| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
revert(release): re-embed runtime assets into the single shipped binary Externalizing the integration templates (#1492/#1493) and the UI bundle (#1501/#1503) was done to reduce the Microsoft `Wacatac.B!ml` surface. It did not work: across dry runs the flagged artifact count stayed at ~3 and the detections merely moved between artifacts. Dissection of run 31286803592 shows there is no structural cause to fix. The verdicts split across every axis at once — linux-amd64 (dynamic) flagged while linux-amd64-portable (static) is clean, but linux-arm64 (dynamic) clean while linux-arm64-portable (static) is flagged. The two macOS binaries have identical segment structure and split clean/flagged. Siblings from one build landed in different variant buckets (.B vs .C). Entropy is low everywhere (code_vectors.bin 4.166, grammar tables 3.464 bits/byte, against 7.5-8.0 for packed payloads), so the packed-payload hypothesis is excluded too. So the complexity bought nothing, and installation goes back to being self-contained: one binary that carries its own UI and agent integration templates, with no adjacent data file that has to resolve before `install` works. Only the UI-capable composition ships from now on, under the historical unsuffixed archive name. Removed: src/ui/asset_pack.{c,h}, asset_pack_stub.c, asset_manifest_stub.c, scripts/pack-ui-assets.mjs, src/cli/integration_assets.{c,h}, assets/cbm-integrations.json, scripts/gen-integrations-hash.sh, the --verify-runtime-assets probe (nothing adjacent left to verify), and the composition gates A6/A7 whose property is now deliberately inverted. Restored: scripts/embed-frontend.sh, src/ui/embedded_{assets.h,stub.c}, the compiled-in hook/adapter template bodies, and the embed/EMBED_OBJS build path. Kept from the reverted commits, re-applied by hand where a wholesale file restore would have dropped them: - cbm_module_path_utf8() in both self-path sites. GetModuleFileNameA renders through the ANSI code page and mangles non-ASCII install paths. - the /__cbm/ui-readiness HMAC proof, secure_random and cbm_hmac_sha256, so `daemon start --open` still waits for a genuine CBM listener. - X-Content-Type-Options: nosniff on served assets. - the MinGW noexecstack gate, -lbcrypt, and the cppcheck/zip CI fixes. Archives are now codebase-memory-mcp-<os>-<arch>[-portable] with exactly four members (binary, LICENSE, installer, THIRD_PARTY_NOTICES.md). That restores the names every static package manifest already points at — aur, chocolatey, homebrew, scoop, winget and glama were all broken by the -ui- rename. Signed-off-by: Martin Vogel <martin.vogel.tech@gmail.com> | 1 个月前 | |
chore(pkg): sync packaging metadata to v0.11.0 Every packaging surface states the newest v-prefixed tag, as the version-metadata contract requires: the Chocolatey nuspec and installer (checksum re-pinned to the released windows-amd64 archive), the Go installer, the Nix flake, server.json, the npm and PyPI wrappers. Signed-off-by: Martin Vogel <martin.vogel.tech@gmail.com> | 14 天前 | |
revert(release): re-embed runtime assets into the single shipped binary Externalizing the integration templates (#1492/#1493) and the UI bundle (#1501/#1503) was done to reduce the Microsoft `Wacatac.B!ml` surface. It did not work: across dry runs the flagged artifact count stayed at ~3 and the detections merely moved between artifacts. Dissection of run 31286803592 shows there is no structural cause to fix. The verdicts split across every axis at once — linux-amd64 (dynamic) flagged while linux-amd64-portable (static) is clean, but linux-arm64 (dynamic) clean while linux-arm64-portable (static) is flagged. The two macOS binaries have identical segment structure and split clean/flagged. Siblings from one build landed in different variant buckets (.B vs .C). Entropy is low everywhere (code_vectors.bin 4.166, grammar tables 3.464 bits/byte, against 7.5-8.0 for packed payloads), so the packed-payload hypothesis is excluded too. So the complexity bought nothing, and installation goes back to being self-contained: one binary that carries its own UI and agent integration templates, with no adjacent data file that has to resolve before `install` works. Only the UI-capable composition ships from now on, under the historical unsuffixed archive name. Removed: src/ui/asset_pack.{c,h}, asset_pack_stub.c, asset_manifest_stub.c, scripts/pack-ui-assets.mjs, src/cli/integration_assets.{c,h}, assets/cbm-integrations.json, scripts/gen-integrations-hash.sh, the --verify-runtime-assets probe (nothing adjacent left to verify), and the composition gates A6/A7 whose property is now deliberately inverted. Restored: scripts/embed-frontend.sh, src/ui/embedded_{assets.h,stub.c}, the compiled-in hook/adapter template bodies, and the embed/EMBED_OBJS build path. Kept from the reverted commits, re-applied by hand where a wholesale file restore would have dropped them: - cbm_module_path_utf8() in both self-path sites. GetModuleFileNameA renders through the ANSI code page and mangles non-ASCII install paths. - the /__cbm/ui-readiness HMAC proof, secure_random and cbm_hmac_sha256, so `daemon start --open` still waits for a genuine CBM listener. - X-Content-Type-Options: nosniff on served assets. - the MinGW noexecstack gate, -lbcrypt, and the cppcheck/zip CI fixes. Archives are now codebase-memory-mcp-<os>-<arch>[-portable] with exactly four members (binary, LICENSE, installer, THIRD_PARTY_NOTICES.md). That restores the names every static package manifest already points at — aur, chocolatey, homebrew, scoop, winget and glama were all broken by the -ui- rename. Signed-off-by: Martin Vogel <martin.vogel.tech@gmail.com> | 1 个月前 | |
chore(pkg): sync packaging metadata to v0.11.0 Every packaging surface states the newest v-prefixed tag, as the version-metadata contract requires: the Chocolatey nuspec and installer (checksum re-pinned to the released windows-amd64 archive), the Go installer, the Nix flake, server.json, the npm and PyPI wrappers. Signed-off-by: Martin Vogel <martin.vogel.tech@gmail.com> | 14 天前 | |
chore(homebrew): point the formula at v0.10.3 The formula still pinned 0.8.1 — five releases and two months behind — so `brew install` handed out a June binary while GitHub, npm and PyPI all served the current one. Nothing in the release pipeline touches this file, which is how it drifted that far without anyone noticing. Version and all four SHA-256 digests come from the published v0.10.3 checksums.txt. Worth doing separately: have the release workflow rewrite this formula from checksums.txt after publish. A channel nothing updates is a channel that rots, and the failure mode is silent — brew keeps working, it just installs something old. Signed-off-by: Martin Vogel <martin.vogel.tech@gmail.com> | 1 个月前 | |
docs: MCP tool count is 17; document the three missing tools The TOOLS[] registry in src/mcp/mcp.c and the v0.11.0 --help output list 17 tools, but README, the npm README, CONTRIBUTING and the Pages site still say 15 (or 14), and the README tool table has no row for get_file_outline, compare_graphs or check_index_coverage. Refs #1297 Assisted-by: Claude Code / claude-opus-5 Machine: MacBook-Anton Account: a@gmail Operator: robot:git-s3-docs-fix-lane Signed-off-by: Anton Dziatkovskii <194927794+tonydzi@users.noreply.github.com> | 14 天前 | |
chore(pkg): sync packaging metadata to v0.11.0 Every packaging surface states the newest v-prefixed tag, as the version-metadata contract requires: the Chocolatey nuspec and installer (checksum re-pinned to the released windows-amd64 archive), the Go installer, the Nix flake, server.json, the npm and PyPI wrappers. Signed-off-by: Martin Vogel <martin.vogel.tech@gmail.com> | 14 天前 | |
fix(scoop): address v0.11.0 review feedback Signed-off-by: Ivan Lin <35771002+ivanlinhf@users.noreply.github.com> | 4 天前 | |
fix(release): externalize runtime assets and harden VT verification Signed-off-by: Martin Vogel <martin.vogel.tech@gmail.com> | 1 个月前 |