chore: untrack sdd reports

This commit is contained in:
2026-08-04 14:58:26 +02:00
parent 01633be8f6
commit ff271d3cce
2 changed files with 0 additions and 281 deletions
@@ -1,134 +0,0 @@
# Task 1 — Deterministic line endings
## Status
Complete. The repository now declares the cross-platform line-ending policy, verifies it
against tracked files (or an explicit test fixture), and performs the Docker-script check before
their executable permissions are set in the core image.
## Changed files
- `.gitattributes` — required LF/CRLF Git normalization contract.
- `.editorconfig` — editor-side UTF-8, final-newline, LF default and PowerShell CRLF policy.
- `scripts/verify-line-endings.sh` — tracked-file/fixture CRLF verifier.
- `scripts/test-verify-line-endings.sh` — LF and CRLF fixture regression test.
- `docker/core.Dockerfile` — image build invokes the verifier on `/app/docker` before `chmod`.
## Red / green evidence
### RED
`bash scripts/test-verify-line-endings.sh` exited 1 before the verifier existed. Its final
assertion output was `missing CRLF path: bad.sh`; the test had captured the underlying attempt to
run the absent verifier, so no CRLF paths could be reported. This confirmed the test was exercising
the missing implementation rather than passing spuriously.
### GREEN
After implementing the verifier and setting its executable mode:
```text
$ bash scripts/test-verify-line-endings.sh
line-ending verifier tests passed
```
The test confirms that `bad.sh`, `compose.yaml`, and `Dockerfile` are all reported for CRLF, that
the LF-only `ok.sh` is absent from the report, and that converting every fixture file to LF returns
0.
## Commands and output summary
| Command | Result |
| --- | --- |
| `bash scripts/test-verify-line-endings.sh` (before implementation) | Exit 1 (expected RED). |
| `chmod +x scripts/verify-line-endings.sh scripts/test-verify-line-endings.sh` | Set executable modes for both shell interfaces. |
| `bash scripts/test-verify-line-endings.sh` | Passed: `line-ending verifier tests passed`. |
| `bash scripts/verify-line-endings.sh` | Passed (exit 0) against tracked repository files. |
| `bash -n scripts/verify-line-endings.sh scripts/test-verify-line-endings.sh` | Passed. |
| `git add --renormalize .` | Completed; no existing tracked files required line-ending-only normalization. |
| `git check-attr text eol -- ...` | Confirmed LF attributes for `.sh`, Dockerfile, YAML, TypeScript, Python, and JSON examples. |
| `git diff --check` and `git diff --cached --check` | Passed. |
## Renormalization review
After `git add --renormalize .`, the staged diff contained only the intentional
`docker/core.Dockerfile` change (3 insertions, 1 deletion). There were no unrelated or
line-ending-only changes to review. New, untracked Task 1 files were then added explicitly.
## Self-review
- Default mode uses `git ls-files`, so it inspects only tracked repository content and avoids
untracked secrets and mounted volumes.
- Explicit-root mode is reserved for the isolated test fixture and uses `find`, as required.
- Detection uses `LC_ALL=C grep -Il $'\r'`; violations are printed as paths relative to the
selected root and return exit 1.
- The Dockerfile runs the verifier immediately after copying Docker scripts and before `chmod`.
- The exact `.gitattributes` contract from the task brief is present verbatim.
## Commit
Task implementation: `ad07a75` (`build: enforce portable line endings`)
## Concerns
None. The prescribed verifier and repository-integrity checks pass. A full Docker image build was
not run because this task's required validation is the shell verifier suite; the Dockerfile change
is structurally covered by the reviewed build instruction ordering.
## Fix round 1 — PowerShell CRLF policy
### Status
Complete. The verifier now applies the `.gitattributes` PowerShell exception: `*.ps1` files may
use CRLF, while CRLF remains a violation for the shell, YAML, and Dockerfile fixture inputs.
### Changed files
- `scripts/verify-line-endings.sh` — skips `.ps1` files before the CRLF rejection check.
- `scripts/test-verify-line-endings.sh` — adds a CRLF `valid.ps1` fixture and asserts it is not
reported; the fixture remains CRLF during the succeeding final verifier invocation.
### Red / green evidence
#### RED
Before the verifier change:
```text
$ bash scripts/test-verify-line-endings.sh
reported compliant CRLF PowerShell path: valid.ps1
```
The failure proves the new regression test exercised the existing incorrect behavior.
#### GREEN
After adding the `.ps1` exception:
```text
$ bash scripts/test-verify-line-endings.sh
line-ending verifier tests passed
```
The existing assertions still require `bad.sh`, `compose.yaml`, and `Dockerfile` to be reported,
while `valid.ps1` is rejected only if it is incorrectly reported. The final fixture verification
passes with `valid.ps1` still in CRLF form.
### Command and output summary
| Command | Result |
| --- | --- |
| `bash scripts/test-verify-line-endings.sh` (before change) | Exit 1: `reported compliant CRLF PowerShell path: valid.ps1`. |
| `bash scripts/test-verify-line-endings.sh` | Passed: `line-ending verifier tests passed`. |
| `bash scripts/verify-line-endings.sh` | Passed (exit 0; no output) for tracked repository files. |
| `git diff --check` | Passed (exit 0; no output). |
### Scope and self-review
The change is limited to the Important finding. It matches the existing lowercase `*.ps1`
pattern in `.gitattributes`, leaves the CRLF detection for every other file untouched, and does
not address either deferred Minor finding.
### Concerns
None.
@@ -1,147 +0,0 @@
# Task 2 report — portable Compose contract
## Status
Completed. The root Compose file is now a portable two-service base, with explicit local and
server overrides. Workspace-registry configuration remains generic and continues to require an
installation-provided Git remote.
## Changed files
- `.env.example` — shared non-secret, generic endpoint and registry examples.
- `compose.yaml` — portable `core` and `frontend` base, owned `thothii` network, health checks,
named settings/Pi/registry/session volumes, and generic external endpoint variables.
- `deploy/compose.local.yaml` — loopback core/frontend ports, `AUTH_MODE=none`, local
installation identity, and non-persistent restart policy.
- `deploy/compose.server.yaml` — frontend-only configurable host bind, `AUTH_MODE=upstream`,
server identity, host-root data/Pi/registry mounts, and restart policy.
- `deploy/env/local.env.example` and `deploy/env/server.env.example` — safe profile-specific
values using `.example.invalid` documentation domains.
- `scripts/test-default-compose.sh` — default local portable Compose assertion.
- `scripts/test-unified-compose.sh` — JSON structural assertions for base/local/server plus the
required missing-remote failure checks.
## RED evidence
Before changing Compose, `bash scripts/test-unified-compose.sh` exited 1 with:
```text
Error: forbidden application coupling
```
The failure was raised by the required assertion while the rendered root config still contained
the portal-specific networks and host paths.
## GREEN evidence
The following fresh commands completed with exit status 0:
```text
bash scripts/test-default-compose.sh
# default Compose contract passed.
bash scripts/test-unified-compose.sh
# unified Compose contract passed.
bash -lc 'set -a; source deploy/env/local.env.example; set +a; docker compose -f compose.yaml -f deploy/compose.local.yaml config --quiet'
bash -lc 'set -a; source deploy/env/server.env.example; set +a; docker compose -f compose.yaml -f deploy/compose.server.yaml config --quiet'
bash scripts/verify-line-endings.sh
git diff --check
```
The two `config --quiet` invocations source only their non-secret profile example so the requested
commands can validate the required Git-remote interpolation without an operator `.env` file.
## Self-review
- The base renders exactly `core` and `frontend`; it has no portal, Chirone, local-LLM-network, or
host-path coupling.
- Local publishing is loopback-only; server has no core host port and publishes the frontend bind.
- The core retains outbound access for configured external DWH, vector, Git, embedding, and LLM
endpoints; the owned Compose network is private to this stack but is not marked Docker-internal.
- The structural test validates the exact required service assertion, forbidden-coupling assertion,
required base network/volumes, profile port policy, and `THT_WORKSPACE_GIT_REMOTE` failure.
- All new YAML and shell files were checked by the repository line-ending verifier.
## Commit
`2595d35682a5200b877acb71764b4eb195a39ea4` — `deploy: unify local and server compose stack`
## Concerns
None for Task 2. Git and connector secret transport remains intentionally outside this base/profile
contract and is addressed by the next scoped task.
---
## Fix round 1/5 — Pi auth mount and generic LLM endpoint
### Status
Completed. Pi’s mutable state remains writable, while provider authentication is supplied only by
the deterministic `PI_AUTH_FILE` host-file contract mounted read-only at Pi’s canonical
`/home/thoth/.pi/agent/auth.json` path. The base now exposes the generic `THT_LLM_URL` contract;
the local and server examples set only documentation endpoint values.
### Changed files
- `compose.yaml` — adds `THT_LLM_URL` and a read-only `PI_AUTH_FILE` bind while retaining the
writable `pi-state` volume for non-secret runtime state.
- `deploy/compose.server.yaml` — retains the auth-file bind when its storage mounts override the
portable base.
- `.env.example`, `deploy/env/local.env.example`, and `deploy/env/server.env.example` — document
the generic `https://llm.example.invalid` endpoint; profile examples also document the required
host auth-file path without including a secret.
- `scripts/test-unified-compose.sh` — asserts generic LLM contract presence, no Docker
socket/daemon mount, and exactly one read-only Pi auth file bind in the base and both profiles.
### RED evidence
Before the Compose changes, this command exited 1:
```text
bash scripts/test-unified-compose.sh
Error: core must expose a generic THT_LLM_URL endpoint contract
```
The failure was raised by the new structural assertion against the previous rendered base.
### GREEN evidence
The following focused commands completed with exit status 0 after the fix:
```text
bash scripts/test-unified-compose.sh
# unified Compose contract passed.
bash scripts/test-default-compose.sh
# default Compose contract passed.
docker compose --env-file deploy/env/local.env.example -f compose.yaml -f deploy/compose.local.yaml config --quiet
docker compose --env-file deploy/env/server.env.example -f compose.yaml -f deploy/compose.server.yaml config --quiet
bash scripts/verify-line-endings.sh
git diff --check
```
### Self-review
- Both rendered profile contracts carry a single `bind` mount to the Pi `auth.json` file with
`read_only: true`; no auth value appears in Compose or the environment examples.
- The writable Pi-state mount does not replace the read-only auth file, and the server override
explicitly retains that file bind after replacing the base storage list.
- The structural regression test rejects any Docker socket/daemon mount and validates the generic
LLM endpoint contract without adding provider-specific endpoints or hostnames.
- The deferred Minor report-wording finding was not changed.
### Commit
`2ce2e0089a66ca508db041a71db9807f66d0bf24` — `fix: harden compose Pi auth mounts`
### Concerns
None for this focused round.