TRACKER: ingest Agent Zero v2.12 into a0-symbolics #127

Open
opened 2026-09-09 14:58:54 +00:00 by nsaspy · 0 comments
Owner

Source

Agent Zero v2.12: https://github.com/agent0ai/agent-zero/releases/tag/v2.12
Published 2026-09-09.

This tracker is the parity map for ingesting upstream v2.12 without overwriting a0-symbolics-specific symbolic/RLM, UI, plugin, and transport work.

Missing-feature / fix issues

  • #121 Connector WebSocket payload ceilings + symmetric checksummed transfer protocol
  • #122 Atomic workspace HTTP transfers + bounded remote connector payload continuation
  • #123 Independent lazy directory trees in Files and Editor
  • #124 File Browser settings/preferences + configurable edit/transfer limits + file-link rendering
  • #125 Connected CLI/Launcher folders with safe authenticated remote transfers
  • #126 Central streamed transfers + archive expansion/entry/path hardening
  • #127 Native Responses tool calls/history/schemas/result metadata end-to-end
  • #128 Context Doctor split-thoughts + fallback response handling
  • #129 Prompt/profile projection, MCP guidance, and compact problem-solving prompts
  • #130 Movable canvas rail + verbose tool-call preference + canvas/UI parity fixes
  • #131 Safari Browser setup + Browser/Desktop startup/display/package fixes
  • #132 Model/provider management + streamed usage parity
  • #133 Management API guide + remote-skill gating + catalog regressions
  • #134 Parallel terminal job lifetime/validation/log preservation
  • #135 SECURITY: WhatsApp media traversal + pre-download authorization
  • #136 SECURITY: Telegram webhook authentication / polling-mode HTTP rejection
  • #137 SECURITY: strict single-mailbox IMAP From parsing before whitelist checks
  • #138 Runtime/infrastructure stability parity

Audited as already substantially present — do not create duplicate work

  • Shared Editor/Markdown-preview stack is already substantial in plugins/_editor and related WebUI/tests; #123/#124 should extend it rather than reintroduce the legacy upstream editor wholesale.
  • a0-create-plugin and a0-manage-plugin already exist and are routed from the local skill catalog.
  • Local plugin DOX already distinguishes hooks.py lifecycle behavior from manual execute.py; retain the fork's semantics while applying any remaining v2.12 validation/doc deltas in #133.
  • a0-symbolics already contains custom native Responses/XML-tool recovery work; #127/#128 are parity/non-regression work, not a revert to stock Agent Zero.

Merge policy

Treat this as a selective upstream ingestion, not a blind source overwrite. For each child issue:

  1. inspect the exact upstream v2.12 implementation/commits,
  2. reconcile with closest AGENTS.md,
  3. preserve fork-specific behavior unless the issue explicitly replaces it,
  4. add regression tests proving the v2.12 invariant,
  5. merge only on the repository's normal green gates.

Priority

  1. #135 #136 #137 security
  2. #121 #122 #126 transport/filesystem boundaries
  3. #127 #128 Responses/repair correctness
  4. remaining feature/UI/provider/runtime parity
## Source Agent Zero v2.12: https://github.com/agent0ai/agent-zero/releases/tag/v2.12 Published 2026-09-09. This tracker is the parity map for ingesting upstream v2.12 without overwriting `a0-symbolics`-specific symbolic/RLM, UI, plugin, and transport work. ## Missing-feature / fix issues - [ ] #121 Connector WebSocket payload ceilings + symmetric checksummed transfer protocol - [ ] #122 Atomic workspace HTTP transfers + bounded remote connector payload continuation - [ ] #123 Independent lazy directory trees in Files and Editor - [ ] #124 File Browser settings/preferences + configurable edit/transfer limits + file-link rendering - [ ] #125 Connected CLI/Launcher folders with safe authenticated remote transfers - [ ] #126 Central streamed transfers + archive expansion/entry/path hardening - [ ] #127 Native Responses tool calls/history/schemas/result metadata end-to-end - [ ] #128 Context Doctor split-thoughts + fallback response handling - [ ] #129 Prompt/profile projection, MCP guidance, and compact problem-solving prompts - [ ] #130 Movable canvas rail + verbose tool-call preference + canvas/UI parity fixes - [ ] #131 Safari Browser setup + Browser/Desktop startup/display/package fixes - [ ] #132 Model/provider management + streamed usage parity - [ ] #133 Management API guide + remote-skill gating + catalog regressions - [ ] #134 Parallel terminal job lifetime/validation/log preservation - [ ] #135 SECURITY: WhatsApp media traversal + pre-download authorization - [ ] #136 SECURITY: Telegram webhook authentication / polling-mode HTTP rejection - [ ] #137 SECURITY: strict single-mailbox IMAP From parsing before whitelist checks - [ ] #138 Runtime/infrastructure stability parity ## Audited as already substantially present — do not create duplicate work - Shared Editor/Markdown-preview stack is already substantial in `plugins/_editor` and related WebUI/tests; #123/#124 should extend it rather than reintroduce the legacy upstream editor wholesale. - `a0-create-plugin` and `a0-manage-plugin` already exist and are routed from the local skill catalog. - Local plugin DOX already distinguishes `hooks.py` lifecycle behavior from manual `execute.py`; retain the fork's semantics while applying any remaining v2.12 validation/doc deltas in #133. - `a0-symbolics` already contains custom native Responses/XML-tool recovery work; #127/#128 are parity/non-regression work, not a revert to stock Agent Zero. ## Merge policy Treat this as a selective upstream ingestion, not a blind source overwrite. For each child issue: 1. inspect the exact upstream v2.12 implementation/commits, 2. reconcile with closest `AGENTS.md`, 3. preserve fork-specific behavior unless the issue explicitly replaces it, 4. add regression tests proving the v2.12 invariant, 5. merge only on the repository's normal green gates. ## Priority 1. #135 #136 #137 security 2. #121 #122 #126 transport/filesystem boundaries 3. #127 #128 Responses/repair correctness 4. remaining feature/UI/provider/runtime parity
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
nsaspy/a0-symbolics#127
No description provided.