Skip to content

fix: A1 支援已下載 MinIO IFC 直接檢核 - #316

Merged
monkey1sai merged 2 commits into
mainfrom
fix/a1-minio-downloaded-rule-run
Jul 8, 2026
Merged

monkey1sai merged 2 commits into
mainfrom
fix/a1-minio-downloaded-rule-run

Conversation

@monkey1sai

@monkey1sai monkey1sai commented Jul 8, 2026 •

Copy link
Copy Markdown
Owner

摘要

  • 修正 A1 選擇 MinIO source_ifc 已下載、但尚未建立 review_session 時被卡在轉檔排程/Review Room 的問題。
  • 新增 coordinator POST /api/governance/rule-runs/for-ifc-ready/:jobId,由 server-side IFC-ready store 解析本機 IFC path,再轉送 governance-service;瀏覽器不送 MinIO key 或 host path。
  • A1 前端在 no-session downloaded job 會鎖定 ifc-ready://<jobId> 並呼叫 createRuleRunForIfcReady;session-backed job 仍走既有 /for-session/:sessionId。
  • 修掉 reviewer 找到的 P2:鎖定 ifc-ready:// 後手動選 session,不得把 run 靜默改派到不相干的 review session。

Formal Spec Evidence

  • docs/superpowers/specs/2026-07-08-a1-minio-downloaded-rule-run-design.md records the documented exception/design evidence for this behavior and repo-boundary change.

風險與邊界

  • GitNexus detect-changes --scope staged --repo AI-BIM-governance:high risk,7 files / 21 symbols / 6 affected flows;範圍符合 coordinator governance proxy + A1 console route 的預期。
  • 新 route 是 operator-console/local boundary:ifc_ready_job_id 不是 auth token;若未來要放到 multi-tenant/public endpoint,需先加 coordinator user/tenant auth。
  • 本 PR 只宣告 A1 CPU rule-run path;未宣告 full Kit/WebRTC visual E2E 或部署區重建完成。

驗證

  • cd bim-review-coordinator && npm run verify:53 files / 591 tests passed。
  • cd web-viewer-sample && npm run verify:build passed;50 files / 558 tests passed;struct-log 10 tests passed。Vite chunk-size warning 與既有 React act / stream-controller 測試警告未造成失敗。
  • cd web-viewer-sample && npm run test:session-first:passed。
  • cd web-viewer-sample && npx playwright test e2e/a1-minio-local-resolution.spec.ts --reporter=list with repo-local Vite server + E2E_DISABLE_WEBSERVER=1:2 passed。
  • git diff --check、git diff --cached --check:passed。

Frontend Verification

Field Evidence
Frontend route /#a1 via web-viewer-sample Vite on http://127.0.0.1:5180/#a1
Main button(s) tested a1-source-minio, a1-minio-select, a1-step-pick, a1-step-run
Fixture used Playwright mocked MinIO source_ifc key 松風庵/root/main/u1/model.ifc; IFC-ready job ifcready_no_session with download_status=downloaded, review_session_id=null, artifact_health.source_ifc_exists=true
Visible success state A1 resolution note shows coordinator ifc-ready proxy; run button posts /api/governance/rule-runs/for-ifc-ready/:jobId; scoreboard a1-rulerun-scoreboard becomes visible
E2E command cd web-viewer-sample && E2E_DISABLE_WEBSERVER=1 npx playwright test e2e/a1-minio-local-resolution.spec.ts --reporter=list after starting repo-local Vite on 127.0.0.1:5180
Screenshot / trace artifacts/e2e/a1-minio-local-resolution-no-session.png; also covers existing session path screenshot artifacts/e2e/a1-minio-local-resolution.png
Known gaps Browser E2E uses mocked coordinator/governance API responses; live MinIO + Kit/WebRTC full-system deploy verification is not claimed by this PR

Copilot AI review requested due to automatic review settings July 8, 2026 10:25
@coderabbitai

coderabbitai Bot commented Jul 8, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR adds a coordinator-side resolver (resolveDownloadedJobForRuleRun) and a new /api/governance/rule-runs/for-ifc-ready/:jobId proxy endpoint for triggering governance rule-runs on downloaded IFC-ready jobs without a review session, plus corresponding web-viewer client method, UI routing, and tests.

Changes

IFC-ready governance rule-run proxy

Layer / File(s) Summary
Shared IFC-ready job resolver
bim-review-coordinator/src/app.ts
Adds resolveDownloadedJobForRuleRun to validate download status and IFC path, makes markSourceIfcUnavailable accept a nullable session, and wires session/ifc-ready resolvers to the shared helper.
New for-ifc-ready proxy route
bim-review-coordinator/src/routes/governanceProxy.ts
Adds RuleRunSourceContext type, extends GovernanceProxyDeps, adds forwardResolvedRuleRun helper, and introduces the /for-ifc-ready/:jobId endpoint alongside the refactored for-session endpoint.
Backend endpoint tests
bim-review-coordinator/tests/governance-rule-run-for-session.test.ts
Adds helpers and a test suite covering invalid job id, successful forwarding, download-failed 404, and stale-artifact 409 with path-leakage checks.
Web-viewer client and A1 workbench routing
web-viewer-sample/src/console/governanceClient.ts, web-viewer-sample/src/console/pages.tsx
Adds createRuleRunForIfcReady client method and updates A1 run/picker logic to route ifc-ready:// inputs through the new proxy with updated readiness gating and button captions.
Frontend tests
web-viewer-sample/src/console/A1ViewerEmbed.test.tsx, web-viewer-sample/e2e/a1-minio-local-resolution.spec.ts
Updates unit and e2e tests to assert createRuleRunForIfcReady usage for no-session downloaded jobs and verifies the for-ifc-ready routing scenario.

Estimated code review effort: 4 (Complex) | ~60 minutes

Sequence Diagram(s)

sequenceDiagram
  participant User
  participant A1GovernanceWorkbenchPage
  participant governanceClient
  participant GovernanceProxy
  participant GovernanceService

  User->>A1GovernanceWorkbenchPage: Click Pick (no session match)
  A1GovernanceWorkbenchPage->>A1GovernanceWorkbenchPage: dispatch PICK_FILE ifc-ready://jobId
  User->>A1GovernanceWorkbenchPage: Click Run Rule Validation
  A1GovernanceWorkbenchPage->>governanceClient: createRuleRunForIfcReady(ifcReadyJobId, body)
  governanceClient->>GovernanceProxy: POST /api/governance/rule-runs/for-ifc-ready/:jobId
  GovernanceProxy->>GovernanceProxy: resolveDownloadedJobForRuleRun(jobId)
  alt job downloaded and IFC path fresh
    GovernanceProxy->>GovernanceService: POST /api/rule-runs (ifc_source_path, model_version_id)
    GovernanceService-->>GovernanceProxy: rule_run_id, status
    GovernanceProxy-->>governanceClient: 200 response
  else missing or stale
    GovernanceProxy-->>governanceClient: 404/409 with artifact_health
  end
  governanceClient-->>A1GovernanceWorkbenchPage: response
Loading

Possibly related PRs

  • monkey1sai/AI-BIM-governance#291: Both update the same A1 governance workflow and tests to remove mandatory session selection and route rule-runs without requiring a review session.
  • monkey1sai/AI-BIM-governance#305: Both build on the downloaded-job resolution/routing contract for governance rule-runs, with this PR adding the no-session for-ifc-ready path.
  • monkey1sai/AI-BIM-governance#313: Both touch checkSourceIfcPath and the source-IFC staleness logic that resolveDownloadedJobForRuleRun and markSourceIfcUnavailable depend on.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: A1 now supports direct validation of already-downloaded MinIO IFC files.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/a1-minio-downloaded-rule-run

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

PR Review Agent Summary

Field Value
Status blocked
Risk high
PR 316
Head fix/a1-minio-downloaded-rule-run / 63b55b22b1793ca50fb7205d8f0f7d9f3efd9e94
Base main / ec7c2ea504320eb097cb9db81e12358780c73912

Blockers

  • [high] Behavior, workflow, code, or repo-boundary changes require an OpenSpec change id or documented exception.

Warnings

  • [medium] GitNexus detect changes did not pass: warning.

Validation Commands

  • npm run verify
  • npm run verify

Checks

  • passed bim-review-coordinator verify (bim-review-coordinator)
  • passed web-viewer-sample verify (web-viewer-sample)

Human Review Notes

  • Optional AI adapter is not required by policy and was skipped.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 63b55b22b1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +517 to +520
const { rule_run_id } = ifcReadyJobId
? await governanceClient.createRuleRunForIfcReady(ifcReadyJobId, { ids_path: idsPath || undefined })
: selectedSession
? await governanceClient.createRuleRunForSession(selectedSession, { ids_path: idsPath || undefined })

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Clear unrelated sessions for ifc-ready runs

When a no-session MinIO job is locked (state.ifcPath is ifc-ready://...) and the operator later picks any review session from the panel, this new branch correctly dispatches the rule-run through for-ifc-ready but leaves selectedSession populated. The rest of doRun still uses selectedSession for mapping enrichment, and the deliverables section uses it for Review Room handoff, so failures from the no-session IFC can be enriched/opened against an unrelated session. Please gate or clear selectedSession for ifc-ready:// runs, or validate that the selected session matches the job before using it downstream.

Useful? React with 👍 / 👎.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR closes a gap in the A1 governance workbench: when a MinIO source_ifc object has already been downloaded by the watcher but no review_session exists yet, A1 was previously blocked (the operator was told to go create a session via the IFC→USD schedule / Review Room). The change lets A1 run a CPU rule-run directly against the server-resolved local IFC path in that no-session state, while keeping the security boundary intact (the browser never sends a MinIO key or host path — it sends only the ifc_ready_job_id and the coordinator resolves the path server-side).

Changes:

  • Adds coordinator route POST /api/governance/rule-runs/for-ifc-ready/:jobId, backed by a shared resolveDownloadedJobForRuleRun helper (refactored out of the existing for-session resolver) and guarded by isSafeIfcReadyJobId. markSourceIfcUnavailable now accepts a null session.
  • A1 frontend locks ifc-ready://<jobId> for downloaded/no-session jobs and calls the new createRuleRunForIfcReady; session-backed jobs keep the existing for-session path. Also fixes the reviewer-found P2: a locked ifc-ready:// source is no longer silently rerouted through a manually selected session.
  • Adds coordinator, component, and Playwright E2E tests covering the no-session happy path, invalid job id (400), failed download (404), stale artifact (409), and the P2 non-rerouting guard.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated no comments.

Show a summary per file
File Description
bim-review-coordinator/src/routes/governanceProxy.ts Adds the for-ifc-ready/:jobId route + shared forwardResolvedRuleRun; generalizes RuleRunSessionContext→RuleRunSourceContext (alias kept).
bim-review-coordinator/src/app.ts Extracts resolveDownloadedJobForRuleRun, wires the ifc-ready resolver, and makes markSourceIfcUnavailable session-optional.
web-viewer-sample/src/console/pages.tsx Routes no-session downloaded jobs through ifc-ready://, updates pick/run gating and resolution notes.
web-viewer-sample/src/console/governanceClient.ts Adds createRuleRunForIfcReady client method.
web-viewer-sample/src/console/A1ViewerEmbed.test.tsx Replaces the "stays blocked" test with ifc-ready-proxy + P2 non-rerouting coverage.
web-viewer-sample/e2e/a1-minio-local-resolution.spec.ts Adds an E2E scenario for the no-session ifc-ready rule-run.
bim-review-coordinator/tests/governance-rule-run-for-session.test.ts Adds coordinator tests for the new route (400/404/409/happy path).

I reviewed the resolver refactor for behavioral parity on the for-session path (the added download_status === "downloaded" gate and reason-string change are covered by existing tests), verified the frontend staleness guard preserves the session semantics while adding the ifc_ready_job_id match, and confirmed the new route reuses isSafeIfcReadyJobId and the stable stale_session_artifact error contract. No blocking code defects were found.

This PR does, however, modify the coordinator's session→IFC resolution and proxy boundary — a security- and correctness-sensitive path — adds a new browser-visible route (the author correctly notes ifc_ready_job_id is not an auth token), and touches bim-review-coordinator/src/app.ts and src/routes/governanceProxy.ts, which are enumerated in the repo's documented backend-freeze list and carry the author's own high-risk impact analysis. These warrant human confirmation.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@github-actions

github-actions Bot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

PR Review Agent Summary

Field Value
Status warning
Risk medium
PR 316
Head fix/a1-minio-downloaded-rule-run / 4f7e4680692096ba21771269f4be1805c395ba14
Base main / ec7c2ea504320eb097cb9db81e12358780c73912

Blockers

  • None

Warnings

  • [medium] GitNexus detect changes did not pass: warning.

Validation Commands

  • npm run verify
  • npm run verify

Checks

  • passed bim-review-coordinator verify (bim-review-coordinator)
  • passed web-viewer-sample verify (web-viewer-sample)

Human Review Notes

  • OpenSpec archive or formal spec evidence detected; active change-id validation was skipped.
  • Optional AI adapter is not required by policy and was skipped.

@monkey1sai
monkey1sai merged commit c8d11ff into main Jul 8, 2026
12 checks passed
@monkey1sai
monkey1sai deleted the fix/a1-minio-downloaded-rule-run branch July 8, 2026 10:39

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4f7e468069

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

? state.ifcPath.slice("ifc-ready://".length)
: "";
const { rule_run_id } = ifcReadyJobId
? await governanceClient.createRuleRunForIfcReady(ifcReadyJobId, { ids_path: idsPath || undefined })

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Isolate ifc-ready runs from selected sessions

Fresh evidence in this revision is that the new ifcReadyJobId branch only protects the initial rule-run POST: after locking a no-session ifc-ready:// job, the operator can still manually select any review session, and the success path continues to use selectedSession for elementMappingForSession and Review Room handoff. In that scenario, failed GUIDs from the no-session IFC can be enriched or opened against an unrelated session even though the run itself correctly went through /for-ifc-ready/:jobId; please clear or ignore selectedSession for ifc-ready:// runs unless it is proven to belong to the job.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants