Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
35 commits
Select commit Hold shift + click to select a range
527c077
feat(backends): add EngraphisCloudDecisionClient and update Pro/Team …
Coding-Dev-Tools Sep 28, 2026
aad1e34
fix: harden cloud decisions and recent graph and release regressions
Coding-Dev-Tools Sep 28, 2026
e2883d9
fix: bound decision response time and preserve streamed body limits
Coding-Dev-Tools Sep 28, 2026
a04f166
fix: enforce decision deadline while parsing response headers
Coding-Dev-Tools Sep 28, 2026
75e6274
fix: bound proxy CONNECT responses by decision deadline
Coding-Dev-Tools Sep 28, 2026
be61950
fix: share decision deadline across connection retries and sends
Coding-Dev-Tools Sep 28, 2026
2b16d92
fix: require an explicit non-fallback decision response
Coding-Dev-Tools Sep 28, 2026
1c3e88f
fix: keep loopback decision credentials away from proxies
Coding-Dev-Tools Sep 28, 2026
3ccbb58
test: compare exact hostname in proxy routing expectations
Coding-Dev-Tools Sep 28, 2026
9cb95f6
fix: serialize GitHub release publication and retained repairs
Coding-Dev-Tools Sep 28, 2026
b0a51de
feat(workspaces): route project memory and preview selective moves
Coding-Dev-Tools Sep 28, 2026
39bf4e2
Integrate deadline and release safeguards before workspace routing
Coding-Dev-Tools Sep 28, 2026
04941d6
Bind workspace routing evidence to the integrated safeguards
Coding-Dev-Tools Sep 28, 2026
a2f63c7
Probe descendant cleanup after timeout without a scheduler race
Coding-Dev-Tools Sep 28, 2026
7bba568
Run CodeQL security gates for stacked Codex pull requests
Coding-Dev-Tools Sep 28, 2026
1b3c297
fix(release): remove unsupported concurrency queue key and recheck La…
Coding-Dev-Tools Sep 28, 2026
baf1052
fix(release): retain supported publication queue
Coding-Dev-Tools Sep 28, 2026
92d0f94
fix(pi): pin patched IP classification dependency across candidate stack
Coding-Dev-Tools Sep 28, 2026
44764fe
merge: carry patched Pi dependency into workspace routing candidate
Coding-Dev-Tools Sep 28, 2026
a498e03
fix(pi): update test host and audit development dependencies
Coding-Dev-Tools Sep 28, 2026
6b0537c
Merge Pi test host security fix into workspace organization
Coding-Dev-Tools Sep 28, 2026
15eeb57
Separate relocation policy from bounded transactional storage operations
Coding-Dev-Tools Sep 29, 2026
69f427e
Preserve existing line endings in evidence documentation
Coding-Dev-Tools Sep 29, 2026
3af569c
Keep evidence refresh limited to changed content
Coding-Dev-Tools Sep 29, 2026
4fd41bc
Keep maximum workspace moves compatible with legacy SQLite limits
Coding-Dev-Tools Sep 29, 2026
9321e60
Clarify explicitly scoped reads with unknown sessions
Coding-Dev-Tools Sep 29, 2026
e00581e
Refresh shipped skill checksum for scoped-read guidance
Coding-Dev-Tools Sep 29, 2026
ecfff5f
fix(ci,pi): patch new Pi advisories and stop Windows hiding step fail…
claude Sep 30, 2026
8ae79b7
Merge the Pi advisory and Windows CI fix from #238 into #239
claude Sep 30, 2026
fce655b
Fix the locked Pi test dependency without waiving audits
Coding-Dev-Tools Oct 1, 2026
9515c65
Include the fully audited Pi dependency fix in workspace routing
Coding-Dev-Tools Oct 1, 2026
df123e5
Pin npm for reproducible Pi shrinkwrap repair on both runners
Coding-Dev-Tools Oct 1, 2026
ac5ba42
Pin the compatible npm runtime in PR 239
Coding-Dev-Tools Oct 1, 2026
0ff3300
Allow large installed-journey wheels to survive slow download pauses
Coding-Dev-Tools Oct 1, 2026
cf41fd7
Carry installed-journey download resilience into PR 239
Coding-Dev-Tools Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions .claude-plugin/skill-assets.sha256
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
df65a383a1ff80572fb6ebd9a807dca6d1ffc0f99f373971262de035b8e3622d .claude-plugin/marketplace.json
a03b5c38d836651d2c5c52173d21a5adeacfbbc4b80aac991c2154b6e060e174 .claude-plugin/plugin.json
4bc8979b9ffeb97190960e551dbf4ddc6f7aeeb7b86894fd2298a59ff0001efa skills/engraphis-memory/SKILL.md
816a798114813dece58d5daa19ad403b692ac5bbd2f736db1709b5c69d831b83 skills/engraphis-memory/SKILL.md
055655db84af07561d002f0c69744313d8413c39f3e873f941f0fa0b1e76dc66 skills/engraphis-memory/references/CONVENTIONS.md
62019760766ff472a76a0f81437898f39e3c1fe2631732b7b7733e50c1ad837f skills/engraphis-memory/references/SCOPING.md
9e5f1c8e91ca5697e828ab9e468504b8e1aa28e34f61307c9fcd850969126be9 skills/engraphis-memory/references/TOOLS.md
9d090a03f5b3f36a34d91f66b72c3844591f6915755ac3a6c6ba5f1b16977de5 skills/engraphis-memory/references/SCOPING.md
3f6e506715bf08e4d79955f8d64aea55b131b4a1842f6020e2886dda1197b185 skills/engraphis-memory/references/TOOLS.md
14 changes: 13 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -235,13 +235,23 @@ jobs:
python -m pip install -e ".[test]"
- name: Install and verify the Pi package
working-directory: integrations/pi
# Windows defaults to pwsh, which reports only the last command's exit code.
shell: bash
env:
ENGRAPHIS_PI_TEST_COMMAND: engraphis-mcp
run: |
# npm 10 crashes while repairing a nested published shrinkwrap.
npm install --global --ignore-scripts npm@11.12.1
npm ci --ignore-scripts
# The test host's published shrinkwrap overrides this package's nested pin.
# Repair that exact leaf in the installed host, preserving its other locked deps.
# --omit=dev excludes the host's own authoring tools, not this package's test tools.
npm install --prefix node_modules/@earendil-works/pi-coding-agent --ignore-scripts --no-save --omit=dev brace-expansion@5.0.12
node -e "require('node:assert/strict').equal(require('./node_modules/@earendil-works/pi-coding-agent/node_modules/brace-expansion/package.json').version, '5.0.12')"
npm run verify
npm run test:integration
npm audit --omit=dev
npm audit
npm audit --no-package-lock --include=dev

browser-accessibility:
name: browser accessibility smoke
Expand Down Expand Up @@ -441,7 +451,9 @@ jobs:
wheels = list(Path("dist").glob("*.whl"))
assert len(wheels) == 1
profile = os.environ["ENGRAPHIS_SMOKE_PROFILE"]
# Large server wheels can pause longer than pip's default socket timeout.
subprocess.run([str(executable), "-m", "pip", "install",
"--timeout", "120", "--retries", "5",
str(wheels[0].resolve()) + f"[{profile}]"], check=True)
subprocess.run([str(executable), "-m", "pip", "check"], check=True)
(root / "environment.lock").write_text(subprocess.check_output(
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,8 @@ on:
push:
branches: [main]
pull_request:
branches: [main]
# Stacked PRs must receive the same security gate before reaching main.
branches: [main, "codex/**"]
schedule:
- cron: "23 4 * * 1"

Expand Down
34 changes: 32 additions & 2 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -892,6 +892,11 @@ jobs:

github-release:
name: Publish GitHub Release
# Share one publication lock with repairs, including runs on other refs.
concurrency:
group: engraphis-github-release-publication
cancel-in-progress: false
queue: max
needs: publish
environment: release-qualification
if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v')
Expand Down Expand Up @@ -953,6 +958,11 @@ jobs:

github-release-repair:
name: Repair GitHub Release
# Hold the lock from the Latest lookup through all GitHub release writes.
concurrency:
group: engraphis-github-release-publication
cancel-in-progress: false
queue: max
environment: release-qualification
if: >-
github.event_name == 'workflow_dispatch' &&
Expand Down Expand Up @@ -1231,7 +1241,27 @@ jobs:
run: |
set -euo pipefail
notes_args=()
latest_args=(--latest)
promote_latest=true
if [ "$WAIVE_QUALIFICATION" = "true" ]; then
# A retained older repair must not displace a newer public Latest.
# Both authorized candidates already have a public release history;
# failed lookups or unknown tag formats stop before any release write.
current_latest="$(gh release view --repo "$GH_REPO" --json tagName --jq .tagName)"
promote_latest="$(python - "$RELEASE_TAG" "$current_latest" <<'PY'
import re
import sys

def version(tag):
if re.fullmatch(r"v(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)", tag) is None:
raise SystemExit("Latest release comparison requires stable version tags")
return tuple(map(int, tag[1:].split(".")))

print("true" if version(sys.argv[1]) >= version(sys.argv[2]) else "false")
PY
)"
latest_args=(--latest=false)
if [ "$promote_latest" = "true" ]; then latest_args=(--latest); fi
{
printf '## Release qualification\n\n'
printf 'The owner waived full-product qualification for this release. Mandatory full-product gates are not represented as passed.\n\n'
Expand All @@ -1254,7 +1284,7 @@ jobs:
gh release upload "$RELEASE_TAG" verified-dist/* release-evidence/* \
--repo "$GH_REPO" \
--clobber
if [ "$WAIVE_QUALIFICATION" = "true" ]; then
if [ "$WAIVE_QUALIFICATION" = "true" ] && [ "$promote_latest" = "true" ]; then
gh release edit "$RELEASE_TAG" --repo "$GH_REPO" --latest
fi
else
Expand All @@ -1264,5 +1294,5 @@ jobs:
--generate-notes \
"${notes_args[@]}" \
--title "Engraphis ${RELEASE_TAG#v}" \
--latest
"${latest_args[@]}"
fi
10 changes: 5 additions & 5 deletions BENCHMARKS.md
Original file line number Diff line number Diff line change
Expand Up @@ -94,14 +94,14 @@ interpretation and do not count as additional benchmark-quality gains.
### Public numeric evidence registry

Every exact public aggregate retained below comes from the checked-in, public-safe
[`offline-fixtures-v80.json`](docs/benchmark-evidence/offline-fixtures-v80.json) artifact. Its
[`offline-fixtures-v103.json`](docs/benchmark-evidence/offline-fixtures-v103.json) artifact. Its
SHA-256 is
`ac63dac1e34c66b658eeb5846599ef42d774a5e212860b2a909941f364c82bc2`, also recorded in the
`549bf84dc7dc6193e983ea0c710ffd4ce1d1c4d492344faaa026056d1c1a5445`, also recorded in the
adjacent `.sha256` file. The artifact contains no raw questions, answers, prompts, customer data,
or per-record content fingerprints.

The fixture-suite digest is
`431b525443f5b4875646e7f6470d107f584120bdd6ee7f53d0b6484d003fa0f7`. The artifact defines
`29f1bdec1d05138fe5a1f1cc9a83f329869620aae9e9cc4527d6cde5816336fc`. The artifact defines
the digest algorithm and records the SHA-256 of every suite and dataset file. Each evidence ID
also binds its exact command through `sha256(UTF-8 exact command)`:

Expand All @@ -123,10 +123,10 @@ Historical LoCoMo, graph, handoff, consolidation, and security figures remain pr
source artifacts but are omitted from the current chart until each has a matching immutable,
public-safe artifact. The chart labels coding outcomes, external datasets, and operational
capacity as pending evaluation tracks rather than implying scores. Regenerate it with
`python scripts/render_benchmark_report.py --report docs/benchmark-evidence/offline-fixtures-v80.json --output docs/images/context-efficiency.svg` after selecting the report to publish.
`python scripts/render_benchmark_report.py --report docs/benchmark-evidence/offline-fixtures-v103.json --output docs/images/context-efficiency.svg` after selecting the report to publish.

The companion examples are also generated from that artifact with
`python -m scripts.render_benchmark_examples --report docs/benchmark-evidence/offline-fixtures-v80.json --output docs/images/evidence-backed-agent-examples.svg`.
`python -m scripts.render_benchmark_examples --report docs/benchmark-evidence/offline-fixtures-v103.json --output docs/images/evidence-backed-agent-examples.svg`.
The historical-to-executable mapping is in
[`docs/BENCHMARK_CHANGE_COVERAGE.md`](docs/BENCHMARK_CHANGE_COVERAGE.md).

Expand Down
35 changes: 35 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,41 @@ All notable changes to Engraphis are documented here. Format loosely follows

## [Unreleased]

- Updated the Pi extension's locked `fast-uri` to 3.1.8, `ip-address` to 10.7.2 and
`brace-expansion` to 5.0.12. CI repairs the Pi test host's embedded vulnerable leaf with
that exact pin, verifies the installed version, and audits both the full dependency lock
and installed tree. Pi checks use bash on Windows, so every install, build, test and audit
failure stops the job.
- Kept selective-memory relocation policy independent of SQL through a domain storage
protocol, with bounded reads and caller-owned transaction rollback.
- Kept 500-memory moves within the legacy SQLite variable limit.
- Reran the unchanged public fixtures into immutable v103 source-bound evidence.

- Updated the Pi test host to 0.87.1 to include the patched WebSocket client, and
extended the Pi dependency audit to cover its development dependencies.
- Updated the Pi extension's locked `ip-address` dependency to 10.5.1, fixing
IPv6 link-local and NAT64 classification advisories without changing its dependency ranges.
- Added saved project-to-workspace routing and connection instructions so agents can use the
user's selected workspace. Routine MCP calls inherit an omitted workspace from an authorized
session or repo mapping, report the resolved destination, and reject session mismatches.
- Command Code's SessionStart hook now uses the nearest Git root's repo name, honors saved
workspace mappings unless explicitly overridden, and labels recalled context with the
server's resolved workspace.
- Added a previewed selective move workflow for organizing mixed workspaces while retaining
source history and enforcing move eligibility and workspace access.
- Hardened the experimental Cloud decision client with validated destinations,
redirect refusal, bounded responses, strict decision parsing, and read-only
result interfaces. Loopback endpoints bypass proxies and reject external DNS
destinations. Managed availability and performance remain unverified.
- Fixed the spacetime overlay's final paused frame being skipped by paint throttling.
- Enforced a Cloud request deadline across connection retries, TLS, request sends,
proxy handshakes, slow headers, and chunk framing. Preserved HTTP 413 for streamed oversized read-only
requests across parser versions.
- Prevented retained-release waiver repairs from replacing a newer GitHub Latest
release, with a shared publication queue to serialize GitHub release writes.
- Reran the public offline fixtures into immutable v88 evidence and refreshed its
source bindings, documentation, and charts.

## [1.7.8] - 2026-09-27

- Improved graph rendering and overlay scheduling, preserved saved Compact and custom
Expand Down
25 changes: 19 additions & 6 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -84,9 +84,9 @@ neither is an end-to-end question-answer score. Coding outcomes, external datase
operational capacity remain separate pending evaluation tracks until their artifacts are selected.

These values are evidence IDs `offline-chunking` and `offline-performance` in
[`offline-fixtures-v80.json`](https://github.com/Coding-Dev-Tools/engraphis/blob/main/docs/benchmark-evidence/offline-fixtures-v80.json),
[`offline-fixtures-v103.json`](https://github.com/Coding-Dev-Tools/engraphis/blob/main/docs/benchmark-evidence/offline-fixtures-v103.json),
SHA-256
`ac63dac1e34c66b658eeb5846599ef42d774a5e212860b2a909941f364c82bc2`.
`549bf84dc7dc6193e983ea0c710ffd4ce1d1c4d492344faaa026056d1c1a5445`.
[`BENCHMARKS.md`](https://github.com/Coding-Dev-Tools/engraphis/blob/main/BENCHMARKS.md#public-numeric-evidence-registry)
records the matching suite digest, exact commands, and per-command config digests. The offline
fixture registry intentionally excludes external, model-dependent, consolidation, productivity,
Expand Down Expand Up @@ -415,9 +415,19 @@ the indicated read or action executor; no profile selection is required. The gat
the discovered capability again before it runs it, and clients remain responsible for their
normal destructive-action approval boundary.

Existing clients that pin the historical 35 named tools can use
Existing clients that use named tools can use
`engraphis-mcp-classic` (or `engraphis-mcp-http --classic`). The complete classic inventory,
including `engraphis_check_update`, is in the [MCP tool reference](https://github.com/Coding-Dev-Tools/engraphis/blob/main/docs/MCP_TOOLS.md).

### Choose where agent memories belong

Use the dashboard's agent connection setup to choose a workspace, save a repo-to-workspace
mapping, and copy project-specific agent instructions. Routine MCP calls with an omitted
workspace can inherit the supplied session or saved repo mapping. Explicit workspace values,
including `"default"`, take precedence; update older instructions or hooks that hardcode them.
Memory types describe the kind of memory, not its destination. See
[workspace organization](https://github.com/Coding-Dev-Tools/engraphis/blob/main/docs/WORKSPACE_ORGANIZATION.md)
for setup, routing precedence, and previewing moves of existing memories.

### Pi extension

Expand All @@ -429,6 +439,9 @@ For installation, configuration, lifecycle commands, and the local trust boundar
`integrations/commandcode/` ships a SessionStart hook that warms up a new
session with bounded, recalled context from the local Engraphis gateway. Fails
open on timeout and is installed via `python scripts/install_cc_hook.py`.
The hook sends the nearest Git root's name as `repo` and lets the server apply a saved workspace
mapping. Set `ENGRAPHIS_HOOK_WORKSPACE` only for an explicit override; a previous `default`
override must be cleared to use the mapping. Its context header shows the resolved workspace.

### prime-agent fleet

Expand Down Expand Up @@ -651,7 +664,7 @@ when you are ready to evaluate the service boundary and billing options.
| | Free (available now) | Pro: $10/mo or $100/yr | Team: $20/seat/mo or $200/seat/yr |
|---|---|---|---|
| Dashboard WebUI (with built-in inspector) | ✓ | ✓ | ✓ |
| Memory engine + Smart MCP (Classic 35-tool compatibility) | ✓ | ✓ | ✓ |
| Memory engine + Smart MCP (Classic 38-tool compatibility) | ✓ | ✓ | ✓ |
| Version-chain diffs, offline knowledge graph | ✓ | ✓ | ✓ |
| Manual local consolidation (dry-run by default) | ✓ | ✓ | ✓ |
| Local workspace export (portable v2 JSON: memories, source manifests, graph/code evidence, sessions, audit, and receipts) | ✓ | ✓ | ✓ |
Expand All @@ -669,7 +682,7 @@ when you are ready to evaluate the service boundary and billing options.

## MCP tools

Engraphis exposes a zero-configuration Smart MCP gateway plus a 35-tool Classic compatibility
Engraphis exposes a zero-configuration Smart MCP gateway plus a 38-tool Classic compatibility
server across memory, recall, code graphs, governance, sessions, and privacy-safe audit receipts.
The focused [MCP tool reference](https://github.com/Coding-Dev-Tools/engraphis/blob/main/docs/MCP_TOOLS.md) is the source for
the full inventory and parameters.
Expand Down Expand Up @@ -859,7 +872,7 @@ engraphis/
│ ├── backends/ # pluggable embedder / vector index / reranker / codegraph / sync transports / encryption
│ ├── factory.py # outer v2 composition root; selects and injects concrete backends
│ ├── service.py # validated MemoryService facade
│ ├── mcp_server.py # Smart MCP gateway + 35-tool Classic compatibility server
│ ├── mcp_server.py # Smart MCP gateway + 38-tool Classic compatibility server
│ ├── dashboard_app.py # dashboard WebUI (FastAPI)
│ ├── dashboard_assets/ # primary Ledger interface + graph engine
│ ├── classic_assets/ # selectable full operator dashboard backup
Expand Down
2 changes: 1 addition & 1 deletion docs/ARCHITECTURE_V3.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ current schema version is 16).
flowchart LR
Agent["Agent / host LLM"] --> Intent["remember · link · recall_context (compact) · recall"]
CLI["engraphis-graph CLI"] --> Service["MemoryService"]
MCP["Smart MCP (9 tools) / Classic MCP (35 tools)"] --> Service
MCP["Smart MCP (9 tools) / Classic MCP (38 tools)"] --> Service
HTTP["Dashboard + read-only graph HTTP"] --> Service
Import["Local resources / PostgreSQL catalog"] --> Extractors["Optional local extractors"]
Extractors --> Service
Expand Down
9 changes: 9 additions & 0 deletions docs/HOSTED_PLANS.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,5 +28,14 @@ The email-confirmed, no-card trial lasts three active days for Pro and ten activ
24 hours. It does not extend a trial or subscription, grant cloud access, or affect the free
local tools. `recovery_read_only` supports hosted account recovery and export after grace.

## Experimental decision adapter

The source includes an opt-in Jev advisory adapter and a client for the experimental
`POST /v1/jev/decide` Cloud endpoint. It is not connected to core memory writes or
grounded recall. Callers supply a client and pinned model and explicitly authorize
each remote request; offline mode keeps these calls local by declining the request.
Managed availability, plan entitlements, quotas, latency, and savings require separate
service verification and are not established by this client implementation.

See [Licensing and commercial service boundary](LICENSING.md) for the full source and service
boundary, and [Cloud Sync](SYNC.md) for the sync security model.
Loading
Loading