Skip to content

feat: TMCRA 1.0.0-rc.1 local workspace (scanner adjudication pending) - #4

Draft
reshuibuduo wants to merge 5 commits into
mainfrom
codex/memory-controls-continuity
Draft

feat: TMCRA 1.0.0-rc.1 local workspace (scanner adjudication pending)#4
reshuibuduo wants to merge 5 commits into
mainfrom
codex/memory-controls-continuity

Conversation

@reshuibuduo

@reshuibuduo reshuibuduo commented Sep 5, 2026

Copy link
Copy Markdown
Owner

Summary

Unified TMCRA 1.0.0-rc.1 candidate: memory workspace, local Writer/organizer settings, knowledge/graph views, session modes, task continuity, bounded evidence budgets, and interactive chat confirmation for exact-source corrections.

Account-free Windows x64 installation bundles the actual backend and verified inventory. Install-Local.cmd / tmcra_open_local_install prepare private Python, pinned models and a local identity. Setup has no API credential and exposes no memory actions; after installation the host must restart. First-time downloads need internet, while memory runtime does not need TMCRA servers/accounts.

Verification

The Codex and Claude Code contract suites pass, including 15 lifecycle scenarios, 7 authorization flows, confirmation/no-write-before-consent, local/cloud isolation and account-free setup. The 235-entry release archive and binary/runtime integrity checks pass. Latest code tests: https://github.com/reshuibuduo/tmcra-plugin-codex/actions/runs/33988900575

Publication blocked by scanner

The official HOL/Cisco job still fails: https://github.com/reshuibuduo/tmcra-plugin-codex/actions/runs/33988900546
The native detector misclassifies PyTorch Module.eval() in eight bundled Python files. The current Action additionally flags synthetic test-fixture credentials because repository test exclusions are not trusted by default. Local CLI and raw CI reports therefore differ; neither is a passing severity gate. No new exclusions, baseline suppressions, or threshold reductions were introduced.

Reviewed source paths and limitations: https://github.com/reshuibuduo/tmcra-plugin-codex/blob/codex/memory-controls-continuity/docs/security-scanner-review.md

This PR and three dependent Codex/Claude catalog refreshes remain draft pending an upstream detector fix or maintainer adjudication. No standalone Codex 1.0.0-rc.1 tag/release has been published. Main TMCRA runtime, DSH and generic MCP are separate 1.0.0-rc.1 releases.

Local-model acceptance is partial

Synthetic CPU ingest/raw recall passed; complex compilation timed out at 600 seconds. Organizer/full-service restart, latest memory-limit settings and balanced/high-tier hardware acceptance remain pending. Current laptop lacks approximately 6.3 GiB of free RAM for the next full run. A cloud-hosted Agent main model may still receive recalled evidence. Production services, real user memory and currently installed plugins were not changed.

@reshuibuduo reshuibuduo changed the title Release 1.0.0-rc.1: redesigned workspace and one-click independent local memory feat: TMCRA 1.0.0-rc.1 local workspace (scanner adjudication pending) Sep 5, 2026
@reshuibuduo
reshuibuduo marked this pull request as draft September 5, 2026 20:14

Copy link
Copy Markdown
Owner Author

Upstream detector fix submitted: hashgraph-online/hol-guard#2805

The patch removes the eight Python inference-method false positives on the unchanged bundled runtime. Local validation: 186 related tests passed on Python 3.12; 93 code-quality tests passed on Python 3.10. Genuine dynamic-evaluation and JavaScript/TypeScript cases retain high-severity findings.

Upstream GitHub Actions currently require maintainer approval. This release stays a draft: the official pinned Action is unchanged, the score-80/high-severity gate and Cisco scanning remain in place, and synthetic test-credential findings still need separate resolution. This local regression result is not a passing official marketplace scan.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant