Changelog

Reinstate Changelog and Release Notes

The latest published Reinstate tag is v0.6.0-rc.6, dated September 8, 2026. v0.6.0-rc.6 is a release candidate, not the current stable release: stable remains v0.5.1. It carries Reinstate Hop (cloud continuity) and the interactive CLI experience on top of verified resume, structured handoff, and universal agent coverage; its acceptance is native Windows x64 only, with Apple Silicon macOS deferred.

Last verified
Current release
v0.6.0-rc.6
Release status
v0.6.0-rc.6 candidate · stable remains v0.5.1 · v0.6.0-rc.5 tagged Windows run (plus two same-artifact rechecks) ended FAIL (211/4/0/0 of 215), zero product defects, grok:E1-E3 live-backend-connectivity plus a grok version drift to 1.0.13 and an H7 digest-equality-unmeasurable gap the four PARTIAL rows · this candidate widens the verified Grok Build range to 1.0.13 and refines the H7 live-home check to per-file listing with attribution · native Windows tagged-artifact acceptance pending, macOS deferred

Unreleased

Current unreleased website work adds the SEO, answer-engine, AI-search, and social-preview foundation and introduces signed website-vYYYY.MM.DD.N deployment tags. A website tag can publish reviewed site changes from current main while the public CLI and installer routes remain pinned to the separately signed v0.6.0-rc.6release. It is not a new Reinstate version or evidence for any platform outside the documented release boundary.

The repository'scanonical CHANGELOG.md is authoritative if this summary and the current branch differ.

v0.6.0-rc.6 · September 8, 2026

v0.6.0-rc.6 is a release candidate, not the current stable release: stable remains v0.5.1. Public installers currently pin this candidate while its own acceptance run is pending, not stable. Its acceptance is native Windows x64 only; the Apple Silicon macOS run is deferred until that hardware returns and is not claimed here.

Reinstate Hop

  • Every hosted journey ships as an ordinary rein command, with no build tag or feature flag: rein login / rein whoami (passwordless sign-in),rein init --hop and rein account init / recover /join / status (the locker and the keyring),rein devices / approve / revoke (pairing and revocation), rein hop status / rein hop credentials,rein sync verify, rein sync migrate --to byo, andrein daemon (a resident sync process; launchd on macOS, systemd--user on Linux, Task Scheduler on Windows).
  • The hosted control plane is not open. The default control-plane URL,https://hop.reinstate.dev, does not resolve yet; rein loginagainst it reports that in one sentence instead of hanging, andREINSTATE_HOP_URL / [hop] url point the client at a control plane you run yourself or a staging instance. No pricing, billing, trial, or sign-up ships in this release.
  • OpenCode reaches T5, encrypted sync — the first embedded-SQLite agent to sync — and Kimi Code CLI reaches T2, a handoff source.
  • See the Hop documentation for the full sign-in, device, and locker walkthrough.

The interactive CLI experience

Carried unchanged from v0.5.2-rc.1, which this candidate supersedes without a separate stable tag:

  • Bare rein opens an interactive session switcher with a readiness verdict per row; a warning checklist replaces retyped --allow-environment-warningidentifiers; a handoff studio previews every policy; rein init becomes a wizard with --link / --paste pairing codes; ctrl+kopens a command palette.
  • Every --json document and non-TTY byte stream stays byte-identical tov0.5.1; --plain andREINSTATE_NO_TUI freeze the old output.
  • OpenCode and Grok Build gain verified native resume; OpenCode, Grok Build, and Qwen Code become handoff destinations alongside Claude Code and Codex.

Continuity and privacy boundary

  • Native execution remains same-vendor; Reinstate does not translate transcripts across agents.
  • The Hop locker holds ciphertext plus one documented plaintext object,keyring.v1.json; credentials are never synced.
  • Stable v0.5.1 verified resume, local continuity, structured handoff, and encrypted sync remain available and unchanged.

Acceptance boundary

  • This candidate's acceptance runs on native Windows x64 (windows/amd64, never WSL) only. Apple Silicon macOS acceptance is deferred until that hardware returns; nothing here implies a macOS result.
  • Verified compatibility ranges widen on native Windows physical resume evidence and are marked "Windows evidence; macOS pending" until the deferred run lands. See thecompatibility matrix.
  • Passing this candidate's Windows run does not by itself authorize stablev0.6.0; the deferred macOS rows and the promotion decision are recorded separately.

View the v0.6.0-rc.6 tag on GitHub.

Release-candidate history

ReleaseDatePrimary focus
v0.6.0-rc.6Release candidate; stable remains v0.5.1 and this candidate does not by itself authorize promoting it. Corrective candidate after v0.6.0-rc.5 tagged-artifact acceptance on native Windows x64, plus two same-artifact rechecks, ended device verdict FAIL (211 PASS / 4 PARTIAL / 0 FAIL / 0 NOT TESTED of 215 required rows, zero product defects; the four PARTIAL rows were grok:E1/E2/E3, live backend connectivity to xAI compounded by the host's grok self-updating to 1.0.13 outside the verified 1.0.5 range, and MatrixH:H7, the daemon round-trip mechanism completing on both rechecks but its digest-equality pass condition proving unmeasurable on a live, multi-session host). This candidate changes exactly two things: the verified Grok Build range widens to 1.0.13 on the maintainer's own console evidence, since the pinned 1.0.5 binary no longer completes a prompt against xAI from any console; and MatrixH:H7's live-home check is refined from aggregate digest equality to a full per-file before/after listing of the session-bearing subtrees with per-entry attribution. Because Grok cannot be driven to a completed turn from this harness, the completed-turn grok:E1-E3 rows against 1.0.13 are executed by the maintainer at their own console in this candidate's tagged run. Nothing else changes: no other agent tier moves, no other compatibility range widens. Acceptance for this candidate is native Windows x64 only; the Apple Silicon macOS run is deferred until that hardware returns and is not claimed here.
v0.6.0-rc.5Release candidate; stable remains v0.5.1 and this candidate does not by itself authorize promoting it. Corrective candidate after v0.6.0-rc.4 tagged-artifact acceptance on native Windows x64 ended device verdict FAIL (208 PASS / 1 PARTIAL / 4 FAIL / 2 NOT TESTED of 215 required rows; both of that candidate's own fixes, the Pi reader and the widened Qwen Code range, were confirmed). That run found two new confirmed redaction/correctness gaps in the agent probe (MatrixB:B4, real project-name path segments reaching a committed artifact unshaped; MatrixB:B7, an existing-but-empty overridden agent root indistinguishable from an absent one), a stale sync-completion contract sentence (MatrixG:G4, scored against unchanged shipped behavior), a confirmed interactive-CLI defect (CLI row 13, the switcher's default all-projects scope showing every visible row as unresumable regardless of true state), a host version-compatibility block (OpenCode self-updated to 1.18.29, above the verified 1.18.27 ceiling), and an operator/elevation-availability gap (MatrixH:H7). This candidate changes exactly these things: probe shape normalization at every tree depth with root state reported (closes B4/B7), the switcher's all-projects readiness (closes row 13), the verified OpenCode range widens to 1.18.21-1.18.29 on native Windows evidence, and the G4/H7 contract text is corrected. Nothing else changes: no other agent tier moves, no other compatibility range widens. Acceptance for this candidate is native Windows x64 only; the Apple Silicon macOS run is deferred until that hardware returns and is not claimed here. Published and tagged: native Windows tagged-artifact acceptance, plus two same-artifact rechecks, ended device verdict FAIL (211 PASS / 4 PARTIAL / 0 FAIL / 0 NOT TESTED of 215 required rows); zero product defects. It found a live grok backend-connectivity gap compounded by a grok version drift to 1.0.13, and an H7 disposition whose digest-equality pass condition proved unmeasurable on a live host; both addressed in v0.6.0-rc.6. Does not authorize stable v0.6.0.
v0.6.0-rc.4Release candidate; stable remains v0.5.1 and this candidate does not by itself authorize promoting it. Corrective candidate after v0.6.0-rc.3 tagged-artifact acceptance on native Windows x64 ended device verdict FAIL (201 PASS / 3 PARTIAL / 1 FAIL / 10 NOT TESTED of 215 required rows; all 22 CLI rows and all 16 Hop rows passed, and the Cursor CLI store-schema fix was confirmed on real data). That run found a confirmed code defect (pi:C3: the Pi reader handed the whole message object to the shared text-flattening helper instead of message.content, so prompt_preview and search text were silently empty for every real, version-3 Pi session) and a version-compatibility block (the host Qwen Code self-updated to 0.23.0, above the verified 0.21.13 ceiling, correctly refusing ten rows). This candidate changes exactly two things: the Pi reader now reads message.content (indexing only user-turn text, matching the Claude and Codex readers), and the verified Qwen Code range widens to 0.21.12-0.23.0 on native Windows physical-resume evidence. Nothing else changes: no other agent tier moves, no other compatibility range widens. Acceptance for this candidate is native Windows x64 only; the Apple Silicon macOS run is deferred until that hardware returns and is not claimed here. Published and tagged: native Windows tagged-artifact acceptance ended device verdict FAIL (208 PASS / 1 PARTIAL / 4 FAIL / 2 NOT TESTED of 215 required rows); both of this candidate's own fixes, the Pi reader and the widened Qwen Code range, were confirmed on real data. It found a probe redaction gap, an empty-vs-absent override root gap, a stale sync-completion contract sentence, the switcher's all-projects readiness defect, an OpenCode version-compatibility block, and an operator-availability gap on MatrixH:H7; corrective fixes land in v0.6.0-rc.5. Does not authorize stable v0.6.0.
v0.6.0-rc.3Release candidate; stable remains v0.5.1 and this candidate does not by itself authorize promoting it. Corrective candidate after v0.6.0-rc.2 tagged-artifact acceptance on native Windows x64 ended device verdict FAIL (203 PASS / 5 PARTIAL / 2 FAIL / 5 NOT TESTED of 215 required rows; all 22 CLI rows and 15 of 16 Hop rows passed). A post-commit, schema-only inspection of two real Cursor CLI 2026.08.11 store.db files found blobs(id, data)/meta(key, value) tables, not the messages/message/bubbles shape the v0.6.0-rc.2 Cursor reader guessed at and no real store ever had, so real Cursor CLI sessions kept reporting message_count 0 and were not found by search despite cursor:C2/cursor:C3 being marked fixed. This candidate changes exactly the Cursor CLI store reader to read that real schema and nothing else: no agent tier changes, no compatibility range widens. Acceptance for this candidate is native Windows x64 only; the Apple Silicon macOS run is deferred until that hardware returns and is not claimed here. Published and tagged: native Windows tagged-artifact acceptance ended device verdict FAIL (201 PASS / 3 PARTIAL / 1 FAIL / 10 NOT TESTED of 215 required rows); all 22 CLI rows and all 16 Hop rows passed, and this candidate's own Cursor CLI store-schema fix was confirmed on real data. It found a new Pi reader defect (pi:C3) and a Qwen Code version-compatibility block (host self-updated to 0.23.0, above the verified ceiling); both are addressed in v0.6.0-rc.4. Does not authorize stable v0.6.0.
v0.6.0-rc.2Release candidate; stable remains v0.5.1 and this candidate does not by itself authorize promoting it. Corrective candidate after v0.6.0-rc.1 tagged-artifact acceptance on native Windows x64 found 7 required-row failures (201 of 216 rows passed): fixes Cursor CLI session discovery, search, inspect, resume, and fork so CURSOR_CONFIG_DIR isolates every command path, not only doctor --agents, plus a conformance check that catches the same class of gap; computes Cline and Cursor message_count from each vendor's own message-bearing store instead of hard-coding 0, and corrects Cursor size_bytes; wires shell-completion candidates for push --agent and pull --agent; makes an OpenCode-sourced handoff deterministic across repeated dry runs by hashing only the session's own rows instead of the whole shared database; and adds committed Windows-shaped partial-final-record fixtures plus a pipeline-level truncation test for Claude Code, Codex, and Grok Build. No agent tier changes. Acceptance for this candidate is native Windows x64 only; the Apple Silicon macOS run is deferred until that hardware returns and is not claimed here. Published and tagged: native Windows tagged-artifact acceptance ended device verdict FAIL (203 PASS / 5 PARTIAL / 2 FAIL / 5 NOT TESTED of 215 required rows, after a post-commit finding re-scored the real-data Cursor CLI rows); the Cursor CLI store-schema defect it found is fixed in v0.6.0-rc.3. Does not authorize stable v0.6.0.
v0.6.0-rc.1Release candidate; stable remains v0.5.1 and this candidate does not by itself authorize promoting it. Carries Reinstate Hop as ordinary rein commands, unconditional on every install: rein login/whoami, an init --hop wizard with --link/--paste pairing, hop status/credentials, account init/recover/join/status, devices/approve/revoke, sync verify, sync migrate --to byo, and a background daemon. OpenCode reaches encrypted sync (T5) and Kimi Code CLI becomes a handoff source (T2). The hosted control plane itself is not deployed, so rein login against the default control-plane URL reports that in one sentence instead of hanging, the URL stays configurable for labs and self-hosters, and no pricing, billing, or sign-up ships. Also carries the interactive CLI experience from v0.5.2-rc.1 unchanged, with every --json document and non-TTY stream still byte-identical to v0.5.1. Acceptance for this candidate is native Windows x64 only; the Apple Silicon macOS run is deferred until that hardware returns and is not claimed here. Published and tagged: native Windows tagged-artifact acceptance ended at 201 of 216 required rows PASS, with every Hop and CLI-experience row passing; the 7 failing rows are fixed in v0.6.0-rc.2. Does not authorize stable v0.6.0.
v0.5.2-rc.1Release candidate; stable remains v0.5.1 and the public installers still pin it. Bare rein opens an interactive session switcher with a readiness verdict per row, a handoff studio, a setup wizard, and a ctrl+k palette, while every --json document stays byte-identical and --plain or REINSTATE_NO_TUI restores the frozen output. OpenCode, Grok Build, and Qwen Code become handoff destinations, so rein handoff --to reaches five agents instead of two; OpenCode and Grok Build also gained verified native resume. The interactive surfaces have development verification on both platforms but no tagged-artifact acceptance, which is what this candidate exists to enable.
v0.5.1Patch release. Updates the pure-Go SQLite driver behind the session index and the OpenCode embedded store from 1.55.0 to 1.56.0. No product code changed. The storage rows were re-run on both platforms against the new driver rather than assumed inert: no write-ahead or shared-memory sidecar is created under an agent root, and an index written by the previous driver is read by this one and back again without losing a row.
v0.5.0Stable Phase 5 release. Universal agent coverage: a catalog of 18 agents, rein doctor --agents with a redacted AGENT-PROBE-V1 artifact, six T1 discover agents, three T2 handoff sources, and Claude Code and Codex as the only native resume and sync surfaces. Authorized by dual-platform tagged-artifact acceptance on v0.5.0-rc.6: Apple Silicon macOS PASS and native Windows x64 PASS across the full 150-row matrix.
v0.5.0-rc.6Sixth Phase 5 candidate. Physical v0.5.0-rc.5 tagged-artifact acceptance failed one required row: the agent probe carried a raw 38-character Git object hash into its artifact, because the shape normalizer recognised only exactly 32, 40 and 64 characters and OpenCode keeps a Git object store under each snapshot. Those names are content hashes of the repository being worked in. Any hex run long enough to identify content is now collapsed. Does not authorize stable v0.5.0. Current stable remains v0.4.0.
v0.5.0-rc.5Fifth Phase 5 candidate. Carries eight fixes found by physical dual-platform acceptance: an index that never re-read a source after Reinstate itself changed, so every reader fix stayed invisible; Gemini project paths recorded in a different case than they are hashed in; an agent root override that was ignored when it named a missing path; incremental refresh; and Windows portability of the documentation tests. Raises the verified ranges to Claude Code 2.1.238 and Codex CLI 0.149.0 on dual-platform physical resume evidence. Does not authorize stable v0.5.0. Current stable remains v0.4.0.
v0.5.0-rc.4Fourth Phase 5 candidate. Physical rc.3 acceptance found the agent probe was not reproducible between runs, raw content hashes reached probe output, resume reported the wrong exit code for a T0 agent, an agent-filtered query scanned every source, and completion offered no agent keys. Does not authorize stable v0.5.0. Current stable remains v0.4.0.
v0.5.0-rc.3Third Phase 5 candidate. Restores Kimi, Copilot, and OpenCode session discovery after those vendor CLIs changed their on-disk formats, so per-agent project truth is correct again on both platforms. Does not authorize stable v0.5.0. Current stable remains v0.4.0.
v0.5.0-rc.2Second Phase 5 candidate after v0.5.0-rc.1 dual-platform tagged-artifact acceptance FAILED. Projection now pairs tool_result with its tool_call so Codex handoff dry-run capsules validate. Does not authorize stable v0.5.0. Current stable remains v0.4.0.
v0.5.0-rc.1First Phase 5 candidate: agent catalog, doctor --agents, six T1 discover agents, three T2 handoff sources. Dual-platform tagged-artifact acceptance FAILED (macOS 88/150, Windows 93/150). Does not authorize stable v0.5.0. Current stable remains v0.4.0.
v0.4.0Phase 4 stable: explicit structured handoff into a new Claude Code or Codex session after dual-platform v0.4.0-rc.11 tagged-artifact acceptance PASS (macOS 44/44, Windows 44/44).
v0.4.0-rc.11Eleventh Phase 4 candidate after v0.4.0-rc.10 physical dual-platform acceptance FAILED (macOS 41/44 A1/A3/A7, Windows 40/44 A1/A2/A3/A5; dest first-reply, lineage-after-launch, dest folder-trust). Dual-platform tagged-artifact acceptance later PASS (macOS 44/44, Windows 44/44); promoted to stable v0.4.0.
v0.4.0-rc.10Tenth Phase 4 candidate after v0.4.0-rc.9 physical dual-platform acceptance FAILED (macOS 38/44, Windows 38/44; dest-ack A4 PASS, A1/A2/A3/A5/A6/A7 FAIL; Windows CreateProcess truncated multi-line dest argv). Physical dual-platform acceptance FAILED: macOS 41/44 A1/A3/A7, Windows 40/44 A1/A2/A3/A5; remaining product defects dest first-reply, lineage-after-launch, dest folder-trust.
v0.4.0-rc.9Ninth Phase 4 candidate after v0.4.0-rc.8 physical dual-platform acceptance FAILED (macOS 38/44, Windows 38/44; Windows inspect JSON agent.status=not_installed despite layout_recognized=true). Physical dual-platform acceptance FAILED: macOS 38/44, Windows 38/44; remaining product defect was Windows dest argv CR/LF truncation.
v0.4.0-rc.8Eighth Phase 4 candidate after v0.4.0-rc.7 physical dual-platform acceptance FAILED (macOS 38/44, Windows 34/44; R1 off-PATH Inspect StatusNotInstalled before layout scan). Pins Go 1.25.13 for govulncheck. Physical dual-platform acceptance FAILED: macOS 38/44, Windows 38/44; remaining product defect was Windows inspect JSON not_installed.
v0.4.0-rc.7Seventh Phase 4 candidate after v0.4.0-rc.6 physical dual-platform acceptance FAILED (Windows WMI busy-check cascade; C8/R6 2.1.230 fail-open; R4 leftover Runtime). Physical dual-platform acceptance FAILED: macOS 38/44, Windows 34/44; remaining product defect was R1 off-PATH Inspect.
v0.4.0-rc.6Sixth Phase 4 candidate after v0.4.0-rc.5 physical dual-platform acceptance FAILED (dest-ack/picker without a console; C4 remapped fixture/foreign workspaces onto any git cwd). Physical dual-platform acceptance FAILED: Windows Plan rows died on a ~305s WMI busy-check; macOS was 37 PASS / 7 FAIL.
v0.4.0-rc.5Fifth Phase 4 candidate after v0.4.0-rc.4 physical dual-platform acceptance FAILED (Windows R4 hang 43s, F8 ~6s non-TTY delay, B6 summarized missing, C5 Windows os-roots exit 5). Physical dual-platform acceptance FAILED.
v0.4.0-rc.4Fourth Phase 4 candidate after v0.4.0-rc.3 physical dual-platform acceptance FAILED (empty dest home UNTESTED blocking flagship A, hanging --version, Windows make verify, G3 list n=0, B6 missing summarized). Physical dual-platform acceptance FAILED.
v0.4.0-rc.3Third Phase 4 candidate after v0.4.0-rc.2 physical dual-platform acceptance FAILED (wrong-repo cwd, non-TTY spawn, Grok-source busy-check, timed-out probe classified Runtime). Physical dual-platform acceptance FAILED.
v0.4.0-rc.2Second Phase 4 candidate after v0.4.0-rc.1 physical acceptance FAILED: Claude source version probing, path tokenization, live changed-file reporting, probe-timeout classification, and prose-vs-path capsule validation are fixed. Physical dual-platform acceptance FAILED.
v0.4.0-rc.1First Phase 4 candidate: explicit structured handoff of the same task into a new Claude Code or Codex session. Dual-platform tagged-artifact acceptance is pending.
v0.3.0Phase 3 stable: verified resume for Claude Code and Codex after dual-platform RC7 acceptance PASS.
v0.3.0-rc.7Phase 3 candidate after RC6 dual FAIL: packages non-TTY fail-closed, Windows Ctrl+C safety, capability probe demotion, isolated agent homes, and expanded local Phase 3 smoke for retest.
v0.3.0-rc.6Phase 3 candidate that widens Claude Code through 2.1.227 and Codex CLI through 0.147.0 after RC5 host-version acceptance failures.
v0.3.0-rc.5Corrective Phase 3 candidate after RC4 stayed unpublished: portable PowerShell artifact verification with the Windows-first product fixes intact.
v0.3.0-rc.4Windows-first Phase 3 candidate whose signed-tag workflow failed before publication during Ubuntu PowerShell artifact verification.
v0.3.0-rc.3Corrective Phase 3 candidate after RC2 Windows FAIL; native Windows acceptance still failed on PowerShell 5.1 staging and human-output privacy.
v0.3.0-rc.2Corrective Phase 3 candidate after RC1 Windows FAIL. Apple Silicon progress recorded; native Windows tagged-artifact acceptance failed (Codex trust and snapshot/PS gates).
v0.3.0-rc.1First Phase 3 verified-resume candidate. Apple Silicon macOS tagged-artifact acceptance passed; native Windows x64 failed (not stable).
v0.2.0Stable Phase 2 local continuity on verified Apple Silicon macOS and native Windows x64; Intel macOS and Linux/WSL2 artifacts remain preview.
v0.2.0-rc.3Package-manager distribution candidate with verified npm, JSR, Homebrew, Scoop, Chocolatey, WinGet, AUR, and native Linux payload generation.
v0.2.0-rc.2Full release-artifact commit provenance and deterministic native-Windows verification gates.
v0.2.0-rc.1Phase 2 local index, literal search, metadata inspect, switcher, and same-vendor resume/fork release candidate.
v0.1.0First stable release. Phase 1 two-device acceptance passed on v0.1.0-rc.8, whose product code this ships unchanged.
v0.1.0-rc.8Session liveness detection that no longer depends on an open file handle.
v0.1.0-rc.7Session-scoped restore safety that no longer blocks on unrelated running agents.
v0.1.0-rc.6Canonical project mapping, exact restore checks, and remote-manifest validation.
v0.1.0-rc.5Safer re-initialization, joined-profile checks, and bounded installer confirmation.
v0.1.0-rc.4Destination-aware Claude paths and portable Codex structural paths.
v0.1.0-rc.3Tested version ranges, fail-closed setup checks, and a dependency security patch.
v0.1.0-rc.2Signed-tag verification correction.
v0.1.0-rc.1Initial Phase 0 and Phase 1 release-candidate foundation.

What the first release candidate established

RC1 introduced the Cobra CLI, versioned local state, device detection, diagnostics, verified installers, S3-compatible storage, age encryption, path mapping, manifests, push and pull, conflicts, Claude Code and Codex adapters, native keyring credentials, restore backups, and the synthetic compatibility-test foundation. It also established rein as the short alias for the reinstate binary.

How to read pre-1.0 release notes

Release candidates were published for testing before stable v0.1 certification, which v0.1.0 completed. Read every intermediate release note before replacing a binary because compatibility behavior, session artifact formats, setup validation, and release gates may still change.

  • Pin an explicit release in automated setup.
  • Verify checksums before installing.
  • Run rein setup check after agent or Reinstate upgrades.
  • Use pull dry-runs and maintain independent backups of important work.