Repository navigation
🔒 Make AI graph cleanup partition-safe - #95
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c5de4db96a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
c5de4db to
93f962d
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 93f962dc30
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
93f962d to
b3bf9bd
Compare
AI graph cleanup now carries one authorized partition through graph discovery, model context, deterministic maintenance, and every model-proposed mutation. Cross-user, cross-partition, and inactive-partition rows are rejected or excluded without weakening provenance, citation, protected-claim, identity, or merge safeguards.
The public request path, placeholder seeding path, and worker remain fail-closed for partitioned and workspace cleanup. This PR makes the replacement path safe to validate; it does not enable or run production cleanup.
Validation
pnpm run build:checkpnpm run lintb3bf9bd.Post-Deploy Monitoring & Validation
Do not remove the fail-closed guards in this deployment. In a later validation environment, create two users with active and inactive partitions, then confirm that cleanup can read and mutate only the selected active partition. Treat any cross-partition read, model-context item, mutation, replay after partial work, or change to a protected claim as a release blocker.
Enabling or executing production cleanup requires a separate explicit owner approval after that end-to-end validation. Until then, mitigation is to keep the request and worker guards unchanged; rollback this commit if normal non-cleanup ingestion, browse, search, or edit flows regress.
Fixes #94