# 1.8.8b10 — the second walk

**Never published** — the tag's build failed; the same changes shipped as
[1.8.8b11](1.8.8b11.md).

An opt-in preview. Stable remains 1.8.7; the Personal Wiki becomes long-term
supported in 1.9.0.

1.8.8b9 carried what five testers found installing 1.8.8b7 into empty
profiles. The same five walks were then run again against b9 as published.
The fixes held: a stale approval on a second device is refused, a visitor sees
only their own runs, the install line resolves stable dependencies. This
preview is what the second walk found.

![co trust and co create now fail with a non-zero exit](assets/v1.8.8b10/exit-codes-that-mean-it.png)

## The browser always answers

- Every `co browser` command now ends within its deadline: 120 seconds, or its
  own `--timeout` plus 15. When Chrome's cookie store waits on a macOS Keychain
  prompt, `co browser cookies --all` and `save_state` used to hang forever and,
  one by one, fill the daemon until even `close` was refused. They now stop and
  say what they waited on; a client that leaves takes its command with it; and
  `status`, `close`, `tab ls` and `tab close` are never answered "busy"
  (#1709).
- The daemon no longer asks Chrome for its cookies after every command with no
  time limit, which leaked one connection per command; `co browser status`
  answers within seconds; a selector that matches nothing, a missing script or
  page, and a bad URL are failures with a non-zero exit (#1704, #1709).
- Read commands such as `get_current_url` no longer start a daemon when none is
  running, so a later `--headless` is not silently ignored.

## Hosting

- A device that joined a session in the first seconds after the host started
  missed the whole next turn — also on 1.8.7. It joins the session's viewers
  before its Home page renders now (#1708).
- `connect()` after a host restart mid-turn raises `TurnLostError` naming the
  session instead of "Auth error: Agent not connected"; a slow `on_approval`
  is declined at the deadline instead of leaving the host waiting; a script
  with no terminal is told to pass `on_onboard=` instead of hitting `EOFError`.
- `co trust add` refuses anything that is not an address. The `host.md` Quick
  Start runs as written.

## First run

- The benchmark example `co benchmark list` prints carries its own data, and
  `co eval run` stops an attempt at 10 steps (`--max-iterations` raises it).
  On the `co create` template the old example cost about $1.00 for five cases;
  `co eval run` now says what it will run before the first model call and
  suggests `--runs 1` (#1707).
- `co create` into an existing folder and `co deploy` with no `agent.py` exit 1,
  and `co create` now refuses the folder before a first run makes a keypair and
  signs up for an account.
- `connect()` with no identity says to run `co init`. Planning notes and
  internal design records no longer ship in the wheel.

## Consent

- `co wiki start` asks again whenever what it showed you changed — the model
  provider, the permissions, the schedule — instead of only when a source is
  added; the summary names the login the runner really uses (#1706).
- `co claude run` stops the Claude process it started when it is terminated,
  instead of leaving it running unsupervised.
- `co wiki init --name` makes your own page without a mailbox.

## Still open

- The web client (`@connectonion/react` 0.4.4-rc.6) must send `request_id`
  before a session open on two browsers can answer approvals; until then that
  case is refused rather than guessed.
- `co auth status` still signs you in, as on 1.8.7; its fix (#1693) is in
  review.

## Install

```sh
python -m pip install --upgrade 'connectonion==1.8.8b10'
co --version
```
