DR-098 — The MemPalace auto-mine daemon runs under launchd supervision; the chromadb 1.5.9 segfault risk is accepted
Owner ruling (S499): DR-048’s disable-until-upstream-fix posture was deliberately
reversed, not drifted from. The auto-mine daemon runs enabled (hooks.daemon: true)
under launchd KeepAlive supervision — the supervision is the considered answer to the
“dead daemon silently reverts the posture” failure DR-048 guarded against. The chromadb
1.5.9 HNSW segfault risk is accepted: the 21/07 partial rebuild (169,823 drawers lost,
fully restored from the pre-rebuild archives on 24/07) is the known worst case, and the
archive-merge recovery path in runbooks/mempalace-repair.md §9 is the mitigation.
Operational posture + repair recipes: runbooks/mempalace-repair.md (§5a hook→daemon
routing, §5g launchd supervision).
Amendment (S506, owner-ratified): the accepted risk materialised 27/07 not as an
occasional daemon death but as a deterministic full-stack reader outage — a corrupt
mempalace_drawers HNSW segment segfaults ANY collection access (MCP, CLI, daemon,
stop-hook writers), and both 3.6.0 guards miss it (id-383 S504 diagnosis). The risk
statement is amended accordingly: the failure shape is a reader outage requiring a
repair --mode from-sqlite rebuild in a §10.3a solo window; the S506 repair recovered
zero-loss from sqlite ground truth — the archives were not needed, so the archive-merge
path (§9) is the secondary net, not the primary mitigation. Acceptance stands.