Changelog

Every release, including the ones that correct our own numbers — honest math is the product, and this page is its paper trail. Rates are verified nightly against Anthropic's published pricing.

1.8.15 — 2026-09-09

Removed

1.8.14 — 2026-09-09

Changed

1.8.13 — 2026-09-09

Changed

1.8.12 — 2026-09-09

Changed

1.8.11 — 2026-09-09

Changed

1.8.10 — 2026-09-06

Added

Changed

1.8.9 — 2026-09-05

Removed

Changed

Fixed

Added

Changed

Fixed

Unchanged

1.8.8 — 2026-09-05

Fixed

Recorded

Unchanged

1.8.7 — 2026-08-26

Removed

Kept, deliberately

Fixed

Recorded

1.8.6 — 2026-08-26

**This release exists because a three-adversary audit of the client tarball

staged for the public repo found six claims that were false or misleading — two

of them in code that reaches customers, four of them in the release

documentation describing the release that fixed the last batch.** The audit's

other findings were clean: the install works, the mcp>=1.2,<2 pin holds at

both edges, the suite passes, the mutation tests are genuinely red, and the

denylist sweep found nothing. Every one of the six is stated here in full,

because a changelog that records only the clean half is an advertisement.

server/app.py health reports 1.8.6 and this heading carries the same

number. The MCP client is cut to 1.5.2. 55_acl_ops/uptime_watch stays

pinned to 1.8.5 until the last step of the deploy runbook (server/DEPLOY.md);

that bump is a deploy act, not a tree edit.

Fixed — in shipped code, reaching customers

Fixed — in the release documentation

Not changed

1.8.5 — 2026-08-26

**This release exists because 1.8.4 shipped three customer-facing defects and

nobody caught them until the SHIPPED artifact was audited rather than the

source.** All three are stated here in full, unsoftened, because a changelog

that only records wins is not a record.

server/app.py health reports 1.8.5 and this heading carries the same

number. The MCP client is cut to 1.5.1. 55_acl_ops/uptime_watch stays

pinned to 1.8.4 until the last step of the deploy runbook (server/DEPLOY.md);

that bump is a deploy act, not a tree edit.

Fixed

Security

Changed

Known limits, stated rather than left to be found

1.8.4 — 2026-08-25

COMMITTED 2026-08-25 on Ross's ruling ("I run it end to end", standing for this

release only). server/app.py health reports 1.8.4 and this heading carries

the same number. At the moment of this commit the live site still serves rev

00037-xj8 (v1.8.3), so zero defects below are fixed for a customer yet — the

deploy follows immediately and is recorded in its own DEPLOY commit, per this

repo's convention. 55_acl_ops/uptime_watch stays pinned to 1.8.3 until the

last step of the deploy runbook (server/DEPLOY.md); that bump is a deploy act,

not a tree edit.

The first block is Ross's ruling of 2026-08-25, after he reported the dogfood

rail's error as a SECOND incident and was then shown the rendered fleet row.

The blocks after it are the copy and gate work of the same day, which the

collapse made necessary.

Fixed

Changed

CORRECTION — three entries above were reverted the same sitting

Recorded here rather than deleted, because the record of a reversal is worth more than a tidy

list. These three do NOT describe the tree:

What survives from that work is the mechanism, not the ruling: METERED/UNMETERED remain as the

switch, now joined by DORMANT for the separate question of which pool may pin the as-of.

Reversed within the same sitting

Consequences, stated rather than smoothed over

Two-direction probe (§1.7 requirement)

LATER THE SAME SITTING — one pool, and the wake-up check

Three rulings, verbatim:

> "you can switch off that cried wolf on a good known state. That's fine."

>

> "I think we just get rid of the fleet pool. I mean, it's just... I think multiagent

> and agent spend should just be one pool. Like, all operations should be agent cost

> lens. It shouldn't be sub split. Maybe later I can add that capability, but now

> it's fine."

>

> "the wake up check, a declared dormant pool whose glob starts matching files and

> said fail. make that, write it."

These supersede several entries above. dogfood_math.METERED is now

(POOL_LABEL,), UNMETERED and DORMANT are both (), and MAIN_LABEL/

FLEET_LABEL are one constant, POOL_LABEL. The stored label STRING is unchanged

(dogfood-main): it is the label of a key Ross minted by hand and of every row

already pushed under it, so renaming the value would orphan the history and need a

new key. What changed is the split, not the identity.

#### Changed

#### Added

#### The fake source, decided rather than left open

A subagent transcript's project is the literal folder name subagents

(parse.py:69), and the WIRE's source is derived from the project

(records.py:41,52). So once a subagent is dispatched from the serving folder the

STORE will hold two sources in the one pool, one of which is not a project.

Accepted, not repaired. The collision it invites needs two projects' subagents in

one pool, and every pattern of this pool lives under ONE project directory — the

folder scope is the guard, and a test asserts it mechanically. The money is unharmed:

simulate_cached and recoverable_conservative both clamp PER SESSION and

aggregate runs them once per source, so a second source partitions the pool's

events rather than duplicating them. The name never reaches a surface. The repair

would be in parse.parse_file, which mcp-client/tests/test_parity.py pins

byte-identical to the SHIPPED client the push rig loads — a client release, and

Ross's call. Pinned in both directions so the trap is written down, not rediscovered.

#### Consequences, stated rather than smoothed over

#### Two-direction probe (§1.7 requirement)

fix-all, serving lane (2026-08-25) — Darwin-gated, Ross's "fix all problems"

#### Fixed

#### Changed

#### Not done, and why

#### Two-direction probes (§1.7 requirement)

#### Not deployed

LATER THE SAME SITTING — the copy the collapse falsified, and one gate that moved

The collapse retired a pool. It did not retire the SENTENCES about that pool, and

a twelve-lane audit found them by RENDERING every surface rather than grepping

source — which is also how it found that "57 main working sessions", the string

everyone suspected, renders nowhere, while two nobody suspected were live and

false. Six fix lanes ran, six adversaries attacked their work, and a serialized

integration pass resolved what the adversaries proved. Every entry below is

tree-only.

#### Fixed — the landing page (the surface that sells at $500/month)

#### Fixed — the landing page, second pass (what the adversary refuted)

Four of the fixes above shipped a new false sentence with them. All four were

proven by rendering or by EXECUTING the product, never by reading source.

#### Fixed — /dogfood

#### Fixed — the API and the release gates

#### Fixed — tests that could not fail

A mutation battery run against the fix lanes' own tests found five assertions

that stayed green while the behavior they claimed to pin was destroyed. Every one

graded CHARACTERS where the defect is MEANING.

All five turn red now; a no-op control mutation stays green.

#### Two-direction probes (§1.7 requirement)

#### Not done, and why

#### Not deployed

1.8.3 — 2026-08-25

Changed

1.8.2 — 2026-08-25

Changed

1.8.1 — 2026-08-25

Changed

Added

Changed

1.8.0 — 2026-08-21

Fixed

Added

Changed

Notes

1.7.0 — 2026-07-31

Changed

1.6.0 — 2026-07-30

Changed

1.5.0 — 2026-07-30

Added

Changed

1.4.0 — 2026-07-30

Changed

Added

Known limits

1.3.0 — 2026-07-26

Added

1.2.11 — 2026-07-24

Added

1.2.10 — 2026-07-24

Changed

1.2.9 — 2026-07-24

Fixed

1.2.8 — 2026-07-22

Removed

1.2.7 — 2026-07-22

Changed

1.2.6 — 2026-07-22

Added

1.2.5 — 2026-07-22

Changed

1.2.4 — 2026-07-22

Fixed

1.2.3 — 2026-07-22

Changed

1.2.2 — 2026-07-22

Changed

1.2.1 — 2026-07-22

Added

1.2.0 — 2026-07-22

Added

1.1.1 — 2026-07-22

Fixed

Added

1.1.0 — 2026-07-20

Added

Unchanged (by contract, test-locked)

Tests

Root 119 · client 19 (incl. byte-parity, now a vendored quintet) · server 58.

1.0.0 — 2026-07-18 (live)

First public version — everything currently serving at lens.r-lattice.com.

Retroactively tagged; see releases/v1.0.0.md for the full report.

Highlights (built 2026-07-12 → 2026-07-18, 70 commits)