Release Notes v1.4.3
Released: 2026-10-02
This release lands the first half of personal archive import, a checked, actor-bound intake path for moving a personal archive into an organization, and rebuilds the graph read path around native cross-store transactions. Alongside that: a project-scope enforcement fix across every search surface, recall fixes that keep unreviewed model drafts out of memory results, and an entity-read path that answers errors with the right status code instead of a 500.
🌟 Highlights
📦 Personal archive import, checked before anything is applied
New POST /archive-imports/check accepts a multipart upload (archive + options) and stages an immutable checked plan without writing a single archived row. GET /archive-imports/{run_id} returns the caller's saved counts and digests. Every run is bound to an organization and actor at creation, and the plan, artifact digests, and credential ceiling are all immutable fields. The apply path is fenced but not yet exposed as a public route.
⚡️ Entity reads stop re-validating the same source
perf(graph): coalesce source validation within entity reads shares one validation pass across an invocation instead of per-observation. On a 100-observation snapshot, content queries dropped from 318 to 12 and authority resolutions from 105 to 3. Query count now tracks the number of distinct sources, not the number of entities.
🔒 Search honors the projects you actually selected
Search, raw-capture listing, MCP retrieval, and the web UI could return rows from projects outside the current selection. POST /search and the raw-capture listing now take project_ids and verify each one against the caller's accessible projects; the web UI resolves selection before issuing a query. MCP search() now requires an explicit project=<id> or all_projects=True. API key project grants still cap the result set; selection can only narrow.
🐛 Corrected and deleted memory text stays gone
Graph detail, list, and related reads now carry a read-only capture-ancestry proof and recheck source membership and delegated team authority on every read. Previously an entity could still serve source-era text if the graph stamp failed mid-correction, and revoked team access did not immediately hide entities the caller had seen before.
🔨 Owned native cross-store transactions
New backends/surreal/native_transaction.py introduces NativeTransaction, NativeScopedExecutor, NativeStoreScope, and NativeCommitOutcome for transactions spanning the content and graph stores with explicit commit semantics and no SQL sandbox. Recursive validation reads are now bound to paired content and graph executors, so a single selected view holds across source observations, derivations, and validation dependencies.
📦 Archive Import
- New routes module set under
apps/api/src/sibyl/api/routes/:archive_imports.py,archive_import_upload.py,archive_import_preview.py,archive_import_limits.py,archive_import_authority.py. - Four new tables:
archive_import_runs,archive_import_artifacts,archive_phase_controls,archive_phase_receipts. Artifacts and receipts rejectUPDATEandDELETEat the schema level. - Explicit budgets on every intake dimension: compressed bytes, inflated bytes, per-member bytes, options bytes, multipart header bytes, JSON scalar bytes, JSON depth and node counts, and encoded plan and artifact bytes. Over-budget uploads answer 413; malformed uploads answer 422.
ArchiveCredentialCeilingintersects the original, request-start, and current grants, preserving an empty restricted ceiling rather than widening it. A credential identity change mid-request answers 409.- Phase controls run a
open → rolling_back → rolled_backstate machine with a token field and a receipt required for every revision, so a partial apply can be rolled back against proof rather than guesswork. - Protection metadata and typed lifecycle state survive as inert staged values under fresh destination identities (
feat(migrate): preserve protection in archive candidates), and merge restores retain existing relationship UUIDs instead of recreating them. - Content exports are now scoped to the selected organization, so a team-scoped archive no longer picks up rows from another org.
🔍 Retrieval and Recall
- Unpromoted reflection drafts are excluded from recall. A capture with
capture_surface == "reflection_candidate"and areview_stateother thanpromotedis filtered inside the vector walk and in the fulltextWHEREclause, before lane limits apply, so drafts can no longer crowd real captures out of a limited result set. The stored column wins over caller-supplied metadata. - BM25 scores for original captures are now stable. Fulltext indexing splits into
raw_lexical_originalsandraw_lexical_reflections(schema_raw_lexical.py), each with its own analyzer. Promoting, editing, or purging a draft no longer shifts corpus statistics for genuine captures. A batched, idempotent backfill migrates existing rows and aborts a batch on concurrent mutation rather than publishing stale content. - Filtered vector candidate pools complete. Filtered HNSW could stop before visiting all eligible vectors, returning a short entity-search result even with compatible candidates present. Two new indexes,
idx_entity_vector_spaceandidx_entity_typed_vector_space, let the planner bind the provider/model/dimension/org slice (and a type-leading variant) instead of scanning unrelated models and orgs. - Derivation publication is now fenced on both the old and new target source ledgers, so an association-only change cannot commit beside a stale archive receipt.
🔧 CLI
--json/-jnow works on the last three list commands:sibyl org list,sibyl auth api-key list, andsibyl skill list.sibyl org members listgains the-jshort flag so every list command accepts both spellings.- API key output passes through a field allowlist (id, name, prefix, scopes, project and memory-space limits, created, last used, expiry, revoked), keeping any field the server adds later out of terminals and pipes. The table derives an
active,expired,revoked, orunknownstatus per key. - Org and API key table cells are Rich-escaped, so a name like
[/]brokenno longer crashes the command and[red]prodno longer silently loses its text. - A malformed server listing now raises a
SibylClientErrorand exits 1 instead of printing "No organizations found" with exit 0 and hiding a server fault. - Worktree routing: new
link_paths.pyresolves a git worktree to its repository's equivalent path, so a repo and its worktrees reach the same server and project.--this-worktreepins a worktree explicitly, andsibyl project links --prunedrops empty, missing, and redundant links. - Team org correctness: logging in against a team server no longer silently activates that context globally; a context activates only with
--useor when nothing is active.sibyl migrate to-teamprints its target org and refuses a personal org unless--allow-personal-orgis passed, and ledgers carry the target org in their route and filename. - Raw memory lifecycle actions are recoverable. Sending a raw memory reference (an id starting with
raw_memory:) to an entity graph route now answers 422 naming it as a raw memory, with a remediation hint pointing atsibyl correct <id> --help. A genuinely missing entity answers 404 (previously a 500 the CLI read as an outage and buffered for replay forever), also hinting atsibyl correct. Rejected and missing writes no longer persist in the replay queue.
🌐 Web
- Brand fonts now apply to the whole app: the
next/fontvariable classes moved from<body>to<html>, so body text, headings, and code render in Space Grotesk and Fira Code rather than system fallbacks. - Graph node labels render in Fira Code, and cluster names are consistent across the legend, canvas labels, and selection chips via a new
withDomainLabels()helper. - All seven documentation screenshots were recaptured on 1.4.2 with correct fonts and the semantic-zoom map.
- The showcase capture script can run headless with a stored session or visible for interactive sign-in.
🔨 Dependencies and Release Tooling
- Next.js 16.3.4 → 16.3.6. The production dependency audit rejects 16.3.4 following the critical advisory GHSA-vcvr-r3jv-pc5j. Consult the upstream advisory for exposure details on 16.3.4.
pydantic-ai-slimpinned to>=2.42.0,<2.52in both thellmextras and thedevgroup. 2.52 and later break Claude structured output handling and the Bedrock profile; the cap lifts with the output mode migration. The lockfile already pinned 2.42.0, so this only affects fresh installs resolving a newer release.- New
tools/release/land_release.pymakes a release survive merges tomainduring the roughly 50-minute gate window: it lands the branch and tag atomically, falling back from fast-forward to a validated merge. The merge is accepted only if the line edits match the bump edits, the tree passessync_versions.py --check, and no guarded path (tools/release/,.github/workflows/publish.yml) was touched. - CI gives each push to
mainits own concurrency group, so a release run is no longer cancelled by a following merge.cancel-in-progressremains on for pull requests.
Breaking Changes
- MCP
search()requires an explicit project scope. Calls that pass neitherproject=<id>norall_projects=Trueare now rejected. Update agent tool definitions and any scripted MCP calls. sibyl org listandsibyl auth api-key listdefault to a table. Both previously printed raw JSON. Add--jsonto any script that parses their output; the JSON keeps the same top-level shape ({"orgs": [...]}and{"keys": [...]}).sibyl skill listis unchanged by default and simply gains the opt-in--json/-j.- Malformed list responses now fail loudly.
sibyl org listandsibyl auth api-key listexit 1 on a listing that is not an object holding a list, where they previously returned an empty result with exit 0. - Entity route status codes changed. A
raw_memory:reference on an entity graph route (PATCH,DELETE) returns 422 instead of falling through to a 500. A missing entity returns 404, also previously a 500. Clients that treated these as retryable server errors should stop retrying. - Revision conflicts have a structured 409 body. The response is now
error: "revision_conflict"withdetails.expectedanddetails.actual, replacing a 409 whose body was the raw exception details dict. Clients reading the old unstructured payload need updating. - Login no longer auto-activates a context. A context becomes active only with
--useor when nothing is active. Scripts that relied on login switching the active context must pass--use.
Upgrade Notes
- Graph schema migrations 34 and 35 add
idx_entity_vector_spaceandidx_entity_typed_vector_spaceon theentitytable. Both are plainDEFINE INDEX IF NOT EXISTSstatements with no concurrent-build clause, so schedule the upgrade with build time in mind if yourentitytable is large. - A batched backfill populates the new
raw_lexical_originalsandraw_lexical_reflectionstables. It is idempotent and leaves captures unchanged, but a large capture corpus will take time to index. - Audit scripts for
sibyl org listandsibyl auth api-key listand add--jsonwhere output is parsed. Check for scripts relying on exit 0 from a malformed listing. - Update MCP agent configurations to pass
projectorall_projectson everysearch()call. - Fresh installs resolve
pydantic-ai-slimbelow 2.52. If you pin it yourself, hold at 2.51.x until the output mode migration lands. - Deploy the Next.js 16.3.6 bump promptly; the prior pin is blocked by the production dependency audit.
Install
Local server
curl -fsSL https://raw.githubusercontent.com/hyperb1iss/sibyl/main/install.sh | sh -s -- --version 1.4.3Remote CLI
curl -fsSL https://raw.githubusercontent.com/hyperb1iss/sibyl/main/install.sh | sh -s -- --remote --version 1.4.3
sibyl init --remote https://sibyl.example.com
sibyl auth loginHomebrew
brew install hyperb1iss/tap/sibyl
sibyl upArch Linux (AUR)
paru -S sibyl
sibyl upHeadless server
curl -fsSL https://raw.githubusercontent.com/hyperb1iss/sibyl/main/install.sh | sh -s -- --version 1.4.3 --no-openKubernetes (Helm)
helm repo add sibyl https://raw.githubusercontent.com/hyperb1iss/sibyl/gh-pages
helm repo update sibyl
helm upgrade --install sibyl sibyl/sibyl --version 1.4.3Artifacts
This release includes Python wheels and sdists, the generated
Homebrew formula, the generated AUR PKGBUILD, Helm charts, Docker
SBOMs, aggregate dual-registry cosign receipts, and a SHA256 checksum
manifest.