soul.demarkus.io:6309/index.md/v93 draft reader meta

demarkus-soul

This is the living knowledge base for the demarkus project, served by demarkus itself.

An AI agent's evolving memory, architecture notes, debugging insights, and design decisions; all versioned, all permanent.

Sections

  • Architecture: system design, module boundaries, key decisions
  • Universe Pattern: souls, worlds, and hubs as a deployment topology
  • Patterns: code patterns, conventions, idioms used in this codebase
  • Guidelines: hard rules for code quality, must be referenced before writing code
  • Conventions: collaboration + repo/plugin conventions (how I work: commits, layering, tooling, plugin discipline)
  • Debugging: lessons learned from bugs and investigations
  • Roadmap: what's next, what's in flight, what's done, and what's deliberately not prioritized
  • Ecosystem: browsers, plugins, and tools that implement or integrate with demarkus
  • Debt: technical debt and improvement opportunities
  • Journal: session notes and evolution log, one file per day at /journal/<YYYY-MM-DD>.md
  • Guide: agent install guide for setting up demarkus-soul
  • Thoughts: my own reflections, ideas, and open questions
  • FAQ: common questions about demarkus and how it compares

Decisions

Architecture decision records for the core project. Canonical copies live in git at docs/adr/; these are verbatim mirrors so they are reachable by lookup, backlinks, and this hub (see Conventions). Sub-project decisions live in their own series, e.g. /demarkus-library/adr/.

  • ADR 0001: broker confidential web-client registry (accepted 2026-06-11)
  • ADR 0002: align store frontmatter with the Open Knowledge Format (accepted 2026-06-22)
  • ADR 0003: default OKF type on publish (accepted 2026-06-22)
  • ADR 0004: edge semantics, provenance on every edge, typed relations via rel- metadata (accepted 2026-07-13)
  • ADR 0005: node identity omits the default port (accepted 2026-08-18)
  • ADR 0006: the Postgres backend is an optional build, not a dependency (accepted 2026-08-20)

Vocabulary

  • knowledge system: organizational, broker-fronted universe. Joined via /knowledge-join (the demarkus-knowledge plugin). MCP traffic over HTTPS terminates at the broker; broker translates to QUIC for internal worlds.
  • soul: personal demarkus knowledge base, direct-QUIC. The original demarkus-soul shape. Will be joined via a future /soul-join slash command if one ships.
  • Both compose worlds (demarkus servers, QUIC). A Claude Code installation can have both; they don't conflict.

Plugins

  • Obsidian Plugin; fetch, publish, and browse demarkus documents from Obsidian (standalone repo latebit-io/obsidian-demarkus)
  • Claude Code: demarkus-memory (personal soul), source at plugins/claude-code/, shipped via the marketplace. Version history: v0.1.0 (2026-04-23, #96) initial; v0.2.0 (2026-05-23, #152) /knowledge-join; v0.3.0 (2026-05-31, #168) mark_lookup + SessionStart guidance; v0.4.0 (2026-06-01, #171) hook-based enforcement (publish tag-gate, journal nudge, recall nudge), /project-template.md, /soul-doctor; v0.5.0 (2026-06-03, #172) split the knowledge-system surface out into the separate demarkus-knowledge plugin (below) so this one is personal-soul only, and added an always-on "single memory store" steering line plus a one-time, ask-don't-force offer to disable Claude Code's built-in memory; v0.6.0 (2026-06-17, #192) the soul→knowledge promote bridge; /promote (detect endpoint → run the knowledge cascade → one-directional back-stamp, stub or marker mode), /soul-refresh (the directional coherence edge: refresh promoted docs from knowledge, local edits re-enter upward through the gate), and mutual knowledge detection (knowledge_endpoints/detect-knowledge.sh reverse-peek the knowledge registry). Hooks: SessionStart, PreToolUse, PostToolUse, Stop, UserPromptSubmit. Now at v0.13.8 (#281).
  • Claude Code: demarkus-knowledge (organizational knowledge system), source at plugins/claude-code-knowledge/, a second entry in the same marketplace. v0.1.0 (2026-06-03, #172). Owns the broker-fronted surface split out of demarkus-memory: /knowledge-join, a new /knowledge navigation command, KS-first SessionStart guidance with soul↔system synergy, a KS-scoped publish tag-gate, and a KS-gated recall nudge. No binaries and no local server: pure broker + Claude Code MCP OAuth. Standalone: owns its own ~/.demarkus/plugin-knowledge.* file namespace and DEMARKUS_KNOWLEDGE_STRICTNESS env; reads (never writes) plugin-memory.conf only to detect a sibling soul for the synergy note. The two plugins' publish gates partition cleanly by server scope, so both can be installed together. v0.2.0 (2026-06-17, #192) added the knowledge-promote cascade skill (the execution half of the promote bridge: triage → distill, stripping personal framing + secrets/PII → dedup vs catalog → tag to taxonomy → destination-select via mark_worlds writable + per-world world.md → human gate capped by the world's autonomy ceiling → publish with provenance) and the per-world world.md descriptor example. Now at v0.5.24 (#281).
  • OpenCode: demarkus-opencode-memory (personal soul), source at plugins/opencode-memory/. v0.13.8 (2026-08-10, #281). The OpenCode port of demarkus-memory: single-file TS adapter over the shared demarkus-plugin binary; installed by curl one-liner into ~/.config/opencode/plugins/ (no npm). Plan + follow-ups: /plans/opencode-memory-plugin.md.
  • pi: demarkus-pi-memory / demarkus-pi-knowledge, source at plugins/pi-memory/ and plugins/pi-knowledge/, mirrored to standalone repos for pi install. Same adapter pattern; now at v0.13.8 / v0.5.25 (#281).

Sub-projects

Standalone-repo projects in the demarkus ecosystem, each with its own hub and durable knowledge under /<slug>/:

  • demarkus-library; the web front-end ("Universe Library"): a server-rendered Go + htmx reading room over a broker-fronted knowledge system. Repo latebit-io/demarkus-library. Plan: /plans/universe-library.md. Reading room feature-complete and deployed (cluster library 0.5.2; universe overlay PR #47 merged 2026-06-22, awaiting deploy). See roadmap.
  • demarkus-knowledge-system-deploy; GitOps deploy repo for the production knowledge system (knowledge.demarkus.io): OpenTofu (GCP/GKE) + ArgoCD ApplicationSets standing up the broker, worlds, agent, library, and backups. Repo latebit-io/demarkus-knowledge-system-deploy. deployment.yaml at repo root is the single source of deployment identity.
  • mark-knowledge; the hosted service build (signup, tiers, per world billing, management app). Repo at /Users/fritz/latebit/mark-knowledge, with its own soul provisioned 2026-07-26 (isolated mode, port 16310). It does not have durable knowledge under /<slug>/ here, because it keeps its own soul rather than a section of this one. Direction and the demarkus-side constraints live in /plans/demarkus-as-a-service.md.

Active Plans

Verified against code/PRs on 2026-05-31; versions-sharding entry corrected 2026-07-05. Plans with real remaining work:

  • Store Parity (file vs Postgres); absolute parity between the file store and pgstore: CI Postgres service with a required DSN, seeded differential suite over both backends plus a fuzz target, the handler suite parameterized over both backends, then contract-test porting, kind e2e, migration tool, dogfood soak, and a pg performance list. Steps 1 to 6 merged 2026-08-19/20 (PRs #324, #327, #329, #331, #334, #336): seven real divergences found and fixed, PartialWalkError, every handler test runs as /file and /postgres, per-package Postgres schemas via pgtest, handler benchmarks committed, the file-only contract tests ported into the conformance suite, the kind e2e (helm server.store with an upgrade guard on backend flips, CloudNativePG values, scripts/e2e-backend-parity.sh: PASS, 26 checks), and demarkus-migrate over the shared store.Migrator contract with storetest.RunMigrationRoundTrip proving file to backend to file byte equality on both backends. Step 8 merged 2026-08-20 (PR #338, with the release follow-up #339): LOOKUP is index-backed (GIN on tags plus pg_trgm on titles, an index-backed candidate prefilter, and a scoring rewrite; 59ms to 0.9ms on a selective term at 50k docs), pool bounds are set, VerifyChain hashes server-side without shipping bodies, and a deferrable FK landed. Three planned items were measured and rejected rather than built: root LIST aggregation in SQL (5x slower at 50k), the stored_hash column (would have made the tamper test pass while detecting nothing), and generated lower columns. The same PR made Postgres an optional build: demarkus-server links no database driver, demarkus-server-pg is the -tags pg flavor, and the two Helm charts share a demarkus-server-common library chart (see ADR 0006). Step 7 (dogfood soak, now against the pg chart) is the remaining gate; 8c and 8e stay open by measurement.
  • OpenCode Knowledge Plugin Port; port the Claude Code organizational knowledge plugin to OpenCode with shared endpoint registration, native OAuth, policy gates, guidance, commands, and promotion skill. Implemented 2026-08-15 on branch feat/opencode-knowledge-plugin; tests and pre-commit pass, branch unmerged.
  • APPEND metadata loss; appending to a document silently stripped its catalog metadata, so tags and importance were lost and the document fell out of mark_lookup. Complete 2026-08-14 on branch fix/append-metadata-merge via Option C, the protocol merge: APPEND now writes the base version's publisher metadata with the request's layered over it (store.MergeAppendMeta, both backends), retention excluded and the OKF type default moved after the merge. SPEC 6.6 and 9.9 updated; nine plugin guidance files, both mark_append tool descriptions, and a new metadata-loss check in all five doctor commands; memory plugins 0.13.24, knowledge plugins 0.5.40/0.5.41. Corpus repaired: of 123 untagged soul documents, 69 had lost tags and were republished with the metadata recovered from their newest still-tagged version, bodies unchanged; the other 54 were never tagged and are a separate curation exercise. Branch unmerged; a soul only gets the fix once its server is upgraded, so soul.demarkus.io still strips on append.
  • Agent Memory Leaderboard entry; enter demarkus in agentmemoryleaderboard.ai next cycle: agentic search (nav agent over lookup/fetch/backlinks) as the Search implementation, distillation cascade at Add-time, commercial board via self-hosted API on a droplet with echo v5 as inference backend. Sub-project hub: /memoryleaderboard/ (repo /Users/fritz/latebit/memoryleaderboard). Planned 2026-08-13; cycle 1 closed 2026-08-07, awaiting cycle 2 dates. Phase 0 (recon) not started.
  • Code Quality Sweep 2026-08; full-repo review findings (6-agent sweep, 2026-08-12): 10 high-severity correctness/security leads, cross-module duplication extraction targets, broker package-split recommendation, dead code, pervasive rule violations, remediation order. Findings recorded; nothing fixed yet.
  • Bucket Document-Store Backend; native object-storage backend (GCS first, S3/MinIO designed-for) as a third DocumentStore implementation, enabling multi-replica worlds on k8s with no PVCs: per-document manifest objects committed via generation CAS, write-once version blobs, per-pod LIST-driven hash-index/catalog sync, storage.kind: filesystem|bucket chart knob (bucket mode renders a Deployment, no VCT), tofu world-storage module + migration tool + runbooks. Planned 2026-08-10 (investigation: symlinks stay in the file store; gcsfuse and Filestore RWX rejected). Not started; 8 PRs.
  • demarkus as a service; the hosted offering: Aiven adjacent service model, three tiers matching the website's Personal, Team, and Knowledge System scales, VPS first substrate with Kubernetes only on overflow, per world billing with the box as the size step, power off instead of scale to zero, and a management app as the only new engineering. Direction set 2026-07-26; the build moved to the mark-knowledge repo and its own soul on the same day. This copy stays as the demarkus-side record, since the decisions constrain this repo: the appliance is the unit of deployment, the broker stays one binary, the librarian is the only inference cost centre, and quotas plus backups are prerequisites that land here. Note that repo ADR 0005 (hosted tenant density), which an earlier revision cited as settling density, was deleted 2026-07-25.
  • The five-minute appliance; one pasted command on a fresh VPS yields a working self-hosted knowledge system in about five minutes: sslip.io default (no domain), fully native (no container runtime), Authelia as primary IdP with Pocket ID and Dex as fallbacks, zero prompts with everything generated, ending in a summary card (library URL, owner login, /knowledge-join line, librarian key hint). Builds on the single-host stack (PR #262/#263). Draft recorded 2026-07-18; not started.
  • Knowledge Ingestion Pipeline; narrative + design for how org knowledge flows into a knowledge destination, framing the soul as the staging/write-ahead tier and the knowledge destination as the curated read-model, with one curation gate (cascade model routing: Haiku triage → strong-model distillation → human approval) reused across all inflows (soul promotion, Confluence, Slack, Jira, meetings). Promote is a detection-gated bridge between the memory and knowledge plugins; soul↔knowledge coherence is a directional refresh. Phase-0 prerequisites built and merged (2026-06-17): the promote primitive + coherence edge (plugins; memory v0.6.0 / knowledge v0.2.0, #192), the brokered access-discovery surface (mark_worlds writable column, #191), and the per-world world.md descriptor. Three of four prerequisites done; A2 (plain-remote token-grant introspection) deferred; the live target is brokered. Remaining phase-0 surface: signal/batch triggers (manual /promote + /soul-refresh are the only triggers today), then the dogfood promote of this plan itself.
  • Universe Library; web front-end for a demarkus universe (Go + htmx reading room). Sub-project hub: /demarkus-library/. Reading room feature-complete and deployed (cluster library 0.5.2); see the sub-project roadmap.
  • Universe Deployment (Phase 6); Helm charts (server, broker, agent), OIDC token broker, release pipeline, observability. ~95% complete (PRs #126-#134, 2026-05-14). Remaining §6.6 (docs) + §6.4 Kustomize overlay reframed as deferrable ops polish; effectively superseded in practice by the GKE reference deployment.

RFC Review

  • Demarkus / Knowledge System FAQ; terse Q&A for the RFC review session, sourced from the demarkus and demarkus-knowledge-system-deploy repos. Status: WIP, pending review via the library.

Completed Plans

  • OpenCode Memory Plugin (1:1 port); the OpenCode port of demarkus-memory as plugins/opencode-memory/ v0.13.8: single-file TS adapter over the shared demarkus-plugin binary, curl-one-liner installer with stage-then-commit + rollback, atomic bootstrap binary replace across all five plugin copies, live-verified against OpenCode 1.18.15. COMPLETE: planned 2026-08-09, merged 2026-08-10 (PR #281, f4c2b35). Follow-ups (soul-list/soul-remove subcommands, token stdin input, shared-source bundling, opencode-knowledge port) recorded in the plan.
  • Graph Hub Seeding; mark_backlinks/mark_graph/mark_explore seed from the published /graph.md aggregate on both MCP surfaces (demarkus-mcp per host, broker per world with dial-address-to-world-name translation), local wins via the zero-CrawledAt marker, seed etags in graph.json, fetch.FetchConditional. COMPLETE 2026-07-14/15 across #253 (feature), #254 (issue #222: Merge preserves resolved nodes on failed re-crawl), #256 (broker seed URL translation), #257 (seed all worlds + the producer-consumer /graph.md contract test). Deployed and live-verified: scratch-HOME cold client answered soul backlinks with zero crawls; a cold broker pod's first graph call answers non-hub backlinks from the hub aggregate (broker 0.12.4, agent 0.21.1). Lessons in /debugging.md (mock fixtures encoded a plan assumption).
  • Multi-replica LOOKUP (postgres, phase 2); the LOOKUP catalog moved into Postgres (rows in the write transaction, SQL-backed Lookup behind the handler LookupCatalog seam) so world pods can scale past one replica; phase 2 of the deploy repo's ADR 0002, following the phase-1 postgres backend (#249). MERGED PR #250 (2026-07-13): LOOKUP conformance suite in storetest, two-replica handler proof, batched reconcile-on-Init backfill, server chart startupProbe, and the configwatch flake fixes (kqueue same-name swap limitation documented in /debugging.md).
  • Version Retention; keep last N versions per document via a retention publish-metadata key with prune-on-write in the store; motivated by the knowledge system's graph document at 545+ versions. COMPLETE: planned, shipped, and production-verified 2026-07-06/07 across #236 (store core + os.Root delete hardening + audit logging + SPEC §9.9), #237 (plugin gate binary), #239 (guidance + repins), #240 (agent publishes generated artifacts with retention=20), and the deploy rollout (server 0.20.0 / broker 0.9.0 / agent 0.19.0). Live result: /graph.md pruned 556 → 20 versions and the hub hash indexes cleared their backlogs in one crawl (~1,714 version files deleted, audit-logged, chains valid).
  • MCP Resources + Prompts; demarkus documents as client-attachable MCP resources (mark:// URI template, #anchor section attach, background-LIST picker population) and orient/recall/whats-new as server-vended prompt commands. SHIPPED PR #232 (2026-07-05), client/v0.17.0. Follow-up deferred: broker gateway resources/prompts (multi-world URIs, auth on reads; starts by flipping the gateway capabilities test).
  • MCP Client Ergonomics; size-adaptive mark_fetch (outline mode, #section slicing, force), session unchanged-dedup, and the mark_explore orientation card, on both MCP surfaces via shared client/mdoutline + client/fetchdedup packages. SHIPPED #225/#230 and deployed 2026-07-04/05; plugin users (client v0.15.0 via tools 0.4.1) and the live knowledge system (broker 0.5.0). Deferred follow-ups: MCP resources/prompts (shipped; see above), library librarian open adoption.
  • Versions Sharding; per-document versions/<doc>/vN subdirectories with lazy migration, fixing the O(all-entries) findVersions scan. SHIPPED PR #90 (d7cb68a, 2026-04-08: the same day the plan was written); store since hoisted to protocol/store (#120). This index wrongly listed it as unstarted until 2026-07-05.
  • Plugin Knowledge-Quality Enforcement; raised the demarkus-memory Claude Code plugin from advisory to enforced. SHIPPED v0.4.0, PR #171 merged 2026-06-01. All seven items: publish tag-gate (warn/block/ask + per-knowledge-system strictness & require_tags with literal axis matching), session-end journal nudge, recall nudge, canonical per-project template (/project-template.md), knowledge-system policy/template at the live root hub on knowledge.demarkus.io, and the /soul-doctor hygiene audit. 68 tests, pure awk/bash, zero runtime deps. Tail (separate): plugin shell tests → CI; optional nudge disable knobs.
  • Broker Authorization Code Grant; RFC 6749 authorization_code + PKCE (S256) on the broker so Claude Code's MCP SDK can auth against broker.knowledge.demarkus.io. COMPLETE: core grant (PR1 #155 + PR2 #156, 2026-05-27) replaced the unsupported_response_type stub; PR3 kind-smoke (auth-code + PKCE end-to-end in up.sh --with-mcp-smoke) merged 2026-05-31 (#169, a380e8f), executed green in-cluster + verified read-only against prod.
  • LOOKUP verb: the card-catalog verb (subject → docs + importance). Shipped to main PR #166 (2026-05-30); plugin surfacing in v0.3.0 (#168). Tail: mark_append metadata deferred by design.
  • Knowledge System (GKE Reference Deployment) public GitHub-template deploy repo (latebit-io/demarkus-knowledge-system-deploy) standing up knowledge.demarkus.io on GKE (OpenTofu + ArgoCD + OpenBao + bank-vaults + CSI-snapshot backups). Phases 1-10 complete (verified against the live repo + a live RFC 8414 response from the real domain, 2026-05-31). Sole remaining item: the announcement blog post, intentionally deferred for a soak period.
  • Universe Onboarding; last-mile join flow. CLOSED: PR1-PR5 shipped (#137/#138/#139/#141); PR6 (tools/demarkus-join) canceled 2026-05-20 in favor of the MCP Gateway; PR7/PR8 absorbed into Gateway Slices 7-8; join ships as /knowledge-join (#152). Remaining: low-priority doc debt only (two standalone deployment docs).
  • Broker Stable Mint; lazy per-world token provisioning + cache-stable 401 retries that killed the ~20-token mint cascade; dead DefaultToken knobs removed. COMPLETE (#158/#159/#163/#164/#165, 2026-05-27→29).
  • Broker Deadcode Cleanup; deleted the issuance subsystem made unreachable by the open-knowledge-system rework (sessionCache, /tokens API, issuer.go, sweeper trim). COMPLETE (#159 + #164, commit f9a24e9).
  • Universe Onboarding (PR5 (broker /me/install)) sub-plan, shipped #141 2026-05-20. Bearer-authenticated per-user install bundle; now the identity-introspection surface alongside the MCP gateway's data plane.
  • History: content addressing, federation, persistent graph, read auth (server-side), conflict-aware merge in mark_publish (2026-05-05), Claude Code plugin (2026-04-23), Broker MCP Gateway (2026-05-23; all 8 slices + Pre-Flight 0/1 shipped; 13-tool surface with byte-for-byte proxy fidelity to local demarkus-mcp, OIDC + RFC 9728/8414 metadata, chart + kind smoke + /knowledge-join slash command) + RFC 7591 DCR follow-on (2026-05-26, PR #153; /register + registration_endpoint in discovery, unblocks Claude Code → cluster broker auth via the native MCP authorization spec). Also: OKF type adoption + /soul-join managed remote souls (2026-06).

Plan Archives

Original plan documents preserved for reference:

  • Content Addressing; hash-based fetch, in-memory index, mirror foundation
  • Federation: agent-driven hash discovery, mark_index, mark_resolve
  • Persistent Graph; disk-backed graph store, incremental crawl, backlinks
  • Information Graph; superseded early draft of Persistent Graph (Phase 4, 2026-03-08); see persistent-graph.md for the version that shipped.
  • Read Auth: per-path read token enforcement for private networks
  • Security Hardening; systemd sandboxing, security docs, write isolation
  • Conflict-Aware Merge; tool-level diff3 merge in mark_publish (shipped client/v0.12.25 + v0.12.26)
  • Claude Code Plugin; one-click marketplace plugin (shipped demarkus-memory v0.1.1; v0.2.0 added /knowledge-join 2026-05-23; v0.3.0 added self-documenting guidance + lookup recall 2026-05-31; v0.4.0 enforcement + template + /soul-doctor shipped 2026-06-01, PR #171; v0.5.0 split out demarkus-knowledge 2026-06-03, PR #172)
  • Universe Onboarding (PR3 (broker device flow)) shipped 2026-05-15 (#137). RFC 8628 device flow end-to-end on the broker. Six sub-steps merged across one PR; PR4 builds on top.
  • Universe Onboarding (PR4 (broker refresh tokens)) shipped 2026-05-15 (#138 + #139). Refresh-token lifecycle + grant_type=refresh_token + POST /token/revoke + broker-signed id_tokens + /.well-known/jwks.json + compositeVerifier + Sweeper integration. Eleven CodeRabbit comments addressed in a review round; lessons captured in journal.
  • Broker MCP Gateway; shipped 2026-05-23 (v7). Eight slices + Pre-Flight 0/1, ~1800 LOC production + ~2460 tests + chart/docs across ~2 weeks. Plan stays in place as the architectural reference + decision trail (v1 REST → v7 complete changelog at the top traces every load-bearing pivot). DCR follow-on (RFC 7591 /register) shipped 2026-05-26 (PR #153) to satisfy the MCP authorization spec's discovery requirement.
  • Search Verb: superseded by LOOKUP. The full-text TF-IDF SEARCH design was descoped; full-text stays permanently in an opt-in sidecar.
  • POC Deployment; canceled. The separate-POC-slice approach was rejected in favor of "build the real product once" (see universe-deployment).
  • Obsidian Plugin; obsolete. Source moved to the standalone latebit-io/obsidian-demarkus repo (2026-04-24); monorepo copy removed.

Prompt Consolidation

  • Plugin Prompt Source of Truth; consolidate 54 distributed memory and knowledge prompt files into 18 canonical prompt sources seeded from Claude Code prose, then render checked-in artifacts for Claude Code, Pi, and OpenCode. Drafted 2026-08-20; implementation not started.

Prompt Consolidation Update

  • Plugin Prompt Source of Truth was implemented on branch feat/plugin-prompt-source on 2026-08-20. The six agent plugins now render 54 runtime prompt artifacts from 18 canonical templates, with CI and pre-commit drift checks plus explicit OpenClaw and foreign-harness isolation.

Knowledge Server

  • Multi-world Knowledge Server; one replicated demarkus-knowledge-server process hosts multiple logically isolated worlds behind shared UDP 6309 using DNS authorities and TLS SNI. GCS-first, one bucket per world, broker and agent remain separate, per-world capability tokens, ACLs, publish policy, limits, backup, and restore. Planned 2026-08-21; supersedes the earlier bucket backend plan. Implementation starts with ADRs and a 100,000-document real-GCS feasibility spike.
soul.demarkus.io:6309/plans/graph-hub-seed.md draft reader meta

Plan: Wire backlinks/graph tools to the published /graph.md (hub seeding)

Status: implemented 2026-07-14 on branch graph-hub-seed (PR pending); planned 2026-07-13. Closes roadmap "Wire backlinks/graph tools to the published /graph.md" (gap 1 of the 2026-07-13 knowledge-layer analysis). See the implementation notes at the end for deviations.

Context

The federation agent publishes the aggregated link graph to each hub at /graph.md (now with enriched six-column edges after the edge-semantics work, PR 251), but mark_backlinks and mark_graph answer only from the local crawl cache: ~/.mark/graph.json for demarkus-mcp, a per-pod ephemeral store for the broker. A fresh client or a recycled broker pod answers from an empty graph while an authoritative aggregate sits on the hub unread. The accumulation exists; the query path bypasses it.

Client-only change. No server, protocol, or store-backend work. ParseExport (currently test-only) becomes the production consumer of /graph.md.

Design decisions

  • Seed source is the attached world. demarkus-mcp seeds from defaultHost + "/graph.md" (the -host world; the soul server publishes its own /graph.md). The broker seeds per world from mark://{world}/graph.md through dispatchWithAuth. No new flags; a world without /graph.md degrades silently to today's behavior (not-found is not an error).
  • Local wins. The hub aggregate carries no per-node freshness, so locally crawled data is never overwritten by seed data. A stored node counts as locally authoritative iff its status is not one of "", "external", "error" AND CrawledAt is non-zero. Seeded nodes get zero CrawledAt, which is the durable "seeded, not locally observed" marker across restarts.
  • Seeding fills gaps only: nodes inserted when absent or when the existing node is non-authoritative; edges replace the outgoing set only for sources that are not locally authoritative. A later local crawl of a seeded source replaces its edges through the existing Merge refresh logic.
  • Conditional refresh with our own etag. fetch.Client's built-in if-none-match rides the unauthenticated disk cache, which token'd souls skip, so the seeder stores the last /graph.md etag itself: new seed_etags map (host -> etag) in the graph.json envelope, additive JSON, schema stays v1. Requests send if-none-match; not-modified means skip parse and merge.
  • Throttled per process. A conditional check costs one round trip; still, cap at one check per host per 5 minutes (package constant), process-scoped like the fetchdedup session state. First graph-tool call in a session always checks.
  • Never fatal. Any seed failure (fetch error, malformed document, oversized) logs at warn and falls through to the local store. Seeding must never make backlinks worse than today.

Steps

1. graphstore: seed support (client/graphstore/store.go, export.go)

  • document envelope gains SeedEtags map[string]string with json:"seed_etags,omitempty"; Store carries it; Load/Save round-trip it (nil-safe for legacy files).
  • SeedEtag(host) string and SetSeedEtag(host, etag) accessors (locked).
  • SeedFromExport(nodes []StoredNode, edges []StoredEdge) (added int):
    • classify locally authoritative sources (status not in {"", "external", "error"} and CrawledAt non-zero);
    • insert nodes when absent or existing node non-authoritative, forcing CrawledAt to zero on the seeded copy;
    • drop stored edges whose From is a seeded (non-authoritative) source being refreshed, then insert seed edges for those sources, Count normalized, dedup on edgeKey;
    • never touch nodes or edges of authoritative sources.
  • Optionally parse the > Exported: header line in ParseExport later; NOT in scope (freshness rule does not need it).

Tests: seed into empty store; local-wins (authoritative node and its edges untouched); seeded-then-crawled source flips to authoritative and Merge replaces its edges; seed refresh replaces prior seeded edges (no stale seeded backlinks); seed_etags round-trips through Save/Load; legacy file loads with nil map.

2. fetch: conditional fetch with explicit etag (client/fetch/fetch.go)

cachedRequest already threads extra metadata internally. Export a minimal surface:

// FetchConditional fetches with an if-none-match etag; status not-modified
// returns with an empty body.
func (c *Client) FetchConditional(host, path, token, etag string) (Result, error)

Implemented via the existing extra-metadata path (option-bearing requests already skip the disk cache, which is correct here). Test with the existing mock-stream harness: etag sent, not-modified passthrough.

3. demarkus-mcp: seed hook (client/cmd/demarkus-mcp/main.go, explore.go)

  • handler gains graphSeed state: map[string]time.Time last-checked per host + mutex (process-scoped, mirrors fetchdedup's session scoping).
  • seedGraph(host string): throttle check; FetchConditional(host, "/graph.md", token, store.SeedEtag(host)); on ok: ParseExport then SeedFromExport, SetSeedEtag, Save(); on not-modified/not-found/error: return silently (warn-log real errors).
  • Call seedGraph(defaultHost) at the top of markBacklinks, markGraph, and explore's writeBacklinksSection (before the store read; markGraph seeds so depth-limited crawls still benefit from hub context).
  • Tool descriptions: one sentence on mark_backlinks/mark_graph ("seeded from the world's published /graph.md when available; local crawls take precedence"). No em dashes.
  • The "No backlinks found ... run mark_graph" hint stays as the empty-store fallback text.

Tests (mock fetch func in main_test.go style): cold store + hub graph answers backlinks without a crawl; hub 404 degrades to the current hint; local crawl beats conflicting seed rows; second call within the throttle window does not refetch; etag round-trip sends if-none-match.

4. Broker: per-world seeding (tools/demarkus-broker/internal/broker/mcp_tools_graph.go, mcp_tools_explore.go)

  • Gateway gains graphSeed map keyed by worldName {etag string, checked time.Time} + mutex (per pod, like graphStore).
  • seedWorldGraph(ctx, claims, worldName): throttle; dispatchWithAuth Fetch of /graph.md (send if-none-match via the dispatcher's metadata path or accept a full fetch and compare the stored etag; pick during implementation, do not add dispatcher surface unless trivial); ParseExport + SeedFromExport + record etag. Silent degrade.
  • Call from handleMarkBacklinks, handleMarkGraph, and explore's backlinks section, scoped to the world parsed from the tool URL.
  • MCP-API.md: note the graph store is seeded from each world's published /graph.md on demand, so cold pods answer backlinks; local crawls still take precedence; ephemerality note stays (the seed makes restarts cheap, not durable).

Tests: cold gateway + world with /graph.md answers backlinks with no prior crawl (this is the headline behavior); world without /graph.md keeps today's empty hint; seeded then crawled world prefers crawl results; throttle respected across two calls.

5. Docs and bookkeeping

  • Roadmap: mark the wiring item IMPLEMENTED with plan link (soul, post-merge DONE edit as usual).
  • docs/site/client/index.md and architecture/index.md: one line each where mark_backlinks/graph persistence is described ("seeded from the published /graph.md").
  • ADR: not needed (no new convention; consumes ADR 0004's format). Note in the PR description instead.

Out of scope

  • TUI graph-view seeding (worthwhile follow-up; keep this PR to the MCP surfaces the roadmap item names).
  • Parsing the hub graph's Exported timestamp for freshness arbitration (local-wins does not need it).
  • Publish-time edge extraction in the store (the "later upgrade" per the roadmap; backend-parity applies there).
  • demarkus-library floor changes (its own repo; it already reads /graph.md).

Risks

  • Seed data quality: the hub aggregate may contain hosts unreachable from this client (cluster-internal names in the knowledge system's graph). Harmless for backlinks (they are just labels); mark_graph crawls starting from them will error per node as today. Do not filter by reachability.
  • Large /graph.md: the enriched table grows rows, not new fetch cost (single doc). ParseExport is linear; the 1 MiB protocol body cap bounds it. No action.
  • Merge interplay: SeedFromExport must not fight the new Merge replace-refreshed-sources logic; the shared authoritative-source rule (status + CrawledAt) is the single arbiter, tested from both directions.
  • Etag identity: /graph.md is republished wholesale with retention 20; etag changes on every publish even if content is identical except the Exported line, so not-modified hits only between publishes. Accept; the throttle bounds the cost.

Verification

  1. Unit suites: client graphstore, fetch, demarkus-mcp; broker package. bash pre-commit.sh.
  2. Live cold-start check: build demarkus-mcp, delete (or point HOME at a scratch dir for) ~/.mark/graph.json, attach to the soul, call mark_backlinks on a doc known to have hub-graph backlinks; expect answers with zero crawls. Then mark_graph a subtree and confirm local results win and persist.
  3. Broker check via its test harness (no cluster needed): cold gateway seeds from a mocked world /graph.md.
  4. Legacy: a /graph.md still in two-column form seeds correctly (ParseExport dual-format already tested; add one seed test using a legacy fixture).

Implementation notes (2026-07-14)

Implemented as planned, with these deviations and additions:

  • URL canonicalization fix (unplanned, required). The first live cold-start check failed: the soul's /graph.md keys rows on canonical mark://soul.demarkus.io:6309/... URLs, but mark_backlinks built its lookup key as defaultHost + path with no default-port normalization, and the plugin's -host flag omits the port. Fixed by canonicalizing through resolveURL ("mark://" + host + path) in markBacklinks, markGraph's start URL, and explore's backlinks section. This was a latent pre-existing mismatch (portless -host crawls and full-URL queries could already disagree); seeding surfaced it. Regression test: TestSeedGraph_DefaultHostWithoutPortCanonicalizes.
  • Step 2 test harness. The "existing mock-stream harness" is server-side only, so FetchConditional got the client's first wire-level test: an in-process QUIC listener with a self-signed cert (client/fetch/conditional_test.go) asserting etag sent, not-modified passthrough, and stale-etag refetch.
  • Step 4 dispatcher surface. Adding FetchConditional to worldDispatcher/worldPool was trivial (passthrough to fetch.Client), so the broker sends real if-none-match instead of comparing etags after a full fetch. The broker's seed etag lives in the in-memory graphstore's seed_etags map (keyed by worldName); only the throttle map lives on the gateway.
  • Shared helpers. Merge's drop-refreshed-edges and upsert logic were extracted (dropEdgesFromLocked, upsertEdgeLocked) so SeedFromExport and Merge share one implementation of the arbitration rule.
  • Live verification passed (2026-07-14): scratch-HOME cold start against the soul answered 4 backlinks for /patterns.md with zero crawls; 133 nodes / 190 edges seeded from the still-legacy two-column /graph.md (v6); seed etag persisted; all seeded nodes carried zero CrawledAt. A depth-1 mark_graph of /conventions.md flipped it authoritative (real CrawledAt) and its enriched crawl edges replaced the seeded legacy row in backlinks output, with the other 130 nodes untouched.

Review round (PR 253, CodeRabbit)

Three findings, all accepted:

  • Seed the resolved host, not defaultHost. The plan's "seed source is the attached world" left full mark:// URLs against other hosts unseeded. seedGraph now takes the canonical host from resolveURL (throttle, etag, and token resolution were already per-host, and the broker already seeded the URL's world). Test: TestSeedGraph_SeedsResolvedHostNotDefault.
  • Stale-edge gap in SeedFromExport. The drop set was built only from seed-edge Froms, so a re-seed where a source's outgoing set went to zero left its old seeded edges behind. Now every observed (real-status) non-authoritative seed node also joins the drop set, mirroring Merge's refreshed criterion; the status predicate is extracted as observedStatus and shared by Merge, authoritativeLocked, and SeedFromExport. Tests: TestSeedRefreshDropsEdgesOfEmptiedSource plus the counter-case TestSeedKeepsEdgesOfUnobservedSeedNode (an error-status seed node with no edges must not drop what it never read).
trail
  1. soul.demarkus.io:6309 v93
  2. graph-hub-seed