# Independent core project history recall Status: core explicit retrieval implemented and targeted integration-tested; not the complete V4 automatic-memory rollout. The disabled external project-history-recall plugin is not imported, consulted, or modified. ## Implemented path Agent sequential/inline session_search calls bind the live caller ID and current_project scope. Registry calls preserve the trusted session_id kwarg. The model cannot supply a broader scope. Internal Python callers retain the historical positional API, with new options keyword-only. `hermes_project_scope.resolve_project_scope` derives a complete metadata-only allowed session set using shared Desktop ownership rules, rejects ambiguity and unrelated principals, and returns an optimistic metadata revision. No UI result limit determines access. Ordinary archives remain eligible; hidden/background rows do not. `SessionDB.search_messages(allowed_session_ids=...)` applies a single JSON-bound session set before SQL ranking/LIMIT in FTS/CJK/trigram/LIKE and fallback paths. None retains legacy behavior; an empty set returns no matches. Compaction archives are retained, rewound rows excluded. `tools/session_search_project.py` rereads source text before presentation, decodes multimodal storage, projects text only, excludes synthetic control messages and secret-bearing text, and rechecks source hashes plus scope before returning. Raw historical assistant replies are not confirmed facts. ## Continuation contracts - Read: pass returned `next_after_message_id` as `after_message_id`. - Scroll: retain the real original `around_message_id`; pass returned forward/backward frontier. A frontier can be a filtered row and is not evidence. - Long text: use `content_offset` / `content_length` on a real message anchor; content hash covers the full safe decoded text. - Discovery: pass `next_search_cursor` with identical query/sort; cursor is bound to caller and scope revision. Live offsets may repeat sessions, and are not snapshot-consistent. - No project: do not browse unrelated Home sessions; only the caller's own compacted history is available for explicit recovery. - Agent project mode does not support role_filter; it returns unsupported instead of silently exposing tools. ## Verification receipt The canonical runner completed 7 selected files with 121 tests passed, zero failed. Tests cover scope ownership, >5000 scope members, SQL fallback boundaries, source revocation, safe multiline/multimodal projection, pagination, trusted inline identity, and old session search behavior. The project-tool target has exhausted the explicitly authorized 10 starts; do not rerun or rename it to bypass that limit. Existing Holographic legacy regressions separately passed 42 tests. The optional project Holographic mode is still under identity review; it is not enabled on the user's profile. ## Known boundaries - Project/source checks are optimistic across multiple stores, not a distributed authorization transaction. - This is Recall subsystem isolation, not an OS sandbox against general file/terminal access. - Global MEMORY/USER and old unscoped Holographic data have not been migrated or claimed to be isolated. - Full source completion/origin policy, import-taint dependencies, automatic injection/revocation of prior api_content, confirmed/revised project facts, durable indexing/restore release gates and full Desktop journey are not complete. - Python callers passing a numeric-string around_message_id together with integer frontiers can hit a TypeError; schema-valid integer anchors are supported. Track as nonblocking compatibility debt before final release. - execute_code identity forwarding is fixed, but session_search remains disallowed by sandbox/agent-loop guards. No extra capability was opened. - No actual model history export/embedding request, user-config change, deployment, restart, or Git commit was performed. ## Rollout Do not mark the whole feature complete or enable automatic retrieval based on these selected tests. Finish Holographic identity fixes, authenticate Desktop RPC, integrate the visible UI, run real user journeys, and close the V4 publication gates first. Source changes do not prove an already-running backend has loaded them.