chore: sync Hardened → main after #741-#745 merge batch - #746
Conversation
…745) * chore(submodules): bump transcribe-and-fetch and cipher for a2a auth parity * chore(submodules): bump transcribe-and-fetch and cipher to merge-ready A2A heads --------- Co-authored-by: Shaela Bello <slbello@uncg.edu>
…rd path (#744) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * fix(security): auth-gate agent-zero A2A discovery endpoint * fix(security): HMAC CHIT proofs + A2A discovery auth audit + dotnet preflight (#736) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * chore(env): require dotnet sdk in bootstrap preflight --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> * chore(deps): bump multer (#735) Bumps the npm_and_yarn group with 1 update in the /CATACLYSM_STUDIOS_INC/L4-PLATFORM/provisions/docker-stacks/jellyfin-ai/api-gateway directory: [multer](https://github.com/expressjs/multer). Updates `multer` from 2.0.2 to 2.1.0 - [Release notes](https://github.com/expressjs/multer/releases) - [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md) - [Commits](expressjs/multer@v2.0.2...v2.1.0) --- updated-dependencies: - dependency-name: multer dependency-version: 2.1.0 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(chit): correct FlOO$ PYTHONPATH for pr-monitor pipeline * feat(chit): CHIT-signed Graphiti trail + skill pairing awareness (#739) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * feat(chit): add CHIT-signed Graphiti trail tooling Add provenance signing for agent trail entries using CHIT HMAC: - sign_trail.py: CLI tool to create and sign trail entries - PostToolUse hook for automatic signing on trail file writes - /chit:sign-trail skill command for interactive use - Preflight check for dotnet SDK (required by CHIT crypto) - CLAUDE.md documentation for trail signing workflow - Settings.json hook registration Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * fix(runtime): service networking, healthchecks, SQL, Makefile hardening (#740) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * fix(compose): networking, healthchecks, and env hardening - Fix external compose service networking and port bindings - Add missing healthcheck configurations to n8n compose - Update env.shared.example with new required variables - Harden docker-compose.yml service definitions Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(services): auth, healthchecks, and dependency updates - Agent Zero: Dockerfile non-root hardening, MCP server auth fixes - service_registry: improve service discovery and health reporting - evo-controller: add healthcheck endpoint and startup guards - flute-gateway: fix import path - render-webhook: update deps, add input validation - retrieval-eval: add health and metrics endpoints Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(sql): RLS policies, model registry seeds, and supabase config - Tighten RLS policies for public_init and geometry tables - Update model registry seed data with current model versions - Add studio board RLS migration for service_role access - Add supabase .gitignore and config.toml for local dev Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(tooling): Makefile targets, smoke tests, and operational scripts - Makefile: add sign-trail, volume-reset, and infra targets - smoke.ps1: expand service coverage and timeout handling - with-env.sh: support multi-tier env loading - bringup_with_ui.sh: improve startup sequencing - chit_security.py: fix HMAC signing edge cases - retro_flightcheck.py: add new validation checks - capture_evidence.sh: new script for PR evidence collection - AI_GRAPHITI_PROTOCOL.md: document agent trail protocol - pr-monitor.md: update skill command definition Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(submodules): update BoTZ-gateway and Cipher pointers Update submodule pointers to latest reviewed commits from 2026-03-01 security sweep. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs(security): 2026-03-01 submodule security reviews and agent notes - 5 submodule security reviews (Agent Zero, BoTZ, DoX, ToKenism, transcribe-and-fetch) - Security queue tracker and sitrep JSON - AGNOTE4482 FlOO$ and Flute agent notes - CHIT review-sweep skill command and post-review hook Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * docs(agents): overlay TAC model/persona readiness into graphiti protocol * docs(agents): correct TAC status wording for local staged artifacts * feat(models): reconcile model registry with Anthropic, TTS, and expanded service mappings Add Anthropic provider (claude-sonnet-4-5, claude-opus-4-5, claude-haiku-4-5) as persona backbone. Add TTS provider with 6 engines from Ultimate TTS Studio. Add 5 missing Ollama models from gpu-models.yaml (qwen3:32b, qwen3:1.7b, llama3.2:3b, codellama:7b, deepseek-coder:6.7b). Fix VRAM values to match gpu-models.yaml truth (qwen3:8b: 8000→6144, nomic-embed-text: 1000→512). Expand service-model mappings from 4 to 15+ services including hirag, archon, coding, orchestrator, vl_sentinel, tts, extract_worker, and more. Covers TAC branches B + C. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(personas): integrate 8 standard persona seeds into initdb pipeline Copy persona seeds from pmoves/db/v5_14_seed_standard_personas.sql into the active Supabase initdb pipeline as 17_persona_seed.sql. Personas reference claude-sonnet-4-5 (Developer/Creator/Analyst/Tester), claude-opus-4-5 (Researcher/Coordinator/Security), and claude-haiku-4-5 (Archivist). Sequenced after model registry (12) to ensure model_preference references are valid. Preserves ON CONFLICT (name, version) idempotency. Covers TAC branch A. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(gpu): sync gpu-models.yaml with SQL model registry Add 10 models missing from gpu-models.yaml that exist in SQL and consume local GPU VRAM: qwen2.5:32b, qwen2.5:14b, qwen2-vl:7b, qwen3-reranker:4b, nemotron-mini, llama3.1, qwen3-embedding:4b/8b, embeddinggemma:300m. GPU Orchestrator needs these entries for VRAM scheduling on RTX 5090. Covers TAC branch D. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(db): add persona-model resolution view for runtime agent identity lookup Create persona_model_resolution view joining persona → model → provider for runtime resolution of which API endpoint to call for each persona. Also adds active_persona_summary convenience view. Grants SELECT to PostgREST anon/auth roles. Covers TAC branch F. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(ops): add model-readiness check and Make target Create model_readiness_check.py that validates: - Supabase model_providers populated with ≥8 active providers - Supabase personas table populated with ≥8 rows - Ollama has expected local models pulled - TensorZero gateway operational - persona_model_resolution view returns valid data Add 'make model-readiness' target and wire into verify-all chain. Covers TAC branch E. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(db): harden model/persona seed determinism and view security * fix(ops): enforce readiness gate and close TAC doc drift * fix(a2a): harden discovery/task auth and add agent-card endpoint * fix(sql): harden studio_board RLS policy for service_role only * fix(chat-relay): lazy-load supabase client to avoid path shadow in tests * fix(ci): avoid hard failures in compose validation and yt docs tests * fix(pmoves-yt): make boto3 optional at import time for test collection * fix(pmoves-yt): stub tenacity when unavailable in CI test env * chore(submodule): bump PMOVES-Agent-Zero for canonical agent-card parity * chore(pr-scope): drop transcribe-and-fetch and cipher gitlink bumps from #744 * fix(a2a): address review blockers — RLS predicate, fail-closed key gate, discovery auth B-1: studio_board RLS policy now restricts to service_role instead of using(true) B-2: model-registry SUPABASE_SERVICE_KEY uses :? (fail-closed) instead of :- (empty) B-3: discover_agents endpoint uses _require_discovery_auth instead of _require_task_auth Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Resolve 10 conflicts from #741-#745 merge batch: - Submodules (transcribe-and-fetch, cipher): keep main pointers - A2A server.py/test_server.py: keep Hardened (B-3 discovery auth fix) - 01_public_init.sql: keep Hardened (B-1 RLS auth.role() fix) - 12_model_registry_seed.sql: keep main (expanded registry) - Studio board RLS migration: keep main (stricter migration) - Persona model resolution migration: keep main (latest view) - model_readiness_check.py: keep main (expanded from #741) - TAC doc: keep main (Phase 1 completion updates) Security fixes from Hardened preserved, feature additions from main included. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Caution Review failedThe pull request is closed. ℹ️ Recent review infoConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro 📒 Files selected for processing (10)
📝 WalkthroughWalkthroughThis PR introduces A2A discovery authentication gating with environment-driven public/private modes, adds fallback credential resolution in Docker configuration, improves dependency handling in chat-relay and YouTube services, updates A2A documentation and database RLS policies, and updates a submodule pointer. Changes
Sequence DiagramsequenceDiagram
participant Client
participant Server as A2A Server
participant EnvConfig as Environment Config
participant Auth as JWT Validator
Client->>Server: GET /.well-known/agent-card.json
Server->>EnvConfig: Check A2A_DISCOVERY_PUBLIC
alt Public Mode Enabled
EnvConfig-->>Server: true
Server-->>Client: Return Agent Card (200)
else Public Mode Disabled
EnvConfig-->>Server: false
Server->>Server: Check Authorization header
alt Header Present
Server->>Auth: Validate JWT
alt Token Valid
Auth-->>Server: Valid
Server-->>Client: Return Agent Card (200)
else Token Invalid
Auth-->>Server: Invalid
Server-->>Client: 401 (WWW-Authenticate header)
end
else Header Missing
Server-->>Client: 401 (WWW-Authenticate header)
end
end
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Possibly related PRs
Poem
✨ Finishing Touches
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Reverse sync after PR #746 merged Hardened → main. Resolves 7 remaining conflicts (all keep main's versions for convergence). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(security): auth-gate agent-zero A2A discovery endpoint * fix(security): HMAC CHIT proofs + A2A discovery auth audit + dotnet preflight (#736) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * chore(env): require dotnet sdk in bootstrap preflight --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> * chore(deps): bump multer (#735) Bumps the npm_and_yarn group with 1 update in the /CATACLYSM_STUDIOS_INC/L4-PLATFORM/provisions/docker-stacks/jellyfin-ai/api-gateway directory: [multer](https://github.com/expressjs/multer). Updates `multer` from 2.0.2 to 2.1.0 - [Release notes](https://github.com/expressjs/multer/releases) - [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md) - [Commits](expressjs/multer@v2.0.2...v2.1.0) --- updated-dependencies: - dependency-name: multer dependency-version: 2.1.0 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(chit): correct FlOO$ PYTHONPATH for pr-monitor pipeline * feat(chit): CHIT-signed Graphiti trail + skill pairing awareness (#739) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * feat(chit): add CHIT-signed Graphiti trail tooling Add provenance signing for agent trail entries using CHIT HMAC: - sign_trail.py: CLI tool to create and sign trail entries - PostToolUse hook for automatic signing on trail file writes - /chit:sign-trail skill command for interactive use - Preflight check for dotnet SDK (required by CHIT crypto) - CLAUDE.md documentation for trail signing workflow - Settings.json hook registration Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * fix(runtime): service networking, healthchecks, SQL, Makefile hardening (#740) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * fix(compose): networking, healthchecks, and env hardening - Fix external compose service networking and port bindings - Add missing healthcheck configurations to n8n compose - Update env.shared.example with new required variables - Harden docker-compose.yml service definitions Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(services): auth, healthchecks, and dependency updates - Agent Zero: Dockerfile non-root hardening, MCP server auth fixes - service_registry: improve service discovery and health reporting - evo-controller: add healthcheck endpoint and startup guards - flute-gateway: fix import path - render-webhook: update deps, add input validation - retrieval-eval: add health and metrics endpoints Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(sql): RLS policies, model registry seeds, and supabase config - Tighten RLS policies for public_init and geometry tables - Update model registry seed data with current model versions - Add studio board RLS migration for service_role access - Add supabase .gitignore and config.toml for local dev Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(tooling): Makefile targets, smoke tests, and operational scripts - Makefile: add sign-trail, volume-reset, and infra targets - smoke.ps1: expand service coverage and timeout handling - with-env.sh: support multi-tier env loading - bringup_with_ui.sh: improve startup sequencing - chit_security.py: fix HMAC signing edge cases - retro_flightcheck.py: add new validation checks - capture_evidence.sh: new script for PR evidence collection - AI_GRAPHITI_PROTOCOL.md: document agent trail protocol - pr-monitor.md: update skill command definition Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(submodules): update BoTZ-gateway and Cipher pointers Update submodule pointers to latest reviewed commits from 2026-03-01 security sweep. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs(security): 2026-03-01 submodule security reviews and agent notes - 5 submodule security reviews (Agent Zero, BoTZ, DoX, ToKenism, transcribe-and-fetch) - Security queue tracker and sitrep JSON - AGNOTE4482 FlOO$ and Flute agent notes - CHIT review-sweep skill command and post-review hook Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * chore: add gitignore for runtime data and DAO docs (#743) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * chore: add gitignore for runtime data, DAO docs, and env backups Add entries to prevent accidental commits of: - pmoves/jellyfin-ai/ (runtime config/data from Jellyfin AI stack) - pmoves/pmoves/PR_EVIDENCE/ (smoke test evidence artifacts) - pmoves/docs/logs/pr_monitor_* (runtime PR monitor logs) - CATACLYSM_STUDIOS_INC/PMOVES DAO/ (managed separately) - pmoves/env.jellyfin-ai, pmoves/env.supa.runtime.bak.* (env backups) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * feat(models): model registry reconciliation + persona seeds + readiness check (#741) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * docs(agents): overlay TAC model/persona readiness into graphiti protocol * docs(agents): correct TAC status wording for local staged artifacts * feat(models): reconcile model registry with Anthropic, TTS, and expanded service mappings Add Anthropic provider (claude-sonnet-4-5, claude-opus-4-5, claude-haiku-4-5) as persona backbone. Add TTS provider with 6 engines from Ultimate TTS Studio. Add 5 missing Ollama models from gpu-models.yaml (qwen3:32b, qwen3:1.7b, llama3.2:3b, codellama:7b, deepseek-coder:6.7b). Fix VRAM values to match gpu-models.yaml truth (qwen3:8b: 8000→6144, nomic-embed-text: 1000→512). Expand service-model mappings from 4 to 15+ services including hirag, archon, coding, orchestrator, vl_sentinel, tts, extract_worker, and more. Covers TAC branches B + C. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(personas): integrate 8 standard persona seeds into initdb pipeline Copy persona seeds from pmoves/db/v5_14_seed_standard_personas.sql into the active Supabase initdb pipeline as 17_persona_seed.sql. Personas reference claude-sonnet-4-5 (Developer/Creator/Analyst/Tester), claude-opus-4-5 (Researcher/Coordinator/Security), and claude-haiku-4-5 (Archivist). Sequenced after model registry (12) to ensure model_preference references are valid. Preserves ON CONFLICT (name, version) idempotency. Covers TAC branch A. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(gpu): sync gpu-models.yaml with SQL model registry Add 10 models missing from gpu-models.yaml that exist in SQL and consume local GPU VRAM: qwen2.5:32b, qwen2.5:14b, qwen2-vl:7b, qwen3-reranker:4b, nemotron-mini, llama3.1, qwen3-embedding:4b/8b, embeddinggemma:300m. GPU Orchestrator needs these entries for VRAM scheduling on RTX 5090. Covers TAC branch D. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(db): add persona-model resolution view for runtime agent identity lookup Create persona_model_resolution view joining persona → model → provider for runtime resolution of which API endpoint to call for each persona. Also adds active_persona_summary convenience view. Grants SELECT to PostgREST anon/auth roles. Covers TAC branch F. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(ops): add model-readiness check and Make target Create model_readiness_check.py that validates: - Supabase model_providers populated with ≥8 active providers - Supabase personas table populated with ≥8 rows - Ollama has expected local models pulled - TensorZero gateway operational - persona_model_resolution view returns valid data Add 'make model-readiness' target and wire into verify-all chain. Covers TAC branch E. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(db): harden model/persona seed determinism and view security * fix(ops): enforce readiness gate and close TAC doc drift * fix(sql): harden studio_board RLS policy for service_role only * fix(db): reconcile model provider upserts and enforce studio policy replacement - update model_providers upserts to refresh mutable fields (type/api_base/api_key_env_var/description/active/metadata)\n- always replace studio_board_service_role_all policy in migration for upgrade parity\n- clarify persona resolution grant comment to match PostgREST role grants\n- add readiness-check type hints/constants and align TAC verify steps * fix(security): tighten studio_board revokes and TensorZero reachability checks * fix(readiness): enforce registry thresholds and harden studio_board revokes --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * docs(agents): comprehensive AGENTS directory review and cross-reference fixes (#742) * docs(agents): update gap analysis with Phase 1 completions - Mark Phase 1 roadmap items as complete (model registry, persona seeds, GPU models YAML, service-model mappings) - Update CHIT integration status from None to Partial - Add A2A MCP foundation status - Update security hooks as implemented - Refresh date to 2026-03-01 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs(agents): add cross-references between operator docs - AGENT_CONTEXT_PATTERNS: add hook portability warning for Windows - CODEX_CIPHER_MEMORY: add cipher categories table for quick reference - CODEX_OPERATOR_HOME: add known gaps link to gap analysis - CODEX_RUNTIME_PROTOCOL: add Codex-Claude collision handling section Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs(agents): create README.md index for 69-file directory Add a start-here index document that catalogs all 69 files in the AGENTS directory with descriptions and category groupings. Provides newcomers a navigation map for the agent documentation corpus. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs(agents): add concrete persona seed examples to PERSONAS.md - Add 4 worked examples (Developer, Creator, Researcher, Analyst) showing model_preference, chit_attribution, and tool_allowlist - Document persona inheritance chain (seed SQL → Supabase row → agent_registry.yaml → runtime resolution view) - Add CHIT attribution configuration section - Add quick reference summary table for all 8 standard personas - Cross-reference 17_persona_seed.sql from PR #741 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(registry): complete CHIT toggle coverage and Hi-RAG port split - Add chit_toggles (encode, sign, bus_emit) to 9 infrastructure agents: nats-init, supabase-db, minio, qdrant, meilisearch, neo4j, prometheus, grafana, loki (all disabled — infra agents don't produce CHIT events) - Add gpu_port: 8087 to hi-rag-gateway for v1/v2 port split - Achieves 60/60 CHIT toggle coverage across all registered agents Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs(agents): update SUBMODULE_CODEX_HOMES naming convention docs - Document naming conventions for codex home files - Add orphan tracking guidance for unmapped submodules - Expand directory structure examples Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs(agents): align persona status, topology ports, and gap metadata --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * chore: sync Hardened → main after #741-#745 merge batch (#746) * chore(submodules): bump transcribe-and-fetch + cipher for A2A parity (#745) * chore(submodules): bump transcribe-and-fetch and cipher for a2a auth parity * chore(submodules): bump transcribe-and-fetch and cipher to merge-ready A2A heads --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> * fix(a2a): secure discovery/task APIs and align with upstream agent-card path (#744) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * fix(security): auth-gate agent-zero A2A discovery endpoint * fix(security): HMAC CHIT proofs + A2A discovery auth audit + dotnet preflight (#736) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * chore(env): require dotnet sdk in bootstrap preflight --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> * chore(deps): bump multer (#735) Bumps the npm_and_yarn group with 1 update in the /CATACLYSM_STUDIOS_INC/L4-PLATFORM/provisions/docker-stacks/jellyfin-ai/api-gateway directory: [multer](https://github.com/expressjs/multer). Updates `multer` from 2.0.2 to 2.1.0 - [Release notes](https://github.com/expressjs/multer/releases) - [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md) - [Commits](expressjs/multer@v2.0.2...v2.1.0) --- updated-dependencies: - dependency-name: multer dependency-version: 2.1.0 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(chit): correct FlOO$ PYTHONPATH for pr-monitor pipeline * feat(chit): CHIT-signed Graphiti trail + skill pairing awareness (#739) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * feat(chit): add CHIT-signed Graphiti trail tooling Add provenance signing for agent trail entries using CHIT HMAC: - sign_trail.py: CLI tool to create and sign trail entries - PostToolUse hook for automatic signing on trail file writes - /chit:sign-trail skill command for interactive use - Preflight check for dotnet SDK (required by CHIT crypto) - CLAUDE.md documentation for trail signing workflow - Settings.json hook registration Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * fix(runtime): service networking, healthchecks, SQL, Makefile hardening (#740) * fix(security): use HMAC for CHIT proofs * docs(security): add A2A discovery auth sweep findings * fix(security): update submodule pointers to 2026-03-01 review fix branches Update gitlink pointers for 5 submodules to their security fix branches: - BoTZ: auth-gate /.well-known/agent.json (PR #70) - ToKenism-Multi: all P1/P2 cred defaults fixed (PR #46) - Agent-Zero: path containment + supervisord users (PR #8) - transcribe-and-fetch: openai v2 alignment + doc scrub (PR #44) - DoX: secrets externalized + honest 501 (PR #114) Also update review status doc with fix verification. All 7 P1 and 20 P2 findings resolved. 4 dependabot PRs merged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore(env): require dotnet sdk in bootstrap preflight * fix(compose): networking, healthchecks, and env hardening - Fix external compose service networking and port bindings - Add missing healthcheck configurations to n8n compose - Update env.shared.example with new required variables - Harden docker-compose.yml service definitions Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(services): auth, healthchecks, and dependency updates - Agent Zero: Dockerfile non-root hardening, MCP server auth fixes - service_registry: improve service discovery and health reporting - evo-controller: add healthcheck endpoint and startup guards - flute-gateway: fix import path - render-webhook: update deps, add input validation - retrieval-eval: add health and metrics endpoints Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(sql): RLS policies, model registry seeds, and supabase config - Tighten RLS policies for public_init and geometry tables - Update model registry seed data with current model versions - Add studio board RLS migration for service_role access - Add supabase .gitignore and config.toml for local dev Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(tooling): Makefile targets, smoke tests, and operational scripts - Makefile: add sign-trail, volume-reset, and infra targets - smoke.ps1: expand service coverage and timeout handling - with-env.sh: support multi-tier env loading - bringup_with_ui.sh: improve startup sequencing - chit_security.py: fix HMAC signing edge cases - retro_flightcheck.py: add new validation checks - capture_evidence.sh: new script for PR evidence collection - AI_GRAPHITI_PROTOCOL.md: document agent trail protocol - pr-monitor.md: update skill command definition Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(submodules): update BoTZ-gateway and Cipher pointers Update submodule pointers to latest reviewed commits from 2026-03-01 security sweep. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs(security): 2026-03-01 submodule security reviews and agent notes - 5 submodule security reviews (Agent Zero, BoTZ, DoX, ToKenism, transcribe-and-fetch) - Security queue tracker and sitrep JSON - AGNOTE4482 FlOO$ and Flute agent notes - CHIT review-sweep skill command and post-review hook Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * docs(agents): overlay TAC model/persona readiness into graphiti protocol * docs(agents): correct TAC status wording for local staged artifacts * feat(models): reconcile model registry with Anthropic, TTS, and expanded service mappings Add Anthropic provider (claude-sonnet-4-5, claude-opus-4-5, claude-haiku-4-5) as persona backbone. Add TTS provider with 6 engines from Ultimate TTS Studio. Add 5 missing Ollama models from gpu-models.yaml (qwen3:32b, qwen3:1.7b, llama3.2:3b, codellama:7b, deepseek-coder:6.7b). Fix VRAM values to match gpu-models.yaml truth (qwen3:8b: 8000→6144, nomic-embed-text: 1000→512). Expand service-model mappings from 4 to 15+ services including hirag, archon, coding, orchestrator, vl_sentinel, tts, extract_worker, and more. Covers TAC branches B + C. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(personas): integrate 8 standard persona seeds into initdb pipeline Copy persona seeds from pmoves/db/v5_14_seed_standard_personas.sql into the active Supabase initdb pipeline as 17_persona_seed.sql. Personas reference claude-sonnet-4-5 (Developer/Creator/Analyst/Tester), claude-opus-4-5 (Researcher/Coordinator/Security), and claude-haiku-4-5 (Archivist). Sequenced after model registry (12) to ensure model_preference references are valid. Preserves ON CONFLICT (name, version) idempotency. Covers TAC branch A. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(gpu): sync gpu-models.yaml with SQL model registry Add 10 models missing from gpu-models.yaml that exist in SQL and consume local GPU VRAM: qwen2.5:32b, qwen2.5:14b, qwen2-vl:7b, qwen3-reranker:4b, nemotron-mini, llama3.1, qwen3-embedding:4b/8b, embeddinggemma:300m. GPU Orchestrator needs these entries for VRAM scheduling on RTX 5090. Covers TAC branch D. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(db): add persona-model resolution view for runtime agent identity lookup Create persona_model_resolution view joining persona → model → provider for runtime resolution of which API endpoint to call for each persona. Also adds active_persona_summary convenience view. Grants SELECT to PostgREST anon/auth roles. Covers TAC branch F. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(ops): add model-readiness check and Make target Create model_readiness_check.py that validates: - Supabase model_providers populated with ≥8 active providers - Supabase personas table populated with ≥8 rows - Ollama has expected local models pulled - TensorZero gateway operational - persona_model_resolution view returns valid data Add 'make model-readiness' target and wire into verify-all chain. Covers TAC branch E. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(db): harden model/persona seed determinism and view security * fix(ops): enforce readiness gate and close TAC doc drift * fix(a2a): harden discovery/task auth and add agent-card endpoint * fix(sql): harden studio_board RLS policy for service_role only * fix(chat-relay): lazy-load supabase client to avoid path shadow in tests * fix(ci): avoid hard failures in compose validation and yt docs tests * fix(pmoves-yt): make boto3 optional at import time for test collection * fix(pmoves-yt): stub tenacity when unavailable in CI test env * chore(submodule): bump PMOVES-Agent-Zero for canonical agent-card parity * chore(pr-scope): drop transcribe-and-fetch and cipher gitlink bumps from #744 * fix(a2a): address review blockers — RLS predicate, fail-closed key gate, discovery auth B-1: studio_board RLS policy now restricts to service_role instead of using(true) B-2: model-registry SUPABASE_SERVICE_KEY uses :? (fail-closed) instead of :- (empty) B-3: discover_agents endpoint uses _require_discovery_auth instead of _require_task_auth Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Shaela Bello <slbello@uncg.edu> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Summary
PMOVES.AI-Edition-Hardened→mainafter merging PRs feat(models): model registry reconciliation + persona seeds + readiness check #741–chore(submodules): bump transcribe-and-fetch + cipher for A2A parity #745Conflict Resolution Strategy
PMOVES-transcribe-and-fetchPmoves-cipherserver.py(A2A)test_server.py(A2A)01_public_init.sqlauth.role()fix12_model_registry_seed.sqlstudio_board_rlsmigrationpersona_model_resolutionmigrationmodel_readiness_check.pyTAC_MODEL_INFRA...mdTest plan
auth.role() = 'service_role'RLS🤖 Generated with Claude Code
Summary by CodeRabbit
New Features
Documentation
Chores