ยทholaryn-owner

Holaryn Agent v0.12.6 Nightly: encrypted memory search and task readiness checks

Holaryn Agent v0.12.6 Nightly encrypts the search vectors of an encrypted memory, checks whether a task can run before you start it, and asks for your approval before plugin hooks run. It is a development release for testing and feedback. It also includes the fixes from an internal security review in September. Several changes can stop something that worked in v0.12.5, so read the "Before you upgrade" section first. The v0.12.6 Nightly release record has the downloads.

New features since v0.12.5

  • An encrypted memory stores its search vectors encrypted and searches them through an index kept only in RAM. Vectors sent to Qdrant stay unencrypted there.
  • An older memory file is searched by keywords only until you reindex it with holaryn memory reindex or the Memory settings page. With the host and every holaryn run session stopped, the reindex also erases the old unencrypted data and reports verified. Backups made earlier still hold that data.
  • holaryn doctor --task <preset> checks whether a task can run on this installation and lists safe repairs.
  • Pair requests now expire after 15 minutes, and pairing is rate limited. If the peer registry becomes unusable, discovery stops within 10 seconds and resumes after a repair.
  • Artifacts open in a dialog in the browser and the desktop app alike, and a newer version is announced without moving focus.
  • Canvas HTML islands, the small visuals the agent can embed in a canvas, are now static, so scripts never run, and animated ones get a "Pause animation" toggle.
  • Opening an address the host cannot serve now shows a short error page in English, Spanish or French.
  • Also new are memory retention dates, holaryn model explain, presets for OpenCode Zen, Abacus.AI RouteLLM and Nous Portal, checked offline only, and two experimental features, off by default.

Changes to existing features

Changes that can stop something you rely on

  • Encrypted installations move to a new format the first time this version opens them. The move is one way: older Holaryn Agent versions can no longer open them.
  • Provider, Holaryn Agent Communication Protocol (HACP), Qdrant, Ollama and memory database addresses can no longer hold a user name, password, query or fragment, or a host name with an underscore. Enter an international host name in its Punycode form, which starts with xn--. Saved connections that break these rules are not used until corrected.
  • Changing a connection's host, port or scheme clears its stored API key.
  • Clients that carry a credential or your content ignore proxy and certificate settings found only in the environment, unless HOLARYN_TRUST_ENV=1 is set.
  • OpenTelemetry export now ignores OTEL_EXPORTER_OTLP_HEADERS and the standard client certificate variables.
  • Plugin hooks stay inactive until you approve their exact content on the "Plugins & Skills" page in Settings, and pause again when it changes. Project skills in .holaryn/skills/ need a content review before the model sees them.
  • Holaryn Agent's git features now need Git 2.38 or later.
  • The user guide covers further changes for administrators, such as hook environments and service installation.

Other changes

  • An approval now covers exactly the arguments the dialog showed, and a call whose arguments change while it waits is refused.
  • The local listener closes idle or slow connections after 20 seconds, answers 503 beyond its connection limit, and ignores X-Forwarded-For and Forwarded headers.
  • When chat updates stop, the notice says "Chat updates stopped" instead of promising a reconnect.

Bug fixes

The skill folder regression in the "Known issues" section is not fixed in this build.

Accessibility

  • After you confirm a plugin's consent dialog, focus returns to that plugin's switch, and a screen reader reads its name and state.
  • After a host restart, an open tab says its sign-in has expired and how to continue. It keeps your draft, the transcript and focus.
  • "Retry connection" no longer reloads the page, so your unsent draft and staged attachments stay.
  • While the voice panel listens, "Connection lost; reconnecting." is now always followed by "Reconnected.", and other recoveries go to the Status panel instead of being spoken.
  • An unreadable peer registry no longer breaks Settings. The Networking page shows it as one alert with a "Check again" button, in English, Spanish and French.

Stability and reliability

  • On Windows, a foreground holaryn serve now stops cleanly on Ctrl+Break or when its console closes.
  • Stopping a local model server that Holaryn Agent started now ends its whole process tree, except for the launchers in the "Known issues" section.

Known issues

  • holaryn skill install refuses a local skill folder whose path passes through a symbolic link or junction, such as /tmp on macOS, which v0.12.5 allowed. Give the real path instead, such as /private/tmp/. Tracked as SA-662.
  • Holaryn Agent can lose track of a local model runtime whose launcher hands over to another program, such as a macOS framework Python launcher, an env shebang or a version-manager shim. A stop can then report it stopped while it still runs. The built-in Ollama and llama.cpp launches are not affected. There is no workaround yet. Tracked as SA-663.
  • Pressing Tab into a canvas island that is still loading can leave focus on the page with nothing announced. Press Tab again to reach the island. A fix has been designed. Tracked as SA-664.

This build also has these limits:

  • holaryn steer exits 0 once a directive is queued, even if the run later discards it.
  • Credentialed sign-in to a real third-party Model Context Protocol (MCP) server has not been tested.
  • The built-in web fetcher cannot fetch through a proxy, so list its hosts in NO_PROXY.
  • The Holaryn Agent service still runs as LocalSystem on Windows and as root on Linux and macOS, with those rights for its tools.
  • The release evidence lists remaining third-party advisories, including one for glib on Linux.

Before you upgrade

Three things can stop an upgrade cold.

  • If you use encrypted state, stop every older Holaryn Agent process, then upgrade the desktop app and any separately installed holaryn command together. Reindex your memory afterwards.
  • Correct any saved address that breaks the new address rules, and rotate any credential that was ever part of one.
  • If your network needs a proxy or a private certificate authority, set HOLARYN_TRUST_ENV=1 for the Holaryn Agent host and restart it.

The user guide for this build has the details.

Downloads and verification

The desktop app reports version 0.12.6-dev.3976+g563af09, built from source revision 563af099deba52fa028e46d19b6b0544bd3eda48.

  • The Windows x64 setup, app, bundled host and uninstaller are Authenticode-signed through SSL.com and timestamped. The signature details show the name SYNERGENTIC INC.
  • The macOS disk image is for Macs with Apple silicon. The app is signed with an Apple Developer ID and notarized by Apple.
  • The Linux AppImage and Debian package were built on Ubuntu 22.04.

The Windows setup, the macOS update archive and both Linux packages carry updater signatures. On the Nightly channel, the SHA-256 checksum file, the software bill of materials and the provenance record ship unsigned. They describe the release but do not prove where a file came from.

Trying this Nightly

Nightly builds change often and are meant for evaluation and early access. This is not a Beta or Stable release. The final manual release validation, with its screen-reader, native and soak checks, has not yet run against this build.

From v0.12.5, check for this release under Settings, then System, then Software updates. If the updater does not offer it, download and run the new installer. Your existing Holaryn Agent state is kept. You choose your update channel on the same page.

For help, or to report a problem with this Nightly, start from the Support page. Keep passwords, keys and private data out of any report. Send a suspected security vulnerability privately to security@synergentic.tech.