feat: implement memory and evidence administration with guided repairs
Publish documentation / publish (push) Successful in 1m27s

Add PostgreSQL-backed memory, editable evidence with source review and activation, and human-approved archive repairs across the harness, API, and UI. Include migrations, deployment support, regression coverage, and validation documentation.

Refresh permissions from validated session roles so existing administrator logins can access newly deployed archive management features.
This commit is contained in:
Codex
2026-09-10 10:31:34 +02:00
parent 8fe526dd6e
commit 82e2c91f42
168 changed files with 11914 additions and 1772 deletions
@@ -0,0 +1,37 @@
# Resolve a conflict in the shared archives
Use this gate when the retrieved Memory and Evidence disagree and the reviewer
must decide which archive to correct. State the conflict, its effect on the current
question, and the concrete alternative corrections. Each choice replaces one existing
Memory Card or one Evidence unit; offer only changes that resolve the stated conflict.
1. Read the complete current target and revision through
`tht memory repair-target --session <id> --archive memory|evidence --target-id <id> --json`.
Keep all content fields that the proposed correction does not change. An Evidence
correction retains its identity, kind and original source history. Evidence must
already be consolidated; external file edits must be reconciled first.
2. Call `reviewer_archive_repair` with `session` and `proposal`:
`{reason, options:[{id,label,archive,target_id,revision,content}]}`.
`content` is the complete resulting card or Evidence unit. Use one to five distinct
choice IDs, excluding the reserved `reject` and `continue`. The gate loads the current
content itself and shows both versions. The human selects the archive correction.
3. A rejection means every proposal was inadequate. Reformulate the choices using the
reviewer's feedback and present a new proposal. No archive mutation follows rejection.
A non-administrator can reject or continue the question; shared corrections require
an administrator. Do not disguise a shared correction as a final-summary promotion.
4. The result distinguishes `active`, `pending_activation`, `applying`, and `superseded`.
`saved` alone does not establish retrieval availability. The gate offers retry of
the same approved correction after an index failure. A newer archive edit requires
reconciliation and a new proposal; replay never overwrites that edit.
5. After interruption, run `tht memory repairs --session <id> --json`, then call
`reviewer_archive_repair` with `session` and `repair_id`. This refreshes current
archive status. The list's `recorded_status` is historical. Resume the existing
receipt for recovery instead of proposing the already-saved correction again.
6. Continue the ordinary clarification/schema/SQL gate for the current question,
carrying the chosen meaning and the reported archive status. Archive repair does
not advance a phase. If activation remains pending, report that explicitly.
The extension alone invokes `repair-apply` after the human response. Model-authored
shell commands may prepare or inspect proposals, but cannot apply them. Correction
receipts, like phase artifacts, persist independently of the live chat. Git remains
an operator action after reviewing the Evidence file diff.