Agenvoy v1.0.25 Release Notes
v1.0.24 -> v1.0.25
Summary
Command execution now runs without networking unless a call asks for it, and read-only inspection folds back into run_command behind a much larger allowlist. Copilot models size their own context window from the provider instead of a fixed guess, and subagent tokens stop counting against the session that dispatched them.
翻譯
指令執行預設不連網,需要連線由該次呼叫指定;唯讀檢查收回 run_command,改以大幅擴充的白名單自動放行。Copilot 模型改向 provider 取得自己的 context window,不再沿用固定估值;subagent 的 token 也不再記在派工的 session 名下。
Changes
FEAT
- Command execution runs with networking denied and opens it per call through
network: true, which always raises a confirmation and never matches the read-only allowlist (@pardnchiu) [6c497d7, 5856611, 13afbc3] - Copilot models resolve their context window from
api.githubcopilot.com/modelswith a non-blocking fetch, a 24-hour cache and an in-flight guard, falling back to 128K until the first result lands (@pardnchiu) [0673b3f] - Execution events carry the per-request context token count, so context pressure is measured from the last request rather than the running total (@pardnchiu) [0673b3f]
翻譯
- 指令執行預設禁網,由該次呼叫的
network: true開啟;帶了就一律跳確認,也不再比對唯讀白名單 - Copilot 模型改從
api.githubcopilot.com/models取得自己的 context window,非阻塞拉取、24 小時快取並避免重複請求,結果回來前先用 128K - 執行事件帶上單次請求的 context token 數,context 壓力改以最後一次請求衡量,而非整輪累計
REFACTOR
run_command_readonlyis gone; read-only auto-approval moves intorun_command, matched against the allowlist by binary plus up to two subcommands, and cancelled when any argument resolves to a sensitive path (@pardnchiu) [13afbc3, 5856611]- The read-only allowlist grows from 116 to 410 entries, covering git, language toolchains, package queries, containers and system inspection, with anything that writes, hangs, leaks a secret or needs networking left out (@pardnchiu) [13afbc3, 5856611]
- Subagent token usage is no longer attributed to the parent session, and
ExecWithSubagentdrops theparentSessionIDparameter it only used for that (@pardnchiu) [0673b3f]
翻譯
- 移除
run_command_readonly,唯讀自動放行併回run_command:以二進位加最多兩段子命令比對白名單,argv 任一參數落在敏感路徑即取消放行 - 唯讀白名單自 116 條擴充至 410 條,涵蓋 git、語言工具鏈、套件查詢、容器與系統檢視;會寫入、不退出、吐出 secret 或需要網路者一律不收
- subagent 的 token 用量不再記到父 session,
ExecWithSubagent也移除只為此存在的parentSessionID參數
Scope
internal/tools/— FEAT, REFACTOR (runCommand.go,runCommandReadonly.go,register.go,interactive/pkgManage.go)internal/agents/exec/compact/— FEAT (copilotLimit.go,checkThreshold.go)internal/agents/exec/— FEAT, REFACTOR (execute.go,execWithSubagent.go,toolCall.go)internal/agents/types/— FEAT (event.go)internal/runtime/tui/— FEAT, UPDATE (multiple files)internal/utils/— UPDATE (event.go,utils.go)configs/jsons/— REFACTOR (read_only_command.json)doc/,README.md— DOC (multiple files)
Generated by SKILL