Repository navigation
release(A9): pin the Hermes knowledge corpus and fail closed without it - #272
Merged
Matr0xshka merged 1 commit intoOct 6, 2026
Merged
Conversation
Checklist A9, built on the release Mac from clean checkouts: knowledge-corpus.tar.gz (citrate-corpus/2, bundle_digest 815eda93..., 32,754 nodes, every node embedded with the bundled BGE weights) is uploaded to runtime-deps and pinned, with bge-base-en-v1.5.tar.gz. Sources and commits are recorded in the SCL-S0 EVIDENCE.md. Fail closed (DGX finding): the knowledge-corpus/**/* resource glob matches the committed README, so an unstaged corpus still bundled README-only. - verify-runtime-deps.sh refuses a manifest without the corpus pin, and a mem-mcp staged without the corpus. - stage-knowledge-corpus.mjs records what it staged beside the directory. - check-staged-corpus.mjs (new, red-green tested) refuses README-only, an unrecorded or changed corpus, a dev-staged corpus, and with --pins one not from the pinned asset; release.yml runs it before bundling and the pin tripwire enforces that. - RELEASE.md, RELEASE_LINUX.md and RELEASE_WINDOWS.md document the staging and the check on every platform. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018wWZZ8GRVU9USh3kKQHsFe
This was referenced Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Checklist A9 (the owner requires it in 0.5.0). The Mac took this over from the DGX. Also fixes the DGX finding that a release without a staged corpus still bundled the README alone.
Corpus
Built on the release Mac from fresh GitHub clones (no working copies), per docs/RELEASE.md section 3, with citrate-memories
0e9d488andEMBED_BGE_DIRset to the BGE files from theruntime-depsbge-base-en-v1.5.tar.gzasset.815eda93c4886927cddf16381abf3a77ebb07d90acdf27e5914c6b300b754b9ac7c1988a…)knowledge-corpus.tar.gz91de29274251aa0e7d0934ebb2e2c8b3ebf3d010804ed6a798eef8c4655acd9b(uploaded toruntime-deps; the re-downloaded asset hashes to the same digest)bge-base-en-v1.5.tar.gzcea05ebe680cf315e41c965caec9d8e009dd9085b622d4cb9c62fe4faf026c3b(the existing asset, now pinned)All 15 sources record clean commits (no
-dirty, nounpinned). The table is in the SCL-S0 EVIDENCE.md.stage-knowledge-corpus.mjswith no--allow-*flag staged it against the rc.1 mem-mcp (31598435…) from both the directory and the tarball.Fail closed
scripts/ci/verify-runtime-deps.shrefuses a pins manifest without aknowledge-corpus.tar.gzpin, and refuses a call that stages amem-mcp-*without the corpus.scripts/stage-knowledge-corpus.mjswritessrc-tauri/knowledge-corpus.staged.jsonbeside the bundled directory (git-ignored). It records the digest, node count and input sha256.scripts/check-staged-corpus.mjsis new and runs before bundling. It refuses:--allow-dev);--pins, a corpus not staged from the pinned asset.tauri-action.check-release-pins.shfails if that step is missing, lacks--pins, or comes after the build. It also self-tests the verifier's new refusals.The citrate-agent-runtime pin is unchanged; it moves to #72 for rc.2 separately.
Tests
scripts/check-staged-corpus.test.mjs(12 tests, 10 failing against the base stager), and the tripwire failed on the missing corpus pin and the missing release.yml step.ac7bb1a(+12).check-release-pins.sh: OK. typecheck: clean.licence-inventory --corpus: OK.Also filed: CitrateNetwork/citrate-memories#21, a mem-corpus false clean pin for ignored untracked directories. It did not affect this build.
🤖 Generated with Claude Code
https://claude.ai/code/session_018wWZZ8GRVU9USh3kKQHsFe