v2.8.0: Durable memory and scoped answerability
Structured answerability remains opt-in. Existing brains
upgrade to schema 15 when opened by this version. Memory projection maintenance
adds local storage/write work even with the guard disabled; no extra model calls
are required for fact extraction or evidence accounting.
Added
- Opt-in
broker.explicit_fact_guardfor scoped configuration evidence, partial
answers and conflicting values. Schema 15 stores a rebuildable fact projection
bound to source events, revisions and visible evidence. No additional model
calls; delivered evidence still consumes context tokens. - Reproducible paired evaluation and per-query delivered evidence. The new
45-query synthetic fixture retained 24/27 positive hits and reduced unwanted
injections from 15/18 to 3/18. Exact metadata matched 36/45 in both repeats;
p95 was 376.6 → 386.6 ms. Compound retrieval and unsupported subjects remain
gaps. See answerability and the report. - Configurable reranker cutoff, an optional pinned multilingual reranker and
opt-in shared ONNX inference thread control. Existing model defaults remain.
Fixed
- Durable corrections and cross-writer ANN refresh; delayed feedback is bound to
delivered claim revisions. Lifecycle decisions preserve distinct claims and
archive/restore state; replay and merged sync imports are atomic. - Final serialized delivery budgets, post-rerank policy, current warm-start
evidence and explicit episode lanes. Free-tier hooks avoid host harvesting. - Conflict warnings survive intermediate budgets, capsule caps and daemon
transport. Tagged agent-recorded lessons can produce structured evidence. - Remote context honors an absent server reranker instead of loading the local
stdio configuration and consulting its warm-start cache. - Release notes correctly extract changelog headings with a version followed by
a colon; empty extracted notes now fail the release job.
Security
- Updated transitive
h2from 0.4.14 to 0.4.16, fixing
RUSTSEC-2026-0258(unbounded empty HTTP/2 DATA frames). - Reject repository identifiers that alias Windows paths and reject redirected
repository roots. Validate existing brain state paths before first-use shortcuts. - Restrict Bedrock region values to a hostname label, encode model IDs as path
segments, require HTTPS, and disable redirects for signed requests. - Replace the yanked
der0.8.0 dependency with 0.8.2. See the
release security review for the
dependency audit and the disposition of existing code-scanning alerts.
Verified metric summary
Frozen synthetic structured-fact fixture: 45 cases, two repeats. Both sides
use the opt-in guard; the baseline is the prior answerability implementation.
| Metric | Baseline | Candidate |
|---|---|---|
| Unwanted injections | 15/18 (83.3%) | 3/18 (16.7%) |
| Positive retrieval hits | 24/27 (88.9%) | 24/27 (88.9%) |
| Exact evidence metadata | Not emitted | 36/45 (80%) per repeat |
| Subsequent-query p95 | 376.6 ms | 386.6 ms |
| Mean MCP response bytes | 613.5 | 651.2 |
That is 80% fewer unwanted injections, with +2.7% p95 latency and +6.2%
response bytes, computed from unrounded measurements. These are delivered-evidence
measurements, not generated-answer accuracy or a new overall BrainBench score.
Measurements retain implementation 3ae8329 and harness 2c74dad; this is not
a fresh benchmark of the tagged binary or a v2.7.0-versus-v2.8.0 comparison.
See the frozen report and artifacts.
Release verification and security disposition
The release-feature workspace suite passed 1,500 tests (six intentionally
ignored); the refreshed benchmark harness passed 132 Rust tests. Main's
cross-platform CI passed. The tag's binaries are built, smoke-tested and
attested by the release workflow; SHA-256 sums are in checksums.txt.
On September 9, all 46 remaining CodeQL findings were reviewed and dismissed
as false positives with individual rationales: 44 traced trusted Axum server
state as HTTP input, and two misclassified non-secret identifiers. GitHub
reported zero open code-scanning and Dependabot alerts after disposition.
No scanning rules were disabled. Dependency audits found zero known
vulnerabilities; informational maintenance notices for paste and
rustls-pemfile remain. The detailed follow-up
records the evidence and limits.
Package availability
GitHub archives, npm packages, and all five crates.io packages are published at
v2.8.0. The release workflow completed successfully after the registry credential
was updated. Install the CLI with cargo install kimetsu-cli --version 2.8.0.