What's Changed
✨ Added
QwenPaw OS Shell
- Open apps in movable, resizable windows with a launcher, taskbar, notifications, and saved layouts (#6645)
- Installed and marketplace apps now share one catalog across the App Center and QwenPaw OS Shell (#6718)
Unified Files Workspace
- Browse, preview, edit, compare, upload, and download workspace files without leaving Chat (#6504)
- Open the Files workspace directly from QwenPaw OS Shell (#6758)
- Edit Robot Framework files with syntax highlighting (#6519)
QwenPaw Creator
- Turn an idea or existing footage into a finished video with a team of specialized Agents (#6284)
- Select clips, subtitles, effects, assets, or text for focused Agent edits while keeping direct controls (#6740)
- Create with images, video, voice, subtitles, motion, overlays, and parallel production steps (#6740)
- Add media task recovery, rendering fixes, structured logs, and review feedback (#6556, #6641)
- Add a settings center, external Skills, asynchronous media generation, more rendering formats, and improved Windows and narrow-screen support (#6870)
Cross-harness Integration
- Create Agents powered by Codex or Qoder, with per-session models, permissions, Skills, and MCP services (#6397)
- ACP clients can pass temporary models, project folders, and MCP services without saving runtime credentials (#6754)
- ACP sessions now report available and current models to compatible clients (#6531)
Browser-use
- Browser-use remains in Beta. It can use a separate browser session or connect selected tabs from the user's signed-in Chrome. Browser-side code execution is not protected by a host-level sandbox, and action policies are not yet enforced (#6276, #6157)
Computer-use
- Add Windows desktop app automation. macOS packaging and signing are complete, while device-level end-to-end validation is still in progress. Operations require per-app approval and stop when the user takes over input (#6424)
- Native Computer-use adds keyboard sequences, improves Windows modal targeting and text editing, and makes macOS menus, dragging, capture, and focus more reliable (#6891, #6913, #6977)
Context, Recovery & Long-running Work
- Snapshot and restore conversations, memory, and selected workspace files without changing project Git history (#6269)
- Long conversations retain the active task while older exact history moves into a searchable index (#6323)
- History search returns paired requests and responses and understands date-based queries (#6237)
- Visual Compact reduces long-context input for supported multimodal models while keeping source recovery (#6456)
- Long-running tools can continue in the background with progress, extension, and cancellation controls (#6151)
- Tool workflows can reuse results, branch, loop, and run independent steps in parallel (#5698)
- ReMe Light memory search can optionally rerank candidates through an OpenAI-compatible endpoint and falls back gracefully when reranking is unavailable (#6398)
- ReMe Light adds validated, hot-updatable embedding settings, Daily Paper and service-level schedules, per-Agent runtime status, manual reindex controls, and independent search and notification options (#6772)
Console & Models
- Agent Statistics now shows token usage and narrows results to the current Agent (#6503, #6402, #6862)
- Project directory selection can include hidden folders when requested (#6878)
- Code blocks now share a responsive, theme-aware design with syntax highlighting, copy and download actions; LaTeX and Mermaid blocks add localized Preview and Source tabs (#6911)
- Explore memory relationships in an interactive 3D graph with focus, filtering, and reduced-motion support (#6922)
Channels
- Feishu, QQ, WeCom, Xiaoyi, and Yuanbao can use opt-in custom gateway endpoints for private deployments and local integration testing without changing their defaults (#6907)
- Saving an enabled built-in channel warns when the same bot identity is already used by another running Agent, while still allowing an explicit override (#6909)
🔄 Changed
- The App Center separates installed and available apps, expands app details, and adds a Simple Mode entry (#6553, #6638)
- Chat keeps loop modes aligned with the active Agent and lists localized Oh-My-Paw modes (#6711, #6521)
- Slash-command Skills show injected content, duplicate copies are skipped, and QwenPaw Skill links can be imported directly (#6345, #6650, #6517)
- Windows selects sandboxing based on current privileges; unsupported restrictions are reported on every platform (#6383, #6657)
- OneBot/QQ preserves text and media order and expands quoted or forwarded messages (#6543, #6769)
- QwenPaw OS Shell places the Simple/Desktop Mode switches side by side and shortens the Desktop Mode label (#6763)
- QwenPaw OS Shell now uses one browser entry, launches apps from inside the desktop, and removes obsolete Coding launch paths (#6868)
- Proactive Mode reuses the active workspace, releases its resources when disabled, and uses lightweight web tools for research (#6712)
- MiniMax models and context limits are updated for the M3 and M2.7 generations (#6479, #6554)
- Plugin installation is more tolerant of packages that declare a newer compatibility ceiling (#6532)
🐛 Fixed
QwenPaw Creator
- Failed work resumes when inputs change, duplicate video renders are avoided, and stale scenes are reviewed before final composition (#6937)
Desktop
- Computer-use reuses the signed macOS app identity so permissions remain across launches (#6590)
- Desktop startup handles port errors; Windows shutdown checks are bounded and stay hidden (#6705, #6203)
- Chrome reconnects after interruption, packaged browsers are found on desktop, and Windows restore locking prevents concurrent recovery (#6669)
- QwenPaw OS Shell windows keep the menu bar visible, stay inside the viewport, and allow text selection and copying (#6801, #6861)
Runtime & Agents
- Provider-specific tool-call fields are no longer lost during streaming, history storage, compaction, or replay (#6759)
- When a model reports a context-limit error, Scroll compacts the context and retries once; history migration also preserves session identity (#6267, #6068)
- Codex-backed Agents stay manageable when the Codex runtime is unavailable (#6664)
- Sub-agents inherit the current session approval level; an empty batch field no longer turns a single task into a batch request (#6508, #6595)
- Loop limits are written back for older configurations, and renamed per-tool entries persist (#6530, #6682)
- Shell execution preserves multiline commands and no longer hangs on inherited background pipes (#6412, #6748)
- Headless tasks construct the effective user message, and workspace commits use a local default Git identity when none is configured (#6616, #6350)
- Copying an Agent no longer creates empty Skills or scheduled-task scaffolding (#6493)
- Background sub-agent tasks wait for authoritative fork finalization and report failures without discarding worktree changes (#6725)
- Corrupted Agent configuration and invalid JSON produce a recoverable configuration error instead of breaking config loading (#6615)
- Scroll recall finds complete CJK turns for substring and multi-term searches and rejects reversed expansion ranges (#6824)
- Legacy sessions load local-path media again, including Windows UNC paths and percent-encoded non-ASCII paths (#6873)
- Memory hints no longer break conversations, and ordinary non-streaming responses can generate chat titles (#6360, #6816)
- Continuation summaries respect disabled thinking and preserve interruption or timeout behavior (#6818)
- Headless ACP sessions honor temporary model context and output limits without saving them (#6933)
Console & UI
- Reconnects and Agent switches no longer restore the wrong chat, stale channel, or duplicate pending messages (#6602, #6546, #6382)
- Rich messages enter the send queue, and multi-file previews wrap inside the composer (#6798, #6662)
- Large tool output uses a bounded preview, and long commands wrap inside cards (#6637, #6677)
- Tool controls stay hidden until streaming finishes (#6749)
- Settings stays visible when the sidebar is collapsed (#6488)
- Production Console builds no longer omit dependency CSS (#6639)
- Chat wheel scrolling stays stable, and the load-more spinner no longer runs while off screen (#6904, #6896)
- The header resources menu no longer shows a duplicate GitHub link (#6903)
- Workspace previews support Unicode PDF filenames and SVG media types, with corrected dark-mode styling for preview and edit surfaces (#6915)
- Long multiline assistant and tool output preserves line breaks, while wide code blocks and tables scroll within their containers (#6890)
- Chat falls back to the standard textarea input, and desktop and end-to-end verification support both textarea and contenteditable inputs (#6934)
- Image uploads no longer inflate the context-usage ring by counting Base64 data as text (#6968)
- Large screenshots can be previewed, and completed tools no longer keep a spinning status icon (#6965, #6967)
- Daily memory notes are grouped and sorted by their path date (#6941)
Governance & Security
- Browser debugging requires authentication unless the user explicitly opts out (#6500)
- Project import only reads approved paths and reports skipped sensitive folders (#6487, #6713)
- Sandbox cleanup handles interrupted sessions; invalid settings fall back without crashing and display a warning (#6600, #6582, #6747, #6857)
- Sandboxed child processes no longer inherit
PYTHONHOME, preventing them from resolving the wrong Python runtime (#6902) - Conversation command arguments are no longer written to logs (#6692)
Memory
- Fix memory and checkpoint saving during context migration and web-workspace recovery (#6592, #6597)
- Automatic-memory progress survives context compression and session recovery; failed submissions can be retried without polluting chat history (#6830)
MCP
- Terminated MCP sessions recover without dropping every tool from the active Agent (#6894)
CLI & Channels
- Scheduled tasks fire while the service is idle (#6481)
- Pausing and resuming a scheduled task preserves its enabled state (#6691)
- Scheduled-task results follow the configured delivery behavior, including migrated tasks (#6182, #6511)
- Pausing or resuming a missing scheduled task returns a not-found response (#6858)
- The task command reports a missing Agent configuration without printing a traceback (#6865)
- CLI project paths are accepted after global options (#6892)
qwenpaw update --prereleasenow discovers newer prereleases from PyPI (#6939)- OneBot listens locally by default and requires a token when exposed to the network (#6676)
- OneBot configuration declarations stay aligned with the configuration API (#6864)
- Channel approvals preserve routing fields through the driver gate, and Xiaoyi messages hide internal Scroll headlines (#6833, #6888)
- DingTalk organization approval now fills returned credentials into channel setup (#6709)
- Matrix can connect and decrypt messages on Python 3.12 (#6486)
- Timestamps without a timezone are interpreted consistently as local process time (#6685, #6855)
Other
- Backup restore waits for the background operation to finish and accepts zero-byte lock files (#6735, #6703)
- OpenRouter preserves known multimodal support and retries recoverable stream or reasoning errors (#6733, #6714, #6721)
- Video input is forwarded to models that declare video support, and channel audio is transcribed again (#6495, #6573)
- Local images keep their original content across file changes, and temporary media errors no longer disable multimodal support (#6930)
New Contributors
- @axelray-dev made their first contribution in #6412
- @WilShi made their first contribution in #6477
- @FittyAr made their first contribution in #6479
- @yaodong-shen made their first contribution in #6502
- @niuda-kok made their first contribution in #6531
- @GMsure made their first contribution in #6543
- @ningblue made their first contribution in #6723
- @AntiQuality made their first contribution in #6898
- @xingliu228 made their first contribution in #6873
Full Changelog: v2.0.1...v2.1.0