| cell | test | backend | state | findings |
|---|---|---|---|---|
P1 | Two consecutive green sharded chain runs on `chain/promo6-ssh` with the #6795 load gate active (2 of 2: ea378d8b8 run 13:41→15:11Z; 574740a31 run 38062495071). Evidence: run URLs, shard budgets, watchdog margins. (0/2) | done | ||
P2a | Overload campaign against a release build, 50/200/1000 concurrent clients issuing store/recall/subscribe mixes while the host is CPU- and IO-saturated: p99 latency stays under the documented bound or the server refuses with a documented status | sqlite | todo | |
P2b | Overload campaign, same load: p99 latency stays under the documented bound or the server refuses with a documented status | postgres | todo | |
P2c | Overload campaign: no corruption or lost write after the run (`memory_verify` + row counts) | sqlite | todo | |
P2d | Overload campaign: no corruption or lost write after the run (`memory_verify` + row counts) | postgres | todo | |
P2e | Overload campaign: inflight permits drain to zero (the #6794 class) | sqlite | todo | |
P2f | Overload campaign: inflight permits drain to zero (the #6794 class) | postgres | todo | |
P2g | Overload campaign: memory and fd ceilings hold | sqlite | todo | |
P2h | Overload campaign: memory and fd ceilings hold | postgres | todo | |
P3 | Subscriber fan-out and webhook DLQ under contention (#6054 family): dispatch caps hold, no unbounded queue. | todo |
| cell | test | backend | state | findings |
|---|---|---|---|---|
F1a | Disk full (ENOSPC) during `memory_store`: the call returns an error, no partial row, no unsigned commit; recovery after space returns | sqlite | todo | |
F1b | Disk full (ENOSPC) during `memory_store`: the call returns an error, no partial row, no unsigned commit; recovery after space returns | postgres | todo | |
F1c | Disk full (ENOSPC) during WAL checkpoint: the call returns an error, no partial row, no unsigned commit; recovery after space returns | sqlite | todo | |
F1d | Disk full (ENOSPC) during WAL checkpoint: the call returns an error, no partial row, no unsigned commit; recovery after space returns | postgres | todo | |
F1e | Disk full (ENOSPC) during signed-commit write: the call returns an error, no partial row, no unsigned commit; recovery after space returns | sqlite | todo | |
F1f | Disk full (ENOSPC) during signed-commit write: the call returns an error, no partial row, no unsigned commit; recovery after space returns | postgres | todo | |
F2a | Process killed (SIGKILL) mid-transaction / mid-batch: on restart the store is consistent; `memory_verify` clean; lineage watermark agrees with rows (the #6983 class, this time from a product path) | sqlite | todo | |
F2b | Process killed (SIGKILL) mid-transaction / mid-batch: on restart the store is consistent; `memory_verify` clean; lineage watermark agrees with rows (the #6983 class, this time from a product path) | postgres | todo | |
F3a | Clock skew (system clock jumps backwards/forwards 1 h, 1 d) across store / recall / TTL expiry / signed-rule validity: no premature expiry, no accepted-then-rejected signatures, monotonic ordering preserved | sqlite | todo | |
F3b | Clock skew (system clock jumps backwards/forwards 1 h, 1 d) across store / recall / TTL expiry / signed-rule validity: no premature expiry, no accepted-then-rejected signatures, monotonic ordering preserved | postgres | todo | |
F4a | Backend unreachable mid-session (SQLite file locked): fail-closed with a documented error; no fall-through to a different store (`resolve_store_url` ladder untouched) | sqlite | todo | |
F4b | Backend unreachable mid-session (Postgres connection drop): fail-closed with a documented error; no fall-through to a different store (`resolve_store_url` ladder untouched) | postgres | todo | |
F5a | Corrupted on-disk state (truncated db, flipped byte in a signed rule): detected and refused, never partially loaded | sqlite | todo | |
F5b | Corrupted on-disk state (truncated db, flipped byte in a signed rule): detected and refused, never partially loaded | postgres | todo |
| cell | test | backend | state | findings |
|---|---|---|---|---|
X1a | Batch store: inject a failure at row k of n; the resulting visible state is identical to the other backend (all-or-nothing on both, or the same documented partial contract), with error type/message parity and the audit record written [sqlite] (divergence #7090 #7099; harness PR #7100) | todo | #7090 | |
X1b | Batch store: inject a failure at row k of n; the resulting visible state is identical to the other backend, with error type/message parity and the audit record written [postgres] (divergence #7090 #7099; harness PR #7100) | todo | ||
X2a | Consolidate: failure at row k of n leaves state identical across backends, error parity, audit record [sqlite] (divergence #7091 #7092; harness PR #7100) | todo | #7091 #7092 | |
X2b | Consolidate: failure at row k of n leaves state identical across backends, error parity, audit record [postgres] (divergence #7091 #7092; harness PR #7100) | todo | ||
X3a | Promote: failure at row k of n leaves state identical across backends, error parity, audit record [sqlite] (divergence #7093; harness PR #7100, cell lane pending) | todo | #7093 | |
X3b | Promote: failure at row k of n leaves state identical across backends, error parity, audit record [postgres] (divergence #7093; harness PR #7100, cell lane pending) | todo | ||
X4a | Forget: failure at row k of n leaves state identical across backends, error parity, audit record [sqlite] (divergence #7094; harness PR #7100, cell lane pending) | todo | #7094 | |
X4b | Forget: failure at row k of n leaves state identical across backends, error parity, audit record [postgres] (divergence #7094; harness PR #7100, cell lane pending) | todo | ||
X5a | Link/unlink: failure at row k of n leaves state identical across backends, error parity, audit record [sqlite] (divergence #7095; harness PR #7100, cell lane pending) | todo | #7095 | |
X5b | Link/unlink: failure at row k of n leaves state identical across backends, error parity, audit record [postgres] (divergence #7095; harness PR #7100, cell lane pending) | todo | ||
X6a | Import: failure at row k of n leaves state identical across backends, error parity, audit record [sqlite] (divergence #7096; harness PR #7100, cell lane pending) | todo | #7096 | |
X6b | Import: failure at row k of n leaves state identical across backends, error parity, audit record [postgres] (divergence #7096; harness PR #7100, cell lane pending) | todo | ||
X7a | Archive restore/purge: failure at row k of n leaves state identical across backends, error parity, audit record [sqlite] (divergence #7097; harness PR #7100, cell lane pending) | todo | #7097 | |
X7b | Archive restore/purge: failure at row k of n leaves state identical across backends, error parity, audit record [postgres] (divergence #7097; harness PR #7100, cell lane pending) | todo | ||
X8a | Lease ops: failure at row k of n leaves state identical across backends, error parity, audit record [sqlite] (divergence #7098; harness PR #7100, cell lane pending) | todo | #7098 | |
X8b | Lease ops: failure at row k of n leaves state identical across backends, error parity, audit record [postgres] (divergence #7098; harness PR #7100, cell lane pending) | todo |
| cell | test | backend | state | findings |
|---|---|---|---|---|
H1 | Make the ephemeral-base rule mechanical: `scripts/test/pg_isolated_binary.py setup` refuses `--db ai_memory_test` (or any non-ephemeral base) unless `--allow-shared-base` is passed with a reason; default creates `ci_base_<pid>_<ts>` exactly as ci.yml does at ~1105-1142. | todo | ||
H2 | A watermark/rows consistency precheck in `setup` (`lineage_integrity_watermark.high_water` vs `count(agent_lineage)`) that refuses with the #6983 diagnostic instead of cloning a poisoned base. | todo | ||
H3 | Identify which test truncated `agent_lineage` without resetting the watermark (open question from the #6983 triage) and fix that test or the truncation helper. | todo | #7086 | |
H4 | A unittest in `scripts/ci/tests/` for 1 and 2 (red first). | todo |
| work package | ticked / total | progress | umbrella |
|---|---|---|---|
| WP-SCHEMA Schema ladder, migrate/schema-init, schema-ahead/behind guards, pre-migration snapshots, store-version drift | 0/19 | 0.0% | #6046 |
| WP-SQLITE-TX Transaction atomicity: DEFERRED to IMMEDIATE, reads outside the write txn (TOCTOU), BUSY handling, lost counte | 0/26 | 0.0% | #6047 |
| WP-ERASURE Forget/delete/tombstone/erasure propagation, archived_memories snapshot model, re-admission of forgotten ids | 0/23 | 0.0% | #6048 |
| WP-FED Federation receive/merge/CRDT, quarantine release, version clamp, signal/transition replay, peer-identity | 0/46 | 0.0% | #6049 |
| WP-GOV Governance: pending/approve/escalate, namespace standards, chain depth, reflection gates, fail-open permission | 1/38 | 2.6% | #6050 |
| WP-FAULT Read faults reported as zero/false/empty (doctor, capabilities, fail-open checks) | 0/8 | 0.0% | #6051 |
| WP-SECRETS Credential channels: argv to file/env forms, store-url precedence, redaction/zeroize, key file modes | 0/25 | 0.0% | #6052 |
| WP-EGRESS Inference/webhook egress admission, DNS pin, SSRF classes, proxy/redirect, model downloads | 0/8 | 0.0% | #6053 |
| WP-WEBHOOK Webhook delivery durability (audit/DLQ at admission and shutdown), subscription validation, dispatcher stalls | 0/9 | 0.0% | #6054 |
| WP-CURATOR Curator/consolidation/decision client: rollback halting, stale snapshots, dry-run purity, breaker state | 0/14 | 0.0% | #6055 |
| WP-WAKE Wake-hub/inbox: counter leaks, stale-socket probe, SIGTERM drain, SSE seq exposure | 0/11 | 0.0% | #6056 |
| WP-KG Knowledge graph / AGE: stale AGE fallback, temporal ordering, timeline correctness, atomise idempotence | 0/12 | 0.0% | #6057 |
| WP-OPS Observability, audit sinks, signal handling, doctor accuracy, boot/health, signed-ledger warnings | 0/30 | 0.0% | #6058 |
| WP-WIRE HTTP/MCP/CLI wire contract: status-by-text classifiers, typed errors, tools/list schema, help text | 1/23 | 4.3% | #6059 |
| WP-PKG Packaging: systemd units, install, SDK constructor contracts | 1/6 | 16.7% | #6060 |
| WP-DOCS User-facing docs and Pages truthfulness: schema version, security claims, argv examples, PgBouncer guide | 0/52 | 0.0% | #6061 |
| WP-B3 Release build/supply chain: reproducible builds, feature-assert binding, workflow least-privilege, Intel mac l | 0/10 | 0.0% | #6062 |
| WP-B1 Certification evidence re-issue and cert tooling correctness (after code freeze) | 0/10 | 0.0% | #6063 |
| WP-B2 CHANGELOG and release notes accuracy (last) | 0/6 | 0.0% | #6064 |
consolidated / 2164)| node | agent | model | sector of work | state |
|---|---|---|---|---|
| f2 | reviewer-f2r | Claude Opus 5 | landing reviewer: reviews every lane before GOD merges; enforces signed commits, Justin identity, Base:/Co-Authored-By trailers and the full-range count gate | gone |
| f2 | rehearsal-f2h | Claude Opus 5 | builder: found-in-testing fix lanes (operator directive 2026-09-27 15:10Z: fix 100%, retest to 100%, document 1:1) | gone |
| f2 | deputy-tmux22 | Claude Opus 5.5 (fate_two) | DEPUTY / capacity pool: Claude builder subagents plus the Codex pools; found-in-testing fix and retest lanes (MCP lane retest-complete; #4134 awaits GOD ruling); code + security review of all Muse work; TypeSafe Jev inbox triage. The GA tag is operator-gated | gone |
| f2 | conductor | Claude Fable 5.1 (ai:god-f2) | conductor / sole merger. Promotion 5 MERGED 2026-10-08 (PR #6103, release/v1.0.0 = 26785a591, 512 SSH-signed commits; D5 #5045 resolved by the SSH re-sign cutover); D5 #5045 CLOSED; 165/165 fixed-on-rehearsal issues CLOSED with both SHAs; Promotion 6 carrier chain/promo6-ssh-r2 (208 commits) accumulating re-cut lanes; audit #6044 / consolidation (R5) continues. The GA tag is operator-gated | active |
| f2 | muse | muse-spark-1.3-contributor (Muse) | builder on graded trial: #4089 (CPU-bound embed/rerank inline on tokio workers in HTTP handlers). Never merges; tmux-22 reviews and approves, GOD merges | gone |
| f1 | astra-f1 | Codex pool (f1) | Codex worker pool on f1, state measured from the pool dir; the earlier quota note expired 2026-09-30 | stopped |
v1.0.1 or v1.1.0 and does not hold the release.#3806, the pluggable [decision] provider slot — a model class, not a vendor, configured in TOML, served by a hosted API, a customer-hosted endpoint, or an air-gapped local model. The stated cost of NOT admitting it: at GA, contradiction detection turns any preamble or refusal into false, synthesis emits delete verdicts with no probability and no abstain, and the curator consolidates and deletes sources with no judge at all.#3831 (scripts are Python, production components are Rust) is CLOSED — met; #3824 (only encrypted data in transit anywhere, loopback included), #3830 (encryption setup simple and manageable at every scale) and #3833 (top-shelf encryption documentation) now carry deferred-v1.x and are OUT of v1.0.0 scope. They are named here because a standard that was dropped from the release is a fact a reader is entitled to, and a board that quietly stopped listing them would be the more dishonest instrument. What remains in scope on the encryption line is #3709 (zero-config TLS — the easy path) and #3823 (refuse a non-loopback plaintext inference endpoint), both LANDED and promoted to release/v1.0.0 in promotion 3 (2026-09-23); each stays open by ruling until the GA tag. Issue counts on this page are measured on the work-package basis ruled in #6044.| #6083 | [BACKLOG] v1.0.1 — 22 items |
| #6084 | [BACKLOG] v1.1.0 — 64 items |
| #6085 | [BACKLOG] v1.x deferred — 174 items |
| #6086 | [BACKLOG] enhancement — 35 items |
| #6087 | [BACKLOG] feature — 11 items |