fix(runtime): service networking, healthchecks, SQL, Makefile hardening - #740
Conversation
…nches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Fix external compose service networking and port bindings - Add missing healthcheck configurations to n8n compose - Update env.shared.example with new required variables - Harden docker-compose.yml service definitions Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Agent Zero: Dockerfile non-root hardening, MCP server auth fixes - service_registry: improve service discovery and health reporting - evo-controller: add healthcheck endpoint and startup guards - flute-gateway: fix import path - render-webhook: update deps, add input validation - retrieval-eval: add health and metrics endpoints Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Tighten RLS policies for public_init and geometry tables - Update model registry seed data with current model versions - Add studio board RLS migration for service_role access - Add supabase .gitignore and config.toml for local dev Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Makefile: add sign-trail, volume-reset, and infra targets - smoke.ps1: expand service coverage and timeout handling - with-env.sh: support multi-tier env loading - bringup_with_ui.sh: improve startup sequencing - chit_security.py: fix HMAC signing edge cases - retro_flightcheck.py: add new validation checks - capture_evidence.sh: new script for PR evidence collection - AI_GRAPHITI_PROTOCOL.md: document agent trail protocol - pr-monitor.md: update skill command definition Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Update submodule pointers to latest reviewed commits from 2026-03-01 security sweep. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- 5 submodule security reviews (Agent Zero, BoTZ, DoX, ToKenism, transcribe-and-fetch) - Security queue tracker and sitrep JSON - AGNOTE4482 FlOO$ and Flute agent notes - CHIT review-sweep skill command and post-review hook Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Warning Rate limit exceeded
⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. 📒 Files selected for processing (47)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…rd path (#744) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * fix(security): auth-gate agent-zero A2A discovery endpoint * fix(security): HMAC CHIT proofs + A2A discovery auth audit + dotnet preflight (#736) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * chore(env): require dotnet sdk in bootstrap preflight --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> * chore(deps): bump multer (#735) Bumps the npm_and_yarn group with 1 update in the /CATACLYSM_STUDIOS_INC/L4-PLATFORM/provisions/docker-stacks/jellyfin-ai/api-gateway directory: [multer](https://github.com/expressjs/multer). Updates `multer` from 2.0.2 to 2.1.0 - [Release notes](https://github.com/expressjs/multer/releases) - [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md) - [Commits](expressjs/multer@v2.0.2...v2.1.0) --- updated-dependencies: - dependency-name: multer dependency-version: 2.1.0 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(chit): correct FlOO$ PYTHONPATH for pr-monitor pipeline * feat(chit): CHIT-signed Graphiti trail + skill pairing awareness (#739) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * feat(chit): add CHIT-signed Graphiti trail tooling Add provenance signing for agent trail entries using CHIT HMAC: - sign_trail.py: CLI tool to create and sign trail entries - PostToolUse hook for automatic signing on trail file writes - /chit:sign-trail skill command for interactive use - Preflight check for dotnet SDK (required by CHIT crypto) - CLAUDE.md documentation for trail signing workflow - Settings.json hook registration Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * fix(runtime): service networking, healthchecks, SQL, Makefile hardening (#740) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * fix(compose): networking, healthchecks, and env hardening - Fix external compose service networking and port bindings - Add missing healthcheck configurations to n8n compose - Update env.shared.example with new required variables - Harden docker-compose.yml service definitions Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(services): auth, healthchecks, and dependency updates - Agent Zero: Dockerfile non-root hardening, MCP server auth fixes - service_registry: improve service discovery and health reporting - evo-controller: add healthcheck endpoint and startup guards - flute-gateway: fix import path - render-webhook: update deps, add input validation - retrieval-eval: add health and metrics endpoints Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(sql): RLS policies, model registry seeds, and supabase config - Tighten RLS policies for public_init and geometry tables - Update model registry seed data with current model versions - Add studio board RLS migration for service_role access - Add supabase .gitignore and config.toml for local dev Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(tooling): Makefile targets, smoke tests, and operational scripts - Makefile: add sign-trail, volume-reset, and infra targets - smoke.ps1: expand service coverage and timeout handling - with-env.sh: support multi-tier env loading - bringup_with_ui.sh: improve startup sequencing - chit_security.py: fix HMAC signing edge cases - retro_flightcheck.py: add new validation checks - capture_evidence.sh: new script for PR evidence collection - AI_GRAPHITI_PROTOCOL.md: document agent trail protocol - pr-monitor.md: update skill command definition Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(submodules): update BoTZ-gateway and Cipher pointers Update submodule pointers to latest reviewed commits from 2026-03-01 security sweep. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs(security): 2026-03-01 submodule security reviews and agent notes - 5 submodule security reviews (Agent Zero, BoTZ, DoX, ToKenism, transcribe-and-fetch) - Security queue tracker and sitrep JSON - AGNOTE4482 FlOO$ and Flute agent notes - CHIT review-sweep skill command and post-review hook Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * docs(agents): overlay TAC model/persona readiness into graphiti protocol * docs(agents): correct TAC status wording for local staged artifacts * feat(models): reconcile model registry with Anthropic, TTS, and expanded service mappings Add Anthropic provider (claude-sonnet-4-5, claude-opus-4-5, claude-haiku-4-5) as persona backbone. Add TTS provider with 6 engines from Ultimate TTS Studio. Add 5 missing Ollama models from gpu-models.yaml (qwen3:32b, qwen3:1.7b, llama3.2:3b, codellama:7b, deepseek-coder:6.7b). Fix VRAM values to match gpu-models.yaml truth (qwen3:8b: 8000→6144, nomic-embed-text: 1000→512). Expand service-model mappings from 4 to 15+ services including hirag, archon, coding, orchestrator, vl_sentinel, tts, extract_worker, and more. Covers TAC branches B + C. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(personas): integrate 8 standard persona seeds into initdb pipeline Copy persona seeds from pmoves/db/v5_14_seed_standard_personas.sql into the active Supabase initdb pipeline as 17_persona_seed.sql. Personas reference claude-sonnet-4-5 (Developer/Creator/Analyst/Tester), claude-opus-4-5 (Researcher/Coordinator/Security), and claude-haiku-4-5 (Archivist). Sequenced after model registry (12) to ensure model_preference references are valid. Preserves ON CONFLICT (name, version) idempotency. Covers TAC branch A. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(gpu): sync gpu-models.yaml with SQL model registry Add 10 models missing from gpu-models.yaml that exist in SQL and consume local GPU VRAM: qwen2.5:32b, qwen2.5:14b, qwen2-vl:7b, qwen3-reranker:4b, nemotron-mini, llama3.1, qwen3-embedding:4b/8b, embeddinggemma:300m. GPU Orchestrator needs these entries for VRAM scheduling on RTX 5090. Covers TAC branch D. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(db): add persona-model resolution view for runtime agent identity lookup Create persona_model_resolution view joining persona → model → provider for runtime resolution of which API endpoint to call for each persona. Also adds active_persona_summary convenience view. Grants SELECT to PostgREST anon/auth roles. Covers TAC branch F. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(ops): add model-readiness check and Make target Create model_readiness_check.py that validates: - Supabase model_providers populated with ≥8 active providers - Supabase personas table populated with ≥8 rows - Ollama has expected local models pulled - TensorZero gateway operational - persona_model_resolution view returns valid data Add 'make model-readiness' target and wire into verify-all chain. Covers TAC branch E. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(db): harden model/persona seed determinism and view security * fix(ops): enforce readiness gate and close TAC doc drift * fix(a2a): harden discovery/task auth and add agent-card endpoint * fix(sql): harden studio_board RLS policy for service_role only * fix(chat-relay): lazy-load supabase client to avoid path shadow in tests * fix(ci): avoid hard failures in compose validation and yt docs tests * fix(pmoves-yt): make boto3 optional at import time for test collection * fix(pmoves-yt): stub tenacity when unavailable in CI test env * chore(submodule): bump PMOVES-Agent-Zero for canonical agent-card parity * chore(pr-scope): drop transcribe-and-fetch and cipher gitlink bumps from #744 * fix(a2a): address review blockers — RLS predicate, fail-closed key gate, discovery auth B-1: studio_board RLS policy now restricts to service_role instead of using(true) B-2: model-registry SUPABASE_SERVICE_KEY uses :? (fail-closed) instead of :- (empty) B-3: discover_agents endpoint uses _require_discovery_auth instead of _require_task_auth Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(submodules): bump transcribe-and-fetch + cipher for A2A parity (#745) * chore(submodules): bump transcribe-and-fetch and cipher for a2a auth parity * chore(submodules): bump transcribe-and-fetch and cipher to merge-ready A2A heads --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> * fix(a2a): secure discovery/task APIs and align with upstream agent-card path (#744) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * fix(security): auth-gate agent-zero A2A discovery endpoint * fix(security): HMAC CHIT proofs + A2A discovery auth audit + dotnet preflight (#736) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * chore(env): require dotnet sdk in bootstrap preflight --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> * chore(deps): bump multer (#735) Bumps the npm_and_yarn group with 1 update in the /CATACLYSM_STUDIOS_INC/L4-PLATFORM/provisions/docker-stacks/jellyfin-ai/api-gateway directory: [multer](https://github.com/expressjs/multer). Updates `multer` from 2.0.2 to 2.1.0 - [Release notes](https://github.com/expressjs/multer/releases) - [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md) - [Commits](expressjs/multer@v2.0.2...v2.1.0) --- updated-dependencies: - dependency-name: multer dependency-version: 2.1.0 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(chit): correct FlOO$ PYTHONPATH for pr-monitor pipeline * feat(chit): CHIT-signed Graphiti trail + skill pairing awareness (#739) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * feat(chit): add CHIT-signed Graphiti trail tooling Add provenance signing for agent trail entries using CHIT HMAC: - sign_trail.py: CLI tool to create and sign trail entries - PostToolUse hook for automatic signing on trail file writes - /chit:sign-trail skill command for interactive use - Preflight check for dotnet SDK (required by CHIT crypto) - CLAUDE.md documentation for trail signing workflow - Settings.json hook registration Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * fix(runtime): service networking, healthchecks, SQL, Makefile hardening (#740) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * fix(compose): networking, healthchecks, and env hardening - Fix external compose service networking and port bindings - Add missing healthcheck configurations to n8n compose - Update env.shared.example with new required variables - Harden docker-compose.yml service definitions Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(services): auth, healthchecks, and dependency updates - Agent Zero: Dockerfile non-root hardening, MCP server auth fixes - service_registry: improve service discovery and health reporting - evo-controller: add healthcheck endpoint and startup guards - flute-gateway: fix import path - render-webhook: update deps, add input validation - retrieval-eval: add health and metrics endpoints Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(sql): RLS policies, model registry seeds, and supabase config - Tighten RLS policies for public_init and geometry tables - Update model registry seed data with current model versions - Add studio board RLS migration for service_role access - Add supabase .gitignore and config.toml for local dev Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(tooling): Makefile targets, smoke tests, and operational scripts - Makefile: add sign-trail, volume-reset, and infra targets - smoke.ps1: expand service coverage and timeout handling - with-env.sh: support multi-tier env loading - bringup_with_ui.sh: improve startup sequencing - chit_security.py: fix HMAC signing edge cases - retro_flightcheck.py: add new validation checks - capture_evidence.sh: new script for PR evidence collection - AI_GRAPHITI_PROTOCOL.md: document agent trail protocol - pr-monitor.md: update skill command definition Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(submodules): update BoTZ-gateway and Cipher pointers Update submodule pointers to latest reviewed commits from 2026-03-01 security sweep. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs(security): 2026-03-01 submodule security reviews and agent notes - 5 submodule security reviews (Agent Zero, BoTZ, DoX, ToKenism, transcribe-and-fetch) - Security queue tracker and sitrep JSON - AGNOTE4482 FlOO$ and Flute agent notes - CHIT review-sweep skill command and post-review hook Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * docs(agents): overlay TAC model/persona readiness into graphiti protocol * docs(agents): correct TAC status wording for local staged artifacts * feat(models): reconcile model registry with Anthropic, TTS, and expanded service mappings Add Anthropic provider (claude-sonnet-4-5, claude-opus-4-5, claude-haiku-4-5) as persona backbone. Add TTS provider with 6 engines from Ultimate TTS Studio. Add 5 missing Ollama models from gpu-models.yaml (qwen3:32b, qwen3:1.7b, llama3.2:3b, codellama:7b, deepseek-coder:6.7b). Fix VRAM values to match gpu-models.yaml truth (qwen3:8b: 8000→6144, nomic-embed-text: 1000→512). Expand service-model mappings from 4 to 15+ services including hirag, archon, coding, orchestrator, vl_sentinel, tts, extract_worker, and more. Covers TAC branches B + C. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(personas): integrate 8 standard persona seeds into initdb pipeline Copy persona seeds from pmoves/db/v5_14_seed_standard_personas.sql into the active Supabase initdb pipeline as 17_persona_seed.sql. Personas reference claude-sonnet-4-5 (Developer/Creator/Analyst/Tester), claude-opus-4-5 (Researcher/Coordinator/Security), and claude-haiku-4-5 (Archivist). Sequenced after model registry (12) to ensure model_preference references are valid. Preserves ON CONFLICT (name, version) idempotency. Covers TAC branch A. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(gpu): sync gpu-models.yaml with SQL model registry Add 10 models missing from gpu-models.yaml that exist in SQL and consume local GPU VRAM: qwen2.5:32b, qwen2.5:14b, qwen2-vl:7b, qwen3-reranker:4b, nemotron-mini, llama3.1, qwen3-embedding:4b/8b, embeddinggemma:300m. GPU Orchestrator needs these entries for VRAM scheduling on RTX 5090. Covers TAC branch D. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(db): add persona-model resolution view for runtime agent identity lookup Create persona_model_resolution view joining persona → model → provider for runtime resolution of which API endpoint to call for each persona. Also adds active_persona_summary convenience view. Grants SELECT to PostgREST anon/auth roles. Covers TAC branch F. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(ops): add model-readiness check and Make target Create model_readiness_check.py that validates: - Supabase model_providers populated with ≥8 active providers - Supabase personas table populated with ≥8 rows - Ollama has expected local models pulled - TensorZero gateway operational - persona_model_resolution view returns valid data Add 'make model-readiness' target and wire into verify-all chain. Covers TAC branch E. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(db): harden model/persona seed determinism and view security * fix(ops): enforce readiness gate and close TAC doc drift * fix(a2a): harden discovery/task auth and add agent-card endpoint * fix(sql): harden studio_board RLS policy for service_role only * fix(chat-relay): lazy-load supabase client to avoid path shadow in tests * fix(ci): avoid hard failures in compose validation and yt docs tests * fix(pmoves-yt): make boto3 optional at import time for test collection * fix(pmoves-yt): stub tenacity when unavailable in CI test env * chore(submodule): bump PMOVES-Agent-Zero for canonical agent-card parity * chore(pr-scope): drop transcribe-and-fetch and cipher gitlink bumps from #744 * fix(a2a): address review blockers — RLS predicate, fail-closed key gate, discovery auth B-1: studio_board RLS policy now restricts to service_role instead of using(true) B-2: model-registry SUPABASE_SERVICE_KEY uses :? (fail-closed) instead of :- (empty) B-3: discover_agents endpoint uses _require_discovery_auth instead of _require_task_auth Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* fix(security): auth-gate agent-zero A2A discovery endpoint * fix(security): HMAC CHIT proofs + A2A discovery auth audit + dotnet preflight (#736) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * chore(env): require dotnet sdk in bootstrap preflight --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> * chore(deps): bump multer (#735) Bumps the npm_and_yarn group with 1 update in the /CATACLYSM_STUDIOS_INC/L4-PLATFORM/provisions/docker-stacks/jellyfin-ai/api-gateway directory: [multer](https://github.com/expressjs/multer). Updates `multer` from 2.0.2 to 2.1.0 - [Release notes](https://github.com/expressjs/multer/releases) - [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md) - [Commits](expressjs/multer@v2.0.2...v2.1.0) --- updated-dependencies: - dependency-name: multer dependency-version: 2.1.0 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(chit): correct FlOO$ PYTHONPATH for pr-monitor pipeline * feat(chit): CHIT-signed Graphiti trail + skill pairing awareness (#739) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * feat(chit): add CHIT-signed Graphiti trail tooling Add provenance signing for agent trail entries using CHIT HMAC: - sign_trail.py: CLI tool to create and sign trail entries - PostToolUse hook for automatic signing on trail file writes - /chit:sign-trail skill command for interactive use - Preflight check for dotnet SDK (required by CHIT crypto) - CLAUDE.md documentation for trail signing workflow - Settings.json hook registration Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * fix(runtime): service networking, healthchecks, SQL, Makefile hardening (#740) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * fix(compose): networking, healthchecks, and env hardening - Fix external compose service networking and port bindings - Add missing healthcheck configurations to n8n compose - Update env.shared.example with new required variables - Harden docker-compose.yml service definitions Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(services): auth, healthchecks, and dependency updates - Agent Zero: Dockerfile non-root hardening, MCP server auth fixes - service_registry: improve service discovery and health reporting - evo-controller: add healthcheck endpoint and startup guards - flute-gateway: fix import path - render-webhook: update deps, add input validation - retrieval-eval: add health and metrics endpoints Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(sql): RLS policies, model registry seeds, and supabase config - Tighten RLS policies for public_init and geometry tables - Update model registry seed data with current model versions - Add studio board RLS migration for service_role access - Add supabase .gitignore and config.toml for local dev Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(tooling): Makefile targets, smoke tests, and operational scripts - Makefile: add sign-trail, volume-reset, and infra targets - smoke.ps1: expand service coverage and timeout handling - with-env.sh: support multi-tier env loading - bringup_with_ui.sh: improve startup sequencing - chit_security.py: fix HMAC signing edge cases - retro_flightcheck.py: add new validation checks - capture_evidence.sh: new script for PR evidence collection - AI_GRAPHITI_PROTOCOL.md: document agent trail protocol - pr-monitor.md: update skill command definition Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(submodules): update BoTZ-gateway and Cipher pointers Update submodule pointers to latest reviewed commits from 2026-03-01 security sweep. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs(security): 2026-03-01 submodule security reviews and agent notes - 5 submodule security reviews (Agent Zero, BoTZ, DoX, ToKenism, transcribe-and-fetch) - Security queue tracker and sitrep JSON - AGNOTE4482 FlOO$ and Flute agent notes - CHIT review-sweep skill command and post-review hook Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * chore: add gitignore for runtime data and DAO docs (#743) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * chore: add gitignore for runtime data, DAO docs, and env backups Add entries to prevent accidental commits of: - pmoves/jellyfin-ai/ (runtime config/data from Jellyfin AI stack) - pmoves/pmoves/PR_EVIDENCE/ (smoke test evidence artifacts) - pmoves/docs/logs/pr_monitor_* (runtime PR monitor logs) - CATACLYSM_STUDIOS_INC/PMOVES DAO/ (managed separately) - pmoves/env.jellyfin-ai, pmoves/env.supa.runtime.bak.* (env backups) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * feat(models): model registry reconciliation + persona seeds + readiness check (#741) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * docs(agents): overlay TAC model/persona readiness into graphiti protocol * docs(agents): correct TAC status wording for local staged artifacts * feat(models): reconcile model registry with Anthropic, TTS, and expanded service mappings Add Anthropic provider (claude-sonnet-4-5, claude-opus-4-5, claude-haiku-4-5) as persona backbone. Add TTS provider with 6 engines from Ultimate TTS Studio. Add 5 missing Ollama models from gpu-models.yaml (qwen3:32b, qwen3:1.7b, llama3.2:3b, codellama:7b, deepseek-coder:6.7b). Fix VRAM values to match gpu-models.yaml truth (qwen3:8b: 8000→6144, nomic-embed-text: 1000→512). Expand service-model mappings from 4 to 15+ services including hirag, archon, coding, orchestrator, vl_sentinel, tts, extract_worker, and more. Covers TAC branches B + C. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(personas): integrate 8 standard persona seeds into initdb pipeline Copy persona seeds from pmoves/db/v5_14_seed_standard_personas.sql into the active Supabase initdb pipeline as 17_persona_seed.sql. Personas reference claude-sonnet-4-5 (Developer/Creator/Analyst/Tester), claude-opus-4-5 (Researcher/Coordinator/Security), and claude-haiku-4-5 (Archivist). Sequenced after model registry (12) to ensure model_preference references are valid. Preserves ON CONFLICT (name, version) idempotency. Covers TAC branch A. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(gpu): sync gpu-models.yaml with SQL model registry Add 10 models missing from gpu-models.yaml that exist in SQL and consume local GPU VRAM: qwen2.5:32b, qwen2.5:14b, qwen2-vl:7b, qwen3-reranker:4b, nemotron-mini, llama3.1, qwen3-embedding:4b/8b, embeddinggemma:300m. GPU Orchestrator needs these entries for VRAM scheduling on RTX 5090. Covers TAC branch D. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(db): add persona-model resolution view for runtime agent identity lookup Create persona_model_resolution view joining persona → model → provider for runtime resolution of which API endpoint to call for each persona. Also adds active_persona_summary convenience view. Grants SELECT to PostgREST anon/auth roles. Covers TAC branch F. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(ops): add model-readiness check and Make target Create model_readiness_check.py that validates: - Supabase model_providers populated with ≥8 active providers - Supabase personas table populated with ≥8 rows - Ollama has expected local models pulled - TensorZero gateway operational - persona_model_resolution view returns valid data Add 'make model-readiness' target and wire into verify-all chain. Covers TAC branch E. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(db): harden model/persona seed determinism and view security * fix(ops): enforce readiness gate and close TAC doc drift * fix(sql): harden studio_board RLS policy for service_role only * fix(db): reconcile model provider upserts and enforce studio policy replacement - update model_providers upserts to refresh mutable fields (type/api_base/api_key_env_var/description/active/metadata)\n- always replace studio_board_service_role_all policy in migration for upgrade parity\n- clarify persona resolution grant comment to match PostgREST role grants\n- add readiness-check type hints/constants and align TAC verify steps * fix(security): tighten studio_board revokes and TensorZero reachability checks * fix(readiness): enforce registry thresholds and harden studio_board revokes --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * docs(agents): comprehensive AGENTS directory review and cross-reference fixes (#742) * docs(agents): update gap analysis with Phase 1 completions - Mark Phase 1 roadmap items as complete (model registry, persona seeds, GPU models YAML, service-model mappings) - Update CHIT integration status from None to Partial - Add A2A MCP foundation status - Update security hooks as implemented - Refresh date to 2026-03-01 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs(agents): add cross-references between operator docs - AGENT_CONTEXT_PATTERNS: add hook portability warning for Windows - CODEX_CIPHER_MEMORY: add cipher categories table for quick reference - CODEX_OPERATOR_HOME: add known gaps link to gap analysis - CODEX_RUNTIME_PROTOCOL: add Codex-Claude collision handling section Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs(agents): create README.md index for 69-file directory Add a start-here index document that catalogs all 69 files in the AGENTS directory with descriptions and category groupings. Provides newcomers a navigation map for the agent documentation corpus. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs(agents): add concrete persona seed examples to PERSONAS.md - Add 4 worked examples (Developer, Creator, Researcher, Analyst) showing model_preference, chit_attribution, and tool_allowlist - Document persona inheritance chain (seed SQL → Supabase row → agent_registry.yaml → runtime resolution view) - Add CHIT attribution configuration section - Add quick reference summary table for all 8 standard personas - Cross-reference 17_persona_seed.sql from PR #741 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(registry): complete CHIT toggle coverage and Hi-RAG port split - Add chit_toggles (encode, sign, bus_emit) to 9 infrastructure agents: nats-init, supabase-db, minio, qdrant, meilisearch, neo4j, prometheus, grafana, loki (all disabled — infra agents don't produce CHIT events) - Add gpu_port: 8087 to hi-rag-gateway for v1/v2 port split - Achieves 60/60 CHIT toggle coverage across all registered agents Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs(agents): update SUBMODULE_CODEX_HOMES naming convention docs - Document naming conventions for codex home files - Add orphan tracking guidance for unmapped submodules - Expand directory structure examples Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs(agents): align persona status, topology ports, and gap metadata --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * chore: sync Hardened → main after #741-#745 merge batch (#746) * chore(submodules): bump transcribe-and-fetch + cipher for A2A parity (#745) * chore(submodules): bump transcribe-and-fetch and cipher for a2a auth parity * chore(submodules): bump transcribe-and-fetch and cipher to merge-ready A2A heads --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> * fix(a2a): secure discovery/task APIs and align with upstream agent-card path (#744) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * fix(security): auth-gate agent-zero A2A discovery endpoint * fix(security): HMAC CHIT proofs + A2A discovery auth audit + dotnet preflight (#736) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * chore(env): require dotnet sdk in bootstrap preflight --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> * chore(deps): bump multer (#735) Bumps the npm_and_yarn group with 1 update in the /CATACLYSM_STUDIOS_INC/L4-PLATFORM/provisions/docker-stacks/jellyfin-ai/api-gateway directory: [multer](https://github.com/expressjs/multer). Updates `multer` from 2.0.2 to 2.1.0 - [Release notes](https://github.com/expressjs/multer/releases) - [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md) - [Commits](expressjs/multer@v2.0.2...v2.1.0) --- updated-dependencies: - dependency-name: multer dependency-version: 2.1.0 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(chit): correct FlOO$ PYTHONPATH for pr-monitor pipeline * feat(chit): CHIT-signed Graphiti trail + skill pairing awareness (#739) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * feat(chit): add CHIT-signed Graphiti trail tooling Add provenance signing for agent trail entries using CHIT HMAC: - sign_trail.py: CLI tool to create and sign trail entries - PostToolUse hook for automatic signing on trail file writes - /chit:sign-trail skill command for interactive use - Preflight check for dotnet SDK (required by CHIT crypto) - CLAUDE.md documentation for trail signing workflow - Settings.json hook registration Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * fix(runtime): service networking, healthchecks, SQL, Makefile hardening (#740) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * fix(compose): networking, healthchecks, and env hardening - Fix external compose service networking and port bindings - Add missing healthcheck configurations to n8n compose - Update env.shared.example with new required variables - Harden docker-compose.yml service definitions Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(services): auth, healthchecks, and dependency updates - Agent Zero: Dockerfile non-root hardening, MCP server auth fixes - service_registry: improve service discovery and health reporting - evo-controller: add healthcheck endpoint and startup guards - flute-gateway: fix import path - render-webhook: update deps, add input validation - retrieval-eval: add health and metrics endpoints Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(sql): RLS policies, model registry seeds, and supabase config - Tighten RLS policies for public_init and geometry tables - Update model registry seed data with current model versions - Add studio board RLS migration for service_role access - Add supabase .gitignore and config.toml for local dev Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(tooling): Makefile targets, smoke tests, and operational scripts - Makefile: add sign-trail, volume-reset, and infra targets - smoke.ps1: expand service coverage and timeout handling - with-env.sh: support multi-tier env loading - bringup_with_ui.sh: improve startup sequencing - chit_security.py: fix HMAC signing edge cases - retro_flightcheck.py: add new validation checks - capture_evidence.sh: new script for PR evidence collection - AI_GRAPHITI_PROTOCOL.md: document agent trail protocol - pr-monitor.md: update skill command definition Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(submodules): update BoTZ-gateway and Cipher pointers Update submodule pointers to latest reviewed commits from 2026-03-01 security sweep. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs(security): 2026-03-01 submodule security reviews and agent notes - 5 submodule security reviews (Agent Zero, BoTZ, DoX, ToKenism, transcribe-and-fetch) - Security queue tracker and sitrep JSON - AGNOTE4482 FlOO$ and Flute agent notes - CHIT review-sweep skill command and post-review hook Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * docs(agents): overlay TAC model/persona readiness into graphiti protocol * docs(agents): correct TAC status wording for local staged artifacts * feat(models): reconcile model registry with Anthropic, TTS, and expanded service mappings Add Anthropic provider (claude-sonnet-4-5, claude-opus-4-5, claude-haiku-4-5) as persona backbone. Add TTS provider with 6 engines from Ultimate TTS Studio. Add 5 missing Ollama models from gpu-models.yaml (qwen3:32b, qwen3:1.7b, llama3.2:3b, codellama:7b, deepseek-coder:6.7b). Fix VRAM values to match gpu-models.yaml truth (qwen3:8b: 8000→6144, nomic-embed-text: 1000→512). Expand service-model mappings from 4 to 15+ services including hirag, archon, coding, orchestrator, vl_sentinel, tts, extract_worker, and more. Covers TAC branches B + C. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(personas): integrate 8 standard persona seeds into initdb pipeline Copy persona seeds from pmoves/db/v5_14_seed_standard_personas.sql into the active Supabase initdb pipeline as 17_persona_seed.sql. Personas reference claude-sonnet-4-5 (Developer/Creator/Analyst/Tester), claude-opus-4-5 (Researcher/Coordinator/Security), and claude-haiku-4-5 (Archivist). Sequenced after model registry (12) to ensure model_preference references are valid. Preserves ON CONFLICT (name, version) idempotency. Covers TAC branch A. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(gpu): sync gpu-models.yaml with SQL model registry Add 10 models missing from gpu-models.yaml that exist in SQL and consume local GPU VRAM: qwen2.5:32b, qwen2.5:14b, qwen2-vl:7b, qwen3-reranker:4b, nemotron-mini, llama3.1, qwen3-embedding:4b/8b, embeddinggemma:300m. GPU Orchestrator needs these entries for VRAM scheduling on RTX 5090. Covers TAC branch D. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(db): add persona-model resolution view for runtime agent identity lookup Create persona_model_resolution view joining persona → model → provider for runtime resolution of which API endpoint to call for each persona. Also adds active_persona_summary convenience view. Grants SELECT to PostgREST anon/auth roles. Covers TAC branch F. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(ops): add model-readiness check and Make target Create model_readiness_check.py that validates: - Supabase model_providers populated with ≥8 active providers - Supabase personas table populated with ≥8 rows - Ollama has expected local models pulled - TensorZero gateway operational - persona_model_resolution view returns valid data Add 'make model-readiness' target and wire into verify-all chain. Covers TAC branch E. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(db): harden model/persona seed determinism and view security * fix(ops): enforce readiness gate and close TAC doc drift * fix(a2a): harden discovery/task auth and add agent-card endpoint * fix(sql): harden studio_board RLS policy for service_role only * fix(chat-relay): lazy-load supabase client to avoid path shadow in tests * fix(ci): avoid hard failures in compose validation and yt docs tests * fix(pmoves-yt): make boto3 optional at import time for test collection * fix(pmoves-yt): stub tenacity when unavailable in CI test env * chore(submodule): bump PMOVES-Agent-Zero for canonical agent-card parity * chore(pr-scope): drop transcribe-and-fetch and cipher gitlink bumps from #744 * fix(a2a): address review blockers — RLS predicate, fail-closed key gate, discovery auth B-1: studio_board RLS policy now restricts to service_role instead of using(true) B-2: model-registry SUPABASE_SERVICE_KEY uses :? (fail-closed) instead of :- (empty) B-3: discover_agents endpoint uses _require_discovery_auth instead of _require_task_auth Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* docs(agents): expand AGNOTE4482FLUTE.md from 4-line seed The file was committed in PR #740 (Mar 1, 2026) as 3 lines of breathing/chakra/EKG/BPM/well-being-matrix scoping notes alongside 'AGNOTE4482 FlOO\$ and Flute agent notes', but never expanded into the AGNOTE-class structured runbook its name implies. This expansion preserves the original seed lines verbatim under a new \`## Seed\` blockquote and adds: - Overture interpreting the seed in plain language - Movement I: Well-Being Matrix axis (chakra ↔ HRV/BPM ↔ Hz octave), proposing a 7-band chakra extension to the existing 5-band BPM table from AGNOTE4482.BEATS.md - Movement II: 6-second breath cycle generator spec (10 BPM cadence, TTS prosodic envelope, persona_selector + prosodic + providers reuse) - Movement III: Tap-HammerOff 3-second octave-climb CGP pattern - Movement IV: existing-infrastructure inventory (bpm_encoder.py, persona_selector.py, prosodic/, providers/, CGP v0.2 skill, tokenism.prosodic.bpm.v1) - Movement V: missing nodes answering the seed's 'any other node we should pay attention to?' (chakra encoder, EKG ingest path, matrix-monitor service, cymatic visualizer hook, tap-hammeroff CGP encoder, voice-clone safety gate) - Open Questions kept live (seed's invitation preserved) - Cross-references to FLUTE_PROSODIC_ARCHITECTURE.md, BEATS spec, service tree, CGP skill No pruning — the seed grows where planted, every word kept. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(agents): address CodeRabbit review on AGNOTE4482FLUTE Three fixes for review feedback on PR #1393: 1. MD040: add `text` language tag to 3 bare fenced code blocks (BPM band table, breath cycle table, tap-hammeroff sequence) so markdownlint stays clean. 2. Movement V — Missing Nodes now opens with an explicit `**Status:** proposal` marker and cross-references the FLUTE_CHIT_GAP_2026-04-26 audit doc where each item is tracked as an issue stub. Removes implementation ambiguity. 3. New `## Open Catalog Sync` section enumerates the pending `.claude/context/nats-subjects.md` + `services-catalog.md` updates (proposed `health.ekg.bpm.v1` / `wellbeing.matrix.score.v1` subjects + Well-Being Matrix Monitor service entry). Filed as a separate scope rather than included here because `.claude/context/` is fenced by the damage-control hook — keeps the protected-path gate visible instead of bypassing it. Resolves all three CodeRabbit comments on PR #1393. The catalog-sync follow-up will land as a separate PR with explicit hook allow-list / operator confirmation as needed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Summary
6 atomic commits covering runtime service hardening from 2026-03-01 security sweep:
Test plan
make -C pmoves verify-allpasses with updated composegit diff --statshows only runtime/service files (no overlap with feat(chit): CHIT-signed Graphiti trail + skill pairing awareness #739)make -C pmoves smoke-testcovers new service endpoints🤖 Generated with Claude Code