From ccea8c9160a14d890a05a7eeae66b7faac04c584 Mon Sep 17 00:00:00 2001 From: Keaton Hoskins Date: Sat, 3 Oct 2026 09:00:58 -0700 Subject: [PATCH 1/6] chore(release): archive v2026.10.3 changesets and plan Co-Authored-By: Claude Opus 5.5 --- .../t13042-vault-snapshot-journal.md | 0 .../v2026.10.3}/t13048-genesis-floor.md | 0 .../v2026.10.3}/t13049-vault-unsupported.md | 0 .../v2026.10.3}/t13098-first-key-rotation.md | 0 .cleo/release/v2026.10.3.plan.json | 168 ------------------ 5 files changed, 168 deletions(-) rename .changeset/{ => shipped/v2026.10.3}/t13042-vault-snapshot-journal.md (100%) rename .changeset/{ => shipped/v2026.10.3}/t13048-genesis-floor.md (100%) rename .changeset/{ => shipped/v2026.10.3}/t13049-vault-unsupported.md (100%) rename .changeset/{ => shipped/v2026.10.3}/t13098-first-key-rotation.md (100%) delete mode 100644 .cleo/release/v2026.10.3.plan.json diff --git a/.changeset/t13042-vault-snapshot-journal.md b/.changeset/shipped/v2026.10.3/t13042-vault-snapshot-journal.md similarity index 100% rename from .changeset/t13042-vault-snapshot-journal.md rename to .changeset/shipped/v2026.10.3/t13042-vault-snapshot-journal.md diff --git a/.changeset/t13048-genesis-floor.md b/.changeset/shipped/v2026.10.3/t13048-genesis-floor.md similarity index 100% rename from .changeset/t13048-genesis-floor.md rename to .changeset/shipped/v2026.10.3/t13048-genesis-floor.md diff --git a/.changeset/t13049-vault-unsupported.md b/.changeset/shipped/v2026.10.3/t13049-vault-unsupported.md similarity index 100% rename from .changeset/t13049-vault-unsupported.md rename to .changeset/shipped/v2026.10.3/t13049-vault-unsupported.md diff --git a/.changeset/t13098-first-key-rotation.md b/.changeset/shipped/v2026.10.3/t13098-first-key-rotation.md similarity index 100% rename from .changeset/t13098-first-key-rotation.md rename to .changeset/shipped/v2026.10.3/t13098-first-key-rotation.md diff --git a/.cleo/release/v2026.10.3.plan.json b/.cleo/release/v2026.10.3.plan.json deleted file mode 100644 index 20ef87ad25..0000000000 --- a/.cleo/release/v2026.10.3.plan.json +++ /dev/null @@ -1,168 +0,0 @@ -{ - "$schema": "https://cleocode.io/schemas/release-plan/v1.json", - "version": "v2026.10.3", - "resolvedVersion": "v2026.10.3", - "suffixApplied": false, - "scheme": "calver", - "channel": "latest", - "epicId": "T12323", - "releaseKind": "regular", - "createdAt": "2026-10-03T02:41:06.659Z", - "createdBy": "keatonhoskins", - "previousVersion": "v2026.10.2", - "previousTag": "v2026.10.2", - "previousShippedAt": "2026-10-02T21:08:05.988Z", - "tasks": [ - { - "id": "T13048", - "kind": "fix", - "impact": "patch", - "userFacingSummary": "cleocode manifest-check mirror: floor a v3 genesis checkpoint's schemaVersion at the window's highest rise (mirror cleo-nexus #31 genesis fix)", - "evidenceAtoms": [ - "pr:1787", - "files:.changeset/t13048-genesis-floor.md,packages/core/src/cloud/__tests__/manifest-check-v3.test.ts,packages/core/src/cloud/manifest-check.ts", - "ci:1787" - ], - "epicAncestor": "T12323", - "ivtrPhaseAtPlan": "contribution" - }, - { - "id": "T13049", - "kind": "fix", - "impact": "patch", - "userFacingSummary": "Vault: a Cleo Nexus server without key escrow gives an explicit 'server does not support the vault yet' error, not 'vault is empty' or 'route not found'", - "evidenceAtoms": [ - "pr:1790", - "files:.changeset/t13049-vault-unsupported.md,packages/contracts/src/nexus-account.ts,packages/core/src/cloud/__tests__/nexus-vault.test.ts,packages/core/src/cloud/http.ts,packages/core/src/cloud/nexus-vault-keys.ts", - "ci:1790" - ], - "epicAncestor": "T12323", - "ivtrPhaseAtPlan": "contribution" - }, - { - "id": "T13042", - "kind": "fix", - "impact": "patch", - "userFacingSummary": "Vault snapshot redaction runs with capture triggers suspended; vault snapshots drop _sync_capture/_sync_undo/_sync_frame (#1773 r6 LOW)", - "evidenceAtoms": [ - "pr:1791", - "files:.changeset/t13042-vault-snapshot-journal.md,packages/core/src/cloud/__tests__/nexus-vault.test.ts,packages/core/src/cloud/nexus-vault.ts,packages/core/src/store/__tests__/snapshot-redaction-capture.test.ts,packages/core/src/store/portable-bundle-scan.ts,packages/core/src/store/portable-bundle.ts", - "ci:1791" - ], - "epicAncestor": "T12323", - "ivtrPhaseAtPlan": "contribution" - }, - { - "id": "T13098", - "kind": "fix", - "impact": "patch", - "userFacingSummary": "cloud push: a project's first key must be sent as a rotation (rotate: true, expectedMax: 0); every first push fails against a real Cleo Nexus server", - "evidenceAtoms": [ - "pr:1792", - "files:.changeset/t13098-first-key-rotation.md,packages/core/src/cloud/__tests__/nexus-vault.test.ts,packages/core/src/cloud/nexus-vault-keys.ts", - "ci:1792" - ], - "epicAncestor": "T12323", - "ivtrPhaseAtPlan": "contribution" - } - ], - "changelog": { - "features": [], - "fixes": [ - "T13048", - "T13049", - "T13042", - "T13098" - ], - "chores": [], - "breaking": [] - }, - "gates": [ - { - "name": "test", - "atom": "tool:test", - "status": "unresolved", - "lastVerifiedAt": "2026-10-03T02:41:06.659Z", - "resolvedCommand": "pnpm run test", - "resolvedSource": "project-context" - }, - { - "name": "build", - "atom": "tool:build", - "status": "unresolved", - "lastVerifiedAt": "2026-10-03T02:41:06.659Z", - "resolvedCommand": "pnpm run build", - "resolvedSource": "project-context" - }, - { - "name": "lint", - "atom": "tool:lint", - "status": "unresolved", - "lastVerifiedAt": "2026-10-03T02:41:06.659Z", - "resolvedCommand": "pnpm run lint", - "resolvedSource": "package-script" - }, - { - "name": "typecheck", - "atom": "tool:typecheck", - "status": "unresolved", - "lastVerifiedAt": "2026-10-03T02:41:06.659Z", - "resolvedCommand": "pnpm run typecheck", - "resolvedSource": "package-script" - }, - { - "name": "audit", - "atom": "tool:audit", - "status": "unresolved", - "lastVerifiedAt": "2026-10-03T02:41:06.659Z", - "resolvedCommand": "npm audit", - "resolvedSource": "language-default" - }, - { - "name": "security-scan", - "atom": "tool:security-scan", - "status": "unresolved", - "lastVerifiedAt": "2026-10-03T02:41:06.659Z", - "resolvedCommand": "npm audit", - "resolvedSource": "language-default" - } - ], - "platformMatrix": [ - { - "platform": "any", - "publisher": "npm", - "package": "@cleocode/cleo" - } - ], - "preflightSummary": { - "esbuildExternalsDrift": false, - "lockfileDrift": false, - "epicCompletenessClean": true, - "doubleListingClean": true, - "preflightWarnings": [ - "Skipped 454 out-of-scope changeset entries whose task anchors are not part of this release plan" - ] - }, - "workflowRunUrl": null, - "prUrl": null, - "mergeCommitSha": null, - "status": "planned", - "meta": { - "firstEverRelease": false, - "archetype": "node", - "releaseNotes": "## v2026.10.3 — 2026-10-03\n\n### Fixed\n\n- Vault snapshots no longer carry the local change journal, and snapshot redaction never re-journals what it clears _(provenance: [T13042](https://github.com/kryptobaseddev/cleo/search?q=T13042&type=commits))_\n- A v3 genesis checkpoint that covers segments must sit at or above their highest schema rise _(provenance: [T13048](https://github.com/kryptobaseddev/cleo/search?q=T13048&type=commits))_\n- The cloud vault names a Cleo Nexus server without key escrow instead of calling the vault empty _(provenance: [T13049](https://github.com/kryptobaseddev/cleo/search?q=T13049&type=commits))_\n- The first cloud push of a project works against Cleo Nexus (its key is minted as a rotation). It needs a Cleo Nexus server with cleo-nexus #33, live in production, which lets a device of the account that registered a keyless project create the project's first key. Against an older server every first push is refused, and the error wrongly says the project key exists but was not shared with this account _(provenance: [T13098](https://github.com/kryptobaseddev/cleo/search?q=T13098&type=commits))_\n", - "changesetEntryCount": 4, - "changesetIds": [ - "t13042-vault-snapshot-journal", - "t13048-genesis-floor", - "t13049-vault-unsupported", - "t13098-first-key-rotation" - ], - "taskIds": [ - "T13048", - "T13049", - "T13042", - "T13098" - ] - } -} From 66ebb8a0801b5d4bea8f5b62d8e73c79703a5971 Mon Sep 17 00:00:00 2001 From: Keaton Hoskins Date: Sat, 3 Oct 2026 09:23:29 -0700 Subject: [PATCH 2/6] chore(release): plan v2026.10.4 (provisional: T13103, T12472, T13100, T13106, T13104) Provisional hotfix plan. It is regenerated when #1797 (T13102) and the P0 PRs (T13122, T13123, T13124) merge. The CHANGELOG body equals meta.releaseNotes. Co-Authored-By: Claude Opus 5.5 --- .cleo/release/v2026.10.4.plan.json | 185 +++++++++++++++++++++++++++++ CHANGELOG.md | 13 ++ 2 files changed, 198 insertions(+) create mode 100644 .cleo/release/v2026.10.4.plan.json diff --git a/.cleo/release/v2026.10.4.plan.json b/.cleo/release/v2026.10.4.plan.json new file mode 100644 index 0000000000..f282ce7904 --- /dev/null +++ b/.cleo/release/v2026.10.4.plan.json @@ -0,0 +1,185 @@ +{ + "$schema": "https://cleocode.io/schemas/release-plan/v1.json", + "version": "v2026.10.4", + "resolvedVersion": "v2026.10.4", + "suffixApplied": false, + "scheme": "calver", + "channel": "latest", + "epicId": "T12256", + "releaseKind": "regular", + "createdAt": "2026-10-03T16:22:59.887Z", + "createdBy": "keatonhoskins", + "previousVersion": "v2026.10.3", + "previousTag": "v2026.10.3", + "previousShippedAt": "2026-10-03T14:24:42.051Z", + "tasks": [ + { + "id": "T13103", + "kind": "fix", + "impact": "patch", + "userFacingSummary": "Classify verified ICO resources and supported JSONC configuration evidence", + "evidenceAtoms": [ + "pr:1793", + "files:packages/nexus/package.json,packages/nexus/src/__tests__/pipeline.test.ts,packages/nexus/src/pipeline/parse-loop.ts,pnpm-lock.yaml", + "ci:1793" + ], + "epicAncestor": "T12256", + "ivtrPhaseAtPlan": "contribution" + }, + { + "id": "T12472", + "kind": "feat", + "impact": "minor", + "userFacingSummary": "Nexus project id = portable project_id: remove base64url(path) default id at every CLI/dispatch site", + "evidenceAtoms": [ + "pr:1794", + "files:.changeset/t12472-nexus-portable-query.md,packages/cleo/src/cli/commands/__tests__/doctor-db-substrate.test.ts,packages/cleo/src/cli/commands/__tests__/nexus-status-files-bound.test.ts,packages/cleo/src/cli/commands/__tests__/nexus-status-scope.test.ts,packages/cleo/src/cli/commands/graph.ts,packages/cleo/src/cli/commands/nexus.ts,packages/cleo/src/dispatch/domains/__tests__/nexus-code-intel-dispatch.test.ts,packages/cleo/src/dispatch/domains/__tests__/nexus-contracts-ingestion-dispatch.test.ts,packages/cleo/src/dispatch/domains/__tests__/nexus-phase2-dispatch.test.ts,packages/cleo/src/dispatch/domains/nexus.ts,packages/contracts/src/doctor.ts,packages/core/src/doctor/db-substrate.ts,packages/core/src/nexus/__tests__/nexus-bridge-mode-gate.test.ts,packages/core/src/nexus/__tests__/nexus-bridge-warnings.test.ts,packages/core/src/nexus/__tests__/registry.test.ts,packages/core/src/nexus/api-contracts.ts,packages/core/src/nexus/api-extractors/http-extractor.test.ts,packages/core/src/nexus/api-extractors/http-extractor.ts,packages/core/src/nexus/clusters.ts,packages/core/src/nexus/diff.ts,packages/core/src/nexus/flows.ts,packages/core/src/nexus/identity.ts,packages/core/src/nexus/index.ts,packages/core/src/nexus/nexus-bridge.ts,packages/core/src/nexus/registry.ts,packages/core/src/store/__tests__/exodus-abort-surface.test.ts,packages/skills/skills/ct-codebase-mapper/SKILL.md,packages/skills/skills/manifest.json", + "ci:1794" + ], + "epicAncestor": "T12256", + "ivtrPhaseAtPlan": "contribution" + }, + { + "id": "T13100", + "kind": "feat", + "impact": "minor", + "userFacingSummary": "Onboarding A: cleo login provisions the account key and certifies the device right after enrolment", + "evidenceAtoms": [ + "pr:1796", + "files:.changeset/t13100-login-provisions-account.md,packages/cleo/src/cli/lib/__tests__/nexus-account-cli.test.ts,packages/cleo/src/cli/lib/nexus-account-cli.ts,packages/contracts/src/index.ts,packages/contracts/src/nexus-account.ts,packages/core/src/cloud/__tests__/nexus-enrol.test.ts,packages/core/src/cloud/__tests__/nexus-vault.test.ts,packages/core/src/cloud/nexus-enrol.ts,packages/core/src/cloud/nexus-vault-keys.ts", + "ci:1796" + ], + "epicAncestor": "T12256", + "ivtrPhaseAtPlan": "contribution" + }, + { + "id": "T13106", + "kind": "fix", + "impact": "patch", + "userFacingSummary": "A read-only cleo list writes a token_usage row (portable table), so cloud verify flips from match to ahead", + "evidenceAtoms": [ + "pr:1800", + "files:.changeset/t13106-reads-record-no-token-usage.md,packages/cleo/src/dispatch/adapters/cli.ts,packages/core/src/metrics/__tests__/dispatch-token-usage.test.ts,packages/core/src/metrics/token-service.ts", + "ci:1800" + ], + "epicAncestor": "T12256", + "ivtrPhaseAtPlan": "contribution" + }, + { + "id": "T13104", + "kind": "fix", + "impact": "patch", + "userFacingSummary": "Vault restore: a restored store rebuilds its migration journal through the partially-applied reconciler (17 ERROR lines on every new device)", + "evidenceAtoms": [ + "pr:1798", + "files:.changeset/t13104-restore-migration-journal.md,packages/cleo/src/cli/commands/doctor-migrations.ts,packages/core/src/cloud/__tests__/nexus-vault.test.ts,packages/core/src/doctor/__tests__/migrations.test.ts,packages/core/src/doctor/migrations.ts,packages/core/src/store/__tests__/vault-manifest.test.ts,packages/core/src/store/table-classification.ts,packages/core/src/store/vault-manifest.ts", + "ci:1798" + ], + "epicAncestor": "T12256", + "ivtrPhaseAtPlan": "contribution" + } + ], + "changelog": { + "features": [ + "T12472", + "T13100" + ], + "fixes": [ + "T13103", + "T13106", + "T13104" + ], + "chores": [], + "breaking": [] + }, + "gates": [ + { + "name": "test", + "atom": "tool:test", + "status": "unresolved", + "lastVerifiedAt": "2026-10-03T16:22:59.887Z", + "resolvedCommand": "pnpm run test", + "resolvedSource": "project-context" + }, + { + "name": "build", + "atom": "tool:build", + "status": "unresolved", + "lastVerifiedAt": "2026-10-03T16:22:59.887Z", + "resolvedCommand": "pnpm run build", + "resolvedSource": "project-context" + }, + { + "name": "lint", + "atom": "tool:lint", + "status": "unresolved", + "lastVerifiedAt": "2026-10-03T16:22:59.887Z", + "resolvedCommand": "pnpm run lint", + "resolvedSource": "package-script" + }, + { + "name": "typecheck", + "atom": "tool:typecheck", + "status": "unresolved", + "lastVerifiedAt": "2026-10-03T16:22:59.887Z", + "resolvedCommand": "pnpm run typecheck", + "resolvedSource": "package-script" + }, + { + "name": "audit", + "atom": "tool:audit", + "status": "unresolved", + "lastVerifiedAt": "2026-10-03T16:22:59.887Z", + "resolvedCommand": "npm audit", + "resolvedSource": "language-default" + }, + { + "name": "security-scan", + "atom": "tool:security-scan", + "status": "unresolved", + "lastVerifiedAt": "2026-10-03T16:22:59.887Z", + "resolvedCommand": "npm audit", + "resolvedSource": "language-default" + } + ], + "platformMatrix": [ + { + "platform": "any", + "publisher": "npm", + "package": "@cleocode/cleo" + } + ], + "preflightSummary": { + "esbuildExternalsDrift": false, + "lockfileDrift": false, + "epicCompletenessClean": true, + "doubleListingClean": true, + "preflightWarnings": [ + "Skipped 454 out-of-scope changeset entries whose task anchors are not part of this release plan" + ] + }, + "workflowRunUrl": null, + "prUrl": null, + "mergeCommitSha": null, + "status": "planned", + "meta": { + "firstEverRelease": false, + "archetype": "node", + "releaseNotes": "## v2026.10.4 — 2026-10-03\n\n### Added\n\n- cleo login nexus sets up the account key and certifies the device, so the first push has nothing left to set up _(provenance: [T13100](https://github.com/kryptobaseddev/cleo/search?q=T13100&type=commits))_\n\n### Fixed\n\n- Nexus graph queries keep portable identity when projects move _(provenance: [T12472](https://github.com/kryptobaseddev/cleo/search?q=T12472&type=commits))_\n- Recognize ICO resources and supported JSONC configuration evidence _(provenance: [T13103](https://github.com/kryptobaseddev/cleo/search?q=T13103&type=commits))_\n- A vault restore keeps the snapshot's migration journal, so a restored store opens without stamping migrations it never ran _(provenance: [T13104](https://github.com/kryptobaseddev/cleo/search?q=T13104&type=commits))_\n- Dispatch token telemetry no longer writes a token_usage row when a command only reads _(provenance: [T13106](https://github.com/kryptobaseddev/cleo/search?q=T13106&type=commits))_\n", + "changesetEntryCount": 5, + "changesetIds": [ + "t12472-nexus-portable-query", + "t13100-login-provisions-account", + "t13103-config-resource-evidence", + "t13104-restore-migration-journal", + "t13106-reads-record-no-token-usage" + ], + "taskIds": [ + "T13103", + "T12472", + "T13100", + "T13106", + "T13104" + ] + } +} diff --git a/CHANGELOG.md b/CHANGELOG.md index e2ee2a0f2e..31de22787f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,18 @@ # Changelog +## [2026.10.4] (2026-10-03) + +### Added + +- cleo login nexus sets up the account key and certifies the device, so the first push has nothing left to set up _(provenance: [T13100](https://github.com/kryptobaseddev/cleo/search?q=T13100&type=commits))_ + +### Fixed + +- Nexus graph queries keep portable identity when projects move _(provenance: [T12472](https://github.com/kryptobaseddev/cleo/search?q=T12472&type=commits))_ +- Recognize ICO resources and supported JSONC configuration evidence _(provenance: [T13103](https://github.com/kryptobaseddev/cleo/search?q=T13103&type=commits))_ +- A vault restore keeps the snapshot's migration journal, so a restored store opens without stamping migrations it never ran _(provenance: [T13104](https://github.com/kryptobaseddev/cleo/search?q=T13104&type=commits))_ +- Dispatch token telemetry no longer writes a token_usage row when a command only reads _(provenance: [T13106](https://github.com/kryptobaseddev/cleo/search?q=T13106&type=commits))_ + ## [2026.10.3] (2026-10-03) ### Fixed From 10ce8633e9cf2b3ebee3e8fd8d526b777b22e9a4 Mon Sep 17 00:00:00 2001 From: Keaton Hoskins Date: Sat, 3 Oct 2026 19:43:29 -0700 Subject: [PATCH 3/6] =?UTF-8?q?chore(release):=20plan=20v2026.10.4=20?= =?UTF-8?q?=E2=80=94=20macOS=20empty-store=20fix,=20heavy-command=20hook,?= =?UTF-8?q?=20no=20implicit=20whole-suite=20evidence,=20CLI=20startup=20me?= =?UTF-8?q?mory,=20heap/worker/typecheck=20caps?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Regenerated from main da4eac935 with `cleo release plan v2026.10.4 --tasks T13103,T12472,T13100,T13104,T13106,T13122,T13136,T13119,T13150`: the tasks that are closed (owner decision: option C, no override). Every other merged PR since v2026.10.3 still ships as commits. The notes lead with the update line and highlights in the owner's order (#1826, #1811, #1818, #1812/#1820, #1808/#1810/#1824), then "Also in this release" (#1797, #1816, #1817, #1807), then the generated sections. The CHANGELOG body equals meta.releaseNotes. Co-Authored-By: Claude Opus 5.5 --- .cleo/release/v2026.10.4.plan.json | 108 +++++++++++++++++++++++------ CHANGELOG.md | 23 +++++- 2 files changed, 108 insertions(+), 23 deletions(-) diff --git a/.cleo/release/v2026.10.4.plan.json b/.cleo/release/v2026.10.4.plan.json index f282ce7904..5ccd0c8ff1 100644 --- a/.cleo/release/v2026.10.4.plan.json +++ b/.cleo/release/v2026.10.4.plan.json @@ -7,7 +7,7 @@ "channel": "latest", "epicId": "T12256", "releaseKind": "regular", - "createdAt": "2026-10-03T16:22:59.887Z", + "createdAt": "2026-10-04T02:42:13.266Z", "createdBy": "keatonhoskins", "previousVersion": "v2026.10.3", "previousTag": "v2026.10.3", @@ -52,6 +52,19 @@ "epicAncestor": "T12256", "ivtrPhaseAtPlan": "contribution" }, + { + "id": "T13104", + "kind": "fix", + "impact": "patch", + "userFacingSummary": "Vault restore: a restored store rebuilds its migration journal through the partially-applied reconciler (17 ERROR lines on every new device)", + "evidenceAtoms": [ + "pr:1798", + "files:.changeset/t13104-restore-migration-journal.md,packages/cleo/src/cli/commands/doctor-migrations.ts,packages/core/src/cloud/__tests__/nexus-vault.test.ts,packages/core/src/doctor/__tests__/migrations.test.ts,packages/core/src/doctor/migrations.ts,packages/core/src/store/__tests__/vault-manifest.test.ts,packages/core/src/store/table-classification.ts,packages/core/src/store/vault-manifest.ts", + "ci:1798" + ], + "epicAncestor": "T12256", + "ivtrPhaseAtPlan": "contribution" + }, { "id": "T13106", "kind": "fix", @@ -66,14 +79,53 @@ "ivtrPhaseAtPlan": "contribution" }, { - "id": "T13104", - "kind": "fix", - "impact": "patch", - "userFacingSummary": "Vault restore: a restored store rebuilds its migration journal through the partially-applied reconciler (17 ERROR lines on every new device)", + "id": "T13122", + "kind": "feat", + "impact": "minor", + "userFacingSummary": "Evidence heap cap is defeated by an inherited NODE_OPTIONS: an existing --max-old-space-size wins, so a profile-wide 8192 doubles the per-run budget to 6 workers x 8 GB = all RAM", "evidenceAtoms": [ - "pr:1798", - "files:.changeset/t13104-restore-migration-journal.md,packages/cleo/src/cli/commands/doctor-migrations.ts,packages/core/src/cloud/__tests__/nexus-vault.test.ts,packages/core/src/doctor/__tests__/migrations.test.ts,packages/core/src/doctor/migrations.ts,packages/core/src/store/__tests__/vault-manifest.test.ts,packages/core/src/store/table-classification.ts,packages/core/src/store/vault-manifest.ts", - "ci:1798" + "pr:1808", + "files:.changeset/t13122-effective-heap-cap.md,AGENTS.md,packages/cleo/bin/cleo.js,packages/cleo/src/cli/__tests__/run-command.test.ts,packages/cleo/src/cli/commands/run.ts,packages/cleo/src/cli/index.ts,packages/cleo/src/cli/lib/__tests__/cli-threadpool-env.test.ts,packages/cleo/src/cli/lib/cli-threadpool-env.ts,packages/contracts/src/index.ts,packages/contracts/src/resource-governor.ts,packages/contracts/src/task.ts,packages/core/src/tasks/__tests__/heavy-tool-env.test.ts,packages/core/src/tasks/__tests__/heavy-tool-limit.test.ts,packages/core/src/tasks/__tests__/tool-cache-resource-kill.test.ts,packages/core/src/tasks/evidence.ts,packages/core/src/tasks/heavy-tool-env.ts,packages/core/src/tasks/index.ts,packages/core/src/tasks/tool-cache-env.ts,packages/core/src/tasks/tool-cache.ts", + "ci:1808" + ], + "epicAncestor": "T12256", + "ivtrPhaseAtPlan": "contribution" + }, + { + "id": "T13136", + "kind": "feat", + "impact": "minor", + "userFacingSummary": "gh#1804: test-run: evidence schema is undocumented, and the zero-total error does not name the expected keys", + "evidenceAtoms": [ + "pr:1814", + "files:.changeset/t13136-test-run-counter-shapes.md,packages/cleo/src/cli/commands/verify.ts,packages/core/src/tasks/__tests__/evidence.test.ts,packages/core/src/tasks/__tests__/test-run-binding.test.ts,packages/core/src/tasks/evidence.ts,packages/skills/skills/ct-task-executor/SKILL.md,packages/skills/skills/ct-task-executor/references/evidence-and-gates.md,packages/skills/skills/manifest.json", + "ci:1814" + ], + "epicAncestor": "T12256", + "ivtrPhaseAtPlan": "contribution" + }, + { + "id": "T13119", + "kind": "feat", + "impact": "minor", + "userFacingSummary": "exodus-reconcile.test.ts 'converges with exodus-on-open whichever runs first (on-open first)' fails in some environments, including on origin/main", + "evidenceAtoms": [ + "pr:1826", + "files:.changeset/t13119-exodus-cpu-deferral.md,packages/core/src/resources/__tests__/governor.test.ts,packages/core/src/resources/governor.ts,packages/core/src/store/__tests__/dual-scope-db.test.ts,packages/core/src/store/dual-scope-db.ts", + "ci:1826" + ], + "epicAncestor": "T12256", + "ivtrPhaseAtPlan": "contribution" + }, + { + "id": "T13150", + "kind": "feat", + "impact": "minor", + "userFacingSummary": "macOS-only failure: upgrade.test.ts 'runUpgrade storage migration from a linked worktree (T12708) > migrates the OWNER store and audits the run' (missing second audit entry)", + "evidenceAtoms": [ + "pr:1826", + "files:.changeset/t13119-exodus-cpu-deferral.md,packages/core/src/resources/__tests__/governor.test.ts,packages/core/src/resources/governor.ts,packages/core/src/store/__tests__/dual-scope-db.test.ts,packages/core/src/store/dual-scope-db.ts", + "ci:1826" ], "epicAncestor": "T12256", "ivtrPhaseAtPlan": "contribution" @@ -82,12 +134,16 @@ "changelog": { "features": [ "T12472", - "T13100" + "T13100", + "T13122", + "T13136", + "T13119", + "T13150" ], "fixes": [ "T13103", - "T13106", - "T13104" + "T13104", + "T13106" ], "chores": [], "breaking": [] @@ -97,7 +153,7 @@ "name": "test", "atom": "tool:test", "status": "unresolved", - "lastVerifiedAt": "2026-10-03T16:22:59.887Z", + "lastVerifiedAt": "2026-10-04T02:42:13.266Z", "resolvedCommand": "pnpm run test", "resolvedSource": "project-context" }, @@ -105,7 +161,7 @@ "name": "build", "atom": "tool:build", "status": "unresolved", - "lastVerifiedAt": "2026-10-03T16:22:59.887Z", + "lastVerifiedAt": "2026-10-04T02:42:13.266Z", "resolvedCommand": "pnpm run build", "resolvedSource": "project-context" }, @@ -113,7 +169,7 @@ "name": "lint", "atom": "tool:lint", "status": "unresolved", - "lastVerifiedAt": "2026-10-03T16:22:59.887Z", + "lastVerifiedAt": "2026-10-04T02:42:13.266Z", "resolvedCommand": "pnpm run lint", "resolvedSource": "package-script" }, @@ -121,7 +177,7 @@ "name": "typecheck", "atom": "tool:typecheck", "status": "unresolved", - "lastVerifiedAt": "2026-10-03T16:22:59.887Z", + "lastVerifiedAt": "2026-10-04T02:42:13.266Z", "resolvedCommand": "pnpm run typecheck", "resolvedSource": "package-script" }, @@ -129,7 +185,7 @@ "name": "audit", "atom": "tool:audit", "status": "unresolved", - "lastVerifiedAt": "2026-10-03T16:22:59.887Z", + "lastVerifiedAt": "2026-10-04T02:42:13.266Z", "resolvedCommand": "npm audit", "resolvedSource": "language-default" }, @@ -137,7 +193,7 @@ "name": "security-scan", "atom": "tool:security-scan", "status": "unresolved", - "lastVerifiedAt": "2026-10-03T16:22:59.887Z", + "lastVerifiedAt": "2026-10-04T02:42:13.266Z", "resolvedCommand": "npm audit", "resolvedSource": "language-default" } @@ -155,7 +211,7 @@ "epicCompletenessClean": true, "doubleListingClean": true, "preflightWarnings": [ - "Skipped 454 out-of-scope changeset entries whose task anchors are not part of this release plan" + "Skipped 462 out-of-scope changeset entries whose task anchors are not part of this release plan" ] }, "workflowRunUrl": null, @@ -165,21 +221,29 @@ "meta": { "firstEverRelease": false, "archetype": "node", - "releaseNotes": "## v2026.10.4 — 2026-10-03\n\n### Added\n\n- cleo login nexus sets up the account key and certifies the device, so the first push has nothing left to set up _(provenance: [T13100](https://github.com/kryptobaseddev/cleo/search?q=T13100&type=commits))_\n\n### Fixed\n\n- Nexus graph queries keep portable identity when projects move _(provenance: [T12472](https://github.com/kryptobaseddev/cleo/search?q=T12472&type=commits))_\n- Recognize ICO resources and supported JSONC configuration evidence _(provenance: [T13103](https://github.com/kryptobaseddev/cleo/search?q=T13103&type=commits))_\n- A vault restore keeps the snapshot's migration journal, so a restored store opens without stamping migrations it never ran _(provenance: [T13104](https://github.com/kryptobaseddev/cleo/search?q=T13104&type=commits))_\n- Dispatch token telemetry no longer writes a token_usage row when a command only reads _(provenance: [T13106](https://github.com/kryptobaseddev/cleo/search?q=T13106&type=commits))_\n", - "changesetEntryCount": 5, + "releaseNotes": "## v2026.10.4 — 2026-10-04\n\n> **Update now: run `cleo self-update`.** This hotfix fixes empty stores on busy Macs and stops CLEO from saturating the machine it runs on.\n\n### Highlights\n\n- **Empty stores on busy Macs are fixed (#1826).** On a busy Mac, opening a project that still had its legacy `tasks.db` and `brain.db` skipped the migration into `cleo.db`, so the project's tasks looked missing, and a write in that state left the legacy rows behind. If a project's tasks looked missing on a Mac, run `cleo doctor superseded-store` in it after updating: it is read-only and shows which store holds the data.\n- **The heavy-command hook now installs and governs (#1811).** `cleo init` and `cleo upgrade` install it for every agent harness in use, `cleo doctor` and the briefing say when it is missing, and in Claude Code's default, acceptEdits and dontAsk modes it governs every command your allow rules already approve.\n- **Evidence no longer runs whole suites (#1818).** Without a declared `affectedCommand`, `tool:test` runs only the affected packages, and `cleo doctor` proposes one.\n- **Less memory at CLI startup (#1812, #1820).** `cleo --version` and `--help` no longer load all of the core library, and loading `@cleocode/core` no longer evaluates js-tiktoken, the AWS Bedrock SDK or the ai SDK.\n- **Heap, worker and typecheck caps (#1808, #1810, #1824).** An inherited `NODE_OPTIONS` heap, worker count or package concurrency no longer multiplies an evidence run's memory, and typecheck and lint slots are sized from RAM and respond to memory pressure.\n\n### Also in this release\n\n- `cleo login nexus` links and backs up the current project, lists your projects on a new machine, and `cleo cloud restore` takes a project name (#1797).\n- `cleo release open` reuses main's tested CI run for the release commit, and `--no-commit-plan` dispatches the merged plan by hash (#1816).\n- The release bump-PR's dispatched CI runs the version-only set instead of the whole suite (#1817).\n- The owned-process probe reads `ESRCH` as a process that is gone, which removes a flaky test failure (#1807).\n\n### Added\n\n- cleo login nexus sets up the account key and certifies the device, so the first push has nothing left to set up _(provenance: [T13100](https://github.com/kryptobaseddev/cleo/search?q=T13100&type=commits))_\n\n### Fixed\n\n- Nexus graph queries keep portable identity when projects move _(provenance: [T12472](https://github.com/kryptobaseddev/cleo/search?q=T12472&type=commits))_\n- Recognize ICO resources and supported JSONC configuration evidence _(provenance: [T13103](https://github.com/kryptobaseddev/cleo/search?q=T13103&type=commits))_\n- A vault restore keeps the snapshot's migration journal, so a restored store opens without stamping migrations it never ran _(provenance: [T13104](https://github.com/kryptobaseddev/cleo/search?q=T13104&type=commits))_\n- Dispatch token telemetry no longer writes a token_usage row when a command only reads _(provenance: [T13106](https://github.com/kryptobaseddev/cleo/search?q=T13106&type=commits))_\n- On a busy Mac, opening a legacy project no longer skips the exodus migration and serves an empty store _(provenance: [T13119](https://github.com/kryptobaseddev/cleo/search?q=T13119&type=commits), [T13150](https://github.com/kryptobaseddev/cleo/search?q=T13150&type=commits))_\n- An inherited NODE_OPTIONS heap, worker count or package concurrency no longer multiplies an evidence run's memory; the plan is reported _(provenance: [T13122](https://github.com/kryptobaseddev/cleo/search?q=T13122&type=commits))_\n- The heavy-tool bounds also catch MAKEFLAGS flag clusters, a dash-spelled workspace variable and a coloured npm warning _(provenance: [T13122](https://github.com/kryptobaseddev/cleo/search?q=T13122&type=commits))_\n- test-run evidence accepts summary and node --test counters, and a report without counts names the keys it needs _(provenance: [T13136](https://github.com/kryptobaseddev/cleo/search?q=T13136&type=commits))_\n", + "changesetEntryCount": 9, "changesetIds": [ "t12472-nexus-portable-query", "t13100-login-provisions-account", "t13103-config-resource-evidence", "t13104-restore-migration-journal", - "t13106-reads-record-no-token-usage" + "t13106-reads-record-no-token-usage", + "t13119-exodus-cpu-deferral", + "t13122-effective-heap-cap", + "t13122-review-nits", + "t13136-test-run-counter-shapes" ], "taskIds": [ "T13103", "T12472", "T13100", + "T13104", "T13106", - "T13104" + "T13122", + "T13136", + "T13119", + "T13150" ] } } diff --git a/CHANGELOG.md b/CHANGELOG.md index 31de22787f..759b837f39 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,6 +1,23 @@ # Changelog -## [2026.10.4] (2026-10-03) +## [2026.10.4] (2026-10-04) + +> **Update now: run `cleo self-update`.** This hotfix fixes empty stores on busy Macs and stops CLEO from saturating the machine it runs on. + +### Highlights + +- **Empty stores on busy Macs are fixed (#1826).** On a busy Mac, opening a project that still had its legacy `tasks.db` and `brain.db` skipped the migration into `cleo.db`, so the project's tasks looked missing, and a write in that state left the legacy rows behind. If a project's tasks looked missing on a Mac, run `cleo doctor superseded-store` in it after updating: it is read-only and shows which store holds the data. +- **The heavy-command hook now installs and governs (#1811).** `cleo init` and `cleo upgrade` install it for every agent harness in use, `cleo doctor` and the briefing say when it is missing, and in Claude Code's default, acceptEdits and dontAsk modes it governs every command your allow rules already approve. +- **Evidence no longer runs whole suites (#1818).** Without a declared `affectedCommand`, `tool:test` runs only the affected packages, and `cleo doctor` proposes one. +- **Less memory at CLI startup (#1812, #1820).** `cleo --version` and `--help` no longer load all of the core library, and loading `@cleocode/core` no longer evaluates js-tiktoken, the AWS Bedrock SDK or the ai SDK. +- **Heap, worker and typecheck caps (#1808, #1810, #1824).** An inherited `NODE_OPTIONS` heap, worker count or package concurrency no longer multiplies an evidence run's memory, and typecheck and lint slots are sized from RAM and respond to memory pressure. + +### Also in this release + +- `cleo login nexus` links and backs up the current project, lists your projects on a new machine, and `cleo cloud restore` takes a project name (#1797). +- `cleo release open` reuses main's tested CI run for the release commit, and `--no-commit-plan` dispatches the merged plan by hash (#1816). +- The release bump-PR's dispatched CI runs the version-only set instead of the whole suite (#1817). +- The owned-process probe reads `ESRCH` as a process that is gone, which removes a flaky test failure (#1807). ### Added @@ -12,6 +29,10 @@ - Recognize ICO resources and supported JSONC configuration evidence _(provenance: [T13103](https://github.com/kryptobaseddev/cleo/search?q=T13103&type=commits))_ - A vault restore keeps the snapshot's migration journal, so a restored store opens without stamping migrations it never ran _(provenance: [T13104](https://github.com/kryptobaseddev/cleo/search?q=T13104&type=commits))_ - Dispatch token telemetry no longer writes a token_usage row when a command only reads _(provenance: [T13106](https://github.com/kryptobaseddev/cleo/search?q=T13106&type=commits))_ +- On a busy Mac, opening a legacy project no longer skips the exodus migration and serves an empty store _(provenance: [T13119](https://github.com/kryptobaseddev/cleo/search?q=T13119&type=commits), [T13150](https://github.com/kryptobaseddev/cleo/search?q=T13150&type=commits))_ +- An inherited NODE_OPTIONS heap, worker count or package concurrency no longer multiplies an evidence run's memory; the plan is reported _(provenance: [T13122](https://github.com/kryptobaseddev/cleo/search?q=T13122&type=commits))_ +- The heavy-tool bounds also catch MAKEFLAGS flag clusters, a dash-spelled workspace variable and a coloured npm warning _(provenance: [T13122](https://github.com/kryptobaseddev/cleo/search?q=T13122&type=commits))_ +- test-run evidence accepts summary and node --test counters, and a report without counts names the keys it needs _(provenance: [T13136](https://github.com/kryptobaseddev/cleo/search?q=T13136&type=commits))_ ## [2026.10.3] (2026-10-03) From 3ebfd8898dbc4aaca6e23e9ce17d805f16430f09 Mon Sep 17 00:00:00 2001 From: Keaton Hoskins Date: Sat, 3 Oct 2026 19:57:57 -0700 Subject: [PATCH 4/6] chore(release): v2026.10.4 notes: name the #1826 recovery, scope the #1811 and #1818 highlights (review) The #1826 highlight names the recovery (superseded-store --reconcile --dry-run, then --reconcile; additive, verified, legacy files untouched). The #1811 highlight no longer claims every allow-rule command is governed: plain pre-approved forms are queued, anything else is warned; it names the files written (kept out of git), the opt-out and doctor heavy-command-hook --fix. The #1818 heading no longer claims whole suites never run. CHANGELOG body still equals meta.releaseNotes. Co-Authored-By: Claude Opus 5.5 --- .cleo/release/v2026.10.4.plan.json | 2 +- CHANGELOG.md | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.cleo/release/v2026.10.4.plan.json b/.cleo/release/v2026.10.4.plan.json index 5ccd0c8ff1..95963368e8 100644 --- a/.cleo/release/v2026.10.4.plan.json +++ b/.cleo/release/v2026.10.4.plan.json @@ -221,7 +221,7 @@ "meta": { "firstEverRelease": false, "archetype": "node", - "releaseNotes": "## v2026.10.4 — 2026-10-04\n\n> **Update now: run `cleo self-update`.** This hotfix fixes empty stores on busy Macs and stops CLEO from saturating the machine it runs on.\n\n### Highlights\n\n- **Empty stores on busy Macs are fixed (#1826).** On a busy Mac, opening a project that still had its legacy `tasks.db` and `brain.db` skipped the migration into `cleo.db`, so the project's tasks looked missing, and a write in that state left the legacy rows behind. If a project's tasks looked missing on a Mac, run `cleo doctor superseded-store` in it after updating: it is read-only and shows which store holds the data.\n- **The heavy-command hook now installs and governs (#1811).** `cleo init` and `cleo upgrade` install it for every agent harness in use, `cleo doctor` and the briefing say when it is missing, and in Claude Code's default, acceptEdits and dontAsk modes it governs every command your allow rules already approve.\n- **Evidence no longer runs whole suites (#1818).** Without a declared `affectedCommand`, `tool:test` runs only the affected packages, and `cleo doctor` proposes one.\n- **Less memory at CLI startup (#1812, #1820).** `cleo --version` and `--help` no longer load all of the core library, and loading `@cleocode/core` no longer evaluates js-tiktoken, the AWS Bedrock SDK or the ai SDK.\n- **Heap, worker and typecheck caps (#1808, #1810, #1824).** An inherited `NODE_OPTIONS` heap, worker count or package concurrency no longer multiplies an evidence run's memory, and typecheck and lint slots are sized from RAM and respond to memory pressure.\n\n### Also in this release\n\n- `cleo login nexus` links and backs up the current project, lists your projects on a new machine, and `cleo cloud restore` takes a project name (#1797).\n- `cleo release open` reuses main's tested CI run for the release commit, and `--no-commit-plan` dispatches the merged plan by hash (#1816).\n- The release bump-PR's dispatched CI runs the version-only set instead of the whole suite (#1817).\n- The owned-process probe reads `ESRCH` as a process that is gone, which removes a flaky test failure (#1807).\n\n### Added\n\n- cleo login nexus sets up the account key and certifies the device, so the first push has nothing left to set up _(provenance: [T13100](https://github.com/kryptobaseddev/cleo/search?q=T13100&type=commits))_\n\n### Fixed\n\n- Nexus graph queries keep portable identity when projects move _(provenance: [T12472](https://github.com/kryptobaseddev/cleo/search?q=T12472&type=commits))_\n- Recognize ICO resources and supported JSONC configuration evidence _(provenance: [T13103](https://github.com/kryptobaseddev/cleo/search?q=T13103&type=commits))_\n- A vault restore keeps the snapshot's migration journal, so a restored store opens without stamping migrations it never ran _(provenance: [T13104](https://github.com/kryptobaseddev/cleo/search?q=T13104&type=commits))_\n- Dispatch token telemetry no longer writes a token_usage row when a command only reads _(provenance: [T13106](https://github.com/kryptobaseddev/cleo/search?q=T13106&type=commits))_\n- On a busy Mac, opening a legacy project no longer skips the exodus migration and serves an empty store _(provenance: [T13119](https://github.com/kryptobaseddev/cleo/search?q=T13119&type=commits), [T13150](https://github.com/kryptobaseddev/cleo/search?q=T13150&type=commits))_\n- An inherited NODE_OPTIONS heap, worker count or package concurrency no longer multiplies an evidence run's memory; the plan is reported _(provenance: [T13122](https://github.com/kryptobaseddev/cleo/search?q=T13122&type=commits))_\n- The heavy-tool bounds also catch MAKEFLAGS flag clusters, a dash-spelled workspace variable and a coloured npm warning _(provenance: [T13122](https://github.com/kryptobaseddev/cleo/search?q=T13122&type=commits))_\n- test-run evidence accepts summary and node --test counters, and a report without counts names the keys it needs _(provenance: [T13136](https://github.com/kryptobaseddev/cleo/search?q=T13136&type=commits))_\n", + "releaseNotes": "## v2026.10.4 — 2026-10-04\n\n> **Update now: run `cleo self-update`.** This hotfix fixes empty stores on busy Macs and stops CLEO from saturating the machine it runs on.\n\n### Highlights\n\n- **Empty stores on busy Macs are fixed (#1826).** On a busy Mac, opening a project that still had its legacy `tasks.db` and `brain.db` skipped the migration into `cleo.db`, so the project's tasks looked missing, and a write in that state left the legacy rows behind. If your tasks looked missing after opening a project on a busy Mac, run `cleo doctor superseded-store --reconcile --dry-run` in that project to see what is stranded, then `cleo doctor superseded-store --reconcile`. It is additive and verified, and your legacy files are never touched.\n- **The heavy-command hook now installs and governs (#1811).** `cleo init` and `cleo upgrade` install it for every agent harness in use, and `cleo doctor` and the briefing say when it is missing. In Claude Code's default, acceptEdits and dontAsk modes it queues the heavy commands your allow rules already approve through CLEO's machine-wide budget when it can tell that from their plain form; anything else gets a warning instead. It writes project-level files only and keeps them out of git (`.claude/settings.local.json`, `.codex/hooks.json` when CLEO created it, the opencode plugin), and it never edits a `.codex/hooks.json` your team already has. `cleo doctor heavy-command-hook --fix` installs it; `resources.heavyCommandHook: off` turns it off.\n- **Evidence runs only the affected packages when no `affectedCommand` is declared (#1818).** `tool:test` derives one from a workspace-wide test command (`pnpm -r`, `npm --workspaces`, `turbo run test`), and `cleo doctor` proposes it. A change outside every package, or a test command with no affected form, still runs the whole suite.\n- **Less memory at CLI startup (#1812, #1820).** `cleo --version` and `--help` no longer load all of the core library, and loading `@cleocode/core` no longer evaluates js-tiktoken, the AWS Bedrock SDK or the ai SDK.\n- **Heap, worker and typecheck caps (#1808, #1810, #1824).** An inherited `NODE_OPTIONS` heap, worker count or package concurrency no longer multiplies an evidence run's memory, and typecheck and lint slots are sized from RAM and respond to memory pressure.\n\n### Also in this release\n\n- `cleo login nexus` links and backs up the current project, lists your projects on a new machine, and `cleo cloud restore` takes a project name (#1797).\n- `cleo release open` reuses main's tested CI run for the release commit, and `--no-commit-plan` dispatches the merged plan by hash (#1816).\n- The release bump-PR's dispatched CI runs the version-only set instead of the whole suite (#1817).\n- The owned-process probe reads `ESRCH` as a process that is gone, which removes a flaky test failure (#1807).\n\n### Added\n\n- cleo login nexus sets up the account key and certifies the device, so the first push has nothing left to set up _(provenance: [T13100](https://github.com/kryptobaseddev/cleo/search?q=T13100&type=commits))_\n\n### Fixed\n\n- Nexus graph queries keep portable identity when projects move _(provenance: [T12472](https://github.com/kryptobaseddev/cleo/search?q=T12472&type=commits))_\n- Recognize ICO resources and supported JSONC configuration evidence _(provenance: [T13103](https://github.com/kryptobaseddev/cleo/search?q=T13103&type=commits))_\n- A vault restore keeps the snapshot's migration journal, so a restored store opens without stamping migrations it never ran _(provenance: [T13104](https://github.com/kryptobaseddev/cleo/search?q=T13104&type=commits))_\n- Dispatch token telemetry no longer writes a token_usage row when a command only reads _(provenance: [T13106](https://github.com/kryptobaseddev/cleo/search?q=T13106&type=commits))_\n- On a busy Mac, opening a legacy project no longer skips the exodus migration and serves an empty store _(provenance: [T13119](https://github.com/kryptobaseddev/cleo/search?q=T13119&type=commits), [T13150](https://github.com/kryptobaseddev/cleo/search?q=T13150&type=commits))_\n- An inherited NODE_OPTIONS heap, worker count or package concurrency no longer multiplies an evidence run's memory; the plan is reported _(provenance: [T13122](https://github.com/kryptobaseddev/cleo/search?q=T13122&type=commits))_\n- The heavy-tool bounds also catch MAKEFLAGS flag clusters, a dash-spelled workspace variable and a coloured npm warning _(provenance: [T13122](https://github.com/kryptobaseddev/cleo/search?q=T13122&type=commits))_\n- test-run evidence accepts summary and node --test counters, and a report without counts names the keys it needs _(provenance: [T13136](https://github.com/kryptobaseddev/cleo/search?q=T13136&type=commits))_\n", "changesetEntryCount": 9, "changesetIds": [ "t12472-nexus-portable-query", diff --git a/CHANGELOG.md b/CHANGELOG.md index 759b837f39..e952399a1b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,9 +6,9 @@ ### Highlights -- **Empty stores on busy Macs are fixed (#1826).** On a busy Mac, opening a project that still had its legacy `tasks.db` and `brain.db` skipped the migration into `cleo.db`, so the project's tasks looked missing, and a write in that state left the legacy rows behind. If a project's tasks looked missing on a Mac, run `cleo doctor superseded-store` in it after updating: it is read-only and shows which store holds the data. -- **The heavy-command hook now installs and governs (#1811).** `cleo init` and `cleo upgrade` install it for every agent harness in use, `cleo doctor` and the briefing say when it is missing, and in Claude Code's default, acceptEdits and dontAsk modes it governs every command your allow rules already approve. -- **Evidence no longer runs whole suites (#1818).** Without a declared `affectedCommand`, `tool:test` runs only the affected packages, and `cleo doctor` proposes one. +- **Empty stores on busy Macs are fixed (#1826).** On a busy Mac, opening a project that still had its legacy `tasks.db` and `brain.db` skipped the migration into `cleo.db`, so the project's tasks looked missing, and a write in that state left the legacy rows behind. If your tasks looked missing after opening a project on a busy Mac, run `cleo doctor superseded-store --reconcile --dry-run` in that project to see what is stranded, then `cleo doctor superseded-store --reconcile`. It is additive and verified, and your legacy files are never touched. +- **The heavy-command hook now installs and governs (#1811).** `cleo init` and `cleo upgrade` install it for every agent harness in use, and `cleo doctor` and the briefing say when it is missing. In Claude Code's default, acceptEdits and dontAsk modes it queues the heavy commands your allow rules already approve through CLEO's machine-wide budget when it can tell that from their plain form; anything else gets a warning instead. It writes project-level files only and keeps them out of git (`.claude/settings.local.json`, `.codex/hooks.json` when CLEO created it, the opencode plugin), and it never edits a `.codex/hooks.json` your team already has. `cleo doctor heavy-command-hook --fix` installs it; `resources.heavyCommandHook: off` turns it off. +- **Evidence runs only the affected packages when no `affectedCommand` is declared (#1818).** `tool:test` derives one from a workspace-wide test command (`pnpm -r`, `npm --workspaces`, `turbo run test`), and `cleo doctor` proposes it. A change outside every package, or a test command with no affected form, still runs the whole suite. - **Less memory at CLI startup (#1812, #1820).** `cleo --version` and `--help` no longer load all of the core library, and loading `@cleocode/core` no longer evaluates js-tiktoken, the AWS Bedrock SDK or the ai SDK. - **Heap, worker and typecheck caps (#1808, #1810, #1824).** An inherited `NODE_OPTIONS` heap, worker count or package concurrency no longer multiplies an evidence run's memory, and typecheck and lint slots are sized from RAM and respond to memory pressure. From e4385d071492e9ffb687d5e3b5427ee51ef005c2 Mon Sep 17 00:00:00 2001 From: Keaton Hoskins Date: Sat, 3 Oct 2026 20:13:26 -0700 Subject: [PATCH 5/6] chore(release): v2026.10.4 notes: #1826 recovery line carries the T13172 known limit team-p0-startup verified --reconcile recovers stranded tasks and memory on 2026.10.3, with one silent-loss case (T13172): a task created after upgrading can take an old task's id, and that old task is not copied. The line now says so, tells users who created tasks after upgrading to wait for the fix, and to keep .cleo/tasks.db. CHANGELOG body still equals meta.releaseNotes. Co-Authored-By: Claude Opus 5.5 --- .cleo/release/v2026.10.4.plan.json | 2 +- CHANGELOG.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.cleo/release/v2026.10.4.plan.json b/.cleo/release/v2026.10.4.plan.json index 95963368e8..0cc96700ed 100644 --- a/.cleo/release/v2026.10.4.plan.json +++ b/.cleo/release/v2026.10.4.plan.json @@ -221,7 +221,7 @@ "meta": { "firstEverRelease": false, "archetype": "node", - "releaseNotes": "## v2026.10.4 — 2026-10-04\n\n> **Update now: run `cleo self-update`.** This hotfix fixes empty stores on busy Macs and stops CLEO from saturating the machine it runs on.\n\n### Highlights\n\n- **Empty stores on busy Macs are fixed (#1826).** On a busy Mac, opening a project that still had its legacy `tasks.db` and `brain.db` skipped the migration into `cleo.db`, so the project's tasks looked missing, and a write in that state left the legacy rows behind. If your tasks looked missing after opening a project on a busy Mac, run `cleo doctor superseded-store --reconcile --dry-run` in that project to see what is stranded, then `cleo doctor superseded-store --reconcile`. It is additive and verified, and your legacy files are never touched.\n- **The heavy-command hook now installs and governs (#1811).** `cleo init` and `cleo upgrade` install it for every agent harness in use, and `cleo doctor` and the briefing say when it is missing. In Claude Code's default, acceptEdits and dontAsk modes it queues the heavy commands your allow rules already approve through CLEO's machine-wide budget when it can tell that from their plain form; anything else gets a warning instead. It writes project-level files only and keeps them out of git (`.claude/settings.local.json`, `.codex/hooks.json` when CLEO created it, the opencode plugin), and it never edits a `.codex/hooks.json` your team already has. `cleo doctor heavy-command-hook --fix` installs it; `resources.heavyCommandHook: off` turns it off.\n- **Evidence runs only the affected packages when no `affectedCommand` is declared (#1818).** `tool:test` derives one from a workspace-wide test command (`pnpm -r`, `npm --workspaces`, `turbo run test`), and `cleo doctor` proposes it. A change outside every package, or a test command with no affected form, still runs the whole suite.\n- **Less memory at CLI startup (#1812, #1820).** `cleo --version` and `--help` no longer load all of the core library, and loading `@cleocode/core` no longer evaluates js-tiktoken, the AWS Bedrock SDK or the ai SDK.\n- **Heap, worker and typecheck caps (#1808, #1810, #1824).** An inherited `NODE_OPTIONS` heap, worker count or package concurrency no longer multiplies an evidence run's memory, and typecheck and lint slots are sized from RAM and respond to memory pressure.\n\n### Also in this release\n\n- `cleo login nexus` links and backs up the current project, lists your projects on a new machine, and `cleo cloud restore` takes a project name (#1797).\n- `cleo release open` reuses main's tested CI run for the release commit, and `--no-commit-plan` dispatches the merged plan by hash (#1816).\n- The release bump-PR's dispatched CI runs the version-only set instead of the whole suite (#1817).\n- The owned-process probe reads `ESRCH` as a process that is gone, which removes a flaky test failure (#1807).\n\n### Added\n\n- cleo login nexus sets up the account key and certifies the device, so the first push has nothing left to set up _(provenance: [T13100](https://github.com/kryptobaseddev/cleo/search?q=T13100&type=commits))_\n\n### Fixed\n\n- Nexus graph queries keep portable identity when projects move _(provenance: [T12472](https://github.com/kryptobaseddev/cleo/search?q=T12472&type=commits))_\n- Recognize ICO resources and supported JSONC configuration evidence _(provenance: [T13103](https://github.com/kryptobaseddev/cleo/search?q=T13103&type=commits))_\n- A vault restore keeps the snapshot's migration journal, so a restored store opens without stamping migrations it never ran _(provenance: [T13104](https://github.com/kryptobaseddev/cleo/search?q=T13104&type=commits))_\n- Dispatch token telemetry no longer writes a token_usage row when a command only reads _(provenance: [T13106](https://github.com/kryptobaseddev/cleo/search?q=T13106&type=commits))_\n- On a busy Mac, opening a legacy project no longer skips the exodus migration and serves an empty store _(provenance: [T13119](https://github.com/kryptobaseddev/cleo/search?q=T13119&type=commits), [T13150](https://github.com/kryptobaseddev/cleo/search?q=T13150&type=commits))_\n- An inherited NODE_OPTIONS heap, worker count or package concurrency no longer multiplies an evidence run's memory; the plan is reported _(provenance: [T13122](https://github.com/kryptobaseddev/cleo/search?q=T13122&type=commits))_\n- The heavy-tool bounds also catch MAKEFLAGS flag clusters, a dash-spelled workspace variable and a coloured npm warning _(provenance: [T13122](https://github.com/kryptobaseddev/cleo/search?q=T13122&type=commits))_\n- test-run evidence accepts summary and node --test counters, and a report without counts names the keys it needs _(provenance: [T13136](https://github.com/kryptobaseddev/cleo/search?q=T13136&type=commits))_\n", + "releaseNotes": "## v2026.10.4 — 2026-10-04\n\n> **Update now: run `cleo self-update`.** This hotfix fixes empty stores on busy Macs and stops CLEO from saturating the machine it runs on.\n\n### Highlights\n\n- **Empty stores on busy Macs are fixed (#1826).** On a busy Mac, opening a project that still had its legacy `tasks.db` and `brain.db` skipped the migration into `cleo.db`, so the project's tasks looked missing, and a write in that state left the legacy rows behind. To recover stranded tasks, run `cleo doctor superseded-store --reconcile --dry-run`, then `cleo doctor superseded-store --reconcile`. This copies stranded tasks and memory into cleo.db and never changes existing rows. Known limit (T13172): if you created tasks after upgrading to 2026.10.3, a new task may have taken an old task's id (usually T001). The old task with that id is not copied, the receipt does not say so, and its subtasks would attach to the new task. If you created tasks after upgrading, wait for the T13172 fix before reconciling. Either way, keep `.cleo/tasks.db`.\n- **The heavy-command hook now installs and governs (#1811).** `cleo init` and `cleo upgrade` install it for every agent harness in use, and `cleo doctor` and the briefing say when it is missing. In Claude Code's default, acceptEdits and dontAsk modes it queues the heavy commands your allow rules already approve through CLEO's machine-wide budget when it can tell that from their plain form; anything else gets a warning instead. It writes project-level files only and keeps them out of git (`.claude/settings.local.json`, `.codex/hooks.json` when CLEO created it, the opencode plugin), and it never edits a `.codex/hooks.json` your team already has. `cleo doctor heavy-command-hook --fix` installs it; `resources.heavyCommandHook: off` turns it off.\n- **Evidence runs only the affected packages when no `affectedCommand` is declared (#1818).** `tool:test` derives one from a workspace-wide test command (`pnpm -r`, `npm --workspaces`, `turbo run test`), and `cleo doctor` proposes it. A change outside every package, or a test command with no affected form, still runs the whole suite.\n- **Less memory at CLI startup (#1812, #1820).** `cleo --version` and `--help` no longer load all of the core library, and loading `@cleocode/core` no longer evaluates js-tiktoken, the AWS Bedrock SDK or the ai SDK.\n- **Heap, worker and typecheck caps (#1808, #1810, #1824).** An inherited `NODE_OPTIONS` heap, worker count or package concurrency no longer multiplies an evidence run's memory, and typecheck and lint slots are sized from RAM and respond to memory pressure.\n\n### Also in this release\n\n- `cleo login nexus` links and backs up the current project, lists your projects on a new machine, and `cleo cloud restore` takes a project name (#1797).\n- `cleo release open` reuses main's tested CI run for the release commit, and `--no-commit-plan` dispatches the merged plan by hash (#1816).\n- The release bump-PR's dispatched CI runs the version-only set instead of the whole suite (#1817).\n- The owned-process probe reads `ESRCH` as a process that is gone, which removes a flaky test failure (#1807).\n\n### Added\n\n- cleo login nexus sets up the account key and certifies the device, so the first push has nothing left to set up _(provenance: [T13100](https://github.com/kryptobaseddev/cleo/search?q=T13100&type=commits))_\n\n### Fixed\n\n- Nexus graph queries keep portable identity when projects move _(provenance: [T12472](https://github.com/kryptobaseddev/cleo/search?q=T12472&type=commits))_\n- Recognize ICO resources and supported JSONC configuration evidence _(provenance: [T13103](https://github.com/kryptobaseddev/cleo/search?q=T13103&type=commits))_\n- A vault restore keeps the snapshot's migration journal, so a restored store opens without stamping migrations it never ran _(provenance: [T13104](https://github.com/kryptobaseddev/cleo/search?q=T13104&type=commits))_\n- Dispatch token telemetry no longer writes a token_usage row when a command only reads _(provenance: [T13106](https://github.com/kryptobaseddev/cleo/search?q=T13106&type=commits))_\n- On a busy Mac, opening a legacy project no longer skips the exodus migration and serves an empty store _(provenance: [T13119](https://github.com/kryptobaseddev/cleo/search?q=T13119&type=commits), [T13150](https://github.com/kryptobaseddev/cleo/search?q=T13150&type=commits))_\n- An inherited NODE_OPTIONS heap, worker count or package concurrency no longer multiplies an evidence run's memory; the plan is reported _(provenance: [T13122](https://github.com/kryptobaseddev/cleo/search?q=T13122&type=commits))_\n- The heavy-tool bounds also catch MAKEFLAGS flag clusters, a dash-spelled workspace variable and a coloured npm warning _(provenance: [T13122](https://github.com/kryptobaseddev/cleo/search?q=T13122&type=commits))_\n- test-run evidence accepts summary and node --test counters, and a report without counts names the keys it needs _(provenance: [T13136](https://github.com/kryptobaseddev/cleo/search?q=T13136&type=commits))_\n", "changesetEntryCount": 9, "changesetIds": [ "t12472-nexus-portable-query", diff --git a/CHANGELOG.md b/CHANGELOG.md index e952399a1b..b025d9d276 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,7 +6,7 @@ ### Highlights -- **Empty stores on busy Macs are fixed (#1826).** On a busy Mac, opening a project that still had its legacy `tasks.db` and `brain.db` skipped the migration into `cleo.db`, so the project's tasks looked missing, and a write in that state left the legacy rows behind. If your tasks looked missing after opening a project on a busy Mac, run `cleo doctor superseded-store --reconcile --dry-run` in that project to see what is stranded, then `cleo doctor superseded-store --reconcile`. It is additive and verified, and your legacy files are never touched. +- **Empty stores on busy Macs are fixed (#1826).** On a busy Mac, opening a project that still had its legacy `tasks.db` and `brain.db` skipped the migration into `cleo.db`, so the project's tasks looked missing, and a write in that state left the legacy rows behind. To recover stranded tasks, run `cleo doctor superseded-store --reconcile --dry-run`, then `cleo doctor superseded-store --reconcile`. This copies stranded tasks and memory into cleo.db and never changes existing rows. Known limit (T13172): if you created tasks after upgrading to 2026.10.3, a new task may have taken an old task's id (usually T001). The old task with that id is not copied, the receipt does not say so, and its subtasks would attach to the new task. If you created tasks after upgrading, wait for the T13172 fix before reconciling. Either way, keep `.cleo/tasks.db`. - **The heavy-command hook now installs and governs (#1811).** `cleo init` and `cleo upgrade` install it for every agent harness in use, and `cleo doctor` and the briefing say when it is missing. In Claude Code's default, acceptEdits and dontAsk modes it queues the heavy commands your allow rules already approve through CLEO's machine-wide budget when it can tell that from their plain form; anything else gets a warning instead. It writes project-level files only and keeps them out of git (`.claude/settings.local.json`, `.codex/hooks.json` when CLEO created it, the opencode plugin), and it never edits a `.codex/hooks.json` your team already has. `cleo doctor heavy-command-hook --fix` installs it; `resources.heavyCommandHook: off` turns it off. - **Evidence runs only the affected packages when no `affectedCommand` is declared (#1818).** `tool:test` derives one from a workspace-wide test command (`pnpm -r`, `npm --workspaces`, `turbo run test`), and `cleo doctor` proposes it. A change outside every package, or a test command with no affected form, still runs the whole suite. - **Less memory at CLI startup (#1812, #1820).** `cleo --version` and `--help` no longer load all of the core library, and loading `@cleocode/core` no longer evaluates js-tiktoken, the AWS Bedrock SDK or the ai SDK. From 4c03e2dbe9602d085ab5b433274019a1585c7636 Mon Sep 17 00:00:00 2001 From: Keaton Hoskins Date: Sat, 3 Oct 2026 20:16:19 -0700 Subject: [PATCH 6/6] chore(release): v2026.10.4 notes: the T13172 limit applies after upgrading to 2026.10.2 or 2026.10.3 (review) The macOS pressure backend behind the deferral (#1777, T12981) first shipped in v2026.10.2 (its merge eb3f774ee is in v2026.10.2, not v2026.10.1), so 10.2 users are exposed too. Co-Authored-By: Claude Opus 5.5 --- .cleo/release/v2026.10.4.plan.json | 2 +- CHANGELOG.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.cleo/release/v2026.10.4.plan.json b/.cleo/release/v2026.10.4.plan.json index 0cc96700ed..387f208f24 100644 --- a/.cleo/release/v2026.10.4.plan.json +++ b/.cleo/release/v2026.10.4.plan.json @@ -221,7 +221,7 @@ "meta": { "firstEverRelease": false, "archetype": "node", - "releaseNotes": "## v2026.10.4 — 2026-10-04\n\n> **Update now: run `cleo self-update`.** This hotfix fixes empty stores on busy Macs and stops CLEO from saturating the machine it runs on.\n\n### Highlights\n\n- **Empty stores on busy Macs are fixed (#1826).** On a busy Mac, opening a project that still had its legacy `tasks.db` and `brain.db` skipped the migration into `cleo.db`, so the project's tasks looked missing, and a write in that state left the legacy rows behind. To recover stranded tasks, run `cleo doctor superseded-store --reconcile --dry-run`, then `cleo doctor superseded-store --reconcile`. This copies stranded tasks and memory into cleo.db and never changes existing rows. Known limit (T13172): if you created tasks after upgrading to 2026.10.3, a new task may have taken an old task's id (usually T001). The old task with that id is not copied, the receipt does not say so, and its subtasks would attach to the new task. If you created tasks after upgrading, wait for the T13172 fix before reconciling. Either way, keep `.cleo/tasks.db`.\n- **The heavy-command hook now installs and governs (#1811).** `cleo init` and `cleo upgrade` install it for every agent harness in use, and `cleo doctor` and the briefing say when it is missing. In Claude Code's default, acceptEdits and dontAsk modes it queues the heavy commands your allow rules already approve through CLEO's machine-wide budget when it can tell that from their plain form; anything else gets a warning instead. It writes project-level files only and keeps them out of git (`.claude/settings.local.json`, `.codex/hooks.json` when CLEO created it, the opencode plugin), and it never edits a `.codex/hooks.json` your team already has. `cleo doctor heavy-command-hook --fix` installs it; `resources.heavyCommandHook: off` turns it off.\n- **Evidence runs only the affected packages when no `affectedCommand` is declared (#1818).** `tool:test` derives one from a workspace-wide test command (`pnpm -r`, `npm --workspaces`, `turbo run test`), and `cleo doctor` proposes it. A change outside every package, or a test command with no affected form, still runs the whole suite.\n- **Less memory at CLI startup (#1812, #1820).** `cleo --version` and `--help` no longer load all of the core library, and loading `@cleocode/core` no longer evaluates js-tiktoken, the AWS Bedrock SDK or the ai SDK.\n- **Heap, worker and typecheck caps (#1808, #1810, #1824).** An inherited `NODE_OPTIONS` heap, worker count or package concurrency no longer multiplies an evidence run's memory, and typecheck and lint slots are sized from RAM and respond to memory pressure.\n\n### Also in this release\n\n- `cleo login nexus` links and backs up the current project, lists your projects on a new machine, and `cleo cloud restore` takes a project name (#1797).\n- `cleo release open` reuses main's tested CI run for the release commit, and `--no-commit-plan` dispatches the merged plan by hash (#1816).\n- The release bump-PR's dispatched CI runs the version-only set instead of the whole suite (#1817).\n- The owned-process probe reads `ESRCH` as a process that is gone, which removes a flaky test failure (#1807).\n\n### Added\n\n- cleo login nexus sets up the account key and certifies the device, so the first push has nothing left to set up _(provenance: [T13100](https://github.com/kryptobaseddev/cleo/search?q=T13100&type=commits))_\n\n### Fixed\n\n- Nexus graph queries keep portable identity when projects move _(provenance: [T12472](https://github.com/kryptobaseddev/cleo/search?q=T12472&type=commits))_\n- Recognize ICO resources and supported JSONC configuration evidence _(provenance: [T13103](https://github.com/kryptobaseddev/cleo/search?q=T13103&type=commits))_\n- A vault restore keeps the snapshot's migration journal, so a restored store opens without stamping migrations it never ran _(provenance: [T13104](https://github.com/kryptobaseddev/cleo/search?q=T13104&type=commits))_\n- Dispatch token telemetry no longer writes a token_usage row when a command only reads _(provenance: [T13106](https://github.com/kryptobaseddev/cleo/search?q=T13106&type=commits))_\n- On a busy Mac, opening a legacy project no longer skips the exodus migration and serves an empty store _(provenance: [T13119](https://github.com/kryptobaseddev/cleo/search?q=T13119&type=commits), [T13150](https://github.com/kryptobaseddev/cleo/search?q=T13150&type=commits))_\n- An inherited NODE_OPTIONS heap, worker count or package concurrency no longer multiplies an evidence run's memory; the plan is reported _(provenance: [T13122](https://github.com/kryptobaseddev/cleo/search?q=T13122&type=commits))_\n- The heavy-tool bounds also catch MAKEFLAGS flag clusters, a dash-spelled workspace variable and a coloured npm warning _(provenance: [T13122](https://github.com/kryptobaseddev/cleo/search?q=T13122&type=commits))_\n- test-run evidence accepts summary and node --test counters, and a report without counts names the keys it needs _(provenance: [T13136](https://github.com/kryptobaseddev/cleo/search?q=T13136&type=commits))_\n", + "releaseNotes": "## v2026.10.4 — 2026-10-04\n\n> **Update now: run `cleo self-update`.** This hotfix fixes empty stores on busy Macs and stops CLEO from saturating the machine it runs on.\n\n### Highlights\n\n- **Empty stores on busy Macs are fixed (#1826).** On a busy Mac, opening a project that still had its legacy `tasks.db` and `brain.db` skipped the migration into `cleo.db`, so the project's tasks looked missing, and a write in that state left the legacy rows behind. To recover stranded tasks, run `cleo doctor superseded-store --reconcile --dry-run`, then `cleo doctor superseded-store --reconcile`. This copies stranded tasks and memory into cleo.db and never changes existing rows. Known limit (T13172): if you created tasks after upgrading to 2026.10.2 or 2026.10.3, a new task may have taken an old task's id (usually T001). The old task with that id is not copied, the receipt does not say so, and its subtasks would attach to the new task. If you created tasks after upgrading, wait for the T13172 fix before reconciling. Either way, keep `.cleo/tasks.db`.\n- **The heavy-command hook now installs and governs (#1811).** `cleo init` and `cleo upgrade` install it for every agent harness in use, and `cleo doctor` and the briefing say when it is missing. In Claude Code's default, acceptEdits and dontAsk modes it queues the heavy commands your allow rules already approve through CLEO's machine-wide budget when it can tell that from their plain form; anything else gets a warning instead. It writes project-level files only and keeps them out of git (`.claude/settings.local.json`, `.codex/hooks.json` when CLEO created it, the opencode plugin), and it never edits a `.codex/hooks.json` your team already has. `cleo doctor heavy-command-hook --fix` installs it; `resources.heavyCommandHook: off` turns it off.\n- **Evidence runs only the affected packages when no `affectedCommand` is declared (#1818).** `tool:test` derives one from a workspace-wide test command (`pnpm -r`, `npm --workspaces`, `turbo run test`), and `cleo doctor` proposes it. A change outside every package, or a test command with no affected form, still runs the whole suite.\n- **Less memory at CLI startup (#1812, #1820).** `cleo --version` and `--help` no longer load all of the core library, and loading `@cleocode/core` no longer evaluates js-tiktoken, the AWS Bedrock SDK or the ai SDK.\n- **Heap, worker and typecheck caps (#1808, #1810, #1824).** An inherited `NODE_OPTIONS` heap, worker count or package concurrency no longer multiplies an evidence run's memory, and typecheck and lint slots are sized from RAM and respond to memory pressure.\n\n### Also in this release\n\n- `cleo login nexus` links and backs up the current project, lists your projects on a new machine, and `cleo cloud restore` takes a project name (#1797).\n- `cleo release open` reuses main's tested CI run for the release commit, and `--no-commit-plan` dispatches the merged plan by hash (#1816).\n- The release bump-PR's dispatched CI runs the version-only set instead of the whole suite (#1817).\n- The owned-process probe reads `ESRCH` as a process that is gone, which removes a flaky test failure (#1807).\n\n### Added\n\n- cleo login nexus sets up the account key and certifies the device, so the first push has nothing left to set up _(provenance: [T13100](https://github.com/kryptobaseddev/cleo/search?q=T13100&type=commits))_\n\n### Fixed\n\n- Nexus graph queries keep portable identity when projects move _(provenance: [T12472](https://github.com/kryptobaseddev/cleo/search?q=T12472&type=commits))_\n- Recognize ICO resources and supported JSONC configuration evidence _(provenance: [T13103](https://github.com/kryptobaseddev/cleo/search?q=T13103&type=commits))_\n- A vault restore keeps the snapshot's migration journal, so a restored store opens without stamping migrations it never ran _(provenance: [T13104](https://github.com/kryptobaseddev/cleo/search?q=T13104&type=commits))_\n- Dispatch token telemetry no longer writes a token_usage row when a command only reads _(provenance: [T13106](https://github.com/kryptobaseddev/cleo/search?q=T13106&type=commits))_\n- On a busy Mac, opening a legacy project no longer skips the exodus migration and serves an empty store _(provenance: [T13119](https://github.com/kryptobaseddev/cleo/search?q=T13119&type=commits), [T13150](https://github.com/kryptobaseddev/cleo/search?q=T13150&type=commits))_\n- An inherited NODE_OPTIONS heap, worker count or package concurrency no longer multiplies an evidence run's memory; the plan is reported _(provenance: [T13122](https://github.com/kryptobaseddev/cleo/search?q=T13122&type=commits))_\n- The heavy-tool bounds also catch MAKEFLAGS flag clusters, a dash-spelled workspace variable and a coloured npm warning _(provenance: [T13122](https://github.com/kryptobaseddev/cleo/search?q=T13122&type=commits))_\n- test-run evidence accepts summary and node --test counters, and a report without counts names the keys it needs _(provenance: [T13136](https://github.com/kryptobaseddev/cleo/search?q=T13136&type=commits))_\n", "changesetEntryCount": 9, "changesetIds": [ "t12472-nexus-portable-query", diff --git a/CHANGELOG.md b/CHANGELOG.md index b025d9d276..f926b28107 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,7 +6,7 @@ ### Highlights -- **Empty stores on busy Macs are fixed (#1826).** On a busy Mac, opening a project that still had its legacy `tasks.db` and `brain.db` skipped the migration into `cleo.db`, so the project's tasks looked missing, and a write in that state left the legacy rows behind. To recover stranded tasks, run `cleo doctor superseded-store --reconcile --dry-run`, then `cleo doctor superseded-store --reconcile`. This copies stranded tasks and memory into cleo.db and never changes existing rows. Known limit (T13172): if you created tasks after upgrading to 2026.10.3, a new task may have taken an old task's id (usually T001). The old task with that id is not copied, the receipt does not say so, and its subtasks would attach to the new task. If you created tasks after upgrading, wait for the T13172 fix before reconciling. Either way, keep `.cleo/tasks.db`. +- **Empty stores on busy Macs are fixed (#1826).** On a busy Mac, opening a project that still had its legacy `tasks.db` and `brain.db` skipped the migration into `cleo.db`, so the project's tasks looked missing, and a write in that state left the legacy rows behind. To recover stranded tasks, run `cleo doctor superseded-store --reconcile --dry-run`, then `cleo doctor superseded-store --reconcile`. This copies stranded tasks and memory into cleo.db and never changes existing rows. Known limit (T13172): if you created tasks after upgrading to 2026.10.2 or 2026.10.3, a new task may have taken an old task's id (usually T001). The old task with that id is not copied, the receipt does not say so, and its subtasks would attach to the new task. If you created tasks after upgrading, wait for the T13172 fix before reconciling. Either way, keep `.cleo/tasks.db`. - **The heavy-command hook now installs and governs (#1811).** `cleo init` and `cleo upgrade` install it for every agent harness in use, and `cleo doctor` and the briefing say when it is missing. In Claude Code's default, acceptEdits and dontAsk modes it queues the heavy commands your allow rules already approve through CLEO's machine-wide budget when it can tell that from their plain form; anything else gets a warning instead. It writes project-level files only and keeps them out of git (`.claude/settings.local.json`, `.codex/hooks.json` when CLEO created it, the opencode plugin), and it never edits a `.codex/hooks.json` your team already has. `cleo doctor heavy-command-hook --fix` installs it; `resources.heavyCommandHook: off` turns it off. - **Evidence runs only the affected packages when no `affectedCommand` is declared (#1818).** `tool:test` derives one from a workspace-wide test command (`pnpm -r`, `npm --workspaces`, `turbo run test`), and `cleo doctor` proposes it. A change outside every package, or a test command with no affected form, still runs the whole suite. - **Less memory at CLI startup (#1812, #1820).** `cleo --version` and `--help` no longer load all of the core library, and loading `@cleocode/core` no longer evaluates js-tiktoken, the AWS Bedrock SDK or the ai SDK.