Commit Graph

1484 Commits

Author SHA1 Message Date
freemo 6dfd7e6b35 Merge pull request 'chore(noxfile): extend pre-migrated database template to slow_integration_tests and e2e_tests' (#2399) from chore/ci-execution-time-template-db-all-suites into master 2026-04-03 17:41:44 +00:00
freemo d650df3622 Merge pull request 'docs(timeline): update schedule adherence Day 54 (2026-04-03)' (#2371) from docs/timeline-day54-update-2026-04-03 into master 2026-04-03 17:41:04 +00:00
freemo dd363e2a45 docs(agents): clarify product-builder execution model and prevent implementation confusion
Added critical warning block and step-by-step checklist to product-builder.md
to ensure the agent always follows the correct workflow:

1. Launch 15 supervisors via curl to http://localhost:4096/session/:id/prompt_async
2. Monitor them with bash sleep loop (60 seconds between checks)
3. Re-launch any that exit

Key changes:
- ⚠️ Critical execution model warning at top (what to do / what NOT to do)
- 📊 Execution flow diagram showing all phases
-  Step-by-step Phase C checklist (C.1: Pre-flight, C.2: Launch, C.3: Monitor)
- 🔒 Clearer permission blocks with explicit bans on implementation agents
- 📝 Comments explaining why supervisors use curl not Task tool

This prevents the product-builder from trying to implement issues directly,
which is the supervisors' job. Product-builder is a process supervisor (like
systemd), not a worker.
2026-04-03 13:38:33 -04:00
freemo 33c1e4cd1a test(plan): add TDD issue-capture test for NamespacedName digit-start validation bug
This TDD test captures the buggy behavior where `NamespacedName.validate_namespace()`
and `validate_name()` accept names starting with digits, violating the spec requirement
that namespace and name components must start with a letter (consistent with
`_BARE_NAME_RE` in project.py).

Three failing scenarios demonstrate the bug:
1. parse() accepting namespace starting with digit ("123abc/my-action")
2. constructor accepting name starting with digit (local/"123-action")
3. constructor accepting namespace starting with digit ("999org"/valid-name)

Tagged with @tdd_expected_fail per Bug Fix Workflow.

Implements #2145
Blocks #2147
2026-04-03 13:38:33 -04:00
freemo 1c3f2dfc04 chore(noxfile): extend pre-migrated database template to slow_integration_tests and e2e_tests
Both slow_integration_tests and e2e_tests sessions require a database
(via setup_workspace() in helper scripts) but were not using the
pre-migrated template DB optimization already present in unit_tests,
integration_tests, and coverage_report.

Changes:
- slow_integration_tests: add _create_template_db() call, set
  CLEVERAGENTS_TEMPLATE_DB env var, upgrade from robot to pabot for
  parallel execution, add NO_COLOR/PYTHONPATH/PATH/compileall setup,
  add --include slow / --exclude discovery/code_blocks/wip/E2E/tdd_fixture
  tag filters, and update docstring.
- e2e_tests: add _create_template_db() call and set
  CLEVERAGENTS_TEMPLATE_DB env var. The existing setup_workspace()
  in helper_e2e_common.py already checks this env var and copies the
  template instead of running 25+ Alembic migrations.

No changes to test helper files are required since setup_workspace()
already implements the fast-path copy logic when CLEVERAGENTS_TEMPLATE_DB
is set.

ISSUES CLOSED: #2334
2026-04-03 17:31:35 +00:00
freemo 744abb9d62 docs(timeline): update schedule adherence Day 54 (2026-04-03) 2026-04-03 17:23:55 +00:00
freemo 8866c58bd4 fix(agents): prevent backlog groomer from closing PRs as duplicates of their tracking issues
Agent evolver identified a critical systematic pattern:
- Pattern: The backlog groomer was closing PRs as 'duplicates' of their
  linked tracking issues. A PR containing 'Closes #N' was being treated
  as a duplicate of issue #N, when it is actually the implementation
  delivery vehicle for that issue.
- Evidence: At least 12 PRs were incorrectly closed (#1219, #1236, #1247,
  #1269, #1267, #953, #1198, #1220, #1237, #1238, #1246, #1248) — all
  with the same 'Duplicate Detected' comment pattern from groomer-1.
- Fix: Added explicit instructions to skip PRs during duplicate detection,
  added a guard in the analysis loop pseudocode, and added a rule in the
  Important Rules section.

This change requires human approval before taking effect.

ISSUES CLOSED: #2180
2026-04-03 07:09:23 +00:00
freemo 0d768b78fa Merge pull request 'docs(tui): document PermissionQuestionWidget and add CHANGELOG entry' (#2181) from docs/update-tui-permission-question-widget into master 2026-04-03 06:41:25 +00:00
freemo d66887766f docs(tui): document PermissionQuestionWidget and add CHANGELOG entry
Add PermissionQuestionWidget API documentation to docs/api/tui.md including
method table, key bindings, PermissionDecisionEvent dataclass, and
render_permission_question() helper reference. Add corresponding CHANGELOG
entry under [Unreleased] Added section.

Refs: #997
2026-04-03 06:39:51 +00:00
freemo 0be3f85c56 feat(tui): implement Permission Question Widget
Implement inline permission question widget for quick allow/reject
decisions within the conversation stream with file diff context.

ISSUES CLOSED: #997
2026-04-03 05:56:27 +00:00
eugen.thaci f66fb5a19a docs(spec): align ASCII UI tables in specification and related pages
Align Unicode box-drawing blocks and related tables in specification.md,
ADR-044/045/046, and reference pages for consistent MkDocs rendering.

ISSUES CLOSED: #1171
2026-04-03 04:55:21 +00:00
freemo 2770f6afdd docs: restructure [Unreleased] CHANGELOG and add entries for recent merged PRs
Consolidate duplicate Added/Fixed headings in [Unreleased] section into single canonical sections per Keep a Changelog format. Add new entries for DomainBaseModel (#1941) and TDD bug-capture test (#1094).

Co-authored-by: Jeffrey Phillips Freeman <the@jeffreyfreeman.me>
Co-committed-by: Jeffrey Phillips Freeman <the@jeffreyfreeman.me>
2026-04-03 04:16:19 +00:00
freemo bbfa5bef01 Merge pull request 'chore(agents): add open PR awareness to UAT tester duplicate avoidance' (#1446) from improvement/uat-tester-check-open-prs into master 2026-04-03 04:13:10 +00:00
freemo 51fcd13220 Merge pull request 'chore(agents): add pre-PR rebase step to issue worker to prevent stale conflicts' (#1407) from improvement/issue-worker-rebase-before-pr into master 2026-04-03 04:10:46 +00:00
brent.edwards df41f64f21 test: add TDD bug-capture test for #989 — JSON decode crash in persistence
Add a new Behave TDD regression scenario that persists corrupt automation-profile JSON and verifies repository reads do not leak raw JSONDecodeError. The scenario is tagged with @tdd_bug, @tdd_bug_989, and @tdd_expected_fail so it currently inverts the intentional assertion failure and will require tag removal when bug #989 is fixed.\n\nAlso stabilize an unrelated integration fixture in robot/resource_dag.robot by sharing a single SQLAlchemy session in inline scripts; this removes nondeterministic visibility of flushed resource-type rows and keeps required nox integration quality gates deterministic for this branch.\n\nISSUES CLOSED: #1094
2026-04-03 03:58:45 +00:00
freemo f6ba8fee56 chore(agents): add pre-PR rebase step to issue worker
Agent evolver identified a systematic pattern:
- Pattern: PR stale/conflict cascade
- Evidence: 11+ PRs were approved but closed without merge due to
  conflicts. PRs #1248, #1247, #1237, #1236, #1220, #1219, #1238,
  #1246, #1269 were all bulk-closed as stale. Reviewer notes on
  #1248, #1220, #1219, #1252 explicitly mention 'merge blocked by
  conflicts'. With 16 parallel workers, master moves fast and branches
  created minutes earlier are already behind by the time PRs are created.
- Fix: Add a rebase-onto-latest-master step (Phase 3, Step 3.0) in
  ca-issue-worker before committing and creating the PR. This ensures
  the branch is current when the PR is opened, dramatically reducing
  the chance of merge conflicts when the reviewer processes it.

This change requires human approval before taking effect.
2026-04-03 03:57:52 +00:00
freemo 81319b575a Merge pull request 'fix(agents): add two-phase claim protocol to prevent duplicate PR reviews' (#1326) from improvement/pr-reviewer-double-claim-prevention into master 2026-04-03 03:41:30 +00:00
freemo 9c7876a913 chore(agents): add open PR awareness to UAT tester duplicate avoidance
Agent evolver identified a systematic pattern:
- Pattern: UAT tester filing bugs for features already being implemented
- Evidence: 25+ UAT bugs filed for TUI MainScreen features (#1329-#1355)
  that already had open implementation PRs (#1219, #1236, #1237, #1238,
  #1246, #1247, #1248, etc.). The tester reported 'missing sidebar',
  'missing tab bar', 'missing escape navigation' etc. while PRs
  implementing these exact features were open and under review.
- Fix: Add step 4 to duplicate avoidance requiring the tester to check
  for open PRs before filing 'missing feature' bugs.

This change requires human approval before taking effect.
2026-04-03 03:38:48 +00:00
freemo c38be2eed8 fix(ci): address review feedback on nightly-quality workflow
- Add missing 'nox -s format -- --check' step (parity with ci.yml)
- Add NOX_DEFAULT_VENV_BACKEND: uv to global env and each nox step
- Fix quality gates script invocation (was using invalid nox session '3.13')
- Fix report artifact paths to match actual nox session output locations
  (build/coverage.json and build/bandit-report.json instead of build/reports/)
- Add mkdir for build/reports before writing quality-trend.json

ISSUES CLOSED: #1537
2026-04-03 03:37:10 +00:00
freemo 36ac24f2dd chore(ci): refactor nightly-quality workflow to use nox sessions
- Replaced manual uv pip install with nox invocations for all quality checks
- Mapped workflow steps to nox sessions:
  - Lint: ruff format + ruff check → nox -s lint
  - Type checking: pyright → nox -s typecheck
  - Security: bandit + semgrep → nox -s security_scan
  - Dead code: vulture → nox -s dead_code
  - Complexity: radon → nox -s complexity
  - Tests + coverage: behave → nox -s unit_tests + coverage_report
- Removed explicit dependency installation steps (nox handles this)
- Removed RUFF_VERSION env var (nox uses pinned versions from pyproject.toml)
- Workflow now consistent with ci.yml approach

Fixes #1537
2026-04-03 03:37:10 +00:00
freemo 28ddfe3873 Merge pull request 'chore(agents): add finding validation requirements to bug hunter' (#1445)
chore(agents): add finding validation requirements to bug hunter

Adds mandatory finding validation checklist to ca-bug-hunter agent prompt
to reduce false-positive and speculative issue filings.

Reviewed-by: ca-pr-self-reviewer
2026-04-03 03:35:47 +00:00
freemo 977cacc299 Merge pull request 'refactor(domain): extract shared model_config into a base Pydantic model' (#2014) from fix/domain-pydantic-base-model-config into master 2026-04-03 03:29:26 +00:00
freemo 108d87e1bb docs: update CHANGELOG and A2A API docs for recent merged PRs
Add CHANGELOG [Unreleased] entries for 6 recently merged commits:
- feat(tui): shell danger detection patterns (#1003)
- fix(a2a): JSON-RPC 2.0 wire format compliance — BREAKING field rename (#1501)
- fix(cli): disallow mixing legacy and v3 plan workflows (#1577)
- fix(cli): actor add rich output missing panels
- fix(infra): E2E suite centralized database initialization (#1023)
- ci(pipeline): parallelized static analysis jobs

Update docs/api/a2a.md to reflect JSON-RPC 2.0 field name changes:
A2aRequest.operation → method, A2aResponse.data → result, etc.
2026-04-03 02:43:00 +00:00
freemo a538713134 refactor(agents): enforce strict curl-only permissions for all supervisors
BREAKING CHANGE: Supervisors can no longer use Task tool to launch workers

Major refactor of the permission model for product-builder and all 15
continuous supervisors to enforce strict separation: supervisors MUST use
curl/prompt_async via bash to launch workers, and CANNOT use the Task tool.

Key Changes:

1. Product-Builder Permissions (product-builder.md):
   - Removed ALL Task permissions for supervisors (previously had 17)
   - Kept Task permissions ONLY for 7 one-shot agents:
     ca-project-bootstrapper, ca-ref-reader, ca-issue-finder,
     ca-session-persister, ca-product-verifier, ca-milestone-reviewer,
     ca-final-reporter
   - Restricted bash to: echo, curl, sleep, jq only
   - Removed Phase B (Architecture) and Phase C.1 (Planning)
   - Updated to launch 15 supervisors (up from 13)

2. New Continuous Supervisors:
   - ca-architect: Converted from one-shot to continuous supervisor
     Monitors for spec needs, new milestones, ambiguities
   - ca-epic-planner: Converted from one-shot to continuous supervisor
     Monitors for milestones without issues, incomplete epics

3. All 15 Supervisors - Standardized Permissions:
   - Removed ALL Task permissions for launching workers
   - Workers MUST be launched via curl to OpenCode Server prompt_async API
   - Added 'jq *' for JSON parsing (replacing python3)
   - Restricted bash to specific commands only (deny all, allow specific)
   - Git commands restricted to specific operations (clone*, fetch*, etc.)
   - Directory operations (cd, mkdir, rm -rf) only where needed

4. Supervisor-Specific Updates:
   - issue-implementor: Removed ca-issue-worker task permission
   - ca-continuous-pr-reviewer: Added git + directory ops, removed worker tasks
   - ca-uat-tester: Added read-only file/git commands, removed self-dispatch
   - ca-bug-hunter: Restricted git to read-only, removed self-dispatch
   - ca-test-infra-improver: Added read-only commands, removed self-dispatch
   - ca-human-liaison: Removed ca-epic-planner/ca-architect task permissions
   - ca-agent-evolver: Added git + directory operations
   - ca-architecture-guard: Added read-only + git clone operations
   - ca-spec-updater: Added git + directory operations
   - ca-backlog-groomer: Removed ca-epic-planner task permission
   - ca-docs-writer: Added git + directory operations
   - ca-timeline-updater: Added git + directory operations
   - ca-project-owner: Minimal permissions (curl, jq, sleep only)

Impact:
- Proper separation of concerns: supervisors orchestrate, workers execute
- No possibility of supervisors blocking on Task tool calls
- True fire-and-forget worker launching via prompt_async
- Consistent permission model across all 15 supervisors
- Maximum parallelism with proper isolation

Architecture now enforces: Product-builder → 15 supervisors → N workers
All launched via curl/prompt_async, NO Task tool for supervisors.
2026-04-03 02:33:00 +00:00
freemo 859c564f69 Merge pull request 'fix(infra): ensure E2E suite setup initializes database before CLI commands' (#1177) from fix/e2e-auto-init into master 2026-04-03 02:06:59 +00:00
freemo 650b1038b6 refactor(domain): extract shared model_config into a base Pydantic model
Introduce DomainBaseModel in src/cleveragents/domain/models/base.py that
defines the single shared model_config (str_strip_whitespace, validate_assignment,
arbitrary_types_allowed=False, populate_by_name, use_enum_values) previously
duplicated verbatim across five domain model files.

Update 14 classes across five files to inherit from DomainBaseModel instead
of pydantic.BaseModel directly, removing all inline model_config duplication:
- aimodelscredentials/ai_models_credentials.py (ModelProviderOption)
- aimodelserrors/ai_models_errors.py (ModelError, FallbackResult)
- aimodelsproviders/ai_models_providers.py (ModelProviderExtraAuthVars,
  ModelProviderConfigSchema)
- auth/auth.py (AuthHeader, TrialPlansExceededError, TrialMessagesExceededError,
  BillingError, ApiError, ClientAccount, ClientAuth)
- planconfig/plan_config.py (PlanConfig, ConfigSetting)

Pure structural refactor — no behavioral changes. Models with different
configurations (acms, aimodels_custom, etc.) are left untouched.

Add BDD feature (22 scenarios) and Robot integration tests (8 test cases)
verifying inheritance, config correctness, and no-duplication invariants.

ISSUES CLOSED: #1941
2026-04-03 02:01:45 +00:00
brent.edwards 998aaf25f8 fix(infra): ensure E2E suite setup initializes database before CLI commands
Centralize E2E initialization in common suite setup so DB-dependent CLI commands no longer rely on per-suite or per-test init workarounds. This also sanitizes suite-home names to prevent invalid path-derived initialization failures in isolated Robot runs.

ISSUES CLOSED: #1023
2026-04-03 01:43:27 +00:00
freemo 8f24887ecf Merge pull request 'fix(cli): disallow mixing legacy and v3 plan workflows' (#1577) from fix/prevent-legacy-v3-mixing into master 2026-04-03 01:24:06 +00:00
freemo 50a5e9672b feat(tui): implement shell danger detection patterns
Implement dangerous shell pattern detection with configurable pattern registry, danger level classification, and user warning system.

Closes #1003

ISSUES CLOSED: #1003
2026-04-03 01:15:23 +00:00
freemo 70e2ce4386 Merge pull request 'fix(infra): resolve TLS handshake failure on git.dev.cleveragents.com' (#1865) from fix/infra-tls-handshake-failure-git-dev into master 2026-04-03 01:13:31 +00:00
freemo b6ea4cd1e6 Merge pull request 'fix(cli): add missing Type field, Config, Capabilities, and Tools panels to actor add rich output' (#1969) from fix/actor-add-rich-output-missing-panels into master 2026-04-03 01:12:34 +00:00
freemo b7574a4fdd Merge pull request 'fix(a2a): rename A2aRequest/A2aResponse fields to comply with JSON-RPC 2.0 wire format' (#1990) from fix-1501-a2a-jsonrpc-wire-format into master 2026-04-03 01:12:34 +00:00
freemo a126a1c5bb Merge pull request 'fix(tests): resolve flakiness in test_example_flaky_test' (#1810) from fix/test-infra-flaky-test-example into master 2026-04-03 01:09:32 +00:00
freemo 6228129919 Merge pull request 'ci(pipeline): parallelize lint, typecheck, security, and quality jobs' (#1633) from task/ci-parallelize-static-analysis into master 2026-04-03 01:08:43 +00:00
freemo 971d6a154d Merge pull request 'test(actors): fix actor examples missing provider fields and incorrect name' (#1733) from fix-1504-actor-examples-missing-fields into master 2026-04-03 01:08:40 +00:00
freemo a39c718363 Merge pull request 'chore(ci): extract behave-parallel runner script from noxfile.py into scripts/' (#1775) from chore/extract-behave-parallel-script into master 2026-04-03 01:08:39 +00:00
freemo 55b9b3605e fix(deps): upgrade aiohttp to 3.13.4 to remediate CVE-2026-34515 open redirect
Add explicit aiohttp>=3.13.4 dependency constraint to pyproject.toml to remediate CVE-2026-34515, a high-severity open redirect vulnerability. The lockfile already resolves aiohttp to 3.13.5 which satisfies the constraint.

Closes #1544
2026-04-03 01:08:34 +00:00
freemo b21e2b1eb1 Merge pull request 'fix(a2a): reformat SseEventFormatter output to JSON-RPC 2.0 notification structure' (#1841) from fix/a2a-sse-event-formatter-jsonrpc2-compliance into master 2026-04-03 01:07:53 +00:00
freemo fe1c3f7cc8 Merge pull request 'chore(ci): consolidate uv cache key across all workflow jobs' (#1644)
Consolidates all per-job uv cache key prefixes across CI workflow files into a single shared key, eliminating redundant package downloads. Also adds missing uv cache steps to the build job and nightly-quality.yml.

Closes #1535
2026-04-03 01:07:33 +00:00
freemo 921c13f410 fix(agents): restore server mode + prompt_async supervisor launch from 9bbec0e6
Restores the working OpenCode server mode + curl-based async supervisor
launch functionality from commit 9bbec0e6 (2026-04-02) and updates it for
the current 13-supervisor architecture.

Changes applied to 7 agent files (938 insertions, 221 deletions):

1. product-builder.md: Restored from 9bbec0e6 and updated for 13 supervisors
   - Full bash permissions for curl/sleep
   - Server URL: http://localhost:4096
   - Launch via POST /session + POST /session/:id/prompt_async
   - Session resume (adopts existing [CA-AUTO] sessions)
   - Added ca-test-infra-improver and ca-project-owner to launch sequence
   - Updated concurrent worker calculations (~5N + ~8 singletons)

2. issue-implementor.md: Restored curl-based worker dispatch
   - 10-second polling loop with bash sleep
   - Worker sessions via prompt_async
   - Session resume for existing workers

3. ca-continuous-pr-reviewer.md: Restored curl dispatch pattern
4. ca-uat-tester.md: Restored curl pool mode
5. ca-bug-hunter.md: Restored curl pool mode
6. ca-test-infra-improver.md: Added self-dispatch permission
7. ca-session-cleanup.md: Restored utility agent

Architecture: 5 pool supervisors (N workers each) + 8 singleton supervisors
= 13 total supervisors running async via prompt_async.

Replaces the broken prompt_async implementation from commit 074c472e that
removed supervisors from task permissions without working server launch.

To use: Start OpenCode with --port 4096, then launch product-builder.

Refs: commit 9bbec0e6 (working version), commit 074c472e (broken version)
2026-04-02 20:56:06 -04:00
freemo 72a9a17a67 docs(timeline): update schedule adherence Day 54 (2026-04-03)
Day 54 morning update. No merges overnight. Agents created 100+ new issues.

Key changes:
- Appended Day 54 schedule adherence entry
- Updated today marker to 2026-04-03 in both gantt charts
- Open bugs: 35 → 50 (+15 new bugs from agents overnight)
- Open PRs: 79 → 84 (+5 new fix/CI branches)
- Open issues: 400 → 500 (+100 new from agents overnight)
- M3 (v3.2.0): 82% → 75% (212/281, milestone grew 256→281)
- M4 (v3.3.0): 79% → 78% (99/127, milestone grew 126→127)
- M5 (v3.4.0): 88% → 87% (126/145, milestone grew 143→145)
- M6 (v3.5.0): 77% → 71% (172/241, milestone grew 221→241)
- M7 (v3.6.0): 73% → 68% (120/177, milestone grew 164→177)
- M8 (v3.7.0): 36% → 29% (54/185, milestone grew 152→185)
- M9 (v3.8.0): 40% → 26% (64/242, milestone grew 160→242)
2026-04-03 00:33:20 +00:00
freemo f0ff4bce69 fix(deps): upgrade aiohttp to 3.13.4 to remediate CVE-2026-34515 open redirect
Add explicit aiohttp>=3.13.4 dependency constraint to pyproject.toml to
remediate CVE-2026-34515, a high-severity open redirect vulnerability in
aiohttp that affects the A2A server HTTP transport, MCP tool source
fetching, and agent communication layers.

The uv.lock already resolves aiohttp to 3.13.5 which satisfies the
>=3.13.4 constraint. Adding the explicit constraint ensures vulnerable
versions (<3.13.4) cannot be installed even if upstream transitive
dependency constraints are loosened.

ISSUES CLOSED: #1544
2026-04-03 00:32:00 +00:00
freemo 9c6d69153e fix(a2a): rename A2aRequest/A2aResponse fields to comply with JSON-RPC 2.0 wire format
Rewrites the A2aRequest and A2aResponse Pydantic models to use the field
names mandated by the JSON-RPC 2.0 specification, fixing a fundamental
protocol compliance issue that prevented external A2A-compliant clients
from communicating with the server.

Changes:
- A2aRequest: a2a_version→jsonrpc (fixed '2.0'), request_id→id,
  operation→method; auth field removed (not in JSON-RPC 2.0)
- A2aResponse: a2a_version→jsonrpc, request_id→id, status+data→result
  (success path), timing_ms removed; added _result_xor_error validator
  enforcing mutual exclusion of result and error fields
- A2aLocalFacade.dispatch(): updated to use request.method, request.id,
  result=data, error=A2aErrorDetail(...)
- A2aHttpTransport.send(): updated to use request.method
- CLI call sites (session.py, plan.py): updated A2aRequest(method=...)
  and response.result / response.error field access
- All existing A2A Behave step files updated to new field names
- New 35-scenario Behave feature (a2a_jsonrpc_wire_format.feature)
  covering serialisation, deserialisation, validation, and facade dispatch
- New 7-test Robot Framework suite (a2a_jsonrpc_wire_format.robot)
  for end-to-end wire format verification

ISSUES CLOSED: #1501
2026-04-03 00:29:46 +00:00
freemo d430d671a0 fix(cli): add missing Type field, Config, Capabilities, and Tools panels to actor add rich output
Extended `_print_actor()` to render the full spec-required output for
`agents actor add`: the Actor Added panel now includes a Type field, and
three additional panels (Config, Capabilities, Tools) plus a success
status line are rendered when `show_add_panels=True`.

- Add `Type:` field to the Actor Added panel (from `config_blob["type"]`)
- Implement Config panel: Path, Hash, Options count, Nodes count, Edges count
- Implement Capabilities panel: bulleted list (rendered only when non-empty)
- Implement Tools panel: Rich table with Tool, Read-Only, Safe columns
  (rendered only when non-empty; string tool entries default to yes/yes)
- Add `✓ OK Actor added` success status line after all panels
- Pass `config_path` and `show_add_panels=True` from `add()` command
- Add Behave BDD scenarios covering each new panel and the success line
- Add Robot Framework integration test verifying the full rich output

ISSUES CLOSED: #1499
2026-04-03 00:23:58 +00:00
freemo 300a5d6ddc fix(cli): disallow mixing legacy and v3 plan workflows
Add ULID format validation to all v3 plan commands to prevent users from
accidentally mixing legacy ('agents tell') and v3 ('agents plan use')
workflows. The two systems use separate storage backends and cannot be
mixed; this change detects the mismatch early and provides actionable
error messages.

Changes:
- Add _validate_plan_ulid() with proper Crockford Base32 regex
  (^[0-9A-HJKMNP-TV-Z]{26}$, re.IGNORECASE) that correctly rejects
  invalid characters (I, L, O, U), hyphens, and wrong-length strings
- Add _PLAN_ULID_RE compiled regex and _ULID_VALIDATION_ERROR_MSG constant
  with actionable guidance explaining the legacy/v3 incompatibility
- Apply ULID validation to all v3 commands: execute_plan,
  _lifecycle_apply_with_id, lifecycle_apply_plan, plan_status,
  plan_errors, cancel_plan (only on user-provided IDs, not auto-discovered)
- Update _LEGACY_DEPRECATION_MSG and tell/build command warnings to
  explicitly state that the two workflows are INCOMPATIBLE and cannot be mixed
- Add comprehensive BDD tests in features/plan_ulid_validation.feature
  with step definitions using Typer CLI runner (not subprocess)
- Update CONTRIBUTING.md with 'Workflow Choice: Legacy vs. v3 Plan
  Lifecycle' section documenting the incompatibility and migration path

ISSUES CLOSED: #1560
2026-04-03 00:01:48 +00:00
freemo 8c81f13758 fix(infra): resolve TLS handshake failure on git.dev.cleveragents.com
The TLS handshake failure on git.dev.cleveragents.com was caused by the
hostname being absent from the certificate's Subject Alternative Names
(SANs), or by SNI virtual-host misconfiguration on the server side.

This commit delivers the repository-side remediation:

- scripts/check-tls-cert.py: New TLS certificate health-check script.
  Connects to a hostname, verifies the certificate's SANs include the
  target hostname, checks expiry, and reports errors/warnings.  Accepts
  an injectable SSLContext for unit testing without real network access.
  Supports wildcard SAN matching and configurable expiry warning threshold.

- docs/development/ops-runbook.md: New ops runbook documenting the full
  certificate renewal procedure (Let's Encrypt/certbot and manual CA),
  SNI misconfiguration diagnosis steps, expiry monitoring with cron, and
  recommended alert thresholds (30/14/7/0 days).

- features/tls_certificate_check.feature: 14 Behave scenarios tagged
  @tdd_issue @tdd_issue_1543 covering: missing SAN detection, valid SAN
  acceptance, expired certificate detection, expiry warning threshold,
  TLS handshake errors, connection timeouts, connection refused, wildcard
  SAN matching, and _hostname_matches_san unit tests.

- features/steps/tls_certificate_check_steps.py: Step definitions for
  the above feature, using unittest.mock to inject SSL contexts and
  socket connections so no real network calls are made.

- mkdocs.yml: Added Ops Runbook to the Development section navigation.

The actual server-side certificate renewal (adding git.dev.cleveragents.com
as a SAN and reloading the web server) must be performed by the server
administrator following the procedure in docs/development/ops-runbook.md.

Closes #1543

ISSUES CLOSED: #1543
2026-04-02 23:59:37 +00:00
freemo ee1710dc3e docs(timeline): update schedule adherence Day 53 (2026-04-02) night refresh
Night refresh after UAT/bug-hunt/CI agents created 50+ new issues.

Key changes:
- Open bugs: 6 → 35 (UAT/bug-hunt agents created 29 new bugs #1749-#1791)
- Open PRs: 74 → 79 (+5 new CI/security PRs)
- Open issues: 339 → 400 (+61 new from UAT/bug-hunt/CI agents)
- M3 (v3.2.0): 85% → 82% (211/256, milestone grew from 236→256)
- M4 (v3.3.0): 80% → 79% (99/126, milestone grew from 124→126)
- M5 (v3.4.0): 89% → 88% (126/143, milestone grew from 142→143)
- M6 (v3.5.0): 79% → 77% (171/221, milestone grew from 214→221)
- M7 (v3.6.0): 75% → 73% (120/164, milestone grew from 150→164)
- M8 (v3.7.0): 38% → 36% (55/152, milestone grew from 107→152)
- M9 (v3.8.0): 35% → 40% (64/160, milestone grew from 49→160)
- Critical: coverage at 37% (#1782), AmbiguousStep crash (#1791)
2026-04-02 23:57:25 +00:00
freemo 8843872ce0 fix(tests): resolve flakiness in test_example_flaky_test
Add deterministic BDD feature and step definitions to resolve the
flaky-test detection alert for test_example_flaky_test (issue #1542).

Root cause: the async-job heartbeat step previously relied on a fixed
time.sleep(0.01) that was insufficient on fast CI runners. When two
consecutive datetime.now(UTC) calls returned the same microsecond value
the 'heartbeat updated' assertion failed intermittently.

The busy-wait guard (already present in async_execution_steps.py) is
the correct fix. This commit adds a dedicated feature that:

- Validates the heartbeat timestamp strictly advances after the
  busy-wait (the primary test_example_flaky_test scenario)
- Covers rejection of heartbeat recording for queued and completed jobs
- Adds a bounded heartbeat step that asserts the busy-wait terminates
  within a wall-clock budget, preventing infinite hangs on broken clocks

ISSUES CLOSED: #1542
2026-04-02 23:53:13 +00:00
freemo 288ff276b3 fix(a2a): reformat SseEventFormatter output to JSON-RPC 2.0 notification structure
- Add _EVENT_TYPE_TO_METHOD class-level mapping (ClassVar[dict[str, str]]) to
  convert A2A event types to JSON-RPC 2.0 method names:
  TaskStatusUpdateEvent → task/statusUpdate
  TaskArtifactUpdateEvent → task/artifactUpdate
- Refactor SseEventFormatter.format() to produce JSON-RPC 2.0 notification
  envelope: {"jsonrpc": "2.0", "method": "...", "params": {...}}
- Move event data fields into params object; include taskId (from plan_id)
  in params when plan_id is present, per spec §Streaming Architecture
- Remove non-spec fields (event_id, event_type, timestamp, plan_id) from
  the data payload; these remain in SSE envelope headers (event: and id:)
- Update BDD feature to verify JSON-RPC 2.0 structure for both event types,
  events with/without plan_id, custom data in params, and exclusion of
  non-spec fields
- Fix pre-existing type errors in step definitions: replace try/except
  ImportError pattern with direct imports and use behave.runner.Context
  for proper static typing (0 pyright errors)

ISSUES CLOSED: #1502
2026-04-02 23:53:13 +00:00
freemo 37586882b3 chore(ci): extract behave-parallel runner script from noxfile.py into scripts/
Move the large embedded `_BEHAVE_PARALLEL_CLI_SOURCE` string constant out of
noxfile.py and into a standalone `scripts/run_behave_parallel.py` module.

The `_install_behave_parallel()` helper now reads the script from disk via
`Path(__file__).parent / 'scripts' / 'run_behave_parallel.py'` instead of
embedding the source as a raw string literal. This allows ruff to lint and
type-check the runner independently, and makes noxfile.py significantly
shorter and easier to read.

No functional changes: the installed `behave-parallel` entry point is
identical to the previous embedded version. Parallel and sequential modes,
coverage integration, and the multiprocessing fork model are all preserved.

Fixed two SIM105 lint violations in the extracted script (replaced
try/except/pass with contextlib.suppress).

ISSUES CLOSED: #1538
2026-04-02 23:44:30 +00:00