Commit graph

5 commits

Author SHA1 Message Date
Ouroboros
932bf095a9 Close the delta-review findings: unread live log, rendered notes, child citation, processing copy
An unreadable live log (a stat error other than "missing") no longer reads
as "window: whole live file": the coverage carries no window facts, so the
header says "unread" beside the unreadable_source gap, while a log that was
never written stays an empty window without a gap. The rendered note is now
formatter-specific: progress says "newest 50 rendered of N loaded", tools
says "10 rendered, 20 scanned for review markers", events never claims a
scan. A child's progress window cites "canonical logs/progress.jsonl" beside
its task-drive tools and events. invocation_record deep-copies the memo row's
processing dict like its neighbours. The locator test now exercises the
delegate_pending.request_body call site with a foreign locator; a test
comment and the ARCH §1 memo row are corrected.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-22 02:56:42 +03:00
Ouroboros
cb41536c5e Give subagent children their own recent-activity windows
A child received only the Working sources block and no Recent
progress/tools/events at all, so across a retry or a compacted long
delegation it had no compact memory of its own process. The loop that builds
the three windows now lives in Memory.recent_activity_sections; a child
reads tools and events from its own execution drive (exactly its worker
rows; the header says host-side rows such as waits stay in the canonical
log) and progress from the canonical log filtered by task, beside the
Working sources block, which now says so. A child on the canonical drive
reads the canonical filtered windows like a root. Owner decision during the
sprint, 2026-09-22.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-22 02:12:35 +03:00
Ouroboros
9f724f26e0 Close the scope-review findings: locator binding, empty-window disclosure, rendered counts
- a compacted row's legacy request body is re-read only if the located line
  names the same invocation, so a rotation can never hand one invocation
  another's body (an unknown body keeps the invocation pending);
- a recent-activity section whose bounded window found no matching row but
  left older archives unopened is still disclosed with its coverage line;
- the tools header says what the formatter renders (10) beside what it
  selects and scans for review markers (20); the architecture sentence says
  the same.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-22 02:02:07 +03:00
Ouroboros
36b46f35b6 Close the review findings on the custody memo and the recent windows
Triad (codex astra, cursor grok, native fable) findings on 8aff64791:
- the live file's consumed prefix is hashed at fold time and re-verified
  before every advance, so an in-place rewrite followed by an append
  refolds instead of serving stale rows (growth alone proved nothing);
- the chain enumeration pins the live file by inode before listing the
  archives and skips its archive alias, and every open is identity-checked,
  so a rotation inside the enumerate/open window refolds or falls back to
  the lenient full scan instead of serving an amputated chain or an empty
  snapshot keep-set;
- records built from memo rows (pending invocations, invocation records,
  replay clones) copy their nested containers; the memo rows are documented
  read-only;
- a recent-activity section whose window met gaps is disclosed even when
  no row survived; the coverage line says "all" only when the whole live
  file was read and no archive was left unopened, names the log, and reads
  "unread" on a failed read; the Supervisor section carries the same line;
  task reflections use the bounded reader too;
- the unreadable-archive tests simulate the denial portably (no chmod);
- the one-scan test counts memo refreshes, the gateway wrapper reuses
  ARCHIVE_BACKFILL_MAX, ARCHITECTURE names replay-class consumers.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-22 01:53:03 +03:00
Ouroboros
8aff64791d Bound the custody replay and the recent-activity windows per task
Every delegated-run custody question (delegate_wait, delegate_start, task
start, completion evidence, audits) re-read the whole rotated events chain
(160 segments, 329 MB on a long-lived install, ~0.6 s CPU per call). A new
process-local memo (ouroboros/delegate_custody_memo.py, the usage-memo shape)
keeps the custody rows behind delegate_custody.custody_rows: an ordered
(st_dev, st_ino, consumed, st_mtime_ns) fingerprint of the folded chain
prefix, only appended bytes folded on later reads, a refold on any doubt, a
bypass while the chain is unreadable, legacy inline request bodies replaced
by a locator delegate_pending.request_body re-reads. Every reader (replay,
run_timing, pending_invocations, invocation_record, unsettled_start_ids,
review custody recovery, payload holders, execution evidence and patch
dispositions) consumes it; replay() results are cloned per caller. Warm
reads drop from ~0.6 s to milliseconds on the same chain; the fold is
verified equal to a full replay across appends, rotations, torn tails and
chain anomalies.

The recent-activity context sections read a global 200-row tail of the
progress/tools/events logs, parsed whole, then filtered by task id, so under
many concurrent tasks a task saw whatever share of the shared suffix it
happened to occupy. They now read each task's own newest rows (progress 50,
tools 20, events 200) through the bounded rotation-aware reader, moved from
gateway/_helpers.py to the core leaf ouroboros/jsonl_tail.py (the gateway
keeps thin wrappers and its parser seam), and the header carries a coverage
line naming the window and any archives left unopened.

ARCHITECTURE and DEVELOPMENT describe both mechanisms; the events-chain
tripwire names the cold fold; chapter byte budgets are raised with reasons.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-22 01:23:52 +03:00