Skip to content

Catalyst Dev — Change Log

12.53.0

Aug 12, 2026

Daemon Reliability & Pipeline Hardening

Daemon logs are now rotated on restart instead of truncated — the previous run’s output is preserved as daemon.log.1 through .5 (configurable via CATALYST_LOG_RETAIN) so you have evidence when diagnosing a wedge. Two daemon-killing bugs are also fixed: an async EAGAIN spawn failure that could take down execution-core, and a zsh local path variable that silently emptied $PATH and caused phantom artifact_not_gate_visible phase failures. Automated merges from linked worktrees no longer fail with fatal: 'main' is already used by worktree — the merge now splits into a REST merge and a checkout-free remote ref delete.

PRs

  • dev: CTL-1755 preserve daemon logs across restarts (#3231) (9acf3c5)
  • dev: CTL-1774 — thread appendDelegateEvent through delegate-first routing seam (#3280) (4cb5ca0)
  • dev: CTL-1789 — emit phase.advance.applied and attribute who asserted each terminal (#3268) (52984b6)
  • dev: bound board-health delegate-lands grace (#3206) (6ec4226)
  • dev: CTL-1764 handle async spawn ‘error’ so EAGAIN cannot kill the daemon (#3230) (3a03870)
  • dev: CTL-1777 — fix write_phase_thoughts_doc under zsh (rename local path vars + static lint) (#3238) (05a10a5)
  • dev: CTL-1791 — delete claim.mjs dispatch-claim, the high-water+1 generation the CTL-736 fence forbids (#3269) (3a9025f)
  • dev: CTL-56 — worktree-safe merge (drop —delete-branch, checkout-free ref cleanup) (#3277) (f9690b5)

12.52.0

Aug 10, 2026

Durable Phase Artifacts & Cross-Host Recovery

Six phase skills now write durable thought docs to the shared repo before emitting complete, enabling reconstruct-ticket-state.mjs to rebuild any in-flight ticket’s history from scratch on a fresh host. The sync gate rolls out behind catalyst.phaseArtifactSync.mode — default off is behavior-identical to today; set shadow to observe without blocking, or enforce to make sync failures fatal. This release also fixes orphaned worker directories that held tickets in-flight indefinitely, corrects claude-accounts.env sourcing on bg-executor nodes where it was silently never loading, and resolves a ps truncation bug that caused the forwarder identity check to fail on Linux CI.

PRs

  • dev: CAT-31 resolve ticket worktrees before dispatch (#3141) (5b40163)
  • dev: CTL-1490 — durable phase artifacts + cross-host ticket-state reconstruction (#2697) (797dfdc)
  • dev: CAT-24 reclaim empty and signal-less worker directories (#3176) (228fb4f)
  • dev: CAT-90 — source claude-accounts.env unconditionally, not gated on CATALYST_EXECUTOR (#3186) (27670c7)
  • dev: confirm SIGKILL reap before returning in forward-stop (CTL-1502) (#3172) (ec9f51b)
  • dev: CTL-1701 move synthetic test pids above the real-pid ceiling (#3197) (c051400)
  • dev: unbreak main — stop ps truncating the forwarder identity check (#3196) (e8ab2e4)

12.51.0

Aug 10, 2026

Triage Aging PRs & Orphaned Worktree Adoption

A new triage-aging-prs skill encodes a proven method for driving a stale PR backlog to zero — including traps around fork CI secrets, ruleset queries, and reviewer signal interpretation that aren’t obvious until they’ve cost you time. Operators also get a new adopt command for claiming orphaned worktrees. Several main-branch test and lint failures that were blocking every open PR from reaching a green check set are fixed as well.

PRs

  • dev: add triage-aging-prs skill (#3173) (0fa37c9)
  • dev: CTL-1642 operator adopt command for orphaned worktrees (#3175) (8180c80)
  • dev: CAT-47 reconcile orphan-stale recovery seams (#3169) (97d63a4)
  • dev: clear the 7 lint errors red on main in pr-status-backfill (#3179) (4d43b2e)
  • dev: unbreak main — inject the skills-dir seam in the install-profile tests (#3180) (90a9967)

12.50.0

Aug 09, 2026

Skills-Dir Plugin Loading & Reliability Fixes

Plugins now load exclusively from a live ~/catalyst/plugin-source checkout via ~/.claude/skills/ symlinks, retiring the version-keyed marketplace cache that caused merged changes to stay invisible until the next release bump. This release also fixes the otel-forward DLQ amplification loop (terminal 4xx errors now drop cleanly instead of cycling), ensures worktree salvage snapshots unpushed commits before any destructive removal, and makes escalation comment + needs-human label an atomic operation so tickets actually appear in the inbox. Run setup-plugin-source.sh on any fleet node not yet cut over — until then, doctor will report a worker-FAIL on skills-dir-plugins.

PRs

  • dev: CAT-52 — enforce registry team identity contract + doctor drift check (#3158) (8c12284)
  • dev: CTL-1506 otel-forward HTTP status classification + DLQ-loop fix (#2742) (ab62f2d)
  • dev: CTL-1639 salvage worktree unpushed work before destructive removal (#3026) (0560821)
  • dev: load catalyst plugins in-place via skills-dir; retire marketplace (#2664) (12c454f)
  • dev: add otel-forward to the post-merge stack-reload chain (#3164) (edc0ae2)
  • dev: CAT-29 refuse execution-core blindness to Linear (#3139) (4761b9e)
  • dev: CTL-1240 census tests never ran their census (isTicketKey skip) (#3148) (7a04cff)
  • dev: CTL-1568 make the escalation comment and the needs-human label one atomic act (#2861) (357a53c)
  • execution-core: fall back to credentials file when Keychain read fails (#3130) (62e4401)

12.49.0

Aug 08, 2026

Escalation Durability & Premature Done Guards

Escalations now survive GC via a durable per-ticket store, so Needs-You cards no longer vanish when a ticket goes terminal. Three independent guards close the false-Done/false-advance family: a dispatch freshness gate, a live GitHub merged check in teardown, and a PR-merged gate in the scheduler’s terminal Done writer. Worker nodes can also now set CATALYST_DRAIN_DISABLED=1 to permanently ignore drain requests, emitting a node.drain.ignored tripwire event instead of silently halting new-work admission.

PRs

  • dev: CTL-1473 — codify four laptop-audit failure modes (#2638) (0783e71)
  • dev: CTL-1494 — wire coordination-publish into catalyst-stack lifecycle (#3066) (6f3f5df)
  • dev: CTL-1502 — stuck-but-alive daemon watchdog (detect + auto-restart wedged otel-forward) (#2703) (5c6c02f)
  • dev: CTL-1552 Phase 1 — parked-by-human label + isParkedByHuman reader (#2791) (0b561cd)
  • dev: CTL-1606 — persist PR status from webhooks; fix board-health phantom/orphan detection (#2878) (43f6ee0)
  • dev: CTL-1643 escalation durability — verified-or-loud labels + GC-surviving attention store (#3009) (13e06a2)
  • dev: CTL-1645 add canonical onboarding planner (#3001) (28f9092)
  • dev: CTL-1667 — root fix for premature Done / monitor-deploy false-advance family (#3061) (c27dedd)
  • dev: CTL-1668 coordination-publish cloud endpoint wiring + ADR-023 parity harness (#3105) (2640720)
  • dev: CTL-1678 — worker nodes can permanently ignore drain requests (#3073) (d9bd6c6)
  • dev: CTL-1081 make match_thoughts_artifact shell-agnostic (zsh/shopt bug) (#3108) (bcafa4f)
  • dev: CTL-1415 — age-gate and auto-clear a stale plugin-source .git/index.lock (#2530) (2740458)
  • dev: CTL-1660 defer P2+ automated-review findings after round one (#3035) (b5592bb)
  • dev: CTL-1680 Phases 2+3 — confirm merge SHA + reviewer-arrival window (#3079) (3850648)
  • dev: fenceGuard fails OPEN on a missing generation at the terminal-sweep needs-human escalation site (#3048) (522e178)
  • dev: isTicketInFlight supersede guard for stale phase signals (#3081) (6accd27)
  • dev: remove hardcoded org name from provision-thoughts convention (#3080) (9cea441)
  • execution-core: close two remaining codex-exec thoughts-symlink escape gaps (#3098) (00374f1)
  • execution-core: codex-exec thoughts symlink resolution + no-progress escalation count (#3082) (4d672d5)
  • execution-core: preserve 0600 on Layer-2 config across autotune write-back (supersedes #3074) (#3106) (5369b6f)

12.48.0

Aug 07, 2026

Escalation Visibility & Stalled-PR Detection

The unstuck sweep now actually reaches the operator: stalled tickets get a needs-human label and a Linear comment instead of silently logging an event that nobody sees. A new periodic timer probes in-flight PRs for CI failures, review latency, and no-push signals, writing stall stamps that board-health reads to emit nudges — enable it with orchestration.stalledPrSweep.enabled in your config. This release also closes two fleet-wide triage bugs where host-local dispatch caps let ownership churn multiply real spawns across nodes, and the orch-monitor sidebar nav is restored for mobile viewports.

PRs

  • dev: CTL-1381 auto-install new catalyst-* CLIs after updater pull (#2847) (215b85a)
  • dev: CTL-1608 board-health stalled-PR detection — review-latency + CI-health sweep (#2908) (e290fb0)
  • dev: CTL-1609 delegate-first escalation + explanation-required chokepoint (#2909) (e8643b4)
  • dev: CTL-1641 — wire unstuck-sweep escalation to reach the operator (#3005) (74f99c9)
  • dev: CTL-708 opt-in bounded-LLM resolver for source conflicts (#3051) (21327cb)
  • dev: dependabot-escalate — file a ticket for the two Dependabot signals no PR ever surfaces (#3053) (a41578b)
  • dev: CTL-1649 — fleet-wide triage cap + exclude launch-failure tickets from board-health recovery (#3030) (50b5510)
  • dev: orch-monitor — mobile nav trigger + Linear reply-token identity walk (#3054) (d9ae8a7)
  • execution-core: close test-hermeticity gaps that only fail on a live, configured host (#3047) (2858769)

12.47.0

Aug 06, 2026

Stranded Ticket Recovery & Monitoring Node Substrate

The board-health delegate now detects mid-pipeline tickets that have gone dark — no worker, no live job, no recent recovery intent — and routes each one to the appropriate revival path (open PR remediation, remote branch resume, or fresh restart). Separately, monitor and developer nodes now run a proper event-mirror substrate instead of the execution core, so observation-only machines no longer accidentally join the dispatch roster; catalyst doctor and verify-node both surface a dead mirror as a real failure rather than silently passing. Several correctness fixes ship alongside: stranded-ticket evidence was previously never populated due to a map key mismatch, recovery-pass reclaim was silently failing on non-FSM phases, and queued/blocked labels now clear reliably once a ticket starts running.

PRs

  • dev: CTL-1644 board-health delegate detects stranded mid-pipeline tickets and routes each to revival or escalation (#3043) (e807fd5)
  • dev: CTL-1654 interactive nodes carry event/monitoring substrate without execution layer (#3016) (42a623c)
  • dev: address upstream review findings on PR #2851 (#3052) (6414e01)
  • dev: CTL-1571 make queued/blocked labels retractable once a ticket starts (#3045) (aa5fe53)
  • dev: CTL-1657 guard reclaim supersede-check against non-FSM phases (#3027) (58a3849)
  • dev: CTL-1662 event-mirror survives reboot + doctor catches it dead (#3038) (89a0e0b)
  • dev: fix bash 3.2 syntax error in setup-plugin-source.sh (#3049) (6dc6e22)

12.46.0

Aug 06, 2026

Account Health Visibility & Worktree Resume

The orch-monitor now surfaces Claude account health everywhere you look: a new accounts-probe library (TTL-cached, edge-triggered) backs a GET /api/accounts endpoint and /api/accounts/stream SSE feed, with a live strip in the Ink HUD and a banner in the web dashboard that fires loudly when an account degrades. Worktree creation now seeds from origin/<ticket> when that remote branch exists, so a resumed or reclaimed worktree picks up where the previous worker left off instead of silently orphaning pushed commits. Board-scan events also now carry per-host slot counts (recovery.slot.capacity, recovery.slot.in_use, recovery.slot.free) as chartable Loki attributes, making fleet-wide free-capacity queries like sum(recovery.slot.free) possible for the first time.

PRs

  • dev: board-scan events now carry per-host worker-slot counts as (602d1f2)
  • dev: CTL-1607 promote board-scan slot scalars to chartable Loki attributes (#2985) (602d1f2)
  • dev: CTL-1653 accounts-probe lib (probe runner + async TTL cache) (#3011) (32b6d07)
  • dev: board-health-seam test expects capacity.admissionGated (CTL-1607) (#3028) (1105e67)
  • dev: CTL-1640 resume worktree from origin/<ticket> instead of orphaning pushed commits (#3025) (898e02e)
  • dev: CTL-1655 — consumer-side coordination-mirror comment tail (#3015) (042d321)
  • monitor: CTL-1653 accept https-configured trusted origins in the refresh Host check (#3020) (b72a53a)
  • monitor: CTL-1653 document MONITOR_TLS_PROXY_PEERS + normalize IPv4-mapped peers (#3023) (fbcaffb)
  • monitor: CTL-1653 operator-declared TLS-proxy peers replace header-derived scheme (#3022) (e2746dc)
  • monitor: CTL-1653 post-merge hardening — stale-strip clear, Bun execPath, non-simple refresh, EOF reconnect, empty-env contract (#3017) (9eb083a)
  • monitor: CTL-1653 post-merge hardening r3 — unavailable transition, Host validation, unreadable-env error (#3019) (b4b7496)
  • monitor: CTL-1653 scheme-aware Host check — never treat an https-only trusted host as plaintext (#3021) (c081851)

12.45.0

Aug 05, 2026

Claude Account Switching Command

The new catalyst-stack claude-account command handles the full Claude SDK account rotation workflow in one step: status shows per-account utilization and reset times, switch <handle> validates the target, flips the SOPS secret, commits, pushes, and verifies the new account is active and error-free. A sync subcommand lets a second node adopt a pushed switch without repeating the full procedure. The release also fixes the orchestration monitor surfacing “unknown reason” for stalled tickets that actually had a specific attentionReason like sdk-overloaded-exhausted, and patches a broker bug where pre-workspace node_modules debris could shadow root installs and leave daemons running stale dependency versions.

PRs

  • dev: CTL-1650 catalyst-stack claude-account subcommand + commit the accounts-usage tool (#3004) (779ef08)
  • broker: CTL-1646 — prune pre-workspace member node_modules before a root install (#2997) (598e3c8)
  • dev: CTL-1623 export the canonical malformed-file validators instead of duplicating them (#2984) (c2b070e)
  • dev: CTL-1623 make the github-token rearm hook reject malformed files + run the bash parity suite in CI (#2983) (160abbf)
  • dev: CTL-1623 resolve github-token/webhook-secret through the secret contract (#2981) (94de78a)
  • dev: CTL-1648 — surface attentionReason in board stalled-phase derivation (#3003) (778b92d)
  • dev: CTL-1650 harden claude-account for BSD sed, stale selectors, and rate-limited targets (#3006) (4f6fb68)

12.44.0 (2026-08-04)

Features

  • dev: CTL-1616 cloud-token name-resolver unification + Groq resolveApiKey adoption (PR5) (#2927) (be673ea)
  • dev: CTL-1616 doctor cloud-guard escalation + shadow-diffed Layer-2 stragglers (PR6) (#2929) (56fbe72)
  • dev: CTL-1616 doctor secret-contract shadow pass (PR2, zero grade change) (#2916) (0377813)
  • dev: CTL-1616 fold the 9-file Linear read into the secret contract + doctor cutover (PR3) (#2919) (01294fc)
  • dev: CTL-1616 fold the OAuth-mint trio + read-only 4th onto the secret contract (PR4) (#2924) (22afee0)
  • dev: CTL-1622 setup-catalyst prompts for and persists catalyst.deployment.mode (#2912) (3af40d2)
  • dev: CTL-1628 catalyst-runtime-root resolver — fold Tier 1 duplicates + 4 latent resolver bugs (Phase A2) (#2946) (c01ef76)
  • dev: CTL-1628 root bun workspace + turbo (Phase A1) (#2945) (a61c8a8)

Bug Fixes

  • dev: CTL-1616 clear the sticky export attribute on the value breadcrumb (#2926) (ea1e474)
  • dev: CTL-1616 declare the split-brain Layer-2 layout unsupported + finish the observe-only story (#2931) (ca7ec68)
  • dev: CTL-1616 divergence check round 3 — reject relative paths, per-service remedy, no committed ticket prefix (#2939) (6c134b1)
  • dev: CTL-1616 divergence check round 4 — prefix-agnostic assertion + no dead-end remedy (#2941) (b811eb0)
  • dev: CTL-1616 harden the layer2-path-divergence check (#2931 round-2 Codex x2) (#2938) (694dc20)
  • dev: CTL-1616 keep the resolved secret VALUE out of child-process environments (#2925) (2c6901c)
  • dev: CTL-1616 PR6 follow-up — observe-only Layer-2 shadow + doctor coherence (#2929 Codex x4) (#2930) (64dddf5)
  • dev: CTL-1617 align doctor webhook-ingestion with the declared deployment mode (#2918) (d1d66e9)
  • dev: CTL-1617 close the three late #2918 Codex findings on the mode-aligned doctor grant (#2920) (905dbaa)
  • dev: CTL-1617 harden the join webhook-wiring gate (Codex follow-up to #2913) (#2914) (0bd14f8)
  • dev: CTL-1628 A1 isolate bun sniff from project config (Codex #2966 post-merge) (#2967) (ef09cb4)
  • dev: CTL-1628 A1 multiline-tolerant jq-less packageManager sniff (Codex #2948 post-merge) (#2964) (bac5434)
  • dev: CTL-1628 A1 post-merge hardening (Codex #2945 threads) (#2948) (c3f6944)
  • dev: CTL-1628 A1 retry TMPDIR when safe-cache mktemp fails (Codex #2972 post-merge) (#2975) (14bd0b6)
  • dev: CTL-1628 A1 sniff scratch-dir hardening + tier fallthrough (Codex #2967 post-merge) (#2972) (92226cb)
  • dev: CTL-1628 A1 tiered packageManager detection (Codex #2964 post-merge) (#2966) (1f22f0e)
  • dev: CTL-1628 A1 verify TMPDIR parent + scratch-dir before trusting it (Codex #2975 post-merge) (#2977) (27517ec)
  • dev: CTL-1628 A2 post-merge hardening (Codex #2946 threads) (#2947) (831a469)
  • dev: CTL-1628 comment-wake emission accounting + cross-host dedup reset (Codex #2970 post-merge) (#2973) (36e4cf4)
  • dev: CTL-1628 credit survives throw + early-path needs-input dedup clear (Codex #2974 post-merge) (#2976) (666044d)
  • dev: CTL-1628 delete unreachable catalyst-filter daemon body (keep alias) (#2949) (6a7d4cd)
  • dev: CTL-1628 freeze-cause telemetry mirror, legacy hydration default, persist retry (#2968) (8fffff5)
  • dev: CTL-1628 heartbeat publisher — require Linear anchor only in linear read-source mode (#2958) (3247e76)
  • dev: CTL-1628 orch-monitor roster readers → cluster.json roster (stop-worker fence + cross-node tail) (#2959) (7d5b93d)
  • dev: CTL-1628 retire ADR-018 JSON-shadow scaffolding + unused recordWorkerTransition module; document CTL-532 as the live projection (#2961) (3600198)
  • dev: CTL-1628 single-consume early-write credit + disposition-scoped dedup reset (Codex #2973 post-merge) (#2974) (c877a25)
  • dev: CTL-1628 surface eligible-set projection-write failure as health event (#2960) (c04f1a7)
  • monitor: mint app-actor Linear token on monitor start (supersedes #2905) (#2978) (f6fdeb9)
  • monitor: post-merge hardening — scan reachability, stop-cancels-remint, bash probe status (#2979) (34c5467)