Skip to content
UHPUHPDeveloper Guide
Independent developer guide. Not affiliated with HarnessRouter or the official UHP project.

Qwen Code integration: UHP, ACP and Qwen Live

Qwen Code is an agent harness with its own CLI and host interfaces. HarnessRouter adapts it to UHP; Qwen Live Harness is a related standalone realtime application with a different installation and lifecycle.

Page reviewed 4 Oct 2026 Source and review policy

Current guidance and dated source history

Qwen’s current README advertises headless execution, SDKs and an experimental qwen serve daemon over HTTP/SSE. Those surfaces share a product family but do not give you interchangeable persistence or cancellation identifiers.

PathWhat the caller should own
qwen -p from a scriptProcess lifetime, selected project and machine output
A Qwen SDKThe SDK’s session/result contract for that language/version
qwen serveDaemon connection, session mapping and server lifecycle
Qwen through HarnessRouterUHP response/session IDs and adapter configuration
Qwen Live background connectionLive job receipt plus separately owned background session

Before combining Live and an existing daemon, identify whether Live starts that service or connects to a service the user already owns. Teardown must follow that choice. A stopped voice turn should not silently delete a user-owned coding session; a lost daemon connection should not be shown as completed background work.

For a small direct test, use the documented qwen -p "..." shape in a disposable project with explicit credentials, then inspect the result and changes. For a product-facing UHP test, use the CE API instead; do not send the same job through two paths while the first result is uncertain. Control-delivery evidence explains why an accepted steer/cancel command still needs outcome evidence.

The application/desktop/SDK matrix below remains the correct version choice. The generic repository latest endpoint currently returns an SDK tag; it cannot choose the CLI release on your behalf.

EntityCurrent reviewed coordinateWhat it means
Qwen Code CLIv0.24.7, 29 September 2026Application release
Qwen Code desktopdesktop-v0.24.7Separate desktop release tag
TypeScript SDKsdk-typescript-v0.1.17Library release, not the CLI version
Qwen Live HarnessStandalone projectRealtime Host/daemon and optional background harnesses
HarnessRouter adapterv0.29.0UHP server implementation release

These coordinates were reviewed on 4 October 2026. The GitHub “latest release” API can return an SDK tag for a repository that publishes several products; select the application release family explicitly.

For direct Qwen usage, follow the upstream project. For an interactive client/agent boundary, inspect Qwen’s native ACP support and negotiated capabilities. For a product that needs a common external execution contract, use the Qwen Code base through HarnessRouter. For voice and visual interaction, use Qwen Live Harness, including its platform and credential requirements.

HarnessRouter first shipped Qwen Code in v0.11.0. The earlier thirteen-backend statements below describe the September snapshot; the current whole implementation is maintained on the HarnessRouter page. Adapter support does not establish native Qwen UHP adoption.

Record the actual CLI version rather than inferring it from the desktop or SDK. Test task output, continuation, required tools, file artifacts and a failed/denied operation through the chosen interface. A Qwen daemon session, ACP session, Live job receipt and UHP Response each has a different lifecycle; map them explicitly if your application spans those boundaries.

The detailed release diary below remains useful for tracing when runtime controls appeared. It is not a substitute for checking your deployed version or a claim that all native host controls are exposed through UHP.

Historical source notes — baseline reviewed 19 Sep 2026

The following evidence preserves the earlier review and its links. “Current”, “stable” and “main” inside this section refer to that historical cutoff; they are not new release or compatibility claims. Use the guidance above for the current scope.

Qwen Code is a released HarnessRouter backend. PR #31, “feat: Qwen Code backend,” merged 27 August 2026 at commit 4e4a1a9; HarnessRouter v0.11.0 points to that commit. Qwen became HarnessRouter’s seventh backend. Cline later became eighth, Gemini CLI ninth, Oh My Pi tenth, Goose eleventh, Kimi Code CLI twelfth and Aider thirteenth.

The latest HarnessRouter stable release observed is v0.19.0, with tag commit ccf4af6647182e7175788353f8b0287829054e07. Checked upstream main is 387ad841551af02001ed6e9c85a25232f0ad9385, after post-release PR #216 corrected OpenCode generated-token accounting to include separately reported reasoning tokens and PR #214 aligned the console proxy’s upstream HTTP lifetime with long-running route semantics. Those post-release changes do not revise Qwen’s seventh-added adapter or establish a new Qwen-specific validation result. UHP remains 2026-09-12 Draft and the current conformance source remains 75 checks.

Upstream Qwen Code stable is now v0.24.1, published 19 September 2026 at 08:18:42 UTC. Release PR #12239 promotes the accumulated v0.24.1 release line, including the Browser Use stack and other host/runtime work that had previously been tracked here as post-v0.24.0 current-main behavior. Checked upstream main is now 42f9d13cdae0a7d462019487646bf7fb4995bf24 on the continuing development line. HarnessRouter has no reviewed Qwen-specific adapter revalidation against v0.24.1 or this current-main build.

Stable v0.24.1 now carries PR #11242 / b7543aeb, a substantial Browser Use stack for the user’s existing Chrome profile. Qwen’s Browser SDK and Playwright runtime connect through a local Native Messaging host and Qwen Chrome extension, so the skill can discover/claim tabs, run CDP-backed browser actions and use existing signed-in browser state without requiring qwen serve or an exposed Chrome remote-debugging port. The current user guide requires macOS or Linux, Chrome 125+, and a manually installed/enabled Qwen extension; there is no Chrome Web Store listing yet. The reviewed merge keeps one Browser Use session bound to one Chrome profile, releases debugger attachments and session decorations on disconnect without closing user pages, and leaves concurrent Browser Use sessions out of scope. Windows Native Host installation is not supported in this merge. Installing the extension authorizes Browser Use and grants the extension Native Messaging/history/tab-group access; browser content used by the agent may be sent to the configured model provider. Upstream reports 390/390 Browser Use tests, 99/99 Chrome-extension tests and 13/13 asset tests at the reviewed late verification point, plus real macOS Chrome 151 and Linux Chrome 145/149 checks under the PR’s stated limits. This is Qwen host/runtime capability, not an MCP, ACP or UHP wire revision, native Qwen UHP adoption, or a fresh HarnessRouter Qwen validation result.

Post-v0.24.1 current main separately carries PR #12198 / c9839a94, which changes workspace trust admission so an undecided workspace is treated as untrusted until the user explicitly trusts it, including the daemon fast-start path. Project settings, .env, hooks, instructions and MCP integrations therefore do not gain trusted-workspace authority merely because startup has not yet resolved the trust decision. This is Qwen host/security behavior on current main after the v0.24.1 release cut; it is not stable v0.24.1 behavior, a UHP/ACP/MCP wire change, or HarnessRouter Qwen revalidation. See workspace trust for the durable architecture boundary.

Stable v0.24.0 now carries PR #11636’s background-result automatic execution lifecycle identity across the ACP Session, daemon bridge, SDK, Web Shell and Qwen Live adaptor. Before the fix, automatic work could sit outside the bridge prompt lifecycle, inherit or lose the wrong prompt identity, make live-state appear idle during real execution, let user steering become an interrupting prompt, or lose queued results on stop/input paths. Same-execution results now consume at safe model boundaries, older results wait for their own automatic continuation, output/permissions/cancellation/replay/steering remain execution-bound, explicit stop retains pending results, and stale terminals cannot settle newer work. This is stable Qwen host/runtime behavior, not an ACP/UHP/MCP wire revision and not a fresh HarnessRouter Qwen validation result.

PR #11647 / 32a25efa, carried by stable v0.23.4 and retained by v0.24.0, hardens ACP settings ownership across daemon-hosted worktree sessions: core settings, memory and permissions resolve the requesting session’s stable workspace root; malformed or unknown session ids fail rather than silently retargeting the bootstrap workspace; request-scoped loads avoid injecting a foreign workspace .env into process-global state; session reads do not repoint the daemon-global settings cache; and workspace-scoped permission fan-out stays within the canonical workspace. MCP/hook/extension writes deliberately remain workspace-global because their status/reload/apply surfaces are workspace-global. The PR reports focused Linux ACP settings tests but explicitly does not claim that the real enter_worktree producer-to-consumer flow was demonstrated; issue #8138 remains open. This is stable Qwen host behavior, not a new ACP or UHP wire rule.

The earlier same-day PR #11280 (7e0beb9d) fixes a resume-time authorization-state gap: --continue / --resume could restore a loaded Skill’s instructions into conversation history without restoring that Skill’s allowedTools session rules or hooks: registrations. A PreToolUse gate could therefore disappear silently and fail open for the remainder of the resumed session. Resume now re-arms side effects only when the recorded Skill body still matches current SKILL.md content and a fresh invocation would still be allowed, awaits that re-arming before the first resumed turn, clears session allow rules when switching sessions, refuses to re-arm records found only inside forgeable exec output, and leaves slash-command-only Skill starts outside restoration because they have no tool-call record. Upstream’s reviewer E2E shows the blocked-command flag changing from no to YES before the fix and remaining no after the gate is re-armed; direct local validation was macOS, while Windows/Linux and container-sandbox legs were not locally validated. This is Qwen Agent Skills/session authorization state, not MCP Skills Over MCP, ACP or UHP wire semantics.

The earlier same-day advance through PR #9402 (00180c53) added the experimental Agent Board, a filesystem-backed coordination surface for independently started local agents and programs. A board stores tasks and questions under ~/.qwen/boards/, uses explicit --board / --as identity labels, exposes stable JSON and wait exit statuses, and protects updates with exclusive creation, validation, locks and atomic replacement. It deliberately does not launch, join, wake, monitor or send input to agent processes, has no participant roster/heartbeat, treats actor names as labels rather than authentication, and is not Agent Team or Qwen’s cross-session messaging transport. Upstream also marks the on-disk format experimental and says multiple agents writing the same checkout are unsupported.

The earlier same-day advance through PR #11763 (f1d5a64b), PR #11289 (79dabcb8) and the three-commit macOS Computer Use stack through e6647b3a remains relevant. PR #11683 (2eaed750) fixes stale REPL state, input/window/AX failures and avoidable recovery; PR #11705 (5f57c78b) adds app-bound native actions, compact AX observations and macOS text/paste operations; PR #11735 (e6647b3a) bounds returned observation text to 12,000 characters by default while keeping current action IDs independent of that text budget and reduces avoidable model round trips. In its five valid paired VM cases, PR #11735 reports the same 3/5 task score on both arms with total tokens down 15.9%, agent time down 6.9% and model responses down 17.9%, but uncached input up 48.2%; upstream explicitly says those single-trial whole-stack figures do not establish lower billing cost or per-patch causal gains. PR #11763 fixes a Desktop AppImage MCP-startup failure by stripping inherited AppImage PYTHONHOME / PYTHONPATH only from stdio MCP child environments under the desktop marker; standalone CLI inheritance is unchanged and an explicit per-server env still wins. Issue #11718 records Python virtualenv MCP servers crashing at interpreter startup because the foreign AppImage Python home was inherited. Upstream reports 134/134 focused MCP-client tests, while explicitly noting that a real GUI/AppImage host was not available for end-to-end validation. PR #11289 separately hardens Web Shell follow-up finality around the turn-end idle race: the daemon can return reason: "session_idle", and the browser reconciles against authoritative pending-prompt state instead of dropping, double-echoing or blindly removing an ambiguous follow-up. The release also carries PR #11606’s DashScope request-metadata isolation, PR #11291’s bounded recovery for provider-traced status-less stream failures, PR #11643’s bundled-ConPTY/reconnect hardening, PR #11443’s saved-file LSP synchronization, PR #11669’s internal-Git execution hardening and the previously documented workflow-effort/tool narrowing, stalled Goal-checkpoint batching, provenance, skill-identity, browser-local-files, Stop-hook, ACP-child resource, Agent Team assignment, daemon REST/OpenAPI, command-hook timeout, telemetry-privacy, unified workspace-history, ACP attachment-filename, graceful Companion ACP-shutdown and active-todo continuity work. Because v0.23.4 was cut from a release branch, the tag and moving main were separate coordinates. These shipped changes remain in the later stable line and do not change UHP, MCP or ACP wire contracts by themselves.

The Qwen runner maps the upstream CLI into HarnessRouter’s backend contract:

  • Structured execution: headless stream-json; HarnessRouter reuses the compatible structured normalizer while preserving streaming.
  • Session continuation: resumes the prior Qwen session; non-interactive auth is pinned on resumed turns.
  • Credential handling: provider key/base are process environment inputs rather than persistent Qwen settings secrets.
  • MCP and instructions: configured MCP servers use Qwen’s mcpServers settings shape; harness instructions use QWEN.md.
  • Workspace durability: Qwen home is redirected inside the session .harness/home tree so settings/skills/session state participate in HarnessRouter checkpointing.
  • Tool restrictions: the released integration relies on instruction-level enforcement rather than claiming a Qwen-native hard kill switch for every individual tool.
  • Provider routing: Qwen participates in supported OpenAI-shaped provider families and custom Chat Completions routes; provider availability is separate from backend availability.

These are HarnessRouter implementation choices, not UHP requirements.

The original integration records a fresh headless turn, a live relay-backed file tool-use turn, resumable session behavior and runner tests. Functional backend evidence should not be conflated with a dedicated current Qwen-specific UHP conformance run.

HarnessRouter v0.12.1 also fixed a catalogue/routing defect that could cause a user-created Qwen harness to fall through to Codex when a handwritten inference chain omitted qwen. The catalogue-derived correction is reference-implementation routing hardening, not a Qwen or UHP protocol change.

HarnessRouter v0.15.6 verification relevance, retained through v0.19.0

Section titled “HarnessRouter v0.15.6 verification relevance, retained through v0.19.0”

Qwen’s direct adapter behavior is not materially changed by v0.15.6, but that release matters for interpreting current reference-implementation evidence:

  • PR #136 makes runnable-model availability yes / no / unknown and does not let an unknown catalogue state become selectable.
  • PR #137 tightens same-model normalization, restore retry/failure classification, CLI-only error recognition and final connection attribution.
  • PR #138 extends the custom-harness verification dimension to a real MCP server and reports candidate coverage across all ten built-in harness bases when its external endpoint is reachable.

PR #138 is not a new Qwen-native protocol feature and not UHP conformance. It is a HarnessRouter custom-harness/runtime test dimension that now covers a real MCP call instead of leaving the MCP-server path untested. Current v0.19.0 retains these Qwen-relevant coordinates; the later backend/runtime/release work does not create a Qwen-specific adapter revision or a fresh Qwen-specific validation result.

Stable v0.23.0: preceding release-maturity boundary

Section titled “Stable v0.23.0: preceding release-maturity boundary”

Qwen Code v0.23.0 made previously tracked nightly/current-main work stable, including standalone Web Shell chats, concurrent named Channel tasks, Agent Team round-boundary message delivery, MCP AUTO-mode argument projection, VS Code WebShell/daemon cutover, trusted-loopback operator access, MCP GET/SSE 404 compatibility, Windows no-follow hardening, Computer Use/Node REPL hardening, model-proposed Goals, Qwen Live milestones and own-process IPC provenance.

That release remains an upstream Qwen behavior milestone. HarnessRouter’s original binary-first backend evidence was against an earlier Qwen build and should not be silently treated as a complete matrix for all later upstream features.

Stable v0.23.1: cross-session messaging finality and trusted controllers

Section titled “Stable v0.23.1: cross-session messaging finality and trusted controllers”

Qwen Code v0.23.1 promotes the previously tracked preview messaging work to a stable release and adds a user-authorized controller origin for external programs:

  • PR #10809 distinguishes policy-level refused from user-reviewed denied receipts and gives held messages bounded expiry (1m, 5m, 10m, never; default 5m).
  • PR #11026 replaces the implicit approval-mode table with two review classes — prompting and bypass. With no explicit inbound policy, auto-delivery occurs only between sessions in the same class; unasserted senders are held. Workspace policy may make this stricter but never looser than user/system policy.
  • PR #10090 rejects an ambiguous send_message that carries both teammate and background-task destinations instead of silently choosing one namespace.
  • PR #11090 lets the user mint a trusted-controller token for a non-session program such as a voice front end or automation relay. The token is shown once; Qwen stores only its SHA-256 hash in a 0600 controller registry. Controller identity is vouched for by connection authentication rather than by a frame claim. The default gate admits a valid controller without per-message review, but an explicit crossSessionInbound: "hold" or "refuse" still wins, and revocation takes effect on the next connection.

The controller grant is deliberately narrower than unrestricted user impersonation. The model-facing notice says a trusted controller can relay what the user wants done next, but it cannot change permission settings or stand in for the user when a pending confirmation asks for approval. It is also a bearer credential: possession authorizes controller-origin delivery across sessions under that Qwen home until revoked. PR #11090’s reviewer evidence is POSIX-focused: Linux is validated, macOS uses the same path but was not locally exercised, and Windows is N/A because the inbox is POSIX-only in that implementation.

These are Qwen runtime/security semantics, not UHP messaging or authorization rules.

Stable v0.23.1: daemon/session and browser-host boundaries

Section titled “Stable v0.23.1: daemon/session and browser-host boundaries”

The same stable release carries several durable host/runtime changes that were previously tracked only on the prerelease line:

  • Web Shell becomes the maintained browser transcript path after retirement of the legacy @qwen-code/webui workspace; exported transcript HTML pins an exact renderer identity with SRI and fails closed when unavailable/integrity-invalid.
  • Daemon-backed Goal turns honor verification checkpoints so a terminal Goal signal can settle the turn before independent verification, rather than remaining trapped in same-turn tool loops.
  • Skills become workspace-runtime scoped rather than implicitly tied to a primary workspace/session model.
  • Session resources and turn navigation are explicit daemon/protocol surfaces.
  • Conversation writers use mandatory writer leases; named Channel tasks can opt into worktree isolation.

These remain Qwen product/host architecture and should not be projected into UHP or HarnessRouter unless the adapter has explicit evidence for them.

Stable v0.23.2: remote serving, overload finality and replay/tool fidelity

Section titled “Stable v0.23.2: remote serving, overload finality and replay/tool fidelity”

Qwen Code published v0.23.2 on 9 September 2026 at 10:51:34 UTC, tag commit f56de980b316cd5410f067fbb62357481ebd66b8. The release reports no known breaking changes and makes the earlier v0.23.2-preview.0 CI-only coordinate obsolete as the current upstream release at that point.

The integration-relevant stable changes include:

  • Remote daemon startup becomes an explicit operator flow (PR #11172): qwen serve gains one-command remote start with a generated token, same-origin Web Shell access and pairing QR. This is Qwen’s own remote-host/authentication surface, not UHP remote execution.
  • Peer overload becomes explicit rather than silently unbounded (PR #11277): peer messages arriving faster than a session can consume are dropped under the new bound and the sender is told once. This is Qwen IPC flow-control/finality behavior, not a UHP event or error rule.
  • Workflow-agent failures are durably represented (PR #11196): failed agents are journaled and their workflow result settles to null, tightening failure visibility inside Qwen’s orchestration runtime.
  • Headless resume preserves prompt identity (PR #11062): daemon prompt identity is persisted for active transcript replay so repeated same-text turns can be distinguished and replayed against their trusted prompt identity.
  • OpenAI tool-schema compatibility is stricter (PR #11431): Qwen omits parameterless OpenAI tool schemas rather than emitting an incompatible empty parameter shape.
  • Model reasoning controls expand (PR #11295): GPT-5 and GPT-6 reasoning-effort configuration becomes a documented stable capability. This is provider/model configuration, not UHP capability negotiation.

The release also includes interactive permission-card work, browser/Web Shell changes, Goal-budget guidance, web-search/provider updates and dependency/security maintenance. Those are kept out of the UHP mapping unless they affect a protocol or adapter boundary.

The official ACP protocol matrix generated on 19 September 2026 at 09:33:55 UTC directly probes Qwen Code 0.24.0. Initialization succeeds with agent authentication and advertises loadSession, session/list and session/resume. This is point-in-time evidence for the exact tested 0.24.0 package. The official registry advanced the Qwen distribution to 0.24.1 about 26 minutes later, at 09:59:26 UTC, so the matrix must not be rewritten as direct 0.24.1 evidence.

Stable v0.23.3: ACP-mediated external subagents and daemon session identity

Section titled “Stable v0.23.3: ACP-mediated external subagents and daemon session identity”

Qwen Code published v0.23.3 on 10 September 2026 at 14:56:46 UTC, after the 10 September matrix that first covered the previous package line. The release reports no known breaking changes. Three changes are especially relevant to harness interoperability:

  • External subagent turns over ACP (PR #11003): a Qwen subagent definition can delegate its turn to an external agent process through ACP; Claude Code is the first wired executor. Qwen remains the parent runtime and republishes external activity through its own event stream so transcript, permission and virtual-subagent/session surfaces remain under the host. Malformed or unknown executor configuration and unsupported constraints fail explicitly rather than silently falling back to an in-process child, and the host’s permission policy bounds the external executor. This is ACP-mediated harness composition inside Qwen, not a UHP hop or a new ACP wire primitive.
  • Daemon-managed ACP sessions become first-class Qwen session identities (PR #11488): ACP sessions hosted by qwen serve register in Qwen’s session registry, can be observed through session tooling and can send peer messages. The implementation gives sessions distinct process-local identities; inbound peer messages to daemon-managed sessions are refused when no human-holding review UI exists instead of being indefinitely held. These are Qwen session/IPC semantics layered around ACP, not stable ACP-v1 session semantics.
  • ACP tool execution receives shell presentation settings (PR #11102): terminal width, height and color preference are forwarded into ACP tool invocations. This improves host/tool fidelity without changing ACP’s wire protocol.

The official ACP registry advanced Qwen Code distribution from 0.24.0 to 0.24.1 in registry commit 9bd27065 on 19 September 2026 at 09:59:26 UTC. The protocol matrix generated earlier the same day at 09:33:55 UTC directly probes 0.24.0; advancing the registry distribution after that run does not rewrite its direct-probe coordinate. No direct matrix result for 0.24.1, HarnessRouter revalidation against v0.24.1, or native Qwen UHP adoption is inferred.

Stable v0.23.4: host controls and harness-composition rollup

Section titled “Stable v0.23.4: host controls and harness-composition rollup”

Qwen Code published v0.23.4 on 14 September 2026 at 15:20:21 UTC with tag commit fdcd7c2761e4ae18d578cf1413ae8d43f58b3e2c. The release promotes the site’s previously tracked post-v0.23.3 runtime/interoperability line into stable software. The former checked cutoff 351b5fc5 is an ancestor of the release tag; GitHub’s comparison reports the tag 14 commits ahead and 0 behind that cutoff.

Two release-note breaking changes deserve explicit treatment. PR #11571 removes configurable message-prefix filtering from Channels so eligibility is controlled by sender/group/mention/pairing policy rather than a user-defined prefix. PR #11615 changes command-hook timeout interpretation to the documented seconds unit for ordinary values, retaining the compatibility handling described below. Neither change is a UHP, ACP or MCP wire revision.

Interoperability-relevant stable additions now include PR #11560’s external-program peer endpoint, PR #11474’s native Claude Code/Codex subagent executors, PR #10607’s experimental CodeModeOnly tool surface, PR #10841’s extension-qualified Skill identity, PR #11691’s per-agent effort/tool narrowing, PR #11690’s stalled-Goal batching, PR #9402’s Agent Board, PR #11145’s ACP-preheated workspace MCP discovery and PR #11369’s Qwen Live protocol-v9 visual/proactive/Memory expansion. The release also contains PR #11826’s Claude-compatible hook tool-name aliases; that matcher mapping improves enforcement portability but does not standardize a cross-harness hook vocabulary.

Stable v0.23.4 detail: promoted runtime controls and native harness delegation

Section titled “Stable v0.23.4 detail: promoted runtime controls and native harness delegation”

The following material merges were previously tracked on the post-v0.23.3 moving line. They are now ancestors of the v0.23.4 release tag, so they should be read as stable v0.23.4 Qwen behavior while their individual validation caveats remain unchanged.

  • ACP settings resolve the durable owner workspace instead of ambient daemon state (PR #11647 / 32a25efa): core settings, memory and permission handlers resolve a requesting session through its stable storage/workspace root instead of process.cwd(), the daemon bootstrap target or the session’s mutable live cwd. Explicit cwd still wins; malformed or unresolvable sessionId values fail rather than falling back; request-local settings loads skip .env injection; session reads do not replace the process-wide settings cache; and workspace permission deltas fan out only to sessions bound to the same canonical real path. MCP, hook and extension writes intentionally remain workspace-global because their status/reload/apply paths are workspace-global. Upstream explicitly says the real worktree-entry producer-to-consumer flow has not been demonstrated end to end, issue #8138 remains open, and local validation was focused Linux ACP settings tests. This is Qwen ACP-host ownership/isolation hardening, not a new ACP method, ACP wire semantic or UHP rule.
  • Resumed Skills re-arm enforcement side effects instead of restoring instructions alone (PR #11280 / 7e0beb9d): --continue / --resume previously reconstructed a loaded Skill’s recorded response in conversation history but did not recreate its session allowedTools rules or hooks: registrations. That could leave the model following Skill instructions while a PreToolUse guard had silently disappeared; upstream’s reviewer E2E records hits=1 flag=YES after resume before the fix versus hits=2 flag=no after re-arming. Restoration now requires the recorded Skill body to match the current SKILL.md and a fresh invocation to still be allowed (enabled, model-visible, activated when conditional and, for project Skills, still trusted), and side effects are awaited before the first resumed turn. Session allow rules are cleared on /clear, in-process /resume and /branch so grants do not outlive the session that loaded them; the resumed session re-arms its own. Records found only inside exec output do not regain side effects because scripts can forge them, and slash-command-only starts still have no restorable tool-call record. If in-process resume fails before initialization, original hooks survive while cleared allowedTools grants stay cleared until re-invocation, which upstream classifies as fail-closed. macOS was directly validated; Windows/Linux and container-sandbox legs were not locally validated. This is Qwen Agent Skills/session authorization state, not MCP SEP-2640 Skills Over MCP, an ACP method or UHP wire semantics.
  • Experimental Agent Board coordinates independently started local agents through a shared filesystem contract (PR #9402 / 00180c53): qwen board --board <name> --as <actor> exposes task create/claim/done and question ask/answer/decline/prune operations over same-machine files under ~/.qwen/boards/, with JSON output suitable for Qwen Code, Codex, shell scripts, scheduled jobs or another program that intentionally follows the contract. Wait exit statuses distinguish answered, declined, item-TTL-expired and local-wait-ended outcomes; item expiry is derived on read, so a foreign reader must apply the documented now >= expiresAt rule rather than assuming an expired ask was rewritten on disk. Board directories/files are private to the current OS user, IDs are UUIDs, creation is exclusive, updates use in-process plus cross-process locks and atomic replacement, records are validated, and prune runs under lock. The feature remains intentionally pull-based and process-agnostic: it does not start, join, wake, monitor or inject input into agent processes; has no participant/membership/heartbeat/roster model; owner/actor names are labels rather than authentication; text is untrusted and never auto-executed; remote boards, fleet/tmux control and multiple agents writing the same checkout are outside the first version. Upstream marks the on-disk format experimental and subject to change between releases. This is Qwen runtime/CLI interoperability, not Agent Team scheduling, Qwen cross-session messaging, or a UHP/MCP/ACP/A2A wire change, native Qwen UHP adoption or HarnessRouter Qwen revalidation.
  • macOS Computer Use moves to app-bound native actions with bounded observations (PRs #11683 / #11705 / #11735; CUA stack head e6647b3a): the stacked work now carried in v0.23.4 fixes stale cross-cell REPL state and OSWorld-observed input/window/AX failures, then adds app handles, compact native AX observations, exact app/window targeting, macOS select/caret/paste operations and one-dispatch uncertainty handling. The final layer keeps useful partial observation baselines when traversal hits limits, caps returned observation text at 12,000 characters by default, retains current action IDs independently of that text cap, shortens duplicated Node REPL discovery guidance and batches only actions whose target/outcome remain known. The five valid paired VM cases in PR #11735 stayed 3/5 on both arms while total tokens fell 15.9%, agent time 6.9% and model responses 17.9%; uncached input rose 48.2%, so upstream does not claim lower billing cost, stable benchmark-wide gains or per-patch causal attribution. The focused current-head checks cover SDK, MCP, bundled-skill and exact-target tests; macOS received direct GUI/VM evidence while Windows/Linux GUI behavior was not locally validated. This is Qwen Computer Use/host runtime behavior, not a UHP, MCP or ACP wire change.
  • Desktop AppImage stdio MCP children no longer inherit the bundled Python runtime (PR #11763 / f1d5a64b): Qwen Desktop’s Linux AppImage exports PYTHONHOME / PYTHONPATH for its bundled Python. Those variables could leak through the desktop daemon into a user-configured Python stdio MCP server, causing the server’s own virtualenv interpreter to resolve its standard library against the AppImage mount and fail during init_fs_encoding. Under QWEN_CODE_DESKTOP, Qwen now removes only inherited values before spawning stdio MCP children; an explicit server-level env override is merged afterward and still wins, while the standalone CLI keeps the user’s inherited environment. Issue #11718 includes /proc environment evidence, a minimal external-interpreter reproduction and a working unset-wrapper workaround. Upstream reports 134/134 focused MCP-client tests covering desktop stripping, explicit override and non-desktop preservation, but did not validate the merged change against a real GUI/AppImage host. Shell/monitor children are explicitly outside this fix. This is Qwen host/process-environment isolation for MCP integration, not an MCP transport or protocol change.
  • Web Shell preserves follow-ups across the turn-end idle race (PR #11289 / 79dabcb8): when a mid-turn message reaches the daemon after the session has already become idle, the response can now say accepted: false, reason: "session_idle". The browser treats that as ownership transfer never having happened, resubmits the content as an ordinary prompt and checks the daemon’s authoritative pending-prompt state before deciding whether the message started, queued or can be removed. Unknown/failed confirmation leaves the queue row intact rather than guessing; a queue-clear path no longer blindly deletes a prompt that may already be running. The new response field is additive and older daemons may omit it, so the existing client-side idle fallback remains. Upstream includes live daemon wire evidence and broad focused tests, while direct browser E2E and Windows/Linux platform validation were not completed. This is Qwen Web Shell/daemon message-finality behavior, not ACP or UHP wire semantics.
  • qwen serve starts workspace MCP discovery after ACP preheat (PR #11145 / 92f57590): after a successful ACP warm-up, the primary workspace runtime is ensured with the daemon keep-alive window so the dedicated workspace discovery configuration can run Skills/MCP preparation immediately at boot. Before the fix, persisted MCP servers could still appear through bootstrap fallback, but workspace discovery itself remained not_started until a later HTTP ensure/reconcile path ran. The bootstrap configuration continues to skip MCP discovery, and the change is scoped to the CLI qwen serve daemon rather than the separate Desktop issue referenced upstream.
  • Web Shell can bind one browser-local directory to one conversation through a session-scoped client-hosted tool server (PR #10962 / 1f8e16c0), with the trust boundary hardened by PR #11169 / 4c072e88: the browser grants a directory explicitly and Qwen exposes four conversation-local list/read/search/write tools without adding that directory to the daemon workspace. Session-scoped registration prevents the local-disk tools from leaking to other conversations in the workspace. The follow-up now withholds the bridge while workspace/capability/trust state is unresolved or ineligible instead of falling through to the bare primary /acp mount, preserves an owner tab’s persisted grant against bystander disconnects, arbitrates revocation under the browser owner lock with entry-identity checks, handles lock rejection as a failed state and bounds directory traversal. These are Qwen Web Shell/daemon isolation controls around a client-hosted tool bridge, not a new standard MCP transport, ACP method or UHP filesystem primitive.
  • MCP/IDE diff identity is separated from path matching (PR #10494 / c46cb85): DiffManager now preserves the caller’s exact originalFilePath for ide/diffAccepted / ide/diffClosed notification identity while using a workspace-resolved path for close, dedupe, focus and editor matching. This fixes relative/absolute open-close mismatches and workspace-relative old-content reads. The final merge also prefers an exact original-path match before resolved-path fallback when multiple shared entries point to the same file, preventing a close from selecting another session’s diff content and avoiding the associated unresolved openDiff/mutex hang class.
  • A standalone external-program peer implementation lands (PR #11560 / af4dece3): @qwen-code/sdk/peer implements Qwen’s documented cross-session protocol for a program that is not itself a Qwen Code session, such as a voice front end, relay or build watcher. PeerEndpoint.start({ name }) publishes an external session record and inbox; the endpoint can list, send, receive and await receipt state transitions. The module is written from the protocol page using Node built-ins and shares no Qwen Code runtime code, so upstream treats it as the protocol page’s first independent implementation. Its conformance suite exercises the endpoint bidirectionally against Qwen Code’s own registry, inbox, directory and send path and pins published limits and hostile-input verdicts between the two implementations. Review also tightened controller-token handling so the bearer credential is presented only on sends explicitly marked controller: true; receiving-session agents.crossSessionInbound policy still outranks the grant. Linux additionally requires procStart and pidNs, while Windows remains unsupported for this endpoint.
  • Goals gain runtime-enforced turn and active-time ceilings (PR #11457 / 5a9c9b34): model.goalMaxTurns counts finished Goal turns and model.goalMaxActiveMinutes counts active wall time; both are opt-in. When either ceiling is spent, Qwen allows one wind-down turn and then settles the Goal as usage_limited with limitKind: "turn_budget" or "time_budget". Ceilings are checked only at continuation boundaries, never in the middle of a turn, so the crossing turn completes and a time limit is not a hard interrupt timer. /goal resume extends only the exhausted ceiling on top of usage already consumed. Existing Goals are not retrofitted with the new ceilings: bounding one already on the record requires replacement with /goal set or clear/start-again, and replacement creates a new revision-1 Goal with reset token/turn/active-time meters and a new evidence cursor, so prior Goal evidence falls outside the replacement’s citable catalogue. One behavior also changes with both new ceilings unset: restoring an active Goal rebases its in-flight clock, so reported elapsed active time no longer includes process downtime and cannot recover uncommitted active time from the interrupted turn. The PR explicitly notes that not every display surface shows the new ceilings yet and its live-model E2E plan was not run on the branch.
  • Session-recovery planning drops one redundant full-history clone (PR #11595 / 8eb33a86): interruption detection now reads the caller-owned rebuilt-history snapshot directly while orphaned-tool-use repair keeps its own mutable clone. Upstream reports field-for-field identical recovery plans and an unchanged caller array; a synthetic 50,000-record transcript measured roughly 85 ms less resume planning when no compression had occurred and roughly 15 ms less when it had. This is a measured performance optimization, not a lifecycle or wire-contract change.
  • Exited Web Shell terminals release PTY host resources promptly (PR #11572 / 38688f89): before the fix, an exited Web Shell terminal could retain node-pty host resources until tab close, workspace drain, disposal or the 15-minute idle reclaim, and exited sessions are intentionally outside the admission cap, so retained resources could accumulate without that cap bounding them. handleExit now defers one event-loop turn so queued trailing output can reach the replay buffer, then frees PTY-side host resources while retaining the session record and buffered scrollback; it does not signal the exited PID, and a per-session flag prevents a later release() from double-freeing resources. Upstream tests cover release-at-exit, post-exit scrollback replay and later release safety. The mechanism was exercised on Linux with the Windows platform path mocked; actual Windows ConPTY/conhost reclamation was not directly verified in the PR.
  • Native Claude Code and Codex subagents share Qwen’s external-executor lifecycle (PR #11474 / 642d36e6): Qwen adds foreground-by-default built-ins named claude-code and codex. Claude Code keeps the ACP executor and live continuation path from the earlier external-subagent work; Codex runs one task through an ephemeral app-server thread and returns its result through Qwen’s shared task records, notifications, cancellation and transcript lifecycle. Custom definitions may select Codex and shadow builtin names. Codex deliberately refuses messaging, continuation and cold restoration.
  • Experimental CodeModeOnly compresses the provider-visible tool surface behind audited exec (PR #10607 / 4ec9f63d): with tools.codeModeOnly: true, Qwen keeps Direct mode as the default but presents the model one structured exec({ source }) function plus the small direct-only control set; ordinary, deferred and MCP tools remain registered and are invoked as tools.<name>(args) inside a fresh isolated QuickJS WASM child context. Nested calls still traverse Qwen’s existing validation, permission/approval, hooks, telemetry, cancellation, concurrency and ACP-recording paths, and restricted forks bind exec to the same effective nested-tool allowlist. The reviewed bundled-CLI E2E reduced provider declarations from 28 to 16 and successfully nested read_file; the runtime was directly tested on macOS, while Windows and Linux runtime execution were not validated in the PR. This is a Qwen tool-surface/runtime mode, not a new MCP, ACP or UHP transport.
  • Web Shell gains live web previews plus immutable saved HTML delivery history (PR #11276 / 20ecdaf6): standalone Web Shell can preview browser-reachable HTTP/HTTPS development URLs in its right panel, while managed ACP sessions with chat recording enabled save each new self-contained HTML Artifact delivery as an independent immutable version. Saved-version cards remain associated with the original message across panel close, shell reload and daemon restart; the authenticated read route is scoped to the owning session/runtime and verifies the stored file/hash. The isolated saved-HTML viewer allows inline interaction while blocking network access and self-navigation; failed history saves leave successful publication available with a warning. Live development URLs are explicitly not frozen historical versions, and ordinary CLI publication or recording-disabled sessions do not create saved history files. Upstream’s direct validation is macOS/Chromium-focused; Windows, Linux and WebKit were not validated for this increment. This is Qwen host/session/artifact behavior around managed ACP sessions, not a new ACP wire primitive or UHP artifact rule.
  • OpenAI Responses retry and assistant-phase fidelity is preserved across recovery (PR #11652 / 91a09e76): Qwen’s fetch-based Responses path now carries allowlisted HTTP status/headers, request and trace IDs plus structured provider diagnostics into retry classification without exposing unrelated account metadata. It retries 408/409/429 and 5xx by default, honors explicit x-should-retry true/false directives and Retry-After / retry-after-ms delays inside existing attempt budgets, while ordinary 404 remains nonretryable and cancellation/permanent-quota stops remain authoritative. Assistant message IDs and optional commentary / final_answer phases are preserved across streamed output, tool-turn replay, session resume, socket-cut continuation and output-truncation recovery, with distinct message boundaries retained even when text overlaps. Upstream reports 863/863 focused tests plus localhost CLI scenarios; direct platform validation was macOS, with Windows/Linux execution not tested for this PR. This is provider/recovery fidelity, not a new Responses, ACP or UHP wire rule.
  • Expanded OpenTUI confirmations keep the full review decision inside the viewport (PR #11656 / 4a029e64): a parity-closeout change had left the expanded confirmation reserve too small, so on an 80-row alt-screen terminal a long hook-forced approval could place the payload tail, question and approve/decline options below the visible screen with no scrollback. Qwen raises the expanded reserve from 14 to 26 rows so the pending card yields enough space for the entire review dialog and decision controls. The previously failing Linux/Bun E2E becomes green; upstream still records taller-than-viewport long-session transcript overflow as an older out-of-scope limitation. This is a human-review visibility/safety fix in Qwen’s OpenTUI host, not a UHP permission semantic.
  • Responses reasoning replay metadata is kept off foreign provider wires (PR #11567 / ce79c9fb): Qwen’s shared Part.thoughtSignature store can contain an OpenAI Responses replay payload shaped as JSON with an id and encrypted_content. Before this fix, switching providers could send that opaque Responses payload as if it were an Anthropic thinking.signature or Gemini thought signature. Qwen now recognizes the Responses payload at the two foreign-wire request builders and strips/demotes it there while preserving visible reasoning and keeping the caller-owned history intact for a later switch back to Responses. Native Anthropic/Gemini signatures remain unchanged. Upstream’s focused synthetic regression suites pass on Linux; no live multi-provider credentialed session was run. This is Qwen cross-provider replay provenance, not a new OpenAI, Anthropic, Gemini, ACP, MCP or UHP wire rule.
  • Extension skills gain owner-qualified capability identity and asymmetric deny/grant matching (PR #10841 / fdb33117): extension-provided skills register as <extension>:<authoredName> (for example rust:pdf) while retaining the authored spelling separately. skills.disabled, skills.defaultDisabled and slashCommands.disabled match either spelling so pre-existing restrictions continue to bite, but skills.enabled grants only the qualified registry identity so a rename or same-named extension skill cannot silently gain capability from a bare legacy grant. Stale grants are warned with their qualified replacement; blocked UI rows name the effective setting/scope; daemon/Web Shell persistence refuses an enable that a higher-precedence restriction would still block; ACP manifest-only skill rows carry the qualified identity. Resume restoration can fall back to authored names for pre-rename transcript deduplication. Upstream directly tested macOS with CI coverage elsewhere. This is Qwen Agent Skills/runtime authorization and ACP presentation behavior, not MCP SEP-2640 Skills Over MCP, not an ACP wire change and not a UHP capability namespace.
  • Stop hooks now report truthful continuation provenance in both core and ACP sessions (PR #11613 / 7340de4f): stop_hook_active is false on the first Stop check and becomes true only while the agent is continuing because a Stop hook blocked the previous stop, including after tool calls made during that continuation. It resets once stopping is allowed, the blocking cap is reached, user steering/new input replaces the turn, a retry or Goal turn starts, or execution exits abnormally. Before the fix, both call sites hard-coded true, so the standard guard pattern that blocks only on the first check could never fire correctly. The core path tracks hook-forced prompt ids; the ACP session tracks hook-forced turns and resets its consecutive-block state when queued user input supersedes the continuation. Qwen explicitly leaves the core client’s consecutive-block counter across tool round trips to follow-up #11673. This is Qwen hook/finality behavior, not ACP or UHP wire semantics.
  • Default ACP child heaps now derive from memory the host can actually back (PR #11653 / cd1707c0): the spawn path reuses the daemon’s available-memory detector so libuv’s near-2^64 “unlimited” cgroup sentinel is rejected and reported limits above host RAM are clamped instead of driving every child toward the 16 GiB V8 old-space cap. Upstream documents a 7,265 MiB host where the old path authorized 16 GiB per ACP child while daemon status modeled 544 MiB per child, roughly a 30× disagreement. The existing half-of-available fraction, 16 GiB cap, raise-only guard and memoization remain; the change adds no spawn admission control, aggregate RSS bound or per-child sharing, and #8182 remains open for the separate enforcement issue. This is Qwen ACP-bridge resource policy, not an ACP protocol limit.
  • Agent Team leader assignment rejects stale ownership/status snapshots before dispatch (PR #10237 / 42549580): expected owner/status is checked while holding the task lock, so concurrent assignments based on the same stale snapshot can no longer both commit and dispatch one task to different teammates. The stale writer gets a retryable snapshot-changed failure, while intentional sequential reassignment and inactive-owner recovery remain supported. This is Qwen orchestration concurrency integrity, not UHP Task semantics.
  • VS Code Companion unifies ordinary workspace history and removes the short-lived source switch (PR #11713 / df864bea, superseding PR #11584 / 05a54fc3): VS Code, terminal, browser and unattributed legacy conversations from the same workspace now appear in one history list with the same ordinary row actions; there are no source tabs, source badges or source-based read-only restrictions. Opening an existing conversation never supplies replacement creator attribution, so its stored source is preserved; only newly created Companion conversations receive VS Code attribution. The current-conversation delete protection remains. Known child/background sessions and marked Live coordinator sessions are filtered, sparse pages retain an explicit Load more path, failed requests retain their cursor for retry, and old source-ownership sidecars are ignored rather than migrated. Upstream reports focused component/host tests, Companion typecheck/lint/build and a real macOS extension-host history display; real-host click-through/reload was not completed, and Windows/Linux were not locally validated. Qwen also records an attribution limitation for machine-generated Live task threads that lack a recognizable source. This is Qwen host/UI session behavior, not an ACP daemon-protocol or UHP session change.
  • ACP non-file resource links retain client filename metadata at the model-prompt boundary (PR #11721 / e14ba73a): when an ACP client supplies a non-file:// resource_link whose URI is an opaque storage key, Qwen now keeps the unchanged @URI reference and appends a non-empty client-provided name as JSON-quoted original filename metadata. Missing or empty names remain exactly @URI, and file:// resources continue through the existing file-resolution path. Upstream verified the before/after transport conversion through a real ACP subprocess and loopback OpenAI-compatible mock plus 938/938 Session tests; its full-repository test run was not established green because unrelated server/socket and review-tool failures remained noisy, and Windows/Linux were not locally validated. This improves model-visible ACP attachment identity without changing ACP schemas, fetching remote content or creating UHP resource semantics.
  • VS Code Companion now gives managed ACP children a bounded graceful shutdown path (PR #11642 / ea10c604): disconnect closes the ACP child’s stdin first so the CLI can run SessionEnd hooks, drain MCP clients, dispose sessions and execute registered process cleanup. The merged design bounds escalation: after 75 seconds, POSIX sends catchable SIGTERM to the ACP child’s process group and waits another 75 seconds before SIGKILL; Windows calls the absolute System32 taskkill.exe path with /f /t, degrading to the direct child if taskkill fails. Retired child exit handlers and asynchronous responses are tied to their originating child/connection, and overlapping EOF/signal shutdown shares SessionEnd, MCP-drain, session-disposal and process-cleanup work; SessionEnd hooks start concurrently under one 30-second abort budget. The design explicitly does not add session-close semantics when the user switches conversations. Upstream reports Companion ACP 26/26, CLI ACP 709/709 and cleanup 10/10 focused tests plus build/typecheck; native validation was macOS, with Windows process-tree behavior mocked and Linux not locally tested. This is Qwen host/process-lifecycle behavior around an ACP client process, not an ACP method/schema or UHP lifecycle rule.
  • Active todo reminders now stay fresh across long foreground delegation without reviving discarded plan state (PR #10963 / 54aa6683): Qwen’s existing three-tool-turn active-todo cadence could become structurally unreachable when one foreground Agent delegation represented tens of minutes of real work but only one parent tool turn. In the motivating session the reminder was injected 0 times and the persisted plan remained stale for roughly 56 minutes; an ordinary user turn asking for progress could then clear the work-chain context. Both core/TUI and ACP paths now force a registered unfinished-plan reminder due when a tool-result batch contains a top-level Agent result, and ordinary user turns carry the prior work chain only while the reminder remains registered and the last plan-writer owner still matches. Plan completion clears the reminder session-wide; superseded owner mappings are bounded; rewind, history restore, setHistory and truncateHistory clear reminder state because the described timeline was discarded; ACP turn-start injection stays reserved for machine continuations so model-authored plan text is not spliced ahead of an ordinary user’s message. Upstream reports focused unit tests/typechecks on Linux; a live multi-hour delegation session was explicitly not validated, and five broad-suite failures were reproduced on pristine upstream main as unrelated. This is Qwen plan-context freshness and delegation-boundary continuity, not UHP Task semantics or an ACP wire change.
  • Workflow scripts can now narrow each dispatched agent’s reasoning/tool envelope (PR #11691 / ba3a51e7): agent(prompt, { effort }) can select low, medium, high, xhigh or max for that agent without mutating the parent session, while respecting the target model/provider’s available tiers and never re-enabling thinking that the session/model disabled. agent(prompt, { disallowedTools }) is unioned with the workflow floor and the agent type’s existing denies, so it can only remove capability; built-in display names normalize to tool names, MCP patterns are supported, unmatched denies fail explicitly and a schema agent is refused if structured_output is removed. Both options are canonicalized into the workflow resume key, so equivalent aliases/order replay while materially different requests run live. This gives fan-out workflows a concrete least-tool / per-stage-effort boundary instead of relying only on prose, but it does not add UHP permissions or a new MCP/ACP mechanism; upstream explicitly leaves per-call shell command clamping and several alternate spawn paths out of scope.
  • Stalled overflowing Goal checkpoints now retry with smaller evidence batches instead of replaying the same deterministic request (PR #11690 / 00d86315): the first checkpoint attempt still sends its whole evidence window. After one stall, only an overflowing live retry is split into consecutive batches of 24 records; after two stalls, the limit becomes 12. Claims are folded forward as previousClaims, only the last batch’s checkpoint is kept, intermediate claim ids get a batch segment, and a failed batch ends the attempt without keeping partial progress while naming the failed batch in diagnostics. Windows with room and restore replays remain single-call because splitting them does not improve stall handling and can delay activation. Upstream ties the change to a 9/10 incident where three identical temperature-0 retries consumed about 7.6M tokens before usage_limited; it also documents the tradeoff that a 100-record retry can use up to five verifier calls after one stall or nine after two, with the configured checkpoint timeout applying per call. The Goal protocol/SDK are unchanged and no live provider Goal run was performed for the PR, so this is Qwen runtime liveness/cost behavior rather than UHP Task semantics or a wire change.
  • Internal Git calls no longer trust repository-configured helper programs by default (PR #11669 / 93c0d6d2): Qwen’s own Git status/diff/history/cleanup paths now disable configured core.fsmonitor helpers and, at the relevant diff/signature boundaries, external diff/textconv and signature programs; selected status probes also suppress optional index writes. The motivating attack is a workspace obtained as files rather than by git clone: a planted .git/config can name a helper that runs when the agent performs an internal status refresh before the user has reviewed the repository. Upstream uses real planted repositories as regression fixtures and keeps expected Git output assertions so a swallowed command failure cannot masquerade as protection. This is deliberately not a general Git sandbox: intentionally mutating staging/checkout paths can still run repository hooks or clean filters, team-memory synchronization can reach credential helpers when enabled, and user-invoked Git flows remain separately governed. The protection covers agent-internal calls that do not pass through the shell tool’s approval classifier; it is Qwen runtime security, not UHP authorization or an MCP/ACP rule.
  • Native LSP document queries synchronize their target from disk before asking the server (PR #11443 / 4f564301): an already-open document could retain stale initial content after edit/write tools, hooks, shell commands or an external editor changed the saved file, producing silently stale hover/definition answers. Qwen now re-reads the requested document at query time, emits Full or Incremental synchronization using per-document versions when content changed, shares synchronization state across warmup/replay and propagates read/synchronization failures through diagnostics rather than presenting a falsely clean result. Upstream reports 243 focused tests plus a bundled headless CLI scenario against TypeScript language-server on Linux. Unsaved editor buffers, workspace-wide dependency freshness and broader diagnostic redesign remain outside the change. This is Qwen tool/runtime fidelity, not an LSP, MCP, ACP or UHP wire extension.
  • Windows Web Shell and agent-view PTYs move to bundled ConPTY with replay-aware terminal history (PR #11643 / b5567bb7): Qwen attributes roughly 8 MB of host leakage per naturally exited web terminal to node-pty’s default inbox ConPTY path and now uses the bundled backend on Windows so the host reference is released after spawn; if bundled spawn fails, a web terminal retries once on the old inbox backend rather than failing to start. The companion replay contract also marks snapshots so reconnect history is restored without re-answering historical terminal queries into the still-live shell, while live queries and keyboard input remain active; daemon and Web Shell must update together and incompatible peers fail with a reload/restart message. The merged review used focused tests and a real Chromium component boundary, but native Windows process cleanup was not directly validated, so the upstream leak-fix claim retains that acceptance caveat. POSIX backend selection is unchanged. This is Qwen host/PTY/reconnect behavior, not an ACP or UHP lifecycle primitive.
  • Provider-traced status-less stream failures now use bounded recovery instead of aborting the turn immediately (PR #11291 / d47fa020): an OpenAI-compatible gateway can inject an error object into an already-200 SSE stream, yielding an SDK error with no HTTP status but a provider request id. Qwen now classifies a non-empty upstream request id as retryable unless the provider code/type is a known permanent moderation, credential/billing or malformed-request class. Before user-visible output it can replay; after delivered text it can continue from that text, reusing existing retry budgets and no-duplication guards. Input-overflow/compaction handling, explicit rate-limit/auth classification, cancellation and closed finish reasons retain precedence so the widened gate does not turn permanent or already-complete outcomes into fabricated retries/continuations. The motivating incident ended a turn that had run for more than four hours; upstream reports three reproductions in eleven hours. Review evidence is unit-focused on macOS with no live-provider E2E and no Windows/Linux execution for this PR. This is Qwen provider-stream recovery and turn-durability behavior, not a new OpenAI, ACP, MCP or UHP wire rule.
  • DashScope request metadata is now model-scoped rather than gateway-scoped (PR #11606 / fa209334): DashScope’s OpenAI-compatible endpoint can forward a request to non-Qwen providers. Qwen Code previously attached an object-valued tracing metadata field (sessionId, promptId, channel) to every DashScope-compatible request; issue evidence for ZHIPU/GLM-5.3-Flash showed otherwise-identical requests failing with a generic 400 only when that object was present because the forwarded backend expects a different metadata shape. The material PR #11606 merge sends the field automatically only for Qwen-family wire models. A tri-state enableRequestMetadata generation setting keeps that automatic behavior when unset, can force the field on, or suppress it everywhere; the final merged line wires the option through model configuration and hot switches, reads it from the provider/model config rather than ambient session state, and prevents a side model from inheriting an unrelated main-model override. Both vision and non-vision request paths are covered, while recognized DashScope-origin Qwen models retain metadata. Upstream reports 433 focused provider/model tests after review; the PR author did not run a live credentialed DashScope E2E, so the production failure/success pair remains reporter-captured request evidence plus focused tests. This is provider request-shaping/interoperability behavior, not a new OpenAI, MCP, ACP or UHP wire rule.
  • Qwen publishes a curated daemon REST/SSE compatibility contract (PR #11592 / 7c1cad5a): qwen serve --no-web now has a checked-in OpenAPI 3.1 artifact plus a human-readable reference for 25 stable v1 operations spanning discovery, session lifecycle, prompting/events, permission voting and read-only workspace context. Each operation records a capability tag where applicable, runtime-ownership scope, authentication posture, request/response contract and TypeScript SDK mapping. The contract is tested against the integration guide, dedicated protocol headings and registered Express routes so route drift is visible. Qwen deliberately excludes Web Shell-only, conditional internal and other non-core routes from this compatibility promise; those surfaces are not deprecated simply because they are outside the curated contract. Normal operations use bearer authentication, the default loopback /health exemption is narrowly documented, prompt acceptance is asynchronous (202) and event completion is correlated through SSE. This is Qwen’s own daemon API contract, not UHP, ACP or MCP wire standardization.
  • Command-hook timeout units are corrected so shared guard hooks do not silently fail open (PR #11615 / f49dda1b): command-hook timeout values below 1000 are now interpreted as seconds, matching the schema, HTTP/prompt hooks and common Claude Code-compatible hook configurations; values of 1000 or more remain a legacy-millisecond compatibility form, numeric strings are accepted, and the default remains 60 seconds. Upstream reproduced the safety consequence: on the prior behavior, "timeout": 10 killed a two-second blocking PreToolUse shell guard after roughly 10 ms and let the shell command execute; with the fix the hook completes and blocks it. The message-bus deadline remains 60 seconds for most hook events and 15 seconds for PostToolBatch, so this is not an unbounded hook-runtime expansion. This is Qwen execution-policy behavior, not a UHP permission rule.
  • telemetry.logPrompts: false now suppresses API request/response content across telemetry sinks (PR #11670 / 908452bb): Qwen no longer serializes conversation request/response text into request_text / response_text when prompt logging is disabled, keeping that material out of telemetry.outfile, log-to-span bridge output and native OTLP log content fields under the documented sink semantics. request_text also joins the bridge’s sensitive-attribute denylist. When prompt logging is explicitly enabled, sensitive bridge attributes still require includeSensitiveSpanAttributes; upstream separately tracks the policy question for opaque provider thoughtSignature replay material. This is a Qwen observability/privacy correction, not a protocol change.

PR #11474 also tightens the native-executor permission boundary. Codex defaults to read-only in DEFAULT/AUTO/PLAN sessions; writes require an explicit Codex definition or a session auto-edit/yolo grant, and an intermediate Qwen subagent cannot escalate native write access through nested delegation. Both native executors reject Windows before spawning. A settled cancellation/timeout keeps its classification if cleanup later fails, completed answers survive trailing output, and external AUTO tasks preserve the parent’s Qwen permission rules. Upstream reports 1,799 unit tests across 16 files plus CLI/subprocess approval-isolation scenarios; macOS was the directly tested platform, while native vendor execution on Linux and Windows remained outside that review. This is Qwen harness-to-harness composition, not ACP expansion, UHP delegation semantics, or evidence that HarnessRouter invokes Qwen’s native subagent executor.

These changes improve Qwen’s ACP session/worktree ownership routing, resume-time Skill enforcement rehydration, experimental same-machine Agent Board interoperability, app-bound/bounded Computer Use runtime, Desktop stdio-MCP process isolation, Web Shell follow-up finality, ACP-preheated daemon/MCP lifecycle, browser-local filesystem isolation, MCP-backed editor diff fidelity, independent cross-session interoperability, autonomous Goal bounding, long-session resume cost, Web Shell resource cleanup, provider-visible tool-surface compression, artifact-history durability, native coding-harness delegation, provider-directed Responses recovery fidelity, cross-provider reasoning provenance, extension-skill capability identity, Stop-hook finality, ACP-child resource sizing, Agent Team assignment integrity, unified ordinary-workspace session history, ACP attachment filename fidelity, Companion ACP process teardown, active-plan freshness at delegation/user-turn/history-discard boundaries, per-agent workflow effort/tool narrowing, stalled Goal checkpoint retry liveness, internal-Git execution hardening, saved-file LSP freshness, Windows PTY/reconnect integrity, status-less upstream stream-recovery durability, DashScope cross-provider request-metadata isolation, human-review visibility, daemon REST contract clarity, guard-hook timeout safety and telemetry privacy. They are stable v0.23.4 behavior subject to the per-PR caveats above and remain inherited by the later stable line. None creates UHP semantics or establishes that HarnessRouter has revalidated its Qwen adapter against v0.24.1.

Stable v0.24.0: ACP admission, workflow provenance and execution ownership

Section titled “Stable v0.24.0: ACP admission, workflow provenance and execution ownership”

Qwen Code published v0.24.0 on 16 September 2026 at 13:14:28 UTC with tag commit 56b003be0785412ed06673948f781dc70a686b5a. Its release notes promote several integration-boundary changes that materially extend the stable host runtime without changing UHP, MCP or stable ACP-v1 wire semantics.

  • ACP child processes gain explicit admission pressure controls: PR #11911 adds budget-based ACP child admission, and PR #11940 can reclaim idle ACP children when admission is full. These are Qwen host resource-management semantics, not ACP protocol limits.
  • ACP permission state is scoped more tightly: PR #11802 scopes the ACP permission queue to the session, reducing cross-session ownership ambiguity without adding a new ACP method or schema.
  • Linux gets another host sandbox option: PR #11614 adds a bwrap kernel sandbox backend. This changes Qwen execution isolation, not UHP authorization semantics.
  • Cross-session messaging becomes default-on in Qwen settings: PR #11840 changes the product default while the underlying Qwen policy/receipt/controller semantics remain product-specific.
  • Workflow identity and authorization become more durable: PRs #11943, #11931, #11932 and #11957 add named saved-workflow execution with grants pinned to script content, preserve source references across runs/resumes, improve nested-run correlation and allow qualifying extension workflows to be model-invocable. These are Qwen workflow/runtime semantics, not a cross-harness workflow protocol.
  • Background automatic execution is now stable: PR #11636 gives background-result processing its own execution identity across Session, daemon bridge, SDK, Web Shell and Qwen Live rather than leaving it as unreleased current-main behavior.

The release tag targets release/v0.24.0. The former checked development cutoff f2e653b5e64c2a0be4dcd64d75f00c167312ba04 was tracked as a post-release upstream coordinate at the time; it is historical now that v0.24.1 and a later main have superseded it.

PR #11636 / 7157cdea closes a separate execution-ownership gap now shipped in stable v0.24.0. Background subagent results already entered the Qwen Session queue, but their automatic processing was not represented as a first-class bridge prompt lifecycle. That could make real automatic work look idle, let output borrow or lose a preceding foreground prompt id, promote user steering into a new interrupting prompt, and discard pending results in stop/input edge cases.

The merged design gives the automatic work its own background execution descriptor and keeps producer/consumer ownership explicit. Same-execution results may be consumed at a safe model boundary without launching a duplicate continuation; results belonging to older executions wait until the foreground is idle and then start a separate automatic execution. Start admission is acknowledged only after the preceding foreground terminal has published. End events clear only a matching execution id, stale descriptors cannot settle a newer prompt, explicit stop keeps pending results and pauses draining until a new user prompt, and hasRunningBackgroundTasks is exposed independently from hasActivePrompt. Recovery uses the existing load/runtime snapshot and active-work heartbeat instead of guessing active state from historical transcript rows.

The separation is also enforced at the host edges. Background output, permissions and terminal markers stay attributed to their automatic execution and are excluded from foreground answer collectors. A background terminal cannot complete another consumer’s prompt or Qwen Live job. When Qwen Live attaches while only an automatic execution is active, it tracks that state separately and a new handoff is queued as a foreground prompt because its job receipt requires a foreground terminal. Non-daemon ACP hosts preserve the legacy fallback through method-not-found rather than pretending to support the admission extension.

Upstream reports 2,956 related unit cases across Qwen Live, SDK, Web Shell, bridge and Session scopes plus two Chromium scenarios, with build/typecheck/bundle and targeted lint/format/diff checks. The deterministic browser fixture validates transport/browser projection without live-model variability; it does not establish real-provider or real-Git end-to-end behavior. Local execution was macOS, while Windows and Linux were not locally tested for the change. This is stable v0.24.0 Qwen behavior: no public ACP method/schema, MCP contract, UHP Task state or HarnessRouter adapter behavior is changed by PR #11636 itself.

Qwen Code natively supports MCP configuration. HarnessRouter’s Qwen adapter materializes configured MCP servers into Qwen settings. HarnessRouter PR #138 adds real-MCP custom-harness verification across all ten bases under its stated reachable-endpoint conditions, but that should not be misreported as a new Qwen-specific blanket MCP guarantee. Qwen PR #11763 separately hardens Desktop AppImage stdio MCP process spawning by removing packaging-only Python environment leakage while preserving explicit server env overrides and standalone CLI inheritance; it changes the host spawn environment, not MCP framing, transport or message semantics.

MCP and UHP solve different boundaries: MCP exposes tools/resources/context to an agent runtime; UHP drives a complete harness through task/session semantics. They can be composed without being interchangeable. Qwen’s CodeModeOnly can programmatically invoke already-registered MCP tools through its internal tools.* gateway, but that changes Qwen’s model-facing execution surface rather than MCP’s wire contract. Qwen’s Web Shell local-files bridge uses Qwen’s client-hosted reverse channel and session-scoped server registration to expose browser-local tools to one conversation; that is a Qwen runtime/transport composition, not a new standard MCP transport. Qwen’s extension-qualified Agent Skills are likewise a local runtime capability namespace; PR #10841 does not implement MCP SEP-2640 Skills Over MCP. PR #11280 likewise restores Qwen-local Skill hooks and allowedTools state during session resume; it does not use or extend the MCP Skills extension.

Qwen’s upstream architecture includes a qwen serve daemon and ACP-oriented integration paths. Stable v0.23.1 includes PR #8729, which makes subagent execution visible through parent tool_call updates on the ACP path. Stable v0.23.3 adds ACP-mediated external subagent turns and daemon-managed ACP session registration/peer messaging. Stable v0.23.4 added PR #11647’s session/worktree ownership hardening for core settings, memory and permissions while intentionally leaving MCP/hook/extension writes on the workspace-global coordinate their status/apply routes use. Stable v0.24.0 adds budget-based ACP-child admission and idle-child reclamation, scopes the ACP permission queue to its session, and carries PR #11636’s automatic background-execution ownership across ACP Session/daemon surfaces. PR #11145 tightens the daemon lifecycle around ACP preheat and workspace MCP discovery; PRs #10962/#11169 add and harden the browser-local-files reverse-channel registration path; PR #11560 adds a separate external-program implementation of Qwen’s own cross-session peer protocol; PR #11474 adds native Claude Code/Codex subagent executors above the shared task lifecycle; PR #10607 preserves real nested tool identities in ACP recording while compressing the provider-visible tool surface; PR #11276 layers durable saved HTML delivery resources around managed recorded ACP sessions; and PR #11592 publishes a separate 25-operation OpenAPI 3.1 contract for the supported daemon REST/SSE integration surface. That REST contract is Qwen-specific and remains distinct from ACP-over-HTTP/WebSocket references. PR #11652 separately preserves OpenAI Responses retry metadata and assistant message phases through replay/resume/recovery; PR #11567 prevents Responses reasoning-replay data from being projected as a foreign provider’s native signature; PR #10841 gives extension skills a qualified identity that is also carried on ACP manifest-only skill rows; PR #11613 makes Stop-hook continuation provenance truthful in the ACP session path; and PR #11653 corrects the host resource ceiling used when Qwen spawns default ACP children. PR #11713 replaces the short-lived source-scoped VS Code history UI with one ordinary-workspace history while retaining stored creator attribution on restore. PR #11721 preserves a non-file ACP resource link’s client-provided original filename when Qwen converts that link into model-visible prompt text, without changing ACP schemas or fetching remote resources. PR #11642 separately makes the Companion’s managed ACP process teardown graceful and bounded, preserving Qwen’s existing cleanup phases before platform-specific escalation while explicitly not adding session-close protocol semantics. PR #10963 keeps active-todo reminder lineage/freshness aligned between core and ACP Session paths at delegation, ordinary-user-turn and history-discard boundaries without adding ACP methods or changing its wire contract. PR #11615 and PR #11670 harden hook execution policy and telemetry privacy without extending ACP. PR #11643 separately hardens the Windows Web Shell PTY/reconnect boundary; it changes host terminal mechanics rather than ACP semantics. PR #11291 likewise changes provider-stream retry and turn recovery without extending ACP, while PR #11289 changes the Qwen Web Shell/daemon follow-up-ownership contract rather than ACP. Agent Board remains outside these ACP/daemon semantics: it is a same-machine filesystem coordination contract among independently started processes, not an ACP session or transport. Browser Use likewise does not require qwen serve; its local Native Messaging/Chrome-debugger bridge is a Qwen host capability, not an ACP transport. These are provider/history and host/runtime fidelity choices rather than ACP expansion. Native ACP/daemon support, Qwen’s ACP settings/worktree ownership routing, Qwen’s client-hosted local-files bridge, Qwen-specific peer interoperability, Agent Board coordination, Browser Use, internal delegation to another coding harness, CodeModeOnly execution, saved-preview history, daemon REST/OpenAPI publication, Responses recovery fidelity, qualified skill presentation, hook continuation state, unified host history, resource-link filename presentation, graceful ACP process teardown, active-plan continuity, hook timeout interpretation, telemetry filtering, Windows PTY replay behavior, provider-stream recovery, Web Shell follow-up reconciliation, automatic background execution, ACP-child admission/reclamation or ACP-child heap policy does not establish native UHP adoption.

The official ACP registry now distributes Qwen Code 0.24.1 through @qwen-code/qwen-code@0.24.1 --acp --experimental-skills, after registry commit 9bd27065 on 19 September 2026 at 09:59:26 UTC. The protocol matrix generated earlier that day, at 09:33:55 UTC, directly initialized 0.24.0 with agent authentication and advertised loadSession, session/list and session/resume. That direct evidence is version-bounded: the later registry/stable 0.24.1 coordinate and current main 42f9d13c are not silently promoted to measured ACP-matrix coordinates without a fresh probe.

As of 19 September 2026:

  • UHP remains 2026-09-12 Draft with the optional Harness Plugins sub-protocol.
  • HarnessRouter stable is v0.19.0 / ccf4af66 and checked current main is 387ad841, with no reviewed Qwen-specific adapter revision; current conformance source is 75 checks while the package version remains 2026.9.12.
  • HarnessRouter released backend set is thirteen; Qwen is the seventh-added backend and Aider is the thirteenth.
  • Qwen Code stable is v0.24.1, published 19 September 2026 at 08:18:42 UTC. Checked main is 42f9d13c on the continuing development line.
  • Browser Use from PR #11242 is now part of stable v0.24.1; it uses the user’s existing Chrome state through a local Native Messaging/extension bridge and remains a Qwen host/runtime feature rather than UHP/ACP/MCP wire capability.
  • Workspace-trust PR #12198 / c9839a94 is post-v0.24.1 current-main behavior: undecided workspaces fail closed until explicitly trusted. It is not promoted into stable v0.24.1 here.
  • Qwen’s refusal/denial/expiry/review-class rules and trusted-controller grant remain stable upstream v0.23.1 behavior and are retained in the later line; they are not UHP semantics.
  • v0.23.2 adds the remote-serve operator flow, bounded peer-message overload handling, workflow failure journaling, prompt-identity replay hardening, parameterless OpenAI tool-schema omission and GPT-5/GPT-6 reasoning controls described above.
  • v0.23.3 adds ACP-mediated external subagent execution, daemon-managed ACP session registration/peer messaging and ACP shell-execution settings passthrough; these are Qwen runtime/integration changes, not ACP or UHP protocol changes.
  • v0.23.4 promotes the previously tracked ACP session/worktree ownership hardening, resume-time Skill enforcement rehydration, Agent Board, app-bound/bounded macOS Computer Use, Desktop AppImage stdio-MCP environment isolation, Web Shell idle-race reconciliation, ACP-preheated workspace MCP discovery, browser-local-files isolation, MCP/IDE diff identity, external peer SDK, Goal budgets/checkpoint batching, native Claude/Codex subagents, CodeModeOnly, durable saved previews, Responses recovery/provenance, extension-qualified Skills, Stop-hook state, ACP-child heap sizing, Agent Team stale-assignment rejection, unified ordinary-workspace history, ACP filename preservation, graceful Companion ACP teardown, active-todo continuity, workflow narrowing, internal-Git hardening, LSP synchronization, Windows ConPTY/replay hardening, DashScope metadata isolation, daemon REST/OpenAPI, corrected hook timeout semantics, telemetry privacy, Claude-compatible hook matcher aliases, and Qwen Live protocol-v9 visual/proactive/Memory work into stable software.
  • v0.24.0 adds ACP child admission/reclamation, session-scoped ACP permission queues, Linux bwrap sandboxing, default-on cross-session messaging, stronger saved/extension workflow identity/provenance and stable background automatic-execution ownership. These remain inherited by the later stable line and are host/runtime changes, not ACP/UHP/MCP wire changes.
  • Qwen Live’s protocol-v9 visual/proactive/Memory expansion remains carried by the stable line; the separately versioned @qwen-code/qwen-live source package remains 0.1.0. See Qwen Live.
  • The official ACP registry distributes Qwen Code 0.24.1, while the official 19 September 09:33:55 UTC ACP matrix directly tests 0.24.0. The registry update to 0.24.1 landed at 09:59:26 UTC after the matrix run; do not rewrite the direct-probe coordinate as 0.24.1 until that build is directly re-probed.
  • PR #93 remains historical eight-backend matrix evidence from before Gemini CLI, OMP and Goose; PR #119 is OMP-specific; PR #138 is custom-harness real-MCP verification; PR #139 changes other backend/runtime fidelity; PR #140 changes dsh/OpenRouter evidence; PR #148 is a Codex app-server provider rerun; PR #151 is hosted-provider candidate evidence; PR #155 is connection/provider-control evidence. None is a current Qwen-specific UHP conformance result.
  • Native Qwen UHP adoption remains not established.

Read HarnessRouter, release tracker, conformance, ecosystem, adoption, UHP vs MCP, UHP vs ACP, workspace trust and Qwen Live.