Repository navigation
feat(context): 层级项目指令、长期记忆与恢复点浏览 - #108
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
AGENTS.md,CLAUDE.md,.prayu/instructions.md, and.prayu/rules/**/*.md, including root-to-target inheritance, closest-scope precedence, stable fingerprints, source hashes/scopes, conflict explanations, ignore rules, and fail-closed path/size/depth/concurrency checksCloses #106.
Project instructions and precedence
AGENTS.md,CLAUDE.md,.prayu/instructions.md, then lexically sorted.prayu/rules/**/*.mdwhy_effective; conflicts remain visible and explain why the closest directory wins.prayu/instructions.ignoresupports bounded canonical relative-path globs; absolute paths,..escape, NUL/invalid UTF-8, empty/special files, symlinks/junctions/reparse points, concurrent replacement, malformed ignore input, and configured count/size/depth overflow fail closedproject_instruction_snapshot.v1; refresh appends a new immutable revision only after a diff and explicit dual-fingerprint confirmation, preventing stale-UI/time-of-check replacementThe fixed precedence is system/operator input > Go-owned runtime safety policy and current authority > explicit Run selections > pinned project instructions and explicit memory > ordinary files/history/tool output. Project text may influence workflow, formatting, and validation advice only. Its authority projection is always false for tools, network, secrets, Debug, plugins, hooks, MCP, policy overrides, and every other capability.
Explicit memory lifecycle
context_memory.v1supportsuser(local-user) and Workspace-boundprojectscopes with title/content hash, status, source provenance, deduplicated references, optional retention, redaction state, operator identities, timestamps, and an optimistic version.env, stdin, terminal input, and keystrokes are always rejectedrecoverable=false; immutable checkpoints retain only memory ID/version/hash, never the memory body, and report disabled/expired/deleted/version driftCheckpoint, Fork, Resume, and browsing
continuity_snapshot.v1pinned into the new Runcreatedstate and newly constructed non-authorizing execution snapshotsCLI additions include
context instructions, fullcontext memorylifecycle/export commands, andsession tree|checkpoint|fork|resume. HTTP adds read routes for memories/export, Run project instructions, and session trees plus control-bearer-protected create/edit/delete/refresh/checkpoint/fork/resume routes with strict JSON, query, size, duplicate-field, and unknown-field validation.Schema, restart, and compatibility
context_memories,run_instruction_snapshots, andsession_continuity_nodeswith indexes, validation constraints, foreign keys, and immutability triggersSecurity and compatibility boundaries
Validation
go test -timeout 20m -count=1 ./...go test ./internal/store -count=1 -timeout 20m— full v1-v114 migration/store suite passed in 1025.416sgo test ./internal/app ./internal/application ./internal/contextmgr ./internal/domain ./internal/events ./internal/httpapi ./internal/projectconfig ./internal/repository -count=1 -timeout 10mgo test -race ./internal/contextmgr ./internal/projectconfig -count=1 -timeout 10mgo vet ./...go build ./...go mod verifyandgo mod tidy -diffnpm test -- --run— 60 files / 246 tests passednpm run typecheck,npm run check:api, andnpm run buildnpm audit --audit-level=high— 0 vulnerabilitiesAudit
README.md,README.en.md, usage/architecture/HTTP docs, bilingual lifecycle/threat-model guidance, OpenAPI artifacts, and ADR 0115 were updated.Manual evidence still required
The PR is intentionally Draft. CI should execute the Linux path/symlink cases on a real Linux filesystem, and the Desktop Context tab still needs reviewer-facing screenshots/manual interaction evidence for instruction drift confirmation, memory deletion, checkpoint creation, branch comparison, Fork, and Resume before merge.
CI follow-up
The first Actions attempt exposed the same Desktop test-fixture failure in three jobs: Windows Desktop shell, macOS Desktop shell, and the Portable ZIP reproducibility build (which runs the Desktop boundary suite before comparing artifacts). Both failing tests wrote a raw
t.TempDir()path directly into the workspace store, bypassing the productionRegisterWorkspaceDirectorycanonicalization path; hosted-runner temp roots may traverse a platform alias/junction, so project-instruction discovery correctly failed closed with HTTP 412.Commit
e4941e0changes only those two fixtures to register their temporary Workspace through the real production boundary. It does not relax symlink/junction rejection. The exact Windows CI command and both focused cases pass locally:go test -tags "desktop,wv2runtime.error" -count=1 ./cmd/cyberagent-desktop ./internal/desktop ./internal/webui -timeout 10mgo test ./internal/desktop -count=1 -timeout 10m