feat(runtime-host): establish canonical Memory authority - #1610

Merged
Astro-Han merged 2 commits into
apache:mainfrom
M4n5ter:feat/runtime-host-canonical-memory-authority
Jul 29, 2026
Merged

feat(runtime-host): establish canonical Memory authority#1610
Astro-Han merged 2 commits into
apache:mainfrom
M4n5ter:feat/runtime-host-canonical-memory-authority

Conversation

@M4n5ter

@M4n5terM4n5ter commented Jul 29, 2026

Copy link
Copy Markdown
Member
English

Summary

This PR establishes the Runtime Host boundary for transparent local Memory:

  • one authenticated, lease-bound writer for MEMORY.md, PENDING.md, and public backup candidates;
  • one CAS-fenced MemoryBundle commit boundary for canonical and pending state;
  • durable, fail-closed transaction recovery;
  • bounded typed memory.query and memory.mutate operations;
  • policy-gated, session-correct prompt projection;
  • bounded upload, connection, drain, and unknown-outcome handling.

This is part of the M3 extraction tracked by #1167 and follows the ownership and lifecycle direction in #853.

Authority and protocol

  • MEMORY.md and PENDING.md form one revisioned bundle, so proposal approval cannot publish only half of its state.
  • Only the first maka-memory metadata comment in a section is authoritative; later metadata comments cannot replace canonical status or scope.
  • Accepted operations enter the Interactive root owner before waiting on the serialized mutation lane.
  • Recovery accepts only the recorded basis or target generation and fails closed on conflicting external state.
  • Post-decision publication uncertainty returns commit_outcome_unknown and requests Host drain.
  • The protocol preserves the 128 KiB document limit through revision-pinned pages and 32 KiB raw chunks rather than oversized transport frames.
  • Backup candidates carry their own revision, and restore checks both the bundle revision and selected candidate revision.
  • Uploads are bound to the Host Epoch and connection, with bounded count, aggregate size, and lifetime.
  • Commit revalidates size, SHA-256, UTF-8, Memory syntax, secret redaction, and the expected revision.

Policy and product boundary

  • Memory reads and prompt projection use the shared policy activation gate.
  • Memory and Runtime Policy mutations share one mutation barrier.
  • Disabled and incognito access fail closed.
  • Session-scoped entries persist their canonical Session identity and are projected only to that Session.
  • Connection teardown, policy changes, abort, and expiry reclaim incomplete uploads.
  • Host drain rejects new work immediately, lets accepted mutations settle, and then reclaims remaining staged uploads.
  • Existing transparent Markdown paths, legacy metadata, default content, safe-mode behavior, backup candidates, and restore history remain supported.

This slice does not switch the production Desktop or TUI owner. Production adapter wiring and removal of embedded writers remain later cutover work. It also does not introduce a generic file, blob, Store, or transaction RPC.

Non-cooperating writers that retain an already-open file descriptor remain outside the Store's concurrency guarantee. Before production activation, raw writers for the same Interactive root must be routed through the Host or removed.

Validation

  • Biome passes for all 37 changed files.
  • Core: 1,193 tests passed.
  • Storage: 803 tests passed; one existing Windows-only test skipped.
  • Runtime Host: 355 tests passed.
  • Desktop: 2,945 tests passed, including console, accessibility, and copy checks.
  • Root typecheck, production build, and git diff --check pass.
简体中文

概要

本 PR 为透明本地 Memory 建立 Runtime Host 边界:

  • MEMORY.mdPENDING.md 与公开 backup candidate 建立唯一、经过认证且受 lease 约束的 writer;
  • 为 canonical 与 pending 状态建立一个受 CAS 约束的 MemoryBundle 提交边界;
  • 提供 durable、fail-closed 的 transaction recovery;
  • 提供有界 typed memory.querymemory.mutate operation;
  • 提供受 policy gate 约束且 session-correct 的 prompt projection;
  • 对 upload、connection、drain 与 unknown outcome 建立有界处理。

本 PR 属于 #1167 追踪的 M3 提取,并遵循 #853 的 ownership 与 lifecycle 方向。

Authority 与协议

  • MEMORY.mdPENDING.md 组成一个 revisioned bundle,proposal approval 不会只发布一半状态。
  • 每个 section 只有第一条 maka-memory metadata comment 具备权威性;后续 metadata comment 不能替换 canonical status 或 scope。
  • 已接纳操作会在等待串行 mutation lane 前进入 Interactive root owner。
  • Recovery 只接受已记录的 basis 或 target generation,并在外部状态冲突时 fail closed。
  • durable decision 之后出现 publication uncertainty 时返回 commit_outcome_unknown,并请求 Host drain。
  • 协议通过绑定 revision 的分页与 32 KiB raw chunk 保留 128 KiB document 上限,避免产生超出 transport 限制的 frame。
  • Backup candidate 带有独立 revision;restore 同时检查 bundle revision 与所选 candidate revision。
  • Upload 绑定 Host Epoch 与 connection,并限制数量、总大小和生命周期。
  • Commit 会重新验证大小、SHA-256、UTF-8、Memory 语法、secret redaction 与 expected revision。

Policy 与产品边界

  • Memory read 与 prompt projection 经过 shared policy activation gate。
  • Memory mutation 与 Runtime Policy mutation 共用一个 mutation barrier。
  • disabled 与 incognito access 均 fail closed。
  • session-scoped entry 持久化 canonical Session identity,并且只向所属 Session 投影。
  • connection teardown、policy change、abort 与 expiry 都会回收未完成的 upload。
  • Host drain 会立即拒绝新工作,等待已接纳 mutation settle,然后回收剩余 staged upload。
  • 继续支持现有透明 Markdown 路径、legacy metadata、默认内容、safe-mode 行为、backup candidate 与 restore history。

本 slice 不切换 production Desktop 或 TUI owner。Production adapter 接线与 embedded writer 删除仍属于后续 cutover。本 PR 也不增加 generic file、blob、Store 或 transaction RPC。

已经持有打开 file descriptor 的非协作 writer 不在 Store 的并发保证内。Production activation 前,同一 Interactive root 下的 raw writer 必须路由到 Host,或被删除。

验证

  • 全部 37 个 changed file 通过 Biome。
  • Core:1,193 项测试通过。
  • Storage:803 项测试通过;另有 1 项既有 Windows-only skip。
  • Runtime Host:355 项测试通过。
  • Desktop:2,945 项测试通过,包括 console、accessibility 与 copy 检查。
  • 根级 typecheck、production build 与 git diff --check 通过。

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. This keeps the production entry points unchanged, reuses the existing root-lease and policy-activation seams, and does not add a generic Store or file RPC. The two-document transaction and chunked upload both follow from concrete product and transport constraints, so I would keep the current boundary.

I found three non-blocking edge cases worth following up:

  • The Markdown parser accepts every maka-memory metadata comment in a section, so a later comment in the content can replace the canonical scope or status. Only the first metadata line should be authoritative.
  • A no-op raw replacement can rewrite a backup without advancing the bundle revision. A client may then restore a different backup from the one it previously queried. Giving each backup candidate a revision and checking it during restore would close that race.
  • beginDrain() clears staged uploads before accepted mutations have finished waiting on the shared lane. A queued replace_commit can therefore return upload_not_found during shutdown. Upload cleanup should wait for accepted operations to settle.

None of these need to block this M3 slice. Each should get a focused regression test before production activation.

@M4n5ter
M4n5terforce-pushed the feat/runtime-host-canonical-memory-authority branch from d332d5b to 0cabf50CompareJuly 29, 2026 15:24
@M4n5ter

Copy link
Copy Markdown
MemberAuthor

Addressed all three follow-up edge cases in 0cabf50ce: first-metadata authority, revision-fenced backup restore, and drain-safe staged uploads. Focused and full affected test suites, typecheck, build, Biome, and diff checks all pass. A maintainer re-review would be appreciated.

@Astro-Han
Astro-Han merged commit 7ee7bc5 into apache:mainJul 29, 2026
3 checks passed
@M4n5ter
M4n5ter deleted the feat/runtime-host-canonical-memory-authority branch July 29, 2026 15:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@M4n5ter@likun666661@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(runtime-host): establish canonical Memory authority - #1610

Merged
Astro-Han merged 2 commits into
apache:mainfrom
M4n5ter:feat/runtime-host-canonical-memory-authority
Jul 29, 2026
Merged

feat(runtime-host): establish canonical Memory authority#1610
Astro-Han merged 2 commits into
apache:mainfrom
M4n5ter:feat/runtime-host-canonical-memory-authority

Conversation

@M4n5ter

@M4n5terM4n5ter commented Jul 29, 2026

Copy link
Copy Markdown
Member
English

Summary

This PR establishes the Runtime Host boundary for transparent local Memory:

  • one authenticated, lease-bound writer for MEMORY.md, PENDING.md, and public backup candidates;
  • one CAS-fenced MemoryBundle commit boundary for canonical and pending state;
  • durable, fail-closed transaction recovery;
  • bounded typed memory.query and memory.mutate operations;
  • policy-gated, session-correct prompt projection;
  • bounded upload, connection, drain, and unknown-outcome handling.

This is part of the M3 extraction tracked by #1167 and follows the ownership and lifecycle direction in #853.

Authority and protocol

  • MEMORY.md and PENDING.md form one revisioned bundle, so proposal approval cannot publish only half of its state.
  • Only the first maka-memory metadata comment in a section is authoritative; later metadata comments cannot replace canonical status or scope.
  • Accepted operations enter the Interactive root owner before waiting on the serialized mutation lane.
  • Recovery accepts only the recorded basis or target generation and fails closed on conflicting external state.
  • Post-decision publication uncertainty returns commit_outcome_unknown and requests Host drain.
  • The protocol preserves the 128 KiB document limit through revision-pinned pages and 32 KiB raw chunks rather than oversized transport frames.
  • Backup candidates carry their own revision, and restore checks both the bundle revision and selected candidate revision.
  • Uploads are bound to the Host Epoch and connection, with bounded count, aggregate size, and lifetime.
  • Commit revalidates size, SHA-256, UTF-8, Memory syntax, secret redaction, and the expected revision.

Policy and product boundary

  • Memory reads and prompt projection use the shared policy activation gate.
  • Memory and Runtime Policy mutations share one mutation barrier.
  • Disabled and incognito access fail closed.
  • Session-scoped entries persist their canonical Session identity and are projected only to that Session.
  • Connection teardown, policy changes, abort, and expiry reclaim incomplete uploads.
  • Host drain rejects new work immediately, lets accepted mutations settle, and then reclaims remaining staged uploads.
  • Existing transparent Markdown paths, legacy metadata, default content, safe-mode behavior, backup candidates, and restore history remain supported.

This slice does not switch the production Desktop or TUI owner. Production adapter wiring and removal of embedded writers remain later cutover work. It also does not introduce a generic file, blob, Store, or transaction RPC.

Non-cooperating writers that retain an already-open file descriptor remain outside the Store's concurrency guarantee. Before production activation, raw writers for the same Interactive root must be routed through the Host or removed.

Validation

  • Biome passes for all 37 changed files.
  • Core: 1,193 tests passed.
  • Storage: 803 tests passed; one existing Windows-only test skipped.
  • Runtime Host: 355 tests passed.
  • Desktop: 2,945 tests passed, including console, accessibility, and copy checks.
  • Root typecheck, production build, and git diff --check pass.
简体中文

概要

本 PR 为透明本地 Memory 建立 Runtime Host 边界:

  • MEMORY.mdPENDING.md 与公开 backup candidate 建立唯一、经过认证且受 lease 约束的 writer;
  • 为 canonical 与 pending 状态建立一个受 CAS 约束的 MemoryBundle 提交边界;
  • 提供 durable、fail-closed 的 transaction recovery;
  • 提供有界 typed memory.querymemory.mutate operation;
  • 提供受 policy gate 约束且 session-correct 的 prompt projection;
  • 对 upload、connection、drain 与 unknown outcome 建立有界处理。

本 PR 属于 #1167 追踪的 M3 提取,并遵循 #853 的 ownership 与 lifecycle 方向。

Authority 与协议

  • MEMORY.mdPENDING.md 组成一个 revisioned bundle,proposal approval 不会只发布一半状态。
  • 每个 section 只有第一条 maka-memory metadata comment 具备权威性;后续 metadata comment 不能替换 canonical status 或 scope。
  • 已接纳操作会在等待串行 mutation lane 前进入 Interactive root owner。
  • Recovery 只接受已记录的 basis 或 target generation,并在外部状态冲突时 fail closed。
  • durable decision 之后出现 publication uncertainty 时返回 commit_outcome_unknown,并请求 Host drain。
  • 协议通过绑定 revision 的分页与 32 KiB raw chunk 保留 128 KiB document 上限,避免产生超出 transport 限制的 frame。
  • Backup candidate 带有独立 revision;restore 同时检查 bundle revision 与所选 candidate revision。
  • Upload 绑定 Host Epoch 与 connection,并限制数量、总大小和生命周期。
  • Commit 会重新验证大小、SHA-256、UTF-8、Memory 语法、secret redaction 与 expected revision。

Policy 与产品边界

  • Memory read 与 prompt projection 经过 shared policy activation gate。
  • Memory mutation 与 Runtime Policy mutation 共用一个 mutation barrier。
  • disabled 与 incognito access 均 fail closed。
  • session-scoped entry 持久化 canonical Session identity,并且只向所属 Session 投影。
  • connection teardown、policy change、abort 与 expiry 都会回收未完成的 upload。
  • Host drain 会立即拒绝新工作,等待已接纳 mutation settle,然后回收剩余 staged upload。
  • 继续支持现有透明 Markdown 路径、legacy metadata、默认内容、safe-mode 行为、backup candidate 与 restore history。

本 slice 不切换 production Desktop 或 TUI owner。Production adapter 接线与 embedded writer 删除仍属于后续 cutover。本 PR 也不增加 generic file、blob、Store 或 transaction RPC。

已经持有打开 file descriptor 的非协作 writer 不在 Store 的并发保证内。Production activation 前,同一 Interactive root 下的 raw writer 必须路由到 Host,或被删除。

验证

  • 全部 37 个 changed file 通过 Biome。
  • Core:1,193 项测试通过。
  • Storage:803 项测试通过;另有 1 项既有 Windows-only skip。
  • Runtime Host:355 项测试通过。
  • Desktop:2,945 项测试通过,包括 console、accessibility 与 copy 检查。
  • 根级 typecheck、production build 与 git diff --check 通过。

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. This keeps the production entry points unchanged, reuses the existing root-lease and policy-activation seams, and does not add a generic Store or file RPC. The two-document transaction and chunked upload both follow from concrete product and transport constraints, so I would keep the current boundary.

I found three non-blocking edge cases worth following up:

  • The Markdown parser accepts every maka-memory metadata comment in a section, so a later comment in the content can replace the canonical scope or status. Only the first metadata line should be authoritative.
  • A no-op raw replacement can rewrite a backup without advancing the bundle revision. A client may then restore a different backup from the one it previously queried. Giving each backup candidate a revision and checking it during restore would close that race.
  • beginDrain() clears staged uploads before accepted mutations have finished waiting on the shared lane. A queued replace_commit can therefore return upload_not_found during shutdown. Upload cleanup should wait for accepted operations to settle.

None of these need to block this M3 slice. Each should get a focused regression test before production activation.

@M4n5ter
M4n5terforce-pushed the feat/runtime-host-canonical-memory-authority branch from d332d5b to 0cabf50CompareJuly 29, 2026 15:24
@M4n5ter

Copy link
Copy Markdown
MemberAuthor

Addressed all three follow-up edge cases in 0cabf50ce: first-metadata authority, revision-fenced backup restore, and drain-safe staged uploads. Focused and full affected test suites, typecheck, build, Biome, and diff checks all pass. A maintainer re-review would be appreciated.

@Astro-Han
Astro-Han merged commit 7ee7bc5 into apache:mainJul 29, 2026
3 checks passed
@M4n5ter
M4n5ter deleted the feat/runtime-host-canonical-memory-authority branch July 29, 2026 15:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@M4n5ter@likun666661@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(runtime-host): establish canonical Memory authority - #1610

Merged
Astro-Han merged 2 commits into
apache:mainfrom
M4n5ter:feat/runtime-host-canonical-memory-authority
Jul 29, 2026
Merged

feat(runtime-host): establish canonical Memory authority#1610
Astro-Han merged 2 commits into
apache:mainfrom
M4n5ter:feat/runtime-host-canonical-memory-authority

Conversation

@M4n5ter

@M4n5terM4n5ter commented Jul 29, 2026

Copy link
Copy Markdown
Member
English

Summary

This PR establishes the Runtime Host boundary for transparent local Memory:

  • one authenticated, lease-bound writer for MEMORY.md, PENDING.md, and public backup candidates;
  • one CAS-fenced MemoryBundle commit boundary for canonical and pending state;
  • durable, fail-closed transaction recovery;
  • bounded typed memory.query and memory.mutate operations;
  • policy-gated, session-correct prompt projection;
  • bounded upload, connection, drain, and unknown-outcome handling.

This is part of the M3 extraction tracked by #1167 and follows the ownership and lifecycle direction in #853.

Authority and protocol

  • MEMORY.md and PENDING.md form one revisioned bundle, so proposal approval cannot publish only half of its state.
  • Only the first maka-memory metadata comment in a section is authoritative; later metadata comments cannot replace canonical status or scope.
  • Accepted operations enter the Interactive root owner before waiting on the serialized mutation lane.
  • Recovery accepts only the recorded basis or target generation and fails closed on conflicting external state.
  • Post-decision publication uncertainty returns commit_outcome_unknown and requests Host drain.
  • The protocol preserves the 128 KiB document limit through revision-pinned pages and 32 KiB raw chunks rather than oversized transport frames.
  • Backup candidates carry their own revision, and restore checks both the bundle revision and selected candidate revision.
  • Uploads are bound to the Host Epoch and connection, with bounded count, aggregate size, and lifetime.
  • Commit revalidates size, SHA-256, UTF-8, Memory syntax, secret redaction, and the expected revision.

Policy and product boundary

  • Memory reads and prompt projection use the shared policy activation gate.
  • Memory and Runtime Policy mutations share one mutation barrier.
  • Disabled and incognito access fail closed.
  • Session-scoped entries persist their canonical Session identity and are projected only to that Session.
  • Connection teardown, policy changes, abort, and expiry reclaim incomplete uploads.
  • Host drain rejects new work immediately, lets accepted mutations settle, and then reclaims remaining staged uploads.
  • Existing transparent Markdown paths, legacy metadata, default content, safe-mode behavior, backup candidates, and restore history remain supported.

This slice does not switch the production Desktop or TUI owner. Production adapter wiring and removal of embedded writers remain later cutover work. It also does not introduce a generic file, blob, Store, or transaction RPC.

Non-cooperating writers that retain an already-open file descriptor remain outside the Store's concurrency guarantee. Before production activation, raw writers for the same Interactive root must be routed through the Host or removed.

Validation

  • Biome passes for all 37 changed files.
  • Core: 1,193 tests passed.
  • Storage: 803 tests passed; one existing Windows-only test skipped.
  • Runtime Host: 355 tests passed.
  • Desktop: 2,945 tests passed, including console, accessibility, and copy checks.
  • Root typecheck, production build, and git diff --check pass.
简体中文

概要

本 PR 为透明本地 Memory 建立 Runtime Host 边界:

  • MEMORY.mdPENDING.md 与公开 backup candidate 建立唯一、经过认证且受 lease 约束的 writer;
  • 为 canonical 与 pending 状态建立一个受 CAS 约束的 MemoryBundle 提交边界;
  • 提供 durable、fail-closed 的 transaction recovery;
  • 提供有界 typed memory.querymemory.mutate operation;
  • 提供受 policy gate 约束且 session-correct 的 prompt projection;
  • 对 upload、connection、drain 与 unknown outcome 建立有界处理。

本 PR 属于 #1167 追踪的 M3 提取,并遵循 #853 的 ownership 与 lifecycle 方向。

Authority 与协议

  • MEMORY.mdPENDING.md 组成一个 revisioned bundle,proposal approval 不会只发布一半状态。
  • 每个 section 只有第一条 maka-memory metadata comment 具备权威性;后续 metadata comment 不能替换 canonical status 或 scope。
  • 已接纳操作会在等待串行 mutation lane 前进入 Interactive root owner。
  • Recovery 只接受已记录的 basis 或 target generation,并在外部状态冲突时 fail closed。
  • durable decision 之后出现 publication uncertainty 时返回 commit_outcome_unknown,并请求 Host drain。
  • 协议通过绑定 revision 的分页与 32 KiB raw chunk 保留 128 KiB document 上限,避免产生超出 transport 限制的 frame。
  • Backup candidate 带有独立 revision;restore 同时检查 bundle revision 与所选 candidate revision。
  • Upload 绑定 Host Epoch 与 connection,并限制数量、总大小和生命周期。
  • Commit 会重新验证大小、SHA-256、UTF-8、Memory 语法、secret redaction 与 expected revision。

Policy 与产品边界

  • Memory read 与 prompt projection 经过 shared policy activation gate。
  • Memory mutation 与 Runtime Policy mutation 共用一个 mutation barrier。
  • disabled 与 incognito access 均 fail closed。
  • session-scoped entry 持久化 canonical Session identity,并且只向所属 Session 投影。
  • connection teardown、policy change、abort 与 expiry 都会回收未完成的 upload。
  • Host drain 会立即拒绝新工作,等待已接纳 mutation settle,然后回收剩余 staged upload。
  • 继续支持现有透明 Markdown 路径、legacy metadata、默认内容、safe-mode 行为、backup candidate 与 restore history。

本 slice 不切换 production Desktop 或 TUI owner。Production adapter 接线与 embedded writer 删除仍属于后续 cutover。本 PR 也不增加 generic file、blob、Store 或 transaction RPC。

已经持有打开 file descriptor 的非协作 writer 不在 Store 的并发保证内。Production activation 前,同一 Interactive root 下的 raw writer 必须路由到 Host,或被删除。

验证

  • 全部 37 个 changed file 通过 Biome。
  • Core:1,193 项测试通过。
  • Storage:803 项测试通过;另有 1 项既有 Windows-only skip。
  • Runtime Host:355 项测试通过。
  • Desktop:2,945 项测试通过,包括 console、accessibility 与 copy 检查。
  • 根级 typecheck、production build 与 git diff --check 通过。

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. This keeps the production entry points unchanged, reuses the existing root-lease and policy-activation seams, and does not add a generic Store or file RPC. The two-document transaction and chunked upload both follow from concrete product and transport constraints, so I would keep the current boundary.

I found three non-blocking edge cases worth following up:

  • The Markdown parser accepts every maka-memory metadata comment in a section, so a later comment in the content can replace the canonical scope or status. Only the first metadata line should be authoritative.
  • A no-op raw replacement can rewrite a backup without advancing the bundle revision. A client may then restore a different backup from the one it previously queried. Giving each backup candidate a revision and checking it during restore would close that race.
  • beginDrain() clears staged uploads before accepted mutations have finished waiting on the shared lane. A queued replace_commit can therefore return upload_not_found during shutdown. Upload cleanup should wait for accepted operations to settle.

None of these need to block this M3 slice. Each should get a focused regression test before production activation.

@M4n5ter
M4n5terforce-pushed the feat/runtime-host-canonical-memory-authority branch from d332d5b to 0cabf50CompareJuly 29, 2026 15:24
@M4n5ter

Copy link
Copy Markdown
MemberAuthor

Addressed all three follow-up edge cases in 0cabf50ce: first-metadata authority, revision-fenced backup restore, and drain-safe staged uploads. Focused and full affected test suites, typecheck, build, Biome, and diff checks all pass. A maintainer re-review would be appreciated.

@Astro-Han
Astro-Han merged commit 7ee7bc5 into apache:mainJul 29, 2026
3 checks passed
@M4n5ter
M4n5ter deleted the feat/runtime-host-canonical-memory-authority branch July 29, 2026 15:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@M4n5ter@likun666661@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(runtime-host): establish canonical Memory authority - #1610

Merged
Astro-Han merged 2 commits into
apache:mainfrom
M4n5ter:feat/runtime-host-canonical-memory-authority
Jul 29, 2026
Merged

feat(runtime-host): establish canonical Memory authority#1610
Astro-Han merged 2 commits into
apache:mainfrom
M4n5ter:feat/runtime-host-canonical-memory-authority

Conversation

@M4n5ter

@M4n5terM4n5ter commented Jul 29, 2026

Copy link
Copy Markdown
Member
English

Summary

This PR establishes the Runtime Host boundary for transparent local Memory:

  • one authenticated, lease-bound writer for MEMORY.md, PENDING.md, and public backup candidates;
  • one CAS-fenced MemoryBundle commit boundary for canonical and pending state;
  • durable, fail-closed transaction recovery;
  • bounded typed memory.query and memory.mutate operations;
  • policy-gated, session-correct prompt projection;
  • bounded upload, connection, drain, and unknown-outcome handling.

This is part of the M3 extraction tracked by #1167 and follows the ownership and lifecycle direction in #853.

Authority and protocol

  • MEMORY.md and PENDING.md form one revisioned bundle, so proposal approval cannot publish only half of its state.
  • Only the first maka-memory metadata comment in a section is authoritative; later metadata comments cannot replace canonical status or scope.
  • Accepted operations enter the Interactive root owner before waiting on the serialized mutation lane.
  • Recovery accepts only the recorded basis or target generation and fails closed on conflicting external state.
  • Post-decision publication uncertainty returns commit_outcome_unknown and requests Host drain.
  • The protocol preserves the 128 KiB document limit through revision-pinned pages and 32 KiB raw chunks rather than oversized transport frames.
  • Backup candidates carry their own revision, and restore checks both the bundle revision and selected candidate revision.
  • Uploads are bound to the Host Epoch and connection, with bounded count, aggregate size, and lifetime.
  • Commit revalidates size, SHA-256, UTF-8, Memory syntax, secret redaction, and the expected revision.

Policy and product boundary

  • Memory reads and prompt projection use the shared policy activation gate.
  • Memory and Runtime Policy mutations share one mutation barrier.
  • Disabled and incognito access fail closed.
  • Session-scoped entries persist their canonical Session identity and are projected only to that Session.
  • Connection teardown, policy changes, abort, and expiry reclaim incomplete uploads.
  • Host drain rejects new work immediately, lets accepted mutations settle, and then reclaims remaining staged uploads.
  • Existing transparent Markdown paths, legacy metadata, default content, safe-mode behavior, backup candidates, and restore history remain supported.

This slice does not switch the production Desktop or TUI owner. Production adapter wiring and removal of embedded writers remain later cutover work. It also does not introduce a generic file, blob, Store, or transaction RPC.

Non-cooperating writers that retain an already-open file descriptor remain outside the Store's concurrency guarantee. Before production activation, raw writers for the same Interactive root must be routed through the Host or removed.

Validation

  • Biome passes for all 37 changed files.
  • Core: 1,193 tests passed.
  • Storage: 803 tests passed; one existing Windows-only test skipped.
  • Runtime Host: 355 tests passed.
  • Desktop: 2,945 tests passed, including console, accessibility, and copy checks.
  • Root typecheck, production build, and git diff --check pass.
简体中文

概要

本 PR 为透明本地 Memory 建立 Runtime Host 边界:

  • MEMORY.mdPENDING.md 与公开 backup candidate 建立唯一、经过认证且受 lease 约束的 writer;
  • 为 canonical 与 pending 状态建立一个受 CAS 约束的 MemoryBundle 提交边界;
  • 提供 durable、fail-closed 的 transaction recovery;
  • 提供有界 typed memory.querymemory.mutate operation;
  • 提供受 policy gate 约束且 session-correct 的 prompt projection;
  • 对 upload、connection、drain 与 unknown outcome 建立有界处理。

本 PR 属于 #1167 追踪的 M3 提取,并遵循 #853 的 ownership 与 lifecycle 方向。

Authority 与协议

  • MEMORY.mdPENDING.md 组成一个 revisioned bundle,proposal approval 不会只发布一半状态。
  • 每个 section 只有第一条 maka-memory metadata comment 具备权威性;后续 metadata comment 不能替换 canonical status 或 scope。
  • 已接纳操作会在等待串行 mutation lane 前进入 Interactive root owner。
  • Recovery 只接受已记录的 basis 或 target generation,并在外部状态冲突时 fail closed。
  • durable decision 之后出现 publication uncertainty 时返回 commit_outcome_unknown,并请求 Host drain。
  • 协议通过绑定 revision 的分页与 32 KiB raw chunk 保留 128 KiB document 上限,避免产生超出 transport 限制的 frame。
  • Backup candidate 带有独立 revision;restore 同时检查 bundle revision 与所选 candidate revision。
  • Upload 绑定 Host Epoch 与 connection,并限制数量、总大小和生命周期。
  • Commit 会重新验证大小、SHA-256、UTF-8、Memory 语法、secret redaction 与 expected revision。

Policy 与产品边界

  • Memory read 与 prompt projection 经过 shared policy activation gate。
  • Memory mutation 与 Runtime Policy mutation 共用一个 mutation barrier。
  • disabled 与 incognito access 均 fail closed。
  • session-scoped entry 持久化 canonical Session identity,并且只向所属 Session 投影。
  • connection teardown、policy change、abort 与 expiry 都会回收未完成的 upload。
  • Host drain 会立即拒绝新工作,等待已接纳 mutation settle,然后回收剩余 staged upload。
  • 继续支持现有透明 Markdown 路径、legacy metadata、默认内容、safe-mode 行为、backup candidate 与 restore history。

本 slice 不切换 production Desktop 或 TUI owner。Production adapter 接线与 embedded writer 删除仍属于后续 cutover。本 PR 也不增加 generic file、blob、Store 或 transaction RPC。

已经持有打开 file descriptor 的非协作 writer 不在 Store 的并发保证内。Production activation 前,同一 Interactive root 下的 raw writer 必须路由到 Host,或被删除。

验证

  • 全部 37 个 changed file 通过 Biome。
  • Core:1,193 项测试通过。
  • Storage:803 项测试通过;另有 1 项既有 Windows-only skip。
  • Runtime Host:355 项测试通过。
  • Desktop:2,945 项测试通过,包括 console、accessibility 与 copy 检查。
  • 根级 typecheck、production build 与 git diff --check 通过。

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. This keeps the production entry points unchanged, reuses the existing root-lease and policy-activation seams, and does not add a generic Store or file RPC. The two-document transaction and chunked upload both follow from concrete product and transport constraints, so I would keep the current boundary.

I found three non-blocking edge cases worth following up:

  • The Markdown parser accepts every maka-memory metadata comment in a section, so a later comment in the content can replace the canonical scope or status. Only the first metadata line should be authoritative.
  • A no-op raw replacement can rewrite a backup without advancing the bundle revision. A client may then restore a different backup from the one it previously queried. Giving each backup candidate a revision and checking it during restore would close that race.
  • beginDrain() clears staged uploads before accepted mutations have finished waiting on the shared lane. A queued replace_commit can therefore return upload_not_found during shutdown. Upload cleanup should wait for accepted operations to settle.

None of these need to block this M3 slice. Each should get a focused regression test before production activation.

@M4n5ter
M4n5terforce-pushed the feat/runtime-host-canonical-memory-authority branch from d332d5b to 0cabf50CompareJuly 29, 2026 15:24
@M4n5ter

Copy link
Copy Markdown
MemberAuthor

Addressed all three follow-up edge cases in 0cabf50ce: first-metadata authority, revision-fenced backup restore, and drain-safe staged uploads. Focused and full affected test suites, typecheck, build, Biome, and diff checks all pass. A maintainer re-review would be appreciated.

@Astro-Han
Astro-Han merged commit 7ee7bc5 into apache:mainJul 29, 2026
3 checks passed
@M4n5ter
M4n5ter deleted the feat/runtime-host-canonical-memory-authority branch July 29, 2026 15:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@M4n5ter@likun666661@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(runtime-host): establish canonical Memory authority - #1610

Merged
Astro-Han merged 2 commits into
apache:mainfrom
M4n5ter:feat/runtime-host-canonical-memory-authority
Jul 29, 2026
Merged

feat(runtime-host): establish canonical Memory authority#1610
Astro-Han merged 2 commits into
apache:mainfrom
M4n5ter:feat/runtime-host-canonical-memory-authority

Conversation

@M4n5ter

@M4n5terM4n5ter commented Jul 29, 2026

Copy link
Copy Markdown
Member
English

Summary

This PR establishes the Runtime Host boundary for transparent local Memory:

  • one authenticated, lease-bound writer for MEMORY.md, PENDING.md, and public backup candidates;
  • one CAS-fenced MemoryBundle commit boundary for canonical and pending state;
  • durable, fail-closed transaction recovery;
  • bounded typed memory.query and memory.mutate operations;
  • policy-gated, session-correct prompt projection;
  • bounded upload, connection, drain, and unknown-outcome handling.

This is part of the M3 extraction tracked by #1167 and follows the ownership and lifecycle direction in #853.

Authority and protocol

  • MEMORY.md and PENDING.md form one revisioned bundle, so proposal approval cannot publish only half of its state.
  • Only the first maka-memory metadata comment in a section is authoritative; later metadata comments cannot replace canonical status or scope.
  • Accepted operations enter the Interactive root owner before waiting on the serialized mutation lane.
  • Recovery accepts only the recorded basis or target generation and fails closed on conflicting external state.
  • Post-decision publication uncertainty returns commit_outcome_unknown and requests Host drain.
  • The protocol preserves the 128 KiB document limit through revision-pinned pages and 32 KiB raw chunks rather than oversized transport frames.
  • Backup candidates carry their own revision, and restore checks both the bundle revision and selected candidate revision.
  • Uploads are bound to the Host Epoch and connection, with bounded count, aggregate size, and lifetime.
  • Commit revalidates size, SHA-256, UTF-8, Memory syntax, secret redaction, and the expected revision.

Policy and product boundary

  • Memory reads and prompt projection use the shared policy activation gate.
  • Memory and Runtime Policy mutations share one mutation barrier.
  • Disabled and incognito access fail closed.
  • Session-scoped entries persist their canonical Session identity and are projected only to that Session.
  • Connection teardown, policy changes, abort, and expiry reclaim incomplete uploads.
  • Host drain rejects new work immediately, lets accepted mutations settle, and then reclaims remaining staged uploads.
  • Existing transparent Markdown paths, legacy metadata, default content, safe-mode behavior, backup candidates, and restore history remain supported.

This slice does not switch the production Desktop or TUI owner. Production adapter wiring and removal of embedded writers remain later cutover work. It also does not introduce a generic file, blob, Store, or transaction RPC.

Non-cooperating writers that retain an already-open file descriptor remain outside the Store's concurrency guarantee. Before production activation, raw writers for the same Interactive root must be routed through the Host or removed.

Validation

  • Biome passes for all 37 changed files.
  • Core: 1,193 tests passed.
  • Storage: 803 tests passed; one existing Windows-only test skipped.
  • Runtime Host: 355 tests passed.
  • Desktop: 2,945 tests passed, including console, accessibility, and copy checks.
  • Root typecheck, production build, and git diff --check pass.
简体中文

概要

本 PR 为透明本地 Memory 建立 Runtime Host 边界:

  • MEMORY.mdPENDING.md 与公开 backup candidate 建立唯一、经过认证且受 lease 约束的 writer;
  • 为 canonical 与 pending 状态建立一个受 CAS 约束的 MemoryBundle 提交边界;
  • 提供 durable、fail-closed 的 transaction recovery;
  • 提供有界 typed memory.querymemory.mutate operation;
  • 提供受 policy gate 约束且 session-correct 的 prompt projection;
  • 对 upload、connection、drain 与 unknown outcome 建立有界处理。

本 PR 属于 #1167 追踪的 M3 提取,并遵循 #853 的 ownership 与 lifecycle 方向。

Authority 与协议

  • MEMORY.mdPENDING.md 组成一个 revisioned bundle,proposal approval 不会只发布一半状态。
  • 每个 section 只有第一条 maka-memory metadata comment 具备权威性;后续 metadata comment 不能替换 canonical status 或 scope。
  • 已接纳操作会在等待串行 mutation lane 前进入 Interactive root owner。
  • Recovery 只接受已记录的 basis 或 target generation,并在外部状态冲突时 fail closed。
  • durable decision 之后出现 publication uncertainty 时返回 commit_outcome_unknown,并请求 Host drain。
  • 协议通过绑定 revision 的分页与 32 KiB raw chunk 保留 128 KiB document 上限,避免产生超出 transport 限制的 frame。
  • Backup candidate 带有独立 revision;restore 同时检查 bundle revision 与所选 candidate revision。
  • Upload 绑定 Host Epoch 与 connection,并限制数量、总大小和生命周期。
  • Commit 会重新验证大小、SHA-256、UTF-8、Memory 语法、secret redaction 与 expected revision。

Policy 与产品边界

  • Memory read 与 prompt projection 经过 shared policy activation gate。
  • Memory mutation 与 Runtime Policy mutation 共用一个 mutation barrier。
  • disabled 与 incognito access 均 fail closed。
  • session-scoped entry 持久化 canonical Session identity,并且只向所属 Session 投影。
  • connection teardown、policy change、abort 与 expiry 都会回收未完成的 upload。
  • Host drain 会立即拒绝新工作,等待已接纳 mutation settle,然后回收剩余 staged upload。
  • 继续支持现有透明 Markdown 路径、legacy metadata、默认内容、safe-mode 行为、backup candidate 与 restore history。

本 slice 不切换 production Desktop 或 TUI owner。Production adapter 接线与 embedded writer 删除仍属于后续 cutover。本 PR 也不增加 generic file、blob、Store 或 transaction RPC。

已经持有打开 file descriptor 的非协作 writer 不在 Store 的并发保证内。Production activation 前,同一 Interactive root 下的 raw writer 必须路由到 Host,或被删除。

验证

  • 全部 37 个 changed file 通过 Biome。
  • Core:1,193 项测试通过。
  • Storage:803 项测试通过;另有 1 项既有 Windows-only skip。
  • Runtime Host:355 项测试通过。
  • Desktop:2,945 项测试通过,包括 console、accessibility 与 copy 检查。
  • 根级 typecheck、production build 与 git diff --check 通过。

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. This keeps the production entry points unchanged, reuses the existing root-lease and policy-activation seams, and does not add a generic Store or file RPC. The two-document transaction and chunked upload both follow from concrete product and transport constraints, so I would keep the current boundary.

I found three non-blocking edge cases worth following up:

  • The Markdown parser accepts every maka-memory metadata comment in a section, so a later comment in the content can replace the canonical scope or status. Only the first metadata line should be authoritative.
  • A no-op raw replacement can rewrite a backup without advancing the bundle revision. A client may then restore a different backup from the one it previously queried. Giving each backup candidate a revision and checking it during restore would close that race.
  • beginDrain() clears staged uploads before accepted mutations have finished waiting on the shared lane. A queued replace_commit can therefore return upload_not_found during shutdown. Upload cleanup should wait for accepted operations to settle.

None of these need to block this M3 slice. Each should get a focused regression test before production activation.

@M4n5ter
M4n5terforce-pushed the feat/runtime-host-canonical-memory-authority branch from d332d5b to 0cabf50CompareJuly 29, 2026 15:24
@M4n5ter

Copy link
Copy Markdown
MemberAuthor

Addressed all three follow-up edge cases in 0cabf50ce: first-metadata authority, revision-fenced backup restore, and drain-safe staged uploads. Focused and full affected test suites, typecheck, build, Biome, and diff checks all pass. A maintainer re-review would be appreciated.

@Astro-Han
Astro-Han merged commit 7ee7bc5 into apache:mainJul 29, 2026
3 checks passed
@M4n5ter
M4n5ter deleted the feat/runtime-host-canonical-memory-authority branch July 29, 2026 15:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@M4n5ter@likun666661@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(runtime-host): establish canonical Memory authority - #1610

Merged
Astro-Han merged 2 commits into
apache:mainfrom
M4n5ter:feat/runtime-host-canonical-memory-authority
Jul 29, 2026
Merged

feat(runtime-host): establish canonical Memory authority#1610
Astro-Han merged 2 commits into
apache:mainfrom
M4n5ter:feat/runtime-host-canonical-memory-authority

Conversation

@M4n5ter

@M4n5terM4n5ter commented Jul 29, 2026

Copy link
Copy Markdown
Member
English

Summary

This PR establishes the Runtime Host boundary for transparent local Memory:

  • one authenticated, lease-bound writer for MEMORY.md, PENDING.md, and public backup candidates;
  • one CAS-fenced MemoryBundle commit boundary for canonical and pending state;
  • durable, fail-closed transaction recovery;
  • bounded typed memory.query and memory.mutate operations;
  • policy-gated, session-correct prompt projection;
  • bounded upload, connection, drain, and unknown-outcome handling.

This is part of the M3 extraction tracked by #1167 and follows the ownership and lifecycle direction in #853.

Authority and protocol

  • MEMORY.md and PENDING.md form one revisioned bundle, so proposal approval cannot publish only half of its state.
  • Only the first maka-memory metadata comment in a section is authoritative; later metadata comments cannot replace canonical status or scope.
  • Accepted operations enter the Interactive root owner before waiting on the serialized mutation lane.
  • Recovery accepts only the recorded basis or target generation and fails closed on conflicting external state.
  • Post-decision publication uncertainty returns commit_outcome_unknown and requests Host drain.
  • The protocol preserves the 128 KiB document limit through revision-pinned pages and 32 KiB raw chunks rather than oversized transport frames.
  • Backup candidates carry their own revision, and restore checks both the bundle revision and selected candidate revision.
  • Uploads are bound to the Host Epoch and connection, with bounded count, aggregate size, and lifetime.
  • Commit revalidates size, SHA-256, UTF-8, Memory syntax, secret redaction, and the expected revision.

Policy and product boundary

  • Memory reads and prompt projection use the shared policy activation gate.
  • Memory and Runtime Policy mutations share one mutation barrier.
  • Disabled and incognito access fail closed.
  • Session-scoped entries persist their canonical Session identity and are projected only to that Session.
  • Connection teardown, policy changes, abort, and expiry reclaim incomplete uploads.
  • Host drain rejects new work immediately, lets accepted mutations settle, and then reclaims remaining staged uploads.
  • Existing transparent Markdown paths, legacy metadata, default content, safe-mode behavior, backup candidates, and restore history remain supported.

This slice does not switch the production Desktop or TUI owner. Production adapter wiring and removal of embedded writers remain later cutover work. It also does not introduce a generic file, blob, Store, or transaction RPC.

Non-cooperating writers that retain an already-open file descriptor remain outside the Store's concurrency guarantee. Before production activation, raw writers for the same Interactive root must be routed through the Host or removed.

Validation

  • Biome passes for all 37 changed files.
  • Core: 1,193 tests passed.
  • Storage: 803 tests passed; one existing Windows-only test skipped.
  • Runtime Host: 355 tests passed.
  • Desktop: 2,945 tests passed, including console, accessibility, and copy checks.
  • Root typecheck, production build, and git diff --check pass.
简体中文

概要

本 PR 为透明本地 Memory 建立 Runtime Host 边界:

  • MEMORY.mdPENDING.md 与公开 backup candidate 建立唯一、经过认证且受 lease 约束的 writer;
  • 为 canonical 与 pending 状态建立一个受 CAS 约束的 MemoryBundle 提交边界;
  • 提供 durable、fail-closed 的 transaction recovery;
  • 提供有界 typed memory.querymemory.mutate operation;
  • 提供受 policy gate 约束且 session-correct 的 prompt projection;
  • 对 upload、connection、drain 与 unknown outcome 建立有界处理。

本 PR 属于 #1167 追踪的 M3 提取,并遵循 #853 的 ownership 与 lifecycle 方向。

Authority 与协议

  • MEMORY.mdPENDING.md 组成一个 revisioned bundle,proposal approval 不会只发布一半状态。
  • 每个 section 只有第一条 maka-memory metadata comment 具备权威性;后续 metadata comment 不能替换 canonical status 或 scope。
  • 已接纳操作会在等待串行 mutation lane 前进入 Interactive root owner。
  • Recovery 只接受已记录的 basis 或 target generation,并在外部状态冲突时 fail closed。
  • durable decision 之后出现 publication uncertainty 时返回 commit_outcome_unknown,并请求 Host drain。
  • 协议通过绑定 revision 的分页与 32 KiB raw chunk 保留 128 KiB document 上限,避免产生超出 transport 限制的 frame。
  • Backup candidate 带有独立 revision;restore 同时检查 bundle revision 与所选 candidate revision。
  • Upload 绑定 Host Epoch 与 connection,并限制数量、总大小和生命周期。
  • Commit 会重新验证大小、SHA-256、UTF-8、Memory 语法、secret redaction 与 expected revision。

Policy 与产品边界

  • Memory read 与 prompt projection 经过 shared policy activation gate。
  • Memory mutation 与 Runtime Policy mutation 共用一个 mutation barrier。
  • disabled 与 incognito access 均 fail closed。
  • session-scoped entry 持久化 canonical Session identity,并且只向所属 Session 投影。
  • connection teardown、policy change、abort 与 expiry 都会回收未完成的 upload。
  • Host drain 会立即拒绝新工作,等待已接纳 mutation settle,然后回收剩余 staged upload。
  • 继续支持现有透明 Markdown 路径、legacy metadata、默认内容、safe-mode 行为、backup candidate 与 restore history。

本 slice 不切换 production Desktop 或 TUI owner。Production adapter 接线与 embedded writer 删除仍属于后续 cutover。本 PR 也不增加 generic file、blob、Store 或 transaction RPC。

已经持有打开 file descriptor 的非协作 writer 不在 Store 的并发保证内。Production activation 前,同一 Interactive root 下的 raw writer 必须路由到 Host,或被删除。

验证

  • 全部 37 个 changed file 通过 Biome。
  • Core:1,193 项测试通过。
  • Storage:803 项测试通过;另有 1 项既有 Windows-only skip。
  • Runtime Host:355 项测试通过。
  • Desktop:2,945 项测试通过,包括 console、accessibility 与 copy 检查。
  • 根级 typecheck、production build 与 git diff --check 通过。

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. This keeps the production entry points unchanged, reuses the existing root-lease and policy-activation seams, and does not add a generic Store or file RPC. The two-document transaction and chunked upload both follow from concrete product and transport constraints, so I would keep the current boundary.

I found three non-blocking edge cases worth following up:

  • The Markdown parser accepts every maka-memory metadata comment in a section, so a later comment in the content can replace the canonical scope or status. Only the first metadata line should be authoritative.
  • A no-op raw replacement can rewrite a backup without advancing the bundle revision. A client may then restore a different backup from the one it previously queried. Giving each backup candidate a revision and checking it during restore would close that race.
  • beginDrain() clears staged uploads before accepted mutations have finished waiting on the shared lane. A queued replace_commit can therefore return upload_not_found during shutdown. Upload cleanup should wait for accepted operations to settle.

None of these need to block this M3 slice. Each should get a focused regression test before production activation.

@M4n5ter
M4n5terforce-pushed the feat/runtime-host-canonical-memory-authority branch from d332d5b to 0cabf50CompareJuly 29, 2026 15:24
@M4n5ter

Copy link
Copy Markdown
MemberAuthor

Addressed all three follow-up edge cases in 0cabf50ce: first-metadata authority, revision-fenced backup restore, and drain-safe staged uploads. Focused and full affected test suites, typecheck, build, Biome, and diff checks all pass. A maintainer re-review would be appreciated.

@Astro-Han
Astro-Han merged commit 7ee7bc5 into apache:mainJul 29, 2026
3 checks passed
@M4n5ter
M4n5ter deleted the feat/runtime-host-canonical-memory-authority branch July 29, 2026 15:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@M4n5ter@likun666661@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(runtime-host): establish canonical Memory authority - #1610

Merged
Astro-Han merged 2 commits into
apache:mainfrom
M4n5ter:feat/runtime-host-canonical-memory-authority
Jul 29, 2026
Merged

feat(runtime-host): establish canonical Memory authority#1610
Astro-Han merged 2 commits into
apache:mainfrom
M4n5ter:feat/runtime-host-canonical-memory-authority

Conversation

@M4n5ter

@M4n5terM4n5ter commented Jul 29, 2026

Copy link
Copy Markdown
Member
English

Summary

This PR establishes the Runtime Host boundary for transparent local Memory:

  • one authenticated, lease-bound writer for MEMORY.md, PENDING.md, and public backup candidates;
  • one CAS-fenced MemoryBundle commit boundary for canonical and pending state;
  • durable, fail-closed transaction recovery;
  • bounded typed memory.query and memory.mutate operations;
  • policy-gated, session-correct prompt projection;
  • bounded upload, connection, drain, and unknown-outcome handling.

This is part of the M3 extraction tracked by #1167 and follows the ownership and lifecycle direction in #853.

Authority and protocol

  • MEMORY.md and PENDING.md form one revisioned bundle, so proposal approval cannot publish only half of its state.
  • Only the first maka-memory metadata comment in a section is authoritative; later metadata comments cannot replace canonical status or scope.
  • Accepted operations enter the Interactive root owner before waiting on the serialized mutation lane.
  • Recovery accepts only the recorded basis or target generation and fails closed on conflicting external state.
  • Post-decision publication uncertainty returns commit_outcome_unknown and requests Host drain.
  • The protocol preserves the 128 KiB document limit through revision-pinned pages and 32 KiB raw chunks rather than oversized transport frames.
  • Backup candidates carry their own revision, and restore checks both the bundle revision and selected candidate revision.
  • Uploads are bound to the Host Epoch and connection, with bounded count, aggregate size, and lifetime.
  • Commit revalidates size, SHA-256, UTF-8, Memory syntax, secret redaction, and the expected revision.

Policy and product boundary

  • Memory reads and prompt projection use the shared policy activation gate.
  • Memory and Runtime Policy mutations share one mutation barrier.
  • Disabled and incognito access fail closed.
  • Session-scoped entries persist their canonical Session identity and are projected only to that Session.
  • Connection teardown, policy changes, abort, and expiry reclaim incomplete uploads.
  • Host drain rejects new work immediately, lets accepted mutations settle, and then reclaims remaining staged uploads.
  • Existing transparent Markdown paths, legacy metadata, default content, safe-mode behavior, backup candidates, and restore history remain supported.

This slice does not switch the production Desktop or TUI owner. Production adapter wiring and removal of embedded writers remain later cutover work. It also does not introduce a generic file, blob, Store, or transaction RPC.

Non-cooperating writers that retain an already-open file descriptor remain outside the Store's concurrency guarantee. Before production activation, raw writers for the same Interactive root must be routed through the Host or removed.

Validation

  • Biome passes for all 37 changed files.
  • Core: 1,193 tests passed.
  • Storage: 803 tests passed; one existing Windows-only test skipped.
  • Runtime Host: 355 tests passed.
  • Desktop: 2,945 tests passed, including console, accessibility, and copy checks.
  • Root typecheck, production build, and git diff --check pass.
简体中文

概要

本 PR 为透明本地 Memory 建立 Runtime Host 边界:

  • MEMORY.mdPENDING.md 与公开 backup candidate 建立唯一、经过认证且受 lease 约束的 writer;
  • 为 canonical 与 pending 状态建立一个受 CAS 约束的 MemoryBundle 提交边界;
  • 提供 durable、fail-closed 的 transaction recovery;
  • 提供有界 typed memory.querymemory.mutate operation;
  • 提供受 policy gate 约束且 session-correct 的 prompt projection;
  • 对 upload、connection、drain 与 unknown outcome 建立有界处理。

本 PR 属于 #1167 追踪的 M3 提取,并遵循 #853 的 ownership 与 lifecycle 方向。

Authority 与协议

  • MEMORY.mdPENDING.md 组成一个 revisioned bundle,proposal approval 不会只发布一半状态。
  • 每个 section 只有第一条 maka-memory metadata comment 具备权威性;后续 metadata comment 不能替换 canonical status 或 scope。
  • 已接纳操作会在等待串行 mutation lane 前进入 Interactive root owner。
  • Recovery 只接受已记录的 basis 或 target generation,并在外部状态冲突时 fail closed。
  • durable decision 之后出现 publication uncertainty 时返回 commit_outcome_unknown,并请求 Host drain。
  • 协议通过绑定 revision 的分页与 32 KiB raw chunk 保留 128 KiB document 上限,避免产生超出 transport 限制的 frame。
  • Backup candidate 带有独立 revision;restore 同时检查 bundle revision 与所选 candidate revision。
  • Upload 绑定 Host Epoch 与 connection,并限制数量、总大小和生命周期。
  • Commit 会重新验证大小、SHA-256、UTF-8、Memory 语法、secret redaction 与 expected revision。

Policy 与产品边界

  • Memory read 与 prompt projection 经过 shared policy activation gate。
  • Memory mutation 与 Runtime Policy mutation 共用一个 mutation barrier。
  • disabled 与 incognito access 均 fail closed。
  • session-scoped entry 持久化 canonical Session identity,并且只向所属 Session 投影。
  • connection teardown、policy change、abort 与 expiry 都会回收未完成的 upload。
  • Host drain 会立即拒绝新工作,等待已接纳 mutation settle,然后回收剩余 staged upload。
  • 继续支持现有透明 Markdown 路径、legacy metadata、默认内容、safe-mode 行为、backup candidate 与 restore history。

本 slice 不切换 production Desktop 或 TUI owner。Production adapter 接线与 embedded writer 删除仍属于后续 cutover。本 PR 也不增加 generic file、blob、Store 或 transaction RPC。

已经持有打开 file descriptor 的非协作 writer 不在 Store 的并发保证内。Production activation 前,同一 Interactive root 下的 raw writer 必须路由到 Host,或被删除。

验证

  • 全部 37 个 changed file 通过 Biome。
  • Core:1,193 项测试通过。
  • Storage:803 项测试通过;另有 1 项既有 Windows-only skip。
  • Runtime Host:355 项测试通过。
  • Desktop:2,945 项测试通过,包括 console、accessibility 与 copy 检查。
  • 根级 typecheck、production build 与 git diff --check 通过。

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. This keeps the production entry points unchanged, reuses the existing root-lease and policy-activation seams, and does not add a generic Store or file RPC. The two-document transaction and chunked upload both follow from concrete product and transport constraints, so I would keep the current boundary.

I found three non-blocking edge cases worth following up:

  • The Markdown parser accepts every maka-memory metadata comment in a section, so a later comment in the content can replace the canonical scope or status. Only the first metadata line should be authoritative.
  • A no-op raw replacement can rewrite a backup without advancing the bundle revision. A client may then restore a different backup from the one it previously queried. Giving each backup candidate a revision and checking it during restore would close that race.
  • beginDrain() clears staged uploads before accepted mutations have finished waiting on the shared lane. A queued replace_commit can therefore return upload_not_found during shutdown. Upload cleanup should wait for accepted operations to settle.

None of these need to block this M3 slice. Each should get a focused regression test before production activation.

@M4n5ter
M4n5terforce-pushed the feat/runtime-host-canonical-memory-authority branch from d332d5b to 0cabf50CompareJuly 29, 2026 15:24
@M4n5ter

Copy link
Copy Markdown
MemberAuthor

Addressed all three follow-up edge cases in 0cabf50ce: first-metadata authority, revision-fenced backup restore, and drain-safe staged uploads. Focused and full affected test suites, typecheck, build, Biome, and diff checks all pass. A maintainer re-review would be appreciated.

@Astro-Han
Astro-Han merged commit 7ee7bc5 into apache:mainJul 29, 2026
3 checks passed
@M4n5ter
M4n5ter deleted the feat/runtime-host-canonical-memory-authority branch July 29, 2026 15:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@M4n5ter@likun666661@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(runtime-host): establish canonical Memory authority - #1610

Merged
Astro-Han merged 2 commits into
apache:mainfrom
M4n5ter:feat/runtime-host-canonical-memory-authority
Jul 29, 2026
Merged

feat(runtime-host): establish canonical Memory authority#1610
Astro-Han merged 2 commits into
apache:mainfrom
M4n5ter:feat/runtime-host-canonical-memory-authority

Conversation

@M4n5ter

@M4n5terM4n5ter commented Jul 29, 2026

Copy link
Copy Markdown
Member
English

Summary

This PR establishes the Runtime Host boundary for transparent local Memory:

  • one authenticated, lease-bound writer for MEMORY.md, PENDING.md, and public backup candidates;
  • one CAS-fenced MemoryBundle commit boundary for canonical and pending state;
  • durable, fail-closed transaction recovery;
  • bounded typed memory.query and memory.mutate operations;
  • policy-gated, session-correct prompt projection;
  • bounded upload, connection, drain, and unknown-outcome handling.

This is part of the M3 extraction tracked by #1167 and follows the ownership and lifecycle direction in #853.

Authority and protocol

  • MEMORY.md and PENDING.md form one revisioned bundle, so proposal approval cannot publish only half of its state.
  • Only the first maka-memory metadata comment in a section is authoritative; later metadata comments cannot replace canonical status or scope.
  • Accepted operations enter the Interactive root owner before waiting on the serialized mutation lane.
  • Recovery accepts only the recorded basis or target generation and fails closed on conflicting external state.
  • Post-decision publication uncertainty returns commit_outcome_unknown and requests Host drain.
  • The protocol preserves the 128 KiB document limit through revision-pinned pages and 32 KiB raw chunks rather than oversized transport frames.
  • Backup candidates carry their own revision, and restore checks both the bundle revision and selected candidate revision.
  • Uploads are bound to the Host Epoch and connection, with bounded count, aggregate size, and lifetime.
  • Commit revalidates size, SHA-256, UTF-8, Memory syntax, secret redaction, and the expected revision.

Policy and product boundary

  • Memory reads and prompt projection use the shared policy activation gate.
  • Memory and Runtime Policy mutations share one mutation barrier.
  • Disabled and incognito access fail closed.
  • Session-scoped entries persist their canonical Session identity and are projected only to that Session.
  • Connection teardown, policy changes, abort, and expiry reclaim incomplete uploads.
  • Host drain rejects new work immediately, lets accepted mutations settle, and then reclaims remaining staged uploads.
  • Existing transparent Markdown paths, legacy metadata, default content, safe-mode behavior, backup candidates, and restore history remain supported.

This slice does not switch the production Desktop or TUI owner. Production adapter wiring and removal of embedded writers remain later cutover work. It also does not introduce a generic file, blob, Store, or transaction RPC.

Non-cooperating writers that retain an already-open file descriptor remain outside the Store's concurrency guarantee. Before production activation, raw writers for the same Interactive root must be routed through the Host or removed.

Validation

  • Biome passes for all 37 changed files.
  • Core: 1,193 tests passed.
  • Storage: 803 tests passed; one existing Windows-only test skipped.
  • Runtime Host: 355 tests passed.
  • Desktop: 2,945 tests passed, including console, accessibility, and copy checks.
  • Root typecheck, production build, and git diff --check pass.
简体中文

概要

本 PR 为透明本地 Memory 建立 Runtime Host 边界:

  • MEMORY.mdPENDING.md 与公开 backup candidate 建立唯一、经过认证且受 lease 约束的 writer;
  • 为 canonical 与 pending 状态建立一个受 CAS 约束的 MemoryBundle 提交边界;
  • 提供 durable、fail-closed 的 transaction recovery;
  • 提供有界 typed memory.querymemory.mutate operation;
  • 提供受 policy gate 约束且 session-correct 的 prompt projection;
  • 对 upload、connection、drain 与 unknown outcome 建立有界处理。

本 PR 属于 #1167 追踪的 M3 提取,并遵循 #853 的 ownership 与 lifecycle 方向。

Authority 与协议

  • MEMORY.mdPENDING.md 组成一个 revisioned bundle,proposal approval 不会只发布一半状态。
  • 每个 section 只有第一条 maka-memory metadata comment 具备权威性;后续 metadata comment 不能替换 canonical status 或 scope。
  • 已接纳操作会在等待串行 mutation lane 前进入 Interactive root owner。
  • Recovery 只接受已记录的 basis 或 target generation,并在外部状态冲突时 fail closed。
  • durable decision 之后出现 publication uncertainty 时返回 commit_outcome_unknown,并请求 Host drain。
  • 协议通过绑定 revision 的分页与 32 KiB raw chunk 保留 128 KiB document 上限,避免产生超出 transport 限制的 frame。
  • Backup candidate 带有独立 revision;restore 同时检查 bundle revision 与所选 candidate revision。
  • Upload 绑定 Host Epoch 与 connection,并限制数量、总大小和生命周期。
  • Commit 会重新验证大小、SHA-256、UTF-8、Memory 语法、secret redaction 与 expected revision。

Policy 与产品边界

  • Memory read 与 prompt projection 经过 shared policy activation gate。
  • Memory mutation 与 Runtime Policy mutation 共用一个 mutation barrier。
  • disabled 与 incognito access 均 fail closed。
  • session-scoped entry 持久化 canonical Session identity,并且只向所属 Session 投影。
  • connection teardown、policy change、abort 与 expiry 都会回收未完成的 upload。
  • Host drain 会立即拒绝新工作,等待已接纳 mutation settle,然后回收剩余 staged upload。
  • 继续支持现有透明 Markdown 路径、legacy metadata、默认内容、safe-mode 行为、backup candidate 与 restore history。

本 slice 不切换 production Desktop 或 TUI owner。Production adapter 接线与 embedded writer 删除仍属于后续 cutover。本 PR 也不增加 generic file、blob、Store 或 transaction RPC。

已经持有打开 file descriptor 的非协作 writer 不在 Store 的并发保证内。Production activation 前,同一 Interactive root 下的 raw writer 必须路由到 Host,或被删除。

验证

  • 全部 37 个 changed file 通过 Biome。
  • Core:1,193 项测试通过。
  • Storage:803 项测试通过;另有 1 项既有 Windows-only skip。
  • Runtime Host:355 项测试通过。
  • Desktop:2,945 项测试通过,包括 console、accessibility 与 copy 检查。
  • 根级 typecheck、production build 与 git diff --check 通过。

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. This keeps the production entry points unchanged, reuses the existing root-lease and policy-activation seams, and does not add a generic Store or file RPC. The two-document transaction and chunked upload both follow from concrete product and transport constraints, so I would keep the current boundary.

I found three non-blocking edge cases worth following up:

  • The Markdown parser accepts every maka-memory metadata comment in a section, so a later comment in the content can replace the canonical scope or status. Only the first metadata line should be authoritative.
  • A no-op raw replacement can rewrite a backup without advancing the bundle revision. A client may then restore a different backup from the one it previously queried. Giving each backup candidate a revision and checking it during restore would close that race.
  • beginDrain() clears staged uploads before accepted mutations have finished waiting on the shared lane. A queued replace_commit can therefore return upload_not_found during shutdown. Upload cleanup should wait for accepted operations to settle.

None of these need to block this M3 slice. Each should get a focused regression test before production activation.

@M4n5ter
M4n5terforce-pushed the feat/runtime-host-canonical-memory-authority branch from d332d5b to 0cabf50CompareJuly 29, 2026 15:24
@M4n5ter

Copy link
Copy Markdown
MemberAuthor

Addressed all three follow-up edge cases in 0cabf50ce: first-metadata authority, revision-fenced backup restore, and drain-safe staged uploads. Focused and full affected test suites, typecheck, build, Biome, and diff checks all pass. A maintainer re-review would be appreciated.

@Astro-Han
Astro-Han merged commit 7ee7bc5 into apache:mainJul 29, 2026
3 checks passed
@M4n5ter
M4n5ter deleted the feat/runtime-host-canonical-memory-authority branch July 29, 2026 15:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@M4n5ter@likun666661@Astro-Han