docs(research): hal0 × ODS field study — comparison, observed install, adoption plan - #2237
Draft
thinmintdev wants to merge 1 commit into
Draft
thinmintdev wants to merge 1 commit into
thinmintdev wants to merge 1 commit into
Conversation
…, adoption plan Adds docs/research/ods-field-study-2026-09/: a source-level comparison of Osmantic ODS (v2.6.0 line, 21f4b3a) and hal0 (108b366), a journal of a sandbox install of ODS, all 106 open issues triaged against ODS's code, and a ranked port ledger in waves. The HTML is self-contained (reports and screenshots embedded); the nine domain reports and the install journal are also committed as Markdown. Headline findings recorded in the study, none acted on here: - /api/agent/approvals/{id}/approve executes gated tools with auth removed on a LAN-open default bind; ODS's stateless signed-cookie module is a near-verbatim fix. - hal0-Max's coder pick (Qwen3-Coder-Next-80B-A3B) is the family ODS's fleet tests found broken on unified-memory backends; needs a verdict on real hardware before shipping. - ODS ships no MCP; hal0 already has most of a user-added MCP registry and the study specifies the three missing pieces. - ODS's two-file extension model is verified (fourteen auto-attaching consumers) and translated into a manifest.toml → hal0-ext@<id> quadlet proposal. - The install surfaced an ODS bug (host agent inherits the installer's lock descriptor in the non-systemd path) and two IPv6-less-kernel crash loops relevant to LXC hosts. Signed-off-by: Alexander <alexander@awideweb.com> Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ntx2XQ8VhpG78MLxpWXDZR
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
docs/research/ods-field-study-2026-09/: a source-level comparison of Osmantic ODS (v2.6.0 line,21f4b3a) and hal0 (108b366), a journal of a sandbox install of ODS, all 106 open hal0 issues triaged against ODS's code, and a ranked port ledger in waves. The HTML is self-contained (nine domain reports and install screenshots embedded); the reports and journal are also committed as Markdown so they diff and cite cleanly. Nothing is acted on in this PR; it is a research note in thedocs/research/convention, for the maintainers to decide on. Headline findings it records: the approvals endpoints execute gated tools with auth removed on a LAN-open default bind (ODS's stateless signed-cookie module is a near-verbatim fix); hal0-Max's coder pick is the model family ODS's fleet tests found broken on unified-memory backends and needs a verdict on real hardware; ODS ships no MCP while hal0 already has most of a user-added MCP registry; ODS's two-file extension model is verified and translated into amanifest.toml → hal0-ext@<id>quadlet proposal.Risk grade
Touched surfaces
src/hal0/api/)src/hal0/auth/, login routes, middleware)src/hal0/slots/,slot_state,/v1/load|unload)src/hal0/capabilities/,model_meta,model_fit)installer/, systemd units)src/hal0/updater/,hal0.releases.v1manifest)src/hal0/api/routes/board_chat.py,src/hal0/mcp/admin.py)src/hal0/config/, pydantic models)ui/src/, Playwright specs)docs/,CONTRIBUTING.md).github/workflows/,release.yml)§14.1 high-risk surfaces
/v1/board/*or MCP endpoint exposed without auth middleware (KB-1 / §1 deny-by-default)AUTONOMOUS_WRITE_TOOLS— additions to the write set insrc/hal0/mcp/admin.py(board-chat auto-actions)None touched. The study documents that
src/hal0/api/routes/approvals.pyruns gated tools unauthenticated, but this PR does not change any route.Rollback
Rollback: revert the single commit, or delete
docs/research/ods-field-study-2026-09/. No code, config, or CI is touched.Test tiers run
make test) — passed in CI ona9d7c96(thepython (3.12)job, ~28 min). A local run in the authoring sandbox (4 vCPU shared with a running ODS stack) did not complete inside the session's time budget; CI is the authority for this docs-only PR.make test-integration) — not applicable to a docs-only change.make release-test) — not required (low risk); theγ-suite (chromium)job ran and passed on this head regardless.Notes for reviewers
docs/research/ods-field-study-2026-09/**is added (HTML ≈ 3 MB because screenshots are embedded as data URIs; the Markdown reports are the reviewable text).vmand the/home/odspaths in the journal are the sandbox's.CHANGELOG.md(chore: gitignore docs/internal/ and untrack 84 internal docs #638: ADR texts live in the gitignored internal tree); the remaining drift it flags is theCLAUDE.mdvsARCHITECTURE.mddisagreement about whetherdocs/adr/is the record.a9d7c96: CodeQL, ui, sunset, python (3.12), γ-suite (chromium), detect, and the three analyzers;engine-gateskipped (no engine paths touched).🤖 Generated with Claude Code
https://claude.ai/code/session_01Ntx2XQ8VhpG78MLxpWXDZR