Local-first Personal Model Runtime for macOS
Gator is the Runtime’s cross-stage admission policy, not a second capture daemon or a parallel model writer. It keeps raw local observation, normalized activity, and promoted personal-model geometry distinct so recall-oriented capture does not imply first-sighting memory.
capture evidence
-> privacy boundary
-> S0 event/content suppression
-> S1 focused content
-> timeline provenance
-> reducer / memory-delta evidence gate
-> independent-session Point candidates and retry-safe Lines
-> independent-input promotion for Face, Volume, Root
capture-once diagnostic holds the Runtime lifetime lock and cannot race the daemon.QueuedSurfaceRefresh, keeps
only the sanitized source event type, discards stale pointer details, and updates the session from
the persisted surface rather than the event-time app.normalization_status; downstream
model consumers fail closed on ineligible statuses while still advancing watermarks.active / worked in window records are removed
before an llm block becomes eligible.unknown and is ineligible; only the database
migration assigns legacy to rows whose earlier origin cannot be reconstructed.self and ambiguous identities fail closed.
Context case/width/whitespace variants share one display node, and duplicate projected strokes
render once without deleting their separate audit Lines.knows is symmetric; all other
predicates remain directed. Legacy collisions stop relation migration without merging rows or
summing observation counts.applied only when deterministic apply reports no item errors. Partial failure
remains retryable and visible as failed.person-event.
If one raw identity Point arrives after one receipt-bearing derived roster head for the same
person file, the two are merged through one atomic multi-predecessor supersession without
incrementing interaction sightings. Point maintenance runs before entry interactions with a
separate bounded budget; the first same-file fact after an entry-created roster supplies one
identity bridge without becoming a sighting or copying every later receipt. Durable source events
remain idempotent through slug/display-name adoption. Ambiguous raw identities or roster heads,
plus unreceipted legacy heads, fail closed and are left for explicit legacy repair.Raw captures retain their configured local retention policy. A TimelineBlock is a bounded evidence
projection, not a promise that every frame is stored forever. Existing blocks migrate to legacy
because their original normalization path cannot be reconstructed safely. No migration guesses from
entry wording or silently deletes prior model state.
Pre-item-ledger memory deltas keep the same conservative boundary. A legacy row explicitly marked
not_requested can take its historical context-free apply path. A legacy pending or failed row
with Point/Line/event effects is not replayed automatically: some effects may already have committed,
and inventing a receipt after the fact could count an additive Line twice. It remains failed and
owner-auditable until an explicit repair can establish what happened. The affected window is
quarantined and its session watermark advances, so one irrecoverable historical receipt cannot block
all later, fully receipted windows.
An llm block has passed content-signal and response-shape checks; it is not yet a per-entry
cryptographic grounding guarantee. Source receipts plus locally verified evidence spans are part of
the next promotion hardening slice.