Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,13 @@ MEMNET_SESSION_TTL_MINUTES=60
# TCP frame size cap (default 4 MiB):
# MEMNET_SERVE_MAX_FRAME_BYTES=4194304

# Product gateway (opt-in). Unset = single-backend memnet-mcp, unchanged.
# JSON maps backend id -> host:port, product backends, pinned version, and
# sha256 of each product credential. No secrets in this file.
# MEMNET_GATEWAY_CONFIG=/var/lib/memnet/gateway.json
# Public bind is refused unless this is 1. Leave unset for Endleaf.
# MEMNET_GATEWAY_ALLOW_PUBLIC=

# Optional CheapLlmImportGuard (Path-B import-slice soft LLM). Unset = off; absorb still works.
# Set the key on the serve process to activate. Not MEMNET_MCP_HTTP_TOKEN / session_token / RSV llm_id.
# MEMNET_IMPORT_GUARD_API_KEY=
Expand Down
3 changes: 3 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ This project uses Semantic Versioning as **interpreted for MemNet**: package `a.

## [Unreleased]

### Added
- **Product gateway on memnet-mcp (MN-REQ-06.12)** — `memnet-mcp --transport gateway` routes by product, house, or session to one owning `memnet serve`. Hashed per-product credentials, namespace isolation, verbatim GQL / stdin / `@ERR` `@WRN` `@STAT` pass-through, gateway refusals, health with failover only for a new unpinned session, version pin, loopback or tailnet bind, per-product admin counts. Single-backend stdio and streamable-http stay unchanged when no registry is configured. No SemVer bump. Not deployed. Wire: [`docs/operations/product-gateway-contract.md`](docs/operations/product-gateway-contract.md).

### Changed
- **Invent only — ClusterRoute vs SliceHandCarry (#191 / #47 cousin)** — `MemNetTwoMoves` outside `MemNetSystem` (`MN-REQ-06.9` + `MN-REQ-06.10` / `MN-VER-06-S08`). ClusterRoute = where the session lives (`MemNetLanMcpFront`; one owner; `pin_map` / `find` SHALL NOT span backends). SliceHandCarry = explicit copy into another session (`export_pin_map` or `session_save` → LAN file copy → dest import/`session_load`; `import_slice` same-serve only). Not a live hop. `import_slice(from_url)` not shipped. tip≠face. `inventOnly=true`; `implemented=false`; no engine code; no SemVer bump. Wire: [`docs/operations/cluster-route-vs-slice-hand-carry.md`](docs/operations/cluster-route-vs-slice-hand-carry.md).
- **Invent only — LAN MCP front over several serves (#191)** — `MemNetLanMcpFront` outside `MemNetSystem` (`MN-REQ-06.9` / `MN-VER-06-S07`). One MCP catalogue, N LAN `memnet serve` backends; `SessionOwnerRegistry` is owner (explicit pin allowed; silent hash is not sole routing). One owner per session; `pin_map` / `find` SHALL NOT span backends. Cousin of #47 (peer sid handoff), not the same invent. tip≠face. `inventOnly=true`; `implemented=false`; no engine code; no SemVer bump. Wire: [`docs/operations/memnet-lan-mcp-front.md`](docs/operations/memnet-lan-mcp-front.md).
Expand Down
1 change: 1 addition & 0 deletions docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -65,6 +65,7 @@ Multitask MUST for this product. Index: [`operations/README.md`](operations/READ
| [`operations/honesty-c-wire-audit.md`](operations/honesty-c-wire-audit.md) | 0.19.10 CueMiss/Peak_L vs CueConflict; snapshot locator SCHEMA warn; Path-B SysML CON; Truncation; hid emit audit |
| [`operations/tip-memnet-access-portal.md`](operations/tip-memnet-access-portal.md) | Sidecar: keyed tip MemNet MCP access (invite, Google, Bearer; tip≠face; not sysmledge) |
| [`operations/memnet-lan-mcp-front.md`](operations/memnet-lan-mcp-front.md) | Later invent #191: ClusterRoute — one MCP catalogue over N LAN serves (tip≠face; not shipped) |
| [`operations/product-gateway-contract.md`](operations/product-gateway-contract.md) | Product gateway on memnet-mcp (MN-REQ-06.12): route by product, house, or session |
| [`operations/cluster-route-vs-slice-hand-carry.md`](operations/cluster-route-vs-slice-hand-carry.md) | Two named moves: ClusterRoute vs SliceHandCarry (#191 / #47 cousin; inventOnly) |
| [`operations/admin-usage-report.md`](operations/admin-usage-report.md) | Admin-only serve usage JSON for a product-gate admin MCP (opaque alias; not agent MCP) |
| [`operations/one-session-per-document.md`](operations/one-session-per-document.md) | One MemNet session per document over loopback serve (no MCP front) |
Expand Down
1 change: 1 addition & 0 deletions docs/operations/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ Agent operating doctrine for this product (not domain recipes).
| [`../cap-contract.md`](../cap-contract.md) | Product-gate cap contract: every refuse/clip, exact `@ERR` / Truncation, integrator checklist |
| [`tip-memnet-access-portal.md`](tip-memnet-access-portal.md) | Live sidecar: admin invite, Google login, Bearer for keyed tip MCP (tip≠face; not sysmledge) |
| [`memnet-lan-mcp-front.md`](memnet-lan-mcp-front.md) | Later invent #191: ClusterRoute — one MCP catalogue, N LAN serves (tip≠face; not shipped) |
| [`product-gateway-contract.md`](product-gateway-contract.md) | Product gateway on memnet-mcp (MN-REQ-06.12): per-product route to one owning serve |
| [`cluster-route-vs-slice-hand-carry.md`](cluster-route-vs-slice-hand-carry.md) | Two named moves: ClusterRoute vs SliceHandCarry (#191 / #47 cousin; inventOnly) |
| [`admin-usage-report.md`](admin-usage-report.md) | Admin-only serve usage JSON (opaque alias; not agent MCP; MN-REQ-06.11) |
| [`one-session-per-document.md`](one-session-per-document.md) | Product gate: one serve session per document over loopback (no MCP); 0.19.18 probe |
Expand Down
Loading
Loading