Skip to content

Harden Hoard runtime, security, and scale paths - #17

Merged
thrr87 merged 1 commit into
mainfrom
claude/analyze-db-agent-locking-M0MZv
Feb 7, 2026
Merged

thrr87 merged 1 commit into
mainfrom
claude/analyze-db-agent-locking-M0MZv

Conversation

@thrr87

@thrr87 thrr87 commented Feb 7, 2026

Copy link
Copy Markdown
Owner

Summary

  • fix correctness/security hot spots (memory_put/upsert, artifact traversal hardening, constant-time token compares, heartbeat write classification, bm25 normalization)
  • improve reliability and runtime safety (writer startup fail-fast, flock-based sync lock, SSE connection lifecycle, WAL checkpoint policy)
  • decouple audit/rate-limit hot path and add observability (async audit sink, in-memory limiter, structured logging, /metrics)
  • improve scale behavior (bounded vector candidates, duplicate worker candidate bounds, N+1 tag fetch removal, ANN scaffolding + migrations)
  • add config/schema/maintainability work (typed config validation, shared error/scope/time utilities, canonical tool aliases + legacy compatibility)
  • add operational UX improvements (stdio write opt-in, db backup/restore commands with checksum verification)

Testing

  • .venv/bin/python -m pytest
  • result: 152 passed

@thrr87
thrr87 merged commit 5f76608 into main Feb 7, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant