Skip to content

v4.7.1 — The audit lands; the loop closes

Choose a tag to compare

@github-actions github-actions released this 23 Sep 23:25
· 168 commits to main since this release

Post-ship audit round (hostile, by the Gemini executor and verified by the
orchestrator): 14 findings, 12 fixed, 2 routed to the roadmap. Everything
below is measured against the live codebase.

Added

  • Decision-outcome CLI — the calibration loop closes. conscio outcomes list and conscio outcomes resolve <ref> <outcome> --evidence ...
    attach the real outcome to captured decisions. Before this, every council
    capture stayed pending forever — nothing in production could resolve
    them, making measured calibration unreachable outside tests (the orphan
    defect: tests proved the method worked; nothing proved a production
    path called it). Ghost resolves and invalid outcomes are visible errors.

  • Host identity derived from environment presence. When neither the
    --identity-* flags nor the env vars are set, the server now knows its
    host from the PRESENCE of host-specific environment keys (ZCode,
    Antigravity, Claude Code, Hermes, OpenCode). The golden rule, born from
    a live audit that found shell tokens in a server's environ: detection
    reads key NAMES only — values are never read. No recognizable signal
    means empty identity with source=none (the v4.7 absence contract —
    never a guess). Family derives strictly from the model name; no forced
    fallbacks. Final precedence: CLI flag > env var > host derivation > empty.

  • CONSCIO_IDENTITY_MODEL / _FAMILIA / _RUNTIME / _PAPEL env
    vars
    — per-host identity for hosts that cannot override MCP args
    (plugin-shipped configs). Precedence: CLI flag > env var > empty. Without
    them, a server boot republishes the card with explicit empty strings and
    wipes the identity an agent published by hand.

Fixed

  • Native embedding failure is no longer silent. A bare pip install conscio without sentence-transformers had semantic recall off with
    only a debug-level log. Now: WARNING naming the remedy (install the
    package or opt into a daemon via CONSCIO_EMBED_BACKEND).
  • Coherence epistemic score honors the None contract. Cold start
    (calibration None) was a TypeError swallowed by a bare except;
    it is now an explicit branch — absence is a contract, not an exception
    to mask.
  • conscio/USAGE.md resynced from the root — the packaged copy had
    drifted (297 vs 580 lines).

Fixed (bug-hunt round)

  • Evaluate Clarity no longer inflates on a broken detector. The
    contradiction counter's except: pass silently reported a clean score
    when the world read failed; the failure now logs and the axis reports
    the count as UNMEASURED.
  • HNSW signature metadata opens with busy_timeout — concurrent agents
    validating the vector signature no longer die on database is locked.
  • Relay token and tick cursor writes are atomic (tmp+rename) — a crash
    mid-write can no longer leave a truncated token or a torn cursor that
    silently re-ingests the window.

Changed (docs — the standing rigor rule)

  • CONTRIBUTING.md rewritten against measured truth: one test file per
    process (the old pytest tests/ -q OOMs), test counts re-measured per
    release instead of frozen numbers, pyright (not mypy), line length 100,
    the ConfidenceValue contract, native-first embeddings, and the
    fake-module-in-sys.modules pattern for optional dependencies.
  • USAGE.md: 8 console scripts (reactor + relay-bridge were missing);
    native-first embedding policy (the fallback-chain text was stale);
    storage defaults corrected (library default vs the CLI's live-space
    resolution; $HERMES_HOME is legacy).
  • Docs speak spaces, not internal filenames. Storage sections describe
    the space — one directory per agent host, one file per concern — and no
    longer cite internal database filenames.
  • docs/roadmap.md extended to 4.7.0 with the measured suite count and
    a candidate-directions section distilled from the idea banks (durable
    shadow receipts, execution verification, provenance chain, distributed
    consensus, per-runtime evidence producers, decision-model support).