Skip to content

MEM-02: Reviewed dedup merge/apply with revision checks, receipts, provenance and recovery #1804

Description

@devin-ai-integration

Backend-first slice; the UI hookup is a thin final PR. Split: (a) core/gateway apply service + tests, (b) API route + auth/hosted-mode rules, (c) UI apply flow.

Scope

  • Core service: apply a reviewed set of merge decisions ({ keepId, mergeIds[], expectedRevisions{} }) atomically per group; refuse when any entry's current revision/version differs from the reviewed one (stale-result principle from Guard async LLM results with source revisions to prevent stale writes #1673); write provenance (what merged into what, by whom, when, from which review) and a receipt with an operation id; idempotent re-submission by operation id.
  • Restore path: merged entries remain recoverable through versioning (ties into MEM-03).
  • Gateway: POST /api/v1/projects/:id/dedup/apply (new, explicit; the dry-run route stays dry-run) with body validation, refusal in hosted mode where writes are disallowed, and the same management-boundary rules as other mutations.
  • Tests: adversarial-order setup (entry edited between preview and apply; concurrent applies; partial failure mid-group), receipts, provenance, sync/export effects (.lore.md regeneration).

Definition of done: reviewed decisions can be applied safely and audited; stale reviews are rejected with a clear error; recovery works.

Depends on: #1803
Size: L
Priority: P2
Epic: #1824


Working rules for this slice

  • One PR per slice (split further if the diff stops being reviewable). Branch from main; conventional-commit title.
  • Follow AGENTS.md and quality/REVIEW.md (adversarial correctness review, regression tests, two-reviewer discipline). pnpm run typecheck, pnpm run lint, pnpm run format:check, pnpm test, pnpm run build must pass.
  • Do not touch proxy/pipeline behaviour, CHANGELOG.md, or package versions.
  • packages/core must never depend on ACP, Git process control, browser state or UI types. The browser bundle must never import gateway boot code, credentials or database modules.
  • Existing /api/v1 routes keep their response shapes; new options/routes are opt-in and backward compatible.
  • Record decisions, dependency versions and test commands in packages/ui/README.md (or the relevant package README) instead of a separate design doc.

Plan reference: Lore UI and agent-workspace action plan v2.3 (18 Sep 2026; kept out of the repo, held by @BYK). Baseline commit for the plan: a4e6af5b.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions