Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,17 @@
# Changelog

## 2.19.0

- Exposes Desktop Control's UIA operations as ten flat, natively-typed MCP tools (`ui_list_windows`, `ui_inspect_window`, `ui_find_element`, `ui_get_properties`, `ui_get_value`, `ui_screenshot`, `ui_wait_for`, `ui_set_value`, `ui_invoke`, `ui_focus`), registered as native FastMCP tools on the SAME MCP Runtime instance and port (`server:mcp:ki-stack-mcp-runtime`, `127.0.0.1:8021`) Open Terminal's own tools already run on -- no new MCP server, port, or credential. `scroll`/`scroll_into_view`/`send_input`/`send_keys`/raw-`winapp` remain structurally absent, not merely policy-blocked.
- Each `ui_*` tool is a thin transport straight to Desktop Control's own `Invoke-KIStackDesktopControl.ps1`, resolved only at `<TargetRoot>\tools\desktop-control\current\...` with no PATH fallback; every policy decision (Resolve -> Validate -> Act -> Re-observe -> Verify, the secret-context guard, the Target Contract) stays inside Desktop Control unchanged. A business-level result (`SecretContextBlocked`, `PostconditionNotProven`, `ResolverError`, ...) passes through unmodified; only a transport failure (dispatcher missing, invalid JSON) raises a structured MCP tool error.
- Fixes a real, previously undetected delivery gap: mcp-runtime never materialized a persistent, source-parity-checked package tree on a target the way winapp/desktop-control already do. Its generated `Start`/`Stop` scripts hard-coded a path into a transaction-scoped payload staging directory (`state\complete-installer\transactions\<TransactionId>\payload\McpRuntime\...`), and neither `Test-KIMcpRuntime` nor `Test-KICompleteMcpRuntimeCompliant` ever compared deployed content against source -- so a changed payload at an unchanged component VERSION was silently reported `SkippedAlreadyCompliant` instead of being reconciled.
- mcp-runtime now deploys a persistent package tree at `<TargetRoot>\tools\mcp-runtime\current\` (`Get-KIMcpRuntimeInstallPaths`/`Test-KIMcpRuntimeDeployed`/`Test-KIMcpRuntimeSourceParity` in `McpRuntime.psm1`, mirroring `DesktopControl.psm1`'s own functions); `Install-KIMcpRuntime` accepts an externally-owned `-BackupRoot` (the same 2.18.1 Desktop-Control BackupRoot-respect fix applied here); generated starter/stopper scripts reference the persistent package root, never the transaction staging path.
- `Test-KICompleteMcpRuntimeCompliant` gains an `-InstallerPackageRoot` parameter and a new `Test-KICompleteMcpRuntimePayloadParity` function (mirroring `Test-KICompleteDesktopControlPayloadParity`), wired into both `New-KICompletePlan` and the resume-recheck block; the Complete Installer's own `mcp-runtime` step now passes its own `TransactionBackupRoot` slice and runs Install/Upgrade/Repair+Validate via a fresh, isolated `pwsh` process, matching desktop-control's own hardening.
- Corrects `Contracts/COMPONENTS.json`'s dependency order to `python-git -> winapp -> desktop-control -> mcp-runtime` (mcp-runtime now `requires` desktop-control, transitively winapp): its own `ui_*` tools resolve Desktop Control's dispatcher path unconditionally, so a target that provisioned mcp-runtime before Desktop Control would have had that path missing at every `ui_*` call.
- Fixes a real, reproduced `FastMCPDeprecationWarning`: `mcp_launcher.py`'s `OpenAPIProvider` client construction used a plain `httpx.AsyncClient` (aliased as `httpx2`), which fastmcp `4.0.3` (the version actually resolved by the pinned `open-terminal[mcp]==0.11.34`, reproducibly verified) flags as deprecated in favor of a real `httpx2.AsyncClient` -- `httpx2` is a genuine, separate package already resolved transitively by the same pin; no new dependency, no architecture change.
- Bumps mcp-runtime from 0.1.0 to 0.2.0 and Desktop Control from 0.1.0 to 0.1.1 so an existing target actually receives these fixes through a normal Upgrade/Repair run instead of being planned as Skip on unchanged component versions. Complete Installer advances from 2.18.2 to 2.19.0. WinApp stays at 0.6.1.
- Adds dedicated regression coverage: `Test-KIStackMcpRuntimeInstall.ps1` (fresh install deploys the persistent tree; same-version/same-payload Skip; same-version/changed-payload reconciles -- the actual bug fix; missing/extra deployed file reconciles; state never treated as payload; external `-BackupRoot` respected; rollback restores the persistent tree; a failed fresh install leaves no orphaned tree; source/config VERSION mismatch fails closed; Uninstall removes the persistent tree) and `Test-KIStackMcpRuntimePayloadParity.ps1` (the real `Test-KICompleteMcpRuntimePayloadParity`, never a copy, against real `Payload/McpRuntime/*.zip` archives: identical payload/deploy compliant, a changed productive file / a missing deployed file / an extra deployed file / a VERSION mismatch each non-compliant, including the full version-gate contract). `test_ki_desktop_control_tools.py` covers the `ui_*` tool layer itself (26 tests) against the real resolved `open-terminal[mcp]==0.11.34` environment.

## 2.18.2

- Fixes a real, reproduced defect where the central `Start-KIStack.cmd`/`Stop-KIStack.cmd` deployed onto every target called the old cutover core (`modules\cutover\*-KIStack.cmd`) directly instead of `Invoke-KIStackCompleteInstaller.ps1 -Mode Start`/`-Mode Stop`; as a result MCP Runtime and Open Terminal were never started or stopped by the central starters, and the MCP health gate ahead of Open WebUI never applied there.
Expand Down
2 changes: 1 addition & 1 deletion README.de.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ Projektseite und begleitende Artikel: [okami.de – Lokaler KI-Stack](https://ww
| Open Terminal | 0.1.1 | Stabile Komponente; lokaler Tool-/Terminal-Backend-Dienst für OpenWebUI (Filesystem, PowerShell, WSL, Git, Prozess-/Command-Ausführung) unter `http://127.0.0.1:8000`, kein Docker; gestartet über den bestehenden, bereits verwalteten KI-Stack-Python/uv-Vertrag (deterministische Auflösung des verwalteten Pfads, nie ein blindes PATH-Lookup); authentifiziert über einen einzigen persistenten, DPAPI-geschützten lokalen API-Key (nie im Repository, nie geloggt, über Neustarts hinweg unverändert wiederverwendet); Install/Upgrade/Repair/Skip über den Complete Installer, Start/Stop/Status über dieselben zentralen KI-Stack-Lifecycle-Kommandos wie jede andere Komponente; real zielsystemvalidiert, einschließlich eines echten Complete-Installer-Laufs, der es beim zweiten Durchlauf korrekt als `SkippedAlreadyCompliant` meldete. Die Anbindung an OpenWebUI selbst erfordert weiterhin eine einmalige manuelle Tool-Server-Registrierung (siehe „Open Terminal" unten) |
| WinApp | 0.6.1 | Zentral verwaltete Windows-UI-Automation-Basis für Desktop Control; lokaler Komponentenvertrag ohne eigenen Dienst, Port oder Credential |
| Desktop Control | 0.1.0 | Kontrollierte Windows-UIA-Schicht auf WinApp mit Resolve -> Validate -> Act -> Re-observe -> Verify, Policy-/Secret-/Evidence-Prüfung und unabhängig verifizierten Postconditions; MCP-Anbindung in 2.18 noch nicht aktiviert |
| Complete Installer | 2.18.2 | Aktuell veröffentlichtes GitHub-Release `v2.18.2`. Enthält die MCP Foundation aus 2.15, autonomes Local Control aus 2.16, natives persistentes OpenWebUI-Memory aus 2.17 und die Desktop-Control-/WinApp-Basis aus 2.18; außerdem Component Isolation, interne Komponentenversions-Registry, automatische Release Attestation, sicheren OpenWebUI-Credential-Bootstrap, Codex Local `0.2.1`, RAG `0.4.0`, unterstützten Open-Terminal-Fallback, deterministische Builds, PackageSelfTest und die bis zu diesem Release validierten Installer-/Reconciliation-Härtungen. |
| Complete Installer | 2.19.0 | Aktuell veröffentlichtes GitHub-Release `v2.19.0`. Enthält die MCP Foundation aus 2.15, autonomes Local Control aus 2.16, natives persistentes OpenWebUI-Memory aus 2.17 und die Desktop-Control-/WinApp-Basis aus 2.18; außerdem Component Isolation, interne Komponentenversions-Registry, automatische Release Attestation, sicheren OpenWebUI-Credential-Bootstrap, Codex Local `0.2.1`, RAG `0.4.0`, unterstützten Open-Terminal-Fallback, deterministische Builds, PackageSelfTest und die bis zu diesem Release validierten Installer-/Reconciliation-Härtungen. |
| System Cleanup Audit | 1.0.0 | Audit abgeschlossen; Bereinigungsplan wartet auf ausdrückliche Freigabe |

Vollständige Paketquellen liegen im Verzeichnis `package`. Fertige ZIP-Pakete werden als GitHub-Release-Artefakte veröffentlicht und nicht dauerhaft in die normale Git-Historie aufgenommen.
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ Project page and accompanying articles: [okami.de – Lokaler KI-Stack](https://
| Open Terminal | 0.1.1 | Stable component; local tool/terminal backend service for OpenWebUI (filesystem, PowerShell, WSL, Git, process/command execution) at `http://127.0.0.1:8000`, no Docker; started through the existing, already-managed KI-Stack Python/uv contract (deterministic managed-path resolution, never a bare PATH lookup); authenticated with a single persistent, DPAPI-protected local API key (never in the repository, never logged, reused unchanged across restarts); Install/Upgrade/Repair/Skip via the Complete Installer, Start/Stop/Status via the same central KI-Stack lifecycle commands as every other component; real-target validated, including a real Complete Installer run that left it `SkippedAlreadyCompliant` on a second pass. Connecting it to OpenWebUI itself still requires one manual, one-time tool-server registration (see "Open Terminal" below) |
| WinApp | 0.6.1 | Centrally managed Windows UI Automation base for Desktop Control; local component contract with no runtime service, port, or credential of its own |
| Desktop Control | 0.1.0 | Controlled Windows UIA layer on top of WinApp with Resolve -> Validate -> Act -> Re-observe -> Verify, policy/secret/evidence checks, and independently verified postconditions; MCP wiring is not yet activated in 2.18 |
| Complete Installer | 2.18.2 | Current published GitHub Release `v2.18.2`. Includes the 2.15 MCP Foundation, 2.16 autonomous Local Control, 2.17 native persistent Open WebUI Memory, and the 2.18 Desktop Control / WinApp foundation; also carries Component Isolation, the internal component version registry, automatic Release Attestation, secure OpenWebUI credential bootstrap, Codex Local `0.2.1`, RAG `0.4.0`, Open Terminal fallback support, deterministic builds, PackageSelfTest, and the validated installer/reconciliation hardening accumulated through this release. |
| Complete Installer | 2.19.0 | Current published GitHub Release `v2.19.0`. Includes the 2.15 MCP Foundation, 2.16 autonomous Local Control, 2.17 native persistent Open WebUI Memory, and the 2.18 Desktop Control / WinApp foundation; also carries Component Isolation, the internal component version registry, automatic Release Attestation, secure OpenWebUI credential bootstrap, Codex Local `0.2.1`, RAG `0.4.0`, Open Terminal fallback support, deterministic builds, PackageSelfTest, and the validated installer/reconciliation hardening accumulated through this release. |
| System Cleanup Audit | 1.0.0 | Audit completed; cleanup plan pending explicit approval |

The repository tracks complete package sources. Built ZIP files are published as GitHub Release assets rather than committed to normal Git history.
Expand Down
4 changes: 2 additions & 2 deletions docs/de/KI-Stack-Betriebs-und-Benutzerhandbuch.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# KI-Stack 2.18.2 – Betriebs- und Benutzerhandbuch
# KI-Stack 2.19.0 – Betriebs- und Benutzerhandbuch

## Normalbetrieb

Expand Down Expand Up @@ -228,7 +228,7 @@ Eine erstmalige WSL2-Aktivierung auf einer wirklich leeren Maschine kann einen W
- **SearXNG scheint nicht erreichbar**: in der WSL-Debian-Instanz `systemctl status ki-stack-searxng uwsgi nginx valkey-server` prüfen; dass entweder `ki-stack-searxng` oder `uwsgi` aktiv und auf Port 8888 gesund ist, ist ein gültiger, erwarteter Zustand.
- **Ein OpenWebUI-API-abhängiger Schritt meldet einen Credential-bezogenen Pending-/Blocked-Zustand**: `Test-KIStackOpenWebUICredential.ps1` ausführen. Existiert kein gültiges Credential, dieses mit `Initialize-KIStackOpenWebUICredential.ps1` bootstrappen; nicht auf einen separat gepflegten temporären API-Key zurückfallen.

Die letzte vollständige, erfolgreiche, reale Greenfield-Installation auf einem leeren Zielsystem wurde mit Complete Installer 2.4.0 verifiziert. Die späteren Releases bis 2.18.2 ergänzen Regression-, Paket-, Komponenten-, Upgrade-/Reconcile- und Real-Target-Nachweise, behaupten jedoch keinen neueren vollständigen Windows-Greenfield-Lauf auf einem leeren Zielsystem.
Die letzte vollständige, erfolgreiche, reale Greenfield-Installation auf einem leeren Zielsystem wurde mit Complete Installer 2.4.0 verifiziert. Die späteren Releases bis 2.19.0 ergänzen Regression-, Paket-, Komponenten-, Upgrade-/Reconcile- und Real-Target-Nachweise, behaupten jedoch keinen neueren vollständigen Windows-Greenfield-Lauf auf einem leeren Zielsystem.

## Bekannte offene Punkte

Expand Down
8 changes: 4 additions & 4 deletions docs/de/KI-Stack-Installationsanleitung.md
Original file line number Diff line number Diff line change
@@ -1,13 +1,13 @@
# KI-Stack Complete Installer 2.18.2 – Installation und Upgrade
# KI-Stack Complete Installer 2.19.0 – Installation und Upgrade

Diese Anleitung gilt für das aktuell veröffentlichte Paket `KI-Stack-Complete-Installer-v2.18.2.zip`. Die letzte vollständige, erfolgreiche, physische Greenfield-Installation auf einem leeren Zielsystem wurde mit Version 2.4.0 durchgeführt und verifiziert. Die späteren Releases bis einschließlich 2.18.2 wurden durch Repository-Regressionstests, deterministische Paket-Builds, komponentenspezifische Acceptance-Tests und reale Upgrade-/Reconciliation-Läufe validiert, wie für die jeweiligen Releases dokumentiert; ein neuerer vollständiger Windows-Greenfield-Lauf auf einem leeren Zielsystem wird hier ausdrücklich nicht behauptet.
Diese Anleitung gilt für das aktuell veröffentlichte Paket `KI-Stack-Complete-Installer-v2.19.0.zip`. Die letzte vollständige, erfolgreiche, physische Greenfield-Installation auf einem leeren Zielsystem wurde mit Version 2.4.0 durchgeführt und verifiziert. Die späteren Releases bis einschließlich 2.19.0 wurden durch Repository-Regressionstests, deterministische Paket-Builds, komponentenspezifische Acceptance-Tests und reale Upgrade-/Reconciliation-Läufe validiert, wie für die jeweiligen Releases dokumentiert; ein neuerer vollständiger Windows-Greenfield-Lauf auf einem leeren Zielsystem wird hier ausdrücklich nicht behauptet.

## Download und SHA-256

Lade ZIP und `KI-Stack-Complete-Installer-v2.18.2.zip.sha256` aus demselben GitHub-Release. Der verbindliche Hash steht ausschließlich im Sidecar und in der GitHub-Releasebeschreibung.
Lade ZIP und `KI-Stack-Complete-Installer-v2.19.0.zip.sha256` aus demselben GitHub-Release. Der verbindliche Hash steht ausschließlich im Sidecar und in der GitHub-Releasebeschreibung.

```powershell
$zip = '.\KI-Stack-Complete-Installer-v2.18.2.zip'
$zip = '.\KI-Stack-Complete-Installer-v2.19.0.zip'
$expected = ((Get-Content "$zip.sha256" -Raw) -split '\s+')[0].ToLowerInvariant()
$actual = (Get-FileHash -LiteralPath $zip -Algorithm SHA256).Hash.ToLowerInvariant()
if ($actual -ne $expected) { throw 'SHA-256 stimmt nicht überein.' }
Expand Down
2 changes: 1 addition & 1 deletion docs/de/KI-Stack-Manuelle-Modellbereitstellung.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Optionale Modellbereitstellung und Preload

Complete Installer 2.18.2 lädt fehlende Modelle einschließlich des ausschließlich für Embeddings verwendeten Nomic Q4_K_M automatisch aus den revisionsgebundenen Quellen des zentralen Modellmanifests. Eine manuelle Bereitstellung ist keine Installationsvoraussetzung.
Complete Installer 2.19.0 lädt fehlende Modelle einschließlich des ausschließlich für Embeddings verwendeten Nomic Q4_K_M automatisch aus den revisionsgebundenen Quellen des zentralen Modellmanifests. Eine manuelle Bereitstellung ist keine Installationsvoraussetzung.

Ein optionaler Cache oder `ExternalModels`-Preload kann Bandbreite sparen. Der Installer akzeptiert eine Datei ausschließlich nach Prüfung von Dateiname, exakter Größe und vollständigem SHA-256. Eine gültige Zieldatei wird wiederverwendet und nicht erneut geladen. Unterbrochene Downloads bleiben fortsetzbar; eine falsche Größe oder Prüfsumme führt zu `Failed`.

Expand Down
2 changes: 1 addition & 1 deletion docs/de/KI-Stack-Modell-Downloadanleitung.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Automatischer Modell-Downloadvertrag

Dieser Vertrag gilt für das aktuell veröffentlichte Complete-Installer-Release 2.18.2.
Dieser Vertrag gilt für das aktuell veröffentlichte Complete-Installer-Release 2.19.0.

Der Complete Installer benötigt auf einem leeren Zielsystem keine manuell bereitgestellten Modell- oder Payloaddateien. Die neun Visualartefakte für Z-Image Turbo und WAN2.2 T2V 14B mit beiden LightX2V-4-Step-LoRAs, die beiden Heretic-Dateien und das ausschließlich für Embeddings verwendete `nomic-embed-text-v1.5.Q4_K_M.gguf` besitzen revisionsgebundene Downloadquellen, exakte Bytegrößen und SHA-256-Werte in `tools/models-workflows/current/Manifests/models.manifest.json`.

Expand Down
Loading
Loading