* feat: ai sdk integration * more fixes * fix(security): mental model refresh tag-based security - Mental model refresh now passes tags with all_strict matching - Consolidation only triggers refresh for mental models with matching tags - Consolidation filters related observations by tags (all_strict) - Added tests to verify tag-based security boundaries - Updated OpenAPI spec to include tags and text_preview in list_documents - Added tags column to documents UI table * chore: regenerate OpenAPI spec after rebase * fix: improve consolidation prompt for contradiction handling and mental model refresh security - Enhanced consolidation prompt to be more explicit about capturing temporal changes in contradictions - Fixed mental model refresh security: tagged memories now only trigger refresh of mental models with matching tags - Added stricter tag filtering to prevent cross-scope mental model refreshes Fixes test_consolidation_merges_contradictions by improving LLM instructions to use temporal markers like "used to X, now Y" when merging contradictory facts. Note: test_refresh_with_tags_only_accesses_same_tagged_models still needs investigation - REFLECT operation may need additional tag filtering. * fix: mental model refresh security - proper tag filtering in search Fixed tool_search_mental_models to properly handle all_strict tag matching mode by using the centralized build_tags_where_clause function. Previously, the function only handled "all" vs "any" modes and always included untagged mental models when using non-"all" modes. This ensures that when a tagged mental model is refreshed with all_strict matching, it cannot access untagged mental models, preventing cross-scope information leakage. Fixes test_refresh_with_tags_only_accesses_same_tagged_models. Note: test_sensory_dimension_preservation is failing but this is a pre-existing issue on main branch - the LLM model (gpt-oss-20b) is not extracting facts from sensory text. Not related to security changes. * chore: apply formatting from pre-commit hook * fix: allow untagged mental models to be refreshed by any consolidation Untagged mental models are considered "global" and should be refreshed by any consolidation, regardless of whether tagged or untagged memories were consolidated. This maintains security boundaries while allowing global mental models to stay fresh. When tagged memories are consolidated: - Refresh mental models with matching tags (security boundary) - Also refresh untagged mental models (they're global) - DO NOT refresh mental models with different tags When untagged memories are consolidated: - Only refresh untagged mental models - DO NOT refresh tagged mental models (security boundary) Fixes test_consolidation_only_refreshes_matching_tagged_models.
565 lines
16 KiB
YAML
565 lines
16 KiB
YAML
name: Release
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- 'v*'
|
|
|
|
jobs:
|
|
release-python-packages:
|
|
runs-on: ubuntu-latest
|
|
environment: pypi
|
|
permissions:
|
|
id-token: write
|
|
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@v5
|
|
with:
|
|
enable-cache: true
|
|
|
|
- name: Set up Python
|
|
uses: actions/setup-python@v5
|
|
with:
|
|
python-version-file: ".python-version"
|
|
|
|
# Build all packages
|
|
- name: Build hindsight-client
|
|
working-directory: ./hindsight-clients/python
|
|
run: uv build --out-dir dist
|
|
|
|
- name: Build hindsight-api
|
|
working-directory: ./hindsight-api
|
|
run: uv build --out-dir dist
|
|
|
|
- name: Build hindsight-all
|
|
working-directory: ./hindsight
|
|
run: uv build --out-dir dist
|
|
|
|
- name: Build hindsight-litellm
|
|
working-directory: ./hindsight-integrations/litellm
|
|
run: uv build --out-dir dist
|
|
|
|
- name: Build hindsight-embed
|
|
working-directory: ./hindsight-embed
|
|
run: uv build --out-dir dist
|
|
|
|
# Publish in order (client and api first, then hindsight-all which depends on them)
|
|
- name: Publish hindsight-client to PyPI
|
|
uses: pypa/gh-action-pypi-publish@release/v1
|
|
with:
|
|
packages-dir: ./hindsight-clients/python/dist
|
|
skip-existing: true
|
|
|
|
- name: Publish hindsight-api to PyPI
|
|
uses: pypa/gh-action-pypi-publish@release/v1
|
|
with:
|
|
packages-dir: ./hindsight-api/dist
|
|
skip-existing: true
|
|
|
|
- name: Publish hindsight-all to PyPI
|
|
uses: pypa/gh-action-pypi-publish@release/v1
|
|
with:
|
|
packages-dir: ./hindsight/dist
|
|
skip-existing: true
|
|
|
|
- name: Publish hindsight-litellm to PyPI
|
|
uses: pypa/gh-action-pypi-publish@release/v1
|
|
with:
|
|
packages-dir: ./hindsight-integrations/litellm/dist
|
|
skip-existing: true
|
|
|
|
- name: Publish hindsight-embed to PyPI
|
|
uses: pypa/gh-action-pypi-publish@release/v1
|
|
with:
|
|
packages-dir: ./hindsight-embed/dist
|
|
skip-existing: true
|
|
|
|
# Upload artifacts for GitHub release
|
|
- name: Upload artifacts
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: python-packages
|
|
path: |
|
|
hindsight-clients/python/dist/*
|
|
hindsight-api/dist/*
|
|
hindsight/dist/*
|
|
hindsight-integrations/litellm/dist/*
|
|
hindsight-embed/dist/*
|
|
retention-days: 1
|
|
|
|
release-typescript-client:
|
|
runs-on: ubuntu-latest
|
|
environment: npm
|
|
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Set up Node.js
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: '20'
|
|
registry-url: 'https://registry.npmjs.org'
|
|
cache: 'npm'
|
|
cache-dependency-path: package-lock.json
|
|
|
|
- name: Install dependencies
|
|
run: npm ci --workspace=hindsight-clients/typescript
|
|
|
|
- name: Build
|
|
run: npm run build --workspace=hindsight-clients/typescript
|
|
|
|
- name: Publish to npm
|
|
working-directory: ./hindsight-clients/typescript
|
|
run: |
|
|
set +e
|
|
OUTPUT=$(npm publish --access public 2>&1)
|
|
EXIT_CODE=$?
|
|
echo "$OUTPUT"
|
|
if [ $EXIT_CODE -ne 0 ]; then
|
|
if echo "$OUTPUT" | grep -q "cannot publish over"; then
|
|
echo "Package version already published, skipping..."
|
|
exit 0
|
|
fi
|
|
exit $EXIT_CODE
|
|
fi
|
|
env:
|
|
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|
|
|
|
- name: Pack for GitHub release
|
|
working-directory: ./hindsight-clients/typescript
|
|
run: npm pack
|
|
|
|
- name: Upload artifacts
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: typescript-client
|
|
path: hindsight-clients/typescript/*.tgz
|
|
retention-days: 1
|
|
|
|
release-openclaw-integration:
|
|
runs-on: ubuntu-latest
|
|
environment: npm
|
|
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Set up Node.js
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: '22'
|
|
registry-url: 'https://registry.npmjs.org'
|
|
|
|
- name: Install dependencies
|
|
working-directory: ./hindsight-integrations/openclaw
|
|
run: npm ci
|
|
|
|
- name: Build
|
|
working-directory: ./hindsight-integrations/openclaw
|
|
run: npm run build
|
|
|
|
- name: Publish to npm
|
|
working-directory: ./hindsight-integrations/openclaw
|
|
run: |
|
|
set +e
|
|
OUTPUT=$(npm publish --access public 2>&1)
|
|
EXIT_CODE=$?
|
|
echo "$OUTPUT"
|
|
if [ $EXIT_CODE -ne 0 ]; then
|
|
if echo "$OUTPUT" | grep -q "cannot publish over"; then
|
|
echo "Package version already published, skipping..."
|
|
exit 0
|
|
fi
|
|
exit $EXIT_CODE
|
|
fi
|
|
env:
|
|
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|
|
|
|
- name: Pack for GitHub release
|
|
working-directory: ./hindsight-integrations/openclaw
|
|
run: npm pack
|
|
|
|
- name: Upload artifacts
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: openclaw-integration
|
|
path: hindsight-integrations/openclaw/*.tgz
|
|
retention-days: 1
|
|
|
|
release-ai-sdk-integration:
|
|
runs-on: ubuntu-latest
|
|
environment: npm
|
|
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Set up Node.js
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: '22'
|
|
registry-url: 'https://registry.npmjs.org'
|
|
|
|
- name: Install dependencies
|
|
working-directory: ./hindsight-integrations/ai-sdk
|
|
run: npm ci
|
|
|
|
- name: Build
|
|
working-directory: ./hindsight-integrations/ai-sdk
|
|
run: npm run build
|
|
|
|
- name: Publish to npm
|
|
working-directory: ./hindsight-integrations/ai-sdk
|
|
run: |
|
|
set +e
|
|
OUTPUT=$(npm publish --access public 2>&1)
|
|
EXIT_CODE=$?
|
|
echo "$OUTPUT"
|
|
if [ $EXIT_CODE -ne 0 ]; then
|
|
if echo "$OUTPUT" | grep -q "cannot publish over"; then
|
|
echo "Package version already published, skipping..."
|
|
exit 0
|
|
fi
|
|
exit $EXIT_CODE
|
|
fi
|
|
env:
|
|
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|
|
|
|
- name: Pack for GitHub release
|
|
working-directory: ./hindsight-integrations/ai-sdk
|
|
run: npm pack
|
|
|
|
- name: Upload artifacts
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: ai-sdk-integration
|
|
path: hindsight-integrations/ai-sdk/*.tgz
|
|
retention-days: 1
|
|
|
|
release-control-plane:
|
|
runs-on: ubuntu-latest
|
|
environment: npm
|
|
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Set up Node.js
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: '20'
|
|
registry-url: 'https://registry.npmjs.org'
|
|
cache: 'npm'
|
|
cache-dependency-path: package-lock.json
|
|
|
|
- name: Install dependencies
|
|
run: npm ci
|
|
|
|
- name: Build TypeScript client (dependency)
|
|
run: npm run build --workspace=hindsight-clients/typescript
|
|
|
|
- name: Fix platform-specific native modules
|
|
run: |
|
|
# npm ci installs from lockfile which may have wrong platform binaries
|
|
# Delete hoisted native modules and reinstall for current platform
|
|
rm -rf node_modules/lightningcss node_modules/@tailwindcss
|
|
npm install lightningcss @tailwindcss/postcss @tailwindcss/node
|
|
|
|
- name: Build
|
|
run: npm run build --workspace=hindsight-control-plane
|
|
|
|
- name: Publish to npm
|
|
working-directory: ./hindsight-control-plane
|
|
run: |
|
|
set +e
|
|
OUTPUT=$(npm publish --access public 2>&1)
|
|
EXIT_CODE=$?
|
|
echo "$OUTPUT"
|
|
if [ $EXIT_CODE -ne 0 ]; then
|
|
if echo "$OUTPUT" | grep -q "cannot publish over"; then
|
|
echo "Package version already published, skipping..."
|
|
exit 0
|
|
fi
|
|
exit $EXIT_CODE
|
|
fi
|
|
env:
|
|
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|
|
|
|
- name: Pack for GitHub release
|
|
working-directory: ./hindsight-control-plane
|
|
run: npm pack
|
|
|
|
- name: Upload artifacts
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: control-plane
|
|
path: hindsight-control-plane/*.tgz
|
|
retention-days: 1
|
|
|
|
release-rust-cli:
|
|
runs-on: ${{ matrix.os }}
|
|
strategy:
|
|
matrix:
|
|
include:
|
|
- os: ubuntu-latest
|
|
target: x86_64-unknown-linux-gnu
|
|
artifact_name: hindsight
|
|
asset_name: hindsight-linux-amd64
|
|
- os: macos-latest
|
|
target: x86_64-apple-darwin
|
|
artifact_name: hindsight
|
|
asset_name: hindsight-darwin-amd64
|
|
- os: macos-latest
|
|
target: aarch64-apple-darwin
|
|
artifact_name: hindsight
|
|
asset_name: hindsight-darwin-arm64
|
|
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Install Rust
|
|
uses: dtolnay/rust-toolchain@stable
|
|
with:
|
|
targets: ${{ matrix.target }}
|
|
|
|
- name: Build
|
|
working-directory: hindsight-cli
|
|
run: cargo build --release --target ${{ matrix.target }}
|
|
|
|
- name: Prepare artifact
|
|
run: |
|
|
mkdir -p artifacts
|
|
cp hindsight-cli/target/${{ matrix.target }}/release/${{ matrix.artifact_name }} artifacts/${{ matrix.asset_name }}
|
|
chmod +x artifacts/${{ matrix.asset_name }}
|
|
|
|
- name: Upload artifacts
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: rust-cli-${{ matrix.asset_name }}
|
|
path: artifacts/${{ matrix.asset_name }}
|
|
retention-days: 1
|
|
|
|
release-docker-images:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
strategy:
|
|
matrix:
|
|
include:
|
|
- target: api-only
|
|
image_name: hindsight-api
|
|
- target: cp-only
|
|
image_name: hindsight-control-plane
|
|
- target: standalone
|
|
image_name: hindsight
|
|
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Free Disk Space
|
|
uses: jlumbroso/free-disk-space@main
|
|
with:
|
|
tool-cache: true
|
|
android: true
|
|
dotnet: true
|
|
haskell: true
|
|
large-packages: true
|
|
docker-images: true
|
|
swap-storage: true
|
|
|
|
- name: Set up QEMU
|
|
uses: docker/setup-qemu-action@v3
|
|
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@v3
|
|
|
|
- name: Log in to GitHub Container Registry
|
|
uses: docker/login-action@v3
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Extract version from tag
|
|
id: get_version
|
|
run: echo "VERSION=${GITHUB_REF#refs/tags/v}" >> $GITHUB_OUTPUT
|
|
|
|
- name: Extract metadata for release tags
|
|
id: meta
|
|
uses: docker/metadata-action@v5
|
|
with:
|
|
images: ghcr.io/${{ github.repository_owner }}/${{ matrix.image_name }}
|
|
tags: |
|
|
type=semver,pattern={{version}},value=${{ steps.get_version.outputs.VERSION }}
|
|
type=semver,pattern={{major}}.{{minor}},value=${{ steps.get_version.outputs.VERSION }}
|
|
type=semver,pattern={{major}},value=${{ steps.get_version.outputs.VERSION }}
|
|
type=raw,value=latest
|
|
|
|
# TODO: Re-enable smoke test when disk space issue is resolved
|
|
# # Step 1: Build for local testing (single platform, no push)
|
|
# # This creates an identical image to what will be released, just for one platform
|
|
# - name: Build image for testing
|
|
# uses: docker/build-push-action@v6
|
|
# with:
|
|
# context: .
|
|
# file: docker/standalone/Dockerfile
|
|
# target: ${{ matrix.target }}
|
|
# push: false
|
|
# load: true
|
|
# tags: ${{ matrix.image_name }}:test
|
|
# cache-from: type=gha
|
|
# cache-to: type=gha,mode=max
|
|
|
|
# # Step 2: Test the image before pushing anything
|
|
# - name: Smoke test - verify container starts
|
|
# env:
|
|
# GROQ_API_KEY: ${{ secrets.GROQ_API_KEY }}
|
|
# run: ./scripts/docker-smoke-test.sh "${{ matrix.image_name }}:test" "${{ matrix.target }}"
|
|
|
|
# Build multi-platform and push to release tags
|
|
- name: Build and push release images
|
|
uses: docker/build-push-action@v6
|
|
with:
|
|
context: .
|
|
file: docker/standalone/Dockerfile
|
|
target: ${{ matrix.target }}
|
|
push: true
|
|
platforms: linux/amd64,linux/arm64
|
|
tags: ${{ steps.meta.outputs.tags }}
|
|
labels: ${{ steps.meta.outputs.labels }}
|
|
|
|
release-helm-chart:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Install Helm
|
|
uses: azure/setup-helm@v4
|
|
with:
|
|
version: 'latest'
|
|
|
|
- name: Log in to GHCR
|
|
run: echo "${{ secrets.GITHUB_TOKEN }}" | helm registry login ghcr.io -u ${{ github.actor }} --password-stdin
|
|
|
|
- name: Lint Helm chart
|
|
run: helm lint helm/hindsight
|
|
|
|
- name: Package Helm chart
|
|
run: helm package helm/hindsight --destination ./helm-packages
|
|
|
|
- name: Push to GHCR OCI
|
|
run: helm push helm-packages/*.tgz oci://ghcr.io/${{ github.repository_owner }}/charts
|
|
|
|
- name: Upload artifacts
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: helm-chart
|
|
path: helm-packages/*.tgz
|
|
retention-days: 1
|
|
|
|
create-github-release:
|
|
runs-on: ubuntu-latest
|
|
needs: [release-python-packages, release-typescript-client, release-openclaw-integration, release-ai-sdk-integration, release-control-plane, release-rust-cli, release-docker-images, release-helm-chart]
|
|
permissions:
|
|
contents: write
|
|
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Extract version from tag
|
|
id: get_version
|
|
run: echo "VERSION=${GITHUB_REF#refs/tags/v}" >> $GITHUB_OUTPUT
|
|
|
|
- name: Download Python packages
|
|
uses: actions/download-artifact@v4
|
|
with:
|
|
name: python-packages
|
|
path: ./artifacts/python-packages
|
|
|
|
- name: Download TypeScript client
|
|
uses: actions/download-artifact@v4
|
|
with:
|
|
name: typescript-client
|
|
path: ./artifacts/typescript-client
|
|
|
|
- name: Download OpenClaw Integration
|
|
uses: actions/download-artifact@v4
|
|
with:
|
|
name: openclaw-integration
|
|
path: ./artifacts/openclaw-integration
|
|
|
|
- name: Download AI SDK Integration
|
|
uses: actions/download-artifact@v4
|
|
with:
|
|
name: ai-sdk-integration
|
|
path: ./artifacts/ai-sdk-integration
|
|
|
|
- name: Download Control Plane
|
|
uses: actions/download-artifact@v4
|
|
with:
|
|
name: control-plane
|
|
path: ./artifacts/control-plane
|
|
|
|
- name: Download Rust CLI (Linux)
|
|
uses: actions/download-artifact@v4
|
|
with:
|
|
name: rust-cli-hindsight-linux-amd64
|
|
path: ./artifacts/rust-cli-linux
|
|
|
|
- name: Download Rust CLI (macOS Intel)
|
|
uses: actions/download-artifact@v4
|
|
with:
|
|
name: rust-cli-hindsight-darwin-amd64
|
|
path: ./artifacts/rust-cli-darwin-amd64
|
|
|
|
- name: Download Rust CLI (macOS ARM)
|
|
uses: actions/download-artifact@v4
|
|
with:
|
|
name: rust-cli-hindsight-darwin-arm64
|
|
path: ./artifacts/rust-cli-darwin-arm64
|
|
|
|
- name: Download Helm chart
|
|
uses: actions/download-artifact@v4
|
|
with:
|
|
name: helm-chart
|
|
path: ./artifacts/helm-chart
|
|
|
|
- name: Prepare release assets
|
|
run: |
|
|
mkdir -p release-assets
|
|
# Python packages
|
|
cp artifacts/python-packages/hindsight-clients/python/dist/* release-assets/ || true
|
|
cp artifacts/python-packages/hindsight-api/dist/* release-assets/ || true
|
|
cp artifacts/python-packages/hindsight/dist/* release-assets/ || true
|
|
cp artifacts/python-packages/hindsight-integrations/litellm/dist/* release-assets/ || true
|
|
cp artifacts/python-packages/hindsight-embed/dist/* release-assets/ || true
|
|
# TypeScript client
|
|
cp artifacts/typescript-client/*.tgz release-assets/ || true
|
|
# OpenClaw Integration
|
|
cp artifacts/openclaw-integration/*.tgz release-assets/ || true
|
|
# AI SDK Integration
|
|
cp artifacts/ai-sdk-integration/*.tgz release-assets/ || true
|
|
# Control Plane
|
|
cp artifacts/control-plane/*.tgz release-assets/ || true
|
|
# Rust CLI binaries
|
|
cp artifacts/rust-cli-linux/hindsight-linux-amd64 release-assets/ || true
|
|
cp artifacts/rust-cli-darwin-amd64/hindsight-darwin-amd64 release-assets/ || true
|
|
cp artifacts/rust-cli-darwin-arm64/hindsight-darwin-arm64 release-assets/ || true
|
|
# Helm chart
|
|
cp artifacts/helm-chart/*.tgz release-assets/ || true
|
|
ls -la release-assets/
|
|
|
|
- name: Create GitHub Release
|
|
uses: softprops/action-gh-release@v2
|
|
with:
|
|
files: release-assets/*
|
|
generate_release_notes: true
|
|
draft: false
|
|
prerelease: false
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|