Repository navigation
Conversation
HEAD archive owner-preflight and fake-SQL contracts passed offline. Live validation is not included.
Checkpoint only: explicit prepared/active/halted metadata and pinned policy/config/period identity, with UNKNOWN historical usage. Runtime accounting is not connected; actual spending limits are not enforced by this lifecycle layer. No reserve/settle, provider, runner, DAV-53 or U03 integration is included. Live acceptance remains pending. Verified in the f466d9c HEAD archive: independent import and 48 focused temporary-path tests pass; scope/secret scans and diff checks pass.
Checkpoint only: runtime binding candidate has a known SQLite descriptor lifetime blocker. Focused proof: 79 passed, 2 failed; original 57 regression tests pass. No runner/provider wiring, live initialization or activation; live acceptance remains open. Preserve UNKNOWN history and original worktree WIP.
Checkpoint: avoid auxiliary ledger descriptors while SQLite connections are open; verify bound inode identity with stat and use SQLite FULL synchronization. Preserve canonical configuration and shared atomic period accounting. Focused temporary-environment regression proof passed; no runner/provider wiring or live initialization, activation or acceptance. Historical spend remains UNKNOWN.
Checkpoint: bind only the standalone DAV58 runner to an explicitly selected existing active canonical period. Preserve legacy no-argument authorization callers, shared purpose accounting and historical UNKNOWN spend. Focused temporary SQLite and MockTransport verification passed; no real key, provider request, period preparation or activation. Provider effectiveness flags remain false and live acceptance remains open.
Resolves the two conflicted paths, keeping both sides' intent: - services/agent/README.md: main restructured this file so the canonical guide (docs/DEVELOPMENT.md) owns the detailed contracts, and the block removed here was the only branch-only content in the file. Take main's structure, and keep the two new opt-in runners discoverable through a short pointer section rather than a second copy of the guide. - services/agent/src/deepseek_model.py: keep this branch's shared-budget reservation, settlement and fail-closed accounting guard, while taking main's extraction of `_api_messages` and `_check_prompt_budget`. The auto-merge also spliced `decide()` outside the conflict markers: main's `_check_prompt_budget` made `prompt_tokens_estimate` a local, while `reserve()` still needed it. The estimate now has a single owner, `_prompt_tokens_estimate()`, called by both the check and `decide()`. Verified on this merge: services/agent 1124 passed / 1 skipped (optional qdrant_client absent); `./mvnw compile -B` BUILD SUCCESS; focused LearningPlan gate 35 passed, including LearningPlanWriteIT's 6 real-MySQL Testcontainers idempotency and owner-scoping tests. Co-Authored-By: Claude Code <noreply@anthropic.com>
Keep model tools read-only and require explicit confirmation before Java\nlearning-plan writes. Persist private workflow state and reconcile unknown\nwrites through the original idempotency key.\n\nBind acceptance evidence to source, budget identity, and raw receipts.\nMissing original accounting or unauthorized purposes remain fail-closed;\noffline checks never grant spend or mark real acceptance complete.
fix: preserve safe network diagnostics through budget recovery
fix(agent): propagate reviewed U02 repairs into the V12 stack
fix(agent): integrate V12 binding and reviewed U02 safeguards
…vations fix: enforce required prior evidence observations
feat: bind acceptance v11 to sealed v10 accounting
fix: define evidence and behavior rules for development judging
fix: bind fresh acceptance to sealed V9 history
fix: align U02 source refusal checks and boundary provenance
fix: retain sealed v8 history in fresh acceptance binding
fix: share guarded transport across fresh boundary evaluation
fix: retain sealed v7 liabilities in authorized v8 allowance
fix: bind boundary settlement and judge evidence
fix: validate boundary corpus digest against loaded text
fix: bind acceptance package to sealed v6 liabilities
fix: execute requested authorized read-only actions
fix: require and recognize direct submission clarification
fix: recover DeepSeek acceptance while retaining unknown usage
…stics fix: preserve safe diagnostics for isolation protocol failures
|
| GitGuardian id | GitGuardian status | Secret | Commit | Filename | |
|---|---|---|---|---|---|
| 38100875 | Triggered | Generic Password | 1733278 | services/agent/tests/test_agent_store.py | View secret |
🛠 Guidelines to remediate hardcoded secrets
- Understand the implications of revoking this secret by investigating where it is used in your code.
- Replace and store your secret safely. Learn here the best practices.
- Revoke and rotate this secret.
- If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.
To avoid such incidents in the future consider
- following these best practices for managing and storing secrets including API keys and other credentials
- install secret detection on pre-commit to catch secret before it leaves your machine and ease remediation.
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Current engineering verification
Current head 9ff372e integrates main cae43e4, including backend security/dependency repairs and release 1.0.2. Merge conflicts are resolved, with three main-integration reviews and two release-increment reviews approved. Agent source code and CoreEnabledOwnerJourneyIT remain byte-identical to original delivery head736; the only Agent data change refreshes DEVELOPMENT/OPERATIONS whole-file versions and matching chunk IDs, with all five excerpt digests, license/scope, loader, cases, and ledger unchanged. Two reviews approved that four-line repair.
Integration head d1a produced1657 passed, three corpus version failures, and one optional qdrant dependency skip; the version failures motivated the manifest repair. Exact current-head9ff remote locked-dependency full unit tests passed:1660 passed,1 optional qdrant skip,174.40s,exit0. CI38127164786 completed SUCCESS on exact9ff, with23 applicable checks passed. The previous CI38126769818 was superseded and cancelled. AST refresh on d1a completed with exit0; SQL parser coverage remains incomplete. Historical359 regressions and CI38111860861 SUCCESS apply to head736, not the new integration. Original review threads in PR239/243/245/252/253/254/255/257 were resolved after actual-head propagation.
This PR remains Draft: U02 formal acceptance is incomplete, V12 is permanently halted and three unknown-usage liabilities remain; downstream U03/U04 and genuine personal/research evidence are not proven by CI. Separate U03 DB/dependency slice remains Draft PR260. Independent dotenv PR251 merged into main29309e642; it does not waive this delivery's prerequisites. Historical details below retain their original evidence dates and statuses.
当前候选与验收绑定
当前修复链:PR239(66d2223ca)精确CI38025933796 SUCCESS,但合并被环境自动审批策略拒绝(approval required / Never);PR240(fc4eefe7b)精确CI38026335932 SUCCESS,172协议回归+11语料回归与实际5文档加载通过,正在标记Ready。PR241(4f488c5218360436add469f3d76abacdc497cefe)预算绑定153远端回归通过、真实21历史指纹一致、两项独立审查通过,精确CI38026855548运行中。
V6已实际封存105settled/0新增unknown;V7已PREPARED_BOUND_NOT_ACTIVE,fresh0,未调用付费模型。新绑定保留523历史/2unknown,总保守责任8.8272美元低于累计USD100,不重置或释放历史。DAV53真实隔离仍INCOMPLETE,U02/U03/U04与旧holdout连续性仍待验收;PR231保持Draft。
Current candidate runtime and development replay evidence
At
e1f5658fb1bd212b4491f60a9adc3a9c15da79e0, strict replay verified all 80 real development exchanges and reconciled 84 settled V6 receipts; response tampering was rejected with zero new provider calls. The two actual execution heads remain distinct (first pass1ed2d8802032b3f48765a13b56e9ba2410656d8a, second pass current head). Replay proof SHA256868d114fad3244be31d9310798274e3e74d76d1e7e76235a8a3d1090eeaee245. Both passes matched 20/20 behaviors but each had 2 incomplete answers; this is not blanket quality acceptance.Supported remote startup now verifies Auth/App public readiness 200 and actual Java process working directories in the clean current-head checkout. Runtime proof SHA256
4a0ba939f18c043779024e582ea4f1a317a5025488377d79db9fc7c6296efe29. The existing container-backed migration probe passed; task-only Maven test-compilation skipping prevented startup from repeatedly exceeding the unchanged PM2 memory limit. Startup did not run tests; existing exact-head CI and Agent tests remain separate evidence.Cumulative USD100 authorization retains historical 418 attempts and both unknown liabilities. Current DAV-53 live contrast is running once under its original 12-call purpose cap; no outcome is claimed yet. Legacy holdout continuity, U03, U04, human acceptance and main delivery remain unfulfilled. This PR stays Draft.
Current delivery head: e1f5658. Sealed-history performance repair PR #238 is merged into this task branch (not main). Full remote Agent suite: 1531 passed; focused budget suite: 202 passed. Exact-head CI workflow_dispatch 38018921774 completed successfully. All 18 archive fingerprints verified; 418 historical attempts and both unknown liabilities retained; altered fingerprint rejected. Validation profile fell from 49.374s to 4.014s, not an end-user benchmark.
The ongoing paid development pass remains bound to the isolated 1ed2d88 candidate; results will retain their real execution provenance and need explicit replay/revalidation before binding to the new head. Auth/App packaging at 1ed2d88 passed and JAR digests were captured; existing running services still come from the earlier validation checkout, so this is not current-runtime/U03 proof. Cumulative USD100 authorization remains enforced. This PR stays Draft until actual acceptance and delivery requirements finish.
Latest verification at
1ed2d8802032b3f48765a13b56e9ba2410656d8a: CI38016183874 completed successfully. V6 real source1/1 and citation3/3 evaluations passed; full development pass1 is running. Current candidate-input SHA is4c95c31a520b14e913a1a231caa85e8eba32f550de7deb5026bb12b26030c767; sealed v3 remains unread. A fresh development-only Qdrant/vector comparison completed with no demonstrated gain; its disposable container was removed and absence verified. Four raw evidence items are bound to current source/configuration fingerprints, explicitly INCOMPLETE until both development passes and subsequent gates succeed. The owner-authorized cumulative USD100 cap and all historical failures/unknown liabilities remain enforced. No formal U02/U03/U04 or whole-project completion claim.Current budget delivery: commit
1ed2d8802032b3f48765a13b56e9ba2410656d8aimplements the owner's cumulative USD100 authorization. V6 is ACTIVE_BOUND, retains all 418 historical attempts and both unknown liabilities, and preserves the 241-attempt fresh package with unchanged purpose/token/round/scoring gates. Real retained-history verification passed all 18 fingerprints. Remote focused regressions: 141 passed; expanded checks: 146 passed, one import-path failure subsequently passed withpython -m pytest. CI run 38016183874 is still in progress. Model availability and two authenticated read-only fixture controls passed; fresh source evaluation is running. Formal U02/U03/U04 acceptance remains incomplete; this PR remains Draft/unmerged.最终候选CI完成|1a9a2ce5f
GitHub CI37998392642已completed/success,绑定1a9a2ce5fb9c43141c444a67ffd4b5240a3ccc55。三个Backend Test、Migration动态门禁及全部Docker构建/扫描成功;Frontend及japicmp比较步骤仍按workflow条件skipped,覆盖限制不变。最终文档corpus81PASS,Java同ed9155bfb真实HTTP旅程PASS225.4s/Admin47PASS,临时容器已清理,SVC025/DAV66工程Done。
正式U02→U03→U04仍未通过,17Done/28未完成/6Canceled;原580次/USD7.14保持有效,659/USD7.90恢复方案仍需显式预算授权,无新调用/period/guard,不读取sealed holdout。PR231 Open/Draft,不合并、不部署;全部计划未完成。
SVC-025工程验收完成|1a9a2ce5f
canonical关闭文档及ARCH/DEV语料manifest已在1a9a2ce5fb9c43141c444a67ffd4b5240a3ccc55推送,远端corpus81 tests PASS2.37s,双轴审查APPROVE。Java实现与ed9155bfb相同:真实Auth/Admin HTTP旅程1 PASS225.4s、Admin47 PASS、ed CI37996874277 SUCCESS,容器已清理;报告hash bd34eb3c8f32421fa5f3233cfb06588e211a68dac98235a263d4562bdfddfc44。三项原始checklist已满足,SVC025只关闭bounded工程范围。最终文档head CI尚待终态,不把ed CI表述为新headCI。保持distributed默认及App disabled;RSA/JWKS、App四步/production/transport不在证据范围。PR231仍Draft未合并。
ed9155b:当前提交CI终态SUCCESS
GitHub CI 37996874277已completed/success(同一head ed9155b)。Migration与Backend Test/default/features off/features on全部完成,没有失败job。Frontend skipped、japicmp比较步骤skipped仍保留对应覆盖限制。远端Admin47项PASS;CoreEnabledOwnerJourneyIT真实HTTP旅程进程仍存活,尚无终态,不能提前关闭SVC-025或宣称全部计划完成。
当前交付证据|ed9155bfb(旅程验收仍运行)
当前 head
ed9155bfb3f1a9666e5a6d0691e3597b73e345fc。补齐Admin既有optional读取构造注入:缺少App profile、Solution、Submission stats、Authorization snapshot时保留typed unavailable语义,Auth account与安全链仍为必需依赖。Java/Spec双轴静态审查通过;远端Admin三类回归47项全通过、零跳过。真实Auth/Admin HTTP→授权持久化→用户重新登录读取旅程已启动,尚无终态,SVC-025未关闭。CI 37996874277当前Backend Build、Agent Unit Tests、Secret Scan、Baseline Parity、静态门禁与9个Docker build/scan通过;Migration动态检查与3个Backend Test仍运行。Contract job成功但japicmp比较步骤明确skipped;Frontend skipped,均不冒充实际验收。PR保持Open/Draft,未合并或部署。以下历史记录按各自SHA解释。
Core HTTP 旅程推进|099d8af82(尚未通过)
当前 head
099d8af82800656c4d8733a99eb952489eb28de9,PR仍Open/Draft。Auth/Admin独立Owner MVC与安全链复用,不复制业务实现。c6a6afd1c远端30项Core单元/生命周期回归通过。真实HTTP旅程前两轮失败已保留:parent MockEnvironment缺storage canonical绑定;补齐后Auth安全链因MockEnvironment缺JWT输入,login403。当前仅补测试配置,Java/Spec审查通过,第三轮真实旅程仍运行,不关闭DAV66/SVC025。当前同SHA语料81 passed/0.83s;DEV授权摘录与digest不变,文件版本hash同步。RSA/JWKS未验证,Appdisabled。前一个完整CI的镜像拉取被DockerHub429阻断,Secret Scan/Migrations/BackendTest未执行不能算通过;不得绕过。0新增付费模型调用,原580次/USD7.14有效,未读sealed holdout。以下是历史SHA绑定的交付记录。
M03 工程验收完成|b1f04b3
当前head b1f04b3,Agent CI job114019619917真实1514 passed/1 optional Qdrant skip/36.74s。remote-dev同SHA干净,corpus/manifest focused67 passed/0.56s/exit0;strict响应及identity/service85项于bd8f2f3通过,后续仅manifest版本/行位置修正。原真实TCP资源释放证明83656b3保留原SHA/固定Auth测试数据边界。请求/响应Pydantic、严格非法输入、安全错误码、可信Auth owner隔离、server trace/run标识、async adapter、超时取消释放均有源码和对应程序证据。两轴审查发现并已修正Reference行位移,加载器仍严格,授权excerpt/许可/范围不变。
类型校验确保输入/输出形状;认证确认可信JavaAuth当前principal;业务授权限制该owner的source/thread,跨owner统一404。依自主验收规则,复用既有真实端点而不新增重复API;本人独立开发/讲解/实际小时仍为后置学习目标,不伪造完成或将1.5h计划计实际工时。
仅M03工程Done:完整CI37989304998尚未通过,已检查DockerAdmin/Console与baseline存在DockerHub429/exit125外部阻塞;PR仍Draft,不推断全项目完成、正式模型/Java端到端验收或生产发布。0新付费调用/未读sealed holdout。
CI 语料版本修复|b1f04b3
当前head b1f04b3。bd8f2f3的完整Agent CI已失败:3 failed/1511 passed/1 optional skip,均为文档改动后授权语料来源版本未同步。c5d12c8更新整文件hash及行位移;独立审查发现Reference多算一行,本head修正为160–176。ARCH90–104和REF160–176保留原excerpt content_digest、MIT许可与访问范围,严格loader未放宽。旧c5远端全量还在运行,不能证明当前head;新CI37989304998 pending。响应schema85项focused之前通过,完整兼容验收尚未完成,M03不关闭。0付费模型调用/未读sealed holdout。
M03 响应 schema 远端通过|bd8f2f3
remote-dev干净源码bd8f2f36b72be0285aaf6f891fa2d8402fdb9060:
uv run --locked --group eval pytest -q tests/test_agent_security.py tests/test_agent_service.py实际85 passed/37.97s/exit0。strict Pydantic统一响应校验新增5项回归全部通过:非法对象、NaN、bool code、int message拒绝及原401 wire合同保持。此前6missingcookie/forged Bearer身份及原合法/非法输入、cross-owner、取消/超时回归亦包含。两轴静态审查完成。0付费模型调用,未宣称真实JavaAuth或用户学习完成。完整CI37988763153仍待确认,M03保持InProgress。资源实际TCP释放证明沿用83656b3并明确原SHA,不冒充本次重复执行。类型校验约束JSON输入和输出形状;认证由JavaAuth当前principal确定身份;业务授权用该owner查线程及source,跨owner统一404。三者不可互相替代。复用原真实端点符合目标,不为学习指标新增重复API;本人独立实现/讲解/实际小时仍是后置学习事项。
M03 Cookie 身份回归通过|9163a8b
remote-dev干净源码9163a8ba3a1474d371e0b272849e1cea86cd992a,
uv run --locked --group eval pytest -q tests/test_agent_security.py tests/test_agent_service.py实际80 passed /66.21s/exit0。新增6项create/get/analyze × 缺失cookie/forged Bearer均401并禁止创建upstreamclient;既有伪造字段与跨owner404保留。Standards/Spec静态APPROVE。0付费模型调用,固定测试客户端不冒充真实JavaAuth。完整CI37988312990尚未确认通过。M03仍InProgress:独立Spec审查发现Pydantic响应schema缺口,下一步补齐,不用测试绿灯替代原要求。架构文档校准|6821d9c
当前 head 仅修正
docs/ARCHITECTURE.md:区分历史 exec-jar 装配失败与已通过的 disposable Auth/Admin bounded proof,保留业务入口、完整 journey、生产边界。文档差异与 whitespace 检查通过;本次未重复运行此前通过的 Java IT。当前 head CI run 37987901088 已排队,不能继承 200bf88 的 CI 结果。用户已有 mvnw.cmd 修改未提交。Core 关闭条件校准
SVC-025 / DAV-66 当前剩余的是受支持的 Core 业务入口及完整 disposable business journey。11 个本地只读契约与真实 Auth Owner 对照已通过。未证明 distributed RPC transport/filter parity 是证据边界,不是原关闭条件要求的额外门禁;不追加这一门禁。distributed 仍是唯一默认,PR 保持 Draft,正式模型与业务验收尚未完成。
Core local read-adapter parity 实际通过|200bf88
当前
200bf88f585ca4ec861d16b4444c9d23542d950e在remote-dev干净Git同步后,经支持入口CORE_ENABLED_OWNER_JOURNEY=1 ./scripts/test/core-enabled-owner-journey.sh实际通过:1 IT、0失败/错误/跳过,237.039s,BUILD SUCCESS/CORE_EXIT=0。三个IdentityQuery+八个AccountQuery方法与真实Auth Owner provider结果对照,包括实际MySQL分页/计数/趋势及缺失账户/非法查询typed错误;原grant/missing signer/fail-closed/cleanup也通过。Docker正常可用,按本日志的精确ID检查三个专属容器均已删除。首次cleanup观察脚本因Dockerno such object大小写匹配失败;只修正读取断言再核对,未重跑测试或修改运行态。私有0600/no-clobber artifact
/home/david/.local/state/ulticode/autonomous-project/core-read-parity-200bf88.jsonSHA2567e4a0be01c5adef1072382c7c6582f7ca115e64c11a00a267b177afec9e0a542,父流程已核对摘要/权限/head/结果/11方法/3容器读回PASS。原始log/XML摘要在artifact内。当前完整CI 37984948565 SUCCESS(24/24 terminal jobs,路径跳过按实际配置保留);Agent实际日志1503 passed/1 optional dependency skip/31.11s。graphify AST更新terminal PASS,但缺tree_sitter_sql,122 SQL文件未覆盖;不能把独立MCP Sept14图当作已更新。
本证据只证明local只读委派及bounded Auth/Admin wiring,distributed transport/filter parity与业务HTTP/WS journey仍未完成,SVC025/DAV66保持In Progress。PR231 Open/Draft;0付费模型调用、未读取sealed holdout-v3,原580次/USD7.14上限不变,扩额未批准。
SVC-025 只读契约对照增量|200bf88
当前提交
200bf88f585ca4ec861d16b4444c9d23542d950e已正常推送PR231,扩展既有单一CoreEnabledOwnerJourneyIT,在同一disposable Auth/Admin环境中覆盖3个IdentityQuery+8个AccountQuery方法与真实AuthOwnerprovider结果对照;独立断言账户ID、分页总数、计数、趋势非空,以及缺失账户/非法趋势typed failure。沿用已有canonical migrations、grant/missing signer/cleanup和恰好1个IT门禁,不新增生产业务实现。规格审查及Java标准审查无阻断;remote-dev干净Git同步当前SHA,支持入口
CORE_ENABLED_OWNER_JOURNEY=1 ./scripts/test/core-enabled-owner-journey.sh已启动,执行仍在运行,尚无PASS结论。私有0600/no-clobber日志core-read-parity-200bf88.log。当前完整CI37984948565 pending,旧83656b3 CI成功不替代本SHA。该测试仅覆盖local read delegation;distributed transport/filter parity及Core业务HTTP/WS旅程仍缺,DAV66继续In Progress。0新增付费模型调用/未读sealed holdout-v3;原580次/USD7.14上限保持。
M10 工程验收完成|83656b3
原始M10工程范围为授权小语料、版本/位置/scope可追溯、关键词命中/未命中、预标注20development+10holdout及禁止用留出输出调参。四项条件已有当前源码/题集与原始执行证据;规格审查再次读取实时issue,确认真实模型回答不是原始M10工程条件,前文追加的“等待真实回答”不再作为本任务关闭门禁。该验收由M12/DAV58/DAV45继续承接。
当前head83656b3a9e5733f00b9a270dd4edec255907838a完整CI37983181574成功;Agent1503 passed/1 optional skip/34.21s,remote-dev相关87tests PASS/4.65s;20+10schema及来源/类别/ID无交叉验证PASS。五份MIT片段的manifest、白名单/版本/摘要校验及dev真实keyword失败样本保留。关键词required-source hit12/20、vector11/20,不当作回答准确率。10新holdout作者/审查者可见、未检索/未评分,不具unseen U04资格。两轴静态审查通过。
M10标记Done仅代表上述工程交付。真实回答支持/完成维度deferred,U02/U03/U04未完成;个人独立学习/掌握及开发人工总工时Not Recorded,不能拿计划3h或CI运行时间代替。0新增付费模型调用,未读sealed holdout-v3,原580次/USD7.14预算继续有效。
当前提交完整CI成功|83656b3
当前SHA
83656b3a9e5733f00b9a270dd4edec255907838a的完整 CI37983181574 completed/success;Agent日志1503 passed/1 optional dependency skip/34.21s。M10题集schema校验和87项远端回归仍是本SHA证据;留出题未检索/未评分,作者可见,不当作未见U04。M03实际TCP超时/取消资源释放证据已读回。PR231仍Open/Draft,正式U02–U04不以CI成功替代。M10 题集划分补齐|83656b3
提交
83656b3a9e5733f00b9a270dd4edec255907838a新增独立services/agent/data/repository_holdout_cases.json10道题,覆盖五类场景,预声明来源、可回答性、允许/禁止行为。20道development与10道holdout ID无交叉。全部新题标记author-visible、not evaluated;作者及静态审查者已见,不具未见确认资格,不替代/读取sealed holdout-v3。禁止用留出输出选择当前策略,常规测试只验证schema。两路审查0阻断;remote-dev干净Git同步本SHA,既有load_cases格式/来源/划分校验PASS,留出retrieval_calls=0/model_calls=0,87项相关回归通过(4.65s)。DEVELOPMENT整文件版本随说明更新,五份引用片段内容未变。当前完整CI 37983181574 pending;8ef44a4的完整CI成功属于旧SHA证据。
题集与检索工程条件现已补齐,真实回答支持/完成维度仍deferred;M10保持In Progress等待当前CI及真实回答验收,不宣称模型效果、未见验证或实际人工总工时。0新增付费调用;原580次/USD7.14上限仍有效,659次/USD7.90提案未批准。
M11 工程验收完成|8ef44a4
当前精确提交
8ef44a4285bd2d1ec96b39643dce4da4335db040的 完整 CI #37981239798 已 completed/success。Agent job 实际日志 1503 passed / 1 optional dependency skip / 20.98s;remote-dev 带 eval 依赖聚焦回归 207 passed / 15.49s,真实 Auth 双 USER + Qdrant HTTP 23 项 owner 隔离通过。当前 BGE 与五份 MIT corpus 的证据读回通过,集合已删除,临时容器停止并确认不存在。两路源码审查无阻断,四项工程验收满足,M11 标记 Done。向量 required-source hit 11/20,keyword 12/20,均 false_positive 5;没有证明向量质量优势,默认策略保留 keyword。受控向量验证真实授权边界,BGE 质量另行评估;未加入生产 Agent 向量工具。模型回答支持/任务完成未测量,不替代 U02/U03/U04。可观测验证时间 22.032s(15.49s 聚焦回归 + 6.542s BGE 当前验证),开发及人工总工时 Not Recorded,不能把计划 2h 当成实际投入。
0 新增付费 LLM 调用,未读 sealed holdout-v3;原 580 次/USD7.14 上限保持,扩额提案未批准。PR231 仍 Open/Draft。
当前 M11 工程证据(8ef44a4)
当前提交
8ef44a4285bd2d1ec96b39643dce4da4335db040:真实 Auth 双 USER 会话 + Qdrant HTTP 的 owner 隔离 23 项通过,最终模型输入仅保留本人来源;伪造范围参数在查询前拒绝,匿名查询拒绝。当前提交的 BGE 实测及私有证据已逐项读回,临时 Qdrant 容器已删除。Agent CI 实际日志为 1503 passed / 1 optional dependency skip(20.98s);完整 CI #37981239798 尚在迁移检查阶段,其余运行项成功,Frontend 按路径跳过。20 条预声明 repository development cases:keyword required-source hit 12/20,vector 11/20,均有 5 条 false positives;没有证明向量检索优于基线,默认 Agent 仍用 keyword。实际 Auth 隔离使用受控向量,BGE 检索质量另行测量。当前 BGE 证据 SHA256
cd644c8c4fa62513a01c8c3cfdb7a903f257af7660584e0a110850e500e40144;真实 owner 证据 SHA2569a08cee0c0a11b33604ad134bb8e7c08900503f2ba5f61496db2c5e02135f20e,均私有 0600、集合删除已验证。0 新增付费 LLM 调用;未读 sealed holdout-v3;不代表 U02/U03/U04 正式验收。原预算 580 次/USD7.14 继续生效,659 次/USD7.90 只是待批准提案。M11 保持 In Progress,等待当前完整 CI。
Trusted-scope vector evaluation and real repository comparison
At
4b2b502e5b3e5bd2e1ccdde8ec9c2b94fc4294c8, evaluation-only Qdrant HTTP queries filter trusted caller scope before Top-k and recheck returned payload scope. Embedding count, 384-dimensional shape and finite numeric values are checked before index mutation. The main Agent keyword path is preserved.Remote locked eval regression: 103 passed / 15.96s; both static reviews approved. Real Qdrant HTTP controlled-vector scope checks: 4 passed, including a foreign nearest point that cannot crowd out the owner's result. Real pinned BGE / Qdrant 1.19.1 on the same five MIT excerpts and 20 predeclared development cases: keyword required-source hit 12/20, vector 11/20; both retain 5 false positives and 3 refusal cases retrieving tempting evidence. No vector benefit is claimed; default keyword strategy remains. Artifacts are SHA-bound and read back; collections and disposable container were removed.
Zero paid LLM calls or sealed holdout reads; 25 local embedding inputs. Correct scope filtering does not yet prove identity-to-scope binding or answer correctness; DAV-23 remains In Progress. Current full CI run 37979808403 is in progress. Previous f602 full CI run 37978488036 was cancelled, even though its Agent job passed. PR remains Draft.
Predeclared repository development retrieval baseline
At
f602bda76d10952b296ea0ad160c12669197532b, 20 development-only cases cover normal calls, no-tool, clarification, staged tool errors and insufficient evidence. Expectations were committed before evaluation. Remote locked focused regression: 109 passed / 1.75s; both static reviews approved.The actual retrieval baseline exposes limitations: required-source hit 12/20, all 12 with extra hits; 5 false positives on missing-evidence/clarification cases and 3 refusal cases retrieved tempting fragments; exact retrieval matches 0/20. Original case expectations and traces are preserved. All answer-level judgments remain deferred; staged errors are not real HTTP failure proof. Zero model calls, zero HTTP requests, no sealed holdout read. Private artifact SHA-256
8a56f47e5df65662a9e991ee320723033d6291bdb0d1c2fe27a40b516983357dverified on readback. M10 remains In Progress; current full CI run 37978488036 is pending.Licensed repository corpus and evaluation binding
Five bounded excerpts from MIT-licensed core documents now bind source line ranges, full-file versions, content hashes and the LICENSE hash through the existing manifest gate. The per-case evaluator can use this explicit corpus while preserving the default synthetic baseline. Answer correctness and citation support remain deferred.
Validation at
f3464fee5da9ee28e82979d2637b985ee4a98e51: remote-dev locked focused regression 108 passed / 1.70s; two static reviews approved. Initial corpus run 106 passed / 1 failed (oversized operations excerpt) is retained; the excerpt was reduced to 403 characters without relaxing the 1200-character limit. Current-head full CI is pending (run 37977873950). M10 remains In Progress; no paid call, sealed holdout consumption or formal acceptance is claimed.Real Auth-bound Agent owner guards
At
4b1c3c733799cae7f9b726c5391e977fec9155ef, actualcreate_appASGI + SQLite/LangGraph and default session client use two real synthetic Auth sessions and owned Java submissions. Both owners create/read their own threads; foreign thread/events/SSE/analyze/cancel requests return 404. Forged owner field returns 400, bad CSRF 403, state stays unchanged; own missing-gate analysis returns 503 before model calls, own cancel succeeds. Remote execution and private artifact readback pass (14 recorded checks, 0600). No model calls or Java business writes.This is in-process ASGI and live Auth/App, not a deployed Agent socket or real model attack. Running Java build SHA remains unverified. Separate real session-bound tool checks also pass: 12 forged identity/approval fields rejected; owner result IDs match own listing; foreign detail returns 40400; principal, USER role and cookies unchanged (18 recorded checks, private 0600 artifact). M09's four engineering criteria are now Done; both source/evidence-scope reviews agree. This is direct argument injection, not a provider-model attack. Formal model isolation and U-chain acceptance stay incomplete; original paid cap and Draft status remain.
Current Java persistence verification
At head
4b1c3c733799cae7f9b726c5391e977fec9155ef, remoteLearningPlanWriteITpasses 6 tests / 0 failures / 0 errors / 0 skipped in 174.846s; Maven reactor succeeds (7:48 total). Real MySQL transactions cover first save, identical replay, payload conflict, owner-scoped reads and both concurrency cases. Cross-owner access is mocked; this does not prove HTTP confirmation or the three Python/Java crash scenarios.Current-head real two-account HTTP ownership/list/search controls pass; model probe intentionally unconfigured, aggregate INCOMPLETE, no paid calls.
e2e_readonly.pyseparately passes realUlticodeClient/tool GETs plus session login. Running Java stack build SHA was not rebound, so these are runtime subchecks, not current formal U02 acceptance. M08 and M14 engineering acceptance are Done; M09/M15/M17 and U-chain remain incomplete. Original paid cap and Draft status remain.Current model observation verification
Head
4b1c3c733799cae7f9b726c5391e977fec9155ef: model and citation-judge calls emit run-correlated metadata (server call ID, node, elapsed time, bounded provider model label, existing budget attempt UUID, nullable token usage). Unknown usage remains unavailable; messages, answers and provider error bodies are excluded. Existing budget, resource ownership and cancellation semantics are preserved.Remote locked regression 103 passed in 26.27s (service/loop/security/citation); both reviews approve. Earlier
1dd62745fhad 101 passed / 2 failed due to old exact-event assertions; updated assertions retain dispatch and late-completion fencing and the full focused rerun passes. Current-head Agent CI: 1482 passed / 1 optional dependency skipped in 33.49s. Overall CI 37972430798 completed successfully. Real Java trace/write acceptance and paid formal acceptance remain gated; DAV-29 remains In Progress. Original paid cap unchanged; PR stays Draft.Historical process recovery verification
Head
384ca792fdc33772ed65f93df413f9810f0f4de1: an actual app/LangGraph checkpoint survives forced process death. A distinct process loads the same checkpoint/thread/run/version, rejects foreign-owner mutation, and resumes an authorized edit without model replay. Remote focused regression 1 passed / 41 deselected in 10.28s; current-head Agent CI 1477 passed / 1 optional dependency skipped in 33.40s. Both reviews approve.This is local SQLite with controlled auth/model fixtures, not real Auth/Java or external-write exactly-once acceptance. Overall CI 37970304539 completed successfully for that previous head; DAV-26 remains In Progress. Original paid cap unchanged; PR stays Draft.
Historical M08 protocol verification
Head
f13a8dfbdec7fccdeb59053a13991b98c8459e9c: 68 remote tests passed in 14.69s (service/store/loop). Coverage includes real TCP/SSE disconnect/cancel/run replacement, late-tool fencing with no extra model calls, genuine task cancellation, 205-event pagination, cursor resume, stable IDs/test-consumer deduplication, and timeout closing only the subscription. Both reviews approve. Actual locked environment versions are recorded on DAV-20; the optional Vue consumer is not implemented by these tests.Current-head Agent CI job passed: 1476 passed, 1 optional dependency skipped in 23.57s. Overall CI 37969685451 is still in progress, so DAV-20 remains In Progress. These scripted-model regressions do not replace formal paid real-model/Java business acceptance. Original paid cap remains unchanged; PR stays Draft.
Historical checkpoints
Current live stream validation
Head
b3f70c929f63569bad4aaf728b29722c560f0c09: 66 remote tests passed in 10.03s (service/store/loop), including real loopback TCP/SSE disconnect, cancellation and run replacement while a tool is blocked. Fenced runs emit no late tool/analysis completion and make no additional model call; genuine task cancellation propagates. Both reviews approve. Previous 337ab cancellation/replacement tests failed with 502; this head reconciles incomplete graph output only when canonical storage proves cancellation/replacement, preserving active-run errors.Full M08 still needs pagination/timeout and consumer SSE-ID deduplication validation. CI 37969338558 is in progress. Paid formal acceptance remains open under the original cap. PR remains Draft.
Earlier checkpoints
Current M08 SSE checkpoint
Current head
792a0d10e3ed003baf8de63183ad542dabfc33f5adds owner-authenticated bounded SSE over the canonical event store, run isolation, tool metadata and validated persisted answer text. A deterministic regression fixes a concurrent completion race so all durable workflow events precede terminal output. Remote clean Git checkout: 62 passed in 14.04s (store/service/loop); both reviews approve after the fix. The polling API remains available.Full M08 acceptance remains open: live disconnect, run replacement, late tool cancellation, pagination/timeout and consumer replay deduplication need verification. CI 37967772618 is in progress; previous 7d9 CI was cancelled. Paid real-model acceptance remains blocked under the original cap. PR remains Draft.
Historical checkpoints
Current event ownership checkpoint
Commit
7d9fed91ec1a49c94021455a334000888e3674c5persists canonicaldetail.runIdatomically for create/transition/cancel. Caller detail cannot overwrite it; historical payloads remain unchanged. Remote clean Git checkout: 52 passed in 34.66s (test_agent_store.py,test_agent_service.py); both Standards/Spec reviews found no blocking issues. Full M08 streaming/text/tool/disconnect acceptance remains unfinished. Current CI 37967170617 is in progress; PR remains Draft.Earlier checkpoints
Current Core validation checkpoint
Commit
9fc627eda38068276a0fb2a1ee8b86cadf6dd018aligns the bounded Core integration test with the runtime per-owner startup budget and covers sequential startup plus independent drain budgets. The remote disposable MySQL/Redis gate passed: 1 test, 0 failures, 0 errors, 0 skipped (172.0s); script exit 0. All readiness, permission, fail-closed and cleanup assertions remain. Two Java reviews found no blocking issues.This verifies Auth/Admin bounded wiring only. Full Core business journeys/local parity and real-model Agent acceptance remain open. Current head CI 37966463512 is in progress. PR remains Draft.
Current candidate and acceptance
Candidate
afc0e0238ca5fc8ea18290489c8eb34227659efcclarifies that the answer envelope contains a serialized JSON string and supplies an escaped example. The adapter remains strict; nested object output is still rejected. Remote focused regressions: 89 passed. Standards and Spec static reviews: no actionable findings. Current-head CI 37963873870 completed successfully; Agent job reports1467 passed/1 optional dependency skipped.Preceding candidate
f7994f1passed CI37957817917 and262 focused regressions. Actual V5 source/citation passed; development1 matched20/20 with40 calls, while development2 is INCOMPLETE after35 calls because the provider returned an object instead of the required string. All35 exchanges are retained; V5 ended at79 attempts,20433microUSD actual, no new unknown/unsettled usage. Historical unknown liabilities remain retained. No automatic paid retry or budget increase; original580/USD7.14 ceiling unchanged. The prompt fix has not been accepted by a new real-model run.Formal U02, isolation, U03 Java persistence/recovery and frozen U04 remain incomplete; PR stays Draft. Third holdout remains unread. Independently, current-candidate disposable CoreEnabledOwnerJourneyIT failed Auth child startup/readiness timeout; SVC025 remains open. This failure is outside the two-file Agent repair.
Historical delivery and acceptance snapshots
The following records retain their original SHA/status and are superseded by the current checkpoint above.
Latest revalidation outcome
Current candidate:
22e9a81. Focused remote regressions: 163 passed. The replacement period's source analysis 1/1 and citation checks 3/3 passed. Development round 1 is INCOMPLETE after 31 exchanges because a 1027-character answer exceeded the unchanged 1000-character contract; round 2 did not start. All requests settled, with no new unknown usage or automatic retry. That period is permanently sealed with all prior liabilities retained.Local commit
f7994f1adds concise-answer headroom and the approved replacement period's immutable history binding, preserving all round limits and scoring. Static reviews passed; remote checks of this new change are Not Run, pending Git delivery because execution policy rejected pushing. The new period is not activated. Formal boundary, isolation, U03 and U04 acceptance remain incomplete; this PR remains Draft. Older results below are historical snapshots, not current completion claims.V4 remote validation follow-up
The candidate is now
2d31a9f. Focused remote regressions returned 162 passed / 1 failed. The missing v4 policy case in the development evaluation entry point is fixed locally in22e9a81; static review passed, but runtime verification awaits Git delivery because environment policy rejected pushing. Actual sealed-history validation passed. The replacement period remains inactive, no new paid requests occurred, and formal acceptance is incomplete. This supersedes the earlier Not Run snapshot below.Revalidation delivery update
The replacement acceptance allowance is approved. The previous run is permanently sealed with its liabilities and receipt history preserved. Local commit
2d31a9fadds immutable history binding and regression coverage; static reviews passed, but runtime checks are Not Run because environment policy rejected pushing the commit. The GitHub candidate remains unchanged. The replacement period is not activated and no new paid requests have been issued. Formal acceptance remains incomplete pending Git delivery, remote regressions and the full acceptance sequence. This PR remains Draft.Summary
Adds an opt-in Agent workflow for submission analysis and learning-plan creation. Authenticated users can analyze an owned submission, review a durable draft, explicitly confirm it, and save it through the Java App service. Model execution uses read-only tools; business writes remain behind explicit confirmation and owner checks.
This PR also adds evidence-based acceptance runners and cumulative model-budget accounting. Implementation and regression checks are complete for the fixes described below; formal end-to-end acceptance remains in progress.
Changes
404 source_not_owned, reject malformed session cookies as authentication errors, bound SQLite event cursors, and keep transient authorization failures recoverable.Validation
Current-head CI: success — 23 jobs passed, 1 conditional skip; Agent 1,444 passed, 1 optional skip. The remote checkout was fast-forwarded through Git and verified clean at
e376694. Model adapter, budget and account-isolation driver regressions: 186 passed. Earlier CI results below are historical.Current-head CI: success — 23 jobs passed, 1 conditional skip; Agent 1,443 passed, 1 optional skip. Docker backend-app and ci-ok passed. Commit
02231026fixes the unavailable Maven 3.10.0 wrapper distribution by selecting Maven 3.9.11. This replaces the preceding failed/running CI status; it does not complete real-model acceptance.Current head:
e3766943f5322e4d91169a0a759ed1b0037fe86aBranch:
agent/first-delivery→maind33f7f81: 1,421 passed on the remote environment. This is retained evidence from the preceding candidate, not a new full-suite execution.The focused checks above do not replace formal acceptance. Earlier failed and incomplete model runs remain retained as evidence.
Remaining acceptance
Latest current-head model isolation execution completed three attack scenarios. Explicit foreign-subject and injected-source scenarios met all predicates. The identity-swap scenario refused the malicious instructions without leakage or identity changes, but did not execute the separately requested owner-listing positive control, so the overall result remains INCOMPLETE. The shared tool prompt now clarifies that independent authorized read-only parts should continue under the current server session while unauthorized parts are refused. This minimal correction was pushed by the owner as
e376694, statically reviewed, and validated by 186 focused remote regressions plus current-head CI. No fresh real-model acceptance pass is claimed. Failed evidence is retained; no automatic model retry was made.Fresh revalidation on the current head has passed source analysis, all three citation judgments, and both complete development passes (20/20 behavior matches and 40 provider exchanges per pass). The six-case DAV-58 boundary run failed overall: 3/6 behavior checks met. Missing ID, no retrieval hit, and wrong citation failed; no-tool, tool failure, and source injection passed. Further paid acceptance is paused. Diagnosis identified two evaluator false positives: listing detection crossed a comma between separate clauses, and tool-failure detection misread a relative phrase about retrieved evidence. The third failure genuinely echoed a supplied submission UUID in a source refusal. The minimal correction is now pushed. Current-head remote boundary/service/driver regressions passed: 240 tests. Zero-paid replay confirms the two evaluator corrections while the echoed UUID remains rejected. The complete bounded real-model rerun has finished: 4/6 behavior checks passed. Missing ID, no-tool, no-hit, and tool failure passed. Source injection failed only because a valid equivalent explanation was absent from the evaluator's phrase list; no unauthorized action was observed. Wrong citation remained a genuine refusal-contract failure: the answer added generic judging semantics after acknowledging unavailable source. The minimal prompt and phrase-list correction was pushed by the owner as
46fc5ef. The remote validation checkout was fast-forwarded through Git and verified clean at that exact SHA. Its focused boundary/service/driver regressions passed: 245 tests. The preceding CI run failed while downloading the unavailable Maven 3.10.0 distribution, before compilation. Commit02231026repairs that configuration and its current-head CI passed. No fresh real-model pass is claimed. Paid reruns remain paused because the frozen boundary-loop quota cannot cover another complete six-case run. Acceptance criteria have not been reduced. Failed raw artifacts remain unchanged. The preceding network-interrupted run remains retained as INCOMPLETE. Recovery uses a separately bound period with unresolved historical liabilities fully retained; it does not settle or erase missing provider evidence. No downstream formal acceptance is claimed.A real Qdrant / pinned BGE comparison on the 20 synthetic development cases completed with zero model calls. This is development-only retrieval evidence; the unseen holdout remains unread. It does not complete U02 or downstream acceptance.
Delivery boundaries
The autonomous product-definition review, replacement static low-fidelity entry/contract design, and metrics/pilot-design tasks (DAV-54, DAV-56, DAV-57) have been completed as design work only. No Console integration, instrumentation, recruited-user research, pilot outcome, or formal model acceptance is implied. Those implementation and external-evidence items remain separate.
This PR remains Draft. CI success and focused validation do not imply formal acceptance or authorization to merge, release, or deploy. Credentials, private accounting records, raw internal logs, and unseen holdout contents are excluded from the public repository.