Commit Graph

12110 Commits

Author SHA1 Message Date
Jordan Ritter df1b2d572d fix(showcase/spring-ai): consolidate content-red fixes — manifest NSF reasoning canon, Jackson @Primary mapper + RunErrorEvent wire-shape, error-banner pattern, Java tool JSON hardening, .ag-ui-sha pin + CI workflow 2026-06-12 07:59:35 -07:00
Jordan Ritter 9984c82c66 fix(showcase): D6 reds remediation on built-in-agent — testid backfill + PARITY_NOTES + aimock fixtures + STATE_DELTA wiring (#5413)
## Scope

Built-in-agent integration D6 readiness pass — companion to PR #5407
(merged) which fixed the claude-sdk-python integration. This PR follows
the same PARITY_NOTES pattern.

### What changed

- **~28 testids backfilled across 13 demos**: declarative-gen-ui
renderers, headless-complete (assistant-bubble, user-bubble,
weather-card, highlight-note, input-bar), headless-simple, gen-ui-agent,
a2ui-fixed-schema (definitions + renderers), auth (new `sign-in-card`
component), chat-slots welcome, gen-ui-interrupt cancel.
- **New components**: shared `not-supported-banner` for NSF demos (hitl,
shared-state-streaming); subagents extraction into LGP-mirror components
(`subagent-activity-card`, `delegation-log`,
`supervisor-activity-banner`).
- **2 aimock fixtures**: `gen-ui-a2ui-fixed.json` (new — routes
`display_flight` pill through the Card mount); `gen-ui-declarative.json`
(reshaped to BIA's two-call sequence + flat catalog shape).
- **1 backend wire-up**: `set_steps` tool registered in `state-tools`
and wired through `tanstack-factory` so `gen-ui-agent` emits
`STATE_DELTA` events on its agent-plan stream.
- **PARITY_NOTES.md**: tracks BIA-vs-LGP feature parity + a Known Issues
section.
- **feature-registry.json**: adds `threadid-frontend-tool-roundtrip`
feature entry.

## D6 verify status

- **3 GREEN**: auth, chat-slots, subagents.
- **1 expected-NSF**: gen-ui-interrupt (cancel testid verified).
- **3 still RED with documented downstream root causes** (all require
fixes in `packages/react-core`, outside this PR's scope — see
`PARITY_NOTES.md` "Known Issues"):
  - a2ui-fixed-schema: renderer host doesn't mount Card.
- gen-ui-agent: STATE_DELTA stream emits, but `useAgent`
state-subscription gap prevents the React side from observing the delta.
  - declarative-gen-ui: same renderer-host class as a2ui-fixed-schema.
- **2 additional reds are pre-existing harness issues NOT introduced
here**: headless-complete aimock fixture, headless-simple chip-text
drift.

Verify reports: `/tmp/cr/verify-5425/d6-direct-v2-REPORT.md`.

## Builds on

PR #5407's PARITY_NOTES pattern for documenting integration-vs-LGP gaps
with downstream-tracked known issues.
2026-06-12 07:57:13 -07:00
Ran Shemtov 3788748e32 chore: release monorepo v1.60.1 (#5415) v1.60.1 2026-06-12 15:30:00 +02:00
ranst91 02c3a8aef0 chore: release monorepo v1.60.1 2026-06-12 13:03:45 +00:00
Ran Shemtov 8fb13fd602 fix: update cpk to use latest agui core packages (#5408)
## Summary

- Bumps `@ag-ui/client`, `@ag-ui/core`, and `@ag-ui/encoder` to `0.0.57`
across all packages under `packages/`
- Updates `pnpm-lock.yaml` to reflect the new versions

## Test plan

- [ ] Verify packages build successfully
- [ ] Confirm no runtime regressions in ag-ui communication
2026-06-12 14:52:10 +02:00
Ran Shemtov 246b907ed8 Merge branch 'main' into claude/stupefied-fermi-0c3310 2026-06-12 14:23:17 +02:00
Jordan Ritter 1427475a7e fix(showcase): bump generate-catalog test counts for threadid-frontend-tool-roundtrip feature add 2026-06-12 05:12:24 -07:00
Ran Shem Tov 10a4c38b46 fix(showcase-tests): skip generator in integration-smoke-registry when registry.json exists
Prevents a file-parallelism race where this suite's beforeAll generator
call atomically renamed catalog.json while generate-registry.test.ts was
mid-sentinel-test, clobbering the appended sentinel.
2026-06-12 14:06:53 +02:00
Jordan Ritter 02fcf43d6d docs(showcase): built-in-agent PARITY_NOTES + feature-registry threadid-frontend-tool-roundtrip + known issues
Documentation companion to the BIA D6 readiness work:

- PARITY_NOTES.md: tracks built-in-agent feature parity vs LGP +
  a 'Known Issues' section documenting 3 D6 demos that remain red
  due to downstream renderer/state gaps in @copilotkit/react-core
  (a2ui renderer host doesn't mount Card; STATE_DELTA → useAgent
  state-subscription gap; declarative-gen-ui renderer host shares
  the same class). All three require fixes outside this PR's scope.
- feature-registry.json: adds threadid-frontend-tool-roundtrip
  feature entry covering the new gen-ui-agent STATE_DELTA wiring.
2026-06-12 05:02:39 -07:00
Jordan Ritter 9abe8a183f fix(showcase/built-in-agent): wire set_steps tool for gen-ui-agent STATE_DELTA stream
Adds the set_steps tool definition to state-tools and wires it through
the tanstack factory so the gen-ui-agent demo emits STATE_DELTA events
on its agent-plan stream the same way the LGP integration does.
2026-06-12 05:02:32 -07:00
Jordan Ritter c49da076dd fix(showcase/aimock): add gen-ui-a2ui-fixed + reshape gen-ui-declarative fixtures for built-in-agent D6
Two aimock fixture updates to unblock built-in-agent D6 verification:

- gen-ui-a2ui-fixed.json: new fixture so display_flight pill routes
  the Card mount through the a2ui-fixed-schema renderer host
- gen-ui-declarative.json: reshaped to the built-in-agent two-call
  sequence with the flat catalog shape the BIA route emits
2026-06-12 05:02:26 -07:00
Jordan Ritter 99aafd0283 feat(showcase/built-in-agent): extract subagents DelegationCard into LGP-mirror components
Extracts the inline subagents page DelegationCard into three reusable
components that mirror the LGP integration layout, enabling D6 testid
coverage:

- subagent-activity-card.tsx: per-subagent activity panel
- delegation-log.tsx: cumulative delegation event log
- supervisor-activity-banner.tsx: supervisor-level status banner

The subagents page now composes these components instead of inlining
the markup, with data-testid hooks for D6 selectors.
2026-06-12 05:02:20 -07:00
Jordan Ritter b6750b7423 fix(showcase/built-in-agent): D6 testid backfill across 13 demos
Backfills data-testid attributes to enable D6 cross-integration test
coverage for the built-in-agent integration. Covers:

- declarative-gen-ui renderers (5 testids)
- headless-complete demo components (6 testids: assistant-bubble,
  user-bubble, weather-card, highlight-note, input-bar)
- headless-simple page (3 testids)
- gen-ui-agent page (3 testids including agent-step)
- a2ui-fixed-schema definitions + renderers (chat-slots, auth flow)
- new sign-in-card component for auth demo
- gen-ui-interrupt cancel testid on time-picker-card
- shared not-supported-banner component for hitl +
  shared-state-streaming NSF demos
2026-06-12 05:02:13 -07:00
Jordan Ritter 089f8ac243 fix(showcase): D6 reds remediation — manifest NSF + hygiene (14 integrations) + claude-sdk-python testid/hook fixes (+16 component testids) (#5407)
## Summary

D6 reds remediation across the staging dashboard. Consolidates
manifest-level NSF/hygiene fixes for 13 integrations with two targeted
claude-sdk-python fixes that surfaced during the per-integration audit.

### What's in scope

**Manifest cleanup** (12-14 integrations touched):
- Added `not_supported_features` entries for `reasoning-default-render`,
`agentic-chat-reasoning`, `tool-rendering-reasoning-chain`, and
`interrupt-headless` per backend capability (e.g. ms-agent-dotnet gets
only `interrupt-headless` since its `ReasoningAgent.cs` natively emits
REASONING_MESSAGE_*; langgraph-fastapi natively supports both → no
additions).
- Deduped `shared-state-streaming` and related entries that previously
appeared in BOTH `features:` AND `not_supported_features:`.
- Added `shared-state-read` and `threadid-frontend-tool-roundtrip` to
`features:` where the demo exists but wasn't declared. **Note**:
`threadid-frontend-tool-roundtrip` was REVERTED — feature isn't
registered in `showcase/shared/feature-registry.json`; the registry
needs the canonical entry before manifests can declare it. Tracked as
follow-up.

**claude-sdk-python**:
- `hitl/page.tsx`: replaced `useLangGraphInterrupt` (from
`@copilotkit/react-core`) with `useInterrupt` (from
`@copilotkit/react-core/v2`) — wrong-framework import on a non-LG
backend.
- `gen-ui-interrupt`: added `data-testid="time-picker-cancel"` to the
cancel button.

### Out of scope (deferred / handled elsewhere)

- **ag2 + spring-ai manifests**: owned by parallel session
`fix/content-reds` — those changes land via that PR.
- **11 of 12 audit-flagged claude-sdk-python testid gaps**: investigated
and refused — they're missing FEATURES (custom-catchall renderers,
sign-in cards, headless composer, etc.), not missing testid attributes
on existing JSX. Adding them would be a behavior change requiring
backend-capability audit per demo. Separate follow-up if the team wants
the structural gaps closed.
- **built-in-agent 17-item testid backfill**: per D analysis, the
single-`"default"`-agent pattern is INTENTIONAL architecture (documented
in README + earliest port commit + uniform across 12+ routes); per-demo
dimension comes from `src/lib/factory/*` keyed off route URL. Track 1
(PARITY_NOTES.md doc) + Track 2 (testid-only backfill, separate PR)
tracked as follow-ups.

### Validation

- `npm run validate-manifests` passes; all 15 affected manifests parse
valid YAML.
- claude-sdk-python typecheck: no new errors (pre-existing
module-resolution noise unchanged).
- No vitest tests exist for the touched claude-sdk-python demos.
- `npx oxfmt --write` on changed files.

### Provenance

Driven by a per-integration parity audit (LGP canon, 17 red
integrations, 11-slot CR fan-out, 39-demo canon enumerated; reports
archived to /tmp/cr/audit/ during the investigation). Coordinated with
parallel `fix/content-reds` session via the `coordinate` skill to avoid
file-overlap with their ag2 + spring-ai manifest work and other deeper
changes.

Closes #5406 (claude-sdk-python testid/hook fixes — folded into this
PR).

## Additional fixes (folded in after re-audit)

Re-audit of the original claude-sdk-python audit revealed 16 ADD-EMITTER
fixes the prior agent missed. All components existed; only `data-testid`
attributes were absent.

| demo | testids | commit |
|---|---|---|
| auth | 1 (`auth-demo-error-message`) | 1238046fc |
| headless-simple | 3 (composer + 2 message bubbles) | 5793a3652 |
| a2ui-fixed-schema | 1 (`a2ui-fixed-card` via Card renderer override +
matching definitions entry, mirroring LGP) | 4436f3afa |
| headless-complete | 6 (composer + 2 bubbles + stock/weather/highlight
cards) | 083eb09a7 |
| declarative-gen-ui | 5 (card + status-badge + metric + pie-chart +
bar-chart) | 6187040b5 |

Not added (genuinely missing components, deferred):
- `auth-sign-in-card`, `auth-sign-out-button`, `auth-profile-card`
- `headless-revenue-chart`
- tool-rendering testids (15 components), chat-slots (2), etc.
2026-06-12 03:33:08 -07:00
Jordan Ritter dad8ff0a71 chore(showcase/claude-sdk-python): document LGP parity for headless-message testids
Adds inline comments next to the data-testid="headless-message-{user,assistant}"
markers in assistant-bubble.tsx, user-bubble.tsx, and headless-simple/page.tsx
explaining that the testids intentionally repeat once per message — mirroring
the canonical LGP implementation — and that role discrimination for the D6
conversation-runner is via data-message-role, not unique testids.
2026-06-12 03:25:32 -07:00
Jordan Ritter f9bb881555 fix(showcase/claude-sdk-python): D6 probe alignment — testid backfill + demo bugfixes + V2 import for gen-ui-interrupt
Backfills the data-testid markers the D6 probes assert against across the
auth, headless-simple, headless-complete, a2ui-fixed-schema,
declarative-gen-ui, and gen-ui-interrupt demos; aligns the python
a2ui_fixed agent + a2ui definitions/renderers with the canonical LGP
shapes; and switches the gen-ui-interrupt CopilotKit provider import to
@copilotkit/react-core/v2 so the demo mounts under the V2 runtime that
the D6 probe drives.
2026-06-12 03:25:18 -07:00
Jordan Ritter 28055f0688 feat(showcase/claude-sdk-python): add headless-revenue-chart for D6 probe
Adds the chart-card renderer and wires it into the headless-complete
tool-renderers map so the D6 probe for the headless-revenue-chart feature
can mount and assert against a real chart component.
2026-06-12 03:24:43 -07:00
Jordan Ritter 2df48c8581 fix(showcase/aimock): a2ui-fixed + declarative fixtures for claude-sdk-python D6 probes
Adds the missing gen-ui-a2ui-fixed aimock fixture and reshapes the
declarative-gen-ui fixture so the claude-sdk-python D6 probes have
deterministic LLM replay for both gen-ui demos.
2026-06-12 03:24:38 -07:00
Jordan Ritter 8f72c2840a fix(showcase/claude-sdk-python): hitl demo bugfixes — useInterrupt hook + V2 CopilotKit import
Replaces useLangGraphInterrupt with useInterrupt (LangGraph-specific hook
not exported from the V2 React core) and switches the CopilotKit provider
import to @copilotkit/react-core/v2 so the demo mounts under the V2
runtime that the D6 probe drives.
2026-06-12 03:24:22 -07:00
Jordan Ritter 928ece2f6c fix(showcase): add D6 NSF entries + feature alignment across 14 integration manifests
Annotates 14 integration manifests with d6_not_supported_features entries
and aligns d6_supported_features with what each backend actually implements,
so the D6 fleet probe only enumerates demos that the backend can serve.
2026-06-12 03:24:16 -07:00
Ran Shem Tov da5b50a929 fix(bot-slack): adapt runHttpRequest call to ag-ui 0.0.57 signature 2026-06-12 11:58:12 +02:00
Ran Shem Tov 7805a9a57b fix: update cpk to use latest agui core packages 2026-06-12 11:16:19 +02:00
Jordan Ritter 1e9d77ec50 feat(showcase): end-to-end run-visibility for fleet — /api/runs + family-silence Slack alerting (#5400)
## Summary

Adds end-to-end **run-visibility** to the showcase fleet — a new data
path from queue enqueue → per-family projection → dashboard + Slack
alerting:

- **Contracts + PB schema**: `EnqueueJobInput.family`,
`FleetQueueClient.pruneAged`, run-id/family/worker-id columns on
`probe_jobs` / `resource_snapshots`, fleet-claim hook stamps at claim
time.
- **Queue + aggregator**: queue-client stamps run-id/family on enqueue;
d6 producer owns `pruneAged` retention; aggregator computes
`redsIntroduced`/`redsCleared` into `probe_runs`.
- **Run-view projection (`run-view.ts`)**: §5.1 `FLEET_FAMILIES`
registry + §5.2.1 family-summary projection.
`createMemoizedFamilySummary` bounds PB load at ~one fan-out per TTL
regardless of viewer count.
- **Producer wiring**: `PRODUCER_FAMILY_WIRING` drift-locks the four
producers' family ids set-equal to the registry (unit-tested);
CLI-triggered runs route through `familyForLevel` so a registry rename
breaks loudly.
- **Family-silence monitor (§9)**: Slack alerting for the one incident
class transition-keyed rules are blind to (a silent family produces no
row transitions). Rides the existing fleet-health interval (no extra
timer), per-family 6h rate-limit + recovered one-shot + boot-grace,
fails open on PB-down for the meta-alert. Closed-vocabulary redaction.
- **HTTP `/api/runs`** + **`/health.fleetRuns.lastEvaluatedAt`**:
read-only fleet-runs routes mounted unconditionally on the CP role,
backed by the SAME memoized summary the monitor uses. `/health` stamp is
the §9 compensating control so an external poll can detect a wedged
monitor.
- **Orchestrator wiring**: boot-resolved `workerStaleAfterMs` threaded
through both fleet-health and the projection so they judge staleness
against the same window; test queues across the harness gain a no-op
`pruneAged`.
- **Dashboard**: worker-runs Ops section (family table, worker strip,
run-history drill-down), D0-from-staleness vs D0-from-failure family
annotation, per-family silence banner on the coverage tab; data layer
(DTOs, fetchers, polling hook, context provider).
- **Integration test**: 689-line end-to-end test exercising the full
queue lifecycle → /api/runs projection across all four families.

This is the merged scope of the **runviz blitz** lanes T1-T15.

## Test plan

- [x] `pnpm typecheck` on `showcase/harness` and
`showcase/shell-dashboard` — clean
- [x] `vitest run` on full harness suite — 2276 pass / 3 pre-existing
probe-pool timing flakes (NOT in diff; subject is "probe-pool timing
fragility", a different PR's concern)
- [x] `oxfmt --check showcase/` — all green
- [x] Integration test `run-visibility.integration.test.ts` passes —
exercises queue → projection across all four families
- [ ] CI on PR HEAD — pending push, monitored after open

## Known follow-up (bucket-d)

- Probe-pool timing-sensitive flakes in
`src/probes/helpers/browser-pool.test.ts` (FIX#4a self-heal) and
`src/probes/loader/probe-invoker.test.ts` (timeout assertions) —
different test fails on each run; subject is probe-pool timing
fragility, not runviz.

## Deviation note

The runviz ship-finisher session ran in a Claude Agent SDK harness
without an Agent dispatch tool, so the standard 7-agent CR-loop could
not be dispatched. Inline review was performed against the cr-loop
subject-manifest + four-bucket partition: T1-T15 each landed via their
own per-task review on the blitz integration branch before reaching this
PR, and T8/T15 (the two final-merged streams) were validated via
typecheck-clean + targeted-tests-pass + cross-module wiring inspection.
A heavyweight 7-agent CR can be run against this PR if desired.
2026-06-11 21:49:06 -07:00
Jordan Ritter f6edd48ca8 fix(harness): post-rebase test/syntax fixes for queue-client and fleet tests
- queue-client.ts: add missing closing brace at EOF (TS1005 after rebase)
- job-producer.test.ts: add required `family: "d6"` to producer fixtures
  and remove duplicate `logger` key in startedProducer
- result-aggregator.test.ts: align with per-row try/catch + dedup-lookup
  behavior introduced in 0b2f613e0 — add `persisted: true` and
  `writeOverlay` to test writers, update B6 contract expectations
- queue-client.test.ts: drop a stray blank line
2026-06-11 21:48:18 -07:00
Jordan Ritter 06f6f2cd6d fix(dashboard): worker-run-detail-panel abort fetches on cleanup + move side-effects out of setState updater 2026-06-11 21:16:38 -07:00
Jordan Ritter 91f4fd9f55 fix(harness): job-producer.pruneAged uses depth registry constant, not hardcoded literal 2026-06-11 21:16:37 -07:00
Jordan Ritter 0b2f613e00 fix(harness): aggregator per-row try/catch + dedup lookup throw + worker-health helper parity 2026-06-11 21:16:00 -07:00
Jordan Ritter 3c03377935 fix(harness): escape PB filter args in control-plane-run + run-history 2026-06-11 21:13:36 -07:00
github-actions[bot] 3aae755694 style: auto-fix formatting 2026-06-11 21:13:36 -07:00
Jordan Ritter 5c62a1f1d7 test(showcase): run-visibility integration + deploy-script regression covers
Adds a 689-line integration test that exercises the full queue lifecycle
to the /api/runs projection (enqueue → claim → terminal → projection)
across all four families. Updates the railway-envs golden + verify-deploy
drivers regression test to account for the new fleet-runs route surface.
2026-06-11 21:13:35 -07:00
Jordan Ritter 1223bb9fc1 feat(showcase): dashboard worker-runs UI + data layer
Adds the dashboard Ops worker-runs section — family table, worker strip,
run-history drill-down, D0-from-staleness vs D0-from-failure family
annotation with clock glyph, and the per-family silence banner on the
coverage tab. Wires the data layer: DTOs, /api/runs fetchers, polling
hook, and a worker-runs context provider. cell-drilldown / cell-pieces
gain family-aware rendering.
2026-06-11 21:13:34 -07:00
Jordan Ritter cb0e774e8a feat(showcase): orchestrator wires producers + monitor + /api/runs onto runControlPlane
PRODUCER_FAMILY_WIRING (drift-locked set-equal to FLEET_FAMILIES via a unit
test) drives every buildJobProducer call site; the boot-resolved
worker-stale-after window is threaded through BOTH fleet-health and the
shared family-summary projection so they judge staleness against the same
window. Triggered CLI control-plane runs route through familyForLevel so a
registry rename breaks loudly instead of silently enqueueing jobs invisible
to the projection. Test queues across the harness gain a no-op pruneAged
for the new contract.
2026-06-11 21:13:09 -07:00
Jordan Ritter 53641d0a2d feat(showcase): /api/runs fleet-runs HTTP routes + /health fleetRuns stamp
Read-only /api/runs routes mounted on the control-plane role, backed by
the SHARED memoized family-summary instance (one PB fan-out per TTL).
Bounds: per-route memo, request rate-limit. /health gains the
fleetRuns.lastEvaluatedAt stamp from the family-silence monitor as the
§9 compensating control for a wedged monitor (an external poll detects
the wedge — the monitor cannot report its own host's death).
2026-06-11 21:10:29 -07:00
Jordan Ritter e3ecf8e3db feat(showcase): producer family-stamping + family-silence Slack monitor
job-producer takes a family option and stamps it on every enqueue; the
prune-ownership key is the d6 producer's family. family-silence-monitor
rides the existing fleet-health interval (no extra timer to tear down),
keys 6 h rate-limit + recovered one-shot per family, fails open on
PB-down (the meta-alert path must still fire), and renders alert text
from closed-vocabulary parts only (§5.2.1 redaction). control-plane
fire-and-forgets familySilence.tick(now) each fleet-health cycle.
2026-06-11 21:10:28 -07:00
Jordan Ritter 5ea1e37277 feat(showcase): run-view family registry + memoized family-summary projection
The §5.1 FLEET_FAMILIES registry and the §5.2.1 family-summary projection
that derives per-family outcome / inflight / lastRun / lastSuccessAt from
the PB-backed batches. The memoized variant fan-outs PB reads at most once
per TTL regardless of viewer count — the SAME instance is shared by the
/api/runs routes and the family-silence monitor so a dashboard poll and a
monitor evaluation inside the same TTL cost one PB fan-out total.
2026-06-11 21:08:57 -07:00
Jordan Ritter 9dad6890ca feat(showcase): queue-client + aggregator wire run-id/family + reds projection
queue-client stamps run_id/family onto every enqueue so downstream
projections can attribute jobs to a family-scoped batch; pruneAged
retention legs land here (the d6 producer owns the call, per §4.2).
result-aggregator computes redsIntroduced/redsCleared from claimed/
sequenced job state into probe_runs summary.
2026-06-11 21:08:56 -07:00
Jordan Ritter 6e90e7bb38 feat(showcase): fleet contracts + PB run-metadata schema for run-visibility
Adds run-id/family/worker-id columns to probe_jobs and resource_snapshots,
plus the EnqueueJobInput.family + FleetQueueClient.pruneAged contracts and
the hoisted deriveHealth primitive that downstream projections share. The
fleet-claim PB hook stamps run-id/family at claim time so every later
projection has a stable join key. probes/run-history is updated to read
the new columns.
2026-06-11 21:04:59 -07:00
Jordan Ritter f0a39c8bd7 fix(cf+dashboard): fleet claim-fairness, supplemental-merge freshness, dashboard drilldown D4 parity (#5399)
## Summary

Bundles two related dashboard/harness lanes that landed together once
both reached green:

1. **CF #18 fairness / claim-fair lane** — the 23-commit base
(`fix/fleet-claim-fairness` rebased onto its CF7 integration tip
`80c5c9402`) carrying claim-spike, cf3/cf4/cf5/cf6/cf7 hardening waves,
plus the **CF8 micro-fix** for the round-8 supplemental-merge finding:

- **CF8 F3 supplemental-merge freshness guard** (`useLiveStatus.ts`):
the cold-load comm-error supplemental fetch runs CONCURRENTLY with the
bulk pages, so the bulk copy of an aggregate row can be NEWER than the
supplemental snapshot. The previous merge replaced the bulk row
unconditionally, regressing `state`/`observed_at` to stale values until
the row's next SSE delta (long for slow-cadence aggregates). Added
`supplementalRowIsOlder` — when the supplemental row is strictly older
the newer bulk row stays INTACT (signal-less) rather than being grafted
into a chimera (newer core + stale signal) that the reducer's
signal-PRESENCE no-op check would silently swallow.

- **Procedure 3 promotions** (bucket-c/d audit over the CF round-8
ledger): one functional fix (escape `workerId` in fleet-health's reclaim
list filter — matches the `JSON.stringify` pattern used at
orchestrator.ts:3240 for the same field; a `"`-bearing worker_id would
otherwise break out of the literal) plus five doc reconciliations on the
producer/contract surfaces flagged across slot1/slot2/slot4/slot5 (stale
queue-client cross-reference, WarmHealthConfig doc vs `gate.specs`
reality, TickResult.reclaimedIndeterminate "Of reclaimed" → "In addition
to reclaimed", TickResult.skippedForBacklog poisoned-count contributor,
SweepResult.commErrors equation scoping).

2. **Dashboard drilldown D4 parity** — three commits making the
dashboard drilldown surface the D4 rung the same way the grid does:

- `feat(showcase): add resolveD4Row + CellState.d4 so the drilldown can
see the D4 rung` — exposes the D4 row on `CellState`, modeled after
`resolveD3Row`.
- `fix(showcase): drilldown shows the D4 row, de-crosses the e2e label,
and scopes the rollup line honestly` — renders D4 in the drilldown
panel, fixes the crossed e2e label, scopes the rollup line to its real
source set.
- `fix(showcase): unify dimension naming on the legend taxonomy across
grid, legacy cells, and legend` — taxonomy cleanup so legend, grid, and
legacy cells use one set of labels.

## Verification

- Dashboard `npx tsc --noEmit`: clean (only the pre-existing
missing-`@/data/*.json` errors that exist on `main`).
- Dashboard `vitest run`: 59 files / 1012 tests passing, 1 skipped.
- Harness `npx tsc --noEmit`: clean.
- Harness `vitest run`: 121/122 files passing; 1 failed = `probe-invoker
times out invoker-level even when driver ignores abortSignal` — the
NAMED known wall-clock flake (per CF7 integration verification), re-run
in isolation: 67/67 PASS.
- Rebase of drilldown-parity onto the updated `fix/cf8-m1` tip: ZERO
conflicts (the two lanes touch disjoint files).

## Test plan

- [ ] CI green on the PR
- [ ] Dashboard drilldown shows D4 rung in addition to D3/D5/D6
- [ ] Legend taxonomy reads the same in legend, grid, drilldown
- [ ] (post-merge, in showcase) cold-load comm-error overlay still
paints; a stale supplemental no longer regresses a freshly-failed
aggregate row
2026-06-11 21:00:29 -07:00
Jordan Ritter b074a47c98 test(harness): update SMOKE sweep test mock to writeOverlay API after rebase 2026-06-11 20:59:45 -07:00
Jordan Ritter 230ec3efcc fix(harness): import PoolCommError type after rebase merge 2026-06-11 20:44:24 -07:00
Jordan Ritter 174ae5e534 test(harness): tolerate oxfmt line-wrap in routerAdd auth-middleware pin
The auth-middleware-presence regex in queue-client.test.ts hook-parity
suite was anchored to the single-line `}, $apis.requireAdminAuth());`
closer. After oxfmt rewrote fleet-claim.pb.js to its multi-line form
(`},\n  $apis.requireAdminAuth(),\n);`) the regex stopped matching
and the test asserted 0 routes were guarded — a false alarm.

Broaden the regex to accept both the single-line closer and the
formatter's split form; the structural intent (each routerAdd
handler-end is followed by the requireAdminAuth middleware) is
unchanged.
2026-06-11 20:42:50 -07:00
Jordan Ritter 1a87c279a7 fix(harness): fleet-claim handlers preserve {ok:false} shape on transaction throw 2026-06-11 20:42:50 -07:00
github-actions[bot] a97bf39ccb style: auto-fix formatting 2026-06-11 20:42:49 -07:00
Jordan Ritter 9554abf78f fix(showcase): unify dimension naming on the legend taxonomy across grid, legacy cells, and legend
Grid d3 badge API->E2E, legacy e2e badge RT->E2E, legend D6 "Parity
(PR)"->"Parity (Reference)", legend D4 chip copy 6h->1h (real window);
d4 grid "RT" and d2 "API" unchanged.
2026-06-11 20:42:49 -07:00
Jordan Ritter 553b64495a fix(showcase): drilldown shows the D4 row, de-crosses the e2e label, and scopes the rollup line honestly
D4 row inserted with worst-state strictness; e2e relabeled "E2E (Demo)"
atomically (label-derived testids); rollup line relabeled "Service
(health + e2e)"; headline regression pins pill-red <-> visible red popup
row via buildCellModel.chipColor cross-assert; green-badge tests
FRESH-pinned.
2026-06-11 20:42:48 -07:00
Jordan Ritter f5c40c0c4b feat(showcase): add resolveD4Row + CellState.d4 so the drilldown can see the D4 rung
Mirrors cell-model resolveD4 fold semantics (worst-state-wins, 1h stale
window, rank-based missing-chat collapse, chat-wins tie-break pinned by
row-identity assertions); d4 is informational — rollup contributors
unchanged.
2026-06-11 20:42:48 -07:00
Jordan Ritter e5b534750e fix(harness): escape claimed_by literal in fleet-health reclaim, plus tick-result doc reconciliations (Procedure 3 promotions)
PROMOTE_TO_A (defense-in-depth, exploit-class):
- fleet-health.ts reclaim list interpolated workerId raw into the PB filter
  literal. workerId is DB-sourced (read back from the workers roster row),
  not a compile-time constant, and the same field is escaped via JSON.stringify
  at orchestrator.ts:3240 — but the reclaim path was missing the same
  hardening. A double-quote in worker_id (corrupt row, buggy self-registration)
  would either throw the list (silently skipping this worker's reclaim every
  cycle) or widen the filter to claim other workers' jobs. Match the sibling
  escape pattern.

PROMOTE_TO_B (doc reconciliations exposed by the CF round-8 audit):
- queue-client.ts COUNT-NAME CAVEAT was stale — the cross-referenced
  contracts.ts doc was already updated (commit 80c5c940) but the queue-client
  side still asked a future maintainer to make the edit that had already
  landed.
- WarmHealthConfig + JobProducerOptions.warmHealth docs said the producer
  warms 'every enumerated backend' / 'each enumerated spec'; the implementation
  warms gate.specs (post-validation, post-backlog-gate). A fully-backlogged
  tick warms nothing. Updated both interface-level docs to match.
- TickResult.reclaimedIndeterminate said 'Of reclaimed, the reclaims...' —
  but the field is DISJOINT from reclaimed (sibling SweepResult contract +
  the queue-client both state a thrown release lands here exclusively).
  Rewrote to 'In addition to reclaimed, ...'.
- TickResult.skippedForBacklog doc named only the dedupe-gate contributor;
  the in-function comment correctly documents the fail-CLOSED poisoned-count
  fold-in. Expanded the field doc to name both contributors, and to clarify
  that the fail-OPEN leg lands in backlogGateFailedOpen separately.
- SweepResult.commErrors pairing equation
  (commErrors.length === reclaimed + reclaimedIndeterminate) was asserted
  unconditionally on the shared contract, but reclaimedIndeterminate is
  optional and fakes may not report the split. Scoped to 'implementations
  that report the split'.
2026-06-11 20:42:47 -07:00
Jordan Ritter b1fa1e7563 fix(dashboard): supplemental-merge keeps newer bulk row intact, never grafts older signal (CF8 F3)
The cold-load comm-error supplemental fetch runs CONCURRENTLY with the bulk
pages, so the bulk copy of an aggregate row can be NEWER than the supplemental
snapshot (the row's state changed between the two reads). The previous merge
replaced the bulk row unconditionally — regressing state/observed_at and
potentially fail_count back to the older supplemental values until the row's
next SSE delta (long for slow-cadence aggregates).

Add a freshness guard: when the supplemental row is strictly older (by
observed_at), keep the newer bulk row INTACT — signal-less rather than
chimera (newer core + stale signal). A chimera row would be silently swallowed
by the reducer's signal-PRESENCE no-op check; a signal-less bulk row lets
the next SSE delta restore the real current signal via the
undefined→defined presence flip.

Equal timestamps and unparseable timestamps both prefer the supplemental
(signal-bearing) row — only POSITIVELY-stale supplemental is suppressed,
preserving the cold-load comm-error overlay intent of CF7-F3 #1.
2026-06-11 20:42:47 -07:00
Jordan Ritter 1b4e81d5a2 docs(harness): SweepResult.expiredPending documents the lease-phase long-expired carve-out
Sibling of the queue-client prose fix (CF7 #10), which flagged this
contract doc as describing only the drain phase: despite the name, the
lease phase's long-expired carve-out also claim-deletes claimed/running
rows (stale created-age, long-expired or unparseable lease) into this
count — no re-queue, no comm error, no reclaimed increment.
2026-06-11 20:42:46 -07:00
Jordan Ritter ace295bbaf fix(dashboard): statusSignalHasCommErrorKey sibling companion lands on the live-status mirror
The harness contract gained statusSignalHasCommErrorKey (REQ-B
version-skew observability) with its dashboard sibling explicitly left
to the dashboard owner. Add the byte-identity-safe companion to
live-status.ts — placed OUTSIDE the commErrorFromStatusSignal region
pinned by commError-contract-drift.test.ts (only the decode function
source is mirrored; proven by the drift suite staying green) — so
dashboard consumers can distinguish a present-but-undecodable overlay
from a genuinely absent one. Unit-pinned: unknown future kind,
well-formed, absent, and array-expando wire shapes.
2026-06-11 20:42:46 -07:00