Skip to content

DR-098 — The MemPalace auto-mine daemon runs under launchd supervision; the chromadb 1.5.9 segfault risk is accepted

Owner ruling (S499): DR-048’s disable-until-upstream-fix posture was deliberately reversed, not drifted from. The auto-mine daemon runs enabled (hooks.daemon: true) under launchd KeepAlive supervision — the supervision is the considered answer to the “dead daemon silently reverts the posture” failure DR-048 guarded against. The chromadb 1.5.9 HNSW segfault risk is accepted: the 21/07 partial rebuild (169,823 drawers lost, fully restored from the pre-rebuild archives on 24/07) is the known worst case, and the archive-merge recovery path in runbooks/mempalace-repair.md §9 is the mitigation. Operational posture + repair recipes: runbooks/mempalace-repair.md (§5a hook→daemon routing, §5g launchd supervision).

Amendment (S506, owner-ratified): the accepted risk materialised 27/07 not as an occasional daemon death but as a deterministic full-stack reader outage — a corrupt mempalace_drawers HNSW segment segfaults ANY collection access (MCP, CLI, daemon, stop-hook writers), and both 3.6.0 guards miss it (id-383 S504 diagnosis). The risk statement is amended accordingly: the failure shape is a reader outage requiring a repair --mode from-sqlite rebuild in a §10.3a solo window; the S506 repair recovered zero-loss from sqlite ground truth — the archives were not needed, so the archive-merge path (§9) is the secondary net, not the primary mitigation. Acceptance stands.