Skip to content

release(A9): pin the Hermes knowledge corpus and fail closed without it - #272

Merged
Matr0xshka merged 1 commit into
release/0.5.0-hermes-upskillfrom
release/v0.5.0-knowledge-corpus
Oct 6, 2026
Merged

Matr0xshka merged 1 commit into
release/0.5.0-hermes-upskillfrom
release/v0.5.0-knowledge-corpus

Conversation

@SaulBuilds

@SaulBuilds SaulBuilds commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Checklist A9 (the owner requires it in 0.5.0). The Mac took this over from the DGX. Also fixes the DGX finding that a release without a staged corpus still bundled the README alone.

Corpus

Built on the release Mac from fresh GitHub clones (no working copies), per docs/RELEASE.md section 3, with citrate-memories 0e9d488 and EMBED_BGE_DIR set to the BGE files from the runtime-deps bge-base-en-v1.5.tar.gz asset.

bundle_digest 815eda93c4886927cddf16381abf3a77ebb07d90acdf27e5914c6b300b754b9a
Nodes 32,754 (citrate-docs 1,740 · methodology 37 · refs 12,730 · skills 18,247), every node embedded (BGE weights c7c1988a…)
knowledge-corpus.tar.gz 58,592,427 bytes, sha256 91de29274251aa0e7d0934ebb2e2c8b3ebf3d010804ed6a798eef8c4655acd9b (uploaded to runtime-deps; the re-downloaded asset hashes to the same digest)
bge-base-en-v1.5.tar.gz sha256 cea05ebe680cf315e41c965caec9d8e009dd9085b622d4cb9c62fe4faf026c3b (the existing asset, now pinned)

All 15 sources record clean commits (no -dirty, no unpinned). The table is in the SCL-S0 EVIDENCE.md. stage-knowledge-corpus.mjs with no --allow-* flag staged it against the rc.1 mem-mcp (31598435…) from both the directory and the tarball.

Fail closed

  • scripts/ci/verify-runtime-deps.sh refuses a pins manifest without a knowledge-corpus.tar.gz pin, and refuses a call that stages a mem-mcp-* without the corpus.
  • scripts/stage-knowledge-corpus.mjs writes src-tauri/knowledge-corpus.staged.json beside the bundled directory (git-ignored). It records the digest, node count and input sha256.
  • scripts/check-staged-corpus.mjs is new and runs before bundling. It refuses:
    • a README-only directory;
    • a corpus the stager did not record;
    • a digest or node count that differs from the record;
    • changed files;
    • a corpus staged for a dev build (needs --allow-dev);
    • with --pins, a corpus not staged from the pinned asset.
  • release.yml runs the check before tauri-action. check-release-pins.sh fails if that step is missing, lacks --pins, or comes after the build. It also self-tests the verifier's new refusals.
  • docs/RELEASE.md (local Mac DMG), RELEASE_LINUX.md and RELEASE_WINDOWS.md step 2b now cover download → verify → stage against that platform's mem-mcp → check.

The citrate-agent-runtime pin is unchanged; it moves to #72 for rc.2 separately.

Tests

  • New tests failed first: scripts/check-staged-corpus.test.mjs (12 tests, 10 failing against the base stager), and the tripwire failed on the missing corpus pin and the missing release.yml step.
  • vitest: 2,459 passed on ac7bb1a (+12). check-release-pins.sh: OK. typecheck: clean. licence-inventory --corpus: OK.
  • No Rust changes.

Also filed: CitrateNetwork/citrate-memories#21, a mem-corpus false clean pin for ignored untracked directories. It did not affect this build.

🤖 Generated with Claude Code

https://claude.ai/code/session_018wWZZ8GRVU9USh3kKQHsFe

Checklist A9, built on the release Mac from clean checkouts:
knowledge-corpus.tar.gz (citrate-corpus/2, bundle_digest 815eda93..., 32,754
nodes, every node embedded with the bundled BGE weights) is uploaded to
runtime-deps and pinned, with bge-base-en-v1.5.tar.gz. Sources and commits are
recorded in the SCL-S0 EVIDENCE.md.

Fail closed (DGX finding): the knowledge-corpus/**/* resource glob matches the
committed README, so an unstaged corpus still bundled README-only.
- verify-runtime-deps.sh refuses a manifest without the corpus pin, and a
  mem-mcp staged without the corpus.
- stage-knowledge-corpus.mjs records what it staged beside the directory.
- check-staged-corpus.mjs (new, red-green tested) refuses README-only, an
  unrecorded or changed corpus, a dev-staged corpus, and with --pins one not
  from the pinned asset; release.yml runs it before bundling and the pin
  tripwire enforces that.
- RELEASE.md, RELEASE_LINUX.md and RELEASE_WINDOWS.md document the staging
  and the check on every platform.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018wWZZ8GRVU9USh3kKQHsFe
@SaulBuilds
SaulBuilds requested a review from a team as a code owner October 6, 2026 19:36
@Matr0xshka
Matr0xshka merged commit ef17edd into release/0.5.0-hermes-upskill Oct 6, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants