Skip to content

Drop producer inputs above the request label - #569

Draft
samrusani wants to merge 183 commits into
mainfrom
cursor/derived-labels-list-doors-a34e
Draft

samrusani wants to merge 183 commits into
mainfrom
cursor/derived-labels-list-doors-a34e

Conversation

@samrusani

@samrusani samrusani commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Stacked on #568.

Summary

Published draft head 44694b55a06bbc2f41d46c3e43032e2a2a0c417b has 22 successful GitHub checks in the exact-head snapshot observed at 2026-10-06T00:48:16.326311+00:00. All nine final draft heads are green in that same snapshot.

Final combined root 89e13def51b508ce42155d7dcad9a310e7b95fbb has 13,858 passing unit cases and 20 skips through the recorded complete corrective shards. Global statement-plus-branch coverage is 85.619226%; one aggregate statement gate across 14 API paths reaches 71.538857% (4170/5829), above its 45% floor. The source-equivalent CI migration model passes 669 PostgreSQL cases with one intentional skip; static, Bandit, LongMemEval, actual upgrade/restore and all 20 strict concurrency suites pass within their recorded heads. Capture and relabel budgets pass at their measured head with verified unchanged final source paths. These combined receipts are distinct from each historical local worker selection below.

The only restricted-owner full PostgreSQL failure is unchanged historical migration 0067; current 0096 retains restricted owner controls and the actual CI migration model passes. Designated control-tower merge approval and owner/security-team approval before the tag are external gates. Earlier force-push variance and the missing original standalone kernel-main proof remain disclosed; no release, deployment or second full independent scan is claimed.

The current published ordinary draft head is 44694b55a06bbc2f41d46c3e43032e2a2a0c417b. The final ordinary forward merge carries the #568 saved-quote correction and the actual UTC-midnight integration-fixture correction. Earlier head 77564062 CI reports 624 passes, one skip and two report-window failures. The native test was using a real October 6 creation default inside a fixed October 5 report window. Fixture commit 4416acfe gives the seeded loop an explicit October 5 opened_at value, without runtime changes. It passes all 18 owning-module cases in 8.20 seconds on October 6, including two UTC boundary controls; stale memory and loop guard omissions each fail and restore byte for byte. The coordinator confirms the full 18-case module at root 89e13def in 8.38 seconds. These corrections do not retroactively turn the older CI receipt green. All later dependency updates use ordinary merges and normal pushes. Current-head GitHub CI now has 22 successful checks at the final snapshot. Designated outside premerge approval remains separate.

Counts now enumerate the complete matching population through effective admission before pagination, and workspace ancillary responses exclude IDs and counts of withheld targets.

Loaded inputs to producers and list readers now use effective labels. Locked producers apply the same all-of project rule as exact reads, including beliefs, prior consolidation artifacts and existing rollup cards. Recall, context packs, resume, review queues, workspace and operator screens filter rows using their applicable sensitivity and project restrictions. Includes the concurrent list/screen update and retains its behavior while fixing row typing and locked-reader compatibility.

These changes are proposed and unmerged; they are not part of the released v0.20.0.

Historical validation

Original review reproductions, locked producers, exact/list doors, concurrent reader tests and MCP authorization controls passed. The combined stack passed 512 PostgreSQL integration tests (1 skipped), 216 LongMemEval tests, 244 frontend tests, both frontend coverage gates, type checking, lint, production build, bundle budgets and 24 browser tests. Stable benchmark provenance tests passed (68). Ruff, Bandit and release-static typing passed.

Historical combined-stack unit matrix: 13,401 passed, 20 skipped and 11 initial failures. All 11 failures passed the corrective rerun; the affected owning modules also passed 275 tests. Combined coverage is 85.64% (required 50%); API carrier coverage is 70.56% (required 45%). This was a complete matrix followed by focused corrective reruns, not one clean full invocation. Those historical local results did not establish current-head CI. The final exact-head remote checks are reported above; outside merge approval remains separate.

Reproduction and executed mutations

Historical builder evidence recovered from the original description at f074449ef4efbb839db7d55545eb81907dabd72d:

tests/unit/test_list_door_readers.py (4), tests/unit/test_label_door_registry.py (2), tests/unit/test_list_door_inputs.py (1), and tests/unit/test_label_guard_exact_doors.py (8): 15 passed.

A later run of retrieval, the open-loop reference fence, group scope, the session brief, workspaces, the context tree, contradictions, the list-door input test, the door registry, and the new reader tests: 333 passed.

Route, project, and resume tests: test_vnext_source_trace_caps_every_collection_and_reports_truncation, test_vnext_contradiction_and_belief_endpoints, test_vnext_project_and_open_loop_endpoints, test_dogfooding_dashboard_and_insight_feedback_api, tests/unit/test_vnext_projects.py, and the resume files: 170 passed, with one failure that this commit does not introduce (test_vnext_source_review_trace_and_doctor_endpoints raises AttributeError: FakeVNextStore has no attribute lock_graph_mutation on the assign-project path that already takes the label lock).

test_fts_stage_drops_a_public_copy_of_a_confidential_source fails if _memory_fts_rows returns the FTS rows without admit_loaded. That was shown by replacing the admit with list(rows): the sentinel id and title came back. The admit call was restored.

Not verified in that historical local receipt: the full tests/unit run, Bandit, mypy, and Postgres.

The recovered description does not retain a complete main-failure command and output. That evidence remains a review obligation; a missing-module collection failure alone is weaker than an exercised behavior regression. The list above records reported executed mutations. It does not turn other mutations proposed in test docstrings into executed proof.

Remediation evidence at packet cutoff

These are synthetic local checks of the named worker checkout. They do not establish the final combined candidate, live CI, merge approval or release approval. The command spelling below uses python; private receipts retain the interpreter and environment.

Read head 8c1b5d5babcb528e027b228e6fa9c4e20ba698db counts the complete matching population through effective admission in narrow keyset batches before display pagination. The native PostgreSQL population test seeds 205 public sources plus one confidential source, enumerates all 206 in batches of 100, 100 and 6, and reports 205 readable sources. It returns 35 readable memories and excludes 40 stale confidential copies. Hidden artifact and project totals are zero. The filtered workspace skips content diagnostics; the full doctor retains its derived-label and flagged-source report. Trace truncation and event totals use admitted targets. All five operator screens are tested with real keys and owner/admin controls. At 1165b330, the trusted HTTP workspace is unchanged when hidden rows are added: omitted content diagnostics report skipped/info with scope=filtered_workspace and evaluated=false, without hidden IDs, per-row counts or aggregate status changes. The full SQLite doctor count control uses a synthetic provider/connector protocol adapter; it is not a literal CLI subprocess proof.

Three complete-count assertions fail when the three affected production modules are replaced with their 8a851c52 pre-fix versions. They exercise SQL-prefiltered rows, rows after the display page and rows after the dogfood limit; no missing API or collection failure is involved.

python -m pytest tests/unit/test_complete_readable_counts.py::test_workspace_counts_sql_hidden_and_beyond_display_page tests/unit/test_complete_readable_counts.py::test_all_sql_prefiltered_rows_leave_zero_totals tests/unit/test_complete_readable_counts.py::test_dogfooding_counts_hidden_rows_beyond_500 -q
3 failed

At 8c1b5d5b, the 36-unit and 11-PostgreSQL proof selections passed; after mutations, the restored controls passed 17 unit and 11 PostgreSQL tests. A workspace follow-up at a6d14ab0 filters agent events, recent commits, confirmations and nested dashboard output; its restored controls passed 14 PostgreSQL and 7 SQLite cases.

Executed mutation Named failing test
count-population-killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_workspace_counts_full_population_with_sql_hidden_and_stale_rows
count-admission-killed tests/unit/test_complete_readable_counts.py
event-count-admission-killed tests/unit/test_complete_readable_counts.py::test_workspace_counts_sql_hidden_and_beyond_display_page
trace-completeness-killed tests/unit/test_complete_readable_counts.py::test_trace_completeness_does_not_reveal_hidden_501st_row, tests/unit/test_complete_readable_counts.py::test_trace_event_completeness_uses_admitted_targets
operator-artifacts-killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_all_five_operator_screens_with_real_keys[trusted]
operator-source-trace-killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_all_five_operator_screens_with_real_keys[trusted]
operator-project-list-killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_all_five_operator_screens_with_real_keys[trusted]
operator-project-dashboard-killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_all_five_operator_screens_with_real_keys[trusted]
operator-belief-state-killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_all_five_operator_screens_with_real_keys[trusted]
registry-discovery-killed tests/unit/test_label_door_registry.py::test_every_scanned_reader_is_classified

The workspace ledger records four additional independent ancillary guard kills with byte restoration.

Executed workspace mutation Named failing test
workspace-agent-events-killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_workspace_activity_uses_actual_key_and_current_targets[trusted]
workspace-recent-commits-killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_workspace_activity_uses_actual_key_and_current_targets[trusted]
workspace-confirmations-killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_workspace_activity_uses_actual_key_and_current_targets[trusted]
workspace-nested-dashboard-killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_workspace_activity_uses_actual_key_and_current_targets[trusted]

The first two campaigns have 17 selected reader mutation kills. Later campaigns add 15 and seven actual kills, with overlap at shared guards and three historical survivors preserved. At that earlier cutoff, complete exact/list/input mapping still required reconciliation; the final classified matrix below records later completion within its stated scope. These totals count experiments, not distinct handoff requirements.

Further executed reader controls

The later physical-site ledger records 15 behavioral kills and three surviving experiments. Those experiments and their 55-unit/18-PostgreSQL baseline and restored controls belong to clean 1165b3302a17c01429d39e13a6f4fd557b11d93e, before the later test follow-ups. The supplemental seven experiments were executed at clean 9d73f0e66e458d6eaac2fff864fdfd77b510e849, with original/restored source hashes and 58 unit plus 24 real PostgreSQL restored controls. The following rows record executed failures rather than source-string suggestions.

Executed physical mutation Named failing test
M50-backing-belief-label-killed tests/unit/test_list_door_readers.py::test_operator_screens_hide_a_confidential_row_from_a_trusted_key
M41-resume-target-killed tests/unit/test_complete_readable_counts.py::test_resume_and_session_events_use_current_target_labels
M41-session-target-killed tests/unit/test_complete_readable_counts.py::test_resume_and_session_events_use_current_target_labels
M41-context-target-killed tests/unit/test_complete_readable_counts.py::test_context_events_use_current_effective_target_of_every_kind, tests/unit/test_complete_readable_counts.py::test_context_event_missing_and_unknown_label_targets_fail_closed
filtered-doctor-skip-killed tests/unit/test_derived_labels_real_keys.py::test_full_owner_doctor_keeps_true_counts_and_filtered_view_skips_content
telemetry-event-admission-killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_telemetry_and_quality_ratings_use_current_target_labels[trusted]
telemetry-artifact-admission-killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_telemetry_and_quality_ratings_use_current_target_labels[trusted]
telemetry-memory-admission-killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_telemetry_and_quality_ratings_use_current_target_labels[trusted]
rating-current-target-killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_telemetry_and_quality_ratings_use_current_target_labels[trusted]
M38-fts-or_fallback-killed tests/unit/test_list_door_readers.py::test_fts_stage_drops_a_public_copy_of_a_confidential_source[or_fallback]
M38-fts-strict-killed tests/unit/test_list_door_readers.py::test_fts_stage_drops_a_public_copy_of_a_confidential_source[strict]
M38-fts-legacy-killed tests/unit/test_list_door_readers.py::test_fts_stage_drops_a_public_copy_of_a_confidential_source[legacy]
M50-real-key-backing-belief-killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_all_five_operator_screens_with_real_keys[trusted]
ordinary-loop-uuid-cast-killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_direct_column_loop_references_reach_real_read_guard[confidential-trusted]
count-loop-uuid-cast-killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_direct_column_loop_references_reach_real_read_guard[confidential-trusted]

The earlier FTS fixture survived, then each strict, OR-fallback and legacy branch failed under the stronger branch-specific fixture. The outer open-loop helper removal still survives because the inner policy decision independently settles effective labels. The earlier memory-review fixture also survived; the supplemental inner-policy floor bypass fails with the new bound-admin control. These earlier results alone do not establish an individual behavioral guard-removal kill for every registered door. The final classified matrix below adds cache-isolated semantic receipts and explicit compound/redundant-control interpretation; registry discovery remains a separate structural check.

Frozen combined gate and staged corrective evidence

The complete frozen combined 68946a42e979833a39c300ed80c734d8f7288552 unit shards report 13,788 passed, 20 skipped and 12 failed. The strict full PostgreSQL run reports 544 passed, one skipped and 86 failed; fixture identity/lock compatibility corrections were underway at that historical cutoff. The later final combined gates and current-head CI pass. Default smoke has one pass and one old HTTP operation-count pin failure. These broad runs remain failed receipts, separate from later selected corrective controls. Release-static checks 281 files, Bandit, 216 LongMemEval cases, saved seven-arm evidence and all-backend operations pass at that same frozen head. All-backend operations include real SQLite recovery and PostgreSQL custom dump/destroy/recreate/restore with no declared proof gaps.

The historical local stage observed for this PR was 2c37dfcb: fourteen module scope 994 passed/1real reference tripwire failure; reader follow-up was pending at that historical cutoff. That interim stage preceded the final ordinary dependency mapping and current published head.

A later workspace tripwire found an actual original-loop backing-reference leak through workspace, dashboard and source trace. Reader correction is committed as dda36a3d39e7e6e8a2819aa9b214b221fdf12f1d, using the shared #568 effective-reference helper and applying it to #569 view responses. The 27-case PostgreSQL run passed with identical patch bytes before commit, with original failures retained. Root additionally passes 165 focused controls at 059fbad3 in 32.95 seconds. Those selected results alone were bounded; the later final combined broad gate and current-head CI are separate passing receipts.

Final classified reader receipts

These later worker proofs preserve their actual heads and do not imply a full rerun on the native PR head below. The completed classified reader matrix covers 61 guarded functions and 54 explicit exceptions with no unmapped guarded row. Across six accepted tranches there are 108 physical experiments: 95 kills and 13 recorded survivals. The two fresh cache-isolated tranches have 66 experiments, 56 kills and 10 redundant survivals. The initial non-isolated pass is excluded because timestamp bytecode could be reused. Every accepted source mutation has byte restoration and SHA-256 checks.

The 62 fresh experiments belong to 32d01f7ecde4d3f61effb7321e840989ff23b080; the four additional experiments belong to 4f53e4d69e6c7b37edb5f37e0ee203f347fb5c1c. Latest restored controls at the latter head pass 126 unit cases and 57 actual PostgreSQL cases. This matrix classifies the registered readers and chosen guard sites; it does not claim every syntactic mutant or every alias/profile combination. Producer reader receipts retain their own heads.

The following 40 fresh experiments concern this PR's cumulative scope: 39 killed and 1 survived. Each killed row lists the actual failing test. Surviving rows list the exercised control and remain recorded as survivors.

Physical mutation Result Named test
M41-label-event-payload-content Killed tests/unit/test_derived_labels_kernel.py::test_labels_raised_events_carry_no_text_or_ids
M38-_memories_by_ids Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[by_ids], tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[by_ids_fallback]
M38-_memory_vector_rows Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[vector]
M38-_memory_temporal_rows Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[temporal]
M38-expand_provenance_once Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[provenance]
M38-memory_visibility Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[visibility]
M38-_recent_changes Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[recent_changes], tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[scoped_recent_changes]
M38-compile_context_pack Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[pack_open_loops]
M38-graph-outer-redundancy Survived tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[graph]
M38-graph-and-byids-shared-admission Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[graph]
M38-contradicting-beliefs Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[contradictions], tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[scoped_contradictions]
M38-session-open_loop Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[session]
M38-session-memory Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[session]
M38-context-tree-project Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[context_projects]
M38-context-tree-memory Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[context_memories]
M38-context-tree-source Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[context_sources]
M38-context-tree-open_loop Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[context_open_loops]
M38-context-tree-artifact Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[context_artifacts]
M38-project-resolution Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[project_resolution]
M38-project-dashboard-memory Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[dashboard_lists]
M38-project-dashboard-open_loop Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[dashboard_lists]
M38-project-dashboard-artifact Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[dashboard_lists]
M38-workspace-project Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[workspace_projects]
M38-workspace-memory Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[workspace_memories]
M38-workspace-open_loop Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[workspace_open_loops]
M38-workspace-artifact Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[workspace_artifacts]
M38-workspace-beliefs Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[workspace_beliefs]
M38-dogfooding-source Killed tests/unit/test_label_reader_stage_matrix.py::test_each_dogfooding_sample_counts_only_currently_readable_rows[sources]
M38-dogfooding-memory Killed tests/unit/test_label_reader_stage_matrix.py::test_each_dogfooding_sample_counts_only_currently_readable_rows[memories]
M38-dogfooding-open_loop Killed tests/unit/test_label_reader_stage_matrix.py::test_each_dogfooding_sample_counts_only_currently_readable_rows[open_loops]
M38-dogfooding-artifact Killed tests/unit/test_label_reader_stage_matrix.py::test_each_dogfooding_sample_counts_only_currently_readable_rows[artifacts]
M41-dogfooding-event-target Killed tests/unit/test_label_reader_stage_matrix.py::test_each_dogfooding_sample_counts_only_currently_readable_rows[events]
M38-mcp-_vnext_recent_decisions-memory Killed tests/unit/test_derived_labels_real_keys.py::test_sqlite_real_key_core_doors[trusted]
M38-mcp-_vnext_resume-memory Killed tests/unit/test_derived_labels_real_keys.py::test_sqlite_real_key_core_doors[trusted]
M38-mcp-_vnext_resume-open_loop Killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_direct_column_loop_references_reach_real_read_guard[confidential-trusted]
M38-mcp-open-loops Killed tests/integration/test_derived_labels_read_acceptance_postgres.py::test_direct_column_loop_references_reach_real_read_guard[confidential-trusted]
M38-mcp-review-queue-list Killed tests/integration/test_derived_labels_exact_entrypoints_postgres.py::test_review_queue_list_uses_current_parent_scope[bound_admin]
M50-backing-memory-effective-label-all-belief-readers Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[workspace_beliefs], tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[contradictions], tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[scoped_contradictions], tests/integration/test_derived_labels_read_acceptance_postgres.py::test_all_five_operator_screens_with_real_keys[trusted]
M41-dormant-workspace-event-helper Killed tests/unit/test_label_reader_stage_matrix.py::test_each_stage_uses_current_parent_label[workspace_event_helper]
M38-dogfooding-rating-target Killed tests/unit/test_label_reader_stage_matrix.py::test_dogfooding_rating_count_uses_the_current_artifact_label

Individual memory review/correction guards can survive the other exact guard. Outer redaction and loop guards can survive the inner commit policy. Graph outer admission can survive the guarded ID loader. The campaign executes compound removals that reach a semantic failure, and separate inner-policy controls substantiate the remaining defense. A surviving outer omission is never relabeled as a kill. The earlier three surviving probes remain in their original historical tranche.

Native held stage 5d7e5dd31586b3e18ab546c87a3d95428b237bea passes all 62 selected PostgreSQL cases in 16.08 seconds without skips, including actual locks and stored permitted/denied state. Its final matrix plus deferred-review controls passes 40 cases in 1.08 seconds. Later forward staging requires its own head attribution.

Native validation snapshots and remaining gates

The earlier validated native draft head was 775640621979844b1b0fc4bcd542ed708f107c5c, after a plain forward merge of final #568 b26e8ebb. At that earlier head, native controls pass all 65 PostgreSQL cases in 16.74 seconds without skips, including the earlier nine-failure gate, actual held locks and persisted admitted/denied state, and three original-project identity/canonical-scope controls. That earlier head's CLI/project/matrix/deferred-review unit selection passes 275 cases in 2.38 seconds. Ruff and diff checks pass.

Portable executed selections, with exact private interpreter and disposable PostgreSQL configuration retained in the receipt:

python -m pytest -q tests/integration/test_derived_labels_group_scope_postgres.py tests/integration/test_derived_labels_exact_entrypoints_postgres.py tests/integration/test_derived_labels_read_acceptance_postgres.py tests/integration/test_label_guard_project_identity_postgres.py --require-executed-tests --tb=short
python -m pytest -q tests/unit/test_cli.py tests/unit/test_vnext_projects.py tests/unit/test_label_reader_stage_matrix.py tests/unit/test_main.py::test_vnext_memory_review_defers_embedding_until_primary_transaction_closes tests/unit/test_main.py::test_vnext_consolidation_defers_embedding_until_primary_transaction_closes tests/unit/test_main.py::test_vnext_project_review_defers_embedding_and_preserves_human_attribution --tb=short

The source lock corrections belong to earliest #566; their dependent exact-entrypoint integration tests belong here. Actual core reader/write/guard source paths byte-match combined 385ccd8a. Later #570/#571 repair/migration paths and independent #572/#573 contributions remain separate. This is a source-equivalence statement for the named core paths, not a claim the whole native tree equals the all-nine tree. Earlier 5d7e5dd3 selected passes and the failed nine/53 gate retain their own heads. The saved original snapshot and earlier broad matrix remain historical evidence.

Later combined head 65044cc37f0c61b7442557b3e5591fde474d939a, tree 22f792816bb48a5fcc03ee576640765b5496d82c, passes all seven CI-role gates: 669 PostgreSQL cases and one intentional legacy-flag skip; release-static, baseline Bandit, 216 LongMemEval, saved seven-arm replay, two flag-off default-smoke cases and actual all-backend upgrade/restore operations with no proof gaps. The strict-owner run has 668 passes, one skip and only the unchanged historical 0067 revision NOT NULL failure. Current 0096 acceptance retains NOSUPERUSER/NOBYPASSRLS owner controls; historical 0067 uses its unchanged CI migrator model.

Final concurrency head 94ff573e656a30761d382c8717b608e14f9e630d has production identical to corrected 6cf579d4 and completes 20 of 20 strict 27-case suites: 540 tests, 3,500 review/relabel races and 20 shared-dependent relabel pairs, with constant tracked hashes and no failures, retries or edits. The intermediate earlier twenty-series remains archived separately. The physical mutation runs retain their earlier heads.

The final complete corrective unit matrix uses 385ccd8a for shards 1 and 2 and the final owning shard 3 at 1319c69f: shard 1 has 4,489 passes and 15 skips, shard 2 has 5,600 passes and five skips, and shard 3 has 3,769 passes. Total: 13,858 passed and 20 skipped. The final root 89e13def51b508ce42155d7dcad9a310e7b95fbb differs from 1319c69f only by the integration report-window fixture; all unit files and production are identical. The older 13,857-case matrix and its archive remain preserved. Combined statement-and-branch coverage passes at 85.6192261959206%, with statement coverage 87.73828853% and branch coverage 78.89058621%. The global 50% requirement and the single 45% aggregate statement floor across 14 API paths passes at 71.538857%. Exact-head GitHub CI now passes as reported above; it is separate from these local combined receipts. The scoped skeptical probes and execution evidence above do not replace designated control-tower premerge approval or human security-team approval before the tag. One actual independent combined review cycle and its closure probes are retained; no second full independent scan is claimed. Earlier failed complete runs remain preserved. Merge, release tagging and advisory publication remain separate gates.

Upgrade Overview

Protected Areas

  • memory schema
  • evidence pipeline
  • trust rules
  • promotion logic
  • continuity APIs

The checked areas cover the complete cumulative diff of this exact published head against the frozen release base.

Compatibility Impact

Derived content may become stricter or disappear from restricted reads when current input labels, project scope or incomplete ancestry require it. Provenance, text and original-row trust meanings are preserved. Owner and unbound admin controls retain their applicable policy contracts. List counts must use the complete admitted population; a limited fetched page cannot substantiate a total.

Migration / Rollout

No migration is added by this PR. Land the kernel before runtime consumers. Ship the seven-PR set together in the dedicated security release.

Operator Action

After a restore at head or older-binary writes, run the store-specific labels check and labels repair commands. Confirm a source-move preview before a move that hides derived rows. Regenerate fresh candidates with POST /v0/vnext/sources/{source_id}/regenerate as the owner or unbound admin, and rerun each report's normal generation route.

Validation

Earlier worker commands retain their actual tested revisions and limits. Final exact-head remote CI and the source-equivalent combined acceptance are separately established in the current summary; they do not backdate the historical local receipts. Designated control-tower merge approval and owner/security-team release approval remain external gates. Historical process and evidence limits remain disclosed.

Rollback

Revert consumers before the kernel. Raised labels and scrubbed content persist; reverting code or migration 0096 does not lower labels or restore removed text. Keep a compatible backup and rerun restricted-read verification after recovery.

Process variance

The existing review branch name is preserved. It differs from the handoff naming convention. Earlier updates to #565 through #569 used identity-only force-pushes and violated the mandatory no-force-push rule; preserving source trees did not make them compliant. This historical violation cannot be erased by later tests. Further updates use ordinary commits and plain merges. The handoff contains a later rebase sentence that contradicts its mandatory plain-merge rule; the mandatory rule governs.

Domain, sensitivity, and project requirement are computed in one place. No product path calls it yet, so reads and writes stay as they are in v0.20.0.
A memory copied from another row is stored at least as strict as that row. A metadata write keeps the marker and the stored project scope and floor.
Main gained the consolidation report label count by record type. The write path keeps its own commits.
A stricter source or memory raises the rows derived from it. Artifact and open-loop inserts take the same floor. A source move previews how many derived rows a project key would lose, and a relabel that cannot finish answers 409 or 503.
A key bound to a project builds a brief, connection report, contradiction report, or project update only from rows whose scope and floor are both inside its binding.
Consolidation and roll-ups overlap scope united with floor, and a locked run applies the exact project test after that overlap check. Roll-up lookups and the operator artifact list match the floor. Each producer writes derived_from for the rows it used.
The artifact authorization door and a write that cites a memory settle a derived row before the policy check. A locked key is refused when that row cannot be checked. The owner and an unbound admin still read the stored row.
A view that asks for global rows keeps a row with no Alice project id only when every Alice project id in its floor is in the view. The four Python checks and the SQLite view SQL now pass that floor.
Explain, memory review, redaction, open-loop update, and the legacy artifact authorizer use the input labels. A registry names each exact door and the readers that are not doors yet.
Daily briefs, connection and contradiction reports, consolidation, roll-ups, project updates, staleness sweeps, and open-loop reviews now discard a loaded row when its inputs make the label stricter than the request allows.
Recall, context packs, resume, recent decisions, the session brief, the review queue, and the operator lists now admit rows by the effective label. The five operator screens apply the caller's sensitivity ceiling, and event readers hide a change whose target the caller cannot read.
# Conflicts:
#	tests/integration/conftest.py
#	tests/integration/test_derived_labels_group_scope_postgres.py

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant