{"slug": "ototo-2026-15", "title": "Otōto 2026.15", "summary": "Otōto released version 2026.15 beta5 in October 2026, changing its ask feature so Claude no longer receives the whole task including the fix and tests, and instead is told that ask reports what the code does while deciding changes itself. Updating rewrites Otōto's hook in settings.json and its block in CLAUDE.md with the new wording, and users upgrade from 2026.14 with ototo update. The release follows 2026.14 beta5, which added ototo forge --ref for querying a tag's pipeline and fixed ototo doctor falsely marking working model endpoints as ✗.", "body_md": "What each release added or changed, as its package's own notes say. ototo update installs the newest; the feed tells a feed reader, or your team's chat, when there is one.\n\n2026.15 beta5 October 2026\n\nask finds and explains; the fix is Claude's. Claude was handing ask its whole task, the fix and its tests included, and the small model answered that part too. Claude is now told that ask reports what the code does, and that what to change is its own to decide. Asked for a fix all the same, the small model reports what bears on it and says which part it left.\n\nUpdating rewrites Otōto's hook in settings.json and its block in CLAUDE.md with the new wording.\n\nUpgrading from 2026.14: ototo update.\n\n2026.14 beta5 October 2026\n\nototo forge finds a tag's pipeline.ototo forge --ref <name> (ref for the tool) asks about another branch, or a tag, in place of the checked-out branch, and a checkout at a tag asks about the tag. A release's pipeline runs under its tag, and could not be asked for before.\n\nototo doctor no longer calls a working model's name wrong. Some servers list one name and answer to another (a vLLM started with a served name answers to the model's own too). Doctor went by the list and marked the endpoint ✗; it now asks for one token under the name in your settings before saying so.\n\nUpgrading from 2026.13: ototo update.\n\n2026.13 beta3 October 2026\n\nVersions now say the year. A version is the year, the release's count in that year, and the patch to it: 2026.13 is 2026's thirteenth release, and a fix to it would be 2026.13.1. It comes after 2.12.1: ototo update and ototo plugins compare versions number by number, as they always have, so it is offered as the newer one.\n\nOtherwise the same as 2.12.1.\n\nUpgrading from 2.12: ototo update.\n\n2.12.1 beta3 October 2026\n\nSecurity: the plugin runtime is updated. Wasmtime, which runs Otōto's plugins, moves to 48.0.4 for seven advisories published on 2 October (RUSTSEC-2026-0321 to 0327), one rated critical. A plugin runs only when signed by a key you trust, which narrows who could exploit them; update anyway.\n\nUpgrading from 2.12: ototo update.\n\n2.12 beta2 October 2026\n\nAn answer that was cut off says why. \"Turn budget exhausted\" used to be said of every answer the small model did not finish by itself, whatever had stopped it. Now the footer says which it was, each beginning \"cut off\": out of turns, out of tokens, stopped for repeating its calls, or answered without finish (so nothing in it is cited). The run log has it as ending, and ototo report and ototo tail say it too.\n\nA question that will not finish stops sooner. A question may now send the model 400,000 input tokens over all its turns, far more than a question that finishes needs; past that, its next turn is the last, and it answers with what it has, where it used to run through every turn first. max_input_tokens in config.toml changes it, and 0 turns it off.\n\nThe dashboard counts before it grades. The first reliability tile is now \"Finished, not cut off\": \"4 of 7 answers finished\", what cut the others off, no grade under twenty answers, and advice by cause (more budget helps an answer that ran out of turns or tokens, not a model that repeats itself).\n\nA forge token for one project, or one group. The gitlab plugin's token was chosen by host, so a project access token, the narrowest GitLab makes, worked in one repository and got 404 in the others. Beside a host's token there can now be [plugin_settings.gitlab.projects.\"group/project\"] and [plugin_settings.gitlab.projects.\"group\"] (under hosts.\"<host>\" for a GitLab of your own): the longest path that holds the repository's project gives the token. ototo plugins help gitlab and ototo doctor, in a repository, say which token it is asked about with (the setting's name, never the token), and when its variable is not set where Otōto runs; when GitLab refuses, ototo forge says the same after the error.\n\nA grant or a new token works at once.ototo plugins grant gitlab, or a token added to config.toml, is read at the next forge call: no new session. A job's log of up to 200 lines now comes back whole.\n\nThe note beside a Read asks for nothing. When Claude reads a file a plugin evaluates (a compose file, a kustomization), Otōto's Read hook adds a note. It now says what it is, that the Read goes ahead, and what Otōto's outline and read give for that file; it no longer tells Claude what to do instead.\n\nA macOS download you can check on any Mac.sh dist/reproduce.sh rebuilds the commit a release was built from and compares it with the download. From this release the macOS binary comes out the same byte for byte on any Mac with the same Xcode, as the Linux binary and the plugins already did. (For 2.10 and 2.11 the script now says so when a rebuild matches in everything but a 16-byte identifier the linker adds.)\n\nUpgrading from 2.11: ototo update, as before. The installer rewrites its line in CLAUDE.md (\"says it was cut off\", where it said \"its turn budget ran out\"); restart open Claude Code or OpenCode sessions.\n\n2.11 beta1 October 2026\n\nInside JARs, without unpacking.ototo outline lib/core.jar lists a JAR, WAR, wheel or any other ZIP by directory, with what its manifest says, and ototo read lib/core.jar!org.demo.Shelf gives a class as its declarations: generics, throws, parameter names and constants, read from the class file itself, with no unzip, no javap and no JDK. Any other entry reads like a file (lib/core.jar!META-INF/MANIFEST.MF, with :10-40 or #name), a library inside a WAR is one more !, and a class says where its source is when a -sources.jar sits beside the JAR. Nothing is unpacked to disk, and a secrets file in an archive is neither listed nor read. Claude is told: the CLAUDE.md block gains a line, and the Bash hook now sends unzip -l, unzip -p, jar tf and javap on such a file to ototo read.\n\nIt is a plugin, archive, of a new kind. It comes with this package like the others. A plugin of this kind is lent the bytes of the files its own globs name (.jar, .zip, .class…), read-only, and nothing else: no other file, no network. ototo plugins shows it as \"opens …\".\n\nYour dependencies' JARs, if you say so. A dependency's JAR is usually outside the repository, where Otōto reads nothing. dependency_caches = true in config.toml lets read and outline look into the archives in ~/.m2/repository and ~/.gradle/caches (or the directories you list), by absolute path: archives only, nothing else there, never a write, and off unless you set it. /add-dir ~/.m2/repository in Claude Code is the other way, for one session. An organisation can enforce the setting, off included, and ototo doctor says which directories are read.\n\nPlugins are published on their own. A new or fixed plugin no longer waits for a release of Otōto: each has its own version, and the download channel has a signed index of them. ototo plugins available says how each stands to the one you have (the same, newer, or in need of a later Otōto), and ototo plugins update brings yours up to the channel's. It only goes forward a version, and nothing updates by itself. The index must be signed by Otōto's release key, and each plugin still needs its own signature by a key in your allowed_signers.\n\nA plugin you can rebuild. The index names the commit each plugin was built from: sh dist/reproduce.sh --plugin archive in the source rebuilds it and compares it with the channel's file, as sh dist/reproduce.sh does for a release.\n\nUpgrading from 2.10: ototo update, as before. It installs the archive plugin with the rest; restart open Claude Code or OpenCode sessions to load it.\n\n2.10 beta1 October 2026\n\nSeveral agents at once, also on few CPUs. A session's agents share one Otōto, and on a machine with one or two CPUs (a CI runner, a small container) one agent's slow step could stop every other call until it ended. The small model's tools no longer hold the server's threads: a quick read stays quick while another agent's ask or build check runs. Build checks (check_cmd) in one checkout now take turns, and one that waited says for how long.\n\nPlugins one by one.ototo plugins available lists the plugins the download channel offers, with their tags (ototo plugins available java) and whether each is installed here; ototo plugins add <plugin> installs one, ototo plugins update brings the installed ones up to the channel's, ototo plugins remove <plugin> deletes one, and ototo plugins list --json is for scripts. A plugin from the channel is installed only when the release's plugins index is signed by Otōto's release key, the file has the index's checksum, and its own signature is by a key in your allowed_signers. https://ototo.dev/plugins lists them too.\n\nOpen source. Otōto's source is at https://gitlab.com/handmadedigital/projects/ototo, under MIT or Apache-2.0, your choice. This package carries both licences, NOTICE, and THIRD-PARTY-LICENSES.txt, the licence texts of the crates it is built from.\n\nA release you can rebuild.BUILDINFO in this package says which commit it was built from, and with what; sh dist/reproduce.sh in the source rebuilds that commit and compares the binary and every plugin with the download. The Linux binary and the plugins are built in a container image named by its digest; the macOS binary comes out the same with the same Xcode.\n\nLinux: older distributions too. The Linux binary is now built against glibc 2.31 (it was 2.35), so it also runs on Ubuntu 20.04, Debian 11 and RHEL 9, and on what is newer.\n\nReporting: Otōto's OpenTelemetry series now carry service.namespaceototo (it was fleet): a dashboard that filters on it needs the new name, or otlp_attributes can set the old one.\n\nWith no model server set anywhere, Otōto now tries http://127.0.0.1:8080/v1, this machine's own.\n\n2.9 beta30 September 2026\n\nInstall and update without a package in hand.curl -fsSL https://ototo.sh | sh installs the newest release for this machine, and ototo update fetches it from the same channel (update_url in config.toml points at your own mirror). Both check the release against Otōto's release key before anything is installed; ototo update --check only says whether there is a newer one. A package in ~/Downloads still works as before.\n\nsearch: exact text or a regex across the repository, as path:line hits, with globs, whole words and case folding; for Claude Code and OpenCode, and as ototo search. No model, so it answers at once.\n\nFour new plugins, signed and in this package: - maven: a dependency's effective version and scope, through parents, BOMs and properties (ototo read pom.xml#spring-core); - spring-config: a property as each profile sees it, and where each value is set (ototo read spring.datasource.url); - terraform: a block with its variables and locals worked out, per environment (ototo read aws_db_instance.main@prod); - kube: a Kustomize resource as it builds, and a Helm value with the templates that use it.\n\nForge plugins, and forge. The gitlab plugin answers about the branch's merge request, a pipeline by stage and a failed job's log, cut to what failed, for Claude Code (the forge tool) and as ototo forge. It reaches the network only once you grant it: ototo plugins grant gitlab, then a token in [plugin_settings.gitlab] (or per host, for a self-hosted GitLab). It never sees the token; Otōto adds it.\n\nototo plugins lists the plugins, and ototo plugins help <plugin> says what one reads and adds.\n\nchanges for one commit or a range: --commit <sha>, --range A..B, told by declaration like a branch's.\n\nBuilds and tests through ototo digest. In auto mode the hook runs Claude's plain builds and tests (cargo, mvnw, gradlew, npm…) through ototo digest, which keeps the failures, the errors and the summary; in other modes it suggests it. OTOTO_FULL=1 gives the whole output.\n\nA note when Claude reads a file a plugin reads, naming the plugin and the ototo read that answers better.\n\nEdits the ordinary way. The instructions now say to Read the lines to change, then Edit, rather than writing files with python or sed.\n\nProgress while ask works: the turns so far and the latest step, and every 30 seconds while the model server is quiet, what it is waiting for. Claude Code no longer ends a long ask for having heard nothing for 30 minutes.\n\nOne more try when every model server failed in passing (a dropped connection, 502, 503, 504, 529), after 2 s; errors say what failed.\n\nFewer false flags in the claim check: it reads a declaration's doc comment, the file's own comments and the whole of a declaration, and quotes a name found elsewhere in the file with its line.\n\nototo doctor shows what it is checking, and each model server as it finishes.\n\nThe dashboard's \"Claude tokens avoided\" estimate is gone.\n\nComing from 2.8.5 or earlier? 2.8.6's tidier ototo --help is new to you too.\n\n2.8.6 beta29 September 2026\n\nA tidier ototo --help. The commands are grouped by what they do: asking the small model (ask, locate, callers, edit, routine), reading the code with no model (read, outline, find, changes, history, replace, digest), watching and checking (tail, ui, doctor, report), setting up and updating (init, update, managed, settings), and the server Claude Code and OpenCode start (serve). Each has a one-line description; ototo <command> --help has the rest.\n\nComing from 2.8.4 or earlier? 2.8.5's changes are new to you too: routines, and the reporting names (INSTALL.md, \"New in beta 2.8.5\").\n\n2.8.5 beta29 September 2026\n\nRoutines (experimental). A job you do again and again, described once in a markdown file, done by Otōto's small model with its read-only tools: ototo routine list, ototo routine run <name> [input], ototo routine new <name>. install.sh puts five examples in ~/.config/ototo/routines/ (the CI jobs, the dependencies, the HTTP endpoints, the configuration, and a file's ticket number and summary for Jira), never over a file of the same name. Claude Code and OpenCode get a routine tool only with routines = true in config.toml; until then nothing changes for them. routines/README.md shows how to use them and write your own.\n\nReporting that fits beside our other products, when you send Otōto's counts to a collector: service.namespace, the standard OTEL_RESOURCE_ATTRIBUTES read as well as otlp_attributes, and OpenTelemetry's own names for tool calls (mcp.server.operation.duration) and small-model tokens (gen_ai.client.token.usage) beside Otōto's. Otōto's own metrics are unchanged.\n\nototo update keeps what it unpacked, so the \"Undo all\" path install.sh prints at the end still works.\n\n2.8.4 beta29 September 2026\n\nototo update. Put the package we send, with its .SHA256SUMS and .sig, in ~/Downloads and run ototo update: it checks them against Otōto's release key, then runs the package's install.sh, which keeps your settings. --dry-run only checks; a path picks another package. This one you still install with sh install.sh.\n\nOpenCode.install.sh now sets Otōto up in OpenCode too, beside Claude Code or on its own. In ~/.config/opencode/opencode.json it registers Otōto with 30 minutes for each call (OpenCode otherwise gives up on a tool after about a minute, and an ask can take longer), lists Otōto's instructions (your own AGENTS.md is left as it is), and turns OpenCode's own grep and glob off (--keep-search keeps them). A config with comments is left alone, and it prints what to add by hand. ototo doctor checks it; uninstall.sh takes it out. Set OpenCode up by hand before? Its mcp.ototo needs \"timeout\": 1800000.\n\nFewer wasted reads. A list of files sent as a string of JSON (\"[\\\"src/a.rs\\\"]\") is now read as that list, not as one file that is not there.\n\n2.8.3 beta29 September 2026\n\nototo report, for when something goes wrong. It writes one file to send us: Otōto's version and your machine's, what ototo doctor finds, your settings with API keys and headers taken out, the run log's counts for the last week, and the messages of its latest errors. Not your questions, the code Otōto read or its answers. Read it, then send it with what you asked and what happened.\n\nReads Claude garbles still work. Claude sometimes sends read's or outline's list of files under another name, and Otōto used to answer \"give at least one target\", which did not say what was wrong, so Claude tried the same call again. Otōto now takes the list; and when a call has none at all, it says what the argument is called and what the call sent instead. The dashboard shows what such a call sent, rather than \"(not recorded)\".\n\n2.8.2 beta27 September 2026\n\nDirectories you add to a session. A Claude Code session can reach beyond the repo it started in (/add-dir, or claude --add-dir), and Otōto now works there too: an absolute path inside an added directory, or naming one in a question, is enough. It serves only what the session lists, never your whole home directory. A path outside all of them gets a note saying to add its directory with /add-dir first.\n\nSecrets stay out. Environment files (.env; not .env.example), private keys, credentials files (.netrc, .npmrc, .aws/credentials, …) and Terraform state are no longer read or listed by Otōto, so they never reach a model server. Claude Code's own tools are unaffected. read_secrets = true in config.toml turns this off.\n\nYour files are yours only. The run log, the live trace and config.toml are readable by you alone, and so is ~/.ototo; files from earlier betas are tightened on first use, and ototo doctor warns about any that are not.\n\nThe dashboard needs its link. Its data now needs a key only you can read, so other users on the machine cannot see your questions and answers through it. Open it once with the link ototo ui prints (ototo ui --link prints it again); the page remembers it. A bookmark of the plain address says how to get the link.\n\nHarder to steer through the code. The small model is told that what it reads in a repository is data, never instructions, and text in a file shaped like its own control tokens can no longer open a turn of its own.\n\nototo doctor warns when a model server or collector on another machine is reached over plain HTTP, and shows the check command (check_cmd) edits run, if one is set.\n\nSigned checksums. Each release now comes with ototo-<version>-<commit>.SHA256SUMS and its .sig. To check a download, save the key line from https://ototo.dev/release-key.txt as release-key.txt, then: ssh-keygen -Y verify -f release-key.txt -I ototo-release -n ototo-release -s <sums>.sig < <sums> and shasum -a 256 -c <sums> (sha256sum -c on Linux).\n\nFor organisations:ototo managed --install with --base-url and --model now enforces those model servers, so users cannot send code elsewhere; --allow-user-endpoints lets them add their own.\n\n2.8.1 beta27 September 2026\n\nFewer wasted turns. The small model sometimes answered its first turn in prose (\"no repository was provided\") or called Claude Code's tools by name. Now a prose answer is asked again with a tool call required (on servers that allow it), shell commands that only look at files (grep, cat, sed -n, ls, find) run as Otōto's own tools, and a search that finds nothing says why and which kinds of file the repository has.\n\nSafe from a model server's stale cache. On 27 September our vLLM server's shared prompt cache held wrong data for part of Otōto's instructions, and every question that reused it went wrong until a restart. Each question now keeps its own cache on the server (cache_salt), and ototo doctor checks whether a server's cache answers as a fresh request would, and says to restart it if not.\n\nRunning your own vLLM?vllm/README.md in this package has the flags we run, a chat template for coding clients (Qwen's own, plus what those clients send that Qwen's refuses) with a script that checks it, and what to do when the prompt cache goes bad.\n\nPlugins, sealed. Compiled plugins are cached with a key of your own (~/.config/ototo/cache.key, made on first use), so code put in the cache by anything else is compiled over, never run. The first start after upgrading compiles them once, in about a second.\n\nReporting: if your team collects Otōto's counts, they now carry your Claude account's e-mail, as Claude Code's own do, so the dashboard shows the two side by side per person without any setting. user.email= in otlp_attributes sends none, and ototo doctor says which address goes out.\n\nFor organisations:ototo managed --install run twice no longer loses the backup of the original settings, and ototo doctor no longer gives managed users advice they cannot take.\n\n2.8 beta27 September 2026\n\nA new look. Otōto has a new logo, ( • ): two arms round a little one, which is what otōto (弟, little brother) means. It is in the dashboard and on the tab's icon.\n\n(•) in the terminal.ototo ask, locate, callers and edit show the call on the last line while it runs: the time so far, the small model's turn and what it is doing. Through a pipe, or from Claude Code, nothing changes.\n\nThe dashboard (ototo ui): - Plugins: every plugin with its version, the files it reads, who signed it and whether it loads (and why not). Switch one off or on, remove it, or add one from its .wasm and .wasm.sig (only plugins signed by a key you already trust). - What the small model did is now a table that stays inside its panel: its own tools, tools it made up, turns it answered in prose, and garbled calls, with the share of turns wasted; click a row for examples. - Light, dark or automatic, from the switch at the top right.\n\nFor organisations rolling Otōto out to many machines: organisation-wide settings that users cannot override, ototo managed to push the setup to every machine through Claude Code's managed settings, and a fleet dashboard of what is running where. Ask us for the admin guide.\n\nFor your security team:SECURITY.md (what runs, what it reads, what leaves the machine) and sbom.cdx.json (every dependency and its licence) are in this package.\n\nVersion numbers:ototo --version now says 2.8.0, not 0.1.0.\n\n2.7 beta25 September 2026\n\nFixes plugins on macOS. Beta 2.6's Mac build was signed in a way that let macOS stop it the moment a plugin loaded, and Otōto loads plugins when it starts, so with the plugins installed Claude Code lost Otōto altogether (claude mcp get ototo said it failed). This build carries the permission plugins need.\n\nototo doctor checks the whole setup and says what to do about anything wrong: the settings, each model server (reachable, serving the model, and answering a test request with a tool call), Claude Code's registration, settings.json and CLAUDE.md, whether the plugins load and run, reporting, and the run log.\n\nototo init (what install.sh now runs) finds the model server, tests it, shows what it will change and asks. Run it again to switch models: ototo init --base-url <url>. --preset gpu-server|mac-bonsai|haiku|other picks the settings for that kind of model and shows what we measured on it; --haiku-fallback adds Claude Haiku as the paid last resort.\n\nDocker Compose files are read as Compose merges them (overrides, extends, include, .env values), by a second plugin: read compose.yaml#api is the api service as it will run.\n\n2.6 beta25 September 2026\n\nMore languages and formats: Go, C#, shell scripts and SQL (any dialect: tables with their columns, procedures, migrations); XML by element (Maven POMs, MSBuild, Spring: read pom.xml#spring-core); properties files; CSV by column; Dockerfiles by stage and Makefiles by target.\n\nWhat changed, and why: Claude can ask changes (what this branch changed, by function) and history (the commits behind some lines) instead of reading git diff and log output.\n\nTest output: Claude runs tests as ototo digest -- <command> and sees the failures and the summary, not every line. Your permissions still decide what runs.\n\nPlugins: GitLab CI jobs are read as GitLab runs them (includes, extends, anchors resolved), by a plugin: a sandboxed WebAssembly file that loads only because it is signed, by the key this package trusts for plugins.\n\n2.5 beta25 September 2026\n\nLinux. A build for x86-64 Linux, with the same installer.\n\nNo more reading code through Bash. A hook refuses Bash commands that only print lines of your repo's files (sed -n '10,40p', head, tail, cat, awk 'NR>=…') and tells Claude the ototo read to use instead; Claude had kept cd-ing into worktrees to read files that way. Anything else in Bash runs as before (pipes, redirections, other commands, files outside the repo). --keep-search leaves Bash alone.\n\nThe installer edits settings.json with ototo settings add|remove, on macOS and Linux alike.\n\n2.4 beta25 September 2026\n\nGit worktrees. If you work in a git worktree (a second checkout of the same repo, from git worktree add) while Claude Code was started in the main one, Otōto now reaches it too: Claude gives it a path inside the worktree, or names the worktree. Before this Otōto refused those files, so Claude read them itself.\n\n2.3 beta25 September 2026\n\nAgents use Otōto too. When Claude starts one of its own agents (to explore or audit code), a new hook tells the agent that Otōto is there and to outline files and read only the parts it needs, and the CLAUDE.md block tells Claude to say the same in the agent's brief. Before this, agents read whole files.\n\nUpgrading updates the CLAUDE.md block in place when it has changed (backed up first), instead of leaving the old one.\n\n2.2 beta25 September 2026\n\nWorks in plan mode. Otōto's tools now say which of them only read (all but edit and replace_all), so Claude Code's plan mode uses them without asking for permission.\n\n2 beta25 September 2026\n\nSigned and notarised with a Developer ID (beta 2.1), so macOS runs it without warnings.\n\nFallback endpoints. List several model servers in ~/.config/ototo/config.toml and each request goes to the first that answers; Claude Haiku can be the paid last resort (below).\n\nReporting. Counts (never code) to an OpenTelemetry collector, next to Claude Code's own metrics.", "url": "https://wpnews.pro/news/ototo-2026-15", "canonical_source": "https://ototo.dev/changelog#v2026.15", "published_at": "2026-10-05 22:17:00+00:00", "updated_at": "2026-10-06 08:48:21.222987+00:00", "lang": "en", "topics": ["ai-tools", "developer-tools", "ai-agents"], "entities": ["Otōto", "Claude", "Wasmtime", "GitLab", "vLLM"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/ototo-2026-15", "markdown": "https://wpnews.pro/news/ototo-2026-15.md", "text": "https://wpnews.pro/news/ototo-2026-15.txt", "jsonld": "https://wpnews.pro/news/ototo-2026-15.jsonld"}}