Make engram deletes/updates/forgets immutable on the launch branch
The ship-soul builds from this branch, which has the bounded-persona floor (#93) but never received the tombstone/supersede immutability fix (that went to main; hotfix diverged before it). So the launch soul failed verify-soul-contract IMMUTABILITY on the delete/update/forget routes — they hard-removed engram nodes via engram_forget/mem_forget. Apply the same fix, mirroring the knowledge routes' supersede pattern: - node/update -> create new node + "supersedes" edge to the original, KEEP the original (no engram_forget). - node/delete, memory/delete, memory/forget, cultivate forget, and the autonomous awareness forget -> TOMBSTONE via the canonical mem_tombstone (memory.el): keep the node + its edges, record a Tombstone marker, hide from default bounded list reads (?include_deleted recovers). Never engram_forget. The MCP forget tool now routes to the tombstoning delete instead of faking a delete. Internal GC that genuinely removes transient nodes (awareness inbox-trigger consume, consolidation dedup, session-summary replace, telemetry pruning) still calls engram_forget directly and is unchanged. Regenerated dist/soul.c (single-TU) + per-module dist/{memory,awareness, neuron-api}.c from THIS branch's sources under a 3GB physical-RSS watchdog (peak ~32MB), built against the release el_runtime (v1.0.0-20260501). The bounded-persona floor is preserved — verified in the emitted C and the linked binary (BOUNDED PERSONA / SOUL_PERSONA_NAME strings present). verify-soul-contract.sh: GATE PASS — PRESENCE all 27 routes, IMMUTABILITY 5/5 KEPT (memory-update, memory-delete, node-update, node-delete, memory-forget).
This commit is contained in:
@@ -43,8 +43,32 @@ fn mem_strengthen(node_id: String) -> Void {
|
||||
engram_strengthen(node_id)
|
||||
}
|
||||
|
||||
// mem_tombstone — immutable "delete": KEEP the node and all its edges; record a
|
||||
// Tombstone marker (content = target id, label "tombstone:<id>", wired with a
|
||||
// "tombstones" edge). Never engram_forget. Default bounded list reads hide
|
||||
// tombstoned nodes; ?include_deleted=1 recovers them. This is the ONE canonical
|
||||
// tombstone helper — every forget path routes through it. Defined here in
|
||||
// memory.el (imported first) so awareness.el and neuron-api.el can both call it.
|
||||
fn mem_tombstone(node_id: String) -> String {
|
||||
let tags: String = "[\"Tombstone\",\"status:deleted\"]"
|
||||
let marker: String = engram_node_full(
|
||||
node_id, "Tombstone", "tombstone:" + node_id,
|
||||
el_from_float(0.01), el_from_float(0.01), el_from_float(1.0),
|
||||
"Episodic", tags)
|
||||
if !str_eq(marker, "") {
|
||||
engram_connect(marker, node_id, el_from_float(1.0), "tombstones")
|
||||
}
|
||||
return marker
|
||||
}
|
||||
|
||||
// mem_forget — NOTE: no longer a hard delete. Engram nodes are immutable, so
|
||||
// this now TOMBSTONES (via mem_tombstone): the node and its edges are kept and
|
||||
// stay recoverable. Every caller (the /memory/forget route and the cultivate
|
||||
// forget op) is non-destructive as a result. Internal GC that genuinely needs
|
||||
// removal (session-summary replace, telemetry pruning) calls engram_forget
|
||||
// directly and is unaffected by this.
|
||||
fn mem_forget(node_id: String) -> Void {
|
||||
engram_forget(node_id)
|
||||
let _marker: String = mem_tombstone(node_id)
|
||||
}
|
||||
|
||||
// mem_consolidate — structural scan plus salience-evolution pass.
|
||||
|
||||
Reference in New Issue
Block a user