Skip to content

v0.16.0

Choose a tag to compare

@github-actions github-actions released this 23 Sep 13:46
· 23 commits to main since this release
0329cf1

Bug Fixes

  • pin rand to 0.8 to satisfy ed25519-dalek's rand_core 0.6 requirement (d57e4be)
  • isolate device_id/public_key consistency test, deduplicate derivation logic (7ff818c)
  • close gossip merge trust-bootstrapping, cross-target replay, and new-entry poisoning holes (81ee563)
  • silence unused-variable clippy warning in pairing test (e7b1468)
  • scope TLS listener to hive routes only, wire self-identity/self-join/mDNS at startup, stop swallowing config errors on stdio entry point (caf0351)
  • warn when the hive pairing endpoint is exposed on a non-loopback host (4fde453)
  • use explicit crypto provider for the hive TLS listener, not the ambiguous default (025a12a)
  • backfill hive_content_hash lazily so pre-existing memories actually sync (cc0dbc5)
  • wrap backfill_hive_content_hashes' writes in a single transaction (f3b4723)
  • split pairing/sync TLS ports, time-bound the pairing window, hot-reload sync trust config, wire settings/tag-namespace sync (ff428c8)
  • graph nodes could not be dragged (aad03c9)
  • bake caller's PATH into the systemd unit / launchd plist (03eaf45)
  • don't clobber a fast agent-error back to 'suggesting' (52deab9)
  • pin pairing TLS to peer key, gate trusted-networks to loopback (a2755f5)
  • don't report revoke success when merge_roster silently rejected it (080ddb7)
  • make the enable-toggle restart fire in interactive TUI mode (466790b)
  • dashboard_port default collision + wrong pairing-expiry label (fa39eef)
  • address final-review findings on Settings > Hive page (75cb202)
  • stop cluster forces dragging every other node along with one (c68d4e4)
  • freeze cluster-anchor forces during an active node drag (8ff68a0)
  • temporarily pin every other node during an active drag (1e8deda)
  • silence dead_code warning on diff_and_apply (e49bf7f)
  • stop diff_and_apply's conflict test from flaking on timing (f5a74e2)
  • satisfy clippy -D warnings across the hive module (9b09f06)
  • gate POST /api/v1/hive/join behind require_loopback (b39b033)
  • close security and correctness gaps found in review (0496848)
  • rename stale hivemind references after merging main's mynd rename (87d9a30)
  • require allowed_users for room messages and invites (9871d07)
  • cap expression depth and length to prevent stack overflow (960f9d0)
  • reject DNS-rebound and cross-site browser requests (626104e)
  • graceful shutdown on SIGTERM/SIGINT; verify pid before kill (b57103b)
  • serialise writers on the shared libsql connection (40bcb51)
  • require explicit confirmation to apply, add timeout and opt-out (55ea4c2)
  • create config.toml owner-only; allow sync keys from env (676c981)
  • enforce size and enum validation inside the store (0118581)
  • retry spawn briefly on ETXTBSY (3aaff43)
  • treat memory content as data in every agent-facing prompt (5a9683f)
  • unknown-memory feedback 404s, wildcard-bind api_url, bigger SSE buffer, full wipe (52bb970)
  • address final whole-branch review findings on Discord daemon (43e163a)
  • serialize org_db_path test's XDG_DATA_HOME mutation with ENV_MUTEX (0990c3b)
  • rename Discord's hardcoded hivemind identifiers to mynd (fea3302)
  • replace deprecated rmcp::model::ServerInfo with ServerConfig (2e235fe)
  • restore dashboard/dist/.gitkeep dropped by the main merge (f0ca509)
  • unbreak build after ed25519-dalek 3.0.0 bump (b2c3173)
  • grant packages:write to release job for docker publish (6ebeeb1)

Documentation

  • add full-repository security and quality audit report (154e16b)
  • record m3/m6/m14/m16 in the remediation status table (0a047a7)
  • add Discord chat interface design spec (804713d)
  • add Discord integration implementation plan (833dda8)
  • document the Discord chat interface (1abb019)
  • document Discord's wider guild trust boundary vs Matrix (b465528)

Features

  • add hive_devices roster table (8ea693a)
  • device identity generation and Ed25519 sign/verify helpers (80c6249)
  • keyring-backed device identity storage (77ed093)
  • self-signed join/revocation records and roster entry model (bde202c)
  • gossip roster merge with sticky, revoker-verified revocation (b3fef30)
  • persist roster entries in SqliteStore (bf0a9b9)
  • [hive] global config, mutually exclusive with [sync] (e221894)
  • single-use, expiring pairing codes (9dd068e)
  • add --hive flag to hivemind service install (1519283)
  • pairing HTTP endpoint served over TLS (cc06f64)
  • mDNS advertise/browse for LAN peer discovery (741350e)
  • add sync dependencies, hive_content_hash column, hive_tombstones table (2d114df)
  • compute hive_content_hash on every memory write, write tombstones on delete (45705ee)
  • wrap device identity as a persistent self-signed TLS certificate (d604354)
  • custom rustls ClientCertVerifier accepting only Active roster members (286e191)
  • custom rustls ServerCertVerifier pinning one expected peer's public key (dc1c506)
  • require and verify client certs against the live roster on the hive TLS listener (114f0bc)
  • manifest data model and GET /api/v1/hive/manifest endpoint (ac379ad)
  • apply-incoming-memory LWW logic, hive read endpoints, push endpoint (9cbdc12)
  • outbound mTLS-pinned HTTP client for hive-to-hive requests (bf007b3)
  • pull-round diff/apply logic and sync-interval loop skeleton (e32baec)
  • hive_peer_status table and presence/ping loop skeleton (e3293a0)
  • push-on-change to currently-online peers after local memory writes (18b97c7)
  • mDNS address resolution, join-a-hive endpoint, spawn sync/ping loops (0d914d7)
  • add whichnet dependency and network identity mapping (beb3c06)
  • add store methods for the trusted-networks list (fbf58cb)
  • REST CRUD for the trusted-networks allowlist (c92352a)
  • mDNS shutdown + pure pause/resume decision function (2a516b1)
  • auto-pause/resume the hive stack on untrusted networks (11c5bb6)
  • wire conflicts.source_device_id into per-peer pending_conflict_count (828c87f)
  • attribute pull-path conflicts to the peer they came from (936e21d)
  • DB-backed hive_enabled_override, checked before config.toml at boot (b54257c)
  • GET /api/v1/hive/status for the dashboard (4ece9f9)
  • POST /api/v1/hive/roster/{device_id}/revoke (8eb7a8e)
  • POST /api/v1/hive/enabled with live restart, no config.toml edit (fe2028b)
  • emit hive_peer_status_changed on real online/offline flips (90c3614)
  • add hive API client (ffe5c8e)
  • add hive Pinia store (7718190)
  • add hive revoke confirmation modal (3a3c4bc)
  • add HiveSection component (97c9e78)
  • add Hive tab to settings (c9cf7df)
  • live-update hive peer status via SSE (b65c9fb)
  • add [discord] config schema (application_id, channels, permission_gate) (89efaf9)
  • add Discord bot-token keyring storage (7017c6b)
  • add Discord login persistence (7ffbb0e)
  • add Discord channel/DM memory-target resolution (98f2f3e)
  • add Discord per-channel session TTL map (e5f5217)
  • add Discord fast-path direct memory store (f22952d)
  • add Discord daemon status Unix-socket broadcast (a92558d)
  • add discord daemon pidfile path (aede682)
  • add Discord message-authorization and permission-gate logic (b8dd6ad)
  • add Discord gateway daemon (message/slash-command handling, run(), send_direct_message) (18ebbb2)
  • add hivemind discord subcommand surface (5b08701)
  • add hivemind discord login/status CLI commands (c42c2a0)
  • wire hivemind discord login|run|status|send into main (e83c1b6)
  • add --discord flag to hivemind service install (f8d225e)
  • add DiscordStatusLine to hivemind status (403037c)
  • render Discord status line in hivemind status TUI (e54c975)
  • add CLI-native pairing for headless devices (0dc33d8)
  • implement Analytics view from design handoff (4a3dd9a)

Performance

  • offload blocking network probe, cache the self-signed cert DER (6835d49)
  • batch tag loading instead of one query per memory (59571c5)

Refactoring

  • extract shared agent-turn-runner into src/chat_bot (ceb9a6b)

Testing

  • strengthen crypto-provider test to prove the bare builder() genuinely panics (a12e8d2)
  • cover the None-preserves-last_synced_at path in hive_upsert_peer_status (5d59f76)
  • cover the already-revoked branch of hive_revoke_device's 404 path (619ef8d)
  • raise coverage on api/hive.rs and hive/* modules (c39cd4b)
  • add Vitest unit tests + Playwright e2e for the graph canvas (45bdb18)
  • serialise the tests that read sync keys with the env tests (36b3d86)
  • cover TUI render functions and pure http.rs helpers (d4aeb62)
  • increase coverage for discord daemon and CLI commands (4758068)