Open source contribution · Rust · MCP · AI Infrastructure
akitaonrails/ ai-memory
Long-term memory solution for coding agents (Claude, Codex, OpenCode, Agy), providing cross-session persistence, structured handoffs, and semantic search.
- 34 merged PRs
- 104 commits to the project
- +6.6k lines added
- 9.1k GitHub stars
The project
ai-memory is long-term memory for AI coding agents. More than twenty tools, such as Claude Code, Codex, Cursor, Gemini CLI and OpenCode, feed one shared memory: quit a session mid-task, open another agent in the same folder and it receives a handoff saying where the work stopped, what already failed and what is still open.
It records the work automatically, strips sensitive data before storing anything and organizes it all in a wiki of plain text files that a whole team can share on its own server. That is why the contributions below focus on what that trust depends on: privacy, continuity across agents, operations without data loss and a correct knowledge base.
Highlights
The PRs with the largest effect for people who rely on the project every day.
-
#923merged Sep 27, 2026
Backup restore that never wipes the current data
Removes a path to total data loss during recovery, the riskiest moment of operations. Nothing destructive happens before whatever takes its place has been verified.
-
#1128merged Oct 7, 2026
Passwords and keys filtered before any text is trimmed
Closes a path through which fragments of passwords and access keys could end up stored in the project's memory despite the filter. It is the same kind of flaw fixed earlier in record titles, now closed for the content as well.
-
#1194merged Oct 9, 2026
A purged session stays deleted, even with late events
Purging a session is now final: what someone asked to delete does not come back with the next event. And capture clients no longer get stuck resending those events.
How each PR was made
-
One problem per PR
Each PR fixes a single thing with the smallest possible change. That keeps reviews simple, lowers the risk of side effects and lets one change be reverted without taking others with it.
-
The problem becomes a test
Fixes come with automated tests that cover the case that used to fail, so the problem cannot come back unnoticed.
-
The project's own bar
Formatting, static analysis and the full test suite run in the project's continuous integration, and a change only lands after the maintainer's review.
-
Written for the reviewer
Each PR description explains the problem, the change and how it was tested, so the maintainer can decide with confidence.
Where the work went
Each PR solves a single problem. Grouped by what it changes for the people using the tool:
-
5 PRs
Security and privacy
Secrets and sensitive content kept out of memory, users and projects kept apart, and deleted data that stays deleted.
-
8 PRs
Continuity across agents
Handoffs and context carry over from one session to the next and from one agent to another without getting lost, including in less common tools.
-
10 PRs
Reliability and operations
Nothing is lost in a backup restore, a shutdown, a server overload or a project move, and installation works the first time.
-
11 PRs
Knowledge base quality
Correct links, pages and consolidation, so the project wiki stays navigable and trustworthy.
Every PR, in business terms
Click a PR to see the problem, what was done and the value delivered. The link at the end of each one leads to the full technical discussion on GitHub.
Security and privacy 5 PRs
-
#1195merged Oct 9, 2026 Purging a session also deletes the sentences kept for the profile When a session was purged, the user's sentences collected from it for the preference profile stayed stored and could later become a profile page; they are now deleted along with the session.
- The problem
- ai-memory builds a user preference profile that applies across all projects, collecting preference-like sentences from requests; each one keeps the original text and points to its source session. Purging a project deleted these sentences, but purging a session removed the session, its records, pages and handoffs while leaving the sentences behind. A later pass could still write them into a profile page.
- What was done
- Session purge now also deletes the sentences collected from that session's requests, in the same operation that deletes everything else. The test checks that only the purged session's sentences disappear, not those of a neighboring session or of the same ID in another project. Anything already incorporated into the profile before the purge still requires the dedicated forget command.
- Value delivered
- A deletion request now also covers the user's own words: a sentence from a purged session can no longer resurface in the profile shared across projects.
-
#1194merged Oct 9, 2026 A purged session stays deleted, even with late events After a session was deleted on request, the next event from an agent recreated it with a new record; event intake now honors the deletion marker and discards those events.
- The problem
- The purge command deletes a session and leaves a marker so that late events, still in a client's queue or coming from an agent that is still open, cannot recreate it. That check lived at a point that live capture no longer went through: agent event intake created the session on its own, without looking at the marker. So the next event for a purged session brought it back, with a new record.
- What was done
- Event intake now checks the marker and refuses the event, answering "discarded, can never be stored" rather than reporting a failure; otherwise the client would keep the event, and everything queued behind it, retrying for a session that can never come back. The tests confirm that a neighboring session and the same ID in another project are still accepted.
- Value delivered
- Purging a session is now final: what someone asked to delete does not come back with the next event. And capture clients no longer get stuck resending those events.
-
#1128merged Oct 7, 2026 Passwords and keys filtered before any text is trimmed A secret that landed right at the cut-off point of a long text was split in half, and the leftover piece, unrecognizable to the filter, was stored in plain text; now the text is filtered whole and trimmed afterwards.
- The problem
- ai-memory stores session excerpts (requests, tool results, notifications, summaries) with a maximum size for each type. Trimming ran before the filter that hides passwords and access keys, so a secret at the cut-off point was split, and the leftover piece, too short to be recognized, was stored in plain text. On the user's machine, the capture client trimmed large texts with no filtering at all, so the fragment reached the server already unrecognizable.
- What was done
- The order is now reversed on both ends: the full text goes through the secret filter first, then it is trimmed to the maximum size, which stays the same. New tests place a key exactly at the cut-off point of requests, summaries and tool results, and in the local queue as well. In every case, only the redaction marker gets stored.
- Value delivered
- Closes a path through which fragments of passwords and access keys could end up stored in the project's memory despite the filter. It is the same kind of flaw fixed earlier in record titles, now closed for the content as well.
-
#1109merged Oct 6, 2026 Secrets filtered out before feedback reasons are cut An access key pasted into the reason for a feedback rating could be partly stored if it crossed the 500-character limit; the secret filter now runs before the cut.
- The problem
- Agents can rate whether a retrieved memory was useful and attach a reason of up to 500 characters. The text was cut at the limit and only then passed through the filter that removes secrets such as access keys. A secret crossing the limit became too short to be recognized, so its first part was stored and could show up in the wiki audit report.
- What was done
- The order is now reversed: the reason goes through the secret filter first, is then collapsed to a single line, and only then cut at 500 characters. A new test places an access key starting 12 characters before the limit and confirms no piece of it survives. It is the same fix applied earlier to the titles of observations captured in sessions.
- Value delivered
- Closes another path by which users' credential fragments could reach the database and the tool's reports. The protection now holds wherever the secret falls in the text.
-
#1083merged Oct 4, 2026 Each user can only delete their own context notes On multi-user servers, deleting a context note could remove the version shared with everyone or another person's note; deletion now follows the same rule as writing.
- The problem
- ai-memory keeps short context notes, such as the current focus, that go into the briefing at the start of every session and, on a multi-user server, can be personal. Writing already routed each user to their own area, but deletion did not: deleting the generic path removed the shared version everyone receives, and passing another person's path deleted their note.
- What was done
- Deletion now follows the same rule as writing. A regular user deleting the generic path removes only their own version, and an attempt to delete inside another person's area is refused with a clear message. Administrators can still delete any of them, and with per-user mode off, which is the default, nothing changes.
- Value delivered
- On shared servers, no one can delete another person's context or the team's common context anymore, whether by mistake or on purpose. Writing and deletion now respect the same isolation boundary.
Continuity across agents 8 PRs
-
#1190merged Oct 9, 2026 Crush: resume and import only use the main sessions Crush's internal sub-agent sessions were listed as sessions of their own, imported separately and even picked for automatic resume; now only the main conversations make the list.
- The problem
- Crush records main conversations and auxiliary sessions, such as sub-agent ones, in the same list, with the auxiliary ones pointing to their parent conversation. Session discovery already skipped them, but the listing used by three features did not: history import brought a sub-agent session in as a separate session of the project, the diagnostic command counted it, and automatic resume could pick it if it was the most recent.
- What was done
- The listing now skips sessions that have a parent conversation, the same filter discovery already applied. The test gained a sub-agent session newer than the main ones, which must not appear in the list, and it fails without the fix.
- Value delivered
- Crush users get a history without sub-agent sessions mixed in with the main conversations, and automatic resume goes back to the main conversation instead of landing in an internal session.
-
#1189merged Oct 9, 2026 Sessions found even with more than 2,000 stored conversations With more than 2,000 stored conversations, Codex, Pi, OMP and Grok could have a session reported as missing, and ai-memory started a new one from scratch; the lookup now reads the file named after the session first.
- The problem
- To find a session by its ID, ai-memory scanned the agent's conversation files and read at most the first 2,000, in an arbitrary on-disk order. For Codex, Pi, OMP and Grok, anyone with more than 2,000 conversations could have the session reported as missing. When the agent was opened through ai-memory, the linked session was then dropped and a fresh one started, and importing that conversation failed.
- What was done
- The lookup now reads the file whose name or folder contains the session ID first (that is how these agents save them), then the newest ones. The 2,000 limit stays, and each candidate is still confirmed by its header, so a wrong guess costs only one read. The test uses 2,500 decoy files with the right one at the end of the list.
- Value delivered
- Heavy users of these agents no longer lose a session's continuity just because their history grew: resuming and importing find the right conversation even among thousands of files.
-
#1187merged Oct 9, 2026 Kiro CLI tool use recorded with a real title and content Every time Kiro CLI used a tool, the record was stored with a generic title and empty content; it now gets the same treatment as Claude Code, with the kind of tool, the outcome and the output.
- The problem
- Kiro CLI's tool-use events reach ai-memory with the tool name, its input and, after it runs, the response. The capture rules already knew how to read that format, but Kiro was missing from the list of agents whose tools get a structured title and content. So every Kiro tool call was stored with a generic title and an empty body, and consolidating a Kiro session only saw the requests.
- What was done
- Kiro CLI joined that list, and its tool calls now get the same title and content as Claude Code's: the kind of tool, whether it succeeded, and the output it produced. Rules that exclude paths from capture keep applying as before. A new test uses events in Kiro's real format, for both versions of its engine, and fails without the change.
- Value delivered
- Kiro CLI users now get a memory of what was done in the session, not just what was asked. Knowledge consolidated from these sessions now takes the tools' work into account as well.
-
#1137merged Oct 8, 2026 Pi integration without an error warning on every launch The ai-memory extension for Pi sent its "connection ready" notice in a format the server rejected, logging an error warning on every launch; the notice now follows the protocol standard.
- The problem
- On startup, Pi tells the ai-memory server that the connection is ready. The extension generated by ai-memory sent that notice as if it were a request awaiting a reply, with an ID number. The server did not recognize it, answered with a "method not found" error and logged a warning every time Pi was opened, while the extension ignored the error and moved on.
- What was done
- The extension generator now sends the notice in the format meant for notices, with no ID and no reply expected, and accepts the server's empty success response. Tests check the generated extension and show that the server accepts the correct notice and still rejects the old format. Because the fix lives in the generator, reinstalling the integration does not bring the problem back.
- Value delivered
- Pi users running ai-memory no longer see a false error warning in the server log on every launch. And the server now receives the notice in a valid form, which never happened before.
-
#1081merged Oct 3, 2026 OpenCode 2 stops ending sessions that are still in use The OpenCode 2 plugin ended live sessions whenever OpenCode freed idle services, producing false summaries and handoffs; now only actually deleting a session ends it.
- The problem
- OpenCode 2 unloads and reloads plugins during normal use whenever it frees idle services, and on every unload the ai-memory plugin declared all running sessions ended. The session froze, stopped recording progress for each turn, and got a false summary and handoff. In the reported case, a single active session was ended 13 times in one day, with 16 handoffs, and the next delivery failed.
- What was done
- The generated plugin no longer ends sessions when it is unloaded. A session now ends only when it is actually deleted, and each completed turn still publishes its summary and handoff when the turn ends, so an abrupt shutdown loses nothing. Existing installs need to regenerate the plugin with the install command.
- Value delivered
- Anyone using ai-memory with OpenCode 2 keeps continuous sessions and reliable handoffs, without duplicate pages and handoffs or a language-model consolidation for every session end that never happened.
-
#1063merged Oct 3, 2026 Option to turn off the automatic handoff at the end of each session Every session end created a handoff for the next session, even for people working alone on a project; operators can now turn this automatic creation off without losing the session summary.
- The problem
- Every ended session generated a pending handoff that was injected at the start of the next one. For someone working alone and chaining sessions on the same project this became noise, because the previous session was the same person minutes earlier. There was no way to turn it off without also losing the session summary page, and one report counted more than 60 handoffs piled up before a manual cleanup.
- What was done
- A new server-wide setting turns off automatic handoff creation at session end. The default stays on, so nothing changes for anyone who leaves it alone. With the option off, the session summary and background consolidation run as usual, and handoffs created on purpose by the agent or by managed runs are unaffected.
- Value delivered
- People working alone stop getting repeated context every session and no longer pile up handoffs to clean up, without giving up the history. Anyone who relies on handoffs between agents keeps the current behavior.
-
#990merged Sep 30, 2026 Agents can tell whether a handoff already arrived or none is pending When asking for the handoff, the agent got the same empty answer whether nothing was pending or it had already been delivered at session start; the answer now says which case happened.
- The problem
- The tool that delivers the handoff answered "nothing" in two different situations: when no handoff was pending, and when it had already been injected into the context by the automatic session start. The model could not tell the cases apart from the answer, and the instructions needed a paragraph of warnings so the agent would not conclude there was no earlier work to resume.
- What was done
- The answer gained a status field: delivered now, already delivered at session start, or nothing pending. "Already delivered" is reported only to the very session that received the handoff, in the same project, for the same owner and while still active; forged identifiers, other projects, and sibling or ended sessions get "nothing pending". New tests fail if any of these guards is removed, and the existing field stays the same for current clients.
- Value delivered
- The agent stops guessing: it knows whether to use the context it already has or carry on without a handoff, with less risk of concluding there is no earlier work. The new information opens no gap, since no session can learn about another's handoff.
-
#664merged into release 2.2.0, Sep 7, 2026 Pending handoffs visible before they are claimed Agents that don't get the automatic context at session start could only see a pending handoff by consuming it blindly; they can now list what is pending and claim exactly the one they choose.
- The problem
- Some agents, such as Grok and Zero, can't receive the handoff that ai-memory injects automatically at the start of a session. For them, the only way to see a pending handoff was to accept it, which consumes it, since each handoff can be used only once. The agent always ended up taking the most recent one, without checking its content or being able to pick another.
- What was done
- A new read-only tool lists the project's open handoffs with their summary, open questions, next steps and files involved, without changing the state of any of them. The agent then claims exactly the handoff it picked, once. The listing follows the same ownership rules as delivery: other users' private handoffs stay hidden, and seeing all of them requires admin rights.
- Value delivered
- Agents without a session-start integration can now resume work by picking the right context instead of blindly consuming the most recent one. Isolation between users is preserved, as the maintainer's review confirmed, and nothing changes for other agents.
Reliability and operations 10 PRs
-
#1196merged Oct 9, 2026 Moving a project to another workspace takes all its data along When a project moved to another workspace, seven kinds of data stayed behind, including pending messages and deletion markers, while the operation reported success; now everything moves together.
- The problem
- The documentation says moving a project to another workspace updates all of its data, but the operation left seven kinds of data behind and still reported success. After the move, pending messages between projects could no longer be found, the project lost one of its search sources and the open feedback on its pages, a purged session could be recreated by a late event, and profile collection restarted, recording the same evidence again.
- What was done
- The move now updates the seven missing kinds of data, in the same operation and with the same criteria as the others, including both ends of each message. The documentation now lists what gets updated. The new test puts one record of each kind in place, moves the project, checks that all of them follow it to the destination, and fails without the fix.
- Value delivered
- Reorganizing projects across workspaces no longer silently drops messages, search data and pending feedback, and no longer reopens the door to sessions that had already been purged.
-
#1188merged Oct 9, 2026 OpenCode, OMP, Pi and OpenClaw keep events when the server is busy The integrations generated for OpenCode, OMP, Pi and OpenClaw dropped the event when the server asked to try later, and even erased the stored queue; they now keep the event and retry later.
- The problem
- Unlike the native client and the capture scripts, the integrations for OpenCode (both versions), OMP, Pi and OpenClaw treated an overloaded server's "try again later" answers as a permanent rejection. The event was neither kept nor resent, and was lost exactly when the server asked for a retry. Worse, sending the local queue deleted every stored event it hit in that situation, up to 500, from a queue shared with the native client.
- What was done
- The three answers that mean "try again later" are now handled as a temporary server failure: the event goes to the local queue, and sending the queue halts, keeping what is stored. The rule lives in a single shared function, so the three places that use it cannot disagree. The documentation, which said such errors are never retried, was corrected.
- Value delivered
- Users of these agents stop losing session records under load, and the queue kept by the native client is no longer erased by the plugin. The rule now matches the capture scripts, and reinstalling the agent's integration is enough to get the fix.
-
#1185merged Oct 9, 2026 Complete Docker-free install for Antigravity, Claude Code and Grok The Docker-free installer's script lists were out of date: installing for Antigravity CLI always failed, and Claude Code and Grok were missing the sub-agent scripts; the lists now match the packages.
- The problem
- The Docker-free installer keeps a hand-written list of scripts for each agent, and the lists had drifted from what the published packages contain. For Antigravity CLI, listed as supported in the documentation, it asked for seven scripts when the package has four, so the install always stopped with an error. For Claude Code and Grok, the two scripts that record when a sub-agent starts and ends were never installed, although the generated configuration pointed to them.
- What was done
- The installer now installs exactly the scripts each package ships: a dedicated four-script list for Antigravity CLI and the two sub-agent scripts for Claude Code and Grok. A new test feeds the installer the real file names for each of the nine script-based agents and requires the installed set to equal the published one.
- Value delivered
- The Docker-free install now works for Antigravity CLI and is complete for Claude Code and Grok, sub-agent events included. The new test flags any future mismatch between the lists and the packages.
-
#1184merged Oct 9, 2026 Docker-free install with capture working from day one The Docker-free installer copied each agent's capture scripts but not the support file they all load first, so no event ever reached the server; that file is now installed with them.
- The problem
- For people who do not use Docker, there is an installer that copies each agent's capture scripts from the published release. Every one of those scripts starts by loading a shared support file, which the installer never copied. After installing, each script stopped right at the start and nothing reached the server, and running ai-memory's own install command afterwards did not fix it either.
- What was done
- The installer now extracts the support file from the same verified release package and places it where the scripts already look for it. If the package lacks the file, the install stops with an error instead of leaving a broken setup, as already happened with a missing script. The installer test now requires the file and fails without the fix.
- Value delivered
- People who install capture without Docker now get records reaching the server from the first use, instead of an install that finishes without errors and records nothing.
-
#1146merged Oct 8, 2026 Capture scripts keep events when the server is overloaded When the server asked to try again later, the capture scripts for macOS, Linux and Windows dropped the event and even deleted the queue stored on disk; now they keep everything and retry later.
- The problem
- When overloaded, the ai-memory server answers "too many requests, try again later" by design; answers saying a request took too long or arrived too early ask for the same. The capture scripts for macOS and Linux and the PowerShell version for Windows treated these answers as a permanent rejection. The event was dropped instead of going to the local queue on disk, and sending the queue deleted the stored events on that answer.
- What was done
- Both sets of scripts now treat the three answers as temporary: the event goes to the local queue, and sending the queue pauses and keeps everything for the next attempt. Permanent rejections, such as an invalid request or missing permission, are still dropped as before. The tests include that control case, to show that only the temporary answers changed.
- Value delivered
- Prevents silent loss of session records exactly when the server is under load, for anyone using script-based capture, Windows included. The native ai-memory client already treated these answers as temporary, and the scripts now follow the same principle.
-
#1088merged Oct 4, 2026 Activity metrics count handoff lookups as reads Looking up pending handoffs, which changes nothing, was counted as a write in the agents' activity metrics; it now counts as a read and the numbers reflect actual use.
- The problem
- ai-memory counts, per client, how many reads and writes each agent performs, and those numbers show up in the admin metrics. The tool that only lists pending handoffs was left off the list of reads, and any tool not on that list counts as a write. Every lookup inflated the write counter.
- What was done
- The tool is now classified as a read. The tests now cover the classification of every read and every modifying tool, and a new test confirms that each lookup adds one read and no writes.
- Value delivered
- Server administrators see the real ratio between lookups and changes for each agent, with no phantom writes. The conservative rule of counting anything unclassified as a write still applies to new tools.
-
#923merged Sep 27, 2026 Backup restore that never wipes the current data Restoring from a damaged backup file could erase the existing memory before the problem was noticed; now the live data only moves after the backup has been checked.
- The problem
- The restore command deleted the live data folders before it even opened the backup file. If the file was truncated, corrupted or came from an incompatible version, the user was left with neither the old data nor the new, at the very moment they usually have no other copy.
- What was done
- The backup is now extracted and checked in a separate area first. Only after it passes does it replace the live data, and every step of the swap can be rolled back if something fails midway. Four new tests reproduce bad-archive scenarios and fail on the previous version.
- Value delivered
- Removes a path to total data loss during recovery, the riskiest moment of operations. Nothing destructive happens before whatever takes its place has been verified.
-
#781merged Sep 19, 2026 Wiki version history protected from invalid page names A page whose name was reserved by Git, such as ".git", was accepted and then blocked every later version snapshot of the wiki; invalid names are now refused on every write path.
- The problem
- The wiki keeps its change history with Git. Pages with names Git reserves, such as ".git" or the Windows short alias "git~1", were accepted, but Git refused them when recording the version, and the path stayed stuck in the queue, breaking every later snapshot. Meanwhile, batch writes from consolidation and approved improvement proposals skipped the check for names that don't work on Windows.
- What was done
- The valid-name rule now refuses Git-reserved names and applies on every write path: single pages, batch writes, proposal approvals, and the interfaces used by agents and administrators, which return a clear error. Version recording and the file watcher also skip these paths, and pages already stored remain readable so listings don't break.
- Value delivered
- Anyone relying on the wiki's version history no longer sees it stall because of a single bad name, and the rule that keeps a wiki usable on Windows now also covers what the system writes on its own.
-
#753merged Sep 18, 2026 Server tests stop competing for a limited machine resource Tests that start a real server only to check startup or shutdown were also turning on the wiki file watcher; they now switch it off, addressing the most likely cause of intermittent failures on macOS.
- The problem
- On macOS, the command-line test suite failed intermittently when run in parallel: each run broke different tests, all of which passed on their own. The maintainer's leading hypothesis was exhaustion of the operating system's file monitoring, which grows with the number of servers alive at once, and every one of these tests turned on the wiki watcher without needing it.
- What was done
- The servers started by these tests now use the product's existing option to switch off the file watcher, and each test checks in the server's own log that the watcher never started. The product default is unchanged, and the tests that do exercise the watcher are untouched. Since the failure never reproduced outside the original machine, the PR presents this as a mitigation, not a proven cure.
- Value delivered
- Contributors run a lighter, more isolated suite without losing any check: a reviewer measured five fewer open files and three fewer threads per test server, relief for the open-file limit that macOS keeps low by default.
-
#703merged Sep 10, 2026 Clean server shutdown under Docker, Linux services and Ctrl+C The server ignored the standard stop request from Docker and Linux service managers, or died without finishing work in progress; it now shuts down cleanly within five seconds.
- The problem
- The server did not handle the standard stop request sent by Docker and Linux service managers, and in one of its connection modes it did not even handle Ctrl+C. In containers the request was discarded: a stop waited out the whole grace period and ended in a forced kill, and in the reported case Ctrl+C did nothing. Outside containers, the process died on the spot and cut the end-of-session consolidation off midway.
- What was done
- Both connection modes now respond to Ctrl+C and to the standard stop request, listening from before startup finishes. Shutdown completes the work in progress, with a five-second cap on each wait so a stuck connection cannot hold the process open. Three new tests fail on the previous version; in manual checks the server exited in 58 and 10 milliseconds.
- Value delivered
- Anyone running the server under Docker can now restart and upgrade without waiting out the full grace period or forcing a kill, and work in progress finishes before exit. Containers also no longer need the helper process that used to be required just to pass the stop request along.
Knowledge base quality 11 PRs
-
#1192merged Oct 9, 2026 Review queue free of out-of-scale confidence scores An improvement suggestion where the model gave its confidence as a percentage passed the filter, showed up as 8500% and jumped to the top of the review queue; values outside 0 to 1 are now rejected.
- The problem
- Auto-improvement asks a language model for proposals to improve the knowledge base, each with a confidence score from 0 to 1; those below a minimum are discarded and the rest go to review. Nothing blocked values above 1: a model that answered in percent (85 instead of 0.85) cleared the minimum, showed up as 8500% and went to the top of the confidence ranking. An invalid value that is not even a number also got through.
- What was done
- Proposals with a confidence outside the 0 to 1 range are now rejected with a dedicated reason and recorded alongside the other rejected ones, so the next review sees why. The value is rejected, not adjusted: guessing whether 85 meant 85% would turn a malformed answer into a trusted score. Proposals already in the queue are left untouched.
- Value delivered
- Reviewers no longer see a proposal with an absurd score at the top of the queue, and a badly formatted model answer does not become a high score. Sorting by confidence now compares only valid values.
-
#1191merged Oct 9, 2026 Rules in Cyrillic, Chinese or Arabic no longer overwrite each other Every rule titled entirely in non-Latin characters, such as Cyrillic, Chinese or Arabic, went to the same page and replaced the previous one; each now gets its own stable name derived from the title.
- The problem
- During consolidation, each project rule becomes a page named after its title, using only Latin letters and digits. A title in Cyrillic, Chinese, Arabic or Greek produced no name at all and fell back to a fixed name shared by all of them. Within one batch, the last rule overwrote the others; across sessions, each new rule replaced the previous one, and only one showed up in the rules list displayed at the start of every session.
- What was done
- These rules now get their own name, with a short code computed from the title. The name is stable between runs, so a restated rule updates its own page, and two ways of writing the same accented character lead to the same name. Titles in the Latin alphabet keep their existing names.
- Value delivered
- Projects that record rules in Russian, Chinese, Arabic, Greek and other languages with non-Latin scripts now keep all of them active at session start, not just the most recent one.
-
#1141merged Oct 8, 2026 Expired pages also disappear from links and related pages Pages past their expiration date already left search results but still appeared in the web interface's link panel and in the related-pages list given to agents; now they disappear there too.
- The problem
- ai-memory lets pages be saved with an expiration date; after it, the page disappears from search, the recent list and the session-start summary. Two queries were left out: the web interface's link panel and the related-pages list an agent receives when it reads a page. There, an expired page kept appearing and still served as a bridge to reach other pages.
- What was done
- Both queries now apply the same validity filter as search: an expired page is no longer shown and is not used as a path to reach others. Opening an expired page directly by its address still works, on purpose, with a note that it has expired. Tests build live, expired and future-dated pages and check each case.
- Value delivered
- The expiration date now also holds when navigating through links: content marked for retirement no longer reaches agents through a side door, just as it already stayed out of search.
-
#1111merged Oct 6, 2026 Clean session record titles, Windows included On Windows, captured record titles could keep an invisible character at the end, and some event types kept multi-line titles; now every title is a single clean line.
- The problem
- ai-memory uses the first line of each request sent to the agent as the record's title. The rule only recognized the Linux and macOS line ending, so on Windows an invisible character was left at the end of the title and could reach the session title and the search index. Titles for session starts, notifications and the summaries produced when the agent compacts a conversation skipped this rule entirely and could keep line breaks.
- What was done
- All of these events now use the same first-line rule, which recognizes the Windows line ending as well as the Linux and macOS one. When the first line is empty, no title is suggested and the system falls back to the event's default title instead of storing a blank one. The tests cover requests with Windows line endings and the three event types that were previously left out.
- Value delivered
- Windows users get session and record titles that match those on other systems, with no hidden character going into the search index. Notifications and summaries also get single-line titles, as requests already did.
-
#1110merged Oct 6, 2026 No false wiki links from local-file and script addresses Addresses pointing to files on the computer or to scripts were read by the wiki as links to another project; they now follow the same blocking rule the web interface already applied.
- The problem
- The ai-memory web interface already treated addresses starting with file: (files on the computer) and vbscript: (scripts) as unsafe and displayed them as plain text. The wiki's link indexer did not recognize them: it read the prefix ("file", for example) as the name of another project and recorded a false link to it. The wiki's link index and export disagreed with what the page actually showed.
- What was done
- Both checks that identify wiki links now refuse these two prefixes, matching the list of blocked addresses used by the web interface. Both had to change, because fixing only one would still record the link to the "file" project. A new test covers both link formats the wiki accepts, including an address that points to a system file.
- Value delivered
- The wiki's link map, used for navigating between pages and for export, no longer picks up false links between projects. There is now a single rule for which addresses count as links, in indexing, export and display alike.
-
#1108merged Oct 6, 2026 No more duplicated page titles in files coming from Windows Pages whose title was underlined with equals signs and that used Windows line endings showed the title twice in the web interface; the duplicate is now removed in these cases too.
- The problem
- The web interface shows the page title in the header and removes the repeated title from the start of the text. For titles underlined with equals signs, one of the ways to write headings in Markdown, this failed in three cases: files with Windows-style line endings, an underline with trailing spaces, and a file ending right after the underline.
- What was done
- The check now ignores the extra character in Windows line endings and any spaces or tabs at the end of the underline, and it handles a file that ends on the underline line itself, as the other heading style already did. New tests cover all three cases.
- Value delivered
- Anyone working with the wiki on Windows sees pages with the same clean look as the rest, with no repeated title at the top.
-
#1105merged Oct 6, 2026 Section links scroll to the right spot in the web interface Headings on web interface pages had no identifier, so a link to a section opened the top of the page; every heading now has an address of its own.
- The problem
- Even after links started preserving the section reference (PR #1089), the web interface displayed page headings without identifiers. With no target, the browser had nowhere to scroll, and a link to a section opened the top of the page.
- What was done
- Every heading now gets a readable identifier derived from its own text: lowercase, without punctuation, with hyphens in place of spaces. Repeated headings on the same page get numeric suffixes so they don't collide, empty headings get a default name, and identifiers already set by the author are kept.
- Value delivered
- Completes the section navigation started in PR #1089: anyone following a wiki link or a shared address lands straight on the right part of the page.
-
#1089merged Oct 4, 2026 Links to a specific section keep their destination Wiki links pointing to a section of another page lost the section reference when displayed or exported; the full address is now preserved.
- The problem
- The wiki accepts internal links that point to a specific section of another page, a standard wiki notation. Both in the web interface and when the wiki was exported to files, the part naming the section was dropped, and the link only led to the top of the page.
- What was done
- Both link conversions now split off the section reference, along with any address parameters, before locating the page, then put it back on the final address. Links without a section and links to a section of the same page work as before, and the index still points to the right page.
- Value delivered
- People browsing the knowledge base land directly on the cited section, such as the context of a decision, and exported bundles keep the same precise references.
-
#1064merged Oct 3, 2026 Links to global pages work from any workspace Links to the pages shared by every project broke when written outside the default workspace; they now always point to the right place, and old ones are fixed when the global page is next saved.
- The problem
- ai-memory reserves a space for global pages, readable from every project, that lives in the default workspace. A link to one of those pages written in a project from another workspace was looked up in the source workspace: in the web interface it led to an address that did not exist, and in the map of relationships between pages it had no target. Since the consolidator's own instructions produce this kind of link, the system was writing links it could not resolve.
- What was done
- Links to the global space now always point to its fixed home in the default workspace, wherever they come from, both in the index and in the web interface. Other link forms, including those that name a workspace explicitly, are unchanged. Old links stored in the broken form are fixed the next time the global page is saved.
- Value delivered
- For anyone who organizes work across more than one workspace, shared rules and preferences become reachable through the links the system itself writes. Nothing new is exposed, since global pages were already readable from every project.
-
#985merged Sep 30, 2026 Wiki links that no longer vanish or lead to missing pages Links in common technical-documentation cases vanished, turned into false links or led to missing pages; link reading now follows the standard Markdown specification.
- The problem
- Link reading failed in common cases. A code block opened with a longer or different marker was closed too early, so code lines became links while the text after it was treated as code. Addresses with parentheses, such as Wikipedia links, were cut short and dropped, relative links starting with "./" returned page-not-found in the web interface, and export produced invalid links to pages with spaces in their names.
- What was done
- Link reading now follows the standard Markdown specification: a code block only closes with the same kind and length of marker that opened it, balanced parentheses and addresses wrapped in < and > are recognized, addresses with spaces are exported inside those signs, and the "./" prefix is removed before opening the page. Each case got a test that keeps the problem from coming back.
- Value delivered
- For anyone who writes and reads the wiki, links stop disappearing from the map of relationships between pages, exports produce files other Markdown tools accept, and clicking a relative link in the web interface opens the right page.
-
#926merged Sep 27, 2026 Every session page gets its own title in the wiki Similar sessions produced pages with the same generic title; each session page now gets a name of its own, without eating into the room the model needs for the session's content.
- The problem
- Repeated, near-identical runs, such as Grok Build ones, produced session pages with the same generic title (for example, "Adversarial Verification"), and the wiki audit flagged duplicate titles. Adding more instructions for the model was not enough on its own: at the smallest input limit the configuration accepts, the extra text left the model with no session observations to summarize.
- What was done
- The instructions gained two short lines asking for a title specific to the session, and the list of titles already in use, capped at 15, is sent only when the project has any. As a final safeguard, a title that still matches an existing one, ignoring case and extra spaces, gets a suffix with the session's short identifier when it is written. Tests confirm the session content still reaches the model even at the minimum limit.
- Value delivered
- People browsing the project wiki find each session by its own name and the audit stops flagging duplicates, without the fix degrading summaries: the model keeps receiving the session content even on the leanest configuration.
Figures updated on Oct 11, 2026.
The same care in your system
The habits behind these PRs carry over to backends that move money: reproduce the problem before fixing it, prove the fix with a test and keep sensitive data from leaking.