52facd1461ea575a0c37a5926d1cdcbfb862acf3
1145 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
6cc15fd73d |
fix(ci): restore clean-main CLI and lifecycle gates (#3420)
## Summary - Complete the isolated `@fusion/core` mock used by the experiment-finalize extension suite - Classify three intentional physical/synthetic lifecycle literals introduced on current main - Re-record the strict lifecycle census baseline with zero unexamined guards ## Test plan - `pnpm --filter @runfusion/fusion exec vitest run src/__tests__/extension-experiment-finalize.test.ts --silent=passed-only --reporter=dot` - `pnpm --filter @fusion/core exec vitest run src/__tests__/task-intake-owner-resolver.test.ts --silent=passed-only --reporter=dot` - `pnpm --filter @fusion/engine exec vitest run --project engine-default src/__tests__/mission-feature-sync-lanes.test.ts --silent=passed-only --reporter=dot` - `pnpm check:lifecycle-columns` - `node scripts/check-mock-completeness.mjs` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Improved mission reconciliation previews for task links, specification alignment, and lifecycle updates. - Prevented stale or superseded validation runs from overwriting current feature status or ownership. - Improved blocked-feature diagnostics and archived-task handling across workflow configurations. - **Documentation** - Clarified validation, assignment checks, and mission synchronization behavior. - **Tests** - Expanded coverage for reconciliation previews and validator ownership scenarios. - **Chores** - Updated lifecycle baseline data for known archived-task cases. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
25e292d0e6 |
FN-8954: preserve CLI liveness during startup
Ensure CLI startup operations settle before process exit on supported Node runtimes. - Keep awaited QMD probes and ephemeral port selection ref'd until completion. - Add CLI process regressions for init persistence and exit code 13. - Declare the Node 22.4 runtime floor and extend boot smoke coverage. Files changed: .changeset/fn-8954-cli-exit-13.md | 7 ++ docs/testing.md | 4 +- package.json | 3 + packages/cli/agent-browser.mjs | 6 ++ packages/cli/bin.mjs | 7 ++ packages/cli/package.json | 3 + packages/cli/src/__tests__/ci-workflow.test.ts | 9 +++ packages/cli/src/__tests__/cli-exit-code.test.ts | 82 ++++++++++++++++++++++ packages/cli/src/__tests__/package-config.test.ts | 12 ++++ packages/cli/src/bin.ts | 6 ++ .../__tests__/postgres/embedded-free-port.test.ts | 37 ++++++++++ packages/core/src/memory/memory-backend.ts | 17 +++-- packages/core/src/postgres/embedded-lifecycle.ts | 16 +++-- scripts/boot-smoke.mjs | 62 +++++++++++----- 14 files changed, 244 insertions(+), 27 deletions(-) Fusion-Task-Id: FN-8954 Fusion-Task-Lineage: 05303d07-2662-48d5-a442-6d43fa0a4493 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
62979d8796 |
FN-8985: centralize CLI version resolution
Centralize CLI self-version discovery without widening the early boot import graph. - Reuse one bounded manifest resolver for the CLI binary, updater, and plugin scaffold. - Add regression coverage for manifest lookup bounds, malformed manifests, and scaffold version fallback. - Preserve update command test isolation after the core i18n module relocation. Files changed: packages/cli/src/__tests__/cli-version.test.ts | 136 +++++++++++++++++++++ .../plugin-scaffold-caret-fallback.test.ts | 91 ++++++++++++++ packages/cli/src/bin.ts | 45 +------ packages/cli/src/cli-version.ts | 51 ++++++++ packages/cli/src/commands/__tests__/update.test.ts | 2 +- packages/cli/src/commands/plugin-scaffold.ts | 40 +----- packages/cli/src/commands/update.ts | 37 +----- 7 files changed, 292 insertions(+), 110 deletions(-) Fusion-Task-Id: FN-8985 Fusion-Task-Lineage: dd95b651-3578-4c5f-957a-5af7b85129d7 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
8f6190910d |
FN-8971: add mission blocked-status clearing tool
Add an operator-only CLI tool for repairing stale mission blocked badges. - Register and document fn_mission_clear_blocked with PostgreSQL and status-error handling. - Withhold the repair action from agent principals and deny it in readonly workflow steps. - Classify the tool consistently across engine permission gates and add coverage. - Add a minor CLI changeset for the new operator capability. Files changed: .changeset/fn-8971-mission-clear-blocked-tool.md | 7 +++ docs/missions.md | 7 ++- packages/cli/skill/fusion/SKILL.md | 2 +- .../cli/skill/fusion/references/extension-tools.md | 9 ++++ .../skill/fusion/references/fusion-capabilities.md | 1 + .../__tests__/extension-permission-gates.test.ts | 26 ++++++++++ packages/cli/src/__tests__/extension.test.ts | 56 +++++++++++++++++++++- packages/cli/src/extension.ts | 54 +++++++++++++++++++++ .../src/__tests__/agent-mission-tools.test.ts | 5 +- .../src/__tests__/gating-classifications.test.ts | 8 ++++ .../workflow-step-readonly-allowlist.test.ts | 5 +- .../engine/src/execution/gating-classifications.ts | 7 +++ 12 files changed, 182 insertions(+), 5 deletions(-) Fusion-Task-Id: FN-8971 Fusion-Task-Lineage: 650c13b3-c6c4-4dc5-a0b5-9c71d3b94fc5 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
eacd6687bc |
FN-8961: add computer-use skill and version-matched guide
Ship the computer-use skill across bundled clients and surface its matching guide through the CLI. - add the computer-use skill, computer command descriptor, and `fn skills get computer-use` guide - reconcile all shipped Claude skills at project and startup entry points - cover both skills' reconciliation outcomes and every required call site Files changed: .changeset/fn-8961-computer-use-skill.md | 7 + docs/cli-reference.md | 6 +- docs/computer-use.md | 8 + packages/cli/skill/computer-use/SKILL.md | 31 +++ packages/cli/src/__tests__/package-config.test.ts | 20 ++ packages/cli/src/bin.ts | 14 +- .../__tests__/claude-skills-callsites.test.ts | 64 ++++++ .../src/commands/__tests__/claude-skills.test.ts | 221 ++++++++------------- .../__tests__/computer-surface-descriptor.test.ts | 108 ++++++++++ .../commands/__tests__/computer-use-guide.test.ts | 36 ++++ .../commands/__tests__/computer-use-skill.test.ts | 20 ++ packages/cli/src/commands/__tests__/daemon.test.ts | 36 +++- .../__tests__/dashboard-claude-skills.test.ts | 19 ++ packages/cli/src/commands/__tests__/init.test.ts | 48 ++++- .../cli/src/commands/__tests__/project.test.ts | 38 ++++ packages/cli/src/commands/__tests__/serve.test.ts | 36 +++- .../commands/__tests__/skill-installation.test.ts | 12 ++ .../cli/src/commands/__tests__/skills-get.test.ts | 67 ++++++ packages/cli/src/commands/claude-skills-runner.ts | 55 ++--- packages/cli/src/commands/claude-skills.ts | 47 +++-- packages/cli/src/commands/computer.ts | 6 +- packages/cli/src/commands/computer/contract.ts | 52 +++++ packages/cli/src/commands/computer/guide.ts | 62 ++++++ packages/cli/src/commands/init.ts | 4 +- packages/cli/src/commands/skill-installation.ts | 45 +++-- packages/cli/src/commands/skills.ts | 24 +++ 26 files changed, 853 insertions(+), 233 deletions(-) Fusion-Task-Id: FN-8961 Fusion-Task-Lineage: b6baaebb-bf72-4991-8239-eb9bcf9cbcf1 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
79502c67a0 |
FN-8978: fix CLI TypeScript external packaging
Keep TypeScript available as a runtime external in the published CLI package. - Remove the duplicate TypeScript devDependency declaration. - Assert tsup externals are published runtime dependencies. - Document the runtime external packaging invariant. Files changed: .changeset/fn-8978-typescript-dedup.md | 7 +++++ packages/cli/package.json | 1 - packages/cli/src/__tests__/package-config.test.ts | 31 +++++++++++++++++++++++ packages/cli/tsup.config.ts | 6 +++++ 4 files changed, 44 insertions(+), 1 deletion(-) Fusion-Task-Id: FN-8978 Fusion-Task-Lineage: b9630c4a-73a9-414f-9a78-25c689359509 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
79206c3f31 |
FN-8977: unify CLI Vitest mock resolution
Route CLI test mocks through dashboard and engine runtime imports. - Anchor pi-coding-agent resolution to the CLI package instance - Preserve real session exports while overriding runtime dependencies - Add a regression test and document cross-package mock scoping Files changed: docs/testing.md | 6 ++ .../__tests__/extension-permission-gates.test.ts | 10 ++- .../vitest-cross-package-mock-scope.test.ts | 75 ++++++++++++++++++++++ packages/cli/vitest.config.ts | 12 ++++ 4 files changed, 101 insertions(+), 2 deletions(-) Fusion-Task-Id: FN-8977 Fusion-Task-Lineage: a652cdf4-463e-4603-8d71-87db91d0b846 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
1da61f35f7 |
FN-8960: add macOS computer automation CLI
Add a snapshot-backed macOS computer-use surface to the Fusion CLI. - Register fn computer commands for app state, permission, capability, and UI actions. - Implement macOS JXA automation with locator replay and persisted snapshot safety checks. - Document the CLI surface, add contract coverage, and include a release changeset. Files changed: .changeset/fn-8960-computer-use-cli.md | 7 + docs/README.md | 1 + docs/cli-reference.md | 21 ++ docs/computer-use.md | 156 +++++++++++++ packages/cli/src/bin.ts | 11 + .../__tests__/computer-adapter-registry.test.ts | 154 ++++++++++++ .../commands/__tests__/computer-commands.test.ts | 71 ++++++ .../commands/__tests__/computer-contract.test.ts | 34 +++ .../__tests__/computer-snapshot-index.test.ts | 87 +++++++ packages/cli/src/commands/computer.ts | 182 +++++++++++++++ .../cli/src/commands/computer/adapter-macos.ts | 211 +++++++++++++++++ .../cli/src/commands/computer/adapter-registry.ts | 42 ++++ .../src/commands/computer/adapter-unsupported.ts | 44 ++++ packages/cli/src/commands/computer/adapter.ts | 97 ++++++++ packages/cli/src/commands/computer/contract.ts | 83 +++++++ packages/cli/src/commands/computer/exec-seam.ts | 61 +++++ .../cli/src/commands/computer/scripts/macos-jxa.ts | 37 +++ .../cli/src/commands/computer/snapshot-store.ts | 257 +++++++++++++++++++++ 18 files changed, 1556 insertions(+) Fusion-Task-Id: FN-8960 Fusion-Task-Lineage: 5870bf69-b751-4879-bf9d-5f5396cc0f55 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
cef07527f6 |
FN-8948: reconcile mission state from task ground truth
Centralize mission and feature state repair around deterministic task lifecycle evidence. - Add a reusable mission reconciliation authority with task-move, API, tool, and maintenance callers. - Repair unambiguous title links while preserving terminal, validation, and audit safeguards. - Route scheduler moves through the authority and reject duplicate feature-title ownership. - Expose reconcile controls and document the operator workflow. Files changed: .changeset/fn-8948-mission-auto-reconcile.md | 7 + AGENTS.md | 1 + docs/missions.md | 8 +- packages/cli/skill/fusion/SKILL.md | 2 +- .../cli/skill/fusion/references/extension-tools.md | 9 + .../skill/fusion/references/fusion-capabilities.md | 1 + .../extension-experiment-finalize.test.ts | 2 + .../__tests__/extension-gitlab-tracking.test.ts | 2 + .../cli/src/__tests__/extension-web-fetch.test.ts | 2 + packages/cli/src/extension.ts | 14 + packages/dashboard/src/mission-routes.ts | 24 +- .../src/__tests__/agent-mission-tools.test.ts | 2 +- .../engine/src/__tests__/mission-autopilot.test.ts | 8 +- .../src/__tests__/mission-state-reconcile.test.ts | 67 +++++ packages/engine/src/agent-tools.ts | 6 + .../engine/src/execution/gating-classifications.ts | 1 + packages/engine/src/index.ts | 6 + packages/engine/src/missions/index.ts | 8 +- packages/engine/src/missions/mission-autopilot.ts | 106 +------ .../engine/src/missions/mission-feature-sync.ts | 1 + .../engine/src/missions/mission-state-reconcile.ts | 169 +++++++++++ packages/engine/src/runtimes/in-process-runtime.ts | 4 +- packages/engine/src/scheduler.ts | 331 +++++---------------- packages/engine/src/util/run-audit.ts | 2 + 24 files changed, 426 insertions(+), 357 deletions(-) Fusion-Task-Id: FN-8948 Fusion-Task-Lineage: 0fbccef3-eeac-46d2-b3d8-aca679b3657e Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
b82f1a41f3 |
FN-8947: add repairable mission validation controls
Add repairable mission-validation badges with clear and re-run flows. - Persist repair metadata and audit events for mission validation state changes. - Expose validation repair through dashboard routes, UI controls, engine tools, and CLI capabilities. - Add database, API, UI, engine, and extension coverage plus operator documentation. Files changed: .changeset/fn-8947-mission-validation-repair.md | 7 + docs/missions.md | 15 +- packages/cli/skill/fusion/SKILL.md | 2 +- .../cli/skill/fusion/references/extension-tools.md | 10 + .../skill/fusion/references/fusion-capabilities.md | 1 + .../extension-experiment-finalize.test.ts | 2 + .../__tests__/extension-gitlab-tracking.test.ts | 2 + .../cli/src/__tests__/extension-web-fetch.test.ts | 2 + packages/cli/src/__tests__/extension.test.ts | 24 +++ packages/cli/src/extension.ts | 40 ++++ .../mission-status-event-metadata.test.ts | 23 +++ .../postgres/mission-validation-repair.pg.test.ts | 187 ++++++++++++++++++ .../core/src/async-stores/async-mission-store.ts | 216 ++++++++++++++++++--- packages/core/src/index.gate.ts | 5 + packages/core/src/index.ts | 5 +- packages/core/src/missions/mission-types.ts | 49 +++++ packages/core/src/types.ts | 7 + packages/dashboard/app/api/legacy.ts | 1 + packages/dashboard/app/api/missions/missions.ts | 13 ++ .../dashboard/app/components/MissionManager.css | 26 ++- .../dashboard/app/components/MissionManager.tsx | 207 +++++++++++++++++--- .../__tests__/MissionManager.mobile-css.test.ts | 8 + .../MissionManager.validation-repair.test.tsx | 83 ++++++++ .../__tests__/mission-task-prefix-routes.test.ts | 162 +++++++++++++++- packages/dashboard/src/mission-routes.ts | 104 +++++++++- .../src/__tests__/agent-mission-tools.test.ts | 119 +++++++++++- .../__tests__/mission-feature-sync-lanes.test.ts | 59 +++++- .../workflow-step-readonly-allowlist.test.ts | 1 + packages/engine/src/agent-tools.ts | 36 ++++ .../engine/src/execution/gating-classifications.ts | 1 + packages/engine/src/index.ts | 1 + .../engine/src/missions/mission-feature-sync.ts | 79 ++++++++ 32 files changed, 1430 insertions(+), 67 deletions(-) Fusion-Task-Id: FN-8947 Fusion-Task-Lineage: b93e5ab6-021c-4d32-bffb-f89f4c3894bc Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
a839c61929 |
FN-8926: expose graph and recall through MCP
Expose Fusion knowledge graph and durable recall through a built-in MCP transport. - Add the reserved fusion-memory server with graph and recall MCP tools. - Resolve built-in availability and enable/disable tombstones across configuration and UI. - Add CLI transport, documentation, release metadata, and lane coverage tests. Files changed: .changeset/fn-8926-memory-mcp-server.md | 7 + docs/cli-reference.md | 4 + docs/mcp.md | 10 ++ packages/cli/src/bin.ts | 6 + .../__tests__/mcp-memory-server-spawn.test.ts | 79 ++++++++++ .../commands/__tests__/mcp-memory-server.test.ts | 83 +++++++++++ packages/cli/src/commands/__tests__/mcp.test.ts | 27 +++- packages/cli/src/commands/mcp-memory-server.ts | 104 +++++++++++++ packages/cli/src/commands/mcp.ts | 64 ++++++-- packages/core/package.json | 10 ++ .../core/src/__tests__/mcp-builtin-servers.test.ts | 17 +++ packages/core/src/__tests__/mcp-config.test.ts | 12 ++ packages/core/src/config/mcp-builtin-descriptor.ts | 16 ++ packages/core/src/config/mcp-builtin-servers.ts | 18 +++ packages/core/src/config/mcp-config.ts | 40 +++-- packages/core/src/config/mcp-discovery.ts | 3 +- packages/core/src/index.ts | 6 + packages/core/src/memory/index.ts | 1 + .../mcp/__tests__/memory-mcp-handler.test.ts | 36 +++++ .../mcp/__tests__/memory-mcp-serialization.test.ts | 23 +++ packages/core/src/memory/mcp/index.ts | 4 + .../core/src/memory/mcp/memory-mcp-backends.ts | 39 +++++ packages/core/src/memory/mcp/memory-mcp-handler.ts | 54 +++++++ .../src/memory/mcp/memory-mcp-serialization.ts | 48 ++++++ packages/core/src/memory/mcp/memory-mcp-tools.ts | 64 ++++++++ packages/core/src/types.ts | 10 ++ .../settings/sections/GlobalMcpSection.tsx | 14 +- .../settings/sections/McpServersCard.tsx | 67 +++++++-- .../settings/sections/ProjectMcpSection.tsx | 15 +- .../__tests__/McpServersCard.builtin.test.tsx | 45 ++++++ .../dashboard/src/__tests__/chat-manager.test.ts | 24 +++ .../register-config-mcp-pi-settings-routes.ts | 20 ++- packages/dashboard/vitest.config.ts | 2 + .../__tests__/mcp-builtin-lane-coverage.test.ts | 163 +++++++++++++++++++++ packages/engine/src/mcp/mcp-resolution.ts | 10 +- packages/engine/vitest.config.ts | 2 + 36 files changed, 1097 insertions(+), 50 deletions(-) Fusion-Task-Id: FN-8926 Fusion-Task-Lineage: b2861491-33da-4b05-b9f8-a7c1448c1c8c Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
3143f9536f |
FN-8908: auto-recover terminal task failures
Recover generic terminal task failures through a bounded, durable retry budget before escalating them to operators. - add fenced task-store recovery claims, retries, budget resets, and audit events - defer terminal-failure notifications until recovery is exhausted while preserving a single escalation - expose operator retry budget reset and cover recovery lifecycle behavior Files changed: .../fn-8908-terminal-failure-auto-recovery.md | 7 + AGENTS.md | 1 + docs/agents.md | 2 + docs/architecture.md | 2 + packages/cli/src/commands/task.ts | 2 + packages/cli/src/extension.ts | 2 + ...terminal-failure-auto-recovery-store.pg.test.ts | 108 +++++++++ .../terminal-failure-auto-recovery.test.ts | 60 +++++ packages/core/src/index.gate.ts | 1 + packages/core/src/index.ts | 1 + packages/core/src/store.ts | 179 ++++++++++++++- .../core/src/task-store/archive-lifecycle-2.ts | 15 ++ packages/core/src/task-store/moves.ts | 48 +++- packages/core/src/task-store/persistence.ts | 18 +- packages/core/src/task-store/project-store-ops.ts | 4 +- .../src/task-store/workflow-task-create-ops.ts | 4 +- packages/core/src/tasks/index.ts | 1 + .../src/tasks/terminal-failure-auto-recovery.ts | 114 ++++++++++ packages/core/src/types/task/task-core.ts | 24 ++ .../src/routes/register-task-workflow-routes.ts | 2 + ...-healing-terminal-failure-auto-recovery.test.ts | 199 ++++++++++++++++ .../__tests__/notification-service.test.ts | 86 ++++++- .../__tests__/task-wedge-notification.test.ts | 2 +- .../src/notification/notification-service.ts | 103 +++++++-- .../src/notification/task-wedge-notification.ts | 30 ++- packages/engine/src/self-healing.ts | 251 ++++++++++++++++++++- packages/engine/src/util/run-audit.ts | 7 + 27 files changed, 1240 insertions(+), 33 deletions(-) Fusion-Task-Id: FN-8908 Fusion-Task-Lineage: 99e96b16-0306-41f1-87da-8623d69735f7 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
0fc6f3d849 |
FN-8946: enable attributed agent mission status updates
Enable authorized agents to update feature and mission statuses with transactional, attributed audit events. - Add mission and feature status tools to the Fusion extension and engine allowlists. - Record bounded actor, reason, and hierarchy metadata for status transitions across every writer. - Guard linked feature transitions and document the agent-facing workflow. Files changed: .changeset/fn-8946-mission-status-writes.md | 7 + docs/missions.md | 7 +- packages/cli/skill/fusion/SKILL.md | 2 +- .../cli/skill/fusion/references/extension-tools.md | 20 +++ .../skill/fusion/references/fusion-capabilities.md | 2 + packages/cli/src/__tests__/extension.test.ts | 46 ++++++ packages/cli/src/extension.ts | 27 +++ .../mission-status-event-metadata.test.ts | 50 ++++++ .../__tests__/postgres/mission-store.pg.test.ts | 160 +++++++++++++++++- .../core/src/async-stores/async-mission-store.ts | 182 +++++++++++++++------ packages/core/src/index.ts | 5 + packages/core/src/missions/mission-store.ts | 7 +- packages/core/src/missions/mission-types.ts | 99 +++++++++-- .../src/__tests__/chat-toolset-permissions.test.ts | 24 +++ packages/dashboard/src/mission-routes.ts | 3 +- .../src/__tests__/agent-mission-tools.test.ts | 42 ++++- .../src/__tests__/heartbeat-executor.test.ts | 4 +- .../workflow-step-readonly-allowlist.test.ts | 2 + packages/engine/src/agent-tools.ts | 18 ++ .../engine/src/execution/gating-classifications.ts | 2 + 20 files changed, 635 insertions(+), 74 deletions(-) Fusion-Task-Id: FN-8946 Fusion-Task-Lineage: 473cc0e0-e632-48b3-ac84-adaaeb81db4b Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
27cb2d2621 |
FN-8921: add deterministic knowledge graph tooling
Add a committable, provenance-tagged knowledge graph layer with CLI generation and query support. - Extract TypeScript, Markdown, and FNXC knowledge into deterministic graph nodes and edges. - Persist recoverable graph artifacts outside ignored Fusion state and expose build/query CLI commands. - Document configuration and add core and CLI coverage for graph structure, serialization, and recovery. Files changed: .changeset/fn-8921-knowledge-graph.md | 7 + .gitattributes | 3 + AGENTS.md | 1 + docs/README.md | 2 + docs/cli-reference.md | 4 + docs/knowledge-graph.md | 37 +++++ docs/settings-reference.md | 4 + docs/storage.md | 2 + packages/cli/package.json | 3 +- .../__tests__/knowledge-graph-bundle-shape.test.ts | 4 + .../src/__tests__/knowledge-graph-command.test.ts | 115 ++++++++++++++ packages/cli/src/bin.ts | 19 +++ packages/cli/src/commands/knowledge-graph.ts | 79 ++++++++++ packages/cli/tsup.config.ts | 2 + packages/core/package.json | 4 +- packages/core/src/config/settings-schema.ts | 2 + packages/core/src/index.ts | 1 + .../__tests__/derive-modules.test.ts | 11 ++ .../__tests__/extract-file-composition.test.ts | 20 +++ .../knowledge-graph/__tests__/extract-fnxc.test.ts | 33 ++++ .../__tests__/extract-markdown.test.ts | 21 +++ .../__tests__/extract-typescript.test.ts | 30 ++++ .../__tests__/file-discovery.test.ts | 26 ++++ .../graph-artifact-not-gitignored.test.ts | 15 ++ .../__tests__/graph-builder-equivalence.test.ts | 76 ++++++++++ .../__tests__/graph-builder-incremental.test.ts | 52 +++++++ .../__tests__/graph-identity.test.ts | 11 ++ .../knowledge-graph/__tests__/graph-query.test.ts | 13 ++ .../__tests__/graph-serialization.test.ts | 29 ++++ .../__tests__/graph-store-recovery.test.ts | 106 +++++++++++++ .../__tests__/resolve-imports.test.ts | 10 ++ .../core/src/knowledge-graph/derive-modules.ts | 4 + packages/core/src/knowledge-graph/extract-file.ts | 6 + packages/core/src/knowledge-graph/extract-fnxc.ts | 168 +++++++++++++++++++++ .../core/src/knowledge-graph/extract-markdown.ts | 9 ++ .../core/src/knowledge-graph/extract-typescript.ts | 107 +++++++++++++ .../core/src/knowledge-graph/file-discovery.ts | 85 +++++++++++ packages/core/src/knowledge-graph/graph-builder.ts | 141 +++++++++++++++++ .../core/src/knowledge-graph/graph-manifest.ts | 4 + packages/core/src/knowledge-graph/graph-query.ts | 126 ++++++++++++++++ .../src/knowledge-graph/graph-serialization.ts | 134 ++++++++++++++++ packages/core/src/knowledge-graph/graph-store.ts | 97 ++++++++++++ packages/core/src/knowledge-graph/graph-types.ts | 54 +++++++ packages/core/src/knowledge-graph/index.ts | 14 ++ .../core/src/knowledge-graph/resolve-imports.ts | 4 + packages/core/src/types/settings/settings-scope.ts | 2 + pnpm-lock.yaml | 12 +- 47 files changed, 1700 insertions(+), 9 deletions(-) Fusion-Task-Id: FN-8921 Fusion-Task-Lineage: 7014d0f1-fc47-454b-afe5-5f0d9b229f33 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
1cf86baa1c |
refactor: package code organization wave 18 (executor pure peels) (#3317)
## Summary
Wave 18 continues the package code-organization program after wave 17
domain folders (U4 Slice A from
`docs/plans/2026-07-14-001-refactor-package-code-organization-plan.md`).
### What changed
Peel **pure, behavior-preserving** helpers out of
`packages/engine/src/executor.ts` into domain modules under
`packages/engine/src/executor/`, with **stable re-exports** from
`executor.ts` so deep imports and `vi.mock("../executor.js")` keep
working.
| New module | Symbols |
|------------|---------|
| `executor/task-done-refusal.ts` | `evaluateTaskDoneRefusal`,
`determineRevisionResetStart`, skip-bypass refusal helper |
| `executor/workflow-feedback-paths.ts` |
`extractReferencedPathsFromWorkflowFeedback`,
`isAlwaysAllowedScopeLeakPath`, `workflowPathMatchesDeclaredScope` |
| `executor/workflow-step-verdict.ts` |
`FUSION_WORKFLOW_STEP_CONVENTIONS_PREAMBLE`, `parseWorkflowStepVerdict`
/ `parseWorkflowStepOutput`, step outcome types |
| `executor/await-input-parse.ts` | `parseAwaitInputSentinel`,
`parseAwaitInputQuestionToolCall` |
| `executor/no-commit-eligibility.ts` | `getNoCommitEligibilityReason`
(+ prompt heuristics) |
`executor.ts` live LOC ~**22817 → ~22427** (first pure-peel batch; more
peels needed to approach the 2k cap).
### Shims
- `old path` `executor.ts` public exports → `new path` `executor/*.ts` →
delete-when consumer deep-imports are re-pointed (not this PR)
### Test plan
- [x] `@fusion/engine` typecheck
- [x] Oracle: task-done refusal, skip-bypass, workflow malformed
verdict, scope-leak allowlist, executor-step-session, executor-prompt
- [x] `vitest --project=engine-core` (merge-gate curated suite)
- [ ] CI merge gate
**Stack:** wave17 (merged) → **this PR**
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Improved recognition of workflow outcomes from structured and
conversational responses.
* Added support for extracting questions from await-input responses and
tool calls.
* Improved workflow feedback handling for referenced files and declared
scope patterns.
* Added clearer guidance for task execution, approvals, verification,
and available tools.
* **Bug Fixes**
* Prevented completion when required review approvals are missing or
revisions remain pending.
* Improved handling of workflows that legitimately require no code
changes.
* Added clearer refusal messages and more reliable revision restarts.
* Sanitized repository paths in Git remediation instructions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
a09e0cb87f |
feat(i18n): add Português (Brasil) (pt-BR) locale (#3347)
## Summary Adds **Português (Brasil)** (`pt-BR`) as a supported locale: - Selectable as **Translation target language** (project settings) and as the dashboard / terminal UI language. - Full machine-drafted catalogs (`app`, `cli`, `common`), disclosed in `packages/i18n/locales/TRANSLATION_STATUS.md` following the pattern #1352 established — reviewed for glossary/register consistency (0.18% untranslated, matching only keys that are empty in `en`), but native-speaker corrections are welcome. - Brazilian Portuguese content-language detection (accent-stripped stopword list — the scorer strips diacritics before matching, so accented entries never match; `com`/`mais` deliberately omitted to avoid bare-domain `.com` and French collisions, with regression tests for both directions). - `pt`/`pt-PT` browser and environment locales resolve to `pt-BR` on all three detection paths (`FALLBACK_LNG` routing plus a `pt` branch in `normalizeToSupportedLocale`, mirroring the existing `zh` handling). - `README.pt-BR.md` + switcher links in all READMEs, docs updates (`settings-reference`, `cli-reference`, `i18n-contributing`, `--lang` help text), changeset (`minor`). Drive-by fixes bundled: `TRANSLATION_STATUS.md` was missing the `ko` row; the LanguageSelector endonym test was missing `한국어`; `docs/i18n-contributing.md` now names the two compile-enforced display maps (`LOCALE_LABELS`, `localeDisplayName`) a new locale must update; the `--lang` CLI help text no longer drifts from its validator. ## Test plan - `pnpm i18n:status` (key parity gate) green; catalogs are `i18n:sync`-idempotent. - Updated/extended suites: core `locale-settings`, i18n `config`/`parity`/`db-banner-catalog`/`i18n-gate-coverage`, dashboard `useLanguage`/`LanguageSelector`/`GeneralSection.importTranslate`/`detectContentLanguage` (incl. new pt-BR detection + bare-domain regression tests), CLI `settings`. - `pnpm verify:fast` (typecheck, build, boot smoke), `pnpm lint`, `pnpm check:changesets`, and the bounded `pnpm test` lane all green locally (the three `test:pg-gate` files fail locally only for lack of a Postgres instance; they fail identically on clean `main`). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added Brazilian Portuguese (Português (Brasil)) across the dashboard, terminal interface, settings, and translation tools. * Added Portuguese translations for common interface and CLI content. * Added automatic Portuguese language detection, locale normalization, and fallback support. * Added a Portuguese (Brazil) README with product, setup, and usage documentation. * **Documentation** * Updated language selectors, CLI references, settings documentation, and translation guidance. * Added Portuguese README links to translated documentation. * Added French to the documented dashboard language options. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: gsxdsm <gsxdsm@users.noreply.github.com> |
||
|
|
c7c879905b |
FN-8903: add event-driven GitHub CI merge checks
Persist ingested GitHub CI signals and use them to assess merge readiness. - Store project-scoped GitHub check states with retention maintenance. - Resolve configured required checks from ingested signals during PR merge decisions. - Add delivery, lifecycle, persistence, and retention coverage with operator documentation. Files changed: .changeset/fn-8903-event-driven-checks.md | 7 ++ docs/architecture.md | 1 + docs/settings-reference.md | 2 +- docs/signals-connectors.md | 2 +- .../src/commands/__tests__/task-lifecycle.test.ts | 50 ++++++++- packages/cli/src/commands/task-lifecycle.ts | 7 +- .../core/src/__tests__/ingested-checks.test.ts | 66 +++++++++++ .../postgres/github-check-states.pg.test.ts | 71 ++++++++++++ packages/core/src/config/index.ts | 1 + packages/core/src/config/ingested-checks.ts | 32 ++++++ packages/core/src/index.ts | 10 ++ .../0048_fn_8903_github_check_states.sql | 32 ++++++ packages/core/src/postgres/schema-applier.ts | 15 ++- packages/core/src/postgres/schema/project.ts | 29 ++++- .../core/src/task-store/async/async-ci-checks.ts | 104 ++++++++++++++++++ packages/core/src/task-store/async/index.ts | 1 + packages/core/src/types.ts | 2 + packages/dashboard/src/__tests__/github.test.ts | 121 ++++++++++++++++++++- .../src/__tests__/register-signal-routes.test.ts | 81 +++++++++++++- packages/dashboard/src/github.ts | 74 +++++++++---- .../dashboard/src/routes/register-git-github.ts | 29 +++-- .../dashboard/src/routes/register-signal-routes.ts | 10 +- .../src/routes/register-task-workflow-routes.ts | 14 ++- packages/dashboard/src/signal-source.ts | 23 ++++ packages/dashboard/src/signal-sources/github.ts | 2 + .../self-healing-github-check-retention.test.ts | 121 +++++++++++++++++++++ packages/engine/src/self-healing.ts | 23 ++++ 27 files changed, 878 insertions(+), 52 deletions(-) Fusion-Task-Id: FN-8903 Fusion-Task-Lineage: b2643587-c568-4b6c-8b3a-d50a6165963d Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
2643f4e567 |
FN-8884: enable GitHub-native PR auto-merge
Enable opt-in GitHub-managed auto-merge for pull requests. - Add a project setting and dashboard control for GitHub native auto-merge. - Arm individual, group, dashboard, and workflow PRs with `gh pr merge --auto` or GraphQL, including while checks are pending. - Preserve deferred PR reconciliation, unavailable-feature errors, project-scoped runtime configuration, tests, documentation, and a release changeset. Files changed: .changeset/fn-8884-github-native-auto-merge.md | 7 + docs/settings-reference.md | 5 + packages/cli/src/commands/__tests__/daemon.test.ts | 16 +++ packages/cli/src/commands/__tests__/serve.test.ts | 14 ++ .../src/commands/__tests__/task-lifecycle.test.ts | 158 +++++++++++++++++++++ packages/cli/src/commands/daemon.ts | 11 +- packages/cli/src/commands/dashboard.ts | 11 +- packages/cli/src/commands/serve.ts | 11 +- packages/cli/src/commands/task-lifecycle.ts | 45 ++++-- .../core/src/__tests__/settings-defaults.test.ts | 4 + packages/core/src/config/settings-schema.ts | 1 + packages/core/src/types/settings/settings-scope.ts | 8 ++ .../settings/__tests__/section-keys.test.ts | 1 + .../app/components/settings/section-keys.ts | 1 + .../components/settings/sections/MergeSection.tsx | 14 +- .../settings-default-descriptions.test.tsx | 1 + .../src/__tests__/github-native-auto-merge.test.ts | 114 +++++++++++++++ .../src/__tests__/routes-pr-merge.test.ts | 84 +++++++++++ packages/dashboard/src/github.ts | 88 +++++++++++-- packages/dashboard/src/index.ts | 2 +- .../dashboard/src/routes/register-git-github.ts | 33 +++-- .../project-engine-deferred-startup.test.ts | 21 +++ packages/engine/src/project-engine-manager.ts | 2 + packages/engine/src/project-engine.ts | 6 + packages/engine/src/project/project-runtime.ts | 6 + packages/engine/src/runtimes/in-process-runtime.ts | 9 +- packages/i18n/locales/en/app.json | 4 +- 27 files changed, 634 insertions(+), 43 deletions(-) Fusion-Task-Id: FN-8884 Fusion-Task-Lineage: cf1b1ea4-7ef7-4050-bd87-25933456a5b6 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
d59c1b162f |
FN-8855: enforce configured PR checks before merging
Add configurable Fusion-side PR check gating across merge surfaces. - Add project required-check settings, validation, UI controls, CLI support, and operator documentation. - Evaluate configured checks before dashboard and CLI PR merges, accepting successful, skipped, and neutral checks. - Bind merges to the evaluated PR head SHA to prevent push-and-merge races. - Cover required-check policy and head-SHA merge behavior with tests. Files changed: .changeset/fn-8855-required-checks.md | 7 + docs/dashboard-guide.md | 5 + docs/settings-reference.md | 1 + .../src/commands/__tests__/task-lifecycle.test.ts | 30 ++++- packages/cli/src/commands/task-lifecycle.ts | 17 ++- .../core/src/__tests__/required-checks.test.ts | 16 +++ packages/core/src/config/index.ts | 1 + packages/core/src/config/required-checks.ts | 16 +++ packages/core/src/config/settings-schema.ts | 1 + packages/core/src/index.ts | 1 + packages/core/src/types.ts | 6 + packages/core/src/types/settings/settings-scope.ts | 6 + packages/core/src/types/task/task-tracking.ts | 5 + .../settings/__tests__/section-keys.test.ts | 1 + .../app/components/settings/section-keys.ts | 1 + .../settings/sections/MergeSection.search.ts | 3 + .../components/settings/sections/MergeSection.tsx | 30 ++++- .../__tests__/MergeSection.requiredChecks.test.tsx | 50 +++++++ .../settings-default-descriptions.test.tsx | 1 + packages/dashboard/src/__tests__/github.test.ts | 123 +++++++++++++++++ packages/dashboard/src/github.ts | 149 +++++++++++++-------- .../dashboard/src/routes/register-git-github.ts | 38 ++++-- .../src/routes/register-task-workflow-routes.ts | 8 +- packages/i18n/locales/en/app.json | 4 +- 24 files changed, 441 insertions(+), 79 deletions(-) Fusion-Task-Id: FN-8855 Fusion-Task-Lineage: 708e9c27-72be-4925-bf09-5db421bcaa67 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
b3504f01a4 |
FN-8838: refresh automated PR heads before GitHub mutations
Refresh isolated automated PR heads against their target immediately before PR creation or merge. - Rebase and lease-publish task and group heads at every automated GitHub boundary. - Fail closed on concurrent head updates and reconcile retained refresh worktrees. - Add lifecycle coverage and document the configurable integration remote. Files changed: .changeset/fn-8838-refresh-pr-heads.md | 7 + docs/settings-reference.md | 6 + .../task-lifecycle-refresh.integration.test.ts | 438 ++++++++++++++++ .../src/commands/__tests__/task-lifecycle.test.ts | 309 ++++++++++- packages/cli/src/commands/daemon.ts | 4 +- packages/cli/src/commands/dashboard.ts | 4 +- packages/cli/src/commands/serve.ts | 4 +- packages/cli/src/commands/task-lifecycle.ts | 581 +++++++++++++++++++-- .../src/__tests__/group-merge-coordinator.test.ts | 43 ++ .../engine/src/merge/group-merge-coordinator.ts | 34 +- packages/engine/src/merge/pr-nodes.ts | 35 +- packages/engine/src/project-engine.ts | 16 +- 12 files changed, 1425 insertions(+), 56 deletions(-) Fusion-Task-Id: FN-8838 Fusion-Task-Lineage: a9b9e800-7d73-441f-bc1b-2488d244e0b1 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
c0e2ba2ade |
FN-8836: classify GitHub branch policy merge blocks
Classify ambiguous GitHub merge failures using refreshed pull request state. - Distinguish branch-protection blocks from true merge conflicts. - Surface review and required-check blockers in CLI and dashboard merge flows. - Add regression coverage and a patch changeset. Files changed: .changeset/fn-8836-gh-merge-policy-errors.md | 7 ++ .../src/commands/__tests__/task-lifecycle.test.ts | 55 +++++++++ packages/cli/src/commands/task-lifecycle.ts | 14 ++- packages/core/src/__tests__/gh-cli.test.ts | 39 +++++- packages/core/src/cli/gh-cli.ts | 60 +++++++++- packages/core/src/index.gate.ts | 1 + packages/core/src/index.ts | 1 + .../dashboard/src/__tests__/routes-github.test.ts | 131 +++++++++++++++++++++ .../dashboard/src/routes/register-git-github.ts | 58 +++++++-- 9 files changed, 351 insertions(+), 15 deletions(-) Fusion-Task-Id: FN-8836 Fusion-Task-Lineage: 7102f5ba-aca9-48cd-a27b-76deb952c4a5 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
54d1ccb8d5 |
FN-8835: block unmergeable pull requests
Fail closed before auto-merging pull requests that GitHub reports as unmergeable. - Require normalized clean mergeability in PR readiness checks. - Cover protected, behind, conflicting, and unknown PR states across CLI and dashboard tests. - Add a patch changeset for the corrected auto-merge behavior. Files changed: .changeset/fn-8835-pr-merge-readiness.md | 7 +++ .../src/commands/__tests__/task-lifecycle.test.ts | 21 ++++--- packages/dashboard/src/__tests__/github.test.ts | 64 ++++++++++++++++++---- packages/dashboard/src/github.ts | 11 ++++ 4 files changed, 84 insertions(+), 19 deletions(-) Fusion-Task-Id: FN-8835 Fusion-Task-Lineage: 698dacf9-5f24-42b7-b927-ae5b5579ee3f Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
0fda8b203b |
test: bind a project partition in the PG harness for built-in agent provisioning
FN-8764 made AgentStore.init() unconditionally provision the four durable built-in workflow-owner agents, and that provisioning needs a bound asyncLayer.projectId — backendProjectId rejects the empty/unbound partition so a shared cluster cannot mix ownership. Every AgentStore-backed PG test therefore threw in init(); without this change all 10 cases in agent-instructions.pg.test fail at agent-store.ts:526. createTaskStoreForTest / createSharedPgTaskStoreTestHarness gain an OPT-IN projectId. Undefined keeps the historical project-agnostic harness (RLS bypass, empty-string partition) that the rest of the core suite relies on. When set, the connection GUC `fusion.project_id`, the AsyncDataLayer, and the seeded config row all share one partition — so agents (explicit project_id) and their config revisions (GUC-default project_id) land together and the (project_id, agent_id) FK on agent_config_revisions holds. Also folds in two already-merged consequences: serve.test expects the consumerId: "engine" that serve.ts:326 already passes (FN-8685), and the auto-generated Fusion skill docs pick up fn_workflow_step_resume, the roles / max_workflow_sessions agent fields, and the deprecated singular role. Uncommitted in the working tree; reviewed, verified against the real database, and committed as-is. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
eaadd153b1 |
FN-8764: route workflow stages through durable role agents
Route workflow stages through task-scoped durable role agents. - Persist normalized multi-role agents and workflow principal fences with migrations. - Route planning, execution, review, and merge workflow nodes through authorized permanent principals with capacity leasing and recovery. - Retire ephemeral workflow-stage workers and expose role-aware agent configuration, workflow editing, and documentation. - Preserve lifecycle-column ratchet coverage by centralizing workflow-role classification rather than adding test exemptions. Files changed: .changeset/fn-8764-workflow-role-agents.md | 7 + CONCEPTS.md | 3 + docs/agents.md | 6 + docs/architecture.md | 6 + docs/cli-reference.md | 2 + docs/dashboard-guide.md | 4 + docs/settings-reference.md | 6 +- docs/storage.md | 2 + docs/workflow-steps.md | 6 + .../src/__tests__/extension-agent-update.test.ts | 11 +- packages/cli/src/__tests__/extension.test.ts | 18 +- packages/cli/src/extension.ts | 41 +- .../core/src/__tests__/agent-permissions.test.ts | 12 + .../core/src/__tests__/agent-role-policy.test.ts | 7 + packages/core/src/__tests__/agent-roles.test.ts | 21 + .../legacy-column-collection-gating-ledger.test.ts | 19 +- .../src/__tests__/postgres/schema-applier.test.ts | 16 +- .../core/src/__tests__/settings-parity.test.ts | 9 +- .../workflow-agent-node-classification.test.ts | 25 + .../src/__tests__/workflow-work-item-cas.test.ts | 38 ++ packages/core/src/agents/agent-permissions.ts | 11 +- packages/core/src/agents/agent-role-policy.ts | 39 +- packages/core/src/agents/agent-store.ts | 190 ++++++- .../core/src/async-stores/async-agent-store.ts | 6 + packages/core/src/config/settings-schema.ts | 5 +- packages/core/src/index.gate.ts | 2 +- packages/core/src/index.ts | 7 +- .../0045_fn_8764_multi_role_workflow_agents.sql | 20 + .../0046_fn_8764_workflow_principal_fence.sql | 49 ++ packages/core/src/postgres/schema-applier.ts | 22 +- packages/core/src/postgres/schema/project.ts | 21 + packages/core/src/store.ts | 2 +- .../task-store/async/async-workflow-workitems.ts | 49 +- packages/core/src/task-store/row-types.ts | 4 + packages/core/src/task-store/settings-helpers.ts | 16 +- packages/core/src/task-store/settings-ops-2.ts | 13 +- packages/core/src/task-store/settings-ops.ts | 16 +- packages/core/src/task-store/task-row-mappers.ts | 4 + .../src/task-store/workflow-task-create-ops.ts | 6 +- .../src/task-store/workflow-workitems-ops-2.ts | 25 +- packages/core/src/types.ts | 2 + packages/core/src/types/agents/agents.ts | 45 +- packages/core/src/types/merge/merge-queue.ts | 17 + packages/core/src/types/settings/settings-scope.ts | 9 +- packages/core/src/workflows/workflow-ir-types.ts | 58 +++ packages/core/src/workflows/workflow-ir.ts | 19 + .../dashboard/app/components/AgentDetailView.css | 14 + .../dashboard/app/components/AgentDetailView.tsx | 34 +- .../dashboard/app/components/NewAgentDialog.tsx | 28 +- .../app/components/WorkflowNodeEditor.tsx | 19 + .../__tests__/AgentDetailView.core.test.tsx | 4 +- .../app/components/__tests__/AgentsView.test.tsx | 2 +- .../__tests__/SettingsModal.general.test.tsx | 86 --- .../__tests__/SettingsModal.test-harness.tsx | 1 - .../components/agent-presets/agentCreatePayload.ts | 9 +- .../app/components/settings/section-keys.ts | 1 - .../settings/sections/GeneralSection.tsx | 8 - .../settings-default-descriptions.test.tsx | 1 - .../app/components/workflow-flow-mapping.ts | 7 + packages/dashboard/src/mission-routes.ts | 26 +- .../src/routes/__tests__/agent-core-routes.test.ts | 23 +- .../src/routes/register-agent-core-routes.ts | 42 +- ...gister-agent-import-export-generation-routes.ts | 21 - .../engine/src/__tests__/agent-action-gate.test.ts | 33 ++ .../engine/src/__tests__/agent-assignment.test.ts | 370 ------------- .../src/__tests__/ephemeral-worker-manager.test.ts | 575 --------------------- ...ecutor-ephemeral-disabled-dispatch-gate.test.ts | 223 -------- .../__tests__/executor-fast-mode-workflows.test.ts | 58 +++ .../engine/src/__tests__/log-severity-manifest.ts | 1 - .../__tests__/log-severity-spam-contract.test.ts | 3 - .../resolved-read-with-literal-filter.test.ts | 4 - .../__tests__/scheduler-ephemeral-toggle.test.ts | 175 ------- .../__tests__/scheduler-workflow-cutover.test.ts | 19 - .../src/__tests__/workflow-agent-capacity.test.ts | 47 ++ .../src/__tests__/workflow-agent-routing.test.ts | 137 +++++ .../src/__tests__/workflow-graph-foreach.test.ts | 15 + .../__tests__/workflow-graph-task-runner.test.ts | 73 +++ .../src/__tests__/workflow-task-runtime.test.ts | 95 ++++ .../src/__tests__/workflow-work-scheduler.test.ts | 20 + packages/engine/src/agents/agent-action-gate.ts | 64 +++ packages/engine/src/agents/agent-assignment.ts | 135 ----- packages/engine/src/agents/agent-reflection.ts | 1 + .../engine/src/agents/ephemeral-worker-manager.ts | 429 --------------- .../engine/src/agents/workflow-agent-capacity.ts | 113 ++++ .../engine/src/agents/workflow-agent-router.ts | 185 +++++++ packages/engine/src/execution/reviewer.ts | 26 +- packages/engine/src/executor.ts | 501 +++++++++++++++--- packages/engine/src/index.ts | 1 - packages/engine/src/merger.ts | 20 +- packages/engine/src/pi.ts | 11 + packages/engine/src/runtimes/in-process-runtime.ts | 37 -- packages/engine/src/scheduler.ts | 114 +--- packages/engine/src/triage.ts | 196 ++++++- .../src/workflows/workflow-graph-executor.ts | 109 +++- .../engine/src/workflows/workflow-graph-loop.ts | 13 +- .../src/workflows/workflow-graph-task-runner.ts | 12 + .../engine/src/workflows/workflow-task-runtime.ts | 125 ++++- .../src/workflows/workflow-work-scheduler.ts | 8 +- 98 files changed, 2722 insertions(+), 2468 deletions(-) Fusion-Task-Id: FN-8764 Fusion-Task-Lineage: 5527fccb-342d-46f6-8108-bbf89142efec Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
f7ca14beab |
feat(workflow): add fn_workflow_step_resume operator escape hatch for stuck pending merge-review steps (#3339)
## Summary Adds an **operator-only** escape hatch for a card stranded `in-review` (or `in-progress`) with a workflow step permanently stuck in `pending` status — the leading real-world cause being a dispatched prompt node (e.g. `code-review`) whose verdict callback was never received (see #1946). Transitions the stuck `pending` pre-merge step to `status: "failed"` with resume audit metadata, so the existing `fn_task_bypass_review` escape hatch can then clear the merge blocker. ## What changed - **`WorkflowStepResult`** gains resume audit fields: `resumedBy`, `resumedAt`, `resumeReason`, `resumedFromStatus`. They are pure audit trail and **do not** participate in merge-blocking (`getTaskMergeBlocker`). - **`findPendingPreMergeStep`** (new helper, exported from `@fusion/core`) summarizes the stuck-pending pre-merge state for operator tooling. Ignores post-merge steps; returns the newest pending pre-merge result. - **`TaskStore.resumeWorkflowStep(id, { stepId, reason, actor })`** — the store primitive (eligibility-gated: task must be `in-review`/`in-progress`, not paused; step must exist and be `pending`; a mandatory non-blank `reason` and `stepId` are required). Runs under `withTaskLock`, writes the resume as a terminal `failed` result, appends a task-log breadcrumb, and emits the new `task:resume-step` run-audit event. - **`fn_workflow_step_resume`** — new CLI/pi-extension tool registered **only** on the operator surface (deliberately **not** wired into executor/reviewer/triage agent tool lists). Accepts `{ id, stepId, reason }`; the actor defaults to `cli-operator`. - **Run-audit**: new `task:resume-step` `DatabaseMutationType` member. ## Why A prompt-node verdict callback can be lost (dispatched prompt never receives a verdict), leaving the step `pending` forever. Previously the only recourse was `fn_task_bypass_review`, which requires a terminal *failed* pre-merge step to clear the blocker — a permanently `pending` step could not be bypassed. This PR bridges that gap: resume (pending → failed) then bypass (failed merge-blocker cleared). ## Verification - **Typecheck**: `@fusion/core`, `@fusion/engine`, `@runfusion/fusion` all clean. - **`task-merge-bypass.test.ts`**: 15/15 pass (incl. 5 new `findPendingPreMergeStep` cases). - **`store-resume-step.test.ts`** (new, PG-backed): 9/9 pass — eligibility gating, resume rewrite + audit fields, run-audit event, non-pending/non-found/blank-argument rejection, in-progress column support, property preservation. - **`extension.test.ts`**: 75/75 pass (expected-tool registration includes the new tool). ## Files - `packages/core/src/types/workflow/workflow-steps.ts` - `packages/core/src/merge/task-merge.ts` - `packages/core/src/store.ts` - `packages/core/src/index.ts` - `packages/core/src/__tests__/store-resume-step.test.ts` (new) - `packages/core/src/__tests__/task-merge-bypass.test.ts` - `packages/engine/src/util/run-audit.ts` - `packages/cli/src/extension.ts` - `packages/cli/src/__tests__/extension.test.ts` - `.changeset/stas-032-resume-workflow-step.md` (minor, feature) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added an operator-only workflow recovery tool for permanently pending pre-merge steps. * Operators can mark eligible pending steps as failed by providing a required audit reason. * Recovery actions record operator details, timestamps, reasons, prior status, task logs, and audit events. * **Bug Fixes** * Improved selection of the latest pending pre-merge workflow step while excluding post-merge steps. * Added validation to prevent recovery of paused, invalid, or out-of-scope workflow steps. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: schindler <schindler@users.noreply.github.com> Co-authored-by: gsxdsm <gsxdsm@users.noreply.github.com> |
||
|
|
4739f8aa67 |
fix: eagerly warm extension host stores from engine TaskStores (#3340)
## Summary Warm the extension-host task stores **up front** at dashboard startup instead of letting the first `fn_task_*` call lazily boot a second PostgreSQL pool per project. ## What changed `packages/cli/src/commands/dashboard.ts`: - After the dashboard boots, iterate every registered project (from `centralCoreForEngine.listProjects()`) and call `setHostTaskStore(p.path, engine.getTaskStore())` for each non-cwd project that already has a running `ProjectEngine`. - Reuses each engine's **existing** `TaskStore` directly — no new backend connection, no schema advisory-lock contention, no extra connection-pool exhaustion. - `cwd` is skipped because its store is already injected at startup. - Per-project failures are non-fatal (warn) and a failed project listing logs a single warn — dashboard startup never blocks on this. - `.changeset/extension-host-store-warmup.md` (patch, fix). ## Why Left on its own, the first extension tool call (`fn_task_update`, `fn_task_archive`, `fn_agent_show`, …) for a non-cwd project falls through to `createTaskStoreForBackend`, which boots a **second** PostgreSQL connection pool on demand. On busy hosts that lazy boot can time out, or the call stalls behind pool/startup contention — the classic "first `fn_task_*` call is slow or errors" experience. Pre-populating from the already-running engines removes that lazy worst-case path entirely. ## Verification - `pnpm verify:fast` — PASS (13 steps, 115s): CLI `tsup` build green, scoped typecheck/build green, boot smoke green (`fn --help` + real `serve` with `GET /api/health` 200). - Cherry-picked cleanly onto current `origin/main` (`5532019fd`); branch is up-to-date with `origin/main` at PR time. ## Files - `packages/cli/src/commands/dashboard.ts` (+30) - `.changeset/extension-host-store-warmup.md` (new) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved dashboard startup reliability by reusing existing project task connections. * Prevented extension task tools from creating duplicate connection pools. * Added non-blocking warnings when individual project initialization or discovery fails. * Dashboard startup now reports how many project task stores were successfully prepared. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: gsxdsm <gsxdsm@users.noreply.github.com> |
||
|
|
1db7adcdb0 |
FN-8809: preserve agent principals for secret approvals
Keep prompt-gated secret approvals bound to their calling chat-agent session. - Resolve extension secret callers through async session identity context. - Give anonymous engine sessions unique principals and preserve them across tool invocations. - Surface actionable approval decision errors in the mailbox and cover approval flows. Files changed: .changeset/fn-8809-secrets-chat-approval.md | 7 + .../__tests__/extension-permission-gates.test.ts | 257 ++++++++++++++++++++- packages/cli/src/extension.ts | 96 +++++--- .../__tests__/session-identity-registry.test.ts | 27 +++ packages/core/src/index.ts | 4 +- packages/core/src/session-identity-registry.ts | 47 +++- packages/dashboard/app/components/MailboxView.tsx | 11 +- .../app/components/__tests__/MailboxView.test.tsx | 49 ++++ .../dashboard/src/__tests__/chat-manager.test.ts | 28 ++- .../__tests__/register-approval-routes.test.ts | 22 ++ .../src/__tests__/pi-create-fn-agent.test.ts | 210 ++++++++++++++++- packages/engine/src/pi.ts | 34 ++- 12 files changed, 748 insertions(+), 44 deletions(-) Fusion-Task-Id: FN-8809 Fusion-Task-Lineage: 2e070f78-7215-4401-bcf2-6fa25fa27066 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
2a0827835d |
FN-8810: wire secrets stores into runtime worktrees
Wire project secrets stores into runtime and dashboard heartbeat worktree acquisition. - Inject the project secrets store into executor and heartbeat monitors. - Cover in-process, UI-only dashboard, and secrets-env worktree materialization paths. - Add a patch changeset for restored secrets-env files. Files changed: .changeset/fn-8810-secrets-env-runtime-wiring.md | 7 ++ .../commands/__tests__/dashboard-supervise.test.ts | 28 ++++- packages/cli/src/commands/dashboard.ts | 38 ++++++- .../src/__tests__/in-process-runtime.pg.test.ts | 121 ++++++++++++++++++++- .../src/__tests__/secrets-env-writer.test.ts | 35 ++++++ .../worktree-acquisition-secrets-env.test.ts | 4 +- packages/engine/src/runtimes/in-process-runtime.ts | 9 ++ 7 files changed, 233 insertions(+), 9 deletions(-) Fusion-Task-Id: FN-8810 Fusion-Task-Lineage: a67c3fbe-7744-4898-8a56-8739caa04479 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
07dccbe2bd |
FN-8783: parallelize static merge-gate validators
Run independent static merge-gate policy validators concurrently without weakening gate ordering. - Add a fail-closed concurrent static-validator runner with coverage for inventory and failures. - Preserve curated engine, PostgreSQL, unit, and CI-shape gate contracts. - Document the gate composition and warm-cache performance policy. Files changed: docs/testing.md | 13 ++- package.json | 3 +- packages/cli/src/__tests__/ci-workflow.test.ts | 21 ++-- packages/engine/vitest.config.ts | 36 +++++-- .../__tests__/engine-vitest-gate-policy.test.mjs | 90 +++++++++++++---- scripts/__tests__/run-static-gate-checks.test.mjs | 100 +++++++++++++++++++ scripts/run-static-gate-checks.mjs | 106 +++++++++++++++++++++ 7 files changed, 332 insertions(+), 37 deletions(-) Fusion-Task-Id: FN-8783 Fusion-Task-Lineage: d5d3c9e1-b3c4-45ff-a3e7-f9555585cd70 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
9e4a0817db |
feat: restart the development engine on source changes (#3329)
## Summary Add an opt-in source-development loop that restarts the dashboard and engine when runtime TypeScript or JSON changes. Use `pnpm dev:watch`; `pnpm dev:hmr` now combines Vite UI HMR with the same supervised API/engine restart path. The watcher filters tests, fixtures, generated declarations, build output, and task state. It coalesces bursts with a two-second maximum wait, waits for the child to acknowledge its IPC listener, and rebuilds runtime dist artifacts before a source-triggered respawn. ## Safety model - Close scheduler, triage, heartbeat, mission, routine, self-healing, and merge admission before checking for active work. - Let already-running agents reach a safe boundary; do not mutate durable pause settings. - Enter the existing graceful exit-code-86 shutdown and supervised respawn path. - Retry failed liveness reads and declined restart requests instead of dropping the pending change. - Keep ordinary `pnpm dev` behavior unchanged; inherited watch state does not break nested non-dashboard development commands. A development restart intentionally replaces the dashboard process, so transient dashboard connections and project dev-server children reconnect or restart with it. Agent work is the protected boundary. ## Validation - `pnpm lint` - `pnpm test:gate` (753 tests passed across engine, core, PostgreSQL gate, and CI-shape suites) - Focused CLI watcher/restart/supervision suites: 40 tests passed - Focused engine drain/manager suites: 52 tests passed - `pnpm --filter @runfusion/fusion typecheck` - `pnpm --filter @fusion/engine typecheck` - `pnpm verify:fast` (13 steps passed, including CLI build and real health boot smoke) - Manual unsupported-command probe confirms explicit `--watch` fails clearly outside the dashboard command ## Post-Deploy Monitoring & Validation - Watch for `[fusion:dev] source changed`, `source restart deferred`, `active work drained`, and `restart requested` logs during the first watched development session. - Healthy behavior is one exit-86 respawn per edit batch, no interrupted active agents, refreshed dist artifacts, and a healthy dashboard after respawn. - Investigate repeated restart loops, watcher attachment warnings, declined restart retries, or liveness-read failures. - Immediate mitigation is to use ordinary `pnpm dev` without `--watch`; no production runtime behavior or durable setting needs rollback. - Validation owner: Fusion maintainers during the first source edit after merge. --- [](https://github.com/EveryInc/compound-engineering-plugin) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added `pnpm dev:watch` to automatically restart development runtime processes when source files change. * Development restarts now wait for active work to finish, preventing new work from starting during the transition. * Enhanced `pnpm dev:hmr` with graceful runtime source restarts while keeping the dashboard available. * Rapid source changes are grouped to avoid unnecessary restarts. * **Documentation** * Updated development setup and contribution guides with the new watch workflow. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
56819e21e9 | fix: restore plugin SDK and Todo packaging | ||
|
|
5d8d494230 |
fix(todos): restore clean build and navigation coverage (#3321)
## Summary - remove an unavailable jest-dom type from the Todo plugin production TypeScript build - update the dashboard navigation fixture for the plugin-owned Todo destination and root test id ## Test plan - `corepack pnpm --filter @fusion-plugin-examples/todos build` - `corepack pnpm --filter @fusion-plugin-examples/todos test` - `FUSION_DASHBOARD_DEEP=1 corepack pnpm --filter @fusion/dashboard exec vitest run app/components/__tests__/navigation-history.test.tsx --project dashboard-app-quality-components-a --silent=passed-only --reporter=dot` - `corepack pnpm check:changesets` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Restored CLI packaging for the bundled Todo Lists plugin. * Made `AgentStore` available to bundled plugins at runtime. * **Tests** * Updated navigation coverage for Todo Lists dashboard views, overflow placement, and ordering. * Added coverage for opening and dismissing the Todo view through browser history navigation. * Improved validation of runtime exports. * **Chores** * Simplified test type configuration for the Todo Lists plugin. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5b2b31d2c9 |
FN-8762: extract Todo Lists into bundled plugin
Move Todo Lists into a bundled, project-enabled plugin package. - Move Todo UI, client API, and server routes into the plugin package. - Register and bundle Todo as an enabled plugin dashboard view rather than a static host feature. - Preserve Todo route validation and server-error semantics, including task assignment agent lookup. - Keep disabled and legacy Todo views out of project navigation and main content. Files changed: .changeset/fn-8762-todos-plugin.md | 7 + AGENTS.md | 3 +- docs/PLUGIN_AUTHORING.md | 4 + docs/dashboard-guide.md | 4 + docs/todo-view.md | 151 +---- .../cli/src/plugins/staged-bundled-plugin-ids.ts | 1 + packages/cli/tsup.config.ts | 8 + .../core/src/board/mobile-nav-primary-items.ts | 2 - .../__tests__/bundled-plugin-install.test.ts | 2 + .../core/src/plugins/bundled-plugin-install.ts | 1 + packages/dashboard/app/App.tsx | 18 +- .../app/__tests__/lazy-loaded-views-docs.test.ts | 9 +- packages/dashboard/app/api/legacy.ts | 15 - packages/dashboard/app/api/system/index.ts | 1 - packages/dashboard/app/api/system/todo.ts | 85 --- packages/dashboard/app/components/Header.tsx | 23 +- .../dashboard/app/components/LeftSidebarNav.tsx | 1 - packages/dashboard/app/components/MobileNavBar.tsx | 4 - .../dashboard/app/components/SettingsModal.tsx | 2 - .../app/components/__tests__/App.test.tsx | 7 - .../app/components/__tests__/Header.test.tsx | 42 -- .../app/components/__tests__/RightDock.test.tsx | 18 +- ...skDetail.mobile-transition.board-panel.test.tsx | 1 - .../__tests__/TaskDetail.swipe-back.test.tsx | 1 - .../__tests__/TodoView.mobile-css.test.ts | 66 --- .../app/components/__tests__/TodoView.test.tsx | 649 --------------------- .../__tests__/navigation-history.test.tsx | 3 - .../__tests__/overflowViewRegistry.test.tsx | 118 +--- .../app/components/dashboard/MainContent.tsx | 27 +- .../dashboard/app/components/dashboard/types.ts | 6 +- .../app/components/overflowViewRegistry.tsx | 21 +- .../app/hooks/__tests__/useTodoLists.test.ts | 291 --------- .../app/hooks/__tests__/useViewState.test.ts | 11 + packages/dashboard/app/hooks/useAppSettings.ts | 5 - packages/dashboard/app/hooks/useViewState.ts | 5 + .../__tests__/registerBundledPluginViews.test.tsx | 14 + packages/dashboard/app/plugins/bundled-todos.d.ts | 5 + .../app/plugins/registerBundledPluginViews.ts | 18 + packages/dashboard/app/plugins/types.ts | 4 + .../src/__tests__/todo-documentation.test.ts | 68 --- .../dashboard/src/__tests__/todo-routes.test.ts | 577 ------------------ packages/dashboard/src/registry-manifest.json | 101 +++- packages/dashboard/src/routes.ts | 1 - .../src/routes/plugin-bundled-runtimes.ts | 1 + .../src/routes/register-integrated-routers.ts | 2 - packages/dashboard/src/shared/dashboard-views.ts | 6 - packages/dashboard/src/todo-routes.ts | 342 ----------- packages/dashboard/vite.config.ts | 8 + packages/dashboard/vitest.config.ts | 8 + packages/desktop/scripts/workspace-tools.ts | 1 + plugins/fusion-plugin-todos/README.md | 20 + plugins/fusion-plugin-todos/manifest.json | 6 + plugins/fusion-plugin-todos/package.json | 38 ++ .../fusion-plugin-todos/src/dashboard-interop.d.ts | 12 + plugins/fusion-plugin-todos/src/dashboard-view.tsx | 4 + .../src/dashboard/LoadingSpinner.tsx | 1 + .../src/dashboard}/TodoView.css | 0 .../src/dashboard}/TodoView.tsx | 16 +- plugins/fusion-plugin-todos/src/dashboard/api.ts | 15 + .../src/dashboard/projectStorage.ts | 3 + .../fusion-plugin-todos/src/dashboard/swrCache.ts | 6 + .../src/dashboard/useConfirm.ts | 1 + .../src/dashboard}/useTodoLists.ts | 4 +- plugins/fusion-plugin-todos/src/index.ts | 4 + .../fusion-plugin-todos/src/todo-routes.test.ts | 46 ++ plugins/fusion-plugin-todos/src/todo-routes.ts | 156 +++++ plugins/fusion-plugin-todos/tsconfig.json | 28 + plugins/fusion-plugin-todos/vitest.config.ts | 9 + pnpm-lock.yaml | 64 +- pnpm-workspace.yaml | 1 + 70 files changed, 671 insertions(+), 2531 deletions(-) Fusion-Task-Id: FN-8762 Fusion-Task-Lineage: 3beb502c-3793-451b-b357-50c243395410 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
cb57093d03 |
refactor: domain folder layout (types, API, core, engine) (#2398)
## Summary Wave 17 organizes Fusion into **domain folders** (stacks on #2397). ### Layout - **core/types/** — board, task, agents, settings, merge, workflow, mesh, … - **core/src/** — agents, ai, async-stores, workflows, tasks, config, db, … - **dashboard/app/api/** — client, tasks, agents, git, missions, planning, … - **engine/src/** — agents, auth, execution, merge, missions, overseer, worktree, … Root keepers retained for large entrypoints (`store.ts`, `executor.ts`, `merger.ts`, …). Public barrels (`@fusion/core`, `@fusion/engine`, `app/api.ts` → legacy) stay stable. ## Test plan - [x] `@fusion/core` typecheck - [x] `@fusion/engine` typecheck (pre-existing playwright-core noise only) - [ ] CI merge gate **Stack:** #2394 → #2397 → **this PR** |
||
|
|
86a749cac9 |
fix(ci): disable package-manager-cache on skip-install setup-node
actions/setup-node@v5 defaults package-manager-cache:true, so the agent-browser pack fixture still registered a pnpm store path and failed post-job with Path Validation Error after a successful pack/upload. Explicitly set package-manager-cache:false when skip-install is true. |
||
|
|
fb0863f660 |
FN-8753: enable installed voice input in project settings
Make Voice Input available only after its local model and runtime are ready. - Bundle the optional sherpa runtime with the published CLI. - Gate the project setting on model installation and stable runtime status codes. - Add localized recovery guidance, documentation, and coverage. Files changed: .changeset/fn-8753-voice-input-enable.md | 7 ++++ docs/dashboard-guide.md | 2 +- docs/settings-reference.md | 8 +++-- packages/cli/package.json | 3 ++ packages/cli/src/__tests__/package-config.test.ts | 16 +++++++++ .../settings/__tests__/VoiceInputSection.test.tsx | 36 ++++++++++++++++---- .../settings/sections/VoiceInputSection.tsx | 30 ++++++++++++----- packages/dashboard/package.json | 2 +- .../routes/__tests__/register-voice-routes.test.ts | 39 ++++++++++++++++++++++ .../dashboard/src/stt/__tests__/voice-stt.test.ts | 27 ++++++++++++--- packages/dashboard/src/stt/parakeet-service.ts | 26 ++++++++++----- packages/i18n/locales/en/app.json | 6 ++++ pnpm-lock.yaml | 6 +++- 13 files changed, 175 insertions(+), 33 deletions(-) Fusion-Task-Id: FN-8753 Fusion-Task-Lineage: db92b148-37f0-45d2-b616-ed2e3f2d54f6 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
6e416b044d |
chore(deps): bump actions/download-artifact from 4 to 8 (#3304)
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 8. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/actions/download-artifact/releases">actions/download-artifact's releases</a>.</em></p> <blockquote> <h2>v8.0.0</h2> <h2>v8 - What's new</h2> <blockquote> <p>[!IMPORTANT] actions/download-artifact@v8 has been migrated to an ESM module. This should be transparent to the caller but forks might need to make significant changes.</p> </blockquote> <blockquote> <p>[!IMPORTANT] Hash mismatches will now error by default. Users can override this behavior with a setting change (see below).</p> </blockquote> <h3>Direct downloads</h3> <p>To support direct uploads in <code>actions/upload-artifact</code>, the action will no longer attempt to unzip all downloaded files. Instead, the action checks the <code>Content-Type</code> header ahead of unzipping and skips non-zipped files. Callers wishing to download a zipped file as-is can also set the new <code>skip-decompress</code> parameter to <code>true</code>.</p> <h3>Enforced checks (breaking)</h3> <p>A previous release introduced digest checks on the download. If a download hash didn't match the expected hash from the server, the action would log a warning. Callers can now configure the behavior on mismatch with the <code>digest-mismatch</code> parameter. To be secure by default, we are now defaulting the behavior to <code>error</code> which will fail the workflow run.</p> <h3>ESM</h3> <p>To support new versions of the @actions/* packages, we've upgraded the package to ESM.</p> <h2>What's Changed</h2> <ul> <li>Don't attempt to un-zip non-zipped downloads by <a href="https://github.com/danwkennedy"><code>@danwkennedy</code></a> in <a href="https://redirect.github.com/actions/download-artifact/pull/460">actions/download-artifact#460</a></li> <li>Add a setting to specify what to do on hash mismatch and default it to <code>error</code> by <a href="https://github.com/danwkennedy"><code>@danwkennedy</code></a> in <a href="https://redirect.github.com/actions/download-artifact/pull/461">actions/download-artifact#461</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/download-artifact/compare/v7...v8.0.0">https://github.com/actions/download-artifact/compare/v7...v8.0.0</a></p> <h2>v7.0.0</h2> <h2>v7 - What's new</h2> <blockquote> <p>[!IMPORTANT] actions/download-artifact@v7 now runs on Node.js 24 (<code>runs.using: node24</code>) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.</p> </blockquote> <h3>Node.js 24</h3> <p>This release updates the runtime to Node.js 24. v6 had preliminary support for Node 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.</p> <h2>What's Changed</h2> <ul> <li>Update GHES guidance to include reference to Node 20 version by <a href="https://github.com/patrikpolyak"><code>@patrikpolyak</code></a> in <a href="https://redirect.github.com/actions/download-artifact/pull/440">actions/download-artifact#440</a></li> <li>Download Artifact Node24 support by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/download-artifact/pull/415">actions/download-artifact#415</a></li> <li>fix: update <code>@actions/artifact</code> to fix Node.js 24 punycode deprecation by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/download-artifact/pull/451">actions/download-artifact#451</a></li> <li>prepare release v7.0.0 for Node.js 24 support by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/download-artifact/pull/452">actions/download-artifact#452</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/patrikpolyak"><code>@patrikpolyak</code></a> made their first contribution in <a href="https://redirect.github.com/actions/download-artifact/pull/440">actions/download-artifact#440</a></li> <li><a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> made their first contribution in <a href="https://redirect.github.com/actions/download-artifact/pull/415">actions/download-artifact#415</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/download-artifact/compare/v6.0.0...v7.0.0">https://github.com/actions/download-artifact/compare/v6.0.0...v7.0.0</a></p> <h2>v6.0.0</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href=" |
||
|
|
006cc40454 |
FN-8685: add durable cross-process task deletion consumers
Deliver durable, replay-safe cross-process task deletion observation. - Add PostgreSQL lifecycle consumer cursors, leases, acknowledgements, retention, and recovery. - Start named consumers in dashboard, serve, and engine runtime paths. - Preserve delete integration metadata while suppressing replayed GitHub and GitLab side effects. - Cover outbox identity, observed delivery, fencing, and reconciliation behavior. Files changed: ...fn-8685-cross-process-task-deleted-observers.md | 7 + .../fn-8685-task-deleted-outbox-consumers.md | 7 + docs/architecture.md | 8 +- ...tgres-cross-process-task-deleted-observation.md | 8 +- docs/storage.md | 10 +- packages/cli/src/commands/dashboard.ts | 9 +- packages/cli/src/commands/serve.ts | 9 +- packages/cli/src/project-context.ts | 9 +- .../task-deleted-outbox-consumer.pg.test.ts | 157 ++++++++ ...-deleted-observed-dispatch-side-effects.test.ts | 36 ++ .../task-lifecycle-consumer-identity.test.ts | 22 ++ packages/core/src/index.ts | 11 + .../0041_fn_8685_task_lifecycle_consumers.sql | 88 +++++ packages/core/src/postgres/schema-applier.ts | 16 +- packages/core/src/postgres/schema/project.ts | 45 +++ packages/core/src/postgres/startup-factory.ts | 4 + packages/core/src/store.ts | 54 ++- .../__tests__/lifecycle-outbox-writer.test.ts | 4 +- .../core/src/task-store/archive-lifecycle-2.ts | 1 + packages/core/src/task-store/lifecycle-ops.ts | 13 +- packages/core/src/task-store/lifecycle-outbox.ts | 2 + packages/core/src/task-store/project-store-ops.ts | 4 +- .../src/task-store/task-deleted-outbox-consumer.ts | 333 +++++++++++++++++ .../task-store/task-lifecycle-consumer-identity.ts | 32 ++ .../task-store/task-lifecycle-consumer-registry.ts | 396 +++++++++++++++++++++ .../task-store/task-lifecycle-event-retention.ts | 104 ++++++ packages/core/src/task-store/task-mutation-ops.ts | 1 + packages/dashboard/src/github-tracking-state.ts | 12 +- packages/dashboard/src/gitlab-delete-close.ts | 3 + packages/dashboard/src/gitlab-split-close.ts | 7 +- packages/dashboard/src/project-store-resolver.ts | 9 +- packages/engine/src/project-manager.ts | 4 +- packages/engine/src/project-runtime.ts | 2 +- packages/engine/src/runtimes/in-process-runtime.ts | 17 +- packages/engine/src/self-healing.ts | 27 ++ 35 files changed, 1439 insertions(+), 32 deletions(-) Fusion-Task-Id: FN-8685 Fusion-Task-Lineage: 63eca9ac-d2af-44b0-ba79-388a950148d3 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
56e16d9dea |
test(cli): pin the board glyph's terminal-lane resolve (extract seam + pin) (#3238)
## What Pins the CLI board glyph's terminal-lane resolve — **the last flagged site in the repo-wide resolver audit.** Two commits: a behaviour-preserving extraction, then the test. ## I was wrong to flag this as unpinnable In #3236 I recorded this site as not pinnable, reasoning that *"extracting a pure helper and testing it would look like coverage and would not be."* That is true of a helper that **receives** the lane set — such a test passes with the resolve blinded, which is exactly the `reads.ts` trap the audit note records. It is **not** true of one that **resolves** it. Building `resolveReliabilityLanes` in #3237 made the distinction obvious: the seam has to contain the resolve, and then blinding fails a test of it. So the flag was too broad, and correcting it closes the site rather than leaving a permanent excuse. That is the same failure mode I corrected in someone else's note earlier today — a caution that hardens into a reason not to look. ## Measured ``` converted: Tests 5 passed (5) blinded: Tests 2 failed | 3 passed (5) ``` The two failures are the **renamed complete** and **renamed archive** lanes. The three survivors are the default-vocabulary control, the active-lane negative, and the degrade path — all of which should survive. ``` task-list-board-columns + bin: 82 passed typecheck clean; lint clean; fnxc-future-dates: none added ``` ## Why the sibling file did not cover it `task-list-board-columns.test.ts` pins `boardColumnsForDisplay`, which decides **which** lanes print. That function takes no lane set, so it cannot fail when this resolve is blinded — and its own header says so honestly. Two tests about the same command, one of which cannot see the other's bug. ## What breaks without the conversion On a board whose complete lane is `shipped`, a finished lane renders `●` — the same glyph as active work. The board says work is in flight when it shipped. Cosmetic next to the blank-board bug this area already fixed, but wrong in the direction an operator reads at a glance. ## Also pinned Two contracts the surrounding comments assert but nothing tested: - **Cards come from the TASKS, not a resolved IR** — a card must never depend on resolution succeeding to be *visible*. Asserted with an unreadable workflow list. - **A failed resolve degrades to the legacy pair**, with an unresolved custom lane rendering as active — the documented fail-open direction. Plus the paired negative: an ACTIVE lane keeps the active glyph under both vocabularies, so widening the terminal set cannot mark the whole board finished. ## Audit complete Every `resolveProjectColumnsForRoles` call site in the repository — `engine`, `core`, `dashboard`, `cli` — has now been blinded individually, and every uncovered one is either pinned or has a recorded reason it cannot be. Nothing is left flagged. |
||
|
|
d6079970e8 |
fix(self-healing): 18 recovery rebounds hardcoded todo and THREW on a renamed board (#3150, first slice) (#3152)
First slice of #3150. `self-healing.ts` held **26** `moveTask` calls with a legacy literal target; this converts the **18 `todo` rebounds**. ## Why this is worse than a guard, and documented already `task-store/moves.ts` records it from a previous incident: > `moveTaskInternal` **REJECTS** a target the workflow does not declare (`TransitionRejectionError: unknown-column`) … completion handoff did not silently no-op — it **THREW**. Every one of these 18 is a **recovery**. On a renamed board they threw instead of rebounding, so the strand each sweep exists to clear survived *and* the sweep reported failure. The reliability layer meant to be the backstop was the layer that broke. ## Why the census never saw it It counts **comparisons** against legacy ids. A move target is an **argument**. That is the third blind spot of the same instrument, and all three have now produced real defects found by hand: | blind spot | found this session | |---|---| | definitions | `GITHUB_TRACKING_EDITABLE_COLUMNS` — tracking unreachable on renamed boards (#3149) | | collections | swept: 30 sites, 29 already correct, 1 defect (the above) | | **targets** | **this** — 26 in one file, 31 tree-wide | ## Why 18 sites at once is safe `resolveReboundTargetForTask` **degrades to `"todo"`** when no workflow resolves, and `self-healing.ts` already used it at line 745. On every board we ship, the resolved answer *is* `todo` — so default behaviour is unchanged **by construction**, not by inspection. The control case pins exactly that, and it is the reason this can land as one change rather than eighteen. ## Scope, and what I deliberately did not touch Converted: the 18 `todo` rebounds. **Not** converted: the `done`, `archived` and `in-review` targets. They need different helpers and genuine reasoning about which lane a completion or an archive belongs in — converting them by analogy is exactly the half-conversion this program keeps paying for. Sites with no resolver in scope are unchanged. The audit behind the split is in the commit: of 26 sites, 5 had resolved lanes in scope, 4 had an IR, 17 had nothing — and `lanesOfReclaim` returns **Sets**, which is the wrong arity for a target (a move takes exactly one column, per the `moves.ts` note). ## Verification | | result | |---|---| | engine `tsc` | **0 errors** | | **all 43 self-healing suites** | **843 passed** | | census `--strict` | exit 0, **unchanged** — invisible to it | | `check-inert-sync-lanes` | exit 0 | | differential | restoring the literal → **1 failed \| 1 passed**, renamed case only | The new test drives a **public entry point** (`reconcileInReviewUnmetDependencies`, the FN-6793 contract) rather than calling the helper directly, so it covers the producer path too. One harness note worth keeping: the first version of the test failed **upstream** of the target, because the sweep selects rows via `resolveProjectColumnsForRoles` — a *project-level* resolver reading `listWorkflowDefinitions`, not the task's own selection. Without that mocked, the renamed card was never considered and the failure looked like the fix not working. That distinction (project-level vocabulary vs per-task IR) will bite the next slices too. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Tasks now move to workflow-specific rebound, completion, and archive columns instead of fixed default destinations. * Retrying and recovering tasks works correctly on boards with renamed lifecycle columns. * Added safe fallback behavior for workflows without custom lifecycle settings. * **Tests** * Added coverage to prevent legacy hardcoded task destinations and verify renamed-column recovery scenarios. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
7d9d097acf |
fix(cli): the TUI board fell back to the LEGACY workflow — it rendered a triage lane the default no longer has (#3178)
Found by following an unexplained number rather than by a sweep: while re-verifying #3141 the resolver reported `intake: "todo"` where `BUILTIN_CODING_WORKFLOW_IR` resolves `intake: "triage"`. That divergence is correct and intentional inside core — and wrong here. ## The defect `dashboard.ts` resolved a task's columns as `def?.ir ?? BUILTIN_CODING_WORKFLOW_IR`, and its card-chip fields the same way. That constant is the **legacy** monolithic IR (`builtin:legacy-coding`); the catalog's actual default is `resolveDefaultWorkflowIr()`. Post-U11 they differ **by a whole column**: ``` default todo, in-progress, in-review, done, archived (planning merged into todo) legacy triage, todo, in-progress, in-review, done, archived ``` So a task with **no workflow selection row** was rendered against a six-column board including `triage` — a lane the real default no longer declares. ## The same drift is already documented as fixed elsewhere `builtin-workflows.ts` records it: > `prepareWorkflowMovePolicyPreflightImpl` resolved the default through the catalog while `resolveTaskWorkflowIrForMove` used the raw constant, so a task with NO selection row produced two different workflow signatures and every flag-ON move threw *"workflow move policy preflight is stale"*. Both sides (and the sync resolver) now call this helper so the default cannot drift again. This surface was missed, and it is the **last non-test consumer of the legacy constant outside core**. ## Test scope, stated because it is narrow Driving the TUI end-to-end needs a rendered terminal and a live store. That harness does not exist here, and building one to assert a fallback would be testing the harness. So the test pins the two facts that make the bug possible and the fix meaningful: 1. **the two IRs genuinely disagree, about `triage` specifically** — if a future change re-merges them, this reports it rather than leaving the fix silently pointless; 2. **the source no longer reaches for the legacy constant.** (2) is a source assertion, weaker than driving the code. It is used for the same reason as the `FloatingWindow` aria-label scan: the defect is a **value at a call site**, there is no single render that reaches both sites, and a per-site render test would pin the one someone bothered to write. Both assertions are anti-vacuity guarded — the IR comparison fails if either side stops resolving to a v2 column set. ## Verification | | result | |---|---| | cli `tsc` | **0 errors** | | new test | **2 passed** | | mutation — restore `?? BUILTIN_CODING_WORKFLOW_IR` | **1 failed / 2** | | census `--strict`, `check-fnxc-future-dates` | exit 0 (this class is invisible to the census — an argument, not a comparison) | Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
25b3c06d2d |
fix(plugins): compound-engineering pipelines stalled forever on a renamed board (#3022)
Closes #3020 — which I filed **instead of** fixing, on a rationale that turned out to be wrong. I said the plugin had no scaffolding for faking `CePipelineStore` + `taskStore` together. It does: `_harness.ts` already builds a real `PluginContext` over a live PostgreSQL layer. The gap was **two missing readers on its task-store stub**, not missing infrastructure. I checked the harness only after filing. ## The defect `TERMINAL_COLUMNS` is `{in-review, done}`, and the reconciler advances a pipeline only when **every** current-stage board task is in that set. On a board whose review and completion lanes are renamed that's false for every task, permanently: - the pipeline never advances a stage - it never creates its outbound task - it sits `running` indefinitely Nothing errors, so it reads as work that hasn't finished. Unlike the display defects in this family (#3014, #3017), the CE flow actually **stops**. ## Shape The decision is extracted to an exported `isStageTerminalColumn` because it *is* the whole decision. Left private it could only be reached through a pipeline-state + links + board-tasks fixture, and the half that needed proving is that a renamed board resolves to its own lanes through this store. It uses `resolveReviewColumns` rather than re-deriving the union — that helper is the documented review **set** (`mergeOrchestration ∪ mergeBlocker ∪ humanReview`), so a board splitting those across a merge lane and a human lane is covered without this site drifting from it. ## Two things my first attempt got wrong **The fixture spelled traits in camelCase** — `{ trait: "humanReview" }`. Trait **ids** are kebab-case (`human-review`, `merge-blocker`, `wip`); the camelCase names are the resolved **flags**. Those columns therefore resolved to *no roles at all*, silently, because an unknown trait isn't an error. `complete` is spelled identically in both vocabularies, which is exactly what made the first run look like *"complete works, review is broken"* rather than *"the fixture is wrong"* — I nearly went debugging the production union. **The harness extension is additive** and inert until a test seeds it, so all 24 existing plugin suites see the previous shape. ## Measured | check | result | |---|---| | new suite | **4/4** | | reverting to the literal-only gate | fails **exactly 2** — the renamed-terminal case, and a board declaring a NON-terminal column named `done` — while the legacy control and the WIP/intake negative still pass | | plugin suite | **24 files, 184 tests green** | | `tsc` + all five gates | clean | That second row is the one that matters: the `done`-without-`complete` board is the only shape where a real resolution and a legacy fallback disagree, so it's what separates the fix from a lucky agreement. --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
f8155cafd7 |
fix(cli): the node-override guard saw only the FIRST wip lane (#3023)
Follow-up to #3019, which merged with an incomplete fix. I found this while sitting down to write the test that PR was missing. ## The guard still never fired, one lane over #3019 wired `fn_task_update`'s guard like this: ```ts const nodeOverrideLifecycle = await resolveTaskLifecycleColumns(store, task.id); wipColumns: nodeOverrideLifecycle?.wip ? new Set([nodeOverrideLifecycle.wip]) : undefined, ``` `resolveTaskLifecycleColumns` → `resolveLifecycleColumns`, whose per-role accessor is **first match** (`workflow-lifecycle-traits.ts:353`): ```ts const first = (flag) => resolved.find((c) => c.flags[flag] === true)?.id; ``` The guard's contract is **every** column carrying the trait — its own resolver uses `columnsWithFlag(ir, "countsTowardWip")`. So on a board with a build lane beside a verify lane, a task sitting in the **second** wip lane still slipped the mid-flight check, and an operator could still repoint the node of a running task. That is the defect #3019 set out to close. Interchangeable on any single-wip-lane board, which is exactly why it read as correct — the same arity trap #2975 removed from the surfacing family. ## The fix Use `resolveNodeOverrideLanes`, the guard's own resolver, which `task-update.ts` and `branch-and-pr-entities.ts` already call. All three callers now resolve identically and the V1/unresolvable fallback lives in one place. Needed a one-line re-export from `@fusion/core`. **Mutation:** forcing the resolver to first-match (`.slice(0, 1)`) fails the new case, 1 of 32. The new test names **two** wip lanes, because that is the only shape that separates the two resolutions — a single-wip-lane test passes against both, which is why #3019's gap was invisible and why I would have written a useless test if I had not read the implementation first. ## A gate constraint worth recording My first version passed the resolved object straight through: ```ts validateNodeOverrideChange(task, normalizedNodeId ?? null, overrideLanes) ``` Identical at runtime, and it turned the lane-wiring gate **red**: `check-lane-wiring` matches an object-literal argument and cannot see through a variable, so the correct call reads as UNWIRED. #3019's header records hitting the same constraint — and it is what pushed that PR toward resolving the lanes inline, which is where the first-match bug entered. So the gate's shape requirement steered a correct instinct into a subtly wrong implementation. The fix here spells both keys explicitly, satisfying the gate without the bespoke resolution. Worth someone deciding whether the census should follow a variable to its initializer — but that is a change to a shared ratchet, and I have noted it at the call site rather than making it. **Verified:** 32/32 core guard suite, `tsc` 0 errors for both packages, lane-wiring gate exit 0, FNXC gate exit 0, lint clean. --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
5659ccace9 |
test(cli): pin the node-override error contract on a renamed board, which is what #3019 actually changed (#3024)
## What #3019 actually changed, pinned — and a correction to my own claim I described #3019 as closing a hole where an operator could re-route a running task on a renamed board. **That was wrong.** `TaskStore.updateTask` runs the same guard with its own resolved lanes (`resolveNodeOverrideLanes`) and throws, so the change was refused either way. This test is how I found out: I wrote it to cover #3019's wiring and it passed against a tree with that wiring removed. A test that passes with the change reverted is not a test, so I went looking for what was really refusing — and it was the store. ## But the two paths *are* distinguishable, which my correction then got wrong in the other direction In correcting myself on #3019 I said the paths were externally indistinguishable and no test could separate them. Also wrong. Measured both ways: | | `details.error` | | --- | --- | | pre-check fires (wired) | `"task-in-progress"` — machine-readable reason code | | pre-check misses (unwired) | `"Cannot change node override for KB-001 while it is in progress…"` — the store's thrown prose | So on a **legacy** board a caller could branch on `task-in-progress`; on a **renamed** board it silently got a sentence instead. That is a real API inconsistency, visible only to whoever was parsing it — the kind of thing nobody notices until it breaks. That is what these cases pin, and it is the honest description of #3019's value: an error-contract fix, not a security fix. ## Revert proof With #3019's wiring removed: ``` Expected: "task-in-progress" Received: "Cannot change node override for KB-001 while it is in progress. …" Tests 1 failed | 1 passed (2) ``` Verified by actually reverting, not by reading the source — which is the discipline that caught both of my wrong claims above. The paired case ("still allows the override once the card leaves that wip lane") passes both ways by design; it guards against over-refusal, so I am not counting it as coverage of the contract. ## Also closes the gap I named in #3019 That PR shipped with `check-lane-wiring` as its only regression proof, and I said a behavioural test was owed. The two are complementary and fail for different reasons: **the ratchet** fails if the argument stops being passed; **this** fails if it is passed and the contract still degrades. ## Verification (measured) - **2 passed / 0 failed** - `tsc --noEmit` clean; `eslint` clean (one pre-existing warning, no errors) - `check-fnxc-future-dates`, `lifecycle-column-census --strict`, `check-lane-wiring` — green Tests only; no product file touched. No changeset. ## Note on the harness, for whoever writes the next one of these Seeding a card into a renamed lane has two traps, both inherited from `merge-blocker-renamed-review-lane.test.ts` and both recorded in this file's header: the real API is `createWorkflowDefinition` + `selectTaskWorkflow` (the plausible `saveWorkflowDefinition?.()` does not exist and the optional call swallows it silently), and moving a card takes `moveTask`, not `updateTask({ column })`. Both are guarded here by asserting the card really is in `building` before the subject runs. |
||
|
|
6f936f2de7 |
fix(cli): the node-override guard never fired on a renamed board, so mid-flight changes were allowed (#3019)
## The node-override guard never fired on a renamed board
`fn_task_update` called the guard with no options:
```ts
const validation = validateNodeOverrideChange(task, normalizedNodeId ?? null);
```
so `wipColumns` fell back to its documented default of
`{"in-progress"}`. On a board whose WIP lane is named anything else,
`wipColumns.has(task.column)` is false, the mid-flight check passes, and
**an operator can change the node override on a running task** —
precisely what that guard exists to refuse, in its own words:
> "Is this task executing right now?" — keyed on the literal, a renamed
board let an operator change the node override MID-FLIGHT on a running
task, which is exactly what this guard exists to refuse.
That note is attached to the `wipColumns` option added for this purpose.
The CLI simply never passed it.
## Two assumptions in the guard's own docs that did not hold
```
Both callers supply them. An omitted set keeps the legacy id, which is what a caller
without cheap IR access (a CLI tool, a route with only a task row) still gets.
```
1. **"Both callers"** — this is a *third* one, and it was in
`check-lane-wiring`'s known-unwired baseline the whole time.
2. **"a CLI tool … without cheap IR access"** — this handler is async
and has already awaited `store.getTask`, so one more resolve costs
exactly what `resolveTaskLifecycleColumns` already costs elsewhere **in
this same file** (the linked-lineage label at ~1239). The assumption was
reasonable in general and wrong here.
Passed present-but-conditionally-valued rather than as a conditional
argument: an omitted set still keeps the documented legacy default, and
only that shape is visible to `lane-wiring-census`, which matches an
object-literal argument and cannot see a ternary.
## Coverage — stated rather than implied
**There is no new unit test.** The regression guard is the ratchet
itself, and it is a real revert-proof: with the wiring removed,
```
[check-lane-wiring] call sites not passing a resolved lane argument INCREASED:
packages/cli/src/extension.ts: 1 unwired now, baseline allows 0
```
Verified by actually reverting it, not by assuming. Baseline re-recorded
19 → 18 in the same commit, so the allowance cannot be regrown into.
A behavioural test would need a custom workflow definition persisted
*and* selected inside the integration harness to get a card resting in a
renamed WIP lane. That is worth doing and I would take it as follow-up
harness work — but it is not part of this fix, and I would rather name
the gap than let "85 passed" imply coverage I did not write.
## Verification (measured)
- **85 passed** across `extension.test.ts`,
`extension-experiment-finalize.test.ts`,
`task-list-board-columns.test.ts`
- `tsc --noEmit`, `eslint` — clean
- `check-lane-wiring` (18, none added), `lifecycle-column-census
--strict`, `check-inert-flag-seams`, `check-fnxc-future-dates`,
`check:changesets` — green
Changeset included (`patch`): `packages/cli` is the published
`@runfusion/fusion` and this changes guard behaviour operators rely on.
|
||
|
|
72f5f8e51a |
fix(gate): the FNXC stamp gate never validated the hour, so 25:30 passed (#2995)
`check-fnxc-future-dates.mjs` validates the **date** portion of a stamp
and never looks at the clock time:
```js
const STAMP = /FNXC:[A-Za-z0-9_-]+\s+(\d{4}-\d{2}-\d{2})/g;
…
for (const match of source.matchAll(STAMP)) if (match[1] > today) hits += 1;
```
The capture stops before the hour, so a stamp may carry **any** `hh:mm`
and pass. Found while pre-flighting #2992, whose new comments read
`2026-07-30-25:30`.
## It is not one typo
Four stamps **already on `main`** carry a clock time that cannot exist:
```
packages/cli/src/__tests__/task-list-board-columns.test.ts:2 -24:40
packages/cli/src/commands/task.ts:29 -24:40
packages/cli/src/commands/task.ts:636 -24:40
scripts/check-lane-wiring.mjs:18 -24:00
```
Three separate authors, so this is the gate's blind spot rather than one
person's slip — and #2992 adds two more, which is how I noticed.
AGENTS.md specifies `yyyy-MM-dd-hh:mm`. The stamp's whole purpose is to
make the FNXC record a readable chronology of *why* code exists; a
timestamp that cannot exist quietly costs it that, and nothing was going
to catch it.
## The fix
Hours `00-23`, minutes `00-59`, counted per file **alongside** the
future-dated population rather than as a separate gate — same defect
class (a stamp that does not describe a real moment), and one ratchet is
cheaper to keep honest than two.
**Mutations, both directions:**
| stamp | result |
|---|---|
| `2026-07-30-25:00` | **flagged** |
| `2026-07-30-23:75` | **flagged** |
| clean tree | `475 known future-dated stamp(s), none added`, exit 0 |
## On the four existing stamps
Normalized by clamping the impossible hour to `23`, minutes preserved,
so relative ordering within each file survives. **That is a
normalization with a stated rule, not a claim about the true minute** —
`-24:40` most plausibly meant "just past midnight", but writing
`2026-07-31-00:40` would be future-dated against today's local calendar
and fail the very gate this PR extends. Clamping keeps every stamp real,
ordered, and non-future; the exact minute was already unrecoverable.
**Verified:** FNXC gate exit 0, lane-wiring gate exit 0,
`task-list-board-columns` 5/5, lint clean.
Comment-only changes to the CLI files (stamp text inside FNXC blocks),
so no behaviour change and no changeset.
Noted separately on #2992 so its two new stamps get corrected there
rather than landing and immediately failing this gate.
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
||
|
|
a57f6699b3 |
fix(cli): fn task list never printed cards in renamed columns (#2986)
## `fn task list` never printed cards in renamed columns
```ts
for (const col of COLUMNS) { // the legacy six ids
const colTasks = tasks.filter((t) => t.column === col);
```
A task in a workflow-defined column matches **no iteration**, so it is
not printed. This is not a wrong label or a wrong glyph — **the card is
absent**, and the output reads as a shorter, healthy board rather than
as a bug. On a fully renamed board the command prints nothing but the
header. `COLUMNS` also still contains `triage`, which U11 (#2515)
deleted.
## Found where the previous author left it
The `DELIBERATE-LITERAL` note directly above this loop is correct about
its own glyph, and it named the deeper bug rather than hiding it:
> NOT claimed as trait-resolved, and the deeper bug is left alone:
because the loop iterates the legacy enum, a card in a workflow-renamed
column is not rendered AT ALL. That is the R8/U10 surface change […] and
a far bigger fix than this glyph.
It also predicted the coupling: *"If this ever iterates
workflow-resolved columns, that difference becomes live and the right
answer is a trait lookup, not this."* So both move together — once the
loop can yield a custom id, the terminal test **must** stop being an id
comparison. Fixing only the loop would leave a renamed done-lane
rendering as active work.
## Two deliberate choices
**Lanes come from the tasks, not from a resolved IR.** A board can span
several workflows and therefore has no single column list, and a card
must never depend on a resolution succeeding in order to be *visible*.
Legacy ids keep their familiar order and labels; anything else follows
alphabetically, so output is deterministic.
**Terminal lanes are resolved**, via
`resolveProjectColumnsForRoles(TERMINAL_ROLES)` — that is a display
question with a real answer, and this function is async with a store in
hand. Best-effort: a failed resolve falls back to the legacy pair rather
than failing the command, and an unresolved custom lane renders as
*active*. Showing a finished card with the wrong glyph is a far smaller
error than the blank board this replaces.
## Coverage, and its limit stated plainly
The lane-selection decision is extracted to an exported seam and tested
there. It is **not** end-to-end: `runTaskList` resolves a real project
context and ends in `process.exit`, so driving it would need the
mock-the-world shell `docs/testing.md` tells us to avoid when a narrower
seam exists. The call site is held by the compiler instead — the loop's
only source of lanes is that function. I have written this in the test
file rather than leaving it implied, because "5 passed" on a helper
could otherwise read as proof of the command's behaviour.
Reverted — the seam returning `[...COLUMNS]`, which is exactly what the
loop did — **all 5 cases fail**:
```
AssertionError: expected [ 'triage', 'todo', …(4) ] to deeply equal [ 'backlog', 'building', 'checking' ]
AssertionError: expected [ 'triage', 'todo', …(4) ] to deeply equal [ 'todo', 'shipped' ]
Tests 5 failed (5)
```
## Verification (measured)
- **86 passed / 3 files** — new suite plus `bin.test.ts` and
`pr-merge-review-lane.test.ts`
- `tsc --noEmit`, `eslint` — clean
- `lifecycle-column-census --strict`, `check-lane-wiring` (26, none
added), `check-fnxc-future-dates` — green
- `pnpm check:changesets` — clean; changeset included (`patch`), since
`packages/cli` is the published `@runfusion/fusion` and this is
user-facing
|
||
|
|
be79fe0db6 |
fix(cli): PR merges silently never ran on a renamed board — the blocker was asked about in-review (#2976)
## PR merges silently never ran on a renamed board
`processPullRequestMergeTask` called its injected blocker with the task
alone:
```ts
if (getTaskMergeBlocker(task)) return "skipped";
```
So `options.reviewColumns` was undefined and the blocker's identity
check fell back to `task.column === "in-review"`. On a board whose merge
lane is named anything else it returns:
```
task is in 'checking', must be in 'in-review'
```
…which is truthy, so this function returns `"skipped"`. **Silently and
permanently** — nothing logs, nothing fails, the PR simply never merges.
`daemon.ts`, `serve.ts` and `dashboard.ts` all drain PR merges through
here, making this a third instance of the #2963/#2964 class ("merge
entry points unwired — merging was impossible on a renamed board").
Found via the baseline #2966 shipped:
`packages/cli/src/commands/task-lifecycle.ts` was a known-unwired call
site in it.
## Narrow resolution, deliberately
`resolveReviewColumns` is the **broad** set, and its own FNXC note warns
that a caller which admits on it *and then moves the card* will act on
cards the engine does not consider in review. This function merges and
moves to the complete lane — a state-changing admission — so it uses
`resolveMergeOrchestrationColumn`, the single lane the engine acts on.
That matches how `moves.ts` wires the same call.
Degradation is unchanged in both directions: `resolveWorkflowIrForTask`
substitutes the default IR rather than throwing, so a default board
resolves `in-review` and behaves identically; a v1-upgraded IR resolves
every role empty and keeps the documented legacy literal (covered by a
test).
## One shape choice worth flagging
The option is always **passed** and conditionally **valued**:
```ts
getTaskMergeBlocker(task, { reviewColumns: mergeLane ? new Set([mergeLane]) : undefined })
```
rather than making the whole argument conditional. These are identical
at runtime — the blocker treats an undefined `reviewColumns` exactly as
it treats absent options — but **only this shape is visible to
`lane-wiring-census.mjs`**, which matches an object-literal argument and
cannot see a ternary. I wrote the ternary first, and the gate still
reported the site as unwired; wiring a gate cannot check is how this
defect survived in the first place.
The gate then confirmed the fix and asked for the baseline in the same
commit:
```
[check-lane-wiring] unwired call sites decreased:
packages/cli/src/commands/task-lifecycle.ts: 1 -> 0
```
Baseline re-recorded 9 → 8 in this commit, so the allowance cannot be
regrown into.
## Revert proof
**There was no test for this function at all** — that is why it went
unnoticed. Restoring only `task-lifecycle.ts`:
```
AssertionError: expected "vi.fn()" to be called with arguments: [ ObjectContaining{…}, …(1) ]
AssertionError: expected 'skipped' not to be 'skipped'
AssertionError: expected "vi.fn()" to be called with arguments: [ ObjectContaining{…}, undefined ]
Tests 3 failed | 1 passed (4)
```
The one case that passes both ways is "still skips a card that is not in
any merge lane" — it guards against over-admission rather than proving
the fix, and I am not claiming it as coverage of the defect.
## Verification (measured)
- new suite **4/4**; with `pr-automerge-cleanup` **9 passed / 2 files**
- `tsc --noEmit`, `eslint` — clean
- `check-lane-wiring` (8, none added), `lifecycle-column-census
--strict`, `check-sql-column-literals`, `check-fnxc-future-dates` —
green
**Changeset added** (`patch`). `packages/cli` is the published
`@runfusion/fusion` and this changes user-facing merge behaviour, so
AGENTS.md requires one. My first pass hedged and left it to a maintainer
— that was wrong, the rule is not discretionary, and it is now in the
branch.
|
||
|
|
dd930c8d7d |
fix(cli): qualify cross-fork PR heads (#2377)
## Summary - resolve the repository receiving pushes through `git remote get-url --push origin` - qualify pull-request head branches with the fork owner when the push owner differs from upstream - preserve the existing unqualified head for same-repository workflows ## Root cause Fusion correctly resolved the PR target from origin's fetch URL, but assumed the pushed branch lived in that same repository. With an upstream fetch URL and a fork push URL, GitHub requires `fork-owner:branch`; the unqualified branch is rejected. ## Validation - CLI task lifecycle tests: 48 passed - `@fusion/core` typecheck - `@runfusion/fusion` typecheck - strict changeset validation <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Pull requests created from branches pushed to contributor forks now correctly qualify the PR head with the fork owner when the push remote differs from the upstream owner. * Improved PR head handling across both group/shared-branch and per-task pull request creation paths. * **Tests** * Updated and expanded lifecycle tests to cover “origin push to fork” scenarios using push URL–based repo resolution. * **Documentation** * Added a patch release note for the fork-aware PR head fix. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: v <v@v.speedport.ip> Co-authored-by: gsxdsm <gsxdsm@users.noreply.github.com> |
||
|
|
189f237a07 |
fix(security): make the approval and permission gates actually enforce (#2457)
## Why
An AI agent autonomously deleted a live task (FN-8609) via
`fn_task_delete`. Investigating that led to two audits, which found the
gate machinery is well-built and its *enforcement* well-tested — but the
*decision boundary* was unguarded and the tools that matter never
reached the gate at all.
The headline defect: all ~76 tools in `packages/cli/src/extension.ts`
are delivered through `hostExtensionPaths` → `DefaultResourceLoader`,
which never passes through `wrapToolsWithActionGate`. `fn_task_delete`
*was* classified as gated in `gating-classifications.ts` — that
classification was dead code. Roughly 15 destructive tools were ungated
even for an operator who had locked their policy all the way down.
Second: `POST /api/approvals/:id/decision` took the approver identity
from the request body, validated for shape only, with no check that the
decider was human or differed from the requester. Combined with a bash
tool whose command string was never inspected (only `params.cwd`), an
agent could read the daemon token from `~/.fusion/settings.json`, find
its own pending request, and approve it.
## Scope
This does **not** tighten defaults. The `unrestricted` preset is
byte-for-byte unchanged — `git diff` on `agent-permission-policy.ts` is
empty — and regression tests assert that an out-of-the-box install
behaves exactly as before. The bug was never "the default is too
permissive"; it was "strict policy doesn't enforce." This makes turning
security up actually work.
The one deliberate exception: the containment that stops an agent
escalating its *own* privileges (reading the daemon token / credentials,
calling the approvals API to self-approve) applies at every preset
including `unrestricted`. That is a privilege-escalation boundary rather
than a permission preference — if it only engaged under strict policy it
would not have prevented the incident that prompted this.
## What changed
8 bisectable commits:
- **Approval lifecycle** — self-approval blocked via server-derived
deciders; same-verdict replay 409s; decide re-reads and re-validates
inside the transaction; expiry TTLs; `markCompleted` ownership check;
session identity registry in core.
- **Engine gates enforce for real** — unclassified tools resolve to a
policy-governed category instead of hardcoded `allow`; missing-policy
fail-open closed; bash containment floor + exact-command approval
binding.
- **Dashboard decision routes** — stop trusting client-supplied actors
(decision, bypass-review, worktrunk → 403 on forged actors).
- **`fn serve` authenticated by default** — auto-mints a token following
the existing `fn dashboard` precedent; `--no-auth` opts out.
- **Sibling entry points closed** — user-sourced hard-cancel moves, ACP
execute-once approvals, plugin task-store gating.
- **pi-extension principal resolution** — the extension resolves the
acting principal and can withhold or policy-gate the previously ungated
destructive tools.
- **Root-cause bonus fix** — `findLatestByDedupeKey` was broken in
PostgreSQL backend mode (already-parsed jsonb fed through a string-only
parser), so approved-grant redemption **never matched in production**,
minting duplicate requests. This explains the live DB state of 17
approved / 0 completed. *(Also cherry-picked to `main` as `a9b30013bb`,
since it is an active production defect on its own.)*
- **Review follow-ups** (`627f1b1fa8`) — operator-configured
provisioning privilege and a configurable grant TTL; see below.
## Review follow-ups
**Provisioning privilege is operator-configured, not role-derived.**
`isCallerPrivileged` had gone from `caller.reportsTo == null` (every
top-level agent privileged — permanent escalation by creating a
manager-less agent) to `caller.role === "ceo"`, which swapped an
implicit rule for a magic string: any agent config can claim that role,
while an operator who genuinely wants a privileged agent had no
supported way to say so. Privilege now derives solely from
`agentProvisioning.trustedAgentIds` / `trustedRoles` and fails closed
when settings are unresolvable.
It is also no longer forwarded to `resolveAgentProvisioningPolicy` as
`isPrivileged`, because that flag short-circuits ahead of
`alwaysApproveDelete` — a trusted caller was bypassing delete approval
entirely. The policy applies the same trusted rules itself, in the right
order. The function now governs only the org-chart escape hatch (acting
outside your own direct reports).
**Grant TTL defaults to 1 hour and is configurable.** Approval →
redemption is not instantaneous: an operator approving from their phone,
an engine restart, a queued lane, or a task waiting on a worktree all
routinely exceeded 15 minutes, after which the grant expired and the
agent silently re-requested. One hour remains far short of the
"redeemable forever" hazard the TTL exists to bound. Override via
`FUSION_APPROVAL_GRANT_TTL_MS` or `configureApprovalRequestTtls()`;
invalid overrides are ignored rather than widening the window to
infinity or collapsing it to zero.
## Behavior changes requiring operator review before rollout
1. `fn serve` requires a bearer token by default (`--no-auth` opts out);
unauthenticated clients get 401.
2. Agents can no longer run withheld destructive tools
(`fn_task_delete`, `fn_task_bypass_review`,
mission/milestone/slice/feature/workflow deletes, `experiment_finalize`,
`skills_install`). Operators keep them via CLI/dashboard. **This is the
incident fix.**
3. Agents get provisioning privilege only when the operator lists them
in `agentProvisioning.trustedAgentIds` / `trustedRoles`; the
provisioning gate is now live in production. Previously-implicit
privilege (top-level position, or a `ceo` role) no longer grants
anything on its own.
4. Decision replay 409s (was 200); pending approvals expire after 24h,
approved grants after 1h (configurable); bash approvals bind per exact
command.
5. Forged/body actors on decision, bypass-review, worktrunk routes →
403; `archive-all-done` requires `{confirm:true}` (external scripts
affected).
6. `fn_secret_get` approvals grant exactly one reveal (previously
granted nothing and looped forever); ACP approvals are execute-once
(previously infinite reuse).
7. Bash containment denies token/credential/approvals-API commands in
all agent sessions at every preset.
## Verification
Independently re-run against the branch, not just self-reported:
- 5 typechecks (core, engine, cli, dashboard `tsconfig.json` +
`tsconfig.app.json`) — clean
- `pnpm lint` — clean
- `pnpm test:gate` — 379 passed
- `pnpm build --force` — green (a plain `pnpm build` skips packages as
unchanged and does **not** compile the branch)
- `pnpm check:changesets` — clean
- ~650 file-scoped tests including new negative-path suites for the
decision boundary, which previously had **zero** test coverage
`packages/engine/src/__tests__/plugin-runner.test.ts` fails 56/80 —
**verified pre-existing**, reproducing identically at base commit
`93a403af67` on `main`. Not in the merge gate.
### A mutation check that failed to fail
Worth recording, because it nearly shipped an untested security fix. The
first mutation check on the provisioning change reintroduced the `ceo`
hardcode and **all 17 tests still passed** — the tests asserted through
the policy path, which can no longer observe `isCallerPrivileged` at
all, precisely because `isPrivileged` is no longer forwarded there.
Org-chart cases that do exercise the function were added; the hardcode
now fails exactly 1 of 19, and restoring is green. A green mutation run
is only meaningful if the test can actually see the code under test.
## Known limitations (stated, not papered over)
- The bash containment floor is string-matching: a cost-raiser, not a
sandbox. Quoting, encoding, `$HOME`, symlinks, or an interpreter
one-liner can evade it. The durable protection is the decision route
refusing agent-originated deciders — the filter is the belt, not the
braces.
- Approval expiry is lazy (evaluated at decide/complete/redeem), not
swept, so an expired pending row stays visible in lists until touched.
- The extension's require-approval path returns a pending message but
cannot suspend a pi session mid-turn; engine-side pause hooks cover
engine lanes only.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Security**
* Hardened approval and permission gating with server-side decider
attribution, self-approval blocking, ownership checks, replay/race
protection, and status/TTL enforcement.
* Added fail-closed behavior for sensitive/unclassified tools and
sandbox provisioning approvals.
* Blocked credential/approval access via bash containment; plugin
destructive task operations now require explicit permission.
* **New Features**
* `fn serve` now defaults to bearer-token auth, with `--no-auth` as the
explicit opt-out.
* **Bug Fixes**
* Improved task move-source attribution (`moveSource: "user"`) and
tightened dashboard archive/bypass confirmation and operator attribution
behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
|