Commit Graph
128 Commits
Author SHA1 Message Date
marcopan 5b3ce93e31 fix: acknowledge pi maintenance barrier 2026-08-04 19:32:05 +02:00
marcopan 0b9ad7f53f fix: harden pi maintenance lifecycle 2026-08-04 19:09:04 +02:00
marcopan e4fdbed864 fix: harden workspace activation and snapshot retention 2026-08-04 09:25:06 +02:00
marcopan 3b23cf3714 fix: retain snapshots for removed workspaces 2026-08-04 08:52:11 +02:00
marcopan 8b046f9fb2 test: verify portable workspace registry end to end 2026-08-04 08:42:33 +02:00
marcopan 802b564200 fix: harden workspace registry deployment 2026-08-04 07:42:35 +02:00
marcopan f71feecaea feat: deploy portable workspace registry 2026-08-04 07:26:45 +02:00
marcopan 8effdc6c89 fix: report nested workspace conflicts 2026-08-04 07:05:51 +02:00
marcopan 6c09adc05e feat: pin sessions to workspace revisions 2026-08-04 05:18:08 +02:00
marcopan bc39730b58 feat: pin sessions to workspace revisions 2026-08-04 05:13:39 +02:00
marcopan 301db4bd85 feat: pin sessions to workspace revisions 2026-08-04 05:05:20 +02:00
marcopan 90894176b6 feat: pin sessions to workspace revisions 2026-08-04 04:52:06 +02:00
marcopan 2573d87a0e fix: recover workspace publication failures 2026-08-04 01:10:35 +02:00
marcopan f95a18ab0d feat: expose workspace registry API 2026-08-04 01:01:57 +02:00
marcopan 49fa7030a5 fix: complete diagnostic extension remediation 2026-08-04 00:46:44 +02:00
marcopan 565e93a456 fix: align workspace diagnostic contracts 2026-08-04 00:37:57 +02:00
marcopan f6494fd8ef docs: specify workspace diagnostic protocols 2026-08-04 00:24:30 +02:00
marcopan e2c698d553 fix: buffer SSH readiness confirmation 2026-08-04 00:17:13 +02:00
marcopan 1943435225 fix: confirm SSH forward ownership 2026-08-04 00:14:40 +02:00
marcopan 9986d9be28 fix: await SSH tunnel readiness 2026-08-04 00:09:24 +02:00
marcopan 67bb4f6ef9 fix: complete workspace diagnostic adapters 2026-08-04 00:05:33 +02:00
marcopan ca97bbb9c2 fix: harden workspace diagnostic protocols 2026-08-03 23:59:46 +02:00
marcopan 9e2eafb66c feat: run bounded workspace connector diagnostics 2026-08-03 23:50:12 +02:00
marcopan 6ab80d8a38 fix: migrate pre-state workspace manifests 2026-08-03 23:39:06 +02:00
marcopan 450d7ab07f fix: gate workspace diagnostic migration 2026-08-03 23:30:15 +02:00
marcopan c5685f4962 feat: define workspace diagnostic contracts 2026-08-03 23:16:23 +02:00
marcopan 319d1add2e fix: harden workspace diagnostics probes 2026-08-03 22:59:06 +02:00
marcopan ff795d1c91 feat: diagnose workspace connector bindings 2026-08-03 22:52:29 +02:00
marcopan e2d1117614 fix: make workspace registry lock process-bound 2026-08-03 22:42:57 +02:00
marcopan 553bb41138 fix: harden workspace registry refresh and snapshots 2026-08-03 22:33:39 +02:00
marcopan 2087fbb0c9 feat: manage workspace Git checkout and snapshots 2026-08-03 22:21:10 +02:00
marcopan 5d7ebc5b01 fix: harden workspace runtime snapshots 2026-08-03 22:10:09 +02:00
marcopan 049f8675c6 feat: resolve workspace bindings into runtime configs 2026-08-03 21:49:57 +02:00
marcopan 5a654939a5 fix: harden workspace schema contracts 2026-08-03 21:40:58 +02:00
marcopan 92cb0545be feat: add canonical workspace schema 2026-08-03 21:31:07 +02:00
marcopan 6434c9c4e1 fix: reject reserved Git HEAD branch 2026-08-03 21:22:08 +02:00
marcopan cc951d8073 fix: harden workspace registry config validation 2026-08-03 21:19:29 +02:00
marcopan 6e1321f93c feat: configure Git workspace registry 2026-08-03 21:13:23 +02:00
marcopan 00761ae2ca fix: enforce one Pi runtime per user 2026-07-21 16:13:17 +02:00
marcopan a040c083cc fix: reap finalized runtimes before session start 2026-07-21 16:04:08 +02:00
marcopan 019f6b282e fix: release finalized Pi runtimes 2026-07-21 15:39:34 +02:00
marcopan 801f847ec4 fix: use Pi user auth and handle startup failures 2026-07-21 14:01:47 +02:00
marcopan 2ff63d371f feat: harden workflow gates and expose token usage 2026-07-21 12:14:26 +02:00
marcopan 0cf09777f2 Fix session resume and PSD container configuration 2026-07-20 20:22:47 +02:00
marcopanandClaude Opus 4.6 3b52c8c08c feat: DWH connectivity probe at startup — modal alert within 5s if unreachable
Backend: GET /health/dwh (unauthenticated) calls tht db ping with a 5s
timeout. Frontend: checkDwhHealth() races a 5s timer against the fetch;
on failure a non-dismissable Dialog with Retry appears immediately.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-07-20 13:59:11 +02:00
marcopanandClaude Fable 5 c4951e2aa5 chore: hygiene pass — ruff clean, docs storage-model truth, replay /me, failSession log
Audit findings 6.1-6.4 + the audit's remediation plan itself
(docs/superpowers/plans/2026-07-20-full-audit-remediation-plan.md).

- ruff: 34 → 0 (unused imports/f-strings auto-fixed; E702 semicolon lines
  split in test files; one unused local dropped). Suite still 819 green.
- CLAUDE.md + PROJECT_STATE.md no longer claim "no database / settings in
  settings.json": the harness selects filesystem OR PostgreSQL session
  storage (repository.py, server mode), and settings flow through harness
  preferences with the JSON file as fallback only.
- tools/replay: stub /me (SPA boot was parsing the SPA's own HTML as JSON)
  and /runtime/prewarm.
- failSession best-effort persistence now logs its failure server-side
  instead of vanishing.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 01:55:41 +02:00
marcopanandClaude Fable 5 f772ef9dca fix(backend): robustness pass — spawn leak, timeouts, workspace fail-loud, 409 order, respond guard
Audit findings 4.1-4.6.

- spawnFor: a rejected configure/start no longer leaks a registered runtime
  with a live Pi child (identity-checked teardown + rethrow); every later
  start used to hit "session runtime already active".
- ThtRunner.run: default 60s timeout on every tht child (SIGKILL backstop),
  120s for DWH-touching calls (sql preview/export, search pack); a dropped
  VPN mid-call no longer wedges the HTTP request forever.
- configArg: a NAMED workspace whose yaml is missing now throws instead of
  silently falling back to the default config (operations were silently
  targeting the wrong workspace).
- resume: the finalized/archived 409 is evaluated BEFORE the alreadyActive
  fast-path — the manifest is the truth even with a lingering runtime.
- ollamaEnsure: exit-0 with non-JSON stdout is a failed check, not ok:true.
- SessionBridge.respond: only the response matching the pending descriptor
  is forwarded to Pi; stale/duplicate submissions return 409 instead of
  being sent with the current gate's RPC id.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 01:37:20 +02:00
marcopanandClaude Fable 5 2958b32fd5 fix(backend): generation-aware SSE event ids — stale cursors can no longer eat events
Audit finding 3.1 (high, 3/3 reviewer consensus). Event ids restart at 1
when the backend restarts; a browser auto-reconnect carrying the old
numeric Last-Event-ID was honored whenever the new process had already
emitted that many events, silently suppressing fresh events (same ids,
different content). The previous guard only caught cursor > lastId.

Wire ids are now "<generation>:<seq>" (generation = per-hub instance
token; seq = the existing per-session monotonic counter). The hub parses
raw header/query candidates itself: other-generation and legacy bare-
number cursors are stale → replay from the beginning; same-generation
cursors keep the newest-valid-wins behavior. EventSource treats ids as
opaque, so no frontend change.

Finding 3.2 (eviction) resolved by NOT evicting: close keeps the seq
counter on purpose (sessions reopen; monotonicity is what makes old
cursors detectable) — documented at the call site; buffers are emptied by
clear() and ring-bounded at 200.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 01:32:47 +02:00
marcopanandClaude Opus 4.6 6ee5bda7f0 feat: gate decision-type validation, force-advance, and frontend fixes
Gate (tht-gate.js):
- Pre-validate decision types against workflow.yaml before showing reviewer widget
- Reject decisions emitted by later phases (min-phase check)
- Copy top-level `kind` into artifact when model forgets it (prevents loop)
- Force-advance on reviewer_decide/schema_linking when advance:true — skip
  redundant reviewer_confirm gate

Backend:
- Emit agent_end on clean Pi exit (code 0 + bridge idle) instead of marking failed

Frontend:
- Strip <think> tags from transcript and activity panel
- Fix mermaid render with offscreen container + cleanup
- Graceful mermaid error: show source code instead of red error, fall back to table

Workflow:
- F2 now emits table_promoted and table_excluded (early schema linking decisions)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-07-19 14:14:44 +02:00
marcopanandClaude Opus 4.8 3453f3ae23 feat: pre-check DWH reachability before creating a session (local dev only)
New session now refuses to spawn a Pi runtime that would only die in bootstrap
retrieval when the DWH/vector host is unreachable (e.g. a dropped VPN). Before
`session new`, POST /sessions probes the DWH via `tht db ping`; if it is down it
returns 503 {code:"dwh_unreachable"} with a clear message and creates nothing.

- Gated behind the THT_DWH_PRECHECK flag (default off), enabled only by the local
  dev launcher (run-stack.sh) — containers/CI never pay the probe, and existing
  tests that don't set it are unaffected.
- ThtRunner.dbPing() runs `tht db ping` with a 10s timeout (run() gains an optional
  timeout that SIGKILLs a hung child).
- Frontend: apiFetch throws a typed ApiError (status + parsed payload); the new-
  session composer shows the specific alert on `dwh_unreachable` instead of the
  generic retry hint, keeping the question for retry.

Verified live on an isolated backend (precheck on + broken DWH host → 503
dwh_unreachable, no session created) and via unit tests (backend 228, frontend 308).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-18 12:08:47 +02:00