Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 13 additions & 3 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,12 +2,17 @@

## Unreleased

No changes yet after the 0.2.1 release-prep branch.

## 0.2.1

Honesty repairs to the wiring surface (the credo: color/verdict vocabulary only
where a real check ran; no receipt no accept; the honest null is first-class).

- Edges are DECLARED, not probed: plexus never imports, resolves, or runs the
tools, so each edge is tagged `evidence: "declared"` and the "grounded, not
asserted" / "traces back to real code" / "genuinely compose" wording is gone.
- Edges are DECLARED, not probed: declarative discovery never imports,
resolves, or runs the cited tools, so each edge is tagged
`evidence: "declared"` and the "grounded, not asserted" / "traces back to
real code" / "genuinely compose" wording is gone.
- Duplicate organ ids are NAMED (`discover().collisions`, `validate` reports
`duplicate_organs` and exits 1) instead of collapsing last-writer-wins.
- `discover` stamps a re-runnable `receipt`: plexus version, UTC timestamp, and
Expand All @@ -24,6 +29,11 @@ where a real check ran; no receipt no accept; the honest null is first-class).
`mneme.crucible-export/2`, still consumable as `crucible.thesis/1`, and Mneme
also declares `mneme.local-origin-recheck/1` as a terminal read-only freshness
report capability.
- Add Canon and Relay to the declared capability catalog from public
origin-main source, with repo-relative public paths and no live external lane probing by Plexus.
- Keep this release on the GitHub-asset track: wheel, sdist, and
`SHA256SUMS.txt` are reviewable release assets, while PyPI publication remains
outside this patch.

## 0.2.0

Expand Down
110 changes: 103 additions & 7 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,10 +9,101 @@ to consumer into a runnable pipeline. Zero runtime dependencies.
MCP tells an agent *that tools exist*. plexus tells it *how their outputs plug
into each other's inputs*: the layer above a flat tool list.

GitHub-only release install for 0.2.1 on Bash/macOS/Linux:

```bash
set -euo pipefail
VERSION=0.2.1
BASE="https://github.com/HarperZ9/plexus/releases/download/v0.2.1"
WHEEL="plexus_mesh-${VERSION}-py3-none-any.whl"
SDIST="plexus_mesh-${VERSION}.tar.gz"
SUMS="SHA256SUMS.txt"
curl -fL -o "$WHEEL" "${BASE}/${WHEEL}"
curl -fL -o "$SDIST" "${BASE}/${SDIST}"
curl -fL -o "$SUMS" "${BASE}/${SUMS}"
python - "$WHEEL" "$SDIST" "$SUMS" <<'PY'
import hashlib
import re
import sys
from pathlib import Path

required = list(sys.argv[1:3])
sums = Path(sys.argv[3])
expected = {}
for line_number, raw_line in enumerate(sums.read_text(encoding="utf-8").splitlines(), 1):
line = raw_line.strip()
if not line:
continue
parts = line.split(maxsplit=1)
if len(parts) != 2:
raise SystemExit(f"malformed checksum line {line_number}")
digest, name = parts[0].lower(), parts[1].lstrip("*")
if not re.fullmatch(r"[0-9a-f]{64}", digest):
raise SystemExit(f"invalid checksum for {name}")
if Path(name).name != name:
raise SystemExit(f"unexpected checksum path: {name}")
if name not in required:
raise SystemExit(f"unexpected checksum entry: {name}")
if name in expected:
raise SystemExit(f"duplicate checksum entry: {name}")
expected[name] = digest
missing = [name for name in required if name not in expected]
if missing:
raise SystemExit(f"missing checksum entry: {', '.join(missing)}")
for name in required:
got = hashlib.sha256(Path(name).read_bytes()).hexdigest()
if got != expected[name]:
raise SystemExit(f"{name}: expected {expected[name]}, got {got}")
PY
python -m pip install "$WHEEL"
```
pip install git+https://github.com/HarperZ9/plexus.git

GitHub-only release install for 0.2.1 on native PowerShell:

```powershell
& {
$ErrorActionPreference = "Stop"
$Version = "0.2.1"
$Base = "https://github.com/HarperZ9/plexus/releases/download/v0.2.1"
$Wheel = "plexus_mesh-$Version-py3-none-any.whl"
$Sdist = "plexus_mesh-$Version.tar.gz"
$Sums = "SHA256SUMS.txt"
$Files = @($Wheel, $Sdist, $Sums)
foreach ($Name in $Files) {
Invoke-WebRequest -Uri "$Base/$Name" -OutFile $Name
}
$Required = @($Wheel, $Sdist)
$Expected = @{}
$LineNumber = 0
Get-Content -LiteralPath $Sums | ForEach-Object {
$LineNumber += 1
$Line = $_.Trim()
if (-not $Line) { return }
$Parts = $Line -split '\s+', 2
if ($Parts.Count -ne 2) { throw "malformed checksum line $LineNumber" }
$Digest = $Parts[0].ToLowerInvariant()
$Name = $Parts[1].TrimStart("*")
if ($Digest -notmatch '^[0-9a-f]{64}$') { throw "invalid checksum for $Name" }
if ([IO.Path]::GetFileName($Name) -ne $Name) { throw "unexpected checksum path: $Name" }
if ($Required -notcontains $Name) { throw "unexpected checksum entry: $Name" }
if ($Expected.ContainsKey($Name)) { throw "duplicate checksum entry: $Name" }
$Expected[$Name] = $Digest
}
foreach ($Name in $Required) {
if (-not $Expected.ContainsKey($Name)) { throw "missing checksum entry: $Name" }
$Got = (Get-FileHash -Algorithm SHA256 -Path $Name).Hash.ToLowerInvariant()
if ($Got -ne $Expected[$Name]) {
throw "${Name}: expected $($Expected[$Name]), got $Got"
}
}
python -m pip install $Wheel
}
```

`plexus-mesh` is not published on PyPI in this release track. A source branch or
CI run is not a release; install from the GitHub `v0.2.1` assets only after the
wheel, sdist, and `SHA256SUMS.txt` are attached to that release.

```
$ plexus discover --builtin
$ plexus plan --goal crucible
Expand Down Expand Up @@ -127,8 +218,7 @@ A manifest is plain JSON. A tool ships one and it joins the mesh. Drop
An edge `A -> B` forms when `B` consumes a capability that `A` emits (directly,
or via `consumable_as`, the way a producer declares "my output is also
consumable as X"). Matching is by capability string, so an edge exists wherever
the tools DECLARE compatible capabilities. plexus does not run the tools, so the
edge is a declared claim, not a probed result.
the tools DECLARE compatible capabilities. Declarative discovery does not run the tools, so the edge is a declared claim, not a probed result.

Plexus commits the built-in registry's exported JSON manifests under
[`manifests/`](manifests/). Discovery from these Plexus-side files produces the
Expand Down Expand Up @@ -185,9 +275,9 @@ for r in results:
<p align="center"><img src="docs/art/edge-evidence.svg" alt="The six keys plexus discover returns for one wiring edge, one to a row, each with what settled it. Four are computed by discovery: the producing organ, the consuming organ, the capability that matched, and whether both ends are the same organ. One is copied out of a manifest without being read: via, the producer's own pointer at the code behind the port. One is a constant: evidence, always the word declared. The via row is accented, because it is the field that looks like a citation and is the one plexus never follows." width="100%"></p>

Every edge is tagged `evidence: "declared"` and cites the **module** its producer
names as the source (`file:function`). plexus does not import, resolve, or run
that pointer, so the citation is a self-reported claim to check, not a verified
receipt. The running tool re-checks none of the built-in manifests, so treat
names as the source (`file:function`). Declarative discovery does not import,
resolve, or run that pointer, so the citation is a self-reported claim to check,
not a verified receipt. The running tool re-checks none of the built-in manifests, so treat
every edge as declared until you follow the pointer yourself. Mneme's contract
was refreshed from public main on 2026-09-14, including
`mneme.crucible-export/2` and `mneme.local-origin-recheck/1`. Canon and Relay
Expand Down Expand Up @@ -226,9 +316,15 @@ mesh to exactly the manifests that produced it.
## Install

```
pip install git+https://github.com/HarperZ9/plexus.git
python -m pip install plexus_mesh-0.2.1-py3-none-any.whl
```

Use the GitHub release asset and verify it against `SHA256SUMS.txt` first. This
repository does not claim a PyPI publication for `plexus-mesh` in the 0.2.1
track. The installed package covers declared and synthetic mesh workflows; it
does not prove that real external lanes are live or that `probe_lane()` has been
run against owned services.

## Library

```python
Expand Down
4 changes: 2 additions & 2 deletions pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,8 @@ build-backend = "setuptools.build_meta"

[project]
name = "plexus-mesh"
version = "0.2.0"
description = "Capability discovery + auto-wiring for agent toolchains: point it at your tools and it discovers what each one emits and consumes, then wires producer to consumer into an executable pipeline, every edge tagged declared and citing the module its producer names. plexus does not probe or run the tools. Zero runtime dependencies."
version = "0.2.1"
description = "Declarative capability discovery + auto-wiring for agent toolchains: point it at tool manifests and it wires producer to consumer into an executable pipeline, every discovery edge tagged declared and citing the module its producer names. Discovery does not import or run cited tools; optional explicit probe helpers can launch owned MCP servers. Zero runtime dependencies."
readme = "README.md"
requires-python = ">=3.11"
license = "LicenseRef-FSL-1.1-MIT"
Expand Down
11 changes: 6 additions & 5 deletions src/plexus/__init__.py
Original file line number Diff line number Diff line change
@@ -1,9 +1,10 @@
"""plexus: capability discovery + auto-wiring for agent toolchains.

Point it at a set of tools that ship interop manifests and it discovers what each
one emits and consumes, then wires producer to consumer into a pipeline, every
edge tagged `declared` and carrying the module its producer names. plexus does
not import, probe, or run those tools. Zero runtime dependencies.
Point it at a set of tools that ship interop manifests and declarative discovery
wires producer to consumer into a pipeline, every edge tagged `declared` and
carrying the module its producer names. Discovery does not import or run cited
tools. Optional probe helpers in `plexus.registry` launch owned MCP servers only
when explicitly called. Zero runtime dependencies.
"""
from .graph import to_dot, to_mermaid
from .manifest import Manifest, Port, validate
Expand All @@ -13,7 +14,7 @@
from .registry import builtin_manifests, load_dir
from .run import pipeline_script

__version__ = "0.2.0"
__version__ = "0.2.1"

__all__ = [
"Manifest", "Port", "validate",
Expand Down
Loading
Loading