* fix: runtime lifecycle issues #774#779#781#783
- fix(#779): reuse app ConfigService singleton in delegation-violation route
to prevent per-request FSWatcher leaks; fallback disposes cleanly
- fix(#783): debounce and async-ify agent-registry heartbeat writes;
coalesce over 2s window, use atomic rename-on-write, flush on shutdown
- fix(#781): reconcile orphaned running agent attempts on startup;
ClawdbotAgentService.reconcileRunningAttempts() marks stale attempts
failed and reverts tasks to todo after crash/restart
- fix(#774): route .veritas-kanban paths in clawdbot-agent-service.ts and
agent-status.ts through centralized getRuntimeDir()/getLogsDir() helpers
so DATA_DIR/VERITAS_DATA_DIR overrides are respected consistently
- add async rename export to fs-helpers.ts
- update CHANGELOG, docs/AGENT-REGISTRY.md, docs/DEPLOYMENT.md
- add regression tests: agent-registry-heartbeat, delegation-violation-config,
clawdbot-reconcile, path-audit (16 new tests)
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* fix: address GPT cross-model review findings
- fix(#779): configService wiring was effectively a no-op because
initAgentStatus runs before the async IIFE sets configService.
Add setAgentStatusConfigService() setter; call it from inside the
startup IIFE immediately after new ConfigService() is assigned.
- fix(#783): replaced persistInFlight with a serialized persistChain
promise so concurrent writeToDisk() calls can never race over the
same *.tmp path. flushPersist() enqueues the write onto the chain
and awaits the whole chain to guarantee durability.
- fix(#781): reconcileRunningAttempts() no longer blindly sets
task.status = 'todo'; it only reverts the task status when
task.status === 'in-progress', leaving blocked/done/etc. tasks
untouched. Attempt status is always set to 'failed'.
- add test: non-in-progress task with stale running attempt keeps
its status but attempt is still marked failed.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* fix: resolve PR801 CI blockers and review comments
- add async rename mocks in jwt/docker path tests for fs-helpers rename export
- fix delegation fallback test to clear injection and assert disposal
- await async registry disposal in heartbeat test setup
- remove new lint warnings in reconcile/delegation tests
- align persistStatus comment with synchronous implementation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* test: remove duplicate filesystem mock
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* docs: add PRD traceability and work-item hierarchy design (#773)
Design document for first-class traceability layer connecting tasks to
PRD requirements, risks, decisions, and verification evidence.
Key design decisions addressed:
- WorkItemLevel uses 'child-task' not 'subtask' to avoid collision with
existing task.subtasks[] checklist model
- next_safe query evaluates depends_on ∪ blockedBy (covers both modern
dependency graph and legacy blockedBy semantics)
- next_safe forces status=todo; returns 400 on conflicting status filter
- stopConditions includes stopConditionResolved map for machine-queryable
state rather than free-form strings only
- Coverage endpoints introduce optional project requirement/risk catalogs
(POST /api/projects/:id/catalog/{requirements,risks}) to enable true
uncovered-row semantics; without a catalog, total = observed IDs only
- Verification semantics: 'verified' requires done task + checked
verificationSteps or verificationIds (presence alone is insufficient)
- Archive/hierarchy: ON DELETE SET NULL is physical-delete-only; service
layer warns on archiving parents with active children
- Cross-scope parent links rejected at the project level (400)
- SQLite JSON columns for ID arrays with json_each() query model; forward
path to normalized junction tables documented
Changes:
- docs/features/prd-traceability.md — new design doc (958 lines)
- docs/FEATURES.md — add design-draft entry with link to doc
GPT cross-model review addressed before commit.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* docs: fix gated/blocked next-safe exclusion and archive wording consistency
Two semantic contradictions flagged in PR #800 review:
1. next_safe gated exclusion — RiskDisposition.gated is documented as
'this task may not proceed until the gate is cleared' and coverage
treats gated as an open risk, but the algorithm only excluded blocked
and unknown. Fix: exclude blocked and gated always (no override),
exclude unknown unless allow_unknown_risks=true. Updated in:
- next-safe algorithm criterion 6+7
- acceptance criterion #5 and #7
- rollout step 10
- B-5 backlog row
2. Archive wording mismatch — SQLite schema section said 'issues a
warning and requires reparent or cascade archive', but AC #14 said
'warning only'. Resolved as warning-only throughout: archive proceeds
regardless, children retain parentId, response includes
archiveWarning field. Updated in:
- SQLite schema archive semantics prose
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Fix audit follow-up gates
- remove gray-matter and use local YAML frontmatter handling
- upgrade DOMPurify and clear production advisories
- make CLI/MCP smoke skip cleanly without VK_API_KEY
- reduce initial JS below the Mantine QA budget
Closes#753Closes#754Closes#755