Repository navigation
Conversation
A free-form project name stays in metadata_json.project_scope. v0.20.0 wrote that name into open_loops.project_id and the brief failed on Postgres.
SQLite delete, prune, and markdown replacement now use one pass over the user's loops. v0.20.0 kept the loop text for every spelling other than the stored id or source:<id>.
# Conflicts: # CHANGELOG.md
# Conflicts: # CHANGELOG.md # apps/api/src/alicebot_api/vnext_stores/sqlite/source_retirement.py # docs/alpha/known-limitations.md # tests/unit/test_known_limitations_page_shape.py # tests/unit/test_store_graph_open_loops_split.py
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Open-loop extraction could fail after a source moved A → B → A, weekly candidates could be stored below their report inputs, and two readers omitted the caller's full fence. This correction recovers the existing per-user digest after a conflict, inserts weekly candidates with the artifact input floor, and fences source GET and enabled legacy review lists, including saved quotes.
The draft remains against the final branch of the existing stack, #571. Round two adds ordinary commits to #574 only; This work does not modify #565–#573. The owner accepted the recorded earlier force-pushes on the condition that there are no further rewrites. This round contains none. The tower must recheck the new head before merge.
The combined candidate retains the earlier UUID normalization, producer and scheduler identity, all-of selection/refill, parser-recognized source-reference withholding, retryable label-lock refusal, SQLite rollback, PostgreSQL repair CAS and source-review writeback fixes. Round two adds:
Source GET and native MCP budgets use real minted keys. Existing registry policy still disables keybound legacy aliases, even with legacy opt-in. Enabled keyless legacy review tests exercise declared trusted/admin/read-only identities and resolved locked runtime context, plus the owner; this change does not enable the disabled aliases.
The required web audit also identified GHSA-wq5f-xc86-pv6w in Sharp 0.35.4. Sharp and its binary entries now pin 0.35.5, the patched release listed in the GitHub advisory. The existing source-map-js 1.2.2 and tinypool 2.1.2 pins remain. Framework versions are unchanged.
Validation at final head 1754f8e: GitHub CI passed. The full unit shards passed 4,527 + 5,688 + 3,778 = 13,993 tests, with 20 skipped. Combined coverage is 86%; the required 50% total and 45% combined floor across 14 protected paths passed. Full role-separated PostgreSQL integration passed 746 tests, with 1 skipped, followed by 6 passing SQLite varied-parent budget tests. Model-free LongMemEval passed 216 tests, plus two configured-vector contract controls; the semantic release gate intentionally fails closed without a provider.
Final-head web validation passed 244 tests with coverage, types, production build, accessibility and browser budgets. Production audit checked 94 packages with zero matching advisories. Full audit checked 550 packages with two moderate Vitest notices and the existing high braces exception until 2026-11-03; there are zero unexcepted advisories at or above high. Final-head lint, the 279-file mypy command, distribution/install contracts, release truth, Bandit baseline, CodeQL, secrets and ops/configuration checks passed.
Local final-head retry, weekly-floor, reader, saved-quote and held-lock controls passed 38 tests, and dependency/cache controls passed 27. At runtime-identical 0a6f6ad, 251 focused label/connector/doctor tests and both full local store budget matrices passed. Raw logs and source bindings distinguish these results from older diagnostic runs.
Read budgets: paired main 48873b0 and candidate runtime 0a6f6ad, on the same analyzed synthetic data. Final head 1754f8e adds only a prefetched-alias regression-test call; API, web, performance, integration, scripts and eval trees are byte-identical to the measured revision, verified by tree hashes.
All 9 PostgreSQL and 7 SQLite tests passed. Five samples after warmup; each cell is main wall/CPU → head wall/CPU, minimum seconds. Pack and recall satisfy 2 × main + 0.1 s for both wall and process CPU. PostgreSQL native-view minimum wall time is below 1 s. Complete SQLite counts satisfy 1 s for both clocks (maximum of the fixture minima: 0.5440 wall / 0.5438 CPU), with exact admitted populations of 0, 2,500 or 5,000. Repaired fixtures assert zero stored/effective label gaps before measuring. CPU covers the measured Python process, not PostgreSQL's server CPU.
The new identical case has identical metadata and one parent, while text still identifies each row. The original byte-identical fixtures remain unchanged and passed separately. Their median main → head seconds:
The host was loaded and individual samples exceeded minima. Raw five-sample arrays, earlier failures and profiling attempts are retained; no threshold was relaxed or user process stopped. The pass establishes this fixture matrix, not an SLA under arbitrary contention.
Final-head mutation proofs: 20 of 20 selected guard removals fail the intended regression. They cover both digest retries; the complete weekly artifact-input rule; source GET; legacy effective admission and saved quotes; ancestry and original-row partitioning; bounded redact/source-review locks; plain reimport; reverse ordering; three empty-project producers; indexed PostgreSQL parent lookup; pure-parser/classifier top-level fields; source-copy closure, single-parent ambiguity and parent labels; and connector cursor-kind selection. The indexed-parent mutant fails the plain context-pack timing gate, not collection or a native-view assertion.
The first final-source attempt was 19/20: its alias test did not prime the prefetched-parent path. The final commit adds that call, ordinary controls still pass, and both alias guards are killed. This test-only correction and the failed attempt are retained. Redundant implicit weekly-parent and earlier planner removals still have no independently observable effect; they are disclosed separately and are not included as successful proofs.
Minor responses and release limits:
Upgrade Overview
Protected Areas
Compatibility Impact
Public request fields remain compatible. Source GET uses the declared route-local read policy: read-only identities can read admitted sources, while the public-health operator gate still refuses that profile. Source GET returns 404 outside the caller fence, including raw titles/text. Enabled legacy review responses omit hidden memories, quotes and their counts. Owner and admitted admin reads remain available. The earlier explicit producer identity and three-second retryable contention contract remain. Free-text source_refs remain usable outside UUID casts. Web CI remains on Node 22.
Migration / Rollout
Round two adds no migration beyond 0096 in the existing stack. That migration must run as the restricted table owner before requests are served. SQLite open repair, explicit repair and restore keep their atomicity boundary. Preserve a backup and run label checks on a restored copy under the release runbook.
Operator Action
The tower should independently recheck this exact new head before merge, review the disclosed graph/doctor limits, and repeat capture/relabel measurements before tagging. This draft does not establish production or provider-backed semantic evaluation.
Validation
Revision-bound results and paired same-data measurements are above. The focused reproductions preserve owner/admin controls, admitted sources, quotes, refs and connector state. The three CI unit shards, combined coverage, role-separated PostgreSQL integration, eval contracts, distributions, types, web build/accessibility/budgets and security audits are required.
Rollback
Use the owner-controlled code/database backup runbook. Failed repair leaves rows, audit events and the SQLite completion stamp unchanged; PostgreSQL repair refuses concurrent changes. Reverting code alone must not lower raised labels or reverse audit history.