Releases: Hyphae-Research-Foundation/hyphae-omarchy
Release list
Hyphae Memory 0.2.2
Hyphae Memory 0.2.2
This maintainer-review patch closes the credential/socket pathname boundary
reported for 0.2.1. It keeps the hyphae-memory-panel-v1 interface and the same
memory-data authority.
Every credential and endpoint directory component is opened from the filesystem
root with descriptor-relative O_PATH | O_DIRECTORY | O_NOFOLLOW traversal and
checked for safe ownership and write modes. The credential is opened relative
to the validated parent descriptor. The socket is inspected there and connected
through the held parent's /proc/self/fd identity. Linux SO_PEERCRED is
mandatory and checked before the token is transmitted. Held descriptors are
released after connect() and on every failure path.
Validation passes 44 Python client tests, eight JavaScript limits tests, five
native Quickshell scenarios, QML lint and official Omarchy manifest validation.
The Python cases include all 29 original tests plus path substitution, unsafe
ancestor, peer identity, descriptor lifecycle and compatibility checks. The
validation record
contains the environment, source hashes, baseline counterexamples and test-only
overrides.
The bounded process behavior introduced in 0.2.1 remains unchanged. The helper
runs through /usr/bin/python3 -I -S -B, applies bounded request/response and
process-lifetime policies, and never automatically retries an unconfirmed
mutation.
The release contains hyphae-memory-0.2.2.tar.gz, its complete package.json
member inventory and SHA256SUMS. The clean archive inventories 37 regular
source files and has SHA-256
08696b001e1753483a9b2edf6a2cd9ebab659df014913f0442c40a7674866847.
Release source: e066f5fd769ffe688a650db1ad6b84c342b64aa6.
CI
passed on Python 3.11.15 and 3.13.9 for this exact default-branch commit.
Hyphae Memory 0.2.1
Hyphae Memory 0.2.1
This maintainer-review patch hardens the local helper process used by the
Omarchy memory client. It keeps the hyphae-memory-panel-v1 interface and the
same memory-data authority. Runtime/service administration and external
integrations remain independently managed through Hyphae.
The helper now launches directly through /usr/bin/python3 -I -S -B with a
cleared environment: LC_ALL=C.UTF-8 plus optional absolute HOME,
XDG_CONFIG_HOME and HYPHAE_MEMORY_PANEL_CONFIG paths. It does not select an
interpreter through PATH or load Python site initialization.
The process reader checks a 4-MiB conservative stdout admission budget before
retention, charging ASCII length plus three bytes per chunk for a BOM that Qt
may discard. Retained/emitted ASCII JSON is separately limited to 2 MiB plus
one newline. The Python emitter checks encoded size before writing; oversized
output becomes a small sanitized error. Stderr has zero client retention and
any read event aborts the request. These bounds do not cover Qt's transient
pipe-read/decode allocations or total process memory.
A 140-second lifetime watchdog covers startup and request handling. Termination
uses SIGTERM with a two-second grace, then SIGKILL and a two-second reap grace.
An unreaped helper holds its slot and blocks another launch. Mutating requests
whose result cannot be confirmed return outcome_unknown; the client never
automatically retries store, forget or backup. Check current records or
backups before resubmitting an uncertain change.
Validation passes 29 Python client tests, eight JavaScript limits tests, five
native Quickshell fixture scenarios and official Omarchy manifest validation.
The native cases cover Unicode, queue ordering, uncertain outcomes, deadline
cleanup and failed startup. The validation record includes
source hashes, test-only overrides and the single QML lint type-metadata warning;
the native normal-exit tests pass. The unchanged 0.2.0 desktop receipts are
labeled as historical evidence. Marketplace listing still requires review of
the final default-branch commit.
The versioned client archive is named hyphae-memory-0.2.1.tar.gz; a published
release pairs it with package.json and SHA256SUMS. The package receipt
inventories every source member. Omarchy, system Python and the separately
provisioned Hyphae service supply runtime dependencies. Node.js is needed only
for development/CI tests. Restart the desktop shell after updating so Qt loads
the new process components.
Complete native proofs retain their separate 16-MiB limit; the panel receives
verified digest metadata. Proof verification establishes retrieval at a
snapshot, not the factual correctness of remembered text. Backups are created
by the service; restoration remains an independent Hyphae operation.
Release source: ae68f2466425c89a4654c539aa8b78f43f404b82. CI passed for this exact default-branch commit. The clean archive contains 35 inventoried files.
Hyphae Memory 0.2.0
Hyphae Memory 0.2.0
This release provides the Omarchy desktop client for an independently managed
Hyphae memory service. It supports project and layer selection, explicit memory
capture and forgetting, scoped search, verified queries and backup creation.
The client uses a dedicated Unix socket and credential whose authority is
restricted by the service to the documented memory operations. Runtime/service
administration and external integrations are managed independently through Hyphae.
A Hyphae build providing hyphae-memory-panel-v1 is required; follow the upstream
memory-panel guide linked in the README.
Download hyphae-memory-0.2.0.tar.gz, package.json and SHA256SUMS from this
release. Verify checksums before installing the client archive. The package
receipt inventories every source member. The archive contains the desktop client,
its protocol contract and documentation; dependencies are provided by Omarchy,
Python and the separate Hyphae installation.
The validation report describes client, server-boundary and actual Omarchy
checks. Native proof responses retain the 16-MiB limit. Proof verification
establishes retrieval at a snapshot, not factual correctness of remembered text.
Backups are created by the service; restore remains an independent Hyphae action.
Validated client source: afa8fa647435776400730ae2ddaff511d5489eac.
Client CI passed on Python 3.11 and 3.13. The archive contains 29 inventoried source files; its production files match the actual Omarchy VM validation. See the committed validation report.
The independent server interface is merged in Hyphae PR #285. A source build with that interface is required; the older Hyphae 3.0.0 registry packages do not contain it.
Hyphae Memory 0.1.0
Hyphae Memory 0.1.0
This release targets Linux x86_64 on Omarchy 4.0.3. It provides the native bar
widget and panel, a pinned local runtime, project-scoped memory, optional local
semantics, verified recall and backups, and integration with Claude Code,
Codex, OpenCode and Pi.
The runtime source is public Hyphae commit
8fe08dfce903d09e4e5f4b82ba02d3d28ec45191. Its native protocol is minor 7;
the Hyphae 3.0.0 registry packages do not contain the Agent Memory additions.
Install the plugin's pinned runtime when using this release.
Download and verify
Download from the 0.1.0 release:
hyphae-memory-0.1.0.tar.gz: complete plugin and runtime for offline installation.hyphae-memory-0.1.0-linux-x86_64-8fe08dfce903.tar.gz: the exact runtime used by source installations.hyphae-memory-0.1.0-upstream-evidence.zip: signed upstream artifacts, G8 receipts and verification data.hyphae-memory-0.1.0.cdx.json: combined runtime dependency inventory.hyphae-memory-0.1.0-dependency-licenses.txt: retained dependency license texts.SHA256SUMS: identities of the release files.
Verify the downloaded files with sha256sum --check SHA256SUMS. The installer
also verifies the complete runtime archive and every inventoried member before
activating either binary. A mismatch preserves the existing installation.
The full archive extracts into org.hyphaeresearch.memory; place that directory
under ~/.config/omarchy/plugins, validate it and enable the widget. A source
installation retrieves the exact runtime through the public HTTPS URL in
runtime.lock.json. See the README for setup and removal.
Source and verification scope
The Hyphae CLI is the exact Linux binary from
Release run 34699387730.
That run built commit 98792adde4bdb90eca0bee778e5b23a5c7ee804d; its tree is
identical to the public merge above. The supplied lock preserves both identities
and the executable hash. All four upstream platform archives, 12 signatures
and 12 attestations were verified with the pinned upstream verifier.
G8 run 34702899455
closed all nine G8 requirements for the exact merge, using
readiness run 34702184771.
G7 used authority mode. The closure and signed artifacts describe the upstream
native engine. The optional Candle worker is built from the same public source
and has its own model, runtime and Omarchy integration checks. The
validation report records their results and limits.
The upstream signed artifact retains its original candidate identity and
workflow certificate. This Omarchy release does not rename or replace an
existing Hyphae registry release or its version tag.
Known limits
The reference BGE model is English-oriented. The small ES/EN fixture is a
reproducible check, not a production quality guarantee. Proofs verify retrieval
against a snapshot and can include private retained data; they do not establish
that remembered statements are true. Forget/expiry does not securely erase old
versions or backups. Complete proof responses retain the native 16-MiB bound.
The optional embedding build retains the existing unmaintained paste macro
dependency through Candle and tokenizers (RUSTSEC-2024-0436). No advisory
exception was added. Its license and package identity remain in the dependency
inventory.
User services, local credentials and host configuration are created through
explicit setup actions. Removing the integration preserves memories, backups
and models. Edited managed host entries require review before replacement.
The hyphae-memory-0.1.0-validation.zip asset retains the local validation reports, final packaged VM installation, package/source identity, and hosted CI record. package.json identifies the complete offline archive.