Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
339 commits
Select commit Hold shift + click to select a range
ee56f5b
Freeze legacy surfaces before the backend clean break
Y1fe1Zh0u Sep 1, 2026
e7d8561
Establish one clean target for Frontend UI ownership
Y1fe1Zh0u Sep 1, 2026
0184b7f
Freeze clean-break governance before target implementation
Y1fe1Zh0u Sep 1, 2026
7abad63
Make coverage ownership follow the canonical ledger
Y1fe1Zh0u Sep 1, 2026
5646a4c
Keep Backend load evidence comparable
Y1fe1Zh0u Sep 1, 2026
bfffbe1
Close the S3 owner approval bypass
Y1fe1Zh0u Sep 1, 2026
8b36403
Freeze every legacy surface before target replacement
Y1fe1Zh0u Sep 1, 2026
cba7969
Give the target backend one owned composition lifecycle
Y1fe1Zh0u Sep 1, 2026
f9fbc3c
Establish owner boundaries before module implementation
Y1fe1Zh0u Sep 1, 2026
983e112
Prevent database credentials escaping configuration diagnostics
Y1fe1Zh0u Sep 1, 2026
1b13003
Make target ownership violations fail before implementation
Y1fe1Zh0u Sep 1, 2026
cc2d3e1
Prevent legacy execution authority surviving target cutover
Y1fe1Zh0u Sep 1, 2026
9c0f1a0
Make target startup incapable of reviving legacy persistence
Y1fe1Zh0u Sep 1, 2026
18ace9c
Make startup authority closed under review
Y1fe1Zh0u Sep 1, 2026
974a4e9
Prevent legacy Context import identity from returning
Y1fe1Zh0u Sep 1, 2026
18c64ac
Prevent structured Experience import identities from returning
Y1fe1Zh0u Sep 1, 2026
f679bea
Prevent old Model and LLM import identities from returning
Y1fe1Zh0u Sep 1, 2026
dbca6d3
Prevent persistent Task authority from returning
Y1fe1Zh0u Sep 1, 2026
c246c26
Prevent legacy Tool authority from returning
Y1fe1Zh0u Sep 1, 2026
aada76a
Prevent legacy Skill authority from returning
Y1fe1Zh0u Sep 1, 2026
7bd51e8
Prevent OpenClaw Gateway authority from returning
Y1fe1Zh0u Sep 1, 2026
3e69d28
Prevent old Agent Credential authority from returning
Y1fe1Zh0u Sep 1, 2026
efbed07
Close the deleted Credential DAO export surface
Y1fe1Zh0u Sep 1, 2026
e95f1ab
Require Credential readiness before SSO
Y1fe1Zh0u Sep 1, 2026
0225007
Prevent the overloaded Agent aggregate from returning
Y1fe1Zh0u Sep 1, 2026
0a365cc
Keep Phase 1 fixtures aligned with owner readiness
Y1fe1Zh0u Sep 1, 2026
37ccb27
Prevent the old Identity and Tenant aggregate from returning
Y1fe1Zh0u Sep 1, 2026
4151fea
Prevent legacy Auth orchestration from returning
Y1fe1Zh0u Sep 1, 2026
373566e
Keep SSO tests with their surviving owner
Y1fe1Zh0u Sep 1, 2026
1700f74
Close Auth package-export imports in tests
Y1fe1Zh0u Sep 1, 2026
439c75a
Prevent the old SSO authority from returning
Y1fe1Zh0u Sep 1, 2026
b8111b9
Keep mixed Google Workspace entry ownership explicit
Y1fe1Zh0u Sep 1, 2026
39f3e58
Prevent the overloaded Organization aggregate from returning
Y1fe1Zh0u Sep 1, 2026
6e56ded
Stop publishing Tenant Knowledge into Agent files
Y1fe1Zh0u Sep 1, 2026
89cf50d
Prevent the old Invitation persistence contract from returning
Y1fe1Zh0u Sep 1, 2026
8b660f8
Prevent legacy Onboarding state from returning
Y1fe1Zh0u Sep 1, 2026
c43bfb8
Prevent the old Directory authority from returning
Y1fe1Zh0u Sep 1, 2026
ed5daff
Prevent the old Focus authority from returning
Y1fe1Zh0u Sep 1, 2026
8a5d676
Prevent the old Notification authority from returning
Y1fe1Zh0u Sep 2, 2026
0acf621
Close the remaining Notification deletion gaps
Y1fe1Zh0u Sep 2, 2026
3f29882
Prevent the old Published Page authority from returning
Y1fe1Zh0u Sep 2, 2026
1a026f7
Clarify why deferred capabilities can lose old authority first
Y1fe1Zh0u Sep 2, 2026
92f5002
Prevent the old Plaza authority from returning
Y1fe1Zh0u Sep 2, 2026
bc1b475
Keep source-disposition claims within verified guard coverage
Y1fe1Zh0u Sep 2, 2026
5af2967
Prevent the old Agent Template authority from returning
Y1fe1Zh0u Sep 2, 2026
c369d0b
Keep the source-disposition summary aligned with Agent Template deletion
Y1fe1Zh0u Sep 2, 2026
f6dbf6d
Prevent the legacy AgentBay authority from returning
Y1fe1Zh0u Sep 2, 2026
9309622
Remove the obsolete runtime approval authority
Y1fe1Zh0u Sep 2, 2026
30b56e7
Close gaps in the retired approval boundary
Y1fe1Zh0u Sep 2, 2026
b61a747
Require validated environment names before lookup
Y1fe1Zh0u Sep 2, 2026
c032321
Keep load-profile assertions on typed mappings
Y1fe1Zh0u Sep 2, 2026
0f18151
Keep G002 deletion authority in the Phase 0 ledger
Y1fe1Zh0u Sep 2, 2026
29e6c6a
Constrain database secret revelation to connection owners
Y1fe1Zh0u Sep 2, 2026
5ff3714
Close Alembic imports over dynamic loading
Y1fe1Zh0u Sep 2, 2026
395c818
Make composition tests express their runtime types
Y1fe1Zh0u Sep 2, 2026
e4f404c
Make DAO package exports statically enforceable
Y1fe1Zh0u Sep 2, 2026
3c49189
Prevent long-running tenants from monopolizing execution slots
Y1fe1Zh0u Sep 2, 2026
cf9fc97
Make dotted guards declare their own coverage
Y1fe1Zh0u Sep 2, 2026
c51af58
Describe the target Backend without retired checkpoints
Y1fe1Zh0u Sep 2, 2026
1608799
Keep rewrite evidence cumulative at every Goal
Y1fe1Zh0u Sep 2, 2026
9c2f7b2
Keep Goal authority recoverable from Git
Y1fe1Zh0u Sep 2, 2026
eb28b01
Keep Goal checkpoint rationale with its gate
Y1fe1Zh0u Sep 2, 2026
4ea2c36
Close dynamic DAO export installation paths
Y1fe1Zh0u Sep 2, 2026
f804a53
Keep Alembic failures actionable without exposing secrets
Y1fe1Zh0u Sep 2, 2026
062a7d6
Make Goal gates executable without widening their language
Y1fe1Zh0u Sep 2, 2026
931477e
Keep Phase 0 disposition authority recoverable
Y1fe1Zh0u Sep 2, 2026
69bd740
Honor contract dependencies before schema-wave gates
Y1fe1Zh0u Sep 2, 2026
1f26bf5
Explain cumulative gates at their owning testing boundary
Y1fe1Zh0u Sep 2, 2026
4530f30
Preserve clean-break traceability without rewriting history
Y1fe1Zh0u Sep 2, 2026
11dbf1e
Remove an unused duplicate Run DAO identity
Y1fe1Zh0u Sep 3, 2026
3d77ef3
Remove an orphaned OKR relationship hook
Y1fe1Zh0u Sep 3, 2026
3ae2787
Remove an inactive token accounting producer
Y1fe1Zh0u Sep 3, 2026
7651908
Remove a dead duplicate WeCom transport facade
Y1fe1Zh0u Sep 3, 2026
46d7c1a
Stop retired Agent tests from defining target policy
Y1fe1Zh0u Sep 3, 2026
4b50684
Remove obsolete direct Session authority before target rebuild
Y1fe1Zh0u Sep 3, 2026
130dd6f
Prevent Session authority from returning under alternate paths
Y1fe1Zh0u Sep 3, 2026
e41269e
Remove obsolete Group and Participant authority before rebuild
Y1fe1Zh0u Sep 3, 2026
2b0a9fb
Remove legacy Schedule authority before Trigger rebuild
Y1fe1Zh0u Sep 3, 2026
5b481f4
Keep source-disposition status aligned with Schedule deletion
Y1fe1Zh0u Sep 3, 2026
31da526
Remove legacy Trigger authority before contract rebuild
Y1fe1Zh0u Sep 3, 2026
22d16bd
Remove legacy Heartbeat authority before contract rebuild
Y1fe1Zh0u Sep 3, 2026
eb5d3cc
Stop Sandbox from exposing the retired Heartbeat root
Y1fe1Zh0u Sep 3, 2026
9bf149e
Isolate Channel provider transports before owner rebuild
Y1fe1Zh0u Sep 3, 2026
2ce9ac6
Remove legacy Channel authority before contract rebuild
Y1fe1Zh0u Sep 3, 2026
0431525
Remove the unapproved legacy OKR authority
Y1fe1Zh0u Sep 3, 2026
7458c49
Remove orphaned timezone resolution policy
Y1fe1Zh0u Sep 3, 2026
9599588
Remove obsolete Workspace authority before target ownership
Y1fe1Zh0u Sep 3, 2026
a7c6479
Remove obsolete A2A collaboration before contract review
Y1fe1Zh0u Sep 3, 2026
e4e11a4
Keep staged advanced routes outside the A2A deletion
Y1fe1Zh0u Sep 3, 2026
6267bad
Separate email provider mechanics from legacy Workspace storage
Y1fe1Zh0u Sep 3, 2026
16030e7
Stop setup from recreating legacy database authority
Y1fe1Zh0u Sep 3, 2026
5bb406f
Make bootstrap guard inspect executable shell structure
Y1fe1Zh0u Sep 3, 2026
22960cd
Preserve object mechanics without legacy storage authority
Y1fe1Zh0u Sep 3, 2026
ac8edad
Remove mixed advanced transport before owner rebuilds
Y1fe1Zh0u Sep 3, 2026
246d4fb
Remove legacy Activity transport before observability design
Y1fe1Zh0u Sep 3, 2026
cb4240a
Remove legacy Messages inbox transport before notification design
Y1fe1Zh0u Sep 3, 2026
0cd204c
Remove mixed Platform Administration transport
Y1fe1Zh0u Sep 3, 2026
86bed36
Remove mixed Enterprise transport before owner rebuilds
Y1fe1Zh0u Sep 3, 2026
e5e996e
Remove orphaned legacy observability and audit loggers
Y1fe1Zh0u Sep 3, 2026
d570d99
Remove orphaned legacy Platform URL policy
Y1fe1Zh0u Sep 3, 2026
ec57fb4
Remove the orphaned legacy quota guard
Y1fe1Zh0u Sep 3, 2026
a95caa4
Remove product-shaped legacy Realtime services
Y1fe1Zh0u Sep 3, 2026
44a267c
Remove the orphaned monolithic resource discovery facade
Y1fe1Zh0u Sep 3, 2026
e85fbcd
Remove legacy System Email product transport
Y1fe1Zh0u Sep 3, 2026
43fd3a5
Remove orphaned vision injection and maintenance scripts
Y1fe1Zh0u Sep 3, 2026
d22a7bb
Remove legacy Observability and Audit persistence before owner rebuilds
Y1fe1Zh0u Sep 3, 2026
fc99065
Remove orphaned legacy Run and Settings persistence
Y1fe1Zh0u Sep 3, 2026
a2de32e
Remove legacy core compatibility facades
Y1fe1Zh0u Sep 3, 2026
981e259
Remove obsolete BaseDAO contract coverage
Y1fe1Zh0u Sep 3, 2026
8e9503f
Prevent document conversion from stalling concurrent runs
Y1fe1Zh0u Sep 3, 2026
662e06a
Keep staged email providers statically clean
Y1fe1Zh0u Sep 3, 2026
6e7e0b4
Keep staged DingTalk providers statically clean
Y1fe1Zh0u Sep 3, 2026
a41e0c7
Keep staged Feishu providers statically clean
Y1fe1Zh0u Sep 3, 2026
a2f1a21
Keep staged MCP transport statically clean
Y1fe1Zh0u Sep 3, 2026
30b342c
Remove orphaned global logging configuration
Y1fe1Zh0u Sep 3, 2026
b6f0295
Expose text extraction defects instead of misreporting invalid files
Y1fe1Zh0u Sep 3, 2026
71f34fb
Keep optional browser failures inside document conversion
Y1fe1Zh0u Sep 3, 2026
96634a5
Decouple Sandbox secrets from legacy Auth and DAO authority
Y1fe1Zh0u Sep 3, 2026
e835e64
Make Sandbox lease ownership explicit
Y1fe1Zh0u Sep 3, 2026
305e999
Keep Workspace path mechanics private to Sandbox
Y1fe1Zh0u Sep 3, 2026
cdbd307
Make retained Sandbox mechanics statically clean
Y1fe1Zh0u Sep 3, 2026
2ba09c9
Keep Phase 0 disposition evidence bound to its current authority
Y1fe1Zh0u Sep 3, 2026
8e2cfdc
Align DAO governance with the empty target namespace
Y1fe1Zh0u Sep 3, 2026
89e1b20
Preserve archived Sandbox evidence verbatim
Y1fe1Zh0u Sep 3, 2026
8283b0e
Keep self-hosted health logs free of URL secrets
Y1fe1Zh0u Sep 3, 2026
bdface8
Keep final G002 disposition evidence bound to its governing Note
Y1fe1Zh0u Sep 3, 2026
a5f2c18
Make the first cumulative rewrite checkpoints independently auditable
Y1fe1Zh0u Sep 3, 2026
689d89a
Remove orphaned schema and Tool maintenance scripts
Y1fe1Zh0u Sep 3, 2026
e4c12e2
Keep the final known Lore defect explicit without replacing G002 history
Y1fe1Zh0u Sep 4, 2026
0b716cf
Keep G002 source evidence bound after the final legacy script deletion
Y1fe1Zh0u Sep 4, 2026
f056b9d
Bind the completed checkpoints to the final G002 source tree
Y1fe1Zh0u Sep 4, 2026
8ad1a3d
Make deleted maintenance scripts unreachable through real interpreter…
Y1fe1Zh0u Sep 4, 2026
8534a24
Keep source disposition evidence bound after the guard contract repair
Y1fe1Zh0u Sep 4, 2026
ecea39b
Bind the G002 checkpoint to the closed maintenance guard
Y1fe1Zh0u Sep 4, 2026
bb18f8d
Make the active Phase 0 authority contract visible as implemented
Y1fe1Zh0u Sep 4, 2026
556320f
Make the outgoing Lore exception set complete and closed
Y1fe1Zh0u Sep 4, 2026
82b2673
Keep G002 startup isolated and health-only
Y1fe1Zh0u Sep 4, 2026
712716c
Enforce the target database namespace in Settings
Y1fe1Zh0u Sep 4, 2026
924b329
Make health-only restart process ownership provable
Y1fe1Zh0u Sep 4, 2026
1598f73
Quarantine operator guidance to the G002 health boundary
Y1fe1Zh0u Sep 4, 2026
20d2118
Reject database identity overrides in target URLs
Y1fe1Zh0u Sep 4, 2026
69c6199
Bind restart health to the launched Backend instance
Y1fe1Zh0u Sep 4, 2026
357721b
Quarantine schema execution until the target baseline exists
Y1fe1Zh0u Sep 4, 2026
898981a
Remove dependencies whose owning runtime paths are gone
Y1fe1Zh0u Sep 4, 2026
45895cb
Make remote CI prove the same cumulative checkpoint as local review
Y1fe1Zh0u Sep 4, 2026
31f7035
Make the target persistence namespace one Settings-owned fact
Y1fe1Zh0u Sep 4, 2026
43ec654
Close command-segment and Helm quarantine bypasses
Y1fe1Zh0u Sep 4, 2026
6b282f5
Bind Phase 0 evidence to the completed G002 source authorities
Y1fe1Zh0u Sep 4, 2026
821f928
Accept only the legacy checkout's real virtual-environment entry
Y1fe1Zh0u Sep 4, 2026
3bc1e1c
Bind the G002 checkpoint to the completed cumulative source tree
Y1fe1Zh0u Sep 4, 2026
31929b5
Make startup and CI guards closed over executable syntax
Y1fe1Zh0u Sep 4, 2026
eb62910
Give immutable-reference validation one executable owner
Y1fe1Zh0u Sep 4, 2026
f58e066
Fail closed on nested assignment command substitutions
Y1fe1Zh0u Sep 4, 2026
2237575
Serialize restart ownership before touching shared process evidence
Y1fe1Zh0u Sep 4, 2026
ff8c296
Make setup consume the reviewed dependency lock without mutation
Y1fe1Zh0u Sep 4, 2026
6612ea6
Make replaced-evidence cleanup coverage wait for child readiness
Y1fe1Zh0u Sep 4, 2026
fd863a8
Close command-substitution guards across restart entrypoints
Y1fe1Zh0u Sep 4, 2026
1fcca1d
Close the remaining executable shell-expansion bypass
Y1fe1Zh0u Sep 4, 2026
7099ae4
Reject dynamic shell sinks across startup boundaries
Y1fe1Zh0u Sep 4, 2026
69c60b8
Bind disposition evidence to the independently approved G002 source
Y1fe1Zh0u Sep 4, 2026
e9523ea
Close G002 with evidence from the approved source
Y1fe1Zh0u Sep 4, 2026
7c23b17
Preserve existing database credentials during target setup
Y1fe1Zh0u Sep 6, 2026
5fbdebc
Make the agreed G003 foundation ready for implementation
Y1fe1Zh0u Sep 6, 2026
4ece6bc
Constrain foundation ownership before services write durable state
Y1fe1Zh0u Sep 6, 2026
e75425d
Keep identity mutations inside a single Tenant transaction
Y1fe1Zh0u Sep 6, 2026
211931e
Keep shared credentials encrypted and separate from Agent use rights
Y1fe1Zh0u Sep 6, 2026
118c3b9
Resolve Agent configuration without recreating execution or authoriza…
Y1fe1Zh0u Sep 6, 2026
9480cbb
Capture login authorization atomically without live permission polling
Y1fe1Zh0u Sep 6, 2026
e6ecf3b
Keep required audit evidence atomic with the recorded mutation
Y1fe1Zh0u Sep 6, 2026
c18acd6
Require real foundation integration in cumulative CI gates
Y1fe1Zh0u Sep 6, 2026
e29ba34
Close G003 against freshly verified committed source
Y1fe1Zh0u Sep 6, 2026
38f0893
Separate audit observation from authoritative business outcomes
Y1fe1Zh0u Sep 6, 2026
1cba543
Keep prior approvals verifiable when foundation contracts evolve
Y1fe1Zh0u Sep 7, 2026
618eacd
Bind Audit implementation to the agreed independent observation inter…
Y1fe1Zh0u Sep 7, 2026
fb0f1ad
Prevent Audit persistence from controlling business transactions
Y1fe1Zh0u Sep 7, 2026
5eea5b7
Fix G004 execution boundaries before registering dependent schemas
Y1fe1Zh0u Sep 7, 2026
085a40b
Keep fresh ledger fixtures independent of existing approval history
Y1fe1Zh0u Sep 7, 2026
8fb0465
Keep cumulative evidence current after isolating Audit failures
Y1fe1Zh0u Sep 7, 2026
a8a700e
Constrain execution dependencies to their approved ownership graph
Y1fe1Zh0u Sep 7, 2026
c6ca8a1
Keep pooled execution requests free of shared cookie accounts
Y1fe1Zh0u Sep 7, 2026
70cfb6b
Keep rewrite guards aligned with approved execution owners
Y1fe1Zh0u Sep 7, 2026
5dd8130
Require validated Model configurations before execution
Y1fe1Zh0u Sep 7, 2026
6d98145
Preserve storage revisions without serializing unrelated work
Y1fe1Zh0u Sep 7, 2026
fb900ec
Keep Workspace publication scoped and conflict-aware
Y1fe1Zh0u Sep 7, 2026
3e6aca7
Fix Tool execution to authorized account-local bindings
Y1fe1Zh0u Sep 7, 2026
a620909
Separate shared capability discovery from Agent activation
Y1fe1Zh0u Sep 7, 2026
2a4b406
Expose searched Tools without changing Run authorization
Y1fe1Zh0u Sep 7, 2026
ec4cae9
Make Workspace capabilities executable through scoped Tools
Y1fe1Zh0u Sep 7, 2026
b6b4daa
Provision explicit Builtin grants without initialization races
Y1fe1Zh0u Sep 7, 2026
f218565
Give application shutdown an explicit storage disposal boundary
Y1fe1Zh0u Sep 7, 2026
38db133
Give execution dependencies one application resource lifetime
Y1fe1Zh0u Sep 7, 2026
67d2e0e
Validate Model capabilities with a feasible configured output budget
Y1fe1Zh0u Sep 7, 2026
3a2a46c
Keep S3 clients owned across concurrent initialization and cancellation
Y1fe1Zh0u Sep 7, 2026
3083dba
Keep G004 status notes aligned with completed resource wiring
Y1fe1Zh0u Sep 7, 2026
37e92d8
Record clean committed-source acceptance for G004 architecture
Y1fe1Zh0u Sep 7, 2026
e4158b7
Keep ready Run allocation fair across Tenants and Agents
Y1fe1Zh0u Sep 7, 2026
f8e0762
Keep first-release service interruption uniform across unfinished Runs
Y1fe1Zh0u Sep 7, 2026
aea43e0
Bind Run and Context implementation to the reviewed G005 contract
Y1fe1Zh0u Sep 7, 2026
7300736
Preserve typed execution facts before introducing Run writers
Y1fe1Zh0u Sep 7, 2026
1abe8da
Enable component-by-component UI work without resetting legacy pages
Y1fe1Zh0u Sep 7, 2026
c13785f
Keep Run History atomic and bounded before lifecycle integration
Y1fe1Zh0u Sep 7, 2026
5401fcf
Preserve captured Child authorization before filtering Main tools
Y1fe1Zh0u Sep 7, 2026
8f68db3
Preserve observed Context without repeating every complete model request
Y1fe1Zh0u Sep 7, 2026
c871e0b
Keep Context rebuildable without changing observed execution facts
Y1fe1Zh0u Sep 7, 2026
87c2dde
Keep summary generation from changing live model continuation
Y1fe1Zh0u Sep 7, 2026
3167371
Preserve fixed execution inputs without repeated startup encoding
Y1fe1Zh0u Sep 8, 2026
64e2e8c
Bind reusable Context to the input actually recorded by Run
Y1fe1Zh0u Sep 8, 2026
a565029
Keep delegation immediate and role-scoped during native execution
Y1fe1Zh0u Sep 8, 2026
bf69427
Align dependency checks with sourced Context assembly
Y1fe1Zh0u Sep 8, 2026
436419b
Keep waiting work from occupying execution slots
Y1fe1Zh0u Sep 8, 2026
b266f20
Let independent Runs start concurrently without weakening durable set…
Y1fe1Zh0u Sep 8, 2026
b341b93
Exercise native Runs through the application-owned execution path
Y1fe1Zh0u Sep 8, 2026
aefb660
Separate measured startup improvement from platform qualification
Y1fe1Zh0u Sep 8, 2026
20fb338
Initialize a new Main Run without redundant database round trips
Y1fe1Zh0u Sep 8, 2026
886c3d4
Prevent private execution contexts from publishing shared Agent memory
Y1fe1Zh0u Sep 8, 2026
27e1d7e
Prevent disabled Skill sources from becoming active during publication
Y1fe1Zh0u Sep 8, 2026
3573d1b
Let Model account for image requests without guessing their token cost
Y1fe1Zh0u Sep 8, 2026
ec70312
Keep Context preparation incremental while respecting image budgets
Y1fe1Zh0u Sep 8, 2026
ae50d00
Preserve MCP images without duplicating or rewriting Tool results
Y1fe1Zh0u Sep 8, 2026
3dbad45
Let authorized members execute Agents without management privileges
Y1fe1Zh0u Sep 8, 2026
5c40b81
Return a stable validation error for malformed timezone paths
Y1fe1Zh0u Sep 8, 2026
989716c
Preserve Run input and family outcomes across transient execution fai…
Y1fe1Zh0u Sep 8, 2026
ab5b05c
Exercise prepared media requests through application-owned runtime se…
Y1fe1Zh0u Sep 8, 2026
26c792f
Make core qualification depend on measured execution rather than late…
Y1fe1Zh0u Sep 8, 2026
936ec8c
Record the verified G005 repair boundary without claiming platform qu…
Y1fe1Zh0u Sep 8, 2026
f3c17b4
Keep Model integration status consistent with verified application wi…
Y1fe1Zh0u Sep 8, 2026
e4e15c4
Bind the approved Memory restriction without rewriting prior approvals
Y1fe1Zh0u Sep 8, 2026
7527bbf
Fix G006 input and communication decisions before product integration
Y1fe1Zh0u Sep 8, 2026
1fb868c
Keep model retry tuning in one Run-owned policy
Y1fe1Zh0u Sep 8, 2026
b011a49
Bind product input ownership before connecting live execution
Y1fe1Zh0u Sep 9, 2026
d876066
Expose the fixed login deadline without renewing human access
Y1fe1Zh0u Sep 9, 2026
ce5e10d
Keep explicitly selected personal accounts from silently changing exe…
Y1fe1Zh0u Sep 9, 2026
435f33e
Commit product associations with Run transitions and serialize late s…
Y1fe1Zh0u Sep 9, 2026
da000e6
Keep private provenance and explicit media semantics with captured co…
Y1fe1Zh0u Sep 9, 2026
36e583d
Keep input attachments immutable without creating another storage bac…
Y1fe1Zh0u Sep 9, 2026
1aed238
Resolve autonomous input configuration without manufacturing human au…
Y1fe1Zh0u Sep 9, 2026
c3be794
Prevent product messages and deliveries from naming inconsistent sources
Y1fe1Zh0u Sep 9, 2026
8d90ca8
Keep conversation inputs and file publication under their product owners
Y1fe1Zh0u Sep 9, 2026
5912b94
Bind the confirmed unattended and A2A continuation boundaries before …
Y1fe1Zh0u Sep 9, 2026
fff6adb
Enforce unattended waits and keep delegated files out of shared Agent…
Y1fe1Zh0u Sep 9, 2026
864f359
Preserve real creators and delivery ownership without fabricating hum…
Y1fe1Zh0u Sep 9, 2026
2b309a6
Preserve message ownership when unattended Runs publish results
Y1fe1Zh0u Sep 9, 2026
ad0e164
Keep independent A2A work attributable and safely transferable
Y1fe1Zh0u Sep 9, 2026
9f58a14
Keep scheduled work private and independent of conversational lifetimes
Y1fe1Zh0u Sep 9, 2026
f93345b
Separate Channel delivery facts from execution completion
Y1fe1Zh0u Sep 9, 2026
5e22405
Read authorized documents without importing them into shared storage
Y1fe1Zh0u Sep 9, 2026
fae967b
Connect product inputs to the single Runtime through owned public bou…
Y1fe1Zh0u Sep 10, 2026
96bdb54
Make complete scheduled results readable without widening source access
Y1fe1Zh0u Sep 10, 2026
64f83bb
Record verified G006 behavior without overstating platform qualification
Y1fe1Zh0u Sep 10, 2026
7520f3c
Prevent remaining product work from being hidden by foundation comple…
Y1fe1Zh0u Sep 10, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
7 changes: 7 additions & 0 deletions .agents/notes/AGENTS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# AGENTS.md — Agent Notes

These rules apply to `.agents/notes/**` and supplement the repository-wide [instructions](../../AGENTS.md).

Before creating a Note, search active Notes for an existing owner or a decision that the new work supersedes. Update the owner when the decision is unchanged; create and cross-link a new Note when the decision changes.

Follow the lifecycle, classification, format, and alignment rules in [`README.md`](README.md). Do not copy current architecture or product documentation into a Note; link the owning source and record only the durable decision rationale, consequences, and verification contract.
64 changes: 64 additions & 0 deletions .agents/notes/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,64 @@
# Agent Notes

An Agent Note records a durable engineering decision: the problem it addresses, the chosen decision, the alternatives actually considered, the consequences, and the evidence that verifies the result.

Agent Notes do not replace product requirements, current architecture documentation, implementation plans, test reports, incident records, or commit history. They own why an engineering decision exists and what was deliberately given up.

## Path and classification

Every Agent Note uses this path:

```text
{lifecycle}/{class}/yyyy-mm-dd-topic.md
```

The lifecycle is one of:

- `proposed` — the decision is under discussion or implementation and has not become current repository behavior.
- `implemented` — the decision has shipped and the Note describes current repository behavior in the present tense.
- `rejected` — the proposal was declined and remains useful because it prevents a plausible repeated mistake.
- `archived` — a frozen historical snapshot of an implemented decision that no longer needs current-fact maintenance. Archived Notes are not current authority.

The class is one of:

- `architecture` — source structure, ownership, boundaries, runtime vocabulary, or durable execution semantics.
- `bug-fix` — a defect whose cause, contract, or prevention is likely to be revisited.
- `feature` — a product or platform capability decision.
- `process` — development, documentation, review, release, or operational workflow.
- `simplification` — removal, consolidation, or reduction of owned complexity.
- `testing` — test strategy, evidence boundaries, harnesses, or required gates.

## When to write one

A change is non-trivial when it alters observable behavior, architecture, ownership, a shared contract, Runtime semantics, lifecycle, persistence, configuration, compatibility, security, permissions, testing strategy, CI, release behavior, or another engineering decision a maintainer may reasonably revisit.

Update the Agent Note that already owns the decision. Create a new Note only when no current Note owns it or when the decision itself changes. Purely mechanical or strictly local changes with no behavioral, contractual, architectural, or process effect are exempt.

Agent Note work begins when the decision is discovered, not at Push time. The pre-push workflow is the final enforcement point: it inspects the complete outgoing change and blocks the Push when a required owning Note is missing or contradicts the code or commit history.

## Required format

Every active Agent Note begins with:

```markdown
# Agent Note: <title>

Status: proposed | implemented | rejected — <reason>
```

Every Note opens with `## Problem` and includes `## Alternatives considered`. Lifecycle-specific content follows:

- `proposed`: `## Proposal`, then plans, acceptance criteria, risks, and open questions only when they materially help decide or implement the proposal.
- `implemented`: `## Decision`, `## Consequences`, and the relevant verification evidence or named gaps. It describes current behavior, not a migration diary.
- `rejected`: retain the proposal and alternatives; put the rejection verdict on the `Status:` line.
- `archived`: retain `Status: implemented`, add `Archived: YYYY-MM-DD`, and freeze the file permanently.

Alternatives are recorded, never invented. State what each real alternative would have changed and why it lost.

## Updating and superseding decisions

Keep an implemented Note's paths, names, defaults, and mechanisms aligned with the code when the decision itself has not changed. Do not append change history; rewrite stale current facts in place.

Do not edit an existing Note into the opposite decision. Create a new proposed or implemented Note, cross-link both decisions, and retain the old rationale. Archive an implemented Note only when it is no longer useful as current guidance.

Code, the owning Agent Note, and commit history must agree. Code implements the decision, the Note owns durable rationale and the current contract, and the commit records the intent, scope, and verification of the concrete change.
5 changes: 5 additions & 0 deletions .agents/notes/archived/AGENTS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# AGENTS.md — Archived Agent Notes

Archived Agent Notes are frozen historical snapshots, not current authority. Never edit, reformat, move, delete, or repair a sealed archived Note. Record new facts and decisions in an active Note or current documentation.

Archiving may only move an implemented Note into the matching archived class, add `Archived: YYYY-MM-DD` below `Status: implemented`, and repair inbound links.
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
# Agent Note: Sandbox Execution Venue Ownership

Status: implemented — each code execution resolves one Sandbox backend and never retries through a separate legacy subprocess path.

Archived: 2026-09-03

## Problem

`execute_code` selects a backend with specific isolation, network, timeout, output, and cancellation semantics. A separate fallback executor could repeat code after an unknown outcome or run it under a policy the caller did not select. Deterministic per-Agent configuration errors must also fail before Session workspace resources are acquired, while result-formatting errors must not obscure the backend's already known execution result.

## Decision

The workspace entry resolves and validates the effective `SandboxConfig` and execution venue exactly once for both `execute_code` and `execute_code_e2b`, before acquiring a Session execution lease, materializing a workspace, flushing output, or dispatching code. The executor consumes that resolved configuration and does not read the configuration store again. Invalid values and configuration-store exceptions return a deterministic typed configuration failure without starting execution or workspace lifecycle work.

The resolved Sandbox backend is the sole execution venue. Pre-dispatch configuration or startup failures return a typed failure. Once `backend.execute` starts, an exception that leaves side effects unprovable returns `sandbox_execution_outcome_unknown`; it never starts a second backend. The platform may still explicitly resolve `execute_code` to the Sandbox subsystem's `subprocess` backend, including its configured isolation policy, but `agent_tools` has no independent legacy subprocess executor.

Result formatting is post-execution presentation, not execution evidence. If a backend formatter raises, the Tool outcome retains the `ExecutionResult` success and exit-code classification, emits a bounded fallback summary, records the formatter exception type in `metadata.formatter_error`, and logs a warning.

## Alternatives considered

**Keep the legacy subprocess executor as an emergency fallback.** Rejected because it changes the selected execution venue and may repeat code whose first outcome is unknown.

**Resolve per-Agent Sandbox configuration after Session workspace setup.** Rejected because deterministic configuration errors must fail before leases, materialization, or dispatch create lifecycle work.

**Treat formatter failure as execution failure or unknown execution.** Rejected because formatting runs after the backend has returned primary execution evidence and does not change whether code ran or its exit status.

## Consequences

An unavailable or invalid configured backend is visible instead of silently running code under a different policy. Timeout, output capture, process cleanup, and cancellation have one owner in the selected Sandbox backend rather than a duplicate `agent_tools` implementation. Deployments that intentionally use local execution continue through the configured Sandbox `subprocess` backend. Formatter failures may reduce summary detail, but callers retain the primary status, exit-code-derived classification, and explicit formatter evidence.

## Verification

`backend/tests/test_sandbox_execution_policy.py` covers configured-backend failure without venue switching, invalid configuration and configuration-store failure at the real workspace entry before lease/materialization/flush/dispatch, missing or invalid E2B configuration at the same boundary, post-dispatch unknown outcomes, and formatter failure with preserved result status and metadata. The typed E2B and content-outcome tests cover explicit cloud venue selection and the no-reexecution rule. Backend Ruff formatting, Ruff checks, Pyright, and the focused Sandbox tests are the required evidence for this boundary.
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
# Agent Note: Audit records share the mutation commit

Status: implemented — Audit supports append and bounded Tenant reads through the caller's transaction.
Archived: 2026-09-07

The agreed [asynchronous Audit replacement](../../proposed/architecture/2026-09-06-asynchronous-audit-observation.md) supersedes this coupling as the target design. This Note continues to describe the unchanged G003 code and tests until that replacement is implemented.

## Problem

A required Audit record must not disappear independently of the change it describes. Actor attribution must distinguish a human Membership, platform Account, Agent/Run or named System component without accepting contradictory identities.

## Decision

Audit owns an append-only public service and private persistence. Its closed actor union maps to database CHECKs and same-Tenant foreign keys; an Agent's optional Run must belong to that Agent. Metadata uses one explicitly supported JSON schema version with depth, item and complete UTF-8 byte bounds, finite JSON values and recursive rejection of known Secret field names. Returned metadata is copied rather than exposing mutable ORM state. Secret-free metadata remains a caller contract; key-name validation cannot identify every possible secret value.

Required Audit writes use the authoritative mutation's TransactionContext and commit or roll back with it. Audit does not start another transaction, write another owner's tables, publish success early, or provide update/delete operations. Tenant-administrator queries filter by Tenant and paginate in SQL. Actor references used only in schema fixtures are not product APIs.

## Alternatives considered

**Independent asynchronous Audit persistence.** Rejected for required records because the authoritative mutation could commit without its evidence.

**Several nullable actor IDs without a closed union.** Rejected because contradictory attribution could be persisted.

## Consequences

The outer application operation decides which mutations require Audit and supplies the actor. Logging remains independent observability, not a replacement for durable Audit. Product workflow orchestration is not implemented by this service.

## Verification

Real PostgreSQL tests exercise all actor variants, invalid mixed actors, cross-Tenant references, Agent/Run mismatch, metadata limits, version rejection, scoped reads and rollback of a public Identity mutation when the required Audit write fails. External delivery, user-facing Audit pages and product mutation coverage remain deferred to their owners.
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
# Agent Note: Atlassian Credential and Tool-Sync Boundary

Status: implemented — Atlassian credentials and assigned tools share one fail-closed persistence contract.

Archived: 2026-09-03

## Problem

Atlassian configuration spans the owning `ChannelConfig`, discovered shared `Tool` records, per-Agent assignments, and runtime credential dispatch. Persisting plaintext credentials, accepting undecryptable values as legacy plaintext, or committing those records independently would expose a secret at rest, dispatch ciphertext as a credential, or publish configuration success without matching tool assignments.

## Decision

`app.services.atlassian_tool_service` owns configuration reads, writes, deletion, connection tests, Provider discovery, shared Tool upsert, per-Agent assignment synchronization, transaction settlement, and assignment cleanup. API routes authenticate, normalize transport input, and map service outcomes to HTTP. Runtime imports the service directly and never imports an API module.

`ChannelConfig.app_secret` is the sole persisted Atlassian credential. Atlassian Tool config, AgentTool config, and `ChannelConfig.extra_config` never contain a credential alias; synchronization removes legacy copies while preserving unrelated config. API projections return only non-secret fields. Runtime obtains the decrypted key transiently through the strict service reader. Missing or corrupt ciphertext fails before Provider dispatch with an explicit configuration failure.

One service-owned identity predicate recognizes canonical, legacy, and imported Atlassian Tool records by normalized category, name, server name, or structured canonical URL. URL identity includes default-port, trailing-slash, query, and fragment variants for rejection, redaction, and cleanup. Generic Tool creation, update, deletion, server configuration, and per-Agent credential writes cannot bypass the category configuration owner. Generic Smithery and direct MCP imports reject both requested and existing Atlassian records before mutation. Runtime attaches the authoritative credential only to the canonical HTTPS endpoint without user information, query, or fragment; a matching display name cannot redirect the credential to another host.

Atlassian discovery, Tool upsert, AgentTool assignment, and ChannelConfig mutation reuse the request's `AsyncSession`. The service owns the single commit after synchronization succeeds. Missing credentials, discovery failure, empty discovery results, encryption failure, or persistence failure cannot return configuration success; the service rolls back instead. Both configuration routes await the same command and do not create unowned background tasks.

Deleting either Atlassian configuration surface removes the owning `ChannelConfig` and that Agent's Atlassian `AgentTool` assignments in the same transaction. Shared `Tool` discovery records remain available for other Agents. Cleanup failure rolls back both sides, so configuration deletion cannot leave an enabled orphan assignment.

Deployments that may contain pre-fix secret copies use `scripts/remove_legacy_atlassian_agent_tool_secrets.py`. The out-of-band job defaults to dry-run and processes matching Tool config, AgentTool config, and Atlassian `ChannelConfig.extra_config` in bounded batches. It removes only supported credential aliases, is idempotent, and preserves unrelated config and rows. Applying the cleanup is intentionally irreversible because legacy plaintext and corrupt ciphertext cannot be distinguished or restored safely; the authoritative encrypted `ChannelConfig.app_secret` is retained.

## Alternatives considered

- Preserve background synchronization and report eventual status separately. Rejected because no durable synchronization object or consumer currently owns that lifecycle.
- Keep Tool or AgentTool credential copies as runtime fallbacks. Rejected because either copy duplicates the ChannelConfig authority and expands the secret persistence surface.
- Treat decryption failure as legacy plaintext. Rejected because corrupt ciphertext and plaintext cannot be distinguished safely at the dispatch boundary.

## Consequences

Atlassian configuration may take as long as provider discovery, but success means the encrypted ChannelConfig and non-secret Tool/AgentTool records committed together. Provider unavailability is visible as an HTTP failure and does not publish partial configuration state. Removing configuration also removes only the requesting Agent's assignments; shared Tool records and other Agents' assignments are preserved. Platform startup may use `ATLASSIAN_API_KEY` transiently for discovery but never copies it into Tool config. Other MCP providers retain their existing credential contracts.

## Verification

Regression coverage verifies missing-key rejection before database work; category-case and URL identity variants; canonical route repair; requested and existing generic import rejection; current and proposed mutation rejection; API redaction; absence of Tool, AgentTool, and extra-config secret copies; shared-session synchronization before one service-owned commit; rollback on synchronization or commit failure; corrupt-ciphertext rejection; attacker-URL isolation; atomic deletion through both routes; and dry-run, selector, idempotence, and rollback behavior for legacy cleanup. Backend Pyright and the focused Atlassian, dynamic MCP, and LLM capability tests must remain green.
5 changes: 5 additions & 0 deletions .agents/notes/implemented/AGENTS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# AGENTS.md — Implemented Agent Notes

Implemented Agent Notes describe decisions that have shipped. Keep their paths, names, defaults, mechanisms, and verification facts aligned with current code in the same change that moves those facts.

Update factual realization in place, but do not rewrite the decision or its rationale into a different choice. A reversal requires a new Agent Note and cross-links between the decisions.
Loading
Loading