Skip to content

Record scheduled memory learning and daily native lifecycle evidence - #116

Merged
seathatflowsinourveins merged 4 commits into
mainfrom
codex/memory-scheduled-evidence-20260923
Sep 25, 2026
Merged

seathatflowsinourveins merged 4 commits into
mainfrom
codex/memory-scheduled-evidence-20260923

Conversation

@seathatflowsinourveins

Copy link
Copy Markdown
Owner

The memory lifecycle handbook still described hourly learned writes and a future daily wake as unobserved. Record the actual September 23 native task heartbeat and bounded read-only follow-up. The existing hourly scheduler applied two pages, confirmed independently through its journal, proposal store and native MCP page reads. A later HTTP response-decoding failure has no persisted learning run and remains explicitly unresolved.

Retain sanitized native command/tool returns, genuine completed-session consolidation, exact source agreement for one SocratiCode result and QMD document, and an independent snapshot of the existing monitoring services. Add the dated memory checkpoint to the dashboard and rebuilt HTML handbook. Existing gateway/swap warnings, old token-counter timestamps, unknown restart persistence and absent quality/savings measurements stay visible. No installation, service restart, manual learning run, new monitor or broker action occurred.

Validation: 60 relevant project tests, public integrity/privacy validation and the generated HTML check passed under the host's bounded runner. Independent review caught journal identifiers before publication; the final output uses consistent aliases and retains the initial failed privacy check. These are project publication checks; prior upstream execution evidence is not relabeled as a new run.

Integrated with the latest published catalog layout: generated HTML remains ignored and is rebuilt locally/CI. The current base adds three relevant tests; all 63 passed. Its new sorted-manifest check identified two appended entries, resolved with the repository's supported manifest writer before publication.

seathatflowsinourveins added a commit that referenced this pull request Sep 23, 2026
…EAD) (#118)

gitleaks' git mode scans every fetched ref by default, and the job checks
out with fetch-depth 0, so one open branch's finding failed every other
pull request: PR #116's branch (four generic-api-key hits on 64-hex
fingerprint values, commit b801fe4) failed PR #117's required
secret-scan. Scanning HEAD's ancestry covers a pull request's merge commit
or main on push; each branch is still scanned by its own pull request.
Records the resolution of the scope decision .gitleaks.toml and
docs/github-automation.md had left to the coordinator.

Co-authored-by: seathatflowsinourveins <234074349+seathatflowsinourveins@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Heads-up from the coordinating session: #135 merged (35416786), and the main ruleset now requires the verdict-review-gate check. This branch predates it, so it has no job that reports that check and will stay blocked. Merge or rebase origin/main (at or after 35416786) into it to fix that. The gate passes trivially for a PR that changes no verdict rows. The earlier open item still stands: the gitleaks key field needs the Codex owner or the user (board #140).

@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Diagnosis of this PR's secret-scan failure, from the coordinating session.

The findings are false positives. All 4 are generic-api-key hits on "key": "<64-hex>" lines under learning.report.aggregate.repeated_rejection_fingerprints[] in observability/memory-scheduled-20260923.json. These are ai-memory's rejection_fingerprint values: hex_sha256 over normalized rejection fields (akitaonrails/ai-memory crates/ai-memory-store/src/auto_improve.rs). They are content digests, not credentials.

The fix is in #155. It adds a rule-scoped, exact-file, whole-line allowlist with regression tests showing that real api_key fields and other files stay detected. A local gitleaks dir over this PR's added files with #155's config reports no leaks.

What this PR then needs. Merge origin/main after #155 lands. That clears secret-scan and also brings the required verdict-review-gate job. Nothing on this branch was changed.

seathatflowsinourveins added a commit that referenced this pull request Sep 24, 2026
…rom generic-api-key (#155)

* Exempt ai-memory's SHA-256 rejection fingerprints in #116's evidence from generic-api-key

learning.report.aggregate.repeated_rejection_fingerprints[].key in
observability/memory-scheduled-20260923.json is ai-memory's rejection_fingerprint (hex_sha256 over
normalized rejection fields), a content digest. Rule-scoped, exact-file, whole-line allowlist with
regression tests (test_e, test_e2) that an api_key in the file and the same lines elsewhere stay detected.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Pin the 4 reviewed rejection fingerprints by value; an unreviewed 64-hex key stays detected

Review of #155 (optional hardening, adopted): the allowlist names the 4 reviewed digests instead of any
64-hex value, like the QuantConnect entry, so a later value under "key" in the same file is still a
finding; test_e2 now asserts that case. Comment date aligned to 2026-09-23.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Run the gitleaks allowlist regression tests in CI with the pinned binary (Codex review of #155)

The validate job has no gitleaks, so tests/test_gitleaks_config.py skipped entirely in CI. The
secret-scan job now runs it with the pinned binary on PATH and GITLEAKS_TESTS_REQUIRED=1, under
which a missing binary fails instead of skipping; test_workflow_hardening pins the step.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: seathatflowsinourveins <234074349+seathatflowsinourveins@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

#155 has merged (e2f014fd), so this PR's secret-scan blocker is resolved on main. The 4 reviewed rejection-fingerprint lines are exempt by exact value, and the allowlist's regression tests now run in CI with the pinned gitleaks: 19 tests OK. To go green, merge origin/main into this branch. That also brings the required verdict-review-gate job.

Resolves conflicts in manifests/evidence.json (both branches' additive
receipts and files[] entries kept) and observability/grand-dashboard/state.json
(recorded_at_utc taken from main's later checkpoint; both sides' lane content
was already preserved by git's auto-merge). sha256/bytes for the touched
files[] entries were regenerated with scripts/host_receipts.py's
register_file() helper rather than hand-typed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@seathatflowsinourveins seathatflowsinourveins added the lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers label Sep 24, 2026
seathatflowsinourveins added a commit that referenced this pull request Sep 25, 2026
…ory assistant capture opt-in, ignore Claude Code local state (#159)

* Adoption hygiene: native Claude Code pin is a floor (2.1.281), ai-memory assistant capture is opt-in, ignore Claude Code local state

bootstrap-macos.sh's install_native ran `"$bin" install <pin>` even when Claude Code's
native auto-updater had already installed something newer, so re-running the bootstrap
downgraded it. It now keeps a ~/.local/bin/<bin> whose --version is at or above the pin
(logs "Kept", downloads and installs nothing); a missing, older or unreadable launcher
takes the unchanged checksum-verified install. The check lives inside install_native
because tests/test_adoption_bootstrap.py runs that function on its own. Bash 3.2 safe.

Both claude-code pins move to 2.1.281 together (shared components keep one version on
both platforms). darwin-arm64 a922981f... comes from the official 2.1.281 manifest.json
and matches, byte for byte, the copy the native updater installed on a Mac. linux-x64
56fe3da8... comes from the same manifest and was not re-hashed; fetch() checks it before
running anything. 2.1.281 fixes a recursive rm of command-substitution output running
unprompted in auto and --dangerously-skip-permissions mode. The macOS page's pin table
and the generated new-host grand list follow the pins.

The Claude settings template no longer passes --capture-assistant to ai-memory's Stop
hook. render_config.py adds it only when AI_MEMORY_CAPTURE_ASSISTANT=true (host value
file or --set) and rejects any value other than true, false or empty. defaultMode and
skipDangerousModePermissionPrompt are unchanged.

.gitignore adds .claude/settings.local.json and .claude/worktrees/.

Not included, because open PRs #116, #145 and #151 own these files: the
manifests/evidence.json re-hash of the 12 changed files, and the adoption/bootstrap.md
"changed after `v2026.09.23.1`" marker for the three changed install inputs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Re-hash evidence and mark the Claude Code floor in the bootstrap guide

Records the SHA-256/byte entries for every file this branch changes and
adds the "changed after `v2026.09.23.1`" note that the docs-consistency
test requires for the new install behavior (pins 2.1.281, floor instead
of unconditional reinstall). Both files are also edited by open PRs;
whichever lands later re-runs the same host_receipts.register_file helper.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: seathatflowsinourveins <234074349+seathatflowsinourveins@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Scout <scout@local>
seathatflowsinourveins added a commit that referenced this pull request Sep 25, 2026
…loor (stacked on #159) (#177)

* Adoption hygiene: native Claude Code pin is a floor (2.1.281), ai-memory assistant capture is opt-in, ignore Claude Code local state

bootstrap-macos.sh's install_native ran `"$bin" install <pin>` even when Claude Code's
native auto-updater had already installed something newer, so re-running the bootstrap
downgraded it. It now keeps a ~/.local/bin/<bin> whose --version is at or above the pin
(logs "Kept", downloads and installs nothing); a missing, older or unreadable launcher
takes the unchanged checksum-verified install. The check lives inside install_native
because tests/test_adoption_bootstrap.py runs that function on its own. Bash 3.2 safe.

Both claude-code pins move to 2.1.281 together (shared components keep one version on
both platforms). darwin-arm64 a922981f... comes from the official 2.1.281 manifest.json
and matches, byte for byte, the copy the native updater installed on a Mac. linux-x64
56fe3da8... comes from the same manifest and was not re-hashed; fetch() checks it before
running anything. 2.1.281 fixes a recursive rm of command-substitution output running
unprompted in auto and --dangerously-skip-permissions mode. The macOS page's pin table
and the generated new-host grand list follow the pins.

The Claude settings template no longer passes --capture-assistant to ai-memory's Stop
hook. render_config.py adds it only when AI_MEMORY_CAPTURE_ASSISTANT=true (host value
file or --set) and rejects any value other than true, false or empty. defaultMode and
skipDangerousModePermissionPrompt are unchanged.

.gitignore adds .claude/settings.local.json and .claude/worktrees/.

Not included, because open PRs #116, #145 and #151 own these files: the
manifests/evidence.json re-hash of the 12 changed files, and the adoption/bootstrap.md
"changed after `v2026.09.23.1`" marker for the three changed install inputs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Re-hash evidence and mark the Claude Code floor in the bootstrap guide

Records the SHA-256/byte entries for every file this branch changes and
adds the "changed after `v2026.09.23.1`" note that the docs-consistency
test requires for the new install behavior (pins 2.1.281, floor instead
of unconditional reinstall). Both files are also edited by open PRs;
whichever lands later re-runs the same host_receipts.register_file helper.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Keep a newer native Claude Code on Linux/WSL2: the pin is a floor there too

adoption/bootstrap-linux.sh's install_native ran `"$bin" install <pin>`
unconditionally, so on a Linux/WSL2 host whose native updater (latest channel)
was ahead of the pin, re-running the bootstrap moved Claude Code back to the
pin and dropped newer fixes. install_native is now the same function as
bootstrap-macos.sh's (#159): a ~/.local/bin/<bin> whose --version first word
is a dotted numeric version at or above the pin is kept (nothing downloaded
or installed; install_pin logs "Kept installed ..." instead of "Installed
..."); a missing, older, non-numeric or failing launcher takes the unchanged
checksum-verified install.

Tests: NativeInstallFloorTests in tests/test_adoption_bootstrap.py run the
verbatim fetch/install_native/install_pin against a one-pin fixture (curl
shimmed; a shasum-backed sha256sum shim only where GNU --check --status is
missing), plus an identity check that both scripts share one install_native.

Docs: the Linux claude-code install_note describes the floor; bootstrap.md
step 2's stale "Linux/WSL2's script and pins are the same at v2026.09.23 as
on main" now says what differs at that tag; the claude-code floor notes on
bootstrap.md, linux-wsl2.md and macos-arm64.md name the currently pinned
release v2026.09.24.1 (#171), which the docs-consistency test requires.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* linux-wsl2.md: keep the changed-after marker on one line (docs-consistency)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: seathatflowsinourveins <234074349+seathatflowsinourveins@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Scout <scout@local>
# Conflicts:
#	manifests/evidence.json
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Merged current main into this branch (native-agent-stack-9a, foundation PR queue): kept the retained September 23 memory evidence, the lifecycle doc update and the additive memory-scheduled-learning gate row; manifests/evidence.json taken from main and the four changed files re-registered. validate.py passes; grand-dashboard, native-dashboard-data and new-host-grand-list tests: 49 OK.

@seathatflowsinourveins
seathatflowsinourveins enabled auto-merge (squash) September 25, 2026 17:05
@seathatflowsinourveins
seathatflowsinourveins merged commit 3ff5211 into main Sep 25, 2026
24 checks passed
@seathatflowsinourveins
seathatflowsinourveins deleted the codex/memory-scheduled-evidence-20260923 branch September 25, 2026 17:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant