Skip to content

Filter locked report inputs by every project - #567

Merged
samrusani merged 96 commits into
mainfrom
cursor/derived-labels-producers-a34e
Oct 8, 2026
Merged

samrusani merged 96 commits into
mainfrom
cursor/derived-labels-producers-a34e

Conversation

@samrusani

@samrusani samrusani commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Stacked on #566.

Summary

Published draft head 5b0b4d64e8550db62e064dee6cf00902862f0b90 has 22 successful GitHub checks in the exact-head snapshot observed at 2026-10-06T00:48:16.326311+00:00. All nine final draft heads are green in that same snapshot.

Final combined root 89e13def51b508ce42155d7dcad9a310e7b95fbb has 13,858 passing unit cases and 20 skips through the recorded complete corrective shards. Global statement-plus-branch coverage is 85.619226%; one aggregate statement gate across 14 API paths reaches 71.538857% (4170/5829), above its 45% floor. The source-equivalent CI migration model passes 669 PostgreSQL cases with one intentional skip; static, Bandit, LongMemEval, actual upgrade/restore and all 20 strict concurrency suites pass within their recorded heads. Capture and relabel budgets pass at their measured head with verified unchanged final source paths. These combined receipts are distinct from each historical local worker selection below.

The only restricted-owner full PostgreSQL failure is unchanged historical migration 0067; current 0096 retains restricted owner controls and the actual CI migration model passes. Designated control-tower merge approval and owner/security-team approval before the tag are external gates. Earlier force-push variance and the missing original standalone kernel-main proof remain disclosed; no release, deployment or second full independent scan is claimed.

The current published ordinary draft head is 5b0b4d64e8550db62e064dee6cf00902862f0b90. The ordinary forward merge includes the earliest #566 FTS fixture correction. The coordinator runs the complete retrieval module at this exact head: 119 passed in 1.35 seconds. The midnight report-window fixture belongs to #569, where that integration module is introduced; it is not attributed to this PR. All later dependency updates use ordinary merges and normal pushes. Current-head GitHub CI now has 22 successful checks at the final snapshot. Designated outside premerge approval remains separate.

Project-bound producers require every project in an input's scope and floor to fit the binding; ordinary unbound views retain overlap semantics. Reports record canonical provenance, consolidation and rollups compare group scope, and project views respect inherited floors. Includes the corrected typing and write-path fixes from #565 and #566.

These changes are proposed and unmerged; they are not part of the released v0.20.0.

Historical validation

Producer, consolidation, rollup, group-scope, project-view and locked-input regressions passed. The combined stack passed 512 PostgreSQL integration tests (1 skipped) and the 216-test LongMemEval suite. Ruff and release-static typing passed.

Historical combined-stack unit matrix: 13,401 passed, 20 skipped and 11 initial failures. All 11 failures passed the corrective rerun; the affected owning modules also passed 275 tests. Combined coverage is 85.64% (required 50%); API carrier coverage is 70.56% (required 45%). This was a complete matrix followed by focused corrective reruns, not one clean full invocation. Those historical local results did not establish current-head CI. The final exact-head remote checks are reported above; outside merge approval remains separate.

Reproduction and executed mutations

Historical builder evidence recovered from the original description at a97fbb36a656069e08906b1545531b6d5c270440:

tests/unit/test_view_floor.py (2). Dropping the floor from _resource_matches_project_scope made test_python_view_mirrors_hide_a_foreign_floor admit a row whose floor names another project. The floor argument was restored.

Earlier producer tests: tests/unit/test_group_scope_consumers.py (7). A combined run of the consolidation, roll-up, memory-commit, scheduler, brain, connection, contradiction, and store-split files was 447 passed. Receipt, brain, SQLite store, queue, and report-label files: 218 passed.

Not verified in that historical local receipt: the full tests/unit run, Bandit, mypy, and the Postgres generation tests.

The recovered description does not retain a complete main-failure command and output. That evidence remains a review obligation; a missing-module collection failure alone is weaker than an exercised behavior regression. The list above records reported executed mutations. It does not turn other mutations proposed in test docstrings into executed proof.

Remediation evidence at packet cutoff

The producer tranche at a47b2e0f exercises eight authenticated production generators with positive controls and checks body, stored row, events, GET, trace, promoted copy, recall and explain. It also exercises 252 floor cells across both SQLite SQL builders and five Python mirrors. The retained frozen-main probe executes four actual API failures: two incomplete-provenance reports remain readable, and daily and weekly generation print a shared-project sentinel to an alpha-bound key. These motivate the combined stack.

python -m pytest main_behavior_probe.py -q -p no:randomly
FAILED test_a_bound_key_cannot_read_a_report_with_incomplete_dependencies[record0]
FAILED test_a_bound_key_cannot_read_a_report_with_incomplete_dependencies[record1]
FAILED test_a_real_alpha_key_generator_never_prints_a_shared_input[daily-brief]
FAILED test_a_real_alpha_key_generator_never_prints_a_shared_input[weekly-synthesis]
4 failed in 5.15s

The probe is retained synthetic evidence transplanted into the frozen main checkout, not a claim that this test file ships on main. The candidate probe ran at a47b2e0f7fea7c0a0d76604f6f8919cfd8e13157 and passed four cases in 8.65 seconds. This is a worker checkout control, not final combined proof.

The final producer ledger records 54 actual physical mutation experiments with matching original and restored hashes. These are cumulative experiments across test tranches a47b2e0f, 47378a7b and 0f27c36e; the production files match across those test-only follow-ups. They were not all repeated at 0f27c36e, which is the final restored-control head. Individual source ledgers and fragments retain experiment chronology.

The 342-test proof selection passed at 47378a7bcb93ec640e732b01b29b19a0b1831acb. Final restored controls at 0f27c36eebf7052d549f1d9a364e8d728c049f24 are still running at this cutoff. All eight producer paths, five Python view mirrors, both SQLite SQL builders, seven rank-module copies, nine effective-input families and four individual scoped rollup queries have declared physical kills. The two consolidation-input mutations initially survived their fixtures; stronger provider-input and stored canonical-record checks killed them. Those survivors remain in the history rather than being erased. The earlier canonical-missing-count fixture survivor is also preserved with its decisive follow-up kill.

Executed producer/kernel/view mutation Named failing test
M1K tests/unit/test_derived_labels_kernel.py::test_sensitivity_is_raise_only_and_unknown_never_swaps_with_internal
M2K tests/unit/test_derived_labels_kernel.py::test_floor_is_the_union_and_never_shrinks
M4 tests/unit/test_derived_labels_kernel.py::test_a_chain_settles_in_one_pass
M5 tests/unit/test_derived_labels_kernel.py::test_scope_rules_per_row_class
M6K-copy tests/unit/test_derived_labels_kernel.py::test_scope_rules_per_row_class
M6K-aggregate-M48K tests/unit/test_derived_labels_kernel.py::test_scope_rules_per_row_class
M14K tests/unit/test_derived_labels_kernel.py::test_every_unverified_case_is_unverified
M15K tests/unit/test_derived_labels_record_completeness.py::test_canonical_counts_and_identifiers_do_not_use_the_legacy_duplicate_exception
M16K tests/unit/test_derived_labels_kernel.py::test_unverified_is_contagious_through_every_level
M17K tests/unit/test_derived_labels_kernel.py::test_every_unverified_case_is_unverified
M26-M47K tests/unit/test_derived_labels_kernel.py::test_scope_rules_per_row_class
M27-SQL tests/unit/test_project_floor_views.py
M28-Python tests/unit/test_project_floor_views.py
M49K tests/unit/test_derived_labels_kernel.py::test_every_unverified_case_is_unverified
M51 tests/unit/test_group_scope_sqlite.py::test_a_consolidation_candidate_over_a_two_project_group_is_accepted
M52-SQLite tests/unit/test_group_scope_sqlite.py::test_a_second_scoped_rollup_run_over_the_same_group_finds_its_card_and_inserts_nothing
M52-Postgres tests/integration/test_derived_labels_group_scope_postgres.py
M53 tests/integration/test_derived_labels_producers_postgres.py::test_input_selection_uses_effective_labels_including_the_owner_default_ceiling
M58K tests/unit/test_derived_labels_record_completeness.py::test_a_missing_or_malformed_legacy_completeness_record_is_unverified
M42-vnext_brain tests/unit/test_derived_labels_kernel.py::test_the_seven_sensitivity_rank_tables_equal_the_kernel_table
M42-vnext_consolidation tests/unit/test_derived_labels_kernel.py::test_the_seven_sensitivity_rank_tables_equal_the_kernel_table
M42-vnext_connections tests/unit/test_derived_labels_kernel.py::test_the_seven_sensitivity_rank_tables_equal_the_kernel_table
M42-vnext_contradictions tests/unit/test_derived_labels_kernel.py::test_the_seven_sensitivity_rank_tables_equal_the_kernel_table
M42-vnext_rollups tests/unit/test_derived_labels_kernel.py::test_the_seven_sensitivity_rank_tables_equal_the_kernel_table
M42-vnext_scheduler tests/unit/test_derived_labels_kernel.py::test_the_seven_sensitivity_rank_tables_equal_the_kernel_table
M42-vnext_projects tests/unit/test_derived_labels_kernel.py::test_the_seven_sensitivity_rank_tables_equal_the_kernel_table
canonical-blank-identifiers tests/unit/test_derived_labels_record_completeness.py::test_canonical_counts_and_identifiers_do_not_use_the_legacy_duplicate_exception
canonical-missing-counts tests/unit/test_derived_labels_record_completeness.py::test_a_nonempty_canonical_record_requires_well_formed_complete_counts
M19-daily-weekly tests/integration/test_derived_labels_producers_postgres.py::test_a_bound_key_generates_from_admitted_inputs_only[daily]
M20-connections tests/integration/test_derived_labels_producers_postgres.py::test_a_bound_key_generates_from_admitted_inputs_only[connections]
M21-contradictions tests/integration/test_derived_labels_producers_postgres.py::test_a_bound_key_generates_from_admitted_inputs_only[contradictions]
M22-consolidation tests/integration/test_derived_labels_producers_postgres.py::test_a_bound_key_generates_from_admitted_inputs_only[consolidation]
M23-scheduler tests/integration/test_derived_labels_producers_postgres.py::test_a_bound_key_generates_from_admitted_inputs_only[open_loop_review]
M24-project tests/integration/test_derived_labels_producers_postgres.py::test_a_bound_key_generates_from_admitted_inputs_only[project_update]
M28-scope-core tests/unit/test_project_floor_views.py
M28-retrieval-helper tests/unit/test_project_floor_views.py
M28-retrieval-row tests/unit/test_project_floor_views.py
M28-session-brief tests/unit/test_project_floor_views.py
M27-SQL-view tests/unit/test_project_floor_views.py
M52-sqlite-pending tests/unit/test_group_scope_sqlite.py::test_a_second_scoped_rollup_run_over_the_same_group_finds_its_card_and_inserts_nothing
M52-sqlite-accepted tests/unit/test_group_scope_sqlite.py::test_a_second_scoped_rollup_run_over_the_same_group_finds_its_card_and_inserts_nothing
M52-postgres-pending tests/integration/test_derived_labels_group_scope_postgres.py::test_a_second_scoped_rollup_run_over_the_same_group_finds_its_card_and_inserts_nothing
M52-postgres-accepted tests/integration/test_derived_labels_group_scope_postgres.py::test_a_second_scoped_rollup_run_over_the_same_group_finds_its_card_and_inserts_nothing
M53-connections tests/integration/test_derived_labels_producers_postgres.py::test_input_selection_uses_effective_labels_including_the_owner_default_ceiling[connections]
M53-contradictions tests/integration/test_derived_labels_producers_postgres.py::test_input_selection_uses_effective_labels_including_the_owner_default_ceiling[contradictions]
M53-consolidation-memories tests/integration/test_derived_labels_producers_postgres.py::test_consolidation_admits_effective_memory_labels_before_the_embedding_provider
M53-consolidation-artifacts tests/integration/test_derived_labels_producers_postgres.py::test_input_selection_uses_effective_labels_including_the_owner_default_ceiling[consolidation]
M53-rollup-memories tests/integration/test_derived_labels_producers_postgres.py::test_input_selection_uses_effective_labels_including_the_owner_default_ceiling[consolidation]
M53-project tests/integration/test_derived_labels_producers_postgres.py::test_input_selection_uses_effective_labels_including_the_owner_default_ceiling[project_update]
M53-scheduler-loops tests/integration/test_derived_labels_producers_postgres.py::test_input_selection_uses_effective_labels_including_the_owner_default_ceiling[open_loop_review]
M53-scheduler-staleness tests/integration/test_derived_labels_producers_postgres.py::test_input_selection_uses_effective_labels_including_the_owner_default_ceiling[staleness]
M19-weekly tests/integration/test_derived_labels_producers_postgres.py::test_a_bound_key_generates_from_admitted_inputs_only[weekly]
M23-staleness tests/integration/test_derived_labels_producers_postgres.py::test_a_bound_key_generates_from_admitted_inputs_only[staleness]
M25-artifacts tests/integration/test_derived_labels_producers_postgres.py::test_a_bound_key_generates_from_admitted_inputs_only[daily]

M6 aggregate and M48 share one kernel predicate; M26 and M47 share one global-report predicate. Grouped helper mutations and four individual lookup mutations are separate experiments, not extra handoff requirements. The complete exact/list-door mutation universe is separate read-owner evidence.

Final restored producer proof and existing rollup readers

Clean ac38d028fb24600ff01d058990e8a46f4bca1c16 passes 348 complete-owned controls in 10.70 seconds, including reverse-query and existing-rollup admissions. Two additional physical existing-state admission omissions are killed and restored byte for byte. Their experiment production head is ce28f30f412e267252f48c33dfa0c2656fea45c2, with the test changes later committed at ac38d028. Together with the prior 54 experiments, this is 56 cumulative experiments across declared tranches; all 56 were not repeated at the final restored-control head.

Executed physical mutation Named failing test
M38-M53-existing-pending tests/integration/test_derived_labels_group_scope_postgres.py::test_existing_rollup_state_admits_effective_labels_for_pending_and_accepted_cards[False]
M38-M53-existing-accepted tests/integration/test_derived_labels_group_scope_postgres.py::test_existing_rollup_state_admits_effective_labels_for_pending_and_accepted_cards[True]

Frozen combined gate and staged corrective evidence

The complete frozen combined 68946a42e979833a39c300ed80c734d8f7288552 unit shards report 13,788 passed, 20 skipped and 12 failed. The strict full PostgreSQL run reports 544 passed, one skipped and 86 failed; fixture identity/lock compatibility corrections were underway at that historical cutoff. The later final combined gates and current-head CI pass. Default smoke has one pass and one old HTTP operation-count pin failure. These broad runs remain failed receipts, separate from later selected corrective controls. Release-static checks 281 files, Bandit, 216 LongMemEval cases, saved seven-arm evidence and all-backend operations pass at that same frozen head. All-backend operations include real SQLite recovery and PostgreSQL custom dump/destroy/recreate/restore with no declared proof gaps.

The historical local stage observed for this PR was 797c859e: 724 passed/1 obsolete artifact params failure; corrected and whole test_vnext_store92passed0.35s. That interim stage preceded the final ordinary dependency mapping and current published head.

A later workspace tripwire found an actual original-loop backing-reference leak through workspace, dashboard and source trace. Reader correction is committed as dda36a3d39e7e6e8a2819aa9b214b221fdf12f1d, using the shared #568 effective-reference helper and applying it to #569 view responses. The 27-case PostgreSQL run passed with identical patch bytes before commit, with original failures retained. Root additionally passes 165 focused controls at 059fbad3 in 32.95 seconds. Those selected results alone were bounded; the later final combined broad gate and current-head CI are separate passing receipts.

Measured runtime budgets

The official quiet full-commit window at combined 98f2b6f510c48c6004efa0409cc6b3322ca46b63 compares frozen main 48873b038013f4cf548099fcc4610a150972eedd. A 200-fact capture uses one warm run plus five measured commits: candidate median 0.629653875 seconds versus main 0.554330375 seconds, 13.588196% overhead within the 15% budget. On the 50,000-memory/2,000-artifact dataset, 100+100 dependants settle in median 0.354523250 seconds, maximum 0.358560584; 1000+1000 settle in median 1.949962292 seconds, maximum 2.015073416. Each run checks the exact changed rows and 200/2000 label events. Both measured cases meet three seconds; these are the stated dependent cases, not a claim every row changed. Earlier failed capture measurements remain retained. The final combined matrix and source mapping are separate receipts; designated acceptance remains separate.

Native validation snapshots and remaining gates

The earlier validated native draft head was 98949374745b3b808328f2974b4c810603d8351d, after the ordinary #566 forward merge and a two-line group fixture correction. The corresponding two PostgreSQL controls pass at that earlier head, reported by the coordinator. Earlier e466ce7e CLI/project/semantic/store scope has 340 passes in 2.05 seconds; the obsolete artifact-query fixture initially fails one case and the corrected whole store module passes 92. Those earlier runs remain distinct from the final forwarded source.

The complete-owned producer proof passes 348 at ac38d028, and all 56 physical experiments retain their declared production/test tranches. The quiet capture and scale budgets pass at combined 98f2b6f5, with exact samples and changed-label/event checks described above. Neither worker count is presented as a fresh full native-head run.

Later combined head 65044cc37f0c61b7442557b3e5591fde474d939a, tree 22f792816bb48a5fcc03ee576640765b5496d82c, passes all seven CI-role gates: 669 PostgreSQL cases and one intentional legacy-flag skip; release-static, baseline Bandit, 216 LongMemEval, saved seven-arm replay, two flag-off default-smoke cases and actual all-backend upgrade/restore operations with no proof gaps. The strict-owner run has 668 passes, one skip and only the unchanged historical 0067 revision NOT NULL failure. Current 0096 acceptance retains NOSUPERUSER/NOBYPASSRLS owner controls; historical 0067 uses its unchanged CI migrator model.

Final concurrency head 94ff573e656a30761d382c8717b608e14f9e630d has production identical to corrected 6cf579d4 and completes 20 of 20 strict 27-case suites: 540 tests, 3,500 review/relabel races and 20 shared-dependent relabel pairs, with constant tracked hashes and no failures, retries or edits. The intermediate earlier twenty-series remains archived separately. The physical mutation runs retain their earlier heads.

The final complete corrective unit matrix uses 385ccd8a for shards 1 and 2 and the final owning shard 3 at 1319c69f: shard 1 has 4,489 passes and 15 skips, shard 2 has 5,600 passes and five skips, and shard 3 has 3,769 passes. Total: 13,858 passed and 20 skipped. The final root 89e13def51b508ce42155d7dcad9a310e7b95fbb differs from 1319c69f only by the integration report-window fixture; all unit files and production are identical. The older 13,857-case matrix and its archive remain preserved. Combined statement-and-branch coverage passes at 85.6192261959206%, with statement coverage 87.73828853% and branch coverage 78.89058621%. The global 50% requirement and the single 45% aggregate statement floor across 14 API paths passes at 71.538857%. Exact-head GitHub CI now passes as reported above; it is separate from these local combined receipts. The scoped skeptical probes and execution evidence above do not replace designated control-tower premerge approval or human security-team approval before the tag. One actual independent combined review cycle and its closure probes are retained; no second full independent scan is claimed. Earlier failed complete runs remain preserved. Merge, release tagging and advisory publication remain separate gates.

Upgrade Overview

Protected Areas

  • memory schema
  • evidence pipeline
  • trust rules
  • promotion logic
  • continuity APIs

The checked areas cover the complete cumulative diff of this exact published head against the frozen release base.

Compatibility Impact

Derived content may become stricter or disappear from restricted reads when current input labels, project scope or incomplete ancestry require it. Provenance, text and original-row trust meanings are preserved. Owner and unbound admin controls retain their applicable policy contracts. List counts must use the complete admitted population; a limited fetched page cannot substantiate a total.

Migration / Rollout

No migration is added by this PR. Land the kernel before runtime consumers. Ship the seven-PR set together in the dedicated security release.

Operator Action

After a restore at head or older-binary writes, run the store-specific labels check and labels repair commands. Confirm a source-move preview before a move that hides derived rows. Regenerate fresh candidates with POST /v0/vnext/sources/{source_id}/regenerate as the owner or unbound admin, and rerun each report's normal generation route.

Validation

Earlier worker commands retain their actual tested revisions and limits. Final exact-head remote CI and the source-equivalent combined acceptance are separately established in the current summary; they do not backdate the historical local receipts. Designated control-tower merge approval and owner/security-team release approval remain external gates. Historical process and evidence limits remain disclosed.

Rollback

Revert consumers before the kernel. Raised labels and scrubbed content persist; reverting code or migration 0096 does not lower labels or restore removed text. Keep a compatible backup and rerun restricted-read verification after recovery.

Process variance

The existing review branch name is preserved. It differs from the handoff naming convention. Earlier updates to #565 through #569 used identity-only force-pushes and violated the mandatory no-force-push rule; preserving source trees did not make them compliant. This historical violation cannot be erased by later tests. Further updates use ordinary commits and plain merges. The handoff contains a later rebase sentence that contradicts its mandatory plain-merge rule; the mandatory rule governs.

Domain, sensitivity, and project requirement are computed in one place. No product path calls it yet, so reads and writes stay as they are in v0.20.0.
A memory copied from another row is stored at least as strict as that row. A metadata write keeps the marker and the stored project scope and floor.
Main gained the consolidation report label count by record type. The write path keeps its own commits.
A stricter source or memory raises the rows derived from it. Artifact and open-loop inserts take the same floor. A source move previews how many derived rows a project key would lose, and a relabel that cannot finish answers 409 or 503.
A key bound to a project builds a brief, connection report, contradiction report, or project update only from rows whose scope and floor are both inside its binding.
Consolidation and roll-ups overlap scope united with floor, and a locked run applies the exact project test after that overlap check. Roll-up lookups and the operator artifact list match the floor. Each producer writes derived_from for the rows it used.
A view that asks for global rows keeps a row with no Alice project id only when every Alice project id in its floor is in the view. The four Python checks and the SQLite view SQL now pass that floor.
@samrusani
samrusani merged commit 21bbea9 into main Oct 8, 2026
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant