Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
36 commits
Select commit Hold shift + click to select a range
60b66b6
docs(harbour): reject cross-model repair experiment
zedarvates Aug 24, 2026
ee3b4eb
docs(harbour): record fail-closed A06 reproduction
zedarvates Aug 24, 2026
1cdcb1b
docs(harbour): record blocked third-model probe
zedarvates Aug 25, 2026
4202d3b
docs(harbour): record default-model corpus regression
zedarvates Aug 27, 2026
2ee3bee
docs(harbour): record Gemma corpus rerun
zedarvates Aug 27, 2026
718eaa5
test(harbour): refine privacy-safe acceptance failures
zedarvates Aug 28, 2026
03c2c54
docs(harbour): record Anna draft revision 10
zedarvates Aug 28, 2026
76965d0
docs(harbour): refresh owner handoff and grants evidence
zedarvates Aug 28, 2026
cdaf4c0
test(harbour): run browser smokes sequentially
zedarvates Aug 28, 2026
13adb02
fix(harbour): preserve states in forced colours
zedarvates Aug 28, 2026
96df0e1
docs(harbour): record Anna draft revision 11
zedarvates Aug 28, 2026
17b7095
docs(harbour): refresh revision 11 demo evidence
zedarvates Aug 28, 2026
bef958f
fix(harbour): make repair prompt schema-complete
zedarvates Aug 29, 2026
234987a
test(harbour): lock schema-complete repair contract
zedarvates Aug 29, 2026
b4a41b7
docs(harbour): prepare Anna media requirements request
zedarvates Aug 29, 2026
291ceb4
Merge remote-tracking branch 'github/agent/storycore-harbour-bootstra…
zedarvates Aug 29, 2026
8847853
docs(harbour): record Anna draft revision 12
zedarvates Aug 29, 2026
5ce095e
feat(harbour): prepare validated Anna marketplace logo
zedarvates Aug 29, 2026
104a149
docs(harbour): record working-draft install path
zedarvates Aug 29, 2026
8cc3e87
docs(harbour): capture Anna manifest credential blocker
zedarvates Aug 29, 2026
67944e4
docs(harbour): close Anna manifest read blocker
zedarvates Aug 29, 2026
fa7984c
docs(harbour): update manifest reauthentication runbook
zedarvates Aug 29, 2026
3800320
docs(harbour): diagnose dev-install permission mismatch
zedarvates Aug 29, 2026
0b76c86
docs(harbour): reconcile Anna draft-install guidance
zedarvates Aug 30, 2026
e384c7c
fix(harbour): confine marketplace logo renderer paths
zedarvates Aug 30, 2026
0d8d1de
fix(harbour): correct marketplace renderer imports
zedarvates Aug 30, 2026
6118b20
fix(harbour): confine marketplace logo validation path
zedarvates Aug 30, 2026
5df61e2
test(harbour): lock marketplace logo file contract
zedarvates Aug 30, 2026
ab63ce5
docs(harbour): record bounded Sonar security remediation
zedarvates Aug 30, 2026
9e80b54
docs(harbour): record suspected upstream Sonar autoscan failure
zedarvates Aug 30, 2026
4334cf5
docs(harbour): close Sonar gate after clean analysis
zedarvates Aug 30, 2026
875a2dc
docs(harbour): record post-repair Gemma corpus
zedarvates Aug 31, 2026
ebf525a
docs(harbour): reject insufficient JSON punctuation recovery
zedarvates Aug 31, 2026
e076230
docs(harbour): map Anna structured-output boundary
zedarvates Sep 1, 2026
c9c3fc7
docs(harbour): refresh Anna CLI 0.1.51 boundaries
zedarvates Sep 5, 2026
4146f43
docs(harbour): record Anna support escalation
zedarvates Sep 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions apps/storycore-harbour/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,12 @@ npm run dev:mock

`npm install` also generates the bundle copy of the canonical acceptance corpus. `npm run check` runs the tests, contract, mock response, acceptance corpus/synchronization, and strict Anna validator.

With the mock Anna harness already running, set `BROWSER_EXECUTABLE` to Edge or
another compatible Chromium binary and run `npm run browser:check`. This runs
the complete generation/export smoke and the storage-deletion smoke
sequentially. Do not run them in parallel against one mock harness because the
fixture stream is shared.

For the real-model protocol, follow `acceptance/README.md`. Do not run the collector without an authenticated Anna test account, an enabled model, sufficient quota, and explicit confirmation in its UI.

## Release identity
Expand Down
28 changes: 28 additions & 0 deletions apps/storycore-harbour/STATUS.md
Original file line number Diff line number Diff line change
Expand Up @@ -288,4 +288,32 @@ Codex must inspect the latest CI and Sonar results first. The next legitimate im
- The Anna adapter now exposes an optional user-entered model preference. Blank or invalid values preserve the Anna default; valid hints are advisory and only match models already enabled for that user. Normal StoryCore data and provider credentials remain unaffected. Automated gates pass: 65/65 Node tests, strict validation, Edge end-to-end smoke, and Edge deletion/storage-preservation smoke.
- The complete fixed corpus with user preference `gemma` finished at 14/20: median 21.67 seconds, p95 39.78 seconds, 6 repaired passes, and no JSON truncation. Failures were A02 `reference_invalid`, A06/A09/A11 `contract_invalid`, A10 `warning_severity_invalid`, and A19 `required_field_invalid`.
- Exact private-output replay identified two bounded schema aliases: A02 used warning `sceneId: "null"`; A10 used severity `minor`. Both now normalize to canonical `null` and `info`, and their exact real outputs pass the validator locally. This projects Gemma to 16/20 but does not replace the measured 14/20 score. Three malformed JSON responses and one structurally empty project remain rejected.
- A loopback-only cross-model experiment kept Anna default for primary generation and hinted Gemma only for the single repair. It passed A02/A15 directly but failed A07 (`contract_invalid`) and A18 (`unknown`): 2/4, worse than Gemma-only 3/4. The uncommitted experiment was removed; production retains one user-selected preference for both calls.
- A fresh Gemma A06 reproduction ruled out a bounded syntax-only repair. The primary output was missing one final brace, but appending it still left characters, locations, scenes, score, and warnings absent. The model repair was valid JSON yet again omitted the production bible and all core arrays. Parser recovery must remain fail-closed because required creative structure cannot be inferred safely.
- A single A06 diagnostic using Anna's documented example hint `gpt-4o` produced no completion or model metadata. The UI recorded timeout while the harness request remained pending for more than six minutes and only window heartbeats continued. The server was stopped to terminate the orphaned request; do not retry this hint until Anna exposes model grants or fixes cancellation/deadline propagation.
- Reliability evidence is now a two-profile matrix: Anna default 16/20; Gemma preference 14/20. Both fail the 18/20 gate. No readiness, version cut, review, or release claim is permitted.
- An owner-authorized complete corpus rerun on 2026-08-27 used Anna default `minimax/minimax-m3` through OpenRouter and regressed to 6/20. Median successful duration was 49.13 seconds, p95 was 57.87 seconds, and 2 successful projects used repair. Privacy-safe failures were eight `json_invalid`, five `contract_invalid`, and one timeout. The complete private result remains ignored at `acceptance/results.2026-08-27.local.jsonl`. This stochastic regression does not justify weakening the contract or cutting a version; it reinforces the unresolved default-model reliability blocker.
- A second owner-authorized complete corpus rerun on 2026-08-27 used the advisory `gemma` hint and finished at 15/20. Median successful duration was 21.91 seconds, p95 was 41.92 seconds, and 6 successful projects used repair. Privacy-safe failures were A07/A10/A12/A19 `contract_invalid` and A20 `required_field_invalid`; there were no timeouts or JSON truncations. The private result remains ignored at `acceptance/results.2026-08-27.gemma.local.jsonl`. This improves the measured Gemma profile from 14/20 to 15/20 but remains below the 18/20 gate, so no readiness, version cut, review submission, or release claim is permitted.
- Future acceptance runs now classify schema, timestamp, duplicate, ordering, continuity-score, structure, and parent-scene reference failures with stable privacy-safe names. Unknown validation details still collapse to `contract_invalid`; generated content and private identifiers are never persisted in the public result.
- The privacy-safe diagnostic update is synchronized to Anna working draft revision 10. The 15-file, 104,031-byte bundle is ready with content hash `7d3edf2a89b942055c4af9d53b7dcfb6de1777e0437b27711b05bef09e2049b9`. The App remains a mutable draft with zero immutable versions; this synchronization is not an installation, review, or release claim.
- Read-only `apps grants storycore-harbour --json` currently returns `grants: null`. In CLI 0.1.30 this specifically represents a 404 from the informational grants endpoint (`no grants endpoint data available`), not evidence that the declared Host APIs were denied. Prior authenticated Host calls remain the capability evidence; do not use this null result to claim either a grant or a denial.
- Fresh Edge verification on 2026-08-28 passed the 520 × 680 generation/export flow, keyboard navigation, focus management, reduced-motion context, 400% text reflow, project reset/restore, and contract-valid export. The deletion smoke also passed sequentially with two ETag deletions, paginated listing, unrelated-key preservation, and a not-found reload. A new `browser:check` script fixes the intended sequential order because both smokes share one mock fixture stream.
- Edge now emulates `forced-colors: active` during the browser smoke and verifies visible keyboard focus, a non-colour selected-step outline, fully opaque dashed disabled controls, and a solid error boundary. The App also supplies forced-colour treatments for warning/success/error deletion states, armed destructive actions, and the continuity score. This automated evidence reduces risk but does not replace the remaining human Windows High Contrast and screen-reader passes.
- The forced-colour fix is synchronized to Anna working draft revision 11. Its 15-file, 104,890-byte bundle is ready with content hash `c5ddb6b3a45b42cebb3ceed713f65121ba3efac9808fece05aa05ad6ce863a17`; the App still has zero immutable versions and remains unpublished.
- Revision 11 demo evidence was regenerated locally in under twenty seconds: four visually inspected 900 × 820 PNGs plus a 3,288-byte contract-valid JSON export. The generated files remain ignored under `demo/output.local/revision-11/`; their sizes and one-run SHA-256 values are recorded in `demo/EVIDENCE_2026-08-28_REVISION_11.md`. The screenshot helper now resets every App scroll container before capture, fixing the measured missing-header defect on the World draft.
- Anna's public Developer Hub and pinned CLI schema were rechecked on 2026-08-29. They identify the Developer Console Listing tab as the metadata/media surface but expose no numeric screenshot or Marketplace-logo limits. Both available browser sessions required a fresh owner sign-in, so no authenticated field hints were claimed. `review/ANNA_MEDIA_REQUIREMENTS_REQUEST.md` contains the exact ready-to-send question; the 900 × 820 PNGs remain drafts and nothing was uploaded or submitted.
- Concurrent owner work on 2026-08-29 made the single repair prompt schema-complete: it now enumerates every required project, bible, entity, scene, shot, and continuity field; fixes the three-scene/one-shot shape; preserves exact source input; and still discards the failed response. The changes were merged without rewriting history and pass 67/67 Node tests, strict validation, the sequential Edge generation/export smoke, forced-colour assertions, and the ETag deletion smoke.
- The schema-complete repair prompt is synchronized to Anna working draft revision 12. Its 15-file, 107,699-byte bundle is ready with content hash `ad383957f123c1a2ea6c20e6ebb499f192f9ad161af4b0a9b0cc2bdb8e353fad`; the App remains an unpublished draft with zero immutable versions. No real-model run or quota consumption was performed for this synchronization.
- Authenticated Listing inspection on 2026-08-29 confirmed logo formats PNG/JPG/WebP/GIF, a 2MB maximum, and 256 × 256 cropping. Screenshot metadata remains one URL per line with no visible or HTML-enforced count, dimensions, aspect ratio, format, or byte limit. No field was changed and no asset was uploaded.
- A reproducible Marketplace logo candidate now renders from the committed SVG through Edge at `review/marketplace-media/storycore-harbour-logo-256.png`. It is 256 × 256, 5,302 bytes, SHA-256 `4a54e1955ac5ebe67eef8c82a260b1b1cdc351a7e87902f2bba2b15532cea7dd`, and passes PNG header, size, dimension, and representative-pixel validation. The first renderer attempt was correctly rejected after visual inspection exposed an unloaded black image; the renderer now embeds and decodes the SVG before capture.
- Authenticated Console inspection on 2026-08-29 confirmed working draft r12, bundle `ready`, content hash prefix `ad383957f123…`, and no version history. CLI status independently confirms `draft`, unpublished, and zero versions. The current Versions tab now exposes a distinct **Install & test** working-draft action, so an immutable cut is no longer assumed to be the only test path. It was not clicked. **View manifest** returned `Could not validate credentials`; this is recorded as a web-session/platform blocker rather than a bundle failure.
- A single instrumented **View manifest** reproduction produced the same credential message but no observable network event, HTTP status, or console error through the available browser diagnostics. Root cause remains unproven. `review/ANNA_VIEW_MANIFEST_CREDENTIAL_REPORT.md` contains privacy-safe steps, independent CLI evidence, the exact uncertainty boundary, and a ready-to-send support question; nothing was posted.
- After a fresh owner sign-in, **View manifest** succeeded and displayed the normalized working r12 manifest. It matches the committed Schema 2 Host-API-only boundary: no Executas, no top-level permissions, no external origins, one desktop view, `llm.complete`, App storage get/set/list/delete, `window.set_title`, self-only script CSP, and `last_writer_wins`. The credential incident is operationally resolved by reauthentication, while the exact token/frontend root cause remains unproven. No support message was sent.
- Installed Apps already contains StoryCore Harbour as `v0.0.0-dev`, so **Install & test** was not clicked again. Its read-only Permissions panel returns `Failed to load permissions: App version not found`. CLI status simultaneously confirms draft r12 has zero immutable versions and the grants endpoint exposes no data. The facts identify a dev-install/version-resolution blocker for permission management; they do not prove whether refresh, immutable cut, or server repair is the correct fix. `review/ANNA_DEV_INSTALL_PERMISSIONS_REPORT.md` contains the bounded support question, and nothing was sent or changed.
- Public Anna guidance rechecked on 2026-08-30 is internally ambiguous for this exact boundary: one guide moves installation/permissions after an immutable cut, another team response directs working-draft installation, and beta.126 excludes `0.0.0-draft` projections from release-candidate selection. The evidence is recorded in the permissions report and does not authorize a speculative reinstall or `0.1.0` cut.
- An owner-authorized complete corpus on 2026-08-31 used the advisory `gemma` hint after the schema-complete repair change. The connected Anna UI finished at 15/20, median 23.90 seconds, p95 44.00 seconds, and 7 repaired passes. Failures were HBR-A01 `unknown` after one transport `fetch failed`, plus HBR-A06/A08/A15/A20 `json_invalid`. Every malformed primary/repair response used `gemma-4-E4B-it` through Runpod, ended with `endTurn`, stayed between 1,269 and 1,722 output tokens, and ended with a closing brace; the remaining failures are internal JSON syntax errors rather than 4,096-token truncation. The score remains below 18/20, so no readiness, immutable cut, review, merge, or release claim is permitted.
- The iframe sandbox did not surface its Blob download to Browser automation. The private result was therefore recovered from the same run's RPC log: exactly 15 `projects/current` writes were matched to the immutable corpus, each recovered project passed the canonical contract, UI-displayed successful durations were retained at 0.1-second precision, and failure durations came from the sequential RPC timestamps. The canonical evaluator independently reproduced 15/20 and the same five privacy-safe failures. Ignored evidence remains at `acceptance/results.2026-08-31.gemma.recovered.local.jsonl`, `acceptance/harness.2026-08-31.gemma.local.log`, and companion local logs; generated content was not committed or posted.
- A private offline punctuation-recovery experiment made no model calls and never changed generated words. A bounded search of at most three edits from `{ } [ ] , :` recovered A08 and A15 with two edits each, so the best projected score was only 17/20. A06 remained unparsable after 28,876 bounded candidates. Closing A20's unbalanced JSON made it parse but left five canonical contract errors. There is no single bounded syntax rule that reaches the release gate, so the experimental helper was removed and production parsing remains fail-closed.
- Structured-output research on 2026-09-01 found that Anna documents `json_object`/`json_schema` for Executa `sampling/createMessage`, not for StoryCore's direct iframe `anna.llm.complete`. The pinned CLI 0.1.30 has no structured-output implementation; a read-only inspection of npm CLI 0.1.49 found negotiation only in the sampling bridge and still no direct Host API field. An Executa migration would violate the Host-API-only MVP boundary, and a current Cloud Agent report shows `json_schema` failures even with fallback. `review/ANNA_STRUCTURED_OUTPUT_REQUEST.md` contains the exact support question and a one-prompt gate; no package was upgraded and no model call was made.
- A 2026-09-05 refresh found no direct-Host structured-output update. CLI 0.1.51 still confines `response_format` negotiation to Executa sampling. Its enhanced read-only `apps grants` command also returned only `grants: null` for StoryCore, without the new `satisfied`/`missing` fields, matching the unresolved `v0.0.0-dev` permission-version gap. The newer CLI was executed ephemerally and not added to the project; no quota, grant, draft, version, or installation state changed.
- With explicit owner approval, one combined plain-text support email was sent to `hi@anna.partners` on 2026-09-05. It asks how to repair the existing `v0.0.0-dev` permission/version mismatch and whether direct iframe `anna.llm.complete` supports negotiated `json_object`/`json_schema`. It includes App id 214, slug, revision, privacy-safe 15/20 evidence, and the non-action boundaries; it contains no attachment, raw generated response, private JSONL, credential, or token. Do not send a duplicate while awaiting Anna's reply.
17 changes: 16 additions & 1 deletion apps/storycore-harbour/bundle/acceptance-failure.js
Original file line number Diff line number Diff line change
Expand Up @@ -20,12 +20,27 @@ export function publicFailureName(message, category) {
return "json_invalid";
}
if (value.includes("severity must be")) return "warning_severity_invalid";
if (value.includes("references unknown") || value.includes("unknown scene") || value.includes("unknown character")) {
if (
value.includes("references unknown") ||
value.includes("unknown scene") ||
value.includes("unknown character") ||
value.includes("not listed in the parent scene")
) {
return "reference_invalid";
}
if (value.includes("duration")) return "duration_invalid";
if (value.includes("schemaversion must be") || value.includes("project.format is unsupported")) {
return "schema_invalid";
}
if (value.includes("iso-compatible date-time")) return "timestamp_invalid";
if (value.includes("duplicate")) return "duplicate_invalid";
if (value.includes("must be a positive integer")) return "ordering_invalid";
if (value.includes("continuityreport.score")) return "continuity_score_invalid";
if (value.includes("required") || value.includes("must contain") || value.includes("must be a string")) {
return "required_field_invalid";
}
if (value.includes("must be an array") || value.includes("must be an object")) {
return "structure_invalid";
}
return "contract_invalid";
}
Loading
Loading