-
Notifications
You must be signed in to change notification settings - Fork 0
Production-ready synthesis candidate #402
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
thebtf
wants to merge
126
commits into
main
Choose a base branch
from
work/prc-sol-synthesis-r1
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
126 commits
Select commit
Hold shift + click to select a range
88f6bbb
test(reaper): serialize environment override
thebtf 595218d
fix(bulkops): make snapshots and rollback conflict-safe
thebtf b0955df
chore(security): upgrade Go toolchain and x modules
thebtf 2ab6211
test(crystallization): align session-end DB contract
thebtf b0c4ab4
test(auth): harden last-admin invariant proof
thebtf d72e8e4
fix(bulkops): make rollback conflict checks atomic
thebtf da97c88
fix(auth): serialize initial admin setup
thebtf 2b085de
fix(bulkops): make promotion snapshots atomic
thebtf 451edca
ci: add fail-closed release gate foundation
thebtf 6ea1049
fix(bulkops): lock promotion capture and guard rollback conflicts
thebtf 68b2ce5
Fix DB bulkops sibling-path acceptance gaps
thebtf 2b3ef3e
ci: harden production release gates
thebtf cd09839
fix: close DB bulkops behavioral edges
thebtf 38d6a4f
fix: handle empty embedding stats
thebtf a1653ab
governance: pin production-ready plan authority
thebtf badc408
ci: harden production release gates
thebtf 586b39d
evidence: record release-gate maker handoff
thebtf bd68c05
fix: harden candidate review snapshot validation
thebtf 0f79e92
fix(reaper): harden retention and lifecycle shutdown
thebtf f987ce1
governance: amend production-ready revision 4 authority
thebtf 46ccf27
ci: harden revision 4 production gates
thebtf 0d5cfa5
fix(reaper): bound shutdown wait by caller context
thebtf 4812589
evidence: record release-gate revision 4 handoff
thebtf 462c97d
docs(evidence): define embedding manifest bytes
thebtf 276337b
test(db): close candidate test pools at owner cleanup
thebtf 580b0cd
docs(evidence): prove portable embedding hashes
thebtf db2cf89
fix(evidence): harden embedding manifest verifier
thebtf 68242c4
docs(evidence): repair DB pool hygiene audit packet
thebtf eb44a8e
ci: close release gate false greens
thebtf 135e4a0
docs: record release gate revision 5 evidence
thebtf 8dac791
docs(review): reject embedding evidence transport R2
thebtf 5dd3e3c
ci: pin required session start inventory
thebtf d59d160
docs: refresh release gate revision 5 evidence
thebtf d650df5
docs(evidence): repair embedding transport R3
thebtf d22ebb9
feat(security): enforce project identity v2 barriers
thebtf 369951b
docs(evidence): repair embedding transport R4
thebtf 9e2ce4e
fix(security): harden project identity fail-closed edges
thebtf 37d185b
docs(governance): reconcile production scope map r8
thebtf a538f62
docs(evidence): make embedding coverage capture reproducible
thebtf 406fe95
ci(release): harden r8 scope and package gates
thebtf 3834445
fix(security): close project identity R3 races
thebtf 8cb8100
PLAN-GOVERNANCE-R9: freeze exact candidate path authority
thebtf ffdbaef
test(security): add project identity process rail
thebtf 320f1d8
chore(security): align R4 authority scope
thebtf f11a77c
Release gates: enforce R9 frozen candidate authority
thebtf a1a3bfe
evidence: bind embedding coverage to process envelopes
thebtf 30de64d
Merge commit 'b0955dfd61b4ea7364f6d400579247b475a1a680' into work/prc…
thebtf 1a11a65
Merge commit 'da97c88be6753703bac112be8431dc373e4d9dda' into work/prc…
thebtf 92c5398
Merge commit '0d5cfa5c67ddbc331d7e812f98679742541b32ca' into work/prc…
thebtf 20b340f
Merge commit '2ab6211494e51aeb7b787a99e78cff8bf2d5694a' into work/prc…
thebtf e00c084
Merge commit '320f1d806729085f56e91b505b738444408639e1' into work/prc…
thebtf badfb3c
Merge commit '276337b3e96aa5af6d2e7dd9a0002ff957e5ffc9' into work/prc…
thebtf 0c62699
Merge commit 'a1a3bfeb6546d1f3f24192b1c9f057402b6249a2' into work/prc…
thebtf 331b5b1
docs(evidence): fail closed DB pool hygiene packet
thebtf af1ed63
PLAN-GOVERNANCE-R10: own trusted authority guard
thebtf 1418796
test(mcp): align T007 flag-off visibility assertion
thebtf 637adf0
review(t007): record independent compatibility verdict
thebtf ce6a40d
Evidence R4: harden DB pool hygiene packet
thebtf 2c88fed
fix: harden demolition portability contracts
thebtf 2af6882
review(dbph): accept R4 evidence packet
thebtf 8923f2a
review: accept demolition portability r1
thebtf 2bd2e7b
Merge commit '2af6882d8fae89540c159c724e18c4d65668c6f6' into work/prc…
thebtf 24b77c2
Merge commit '8923f2ac79dddbd7812dba1b5d6c950653c0a7b1' into work/prc…
thebtf fef455b
Merge commit '637adf0e6a2d34355c854c9c9e27e107eed4c35f' into work/prc…
thebtf 65837cc
Harden immutable image publication
thebtf 1bbda20
fix(mb1): isolate governance and literal selectors
thebtf ef763e5
test(mb1): prove candidate review rollback
thebtf 310f948
fix(mb1): demolish executable ingest snapshots
thebtf e86cf65
fix(mb1): reject lossy mutation inputs
thebtf cc83b97
fix(mb1): fail closed in dream crystallization
thebtf 0983333
test(mb1): prove deterministic vector retrieval
thebtf 8b60aa5
test(mb1): enforce static embed contract
thebtf 5449a23
fix(mb1): prove pre-v5 upgrade safety
thebtf 05b341c
fix(mb1): close migration and document coercion edges
thebtf e85c0e6
test(mb1): isolate governance batch proofs
thebtf a6a88b8
fix(images): skip non-release workflow runs
thebtf a693d09
feat(observability): wire opt-in OTLP metrics runtime
thebtf 0b51293
test(observability): prove hostile OTLP exporter paths
thebtf 17dcfad
test(observability): prove trusted OTLP TLS transport
thebtf befa372
test(recovery): prove PostgreSQL backup restore
thebtf 953e006
fix(observability): flush fatal startup diagnostics
thebtf 88fb24a
docs(mb1): sync migration-derived data model
thebtf f121f90
test(recovery): harden freeze evidence
thebtf 937a2c9
fix(operator-console): report graph runtime truth
thebtf b5c3c3f
test(operator-console): replay graph truth and accessibility
thebtf e0044f3
fix(observability): serialize runtime lifecycle ownership
thebtf 3e91ec6
test(observability): gate concurrent runtime ownership
thebtf f8e2921
fix(recovery): make restore atomic and secret-safe
thebtf 91c2632
test(observability): stress repeated runtime transitions
thebtf 1e569f3
test(recovery): freeze R2 recovery evidence
thebtf 88604f1
test(deploy): define production rollback contract
thebtf 79d3283
feat(deploy): harden runtime and prove rollback
thebtf 4311109
evidence(deploy): record current source research
thebtf 6786e01
fix(operator-console): make graph async state latest-wins
thebtf dfa1d66
test(operator-console): replay hostile graph races
thebtf 981b11a
fix(mb1): make recovery and schema truth portable
thebtf 3e8ed6e
test(mb1): prove repeatable customer data gates
thebtf 1a9a88c
fix(operator-console): keep newest graph action notice
thebtf 8dea63b
fix(recovery): scavenge interrupted restore residue
thebtf db6e28a
test(release-gates): record closed-world authority red
thebtf d4ffc5e
fix(release-gates): validate authority as closed world
thebtf 6f0a11c
docs(release-gates): freeze R15 authority evidence
thebtf 43b3c0b
fix(release-gates): make authority proof transplant-safe
thebtf 24d8ab6
chore(release-gates): materialize portable authority snapshot
thebtf 42705af
fix(release-gates): ship immutable macro authority source
thebtf faa0242
review(observability): accept R2 lifecycle repair
thebtf e65b483
feat(config): load runtime secrets from files
thebtf a04e2de
fix(deploy): secure rollback inputs and interrupted cleanup
thebtf 605ea01
test(deploy): bind secure rollback replay evidence
thebtf 33828fc
test(mb1): tolerate persistent global rule fixtures
thebtf 0538250
fix(mb1): reuse normalized write-lint target id
thebtf 5b32c4f
docs(mb1): record SOL takeover acceptance
thebtf d4f6dc2
merge: synthesize MB1 data integrity
thebtf 186564a
merge: synthesize operator console graph truth
thebtf 1d4541b
merge: synthesize recovery data
thebtf a766e6f
merge: synthesize observability lifecycle
thebtf 6e50fd9
merge: synthesize deploy rollback
thebtf 15cc5a3
test(auth): isolate gRPC token acceptance probe
thebtf d6b3375
test(ui): make rules replay state-independent
thebtf 888708b
feat(observability): wire production runtime call sites
thebtf 5722882
fix(release): make integration gates reproducible
thebtf 9282f32
test(security): guard Nuxt UI advisory reachability
thebtf cce0832
fix(build): fail closed on missing native optionals
thebtf af77359
fix(security): close release review findings
thebtf 08987dd
fix(deploy): pass version to operator build
thebtf 8279d22
fix(deploy): build project postgres in dev stand
thebtf File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,83 @@ | ||
| version: 1 | ||
|
|
||
| test_glob: "tests/critical/**/*.{go,py,ts,js,rs,cs,sh}" | ||
| categories: | ||
| - smoke | ||
| - behavioral | ||
| - data-consistency | ||
| dev_stand_required: true | ||
| fail_on_missing: error | ||
| timeout_minutes: 30 | ||
|
|
||
| runner: | ||
| command: "go test -tags=critical -json ./tests/critical/... -count=1" | ||
| transcript_parser: "pwsh -NoProfile -File scripts/production-gates/assert-go-test-json.ps1 -FailOnUnexpectedSkip" | ||
| fail_on_unexpected_skip: true | ||
| allowed_skip_identities: [] | ||
|
|
||
| database_gate: | ||
| command: "pwsh -NoProfile -File scripts/production-gates/run-db-suite.ps1 -FreshDatabase -Package ./... -Race -FailOnUnexpectedSkip" | ||
| postgres_image: "pgvector/pgvector:pg17" | ||
| repeat_source: "run-db-suite.ps1 default (3); callers do not duplicate the value" | ||
| fresh_database_per_repeat: true | ||
| schema: "public" | ||
| package_parallelism: 1 | ||
| test_parallelism: 1 | ||
| race_detector: true | ||
| connection_budget: 20 | ||
| post_test_sessions_required: 0 | ||
| cleanup_required: true | ||
|
|
||
| coverage: | ||
| profile_required_on_all_operating_systems: true | ||
| overall_statement_minimum_percent: 60 | ||
| assertion_command: "pwsh -NoProfile -File scripts/production-gates/assert-coverage.ps1 -CoverageProfile coverage.out -OverallThreshold 60" | ||
| package_statement_minimum_percent: | ||
| "internal/module/": 75 | ||
| "internal/handlers/engramcore": 60 | ||
| "internal/handlers/loom": 70 | ||
| "cmd/engram/": 10 | ||
| "cmd/engram-server/": 10 | ||
| "internal/update/": 20 | ||
| "internal/worker/": 55 | ||
| "internal/mcp/": 55 | ||
| "internal/db/gorm/": 55 | ||
| critical_path_mapping: | ||
| launcher: "cmd/engram/" | ||
| server: "cmd/engram-server/" | ||
| update: "internal/update/" | ||
| worker: "internal/worker/" | ||
| mcp: "internal/mcp/" | ||
| database: "internal/db/gorm/" | ||
|
|
||
| evidence: | ||
| root: ".agent/reports/evidence/production-ready/release-gates-foundation" | ||
| require_raw_stdout: true | ||
| require_raw_stderr: true | ||
| require_machine_summary: true | ||
| require_child_exit_codes: true | ||
| require_database_schema_identity: true | ||
| require_pg_stat_activity: true | ||
| require_cleanup_result: true | ||
|
|
||
| security: | ||
| image_scan: | ||
| command: "pwsh -NoProfile -File scripts/production-gates/run-db-suite.ps1 -DevStandAction Scan -ComposeProject engram-critical-stand -ComposeFile docker-compose.yml" | ||
| discovery: "compose labels for project engram-critical-stand" | ||
| scanner: "docker scout cves" | ||
| severities: ["critical", "high"] | ||
| fail_on_findings: true | ||
| machine_evidence: "dev-stand/<run-id>-scan/docker-scout-*.sarif.json plus summary.json" | ||
| exact_service_images: | ||
| postgres: "ghcr.io/thebtf/engram-postgres:main" | ||
| server: "ghcr.io/thebtf/engram:main" | ||
| operator-console: "ghcr.io/thebtf/engram-operator-console:main" | ||
| forbidden_synthetic_tags: | ||
| - "engram:prc-candidate" | ||
| govulncheck: | ||
| authoritative_modes: | ||
| - "source scan with tests: govulncheck -test ./..." | ||
| - "unstripped binary scan before -ldflags=-s -w" | ||
| non_authoritative_modes: | ||
| - "stripped binary scan: absence of symbols forces module-level fallback" | ||
| rule: "A stripped-binary finding cannot override source/test or unstripped-binary reachability evidence." | ||
72 changes: 72 additions & 0 deletions
72
.agent/debug/lightningcss-linux-native-missing/investigation.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,72 @@ | ||
| # Investigation: intermittent missing Lightning CSS Linux native package | ||
|
|
||
| Status: RESOLVED_IN_BATCH | ||
|
|
||
| ## 1. Symptom | ||
|
|
||
| Verbatim error from the exact-head clean Docker image gate: | ||
|
|
||
| ```text | ||
| ERROR Cannot find module '../lightningcss.linux-x64-gnu.node' | ||
| Require stack: | ||
| - /workspace/apps/operator-console/node_modules/lightningcss/node/index.js | ||
| ``` | ||
|
|
||
| The failure occurs during `npm run build` inside the Linux/amd64 Docker operator-console build stage after `npm ci` exits successfully. | ||
|
|
||
| ## 2. Reproduction | ||
|
|
||
| Status: CONFIRMED INTERMITTENT | ||
|
|
||
| - `build-and-scan-images.ps1` on commit `5722882e` completed PASS; its clean build installed 840 packages. | ||
| - The same no-cache gate on commit `9282f324` failed during the server target's shared operator-console build; `npm ci` installed 839 packages and the Lightning CSS Linux native module was absent. | ||
| - The two commits do not change `package.json` or `package-lock.json`; the second commit adds only a Go critical guard and evidence. | ||
| - Target environment: Docker Desktop Linux/amd64 builder, Node 22 bookworm-slim, npm 10.9.8. | ||
|
|
||
| ## 3. Competing hypotheses | ||
|
|
||
| | ID | Claim | Prediction | Disproving test | Disproving test result | Status | | ||
| |---|---|---|---|---|---| | ||
| | H1 | The local lock graph omits the platform-specific Lightning CSS package. | `package-lock.json` lacks `lightningcss-linux-x64-gnu` or its parent optional edge. | Parse the lock structurally. | REFUTED: lock contains Lightning CSS 1.32.0, all eleven platform variants, and the exact Linux x64 GNU edge/package. | REFUTED | | ||
| | H2 | A fetch/extract failure silently omitted the target because npm models the native package as optional. | Complete lock plus successful `npm ci` exit can coexist with 839 packages and a later native require failure; deliberately making only the target tarball unavailable should reproduce this shape. | Repeat clean installs, then mutate only the disposable target `resolved` URL to an unreachable endpoint and observe npm exit plus native require. | CONFIRMED: target-only unreachable URL produced 839 packages, `npm ci` exit 0, and the identical `Cannot find module '../lightningcss.linux-x64-gnu.node'` stack. | CONFIRMED | | ||
| | H3 | Dockerfile or environment selects the wrong platform/architecture or strips optional dependencies. | `process.platform/arch`, npm config, or Dockerfile flags show non-linux/non-x64 or `omit=optional`. | Capture platform/arch/npm config in the same builder image. | REFUTED: two pinned builder runs report linux/x64 and empty omit config, and resolve the GNU native package. | REFUTED | | ||
| | H4 | The Nuxt advisory guard commit changed the operator dependency graph. | Diff `5722882e..9282f324` includes package manifest/lock changes. | Inspect exact git diff names. | OBSERVED: diff contains no operator package manifest or lock change. | REFUTED | | ||
|
|
||
| ## 4. Evidence classification | ||
|
|
||
| | Fact | Class | Source | | ||
| |---|---|---| | ||
| | Exact missing-module stack and Linux build stage | OBSERVED | `.agent/tmp/image-gate-9282f324/server/build.log` and failed gate output | | ||
| | Prior exact gate passed from the same dependency lock | OBSERVED | `.agent/tmp/image-gate-5722882e/final-image-set.json` status PASS | | ||
| | Successful run installed 840 packages; failed run installed 839 | OBSERVED | the two image-gate build transcripts | | ||
| | Package manifests were unchanged between exact commits | OBSERVED | scoped commit contents and prior PR diff | | ||
| | npm optional-dependency lock behavior may be causal | INFERRED | requires current official/upstream source confirmation | | ||
| | npm treats unsupported optional platform packages as inert rather than fatal | OBSERVED | Context7 current `/npm/cli` source excerpt from Arborist `build-ideal-tree.js` | | ||
| | npm/cli #4828 describes inconsistent package locks that silently omit another platform's optional native package | OBSERVED | Parallel fetch of official npm/cli issue #4828, updated 2026-06-30 | | ||
| | npm/cli #8320 reproduces the class on npm 10.9.2 and 11.4.1 with Node 22 | OBSERVED | Parallel fetch of official npm/cli issue #8320 | | ||
| | Lightning CSS maintainers linked the exact missing native-module error to npm/cli #4828 | OBSERVED | Parallel fetch of official parcel-bundler/lightningcss issue #567 | | ||
| | Engram memory contains prior project guidance for this failure | OBSERVED FALSE | live Engram recall returned zero memories | | ||
| | A fresh external structured-reasoning pass is available through aimux | OBSERVED FALSE | aimux returned non-retryable `CapabilityMismatch`: Loom SQLite session store unavailable | | ||
| | Clean Linux install environment is accidentally non-x64 or omits optional packages | OBSERVED FALSE | two disposable Node 22 bookworm-slim runs reported linux/x64, npm 10.9.8, empty omit config, 840 packages, and successful native package resolution | | ||
| | Failed image gate leaked build context, secret files, containers, volumes, or networks | OBSERVED FALSE | FAIL manifest records build-context cleanup true, cleanup PASS, secret files cleaned true; live prefixed residue query returned zero rows | | ||
| | npm/cli PR #8184 addresses the ideal/hidden-lock cause and shipped in npm 11.3.0 | OBSERVED | Parallel fetch of official merged PR #8184 and linked 11.3.0 release event | | ||
| | Upgrading npm alone is proven sufficient | OBSERVED FALSE | official npm/cli #8320 reports the related cross-platform lock failure on npm 11.4.1; an upgrade remains a hypothesis, not a verified fix | | ||
| | npm's successful exit proves the Linux native binding exists | OBSERVED FALSE | target-only failure injection completed `npm ci` successfully with 839 packages, then failed the native require with the original stack | | ||
|
|
||
| ## 5. Hypothesis status log | ||
|
|
||
| - H4 REFUTED: the only change between the successful and failed exact heads is the critical advisory guard/evidence; operator dependency inputs are byte-identical. | ||
| - H2 strengthened by three upstream issue records, including npm 10/11 reproduction and the exact Lightning CSS error. H3 remained active pending lock inspection and a minimal repeated Linux install. | ||
| - H3 REFUTED: two clean pinned builder-container diagnostics prove linux/x64 selection, optional dependencies enabled, and successful native resolution. H2 remains possible because the exact full build produced 839 packages once while two subsequent minimal installs produced 840. | ||
| - H1 REFUTED for this repository: structural JSON inspection shows Lightning CSS 1.32.0 plus all platform packages, including `lightningcss-linux-x64-gnu`, are present in the committed lock. | ||
| - SocratiCode semantic index did not reach its graph phase within the bounded debug window (55%, batch 13); Engram semantic fallback returned zero results. The fallback was a narrow structural JSON query, not broad text search. | ||
| - H2 CONFIRMED: a disposable lock mutation changed only the target native package URL. npm exited 0 with 839 packages, and `require('lightningcss')` produced the same missing GNU binding stack. This directly reproduces the product failure class without changing the repository. | ||
| - A package-specific in-place repair was rejected after two failed probes (`ERR_INVALID_ARG_TYPE`, then a 300-second timeout) and a structural lock query found nine native-parent families. The repair target was widened to the whole applicable optional-native class. | ||
| - The final verifier selects every optional lock entry applicable to the running OS, CPU, and Linux libc, requires the exact installed version, and fails before Nuxt. A clean pinned Linux/glibc install checked 12 packages; the injected 839-package tree failed with the exact missing `lightningcss-linux-x64-gnu@1.32.0` identity. | ||
| - Full acceptance passed 201/201 critical tests with zero skips and repository-relative evidence after the parser stdout portability discrepancy was found and fixed. | ||
|
|
||
| ## 6. Root cause | ||
|
|
||
| The Linux builder treats `lightningcss-linux-x64-gnu@1.32.0` as transitively optional, so npm 10.9.8 can exit successfully after failing to materialize that runtime-required binding; the Docker build trusts the exit code and discovers the absence only when Nuxt loads Lightning CSS. Evidence chain: complete target lock entry + correct linux/x64/optional-enabled environment + target-only failure injection -> 839 packages/npm exit 0 -> identical native-module stack. H1, H3, and H4 are refuted; no assumed link remains. | ||
|
|
||
| Implemented class-level fix: retain immutable `npm ci`, explicitly include optional packages, add bounded registry retries, then run the lock-driven OS/CPU/libc verifier before Nuxt. No second install and no lock mutation are allowed. The exact-commit image gate remains the next acceptance boundary; this investigation is resolved at the reproduced project-boundary defect and implementation level, not yet at release level. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,59 @@ | ||
| version: 1 | ||
| shape: docker-compose | ||
|
|
||
| # The critical stand is isolated from ordinary local compose state by project | ||
| # name and non-default host ports. The critical-suite runner exports the env | ||
| # below before invoking the lifecycle commands. | ||
| up: | ||
| command: "pwsh -NoProfile -File scripts/production-gates/run-db-suite.ps1 -DevStandAction Up -ComposeProject engram-critical-stand -ComposeFile docker-compose.yml" | ||
| readiness_check: "pwsh -NoProfile -File scripts/production-gates/run-db-suite.ps1 -DevStandAction Ready -ComposeProject engram-critical-stand -ComposeFile docker-compose.yml" | ||
| timeout_seconds: 600 | ||
| down: | ||
| command: "pwsh -NoProfile -File scripts/production-gates/run-db-suite.ps1 -DevStandAction Down -ComposeProject engram-critical-stand -ComposeFile docker-compose.yml" | ||
| timeout_seconds: 180 | ||
| logs: | ||
| command: "docker compose -p engram-critical-stand -f docker-compose.yml logs --no-color --tail=300" | ||
|
|
||
| env: | ||
| COMPOSE_PROJECT_NAME: "engram-critical-stand" | ||
| POSTGRES_PORT: "55433" | ||
| WORKER_PORT: "37778" | ||
| OPERATOR_CONSOLE_PORT: "3001" | ||
| STAND_API_URL: "http://localhost:37778" | ||
| STAND_OPERATOR_URL: "http://localhost:3001" | ||
| NUXT_OPERATOR_API_TARGET: "http://server:37777" | ||
| ENGRAM_AUTH_DISABLED: "false" | ||
|
|
||
| credential_policy: | ||
| generation_scope: "four independent cryptographic 256-bit values generated inside the Up runner process" | ||
| postgres_password: "generated cryptographically inside the Up runner process" | ||
| admin_token: "generated cryptographically inside the Up runner process" | ||
| vault_key: "generated cryptographically inside the Up runner process" | ||
| bootstrap_capability: "generated cryptographically inside the Up runner process" | ||
| postgres_runtime_interface: "ENGRAM_POSTGRES_PASSWORD_SECRET_FILE plus ENGRAM_DATABASE_DSN_SECRET_FILE" | ||
| admin_runtime_interface: "ENGRAM_AUTH_ADMIN_TOKEN_SECRET_FILE" | ||
| bootstrap_runtime_interface: "ENGRAM_AUTH_BOOTSTRAP_CAPABILITY via ephemeral compose override" | ||
| required_distinct: true | ||
| forbidden_defaults: ["engram", "password", "changeme", "change-me", "change-me-in-production", "default", "admin"] | ||
| persistence: "never written to raw logs, machine summaries, config, or caller environment" | ||
| auth_disabled_fallback: false | ||
|
|
||
| image_scan: | ||
| command: "pwsh -NoProfile -File scripts/production-gates/run-db-suite.ps1 -DevStandAction Scan -ComposeProject engram-critical-stand -ComposeFile docker-compose.yml" | ||
| discovery: "docker service inventory filtered by com.docker.compose.project=engram-critical-stand" | ||
| scanner: "docker scout cves" | ||
| severities: ["critical", "high"] | ||
| fail_on_findings: true | ||
| machine_evidence: "dev-stand/<run-id>-scan/docker-scout-*.sarif.json plus summary.json" | ||
| exact_service_images: | ||
| postgres: "ghcr.io/thebtf/engram-postgres:main" | ||
| server: "ghcr.io/thebtf/engram:main" | ||
| operator-console: "ghcr.io/thebtf/engram-operator-console:main" | ||
| forbidden_synthetic_tags: | ||
| - "engram:prc-candidate" | ||
|
|
||
| database_evidence: | ||
| runner: "pwsh -NoProfile -File scripts/production-gates/run-db-suite.ps1" | ||
| postgres_image: "pgvector/pgvector:pg17" | ||
| database_lifecycle: "fresh unique database per repetition; cleanup owns only engram_prc_rg_* databases" | ||
| shared_service_policy: "Never stop or remove an operator-owned PostgreSQL container; only terminate/drop the current run database." |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,98 @@ | ||
| { | ||
| "schema_version": 1, | ||
| "gate": "full-project-fresh-db-race-repeat-3", | ||
| "verdict": "FAIL", | ||
| "repeat_test_failures": [27, 28, 27], | ||
| "stable_failed_tests": { | ||
| "internal/bulkops": [ | ||
| "TestEC_F3_ConflictDetected_Integration", | ||
| "TestFacade_BulkDelete_Committed_AuditLogWritten", | ||
| "TestFacade_BulkSupersede_Committed_AuditLogWritten", | ||
| "TestRollback_HappyPath" | ||
| ], | ||
| "internal/db/gorm": [ | ||
| "TestMigration144_RuleGovernanceEscapeConstraints", | ||
| "TestMigration144_RuleGovernanceRollbackAndReapply", | ||
| "TestMigration144_RuleGovernanceSnapshotStatusesAcceptExtendedStates", | ||
| "TestRuleGovernanceStore_AnnotatedCandidateWaitsUntilReviewAfter", | ||
| "TestRuleGovernanceStore_GetLifecycleHealthAggregatesGovernanceTables", | ||
| "TestRuleGovernanceStore_GetLifecycleHealthOmitsGlobalArbiterRunsForProjectScopedReads" | ||
| ], | ||
| "internal/embedding": [ | ||
| "TestStatsWithCoverage_NoActiveMemories", | ||
| "TestStoreStats_Empty" | ||
| ], | ||
| "internal/graph": [ | ||
| "TestDangling_T016_DanglingEdgeReturnsFlag", | ||
| "TestPathC_T015_NodeCreatedAtTimestamp", | ||
| "TestPathC_T015_NodeTypedEdgeListFilter", | ||
| "TestPathC_T015_SkillNodeEdgeRoundtrip" | ||
| ], | ||
| "internal/mcp": [ | ||
| "TestEC_F1_TagDerivedBackfill_T007", | ||
| "TestHybridTG3_ConfidenceMin_FloorEnforced_T022" | ||
| ], | ||
| "internal/worker": [ | ||
| "TestAuthHandlersLifecycle_DisabledAdminCanBeDemotedWithoutLastAdminError", | ||
| "TestAuthHandlersLifecycle_LastAdminDemoteRaceLeavesOneAdmin", | ||
| "TestCrystallizationIntegration_ConcurrentReplaySkipsDuplicateFingerprint", | ||
| "TestCrystallizationIntegration_DecisionsStoredWithCorrectFields", | ||
| "TestCrystallizationIntegration_PrivacyRedaction", | ||
| "TestHandleCreateBehavioralRule_Success", | ||
| "TestHandleListBehavioralRules_ProjectScope", | ||
| "TestHandleSetBehavioralRuleEnabled_Success" | ||
| ], | ||
| "internal/worker/reaper": [ | ||
| "TestReaper_RespectsRetentionEnvVar: panic because t.Setenv is used under t.Parallel" | ||
| ] | ||
| }, | ||
| "repeat_2_only_failure": "internal/bulkops::TestRollback_Conflict_EC_F3", | ||
| "unexpected_skips_each_repeat": 25, | ||
| "unexpected_skip_inventory": [ | ||
| "internal/db/gorm::TestMigrationsIntegration_AddsCommandsRunColumn", | ||
| "internal/grpcserver::TestCredentialDecryptRoundTripAfterMigration", | ||
| "internal/grpcserver::TestEC_F1_P1_GRPCSessionStart_FlagOff_ByteIdentity", | ||
| "internal/grpcserver::TestEC_F1_P1_GRPCSessionStart_FlagOn_NoCallerIdentity_PrivateInvisible", | ||
| "internal/grpcserver::TestEC_F1_P1_GRPCSessionStart_FlagOn_PrivateCrossWorkstationInvisible", | ||
| "internal/grpcserver::TestGetSessionStartContext_DefaultLimits", | ||
| "internal/grpcserver::TestGetSessionStartContext_HappyPath", | ||
| "internal/grpcserver::TestGetSessionStartContext_MetaSummaryCountsBeyondResponseCap", | ||
| "internal/grpcserver::TestGetSessionStartContext_MetaSummaryFlagOffOmitted", | ||
| "internal/grpcserver::TestGetSessionStartContext_MetaSummaryFlagOnDescribesMemoryLandscape", | ||
| "internal/grpcserver::TestGetSessionStartContext_MetaSummaryFlagOnEmptyProjectIsBoundedAndContentFree", | ||
| "internal/grpcserver::TestGetSessionStartContext_PrincipalPrivateCrossPrincipalInvisible_FlagOff", | ||
| "internal/grpcserver::TestGetSessionStartContext_RuleRouterEnabledPacketShape", | ||
| "internal/grpcserver::TestGetSessionStartContext_T014_MetaSummaryRequiresMasterAndS2Flags", | ||
| "internal/handlers/loom::TestCliWorker_ContextCancellation", | ||
| "internal/handlers/loom::TestCliWorker_EmptyStdoutTriggersRetry", | ||
| "internal/handlers/loom::TestCliWorker_EnvMerge", | ||
| "internal/handlers/loom::TestCliWorker_HappyPath", | ||
| "internal/handlers/loom::TestCliWorker_InvalidEnvKey", | ||
| "internal/handlers/loom::TestCliWorker_StderrCapture", | ||
| "internal/handlers/loom::TestCliWorker_Timeout", | ||
| "internal/redaction::TestEC_F5_FullRedactionRejected", | ||
| "internal/redaction::TestEC_F9_HotReloadNotSupported", | ||
| "internal/retrieval::TestIntegration_HybridWithVector", | ||
| "internal/worker::TestStaticEmbedIncludesUnderscoreNuxtChunks" | ||
| ], | ||
| "coverage": { | ||
| "overall_percent": [53.0, 52.99, 52.99], | ||
| "overall_floor": 60.0, | ||
| "failed_package_floors": { | ||
| "internal/handlers/loom": "64.77 < 70", | ||
| "cmd/engram": "6.39 < 10", | ||
| "cmd/engram-server": "0 < 10", | ||
| "internal/update": "0 < 20", | ||
| "internal/worker": "46.77 < 55", | ||
| "internal/mcp": "46.23 < 55", | ||
| "internal/db/gorm": "49.10 < 55" | ||
| } | ||
| }, | ||
| "cleanup": { | ||
| "repeat_cleanup_exit_codes": [0, 0, 0], | ||
| "direct_sql_residual_databases": 0, | ||
| "direct_sql_residual_sessions": 0, | ||
| "shared_postgres_container_left_running": true | ||
| }, | ||
| "routing": "Existing master-plan lanes own these product/test/coverage blockers. RELEASE-GATES does not allowlist, suppress, or patch them." | ||
| } |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There is an inconsistency in the trailing slashes of package paths. For example,
"internal/handlers/engramcore"and"internal/handlers/loom"do not have trailing slashes, whereas other packages like"internal/module/"and"cmd/engram/"do. This inconsistency can lead to brittle path matching in the coverage assertion scripts. Standardizing the format by removing trailing slashes across all package keys is recommended.