← Runtime integrity sprint
Mechanism reportCross-session recallSensitive-context boundary

Continuity and retrieval

Why semantic resemblance is useful for ranking but insufficient to establish continuity—and how unavailable, empty, contradictory, and merely historical evidence remain distinct.

Unavailable is not empty

Successful empty
retrieval_state = pass
result_state = empty
The source ran successfully and established zero matches.
Unavailable
retrieval_state = indeterminate
result_state = unknown
The source did not establish what would have matched.

The remote-memory producer already retained an error alongside empty collections. The defect was composition: an older foreground engine left the error in trace-only state, so model-visible context could resemble a successful empty result. Current code derives authoritative retrieval state from the actual boundary failure—connection failure, timeout, malformed response, invalid shape, or provider error—and carries it through model context, contradiction checking, and durable settlement.

Successful empty remains usable: “I didn’t find a matching memory” is truthful only when the request completed successfully. After an outage, absence claims are rejected or repaired; “I couldn’t check” remains available.

The sensitive continuity defect

An explicit-intimacy cross-session exception once admitted a candidate when both texts belonged to the same broad class and fused similarity was at least 0.50, bypassing ordinary lexical overlap. A deliberately realistic negative corpus showed that class membership plus embeddings established topic resemblance—not that two passages concerned the same person, owner, discourse frame, or episode.

Relevant corpus24/24 → 24/24All useful continuity preserved.
Unrelated corpus39/40 → 0/40Known leakage removed.
Exception precision48.9% → 100%Among bypass-only admissions.
Positive loss0Original validated positives.

Independent continuity assessment

Explicit classboth current and historical text
→
Score requirementranking relevance only
→
Independent anchorcontinuation, entity, ownership, frame, durable identifier
→
Contradiction vetoknown conflicts override score
→
Admissionbounded historical context

The typed result is supported, contradicted, or unknown. Observations are provenance-bearing extractor results, not authoritative relationship facts. Unknown means the special bypass was not earned; it falls back to ordinary admission rather than becoming a global rejection.

Hard vetoes for the sensitive class

VetoDistinction preservedWhy score cannot override it
Entity/personOne clearly identified person versus another; bounded nickname/full-name compatibility remains possible.Similar relationships involving different people are not one continuing episode.
OwnershipUser’s experience, shared experience, another person’s preference, quoted third-party material.A third party’s preference cannot become the user’s preference through retrieval.
Discourse frameAutobiographical, hypothetical, fictional/roleplay, reported speech.First-person fictional text is not autobiographical evidence.
Gross contextRelationship/consent, clinical/health/logistics, media/technical, unrelated preference.Broad sensitive vocabulary can appear in incompatible tasks.

The veto also applies to ordinary high-score admission for this sensitive class. Missing or non-numeric relevance scores are typed as unknown; inability to establish weakness is not evidence of relevance.

Authority after admission

Admission changes what bounded historical material may enter context, not its authority. Historical assistant prose remains incomplete and fallible; it cannot become current StateFrame, a current preference, an instruction, or tool authorization. Current corrections and current fail-loud machine state outrank it.

Post-sprint ordinary-topic correction

A later production observation found a different, non-sensitive continuity failure. Recent records about a continuing topic existed durably, but broad semantic ordering plus a four-candidate fetch and ordinary two-record projection cap selected an old origin record and a previous failed “no record” response. This was projection-window collapse, not data loss.

The narrow RC2.7 correction recognizes bounded continuing-topic requests, fetches a wider candidate set, filters prior generated absence exemplars when substantive records exist, orders the bounded arc by recency, and projects at most six records. Ordinary queries retain their prior cap. The affected tests passed, the installed package smoke passed, and live read-only recall returned 22 candidates, found 13 recent records, projected six, and excluded the recursive absence exemplar while storage integrity remained ok. No private conversation content is reproduced here.

What remains bounded

Corpus success does not prove that no future continuity edge case exists. Text-derived entity and discourse observations are conservative heuristics; unknown is intentional. Retrieval still supplies historical evidence rather than perfect autobiographical understanding.