Commit Graph

1135 Commits

Author SHA1 Message Date
c01fcffdbe feat(execution): P0 runtime safety wave — provider shutdown drain, mutation readback, filter canary (SCEX-FR-037/038, BSC-FILT-001)
- ProviderEventLoop.stop(): close_all_sessions fan-out on the live loop before detach +
  bounded pending-task drain before loop.close() (zero 'Task was destroyed' live-proven);
  close_all_sessions weak-registry shutdown fan-out in browser_session_managers.
- SCEX-FR-038 independent mutation readback: browser_readback.py (same-session fresh
  client_id SELECT, cleanup-aware expectation, canonical 6dp float normalization);
  transport wiring adds readback_verified checkpoint; BrowserTransportReadbackMismatch ->
  reconciliation_required/effect unknown/retry blocked; INV_7 kept (browser.py 395 LOC
  via factory-helpers extraction).
- Live canaries: actions/mutation (readonly-canary-20260918T174659/174740/184343Z) and
  native filters (filters-canary-20260918T195946Z: values/clear/replay/chart PASS; date
  vector absent on stand — external prerequisite).
- Robustness fixes from live flake: pre-apply Escape (stale overlay in reused sessions)
  and bounded antd dropdown settle in browser_native_filter.
- Root-cause of the 82.75/82.74 divergence: mid-step post-SELECT vs post-restore
  lifecycle skew, not a cache defect.
2026-09-22 09:39:17 +03:00
6e20664b22 docs(specs): unify production acceptance matrix and live residual gates 2026-09-18 17:10:37 +03:00
0a2379c0ed test(canary): retain 2026-09-18 live Superset wave-2 observe and mutation evidence 2026-09-18 15:56:54 +03:00
c9e6e642e3 fix(analytics): implement case index API for investigation findability (SCAN-FR-020) 2026-09-18 14:54:09 +03:00
67c7b1d89e feat(baseline): scenario_transform candidate kind with run/expression provenance (AGBASE-FR-017) 2026-09-18 13:36:59 +03:00
87a90f6f64 feat(scenario): set_step_evaluation op — E-class spec pinning with code-token guard (AGSCN-FR-021/034) 2026-09-18 13:24:46 +03:00
3633e6751d docs(workstate): wave-2 checkpoint — observe drivers and zero-human mapper closed 2026-09-18 13:08:54 +03:00
a59f5e3cbb feat(scenario): zero-human capability mapping — human_checkpoint emission replaced with unsupported (AGSCN-FR-019/020) 2026-09-18 12:58:52 +03:00
4274e40395 feat(scenario): wave-2 observe drivers — assert_dom, inspect_filter_options, navigate_tabs, wait_for_selector (AGSCN-FR-024) 2026-09-18 12:47:01 +03:00
2fcd50564f docs(workstate): wave-1 implementation checkpoint — four amendment branches verified and merged 2026-09-18 12:07:13 +03:00
5d86da54a4 Merge feat/038-registry-filters: registry 038.5.0 disabled-action discipline, native filter search/clear/date modes, click URL outcome 2026-09-18 12:04:50 +03:00
683347bee8 feat(scenario): native filter search/clear/date modes and click URL outcome (AGSCN-FR-024) 2026-09-18 12:04:37 +03:00
d29959f6c5 feat(scenario): registry 038.5.0 with disabled-action discipline (AGSCN-FR-025) 2026-09-18 11:39:37 +03:00
80980cee29 Merge feat/047-investigation-ui: queue findability, case index, linked runs and evidence refs (SCAN-FR-020/021) 2026-09-18 10:50:39 +03:00
c022448671 Merge feat/047-investigation-mcp: investigation MCP tools, queue/case projections, catalog 2.4.0 (SCAN-FR-016..019, MCPX-FR-031) 2026-09-18 10:50:39 +03:00
e495f9db63 Merge feat/038-step-inputs: typed action_inputs op, per-action validation, embedded-metric-literal validator (AGSCN-FR-016/023) 2026-09-18 10:49:58 +03:00
e7925d0e26 feat(analytics): investigation queue findability, case index, linked runs and evidence refs in workspace 2026-09-18 10:48:19 +03:00
f123210bb2 fix(scenario): keep ScenarioStep.inputs as canonical ref list; pin action args in action_inputs 2026-09-18 09:51:04 +03:00
5eea72bc46 fix(mcp): align investigation catalog contract 2026-09-18 09:17:06 +03:00
23414f9af6 feat(mcp): add investigation case tools 2026-09-17 22:11:28 +03:00
6fcc861677 feat(analytics): start investigation queue refresh 2026-09-17 21:26:27 +03:00
534d488f73 feat(scenario): add typed step inputs 2026-09-17 21:19:15 +03:00
fcf4e6eb87 docs(specs): design amendments 2026-09-17 — complex browser scenarios, D/M/E taxonomy, zero-human runtime, evidence tiering, investigation loop 2026-09-17 19:41:49 +03:00
ec917ac677 feat(scenario): 044 provider INV_7 decomposition + T044/T045 live canaries; evidence-backed spec status
The 044 provider lifecycle is decomposed to satisfy INV_7 and closed with live canaries;
the remaining acceptance row (T046 graph-level terminal PASS) is diagnosed with executable proof.

- split browser_readonly_actions (534->160), browser_session (501->58) and browser.py (407->398)
  into sibling modules with frozen contract IDs and frozen import surface (facades re-export every
  moved public name); monkeypatch seams follow the owning modules
- gates per phase: scoped 044 suite 1590 passed and full backend 11269 passed / 0 failed, no delta
- T042b: six PREPROD browser canaries GREEN under the Wave-C run-scoped session architecture;
  harness gains SS_CANARY_STORAGE_ROOT and fixes the dead-loop scheduler drain hang
- T044: new artifact-content live HTTP canary 11/11 (real app, PostgreSQL, JWTs, live-captured bytes)
- T045: new fault-injection canary 16/16 (bounded loop refusals, deadline cancellation, shutdown
  drain, capacity quarantine + TTL reconcile, receipt CAS, late response, cancel drain)
- T046: walker-level evaluation->comparison binding diagnosed (compare-only + mandatory ->
  EVALUATION_UNAVAILABLE; bound evaluation -> BASELINE_AND_SEMANTIC_PASS); T043/T046 stay open
- refresh 044 spec/traceability/checklist/quickstart/SESSION_STATE/contracts/plan/data-model and the
  037/050 rows to evidence-backed states; split three malformed multi-target @RELATION lines
- fix skill drift in semantics-python/semantics-svelte (logger facade, notify(), i18n proxy)
2026-09-17 18:05:45 +03:00
4746af2f3e fix(health): address consolidation review findings 2026-09-16 16:11:02 +03:00
3de0756d4f refactor(validation): remove legacy LLM dashboard validation mechanism
Scenario-based dashboard testing (042/044) and scenario automation (046)
replace the legacy policy/run based validation surface.

- drop backend validation routes, service, schemas and DashboardValidationPlugin
- add migration 0025_drop_legacy_validation removing legacy tables
- redirect legacy settings/automation page to scenario automation surface
- remove frontend validation models, routes, components and i18n bundles
- repair dangling semantic relations and dead plugin-id fixtures
2026-09-16 11:13:50 +03:00
63beea9694 chore(git): ignore docs/openapi external-API reference snapshots 2026-09-15 10:32:35 +03:00
8522a2ee3c feat(scenario): complete dashboard testing UX flow 2026-09-15 10:12:17 +03:00
22ffdb5ba5 chore(tools): add read-only ADFS context collector for closed-contour debugging 2026-09-15 10:01:52 +03:00
b4148cfe5f fix(automation): scheduled runs execute as schedule-owner principal; MCP upsert signature parity — live scheduled happy path proven (046 T018 CLOSED) 2026-09-11 20:22:47 +03:00
d0466a2c1e fix(automation): deterministic scheduled-run idempotency key + typed scheduled-reject observability (046 happy path) 2026-09-11 20:01:53 +03:00
578a6110e7 fix(scenario): T045 review hardening — RUN_PROD REST gate, fail-marked typed errors, marker-bound adoption, unique idempotency, path guard 2026-09-11 19:05:20 +03:00
72018383c4 test(mcp): catalog list includes publish_baseline_catalog (050 T045) 2026-09-11 18:14:30 +03:00
6dde7e15c3 feat(scenario): 050 T045 — gated MCP publish_baseline_catalog + 037 publication worker (CAS, receipts, reconcile), REST parity 2026-09-11 18:13:09 +03:00
e925d4a85c chore(kilo): retire qa-tester and security-auditor runtime agents 2026-09-11 17:27:50 +03:00
f37a46e366 docs(reports): add ss-prod agentic E2E gap analysis and task notes
Add 2026-09-08 production gap/spec-coverage/refresh-plan and dashboard
scenario E2E plan/report, axiom-mcp feedback, and 2026-09-11 data-team
maintenance dev-test run notes.
2026-09-11 17:27:50 +03:00
605c5d0552 docs(specs): refresh 017/036/037/038/039 production contracts
Add production contract refresh sections and normative contracts: 017/050
capture-reuse trust, 036 evidence promotion, 037 catalog lifecycle/revision,
038 browser actions/decision policy, 044-047 production chain/evidence/atomic
triage, and 050 MCP interface artifacts. Requirements marked OPEN pending
executable evidence.
2026-09-11 17:27:48 +03:00
6da072b9d4 test(database): cover DB_SCHEMA isolation and prepare_database reset
- env_settings schema resolution/search_path args incl. invalid-name rejection
- dedicated schema pins engine search_path
- e2e: no-public-privilege role, missing-schema bootstrap/denied, object-kind
  reset (sequences/views/domains)
- enterprise template asserts DB_SCHEMA
2026-09-11 17:27:45 +03:00
7cb02f4fe0 test(scenario): DEF-01 promotion graph validation regressions
Structure-first validation: prose double-hyphen passes, SQL in title rejected,
needs_baseline is not a promotion gate, legacy snapshot stays free-text scan.
2026-09-11 17:27:45 +03:00
7291169343 feat(scenario): durable 037 baseline catalog publication
- PublicationOperation model + 0023 migration with idempotent inspector guard
- publication_worker: reviewed-gate binding, branch-head CAS, commit/receipt
  reconcile on retry (never duplicate/force-push)
- REST /api/catalog-publications (RUN_PROD) sharing the worker with the gated
  publish_baseline_catalog MCP tool (050 T045 / MCPX-FR-030 parity)
- MCP op input schema, catalog registration and approved-dispatch adapter
- tests: worker, REST surface, MCP gate/dispatch parity
2026-09-11 17:27:43 +03:00
71135c0822 fix(maintenance): single-banner multi-event render and per-env end-all
- multi-event builds exactly one banner (dedup messages <br>, min-start/max-end
  envelope, open-ended keeps 'уточняется') instead of nested invalid HTML
- event.environment_id is authoritative for states/banner rows (settings target
  only legacy fallback)
- end_all resolves a SupersetClient per event environment via memoized factory
- structured reason/explore logging for fan-out target resolution
- suppress toast for unconfigured /maintenance/settings 404
2026-09-11 17:27:39 +03:00
5758ae4a83 fix(database): object-level reset and optional DB_SCHEMA isolation
Safe one-shot reset, fail-fast on unknown revisions, object-level drops for non-owner corporate PG, rollback before advisory unlock, configurable DB_SCHEMA via search_path, e2e migration matrix tests.
2026-09-11 16:17:11 +03:00
e334863771 build(backend): declare python-dotenv explicitly (review nit — direct import) 2026-09-11 15:10:24 +03:00
de5e098a1b fix(scenario): review hardening — run.sh key reuse, resolver-canonical publisher envelope, strict pin asserts, honest T045/T046 statuses 2026-09-11 15:09:16 +03:00
7d3fb8a770 feat(scenario): live baseline pin via published Gitea catalog — publisher POST/PUT contract, run.sh key-wipe fix, T045/T046 closed 2026-09-11 14:07:20 +03:00
1411c03f9b fix(scenario): orthogonal review hardening — binding fingerprint guard, strict image digest, typed publisher errors, T029m human-loop closure 2026-09-11 10:10:01 +03:00
1d48625b10 test(maintenance): fix 5s first-test timeout flake — static import + vi.hoisted mocks
Module load of maintenance.svelte.js happened inside the first test via
dynamic import and exceeded the 5000ms testTimeout under full-suite
parallel load. Move to a single hoisted static import (mock factories
now resolve vi.fn()s created via vi.hoisted) and drop a dead no-op
placeholder test. 39/39 in isolation, 3563/3563 full suite.
2026-09-11 09:49:52 +03:00
d04927bda7 feat(scenario): T029m live MCP replay — binding identity fixes, Gitea catalog publisher, 050 statuses 2026-09-11 08:40:37 +03:00
792bb1251d feat(scenario): live eval trust — MIME sniffing, multimodal evidence, baseline pin stamping, binding admin surface 2026-09-11 08:40:19 +03:00
bac002bcbc feat(settings): derive project-sections toggles from sidebar nav registry
- sidebarNavigation.ts: static SIDEBAR_SECTIONS registry (i18n labelKey) + getTogglableFeatureNodes() with per-flag dedup
- projectSections.json: shared feature-id manifest; vitest guard pins nav ids to it, pytest guard pins it to FeaturesConfig fields
- FeaturesSettings: toggles derived and grouped by sidebar section/category, extra block for non-nav flags
- features.svelte.ts: reactive flags store; sidebar rebuilds live after settings save, untracked health polling
2026-09-11 07:35:26 +03:00