feat: implement memory and evidence administration with guided repairs
Publish documentation / publish (push) Successful in 1m27s

Add PostgreSQL-backed memory, editable evidence with source review and activation, and human-approved archive repairs across the harness, API, and UI. Include migrations, deployment support, regression coverage, and validation documentation.

Refresh permissions from validated session roles so existing administrator logins can access newly deployed archive management features.
This commit is contained in:
Codex
2026-09-10 10:31:34 +02:00
parent 8fe526dd6e
commit 82e2c91f42
168 changed files with 11914 additions and 1772 deletions
@@ -0,0 +1,61 @@
const test = require("node:test");
const assert = require("node:assert/strict");
const { installRepairGate } = require("../memory/repair.js");
function gate({ answers, fail = false, resume = false }) {
let tool;
const calls = [], widgets = [];
const repair = { repair_id: "receipt", choice: null, status: "proposed", can_apply: true,
saved: false, indexed: false, options: [{ id: "fix", content: { detail: "Correction" } }] };
installRepairGate({ registerTool: def => { tool = def; } }, {
workflow: { activate() {}, phase: () => ({ id: "F4" }) },
memory: { execute: (_ctx, args) => {
calls.push(args);
if (args[0] === "repair-apply") {
const choice = args[args.indexOf("--choice") + 1];
if (choice === "reject") Object.assign(repair, { choice, status: "rejected" });
else Object.assign(repair, { choice, saved: true, indexed: !fail,
status: fail ? "pending_activation" : "active" });
fail = false;
}
return JSON.stringify(repair);
} },
waitForReviewer: async (_ctx, descriptor) => {
widgets.push(descriptor);
assert.ok(answers.length, "gate must not ask an unbounded extra question");
return answers.shift();
},
toTextResult: text => text,
});
return { calls, widgets, run: () => tool.execute("id", {
session: "s", ...(resume ? { repair_id: "receipt" } : { proposal: { reason: "conflict", options: [] } }),
}, null, null, {}) };
}
test("human choice applies once and the next widget reports activation", async () => {
const g = gate({ answers: [{ choices: ["fix"] }, { choices: ["continue"] }] });
assert.equal(JSON.parse(await g.run()).indexed, true);
assert.deepEqual(g.calls.map(args => args[0]), ["repair-prepare", "repair-apply"]);
assert.equal(g.widgets[0].repair.saved, false);
assert.equal(g.widgets[1].repair.status, "active");
});
test("rejection asks for reformulation without a normal workflow decision", async () => {
const g = gate({ answers: [{ choices: ["reject"] }] });
assert.match(await g.run(), /rejected as inadequate/);
assert.equal(g.calls.length, 2);
});
test("retry keeps the receipt and selected choice, then reports true activation", async () => {
const g = gate({ resume: true, fail: true,
answers: [{ choices: ["fix"] }, { choices: ["fix"] }, { choices: ["continue"] }] });
assert.equal(JSON.parse(await g.run()).indexed, true);
assert.equal(g.widgets[1].repair.status, "pending_activation");
assert.equal(g.calls[0][0], "repair-show");
assert.deepEqual(g.calls[1], g.calls[2]);
});
test("free text and forged choices never apply a correction", async () => {
for (const response of [{ control: "freetext", text: "Explain the conflict" }, { choices: ["forged"] }]) {
const g = gate({ answers: [response] });
await g.run();
assert.equal(g.calls.length, 1);
}
});
@@ -1,163 +1,44 @@
const test = require("node:test");
const assert = require("node:assert");
const assert = require("node:assert/strict");
const { createMemoryGate } = require("../memory/index.js");
const { buildMultiselectRequest } = require("../core/builders.js");
const { isReserved } = require("../core/reserved-labels.mjs");
const { createFakePi } = require("./fake_pi_runtime.js");
const TABLE_CANDIDATE = {
decision_seq: 3,
type: "table_promoted",
subject: "fact_seeablazione",
detail: "tabella principale ablazioni",
rationale: "scelta dal reviewer",
question_context: "quante ablazioni nel 2023",
tables: ["fact_seeablazione"],
concepts: [],
};
const MEMORY_CANDIDATE = {
decision_seq: 5,
type: "concept_clarified",
subject: "paziente attivo",
detail: "flag_attivo = TRUE",
rationale: "scelta dal reviewer",
question_context: "quante ablazioni nel 2023",
tables: [],
concepts: ["paziente attivo"],
};
test("the public Memory facade owns F8 policy and mutation ordering", async () => {
const { pi, tools, ctx } = createFakePi();
function setup({ phase = 8, response, failure = null } = {}) {
const runtime = createFakePi();
const calls = [];
let descriptor;
const duplicateMemory = { ...MEMORY_CANDIDATE, decision_seq: 6 };
const declinedMemory = {
...MEMORY_CANDIDATE,
decision_seq: 7,
subject: "ricovero indice",
detail: "first_event",
};
ctx.ui.input = async (title) => {
descriptor = JSON.parse(title);
calls.push(["review", descriptor.options.map((option) => option.id)]);
return JSON.stringify({ id: descriptor.id, choices: ["seq-5"] });
};
const memoryGate = createMemoryGate({
workflow: {
activate: () => calls.push(["activate"]),
phase: () => ({ number: 8, id: "F8" }),
close: (_ctx, _session, phaseNumber, summary) => {
calls.push(["close", phaseNumber, summary]);
return null;
},
},
memory: {
execute: (_ctx, args) => {
calls.push(["memory-execute", args]);
return JSON.stringify([
TABLE_CANDIDATE,
MEMORY_CANDIDATE,
duplicateMemory,
declinedMemory,
]);
},
mutate: (_ctx, args, recovery) => {
calls.push(["memory-mutate", args, recovery]);
return null;
},
},
ledger: {
record: (_ctx, session, decision, recovery) => {
calls.push(["ledger", session, decision, recovery]);
return null;
},
},
reviewer: {
buildMultiselect: buildMultiselectRequest,
isReserved,
},
waitForReviewer: async (runtimeContext, widget) => {
const response = await runtimeContext.ui.input(JSON.stringify(widget), "");
return JSON.parse(response);
},
toTextResult: (text) => ({ content: [{ type: "text", text }] }),
const summary = { summary_id: "summary", items: [{ id: "rule", card: { subject: "Rule" } }] };
createMemoryGate({
workflow: { activate() {}, phase: () => ({ number: phase, id: "F" + phase }),
close: () => { calls.push("close"); return "closed"; } },
memory: { execute: () => JSON.stringify(summary),
mutate: async (_ctx, args) => { calls.push(["save", args]); return failure; } },
ledger: { record: (_ctx, _session, decision) => { calls.push(["ledger", decision]); } },
waitForReviewer: async (_ctx, widget) => { calls.push(["widget", widget]); return response; },
toTextResult: text => ({ content: [{ type: "text", text }] }),
}).install(runtime.pi);
return { calls, run: () => runtime.tools.get("reviewer_memory_promote").def.execute(
"id", { session: "s1" }, null, null, runtime.ctx) };
}
for (const control of ["back", "exit", "freetext"]) {
test("review control " + control + " never saves or closes", async () => {
const { calls, run } = setup({ response: { control, text: "Revise scope" } });
await run();
assert.deepEqual(calls.map(call => call[0]), ["widget"]);
});
memoryGate.install(pi);
const result = await tools.get("reviewer_memory_promote").def.execute(
"promote-via-facade",
{ session: "s1" },
null,
null,
ctx,
);
assert.deepEqual(descriptor.options, [
{
id: "seq-5",
label: "concept_clarified: paziente attivo",
detail: "flag_attivo = TRUE",
rationale: "scelta dal reviewer",
meta: { question_context: "quante ablazioni nel 2023" },
selected: true,
},
{
id: "seq-7",
label: "concept_clarified: ricovero indice",
detail: "first_event",
rationale: "scelta dal reviewer",
meta: { question_context: "quante ablazioni nel 2023" },
selected: true,
},
]);
assert.deepEqual(descriptor.selected, ["seq-5", "seq-7"]);
assert.doesNotMatch(descriptor.content, /fact_seeablazione/);
assert.match(descriptor.content, /flag_attivo = TRUE/);
assert.deepEqual(calls.slice(0, 7), [
["activate"],
[
"memory-execute",
["promote", "--session", "s1", "--preview", "--json"],
],
["review", ["seq-5", "seq-7"]],
[
"memory-mutate",
["save-one", "--session", "s1", "--decision", "5", "--json"],
"Recupero manuale (umano): tht memory save-one --session s1 " +
"--decision 5. Finora salvate: 0.",
],
[
"ledger",
"s1",
{
type: "memory_promoted",
subject: "paziente attivo",
detail: "seq:5",
rationale: "scelta dal reviewer",
},
"Memoria salvata nel vectordb ma decisione memory_promoted NON registrata: " +
"recupero manuale (umano) con tht decision add --session s1 " +
"--type memory_promoted --subject \"paziente attivo\" --detail seq:5.",
],
[
"ledger",
"s1",
{
type: "memory_promotion_declined",
subject: "ricovero indice",
detail: "seq:7",
},
"",
],
[
"close",
8,
"Promozione registrata: 1 memorie salvate nel vectordb, 1 candidati scartati.",
],
]);
assert.match(result.content[0].text, /1 memorie salvate.*1 candidati scartati/);
}
test("a mismatched review identity cannot mutate Memory", async () => {
const { calls, run } = setup({ response: { text: JSON.stringify({ summary_id: "old", items: [] }) } });
assert.match((await run()).content[0].text, /Invalid/);
assert.equal(calls.length, 1);
});
test("review is only presented at F8", async () => {
const { calls, run } = setup({ phase: 7 });
assert.match((await run()).content[0].text, /end of F8/);
assert.equal(calls.length, 0);
});
test("a persistence failure prevents the review marker and closing", async () => {
const { calls, run } = setup({ failure: "database unavailable",
response: { text: JSON.stringify({ summary_id: "summary", items: [] }) } });
assert.equal(await run(), "database unavailable");
assert.deepEqual(calls.map(call => call[0]), ["widget", "save"]);
});
@@ -117,6 +117,18 @@ test("the Memory facade normalizes search hits and applies only the selected F2
assert.match(result.content[0].text, /1 decisioni.*La fase resta aperta/s);
});
test("authoritative UUID card identities survive normalization into the reviewer widget", async () => {
const { ctx, memoryGate, descriptor } = setupRecall(["first"]);
const id = "mem-11111111-1111-4111-8111-111111111111";
await memoryGate.reviewRecall(ctx, {
session: "s1", title: "Memory", allow_empty: true, advance: false,
options: [{ ...MEMORY_OPTIONS[0], decision: {
...MEMORY_OPTIONS[0].decision, rationale: `Riusa ${id}`,
} }],
}, "F2");
assert.equal(descriptor().options[0].meta.memory_id, id);
});
test("the Memory facade accepts a deselected F2 result without a rejection", async () => {
const { ctx, calls, memoryGate } = setupRecall([]);
@@ -25,7 +25,7 @@ echo "$@" >> "${log}"
case "$1 $2" in
"phase show") echo "Fase corrente: ${phase}";;
"phase meta") echo '{"max_phase":8,"phases":[{"num":2,"id":"F2","emits":[]},{"num":8,"id":"F8","emits":[]}]}';;
"memory promote") echo "[]";;
"memory summary") echo '{"summary_id":"saved-review","reviewed":true}';;
"session show") echo '{"status":"${status}"}';;
*) echo "OK";;
esac
@@ -52,7 +52,7 @@ async function runPromote(t, { phase }) {
return { res, calls: fake.calls() };
}
test("F8 + zero candidati: il gate avanza la fase e finalizza da solo", async (t) => {
test("F8 recupera un riepilogo già salvato e finalizza da solo", async (t) => {
const { res, calls } = await runPromote(t, { phase: 8 });
const text = res.content[0].text;
assert.match(text, /sessione finalizzata \(s1\)/);
@@ -63,7 +63,7 @@ test("F8 + zero candidati: il gate avanza la fase e finalizza da solo", async (t
test("fuori dall'ultima fase non chiude nulla (comportamento precedente)", async (t) => {
const { res, calls } = await runPromote(t, { phase: 2 });
assert.match(res.content[0].text, /prosegui con la chiusura della sessione/);
assert.match(res.content[0].text, /end of F8/);
assert.doesNotMatch(calls, /phase advance/);
assert.doesNotMatch(calls, /session finalize/);
});
@@ -33,12 +33,12 @@ const PHASE_META = JSON.stringify({
num: 8,
id: "F8",
name: "datamart",
emits: ["datamart_declined", "memory_promoted", "memory_promotion_declined"],
emits: ["datamart_declined", "memory_summary_reviewed"],
},
],
});
function useShell({ phase, preview = [], fail = () => null }) {
function useShell({ phase, preview = [], fail = () => null, indexed = true, reviewed = false }) {
const calls = [];
shell.current = (_file, args, options = {}) => {
calls.push({ args: [...args], input: options.input });
@@ -51,7 +51,8 @@ function useShell({ phase, preview = [], fail = () => null }) {
}
if (sameArgs(args, ["phase", "meta", "--json"])) return PHASE_META;
if (startsWithArgs(args, ["phase", "show", "--session"])) return `Fase corrente: ${phase}\n`;
if (startsWithArgs(args, ["memory", "promote", "--session"])) return JSON.stringify(preview);
if (startsWithArgs(args, ["memory", "summary", "--session"])) return JSON.stringify({ summary_id: "summary-1", items: preview, reviewed });
if (startsWithArgs(args, ["memory", "review-apply"])) return JSON.stringify({ indexed, saved: true });
return "";
};
return calls;
@@ -73,7 +74,7 @@ function mutationArgs(calls, prefixes) {
function memoryPromotionMutationArgs(calls) {
return mutationArgs(calls, [
["memory", "save-one"],
["memory", "review-apply"],
["decision", "add"],
["phase", "advance"],
["session", "finalize"],
@@ -511,144 +512,55 @@ test("F4 persists exactly the reviewer-selected Evidence disposition", async ()
});
const PROMOTION_CANDIDATE = {
decision_seq: 5,
type: "concept_clarified",
subject: "paziente attivo",
detail: "flag_attivo = TRUE",
rationale: "scelta dal reviewer",
question_context: "quanti pazienti attivi",
tables: [],
concepts: ["paziente attivo"],
id: "decision-5", card: { family: "domain_clarification", subject: "paziente attivo", detail: "flag_attivo = TRUE" },
};
test("F8 saves an accepted Memory before its ledger marker and finalizes", async () => {
const { ctx, tools, calls } = await setupGate({ phase: 8, preview: [PROMOTION_CANDIDATE] });
let descriptor;
answerNextWidget(ctx, ["seq-5"], (value) => { descriptor = value; });
const result = await tools.get("reviewer_memory_promote").def.execute(
"promote-accepted",
{ session: "s1" },
null,
null,
ctx,
);
assert.equal(descriptor.phase, "F8");
assert.equal(descriptor.widget, "multiselect");
assert.deepEqual(descriptor.selected, ["seq-5"]);
assert.match(descriptor.content, /flag_attivo = TRUE/);
const mutations = memoryPromotionMutationArgs(calls);
assert.deepEqual(mutations, [
["memory", "save-one", "--session", "s1", "--decision", "5", "--json"],
[
"decision", "add", "--session", "s1", "--type", "memory_promoted",
"--subject", "paziente attivo", "--detail", "seq:5",
"--rationale", "scelta dal reviewer",
],
["phase", "advance", "--session", "s1"],
["session", "finalize", "s1"],
]);
assert.match(result.content[0].text, /1 memorie salvate.*sessione finalizzata/s);
});
test("F8 records a declined candidate without saving it and finalizes", async () => {
const { ctx, tools, calls } = await setupGate({ phase: 8, preview: [PROMOTION_CANDIDATE] });
answerNextWidget(ctx, []);
const result = await tools.get("reviewer_memory_promote").def.execute(
"promote-declined",
{ session: "s1" },
null,
null,
ctx,
);
const mutations = memoryPromotionMutationArgs(calls);
assert.deepEqual(mutations, [
[
"decision", "add", "--session", "s1", "--type", "memory_promotion_declined",
"--subject", "paziente attivo", "--detail", "seq:5",
],
["phase", "advance", "--session", "s1"],
["session", "finalize", "s1"],
]);
assert.match(result.content[0].text, /1 candidati scartati.*sessione finalizzata/s);
});
test("F8 with no promotion candidates finalizes without showing a widget", async () => {
const { ctx, tools, calls } = await setupGate({ phase: 8, preview: [] });
ctx.ui.input = async () => { throw new Error("a promotion widget must not be shown"); };
const result = await tools.get("reviewer_memory_promote").def.execute(
"promote-absent",
{ session: "s1" },
null,
null,
ctx,
);
assert.equal(calls.some(({ args }) => startsWithArgs(args, ["memory", "save-one"])), false);
assert.equal(calls.some(({ args }) => startsWithArgs(args, ["decision", "add"])), false);
assert.deepEqual(
mutationArgs(calls, [["phase", "advance"], ["session", "finalize"]]),
[["phase", "advance", "--session", "s1"], ["session", "finalize", "s1"]],
);
assert.equal(ctx.notifications.length, 1);
assert.match(result.content[0].text, /Nessun candidato.*sessione finalizzata/s);
});
test("F8 does not write the ledger or finalize when the vector save fails", async () => {
const { ctx, tools, calls } = await setupGate({
phase: 8,
preview: [PROMOTION_CANDIDATE],
fail: (args) => startsWithArgs(args, ["memory", "save-one"])
? { status: 1, stderr: "vector save failed" }
: null,
function answerReview(ctx, items) {
ctx.ui.input = async title => {
const descriptor = JSON.parse(title);
assert.equal(descriptor.widget, "memory-review");
return JSON.stringify({ id: descriptor.id, text: JSON.stringify({
summary_id: descriptor.summary.summary_id, items,
}) });
};
}
for (const selected of [true, false]) {
test(`F8 persists the edited review (selected=${selected}) before its marker and finalization`, async () => {
const { ctx, tools, calls } = await setupGate({ phase: 8, preview: [PROMOTION_CANDIDATE] });
const items = selected ? [{ ...PROMOTION_CANDIDATE, card: { ...PROMOTION_CANDIDATE.card, detail: "Reviewer correction" } }] : [];
answerReview(ctx, items);
const result = await tools.get("reviewer_memory_promote").def.execute("review", { session: "s1" }, null, null, ctx);
const mutations = memoryPromotionMutationArgs(calls);
assert.deepEqual(mutations[0], ["memory", "review-apply", "--session", "s1", "--review-json",
JSON.stringify({ summary_id: "summary-1", items }), "--json"]);
assert(mutations[1].includes("memory_summary_reviewed"));
assert.deepEqual(mutations.slice(2), [["phase", "advance", "--session", "s1"], ["session", "finalize", "s1"]]);
assert.match(result.content[0].text, /sessione finalizzata/s);
});
answerNextWidget(ctx, ["seq-5"]);
const result = await tools.get("reviewer_memory_promote").def.execute(
"promote-save-failure",
{ session: "s1" },
null,
null,
ctx,
);
const mutations = memoryPromotionMutationArgs(calls);
assert.deepEqual(mutations, [
["memory", "save-one", "--session", "s1", "--decision", "5", "--json"],
]);
assert.match(result.content[0].text, /vector save failed.*Recupero manuale/s);
}
test("F8 warns about pending indexing but preserves the saved review and finalizes", async () => {
const { ctx, tools, calls } = await setupGate({ phase: 8, preview: [PROMOTION_CANDIDATE], indexed: false });
answerReview(ctx, [PROMOTION_CANDIDATE]);
await tools.get("reviewer_memory_promote").def.execute("pending", { session: "s1" }, null, null, ctx);
assert(ctx.notifications.some(({ message, level }) => level === "warning" && message.includes("Memory saved")));
assert(memoryPromotionMutationArgs(calls).some(args => args.includes("memory_summary_reviewed")));
});
test("F8 reports manual recovery and does not finalize after save succeeds but ledger fails", async () => {
const { ctx, tools, calls } = await setupGate({
phase: 8,
preview: [PROMOTION_CANDIDATE],
fail: (args) => args.includes("--type") && args.includes("memory_promoted")
? { status: 1, stderr: "promotion ledger failed" }
: null,
test("F8 recovers a saved review without asking again or saving cards again", async () => {
const { ctx, tools, calls } = await setupGate({ phase: 8, reviewed: true });
ctx.ui.input = async () => { throw new Error("review must not be shown twice"); };
await tools.get("reviewer_memory_promote").def.execute("recover", { session: "s1" }, null, null, ctx);
const mutations = memoryPromotionMutationArgs(calls);
assert.equal(mutations.length, 3);
assert(mutations[0].includes("memory_summary_reviewed"));
assert.deepEqual(mutations.at(-1), ["session", "finalize", "s1"]);
});
for (const failingStep of ["review-apply", "memory_summary_reviewed"]) {
test(`F8 stops after failure at ${failingStep} without finalizing`, async () => {
const { ctx, tools, calls } = await setupGate({ phase: 8, preview: [PROMOTION_CANDIDATE],
fail: args => args.includes(failingStep) ? { status: 1, stderr: "persistence unavailable" } : null });
answerReview(ctx, [PROMOTION_CANDIDATE]);
const result = await tools.get("reviewer_memory_promote").def.execute("fail", { session: "s1" }, null, null, ctx);
const mutations = memoryPromotionMutationArgs(calls);
assert.equal(mutations.length, failingStep === "review-apply" ? 1 : 2);
assert.match(result.content[0].text, /persistence unavailable/s);
});
answerNextWidget(ctx, ["seq-5"]);
const result = await tools.get("reviewer_memory_promote").def.execute(
"promote-ledger-failure",
{ session: "s1" },
null,
null,
ctx,
);
const mutations = memoryPromotionMutationArgs(calls);
assert.deepEqual(mutations, [
["memory", "save-one", "--session", "s1", "--decision", "5", "--json"],
[
"decision", "add", "--session", "s1", "--type", "memory_promoted",
"--subject", "paziente attivo", "--detail", "seq:5",
"--rationale", "scelta dal reviewer",
],
]);
assert.match(result.content[0].text, /vectordb.*NON registrata.*recupero manuale/is);
});
}
@@ -150,6 +150,36 @@
"properties": { "session": { "type": "string" } }
}
},
{
"name": "reviewer_archive_repair",
"parameters": {
"type": "object",
"required": ["session"],
"properties": {
"session": { "type": "string" },
"repair_id": { "type": "string" },
"proposal": {
"type": "object", "required": ["reason", "options"],
"properties": {
"reason": { "type": "string" },
"options": {
"type": "array", "minItems": 1, "maxItems": 5,
"items": {
"type": "object",
"required": ["id", "label", "archive", "target_id", "revision", "content"],
"properties": {
"id": { "type": "string" }, "label": { "type": "string" },
"archive": { "anyOf": [{ "const": "memory", "type": "string" }, { "const": "evidence", "type": "string" }] },
"target_id": { "type": "string" }, "revision": { "type": "string" },
"content": { "type": "object", "patternProperties": { "^.*$": {} } }
}
}
}
}
}
}
}
},
{
"name": "rewrite_question",
"parameters": {