Skip to content

v2.11.1

Choose a tag to compare

@nokhodian nokhodian released this 17 Sep 22:20
· 2020 commits to main since this release

monomind v2.11.1

npm: monomind@2.11.1 · @monoes/monomindcli@2.11.1

Added

  • Org runtime: every role now gets an explicit adapter_config.model when an org is created (mastermind-createorg templates, org create, and init's sample org) — the user's choice, or else the latest model for its runtime (claude-sonnet-5 for Claude, vendor defaults from VERCEL_PROVIDERS otherwise) — closing the drift where an unset model silently followed whatever the runtime's own default happened to be (3a6a4bc).
  • Memory: entity resolution now tolerates common name-spelling variants (Node.js vs nodejs, case/separator/plain-plural differences) via a new coarser mergeKey fold, validated on a blind-labeled benchmark at F0.5 0.775 vs 0.480 for the previous exact-match identity — wired in as a purely additive second index alongside the existing exact-match one, so it can only ever promote or flag a candidate, never merge two differently-typed entities on its own (PR #260: 0450ecc, 13d87a9).
  • Memory: the ettin reranker can now score without a self-exported PyTorch/ONNX build — a pure-JS classifier head (fetched by doc eval --provision-model) restores real reranking (measured Recall@5 0.458 vs 0.396 dense-only) instead of silently falling back to unranked order (PR #259: 75f2651).

Fixed

  • Org runtime / policy.git sandbox enforcement (#258, #262, #263): policy.git was previously enforced only by classifying Bash command text, which couldn't see git reached as data, through scripts, node -e, npm scripts, or non-Claude runtimes' native shells. Roles below push now get a real git guard (blocked credentials/hooks/protocols) plus, on the Claude runtime, an OS-level sandbox; codex and grok's own sandbox flags are now wired to the same policy, and the opencode runner's server now actually receives the role's scoped session env instead of the daemon's own (4c9ea05 #258, 2215c3d, 4c96c81, 3c3de1b, 7c68fe2, 31ec5b2 #263, 0265112 #262, dbb3300, d23bc81, b812038).
  • Git command classifier gaps (#250, #257, #261): closed several ways a policy-gated role could reach git push/git commit/git config writes without detection — command substitutions hiding a git call ($(git push), backticks, here-docs, arithmetic) (#257: 334f797), four shell shapes the scanner previously gave up on and denied wholesale (case arms, ${...} quoting, arithmetic shifts, here-docs) (#261: c703699), and git config write/read misclassification against real git argument parsing (#250: f612369, 2a43398).
  • Org daemon/session reliability: a role's task-dependency graph no longer lets org_task_done complete a task whose dependencies aren't done, which could dispatch downstream work (e.g. a final build) before docs/version-bump work had landed (#246: b473d66). A crashed SDK session now actually resumes its prior conversation on auto-restart instead of starting cold (#247: 95e11e0). A stopped run's unanswered ask_human questions no longer leak into the next run (#248: fb671e6). Monomind-internal env vars (MONOMIND_SDK_AGENT, MONOMIND_HOOK_QUIET, MONOMIND_GRAPH_GATE, MONOMIND_NO_LOCAL_EMBEDDINGS) no longer leak into every Bash command an org role runs, which had been silently changing hook/graph-gate/memory-search behavior mid-role (#249: c503fc0, fd862dd). Idle roles aborted by a normal org_complete/stop no longer get logged and alerted as crashes (#251: 659dd25). The Claude runtime's default model no longer drifts to a stale claude-sonnet-4-5 fallback (#252: 25ddccd). Org logs/status/questions/approvals timestamps are now explicitly marked UTC (Z suffix) instead of printing bare local-looking times (#253: 0bfe079). org run now applies a reload request queued in the same tick as a stop, and clears a stale one at start (#254: 38cc8df, 00215d3). A stuck/silent session attempt's internal abort no longer poisons the whole role slot's retry loop (#256: 0272650). org run/org serve no longer act on a stop/reload request left over from a previous daemon (#264: d5ef39f). Restored clearing a stale pending approval on a fresh (non-resume) org start, regressed since #165 (f6a0d9b).
  • monomind autopilot log entries are now marked UTC (Z) instead of printing an unlabelled local-looking time, matching #253's fix for the org runtime's own logs (#265: 3185ad2).
  • monomind monograph watch (and the background watcher init --watch starts) never fired for a project under a dot-directory or an ancestor named dist//build//node_modules — ignore patterns are now matched against the repo-relative path instead of the absolute one (#255: b1d2c25).
  • Every pricing table (model-pricing, dashboard collector/server, token trackers) priced claude-sonnet-5 like Sonnet 4.6 ($3/$15 instead of its real $2/$10 per MTok), overstating org cost estimates and budget-cap usage by 50%; claude-fable-5-1 also gains a pricing row ($10 in / $50 out, cache reads $0.25/MTok) so its usage is no longer reported unpriced (17a42e2).
  • This run's fixes, verified independently against a clean environment: security scan/secrets now actually reads file contents instead of always reporting "no issues found" (6085a72); top-level search --type code now returns results instead of always "No results found" (f10bc32); mcp start now honors --help/--transport/--port instead of silently starting a hardcoded stdio server, and mcp status/mcp health can now see a bare mcp start via a PID file — 3 findings, one root cause (8627807); config set --help's own first example now works instead of failing "Required option missing" (469c8f4); analyze diff --risk/--classify no longer print literal "undefined" for Type/Category/Subcategory/Reasoning (7760455); monograph search's text-mode table now shows a Line column, matching --format json (fd9f9ed); graph-report-gaps.test.ts/graph-report-confidence.test.ts no longer hardcode /tmp for their output path, which fails with EROFS in any sandboxed/read-only-tmp environment (0902c91).

Changed

  • Replaced claude-sonnet-4-6 model defaults/aliases with claude-sonnet-5 across pricing tables, the dashboard adapters endpoint, the statusline label, and all five mastermind skill trees' recommendations (3b0cd3f); centralized the default Claude model into one exported constant instead of four hard-coded copies, refs #252 (f0be2c5); pinned every release-gate role explicitly to the latest model (ec76708).
  • session.ts's hand-maintained per-vendor model-default table was replaced with a direct read of the VERCEL_PROVIDERS registry, removing a second list that could drift from the first (f234445).
  • policy.ts (861 lines) split into shell-scan.ts and policy-git.ts, with behavior unchanged (7f150bf).
  • The release-gate org config is now tracked in the repo at config/orgs/release-gate.json instead of existing only on one machine (6978f8d).
  • The mastermind-review skill and its command docs now explicitly trigger on plain-language "review this session/worktree" phrasing, not just the literal slash command (bce80ec).
  • Internal milestone notes recorded the org-run-reload fix and a worktree cleanup sweep, and corrected a stale version label (4650438, 45a1984).
  • Docs and site content updated for 2.11.1 (e5b4026).