Commit graph

353 commits

Author SHA1 Message Date
Brad Groux
55e621d147
release: prepare v5.2.5 (#922)
Prepare the v5.2.5 source, migration guidance, release documentation, and desktop publication evidence. Refs #914.
2026-07-23 10:17:10 -05:00
Brad Groux
f3ddfb4258 docs: harden desktop migration runbook 2026-07-23 09:37:38 -05:00
bradgroux
c205ad2e4e docs: add web to Mac desktop migration guide 2026-07-23 08:28:31 -05:00
Brad Groux
b704ab92d0
feat: add provider-neutral task envelope contracts (#891) (#894)
Some checks failed
CI / Lint & Type Check (push) Has been cancelled
CI / Workspace Unit Tests (push) Has been cancelled
CI / Build (push) Has been cancelled
CI / Security Audit (push) Has been cancelled
Co-authored-by: bradgroux <brad@digitalmeld.io>
2026-07-16 12:48:48 -05:00
Brad Groux
566ec0f7fe
feat: enforce provider runtime manifests (#887) (#890)
Co-authored-by: bradgroux <brad@digitalmeld.io>
2026-07-16 11:00:44 -05:00
Brad Groux
a42dc62ba4
feat: route agents by runtime manifests (#886) (#889)
Co-authored-by: bradgroux <brad@digitalmeld.io>
2026-07-16 10:54:05 -05:00
Brad Groux
6f020263c0
feat: add provider runtime manifests (#885) (#888)
Co-authored-by: bradgroux <brad@digitalmeld.io>
2026-07-16 10:46:54 -05:00
Brad Groux
44d1611741
feat: add governed SQLite journal maintenance (#884)
Some checks are pending
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
* feat: add governed SQLite journal maintenance

* fix: update permission coverage for SQLite maintenance

---------

Co-authored-by: bradgroux <brad@digitalmeld.io>
2026-07-15 20:00:58 -05:00
Brad Groux
bd6b0932a6
fix: enforce SQLite filesystem startup posture (#881) (#883)
Some checks are pending
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
Co-authored-by: bradgroux <brad@digitalmeld.io>
2026-07-15 17:49:13 -05:00
Brad Groux
7ff4acba8e
chore: prepare Veritas Kanban 5.2.4 (#845)
Some checks failed
CI / Lint & Type Check (push) Has been cancelled
CI / Workspace Unit Tests (push) Has been cancelled
CI / Build (push) Has been cancelled
CI / Security Audit (push) Has been cancelled
2026-07-13 02:16:02 -05:00
Brad Groux
d4c5b65859
chore: prepare Veritas Kanban 5.2.3 (#841)
Some checks are pending
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
2026-07-13 00:44:16 -05:00
Brad Groux
9754765987
docs: record annotated v5.2.2 tag (#834)
Fixes #833
2026-07-12 21:16:59 -05:00
Brad Groux
d082740a09
docs: finalize v5.2.2 release evidence (#832)
Fixes #830\nRelated to #809 and #816
2026-07-12 20:04:28 -05:00
Brad Groux
806f56d936
docs: record v5.2.2 release evidence (#831)
Related to #830
2026-07-12 19:02:24 -05:00
Brad Groux
4b84eccd1b
chore: prepare Veritas Kanban 5.2.2 (#827)
Tracks #809
2026-07-12 18:26:31 -05:00
Brad Groux
52b5ffce8a
fix: remove layout-driven dashboard motion (#822)
Fixes #814
2026-07-12 18:10:39 -05:00
Brad Groux
eb1817aa74
fix: make scoring profiles usable on phones (#826)
Fixes #813
2026-07-12 18:08:31 -05:00
Brad Groux
5819082664
fix: restore compact navigation and chat (#821)
Fixes #811
2026-07-12 17:27:57 -05:00
Brad Groux
e834cf8c3e
fix: make mobile settings responsive (#820)
Fixes #810
2026-07-12 17:16:41 -05:00
Brad Groux
f7de4cf7db
fix: respect overlay display preferences (#819)
Fixes #815
2026-07-12 17:03:26 -05:00
Brad Groux
fd7a62700c
fix: restore keyboard board movement (#818)
Fixes #812
2026-07-12 16:47:35 -05:00
Brad Groux
e781d30842
fix: externalize Electron runtime in desktop builds (#817)
Some checks are pending
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
Fixes #809
2026-07-12 16:18:42 -05:00
Brad Groux
999acb6317
Add canonical AGENTS guidance and validated Hermes/OpenClaw providers (#803)
* feat: add AGENTS.md, hermes-cli provider, and validated OpenClaw gateway dispatch

Issue #790: Add canonical AGENTS.md as the source-of-truth repository
instruction file for Codex, OpenClaw, Hermes, Claude, and other compatible
coding harnesses. Correct stale pnpm (9+ → ≥ 11.0.0) and Node (22+ → ≥ 22.22.1)
version requirements. Convert CLAUDE.md to a Claude-specific supplement.

Issue #791: Add first-class hermes-cli provider for Hermes Agent v2026.7.7.2.
- Add hermes-cli to AgentProvider type in shared/src/types/config.types.ts
- Add buildSafeHermesEnv utility with Hermes-specific env allowlist
- Add hermes-cli auth probe to AgentHealthService (hermes --version + API key check)
- Add hermes-cli provider adapter that spawns hermes -z <prompt> in task worktree
  without a shell, captures stdout/stderr/exit code, records session identity
- Add SIGTERM with bounded SIGKILL fallback for graceful stop
- Document limitations: resume not supported in this release

Issue #794: Fix OpenClaw gateway dispatch for task and workflow runs.
- Add OpenClawGatewayPreflightResult type and preflight() method to
  HttpOpenClawWorkflowAdapter that verifies sessions_spawn policy before dispatch
- Add HttpOpenClawTaskAdapter that uses sessions_spawn to dispatch tasks via the
  gateway HTTP API (replacing the broken request-file approach)
- Store childSessionKey in PendingAgent for durable session tracking
- Policy denial surfaces an actionable configHint pointing to gateway tool policy
- Add openclawSessionKey and hermesSessionId to PendingAgent interface

Add contract and regression tests:
- hermes-provider.test.ts: env utility, key sensitivity, health service
- openclaw-provider.test.ts: preflight scenarios (blocked, timeout, 403, ok: false, success)
  and spawnTask scenarios (policy denial, missing key, success, timeout, forbidden status)

Update docs/AGENT-PROVIDERS.md with Hermes and OpenClaw setup sections.
Update CHANGELOG.md Unreleased section.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* fix: address GPT review findings for harness providers

- preserve Hermes base allowlist when sandbox passthrough keys are present
- add hermes-cli sandbox capability mapping and built-in preset auth keys
- treat OpenClaw transport failures as unreachable in gateway preflight
- parse text-wrapped MCP tool results in OpenClaw task dispatch
- extend contract tests for the reviewed regressions

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* fix: align OpenClaw dispatch with current gateway contract

Persist acknowledged child session keys atomically without overwriting newer attempt state.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-07-10 11:27:33 -05:00
Brad Groux
5329612f7a
fix: runtime lifecycle issues — ConfigService leak, async registry writes, attempt reconciliation, path helpers (#779, #783, #781, #774) (#801)
* fix: runtime lifecycle issues #774 #779 #781 #783

- fix(#779): reuse app ConfigService singleton in delegation-violation route
  to prevent per-request FSWatcher leaks; fallback disposes cleanly

- fix(#783): debounce and async-ify agent-registry heartbeat writes;
  coalesce over 2s window, use atomic rename-on-write, flush on shutdown

- fix(#781): reconcile orphaned running agent attempts on startup;
  ClawdbotAgentService.reconcileRunningAttempts() marks stale attempts
  failed and reverts tasks to todo after crash/restart

- fix(#774): route .veritas-kanban paths in clawdbot-agent-service.ts and
  agent-status.ts through centralized getRuntimeDir()/getLogsDir() helpers
  so DATA_DIR/VERITAS_DATA_DIR overrides are respected consistently

- add async rename export to fs-helpers.ts
- update CHANGELOG, docs/AGENT-REGISTRY.md, docs/DEPLOYMENT.md
- add regression tests: agent-registry-heartbeat, delegation-violation-config,
  clawdbot-reconcile, path-audit (16 new tests)

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* fix: address GPT cross-model review findings

- fix(#779): configService wiring was effectively a no-op because
  initAgentStatus runs before the async IIFE sets configService.
  Add setAgentStatusConfigService() setter; call it from inside the
  startup IIFE immediately after new ConfigService() is assigned.

- fix(#783): replaced persistInFlight with a serialized persistChain
  promise so concurrent writeToDisk() calls can never race over the
  same *.tmp path. flushPersist() enqueues the write onto the chain
  and awaits the whole chain to guarantee durability.

- fix(#781): reconcileRunningAttempts() no longer blindly sets
  task.status = 'todo'; it only reverts the task status when
  task.status === 'in-progress', leaving blocked/done/etc. tasks
  untouched. Attempt status is always set to 'failed'.

- add test: non-in-progress task with stale running attempt keeps
  its status but attempt is still marked failed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* fix: resolve PR801 CI blockers and review comments

- add async rename mocks in jwt/docker path tests for fs-helpers rename export
- fix delegation fallback test to clear injection and assert disposal
- await async registry disposal in heartbeat test setup
- remove new lint warnings in reconcile/delegation tests
- align persistStatus comment with synchronous implementation

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* test: remove duplicate filesystem mock

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-07-10 09:45:27 -05:00
Brad Groux
70a83e3539
docs: PRD traceability and work-item hierarchy design (#800)
* docs: add PRD traceability and work-item hierarchy design (#773)

Design document for first-class traceability layer connecting tasks to
PRD requirements, risks, decisions, and verification evidence.

Key design decisions addressed:
- WorkItemLevel uses 'child-task' not 'subtask' to avoid collision with
  existing task.subtasks[] checklist model
- next_safe query evaluates depends_on ∪ blockedBy (covers both modern
  dependency graph and legacy blockedBy semantics)
- next_safe forces status=todo; returns 400 on conflicting status filter
- stopConditions includes stopConditionResolved map for machine-queryable
  state rather than free-form strings only
- Coverage endpoints introduce optional project requirement/risk catalogs
  (POST /api/projects/:id/catalog/{requirements,risks}) to enable true
  uncovered-row semantics; without a catalog, total = observed IDs only
- Verification semantics: 'verified' requires done task + checked
  verificationSteps or verificationIds (presence alone is insufficient)
- Archive/hierarchy: ON DELETE SET NULL is physical-delete-only; service
  layer warns on archiving parents with active children
- Cross-scope parent links rejected at the project level (400)
- SQLite JSON columns for ID arrays with json_each() query model; forward
  path to normalized junction tables documented

Changes:
- docs/features/prd-traceability.md — new design doc (958 lines)
- docs/FEATURES.md — add design-draft entry with link to doc

GPT cross-model review addressed before commit.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs: fix gated/blocked next-safe exclusion and archive wording consistency

Two semantic contradictions flagged in PR #800 review:

1. next_safe gated exclusion — RiskDisposition.gated is documented as
   'this task may not proceed until the gate is cleared' and coverage
   treats gated as an open risk, but the algorithm only excluded blocked
   and unknown. Fix: exclude blocked and gated always (no override),
   exclude unknown unless allow_unknown_risks=true. Updated in:
   - next-safe algorithm criterion 6+7
   - acceptance criterion #5 and #7
   - rollout step 10
   - B-5 backlog row

2. Archive wording mismatch — SQLite schema section said 'issues a
   warning and requires reparent or cascade archive', but AC #14 said
   'warning only'. Resolved as warning-only throughout: archive proceeds
   regardless, children retain parentId, response includes
   archiveWarning field. Updated in:
   - SQLite schema archive semantics prose

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-07-10 00:28:12 -05:00
Brad Groux
b3eda417ae
fix: stabilize Codex and development dependencies (#798)
* fix: stabilize dependency and Codex integration

Resolve development-only dependency advisories, remove the search test teardown race, and validate the Codex 0.144.1 event and health contracts.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* chore: keep generated lockfile reviewable

Exclude pnpm-lock.yaml from Prettier and restore pnpm's generated formatting after dependency resolution.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* test: stabilize Codex process lifecycle

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-07-10 00:03:27 -05:00
Brad Groux
2b174fd392 Add Squad Chat demo screenshots 2026-06-29 06:00:36 -05:00
Brad Groux
cf03145353
Update v5 release notes for 5.2.1 assets (#768)
Some checks are pending
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
2026-06-28 23:28:14 -05:00
Brad Groux
6c043c76d4
Bump version to 5.2.1 (#766)
* Bump version to 5.2.1

* Stabilize workflow run metadata test

* Document v5.2.1 release notes and harden CI setup
2026-06-28 21:50:14 -05:00
Brad Groux
5e8d1d65be
Fix v5.2 audit follow-ups (#764) 2026-06-28 21:27:01 -05:00
Brad Groux
a819808ef8
Document v5.2 latest changes (#759)
Some checks are pending
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
2026-06-27 21:18:04 -05:00
Brad Groux
3c9065b8ab
Bump version to 5.2.0 (#757)
Some checks failed
CI / Security Audit (push) Has been cancelled
CI / Lint & Type Check (push) Has been cancelled
CI / Workspace Unit Tests (push) Has been cancelled
CI / Build (push) Has been cancelled
2026-06-26 15:11:19 -05:00
Brad Groux
013c2b5383
Fix audit follow-up gates
Fix audit follow-up gates

- remove gray-matter and use local YAML frontmatter handling
- upgrade DOMPurify and clear production advisories
- make CLI/MCP smoke skip cleanly without VK_API_KEY
- reduce initial JS below the Mantine QA budget

Closes #753
Closes #754
Closes #755
2026-06-26 14:59:20 -05:00
Brad Groux
5bd4377f32
Add external tracker schema introspection
Adds configurable external tracker schema introspection, mapping profiles, validation, dry-run create, and approved mock create support.
2026-06-26 14:28:59 -05:00
Brad Groux
7950fec5f4
Add reflection memory promotion queue
Adds a reviewed reflection candidate queue, API, Settings UI, duplicate merge flow, task lesson promotion, redaction, docs, and tests.
2026-06-26 14:00:51 -05:00
Brad Groux
b9a648afe7
Add ceremony enforcement gates (#750) 2026-06-26 13:35:45 -05:00
Brad Groux
13fc8ac083
Add human reply communication adapters (#749) 2026-06-26 13:08:22 -05:00
Brad Groux
1b29b2eb24
Add Squad Chat collaboration state (#748) 2026-06-26 12:42:14 -05:00
Brad Groux
9abd06dd0e
Add policy-gated queue intake monitors
Add GitHub-backed queue monitor service, APIs, CLI commands, Settings queue dashboard, scheduler integration, operations digest activity, tests, and documentation.
2026-06-26 11:40:11 -05:00
Brad Groux
5b363303c4
Add unified recurring work scheduler
Add scheduler APIs, CLI commands, settings UI, retry/event state, telemetry hooks, and documentation over scheduled deliverables and workflow schedules.
2026-06-26 11:06:45 -05:00
Brad Groux
fbff5b5c40
Add workspace capability discovery and intake
Add config-backed workspace capability discovery, trusted intake APIs, CLI commands, settings UI, and delegated work status links.
2026-06-26 10:45:47 -05:00
Brad Groux
c6eed92631
Add team roster routing manifests
Add config-backed team roster manifests, route preview APIs, and roster-first agent routing.
2026-06-26 10:12:49 -05:00
Brad Groux
1bbd3739e0 Prepare Veritas Kanban 5.1.0 release 2026-06-18 17:01:39 -05:00
Brad Groux
ca2dd7ef23
Add shared live run sessions (#731) 2026-06-18 16:49:55 -05:00
Brad Groux
43c21b71a4
Add decision review sessions
Adds task-linked multi-participant decision review sessions with ordered critique rounds, final packet attachment, export support, API/UI integration, docs, and regression coverage.
2026-06-18 16:16:05 -05:00
Brad Groux
4a0c66d331
Add reusable agent profile packages (#729)
* Add reusable agent profile packages

* Add profile CLI permission coverage
2026-06-18 15:53:47 -05:00
Brad Groux
8686803350
Implement agent run budget enforcement
Adds enforceable agent and workflow run budgets with governance traces, UI controls, completion evidence, docs, and regression coverage.
2026-06-18 15:22:45 -05:00
Brad Groux
398d6024af
Add sandbox policy presets (#727) 2026-06-18 14:44:27 -05:00
Brad Groux
044e0c0ba3
Fix Docker source builds
Some checks are pending
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
Fix Docker build context and pnpm setup for source builds. Closes #725.
2026-06-18 13:47:00 -05:00
Brad Groux
ac0687ac72
Prepare v5.0.1 patch release
Bump Veritas Kanban to v5.0.1, update release docs, and fix the local macOS packaging smoke check.
2026-06-12 03:19:52 -05:00