note tag
- New `cube note tag <coord> <cat>` subcommand: reclassify an existing note in place by
setting its doc_type to `note:<cat>` and put_record under the same coord. Used to move
mis-tagged notes into the right category (e.g. a finding accidentally logged as a debug
or action). Puts are WAL+delta+checkpoint durable. Note: `delete_raw` is NOT durable here
(the checkpoint/delta records Puts of surviving keys only — no tombstones — so a deleted
key resurrects from the base snapshot on reload), so `tag` is the reliable in-place
reclassify path. 5 notes tests pass.
Notes -> model CUBE integration (message-save-path)
- cubesys:🎶 WordFlags-tagged CZYX note log (doc_type=note:<category>); project threads
via linked_records; project resume (<cubecoords> project resume <name> <text>) and context
injection (<project context <name>>). Durable ConcurrentStore (WAL + delta + checkpoint);
short-lived processes must checkpoint() before exit.
- CLI: cube note add|list|search|show; cube project list|show|resume|context.
- cube-notes-mcp (stdio MCP server) exposes mcp__cubenotes__note_*/project_* tools to the
DeepSeek Harness; harness registers the mcp-client at the BUNDLE layer (inject: [tools])
so the plugin actually mounts (profile-layer rows can't inject the tools service — the
silent no-mount bug).
How we used it: trace errors from prior run data saved in CUBE
- The headless agent (cube-agent) treats CUBE as a searchable, replayable log: every action
is written as a note (category=action) so a run can be replayed/fine-tuned; each review run
reads ONLY uncovered findings (category=finding) and marks them covered with a checkpoint
note (category=checkpoint) — true incremental, non-destructive review.
- The deterministic, grounded report tool reads finding notes verbatim (no model
hallucination), assigns severity (HIGH/MEDIUM/LOW) + priority order, and writes a review
.txt. It surfaced 7 previously un-categorized logs (GIT-SHALLOW-CLONE, POSTFIX-TLS-CERTS,
SELINUX-RESTORECON, DSH-WEB-EADDRINUSE, CONCURRENT-STORE-CHECKPOINT, MCP-BUNDLE-LAYER,
CUBES-TWO-TREES) that were logged but never tagged finding.
- Coverage is precise: the report marks exactly the findings it reviewed, so the next run
reports only new ones. The notes store is also the harness GUI's CUBE surface
(mcp-cubenotes note_list), so everything the agent writes is visible and reviewable.
Implements the PDF's Package 3 with new code:
- path: bijective POSIX path <-> Czyx mapping (/c001/z002/y003/x004).
Axis-letter + 3-digit zero-padded canonical names so lexical order equals
numeric order and each coordinate has exactly one spelling. Inode IS the
packed u32 coordinate — no inode side table.
- nullspace: the PDF's 'use Null cubes for ACLs, xattrs, journaling, volume
metadata', with the Z-plane allocation fixed and documented (Z=1 volume,
Z=2 ACL, Z=3 xattr, Z=4 journal ring). ACL/xattr tables are FNV
hash-bucketed with exact-match resolution inside the bucket, because 4
axes of subject cannot injectively mirror into 2 axes of Null space.
Journal is a bounded ring; wraps are detectable via a monotonic counter.
- vfs: the whole filesystem, kernel-free and unit-testable — lookup,
readdir, create/read/write/truncate/unlink, mkdir/rmdir, ACL enforcement,
xattrs, journaling, POSIX errno mapping.
- fuse (feature 'mount'): thin kernel adapter, zero TTL (the store is
writable out-of-band, so cached metadata would go stale).
- cubestore: added the PDF's 'optional scanning primitives' (keys,
scan_prefix) and the Package 2 association API (associate, linked_to)
that cubefs needs for directory listings.
Two defects were found by LIVE MOUNT testing and fixed, not by unit tests:
1. mkdir succeeded then the kernel's revalidating lookup returned ENOENT,
so 'mkdir -p' could never reach depth 4. Directories were purely
inferred from records, making an empty directory unrepresentable. Fixed
with an explicit Null-space directory marker; rmdir removes it; readdir
merges markers in. 5 regression tests added.
2. Multi-user ACL behaviour was untestable because the mount lacked
AllowOther — the kernel returned EACCES at the mountpoint before any
request reached us. Added --allow-other.
Verified: 58 unit tests pass; clippy clean; live mount exercised with cat,
echo, dd, truncate, cp, chmod, chown, getfattr/setfattr, mkdir -p, rmdir,
find, a 200-record write loop, and cross-user reads/writes as luulu.