Skip to content

[stacked on #207] Write events as prose with the envelope in labels; let items opt out of derivation - #208

Merged
senamakel merged 7 commits into
tinyhumansai:mainfrom
M3gA-Mind:feat/prose-events-v3
Oct 6, 2026
Merged

senamakel merged 7 commits into
tinyhumansai:mainfrom
M3gA-Mind:feat/prose-events-v3

Conversation

@M3gA-Mind

Copy link
Copy Markdown
Collaborator

Summary

Events are now written as prose with the envelope in labels (v3), and an item can opt out of derivation.

Until now each CortexDB event's content.text was the whole JSON envelope: id, kind, full metadata and the item's text. The CortexDB team advises against that. JSON counts in full toward the 1 MiB limit, it extracts worse than plain sentences, and the ~500-byte search split happens at sentence boundaries, which JSON lacks. Their advice is the memory as natural-language text, with IDs and attributes in labels; context.labels is the documented app-metadata extension point.

Stacked on #207. It includes #207's two commits (it needs #207's split of cortex-wire.md to stay under the 500-line limit). Merge after #207; this PR's own change is the last commit.

Related issue

None. This is TM-5 and D from the CortexDB scoping review.

API or behavior changes

Breaking (needs a major release): tinymemory_api::MemoryMeta gains a public field, derive: Option<bool>. Adding a field breaks struct literals in downstream code (openhuman builds MemoryMeta { … } in places; ..MemoryMeta::default() keeps compiling).

  • It is #[serde(skip_serializing_if = "Option::is_none")], so an unset value is not serialized and existing fingerprints, item ids and stored envelopes are unchanged.
  • Some(false) stores and indexes the item, so it stays searchable, but asks the engine to derive nothing from it. On CortexDB that is directives.extract: [] (no facts, beliefs or concepts).
  • Every tool turn of a conversation is sent the same way: raw tool output is searchable, but it is not memory about the person.

Storage layout (v3), no API change:

  • content.text is the item's own text: the document body or piece, the turn's text, or the learning's statement.
  • context.labels holds, in order:
    • the existing lookup labels (tm:i: first);
    • readable labels, each at most 256 bytes or left out: kind:<kind>, file:<path>, and a piece's page:<n>/page:<a>-<b> and section:<title>. Never lang: (CortexDB reserves it);
    • the envelope with an empty text, as compact JSON in tm:e:<NN>: parts of at most 240 bytes each.
  • An event whose text is empty (CortexDB requires message text), or whose labels would be more than 64, is written as v2: the whole envelope as JSON text, as every event was before.
  • Reads take both layouts, so existing stores need no rewrite and v2 and v3 events can share a scope. An event with numbered tm:e: parts that join to a v3 envelope is v3; otherwise its text is tried as v2.
  • Size limits are still checked on the v2 JSON size (one rule for both layouts; a v3 text is never longer). Chunking is unchanged.
  • A hosted write whose outcome is unknown is now recovered by matching its labels as well as its text. Two v3 turns of one conversation can say the same words, and matching on text alone could take a different turn for the lost one and report it written.
  • The test double's recall no longer prefixes pack events with [role] . CortexDB 0.10.3 and 0.10.4 return the stored text in layers.events; the marker is only in context_block (API §9.4). The v2 decoder still tolerates the prefix.

Verified on the live harness (CortexDB 0.10.4):

  • labels round-trip verbatim (spaces, commas, Unicode, and 300-byte values);
  • recall packs carry them;
  • after the live suites, the stored events are v3, e.g. text Office pipeline marker 7391 with labels tm:i:…, kind:document, file:/office/brief.docx, tm:e:00:{"v":3,…}.

Validation

Local, at 73f5889, in a target dir of this worktree's own:

  • cargo fmt --all -- --check: ok
  • cargo clippy --all-targets --all-features -- -D warnings: ok
  • cargo build --all-targets --all-features: ok
  • cargo test --all-features: ok, 1123 passed
  • cargo test: ok, 435 passed
  • RUSTDOCFLAGS="-D warnings" cargo doc --no-deps --all-features: ok
  • cargo run -p tinymemory-integrations --example basic: ok
  • The CI "Refuse inline test code" script: ok
  • cargo llvm-cov … --fail-under-lines 80: ok, 94.14% lines
  • cargo hack --feature-powerset --depth 2 --workspace check --all-targets: ok
  • scripts/cortexdb-live.sh's three suites on a fresh local CortexDB v0.10.4: ok
  • live_cortexdb on 3 fresh servers: 3/3 passed

Revert-checks (each made its test fail, then restored; run before stacking on #207, on the same code):

  1. decoding ignores labels (v2 only): every_piece_and_turn_round_trips_through_its_labels fails;
  2. no v2 fallback past 64 labels: an_envelope_too_big_for_its_labels_or_with_no_text_is_written_as_v2 fails;
  3. tool turns derive as usual: a_tool_turn_asks_to_extract_nothing_and_other_turns_do_not fails;
  4. recovery matches text alone: recovery_does_not_take_another_turn_with_the_same_words_for_the_lost_one fails.

Tests

  • v3 round trips: a document, every piece of a chunked document, and every turn of a conversation round-trip through text plus labels, and rebuild the item exactly.
  • Labels: the lookup labels come first; kind:/file:/page:/section:; at most 64 labels of at most 256 bytes each; no lang:.
  • v2 fallback: an envelope too big for 64 labels, and an empty turn, are written as v2 and read back.
  • Envelope parts: they are read by their numbers, not their order. A missing part, a v2 envelope in parts, or labels without parts are not an envelope.
  • v2 still reads: the existing v2 decoding tests (including the [role] -prefixed text) are kept.
  • Derivation: derive: Some(false) sends directives.extract: [], and an unset derive leaves the fingerprint as it was. Only the tool turn of a user/tool/assistant conversation is sent with extract: [].
  • Recovery: two turns say "ok", the second is lost, and its re-write is claimed but not applied. Recovery reports the outcome as unknown instead of taking the first turn.

Documentation

  • docs/architecture/cortex-wire.md (the envelope, v3 and v2);
  • docs/architecture/cortex-chunks.md (limits measured on v2; readable page and section labels);
  • docs/architecture/cortex.md;
  • docs/specs/memory-v2.md;
  • crates/tinymemory-integrations/src/cortex/README.md;
  • module docs.

Checklist

  • The change is focused on one logical change
  • No new #[allow(...)], #[ignore], or relaxed lints
  • No secrets, tokens, or .env contents in the diff or the description

…udget beliefs

- Recall builds the chosen scope's pack again when /v1/answer answers 404
  for use_pack_id, up to three answers. CortexDB 0.10.4 drops every pack
  it holds on any successful forget, even in another scope, so a
  concurrent forget made recall fail (CortexDB live at 9d40d5d).
- get and list return a chunked document whole only when every piece
  agrees on one positive count, each index is below it, and all are
  present; an unchunked envelope of the same id is the whole body and
  wins over pieces.
- The beliefs read sends max_tokens for each belief it asks for.
- The live long-document test is two pieces, so its forget stays inside
  the request timeout, and after forget it polls fetch until no piece of
  the item is left.
- The spec states the chunking threshold on the envelope as a piece.
- A 404 for use_pack_id now repeats the whole round: every scope's pack
  is built again and the answer asked from the new chosen pack, so the
  citations also come from packs read after the drop and cannot cite an
  item forgotten in between. At most three rounds.
- docs/architecture/cortex-wire.md was over the 500-line limit; its
  "Chunked documents" section is now docs/architecture/cortex-chunks.md.
@M3gA-Mind M3gA-Mind changed the title Write events as prose with the envelope in labels; let items opt out of derivation [stacked on #207] Write events as prose with the envelope in labels; let items opt out of derivation Oct 6, 2026
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

  • Run on-demand review

This review includes 26 billable files and costs up to $6.50.

Or wait 58 minutes for your next included review.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: df130428-d269-4096-96d9-472aad113081
📥 Commits

Reviewing files that changed from the base of the PR and between cc281d1 and 06f2763.

📒 Files selected for processing (26)
  • crates/tinymemory-api/src/item/mod_tests.rs
  • crates/tinymemory-api/src/meta/filter_tests.rs
  • crates/tinymemory-api/src/meta/mod.rs
  • crates/tinymemory-integrations/src/cortex/README.md
  • crates/tinymemory-integrations/src/cortex/engine/beliefs.rs
  • crates/tinymemory-integrations/src/cortex/engine/beliefs_tests.rs
  • crates/tinymemory-integrations/src/cortex/engine/mod_chunk_tests.rs
  • crates/tinymemory-integrations/src/cortex/engine/mod_hosted_tests.rs
  • crates/tinymemory-integrations/src/cortex/engine/mod_tests.rs
  • crates/tinymemory-integrations/src/cortex/engine/recall.rs
  • crates/tinymemory-integrations/src/cortex/engine/store.rs
  • crates/tinymemory-integrations/src/cortex/envelope/mod.rs
  • crates/tinymemory-integrations/src/cortex/envelope/mod_tests.rs
  • crates/tinymemory-integrations/src/cortex/envelope/rebuild.rs
  • crates/tinymemory-integrations/src/cortex/log/write.rs
  • crates/tinymemory-integrations/src/cortex/mod.rs
  • crates/tinymemory-integrations/src/cortex/testing/log.rs
  • crates/tinymemory-integrations/src/cortex/testing/mod.rs
  • crates/tinymemory-integrations/src/cortex/testing/routes.rs
  • crates/tinymemory-integrations/tests/live_cortexdb.rs
  • docs/architecture/README.md
  • docs/architecture/cortex-chunks.md
  • docs/architecture/cortex-flows.md
  • docs/architecture/cortex-wire.md
  • docs/architecture/cortex.md
  • docs/specs/memory-v2.md
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@tinysweeper

tinysweeper Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Tiny Sweeper completed its review; deterministic results follow.

State: Ready for maintainer review
Priority: medium
Reviewed head: 06f276353573
Updated: 1791317076 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 8 Active findings 4
Tests 11 Noted findings 0
Documentation 7 Resolved findings 59
Configuration 0 Pending checks/questions 0

Completeness: Complete
Test assessment: Test coverage is assessed from changed tests and lane evidence; execution is not claimed without trusted check data.

What changed

The CortexDB event layout changes from v2 (the whole envelope as JSON in content.text) to v3: an event's content.text is the item's own text, and the rest of the envelope rides in numbered tm:e:<NN>: labels of at most 240 bytes each, beside readable kind:/file:/page:/section: labels (crates/tinymemory-integrations/src/cortex/envelope/mod.rs#impl Envelope {). Events with empty text, or whose labels would exceed 64, fall back to v2, and decode_event reads both layouts (crates/tinymemory-integrations/src/cortex/envelope/rebuild.rs#pub(crate) fn decode_event(event: &Value) -> Option<Decoded> {). A new public MemoryMeta.derive field lets items opt out of derivation; opted-out items and tool turns are written with directives.extract: [] (crates/tinymemory-api/src/meta/mod.rs#pub struct MemoryMeta {). Recall retries up to three rounds when the answer route 404s because CortexDB dropped its packs, with the round factored into answer_round and pack_id_of (crates/tinymemory-integrations/src/cortex/engine/recall.rs#impl CortexEngine {). rebuild_whole now rejects chunked documents whose pieces disagree on count or index and accepts a whole-body envelope mixed with pieces (crates/tinymemory-integrations/src/cortex/envelope/rebuild.rs#pub(crate) fn rebuild_whole(envelopes: &[Envelope]) -> Option<StoreItem> {). Replay detection matches events by text and labels together, since two v3 turns can share the same words (crates/tinymemory-integrations/src/cortex/log/write.rs#impl Log {). Belief reads set budgets.max_tokens from the beliefs limit (crates/tinymemory-integrations/src/cortex/engine/beliefs.rs#impl CortexEngine {). The testing double gains an expire_packs counter and its pack events no longer carry a role-marker prefix (crates/tinymemory-integrations/src/cortex/testing/routes.rs#async fn answer(, crates/tinymemory-integrations/src/cortex/testing/log.rs#impl CortexLog {). The live long-document test defaults to 12 pages with an opt-in for longer runs and adds a ranked-recall check that no piece outlives forget (crates/tinymemory-integrations/tests/live_cortexdb.rs#async fn a_long_document_round_trips_in_pieces() {). Chunked-document guidance moves to a new docs/architecture/cortex-chunks.md, and the wire/flows/spec/README pages describe v3, the fallback, the derive opt-out and the pack retry.

Features

  • Added — MemoryMeta.derive opt-out and no derivation from tool turns: A new public Option<bool> derive field on MemoryMeta, unset by default and skipped in serialization so fingerprints of existing items are unchanged; Some(false) stores and indexes the item but derives nothing from it, and Role::Tool turns are likewise sent with directives.extract: [] so raw tool output stays searchable without becoming derived memory. (crates/tinymemory-api/src/meta/mod.rs#pub struct MemoryMeta {, crates/tinymemory-integrations/src/cortex/envelope/mod.rs#impl Envelope {)
  • Modified — Recall retries when packs are dropped: Because CortexDB drops every pack when anything is forgotten, a 404 from the answer route now triggers rebuilding every scope's pack and asking again, up to three rounds (ANSWER_ATTEMPTS); a third 404 surfaces as Error::NotFound. The round logic is factored into answer_round and pack_id extraction into pack_id_of. (crates/tinymemory-integrations/src/cortex/engine/recall.rs#impl CortexEngine {, crates/tinymemory-integrations/src/cortex/engine/recall.rs#fn pack_budgets(limit: usize) -> Value {, docs/architecture/cortex-flows.md#cites from the pack.)
  • Modified — Replay detection matches on labels as well as text: Log write replay detection now also compares context.labels, because two v3 turns of one item can say the same words while their labels (carrying the turn index) differ. (crates/tinymemory-integrations/src/cortex/log/write.rs#impl Log {)
  • Modified — Belief recall token budget: The beliefs recall body sets budgets.max_tokens to whole_items_budget(limit), giving room for each belief asked for. (crates/tinymemory-integrations/src/cortex/engine/beliefs.rs#impl CortexEngine {)
  • Modified — Readable CortexDB labels: v3 events carry human-readable labels (kind:, file:, and a piece's page:/section:) of at most 256 bytes each, never filtered on, with no lang: label written since CortexDB reserves it. (crates/tinymemory-integrations/src/cortex/envelope/mod.rs#impl Envelope {, crates/tinymemory-integrations/src/cortex/README.md#as prefixes, so they cannot be labelled and are filtered only client-side.)

Tests

  • unit — A new MemoryMeta test verifies that an unset derive flag is not serialized (leaving the fingerprint unchanged), that Some(false) changes the fingerprint, and that Some(false) survives a JSON round trip.: Reasonable; covers the fingerprint-compatibility claim documented on the field. (crates/tinymemory-api/src/item/mod_tests.rs#fn a_turn_renders_its_tool_calls() {)
  • unit — A recall test asserts the retry: one scope packed and answered twice on a 404, four rounds' worth of recalls across two scopes, and a bounded failure as Error::NotFound after three refused answers; a hosted test asserts recovery does not mistake the first of two identically worded turns for the lost second turn.: Directly exercise the new retry and label-aware replay behavior described in the diff. (crates/tinymemory-integrations/src/cortex/engine/mod_tests.rs#async fn a_store_succeeds_when_ranked_recall_is_down() {, crates/tinymemory-integrations/src/cortex/engine/mod_hosted_tests.rs#async fn the_answer_body_holds_only_keys_the_strict_schema_allows() {)
  • test_infrastructure — The testing double gains an expire_packs counter that makes the answer route return 404 a configurable number of times, and its recall rendering no longer prefixes role markers in stored pack text.: Supports the new retry tests; the rendering change matches the documented 0.10.3/0.10.4 behavior. (crates/tinymemory-integrations/src/cortex/testing/mod.rs#pub(crate) struct Double {, crates/tinymemory-integrations/src/cortex/testing/routes.rs#async fn answer(, crates/tinymemory-integrations/src/cortex/testing/log.rs#impl CortexLog {)

Findings

  • medium · critique · Reject mixed chunked and unchunked envelopes — The specification still does not define what happens when the same document identity has both chunked pieces and an unchunked event. Checking that every expected piece is present d (docs/specs/memory\-v2\.md)
  • medium · critique · Share live-test serialization across integration binaries — `cargo test` runs each integration-test file as a separate binary, so this process-local mutex does not coordinate with `live_cortex_lifecycle.rs` or any other live-test binary. Th (crates/tinymemory\-integrations/tests/live\_cortexdb\.rs:110)
  • medium · security · Restore the live chunking test's full document size — This test now constructs only 12 pages, producing three chunks instead of the previous 24-page document. That halves the exercised chunking and forgetting coverage, including the n (crates/tinymemory\-integrations/tests/live\_cortexdb\.rs:289)
  • medium · security · Restore the live test's full document size — The live long-document scenario remains reduced from the former 24-page input to 12 pages, so it no longer covers the full-size document and chunk-forget workload previously tested (crates/tinymemory\-integrations/tests/live\_cortexdb\.rs:289)

Resolved this pass

  • Preserve compatibility for public struct literals
  • Set the version before encoding the stored envelope
  • Use non-empty text in the v3 envelope example
  • Reject mixed chunked and unchunked envelopes
  • Update callers for the new encoded request API
  • Live chunking test shrank from 24 pages to 12, halving its coverage
  • Restore the live chunking test's full document size
  • Restore the live test's full document size
  • Restore the default three-piece document coverage
  • Preserve compatibility for public struct literals
  • Set the version before encoding the stored envelope
  • Use non-empty text in the v3 envelope example
  • Reject mixed chunked and unchunked envelopes
  • Update callers for the new encoded request API
  • Live chunking test shrank from 24 pages to 12, halving its coverage
  • Restore the live chunking test's full document size
  • Restore the live test's full document size
  • Restore the default three-piece document coverage
  • Preserve compatibility for public struct literals
  • Set the version before encoding the stored envelope
  • Use non-empty text in the v3 envelope example
  • Update callers for the new encoded request API
  • Live chunking test shrank from 24 pages to 12, halving its coverage
  • Restore the live chunking test's full document size
  • Restore the live test's full document size
  • Restore the default three-piece document coverage
  • Preserve compatibility for public struct literals
  • Set the version before encoding the stored envelope
  • Use non-empty text in the v3 envelope example
  • Reject mixed chunked and unchunked envelopes
  • Update callers for the new encoded request API
  • Restore the default three-piece document coverage
  • Preserve compatibility for public struct literals
  • Set the version before encoding the stored envelope
  • Use non-empty text in the v3 envelope example
  • Reject mixed chunked and unchunked envelopes
  • Update callers for the new encoded request API
  • Live chunking test shrank from 24 pages to 12, halving its coverage
  • Restore the live chunking test's full document size
  • Restore the live test's full document size
  • Restore the default three-piece document coverage
  • Preserve compatibility for public struct literals
  • Set the version before encoding the stored envelope
  • Use non-empty text in the v3 envelope example
  • Reject mixed chunked and unchunked envelopes
  • Update callers for the new encoded request API
  • Live chunking test shrank from 24 pages to 12, halving its coverage
  • Restore the live chunking test's full document size
  • Restore the live test's full document size
  • Restore the default three-piece document coverage
  • Preserve compatibility for public struct literals
  • Set the version before encoding the stored envelope
  • Use non-empty text in the v3 envelope example
  • Reject mixed chunked and unchunked envelopes
  • Update callers for the new encoded request API
  • Live chunking test shrank from 24 pages to 12, halving its coverage
  • Restore the live chunking test's full document size
  • Restore the live test's full document size
  • Restore the default three-piece document coverage

Before merge

None.

Agent review details

critique

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 3 files; 2 findings. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._
  • Evidence: docs/specs/memory\-v2\.md — Reject mixed chunked and unchunked envelopes
  • Evidence: crates/tinymemory\-integrations/tests/live\_cortexdb\.rs — Share live-test serialization across integration binaries

security

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Positive: The security lane's API-compatibility finding was addressed: MemoryMeta now documents the struct-literal contract, telling users to build with ..MemoryMeta::default() since a literal naming every field stops compiling when a field is added.
  • Lane summary: The test serialization and post-forget visibility check are sound, but the long-document test still exercises only half of its previous document size and therefore loses chunking coverage. 2 files were not security-reviewed: docs/architecture/cortex-wire.md (prose or tabular data), docs/specs/memory-v2.md (prose or tabular data). (1 earlier finding(s) still open) _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._
  • Evidence: crates/tinymemory\-integrations/tests/live\_cortexdb\.rs — Restore the live chunking test's full document size
  • Evidence: crates/tinymemory\-integrations/tests/live\_cortexdb\.rs — Restore the live test's full document size

tests

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Positive: The mixed chunked/unchunked rebuild case is deliberately handled and regression-tested, including index/count disagreement and zero-count rejection.
  • Lane summary: This increment serialises the live CortexDB tests behind a mutex, restores the long-document test to over twice the chunk target (three pieces, two boundaries), and adds a post-forget check that no piece survives via ranked fetch; the wire and spec docs were updated to match (max_tokens 6291456 = 8 × 768 KiB, consistent with the beliefs budget change and its new test). All previously raised findings are addressed in this revision: the encoded-request callers were migrated, the stored envelope is encoded as v2, the example explains the empty v3 text, the mixed-layout read is now deliberate and pinned by a test, and the live chunking test's coverage was restored. Nothing new to block on; safe to merge. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: This revision restores the live chunking test to a three-piece document, serializes the live tests, and documents the pack-expiry retry and v3 layout; the previously raised findings (struct-literal compatibility, envelope version handling, mixed-layout rebuild, the caller updates for `Encoded`, and the shrunken live test) are all addressed in the code shown. Nothing new stands out — the changes look sound. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

e2e

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: The v3 envelope layout, the derive opt-out and the recall pack-drop retry are all behavioural changes to how this crate talks to a running CortexDB, and the only harness that drives a real server is the live tests in tests/live_cortexdb.rs; that suite still covers the full contract surface (round trip, chunked document, fetch) and now additionally exercises the forget that drops packs, so the wire-level behaviour is verified end to end. No end-to-end job runs on this head, which the repository's own setup makes the norm rather than a gap this PR introduced. The unit-level changes look sound; the earlier findings about struct-literal compatibility, the chunking-test coverage and the version handling were addressed in earlier revisions and do not reappear here. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._
Evidence and run details
  • Models: gpt-5.6-luna, glm-5.3-flash
  • Spend: $0.001959
  • Tokens: 226149 input · 15381 output · 11696 cached · 0 embedding
  • Continuity: summary cache chain restarted at the storage ceiling.
Head State Pass summary
73f5889029c3 changes requested 6 active finding(s), 0 resolved finding(s) (at 1791315268)
6971f7989594 changes requested 3 active finding(s), 4 resolved finding(s) (at 1791315570)
07f499a6665b changes requested 4 active finding(s), 44 resolved finding(s) (at 1791315901)
06f276353573 ready for maintainer review 4 active finding(s), 59 resolved finding(s) (at 1791317076)

tinysweeper 0.1.0

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 2 lane(s) blocking, worst finding is critical.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0128 · 878,749 in / 45,091 out · 77,493 cached (9%)  · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0058 · 451,698 in / 27,316 out · 48,859 cached (11%) · gpt-5.6-luna, glm-5.3-flash
security:    $0.0035 · 283,338 in / 13,072 out · 28,634 cached (10%) · gpt-5.6-luna
tests:       $0.0005 · 55,463 in  / 786 out    · 0 cached (0%)       · glm-5.3-flash
description: $0.0003 · 28,421 in  / 369 out    · 0 cached (0%)       · glm-5.3-flash
e2e:         $0.0003 · 30,307 in  / 399 out    · 0 cached (0%)       · glm-5.3-flash

Comment thread crates/tinymemory-api/src/meta/mod.rs
Comment thread crates/tinymemory-integrations/src/cortex/envelope/mod_tests.rs
Comment thread crates/tinymemory-integrations/src/cortex/README.md
Comment thread crates/tinymemory-integrations/src/cortex/envelope/rebuild.rs
Comment thread crates/tinymemory-integrations/src/cortex/envelope/mod.rs
Comment thread crates/tinymemory-integrations/tests/live_cortexdb.rs Outdated
@tinysweeper tinysweeper Bot added the priority: p0 Drop what you are doing. Data loss, a live break, or an exploitable hole. label Oct 6, 2026

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 1 lane(s) blocking, worst finding is high.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0008 · 130,561 in / 7,775 out · 2,033 cached (2%)  · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0001 · 13,621 in  / 1,285 out · 2,033 cached (15%) · gpt-5.6-luna, glm-5.3-flash
tests:       $0.0001 · 28,030 in  / 2,854 out · 0 cached (0%)      · glm-5.3-flash
description: $0.0003 · 28,833 in  / 76 out    · 0 cached (0%)      · glm-5.3-flash
e2e:         $0.0003 · 30,719 in  / 75 out    · 0 cached (0%)      · glm-5.3-flash

Comment thread crates/tinymemory-api/src/meta/mod.rs
Comment thread crates/tinymemory-integrations/tests/live_cortexdb.rs Outdated
@tinysweeper tinysweeper Bot added priority: p1 Next. Wrong behaviour a user will hit, or a security weakness behind a condition. and removed priority: p0 Drop what you are doing. Data loss, a live break, or an exploitable hole. labels Oct 6, 2026

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 2 lane(s) blocking, worst finding is high.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0037 · 250,466 in / 10,850 out · 11,460 cached (5%) · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0018 · 63,969 in  / 4,549 out  · 6,096 cached (10%) · gpt-5.6-luna, glm-5.3-flash
security:    $0.0004 · 34,738 in  / 1,914 out  · 5,364 cached (15%) · gpt-5.6-luna
tests:       $0.0006 · 60,045 in  / 606 out    · 0 cached (0%)      · glm-5.3-flash
description: $0.0003 · 29,150 in  / 229 out    · 0 cached (0%)      · glm-5.3-flash
e2e:         $0.0003 · 31,036 in  / 1,026 out  · 0 cached (0%)      · glm-5.3-flash

Comment thread crates/tinymemory-integrations/tests/live_cortexdb.rs Outdated
Comment thread crates/tinymemory-api/src/meta/mod.rs
Comment thread crates/tinymemory-integrations/tests/live_cortexdb.rs Outdated
Run together, one live test's forgets drop the packs another is about to
answer from, and load the server enough that forgetting a ~700 KiB
document (seconds per ~240 KiB event on CortexDB 0.10.4) outlasted the
request timeout. Each live test now holds one async lock for its run, and
the long document is back to 24 pages (three pieces, two boundaries).
…of derivation

CortexDB extracts from an event's text and splits it for search at
sentence boundaries, which a JSON text lacks, and counts that text toward
its 1 MiB limit; labels are its app-metadata extension point. So events
are now written as v3:

- content.text is the item's own text: the body or piece, the turn's
  text, or the learning's statement;
- context.labels hold the lookup labels, readable kind:/file:/page:/
  section: labels (at most 256 bytes each, never lang:), and the rest of
  the envelope as compact JSON in tm:e:<NN>: parts of at most 240 bytes.

An event with empty text, or whose labels would pass 64, is written as v2
(the whole envelope as JSON text) as every event was before. Readers take
both, so existing stores need no rewrite. A recovered hosted write is
matched on its labels as well as its text, since two v3 turns can say the
same words.

MemoryMeta gains derive: Option<bool>. Some(false) stores and indexes an
item but asks CortexDB to derive nothing from it (directives.extract: []);
every tool turn is sent the same way. Unset, it is not serialized, so
fingerprints are unchanged.

The test double's recall no longer prefixes a pack event's text with
[role]: CortexDB 0.10.3 and 0.10.4 return the stored text there.
@M3gA-Mind
M3gA-Mind force-pushed the feat/prose-events-v3 branch from 07f499a to 06f2763 Compare October 6, 2026 20:02

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The previously-blocking findings are resolved. Clearing the changes request.

             $0.0020 · 226,149 in / 15,381 out · 11,696 cached (5%) · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0011 · 86,210 in  / 8,340 out  · 8,118 cached (9%)  · gpt-5.6-luna, glm-5.3-flash
security:    $0.0003 · 18,335 in  / 2,190 out  · 3,578 cached (20%) · gpt-5.6-luna
tests:       $0.0001 · 28,680 in  / 1,548 out  · 0 cached (0%)      · glm-5.3-flash
description: $0.0001 · 29,490 in  / 531 out    · 0 cached (0%)      · glm-5.3-flash
e2e:         $0.0003 · 31,369 in  / 259 out    · 0 cached (0%)      · glm-5.3-flash

Comment thread crates/tinymemory-integrations/tests/live_cortexdb.rs
Comment thread crates/tinymemory-integrations/tests/live_cortexdb.rs
Comment thread crates/tinymemory-integrations/tests/live_cortexdb.rs
@tinysweeper tinysweeper Bot added priority: p2 Soon. Real but survivable — a rough edge, a gap, a thing that will bite later. and removed priority: p1 Next. Wrong behaviour a user will hit, or a security weakness behind a condition. labels Oct 6, 2026
@senamakel
senamakel merged commit b3bed86 into tinyhumansai:main Oct 6, 2026
25 checks passed
senamakel added a commit that referenced this pull request Oct 6, 2026
[stacked on #208] Key each event by its own body; skip the lookup on the turn hot path
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p2 Soon. Real but survivable — a rough edge, a gap, a thing that will bite later.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants