v0.9.3

Hmbown/Codewhalev0.9.3Jul 31, 2026by github-actions[bot]

AI Summary

Codewhale v0.9.3 ships DeepSeek V4 Flash as a first-class route and reduces the agent-facing tool surface to canonical actions. It hardens credential and authorization boundaries.

Key Highlights

  • Native `deepseek-v4-flash` support over DeepSeek's Responses API.
  • Canonical action tools (`Bash`, `File`, `Run`) replace legacy aliases.
  • Per-turn `max_tool_calls` enforcement at the engine admission gate.
  • Pipe-only `codewhale auth print-api-key` handoff.
  • Runtime-contract ratchets that name drift instead of allowing large ownership surfaces to grow.

Breaking Changes

  • Removed legacy callable aliases (`exec_shell`, `run_shell_command`, `read_file`, `write_file`, `list_dir`, `grep_files`, `file_search`).
  • Removed the bundled PDF parser dependency chain.

New Features

  • Native DeepSeek V4 Flash support.
  • Canonical action schemas.
  • `apply_patch` support for DeepSeek Responses.
  • Tool-call budget enforcement.
  • Authorization-order contract documentation.

Full Release Notes

> **Codewhale** is the public product from Shannon Labs. The `codewhale`
> command, npm package, and release-asset names remain lowercase technical
> identifiers. The legacy npm package `deepseek-tui` is deprecated and
> receives no further releases. Users coming from v0.8.x legacy `deepseek` /
> `deepseek-tui` names should migrate with `docs/REBRAND.md`.

## Install

### Recommended — npm (one command, all three entrypoints)

```bash
npm install -g codewhale
```

The wrapper downloads the matched `codewhale`, `codew`, and `codewhale-tui`
binaries from this Release and places them in the same directory.

### Docker / GHCR

```bash
docker run --rm -it \
  -e DEEPSEEK_API_KEY="$DEEPSEEK_API_KEY" \
  -v codewhale-home:/home/codewhale/.codewhale \
  ghcr.io/hmbown/codewhale:v0.9.3
```

The image ships the `codewhale` dispatcher, `codew` shim, and `codewhale-tui` runtime. The `latest` tag is also updated on release.

### Cargo (Linux / macOS)

```bash
cargo install codewhale-cli codewhale-tui --locked
```

Both crates are required — `codewhale-cli` produces the `codewhale` dispatcher and `codew` shim, while `codewhale-tui` produces the interactive runtime that the dispatcher delegates to. Installing only one crate will fail at runtime with a `MISSING_COMPANION_BINARY` error.

### Manual download — platform archives (recommended)

Each archive below contains the `codewhale` dispatcher, `codew` shim, and `codewhale-tui` runtime, plus an install script:

| Platform | Archive | Install script |
|---|---|---|
| Linux x64 | `codewhale-linux-x64.tar.gz` | `install.sh` |
| Linux ARM64 | `codewhale-linux-arm64.tar.gz` | `install.sh` |
| Android ARM64 (Termux) | `codewhale-android-arm64.tar.gz` | `install.sh` |
| macOS x64 | `codewhale-macos-x64.tar.gz` | `install.sh` |
| macOS ARM | `codewhale-macos-arm64.tar.gz` | `install.sh` |
| Windows x64 (installer) | `CodeWhaleSetup.exe` | NSIS setup |
| Windows x64 | `codewhale-windows-x64.zip` | `install.bat` |
| Windows x64 (portable) | `codewhale-windows-x64-portable.zip` | — |
| Windows ARM64 | `codewhale-windows-arm64.zip` | `install.bat` |
| Windows ARM64 (portable) | `codewhale-windows-arm64-portable.zip` | — |

**Unix (Linux / macOS):**
```bash
tar xzf codewhale-<platform>.tar.gz
cd codewhale-<platform>
./install.sh
```

**Windows:**
- For the installer path, run `CodeWhaleSetup.exe`; it installs `codewhale.exe`, `codew.exe`, and `codewhale-tui.exe` under `%LOCALAPPDATA%\Programs\CodeWhale\bin` and adds that directory to the current-user PATH.
- Extract the archive for your machine: `codewhale-windows-x64.zip` or
  `codewhale-windows-arm64.zip`
- Run `install.bat` (copies to `%USERPROFILE%\bin`)
- Add `%USERPROFILE%\bin` to your PATH

The **portable** Windows archive skips the install script — extract and run from any directory. The NSIS installer is currently unsigned and may trigger Windows SmartScreen until a signing certificate is wired into the release pipeline.

Each platform also has **bare, unarchived** binaries attached below (`codewhale-<platform>`, `codew-<platform>`, and `codewhale-tui-<platform>`) — the npm wrapper and the in-app `codewhale update` download the matched runtime binaries, whereas the `.tar.gz` / `.zip` archives above are the recommended manual download and additionally bundle an install script. The legacy npm package `deepseek-tui` is deprecated and is not republished. For migration from v0.8.x legacy binary names, see `docs/REBRAND.md`.

### Verify (recommended)

Download the checksum manifests from this Release and verify:

```bash
# Linux — archive bundles
sha256sum -c codewhale-bundles-sha256.txt --ignore-missing

# Linux — individual binaries
sha256sum -c codewhale-artifacts-sha256.txt --ignore-missing

# macOS
shasum -a 256 -c codewhale-bundles-sha256.txt --ignore-missing
shasum -a 256 -c codewhale-artifacts-sha256.txt --ignore-missing
```

## What's in v0.9.3

This is the Codewhale v0.9.3 source candidate. It is not a published release
until the matching tag, packages, checksums, and release assets exist.

DeepSeek V4 Flash is now a first-class Codewhale route, and the agent-facing
tool surface has been reduced to the canonical action tools that current
models actually need. This release also hardens credential, authorization,
durability, compaction, and macOS File Provider boundaries while deleting
stale runtime and dependency surface.

### Added

- Native `deepseek-v4-flash` support over DeepSeek's Responses API, including
  stateless reasoning-item replay, semantic SSE terminal events, structured
  function calls and outputs, `apply_patch`, and model-aware wire-format
  selection. Exact current Flash IDs use Responses; future direct
  `deepseek-vN-*` model IDs inherit that route conservatively, while custom
  DeepSeek-compatible endpoints retain Chat Completions unless configured
  otherwise.
- A pipe-only `codewhale auth print-api-key` handoff for explicitly selected
  providers. It shares Codewhale's home-scoped credential authority, refuses
  terminal output, and prevents sentinel placeholders from becoming live
  credentials.
- Per-turn `max_tool_calls` enforcement at the engine admission gate, plus a
  named-file write scope with a separate read seam. The runtime now rejects
  over-budget calls before execution and keeps the operator's write boundary
  explicit (#4415).
- Runtime-contract, source-structure, and persistence-backlog ratchets that
  name drift instead of allowing large ownership surfaces to grow silently
  (#3921, #4785).

### Changed

- Model-visible built-ins now use the canonical `Bash`, `File`, and `Run`
  action schemas. `apply_patch` remains available as the one direct custom
  edit tool supported by DeepSeek Responses. The bundled stop-ship workflow,
  Fleet fixtures, shell shortcut, and engine tests use the same canonical
  vocabulary.
- Canonical `File { action: "write" }` requests now pass through the same
  semantic repo-law checks as the former write path. Approval, Full Access,
  and workflow execution cannot bypass the repository safety floor by choosing
  the canonical schema.
- Codewhale home resolution is shared across the CLI, TUI, state, and secret
  stores. `doctor` is offline by default, distinguishes credential source from
  availability, and reports one consistent path snapshot.
- Durable runtime event writes are serialized across simultaneous processes,
  blocking history waits move off async workers, and provider quota exhaustion
  remains typed and retryable through compaction (#4522).
- Skill discovery caches the merged catalog behind watched-mtime validation;
  large skill, engine, subagent, UI, and ambient-ocean test blocks now live in
  owned test seams.
- Reasoning summaries stay in the user's language, complete jellyfish
  silhouettes relocate around transcript text, and cached ocean frames include
  their palette identity (#4807).
- The authorization-order contract now documents and tests how modes, hooks,
  permission rules, safety floors, repo law, approvals, and sandboxing compose
  (PR #4980).

### Fixed

- macOS sandbox extensions cover CloudStorage/File Provider workspaces without
  broadening unrelated paths; thanks @Watcher24 for the #4085 report and
  reproduction.
- Foreground shell state detaches before steering, so an interrupted command
  cannot keep owning the composer (PR #4979).
- MCP application-level failures and malformed error envelopes fail closed
  instead of looking like successful tool output.
- Optional PDF failures are truthful and PDF classification no longer misses
  supported inputs.
- Bracketed-paste contents are redacted from traces, and credential diagnostics
  never treat placeholder sentinels as usable keys.

### Removed

- The legacy callable aliases `exec_shell`, `run_shell_command`, `read_file`,
  `write_file`, `list_dir`, `grep_files`, `file_search`, and the duplicate
  Work/RLM registrations. Historical transcript and policy semantics remain
  readable, but new model turns receive only the canonical action surface.
- The bundled PDF parser dependency chain, replacing it with the smaller
  optional extraction boundary tracked by #4382.

## Contributors

- [Turisla](https://github.com/greyfreedom) (`@greyfreedom`) documented and
  locked the authorization-order contract in PR #4980.
- [Nightt](https://github.com/nightt5879) (`@nightt5879`) fixed foreground
  shell detachment before steering in PR #4979.
- [Watcher24](https://github.com/Watcher24) (`@Watcher24`) provided the macOS
  File Provider report and reproduction for #4085.
- [Fred Leitz](https://github.com/fleitz) (`@fleitz`) retains required
  source-candidate credit for the canonical `Bash` workspace fix from PR #4673
  and issue #4674.

See [CHANGELOG.md](https://github.com/Hmbown/CodeWhale/blob/main/CHANGELOG.md) for full notes and [docs/CHANGELOG_ARCHIVE.md](https://github.com/Hmbown/CodeWhale/blob/main/docs/CHANGELOG_ARCHIVE.md) for older releases.