Self-maintenance
Three layers, each narrower than the last.
None of this needs the internet, and all of it runs in Private mode too. What it did shows under SYSTEM → Activity on the screen, in plain words.
Available now
It heals.
When the assistant, the model server or the Telegram bridge dies, it restarts it. It has its own fixes for memory pressure, a frozen screen, a failed boot self-test, a stale warm-up and a dropped Wi-Fi connection (it rejoins a network it already knows, and never asks for or changes a password). When the disk is nearly full it trims logs, clears the package cache and, if needed, deletes older backups, always keeping the newest.
Every fix is checked afterwards. At least two minutes apart, at most three in thirty minutes; when the budget runs out it waits before trying again (six hours, for the assistant itself) and tells you, unless you've set notices to Never; a notice about the assistant itself arrives either way.
Available now · early
It repairs, with an undo.
Some faults need more than a restart: a configuration file that drifted from what the release ships, or a memory or conversation search index that no longer matches what you told it. Those are repaired as a transaction: snapshot, stage, check, apply, check again live.
The change is kept only if every check passes. If not, it puts back exactly what was there, checks that too, and leaves a notice in your Journal. Your own words are never rewritten from an index; the index is rebuilt from them.
Available now · early
It keeps score of every fix.
Every incident and every repair outcome is recorded on the device. Where it has more than one allowed fix (today: an unresponsive model server and the two search indexes), it can try one out of the shipped order first: once each of the fixes it is weighing has been tried at least five times, across at least three separate incidents, and one has a clearly better record.
It can also hold back a fix that keeps failing, for up to 30 minutes. It only ever chooses among fixes it was already allowed to make, every unit starts with no evidence, and many units may never see one fault often enough to use it.
Alongside those, it watches for trouble coming, like a disk filling up or memory creeping, and may warn you. Those parts only watch and record. They never act.