* docs(plans): plan-26 Telegram session wrap-ups from the Stop summary
Alex, 2026-09-12: "the 'telegram session wrap-ups' are not derived of the
stop hook summary, they're coming at the end of all turns. ALSO NOT scoped
that way".
Verified against this checkout: notifyTelegram fires per observation batch
from the PostToolUse path (ResponseProcessor.ts:623-628), never from the
summary path (:828-890); the plugin registers Stop (per turn) and no
SessionEnd (plugin/hooks/hooks.json); delivery is one global chat with no
route, no ledger. Claude Code docs give SessionEnd a 1.5 s budget that
plugin timeouts cannot raise, so the hook must POST and exit.
Plan: SessionEnd hook + /api/sessions/session-end; wrap-up text is the
latest stored summary (getSummaryForSession, no new model call); SQLite
ledger telegram_wrapups (schema v52) with atomic claim; JSON route map
CLAUDE_MEM_TELEGRAM_WRAPUP_ROUTES with exact/parent match and reject on
unknown; observation alerts behind a new default-off switch. Four Codex
phases, each with exact files, bun tests and a stop line.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017DdeSScwheHym2T4xQ8cLW
* feat(telegram): wrap-up ledger, routes and notifier (plan-26 phase 1)
Baseline failures (pre-existing):
- tests/worker/field-deadline-wire.test.ts — mandatory first-baseline failure
- tests/infrastructure/plugin-distribution.test.ts — mandatory first-baseline failure
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017DdeSScwheHym2T4xQ8cLW
* docs(telegram): mark plan-26 phase 1 complete
* feat(telegram): SessionEnd hook, session-end route and wrap-up request (plan-26 phase 2)
Verification: focused 2/2 + 2/2 + 9/9; CLI+HTTP 176/176; build/tsc green; full npm test 3758 pass, 28 skip, sole pre-existing field-deadline failure. Cold Node probe 0.197/0.172/0.170s failed pre-dispatch due inherited bun:sqlite Node incompatibility.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017DdeSScwheHym2T4xQ8cLW
* docs(telegram): mark plan-26 phase 2 complete
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017DdeSScwheHym2T4xQ8cLW
* feat(telegram): deliver wrap-up after the session-end summary lands (plan-26 phase 3)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017DdeSScwheHym2T4xQ8cLW
* docs(plan): mark telegram wrap-up Phase 3 complete
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017DdeSScwheHym2T4xQ8cLW
* docs(telegram): wrap-up routes, alerts default off; plan-26 verification
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017DdeSScwheHym2T4xQ8cLW
* docs(plan): mark telegram wrap-up Phase 4 complete
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017DdeSScwheHym2T4xQ8cLW
* fix(telegram): recover SessionEnd wrap-up review findings
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017DdeSScwheHym2T4xQ8cLW
---------
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Mechanical package-facing bump so 13.24.22 ships the empty-title observation capture fix now on main after v13.24.21. Rebuilds plugin bundles so the injected version matches. Does not npm publish.
Mechanical package-facing bump so 13.24.21 ships the session rehydration fix now on main after v13.24.20. Rebuilds plugin bundles so the injected version matches. Does not npm publish.
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Alex Newman <thedotmack@users.noreply.github.com>
Package-facing patch bump so 13.24.20 ships the commits now on main after v13.24.19. Rebuilds plugin bundles so the injected version matches.
Does not npm publish.
Package-facing patch bump so 13.24.18 ships the commits now on main after v13.24.17. Rebuilds plugin bundles so the injected version matches.
Does not npm publish — Prioritizer publishes from tag.
Package-facing patch bump so 13.24.17 ships #4026/#3575 (health probe deadline cap), #3445 (desktop-bundled Codex CLI on macOS), and #4027 (register memory_session_id, do not re-register). Rebuilds plugin bundles so the injected version matches.
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Alex Newman <thedotmack@users.noreply.github.com>
Package-facing security patch for the #3861 / #3985 credential-leak fixes
(unauthenticated /api/settings redaction, MCP workspace containment, host
bind tightening). Publish-ready; do not npm publish from this PR.
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Alex Newman <thedotmack@users.noreply.github.com>
Raw tool I/O had no durable home. `pending_messages` is the generation
queue -- rows are claimed, summarized, and deleted -- so once an
observation existed the original tool_input/tool_response were gone.
Adds `tool_uses` (schema v51) as a by-reference side index for those
bodies, written from the one ingest choke point both the PostToolUse hook
route and the transcript-watch processor already share. The JSONL
transcripts and `src/services/transcripts/*` remain the spine and are
untouched.
Schema (Receipt freeze 2026-09-06): UNIQUE(content_session_id,
tool_use_id), nullable `or_generation_id` / `or_session_id` as join keys
back to an OpenRouter spend line, and deliberately no cost_usd/micros --
this table carries tool identity, dollars stay on the OR stamp. No FK on
session_db_id/observation_id: a FK there can abort the constructor
migration chain (#3378), and observation_id is linked late by design.
Write path dual-writes alongside -- never instead of -- the
pending_messages enqueue, and swallows its own failures so an observation
is never lost to a backup-index error. `toolUseId` now actually reaches
the worker from hooks: it was missing from NormalizedHookInput and every
hook adapter, so only the transcript path supplied it. ResponseProcessor
links the batch's claimed ids to the first stored observation.
Read path is progressive-disclosure layer 4: POST /api/tool-uses/batch
requires explicit ids (never a full-table scan), GET /api/tool-uses
returns a cheap index shape with size hints and never the payloads, and
the `get_tool_uses` MCP tool is described as a last resort. claude-mem's
own read tools are skipped by the writer -- without that, every call to
get_tool_uses would store the bodies it just returned.
Payloads are stored in-row with a 64 KB soft cap and a UTF-8-safe
truncation marker; content_hash is computed over the original.
Join contract for Receipt: RECEIPT-JOIN.md
Claude-Session: https://claude.ai/code/session_01QgdJ6gExgBirDoAxknt94m
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
* fix: rebuild plugin bundles so committed artifacts match manifest 13.24.0
The 13.24.0 release commit (85ccd626) bumped the manifests and CHANGELOG
but never re-ran the build, so plugin/scripts/*.cjs kept the 13.23.1 bytes
last produced by 89ca057a. The Claude Code marketplace installs straight
from this repo (.claude-plugin/marketplace.json -> "source": "./plugin"),
so every marketplace user on 13.24.0 has been executing 13.23.1 code.
ensureWorkerRunning() compares the resolved plugin version (13.24.0, taken
from the plugin cache directory name) against the worker's baked-in
__DEFAULT_PACKAGE_VERSION__ (13.23.1, reported by /api/health). The
mismatch SIGKILLs the worker and respawns the same stale file on every
hook event, with no state that survives the hook process to bound it --
an unbounded kill/respawn loop that takes the in-flight observer
generator down with it, so no observations get written.
This is a genuine `npm run build`, not a version-string patch. The
bundles were stale in code, not merely in the constant: src/ moved 704
insertions across 12 files since 13.23.1, including the observer's
<skip_summary reason="noise" /> protocol change, the new manual-session
module, and the platform_source plumbing in SessionStore and MemoryRoutes.
No version bump: the manifests were already correct at 13.24.0. It is the
artifacts that were wrong.
Fixes#3857
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bshprs1vjut2XmaGTRESqX
* fix(tests): restore module mocks so worker-spawner stubs stop leaking
bun runs the whole suite in one process and mock.module is process-global
and sticky, so stubs installed by one test file stay installed for every
file loaded after it.
tests/services/worker-spawner.test.ts mocked
src/services/infrastructure/{ProcessManager,HealthMonitor}.js and never
restored them. tests/infrastructure/{health-monitor,process-manager}.test.ts
import the same symbols through the src/services/infrastructure/index.js
barrel, so they silently exercised those stubs instead of the real code:
isPortInUse returned false without touching net.createServer, waitForHealth
returned false without fetching, getPlatformTimeout skipped the Windows
doubling, cleanStalePidFile always reported 'dead', and spawnDaemon never
returned undefined. waitForPortFree stayed real but resolved through the
stubbed isPortInUse binding, inverting its timeout case.
This is order-dependent, not new: bun walks test files in filesystem order,
and a fresh CI checkout loads worker-spawner (59) well before health-monitor
(169) and process-manager (172), while many local checkouts load
tests/infrastructure first and pass. That ordering is what surfaced 19
failures in Actions run 33939805959.
Snapshot the real namespaces eagerly, before the mock.module calls, and
reinstall them in afterAll. The snapshot must be eager: `import * as x`
yields a live namespace object that bun re-points when the module is mocked,
so spreading it inside afterAll copies the stubs back in. That is exactly
the latent bug in tests/cli/handlers/context-session-start.test.ts, whose
restore was re-installing its own hook-settings, oauth-token, project-name
and worker-utils stubs; fixed here the same way.
Tests only. No source, plugin bundle, or version changes — the committed
artifacts still match manifest 13.24.0.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LcjsK6QqeBcYXbJ8gqBsea
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Regenerated from src including 7c8c6ebc7 (joined drain pushes real
memory_session_id/project on prompts) and 5af1b059b (v40 requeue +
backfill lane). Deployed live: v40 re-queued all 20,226 local prompts
and the worker drained them to zero through the backfill lane with no
errors.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>