mem Git-backed agent memory
Type: types/agentic-system-analysis-result.md
Run identity
Run state: kb/reports/state/agentic-system-analysis/AAS-2026-09-25-instinctual-memory-01/run-state.md
Generated review: kb/agentic-systems/reviews/instinctual-memory.md
Memory analysis report: kb/reports/state/agentic-system-analysis/AAS-2026-09-25-instinctual-memory-01/memory-report.md
Memory analysis report SHA-256: 0d0859caab64bcf292453fedb7ec637fff4bf31a41fbea1fc68971b1e474f10f
Boundary and evidence
Evidence basis: Rust source and shipped documentation at 6acb13dc35765bf5ccfc87e445dd09c480f1c28a, inspected 2026-09-25; no observed execution or causal experiment. The source-native name is mem; repository name instinctual-memory. Target class: memory/knowledge/context-engineering system. Boundary kind: complete artifact, partial loop. Includes input ingestion, rules/model consolidation, explicit changes/recovery, search/reranking/read/history, hook/writeback delivery, transports, task storage, erasure/tidy and evaluation. Excludes host agents' implementations and model activation, provider internals, deployed stores/permissions and local user data.
Source allowlist: https://github.com/jasonkneen/instinctual-memory only; full-commit evidence reads at /home/zby/llm/commonplace/related-systems/jasonkneen--instinctual-memory. No worktree or prior review/ingest/index evidence. Rust/Git and optional remote/local models are runtime dependencies; none installed or invoked here.
Source register
| Source ID | Kind | Identity/location | Revision | Evidence layer | Inspected scope | Citation anchors | Access gaps and conclusion prevented |
|---|---|---|---|---|---|---|---|
| SRC-1 | Git | https://github.com/jasonkneen/instinctual-memory |
6acb13dc35765bf5ccfc87e445dd09c480f1c28a | implementation | CLI/operations, extraction/admission, publication and delivery, memory specialist paths | src/main.rs; src/ops.rs; src/consolidate.rs; src/change.rs; src/repo.rs; src/validate.rs; src/hook.rs; src/http_serve.rs; src/mcp.rs; src/evaluation.rs; src/search/rerank.rs; src/journal.rs; src/entity.rs; src/fact.rs; src/index.rs; src/checkpoint.rs; src/controls.rs; src/ingest.rs; src/search/lexical.rs; src/search/journal.rs; src/search/laya.rs; src/jev.rs; src/cli.rs; src/shell.rs; src/tidy.rs; src/erasure.rs; tests/recorded_search.rs |
deployed store/host/provider outcomes uninspected |
| SRC-2 | Git | https://github.com/jasonkneen/instinctual-memory |
6acb13dc35765bf5ccfc87e445dd09c480f1c28a | doctrine/design | README and shipped skill/prompt instructions | README.md; skills/mem/SKILL.md; src/consolidate.rs:576-598 |
declaration is not execution evidence |
Shared records
Components
CMP-1 — Rust CLI/service and Git publisher. Symbolic implementation governs entry dispatch, extraction checks, retrieval and mutation. Conclusion status: wired. Git/filesystem effects run under caller process authority, not an isolated model sandbox. Source: SRC-1 src/main.rs:6-28; src/ops.rs:35-51; src/repo.rs:196-330.
CMP-2 — Configurable LLM extractor, default anthropic/claude-haiku-4.5 through OpenAI-compatible chat endpoint. Model/endpoint resolution is wired; exact weights and provider parameter change each uninspected. The inspected call requests temperature zero and JSON, with three bounded retries; those settings do not prove deterministic or factually correct extraction. This path performs no parameter update. Source: SRC-1 src/consolidate.rs:543-568,836-880.
let body = serde_json::json!({ "model": cfg.model, "temperature": 0, "response_format": {"type": "json_object"}, "messages": [ {"role": "system", "content": system}, {"role": "user", "content": user}, ],---
src/consolidate.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
CMP-3 — Ranking alternatives: external JEV judgment, local fastembed cross-encoder and lexical fallback. Selection is source-wired; model files/provider pinning and parameter behavior are treated separately by the memory findings. Ranking relevance does not establish truth. Source: SRC-1 src/search/rerank.rs:151-180. JEV or local cross-encoder alternatives for requested search. Implementation conclusion status: wired. SRC-1 src/jev.rs:24-28,67-88,128-170, src/search/rerank.rs:69-127,156-188, src/search/laya.rs:26-48,95-127,149-180. Automatic resolution tries configured JEV, cached local model, then lexical fallback. JEV defaults to the mutable ~typesafe/jev-latest; local selection uses an environment value, selected-model file, or default BGE. Local fastembed consumes ONNX parameters, an opaque parametric component separately from text candidates. Download/load selection is not learning from memory. Exact weights and dependency internals were excluded, preventing an immutable-model claim. JEV receives up to eight selected candidates, clips each statement to 2,000 characters and the query to 400; local reranking consumes shortlist statements. The local branch declines when its best sigmoid score is below 0.05. No empirical calibration follows from these constants.
let off = cfg!(test) || std::env::var("MEM_RERANK").is_ok_and(|v| matches!(v.as_str(), "off" | "0" | "false")); ---
src/search/rerank.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
This makes test-mode/network-off fallback explicit; the source tests cannot establish live model behavior merely by exercising the shared search function.
CMP-4 — External host agent and its model consume tools/hooks/instruction files. Artifact emits context but does not schedule or observe the host's next model decision. Host grants, loading behavior and actual activation are uninspected. Source: SRC-1 src/hook.rs:49-79; SRC-2 README.md.
Operative objects
OBJ-1 — Journal events: retained imported message/document content plus symbolic source, role, sequence, session, scope, content digest, redaction and arbitrary JSON metadata. Storage: framed daily JSONL files. Lineage: imported source with compiled access metadata. Raw session material is not automatically curated fact or instruction. Evidence: SRC-1 src/journal.rs:57-99,103-143,468-555, src/ingest.rs:170-219,534-591. Primary-key duplicate skipping prevents re-ingestion; semantic deduplication belongs elsewhere.
pub content: String, pub content_sha256: String, pub redaction: Redaction, ---
src/journal.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
OBJ-2 — Entity Markdown in the Git memory branch. YAML is the operative structured record; natural-language statements and evidence are payloads. The Markdown body is a regenerated active-fact display, not a separate authoritative store. Status, time, visibility and provenance fields control some consumer paths. INDEX.md is a compiled entity/type/title/count projection with a 60,000-byte row budget; retrieval scans entity files rather than using it as a vector index. Sources: SRC-1 src/fact.rs:13-35,63-89,129-143, src/entity.rs:32-55,69-109, src/index.rs:18-48,79-88, src/search/lexical.rs:96-138.
/// Rewrite the Markdown body as the human-readable form of the /// frontmatter: the title and every active fact with its id. ---
src/entity.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
OBJ-3 — Combined publication/control record remains the supplied referent. Facets: checkpoint and dispositions in Git; fact suppressions/retractions/deletions and event-redaction markers in Git; publication receipts in Git; durable intent JSON files beside the repository. These are symbolic operational memory, with optional natural-language reasons. Checkpoint sequence changes future extraction; control IDs affect read eligibility; receipts and intents govern replay/recovery. Evidence: SRC-1 src/checkpoint.rs:15-25,65-85, src/consolidate.rs:178-203, src/controls.rs:20-43,83-122, src/repo.rs:150-187,207-238, src/change.rs:180-185,248-305. They are not truth certificates.
checkpoint.accepted.clear(); checkpoint.quarantined.clear(); checkpoint.advance(window_end, Default::default(), Default::default())?; ---
src/consolidate.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
The shipped consolidator puts event outcomes in separate disposition files. The checkpoint type still permits embedded accepted/quarantine records; those fields do not gate this route's next read.
OBJ-4 — Delivered natural-language facts and raw-event text, with symbolic result labels/IDs. Tool responses and hook strings are transient projections. Managed writeback is the retained facet: a project file containing generated statements and abbreviated source-commit provenance; future host loading affords instruction/knowledge use. Evidence: SRC-1 src/ops.rs:71-86,245-332, src/hook.rs:75-78,99-110,152-158, src/cli.rs:1808-1855. Static tool and skill instructions are separate doctrine, not this accumulated content.
OBJ-5 — versioned root-level tasks.json, separate from Git facts and journal. Natural-language titles with symbolic task IDs/version; caller-authored, retained across calls. The file is protected by a task lock, and updates require expected_version; the writer truncates and fsyncs the same file rather than using the Git intent/receipt pipeline. Evidence: SRC-1 src/ops.rs:485-529,688-743, src/mcp.rs:131-145. It is a named external-agent pull surface, not evidence of task-scoped trace learning.
let path = root.join("tasks.json"); ---
src/ops.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
Routes
RTE-1 — Ingest/backfill. Import/backfill acquisition. Implementation conclusion status: wired. CLI file adapters and local/global backfill produce OBJ-1; bulk appends reject already-seen event IDs. Message sources include Claude, Codex, OpenCode and generic JSONL; project-memory files become Note events keyed by path plus content hash. Calendar/voice inputs also become Note events, while IDE command/result imports are Tool events. Sources: SRC-1 src/cli.rs:807-843,1018-1088,1163-1213,1510-1613,1618-1698,2134-2169, src/ingest.rs:314-380,392-499,534-591,610-670,688-739,763-855, src/journal.rs:468-555. Source-role labels are parser assignments, not authenticated authorship. Codex explicitly filters subagent rollouts and non-final assistant messages. These acquisition filters must not be generalized into proof that all imported User/Note text is trustworthy.
let source_id = format!("md:{}:{}", path.display(), &digest[..16]); ---
src/ingest.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
RTE-2 — Consolidation. Explicit command or hook sync chooses rules/LLM, reads the post-checkpoint journal window and proposes facts. Shape/source/quote and duplicate/control filters govern admission; changed entities/index/checkpoint/dispositions publish together. Conclusion status: wired. Checkpoint advances by journal position even when a scope filter excludes events, so a scoped pass is not proof that all events before the checkpoint were extracted. Empty batches return current revision. Source: SRC-1 src/consolidate.rs:101-213.
let from_seq = checkpoint.through_seq + 1; // The window is bounded by journal position so the checkpoint always // advances, even when the scope filter drops every event in it. let bounded: Vec<JournalEvent> = all_after .into_iter() .filter(|e| e.seq <= window_end) .filter(|e| options.scope_id.as_deref().is_none_or(|s| e.scope_id == s)) .collect();---
src/consolidate.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
For LLM extraction, only notes and filtered user content become candidates; note files are chunked, user content capped. Parallel request batches share initial known-entity context. lasting is the model's judgment, then code checks statement/evidence length, ordered normalized source fragments, predicate and entity/project mapping. A located quote establishes occurrence, not that the proposed statement follows from it or remains true. Output facts are marked explicit assertion/active on placement; operational adoption has no additional human approval. Source: SRC-1 src/consolidate.rs:362-395,576-618,620-706,909-1005.
let evidence = fact.evidence.trim(); let statement = fact.statement.trim(); if !fact.lasting { return Err("not lasting (true for one session only)"); } if evidence.chars().count() < 8 { return Err("evidence too short"); } if !(8..=600).contains(&statement.chars().count()) { return Err("statement empty or over 600 characters"); } if !quote_found(&event.content, evidence) { return Err("evidence not found in the cited event"); }---
src/consolidate.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28alet fact = Fact { id: fact_id, predicate: p.predicate, statement: p.statement, kind: FactKind::ExplicitAssertion, status: FactStatus::Active, observed_at: event.occurred_at,---
src/consolidate.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
Rules extraction differs materially: it searches User-role content directly for name/residence/preference regexes. The preference regex consumes always, never or don't outside the captured phrase, then constructs User requested: <capture>. This can lose directive polarity: for a matching request, positive/negative operator bytes are not carried into the constructed statement, though evidence preserves the full match. This is a source-level transformation limitation, not an observed run failure. The LLM path's injected-block filtering is not called by this rules function. Source: SRC-1 src/consolidate.rs:279-336,774-796.
let name_re = Regex::new(r"(?i)my name is\s+([A-Z][a-zA-Z\-']+)").unwrap(); let live_re = Regex::new(r"(?i)I (?:live|am living) in\s+([A-Z][a-zA-Z\-' ]+)").unwrap(); let pref_re = Regex::new(r"(?i)please (?:always|never|don't)\s+([a-z][^.!?]+)").unwrap();---
src/consolidate.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28afor cap in pref_re.captures_iter(&event.content) { found.push(Proposal { entity_id: "pref_user".into(), entity_type: "preference".into(), title: "User preferences".into(), predicate: "comms_preference".into(), statement: format!("User requested: {}", cap[1].trim()), evidence: cap[0].to_string(), });---
src/consolidate.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
Near-duplicate rejection uses stemmed content-word overlap; its stopword set drops not, no, never, always and must. Similarity-based disposition therefore does not prove semantic equivalence or contradiction resolution. Facts sourced exclusively to obsolete memory-file versions are superseded by source-version rules, not by a truth test. Source: SRC-1 src/consolidate.rs:221-251,417-476. These observations qualify CLM-1's curated/sourced claim without inferring measured harm.
const STOPWORDS: &[&str] = &[ "a", "an", "the", "is", "are", "be", "to", "of", "in", "on", "for", "and", "or", "with", "that", "this", "it", "its", "as", "by", "at", "from", "has", "have", "uses", "use", "project", "user", "includes", "include", "consists", "assistant", "agent", "must", "always", "should", "only", "when", "not", "no", "never", "do", "does", "wants", "want", "prefers", ]; ---
src/consolidate.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
Bounded consolidation, with rules and LLM alternatives. Implementation conclusion status: wired. Explicit CLI invocation or hook sync reads journal events after the shared checkpoint, selects a high-water window, then filters by configured scope. Rules accept User events matching name/home-city/preference patterns; LLM accepts User text after injection stripping and every Note role. It proposes a lasting statement and source quote. Guards reject missing/short evidence, disallowed statement length, non-lasting judgment, wrong batch references and duplicate/suppressed candidates. Accepted facts plus entity/index/checkpoint/dispositions publish together. Later consumers are RTE-4, RTE-5 and RTE-6. Sources: SRC-1 src/consolidate.rs:100-213,221-264,279-337,362-449,570-706,774-831,909-999, src/cli.rs:2245-2289, src/hook.rs:183-212.
Role::Note => Some(event.content.clone()), Role::User => user_words(&event.content), ---
src/consolidate.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
This is a role gate, not a file-type gate. Calendar and voice Note imports therefore reach the LLM's memory_file branch too. Rules do not apply the LLM's user_words preprocessing. The generic CLI and automatic sync share extraction mechanics but differ in trigger.
The evidence check matches normalized ordered fragments separated by ellipses; it does not test that the statement follows from the quote. Durability is the model's Boolean judgment. The earlier prompt requests exact evidence and decisions with reasons, but neither proposition truth nor rationale retention is guaranteed.
A fact is worth keeping only if it will still be true and useful in a session weeks from now, in a different task: the user's identity and role, standing preferences and working rules, project facts (what it is, stack, architecture, conventions, commands, decisions and why), and named people or organisations with a stated relationship. ---
src/consolidate.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
This proposal guidance, paired with durable project/preference storage and later-consumer routes, establishes the intended cross-task horizon. The lasting check enforces the returned flag, not the truth of the guidance's prediction.
RTE-3 — Explicit remember/correct/forget and recovery. Caller submits identity/payload, code validates, applies entity changes and optional suppression, writes an intent, then publishes with DomainValidator. Correct supersedes an old fact; forget retracts and controls future use. Recovery republishes against original base, reuses receipts or sets conflicting intents aside as stale. Conclusion status: wired. These are permitted content revisions, not validation of submitted truth or necessity. Reasons are optional; actual human review uninspected. Source: SRC-1 src/change.rs:28-77,87-197,248-305; src/ops.rs:408-483.
// Persist a durable intent so retries can recover the original base. let intent = Intent::new(&request.request_id, base, &change_set)?; repo.write_intent(&intent)?; let receipt = repo.publish(base, &request.request_id, &change_set, &DomainValidator)?; repo.complete_intent(&request.request_id)?;---
src/change.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
Publisher checks request digest and current base, builds a candidate commit, invokes domain validation, then compare-and-swaps the memory branch. That protects cooperating writes through this publisher; direct Git/filesystem edits and erasure's separate route need their own boundaries. The operation wrapper has an earlier receipt lookup: an existing request ID returns replayed before reconstructing/applying the change. Thus the publisher's changed-payload conflict check cannot be asserted as a universal semantic request-reuse check at every entry. Source: SRC-1 src/repo.rs:196-237,293-329; src/ops.rs:436-453.
let changed_paths: Vec<String> = changes.iter().map(|(p, _)| p.clone()).collect(); validator.validate(self, &candidate, &changed_paths)?; // Compare-and-swap on the published branch. let update_result = self .git .run_args(&["update-ref", MEMORY_REF, &candidate, base], None, None); if let Err(err) = update_result { let now = self.head(); if !matches!(now, Ok(ref h) if h == base) { return Err(Error::Conflict( "another writer published first; reconcile and retry".into(), ));---
src/repo.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28aif let Ok(head) = repo.head() { if repo .read_receipt(&head, &request_id) .ok() .flatten() .is_some() { let stored = count_statement(&repo, &entity_id, &statement).unwrap_or(0); return ok(json!({ "request_id": request_id, "replayed": true, "fact_id": fact_id, "entity_id": entity_id, "statement": statement, "stored": stored, }));---
src/ops.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
DomainValidator checks parsed entity/control/checkpoint and references on its inspected path. Code comments mention broader parent/supersession/checkpoint rules, but the inspected function merely parses checkpoint then discards that local value. Do not infer extra guarantees from its comment list. Existing checkpoint advancement is separately checked by the consolidator's checkpoint method. Source: SRC-1 src/validate.rs:14-125; src/consolidate.rs:195-200.
Explicit remember/correct/forget. Implementation conclusion status: wired. Caller-authored statements enter through CLI or common ops. Remember upserts; correct supersedes a target and inserts the replacement; forget retracts and adds suppression/retraction controls with optional reason. Domain/path validation and Git compare-and-swap can reject; durable intents preserve the original base, with stale conflicting intents set aside. Evidence: SRC-1 src/change.rs:87-197,248-305, src/ops.rs:408-483, src/cli.rs:2173-2242, src/repo.rs:196-238,292-329, src/validate.rs:27-125. Direct caller writes do not pass LLM evidence checks. Reason is retained for forget; correct/remember have no separate persistent explanatory field in this path. CLI SourceRef repeats the supplied statement, which is attribution rather than external verification.
entity.supersede(&old_id, &new_fact.id)?; entity.upsert_fact(new_fact.clone()); ---
src/change.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
RTE-4 — Search/read/history. Requested search/read/history. Implementation conclusion status: wired. External agent/operator requests select OBJ-2 facts and OBJ-1 journal rows through common ops, optionally rank with CMP-3, and receive OBJ-4. Search facts use time/status/visibility/control eligibility, corpus-dependent lexical weights, optional project/source filtering; raw search uses scope/source/project filters and lexical matching plus short same-event siblings. Results interleave the two pools before reranking. History returns current-tree fact records with statuses, not a walk of Git revisions. Evidence: SRC-1 src/ops.rs:54-107,160-332,603-685, src/search/lexical.rs:80-148, src/search/journal.rs:90-173,276-315, src/fact.rs:63-89, src/cli.rs:2294-2382.
entity .facts .retain(|f| !controls.is_suppressed(&f.id) && !controls.is_deleted(&f.id)); ---
src/ops.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
That fact filter does not apply to raw journal reads, which resolve an event ID and sequence directly. A soft-forgotten fact can remain recoverable as raw source wording; erasure must actually redact the journal. Direct fact reads/history also differ from search: they do not apply the full temporal/visibility eligibility function.
RTE-5 — Hook context. SessionStart reads preferences and memory-routing advice; prompt hook requests facts-only lexical search, then requires meaningful stem overlap and emits up to six fact statements. Slash commands/short prompts are skipped; errors are swallowed, so delivery is best effort. Conclusion status: wired at output boundary, actual host activation uninspected. Current project chooses scope; session-end launches detached sync, which can consolidate after backlog threshold with LLM configuration. Source: SRC-1 src/hook.rs:39-212.
let needed = terms.len().min(2); let hits: Vec<_> = found .hits .iter() .filter(|h| { let words = content_terms(&h.statement); terms.iter().filter(|t| words.contains(*t)).count() >= needed }) .take(PROMPT_FACTS) .collect();---
src/hook.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
Automatic hook supply and acquisition trigger. Implementation conclusion status: wired. SessionStart reads pref_user, supplies at most twenty preference statements plus static routing advice, only when the store reports active facts. UserPromptSubmit skips slash commands and prompts shorter than three words, takes 600 prompt characters, runs facts-only lexical search with a twelve-result candidate limit and project filter, requires up to two meaningful shared terms, then supplies at most six facts through additionalContext. Hook failures are swallowed. SessionEnd starts detached sync, which backfills and invokes consolidation when backlog reaches the default 200 and an LLM extractor is configured; threshold zero disables this. Evidence: SRC-1 src/hook.rs:24-28,39-111,114-169,171-212. External installation/use remains afforded at the host boundary.
let read = crate::ops::execute(root, "personal", "default", "memory_read", &json!({"id": "pref_user"})); ---
src/hook.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
These support distinct identifier and inferred-lexical push selectors, not inferred-judgment selection merely because other routes use models.
RTE-6 — Managed writeback. Managed project-file writeback. Implementation conclusion status: wired. Later host consumption conclusion status: afforded. Caller invocation selects facts for a project entity and preference family, or all local-store facts/explicit --all; excludes file-only facts unless requested; replaces a managed block, preserving outside text unless --force. Default target is AGENTS.md. No content budget is enforced here. Later host loading is documented for Codex/OpenCode, not inspected. Evidence: SRC-1 src/cli.rs:1725-1878; SRC-2 README.md:120-122.
let from_files_only = !fact.sources.is_empty() && fact.sources.iter().all(|s| s.event_id.starts_with("evt_ide_md:")); if from_files_only && !include_file_facts { continue; } ---
src/cli.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
The writeback loop excludes Superseded/Retracted/Expired statuses but does not call Fact::is_eligible or load Controls; Disputed and time-expired-but-Active facts can pass. Normal forget changes status and is consequently omitted, but a blanket shared suppression/temporal guarantee would be false. Already-written project blocks persist until another writeback/edit; fact withdrawal does not automatically retract them.
RTE-7 — Erasure/tidy. Tidy and erase, retained as one supplied maintenance referent with separate mechanisms. Implementation conclusion status: wired. Tidy compares active unsuppressed facts for near duplicates, keeps the longest statement, and optionally asks CMP-2 which remaining facts are session-only. Default is a report; --apply retracts/suppresses selected facts with a generic reason in one Git publication, with caller --keep veto. Skill doctrine requires human review of the list, but the CLI itself accepts --apply. Erase removes current facts/entities, publishes Completed deletion/suppression records, then redacts cited journal events, rewrites reachable memory-branch Markdown history, expires reflogs/prunes unreachable objects, and removes matching intents. Sources: SRC-1 src/tidy.rs:53-61,73-160,172-220, src/erasure.rs:52-162,171-217,223-331,370-384, src/journal.rs:330-372; SRC-2 skills/mem/SKILL.md:58-73.
let reason = match &f.duplicate_of { Some(keep) => format!("tidy: duplicate of {keep}"), None => "tidy: session-only, not lasting".to_string(), }; ---
src/tidy.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28apipeline_state: DeletionState::Completed, ---
src/erasure.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
Completed is written before later erasure phases finish. If publication succeeds and journal redaction fails, a retry reconstructs source-event IDs from facts already removed, so that source set may be empty. No retained per-phase recovery manifest is used by this function. This is a static failure-path inference, not a reproduced incident. External source files, managed writeback files, other refs and backups are outside this erasure loop; all-copy deletion is not established.
RTE-8 — Evaluation. Caller provides rubric with expected fact IDs and required/prohibited substrings. Each case runs lexical and reranked retrieval; deterministic membership/text checks produce side-by-side reports. Conclusion status: wired. This is a bounded retrieval oracle supplied by the rubric author, not a factual ground-truth oracle for extracted claims or faithful downstream model use. No runtime self-adoption of the winning ranker is established by the inspected return function. Source: SRC-1 src/evaluation.rs:34-53,87-150.
let recall = case.expected_fact_ids.iter().all(|id| ids.contains(&id.as_str())); let first_expected_rank = ids .iter() .position(|id| case.expected_fact_ids.iter().any(|e| e == id)) .map(|i| i + 1); let includes_ok = case.must_include.iter().all(|s| text.contains(&s.to_lowercase())); let excludes_ok = case.must_not_include.iter().all(|s| !text.contains(&s.to_lowercase())); cases.push(CaseScore { id: case.id.clone(), category: case.category.clone(), passed: recall && includes_ok && excludes_ok,---
src/evaluation.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
Caller-rubric retrieval evaluation and static retrieval tests. Implementation conclusion status: wired. Caller supplies expected IDs and required/forbidden strings; the command compares lexical and reranked results by recall and text conditions. It neither runs a host task with/without memory nor records faithful host dependence. Static recorded-search tests contain fixtures and assertions, including ignored model-dependent tests, not retained execution outputs. Evidence: SRC-1 src/evaluation.rs:35-53,88-150, tests/recorded_search.rs:1-8,77-152.
RTE-9 — Transport dispatch. CLI resolves store then calls command; stdio MCP dispatches tool calls and returns JSON; HTTP refuses nonloopback bind, dispatches the same operations and exposes progress/result; shell supplies an interactive entry. Conclusion status: wired. Loopback binding is the implemented network restriction, not caller authentication; server root/scope/session identify configured store context, not verified person. No internal human approval gate precedes memory_request_change. Capability exposure is distinct from deployed host permission. Source: SRC-1 src/main.rs; src/mcp.rs:17-89; src/http_serve.rs:34-50,99-145; src/ops.rs:35-51. CLI/MCP/loopback HTTP/shell transport facade. Implementation conclusion status: wired. The named external-agent consumer is documented by SRC-2 README.md:117-122, skills/mem/SKILL.md:39-59; this makes requested recall more than a storage API with a hypothetical caller. MCP returns JSON payload text; HTTP dispatches shared ops and retains process-local operation results for later SSE reads; shell exposes memory and task operations. Evidence: SRC-1 src/mcp.rs:92-191, src/http_serve.rs:25-44,99-161, src/shell.rs:43-51,66-96,142-158, src/ops.rs:35-50. HTTP replay buffers are transient transport state excluded from the durable-memory profile. Neither loopback binding nor a caller's scope label authenticates fact truth.
pub fn bind_listen(listen: &str) -> Result
{ let addr: SocketAddr = listen .parse() .map_err(|_| Error::InvalidContent(format!("bad listen address: {listen}")))?; if !is_loopback(addr.ip()) { return Err(Error::InvalidContent(format!( "refusing non-loopback listen address {listen}" ))); } TcpListener::bind(addr).map_err(|e| Error::io(std::path::Path::new(listen), e)) --- src/http_serve.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
RTE-10 — task append/read. Implementation conclusion status: wired. A host/operator calls tasks_update(title, expected_version); the locked file version must match, otherwise the current version/tasks are returned as a conflict without an append. Success adds a generated ID/title and increments the version. tasks_read delivers the retained list to the requesting host through MCP or shell/common ops. Sources: SRC-1 src/ops.rs:485-529,688-743, src/mcp.rs:131-145, src/shell.rs:142-158. No completion/edit workflow, task planner, inferred task extraction or downstream task execution is shown in these functions. Interrupted in-place file writing has no Git-style recovery route here.
if file.version != expected { ---
src/ops.rs@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
Claims
CLM-1 — README claims Git-first durable, sourced curated facts with validated changes and no concurrent writer overwrites. Conclusion status: claimed; the cooperating publisher's validation/CAS is wired, while blanket truth, host activation or universal same-request semantics are not established. Source: SRC-2 README.md; SRC-1 src/repo.rs:196-330; RTE-2/RTE-3 qualifications above.
The model never writes memory directly: changes go through
memory_request_changeor consolidation, are validated, and publish with compare-and-swap on thememorybranch, so a concurrent writer can never overwrite another's commit. ---README.md@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
Evidenced absences
ABS-1 — no retained host-faithfulness execution evidence in the inspected evaluation/test boundary. Conclusion status: absent. Searched SRC-1 src/evaluation.rs:35-150 and tests/recorded_search.rs:1-152; the relevant mechanisms assess returned IDs/text/ranking, and no host-answer dependence intervention/result is present there. This prevents a faithfulness-tested yes for this source-only analysis, not a conclusion about all external deployments.
Behavioral-authority paths
BAP-1 — Host-facing content arrives through requested tool/CLI reads, hook additionalContext and managed project instruction files. Source-wired delivery has route-specific selection and authority; host loading/compliance remains unobserved. An active fact can be a preference/rule or historical assertion; status is not proof of truth. External host models receive natural-language fact/history/tool text, hook additionalContext, and managed project instructions. Knowledge consumption is afforded via named agents; preferences and AGENTS.md afford instruction force. Duration differs: one result/context versus a persistent managed file. Internal mem delivery is wired; external activation and practical benefit are uninspected. Sources: SRC-1 src/hook.rs:75-110,152-158, src/mcp.rs:168-191, src/cli.rs:1808-1845; SRC-2 README.md:117-122, skills/mem/SKILL.md:39-59.
Codex and OpenCode also read
AGENTS.md; keep it current withmem writeback --to AGENTS.md. ---README.md@6acb13dc35765bf5ccfc87e445dd09c480f1c28a
BAP-2 — Code reads control/checkpoint/receipt/source metadata to select eligible memory, continue consolidation and admit or reject publication. Executable operational authority is wired within named entry paths; direct edits and distinct erasure/task routes are not covered merely by sharing a store. Mem's deterministic consumers interpret OBJ-3 and typed fields in OBJ-1, OBJ-2 and OBJ-5. Force: enforcement/validation for publication and version admission; routing for source/project/identity selection; ranking where retained corpus content determines lexical rarity. Scope is each particular function, not universal correctness. Sources: SRC-1 src/consolidate.rs:108-157, src/search/lexical.rs:96-148, src/ops.rs:182-189,499-519,615-631, src/repo.rs:218-238,309-324, src/validate.rs:84-123.
Runtime account
An operator/host chooses a resolved local/global/root store and invokes a CLI, hook or tool operation. Input ingestion records source material; consolidation produces bounded proposals and validates/publishes the candidate memory tree. Host reads can retrieve facts and raw journal evidence, while automatic hooks and manual writeback deliver selected text for later host context. The artifact returns results, revisions or context JSON. It does not run the host agent's overall loop, prove a recalled fact was used, or establish task completion.
The inspected public APIs group mutations behind change and publication code, with explicit erasure/task alternatives. Human/model callers propose changes; source filters, shape checks, model lasting judgment, dedup heuristics and domain validator decide different kinds of admission. CAS can veto a stale base; recovery preserves stale intents for a new request. There is no independently supplied answer key in consolidation: source text is quote-occurrence evidence, not ground truth. Evaluation has a separate caller-authored retrieval rubric. Normal operation serves ongoing user/project memory; evaluation/bench are bounded measurements, not a demonstrated improvement curriculum.
Static forcing cases: missing store terminates; forced LLM without configured key errors and parse/network exhaustion publishes no batch; filtered windows still advance consolidation checkpoint; stale base or changed publisher digest conflicts, while the operation-level early receipt shortcut returns replay; hook errors omit context without blocking host; nonloopback HTTP bind is refused. These branches delimit their actual enforcement points. No dynamic check planned. Considered offline CLI publication/recovery and retrieval tests; static source supports wiring and identifies the important branch differences. Running bundled fixtures would not establish production extraction fidelity or host activation. No model download, network inference, destructive erasure or benchmark was performed.
Current grants/OS isolation are uninspected. Store selection/project filtering is routing, not a complete multi-user authorization scheme. Git wrapper disables hooks/signing/selected aliases and removes inherited Git environment under its own command construction; this is a concrete subprocess control, not isolation of arbitrary host code. Provider calls can send selected source/known facts for extraction and candidate text for ranking. Full deployment data governance is outside this source-boundary claim.
| Route | Return and later consumer | Selection, expiry, visibility and effect limit |
|---|---|---|
| RTE-1 | Import counts; journal later read by consolidation/search | Source-role/path/digest/sequence; retained until redaction; host visibility only through later reads |
| RTE-2 | New/current revision and dispositions; facts/checkpoint later reused | Scope/window/status/source checks; supersession and suppression; extractor sees bounded batches, not all history; activation uninspected |
| RTE-3 | Receipt/result; later recall and recovery | Caller IDs/base/digest plus route-specific shortcut; status/control withdrawal; host sees returned result, not guaranteed all reasons |
| RTE-4 | Requested rows/history/source text | Query/ID/project/time/control filters differ by branch; immediate caller visibility; no automatic host action |
| RTE-5 | Hook JSON or detached sync launch | Identifier/lexical selectors, count bounds; one context event; swallowed errors omit delivery; activation uninspected |
| RTE-6 | Written project-file path/text | Caller project/all/file-fact selection; retained until rewritten; host-file visibility afforded, refresh/withdrawal not automatic |
| RTE-7 | Report or mutation revision/cleanup result | Duplicate/session-only/caller erase criteria; caller keep veto; phases have separate failure limits; copies outside loop excluded |
| RTE-8 | Rubric scores returned to evaluator caller | Expected IDs/text; no automatic winner admission; later model use inapplicable to this return route |
| RTE-9 | JSON/SSE/shell result to requesting host | Configured store/scope and operation; HTTP process-local replay buffer; external host grants/activation uninspected |
| RTE-10 | Current tasks/version or conflict | Exact expected version admits append; no expiry; named host explicitly reads retained list; task execution uninspected |
Lens scoping
Memory/context scope
Full lens on the artifact's whole retained-memory lifecycle, including raw journal, entity facts, controls/checkpoints, explicit changes, task storage, extractor alternatives, retrieval/ranking, hooks/writeback, erasure and evaluation. Source-native memory is the product's principal effect; external host/provider behavior is excluded but its limits remain explicit.
Epistemic scope
Full lens on source-to-fact transformation, occurrence/durability/duplicate checks, active-status admission, correction/supersession, retrieval ranking and rubric evaluation. The central question is what sourced/validated memory licenses. Content filters, Git publication and host instruction force have different warrant domains.
Lens outputs
Memory/context lens
Acquisition and learning are distinct. RTE-1 records source text and metadata without making it durable knowledge. RTE-2 automatically derives readable facts from selected user traces, persists them in OBJ-2 with source evidence and symbolic identity/status, and connects them to later recall/hook/writeback consumers. Both the regex and LLM branches therefore satisfy this report's trace-learning meaning. Assistant and Tool roles can remain in OBJ-1 for recall but do not pass these extraction branches. No separate continuation-summary generator was found in the inspected acquisition/consolidation routes; imported host summaries remain imported material, not a second mem-generated learning mechanism.
The imported-document branch must be kept separate: a changed Markdown file becomes another Note event. The LLM can derive facts from it; the rules branch rejects Notes. Both branches nevertheless call old-file retirement after extraction. Consequently a rules-mode pass on changed Markdown can supersede old file-derived facts without deriving replacements. Even an LLM pass can retire an old statement after a newer rewording was rejected as a near duplicate, because old-only source lineage remains. These are static consequences of RTE-2's ordering, not observed data loss (SRC-1 src/consolidate.rs:154-158,221-251,290-294,362-410,417-444).
Checkpointing is positional. RTE-2 chooses the end before the scope filter and advances across the full position window even when no filtered events remain. Therefore one shared checkpoint can move past another scope's events; quarantine is not a retained retry queue in the current consolidator. A new model/extractor run starts after that same mark. The API's optional scope, CLI's Some(cli.scope), and automatic sync's ordinary CLI invocation share this behavior (SRC-1 src/consolidate.rs:114-140,178-203, src/cli.rs:2264-2269). The batch's event high-water bound also does not bound initial allocation: read_from first scans and collects the entire post-checkpoint backlog. Model input is separately bounded: 2,000 user-event characters, 8,000 Note chunks, 16,000 event-text bytes as accumulated by .len(), and an 8,000-byte statement budget over at most 200 existing entities/40 facts each. These are selection limits, not a complete token/context guarantee (SRC-1 src/consolidate.rs:570-574,642-674,801-815, src/journal.rs:388-397).
Rationale retention is partial. The extractor prompt names “decisions and why,” but the fact schema has statement/evidence rather than a mandatory reason field. A reason survives if the model includes it in the statement or quote; place stores a single SourceRef. Ordinary search/read/history/hook/writeback primarily deliver the statement, not stored evidence. CLI --source-lines can retrieve raw source-event excerpts, making diagnosis possible when those excerpts contain the reason; it is not automatic delivery of a rationale. Exact-source recurrence upserts a fact and can replace earlier SourceRef attribution instead of accumulating it. RTE-3 correct/remember do not retain the request's reason separately; forget/tidy preserve generic reason text in Controls, while consumer filters read target membership rather than interpreting the reason (SRC-1 src/consolidate.rs:576-598,376-410, src/fact.rs:13-35, src/entity.rs:91-99, src/cli.rs:2333-2372, src/change.rs:108-155, src/controls.rs:83-96).
RTE-3 admits direct edits under structural validation, with no factual oracle. RTE-7 tidy criticizes duplicate/session-only content through explicit symbolic rules and optional model judgment; the caller can inspect and veto candidates. It records changed reliance but provides no attribution of improved future capacity to that criticism. Erasure is stronger withdrawal with narrower failure guarantees, as its canonical route records. Neither index rebuilding nor bulk event-ID skipping alone supplies semantic curation.
For pull, the requesting role is an external coding agent or human invoking the CLI, MCP or shell, as the README/skill explicitly documents. RTE-4 fulfills their query or identifier request; RTE-9 carries the response. A returned fact is available to that consumer, but its activation in reasoning is not inspected. Search defaults to eight results in common ops and clamps to 1–20; factual lexical candidates cap at twenty before project filtering, so the limit can omit otherwise-relevant project facts before filtering. Journal scan is linear in retained events with bounded ranking structures; the combined pool is reranked, not a persistent embedding retrieval index. Scope filtering applies to journal rows, while fact project filtering uses entity families and source filtering uses SourceRefs (SRC-1 src/ops.rs:54-67,160-242, src/search/journal.rs:90-173).
Direct fact history uses current entity records, including superseded statuses after excluding controlled targets; it is not unrestricted Git archaeology. Raw journal identifiers resolve full content without the fact-control filter. Soft forget therefore withdraws a curated fact while its source transcript remains separately recallable. Erase changes that only after physical redaction succeeds. Optional CLI source excerpts key the journal map by event ID, so duplicate IDs choose the last scanned event; IDs plus sequence are used for direct raw reads. Provenance display is not an infallible join or epistemic endorsement (SRC-1 src/ops.rs:245-332,603-685, src/cli.rs:2333-2372).
For push, RTE-5 is the concrete automatic selector: session start uses pref_user, prompt-time supply uses lexical content plus project identity, and its channel is hook additionalContext. Its static advice to search or remember does not itself count as accumulated memory. RTE-6's file generation is explicitly requested, followed by afforded automatic host loading of the generated block. That second boundary supports coarse delivery without requiring the host to request a memory query; no inspected host parser establishes exact deployed priority. The retained file has no automatic refresh or withdrawal link to subsequent forget/erase. RTE-10 supplies task titles only upon a supported request; the names “task” and “session” establish neither online learning nor task execution.
The storage/form union covers the full scoped payload: natural-language journal/fact/task text plus symbolic control/access data in files and Git. Compiled Markdown displays do not erase the authority of YAML facts. Opaque inference components CMP-2 and CMP-3 are distinguished from the user memory they consume; their parameters are not changed by the inspected trace routes, and exact assets remain uninspected. Temporary HTTP results and candidate lists are not durable memory just because they use in-process maps.
The lineage union comes from RTE-1 imports, RTE-2 trace extraction/document compilation, RTE-3 and RTE-10 authoring, and automatic index/control/writeback projections. Manual means direct authored changes by the operator/caller; automatic includes code-generated extraction and curation after human initiation. Whole-system agency beyond these interfaces is uninspected.
Curation values are mechanism-based. Consolidate is reduction of already-retained traces into selected standing statements; it does not mean the raw journal is deleted. Dedup includes lexical near-duplicate checks/tidy over existing entries. Evolve includes same-ID upsert/correction. Invalidate covers retained-history supersession and suppression. Decay is the vocabulary's forgetting/downweighting category, here covering physical erase and timed retrieval expiry; no gradual strength-decay model is inferred. Neither the command name consolidate nor a model's capacity to invent warrants synthesize, and no tier/salience promotion mechanism was found in these branches.
The authority union uses the weakest afforded basis because host interpretation is outside the code boundary. Mem itself enforces symbolic control and admission rules; facts/content also route and influence corpus-based lexical ranking. A static reranking prompt is not accumulated ranking memory. Instruction authority is the explicitly named host-file/preference route, not every fact. Validation authority is scoped to typed reference/control/version consumers, not semantic truth.
Trace-learning axes all describe RTE-2's automatic trace-to-fact transformation, followed by RTE-4 or RTE-5 delivery and optional RTE-6 projection. Session-log user messages and generic journal event imports can qualify; Tool-role history does not enter extraction. Note import handling broadens inputs to calendar/voice event material but does not make imported Markdown instructions agent traces. The prescribed and implemented destination is reusable standing knowledge across tasks, with project grouping and general preferences; the source prompt explicitly rejects one-session plans. Timing is offline batch processing and staged session-end triggering, with no per-prompt extraction. Distilled natural-language statements coexist with operative symbolic fields. Memory-file extraction, manual edits, task storage and retrieval reranking do not add independent trace-learning horizons. Faithfulness remains a bounded no because RTE-8 has retrieval contracts and no retained host dependence execution evidence.
Epistemic lens
-
Boundary: SRC-1/SRC-2 and the named routes above; external host decisions, provider internals and live truth state excluded. CLM-1 claims curation and validated durable retention. No observed candidate/store or controlled model-behavior experiment supplied.
-
Objects: OBJ-1 messages/files carry user assertions/instructions with unverified underlying truth. OBJ-2 fact statements can describe projects/people or encode policy; occurrence evidence and active status differ from factual warrant. OBJ-3 control records express operational disposition and progress, not independent truth. OBJ-4 delivery reshapes/selects these contents; a context channel may grant instruction force without new warrant. Schemas/sources are addressable fields, while rationale survives only when present in retained evidence/statement or optional reason; no theory-history guarantee follows.
-
Authority ledger:
| Route/function | Architectural status | Content relation | Evaluator, admission and authority | Limit |
|---|---|---|---|---|
| RTE-1 acquisition | implemented | truth-apt acquisition/import | recognized source/role/project → journal | origin fields do not verify assertions |
| RTE-2 transformation | implemented | indeterminate LLM paraphrase; rules reshape matched strings | model proposals or regex; explicit assertion records | quote occurrence does not establish entailment; rules can lose polarity |
| RTE-2 check/evidence production | implemented | occurrence derivation and non-truth-apt lasting/dedup judgment | normalized ordered quotes, length/shape, model lasting flag, word overlap | no separate fact-truth or semantic-equivalence evaluator |
| RTE-2 disposition | implemented | active/superseded/blocked status update | deterministic filters/source-version rule grant retrieval eligibility | operational acceptance, not general epistemic acceptance |
| RTE-2 retention | implemented | no further content change | publish fact/index/checkpoint/dispositions | versioned durability does not add warrant |
| RTE-3 check/disposition | implemented | caller-authored change plus status/revision update | schema/reference checks and CAS; correct/forget allowed | no compulsory content-directed criticism or independent truth oracle |
| RTE-4 operational selection | implemented | no new source claim | lexical/reranker relevance and eligibility choose delivery | relevance score does not prove truth |
| RTE-5/RTE-6 operational consumption | implemented at artifact boundary | selected/formatted retained content | host channels BAP-1; semantic reliance unobserved | delivery can increase force without increased warrant |
| RTE-7 disposition | implemented subject to integrated source scope | removal/suppression update | caller/heuristic criteria control future availability | forgetting is not a refutation |
| RTE-8 check/evidence production | implemented | result derived from fixed rubric and retrieved rows | expected IDs/substrings score retrieval | no automatic promotion or task-performance license |
-
Lifecycle: OBJ-2 LLM-produced statements have indeterminate preservation/ampliation; implementation retains source reference and quote but checks occurrence, shape and model judgment only. Candidate generation, admission and downstream availability are implemented; observed candidate state is no instance observed at every phase. No candidate-linked consequence test or truth acceptance is established. Rules reshaping is non-ampliative in intent, with a specifically visible polarity-loss limit; discovery lifecycle not applicable to literal extraction itself. OBJ-1 acquisition and OBJ-4 selection have unknown source warrant. OBJ-3 progress/control updates have no candidate truth-apt theory output. RTE-8 metrics are entailed within its rubric domain; they do not validate the statements being retrieved.
-
CLM-1 comparison: source-backed curation and CAS publication exist, but sourced text is not necessarily entailed text, and validation is not semantic proof. RTE-3's operation shortcut narrows universal replay claims. Source-only branches supply no observed or causal support for durable memory improving agents. The source's instruction to retain enduring facts asks for a model judgment that code checks only as a boolean before other admission rules.
-
Bounded conclusion: mem implements a practical source-to-memory admission and delivery chain, with explicit state/control records. That chain can make past assertions available and can preserve quoted reasons. Its occurrence, schema, version and retrieval checks operate in narrower domains than factual truth or future task benefit. No whole-system epistemic grade follows.
Reconciliation
Verified complete specialist report, run/source/boundary, exact report SHA and unchanged input/method hashes. Registered MEM-OBJ-1 → OBJ-5, MEM-RTE-1 → RTE-10, MEM-ABS-1 → ABS-1. Original combined OBJ-3 and RTE-7 identities remain combined; added facets do not reassign them.
Accepted every material issue: versioned task append/read; bounded source-only faithfulness absence; rules versus Note/User LLM extraction and occurrence/lasting limits; positional checkpoint and file-retirement ordering; raw/fact/history/source-excerpt differences; writeback's distinct eligibility and persistent copies; erasure's early Completed state and retry limitation; rationale retention versus consumption; model resolution versus readable memory form. Report quotes are carried onto canonical records, with duplicate excerpts retained once. No substantive conflict remains. Baseline polarity-loss and wrapper replay findings independently qualify their own paths; they do not strengthen the specialist profile.
Bounded synthesis
mem separates source journal, curated Git memory and host delivery. It makes edits/version conflicts and many memory dispositions inspectable; automatic hooks reduce dependence on explicit recall. The strongest supported contribution is wired retention, selection and controlled publication, with important per-entry limits and distinct raw/fact delivery paths.
Conjectural learning remains uninspected: correction and quoted evidence do not show an operative formulated theory criticized for what it says with attributable improved future capacity. Reflection is wired narrowly for consolidation progress and control state feeding subsequent processing; that does not establish a reflective theory builder or a self-model of knowledge quality. Self-improvement remains uninspected: evaluation returns retrieval scores and memory evolves, but no observed improvement or automatic machinery revision is shown in this boundary. Candidate-linked extraction audits, controlled host recall tests and fault/conflict traces would strengthen separate claims.
Limitations
| Limitation | Affected IDs | Inspected boundary | Conclusion prevented | Evidence needed |
|---|---|---|---|---|
| Host/provider operation excluded | CMP-2, CMP-3, CMP-4 | emitted requests/context | exact model identity and actual downstream activation | deployment/provider and candidate-linked host evidence |
| Occurrence/shape differ from entailment | OBJ-2, RTE-2 | source matcher and proposal gates | factual soundness and lasting truth | proposition-specific source/claim checks and live validation |
| Entry-specific publication semantics | RTE-3, RTE-7, RTE-9 | wrapper/publisher alternatives | universal replay or concurrent-mutation guarantee | per-entry fault/concurrency tests |
| No observed runs | RTE-8, BAP-1 | source/static tests | measured retrieval/agent capacity benefit | retained results and controlled comparisons |
| Separate memory copies and erase phases | OBJ-1, OBJ-4, RTE-6, RTE-7 | writeback/erase static branches | all-copy withdrawal and crash-safe erasure | fault-injected retained execution and host-file coordination |
Verification and blockers
Semantic verification
Checked API/publisher boundary, forcing cases, extractor variants, quote-occurrence versus entailment, polarity/dedup transformation limits, provider identity limits, and separation of retrieval rubric from host-faithfulness testing. Integrated all ten routes and five memory objects, including task files and managed host files. Known profile sets include raw/fact/control/task/writeback paths and both model/rules extractors. RTE-2 alone supplies automatic trace transformation: session logs/event streams to durable natural-language/symbolic facts, cross-task/per-project, offline or staged by RTE-5. Imported Markdown compilation, task appends, reranking and raw replay do not add trace-learning horizons. RTE-5 identifier push selects pref_user and project identity; lexical push selects fact statements by prompt overlap; RTE-6 affords coarse later host loading. RTE-4/RTE-10 are explicit pull. Opaque CMP-2/CMP-3 weights are outside accumulated memory rather than falsely counted as readable payload. RTE-8/ABS-1 support only bounded no faithfulness testing; no observed behavior or capacity upgrade. Erasure inference and writeback differences remain explicit.
Deterministic validation
Target: kb/reports/state/agentic-system-analysis/AAS-2026-09-25-instinctual-memory-01/result.md; full validation after integration; guarded publication verifies every source anchor and retained quote.
Blockers
none