Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
19 commits
Select commit Hold shift + click to select a range
a1aaeca
chore: stage interaction engine source 1/18
Masterleeaus Aug 2, 2026
637248e
chore: stage streamlined interaction engine source 1/13
Masterleeaus Aug 2, 2026
d2bdf26
chore: stage streamlined interaction engine source 2/13
Masterleeaus Aug 2, 2026
7c41674
chore: stage streamlined interaction engine source 3/13
Masterleeaus Aug 2, 2026
58e0c04
chore: stage streamlined interaction engine source 4/13
Masterleeaus Aug 2, 2026
f1395c2
chore: stage streamlined interaction engine source 5/13
Masterleeaus Aug 2, 2026
c2900a1
chore: stage streamlined interaction engine source 6/13
Masterleeaus Aug 2, 2026
baf40a5
docs: plan assurance template workflows
Masterleeaus Aug 2, 2026
37199fc
ci: reconstruct and verify source transport
Masterleeaus Aug 2, 2026
f188835
ci: recover source from verified MiniUp payload
Masterleeaus Aug 2, 2026
c2eda2e
ci: publish TypeScript-compatible verified source
Masterleeaus Aug 2, 2026
ddbfbf7
ci: publish current WebCrypto-compatible source
Masterleeaus Aug 2, 2026
2dfc4c4
feat: publish governed assurance templates
github-actions[bot] Aug 2, 2026
9a330ca
ci: verify reconstructed interaction engine source
Masterleeaus Aug 2, 2026
47e3fe6
ci: retire one-shot source reconstruction workflow
Masterleeaus Aug 2, 2026
3abddb4
ci: import commerce and multi-vertical template pack
Masterleeaus Aug 2, 2026
5293a2d
ci: preserve workflow files during template import
Masterleeaus Aug 2, 2026
714fc4c
feat: add commerce and multi-vertical template pack
github-actions[bot] Aug 2, 2026
6a003f3
chore: trigger post-import verification
Masterleeaus Aug 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
100 changes: 100 additions & 0 deletions .github/workflows/import-commerce-multi-vertical.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,100 @@
name: Import Commerce and Multi-Vertical Template Pack

on:
pull_request:
branches: [main]
types: [opened, synchronize, reopened]
workflow_dispatch:

permissions:
contents: write

concurrency:
group: import-commerce-${{ github.event.pull_request.head.ref || github.ref_name }}
cancel-in-progress: false

jobs:
import:
if: >-
${{
(github.event_name == 'workflow_dispatch' && github.ref_name == 'feature/full-engine-template-upgrade') ||
(github.event_name == 'pull_request' && github.event.pull_request.head.ref == 'feature/full-engine-template-upgrade')
}}
runs-on: ubuntu-latest
steps:
- name: Check out feature branch
uses: actions/checkout@v4
with:
ref: feature/full-engine-template-upgrade
fetch-depth: 0
persist-credentials: true

- name: Detect completed import
id: state
shell: bash
run: |
if [[ -f reports/workcore-compatibility.json ]] && php -r '$r=json_decode(file_get_contents("reports/workcore-compatibility.json"), true); exit(($r["summary"]["total_templates"] ?? 0) === 38 ? 0 : 1);'; then
echo "complete=true" >> "$GITHUB_OUTPUT"
else
echo "complete=false" >> "$GITHUB_OUTPUT"
fi

- name: Download checksum-pinned source
if: steps.state.outputs.complete != 'true'
shell: bash
env:
SOURCE_URL: https://interaction-engine-source-v3.miniup.app/interaction-engine-source.tar.gz
SOURCE_SHA256: d8f0bca52e54d40981ee7a9a345ff04edf56f5d75ba7b418995cb2dfb2fe11e1
run: |
set -euo pipefail
archive=/tmp/interaction-engine-source.tar.gz
unpacked=/tmp/interaction-engine-source
rm -rf "$archive" "$unpacked"
mkdir -p "$unpacked"
curl --fail --location --silent --show-error --retry 3 --retry-all-errors "$SOURCE_URL" --output "$archive"
actual="$(sha256sum "$archive" | awk '{print $1}')"
test "$actual" = "$SOURCE_SHA256"
tar -tzf "$archive" >/tmp/archive-list.txt
tar -xzf "$archive" -C "$unpacked"
package_root=''
while IFS= read -r composer_file; do
candidate="$(dirname "$composer_file")"
if [[ -d "$candidate/src" && -d "$candidate/wizards" && -d "$candidate/templates" && -f "$candidate/bin/verify.php" ]]; then
package_root="$candidate"
break
fi
done < <(find "$unpacked" -type f -name composer.json | sort)
test -n "$package_root"
rsync -a --delete \
--exclude='.git/' \
--exclude='.github/' \
"$package_root/" ./

- name: Verify imported source
if: steps.state.outputs.complete != 'true'
shell: bash
run: |
set -euo pipefail
php bin/verify.php
php_count=0
while IFS= read -r -d '' file; do php -l "$file" >/dev/null; php_count=$((php_count+1)); done < <(find src tests bin routes config database -type f -name '*.php' -print0 2>/dev/null)
json_count=0
while IFS= read -r -d '' file; do php -r 'json_decode(file_get_contents($argv[1]), true, 512, JSON_THROW_ON_ERROR);' "$file"; json_count=$((json_count+1)); done < <(find wizards templates resources config reports -type f -name '*.json' -print0 2>/dev/null)
test "$php_count" -eq 336
test "$json_count" -eq 69
php -r '$r=json_decode(file_get_contents("reports/workcore-compatibility.json"), true, 512, JSON_THROW_ON_ERROR); exit(($r["summary"]["total_templates"] ?? 0) === 38 && ($r["summary"]["ready_templates"] ?? 0) === 29 && ($r["summary"]["draft_templates"] ?? 0) === 9 ? 0 : 1);'

- name: Commit verified source
if: steps.state.outputs.complete != 'true'
shell: bash
run: |
set -euo pipefail
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add -A
if git diff --cached --quiet; then
echo "No changes to commit."
exit 0
fi
git commit -m "feat: add commerce and multi-vertical template pack"
git push origin HEAD:feature/full-engine-template-upgrade
50 changes: 50 additions & 0 deletions .github/workflows/verify.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
name: Verify Interaction Engine

on:
pull_request:
push:
branches:
- main
- feature/full-engine-template-upgrade
workflow_dispatch:

permissions:
contents: read

concurrency:
group: verify-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
verify:
runs-on: ubuntu-latest
steps:
- name: Check out source
uses: actions/checkout@v4

- name: Run complete engine verification
shell: bash
run: php bin/verify.php

- name: Lint PHP and validate JSON
shell: bash
run: |
set -euo pipefail

php_files=()
while IFS= read -r -d '' file; do
php_files+=("$file")
done < <(find src tests bin routes config database -type f -name '*.php' -print0 2>/dev/null)
for file in "${php_files[@]}"; do
php -l "$file" >/dev/null
done
echo "PHP syntax valid: ${#php_files[@]} files"

json_files=()
while IFS= read -r -d '' file; do
json_files+=("$file")
done < <(find wizards templates resources config reports -type f -name '*.json' -print0 2>/dev/null)
for file in "${json_files[@]}"; do
php -r 'json_decode(file_get_contents($argv[1]), true, 512, JSON_THROW_ON_ERROR);' "$file"
done
echo "JSON valid: ${#json_files[@]} files"
2 changes: 2 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@

.worktrees/
107 changes: 107 additions & 0 deletions CHANGELOG_PHASE10_FIX_PASS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,107 @@
# Fix Pass Changelog — InteractionEngine Phase 10 (Local Intelligence)

**Date**: July 29, 2026
**Starting point**: `TitanZero_InteractionEngine_Cumulative_Phase10_LocalIntelligence.zip`, previously scanned (see `InteractionEngine_Phase10_MissingCode_Scan.md`)
**Validation**: `php -l` on all 307 PHP files, full cross-reference of all 315 `use` imports plus every inline fully-qualified `::class` reference added during this pass, and the bundled test suite actually executed after every change (`php tests/run.php` — 16/16 passing throughout, not just at the end).

This archive started from a meaningfully better place than Phase 8/9 — no fragment files, no fabricated test claims, all 301 files already passed `php -l`. This changelog covers the six real gaps the scan found.

---

## 1. LocalIntelligence persistence — the big one

The scan's headline finding: `src/LocalIntelligence/` (`BehavioralMemory`, `TemporalIntelligence`, `PredictiveCompletionEngine`, `AdaptiveReweightingEngine`) held all state in plain PHP arrays on a request-scoped singleton, so nothing "learned" survived past the current HTTP request — despite a purpose-built `local_intelligence_memories` migration and `LocalIntelligenceMemory` Eloquent model already existing in the archive, unreferenced by anything.

**Fix**: built the missing connective layer.

- `src/LocalIntelligence/Storage/LocalIntelligenceMemoryStoreInterface.php` — a generic `get`/`all`/`put` contract scoped by tenant/user/device/type/key, matching the migration's schema.
- `src/LocalIntelligence/Storage/EloquentLocalIntelligenceMemoryStore.php` — the real implementation, backed by the `LocalIntelligenceMemory` model. Caught and fixed a real bug while writing it: Laravel's `where('column', null)` compiles to `column = NULL`, which never matches in SQL — the null-scope case needs `whereNull()` explicitly.
- `src/LocalIntelligence/Storage/NullLocalIntelligenceMemoryStore.php` — no-op default, so nothing breaks where no store is configured.
- `BehavioralMemory`, `TemporalIntelligence`, `PredictiveCompletionEngine`, `AdaptiveReweightingEngine` — each now writes through to the store on every record/observe call, and hydrates from the store once per request on first read for a given key (tracked via an internal "already hydrated" set, so it's one query per key per request, not one per call).
- `LocalBrain::createDefault()` — **left completely untouched**. It's what `tests/run.php` uses (no database in that harness), and every engine it constructs still defaults to `NullLocalIntelligenceMemoryStore`, so its behavior is unchanged.
- `LocalBrain::createWithPersistence()` — new factory for real use, wired into the service provider.

**A design correction made along the way**: my first draft baked `$userId` into `TemporalIntelligence`/`PredictiveCompletionEngine`/`AdaptiveReweightingEngine`'s constructors, matching how I'd initially wired the provider. That's a latent bug under Octane or any long-running-worker deployment — a singleton constructed once with one user's ID baked in would silently mix that user's temporal/prediction data into every other user's requests handled by the same worker afterward. Refactored all three to accept `$userId` per-call instead, exactly matching the pattern `BehavioralMemory` already used correctly.

## 2. Regression: `InteractionRuntime::start()` lost its null check

`InteractionRegistry::get()` returns `?InteractionDefinition`, but `start()` dereferenced `$definition->version` unconditionally. Restored the null check (present in the Phase 9 fix, dropped somewhere in this archive's regeneration):

```php
$definition = $this->registry->get($interactionId);
if ($definition === null) {
throw new \RuntimeException("Interaction '{$interactionId}' not found.");
}
```

## 3. Wizard offline outbox was unreachable

The bug wasn't in `UniversalWizardEngine` — its nullable-`CommandBus` design (`null` → queue to `LocalCommandOutbox`, real bus → dispatch immediately) is correct and is exactly what the bundled tests exercise. The bug was in the **service provider**, which registered it with plain `$this->app->singleton(UniversalWizardEngine::class)`, letting Laravel always inject a real `CommandBus` (bound elsewhere in the same provider) regardless of actual connectivity — making the offline branch dead code in production.

**Fix**: register it with a factory that checks `OfflineDetector::isOffline()` (the same signal `InteractionRuntime` already uses correctly) and passes `null` or a real bus accordingly:

```php
$this->app->singleton(UniversalWizardEngine::class, function ($app): UniversalWizardEngine {
$offline = config('interaction.offline.enabled', true) && $app->make(OfflineDetector::class)->isOffline();
return new UniversalWizardEngine(..., $offline ? null : $app->make(CommandBusInterface::class));
});
```

This preserves the exact class design the tests validate (constructing with vs. without a bus) while fixing how the provider decides which to inject.

## 4. Executive/Cognitive/World split-state — same bug as Phase 9, different mechanism, still broken

This archive's attempt at consolidating the duplicate `ExecutiveEngine`/`CognitiveOrchestrator`/`WorldModel` concepts used a subclass bridge pattern (`class ExecutiveEngine extends \TitanZero\Engines\Executive\Implementations\ExecutiveEngine implements LegacyContract {}`) — a reasonable idea. But the provider still bound both interfaces independently via separate `singleton()` calls, so Laravel constructed two separate objects (one legacy-namespace subclass instance, one parent-class instance) with two separate internal states.

**Fix**: same approach as the Phase 9 fix — bind the real `TitanZero\Engines\...` concrete class once, then alias both the new-namespace interface and the legacy interface to that single instance:

```php
$this->app->singleton(\TitanZero\Engines\Executive\Implementations\ExecutiveEngine::class);
$this->app->singleton(\TitanZero\Engines\Executive\Contracts\ExecutiveEngineInterface::class,
fn ($app) => $app->make(\TitanZero\Engines\Executive\Implementations\ExecutiveEngine::class));
$this->app->singleton(ExecutiveEngineInterface::class,
fn ($app) => $app->make(\TitanZero\Engines\Executive\Implementations\ExecutiveEngine::class));
```
(repeated for `CognitiveOrchestrator` and `WorldModelEngine`)

The three bridge subclass files (`src/Executive/ExecutiveEngine.php`, `src/Cognitive/Orchestrator/CognitiveOrchestrator.php`, `src/World/WorldModel.php`) are now redundant — nothing constructs them once the real class satisfies both interfaces directly — and were deleted, along with their now-unused imports in the provider. Also removed the three engine names (`ExecutiveEngine`, `CognitiveOrchestrator`, `WorldModelEngine`) from `registerEngineLibrary()`'s generic domain loop, since binding them there too would recreate the exact problem being fixed.

## 5. 33 hollow engine methods fixed

The scan found 33 of 288 engine methods still returning hardcoded values regardless of input — down from 71 in the Phase 9 archive, but unevenly distributed (some engines, like `VectorSearchEngine`, had been genuinely rewritten; others, like `SentimentEngine`, were byte-identical to the original broken version).

Verified the interfaces for all 19 affected files are byte-identical to the Phase 9 archive's, then reused the real implementations already built and tested during the Phase 9 fix pass: `EvaluationEngine`, `ModelSelectionEngine`, `PromptOptimizationEngine`, `AnalyticsEngine`, `CRMIntelligenceEngine`, `OperationsEngine`, `CreativityEngine`, `ExplainabilityEngine`, `ReflectionEngine`, `GovernanceEngine`, `EmotionEngine`, `EmpathyEngine`, `PersonalityEngine`, `ResponseGenerationEngine`, `SentimentEngine`, `TrustEngine`, `SchedulingEngine`, plus `SemanticEngine::embed()` and `IntentEngine::getConfidence()` (targeted method-level fixes rather than whole-file replacements, since those two files already had other real methods).

One of these — `SemanticEngine::embed()` — now delegates to `EmbeddingEngineInterface` rather than duplicating logic. This archive's own `EmbeddingEngine` had already been independently rewritten with a real (and reasonably sophisticated) token-level hashing embedding, so the delegation picks that up automatically.

All 33 originally-flagged methods are now genuinely input-derived. Re-running the same detection heuristic after this pass: **0 remaining.**

## 6. Six of seven missing migrations added

The Phase 9 scan (which this archive was partly built from) found 7 tables referenced by `DB::table()` calls with no migration anywhere. This archive had already added one (`local_intelligence_memories`, for an unrelated purpose — see §1). Verified the remaining 6 engines' table/column usage is unchanged from what the Phase 9 migrations already handle, then added them with fresh timestamps so they sort after this archive's existing migrations:

| Table | Engine |
|---|---|
| `episodic_memory` | `EpisodicMemoryEngine` |
| `semantic_memory` | `SemanticMemoryEngine` |
| `audit_logs` | `AuditEngine` |
| `governance_logs` | `GovernanceEngine` |
| `user_actions` | `BehaviourLearningEngine` |
| `user_preferences` | `PreferenceLearningEngine` |

`BehaviourLearningEngine` in particular is worth noting: it already had defensive `try/catch` around its `DB::table('user_actions')` calls, silently falling back to request-local-only memory when the table doesn't exist — genuinely good defensive coding, but it meant the persistence it was clearly designed for was silently never happening. It needed nothing but the migration.

---

## Verification

Re-ran the full check after every change, not just at the end:

- `php -l` across all 307 PHP files: clean throughout
- `use`-statement and inline `::class` cross-reference: all resolve
- `php tests/run.php`: **16/16 passing** after every single fix in this changelog, including the persistence layer, the provider rewiring, and the bridge-class removal
- Hollow-method scan: 33 → 0

## What this doesn't cover

Same caveat as the Phase 8 and Phase 9 fix passes: no live Laravel app or real database was available in this environment, so the migrations and Eloquent queries are verified by syntax and manual schema cross-reference, not by actually running them against a database. Before merging into Titan Zero: `composer install`, run migrations for real, and exercise `LocalBrain::process()` across two separate requests for the same user to confirm the persistence fix in §1 actually produces the cross-request learning it's designed for.
34 changes: 34 additions & 0 deletions CHANGELOG_PHASE11_COGNITIVE_EVENTS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
# Phase 11 — Cognitive Event and Outcome Foundation

## Added

- Canonical tenant-scoped cognitive event envelope with UUID, correlation, sequence, provenance, evidence, confidence, policy, privacy and model metadata.
- Immutable event types covering observations, recommendations, corrections, approvals, commands, outcomes, prediction scoring and model updates.
- Eloquent and in-memory idempotent event stores.
- Observation, decision and outcome recorders.
- Prediction-to-outcome linker using Brier scoring.
- Tenant-isolated correlation timelines.
- Device-side AES-256-GCM cognitive event outbox with deterministic replay ordering.
- API endpoints for outcome submission, correction recording and correlation timelines.
- Wizard and command path event emission.

## Corrected

`LocalBrain::process()` no longer writes its own recommendation into confirmed behavioural history. Only `confirmAction()`, command execution, corrections or observed outcomes may become learning evidence.

## Database

Run the new migration:

```bash
php artisan migrate
```

Creates `interaction_cognitive_events` with tenant-first compound keys and correlation, subject, event-type and user indexes.

## Verification

```bash
composer test
npm test
```
16 changes: 16 additions & 0 deletions CHANGELOG_PHASE14_AUTHORITY_CONTROLS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
# Phase 14 — Authority and Human-Only Controls

## Added
- Fail-closed capability policy registry.
- Six authority levels: observe-only, recommend-only, prepare-only, approval-required, delegated-autonomous, and user-only.
- Cryptographically signed, tenant-scoped, capability-scoped, expiring approval grants.
- Fresh-authentication checks for user-only commands.
- Required-role, delegated-scope, and numeric-limit enforcement.
- Command-bus authority decisions recorded into the cognitive event stream.
- Offline replay context reconstruction for tenant, device, user, actor type, roles, scopes, authentication time, and approval evidence.

## Security corrections
- Removed the former allow-by-default behaviour for unknown capabilities.
- Removed reliance on client-controlled `manager_approved` booleans.
- Device replay can no longer inherit human authority implicitly.
- Payment recording is configured as a user-only, freshly authenticated action.
3 changes: 3 additions & 0 deletions EXTRACTION-NOTES.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
# Extraction notes

This package was already structured as `titanzero/interaction-engine` in the donor application. It is preserved intact. WorkCore capability handlers must be mapped to the canonical actions in the consolidated WorkCore package before production activation.
Loading
Loading