Skip to content

feat(memory): add durable open work and bounded preflight - #46

Open
DivyamTalwar wants to merge 6 commits into
codex/jitmind-j05-reviewed-20260928from
codex/jitmind-j06-reviewed-20260928
Open

DivyamTalwar wants to merge 6 commits into
codex/jitmind-j05-reviewed-20260928from
codex/jitmind-j06-reviewed-20260928

Conversation

@DivyamTalwar

Copy link
Copy Markdown
Owner

Scope and dependency

J-06, refs #36. Stacked on #45. Adapt Koragraph-inspired open-loop and bounded preflight concepts within JITMIND, not another service. Reference: Koragraph/KoragraphMCP@c9ce746fbd6db67e794f5f8714c8d9a8f4669e27, src/practice/loop-anchors.js and src/practice/preflight.js.

Changes

  • Add durable UUID obligations with owner/admin authorization, revision CAS, idempotent transitions, immutable history and explicit completion evidence/reopening.
  • Keep task lifecycle separate from fact expiry, code movement and memory forgetting; losing an anchor does not complete an obligation.
  • Deliver a bounded contextual preflight: at most 20 candidate bodies and two lessons, explicit candidate-window completeness, scoped/session deduplication and no broad fallback after an empty ranked result.
  • Recheck actual fact/backing-page validity and TTL before delivery and receipt replay.
  • Resolve code-bound lessons against the current schema-2 binding authority, so a known changed/unknown/retracted binding suppresses delivery even when the lesson projection is delayed.
  • Separate authenticated policy authoring from imported observations and provide explicit owner retirement for durable approved policies.

Review-driven fixes

Corrected temporal eligibility, pre-LIMIT filtering/priority, delayed binding invalidation and policy-retirement behavior. Known unavailable authority yields an explicit unavailable/deferred result rather than guessed permission or stale lesson content. All original obligation and no-prompt-flooding controls are retained.

Verification

Candidate 8591dd75ea1289f66cd98ef42b39ae5227867157; parent 4e9535ec8567726a15f4b020a0dbac13c03ee5d4.
Supervisor run on the assembled branch with current storage, scopes, parser and anchors:

PYTHONPATH=$PWD python -m pytest -q -p no:cacheprovider
# 588 passed, 3 expected optional-provider warnings
python -m compileall -q jitmind tests
python -m ruff check --no-cache --isolated --select E9,F <owned Python files>
python -m pip check
git diff --check
# all passed

Includes 94 J-06 tests, real parser/binding/fact integration and independent-process contention controls. Tests were not skipped and copied development dependencies are excluded from the diff. No provider calls or new Python dependency.

Host and release boundaries

The host must configure trusted authoring/resolution and the bounded binding-authority reader. An author losing future authoring permission does not silently revoke every previously owner-approved policy; owner retirement is explicit and checked on replay. This policy distinction is documented.

Current visibility suppression is not physical erasure of backups. Deadlines are best-effort around host callbacks/filesystem calls, not a hard real-time guarantee. Unobserved filesystem changes are not globally atomic with multiple databases. Legacy code-bound lessons require explicit retirement/reprojection to gain new binding metadata.

See docs/open-work-preflight.md for public APIs, composition, schema/retention and rollback. Merge prerequisites first, then retarget/rerun CI. No automatic merge or production-readiness claim.

Copy link
Copy Markdown
Owner Author

CI remediation and deadline-contract evidence

Latest J-06 head: cd8059541eb28e35b626a4a5302ce7eed892ad40.

Two shared-runner fixture problems were corrected without changing production code: quota setup now seeds its 256 rows in one transaction rather than 256 FULL-sync commits, and positive RESERVED-lock read compatibility is separated from a wall-clock delivery benchmark. The positive primary-read control still requires delivered content while another process holds its lock, using a bounded functional budget. The three incompatible-lock controls retain the production 150 ms deadline, original blocked-call ceiling and deferred outcomes, with explicit empty-payload assertions.

This second change is an explicit test-oracle correction, not a claim that every assertion remained textually unchanged. Three new actual-SQLite tests advance only the monotonic deadline clock to before, exactly at, and after the default cutoff: before must deliver and commit one receipt; at/after must defer with no payload, no lesson IDs and no receipt. The original sleep-driven exhaustion test remains.

Actual verification

  • Full J-06 suite: 600 passed, three expected optional-provider warnings.
  • Eight deadline/independent-process cases repeated 25 times; all repetitions passed. These are repeated controls, not 200 independent scenarios or a production latency benchmark.
  • Compilation, selected E9/F checks, dependency consistency and whitespace checks passed.
  • No runtime deadline, authorization, visibility or receipt logic was relaxed.

The correction is being carried through the dependent PR branches with their own exact-source tests and qualification records. No PR or production release is automatically merged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant