Commit Graph
252 Commits
Author SHA1 Message Date
marcopan 2c4534d968 fix: close internal semantic review gaps 2026-08-08 23:27:58 +02:00
marcopan 43d8063922 fix: scope workspace registry smoke cleanup 2026-08-08 22:32:57 +02:00
marcopan 4e810af516 test: align qdrant ollama verification fixtures 2026-08-08 22:15:02 +02:00
marcopan ffe0afb6a7 test: restore taskdoc truncation regression 2026-08-08 21:50:25 +02:00
marcopan 569bb7f1db fix: remove dead vector migrate command 2026-08-08 21:45:16 +02:00
marcopan 8826f8ac6b refactor: remove pgvector runtime 2026-08-08 21:38:03 +02:00
marcopan 8f4ec1e1a3 fix: tighten internal semantic compose contracts 2026-08-08 18:47:22 +02:00
marcopan ca1511df60 test: cover qdrant delete-kinds scoping 2026-08-08 18:25:28 +02:00
marcopan 820b237239 fix: remove http delete-kinds regression 2026-08-08 18:21:20 +02:00
marcopan 32cd2165eb fix: support qdrant-only vector maintenance 2026-08-08 18:14:03 +02:00
marcopan 5e39cfa347 feat: index semantic records in qdrant 2026-08-08 18:03:57 +02:00
marcopan f61648fb69 fix: harden qdrant payload and paging 2026-08-08 17:48:56 +02:00
marcopan 7109ee15c4 feat: add qdrant vector adapter 2026-08-08 17:43:15 +02:00
marcopan c875fa52ce fix: enforce internal embeddings contract 2026-08-08 17:33:19 +02:00
marcopan 2911e008d1 feat: use internal ollama embeddings 2026-08-08 17:29:36 +02:00
marcopan b93f13e39e fix: stabilize runtime workspace identity 2026-08-05 16:39:23 +02:00
marcopan bd798b1c96 fix: render registry workspaces for harness 2026-08-05 16:03:45 +02:00
marcopan 09834d5cd4 fix: close deployment decoupling review 2026-08-05 07:52:32 +02:00
marcopan 5d037e97c4 refactor: remove portal deployment coupling 2026-08-05 06:58:19 +02:00
marcopan 8b046f9fb2 test: verify portable workspace registry end to end 2026-08-04 08:42:33 +02:00
marcopan 90894176b6 feat: pin sessions to workspace revisions 2026-08-04 04:52:06 +02:00
marcopan 18233d59af fix: refine session report and live activity layout 2026-07-24 00:21:36 +02:00
marcopan 2e1bb621a0 fix: exclude schema tables from session memories 2026-07-23 15:54:27 +02:00
marcopan 0db85e4e4e feat: redesign persisted session summaries 2026-07-23 15:35:31 +02:00
marcopan 694b7dd21f fix: harden reviewer workflow and memory handling 2026-07-23 12:34:23 +02:00
marcopan 2ff63d371f feat: harden workflow gates and expose token usage 2026-07-21 12:14:26 +02:00
marcopan 8aa1676811 Expose PSD frontend locally 2026-07-20 20:27:37 +02:00
marcopan ad6057f0dd Fix PSD frontend network wiring 2026-07-20 20:26:13 +02:00
marcopan 0cf09777f2 Fix session resume and PSD container configuration 2026-07-20 20:22:47 +02:00
marcopan ec9b12dff4 fix(harness): recover schema table name typos 2026-07-20 17:53:24 +02:00
marcopanandClaude Fable 5 83942c0b5c feat(harness): F6/F7 close on their last approval — no echo phase gate
Where completeness is machine-detectable, the reviewer's last substantive
approval now closes the phase itself (same pattern as F3/F4/F8):

- F6: approving the LAST CTE of the plan (kind:"cte_result" with next_cte
  now empty) advances the phase; a non-final CTE keeps the phase open and
  names the next one.
- F7: kind:"sql" records sql_approved — which IS F7's only advance
  prerequisite — and advances immediately.

Two reviewer interactions per session removed, both pure echoes. The
summary phase gate remains only where completeness is a human judgment
(F1, F2 with recorded memories, F5). SKILL.md states the rule and the
five self-closing gates; L1 tests cover last/non-last CTE and sql close.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 02:23:45 +02:00
marcopanandClaude Fable 5 c4951e2aa5 chore: hygiene pass — ruff clean, docs storage-model truth, replay /me, failSession log
Audit findings 6.1-6.4 + the audit's remediation plan itself
(docs/superpowers/plans/2026-07-20-full-audit-remediation-plan.md).

- ruff: 34 → 0 (unused imports/f-strings auto-fixed; E702 semicolon lines
  split in test files; one unused local dropped). Suite still 819 green.
- CLAUDE.md + PROJECT_STATE.md no longer claim "no database / settings in
  settings.json": the harness selects filesystem OR PostgreSQL session
  storage (repository.py, server mode), and settings flow through harness
  preferences with the JSON file as fallback only.
- tools/replay: stub /me (SPA boot was parsing the SPA's own HTML as JSON)
  and /runtime/prewarm.
- failSession best-effort persistence now logs its failure server-side
  instead of vanishing.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 01:55:41 +02:00
marcopanandClaude Fable 5 1ab0015460 fix(harness): state-integrity pass — reopen order, atomic decision batch, bash anti-bypass
Audit findings 5.1-5.3.

5.1 `phase reopen` now appends `phase_reopened` BEFORE the artifact
teardown: a crash between the two used to leave later-phase artifacts
deleted with the ledger still at the old phase (resume entered a phase
missing its artifacts). The inverse half-state — reopened with stale later
artifacts — is benign. Order locked by tests/test_phase_reopen_order.py.

5.2 New `tht decision add-batch --doc -`: N substantive decisions in ONE
atomic ledger write (meta types and cte_approved stay on `decision add`;
strictest min-phase enforced). reviewer_schema_linking now builds the
complete curation set and persists it with a single add-batch call — a
mid-loop failure can no longer leave the audit ledger half-written, and a
retry cannot duplicate the first K decisions.

5.3 The anti-bypass hook now also blocks BASH mutations of protected
state (`echo >> review_decisions.jsonl`, `sed -i` on the manifest,
`cat > tht-gate.js`, python open('w'), mv/rm/tee/…): FORBIDDEN only
covered tht subcommands and the write/edit hook only covered pi's own
tools. Read-only access (cat/grep/tail/ls) stays allowed.

Also: knownDecisionTypes is defensive — a workflow meta declaring NO
emits at all (older tht, minimal stubs) skips pre-validation instead of
rejecting every substantive type; with emits present, unknown types are
still rejected before the widget (new L1 test).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 01:51:38 +02:00
marcopanandClaude Fable 5 3e072fe652 fix: realign workflow advance semantics and phase labels with workflow.yaml
Audit findings 2.1 + 2.2 (high).

2.1 WorkflowBar's static phase list was fiction from F2 on (F2 "Schema
linking" vs memoria, F4 "SQL plan" vs schema_linking, …): every live
session showed the wrong phase name. Both maps now mirror
harness/workflow.yaml (F1 chiarimento … F8 datamart).

2.2 forceAdvance (6ee5bda) let reviewer_decide advance:true bypass the
phase gate on ANY phase, contradicting SKILL.md's "auto-advance only
empty F2 / skipped F6". reviewer_decide is back on advanceIfReady (exit-6
no-op) and tells the model to close via reviewer_confirm; forceAdvance
stays only where selection IS the approval by design: reviewer_schema_linking
(F4) and the F8 promotion close path. SKILL.md now names the three
self-closing gates (F3 rewrite_question, F4 schema-linking advance:true,
F8 memory_promote) so gate and skill state one contract.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 01:28:18 +02:00
marcopanandClaude Fable 5 075883370e fix(harness): close the Pi-crash class — top-level try/catch on ALL gate tools
Audit finding 1.1 (high): reviewer_memory_promote, rewrite_question,
write_schema_linking, write_cte_sql and write_final_sql still ran execute
without a top-level catch — the same unhandled-rejection class that killed
Pi in reviewer_schema_linking (fixed in 87cb806 for the four reviewer_*
tools). All 9 registered tools now share the pattern: any uncaught throw
becomes a textResult the model can react to.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 01:26:27 +02:00
marcopanandClaude Opus 4.6 87cb806dfc fix(harness): prevent Pi crash on unhandled throw in reviewer tool execute
The last live session crashed during reviewer_schema_linking: an uncaught
exception (likely from execFileSync in currentPhase/phaseMeta or from
cat.columns being undefined) rejected the async execute() Promise. Pi does
not catch rejected tool Promises — Node.js treats them as unhandled
rejections and kills the process.

Fix:
- Wrap all four reviewer tool execute bodies (select/decide/confirm/
  schema_linking) in a top-level try/catch → returns a textResult on any
  unexpected error instead of crashing Pi.
- reviewer_schema_linking: defensively re-parse `tables` if still a string
  (belt-and-suspenders over prepareArguments), guard cat.columns before .map().

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-07-19 14:33:42 +02:00
marcopanandClaude Opus 4.6 6ee5bda7f0 feat: gate decision-type validation, force-advance, and frontend fixes
Gate (tht-gate.js):
- Pre-validate decision types against workflow.yaml before showing reviewer widget
- Reject decisions emitted by later phases (min-phase check)
- Copy top-level `kind` into artifact when model forgets it (prevents loop)
- Force-advance on reviewer_decide/schema_linking when advance:true — skip
  redundant reviewer_confirm gate

Backend:
- Emit agent_end on clean Pi exit (code 0 + bridge idle) instead of marking failed

Frontend:
- Strip <think> tags from transcript and activity panel
- Fix mermaid render with offscreen container + cleanup
- Graceful mermaid error: show source code instead of red error, fall back to table

Workflow:
- F2 now emits table_promoted and table_excluded (early schema linking decisions)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-07-19 14:14:44 +02:00
marcopanandClaude Opus 4.8 9fbca06f7c feat(harness): make tht schema columns glob/pattern-aware
At F4 (schema_linking) a model asking for a whole table family, e.g.
`fact_sost_impianto_*`, used to hit a bare "tabella non nel catalogo" and stall
without recovering. Now a pattern (containing * ? [) resolves to every matching
catalog table and returns their columns (JSON becomes an array of per-table
objects); exact names keep the original single-object contract. A non-glob miss
also suggests sibling tables sharing the leading segment, to aid recovery.

Verified live: `fact_sost_impianto_*` resolves the 20-table family on the psd
catalog. Harness suite green (811 passed).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-18 13:24:20 +02:00
User 5cacf70a0d fix: bootstrap user preferences without invalidating DWH cache 2026-07-16 20:32:20 +02:00
User ccb3cf4aa9 test: cover user-owned session security boundaries 2026-07-16 19:16:58 +02:00
User 458eb13c89 feat(backend): enforce user-owned sessions 2026-07-16 18:32:52 +02:00
User 72db6b823d fix(harness): record postgres decision phases 2026-07-16 18:08:17 +02:00
User c1cddaa667 refactor(harness): route workflow persistence through repositories 2026-07-16 18:01:29 +02:00
User 259f021313 fix(harness): preserve session migration JSON errors 2026-07-16 17:35:54 +02:00
User 5dbb91390f feat(harness): persist server sessions in postgres 2026-07-16 17:31:04 +02:00
User 8f0154eb9e fix(harness): persist evidence artifact 2026-07-16 17:14:47 +02:00
User 8f364ec564 feat(harness): add local session repository 2026-07-16 17:11:22 +02:00
User 9d4e057426 fix: serialize decision ledger writes 2026-07-14 15:30:06 +02:00
User 333874a755 fix: make join approval atomic 2026-07-14 15:24:06 +02:00
User e228c6f2fd fix: harden phase summary open questions 2026-07-14 15:09:50 +02:00