Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .claude-plugin/marketplace.json
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@
"name": "engraphis-memory",
"source": "./",
"description": "Discipline for giving agents durable, scoped, explainable memory across sessions and repos with the Engraphis MCP tools.",
"version": "1.7.8"
"version": "1.7.9"
}
]
}
2 changes: 1 addition & 1 deletion .claude-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "engraphis-memory",
"version": "1.7.8",
"version": "1.7.9",
"description": "Give agents durable, scoped, explainable memory across sessions and repos via the Engraphis MCP tools. Use when you learn something worth keeping, need prior context before acting, or ask why/how a fact changed. Covers remember/recall, why/timeline, forget/pin/correct, sessions, and code search.",
"author": {
"name": "The Engraphis Authors",
Expand Down
4 changes: 2 additions & 2 deletions .claude-plugin/skill-assets.sha256
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
df65a383a1ff80572fb6ebd9a807dca6d1ffc0f99f373971262de035b8e3622d .claude-plugin/marketplace.json
a03b5c38d836651d2c5c52173d21a5adeacfbbc4b80aac991c2154b6e060e174 .claude-plugin/plugin.json
c1d184247775c8b3bf4d3f185d54fcac983aca8c54638a05d85b21e20db3ae7c .claude-plugin/marketplace.json
c5d0c26f28c9ee14092f9deaf24c98dd8bef49d971fef2b7a537ffb1ab9f2887 .claude-plugin/plugin.json
aeee7a94671ceb306fe2d24c5acc9f2d96ad8a8e7410536566799eea6265f080 skills/engraphis-memory/SKILL.md
055655db84af07561d002f0c69744313d8413c39f3e873f941f0fa0b1e76dc66 skills/engraphis-memory/references/CONVENTIONS.md
9d090a03f5b3f36a34d91f66b72c3844591f6915755ac3a6c6ba5f1b16977de5 skills/engraphis-memory/references/SCOPING.md
Expand Down
10 changes: 5 additions & 5 deletions BENCHMARKS.md
Original file line number Diff line number Diff line change
Expand Up @@ -94,14 +94,14 @@ interpretation and do not count as additional benchmark-quality gains.
### Public numeric evidence registry

Every exact public aggregate retained below comes from the checked-in, public-safe
[`offline-fixtures-v115.json`](docs/benchmark-evidence/offline-fixtures-v115.json) artifact. Its
[`offline-fixtures-v117.json`](docs/benchmark-evidence/offline-fixtures-v117.json) artifact. Its
SHA-256 is
`4d2cd6be29324597f0b201f8c0bd753173be69d24a274dff570c95c0db6ae629`, also recorded in the
`c64eadffbc7f87938e0e822b7aab33dcfece6fffa5175932ac208465d36df192`, also recorded in the
adjacent `.sha256` file. The artifact contains no raw questions, answers, prompts, customer data,
or per-record content fingerprints.

The fixture-suite digest is
`ddf3b70d426441a364ef02967f98454435ca045c3840e1c4b81ba05ab7f139bb`. The artifact defines
`77b140068cd036330b421a0d7668847d196f1bbeaa36c965d68943457002e6eb`. The artifact defines
the digest algorithm and records the SHA-256 of every suite and dataset file. Each evidence ID
also binds its exact command through `sha256(UTF-8 exact command)`:

Expand All @@ -123,10 +123,10 @@ Historical LoCoMo, graph, handoff, consolidation, and security figures remain pr
source artifacts but are omitted from the current chart until each has a matching immutable,
public-safe artifact. The chart labels coding outcomes, external datasets, and operational
capacity as pending evaluation tracks rather than implying scores. Regenerate it with
`python scripts/render_benchmark_report.py --report docs/benchmark-evidence/offline-fixtures-v115.json --output docs/images/context-efficiency.svg` after selecting the report to publish.
`python scripts/render_benchmark_report.py --report docs/benchmark-evidence/offline-fixtures-v117.json --output docs/images/context-efficiency.svg` after selecting the report to publish.

The companion examples are also generated from that artifact with
`python -m scripts.render_benchmark_examples --report docs/benchmark-evidence/offline-fixtures-v115.json --output docs/images/evidence-backed-agent-examples.svg`.
`python -m scripts.render_benchmark_examples --report docs/benchmark-evidence/offline-fixtures-v117.json --output docs/images/evidence-backed-agent-examples.svg`.
The historical-to-executable mapping is in
[`docs/BENCHMARK_CHANGE_COVERAGE.md`](docs/BENCHMARK_CHANGE_COVERAGE.md).

Expand Down
14 changes: 12 additions & 2 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,16 @@
All notable changes to Engraphis are documented here. Format loosely follows
[Keep a Changelog](https://keepachangelog.com/); versions use SemVer.

## [Unreleased]
## [Unreleased]

## [1.7.9] - 2026-09-29

- Added the saved-session managed Jev transport and Classic/Smart MCP decision route
for Pro and Team, with explicit consent and current hosted entitlement checks.
Cloud activation remains a separate rollout requirement; see the upgrade and
qualification instructions in `docs/RELEASE_1_7_9.md`.
- Retire consumed refresh credentials when a successful response has an invalid
token subject, and keep empty graph-layer selections separate from all-layer cache entries.

- Provide a valid offline decision example in Smart MCP action discovery.
- Reject coerced numeric/string remote consent before Classic MCP can select a Jev backend.
Expand Down Expand Up @@ -36,7 +45,8 @@ All notable changes to Engraphis are documented here. Format loosely follows
- Rebuild FastMCP settings eagerly to avoid a forward-reference warning on newer SDKs.
- Preserve CSS gradient tiles, screen blending and reduced-motion opacity in graph PNGs,
including fractional display scaling; synchronize graph cache metadata across threads.
- Refreshed the public offline fixtures and source bindings in immutable v111 evidence.
- Refreshed public offline fixtures and source bindings in immutable v117 evidence for 1.7.9.
- Campaign adapter capabilities and metrics now report the loaded Engraphis runtime version.

- Added saved project-to-workspace routing and connection instructions so agents can use the
user's selected workspace. Routine MCP calls inherit an omitted workspace from an authorized
Expand Down
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -84,9 +84,9 @@ neither is an end-to-end question-answer score. Coding outcomes, external datase
operational capacity remain separate pending evaluation tracks until their artifacts are selected.

These values are evidence IDs `offline-chunking` and `offline-performance` in
[`offline-fixtures-v115.json`](https://github.com/Coding-Dev-Tools/engraphis/blob/main/docs/benchmark-evidence/offline-fixtures-v115.json),
[`offline-fixtures-v117.json`](https://github.com/Coding-Dev-Tools/engraphis/blob/main/docs/benchmark-evidence/offline-fixtures-v117.json),
SHA-256
`4d2cd6be29324597f0b201f8c0bd753173be69d24a274dff570c95c0db6ae629`.
`c64eadffbc7f87938e0e822b7aab33dcfece6fffa5175932ac208465d36df192`.
[`BENCHMARKS.md`](https://github.com/Coding-Dev-Tools/engraphis/blob/main/BENCHMARKS.md#public-numeric-evidence-registry)
records the matching suite digest, exact commands, and per-command config digests. The offline
fixture registry intentionally excludes external, model-dependent, consolidation, productivity,
Expand Down
6 changes: 6 additions & 0 deletions docs/HOSTED_PLANS.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,12 @@ particular deployment has enabled Jev; the service checks current entitlement an
Usage and availability are reported by the account portal. No latency, accuracy, or cost-saving
guarantee is established by client configuration or a successful health check.

The managed transport and MCP decision route require client **1.7.9 or newer**.
The published 1.7.8 client has an experimental adapter but does not provide this route.
After 1.7.9 is published, upgrade the Python environment that launches your MCP host
and restart that host. See the [1.7.9 upgrade and release checklist](RELEASE_1_7_9.md).
Installing a new client does not enable a deployment whose managed service is disabled.

Set `ENGRAPHIS_DECISION_BACKEND=managed` and connect the installation through the ordinary
Cloud account flow. The client refreshes its saved session and sends only to that session's
bound control origin. `auto` chooses this managed route when configured; it never silently
Expand Down
71 changes: 71 additions & 0 deletions docs/RELEASE_1_7_9.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,71 @@
# Engraphis 1.7.9 release preparation

This candidate packages the reviewed managed Jev client and graph fixes from
Core PRs #238 through #241. Its base is
`f10dbc40de2d8bb2b0b7ab9bddb4870f6115a64c`. Preparing a version and validating its
source does not publish it or enable the Cloud service. The existing 1.7.8
release remains immutable.

## Customer upgrade after publication

Managed Jev requires both this client and an enabled, qualified Cloud deployment.
The published 1.7.8 distribution contains an experimental injected adapter but
does not ship the managed transport or the registered MCP decision tool.

1. Upgrade the Python environment that actually launches MCP. For an MCP
installation, run `python -m pip install --upgrade "engraphis[mcp]==1.7.9"`
after this version is published. Preserve any other extras your installation
needs. Check the installation with `python -m pip show engraphis`.
2. Keep an existing valid saved Cloud session. If the installation is not
connected, use the account portal's generated `engraphis connect` command in
that same environment. Never copy a provider key into a customer installation.
3. Set `ENGRAPHIS_DECISION_BACKEND=managed` in the process environment or the
owner-private `~/.engraphis/config.env`. A searched working-directory `.env`
is not a trusted configuration source. Restart the MCP host.
4. Classic MCP exposes `engraphis_decide`. In Smart MCP, discover the decision
action and execute it using the returned schema and `engraphis_execute_action`.
Every remote request requires literal `allow_remote=true` and a
`data_classification` of `public` or `internal`. Review the text before sending
it. Requests classified as secret and recognized secret patterns are rejected;
`offline_mode=true` prevents remote execution. Pattern filtering cannot detect
every secret in arbitrary prose.

The service enforces current membership, entitlement, monthly allowance and a
separate fleet cap. A local success, fallback, health response or configured
backend does not establish a successful managed provider request. The account
portal reports availability and usage. Jev advice does not authorize actions or
replace deterministic checks.

## Qualification and publication sequence

1. Freeze the final reviewed source and give all package, plugin and commercial
version surfaces the same unused version, 1.7.9. Preserve historical evidence;
generate new offline fixtures and skill checksums for these bytes.
2. Pass the required CI checks on the final commit. The release workflow checks
that the package version matches `v1.7.9` and that its commit is on protected
`main`. Merge and tag creation remain release-owner actions.
3. Build and retain the exact wheel and source archive. Verify their manifests,
dependency/security results, installed-client journeys and reproducibility.
Local candidate builds are preparation; the final publication artifacts must
match the signed qualification after the final source is selected.
4. Complete the private full-product ledger, including the selected Cloud/site
identities, staging acceptance, recovery/rollback evidence and real Pro/Team
saved-session Jev journeys. Run `check_release_readiness.py --require-release`
with that ledger and its actual evidence. An unresolved gate stays unresolved.
5. The existing owner-controlled release authority must review the completed
ledger and issue a fresh, time-bounded Ed25519 qualification for the exact
commit, distribution hashes, candidate ID and ledger digest. Keep private-key
custody outside this repository, workflow artifacts and runners. Preparing
this branch does not create a signing key, select an approver or grant approval.
6. Supply the four protected `release-qualification` environment secrets required
by [the qualification contract](RELEASE_QUALIFICATION.md), and obtain its
configured authorized review. Verify the envelope with
`python -m scripts.verify_release_qualification --dist DIST --commit COMMIT --tag v1.7.9`
against those independently selected identities before publication.
7. Publish through the existing release workflow. Check PyPI and GitHub artifact
hashes against the qualified bytes, then verify a fresh customer upgrade and
update public availability only from the accepted deployment and client.

The old v1.7.6 and v1.7.8 waivers apply only to their named retained candidates.
They cannot qualify or authorize this release. See [release readiness](RELEASE_READINESS.md)
for the mandatory evidence categories and recovery requirements.
Loading
Loading