Add PostgreSQL-backed memory, editable evidence with source review and activation, and human-approved archive repairs across the harness, API, and UI. Include migrations, deployment support, regression coverage, and validation documentation. Refresh permissions from validated session roles so existing administrator logins can access newly deployed archive management features.
7.1 KiB
X1 — validation of session archive corrections
Date: 2026-09-09. The joint Memory/Evidence repair increment is implemented. The authoritative contract is Session archive corrections.
Delivered behavior
The session gate shows complete before/after content for specific alternatives targeting Memory or Evidence. The reviewer chooses one correction or rejects all proposals as inadequate and requests reformulation. The resulting receipt survives interruption; saved content and index activation are reported separately. Pending activation offers retry of the same chosen operation. A subsequent curator change blocks replay.
Application requires an administrator in the harness and the responding browser principal's archive-management permission. Cross-principal runtime responses cannot misattribute the correction. A non-administrator can decline or continue the current question without modifying shared archives. The gate does not advance a workflow phase.
Memory and Evidence remain separate domains. The integration coordinator reuses their canonical persistence and activation operations. A session Evidence correction requires a consolidated archive, preserves source lineage, and cannot publish unrelated external edits. Existing administration, source import, dependency cleanup and final Memory review remain available. No automatic Git commit or push was added.
Verification
- Harness regression: 1,264 passed, one skipped, five deselected. All nine
portable-path checks passed separately without
THT_HOME. Python lint passed on changed modules. - Backend: 1,366 passed, 40 skipped. Tests include actual session-response routes for both target archives, unauthorized response, malformed choice and runtime ownership.
- Frontend: complete suite 645 passed; the final display adjustment passed all four focused widget tests. Backend and frontend TypeScript checks passed.
- Pi extension: 199 passed, including closed human choices, rejection, failure/retry, forged selections and the updated public tool schema. The modular skill projection is byte-identical to its updated approved template.
- PostgreSQL/Qdrant integration traverses the actual Python CLI for preparation, application and recovery inspection. Corrected Memory and Evidence are retrieved from real indexes, and Evidence activation preserves the Memory card. Session loading is a controlled fixture and embeddings are deterministic; this is not an LLM quality test.
- Failure tests cover both targets, index outage, replay, later edits, workspace/session isolation, changed session context, rejection, non-admin writes, and interruption after the Evidence file write but before its saved receipt.
- Playwright desktop/mobile: one passed. The real widget renders both alternatives,
accepts an Evidence choice, displays pending activation and allows retry to active.
No page errors or mobile horizontal overflow. Screenshots are
/private/tmp/thothii-x1-repair-desktop.pngand/private/tmp/thothii-x1-repair-mobile.png. This browser fixture controls operation outcomes; persistent behavior is tested above. - Strict MkDocs build and
git diff --checkpassed.
Local installation and reviewer acceptance
Core and frontend images were rebuilt from this worktree using the existing local
preview launcher. Migration 004_archive_repairs.sql was applied to the existing
installation catalog. The new gate is available to session workflows; it is not an
always-visible administration panel. Existing PSD archive content was not changed by
the synthetic validation cases.
All five local services are healthy at http://127.0.0.1:8080/.
The technical increments and their planned checks are complete. The end-user acceptance check remains a real session containing a meaningful domain conflict, with the reviewer evaluating the proposed correction. Automated browser validation uses temporary accounts and data, not the user's authenticated PSD session. Source import retains its E3 validation boundaries; no broader model-quality benchmark was added.
Follow-up acceptance: configured model
The opt-in test_real_model_proposes_a_reviewable_persistent_archive_correction
passed with the installation's zai/glm-5.3 model. Synthetic Memory asserted an
order-ID-only join; synthetic Evidence required the financial year too. The model
returned two schema-valid, specific alternatives with complete content and the exact
target revisions. The test reviewer selected Memory, persisted the correction through
the real coordinator and PostgreSQL, and retrieved the updated rule. Evidence stayed
unchanged. This test uses deterministic vectors and the configured completion helper;
it does not claim a full autonomous Pi session or human acceptance of PSD semantics.
The run log is /private/tmp/x1-acceptance-model.log. Reproduce with
THT_MEMORY_L2_INSTALLATION=<installation.yaml> and THT_MEMORY_L2_CORE=<core-container>
using pytest -q -s -m l2 tests/memory/test_administration.py -k real_model_proposes.
Credentials are resolved inside core and are not returned to the test runner.
Follow-up acceptance: both administration pages
The opt-in frontend/e2e/memory-real.spec.ts passed through real authentication,
Fastify, ThtRunner, Python, isolated PostgreSQL and Qdrant. It verifies:
- Database management, Memory management and Evidence management appear as peers in that order, with no active core session or DWH binding required.
- Memory creation, editing, persistence across backend restart, deletion and absence from subsequent recall.
- Canonical Evidence remains intact after the Memory deletion. Its full rule is read through the real Evidence administration worker; content filtering finds it and an unmatched filter produces the empty state.
- Requests for an unregistered workspace return 404 for both archives.
- Desktop and mobile Evidence views render without horizontal document overflow. On phones, both archive pages have at least 380px of usable width at a 390px viewport. Navigation opens in the shared accessible dialog, closes with Escape or archive selection, and returns focus to the trigger after Escape.
The temporary PostgreSQL readiness probe now waits for TCP, avoiding the image's
socket-only initialization server. The browser waits for Memory refresh to finish
before leaving its page, matching the existing navigation guard. Visual inspection
also exposed a real mobile layout issue: the fixed sidebar left only 134px for the
Evidence page. ArchiveNavigation now moves that sidebar into the shared dialog below
768px on Memory/Evidence pages. Desktop behavior is unchanged. The frontend image
was rebuilt for the local preview.
Run log: /private/tmp/x1-acceptance-browser7.log (one passed).
Screenshots: /private/tmp/thothii-acceptance-evidence-desktop.png and
/private/tmp/thothii-acceptance-evidence-mobile.png. Reproduce with
THT_MEMORY_BROWSER_E2E=1 npx playwright test e2e/memory-real.spec.ts from frontend/.
The fixture removes its temporary containers, accounts and checkout on completion.
The TypeScript check, Python lint, strict documentation build and diff check also pass.