Skip to content

chore: certify current production baseline - #1

Merged
OneBigHen merged 52 commits into
mainfrom
feat/single-user-ai-studio
Aug 24, 2026
Merged

OneBigHen merged 52 commits into
mainfrom
feat/single-user-ai-studio

Conversation

@OneBigHen

@OneBigHen OneBigHen commented Aug 11, 2026 •

Copy link
Copy Markdown
Owner

Phase 00 records the re-audit against the extracted production readiness pack. Local evidence: clean frozen install across 24 workspaces; forced check 115/115 successful with zero cached tasks; Playwright 43 passed and 2 skipped across desktop, iPad, and iPhone profiles; package, collaboration, supply-chain, boundary, dependency, secret, and SBOM gates passed. Current product gaps remain explicitly recorded in the capability matrix and execution ledger. Numbered implementation phases remain uncertified until binding acceptance evidence is implemented and verified.

Summary by CodeRabbit

  • New Features
    • Added Source Studio for ingesting and synthesizing content from documents, spreadsheets, presentations, images, audio, and video.
    • Expanded the spatial editor with layers, assets, annotations, camera bookmarks, alignment, isolation, undo/redo, shortcuts, and recovery.
    • Added a local asset library with search and procedural scientific equipment templates.
    • Added companion settings for setup, sign-in, pairing, encrypted secrets, and storage health.
  • Improvements
    • Added citations, confidence, provider details, personal release export, full backups, and connection status.
  • Security
    • Strengthened session protection, archive validation, approval handling, supply-chain checks, and release trust indicators.

GuideForge Build Agent added 9 commits August 5, 2026 10:11
- add AGENTS_SINGLE_USER.md operating policy (from build pack)
- AGENTS.md links the single-user policy as the program operating rules
- gitignore the build pack (binding instructions, not repo content)
…ty matrix

- CI now runs Playwright E2E (desktop Chromium + iPad/iPhone WebKit) in a
  dedicated job with browser install and artifact upload
- CI provisions Postgres 17 for the apps/api integration tests
- supply-chain gates are blocking and policy-driven (audit, licenses, SBOM,
  secrets) with docs/security/reviewed-exceptions.json + schema + policy
- boundary checker fixed to match real import specifiers (was matching
  comments); catalog pinning for @types/pg, tsx, @axe-core/playwright,
  @cyclonedx/cyclonedx-npm so dep-check passes
- no-credential AI test: gateway reports explicit unavailability, never
  fabricates output; offline authoring requires explicit deterministic adapter
- capability matrix (docs/progress/CAPABILITY_MATRIX.md) records implemented/
  partial/missing with evidence; original phase reports preserved in
  docs/progress/legacy/ as evidence of intent
- baseline bundle/perf report (1.58 MB main chunk finding recorded)
- pnpm check --force 100/100; e2e 37 passed / 2 skipped (WebKit offline);
  ADR 0009
…on, provenance, bounded unzip, unsigned releases

- session: roles never accepted from body; ownerId enforced for network mode;
  stable single-owner audit org constant (no random UUIDs per event)
- approval: real content-hash invalidation (409 on changed content)
- SHA-256 everywhere: @noble/hashes in domain; FNV removed from api,
  interop-ms-guide, model-gateway, package-gforge release verify, web
- adapters: constructor API keys actually used (DeepSeek + OpenRouter)
- validation: deep isExtractionOutput; zero-citation steps rejected
- proposals: persist citations + full provider receipt (Dexie v3); provider
  badge in UI (DeepSeek live vs offline deterministic)
- signing: browsers never hold keys; unsigned personal releases (manifest
  signed:false), XR viewer trust warning
- archives: preflightZipArchive bounds entry count/sizes/ratio pre-inflation
- API: CSRF Origin check, rate limits, loopback bind default
- web: draft export downloads; stale hierarchy selection fixed; truthful
  companion status pill
- ADR 0010; pnpm check --force 100/100; e2e 37 passed / 2 skipped
- GuideSnapshot v2: scene (GuideScene), training (TrainingState), sources;
  JSON Schema v2 + pure v1->v2 migration (tested)
- Yjs canonical scene/training: working doc maps scene+training; every
  command syncs them; scene editor reads/writes the working doc (no separate
  authoritative Dexie DB)
- scene converters (scene-core SceneState <-> canonical GuideScene)
- complete packaging: collectReferencedAssets (no empty asset maps), import
  restores asset bytes; validateReferencedAssets
- semantic comparison: compareSnapshots / snapshotsSemanticallyEqual
- training commands: training/add-objective, training/add-assessment-item
  with deep-clone reducer (no aliasing)
- vertical slice round trip test (scene+camera+objective+question export/
  import identical); ADR 0011
- pnpm check --force 100/100; e2e 37 passed / 2 skipped
- connected asset browser: GLB import + attach to node (scene/set-asset)
- all-axis align/distribute (X/Y/Z selector) + isolate
- layer UI (add/assign) + camera bookmarks UI
- annotation UI (add/remove label); SceneState carries annotations
- scene undo/redo + keyboard shortcuts (W/E/R, Delete, I, Cmd/Ctrl+Z/Y)
- WebGL context-loss recovery (canvas remount)
- scene-core: addLayer, setAsset, addAnnotation, removeAnnotation commands
- ADR 0012; scene-core 19/19; check 100/100; e2e 40 passed / 2 skipped
@coderabbitai

coderabbitai Bot commented Aug 11, 2026 •

Copy link
Copy Markdown

Review Change Stack

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: e6ad9c53-7b01-4a7d-85d8-66212ccc50fc

📝 Walkthrough

Walkthrough

The PR adds single-user security, canonical guide state, spatial editing, asset management, multimodal ingestion, source-grounded synthesis, unsigned personal releases, companion settings, and blocking CI checks.

Changes

GuideForge production-readiness and authoring

Layer / File(s) Summary
Single-user policy and blocking CI controls
.github/workflows/ci.yml, AGENTS*.md, apps/companion/*, apps/api/src/*, scripts/*, docs/security/*
CI adds PostgreSQL integration tests, blocking audit, license, SBOM, secret, policy, and Playwright checks. The companion adds owner authentication, encrypted secrets, pairing, recovery, session controls, and transport enforcement.
Canonical guide contract and command state
packages/guide-schema/*, packages/commands/*, packages/collaboration/*, packages/domain/*
Guide snapshots advance to version 4 with scene, training, sources, step metadata, migrations, semantic comparison, Yjs synchronization, and typed commands.
Multimodal ingestion and source-grounded synthesis
packages/ingestion/*, packages/synthesis/*, apps/worker-documents/*, apps/web/src/services/sourceStudio*, apps/web/src/services/sourceSynthesis*
Sources receive deterministic format detection, conversion receipts, stable regions, OCR and media routing, conflict detection, cancellation, grounded synthesis, validation, repair, and pending proposals.
Asset library and package safety
packages/assets/*, packages/package-gforge/*, apps/web/src/services/assetLibrary.ts, apps/web/src/services/guideStore.ts
The asset library adds local search, license decisions, procedural GLB generation, attribution reports, archive preflight, safe paths, asset import, and unsigned personal releases.
Canonical scene persistence and spatial editor
packages/scene-core/*, apps/web/src/services/sceneStore.ts, apps/web/src/routes/scene.$guideId.tsx
Scene state moves to collaborative working documents. The editor adds layers, asset attachment, annotations, cameras, isolation, alignment and distribution axes, undo/redo, keyboard controls, and WebGL recovery.
Source Studio, proposal provenance, and web integration
apps/web/src/routes/sources.$guideId.tsx, apps/web/src/routes/settings.tsx, apps/web/src/components/*, apps/web/src/services/aiProposals.ts, apps/web/src/routeTree.gen.ts
The web app adds Source Studio and settings routes, source upload and preview flows, companion status, synthesis controls, proposal citation and receipt display, encrypted-secret management, and generated route metadata.
API ownership, provenance, and personal releases
apps/api/src/*, apps/web/src/routes/edit.$guideId.tsx, apps/xr-web/src/main.tsx, packages/package-gforge/src/release.ts
The API derives owner roles, validates origins and content hashes, applies rate limits, uses stable audit context, and returns proposal provenance. Release flows support unsigned personal packages and XR trust warnings.
Storage migrations, fixtures, documentation, and workspace wiring
packages/storage-web/src/index.ts, docs/adr/*, docs/progress/*, package.json, pnpm-workspace.yaml, apps/*/package.json, packages/*/package.json
Storage adds proposal provenance and source records. Reports, ADRs, fixtures, package manifests, dependency catalogs, styles, and test setup record the updated contracts and validation evidence.

Estimated code review effort: 5 (Critical) | ~120 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Author
  participant Companion
  participant SourceStudio
  participant Ingestion
  participant Synthesis
  participant GuideStore
  participant SpatialEditor
  Author->>Companion: configure owner session
  Companion->>Author: return authenticated companion state
  Author->>SourceStudio: upload guide sources
  SourceStudio->>Ingestion: convert bytes and build source regions
  Ingestion->>SourceStudio: return receipts, conflicts, and processing status
  Author->>Synthesis: request procedure synthesis
  Synthesis->>GuideStore: persist citation-grounded pending proposals
  Author->>SpatialEditor: edit canonical scene
  SpatialEditor->>GuideStore: commit scene changes to the working document
Loading

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

GuideForge Build Agent and others added 21 commits August 11, 2026 21:42
Was left uncommitted locally; Paperclip's GuideForge workspace is a separate
clone with no access to local working-tree files, so Codex Builder correctly
blocked rather than guess at the plan content.
Phase 0 of PLAN_TONIGHT.md: CI on the feature PR failed only on
prettier --check for 8 files; formatted them. The Universal V2 build
pack zip stays a local planning artifact like the other two packs.
The npm-based self-installer dies with EACCES opening
/root/.cache/pnpm-store/v3/server/server.json on hosted runners.
standalone: true fetches the release binary directly and takes the
version from package.json packageManager instead of a duplicate input.
apps/worker-documents renderPdfPageImages shells out to pdftoppm,
which exists locally but not on hosted runners, so the docling
fallback test failed only in CI.
pnpm audit flags nanoid 3.3.17 (high) pulled in transitively via
postcss; the repo audit policy always-blocks high findings. Override
within the ^3 range postcss accepts.
@OneBigHen

Copy link
Copy Markdown
Owner Author

@claude Please perform an adversarial production-readiness review of this branch before it merges to main (GF3 gate per PLAN_TONIGHT.md).

Scope: all 48+ commits vs main — especially phases 06-17 work that has never had CI until today (now green: check + e2e), plus recent fixes:

  • ci.yml: standalone pnpm install + poppler-utils for hosted runners
  • nanoid override 3.3.18 (high advisory via postcss)
  • prettier formatting batch
  • OpenRouter provider routing, runtime receipts, multimodal fallback seams

Key questions:

  1. Any data-loss or correctness regressions in the canonical sources model (packages/collaboration) and citation SHA-256 migration?
  2. Is the single-owner companion (SQLite, no RBAC surface) consistent and free of leftover enterprise auth paths?
  3. Does anything block cutting a release candidate (pnpm release:prepare)?

Flag anything that should block merge to main.

GuideForge Build Agent added 2 commits August 24, 2026 10:24
Reviewer: opencode ox-alpha-free adversarial diff review vs main.
Verdict APPROVE, no diff-introduced blockers. Three majors recorded
as follow-ups: provenance-drop seam in materializeSources, silent
runtime-session reset on step mismatch, release signature verified
against package-embedded key.
@OneBigHen
OneBigHen merged commit dcc5505 into main Aug 24, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants