Skip to content

feat: align LCM with Codex continuity and whitepaper control flow - #215

Closed
100yenadmin wants to merge 2 commits into
mainfrom
upstream/pr-527
Closed

100yenadmin wants to merge 2 commits into
mainfrom
upstream/pr-527

Conversation

@100yenadmin

Copy link
Copy Markdown
Member

Important

This executable LCM-X PR was recreated by the migration operator from the exact upstream commit head. GitHub did not transfer the original PR actor, dates, review objects, or approval state.

Source and attribution

@coderabbitai ignore

Original commit authorship and history remain in the commits. Historical discussion and review text are imported below as attributed ordinary comments; they are not new approvals or change requests.

Original upstream PR description

Summary

  • add lossless opaque Codex reasoning and native-compaction continuity without exposing capsules through FTS, summaries, inspection, or expansion
  • add explicit soft/hard compaction, deterministic convergence, file lineage, and persistent llm_map / agentic_map operators
  • make concurrent SQLite ownership and lock recovery durable, and bound restart reconciliation over large externalized-output archives

Why

Long-running concurrent gateway sessions exposed two production failures: restart reconciliation repeatedly scanned a 12,799-file, roughly 540 MB archive, and cloned engines could contend over independently owned SQLite helpers. The first failure pushed a 590K-token resume beyond the 30-second host timeout. The bounded lookup and per-pass identity cache reduce that reconciliation to roughly 2 seconds while preserving every source row and externalized payload.

Validation

  • Focused validation: 483 passed
  • Default validation:
    • pytest tests/test_lcm_core.py tests/test_lcm_engine.py tests/test_packaging_install.py -q
    • pytest -q: 2,846 passed, 1 skipped
    • low-FD pytest at ulimit -n 1024: 2,846 passed, 1 skipped
    • scripts/validate_release.sh --full --keep-going: all gates passed
    • benchmark smoke, stress smoke, and release stress tier: zero failures
    • git diff checks for origin/main...HEAD, working tree, and staged tree
    • Python compileall, script py_compile, and shell syntax checks
  • Workflow validation not applicable: workflow files are unchanged

Notes

  • Scope is broad because the storage, compaction, provider-state, and operator invariants share one schema and lifecycle boundary; the commit keeps the existing plugin name, engine name, and database path compatible.
  • Background compaction remains opt-in.
  • The separate Hermes gateway-core teardown patch is intentionally excluded from this plugin PR.
  • Validation started and ended with a clean git status.

Add provider-native Codex continuity, deterministic map operators, shared storage ownership, durable lock recovery, large-file lineage, bounded restart reconciliation, and explicit soft/hard compaction behavior while preserving existing Hermes plugin and storage compatibility.

Constraint: Preserve plugin name, context engine name, and database compatibility

Rejected: Raise compression timeouts | leaves archive scanning unbounded and masks the restart defect

Confidence: high

Scope-risk: broad

Reversibility: clean

Directive: Keep opaque provider capsules out of FTS, summaries, inspection, and public expansion

Tested: 2,846 tests passed with one expected skip; Ruff; compileall; shell syntax; live 590K-token gateway auto-resume

Not-tested: GitHub Actions Python 3.13/3.14 runners before PR publication
Restarted gateway sessions can contain thousands of replay rows, transient host placeholders, and rewritten Discord messages. Reconcile them with linear-time prefix/suffix matching, a conservative durable-tail anchor for very large histories, and an indexed tool-result archive lookup.

Constraint: Preserve ambiguous short deltas and immutable stored payloads
Rejected: Raise the 30-second timeout | masks quadratic work and continued duplicate ingestion
Confidence: high
Scope-risk: moderate
Reversibility: clean
Directive: Keep the 4096/1024 large-replay anchor conservative unless production evidence and replay-safety tests justify changes
Tested: 1071 core and engine tests; exact 8964-message production replay in 2.136 seconds; 9000-message mismatch in 0.14 seconds
Not-tested: Destructive cleanup of pre-existing duplicate LCM rows
@100yenadmin 100yenadmin added active-continuation Active continuation of an attributed upstream item data-integrity Durable or active-context correctness and ownership defect eva-direct Direct impact on Electric Sheep supported Hermes/LCM paths P2 Significant supported-path regression or bounded correctness failure triage-pending New upstream item awaiting LCM-X classification upstream-evidence Preserves links and attribution to the upstream report or pull request upstream-pr Imported upstream pull-request evidence labels Aug 16, 2026
@100yenadmin

Copy link
Copy Markdown
Member Author

Triage: this is one of three open PRs implementing the same architectural change — flagging so it is not reviewed in isolation.

#197, #202 and #215 each introduce a shared, reference-counted SQLite storage bundle across LCM engine clones. All three necessarily relax the same documented guarantee — that a clone owns isolated storage — by removing the six clone._store is not prototype._store / _dag / _lifecycle assertions at tests/test_lcm_core.py:7495 and :7538.

To be clear, that is not test-hiding, and I checked before saying so: all three add replacement assertions for the new invariant (9, 8 and 11 respectively — clone-local session state, one idempotent lease per engine, owner-first shutdown). This is a legitimate contract change with coverage.

The motivation is real and measured, from #197: ten retained clones cost 60 file descriptors and roughly 100 ms of duplicate SQLite helper construction, which risks descriptor exhaustion under parallel child-agent workloads. That is the defect tracked as #9.

So the problem is not any one of these PRs — it is that there are three. Reviewing them independently would mean deciding the same architecture question three times, and merging any one of them makes the other two conflict against a moved contract. The maintainer action is to pick one design, land it, and close the other two with evidence.

This needs an owner/architecture call, because it changes a documented guarantee for every embedder of the engine. It is not a call I will make unilaterally as maintainer. Recorded on #9 as the tracking issue; holding all three until it is decided.

@100yenadmin

Copy link
Copy Markdown
Member Author

Closed superseded by the owner-ratified storage-trio decision: #197 is the pick (memo + ratification on #9, 2026-08-20). Reopenable — this records a product decision, not a merit refutation. The Codex-continuity/whitepaper control-flow ideas herein remain referenced from the memo for future consideration.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

active-continuation Active continuation of an attributed upstream item data-integrity Durable or active-context correctness and ownership defect eva-direct Direct impact on Electric Sheep supported Hermes/LCM paths P2 Significant supported-path regression or bounded correctness failure triage-pending New upstream item awaiting LCM-X classification upstream-evidence Preserves links and attribution to the upstream report or pull request upstream-pr Imported upstream pull-request evidence

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants