From b61a43cf769c1931f32c3c41c0fa8a9965308c8f Mon Sep 17 00:00:00 2001 From: Galin Iliev Date: Sun, 9 Aug 2026 20:46:05 -0700 Subject: [PATCH] test(memory): inventory remaining Phase 0 ingress paths --- ...emory-authorization-path-inventory.test.ts | 96 +++++++++++++++++-- .../memory-authorization-path-inventory.ts | 35 +++++++ 2 files changed, 123 insertions(+), 8 deletions(-) diff --git a/src/plugins/memory-authorization-path-inventory.test.ts b/src/plugins/memory-authorization-path-inventory.test.ts index b7c20e4c2314..e68413d9ab99 100644 --- a/src/plugins/memory-authorization-path-inventory.test.ts +++ b/src/plugins/memory-authorization-path-inventory.test.ts @@ -53,6 +53,7 @@ const REQUIRED_PHASE_0_PATH_IDS = [ "memory-core-doctor-dreaming-state-import", "memory-core-doctor-qmd-retirement", "memory-core-doctor-vector-index-diagnostic", + "doctor-transcript-memory-repair", "gateway-memory-search", "memory-import", "session-backfill-transcript-read", @@ -80,6 +81,7 @@ const REQUIRED_PHASE_0_PATH_IDS = [ "profile-and-short-term-promotion", "short-term-promotion-recall-recording", "short-term-promotion-operator-repair", + "memory-rem-harness-preview", "child-agent-delegation", "child-agent-completion-handoff", "cron-triggered-run", @@ -135,6 +137,7 @@ const MEMORY_MIGRATION_IMPORT_ROUTE_SURFACES = [ "src/wizard/setup.migration-import.ts", "src/wizard/setup.migration-finalize.ts", "src/wizard/setup.post-install-migration.ts", + "src/wizard/setup.memory-import.ts", "src/plugin-sdk/migration-runtime.ts", ] as const; @@ -149,9 +152,18 @@ const MEMORY_MIGRATION_IMPORT_ROOTS = [ "src/wizard/setup.migration-import.ts", "src/wizard/setup.migration-finalize.ts", "src/wizard/setup.post-install-migration.ts", + "src/wizard/setup.memory-import.ts", "src/plugin-sdk/migration-runtime.ts", ] as const; +const MEMORY_CORE_DOCTOR_STATE_MIGRATION_REGISTRATION_SURFACES = [ + "extensions/memory-core/doctor-contract-api.ts", + "src/plugins/doctor-contract-registry.ts", + "src/infra/state-migrations.doctor.ts", + "src/commands/doctor-config-preflight.ts", + "src/flows/doctor-health-contributions.ts", +] as const; + const MEMORY_CORE_DOCTOR_STATE_MIGRATION_SURFACES = [ "extensions/memory-core/doctor-contract-api.ts", "extensions/memory-core/src/migration/doctor-memory-sidecar.ts", @@ -302,6 +314,10 @@ function listMemoryMigrationIngressMarkers(file: string, sourceText: string): st const defaultCommandBindings = listImportedCallBindings(source, "migrateDefaultCommand"); const applyCommandBindings = listImportedCallBindings(source, "migrateApplyCommand"); const applyBindings = listImportedCallBindings(source, "runMigrationApply"); + const providerMemoryImportBindings = listImportedCallBindings( + source, + "applyProviderMemoryImport", + ); const markers: string[] = []; const visit = (node: ts.Node) => { if ( @@ -325,6 +341,9 @@ function listMemoryMigrationIngressMarkers(file: string, sourceText: string): st // caller is an ingress route until an owning Phase records its authorization boundary. markers.push("migration-plan-apply"); } + if (isNamedCall(node.expression, providerMemoryImportBindings)) { + markers.push("provider-memory-import-apply"); + } if (isMigrationProviderApplyCall(node.expression)) { markers.push("migration-provider-apply"); } @@ -431,7 +450,9 @@ describe("memory authorization path inventory", () => { direction: "control", owner: "operator-memory-host", disposition: "blocked-in-enforced-mode", - surfaces: ["extensions/memory-core/doctor-contract-api.ts"], + surfaces: expect.arrayContaining([ + ...MEMORY_CORE_DOCTOR_STATE_MIGRATION_REGISTRATION_SURFACES, + ]), }); for (const [id, surface] of [ [ @@ -461,6 +482,7 @@ describe("memory authorization path inventory", () => { surfaces: expect.arrayContaining([ "extensions/memory-core/src/short-term-promotion-apply.ts", "extensions/memory-core/src/short-term-promotion-memory-write.ts", + "extensions/memory-core/src/cli-index-search.runtime.ts", ]), }); expect([...inventoriedSurfaces]).toEqual( @@ -487,9 +509,20 @@ describe("memory authorization path inventory", () => { disposition: "blocked-in-enforced-mode", surfaces: ["extensions/memory-core/src/migration/doctor-vector-index-provider.ts"], }); + expect(entriesById.get("doctor-transcript-memory-repair")).toMatchObject({ + direction: "control", + owner: "operator-memory-host", + disposition: "blocked-in-enforced-mode", + surfaces: expect.arrayContaining([ + "src/flows/doctor-health-contribution-runners.state.ts", + "src/commands/doctor-session-transcripts.ts", + "src/commands/doctor-session-transcript-headers.ts", + "src/commands/doctor-session-transcript-labels.ts", + ]), + }); }); - it("keeps import, recall recording, promotion, and operator repair as separate paths", () => { + it("keeps import, preview, recall recording, promotion, and operator repair as separate paths", () => { const entriesById = new Map(inventory.map((item) => [item.id, item])); expect(entriesById.get("memory-migration-import")).toMatchObject({ @@ -501,6 +534,7 @@ describe("memory authorization path inventory", () => { "src/wizard/setup.migration-import.ts", "src/wizard/setup.migration-finalize.ts", "src/wizard/setup.post-install-migration.ts", + "src/wizard/setup.memory-import.ts", "src/plugin-sdk/migration-runtime.ts", ]), }); @@ -511,6 +545,9 @@ describe("memory authorization path inventory", () => { surfaces: expect.arrayContaining([ "extensions/memory-core/src/tools.ts", "extensions/memory-core/src/cli-index-search.runtime.ts", + "extensions/memory-core/src/cli-rem.runtime.ts", + "extensions/memory-core/src/dreaming-phases.ts", + "extensions/memory-core/src/session-backfill.ts", "extensions/memory-core/src/short-term-promotion-record.ts", "extensions/memory-core/src/short-term-promotion-store.ts", ]), @@ -524,6 +561,22 @@ describe("memory authorization path inventory", () => { "src/commands/doctor-memory-search.ts", "src/gateway/server-methods/doctor.ts", "src/gateway/server-methods/doctor.memory-core-runtime.ts", + "src/plugin-sdk/memory-core-bundled-runtime.ts", + "extensions/memory-core/src/short-term-promotion-artifacts.ts", + ]), + }); + expect(entriesById.get("memory-rem-harness-preview")).toMatchObject({ + direction: "egress", + owner: "operator-memory-host", + disposition: "blocked-in-enforced-mode", + surfaces: expect.arrayContaining([ + "extensions/memory-core/src/cli.ts", + "extensions/memory-core/src/cli.runtime.ts", + "extensions/memory-core/src/cli-rem.runtime.ts", + "extensions/memory-core/src/rem-harness.ts", + "src/gateway/server-methods/doctor.ts", + "src/gateway/server-methods/doctor.memory-core-runtime.ts", + "src/plugin-sdk/memory-core-bundled-runtime.ts", ]), }); }); @@ -673,6 +726,21 @@ describe("memory authorization path inventory", () => { ).toEqual(["migration-plan-apply"]); }); + it("finds hosted provider memory import calls", () => { + expect( + listMemoryMigrationIngressMarkers( + "fixture.ts", + ` + import { applyProviderMemoryImport as applyMemory } from "./memory-import.js"; + async function migrate() { + await applyMemory({}); + await unrelated({}); + } + `, + ), + ).toEqual(["provider-memory-import-apply"]); + }); + it("recognizes the generic CLI migration apply ingress", () => { const command = "src/cli/program/register.migrate.ts"; const source = fs.readFileSync(path.join(REPO_ROOT, command), "utf8"); @@ -685,6 +753,15 @@ describe("memory authorization path inventory", () => { ); }); + it("recognizes the hosted wizard memory import ingress", () => { + const command = "src/wizard/setup.memory-import.ts"; + const source = fs.readFileSync(path.join(REPO_ROOT, command), "utf8"); + + expect(listMemoryMigrationIngressMarkers(command, source)).toEqual( + expect.arrayContaining(["provider-memory-import-apply"]), + ); + }); + it("does not treat test-only source helpers as production manager paths", () => { expect( isProductionTypeScript("extensions/memory-core/src/memory/test-manager-helpers.ts"), @@ -747,16 +824,19 @@ describe("memory authorization path inventory", () => { pathspecs: ["extensions/memory-core/src"], }); if (!tracked) { - throw new Error("could not list tracked files for the session transcript ingestion inventory"); + throw new Error( + "could not list tracked files for the session transcript ingestion inventory", + ); } const inventoried = new Set(inventory.flatMap((item) => item.surfaces)); const missing = tracked .filter(isProductionTypeScript) - .filter((file) => - listSessionTranscriptIngestionCalls( - file, - fs.readFileSync(path.join(REPO_ROOT, file), "utf8"), - ).length > 0, + .filter( + (file) => + listSessionTranscriptIngestionCalls( + file, + fs.readFileSync(path.join(REPO_ROOT, file), "utf8"), + ).length > 0, ) .filter((file) => !inventoried.has(file)); diff --git a/src/plugins/memory-authorization-path-inventory.ts b/src/plugins/memory-authorization-path-inventory.ts index da271ecaec9e..c04c89381978 100644 --- a/src/plugins/memory-authorization-path-inventory.ts +++ b/src/plugins/memory-authorization-path-inventory.ts @@ -326,6 +326,10 @@ export const MEMORY_AUTHORIZATION_PATH_INVENTORY = Object.freeze([ "operator-memory-host", "blocked-in-enforced-mode", "extensions/memory-core/doctor-contract-api.ts", + "src/plugins/doctor-contract-registry.ts", + "src/infra/state-migrations.doctor.ts", + "src/commands/doctor-config-preflight.ts", + "src/flows/doctor-health-contributions.ts", ), entry( "memory-core-doctor-sidecar-state-import", @@ -362,6 +366,17 @@ export const MEMORY_AUTHORIZATION_PATH_INVENTORY = Object.freeze([ "blocked-in-enforced-mode", "extensions/memory-core/src/migration/doctor-vector-index-provider.ts", ), + entry( + "doctor-transcript-memory-repair", + "control", + "operator-memory-host", + "blocked-in-enforced-mode", + "src/flows/doctor-health-contributions.ts", + "src/flows/doctor-health-contribution-runners.state.ts", + "src/commands/doctor-session-transcripts.ts", + "src/commands/doctor-session-transcript-headers.ts", + "src/commands/doctor-session-transcript-labels.ts", + ), entry( "gateway-memory-search", "egress", @@ -469,6 +484,7 @@ export const MEMORY_AUTHORIZATION_PATH_INVENTORY = Object.freeze([ "src/wizard/setup.migration-import.ts", "src/wizard/setup.migration-finalize.ts", "src/wizard/setup.post-install-migration.ts", + "src/wizard/setup.memory-import.ts", "src/plugin-sdk/migration-runtime.ts", ), entry( @@ -621,6 +637,7 @@ export const MEMORY_AUTHORIZATION_PATH_INVENTORY = Object.freeze([ "extensions/memory-core/src/short-term-promotion-memory-write.ts", "extensions/memory-core/src/short-term-promotion-rehydrate.ts", "extensions/memory-core/src/short-term-promotion-store.ts", + "extensions/memory-core/src/cli-index-search.runtime.ts", ), entry( "short-term-promotion-recall-recording", @@ -629,6 +646,9 @@ export const MEMORY_AUTHORIZATION_PATH_INVENTORY = Object.freeze([ "blocked-in-enforced-mode", "extensions/memory-core/src/tools.ts", "extensions/memory-core/src/cli-index-search.runtime.ts", + "extensions/memory-core/src/cli-rem.runtime.ts", + "extensions/memory-core/src/dreaming-phases.ts", + "extensions/memory-core/src/session-backfill.ts", "extensions/memory-core/src/short-term-promotion-record.ts", "extensions/memory-core/src/short-term-promotion-store.ts", ), @@ -641,6 +661,21 @@ export const MEMORY_AUTHORIZATION_PATH_INVENTORY = Object.freeze([ "src/commands/doctor-memory-search.ts", "src/gateway/server-methods/doctor.ts", "src/gateway/server-methods/doctor.memory-core-runtime.ts", + "src/plugin-sdk/memory-core-bundled-runtime.ts", + "extensions/memory-core/src/short-term-promotion-artifacts.ts", + ), + entry( + "memory-rem-harness-preview", + "egress", + "operator-memory-host", + "blocked-in-enforced-mode", + "extensions/memory-core/src/cli.ts", + "extensions/memory-core/src/cli.runtime.ts", + "extensions/memory-core/src/cli-rem.runtime.ts", + "extensions/memory-core/src/rem-harness.ts", + "src/gateway/server-methods/doctor.ts", + "src/gateway/server-methods/doctor.memory-core-runtime.ts", + "src/plugin-sdk/memory-core-bundled-runtime.ts", ), entry( "child-agent-delegation",