changelog: release v1.8.10 — deploy the scrubber, and name the check that must not be skipped
Publish Docker Image / build-variant-studio (push) Successful in 17m4s
Lint / actionlint (push) Successful in 17s
Publish Docker Image / resolve-versions (push) Successful in 14s
Publish Docker Image / base-decide (push) Successful in 12s
Publish Docker Image / build-variant (push) Successful in 18m45s
Publish Docker Image / build-base (push) Successful in 41m59s
Publish Docker Image / update-description (push) Successful in 6s
Publish Docker Image / promote-base-latest (push) Successful in 11s
Publish Docker Image / smoke (push) Successful in 4m55s
Lint / hadolint (push) Successful in 8s
Publish Docker Image / smoke-studio (push) Successful in 5m9s
Publish Docker Image / build-variant-studio (push) Successful in 17m4s
Lint / actionlint (push) Successful in 17s
Publish Docker Image / resolve-versions (push) Successful in 14s
Publish Docker Image / base-decide (push) Successful in 12s
Publish Docker Image / build-variant (push) Successful in 18m45s
Publish Docker Image / build-base (push) Successful in 41m59s
Publish Docker Image / update-description (push) Successful in 6s
Publish Docker Image / promote-base-latest (push) Successful in 11s
Publish Docker Image / smoke (push) Successful in 4m55s
Lint / hadolint (push) Successful in 8s
Publish Docker Image / smoke-studio (push) Successful in 5m9s
Audited every component against upstream rather than assuming. Only two moved since v1.8.9: - mempalace-toolkit 5b8d78f -> b2b50af (ours): feeder scrubber, the symlink fix that stops it refusing to stage, hlc owed-set join, queued-delivery note, explicit MEMPALACE_MAILBOX_NOTIFY protocol modes, RFC 003 + fleet-memory docs. - pi-studio v0.9.48 -> v0.9.52 (upstream, studio variant only): 22 commits, all additive — PDF previews, hideable header, contextual side questions. No removals or renames. Its pi floor is >=0.84.3 against our exact 0.84.3 pin: satisfied, zero headroom, named as a watch item because the next floor bump breaks the studio job only, after core has already published. Verified unchanged, with dates proving they predate the v1.8.9 bake: pi 0.84.3 (= npm latest), mempalace 3.8.0 (= PyPI latest), pi-atelier v0.8.2, playwright 1.62.1 (no drift this cycle despite floating on latest), pi-fork bf702b4, pi-obsmem ce9fc98, pi-toolkit 0e1369e, pi-extensions 2022887. No breaking changes anywhere, so everything can ship in one tag. The reason for tagging now is not features. The scrubber has been live on exactly ONE device since this morning; every other device has kept staging unscrubbed transcripts into a shared palace, and cleanup after the fact is manual redaction (done twice today, with freed-page residue left behind by choice). The entry leads with the acceptance check instead of burying it, because this release's worst failure is silent: the feeder is fail-closed, so a packaging or path mistake stops the fleet's memory feed and nothing complains — refusing to stage looks exactly like a quiet session. f0bffd1 exists because that very bug was real (BASH_SOURCE reports the symlink path, not the target). First client on the new image must confirm a [scrub] summary line appears, the drawer count moves, and exit 3 did not fire. Silence is the failure signal, not success.
This commit is contained in:
+82
-7
@@ -11,18 +11,95 @@ Pre-v1.0.0 tags followed the pi npm version (`v{pi_version}[letter]`).
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Unreleased
|
## v1.8.10 — 2026-08-27
|
||||||
|
|
||||||
|
**This tag exists to deploy a fix and a safety net that are currently running on
|
||||||
|
exactly one machine.** The feeder scrubber has been hand-copied to `/opt` on one
|
||||||
|
device since this morning; every other device has kept staging unscrubbed
|
||||||
|
transcripts into the shared palace. Nothing here is a new capability for its own
|
||||||
|
sake.
|
||||||
|
|
||||||
**No tag yet, so nothing is built.** This section exists because
|
|
||||||
`MEMPALACE_TOOLKIT_REF=main` floats: `docker-publish.yml` resolves it to a
|
`MEMPALACE_TOOLKIT_REF=main` floats: `docker-publish.yml` resolves it to a
|
||||||
concrete SHA at build time, so whatever is on toolkit `main` when the next tag is
|
concrete SHA at build time, so whatever is on toolkit `main` when the tag is
|
||||||
pushed ships in that image whether or not this repo has a commit. That is the
|
pushed ships in that image whether or not this repo has a commit. That is the
|
||||||
rule v1.8.9 adopted after `553d865`/`5b8d78f` shipped undocumented twice — *name
|
rule v1.8.9 adopted after `553d865`/`5b8d78f` shipped undocumented twice — *name
|
||||||
the behaviour change before tagging, not after* — and this entry is that rule
|
the behaviour change before tagging, not after* — and this entry is that rule
|
||||||
being obeyed rather than re-learned.
|
being obeyed rather than re-learned.
|
||||||
|
|
||||||
**`mempalace-toolkit` main moves `5b8d78f` → `f0bffd1`** (10 commits, ~1800
|
**`mempalace-toolkit` main moves `5b8d78f` → `b2b50af`** (13 commits, ~2100
|
||||||
insertions / ~500 deletions). No pi-devbox commit implements any of it.
|
insertions / ~520 deletions). No pi-devbox commit implements any of it.
|
||||||
|
|
||||||
|
### ⚠️ THE ONE CHECK THIS RELEASE MUST NOT SKIP
|
||||||
|
|
||||||
|
**On the first client that runs this image, verify the memory feed still stages.**
|
||||||
|
The feeder is *fail-closed* by design: no redactor module, no staging (`exit 3`).
|
||||||
|
That is correct behaviour and it is also the failure mode with no alarm — a
|
||||||
|
packaging or path mistake stops the fleet's entire transcript feed and nothing
|
||||||
|
complains loudly, because refusing to stage looks exactly like a quiet session.
|
||||||
|
|
||||||
|
This is not hypothetical. `f0bffd1` exists because the feeder is installed as a
|
||||||
|
symlink (`/usr/local/bin/mempalace-pi-session` → `/opt/mempalace-toolkit/bin/…`)
|
||||||
|
and `${BASH_SOURCE[0]}` reports the *symlink* path, so the module lookup landed in
|
||||||
|
a directory where it does not exist. Had that shipped, every device would have
|
||||||
|
refused to stage on first boot. It was caught by execution, not by review.
|
||||||
|
|
||||||
|
Acceptance, in order, on the first recreated client:
|
||||||
|
|
||||||
|
1. Run a session, then confirm the feeder logged a scrub summary — a
|
||||||
|
`[scrub]` line with tier-tagged counts (`T1:env-value=…`, `T2:github-pat=…`),
|
||||||
|
or an explicit "zero redactions". **Silence is the failure signal**, not success.
|
||||||
|
2. Confirm the palace drawer count *moved* for that session (the feed reached the
|
||||||
|
server, not just the stager).
|
||||||
|
3. Confirm `exit 3` did **not** fire: `mempalace-pi-session` invoked through the
|
||||||
|
`/usr/local/bin` symlink must find `mempalace_redact.py`.
|
||||||
|
4. Only then trust the rest of this release.
|
||||||
|
|
||||||
|
If step 1 or 3 fails, the memory feed is down fleet-wide until it is fixed, and
|
||||||
|
sessions that ran in the meantime are not recoverable from the palace — they were
|
||||||
|
never staged. `MEMPALACE_FEED_ALLOW_UNSCRUBBED=1` is the loud escape hatch, and
|
||||||
|
using it means accepting unscrubbed transcripts until the packaging is repaired.
|
||||||
|
|
||||||
|
### Dependency audit (2026-08-27)
|
||||||
|
|
||||||
|
Every component checked against upstream, not assumed:
|
||||||
|
|
||||||
|
| Component | Baked in v1.8.9 | Upstream now | Action |
|
||||||
|
|---|---|---|---|
|
||||||
|
| **mempalace-toolkit** | `5b8d78f` | **`b2b50af`** | ships the scrubber + symlink fix + `hlc` join |
|
||||||
|
| **pi-studio** (studio variant) | `v0.9.48` | **`v0.9.52`** | 22 commits, additive only — see below |
|
||||||
|
| pi | `0.84.3` (pinned) | `0.84.3` is npm latest | none |
|
||||||
|
| mempalace | `3.8.0` (pinned) | `3.8.0` is PyPI latest | none |
|
||||||
|
| pi-atelier | `v0.8.2` (pinned) | `v0.8.2` highest tag | none |
|
||||||
|
| playwright | `1.62.1` (floats `latest`) | `1.62.1` | none — no drift this cycle |
|
||||||
|
| pi-fork | `bf702b4` | `bf702b4` (2026-08-24) | none |
|
||||||
|
| pi-observational-memory | `ce9fc98` (v3.0.4) | `ce9fc98` | none |
|
||||||
|
| pi-toolkit | `0e1369e` | `0e1369e` (2026-08-07) | none |
|
||||||
|
| pi-extensions | `2022887` | `2022887` (2026-08-17) | none |
|
||||||
|
|
||||||
|
**`pi-studio` `v0.9.48` → `v0.9.52`** — four releases, 22 commits, all additive:
|
||||||
|
PDFs open directly in Studio with watched previews, the header can hide, and
|
||||||
|
contextual *side questions* arrive (selected-tool use, frozen git context, export,
|
||||||
|
keyboard shortcuts). No removals or renames in the diff; the changes are
|
||||||
|
concentrated in `client/studio-client.js`, `index.ts` and three new `shared/`
|
||||||
|
helpers.
|
||||||
|
|
||||||
|
**Its `pi` floor is `>=0.84.3` and we pin exactly `0.84.3` — satisfied with zero
|
||||||
|
headroom.** Worth naming as a watch item rather than a problem: the next studio
|
||||||
|
release that raises the floor breaks the studio variant until `PI_VERSION` moves,
|
||||||
|
and that failure surfaces at build time in the studio job only, after the core
|
||||||
|
variant has already published.
|
||||||
|
|
||||||
|
### Also pulled in by the floating toolkit ref (documentation only)
|
||||||
|
|
||||||
|
RFC 003 gains **§9.2**, a proposed direction for the one open decision this
|
||||||
|
fleet keeps tripping over — that a report addressed to a device is never
|
||||||
|
delivered, because mailbox candidacy requires exactly `status="open"`. It records
|
||||||
|
a negative result worth keeping: widening the owed set to include terminal events
|
||||||
|
cannot work, since the asserting shape and the clearing shape must be disjoint or
|
||||||
|
every closure mints a fresh obligation. No code implements §9.2 in this release.
|
||||||
|
|
||||||
|
The skillset snapshot also moves, so this image bakes the mermaid-diagrams skill's
|
||||||
|
Playwright driver and the honest note that a `claimed` ack notifies nobody.
|
||||||
|
|
||||||
### Transcripts get scrubbed before they are staged (`3d47937`, `836e35b`, `f0bffd1`)
|
### Transcripts get scrubbed before they are staged (`3d47937`, `836e35b`, `f0bffd1`)
|
||||||
|
|
||||||
@@ -272,8 +349,6 @@ staged by a non-pi client, still lands unscrubbed.
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## v1.8.9 — 2026-08-26
|
## v1.8.9 — 2026-08-26
|
||||||
|
|
||||||
The coordination log gets a reader, and the release checklist's last gate stops
|
The coordination log gets a reader, and the release checklist's last gate stops
|
||||||
|
|||||||
Reference in New Issue
Block a user