Skip to content

chore: release main - #1738

Merged
erni-a merged 1 commit into
mainfrom
release-please--branches--main
Oct 3, 2026
Merged

erni-a merged 1 commit into
mainfrom
release-please--branches--main

Conversation

@caura-deploy-bot

@caura-deploy-bot caura-deploy-bot Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

🤖 I have created a release beep boop

backend: 3.21.0

3.21.0 (2026-10-03)

Features

  • contradiction: add a per-tenant switch to turn contradiction detection off (SIDE-58) (#1761) (8ce0fff)
  • search: per-request recall_boost/entity_boost opt-outs on REST /search (#1763) (9a6eb4e)
  • stats: report pending background work and a settled flag on GET /memories/stats (#1768) (5ea8f80)

Bug Fixes

  • apply the same identity, trust, fleet and visibility rules across write paths, lifecycle and audit (#1775) (b58759f)
  • audit: give the audit flusher's storage-slot acquire its own budget (oss-0927-m-04) (#1741) (ac33b26)
  • ci: isolate review tools from runner credentials (#1784) (5bc489e)
  • ci: validate review-memory authors before model capture (#1783) (2273911)
  • embed: record the re-embed give-up that reported success (oss-0924-m-05) (#1733) (d9ee8a5)
  • enrich: record the enrichment give-up that reported success (oss-0927-m-02) (#1736) (94a142b)
  • events: refuse a forge dry_run instead of silently running for real (#1737) (2e10e33)
  • graph: preserve relations with surviving evidence (#1787) (37f8f15)
  • graph: validate relation errors and tenant-scope overlap seeds (#1782) (17da42f)
  • interview: accept adapter streams and bind them to their agent (#1788) (3930964)
  • lifecycle dedup cadence, bulk write ordering, fresh reads, skill fleet scope, PII policy on edits (#1772) (f5983a0)
  • lifecycle, storage, write-path and configuration reliability (#1776) (adca395)
  • lifecycle: settle the embed-backfill topic on one spelling (#1739) (586b249)
  • llm: refuse anthropic structured output instead of silently faking it (oss-0915-m-01) (#1742) (fab8174)
  • low-batch (oss-0909-l-02, l-03, l-04) (#1744) (77abe9e)
  • plugin: align tool parameters and document requests with REST (#1779) (b3ef98d)
  • plugin: bound credential provisioning and reject API redirects (#1780) (8bf503d)
  • plugin: honor auto-write opt-out for conversation persistence (#1778) (ad8f8c3)
  • plugin: preserve keystone truncation and normalize tool results (#1781) (1adae88)
  • plugin: refuse to send the API key over plain HTTP to non-loopback hosts (oss-0917-m-01) (#1745) (4981f45)
  • ratchet: a new file inherits old-name lines only from files the change deletes (#1785) (71b8883)
  • ratchet: read a JSON key's $comment marker on the line below it (#1732) (a196921)
  • respect memory visibility in lifecycle passes, keep distinct entities apart, bound Google LLM calls (#1771) (bed4935)
  • search: caller-named top_k beats profile/tenant default top_k (#1764) (47c2796)
  • search: honour explicit top_k on recent_context; expose retrieval strategy header (#1762) (b6dde15)
  • settings: let a null unset a search.default_profile knob (#1765) (0e6f4ab)
  • storage: compile the stats breakdown filter without psycopg bind casts (#1790) (11d5d13)
  • tasks: record the three known-open give-ups; exclude the audit one (oss-0927-m-03) (#1746) (2f6c247)
  • tests: let unit-marked tests run without a database (#1747) (51542cb)
  • tighten fleet command validation, installer URL handling and settings storage (#1769) (f96768c)

Dependencies

  • bump the uv-minor-patch group across 4 directories with 9 updates (#1770) (0194ce6)
  • update sqlalchemy[asyncio] requirement from <2.1,>=2.0.51 to >=2.0.51,<2.2 in /core-storage-api (#1758) (1e9d73f)

Documentation

  • embedding: stop telling operators the nightly sweep repairs unembedded rows (oss-0927-h-01) (#1740) (b6cc308)
  • embedding: the gateway's None is not queued for a backfill sweep (oss-0927-m-01) (#1735) (5e1179e)
  • update Eldad's GitHub handle to @eldad-caura-ai (#1767) (d148bb6)
plugin: 2.23.4

2.23.4 (2026-10-03)

Bug Fixes

  • apply the same identity, trust, fleet and visibility rules across write paths, lifecycle and audit (#1775) (b58759f)
  • plugin: align tool parameters and document requests with REST (#1779) (b3ef98d)
  • plugin: bound credential provisioning and reject API redirects (#1780) (8bf503d)
  • plugin: honor auto-write opt-out for conversation persistence (#1778) (ad8f8c3)
  • plugin: preserve keystone truncation and normalize tool results (#1781) (1adae88)
  • plugin: refuse to send the API key over plain HTTP to non-loopback hosts (oss-0917-m-01) (#1745) (4981f45)
  • tighten fleet command validation, installer URL handling and settings storage (#1769) (f96768c)

This PR was generated with Release Please. See documentation.

@github-actions

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 9feae34 to 846950e Compare September 27, 2026 09:13
@github-actions

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 846950e to 5224770 Compare September 27, 2026 09:52
@github-actions

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 5224770 to 0479991 Compare September 27, 2026 10:08
@github-actions

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 0479991 to 6fad06c Compare September 27, 2026 10:38
@github-actions

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 6fad06c to 0d0d5bd Compare September 27, 2026 11:25
@github-actions

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 0d0d5bd to 208bb06 Compare September 27, 2026 13:11
@github-actions

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 208bb06 to 7685f0c Compare September 27, 2026 17:16
@github-actions

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 7685f0c to 1167756 Compare September 27, 2026 17:29
@github-actions

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 1167756 to 052aaa9 Compare September 27, 2026 17:46
@github-actions

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 052aaa9 to 13bfbf8 Compare September 28, 2026 14:20
@github-actions

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 13bfbf8 to 8a79d73 Compare September 28, 2026 14:45
@github-actions

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 8a79d73 to 8cb4a20 Compare September 28, 2026 15:00
@github-actions

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 8cb4a20 to ff42a6e Compare September 29, 2026 11:27
@github-actions

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from ff42a6e to 0f5a32e Compare September 29, 2026 11:40
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 7aa26b2 to 0340ee1 Compare October 1, 2026 21:28
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 0340ee1 to 19df741 Compare October 1, 2026 21:43
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 19df741 to dc1c545 Compare October 2, 2026 12:11
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from dc1c545 to 3acbed3 Compare October 2, 2026 12:26
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 3acbed3 to 665f318 Compare October 2, 2026 12:49
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

eldad-caura-ai added a commit that referenced this pull request Oct 2, 2026
…1788)

## Audit finding

Addresses part of **M-86** (`POST /interview/submit` trusted `node_id`),
and a regression that merged caura PR #1775 introduced in the same
check.

- **Regression.** #1775 made the route return 404 for any `node_id` that
is not a fleet node of the tenant. `caura-interviewer`, the Claude Code
and Cursor adapter in `clients/python`, keys one stream per transcript
as `cc:<machine>:<session>` or `cursor:...` and never registers a fleet
node. Every window it submits is therefore refused, and the runner skips
the transcript. No release contains #1775 yet; release PR #1738 lists
it.
- **M-86, adapter streams.** Before #1775, any write credential in the
tenant could advance any stream's watermark. A same-tenant agent
credential could move another agent's transcript cursor far ahead, and
that transcript would not be interviewed again.

## Change

- A UUID `node_id` must still name a fleet node of the tenant (404
otherwise), as in #1775.
- Any other `node_id` is an adapter stream and is accepted again.
- An agent credential, or an install credential, may continue an adapter
stream only when the agent it resolved to last advanced that stream's
watermark. Otherwise the route returns 409 and persists nothing. 409
rather than 403, because `caura-interviewer` skips one transcript on a
409 but aborts its whole run on a 403. Tenant credentials keep
tenant-wide authority, as on the other write gates.
- `read_watermark_state` returns the cursor and the last-advancing agent
in one primary read; `read_watermark` keeps its contract.

## Not in this PR

- Fleet-node windows. A same-tenant agent credential can still submit
for another fleet node, capped at 1,000,000 past its watermark per call.
Closing that depends on binding node heartbeats and command receipt to
the node's credential (M-85), which needs a migration and a policy
decision. It is tracked separately.
- A reserved `main` credential still names its subject, the existing
known gap until `reserved_agent_id_policy=reject`.

## Verification

- Tests first: the first push carries only the new tests, so CI can show
them failing against unfixed `main`. The fix is then amended into the
same single commit.
- No repository scripts, dependency installs, tests or builds were run
on Eldad's Mac under its safety hold. CI runs the suites.

One signed-off commit. Do not merge or enable auto-merge; Eldad merges
after review.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Signed-off-by: eldad-caura <eldad@caura.ai>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from c9d87de to 38b2c29 Compare October 2, 2026 23:19
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 38b2c29 to 8bb007c Compare October 3, 2026 05:13
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

Signed-off-by: release-please[bot] <release-please[bot]@users.noreply.github.com>
@caura-deploy-bot
caura-deploy-bot Bot force-pushed the release-please--branches--main branch from 8bb007c to cfb9d8d Compare October 3, 2026 05:48
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'caura-deploy-bot[bot]' is not a public member of the 'caura-ai' org

@erni-a

erni-a commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

@arkash20 please revieww

@erni-a
erni-a merged commit e4bb64f into main Oct 3, 2026
14 checks passed
@erni-a
erni-a deleted the release-please--branches--main branch October 3, 2026 08:49
@caura-deploy-bot

Copy link
Copy Markdown
Contributor Author

🤖 Created releases:

🌻

@caura-deploy-bot caura-deploy-bot Bot added autorelease: tagged release-please: PR has been tagged and released and removed autorelease: pending labels Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

autorelease: tagged release-please: PR has been tagged and released

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants