Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
77 commits
Select commit Hold shift + click to select a range
527c077
feat(backends): add EngraphisCloudDecisionClient and update Pro/Team …
Coding-Dev-Tools Sep 28, 2026
aad1e34
fix: harden cloud decisions and recent graph and release regressions
Coding-Dev-Tools Sep 28, 2026
8d8d691
feat(jev): add TypeSafeDecisionClient BYOK adapter and tests
Coding-Dev-Tools Sep 28, 2026
e2883d9
fix: bound decision response time and preserve streamed body limits
Coding-Dev-Tools Sep 28, 2026
0d65753
feat(mcp,init): support BYOK Jev API key installation and decision ga…
Coding-Dev-Tools Sep 28, 2026
a04f166
fix: enforce decision deadline while parsing response headers
Coding-Dev-Tools Sep 28, 2026
75e6274
fix: bound proxy CONNECT responses by decision deadline
Coding-Dev-Tools Sep 28, 2026
be61950
fix: share decision deadline across connection retries and sends
Coding-Dev-Tools Sep 28, 2026
2b16d92
fix: require an explicit non-fallback decision response
Coding-Dev-Tools Sep 28, 2026
1c3e88f
fix: keep loopback decision credentials away from proxies
Coding-Dev-Tools Sep 28, 2026
3ccbb58
test: compare exact hostname in proxy routing expectations
Coding-Dev-Tools Sep 28, 2026
9cb95f6
fix: serialize GitHub release publication and retained repairs
Coding-Dev-Tools Sep 28, 2026
b0a51de
feat(workspaces): route project memory and preview selective moves
Coding-Dev-Tools Sep 28, 2026
c848591
Integrate consented managed Jev with saved Cloud sessions
Coding-Dev-Tools Sep 28, 2026
5d1163f
Preserve reviewed transport deadlines and fail closed on advisory fal…
Coding-Dev-Tools Sep 28, 2026
1f0f140
Fix Jev setup and loopback reviews, align trial contracts, and refres…
Coding-Dev-Tools Sep 28, 2026
39bf4e2
Integrate deadline and release safeguards before workspace routing
Coding-Dev-Tools Sep 28, 2026
04941d6
Bind workspace routing evidence to the integrated safeguards
Coding-Dev-Tools Sep 28, 2026
c7cfb38
Integrate workspace routing and Jev in one consistent tool catalog
Coding-Dev-Tools Sep 28, 2026
b036a2f
Bind combined workspace and Jev evidence to the validated source
Coding-Dev-Tools Sep 28, 2026
a2f63c7
Probe descendant cleanup after timeout without a scheduler race
Coding-Dev-Tools Sep 28, 2026
8562c01
Include credential refresh in the managed Jev request deadline
Coding-Dev-Tools Sep 28, 2026
f0e86b6
Merge commit 'a2f63c73' into codex/managed-jev-benefits-20260928
Coding-Dev-Tools Sep 28, 2026
ef19f70
Finalize clean source and immutable evidence for the combined core PR
Coding-Dev-Tools Sep 28, 2026
7bba568
Run CodeQL security gates for stacked Codex pull requests
Coding-Dev-Tools Sep 28, 2026
d320331
Merge remote-tracking branch 'origin/codex/workspace-organization-pr'…
Coding-Dev-Tools Sep 28, 2026
7cce7e4
Require member policy for remote Jev decisions
Coding-Dev-Tools Sep 28, 2026
46bfce3
Validate Jev decision inputs through actual transport contracts
Coding-Dev-Tools Sep 28, 2026
595a395
Reject conventional credential assignments before Jev requests
Coding-Dev-Tools Sep 28, 2026
f4dd95a
Normalize managed Jev bootstrap origins and clarify secure setup
Coding-Dev-Tools Sep 28, 2026
1b3c297
fix(release): remove unsupported concurrency queue key and recheck La…
Coding-Dev-Tools Sep 28, 2026
f985ff3
fix(jev): remove control-only setup and validation blockers
Coding-Dev-Tools Sep 28, 2026
3e7d024
fix: preserve reviewed GitHub release publication queue
Coding-Dev-Tools Sep 28, 2026
baf1052
fix(release): retain supported publication queue
Coding-Dev-Tools Sep 28, 2026
a3f2654
fix(jev): preserve trusted key updates and injected client compatibility
Coding-Dev-Tools Sep 28, 2026
49bd369
fix(cloud): preserve completed refresh rotations at request deadlines
Coding-Dev-Tools Sep 28, 2026
c442ce3
fix(pi): update vulnerable IP address classification dependency
Coding-Dev-Tools Sep 28, 2026
92d0f94
fix(pi): pin patched IP classification dependency across candidate stack
Coding-Dev-Tools Sep 28, 2026
44764fe
merge: carry patched Pi dependency into workspace routing candidate
Coding-Dev-Tools Sep 28, 2026
0645a41
merge: integrate the patched Pi dependency through the candidate stack
Coding-Dev-Tools Sep 28, 2026
fe46d79
fix(pi): update test host and audit development dependencies
Coding-Dev-Tools Sep 28, 2026
a498e03
fix(pi): update test host and audit development dependencies
Coding-Dev-Tools Sep 28, 2026
6b0537c
Merge Pi test host security fix into workspace organization
Coding-Dev-Tools Sep 28, 2026
87f19b8
Merge Pi host security checks through managed Jev stack
Coding-Dev-Tools Sep 28, 2026
3a9651a
fix(cloud): prove chunked refresh completion across watchdog expiry
Coding-Dev-Tools Sep 29, 2026
15eeb57
Separate relocation policy from bounded transactional storage operations
Coding-Dev-Tools Sep 29, 2026
69f427e
Preserve existing line endings in evidence documentation
Coding-Dev-Tools Sep 29, 2026
3af569c
Keep evidence refresh limited to changed content
Coding-Dev-Tools Sep 29, 2026
593b3cc
Bind managed Jev configuration to its credential origin and bound tra…
Coding-Dev-Tools Sep 29, 2026
4fd41bc
Keep maximum workspace moves compatible with legacy SQLite limits
Coding-Dev-Tools Sep 29, 2026
3700f68
Integrate reviewed workspace storage and publish final managed Jev ev…
Coding-Dev-Tools Sep 29, 2026
9321e60
Clarify explicitly scoped reads with unknown sessions
Coding-Dev-Tools Sep 29, 2026
201431b
Merge commit '9321e60d85f26ceedb947adf01df8349bdc307b7' into codex/ma…
Coding-Dev-Tools Sep 29, 2026
e00581e
Refresh shipped skill checksum for scoped-read guidance
Coding-Dev-Tools Sep 29, 2026
17df5f9
fix(skill): update SCOPING.md checksum in skill-assets manifest
Coding-Dev-Tools Sep 29, 2026
74be1b1
Merge branch 'codex/workspace-organization-pr' into codex/managed-jev…
Coding-Dev-Tools Sep 29, 2026
f969a47
fix(mcp): rebuild FastMCP Settings model before instantiation to reso…
Coding-Dev-Tools Sep 29, 2026
bc963ba
Integrate scoped-read skill checksum while retaining managed Jev assets
Coding-Dev-Tools Sep 29, 2026
bd309b4
Merge commit 'f969a476e8a6344557f4f4157c50f55a0298bc97' into codex/ma…
Coding-Dev-Tools Sep 29, 2026
85a4660
Refresh immutable evidence after MCP compatibility repair
Coding-Dev-Tools Sep 29, 2026
30b0f09
Require literal MCP remote consent and refresh immutable source evidence
Coding-Dev-Tools Sep 29, 2026
7899c6e
Make the discovered decision example valid and safely offline
Coding-Dev-Tools Sep 29, 2026
4b98e56
docs: explain managed and BYOK Jev decisions in README
Coding-Dev-Tools Sep 29, 2026
c9f42d6
fix: keep command decisions advisory and require complete inputs
Coding-Dev-Tools Sep 29, 2026
8f210d4
fix: retire consumed refreshes with invalid subject metadata
Coding-Dev-Tools Sep 29, 2026
ecfff5f
fix(ci,pi): patch new Pi advisories and stop Windows hiding step fail…
claude Sep 30, 2026
8ae79b7
Merge the Pi advisory and Windows CI fix from #238 into #239
claude Sep 30, 2026
c28fc4f
Merge the Pi advisory and Windows CI fix from #238 into #240
claude Sep 30, 2026
fce655b
Fix the locked Pi test dependency without waiving audits
Coding-Dev-Tools Oct 1, 2026
9515c65
Include the fully audited Pi dependency fix in workspace routing
Coding-Dev-Tools Oct 1, 2026
639cdbb
Include the fully audited Pi dependency fix in PR 240
Coding-Dev-Tools Oct 1, 2026
df123e5
Pin npm for reproducible Pi shrinkwrap repair on both runners
Coding-Dev-Tools Oct 1, 2026
ac5ba42
Pin the compatible npm runtime in PR 239
Coding-Dev-Tools Oct 1, 2026
6676b57
Pin the compatible npm runtime in PR 240
Coding-Dev-Tools Oct 1, 2026
0ff3300
Allow large installed-journey wheels to survive slow download pauses
Coding-Dev-Tools Oct 1, 2026
cf41fd7
Carry installed-journey download resilience into PR 239
Coding-Dev-Tools Oct 1, 2026
ca88a7f
Carry installed-journey download resilience into PR 240
Coding-Dev-Tools Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions .claude-plugin/skill-assets.sha256
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
df65a383a1ff80572fb6ebd9a807dca6d1ffc0f99f373971262de035b8e3622d .claude-plugin/marketplace.json
a03b5c38d836651d2c5c52173d21a5adeacfbbc4b80aac991c2154b6e060e174 .claude-plugin/plugin.json
4bc8979b9ffeb97190960e551dbf4ddc6f7aeeb7b86894fd2298a59ff0001efa skills/engraphis-memory/SKILL.md
aeee7a94671ceb306fe2d24c5acc9f2d96ad8a8e7410536566799eea6265f080 skills/engraphis-memory/SKILL.md
055655db84af07561d002f0c69744313d8413c39f3e873f941f0fa0b1e76dc66 skills/engraphis-memory/references/CONVENTIONS.md
62019760766ff472a76a0f81437898f39e3c1fe2631732b7b7733e50c1ad837f skills/engraphis-memory/references/SCOPING.md
9e5f1c8e91ca5697e828ab9e468504b8e1aa28e34f61307c9fcd850969126be9 skills/engraphis-memory/references/TOOLS.md
9d090a03f5b3f36a34d91f66b72c3844591f6915755ac3a6c6ba5f1b16977de5 skills/engraphis-memory/references/SCOPING.md
210e42da31fc68f41c83b3ab9eb1f91a415dbc1ef148f75b6b170bddc35d5752 skills/engraphis-memory/references/TOOLS.md
18 changes: 17 additions & 1 deletion .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -138,6 +138,22 @@ ENGRAPHIS_RETENTION_SUPERVISOR=none
# ENGRAPHIS_GRAPH_HOST=127.0.0.1
# ENGRAPHIS_GRAPH_PORT=8720

# ── System 1 Decision Gating (TypeSafe AI Jev) ───────────────────────────
# Advisory typed decisions for command screening and evidence assessment.
# Default none/local sends no requests; each remote call needs allow_remote=true.
# Pro & Team include a managed allowance when enabled by the service (no personal key needed).
# For BYOK, enter the key at a hidden prompt and pipe it directly to the CLI:
# python -c "import getpass,warnings; warnings.simplefilter('error',getpass.GetPassWarning); print(getpass.getpass('TypeSafe API key: '))" | engraphis-init --jev-key -
# The key stays out of shell history and process arguments. If hidden input is
# unavailable, the prompt fails instead of accepting visible input.
# Community/BYOK users can set their own TypeSafe API key:
# TYPESAFE_API_KEY=
# JEV_API_KEY=
# TYPESAFE_BASE_URL=https://api.typesafe.ai
# ENGRAPHIS_DECISION_BACKEND=none # none | local | managed | auto | byok
# ENGRAPHIS_DECISION_MODEL=jev-1.13.0


# Standalone MCP-over-HTTP server (`engraphis-mcp-http`). Loopback-only by default;
# any non-loopback bind (via these or ENGRAPHIS_HOST) requires ENGRAPHIS_API_TOKEN.
# ENGRAPHIS_HTTP_HOST=127.0.0.1
Expand Down Expand Up @@ -253,7 +269,7 @@ ENGRAPHIS_LLM_MODEL=gpt-4o-mini
# ENGRAPHIS_STATE_DIR=/data/.engraphis

# The private control plane may report ``workspace_write_grace`` for already-authorized
# hosted-account continuity, capped at 24 hours. It never extends the exact 3-day trial,
# hosted-account continuity, capped at 24 hours. It never extends the 7-day Pro or 14-day Team trial,
# subscription expiry, or cloud access, and it never restricts the free local core.

# Managed compute consent is decided automatically and needs no customer action: a
Expand Down
14 changes: 13 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -235,13 +235,23 @@ jobs:
python -m pip install -e ".[test]"
- name: Install and verify the Pi package
working-directory: integrations/pi
# Windows defaults to pwsh, which reports only the last command's exit code.
shell: bash
env:
ENGRAPHIS_PI_TEST_COMMAND: engraphis-mcp
run: |
# npm 10 crashes while repairing a nested published shrinkwrap.
npm install --global --ignore-scripts npm@11.12.1
npm ci --ignore-scripts
# The test host's published shrinkwrap overrides this package's nested pin.
# Repair that exact leaf in the installed host, preserving its other locked deps.
# --omit=dev excludes the host's own authoring tools, not this package's test tools.
npm install --prefix node_modules/@earendil-works/pi-coding-agent --ignore-scripts --no-save --omit=dev brace-expansion@5.0.12
node -e "require('node:assert/strict').equal(require('./node_modules/@earendil-works/pi-coding-agent/node_modules/brace-expansion/package.json').version, '5.0.12')"
npm run verify
npm run test:integration
npm audit --omit=dev
npm audit
npm audit --no-package-lock --include=dev

browser-accessibility:
name: browser accessibility smoke
Expand Down Expand Up @@ -441,7 +451,9 @@ jobs:
wheels = list(Path("dist").glob("*.whl"))
assert len(wheels) == 1
profile = os.environ["ENGRAPHIS_SMOKE_PROFILE"]
# Large server wheels can pause longer than pip's default socket timeout.
subprocess.run([str(executable), "-m", "pip", "install",
"--timeout", "120", "--retries", "5",
str(wheels[0].resolve()) + f"[{profile}]"], check=True)
subprocess.run([str(executable), "-m", "pip", "check"], check=True)
(root / "environment.lock").write_text(subprocess.check_output(
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,8 @@ on:
push:
branches: [main]
pull_request:
branches: [main]
# Stacked PRs must receive the same security gate before reaching main.
branches: [main, "codex/**"]
schedule:
- cron: "23 4 * * 1"

Expand Down
34 changes: 32 additions & 2 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -892,6 +892,11 @@ jobs:

github-release:
name: Publish GitHub Release
# Share one publication lock with repairs, including runs on other refs.
concurrency:
group: engraphis-github-release-publication
cancel-in-progress: false
queue: max
needs: publish
environment: release-qualification
if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v')
Expand Down Expand Up @@ -953,6 +958,11 @@ jobs:

github-release-repair:
name: Repair GitHub Release
# Hold the lock from the Latest lookup through all GitHub release writes.
concurrency:
group: engraphis-github-release-publication
cancel-in-progress: false
queue: max
environment: release-qualification
if: >-
github.event_name == 'workflow_dispatch' &&
Expand Down Expand Up @@ -1231,7 +1241,27 @@ jobs:
run: |
set -euo pipefail
notes_args=()
latest_args=(--latest)
promote_latest=true
if [ "$WAIVE_QUALIFICATION" = "true" ]; then
# A retained older repair must not displace a newer public Latest.
# Both authorized candidates already have a public release history;
# failed lookups or unknown tag formats stop before any release write.
current_latest="$(gh release view --repo "$GH_REPO" --json tagName --jq .tagName)"
promote_latest="$(python - "$RELEASE_TAG" "$current_latest" <<'PY'
import re
import sys

def version(tag):
if re.fullmatch(r"v(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)", tag) is None:
raise SystemExit("Latest release comparison requires stable version tags")
return tuple(map(int, tag[1:].split(".")))

print("true" if version(sys.argv[1]) >= version(sys.argv[2]) else "false")
PY
)"
latest_args=(--latest=false)
if [ "$promote_latest" = "true" ]; then latest_args=(--latest); fi
{
printf '## Release qualification\n\n'
printf 'The owner waived full-product qualification for this release. Mandatory full-product gates are not represented as passed.\n\n'
Expand All @@ -1254,7 +1284,7 @@ jobs:
gh release upload "$RELEASE_TAG" verified-dist/* release-evidence/* \
--repo "$GH_REPO" \
--clobber
if [ "$WAIVE_QUALIFICATION" = "true" ]; then
if [ "$WAIVE_QUALIFICATION" = "true" ] && [ "$promote_latest" = "true" ]; then
gh release edit "$RELEASE_TAG" --repo "$GH_REPO" --latest
fi
else
Expand All @@ -1264,5 +1294,5 @@ jobs:
--generate-notes \
"${notes_args[@]}" \
--title "Engraphis ${RELEASE_TAG#v}" \
--latest
"${latest_args[@]}"
fi
10 changes: 5 additions & 5 deletions BENCHMARKS.md
Original file line number Diff line number Diff line change
Expand Up @@ -94,14 +94,14 @@ interpretation and do not count as additional benchmark-quality gains.
### Public numeric evidence registry

Every exact public aggregate retained below comes from the checked-in, public-safe
[`offline-fixtures-v80.json`](docs/benchmark-evidence/offline-fixtures-v80.json) artifact. Its
[`offline-fixtures-v114.json`](docs/benchmark-evidence/offline-fixtures-v114.json) artifact. Its
SHA-256 is
`ac63dac1e34c66b658eeb5846599ef42d774a5e212860b2a909941f364c82bc2`, also recorded in the
`40188db31e07680e1c886ecec8ed523c6237858f0d5c63ef3159251c63538970`, also recorded in the
adjacent `.sha256` file. The artifact contains no raw questions, answers, prompts, customer data,
or per-record content fingerprints.

The fixture-suite digest is
`431b525443f5b4875646e7f6470d107f584120bdd6ee7f53d0b6484d003fa0f7`. The artifact defines
`6347175b1e4b3760e23afe2dcb7722d48557f987c45c7fcbd4f115e1e7720b54`. The artifact defines
the digest algorithm and records the SHA-256 of every suite and dataset file. Each evidence ID
also binds its exact command through `sha256(UTF-8 exact command)`:

Expand All @@ -123,10 +123,10 @@ Historical LoCoMo, graph, handoff, consolidation, and security figures remain pr
source artifacts but are omitted from the current chart until each has a matching immutable,
public-safe artifact. The chart labels coding outcomes, external datasets, and operational
capacity as pending evaluation tracks rather than implying scores. Regenerate it with
`python scripts/render_benchmark_report.py --report docs/benchmark-evidence/offline-fixtures-v80.json --output docs/images/context-efficiency.svg` after selecting the report to publish.
`python scripts/render_benchmark_report.py --report docs/benchmark-evidence/offline-fixtures-v114.json --output docs/images/context-efficiency.svg` after selecting the report to publish.

The companion examples are also generated from that artifact with
`python -m scripts.render_benchmark_examples --report docs/benchmark-evidence/offline-fixtures-v80.json --output docs/images/evidence-backed-agent-examples.svg`.
`python -m scripts.render_benchmark_examples --report docs/benchmark-evidence/offline-fixtures-v114.json --output docs/images/evidence-backed-agent-examples.svg`.
The historical-to-executable mapping is in
[`docs/BENCHMARK_CHANGE_COVERAGE.md`](docs/BENCHMARK_CHANGE_COVERAGE.md).

Expand Down
51 changes: 51 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,57 @@ All notable changes to Engraphis are documented here. Format loosely follows

## [Unreleased]

- Updated the Pi extension's locked `fast-uri` to 3.1.8, `ip-address` to 10.7.2 and
`brace-expansion` to 5.0.12. CI repairs the Pi test host's embedded vulnerable leaf with
that exact pin, verifies the installed version, and audits both the full dependency lock
and installed tree. Pi checks use bash on Windows, so every install, build, test and audit
failure stops the job.
- Provide a valid offline decision example in Smart MCP action discovery.
- Reject coerced numeric/string remote consent before Classic MCP can select a Jev backend.
- Require the credential-bound control origin before selecting managed Jev.
- Bound chunked response trailers while retaining strict deadline completion checks.
- Keep relocation policy behind domain storage operations and 500-memory moves
within the legacy SQLite variable limit.
- Updated the Pi test host to 0.87.1 to include the patched WebSocket client, and
extended the Pi dependency audit to cover its development dependencies.
- Updated the Pi extension's locked `ip-address` dependency to 10.5.1, fixing
IPv6 link-local and NAT64 classification advisories without changing its dependency ranges.
- Kept managed Jev available when an unrelated compute endpoint cannot resolve,
while retaining destination validation for requests that use compute.
- Bounded Jev key input and serialized configuration before publication, preserving
existing setup on rejection. Invalid decision kinds now defer without a fabricated
selection in direct, Classic, and Smart calls.
- Preserved owner-only configuration checks when updating an existing Jev key, and
restored support for legacy injected decision clients while retaining per-call consent
and a single provider invocation.
- Save fully received Cloud credential rotations before reporting an expired request
deadline, while rejecting truncated bodies and watchdog-interrupted responses.
- Recognize complete chunked refresh responses at the watchdog boundary without
accepting a missing or truncated trailer terminator.
- Rebuild FastMCP settings eagerly to avoid a forward-reference warning on newer SDKs.
- Refreshed the public offline fixtures and source bindings in immutable v110 evidence.

- Added saved project-to-workspace routing and connection instructions so agents can use the
user's selected workspace. Routine MCP calls inherit an omitted workspace from an authorized
session or repo mapping, report the resolved destination, and reject session mismatches.
- Command Code's SessionStart hook now uses the nearest Git root's repo name, honors saved
workspace mappings unless explicitly overridden, and labels recalled context with the
server's resolved workspace.
- Added a previewed selective move workflow for organizing mixed workspaces while retaining
source history and enforcing move eligibility and workspace access.
- Hardened the experimental Cloud decision client with validated destinations,
redirect refusal, bounded responses, strict decision parsing, and read-only
result interfaces. Loopback endpoints bypass proxies and reject external DNS
destinations. Managed availability and performance remain unverified.
- Fixed the spacetime overlay's final paused frame being skipped by paint throttling.
- Enforced a Cloud request deadline across connection retries, TLS, request sends,
proxy handshakes, slow headers, and chunk framing. Preserved HTTP 413 for streamed oversized read-only
requests across parser versions.
- Prevented retained-release waiver repairs from replacing a newer GitHub Latest
release, with a shared publication queue to serialize GitHub release writes.
- Reran the public offline fixtures into immutable v88 evidence and refreshed its
source bindings, documentation, and charts.

## [1.7.8] - 2026-09-27

- Improved graph rendering and overlay scheduling, preserved saved Compact and custom
Expand Down
Loading
Loading