Replace the billed_model_usage_from_llm_with_cost wrapper with a
with_reported_cost method on BilledModelUsage and BilledTokenCounts, and
centralize the optional-cost fold as UsdMicros::accumulate so fabro-agent
and fabro-workflow share one implementation.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Add Poolside as a built-in OpenAI-compatible provider and expose Laguna S 2.1 and XS 2.1 both directly and through OpenRouter. Include vault/env credential registration, secret redaction, live coverage, catalog tests, and user documentation.
Consolidate duplicated logic from the SQLite runs read model review:
- Derive the status sort CASE and board-column filter from a new
RunStatusKind::board_rank(), replacing three hand-maintained copies
of the status/column mapping; add a test upserting every status
variant so the migration CHECK can't silently drift
- Share RunSize bucket thresholds between from_total_usd_micros and
the generated size-sort CASE via RunSize::BUCKET_MAX_USD_MICROS
- Resolve run selectors from a lean identity query instead of
decoding every stored summary per request
- Delete the RunsSortKey/RunsSortDirection adapter enums; the store
sort enums now carry the wire serde names
- Consolidate the workflow display-name fallback chain into
WorkflowRef::display_name() (store, CLI, run lookup)
- Share pagination clamping and the paginated list envelope across
handlers
- Reconcile now skips rows whose source seq is unchanged and
batch-deletes stale rows; drop the two indexes no query can use
- Hold the summary store OnceLock cell in RunDatabaseInner instead of
a snapshot so late attachment reaches already-open writers
- Misc: expect() on COUNT(*) sign, %err logging, shared wall-time
helper, shared SQLite test fixture, dead billing fallback removed
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Consolidate the legacy-import helpers (backup path naming, RFC 3339
timestamp parsing, import report) into fabro-db and reuse them from the
vault, automation, variable, and environment stores. Add
SecretStore::open_snapshot to collapse the repeated
open/snapshot/into_vault chain. Let automation trigger canonicalization
live solely in normalize_replace, replace its redundant second full
validation with a targeted manual-id collision check, single-source the
automation SELECT projection, and gate list_automation_runs on a
lightweight existence query.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Delete the dead test-only Vault-based env-secrets migration and point
the startup migration tests at the production migrate_to_store path
over a real SQLite-backed SecretStore
- Extract shared legacy-import helpers (timestamped backup rename,
is_toml_file) into fabro_db::legacy and parse_rfc3339_utc into
fabro-db, replacing four per-crate copies
- Take one secrets snapshot in migrate_to_store instead of per-name
queries
- Share one bind order between the MCP store INSERT and UPDATE
statements
- Return SecretEntry directly from entry_from_row
- Unify the environment/MCP store blocking loaders into a generic
load_store_blocking helper
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The automations legacy import declares REMOVAL_DEADLINE per
docs/internal/migrations-strategy.md; the secrets JSON import predates it
and never did. Add the same constant and log field so the temporary
migration's lifespan is visible in code and in startup logs.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Review pass over the secrets-to-SQLite migration:
- Add SecretStore::open() consolidating the connect/migrate/import-legacy
sequence repeated at five call sites; fabro-agent and fabro-cli drop
their fabro-db dependency
- Restore process-env LLM credential lookup in the standalone CLI/agent
sources via SqlVaultCredentialSource::new (regression: vault_only
dropped the env fallback that VaultCredentialSource::new provided)
- Fix five install tests that still asserted against the legacy
secrets.json, which the importer renames to .bak
- Make AppStateConfig.preloaded_vault required, deleting the fallback
that re-read the already-renamed legacy file; drop the now-unused
vault_path field and demote load_startup_vault to test-only
- Skip the snapshot clones and CAS retry in resolve() when the vault
holds no OAuth secrets (per-request hot path)
- Remove dead persist_with_secret_store, the VaultSecretWrite alias,
the secret_type_string one-liner (now SecretType::as_str), the
impossible RowCountOverflow error, and duplicated row parsing
- Run check_crypto concurrently with the other diagnostics checks
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Detect applied migrations via sqlx's Migrate trait
(ensure_migrations_table + list_applied_migrations) instead of
hand-querying the _sqlx_migrations bookkeeping table, so the check
cannot drift from what Migrator::run actually applies.
- Write the snapshot to a staging file and rename it into place, so a
failure mid-copy never leaves a partial file at the snapshot path.
- Derive the database path from the pool's connect options instead of
storing a duplicate copy on Database.
- Drop the invented "fabro.sqlite3" fallback filename from
pre_migration_snapshot_path; append the suffix to the path directly.
- Deduplicate the snapshot-inspection blocks in the test behind small
connect_read_only/table_exists helpers.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
A binary downgrade after new SQLite migrations have been applied fails
sqlx's startup validation ("migration was previously applied but is
missing in the resolved migrations") and previously left the operator
with no rollback artifact: the shared database had no backup, so
recovering meant hand-editing _sqlx_migrations and dropping tables.
Database::migrate now writes a consistent single-file snapshot to
<db>.pre-migration.bak (via VACUUM INTO, mode 0600) before applying any
migration the database has not seen. Rollback is: stop the server,
replace the database file with the snapshot, delete -wal/-shm siblings,
start the previous binary. Fresh databases and no-op migrates skip the
snapshot, so the file always preserves the state from immediately before
the most recent schema change. A snapshot failure fails the migration:
no rollback artifact, no schema change.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Parallel branches run in spawned tasks that bypass the engine's
StageStarted/StageCompleted lifecycle, so a branch stage was created
Running by its first branch-scoped event and never reached a terminal
state. On a successful run nothing swept it (only RunFailed does), so
the fan-out rows spun forever with a `--` duration even after the run
and its fan-in finished.
Fold ParallelBranchStarted/ParallelBranchCompleted in the projection:
seed started_at for the live timer, then set the terminal state and
wall-time from the branch's own completion event.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>