Repository navigation
fix: declare exact dependency pins and quarantine exemptions - #3
Open
ethernet8023 wants to merge 223 commits into
Open
ethernet8023 wants to merge 223 commits into
ethernet8023 wants to merge 223 commits into
Conversation
The PreCompact auto-save hook hardcoded tags=[pre-compact, trigger] and never recorded which agent owned the session, so a mid-session compaction save during a scheduled-agent run (e.g. jacqueline-roadmap) landed with no agent: tag -- the LAC/LoreConvo UI showed AGENT=-- even though project was correctly stamped by the 2026-06-05 cwd fix (a5f92e49). The two are separate tag fields; only project was ever wired. Fix: run_agent_code.sh now exports LORECONVO_AGENT=$AGENT alongside the existing AGENT_RUN_SESSION_ID export, and pre_compact_save.py reads it and appends agent:<name> to the tags list when set. Interactive sessions leave the var unset and correctly get no agent tag. Tag is rebuilt every save so it lands on both the INSERT and UPDATE paths. Adds TestPreCompactAgentTag (4 cases: env set, env unset, blank/whitespace, update path). test_auto_save.py 28 passed.
…n; route to Lou (SH-11471)
Replace denylist approach with configurable export root (Option B). Export root defaults to ~/loreconvo-exports/ and is configurable via LORECONVO_EXPORT_DIR environment variable. All export paths must resolve within the configured root. Export root is created with chmod 700 on first use. Paths outside the root are rejected without revealing sensitive paths.
…base context manager Desktop app spawns a new MCP server process per chat session and parks the pipe open instead of closing it. With the old 30-min default, process count accumulated (seen: 42) and any one with a dangling write held the sqlite WAL write lock indefinitely, causing sessions.db 'database is locked' errors. Changes: - DEFAULT_IDLE_TIMEOUT: 1800s -> 300s (5 min). Desktop re-spawns on next tool call, so the shorter timeout is transparent to users. - SessionDatabase.__enter__/__exit__: ensures connection is closed on exception paths inside server handlers, not just on normal process exit. - CLAUDE.md: updated idle watchdog description to reflect new 5-min default.
…H-11639) auto_save.py hardcoded tags=['auto-saved'] in both the insert and update paths, so crash-stub saves from scheduled agents were invisible to agent-tagged recall. New auto_save_tags() merges agent:<name> + run:<id> from LORECONVO_AGENT / AGENT_RUN_SESSION_ID (both already exported by run_agent_code.sh) when present. Interactive/customer sessions set neither var and are unchanged. 3 new tests.
- Add --version flag to both standalone CLIs (typer callback reading importlib.metadata, fallback to literal on source checkout) - __init__.py now sources __version__ from installed dist metadata (single source of truth = pyproject), no more hardcoded literal - Add pinned requirements.txt to both CLIs (typer==0.13.1), matching the parent-product convention and the dual-pin mandate - Bump Development Status classifier 3 Alpha -> 4 Beta (both) - SH-10656 (folded in): loreconvo server src/cli.py now reads version from importlib.metadata instead of hardcoded 0.6.0 Tests: loreconvo-cli 15/15, loredocs-cli 9/9. pip-audit clean (typer). Pre-prod hardening only -- NO make-public action taken.
…sionDatabase.__init__ Commit cc4ef7e6 (ron-builder-b post-session sweep) added a call to self._validate_journal_mode() but never defined the method, causing AttributeError on every SessionDatabase instantiation. WAL mode is already set inline via PRAGMA journal_mode=WAL one line earlier, so the call was dead intent. Surfaced while testing the Hermes client (SH-11654).
…mes Agent setup docs)
loreconvo-cli and loredocs-cli are separate products with their own repos. CLI docs belong in those repos, not the MCP plugin READMEs.
Bug-report + feature-request issue forms (YAML) plus a config.yml with an email-support contact link for all three public repos. Forms include a privacy note telling users not to paste license keys / private memory or vault contents into public issues. Lands in each repo's .github/ISSUE_TEMPLATE/ so it subtree-publishes alongside the existing publish.yml workflow. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The monorepo root .gitignore already covers **/build/ and **/dist/, but the root file is not published with the subtree -- only ron_skills/loreconvo/.gitignore travels to the public repo, and it lacked these rules. Forward-looking hygiene so build artifacts never get tracked in the public mirror. No artifacts were tracked or published; this is preventative. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
User-facing summary of the fixes/improvements accumulated since v0.7.1 (idle watchdog + busy_timeout lock fixes, startup-crash fix, PreCompact namespacing, auto-save open-questions extraction, export-path validation, dependency pins, GitHub issue templates). Prepares the changelog gate for release.sh --version 0.7.2. Does not bump the version itself -- release.sh does that. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…/Hermes connection paths
Replaced all >=, ~=, ^ specifiers with ==X.Y.Z exact pins: - ron_skills/loreconvo/pyproject.toml: mcp[cli]==1.27.0, click==8.3.1, cryptography==46.0.7, pytest==9.0.3, pytest-asyncio==1.4.0 - ron_skills/lorepulse/pyproject.toml: pytest==9.0.3, pytest-asyncio==1.4.0 - ron_skills/loreschema/pyproject.toml: pytest==9.0.3, pytest-asyncio==1.4.0 - loredocs: already clean (no changes needed) All 4 products now pass hygiene-check audit.
… 0.1.9 release - Bump plugin.json and marketplace.json for both products to match pyproject.toml (loreconvo 0.7.2->0.7.3, loredocs 0.1.8->0.1.9) - Fix delete_session FK violation: delete from persona_sessions and session_links before deleting from sessions (no ON DELETE CASCADE on those tables) - Fix free-tier test failures when LORECONVO_PRO is set in the host environment: add monkeypatch.delenv to the two affected loreconvo tests - Fix 19 loredocs test failures when LOREDOCS_PRO is set in the host environment: add autouse clear_pro_env fixture to loredocs conftest.py
…petitive intel on fernme
…reConvo + LoreDocs READMEs)
LoreDocs + LoreConvo public READMEs scattered (Pro) tags but never stated the
Free-vs-Pro split in one place, and both claimed a 'team' tier that does not
exist (code is {free, pro}; 'team' is rejected). Added a Plans comparison table
to each README and removed the three stale team-tier mentions. Also appended
prior-decision context to SH-12046 (Gina team-tier scoping item).
Refs: SH-12045 (Meg QA doc review), SH-12046 (Gina scoping)
…s/lorecap (clears OpenSSL CVE GHSA-537c-gmf6-5ccf); document Option-B exception for atproto-capped social pipeline Public products have no atproto cap, so cryptography resolves to 49.0.0 cleanly; verified CVE cleared via scripts/run_pip_audit.sh. Social pipeline keeps atproto==0.0.65 (caps cryptography<47) with an in-file documented risk exception ratified by Debbie 2026-06-23: local-only execution, DID key-signing not TLS, re-review 2026-07-23. Internal-only dep bump, no user-facing changelog needed.
Replace deprecated setuptools license table form (license = { file = "LICENSE" })
with SPDX string expression (license = "BUSL-1.1") plus license-files = ["LICENSE"]
across all 12 Lore product pyproject.toml files, drop the deprecated
'License :: Other/Proprietary License' classifier, and bump build-system
setuptools requirement to >=77 (SPDX-string support landed in setuptools 77).
setuptools deprecates the project.license table form and License classifiers,
unsupported after 2027-02-18. All 12 products build cleanly (python -m build)
with no project.license deprecation warning.
Note: lorealert and lorecap lack a LICENSE file, so their license-files glob
matches nothing (pre-existing gap, not a regression) -- flagged for Debbie.
Products: loreconvo, loredocs, loreconvo-cli, loredocs-cli, lorealert,
lorecache, lorecap, loreenv, loregate, loremigrate, lorepulse, loreschema
…evious_summary Fallback script (save_to_loreconvo.py) and CLI (loreconvo_cli/main.py): - --read-id / read now include previous_summary - add save/query/transition/update memory-item ops, second callers of the existing SessionDatabase.*_memory_item methods (no new DB logic) Updates FEATURE_SURFACES (surface_coverage.py), regenerates feature_manifest.yml, and documents the new fallback ops in FALLBACK_CONTRACT.md. Fixes previous_summary-column gaps in 6 hand-built sessions-table test fixtures (loreconvo-cli/tests/test_cli.py, tests/scripts/test_save_to_loreconvo.py) broken by the new SELECT. Verified: ron_skills/loreconvo/tests + ron_skills/loreconvo-cli/tests + tests/scripts/test_save_to_loreconvo.py all green (1324+1skip, 54, 197 passed respectively). --skip-test-gate used only because the gate's combined run also includes tests/scripts/test_safe_git.py, which has 2 pre-existing failures (scripts/foo.py sweep-staging assertions) verified unrelated via git stash on a clean tree -- same 2 failures with none of this commit's changes applied.
…bda (was 'one business day') Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…io.github.labyrinth-analytics/loreconvo)
…the 100-char limit (mcp-publisher validate passes)
…sessions table _migrate_fts_v2's fresh-install branch created an empty external-content index over rows that were never indexed; the next UPDATE fired the 'delete' trigger for them -> 'database disk image is malformed'. Flag the condition there and rebuild in _init_schema after the last FTS migration, when every indexed column exists. Regression test mutation-checked (goes red with the rebuild disabled). loreconvo suite 1328 passed / 1 skipped (.venv). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…_bootstrap (installed pkg or src/ synthesis) Work authored by Ron-D session ron-builder-d_20260927_130013, which hit the Hermes cron timeout before its session-end commit. Committed from an interactive session after re-verification on .venv/bin/python: loreconvo 1328 passed / 1 skipped, loreconvo-cli 49 passed, tests/scripts/ test_save_to_loreconvo.py 14 passed. Mutating package synthesis turns test_session_core_broken_installed_package_falls_back_to_src red. Bare /usr/bin/python3 (no loreconvo installed) save + read verified end to end. test_save_to_loreconvo.py stub seeded with a UTC 'Z' start_date: the save now goes through SessionDatabase, whose migration normalizes naive-local values; the merge-preserves-start_date assertion stays exact. The gate failure that surfaced here was a real core bug, fixed separately in SH-103036. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…l); test updates needed (carryover marked)
…om 4c1abf177). discover_loreconvo_db gains require_existing flag (server keeps create-on-first-use; fallback keeps hard-fail); save_to_loreconvo restores _find_loreconvo_db wrapper delegating to core (public contract + None-on-missing preserved); CLI _db_path honors LORECONVO_DB_PATH again ahead of LORECONVO_DB; discovery tests updated for Path.home derivation. Verified: loreconvo suite 1328 passed 1 skipped; CLI suite 49 passed; parity 6 passed; SH-101871 repro (LORECONVO_DB=a.db, --db-path b.db) writes to b.db only.
--skip-test-gate: integrations/hermes/__init__.py tested via test_hermes_provider.py (package import)
--skip-test-gate: integrations/hermes/__init__.py tested via test_hermes_provider.py (package import)
…ack import, skip writes for background contexts
…stall Add attribute validation to resolve_storage_core() so stale/incomplete installs (missing discover_loreconvo_db, etc.) are detected and fall back to the source-tree path. Prevents fleet-wide LoreConvo save breakage when MCP is unavailable and the installed package is out of sync.
Declare reviewed exact releases and exempt only those direct packages. Hermes keeps the global cutoff for transitive dependencies and rejects exemptions for packages held by its core lock.
15 of 17 tasks
Owner
|
Thanks for this, and for the clear write-up on the Hermes quarantine proposal. Our public repo is a published mirror of an internal source tree, so we can't merge PRs here directly. We've ported this change into our source and it will ship in the next LoreConvo release, with the plugin version tied to the package version so the two can't drift apart. Closing this one, and thanks again. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Hermes is proposing a 14-day dependency-release quarantine in NousResearch/hermes-agent#133409. this declares the plugin's exact direct package pin and explicit exemption so its reviewed release can install without exempting transitive packages.
summary
allow the reviewed plugin releases through hermes' 14-day quarantine without exempting transitive dependencies.
loreconvo==0.10.15as exact direct dependencies.[tool.uv.exclude-newer-package]entries set tofalsefor only those packages.[project]in the catalog plugin directory; keep the existing manifest for older hosts.verification
uv pip checkpass.this does not fix the lancedb version clash tracked in #2. that needs a new package release and pin update; this PR changes only the companion plugin declaration.
Infographic