Skip to content

feat(agent): add gated durable learning workflows - #231

Open
DavidHLP wants to merge 43 commits into
mainfrom
agent/first-delivery
Open

DavidHLP wants to merge 43 commits into
mainfrom
agent/first-delivery

Conversation

@DavidHLP

@DavidHLP DavidHLP commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

自主验收规则校正|1f1bf0c

用户已明确纠正文档中的人工前置要求:开发、产品工作决策、显式确认演示及独立评估由自主流程执行,不再以真人会议、TTY操作、访谈、本人讲解或人工批准作为开发与验收准备的阻塞。真实访谈和用户反馈仍不得伪造;AI独立评审不冒充GitHub批准,不绕过实际分支保护。旧记录中相反的人工门禁已被本规则取代,仅保留为历史。
U03/U04默认自主显式确认,保留owner、draftVersion、paramsDigest、confirmationId、expiry、Java保存读回及重启恢复;交互确认仅为可选模式。合成测试不记真实流程完成,actor如实记录autonomous。远端针对性回归68 passed;当前提交1f1bf0ce0469238648af03093fdded6bace99670的CI成功:CI 37642684500。两项独立代理评审已完成并修复确认决策消费缺陷,不冒充真人或GitHub审批。
PR #231已转Ready供评审(OPEN,isDraft=false,读回核实),不等于正式验收PASS或满足合并条件。unknown保留,累计USD2.20/180次上限不变,未启用付费调用。尚需可信usage、可执行预算及真实服务/模型验收;不再要求安排真人才能继续。

Historical delivery evidence (superseded where human prerequisites conflict)

Acceptance recovery preparation — ff2e933

  • Current head: ff2e933. New recovery regressions first failed at399f091; implementation450d54c passed all36 tests in the existing migration test file on a clean, exact remote-dev checkout. Documentation-only ff2e933 adds the supported copy rehearsal command.
  • Real47-row locked audit accounting was copied without changing original rows, counters, source mapping or the one unknown. Both normal filesystem and actual cross-device rehearsal (device59→33) preserve47/46/1, pass SQLite integrity, and reject paid reservations. This is audit-copy binding evidence, not a live device exception; the existing pinned58→59 migration and resolve_pair remain unchanged.
  • No paid requests, usage settlement, cap change, Ready transition or merge. Approved cumulativeUSD2.20/180 remains unapplied. The complete existing continuation43 +independent DAV53 12 +standalone U03 14 +U04 88 needs157 new calls, cumulative204 with47 historical, leaving a24-call shortage under180. U04 reopen81 is already inside88, not additional. The old145/12-short plan omitted DAV53.
  • Existing guarded8k-input continuation yields successful-request peak1286400microUSD; pending provider usage must be recovered before execution. With trustworthy unknown actual U, full-envelope guard ceiling2078546+U fitsUSD2.20 only if U≤121454 and all identity/purpose prerequisites pass. This arithmetic is not a supplier receipt or an applied grant. Current runtime purposes do not yet authorize U03/U04.
  • Private A/B USER credential fixtures prepared but not registered; actual Owner services, supplier per-request evidence, fresh unseen holdout, genuine human/product acceptance and valid non-author review remain required. Review requested from thana0623; a request is not approval.
  • Current-head CI: https://github.com/DavidHLP/UltiCode/actions/runs/37636076564 SUCCESS:23 jobs passed/1 path-conditioned skip; Agent1353 passed/1 optional skip, actual test merge a7a8149, matching current head/base. Previous successful CI applies only to its historical head.

The sections below are preserved historical evidence, not current-head acceptance.

Historical remote delivery — a1cdf46

The user pushed the four recovered commits normally. This continuation then pushed regression 4000b4858440b9d4c1991802b16b163cced81730 and minimal shared-boundary fix a1cdf461c6068be0e79566f2710ede7a3661caa7; both the remote source branch and this PR head were verified. User wrapper changes remain excluded. Draft is retained; no merge, deployment or new release.

Regression-first HTTP evidence on remote-dev: at 4000b48, a private-source request with non-refusal text return 42; and no citations returned 200 instead of expected 502. The fix requires an asserted existing refusal marker before persisting an actual-source answer, while retaining zero-reference refusals and supported ordinary concept explanations. Pure refusals need not repeat the words source code. Failure preserves the draft and empty analysis. Independent contextual review found no confirmed defects; this is not a GitHub approval or evidence of real private-source disclosure.

Target-revision validation in an isolated remote-dev checkout, Linux / Python 3.14.7 / uv 0.12.23, at the exact clean a1cdf461... revision:

  • locked dependencies and the three focused service/delivery/U04 files: 75 passed, exit 0;
  • supported Agent wrapper: 1344 passed / 1 optional qdrant_client skip, exit 0;
  • Bash documentation contract: PASS, exit 0;
  • scoped staged diff and whitespace review passed.

The fresh clone’s wrapper bytes matched Git exactly; only its local Git attributes were corrected for a global line-ending false dirty status. Existing user worktrees were not changed. Documentation script is tracked non-executable, so its Bash entry point was used after direct execution returned 126.

Current-head CI 37612366022 completed SUCCESS: 23 successful jobs / 1 path-conditioned Frontend skip. Agent job checked out test merge 901d37e34df1d167d334912283eb5ba6466de7dd, with exact base bc505116062b913f99b5ed4cce1545dc3a5fc92d and head a1cdf461c6068be0e79566f2710ede7a3661caa7 as parents. All nine raw Trivy reports were parsed: zero fixable HIGH/CRITICAL under existing filters, not zero vulnerabilities of every class. Dynamic japicmp was path-conditionally skipped, not claimed as executed. The b76 run was superseded/cancelled; old 214c success is historical only. Formal real-model/isolation/U03/U04 acceptance and valid nonself review remain prerequisites. Linear connectivity is restored; core delivery tasks and product preparation were updated and read back without changing acceptance checklists. The user approved a cumulative USD2.20 / 180-attempt ceiling and explicitly requested creation of a missing ledger. A separate private audit-only ledger was created on remote-dev using the existing SQLite accounting schema, preserving both disjoint source histories: 47 attempts / 46 settled / 1 unknown, known actual USD0.015314 and SQL reservations USD0.451200. Original source ledgers remain unchanged; the unknown guard envelope remains separately recorded, not counted as an invoice or added to SQL reservations. The new ledger is halted and not connected to paid authorization. Actual checks rejected ordinary/frozen reservations, evaluation-group start, history updates/deletes and INSERT OR REPLACE budget reset; SQLite integrity and private permissions passed. Triggers prevent ordinary DML mistakes, not database-owner/schema tampering. The approved cap leaves an upper bound of 133 new attempts, 12 fewer than the previous 145-call plan; no cap was increased, no paid call was made and no code was changed by this accounting operation. Provider usage, reviewed source/device binding, purpose grants and formal human acceptance remain pending. A nonself review was requested from thana0623; no submitted review is claimed. Notion and Linear evidence were read back.

The sections below are historical snapshots, including earlier push refusals and pre-reproduction findings.

Historical local follow-up — previously not pushed

Local commit b76b73c0bf81ab8bdf70fabe4a997dbc53bdb00e follows the three recovered commits a3c6061c, 35eab1d1, and a0c3f19b. It fixes concept questions containing “该概念 / this concept” or plural “concepts” being rejected as private-source requests. Actual/private-source and mixed requests retain citation-free refusal checks. Existing HTTP regressions reproduced both the false 502 and the private-qualifier 200 bypass before correction; 14 service tests and independent contextual re-review passed.

Current local validation: Linux / Python 3.13.15; supported Agent wrapper 1344 passed / 1 optional Qdrant skip, then locked optional eval dependencies plus uv run --group eval pytest -q 1345 passed / 0 skipped. Documentation contract and diff whitespace checks passed. Optional-library wiring is not live embedding/model/Java acceptance. The user’s wrapper changes are excluded.

Normal Git push was rejected by the execution layer (approval required by policy, but AskForApproval is set to Never); no alternative transport was used. All four commits remain local. This PR remains Draft at remote head 214c2042189d438d9670eb35b1810499c72a8c1b, base bc505116062b913f99b5ed4cce1545dc3a5fc92d. CI 37559997206 is evidence for that older remote head only. No new-head CI or submitted GitHub approval is claimed.

Read-only accounting remains 35 attempts / 34 settled / 1 unknown; no paid calls, settlements, resets or new ledger. U02, model isolation, formal U03/U04 and real product/human decisions remain gated. PR #237 and its successful release were read back; no repeat publishing.

Additional source-level feasibility check: U04 currently requires at least 88 remaining calls (81 on reopening), but the original period permits 78 total and already records 35 attempts, leaving at most 43. A trustworthy receipt for the unknown request alone cannot unblock formal U04. U03/U04 purposes and an audited device/execution-environment recovery are also prerequisites; no threshold, purpose, budget, ledger or holdout-consumption record was changed. This continuation rechecked the four local patches and whitespace only; the test counts above are historical, not newly rerun. The existing push policy refusal remains unresolved, so no new push was attempted and no new-head CI exists. Linear is currently disconnected; its older project snapshot is not a live status read.

Current contextual review: the source-refusal-with-citations finding was excluded because that rejection is intentional and already covered by the zero-reference contract. A separate static gate gap remains: for an actual/private-source request, citation-free non-refusal text is not required to be a refusal before the analysis is persisted. The response return 42; with an empty citation list is a focused counterexample to reproduce in the existing service regression. This has not been executed as an HTTP scenario in this continuation and is not evidence of real source disclosure. Keep it pending regression-first repair and target-revision validation; earlier no-remaining-findings statements are historical.

Continuation verification — local a0c3f19 (2026-10-07 UTC)

Local branch agent/delivery-audit is now three commits ahead of remote PR head, ending at a0c3f19bc06c7d5dbcd0689a96a1e7de873e13c0. This continuation fixes an introduced U03 regression: requesting an explanation of the source-code concept was incorrectly treated as requesting unavailable submission source. Only the concept phrase is excluded from request detection; mixed requests for another source-code object and citation-bearing refusals still fail closed.

  • Extended the existing regression first: ordinary concept explanation failed with HTTP 502; independent review then caught a mixed-request bypass, reproduced as HTTP 200 instead of 502. Both were repaired. Final local native Linux / Python 3.13.15: uv run pytest -q tests/test_agent_service.py = 14 passed; ./scripts/dev/test.sh agent = 1344 passed / 1 optional Qdrant dependency skip; documentation contract and whitespace checks passed. Independent contextual code review has no remaining confirmed findings. These results cover local changed source, not remote CI or formal acceptance.
  • Original budget and existing consistent backup rechecked read-only: SQL 35 attempts / 34 settled / 1 unknown, 336000 micro-USD reserved / 11447 known actual; guard 35 receipts / pending 786432. Binding equals sidecar but current device differs. No accounting mutation or paid call.
  • After renewed explicit user authorization, one normal push was attempted and rejected again: approval required by policy while AskForApproval is Never. No alternate route was used. Remote head remains 214c2042189d438d9670eb35b1810499c72a8c1b, base bc505116062b913f99b5ed4cce1545dc3a5fc92d; no new CI was triggered. Remote historical CI 37559997206 remains 23 successful / 1 conditional skip. No submitted GitHub review or review thread. Draft retained pending real acceptance and valid nonself review.
  • Full Linear project list refreshed: 50 tasks, no next page. Product research/prototype/metrics preparation already exists; no interview, decision, pilot, optional MCP/Vue delivery or owner learning is fabricated. Product-page historical implementation and consumed-holdout wording clarified while preserving all nine native tables. After renewed user authorization, the delivery-record page was updated and read back.

The following takeover and delivery sections are earlier checkpoints, preserved for provenance.


Current takeover evidence — 2026-10-07 UTC

Remote head remains 214c2042189d438d9670eb35b1810499c72a8c1b; base bc505116062b913f99b5ed4cce1545dc3a5fc92d. Draft retained; no submitted GitHub reviews or review threads. This session has not merged or deployed anything.

  • Re-read latest remote-head CI 37559997206: SUCCESS, 23 successful jobs / 1 path-conditioned Frontend skip. Test merge 1ea71cc6767e88afe26d691b1df9b5e0f8bcabe5 has exactly this base/head as parents. Downloaded and parsed all nine raw Trivy reports: zero fixable HIGH/CRITICAL under the existing HIGH/CRITICAL + ignore-unfixed configuration. Older run 37510690544 / merge 9a6a619 below are historical, not current evidence.
  • New local commit a3c6061cff0c472b0aa761cf6fe7b0230c7f5607: fixes execution-checkout/evidence mismatch, citation-bearing source refusals in U03, and inline references in U04 refusals. Regression-first failure reproduction, scoped contextual review and independent cross-review completed. Native Linux / Python 3.13.15: ./scripts/dev/test.sh agent = 1344 passed / 1 optional Qdrant skip; documentation contract and whitespace checks passed. These are local changed-code results, not new remote-head CI or real-model acceptance. Additional local commit 35eab1d190ccf45b47c43832d9cb00a73f5a4703 separates cumulative SQL reservations from the sequential guard envelope with conservative maximum lane caps. Its budget regressions failed before the fix, then all eight passed; 61 U04/driver tests and independent cross-review passed. Existing purpose, unknown-usage and USD 1 gates remain unchanged.
  • Not pushed: execution-layer approval policy rejected the normal push because approval is required while AskForApproval is Never. No alternate tool or API used to bypass it. Remote PR source is unchanged; no CI for the new local commit was triggered. User's pre-existing wrapper modifications excluded.
  • Budget audit materially updates the historical missing-original statement: the original-state SQL now has 35 attempts / 34 settled / 1 unknown, 336000 micro-USD reserved and 11447 known actual. Guard has 35 matching-order lane/cost receipts and 786432 pending envelope; unknown SQL reserve is 9600. Read-only consistent backup and metadata copies passed integrity checks. SQL binding equals sidecar; period/config agree with guard. Current device identity differs from pinned binding; an old migration record does not authorize this new device change. No original file was changed, no unknown settled/reset, no paid call or retry. Supplier console interval totals are not unique per-request usage and were not used for settlement.
  • U02 remains 5/7; DAV-53 ordinary HTTP remains 4/5; real six-category boundary and three model isolation legs remain open. U03 formal acceptance remains 0/6; U04 remains blocked. New U03/U04 purposes, genuine provider receipt/reconciliation, fresh post-freeze unseen data and human flow evidence are still required. Product research/decisions/optional MCP/Vue/owner learning were not invented or bulk-closed.

Historical security and delivery evidence

All prior "current" statements below refer to their original checkpoints. They are preserved for provenance and do not describe this takeover's local commit or latest remote CI.

Current security patch follow-up

Current head: 214c2042189d438d9670eb35b1810499c72a8c1b. Draft retained.

Run 37507592454 passed backend build and all three test variants, Agent, static and compatibility gates, but six image scans exposed additional Boot BOM vulnerabilities: Tomcat 11.0.24 (three CRITICAL findings) and Jackson 3.1.5 (five HIGH findings). CVE-2026-47884 was no longer reported.

Pin same-minor security patches Tomcat 11.0.25 and Jackson 3 BOM 3.1.7; retain Jackson 2 2.21.7 and the existing JSON mapper. All scanner gates remain unchanged. Actual Auth/Admin/App executable JARs contain these patch versions and Spring WebMVC 7.0.9.

Current patch verification: ./mvnw -U -pl auth,admin,app/app-web,core,platform/observability -am -Dtest=BackendAuthApplicationTest,AdminAccountControllerTest,LearningPlanControllerTest,CoreApplicationSmokeTest,OtlpSecurityAutoConfigurationTest,DubboBoot4LocalRoundTripIT,LearningPlanWriteIT -Dsurefire.failIfNoSpecifiedTests=false package -B: 44 tests PASS, including 6 real MySQL cases and the actual Boot/Dubbo round trip; packaging PASS. Diff/whitespace review PASS. Prior full-reactor unit result below belongs to 3da2f11; current-head CI 37510690544 is SUCCESS: 23 passed, 0 failed, 1 intended frontend skip. Backend build and all three test variants passed. All nine raw Trivy reports have zero fixed HIGH/CRITICAL findings, scanned merge 9a6a61918f0747c60d4edcd77ecf86850fd3c860 verified to contain this exact head and base bc505116062b913f99b5ed4cce1545dc3a5fc92d.

Push verified via remote full SHA; transient SSH/HTTP2 transport failures were worked around using the same authenticated Git destination with HTTP/1.1, without changing remote, account or TLS/host verification. Original budget and acceptance blockers remain unchanged.


Historical CI repair evidence

Current CI security repair

Current head: 3da2f11c55c69f63d72c5320be2351257e064c4b on agent/first-delivery. Draft retained; no merge or production deployment. Earlier delivery evidence below is historical.

Root cause and fix

  • Run 37453328443 failed five owner image scans on Spring WebMVC 6.2.19 / CVE-2026-47884, plus the aggregate CI gate. Other jobs passed or were intentionally skipped.
  • Official advisory provides OSS remediation in Framework 7.0.9; 6.2.20 is enterprise-only. Upgrade coherently to Spring Boot 4.1.1, Framework 7.0.9 and Tomcat 11; retain Java 17. No scanner ignore, severity downgrade or gate removal.
  • Preserve Jackson 2 wire/persisted payloads via Boot's compatibility module, owner security/default-user exclusions, OAuth HTTP(S) URL validation, Redis SCAN ACL and OTLP tracing/security binding. Migrate actual Boot 4 modules and auto-configuration paths.
  • Add real Boot/Dubbo auto-configuration local RPC proof. Remove an accidental gRPC module from the non-gRPC Core assembly. Fix Redis mock API seams and a stale class-initialization timestamp in delegation tests without changing production TTL or signature checks.

Local verification

Environment: Linux, Zulu Java 17.0.20.1, Maven 3.10.0; Docker 29.7.2 for MySQL Testcontainers.

  • Full reactor ./mvnw test -Punit -fae -B: PASS (all 29 modules).
  • Reactor packaging ./mvnw -U package -Punit -DskipTests -fae -B: PASS; packaging-only, not counted as a test run. First package attempt hit a transient Maven Central TLS handshake; retry succeeded.
  • Real MySQL LearningPlanWriteIT: 6 PASS, no skip.
  • Boot/Dubbo local round trip: 1 PASS; HTTP/Dubbo execution: 2 PASS.
  • Auth random-port HTTP 3 PASS, OAuth URL 2 PASS, OTLP binding/security 5 PASS, LearningPlan MVC 19 PASS, Admin account MVC 5 PASS.
  • Repaired Auth security/Redis cache tests 3 PASS; Core smoke 5 PASS; delegation signature positive/negative tests 4 PASS.
  • Supply-chain contract, docs contract, zero-infra static validation and whitespace checks: PASS. Read-only final migration reviews found no remaining source-backed blocker.
  • Current-head GitHub CI and all nine image scan receipts: pending, will be updated after completion.

Original real-budget/acceptance blockers remain unchanged: 35-attempt original evidence is missing; current 12-attempt ledger is not a substitute. No paid calls, no U04 holdout execution, no acceptance reset. User's services/mvnw.cmd modification remains uncommitted and untouched.


Historical delivery evidence

Summary

Current delivery: 1733278ea5643d2c7c731a1bc58cda2fa46e383c on agent/first-delivery, base main. Draft intentionally retained. All sections below the historical separator are prior-revision evidence, not current-head acceptance.

Authenticated user + CSRF
  -> checkpointed FastAPI/LangGraph workflow
     -> shared read-only model/tool kernel
     -> private SQLite draft + version/run/TTL checks
     -> explicit confirm -> explicit save -> Java idempotent LearningPlan
     -> unknown -> owner-bound original-key readback, no blind retry

source/config + raw receipts + original budget audit
  -> U02 gate -> U03 ten-scenario result
  -> frozen U04 bundle -> independent unseen + R01–R10 + 180s human flow
  • Same analysis kernel for offline models and guarded provider integration. No model-controlled write tool, new business-table owner, default service startup, migration, or Compose change in this increment.
  • Strict request/auth/owner boundaries, private durable state/checkpoints, whole-answer/citation validation, cancellation/late-run fences, dispatch-time expiry, Java response-loss reconciliation, hashed/redacted evidence and fail-closed budget/source binding.
  • Canonical docs and conditional acceptance CLIs now match actual routes and wire contracts. Product definition/interview/prototype/metrics preparation synced to authorized Notion/Linear; no real interview, meeting or pilot claimed.

Evidence

  • Before: final static review found unreachable Java matrix, snake/camel mismatch, split scenario aggregation, missing pre-claim corpus dependency, reused-query loophole, FAIL/INCOMPLETE misclassification and inconsistent result roots; final undefined-global scan also found missing U03 start timestamp.
    After: targeted actual-helper/MockTransport orchestration regressions: uv run pytest -q tests/test_delivery_drivers.py tests/test_u04_acceptance.py → 47 passed. Final scoped read-only review: no remaining findings.
  • Local Linux workstation, Python 3.14.7 / uv 0.12.23: ./scripts/dev/test.sh agent → 1329 passed, 1 skipped (optional qdrant_client.models unavailable). No paid call, real service startup, or formal holdout read/claim.
  • Java 17.0.20.1: LearningPlanServiceTest targeted Maven reactor → 9 passed, BUILD SUCCESS. These are current focused unit checks, not fresh real-MySQL fault acceptance or full Java integration evidence.
  • Docs contract, relative links/routes, uv lock --check, both CLI --help, undefined-global scan and git diff --check passed. AST graph refreshed; SQL extraction unavailable without optional tree_sitter_sql, so graph is navigation only.
  • Current budget SQLite SHA remains f44806b5762f67eb3554c5cd0afd891ede5cc030b2f8c5d4c5ab0c701c86a45d; no budget/journal reset, migration, settlement guess or new lane/period. User's pre-existing services/mvnw.cmd modification excluded from commit.
  • Current-head CI 37453328443: FAILURE — 17 success, 6 failure, 1 intentional Frontend skip. Checked merge 32bc9ab32be8e26cc124c486787b548cf0f5f372 has parents bc505116062b913f99b5ed4cce1545dc3a5fc92d and this head 1733278ea5643d2c7c731a1bc58cda2fa46e383c. Agent, Java build/tests (normal/features on/off), static contracts, migrations, compatibility and secret scan passed. Five web-owner image scans failed on raw-report CRITICAL CVE-2026-47884, org.springframework:spring-webmvc installed 6.2.19 (scanner lists fixed 7.0.9); ci-ok failed accordingly. All nine raw reports downloaded and parsed: remaining four have zero fixed HIGH/CRITICAL findings. Spring Boot parent 3.5.16 is unchanged from main and this increment did not change Spring dependencies; do not suppress scanner or attempt unreviewed Spring 7 migration. This is a current dependency/security gate blocker, not failed Agent assertions or a scanner timeout. Exploitability/compatible backport has not been independently validated. Earlier CI 37388691011 remains historical only.

Real acceptance remains blocked

Original period dav58-local-20261003T171726Z / identity b7131661377941b3b3627adaefa8d887 needs its consistent original 35-attempt SQL backup, matching binding/guard and unique unresolved provider receipt/usage. Current 12-call ledger is not replacement. Purpose policy currently does not authorize U03/U04 live calls.

U02 remains 5/7; DAV-53 HTTP remains 4/5, three real-model attack legs unrun; DAV-58 six real boundaries unrun on this candidate. U03 real acceptance not passed. U04 remains Backlog: independent formal holdout unconsumed, R01–R10 real layers and 180-second full human Java flow unexecuted. Offline success never upgrades these gates.

20-dev structural/citation integrity and retrieval quality are separate: oracle 12/20, required coverage 18/20 are not relabeled 20/20. Prior-five actual answer 20/20, independent unseen ten, real isolation/crash evidence and human flow still require actual raw proof.

Merge Danger

Door: two-way

Opt-in runtime; existing Java storage contract retained. Rollback code without deleting private state or rewriting applied migrations. Same-UID malicious path swapping during SQLite internal VFS opens is not claimed fully prevented.

Blast Radius: Agent

This remains Draft: no Ready, self-approval, merge, release, production publish or CD. Current CI/nonself review and real acceptance are separate gates.


Historical PR evidence (preserved)

Current evidence boundaries

  • DAV-53 is In Progress at 4/5: ordinary real HTTP contrast passed; actual-model identity-swap/foreign-ID/source-injection remains unrun. The final artifact stays INCOMPLETE/model_not_configured, not full acceptance. DAV-58 original 35-attempt SQL/guard and trusted provider usage remain missing; the existing 12-call ledger is not replacement. DAV-46 stays 0/6; U03 is not unlocked. This PR remains Draft.
  • CI 37388691011 actually checked out merge 0364b40, whose parents are current main bc50511 and head b9d5801. Current Agent job log confirms 1150 passed / 1 skipped. This is current-main × current-head proof, not old baseline proof.
  • The 72-row cutover parity belongs to the pre-HTTP verification checkpoint. Later HTTP acceptance created two owner-side submissions; post-HTTP 72-row parity is not claimed. Old historical cutover evidence remains UNKNOWN.
  • This clarification re-read GitHub state, the merge parents, and the existing CI Agent log; it did not rerun HTTP/Java, re-download nine Trivy reports, or re-query registry tags. Full Java results, raw-image scan verification and unchanged historical tags above remain earlier delivery evidence, not fresh independent revalidation by this edit.
  • Notion synchronization is still blocked in this execution environment: current get_tool_access returns MCP server not connected: notion; existing browser relay has no connected extension. This says nothing about the user's separate Notion read permission. No Notion page has been read or changed by this clarification.

Latest scoped runtime correction — b9d5801

  • Real HTTP exposed a shared runtime cause: Nacos denied DEFAULT_GROUP Dubbo metadata publishes for workload identities, generating a large retry storm. Fixed bootstrap grants only own-application provider/consumer metadata keys; ordinary application config remains read-only, foreign application writes denied, built-in account disabled. No RPC deadline or auth weakening.
  • Actual Nacos 2.3.2 API on disposable project: all six identities publish/read/delete own provider and consumer metadata (200); foreign-app and ordinary application.yml writes 403. Contract regression, bash syntax and diff whitespace passed; independent scoped security review found no issues. Three-file corrective commit pushed with exact remote SHA verified.
  • Final-source ordinary A/B real HTTP contrast PASSED on b9d5801: distinct USER identities unchanged, own-only detail/list, cross detail 404, anonymous private 403, public list/detail allowed, DATABASE search 3 public / zero private with no foreign IDs/source/canary leak. Real App remote owner queries exercised unchanged 800 ms RPC policy. Raw final artifact remains INCOMPLETE/model_not_configured; actual-model attack legs not run, zero paid calls. Scoped metadata denial storm zero in final session; private owner heaps bounded at 512 MiB, existing PM2 1 GiB limit unchanged, zero restarts. Supported shutdown completed, no owner processes/listeners, correct and accidental diagnostic containers stopped, all volumes preserved. Full main...head scope is 65 files; original Java storage/Agent slice retained, only two security helper/test paths added since 073. Earlier 073e8c8 Agent/Java/local-image results remain explicitly named-source proof, not invented reruns. New cutover/backup/observation facts do not repair unknown old history or original 35-attempt budget.
  • Current-head CI 37388691011 completed SUCCESS: 23 jobs succeeded, one intended skip; all nine Docker build/scan jobs succeeded and nine downloaded raw Trivy reports contain zero fixed HIGH/CRITICAL findings. Older runner-acquisition failures belong to the previous head. Draft retained pending real acceptance; no merge or production deployment.

Historical verified checkpoint — 073e8c8 / 2026-10-05

Draft remains intentional. Current remote head: 073e8c89f8c4b5a7629c84104c0cdadcab080b72; main baseline: bc505116062b913f99b5ed4cce1545dc3a5fc92d, merged once via 2218bc1b2eca0930cf6728b803af8174db650c67. Complete base...head scope remains 63 files, including the existing Java LearningPlan storage slice; no scope reduction or deletion.

  • Local final Agent suite: 1150 passed, 1 skipped (optional qdrant-client unavailable), actual offline MockTransport/temp-ledger checks, zero new paid provider calls. Earlier failed runs retained; concurrent unsettled-window, synthetic reviewed permissions, and precise guarded-resume assertions fixed without weakening production checks.
  • Bound reserve atomically rejects any unknown/unsettled attempt before mutation. DAV-53 uses explicit period identity and shared dav53_scenarios limits; unknown tool calls and terminal answers stop remaining scenarios. Before/after snapshot faults retain previous/current per-call receipts and usage. Independent review findings resolved; provider labels/receipt binding and redacted answer/tool traces retained.
  • Java LearningPlan slice: 44 targeted tests passed, zero skipped, including 6 real MySQL Testcontainers integration tests for concurrent idempotency/replay/conflict and owner reads. These storage checks do not enable Agent confirmation runtime.
  • Offline client now covers save/get/by-key, exact Java DTO/UUID/code-point limits, unique access+CSRF write cookie/header and idempotency key, retained sanitized business code; no draft_write registration, actual confirmation runtime, automatic retries or U03 acceptance.
  • Original 35-attempt checkpoint remains unreconciled: SQL unknown reserve 9600 micro-USD; guard pending 786432 micro-USD; conservative mixed envelope 797879 micro-USD is not confirmed billing. Current 12-attempt ledger is NOT a substitute and its SHA256 remains unchanged. No reset, refund, replay, unknown-to-zero, new period or paid resume.
  • New isolated non-production project has actual encrypted backup/restore checksum proof, 72-row source-to-owner backfill/parity, revoked newly staged legacy grants, zero source/target App DML/global/role-derived privilege paths. Old historical backup/quiesce/observation remains UNKNOWN. Final-head full observation battery passed: 13 suites / 75 tests, zero skipped, REHEARSAL_VERIFIED; the actual app_rw direct and recursive-role source/target grants were independently re-audited as zero after owner provisioning. Full unit install passed 3309 tests, zero failures/errors, 16 skipped, with eight existing JaCoCo gates satisfied. Actual ordinary A/B HTTP ran on this exact source: USER/distinct identities, own detail 200/200, cross detail 404/404, anonymous private routes 403/403/403, no observed body/source leak; then owner problem-submission listing returned 403 after an authenticated controller Dubbo 800 ms deadline exceeded. One bounded warmed retry with correct six actual process environments and public readiness 200 failed GET /problems with 403 before later checks; corrected request-time correlation confirms ProblemSubmissionStatsPort.countByProblemIds also exceeded the unchanged 800 ms RPC deadline, then secured error dispatch masked it as 403. Underlying latency remains under investigation; no server-side timing proof. HTTP acceptance is NOT passed; lists/search/public/model success not claimed. Fresh owned services/containers stopped and volumes preserved. No model acceptance or paid calls claimed.
  • Current-head CI 37365437461 attempts 1 and 2 failed because hosted runners were not acquired (all cancelled jobs have GitHub failure annotations), not test assertions. One bounded full rerun exhausted; required CI remains BLOCKED, not passed. Local final-head nine-image no-push verification passed: all nine builds and pinned Trivy scans exited 0, zero fixed HIGH/CRITICAL findings, each raw report ImageID matches the built image and source HEAD 073e8c8. Fresh private scanner DB and uncached final package layers retained; this does not substitute for required CI. DAV-65 #237 merged and actual nine-image release 37361248376 succeeded; not a production deployment.

Historical snapshots below are preserved, not current acceptance claims.

Historical closeout snapshot — 2026-10-05 (local workstation; not remote-dev)

  • Head 60c07cca2. The branch is no longer merge-conflicting: origin/main was merged in with a merge commit — no rebase and no force-push.
  • Review scope. 63 files on the three-dot basis GitHub uses (merge-base(main, head)..head, merge-base b060b2dc2): 36 added, 27 modified; 36 under services/agent, 27 outside it. The "96 files / 55 outside" figure published earlier in this PR and in the DAV-45 record was wrong: it came from a two-dot diff against a main that had already moved, which counts changes on both sides and swept in files only main changed. The claim derived from it — that this branch's lockfile could revert the KaTeX pin — is retracted for the same reason: the correct 63-file list contains no package.json, pnpm-lock.yaml or pnpm-workspace.yaml.
  • Two conflicts were resolved by hand. services/agent/README.md: main restructured the file so docs/DEVELOPMENT.md owns the detailed contracts, and the deleted block was the only branch-only content in it, so main's structure was kept with a short pointer section for the two new opt-in runners. services/agent/src/deepseek_model.py: this branch's shared-budget reservation, settlement and fail-closed accounting guard were kept, together with main's _api_messages / _check_prompt_budget extraction.
  • The auto-merge also spliced decide() outside the conflict markers: main's _check_prompt_budget made prompt_tokens_estimate a local, while reserve() still needed it. The estimate now has a single owner, _prompt_tokens_estimate(). The test suite is what surfaced this — a textual merge can be silently wrong in the regions it does not mark.
  • Verified at 60c07cca2 (local): pnpm install --frozen-lockfile passes and the lockfile's overrides block matches pnpm-workspace.yaml key for key; services/agent 1124 passed / 1 skipped (optional qdrant_client absent); ./mvnw compile -B BUILD SUCCESS; focused LearningPlan gate 35 passed, including LearningPlanWriteIT's 6 real-MySQL Testcontainers tests for idempotency and owner scoping.
  • CI run 37258315484 succeeded for merge ref refs/pull/231/merge = 9c4d011821ee25cd74e79a5cc2208d032518985a, i.e. head 60c07cca2 × base b060b2dc2 (23 passed, 1 path-filtered skip, 0 failed). It does not cover head × the current main c3194bc36; no run exists for that pair and none is claimed. No remote-dev run was performed in this session.
  • A broader ./mvnw test -B across the reactor was attempted and stopped on an environment failure unrelated to this change: SearchWorkerApplicationTest fails instantiating Micrometer ProcessorMetrics (Cannot invoke "jdk.internal.platform.CgroupInfo.getMountPoint()" because "anyController" is null) under JDK 17.0.2 on kernel 7.2.5. services/search is untouched by this merge, so the failure is not attributable to it.
  • DAV-53 is still open. The local stack is not running (./scripts/dev/doctor.sh --json, exit 0: six services absent, ports free, mysql/redis/nacos/rustfs absent). .env already carries SUBMISSION_CUTOVER_COMPLETE=true, and doctor output cannot establish whether that reflects a genuinely completed cutover on the current local DB, so the stack was not started. The identity-swap and injection legs also need a real model, which the budget gate blocks.
  • DAV-58 is unchanged. No paid call was made. The SQL ledger still reads 35 attempts / 34 settled / 1 unsettled, $0.336000 reserved and $0.011447 known actual; the guard still holds 1 pending receipt with a $0.786432 reservation and no provider usage payload.
  • This PR stays Draft: offline and CI evidence do not substitute for the open DAV-53 and DAV-58 acceptance.

Historical closeout snapshot — 2026-10-04

  • Latest code: e95fd74, subject: fix: reject inline references in source refusals. It rejects explicit URLs/links/images, citation-shaped reference markers, quoted/source excerpts and provenance identifiers in wrong_citation refusals with forbid_citations=true; the artifact retains the original final_answer. source_injection remains on its existing per-citation checks.
  • Remote-dev, exact head e95fd74: focused DAV-58 regression set 284 passed; full services/agent suite 1090 passed, 1 skipped because qdrant_client.models is unavailable.
  • GitHub Actions workflow_dispatch run 37188793921 completed successfully for exact head e95fd74; real-model acceptance remains blocked on provider-usage evidence and a safe recovery path.
  • Live six-case model acceptance and paid probes were not run. A pending provider usage receipt/details and a safe recovery path are absent, so unknown usage remains unsettled and the one-shot continuation guard is not reset.
  • Accounting remains split: SQL ledger 35 attempts / 34 settled / 1 unsettled, $0.336000 reserved and $0.011447 known actual; its pending attempt reserved $0.009600 with unknown usage. Separately, the guard has 35 receipts / 34 settled / 1 pending and a $0.786432 reservation with no provider usage payload. $0.797879 is known actual plus the pending guard reservation only; it is not billed spend, and the SQL reserve total is not added to it.

This PR remains Draft / OPEN; the historical description below is retained as prior context, not overwritten.


Scope

  • Add DAV-58 six-category synthetic boundary evaluation with citation checks, provenance, per-case costs, and shared DeepSeek budget limits.
  • Extend DAV-53 dual-account isolation contrast through HTTP and the real agent tool path; require approved deepseek-flash and keep loopback/disposable target constraints.
  • The current remote head also contains the Java LearningPlan storage slice (schema/migration, service, access adapter, controller, and tests). Preserve this U03 slice without expanding it while U02 acceptance remains open.

Remote revision and validation

  • Remote head, checked 2026-10-03 11:02 UTC: 5dd6e0c17d4f5737b70c28eacf10e23bcd919bef (documentation-only failure checkpoint; parent 9e9d4b5dda1bd0e9de76eb4fc1509c8f23b36563); base agent/u02-citation-fixture at 73375e91d0dd5943129395f29fccf36f3c74ac64 (feat: let an analysis cite from an explicitly versioned corpus #230).
  • Historical deterministic Agent result on f71c7a55146c042c59e7d90e3cc5f86a5c27b905: cd services/agent && uv sync --locked && uv run pytest -q → 797 passed, 1 skipped; git diff --check passed. This result belongs to that earlier revision and does not establish validation of the current head.
  • The earlier 0590e87c check returned no commit statuses or PR-triggered Actions runs. No GitHub CI pass or current-head full-suite pass is claimed.
  • PR remains Draft; DAV-53 live dual-account acceptance and DAV-58 real-model six-category acceptance remain unverified.

DAV-58 real-model failure checkpoint | 2026-10-03 11:02 UTC

  • User-started real run at 10:35:03–10:35:17 UTC on clean 9e9d4b5d: 4/6 passed, 2/6 failed, 0 evaluator errors; exit 1. Both negative probes recorded gate_rejected=true. Immutable-version failure record and offline plan.
  • boundary-no-tool gave a correct equivalent array-index explanation but failed the fixed lexical marker. boundary-missing-id also has a genuine policy deviation: offering to list recent submissions after confirmation instead of directly asking for the specific submission ID. Both made zero tool calls and guessed no ID; these failures do not establish actual unauthorized access. Preserve the original failure artifact without relabeling it as passed.
  • 12 calls / 8,401 tokens: 9 loop + 3 judge. Usage at the frozen peak rate computes to US$0.003867 (3,867 micro-USD), not a verified provider bill. Conservative committed reservation remains US$0.1152 (115,200 micro-USD) without refund; ledger remainder US$0.8848 / 66 slots. Period is now active and was not reset; historical spend UNKNOWN and both global effectiveness flags remain false.
  • Limited offline corrections are underway for no-tool semantic/negative cases, direct missing-ID clarification, and empty response-identity slices (zero judge calls must not create unknown placeholders). No new framework, paid judge, DB/DAV-53/U03 expansion, or automatic paid rerun is authorized. No corrected-candidate pass is claimed.
  • Config SHA-256: edf4ae8520baf9fb6a530495355976c9350495d6bd0c6b8a72af29f12ea7d1ef; original artifact SHA-256: c6033d0b313bd24dec6c6eb9f0258dd7e9df19dfc39f2919dc0e6b3a8fb137d3.
  • DAV-58 remains unaccepted; DAV-45 stays In Progress at 5/7 and DAV-53 remains open. Earlier statements about no live call or inactive period are historical and superseded by this run.

Historical DAV-58 explicit period-binding checkpoint | 2026-10-03 06:29 UTC

  • 9e9d4b5d binds the existing standalone e2e_boundary_evaluation.py through authorized_model(expected) to one explicitly selected existing active PeriodIdentity/ledger. Loop 24 + judge 42 share the US$1 / 78-call ceiling; DAV-53's reserved 12 calls remain untouched.
  • Missing, wrong, or non-active identities fail before HTTP without fallback. Legacy no-argument factory ledger selection is unchanged; the shared DeepseekModel accounting-failure latch also applies to legacy callers.
  • Focused verification: 129 passed, exit 0, using a 77-file isolated candidate, dummy key, temporary SQLite, and MockTransport. All seven changed GitHub blobs were independently matched to the tested candidate. This is focused offline evidence, not a full-suite, CI, or live-model acceptance result.
  • Earlier 6ef0028 retained 79 passed / 2 failed; 5a270e7 fixed the SQLite auxiliary-descriptor lock issue and its exact-archive focused verification recorded 84 passed, exit 0.
  • No real key, provider call, or real-period preparation/activation was used. Global runtime_accounting_connected=False and spend_limit_enforced=False; historical spend remains UNKNOWN. DAV-58's real six-category matrix and DAV-53's live A/B gate remain open; DAV-45 remains In Progress at 5/7. Main-worktree WIP was preserved.

Historical local, unpublished verification | 2026-10-03 01:56 UTC

These results are separate from the remote PR and its CI.

  • Local-only commit f466d9c735ef36dbc25237a5493a3493cf4c433d, parent 0590e87c, changes only scripts/dev/lib/sql.sh and scripts/dev/migrate-owner-preflight-test.sh (31 additions / 8 deletions). It adjusts the container MySQL stdin transport and the owner-preflight fake fixture. It has not been pushed.
  • The isolated HEAD-archive + minimal-patch verification passed both fake-SQL contracts (exit 0).
  • A separate mixed local worktree run recorded Agent 886 passed / 1 skipped (exit 0) and static checks exit 0. This is not a clean-commit full-suite result for f466d9c, nor remote-head CI.
  • Same-image database restore verification passed: 6 schemas / 186 tables, matching source/target checksum, three-table parity, zero active writers, and the post-cutover app-grant check. These are restore/cutover prerequisites, not DAV-53 or DAV-58 acceptance evidence.

Historical stage boundary — superseded by b9d5801 HTTP acceptance

  • Prioritize U02: close DAV-53 and DAV-58 with attributable live evidence. Keep the existing U03 storage slice bounded until that work is complete.
  • Historical statement at this checkpoint: DAV-53 still needed all five live A/B acceptance checks. Superseded: the final real HTTP run on b9d5801 passed four nonpaid acceptance items; only the actual-model adversarial item remains open. Restore/fake-contract checks alone did not satisfy those HTTP items.
  • DAV-58's standalone e2e_boundary_evaluation.py uses the synthetic boundary client/corpus and does not require a database or APP/AUTH readiness. Keep this route independent of the combined runner's service-readiness checks; the first real-model six-category run failed and acceptance remains pending.
  • The DAV-58 run used the standalone synthetic route and does not establish business-service readiness or DAV-53 acceptance. The existing budget period is active; no reset or automatic paid rerun is authorized.
  • The owner's independent coding/explanation learning checkpoint is deferred and is not an additional delivery gate.

HEAD archive owner-preflight and fake-SQL contracts passed offline.

Live validation is not included.
Checkpoint only: explicit prepared/active/halted metadata and pinned
policy/config/period identity, with UNKNOWN historical usage.
Runtime accounting is not connected; actual spending limits are not
enforced by this lifecycle layer. No reserve/settle, provider, runner,
DAV-53 or U03 integration is included. Live acceptance remains pending.

Verified in the f466d9c HEAD archive: independent import and 48 focused
temporary-path tests pass; scope/secret scans and diff checks pass.
Checkpoint only: runtime binding candidate has a known SQLite descriptor lifetime blocker. Focused proof: 79 passed, 2 failed; original 57 regression tests pass. No runner/provider wiring, live initialization or activation; live acceptance remains open. Preserve UNKNOWN history and original worktree WIP.
Checkpoint: avoid auxiliary ledger descriptors while SQLite connections are open; verify bound inode identity with stat and use SQLite FULL synchronization. Preserve canonical configuration and shared atomic period accounting. Focused temporary-environment regression proof passed; no runner/provider wiring or live initialization, activation or acceptance. Historical spend remains UNKNOWN.
Checkpoint: bind only the standalone DAV58 runner to an explicitly selected existing active canonical period. Preserve legacy no-argument authorization callers, shared purpose accounting and historical UNKNOWN spend. Focused temporary SQLite and MockTransport verification passed; no real key, provider request, period preparation or activation. Provider effectiveness flags remain false and live acceptance remains open.
@DavidHLP
DavidHLP changed the base branch from agent/u02-citation-fixture to main October 4, 2026 15:48
DavidHLP and others added 6 commits October 5, 2026 10:57
Resolves the two conflicted paths, keeping both sides' intent:

- services/agent/README.md: main restructured this file so the canonical
  guide (docs/DEVELOPMENT.md) owns the detailed contracts, and the block
  removed here was the only branch-only content in the file. Take main's
  structure, and keep the two new opt-in runners discoverable through a
  short pointer section rather than a second copy of the guide.
- services/agent/src/deepseek_model.py: keep this branch's shared-budget
  reservation, settlement and fail-closed accounting guard, while taking
  main's extraction of `_api_messages` and `_check_prompt_budget`.

The auto-merge also spliced `decide()` outside the conflict markers: main's
`_check_prompt_budget` made `prompt_tokens_estimate` a local, while
`reserve()` still needed it. The estimate now has a single owner,
`_prompt_tokens_estimate()`, called by both the check and `decide()`.

Verified on this merge: services/agent 1124 passed / 1 skipped (optional
qdrant_client absent); `./mvnw compile -B` BUILD SUCCESS; focused
LearningPlan gate 35 passed, including LearningPlanWriteIT's 6 real-MySQL
Testcontainers idempotency and owner-scoping tests.

Co-Authored-By: Claude Code <noreply@anthropic.com>
Keep model tools read-only and require explicit confirmation before Java\nlearning-plan writes. Persist private workflow state and reconcile unknown\nwrites through the original idempotency key.\n\nBind acceptance evidence to source, budget identity, and raw receipts.\nMissing original accounting or unauthorized purposes remain fail-closed;\noffline checks never grant spend or mark real acceptance complete.
@DavidHLP DavidHLP changed the title feat(agent): add boundary and account isolation evaluation gates feat(agent): add gated durable learning workflows Oct 6, 2026
Resolve CVE-2026-47884 with Spring Framework 7.0.9 via the supported Boot 4 BOM. Preserve Java 17, Jackson 2 payloads, authentication, Redis SCAN policy and OTLP tracing while migrating owner auto-configuration and test modules.

Verify full unit reactor, real MySQL learning-plan writes, Boot/Dubbo local RPC and security regressions; retain all image vulnerability gates.
Boot 4.1.1 ships spring-boot-grpc-server through the classic autoconfigure aggregate while wildcard-excluding its spring-grpc-core dependency, so the module registers GrpcDisableCsrfHttpConfigurer without the class it loads on every HttpSecurity build. Exclude it where spring-boot-starter-classic is declared, which covers every consumer, and drop the now-redundant per-consumer workaround in Core.
@DavidHLP
DavidHLP requested a review from thana0623 October 7, 2026 11:32
@DavidHLP
DavidHLP removed the request for review from thana0623 October 7, 2026 14:14
@DavidHLP
DavidHLP requested a review from thana0623 October 7, 2026 14:30
@DavidHLP
DavidHLP marked this pull request as ready for review October 7, 2026 15:34
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T15:52:27.862156Z 1f1bf0c Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1f1bf0ce04

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +79 to +81
return await run_readonly_graph(
model, tools, user_input, max_rounds=max_rounds
)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Pass the requested timeout to the graph

When callers request more than 30 seconds, this delegation silently retains run_readonly_graph's 30-second default, so existing 90-second real-model runs such as e2e_model_qa.py and e2e_account_isolation.py now fail halfway through their advertised allowance. Forward total_timeout into the graph instead of wrapping a second, longer timeout around a call that always expires first.

Useful? React with 👍 / 👎.

async def operation(client: UlticodeClient, owner: str):
submission = await client.get_my_submission(source_id)
source, status = validate_submission_facts(submission)
if source.lower() != source_id:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve source-not-owned errors during thread creation

When sourceSubmissionId does not exist or belongs to another account, this call raises UlticodeServiceError(40400, 404), but unlike _verify_source this path does not translate it; with_session subsequently maps every non-auth service error to 502 upstream_unavailable. Consequently a normal invalid/foreign source is reported as an infrastructure outage rather than the documented 404 source_not_owned, so handle the precise 404 response here before it reaches the generic wrapper.

Useful? React with 👍 / 👎.

Comment on lines +262 to +268
status_claim = re.search(
r"\bstatus\s*(?:is|=|:)\s*([A-Za-z_-]+)|状态\s*(?:为|是|=|:)\s*([A-Za-z_-]+)",
text, flags=re.IGNORECASE,
)
if status_claim and isinstance(actual_status, str) and (
(status_claim.group(1) or status_claim.group(2)).casefold() != actual_status.casefold()
):

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Match the complete submission status

For multi-word statuses, this regex captures only the first word, so a correct answer such as The submission status is Wrong Answer is compared as Wrong against the actual Wrong Answer and rejected with answer_submission_fact_mismatch. The same occurs for common values such as Time Limit Exceeded and Runtime Error, causing otherwise valid analysis runs to fail; match one of the complete allowed status values rather than a single token.

Useful? React with 👍 / 👎.

Comment thread services/app/pom.xml
@@ -25,6 +25,7 @@
<module>modules/problem</module>
<module>modules/contest</module>
<module>modules/moderation</module>
<module>modules/learningplan</module>

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Register the learning-plan domain in the Core app context

Adding this App-private module makes it available to the standalone backend-app, but the opt-in backend-core profile assembles App through the explicit package list in CoreOwnerBootConfigurations.App, which does not include com.ulticode.modules.learningplan. In that supported profile the controller, service configuration, and remote access adapter are therefore never created, so every new /learning-plans route is absent even though the module is on the classpath.

Useful? React with 👍 / 👎.

Comment on lines +305 to +307
def _deterministic_business_error(exc: UlticodeServiceError) -> bool:
return exc.status_code in {400, 401, 403, 409} or (
exc.status_code == 200 and exc.code in {40000, 40100, 40300, 40900}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep transient authorization outages retryable

Classifying every HTTP 401/403 as deterministic makes a transient dependency failure terminal: RemoteLearningPlanAccessAdapter deliberately returns 401 when its Auth RPC is unavailable, before opening the write transaction, but this predicate makes the Agent transition the thread to failed with retry_blocked=1. A brief Auth/Dubbo outage between /auth/me and the Java save therefore permanently prevents that confirmed draft from being saved or explicitly recovered, even though no write was attempted; distinguish transient verification failures from actual payload or idempotency rejections.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant