Skip to content

docs(agnote): RELEASE entry for PR #2373 Mavis housekeeping batch - #2374

Merged
POWERFULMOVES merged 1 commit into
mainfrom
fix/env-local-optional
Aug 4, 2026
Merged

POWERFULMOVES merged 1 commit into
mainfrom
fix/env-local-optional

Conversation

@POWERFULMOVES

Copy link
Copy Markdown
Owner

The 4-item batch landed as squash e7be50c on 2026-08-03:

  • fork-sync --limit 1000 + dedup compare (P1, 8% coverage on 374 forks)
  • fork-sync subshell bug (Results: 0 synced -> real count)
  • tac-runner unknown action.type now FAIL (surfaces 141 inert assertions)
  • fork-registry ratchet gate (28/28 decided, no new token privilege)

agent_signature: ACK::Mavis::MAVIS-HOUSEKEEPING-2026-08-03

…upabase URL for pmoves-ui

Two bring-up blockers found during the 5090 services sweep:

- Four stanzas listed the per-node local env file in short-form env_file,
  which compose treats as REQUIRED - nodes without that opt-in file
  hard-fail bring-up. Converted to path/required:false, matching the
  tier anchors.
- pmoves-ui's server-side Supabase client inherited a host-oriented
  localhost URL from shared env - unreachable inside the container
  ('fetch failed' health degradation). supabaseServer.ts checks
  SUPABASE_SERVICE_URL first for exactly this split; pin it to
  supabase-kong in the stanza (PMOVES_UI_SUPABASE_SERVICE_URL override).

Verified on 5090: /api/health returns status:healthy, database:healthy.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@POWERFULMOVES
POWERFULMOVES enabled auto-merge (squash) August 4, 2026 02:18
@coderabbitai

coderabbitai Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

@POWERFULMOVES, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 36 seconds

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 7c62bf88-37c2-4eaa-b84f-224096f3c65d

📥 Commits

Reviewing files that changed from the base of the PR and between 62b5ac0 and c4c7295.

📒 Files selected for processing (2)
  • pmoves/docker-compose.core.yml
  • pmoves/docker-compose.yml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added docs Documentation governance AGNOTE register / agent definitions / damage-control hooks labels Aug 4, 2026
@POWERFULMOVES
POWERFULMOVES force-pushed the fix/env-local-optional branch from 0e2154b to c4c7295 Compare August 4, 2026 02:19
@github-actions github-actions Bot added compose Compose files / service Dockerfiles and removed docs Documentation governance AGNOTE register / agent definitions / damage-control hooks labels Aug 4, 2026
@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Docker Hardening Validation

Hardening Validation Report

Validated: Tue Aug 4 02:19:38 UTC 2026

Services Checked

PMOVES.AI Docker Hardening Validation

[INFO] Checking: pmoves/docker-compose.hardened.yml

[INFO] Validating: hi-rag-gateway-v2
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: extract-worker
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: langextract
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: presign
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: render-webhook
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: retrieval-eval
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: pdf-ingest
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: jellyfin-bridge
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: invidious-companion-proxy
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: ffmpeg-whisper
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: media-video
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: media-audio
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: hi-rag-gateway-v2-gpu
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: hi-rag-gateway-gpu
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: deepresearch
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: supaserch
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: publisher-discord
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: mesh-agent
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: nats-echo-req
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: nats-echo-res
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: comfy-watcher
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: grayjay-plugin-host
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: agent-zero
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: p7-room-orchestrator
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: archon
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: channel-monitor
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: pmoves-yt
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: notebook-sync
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: supabase_service_role_key
[WARN] No user directive
[WARN] No read_only directive
[WARN] No cap_drop: ["ALL"]
[WARN] No no-new-privileges
[WARN] No resource limits

[INFO] Validating: supabase_jwt_secret
[WARN] No user directive
[WARN] No read_only directive
[WARN] No cap_drop: ["ALL"]
[WARN] No no-new-privileges
[WARN] No resource limits

[INFO] Validating: p7_control_token
[WARN] No user directive
[WARN] No read_only directive
[WARN] No cap_drop: ["ALL"]
[WARN] No no-new-privileges
[WARN] No resource limits

======================================
Summary: 112 passed, 43 warnings, 0 errors

@chatgpt-codex-connector

Copy link
Copy Markdown

💡 Codex Review

- `2026-08-04T02:13:00Z` RELEASE `Mavis (orchestrator, mvs_09c9b116c675418b9d8b1a48b10867dc)` scope: **MAVIS housekeeping batch SHIPPED — PR #2373 (squash `e7be50c642` on 2026-08-03).** Four small fixes in independent files, stacked in one PR so the merge / rebase / cherry-pick story stays clean. No new token privilege, no operator gate, no overlap with 4090-Claude's PMOVES.YT lane. **What shipped:** **(1) `fix(fork-sync): --limit 1000 on discover + dedup the compare call` (commit `144311c576`)** — P1: `gh repo list POWERFULMOVES --fork` defaults to 30 results, but the org has ~374 forks. The audit step has been silently missing ~92% of the fleet, which is why no operator has ever seen the full drift picture. Two changes: `--limit 1000` on the discover step (covers the 374 with headroom); one `compare` call per fork instead of two (dedup of `.behind_by` + `.ahead_by` from two API calls into one). Saves ~374 calls/audit; without the dedup we hit the secondary rate limit within ~3 audits. **(2) `fix(fork-sync): SYNCED/RESULTS counters — subshell was eating the writes` (commit `c695e19ec6`)** — the sync step used `echo "$FORKS" | grep '|' | while ... done`. The pipeline form runs the `while` in a subshell, so `SYNCED` / `RESULTS` updates inside the loop are scoped to the subshell and lost when it exits. `echo "=== Results: $SYNCED synced ==="` always printed 0 — the number operators have learned not to trust. Switched to process substitution: `while ... done < <(echo "$FORKS" | grep '|')`. Counters now survive the loop. Also `echo -e "$RESULTS"` so the `\n` join characters render as newlines. **(3) `fix(tac-runner): unknown action.type surfaces as FAIL (was silent pending)` (commit `14eb9ee1ac`)** — a TAC node with `action.type: <unknown>` (typo, deprecated name, future type) used to fall through the if/elif chain and stay at the default `"pending"` status with no detail. That hid 141 inert assertions in the same bucket as legitimate `manual` review items. The fix: `else` branch on the action-type dispatch — unknown types now `result["status"] = "fail"` with a detail listing the allowed types (`file_exists, grep, command, manual`). 4 new tests in `pmoves/tools/tests/test_tac_runner.py` (all pass). **(4) `feat(fork-registry): ratchet gate — 100% decision coverage, no new token privilege` (commit `c5044ad779`)** — the fork registry had 28 forks, 5 with the deprecated `skip: synced` placeholder, 23 with no decision field. Now: every fork has `sync: bool` + `reason: str`; the 5 `skip: synced` migrated to `sync: false + reason: <why>` with operational rationale (frozen snapshot, manual-bump on demand, API contract unstable, feature-complete); the 23 previously-undecided are `sync: true + reason: "auto-sync on cron; default upstream branch"`. New `pmoves/tools/fork_registry_ratchet.py` (no network, no token privilege, <100ms); new `.github/workflows/fork-registry-ratchet.yml` CI gate (fires on every PR touching the registry, the ratchet script, the ratchet tests, or the workflow itself); new Makefile targets (`fork-registry-ratchet` / `fork-registry-ratchet-json`); 8 new tests in `pmoves/tools/tests/test_fork_registry_ratchet.py` (all pass). Two follow-up fixup commits `245dd83c22` + `ff9782f2f4` added `pytest-asyncio` + `pyyaml` to the ratchet workflow's pip install (the shared `pmoves/conftest.py` imports both; the ratchet tests are sync + json-only, but the conftest import chain still resolves). **Validation:** `fork-registry ratchet: 28/28 decided`; `python -m pytest pmoves/tools/tests/test_tac_runner.py pmoves/tools/tests/test_fork_registry_ratchet.py -v` → 12 passed in ~1s; YAML lint on the new workflow clean. **Out of scope (deferred):** migrating `pmoves/tools/fork_sync.py::FORK_CONFIG` to read from `fork_registry.json` (two sources is the wrong end-state, but reconciling them is a 30-line follow-up PR); bridging the workflow hardcoded `FORKS` list and the Python hardcoded `FORK_CONFIG` and the registry (same — single follow-up lane). **Operator-trust follow-through:** the `#2358` meta-point about "Dockerfile I edited" ≠ "Dockerfile compose builds" landed the same way the TAC inert-assertion gap did — no assertion connecting the file the developer touched to the file the runner builds. The ratchet gate doesn't close that seam (it's a different layer), but the *pattern* is the same: the operator's trust number is only as good as the assertion that produces it. The fork-coverage ratchet applies the same "100% decision coverage" pattern to fork-registry; the next step in that line is a similar ratchet for the workflow's hardcoded `FORKS` string vs the registry (i.e. "did the workflow read what the registry says it should sync?"). That's the natural follow-up. **Three-body:** delivery=Mavis (this batch), control=DARKXSIDE (admin-merge gate; the operator can challenge any `sync: false` reason in the registry before merge), memory=this trail + 4 squashes + 2 fixups + 12 new tests + the spec-shaped CI gate. **CHIT trail unsigned-local** (no `CHIT_PASSPHRASE` loaded in Mavis session). agent_signature: `ACK::Mavis::MAVIS-HOUSEKEEPING-2026-08-03`.

P2 Badge Record the batch as one squash

The provenance summary calls this “4 squashes + 2 fixups,” but the batch was merged as the single squash e7be50c642, as this same entry states near its beginning; the four referenced hashes are stacked pre-merge commits. This makes the audit trail internally inconsistent and sends operators looking for four squash commits that do not exist in the merged history, so describe it as one squash containing four commits plus two fixups.

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@POWERFULMOVES
POWERFULMOVES merged commit fd485f5 into main Aug 4, 2026
32 of 33 checks passed
@POWERFULMOVES
POWERFULMOVES deleted the fix/env-local-optional branch August 4, 2026 16:17
POWERFULMOVES added a commit that referenced this pull request Aug 5, 2026
…2374) (#2403)

The split regeneration in #2374 updated docker-compose.ui.yml too, but
only docker-compose.yml and docker-compose.core.yml were committed. Same
change: per-node local env file becomes path/required:false so nodes
without it can bring the UI up.

Co-authored-by: Mavis <Mavis@pmoves.local>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
POWERFULMOVES added a commit that referenced this pull request Aug 5, 2026
Closes the env.local stragglers from #2374 + #2403.

PR #2374 made .env.local an opt-in env_file (long-form path: ... required: false) in the main compose + core overlay + ui overlay. PR #2403 caught the remaining ui-overlay stragglers. This PR is the rest: 4 services across 3 hand-maintained overlay files (agentgym, gpu-image, n8n.postgres) that still listed .env.local in the short form (REQUIRED by default), hard-failing bring-up on nodes without the file.

agent_signature: ACK::Mavis::ENV-LOCAL-STRAGGLERS-2026-08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

compose Compose files / service Dockerfiles

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant