Repository navigation
feat(memory): implement independent atomic memory - #1857
Conversation
Exclude detailed design documents from the PR while keeping local copies.
…y-specific policy Atomic Memory now applies the common access service with the shared execution context: no policy-head lock, no implicit local-runtime Owner, and no Owner prefilter for extraction candidates. Unauthenticated deployments keep memories without Owners; the current projection no longer stores Owner columns, and enforced collection reads use the common Owner readiness check. Co-authored-by: Cursor <cursoragent@cursor.com>
… probe Co-authored-by: Cursor <cursoragent@cursor.com>
…e API layer Remove the runtime ScopedMemoryApplication. The Server translates remember, search, list, get-by-target, and flush onto ScopedAtomicMemoryApplication, which gains create, flush, and cursor. Citation reads, capacity, changes, entry tags, and memory access targets are rejected before any work. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Imported revisions carry the entry's own Sources and Artifact references instead of a collection anchor and predecessor, so the evidence resolver no longer reads legacy entry tables. Apply rewrites the anchored lineage left by the earlier import. Co-authored-by: Cursor <cursoragent@cursor.com>
Extraction diagnostics now wrap the shared Atomic Source flush, so explicit and scheduled flushes report the same outcomes. The new diagnostics tests inject Atomic extraction pipelines. Co-authored-by: Cursor <cursoragent@cursor.com>
Runtime and persistence tags only address Artifacts; the deterministic legacy identity mapping stays in the server get_memory_entry adapter. The server rejects legacy collection tags and tag queries that select the memory family or memory_entry targets, and default tag queries exclude legacy Memory. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
hidb4ai
left a comment
There was a problem hiding this comment.
Reviewed 8b7a953ed2b7840e9e5349b8a24bfc9e1dca5274. Three reproduced issues remain in the inline comments: a custom Builtin authorization bypass, SQLite migration falsely reporting readiness, and non-resumable migration decisions. These should be addressed before merging.
Validation used the configured Qwen generation/embedding services, SQLite, and real OceanBase CE 4.3.5.4, including HTTP/MCP, lifecycle/restart, migration, and authorization snapshots. Acceptance is not fully green: OceanBase temporal reconciliation hit the configured 60-second timeout; Prompt acceptance failed initially and passed on a fresh-database replay, with the initial cause unresolved. The supplementary local full-suite run was stopped before completion. No installed Desktop/native-host acceptance is claimed.
- Archive and remove whole-collection citations in Handoffs and Work, blocking when a claim loses its required evidence. - Remove all collection-owned lineage before deleting collections. - Let an applied decision file be reused on rerun. - Block unfinished Dream runs whose pinned Artifacts or Sources change. - Accept import, references and projection before removal; startup runs only a light residual check. - Recreate development current-projection layouts during apply. Co-authored-by: Cursor <cursoragent@cursor.com>
…ntract The runtime, public models, OpenAPI contract, SDK, dashboard and integrations no longer know the legacy Memory collection: MemoryService, its persistence and indexes, MemoryCitation, memory_citations fields and Handoff memory citations are removed. ArtifactRef rejects family=memory, so new requests cannot reintroduce collection references; generic reads and tag queries of family=memory are unsupported. atomic-memory-migrate gains the remaining data steps and stays repeatable: - Handoff receipt evidence citing a whole collection moves to the receipt's historical_data; - unfinished Dream runs drop the empty entry citation fields, and request digests are recomputed so identical retries still replay; - Task Outcome item digests are recomputed from frozen legacy decoders; - the emptied memory_citations columns are dropped last, and startup refuses while they exist. The legacy write gate stays rejected at configuration time. The legacy collection capacity benchmark is removed. Desktop reads only Atomic Memory references and no longer bundles citation-only Server profiles. Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
|
please resolve conflicts |
Recall-gate relevance (oceanbase#1918) reads Atomic Memory hits' vector distance as cosine relevance. Its e2e expectations follow Atomic Memory search, which embeds kind and body together, limits each channel before fusion and reports recoverability as an existence probe rather than admission counts. Co-Authored-By: Claude Code <noreply@anthropic.com>
… citations Co-Authored-By: Claude Code <noreply@anthropic.com>
hidb4ai
left a comment
There was a problem hiding this comment.
Re-reviewed 400602e827fdc91eab5ba72c3b515a6423465b6f. The previous decision-replay issue is fixed in the real OceanBase CLI interruption/retry probe. The Builtin authorization bypass and SQLite BLOB migration issue remain reproducible. Two additional P2 findings are below: silently discarded Python Runtime evidence and stale pinned Dream evidence after migration.
Real-service checks used the original .env Qwen generation/embedding models and isolated OceanBase CE 4.3.5.4 databases. HTTP/MCP extraction, text/vector/hybrid retrieval, lifecycle/restoration, restart readback, tagged retrieval (access disabled/enforced), and Prompt/Experience/Skill/Handoff generation passed on SQLite and OceanBase. OceanBase temporal reconciliation and migration/DDL-interruption recovery also passed. All test databases were cleaned up. These results do not establish installed native-host acceptance; the pinned-Dream finding was reproduced at the resolver boundary before generation.
The Dify tools check also needs its stale selector-count assertion updated: the probe resolves 17 remaining selectors while the test still expects 20. Correctness findings above remain blocking.
| sources: tuple[SourceRef, ...] = () | ||
| artifacts: tuple[ArtifactRef, ...] = () | ||
| memory_citations: tuple[MemoryCitation, ...] = () | ||
| target: ArtifactRef | None = None | ||
| reason: str | None = None |
There was a problem hiding this comment.
[P2] Reject removed evidence fields at the Python Runtime boundary
Removing memory_citations leaves these public request models with Pydantic's default extra="ignore". Through the embedded Runtime, I passed a valid Source plus an invalid legacy citation to Experience propose and Candidate revise; both succeeded, and approval plus restart preserved only the Source. The same proposal on the previous head fails with InvalidMemoryCitationError before creating a Candidate.
HTTP/SDK models already reject this field, and the clean-migration contract requires rejecting legacy Candidate evidence before persistence. Please enforce that rejection for ProposeExperienceRequest and ReviseArtifactCandidateRequest too, so a successful write cannot silently discard supplied provenance.
There was a problem hiding this comment.
Verified fixed in the current Python Runtime. The original proposal now raises a validation error for memory_citations before creating a Candidate. The focused checks also verify rejection of populated, empty and null legacy fields for both ProposeExperienceRequest and ReviseArtifactCandidateRequest, while preserving current evidence references.
hidb4ai
left a comment
There was a problem hiding this comment.
Re-reviewed 60eb0095bfe7c25fc1c7f7ce7c1864106d1879c1. The Builtin authorization bypass remains reproducible. One additional P2 is below: ordinary Work message text can stop migration after writes and prevent Runtime startup. The SQLite BLOB filtering, removed Python evidence field and unfinished Dream snapshot issues are verified fixed; I have replied on their existing threads. The latest commit also fixes Desktop contract generation drift.
Validation: 95 focused tests, 55 authorization/lifecycle tests and five native SQLite BLOB regressions passed, plus a standalone public API reproduction without the pytest LIKE fixture. Using the original .env Qwen generation and 1024-dimensional embedding models, real HTTP/MCP journeys passed on SQLite and OceanBase CE 4.3.5.4, including extraction, three search modes, lifecycle changes, history and restart. Real-embedding CLI migration and repeated projection rebuilds also passed on both backends after deleting the disposable legacy tables/archive, preserving authoritative data and search results. OceanBase migration probes additionally covered pinned/queued Dream runs and recovery after committed Candidate conversion or column removal. All ten disposable remote databases were deleted and their absence independently verified.
Runtime tests ran at 38432c5a; local Git comparison confirms that the two subsequent commits change only Skill vendor/lock files and Desktop generated outputs. Their corresponding local validation checks pass. CI is not fully green: the current OceanBase migration job failed during fixture setup while creating a full-text index (SQL error 1205, lock wait timeout), before migration started; the cause remains unresolved, and other checks are still running. Native installed hosts and SeekDB were not exercised locally.
…dge legacy refs by structure with_connection rebound any Builtin provider to the base class, dropping subclass denials (e.g. Atomic lifecycle writes). Only an exact Builtin provider with an exact RelationalAccessRepository is rebound now, matching require_scope_read. Migration residual checks matched the literal "memory_citation" in Handoff and Source text, so ordinary prose blocked apply. They now inspect parsed fields only. Co-Authored-By: Claude Code <noreply@anthropic.com>
Which issue or RFC does this PR close?
Implements RFC #1809 and follows the retrieval contract in RFC #1803.
Rationale for this change
Memory collections couple unrelated entries to one revision and write boundary. This change makes each fact, preference or decision an independent Artifact, so content revision, lifecycle, authorization and exact evidence can be managed per memory.
What changes are included in this PR?
atomic-memorycontent with immutable revisions and separateactive,forgotten,mergedandretiredstate. Add explicit writes, exact historical reads, merge, forgetting, restoration preview, restoration and merge undo.create,revise,merge,noop). Recheck evidence, authorization, read dependencies and cursor generation before publishing memory changes and Source progress together.Clean migration
Legacy Memory leaves the runtime completely (
8b7a953e,e8e6b25b,6e923f3a):pc_memory_artifact_archiveand removed from the public Artifact tables, search and online reads. The legacy entry tables are retained but detached frompc_artifacts.unavailable_evidenceremain in the same JSON shape as historical descriptions of unavailable evidence. They are not resolved and cannot support new requests; exact entry citations still become Atomic references. A claim left without required evidence, a Candidate without evidence (unless a--decisionsreplacement is supplied), or an unfinished Dream whose pinned inputs would change blocks before any write.historical_dataformat. Unfinished runs with legacy input snapshots must finish before migration: removing even an empty legacy lineage field changes the pinned Artifact digest. Queued runs without a snapshot can migrate if their selected inputs are unaffected. Empty legacy request fields are removed and request digests are recomputed so identical retries still replay; a historical request that cited legacy entries keeps its original digest.memory_citationscolumns. Startup refuses while those columns exist; rerunning apply completes the remaining steps.MemoryService, legacy persistence/indexes,MemoryCitation, everymemory_citationsfield and Handoffkind: memorycitations are removed from the runtime, OpenAPI contract, SDK, dashboard, Desktop and host integrations.ArtifactRefrejectsfamily=memory, so new requests cannot reintroduce collection references; generic reads and tag queries offamily=memoryare unsupported. Frozen legacy decoders exist only inside the offline migration.Are there any user-facing changes?
This is a breaking Memory upgrade.
memory: null. Route retention does not preserve the old response models. Collection CAS, citation revise/retire, capacity/compaction, collection Create/Replace, continuous changes and collection rollback are unsupported; HTTP rejects unsupported operations with422 legacy_memory_operation_unsupportedbefore writes.atomic-memory-migrate --action plan/apply/verify; startup verifies readiness instead of converting data automatically. Migration maps legacy entries to deterministic new Artifact IDs while retaining their version chains, historical evidence, lifecycle, ownership, tags, grants/receipts and Source/task progress. Invalid history/ownership, unsupported grants, unresolved candidates or task/cursor formats can block conversion.memory.extractPrompts require explicit migration toatomic_memory.extractandatomic_memory.reconcile. Legacy CandidatePipeline and MemoryWriteGate injection are incompatible with the Atomic runtime.How was this change tested?
Current validation at
3be389ce:installed-packagejob requires manual dispatch with an installer run; the regular Windows Desktop validation passed. Python 3.11–3.14, SQLite/OceanBase acceptance and SeekDB checks passed.Focused validation for
f97529c5:Submission checks:
uv run --locked prek run -apassed all 11 hooks, including Ruff and ty;git diff --checkpassed. The seven follow-up files match the recorded validation material.Recorded validation used isolated, locked environments:
pnpm --dir integrations/dsh/plugins/powercontext testandtest:e2e— 266 unit tests and 9 E2E tests passed on each of macOS and Linux. Formal builds reproduced the checked-in bundles. OpenCodetest— 72 passed;typecheckandbuildpassed.text-embedding-3-small. SQLite's three raw XML reports were checked locally. OceanBase's three complete launcher records exited 0; their raw XML/events could not be exported after connectivity was lost. Across all model attempts, results were 9 passed / 8 failed over 17 executions of those six nodes: two provider errors, three model-output/decision failures and three configuration failures. These earlier failures remain recorded.2b903293: 3,798 passed / 152 skipped / 4 deselected. Across recorded implementation commits, all 90 distinct official OceanBase nodes have passing records after targeted fixes/replays. This is not a full-suite run of the submission's seven follow-up files; that full suite was not rerun.A historical Zcode Stop
unknownand one OceanBase FULLTEXT initialization lock timeout were not reproduced in bounded diagnostics; their causes remain unknown. Windows/macOS-specific cases, isolated native service checks and four controlled/live Zcode acceptance nodes remain deferred. Real-model OceanBase raw evidence export and the new validation container's stop operation remain pending connectivity. Migration evidence covers the tested schemas/scenarios, not production deployment acceptance.Clean migration commits: the full default suite at
e8e6b25bpassed (4,853 passed / 291 skipped) except one assertion on the startup rejection message, which was updated and rerun;tests/e2e/test_opencode_plugin_host.pywas deselected because the local OpenCode installation had no usable model.prek run -a,ty checkandmake contract-testpassed. Network-dependent packaging tests that failed during one local run on DNS errors passed when rerun.Runtime removal (
6e923f3a, merged with master atf69c2f92): the full default suite passed atf69c2f92(4,867 passed / 279 skipped;tests/e2e/test_opencode_plugin_host.pydeselected; Node 22 for native adapter checks).prek run -a,ty check,make contract-test, the Dify contract check and Desktopgenerate:checkpassed. OpenClaw, Pi, OpenCode and dsh plugin tests passed locally; Desktop UI tests and Rust tests passed on macOS except threetests/ipc.rsorigin checks that depend on Windows. The column drop on seekDB/OceanBase and Windows-specific Desktop checks rely on CI. Merging #1918 makes the recall gate read an Atomic Memory hit's vector distance as cosine relevance; its new e2e cases were adapted to Atomic search (kind+body embedding input, per-channel limits before fusion, recoverability as an existence probe).AI usage statement
GPT-6.1 Sol Ultra subagents performed implementation, validation and PR preparation; the Codex root agent reviewed the result. The runtime removal was implemented and validated by Claude Code with subagents. GPT-6 Astra Ultra subagents completed the CI and receipt migration fixes; the Codex root agent independently reviewed the combined changes and ran the final local suite. GPT-5.6 Luna was used as the generation/reranking model in the final real-model acceptance run. Validation scope and evidence limits are stated above.