# KIMU 5.2.0 Increment 44 — release notes

## Added

- Secure, audited Tools Runtime and mobile Tools panel.
- Full-duplex Whisper/Sonic WebSocket Conversation Mode with true barge-in.
- Mobile Website Builder with safe ZIP import, editing, tested revisions, preview, versioning, rollback and export.
- Controlled six-role Agent Swarm foundation with tool/time limits, agent-attributed writes, file leases, checkpoints, resume and release gates.
- Increment 44 readiness and administration counts.
- Target HTTP workflow tests for all four modules.

## Security hardening

- WebSocket CSRF handshake.
- Explicit provider connection failure closure.
- Stale turn cleanup after cancellation and audio completion.
- Website preview isolated without `allow-same-origin`.
- Duplicate and encrypted ZIP entries rejected.
- File lease transitions exposed correctly between swarm tasks.
- Swarm writes now create agent-attributed tool-operation evidence.

## Preserved

- Kimi K2.6/K2.7 Coder switching and adaptive settings.
- Streaming persistent chat.
- AES-256-GCM encrypted artifacts.
- Offline IndexedDB queue and incremental sync.
- Safe file/ZIP attachments, Code Interpreter, memory and skill foundations.

## Known external gates

Live Together provider, K2.7 endpoint, realtime audio, physical Android/headset, HTTPS and production recovery acceptance remain open.

## Truthful scope boundary

The four modules are operational implementations/foundations. Full visual-builder UX, general parallel swarm scheduling, interactive swarm approval modes, native chat tool-loop integration and live provider/device acceptance remain open gates under the locked R3 specification.
