From c569057e089ba721ccb45d1f984c0112f031037d Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Sun, 23 Aug 2026 02:03:51 +0000 Subject: [PATCH] =?UTF-8?q?=F0=9F=A6=8B=20New=20version=20release?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .changeset/ingest-acl-contract-fence.md | 33 ------------------ ...AI.SmoothOperator.Server.AspNetCore.csproj | 2 +- ...ooAI.SmoothOperator.Server.Postgres.csproj | 2 +- .../src/SmooAI.SmoothOperator.Server.csproj | 2 +- examples/web-chat/CHANGELOG.md | 7 ++++ examples/web-chat/package.json | 2 +- go/version.go | 2 +- python/pyproject.toml | 2 +- python/server/pyproject.toml | 2 +- rust/Cargo.lock | 16 ++++----- rust/Cargo.toml | 2 +- rust/adapters/backplane-nats/Cargo.toml | 2 +- rust/adapters/backplane-redis/Cargo.toml | 2 +- rust/adapters/dynamodb/Cargo.toml | 4 +-- rust/adapters/in-memory/Cargo.toml | 2 +- rust/adapters/postgres/Cargo.toml | 4 +-- rust/ingestion/Cargo.toml | 2 +- rust/smooth-operator-server/Cargo.toml | 14 ++++---- rust/smooth-operator/Cargo.toml | 2 +- typescript/CHANGELOG.md | 34 +++++++++++++++++++ typescript/package.json | 2 +- 21 files changed, 74 insertions(+), 66 deletions(-) delete mode 100644 .changeset/ingest-acl-contract-fence.md diff --git a/.changeset/ingest-acl-contract-fence.md b/.changeset/ingest-acl-contract-fence.md deleted file mode 100644 index 50ab832a..00000000 --- a/.changeset/ingest-acl-contract-fence.md +++ /dev/null @@ -1,33 +0,0 @@ ---- -"@smooai/smooth-operator": patch ---- - -test: fence the ingest→ACL chain at the pipeline seam, not just the GitHub connector - -The guarantee that a connector's document ACL survives ingestion — `RawDocument::acl` -→ chunk → structured `DocAcl` → `AclKnowledgeStore` side table → `AclReader` — was -asserted end to end in exactly one place: `github_connector.rs`. That test is real, but -it is a *connector* test. Delete or rewrite the GitHub connector and the ingest half of -G3 loses its only fence, silently, with the ingestion contract test still green. - -`ingestion_contract.rs::ingested_acls_gate_retrieval_for_every_connector` asserts the -same chain at the pipeline seam over a `MockConnector`, so it holds for every connector -present and future: a document ingested for `group-eng` is readable by a principal -carrying that group and returns **nothing** for `group-fin` or for anonymous, while a -document ingested with no ACL stays org-public. Each negative assertion is paired with -the entitled-principal positive control on the same query, so a pipeline that stored -nothing cannot satisfy "nothing leaked" vacuously — the failure mode this repo has -shipped before. - -Verified red before green: with `DocAcl::for_groups(...).attach_to(document)` reverted -in `pipeline.rs`, the new test fails with `group-fin must not read the group-eng doc, -got 1 hits` — the exact G3 cross-user leak — while the pre-existing contract test stays -green, which is what made the gap invisible. - -No production behavior changes. `docs/Planning/Feature Gaps.md` §G1/§G2/§G9 are updated -to record what actually shipped (the `Connector` seam, `MockConnector`, and the file / -web / github connectors landed some time ago and were never marked), the `pull` → -`Vec` deviation from the planned `Stream` and why it should be -re-shaped before the SaaS connectors rather than after, and what remains: the connector -long tail, format extraction, and the nightly job that would actually run the gated -`external` tier. diff --git a/dotnet/server/aspnetcore/SmooAI.SmoothOperator.Server.AspNetCore.csproj b/dotnet/server/aspnetcore/SmooAI.SmoothOperator.Server.AspNetCore.csproj index 58b5f146..f8869a8f 100644 --- a/dotnet/server/aspnetcore/SmooAI.SmoothOperator.Server.AspNetCore.csproj +++ b/dotnet/server/aspnetcore/SmooAI.SmoothOperator.Server.AspNetCore.csproj @@ -15,7 +15,7 @@ attribute. (Keep the element-form version out of comments: the sync regex replaces the first element-form match in the file.) --> SmooAI.SmoothOperator.Server.AspNetCore - 1.57.0 + 1.57.1 SmooAI ai;agent;llm;chat;smooth-operator;server;aspnetcore;websocket;smooai MIT diff --git a/dotnet/server/postgres/src/SmooAI.SmoothOperator.Server.Postgres.csproj b/dotnet/server/postgres/src/SmooAI.SmoothOperator.Server.Postgres.csproj index 2a6dbbb1..150802d7 100644 --- a/dotnet/server/postgres/src/SmooAI.SmoothOperator.Server.Postgres.csproj +++ b/dotnet/server/postgres/src/SmooAI.SmoothOperator.Server.Postgres.csproj @@ -15,7 +15,7 @@ attribute. (Keep the element-form version out of comments: the sync regex replaces the first element-form match in the file.) --> SmooAI.SmoothOperator.Server.Postgres - 1.57.0 + 1.57.1 SmooAI ai;agent;llm;chat;smooth-operator;server;postgres;pgvector;smooai MIT diff --git a/dotnet/server/src/SmooAI.SmoothOperator.Server.csproj b/dotnet/server/src/SmooAI.SmoothOperator.Server.csproj index 2daea3c2..596e4292 100644 --- a/dotnet/server/src/SmooAI.SmoothOperator.Server.csproj +++ b/dotnet/server/src/SmooAI.SmoothOperator.Server.csproj @@ -14,7 +14,7 @@ scripts/sync-versions.mjs (do NOT confuse with the SmooAI.SmoothOperator.Core PackageReference version below, which tracks the separately-published engine). --> SmooAI.SmoothOperator.Server - 1.57.0 + 1.57.1 SmooAI ai;agent;llm;chat;smooth-operator;server;websocket;smooai MIT diff --git a/examples/web-chat/CHANGELOG.md b/examples/web-chat/CHANGELOG.md index cf939328..5f95e68c 100644 --- a/examples/web-chat/CHANGELOG.md +++ b/examples/web-chat/CHANGELOG.md @@ -1,5 +1,12 @@ # @smooai/smooth-operator-web-chat-example +## 0.0.111 + +### Patch Changes + +- Updated dependencies [3f25540] + - @smooai/smooth-operator@1.57.1 + ## 0.0.110 ### Patch Changes diff --git a/examples/web-chat/package.json b/examples/web-chat/package.json index bba805e7..183b9515 100644 --- a/examples/web-chat/package.json +++ b/examples/web-chat/package.json @@ -1,6 +1,6 @@ { "name": "@smooai/smooth-operator-web-chat-example", - "version": "0.0.110", + "version": "0.0.111", "private": true, "description": "A smooth-web-like Vite + React chat client that drives a running smooth-operator server over its WebSocket protocol — token streaming, inline tool-call/result blocks, a conversation sidebar, and oldest-first history, all on top of the published @smooai/smooth-operator SDK.", "type": "module", diff --git a/go/version.go b/go/version.go index 7b954db6..06f305d0 100644 --- a/go/version.go +++ b/go/version.go @@ -5,4 +5,4 @@ package e2e // language artifacts. The real Go "publish" is a git tag (go/v); this // constant is the anchor that scripts/sync-versions.mjs keeps in sync with the // canonical npm version on every changeset release. -const Version = "1.57.0" +const Version = "1.57.1" diff --git a/python/pyproject.toml b/python/pyproject.toml index 0d20a01c..14da4279 100644 --- a/python/pyproject.toml +++ b/python/pyproject.toml @@ -1,6 +1,6 @@ [project] name = "smooai-smooth-operator" -version = "1.57.0" +version = "1.57.1" description = "Python protocol types and native async WebSocket client for the smooth-operator protocol. Generated from the language-neutral JSON Schemas in spec/." readme = "README.md" license = { text = "MIT" } diff --git a/python/server/pyproject.toml b/python/server/pyproject.toml index 37e2293d..e92a0516 100644 --- a/python/server/pyproject.toml +++ b/python/server/pyproject.toml @@ -1,6 +1,6 @@ [project] name = "smooai-smooth-operator-server" -version = "1.57.0" +version = "1.57.1" description = "Native async WebSocket server for the smooth-operator protocol — parity with the Rust and C# reference servers, consuming the in-process smooai-smooth-operator-core engine." readme = "README.md" license = { text = "MIT" } diff --git a/rust/Cargo.lock b/rust/Cargo.lock index 186244ef..c4ee5765 100644 --- a/rust/Cargo.lock +++ b/rust/Cargo.lock @@ -4099,7 +4099,7 @@ checksum = "8ed6a63f02c8539c91a8685a86f4099661ba3da017932f6ebbea6de3f0fa7c90" [[package]] name = "smooai-smooth-operator" -version = "1.57.0" +version = "1.57.1" dependencies = [ "anyhow", "async-trait", @@ -4133,7 +4133,7 @@ dependencies = [ [[package]] name = "smooai-smooth-operator-adapter-backplane-nats" -version = "1.57.0" +version = "1.57.1" dependencies = [ "anyhow", "async-nats", @@ -4149,7 +4149,7 @@ dependencies = [ [[package]] name = "smooai-smooth-operator-adapter-backplane-redis" -version = "1.57.0" +version = "1.57.1" dependencies = [ "anyhow", "async-trait", @@ -4165,7 +4165,7 @@ dependencies = [ [[package]] name = "smooai-smooth-operator-adapter-dynamodb" -version = "1.57.0" +version = "1.57.1" dependencies = [ "anyhow", "async-trait", @@ -4186,7 +4186,7 @@ dependencies = [ [[package]] name = "smooai-smooth-operator-adapter-memory" -version = "1.57.0" +version = "1.57.1" dependencies = [ "anyhow", "async-trait", @@ -4199,7 +4199,7 @@ dependencies = [ [[package]] name = "smooai-smooth-operator-adapter-postgres" -version = "1.57.0" +version = "1.57.1" dependencies = [ "anyhow", "async-trait", @@ -4290,7 +4290,7 @@ dependencies = [ [[package]] name = "smooai-smooth-operator-ingestion" -version = "1.57.0" +version = "1.57.1" dependencies = [ "anyhow", "async-trait", @@ -4337,7 +4337,7 @@ dependencies = [ [[package]] name = "smooai-smooth-operator-server" -version = "1.57.0" +version = "1.57.1" dependencies = [ "anyhow", "async-trait", diff --git a/rust/Cargo.toml b/rust/Cargo.toml index 5f032a38..9c234d08 100644 --- a/rust/Cargo.toml +++ b/rust/Cargo.toml @@ -40,7 +40,7 @@ smooai-smooth-operator-core = "1.10.0" # Intra-workspace dep on the reference lib carries its version so the adapters / # ingestion / server that depend on it are publishable (path = local dev, # version = the crates.io requirement). -smooth-operator = { package = "smooai-smooth-operator", path = "smooth-operator", version = "1.57.0" } +smooth-operator = { package = "smooai-smooth-operator", path = "smooth-operator", version = "1.57.1" } async-trait = "0.1" anyhow = "1" diff --git a/rust/adapters/backplane-nats/Cargo.toml b/rust/adapters/backplane-nats/Cargo.toml index 2f1564cc..6cb9e0e2 100644 --- a/rust/adapters/backplane-nats/Cargo.toml +++ b/rust/adapters/backplane-nats/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "smooai-smooth-operator-adapter-backplane-nats" -version = "1.57.0" +version = "1.57.1" edition.workspace = true license.workspace = true repository.workspace = true diff --git a/rust/adapters/backplane-redis/Cargo.toml b/rust/adapters/backplane-redis/Cargo.toml index cf0599bb..55d05ec1 100644 --- a/rust/adapters/backplane-redis/Cargo.toml +++ b/rust/adapters/backplane-redis/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "smooai-smooth-operator-adapter-backplane-redis" -version = "1.57.0" +version = "1.57.1" edition.workspace = true license.workspace = true repository.workspace = true diff --git a/rust/adapters/dynamodb/Cargo.toml b/rust/adapters/dynamodb/Cargo.toml index 771c5c5d..ff8a13d7 100644 --- a/rust/adapters/dynamodb/Cargo.toml +++ b/rust/adapters/dynamodb/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "smooai-smooth-operator-adapter-dynamodb" -version = "1.57.0" +version = "1.57.1" edition.workspace = true license.workspace = true repository.workspace = true @@ -19,7 +19,7 @@ s3-vectors = ["dep:aws-sdk-s3vectors", "dep:aws-smithy-types"] smooth-operator = { workspace = true } smooai-smooth-operator-core = { workspace = true } # IndexingStore / IndexingRun for the persistent admin indexing-runs store. -smooai-smooth-operator-ingestion = { path = "../../ingestion", version = "1.57.0" } +smooai-smooth-operator-ingestion = { path = "../../ingestion", version = "1.57.1" } async-trait = { workspace = true } anyhow = { workspace = true } chrono = { workspace = true } diff --git a/rust/adapters/in-memory/Cargo.toml b/rust/adapters/in-memory/Cargo.toml index be016984..4aaffd0a 100644 --- a/rust/adapters/in-memory/Cargo.toml +++ b/rust/adapters/in-memory/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "smooai-smooth-operator-adapter-memory" -version = "1.57.0" +version = "1.57.1" edition.workspace = true license.workspace = true repository.workspace = true diff --git a/rust/adapters/postgres/Cargo.toml b/rust/adapters/postgres/Cargo.toml index a10d76c1..207df73f 100644 --- a/rust/adapters/postgres/Cargo.toml +++ b/rust/adapters/postgres/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "smooai-smooth-operator-adapter-postgres" -version = "1.57.0" +version = "1.57.1" edition.workspace = true license.workspace = true repository.workspace = true @@ -15,7 +15,7 @@ smooth-operator = { workspace = true } # `postgres` feature pulls in PostgresCheckpointStore (sync r2d2 path). smooai-smooth-operator-core = { workspace = true, features = ["postgres"] } # IndexingStore / IndexingRun for the persistent admin indexing-runs store. -smooai-smooth-operator-ingestion = { path = "../../ingestion", version = "1.57.0" } +smooai-smooth-operator-ingestion = { path = "../../ingestion", version = "1.57.1" } async-trait = { workspace = true } anyhow = { workspace = true } chrono = { workspace = true } diff --git a/rust/ingestion/Cargo.toml b/rust/ingestion/Cargo.toml index a5fac764..d863b450 100644 --- a/rust/ingestion/Cargo.toml +++ b/rust/ingestion/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "smooai-smooth-operator-ingestion" -version = "1.57.0" +version = "1.57.1" edition.workspace = true license.workspace = true repository.workspace = true diff --git a/rust/smooth-operator-server/Cargo.toml b/rust/smooth-operator-server/Cargo.toml index af12444d..3e219651 100644 --- a/rust/smooth-operator-server/Cargo.toml +++ b/rust/smooth-operator-server/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "smooai-smooth-operator-server" -version = "1.57.0" +version = "1.57.1" edition.workspace = true license.workspace = true repository.workspace = true @@ -35,22 +35,22 @@ smooth-operator = { workspace = true } smooai-smooth-operator-core = { workspace = true } # In-memory storage + backplane — ALWAYS included. The local-flavor default and # the lean (`--no-default-features`) build run entirely on these. -smooai-smooth-operator-adapter-memory = { path = "../adapters/in-memory", version = "1.57.0" } +smooai-smooth-operator-adapter-memory = { path = "../adapters/in-memory", version = "1.57.1" } # Persistent storage + admin-store backends, selected at runtime to match the # configured storage backend (Postgres / DynamoDB; default in-memory). Optional: # gated behind the `postgres` / `dynamodb` features so a lean local/embed build # can exclude tokio-postgres / the AWS SDK. The `postgres` crate also provides the # gateway-backed embedder/reranker, so the `postgres` feature additionally enables # the semantic-retrieval path in `embedder.rs` / `reranker.rs`. -smooai-smooth-operator-adapter-postgres = { path = "../adapters/postgres", version = "1.57.0", optional = true } -smooai-smooth-operator-adapter-dynamodb = { path = "../adapters/dynamodb", version = "1.57.0", optional = true } +smooai-smooth-operator-adapter-postgres = { path = "../adapters/postgres", version = "1.57.1", optional = true } +smooai-smooth-operator-adapter-dynamodb = { path = "../adapters/dynamodb", version = "1.57.1", optional = true } # Distributed Backplane backends for horizontal scale-out, selected at runtime # via SMOOTH_AGENT_BACKPLANE (default in-memory / single-process). Optional: gated # behind the `redis` / `nats` features so a lean build excludes their drivers. -smooai-smooth-operator-adapter-backplane-redis = { path = "../adapters/backplane-redis", version = "1.57.0", optional = true } -smooai-smooth-operator-adapter-backplane-nats = { path = "../adapters/backplane-nats", version = "1.57.0", optional = true } +smooai-smooth-operator-adapter-backplane-redis = { path = "../adapters/backplane-redis", version = "1.57.1", optional = true } +smooai-smooth-operator-adapter-backplane-nats = { path = "../adapters/backplane-nats", version = "1.57.1", optional = true } # Admin API surfaces indexing-run status via the ingestion crate's IndexingStore. -smooai-smooth-operator-ingestion = { path = "../ingestion", version = "1.57.0" } +smooai-smooth-operator-ingestion = { path = "../ingestion", version = "1.57.1" } async-trait = { workspace = true } anyhow = { workspace = true } diff --git a/rust/smooth-operator/Cargo.toml b/rust/smooth-operator/Cargo.toml index 229a3d1c..9e4e230d 100644 --- a/rust/smooth-operator/Cargo.toml +++ b/rust/smooth-operator/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "smooai-smooth-operator" -version = "1.57.0" +version = "1.57.1" edition.workspace = true license.workspace = true repository.workspace = true diff --git a/typescript/CHANGELOG.md b/typescript/CHANGELOG.md index 48abbc3e..21d7706f 100644 --- a/typescript/CHANGELOG.md +++ b/typescript/CHANGELOG.md @@ -1,5 +1,39 @@ # @smooai/smooth-operator +## 1.57.1 + +### Patch Changes + +- 3f25540: test: fence the ingest→ACL chain at the pipeline seam, not just the GitHub connector + + The guarantee that a connector's document ACL survives ingestion — `RawDocument::acl` + → chunk → structured `DocAcl` → `AclKnowledgeStore` side table → `AclReader` — was + asserted end to end in exactly one place: `github_connector.rs`. That test is real, but + it is a _connector_ test. Delete or rewrite the GitHub connector and the ingest half of + G3 loses its only fence, silently, with the ingestion contract test still green. + + `ingestion_contract.rs::ingested_acls_gate_retrieval_for_every_connector` asserts the + same chain at the pipeline seam over a `MockConnector`, so it holds for every connector + present and future: a document ingested for `group-eng` is readable by a principal + carrying that group and returns **nothing** for `group-fin` or for anonymous, while a + document ingested with no ACL stays org-public. Each negative assertion is paired with + the entitled-principal positive control on the same query, so a pipeline that stored + nothing cannot satisfy "nothing leaked" vacuously — the failure mode this repo has + shipped before. + + Verified red before green: with `DocAcl::for_groups(...).attach_to(document)` reverted + in `pipeline.rs`, the new test fails with `group-fin must not read the group-eng doc, +got 1 hits` — the exact G3 cross-user leak — while the pre-existing contract test stays + green, which is what made the gap invisible. + + No production behavior changes. `docs/Planning/Feature Gaps.md` §G1/§G2/§G9 are updated + to record what actually shipped (the `Connector` seam, `MockConnector`, and the file / + web / github connectors landed some time ago and were never marked), the `pull` → + `Vec` deviation from the planned `Stream` and why it should be + re-shaped before the SaaS connectors rather than after, and what remains: the connector + long tail, format extraction, and the nightly job that would actually run the gated + `external` tier. + ## 1.57.0 ### Minor Changes diff --git a/typescript/package.json b/typescript/package.json index 7e038ae2..5b39df46 100644 --- a/typescript/package.json +++ b/typescript/package.json @@ -1,6 +1,6 @@ { "name": "@smooai/smooth-operator", - "version": "1.57.0", + "version": "1.57.1", "description": "TypeScript SDK for the smooth-operator WebSocket protocol: the native client (`.`), React bindings (`./react`), and the embeddable web-component chat widget (`./widget`). Generated from the language-neutral JSON Schemas in spec/.", "license": "MIT", "type": "module",