ai-memory v1.0.0 — GA burn-down

GA gate: campaigns 0/4 closed — release blocked until 4/4
GA readiness 63.4% — shipped on release/v1.0.0: 483 · fixed on carrier, awaiting Promotion 6: 161 · remaining in 19 work packages: 373 of 376.
How this is measured: GA readiness = (shipped on release + fixed on carrier + ticked work-package items) ÷ (shipped + fixed + total work-package items); on release/v1.0.0 = shipped ÷ the same denominator. On release/v1.0.0 today: 47.4% (fixed-on-carrier work reaches the release only when Promotion 6 merges).
Stage gates: 2 of 8 (GOD’s sequence to the tag):The operator tags v1.0.0 only when both are at 100%. Every number here is measured at generation time; the two stages no tool records yet (Phase B, full reviews) are read from a dated evidence file.

GA proof campaigns — hard gate (operator 2026-10-10)

GA gate: campaigns 0/4 closed — release blocked until 4/4 · cells ticked 0/44. Derived at run time from the four campaign issues and their findings; GA does not occur until all four are closed.

Campaign P — #7028 Performance under contention: prove bounded, non-DoS-able, live-under-contention on CI v2 and under an overload campaign

state OPEN · cells 0/10 · findings open 0 / closed 0
celltestbackendstatefindings
P1Two consecutive green sharded chain runs on `chain/promo6-ssh` with the #6795 load gate active (currently 0 of 2). Evidence: run URLs, shard budgets, watchdog margins. (0/2)todo
P2aOverload campaign against a release build, 50/200/1000 concurrent clients issuing store/recall/subscribe mixes while the host is CPU- and IO-saturated: p99 latency stays under the documented bound or the server refuses with a documented statussqlitetodo
P2bOverload campaign, same load: p99 latency stays under the documented bound or the server refuses with a documented statuspostgrestodo
P2cOverload campaign: no corruption or lost write after the run (`memory_verify` + row counts)sqlitetodo
P2dOverload campaign: no corruption or lost write after the run (`memory_verify` + row counts)postgrestodo
P2eOverload campaign: inflight permits drain to zero (the #6794 class)sqlitetodo
P2fOverload campaign: inflight permits drain to zero (the #6794 class)postgrestodo
P2gOverload campaign: memory and fd ceilings holdsqlitetodo
P2hOverload campaign: memory and fd ceilings holdpostgrestodo
P3Subscriber fan-out and webhook DLQ under contention (#6054 family): dispatch caps hold, no unbounded queue.todo

Campaign F — #7029 Failure injection: ENOSPC, kill mid-commit, clock skew, crash recovery on both backends

state OPEN · cells 0/14 · findings open 0 / closed 0
celltestbackendstatefindings
F1aDisk full (ENOSPC) during `memory_store`: the call returns an error, no partial row, no unsigned commit; recovery after space returnssqlitetodo
F1bDisk full (ENOSPC) during `memory_store`: the call returns an error, no partial row, no unsigned commit; recovery after space returnspostgrestodo
F1cDisk full (ENOSPC) during WAL checkpoint: the call returns an error, no partial row, no unsigned commit; recovery after space returnssqlitetodo
F1dDisk full (ENOSPC) during WAL checkpoint: the call returns an error, no partial row, no unsigned commit; recovery after space returnspostgrestodo
F1eDisk full (ENOSPC) during signed-commit write: the call returns an error, no partial row, no unsigned commit; recovery after space returnssqlitetodo
F1fDisk full (ENOSPC) during signed-commit write: the call returns an error, no partial row, no unsigned commit; recovery after space returnspostgrestodo
F2aProcess killed (SIGKILL) mid-transaction / mid-batch: on restart the store is consistent; `memory_verify` clean; lineage watermark agrees with rows (the #6983 class, this time from a product path)sqlitetodo
F2bProcess killed (SIGKILL) mid-transaction / mid-batch: on restart the store is consistent; `memory_verify` clean; lineage watermark agrees with rows (the #6983 class, this time from a product path)postgrestodo
F3aClock skew (system clock jumps backwards/forwards 1 h, 1 d) across store / recall / TTL expiry / signed-rule validity: no premature expiry, no accepted-then-rejected signatures, monotonic ordering preservedsqlitetodo
F3bClock skew (system clock jumps backwards/forwards 1 h, 1 d) across store / recall / TTL expiry / signed-rule validity: no premature expiry, no accepted-then-rejected signatures, monotonic ordering preservedpostgrestodo
F4aBackend unreachable mid-session (SQLite file locked): fail-closed with a documented error; no fall-through to a different store (`resolve_store_url` ladder untouched)sqlitetodo
F4bBackend unreachable mid-session (Postgres connection drop): fail-closed with a documented error; no fall-through to a different store (`resolve_store_url` ladder untouched)postgrestodo
F5aCorrupted on-disk state (truncated db, flipped byte in a signed rule): detected and refused, never partially loadedsqlitetodo
F5bCorrupted on-disk state (truncated db, flipped byte in a signed rule): detected and refused, never partially loadedpostgrestodo

Campaign X — #7030 Cross-backend failure-semantics parity: a half-failed batch leaves identical state on SQLite and Postgres

state OPEN · cells 0/16 · findings open 0 / closed 0
celltestbackendstatefindings
X1aBatch store: inject a failure at row k of n; the resulting visible state is identical to the other backend (all-or-nothing on both, or the same documented partial contract), with error type/message parity and the audit record writtensqlitetodo
X1bBatch store: inject a failure at row k of n; the resulting visible state is identical to the other backend, with error type/message parity and the audit record writtenpostgrestodo
X2aConsolidate: failure at row k of n leaves state identical across backends, error parity, audit recordsqlitetodo
X2bConsolidate: failure at row k of n leaves state identical across backends, error parity, audit recordpostgrestodo
X3aPromote: failure at row k of n leaves state identical across backends, error parity, audit recordsqlitetodo
X3bPromote: failure at row k of n leaves state identical across backends, error parity, audit recordpostgrestodo
X4aForget: failure at row k of n leaves state identical across backends, error parity, audit recordsqlitetodo
X4bForget: failure at row k of n leaves state identical across backends, error parity, audit recordpostgrestodo
X5aLink/unlink: failure at row k of n leaves state identical across backends, error parity, audit recordsqlitetodo
X5bLink/unlink: failure at row k of n leaves state identical across backends, error parity, audit recordpostgrestodo
X6aImport: failure at row k of n leaves state identical across backends, error parity, audit recordsqlitetodo
X6bImport: failure at row k of n leaves state identical across backends, error parity, audit recordpostgrestodo
X7aArchive restore/purge: failure at row k of n leaves state identical across backends, error parity, audit recordsqlitetodo
X7bArchive restore/purge: failure at row k of n leaves state identical across backends, error parity, audit recordpostgrestodo
X8aLease ops: failure at row k of n leaves state identical across backends, error parity, audit recordsqlitetodo
X8bLease ops: failure at row k of n leaves state identical across backends, error parity, audit recordpostgrestodo

Campaign H — #7031 Test-lane hygiene gate: live-PG lanes must template from an ephemeral base db; shared ai_memory_test contamination (#6983) becomes a CI-enforced rule

state OPEN · cells 0/4 · findings open 0 / closed 0
celltestbackendstatefindings
H1Make the ephemeral-base rule mechanical: `scripts/test/pg_isolated_binary.py setup` refuses `--db ai_memory_test` (or any non-ephemeral base) unless `--allow-shared-base` is passed with a reason; default creates `ci_base_<pid>_<ts>` exactly as ci.yml does at ~1105-1142.todo
H2A watermark/rows consistency precheck in `setup` (`lineage_integrity_watermark.high_water` vs `count(agent_lineage)`) that refuses with the #6983 diagnostic instead of cloning a poisoned base.todo
H3Identify which test truncated `agent_lineage` without resetting the watermark (open question from the #6983 triage) and fix that test or the truncation helper.todo
H4A unittest in `scripts/ci/tests/` for 1 and 2 (red first).todo
Basis = the 19 GA work-package umbrellas #6046–#6064 ruled in #6044 (R5/R6): ticked checklist items over total checklist items in each umbrella, summed. The old ga-blocker / found-in-testing label count is retired. Generated from live repository and issue state.
Last updated 2026-10-10T16:36:01Z · release 26785a591 tip commit dated 2026-10-07 · carrier (chain/promo6-ssh-r2) 574740a31
483 shipped on release/v1.0.0161 fixed on carrier + 3 work-package items ticked373 remaining
647 of 1020 complete · 63.4%

Promotion state

26785a591release tip (release/v1.0.0)
574740a31carrier tip (chain/promo6-ssh-r2)
+404 / -0carrier vs release (ahead / behind)
openPromotion 6 (chain/promo6-ssh-r2 -> release); Promotion 5 merged as #6103
RUN_DONEgate table

GA work packages — 3/376 items ticked (63.4%)

work packageticked / totalprogressumbrella
WP-SCHEMA
Schema ladder, migrate/schema-init, schema-ahead/behind guards, pre-migration snapshots, store-version drift
0/190.0%#6046
WP-SQLITE-TX
Transaction atomicity: DEFERRED to IMMEDIATE, reads outside the write txn (TOCTOU), BUSY handling, lost counte
0/260.0%#6047
WP-ERASURE
Forget/delete/tombstone/erasure propagation, archived_memories snapshot model, re-admission of forgotten ids
0/230.0%#6048
WP-FED
Federation receive/merge/CRDT, quarantine release, version clamp, signal/transition replay, peer-identity
0/460.0%#6049
WP-GOV
Governance: pending/approve/escalate, namespace standards, chain depth, reflection gates, fail-open permission
1/382.6%#6050
WP-FAULT
Read faults reported as zero/false/empty (doctor, capabilities, fail-open checks)
0/80.0%#6051
WP-SECRETS
Credential channels: argv to file/env forms, store-url precedence, redaction/zeroize, key file modes
0/250.0%#6052
WP-EGRESS
Inference/webhook egress admission, DNS pin, SSRF classes, proxy/redirect, model downloads
0/80.0%#6053
WP-WEBHOOK
Webhook delivery durability (audit/DLQ at admission and shutdown), subscription validation, dispatcher stalls
0/90.0%#6054
WP-CURATOR
Curator/consolidation/decision client: rollback halting, stale snapshots, dry-run purity, breaker state
0/140.0%#6055
WP-WAKE
Wake-hub/inbox: counter leaks, stale-socket probe, SIGTERM drain, SSE seq exposure
0/110.0%#6056
WP-KG
Knowledge graph / AGE: stale AGE fallback, temporal ordering, timeline correctness, atomise idempotence
0/120.0%#6057
WP-OPS
Observability, audit sinks, signal handling, doctor accuracy, boot/health, signed-ledger warnings
0/300.0%#6058
WP-WIRE
HTTP/MCP/CLI wire contract: status-by-text classifiers, typed errors, tools/list schema, help text
1/234.3%#6059
WP-PKG
Packaging: systemd units, install, SDK constructor contracts
1/616.7%#6060
WP-DOCS
User-facing docs and Pages truthfulness: schema version, security claims, argv examples, PgBouncer guide
0/520.0%#6061
WP-B3
Release build/supply chain: reproducible builds, feature-assert binding, workflow least-privilege, Intel mac l
0/100.0%#6062
WP-B1
Certification evidence re-issue and cert tooling correctness (after code freeze)
0/100.0%#6063
WP-B2
CHANGELOG and release notes accuracy (last)
0/60.0%#6064

Open issues — 852 open

852total open issues
7ship-defect
1release-process
0fixed-on-rehearsal
1deferred
10meta
1tooling
1996/2164 (92.2%)consolidation progress (issues labelled consolidated / 2164)
Bucket counts are open issues carrying that label, measured live; an issue may carry more than one. Rulings: #6044.

Coding agents — who is running where

nodeagentmodelsector of workstate
f2reviewer-f2rClaude Opus 5landing reviewer: reviews every lane before GOD merges; enforces signed commits, Justin identity, Base:/Co-Authored-By trailers and the full-range count gategone
f2rehearsal-f2hClaude Opus 5builder: found-in-testing fix lanes (operator directive 2026-09-27 15:10Z: fix 100%, retest to 100%, document 1:1)gone
f2deputy-tmux22Claude Opus 5.5 (fate_two)DEPUTY / capacity pool: Claude builder subagents plus the Codex pools; found-in-testing fix and retest lanes (MCP lane retest-complete; #4134 awaits GOD ruling); code + security review of all Muse work; TypeSafe Jev inbox triage. The GA tag is operator-gatedgone
f2conductorClaude Fable 5.1 (ai:god-f2)conductor / sole merger. Promotion 5 MERGED 2026-10-08 (PR #6103, release/v1.0.0 = 26785a591, 512 SSH-signed commits; D5 #5045 resolved by the SSH re-sign cutover); D5 #5045 CLOSED; 165/165 fixed-on-rehearsal issues CLOSED with both SHAs; Promotion 6 carrier chain/promo6-ssh-r2 (208 commits) accumulating re-cut lanes; audit #6044 / consolidation (R5) continues. The GA tag is operator-gatedactive
f2musemuse-spark-1.3-contributor (Muse)builder on graded trial: #4089 (CPU-bound embed/rerank inline on tokio workers in HTTP handlers). Never merges; tmux-22 reviews and approves, GOD mergesgone
f1astra-f1Codex pool (f1)Codex worker pool on f1, state measured from the pool dir; the earlier quota note expired 2026-09-30stopped
Node and state are measured live (process working directories on f2, an SSH probe to f1); the sector column is maintained by the conductor and was last reviewed 2026-10-08.
Freeze boundary, current. The freeze zone is closed to ordinary work: an issue enters v1.0.0 scope only if it is a defect in something already in scope, or a regression, and admitting one requires publicly stating what it costs a paying customer. Everything else is v1.0.1 or v1.1.0 and does not hold the release.

One feature admitted, by operator order (2026-09-19): #3806, the pluggable [decision] provider slot — a model class, not a vendor, configured in TOML, served by a hosted API, a customer-hosted endpoint, or an air-gapped local model. The stated cost of NOT admitting it: at GA, contradiction detection turns any preamble or refusal into false, synthesis emits delete verdicts with no probability and no abstain, and the curator consolidates and deletes sources with no judge at all.

The four GA standards — current label state, measured 2026-09-22, not as first written. This block previously read “four standards are in freeze scope and required at 100%”. That is no longer true and is corrected here rather than left standing: #3831 (scripts are Python, production components are Rust) is CLOSED — met; #3824 (only encrypted data in transit anywhere, loopback included), #3830 (encryption setup simple and manageable at every scale) and #3833 (top-shelf encryption documentation) now carry deferred-v1.x and are OUT of v1.0.0 scope. They are named here because a standard that was dropped from the release is a fact a reader is entitled to, and a board that quietly stopped listing them would be the more dishonest instrument. What remains in scope on the encryption line is #3709 (zero-config TLS — the easy path) and #3823 (refuse a non-loopback plaintext inference endpoint), both LANDED and promoted to release/v1.0.0 in promotion 3 (2026-09-23); each stays open by ruling until the GA tag. Issue counts on this page are measured on the work-package basis ruled in #6044.

Deferred — the 5 backlog umbrellas (milestone v1.1.0), do not block the first customer

#6083[BACKLOG] v1.0.1 — 22 items
#6084[BACKLOG] v1.1.0 — 64 items
#6085[BACKLOG] v1.x deferred — 174 items
#6086[BACKLOG] enhancement — 35 items
#6087[BACKLOG] feature — 11 items
Gate: Conductor landing gate on ceb199f0e — 49 rows, 1 non-green, RUN_DONE · quiet 21374 min · 0 processes · disk 157G / 184G.