Skip to content

Blank an open loop for every spelling the saved-quote reader names - #573

Draft
samrusani wants to merge 4 commits into
mainfrom
cursor/open-loop-scrub-spellings-a34e
Draft

samrusani wants to merge 4 commits into
mainfrom
cursor/open-loop-scrub-spellings-a34e

Conversation

@samrusani

@samrusani samrusani commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Summary

Published draft head 3f69f1a73518d3906e9480c358bc3058fa17d0a9 has 22 successful GitHub checks in the exact-head snapshot observed at 2026-10-06T00:48:16.326311+00:00. All nine final draft heads are green in that same snapshot.

Final combined root 89e13def51b508ce42155d7dcad9a310e7b95fbb has 13,858 passing unit cases and 20 skips through the recorded complete corrective shards. Global statement-plus-branch coverage is 85.619226%; one aggregate statement gate across 14 API paths reaches 71.538857% (4170/5829), above its 45% floor. The source-equivalent CI migration model passes 669 PostgreSQL cases with one intentional skip; static, Bandit, LongMemEval, actual upgrade/restore and all 20 strict concurrency suites pass within their recorded heads. Capture and relabel budgets pass at their measured head with verified unchanged final source paths. These combined receipts are distinct from each historical local worker selection below.

The only restricted-owner full PostgreSQL failure is unchanged historical migration 0067; current 0096 retains restricted owner controls and the actual CI migration model passes. Designated control-tower merge approval and owner/security-team approval before the tag are external gates. Earlier force-push variance and the missing original standalone kernel-main proof remain disclosed; no release, deployment or second full independent scan is claimed.

Decoded JSON scrubbing also covers fully escaped IDs and repeated keys while preserving admitted live values and owner controls.

On SQLite, sources delete, sources prune, and import-markdown --supersede blanked an open loop only when its source_id column or its metadata held the id as stored or source:<id>. A loop that named the source in another spelling kept its text. The lookup, the delete preview, the scrub, and the reader that withholds ids now use every spelling cited_source_ids names (capitals, no hyphens, braces, urn:uuid:, a list, JSON text). One pass over the user's loops answers for every source of the command.

On main, test_each_spelling_is_blanked_on_delete_and_on_replace fails because the reader lists none of those loops (assert set() == {the planted ids}).

Historical validation

tests/unit/test_source_scrub_loop_references.py, tests/unit/test_known_limitations_page_shape.py, tests/unit/test_store_graph_open_loops_split.py, and test_the_reference_keys_include_every_key_the_reverse_lookup_of_a_source_reads: 49 passed.

tests/unit/test_open_loop_references_read_fence.py and tests/unit/test_open_loop_ids_every_spelling_and_after_delete.py: 699 passed.

Killing mutation, reverted before this commit: named_source_ids returned an empty set. test_each_spelling_is_blanked_on_delete_and_on_replace failed because the reader listed no loop. The file was restored byte for byte, and that test then passed (1 passed).

Not run: the full tests/unit suite, Bandit, and mypy. This change is SQLite only.

Reproduction and executed mutations

The original reproduction and named mutation results are retained in the validation section above. Later remediation evidence must identify its exact tested head and distinguish actual executions from suggested mutations.

Current validation and executed mutations

These are synthetic local checks of the named worker checkout. They do not establish the final combined candidate, live CI, merge approval or release approval. The command spelling below uses python; private receipts retain the interpreter and environment.

Corrective head is 6a95c209d3fe971a544f9e4700b3734723d56621. Fully escaped JSON source IDs were already canonically recognized but could survive raw-text scrub. The reader now scrubs decoded JSON, including repeated keys and depth bounds, and gathers canonical aliases. Admitted live source values and owner controls remain visible.

Frozen main 48873b038013f4cf548099fcc4610a150972eedd executes 21 deletion, replacement and pruning cases that retain loop text, plus six encoded-JSON real-key reads; all 27 assertions fail. The standalone synthetic behavior probe and encoded-read tests are copied into the isolated frozen-main checkout before executing:

PYTHONPATH=apps/api/src python -m pytest tests/unit/test_side_open_loop_repro.py tests/unit/test_open_loop_references_read_fence.py -q -k 'main_executes_scrub or encoded_json'
27 failed, 121 deselected in 160.20s

The probe source is retained in the review packet as test_side_open_loop_repro.py. The original side head also reproduced the fully escaped JSON reader failure. The fixed narrow encoded selection passed seven cases, and 31 source-scrub tests passed.

Executed side mutations, each killed and byte-restored:

Executed mutation Named failing test
retire_column_only tests/unit/test_source_scrub_loop_references.py::test_delete_blanks_every_loop_the_reader_names, tests/unit/test_source_scrub_loop_references.py::test_replacement_blanks_every_loop_the_reader_names (additional parameter failures retained)
preview_column_only tests/unit/test_source_scrub_loop_references.py::test_delete_blanks_every_loop_the_reader_names
blank_without_user_filter tests/unit/test_source_scrub_loop_references.py::test_cached_loop_ids_cannot_blank_another_users_loop
retain_description tests/unit/test_source_scrub_loop_references.py::test_delete_blanks_every_loop_the_reader_names, tests/unit/test_source_scrub_loop_references.py::test_replacement_blanks_every_loop_the_reader_names
retain_resolution_note tests/unit/test_source_scrub_loop_references.py::test_delete_blanks_every_loop_the_reader_names, tests/unit/test_source_scrub_loop_references.py::test_replacement_blanks_every_loop_the_reader_names
retain_metadata tests/unit/test_source_scrub_loop_references.py::test_delete_blanks_every_loop_the_reader_names, tests/unit/test_source_scrub_loop_references.py::test_replacement_blanks_every_loop_the_reader_names
canonical_parser_replaced_with_stored_spellings tests/unit/test_source_scrub_loop_references.py::test_each_spelling_is_blanked_on_delete_and_on_replace, tests/unit/test_source_scrub_loop_references.py::test_the_shared_rule_reads_exactly_the_reference_keys
reader_copy_drops_selected_source_ids tests/unit/test_source_scrub_loop_references.py::test_the_scrub_matches_exactly_what_the_reader_lists
preview_without_user_filter tests/unit/test_source_scrub_loop_references.py::test_another_users_loop_that_names_the_source_is_left_alone
blank_open_status_only tests/unit/test_source_scrub_loop_references.py::test_delete_blanks_every_loop_the_reader_names, tests/unit/test_source_scrub_loop_references.py::test_replacement_blanks_every_loop_the_reader_names (additional parameter failures retained)
count_open_status_only tests/unit/test_source_scrub_loop_references.py::test_a_resolved_and_a_dismissed_loop_named_only_in_metadata_are_counted_and_blanked[delete], tests/unit/test_source_scrub_loop_references.py::test_a_resolved_and_a_dismissed_loop_named_only_in_metadata_are_counted_and_blanked[replace]
retain_closed_at tests/unit/test_source_scrub_loop_references.py::test_delete_blanks_every_loop_the_reader_names, tests/unit/test_source_scrub_loop_references.py::test_replacement_blanks_every_loop_the_reader_names
retain_resolved_at tests/unit/test_source_scrub_loop_references.py::test_delete_blanks_every_loop_the_reader_names, tests/unit/test_source_scrub_loop_references.py::test_replacement_blanks_every_loop_the_reader_names
retain_updated_at tests/unit/test_source_scrub_loop_references.py::test_delete_blanks_every_loop_the_reader_names, tests/unit/test_source_scrub_loop_references.py::test_replacement_blanks_every_loop_the_reader_names
preview_pass_per_source tests/unit/test_source_scrub_loop_references.py::test_a_prune_reads_the_loops_once_for_the_preview_and_once_for_the_receipt
receipt_pass_per_source tests/unit/test_source_scrub_loop_references.py::test_a_prune_reads_the_loops_once_for_the_preview_and_once_for_the_receipt
replacement_discards_cached_ids tests/unit/test_source_scrub_loop_references.py::test_replacement_reads_all_source_loops_once
key_contract_drops_reference_key tests/unit/test_source_scrub_loop_references.py::test_the_shared_rule_reads_exactly_the_reference_keys
key_contract_adds_reference_key tests/unit/test_source_scrub_loop_references.py::test_the_shared_rule_reads_exactly_the_reference_keys
encoded_json_skips_decode tests/unit/test_open_loop_references_read_fence.py::test_encoded_json_references_are_withheld_on_the_real_key_list[object-source_refs], tests/unit/test_open_loop_references_read_fence.py::test_encoded_json_references_are_withheld_on_the_real_key_list[object-sources] (additional parameter failures retained)
encoded_json_skips_canonical_metadata_names tests/unit/test_open_loop_references_read_fence.py::test_encoded_json_references_are_withheld_on_the_real_key_list[object-sources], tests/unit/test_open_loop_references_read_fence.py::test_encoded_json_references_are_withheld_on_the_real_key_list[duplicate_key-sources] (additional parameter failures retained)
encoded_json_serializes_depth_sentinel tests/unit/test_open_loop_references_read_fence.py::test_json_text_at_the_metadata_depth_limit_is_dropped_without_raising

At the earlier 6a95c209 corrective head, 281 docs tests, nine real PostgreSQL cases, release controls, Ruff, mypy on 273 files and Bandit passed. The initial LongMemEval permission failures were resolved by the full rerun described below. These earlier side-head results are preserved separately from final-head proof and the combined candidate.

Ordinary corrective follow-ups culminate at 3f69f1a73518d3906e9480c358bc3058fa17d0a9. Canonical JSON collection follows decoded removal recursion and reference positions, closing escaped memory_refs and escaped trace source-ID collection paths. Before that correction, two new actual-key cases failed and the duplicate-key control passed; the corrected read-fence selection passed all 131 cases, including owner and admitted-source controls.

At the final side head, 444 targeted and docs tests passed in 57.48 seconds, nine real PostgreSQL tests passed in 3.52 seconds, all 216 LongMemEval tests and its evidence check passed, release/static checks passed with mypy on 273 sources, and Bandit passed. All 23 physical mutations were then executed at this exact head, killed and restored byte for byte:

Final-head executed mutation Named failing test
retire_column_only tests/unit/test_source_scrub_loop_references.py::test_delete_blanks_every_loop_the_reader_names, tests/unit/test_source_scrub_loop_references.py::test_replacement_blanks_every_loop_the_reader_names (additional parameter failures retained)
preview_column_only tests/unit/test_source_scrub_loop_references.py::test_delete_blanks_every_loop_the_reader_names
blank_without_user_filter tests/unit/test_source_scrub_loop_references.py::test_cached_loop_ids_cannot_blank_another_users_loop
retain_description tests/unit/test_source_scrub_loop_references.py::test_delete_blanks_every_loop_the_reader_names, tests/unit/test_source_scrub_loop_references.py::test_replacement_blanks_every_loop_the_reader_names
retain_resolution_note tests/unit/test_source_scrub_loop_references.py::test_delete_blanks_every_loop_the_reader_names, tests/unit/test_source_scrub_loop_references.py::test_replacement_blanks_every_loop_the_reader_names
retain_metadata tests/unit/test_source_scrub_loop_references.py::test_delete_blanks_every_loop_the_reader_names, tests/unit/test_source_scrub_loop_references.py::test_replacement_blanks_every_loop_the_reader_names
canonical_parser_replaced_with_stored_spellings tests/unit/test_source_scrub_loop_references.py::test_each_spelling_is_blanked_on_delete_and_on_replace, tests/unit/test_source_scrub_loop_references.py::test_the_shared_rule_reads_exactly_the_reference_keys
reader_copy_drops_selected_source_ids tests/unit/test_source_scrub_loop_references.py::test_the_scrub_matches_exactly_what_the_reader_lists
preview_without_user_filter tests/unit/test_source_scrub_loop_references.py::test_another_users_loop_that_names_the_source_is_left_alone
blank_open_status_only tests/unit/test_source_scrub_loop_references.py::test_delete_blanks_every_loop_the_reader_names, tests/unit/test_source_scrub_loop_references.py::test_replacement_blanks_every_loop_the_reader_names (additional parameter failures retained)
count_open_status_only tests/unit/test_source_scrub_loop_references.py::test_a_resolved_and_a_dismissed_loop_named_only_in_metadata_are_counted_and_blanked[delete], tests/unit/test_source_scrub_loop_references.py::test_a_resolved_and_a_dismissed_loop_named_only_in_metadata_are_counted_and_blanked[replace]
retain_closed_at tests/unit/test_source_scrub_loop_references.py::test_delete_blanks_every_loop_the_reader_names, tests/unit/test_source_scrub_loop_references.py::test_replacement_blanks_every_loop_the_reader_names
retain_resolved_at tests/unit/test_source_scrub_loop_references.py::test_delete_blanks_every_loop_the_reader_names, tests/unit/test_source_scrub_loop_references.py::test_replacement_blanks_every_loop_the_reader_names
retain_updated_at tests/unit/test_source_scrub_loop_references.py::test_delete_blanks_every_loop_the_reader_names, tests/unit/test_source_scrub_loop_references.py::test_replacement_blanks_every_loop_the_reader_names
preview_pass_per_source tests/unit/test_source_scrub_loop_references.py::test_a_prune_reads_the_loops_once_for_the_preview_and_once_for_the_receipt
receipt_pass_per_source tests/unit/test_source_scrub_loop_references.py::test_a_prune_reads_the_loops_once_for_the_preview_and_once_for_the_receipt
replacement_discards_cached_ids tests/unit/test_source_scrub_loop_references.py::test_replacement_reads_all_source_loops_once
key_contract_drops_reference_key tests/unit/test_source_scrub_loop_references.py::test_the_shared_rule_reads_exactly_the_reference_keys
key_contract_adds_reference_key tests/unit/test_source_scrub_loop_references.py::test_the_shared_rule_reads_exactly_the_reference_keys
encoded_json_skips_decode tests/unit/test_open_loop_references_read_fence.py::test_encoded_json_references_are_withheld_on_the_real_key_list[object-source_refs], tests/unit/test_open_loop_references_read_fence.py::test_encoded_json_references_are_withheld_on_the_real_key_list[object-sources] (additional parameter failures retained)
encoded_json_skips_canonical_metadata_names tests/unit/test_open_loop_references_read_fence.py::test_a_missing_encoded_sources_alias_is_withheld_for_the_key_and_owner
encoded_json_serializes_depth_sentinel tests/unit/test_open_loop_references_read_fence.py::test_json_text_at_the_metadata_depth_limit_is_dropped_without_raising
collection_skips_json_decode tests/unit/test_open_loop_references_read_fence.py::test_encoded_memory_and_trace_references_are_collected_before_the_real_key_list[memory_reference], tests/unit/test_open_loop_references_read_fence.py::test_encoded_memory_and_trace_references_are_collected_before_the_real_key_list[nested_source_reference]

The decoder harness initially matched the collector's identical source line. The intended scrub-site mutation was corrected and killed six encoded cases; the wrong-site execution remains separately retained and is not represented as the intended scrub guard.

The earlier 6a95c209 full suite recorded 13,341 passes, 20 skips and five resource failures; all five passed the isolated rerun, with 85.68 percent coverage and module floors passing. The local worker full unit suite was not repeated at 3f69f1a7. Final side-head selected local proof and older local broad proof remain separate from the combined candidate and the later exact-head remote full CI checks.

Tested head and remaining gates

The final publication head is 3f69f1a73518d3906e9480c358bc3058fa17d0a9. The saved original PR snapshot 9999f095394df15dc36bc48fede00e3a018822de remains historical. All tests use synthetic fixtures; no live vault or production database is asserted. The final exact-head GitHub CI snapshot is verified above. The final combined validation, bounded M1-M58 reconciliation, measured source mapping and scoped execution/skeptic evidence are separately recorded above. Designated outside approvals are not issued by this work. Merge, the dedicated release tag, the owner's security-team review before the tag and advisory publication remain separate gates.

Upgrade Overview

Protected Areas

  • memory schema
  • evidence pipeline
  • trust rules
  • promotion logic
  • continuity APIs

The checked areas cover the complete cumulative diff of this exact published head against the frozen release base.

Compatibility Impact

Source deletion, pruning and replacement blank every canonically named open loop of the acting user. Other users are untouched. Preview and receipt must agree, and the pass count must not grow with source count.

Migration / Rollout

No migration is required. This independent change is included in the frozen nine-PR release candidate and needs combined verification.

Operator Action

Review the existing no-write delete or prune preview and use --yes only for the selected command. Wider reference matching applies when the command runs.

Validation

Earlier worker commands retain their actual tested revisions and limits. Final exact-head remote CI and the source-equivalent combined acceptance are separately established in the current summary; they do not backdate the historical local receipts. Designated control-tower merge approval and owner/security-team release approval remain external gates. Historical process and evidence limits remain disclosed.

Rollback

Revert the matching change. Already blanked loops stay blanked; a code rollback cannot recover deleted text.

Process variance

The existing review branch name is preserved. It differs from the handoff naming convention. Earlier updates to #565 through #569 used identity-only force-pushes and violated the mandatory no-force-push rule; preserving source trees did not make them compliant. This historical violation cannot be erased by later tests. Further updates use ordinary commits and plain merges. The handoff contains a later rebase sentence that contradicts its mandatory plain-merge rule; the mandatory rule governs.

SQLite delete, prune, and markdown replacement now use one pass over the user's loops. v0.20.0 kept the loop text for every spelling other than the stored id or source:<id>.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant