Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
528 commits
Select commit Hold shift + click to select a range
c7e961b
docs: record Dashboard worker follow-up evidence
Aug 26, 2026
c142c4e
Merge pull request #722 from ContextualWisdomLab/codex/pr640-http-tes…
seonghobae Aug 26, 2026
353dfd0
fix(ui): replace internal-boundary customer copy (#727)
seonghobae Aug 26, 2026
b3befa8
test(storybook): cover Global Ask next action (#730)
seonghobae Aug 26, 2026
c681a40
fix(api): keep recovery guidance customer-facing
Aug 26, 2026
ebfe60a
ops: capture worker cgroup memory evidence (#725)
seonghobae Aug 26, 2026
cede3ad
feat(leftover): persist leftover-map explained share (ADR 0232) (#728)
seonghobae Aug 26, 2026
bd73e0a
fix: pin validated structured workflow runtime (#711)
seonghobae Aug 27, 2026
1640ce0
feat: persist evidence-bound product relations (#742) (#776)
seonghobae Aug 28, 2026
5fd5096
test: match product project target identifier (#777)
seonghobae Aug 28, 2026
e365664
fix: prioritize evidence-bound operations backfill (#716)
seonghobae Aug 27, 2026
40d953f
docs: refresh dashboard repair snapshot
Aug 28, 2026
7db6af6
fix: isolate acceptance profiles and research copy
Aug 28, 2026
f5706e8
revert: keep measured compose profile boundary
Aug 28, 2026
2e558d3
docs: trace final dashboard repair review
Aug 28, 2026
afa8f4b
fix(frontend): localize operations dashboard copy
Aug 28, 2026
f68a0b2
test(frontend): verify dashboard locale switching
Aug 28, 2026
5138c7c
fix(frontend): localize dashboard code labels
Aug 28, 2026
1d8fcc7
fix(frontend): localize workspace navigation
Aug 28, 2026
5ea18ae
docs: refresh TEPP estimator evidence
Aug 28, 2026
09bf6ec
fix: stabilize source evidence response races
Aug 28, 2026
fd7de92
fix(frontend): remove mixed dashboard locale copy
Aug 28, 2026
959695d
fix(dashboard): close measurement and runtime acceptance gaps
Aug 28, 2026
e857c78
docs(gap): refresh exact repair snapshot
Aug 28, 2026
60150d8
fix(worker): continue bounded durable backfill
Aug 28, 2026
b2b46f4
docs(gap): bind durable continuation evidence
Aug 28, 2026
587a01a
fix(orchestrator): retain buildable Rust runtime pin
Aug 28, 2026
ef55c40
feat(orchestrator): scope endpoint routing selector
Aug 28, 2026
94cb65d
fix: keep externalized math boundaries fail closed
Aug 28, 2026
326773c
Merge remote-tracking branch 'origin/fix/propagate-pr716-dashboard-st…
Aug 28, 2026
e63b2a1
build: pin endpoint-aware orchestrator candidate
Aug 28, 2026
ddb3235
fix(seed): omit unavailable calibrated lineage
Aug 28, 2026
5ab8faf
Merge remote-tracking branch 'origin/fix/propagate-pr716-dashboard-st…
Aug 28, 2026
027fda0
build: advance endpoint-aware orchestrator pin
Aug 28, 2026
fdc3038
fix(frontend): keep mobile dashboard metrics readable
Aug 28, 2026
3d38f48
fix(frontend): keep mobile dashboard metrics readable
Aug 28, 2026
f038419
build(orchestrator): pin reviewed catalog expansion
Aug 28, 2026
e44be2f
Merge commit '3d38f48dd' into feat/orchestrator-routing-endpoint-cons…
Aug 28, 2026
d8d66f7
fix(orchestrator): declare gateway bootstrap seed
Aug 28, 2026
a4d6948
test(orchestrator): verify gateway startup expansion
Aug 28, 2026
29f4f8d
test(orchestrator): constrain startup proof to endpoint
Aug 28, 2026
56c1952
feat(dashboard): restack evidence operations on current main
Aug 28, 2026
3270c2b
fix(ui): describe project evidence as a customer action
Aug 28, 2026
902ade5
fix(compose): align orchestrator image provenance
Aug 28, 2026
83de508
test(make): follow the locked development environment
Aug 28, 2026
22fd1fe
fix(runtime): keep queue consumers in the worker service
Aug 28, 2026
4f899d5
fix(tests): exercise dedicated Ask and owner ranking evidence
Aug 28, 2026
9fbd616
fix(rankings): consume owner classic contribution envelope
Aug 28, 2026
97050c7
fix(telemetry): use maintained OTel log handler
Aug 28, 2026
61692c6
docs(product): align exact ownership and customer actions
Aug 28, 2026
824b77e
test(worker): make health fallback explicit
Aug 28, 2026
53ee2a5
fix(voice): render canonical process category
Aug 28, 2026
9b8cbbc
build(orchestrator): verify pinned runtime inputs
Aug 28, 2026
b1cce04
fix(i18n): translate Ask recovery actions
Aug 28, 2026
a72cd41
merge: restack dashboard repair onto current parent
Aug 28, 2026
0070cd2
fix: keep external lineage inference fail closed
Aug 28, 2026
9d917b1
fix(frontend): share canonical Voice labels
Aug 28, 2026
e19ca90
merge: synchronize reviewed dashboard parent
Aug 28, 2026
6f9b328
test: align repair stack with owner math boundary
Aug 28, 2026
bc8b1f3
fix(frontend): restore repair-stack contracts
Aug 28, 2026
3ddee07
test(frontend): align locale-aware navigation
Aug 28, 2026
4982455
docs: correct commercial automation gap evidence
Aug 28, 2026
f0bc98e
fix(dashboard): limit hidden evidence retry facts
Aug 28, 2026
572ef39
merge: synchronize final dashboard parent repair
Aug 28, 2026
f27f427
docs: refresh exact repair-stack snapshot
Aug 28, 2026
7ef8971
merge: restack endpoint consumer onto dashboard repair
Aug 28, 2026
a8b9199
docs: align source research citations with ADR 0268
Aug 28, 2026
8f07eba
merge: refresh endpoint consumer parent evidence
Aug 28, 2026
df22c62
feat: expose post source research in detail view
Aug 28, 2026
5369257
merge: expose source research through endpoint consumer stack
Aug 28, 2026
94927d1
fix: keep private source research actions unavailable
Aug 28, 2026
ee49208
merge: preserve private source research boundary
Aug 28, 2026
2c55d6b
test: preserve dashboard and Ask runtime evidence flows
Aug 28, 2026
3c59742
fix: bind runtime Ask evidence to real corpus and token expiry
Aug 28, 2026
d146a57
test: derive Ask acceptance budget from operator input
Aug 28, 2026
b87b186
fix: preserve public research retry after citation load failure
Aug 28, 2026
c151027
merge: preserve public source research retry
Aug 28, 2026
33da29e
docs: refresh final stacked PR evidence
Aug 28, 2026
fe4077f
fix(orchestrator): install pinned Rust token packer
Aug 28, 2026
84aff39
fix(runtime): verify exact image revisions
Aug 28, 2026
5df8227
fix(runtime): require MCP acceptance profile
Aug 28, 2026
41faae0
fix(runtime): use bounded readiness jobs
Aug 28, 2026
ee9f70b
fix(orchestrator): drop local embedding selector
Aug 28, 2026
760d058
fix(orchestrator): preserve deployment routing
Aug 28, 2026
bdd7531
fix: restore exact PR #716 Dashboard delivery slice (#778)
seonghobae Aug 28, 2026
8998c87
feat(ask): persist public claim admission (#784)
seonghobae Aug 28, 2026
17520eb
fix(runtime): honor orchestrator admission cadence
Aug 28, 2026
360d87e
perf(post-content): bound the ordered backfill scan
Aug 28, 2026
5deeada
merge: align successor with dashboard parent
Aug 28, 2026
640cc55
build(orchestrator): advance admission contract pin
Aug 28, 2026
e9e2508
fix(migrations): give backfill index a unique ordinal
Aug 28, 2026
31e1013
fix(runtime): accept resumed content ledgers
Aug 28, 2026
bcd7b8e
Merge pull request #785 from ContextualWisdomLab/perf/post-content-ba…
seonghobae Aug 28, 2026
02df59b
fix(provenance): reject ambiguous claim bindings
Aug 28, 2026
661eca2
Merge branch 'feat/orchestrator-routing-endpoint-consumer' of https:/…
Aug 28, 2026
d766131
fix(runtime): execute resumed-ledger SQL through stdin
Aug 28, 2026
16db1ad
fix(dashboard): localize evidence actions and verify interaction modes
Aug 28, 2026
ec4b219
Merge remote-tracking branch 'refs/remotes/origin/pr-786-latest' into…
Aug 28, 2026
a04c028
test(dashboard): keep story guidance customer-facing
Aug 28, 2026
b4b00cd
Merge pull request #788 from ContextualWisdomLab/codex/dashboard-ui-c…
seonghobae Aug 28, 2026
b4b03ab
fix(runtime): pin structured-ready orchestrator (#789)
seonghobae Aug 28, 2026
97b241a
fix(runtime): retain partial readiness evidence (#790)
seonghobae Aug 28, 2026
23134fb
feat(dashboard): produce topic influence evidence
Aug 28, 2026
8df36e7
Merge remote-tracking branch 'origin/feat/orchestrator-routing-endpoi…
Aug 28, 2026
d6ed152
feat(journey): admit digest-bound temporal evidence
Aug 28, 2026
f050994
fix(journey): bind temporal evidence to view cutoff
Aug 28, 2026
20052d1
Merge pull request #791 from ContextualWisdomLab/feat/project-journey…
seonghobae Aug 28, 2026
093aa52
fix(dashboard): harden topic influence delivery
Aug 28, 2026
061d074
Merge remote-tracking branch 'origin/feat/orchestrator-routing-endpoi…
Aug 28, 2026
7bc1d71
fix(schema): keep topic job migration ordered
Aug 28, 2026
ae2bf1b
fix(dashboard): count cited case events only
Aug 28, 2026
81413c5
Merge commit '20052d1ec325f95344370c6b08d2812b7b03ba57' into feat/cas…
Aug 28, 2026
53e7306
fix(worker): prevent backfill wake-up starvation
Aug 28, 2026
57ad036
fix(schema): validate UUID provenance bindings
Aug 28, 2026
6852d1d
Merge pull request #793 from ContextualWisdomLab/feat/case-specific-e…
seonghobae Aug 28, 2026
e609fe4
fix(dashboard): align event evidence visibility
Aug 28, 2026
d76a2f7
Merge pull request #795 from ContextualWisdomLab/fix/case-event-evide…
seonghobae Aug 28, 2026
a0a4919
Merge remote-tracking branch 'origin/feat/orchestrator-routing-endpoi…
Aug 28, 2026
8ff5ca6
fix(dashboard): scope events to visible cases
Aug 28, 2026
5933d55
Merge pull request #796 from ContextualWisdomLab/fix/case-event-visib…
seonghobae Aug 28, 2026
1f980cb
Merge remote-tracking branch 'origin/feat/orchestrator-routing-endpoi…
Aug 28, 2026
6afdb14
Merge commit '5933d555616eefc140acfc06cf7262c48ed7d386' into fix/post…
Aug 28, 2026
fe31db8
fix(worker): classify construct failures separately
Aug 28, 2026
8eb99bf
fix(worker): enforce one durable consumer
Aug 28, 2026
f783572
fix(worker): bound outage wake-up retention
Aug 28, 2026
8981c13
fix(ui): localize dashboard next actions
Aug 28, 2026
5cb3c99
fix(worker): fence recovery publication and shutdown
Aug 28, 2026
f0f9a18
fix: harden topic influence admission lifecycle
Aug 28, 2026
2563c90
Merge pull request #794 from ContextualWisdomLab/fix/post-content-rec…
seonghobae Aug 28, 2026
e2601e3
docs: record topic influence lifecycle evidence
Aug 28, 2026
2bb846d
Merge latest topic dashboard base into influence producer
Aug 28, 2026
c75a5a4
feat(product): add governed catalog provisioning
Aug 28, 2026
387ee0f
fix(worker): order recovery by eligibility time
Aug 28, 2026
930e1fe
fix: bind influence transport to exact artifact bytes
Aug 28, 2026
8d6489f
Merge pull request #797 from ContextualWisdomLab/fix/effective-eligib…
seonghobae Aug 28, 2026
f5c24ce
Merge recovery scheduler fix into influence producer
Aug 28, 2026
f870373
fix: reserve declared topic persistence lease
Aug 28, 2026
88b8441
fix: isolate and fence topic influence leases
Aug 28, 2026
5f2d3d4
fix: complete topic lease recovery fencing
Aug 28, 2026
16b708d
fix(ci): document bounded explain query
Aug 28, 2026
7f6e151
fix: requeue withdrawn topic evidence
Aug 28, 2026
7954661
fix: wake topic admission on provenance changes
Aug 28, 2026
d319649
fix: clear reclaimed topic request identity
Aug 28, 2026
605d11b
fix: reject partial topic provenance
Aug 28, 2026
f73f078
fix: validate optional topic endpoint
Aug 28, 2026
f775d04
fix: localize analysis run next actions
Aug 28, 2026
1e44efa
fix: bound topic admission state transitions
Aug 28, 2026
ed257cf
fix: keep lifecycle next action available
Aug 28, 2026
43418f7
fix: bind influence to posterior projection
Aug 28, 2026
67fec39
fix: close topic evidence admission race
Aug 28, 2026
18e8253
fix: release all incomplete topic evidence
Aug 28, 2026
f72fa74
Merge pull request #792 from ContextualWisdomLab/feat/topic-influence…
seonghobae Aug 28, 2026
f80c13f
Merge remote-tracking branch 'origin/feat/orchestrator-routing-endpoi…
Aug 28, 2026
3ea01ff
fix: preserve dashboard and claim admission counts
Aug 28, 2026
0c43065
Merge remote-tracking branch 'origin/feat/orchestrator-routing-endpoi…
Aug 28, 2026
0881368
test(product): assert catalog identity linkage
Aug 28, 2026
e907df7
Merge pull request #786 from ContextualWisdomLab/feat/orchestrator-ro…
seonghobae Aug 28, 2026
8b8a818
Merge remote-tracking branch 'origin/feat/dashboard-case-metrics' int…
Aug 28, 2026
1333652
test(dashboard): avoid dynamic regex matcher
Aug 28, 2026
ff33502
fix(product): admit browser provisioning replay
Aug 28, 2026
157e704
Merge remote-tracking branch 'origin/feat/dashboard-case-metrics' int…
Aug 28, 2026
c71e55a
fix(product): validate catalog levels at boundary
Aug 28, 2026
51e6f2f
fix(product): localize catalog next actions
Aug 28, 2026
56e95f1
fix(product): reject invalid catalog text
Aug 28, 2026
fa816d3
Merge pull request #798 from ContextualWisdomLab/feat/governed-produc…
seonghobae Aug 28, 2026
2ff1ebd
style: clear exact-head static findings
Aug 28, 2026
183b355
style: clear catalog protocol findings
Aug 28, 2026
1d24cd4
perf(dashboard): avoid misplanned eligibility scans
Aug 31, 2026
a18cc99
perf(reads): establish twenty millisecond latency contract
Aug 31, 2026
3e183d9
perf(auth): resolve read scope in one query
Aug 31, 2026
57519f2
test(performance): gate reads at twenty milliseconds
Aug 31, 2026
1b8341a
perf(database): remove measured jit startup cost
Aug 31, 2026
61ecefa
Merge remote-tracking branch 'origin/main' into HEAD
Aug 31, 2026
9c6a6a5
test(dashboard): follow customer-facing influence heading
Aug 31, 2026
789ae00
test(dashboard): restore locale runtime acceptance
Aug 31, 2026
4703fe0
fix(dashboard): keep runtime screenshots on dashboard
Aug 31, 2026
c5da909
feat(dashboard): bound evidence reads and rankings
Aug 31, 2026
51cedbf
perf(search): project bounded post evidence
Aug 31, 2026
01b20e4
fix(orchestrator): preserve runtime provider allowlist
Aug 31, 2026
fa1101d
fix(review): clarify dashboard worker paths
Aug 31, 2026
48351f3
fix(ontology): close source-bound SHACL gaps
Aug 31, 2026
9ad662d
fix(search): limit projection refresh triggers
Aug 31, 2026
0849c9d
docs(gaps): record exact ontology and latency evidence
Aug 31, 2026
f97af17
test(embedding): inspect caller model boundary
Aug 31, 2026
5865774
fix(orchestrator): defer exhausted structured routes
Aug 31, 2026
0e7f9ba
fix(database): avoid replaying post projections
Aug 31, 2026
4a2d8c0
fix(database): bound projection migration replay
Aug 31, 2026
59432e8
perf(search): split indexed candidate branches
Aug 31, 2026
b9e36c1
docs(gaps): record exact-head runtime evidence
Aug 31, 2026
5ae36e5
test(load): cover authenticated post search
Aug 31, 2026
e339e54
test(load): identify read latency by route
Aug 31, 2026
707d9c2
docs(gaps): retain tagged k6 evidence
Aug 31, 2026
c52ad5b
feat(ontology): declare dashboard evidence vocabulary
Aug 31, 2026
db41a3e
docs(gaps): record exact dashboard acceptance
Aug 31, 2026
5869cba
docs(gaps): refresh open delivery queue
Aug 31, 2026
7ac1b07
fix(backfill): bound terminal recovery pages
Aug 31, 2026
fe31937
docs(gaps): refresh dashboard delivery evidence
Aug 31, 2026
c260b12
fix(runtime): pin provider-backed orchestrator replacement
Aug 31, 2026
140c22e
fix(import): accept governed Voice taxonomy
Aug 31, 2026
d56efa3
fix(runtime): verify public Rust token packer contract
Aug 31, 2026
8b0b82d
fix(ontology): ship dashboard vocabulary in runtime package
Aug 31, 2026
190543d
fix(runtime): pin accepted orchestrator contracts
Aug 31, 2026
a28dc34
fix(dashboard): align governed milestone labels
Aug 31, 2026
260340a
fix(dashboard): separate milestone time and label
Aug 31, 2026
fa23446
build(orchestrator): pin accepted structured runtime
Aug 31, 2026
ec53dc2
fix(frontend): keep buyer copy implementation-neutral
Aug 31, 2026
097bb19
docs(backfill): record serial throughput boundary
Aug 31, 2026
60dadee
fix(postgres): revalidate tuning restart evidence
Aug 31, 2026
cd49749
fix(dashboard): retain explicit project codes
Aug 31, 2026
2481bf5
fix(ask): guide empty evidence queries
Aug 31, 2026
b7dbd44
docs(gaps): refresh project and Ask evidence
Aug 31, 2026
0c6d5ff
fix(worker): reset health baseline across boots (#894)
seonghobae Aug 31, 2026
450d42f
fix(customers): keep placeholder hints unbound
Aug 31, 2026
bd320ac
feat(voice): derive receipt-bound classifications
Aug 31, 2026
6ef7d81
fix(voice): preserve independent stages during admission defer
Aug 31, 2026
06f233a
fix(runtime): preflight orchestrator credentials before promotion
Aug 31, 2026
74bf668
fix(runtime): inspect configured candidate image
Aug 31, 2026
4516ace
fix(product): decouple receipt-bound extraction from operations
Aug 31, 2026
797d188
fix(product): fence concurrent evidence replacement
Aug 31, 2026
a5a2493
docs: refresh exact runtime gap baseline
Aug 31, 2026
041f352
docs: clarify governed evidence recovery
Aug 31, 2026
68e4934
fix(worker): bind probes to process epochs (#895)
seonghobae Aug 31, 2026
ab43df4
docs(performance): record failed ASGI latency evidence
Aug 31, 2026
1788082
feat(dashboard): open evidence-bound project history (#896)
seonghobae Aug 31, 2026
f40e4ed
docs(gaps): refresh dashboard stack evidence
Aug 31, 2026
5c430d4
fix(worker): supervise post content liveness
Sep 1, 2026
f7099a4
test(frontend): avoid dynamic locale regex
Sep 1, 2026
3d003db
fix(orchestrator): pass configured provider allowlist
Sep 1, 2026
adccfb7
chore(orchestrator): pin endpoint routing candidate
Sep 1, 2026
cbceb97
fix(orchestrator): verify candidate before promotion
Sep 1, 2026
fb897fb
fix(orchestrator): preserve Responses session contract
Sep 1, 2026
046ef4a
docs(gaps): record endpoint-scoped runtime proof
Sep 1, 2026
9ce838e
chore(orchestrator): repin side-effect-free endpoint validation
Sep 1, 2026
56da9d2
docs(gaps): record latency and WAL evidence
Sep 1, 2026
b04fcab
test(compose): isolate runtime selector environment
Sep 1, 2026
fd14c75
fix(frontend): restore mobile touch targets
Sep 1, 2026
7c02c37
docs(gaps): record mobile interaction acceptance
Sep 1, 2026
4bc64ab
chore(orchestrator): integrate endpoint and prompt contracts
Sep 1, 2026
37dbb12
test(valkey): isolate integration broker state
Sep 1, 2026
86b8145
chore(orchestrator): pin current PR 990 head
seonghobae Sep 1, 2026
006efe7
docs(product): make dashboard acceptance authoritative
Sep 1, 2026
eb4c800
docs(gaps): refresh exact dashboard delivery evidence
Sep 1, 2026
51ab461
fix(worker): keep Global Ask independent from backfill
Sep 1, 2026
88e3e46
docs(product): record independent Ask runtime evidence
Sep 1, 2026
c4d13aa
perf(api): compress evidence-rich responses
Sep 1, 2026
615ee2d
perf(api): favor low-latency gzip
Sep 1, 2026
37cfc94
fix(api): retain measured gzip default
Sep 1, 2026
c47cabe
docs(product): record negotiated dashboard latency
Sep 1, 2026
1bf978e
docs(product): refresh exact-head latency evidence
Sep 1, 2026
135d894
merge(main): converge dashboard root onto current protected head
seonghobae Sep 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 2 additions & 1 deletion .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,8 @@ MCP_RATE_LIMIT_WINDOW_SECONDS=
# running contextual-orchestrator to turn the channels on.
ORCHESTRATOR_BASE_URL=
ORCHESTRATOR_API_KEY=
SOURCE_RESEARCH_MAXIMUM_LEADS=
SOURCE_RESEARCH_MAXIMUM_RESULTS=

# GitHub workflows inject the canonical provider names from masked secrets.
# Non-GitHub Compose runs also accept the operator's ~/.env compatibility
Expand All @@ -49,7 +51,6 @@ LLM_GATEWAY_API_URL=
# Compatibility alias; LLM_GATEWAY_API_URL wins when both are set.
LLM_GATEWAY_URL=
LLM_GATEWAY_API_KEY=
LLM_GATEWAY_EMBEDDING_MODEL=
LLM_API_GATEWAY=
LLM_API_KEY=
CALDAV_BASE_URL=
Expand Down
36 changes: 34 additions & 2 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,14 @@ documents unless an ADR explicitly promotes a decision from them --
to its governing ADR. Update research notes as literature changes; never
use them to introduce an untracked architecture decision.

Customer-facing copy must help the reader take the next product action. Do
not expose implementation boundaries, provider or package names, schema
versions, internal status or reason codes, environment variables, transport
setup, hashes, or developer remediation instructions as explanatory UI copy.
Keep that evidence in governed audit and administrator surfaces and logs;
translate a customer-visible state into the source, decision, retry, or
administrator action the reader can actually take.

## Hard rule: no real data in repository artifacts

This repository ships **synthetic fixtures only** (`lineageweave/fixtures.py`)
Expand Down Expand Up @@ -188,8 +196,10 @@ contextual-orchestrator owns model discovery and selection.

`NullEmbeddingClient`, `NullAdjudicationClient`,
`NullKeymanExtractionClient`, `NullEntityRelationshipClient`,
`NullPostSummaryClient`, `NullPostChatClient`, and
`NullCommitmentExtractionClient` (and any new channel client you add)
`NullPostSummaryClient`, `NullPostChatClient`,
`NullCommitmentExtractionClient`, `NullRelationVerificationClient`,
`NullClaimVerificationClient`, and `NullSourceResearchClient`
(and any new channel client you add)
must set `available = False` and make their channel dropped +
renormalized (`reconstruct.active_weights`), never silently return a
placeholder score, invented Keyman, guessed relationship, fabricated
Expand All @@ -202,6 +212,14 @@ adjudication does -- never a raw LLM API. Demo TEPP seed goes through
envelope is Failed (`tepp_not_available` / `tepp_result_not_persisted`),
never a fabricated theta or a local psychometric substitute.

Public source-reference research (ADR 0274) is a post-scoped write action
on existing semantic units or image regions. Only `visibility_code=public`
posts may send lead text to SearXNG or retrieve a result URL. Private posts
fail closed without egress. Redirects and non-global targets are rejected.
Unavailable search, retrieval, or adjudication is `research_unavailable`,
never a fabricated supported/refuted judgment. Global Ask public
verification (ADR 0215) still never fetches result URLs.

The lineage `text` channel follows [ADR 0190](docs/adr/0190-lineage-text-channel-embedding-swap.md):
when an embedding provider is configured, `reconstruct()` precomputes
batched label embeddings once per reconstruction and scores cosine
Expand Down Expand Up @@ -237,6 +255,20 @@ vector degrades that pair back to difflib; it never fabricates a score.

## Tests

### Isolated Compose lifecycle

- The canonical standalone Compose project is `lineageweave` (ADR 0224).
- A test, review, or stacked-PR environment may use an explicit isolated
project name only while that environment is needed. Once its stated test or
review objective has succeeded, preserve the relevant evidence and port any
required behavior into the canonical Compose contract, then run `docker
compose -p <exact-project> down` so its containers and network do not become
a second production-looking stack.
- Never use `down -v` or otherwise delete named volumes without separate,
explicit authorization. Resolve the exact project from Compose labels before
cleanup; never target a glob, directory root, or another agent's active
environment.

```bash
# backend extra compiles fast-mlsirm's PyO3 core -- needs rustc 1.97.1
# (see backend/Dockerfile). Without it, pip falls over at build time.
Expand Down
39 changes: 38 additions & 1 deletion ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -67,7 +67,7 @@ flowchart LR
| `models.py` | `Record`, `Edge`, `Tree` -- source-agnostic data shapes |
| `channels.py` | Independent `[0, 1]` scoring functions |
| `chunking.py` | Splits a document into meaning-identifiable units (paragraph, sentence, DOM, conversation-turn) plus embedded-image extraction, in document order |
| `embedding_client.py` | Pluggable text-embedding channel (`Null` default, `OpenAiCompatible` real impl) + `chunked_max_similarity` |
| `embedding_client.py` | Provider-neutral contextual-orchestrator embedding transport and strict vector-envelope validation; no local similarity arithmetic |
| `adjudication_client.py` | Pluggable LLM-judgment channel (`Null` default, `ContextualOrchestrator` real impl) |
| `image_content.py` | Pluggable vision channel: OCR + object recognition/tagging for embedded images (`Null` default, `OpenAiCompatibleVisionClient` real impl). The product popup (`frontend/src/PostBody.tsx`) renders each `data:image` payload in document order so the buyer sees the picture, not the base64 string; GET does not call the vision client. |
| `tepp_client.py` | TEPP's published `AnalysisRunRequest` wire contract, pluggable transport |
Expand Down Expand Up @@ -172,6 +172,10 @@ real-provider LLM tests).
provider (`docker/keycloak/realm-export.json` seeds a `lineageweave-demo`
realm with synthetic demo accounts carrying `corp_code` / `pu_code` as
custom token claims -- see [README](README.md#local-product-stack-docker-compose)).
ADR 0224 fixes the default project name to `lineageweave` and keeps the
migration, SearXNG, contextual-orchestrator, backend, worker, and frontend in
that same project. Test stacks use an explicit disposable `-p` name; they never
replace a canonical service with a container built from another worktree.
`scripts/smoke_test_oidc.py` proves the round-trip is real: it logs in as
the synthetic demo user, fetches Keycloak's live JWKS, and cryptographically
verifies the returned JWT's RS256 signature rather than just checking for an
Expand Down Expand Up @@ -462,6 +466,14 @@ name, confirmed the events on the activity endpoint, and independently
confirmed the stream's existence and length with `valkey-cli` directly
against the `valkey` container.

Post-content ingestion uses the same transport with a stronger durability
boundary (ADR 0098): PostgreSQL owns each job and Valkey only wakes the worker.
`POST /api/post-content/backfill` is a `post_admin`-gated producer for one
1--200-row eligible page. It commits jobs before publishing, returns HTTP 202
without running semantic providers, and reports wake-ups that the worker's
bounded recovery sweep must republish. `FOR UPDATE SKIP LOCKED` partitions
concurrent operator calls without a second scheduler or an in-memory task.

## Phase 5c: customer commitment derivation and the calendar

The brief asked for two separate-sounding things: issues auto-registered
Expand Down Expand Up @@ -805,6 +817,18 @@ HTML-wrapped, base64-image-embedded version of the existing
people through the live `/extract-keymen` endpoint
(`test_extract_keymen_normalizes_html_and_embedded_image_content`).

## Evidence-operations lifecycle projection

ADR 0206's Dashboard persists a semantic classification separately from its
facts and observed milestones. `operations_case_milestone` binds a closed XES-
style activity code to an exact evidence span, evidence-post digest, observed
instant, and named source clock; `operations_case_missing_milestone` records an
unsupported required endpoint without fabricating one. The Dashboard pairs
only the three declared start/end definitions for claim investigation, rebid
response, and handover. Both endpoints yield `end - start`; a cited start plus
a missing end is open with nullable elapsed time. API projection rechecks
current ABAC for focal and evidence posts before returning either span.

## Phase 6d: external search verification for Ontology relation inferences

The brief requires an external web/internal search agent to check the
Expand Down Expand Up @@ -854,6 +878,19 @@ against a deliberately fabricated one in the same request, asserting
the former comes back `verify_corroborated` with a real evidence URL
and the latter `verify_uncorroborated` with none.

## Phase 6e: post-scoped source-reference research

Issue #611's remaining ADR 0133 criterion is a different workflow from
relation verification and from Global Ask snippet verification (ADR 0215).
A public post may send an existing semantic unit or image-region excerpt
to self-hosted SearXNG, retrieve one cited public page under SSRF and
redirect rejection, and ask contextual-orchestrator to judge in
`mode="verify"`. Private posts fail closed without egress. Citations
persist to `source_research_citation` (migration 0236, ADR 0274). The
reader next action is to open the cited public resource and compare it
with the highlighted passage or image detail. Global Ask still never
fetches result URLs.

## Phase 7: R&R's named actor is a PROV-O Agent, not always a person

`post_summary.py`'s R&R extraction forced every named actor into a
Expand Down
17 changes: 17 additions & 0 deletions CHANGELOG.d/2.19.0-post-scoped-source-reference-research.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# 2.19.0 — Post-scoped source-reference research

## Added

- Public posts can research a highlighted passage or image detail against a
cited public page (ADR 0274, remaining ADR 0133 / issue #611). The workflow
reuses self-hosted SearXNG, retrieves one public HTTP(S) target with
redirects disabled and non-global addresses rejected, and judges through
contextual-orchestrator `mode=verify`. Private posts fail closed without
egress. Deployments must set both source-research resource budgets explicitly;
otherwise the channel remains unavailable. Citations persist in 3NF
`source_research_citation`.
- Reader next action: open the cited public resource, then compare it with
the highlighted passage or image detail. Supported or refuted judgments
without a cited URL downgrade to not enough information. Missing search,
retrieval, or adjudication is `research_unavailable`, never a fabricated
score.
2 changes: 1 addition & 1 deletion CHANGELOG.d/2.20.0-backend-contract-regressions.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
### Fixed

- Restored the runtime-only TEPP credential setting, kept API integration fixtures collision-free, aligned asynchronous Ask tests with semantic retrieval, replaced deprecated FastAPI 422 constants, and moved Starlette integration tests to its supported `httpx2` transport.
- Restored the runtime-only TEPP credential setting, kept API integration fixtures collision-free, aligned asynchronous Ask tests with semantic retrieval, replaced deprecated FastAPI 422 constants, moved Starlette integration tests to its supported `httpx2` transport, and adopted the SPDX license expression required by current packaging metadata.
5 changes: 5 additions & 0 deletions CHANGELOG.d/2.21.2-orchestrator-promotion-preflight.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
### Fixed

- Fail closed before recreating the canonical contextual-orchestrator when the
exact candidate cannot authenticate a structured-capable model through the
currently configured gateway endpoint.
81 changes: 80 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,71 @@ All notable changes to this project are documented here. Format follows

## [Unreleased]

### Added
- Evidence-rich API responses now use standard HTTP gzip content negotiation,
and the Dashboard k6 gate requires and verifies that negotiated transfer.
The exact payload measured 96,415 bytes uncompressed and 10,282 bytes on the
wire; its 130.43 ms five-VU maximum keeps the 20 ms release gate open
(ADR 0272).

- Global Ask now has a consumer-selective durable worker in the canonical
Compose project. Per-consumer PostgreSQL advisory leases prevent overlapping
queue owners, while stopping post-content consumption no longer suspends Ask
or starts any post-content recovery from the Ask worker (ADR 0279).

- Post-content recovery now keys every initial attempt, retry, and stale lease
by its exact eligibility instant, so work that becomes due after the durable
cursor advances is reached without waiting for a full ledger wrap.

- Global Ask public verification now admits only bounded, provenance-bearing
persisted claims attached to exact cited public posts; missing admission
fails closed without token-overlap egress.

### Added

- Product extraction now uses a strict receipt-bearing orchestrator schema,
revalidates the focal source and complete typed-target digest under a shared
replacement lock, and continues after an independent operations-stage
failure. Typed operations/project targets are admitted only from current
evidence-bearing assertions; catalog misses remain misses without guessed
identities, and a later admission delay cannot hide an ordinary stage
failure (ADR 0228).

- Derived Voice classification now uses one strict contextual-orchestrator
receipt over the exact focal Post body, admits all twelve governed Voice
concepts as evidence-supported multi-label assertions, and preserves the
imported source category separately. Exact spans and source digests fail
closed; valid empty results retain a completion receipt, and operations-case
failures no longer suppress the independent Voice stage (ADR 0244).

- Governed product-catalog provisioning now accepts only explicit product
master rows with authorized source-record provenance, a canonical payload
digest, and source-linked aliases. Replays are idempotent, contradictory
definitions fail closed, and unresolved Post evidence tells the reader the
next catalog action without creating identities from model output, keywords,
fuzzy matches, or generic source categories.

- Temporal topic influence now has a durable external-production path: the
worker binds the exact completed TEPP artifact, posterior draws, and
business-unit/PU/team/person memberships into a content-addressed request,
then persists only a complete, converged, identified, parity-passed
fast-mlsirm result. Missing owner transport, partial rows, or digest mismatch
remains unavailable without local scoring. Time-valid membership slices
remain distinct; incomplete evidence enters an event-woken awaiting state;
expired work is reclaimed only from its declared request/lease contract,
whose lease must strictly exceed the request timeout for persistence; and
every terminal transition matches a unique lease token. Evidence changed
during computation releases a fresh request automatically.
LineageWeave-owned request and membership bytes and producer-owned result
bytes are SHA-256 verified before parsing, so admission never depends on
cross-language JSON reserialization. Other
retries use only an exact remote delay or an explicit operator requeue
(ADR 0210).

- Evidence Operations now presents cited claim, rebid, handover, external,
product, and Voice evidence with explicit unavailable states and source-open
actions. Durable analysis and bounded backfill run only in the dedicated
backend worker, while the web process remains responsive; topic-context
results fail closed when their authorized provenance is incomplete.

- Period leftover pairs now caption leftover-map graphic-display pair
segments with persisted leftover-map distance `d` (ADR 0271 /
Expand Down Expand Up @@ -268,6 +332,21 @@ All notable changes to this project are documented here. Format follows

### Fixed

- Product requirement identifiers are now unique and authoritative; duplicated
occupational-taxonomy sections were consolidated without changing their
evidence, measurement, or provider boundaries.
- Public-claim provenance validation now selects its sole UUID binding without
calling PostgreSQL's unavailable `min(uuid)` aggregate, so fresh schema
replays accept valid provenance-bound public claims.
- Post-content wake-up recovery now advances through every ready ledger page
with a deterministic keyset, while Valkey trims only entries already
consumed by the worker. Large backfills can no longer replay the same first
page until a later queued record starves or its unread wake-up is trimmed.
- Post-content ingestion now keeps its bounded Valkey reader and durable-ledger
recovery sweep live while the single provider pipeline awaits a slow
structured operation. Provider work remains serial; PostgreSQL claim and
expected-attempt fencing, restart recovery, and the existing retry budget are
unchanged (ADR 0098).
- Full-corpus Event Lineage rebuilds now count candidate pairs before provider
work and omit the optional LLM channel above the 5,000-pair ADR budget,
preventing millions of synchronous orchestrator calls while retaining one
Expand Down
4 changes: 2 additions & 2 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

# Keep provider credentials outside the repository. Compose interpolation must
# read the same home env file as the orchestrator container's env_file.
COMPOSE := docker compose --env-file "$$HOME/.env"
COMPOSE := COMPOSE_FILE=docker-compose.yml docker compose --env-file "$$HOME/.env"

up:
$(COMPOSE) up -d
Expand All @@ -21,7 +21,7 @@ ps:
# Keycloak's live JWKS, and asserts the corp_code/pu_code claims. See
# scripts/smoke_test_oidc.py.
smoke:
uv run --locked python scripts/smoke_test_oidc.py
uv run --locked --extra dev python scripts/smoke_test_oidc.py

# Seeds synthetic corp/account/post rows keyed to the actual Keycloak demo
# users' real subject ids, plus Valkey ticket_created events so Activity
Expand Down
21 changes: 21 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -123,6 +123,16 @@ compatibility aliases only. `ORCHESTRATOR_BASE_URL` and
`ORCHESTRATOR_API_KEY` are separate, internal
LineageWeave-to-orchestrator settings.

The Compose file declares `lineageweave` as its canonical default project, so
the same eight-service synthetic stack is addressed from the repository and
temporary worktrees. Isolated tests may override it explicitly with `-p`; use
`docker compose down` without `-v` when retiring such a project so its named
volumes remain recoverable (ADR 0224).
The bundled Keycloak realm is the standalone/local/dev/test fallback only.
Setting `KEYVERSE_ISSUER` selects central Keyverse for both backend and
frontend and activates the fail-closed claim binding in ADR 0156; the two
issuers are never combined as authorization authorities.

Postgres and Keycloak are built (`docker/postgres-init/`, `docker/keycloak/`)
rather than bind-mounted, so the keycloak database's init script and the
realm seed ship inside the images themselves -- portable to any Docker host
Expand All @@ -148,6 +158,12 @@ no re-typed copy.
`backend/` is a FastAPI app talking directly to that database (`asyncpg`,
no ORM, no file DB) and to Keycloak's live JWKS for OIDC verification:

The API does not consume durable jobs. Canonical Compose makes `backend`
depend on the progress-healthy `backend-worker`, so `docker compose up backend`
starts both. Any non-Compose deployment must co-deploy
`python -m backend.app.worker` and gate API readiness on that worker service;
`/healthz` is process liveness only.

```bash
make up
make seed # scripts/seed_demo_data.py: inserts synthetic corp/account/post
Expand All @@ -168,6 +184,11 @@ docker compose --profile mcp up mcp
# Streamable HTTP resource: http://localhost:18001/mcp
```

For client initialization, tool arguments, durable status handling, and quota
recovery, see the [MCP manual](docs/manuals/mcp-manual.md). Workspace users can
start with the [user guide](docs/manuals/user-guide.md); deployment and incident
procedures are in the [operations manual](docs/manuals/operations-manual.md).

`GET /api/posts`, `GET /api/posts/{post_id}`,
`GET /api/posts/{post_id}/keymen`, `GET /api/keymen/{person_id}/related`,
`GET /api/posts/{post_id}/affiliate-tree`,
Expand Down
Loading
Loading