Repository navigation
Conversation
Domain, sensitivity, and project requirement are computed in one place. No product path calls it yet, so reads and writes stay as they are in v0.20.0.
2 of 5 tasks
samrusani
force-pushed
the
cursor/derived-labels-kernel-a34e
branch
from
October 5, 2026 19:38
398e797 to
abfb6a2
Compare
This was referenced Oct 5, 2026
This was referenced Oct 5, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Published draft head
9ddcb6ab3d668e05c291d8cc712b788fc27649c8has 22 successful GitHub checks in the exact-head snapshot observed at 2026-10-06T00:48:16.326311+00:00. All nine final draft heads are green in that same snapshot.Final combined root
89e13def51b508ce42155d7dcad9a310e7b95fbbhas 13,858 passing unit cases and 20 skips through the recorded complete corrective shards. Global statement-plus-branch coverage is 85.619226%; one aggregate statement gate across 14 API paths reaches 71.538857% (4170/5829), above its 45% floor. The source-equivalent CI migration model passes 669 PostgreSQL cases with one intentional skip; static, Bandit, LongMemEval, actual upgrade/restore and all 20 strict concurrency suites pass within their recorded heads. Capture and relabel budgets pass at their measured head with verified unchanged final source paths. These combined receipts are distinct from each historical local worker selection below.The only restricted-owner full PostgreSQL failure is unchanged historical migration 0067; current 0096 retains restricted owner controls and the actual CI migration model passes. Designated control-tower merge approval and owner/security-team approval before the tag are external gates. Earlier force-push variance and the missing original standalone kernel-main proof remain disclosed; no release, deployment or second full independent scan is claimed.
Introduce a shared pure kernel for derived domain, sensitivity, project scope and project floor. Incomplete ancestry, cycles, ambiguous UUID identities and nonempty canonical records with blank or missing counts become unverified. The kernel preserves recorded restrictions and understands nested consolidation membership; later stacked PRs connect it to runtime reads and writes.
These changes are proposed and unmerged; they are not part of the released v0.20.0.
Historical validation
138 kernel, mutation and project-view tests passed. The kernel typing errors are resolved. The saved snapshot reported a CI rerun; the final exact-head remote CI is now reported above.
Historical combined-stack unit matrix: 13,401 passed, 20 skipped and 11 initial failures. All 11 failures passed the corrective rerun; the affected owning modules also passed 275 tests. Combined coverage is 85.64% (required 50%); API carrier coverage is 70.56% (required 45%). This was a complete matrix followed by focused corrective reruns, not one clean full invocation. Those historical local results did not establish current-head CI. The final exact-head remote checks are reported above; outside merge approval remains separate.
Reproduction and executed mutations
Historical builder evidence recovered from the original description at
398e7970c47de48f0d7e4c982290f4fae87050d8:On origin/main the module is not there, so
tests/unit/test_derived_labels_kernel.pydoes not collect. On this branch, 19 kernel tests andtests/unit/test_derived_labels_mutations.pypass (20 tests).tests/unit/test_per_project_view_predicates.pypasses with the newfloorargument left empty.Mutations, each restored after the named test failed:
>=instead of>in_raised_sensitivity. Failstest_sensitivity_is_raise_only_and_unknown_never_swaps_with_internal.union_floorkeeps only the stored floor. Failstest_floor_is_the_union_and_never_shrinks.test_scope_rules_per_row_class.test_scope_rules_per_row_class.test_every_unverified_case_is_unverified.derived_fromcounts are ignored. Failstest_every_unverified_case_is_unverified.test_unverified_is_contagious_through_every_level.test_every_unverified_case_is_unverified.project_flooris ignored inevaluate_agent_policy. Failstest_project_floor_blocks_a_locked_key_and_does_not_change_an_empty_floor.labels_raisedpayload gainsinput_id. Failstest_labels_raised_events_carry_no_text_or_ids.sacredto 7. Failstest_the_seven_sensitivity_rank_tables_equal_the_kernel_table.test_scope_rules_per_row_class.test_scope_rules_per_row_class.test_every_unverified_case_is_unverified.test_every_unverified_case_is_unverified.Not verified in that original local receipt: the full
tests/unitrun, the docs tests, Bandit, mypy, and the Postgres integration job. At the original pure-kernel stage, no route posted the forgedvalue.kindbecause runtime wiring belonged to later stack stages. Later real stack behavior probes are separately reported; a standalone kernel-main behavior failure is not claimed.The recovered description does not retain a complete main-failure command and output. That evidence remains a review obligation; a missing-module collection failure alone is weaker than an exercised behavior regression. The list above records reported executed mutations. It does not turn other mutations proposed in test docstrings into executed proof.
Current validation and executed mutations
The original pure-kernel harness executed 14 distinct mutations. The historical description lists the aggregate-scope removal twice, as M6 and M48; that is one compiled-source mutation. A standalone behavioral failure on frozen main is still absent because the kernel did not exist there. The four authenticated frozen-main API failures retained by the producer work motivate the wired stack, and must not be attributed to this isolated kernel PR. Fresh physical kernel and seven-rank-table receipts are now retained, with cumulative experiment boundaries below.
The cumulative fresh physical kernel campaign now supplies the following named kills and original/restored hashes, distinct from the recovered in-memory historical harness. Experiments use production head
a47b2e0fwith later test-only follow-ups through0f27c36e; not every mutation was rerun at the final control head.M1Ktests/unit/test_derived_labels_kernel.py::test_sensitivity_is_raise_only_and_unknown_never_swaps_with_internalM2Ktests/unit/test_derived_labels_kernel.py::test_floor_is_the_union_and_never_shrinksM4tests/unit/test_derived_labels_kernel.py::test_a_chain_settles_in_one_passM5tests/unit/test_derived_labels_kernel.py::test_scope_rules_per_row_classM6K-copytests/unit/test_derived_labels_kernel.py::test_scope_rules_per_row_classM6K-aggregate-M48Ktests/unit/test_derived_labels_kernel.py::test_scope_rules_per_row_classM14Ktests/unit/test_derived_labels_kernel.py::test_every_unverified_case_is_unverifiedM15Ktests/unit/test_derived_labels_record_completeness.py::test_canonical_counts_and_identifiers_do_not_use_the_legacy_duplicate_exceptionM16Ktests/unit/test_derived_labels_kernel.py::test_unverified_is_contagious_through_every_levelM17Ktests/unit/test_derived_labels_kernel.py::test_every_unverified_case_is_unverifiedM26-M47Ktests/unit/test_derived_labels_kernel.py::test_scope_rules_per_row_classM49Ktests/unit/test_derived_labels_kernel.py::test_every_unverified_case_is_unverifiedM58Ktests/unit/test_derived_labels_record_completeness.py::test_a_missing_or_malformed_legacy_completeness_record_is_unverifiedcanonical-blank-identifierstests/unit/test_derived_labels_record_completeness.py::test_canonical_counts_and_identifiers_do_not_use_the_legacy_duplicate_exceptioncanonical-missing-countstests/unit/test_derived_labels_record_completeness.py::test_a_nonempty_canonical_record_requires_well_formed_complete_countsCanonical blank or missing counts are explicitly tested; the original kernel description's missing-main-module collection claim remains historical. The seven physical module-rank mismatch kills belong to the wired producer campaign, and no standalone production-route failure is attributed to this isolated kernel change.
At the final PR head
9ddcb6ab3d668e05c291d8cc712b788fc27649c8, 65 selected kernel controls passed in 0.63 seconds. The independent full-unit run belongs to the earlier frozen366e56bac5605cffb3e7562b2bd1bf8ca2c7132b: 13,389 passed, 20 skipped and one credential-scanner timing case failed. At the final head, all four cases in that timing family passed the isolated retry in 1.70 seconds. This is earlier broad proof plus final focused controls, not a clean local final-head full-suite pass. The later exact-head remote checks supply separate broad CI proof.The full command ran in an isolated synthetic checkout with its repository source and scratch temporary directory. The portable spelling above omits local interpreter and scratch paths; no unrecorded coverage option is added. The retained 65-control result does not preserve its selection command, so no exact selection argv is fabricated here.
Tested head and remaining gates
The final publication head is
9ddcb6ab3d668e05c291d8cc712b788fc27649c8. The saved original PR snapshotabfb6a25b9d7c7005e53b71d55772858476c2b7dremains historical. The earlier recovered broad matrix and its corrective reruns remain historical evidence above. All tests use synthetic fixtures; no live vault or production database is asserted. The final exact-head GitHub CI snapshot is verified above. The final combined validation, bounded M1-M58 reconciliation, measured source mapping and scoped execution/skeptic evidence are separately recorded above. Designated outside approvals are not issued by this work. Merge, the dedicated release tag, the owner's security-team review before the tag and advisory publication remain separate gates.Upgrade Overview
Protected Areas
The checked areas cover the complete cumulative diff of this exact published head against the frozen release base.
Compatibility Impact
Derived content may become stricter or disappear from restricted reads when current input labels, project scope or incomplete ancestry require it. Provenance, text and original-row trust meanings are preserved. The pure kernel alone rewrites no stored row. Owner and unbound admin controls retain their applicable policy contracts. List counts must use the complete admitted population; a limited fetched page cannot substantiate a total.
Migration / Rollout
No migration is added by this PR. Land the kernel before runtime consumers. Ship the seven-PR set together in the dedicated security release.
Operator Action
No manual rewrite is required for this isolated kernel change. Complete final acceptance and current CI before rollout.
Validation
Earlier worker commands retain their actual tested revisions and limits. Final exact-head remote CI and the source-equivalent combined acceptance are separately established in the current summary; they do not backdate the historical local receipts. Designated control-tower merge approval and owner/security-team release approval remain external gates. Historical process and evidence limits remain disclosed.
Rollback
Revert consumers before the kernel. Raised labels and scrubbed content persist; reverting code or migration 0096 does not lower labels or restore removed text. Keep a compatible backup and rerun restricted-read verification after recovery.
Process variance
The existing review branch name is preserved. It differs from the handoff naming convention. Earlier updates to #565 through #569 used identity-only force-pushes and violated the mandatory no-force-push rule; preserving source trees did not make them compliant. This historical violation cannot be erased by later tests. Further updates use ordinary commits and plain merges. The handoff contains a later rebase sentence that contradicts its mandatory plain-merge rule; the mandatory rule governs.