Changelog
What changed for someone using agentctl. The reasons, measurements and
findings behind each item are in the numbered docs/ stream.
Versioning. 0.x while commands and output may still change. A release
is a git tag; nothing between tags is a release.
Unreleased
Nothing yet.
0.3.1 (2026-10-05)
Three rough edges from the first real run of 0.3.0 (docs/0056).
Fixed
- The report no longer lists
__pycache__and other files that running Python leaves behind. It counts them in one line, and--acceptno longer writes bytecode of its own. - The agent is told which command runs Python in its shell when
pythonis not it, instead of finding out fromcommand not found. - The OpenHands SDK's INFO log lines no longer interrupt agentctl's output;
set
LOG_LEVEL=INFOto see them.
0.3.0 (2026-10-04)
The first release. Everything in 0.3.0rc1 below, plus:
Fixed
- A policy's effect rules now hold for every effect class (
docs/0055).external: blockused to compile and then allow everything, andrequire_human_approvalwas enforced fordestructiveonly. Nowblockrefuses the action,require_human_approvalasks (or queues), andallowondestructivestops the question.--allow-destructiveno longer overrides a policy'sblockor approval rule.
0.3.0rc1 (2026-10-04)
The release that makes it usable by someone other than its author
(docs/0043 to docs/0054). A release candidate: the first upload to PyPI.
Added
- Published on PyPI as
handcode(agentctlwas taken). The command is stillagentctl, and is also installed ashandcode; the import package is stillagentctl(docs/0051Stage 1). agentctl demo: a real crash duplicates a commit in plain OpenHands, and agentctl prevents it. No key, no network, $0 (docs/0050).agentctl init: one key, checked with one request, and the model that answered recorded as your default (docs/0047).agentctl runneeds no flags: the model comes from--model, thenAGENTCTL_MODEL, then~/.agentctl/config.toml, then your first provider.- An end-of-run report: what was checked, what changed, what it used, what
needs you.
--accept "<command>"runs your tests after the agent and reports PASS or FAIL. The exit code follows the report (docs/0048). agentctl status,agentctl resume, and a run index, so follow-up commands need no path or id (docs/0049).agentctl dashreads it too.- Ctrl-C pauses after the current step;
agentctl resumecontinues. - Approvals without a terminal: a dangerous action is queued, and answered
with
agentctl approve/agentctl deny(docs/0049). --wait 30mwaits out a rate limit and resumes.agentctl run --poolandagentctl proxy up|status|down: a LiteLLM pool in an environment of its own; no proxy extra in your install (docs/0047).agentctl --version.- A container image (
Dockerfile; published toghcr.io/csdeepak/handcodewith each release). Only the mounted repository is reachable, and the pool's environment is built in (docs/0051Stage 2). - A GitHub Action (
csdeepak/HandCodeandcsdeepak/HandCode/publish): type a task in the Actions tab, get a pull request whose description is the report. Two jobs, so the one running the agent holds no token that can write. Started by a person only, not by issues yet (guide/github-action.md,docs/0053). agentctl run --report-json PATH: the report, for a program to read.- A user guide in
guide/, also built as a website (website/build.py), published at https://csdeepak.github.io/HandCode/ (docs/0054).
Changed
- Installing software into your environment (
pip install,npm install -g,apt,brew, …) asks first, or queues when nobody is at a terminal. Installs into a venv inside the repository do not, and nothing asks in the container (docs/0052). - An identical command the agent re-runs after seeing its result now runs
(the edit, test, re-test loop). It used to get stale output or be blocked
(
docs/0045). --resumeno longer takes over a run that is still alive. A crashed one is taken over without asking;--takeoveroverrides (docs/0046).- Costs say what they can be trusted for. Free-tier calls are a known $0, not
list price and not "unknown"; per-conversation cost works through the pool
(
docs/0048). - A workspace's
.agentctl/is ignored by git automatically. - Advice about extra keys points to a second provider. Several accounts at one provider are unverified as extra quota, and may break that provider's terms.
Fixed
doctorno longer blocks a working install on a package version, andkeys --checkno longer reports a working key as unable to serve because one model left the catalogue (docs/0044).verify.pyskips, rather than fails, the proxy checks when the proxy extra is not installed.- A superseded process can no longer start a new effect (
docs/0046). - Opening a ledger right after its holder was killed no longer fails on
Windows with "disk I/O error" (
docs/0046). 2>/dev/nullno longer asks for confirmation as a write outside the workspace (docs/0047).
0.2.0a0
The correctness core: the effect ledger, the gate, three seams, probes, record
and replay, policy, and the nine-point chaos suite (docs/0001 to
docs/0042). Development snapshot; not released to PyPI.