[codex] 0.18: decontaminate packet planning and repair the substrate - #2103
Conversation
Land the anti-contamination checker, docs, CI wiring, and failing black-box agent tests before planner deletion on the decontamination lane. Co-authored-by: Cursor <cursoragent@cursor.com>
Introduce Stage B graph planning with frozen initial limits and unit coverage for empty, connected, and vocabulary-only inputs. Co-authored-by: Cursor <cursoragent@cursor.com>
Delete domain flow classifiers, cleanup passes, and flow-template claim surfaces; keep generic seeds and Stage B repository evidence planning, and flip the generalization boundary gate to expect a clean head. Co-authored-by: Cursor <cursoragent@cursor.com>
Prove Stage B planning stays stable under rename, paraphrase, wrapper depth, multi-impl, distractors, truncated graphs, and six language paths. Co-authored-by: Cursor <cursoragent@cursor.com>
Lock Stage B constants after the visible metamorphic suite passed so later performance replay cannot silently retune relationship search bounds. Co-authored-by: Cursor <cursoragent@cursor.com>
Strip carrier-coupled evidence predicates to Never, delete unused scoring and probe leftovers, and ignore runtime packet tests that still expect deleted flow taxonomies. Co-authored-by: Cursor <cursoragent@cursor.com>
Stage sealed core generations under core/generations with atomic publication.json pointers and process-crash matrix coverage. Co-authored-by: Cursor <cursoragent@cursor.com>
Replay retrieval lexical base/delta compaction, incremental core wall receipts, and the incremental refresh microprobe onto the clean head. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Replace exact-candidate warm_ms=wallMs aliases with InstalledAgentTimingV1 phase fields and cohort ids shared across ABBA arms. Co-authored-by: Cursor <cursoragent@cursor.com>
Skip dense-anchor writes on sealed cores and advertise verify_indexed_direct_calls in plugin guidance and static checks. Co-authored-by: Cursor <cursoragent@cursor.com>
Strengthen the packet generalization boundary for ownership predicates, domain PacketEvidenceRole variants, and holdout probe spellings, then delete those production selection paths on a new r2 candidate. Co-authored-by: Cursor <cursoragent@cursor.com>
Delete holdout probe matcher/limit/alias tables that steered capping after the r2 Phase 9 FAIL, and strengthen the boundary checker to catch normalized and space-separated leakage shapes. Co-authored-by: Cursor <cursoragent@cursor.com>
Align publication proof filters and cache topology with the renamed immutable-generation crash matrix, keep CoW fail-closed in production while allowing a test-only stage copy on non-reflink filesystems, and restore the pinned retrieval-generalization job shape. Co-authored-by: Cursor <cursoragent@cursor.com>
Refresh release-claim graph digests after the proof-command rename, and update the incremental begin test to the unpublished-stage contract that keeps the inherited proof overlay. Co-authored-by: Cursor <cursoragent@cursor.com>
Delete fixed task_class_seed_queries injection, stop elevating soft plan seeds into sufficiency/required probes, and rank required probes by path/symbol identity only so soft token coverage cannot steer the cap. Co-authored-by: Cursor <cursoragent@cursor.com>
Keep PacketPlanQueryDto on the runtime lib path, drop unused seed/SQL helpers that trip deny-warnings, ignore formula-dispatch R6 tests, and sync the draft cache topology fixture so policy mutations still fire. Co-authored-by: Cursor <cursoragent@cursor.com>
Rewrite the sealed-receipt reuse lookup for clippy, enable a test-only full-copy fallback when CoW clone is unavailable, and stop writing published cores through the live path. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…ve-outs Co-authored-by: Cursor <cursoragent@cursor.com>
Stop fabricating continuation time from leftover wall clock, reconcile phases unrounded, and round once so warm_ms stays a measured sum. Co-authored-by: Cursor <cursoragent@cursor.com>
Drop the CoW write probe, derive clone_shared_bytes from apparent minus allocated, and scope unreadable subtrees instead of treating a blocked prefix as a full-scan zero. Co-authored-by: Cursor <cursoragent@cursor.com>
Copy the published core generation rather than leftover logical databases, then swap publication.json atomically so a crash cannot leave a mixed generation. Co-authored-by: Cursor <cursoragent@cursor.com>
Replace host-translated JSON with a grammar that owns its own clauses, fail closed when provenance is unavailable, and activate core-only for exact verification instead of starting embedding sidecars. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
|
Horizon A is accepted at exact head Independent adversarial review found no counterexample in the frozen boundary matrix. It directly covered renamed and encoded prompt steering, SQL synthesis and ranking, basename authority, magic evidence roles, pre-hydration admission of the seventeenth identity, unadmitted graph endpoints, the exact 16 KiB packet boundary, post-pointer committed/unconfirmed publication semantics, literal timing intervals, and the proof-enabled November 2024 transport path. All focused exact-head checks and required PR checks passed. This accepts the Horizon A foundation only. It makes no unseen-accuracy, performance, product-qualification, version, calibration, packaging, promotion, or release claim. Those remain downstream of #2106 and the accepted 0.18 qualification plan. The packaged CodeStory MCP was unavailable to the independent reviewer, so that review used ordinary source inspection and focused local tests. |
Outcome
Horizon A removes benchmark-shaped packet policy and repairs the trusted substrate without claiming that CodeStory 0.18 is useful or releasable yet.
The packet path now forwards ordinary wording unchanged to generic retrieval, admits at most sixteen stable identities from descriptor metadata before candidate hydration, exact-hydrates only those identities, and reports bounded source-backed evidence with
answer_sufficiency: not_asserted. Repository-derived packet compilation is deliberately absent from this PR and remains owned by #2106.Closes #2105
Refs #2098
Refs #2099
Refs #2104
Refs #2106
Base:
a41e605ea01e9e2c8b400eb5ee5456efd05f060eWhat changed
Packet decontamination and bounded admission
Publication, retrieval, and storage
CoreReadSessionreads.CorePublishTransactionreturn ordinary failure only before pointer replacement; post-replacement durability uncertainty is a committed result.Explicit verification and installed timing
verify_indexed_direct_callsas a separately invoked advanced surface with automatic routing disabled.retry_same_request, read-only tool annotations, and proof-enabled November 2024 transport coverage.InstalledAgentTimingV1intervals. Reused comparator rows remain timing-ineligible.How to review
Start with:
crates/codestory-contracts/src/compilation.rscrates/codestory-retrieval/src/candidate.rsandquery.rscrates/codestory-runtime/src/agent/packet_candidate.rscrates/codestory-runtime/src/agent/retrieval_primary.rscrates/codestory-runtime/src/agent/orchestrator.rscrates/codestory-runtime/src/agent/packet_compiler.rscrates/codestory-store/src/core_session.rscrates/codestory-contracts/src/call_path_public.rsscripts/lib/packet-generalization-boundary.mjsdocs/architecture/packet-generalization.mdThe critical boundary is:
No step after generic retrieval may inspect prompt terms or assign answer roles.
Verification
Focused source checks completed on exact head
62bc6f3f8d1d7291c6258f2639efc912cfe06bba:cargo clippy --workspace --lib --locked -- -D warnings— passedcargo test --locked -p codestory-contracts --lib— 123 passedcargo test --locked -p codestory-agent --lib --tests— 76 passedcargo test --locked -p codestory-retrieval --lib— 403 passed, 3 ignoredcargo test --locked -p codestory-runtime --lib— 824 passed, 4 ignoredcargo test --locked -p codestory-store --lib— 282 passedcargo test --locked -p codestory-cli --lib— 456 passed, 1 ignoredcargo test --locked -p codestory-cli --features proof-qualification-support --lib— 462 passed, 1 ignoredcargo test --locked -p codestory-cli --test architecture_contracts— 56 passedcargo test --locked -p codestory-cli --features proof-qualification-support --test architecture_contracts— 57 passedcargo test --locked -p codestory-cli --test stdio_protocol_contracts— 66 passedcargo test --locked -p codestory-cli --test cli_golden_path— 18 passedcargo fmt --all -- --check, andgit diff --check— passedIndependent adversarial review accepted exact head
62bc6f3f8d1d7291c6258f2639efc912cfe06bbaagainst the named Horizon Aboundary matrix, and every required PR check passed. Broad source
stabilization, performance qualification, and product acceptance deliberately
do not run on this support PR.
Non-claims
Those gates remain in #2106 and the 0.18 qualification plan. The published comparator remains 0.17.5.