Files
ThothII/docs/plans/2026-09-09-archive-repair-x1-validation.md
T
Codex 82e2c91f42
Publish documentation / publish (push) Successful in 1m27s
feat: implement memory and evidence administration with guided repairs
Add PostgreSQL-backed memory, editable evidence with source review and activation, and human-approved archive repairs across the harness, API, and UI. Include migrations, deployment support, regression coverage, and validation documentation.

Refresh permissions from validated session roles so existing administrator logins can access newly deployed archive management features.
2026-09-10 10:31:34 +02:00

7.1 KiB

X1 — validation of session archive corrections

Date: 2026-09-09. The joint Memory/Evidence repair increment is implemented. The authoritative contract is Session archive corrections.

Delivered behavior

The session gate shows complete before/after content for specific alternatives targeting Memory or Evidence. The reviewer chooses one correction or rejects all proposals as inadequate and requests reformulation. The resulting receipt survives interruption; saved content and index activation are reported separately. Pending activation offers retry of the same chosen operation. A subsequent curator change blocks replay.

Application requires an administrator in the harness and the responding browser principal's archive-management permission. Cross-principal runtime responses cannot misattribute the correction. A non-administrator can decline or continue the current question without modifying shared archives. The gate does not advance a workflow phase.

Memory and Evidence remain separate domains. The integration coordinator reuses their canonical persistence and activation operations. A session Evidence correction requires a consolidated archive, preserves source lineage, and cannot publish unrelated external edits. Existing administration, source import, dependency cleanup and final Memory review remain available. No automatic Git commit or push was added.

Verification

  • Harness regression: 1,264 passed, one skipped, five deselected. All nine portable-path checks passed separately without THT_HOME. Python lint passed on changed modules.
  • Backend: 1,366 passed, 40 skipped. Tests include actual session-response routes for both target archives, unauthorized response, malformed choice and runtime ownership.
  • Frontend: complete suite 645 passed; the final display adjustment passed all four focused widget tests. Backend and frontend TypeScript checks passed.
  • Pi extension: 199 passed, including closed human choices, rejection, failure/retry, forged selections and the updated public tool schema. The modular skill projection is byte-identical to its updated approved template.
  • PostgreSQL/Qdrant integration traverses the actual Python CLI for preparation, application and recovery inspection. Corrected Memory and Evidence are retrieved from real indexes, and Evidence activation preserves the Memory card. Session loading is a controlled fixture and embeddings are deterministic; this is not an LLM quality test.
  • Failure tests cover both targets, index outage, replay, later edits, workspace/session isolation, changed session context, rejection, non-admin writes, and interruption after the Evidence file write but before its saved receipt.
  • Playwright desktop/mobile: one passed. The real widget renders both alternatives, accepts an Evidence choice, displays pending activation and allows retry to active. No page errors or mobile horizontal overflow. Screenshots are /private/tmp/thothii-x1-repair-desktop.png and /private/tmp/thothii-x1-repair-mobile.png. This browser fixture controls operation outcomes; persistent behavior is tested above.
  • Strict MkDocs build and git diff --check passed.

Local installation and reviewer acceptance

Core and frontend images were rebuilt from this worktree using the existing local preview launcher. Migration 004_archive_repairs.sql was applied to the existing installation catalog. The new gate is available to session workflows; it is not an always-visible administration panel. Existing PSD archive content was not changed by the synthetic validation cases. All five local services are healthy at http://127.0.0.1:8080/.

The technical increments and their planned checks are complete. The end-user acceptance check remains a real session containing a meaningful domain conflict, with the reviewer evaluating the proposed correction. Automated browser validation uses temporary accounts and data, not the user's authenticated PSD session. Source import retains its E3 validation boundaries; no broader model-quality benchmark was added.

Follow-up acceptance: configured model

The opt-in test_real_model_proposes_a_reviewable_persistent_archive_correction passed with the installation's zai/glm-5.3 model. Synthetic Memory asserted an order-ID-only join; synthetic Evidence required the financial year too. The model returned two schema-valid, specific alternatives with complete content and the exact target revisions. The test reviewer selected Memory, persisted the correction through the real coordinator and PostgreSQL, and retrieved the updated rule. Evidence stayed unchanged. This test uses deterministic vectors and the configured completion helper; it does not claim a full autonomous Pi session or human acceptance of PSD semantics.

The run log is /private/tmp/x1-acceptance-model.log. Reproduce with THT_MEMORY_L2_INSTALLATION=<installation.yaml> and THT_MEMORY_L2_CORE=<core-container> using pytest -q -s -m l2 tests/memory/test_administration.py -k real_model_proposes. Credentials are resolved inside core and are not returned to the test runner.

Follow-up acceptance: both administration pages

The opt-in frontend/e2e/memory-real.spec.ts passed through real authentication, Fastify, ThtRunner, Python, isolated PostgreSQL and Qdrant. It verifies:

  • Database management, Memory management and Evidence management appear as peers in that order, with no active core session or DWH binding required.
  • Memory creation, editing, persistence across backend restart, deletion and absence from subsequent recall.
  • Canonical Evidence remains intact after the Memory deletion. Its full rule is read through the real Evidence administration worker; content filtering finds it and an unmatched filter produces the empty state.
  • Requests for an unregistered workspace return 404 for both archives.
  • Desktop and mobile Evidence views render without horizontal document overflow. On phones, both archive pages have at least 380px of usable width at a 390px viewport. Navigation opens in the shared accessible dialog, closes with Escape or archive selection, and returns focus to the trigger after Escape.

The temporary PostgreSQL readiness probe now waits for TCP, avoiding the image's socket-only initialization server. The browser waits for Memory refresh to finish before leaving its page, matching the existing navigation guard. Visual inspection also exposed a real mobile layout issue: the fixed sidebar left only 134px for the Evidence page. ArchiveNavigation now moves that sidebar into the shared dialog below 768px on Memory/Evidence pages. Desktop behavior is unchanged. The frontend image was rebuilt for the local preview.

Run log: /private/tmp/x1-acceptance-browser7.log (one passed). Screenshots: /private/tmp/thothii-acceptance-evidence-desktop.png and /private/tmp/thothii-acceptance-evidence-mobile.png. Reproduce with THT_MEMORY_BROWSER_E2E=1 npx playwright test e2e/memory-real.spec.ts from frontend/. The fixture removes its temporary containers, accounts and checkout on completion. The TypeScript check, Python lint, strict documentation build and diff check also pass.