Skip to content

docs: complete bilingual memory lifecycle RFC - #3

Closed
larry-zy wants to merge 157 commits into
jiannnnyyyyy:docs/memory-quality-lifecycle-rfcfrom
larry-zy:fix/pr1652-memory-lifecycle
Closed

larry-zy wants to merge 157 commits into
jiannnnyyyyy:docs/memory-quality-lifecycle-rfcfrom
larry-zy:fix/pr1652-memory-lifecycle

Conversation

@larry-zy

Copy link
Copy Markdown

Completes the review and CI fixes for oceanbase#1652.\n\n- adds the synchronized Chinese RFC\n- renames both RFC files to the assigned 1652 number\n- fixes local RFC links used by the website build\n- updates merged oceanbase#1586/oceanbase#1596 references to RFC 1557/1560\n- clarifies that entry_content_hash includes kind, text, Source refs, and Artifact refs\n- preserves evidence when normalized text matches but evidence refs differ\n\nValidation:\n- make check\n- make docs-test

Zxf-xufeng and others added 30 commits September 1, 2026 20:58
…ct-rest-api-implementation

# Conflicts:
#	integrations/dsh/plugins/powercontext/lib/index.js
#	integrations/dsh/plugins/powercontext/openapi/powercontext.yaml
#	integrations/dsh/plugins/powercontext/scripts/openapi-ops.mjs
#	integrations/dsh/plugins/powercontext/src/client.ts
#	integrations/dsh/plugins/powercontext/src/operations.generated.ts
#	integrations/dsh/plugins/powercontext/tests/client.spec.ts
#	integrations/dsh/plugins/powercontext/tests/operations-coverage.spec.ts
#	integrations/opencode/plugins/powercontext/lib/index.js
#	integrations/opencode/plugins/powercontext/src/client.ts
#	integrations/opencode/plugins/powercontext/src/operations.generated.ts
#	integrations/pi/plugins/powercontext/src/client.ts
#	integrations/pi/plugins/powercontext/src/operations.generated.ts
#	openapi/powercontext.yaml
#	scripts/generate_api.py
#	scripts/generate_js_operations.py
#	src/powercontext/builtin/runtime/application.py
#	src/powercontext/builtin/runtime/relational.py
#	src/powercontext/client/client.py
#	src/powercontext/http/__init__.py
#	src/powercontext/http/_generated/operations.py
#	src/powercontext/server/app.py
#	tests/e2e/test_builtin_runtime.py
#	tests/test_api_contract.py
#	tests/test_client.py
#	tests/test_js_operations.py
…ct-rest-api-docs

# Conflicts:
#	zensical.toml
* fix: env file parser

Signed-off-by: thunguo <tew@apache.org>

* perf(cli): scan multiline env values incrementally

* test(cli): decouple multiline env fixture

---------

Signed-off-by: thunguo <tew@apache.org>
knqiufan and others added 26 commits September 16, 2026 09:47
…tions/actions/configure-pages-6.0.0

build(deps): bump actions/configure-pages from 5.0.0 to 6.0.0
…tions/apache/skywalking-eyes/header-0.9.0

build(deps): bump apache/skywalking-eyes/header from 0.8.0 to 0.9.0
* feat(pi): add external skill tools

* fix(pi): defer full profile promotion
* feat(pi): add artifact candidate review tools

* fix(pi): align candidate review schemas

* fix(pi): close candidate review schemas

* fix(pi): expose revision schema as object
…#1622)

* feat(integrations): add layered PowerContext Skill routing

* test(openclaw): build runtime before native Skill discovery

* test(integrations): reject nested Handoff carriers in evaluation

* fix(integrations): unify Skill entries and validate domain reads

* fix(integrations): align Handoff workflows and preview boundaries

* fix(hermes): expose native Skill discovery metadata

* docs(pi): align guidance with candidate review capabilities
* feat(pi): add experience and skill generation tools

* fix(pi): preserve generation schema and handle timeouts
* feat(pi): add memory changes and stats tools

* fix(pi): preserve nullable memory change cursors
* docs(rfc): design topic memory generic API completion

* docs(rfc): add English topic memory API design

* docs(rfc): clarify topic memory tag schema migration

* docs(rfc): define empty lexical projection behavior
…Codex (oceanbase#1580)

* fix(integrations): honor approved transport, status classes, and hook budgets

fix(opencode): pass the approved insecure-HTTP consent into the TUI client
fix(opencode): stop status polling and in-flight requests when the view unmounts
fix(opencode): keep auth, version, unavailable, and invalid outcomes distinct in the statusline
fix(opencode): reject a statistics response without required totals instead of showing no data
fix(claude-code): reject a statistics response without required totals instead of showing no data
fix(codex): keep the Stop hook HTTP budget below the 3-second host deadline

fix(integrations): harden scope binding and status diagnostics

fix(claude-code): resolve the effective Server URL before loading persisted authorization
fix(claude-code): classify statusline failures into typed diagnostics
fix(claude-code): bound Scope response reads and git identity by the absolute HTTP budget
fix(codex): reject malformed stats responses instead of reporting no data
fix(codex): bound Scope response reads by the absolute HTTP budget
fix(opencode): omit empty session and workspace binding keys on non-session routes

fix(integrations): report token savings through the stats contract

fix(codex): POST /v1/stats with a Scope selection instead of the unsupported GET query
fix(codex): classify Stop-hook failures into typed diagnostics with cross-invocation dedup
fix(codex): classify Scope binding transport, auth, and HTTP status failures
fix(claude-code): send the same stats contract and bound both windows by one absolute HTTP budget
fix(opencode): resolve TUI statusline and /pc Scope through server-side Scope bindings
fix(opencode): accept JSONC TUI config and validate it before replacing any installed file

feat(codex): report token savings after turns

feat(claude-code): show token savings statusline

fix(opencode): color token savings by outcome

feat(opencode): show daily and 30d token savings

fix(opencode): rename statusline metric to compression proxy

chore(opencode): sync tui type declarations

fix(opencode): clarify statusline wording

fix(opencode): bound statusline refresh with timeouts

feat(opencode): expand PowerContext statusline

fix(opencode): load token statusline in TUI

feat(opencode): show token savings in statusline

fix(opencode): register TUI plugin during setup

feat(opencode): add PowerContext TUI command

* fix(integrations): harden statusline budgets, scope aborts, and install hygiene

fix(opencode): stop accumulating stale tui.json entries, preserve JSONC comments, tolerate malformed entries, and drop the duplicate Skill install

fix(claude-code): canonicalize Server URLs before matching persisted authorization, tighten statusline ownership, honor per-request Scope timeouts, and bound request opens by wall clock

fix(codex): honor per-request Scope timeouts and bound request opens by wall clock

fix(opencode-tui): abort in-flight Scope resolution on unmount, keep invalid responses distinct from offline, trim resolved Scope IDs, and avoid cleaning the shared lib output

Align compact token formatting between Python and JavaScript, refresh generated lib bundles, and extend regression coverage for budgets, classification, and install hygiene.

* fix(integrations): refresh the Claude plugin cache and bound chunked reads

fix(claude-code): bump the plugin and marketplace manifests to 0.1.2, refresh an existing marketplace and plugin before configuring the status line, and bind every response read to the absolute deadline

fix(codex): bind every response read to the absolute deadline

Add slow chunked-extension drip regression tests for the Claude status line and the Codex Stop hook, update the version contract and setup refresh coverage, and align the Claude Code integration docs.

* fix(integrations): address PR 1580 review follow-ups

* test(opencode): cover TUI file URI parsing
* feat(topic-memory): complete generic Artifact APIs

* fix(topic-memory): allow empty analyzer output

* fix(topic-memory): attribute indexing usage by scope

* fix(topic-memory): isolate usage recording failures

* fix(persistence): make legacy tag upgrades retryable
* fix(service): decode Windows native command output with the OEM code page

icacls, whoami, and schtasks output was captured with text=True and no
explicit encoding. In a no-window process under Python UTF-8 mode the console
reports the OEM code page, strict UTF-8 decoding fails inside the subprocess
reader thread, and the caller silently receives returncode == 0 with stdout
set to None. Protected environment-file validation then crashed with an
AttributeError instead of raising a domain error, and ACL checks could be
skipped.

Route all three commands through run_windows_command, which forces
CREATE_NO_WINDOW so the child always uses the system OEM code page, captures
bytes, and decodes on the calling thread so decoding failures surface as
SubprocessError and are reported as ServiceError or
ProtectedEnvironmentFileError.

Fixes oceanbase#1627

* fix(service): address review findings on Windows command decoding

run_windows_command now treats LookupError as a command failure, so a call
from a non-Windows path reports the missing OEM codec through SubprocessError
instead of escaping the caller except clause.

test_windows_support_preserves_native_command_error mocked every
subprocess.run call, so _user_identity failed at whoami and support() never
reached the scheduler query; the assertion passed for the wrong reason. The
mock now dispatches on the executable and the test asserts the Task Scheduler
wording, so it exercises the schtasks decoding path it names.

test_service_install_cli_expands_the_environment_file_home_directory set
HOME, which Windows expanduser ignores in favour of USERPROFILE. Setting both
makes the test pass on Windows; it failed on ee5c076 as well.

Refs oceanbase#1627

* ci(windows): run the service command encoding regressions on Windows

The six encoding cases added alongside run_windows_command are guarded by
skipif(os.name != "nt"). The full suite runs on Linux, which collected and
skipped them, and neither Windows job listed these files, so no job
exercised the regressions the previous two commits added.

Add tests/test_service.py and tests/test_service_environment.py to the
windows-unit-portability job, the Windows Python unit test job. Verified
locally on Windows that all six cases execute rather than skip.

Refs oceanbase#1627

* test(service): own the Windows env-file fixtures before locking their ACL

The windows-unit-portability job failed 13 cases in tests/test_service.py and
tests/test_service_environment.py: load_protected_environment_file rejected
every fixture with "--env-file must be owned by the current user". Hosted
Windows runners execute jobs under an elevated token whose default owner is
the Administrators group, so a file pytest creates is owned by that group
rather than by the account itself, and the loader's owner check refuses it.
The failures masked the ACL and encoding assertions that follow.

Set the owner to the current account before restricting the ACL, matching
_environment_file in tests/native/test_personal_service_lifecycle.py, which
already carries this call for the same reason. The two unit fixtures were
written alongside it but never ran on Windows CI until now, so they missed it.

Refs oceanbase#1627

* test(service): pin the contract that native command output is never dropped

The six Windows encoding cases run in CI now, but none of them fails against
the pre-fix capture. Hosted runners report an OEM code page of 437, where
icacls writes the fixture's non-ASCII path as question marks and every byte
decodes, so text=True would have produced the same green result. The one case
that does force a decode failure skips on 437 for the same reason.

Drive run_windows_command with a child process that writes 0x81, which is
undefined in the ANSI code page an English console reports and an incomplete
lead byte in a DBCS one. The pre-fix capture therefore loses it on either,
leaving returncode 0 with stdout as None, while the OEM decode either succeeds
or raises. Asserting that the caller sees a string or a reported failure holds
on any code page, so the case needs no skip and turns red on a revert.

Refs oceanbase#1627
* feat(pi): promote integration to Full profile

* style: apply manifest test formatting
…d adapter conformance suite (oceanbase#1483)

* feat(authz): shared filter derivation and snapshot decision boundary

- extract resolve_resource_filter derivation shared by both providers
  (fixes latent parent-type drift between the builtin and Casbin copies)
- add RelationalAccessRepository.decision_snapshot: revision, active
  bindings and ownership read in one transaction; providers use it when
  offered, else bounded revision-check-and-retry, failing closed when no
  stable read is obtained (AccessRepository protocol unchanged)
- one captured evaluation time per decision for all expiry comparisons
- conformance suite: deliberately-interleaving regression for the
  read-consistency gap, single-transaction pin, fail-closed on unstable
  revision, point/list agreement and cross-provider filter parity,
  idempotency ledger conflicts across operations and payloads
- no persistent Casbin policy store added (rationale in PR)

* Fix type errors in snapshot-boundary tests and decision snapshot row annotations

* Annotate decision_snapshot row buffers as Sequence[Mapping[str, Any]] so
  SQLAlchemy Mapping results type-check.
* Make the test doubles nominal subtypes (AsyncDatabase /
  RelationalAccessRepository) instead of duck-typed wrappers, and hide the
  decision_snapshot capability via __getattribute__ so the bounded-retry
  path stays exercised.
* Assert policy revision is not None before int() conversion.

* Use Mapping[Any, Any] row annotations so ty accepts SQLAlchemy mappings

ty infers RowMapping keys as a union type and Mapping is invariant in its
key type, so Sequence[Mapping[str, Any]] rejects the rows returned by
mappings().all(). Mapping[Any, Any] is accepted by both ty and pyright.

* fix(authz): pin the decision read snapshot, fail closed when it moves

sqlite3's legacy transaction control does not BEGIN for a bare SELECT, so
the transaction decision_snapshot reads through was not a snapshot: a commit
landing between the revision read and the bindings read produced a decision
labelled with the pre-commit revision but built from post-commit bindings.
read_decision_state also delegated on the mere presence of decision_snapshot,
leaving the revision-check-and-retry fallback unreachable.

- _pin_read_snapshot issues SAVEPOINT rather than BEGIN, so it composes with
  a caller-owned transaction instead of raising.
- decision_snapshot re-reads the revision before releasing the snapshot and
  raises policy-snapshot-unstable instead of returning the mixture;
  read_decision_state retries within its existing budget. A READ COMMITTED
  profile therefore fails closed rather than returning a stale label.
- Adds a two-connection interleaving regression against the real snapshot
  path, and a fail-closed case for a profile that cannot pin isolation.

Reported by @Teingi in review.

* fix(authz): type the snapshot seams and patch them where they are read

The `quality` job failed on `ty check` with three `invalid-assignment`
diagnostics: the interleaving tests rebound `_read_policy_revision` and
`_pin_read_snapshot` on the *module*, while the attribute being assigned to is
a module-level function whose declared signature the local replacement did not
match (a different parameter name, and a body that ignores it).

That was a symptom of the real problem: the tests were patching a seam the
reader does not go through. `decision_snapshot` called the module functions
directly, so a test could intercept them without the interception being tied to
the code path under test.

- Promote both helpers to overridable methods on `RelationalAccessRepository`
  and call them via `self` from `decision_snapshot`. The module functions stay
  as the default implementations; the seam is now the instance the reader
  actually goes through.
- Patch that seam with `patch.object` in the two interleaving tests, and drop
  the module attribute rebinding plus the now-unused `authz_repository` import.

`uv run ty check` no longer reports any diagnostic in
`tests/test_access_snapshot_boundary.py`; the remaining baseline diagnostics are
unchanged (`Found 9` vs `Found 12` before, none in a file this PR touches).
`ruff check` / `ruff format --check` clean.

---------

Co-authored-by: SanJiu <tlyyxjz@users.noreply.github.com>
* fix(codex): verify native MCP authentication on Windows

* fix(codex): address native MCP auth review

* fix(codex): validate native MCP bearer header

* fix(codex): accept case-insensitive bearer scheme
…ceanbase#1630)

* feat(dashboard): add profile reading and exact handoff export

* fix(dashboard): preserve reading text and theme recovery

* fix(dashboard): preserve indented code in markdown export

* fix(dashboard): preserve multiline indented handoff text

* fix(dashboard): escape equals lines in handoff export

* fix(dashboard): preserve evidence login return
…base#1629)

* docs(rfc): design profile dashboard and exact handoff export

* docs(rfc): assign RFC 1629 and clarify singleton selection

* docs(rfc): remove UI mockup images
oceanbase#1586)

* feat: record recurring failures and gate their repair (oceanbase#1557)

Add failure signatures, append-only recurrence observations, runtime ledger orchestration, persistence, statistics, API contract updates, and the related documentation and tests. Keep recurrence evidence write-only on the outcome path and expose the required ScopeStats.recurrence block.

Constraint: ScopeStats.recurrence is a required breaking API field; Windows-only baseline failures and seven pre-existing ty diagnostics remain outside this change.

Tested: 109 focused tests; 48 contract tests; 26 integration-manifest tests; ruff check and format check; generated schema and enabled server OpenAPI match.

Not-tested: make check remains non-zero only because of the seven baseline ty diagnostics; full unit test comparison is 2252 passed, 58 skipped, 47 failed on the implementation tree versus 2177 passed, 58 skipped, 46 failed on clean baseline.

Co-authored-by: OmX <omx@oh-my-codex.dev>
Signed-off-by: Xin.Zh <alexstocks@foxmail.com>

* fix: align CI checks with recurring failure API

Ignore Mermaid diagrams in license-eye because the checker cannot determine their comment style, and update the existing base-access E2E assertion for the optional Experience failure field.

Constraint: Preserve the required ScopeStats.recurrence and ExperienceProposal.failure contract without weakening validation.

Tested: targeted base-access E2E test and API contract/JS tests pass; Ruff check and format check pass; licenserc parses as YAML.

Co-authored-by: OmX <omx@oh-my-codex.dev>
Signed-off-by: Xin.Zh <alexstocks@foxmail.com>

* fix: harden recurring failure evidence and replay

* fix: reject unresolved handoff revisions

* fix: preserve complete recurrence candidate snapshots

Lore: A scope-head match must use every active Experience head because its persisted candidate snapshot is evidence for an immutable recurrence decision.

Constraint: Keep the independent 64-entry statistics Handoff scan unchanged; this only removes undocumented ledger candidate truncation.

Tested: 78 focused recurrence tests and 48 API contract tests pass; Ruff, targeted ty, and git diff checks pass.

Not-tested: Full Windows prek remains blocked by nine pre-existing artifact-processing and os.WNOHANG ty diagnostics outside this change.

Co-authored-by: OmX <omx@oh-my-codex.dev>

* fix(runtime): keep recurrence ledger evidence transactional

Lore: SQLite savepoints can commit independently when no real outer BEGIN exists, and recurrence verdicts must be backed by resolvable nested evidence.
Constraint: Ledger append savepoints must roll back with the incubation transaction, and terminal recurred/avoided verdicts must not be written when their TaskOutcome item evidence cannot be resolved in the current scope.
Tested: uv run pytest -q tests/builtin/persistence/test_recurrence_repository.py tests/builtin/runtime/test_recurrence_ledger.py tests/e2e/test_recurring_failure_repair.py
Tested: uv run ruff check src/powercontext/builtin/persistence/recurrence.py src/powercontext/builtin/runtime/recurrence.py src/powercontext/builtin/runtime/relational.py tests/builtin/persistence/test_recurrence_repository.py tests/builtin/runtime/test_recurrence_ledger.py tests/e2e/test_recurring_failure_repair.py
Tested: uv run ruff format --check src/powercontext/builtin/persistence/recurrence.py src/powercontext/builtin/runtime/recurrence.py src/powercontext/builtin/runtime/relational.py tests/builtin/persistence/test_recurrence_repository.py tests/builtin/runtime/test_recurrence_ledger.py tests/e2e/test_recurring_failure_repair.py
Tested: uv run ty check src/powercontext/builtin/persistence/recurrence.py src/powercontext/builtin/runtime/recurrence.py src/powercontext/builtin/runtime/relational.py tests/builtin/persistence/test_recurrence_repository.py tests/builtin/runtime/test_recurrence_ledger.py tests/e2e/test_recurring_failure_repair.py
Co-authored-by: OmX <omx@oh-my-codex.dev>

---------

Signed-off-by: Xin.Zh <alexstocks@foxmail.com>
Co-authored-by: OmX <omx@oh-my-codex.dev>
…xt (oceanbase#1596)

* feat(runtime): add bounded recall sufficiency gate

Adds a model-free pre-render sufficiency gate that runs at most two bounded expansion rounds whose only action is lowering the fusion admission floor. It is disabled by default and byte-identical when off, and ships no HTTP, contract or write-path changes.

* wip: RFC 1560 observability increment (T01-T03 partial, not green)

Intermediate checkpoint of the second increment for RFC 1560
recall_sufficiency_gate: the observability and cost-accounting surface.
Committed on a WIP branch so PR oceanbase#1596 (branch feat/recall-gate-impl,
14cbabf) stays at its submitted, green state.

Design: .workbuddy/artifacts/rfc1560-observability-design.md
Rulings: .workbuddy/artifacts/rfc1560-decisions.md (section 三·补二)

Done: AdmissionCounts in artifacts/search.py; RecallBudgetView and the
budget probe (PreparedContextBuilder.probe_budget); RecallEffort reshaped
to the RFC's fields (assessment, expansion_actions, rounds = 1 + len(...),
admission_by_family, added_embeddings, added_generation_calls, and the
dropped sub-counts); omissions sub-counts through _fit_entry, _fit_entries,
_build_text and the assembly path; ExperienceSearchOutcome and
TopicMemoryFusionOutcome; per-family retrieved/admitted counters for all
three searchable families; the query_embedding reuse parameter on
MemoryService.search; SearchPlan.rerank_candidate_limit and
RecallSufficiencyPolicy.round2_rerank_candidate_limit removed per the RFC.

NOT done (T04): RecallEffortSink, the _prepare_build -> (build, effort)
tuple, removal of PreparedContextBuild.recall_effort, the context.build
aggregate counters, and the e2e test updates that depend on them.

KNOWN RED: tests/e2e/test_recall_sufficiency_gate.py still reads
build.recall_effort and the old rounds/gate_reason semantics, so it has
not been adapted and will fail until T04 lands.

* feat(runtime): expose recall gate effort through a sink

* fix(runtime): address recall gate review feedback

Lore: Preserve public recall search contracts and make bounded expansion fail open without evicting round-zero candidates.

Constraint: Keep the fix scoped to Copilot's PR oceanbase#1596 recall-gate feedback; leave unrelated artifact_processing ty diagnostics untouched.

Tested: uv run pytest tests/builtin/artifacts/topic_memory/test_fusion.py tests/builtin/persistence/test_topic_memory.py::test_topic_memory_search_threads_lowered_fts_floor_into_the_backend tests/builtin/persistence/test_experience_index.py tests/builtin/test_publication.py::test_published_experience_is_searchable_in_target_scope_immediately; uv run pytest tests/builtin/runtime/test_recall_sufficiency.py tests/builtin/runtime/test_prepared_context.py::test_expanded_memory_cap_preserves_the_round_zero_prefix tests/builtin/runtime/test_prepared_context.py::test_expanded_experience_cap_preserves_the_round_zero_prefix tests/builtin/runtime/test_prepared_context.py::test_probe_budget_is_budget_bound_at_the_byte_floor tests/builtin/runtime/test_prepared_context.py::test_probe_budget_is_budget_bound_when_the_fit_drops_items_and_leaves_no_headroom; uv run pytest tests/e2e/test_recall_sufficiency_gate.py; uv run prek run ruff-check -a; uv run prek run ruff-format -a; git diff --check.

Not-tested: uv run ty check and uv run prek run -a remain blocked by pre-existing artifact_processing.py and Windows os.WNOHANG ty diagnostics unrelated to this change.

Co-authored-by: OmX <omx@oh-my-codex.dev>

* test: align OceanBase FTS assertions with fusion admission

Lore: FTS indexes must return match candidates so the fusion layer can account for retrieved and admitted Topic Memory results.

Constraint: Keep coverage admission out of backend SQL; preserve the public index and query-channel assertions.

Tested: OceanBase Topic Memory tests 4 passed, 1 skipped; recall gate and Topic Memory suites 160 passed; Ruff and targeted ty pass.

Not-tested: Live OceanBase remains skipped without POWERCONTEXT_TEST_OCEANBASE_URL.

Co-authored-by: OmX <omx@oh-my-codex.dev>

* fix(runtime): avoid unrecoverable recall expansions

Lore: Keep Topic Memory admission accounting separate from backend pool sizing, and keep recall expansion tied to candidates that a lower floor can actually recover.

Constraint: Preserve the public Topic Memory search limit and disabled-by-default recall gate behavior; only widen the internal per-channel candidate pool and stop redundant expansion when round zero fully admitted the retrieved family.

Tested: uv run pytest -q tests/builtin/persistence/test_topic_memory.py tests/builtin/persistence/test_topic_memory_oceanbase.py tests/builtin/artifacts/topic_memory/test_fusion.py tests/builtin/runtime/test_recall_sufficiency.py tests/builtin/runtime/test_prepared_context.py tests/e2e/test_recall_sufficiency_gate.py; uv run ruff check targeted changed files; uv run ruff format --check targeted changed files; uv run ty check targeted changed files; git diff --check.

Co-authored-by: OmX <omx@oh-my-codex.dev>

* test: align topic memory request bounds with internal pool

Lore: Topic Memory public search limits now live at the repository/API boundary, while request candidate limits describe the internal channel pool used before fusion admission.

Constraint: Preserve the public 20-hit search contract; this only updates the model-layer test to assert the internal candidate bound.

Tested: uv run pytest -q tests/builtin/artifacts/topic_memory/test_models.py::test_topic_memory_search_request_enforces_query_and_internal_candidate_bounds

Tested: uv run pytest -q tests/builtin/artifacts/topic_memory/test_models.py tests/builtin/persistence/test_topic_memory.py tests/builtin/persistence/test_topic_memory_oceanbase.py tests/builtin/artifacts/topic_memory/test_fusion.py tests/builtin/runtime/test_recall_sufficiency.py tests/builtin/runtime/test_prepared_context.py tests/e2e/test_recall_sufficiency_gate.py

Tested: uv run ruff check src/powercontext/builtin/artifacts/topic_memory/__init__.py src/powercontext/builtin/artifacts/topic_memory/models.py src/powercontext/builtin/persistence/topic_memory.py src/powercontext/builtin/persistence/sqlite/topic_memory_index.py src/powercontext/builtin/runtime/application.py src/powercontext/builtin/runtime/recall_sufficiency.py tests/builtin/artifacts/topic_memory/test_models.py tests/builtin/persistence/test_topic_memory.py tests/builtin/runtime/test_recall_sufficiency.py tests/e2e/test_recall_sufficiency_gate.py

Tested: uv run ruff format --check src/powercontext/builtin/artifacts/topic_memory/__init__.py src/powercontext/builtin/artifacts/topic_memory/models.py src/powercontext/builtin/persistence/topic_memory.py src/powercontext/builtin/persistence/sqlite/topic_memory_index.py src/powercontext/builtin/runtime/application.py src/powercontext/builtin/runtime/recall_sufficiency.py tests/builtin/artifacts/topic_memory/test_models.py tests/builtin/persistence/test_topic_memory.py tests/builtin/runtime/test_recall_sufficiency.py tests/e2e/test_recall_sufficiency_gate.py

Tested: uv run ty check src/powercontext/builtin/artifacts/topic_memory/__init__.py src/powercontext/builtin/artifacts/topic_memory/models.py src/powercontext/builtin/persistence/topic_memory.py src/powercontext/builtin/persistence/sqlite/topic_memory_index.py src/powercontext/builtin/runtime/application.py src/powercontext/builtin/runtime/recall_sufficiency.py tests/builtin/artifacts/topic_memory/test_models.py tests/builtin/persistence/test_topic_memory.py tests/builtin/runtime/test_recall_sufficiency.py tests/e2e/test_recall_sufficiency_gate.py

Tested: git diff --check

Co-authored-by: OmX <omx@oh-my-codex.dev>

* fix(runtime): stop unrecoverable recall retries

Lore: Recall expansion should only continue while the latest round shows candidates that lowering the floor can still recover. Topic Memory default search also needs to preserve eligible FTS candidates before truncating the internal pool.

Constraint: Preserve the public Topic Memory search limit and existing exported fusion helper contract; keep admission counts as aggregate in-process metadata only.

Tested: uv run pytest -q tests/builtin/persistence/test_topic_memory.py::test_default_topic_memory_search_preserves_eligible_candidates_before_truncating_the_pool tests/e2e/test_recall_sufficiency_gate.py::test_recoverability_is_refreshed_after_an_expansion_round

Tested: uv run pytest -q tests/builtin/persistence/test_topic_memory.py tests/builtin/persistence/test_topic_memory_oceanbase.py tests/builtin/artifacts/topic_memory/test_fusion.py tests/builtin/runtime/test_recall_sufficiency.py tests/builtin/runtime/test_prepared_context.py tests/e2e/test_recall_sufficiency_gate.py

Tested: uv run pytest -q tests/builtin/artifacts/topic_memory/test_models.py tests/builtin/artifacts/topic_memory/test_fusion.py tests/builtin/persistence/test_topic_memory.py tests/builtin/persistence/test_topic_memory_oceanbase.py tests/e2e/test_recall_sufficiency_gate.py

Tested: uv run ruff check src/powercontext/builtin/artifacts/topic_memory/models.py src/powercontext/builtin/artifacts/topic_memory/fusion.py src/powercontext/builtin/persistence/sqlite/topic_memory_index.py src/powercontext/builtin/persistence/oceanbase/topic_memory_index.py src/powercontext/builtin/persistence/topic_memory_index.py src/powercontext/builtin/runtime/application.py tests/builtin/persistence/test_topic_memory.py tests/builtin/persistence/test_topic_memory_oceanbase.py tests/e2e/test_recall_sufficiency_gate.py

Tested: uv run ruff format --check src/powercontext/builtin/artifacts/topic_memory/models.py src/powercontext/builtin/artifacts/topic_memory/fusion.py src/powercontext/builtin/persistence/sqlite/topic_memory_index.py src/powercontext/builtin/persistence/oceanbase/topic_memory_index.py src/powercontext/builtin/persistence/topic_memory_index.py src/powercontext/builtin/runtime/application.py tests/builtin/persistence/test_topic_memory.py tests/builtin/persistence/test_topic_memory_oceanbase.py tests/e2e/test_recall_sufficiency_gate.py

Tested: uv run ty check src/powercontext/builtin/artifacts/topic_memory/models.py src/powercontext/builtin/artifacts/topic_memory/fusion.py src/powercontext/builtin/persistence/sqlite/topic_memory_index.py src/powercontext/builtin/persistence/oceanbase/topic_memory_index.py src/powercontext/builtin/persistence/topic_memory_index.py src/powercontext/builtin/runtime/application.py tests/builtin/persistence/test_topic_memory.py tests/builtin/persistence/test_topic_memory_oceanbase.py tests/e2e/test_recall_sufficiency_gate.py

Tested: git diff --check

Co-authored-by: OmX <omx@oh-my-codex.dev>

* fix(runtime): separate topic admission rejection counts

Lore: Topic Memory recall traces can keep pre-admission retrieved counts that exceed the capped candidate pool.
Constraint: Recall expansion recoverability must only count candidates rejected by admission floors, not rows lost to backend candidate caps.
Tested: uv run pytest -q tests/builtin/persistence/test_topic_memory.py tests/builtin/persistence/test_topic_memory_oceanbase.py tests/builtin/artifacts/topic_memory/test_fusion.py tests/builtin/runtime/test_recall_sufficiency.py tests/builtin/runtime/test_prepared_context.py tests/e2e/test_recall_sufficiency_gate.py
Tested: uv run ruff check src/powercontext/builtin/artifacts/search.py src/powercontext/builtin/artifacts/topic_memory/models.py src/powercontext/builtin/artifacts/topic_memory/fusion.py src/powercontext/builtin/persistence/sqlite/topic_memory_index.py src/powercontext/builtin/persistence/oceanbase/topic_memory_index.py src/powercontext/builtin/persistence/topic_memory.py src/powercontext/builtin/persistence/topic_memory_index.py src/powercontext/builtin/runtime/application.py tests/builtin/persistence/test_topic_memory_oceanbase.py tests/builtin/runtime/test_recall_sufficiency.py tests/e2e/test_recall_sufficiency_gate.py
Tested: uv run ruff format --check src/powercontext/builtin/artifacts/search.py src/powercontext/builtin/artifacts/topic_memory/models.py src/powercontext/builtin/artifacts/topic_memory/fusion.py src/powercontext/builtin/persistence/sqlite/topic_memory_index.py src/powercontext/builtin/persistence/oceanbase/topic_memory_index.py src/powercontext/builtin/persistence/topic_memory.py src/powercontext/builtin/persistence/topic_memory_index.py src/powercontext/builtin/runtime/application.py tests/builtin/persistence/test_topic_memory_oceanbase.py tests/builtin/runtime/test_recall_sufficiency.py tests/e2e/test_recall_sufficiency_gate.py
Tested: uv run ty check src/powercontext/builtin/artifacts/search.py src/powercontext/builtin/artifacts/topic_memory/models.py src/powercontext/builtin/artifacts/topic_memory/fusion.py src/powercontext/builtin/persistence/sqlite/topic_memory_index.py src/powercontext/builtin/persistence/oceanbase/topic_memory_index.py src/powercontext/builtin/persistence/topic_memory.py src/powercontext/builtin/persistence/topic_memory_index.py src/powercontext/builtin/runtime/application.py tests/builtin/persistence/test_topic_memory_oceanbase.py tests/builtin/runtime/test_recall_sufficiency.py tests/e2e/test_recall_sufficiency_gate.py
Co-authored-by: OmX <omx@oh-my-codex.dev>

---------

Co-authored-by: OmX <omx@oh-my-codex.dev>
* docs(rfc): propose desktop control center

* docs(rfc): assign desktop proposal number 1455

* docs(rfc): align desktop design with current contracts

* docs(rfc): choose React TypeScript and Vite for desktop

* docs(rfc): focus desktop proposal on user model and contracts

* ci: rerun checks after macOS service startup timeout

* test(native): sample stalled LaunchAgent before cleanup

* ci(macos): compile installed bytecode before service lifecycle
@larry-zy

Copy link
Copy Markdown
Author

Closing and withdrawing this patch.

@larry-zy larry-zy closed this Sep 19, 2026
@larry-zy
larry-zy deleted the fix/pr1652-memory-lifecycle branch September 19, 2026 17:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.