You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/architecture/rfcs/cross-session-memory-substrate-v0.md
+54-9Lines changed: 54 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@
4
4
5
5
Stage A shipped in [#4094](https://github.com/huangruiteng/loopx/pull/4094), merge `2ebd921ee989f7c696a7214ba1176d3bd5de6fb3`. The historical filename does not imply that a generic memory substrate shipped. The [capable manager and semantic handoff RFC](capable-manager-semantic-handoff-v0.md#513-integrate-shipped-explicit-continuation-4094) includes this implementation in its M2/M3 refactor scope. That successor remains proposed; this document remains the shipped CLI compatibility and authority reference until its replacement qualifies.
6
6
7
-
Reuse rich/legacy context and the existing note validator/claim transfer boundary. Receiver acceptance of a suggestion is distinct from `handoff adopt` ownership mutation. Stage A's note is replaceable current Todo state, not a private immutable history. The successor maps authorized context to a recoverable brief, references current work, and supplies general assessment/result/automatic-return relations without adding a memory ledger or copying claim authority. CLI `prepare/inspect/adopt` remains usable during migration; frontend/Lark and automatic host continuation must be qualified separately. Same-host, registered-agent, lease-free restrictions continue to apply to this adapter, not every general request. See successor §5.13 for mappings, migration conditions and retained negative cases.
7
+
Reuse rich/legacy context and the existing note validator/claim transfer boundary. Receiver acceptance of a suggestion is distinct from `handoff adopt` ownership mutation. Stage A's note is replaceable current Todo state, not a private immutable history. The successor maps authorized context to a recoverable brief, references current work, and supplies general assessment/result/automatic-return relations without adding a memory ledger or copying claim authority. CLI `prepare/inspect/adopt` remains usable during migration; frontend/Lark and automatic host continuation must be qualified separately. Same-host and registered-agentrestrictions continue to apply to this adapter, not every general request. Leased execution uses the explicit transfer path below. See successor §5.13 for mappings, migration conditions and retained negative cases.
8
8
9
9
The successor [§5.7](capable-manager-semantic-handoff-v0.md#57-session-and-product-continuity) now distinguishes same-session resume, same-Agent session replacement and cross-Agent takeover. Only the last may require this adapter’s ownership mutation. Automatic brief capture, source-loss recovery, executable-session fencing and original-route result return are explicit future integration work; optional Obelisk recall supplies missing historical evidence, not a replacement transfer grant.
10
10
@@ -32,8 +32,7 @@ require a different product layer beyond this control-plane primitive.
32
32
## Ownership and placement
33
33
34
34
The existing Todo coordination boundary owns current execution state, stable
35
-
Todo IDs, revision checks and claim/lease decisions. The built-in local
36
-
`file_v0` authority supplies persistence; no new capability, provider, database,
35
+
Todo IDs, revision checks and claim/lease decisions. The selected canonical File/SQLite authority supplies persistence; no new capability, provider, database,
37
36
index, discovery API, recovery service or ownership protocol is introduced.
38
37
The CLI is a host adapter to that TypeScript boundary.
39
38
@@ -44,11 +43,12 @@ nor grants permission to index a workspace or read source-reference bodies.
44
43
45
44
## First usable path
46
45
47
-
Prerequisites: an **already explicitly promoted local file authority**, an open,
48
-
active agent Todo claimed by a registered agent, and no lease on that Todo.
49
-
The existing metadata writer cannot prove lease-bearing updates, so Stage A
50
-
rejects hard-lease goals and lease-bearing Todos. It never promotes authority,
51
-
changes handoff mode, releases another owner's work or falls back to Markdown.
46
+
Prerequisites: an **already explicitly promoted canonical authority** and an
47
+
open, active Agent Todo claimed by a registered Agent. Lease-free adoption
48
+
retains the existing claim transaction. Hard-lease work requires the exact
49
+
current execution proof; ownership moves only through the existing atomic
50
+
`task-lease transfer --transfer-claim` command. This adapter never promotes a
51
+
Goal, changes its handoff mode or falls back to Markdown.
52
52
53
53
The user explicitly hands a Todo from one session to another session of a
54
54
**different registered agent on the same host**. The source writes a revision-
@@ -105,6 +105,51 @@ ID, invokes the existing claim transaction and reads back current authority.
105
105
A same-owner claim may correctly be a no-op; it does not create a Todo or
106
106
manufacture a new lease.
107
107
108
+
## Leased execution continuation
109
+
110
+
Prepare while the sender still owns the claim and lease. Pass the current
111
+
`--task-lease-idempotency-key` and `--task-lease-expected-version` pair to prepare.
112
+
Use actual readback versions; the example assumes source version 3.
# Explicit leased continuation closes a canonical CLI gap
2
+
3
+
For #4574 G1/G2 and the shared-authority L2/L3 program, the explicit handoff
4
+
caller still rejected every hard-lease Todo even though metadata updates and
5
+
atomic claim/lease transfer already owned the necessary execution proof. It
6
+
also left committed prepare/adopt state waiting for Markdown delivery.
7
+
8
+
The same-host CLI now composes those existing owners: prepare with current
9
+
proof, transfer claim and lease atomically, then receive context under the new
10
+
execution proof. Transfer rebinds only a note valid against its original work
11
+
facts. Leased adoption writes a context receipt without changing claim/lease;
12
+
receipt replay is separately checked against current execution and acceptance.
13
+
Python retains host file IO and projection delivery; the closed context schema
14
+
and lease/claim decisions stay in TS. The lease-free path remains compatible.
15
+
16
+
The [operating contract](../../cross-session-memory-substrate-v0.md#leased-execution-continuation)
17
+
describes proof flags, retry/readback and the explicit host/session boundary.
18
+
This is not automatic delegation, host launch, independent result acceptance,
19
+
external-effect fencing or completion of the manager handoff RFC. No new UI
20
+
control is required for this existing CLI-only workflow. Existing Todo display
21
+
consumers receive the same record schema via permanent projection.
22
+
23
+
## Remaining local-default program
24
+
25
+
Retain the conditional **5–8 cohesive packages**, including integration of
26
+
already-open prerequisites. This completes one real caller path within L2/L3
27
+
and fixes its display delivery; it does not retire either entire package.
28
+
SQLite remains the long-lived default candidate, File the reference/explicit
29
+
profile. “New Goal default”, “migrate existing Goals” and “delete all Python”
30
+
are separate outcomes.
31
+
32
+
| Package | Estimate | Observable completion |
33
+
| --- | --- | --- |
34
+
| Remaining CLI/Turn/Chat callers and actual effects | 1–2 | Close the command matrix, exact execution proof and external-effect boundary; remove each replaced Python business rule with its last caller. |
35
+
| Consumer and permanent projection integration | 1 | Full readback/pagination and display recovery through affected packaged entry points; stale or missing Markdown cannot become authority. |
36
+
| SQLite D2 qualification, contributor-owned #4224/#4931| 1–2 | Capacity/receipt/scan budgets, crash/restore/upgrade, platform coverage, consumer lag and at least ten genuinely elapsed days of soak. |
37
+
| Source capture plus whole-Goal migration | 1–2 | Sustained mixed writers and event-only coverage, drain/fence/readback, cohort rehearsal and recoverable export/rollback. |
38
+
| Default selection and legacy writer retirement | 1 | New-Goal creation/settings/install choose the qualified profile; explicit choices survive; obsolete business writers retire after migration windows close. |
39
+
40
+
These are delivery packages, not a prediction that five more arbitrary small
41
+
PRs finish migration. The elapsed soak cannot be replaced by accelerated tests.
42
+
PostgreSQL shares typed command semantics and real backend conformance, but
43
+
service authentication, tenant isolation, operations, restore/failover and
44
+
capacity remain an independent medium-term qualification. Permanent Markdown
45
+
rendering, import/export and host adapters are not duplicate business owners.
0 commit comments