From 0fe64c480e995f47f86425cae9b4ae2dc031fa1c Mon Sep 17 00:00:00 2001 From: Joakim Persson Date: Sun, 23 Aug 2026 13:29:51 +0200 Subject: [PATCH] docs: MEMPALACE_PI_DEVICE now also attributes drawers Follow-up to c64ffa1, which changed the --agent default but left --help claiming $USER. Fixes that text and states in README/ARCHITECTURE that the device label reaches the palace as added_by, since mempalace stores neither the machine nor the harness on a write. --- ARCHITECTURE.md | 8 ++++++++ README.md | 6 ++++-- bin/mempalace-pi-session | 6 +++++- 3 files changed, 17 insertions(+), 3 deletions(-) diff --git a/ARCHITECTURE.md b/ARCHITECTURE.md index d3ae417..d33c085 100644 --- a/ARCHITECTURE.md +++ b/ARCHITECTURE.md @@ -196,6 +196,14 @@ server to mine its own local copy of that inbox over the same HTTP `$MEMPALACE_PI_SSH_TARGET`; see `--help` for the rest (`MEMPALACE_PI_SSH_CONFIG`, `MEMPALACE_PI_REMOTE_PATH`, `MEMPALACE_PI_DEVICE`). +**Attribution.** `MEMPALACE_PI_DEVICE` is not only the inbox directory name: it +also defaults `--agent` to `pi@`, which reaches the palace as each +drawer's `added_by`. This matters because mempalace records neither the +originating machine nor the harness on a write, and a shared bearer token leaves +the server unable to tell clients apart. Without it, attribution has to be +reconstructed after the fact from the inbox path and the `pi_*.jsonl` filename — +which works for mined transcripts but not for anything filed by hand. + **Filters:** two gates, both required — stricter than `mempalace-session`'s single filter because pi's transcripts have a failure mode opencode's don't: diff --git a/README.md b/README.md index 148fc83..758c7cf 100644 --- a/README.md +++ b/README.md @@ -573,8 +573,10 @@ exports. `--mode remote` (or `--mode auto`, which detects the palace host and asks the server to mine its own local copy. Requires `$MEMPALACE_PI_SSH_TARGET` (`user@host:path`); see `MEMPALACE_PI_SSH_CONFIG`, `MEMPALACE_PI_REMOTE_PATH`, and `MEMPALACE_PI_DEVICE` in `--help` for the -rest. Deploying that primary — newt, DNS, and why the auth is a shared bearer -token rather than per-device proxy users — is +rest. `MEMPALACE_PI_DEVICE` also defaults `--agent` to `pi@` so each +drawer's `added_by` records which harness and which machine produced it — +mempalace itself stores neither. Deploying that primary — newt, DNS, and why the +auth is a shared bearer token rather than per-device proxy users — is [`docs/phase-1-exposure-runbook.md`](docs/phase-1-exposure-runbook.md). --- diff --git a/bin/mempalace-pi-session b/bin/mempalace-pi-session index eb75226..416b292 100755 --- a/bin/mempalace-pi-session +++ b/bin/mempalace-pi-session @@ -212,7 +212,11 @@ Options: assistant text, tool results excluded (default: 1000). Catches abandoned sessions whose bulk is injected skill/context text in the user prompt. - --agent Agent name recorded on drawers (default: $USER) + --agent Agent name recorded on drawers. Defaults to + pi@$MEMPALACE_PI_DEVICE when that is set, else $USER. + The palace records neither the harness nor the machine + on a write, so this one string is what makes a drawer + attributable to both. --sessions-dir Path to pi sessions dir (default: $PI_SESSIONS_DIR or ~/.pi/agent/sessions) --stage Staging root (default: $MEMPALACE_PI_STAGE, else