diff --git a/CHANGELOG.md b/CHANGELOG.md index 8d17bcc..9349d4e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,18 +11,95 @@ Pre-v1.0.0 tags followed the pi npm version (`v{pi_version}[letter]`). --- -## Unreleased +## v1.8.10 — 2026-08-27 + +**This tag exists to deploy a fix and a safety net that are currently running on +exactly one machine.** The feeder scrubber has been hand-copied to `/opt` on one +device since this morning; every other device has kept staging unscrubbed +transcripts into the shared palace. Nothing here is a new capability for its own +sake. -**No tag yet, so nothing is built.** This section exists because `MEMPALACE_TOOLKIT_REF=main` floats: `docker-publish.yml` resolves it to a -concrete SHA at build time, so whatever is on toolkit `main` when the next tag is +concrete SHA at build time, so whatever is on toolkit `main` when the tag is pushed ships in that image whether or not this repo has a commit. That is the rule v1.8.9 adopted after `553d865`/`5b8d78f` shipped undocumented twice — *name the behaviour change before tagging, not after* — and this entry is that rule being obeyed rather than re-learned. -**`mempalace-toolkit` main moves `5b8d78f` → `f0bffd1`** (10 commits, ~1800 -insertions / ~500 deletions). No pi-devbox commit implements any of it. +**`mempalace-toolkit` main moves `5b8d78f` → `b2b50af`** (13 commits, ~2100 +insertions / ~520 deletions). No pi-devbox commit implements any of it. + +### ⚠️ THE ONE CHECK THIS RELEASE MUST NOT SKIP + +**On the first client that runs this image, verify the memory feed still stages.** +The feeder is *fail-closed* by design: no redactor module, no staging (`exit 3`). +That is correct behaviour and it is also the failure mode with no alarm — a +packaging or path mistake stops the fleet's entire transcript feed and nothing +complains loudly, because refusing to stage looks exactly like a quiet session. + +This is not hypothetical. `f0bffd1` exists because the feeder is installed as a +symlink (`/usr/local/bin/mempalace-pi-session` → `/opt/mempalace-toolkit/bin/…`) +and `${BASH_SOURCE[0]}` reports the *symlink* path, so the module lookup landed in +a directory where it does not exist. Had that shipped, every device would have +refused to stage on first boot. It was caught by execution, not by review. + +Acceptance, in order, on the first recreated client: + +1. Run a session, then confirm the feeder logged a scrub summary — a + `[scrub]` line with tier-tagged counts (`T1:env-value=…`, `T2:github-pat=…`), + or an explicit "zero redactions". **Silence is the failure signal**, not success. +2. Confirm the palace drawer count *moved* for that session (the feed reached the + server, not just the stager). +3. Confirm `exit 3` did **not** fire: `mempalace-pi-session` invoked through the + `/usr/local/bin` symlink must find `mempalace_redact.py`. +4. Only then trust the rest of this release. + +If step 1 or 3 fails, the memory feed is down fleet-wide until it is fixed, and +sessions that ran in the meantime are not recoverable from the palace — they were +never staged. `MEMPALACE_FEED_ALLOW_UNSCRUBBED=1` is the loud escape hatch, and +using it means accepting unscrubbed transcripts until the packaging is repaired. + +### Dependency audit (2026-08-27) + +Every component checked against upstream, not assumed: + +| Component | Baked in v1.8.9 | Upstream now | Action | +|---|---|---|---| +| **mempalace-toolkit** | `5b8d78f` | **`b2b50af`** | ships the scrubber + symlink fix + `hlc` join | +| **pi-studio** (studio variant) | `v0.9.48` | **`v0.9.52`** | 22 commits, additive only — see below | +| pi | `0.84.3` (pinned) | `0.84.3` is npm latest | none | +| mempalace | `3.8.0` (pinned) | `3.8.0` is PyPI latest | none | +| pi-atelier | `v0.8.2` (pinned) | `v0.8.2` highest tag | none | +| playwright | `1.62.1` (floats `latest`) | `1.62.1` | none — no drift this cycle | +| pi-fork | `bf702b4` | `bf702b4` (2026-08-24) | none | +| pi-observational-memory | `ce9fc98` (v3.0.4) | `ce9fc98` | none | +| pi-toolkit | `0e1369e` | `0e1369e` (2026-08-07) | none | +| pi-extensions | `2022887` | `2022887` (2026-08-17) | none | + +**`pi-studio` `v0.9.48` → `v0.9.52`** — four releases, 22 commits, all additive: +PDFs open directly in Studio with watched previews, the header can hide, and +contextual *side questions* arrive (selected-tool use, frozen git context, export, +keyboard shortcuts). No removals or renames in the diff; the changes are +concentrated in `client/studio-client.js`, `index.ts` and three new `shared/` +helpers. + +**Its `pi` floor is `>=0.84.3` and we pin exactly `0.84.3` — satisfied with zero +headroom.** Worth naming as a watch item rather than a problem: the next studio +release that raises the floor breaks the studio variant until `PI_VERSION` moves, +and that failure surfaces at build time in the studio job only, after the core +variant has already published. + +### Also pulled in by the floating toolkit ref (documentation only) + +RFC 003 gains **§9.2**, a proposed direction for the one open decision this +fleet keeps tripping over — that a report addressed to a device is never +delivered, because mailbox candidacy requires exactly `status="open"`. It records +a negative result worth keeping: widening the owed set to include terminal events +cannot work, since the asserting shape and the clearing shape must be disjoint or +every closure mints a fresh obligation. No code implements §9.2 in this release. + +The skillset snapshot also moves, so this image bakes the mermaid-diagrams skill's +Playwright driver and the honest note that a `claimed` ack notifies nobody. ### Transcripts get scrubbed before they are staged (`3d47937`, `836e35b`, `f0bffd1`) @@ -272,8 +349,6 @@ staged by a non-pi client, still lands unscrubbed. --- ---- - ## v1.8.9 — 2026-08-26 The coordination log gets a reader, and the release checklist's last gate stops