ContextLattice v4.0.10
ContextLattice v4.0.10: Compositional Recall. Continuous Cognition.
v4.0.10 makes recalled context substantially more useful to the requesting agent. A single bounded response can now identify the job, select the right response modules, carry the minimum sufficient proof, preserve temporal and negative evidence, and prepare an evidence-bound next action without acquiring authority to execute it.
The CLI remains the primary interface. HTTP, MCP, and the dashboard remain companion surfaces.
What Changed
- The recall router derives task, object, temporal, provenance, and consequence facets from server-owned evidence and conservative request signals. Caller-supplied labels can only increase caution.
- Ten response modules cover exact status, continuation, decisions, preferences and constraints, timelines, procedures, multi-memory synthesis, conflicts and supersession, bounded negative recall, and memory-to-action preparation.
- One shared proof spine binds the temporal premise, snapshot, receipt, selected evidence, protected conflicts and gaps, component witnesses, and response identity. The emitted proof set remains capped at eight opaque references.
- Historical responses use a fixed semantic
as_of; future evidence is excluded, source revision changes degrade the response, and supersession or selective forgetting cannot silently rewrite an earlier premise. - Negative recall distinguishes
not_found,unknown, anddid_not_happen. A complete negative claim requires a digest-bound coverage receipt over the authorized source universe. - Memory-to-action projects opaque tool, parameter, step, refusal, recovery, and rollback evidence. Proof closure is mandatory, values remain hidden, and
can_actandexecution_performedremain false. - Compact-budget handling removes lowest-ranked optional context before proof-bound modules or direct support. Candidate validation failure still returns the current v1 control projection from the same retrieval artifacts.
- Every component has an independent deterministic bucket, arm, binding, outcome-eligibility decision, canary policy, and rollback receipt. Public defaults remain zero; entitled mutation remains owner/admin authorized and fenced.
- Continuous Cognition now has an explicit silence decision, portable response/proof identity, bounded objective replay, atomic proof-source revisions, bounded Utility selection, reduced snapshot lock hold time, and one owned search-impact projection path.
- The dedicated recall CLI, legacy aliases, native route inventory, generated contracts, Context Passport, and portable continuation surfaces preserve the same bounded response identity.
- Context Passport and portable-continuation rollback anchors are durable, monotonic, bounded, and fail closed on malformed, truncated, reordered, or older restored state.
Evidence Boundary
The frozen synthetic compositional evaluation contains 300 cases: 200 development and 100 holdout-classified cases across ten response archetypes. It records 1,200 four-condition runs and 841 product-selected component ablations from the Go response seam. On the holdout split, the compositional response resolved 80 of 100 first responses versus 72 for the best flat control, completed 75 downstream tasks versus 72, reduced median next-correct-action turns from 2 to 1, and tied the frozen tool and parameter ceiling at 5 of 10. The detailed ledger retains all 161 reported failures; no failure is hidden.
These results are local synthetic regression evidence. Holdout custody is explicitly local_regression/contaminated, so promotional claims are disabled. Provider-free transfer receipts for the primary model and gpt-5.6-luna through native and script harnesses were not furnished; the transfer verifier therefore records FAILED, invokes no provider, and grants no transfer credit.
The shipped policy is consequently control-only: all ten component canary allocations remain zero. This is a deliberate fail-closed release state, not an omitted result. The v1 control response, component rollback, and no-second-retrieval behavior remain covered by deterministic tests.
Verification
Authoritative local verification covers frozen fixture reproduction, focused and full Go tests, race correctness with wall-clock performance gates measured separately outside race instrumentation, Go vet, generated contract and commercial-truth checks, static boundary and native-ownership tests, private/public/paid lane guards, public leak scans, compositional artifact reproduction, custody and transfer fail-closed checks, bounded fuzz windows, installer lifecycle tests, exact-tree release audits, and rebuilt OrbStack runtime proof.
Hosted GitHub checks are secondary status only and are not release authority.
Upgrade and Rollback
Upgrade the gateway and global agent tools together so registry version, route ownership, response validation, and CLI projections remain aligned. Rebuild and restart only the inventoried gateway-go service from the v4.0.10 source, then verify /health, context boundaries, native ownership, one scoped response, explicit silence, candidate fallback, and installed CLI parity.
No owner memory, Utility, session, task, Passport, or continuation record should be discarded during upgrade. Existing unanchored valid Passport and continuation state migrates forward before anchoring. Rollback remains tag-pinned: restore the prior gateway and tools, preserve state in place, keep all component allocations at zero, and use the v1 response projection while any candidate or provenance gate is unavailable.
Artifact signature note
The macOS technical-preview DMG is not code-signed or notarized because no release signing identity was configured for this build. SHA-256 verification remains authoritative for these artifacts.