Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
85 commits
Select commit Hold shift + click to select a range
b816cce
test(db): delete role-level search_path reliance in the test tree (ne…
Hellblazer Sep 7, 2026
6bfdafb
test(db): fold hand-rolled service_tokens seeding onto PgContainerHel…
Hellblazer Sep 7, 2026
234394a
fix(db): qualify SET CONSTRAINTS name, accept qualified <=> in plan-s…
Hellblazer Sep 7, 2026
5db3573
test(db): ALTER ROLE search_path gate accepts every PostgreSQL spelli…
Hellblazer Sep 7, 2026
e11a219
test(e2e): every sandbox opts out of the install ping (nexus-tb01a)
Hellblazer Sep 7, 2026
d210717
test(search): recall-parity gate accepts split-group tail drift as a …
Hellblazer Sep 7, 2026
42e1810
feat(upgrade): nx upgrade converges the Claude Code plugins (nexus-2u…
Hellblazer Sep 7, 2026
1070f98
feat(catalog): add nexus.document_restore/trash caller routes (engine)
Hellblazer Sep 7, 2026
f24fe68
feat(catalog): add nx catalog trash / restore verbs (client)
Hellblazer Sep 7, 2026
b291638
fix(catalog): qualify restore's grace-window claim; fix live/trash ti…
Hellblazer Sep 7, 2026
1bbba3a
test(search): floor-selection tests opt into cloud_mode for the mode-…
Hellblazer Sep 7, 2026
9899f02
test(lint): retarget six pipefail early-exit exemptions moved by the …
Hellblazer Sep 7, 2026
545ed06
fix(catalog): t3 gc alive-set protects tombstoned docs until purge (e…
Hellblazer Sep 7, 2026
00b84f3
fix(catalog): t3 gc alive-set protects tombstoned docs until purge (c…
Hellblazer Sep 7, 2026
d1a116f
fix(catalog): correct stale indexer-prune rationale in dkymw comments…
Hellblazer Sep 7, 2026
7cd690d
fix(catalog): correct stale indexer-prune rationale in dkymw comments…
Hellblazer Sep 7, 2026
606f530
docs(rdr): RDR-204 fifth-gate fixes [24841]: refusal is renameCollect…
Hellblazer Sep 7, 2026
06c6858
docs(rdr): RDR-204 sixth-gate fixes [24844]: the registry table dates…
Hellblazer Sep 7, 2026
2e34eac
docs(rdr): RDR-204 Finalization Gate cites each assumption's own evid…
Hellblazer Sep 7, 2026
521daef
docs(rdr): RDR-204 seventh-gate research fixes [24847] part 1: RDR-14…
Hellblazer Sep 7, 2026
4beaeb3
docs(rdr): RDR-204 seventh-gate research fixes [24847] part 2: Critic…
Hellblazer Sep 7, 2026
c090361
docs(rdr): RDR-204 eighth-gate fixes [24850], sources quoted first in…
Hellblazer Sep 7, 2026
ae58e7d
docs(rdr): RDR-204 fix-check [24854]: model_version is parsed at five…
Hellblazer Sep 7, 2026
df91f40
docs(rdr): RDR-204 fix-check [24858]: the Key Discoveries registratio…
Hellblazer Sep 7, 2026
0739a40
test(lint): changeset citations in docs/rdr resolve and attributions …
Hellblazer Sep 7, 2026
9534791
docs(rdr): RDR-204 Finalization Gate cites 204-research-15 beside res…
Hellblazer Sep 7, 2026
b1a3605
feat(rdr): gate loop remedies: always-on Layer 0, diff-scoped fix che…
Hellblazer Sep 7, 2026
296e8b5
fix(rdr): gate-loop remedies after review [24865] [24866] (nexus-g7zgw)
Hellblazer Sep 7, 2026
a7efb15
docs(rdr): RDR-204 gate 9 residual: the Finalization Gate points at t…
Hellblazer Sep 7, 2026
8d4d5f7
docs(rdr): accept RDR-204 (gate round 9 PASSED, residual dispositione…
Hellblazer Sep 7, 2026
54211cf
docs(rdr): README index row for RDR-204 (missing since create; set-st…
Hellblazer Sep 7, 2026
e5ba579
test(db): convert CollectionRegistryFkExtraTest raw SQL to typed jOOQ…
Hellblazer Sep 7, 2026
0cba4f6
test(db): convert CatalogRenameCollectionTest row-count reads to type…
Hellblazer Sep 7, 2026
af2f1fb
test(db): convert CollectionRegistryFkTest raw SQL to typed jOOQ DSL
Hellblazer Sep 7, 2026
dcea7c7
test(db): convert ForeignKeyConstraintTest raw SQL to typed jOOQ DSL
Hellblazer Sep 7, 2026
5f10003
test(db): convert SoftDeleteTest raw SQL to typed jOOQ DSL
Hellblazer Sep 7, 2026
59da301
test(db): convert ReadShapeViewsTest raw SQL to typed jOOQ DSL
Hellblazer Sep 7, 2026
bc50412
test(db): batch 10 review fold-in -- test-lifecycle DDL functions, ch…
Hellblazer Sep 7, 2026
6a88b46
fix(rdr): gate-loop remedies after e2e critique [24873] (nexus-g7zgw)
Hellblazer Sep 7, 2026
d4960d4
docs(skills): a T3 file:line hit is a lead, re-read from the tree bef…
Hellblazer Sep 7, 2026
9c99cb8
test(db): reword two batch-10 comments so the stale-dim-table lint's …
Hellblazer Sep 7, 2026
c0509cd
fix(cli): retire 'nx catalog setup' from every user-facing remedy (Se…
Hellblazer Sep 7, 2026
28ae9c1
fix(rdr): gate-loop remedies after deep review [24873] [24875] (nexus…
Hellblazer Sep 7, 2026
f6ebe7b
feat(rdr): the fix step's own surface and the gate loop's counter-met…
Hellblazer Sep 7, 2026
dd89744
fix(rdr): rdr-fix surface after review [24883] [24884] (nexus-zbdm0)
Hellblazer Sep 7, 2026
b5476dc
docs(rdr): RDR-204 post-accept fact fixes from plan-audit round 3 [24…
Hellblazer Sep 7, 2026
aa8267e
feat(rdr): one table for the review round contracts, and the gate out…
Hellblazer Sep 7, 2026
3fd601a
docs(rdr): RDR-204 fix-check corrections [24892] (nexus-ft04v)
Hellblazer Sep 7, 2026
4c9a79b
fix(rdr): round table and verdict after review [24898] [24900] (nexus…
Hellblazer Sep 7, 2026
3d42081
test(db): convert StagingPromoteOpsIntegrationTest raw SQL to typed j…
Hellblazer Sep 7, 2026
48a6810
test(db): convert RdrO8dil7GlobalManifestAntiJoinTest raw SQL to type…
Hellblazer Sep 7, 2026
259c472
fix(upgrade): report the pid-file MinerU server stale when its interp…
Hellblazer Sep 7, 2026
8aaf417
fix(index): register docs collections with the effective write model,…
Hellblazer Sep 7, 2026
e2196ff
test: commands inventory pin to 26 after rdr-fix.md (nexus-zbdm0)
Hellblazer Sep 7, 2026
a593242
perf(pdf): auto mode skips the Docling pass once the quick formula sc…
Hellblazer Sep 7, 2026
0be9f97
fix(upgrade): re-check the live command before treating the pid-file …
Hellblazer Sep 7, 2026
c45bd3a
fix(mineru): nx mineru stop refuses a recycled pid; keep the formula …
Hellblazer Sep 7, 2026
5c0d699
fix(mineru): stop keeps the pid file on an inconclusive command read;…
Hellblazer Sep 7, 2026
83fe0ee
build: one engine build lease per box, and a content-keyed gate-jar c…
Hellblazer Sep 7, 2026
db86de5
fix(enrich): aspects-list --missing refuses a collection the catalog …
Hellblazer Sep 7, 2026
61a5329
test(db): convert SchemaRollbackRoundTripIntegrationTest raw SQL to t…
Hellblazer Sep 7, 2026
9f6cf9e
test(db): convert SchemaMigratorIntegrationTest raw SQL to typed jOOQ…
Hellblazer Sep 7, 2026
e70926c
test(db): installTestObjects documents its ownership contract on the …
Hellblazer Sep 7, 2026
fda0242
test(db): reword three batch-12 comments so the stale-dim-table count…
Hellblazer Sep 7, 2026
6ee4795
test(scripts): gate-jar-cache_test matches git status via a command s…
Hellblazer Sep 7, 2026
3bce826
experiment: aspects versus chunks as the reader payload, the ISC A/B …
Hellblazer Sep 7, 2026
c78be96
feat(catalog): tombstone-protected chunk count for nx t3 gc (nexus-ze…
Hellblazer Sep 7, 2026
c67d973
feat(dt): page coverage against DEVONthink's pageCount, DT metadata o…
Hellblazer Sep 8, 2026
9d773a2
fix(catalog): tombstone_protected_count is opt-in on /manifest/chashe…
Hellblazer Sep 8, 2026
392778b
feat(t3): report chunks protected only by a pending tombstone (nexus-…
Hellblazer Sep 7, 2026
fa21c24
fix(t3): client asks for the tombstone-protected count explicitly; wi…
Hellblazer Sep 8, 2026
82a227d
docs(release): CHANGELOG for 7.36.0, plugin-surface entries, docs dri…
Hellblazer Sep 7, 2026
8c70195
chore(release): conexus 7.36.0 (paired with engine-service-v0.1.108)
Hellblazer Sep 8, 2026
cc4f234
fix(aspects): extractor runs on the model it stamps and logs actual c…
Hellblazer Sep 8, 2026
6a6373d
docs(release): 7.36.0 changelog gains the aspects model/cost work and…
Hellblazer Sep 8, 2026
bb46817
test(index): registry-adapter model tests declare cloud_mode; the loc…
Hellblazer Sep 8, 2026
9636269
Merge remote-tracking branch 'origin/develop' into release/v7.36.0
Hellblazer Sep 8, 2026
32162a6
test(release): pin assertion follows REQUIRED_ENGINE_VERSION to (0,1,…
Hellblazer Sep 8, 2026
e67f443
fix(dt): page coverage after review [24937] [24938] (nexus-i0cwh)
Hellblazer Sep 8, 2026
4fcbceb
test(doc_indexer): streaming return_metadata pins carry page_count an…
Hellblazer Sep 8, 2026
ded5dca
fix(aspects): cost banner names the measured model, constant re-based…
Hellblazer Sep 8, 2026
9fdd834
test(command-context): the devonthink-index preamble test names a loc…
Hellblazer Sep 8, 2026
7d3044d
test(doc_indexer): the streaming path's empty result reports pages_wi…
Hellblazer Sep 8, 2026
1f49878
test(t3): the end-to-end gc test asserts the ruled contract: a tombst…
Hellblazer Sep 8, 2026
52a81be
docs(wire): the zewg3 ledger entry cites the develop commits and name…
Hellblazer Sep 8, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions .claude-plugin/marketplace.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,21 +11,21 @@
"source": "git-subdir",
"url": "https://github.com/Hellblazer/nexus.git",
"path": "conexus",
"ref": "v7.35.0"
"ref": "v7.36.0"
},
"description": "Self-hosted three-tier knowledge management with 13 specialized agents, plan-centric retrieval via nx_answer, semantic search, and RDR decision tracking for Claude Code.",
"version": "7.35.0"
"version": "7.36.0"
},
{
"name": "sn",
"source": {
"source": "git-subdir",
"url": "https://github.com/Hellblazer/nexus.git",
"path": "sn",
"ref": "v7.35.0"
"ref": "v7.36.0"
},
"description": "Injects Serena and Context7 MCP tool usage guidance into subagents via SubagentStart hook.",
"version": "7.35.0"
"version": "7.36.0"
}
]
}
2 changes: 1 addition & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -206,7 +206,7 @@ make nearly every cut a docs cut.

The Java **engine-service** binary is a separate release artifact with its own cadence. Conflating it with the PyPI/marketplace release is how the cloud engine silently drifts behind develop (2026-06-26: 22 `service/` commits / 4 days un-deployed, un-cloud-tested).

Build or test the engine through `scripts/mvnw-leased.sh` (never a bare `./mvnw`/`mvn`) — one builder at a time; a concurrent `./mvnw` invocation against the same `service/target` corrupts jOOQ codegen mid-build (nexus-c00dw, see `scripts/lib/build-lease.sh`).
Build or test the engine through `scripts/mvnw-leased.sh` (never a bare `./mvnw`/`mvn`) — one builder at a time; a concurrent `./mvnw` invocation against the same `service/target` corrupts jOOQ codegen mid-build (nexus-c00dw, see `scripts/lib/build-lease.sh`). The lease lives in the git common dir, so every worktree shares it, and a live holder is waited for rather than refused (`NX_BUILD_LEASE_WAIT`, nexus-g6xpa): one engine build or suite per box. `scripts/build-gate-jar.sh` caches the stamped jar on the exact `service/` content, so a fresh worktree with an unchanged tree gets a copy instead of a nine-minute rebuild.

- **Artifact + trigger:** an `engine-service-vX.Y.Z` git tag fires `engine-service-release.yml`, which builds + cosign-signs the 3 native binaries (linux-amd64, linux-arm64, mac-arm64 — mac-arm64 unsmoked, no Docker on GH macOS, nexus-4xf5m; mac-amd64/Intel is not a supported target). It publishes **nothing to PyPI** and is **NOT gated by the luxe6 / RDR-155-P4a develop release boundary** (the workflow header says so explicitly). **The release is a DRAFT until every asset is attached** (nexus-cl14i, after v0.1.95 published PG bundles with no binary): a final `promote-release` job flips it only when both matrices succeeded and all 21 assets are present, so a tag is consumable roughly 40 to 65 minutes after push, never partially; a failed leg, mac-arm64 included, leaves a draft that `gh run rerun --failed` completes and promotes. So the engine can be refreshed in the cloud at any time, independent of the unreleasable-develop state.
- **Version is tag-stamped — there is NO manifest to bump.** `release.properties` `release_version` is blank in source and stamped at native-build time from the tag (the Maven `pom.xml` stays `1.0-SNAPSHOT`, the dev coordinate). The cut is NOT just suite-green-then-tag: the `engine-release` skill (Authority: this section) enforces a full pre-tag battery — full engine suite green on the tagged commit, `tests/e2e/migration-rehearsal/run.sh --shakeout` (must end `CANDIDATE SHAKEOUT PASSED`) — then human pushes `engine-service-vX.Y.Z`, followed by a post-publish `--acquire` gate against the published bytes. `scripts/check_client_release_precondition.py --engine-tag engine-service-vX.Y.Z` gates the **DEPLOY, never the tag cut** (Hal directive 2026-08-02 — its pre-tag wiring forced conexus 7.1.0 to ship pinned to a pre-fence engine, its own flagship feature inert on fresh local installs; a red exit means the deploy waits for the client tag carrying the listed commits, per the paired-release choreography below). **A tag gates DELIVERY, not work**: engine changes are fully testable end-to-end on develop (`scripts/mvnw-leased.sh test` + the Python suite's engine substrate + LSG against a `build-gate-jar.sh` dev jar) — "cannot deploy yet" is never "cannot do/test/tag it" (error recurred 3x: nexus-0ehwe thread 2026-07-31 twice, the 7.1.0/v0.1.62 inversion 2026-08-02). Use the `engine-release` skill as the executable checklist, not this summary.
Expand Down
114 changes: 114 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,120 @@ Versioning follows [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

## [Unreleased]

## [7.36.0] - 2026-09-07

Pairs with engine-service-v0.1.108 (additive).

### Catalog: trash and restore (nexus-dkymw, nexus-xavu7)

- `nx catalog trash [--limit N]` lists this tenant's tombstoned documents;
`nx catalog restore TUMBLER_OR_TITLE` clears a tombstone (title
resolution falls back to the trash listing when the live resolver
misses it). Closes nexus-xavu7: three operator-facing sites told a user
to "restore the trashed document(s)" with no surface to do it. Engine:
`POST /v1/catalog/restore`, `GET /v1/catalog/trash`, the first callers of
the RDR-156 P1.2 `nexus.document_restore` function since it shipped.
- `_resolve_restore_target` no longer resolves a title present both live
and in the trash to the live copy and hides the restorable one — it now
refuses as ambiguous and names every tombstoned tumbler.
- `nx t3 gc`'s orphan-sweep alive-set now protects a tombstoned-but-not-yet-
purged document's chashes, superseding nexus-mqd6t's original immediate-
exclusion filter for that one read (Sam's second 2026-09-07 ruling on
nexus-dkymw): its independent chunk-`indexed_at` clock can no longer
reap a just-tombstoned document's chunks inside `nx catalog restore`'s
recovery window. The MCP `store_delete` tool and `nx collection
delete`/`prune` still bypass the window entirely (they never tombstone,
or hard-delete in the same call); docs narrowed to name exactly those
two remaining carve-outs.

### CLI: `nx catalog setup` retired from every remaining remedy (nexus-owna8)

The SessionStart RDR hook, `mcp_infra`, `health`, `enrich`, `dt`, `t3`,
`doctor`, `upgrade`, and `catalog` no longer point an operator at the
retired verb — the service owns the catalog now; populate with
`nx index repo` / `nx store put`.

### PDF and MinerU

- Auto PDF-extraction mode skips the Docling pass once the quick formula
screen has already routed a document to MinerU, instead of running both
and discarding Docling's output — measured 24s saved ahead of a 32s
MinerU run on a 6-page paper (nexus-m5ym5).
- `nx mineru stop` now signals the PID file's whole process group (so
MinerU's multiprocessing workers and their resource trackers exit too),
refuses to signal a PID the OS has recycled for something other than
`mineru-api`, and leaves an inconclusive command read alone rather than
orphaning a server that may still be ours (nexus-5yrob, nexus-aabdr,
nexus-ajfld, nexus-8sb6x). `nx doctor` / the post-upgrade sweep now
re-check the live command before treating a PID-file MinerU server as
real, and flag one whose interpreter lies outside the current
generation as stale — a server spawned from a develop checkout's
`.venv` previously survived three generation flips unnoticed
(nexus-ho9d2, nexus-ydqwo).

### Aspects

Aspect extraction runs on the model each row is stamped with (haiku for
scholarly-paper-v1) and logs its actual cost and model per document
(nexus-oc98c, nexus-3ygp3). `nx enrich aspects` and `nx enrich aspects-list
--missing` refuse a collection name the catalog does not know instead of
reporting a clean, empty run or false full coverage (nexus-ngpx0).

### DEVONthink: `nx dt index` page coverage and metadata (nexus-i0cwh)

`nx dt index` checks page coverage against DEVONthink's pageCount
(`--allow-page-gap` to accept a gap), records DEVONthink url, year and
pageCount on the catalog row, and gains the `/conexus:devonthink-index`
command.

### Index

`nx index repo` registers `docs`/`rdr` collections with the effective
write-time embedding model instead of a hardcoded `voyage-context-3`,
closing a 422 a local-mode (bge) install would otherwise hit the moment
the engine started enforcing profile-vs-write-model agreement
(nexus-ft04v.34).

### RDR lifecycle: gate loop, fix surface, and one round table (nexus-zbdm0, nexus-g7zgw, nexus-dv7gw, nexus-yxo2l)

- `nx rdr preamble rdr-fix <id>` is the new fix step: prints the latest
gate's findings with their `Sites:` lists, the diff range and fix
commits since the gated commit, whether a fix-check record exists for
the file's current tip, the pre-edit research title, and the fix rules;
`/conexus:rdr-fix` and the `rdr-fix` skill wrap it.
- `nx rdr preamble rdr-verdict <id> <critique-title>` computes a gate's
outcome from the stored critique instead of by hand: Critical and
Significant issue blocks and `Ship-blocker: yes` marks are counted, the
larger of each self-reported and counted number wins, and
`review-rounds.toml`'s round-numbered rdr-gate rule decides
PASSED/BLOCKED.
- `nx rdr preamble rdr-gate`'s re-gate block now fires after every prior
gate record, PASSED or BLOCKED, surfaces the prior round's findings via
a Layer 0 sweep, and adds a diff-scoped Fix check layer ahead of Layer
1. `nx rdr preamble rdr-audit` leads with a Gate loop health block:
rounds and Criticals per round per gated RDR, flagging a loop that ran
past the round cap.
- `src/nexus/tables/review-rounds.toml` is now the single statement of
the code-review, plan-audit, and rdr-gate round bounds; the surfaces
that used to hardcode them cite it instead.

### Developer tooling

- One engine build lease per box, shared across worktrees via the git
common dir, and a content-keyed cache for the stamped gate jar, so a
fresh worktree with an unchanged `service/` tree gets a copy instead of
a nine-minute rebuild (nexus-g6xpa).
- Raw-SQL test-tree conversions onto typed jOOQ DSL continued (batches
9-12, nexus-cbo4a): the tree-wide raw-SQL ceiling fell from 1661 to
1245 sites across batches 9-11, with batch 12 continuing the trend.
Role-level `search_path` reliance was deleted from the test tree
entirely (Sam's directive, nexus-zrcj7), surfacing one real production
bug along the way — `CatalogRepository.deferManifestChunkFk` ran an
unqualified `SET CONSTRAINTS` name that only resolved via search_path.
- The recall-parity gate now accepts a documented, measured cost: the
tail-ranking swap a split embedding-model group shows against
pre-batching fan-out (nexus-atylb, test-only).

## [7.35.0] - 2026-09-07

Paired with engine-service-v0.1.107 (`REQUIRED_ENGINE_VERSION` 0.1.107,
Expand Down
12 changes: 9 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -79,14 +79,20 @@ nx upgrade # 2. converge the data
Both steps, every time. Step 1 installs a new generation beside the one you
are running and repoints `current`; nothing is swapped under a live process,
so it is safe with Claude Code sessions open and the service up. Step 2
converges the package, engine, and service, then walks any pending data
rung. `nx doctor` shows what is pending; `nx upgrade --dry-run` previews.
converges the package, engine, and service, walks any pending data rung,
and brings the Claude Code plugins up to the same release (it runs
`claude plugin update` for a plugin that is behind; the updated plugin
loads at your next session). Either entry point converges the others:
`/plugin update` in Claude Code triggers the same two steps at the next
session start. `nx doctor` shows what is pending; `nx upgrade --dry-run`
previews.

Do not upgrade with `uv tool install conexus` or `--force`: that resets the
environment and drops `[local]`, which downgrades the embedder and makes
search return nothing. If you did, `nx self install` repairs it.

After `/plugin update`, run both steps so the CLI matches the plugin.
After `/plugin update`, the next session start runs both steps for you;
run them by hand to converge now.

Installs that never left ChromaDB (5.x, or 6.x never migrated) take a
different path: [Getting Started § Upgrading from a pre-PG install](docs/getting-started.md#upgrading-from-a-pre-pg-install).
Expand Down
2 changes: 1 addition & 1 deletion conexus/.claude-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "conexus",
"version": "7.35.0",
"version": "7.36.0",
"description": "Self-hosted three-tier knowledge management with plan-centric retrieval (nx_answer), specialized agents, semantic search, and RDR decision tracking for Claude Code.",
"author": {
"name": "Hal Hildebrand",
Expand Down
32 changes: 32 additions & 0 deletions conexus/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,38 @@ All notable changes to the conexus plugin are documented here.
Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
Versioning follows [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

## [7.36.0] - 2026-09-07

- `rdr-gate` skill and command: the outcome is computed by
`nx rdr preamble rdr-verdict`, never by hand (nexus-yxo2l); Layer 0 fires
after PASSED gates too and sweeps the critic's `Sites:` list, a
diff-scoped Fix check layer runs before Layer 1, and Gate Aggregation
blocks on any Critical in rounds 1-2 and on `ship_blockers` only from
round 3, recording the rest as residuals (nexus-g7zgw); the gate record
gains `ship_blockers:`, `fix_check:`, `residuals:`, `prior:`.
- `rdr-research` skill: pre-edit capture for gate fixes — a research entry
written before the edit, quote or "inferred, not read" per clause, a
census for universals; a T3 file:line hit is a lead, re-read from the
tree before it is cited or quoted (nexus-g7zgw.5).
- `rdr_hook.py` (SessionStart): names `nx index repo <root>` alone now that
`nx catalog setup` is retired everywhere (nexus-owna8, the hook's false
NOT-indexed verdict); also names any draft RDR whose file moved past its
gated commit and points at `/conexus:rdr-fix` (nexus-zbdm0).
- `rdr-accept` skill: residuals in the gate record must be dispositioned
(commit sha or bead id) before accept; a `fix_check:` sha that differs
from `commit:` blocks accept (nexus-g7zgw.2).
- `substantive-critic` agent: the canonical Issue format carries a
`Sites:` line (nexus-g7zgw.4).
- New `rdr-fix` command and skill: the fix step's own surface, wired to
`nx rdr preamble rdr-fix` (nexus-zbdm0); `rdr-gate`'s Fixing findings
section points at it.
- `using-nx-skills` skill: `rdr-fix` in the lifecycle line; two Red Flags
rows for the filing-as-deferral and one-more-pass pathologies (Sam,
2026-09-07).
- `code-review` skill, `orchestration` skill, `strategic-planner` agent:
round numbers cite the new `review-rounds.toml` table instead of a
hardcoded literal (nexus-dv7gw).

## [7.35.0] - 2026-09-07

Plugin version aligned with conexus 7.35.0. No plugin-side changes.
Expand Down
2 changes: 1 addition & 1 deletion conexus/PENDING_RELEASE.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,6 @@ mechanize, it matters enough to ship.
---


## Awaiting the next release or plugin cut (pinned: v7.35.0)
## Awaiting the next release or plugin cut (pinned: v7.36.0)

(none)
2 changes: 1 addition & 1 deletion conexus/agents/strategic-planner.md
Original file line number Diff line number Diff line change
Expand Up @@ -201,7 +201,7 @@ mcp__plugin_conexus_nexus__nx_plan_audit(
)
```

**Count the rounds. The tool cannot.** It is one stateless subprocess
**Count the rounds. The tool cannot.** (The cap is `review-rounds.toml`'s, contract `plan-audit`.) It is one stateless subprocess
call with no memory between invocations, so `round_number` is yours to
track. Leaving it at 1 forever reproduces the unterminated audit loop
this parameter exists to break (nexus-ll7zm). A revision produced by an
Expand Down
8 changes: 8 additions & 0 deletions conexus/agents/substantive-critic.md
Original file line number Diff line number Diff line change
Expand Up @@ -277,6 +277,10 @@ The canonical structure (in emission order):
- **Impact**: [Why it matters]
- **Recommendation**: [How to fix]
- **Evidence**: [Supporting references from nx store or analysis]
- **Sites**: every file:line where the fact this issue names lives, so the
author sweeps an enumerated set rather than a remembered phrase (an RDR
states one fact in Problem Statement, Research Findings, Technical Design and
the Implementation Plan at once)
- **Ship-blocker**: yes | no — "yes" only if shipping AS-IS violates the relay's
stated acceptance bar, loses data, wedges an install, or breaks a published
contract. Everything else is "no" and becomes a bead, not a reason to hold.
Expand Down Expand Up @@ -335,6 +339,10 @@ make the verdict look more actionable, and do not suppress a real one to make it
look cleaner; the orchestrator may override a marking upward but the definition
above stays objective.

A caller's aggregation may block on `critical_count` independently of
`ship_blockers` (the RDR gate does so in its first two rounds); `ship_blockers` is
your judgement of the relay's bar, not the caller's rule.

> Fallback parse rule: if this Verdict block is absent or the `- **outcome**:` line cannot be located verbatim, downstream parsers count `### Issue:` headers under `## Critical Issues` and `## Significant Issues` and derive outcome mechanically. The fallback works but the canonical path is preferred, emit the block exactly as shown above.

## Operating Principles
Expand Down
23 changes: 23 additions & 0 deletions conexus/commands/devonthink-index.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
---
allowed-tools: Bash
description: Index DEVONthink records into the T3 knowledge store through nx dt index, with catalog identity on the x-devonthink-item URI and a page-coverage check
---

# DEVONthink Index

!`nx command-context devonthink-index`

## Records to Index

$ARGUMENTS

**Targeted load**: parse the selector from `$ARGUMENTS` (a record UUID, a group path starting with `/`, or a smart-group name) and any `--collection` / `--allow-page-gap` / `--extractor` flags, then run, via the Bash tool, `nx command-context devonthink-index -- <selector> <flags>` with literal argv tokens. Never splice raw `$ARGUMENTS` into a shell-quoted line.

## Action

All data is pre-loaded above — no additional tool calls needed.

- Run the printed `nx dt index ...` line via the Bash tool, with `--collection knowledge__<subject>` naming an existing subject from the list above (a subject area, never a source app or a session). Omit `--collection` only to take the default `knowledge__dt-papers`.
- Read the summary line. `Indexed N record(s)` with no `failed` is done. `page-coverage failed` names the records and their missing pages: re-run those with `--extractor mineru`, or accept with `--allow-page-gap` when the pages are blank by design (cover, figures). `page coverage unverified` means the DEVONthink MCP was unreachable; report it as unverified, never as covered.
- Verify by content: `nx catalog show "<title>" --json` shows `source_uri: x-devonthink-item://<UUID>` and the DEVONthink url and year; a `search` in the target collection returns the document.
- Re-running the same selector is a no-op under the same tumbler; `--force` re-chunks in place.
Loading
Loading