Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
350 commits
Select commit Hold shift + click to select a range
a077f0d
docs: record failed-transition job-object ownership annotations
JuliaEdom Aug 7, 2026
3c96a03
docs: transparent next-session handoff after 2.4j
JuliaEdom Aug 7, 2026
9e358f1
feat(ingestion): load job statuses and wire CLI transition annotations
JuliaEdom Aug 7, 2026
33327b9
docs: record 2.4k job status load and CLI transition annotations
JuliaEdom Aug 7, 2026
0855528
feat(admin): read-only job-object inventory preview HTTP surface
JuliaEdom Aug 7, 2026
8dceeab
docs: record 2.5a admin job-object inventory preview surface
JuliaEdom Aug 7, 2026
6dbabef
feat(ingestion): durable job-to-index publication lifecycle bind
JuliaEdom Aug 7, 2026
770c4bd
docs: record 2.5b job-to-index lifecycle bind
JuliaEdom Aug 7, 2026
5ff8cef
docs: transparent next-session handoff after 2.5b
JuliaEdom Aug 7, 2026
3f3c699
feat(index): inventory/publish fail-closed lifecycle fault injection
JuliaEdom Aug 7, 2026
78b0e8a
docs: record 2.6a inventory/publish lifecycle fault injection
JuliaEdom Aug 7, 2026
0e4451e
feat(index): known-query fail-closed lifecycle fault injection
JuliaEdom Aug 7, 2026
f43d3f5
docs: record 2.6b known-query lifecycle fault injection
JuliaEdom Aug 7, 2026
3ba7986
feat(index): embeddings fail-closed lifecycle fault injection
JuliaEdom Aug 7, 2026
6cbb97c
docs: record 2.6c embeddings lifecycle fault injection
JuliaEdom Aug 7, 2026
5b9e384
feat(index): cleanup discard-path lifecycle fault injection
JuliaEdom Aug 7, 2026
08bad89
docs: record 2.6d cleanup discard-path lifecycle fault injection
JuliaEdom Aug 7, 2026
fbc2293
feat(index): same-tenant rebuild lock contention fail-closed
JuliaEdom Aug 7, 2026
71488c2
docs: record 2.6e same-tenant lock contention fail-closed
JuliaEdom Aug 7, 2026
53a398f
feat(ingestion): prove duplicate job fail-closed without double publish
JuliaEdom Aug 7, 2026
767d283
docs: record 2.6f duplicate job fail-closed
JuliaEdom Aug 7, 2026
0fda397
docs: transparent next-session handoff after 2.6f
JuliaEdom Aug 7, 2026
f347feb
feat(ingestion): worker outage/recovery fail-closed before silent pub…
JuliaEdom Aug 7, 2026
de57323
docs: record 2.6g worker outage/recovery fail-closed
JuliaEdom Aug 7, 2026
a21f364
feat(runtime): shared request executor and hold pipeline capacity pas…
JuliaEdom Aug 7, 2026
4583047
docs: record 3.1a shared request executor and capacity hold
JuliaEdom Aug 7, 2026
76179d5
feat(runtime): cooperative request deadline at provider boundary
JuliaEdom Aug 7, 2026
6594a13
docs: record 3.1b cooperative provider deadline
JuliaEdom Aug 7, 2026
d9ba87e
feat(session): serialize concurrent asks and discard stale turn mutat…
JuliaEdom Aug 7, 2026
c5f989f
docs: record 3.1c per-session serialize
JuliaEdom Aug 7, 2026
48c2381
feat(llm): configurable temperature and max_tokens per LLM role
JuliaEdom Aug 7, 2026
b100fe2
style(llm): ruff import order for role_params
JuliaEdom Aug 7, 2026
a29d861
docs: record 3.1d per-role LLM generation params
JuliaEdom Aug 7, 2026
b98b917
feat(llm): per-request call and token budget fail-closed
JuliaEdom Aug 7, 2026
36d5b18
docs: record 3.1e per-request LLM budget
JuliaEdom Aug 7, 2026
2581855
feat(stream): hold pipeline capacity and bind budget/deadline on SSE
JuliaEdom Aug 7, 2026
70dce00
docs: record 3.1f stream capacity-hold and budget bind
JuliaEdom Aug 7, 2026
fdaa6a7
docs: transparent next-session handoff after 3.1f
JuliaEdom Aug 7, 2026
ae13000
feat(runtime): cooperative deadline at retriever and tool boundaries
JuliaEdom Aug 7, 2026
1259417
docs: record 3.1g retriever/tool deadline and next 3.1h
JuliaEdom Aug 7, 2026
ab7b417
feat(retrieval): cooperative deadline at hybrid reranker boundary
JuliaEdom Aug 7, 2026
88ea9f9
docs: record 3.1h reranker deadline and next 3.1i
JuliaEdom Aug 7, 2026
fe2f0aa
feat(session): optimistic version CAS and sticky identity to pipeline
JuliaEdom Aug 7, 2026
c6c022f
docs: record 3.1i session version CAS and next plan section 4
JuliaEdom Aug 7, 2026
eaf41f3
feat(stream): single terminal answer and history when graph parity su…
JuliaEdom Aug 7, 2026
4ce63c5
docs: record 4.1 stream terminal ownership and next 4.2
JuliaEdom Aug 7, 2026
f1c846e
feat(stream): single graph generation when streaming parity is enabled
JuliaEdom Aug 7, 2026
b4fdeea
docs: record 4.2 graph-only stream parity and next 4.3
JuliaEdom Aug 7, 2026
ad5e435
feat(escalation): idempotent durable ticket service with delivery state
JuliaEdom Aug 7, 2026
82d9a17
docs: record 4.3 durable escalation service and next 4.4
JuliaEdom Aug 7, 2026
63084ad
docs: transparent next-session handoff after 4.3
JuliaEdom Aug 7, 2026
0371971
feat(escalation): auto-escalate terminal human/error on normal ask path
JuliaEdom Aug 7, 2026
f2e7f9e
docs: record 4.4 auto human-route escalation and next 4.5
JuliaEdom Aug 7, 2026
6453530
feat(escalation): outbox retry for failed inbox deliveries
JuliaEdom Aug 7, 2026
1c5143c
docs: record 4.5 outbox retry and next section 5 options
JuliaEdom Aug 7, 2026
7c53bdb
feat(grounding): fail-closed status and auto-route gate (plan 5.1)
JuliaEdom Aug 7, 2026
249e0be
docs: record 5.1 grounding fail-closed and plan residual matrix
JuliaEdom Aug 7, 2026
50bb220
feat(grounding): bind claims to answer citations for auto (plan 5.2)
JuliaEdom Aug 7, 2026
b0dfd41
docs: record 5.2 citation-bound claims and next 5.3
JuliaEdom Aug 7, 2026
1cdecb2
feat(grade): fail-closed grader path without silent context restore (…
JuliaEdom Aug 7, 2026
d6ce977
docs: record 5.3 grader fail-closed and next section 6
JuliaEdom Aug 7, 2026
3d2e3a2
docs: transparent next-session handoff after 5.3 (Update-92)
JuliaEdom Aug 7, 2026
b3494a0
feat(agentic): fail-closed unmeasured quality gate (6.1)
JuliaEdom Aug 7, 2026
59a711d
docs: record 6.1 unmeasured agentic gate and next 6.2 (Update-93)
JuliaEdom Aug 7, 2026
d0317e9
feat(safety): pre-response PII and prompt-injection gate (6.2)
JuliaEdom Aug 7, 2026
fbec72b
docs: record 6.2 pre-response safety and next 6.3 (Update-94)
JuliaEdom Aug 7, 2026
d6e3a55
feat(judge): independent judge policy fail-closed (6.3)
JuliaEdom Aug 7, 2026
496c6d5
docs: record 6.3 independent judge and next 7.1 (Update-95)
JuliaEdom Aug 7, 2026
94ac64e
feat(eval): fail-closed regression gate on skip and infra (7.1)
JuliaEdom Aug 7, 2026
4c8ff1e
docs: record 7.1 eval gate fail-closed and next 7.2 (Update-96)
JuliaEdom Aug 7, 2026
25788ee
feat(eval): mock expected-copy cannot claim release PASS (7.2)
JuliaEdom Aug 7, 2026
87afd6b
docs: record 7.2 mock evidence policy and next 8.1 (Update-97)
JuliaEdom Aug 7, 2026
0bee13e
feat(widget): bootstrap token, origin allowlist, frame-ancestors (8.1)
JuliaEdom Aug 7, 2026
6140df7
docs: record 8.1 widget bootstrap and next 8.2 (Update-98)
JuliaEdom Aug 7, 2026
f09196c
docs: full next-session transparency after 8.1 (Update-99)
JuliaEdom Aug 7, 2026
756562e
feat(security): ASGI received-byte body limits and upload stream atom…
JuliaEdom Aug 7, 2026
84f8df5
docs: record 8.2 body limits and next 8.x residual (Update-100)
JuliaEdom Aug 7, 2026
13a9a5b
feat(auth): OIDC email_verified and issuer-subject identity binding (…
JuliaEdom Aug 7, 2026
19f44a5
docs: record 8.3 OIDC identity binding and next 8.4 (Update-101)
JuliaEdom Aug 7, 2026
68a30b2
feat(security): reject production placeholders and dev-admin bypass (…
JuliaEdom Aug 7, 2026
8e3047f
docs: record 8.4 production secrets and next Playwright E2E (Update-102)
JuliaEdom Aug 7, 2026
48d47d6
docs: full next-session transparency after 8.4 (Update-103)
JuliaEdom Aug 7, 2026
4d6be52
feat(widget): Playwright cross-origin bootstrap E2E and iframe Origin…
JuliaEdom Aug 7, 2026
ad8be2b
docs: record 8.5 Playwright E2E and next residual (Update-104)
JuliaEdom Aug 7, 2026
0d34be2
feat(eval): merge-base baseline artifact for regression gate (7.3)
JuliaEdom Aug 7, 2026
5650711
docs: record 7.3 baseline artifact and next residual (Update-105)
JuliaEdom Aug 7, 2026
f622d58
fix(deps): docs-site npm audit DEP-01 lock refresh and fail-closed gate
JuliaEdom Aug 8, 2026
20b2ac0
docs: record DEP-01 npm audit gate and next residual (Update-106)
JuliaEdom Aug 8, 2026
8f4269f
feat(eval): expand curated dataset with required slices (7.4)
JuliaEdom Aug 8, 2026
6a2b674
docs: record 7.4 dataset expansion and next residual (Update-107)
JuliaEdom Aug 8, 2026
9817d1c
docs: full next-session transparency after 7.4 (Update-108)
JuliaEdom Aug 8, 2026
4eceed3
feat(ci): wire baseline artifact write, publish, require (7.5)
JuliaEdom Aug 8, 2026
31a880b
docs: record 7.5 CI baseline-artifact wire and next residual (Update-…
JuliaEdom Aug 8, 2026
a7cefc3
feat(routing): calibration artifact for auto-route thresholds (6.4)
JuliaEdom Aug 8, 2026
91685c3
docs: record 6.4 calibration artifact and next residual (Update-110)
JuliaEdom Aug 8, 2026
431893c
feat(agentic): measured grounding gate when KB context exists (6.5)
JuliaEdom Aug 8, 2026
2b06f6c
docs: record 6.5 measured agentic KB gate and next residual (Update-111)
JuliaEdom Aug 8, 2026
d1ae4d6
feat(eval): scheduled live provider gate scaffold (7.6)
JuliaEdom Aug 8, 2026
c79f975
docs: record 7.6 live provider gate scaffold and next residual (Updat…
JuliaEdom Aug 8, 2026
47e255a
feat(eval): deepen curated dataset to 3+ cases per required slice (7.7)
JuliaEdom Aug 8, 2026
10da548
docs: record 7.7 deeper curated corpus and next residual (Update-113)
JuliaEdom Aug 8, 2026
93761e9
docs: full next-session transparency after 7.7 (Update-114)
JuliaEdom Aug 8, 2026
69c6fdf
feat(agentic): wire LLM evaluate on KB terminals (6.6)
JuliaEdom Aug 8, 2026
add33e9
docs: record 6.6 agentic LLM evaluate wire and next residual (Update-…
JuliaEdom Aug 8, 2026
c707c46
feat(routing): human calibration readiness and recalibrate CLI (6.7)
JuliaEdom Aug 8, 2026
7c1d170
docs: record 6.7 human calibration readiness and next residual (Updat…
JuliaEdom Aug 8, 2026
11acfec
feat(escalation): Celery beat and CLI for outbox retry schedule (4.6)
JuliaEdom Aug 8, 2026
352ed7f
docs: record 4.6 outbox schedule wire and next residual (Update-117)
JuliaEdom Aug 8, 2026
6b91a35
feat(stream): emit real LangGraph node status events on parity SSE (4.7)
JuliaEdom Aug 8, 2026
b89f197
docs: record 4.7 graph node SSE and next residual (Update-118)
JuliaEdom Aug 8, 2026
18fbd18
docs: full next-session transparency after 4.7 (Update-119)
JuliaEdom Aug 8, 2026
fc7f07b
feat(stream): provider token streaming through graph generate (4.8)
JuliaEdom Aug 8, 2026
cf12230
docs: record 4.8 provider token stream and next residual (Update-120)
JuliaEdom Aug 8, 2026
4f95e18
feat(relevance): independent retrieval relevance, not quality/100 (5.4)
JuliaEdom Aug 8, 2026
7b86c1f
docs: record 5.4 independent relevance and next residual (Update-121)
JuliaEdom Aug 8, 2026
a901692
feat(eval): live quality metrics gate scaffold for plan §5 DoD (5.5)
JuliaEdom Aug 8, 2026
96ef373
docs: record 5.5 live quality metrics scaffold and next residual (Upd…
JuliaEdom Aug 8, 2026
fb72dd2
feat(eval): wire live quality reports into DoD gate (5.6)
JuliaEdom Aug 9, 2026
33949b1
docs: record 5.6 report-to-DoD wire and next residual (Update-123)
JuliaEdom Aug 9, 2026
13bf255
feat(eval): emit canonical section 5 metrics (5.7)
JuliaEdom Aug 9, 2026
336b08e
docs: record 5.7 metric producer and gated residuals (Update-124)
JuliaEdom Aug 9, 2026
faaa815
feat(llm): add OpenCode Zen free provider
JuliaEdom Aug 9, 2026
ddb721c
docs: record OpenCode Zen handoff (Update-125)
JuliaEdom Aug 9, 2026
99c6be5
feat(smoke): add lightweight GraceKelly RAG check
JuliaEdom Aug 9, 2026
79379a6
docs: reconcile GraceKelly smoke handoff (Update-129)
JuliaEdom Aug 9, 2026
9a870f7
docs: record native live quality gate (Update-130)
JuliaEdom Aug 9, 2026
c3ae4f4
fix(retrieval): preserve parent expansion on vector path
JuliaEdom Aug 9, 2026
62a1f27
docs: record QG-01 vector parent expansion fix
JuliaEdom Aug 9, 2026
c157796
test(routing): align mock with independent judge
JuliaEdom Aug 9, 2026
1304ff4
fix(graph): route generation failures to error handling
JuliaEdom Aug 9, 2026
b391028
docs: record QG-02 generation failure routing
JuliaEdom Aug 9, 2026
142747d
docs: consolidate open problem ledger
JuliaEdom Aug 9, 2026
80c2603
fix(graph): fail closed on verifier outages
JuliaEdom Aug 9, 2026
e1d9ae5
docs: record QG-03 verifier outage routing
JuliaEdom Aug 9, 2026
5662ea7
fix(grading): preserve same-source content for context headers
JuliaEdom Aug 9, 2026
3f6f652
docs: record QG-03B grading fix
JuliaEdom Aug 9, 2026
5f8bb78
test(grading): cover retained E30 context recovery
JuliaEdom Aug 9, 2026
62772d7
docs: record QG-04 shared-cause closure
JuliaEdom Aug 9, 2026
3c90368
fix(quality): preserve disabled child reranker
JuliaEdom Aug 9, 2026
4acdd32
docs: record hybrid child env closure
JuliaEdom Aug 9, 2026
1c758bd
docs: reconcile next-session transparency
JuliaEdom Aug 9, 2026
3a37fd2
fix(types): narrow lifecycle fault actions
JuliaEdom Aug 10, 2026
ed1c2fc
docs: record lifecycle type debt closure
JuliaEdom Aug 10, 2026
db65e37
fix(cache): bound Redis fallback memory
JuliaEdom Aug 10, 2026
cc7abaa
docs: record bounded cache fallback
JuliaEdom Aug 10, 2026
eb8466e
fix(cache): retry Redis with bounded backoff
JuliaEdom Aug 10, 2026
3528858
docs: record Redis reconnect backoff
JuliaEdom Aug 10, 2026
a224659
docs: reconcile next-session Redis handoff
JuliaEdom Aug 10, 2026
893efe3
fix(cache): version response cache namespace
JuliaEdom Aug 10, 2026
65c82cc
docs: record versioned cache namespace
JuliaEdom Aug 10, 2026
093b439
docs: reconcile cache handoff transparency
JuliaEdom Aug 10, 2026
4b0fba7
test(index): reconcile retention caller contract
JuliaEdom Aug 10, 2026
11430f8
docs: record VER-05 caller contract
JuliaEdom Aug 10, 2026
3fe6d6d
feat(metrics): expose index lifecycle failures
JuliaEdom Aug 10, 2026
791fedd
docs: record index lifecycle telemetry
JuliaEdom Aug 10, 2026
11e52f1
feat(metrics): expose unverified auto responses
JuliaEdom Aug 10, 2026
09093ef
docs: record unverified auto telemetry
JuliaEdom Aug 10, 2026
356a530
test(agent): align safety mock with kb docs
JuliaEdom Aug 10, 2026
2fd9fd1
docs: close agentic safety mock debt
JuliaEdom Aug 10, 2026
af4fb71
docs: reconcile next-session transparency
JuliaEdom Aug 10, 2026
64f40b3
feat(metrics): expose escalation delivery outcomes
JuliaEdom Aug 11, 2026
7d96d6f
docs: record escalation delivery telemetry
JuliaEdom Aug 11, 2026
9817e89
feat(metrics): expose safety block outcomes
JuliaEdom Aug 11, 2026
3b8681a
docs: record safety block telemetry
JuliaEdom Aug 11, 2026
5a2f696
feat(metrics): expose orphan work gauge
JuliaEdom Aug 11, 2026
ff613b0
docs: record orphan work telemetry
JuliaEdom Aug 11, 2026
344e174
feat(metrics): expose tenant access denials
JuliaEdom Aug 11, 2026
806bf27
docs: record tenant denial telemetry
JuliaEdom Aug 11, 2026
1c5fa2c
docs: reconcile next-session transparency
JuliaEdom Aug 11, 2026
1237f3c
feat(monitoring): add RAG operations dashboard
JuliaEdom Aug 11, 2026
192ef78
docs: record Grafana dashboard artifact
JuliaEdom Aug 11, 2026
5bf5614
docs: reconcile post-dashboard transparency
JuliaEdom Aug 11, 2026
cea370b
chore(docs): upgrade site to Astro 7
JuliaEdom Aug 11, 2026
c246fd7
docs: record Astro 7 verification
JuliaEdom Aug 11, 2026
9c207b6
refactor(tracing): centralize lifecycle ownership
JuliaEdom Aug 11, 2026
77b4d66
docs: record TraceService ownership
JuliaEdom Aug 11, 2026
fd23317
test(tracing): align purge audit tenant contract
JuliaEdom Aug 11, 2026
e7fba57
docs: close VER-07 tenant audit debt
JuliaEdom Aug 11, 2026
cda6001
docs: refresh next-session transparency
JuliaEdom Aug 11, 2026
03057aa
refactor(escalation): centralize lifecycle ownership
JuliaEdom Aug 11, 2026
84fbdf7
refactor(ingestion): centralize API job lifecycle
JuliaEdom Aug 11, 2026
e3c25f0
docs: record lifecycle ownership slices
JuliaEdom Aug 11, 2026
890155a
refactor(ingestion): centralize worker lifecycle ownership
JuliaEdom Aug 11, 2026
a193817
docs: record ingestion worker ownership
JuliaEdom Aug 11, 2026
aefcf20
refactor(pipeline): centralize capacity lifecycle
JuliaEdom Aug 11, 2026
e5006f4
docs: record pipeline capacity ownership
JuliaEdom Aug 11, 2026
d865b06
refactor(pipeline): centralize sync execution deadline
JuliaEdom Aug 11, 2026
a0035bc
docs: record sync pipeline execution ownership
JuliaEdom Aug 11, 2026
378c4f5
docs: reconcile next-session transparency
JuliaEdom Aug 11, 2026
c53f724
refactor(pipeline): centralize streaming execution ownership
JuliaEdom Aug 11, 2026
6154d55
docs: record streaming pipeline ownership
JuliaEdom Aug 11, 2026
fbb18c1
docs: record VER-03 full-gate evidence
JuliaEdom Aug 11, 2026
eb764da
test(ingestion): align deployment reliability contract
JuliaEdom Aug 11, 2026
82c9006
docs: record focused VER-03 contract closure
JuliaEdom Aug 11, 2026
c68911d
docs: record VER-03 aggregate-only failure
JuliaEdom Aug 11, 2026
3e62849
docs: rule out adjacent VER-03 order band
JuliaEdom Aug 11, 2026
520d82a
docs: record VER-03 ingestion timeout blocker
JuliaEdom Aug 11, 2026
fce19ba
test(ingestion): isolate vector-store routing contract
JuliaEdom Aug 11, 2026
cda1254
docs: record contextual ingestion test isolation
JuliaEdom Aug 11, 2026
42931e0
docs: record VER-03 predecessor window evidence
JuliaEdom Aug 12, 2026
aa6c712
docs: record green Python 3.13 full gate
JuliaEdom Aug 12, 2026
7279451
docs: record memory guard enforcement
JuliaEdom Aug 12, 2026
e4879b4
docs: record bounded live provider evidence
JuliaEdom Aug 12, 2026
c9bd46c
docs: make next-session status explicit
JuliaEdom Aug 12, 2026
227e25d
docs: record post-QG live quality failure
JuliaEdom Aug 12, 2026
63aa5df
fix(llm): reject GraceKelly browser artifacts
JuliaEdom Aug 12, 2026
dbd2b28
fix(graph): fail closed on generation provider outages
JuliaEdom Aug 12, 2026
4c91c8b
docs: record GraceKelly artifact containment
JuliaEdom Aug 12, 2026
e400d88
deps: migrate Starlette TestClient to httpx2
JuliaEdom Aug 12, 2026
5e6e480
docs: reconcile next-session state after VER-04
JuliaEdom Aug 12, 2026
121d59b
docs: record VER-01 exact-lock blocker
JuliaEdom Aug 12, 2026
5454c41
docs: record second VER-01 lock timeout
JuliaEdom Aug 12, 2026
775a5d8
docs: record VER-01 lightweight lock diagnostic
JuliaEdom Aug 12, 2026
05cbc19
docs: record VER-01 lightweight lock boundary
JuliaEdom Aug 12, 2026
810906b
docs: record VER-01 type gate findings
JuliaEdom Aug 12, 2026
fbebe5e
fix(api): remove stream variable redeclarations
JuliaEdom Aug 12, 2026
33a4914
docs: record stream no-redef closure
JuliaEdom Aug 12, 2026
370a429
fix(api): close strict type gate findings
JuliaEdom Aug 12, 2026
d84bec6
docs: record API type gate closure
JuliaEdom Aug 12, 2026
02df975
fix(agent): type escalation delivery payload
JuliaEdom Aug 12, 2026
54067e7
docs: record delivery-state type closure
JuliaEdom Aug 12, 2026
25455f5
fix(agent): type grade state boundary
JuliaEdom Aug 12, 2026
3d51779
docs: record grade-state type closure
JuliaEdom Aug 12, 2026
acc76ee
fix(agent): accept covariant claim sequences
JuliaEdom Aug 12, 2026
67a3536
docs: record claims sequence type closure
JuliaEdom Aug 12, 2026
d4583cc
fix(agent): type agentic terminal payloads
JuliaEdom Aug 12, 2026
f95ec99
docs: record local mypy gate closure
JuliaEdom Aug 12, 2026
ad10b54
docs: reconcile ver01 restart routing
JuliaEdom Aug 12, 2026
d157b31
fix(vectordb): guard active embedding dimensions
JuliaEdom Aug 12, 2026
f891114
docs: record index dimension guard boundary
JuliaEdom Aug 12, 2026
1aa9f19
fix(index): preserve legacy rollback target
JuliaEdom Aug 12, 2026
7ed9cd3
docs: record index rebuild lock blocker
JuliaEdom Aug 12, 2026
46b51b2
docs: record verified Mac index rebuild artifact
JuliaEdom Aug 13, 2026
24ca711
docs: reconcile next-session artifact handoff
JuliaEdom Aug 13, 2026
bc9ee2b
test(eval): deepen required curated slices
JuliaEdom Aug 13, 2026
0cba9d1
feat(index): add activation preflight
JuliaEdom Aug 13, 2026
bac1939
docs(index): record activation lock blocker
JuliaEdom Aug 13, 2026
426442a
docs(index): reconcile activation handoff
JuliaEdom Aug 13, 2026
2e5254e
docs(index): record WSL activation blocker
JuliaEdom Aug 13, 2026
bd12a3a
docs(index): record WSL VHD owner gate
JuliaEdom Aug 13, 2026
94c03eb
docs(index): record unavailable UAC owner test
JuliaEdom Aug 13, 2026
8a4a8e0
docs(index): record restored Ubuntu attach
JuliaEdom Aug 13, 2026
7e32629
docs(handoff): clarify WSL recovery boundaries
JuliaEdom Aug 13, 2026
4e77f15
docs(index): record PostgreSQL lock gate blocker
JuliaEdom Aug 13, 2026
fb9e74e
docs(index): record Ubuntu dpkg blocker
JuliaEdom Aug 14, 2026
506debf
docs(index): record PostgreSQL relay blocker
JuliaEdom Aug 14, 2026
cc0458d
test: isolate CSP test from local index; align rollback test with 1aa…
JuliaEdom Aug 19, 2026
5d93e12
docs: commit 2026-08-03 plan re-pointing + track active remediation plan
JuliaEdom Aug 19, 2026
837578a
docs: Update-209 — stage closed (suite green, lock gate root-caused, …
JuliaEdom Aug 19, 2026
752488b
fix(ci): green the CI matrix — dev lock, live-gate tmp path, local ou…
JuliaEdom Aug 19, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
44 changes: 36 additions & 8 deletions .env.example
Original file line number Diff line number Diff line change
@@ -1,30 +1,49 @@
# GraceKelly is the default local orchestrator. Start D:\GraceKelly on this URL first.
# Optional GraceKelly orchestrator. Used only by explicit GraceKelly profiles.
GRACEKELLY_BASE_URL=http://127.0.0.1:8011
GRACEKELLY_API_KEY=
GRACEKELLY_API_KEY_ENV=GRACEKELLY_API_KEY
GRACEKELLY_HEALTH_CHECK_TIMEOUT_SEC=2.0
GRACEKELLY_REQUEST_TIMEOUT_SEC=30.0
FAILOVER_CHAIN_ENABLED=true
FAILOVER_FALLBACK_CACHE_SECONDS=300
# Provider registry and routing profile. `gracekelly-primary` is the default path.
# Use `local-first` only for explicit local-only Ollama mode.
# Provider registry and routing profile. `local-first` is the default Ollama path.
# Use `external-mistral` or a GraceKelly profile only as an explicit opt-in.
PROVIDER_REGISTRY_PATH=config/providers.yml
LLM_PROVIDER_PROFILE=gracekelly-primary
# Optional Ollama settings for explicit `local-first` mode or GraceKelly fallback.
LLM_PROVIDER_PROFILE=local-first
# Ollama settings for the default `local-first` mode or GraceKelly fallback.
# In Docker Compose use http://ollama:11434
OLLAMA_BASE_URL=http://localhost:11434
OLLAMA_MODEL_NAME=qwen2.5:7b
# Benchmarks stay mock-only unless you explicitly allow paid provider calls.
LLM_BENCHMARK_ALLOW_PAID_APIS=false
# Fail fast when paid-provider spend for the current UTC day reaches this limit.
DAILY_COST_LIMIT_USD=5.0
# Paid-provider credentials. Placeholder values such as `changeme` are treated as missing.
# External-provider credentials. Placeholder values such as `changeme` are treated as missing.
MISTRAL_API_KEY=changeme
# OpenCode Zen free models are temporary trials; never send personal or confidential data.
OPENCODE_ZEN_API_KEY=changeme
# Model routing: fast model for simple questions, strong model for complex ones
MODEL_ROUTING_ENABLED=false
OLLAMA_FAST_MODEL_NAME=llama3.2:3b
# Ingestion auto-categorizer model. Override when the default is not pulled locally.
INGESTION_CATEGORIZER_MODEL=llama3.2:3b
# Durable async ingestion job lease / heartbeat / reaper (plan step 4.3).
# Heartbeat must be positive and strictly shorter than the lease.
INGESTION_JOB_LEASE_SEC=120
INGESTION_JOB_HEARTBEAT_INTERVAL_SEC=30
# Queued async jobs older than this become terminal failures (seconds).
INGESTION_JOB_QUEUED_STALE_SEC=900
# Pre-lease async running rows (no lease_token) reaped after this age (seconds).
INGESTION_JOB_LEGACY_RUNNING_STALE_SEC=1800
# FastAPI-process reaper interval; runs independently of the Celery worker.
INGESTION_JOB_REAPER_INTERVAL_SEC=60
# Bounded broker publish-only retry for async /api/upload (plan step 4.4 core).
# Does not enable Celery worker/task autoretry after load/index begins.
INGESTION_PUBLISH_MAX_RETRIES=2
INGESTION_PUBLISH_RETRY_DELAY_SEC=0.2
# Maximum wait for the per-tenant PostgreSQL advisory index lock (seconds).
# A timeout or unavailable lock database fails the rebuild closed.
INGESTION_TENANT_LOCK_WAIT_SEC=30
# Default token pricing used when a model is not listed in LLM_MODEL_PRICES.
LLM_INPUT_PRICE_PER_1M_TOKENS=0.0
LLM_OUTPUT_PRICE_PER_1M_TOKENS=0.0
Expand All @@ -42,8 +61,11 @@ RAG_EMBEDDING_REMOTE_MODEL=mistral-embed
RAG_EMBEDDING_REMOTE_API_KEY_ENV=MISTRAL_API_KEY
RAG_EMBEDDING_REMOTE_BATCH=32
RAG_EMBEDDING_REMOTE_TIMEOUT_SEC=60
# Declared remote embedding vector dimension (must match the remote model; mistral-embed=1024)
RAG_EMBEDDING_REMOTE_DIMENSION=1024
# Cross-encoder reranker model used to reorder retrieved documents
# (multilingual, pairs with BGE-M3; ms-marco is English-only and degrades RU retrieval)
# Leave empty on memory-constrained hosts to disable the reranker.
RAG_RERANKER_MODEL=BAAI/bge-reranker-v2-m3
# Inference device for embedder + reranker: auto (cuda->mps->cpu) | cpu | cuda | cuda:0 | mps
RAG_DEVICE=auto
Expand Down Expand Up @@ -119,8 +141,14 @@ REGRESSION_GATE_MAX_REGRESSIONS=2
REGRESSION_GATE_MIN_PASS_RATE=0.85
# Vector database backend to use for document storage
RAG_VECTOR_BACKEND=chroma
# Optional Chroma persistence directory. Blank keeps <repo>/data/vectordb/chroma.
# Use a new empty directory when changing embedding model or vector dimension.
VECTORDB_CHROMA_DIR=
# Chroma collection prefix; full name = {prefix}_{tenant_id}
VECTORDB_COLLECTION_PREFIX=rag_docs
# Validated per-tenant version budget (active + previous at minimum).
# Runtime retention execution is not wired yet; this must be an integer >= 2.
VECTORDB_RETENTION_MAX_VERSIONS=2
# Backend used to store escalations for human support
SUPPORT_SINK_BACKEND=local
# Bitrix24 webhook URL for sending escalations when Bitrix backend is enabled
Expand All @@ -131,9 +159,9 @@ TELEGRAM_BOT_TOKEN=
LANGFUSE_PUBLIC_KEY=
LANGFUSE_SECRET_KEY=
LANGFUSE_HOST=https://cloud.langfuse.com
# Fail fast on startup if Ollama is unavailable. Set true only for explicit local-first mode.
# Fail fast on startup if the default local Ollama provider is unavailable.
REQUIRE_OLLAMA=false
# Circuit breaker for Ollama - fast-fail when explicit local/fallback Ollama is unhealthy
# Circuit breaker for Ollama - fast-fail when local/fallback Ollama is unhealthy
CIRCUIT_BREAKER_ENABLED=true
CIRCUIT_BREAKER_FAILURE_THRESHOLD=5
CIRCUIT_BREAKER_RESET_TIMEOUT_SEC=30
Expand Down
46 changes: 42 additions & 4 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -312,10 +312,16 @@ jobs:
list-files: shell
filters: |
regression:
- 'agent/prompts.py'
- 'agent/**'
- 'api/routers/conversation.py'
- 'cache/**'
- 'config/settings.py'
- 'evaluation/curated_cases.jsonl'
- 'evaluation/experiments/*.yaml'
- 'config/providers.yml'
- 'evaluation/**'
- 'ingestion/**'
- 'llm/**'
- 'scripts/regression_eval.py'
- 'vectordb/**'

- name: Skip when regression inputs did not change
if: steps.regression_changes.outputs.regression != 'true'
Expand Down Expand Up @@ -353,7 +359,12 @@ jobs:
if: steps.regression_changes.outputs.regression == 'true' && !hashFiles('evaluation/curated_cases.jsonl')
run: echo "evaluation/curated_cases.jsonl is missing; skipping informational regression run."

- name: Run regression eval
# Smoke-only: mock expected-copy is NOT release evidence (plan §7.2).
# Exit follows metrics smoke; do not pass --release-gate here.
# Release evidence requires real pipeline/provider runs without mock.
# Plan §7.5: publish a durable baseline artifact from this smoke run so the
# merge-base compare path is wired in CI (write → upload → require load).
- name: Run regression eval (smoke, write baseline artifact)
if: steps.regression_changes.outputs.regression == 'true' && hashFiles('evaluation/curated_cases.jsonl')
run: >
python scripts/regression_eval.py
Expand All @@ -365,3 +376,30 @@ jobs:
--seed 42
--mock-experiment-runtime
--no-persist
--write-baseline-artifact reports/regression/ci-baseline-artifact.json

- name: Upload regression baseline artifact
if: steps.regression_changes.outputs.regression == 'true' && hashFiles('evaluation/curated_cases.jsonl')
uses: actions/upload-artifact@v4
with:
name: regression-baseline-artifact
path: reports/regression/ci-baseline-artifact.json
if-no-files-found: error

# Plan §7.5: re-compare candidate against the written artifact with
# --require-baseline-artifact (fail-closed if missing/unusable).
# Still mock → still smoke; does not claim release PASS (plan §7.2).
- name: Regression compare against baseline artifact (require wire)
if: steps.regression_changes.outputs.regression == 'true' && hashFiles('evaluation/curated_cases.jsonl')
run: >
python scripts/regression_eval.py
--baseline merge-base
--candidate ${{ steps.regression_target.outputs.candidate }}
--dataset evaluation/curated_cases.jsonl
--tenant all
--max-cases 100
--seed 42
--mock-experiment-runtime
--no-persist
--baseline-artifact reports/regression/ci-baseline-artifact.json
--require-baseline-artifact
15 changes: 5 additions & 10 deletions .github/workflows/docs-site.yml
Original file line number Diff line number Diff line change
Expand Up @@ -47,17 +47,12 @@ jobs:

- name: Audit npm dependencies
working-directory: docs-site
# The deployed artifact is fully static (HTML/CSS/JS/woff2/SVG) — no npm
# package executes at runtime. The current moderate/high advisories
# (esbuild dev-server & Deno installer; dompurify/js-yaml, used only while
# building mermaid diagrams and parsing config) have no runtime exposure
# and no non-breaking fix in the Astro 6 dependency tree (`npm audit fix`
# is a no-op; `--force` would downgrade Astro and break the build).
# Report everything for visibility, but only fail the deploy on a critical
# supply-chain advisory. Revisit when Astro/vite ship patched esbuild.
# Plan DEP-01 (2026-08-07): fail-closed on high/critical after lock refresh.
# Residual moderate/low require dated reachability exceptions in
# docs-site/npm-audit-exceptions.json (no blanket `|| true`).
run: |
npm audit --audit-level=moderate || true
npm audit --audit-level=critical
npm audit --audit-level=high
npm run audit:deps

- name: Type-check docs site
working-directory: docs-site
Expand Down
96 changes: 96 additions & 0 deletions .github/workflows/live-provider-gate.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,96 @@
# Plan §7.6: scheduled live provider / independent-judge gate scaffold.
#
# Separated from PR/master smoke in ci.yml (mock allowed there; never release
# evidence). This workflow defaults to readiness-only — no live provider calls
# and no release PASS claim — unless workflow_dispatch enable_live=true AND
# repository secrets / RAG_LIVE_PROVIDER_GATE opt-in are present.
name: Live Provider Gate

on:
schedule:
# Weekly Monday 06:00 UTC — readiness probe by default.
- cron: "0 6 * * 1"
workflow_dispatch:
inputs:
enable_live:
description: "Opt-in live providers (requires secrets; never default)"
required: false
default: false
type: boolean
max_cases:
description: "Max curated cases for a live attempt"
required: false
default: "20"
type: string
execute:
description: "When live ready, actually run regression_eval (default false)"
required: false
default: false
type: boolean

jobs:
live-provider-gate:
name: live-provider-gate
runs-on: ubuntu-latest
env:
PYTHONPATH: ${{ github.workspace }}

steps:
- uses: actions/checkout@v6
with:
fetch-depth: 0

- uses: actions/setup-python@v6
with:
python-version: "3.13"
cache: "pip"
cache-dependency-path: |
requirements-dev.lock

- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install --require-hashes -r requirements-dev.lock

# Always: readiness scaffold (no live calls, not release evidence).
- name: Live gate readiness (scaffold, no live calls)
run: >
python scripts/live_provider_gate.py
--mode readiness
--max-cases ${{ github.event.inputs.max_cases || '20' }}
--write-report reports/regression/live-provider-gate-readiness.json

# Opt-in live path: workflow_dispatch + enable_live only.
# Secrets mapped only when present; missing keys → fail-closed (exit 1).
# --execute stays false unless explicitly requested so schedule never
# burns paid API quota by default.
- name: Live gate opt-in attempt
if: github.event_name == 'workflow_dispatch' && inputs.enable_live == true
env:
RAG_LIVE_PROVIDER_GATE: "1"
MISTRAL_API_KEY: ${{ secrets.MISTRAL_API_KEY }}
GRACEKELLY_API_KEY: ${{ secrets.GRACEKELLY_API_KEY }}
OPENCODE_ZEN_API_KEY: ${{ secrets.OPENCODE_ZEN_API_KEY }}
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
run: |
EXTRA=""
if [ "${{ inputs.execute }}" = "true" ]; then
EXTRA="--execute"
fi
python scripts/live_provider_gate.py \
--mode live \
--live \
--max-cases ${{ inputs.max_cases || '20' }} \
--write-report reports/regression/live-provider-gate-result.json \
$EXTRA

- name: Upload live gate reports
if: always()
uses: actions/upload-artifact@v4
with:
name: live-provider-gate-reports
path: |
reports/regression/live-provider-gate-readiness.json
reports/regression/live-provider-gate-result.json
if-no-files-found: warn
99 changes: 99 additions & 0 deletions .github/workflows/live-quality-metrics-gate.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,99 @@
# Plan §5.5: scheduled live quality metrics gate scaffold (×3 DoD).
#
# Separated from PR/master smoke in ci.yml. Defaults to readiness-only —
# no live provider calls and no release PASS claim — unless workflow_dispatch
# enable_live=true AND repository secrets / RAG_LIVE_QUALITY_METRICS_GATE.
name: Live Quality Metrics Gate

on:
schedule:
# Weekly Monday 07:00 UTC — readiness probe by default (after provider gate).
- cron: "0 7 * * 1"
workflow_dispatch:
inputs:
enable_live:
description: "Opt-in live multi-run metrics (requires secrets; never default)"
required: false
default: false
type: boolean
max_cases:
description: "Max curated cases per run"
required: false
default: "20"
type: string
runs:
description: "Repeated runs (plan min 3)"
required: false
default: "3"
type: string
execute:
description: "When live ready, actually run multi-seed regression_eval"
required: false
default: false
type: boolean

jobs:
live-quality-metrics-gate:
name: live-quality-metrics-gate
runs-on: ubuntu-latest
env:
PYTHONPATH: ${{ github.workspace }}

steps:
- uses: actions/checkout@v6
with:
fetch-depth: 0

- uses: actions/setup-python@v6
with:
python-version: "3.13"
cache: "pip"
cache-dependency-path: |
requirements-dev.lock

- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install --require-hashes -r requirements-dev.lock

# Always: readiness scaffold (no live calls, not release evidence).
- name: Quality metrics gate readiness (scaffold, no live calls)
run: >
python scripts/live_quality_metrics_gate.py
--mode readiness
--runs ${{ github.event.inputs.runs || '3' }}
--max-cases ${{ github.event.inputs.max_cases || '20' }}
--write-report reports/regression/live-quality-metrics-gate-readiness.json

# Opt-in live path: workflow_dispatch + enable_live only.
- name: Quality metrics gate opt-in attempt
if: github.event_name == 'workflow_dispatch' && inputs.enable_live == true
env:
RAG_LIVE_QUALITY_METRICS_GATE: "1"
MISTRAL_API_KEY: ${{ secrets.MISTRAL_API_KEY }}
GRACEKELLY_API_KEY: ${{ secrets.GRACEKELLY_API_KEY }}
OPENCODE_ZEN_API_KEY: ${{ secrets.OPENCODE_ZEN_API_KEY }}
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
run: |
EXTRA=""
if [ "${{ inputs.execute }}" = "true" ]; then
EXTRA="--execute"
fi
python scripts/live_quality_metrics_gate.py \
--mode live \
--live \
--runs ${{ inputs.runs || '3' }} \
--max-cases ${{ inputs.max_cases || '20' }} \
--write-report reports/regression/live-quality-metrics-gate-result.json \
$EXTRA

- name: Upload quality metrics gate reports
if: always()
uses: actions/upload-artifact@v4
with:
name: live-quality-metrics-gate-reports
path: |
reports/regression/live-quality-metrics-gate-readiness.json
reports/regression/live-quality-metrics-gate-result.json
if-no-files-found: warn
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -48,3 +48,6 @@ reports/ragas/*.md

# Ad-hoc QA screenshots at repo root (per-session captures, not committed assets)
/*.png

# pytest basetemp trees (local test-run artifacts, never evidence)
.pytest_tmp*/
Loading
Loading