- #368 (user,character) memory silo test DONE + PASSED live (WT b127): write-side conjunctive {end_user,agent_self} scoping + read-side cross- character isolation both proven end-to-end; betty (throwaway) deleted, Sindra intact. Full record in persistent-memory.d/2026-07-18-368-silo- test-passed.md. Retired the stale "silo test in progress" in-flight blocks. - Two-tier migration: split 152 over-threshold dated entries into persistent-memory.d/ detail files, leaving one-line pointers in the index (startup load ~196KB -> ~53KB; bodies now load on demand). - Tier-3 stores scrubbed clean (memory 0 / affect 0, provider restarted empty); persistent-memory + detail file updated to reflect the scrub.
910 B
[2026-07-01] env.sh now PERSISTS the web Bifrost-bind vars (gitignored, local-only). ratatoskr-web's in-browser bind needs three server-held values; env.sh sources provider.env for the Heimdall key and exports RATATOSKR_BIFROST_CONSUMER_KEY + RATATOSKR_PROVIDER_VISIBLE_HOST=10.100.10.50 + RATATOSKR_AFFECT_READ_URL=:8392. The HS256 byte-match trap (re-hit + documented): the bind's consumer key must equal the key the :8392 combined provider validates against = RATATOSKR_HEIMDALL_KEY (provider.env, fp 45a0…), NOT WORLDTREE_API_KEY (env.sh, fp 7c2f…) — both are the SAME ratatoskr identity but DIFFERENT 40-char strings; signing with the wrong one → bifrost.auth_rejected. Single-sourced (env.sh sources provider.env) to avoid a rotation footgun; guarded with a stderr warning if provider.env is missing. [auto-memory: HS256-key-is-the-consumer-Heimdall-key-string]