Commit Graph

4 Commits

Author SHA1 Message Date
ruvnet e332689b8c fix(release): harden hooks, statusline, security, and plugin MCP integration 2026-07-16 23:06:29 -04:00
ruv 9056720219 fix(browser): #2015 round 2 — strip bogus --kind flag, ship alpha.42
Round 1 (alpha.41) added the required --dimension flag to
`ruvector rvf create` but left the equally bogus `--kind browser-session`
in place. ruvector@0.2.25's `rvf create` accepts only:

  -d, --dimension <n>    (required)
  -m, --metric <metric>  (optional, default cosine)

Commander's required-option check fires before its unknown-option
check, so the original bug report (#2015) only surfaced the dimension
error. The fresh live regression check after publishing alpha.41
exposed the second-layer bug: `error: unknown option '--kind'`.

This round:
- Strip `--kind browser-session` from all 5 call sites (TS source,
  compiled dist via rebuild, replay-spike.sh, browser-agent.md,
  browser-record/SKILL.md). Also fixed the ADR prose example.
- Tighten the smoke (scripts/smoke-browser-rvf-create-flags.mjs):
  - Switch from rg-based content scan to an explicit PATHS_IN_SCOPE
    list (the original `--kind browser-session` anchor is gone, so
    we can no longer identify call sites by content).
  - Police BOTH invariants per line:
      * --dimension / -d is present
      * --kind is ABSENT (since ruvector@0.2.25 rejects it)
  - Skip quoted-string false positives ('rvf create failed' log lines).

Versions:
  @claude-flow/cli    3.7.0-alpha.42
  claude-flow         3.7.0-alpha.42
  ruflo               3.7.0-alpha.42
  @claude-flow/memory 3.0.0-alpha.16  (unchanged, #2019 fix already live)

Post-publish live functional check (everything green):
- ruvector rvf create --dimension 384 (no --kind): exit 0, .rvf file
  written. Reproduces what the MCP tool now invokes.
- Published CLI dist:113 carries '--dimension','384', no --kind.
- #2019 vectorBackend / graphAdapter functional test from
  alpha.41 still passes against published memory@3.0.0-alpha.16.
- verify.mjs precondition contract still holds.

Co-Authored-By: RuFlo <ruv@ruv.net>
2026-05-16 09:02:08 -04:00
ruv e4bd9bbcbe fix(verify+memory+browser): #1880, #2019, #2015 — three precondition/contract fixes + CI guards
Three small but recurring bugs ship together because they share the
same anti-pattern: a try/catch (or a missing flag) silently turned a
clear precondition failure into a vague "verification failed" /
"controller disabled" / "rvf create failed" outcome that downstream
consumers couldn't act on.

#1880 — witness verify exits 1 on source-only checkouts
  - The 12h scheduled verification has been filing a duplicate
    "HIGH — verification broken" issue every cron run since 2026-05-10
    because the runner does a source-only checkout (no @noble/ed25519
    install, no `npm run build`) and verify.mjs lumped that into the
    same exit-1 bucket as a real signature regression.
  - verify.mjs now reserves exit 2 strictly for precondition misses:
      * @noble/ed25519 not installed                → exit 2
      * every manifest entry missing AND manifest   → exit 2
        references /dist/ paths (= "dist not built")
    Real failures (signature invalid, specific marker regressed)
    keep exit 1. The scheduled runner can now distinguish
    "needs install/build" from "we broke something".
  - New CI guard: scripts/smoke-witness-verify-precondition.mjs
    drives all three shapes (missing dep, all-files-missing,
    built tree) and asserts the exit code contract.
  - Wired into v3-ci.yml as witness-verify-precondition-smoke and
    into witness-verify's `needs:` so a contract break blocks publish.

#2019 — vectorBackend controller permanently disabled
  - @claude-flow/memory's controller-registry.ts calls
    agentdb.getController('vectorBackend'). agentdb@3.0.0-alpha.14's
    getController switch only handles memory/reflexion/skills/causal
    and throws `Unknown controller: vectorBackend` for everything else
    — silently swallowed, leaving the controller `enabled: false`
    even though `agentdb.vectorBackend` is a real field on the
    instance (assigned in AgentDB.initialize()).
  - Registry now probes `agentdb[name]` directly first, falls back to
    getController only when the field is absent. Applied to all three
    accessor paths (initializeController, get, isEnabled).
  - RuntimeConfig gains an optional `agentdb` injection field so
    tests and consumers with a pre-built AgentDB can govern it via
    the registry.
  - Two new tests in controller-registry.test.ts cover both branches
    (direct property wins; falls back to getController when absent).
  - Full controller-registry suite stays green (67 tests).

#2015 — ruflo-browser session_record fails every call
  - ruvector@0.2.25 makes `-d, --dimension <n>` required on
    `rvf create`. The browser_session_record MCP tool wrapper invoked
    `rvf create … --kind browser-session` WITHOUT the flag, so every
    call returned `{ success: false, error: "rvf create failed" }`.
  - All five call sites updated to pass `--dimension 384` (matches
    MiniLM-L6 / AgentDB index default):
      v3/@claude-flow/cli/src/mcp-tools/browser-session-tools.ts
      plugins/ruflo-browser/scripts/replay-spike.sh
      plugins/ruflo-browser/agents/browser-agent.md
      plugins/ruflo-browser/skills/browser-record/SKILL.md
      plugins/ruflo-browser/docs/adrs/0001-browser-skills-architecture.md
  - New CI guard: scripts/smoke-browser-rvf-create-flags.mjs
    statically scans every `rvf create … --kind browser-session`
    invocation across the repo (TS, dist, shell, markdown) and
    fails if any is missing --dimension / -d.
  - Wired into v3-ci.yml as browser-rvf-create-flags-smoke and into
    witness-verify's `needs:` so a regression blocks publish.

Cases covered by guards: source-only checkout (no deps), source-only
checkout with build, built tree, missing dimension flag on TS/dist/
shell/markdown call sites. The smokes are independent jobs so the CI
summary names the specific contract that broke.

Co-Authored-By: RuFlo <ruv@ruv.net>
2026-05-16 08:44:51 -04:00
Reuven b5b6fb3fbe feat(ruflo-browser): v0.2.0 session-as-skill architecture + ADR-0001
Refactors ruflo-browser around recordable, replayable RVF cognitive
containers. Implements ADR-0001 (Proposed). Pre-Accept gate is a 10-site
replay-fidelity spike (≥80% pass) — harness shipped, run pending.

Plugin (plugins/ruflo-browser/):
- bump 0.1.0 → 0.2.0; new keywords (rvf, replay, trajectory, agentdb, aidefence)
- ADR-0001: session-as-skill architecture, 4 AgentDB namespaces, 3 AIDefence
  gates, 7 verb dispatcher, 5 new MCP lifecycle tools, 7+1 skill catalog,
  load-bearing replay-fidelity assumption flagged in Verification §4
- agent: rewritten with session contract, RVF allocation, ruvector
  trajectory-begin/step/end hooks, 4 namespaced AgentDB writes, 3
  mandatory AIDefence gates
- /ruflo-browser command: verb dispatcher (ls/show/replay/export/fork/purge/doctor)
- 7 new skills: browser-record (primitive), browser-replay, browser-extract,
  browser-login, browser-form-fill, browser-screenshot-diff, browser-auth-flow
- browser-test kept; rewritten to compose record+replay
- browser-scrape becomes a deprecation shim (removed in v0.3.0)
- scripts/smoke.sh: 13 structural checks; scripts/replay-spike.sh + SITES.txt:
  10-site interactive harness writing STATUS.md per run

CLI (v3/@claude-flow/cli/):
- src/mcp-tools/browser-session-tools.ts: 5 new lifecycle tools
  (browser_session_record / _end / _replay / browser_template_apply /
  browser_cookie_use). Each shells out to pinned ruvector@0.2.25 + the
  existing agent-browser CLI + bridged claude-flow memory; missing deps
  degrade with structured success:false rather than crash.
- src/mcp-client.ts: registers browserSessionTools alongside existing
  browserTools.
- TypeScript clean (npx tsc --noEmit reports zero errors against the
  new files).

Borrows from Browserbase skills/skill repo (verified 2026-05-04):
trace-as-firehose with per-page bisection (browser-trace/SKILL.md);
outer/inner self-improving loop (autobrowse/SKILL.md); sessions+contexts
as separately addressable artifacts (browser/REFERENCE.md + cookie-sync).
Adapted to use Ruflo's substrates (RVF, ruvector, AgentDB, AIDefence,
federation) rather than Browserbase's hosted backend.

Verification:
- bash plugins/ruflo-browser/scripts/smoke.sh → 13 passed, 0 failed.
- replay spike runnable via scripts/replay-spike.sh (network-dependent;
  not part of the smoke contract). ADR remains Proposed until ≥80% pass
  recorded under spike-results/<timestamp>/STATUS.md.

Co-Authored-By: RuFlo <ruv@ruv.net>
2026-05-04 16:47:37 -04:00