npm publish --provenance failed with E422: the registry compares
package.json repository.url against the OIDC provenance claim
BYTE-FOR-BYTE. "holetron-lab" vs GitHub-canonical "Holetron-lab"
is a hard reject, not cosmetics. Do not lowercase these again.
Also drops the "./" from bin — npm rewrites it on publish anyway
and prints a warning that reads like the bin was dropped.
- name: io.github.holetron-lab/fleet-memory -> ai.rcll/fleet-memory
DNS-verified namespace on a domain we renew ourselves. The io.github.*
namespace is authorised by a GitHub account; io.github.holetron died with
a suspended account and is unrecoverable. Do not repeat that exposure.
- description: 176 -> 95 chars. ServerDetail.description has maxLength 100;
the previous value would have been rejected at publish time.
- repository.id: pinned to GitHub repo id 1344503808 (resurrection-attack
guard - the id changes if a repo is deleted and recreated).
- repository.url stays on github.com: the registry validator hard-matches
^https?://(www\.)?github\.com/... or gitlab.com and rejects anything
else, so the canonical forge URL cannot go in this field. rcll.ai carries
it instead (websiteUrl), and the site names the forge as canonical.
- mcp-server/package.json mcpName must equal the server name exactly; the
registry reads it from the PUBLISHED npm version metadata, so this had to
change before the first publish, not after.
The repository, the npm package and the container image are now
fleet-memory; RCLL stays the product and documentation brand (rcll.ai).
- server.json / package.json: io.github.holetron-lab/fleet-memory,
npm identifier fleet-memory-mcp
- env chain is two names, not three: FLEET_URL/FLEET_BANK with the
pre-rebrand HINDSIGHT_URL/MEMPALACE_BANK still read as a fallback.
RCLL_URL/RCLL_BANK and bank rcll-main never shipped — nothing was
published under rcll-mcp — so they are dropped rather than carried.
- default bank is fleet-main; hindsight-mempalace-mcp@1.0.0 users are
told on stderr that their memory is in mempalace-main
- rooms are described as topic scoping over one shared store, not
per-agent isolation: the read path filters on the room list the
caller passes and has no notion of caller identity
The default memory bank becomes 'rcll-main'. hindsight-mempalace-mcp@1.0.0 (published,
~145 downloads/month) defaulted to 'mempalace-main', so an install that never set the
variable and switches packages would open a different, empty bank. MEMPALACE_BANK is
still honoured, and when neither variable is set the server now prints which bank it
picked and how to keep reading the old one, instead of choosing silently.
rcll-split.py moves to scripts/ — it documents how the fork series was built, which
is not a root-level artifact of the product.