Skip to content

feat(checkpoints): validate closed event ranges and exact identities - #47

Open
DivyamTalwar wants to merge 7 commits into
codex/jitmind-j06-reviewed-20260928from
codex/jitmind-j07-reviewed-20260928
Open

DivyamTalwar wants to merge 7 commits into
codex/jitmind-j06-reviewed-20260928from
codex/jitmind-j07-reviewed-20260928

Conversation

@DivyamTalwar

Copy link
Copy Markdown
Owner

Scope and review order

J-07, refs #37. Stacked on #46 to keep the reviewed series composable; the checkpoint extension remains optional. Native JITMIND implementation of closed-range/tool-boundary invariants informed by omnara-ai/omnara@5fa80ea4f3be999aa63fbc44513de3020ee940af, internal/storage/executionstore/context_checkpoints_boundary.go. No Omnara service or other user product is required.

Changes

  • Add an immutable scoped event/checkpoint ledger with unique sequence identities, contiguous-range validation, both tool-boundary checks, source digests, revision CAS and idempotent publication.
  • Bound aggregate source acquisition before fetching event payloads; bound prefix inspection, history pagination and publication work.
  • Replace lossy checkpoint filenames with exact-identity hashed v2 paths, validate payload identity, and retain explicit genuine-v1 compatibility.
  • Preserve distinct absence, corrupt/incompatible data, I/O failure and uncertain durability outcomes.
  • Validate serialized checkpoint data before replacement so coercing/duplicate JSON keys cannot overwrite good state with an unreadable document.
  • Keep Python 3.10 timestamp compatibility and the corrected persistent-lock/atomic-write semantics.

Composition review

The initial independent review found five correctness/resource issues; those were corrected. A subsequent composition run found six interactions with J-01 tests/error handling; those were also fixed before publication. The existing atomic regression tests now exercise the actual v2 path/open boundary, retain a genuine-v1 fixture, and preserve their original failure/previous-bytes/uncertain-outcome assertions rather than dropping them.

Verification

Candidate 75574aef663b25f48619fcf2179e59492ddbe49b; parent 8591dd75ea1289f66cd98ef42b39ae5227867157.
Full supervisor verification with all preceding components and real parser dependencies:

PYTHONPATH=$PWD python -m pytest -q -p no:cacheprovider
# 718 passed, 3 expected optional-provider warnings
python -m compileall -q jitmind tests
python -m ruff check --no-cache --isolated --select E9,F <owned Python files>
python -m pip check
git diff --check
# all passed

The full suite includes spawned process/crash/restart, JSON collision/corruption, live lock ownership and inherited persistence regressions. Sources remained unchanged during verification. No live-provider calls.

Retention and operational limits

Raw events and immutable history follow the documented retention policy; this does not restore arbitrary processes, browsers, filesystems or external side effects. Gaps cannot be guessed or silently backfilled. Multi-file legacy cleanup is not represented as a crash-atomic database transaction. Local DELETE/FULL SQLite and POSIX helper assumptions remain explicit; hardware power loss and other platforms are not thereby qualified.

See docs/checkpoints.md for exact APIs, schema, legacy migration, error compatibility and rollback. Merge prerequisites, retarget and rerun CI. No automatic merge or production certification.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant