100 Commits
Author SHA1 Message Date
AkitaOnRails e2d7d17d90 fix(run): allow same-owner lease recovery
Refs #795
2026-10-01 16:18:44 -03:00
AkitaOnRails ae1eabe7e0 docs(scope): retain session-aware project routing
Closes #943.
2026-10-01 14:53:36 -03:00
AkitaOnRails 11f7061c51 docs(changelog): record release archive drift guard 2026-10-01 14:33:15 -03:00
AkitaOnRails 37f89020db Merge pull request #1029 from rubenlr/fix/1025-upgrade-packaging-allowlist 2026-10-01 14:31:05 -03:00
AkitaOnRails 53985bddc4 Merge pull request #1028 from MarconiVini/fix/upgrade-deleted-hook-path
Harden the shared renderer and preserve the loaded upgrade config.
2026-10-01 14:03:58 -03:00
AkitaOnRails a1255e3486 test(wrapper): pin container fixtures to script hooks 2026-10-01 13:56:51 -03:00
AkitaOnRails 9e5bfe9f9c fix(upgrade): accept complete release archives
Fixes #1025
2026-10-01 13:54:42 -03:00
AkitaOnRails 2ee5642815 fix(wrapper): enforce capture policy in hook installs
Fixes #1002
2026-10-01 13:45:52 -03:00
AkitaOnRails 15a26421a3 fix(workstream): recover stale Codex daemon runs
Fixes #987
2026-10-01 13:40:39 -03:00
AkitaOnRails 6d723d946d Merge remote-tracking branch 'pr/1026' into resolution/main-2026-10-01
# Conflicts:
#	CHANGELOG.md
2026-10-01 12:32:28 -03:00
AkitaOnRails 2303527a96 fix(run): make jail preflight path portable 2026-10-01 12:24:39 -03:00
AkitaOnRails 7f8b95fea5 fix(run): preflight ai-jail availability 2026-10-01 12:24:19 -03:00
AkitaOnRails 3dce1c503f fix(ci): remove redundant test import 2026-10-01 12:17:12 -03:00
AkitaOnRails a69bf66072 Merge remote-tracking branch 'refs/remotes/pr/1024' into resolution/main-2026-10-01
# Conflicts:
#	CHANGELOG.md
2026-10-01 12:14:42 -03:00
AkitaOnRails 8b0fe5a929 Merge remote-tracking branch 'refs/remotes/pr/1023' into resolution/main-2026-10-01
# Conflicts:
#	CHANGELOG.md
2026-10-01 12:14:06 -03:00
AkitaOnRails 0966ecc230 fix(capture): keep invalid-marker diagnostics panic-free (#1021) 2026-10-01 12:12:24 -03:00
AkitaOnRails 1be2c929cb Merge remote-tracking branch 'refs/remotes/pr/1021' into resolution/main-2026-10-01 2026-10-01 12:09:58 -03:00
AkitaOnRails 112f2c03d2 Merge remote-tracking branch 'refs/remotes/pr/1020' into resolution/main-2026-10-01 2026-10-01 12:09:47 -03:00
AkitaOnRailsandClaude Opus 5.5 7580b74d0f test(run): give the jail e2e fixture the OS's own sandbox backend
usable_ai_jail requires bwrap on Linux but sandbox-exec on macOS, and the
fixture's PATH holds only its own fakes, so on the macOS runner ai-jail read
as unusable and --jail correctly failed closed. Write the backend the host OS
needs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-10-01 04:06:53 -03:00
AkitaOnRailsandClaude Opus 5.5 dfbcfc21a5 chore(release): 2.5.2
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-10-01 03:48:34 -03:00
AkitaOnRailsandClaude Opus 5.5 80a78d0255 fix(run): make an explicit ai-jail selection exact with --no-X for unselected rows
The checklist and `--jail=LIST` emitted only enabled toggles, so the user's
own ai-jail config (e.g. a global `~/.ai-jail` enabling `docker`) could still
mount what an unchecked row or an explicit list left out, and the summary
line misreported it.

- Interactive checklist: `marked_choices` passes every row the user saw,
  checked as `--X` and unchecked as `--no-X`.
- `--jail=LIST` (including `none`): after the named entries, every visible
  checklist row the list did not name is forced off with `--no-X`. Rows that
  are not visible (absent credentials, CLI-only toggles) are never forced.
- Bare `--jail` is unchanged: smart-default rows only, the rest left to the
  user's ai-jail config, because no selection was shown.
- `JailToggleChoice::implied` marks rows forced off by omission, so the
  summary names the user's own `no-X` entries and says "everything else in
  the checklist off" for the rest.
- Tests: an adversarial unit test (unchecked docker row and `--jail=none`
  yield `--no-docker` / `--no-*` for every visible row, with bare `--jail`
  as the control); parse, checklist, summary and end-to-end expectations
  updated, the latter platform-aware for the Linux-only rows.
- Docs: design §5 semantics, cookbook, support matrix, CHANGELOG.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-10-01 03:42:50 -03:00
AkitaOnRailsandClaude Opus 5.5 7e0ec65899 feat(run): choose ai-jail toggles with --jail[=LIST], --no-jail, and a checklist
`ai-memory run` can now decide which ai-jail credentials and capabilities a
jailed session gets, from the CLI or an interactive checklist, with smart
defaults so Enter does the friendly thing.

- ai-memory-workstream/jail.rs: a toggle table (credential mounts github,
  aws, kube, gcloud, docker-config; ssh; worktree; docker, gpu, display,
  pictures, tailscale; CLI-only audio, x11, host-shm, terminal-passthrough,
  update-check, mise, toolchains), support detection from the installed
  ai-jail's `--help` (exact `--X` tokens, so `--docker` never matches
  `--docker-config`), injected host facts (home, SSH agent, origin URL,
  linked worktree, project `.ai-jail` presence), the checklist with smart
  defaults, and the `--jail=` list parser (`no-X`, `all`, `none`; reserved
  security switches and ai-memory-owned flags refused).
- build_ai_jail_invocation emits the chosen `--X`/`--no-X` and a
  `--no-save-config` baseline before the `--`, so ai-jail never writes the
  run's transient flags into the repository's `.ai-jail`.
- inspect_repository reports the `origin` URL and whether the cwd is a
  linked worktree.
- run.rs: `--jail[=TOGGLES]` / `--no-jail` (also stripped when they land in
  the native argv), a pure jail_decision table, an explicit `--jail` re-exec
  before the managed run is prepared (failing closed when ai-jail is not
  usable), and the line-based checklist after the `--yolo` offer. A project
  `.ai-jail` replaces the checklist and the bare-`--jail` defaults.
- Tests: unit coverage for parsing, support detection, defaults, the
  decision table, flag stripping, and the checklist grammar; a real
  `ai-jail --dry-run` over every toggle the installed ai-jail advertises;
  end-to-end runs of the built binary with fake ai-jail/bwrap/claude and a
  mock server, including PTY runs of the offer, the checklist, a project
  `.ai-jail`, and `--yolo --no-jail`.
- Docs: design §5, cookbook yolo recipe, support matrix, CHANGELOG.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-10-01 03:32:13 -03:00
AkitaOnRailsandClaude Opus 5.5 56c2a60358 docs(changelog): reference GHSA-gf78-hf8g-vffm for #999
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-10-01 03:00:10 -03:00
AkitaOnRails 4720291893 Merge fix/wiki-racy-read-enoent: retry a walk that read a vanished file
# Conflicts:
#	CHANGELOG.md
2026-10-01 02:51:07 -03:00
AkitaOnRails 2de6227e0f Merge docs/2.5.2-audit-fixes: frontend-api, windows, Codex daemon drift 2026-10-01 02:51:07 -03:00
AkitaOnRails a502068ebe Merge PR #1008: docs: design proposal for offer-not-claim handoff delivery (#959) 2026-10-01 02:51:07 -03:00
AkitaOnRails dfed757b4e Merge PR #1006: fix(wiki): write the index file on every checkpoint (#983)
# Conflicts:
#	CHANGELOG.md
2026-10-01 02:51:07 -03:00
AkitaOnRails ae62d18827 Merge PR #1001: fix(hooks): send the [briefing] keys on the session-start handoff GET
# Conflicts:
#	CHANGELOG.md
2026-10-01 02:51:07 -03:00
AkitaOnRails daeca8108e Merge PR #756: fix(cli): apply message send admission and post-commit observers
# Conflicts:
#	CHANGELOG.md
2026-10-01 02:51:07 -03:00
AkitaOnRails aeb81aef14 Merge PR #999: fix(read_page): include_related only walks pages the caller may read 2026-10-01 02:51:06 -03:00
AkitaOnRails 9bcfabd60e Merge PR #1014: chore(deps): bump astral-sh/setup-uv from 10.1.0 to 10.2.0 2026-10-01 02:50:37 -03:00
AkitaOnRails d1baad60e3 Merge PR #1013: chore(deps): bump docker/setup-qemu-action from 4.2.0 to 4.4.0 2026-10-01 02:50:37 -03:00
AkitaOnRails 0bca7e30e2 Merge PR #1012: chore(deps): bump docker/build-push-action from 7.3.0 to 7.4.0 2026-10-01 02:50:36 -03:00
AkitaOnRails 86ab639cf2 Merge PR #1011: chore(deps): bump docker/setup-buildx-action from 4.3.0 to 4.4.1 2026-10-01 02:50:36 -03:00
AkitaOnRailsandClaude Opus 5.5 af8ed952e7 fix(wiki): retry a commit whose walk read a file that vanished mid-scan
is_racy_read only recognized libgit2's Filesystem-class "file changed before
we could read it", so the Os-class "failed to read file into stream" (ENOENT:
listed by the walk, gone when streamed in — e.g. an atomic writer's temp file
renamed away) failed the checkpoint outright instead of taking the bounded
racy-read retry. Seen as an intermittent
concurrent_commits_queue_instead_of_failing failure on a loaded CI runner
(v2.5.1 RC dispatch run). Classifier unit test covers both racy shapes and
two non-racy controls; it fails with the old single-branch check.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-10-01 02:50:21 -03:00
AkitaOnRailsandClaude Opus 5.5 013bf691fd docs: fix audited drift in frontend-api, windows, and Codex managed runs
- frontend-api.md (#986): the list, search, and recent routes return bare
  JSON arrays, not `{ "workspaces": … }`-style wrappers (the route tests
  assert `as_array()`); a page read returns `body_markdown`, not `body`; a
  search hit carries workspace/project/kind and no `id`.
- windows.md (#758): native `ai-memory upgrade` is done (#801/#802), not
  in-progress.
- managed-workstreams.md + support matrix (#987): document the Codex shared
  daemon handing hooks a stale AI_MEMORY_RUN_ID and the `--no-daemon`
  workaround until the server-side fix lands.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-10-01 02:47:14 -03:00
AkitaOnRailsandClaude Opus 5.5 18c6949fcc docs(design): fold maintainer review into the offer-not-claim proposal (#959)
Accept the design with corrections verified against the code: note the
existing live-source skip (LIVE_BATON_QUIET_PERIOD) and handoff expiry
(expire_same_cwd_auto_handoffs + post-claim sweep), so open question 5 is
mostly answered; require the notice to name the exact handoff_id; keep the
managed-run ledger claim at session start in offer mode; weigh a per-project
marker key over a server-wide switch; let an explicit accept by id ignore
to_agent; fix the memory_handoff_pop reference.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-10-01 02:43:38 -03:00
AkitaOnRails 4c7bc5b7ad Merge main into #1006 (resolve CHANGELOG against the stamped [2.5.1])
# Conflicts:
#	CHANGELOG.md
2026-10-01 02:41:21 -03:00
AkitaOnRails 949b5ae657 Merge main into #1001 (resolve CHANGELOG against the stamped [2.5.1])
# Conflicts:
#	CHANGELOG.md
2026-10-01 02:41:21 -03:00
AkitaOnRailsandClaude Opus 5.5 8addf87969 fix(admin): refuse a rejected message send with 403, add boundary row 8e
An admission refusal is a policy decision, as on the MCP path
(invalid_request), not a server fault, so the admin send route now answers 403
instead of 500, and the reject test asserts that status. Records the
MCP/admin admission parity as security-boundaries row 8e; the reject test
fails when the send authorizes against an op the webhook does not subscribe
to.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-10-01 02:40:19 -03:00
AkitaOnRails 02c414e534 Merge main into #756 (resolve CHANGELOG against the stamped [2.5.1])
# Conflicts:
#	CHANGELOG.md
2026-10-01 02:39:10 -03:00
AkitaOnRailsandClaude Opus 5.5 ef2e83a2d2 test(mcp): pin #999's viewer at the memory_read_page call site
The store test proves related_walk filters every hop, but nothing failed if
memory_read_page passed `None` instead of the caller's viewer — exactly the
2.5.0/2.5.1 leak. bob_does_not_see_restricted_pages_through_the_related_walk
drives the real tool as an ungranted user (restricted page absent from
`related`) with a no-viewer control, and fails with the call reverted to
`None`. Cited in security-boundaries row 14d.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-10-01 02:37:15 -03:00
AkitaOnRails 458eca6962 Merge main into #999 (resolve CHANGELOG against the stamped [2.5.1])
# Conflicts:
#	CHANGELOG.md
2026-10-01 02:33:36 -03:00
AkitaOnRailsandClaude Opus 5.5 695805eb88 chore(release): 2.5.1
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-10-01 01:59:39 -03:00
AkitaOnRailsandClaude Opus 5.5 ae676d4918 fix(run): ai-jail re-exec/offer, --true-yolo semantics, and relaunch after an interrupted run
ai-jail integration (`ai-memory run --yolo`):
- The re-exec built `ai-jail <flags> <exe> run …` with no `--`. ai-jail
  rejects one of its own flags after the command and `run` shares flag names
  with it, so `run claude --yolo --env GH_TOKEN=…` aborted. The invocation now
  emits `--` before the wrapped exe (forwarding a colliding flag additionally
  needs ai-jail >= 2.4.2, whose guard honors the separator; the cross-tool
  test gates on that version).
- The offer only checked for a file named ai-jail: Windows could show it, a
  host without bwrap/sandbox-exec was offered a jail that cannot start, and a
  ~/.local/bin-only install was offered and then not found by the bare
  `Command::new("ai-jail")` re-exec after the run was already cancelled.
  usable_ai_jail(os, lookup) now returns the exact binary to exec only on
  Linux/macOS with the backend present; otherwise no question is asked.

--true-yolo:
- It now implies --yolo (warning, ai-jail offer, harness dangerous mode):
  alone it used to apply Claude's bypassPermissions with no warning. It is
  interchangeable with --yolo for non-Claude harnesses, and recognized after
  native arguments (`run claude --model opus --true-yolo`), where clap leaves
  it in the native argv and it was forwarded to Claude as an unknown option.
- The claude_true_yolo config key only upgrades an explicit yolo launch, as
  its doc comment stated, instead of bypassing permissions on every run.
- Removed what never worked: three CLAUDE_CODE_DISABLE_*RM* env vars Claude
  Code does not read (absent from the 2.1.280 binary and its env reference),
  and an empty permissions.ask array that cannot clear ask rules from other
  scopes (Claude unions them). Docs now state that Claude honors explicit ask
  rules and its command-safety checks in every permission mode.

Relaunch after an interrupted run:
- A launcher killed before releasing its lease (terminal closed, ai-jail
  torn down) left the workstream held for up to 90s and the next launch failed
  after a 5s retry. An interactive launch now parses the holder and expiry from
  the 409, waits for that lease to lapse (bounded by one lease; Ctrl-C aborts),
  then proceeds. A holder that renews meanwhile is reported as live and never
  displaced; the server's busy check stays the only arbiter (security
  inventory row 13b). Non-interactive launches keep the short window.

Tests: usable_ai_jail OS/backend/Windows/exact-path, `--` placement and the
colliding-flag regression (unit + real ai-jail --dry-run), the yolo_modes
table, --true-yolo in both argv positions via real clap parses, the reduced
true-yolo argv, and HTTP-level held-lease wait / renewed-owner / Ctrl-C cases.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-10-01 01:53:49 -03:00
AkitaOnRailsandClaude Opus 4.8 85ddc1f450 fix(security): derive capture-exclusion path flavor from the host (GHSA-vh98)
A capture-exclusion candidate or shell argument spelled with a leading `//`
(e.g. `//repo/secret/token.txt`) self-classified as a Windows UNC path
regardless of the actual host. On a POSIX host `match_paths` then filtered it
against zero POSIX `ignore_paths` patterns (a flavor mismatch), so the file was
captured instead of dropped — a fail-open in the capture trust boundary.

Path flavor for an untrusted candidate is now derived from the host (the cwd):
on a POSIX host a leading `//` collapses to a single `/` before classification,
so it matches POSIX `ignore_paths` as intended. A genuine Windows/UNC host's
UNC candidates are unaffected. Fixed in both front doors — the native hook
(`ai-memory-hooks` `capture_policy.rs`) and the generated TypeScript
integrations (`ai-memory-cli` `render_shared.rs`, `captureHostWindows` /
`windowsHost`) — with a shared regression fixture and an adversarial test per
surface (violation + POSIX control + Windows-UNC control).

Also documents (docs/users.md) that a trusted-proxy non-root user is
`AuthLevel::User` with no DB identity, so `restricted`/grant enforcement does
not apply to them — the proxy is the authz boundary — and records that boundary
and its pinning test in docs/security-boundaries.md.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-30 21:47:41 -03:00
AkitaOnRailsandClaude Opus 4.8 4b39007c55 fix(security): bump importer rustls to 0.23.45 + audit importer lockfile in CI
RUSTSEC-2026-0285 (rustls <0.23.45, TLS1.3 wrong-encryption-level handshake
accept; GHSA-2mjx-qc3c-rqvc / referenced by GHSA-wc7c-cm87-463c). The main and
relay lockfiles were already at 0.23.45; the importer companion sat at 0.23.41
because CI never audited companions/ai-memory-importer/Cargo.lock. Bump it and
add that lockfile to the cargo-audit step so the drift class is caught. Also
drop the now-stale RUSTSEC-2026-0194/0195 (quick-xml) ignores — quick-xml is in
none of the three lockfiles.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-30 21:18:26 -03:00
AkitaOnRailsandClaude Opus 4.8 a8757a05a9 chore(release): 2.5.0
Minor release. Highlights: safer `--yolo` (warning + ai-jail offer + Claude
true-yolo, #994), per-repository server profiles (#996/#992), handoff-accept
status discriminant (#990), OpenCode 2 routing + turn checkpoints (#865),
finalize-session-on-exit for hookless harnesses (#944), repository `identity`
pinning (#708), reconcile-tombstone opt-in (#964), plus retrieval/consolidation
config, /web multi-user pages, native upgrade, hermes skills, and Fedora RPMs.
Full list in CHANGELOG [2.5.0].

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-30 15:57:29 -03:00
AkitaOnRails 62196091fa Merge PR #996: per-repository server profiles (fixes #992) 2026-09-30 15:55:27 -03:00
AkitaOnRailsandClaude Opus 4.8 db63360f5b docs(changelog): restore the Keep-a-Changelog preamble on release/2.5
A prior forward-merge CHANGELOG reconstruction dropped the '# Changelog' /
Keep-a-Changelog header from release/2.5's CHANGELOG (main and the v2.4.2 tag
were unaffected). Restore it so the file — and the generated release notes —
start with the standard preamble again. No entry content changed.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-30 15:53:28 -03:00
AkitaOnRailsandClaude Opus 4.8 0a7554c86f docs: fill 2.5.0 config reference gaps + fix stale Hermes/tool-count
Pre-release doc-staleness sweep for 2.5.0:
- ARCHITECTURE.md config reference: add the [maintenance] section
  (enabled/forget_sweep/lint/embedding_backfill intervals +
  reconcile_tombstones_deleted_pages, #929/#964) and release_base_url (#801).
- README support matrix: Hermes Agent Community -> Supported, aligning the
  compact table with the authoritative docs/support-matrix.md (#933 hooks +
  #942 skills are first-party).
- research-codebase-memory-mcp.md: correct the stale '19 tools' -> 23.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-30 15:44:55 -03:00
AkitaOnRails c8a34b8460 Merge main into release/2.5 (forward-merge: #997 docs + Kimi {} fix)
# Conflicts:
#	CHANGELOG.md
2026-09-30 14:52:03 -03:00
AkitaOnRailsandClaude Opus 4.8 dbf2391d5c docs(changelog): record the cherry-picked Kimi {} fix (#996)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-30 14:43:51 -03:00
AkitaOnRails 345a9dd1c9 Merge PR #997: document API Route as an openai-compat provider 2026-09-30 14:43:28 -03:00
AkitaOnRails 7e17939881 Merge PR #990: status discriminant on memory_handoff_accept (fixes #988) 2026-09-30 00:04:10 -03:00
AkitaOnRails a7b268363c Merge main into release/2.5 (forward-merge: 2.4.2 + #995 #985 #984 #978 #991)
# Conflicts:
#	CHANGELOG.md
#	crates/ai-memory-hooks/src/router.rs
#	docs/security-boundaries.md
2026-09-30 00:04:01 -03:00
AkitaOnRails dcb475c6bb Merge PR #991
# Conflicts:
#	CHANGELOG.md
2026-09-29 23:44:02 -03:00
AkitaOnRails c1ab66157e Merge PR #978 2026-09-29 23:43:43 -03:00
AkitaOnRails ed91e1dfb4 Merge PR #984
# Conflicts:
#	CHANGELOG.md
2026-09-29 23:43:43 -03:00
AkitaOnRails 8898fe8fdb Merge PR #985
# Conflicts:
#	CHANGELOG.md
2026-09-29 23:43:24 -03:00
AkitaOnRails eb9a3c8568 Merge PR #995 2026-09-29 23:43:05 -03:00
AkitaOnRailsandClaude Opus 4.8 7a7cd277e2 chore(changelog): correct PR ref to #994
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-29 17:30:30 -03:00
AkitaOnRailsandClaude Opus 4.8 80888360e2 feat(run): warn before --yolo, offer ai-jail, add Claude true-yolo (#983)
ai-memory run --yolo now, on an interactive TTY only (never in hook/CI/
detached paths):

- warns that --yolo runs every tool call unconfirmed, [Y/n] default-yes;
- offers to re-run inside ai-jail when it is installed, re-execing the
  original argv under `ai-jail --network --agent-state --env <NAME>…`
  (--network shares the host net namespace so the loopback ai-memory server
  stays reachable; only already-set credential/config env is forwarded);
- skips both prompts when already inside ai-jail (Linux hostname ai-sandbox
  / macOS PS1 (jail) ; fails open to showing the warning; Windows never).

Opt-in Claude "true yolo" (--true-yolo / [config] claude_true_yolo,
AI_MEMORY_CLAUDE_TRUE_YOLO) silences the pauses --dangerously-skip-permissions
leaves: sets the CLAUDE_CODE_DISABLE_*_RM_* env vars and injects
--settings bypassPermissions. Claude-only, off by default, sandbox-first.

Detection and argv assembly are pure/OS-explicit (ai-memory-workstream::jail)
with unit tests for every branch; a CLI integration suite asserts the argv
against the real ai-jail via --dry-run (skips cleanly when ai-jail/bwrap are
absent). Design: docs/design-yolo-safety-ai-jail.md.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-29 15:24:14 -03:00
AkitaOnRailsandClaude Opus 4.8 a0ca8d1a5f chore(release): 2.4.2
Patch release from the 2.4.x line. Fixes: sanitize observation titles before
truncating (#982/#980), export-okf interoperability (#979/#960), the prior
#967-#973 batch, and more. Docs: TLS-interception recipe (#954), Cheaper
Inference provider doc (#981), OpenRouter and backup docs (#949/#950, recorded
as documentation of already-shipped behavior). No new capabilities → patch.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-29 13:27:08 -03:00
AkitaOnRailsandClaude Opus 4.8 e408340fb9 fix(merge): reconcile release/2.5 batch integration
- ids.rs: #944 and #921 each hoisted SessionId::from_native; keep one
  definition (git auto-merged both into a duplicate).
- render_shared.rs: align the generated-TS shell flag with the native
  capture_policy determination (shell = non-file && name != web_search)
  after #966 added search_web/manage_task/manage_subagents to the non-file
  list — the two front doors must agree.
- mount.rs / admin_repair_session_times.rs: set the WebMountSpec
  trusted_proxy_identity and AdminState contradiction_band_min/max fields
  that main added, in the release/2.5-side test constructors that predated
  them.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-29 12:44:06 -03:00
AkitaOnRailsandClaude Opus 4.8 4bb4d55df6 docs(security-boundaries): add row 4f for #944 finalize-on-exit ownership guard
#944 adds a finalize-on-exit entry point that resolves a native session; per
invariant #16 and the security-boundary rule, record that own_native_session
refuses a discovered/concurrent session and the test that proves it.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-29 12:38:22 -03:00
AkitaOnRails 8aeb422a9c Merge PR #921: repair-backfill-timestamps restores original session start/end
# Conflicts:
#	CHANGELOG.md
#	crates/ai-memory-store/src/lib.rs
#	docs/ARCHITECTURE.md
#	docs/lifecycle-ops.md
#	docs/security-boundaries.md
2026-09-29 12:37:40 -03:00
AkitaOnRails dcf4e6512c Merge PR #944: finalize hookless session on exit (fixes #941)
# Conflicts:
#	docs/support-matrix.md
2026-09-29 12:34:25 -03:00
AkitaOnRails 66d99f9e28 Merge PR #966: native Antigravity CLI output.txt resolution (fixes #965)
# Conflicts:
#	crates/ai-memory-cli/src/commands/render_shared.rs
#	crates/ai-memory-hooks/src/capture_policy.rs
2026-09-29 12:33:28 -03:00
AkitaOnRails bf17ff250c Merge main into release/2.5 (forward-merge: #982 #979 #981 #977-stress + docs #954)
# Conflicts:
#	CHANGELOG.md
#	crates/ai-memory-cli/src/commands/render_shared.rs
#	crates/ai-memory-web/src/routes/api.rs
#	docs/security-boundaries.md
2026-09-29 12:30:56 -03:00
AkitaOnRailsandClaude Opus 4.8 da13f091f9 docs(https-via-proxy): recipe for TLS-inspecting firewalls / MITM roots (#954)
ai-memory's reqwest client is built with rustls-tls-native-roots, so it trusts
the OS store and honors SSL_CERT_FILE/SSL_CERT_DIR. Document how to give the
container a combined CA bundle (public roots + the interception root) so
outbound LLM/embedding calls stop failing with UnknownIssuer behind a
corporate MITM appliance or inspecting antivirus. Cross-referenced from
deploy.md's provider-failures troubleshooting bullet.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-29 12:15:43 -03:00
AkitaOnRailsandClaude Opus 4.8 80ed9e0bc7 docs(install): soften Cheaper Inference pricing claim to match the vendor
The submitted text stated a specific '15–60% less' range the vendor site does
not substantiate; reword to a claim we can stand behind (below list price)
without quoting an unverified figure.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-29 12:14:29 -03:00
AkitaOnRails f1b6635ed4 Merge PR #981: document Cheaper Inference as an openai-compat provider 2026-09-29 12:14:11 -03:00
AkitaOnRails eb2d4dd3f8 Merge PR #979: export-okf interoperability (fixes #960) 2026-09-29 12:14:04 -03:00
AkitaOnRailsandClaude Opus 4.8 ef05ddc04a docs(security-boundaries): cite #980 title-scrub-before-truncate tests in row 7
The sanitizer boundary (row 7, invariant #6) gained enforcing code in #982:
Sanitized::new now scrubs the title before applying the 80-char display cap.
Per the mandatory security-boundary rule, record the adversarial tests that
would fail if the guard were removed.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-29 12:14:00 -03:00
AkitaOnRails 90156efaf9 Merge PR #982: sanitize observation titles before truncating (fixes #980) 2026-09-29 12:13:39 -03:00
AkitaOnRailsandClaude Opus 4.8 2bbef8db30 chore(release): place #964 under Added (config key = minor) and add security-boundaries row 10e
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-28 22:54:14 -03:00
AkitaOnRailsandClaude Opus 4.8 0e560e3925 docs(data-handling): correct the retention-expiry claim (#972)
DATA_HANDLING.md said there is no built-in retention expiry, but the daily
forget sweep tombstones cold episodic pages (below [decay] cold_threshold)
and hard-deletes them after hard_delete_after_days, and TTL (expires_at) pages
expire too — both on by default. Describe the actual [decay]/TTL behavior and
what stays (semantic/procedural/pinned, raw observations).

Closes #972

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-28 22:40:45 -03:00
AkitaOnRails b6cef64a1f Merge PR #970 into main
# Conflicts:
#	CHANGELOG.md
2026-09-28 22:39:52 -03:00
AkitaOnRails 90d5157052 Merge PR #973 into main 2026-09-28 22:39:23 -03:00
AkitaOnRails d13400acb3 Merge PR #971 into main 2026-09-28 22:39:22 -03:00
AkitaOnRails 2e30160aca Merge PR #969 into main 2026-09-28 22:39:22 -03:00
AkitaOnRails 32665b4478 Merge PR #968 into main 2026-09-28 22:39:22 -03:00
AkitaOnRails ebac1cd636 Merge PR #967 into main 2026-09-28 22:39:22 -03:00
AkitaOnRailsandClaude Opus 4.8 1c4dbf378a fix(changelog): align released sections with main after forward-merge
The forward-merge's CHANGELOG rebuild took the [2.4.0]+ tail from release/2.5,
but the frozen-section CI check requires the released half (## [2.4.1] down) to
match origin/main byte-for-byte. Since main ⊆ release/2.5 now, main's released
history is authoritative — replaced the released half with main's verbatim.
[Unreleased] (all 2.5 features + merged main fixes) is unchanged.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-28 21:58:30 -03:00
AkitaOnRailsandClaude Opus 4.8 666617e91b fix(merge): thread occurred_at through release/2.5 test constructors
The main->release/2.5 forward-merge combined main's #919 (occurred_at field on
NewObservation/NewSession + a 4th end_admitted_session arg) and #926 (build_request
existing_titles arg) with release/2.5 test constructors that predate them. Adds
occurred_at: None to the affected literals, the missing args, and fixes doctor.rs
to import main's build_launch_plan (relocated_session_dir) after adopting the
injected session_dir_for closure. Preserves invariant #8 (embed_page_version uses
model_identity) and the AI_MEMORY_CAPTURE_OWNER gate in the generated TS capture policy.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-28 21:29:32 -03:00
AkitaOnRails b3d8e99746 Reapply "feat(consolidate): add input_token_safety_margin to bound approximate token budget (#884)"
This reverts commit 0fc60ffc24.
2026-09-28 21:19:04 -03:00
AkitaOnRails 4829c14d43 Merge main into release/2.5
Forward-merge to restore main ⊆ release/2.5: brings the 2.4.x fixes onto the
2.5 feature line. Retains the 2.5 features main reverted for the 2.4.1 patch
(#884 input_token_safety_margin, #873 jev docs); #904 stays reverted as on main.

# Conflicts:
#	.github/workflows/ci.yml
#	CHANGELOG.md
#	crates/ai-memory-cli/src/commands/backfill.rs
#	crates/ai-memory-cli/src/commands/doctor.rs
#	crates/ai-memory-cli/src/commands/render_shared.rs
#	crates/ai-memory-cli/tests/suite/removal.rs
#	crates/ai-memory-hooks/src/router.rs
#	crates/ai-memory-mcp/src/server.rs
#	crates/ai-memory-store/src/lib.rs
#	crates/ai-memory-wiki/src/wiki.rs
#	docs/jev-reranker-adapter.md
#	docs/security-boundaries.md
2026-09-28 21:18:08 -03:00
AkitaOnRailsandClaude Opus 4.8 afae0df346 docs(authz): record the resolved always-on identity-routing decision (#708)
Slice 4 (#925) identity routing was merged with its design-doc section
deferred pending the always-on vs opt-in review. Decision: always-on in
2.5.0 (opt-in would leave the same-basename grant hole open). Documents the
V70 no-backfill migration, lexical normalization, resolution order, and the
four-front-door parity.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-28 20:38:01 -03:00
AkitaOnRails 9d5c41e8ce Merge PR #925 into release/2.5
Route captures by repository identity, not folder name (#708)
2026-09-28 20:37:21 -03:00
AkitaOnRails e80856b63f Merge PR #963 into release/2.5
feat(admin): delete-workspace previews what it would delete before confirm
2026-09-28 20:37:20 -03:00
AkitaOnRails 74cafdfa66 Merge PR #961 into main
fix(hooks): apply capture ignore_paths to shell commands in generated TS integrations (#948)
2026-09-28 18:45:17 -03:00
AkitaOnRails 00de5af032 Merge PR #956 into release/2.5
# Conflicts:
#	CHANGELOG.md
2026-09-28 15:11:36 -03:00
AkitaOnRails 9eca45227c Merge PR #957 into release/2.5 2026-09-28 15:10:49 -03:00
AkitaOnRailsandClaude Opus 4.8 b46b1d18d7 docs(backup): fix status --json flag and widen secret excludes
The merged #952 recipe used `ai-memory status --format=json`, but StatusArgs
only has --json (no --format), so the snippet failed with unknown-argument.
Also widened the example script's SECRET_EXCLUDES default (and its doc
references) to include *.pem/*.key/*.crt so private CA bundles and keys under
the config dir are excluded from the mirror by default, matching the shipped
.gitignore.

Follow-up to #952 (#950).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-28 15:09:20 -03:00
AkitaOnRails 5abe10771b Merge PR #952 into main
# Conflicts:
#	CHANGELOG.md
2026-09-28 15:08:32 -03:00
AkitaOnRailsandClaude Opus 4.8 754690e241 docs(providers): don't assert OpenRouter serves embeddings
The merged #951 stated OpenRouter exposes an OpenAI-compatible /v1/embeddings
endpoint as fact; that is unverified (historically OpenRouter has not) and
would silently fail for a user who configured it. Reworded to a conditional
'verify it exists first' pointer and made the multilingual-embedder
recommendation provider-agnostic.

Follow-up to #951 (#949).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-28 15:07:47 -03:00
AkitaOnRails cd06133677 Merge PR #951 into main 2026-09-28 15:06:53 -03:00
AkitaOnRails c8a3dbc8c4 Merge PR #958 into main
# Conflicts:
#	CHANGELOG.md
2026-09-28 15:06:53 -03:00
AkitaOnRails f2dc0caff3 Merge PR #955 into main 2026-09-28 15:06:20 -03:00