Commit graph

7 commits

Author SHA1 Message Date
RCLL
77ea122dc9 fix(npm): canonical GitHub org case in repository.url — npm rejects provenance on case mismatch
npm publish --provenance failed with E422: the registry compares
package.json repository.url against the OIDC provenance claim
BYTE-FOR-BYTE. "holetron-lab" vs GitHub-canonical "Holetron-lab"
is a hard reject, not cosmetics. Do not lowercase these again.

Also drops the "./" from bin — npm rewrites it on publish anyway
and prints a warning that reads like the bin was dropped.
2026-08-28 15:33:53 +03:00
RCLL
9b05decc2a chore(registry): move MCP namespace to ai.rcll, fix schema violations before first publish
- name: io.github.holetron-lab/fleet-memory -> ai.rcll/fleet-memory
  DNS-verified namespace on a domain we renew ourselves. The io.github.*
  namespace is authorised by a GitHub account; io.github.holetron died with
  a suspended account and is unrecoverable. Do not repeat that exposure.
- description: 176 -> 95 chars. ServerDetail.description has maxLength 100;
  the previous value would have been rejected at publish time.
- repository.id: pinned to GitHub repo id 1344503808 (resurrection-attack
  guard - the id changes if a repo is deleted and recreated).
- repository.url stays on github.com: the registry validator hard-matches
  ^https?://(www\.)?github\.com/... or gitlab.com and rejects anything
  else, so the canonical forge URL cannot go in this field. rcll.ai carries
  it instead (websiteUrl), and the site names the forge as canonical.
- mcp-server/package.json mcpName must equal the server name exactly; the
  registry reads it from the PUBLISHED npm version metadata, so this had to
  change before the first publish, not after.
2026-08-27 09:19:57 +03:00
RCLL
7fca442903 chore(mcp-server): npm storefront metadata before the first publish
Published package metadata cannot be changed without shipping another
version, so this has to land before 0.1.0 goes out, not after.

- repository/homepage/bugs were all missing: the npm page would have
  rendered with no link back to the source at all. repository names the
  GitHub mirror deliberately — npm tooling and the --provenance
  attestation are keyed to the repo the workflow builds in; the canonical
  repository is stated in the README instead.
- README is the npm page body. Its Quick Start opened with `cd
  mcp-server && npm install`, which is the from-a-clone path — the one
  instruction that cannot work for somebody who just installed the
  package. `npx fleet-memory-mcp` first, clone path kept below it, and a
  line saying this package is the client half and does not start a store.
- LICENSE was not in the tarball. MIT text now ships with the artifact,
  Vectorize AI copyright intact.
- engines and an explicit files list, so the tarball contents are stated
  rather than inferred.
2026-08-26 10:30:03 +03:00
RCLL
adce870665 chore: name the artifact fleet-memory, keep RCLL as the product name
The repository, the npm package and the container image are now
fleet-memory; RCLL stays the product and documentation brand (rcll.ai).

- server.json / package.json: io.github.holetron-lab/fleet-memory,
  npm identifier fleet-memory-mcp
- env chain is two names, not three: FLEET_URL/FLEET_BANK with the
  pre-rebrand HINDSIGHT_URL/MEMPALACE_BANK still read as a fallback.
  RCLL_URL/RCLL_BANK and bank rcll-main never shipped — nothing was
  published under rcll-mcp — so they are dropped rather than carried.
- default bank is fleet-main; hindsight-mempalace-mcp@1.0.0 users are
  told on stderr that their memory is in mempalace-main
- rooms are described as topic scoping over one shared store, not
  per-agent isolation: the read path filters on the room list the
  caller passes and has no notion of caller identity
2026-08-24 10:50:24 +03:00
RCLL
0af516ae69 fix(mcp): enforce recall limit, align server version, scope the client claim
Three things found by actually running the server over stdio against a live backend
instead of describing it.

1. recall ignored 'limit'. The backend treats it as a retrieval hint and returns
   everything inside its own token budget — 113 facts, 43 KB of JSON, for a request
   that asked for 2. The tool's own description ('Max results') was therefore false,
   and every recall spent roughly 10k tokens of the caller's context. The MCP layer
   now enforces the requested limit and reports 'N of M' when it truncated:
   limit=2 goes from 43541 to 1000 chars.

2. serverInfo.version said 1.0.0 while package.json and server.json say 0.1.0. The
   MCP registry validates the resolved package against the manifest, so a version
   that disagrees with the tarball is a review failure.

3. The README claimed 'Claude Code, OpenClaw, Cursor, etc.' None of those was tested.
   Replaced with what was measured — MCP 2025-06-18, initialize/tools/list/tools/call
   round-trip, memory_recall returning real results over stdio — plus the Claude Code
   config we actually run.
2026-08-24 08:46:24 +03:00
RCLL
45c1a3c633 chore: default bank rcll-main, announce it, move split tool out of the root
The default memory bank becomes 'rcll-main'. hindsight-mempalace-mcp@1.0.0 (published,
~145 downloads/month) defaulted to 'mempalace-main', so an install that never set the
variable and switches packages would open a different, empty bank. MEMPALACE_BANK is
still honoured, and when neither variable is set the server now prints which bank it
picked and how to keep reading the old one, instead of choosing silently.

rcll-split.py moves to scripts/ — it documents how the fork series was built, which
is not a root-level artifact of the product.
2026-08-24 08:28:28 +03:00
RCLL
d2f74c5126 feat(mcp): RCLL MCP server and MCP-registry manifest
Recovered from the 2026-06-27 snapshot import by classifying the base..snapshot delta at line granularity. Upstream base: d054b884 (2026-04-10).
2026-08-23 23:50:03 +03:00