· 5 min read · AI · Blog post #3

Dev log #2: August to October

Changes from August 4 to October 6, 2026 across oak/oak and oak/oakspace. About 115 merged branches. CLI v0.102.0 → v0.105.0. Previous: Dev log #1.

Pricing

  • Paid plans and their limits moved behind a feature flag. Every account gets 100 GB during the beta.
  • Docs now include an example session, answers about the CI runner, and a price ballpark.

Data safety fixes

  • Merge base on partial history (0.104.0). On a shallow or partially backfilled commit graph, 0.103.0 could pick a too-old merge base, so oak pull could re-apply a change main had reverted and merge previews could predict against the wrong base. A merge base computed on a partial graph is now either correct or reported unavailable (IncompleteAncestry, exit 5).
  • oak pull never drops local-only commits (0.105.0). Against a local oak serve, push → commit → pull could reset the branch and discard the unpushed commit. Pull now checks that the new head contains the local tip before writing anything, and otherwise keeps, re-parents, or enters the conflict flow. --force parks the old tip as <branch>.orphaned-<ts>. Hosted oak.space was not affected.
  • oak close --remote no longer resets a local branch that is ahead of the remote.
  • Hosted merge uses compare-and-swap on the resolved heads, so a concurrent merge or a push during a merge can’t lose acknowledged work.
  • Zero-byte files (0.102.1). Repos containing empty files are clonable again, and the server no longer silently omits blobs it can’t ship.
  • Diff patches keep \ No newline at end of file markers and CRLF bytes so they apply exactly.

Content integrity

  • Clone runs a bounded integrity proof before transfer: header-only history traversal with per-request budgets, one pinned branch-head snapshot for the whole clone, and 412 if the branch moves mid-clone.
  • If the proof runs out of budget, clone reports inconclusive (exit 8, integrity_inconclusive) instead of missing content, and suggests --shallow. oak doctor --json reports verified / failed / inconclusive.
  • Admission is rate-limited per principal, repository and profile; 429s carry Retry-After and the client retries within 60 s.
  • Publication walks the complete commit graph; the server rejects commits whose parent or merge parent is absent.
  • Blob ingest and publication were hardened end to end.

Security

  • A checkout’s repository API key is bound to the server that issued it and is never sent to another remote. Previously, oak push -r <other> or OAK_REMOTE=<other> sent it there. If you did that, rotate the repository’s key.
  • Both installers (install.sh, install.ps1) verify Minisign signatures on the release and the mounter before replacing the existing binary, using a pinned Minisign bootstrap.
  • Fixed a stored XSS in URL-backed 3D previews.
  • Centralized security headers (base-uri, nosniff, framing, referrer, HSTS) on every HTML response.
  • Anonymous web feedback removed; the web form requires login. CLI feedback is unchanged.
  • Protected production deploys: signed grants, protected secrets kept out of command strings, least-privilege AWS boundary, signed crash-recoverable bootstrap.
  • The oak_token session cookie now persists for the token’s lifetime instead of the browser session.

Review without a checkout

  • oak branch review|diff|triage --remote pins to immutable source and target heads and fetches only the content it needs, without touching local refs.
  • Remote branch diffs include hunks and per-file omission reasons; remote file reads are supported.
  • Remote log: oak log --remote --json walks a branch’s history without fetching it.
  • Whole-branch JSON contribution review.
  • Preview merging several independent sibling branches in order, with conflict/incomplete/stale outcomes.
  • Review distinguishes unavailable bytes from binary or large files and rejects unknown comparison targets.
  • Review won’t recommend closing a branch that has uncommitted work in the current checkout.
  • merge_allowed in review and triage is based on CI for the exact head.

Clone and sync

  • oak clone --branch NAME --expected-head FULL clones one branch at an exact head.
  • oak clone --detached lands on the default branch without creating a personal branch.
  • oak clone --from seeds a clone from a local checkout.
  • Sparse clones negotiate cone-aware blob withholding and keep full identities for out-of-cone files.
  • oak switch -c in a fresh shallow clone skips the ancestry walk when main hasn’t moved (about 176 s → under 1 s on oak/oak).
  • Equal-tree refreshes leave unchanged files in place, keeping compiler caches warm.
  • Local oak serve honors depth on GET /pull.
  • New flags: oak pull --json, oak pull --branch-only, oak desc --append, oak push --plan --json.

CI

  • oak ci trigger for an exact commit with an idempotency key.
  • Exact-run cancellation; oak ci cancel --superseded.
  • oak ci wait --current, opt-in progress events, compact summaries without logs, and run_url in JSON.
  • CI step timings recorded by the server.
  • Build cache kept inside the runner’s disk, sandbox SDK pinned to its image, and CLI CI builds tuned to avoid disk exhaustion.

Agent-facing CLI

  • JSON outputs carry receipts with explicit identity and confirmed/uncertain outcomes for push, merge, commit, finish, clone and CI.
  • Structured oak merge output stays parseable during post-merge refresh (progress goes to stderr).
  • oak change capture --json records an immutable local change; oak change export writes it to a verified self-contained archive.
  • oak file inspect --at HEAD|HASH --json PATH for pinned file evidence.
  • oak space inventory lists local checkouts and mounts; fenced close of many branches at once.
  • oak diff: git-compatible add/delete headers, --check, --name-only with --print.
  • oak restore accepts literal HEAD.
  • oak commit on a detached HEAD refuses.
  • The log and diff viewers support less and emacs keys.
  • Credential lock no longer steals from a live owner; concurrent logins don’t lose credentials.
  • oak finish --json reports description_synced truthfully.

Feedback

  • Ten-state feedback workflow, spam-safe exports, and automatic linking/closure from merged branch descriptions that reference fb-N.
  • Edits are atomic with revisions and an audit trail.
  • Admin CLI: feedback list/show, conditional transitions, manual link/unlink.
  • Web feedback preserves drafts across auth, rate-limit and network errors and returns accurate Retry-After.

Removed

  • The “software factory” orchestration layer and its factory flag.

Other

  • @public path principal: a private repo can open-source part of its tree.
  • Homepage rewritten around three differentiators: mount instead of clone, messageless commits, large files without LFS.
  • Public docs and README updated to match what ships (agent skill, CI, shell completion, feedback).
  • Yanked transitive dependency (multer) removed from release builds.
Claim your username

get updates by email

Roughly monthly updates about development and cool things.