite is not. The admitted v0.7.0 predecessor includes that exact predecessor authority but keeps its own versioned installer and independent admission evidence; v0.6.2 admission does not admit v0.7.0. Neither these changes nor artifact admission clear the hosted capacity block, Claude's Linux-only boundary, or pending real-provider acceptance. See the v0.6.2 changelog, immutable v0.6.2 release, and release controls.
Only after immutable GitHub release admission for v0.8.5, install its exact artifact with Bun 1.3.14 and verify its version and offline health. This does not start the daemon. The command is unavailable before admission; use the admitted v0.8.4 archive instead:
test "$(unset BUN_OPTIONS NODE_OPTIONS LD_AUDIT LD_LIBRARY_PATH LD_ORIGIN_PATH LD_PRELOAD DYLD_FALLBACK_FRAMEWORK_PATH DYLD_FALLBACK_LIBRARY_PATH DYLD_FRAMEWORK_PATH DYLD_IMAGE_SUFFIX DYLD_INSERT_LIBRARIES DYLD_LIBRARY_PATH DYLD_ROOT_PATH DYLD_VERSIONED_FRAMEWORK_PATH DYLD_VERSIONED_LIBRARY_PATH && curl -fsSL --connect-timeout 10 --max-time 60 --max-filesize 524288 --retry 3 --retry-delay 1 --retry-max-time 60 --proto '=https' --tlsv1.2 https://raw.githubusercontent.com/hraness/oompa/v0.8.5/src/install-preflight-runtime.ts | command bun --no-env-file --config=/dev/null -e 'const n=["BUN_OPTIONS","NODE_OPTIONS","LD_AUDIT","LD_LIBRARY_PATH","LD_ORIGIN_PATH","LD_PRELOAD","DYLD_FALLBACK_FRAMEWORK_PATH","DYLD_FALLBACK_LIBRARY_PATH","DYLD_FRAMEWORK_PATH","DYLD_IMAGE_SUFFIX","DYLD_INSERT_LIBRARIES","DYLD_LIBRARY_PATH","DYLD_ROOT_PATH","DYLD_VERSIONED_FRAMEWORK_PATH","DYLD_VERSIONED_LIBRARY_PATH"],x=process.execArgv;const c=x.filter(v=>v==="-c"||v.startsWith("--config"));if(n.some(k=>process.env[k]!==undefined)||x.filter(v=>v==="--no-env-file").length!==1||c.length!==1||c[0]!=="--config=/dev/null"||x.some(v=>v.startsWith("-r")||v==="--preload"||v.startsWith("--preload=")||v==="--require"||v.startsWith("--require=")||v==="--import"||v.startsWith("--import=")||v==="--env-file"||v.startsWith("--env-file=")))throw new Error("The tagged Oompa preflight requires a neutral Bun stage zero.");const[a,h]=process.argv.slice(1);const r=Bun.stdin.stream().getReader(),q=[];let z=0;try{for(;;){const o=await r.read();if(o.done)break;z+=o.value.byteLength;if(z>524288)throw new Error("The tagged Oompa preflight exceeds its byte limit.");q.push(o.value)}}finally{r.releaseLock()}const b=new Uint8Array(z);let p=0;for(const v of q){b.set(v,p);p+=v.byteLength}const d=new Bun.CryptoHasher("sha256").update(b).digest("hex");if(d!==h)throw new Error("The tagged Oompa preflight digest is invalid.");const j=new Bun.Transpiler({loader:"ts",target:"bun"}).transformSync(b);const u=URL.createObjectURL(new Blob([j],{type:"text/javascript"}));try{const m=await import(u);await m.installOompaRelease(a);process.stdout.write(`${m.OOMPA_INSTALL_SUCCESS}\n`);}finally{URL.revokeObjectURL(u)}' -- https://github.com/hraness/oompa/releases/download/v0.8.5/hraness-oompa-0.8.5.tgz 84c08d0d11e7d860b738a875c59721fe5589cb9b0d6fd2c819f1347e791f2b57)" = hra-install-safe
oompa --version
oompa doctor --offlineDo not run oompa init --yes, oompa daemon start, or a command that can autostart the daemon while the capacity gate above remains blocked. Existing installations must also complete the update runbook, including local journal reconciliation, before migration.
The single command removes ambient Bun, Node, and native-library injection variables before the download or Bun startup, disables Bun dotenv loading, selects /dev/null as the only Bun configuration, independently caps the streamed preflight at 512 KiB in Curl and the loader, and verifies the SHA-256 of the exact tagged installer runtime before executing it. The loader refuses an overrun before transpilation or installation. The installer then requires GitHub repository ID 1343008607, a published immutable v0.8.3 release, and one uploaded archive whose size and SHA-256 match GitHub's immutable metadata. It privately downloads the archive and gives Bun only a verified in-memory snapshot of those exact bytes. The reviewed normalizer verifies the private archive again, derives its bounded package-file manifest, and compares every extracted Oompa package path and SHA-256 while measuring the archive-bound completion receipt. Local and official archives use separate full-digest version namespaces. Oompa also verifies the complete staged tree, package identity, zero-lifecycle manifest, reviewed normalizer, CLI SHA-256, protected descriptors, links, ownership, permissions, and ACLs before atomically publishing only the $BUN_INSTALL/bin/oompa symlink. The detached staging worker and its Bun package-install child repeat the runtime neutralization while retaining configured registry, proxy, and certificate trust inputs. Bun 1.3.14 resolves the package's exact dependency versions from the configured package registry trust boundary with lifecycle scripts disabled; the archive does not claim to contain that dependency closure. The prior verified command remains active throughout staging, and an exact same-release retry removes or completes only a proven private stage. The invoking shell, PATH-selected pinned Bun binary, configured package registry and transport trust, operating system, and same-UID account remain trust boundaries. Existing trustedDependencies remain unchanged.
A durable installer intent is release-bound. An installer from another release fails closed without deleting it. Do not edit or delete the intent or its staging or version directories; rerun the exact immutable install command from the originating release's trusted README or release notes, require hra-install-safe, and then retry v0.8.5 only after its exact artifact admission. If that installer refuses the intent, stop installation and use bounded read-only diagnosis while preserving the intent and its directories. Establish the originating tag independently from trusted release evidence, never from an intent-supplied URL or command alone. An uncertain tag blocks execution, not diagnosis. Ask the owner only when the evidence cannot resolve a required decision or authority is missing. This is local installer recovery, not authorization to retry or mutate the originating release's workflow, tag, GitHub Release, or npm publication.
The candidate retains the admitted v0.7.1 feature foundation described below, but needs its own immutable GitHub artifact admission. Hosted sync is an open beta: sign-up no longer needs an invitation, and installing this release grants no enrollment authority of its own.
- The v0.8.5 candidate additions and retained default-profile observation are described above. The remaining features below are retained through the admitted v0.7.1 predecessor from v0.7.0; their admission does not admit this candidate.
- This forward repair completes the intended v0.6 admission without mutating or retrying
v0.6.0. That immutable tag produced matching GitHub and npm artifacts, but its first workflow attempt exhausted the bounded registry-visibility window and its second attempt exposed a verifier mismatch before final public admission. The verifier expected the Fulcio repository-subject extension to contain the tag ref; npm's current certificate instead carries environmentnpm-releasein OID.23and the numeric repository subject ending:environment:npm-releasein OID.24. Tag and ref remain independently bound by the certificate URI and OIDs.6,.14, and.18. Oompa now verifies that exact split while retaining every workflow, run, commit, visibility, repository, owner, event, tag, and package-byte claim. - Stable project memory backed by exact public
@hraness/oh@0.10.8. Each project-bound session gets an expiring working lane and reads it together with durable project canonical memory. Codex and Claude Code receive four closed memory tools; the owner-facingoompa memory status|list|get|search|explain|remember|sharesurface addresses Codex and Claude Code sessions. Remember stays working-only, and share adopts one attested page with strict compare-and-swap conflict evidence rather than automatic publication or overwrite. - Attributed same-project peer coordination for Codex and Claude Code sessions. Per-session
off | inspect | coordinatepolicy, stale-revision checks, an eight-hop causal ceiling, rolling rate and fan-out limits, bounded inbound queues, restart-safe effect recovery, and at least seven days of complete replay evidence keep list, inspect, send, queue, and steer distinct from Work or approval authority. Retired sessions cannot participate. - Opt-in hosted canonical memory through
oompa memory hosted list|create|attach|detach|sync. Oompa client-encrypts portable-space descriptors, exact Oh operations, terminal-head proofs, and portable adoption proofs. Sync is fast-forward-only, retains the complete remote operation chain until authenticated account deletion, and fails closed on divergence or uncertain recovery without disabling working-memory writes or working-only reads. A separate encrypted read-only browser summary exposes bounded per-device head, count, recency, enrollment, sync, peer-policy, and content-free peer-action state; it never uploads the working-memory lane or raw Oh history. - Devin support has been removed because the supported CLI/ACP integration cannot report verified remaining account quota and reset times. Existing local history, migration authority, and provider-owned credentials are preserved; retired sessions cannot execute. Only exact local cleanup of historical login grants remains available.
- Codex
highand the defaultultrapreset use exactgpt-6-astraatmaxandultrareasoning. New or explicitly reselected Codexhighandultraroutes bind contract 2, as do new Work plans. Existing contract 1 Codex sessions keep their established Sol route until reselection. - Explicit remote writes of the rebound Codex
highandultraaliases carry the client's immutable preset contract, as does a preset-omitted provider switch targeting Codex because its target alias is daemon-derived. The local CLI request envelope applies a separate current-build fence to session writes and Work creation or extension that names either rebound alias. A High or Ultra session-start replay preserves its caller-authored contract with the idempotency key. Work apply version 2 requires that source contract for affected creation or extension. An affected version 1 document admits only exact historical replay because a fresh one does not distinguish Sol from Astra. Fresh rebound tasks must also match their Work's durable contract, and prepared session starts or switches bind the resolved contract in their durable request identity. Fresh missing, inactive, or mixed-version bindings are refused before provider effects; source-matched settled replay remains historical, effect-started replay remains recovery-required, and changed source under the same key conflicts. Explicit stable aliases and preset-omitted Claude switches retain their token-free wire shapes, and live browser controls remain alias-labelled until their target projects an exact binding. - Hosted session and device command commitments now bind the authenticated requesting device as well as the exact target, payload, kind, deadline, command identity, and session identity where applicable. The current daemon executes only a version 2 requester-bound commitment. During a rolling update, each daemon publishes an internal marker-2 capability before processing commands, and a fresh enqueue must exactly match that target's last stored marker. The hosted runtime also requires an uncharged capacity-activation tuple that exactly matches its compiled release attestation and the protected repair evidence. A target-marker or activation mismatch rejects fresh enqueue before the command, quota charge, or security event is inserted; marker-2 prepare and new effect-start transitions enforce both current executor shape and hosted activation. A candidate redeploy invalidates the old activation tuple. Exact same-key replay and terminal or cleanup paths stay available while fresh work is closed. A registry-publication failure skips both command queues for that cycle, and an old daemon's registry write clears its target capability. Already-hosted terminal rows and legacy recovery keep their conservative precedence and never authorize a provider replay. Deploy the additive hosted candidate first, run the source- and runtime-bound command-capacity repair from
docs/hosted-sync.md, and require both its protected two-pass zero-debt evidence and the exact.activatedreceipt produced after hosted activation and readback. Only then upgrade daemons, collect marker-2 proof from every intended target, and treat marker-emitting clients as globally available. The Vercel app can auto-deploy frommainearlier; that UI is not readiness, and its commands should receive expected pre-insertion refusals until capacity activation and target-marker proof exist. Old clients and targets whose markers are both absent remain compatible. There is no per-target writer switch, all-daemons-current pause, or account-wide legacy-drain barrier. Retain the hosted compatibility surface until local journals and outboxes are reconciled and every related row is terminal or expired. - Oompa now owns a bounded retained provider-neutral transcript from the point the v0.6 daemon begins recording a session. It records accepted direct, queued, Work and scheduled automation, autorespond, and provider-switch handoff messages with actor provenance, plus safe tool-call summaries without raw arguments or output. It does not backfill provider history from before personal-home admission or pre-v0.6 user turns in upgraded state, and those origin gaps do not set the current retention-gap field. Attachments appear only as byte-free manifests with bounded names, media types, sizes, and digests. Retention is capped at 50,000 events, 64 MiB, and seven days; once pruning occurs, switch seeds and exports state the retention reason and leave the unavailable older count unknown. Transcript reads request at most 500 records and may retain fewer to fit the 4 MiB daemon response envelope, with 64 KiB reserved for wrapping; head pages keep the oldest fitting records and return an exclusive cursor, while switch and export tails keep the newest. The latest retained tail remains readable when a provider thread is unavailable and exports as Oompa JSON or as records validated against the trajectory v1 schema shipped by the pinned
@letta-ai/trajectory0.3.0 development fixture. The standard trajectory meta record contains onlyrole: "meta"andsource: "oompa"; Oompa's session, digest, omission, and retention-gap values are JSON text inside a standard observation, while native Oompa JSON retains typed fields for those values. - Schema v43 preserves attachment names accepted by v42 by projecting only the newly unsafe Unicode scalars and assigning deterministic bounded suffixes when two names for one digest would otherwise collapse. A v42 local send or steer that stopped after preparation but before its manifest or provider effect can finish on v43 only with the same command kind, session, message, original attachment path and basename, and explicit idempotency key. The daemon requires the original request digest before resolving the blob or contacting a provider. Fresh commands, queues, and hosted payloads remain on the current strict name rule.
oompa session switchmoves a quiescent session between Codex and Claude Code when both providers support the selected platform and preset. An evidence-first crash protocol fences both account generations and the daemon generation, starts and seeds the target once, releases the source, and commits the new provider binding atomically. Recovery advances only from durable evidence and complete provider projections; it never repeats an unproven target-start or seed effect. If a daemon restart leaves an unreleased process-local Claude side, automatic recovery refuses without provider effects. Explicit abandonment terminalizes with provider-state-unknown evidence and touches only addressable non-Claude sides; a seeded Claude target is never declared live from durable rows alone.- Codex account linking from the web always requests app-server device-code mode. Oompa accepts only the pinned app-server's exact
https://auth.openai.com/codex/deviceverification URL and a separate closed user code, encrypts the complete handoff to the requesting account key, exposes it once, and expires it against hosted time after five minutes. Browser-mode loopback callbacks and unversioned requests are refused before a local login effect. - Codex authentication reads stop on cancellation before dispatch. Durable login and cancellation recovery binds exact successor authority without replaying an uncertain provider effect, and cancellation settlement is atomic. Settings preserves the one-time Codex code during a pending status check and gives recovery guidance when the handoff expires or is lost; email sign-in keeps the submitted identity fixed while its request is pending.
- Claude authentication is a provider-owned foreground path on Linux.
oompa account login <profile> --provider claudelaunches a realpath-resolved Claude executable after its exact self-reported version matches Oompa's compatibility pin inside the profile's isolatedCLAUDE_CONFIG_DIR; this does not authenticate the executable's package bytes.oompa account show <profile> --provider claudereports onlysignedIn. Oompa never opens or copies a Claude credential. One-child grants, exact completion after restart, acknowledged local-fence recovery, bounded status probes, and quiescent idle-session retirement prevent duplicate login children and shared-home races. - Claude status distinguishes subscription authentication from other signed-in modes before attributing account identity. Interrupted foreground login has a bounded final process join; its cleanup deadline starts only after interruption, and uncertain cleanup remains fenced.
- Claude Code sessions and provider switches prove their own sign-in state immediately before their effect. Codex keeps its existing app-server authority, and no provider's authentication can stand in for another's.
- Personal-home session adoption is opt-in only for Codex and Claude Code. Oompa discovers recent conversations and also considers an older Codex thread targeted by a present active or paused Desktop heartbeat automation. That Desktop input is private age-gate authority only: the association waives only age and never becomes an Oompa schedule, a synced scheduled-task row, or a public origin marker. Admission still requires bounded account, project, liveness, quiescence, and exact-thread checks. Personal-home Claude account proof transiently reads bounded identity metadata and retains only a one-way local authority key. Raw identity fields, candidate identities and records, runtime bindings, process identities, schedule-source metadata, provider-home provenance, and provider-account authority hashes are never publicly returned, projected, or uploaded. Optional cloud sync carries only encrypted Codex and Claude Code provider-level enablement plus bounded pending, adopted, and fenced counts. Once admitted, the conversation uses the same provider-supported commands, scheduled work, autorespond policy, and approval authority as an Oompa-created session. Provider-specific limits remain identical for both origins.
- Remote
set_providerandoompa remote provideruse the ordinary execution lease for a provider switch. Account selection stays on the machine holding the credentials. - Everything from
v0.5.0: isolated Codex accounts and the Claude Code provider seam, durable provider interactions and remote decisions, subagent activity, live hosted session projection, device commands, conversation-bound scheduled tasks, agent-safe JSON and JSONL output, and one checksummed npm tarball published as the same bytes on npm and the immutable GitHub Release withSHA256SUMS. v0.5 refused before launching a Claude session; end-to-end Linux Claude sessions are new in v0.6.
-
Existing personal adoptions and legacy sessions without a proved Oompa capability do not gain model-facing memory or peer tools merely by resuming. The owner memory CLI remains available. Codex cannot add dynamic tools through the pinned resume API, and an existing Claude prompt snapshot may ignore a later preamble append. New Oompa-created and explicit provider-switch replacement threads receive the combined binding.
-
Hosted sync, identity enrollment, device pairing, and remote commands are an open beta. The hosted service can change while the beta runs.
-
Hosted memory requires explicit owner enrollment and syncs canonical project memory only. It has no automatic conflict merge, canonical overwrite, identity rebind, hosted-space retirement, local project-memory removal, or local project-memory erasure command. A sticky canonical conflict remains frozen for this release; use working-only reads and writes while preserving both sides for a future reconciliation tool. The browser view is supervisory only and contains no page bodies or peer message and reason text.
-
Claude login, status, session, and switch effects are supported on Linux only. Oompa refuses new Claude provider effects on macOS pending authenticated isolated-Keychain custody and detached-daemon read acceptance. Real authenticated acceptance for the exact Claude Code 2.1.260 pin remains pending. A retained macOS executable now reports the exact pin, but executable discovery and version matching do not prove credential isolation or detached-daemon access.
-
Web account linking is Codex-only and requires local account-linking opt-in on the target machine. Claude login stays on that machine's foreground terminal; Claude Code exposes no Oompa device-code or web-linking protocol.
-
Provider-native threads do not move between providers. A switch creates one target thread and seeds it from the latest retained tail of Oompa's bounded transcript. Pruned history is not reconstructed, a retention gap leaves the unavailable older count unknown, and attachment bytes are never seeded or exported. Pre-admission provider history and pre-v0.6 user turns are also not reconstructed, and the current retention-gap field does not signal those origin gaps. Claude Code exposes no admitted provider-side session listing or read-only observation. Oompa can recover an exact Claude conversation with
--resumeonly after prior-process exit or an already-completed exact process release is proven; ambiguous custody remains fenced and produces no resume effect. -
Attention-email controls are present but delivery is globally inactive in the current production beta because the hosted enablement authority is absent. Local opt-in alone sends nothing.
-
Plugin and connector discovery is read-only. Oompa does not install, enable, authorize, or open OAuth flows.
-
Upgrading over an older install leaves the local state schema pending until the first
oompa daemon start. Until that runs,oompa statusandoompa doctor --offlinereport the pending migration and name both schema versions rather than migrating. Starting the current daemon is a no-downgrade boundary: its journal schema 5 and migrated custody state are not accepted by the older daemon, so never launch the older binary against the same state root afterward. Keep the current binary and hosted recovery endpoints available while any current client remains deployed, then until local journals and outboxes are reconciled and related hosted rows are terminal or expired. -
On a v0.5-to-v0.6 upgrade, that first daemon migration does not infer provider-account authority that v0.5 never recorded immutably. Every affected nonterminal session enters
recovery_required: pending or prepared effects are cancelled, begun effects remain uncertain, scheduled work pauses, pending interactions expire while begun responses become resolution-unknown, and associated Work execution is retired or fenced. Provider threads and local records are not deleted, no provider effect is replayed, and this is not generic automatic recovery. Inspect each affected session; useoompa session abandon <session>only when accepting local terminalization with provider state unknown.
After admission, read the immutable v0.8.5 README, privacy notice, and security policy before installation or use. The currently admitted v0.8.4 README, privacy notice, and security policy retain its release-bound guidance. The superseded v0.8.3 README, privacy notice, and security policy retain its release-bound guidance. The historical canonical predecessor's v0.8.1 README, privacy notice, and security policy retain its release-bound guidance. Report defects through GitHub issues and security concerns through the private process in the security policy.