Skip to content

feat(search): integrate Atomic Memory into artifact retrieval - #1882

Open
frf12 wants to merge 58 commits into
oceanbase:masterfrom
frf12:codex/artifact-search-atomic
Open

frf12 wants to merge 58 commits into
oceanbase:masterfrom
frf12:codex/artifact-search-atomic

Conversation

@frf12

@frf12 frf12 commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Which issue or RFC does this PR close?

Related RFC: #1858.

#1862 has merged into master as 4ac4f898cb3d09a917115ef1e6e15aef27085c65. This branch retains #1862 through aa7150f4a74f0389fb1064d11ce51b42a93cb9f2, includes #1857 at 7000204b, and includes upstream master through 4d3165f87e3d5780fa9aeab3d9b8c5fa4bc17ed2, including RFC #1858. #1857 should merge before this PR.

Rationale for this change

Extend the Family-scoped Artifact search API from #1862 to Atomic Memory, using the independent Artifact identity and lifecycle introduced by #1857.

What changes are included in this PR?

  • Pass the authenticated execution context through both Atomic Artifact GET routes into the existing scoped read service, preserving exact revision, lineage, content digest, ETag and 304 behavior.
  • Pin SQLite content before consulting a separate policy database, retaining the configured provider and audit store.
  • Adapt the targeted current-published-content reconciliation fix from feat(memory): implement independent atomic memory #1857 commit f483d8a4: model inputs use the new Source window and exact published Artifact evidence; durable predecessor and Source lineage remains available through exact reads.
  • Balance integer lexical coverage sums for supported long queries and recovery probes; preserve every analyzed term and admission threshold.

The standalone correction PR #1901 is closed; all its corrections are included here.

  • Register AtomicArtifactSearcher with the shared search service; the API dispatches through each Family's request model and implementation.

  • Add Atomic-owned text/vector/hybrid controls, kind/tag filters, admission thresholds, RRF parameters, normalized retrieval thresholds, and optional original channel scores.

  • Reuse Atomic retrieval and configured reranking for unified and dedicated search. Return complete exact-revision Artifacts and lineage, preserving the order of matches and Artifacts after reranking.

  • Preserve feat(memory): implement independent atomic memory #1857 candidate reauthorization: revoked, changed, or inactive candidates are filtered before external reranking, including empty outcomes.

  • Retain the integrated HTTP/plugin contracts, Dashboard search behavior, Atomic references, and bilingual search capability/fusion documentation.

  • Include feat(artifacts): add family-scoped search #1862's authorization/read-snapshot fix for both Topic search routes, preserving custom point-decision providers and independent audit stores.

  • Include feat(artifacts): add family-scoped search #1862's RRF subnormal-weight correction: precise raw ranking and exact-ratio normalization in the exceptional numeric path, preserving ordinary float behavior and legacy Topic values.

  • Stabilize the usage recorder checkout-expiry regression: force real deadline cancellation, allow the retry sufficient test-only budget, and verify exactly one recorded request. Production timeout defaults are unchanged.

  • Keep the shared AccessControlService.with_connection behavior from before the Topic snapshot fix, preserving configured Casbin providers and their repositories. Topic search reauthorization remains in the read-specific require_scope_read path.

  • Keep Atomic read authorization and its decision audit in one read-local context. Bind only safe canonical policies to the data snapshot, preserve custom point-decision providers and the original audit store, and flush audit writes after the snapshot closes. Apply the same boundary to exact reads, listing, search, candidate reauthorization, preview, and processing preparation. External inference and ordinary write binding retain their existing boundaries.

  • Update Desktop's generated bindings to the Atomic Memory contract while retaining typed adapters for the qualified legacy mutation, search, and citation responses. Atomic writes preserve every returned record and exact reference.

  • Read Atomic memories through the immutable revision endpoint using the original Family, Artifact ID, and revision; validate the returned Scope and reference. Legacy citations retain their original exact-entry request. The UI copies the complete reference and clears private results on read failures.

  • Add an explicit SQLite Atomic compatibility profile with revision-read support, keeping the qualified legacy profile available. Selecting a profile does not attest the remote binary's identity.

  • Qualify the explicit CLI 1.2.1 release/development series for Desktop diagnostics, preserving executable path, digest, exact version, fixed commands and output validation.

  • Place the CLI qualification test module after the production diagnostics items so strict all-target Clippy checks it successfully; preserve both regressions and add no lint suppression.

  • Retain all three historical Legacy/Atomic qualification records unchanged. CI fixtures use the independent explicit qualification introduced by fix(desktop): isolate CI fixture qualification and fix grouped selection #1907: native tests inject synthetic evidence, and built-wheel/installed fixtures validate their current contract, operation set and wheel digest. Only builds with the explicit ci-fixtures feature include that CI profile; ordinary builds retain their historical qualification checks. The current Atomic contract retains all eleven operations, including immutable revision reads.

  • Synchronize feat(artifacts): add family-scoped search #1862's recorder healthy-recovery fixture correction without changing production deadlines or the Atomic upstream locked-phase boundary.

  • Remove the private AccessControlService object-identity assertion from the authenticated Atomic search regression. Retain the authenticated principal, actor, groups, request metadata, and persisted authorization-decision assertions so the read snapshot can use a transaction-bound service.

#1862 has merged into master; this branch still includes the Atomic prerequisite #1857 at 7000204b. Atomic lifecycle, migration, and compatibility follow #1857. Detailed design documents are not included.

Are there any user-facing changes?

POST /v1/scopes/{scope_id}/artifacts/atomic-memory/search becomes supported. Each request searches one Scope and Family; limit bounds the result count without pagination. Atomic defaults to text and supports vector/hybrid with compatible embedding and index capabilities.

include_scores: true adds normalized retrieval scores and original channel values. Existing dedicated Memory/Atomic routes retain their dependency-defined compatibility behavior and configured reranking.

Desktop Memory supports both the qualified legacy citation protocol and the Atomic record/revision protocol, with complete copied references and explicit compatibility-profile selection.

This integration PR is open and no longer marked as a draft. #1857 remains an unmerged prerequisite.

How was this change tested?

Current reviewed merge commit: 75325965f427e9dc61989d8a8b536cddba03f7d5, incorporating master 4d3165f87e3d5780fa9aeab3d9b8c5fa4bc17ed2 (#1907). GitHub confirms 27 successful checks, 0 failed, 0 pending, and all six applicable workflows successful for this exact HEAD. The separate workflow-dispatch-only installed-package job is the one configured skip. While the preceding head's CI was running, #1907 introduced two new textual conflicts in Desktop validation documentation and the installed fixture. Those conflicts are resolved: Atomic qualification history and all Atomic/Legacy exact-reference/read helpers remain, while fixture selection uses the new independent CI qualification.

Current merged-material validation:

  • Native Memory/Session tests: 14 passed, 0 failed, 0 ignored, 0 filtered on macOS/Rust 1.95.0. These use synthetic HTTP fixtures and cover complete Atomic records/references plus isolation of fixture evidence from the ordinary product manager.
  • Python fixture qualification regressions: 5 passed, 0 failed, 0 skipped.
  • ci-fixtures library and server_probe compilation passed using a qualification generated from an actual newly built wheel and the current Atomic contract. Server Python sources are unchanged from 2f4979563; this compile check is not installed Windows or live Server acceptance.
  • make check passed, including 33 integration-manifest tests; Rust formatting checked all 16 actual targets, and commit hooks passed. Initial bare cargo commands failed command lookup before executing tests; the reruns used the existing isolated Rust toolchain. Existing macOS unused-constant and ts-rs warnings remain.

The coordinator resolved and reviewed the merge; an independent GPT-6 Astra ultra review found no lost Atomic operations, assertions or qualification records. Runtime Python sources, OpenAPI, shared authorization, Topic/Atomic read snapshots and historical Desktop compatibility records are unchanged. No design documents or new #1857 branch commits are included. Current-head CI evidence is recorded below; the earlier local compilation alone did not establish external backend or installed Windows acceptance.

Verified CI for the current commit

The audited jobs belong to 75325965f427e9dc61989d8a8b536cddba03f7d5 and actually checked out GitHub merge preview 5b3f125181e108ae7e45505313e4404d52f85f0e against master 4d3165f87e3d5780fa9aeab3d9b8c5fa4bc17ed2. Job logs, run metadata and the Windows JSON evidence were inspected; the Windows artifact archive digest was verified before reading its reports.

  • OceanBase acceptance: actual OceanBase CE 4.3.5.6 reports datafile_maxsize changing from 1G to 8G. Selected Atomic/HTTP regressions finished with 18 passed, 0 failed, 0 errors, 0 skipped, 54 deselected. Subsequent deterministic scenarios, evidence scan and evidence upload succeeded.
  • SQLite acceptance: deterministic scenarios, evidence scan and upload succeeded. The OceanBase-only regression step is intentionally skipped in this matrix entry.
  • Windows Desktop: 34 UI unit tests and 5 fixture qualification regressions passed, alongside native, formatting and lint checks. The actual CI qualification contains all eleven Atomic operations, including immutable revision reads, and matches the built wheel digest and current contract. The installer was built with the explicit ci-fixtures feature.
    • Actual native/SQLite Server checks passed in all four loopback HTTP/TLS modes. The provider-mode report confirms identity-change invalidation, same-identity revocation denying exact reads, and 51 same-title Scopes. These are independent loopback processes, not an external production deployment.
    • The actual installed WebView2 report is passed / complete: save/search/exact read, independent Server exact read, clipboard/reference reuse, connection isolation, reconnect clearing, draft handling and lost-response behavior all succeeded. Installation and uninstallation returned 0; the external sentinel and Server data were preserved. The lifecycle test intentionally forced the owned application to exit and verified the independent Server remained usable.
    • Scope is an unsigned hosted Windows Server 2025 installer with existing WebView2 and disposable automation policy. It does not qualify clean Windows 11, standard-user installation, missing-WebView2 recovery or visual usability. The isolated CLI diagnostic probe succeeded while reporting missing hosts and a noninstalled service; those diagnostic results are not host-integration readiness claims.
  • SeekDB Python 3.11 and 3.14: per version, code indexing/roundtrip selection was 31 passed, 1 skipped; migration base selection 19 passed, 41 deselected; runner collection selected 12 of 24 (12 deselected), followed by 11 passed, 1 skipped across isolated runner executions. A successful job does not mean every migration case ran.
  • Main, Native personal service, Skill guidance, Desktop, E2E harness and License workflows all succeeded. The installed smoke actually ran in the windows job despite the separate dispatch-only job's configured skip.

The six earlier reviewer threads have already received verified replies; no duplicate replies are posted for this CI completion. Historical failures, skips, deselections and controlled-model limitations remain below.

Historical validation records and initial failures

The following entries describe their named commits and checkpoints. Statements that CI was pending apply to those earlier checkpoints; the current-head results are recorded above.

Verified CI for ancestor 2f497956329bb1134b2e121457f1a5fd6f02e617: 27 successful checks and all six workflows successful, one separate dispatch-only job skipped. Audited jobs checked out merge preview 30685a0f55ff5d309e56c8d76110cc4cd10c8b93 against master de1f2b184. These results do not cover the new #1907 integration above.

  • OceanBase/SQLite acceptance: OceanBase 4.3.5.6 confirms datafile_maxsize 1G→8G; selected regressions 18 passed, 0 failed/errors/skipped, 54 deselected. Both deterministic harness and evidence scans passed.
  • Windows Desktop: 34 UI unit tests and native/real Server/CLI/installed smoke stages passed. Installation and uninstallation returned 0 and preserved the external sentinel. Hosted unsigned Windows Server 2025 evidence does not qualify standard-user, absent-WebView2 or visual usability.
  • SeekDB/Main: both Python 3.11 and 3.14 jobs succeeded. Per version, code selection was 31 passed, 1 skipped; base migration selection 19 passed, 41 deselected; runner collection selected 12 of 24 (12 deselected), followed by 11 passed, 1 skipped. These successful jobs do not mean every migration case executed.

Current reviewed merge commit: 2f497956329bb1134b2e121457f1a5fd6f02e617, incorporating master de1f2b1843e7a6e3f0c67140139af6c4ea0ee006. Fresh CI for this new head is pending; the successful checks at ancestor c9ae71a44 do not establish new-head CI success.

Four textual conflicts were resolved while retaining both branches' behavior: Desktop connection-test coverage; Dify's Atomic schemas with the new selected-contract generation; explicit offline migration exports; and Atomic SQLite read-only URL/inspection support alongside master's cancellation/connection cleanup. The newly imported Dify contract-drift regression now mutates the consumed AtomicMemoryRecord.text schema rather than the unused legacy SearchMemoryHit.text, retaining all stale-check and generated-output assertions. There is no new #1857 branch merge or shared permission change in the conflict resolution.

Coordinator execution on the final merged material (Python 3.12.7):

Validation Passed Failed Skipped Deselected
Atomic/search/authorization, SQLite profile/snapshots, migrations, recorder and HTTP contracts 512 0 0 67
Dify real HTTP/SQLite tools and Topic authorization snapshots 34 0 1 36
Isolated Dify SDK and generated-contract regressions 63 0 16 0
Desktop UI unit tests 34 0 0 0

The 17 skips across the Dify executions require external Dify host/daemon source checkouts. Deselections exclude OceanBase/SeekDB and live-model configurations from these local runs. The Dify HTTP execution uses an actual loopback Server and SQLite with controlled generation; it is not Dify application UI or live-model acceptance. No new installed Windows or external database execution is claimed locally.

make check passed, including 33 integration-manifest tests; Desktop lint, Dify generation/format/type checks, whitespace checks and commit hooks passed. The initial Dify run had 62 passed / 1 failed / 16 skipped against the obsolete schema assertion, and the first repository check reported a long-line formatting issue; both are retained in the validation record. The final complete Dify rerun passed after formatting. A GPT-6 Astra ultra read-only review independently checked the SQLite/Atomic boundaries and all five conflict adaptations; no dropped assertions or merge defects were found. Design files are not included.

Current PR head: c9ae71a44c6d755fa2ff61c8b240860d26d85876. GitHub reports 27 successful checks, 0 failed, 0 pending, and all six applicable workflows successful. The separate workflow-dispatch-only installed-package job is the one configured skip. Successful jobs can contain selected/skipped tests; this is not a claim that every backend or model configuration ran.

The CI runs belong to this PR head. The audited acceptance and Desktop jobs checked out GitHub's merge preview 039fbdaa9bf07025459af2c3c799b3089c291d09 against master 2c987ea9dd4f1c2124393a6ef694abb9072292cd.

  • Main CI: Python 3.11–3.14, SeekDB jobs, quality, evaluation, website and package checks passed.
  • OceanBase acceptance: actual OceanBase 4.3.5.6 reports datafile_maxsize changing from 1G to 8G on the disposable SLIM instance. Selected concurrency/read/runtime regressions finished with 18 passed, 0 failed, 0 errors, 0 skipped, 54 deselected. The subsequent deterministic harness scenarios, evidence scan and upload also passed. All test selections and assertions remain enabled.
  • SQLite acceptance: deterministic scenarios, evidence scan and upload passed. The OceanBase-only regression step is intentionally not run in this matrix entry.
  • Windows Desktop: 34 UI unit tests passed, followed by successful native checks, real SQLite Server acceptance, real CLI checks, installer build and installed-package smoke. The installed smoke step actually ran in the windows job, independently of the skipped dispatch-only job. Its report records install/uninstall exit 0 and preservation of the external sentinel. This is unsigned hosted-runner acceptance, not standard-user installation, absent-WebView2 recovery or visual UI qualification.
  • Native personal service, license and Skill guidance workflows also passed. The current CI-only patch passed independent review, YAML/shell checks and make check, including 33 integration-manifest tests.

All six outstanding fixes are included: Desktop upgrade-profile selection, oversized Topic lexical admission floors, both Atomic Artifact GET authorization paths, separate-policy SQLite snapshot ordering, bounded reconciliation evidence and long-query lexical expression depth. The focused local review suite at ancestor 70b1a5e2 passed 396 / 0 failed / 0 skipped / 37 deselected; the master-conflict suite at ancestor e9056efd3 passed 165 / 0 failed / 3 skipped / 0 deselected. These are scoped ancestor runs, not repeated current-head local runs. Real-model quality and temporal-conflict generation remain outside the controlled-model regressions.

The previous e9056efd3 OceanBase run failed with 16 passed, 2 failed, 54 deselected, with both failures caused by error 4184 during database/index initialization. Earlier Windows failures stopped before installed Memory acceptance. Those failures and all earlier skip/deselection distinctions are retained below; the current successful runs do not relabel them.

Current reviewed commit: c9ae71a44c6d755fa2ff61c8b240860d26d85876. This CI-only follow-up raises the disposable OceanBase SLIM instance's bounded datafile growth limit to 8G and prints the real size/growth/max parameters before and after configuration. All OceanBase test selections, assertions and following harness scenarios remain enabled. The fixed-image runtime parameters and successful acceptance still require this new commit's CI.

The prior head e9056efd3 failed OceanBase Acceptance after 16 passed, 2 failed, 54 deselected: both failed database/index initialization with underlying OceanBase error 4184, Server out of disk space. Subsequent scenarios did not execute, and evidence scanning failed on the empty output. The official SLIM demo configuration has a 1G maximum; ordinary resource environment overrides do not configure its restored demo. This change adjusts only this ephemeral CI instance, preserving all production code and regression behavior.

For c9ae71a44, the workflow parses, its shell script passes bash -n, independent source review found no issues, and make check passes including 33 integration-manifest tests. Real OceanBase acceptance and remaining current-head CI are pending.

Reviewed merge ancestor: e9056efd3cf74dfdc14ffc7031a698ed89a5a209, incorporating master 2c987ea9dd4f1c2124393a6ef694abb9072292cd. The LoCoMo and LoCoMo Plus runners use the reorganized evaluation paths and registered Scope mappings while retaining Atomic retrieval and exact evidence lineage. New persisted-scope tests use Atomic extraction/reconciliation and record shapes.

Current merge validation on Python 3.12.7 / Node 22.23.2: 165 passed, 0 failed, 3 skipped, 0 deselected, covering LoCoMo/Plus evaluation, real SQLite Scope restart/resume, model usage and integration guidance. The three skips require Pi/OpenCode package dependencies or a built OpenClaw package. make check passed, including 33 integration-manifest tests. The initial run had 162 passed / 3 failed / 3 skipped: one test lineage accessor was corrected; the native adapter ran under default Node 26, which removed its experimental TypeScript flag; the existing 30 ms SQLite recorder deadline failed once and passed both isolated and complete reruns. These initial results are retained in the validation record. Independent source review found no further merge-resolution defect. GitHub confirms this head is mergeable; its fresh CI is queued/running.

The following Atomic repair validation belongs to ancestor 70b1a5e2d397eeaf7708072e9f86126a3a1de0cc; its production implementation is unchanged by the merge.

The four Atomic review findings are repaired in this commit. Coordinator independently reviewed all 14 changed files and ran the final focused cross-component suite on Python 3.12.7: 396 passed, 0 failed, 0 skipped, 37 deselected. The deselections exclude real-model and OceanBase/SeekDB cases from this local SQLite run. There were 50 existing SQLite datetime-adapter deprecation warnings. make check passed, including repository pre-commit/type checks and 33 integration-manifest tests; commit hooks and whitespace checks passed. The first check invocation reformatted one test file and its nonzero result is retained; the subsequent clean check and final regressions passed.

Regression evidence:

  • Two Atomic GET paths: actual HTTP handlers and SQLite reproduce the route-authorized/revoke/new-revision race for Builtin and Casbin (4 failed before / 4 passed after). Authorized exact/current reads also preserve content digest, lineage, historical revision, ETag/304 and missing-revision behavior.
  • Independent policy/content databases: public scoped text/hybrid search with two actual SQLite files and Builtin/Casbin reproduces the post-allow new-content race (4 failed before / 4 passed after). The read now retains only the earlier authorized content and fresh reads reflect revocation; provider and audit-store semantics remain intact.
  • Long ASCII/CJK queries: real SQLite connections are configured with the standard expression-depth limit 1000, because this local build compiles with 10000. Both unified/dedicated text and hybrid searches, plus a lower-admission recovery probe, complete successfully (5 failed before / 5 passed after). No terms are truncated.
  • Source reconciliation: actual public capture/flush with controlled generators and the production character estimator previously failed on the eighth large Source at 27,090 / 24,000 tokens, and three retries stayed at cursor/revision 7. After adaptation, twelve writes progress to 12 with maximum model input 4,227 tokens. Source originals and all twelve exact historical revisions remain readable after reopen; migration lineage still resolves A/C and excludes unrelated B. Coordinator independently reran the generation, migration and prompt regressions in the final suite.

Fresh GitHub CI for this exact head is pending. Local SQLite/concurrency and controlled-model evidence does not establish live OceanBase/SeekDB, live-model or installed Windows acceptance. Previous failed Windows runs and historical CI results below retain their original commit and scope. Shared authorization helpers, Topic read snapshots, OpenAPI/generated bindings, Desktop/native qualification and design files are unchanged by this correction.

Historical reviewed integration commit: f9570ed28626935408a87bf57420549d2c80ddc5.

This normal merge synchronizes #1901 at 0ac9186b514356636553d11649a814a0638144cf. Its only delta from 5c77f022 is one XPath slash in the installed workflow: select descendant options inside the new optgroups. The exact qualified profile ID and existing WebDriver enabled check remain; the full Atomic workflow and every save/search/reference/immutable-read assertion are unchanged.

The actual previous-head Windows execution 37904879418 passed 34 UI tests, native suites and real Server/CLI stages, then failed installed smoke with installed_element_timeout for its exact Atomic profile at the old immediate-child XPath. Base's corresponding run failed at the same locator for the Legacy profile. Both real failure logs are retained. Neither failed installed workflow reached Memory save/search/exact-read acceptance.

The coordinator independently verified the exact one-character Base and Atomic patches, then ran the actual-rendered Connections XPath probe with each checkout's generated digest and manifest: 1 passed, 0 failed, 0 skipped per execution. Both checkouts passed make check (33 integration-manifest tests each) and three-script Ruff/format/Windows-platform/Linux-platform Ty checks. These are local jsdom and static checks, not installed Windows execution. Fresh CI for the exact current head is pending; native, generated, qualification, production UI and authorization code are unchanged. Earlier validation and failed executions below retain their identified material.

Historical reviewed integration commit: 5c77f0221d5b11b067263e3cbf4eb77515766342.

The final normal merge synchronizes #1901 at 763022e7b5c30fe0c505beaa193a2fdbbf59b82c. Its delta from 1be35b04 is only the two common UI test fixtures. Real focus/key/input observation established navigation heading focus interrupting premature test typing; the fixtures now wait for the existing visible focus transition before typing. All original late-save, dirty-navigation, confirmation and complete-text assertions remain. Atomic-specific tests, production UI, generated contracts, native qualification and authorization source are unchanged.

Coordinator independently ran the complete final Atomic UI: 34 passed, 0 failed, 0 skipped; final Base UI: 28 passed, 0 failed, 0 skipped. Atomic make check including 33 integration-manifest tests, Desktop lint/build, and staged whitespace checks passed. The earlier Topic 198 passed / 0 failed / 0 skipped / 1 deselected execution applies to the identical Python correction source, which the two-file fixture merge does not change. Fresh CI for this exact published head is pending. Earlier local and Windows failures remain recorded below and are not retroactively replaced with passing results.

Historical reviewed integration commit: 1be35b04f2626689863ad559f6276968c805b209.

This normal merge synchronizes #1901 at dc7c631105f47fdfd7b1e3f48011a0259fee82c1 and upstream master at 13c0144dfc49fa8d6367e796866b7adaf9fe86fb. The merge delta contains the nine reviewed correction files and six upstream RFC documents; the Atomic README selects its existing sqlite-atomic-7bd5b85c-v1 qualification. The seven common non-README files are byte-identical to #1901. Native contracts, qualification records and authorization code are unchanged.

Coordinator execution on this merge material: Topic tests 198 passed, 0 failed, 0 skipped, 1 deselected (not live_oceanbase); new compatibility UI regressions 3 passed, 0 failed, 5 skipped; make check including 33 integration-manifest tests, Desktop lint/build and whitespace checks passed. The full local Atomic UI run had 33 passed, 1 failed, 0 skipped, retaining the previously recorded late-connection-editor timing failure (New draft expected, N received). #1901's Windows run 37903135663 also failed a pre-existing late-Memory-save timing case: 27 passed, 1 failed, with subsequent native/installed acceptance not reached. At that checkpoint the cause was under investigation; the final two-file fixture correction and its evidence are recorded above. These are separate executions, not a combined unique-case count. Fresh CI for this published Atomic head is pending.

Historical reviewed integration commit: c07d5524f41eacab2055a5e52507b257cd2c9997.

Fresh GitHub verification on 2026-10-09 at 07:26 UTC confirms 27 required checks and all 6 latest workflows successful for this exact integration head, including Main Python 3.11–3.14, SQLite/OceanBase acceptance, and Desktop Windows. The separate optional installed-package job is skipped because it requires explicit workflow dispatch. This records actual CI completion, not execution of every parameterization or installed-package scenario. Historical local results below retain their original material and limitations.

The earlier same-head OceanBase job 113704300726 in run 37894977471 failed during full-text-index initialization with OceanBase 4184 (Server out of disk space), before the authorization test body: 17 passed, 1 failed, 44 deselected. The new independent same-head run 37896487667 completed successfully, including OceanBase job 113709071278. The original failure remains recorded; the specific host/container/internal-quota cause was not measured or claimed repaired. No additional rerun request or production resource change was made for it. Older cancelled Main jobs are retained as superseded history.

Desktop upgrade-profile instructions and oversized lexical admission floors are addressed by #1901 and the current synchronization. The underlying Experience/Skill authorization race predates #1862; the P1 reply requests a separate issue covering legacy and unified retrieval paths. No Experience/Skill authorization changes are included in this correction. Historical CI completion alone does not establish the new corrections.

The final normal merge of upstream d3ef2c10dc0d8a6fe3bfd983f33c3589c3af6d91 resolves conflicts caused by the squashed #1862 history. Its committed delta from 84e03d88f18e532f95d5f8053c38c6f6c95f042d consists only of the two upstream RFC #1858 files. All 2,226 existing tracked files retain their exact bytes and modes, including the Atomic implementation, generated contracts, UI and tests. The coordinator independently verified the staged and committed diff and the RFC bytes against upstream; all 11 repository checks passed. Runtime results below apply to the unchanged source and are not represented as newly repeated executions after this documentation-only merge. Fresh final-head CI has now completed successfully as recorded above.

Current Desktop synchronization and Windows CI repairs:

  • The actual Windows job for 715d62e3435c217bb1d00f20ee4787c287f7df0e passed Desktop lint/generation, type checking, 31 UI cases across five files, production build and Cargo formatting, then failed strict all-target Clippy with items_after_test_module. Native tests, real Server/CLI probes and installation acceptance were not reached in that job. The fix at 1c711da9a01a4d868aadb82b9467cf01bf589a46 only moves the existing diagnostics test module to the end of the file; its qualification predicate and both regression assertions are unchanged, and no source lint allowance is added.
  • The Desktop integration includes feat(artifacts): add family-scoped search #1862's compatibility repair at 347610aceeb6f5510e77a88e377a6393a651a020 and its three-fixture formatting correction at aa7150f4a74f0389fb1064d11ce51b42a93cb9f2. The compatibility merge was committed as 5f5ba864ff4c6aadf6b79011aeb83c54ec9b7fe4; the subsequent normal merge of Base at aa7150f4a74f0389fb1064d11ce51b42a93cb9f2 produced 84e03d88f18e532f95d5f8053c38c6f6c95f042d with an identical Git tree. The Base commit is an ancestor of this final integration. The reviewed Atomic-relative compatibility merge changes seven Desktop files (89 insertions, 24 deletions). Official generation retains Atomic's 0807df984ba706b505d4fff0cb849d4566222f10572d91a5e03399b833d1fe4f contract and 11 operations, including get_artifact_revision; generated bindings match the actual Atomic OpenAPI source. No backend, OpenAPI, design or UI production/test changes are included in this follow-up.
  • The manifest preserves the complete original sqlite-6e237568-v1 and sqlite-atomic-7bd5b85c-v1 identities and operations, and adds the independently qualified sqlite-legacy-58f7f4f6-v1 record from Base. Native and installed fixtures select the unique explicit record for the bundled source contract and reject unknown or duplicate matches. Atomic's current contract selects only its Atomic qualification. Response shape does not infer qualification. All Legacy/Atomic payload, complete-reference, immutable-read, identity, revocation, audit and no-replay assertions remain intact; the production qualification gate is unchanged.
  • Local macOS verification on the reviewed Desktop integration tree (Atomic parent 1c711da9a01a4d868aadb82b9467cf01bf589a46, Base compatibility parent 347610aceeb6f5510e77a88e377a6393a651a020): 30 passed, 0 failed, 0 ignored, 0 filtered across library 4, API 11, diagnostics 3, Memory 8 and Session 4. The library count includes the two CLI version regressions. The coordinator independently repeated all 30 selected cases with the same zero failed/ignored/filtered result; the executions overlap and are not added as unique cases. These selected suites do not constitute a full native suite.
  • Official generator checks, Desktop lint/type checking/build and native IPC export drift passed. Actual Cargo formatting passed with nonempty verbose evidence showing 16 targets; the three changed fixtures also passed explicit Rustfmt checks after reproducing their original formatting differences. All-target local Clippy passed with only a command-level allowance for the existing macOS unused credentials::SERVICE constant; no new source allowance was introduced. Independent full repository pre-commit checks passed all 11 configured checks. The coordinator independently reviewed the exact merge patch and repeated the actual 16-target formatting check. The old empty formatting log is not used as proof of processed files.
  • Installed fixture Ruff, formatting and Ty checks for darwin/linux/win32 passed 5 checks, with no final errors. The actual shared helper passed five source-contract cases: all three explicit recorded qualifications, unknown-contract rejection and duplicate-qualification rejection. These are static/helper checks and do not establish installed application acceptance.
  • The actual native ConnectionManager passed 4 real built-wheel SQLite Server modes, with zero failed modes: anonymous loopback, Bearer, HTTPS with explicit CA/base path, and injected-provider/enforced access. All original assertions for Atomic writes and complete references, search, immutable revision reads, identity invalidation, same-identity revocation, ambiguous writes without replay and 51 same-title Scope pagination were preserved. The wheel was 1.2.1.dev89+g1c711da9a.d20261009, SHA-256 51432dec5a817cbfc74bfbc7372ca965ea03b7fc0d186a901c30427e41e998be. The report identifies the uncommitted integration tree; historical qualification identities are not rewritten to this wheel.
  • Those real Server executions used macOS 26.2 ARM64, Rust 1.95.0 and Python 3.12.7 with the existing external system Python launcher for native process creation. The launcher preserves the wheel, native client, fixtures and all business assertions. These local SQLite executions do not establish Windows registered-executable, IPC, credential vault, process containment, installer or installed UI acceptance. No new actual legacy remote deployment was exercised. The prior macOS IPC integration and current-exe-child transport environment boundaries were not rerun or reported as passing in this merge validation. Fixed CLI semantic replays below belong to their identified earlier material.

The historical local UI suite did not pass. Four retained executions have the following actual counts; repeated runs are not added as unique cases:

macOS UI execution Passed Failed Skipped Failure
Full 31, inherited PATH resolves Node 26.7.0 30 1 0 Memory late page-switch save: finish is not a function
Full 31, inherited PATH resolves Node 26.7.0 30 1 0 Connection late editor save: finish is not a function
Focused Memory page-switch case, inherited PATH resolves Node 26.7.0 0 1 16 Expected draft B, received d
Full 31, explicit bundled Node 24.19.0 first in PATH 30 1 0 Connection late editor save: expected New draft, received N

The second invocation's intended filter did not apply, so it is correctly reported as a full suite. The first three Node labels describe the inspected executable shim and inherited PATH; their running Vitest process versions were not independently instrumented. The pnpm parent used Node 24.19.0, and the fourth run explicitly corrected PATH and verified pnpm exec node --version; Node 24 alone did not resolve the failure. UI production code, tests, lockfile and Vite configuration are byte-identical to the preceding Atomic material. The existing deferred App.navigate heading-focus callback can interrupt immediate test typing; this is a source-grounded inference, not a demonstrated root cause or an actual Windows failure. No UI assertion was relaxed or UI code changed. The older Windows 31 passed result is historical; fresh Windows CI must execute the current integration's 31 cases and the complete target-platform workflow. This PR does not claim complete local UI or fresh Windows CI success.

Historical CLI qualification and recorder recovery verification at 715d62e3435c217bb1d00f20ee4787c287f7df0e:

  • Actual previous-head Windows CI rejected the built CLI 1.2.1.dev86 before executing diagnostics because the qualification gate accepted only 1.0.1 and 1.1.1. It had already passed UI, native tests, strict Clippy and all four real SQLite Server modes. Installation acceptance was not reached.
  • The explicit new-series qualification regression failed against the old predicate and passed after the correction. Local macOS library/diagnostics suites: 7 passed, 0 failed, 0 ignored, 0 filtered, independently repeated by the coordinator. Actual built-wheel CLI version, service status and integrations outputs were replayed through the production Rust projection: 2 integration cases passed, preserving unhealthy exit status and existing assertions. These executions do not establish Windows registered-executable or installed acceptance.
  • The actual Python 3.11 CI failure occurred in healthy recovery after locked settlement, empty rows and restored connection checks passed. Controlled real SQLite delays separately reproduced deadline exhaustion and premature best-effort flush return. They establish the fixture assumptions without claiming the original Linux runner's exact internal delay.
  • Python 3.11.13 and Python 3.12.7 each passed the full recorder module: 27 passed, 0 failed/skipped/deselected. The target passed 20 repetitions on each version and both controlled delayed-checkout cases. The coordinator independently passed the Python 3.11 module. Executions overlap and are not added as unique cases.
  • The same recorder receives one recovery offer with a separate test-only budget, waits for settlement, and must persist exactly one request. The Atomic locked write/flush/settlement boundaries remain 0.25/0.3/2 seconds. Base's common recovery correction is included by normal merge at 715d62e; Atomic's existing locked phase is preserved.
  • Cargo formatting and affected local Clippy passed, with only the existing macOS dead_code allowance. Full repository pre-commit checks passed all 11 configured checks; commit hooks and diff checks passed. The committed diff equals the independently tested material. No production recorder, authorization, HTTP contract or design changes are included in this follow-up.

Historical Desktop compatibility validation at 78df6ac9fc702541389d4822ae1919763be1f58d after merging upstream master at aeeb735397f692df186c32b404f4245030db1f22:

  • Focused macOS native regressions: 44 distinct passed, 0 failed: API 11, Memory 8, library 2, diagnostics 3, profiles 6, session 4, TLS 1, and transport 9. The transport child-process repetition reports 1 passed and 8 filtered out; it is already included in those 9 transport cases and is not added to the distinct total.
  • Desktop UI: 31 passed across 5 files. The UI production build also completed locally.
  • Independent checks of six affected Python harness scripts passed Ruff lint and formatting. installed_ui.py, installed_fixture.py, and installed_workflow.py also passed ty under both tested platform configurations; these are static platform checks.
  • Independent execution across four affected Atomic HTTP, snapshot, and lifecycle files: 36 passed, 0 failed, 25 skipped, 0 deselected. The skips are backend-availability parameters: the existing OceanBase URL is not configured locally, and embedded SeekDB is not installed. These are separate from the Rust/UI results and are not combined into a unique-case total.
  • The native ConnectionManager passed all four real built-wheel SQLite Server harness modes on macOS: anonymous loopback, Bearer, HTTPS with explicit CA and reverse-proxy base path, and injected-provider/enforced access. The checks cover writes and returned exact references, search, immutable revision reads, identity changes, revocation, ambiguous writes without replay, and Scope pagination. Qualification metadata is recorded in desktop/VALIDATION.md; the complete final JSON report is retained in external validation artifacts.
  • The real Server run used macOS 26.2 ARM64, Rust 1.95.0, and Python 3.12.7. An external launcher used system Python 3.9.6 for native process creation after the Conda Python parent caused the signed native executable to exit with SIGKILL before its first request. The wheel, native client, fixtures, and business assertions were unchanged by the launcher.
  • Local full Cargo execution remains limited by an existing duplicate IPC property-list entry on macOS. Unmodified strict Clippy also encounters the existing unused credentials::SERVICE constant; the focused local Clippy run allows that existing dead_code while retaining strict handling of other lints. These results do not claim an unmodified full Cargo/Clippy pass.
  • Typed adapter regressions cover the retained legacy response/citation protocol. This qualification run did not exercise a real legacy remote deployment. Windows IPC, vault, process containment, and installed-package acceptance remain subject to actual Windows validation. The final native client binary repeated all four real Server modes successfully. Server source, HTTP contract, uv.lock, and project configuration match the qualification snapshot at 7bd5b85c154c284d0ad550de31ecf8aa629d8ccf. Full repository pre-commit checks passed all 11 configured checks; commit hooks and git diff --check passed. The committed diff matches the final tested material.

GitHub CI at 78df6ac9fc702541389d4822ae1919763be1f58d finished with 25 successful checks, two failed checks (Python 3.11 recorder recovery and Windows CLI qualification), and one intentionally skipped installed-package dispatch job. Those two failures were addressed by the historical CLI/recorder follow-up at 715d62e3435c217bb1d00f20ee4787c287f7df0e. Its later actual Windows job then exposed the diagnostics test-module placement failure described above. The current integration includes that placement correction and the common Desktop qualification/format synchronization; fresh final-head CI has now completed successfully as recorded above.

Historical Atomic read-audit repair verification at 6835315a7aa6ea277e6818915667eb3a98c28fc4:

  • Independent execution on Python 3.12.7: 45 passed, 0 failed, 0 skipped, 20 deselected across Atomic search authorization snapshots, prepare lifecycle, access adapters, and the complete worker prompt/usage module. Deselections choose SQLite instead of OceanBase/SeekDB parameterizations.
  • The original Memory worker failure was reproduced using an actual spawned worker and failed before this repair, then passed afterward. Worker family coverage passed 3 cases on both Python 3.11.13 and Python 3.12.7.
  • The other failing CI business flows and three Dashboard cases passed 11 cases on Python 3.12.7. A controlled public remember/write interleaving reproduced the original Dashboard SQLITE_BUSY_SNAPSHOT (517) and HTTP 503; the repaired source returns HTTP 200 under the same interleaving. The actual CI logs exposed the outer access_unavailable failure, so the controlled replay establishes the underlying defect without claiming every CI failure recorded that exact SQLite error code.
  • Full repository pre-commit checks passed: all 11 configured checks, including global type checking. Commit hooks and git diff --check passed.
  • These local runs use actual SQLite and a hermetic loopback inference provider; they do not establish current-head real OceanBase/SeekDB acceptance. Counts across repeated/overlapping executions are not added as unique cases. No local full-suite/tox run was performed for this repair. New-head GitHub CI is tracked separately.

Shared authorization-method restoration verification at d5c3c65d771f5a42e41515e8c9f6c5949b11a248:

  • Focused local authorization and read-snapshot regression on Python 3.12.7: 94 passed, 0 failed, 0 skipped, 36 deselected. The deselections exclude OceanBase/SeekDB parameters from this SQLite run.
  • A new public authorization regression confirms that a custom Casbin repository can allow Scope reads while denying contribution, even when the canonical relationship store still grants contribution. It fails before the restoration and passes afterward. This is a service-level check using actual SQLite, not a complete Dream HTTP execution.
  • Both Topic routes retain the post-embedding read check and consistent snapshot coverage, including custom-provider and independent-audit compatibility. The generic database cases include actual SQLite transactions and simulated MySQL setup; no new live SeekDB/OceanBase execution was performed for this restoration.
  • uv run prek run -a: all repository checks passed, including global type checking. git diff --check passed.
  • These focused checks are separate from GitHub CI and from the historical feature validation below. The full local suite and tox matrix were not rerun for this restoration.

Historical CI validation at 34c1fff84213a8fc56f7ed5eda893244d190283e:

GitHub CI completed successfully on that commit: 26 of 26 checks passed, including Python 3.11 unit and end-to-end tests, the other Python matrix jobs, and both acceptance jobs.

Actual Ubuntu Python 3.11 CI stage Passed Failed Skipped Deselected
Unit 3868 0 128 0
End-to-end 529 0 138 4

The recorder file passed all 27 cases, including the checkout-expiry regression. These CI results retain skips and deselections; successful checks do not mean every backend/configuration was exercised by the matrix suite.

Checkout-expiry fixture validation at 34c1fff84213a8fc56f7ed5eda893244d190283e:

Validation Passed Failed Skipped Deselected
Python 3.11 recorder tests 27 0 0 0
Python 3.11 related statistics, snapshot and API tests 65 0 1 0
Python 3.11 distinct normal repetitions 20 0 0 0
Python 3.11 distinct repetitions with 250 ms retry-checkout delay 10 0 0 0
Independent Python 3.12 recorder, snapshot and fusion regression 79 0 0 0

The single skip is the real OceanBase statistics case because POWERCONTEXT_TEST_OCEANBASE_URL is not configured locally. These are separate executions with overlapping cases, not a sum of unique cases. A diagnostic copy with deadline expiry disabled failed at the required cancellation assertion and completed cleanup without hanging. A controlled 250 ms retry-checkout delay reproduces the empty-row failure with the original 200 ms budget; the revised fixture succeeds with the same delay.

Full repository pre-commit checks, global type checks, Ruff and formatting checks, and commit hooks passed.

Scoring and contract validation at 4406243e0c3db7bbebb8acd746b8ad2ba1796094:

Validation Passed Failed Skipped Deselected
Shared fusion, Topic and Atomic scoring/domain/HTTP regression 108 0 0 4
Independent fusion and Atomic scoring/domain regression 75 0 0 4
make contract-test 49 0 0 0

The four deselections explicitly exclude OceanBase/SeekDB parameters from local SQLite runs. The RRF regressions cover scaling, threshold eligibility, ordering, mixed weights, combined subnormal contributions, and rounding boundaries. Independent actual SQLite HTTP replay confirms equal text weights 1 and 1e-320 both return approximately 0.99193548 and exclude both results at min_score=0.999. Text mode performs no model call.

No generated contract changes were required. The full local repository suite and tox matrix were not rerun.

The inherited Topic fix at base dependency 1fcfe876 also passed 54 core HTTP concurrency cases across real SQLite, SeekDB, and OceanBase, plus 14 SQLite compatibility and 8 generic transaction cases. Those remote executions used the base commit; the local focused authorization verification above uses SQLite. They do not establish final-head real-backend Atomic acceptance.

Live Atomic temporal-conflict generation/reconciliation remains outside these local controlled-model regressions. The targeted published Artifact evidence schema and prompt validation adaptation is described in the current verification above.

AI usage statement

The feature implementation used Codex subagents with GPT-6.1 Sol at ultra reasoning effort. The current Atomic review corrections were implemented by the coordinating Codex agent, with one GPT-6 Astra subagent at ultra reasoning effort for the isolated reconciliation task. The coordinator reviewed all corrections and independently ran the final 396-case focused regression and repository checks. Read-only agents checked source provenance and the reconciliation boundary.

frf12 added 28 commits October 6, 2026 05:49
Exclude detailed design documents from the PR while keeping local copies.
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

frf12 added 10 commits October 9, 2026 16:12
Bind Atomic current and exact Artifact GET reads to the domain read snapshot. Pin SQLite content before external policy decisions. Adapt current published Artifact evidence from f483d8a while retaining exact durable lineage. Balance lexical term sums in search and recovery probes without truncating terms.
Preserve Atomic Memory retrieval and evidence while adopting registered evaluation scopes and relocated LoCoMo suites. Adapt the new persisted-scope regressions to Atomic records.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant