feat(core): Moirai F1 common contracts (judgment, context projection, persona schema, catalog/policy, store) - #14
Conversation
…ion revisions (F1-E1)
…ileRef export (fixup of 4335e94)
…s, assessments and intentions (F1-A2)
…ersona schema test (F1 audit)
…arrel only (F1 audit r2)
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Keep private LIFE dimensions out of derived persona schemas while retaining source ID uniqueness and existing fingerprints. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
Reject invalid source IDs, duplicate provenance, malformed instruction hashes and blank working items. Reject instruction revision overflow while preserving valid maximum revisions. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
Bind option keys to execution semantics and scope. Freeze policy identity with snapshots, reject stale objectives and foreign candidates, verify stored snapshot digests, bound neural bias and require original acceptance on resume. Normalize geometric rank weights without underflow. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
Model process-exit collection before replacement fleet storage validation. Force the delayed SQLite collection point in the real HTTP reopen test while preserving the private-copy audit and all approval assertions. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
Prepare 256 real immutable archives with a durable manifest, exercise the 257th lifecycle normally, and retain every reopen/replay assertion. A temporary conversation-cap mutation fails at the boundary. Production durability and test timeouts remain unchanged. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
Reject altered order, stance vocabulary, ratio or bias strength under personal.v1 revision one while accepting equivalent deserialized declarations. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
Use the shared identifier validator in projection construction and restoration, rejecting embedded NUL and oversized IDs consistently. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
Compare normalized objective, assessment, resolution, selection and intention records with their persisted digests before returning them or deriving writes. Cover valid JSON tampering, digest-column tampering, rollback and normalized reopen behavior using real SQLite. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
Reject noncanonical, local, and impossible intention dates without rewriting digest-bearing evidence. Preserve exact UTC timestamps across acceptance, deadlines, and transitions. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
Require owner-verified commitment attribution and Host eligibility for factual exclusions. Declare exact assessment unavailability, replay frozen evidence, and reject stale objective/intention snapshots or backward scope sequences. Verified the isolated staged tree: 506 judgment tests pass and the public core barrel builds. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
Add versioned dialogue synthesis and immutable judgment references without action candidates or selection specifications. Preserve exact action-v1 records and apply mode-aware provenance checks on writes and historical restore. Verified 535 judgment tests, strict root/browser TypeScript, public core build, and real SQLite dialogue restoration with zero candidate and selection rows. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
Parse restored intention records before reading status, acceptance, revision, or history. Reject invalid source evidence while preserving valid lifecycle transitions and input immutability. Clarify the retained legacy infeasible receipt stage. Verified four failing-first malformed-source cases, 539 judgment tests, strict TypeScript, and direct public API use. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
Allow incomplete dialogue to persist as deferred after budget exhaustion while still rejecting resolved incomplete records. Freeze only one revision per logical source kind and ID. Verified RED-to-GREEN boundary cases, 541 judgment tests, strict TypeScript, and real SQLite deferred/reopen and contradictory-source rejection. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
Reject intention transitions before acceptance or prior history while permitting equal timestamps. Bound raw option strings before normalization and omission, preserving bounded empty arguments. Verified 12 failing-first boundary cases, 556 judgment tests, strict TypeScript, and actual SQLite chronology/argument scenarios. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
Use unchanged real prompt and preset bytes without unrelated shipped-avatar assets in the personal-growth restart fixture. Preserve all three real restarts and existing assertions, and verify no avatar import or unintended provider/conversation work. Removes repeated avatar migration I/O without increasing test timeouts. Verified 48 related tests, strict TypeScript, runtime build, and independent Fleet restart surface. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
Reject reuse of one immutable objective profile revision across module slots in snapshots and selection specs, including conflicting digests. Preserve distinct stored revisions of a shared objective ID. Verified failing-first parser and direct arbitration cases, 563 judgment tests, strict TypeScript, and actual SQLite persistence/reopen. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
Reject live cancellation of adopted, active and suspended user commitments while F1 lacks intention-bound owner-verified authority. Acceptance refs, ranked candidates and caller-claimed approval fields do not grant cancellation permission. Preserve historical schema-v1 ledgers, proposed withdrawal and other lifecycle paths. Verified failing-first helper/store cases, 583 judgment tests, strict types, runtime build and actual SQLite mutation/reopen scenarios. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
Reject an activation whose resulting references would restore a stale scoped open snapshot. Preserve no-ops, forward revisions, isolated scopes and replay of closed rounds without changing serialized contracts. Verified four failing-first ABA cases, 590 judgment tests, strict TypeScript, build/lint and an actual reopened SQLite round that rejects stale work and resolves fresh objective inputs. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
💡 Codex Reviewlina/packages/lina-core/src/agents/judgment-store.ts Lines 75 to 77 in 0785eda In the action-v1 AGENTS.md reference: AGENTS.md:L4-L4 ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Freeze Host source fingerprints in the snapshot before assessment and require dialogue records and references to match them. Reject invented or rehashed provenance while preserving action-v1 snapshots without the optional field. Verified six failing-first provenance cases, 606 judgment tests, 4526 full-suite passes, clean source/test LSP diagnostics, strict types, build/lint and real DurableStore-to-JudgmentStore persistence/reopen with complete cleanup. Ultraworked with [omo](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: sisyphus-dev-ai <sisyphus-dev-ai@users.noreply.github.com>
💡 Codex ReviewWhen a module produces an opinion longer than 1,000 UTF-16 characters, this default AGENTS.md reference: AGENTS.md:L4-L4 lina/packages/lina-core/src/agents/judgment-store.ts Lines 75 to 77 in ff241e6 For an action round whose deadline or evaluation budget expires before the candidate set or all three assessments are available, this branch accepts only AGENTS.md reference: AGENTS.md:L4-L4 lina/packages/lina-core/src/agents/persona-schema.ts Lines 283 to 286 in ff241e6 When a non-null identity snapshot contains policies only for other agents, this helper silently returns AGENTS.md reference: AGENTS.md:L4-L4 ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Summary
This PR defines the Moirai F1 common contracts in
lina-core: judgment records and validation, context read projections, PersonaSchema derivation, the personal option catalog and arbitration policy, and an independent SQLite judgment ledger.It is not an installed Moirai runtime or live-model qualification. The PR also contains separately scoped runtime test-fixture corrections; they are not evidence of F2 product integration.
Contract scope
Review resolution
The current review pass verifies prior fixes and addresses the remaining defects with failing-first regressions:
insufficient_evidenceis the initial declared unavailability code. Arbitrary reason text cannot remove an objective from ordering; detailed diagnosis remains in existing text/evidence fields.infeasiblelabel is not a hard veto. Factual prerequisite failures use Host eligibility.DialogueJudgmentRef. It preserves the three original assessments, frozen objective/snapshot/policy references and textual synthesis. Store write and reopen validation reject action candidates/specifications on dialogue and incomplete or mismatched provenance.dialogueSourcefrozen by the Host in the round snapshot before assessment. Invented or rehashed record digests, and dialogue without those expected fingerprints, are rejected. Source owners retain the raw data; legacy action snapshots omit the optional field unchanged.heldor enddeferredafter budget exhaustion, but cannot be recorded asresolvedor produce an accepted-dialogue reference.Deliberate F1 boundaries
node:sqlitedefers native statement cleanup until collection; in-process test replacement therefore clears the old connection before the private-copy audit. The call-through close spy triggers that audit boundary deterministically. An independent cold child-process exit and fresh protected HTTP read succeeds without GC or a close spy. This does not establish in-process hot-replacement support, and no production GC or relaxed file-audit check is introduced.Phase authority: implementation roadmap and judgment contract.
Verification
bun testatff241e6: 4526 passed, 47 existing opt-in skips, 0 failed, 556 files. No skip was added by this review pass.bun run typecheck: root and browser TypeScript passed.bun run lint: passed. The one new optional-chain warning was fixed; 27 pre-existing warnings remain in untouched files.bun run ci:build: actual runtime assets built and read-only CLI paths smoke passed without creating application state.Review-fix commits:
46b4b77require canonical intention timestamps.7eac3feverify arbitration evidence and currentness.ebd7af9persist candidate-free dialogue judgments.5484813validate source intentions before transitions.fb15519close dialogue and snapshot boundary gaps.ee47070enforce intention chronology and raw argument bounds.be29476isolate Persona restart resources without increasing timeouts.cf3a46ereject cross-module objective aliases.fdce947reject unverified live user cancellation while preserving historical records.0785edaprevent objective reactivation from reviving stale open rounds.ff241e6bind dialogue digests to Host-frozen source provenance.Current-head GitHub results are available on the PR Checks tab.
No PR merge, release, deployment, paid model call or production-data operation is part of this review-resolution pass.