Skip to content

Releases: rustam-python/gbrain

v0.60.11.0

Choose a tag to compare

@github-actions github-actions released this 30 Sep 15:49
1ba2d00

Managed brains stop re-writing the same pages every hour, every maintenance job finishes again, and after an upgrade doctor shows you each leftover problem with the exact fix.

If you connect Gmail, Calendar, Contacts or GitHub to a managed brain, each connector used to forget where it stopped after every maintenance cycle. So every hour it walked its whole window again and spent a new permanent write ID and receipt on every unchanged page. Now it resumes where it stopped, skips pages that did not change, and keeps going when the owner is slow instead of giving up after one write.

On the same brains, a dozen maintenance steps still used a writer that managed brains refuse. Concept synthesis paid for the model call and then died, taking the rest of the nightly job with it. Every maintenance writer now goes through the coordinator, and one failing step no longer stops the steps after it.

After an upgrade, gbrain post-upgrade prints a preview banner, and gbrain doctor --remediation-plan lists every repair with its command. gbrain doctor --remediate --yes --include-repairs --max-usd 2 applies the ones you agree to, under a spending cap.

Managed brain, test fixtures on both engines Before After
Page admissions on a quiet connector's second run every window item 0
Connector runs that resume their cursor after a maintenance cycle none all
Global maintenance after synthesize_concepts is refused job dies later phases run, job reports the failure
Repairs listed by doctor --remediation-plan none every kind with work, each with its command
Commands from gbrain post-upgrade to a clean repair plan not possible 3
Grandfathering 250 pages on a pushed repository, seconds per page (PGLite / Postgres) 0.456 / 0.821 0.060 / 0.070

Things to watch: the first connector run after the upgrade may re-admit its window once (see below). A page you saved to an unbound Postgres source still refuses by default; the error now names both fixes.

To take advantage of v0.60.11.0

gbrain upgrade should do this automatically. If it didn't, or if gbrain doctor warns about a partial migration:

  1. Upgrade hosts in this order, with autopilot paused on connector hosts. Mixed versions refuse with typed errors instead of losing data, and this order keeps them away:

    gbrain autopilot pause --reason "upgrading to v0.60.11.0"   # on each host that runs connector jobs
    gbrain upgrade                                              # first: every consumer and worktree-owner host
    gbrain upgrade                                              # then: the connector hosts
    gbrain doctor --remediation-plan                            # preview; ask the user before applying
    gbrain autopilot resume                                     # on each host you paused
    gbrain sources status                                       # verify

    If schema work did not complete, run gbrain apply-migrations --yes --no-autopilot-install on the brain host.

  2. Expect one connector re-walk, once. Migration 176 moves each connector's cursor to its new key. A source whose newest cursor receipt was compacted re-walks its window once on its next run, and connector writes still queued from before the upgrade fail once with connector_intent_outdated (detail pre_upgrade, nothing to do) and are fetched again. The post-upgrade banner and gbrain sources status count those sources. This first spike is expected and is not the hourly churn this release fixes.

  3. Your agent reads skills/migrations/v0.60.11.0.md the next time you interact with it. It previews the recovery plan and asks you before applying anything.

  4. Verify the outcome:

    gbrain sources status --json          # after the second run a quiet connector shows page_admissions: 0
    gbrain doctor --remediation-plan      # no repair steps left once you applied the agreed ones
    gbrain sources writer status --json   # writer versions per host
  5. If any step fails or the numbers look wrong, please file an issue:
    https://github.com/garrytan/gbrain/issues with:

    • output of gbrain doctor
    • contents of ~/.gbrain/upgrade-errors.jsonl if it exists
    • which step broke

    This feedback loop is how the gbrain maintainers find fragile upgrade paths. Thank you.

Itemized changes

Connectors (garrytan#5686, garrytan#5470, garrytan#5600, garrytan#5601)

  • Stable connector identity. The checkpoint key, the admission and publication change checks and the attachment-repair preview use the parsed connector settings minus credential-delivery fields. Cycle stamps and other bookkeeping in sources.config no longer restart a connector or fail its pending writes with source_changed.
  • Account pinning. Each connector source pins the account its credential belongs to. Google checks it through every enabled service before importing; GitHub records the App installation, or the login under scope: auto. A different account refuses with connector_account_changed and two exact ways out.
  • Unchanged items take no admission. Connector sync, managed gbrain import, gbrain sync --working-tree and company-profile sync run each item through its own publication preparation first and skip it when publishing would change nothing. Pages below the safe-chunk fence, pages whose search projection lags, deleted pages and changed pages are still published. An unchanged cursor is not saved again; freshness for gbrain waiting is stamped directly.
  • Accepted writes count as progress. A connector keeps going when the owner is slow, waits at most 30 seconds in total per run, and records writes still pending; the next run resolves them first and retries failed ones by itself. extract_atoms reports a batch the owner accepted but has not published as pending, not failed, and dream no longer halts on it.
  • gbrain sync --source <id> --reset-checkpoint re-walks one connector's window. Unchanged pages are not admitted again and the account pin is kept.
  • gbrain sources status shows each connector's upgrade recovery state and its last run's admissions, skipped pages, pending writes and checkpoint admissions.
  • Mixed-version safety. Connector writes use a new intent format. An older consumer refuses it with unsupported_mutation_protocol and the connector names the hosts to upgrade; an older connector's writes fail connector_intent_outdated and are fetched again after the upgrade.
  • Your notes on connector pages survive a re-walk. A timeline entry you add to a connector page (add_timeline_entry) is kept when the connector renders the page again from the provider, and adding one to a database-only connector source stays database-only instead of claiming the source or refusing.

Maintenance writers on managed brains (garrytan#5484, garrytan#5280, garrytan#5523, garrytan#5405)

  • synthesize_concepts publishes through the maintenance coordinator in the same order as before: private first, then the provenance edges, then promotion to world. The authority check runs before any model call.
  • A failing phase no longer kills maintenance. A phase that throws is reported as a failed phase and later phases still run; the job still reports the failure and gbrain dream exits non-zero. Cancellation, a lost cycle lease and budget exhaustion still stop the job. A phase that fails after paid model calls is counted in doctor's dream_paid_loop check.
  • More writers go through the coordinator: Life Chronicle events with their timeline row, the purge of deleted pages, gbrain enrich and enrich_thin (keeping facts and takes fences), the drift report and grade_takes auto-resolutions, the managed extract walk, add_link / remove_link as coordinated database-only writes (a manual link survives re-derivation), gbrain bootstrap verify cleanup, and the facts, phantom-redirect, open-loop and conversation-facts writers.
  • Every phase and mutating operation is classified for managed brains, and a matrix test runs every phase once on a managed PGLite and Postgres brain.
  • Unbound Postgres sources (garrytan#5254). Saving a page to a source with a checkout folder but no owner still refuses by default, but the error (owner_unavailable, detail unbound_source) names both fixes: bind with the printed gbrain sources writer claim command, or run gbrain config set persistence.unbound_write database_only. Migration 177 records those pages as database-only, so they stay that way after binding, and a publication racing a bind fails instead of committing. Doctor's unbound_source check is ok while the source is unbound and warns once it is bound; when a canonical file appears at such a page's path, gbrain sources reconcile <source> <slug> --preview shows both sides and --apply resolves it.

Embeddings and migrations (garrytan#5680, garrytan#4616, garrytan#5621, garrytan#5530, garrytan#5289)

  • Embedding migration budget (garrytan#5680). Each provider request is charged at its maximum and settled to reported usage, once per attempt, summed across retries and splits. When --max-cost-usd is below the printed worst case, the migration stops before touching any vector and prints the command that covers it (embedding_budget_below_worst_case).
  • Degenerate vectors are refused per chunk (garrytan#4616). A zero-norm, NaN or infinite vector fails only its own chunk with embedding_zero_norm; the page's other vectors are kept, on managed brains too, and the failure names gbrain embed <slug>. Empty inputs never reach the provider. gbrain reindex --vectors rebuilds vector indexes after a PGLite crash repair, and the repair notice names it.
  • Contextual retrieval mode (garrytan#5621). --no-embed imports record their mode. Contributed by @woprrr (garrytan#5630). gbrain repair contextual-mode stamps existing pages exactly as a fresh import would and re-embeds only pages whose input changes.
  • Grandfathering groups its Git work (garrytan#5530). The effect runner...
Read more

v0.59.18.0

Choose a tag to compare

@github-actions github-actions released this 29 Sep 20:32
f7c8ccd

Dream no longer keeps made-up quotes, wrong-speaker quotes or invented numbers as memory, and gbrain eval compare computes the statistics it claims.

When the nightly dream cycle turns a conversation into brain pages, a mechanical check compares each quote with the transcript. Until now, a quote it could not find lost its quotation marks and stayed on the page as ordinary text, so an invented sentence became searchable memory. Pages that already existed (person pages, earlier reflections) were not checked at all, a close-match repair could splice in the next speaker's words, and numbers the transcript never mentioned were only counted.

Now any sentence that fails the check leaves the page body and is kept word for word in the page's unverified_claims frontmatter, which get_page shows but search, recall and think do not read. A sentence fails when its quote appears in no source transcript, only matches across two speakers, is attributed to someone other than the person who said it, or when it states a number or date the transcript does not contain. Pages that already existed are checked on the sentences the run added, against the transcripts that wrote them. Timeline entries, facts and links derived from a failed sentence are removed with it. Each kept quote records its source file, character span and speaker in grounding.quotes.

Measured on a fixed three-cycle experiment (3 transcripts, a scripted model that writes 13 supported claims and 17 invented ones, including edits into existing pages), counting what search and recall can read after the third cycle:

After 3 dream cycles v0.59.13.0 v0.59.18.0
Invented claims in active memory (of 17) 17 2
of which fabricated quotes (of 6) 6 0
of which speaker-swapped quotes (of 3) 3 0
of which invented numbers (of 6) 6 0
of which unquoted inventions with no number (of 2) 2 2
Supported claims kept (of 13) 13 13

The fixture was written alongside the check, so treat it as a regression pin, not a hallucination rate for a real model. Plain-prose inventions with no quote or number are not mechanically checkable and still get through.

gbrain eval compare printed "paired bootstrap with Bonferroni correction" but computed only side-by-side averages. It now computes paired statistics from per-question rows: for runs whose ledger record points at their per-question output, it joins the rows by question and reports a 95% bootstrap interval, a p-value and a Holm-corrected p-value for each metric. Runs without per-question rows are labeled aggregate-only, with no significance claim.

To take advantage of v0.59.18.0

Run gbrain upgrade. There is no migration. The check applies to the next dream cycle; existing pages are not rescanned. To review what was held back, run gbrain get <slug> and read unverified_claims. To compare two LongMemEval runs with real statistics, record both with gbrain eval longmemeval --record --output <file> and run gbrain eval compare --baseline <run_id> --candidate <run_id>.

Itemized changes

  • synthesize-verify.ts checks sentence-sized claim units (sentences, list items, table rows) instead of bare quote spans, and quarantines a failing unit whole instead of removing its quotation marks.
  • Close-match quote repairs stay inside one speaker's turn and are trimmed to the matched words (write-path audit C-6); any match that touches a speaker label is refused.
  • Attribution check: when a sentence names a transcript speaker, the quote must come from that speaker's turn.
  • Numbers and dates are compared by value, so $250K, $250,000 and 250 thousand agree, as do 2026-03-14 and March 14th; the transcript file name counts as a source for dates.
  • Verification covers every page a child wrote. A page created during the run is checked whole; an older page is checked on the sentences missing from its revision before the run (page_versions), against every transcript that wrote it. Epochs come from the child jobs' creation time, so resumed children still count their own pages.
  • The unmanaged write-back re-projects timeline entries, facts, takes and links from the verified body in the same transaction. The managed path already re-projected timeline entries, facts and takes through its page publication.
  • New telemetry in details.synthesis.quote_verify: quarantined_claims, pages_with_quarantine, preexisting_diffed, skipped_unchanged and one counter per failure reason. stripped, skipped_preexisting and numeric_claim_warns are gone.
  • gbrain eval compare: --baseline, --candidate, --draws, --seed; JSON gains paired and paired_unavailable; Markdown gains a "Paired comparisons" table with a significant / not significant verdict. A per-question file path in the ledger must resolve inside the repository root; paths that escape it are refused and never read. The statistics module (src/core/eval/paired-bootstrap.ts) is a port of the gbrain-evals situation-recall comparator with a two-sided p-value.

For contributors

  • New tests: test/cycle-repeated-consolidation.test.ts (fails on v0.59.13.0, passes here), test/eval-paired-bootstrap.test.ts; extended test/cycle-synthesize-verify.test.ts, test/eval-compare.test.ts, test/cycle-write-path-mini-eval.test.ts.
  • bun run scripts/repeated-consolidation-experiment.ts [--per-cycle] prints the experiment as JSON ($0, no network). Record in docs/eval/FIX_WAVE_BASELINES.md.

v0.59.3.0

Choose a tag to compare

@github-actions github-actions released this 29 Sep 06:49
a7d00a6

A broken worker installation now asks for repair instead of repeatedly interrupting your jobs.

Background workers check that they and the programs they launch can safely talk to
the database before taking work. If an installation is missing a required
capability, processing stops with a repair instruction. Its supervisor stays
available to report the problem rather than starting the same broken worker
again. Temporary connection problems still retry normally.

The database driver now ships with the application, so a global installation no
longer depends on the package manager remembering to apply a separate patch.
Workers also prefer their own installation when launching jobs, while checking
any explicitly selected alternative before using it.

If a configuration problem interrupts running work, the worker only returns a job
to the queue after execution has stopped and its ownership is still valid. When
that cannot be confirmed, the diagnostic says so: recovery may still consume a
stall allowance, and side effects may need inspection before retrying. This does
not impose memory limits on individual jobs or automatically replay failed work.

Situation Behavior
Installation cannot safely run jobs Processing is blocked; repair and explicitly restart the owner.
Database connection is temporarily unavailable Existing retry and backoff behavior remains active.
Supervisor is alive but not processing Status reports readiness, startup stage and next retry separately from process liveness.
Shutdown or job release cannot be confirmed Report the uncertainty; do not claim the job was safely returned.

To take advantage of v0.59.3.0

Run gbrain upgrade, verify the worker and any GBRAIN_JOB_CHILD_CLI override point
to the intended installation, and restart the affected supervisor or autopilot
service. Use gbrain jobs supervisor status --json or
gbrain autopilot --status --json to inspect processing_ready and
processing_state; processing_stage and retry_at explain a startup wait.
A live process alone does not establish progress.
The worker recovery guide covers each installation
and service owner. Inspect already failed jobs individually before retrying them.
An older supervisor keeps running upgraded workers until you restart it, but to roll a
worker back below v0.59.3.0, stop its v0.59.3.0 owner first; otherwise the owner's
120-second startup deadline keeps restarting the older worker.

Itemized changes

  • Bundle the cancellation-capable Postgres driver and share its runtime capability
    check with doctor and startup readiness.
  • Preserve typed configuration failures through database probes and job-child
    results; distinguish them from temporary connectivity failures.
  • Block both supervisor owners without a restart loop, retaining diagnostics and
    explicit repair/restart recovery. Keep the existing soft and hard crash budgets.
  • Fence delayed job release on ownership and actual execution settlement; bound
    shutdown work and report unconfirmed cleanup instead of silently consuming jobs.
  • Validate selected child compatibility, bound handshake output and deadlines,
    and keep process-group cleanup active after a direct child exits.

v0.59.0.0

Choose a tag to compare

@github-actions github-actions released this 27 Sep 09:49
fdbc359

The LongMemEval reader now checks the evidence before giving its short answer.

When an answer depends on several old conversations, the benchmark reader now
briefly extracts the relevant facts and reasons over them before answering. A
matched study over 361 questions moved from 308 to 324 judged correct answers
with the same full sessions, dates and question text. A separate replication
using the published supporting sessions also found a gain from notes in both
natural language and JSON; changing the format to JSON alone did not help.
These are reader comparisons, not evidence that everyday gbrain think
improved. The full research record includes losses, ambiguous grades, and nine
notes responses that reached the original 512-token output limit.

How to use it

gbrain eval longmemeval DATASET --reader-mode notes --reader-max-tokens 1024 --judge --output notes.ndjson
gbrain eval longmemeval DATASET --reader-mode direct --judge --output direct.ndjson

The first command's reader settings are now the defaults. Direct keeps the
original prompt and 512-token cap, so existing baseline runs remain
reproducible. --reader-mode notes --reader-max-tokens 512 reproduces the
original treatment's output budget, but risks the same cutoffs. The larger
default cap is a mitigation, not a separately measured answer-quality gain. A
bounded nine-case replay of the prior cutoffs finished all nine naturally at
1024 tokens (445–603 output tokens), but did not remeasure answer accuracy.

What to watch

The reader still sees the same sanitized full conversations in the same order;
notes do not recover facts missing from retrieval. Output-limit, empty and
unknown completions now record an error and preserve any partial text only as
a diagnostic. They cannot be judged as complete answers or silently inflate
accuracy. Receipts pin the reader mode, prompt, model, output budget and finish
reason; resume rejects a different reader configuration even with the
retrieval-mixing override. Paid reader and judge calls remain opt-in.

To take advantage of v0.59.0.0

gbrain upgrade should apply the update. If it reports a partial migration or
gbrain doctor flags one, run gbrain apply-migrations --yes --no-autopilot-install
and then gbrain doctor. Read skills/migrations/v0.59.0.0.md for the
reader-default comparison boundary and verify the flags with
gbrain eval longmemeval --help. No database migration or new model key is
required; running a judged benchmark still needs its configured providers.

Itemized changes

Added

  • Add a shared LongMemEval reader config and request builder with explicit
    direct|notes selection and output budget flags, plus per-row and summary
    configuration pins and strict resume checks. The stable package subpath
    gbrain/eval/longmemeval/reader lets companion evaluation tools use the
    same request builder instead of copying prompts. Existing invocation-guard
    and canonical-pricing modules are also exported through stable package
    subpaths so a capped companion evaluator can reuse the real cost controls.
  • Preserve original transfer and oracle comparison receipts, negative excerpt
    experiments, source audits and the primary-study compendium under docs/eval/
    and docs/research/, without promoting the experimental selector.

Fixed

  • Retain all provider text blocks and any incomplete partial text separately
    from a completed hypothesis. Output-limit, empty and unknown completions are
    recorded as failed reader rows, kept in the judged denominator, and fail the
    benchmark instead of passing a partial answer to the judge.
  • In the inactive experimental excerpt runner, future incomplete reader
    responses also stop before judging rather than entering a completed pair;
    historical records and results remain untouched.

v0.58.1.0

Choose a tag to compare

@github-actions github-actions released this 26 Sep 19:18
73a76dd

Spend less time rebuilding test fixtures without dropping database coverage.

Contributors can check the same behavior with less repeated setup. Shared
database checks keep their local and server-backed coverage, but no longer
repeat the local half inside the server-backed lane. Ordinary database resets
reuse an already-current migration history; tests of migration behavior still
replay it explicitly.

The complete nightly database collection now runs across four independent
workers. A final check requires every expected file to be accounted for once,
on the same revision, before accepting the run. Cancelled workers cannot report
success, and one coverage run cannot overwrite another run's output.

This release changes test infrastructure, not your stored memories or normal
GBrain commands. It does not enable paid-provider tests or reduce the sustained
durability workload.

For contributors

Run the complete local gate with bun run ci:local. To exercise the complete
scheduled coverage profile on demand, dispatch the E2E workflow with
full_corpus=true; ordinary dispatches keep their existing scope.

Work What changes What stays covered
Shared database contracts Each backend has its own execution owner Both PGLite and PostgreSQL assertions
Database setup Current migration history survives ordinary resets Explicit cold replay, cleanup and embedding identity
Large fixtures Reuse setup and analyze the original seeded data Original sizes, assertions and performance thresholds
Nightly database checks Four isolated workers with exact file receipts The complete discovered collection

The matched sequential E2E benchmark on the audited baseline 31f257a improved from
43m05.91s to 37m48.30s, a 12.28% reduction. Both timing runs retained the same
two host-environment failures; they are timing evidence, not passing gates.
The integrated changes separately passed the complete clean Docker gate.
The four-worker nightly benefit is not yet measured, and a 50% reduction in
overall test time is not established.

To take advantage of v0.58.1.0

No database migration, service change or user configuration is required.
Contributors should use the updated runners and the coverage ownership guidance
in Testing.

Itemized changes

  • Select PostgreSQL before registering shared E2E suites, retaining local-only
    cases in their unit owners and refusing missing or unsafe test databases.
  • Preserve the migration ledger and stored embedding identity during ordinary
    fixture resets. Explicit legacy-width setup aligns both columns and identity.
  • Reuse the embedded admin fixture, batch configured-root fixtures, and analyze
    dense graph and entity-card data without shrinking their workloads.
  • Validate native test reports, cancellation status, exclusive coverage roots
    and exact same-revision nightly execution receipts.
  • Refresh full-profile scheduling weights from complete recorded runs and
    document the separate unit, integration, durability and native coverage owners.

v0.57.0.0

Choose a tag to compare

@github-actions github-actions released this 25 Sep 13:20
16e10d8

Know when an accepted write needs attention.

An accepted write is not always a finished write. When a page or remembered fact is waiting, its receipt can now distinguish ordinary pending work from a known blocker or an unusually old request. Your agent gets a sensible polling interval and a clear instruction to inspect the existing owner when waiting alone is no longer enough. It keeps the original request reference instead of creating a duplicate.

Locked expired work no longer holds up the entire scheduler while unrelated work could proceed. Slow preparation and supported database waits have deadlines, and repeated receipt waits no longer accumulate unfinished reads. A deadline does not turn a pending write into a successful save or authorize another publisher. Work that cannot actually be cancelled stays tracked until it settles, and shutdown keeps the existing safety protections in place. Once contention clears, the original accepted request can finish without losing its identity or applying its content twice.

How to check a pending write

Keep the original request_id and arguments. Read its receipt, then inspect the selected brain's existing owner when advised:

gbrain write-request <request-id> --json
gbrain sources writer status --brain <brain> --probe --json
What the receipt knows What to do
Recent request, no known blocker Poll after 1 second, then 5 seconds as it ages.
Ordinary contention or an earlier write Retain the original request and poll after 5 seconds.
At least two minutes old, or an operator-required blocker Inspect the existing owner; poll no faster than every 30 seconds.

Age is advisory, not proof of a dead owner. Older clients may omit the optional diagnosis. Never remove locks, transfer ownership, or discard recovery records just because a request is old.

To take advantage of v0.57.0.0

Use gbrain upgrade during your approved owner rollout. If automatic migrations did not complete, run:

gbrain apply-migrations --yes --no-autopilot-install
gbrain sources writer status --brain <brain> --probe --json
gbrain stats

Schema migration 165 adds an index for database-only pending writes. It does not rewrite accepted requests or change the writer protocol. Quiesce the existing owner before replacing or rolling it back, preserve original receipts and recovery state, and verify canonical page or fact readback before calling a deployed incident recovered. If migration or verification fails, report sanitized doctor output and the failing step at https://github.com/garrytan/gbrain/issues; do not include credentials or private content.

Itemized changes

  • Pending receipts include validated, privacy-filtered age, assessment, reason and next action. Initial responses, replay, receipt helpers and frozen memory verbs preserve their existing required fields and error codes.
  • Receipt health enrichment is authorization-first, batched for at most 100 receipts, bounded to a 500ms caller wait, and limited to one unsettled query per engine. The new pending index keeps retained terminal history out of this lookup.
  • Expired-claim sweeps skip locked rows without bypassing same-root order. Supported scheduler and renewal waits use cancellation budgets; ordinary put_page and remember preparation gets a cooperative deadline with late-result fencing.
  • PostgreSQL timeout cancellation isolates the affected query from neighboring work, including transaction siblings and connections reassigned after a disconnect. Cancellation failures do not authorize blind statement retries.
  • PostgreSQL pool shutdown rejects work still waiting for a connection instead of silently reconnecting after shutdown. Recognized shutdown cancellations no longer appear as resident storage failures.
  • Trusted writer status exposes process-local phases, deadlines and attempts, with inspection advice consistent with receipt health. Operator guidance distinguishes observation from recovery authority and local tests from live recovery.

v0.54.1.0

Choose a tag to compare

@github-actions github-actions released this 24 Sep 05:54
6fe1444

Your brain has safer repairs and working managed-memory paths.

Keeping a brain current should not require guessing whether a note was saved,
whether a background job is stuck, or whether a backup can actually be read.
This release names blocked work and provides deliberate recovery steps. Health
checks report proposed repairs instead of executing them, and forced migration
previews no longer change the database or migration history.

Managed brains can extract facts into existing entity pages, create atoms,
import Google and GitHub content, and run the supported local synthesis,
patterns and consolidation paths without bypassing their writer protections.
Accepted extraction output can be replayed without another model call. Missing
search data has a separate, preview-first repair with an explicit source and
cost limit. Failed embedding work stops after bounded attempts instead of
retrying forever.

Backup status now distinguishes a configured destination from a recently
verified remote copy. OpenClaw startup and current-turn context handling are
also corrected, and new Apple-silicon release binaries receive a signature
check before execution and publication.

How to inspect before repairing

gbrain sources writer status --json
gbrain backup check --json
gbrain embed --stale --facts --source source-example --dry-run --json

Replace the example source with the one you intend to inspect. None of these
commands authorizes an ownership transfer or a paid repair.

Situation What you can now see or do
A managed sync file fails Inspect the source, file, receipt and pinned run, then explicitly retry the corrected input.
An embedding effect exhausts its retries Reconcile already-complete vectors or authorize one additional bounded cycle for the original request.
A backup destination disappears See failed or unknown evidence instead of treating configuration as a verified backup.

Things to watch

Stop and drain older writers before upgrading a managed deployment, then
restart its owners and workers together. PGLite inline maintenance still needs
exclusive access: gracefully stop its owner/supervisor, complete the local job,
then restart it. Live fact extraction and fact-vector repair have resident IPC
routes; this is not live-owner delegation for every dream command.

Only the named managed paths are restored. Legacy cycle fence reconciliation,
bulk conversation extraction/backfill and Google loop extraction refuse before
provider work. Private facts are not promoted by managed consolidation. Git
verification covers committed files, not a complete database restore. Native
macOS 26.2 checks passed; macOS 27 certification, native Windows backup behavior
and the reported aged-store reindex hang remain separate verification limits.

To take advantage of v0.54.1.0

Follow the managed-upgrade and recovery instructions.
The new repair commands are opt-in; upgrading does not approve a backfill,
ownership change, service installation or model spend. Existing OpenClaw users
must inspect the context-engine slot and use gbrain-context-engine on current
hosts. Keep the original installation and a verified full backup until the
upgraded owner has reopened and the scoped readback checks pass.

Itemized changes

  • Managed writer administration normalizes large counters before IPC, adds
    reviewed same-owner recovery for device/marker drift, identifies incomplete
    onboarding, and allows explicit exact dead-local-lock cleanup without a
    timeout-based takeover.
  • Managed sync records durable, deduplicated failure evidence, preserves
    unfinished cursors, reports it through CLI/doctor, and performs explicit
    fresh admission without mutating terminal receipts or hiding another run.
  • Coordinated fact/atom publication retains source authority, private
    visibility, accepted output and completion receipts. Named local maintenance
    retains publication results and consolidates semantic evidence atomically;
    retired takes leave facts unconsolidated.
  • Google/GitHub connectors use guarded imports, deletion and checkpoint CAS.
    Unbound API sources explicitly publish to the database; bound sources retain
    canonical file publication. Restarted sync recovers retained publication;
    explicit --retry-failed replaces a failed attempt without changing its old
    receipt or resetting the API bookmark. Google embedding requests respect the
    100-item provider limit.
  • Fact reconciliation preserves valid existing vectors on failed embedding
    and cancellation while retaining privacy/withdrawal changes. Explicit
    null-vector backfill validates source, model, row version, selected-brain
    policy and budget before installing projections.
  • Embedding effects check actual vector provenance, avoid re-embedding complete
    chunks, retain lifetime attempt accounting, and atomically complete vectors
    with their effect. Readback and explicit retry remain source/authority-bound.
  • Backup checks use bounded, rotating remote-ref readback and expiring evidence.
    Directory durability uses the narrow Windows error guard without swallowing
    regular-file or unexpected I/O failures.
  • Retrieval output reuses the canonical credential scanner without changing
    ranking or opaque identity. This is bounded display hygiene, not a guarantee
    about all secret formats or earlier provider/evaluation inputs.
  • OpenClaw supports zero-argument factories, canonical slot registration and
    separate current-turn prompts. Release executables use Bun 1.4.2; required
    native checks retain older runtimes and add real pinned-host startup coverage.
  • Forced previews are read-only, failed migration phases remain retryable, and
    installer fixtures no longer overwrite live autopilot files. A detection
    guard reports accidental real-home changes during tests.

Contributed by @olivershe (garrytan#5171), @javieraldape (garrytan#5220), @sheelcheyne (garrytan#5000),
@haumanto (garrytan#5132), @thiagosian (garrytan#5201), @Masashi-Ono0611 (garrytan#5314, garrytan#5352, garrytan#5355),
@VXNCXNX (garrytan#5322), @Mr-B-1 (garrytan#4867), @turian (garrytan#5305),
@rokas-tarasevicius (garrytan#5287), and @lubosxyz (garrytan#5348). Their focused contributions
were adapted to the current persistence and source-identity contracts.

v0.53.0.0

Choose a tag to compare

@github-actions github-actions released this 23 Sep 13:52
976cff5

Keep what your agents know and how they work in the same brain. New local brains now create a content directory containing both knowledge and useful memory skills. Connected agents can discover the same published instructions instead of maintaining unrelated copies. An explicitly authorized editor can update a skill once, and other connections can fetch the same committed version, including its approved supporting files.

Connecting a managed coding agent also installs an owned brain router in its skill directory. Claude Code, Codex and opencode still need a restart, and an installed file is not proof that a native session used it. Other clients receive portable discovery and clear instructions when their own enablement controls are required.

Existing brains are not silently made more public. Previously approved instruction sharing remains prose-only. Personal edits are preserved, and permission to write memories does not grant permission to rewrite shared skills or execute downloaded scripts.

How to use it

New host grants follow published skills by default; choose --skills memory-only to opt out. Existing grants stay unchanged unless explicitly updated. Use list_skills with schema_version: 2, then fetch the chosen qualified skill and revision with get_skill. Shared editors additionally require skill_editor and an explicit operation grant.

Situation What happens
Fresh local initialization Knowledge and packaged memory skills share a recorded content root. Git is optional.
Another agent updates a skill Readers fetch the new complete revision; conflicting edits are rejected.
An old brain is upgraded A staged migration records content, ownership and client actions without overwriting edits or expanding disclosure.
A client cannot check freshness Enforced adapter admission blocks stale use; advisory native integrations do not claim stronger guarantees.

To take advantage of v0.53.0.0

  1. Run gbrain upgrade, then inspect gbrain apply-migrations --dry-run --json.
  2. On an existing file-backed brain, stop older writers and skill-serving processes, review writer status, and follow the migration checklist's state-bound claim and activation steps. Shared-skill activation requires explicit administration intent and the reviewed state; quiescence alone is not authority. Re-run gbrain apply-migrations --yes to finish eligible mechanical stages.
  3. Read skills/migrations/v0.53.0.0.md for explicit follow grants, DB-only export, local conflicts and verification. Reconnect each intended harness; do not count disconnected or native-unverified clients as finished.
  4. See shared brain skills for scoped editing, disclosure policy, exact-version retrieval and recovery. Keep an operational database backup: Git content does not contain grants, delivery receipts or revocation history.

Itemized changes

  • Add source-qualified sealed skill revisions, bounded approved assets, compare-and-swap publication and durable replay through the canonical writer. Schema migration 164 adds the catalog, enrollment records and protocol guards.
  • Add join_brain, sync_brain_skills, leave_brain, put_skill, delete_skill, get_skill_asset and set_skill_policy, with explicit named capabilities and source/operation fences. Discovery joins the starter surface; the seven memory verbs remain unchanged.
  • Serve shared skill resources through the same authorized operations. Existing catalog clients receive compatible prose envelopes after canonical adoption.
  • Install namespaced, ownership-tracked routers and immutable local revision caches, with separate transport, artifact and native-use status. Preserve edited files on update and removal.
  • Add staged combined-content migration, compile-safe default memory skills and explicitly approved DB-only content export with round-trip checks. Existing publishing opt-outs, private files and grant ceilings survive upgrades.
  • Keep fresh-install upgrades compatible with canonical files: grandfathering uses durable metadata publication, preserves existing search projections and vectors, and does not enqueue embedding or fact-extraction work for the compatibility flag.

v0.52.2.0

Choose a tag to compare

@github-actions github-actions released this 23 Sep 05:15
b272cf2

Repair a memory page without guessing which copy to overwrite. GBrain keeps
your notes in files and in its database. When those copies disagree, saving a new
memory can stop even though the file looks unchanged in Git. You can now compare
one exact page, preserve both originals, choose between conflicting fields, and
save the reviewed result through the existing safe writer. Information found on
only one side is kept rather than quietly discarded.

The repair checks again before saving. If another writer changed the page, file,
or owner while you were reviewing it, GBrain stops and asks for a fresh preview.
Interrupted saves recover through the same durable request, and retrying a
completed request does not apply it twice. After repair, retry your original
memory request separately and read back what was actually saved.

Background atom scanning now keeps its progress outside your note's metadata, so
a scan no longer creates a new disagreement just by recording that it finished.
Failed saves and syncs identify their page, specific reason, and durable request
instead of leaving you with a misleading permission error or an unnamed failed
file. Unsupported managed atom extraction stops before spending on a model.

Say to your agent: "Preview this page's file/database disagreement, preserve
both originals, and show me the conflicts before repairing it. Then retry my
memory request and verify the fact, visibility, and provenance."

How to use it

gbrain sources reconcile workspace people/example --brain host --preview --json
gbrain sources reconcile workspace --brain host --audit --limit 25 --json
gbrain sources reconcile --help

Use --out <new-private-file> to keep an actionable preview, resolve conflicting
fields with explicit decisions, then apply the reviewed artifact with a retained
request UUID. The complete flow is in docs/guides/concurrent-writes.md.

Situation What happens now
Each copy has different additional metadata Both sets of fields survive.
The same field has conflicting values You choose explicitly; timestamps do not pick a winner.
A preview became stale Apply refuses without overwriting either copy.
A save was interrupted Retry its original UUID; inspect the durable receipt.

Things to watch

Repair requires an existing valid owner and trusted local CLI registration. It
works before or after managed activation but never claims, transfers, activates,
or changes source checkpoints. Private backups consume bounded local storage and
remain until explicitly removed. Forgotten active facts can still exist in that
history. This does not migrate every legacy maintenance writer to managed mode.

To take advantage of v0.52.2.0

gbrain upgrade should apply migration 163 automatically. If it did not, run
gbrain apply-migrations --yes, then restart upgraded resident writers and
maintenance workers. Follow skills/migrations/v0.52.2.0.md; use a read-only audit
and an exact-page preview before any repair. No automatic bulk merge, ownership
change, activation, or paid enrichment is required.

Itemized changes

  • Add trusted-local sources reconcile preview, decision resolution, guarded
    apply, bounded audit, and retained-backup inspection/removal. Existing
    overwrite guards and frozen memory-verb error codes remain intact.
  • Reuse the persistence journal and coordinator for revision/raw-byte/owner/policy
    checks, same-ID replay, durable preimages, and interrupted-publication recovery.
  • Migration 163 adds source-incarnation/page/hash-keyed atom processing state with
    conservative legacy backfill. Canonical pages are not rewritten by migration.
    Partial atom publication still remains retryable until all provenance is saved.
  • Preserve identical generated safety assessments across repeated imports, while
    keeping safety fields and policy checks in canonical comparisons.
  • Report managed sync failures from their authoritative receipts, including
    resident-owner JSON, even when the local failure ledger is missing or unwritable.
    The ledger call-site fix is adapted from garrytan#5314. Contributed by @Masashi-Ono0611.
  • Add real-engine reconciliation, scoped-authority, concurrent-replay, privacy,
    retained-backup, bounded-audit, real-owner CLI, and process-kill regression tests.