feat(pncc): close memory failures safely

GuangHu-Human-Responsibility: ICE-GL∞ / 冰朔
GuangHu-Persona-Cognitive-Author: ICE-P-ZY001 / 铸渊
GuangHu-Execution-Runtime: Codex macOS / DEV-20260810-014
GuangHu-Development-ID: DEV-20260810-014
GuangHu-Authorization-Scope: GH-PNCC local runtime development and registered REPO-014 publication
GuangHu-Source-Language-Anchor: continue PNCC persona runtime; UI and human projection aesthetics remain deferred
This commit is contained in:
铸渊 / ICE-P-ZY001 2026-08-11 02:38:28 +08:00
commit 18944f5362
9 changed files with 270 additions and 22 deletions

View file

@ -43,6 +43,11 @@ schemas, derived permissions, inference/reality-action boundaries, and the actua
sense and verified-checkpoint memory metabolism organs can wake. Memory metabolism runs no model inference
and promotes only the current structured checkpoint of a distinct same-persona, same-repository, dormant
session after verifying its event chain; the new checkpoint binds both source checkpoint and event hashes.
The registered Tauri memory command executes the Git/filesystem transaction on the blocking task pool. A
rejected candidate closes through a checked failure transaction that records the failure, organ release and
dormancy before releasing the exact lease. If event persistence, session persistence, or lease release fails,
the command returns an explicit recovery-required error and retains the lease whenever closure cannot be
proven complete; it does not swallow the secondary failure.
The execution limb remains visible but non-activatable, so declaring it does not grant a shell or reality action.
`query_persona_code_channel_runtime` is the bounded read model for later projection surfaces. The caller must