Skip to content

🔒 Make AI graph cleanup partition-safe - #95

Merged
marcelsamyn merged 1 commit into
mainfrom
fix/partition-safe-graph-cleanup
Sep 14, 2026
Merged

marcelsamyn merged 1 commit into
mainfrom
fix/partition-safe-graph-cleanup

Conversation

@marcelsamyn

@marcelsamyn marcelsamyn commented Sep 14, 2026 •

Copy link
Copy Markdown
Owner

AI graph cleanup now carries one authorized partition through graph discovery, model context, deterministic maintenance, and every model-proposed mutation. Cross-user, cross-partition, and inactive-partition rows are rejected or excluded without weakening provenance, citation, protected-claim, identity, or merge safeguards.

The public request path, placeholder seeding path, and worker remain fail-closed for partitioned and workspace cleanup. This PR makes the replacement path safe to validate; it does not enable or run production cleanup.

Validation

  • pnpm run build:check
  • pnpm run lint
  • 45 focused cleanup, partition, route, placeholder, deduplication, and predicate-audit tests pass
  • The full suite reached 951 passing and 47 skipped tests. Three unrelated suites could not load because their standalone test process lacked required service environment variables.
  • Code review: harness-native fallback — the external cross-model route was denied before any code was sent; local correctness and security reviews found two safety defects, and both fixes are included.
  • Hosted Codex review found two partition-cache invalidation gaps. Both were fixed, tested, replied to, and resolved before the final green review pass on b3bf9bd.

Post-Deploy Monitoring & Validation

Do not remove the fail-closed guards in this deployment. In a later validation environment, create two users with active and inactive partitions, then confirm that cleanup can read and mutate only the selected active partition. Treat any cross-partition read, model-context item, mutation, replay after partial work, or change to a protected claim as a release blocker.

Enabling or executing production cleanup requires a separate explicit owner approval after that end-to-end validation. Until then, mitigation is to keep the request and worker guards unchanged; rollback this commit if normal non-cleanup ingestion, browse, search, or edit flows regress.

Fixes #94


Compound Engineering

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-14T11:23:24.713018Z b3bf9bd New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c5de4db96a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/lib/jobs/cleanup-operations.ts
@marcelsamyn
marcelsamyn force-pushed the fix/partition-safe-graph-cleanup branch from c5de4db to 93f962d Compare September 14, 2026 11:10

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 93f962dc30

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/lib/jobs/cleanup-operations.ts
@marcelsamyn
marcelsamyn force-pushed the fix/partition-safe-graph-cleanup branch from 93f962d to b3bf9bd Compare September 14, 2026 11:18
@marcelsamyn
marcelsamyn merged commit 4bf01ed into main Sep 14, 2026
1 check passed
@marcelsamyn
marcelsamyn deleted the fix/partition-safe-graph-cleanup branch September 14, 2026 11:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Make AI graph cleanup partition-safe before re-enabling it

1 participant