Commit Graph
100 Commits
Author SHA1 Message Date
marcopan fe5c428354 fix(docs): export compose tool paths 2026-08-04 15:37:42 +02:00
marcopan 4f26a71156 fix(docs): enforce compose preflight workflow 2026-08-04 15:33:04 +02:00
marcopan eb01979072 fix(deploy): generalize connector secret overrides 2026-08-04 15:21:49 +02:00
marcopan b5071f1494 deploy: isolate git and connector secrets 2026-08-04 15:04:39 +02:00
marcopan ff271d3cce chore: untrack sdd reports 2026-08-04 14:58:26 +02:00
marcopan 01633be8f6 docs: record task 2 hardening verification 2026-08-04 14:55:59 +02:00
marcopan 2ce2e0089a fix: harden compose Pi auth mounts 2026-08-04 14:55:05 +02:00
marcopan 2e67568282 docs: record task 2 compose verification 2026-08-04 14:48:20 +02:00
marcopan 2595d35682 deploy: unify local and server compose stack 2026-08-04 14:47:16 +02:00
marcopan f4b9542c92 fix: allow PowerShell CRLF line endings 2026-08-04 14:39:58 +02:00
marcopan be0e49fbc7 docs: record task 1 line ending verification 2026-08-04 14:34:42 +02:00
marcopan ad07a75490 build: enforce portable line endings 2026-08-04 14:33:45 +02:00
marcopan efda41aaa4 docs: plan unified compose deployment 2026-08-04 14:26:28 +02:00
marcopan d82ebece4d docs: design managed embedded pi operations 2026-08-04 14:17:17 +02:00
marcopan ab69c7941e docs: clarify external services and embedded pi 2026-08-04 13:41:03 +02:00
marcopan 08ae9e6d90 docs: design unified compose deployment 2026-08-04 13:00:20 +02:00
marcopan e4fdbed864 fix: harden workspace activation and snapshot retention 2026-08-04 09:25:06 +02:00
marcopan 3b23cf3714 fix: retain snapshots for removed workspaces 2026-08-04 08:52:11 +02:00
marcopan 8b046f9fb2 test: verify portable workspace registry end to end 2026-08-04 08:42:33 +02:00
marcopan 3d5d26c20c fix: validate workspace secret source paths 2026-08-04 08:29:02 +02:00
marcopan 37404512ce fix: bind workspace connector configuration safely 2026-08-04 08:22:09 +02:00
marcopan e5219deab1 fix: harden workspace registry installation docs 2026-08-04 08:11:28 +02:00
marcopan 72e16dd5ea docs: add workspace registry installation manuals 2026-08-04 07:57:09 +02:00
marcopan 802b564200 fix: harden workspace registry deployment 2026-08-04 07:42:35 +02:00
marcopan f71feecaea feat: deploy portable workspace registry 2026-08-04 07:26:45 +02:00
marcopan 8effdc6c89 fix: report nested workspace conflicts 2026-08-04 07:05:51 +02:00
marcopan 234b40e7cf fix: resolve workspace publish conflicts 2026-08-04 06:57:19 +02:00
marcopan b75b3af28e feat: publish and synchronize workspace drafts 2026-08-04 06:47:10 +02:00
marcopan 6b40fa0cc5 fix: harden workspace manager drafts 2026-08-04 06:36:16 +02:00
marcopan 48fd316b90 feat: add workspace management editor 2026-08-04 06:27:59 +02:00
marcopan b686ffe271 fix: gate direct session creation by workspace policy 2026-08-04 06:13:22 +02:00
marcopan 7a780d8904 fix: block creation when workspace summaries fail 2026-08-04 06:05:22 +02:00
marcopan 41c558e06c fix: gate creation until workspace summaries load 2026-08-04 06:01:25 +02:00
marcopan b3ff39fc26 fix: make workspace policy waits selection-safe 2026-08-04 05:55:49 +02:00
marcopan cddd906719 fix: wait for workspace policy before creation 2026-08-04 05:48:13 +02:00
marcopan 959c6871ee fix: validate workspace drafts and reconcile models 2026-08-04 05:38:43 +02:00
marcopan cee4cfa63d feat: store workspace preferences and drafts locally 2026-08-04 05:28:13 +02:00
marcopan 6c09adc05e feat: pin sessions to workspace revisions 2026-08-04 05:18:08 +02:00
marcopan bc39730b58 feat: pin sessions to workspace revisions 2026-08-04 05:13:39 +02:00
marcopan 301db4bd85 feat: pin sessions to workspace revisions 2026-08-04 05:05:20 +02:00
marcopan 90894176b6 feat: pin sessions to workspace revisions 2026-08-04 04:52:06 +02:00
marcopan 2573d87a0e fix: recover workspace publication failures 2026-08-04 01:10:35 +02:00
marcopan f95a18ab0d feat: expose workspace registry API 2026-08-04 01:01:57 +02:00
marcopan 49fa7030a5 fix: complete diagnostic extension remediation 2026-08-04 00:46:44 +02:00
marcopan 565e93a456 fix: align workspace diagnostic contracts 2026-08-04 00:37:57 +02:00
marcopan f6494fd8ef docs: specify workspace diagnostic protocols 2026-08-04 00:24:30 +02:00
marcopan e2c698d553 fix: buffer SSH readiness confirmation 2026-08-04 00:17:13 +02:00
marcopan 1943435225 fix: confirm SSH forward ownership 2026-08-04 00:14:40 +02:00
marcopan 9986d9be28 fix: await SSH tunnel readiness 2026-08-04 00:09:24 +02:00
marcopan 67bb4f6ef9 fix: complete workspace diagnostic adapters 2026-08-04 00:05:33 +02:00
marcopan ca97bbb9c2 fix: harden workspace diagnostic protocols 2026-08-03 23:59:46 +02:00
marcopan 9e2eafb66c feat: run bounded workspace connector diagnostics 2026-08-03 23:50:12 +02:00
marcopan 6ab80d8a38 fix: migrate pre-state workspace manifests 2026-08-03 23:39:06 +02:00
marcopan 450d7ab07f fix: gate workspace diagnostic migration 2026-08-03 23:30:15 +02:00
marcopan c5685f4962 feat: define workspace diagnostic contracts 2026-08-03 23:16:23 +02:00
marcopan 25a85b972e docs: plan diagnostic contract extension 2026-08-03 23:06:56 +02:00
marcopan 319d1add2e fix: harden workspace diagnostics probes 2026-08-03 22:59:06 +02:00
marcopan ff795d1c91 feat: diagnose workspace connector bindings 2026-08-03 22:52:29 +02:00
marcopan e2d1117614 fix: make workspace registry lock process-bound 2026-08-03 22:42:57 +02:00
marcopan 553bb41138 fix: harden workspace registry refresh and snapshots 2026-08-03 22:33:39 +02:00
marcopan 2087fbb0c9 feat: manage workspace Git checkout and snapshots 2026-08-03 22:21:10 +02:00
marcopan 5d7ebc5b01 fix: harden workspace runtime snapshots 2026-08-03 22:10:09 +02:00
marcopan 049f8675c6 feat: resolve workspace bindings into runtime configs 2026-08-03 21:49:57 +02:00
marcopan 5a654939a5 fix: harden workspace schema contracts 2026-08-03 21:40:58 +02:00
marcopan 92cb0545be feat: add canonical workspace schema 2026-08-03 21:31:07 +02:00
marcopan 6434c9c4e1 fix: reject reserved Git HEAD branch 2026-08-03 21:22:08 +02:00
marcopan cc951d8073 fix: harden workspace registry config validation 2026-08-03 21:19:29 +02:00
marcopan 6e1321f93c feat: configure Git workspace registry 2026-08-03 21:13:23 +02:00
marcopan 7ad0199f9b docs: plan Git workspace registry 2026-08-03 21:05:31 +02:00
marcopan a6e6bc6800 docs: require workspace installation manuals 2026-08-03 20:57:53 +02:00
marcopan fef7a7614e docs: design git-backed workspace registry 2026-08-03 20:41:57 +02:00
marcopan 18233d59af fix: refine session report and live activity layout 2026-07-24 00:21:36 +02:00
marcopan 6ca4275ff2 fix: improve memory markdown layout 2026-07-23 23:01:29 +02:00
marcopan 3c75edfd47 docs: explain early-stage disambiguation
Publish documentation / deploy (push) Failing after 4m23s
2026-07-23 19:55:17 +02:00
marcopan 0b11121bcc docs: include canonical harness skill text 2026-07-23 19:50:24 +02:00
marcopan 5d34447975 docs: document application skill contract 2026-07-23 19:44:07 +02:00
marcopan 17bca2b2cb docs: publish MkDocs site on gh-pages 2026-07-23 19:28:09 +02:00
marcopan 724c446087 fix: expand session summary prose with panel 2026-07-23 16:06:22 +02:00
marcopan 2e1bb621a0 fix: exclude schema tables from session memories 2026-07-23 15:54:27 +02:00
marcopan 9b5fca59e8 fix: expand final SQL to session panel width 2026-07-23 15:44:16 +02:00
marcopan 4108b99405 docs: record session summary deployment 2026-07-23 15:37:48 +02:00
marcopan 0db85e4e4e feat: redesign persisted session summaries 2026-07-23 15:35:31 +02:00
marcopan 12c7a976d7 docs: specify session summary redesign 2026-07-23 12:34:30 +02:00
marcopan 694b7dd21f fix: harden reviewer workflow and memory handling 2026-07-23 12:34:23 +02:00
marcopan 00761ae2ca fix: enforce one Pi runtime per user 2026-07-21 16:13:17 +02:00
marcopan a040c083cc fix: reap finalized runtimes before session start 2026-07-21 16:04:08 +02:00
marcopan 019f6b282e fix: release finalized Pi runtimes 2026-07-21 15:39:34 +02:00
marcopan 4c9424f1e3 feat: add button press feedback 2026-07-21 15:10:08 +02:00
marcopan 801f847ec4 fix: use Pi user auth and handle startup failures 2026-07-21 14:01:47 +02:00
marcopan 2ff63d371f feat: harden workflow gates and expose token usage 2026-07-21 12:14:26 +02:00
marcopan 8aa1676811 Expose PSD frontend locally 2026-07-20 20:27:37 +02:00
marcopan ad6057f0dd Fix PSD frontend network wiring 2026-07-20 20:26:13 +02:00
marcopan 32efd647c4 Merge session resume and container configuration fix 2026-07-20 20:23:13 +02:00
marcopan 0cf09777f2 Fix session resume and PSD container configuration 2026-07-20 20:22:47 +02:00
marcopan ec9b12dff4 fix(harness): recover schema table name typos 2026-07-20 17:53:24 +02:00
marcopanandClaude Opus 4.6 3b52c8c08c feat: DWH connectivity probe at startup — modal alert within 5s if unreachable
Backend: GET /health/dwh (unauthenticated) calls tht db ping with a 5s
timeout. Frontend: checkDwhHealth() races a 5s timer against the fetch;
on failure a non-dismissable Dialog with Retry appears immediately.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-07-20 13:59:11 +02:00
marcopanandClaude Fable 5 83942c0b5c feat(harness): F6/F7 close on their last approval — no echo phase gate
Where completeness is machine-detectable, the reviewer's last substantive
approval now closes the phase itself (same pattern as F3/F4/F8):

- F6: approving the LAST CTE of the plan (kind:"cte_result" with next_cte
  now empty) advances the phase; a non-final CTE keeps the phase open and
  names the next one.
- F7: kind:"sql" records sql_approved — which IS F7's only advance
  prerequisite — and advances immediately.

Two reviewer interactions per session removed, both pure echoes. The
summary phase gate remains only where completeness is a human judgment
(F1, F2 with recorded memories, F5). SKILL.md states the rule and the
five self-closing gates; L1 tests cover last/non-last CTE and sql close.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 02:23:45 +02:00
marcopanandClaude Fable 5 c4951e2aa5 chore: hygiene pass — ruff clean, docs storage-model truth, replay /me, failSession log
Audit findings 6.1-6.4 + the audit's remediation plan itself
(docs/superpowers/plans/2026-07-20-full-audit-remediation-plan.md).

- ruff: 34 → 0 (unused imports/f-strings auto-fixed; E702 semicolon lines
  split in test files; one unused local dropped). Suite still 819 green.
- CLAUDE.md + PROJECT_STATE.md no longer claim "no database / settings in
  settings.json": the harness selects filesystem OR PostgreSQL session
  storage (repository.py, server mode), and settings flow through harness
  preferences with the JSON file as fallback only.
- tools/replay: stub /me (SPA boot was parsing the SPA's own HTML as JSON)
  and /runtime/prewarm.
- failSession best-effort persistence now logs its failure server-side
  instead of vanishing.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 01:55:41 +02:00
marcopanandClaude Fable 5 1ab0015460 fix(harness): state-integrity pass — reopen order, atomic decision batch, bash anti-bypass
Audit findings 5.1-5.3.

5.1 `phase reopen` now appends `phase_reopened` BEFORE the artifact
teardown: a crash between the two used to leave later-phase artifacts
deleted with the ledger still at the old phase (resume entered a phase
missing its artifacts). The inverse half-state — reopened with stale later
artifacts — is benign. Order locked by tests/test_phase_reopen_order.py.

5.2 New `tht decision add-batch --doc -`: N substantive decisions in ONE
atomic ledger write (meta types and cte_approved stay on `decision add`;
strictest min-phase enforced). reviewer_schema_linking now builds the
complete curation set and persists it with a single add-batch call — a
mid-loop failure can no longer leave the audit ledger half-written, and a
retry cannot duplicate the first K decisions.

5.3 The anti-bypass hook now also blocks BASH mutations of protected
state (`echo >> review_decisions.jsonl`, `sed -i` on the manifest,
`cat > tht-gate.js`, python open('w'), mv/rm/tee/…): FORBIDDEN only
covered tht subcommands and the write/edit hook only covered pi's own
tools. Read-only access (cat/grep/tail/ls) stays allowed.

Also: knownDecisionTypes is defensive — a workflow meta declaring NO
emits at all (older tht, minimal stubs) skips pre-validation instead of
rejecting every substantive type; with emits present, unknown types are
still rejected before the widget (new L1 test).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 01:51:38 +02:00
marcopanandClaude Fable 5 f772ef9dca fix(backend): robustness pass — spawn leak, timeouts, workspace fail-loud, 409 order, respond guard
Audit findings 4.1-4.6.

- spawnFor: a rejected configure/start no longer leaks a registered runtime
  with a live Pi child (identity-checked teardown + rethrow); every later
  start used to hit "session runtime already active".
- ThtRunner.run: default 60s timeout on every tht child (SIGKILL backstop),
  120s for DWH-touching calls (sql preview/export, search pack); a dropped
  VPN mid-call no longer wedges the HTTP request forever.
- configArg: a NAMED workspace whose yaml is missing now throws instead of
  silently falling back to the default config (operations were silently
  targeting the wrong workspace).
- resume: the finalized/archived 409 is evaluated BEFORE the alreadyActive
  fast-path — the manifest is the truth even with a lingering runtime.
- ollamaEnsure: exit-0 with non-JSON stdout is a failed check, not ok:true.
- SessionBridge.respond: only the response matching the pending descriptor
  is forwarded to Pi; stale/duplicate submissions return 409 instead of
  being sent with the current gate's RPC id.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 01:37:20 +02:00