Repository navigation
Conversation
HEAD archive owner-preflight and fake-SQL contracts passed offline. Live validation is not included.
Checkpoint only: explicit prepared/active/halted metadata and pinned policy/config/period identity, with UNKNOWN historical usage. Runtime accounting is not connected; actual spending limits are not enforced by this lifecycle layer. No reserve/settle, provider, runner, DAV-53 or U03 integration is included. Live acceptance remains pending. Verified in the f466d9c HEAD archive: independent import and 48 focused temporary-path tests pass; scope/secret scans and diff checks pass.
Checkpoint only: runtime binding candidate has a known SQLite descriptor lifetime blocker. Focused proof: 79 passed, 2 failed; original 57 regression tests pass. No runner/provider wiring, live initialization or activation; live acceptance remains open. Preserve UNKNOWN history and original worktree WIP.
Checkpoint: avoid auxiliary ledger descriptors while SQLite connections are open; verify bound inode identity with stat and use SQLite FULL synchronization. Preserve canonical configuration and shared atomic period accounting. Focused temporary-environment regression proof passed; no runner/provider wiring or live initialization, activation or acceptance. Historical spend remains UNKNOWN.
Checkpoint: bind only the standalone DAV58 runner to an explicitly selected existing active canonical period. Preserve legacy no-argument authorization callers, shared purpose accounting and historical UNKNOWN spend. Focused temporary SQLite and MockTransport verification passed; no real key, provider request, period preparation or activation. Provider effectiveness flags remain false and live acceptance remains open.
Resolves the two conflicted paths, keeping both sides' intent: - services/agent/README.md: main restructured this file so the canonical guide (docs/DEVELOPMENT.md) owns the detailed contracts, and the block removed here was the only branch-only content in the file. Take main's structure, and keep the two new opt-in runners discoverable through a short pointer section rather than a second copy of the guide. - services/agent/src/deepseek_model.py: keep this branch's shared-budget reservation, settlement and fail-closed accounting guard, while taking main's extraction of `_api_messages` and `_check_prompt_budget`. The auto-merge also spliced `decide()` outside the conflict markers: main's `_check_prompt_budget` made `prompt_tokens_estimate` a local, while `reserve()` still needed it. The estimate now has a single owner, `_prompt_tokens_estimate()`, called by both the check and `decide()`. Verified on this merge: services/agent 1124 passed / 1 skipped (optional qdrant_client absent); `./mvnw compile -B` BUILD SUCCESS; focused LearningPlan gate 35 passed, including LearningPlanWriteIT's 6 real-MySQL Testcontainers idempotency and owner-scoping tests. Co-Authored-By: Claude Code <noreply@anthropic.com>
Keep model tools read-only and require explicit confirmation before Java\nlearning-plan writes. Persist private workflow state and reconcile unknown\nwrites through the original idempotency key.\n\nBind acceptance evidence to source, budget identity, and raw receipts.\nMissing original accounting or unauthorized purposes remain fail-closed;\noffline checks never grant spend or mark real acceptance complete.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1f1bf0ce04
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4fdf766707
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Summary
Adds an opt-in Agent workflow for submission analysis and learning-plan creation. Authenticated users can analyze an owned submission, review a durable draft, explicitly confirm it, and save it through the Java App service. Model execution uses read-only tools; business writes remain behind explicit confirmation and owner checks.
This PR also adds evidence-based acceptance runners and cumulative model-budget accounting. Implementation and regression checks are complete for the fixes described below; formal end-to-end acceptance remains in progress.
Changes
404 source_not_owned, reject malformed session cookies as authentication errors, bound SQLite event cursors, and keep transient authorization failures recoverable.Validation
Current head:
d33f7f81d47bcb3bf3c1915ec007d3a8eab794f8Branch:
agent/first-delivery→mainThe focused checks above do not replace formal acceptance. Earlier failed and incomplete model runs remain retained as evidence.
Remaining acceptance
Fresh source analysis and three citation judgments passed. The first new development run is INCOMPLETE after a network/read failure; further model-based acceptance is paused pending reconciliation. No complete second development pass or downstream formal acceptance is claimed.
A real Qdrant / pinned BGE comparison on the 20 synthetic development cases completed with zero model calls. This is development-only retrieval evidence; the unseen holdout remains unread. It does not complete U02 or downstream acceptance.
Delivery boundaries
This PR remains Draft. CI success and focused validation do not imply formal acceptance or authorization to merge, release, or deploy. Credentials, private accounting records, raw internal logs, and unseen holdout contents are excluded from the public repository.