clio-relay 1.4.6
clio-relay 1.4.6
This patch fixes registered remote-MCP calls made through an owned desktop relay session. The desktop-selected cluster definition is now staged as an exact, generation-scoped registry and bound to the remote API process by path, SHA-256, and route revision. The API validates and retains that authority at startup, so an incidental cluster-side registry can no longer cause valid catalog or Spack calls to fail with a route-mismatch HTTP 409.
Owned sessions now fail closed when their authority is missing, partial, oversized, mutated, multi-cluster, route-drifted, or registration-drifted. Incomplete starts remove their staged registry, existing-session reuse verifies the same authority, and ordinary non-session registry behavior remains unchanged.
The release also updates acceptance fixtures to model supervised endpoint generations and SHA-bound durable MCP discovery artifacts. Focused authority, lifecycle, CI-reproduction, release-policy, Ruff, and Pyright checks passed locally. Full tag regression and PyPI publication run asynchronously after release publication; released-wheel Ares validation is tracked separately and is not claimed here.
Source commit: a45e9b5c2659a5929d7fd02a1c0c2d3307cedd43
Artifact SHA-256:
559db7b2f0bae7f74ef3ed251fdced173346e7550bf4a71f2e843d0b14fb3cfa—clio_relay-1.4.6-py3-none-any.whl1bc3779334257843fe25594c06ea0dcb03d7e962afc26fe3646cff998f5bfed4—clio_relay-1.4.6.tar.gz