Skip to content

Make the same analysis read the same way twice - #283

Merged
adamjohnwright merged 1 commit into
mainfrom
011-phase7-stability
Sep 20, 2026
Merged

adamjohnwright merged 1 commit into
mainfrom
011-phase7-stability

Conversation

@adamjohnwright

Copy link
Copy Markdown
Contributor

Spec 011 Phase 7 — the last one. The feature is complete.

Stability is reuse, not determinism

FR-014 wants a token to yield the same summary request after request. Generation cannot provide that — the same question through the same surface scores 0.33 similarity twice — so stability comes from storage, and FR-015 exists because the interface must say which it is looking at.

cached on start is now true when a summary was served rather than generated. It was always false before, because nothing was ever stored.

Every part of the key earns its place

(token, release, tier):

  • release — the Analysis Service deletes results on a new release. Without it we serve a confident account of an analysis that no longer exists.
  • tier — an aggregate summary and a disclosing one are different artefacts. Sharing a key would hand a reader who chose the default a summary built from their identifiers.

And it is keyed on the tier that applied, not the one requested. A disclosure that could not be honoured produces an aggregate summary; storing that under identifiers would serve it back later as though the identifiers had been used — the Phase 4 failed-disclosure bug, preserved in the cache instead of the stream.

Two deliberate behaviours

  • An empty summary is never stored. A failed or abandoned generation leaves no text, and storing it would serve the emptiness back forever, indistinguishable from a result with nothing to say.
  • Eviction drops the oldest rather than refusing the newest. An evicted reader regenerates; a refusing store silently stops working for everyone after a few hundred readers.

Known state, not a bug

The store is in process and lost on deploy. That is honest only because cached makes regeneration visible. The durable version is recorded as open in research D4 — there is no existing home to reuse, since POSTGRES_LANGGRAPH_DB is unset on beta and LangGraph already falls back to MemorySaver.

Caught while wiring it

The tests began serving each other cached summaries, because the store is module state that outlives a request by design. The fixture now gives each test its own, as it already did for the limiter — otherwise a test failure would have looked like the feature being broken.

Verified by sabotage, with the sabotage asserted to have applied. All checks gated with set -e.

🤖 Generated with Claude Code

Spec 011 Phase 7, which completes the feature.

FR-014 wants a token to yield the same summary request after request.
Generation cannot provide that -- the same question through the same surface
scores 0.33 similarity twice -- so stability is **reuse**, and FR-015 exists
because the interface must say which it is looking at. `cached` on `start` is
now true when a summary was served rather than generated, and it was always
false before because nothing was ever stored.

Keyed `(token, release, tier)`, and each key earns its place. Release,
because the Analysis Service deletes results on a new release and without it
we would serve a confident account of an analysis that no longer exists.
Tier, because an aggregate summary and a disclosing one are different
artefacts -- sharing a key would hand a reader who chose the default a
summary built from their identifiers, which is a disclosure nobody asked for.

Keyed on the tier that *applied* rather than the one requested. A disclosure
that could not be honoured produces an aggregate summary, and storing that
under `identifiers` would serve it back later as though the identifiers had
been used -- the failed-disclosure bug from Phase 4, preserved in the cache
instead of the stream.

Two behaviours chosen deliberately. An empty summary is never stored: a
failed or abandoned generation leaves no text, and storing it would serve the
emptiness back forever, indistinguishable from a result with nothing to say.
And eviction drops the oldest rather than refusing the newest, because an
evicted reader regenerates while a refusing store silently stops working for
everyone after a few hundred readers.

The store is in process and lost on deploy. That is honest only because
`cached` makes regeneration visible, and the durable version is recorded as
open in research D4 rather than implied.

Caught while wiring it: the tests began serving each other cached summaries,
because the store is module state that outlives a request by design. The
fixture now gives each test its own, as it already did for the limiter.

Verified by sabotage, with the sabotage asserted to have applied.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@adamjohnwright
adamjohnwright merged commit 31db4ca into main Sep 20, 2026
10 checks passed
@adamjohnwright
adamjohnwright deleted the 011-phase7-stability branch September 20, 2026 18:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant