diff --git a/.superpowers/sdd/2026-08-04-unified-compose-deployment/task-1-report.md b/.superpowers/sdd/2026-08-04-unified-compose-deployment/task-1-report.md deleted file mode 100644 index 789894bb..00000000 --- a/.superpowers/sdd/2026-08-04-unified-compose-deployment/task-1-report.md +++ /dev/null @@ -1,134 +0,0 @@ -# Task 1 — Deterministic line endings - -## Status - -Complete. The repository now declares the cross-platform line-ending policy, verifies it -against tracked files (or an explicit test fixture), and performs the Docker-script check before -their executable permissions are set in the core image. - -## Changed files - -- `.gitattributes` — required LF/CRLF Git normalization contract. -- `.editorconfig` — editor-side UTF-8, final-newline, LF default and PowerShell CRLF policy. -- `scripts/verify-line-endings.sh` — tracked-file/fixture CRLF verifier. -- `scripts/test-verify-line-endings.sh` — LF and CRLF fixture regression test. -- `docker/core.Dockerfile` — image build invokes the verifier on `/app/docker` before `chmod`. - -## Red / green evidence - -### RED - -`bash scripts/test-verify-line-endings.sh` exited 1 before the verifier existed. Its final -assertion output was `missing CRLF path: bad.sh`; the test had captured the underlying attempt to -run the absent verifier, so no CRLF paths could be reported. This confirmed the test was exercising -the missing implementation rather than passing spuriously. - -### GREEN - -After implementing the verifier and setting its executable mode: - -```text -$ bash scripts/test-verify-line-endings.sh -line-ending verifier tests passed -``` - -The test confirms that `bad.sh`, `compose.yaml`, and `Dockerfile` are all reported for CRLF, that -the LF-only `ok.sh` is absent from the report, and that converting every fixture file to LF returns -0. - -## Commands and output summary - -| Command | Result | -| --- | --- | -| `bash scripts/test-verify-line-endings.sh` (before implementation) | Exit 1 (expected RED). | -| `chmod +x scripts/verify-line-endings.sh scripts/test-verify-line-endings.sh` | Set executable modes for both shell interfaces. | -| `bash scripts/test-verify-line-endings.sh` | Passed: `line-ending verifier tests passed`. | -| `bash scripts/verify-line-endings.sh` | Passed (exit 0) against tracked repository files. | -| `bash -n scripts/verify-line-endings.sh scripts/test-verify-line-endings.sh` | Passed. | -| `git add --renormalize .` | Completed; no existing tracked files required line-ending-only normalization. | -| `git check-attr text eol -- ...` | Confirmed LF attributes for `.sh`, Dockerfile, YAML, TypeScript, Python, and JSON examples. | -| `git diff --check` and `git diff --cached --check` | Passed. | - -## Renormalization review - -After `git add --renormalize .`, the staged diff contained only the intentional -`docker/core.Dockerfile` change (3 insertions, 1 deletion). There were no unrelated or -line-ending-only changes to review. New, untracked Task 1 files were then added explicitly. - -## Self-review - -- Default mode uses `git ls-files`, so it inspects only tracked repository content and avoids - untracked secrets and mounted volumes. -- Explicit-root mode is reserved for the isolated test fixture and uses `find`, as required. -- Detection uses `LC_ALL=C grep -Il $'\r'`; violations are printed as paths relative to the - selected root and return exit 1. -- The Dockerfile runs the verifier immediately after copying Docker scripts and before `chmod`. -- The exact `.gitattributes` contract from the task brief is present verbatim. - -## Commit - -Task implementation: `ad07a75` (`build: enforce portable line endings`) - -## Concerns - -None. The prescribed verifier and repository-integrity checks pass. A full Docker image build was -not run because this task's required validation is the shell verifier suite; the Dockerfile change -is structurally covered by the reviewed build instruction ordering. - -## Fix round 1 — PowerShell CRLF policy - -### Status - -Complete. The verifier now applies the `.gitattributes` PowerShell exception: `*.ps1` files may -use CRLF, while CRLF remains a violation for the shell, YAML, and Dockerfile fixture inputs. - -### Changed files - -- `scripts/verify-line-endings.sh` — skips `.ps1` files before the CRLF rejection check. -- `scripts/test-verify-line-endings.sh` — adds a CRLF `valid.ps1` fixture and asserts it is not - reported; the fixture remains CRLF during the succeeding final verifier invocation. - -### Red / green evidence - -#### RED - -Before the verifier change: - -```text -$ bash scripts/test-verify-line-endings.sh -reported compliant CRLF PowerShell path: valid.ps1 -``` - -The failure proves the new regression test exercised the existing incorrect behavior. - -#### GREEN - -After adding the `.ps1` exception: - -```text -$ bash scripts/test-verify-line-endings.sh -line-ending verifier tests passed -``` - -The existing assertions still require `bad.sh`, `compose.yaml`, and `Dockerfile` to be reported, -while `valid.ps1` is rejected only if it is incorrectly reported. The final fixture verification -passes with `valid.ps1` still in CRLF form. - -### Command and output summary - -| Command | Result | -| --- | --- | -| `bash scripts/test-verify-line-endings.sh` (before change) | Exit 1: `reported compliant CRLF PowerShell path: valid.ps1`. | -| `bash scripts/test-verify-line-endings.sh` | Passed: `line-ending verifier tests passed`. | -| `bash scripts/verify-line-endings.sh` | Passed (exit 0; no output) for tracked repository files. | -| `git diff --check` | Passed (exit 0; no output). | - -### Scope and self-review - -The change is limited to the Important finding. It matches the existing lowercase `*.ps1` -pattern in `.gitattributes`, leaves the CRLF detection for every other file untouched, and does -not address either deferred Minor finding. - -### Concerns - -None. diff --git a/.superpowers/sdd/2026-08-04-unified-compose-deployment/task-2-report.md b/.superpowers/sdd/2026-08-04-unified-compose-deployment/task-2-report.md deleted file mode 100644 index 2f2b0ffc..00000000 --- a/.superpowers/sdd/2026-08-04-unified-compose-deployment/task-2-report.md +++ /dev/null @@ -1,147 +0,0 @@ -# Task 2 report — portable Compose contract - -## Status - -Completed. The root Compose file is now a portable two-service base, with explicit local and -server overrides. Workspace-registry configuration remains generic and continues to require an -installation-provided Git remote. - -## Changed files - -- `.env.example` — shared non-secret, generic endpoint and registry examples. -- `compose.yaml` — portable `core` and `frontend` base, owned `thothii` network, health checks, - named settings/Pi/registry/session volumes, and generic external endpoint variables. -- `deploy/compose.local.yaml` — loopback core/frontend ports, `AUTH_MODE=none`, local - installation identity, and non-persistent restart policy. -- `deploy/compose.server.yaml` — frontend-only configurable host bind, `AUTH_MODE=upstream`, - server identity, host-root data/Pi/registry mounts, and restart policy. -- `deploy/env/local.env.example` and `deploy/env/server.env.example` — safe profile-specific - values using `.example.invalid` documentation domains. -- `scripts/test-default-compose.sh` — default local portable Compose assertion. -- `scripts/test-unified-compose.sh` — JSON structural assertions for base/local/server plus the - required missing-remote failure checks. - -## RED evidence - -Before changing Compose, `bash scripts/test-unified-compose.sh` exited 1 with: - -```text -Error: forbidden application coupling -``` - -The failure was raised by the required assertion while the rendered root config still contained -the portal-specific networks and host paths. - -## GREEN evidence - -The following fresh commands completed with exit status 0: - -```text -bash scripts/test-default-compose.sh -# default Compose contract passed. - -bash scripts/test-unified-compose.sh -# unified Compose contract passed. - -bash -lc 'set -a; source deploy/env/local.env.example; set +a; docker compose -f compose.yaml -f deploy/compose.local.yaml config --quiet' - -bash -lc 'set -a; source deploy/env/server.env.example; set +a; docker compose -f compose.yaml -f deploy/compose.server.yaml config --quiet' - -bash scripts/verify-line-endings.sh -git diff --check -``` - -The two `config --quiet` invocations source only their non-secret profile example so the requested -commands can validate the required Git-remote interpolation without an operator `.env` file. - -## Self-review - -- The base renders exactly `core` and `frontend`; it has no portal, Chirone, local-LLM-network, or - host-path coupling. -- Local publishing is loopback-only; server has no core host port and publishes the frontend bind. -- The core retains outbound access for configured external DWH, vector, Git, embedding, and LLM - endpoints; the owned Compose network is private to this stack but is not marked Docker-internal. -- The structural test validates the exact required service assertion, forbidden-coupling assertion, - required base network/volumes, profile port policy, and `THT_WORKSPACE_GIT_REMOTE` failure. -- All new YAML and shell files were checked by the repository line-ending verifier. - -## Commit - -`2595d35682a5200b877acb71764b4eb195a39ea4` — `deploy: unify local and server compose stack` - -## Concerns - -None for Task 2. Git and connector secret transport remains intentionally outside this base/profile -contract and is addressed by the next scoped task. - ---- - -## Fix round 1/5 — Pi auth mount and generic LLM endpoint - -### Status - -Completed. Pi’s mutable state remains writable, while provider authentication is supplied only by -the deterministic `PI_AUTH_FILE` host-file contract mounted read-only at Pi’s canonical -`/home/thoth/.pi/agent/auth.json` path. The base now exposes the generic `THT_LLM_URL` contract; -the local and server examples set only documentation endpoint values. - -### Changed files - -- `compose.yaml` — adds `THT_LLM_URL` and a read-only `PI_AUTH_FILE` bind while retaining the - writable `pi-state` volume for non-secret runtime state. -- `deploy/compose.server.yaml` — retains the auth-file bind when its storage mounts override the - portable base. -- `.env.example`, `deploy/env/local.env.example`, and `deploy/env/server.env.example` — document - the generic `https://llm.example.invalid` endpoint; profile examples also document the required - host auth-file path without including a secret. -- `scripts/test-unified-compose.sh` — asserts generic LLM contract presence, no Docker - socket/daemon mount, and exactly one read-only Pi auth file bind in the base and both profiles. - -### RED evidence - -Before the Compose changes, this command exited 1: - -```text -bash scripts/test-unified-compose.sh - -Error: core must expose a generic THT_LLM_URL endpoint contract -``` - -The failure was raised by the new structural assertion against the previous rendered base. - -### GREEN evidence - -The following focused commands completed with exit status 0 after the fix: - -```text -bash scripts/test-unified-compose.sh -# unified Compose contract passed. - -bash scripts/test-default-compose.sh -# default Compose contract passed. - -docker compose --env-file deploy/env/local.env.example -f compose.yaml -f deploy/compose.local.yaml config --quiet - -docker compose --env-file deploy/env/server.env.example -f compose.yaml -f deploy/compose.server.yaml config --quiet - -bash scripts/verify-line-endings.sh -git diff --check -``` - -### Self-review - -- Both rendered profile contracts carry a single `bind` mount to the Pi `auth.json` file with - `read_only: true`; no auth value appears in Compose or the environment examples. -- The writable Pi-state mount does not replace the read-only auth file, and the server override - explicitly retains that file bind after replacing the base storage list. -- The structural regression test rejects any Docker socket/daemon mount and validates the generic - LLM endpoint contract without adding provider-specific endpoints or hostnames. -- The deferred Minor report-wording finding was not changed. - -### Commit - -`2ce2e0089a66ca508db041a71db9807f66d0bf24` — `fix: harden compose Pi auth mounts` - -### Concerns - -None for this focused round.