Repository navigation
feat(admission): enforce record exclusions across indexing and recall - #180
Open
HengYangDS wants to merge 6 commits into
Open
HengYangDS wants to merge 6 commits into
HengYangDS wants to merge 6 commits into
Conversation
Author
|
The upstream CI run for this fork PR is currently |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
A new record-level exclusion cannot be enforced by the existing project filter or whole-conversation marker alone. Direct parser/index/database paths, summaries, MCP/display reads, and retained search rows can otherwise disagree about what is admissible. A previously indexed row must not remain visible merely because it predates a changed operator policy.
Change
record-exclusions.jsonin the existing configuration directory. It binds inclusive physical line ranges and native tool-call IDs to session ID plus transcript basename, not any host-specific absolute path. No policy file or personal exclusions are included in this PR.--repairrefuses to start while either screening failure remains; invalid record policy fails verification before a false healthy result.Verification
mainat7e06519:npm run build,node --check dist/mcp-server.js, and the current full local suite passed (448/448 on Node 26.10.0).Review and CI limits
distanceto a vec0 column rather than the computed alias. The query now usesretrieval_distance; the two ordering regressions and the full suite pass on the updated head.dist/mcp-server.jsdiff is large because upstream does not lock transitive dependency layout. Source/test changes are the reviewable semantic core.npm installand official Node 22/24 CI are not verified. The upstream CI run isaction_requiredpending maintainer approval; no Node 22/24 job executed.Additional local Node matrix (2026-09-26)
On macOS arm64, this current PR head passed
npm run build,node --check dist/mcp-server.js, and the complete test suite on Node 22.23.3 and Node 24.21.0 (448/448 tests on each). Each run used a fresh source snapshot and the corresponding per-Node native dependency tree, with a pre-seeded local embedding-model cache and an isolatedOMP_HOME. The dependency trees were installed from PR #179 (all five PRs have the same dependency declarations); this is not a separate empty-cache install for each PR, an Ubuntu result, or an upstream CI pass.