Skip to content

feat(agent): add gated durable learning workflows - #231

Draft
DavidHLP wants to merge 59 commits into
mainfrom
agent/first-delivery
Draft

DavidHLP wants to merge 59 commits into
mainfrom
agent/first-delivery

Conversation

@DavidHLP

@DavidHLP DavidHLP commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Summary

Adds an opt-in Agent workflow for submission analysis and learning-plan creation. Authenticated users can analyze an owned submission, review a durable draft, explicitly confirm it, and save it through the Java App service. Model execution uses read-only tools; business writes remain behind explicit confirmation and owner checks.

This PR also adds evidence-based acceptance runners and cumulative model-budget accounting. Implementation and regression checks are complete for the fixes described below; formal end-to-end acceptance remains in progress.

Changes

  • Introduce a checkpointed FastAPI/LangGraph workflow with private SQLite state, event replay, draft versioning, expiry, cancellation, and stale-run protection.
  • Add the App-owned learning-plan domain, including idempotent persistence and owner-bound reconciliation after an uncertain save response. Register it in both standalone App and the optional Core context.
  • Validate submission facts, complete status values, citations, and refusals when source information is unavailable. Forward the requested timeout to the graph.
  • Preserve ownership failures as 404 source_not_owned, reject malformed session cookies as authentication errors, bound SQLite event cursors, and keep transient authorization failures recoverable.
  • Add U02, account-isolation, U03, and U04 acceptance tooling with explicit evidence and budget bindings. Fresh revalidation preserves historical attempts and unresolved liabilities rather than resetting accounting or manufacturing missing historical evidence.
  • Correct evaluation prompts to explain retrieved topics without unnecessary refusal and declare the existing 1,000-character answer limit.
  • Align supported commands and contracts in the canonical documentation, address CI security findings, and correct the Nacos heap configuration.

Validation

Current head: d33f7f81d47bcb3bf3c1915ec007d3a8eab794f8
Branch: agent/first-delivery → main

  • Current-head GitHub Actions: success — 23 jobs passed, 1 conditional skip. This head fixes the concurrent SQLite WAL initialization race found in the preceding run.
  • Remote full Agent suite on the current head: 1,421 passed. Current-head budget regressions: 10 passed. GitHub's Agent job also succeeded.
  • Focused answer, evaluation, and revalidation regressions: 75 passed.
  • Real Auth/App/SQLite boundary checks through the production Agent ASGI application: 8 passed, covering ownership, foreign-thread access, malformed cookies, cursor overflow, and rejection without a valid model-budget gate.
  • Two real-model cases that previously exposed topic over-refusal and an oversized response were rerun after correction: 2/2 behavior matches, supported citations, and completed answers.
  • Real two-account HTTP ownership, list, and public-search checks passed. The run explicitly skipped model attacks and remains INCOMPLETE as a full account-isolation result.
  • All eight inline review comments were addressed and received individual replies.

The focused checks above do not replace formal acceptance. Earlier failed and incomplete model runs remain retained as evidence.

Remaining acceptance

  • Complete fresh U02 evidence, including two full development passes on the corrected candidate and the required source, citation, and retrieval checks.
  • Complete model-based account-isolation attacks.
  • Complete U03 cross-service save, response-loss, and restart-recovery scenarios.
  • Complete U04 freezing, the independent unseen holdout, reliability checks, and the complete demonstration.

Fresh source analysis and three citation judgments passed. The first new development run is INCOMPLETE after a network/read failure; further model-based acceptance is paused pending reconciliation. No complete second development pass or downstream formal acceptance is claimed.

A real Qdrant / pinned BGE comparison on the 20 synthetic development cases completed with zero model calls. This is development-only retrieval evidence; the unseen holdout remains unread. It does not complete U02 or downstream acceptance.

Delivery boundaries

This PR remains Draft. CI success and focused validation do not imply formal acceptance or authorization to merge, release, or deploy. Credentials, private accounting records, raw internal logs, and unseen holdout contents are excluded from the public repository.

HEAD archive owner-preflight and fake-SQL contracts passed offline.

Live validation is not included.
Checkpoint only: explicit prepared/active/halted metadata and pinned
policy/config/period identity, with UNKNOWN historical usage.
Runtime accounting is not connected; actual spending limits are not
enforced by this lifecycle layer. No reserve/settle, provider, runner,
DAV-53 or U03 integration is included. Live acceptance remains pending.

Verified in the f466d9c HEAD archive: independent import and 48 focused
temporary-path tests pass; scope/secret scans and diff checks pass.
Checkpoint only: runtime binding candidate has a known SQLite descriptor lifetime blocker. Focused proof: 79 passed, 2 failed; original 57 regression tests pass. No runner/provider wiring, live initialization or activation; live acceptance remains open. Preserve UNKNOWN history and original worktree WIP.
Checkpoint: avoid auxiliary ledger descriptors while SQLite connections are open; verify bound inode identity with stat and use SQLite FULL synchronization. Preserve canonical configuration and shared atomic period accounting. Focused temporary-environment regression proof passed; no runner/provider wiring or live initialization, activation or acceptance. Historical spend remains UNKNOWN.
Checkpoint: bind only the standalone DAV58 runner to an explicitly selected existing active canonical period. Preserve legacy no-argument authorization callers, shared purpose accounting and historical UNKNOWN spend. Focused temporary SQLite and MockTransport verification passed; no real key, provider request, period preparation or activation. Provider effectiveness flags remain false and live acceptance remains open.
@DavidHLP
DavidHLP changed the base branch from agent/u02-citation-fixture to main October 4, 2026 15:48
DavidHLP and others added 6 commits October 5, 2026 10:57
Resolves the two conflicted paths, keeping both sides' intent:

- services/agent/README.md: main restructured this file so the canonical
  guide (docs/DEVELOPMENT.md) owns the detailed contracts, and the block
  removed here was the only branch-only content in the file. Take main's
  structure, and keep the two new opt-in runners discoverable through a
  short pointer section rather than a second copy of the guide.
- services/agent/src/deepseek_model.py: keep this branch's shared-budget
  reservation, settlement and fail-closed accounting guard, while taking
  main's extraction of `_api_messages` and `_check_prompt_budget`.

The auto-merge also spliced `decide()` outside the conflict markers: main's
`_check_prompt_budget` made `prompt_tokens_estimate` a local, while
`reserve()` still needed it. The estimate now has a single owner,
`_prompt_tokens_estimate()`, called by both the check and `decide()`.

Verified on this merge: services/agent 1124 passed / 1 skipped (optional
qdrant_client absent); `./mvnw compile -B` BUILD SUCCESS; focused
LearningPlan gate 35 passed, including LearningPlanWriteIT's 6 real-MySQL
Testcontainers idempotency and owner-scoping tests.

Co-Authored-By: Claude Code <noreply@anthropic.com>
Keep model tools read-only and require explicit confirmation before Java\nlearning-plan writes. Persist private workflow state and reconcile unknown\nwrites through the original idempotency key.\n\nBind acceptance evidence to source, budget identity, and raw receipts.\nMissing original accounting or unauthorized purposes remain fail-closed;\noffline checks never grant spend or mark real acceptance complete.
@DavidHLP DavidHLP changed the title feat(agent): add boundary and account isolation evaluation gates feat(agent): add gated durable learning workflows Oct 6, 2026
@DavidHLP
DavidHLP removed the request for review from thana0623 October 7, 2026 14:14
@DavidHLP
DavidHLP requested a review from thana0623 October 7, 2026 14:30
@DavidHLP
DavidHLP marked this pull request as ready for review October 7, 2026 15:34
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T03:47:14.762344Z dd1e156 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1f1bf0ce04

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread services/agent/src/agent_loop.py
Comment thread services/agent/src/agent_service/app.py Outdated
Comment thread services/agent/src/agent_service/app.py
Comment thread services/app/pom.xml
Comment thread services/agent/src/agent_service/app.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4fdf766707

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread services/agent/src/agent_service/app.py Outdated
Comment thread services/agent/src/agent_service/app.py Outdated
Comment thread services/agent/src/agent_service/app.py
@DavidHLP
DavidHLP removed the request for review from thana0623 October 8, 2026 03:23
@DavidHLP
DavidHLP marked this pull request as draft October 8, 2026 06:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant