From 60b66b667c5f5f54f6c503f6feb886a53afeb116 Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Mon, 24 Aug 2026 11:53:21 +0200 Subject: [PATCH 01/35] docs(harbour): reject cross-model repair experiment --- apps/storycore-harbour/STATUS.md | 1 + apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md | 1 + 2 files changed, 2 insertions(+) diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index aff223d7..755ef3e6 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -288,4 +288,5 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - The Anna adapter now exposes an optional user-entered model preference. Blank or invalid values preserve the Anna default; valid hints are advisory and only match models already enabled for that user. Normal StoryCore data and provider credentials remain unaffected. Automated gates pass: 65/65 Node tests, strict validation, Edge end-to-end smoke, and Edge deletion/storage-preservation smoke. - The complete fixed corpus with user preference `gemma` finished at 14/20: median 21.67 seconds, p95 39.78 seconds, 6 repaired passes, and no JSON truncation. Failures were A02 `reference_invalid`, A06/A09/A11 `contract_invalid`, A10 `warning_severity_invalid`, and A19 `required_field_invalid`. - Exact private-output replay identified two bounded schema aliases: A02 used warning `sceneId: "null"`; A10 used severity `minor`. Both now normalize to canonical `null` and `info`, and their exact real outputs pass the validator locally. This projects Gemma to 16/20 but does not replace the measured 14/20 score. Three malformed JSON responses and one structurally empty project remain rejected. +- A loopback-only cross-model experiment kept Anna default for primary generation and hinted Gemma only for the single repair. It passed A02/A15 directly but failed A07 (`contract_invalid`) and A18 (`unknown`): 2/4, worse than Gemma-only 3/4. The uncommitted experiment was removed; production retains one user-selected preference for both calls. - Reliability evidence is now a two-profile matrix: Anna default 16/20; Gemma preference 14/20. Both fail the 18/20 gate. No readiness, version cut, review, or release claim is permitted. diff --git a/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md b/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md index 3a571035..caa23ee9 100644 --- a/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md +++ b/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md @@ -88,3 +88,4 @@ Do not replace production-platform gates with these local results. - User control complete: the Anna adapter offers an optional validated model hint and otherwise preserves the Anna default. It has 65-test, strict-validation, end-to-end Edge, and deletion/storage-preservation evidence. - Complete Gemma-preference corpus: 14/20, median 21.67 seconds, p95 39.78 seconds, 6 repaired passes. It is faster and avoids MiniMax truncation but creates six schema/reference failures. Keep this score separate from Anna-default 16/20; neither satisfies readiness. - Post-run exact replay: canonicalizing warning severity `minor→info` and string scene reference `"null"→null` makes the measured A02/A10 outputs valid, projecting 16/20 without weakening any structural rule. The measured score remains 14/20 until a real rerun; the four remaining outputs are genuinely malformed or structurally empty. +- Rejected experiment: Anna-default primary plus Gemma-only repair scored 2/4 on A02/A07/A15/A18, below Gemma-only 3/4. The diagnostic code was removed; do not add separate repair-model complexity without new platform evidence. From ee3b4eb2277c1888a23cb932ff17663f5059141c Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Mon, 24 Aug 2026 21:34:08 +0200 Subject: [PATCH 02/35] docs(harbour): record fail-closed A06 reproduction --- apps/storycore-harbour/STATUS.md | 1 + apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md | 1 + 2 files changed, 2 insertions(+) diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 755ef3e6..4b8b5c5e 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -289,4 +289,5 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - The complete fixed corpus with user preference `gemma` finished at 14/20: median 21.67 seconds, p95 39.78 seconds, 6 repaired passes, and no JSON truncation. Failures were A02 `reference_invalid`, A06/A09/A11 `contract_invalid`, A10 `warning_severity_invalid`, and A19 `required_field_invalid`. - Exact private-output replay identified two bounded schema aliases: A02 used warning `sceneId: "null"`; A10 used severity `minor`. Both now normalize to canonical `null` and `info`, and their exact real outputs pass the validator locally. This projects Gemma to 16/20 but does not replace the measured 14/20 score. Three malformed JSON responses and one structurally empty project remain rejected. - A loopback-only cross-model experiment kept Anna default for primary generation and hinted Gemma only for the single repair. It passed A02/A15 directly but failed A07 (`contract_invalid`) and A18 (`unknown`): 2/4, worse than Gemma-only 3/4. The uncommitted experiment was removed; production retains one user-selected preference for both calls. +- A fresh Gemma A06 reproduction ruled out a bounded syntax-only repair. The primary output was missing one final brace, but appending it still left characters, locations, scenes, score, and warnings absent. The model repair was valid JSON yet again omitted the production bible and all core arrays. Parser recovery must remain fail-closed because required creative structure cannot be inferred safely. - Reliability evidence is now a two-profile matrix: Anna default 16/20; Gemma preference 14/20. Both fail the 18/20 gate. No readiness, version cut, review, or release claim is permitted. diff --git a/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md b/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md index caa23ee9..04946785 100644 --- a/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md +++ b/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md @@ -89,3 +89,4 @@ Do not replace production-platform gates with these local results. - Complete Gemma-preference corpus: 14/20, median 21.67 seconds, p95 39.78 seconds, 6 repaired passes. It is faster and avoids MiniMax truncation but creates six schema/reference failures. Keep this score separate from Anna-default 16/20; neither satisfies readiness. - Post-run exact replay: canonicalizing warning severity `minor→info` and string scene reference `"null"→null` makes the measured A02/A10 outputs valid, projecting 16/20 without weakening any structural rule. The measured score remains 14/20 until a real rerun; the four remaining outputs are genuinely malformed or structurally empty. - Rejected experiment: Anna-default primary plus Gemma-only repair scored 2/4 on A02/A07/A15/A18, below Gemma-only 3/4. The diagnostic code was removed; do not add separate repair-model complexity without new platform evidence. +- A06 reproduction: one missing final brace was not the root cause. Both the completed primary object and the syntactically valid repair lacked the required creative structure. Keep fail-closed validation; do not synthesize characters, locations, scenes, or continuity data in the parser. From 1cdcb1b7c0e6503762f1f14fcd1e213d7138ad22 Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Tue, 25 Aug 2026 08:18:13 +0200 Subject: [PATCH 03/35] docs(harbour): record blocked third-model probe --- apps/storycore-harbour/STATUS.md | 1 + apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md | 1 + 2 files changed, 2 insertions(+) diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 4b8b5c5e..9643acaf 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -290,4 +290,5 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - Exact private-output replay identified two bounded schema aliases: A02 used warning `sceneId: "null"`; A10 used severity `minor`. Both now normalize to canonical `null` and `info`, and their exact real outputs pass the validator locally. This projects Gemma to 16/20 but does not replace the measured 14/20 score. Three malformed JSON responses and one structurally empty project remain rejected. - A loopback-only cross-model experiment kept Anna default for primary generation and hinted Gemma only for the single repair. It passed A02/A15 directly but failed A07 (`contract_invalid`) and A18 (`unknown`): 2/4, worse than Gemma-only 3/4. The uncommitted experiment was removed; production retains one user-selected preference for both calls. - A fresh Gemma A06 reproduction ruled out a bounded syntax-only repair. The primary output was missing one final brace, but appending it still left characters, locations, scenes, score, and warnings absent. The model repair was valid JSON yet again omitted the production bible and all core arrays. Parser recovery must remain fail-closed because required creative structure cannot be inferred safely. +- A single A06 diagnostic using Anna's documented example hint `gpt-4o` produced no completion or model metadata. The UI recorded timeout while the harness request remained pending for more than six minutes and only window heartbeats continued. The server was stopped to terminate the orphaned request; do not retry this hint until Anna exposes model grants or fixes cancellation/deadline propagation. - Reliability evidence is now a two-profile matrix: Anna default 16/20; Gemma preference 14/20. Both fail the 18/20 gate. No readiness, version cut, review, or release claim is permitted. diff --git a/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md b/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md index 04946785..fa12b55a 100644 --- a/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md +++ b/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md @@ -90,3 +90,4 @@ Do not replace production-platform gates with these local results. - Post-run exact replay: canonicalizing warning severity `minor→info` and string scene reference `"null"→null` makes the measured A02/A10 outputs valid, projecting 16/20 without weakening any structural rule. The measured score remains 14/20 until a real rerun; the four remaining outputs are genuinely malformed or structurally empty. - Rejected experiment: Anna-default primary plus Gemma-only repair scored 2/4 on A02/A07/A15/A18, below Gemma-only 3/4. The diagnostic code was removed; do not add separate repair-model complexity without new platform evidence. - A06 reproduction: one missing final brace was not the root cause. Both the completed primary object and the syntactically valid repair lacked the required creative structure. Keep fail-closed validation; do not synthesize characters, locations, scenes, or continuity data in the parser. +- Third-model probe blocked: hint `gpt-4o` returned no response metadata and remained pending beyond the App timeout. Treat it as a platform cancellation/grant issue, not model evidence; no further blind hint probes. From 4202d3b4db1eba2eff3c76f3b8f1e7942ce884f9 Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Thu, 27 Aug 2026 13:32:28 +0200 Subject: [PATCH 04/35] docs(harbour): record default-model corpus regression --- apps/storycore-harbour/STATUS.md | 1 + apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md | 1 + 2 files changed, 2 insertions(+) diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 9643acaf..ae2c3002 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -292,3 +292,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - A fresh Gemma A06 reproduction ruled out a bounded syntax-only repair. The primary output was missing one final brace, but appending it still left characters, locations, scenes, score, and warnings absent. The model repair was valid JSON yet again omitted the production bible and all core arrays. Parser recovery must remain fail-closed because required creative structure cannot be inferred safely. - A single A06 diagnostic using Anna's documented example hint `gpt-4o` produced no completion or model metadata. The UI recorded timeout while the harness request remained pending for more than six minutes and only window heartbeats continued. The server was stopped to terminate the orphaned request; do not retry this hint until Anna exposes model grants or fixes cancellation/deadline propagation. - Reliability evidence is now a two-profile matrix: Anna default 16/20; Gemma preference 14/20. Both fail the 18/20 gate. No readiness, version cut, review, or release claim is permitted. +- An owner-authorized complete corpus rerun on 2026-08-27 used Anna default `minimax/minimax-m3` through OpenRouter and regressed to 6/20. Median successful duration was 49.13 seconds, p95 was 57.87 seconds, and 2 successful projects used repair. Privacy-safe failures were eight `json_invalid`, five `contract_invalid`, and one timeout. The complete private result remains ignored at `acceptance/results.2026-08-27.local.jsonl`. This stochastic regression does not justify weakening the contract or cutting a version; it reinforces the unresolved default-model reliability blocker. diff --git a/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md b/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md index fa12b55a..6eb884d1 100644 --- a/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md +++ b/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md @@ -91,3 +91,4 @@ Do not replace production-platform gates with these local results. - Rejected experiment: Anna-default primary plus Gemma-only repair scored 2/4 on A02/A07/A15/A18, below Gemma-only 3/4. The diagnostic code was removed; do not add separate repair-model complexity without new platform evidence. - A06 reproduction: one missing final brace was not the root cause. Both the completed primary object and the syntactically valid repair lacked the required creative structure. Keep fail-closed validation; do not synthesize characters, locations, scenes, or continuity data in the parser. - Third-model probe blocked: hint `gpt-4o` returned no response metadata and remained pending beyond the App timeout. Treat it as a platform cancellation/grant issue, not model evidence; no further blind hint probes. +- 27 August default-model rerun: the complete immutable corpus used `minimax/minimax-m3` through OpenRouter and finished at 6/20, median 49.13 seconds, p95 57.87 seconds, and 2 repaired passes. The privacy-safe failure matrix was eight `json_invalid`, five `contract_invalid`, and one timeout. The ignored private JSONL is `acceptance/results.2026-08-27.local.jsonl`. This is a measured stochastic regression from the earlier 16/20 default run, so readiness remains blocked and no parser relaxation, immutable version, review submission, or release is justified. From 2ee3beecfbe5dff2084a8dd51f27f4d175ae9033 Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Thu, 27 Aug 2026 14:30:21 +0200 Subject: [PATCH 05/35] docs(harbour): record Gemma corpus rerun --- apps/storycore-harbour/STATUS.md | 1 + apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md | 1 + 2 files changed, 2 insertions(+) diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index ae2c3002..6f87db17 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -293,3 +293,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - A single A06 diagnostic using Anna's documented example hint `gpt-4o` produced no completion or model metadata. The UI recorded timeout while the harness request remained pending for more than six minutes and only window heartbeats continued. The server was stopped to terminate the orphaned request; do not retry this hint until Anna exposes model grants or fixes cancellation/deadline propagation. - Reliability evidence is now a two-profile matrix: Anna default 16/20; Gemma preference 14/20. Both fail the 18/20 gate. No readiness, version cut, review, or release claim is permitted. - An owner-authorized complete corpus rerun on 2026-08-27 used Anna default `minimax/minimax-m3` through OpenRouter and regressed to 6/20. Median successful duration was 49.13 seconds, p95 was 57.87 seconds, and 2 successful projects used repair. Privacy-safe failures were eight `json_invalid`, five `contract_invalid`, and one timeout. The complete private result remains ignored at `acceptance/results.2026-08-27.local.jsonl`. This stochastic regression does not justify weakening the contract or cutting a version; it reinforces the unresolved default-model reliability blocker. +- A second owner-authorized complete corpus rerun on 2026-08-27 used the advisory `gemma` hint and finished at 15/20. Median successful duration was 21.91 seconds, p95 was 41.92 seconds, and 6 successful projects used repair. Privacy-safe failures were A07/A10/A12/A19 `contract_invalid` and A20 `required_field_invalid`; there were no timeouts or JSON truncations. The private result remains ignored at `acceptance/results.2026-08-27.gemma.local.jsonl`. This improves the measured Gemma profile from 14/20 to 15/20 but remains below the 18/20 gate, so no readiness, version cut, review submission, or release claim is permitted. diff --git a/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md b/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md index 6eb884d1..bac4b8d0 100644 --- a/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md +++ b/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md @@ -92,3 +92,4 @@ Do not replace production-platform gates with these local results. - A06 reproduction: one missing final brace was not the root cause. Both the completed primary object and the syntactically valid repair lacked the required creative structure. Keep fail-closed validation; do not synthesize characters, locations, scenes, or continuity data in the parser. - Third-model probe blocked: hint `gpt-4o` returned no response metadata and remained pending beyond the App timeout. Treat it as a platform cancellation/grant issue, not model evidence; no further blind hint probes. - 27 August default-model rerun: the complete immutable corpus used `minimax/minimax-m3` through OpenRouter and finished at 6/20, median 49.13 seconds, p95 57.87 seconds, and 2 repaired passes. The privacy-safe failure matrix was eight `json_invalid`, five `contract_invalid`, and one timeout. The ignored private JSONL is `acceptance/results.2026-08-27.local.jsonl`. This is a measured stochastic regression from the earlier 16/20 default run, so readiness remains blocked and no parser relaxation, immutable version, review submission, or release is justified. +- 27 August Gemma rerun: the complete immutable corpus with advisory hint `gemma` finished at 15/20, median 21.91 seconds, p95 41.92 seconds, and 6 repaired passes. Failures were A07/A10/A12/A19 `contract_invalid` and A20 `required_field_invalid`, with no timeout or JSON truncation. The ignored private JSONL is `acceptance/results.2026-08-27.gemma.local.jsonl`. This improves the measured Gemma profile from 14/20 to 15/20 but remains below the 18/20 gate; keep the PR draft and do not cut, submit, or release a version. From 718eaa57ec3bd9ae2007df4e0654596d1ed8e88c Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Fri, 28 Aug 2026 09:50:07 +0200 Subject: [PATCH 06/35] test(harbour): refine privacy-safe acceptance failures --- apps/storycore-harbour/STATUS.md | 1 + .../bundle/acceptance-failure.js | 17 ++++++++++++++++- .../tests/acceptance-failure-name.test.mjs | 11 +++++++++++ 3 files changed, 28 insertions(+), 1 deletion(-) diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 6f87db17..59a73953 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -294,3 +294,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - Reliability evidence is now a two-profile matrix: Anna default 16/20; Gemma preference 14/20. Both fail the 18/20 gate. No readiness, version cut, review, or release claim is permitted. - An owner-authorized complete corpus rerun on 2026-08-27 used Anna default `minimax/minimax-m3` through OpenRouter and regressed to 6/20. Median successful duration was 49.13 seconds, p95 was 57.87 seconds, and 2 successful projects used repair. Privacy-safe failures were eight `json_invalid`, five `contract_invalid`, and one timeout. The complete private result remains ignored at `acceptance/results.2026-08-27.local.jsonl`. This stochastic regression does not justify weakening the contract or cutting a version; it reinforces the unresolved default-model reliability blocker. - A second owner-authorized complete corpus rerun on 2026-08-27 used the advisory `gemma` hint and finished at 15/20. Median successful duration was 21.91 seconds, p95 was 41.92 seconds, and 6 successful projects used repair. Privacy-safe failures were A07/A10/A12/A19 `contract_invalid` and A20 `required_field_invalid`; there were no timeouts or JSON truncations. The private result remains ignored at `acceptance/results.2026-08-27.gemma.local.jsonl`. This improves the measured Gemma profile from 14/20 to 15/20 but remains below the 18/20 gate, so no readiness, version cut, review submission, or release claim is permitted. +- Future acceptance runs now classify schema, timestamp, duplicate, ordering, continuity-score, structure, and parent-scene reference failures with stable privacy-safe names. Unknown validation details still collapse to `contract_invalid`; generated content and private identifiers are never persisted in the public result. diff --git a/apps/storycore-harbour/bundle/acceptance-failure.js b/apps/storycore-harbour/bundle/acceptance-failure.js index 65cedd80..366e2547 100644 --- a/apps/storycore-harbour/bundle/acceptance-failure.js +++ b/apps/storycore-harbour/bundle/acceptance-failure.js @@ -20,12 +20,27 @@ export function publicFailureName(message, category) { return "json_invalid"; } if (value.includes("severity must be")) return "warning_severity_invalid"; - if (value.includes("references unknown") || value.includes("unknown scene") || value.includes("unknown character")) { + if ( + value.includes("references unknown") || + value.includes("unknown scene") || + value.includes("unknown character") || + value.includes("not listed in the parent scene") + ) { return "reference_invalid"; } if (value.includes("duration")) return "duration_invalid"; + if (value.includes("schemaversion must be") || value.includes("project.format is unsupported")) { + return "schema_invalid"; + } + if (value.includes("iso-compatible date-time")) return "timestamp_invalid"; + if (value.includes("duplicate")) return "duplicate_invalid"; + if (value.includes("must be a positive integer")) return "ordering_invalid"; + if (value.includes("continuityreport.score")) return "continuity_score_invalid"; if (value.includes("required") || value.includes("must contain") || value.includes("must be a string")) { return "required_field_invalid"; } + if (value.includes("must be an array") || value.includes("must be an object")) { + return "structure_invalid"; + } return "contract_invalid"; } diff --git a/apps/storycore-harbour/tests/acceptance-failure-name.test.mjs b/apps/storycore-harbour/tests/acceptance-failure-name.test.mjs index 92c40de3..a00be603 100644 --- a/apps/storycore-harbour/tests/acceptance-failure-name.test.mjs +++ b/apps/storycore-harbour/tests/acceptance-failure-name.test.mjs @@ -7,7 +7,18 @@ test("contract failure details map to stable privacy-safe names", () => { assert.equal(publicFailureName("JSON parse failed: Unterminated string", "contract"), "json_invalid"); assert.equal(publicFailureName("warnings[0].severity must be info", "contract"), "warning_severity_invalid"); assert.equal(publicFailureName("sceneId references unknown scene secret-scene", "contract"), "reference_invalid"); + assert.equal( + publicFailureName("shot references secret-character, but that character is not listed in the parent scene", "contract"), + "reference_invalid", + ); assert.equal(publicFailureName("Total scene duration is implausibly short", "contract"), "duration_invalid"); + assert.equal(publicFailureName("schemaVersion must be storycore.project.v1", "contract"), "schema_invalid"); + assert.equal(publicFailureName("project.format is unsupported: private-format", "contract"), "schema_invalid"); + assert.equal(publicFailureName("project.createdAt must be an ISO-compatible date-time", "contract"), "timestamp_invalid"); + assert.equal(publicFailureName("Duplicate id at characters[1]: private-id", "contract"), "duplicate_invalid"); + assert.equal(publicFailureName("scenes[0].order must be a positive integer", "contract"), "ordering_invalid"); + assert.equal(publicFailureName("continuityReport.score must be between 0 and 100", "contract"), "continuity_score_invalid"); + assert.equal(publicFailureName("scenes must be an array", "contract"), "structure_invalid"); }); test("unknown contract details never enter the public failure name", () => { From 03c2c54b9b91471dac3e89be8cda37a7406f670c Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Fri, 28 Aug 2026 09:53:40 +0200 Subject: [PATCH 07/35] docs(harbour): record Anna draft revision 10 --- apps/storycore-harbour/STATUS.md | 1 + 1 file changed, 1 insertion(+) diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 59a73953..49c50cd8 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -295,3 +295,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - An owner-authorized complete corpus rerun on 2026-08-27 used Anna default `minimax/minimax-m3` through OpenRouter and regressed to 6/20. Median successful duration was 49.13 seconds, p95 was 57.87 seconds, and 2 successful projects used repair. Privacy-safe failures were eight `json_invalid`, five `contract_invalid`, and one timeout. The complete private result remains ignored at `acceptance/results.2026-08-27.local.jsonl`. This stochastic regression does not justify weakening the contract or cutting a version; it reinforces the unresolved default-model reliability blocker. - A second owner-authorized complete corpus rerun on 2026-08-27 used the advisory `gemma` hint and finished at 15/20. Median successful duration was 21.91 seconds, p95 was 41.92 seconds, and 6 successful projects used repair. Privacy-safe failures were A07/A10/A12/A19 `contract_invalid` and A20 `required_field_invalid`; there were no timeouts or JSON truncations. The private result remains ignored at `acceptance/results.2026-08-27.gemma.local.jsonl`. This improves the measured Gemma profile from 14/20 to 15/20 but remains below the 18/20 gate, so no readiness, version cut, review submission, or release claim is permitted. - Future acceptance runs now classify schema, timestamp, duplicate, ordering, continuity-score, structure, and parent-scene reference failures with stable privacy-safe names. Unknown validation details still collapse to `contract_invalid`; generated content and private identifiers are never persisted in the public result. +- The privacy-safe diagnostic update is synchronized to Anna working draft revision 10. The 15-file, 104,031-byte bundle is ready with content hash `7d3edf2a89b942055c4af9d53b7dcfb6de1777e0437b27711b05bef09e2049b9`. The App remains a mutable draft with zero immutable versions; this synchronization is not an installation, review, or release claim. From 76965d0c271276f28b90c56511d9acdb29824d40 Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Fri, 28 Aug 2026 10:09:04 +0200 Subject: [PATCH 08/35] docs(harbour): refresh owner handoff and grants evidence --- apps/storycore-harbour/STATUS.md | 1 + .../review/FINAL_HANDOFF_2026-08-24.md | 16 +++++++++------- .../review/OWNER_ACTIVATION_AND_FIRST_REVIEW.md | 8 ++++++++ 3 files changed, 18 insertions(+), 7 deletions(-) diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 49c50cd8..4c17d7d6 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -296,3 +296,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - A second owner-authorized complete corpus rerun on 2026-08-27 used the advisory `gemma` hint and finished at 15/20. Median successful duration was 21.91 seconds, p95 was 41.92 seconds, and 6 successful projects used repair. Privacy-safe failures were A07/A10/A12/A19 `contract_invalid` and A20 `required_field_invalid`; there were no timeouts or JSON truncations. The private result remains ignored at `acceptance/results.2026-08-27.gemma.local.jsonl`. This improves the measured Gemma profile from 14/20 to 15/20 but remains below the 18/20 gate, so no readiness, version cut, review submission, or release claim is permitted. - Future acceptance runs now classify schema, timestamp, duplicate, ordering, continuity-score, structure, and parent-scene reference failures with stable privacy-safe names. Unknown validation details still collapse to `contract_invalid`; generated content and private identifiers are never persisted in the public result. - The privacy-safe diagnostic update is synchronized to Anna working draft revision 10. The 15-file, 104,031-byte bundle is ready with content hash `7d3edf2a89b942055c4af9d53b7dcfb6de1777e0437b27711b05bef09e2049b9`. The App remains a mutable draft with zero immutable versions; this synchronization is not an installation, review, or release claim. +- Read-only `apps grants storycore-harbour --json` currently returns `grants: null`. In CLI 0.1.30 this specifically represents a 404 from the informational grants endpoint (`no grants endpoint data available`), not evidence that the declared Host APIs were denied. Prior authenticated Host calls remain the capability evidence; do not use this null result to claim either a grant or a denial. diff --git a/apps/storycore-harbour/review/FINAL_HANDOFF_2026-08-24.md b/apps/storycore-harbour/review/FINAL_HANDOFF_2026-08-24.md index fec6a12a..ed197550 100644 --- a/apps/storycore-harbour/review/FINAL_HANDOFF_2026-08-24.md +++ b/apps/storycore-harbour/review/FINAL_HANDOFF_2026-08-24.md @@ -1,5 +1,7 @@ # Anna opportunity final handoff — 24 August 2026 +Updated with verified remote state on 28 August 2026. + This document records the verified draft state. It is not authorization to cut a version, submit a review, publish, accept new terms, or spend additional model quota. ## StoryCore Harbour @@ -7,19 +9,19 @@ This document records the verified draft state. It is not authorization to cut a ### Local candidate - branch: `codex/anna-mvp-20260824`; -- latest integration commit before this handoff refresh: `ec2d9da7`; -- GitHub branch `agent/storycore-harbour-bootstrap` was updated through PR #30 without force-push; the PR remains draft and unmerged; +- latest integration commit at this handoff refresh: `03c2c54b`; +- GitHub branch `agent/storycore-harbour-bootstrap` is synchronized through draft PR #37 without force-push; PR #30 and PR #36 are merged, while PR #37 remains open, green, and unmerged; - core StoryCore Engine checkout was not merged, reset, cleaned, or overwritten; - Anna adapter remains isolated under `apps/storycore-harbour/`; -- automated gate: 60/60 Node tests, sample contract, mock fixture, fixed corpus, bundle synchronization, and strict Anna validation pass. +- automated gate: 66/66 Node tests, sample contract, mock fixture, fixed corpus, bundle synchronization, strict Anna validation, GitHub Anna CI, and SonarQube pass. ### Anna draft - public identity: `@storycore-labs/storycore-harbour`; - server App id: `214`; -- working revision: `9`; -- content hash: `762e175e7f150d47845b3fa4ace51d2f058d1758cc4c19f06d621b9756dada74`; -- bundle: 15 files, 103,405 bytes, `ready`; +- working revision: `10`; +- content hash: `7d3edf2a89b942055c4af9d53b7dcfb6de1777e0437b27711b05bef09e2049b9`; +- bundle: 15 files, 104,031 bytes, `ready`; - status: `draft`, not published; - immutable versions: 0; - Executas/local shims: 0. @@ -99,7 +101,7 @@ without addressing the failure. ### Submission decision -Do not cut `0.1.0`, submit for review, mark PR #30 ready, merge, or release while the official gate remains below 18/20. The App is demonstrable and its working draft is reserved, but it is not submission-ready under the repository's own rules. +Do not cut `0.1.0`, submit for review, mark PR #37 ready, merge, or release while the official gate remains below 18/20. The latest measured Gemma run is 15/20 and the latest Anna-default run is 6/20. The App is demonstrable and its working draft is reserved, but it is not submission-ready under the repository's own rules. ### Anna installation diagnosis diff --git a/apps/storycore-harbour/review/OWNER_ACTIVATION_AND_FIRST_REVIEW.md b/apps/storycore-harbour/review/OWNER_ACTIVATION_AND_FIRST_REVIEW.md index de345d56..80d1de1c 100644 --- a/apps/storycore-harbour/review/OWNER_ACTIVATION_AND_FIRST_REVIEW.md +++ b/apps/storycore-harbour/review/OWNER_ACTIVATION_AND_FIRST_REVIEW.md @@ -173,10 +173,18 @@ Only after checking the dry-run output: npx --no-install anna-app apps push --json npx --no-install anna-app apps status storycore-harbour --json npx --no-install anna-app apps list --json +npx --no-install anna-app apps grants storycore-harbour --json ``` `apps push` creates or updates a mutable **working draft**. It is not a public release and should not make the App visible in the public Store. +The grants endpoint is informational only. With the currently pinned CLI, a +JSON result containing `"grants": null` means the server returned 404 for the +public grants endpoint and the CLI has no endpoint data available. It does not +prove that the App was denied the Host APIs declared in the manifest. Confirm +actual LLM, storage, and window capabilities through the authenticated harness +and recorded Host calls; do not infer permission state from `null`. + After the first successful push: - verify that `.anna/app.json` identifies the expected remote App; From cdaf4c03acf79dd000946b9f2411b710e865ef5b Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Fri, 28 Aug 2026 11:25:00 +0200 Subject: [PATCH 09/35] test(harbour): run browser smokes sequentially --- apps/storycore-harbour/README.md | 6 ++++++ apps/storycore-harbour/STATUS.md | 1 + apps/storycore-harbour/package.json | 1 + 3 files changed, 8 insertions(+) diff --git a/apps/storycore-harbour/README.md b/apps/storycore-harbour/README.md index 87b67679..dfbc0ce4 100644 --- a/apps/storycore-harbour/README.md +++ b/apps/storycore-harbour/README.md @@ -67,6 +67,12 @@ npm run dev:mock `npm install` also generates the bundle copy of the canonical acceptance corpus. `npm run check` runs the tests, contract, mock response, acceptance corpus/synchronization, and strict Anna validator. +With the mock Anna harness already running, set `BROWSER_EXECUTABLE` to Edge or +another compatible Chromium binary and run `npm run browser:check`. This runs +the complete generation/export smoke and the storage-deletion smoke +sequentially. Do not run them in parallel against one mock harness because the +fixture stream is shared. + For the real-model protocol, follow `acceptance/README.md`. Do not run the collector without an authenticated Anna test account, an enabled model, sufficient quota, and explicit confirmation in its UI. ## Release identity diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 4c17d7d6..4db805a5 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -297,3 +297,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - Future acceptance runs now classify schema, timestamp, duplicate, ordering, continuity-score, structure, and parent-scene reference failures with stable privacy-safe names. Unknown validation details still collapse to `contract_invalid`; generated content and private identifiers are never persisted in the public result. - The privacy-safe diagnostic update is synchronized to Anna working draft revision 10. The 15-file, 104,031-byte bundle is ready with content hash `7d3edf2a89b942055c4af9d53b7dcfb6de1777e0437b27711b05bef09e2049b9`. The App remains a mutable draft with zero immutable versions; this synchronization is not an installation, review, or release claim. - Read-only `apps grants storycore-harbour --json` currently returns `grants: null`. In CLI 0.1.30 this specifically represents a 404 from the informational grants endpoint (`no grants endpoint data available`), not evidence that the declared Host APIs were denied. Prior authenticated Host calls remain the capability evidence; do not use this null result to claim either a grant or a denial. +- Fresh Edge verification on 2026-08-28 passed the 520 × 680 generation/export flow, keyboard navigation, focus management, reduced-motion context, 400% text reflow, project reset/restore, and contract-valid export. The deletion smoke also passed sequentially with two ETag deletions, paginated listing, unrelated-key preservation, and a not-found reload. A new `browser:check` script fixes the intended sequential order because both smokes share one mock fixture stream. diff --git a/apps/storycore-harbour/package.json b/apps/storycore-harbour/package.json index 1a8b13dd..b2f83d72 100644 --- a/apps/storycore-harbour/package.json +++ b/apps/storycore-harbour/package.json @@ -18,6 +18,7 @@ "test": "node --test tests/*.test.mjs", "browser:smoke": "node scripts/browser-smoke.mjs", "browser:deletion-smoke": "node scripts/browser-deletion-smoke.mjs", + "browser:check": "npm run browser:smoke && npm run browser:deletion-smoke", "contract:check": "node scripts/validate-project.mjs examples/sample-project.json", "acceptance:sync": "node scripts/sync-acceptance-corpus.mjs", "acceptance:sync:check": "node scripts/check-bundled-corpus.mjs", From 13adb0273dd5efe0c18936b73b201155272bcd4b Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Fri, 28 Aug 2026 11:54:31 +0200 Subject: [PATCH 10/35] fix(harbour): preserve states in forced colours --- apps/storycore-harbour/STATUS.md | 1 + apps/storycore-harbour/bundle/style.css | 29 ++++++++++++++ .../scripts/browser-smoke.mjs | 39 +++++++++++++++++++ 3 files changed, 69 insertions(+) diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 4db805a5..1d1f3af9 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -298,3 +298,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - The privacy-safe diagnostic update is synchronized to Anna working draft revision 10. The 15-file, 104,031-byte bundle is ready with content hash `7d3edf2a89b942055c4af9d53b7dcfb6de1777e0437b27711b05bef09e2049b9`. The App remains a mutable draft with zero immutable versions; this synchronization is not an installation, review, or release claim. - Read-only `apps grants storycore-harbour --json` currently returns `grants: null`. In CLI 0.1.30 this specifically represents a 404 from the informational grants endpoint (`no grants endpoint data available`), not evidence that the declared Host APIs were denied. Prior authenticated Host calls remain the capability evidence; do not use this null result to claim either a grant or a denial. - Fresh Edge verification on 2026-08-28 passed the 520 × 680 generation/export flow, keyboard navigation, focus management, reduced-motion context, 400% text reflow, project reset/restore, and contract-valid export. The deletion smoke also passed sequentially with two ETag deletions, paginated listing, unrelated-key preservation, and a not-found reload. A new `browser:check` script fixes the intended sequential order because both smokes share one mock fixture stream. +- Edge now emulates `forced-colors: active` during the browser smoke and verifies visible keyboard focus, a non-colour selected-step outline, fully opaque dashed disabled controls, and a solid error boundary. The App also supplies forced-colour treatments for warning/success/error deletion states, armed destructive actions, and the continuity score. This automated evidence reduces risk but does not replace the remaining human Windows High Contrast and screen-reader passes. diff --git a/apps/storycore-harbour/bundle/style.css b/apps/storycore-harbour/bundle/style.css index 4438a806..1d7cb26e 100644 --- a/apps/storycore-harbour/bundle/style.css +++ b/apps/storycore-harbour/bundle/style.css @@ -244,3 +244,32 @@ footer { @media (prefers-reduced-motion: reduce) { *, *::before, *::after { animation-duration: .001ms !important; animation-iteration-count: 1 !important; scroll-behavior: auto !important; } } +@media (forced-colors: active) { + button:focus, input:focus, select:focus, textarea:focus { + outline: 3px solid Highlight; + outline-offset: 2px; + } + button:focus-visible, input:focus-visible, select:focus-visible, textarea:focus-visible { + outline-color: Highlight; + } + .step.active { + color: HighlightText; + background: Highlight; + outline: 2px solid Highlight; + outline-offset: -3px; + } + button:disabled { + opacity: 1; + color: GrayText; + border-color: GrayText; + border-style: dashed; + } + .message.error, .error-panel, .deletion-status.error { + color: CanvasText; + border: 2px solid CanvasText; + } + .deletion-status.warning { border-style: dashed; } + .deletion-status.success { border-style: double; } + button.danger-outline.armed { outline: 3px double CanvasText; } + .score { border-color: CanvasText; } +} diff --git a/apps/storycore-harbour/scripts/browser-smoke.mjs b/apps/storycore-harbour/scripts/browser-smoke.mjs index 8f574340..71638a91 100644 --- a/apps/storycore-harbour/scripts/browser-smoke.mjs +++ b/apps/storycore-harbour/scripts/browser-smoke.mjs @@ -94,6 +94,7 @@ try { await waitForFocus(app.locator("#form-error")); assert.equal(await app.locator("#step-1").isVisible(), true); assert.equal(await app.locator("#step-2").isVisible(), false); + await assertForcedColorsAccessibility(page, app); await fillReferenceProject(app); assert.match((await app.locator("#idea-count").textContent()) || "", /\/ 12,000/); @@ -254,6 +255,7 @@ try { result: "pass", viewport: { width: dimensions.clientWidth, height: minimumFrameSize.height }, textReflow400Percent: "pass", + forcedColors: "pass", formValidationFocus: "pass", keyboardStepNavigation: "pass", panelFocusManagement: "pass", @@ -316,6 +318,43 @@ async function setFrameSize(frameElement, size) { }, size); } +async function assertForcedColorsAccessibility(page, app) { + await page.emulateMedia({ forcedColors: "active" }); + try { + await app.getByRole("button", { name: "Build my visual story" }).focus(); + const state = await app.locator("html").evaluate(() => { + const style = (selector) => getComputedStyle(document.querySelector(selector)); + const activeStep = style(".step.active"); + const disabledStep = style("#step-tab-2"); + const error = style("#form-error"); + const focusedButton = style("#generate-button"); + return { + mediaActive: matchMedia("(forced-colors: active)").matches, + activeOutlineStyle: activeStep.outlineStyle, + activeOutlineWidth: activeStep.outlineWidth, + disabledOpacity: disabledStep.opacity, + disabledBorderStyle: disabledStep.borderTopStyle, + errorBorderStyle: error.borderTopStyle, + errorBorderWidth: error.borderTopWidth, + focusOutlineStyle: focusedButton.outlineStyle, + focusOutlineWidth: focusedButton.outlineWidth, + }; + }); + + assert.equal(state.mediaActive, true, "Edge must activate the forced-colours media query."); + assert.equal(state.activeOutlineStyle, "solid", "The selected step needs a non-colour outline."); + assert.equal(state.activeOutlineWidth, "2px"); + assert.equal(state.disabledOpacity, "1", "Disabled controls must remain legible in forced colours."); + assert.equal(state.disabledBorderStyle, "dashed", "Disabled controls need a non-colour distinction."); + assert.equal(state.errorBorderStyle, "solid", "Errors need a visible forced-colour boundary."); + assert.equal(state.errorBorderWidth, "2px"); + assert.equal(state.focusOutlineStyle, "solid", "Keyboard focus must remain visible in forced colours."); + assert.equal(state.focusOutlineWidth, "3px"); + } finally { + await page.emulateMedia({ forcedColors: "none" }); + } +} + async function installDeterministicTestStorage(app) { return app.locator("html").evaluate(() => { const runtime = window.anna; From 96df0e1dbb70b967b7b10464f97738595fc34780 Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Fri, 28 Aug 2026 11:57:47 +0200 Subject: [PATCH 11/35] docs(harbour): record Anna draft revision 11 --- apps/storycore-harbour/STATUS.md | 1 + 1 file changed, 1 insertion(+) diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 1d1f3af9..7303578a 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -299,3 +299,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - Read-only `apps grants storycore-harbour --json` currently returns `grants: null`. In CLI 0.1.30 this specifically represents a 404 from the informational grants endpoint (`no grants endpoint data available`), not evidence that the declared Host APIs were denied. Prior authenticated Host calls remain the capability evidence; do not use this null result to claim either a grant or a denial. - Fresh Edge verification on 2026-08-28 passed the 520 × 680 generation/export flow, keyboard navigation, focus management, reduced-motion context, 400% text reflow, project reset/restore, and contract-valid export. The deletion smoke also passed sequentially with two ETag deletions, paginated listing, unrelated-key preservation, and a not-found reload. A new `browser:check` script fixes the intended sequential order because both smokes share one mock fixture stream. - Edge now emulates `forced-colors: active` during the browser smoke and verifies visible keyboard focus, a non-colour selected-step outline, fully opaque dashed disabled controls, and a solid error boundary. The App also supplies forced-colour treatments for warning/success/error deletion states, armed destructive actions, and the continuity score. This automated evidence reduces risk but does not replace the remaining human Windows High Contrast and screen-reader passes. +- The forced-colour fix is synchronized to Anna working draft revision 11. Its 15-file, 104,890-byte bundle is ready with content hash `c5ddb6b3a45b42cebb3ceed713f65121ba3efac9808fece05aa05ad6ce863a17`; the App still has zero immutable versions and remains unpublished. From 17b7095795e832f564c310e7b6a742b4e9d1c4a6 Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Fri, 28 Aug 2026 20:54:37 +0200 Subject: [PATCH 12/35] docs(harbour): refresh revision 11 demo evidence --- apps/storycore-harbour/STATUS.md | 1 + .../demo/EVIDENCE_2026-08-28_REVISION_11.md | 24 +++++++++++++++++++ apps/storycore-harbour/demo/README.md | 18 ++++++++++---- .../scripts/browser-smoke.mjs | 5 +++- 4 files changed, 42 insertions(+), 6 deletions(-) create mode 100644 apps/storycore-harbour/demo/EVIDENCE_2026-08-28_REVISION_11.md diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 7303578a..65503fda 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -300,3 +300,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - Fresh Edge verification on 2026-08-28 passed the 520 × 680 generation/export flow, keyboard navigation, focus management, reduced-motion context, 400% text reflow, project reset/restore, and contract-valid export. The deletion smoke also passed sequentially with two ETag deletions, paginated listing, unrelated-key preservation, and a not-found reload. A new `browser:check` script fixes the intended sequential order because both smokes share one mock fixture stream. - Edge now emulates `forced-colors: active` during the browser smoke and verifies visible keyboard focus, a non-colour selected-step outline, fully opaque dashed disabled controls, and a solid error boundary. The App also supplies forced-colour treatments for warning/success/error deletion states, armed destructive actions, and the continuity score. This automated evidence reduces risk but does not replace the remaining human Windows High Contrast and screen-reader passes. - The forced-colour fix is synchronized to Anna working draft revision 11. Its 15-file, 104,890-byte bundle is ready with content hash `c5ddb6b3a45b42cebb3ceed713f65121ba3efac9808fece05aa05ad6ce863a17`; the App still has zero immutable versions and remains unpublished. +- Revision 11 demo evidence was regenerated locally in under twenty seconds: four visually inspected 900 × 820 PNGs plus a 3,288-byte contract-valid JSON export. The generated files remain ignored under `demo/output.local/revision-11/`; their sizes and one-run SHA-256 values are recorded in `demo/EVIDENCE_2026-08-28_REVISION_11.md`. The screenshot helper now resets every App scroll container before capture, fixing the measured missing-header defect on the World draft. diff --git a/apps/storycore-harbour/demo/EVIDENCE_2026-08-28_REVISION_11.md b/apps/storycore-harbour/demo/EVIDENCE_2026-08-28_REVISION_11.md new file mode 100644 index 00000000..55fd5b7f --- /dev/null +++ b/apps/storycore-harbour/demo/EVIDENCE_2026-08-28_REVISION_11.md @@ -0,0 +1,24 @@ +# StoryCore Harbour demo evidence — Anna draft revision 11 + +Generated locally on 2026-08-28 with the deterministic Anna mock harness and +Microsoft Edge. No Anna model quota, production storage, provider key, or +private prompt was used. The local run completed in under twenty seconds. + +| Artifact | Dimensions | Bytes | SHA-256 | +| --- | ---: | ---: | --- | +| `01-concept.png` | 900 x 820 | 100,272 | `4e5f6ee1f694d30ba8639db511e7b843b92a57228c06b17a44a56be6a60b1e9a` | +| `02-world.png` | 900 x 820 | 105,664 | `60da7be8ca9c56aa6e94f65a36e6b9f23ce0271ee8cc9dc272f571a6b489a4f0` | +| `03-scenes.png` | 900 x 820 | 93,409 | `73e3745867bc21c99701a6b334a7311a86ef7b7a3c10665434cff3c1271c6dc5` | +| `04-continuity.png` | 900 x 820 | 94,405 | `1add93ddd51cd37086b88f73592f1e7864006384f375a2f50f4ad82af823df7d` | +| `browser-smoke-story.storycore-harbour.json` | n/a | 3,288 | `fe10fa513a326fc26d71aea7ddd6a508e9d5f69d57fbf7696c3c4aa95f2a72e2` | + +The JSON export passed the canonical `storycore-harbour.project.v1` validator. +The four screenshots were visually inspected for clipping, inconsistent scroll +position, missing headers, misleading media claims, and obvious unreadable +content. They remain draft Marketplace evidence until Anna confirms its exact +image dimensions and file-size rules. + +The generated artifacts remain intentionally ignored under +`demo/output.local/revision-11/`. Reproduce them with the exact procedure in +`demo/README.md`; do not commit generated project text or screenshots merely to +replace the authenticated real-model, accessibility, or beta gates. diff --git a/apps/storycore-harbour/demo/README.md b/apps/storycore-harbour/demo/README.md index 5bfd10e2..8fda9c0c 100644 --- a/apps/storycore-harbour/demo/README.md +++ b/apps/storycore-harbour/demo/README.md @@ -28,21 +28,23 @@ Keep that terminal open. In a second PowerShell terminal, from the same director ```powershell $env:BROWSER_EXECUTABLE = 'C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe' $env:HARBOUR_URL = 'http://127.0.0.1:5180/' -$env:HARBOUR_SCREENSHOT_DIR = (Resolve-Path '.').Path + '\demo\output.local' -npm run browser:smoke +$env:HARBOUR_SCREENSHOT_DIR = (Resolve-Path '.').Path + '\demo\output.local\current' +npm run browser:check ``` Expected final line: ```text -{"result":"pass",...,"exportContract":"valid",...,"screenshotsCaptured":4,...} +{"result":"pass",...,"forcedColors":"pass",...,"exportContract":"valid",...,"screenshotsCaptured":4,...} +{"result":"pass","deletedProjectRecords":2,...,"unrelatedKeyPreserved":true,...} ``` Stop the mock harness with `Ctrl+C` after the browser command finishes. ## Produced evidence -The browser run writes these local, ignored artifacts to `demo/output.local/`: +The browser run writes these local, ignored artifacts to the selected +`HARBOUR_SCREENSHOT_DIR`: - `01-concept.png`; - `02-world.png`; @@ -50,7 +52,13 @@ The browser run writes these local, ignored artifacts to `demo/output.local/`: - `04-continuity.png`; - `browser-smoke-story.storycore-harbour.json`. -The browser test validates the actual export blob against `storycore-harbour.project.v1` before writing it. It also proves form validation, save/read-back, keyboard step navigation, focus management, the declared 520 x 680 minimum viewport, and 400% text reflow. +Each PNG is captured at 900 x 820. The browser test resets the App scroll before +every capture and validates the actual export blob against +`storycore-harbour.project.v1` before writing it. It also proves form +validation, save/read-back, keyboard step navigation, focus management, +forced-colour states, the declared 520 x 680 minimum viewport, 400% text +reflow, and safe project deletion. Hashes may vary with the Edge build and font +renderer; use them as one-run evidence, not portable golden-image assertions. ## Presenter script diff --git a/apps/storycore-harbour/scripts/browser-smoke.mjs b/apps/storycore-harbour/scripts/browser-smoke.mjs index 71638a91..5e743258 100644 --- a/apps/storycore-harbour/scripts/browser-smoke.mjs +++ b/apps/storycore-harbour/scripts/browser-smoke.mjs @@ -291,7 +291,10 @@ async function captureMarketplaceScreenshot({ app, frameElement, filename }) { await setFrameSize(frameElement, marketplaceFrameSize); await app.locator("html").evaluate(() => { if (document.activeElement instanceof HTMLElement) document.activeElement.blur(); - window.scrollTo({ top: 0, behavior: "instant" }); + window.scrollTo(0, 0); + if (document.scrollingElement) document.scrollingElement.scrollTop = 0; + document.documentElement.scrollTop = 0; + document.body.scrollTop = 0; }); const path = join(screenshotDirectory, filename); From bef958fa4334a003c0ee8d4836315369316d93d5 Mon Sep 17 00:00:00 2001 From: Sylvain Galliez <128614184+zedarvates@users.noreply.github.com> Date: Sat, 29 Aug 2026 07:43:39 +0200 Subject: [PATCH 13/35] fix(harbour): make repair prompt schema-complete --- .../storycore-harbour/bundle/repair-prompt.js | 92 ++++++++++++++++++- 1 file changed, 88 insertions(+), 4 deletions(-) diff --git a/apps/storycore-harbour/bundle/repair-prompt.js b/apps/storycore-harbour/bundle/repair-prompt.js index 3f55ed8b..24664dec 100644 --- a/apps/storycore-harbour/bundle/repair-prompt.js +++ b/apps/storycore-harbour/bundle/repair-prompt.js @@ -1,10 +1,91 @@ +const REQUIRED_SHAPE = Object.freeze({ + schemaVersion: "storycore-harbour.project.v1", + project: [ + "id", + "title", + "language", + "format", + "durationMinutes", + "audience", + "tone", + "sourceIdea", + "createdAt", + "updatedAt", + ], + productionBible: [ + "logline", + "synopsis", + "themes[]", + "visualDirection.style", + "visualDirection.palette[]", + "visualDirection.lighting", + "visualDirection.cameraLanguage", + "continuityRules[]", + ], + character: [ + "id", + "name", + "role", + "goal", + "conflict", + "visualIdentity", + "continuityRules[]", + ], + location: [ + "id", + "name", + "purpose", + "visualIdentity", + "continuityRules[]", + ], + scene: [ + "id", + "order", + "title", + "purpose", + "locationId", + "characterIds[]", + "durationSeconds", + "shots[]", + ], + shot: [ + "id", + "order", + "framing", + "camera", + "action", + "dialogue", + "sound", + "characterIds[]", + "generationPrompt", + ], + continuityReport: ["score", "warnings[]", "checkedAt"], + warning: ["severity", "message", "sceneId"], +}); + export function createRepairPrompt(input, errors) { return JSON.stringify({ - task: "Rebuild a complete StoryCore Harbour production package from the source input.", + task: "Rebuild the complete StoryCore Harbour project from the source input. The previous answer failed validation, so return a fresh self-contained project rather than a patch.", input, validationErrors: errors, - constraints: { - jsonOnly: true, + requiredShape: REQUIRED_SHAPE, + hardRules: [ + "Return exactly one JSON object and nothing else.", + "Include every required field listed in requiredShape, even when a string is intentionally empty.", + "Create exactly 3 scenes and exactly 1 shot inside each scene.", + "Create 1-3 characters and 1-3 locations; every scene locationId must reference a declared location.", + "Every scene characterIds entry must reference a declared character.", + "Every shot characterIds entry must reference a declared character also listed in its parent scene.", + "Use unique ids, scene orders 1,2,3, and shot order 1 in every scene.", + "dialogue and sound are always strings; use an empty string when there is intentionally none.", + "themes, palette, continuityRules, characterIds, shots, and warnings are always arrays.", + "warning severity is only info, warning, or error; sceneId is a declared scene id or null.", + "continuityReport.score is a number from 0 through 100.", + "Preserve input.title exactly when it is non-empty, and preserve input language, format, duration, audience, tone, and source idea.", + "Keep the entire JSON below 12000 characters; do not omit required structure to save space.", + "Before returning, silently verify the project contains project, productionBible, characters, locations, scenes, and continuityReport.", + ], + sizeBudget: { maxCharacters: 12_000, scenes: 3, shotsPerScene: 1, @@ -13,7 +94,10 @@ export function createRepairPrompt(input, errors) { synopsisMaxWords: 80, descriptionMaxWords: 40, generationPromptMaxWords: 60, - discardPreviousResponse: true, + maxThemes: 3, + maxProductionContinuityRules: 3, + maxEntityContinuityRules: 2, }, + discardPreviousResponse: true, }); } From 234987a796485083bfd9dd14d881656a9b7a817b Mon Sep 17 00:00:00 2001 From: Sylvain Galliez <128614184+zedarvates@users.noreply.github.com> Date: Sat, 29 Aug 2026 07:43:57 +0200 Subject: [PATCH 14/35] test(harbour): lock schema-complete repair contract --- .../tests/repair-prompt.test.mjs | 27 ++++++++++++++++++- 1 file changed, 26 insertions(+), 1 deletion(-) diff --git a/apps/storycore-harbour/tests/repair-prompt.test.mjs b/apps/storycore-harbour/tests/repair-prompt.test.mjs index 30413251..cafe33ba 100644 --- a/apps/storycore-harbour/tests/repair-prompt.test.mjs +++ b/apps/storycore-harbour/tests/repair-prompt.test.mjs @@ -21,7 +21,32 @@ test("repair rebuilds from the exact user input without carrying truncated model assert.deepEqual(request.input, input); assert.deepEqual(request.validationErrors, ["JSON parse failed: truncated object"]); - assert.equal(request.task, "Rebuild a complete StoryCore Harbour production package from the source input."); + assert.match(request.task, /Rebuild the complete StoryCore Harbour project/); assert.equal(Object.hasOwn(request, "previousResponse"), false); assert.equal(prompt.includes("PREVIOUS RESPONSE"), false); }); + +test("repair prompt carries a complete structural checklist without weakening the contract", async () => { + const { createRepairPrompt } = await import("../bundle/repair-prompt.js"); + const request = JSON.parse(createRepairPrompt({ + idea: "A sufficiently long fictional source idea for a repair test.", + title: "Repair shape", + format: "short-film", + durationMinutes: 3, + language: "en", + tone: "Clear", + audience: "General audience", + }, ["continuityReport.score must be between 0 and 100."])); + + assert.equal(request.requiredShape.schemaVersion, "storycore-harbour.project.v1"); + assert.ok(request.requiredShape.project.includes("sourceIdea")); + assert.ok(request.requiredShape.productionBible.includes("visualDirection.cameraLanguage")); + assert.ok(request.requiredShape.shot.includes("dialogue")); + assert.ok(request.requiredShape.shot.includes("sound")); + assert.deepEqual(request.requiredShape.continuityReport, ["score", "warnings[]", "checkedAt"]); + assert.ok(request.hardRules.some((rule) => /exactly 3 scenes/i.test(rule))); + assert.ok(request.hardRules.some((rule) => /dialogue and sound are always strings/i.test(rule))); + assert.ok(request.hardRules.some((rule) => /warning severity is only info, warning, or error/i.test(rule))); + assert.equal(request.discardPreviousResponse, true); + assert.equal(request.sizeBudget.maxCharacters, 12_000); +}); From b4a41b79d2a3f856ef35b843f46d34670f92709b Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Sat, 29 Aug 2026 08:33:00 +0200 Subject: [PATCH 15/35] docs(harbour): prepare Anna media requirements request --- apps/storycore-harbour/STATUS.md | 1 + .../review/ANNA_MEDIA_REQUIREMENTS_REQUEST.md | 55 +++++++++++++++++++ .../review/SUBMISSION_BRIEF.md | 6 ++ 3 files changed, 62 insertions(+) create mode 100644 apps/storycore-harbour/review/ANNA_MEDIA_REQUIREMENTS_REQUEST.md diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 65503fda..4536af82 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -301,3 +301,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - Edge now emulates `forced-colors: active` during the browser smoke and verifies visible keyboard focus, a non-colour selected-step outline, fully opaque dashed disabled controls, and a solid error boundary. The App also supplies forced-colour treatments for warning/success/error deletion states, armed destructive actions, and the continuity score. This automated evidence reduces risk but does not replace the remaining human Windows High Contrast and screen-reader passes. - The forced-colour fix is synchronized to Anna working draft revision 11. Its 15-file, 104,890-byte bundle is ready with content hash `c5ddb6b3a45b42cebb3ceed713f65121ba3efac9808fece05aa05ad6ce863a17`; the App still has zero immutable versions and remains unpublished. - Revision 11 demo evidence was regenerated locally in under twenty seconds: four visually inspected 900 × 820 PNGs plus a 3,288-byte contract-valid JSON export. The generated files remain ignored under `demo/output.local/revision-11/`; their sizes and one-run SHA-256 values are recorded in `demo/EVIDENCE_2026-08-28_REVISION_11.md`. The screenshot helper now resets every App scroll container before capture, fixing the measured missing-header defect on the World draft. +- Anna's public Developer Hub and pinned CLI schema were rechecked on 2026-08-29. They identify the Developer Console Listing tab as the metadata/media surface but expose no numeric screenshot or Marketplace-logo limits. Both available browser sessions required a fresh owner sign-in, so no authenticated field hints were claimed. `review/ANNA_MEDIA_REQUIREMENTS_REQUEST.md` contains the exact ready-to-send question; the 900 × 820 PNGs remain drafts and nothing was uploaded or submitted. diff --git a/apps/storycore-harbour/review/ANNA_MEDIA_REQUIREMENTS_REQUEST.md b/apps/storycore-harbour/review/ANNA_MEDIA_REQUIREMENTS_REQUEST.md new file mode 100644 index 00000000..0acd6fb5 --- /dev/null +++ b/apps/storycore-harbour/review/ANNA_MEDIA_REQUIREMENTS_REQUEST.md @@ -0,0 +1,55 @@ +# Anna Marketplace media requirements request + +Prepared on 2026-08-29. This is a support-message draft, not a submission or +authorization to upload files. + +## Verified context + +- Anna's public App Manifest documentation says listing metadata, logos, and + screenshots are managed in the Developer Console Listing tab. +- The public Developer Hub and pinned CLI schema reviewed on 2026-08-29 do not + expose numeric screenshot or Marketplace-logo constraints. +- StoryCore Harbour currently has four deterministic fictional PNG drafts at + 900 x 820. Their largest file is 105,664 bytes. +- The draft is App id 214, slug `storycore-harbour`, working revision 11, with + zero immutable versions and no public release. + +Official pages checked: + +- +- + +## Ready-to-send support message + +```text +Hi Anna team — we are preparing the first review package for StoryCore Harbour +(@storycore-labs/storycore-harbour), a Schema 2 Host-API-only App with no +Executa. + +Could you confirm the current Marketplace media requirements shown to reviewers +and developers? + +1. required screenshot count and accepted formats; +2. exact pixel dimensions or aspect-ratio range; +3. maximum bytes per screenshot; +4. Marketplace logo/icon dimensions, format, transparency, and maximum bytes; +5. any safe-area, rounded-corner, text-overlay, localization, or dark/light + theme requirements; +6. whether screenshots from the local Anna harness are acceptable when they + contain only fictional data and accurately represent the submitted bundle. + +Our current drafts are four PNG files at 900 x 820, each below 106 KB. They show +Concept, World/production bible, Scenes/shots, and Continuity/export. They do not +show account identifiers, hidden acceptance controls, provider metadata, or +real user content. + +We will not treat these drafts as final until the current requirements are +confirmed. Thank you. +``` + +## Owner action + +The owner may either inspect the authenticated Developer Console Listing field +hints or send the message above through Anna's official support channel. Do not +upload assets, submit a review, accept terms, or make a public post without the +owner's explicit approval at the time of the action. diff --git a/apps/storycore-harbour/review/SUBMISSION_BRIEF.md b/apps/storycore-harbour/review/SUBMISSION_BRIEF.md index 5a38193f..0a861487 100644 --- a/apps/storycore-harbour/review/SUBMISSION_BRIEF.md +++ b/apps/storycore-harbour/review/SUBMISSION_BRIEF.md @@ -23,6 +23,12 @@ StoryCore Harbour turns a concept, synopsis, or short script into a coherent vis The deterministic browser demo produces draft versions as `01-concept.png` through `04-continuity.png`. Confirm Anna's exact dimensions and file limits before treating them as final Marketplace assets. +The current revision 11 drafts are 900 x 820 PNG files, each below 106 KB. +Public Anna documentation reviewed on 2026-08-29 did not expose numeric listing +media limits. Use `ANNA_MEDIA_REQUIREMENTS_REQUEST.md` for the prepared support +question; do not upload or submit the drafts until those requirements are +confirmed. + ## Demonstration procedure Follow `../demo/README.md`. The expected reviewer-visible flow takes less than five minutes after dependencies are installed: From 8847853f37b9a3852bee6fef7aa30bfdc7f49d92 Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Sat, 29 Aug 2026 08:39:11 +0200 Subject: [PATCH 16/35] docs(harbour): record Anna draft revision 12 --- apps/storycore-harbour/STATUS.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 4536af82..b740e3bc 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -302,3 +302,5 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - The forced-colour fix is synchronized to Anna working draft revision 11. Its 15-file, 104,890-byte bundle is ready with content hash `c5ddb6b3a45b42cebb3ceed713f65121ba3efac9808fece05aa05ad6ce863a17`; the App still has zero immutable versions and remains unpublished. - Revision 11 demo evidence was regenerated locally in under twenty seconds: four visually inspected 900 × 820 PNGs plus a 3,288-byte contract-valid JSON export. The generated files remain ignored under `demo/output.local/revision-11/`; their sizes and one-run SHA-256 values are recorded in `demo/EVIDENCE_2026-08-28_REVISION_11.md`. The screenshot helper now resets every App scroll container before capture, fixing the measured missing-header defect on the World draft. - Anna's public Developer Hub and pinned CLI schema were rechecked on 2026-08-29. They identify the Developer Console Listing tab as the metadata/media surface but expose no numeric screenshot or Marketplace-logo limits. Both available browser sessions required a fresh owner sign-in, so no authenticated field hints were claimed. `review/ANNA_MEDIA_REQUIREMENTS_REQUEST.md` contains the exact ready-to-send question; the 900 × 820 PNGs remain drafts and nothing was uploaded or submitted. +- Concurrent owner work on 2026-08-29 made the single repair prompt schema-complete: it now enumerates every required project, bible, entity, scene, shot, and continuity field; fixes the three-scene/one-shot shape; preserves exact source input; and still discards the failed response. The changes were merged without rewriting history and pass 67/67 Node tests, strict validation, the sequential Edge generation/export smoke, forced-colour assertions, and the ETag deletion smoke. +- The schema-complete repair prompt is synchronized to Anna working draft revision 12. Its 15-file, 107,699-byte bundle is ready with content hash `ad383957f123c1a2ea6c20e6ebb499f192f9ad161af4b0a9b0cc2bdb8e353fad`; the App remains an unpublished draft with zero immutable versions. No real-model run or quota consumption was performed for this synchronization. From 5ce095eea0f0b2eaeb958ae5b2f1106e56b4e884 Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Sat, 29 Aug 2026 10:55:06 +0200 Subject: [PATCH 17/35] feat(harbour): prepare validated Anna marketplace logo --- apps/storycore-harbour/STATUS.md | 2 + apps/storycore-harbour/package.json | 2 + .../review/ANNA_MEDIA_REQUIREMENTS_REQUEST.md | 24 +++--- .../review/SUBMISSION_BRIEF.md | 5 ++ .../review/marketplace-media/README.md | 26 +++++++ .../storycore-harbour-logo-256.png | Bin 0 -> 5302 bytes .../scripts/render-marketplace-logo.mjs | 45 +++++++++++ .../scripts/validate-marketplace-logo.mjs | 70 ++++++++++++++++++ 8 files changed, 165 insertions(+), 9 deletions(-) create mode 100644 apps/storycore-harbour/review/marketplace-media/README.md create mode 100644 apps/storycore-harbour/review/marketplace-media/storycore-harbour-logo-256.png create mode 100644 apps/storycore-harbour/scripts/render-marketplace-logo.mjs create mode 100644 apps/storycore-harbour/scripts/validate-marketplace-logo.mjs diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index b740e3bc..53c00e3a 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -304,3 +304,5 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - Anna's public Developer Hub and pinned CLI schema were rechecked on 2026-08-29. They identify the Developer Console Listing tab as the metadata/media surface but expose no numeric screenshot or Marketplace-logo limits. Both available browser sessions required a fresh owner sign-in, so no authenticated field hints were claimed. `review/ANNA_MEDIA_REQUIREMENTS_REQUEST.md` contains the exact ready-to-send question; the 900 × 820 PNGs remain drafts and nothing was uploaded or submitted. - Concurrent owner work on 2026-08-29 made the single repair prompt schema-complete: it now enumerates every required project, bible, entity, scene, shot, and continuity field; fixes the three-scene/one-shot shape; preserves exact source input; and still discards the failed response. The changes were merged without rewriting history and pass 67/67 Node tests, strict validation, the sequential Edge generation/export smoke, forced-colour assertions, and the ETag deletion smoke. - The schema-complete repair prompt is synchronized to Anna working draft revision 12. Its 15-file, 107,699-byte bundle is ready with content hash `ad383957f123c1a2ea6c20e6ebb499f192f9ad161af4b0a9b0cc2bdb8e353fad`; the App remains an unpublished draft with zero immutable versions. No real-model run or quota consumption was performed for this synchronization. +- Authenticated Listing inspection on 2026-08-29 confirmed logo formats PNG/JPG/WebP/GIF, a 2MB maximum, and 256 × 256 cropping. Screenshot metadata remains one URL per line with no visible or HTML-enforced count, dimensions, aspect ratio, format, or byte limit. No field was changed and no asset was uploaded. +- A reproducible Marketplace logo candidate now renders from the committed SVG through Edge at `review/marketplace-media/storycore-harbour-logo-256.png`. It is 256 × 256, 5,302 bytes, SHA-256 `4a54e1955ac5ebe67eef8c82a260b1b1cdc351a7e87902f2bba2b15532cea7dd`, and passes PNG header, size, dimension, and representative-pixel validation. The first renderer attempt was correctly rejected after visual inspection exposed an unloaded black image; the renderer now embeds and decodes the SVG before capture. diff --git a/apps/storycore-harbour/package.json b/apps/storycore-harbour/package.json index b2f83d72..a717772a 100644 --- a/apps/storycore-harbour/package.json +++ b/apps/storycore-harbour/package.json @@ -19,6 +19,8 @@ "browser:smoke": "node scripts/browser-smoke.mjs", "browser:deletion-smoke": "node scripts/browser-deletion-smoke.mjs", "browser:check": "npm run browser:smoke && npm run browser:deletion-smoke", + "marketplace:logo": "node scripts/render-marketplace-logo.mjs", + "marketplace:logo:check": "node scripts/validate-marketplace-logo.mjs", "contract:check": "node scripts/validate-project.mjs examples/sample-project.json", "acceptance:sync": "node scripts/sync-acceptance-corpus.mjs", "acceptance:sync:check": "node scripts/check-bundled-corpus.mjs", diff --git a/apps/storycore-harbour/review/ANNA_MEDIA_REQUIREMENTS_REQUEST.md b/apps/storycore-harbour/review/ANNA_MEDIA_REQUIREMENTS_REQUEST.md index 0acd6fb5..2431f2f6 100644 --- a/apps/storycore-harbour/review/ANNA_MEDIA_REQUIREMENTS_REQUEST.md +++ b/apps/storycore-harbour/review/ANNA_MEDIA_REQUIREMENTS_REQUEST.md @@ -7,8 +7,11 @@ authorization to upload files. - Anna's public App Manifest documentation says listing metadata, logos, and screenshots are managed in the Developer Console Listing tab. -- The public Developer Hub and pinned CLI schema reviewed on 2026-08-29 do not - expose numeric screenshot or Marketplace-logo constraints. +- The authenticated Listing inspected on 2026-08-29 accepts PNG/JPG/WebP/GIF + logos up to 2MB and states that they are cropped to 256 x 256. +- Screenshots are entered as one URL per line. The Listing exposes no visible + screenshot count, dimension, aspect-ratio, format, or byte limit, and the + textarea has no corresponding HTML constraint attributes. - StoryCore Harbour currently has four deterministic fictional PNG drafts at 900 x 820. Their largest file is 105,664 bytes. - The draft is App id 214, slug `storycore-harbour`, working revision 11, with @@ -31,14 +34,17 @@ and developers? 1. required screenshot count and accepted formats; 2. exact pixel dimensions or aspect-ratio range; -3. maximum bytes per screenshot; -4. Marketplace logo/icon dimensions, format, transparency, and maximum bytes; -5. any safe-area, rounded-corner, text-overlay, localization, or dark/light +3. maximum bytes per screenshot and whether Anna fetches each URL at review or + requires a long-lived public asset URL; +4. any screenshot safe-area, rounded-corner, text-overlay, localization, or dark/light theme requirements; -6. whether screenshots from the local Anna harness are acceptable when they +5. whether screenshots from the local Anna harness are acceptable when they contain only fictional data and accurately represent the submitted bundle. -Our current drafts are four PNG files at 900 x 820, each below 106 KB. They show +The Listing already confirms that logos may be PNG/JPG/WebP/GIF up to 2MB and +are cropped to 256 x 256. Our prepared PNG logo is 256 x 256 and 5,302 bytes. + +Our current screenshot drafts are four PNG files at 900 x 820, each below 106 KB. They show Concept, World/production bible, Scenes/shots, and Continuity/export. They do not show account identifiers, hidden acceptance controls, provider metadata, or real user content. @@ -49,7 +55,7 @@ confirmed. Thank you. ## Owner action -The owner may either inspect the authenticated Developer Console Listing field -hints or send the message above through Anna's official support channel. Do not +The authenticated Listing constraints above have been inspected. The owner may +send the remaining screenshot question through Anna's official support channel. Do not upload assets, submit a review, accept terms, or make a public post without the owner's explicit approval at the time of the action. diff --git a/apps/storycore-harbour/review/SUBMISSION_BRIEF.md b/apps/storycore-harbour/review/SUBMISSION_BRIEF.md index 0a861487..e151b526 100644 --- a/apps/storycore-harbour/review/SUBMISSION_BRIEF.md +++ b/apps/storycore-harbour/review/SUBMISSION_BRIEF.md @@ -29,6 +29,11 @@ media limits. Use `ANNA_MEDIA_REQUIREMENTS_REQUEST.md` for the prepared support question; do not upload or submit the drafts until those requirements are confirmed. +The authenticated Listing subsequently confirmed PNG/JPG/WebP/GIF logos up to +2MB, cropped to 256 x 256. The validated 5,302-byte candidate is +`marketplace-media/storycore-harbour-logo-256.png`. Screenshot requirements remain the +unconfirmed part of the media gate. + ## Demonstration procedure Follow `../demo/README.md`. The expected reviewer-visible flow takes less than five minutes after dependencies are installed: diff --git a/apps/storycore-harbour/review/marketplace-media/README.md b/apps/storycore-harbour/review/marketplace-media/README.md new file mode 100644 index 00000000..6ef90b85 --- /dev/null +++ b/apps/storycore-harbour/review/marketplace-media/README.md @@ -0,0 +1,26 @@ +# StoryCore Harbour Marketplace media + +## Logo candidate + +- file: `storycore-harbour-logo-256.png`; +- source: `../../bundle/icon.svg`; +- format and dimensions: PNG, 256 x 256; +- size: 5,302 bytes, below Anna's visible 2MB maximum; +- SHA-256: `4a54e1955ac5ebe67eef8c82a260b1b1cdc351a7e87902f2bba2b15532cea7dd`. + +The authenticated Anna Listing inspected on 2026-08-29 accepts PNG, JPG, +WebP, or GIF logos up to 2MB and states that they are cropped to 256 x 256. +This asset is generated from the committed SVG without changing the product +identity. + +Reproduce and validate on Windows with Edge: + +```powershell +$env:BROWSER_EXECUTABLE = 'C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe' +npm run marketplace:logo +npm run marketplace:logo:check +``` + +The validator checks PNG signature, exact dimensions, maximum bytes, and +representative gold, white, red, and cyan pixels. Do not upload the file or +save Listing changes without explicit owner approval at action time. diff --git a/apps/storycore-harbour/review/marketplace-media/storycore-harbour-logo-256.png b/apps/storycore-harbour/review/marketplace-media/storycore-harbour-logo-256.png new file mode 100644 index 0000000000000000000000000000000000000000..3644aa04e343cd3f118c7ea5ebd22f31c4e02d13 GIT binary patch literal 5302 zcmdT|_g7O(+daV$2neAlNRQMY9Yp2QH7LD^AVmbJ(gj3CN&*q3_f9B+^eRa2AXPvC z=`D1mh8jwM5AS{diSMVg&z@)YdS+&=nYDMIw&o)$3T6rb0H{=yk&giYbO}KKIpp&5 z%r(~<0B8Ueq~eoz*o|rL2)!k5GW@pNo6))tOG*YfVZT-Il;kQ}=!i}+IZr5EaxM4I z*jJ?m1C_l`k}1C@H1iW}U;hpZ8?t2Pn^+AQ(6=98&VQ0}$K39TxWbOr)6$1Z28iG% zakW3TWVKRf$7M@5*1e^if4VhtEcZ6lc}fwsW=>C2R+iqT>cYsbTZ<4mWriV}Lg3#d zS^F|n*ZRVf`tD3SXjt3dHf|WdhWOe0=*pS(x|ng*ICYX^)3NqzyP`LV94PXo?GGiB zo`g*=jM%uWqyr64A!NLRh;(hcFjpR)vja3LV zTgw~AM0)XOrk{<)%vYTc-8wa*pEYb$bWpMU;}~An*{Pb>`E4-#aBFK-;h~i{=<1yv zXK@XpfP$rT(MYmzE5>kx)AAMw`)lw`*5HY?+gqN1sd5#8gXT!tO)V}i@krnc3ihtb z&sXcX6pG*OZ@s6O4^4k@Xsaf(G~J&qw-oh<`Do(8X||D2d6UOoS;azaGDUTckC!xs zIzvW0&09jdy7)y;;e8b0JU-IzyD@<2JM-)_fyfPrZ6`UkR7Gzwa8HmRdTr}qs%I%R z(v-;CF@ewnvV&+F4FR^9v@r)oP9gNixXRhWp_6UNQdZ<`Vfq;7xR{fNv#E!soYr6Y z&>d1mcVGH*++0w4gk;K$?Fg0ilxBYzV!laoEvSf)P};&1xydTMn_VvHFHiF4nrE7m7O&q+gBdktmND?7INZ-MZGx!F~e=covh=1t*@$)Bg z@FO3Hybh7OL%onxjL|oV9=(5zv6jcAA(-gwd6)gh3UrE~=}xbj!@YenEK{UzcuHz4 zjm7|$`7qW^KGh#REjJ2{hR3-OyC5epZI-QzQ2Tv79)N$Ftq{+Zv7a(4TI2EbVy;*y zSG#=(?P?yLbC7K2A)*ua(ll==HdW!t&J8qnnC!BLk=&NCLS-crwC~=r3r_$dSTp~% ztZ!NPB1Yhtcnulja=sl~SEfyBf;M9k;q0m3wWuf*MhoI>ovK|$BH65C>wc|%xE%cB zq~%CTYuHXW7z~VKO)I6ODV)?oj_~un>2w6W!i9IeS%8si{vsh49#uk)Fw1}JR0mu? zYvPd{oRdYYAxk=;i2$TzPz@Q!A`ciGeRyG5Z${^2 zAWP{9+qam!Aj)@%8J#&-JB)n=i&|wDaz5V6`iPJ|-^l0OIyv!rm%l6dZ0VxVP>#x* zCvPFivN&Selk;xjwqFcf}o0 z6}cj%n0?a2wpsFFL-$Z4>_*6ODa}j%E~xlV=Y>Xo7sXyr|8dHumrgloEL=(M&Q>zr zT_y9TnO?#-U+m56K9|H}GxJ%@A%h>5HjXe+>8$D-=q&+BXFy|ho<1EocrH=ytco$h z@n^00PU&!1$Ty@~0K$=DgxlKS8jHsv$6j>d*DwF$ZJVtlB#7BZ9j_Or?q+2e(gA#L zO~lU}zVr5b>oRAnk-Q|4dce5cEH8FaUTc+B=Ip8(%?)U7)n+fbO0-JM`KSHhJB{*= zvS(h>ZS6McT)j_wUcXLreLQ|68mlV;h1U*sAS7Pz`Qulf`x|x3S(+|#w`VrB?PJyE zMm7Aa)@k?r!-Ep6QLh$l@Y12sW*0@Z^t|h3pW^rVrC*^Ahjn4lW?SaL zHcFD?7LP+InI}F3u&)Q&HZB~pI z!cq8*rZefr^FC+ajZOyiQnp4)5XxiY^LIbfF1K#C9=GV}1VFIT>|CbsqWeKLp6C{N z+e6dC$%D#Lgcnc~l3Lh@1M%1$o-azNo;XP?bs0T9+FzJFtPy52zbgHU!sFgM4NDGQ z;D_>sr+3H6?5@!WpA5C)fEh_?7l(Z!lKB3)T53}=vP2v0Q^M7kPFz!IupA($WciZJW8}w9* zFrX7A2BKNILI3{(NCubeg z!}>xIAs)lTHm(D{?zp^bpkQPViITvQW44*lrU_vy;IrMI6j| zIX-jYx9-H?d+%Jq#IRjzhV5NG$#UoJ zin>iBIL55ne`H)#JWL>})GNe-h1Zk{B=Xpv;6Zz}IJ09^Q>cjZBt-SH)q)jEN`Br>JHe%0Uf zMw1&z?9`gim1iD-eED=arCbiwrDK{+7^EA4XqVkv;h?goR~TE=TF8~33Xf0m@6YDd z7Qdv~1ad$;t2{?TgG1v?4rEnMEhX&U+($E;64vuAx{SW_ol+O82Jygr(qviy*lUII z=K`*>h!%)_N*P$r{(z1YSzKsqRJ)y zv~j^+Z4K@{XnM6B)jW4g<3U_9rf8%Ywv$9MplaXWG~#44l{SsA^kIPa3o@^uLwj{i zWxTCLMU{uu?EB?|#P})!PVK%PS$d|4sc^~?ewxtR%f#}>W^o^;grISYxBJTZ`wd~H z6Ed1F?%v85ev*`N_52?7bDbYvl<@r4Ap8TnAy!ABMMCVXp3y%pWXl5*Vtq0-Me_)u zs?Uhr;>NsVYRiOrvB&Oul!;L;OXPZa=UYx27smxHjzy@>o!@sQNl)X~Z@q468p>~~ z0H2j{$g&>O8q=YPo8^L+>#}j?TQ+f*%;(WKPmw>8+g0~7RZURBswgOPMsULy8=_bG z#ceCTohixKL^mF!H1!a-(~iM3=OBSITo0}C48Xtk859Lx+#aYmx1z~)i6RJir3&); z;XjCbgt|oN=TN0J^zs2WInuNJgL|AZ{Ie1~9Co$1H|V${!L3e;BXo-Ieuu9U;1Qem`lVybD&=Ui9w~3xE(q{&b-xEOj4@?hfrX5~I>CkE0UZf#B09eKVzb%g%$=Ix~hVv`hV; zXZpkP=9XHdZ0^U1DE7j*fucK@fL#mGWehmIp2NHj0Kleyvw*oKYR;a}zqIx!`l%wa zhPJ~i0+5?MnBiNtmJUF`Dq$Tm^_jDSYdkcOryswcdBk`DY`6)@PII>@!T}3a9G`{)W6T2yvu^3BXFqbUZ4AJVR9aSUN3Z0-o); zINNk~KWLhxLVb9=CPowK_Aq#p7OEg{h6w1A%4|Oj0RO71%WRWzl?~`( zw6L>-|1&RpQD)DC61td@dvUX*nP<%`>!_Dm>;SEybG-pOAtT*^l*Z7xH?s*ZDtzHY z6WQJoKIcNO;Jgw>g{6g;#e@*mu7+FqF`xxm*HDZ|%M@4hDyP;I)~$(2Q7e5ADnGFq!3=<;39f28}17cZXtBE6ygc#S2(syz^) zwr}R3|79Nht19O#UUlIijgGalx~fCQeXDTL)nQb%y_&b~o~0YXi$-T+Yjb+i1(vU^ zM?#aeRm{kel*E`^7p#cP6Foc6>5ZA?$W*-!BcaxPil{s%GvG$XK%@p%1ePm5+|rYQ zh^qhf+06BYH*^LsPxbk5i-?^g2uxAV=tJx7{xiA8R|%f+j(|Q#Mkr}JY@#Yfe9cq{IuPG{0EvT?A#T)G{ zdC`n7SV&Y867)|7W~SNLx)ApHdzM&*wz|P9!lTWB@SYp=>S-rvrm@4c{`(h=tom^) z)Ng3@6NOuqaCx0E#hclI7g4tJ&b{XJD9(}56|JPV6DnD9g`z`&D+wP;d%f)Q#q2(l=sJ=~T{kd(vm`^XhM-O>y~inx0vxY1JcdVIKw}GXPv%JXf|gzf2z? cf3KP=fYLGw7Cy^3dC34ON}9;x`(}Rs2jx8@7XSbN literal 0 HcmV?d00001 diff --git a/apps/storycore-harbour/scripts/render-marketplace-logo.mjs b/apps/storycore-harbour/scripts/render-marketplace-logo.mjs new file mode 100644 index 00000000..ea50ccf8 --- /dev/null +++ b/apps/storycore-harbour/scripts/render-marketplace-logo.mjs @@ -0,0 +1,45 @@ +#!/usr/bin/env node +import { mkdir, readFile } from "node:fs/promises"; +import { dirname, resolve } from "node:path"; +import { chromium } from "playwright-core"; + +const executablePath = process.env.BROWSER_EXECUTABLE; +const inputPath = resolve(process.argv[2] || "bundle/icon.svg"); +const outputPath = resolve(process.argv[3] || "review/marketplace-media/storycore-harbour-logo-256.png"); + +if (!executablePath) { + console.error("BROWSER_EXECUTABLE is required to render the Marketplace logo."); + process.exit(2); +} + +await mkdir(dirname(outputPath), { recursive: true }); +const browser = await chromium.launch({ + executablePath, + headless: true, + args: ["--no-sandbox", "--disable-dev-shm-usage"], +}); + +try { + const page = await browser.newPage({ viewport: { width: 256, height: 256 } }); + const source = await readFile(inputPath); + const sourceUrl = `data:image/svg+xml;base64,${source.toString("base64")}`; + await page.setContent(` + + + `); + const logo = page.locator("img"); + await logo.waitFor({ state: "visible" }); + await logo.evaluate(async (image) => { + await image.decode(); + if (!image.complete || image.naturalWidth <= 0 || image.naturalHeight <= 0) { + throw new Error("The source logo did not decode before capture."); + } + }); + await logo.screenshot({ path: outputPath, omitBackground: true }); + console.log(JSON.stringify({ result: "pass", inputPath, outputPath, width: 256, height: 256 })); +} finally { + await browser.close(); +} diff --git a/apps/storycore-harbour/scripts/validate-marketplace-logo.mjs b/apps/storycore-harbour/scripts/validate-marketplace-logo.mjs new file mode 100644 index 00000000..ebae6a00 --- /dev/null +++ b/apps/storycore-harbour/scripts/validate-marketplace-logo.mjs @@ -0,0 +1,70 @@ +#!/usr/bin/env node +import assert from "node:assert/strict"; +import { readFile } from "node:fs/promises"; +import { resolve } from "node:path"; +import { pathToFileURL } from "node:url"; +import { chromium } from "playwright-core"; + +const logoPath = resolve(process.argv[2] || "review/marketplace-media/storycore-harbour-logo-256.png"); +const executablePath = process.env.BROWSER_EXECUTABLE; +const bytes = await readFile(logoPath); +const pngSignature = Buffer.from([137, 80, 78, 71, 13, 10, 26, 10]); + +if (!executablePath) { + console.error("BROWSER_EXECUTABLE is required to inspect the rendered Marketplace logo."); + process.exit(2); +} + +assert.ok(bytes.subarray(0, 8).equals(pngSignature), "Marketplace logo must be a PNG file."); +assert.equal(bytes.subarray(12, 16).toString("ascii"), "IHDR", "PNG must start with an IHDR chunk."); +assert.equal(bytes.readUInt32BE(16), 256, "Marketplace logo width must be 256 pixels."); +assert.equal(bytes.readUInt32BE(20), 256, "Marketplace logo height must be 256 pixels."); +assert.ok(bytes.length <= 2 * 1024 * 1024, "Marketplace logo must not exceed Anna's 2MB limit."); + +const browser = await chromium.launch({ + executablePath, + headless: true, + args: ["--no-sandbox", "--disable-dev-shm-usage"], +}); +let samples; +try { + const page = await browser.newPage({ viewport: { width: 256, height: 256 } }); + await page.goto(pathToFileURL(logoPath).href); + samples = await page.locator("img").evaluate((image) => { + const canvas = document.createElement("canvas"); + canvas.width = image.naturalWidth; + canvas.height = image.naturalHeight; + const context = canvas.getContext("2d", { willReadFrequently: true }); + context.drawImage(image, 0, 0); + const pixel = (x, y) => [...context.getImageData(x, y, 1, 1).data]; + return { + naturalWidth: image.naturalWidth, + naturalHeight: image.naturalHeight, + goldBeacon: pixel(128, 56), + whiteMast: pixel(128, 128), + redHull: pixel(128, 152), + cyanWave: pixel(48, 172), + }; + }); +} finally { + await browser.close(); +} + +const near = (actual, expected, tolerance = 12) => + expected.every((channel, index) => Math.abs(actual[index] - channel) <= tolerance); +assert.deepEqual([samples.naturalWidth, samples.naturalHeight], [256, 256]); +assert.ok(near(samples.goldBeacon, [247, 198, 90, 255]), "Logo beacon must render gold."); +assert.ok(near(samples.whiteMast, [244, 247, 251, 255]), "Logo mast must render white."); +assert.ok(near(samples.redHull, [239, 75, 95, 255]), "Logo hull must render red."); +assert.ok(near(samples.cyanWave, [71, 215, 232, 255]), "Logo wave must render cyan."); + +console.log(JSON.stringify({ + result: "pass", + logoPath, + format: "PNG", + width: 256, + height: 256, + bytes: bytes.length, + maximumBytes: 2 * 1024 * 1024, + pixelSamples: "pass", +})); From 104a149fd2b2e58af8957d6ea85bccaf2fc0f5e4 Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Sat, 29 Aug 2026 11:12:42 +0200 Subject: [PATCH 18/35] docs(harbour): record working-draft install path --- apps/storycore-harbour/STATUS.md | 1 + .../review/FINAL_HANDOFF_2026-08-24.md | 8 ++++++++ .../review/LAUNCH_CHECKLIST.md | 2 ++ .../OWNER_ACTIVATION_AND_FIRST_REVIEW.md | 20 +++++++++++++++++++ 4 files changed, 31 insertions(+) diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 53c00e3a..821fa672 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -306,3 +306,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - The schema-complete repair prompt is synchronized to Anna working draft revision 12. Its 15-file, 107,699-byte bundle is ready with content hash `ad383957f123c1a2ea6c20e6ebb499f192f9ad161af4b0a9b0cc2bdb8e353fad`; the App remains an unpublished draft with zero immutable versions. No real-model run or quota consumption was performed for this synchronization. - Authenticated Listing inspection on 2026-08-29 confirmed logo formats PNG/JPG/WebP/GIF, a 2MB maximum, and 256 × 256 cropping. Screenshot metadata remains one URL per line with no visible or HTML-enforced count, dimensions, aspect ratio, format, or byte limit. No field was changed and no asset was uploaded. - A reproducible Marketplace logo candidate now renders from the committed SVG through Edge at `review/marketplace-media/storycore-harbour-logo-256.png`. It is 256 × 256, 5,302 bytes, SHA-256 `4a54e1955ac5ebe67eef8c82a260b1b1cdc351a7e87902f2bba2b15532cea7dd`, and passes PNG header, size, dimension, and representative-pixel validation. The first renderer attempt was correctly rejected after visual inspection exposed an unloaded black image; the renderer now embeds and decodes the SVG before capture. +- Authenticated Console inspection on 2026-08-29 confirmed working draft r12, bundle `ready`, content hash prefix `ad383957f123…`, and no version history. CLI status independently confirms `draft`, unpublished, and zero versions. The current Versions tab now exposes a distinct **Install & test** working-draft action, so an immutable cut is no longer assumed to be the only test path. It was not clicked. **View manifest** returned `Could not validate credentials`; this is recorded as a web-session/platform blocker rather than a bundle failure. diff --git a/apps/storycore-harbour/review/FINAL_HANDOFF_2026-08-24.md b/apps/storycore-harbour/review/FINAL_HANDOFF_2026-08-24.md index ed197550..68ccf540 100644 --- a/apps/storycore-harbour/review/FINAL_HANDOFF_2026-08-24.md +++ b/apps/storycore-harbour/review/FINAL_HANDOFF_2026-08-24.md @@ -111,6 +111,14 @@ Do not cut `0.1.0`, submit for review, mark PR #37 ready, merge, or release whil - cutting `0.1.0` would create that immutable version but must not be used as a workaround while the 18/20 reliability gate still fails; - the Console web session also expired on reload and redirected to login, which is a separate authentication condition rather than the original installation cause. +Update from 2026-08-29: the current Console now exposes a separate **Install & +test** button inside the working-draft Versions tab at revision 12, while CLI +status still reports zero immutable versions. This may provide a draft-testing +path without cutting `0.1.0`, but it was not clicked because installation and +permission prompts require explicit owner approval. **View manifest** returned +`Could not validate credentials`; therefore the web-session credential path +must be healthy before any installation result can be claimed. + ## AIMesher Anna App ### Local candidate diff --git a/apps/storycore-harbour/review/LAUNCH_CHECKLIST.md b/apps/storycore-harbour/review/LAUNCH_CHECKLIST.md index 5ffd0577..3df1d295 100644 --- a/apps/storycore-harbour/review/LAUNCH_CHECKLIST.md +++ b/apps/storycore-harbour/review/LAUNCH_CHECKLIST.md @@ -37,6 +37,8 @@ This checklist is a release gate. A checked implementation item does not overrid - [ ] Production ETag conflict induced and safely rejected. - [ ] Qualified App MAU definition and dashboard visibility confirmed. - [ ] Host-API-only completion confirmed as eligible without local runtime installation. +- [ ] Owner-approved working-draft **Install & test** completes from revision 12 without cutting a version. +- [ ] Installed Apps exposes only the expected LLM, App storage, and window capabilities with no Executa. ## Reliability and CI diff --git a/apps/storycore-harbour/review/OWNER_ACTIVATION_AND_FIRST_REVIEW.md b/apps/storycore-harbour/review/OWNER_ACTIVATION_AND_FIRST_REVIEW.md index 80d1de1c..d2c47d34 100644 --- a/apps/storycore-harbour/review/OWNER_ACTIVATION_AND_FIRST_REVIEW.md +++ b/apps/storycore-harbour/review/OWNER_ACTIVATION_AND_FIRST_REVIEW.md @@ -192,6 +192,26 @@ After the first successful push: - open the Developer Console and confirm the App is shown as a working/draft App; - confirm the locked slug is exactly `storycore-harbour`. +### Working-draft installation path + +The authenticated Developer Console inspected on 2026-08-29 exposes an +**Install & test** action inside the **Versions** tab for the mutable working +draft, even while the App has zero immutable versions. This is distinct from +the App-list **Install** action that previously failed with “no available +published version”. Do not cut `0.1.0` merely to discover whether the current +working-draft installation path is usable. + +Installing changes the owner's Installed Apps state and may open Host API +permission controls. Use **Install & test** only after explicit owner approval +at action time, then verify the exact App id, working revision, requested +capabilities, and absence of unexpected Executas before confirming anything. + +During the same inspection, **View manifest** returned `Could not validate +credentials` although the Console displayed working revision 12 and the CLI +independently confirmed the draft. Treat that as a web-session/platform +credential condition, not as evidence that the uploaded manifest or bundle is +invalid. Reauthenticate or ask Anna support rather than recreating the App. + If the CLI or Console creates an unexpected second App, stop before cutting a version. Preserve the outputs needed for diagnosis, but redact tokens. ## 6. Run StoryCore Harbour against real Anna services From 8cc3e8755e498599fd5f22bae52ef9cf11445afc Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Sat, 29 Aug 2026 13:48:24 +0200 Subject: [PATCH 19/35] docs(harbour): capture Anna manifest credential blocker --- apps/storycore-harbour/STATUS.md | 1 + .../ANNA_VIEW_MANIFEST_CREDENTIAL_REPORT.md | 75 +++++++++++++++++++ 2 files changed, 76 insertions(+) create mode 100644 apps/storycore-harbour/review/ANNA_VIEW_MANIFEST_CREDENTIAL_REPORT.md diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 821fa672..3f310752 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -307,3 +307,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - Authenticated Listing inspection on 2026-08-29 confirmed logo formats PNG/JPG/WebP/GIF, a 2MB maximum, and 256 × 256 cropping. Screenshot metadata remains one URL per line with no visible or HTML-enforced count, dimensions, aspect ratio, format, or byte limit. No field was changed and no asset was uploaded. - A reproducible Marketplace logo candidate now renders from the committed SVG through Edge at `review/marketplace-media/storycore-harbour-logo-256.png`. It is 256 × 256, 5,302 bytes, SHA-256 `4a54e1955ac5ebe67eef8c82a260b1b1cdc351a7e87902f2bba2b15532cea7dd`, and passes PNG header, size, dimension, and representative-pixel validation. The first renderer attempt was correctly rejected after visual inspection exposed an unloaded black image; the renderer now embeds and decodes the SVG before capture. - Authenticated Console inspection on 2026-08-29 confirmed working draft r12, bundle `ready`, content hash prefix `ad383957f123…`, and no version history. CLI status independently confirms `draft`, unpublished, and zero versions. The current Versions tab now exposes a distinct **Install & test** working-draft action, so an immutable cut is no longer assumed to be the only test path. It was not clicked. **View manifest** returned `Could not validate credentials`; this is recorded as a web-session/platform blocker rather than a bundle failure. +- A single instrumented **View manifest** reproduction produced the same credential message but no observable network event, HTTP status, or console error through the available browser diagnostics. Root cause remains unproven. `review/ANNA_VIEW_MANIFEST_CREDENTIAL_REPORT.md` contains privacy-safe steps, independent CLI evidence, the exact uncertainty boundary, and a ready-to-send support question; nothing was posted. diff --git a/apps/storycore-harbour/review/ANNA_VIEW_MANIFEST_CREDENTIAL_REPORT.md b/apps/storycore-harbour/review/ANNA_VIEW_MANIFEST_CREDENTIAL_REPORT.md new file mode 100644 index 00000000..2aaea10b --- /dev/null +++ b/apps/storycore-harbour/review/ANNA_VIEW_MANIFEST_CREDENTIAL_REPORT.md @@ -0,0 +1,75 @@ +# Anna Developer Console credential-report draft + +Prepared on 2026-08-29. This is a private support-report draft; it has not been +sent or posted. + +## Summary + +The authenticated Anna Developer Console can list StoryCore Harbour and show +its working draft, but the read-only **View manifest** action reports: + +```text +Could not validate credentials +``` + +## Reproduction + +1. Sign in to Anna and complete workspace onboarding. +2. Open Developer Console. +3. Open StoryCore Harbour, App id 214. +4. Open **Versions**. +5. Confirm the working draft shows revision r12, bundle `ready`, and content + hash prefix `ad383957f123…`. +6. Click **View manifest**. +7. Observe `Could not validate credentials`; no manifest modal/content appears. + +## Independent evidence + +- `anna-app apps status storycore-harbour --json` succeeds with the same owner + account and reports `draft`, unpublished, zero versions. +- `anna-app apps versions storycore-harbour --json` succeeds and returns an + empty immutable-version list. +- Working draft revision 12 was uploaded with the pinned Node 22-compatible + CLI flow and bundle status `ready`. +- Local strict validation, canonical contract, mock fixture, fixed corpus, + browser flow, and deletion flow pass. +- The Console can read the App list, Listing, working revision, bundle status, + Settings, and version history in the same browser session. + +## Instrumentation result + +One instrumented reproduction was performed after enabling browser network +observation. The UI reproduced the same message, but the available event buffer +and console logs exposed no request URL or HTTP status. Do not claim whether +the failure occurs before the request, in an unobserved request, or in response +handling without server/frontend evidence. + +## Expected behavior + +**View manifest** should display the immutable snapshot of the current working +manifest, or return an actionable authentication/authorization error that +identifies which owner/developer credential must be refreshed. + +## Safety and impact + +- No manifest, Listing field, App permission, installation, or version was + changed during reproduction. +- **Install & test**, **Cut version**, **Submit now**, **Discard**, and deletion + actions were not used. +- This blocks a web-console manifest comparison and reduces confidence in the + new working-draft install path. It does not prove that the uploaded manifest + or bundle is invalid. + +## Ready-to-send question + +```text +Hi Anna team — the authenticated Developer Console lists StoryCore Harbour +(App id 214) and shows working draft r12 with bundle ready, but Versions > View +manifest returns “Could not validate credentials”. The pinned CLI can read the +same App status and versions successfully, and strict local validation passes. + +Could you confirm which web credential or endpoint View manifest requires, and +whether refreshing that credential is also required before using the new +working-draft “Install & test” action? We have not clicked Install & test, cut a +version, submitted review, or changed permissions. +``` From 67944e4b9e5b0d12d98401660568dfa6c51c9aaa Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Sat, 29 Aug 2026 15:01:09 +0200 Subject: [PATCH 20/35] docs(harbour): close Anna manifest read blocker --- apps/storycore-harbour/STATUS.md | 1 + .../ANNA_VIEW_MANIFEST_CREDENTIAL_REPORT.md | 30 +++++++++++++++++++ .../review/LAUNCH_CHECKLIST.md | 1 + 3 files changed, 32 insertions(+) diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 3f310752..1123efdb 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -308,3 +308,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - A reproducible Marketplace logo candidate now renders from the committed SVG through Edge at `review/marketplace-media/storycore-harbour-logo-256.png`. It is 256 × 256, 5,302 bytes, SHA-256 `4a54e1955ac5ebe67eef8c82a260b1b1cdc351a7e87902f2bba2b15532cea7dd`, and passes PNG header, size, dimension, and representative-pixel validation. The first renderer attempt was correctly rejected after visual inspection exposed an unloaded black image; the renderer now embeds and decodes the SVG before capture. - Authenticated Console inspection on 2026-08-29 confirmed working draft r12, bundle `ready`, content hash prefix `ad383957f123…`, and no version history. CLI status independently confirms `draft`, unpublished, and zero versions. The current Versions tab now exposes a distinct **Install & test** working-draft action, so an immutable cut is no longer assumed to be the only test path. It was not clicked. **View manifest** returned `Could not validate credentials`; this is recorded as a web-session/platform blocker rather than a bundle failure. - A single instrumented **View manifest** reproduction produced the same credential message but no observable network event, HTTP status, or console error through the available browser diagnostics. Root cause remains unproven. `review/ANNA_VIEW_MANIFEST_CREDENTIAL_REPORT.md` contains privacy-safe steps, independent CLI evidence, the exact uncertainty boundary, and a ready-to-send support question; nothing was posted. +- After a fresh owner sign-in, **View manifest** succeeded and displayed the normalized working r12 manifest. It matches the committed Schema 2 Host-API-only boundary: no Executas, no top-level permissions, no external origins, one desktop view, `llm.complete`, App storage get/set/list/delete, `window.set_title`, self-only script CSP, and `last_writer_wins`. The credential incident is operationally resolved by reauthentication, while the exact token/frontend root cause remains unproven. No support message was sent. diff --git a/apps/storycore-harbour/review/ANNA_VIEW_MANIFEST_CREDENTIAL_REPORT.md b/apps/storycore-harbour/review/ANNA_VIEW_MANIFEST_CREDENTIAL_REPORT.md index 2aaea10b..2d74cefe 100644 --- a/apps/storycore-harbour/review/ANNA_VIEW_MANIFEST_CREDENTIAL_REPORT.md +++ b/apps/storycore-harbour/review/ANNA_VIEW_MANIFEST_CREDENTIAL_REPORT.md @@ -3,6 +3,30 @@ Prepared on 2026-08-29. This is a private support-report draft; it has not been sent or posted. +## Resolution update + +After the owner completed a fresh Anna sign-in and returned through the +Dashboard, **View manifest** succeeded in the same in-app browser. It displayed +working draft r12 and the normalized remote manifest. The earlier failure is +therefore resolved operationally by reauthentication, although the exact token +or frontend validation mechanism remains unproven. + +The remote manifest confirms: + +- schema 2; +- no required or optional Executas; +- no top-level permissions; +- no external bundle origins; +- one desktop view with minimum 520 x 680 and default 900 x 820; +- `llm.complete` only in the LLM namespace; +- App storage `get`, `set`, `list`, and `delete`; +- `window.set_title`; +- CSP `script-src 'self'` and `last_writer_wins` state merge. + +These boundaries match the committed Host-API-only adapter. The support message +below should now be sent only if the credential error recurs after a fresh +login; it is retained as a reproducible diagnostic template. + ## Summary The authenticated Anna Developer Console can list StoryCore Harbour and show @@ -73,3 +97,9 @@ whether refreshing that credential is also required before using the new working-draft “Install & test” action? We have not clicked Install & test, cut a version, submitted review, or changed permissions. ``` + +## Closure boundary + +This resolution does not authorize **Install & test**, enable Host API grants, +cut a version, spend model quota, submit review, merge, or publish. It only +closes the read-only remote-manifest comparison gate. diff --git a/apps/storycore-harbour/review/LAUNCH_CHECKLIST.md b/apps/storycore-harbour/review/LAUNCH_CHECKLIST.md index 3df1d295..28502691 100644 --- a/apps/storycore-harbour/review/LAUNCH_CHECKLIST.md +++ b/apps/storycore-harbour/review/LAUNCH_CHECKLIST.md @@ -31,6 +31,7 @@ This checklist is a release gate. A checked implementation item does not overrid - [x] Manifest declares only LLM, App storage, and window-title Host APIs. - [x] Undeclared tool invocation is denied in the official test harness. - [x] Mock Anna harness starts in CI. +- [x] Authenticated Console View manifest matches the committed Schema 2 Host-API-only boundaries at r12. - [x] Browser flow runs inside the Anna harness at 520 × 680. - [ ] Production Host API handshake verified in the target Anna account. - [ ] Production App storage write/read/reload verified. From fa7984c1c75eb9cdd349adcd83a6885b87b3ea20 Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Sat, 29 Aug 2026 15:02:39 +0200 Subject: [PATCH 21/35] docs(harbour): update manifest reauthentication runbook --- .../review/OWNER_ACTIVATION_AND_FIRST_REVIEW.md | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/apps/storycore-harbour/review/OWNER_ACTIVATION_AND_FIRST_REVIEW.md b/apps/storycore-harbour/review/OWNER_ACTIVATION_AND_FIRST_REVIEW.md index d2c47d34..2bccc82e 100644 --- a/apps/storycore-harbour/review/OWNER_ACTIVATION_AND_FIRST_REVIEW.md +++ b/apps/storycore-harbour/review/OWNER_ACTIVATION_AND_FIRST_REVIEW.md @@ -212,6 +212,11 @@ independently confirmed the draft. Treat that as a web-session/platform credential condition, not as evidence that the uploaded manifest or bundle is invalid. Reauthenticate or ask Anna support rather than recreating the App. +A fresh owner sign-in subsequently restored **View manifest**. The normalized +remote r12 manifest matched the committed Schema 2 Host-API-only boundaries. +Keep `review/ANNA_VIEW_MANIFEST_CREDENTIAL_REPORT.md` as the recurrence report; +do not send it while the read path remains healthy. + If the CLI or Console creates an unexpected second App, stop before cutting a version. Preserve the outputs needed for diagnosis, but redact tokens. ## 6. Run StoryCore Harbour against real Anna services From 3800320777e08fa99b8b8f34b37514731136ccf9 Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Sat, 29 Aug 2026 16:02:01 +0200 Subject: [PATCH 22/35] docs(harbour): diagnose dev-install permission mismatch --- apps/storycore-harbour/STATUS.md | 1 + .../ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md | 63 +++++++++++++++++++ .../review/FINAL_HANDOFF_2026-08-24.md | 8 +++ .../review/LAUNCH_CHECKLIST.md | 2 + .../OWNER_ACTIVATION_AND_FIRST_REVIEW.md | 7 +++ 5 files changed, 81 insertions(+) create mode 100644 apps/storycore-harbour/review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 1123efdb..787e1f2f 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -309,3 +309,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - Authenticated Console inspection on 2026-08-29 confirmed working draft r12, bundle `ready`, content hash prefix `ad383957f123…`, and no version history. CLI status independently confirms `draft`, unpublished, and zero versions. The current Versions tab now exposes a distinct **Install & test** working-draft action, so an immutable cut is no longer assumed to be the only test path. It was not clicked. **View manifest** returned `Could not validate credentials`; this is recorded as a web-session/platform blocker rather than a bundle failure. - A single instrumented **View manifest** reproduction produced the same credential message but no observable network event, HTTP status, or console error through the available browser diagnostics. Root cause remains unproven. `review/ANNA_VIEW_MANIFEST_CREDENTIAL_REPORT.md` contains privacy-safe steps, independent CLI evidence, the exact uncertainty boundary, and a ready-to-send support question; nothing was posted. - After a fresh owner sign-in, **View manifest** succeeded and displayed the normalized working r12 manifest. It matches the committed Schema 2 Host-API-only boundary: no Executas, no top-level permissions, no external origins, one desktop view, `llm.complete`, App storage get/set/list/delete, `window.set_title`, self-only script CSP, and `last_writer_wins`. The credential incident is operationally resolved by reauthentication, while the exact token/frontend root cause remains unproven. No support message was sent. +- Installed Apps already contains StoryCore Harbour as `v0.0.0-dev`, so **Install & test** was not clicked again. Its read-only Permissions panel returns `Failed to load permissions: App version not found`. CLI status simultaneously confirms draft r12 has zero immutable versions and the grants endpoint exposes no data. The facts identify a dev-install/version-resolution blocker for permission management; they do not prove whether refresh, immutable cut, or server repair is the correct fix. `review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md` contains the bounded support question, and nothing was sent or changed. diff --git a/apps/storycore-harbour/review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md b/apps/storycore-harbour/review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md new file mode 100644 index 00000000..6621965a --- /dev/null +++ b/apps/storycore-harbour/review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md @@ -0,0 +1,63 @@ +# Anna working-draft installation permissions report + +Prepared on 2026-08-29. This report is local and has not been sent. + +## Observed state + +- Developer Console: StoryCore Harbour working draft r12, bundle `ready`, no + immutable version history. +- Installed Apps: StoryCore Harbour is already present as `v0.0.0-dev`. +- Installed Apps > StoryCore Harbour > Permissions reports: + +```text +Failed to load permissions: App version not found +``` + +- CLI status independently reports App id 214, `draft`, unpublished, + `latest_version: null`, and `version_count: 0`. +- CLI versions independently returns an empty list. +- CLI grants returns `grants: null`, which in the pinned CLI means the grants + endpoint supplied no data; it does not independently prove grant or denial. + +## Interpretation boundary + +The verified facts show that a development installation record exists while +the permission-management surface cannot resolve an App version. This explains +why StoryCore appears installed but its expected LLM/storage grants cannot yet +be inspected through Installed Apps. + +It is reasonable to suspect a platform working-draft/version-resolution gap, +but the evidence does not prove whether the fix is to refresh **Install & +test**, create an immutable version, or repair the existing dev-install record +server-side. Do not cut `0.1.0`, reinstall, uninstall, or change permissions as +a diagnostic shortcut. + +## Safety boundary + +- **Install & test** was not clicked again because StoryCore is already listed. +- The permission dialog was read but no control was changed or saved. +- No version was cut, no review was submitted, no App was removed, and no model + or storage quota was consumed. + +## Ready-to-send support question + +```text +Hi Anna team — StoryCore Harbour (App id 214) has a ready working draft at r12 +and is already listed in Installed Apps as v0.0.0-dev. However, opening its +Permissions panel returns “Failed to load permissions: App version not found”. + +The Developer Console and pinned CLI both confirm that the App is a draft with +zero immutable versions. Could you confirm the intended permissions path for a +working-draft Install & test record? + +1. Should a v0.0.0-dev installation resolve permissions directly from the + current working draft? +2. Is Install & test expected to refresh an existing dev-install record? +3. Is an immutable cut required for permission management, despite the + working-draft Install & test action? +4. If this is a stale dev-install record, can it be repaired server-side + without recreating the App or losing the reserved slug? + +We have not reinstalled, uninstalled, changed grants, cut a version, submitted +review, or published anything. +``` diff --git a/apps/storycore-harbour/review/FINAL_HANDOFF_2026-08-24.md b/apps/storycore-harbour/review/FINAL_HANDOFF_2026-08-24.md index 68ccf540..5b37a94e 100644 --- a/apps/storycore-harbour/review/FINAL_HANDOFF_2026-08-24.md +++ b/apps/storycore-harbour/review/FINAL_HANDOFF_2026-08-24.md @@ -119,6 +119,14 @@ permission prompts require explicit owner approval. **View manifest** returned `Could not validate credentials`; therefore the web-session credential path must be healthy before any installation result can be claimed. +Second update from 2026-08-29: after reauthentication, **View manifest** works +and matches the committed Host-API-only boundaries. Installed Apps already +contains StoryCore Harbour as `v0.0.0-dev`, so another installation was not +attempted. Its Permissions panel fails with `App version not found`, while CLI +status still confirms zero immutable versions. The current blocker is therefore +permission resolution for the existing development installation, not absence +of an Installed Apps record. See `ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md`. + ## AIMesher Anna App ### Local candidate diff --git a/apps/storycore-harbour/review/LAUNCH_CHECKLIST.md b/apps/storycore-harbour/review/LAUNCH_CHECKLIST.md index 28502691..e2a97625 100644 --- a/apps/storycore-harbour/review/LAUNCH_CHECKLIST.md +++ b/apps/storycore-harbour/review/LAUNCH_CHECKLIST.md @@ -40,6 +40,8 @@ This checklist is a release gate. A checked implementation item does not overrid - [ ] Host-API-only completion confirmed as eligible without local runtime installation. - [ ] Owner-approved working-draft **Install & test** completes from revision 12 without cutting a version. - [ ] Installed Apps exposes only the expected LLM, App storage, and window capabilities with no Executa. +- [x] Existing Installed Apps record identified as StoryCore Harbour `v0.0.0-dev`. +- [ ] Resolve `App version not found` when opening permissions for the existing dev installation. ## Reliability and CI diff --git a/apps/storycore-harbour/review/OWNER_ACTIVATION_AND_FIRST_REVIEW.md b/apps/storycore-harbour/review/OWNER_ACTIVATION_AND_FIRST_REVIEW.md index 2bccc82e..c51c890c 100644 --- a/apps/storycore-harbour/review/OWNER_ACTIVATION_AND_FIRST_REVIEW.md +++ b/apps/storycore-harbour/review/OWNER_ACTIVATION_AND_FIRST_REVIEW.md @@ -217,6 +217,13 @@ remote r12 manifest matched the committed Schema 2 Host-API-only boundaries. Keep `review/ANNA_VIEW_MANIFEST_CREDENTIAL_REPORT.md` as the recurrence report; do not send it while the read path remains healthy. +Installed Apps inspection then showed StoryCore Harbour already present as +`v0.0.0-dev`. Do not click **Install & test** again merely because the +Developer card remains at `v0.0.0`. The existing installation's Permissions +panel currently returns `App version not found`; stop there and use +`review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md` rather than reinstalling, +uninstalling, cutting a version, or changing grants speculatively. + If the CLI or Console creates an unexpected second App, stop before cutting a version. Preserve the outputs needed for diagnosis, but redact tokens. ## 6. Run StoryCore Harbour against real Anna services From 0b76c86a252a92662c689cb074d89053965db8b8 Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Sun, 30 Aug 2026 15:43:59 +0200 Subject: [PATCH 23/35] docs(harbour): reconcile Anna draft-install guidance --- apps/storycore-harbour/STATUS.md | 1 + .../ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md | 22 +++++++++++++++++++ 2 files changed, 23 insertions(+) diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 787e1f2f..feb790ae 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -310,3 +310,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - A single instrumented **View manifest** reproduction produced the same credential message but no observable network event, HTTP status, or console error through the available browser diagnostics. Root cause remains unproven. `review/ANNA_VIEW_MANIFEST_CREDENTIAL_REPORT.md` contains privacy-safe steps, independent CLI evidence, the exact uncertainty boundary, and a ready-to-send support question; nothing was posted. - After a fresh owner sign-in, **View manifest** succeeded and displayed the normalized working r12 manifest. It matches the committed Schema 2 Host-API-only boundary: no Executas, no top-level permissions, no external origins, one desktop view, `llm.complete`, App storage get/set/list/delete, `window.set_title`, self-only script CSP, and `last_writer_wins`. The credential incident is operationally resolved by reauthentication, while the exact token/frontend root cause remains unproven. No support message was sent. - Installed Apps already contains StoryCore Harbour as `v0.0.0-dev`, so **Install & test** was not clicked again. Its read-only Permissions panel returns `Failed to load permissions: App version not found`. CLI status simultaneously confirms draft r12 has zero immutable versions and the grants endpoint exposes no data. The facts identify a dev-install/version-resolution blocker for permission management; they do not prove whether refresh, immutable cut, or server repair is the correct fix. `review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md` contains the bounded support question, and nothing was sent or changed. +- Public Anna guidance rechecked on 2026-08-30 is internally ambiguous for this exact boundary: one guide moves installation/permissions after an immutable cut, another team response directs working-draft installation, and beta.126 excludes `0.0.0-draft` projections from release-candidate selection. The evidence is recorded in the permissions report and does not authorize a speculative reinstall or `0.1.0` cut. diff --git a/apps/storycore-harbour/review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md b/apps/storycore-harbour/review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md index 6621965a..fcf4cac7 100644 --- a/apps/storycore-harbour/review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md +++ b/apps/storycore-harbour/review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md @@ -32,6 +32,28 @@ test**, create an immutable version, or repair the existing dev-install record server-side. Do not cut `0.1.0`, reinstall, uninstall, or change permissions as a diagnostic shortcut. +## Public guidance checked on 2026-08-30 + +Current Anna guidance is not unambiguous enough to choose a destructive or +immutable workaround: + +- the beginner publishing guide describes a working draft as testable, but its + permission walkthrough says to cut a version and then install it; +- an Anna Forum team response separately instructs developers to install a + working draft from Developer Console; +- the beta.126 changelog calls `0.0.0-draft` a projection row and explicitly + excludes it from release-candidate selection. + +Sources: + +- +- +- + +This conflict reinforces the support question below. It does not justify +cutting `0.1.0` while StoryCore's measured reliability gate remains below +18/20. + ## Safety boundary - **Install & test** was not clicked again because StoryCore is already listed. From e384c7cb61d763a9e83192e4c3733221cb390b77 Mon Sep 17 00:00:00 2001 From: Sylvain Galliez <128614184+zedarvates@users.noreply.github.com> Date: Sun, 30 Aug 2026 17:05:46 +0200 Subject: [PATCH 24/35] fix(harbour): confine marketplace logo renderer paths --- .../scripts/render-marketplace-logo.mjs | 19 ++++++++++++------- 1 file changed, 12 insertions(+), 7 deletions(-) diff --git a/apps/storycore-harbour/scripts/render-marketplace-logo.mjs b/apps/storycore-harbour/scripts/render-marketplace-logo.mjs index ea50ccf8..fd32b797 100644 --- a/apps/storycore-harbour/scripts/render-marketplace-logo.mjs +++ b/apps/storycore-harbour/scripts/render-marketplace-logo.mjs @@ -1,18 +1,20 @@ #!/usr/bin/env node import { mkdir, readFile } from "node:fs/promises"; -import { dirname, resolve } from "node:path"; +import { dirname, fileURLToPath } from "node:url"; +import { resolve } from "node:path"; import { chromium } from "playwright-core"; +const APP_ROOT = fileURLToPath(new URL("../", import.meta.url)); +const inputPath = resolve(APP_ROOT, "bundle/icon.svg"); +const outputPath = resolve(APP_ROOT, "review/marketplace-media/storycore-harbour-logo-256.png"); const executablePath = process.env.BROWSER_EXECUTABLE; -const inputPath = resolve(process.argv[2] || "bundle/icon.svg"); -const outputPath = resolve(process.argv[3] || "review/marketplace-media/storycore-harbour-logo-256.png"); if (!executablePath) { console.error("BROWSER_EXECUTABLE is required to render the Marketplace logo."); process.exit(2); } -await mkdir(dirname(outputPath), { recursive: true }); +await mkdir(resolve(APP_ROOT, "review/marketplace-media"), { recursive: true }); const browser = await chromium.launch({ executablePath, headless: true, @@ -28,9 +30,12 @@ try { html, body { margin: 0; width: 256px; height: 256px; background: transparent; } img { display: block; width: 256px; height: 256px; } - + `); - const logo = page.locator("img"); + const logo = page.locator("#marketplace-logo"); + await logo.evaluate((image, src) => { + image.src = src; + }, sourceUrl); await logo.waitFor({ state: "visible" }); await logo.evaluate(async (image) => { await image.decode(); @@ -39,7 +44,7 @@ try { } }); await logo.screenshot({ path: outputPath, omitBackground: true }); - console.log(JSON.stringify({ result: "pass", inputPath, outputPath, width: 256, height: 256 })); + console.log(JSON.stringify({ result: "pass", width: 256, height: 256 })); } finally { await browser.close(); } From 0d8d1deea134376a96b756e347542ca1d0d7b561 Mon Sep 17 00:00:00 2001 From: Sylvain Galliez <128614184+zedarvates@users.noreply.github.com> Date: Sun, 30 Aug 2026 17:05:59 +0200 Subject: [PATCH 25/35] fix(harbour): correct marketplace renderer imports --- apps/storycore-harbour/scripts/render-marketplace-logo.mjs | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/apps/storycore-harbour/scripts/render-marketplace-logo.mjs b/apps/storycore-harbour/scripts/render-marketplace-logo.mjs index fd32b797..adb34b74 100644 --- a/apps/storycore-harbour/scripts/render-marketplace-logo.mjs +++ b/apps/storycore-harbour/scripts/render-marketplace-logo.mjs @@ -1,12 +1,13 @@ #!/usr/bin/env node import { mkdir, readFile } from "node:fs/promises"; -import { dirname, fileURLToPath } from "node:url"; +import { fileURLToPath } from "node:url"; import { resolve } from "node:path"; import { chromium } from "playwright-core"; const APP_ROOT = fileURLToPath(new URL("../", import.meta.url)); const inputPath = resolve(APP_ROOT, "bundle/icon.svg"); -const outputPath = resolve(APP_ROOT, "review/marketplace-media/storycore-harbour-logo-256.png"); +const outputDirectory = resolve(APP_ROOT, "review/marketplace-media"); +const outputPath = resolve(outputDirectory, "storycore-harbour-logo-256.png"); const executablePath = process.env.BROWSER_EXECUTABLE; if (!executablePath) { @@ -14,7 +15,7 @@ if (!executablePath) { process.exit(2); } -await mkdir(resolve(APP_ROOT, "review/marketplace-media"), { recursive: true }); +await mkdir(outputDirectory, { recursive: true }); const browser = await chromium.launch({ executablePath, headless: true, From 6118b208f91eee6a3325d1b0d31b190a64c35860 Mon Sep 17 00:00:00 2001 From: Sylvain Galliez <128614184+zedarvates@users.noreply.github.com> Date: Sun, 30 Aug 2026 17:06:18 +0200 Subject: [PATCH 26/35] fix(harbour): confine marketplace logo validation path --- .../storycore-harbour/scripts/validate-marketplace-logo.mjs | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/apps/storycore-harbour/scripts/validate-marketplace-logo.mjs b/apps/storycore-harbour/scripts/validate-marketplace-logo.mjs index ebae6a00..e2909254 100644 --- a/apps/storycore-harbour/scripts/validate-marketplace-logo.mjs +++ b/apps/storycore-harbour/scripts/validate-marketplace-logo.mjs @@ -2,10 +2,11 @@ import assert from "node:assert/strict"; import { readFile } from "node:fs/promises"; import { resolve } from "node:path"; -import { pathToFileURL } from "node:url"; +import { fileURLToPath, pathToFileURL } from "node:url"; import { chromium } from "playwright-core"; -const logoPath = resolve(process.argv[2] || "review/marketplace-media/storycore-harbour-logo-256.png"); +const APP_ROOT = fileURLToPath(new URL("../", import.meta.url)); +const logoPath = resolve(APP_ROOT, "review/marketplace-media/storycore-harbour-logo-256.png"); const executablePath = process.env.BROWSER_EXECUTABLE; const bytes = await readFile(logoPath); const pngSignature = Buffer.from([137, 80, 78, 71, 13, 10, 26, 10]); @@ -60,7 +61,6 @@ assert.ok(near(samples.cyanWave, [71, 215, 232, 255]), "Logo wave must render cy console.log(JSON.stringify({ result: "pass", - logoPath, format: "PNG", width: 256, height: 256, From 5df61e2319990b222168d140b607f5f55b895361 Mon Sep 17 00:00:00 2001 From: Sylvain Galliez <128614184+zedarvates@users.noreply.github.com> Date: Sun, 30 Aug 2026 17:09:04 +0200 Subject: [PATCH 27/35] test(harbour): lock marketplace logo file contract --- .../tests/marketplace-logo.test.mjs | 20 +++++++++++++++++++ 1 file changed, 20 insertions(+) create mode 100644 apps/storycore-harbour/tests/marketplace-logo.test.mjs diff --git a/apps/storycore-harbour/tests/marketplace-logo.test.mjs b/apps/storycore-harbour/tests/marketplace-logo.test.mjs new file mode 100644 index 00000000..8c6b2232 --- /dev/null +++ b/apps/storycore-harbour/tests/marketplace-logo.test.mjs @@ -0,0 +1,20 @@ +import assert from "node:assert/strict"; +import { readFile } from "node:fs/promises"; +import { fileURLToPath } from "node:url"; +import { resolve } from "node:path"; +import test from "node:test"; + +const APP_ROOT = fileURLToPath(new URL("../", import.meta.url)); +const logoPath = resolve(APP_ROOT, "review/marketplace-media/storycore-harbour-logo-256.png"); +const pngSignature = Buffer.from([137, 80, 78, 71, 13, 10, 26, 10]); + +test("committed Marketplace logo is a bounded 256px PNG", async () => { + const bytes = await readFile(logoPath); + + assert.ok(bytes.subarray(0, 8).equals(pngSignature)); + assert.equal(bytes.subarray(12, 16).toString("ascii"), "IHDR"); + assert.equal(bytes.readUInt32BE(16), 256); + assert.equal(bytes.readUInt32BE(20), 256); + assert.ok(bytes.length > 0); + assert.ok(bytes.length <= 2 * 1024 * 1024); +}); From ab63ce558a8c6dbb77bedc197ccbfab4b541cbb5 Mon Sep 17 00:00:00 2001 From: Sylvain Galliez <128614184+zedarvates@users.noreply.github.com> Date: Sun, 30 Aug 2026 17:11:48 +0200 Subject: [PATCH 28/35] docs(harbour): record bounded Sonar security remediation --- .../SONAR_SECURITY_FOLLOWUP_2026-08-30.md | 60 +++++++++++++++++++ 1 file changed, 60 insertions(+) create mode 100644 apps/storycore-harbour/review/SONAR_SECURITY_FOLLOWUP_2026-08-30.md diff --git a/apps/storycore-harbour/review/SONAR_SECURITY_FOLLOWUP_2026-08-30.md b/apps/storycore-harbour/review/SONAR_SECURITY_FOLLOWUP_2026-08-30.md new file mode 100644 index 00000000..9732fdc8 --- /dev/null +++ b/apps/storycore-harbour/review/SONAR_SECURITY_FOLLOWUP_2026-08-30.md @@ -0,0 +1,60 @@ +# Sonar security follow-up — 2026-08-30 + +## Context + +Draft PR #37 previously passed the StoryCore Harbour functional CI while SonarQube Cloud reported a **C Security Rating on New Code** with two annotations. The regression appeared after the Marketplace-logo helper scripts were added. + +A subsequent Sonar attempt reported only `The last analysis has failed`, so that attempt is not evidence that the security rating recovered. The release/security gate remains open until a completed Sonar analysis reports the required rating. + +## Bounded remediation + +The two new Marketplace-logo scripts were hardened without broadening App permissions or runtime capabilities. + +### Renderer + +`./scripts/render-marketplace-logo.mjs` + +- no longer accepts CLI-supplied input or output paths; +- derives the App root from `import.meta.url`; +- reads only committed `bundle/icon.svg`; +- writes only `review/marketplace-media/storycore-harbour-logo-256.png`; +- no longer interpolates the SVG data URL into an HTML template; +- assigns the fixed local source as the image `src` property; +- no longer prints local filesystem paths in its result log. + +### Validator + +`./scripts/validate-marketplace-logo.mjs` + +- no longer accepts a CLI-supplied logo path; +- reads only the committed StoryCore Harbour Marketplace PNG; +- checks PNG signature, IHDR, 256 × 256 dimensions, the 2 MB limit, and representative pixels; +- no longer prints the local filesystem path. + +### Regression coverage + +`tests/marketplace-logo.test.mjs` independently verifies that the committed asset: + +- is a PNG; +- begins with IHDR; +- is exactly 256 × 256; +- is non-empty; +- remains below 2 MB. + +The normal Harbour CI remains green after these changes. + +## Evidence boundary + +This report does **not** claim that the two former Sonar annotations were definitively those two path flows, because the annotation detail was not exposed through the available connector. It records the smallest plausible remediation from the exact code introduced in the same change window. + +Do not mark the security gate resolved from CI success alone. + +## Exit condition + +A fresh completed SonarQube Cloud analysis for the current PR head must show: + +- Quality Gate passed; +- Security Rating on New Code = A; +- zero unresolved new security issues/hotspots relevant to this change. + +If Sonar reports another concrete issue, fix only that issue and rerun. Do not suppress, accept, or lower the Quality Gate merely to unblock Harbour. From 9e80b5490dd10f25a5cbf54e27d0ff62b367d06b Mon Sep 17 00:00:00 2001 From: Sylvain Galliez <128614184+zedarvates@users.noreply.github.com> Date: Sun, 30 Aug 2026 17:14:44 +0200 Subject: [PATCH 29/35] docs(harbour): record suspected upstream Sonar autoscan failure --- .../SONAR_SECURITY_FOLLOWUP_2026-08-30.md | 26 ++++++++++++++++--- 1 file changed, 23 insertions(+), 3 deletions(-) diff --git a/apps/storycore-harbour/review/SONAR_SECURITY_FOLLOWUP_2026-08-30.md b/apps/storycore-harbour/review/SONAR_SECURITY_FOLLOWUP_2026-08-30.md index 9732fdc8..fedb20f9 100644 --- a/apps/storycore-harbour/review/SONAR_SECURITY_FOLLOWUP_2026-08-30.md +++ b/apps/storycore-harbour/review/SONAR_SECURITY_FOLLOWUP_2026-08-30.md @@ -4,7 +4,7 @@ Draft PR #37 previously passed the StoryCore Harbour functional CI while SonarQube Cloud reported a **C Security Rating on New Code** with two annotations. The regression appeared after the Marketplace-logo helper scripts were added. -A subsequent Sonar attempt reported only `The last analysis has failed`, so that attempt is not evidence that the security rating recovered. The release/security gate remains open until a completed Sonar analysis reports the required rating. +The two helper surfaces were hardened, but subsequent Sonar Automatic Analysis attempts no longer produced a Quality Gate result and instead reported only `The last analysis has failed`. Therefore there is currently **no evidence that the security rating recovered**. The release/security gate remains open until a completed Sonar analysis reports the required rating. ## Bounded remediation @@ -41,11 +41,31 @@ The two new Marketplace-logo scripts were hardened without broadening App permis - is non-empty; - remains below 2 MB. -The normal Harbour CI remains green after these changes. +StoryCore Harbour CI run #135 is green after these changes. + +## Current Sonar service evidence + +Public Sonar Community reports dated 2026-08-28 and 2026-08-29 describe contemporaneous SonarQube Cloud Automatic Analysis failures with the same broad symptom seen here: GitHub checks are queued or ordinary CI remains green while Automatic Analysis reports `The last analysis has failed` and, in at least one report, no Compute Engine task is created at all. + +Relevant public reports: + +- `Automatic Analysis silently failing since 2026-08-28 — failing analysis ID provided` (2026-08-29); +- `SonarQube Cloud Automatic Analysis queues GitHub checks but starts no CE task for PR #8` (2026-08-28); +- `New repo, Error: The last analysis has failed` (2026-08-28). + +This is **corroborating evidence of a possible upstream service incident**, not proof that StoryCore's current analysis failure has the same root cause. Do not treat it as a waiver of the Harbour security gate. ## Evidence boundary -This report does **not** claim that the two former Sonar annotations were definitively those two path flows, because the annotation detail was not exposed through the available connector. It records the smallest plausible remediation from the exact code introduced in the same change window. +This report does **not** claim that the two former Sonar annotations were definitively the two Marketplace path flows, because the annotation details were not exposed through the available connector. It records the smallest plausible remediation from the exact code introduced in the same change window. + +It also does not claim the Sonar service is definitively at fault. The current state is: + +- functional Harbour CI: green; +- previous completed Sonar result: Security Rating C; +- relevant code surfaces: hardened; +- subsequent Sonar Automatic Analysis attempts: analysis failure before a usable Quality Gate result; +- security gate: still open. Do not mark the security gate resolved from CI success alone. From 4334cf54f9b4c61f322a5081348c0bc6ecf7096f Mon Sep 17 00:00:00 2001 From: Sylvain Galliez <128614184+zedarvates@users.noreply.github.com> Date: Sun, 30 Aug 2026 17:16:13 +0200 Subject: [PATCH 30/35] docs(harbour): close Sonar gate after clean analysis --- .../SONAR_SECURITY_FOLLOWUP_2026-08-30.md | 49 +++++++++---------- 1 file changed, 24 insertions(+), 25 deletions(-) diff --git a/apps/storycore-harbour/review/SONAR_SECURITY_FOLLOWUP_2026-08-30.md b/apps/storycore-harbour/review/SONAR_SECURITY_FOLLOWUP_2026-08-30.md index fedb20f9..183b0b72 100644 --- a/apps/storycore-harbour/review/SONAR_SECURITY_FOLLOWUP_2026-08-30.md +++ b/apps/storycore-harbour/review/SONAR_SECURITY_FOLLOWUP_2026-08-30.md @@ -1,10 +1,23 @@ # Sonar security follow-up — 2026-08-30 +## Result + +The StoryCore Harbour security gate is restored. + +After the Marketplace-logo helper hardening, SonarQube Cloud completed a fresh analysis on PR #37 and reported: + +- **Quality Gate passed**; +- **0 New issues**; +- **0 Accepted issues**; +- **0 Security Hotspots**. + +This supersedes the earlier C Security Rating result and the intervening Automatic Analysis failures. No issue was suppressed or accepted and the Quality Gate was not lowered. + ## Context -Draft PR #37 previously passed the StoryCore Harbour functional CI while SonarQube Cloud reported a **C Security Rating on New Code** with two annotations. The regression appeared after the Marketplace-logo helper scripts were added. +Draft PR #37 had previously passed the StoryCore Harbour functional CI while SonarQube Cloud reported a **C Security Rating on New Code** with two annotations. The regression appeared after the Marketplace-logo helper scripts were added. -The two helper surfaces were hardened, but subsequent Sonar Automatic Analysis attempts no longer produced a Quality Gate result and instead reported only `The last analysis has failed`. Therefore there is currently **no evidence that the security rating recovered**. The release/security gate remains open until a completed Sonar analysis reports the required rating. +The two helper surfaces were then hardened. Several intervening Sonar Automatic Analysis attempts reported only `The last analysis has failed`; those attempts were treated as inconclusive rather than as evidence of recovery. ## Bounded remediation @@ -41,40 +54,26 @@ The two new Marketplace-logo scripts were hardened without broadening App permis - is non-empty; - remains below 2 MB. -StoryCore Harbour CI run #135 is green after these changes. +StoryCore Harbour CI run #136 is green after the final evidence update. -## Current Sonar service evidence +## Sonar service evidence during diagnosis -Public Sonar Community reports dated 2026-08-28 and 2026-08-29 describe contemporaneous SonarQube Cloud Automatic Analysis failures with the same broad symptom seen here: GitHub checks are queued or ordinary CI remains green while Automatic Analysis reports `The last analysis has failed` and, in at least one report, no Compute Engine task is created at all. +Public Sonar Community reports dated 2026-08-28 and 2026-08-29 described contemporaneous SonarQube Cloud Automatic Analysis failures with the same broad symptom seen during the intervening attempts: ordinary CI remained green while Automatic Analysis reported `The last analysis has failed`, and one report described no Compute Engine task being created. -Relevant public reports: +Relevant public reports included: - `Automatic Analysis silently failing since 2026-08-28 — failing analysis ID provided` (2026-08-29); - `SonarQube Cloud Automatic Analysis queues GitHub checks but starts no CE task for PR #8` (2026-08-28); - `New repo, Error: The last analysis has failed` (2026-08-28). -This is **corroborating evidence of a possible upstream service incident**, not proof that StoryCore's current analysis failure has the same root cause. Do not treat it as a waiver of the Harbour security gate. +Those reports remain corroborating evidence that the intervening analysis failures may have involved a service-side problem. They are not needed to justify the final result because a subsequent completed StoryCore analysis now passes. ## Evidence boundary -This report does **not** claim that the two former Sonar annotations were definitively the two Marketplace path flows, because the annotation details were not exposed through the available connector. It records the smallest plausible remediation from the exact code introduced in the same change window. - -It also does not claim the Sonar service is definitively at fault. The current state is: - -- functional Harbour CI: green; -- previous completed Sonar result: Security Rating C; -- relevant code surfaces: hardened; -- subsequent Sonar Automatic Analysis attempts: analysis failure before a usable Quality Gate result; -- security gate: still open. - -Do not mark the security gate resolved from CI success alone. - -## Exit condition +The available connector did not expose the detailed text of the original two Sonar annotations, so this report does not claim a proven one-to-one mapping between those annotations and the two path flows. The remediation was the smallest security-oriented change to the executable code introduced in the same change window, and the completed post-remediation Sonar analysis now reports a clean Quality Gate. -A fresh completed SonarQube Cloud analysis for the current PR head must show: +## Current gate -- Quality Gate passed; -- Security Rating on New Code = A; -- zero unresolved new security issues/hotspots relevant to this change. +The Sonar security blocker is closed for the current PR state. It must reopen automatically if a later Harbour change produces a failed or missing required Sonar Quality Gate. -If Sonar reports another concrete issue, fix only that issue and rerun. Do not suppress, accept, or lower the Quality Gate merely to unblock Harbour. +This does **not** close StoryCore Harbour's separate real-model reliability gate. The immutable acceptance target remains at least 18/20 with median successful completion at or below 180 seconds. From 875a2dc8e9727bd194218de6a68254d7053d299a Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Mon, 31 Aug 2026 14:18:31 +0200 Subject: [PATCH 31/35] docs(harbour): record post-repair Gemma corpus --- apps/storycore-harbour/STATUS.md | 2 ++ apps/storycore-harbour/review/FINAL_HANDOFF_2026-08-24.md | 6 ++++++ apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md | 1 + 3 files changed, 9 insertions(+) diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index feb790ae..5033c2db 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -311,3 +311,5 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - After a fresh owner sign-in, **View manifest** succeeded and displayed the normalized working r12 manifest. It matches the committed Schema 2 Host-API-only boundary: no Executas, no top-level permissions, no external origins, one desktop view, `llm.complete`, App storage get/set/list/delete, `window.set_title`, self-only script CSP, and `last_writer_wins`. The credential incident is operationally resolved by reauthentication, while the exact token/frontend root cause remains unproven. No support message was sent. - Installed Apps already contains StoryCore Harbour as `v0.0.0-dev`, so **Install & test** was not clicked again. Its read-only Permissions panel returns `Failed to load permissions: App version not found`. CLI status simultaneously confirms draft r12 has zero immutable versions and the grants endpoint exposes no data. The facts identify a dev-install/version-resolution blocker for permission management; they do not prove whether refresh, immutable cut, or server repair is the correct fix. `review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md` contains the bounded support question, and nothing was sent or changed. - Public Anna guidance rechecked on 2026-08-30 is internally ambiguous for this exact boundary: one guide moves installation/permissions after an immutable cut, another team response directs working-draft installation, and beta.126 excludes `0.0.0-draft` projections from release-candidate selection. The evidence is recorded in the permissions report and does not authorize a speculative reinstall or `0.1.0` cut. +- An owner-authorized complete corpus on 2026-08-31 used the advisory `gemma` hint after the schema-complete repair change. The connected Anna UI finished at 15/20, median 23.90 seconds, p95 44.00 seconds, and 7 repaired passes. Failures were HBR-A01 `unknown` after one transport `fetch failed`, plus HBR-A06/A08/A15/A20 `json_invalid`. Every malformed primary/repair response used `gemma-4-E4B-it` through Runpod, ended with `endTurn`, stayed between 1,269 and 1,722 output tokens, and ended with a closing brace; the remaining failures are internal JSON syntax errors rather than 4,096-token truncation. The score remains below 18/20, so no readiness, immutable cut, review, merge, or release claim is permitted. +- The iframe sandbox did not surface its Blob download to Browser automation. The private result was therefore recovered from the same run's RPC log: exactly 15 `projects/current` writes were matched to the immutable corpus, each recovered project passed the canonical contract, UI-displayed successful durations were retained at 0.1-second precision, and failure durations came from the sequential RPC timestamps. The canonical evaluator independently reproduced 15/20 and the same five privacy-safe failures. Ignored evidence remains at `acceptance/results.2026-08-31.gemma.recovered.local.jsonl`, `acceptance/harness.2026-08-31.gemma.local.log`, and companion local logs; generated content was not committed or posted. diff --git a/apps/storycore-harbour/review/FINAL_HANDOFF_2026-08-24.md b/apps/storycore-harbour/review/FINAL_HANDOFF_2026-08-24.md index 5b37a94e..db0d6998 100644 --- a/apps/storycore-harbour/review/FINAL_HANDOFF_2026-08-24.md +++ b/apps/storycore-harbour/review/FINAL_HANDOFF_2026-08-24.md @@ -103,6 +103,12 @@ without addressing the failure. Do not cut `0.1.0`, submit for review, mark PR #37 ready, merge, or release while the official gate remains below 18/20. The latest measured Gemma run is 15/20 and the latest Anna-default run is 6/20. The App is demonstrable and its working draft is reserved, but it is not submission-ready under the repository's own rules. +The owner-authorized 2026-08-31 Gemma rerun after the schema-complete repair +also measured 15/20 (median 23.90 seconds, p95 44.00 seconds, 7 repaired +passes). A01 failed at transport; A06/A08/A15/A20 returned complete but +syntactically invalid JSON. This supersedes the 27 August Gemma run as the +latest real evidence without changing the submission decision. + ### Anna installation diagnosis - Developer Console shows the working draft as `v0.0.0`, `WORKING`, and `Unpublished`; diff --git a/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md b/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md index bac4b8d0..188a7bc4 100644 --- a/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md +++ b/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md @@ -93,3 +93,4 @@ Do not replace production-platform gates with these local results. - Third-model probe blocked: hint `gpt-4o` returned no response metadata and remained pending beyond the App timeout. Treat it as a platform cancellation/grant issue, not model evidence; no further blind hint probes. - 27 August default-model rerun: the complete immutable corpus used `minimax/minimax-m3` through OpenRouter and finished at 6/20, median 49.13 seconds, p95 57.87 seconds, and 2 repaired passes. The privacy-safe failure matrix was eight `json_invalid`, five `contract_invalid`, and one timeout. The ignored private JSONL is `acceptance/results.2026-08-27.local.jsonl`. This is a measured stochastic regression from the earlier 16/20 default run, so readiness remains blocked and no parser relaxation, immutable version, review submission, or release is justified. - 27 August Gemma rerun: the complete immutable corpus with advisory hint `gemma` finished at 15/20, median 21.91 seconds, p95 41.92 seconds, and 6 repaired passes. Failures were A07/A10/A12/A19 `contract_invalid` and A20 `required_field_invalid`, with no timeout or JSON truncation. The ignored private JSONL is `acceptance/results.2026-08-27.gemma.local.jsonl`. This improves the measured Gemma profile from 14/20 to 15/20 but remains below the 18/20 gate; keep the PR draft and do not cut, submit, or release a version. +- 31 August post-repair Gemma rerun: the complete connected corpus again finished at 15/20, median 23.90 seconds, p95 44.00 seconds, and 7 repaired passes. A01 failed at transport; A06/A08/A15/A20 were `json_invalid` after complete, non-truncated Gemma/Runpod responses. The schema-complete repair changed which prompts pass and increased repaired passes, but did not improve the total score. The private result was canonically re-evaluated from an RPC-log recovery because the iframe download was not surfaced to automation. Keep the release gate failed and do not fund another blind rerun without a measured syntax intervention or platform/model change. From ebf525af91cf2f123c43e68fc2bcf8b97963c371 Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Mon, 31 Aug 2026 17:55:27 +0200 Subject: [PATCH 32/35] docs(harbour): reject insufficient JSON punctuation recovery --- apps/storycore-harbour/STATUS.md | 1 + apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md | 1 + 2 files changed, 2 insertions(+) diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 5033c2db..1e5a9bdc 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -313,3 +313,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - Public Anna guidance rechecked on 2026-08-30 is internally ambiguous for this exact boundary: one guide moves installation/permissions after an immutable cut, another team response directs working-draft installation, and beta.126 excludes `0.0.0-draft` projections from release-candidate selection. The evidence is recorded in the permissions report and does not authorize a speculative reinstall or `0.1.0` cut. - An owner-authorized complete corpus on 2026-08-31 used the advisory `gemma` hint after the schema-complete repair change. The connected Anna UI finished at 15/20, median 23.90 seconds, p95 44.00 seconds, and 7 repaired passes. Failures were HBR-A01 `unknown` after one transport `fetch failed`, plus HBR-A06/A08/A15/A20 `json_invalid`. Every malformed primary/repair response used `gemma-4-E4B-it` through Runpod, ended with `endTurn`, stayed between 1,269 and 1,722 output tokens, and ended with a closing brace; the remaining failures are internal JSON syntax errors rather than 4,096-token truncation. The score remains below 18/20, so no readiness, immutable cut, review, merge, or release claim is permitted. - The iframe sandbox did not surface its Blob download to Browser automation. The private result was therefore recovered from the same run's RPC log: exactly 15 `projects/current` writes were matched to the immutable corpus, each recovered project passed the canonical contract, UI-displayed successful durations were retained at 0.1-second precision, and failure durations came from the sequential RPC timestamps. The canonical evaluator independently reproduced 15/20 and the same five privacy-safe failures. Ignored evidence remains at `acceptance/results.2026-08-31.gemma.recovered.local.jsonl`, `acceptance/harness.2026-08-31.gemma.local.log`, and companion local logs; generated content was not committed or posted. +- A private offline punctuation-recovery experiment made no model calls and never changed generated words. A bounded search of at most three edits from `{ } [ ] , :` recovered A08 and A15 with two edits each, so the best projected score was only 17/20. A06 remained unparsable after 28,876 bounded candidates. Closing A20's unbalanced JSON made it parse but left five canonical contract errors. There is no single bounded syntax rule that reaches the release gate, so the experimental helper was removed and production parsing remains fail-closed. diff --git a/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md b/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md index 188a7bc4..3d0367c8 100644 --- a/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md +++ b/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md @@ -94,3 +94,4 @@ Do not replace production-platform gates with these local results. - 27 August default-model rerun: the complete immutable corpus used `minimax/minimax-m3` through OpenRouter and finished at 6/20, median 49.13 seconds, p95 57.87 seconds, and 2 repaired passes. The privacy-safe failure matrix was eight `json_invalid`, five `contract_invalid`, and one timeout. The ignored private JSONL is `acceptance/results.2026-08-27.local.jsonl`. This is a measured stochastic regression from the earlier 16/20 default run, so readiness remains blocked and no parser relaxation, immutable version, review submission, or release is justified. - 27 August Gemma rerun: the complete immutable corpus with advisory hint `gemma` finished at 15/20, median 21.91 seconds, p95 41.92 seconds, and 6 repaired passes. Failures were A07/A10/A12/A19 `contract_invalid` and A20 `required_field_invalid`, with no timeout or JSON truncation. The ignored private JSONL is `acceptance/results.2026-08-27.gemma.local.jsonl`. This improves the measured Gemma profile from 14/20 to 15/20 but remains below the 18/20 gate; keep the PR draft and do not cut, submit, or release a version. - 31 August post-repair Gemma rerun: the complete connected corpus again finished at 15/20, median 23.90 seconds, p95 44.00 seconds, and 7 repaired passes. A01 failed at transport; A06/A08/A15/A20 were `json_invalid` after complete, non-truncated Gemma/Runpod responses. The schema-complete repair changed which prompts pass and increased repaired passes, but did not improve the total score. The private result was canonically re-evaluated from an RPC-log recovery because the iframe download was not surfaced to automation. Keep the release gate failed and do not fund another blind rerun without a measured syntax intervention or platform/model change. +- Offline syntax experiment: a maximum-three-edit punctuation search recovered only A08/A15, projecting 17/20. A06 had no valid candidate; structurally closing A20 still left five contract failures. Do not add a general JSON-repair dependency or permissive parser from this evidence. Production remains fail-closed; the next useful evidence requires a model/platform change or a specifically measured generation constraint, not another blind corpus run. From e07623070660bf25ee79848bae24454df8ff45f2 Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Tue, 1 Sep 2026 15:05:38 +0200 Subject: [PATCH 33/35] docs(harbour): map Anna structured-output boundary --- apps/storycore-harbour/STATUS.md | 1 + .../review/ANNA_STRUCTURED_OUTPUT_REQUEST.md | 89 +++++++++++++++++++ .../review/MVP_ROADMAP_2026-08-24.md | 1 + 3 files changed, 91 insertions(+) create mode 100644 apps/storycore-harbour/review/ANNA_STRUCTURED_OUTPUT_REQUEST.md diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index 1e5a9bdc..ac5bf627 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -314,3 +314,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - An owner-authorized complete corpus on 2026-08-31 used the advisory `gemma` hint after the schema-complete repair change. The connected Anna UI finished at 15/20, median 23.90 seconds, p95 44.00 seconds, and 7 repaired passes. Failures were HBR-A01 `unknown` after one transport `fetch failed`, plus HBR-A06/A08/A15/A20 `json_invalid`. Every malformed primary/repair response used `gemma-4-E4B-it` through Runpod, ended with `endTurn`, stayed between 1,269 and 1,722 output tokens, and ended with a closing brace; the remaining failures are internal JSON syntax errors rather than 4,096-token truncation. The score remains below 18/20, so no readiness, immutable cut, review, merge, or release claim is permitted. - The iframe sandbox did not surface its Blob download to Browser automation. The private result was therefore recovered from the same run's RPC log: exactly 15 `projects/current` writes were matched to the immutable corpus, each recovered project passed the canonical contract, UI-displayed successful durations were retained at 0.1-second precision, and failure durations came from the sequential RPC timestamps. The canonical evaluator independently reproduced 15/20 and the same five privacy-safe failures. Ignored evidence remains at `acceptance/results.2026-08-31.gemma.recovered.local.jsonl`, `acceptance/harness.2026-08-31.gemma.local.log`, and companion local logs; generated content was not committed or posted. - A private offline punctuation-recovery experiment made no model calls and never changed generated words. A bounded search of at most three edits from `{ } [ ] , :` recovered A08 and A15 with two edits each, so the best projected score was only 17/20. A06 remained unparsable after 28,876 bounded candidates. Closing A20's unbalanced JSON made it parse but left five canonical contract errors. There is no single bounded syntax rule that reaches the release gate, so the experimental helper was removed and production parsing remains fail-closed. +- Structured-output research on 2026-09-01 found that Anna documents `json_object`/`json_schema` for Executa `sampling/createMessage`, not for StoryCore's direct iframe `anna.llm.complete`. The pinned CLI 0.1.30 has no structured-output implementation; a read-only inspection of npm CLI 0.1.49 found negotiation only in the sampling bridge and still no direct Host API field. An Executa migration would violate the Host-API-only MVP boundary, and a current Cloud Agent report shows `json_schema` failures even with fallback. `review/ANNA_STRUCTURED_OUTPUT_REQUEST.md` contains the exact support question and a one-prompt gate; no package was upgraded and no model call was made. diff --git a/apps/storycore-harbour/review/ANNA_STRUCTURED_OUTPUT_REQUEST.md b/apps/storycore-harbour/review/ANNA_STRUCTURED_OUTPUT_REQUEST.md new file mode 100644 index 00000000..da283a04 --- /dev/null +++ b/apps/storycore-harbour/review/ANNA_STRUCTURED_OUTPUT_REQUEST.md @@ -0,0 +1,89 @@ +# Anna direct Host LLM structured-output request + +Prepared on 2026-09-01. This is a support-question and bounded-probe plan; it +has not been sent and no model call was made for this investigation. + +## StoryCore evidence + +- StoryCore Harbour is a Schema 2, Host-API-only App with no Executa. +- Its current generation path is `anna.llm.complete` from the iframe bundle. +- The 2026-08-31 Gemma corpus measured 15/20. Four final repair responses were + complete, non-truncated, and ended with `}`, but contained internal JSON + syntax errors. +- A punctuation-only offline search could recover only two cases, projecting + 17/20; it does not justify a permissive production parser. + +## Verified Anna surfaces + +Anna supports structured output on Executa reverse sampling: + +- `sampling/createMessage` accepts `responseFormat` with `json_object` or + `json_schema` plus `onUnsupported`; +- the real bridge sends the negotiated value as `response_format` to the + platform completion endpoint; +- CLI structured-output emulation exists for the sampling development path. + +This support is not currently documented or typed for the iframe Host API +`anna.llm.complete`. Its published signature lists messages, `maxTokens`, +`modelPreferences`, `systemPrompt`, temperature, stop sequences, and metadata, +but no response-format field. + +Local package inspection confirms the same boundary: + +- pinned CLI 0.1.30 contains no `responseFormat`, `response_format`, or + `onUnsupported` implementation; +- latest npm CLI 0.1.49 adds structured negotiation to its sampling bridge; +- CLI 0.1.49 still exposes no response-format field for direct Host + `llm.complete`. + +Moving StoryCore generation into an Executa only to obtain JSON Schema would +add a backend/distribution/permission boundary and violate the MVP's intended +Host-API-only architecture. Do not make that change without explicit product +and architecture approval. + +## Current platform caution + +The Anna Forum currently reports a Cloud Agent failure for `json_schema` even +with `onUnsupported=json_object`. Structured sampling is therefore not yet a +drop-in reliability proof for StoryCore. + +Sources checked: + +- +- +- +- + +## Ready-to-send question + +```text +Hi Anna team — StoryCore Harbour is a Schema 2 Host-API-only App using direct +iframe anna.llm.complete, with no Executa. Our latest fixed Gemma corpus is +15/20; four failed repairs are complete/non-truncated responses with internal +JSON syntax errors. + +The current sampling/createMessage path supports responseFormat +(json_object/json_schema) and onUnsupported, but the documented direct +anna.llm.complete signature and current CLI types do not expose those fields. + +1. Does direct iframe anna.llm.complete currently accept responseFormat or + response_format in production? +2. If yes, what exact wire shape and capability-negotiation response should a + Schema 2 App use? +3. Is json_object supported for gemma-4-E4B-it/Runpod through the App-complete + path? +4. Can unsupported structured output fail explicitly without silently falling + back to prompt-only text? +5. Is there a recommended Host-API-only example or minimum runtime/CLI version? + +We will not add an Executa, send another full corpus, or claim reliability from +an undocumented field. With confirmation, we can run one owner-authorized +single-prompt probe before considering any code change. +``` + +## Probe gate + +Do not add an undocumented field to production or consume quota until Anna +confirms the direct Host API contract. If confirmed, implement the smallest +adapter-only opt-in and run one previously failing prompt first. A complete +corpus requires separate owner quota approval after that pilot succeeds. diff --git a/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md b/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md index 3d0367c8..7c92f140 100644 --- a/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md +++ b/apps/storycore-harbour/review/MVP_ROADMAP_2026-08-24.md @@ -95,3 +95,4 @@ Do not replace production-platform gates with these local results. - 27 August Gemma rerun: the complete immutable corpus with advisory hint `gemma` finished at 15/20, median 21.91 seconds, p95 41.92 seconds, and 6 repaired passes. Failures were A07/A10/A12/A19 `contract_invalid` and A20 `required_field_invalid`, with no timeout or JSON truncation. The ignored private JSONL is `acceptance/results.2026-08-27.gemma.local.jsonl`. This improves the measured Gemma profile from 14/20 to 15/20 but remains below the 18/20 gate; keep the PR draft and do not cut, submit, or release a version. - 31 August post-repair Gemma rerun: the complete connected corpus again finished at 15/20, median 23.90 seconds, p95 44.00 seconds, and 7 repaired passes. A01 failed at transport; A06/A08/A15/A20 were `json_invalid` after complete, non-truncated Gemma/Runpod responses. The schema-complete repair changed which prompts pass and increased repaired passes, but did not improve the total score. The private result was canonically re-evaluated from an RPC-log recovery because the iframe download was not surfaced to automation. Keep the release gate failed and do not fund another blind rerun without a measured syntax intervention or platform/model change. - Offline syntax experiment: a maximum-three-edit punctuation search recovered only A08/A15, projecting 17/20. A06 had no valid candidate; structurally closing A20 still left five contract failures. Do not add a general JSON-repair dependency or permissive parser from this evidence. Production remains fail-closed; the next useful evidence requires a model/platform change or a specifically measured generation constraint, not another blind corpus run. +- Structured-output boundary: Anna's JSON Schema support is currently verified for Executa sampling, not the direct iframe `anna.llm.complete` path used by StoryCore. CLI 0.1.49 still confines response-format negotiation to sampling, and current Cloud Agent reports show structured fallback failures. Keep StoryCore Host-API-only; ask Anna for the direct contract, then permit at most one failing-prompt pilot before any adapter change or full rerun. From c9c3fc7b0ba45d373028632c45dc647944bf179f Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Sat, 5 Sep 2026 12:01:35 +0200 Subject: [PATCH 34/35] docs(harbour): refresh Anna CLI 0.1.51 boundaries --- apps/storycore-harbour/STATUS.md | 1 + .../review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md | 14 ++++++++++++++ .../review/ANNA_STRUCTURED_OUTPUT_REQUEST.md | 10 ++++++++++ 3 files changed, 25 insertions(+) diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index ac5bf627..aa6bd785 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -315,3 +315,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - The iframe sandbox did not surface its Blob download to Browser automation. The private result was therefore recovered from the same run's RPC log: exactly 15 `projects/current` writes were matched to the immutable corpus, each recovered project passed the canonical contract, UI-displayed successful durations were retained at 0.1-second precision, and failure durations came from the sequential RPC timestamps. The canonical evaluator independently reproduced 15/20 and the same five privacy-safe failures. Ignored evidence remains at `acceptance/results.2026-08-31.gemma.recovered.local.jsonl`, `acceptance/harness.2026-08-31.gemma.local.log`, and companion local logs; generated content was not committed or posted. - A private offline punctuation-recovery experiment made no model calls and never changed generated words. A bounded search of at most three edits from `{ } [ ] , :` recovered A08 and A15 with two edits each, so the best projected score was only 17/20. A06 remained unparsable after 28,876 bounded candidates. Closing A20's unbalanced JSON made it parse but left five canonical contract errors. There is no single bounded syntax rule that reaches the release gate, so the experimental helper was removed and production parsing remains fail-closed. - Structured-output research on 2026-09-01 found that Anna documents `json_object`/`json_schema` for Executa `sampling/createMessage`, not for StoryCore's direct iframe `anna.llm.complete`. The pinned CLI 0.1.30 has no structured-output implementation; a read-only inspection of npm CLI 0.1.49 found negotiation only in the sampling bridge and still no direct Host API field. An Executa migration would violate the Host-API-only MVP boundary, and a current Cloud Agent report shows `json_schema` failures even with fallback. `review/ANNA_STRUCTURED_OUTPUT_REQUEST.md` contains the exact support question and a one-prompt gate; no package was upgraded and no model call was made. +- A 2026-09-05 refresh found no direct-Host structured-output update. CLI 0.1.51 still confines `response_format` negotiation to Executa sampling. Its enhanced read-only `apps grants` command also returned only `grants: null` for StoryCore, without the new `satisfied`/`missing` fields, matching the unresolved `v0.0.0-dev` permission-version gap. The newer CLI was executed ephemerally and not added to the project; no quota, grant, draft, version, or installation state changed. diff --git a/apps/storycore-harbour/review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md b/apps/storycore-harbour/review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md index fcf4cac7..75d3cc29 100644 --- a/apps/storycore-harbour/review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md +++ b/apps/storycore-harbour/review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md @@ -83,3 +83,17 @@ working-draft Install & test record? We have not reinstalled, uninstalled, changed grants, cut a version, submitted review, or published anything. ``` + +## 2026-09-05 CLI 0.1.51 read-only check + +Anna CLI 0.1.51 adds a richer `apps grants` reader that first queries the App +permissions endpoint and normally reports `satisfied`, `missing`, and bundled +Executa grants. Running that command ephemerally against StoryCore Harbour still +returned only `grants: null`, with none of those permissions fields. This is +consistent with the Console's `App version not found` result: the improved CLI +cannot resolve permissions for the existing `v0.0.0-dev` record either. + +The CLI was not added to the project, no grant was changed, and the temporary +package inspection directory was removed. Version 0.1.51 does not provide a +grant mutation command; the dashboard remains the documented permission-change +surface. diff --git a/apps/storycore-harbour/review/ANNA_STRUCTURED_OUTPUT_REQUEST.md b/apps/storycore-harbour/review/ANNA_STRUCTURED_OUTPUT_REQUEST.md index da283a04..611bd946 100644 --- a/apps/storycore-harbour/review/ANNA_STRUCTURED_OUTPUT_REQUEST.md +++ b/apps/storycore-harbour/review/ANNA_STRUCTURED_OUTPUT_REQUEST.md @@ -87,3 +87,13 @@ Do not add an undocumented field to production or consume quota until Anna confirms the direct Host API contract. If confirmed, implement the smallest adapter-only opt-in and run one previously failing prompt first. A complete corpus requires separate owner quota approval after that pilot succeeds. + +## 2026-09-05 refresh + +No newer public Anna reference or forum answer was found that adds +`responseFormat` to direct iframe `anna.llm.complete`. Anna CLI 0.1.51 was +inspected without installation into the project. Its real sampling bridge +negotiates `responseFormat` and forwards `response_format`, but its direct App +LLM bridge still exposes no structured-output contract. Do not upgrade the +pinned CLI merely for this issue and do not send an undocumented field to the +production endpoint. From 4146f43b00195a8812daf4560883c01408aacf10 Mon Sep 17 00:00:00 2001 From: RapideCastor Date: Sat, 5 Sep 2026 12:55:28 +0200 Subject: [PATCH 35/35] docs(harbour): record Anna support escalation --- apps/storycore-harbour/STATUS.md | 1 + .../review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md | 7 ++++++- .../review/ANNA_STRUCTURED_OUTPUT_REQUEST.md | 9 +++++++-- 3 files changed, 14 insertions(+), 3 deletions(-) diff --git a/apps/storycore-harbour/STATUS.md b/apps/storycore-harbour/STATUS.md index aa6bd785..c8444c35 100644 --- a/apps/storycore-harbour/STATUS.md +++ b/apps/storycore-harbour/STATUS.md @@ -316,3 +316,4 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im - A private offline punctuation-recovery experiment made no model calls and never changed generated words. A bounded search of at most three edits from `{ } [ ] , :` recovered A08 and A15 with two edits each, so the best projected score was only 17/20. A06 remained unparsable after 28,876 bounded candidates. Closing A20's unbalanced JSON made it parse but left five canonical contract errors. There is no single bounded syntax rule that reaches the release gate, so the experimental helper was removed and production parsing remains fail-closed. - Structured-output research on 2026-09-01 found that Anna documents `json_object`/`json_schema` for Executa `sampling/createMessage`, not for StoryCore's direct iframe `anna.llm.complete`. The pinned CLI 0.1.30 has no structured-output implementation; a read-only inspection of npm CLI 0.1.49 found negotiation only in the sampling bridge and still no direct Host API field. An Executa migration would violate the Host-API-only MVP boundary, and a current Cloud Agent report shows `json_schema` failures even with fallback. `review/ANNA_STRUCTURED_OUTPUT_REQUEST.md` contains the exact support question and a one-prompt gate; no package was upgraded and no model call was made. - A 2026-09-05 refresh found no direct-Host structured-output update. CLI 0.1.51 still confines `response_format` negotiation to Executa sampling. Its enhanced read-only `apps grants` command also returned only `grants: null` for StoryCore, without the new `satisfied`/`missing` fields, matching the unresolved `v0.0.0-dev` permission-version gap. The newer CLI was executed ephemerally and not added to the project; no quota, grant, draft, version, or installation state changed. +- With explicit owner approval, one combined plain-text support email was sent to `hi@anna.partners` on 2026-09-05. It asks how to repair the existing `v0.0.0-dev` permission/version mismatch and whether direct iframe `anna.llm.complete` supports negotiated `json_object`/`json_schema`. It includes App id 214, slug, revision, privacy-safe 15/20 evidence, and the non-action boundaries; it contains no attachment, raw generated response, private JSONL, credential, or token. Do not send a duplicate while awaiting Anna's reply. diff --git a/apps/storycore-harbour/review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md b/apps/storycore-harbour/review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md index 75d3cc29..a116ba23 100644 --- a/apps/storycore-harbour/review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md +++ b/apps/storycore-harbour/review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md @@ -1,6 +1,8 @@ # Anna working-draft installation permissions report -Prepared on 2026-08-29. This report is local and has not been sent. +Prepared on 2026-08-29. An owner-approved combined support email was sent to +`hi@anna.partners` on 2026-09-05 with this installation question and the direct +structured-output question. No attachment or generated private result was sent. ## Observed state @@ -63,6 +65,9 @@ cutting `0.1.0` while StoryCore's measured reliability gate remains below ## Ready-to-send support question +Sent in the combined 2026-09-05 support email. Do not send a duplicate while a +reply is pending. + ```text Hi Anna team — StoryCore Harbour (App id 214) has a ready working draft at r12 and is already listed in Installed Apps as v0.0.0-dev. However, opening its diff --git a/apps/storycore-harbour/review/ANNA_STRUCTURED_OUTPUT_REQUEST.md b/apps/storycore-harbour/review/ANNA_STRUCTURED_OUTPUT_REQUEST.md index 611bd946..ad12b3d7 100644 --- a/apps/storycore-harbour/review/ANNA_STRUCTURED_OUTPUT_REQUEST.md +++ b/apps/storycore-harbour/review/ANNA_STRUCTURED_OUTPUT_REQUEST.md @@ -1,7 +1,9 @@ # Anna direct Host LLM structured-output request -Prepared on 2026-09-01. This is a support-question and bounded-probe plan; it -has not been sent and no model call was made for this investigation. +Prepared on 2026-09-01. An owner-approved combined support email was sent to +`hi@anna.partners` on 2026-09-05 with this question and the working-draft +permission issue. No attachment or generated private result was sent, and no +model call was made for this investigation. ## StoryCore evidence @@ -56,6 +58,9 @@ Sources checked: ## Ready-to-send question +Sent in the combined 2026-09-05 support email. Do not send a duplicate while a +reply is pending. + ```text Hi Anna team — StoryCore Harbour is a Schema 2 Host-API-only App using direct iframe anna.llm.complete, with no Executa. Our latest fixed Gemma corpus is