- add one inline deterministic MCP task and sealed planning assets
- reseal S2_00/S2_10 release hashes for the S2_20 handoff
- keep live and legal admission explicitly pending
Replace the unresolved host-loader invocation with one hash-bound Code Executor task so deterministic ingress has a concrete Agent execution path.\n\nBREAKING CHANGE: S2_00 no longer invokes stage2_loader.py. The legacy loader binding is reference-only and cannot authorize or provide fallback.
- stage_1_part_2_v.8.yml (195,963 B, sha16 ec407309a5ab43f4): drop two
dead R0 path constants (S0's own copies untouched); narrow the
legacy_paths_forbidden header comment to old slice/seed paths and
state that stage_a_context/source_universe/postb_* keep
stage1_tmp/task_c_bo as canonical. R0 fragment synced; prior
versions preserved under outdated/ (pre_asset_triage_fix)
- Default_Agent/runtime_manifest.json 426->432: register six unanchored
Part 1 assets (component union, client_goal schema, two reference
catalogs, determinism contract, activation cue digest) with
runtime_artifact_count updated and round-trip serialization kept
- remove case_kind_domain_matrix.v2.json from deployment origin
(byte-identical master kept in assembly tree; empty folders pruned);
tree 210->209, listed∩tree 155 with zero hash mismatches
- stage_1_2_3_assets_distribution_location.md rewritten as the
Default_Agent change record only; full survey kept as *_old.md
- Part 1|2 analysis doc: 10 targeted updates (sizes/sha, shifted line
ranges A0 62-719 / B 720-849 / R0 850-1793, constant wording removed,
§8 history row annotated with a dated note instead of rewriting)
- verified: 3-pass dry run PASS with BO.json and
legal_effect_structures.json byte-identical to the previous round;
adversarial sub-agent check 29 items, findings 1 -> 0
- v.7/MEMORY.md entry 26
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- stage_1_part_3_updated_yaml_analysis.md (41,948 B): full analysis of
stage_1_part_3_v.8.yml — DAG, per-task IO with formats, asset deploy
locations (.py/.txt mirrors included), sub-task purposes, upstream/
downstream contracts; verified by sub-agent loop 6->1->0 findings
(all MINOR; diagram order corrected to code-measured sequence)
- problems_identified_in_detecting_assets_location_v.2.md: re-verified
all 8 items of the distribution survey §8 plus the 277-row manifest
gap (1st-pass measurement + one independent sub-agent recheck, 9/9
agreed). Two v.1 verdicts overturned with evidence: 277-file copy
recommendation rejected (superset-ledger design documented in 4 docs;
no gate scans those paths) and P3 header L24 "corruption" disproven
via creation-commit byte identity. Confirmed problems: R0 dead
constants, legacy_paths comment, 6 unanchored P1 assets (register
rows directly in deployment-origin manifest, count field updated),
plaintext Bearer token (rotation is the real fix — 402 files carry it;
SKILL.md has no secret-injection syntax)
- includes source docs from survey round: stage_1_2_3_assets_
distribution_location.md, problems_identified_...(v.1)
- v.7/MEMORY.md entries 24-25; session prompt log update
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The backend now has a global AuthGateMiddleware: every data route
(workspaces/lookup, upload-agent, sse/...) requires auth, returning
401 {"detail":"authentication required"} otherwise. CI authenticates with
the service token via the X-Admin-Token header (proxies any user_id).
- run_agent_api.py: read ADMIN_API_TOKEN from env, attach X-Admin-Token to
both httpx clients (all lookup/upload/sse/action/cancel calls); warn if unset
- run-agent.yml: inject ADMIN_API_TOKEN from Gitea repo secret
- Gitea repo secret ADMIN_API_TOKEN registered
- TEST_WORKFLOW.md / .env.example: document ADMIN_API_TOKEN (.env local, secret in CI)
Verified end-to-end: workspaces/lookup for user_id=jhogyu now resolves
(401 -> 200), e.g. Aug_2026_Test -> 3523fa2b-...
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The Claude Part_2 domain workers (Stage_B_B1..B5) had use_tools: [] and
relied entirely on preflight injecting stage1_tmp/task_c_bo/domain_slices/
B{n}.json. In the failing run the executed A0 wrote full-name slices
(B1_Money_Successor.json ...) while preflight expected short names
(B1.json), so nothing was injected and the tool-less workers emitted
tool-call syntax as plain text (<mcp_tool_call>/<function=read_file>) and
produced FAILED/empty output.
The current v.7 A0 already writes short names matching preflight, so the
naming mismatch itself is resolved in this file. This change adds
use_tools: ['localdocs'] (already declared on the stage) so the workers can
read their slice directly if preflight ever misses again — matching the
proven Codex worker design and removing the single point of failure.
Note: domain slices are 255-300KB (~65-90K tokens); llm_bridge caps tool/
injected content at 50K tokens, so slice compaction in A0 is still needed
for full-fidelity output quality.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Task_C_BO_R0_seed_reducer_exception_planner raised RuntimeError (exit 1)
whenever status became BLOCKED, and BLOCKED was triggered by validation
findings that are inherently fragile because they require an LLM (Stage B
workers) to echo values verbatim or stay perfectly in scope:
- slice_digest_sha256 echo mismatch (all 5 domains)
- run_fingerprint echo mismatch
- source meeting-clause refs outside slice/global (B5, 42 findings)
A decrypted postb_seed_ledger.json from the 2026-07-20 run confirmed all
47 blocking failures came from exactly these three check classes (no BLOCK
severity reviews / no budget overflow). Downgrade them from fatal
`failures` to non-fatal `reviews` (candidates preserved, routed to human
review). Genuine contract violations (schema/domain mismatch, worker
FAILED, candidate_ref sequence, forbidden keys, invalid enum) and the
deterministic A0-artifact integrity raises are kept fatal.
Gate simulation on the confirmed inputs: BLOCKED/exit-1 -> READY_WITH_REVIEW,
fan-out restored so R1 exception adjudication can run.
Note: this unblocks the pipeline and flags the issues; the upstream root
cause (Stage B tool-content truncated 66-78K -> 50K tokens) still needs a
slice-compaction fix for output quality.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
user_id is now a required workflow_dispatch input (no default) and the
runner validates it is non-empty before doing anything. Removed the
'jsahn' default from the script arg and replaced jsahn with <user_id>
placeholders throughout TEST_WORKFLOW.md so the workflow is not pinned
to one account.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- Created new files for Stage 1 evaluation and revision strategy based on GPT and Claude recommendations.
- Added detailed revision plans addressing runtime issues in LES2 and optimizing workflows for Stage 2.
- Updated existing Stage 1 to Stage 2 transition prompts with additional search results and completion indicators.
- Enhanced clarity and structure in the documentation for better usability and understanding.
- Documented the workflow for running Agent YAML using Gitea Actions.
- Included setup instructions for .env file with Gitea token.
- Provided three methods for triggering the workflow: via Gitea API, Gitea web UI, and local script execution.
- Added workflow input reference and prerequisites for server infrastructure.
- Included troubleshooting section for common issues encountered during execution.
Add workspace_name input; the runner resolves it to a workspace_id through
GET {api_base}/workspaces/lookup?user_id=... before uploading the agent.
workspace_id remains as an explicit override. Name matching is NFC-normalized
(handles Korean NFD/NFC) with a case-insensitive fallback, and a no-match
error lists the available workspace names. Requires one of name/id.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Gitea Actions only supports the v3 artifact protocol; upload-artifact@v4
uses the @actions/artifact v2 API which Gitea (identifying as GHES) rejects
with GHESNotSupportedError. The agent run step itself succeeds; only the
artifact upload was failing.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
localhost:8800 fails because act_runner job containers run in their own
network namespace. Point api_base at the backend container on the shared
docker network (http://agent-backend:8000). Requires the runner's
config.yaml container.network to be set to the backend's docker network.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The public URL (legalpoc.eroomai.com) sits behind a Google OAuth proxy,
so CI requests get 302-redirected to the login page. Point api_base at the
internal backend (http://localhost:8800, served at root without /api prefix)
which the act_runner reaches on the same host. Documents host.docker.internal
and Tailscale fallbacks for containerized runners.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- .gitignore: add .serena/ and .DS_Store (both match at any depth)
- untrack 4 .serena files and 155 .DS_Store files (kept on disk)
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>