Repository navigation
Conversation
HEAD archive owner-preflight and fake-SQL contracts passed offline. Live validation is not included.
Checkpoint only: explicit prepared/active/halted metadata and pinned policy/config/period identity, with UNKNOWN historical usage. Runtime accounting is not connected; actual spending limits are not enforced by this lifecycle layer. No reserve/settle, provider, runner, DAV-53 or U03 integration is included. Live acceptance remains pending. Verified in the f466d9c HEAD archive: independent import and 48 focused temporary-path tests pass; scope/secret scans and diff checks pass.
Checkpoint only: runtime binding candidate has a known SQLite descriptor lifetime blocker. Focused proof: 79 passed, 2 failed; original 57 regression tests pass. No runner/provider wiring, live initialization or activation; live acceptance remains open. Preserve UNKNOWN history and original worktree WIP.
Checkpoint: avoid auxiliary ledger descriptors while SQLite connections are open; verify bound inode identity with stat and use SQLite FULL synchronization. Preserve canonical configuration and shared atomic period accounting. Focused temporary-environment regression proof passed; no runner/provider wiring or live initialization, activation or acceptance. Historical spend remains UNKNOWN.
Checkpoint: bind only the standalone DAV58 runner to an explicitly selected existing active canonical period. Preserve legacy no-argument authorization callers, shared purpose accounting and historical UNKNOWN spend. Focused temporary SQLite and MockTransport verification passed; no real key, provider request, period preparation or activation. Provider effectiveness flags remain false and live acceptance remains open.
Resolves the two conflicted paths, keeping both sides' intent: - services/agent/README.md: main restructured this file so the canonical guide (docs/DEVELOPMENT.md) owns the detailed contracts, and the block removed here was the only branch-only content in the file. Take main's structure, and keep the two new opt-in runners discoverable through a short pointer section rather than a second copy of the guide. - services/agent/src/deepseek_model.py: keep this branch's shared-budget reservation, settlement and fail-closed accounting guard, while taking main's extraction of `_api_messages` and `_check_prompt_budget`. The auto-merge also spliced `decide()` outside the conflict markers: main's `_check_prompt_budget` made `prompt_tokens_estimate` a local, while `reserve()` still needed it. The estimate now has a single owner, `_prompt_tokens_estimate()`, called by both the check and `decide()`. Verified on this merge: services/agent 1124 passed / 1 skipped (optional qdrant_client absent); `./mvnw compile -B` BUILD SUCCESS; focused LearningPlan gate 35 passed, including LearningPlanWriteIT's 6 real-MySQL Testcontainers idempotency and owner-scoping tests. Co-Authored-By: Claude Code <noreply@anthropic.com>
Keep model tools read-only and require explicit confirmation before Java\nlearning-plan writes. Persist private workflow state and reconcile unknown\nwrites through the original idempotency key.\n\nBind acceptance evidence to source, budget identity, and raw receipts.\nMissing original accounting or unauthorized purposes remain fail-closed;\noffline checks never grant spend or mark real acceptance complete.
Resolve CVE-2026-47884 with Spring Framework 7.0.9 via the supported Boot 4 BOM. Preserve Java 17, Jackson 2 payloads, authentication, Redis SCAN policy and OTLP tracing while migrating owner auto-configuration and test modules. Verify full unit reactor, real MySQL learning-plan writes, Boot/Dubbo local RPC and security regressions; retain all image vulnerability gates.
Boot 4.1.1 ships spring-boot-grpc-server through the classic autoconfigure aggregate while wildcard-excluding its spring-grpc-core dependency, so the module registers GrpcDisableCsrfHttpConfigurer without the class it loads on every HttpSecurity build. Exclude it where spring-boot-starter-classic is declared, which covers every consumer, and drop the now-redundant per-consumer workaround in Core.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1f1bf0ce04
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| return await run_readonly_graph( | ||
| model, tools, user_input, max_rounds=max_rounds | ||
| ) |
There was a problem hiding this comment.
Pass the requested timeout to the graph
When callers request more than 30 seconds, this delegation silently retains run_readonly_graph's 30-second default, so existing 90-second real-model runs such as e2e_model_qa.py and e2e_account_isolation.py now fail halfway through their advertised allowance. Forward total_timeout into the graph instead of wrapping a second, longer timeout around a call that always expires first.
Useful? React with 👍 / 👎.
| async def operation(client: UlticodeClient, owner: str): | ||
| submission = await client.get_my_submission(source_id) | ||
| source, status = validate_submission_facts(submission) | ||
| if source.lower() != source_id: |
There was a problem hiding this comment.
Preserve source-not-owned errors during thread creation
When sourceSubmissionId does not exist or belongs to another account, this call raises UlticodeServiceError(40400, 404), but unlike _verify_source this path does not translate it; with_session subsequently maps every non-auth service error to 502 upstream_unavailable. Consequently a normal invalid/foreign source is reported as an infrastructure outage rather than the documented 404 source_not_owned, so handle the precise 404 response here before it reaches the generic wrapper.
Useful? React with 👍 / 👎.
| status_claim = re.search( | ||
| r"\bstatus\s*(?:is|=|:)\s*([A-Za-z_-]+)|状态\s*(?:为|是|=|:)\s*([A-Za-z_-]+)", | ||
| text, flags=re.IGNORECASE, | ||
| ) | ||
| if status_claim and isinstance(actual_status, str) and ( | ||
| (status_claim.group(1) or status_claim.group(2)).casefold() != actual_status.casefold() | ||
| ): |
There was a problem hiding this comment.
Match the complete submission status
For multi-word statuses, this regex captures only the first word, so a correct answer such as The submission status is Wrong Answer is compared as Wrong against the actual Wrong Answer and rejected with answer_submission_fact_mismatch. The same occurs for common values such as Time Limit Exceeded and Runtime Error, causing otherwise valid analysis runs to fail; match one of the complete allowed status values rather than a single token.
Useful? React with 👍 / 👎.
| @@ -25,6 +25,7 @@ | |||
| <module>modules/problem</module> | |||
| <module>modules/contest</module> | |||
| <module>modules/moderation</module> | |||
| <module>modules/learningplan</module> | |||
There was a problem hiding this comment.
Register the learning-plan domain in the Core app context
Adding this App-private module makes it available to the standalone backend-app, but the opt-in backend-core profile assembles App through the explicit package list in CoreOwnerBootConfigurations.App, which does not include com.ulticode.modules.learningplan. In that supported profile the controller, service configuration, and remote access adapter are therefore never created, so every new /learning-plans route is absent even though the module is on the classpath.
Useful? React with 👍 / 👎.
| def _deterministic_business_error(exc: UlticodeServiceError) -> bool: | ||
| return exc.status_code in {400, 401, 403, 409} or ( | ||
| exc.status_code == 200 and exc.code in {40000, 40100, 40300, 40900} |
There was a problem hiding this comment.
Keep transient authorization outages retryable
Classifying every HTTP 401/403 as deterministic makes a transient dependency failure terminal: RemoteLearningPlanAccessAdapter deliberately returns 401 when its Auth RPC is unavailable, before opening the write transaction, but this predicate makes the Agent transition the thread to failed with retry_blocked=1. A brief Auth/Dubbo outage between /auth/me and the Java save therefore permanently prevents that confirmed draft from being saved or explicitly recovered, even though no write was attempted; distinguish transient verification failures from actual payload or idempotency rejections.
Useful? React with 👍 / 👎.
自主验收规则校正|1f1bf0c
用户已明确纠正文档中的人工前置要求:开发、产品工作决策、显式确认演示及独立评估由自主流程执行,不再以真人会议、TTY操作、访谈、本人讲解或人工批准作为开发与验收准备的阻塞。真实访谈和用户反馈仍不得伪造;AI独立评审不冒充GitHub批准,不绕过实际分支保护。旧记录中相反的人工门禁已被本规则取代,仅保留为历史。
U03/U04默认自主显式确认,保留owner、draftVersion、paramsDigest、confirmationId、expiry、Java保存读回及重启恢复;交互确认仅为可选模式。合成测试不记真实流程完成,actor如实记录autonomous。远端针对性回归68 passed;当前提交1f1bf0ce0469238648af03093fdded6bace99670的CI成功:CI 37642684500。两项独立代理评审已完成并修复确认决策消费缺陷,不冒充真人或GitHub审批。
PR #231已转Ready供评审(OPEN,isDraft=false,读回核实),不等于正式验收PASS或满足合并条件。unknown保留,累计USD2.20/180次上限不变,未启用付费调用。尚需可信usage、可执行预算及真实服务/模型验收;不再要求安排真人才能继续。
Historical delivery evidence (superseded where human prerequisites conflict)
Acceptance recovery preparation — ff2e933
The sections below are preserved historical evidence, not current-head acceptance.
Historical remote delivery — a1cdf46
The user pushed the four recovered commits normally. This continuation then pushed regression
4000b4858440b9d4c1991802b16b163cced81730and minimal shared-boundary fixa1cdf461c6068be0e79566f2710ede7a3661caa7; both the remote source branch and this PR head were verified. User wrapper changes remain excluded. Draft is retained; no merge, deployment or new release.Regression-first HTTP evidence on remote-dev: at
4000b48, a private-source request with non-refusal textreturn 42;and no citations returned 200 instead of expected 502. The fix requires an asserted existing refusal marker before persisting an actual-source answer, while retaining zero-reference refusals and supported ordinary concept explanations. Pure refusals need not repeat the words source code. Failure preserves the draft and empty analysis. Independent contextual review found no confirmed defects; this is not a GitHub approval or evidence of real private-source disclosure.Target-revision validation in an isolated remote-dev checkout, Linux / Python 3.14.7 / uv 0.12.23, at the exact clean
a1cdf461...revision:The fresh clone’s wrapper bytes matched Git exactly; only its local Git attributes were corrected for a global line-ending false dirty status. Existing user worktrees were not changed. Documentation script is tracked non-executable, so its Bash entry point was used after direct execution returned 126.
Current-head CI 37612366022 completed SUCCESS: 23 successful jobs / 1 path-conditioned Frontend skip. Agent job checked out test merge
901d37e34df1d167d334912283eb5ba6466de7dd, with exact basebc505116062b913f99b5ed4cce1545dc3a5fc92dand heada1cdf461c6068be0e79566f2710ede7a3661caa7as parents. All nine raw Trivy reports were parsed: zero fixable HIGH/CRITICAL under existing filters, not zero vulnerabilities of every class. Dynamic japicmp was path-conditionally skipped, not claimed as executed. The b76 run was superseded/cancelled; old 214c success is historical only. Formal real-model/isolation/U03/U04 acceptance and valid nonself review remain prerequisites. Linear connectivity is restored; core delivery tasks and product preparation were updated and read back without changing acceptance checklists. The user approved a cumulative USD2.20 / 180-attempt ceiling and explicitly requested creation of a missing ledger. A separate private audit-only ledger was created on remote-dev using the existing SQLite accounting schema, preserving both disjoint source histories: 47 attempts / 46 settled / 1 unknown, known actual USD0.015314 and SQL reservations USD0.451200. Original source ledgers remain unchanged; the unknown guard envelope remains separately recorded, not counted as an invoice or added to SQL reservations. The new ledger is halted and not connected to paid authorization. Actual checks rejected ordinary/frozen reservations, evaluation-group start, history updates/deletes and INSERT OR REPLACE budget reset; SQLite integrity and private permissions passed. Triggers prevent ordinary DML mistakes, not database-owner/schema tampering. The approved cap leaves an upper bound of 133 new attempts, 12 fewer than the previous 145-call plan; no cap was increased, no paid call was made and no code was changed by this accounting operation. Provider usage, reviewed source/device binding, purpose grants and formal human acceptance remain pending. A nonself review was requested from thana0623; no submitted review is claimed. Notion and Linear evidence were read back.The sections below are historical snapshots, including earlier push refusals and pre-reproduction findings.
Historical local follow-up — previously not pushed
Local commit
b76b73c0bf81ab8bdf70fabe4a997dbc53bdb00efollows the three recovered commitsa3c6061c,35eab1d1, anda0c3f19b. It fixes concept questions containing “该概念 / this concept” or plural “concepts” being rejected as private-source requests. Actual/private-source and mixed requests retain citation-free refusal checks. Existing HTTP regressions reproduced both the false 502 and the private-qualifier 200 bypass before correction; 14 service tests and independent contextual re-review passed.Current local validation: Linux / Python 3.13.15; supported Agent wrapper 1344 passed / 1 optional Qdrant skip, then locked optional eval dependencies plus
uv run --group eval pytest -q1345 passed / 0 skipped. Documentation contract and diff whitespace checks passed. Optional-library wiring is not live embedding/model/Java acceptance. The user’s wrapper changes are excluded.Normal Git push was rejected by the execution layer (
approval required by policy, but AskForApproval is set to Never); no alternative transport was used. All four commits remain local. This PR remains Draft at remote head214c2042189d438d9670eb35b1810499c72a8c1b, basebc505116062b913f99b5ed4cce1545dc3a5fc92d. CI 37559997206 is evidence for that older remote head only. No new-head CI or submitted GitHub approval is claimed.Read-only accounting remains 35 attempts / 34 settled / 1 unknown; no paid calls, settlements, resets or new ledger. U02, model isolation, formal U03/U04 and real product/human decisions remain gated. PR #237 and its successful release were read back; no repeat publishing.
Additional source-level feasibility check: U04 currently requires at least 88 remaining calls (81 on reopening), but the original period permits 78 total and already records 35 attempts, leaving at most 43. A trustworthy receipt for the unknown request alone cannot unblock formal U04. U03/U04 purposes and an audited device/execution-environment recovery are also prerequisites; no threshold, purpose, budget, ledger or holdout-consumption record was changed. This continuation rechecked the four local patches and whitespace only; the test counts above are historical, not newly rerun. The existing push policy refusal remains unresolved, so no new push was attempted and no new-head CI exists. Linear is currently disconnected; its older project snapshot is not a live status read.
Current contextual review: the source-refusal-with-citations finding was excluded because that rejection is intentional and already covered by the zero-reference contract. A separate static gate gap remains: for an actual/private-source request, citation-free non-refusal text is not required to be a refusal before the analysis is persisted. The response
return 42;with an empty citation list is a focused counterexample to reproduce in the existing service regression. This has not been executed as an HTTP scenario in this continuation and is not evidence of real source disclosure. Keep it pending regression-first repair and target-revision validation; earlier no-remaining-findings statements are historical.Continuation verification — local a0c3f19 (2026-10-07 UTC)
Local branch
agent/delivery-auditis now three commits ahead of remote PR head, ending ata0c3f19bc06c7d5dbcd0689a96a1e7de873e13c0. This continuation fixes an introduced U03 regression: requesting an explanation of the source-code concept was incorrectly treated as requesting unavailable submission source. Only the concept phrase is excluded from request detection; mixed requests for another source-code object and citation-bearing refusals still fail closed.uv run pytest -q tests/test_agent_service.py= 14 passed;./scripts/dev/test.sh agent= 1344 passed / 1 optional Qdrant dependency skip; documentation contract and whitespace checks passed. Independent contextual code review has no remaining confirmed findings. These results cover local changed source, not remote CI or formal acceptance.214c2042189d438d9670eb35b1810499c72a8c1b, basebc505116062b913f99b5ed4cce1545dc3a5fc92d; no new CI was triggered. Remote historical CI 37559997206 remains 23 successful / 1 conditional skip. No submitted GitHub review or review thread. Draft retained pending real acceptance and valid nonself review.The following takeover and delivery sections are earlier checkpoints, preserved for provenance.
Current takeover evidence — 2026-10-07 UTC
Remote head remains
214c2042189d438d9670eb35b1810499c72a8c1b; basebc505116062b913f99b5ed4cce1545dc3a5fc92d. Draft retained; no submitted GitHub reviews or review threads. This session has not merged or deployed anything.1ea71cc6767e88afe26d691b1df9b5e0f8bcabe5has exactly this base/head as parents. Downloaded and parsed all nine raw Trivy reports: zero fixable HIGH/CRITICAL under the existing HIGH/CRITICAL + ignore-unfixed configuration. Older run 37510690544 / merge 9a6a619 below are historical, not current evidence.a3c6061cff0c472b0aa761cf6fe7b0230c7f5607: fixes execution-checkout/evidence mismatch, citation-bearing source refusals in U03, and inline references in U04 refusals. Regression-first failure reproduction, scoped contextual review and independent cross-review completed. Native Linux / Python 3.13.15:./scripts/dev/test.sh agent= 1344 passed / 1 optional Qdrant skip; documentation contract and whitespace checks passed. These are local changed-code results, not new remote-head CI or real-model acceptance. Additional local commit35eab1d190ccf45b47c43832d9cb00a73f5a4703separates cumulative SQL reservations from the sequential guard envelope with conservative maximum lane caps. Its budget regressions failed before the fix, then all eight passed; 61 U04/driver tests and independent cross-review passed. Existing purpose, unknown-usage and USD 1 gates remain unchanged.Historical security and delivery evidence
All prior "current" statements below refer to their original checkpoints. They are preserved for provenance and do not describe this takeover's local commit or latest remote CI.
Current security patch follow-up
Current head:
214c2042189d438d9670eb35b1810499c72a8c1b. Draft retained.Run 37507592454 passed backend build and all three test variants, Agent, static and compatibility gates, but six image scans exposed additional Boot BOM vulnerabilities: Tomcat 11.0.24 (three CRITICAL findings) and Jackson 3.1.5 (five HIGH findings). CVE-2026-47884 was no longer reported.
Pin same-minor security patches Tomcat 11.0.25 and Jackson 3 BOM 3.1.7; retain Jackson 2 2.21.7 and the existing JSON mapper. All scanner gates remain unchanged. Actual Auth/Admin/App executable JARs contain these patch versions and Spring WebMVC 7.0.9.
Current patch verification:
./mvnw -U -pl auth,admin,app/app-web,core,platform/observability -am -Dtest=BackendAuthApplicationTest,AdminAccountControllerTest,LearningPlanControllerTest,CoreApplicationSmokeTest,OtlpSecurityAutoConfigurationTest,DubboBoot4LocalRoundTripIT,LearningPlanWriteIT -Dsurefire.failIfNoSpecifiedTests=false package -B: 44 tests PASS, including 6 real MySQL cases and the actual Boot/Dubbo round trip; packaging PASS. Diff/whitespace review PASS. Prior full-reactor unit result below belongs to 3da2f11; current-head CI 37510690544 is SUCCESS: 23 passed, 0 failed, 1 intended frontend skip. Backend build and all three test variants passed. All nine raw Trivy reports have zero fixed HIGH/CRITICAL findings, scanned merge9a6a61918f0747c60d4edcd77ecf86850fd3c860verified to contain this exact head and basebc505116062b913f99b5ed4cce1545dc3a5fc92d.Push verified via remote full SHA; transient SSH/HTTP2 transport failures were worked around using the same authenticated Git destination with HTTP/1.1, without changing remote, account or TLS/host verification. Original budget and acceptance blockers remain unchanged.
Historical CI repair evidence
Current CI security repair
Current head:
3da2f11c55c69f63d72c5320be2351257e064c4bonagent/first-delivery. Draft retained; no merge or production deployment. Earlier delivery evidence below is historical.Root cause and fix
Local verification
Environment: Linux, Zulu Java 17.0.20.1, Maven 3.10.0; Docker 29.7.2 for MySQL Testcontainers.
./mvnw test -Punit -fae -B: PASS (all 29 modules)../mvnw -U package -Punit -DskipTests -fae -B: PASS; packaging-only, not counted as a test run. First package attempt hit a transient Maven Central TLS handshake; retry succeeded.LearningPlanWriteIT: 6 PASS, no skip.Original real-budget/acceptance blockers remain unchanged: 35-attempt original evidence is missing; current 12-attempt ledger is not a substitute. No paid calls, no U04 holdout execution, no acceptance reset. User's
services/mvnw.cmdmodification remains uncommitted and untouched.Historical delivery evidence
Summary
Current delivery:
1733278ea5643d2c7c731a1bc58cda2fa46e383conagent/first-delivery, basemain. Draft intentionally retained. All sections below the historical separator are prior-revision evidence, not current-head acceptance.Evidence
After: targeted actual-helper/MockTransport orchestration regressions:
uv run pytest -q tests/test_delivery_drivers.py tests/test_u04_acceptance.py→ 47 passed. Final scoped read-only review: no remaining findings../scripts/dev/test.sh agent→ 1329 passed, 1 skipped (optionalqdrant_client.modelsunavailable). No paid call, real service startup, or formal holdout read/claim.uv lock --check, both CLI--help, undefined-global scan andgit diff --checkpassed. AST graph refreshed; SQL extraction unavailable without optional tree_sitter_sql, so graph is navigation only.f44806b5762f67eb3554c5cd0afd891ede5cc030b2f8c5d4c5ab0c701c86a45d; no budget/journal reset, migration, settlement guess or new lane/period. User's pre-existingservices/mvnw.cmdmodification excluded from commit.32bc9ab32be8e26cc124c486787b548cf0f5f372has parentsbc505116062b913f99b5ed4cce1545dc3a5fc92dand this head1733278ea5643d2c7c731a1bc58cda2fa46e383c. Agent, Java build/tests (normal/features on/off), static contracts, migrations, compatibility and secret scan passed. Five web-owner image scans failed on raw-report CRITICALCVE-2026-47884,org.springframework:spring-webmvcinstalled6.2.19(scanner lists fixed7.0.9);ci-okfailed accordingly. All nine raw reports downloaded and parsed: remaining four have zero fixed HIGH/CRITICAL findings. Spring Boot parent3.5.16is unchanged from main and this increment did not change Spring dependencies; do not suppress scanner or attempt unreviewed Spring 7 migration. This is a current dependency/security gate blocker, not failed Agent assertions or a scanner timeout. Exploitability/compatible backport has not been independently validated. Earlier CI 37388691011 remains historical only.Real acceptance remains blocked
Original period
dav58-local-20261003T171726Z/ identityb7131661377941b3b3627adaefa8d887needs its consistent original 35-attempt SQL backup, matching binding/guard and unique unresolved provider receipt/usage. Current 12-call ledger is not replacement. Purpose policy currently does not authorize U03/U04 live calls.U02 remains 5/7; DAV-53 HTTP remains 4/5, three real-model attack legs unrun; DAV-58 six real boundaries unrun on this candidate. U03 real acceptance not passed. U04 remains Backlog: independent formal holdout unconsumed, R01–R10 real layers and 180-second full human Java flow unexecuted. Offline success never upgrades these gates.
20-dev structural/citation integrity and retrieval quality are separate: oracle 12/20, required coverage 18/20 are not relabeled 20/20. Prior-five actual answer 20/20, independent unseen ten, real isolation/crash evidence and human flow still require actual raw proof.
Merge Danger
Door: two-way
Opt-in runtime; existing Java storage contract retained. Rollback code without deleting private state or rewriting applied migrations. Same-UID malicious path swapping during SQLite internal VFS opens is not claimed fully prevented.
Blast Radius: Agent
This remains Draft: no Ready, self-approval, merge, release, production publish or CD. Current CI/nonself review and real acceptance are separate gates.
Historical PR evidence (preserved)
Current evidence boundaries
Latest scoped runtime correction — b9d5801
Historical verified checkpoint — 073e8c8 / 2026-10-05
Draft remains intentional. Current remote head:
073e8c89f8c4b5a7629c84104c0cdadcab080b72; main baseline:bc505116062b913f99b5ed4cce1545dc3a5fc92d, merged once via2218bc1b2eca0930cf6728b803af8174db650c67. Complete base...head scope remains 63 files, including the existing Java LearningPlan storage slice; no scope reduction or deletion.Historical snapshots below are preserved, not current acceptance claims.
Historical closeout snapshot — 2026-10-05 (local workstation; not remote-dev)
60c07cca2. The branch is no longer merge-conflicting:origin/mainwas merged in with a merge commit — no rebase and no force-push.merge-base(main, head)..head, merge-baseb060b2dc2): 36 added, 27 modified; 36 underservices/agent, 27 outside it. The "96 files / 55 outside" figure published earlier in this PR and in the DAV-45 record was wrong: it came from a two-dot diff against amainthat had already moved, which counts changes on both sides and swept in files onlymainchanged. The claim derived from it — that this branch's lockfile could revert the KaTeX pin — is retracted for the same reason: the correct 63-file list contains nopackage.json,pnpm-lock.yamlorpnpm-workspace.yaml.services/agent/README.md: main restructured the file sodocs/DEVELOPMENT.mdowns the detailed contracts, and the deleted block was the only branch-only content in it, so main's structure was kept with a short pointer section for the two new opt-in runners.services/agent/src/deepseek_model.py: this branch's shared-budget reservation, settlement and fail-closed accounting guard were kept, together with main's_api_messages/_check_prompt_budgetextraction.decide()outside the conflict markers: main's_check_prompt_budgetmadeprompt_tokens_estimatea local, whilereserve()still needed it. The estimate now has a single owner,_prompt_tokens_estimate(). The test suite is what surfaced this — a textual merge can be silently wrong in the regions it does not mark.60c07cca2(local):pnpm install --frozen-lockfilepasses and the lockfile'soverridesblock matchespnpm-workspace.yamlkey for key;services/agent1124 passed / 1 skipped (optionalqdrant_clientabsent);./mvnw compile -BBUILD SUCCESS; focused LearningPlan gate 35 passed, includingLearningPlanWriteIT's 6 real-MySQL Testcontainers tests for idempotency and owner scoping.refs/pull/231/merge = 9c4d011821ee25cd74e79a5cc2208d032518985a, i.e. head60c07cca2× baseb060b2dc2(23 passed, 1 path-filtered skip, 0 failed). It does not cover head × the currentmainc3194bc36; no run exists for that pair and none is claimed. No remote-dev run was performed in this session../mvnw test -Bacross the reactor was attempted and stopped on an environment failure unrelated to this change:SearchWorkerApplicationTestfails instantiating MicrometerProcessorMetrics(Cannot invoke "jdk.internal.platform.CgroupInfo.getMountPoint()" because "anyController" is null) under JDK 17.0.2 on kernel 7.2.5.services/searchis untouched by this merge, so the failure is not attributable to it../scripts/dev/doctor.sh --json, exit 0: six services absent, ports free, mysql/redis/nacos/rustfs absent)..envalready carriesSUBMISSION_CUTOVER_COMPLETE=true, and doctor output cannot establish whether that reflects a genuinely completed cutover on the current local DB, so the stack was not started. The identity-swap and injection legs also need a real model, which the budget gate blocks.Historical closeout snapshot — 2026-10-04
This PR remains Draft / OPEN; the historical description below is retained as prior context, not overwritten.
Scope
deepseek-flashand keep loopback/disposable target constraints.Remote revision and validation
5dd6e0c17d4f5737b70c28eacf10e23bcd919bef(documentation-only failure checkpoint; parent9e9d4b5dda1bd0e9de76eb4fc1509c8f23b36563); baseagent/u02-citation-fixtureat73375e91d0dd5943129395f29fccf36f3c74ac64(feat: let an analysis cite from an explicitly versioned corpus #230).f71c7a55146c042c59e7d90e3cc5f86a5c27b905:cd services/agent && uv sync --locked && uv run pytest -q→ 797 passed, 1 skipped;git diff --checkpassed. This result belongs to that earlier revision and does not establish validation of the current head.0590e87ccheck returned no commit statuses or PR-triggered Actions runs. No GitHub CI pass or current-head full-suite pass is claimed.DAV-58 real-model failure checkpoint | 2026-10-03 11:02 UTC
9e9d4b5d: 4/6 passed, 2/6 failed, 0 evaluator errors; exit 1. Both negative probes recordedgate_rejected=true. Immutable-version failure record and offline plan.boundary-no-toolgave a correct equivalent array-index explanation but failed the fixed lexical marker.boundary-missing-idalso has a genuine policy deviation: offering to list recent submissions after confirmation instead of directly asking for the specific submission ID. Both made zero tool calls and guessed no ID; these failures do not establish actual unauthorized access. Preserve the original failure artifact without relabeling it as passed.edf4ae8520baf9fb6a530495355976c9350495d6bd0c6b8a72af29f12ea7d1ef; original artifact SHA-256:c6033d0b313bd24dec6c6eb9f0258dd7e9df19dfc39f2919dc0e6b3a8fb137d3.Historical DAV-58 explicit period-binding checkpoint | 2026-10-03 06:29 UTC
9e9d4b5dbinds the existing standalonee2e_boundary_evaluation.pythroughauthorized_model(expected)to one explicitly selected existing active PeriodIdentity/ledger. Loop 24 + judge 42 share the US$1 / 78-call ceiling; DAV-53's reserved 12 calls remain untouched.6ef0028retained 79 passed / 2 failed;5a270e7fixed the SQLite auxiliary-descriptor lock issue and its exact-archive focused verification recorded 84 passed, exit 0.runtime_accounting_connected=Falseandspend_limit_enforced=False; historical spend remains UNKNOWN. DAV-58's real six-category matrix and DAV-53's live A/B gate remain open; DAV-45 remains In Progress at 5/7. Main-worktree WIP was preserved.Historical local, unpublished verification | 2026-10-03 01:56 UTC
These results are separate from the remote PR and its CI.
f466d9c735ef36dbc25237a5493a3493cf4c433d, parent0590e87c, changes onlyscripts/dev/lib/sql.shandscripts/dev/migrate-owner-preflight-test.sh(31 additions / 8 deletions). It adjusts the container MySQL stdin transport and the owner-preflight fake fixture. It has not been pushed.f466d9c, nor remote-head CI.Historical stage boundary — superseded by b9d5801 HTTP acceptance
e2e_boundary_evaluation.pyuses the synthetic boundary client/corpus and does not require a database or APP/AUTH readiness. Keep this route independent of the combined runner's service-readiness checks; the first real-model six-category run failed and acceptance remains pending.