Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
50 commits
Select commit Hold shift + click to select a range
7d373bd
docs(plan): Branch 5, AQE store integrity
pacphi Sep 27, 2026
1925fec
fix(aqe): recognize every plain npx spelling of AQE's server
pacphi Sep 27, 2026
eb6755d
refactor(heal): remove the AQE solver heal that never installs anything
pacphi Sep 27, 2026
f35d371
fix(verify): do not record failures of an unmanaged AQE backend
pacphi Sep 27, 2026
ce097df
fix(aqe): say the embedder is verified, not that pattern search works
pacphi Sep 27, 2026
5eec3a0
docs(aqe): name agentic-qe#574 as the busy rule's removal condition
pacphi Sep 27, 2026
61f7bcd
docs(plan): Branch 5 pins AQE_STORAGE_PATH too (B5-D1a)
pacphi Sep 28, 2026
0296c6c
fix(aqe): pin AQE to the project root
pacphi Sep 28, 2026
2f13f04
fix(verify): run provider checks from the project root without writing
pacphi Sep 28, 2026
abe3d75
fix(aqe): show the pin's hand fix even while other keys are still to …
pacphi Sep 28, 2026
4ab63ed
fix(aqe): pin AQE in the project Codex shell environment too
pacphi Sep 28, 2026
f0da2f6
chore(git): ignore ak's pin and embedding receipts and backups
pacphi Sep 28, 2026
0dfe393
docs(upstream-watch): the dispatch routine runs on a daily schedule
pacphi Sep 28, 2026
38ef6b4
feat(aqe): find the processes holding an AQE store
pacphi Sep 28, 2026
6061832
feat(aqe): merge stray AQE stores into the project store, then archiv…
pacphi Sep 28, 2026
9442e83
fix(status): name ak x aqe-store merge as the hand fix for stray AQE …
pacphi Sep 28, 2026
f770c1f
fix(aqe): read lsof's silent exit 1 as no holder
pacphi Sep 28, 2026
5584897
fix(aqe): take the merge's AQE version from the aqe it runs
pacphi Sep 28, 2026
f84e97e
test(aqe): give the holder tests' child processes an explicit env
pacphi Sep 28, 2026
a69f272
feat(aqe): leave AQE's starter patterns out of a store merge
pacphi Sep 28, 2026
9fdac7c
chore(upstream): sunset agentic-qe-3.13-external-provider-contract af…
pacphi Sep 28, 2026
e2e9c61
chore(upstream): sunset agentic-qe-3.14.0-stop-hook-generator after i…
pacphi Sep 28, 2026
76696c7
chore(upstream): record Branch 5 evidence and retire finished threads
pacphi Sep 28, 2026
9cf5861
docs(aqe): one AQE store per project; record Branch 5 decisions
pacphi Sep 28, 2026
482b1ea
fix(aqe): a killed or timed-out lsof is an incomplete holder check
pacphi Sep 28, 2026
3fbcc97
fix(aqe): stop the stray search at nested repositories
pacphi Sep 28, 2026
a37edf2
fix(aqe): take AQE's relative memory path back after an AQE re-init
pacphi Sep 28, 2026
88e76e7
fix(aqe): release the pin without leftovers
pacphi Sep 28, 2026
70d7b07
fix(aqe): never pin a file git tracks
pacphi Sep 28, 2026
77c795e
fix(aqe): refuse a merge into a store that already fails its checks
pacphi Sep 28, 2026
a4980a7
fix(aqe): never archive a stray that changed after its copy
pacphi Sep 28, 2026
0d1e607
fix(aqe): journal a merge before its real import
pacphi Sep 28, 2026
e11de13
fix(aqe): keep usage of starter patterns the root already holds
pacphi Sep 28, 2026
cb2ec3c
fix(aqe): show experiences a merge skips because the root has their id
pacphi Sep 28, 2026
9e6e36e
fix(aqe): report a cross-device move whose source removal failed part…
pacphi Sep 28, 2026
cf99937
docs(aqe): give the merge restore steps in order and say what they di…
pacphi Sep 28, 2026
1a6b652
refactor(aqe): keep the pin and merge functions under the complexity …
pacphi Sep 28, 2026
742021e
fix(setup): say which AQE Codex hooks and skills exist after aqe init
pacphi Sep 28, 2026
63107d0
chore(upstream): keep agentic-qe-3.14.0-codex-guidance-policy after i…
pacphi Sep 28, 2026
52bfa71
test(live): opt-in Codex guidance conformance for agentic-qe#655
pacphi Sep 28, 2026
6d62d50
docs(aqe): say what ak x aqe-store status runs, and describe the revi…
pacphi Sep 28, 2026
044a3f6
docs(aqe): record the Branch 5 review fixes in the ADRs, audit and plan
pacphi Sep 28, 2026
bd2ad43
test(aqe): give the pin test's git probe an explicit env
pacphi Sep 28, 2026
9ca3441
fix(status): no "not pinned" row for a tracked file ak is about to re…
pacphi Sep 28, 2026
10c7db2
fix(aqe): word two merge messages for the cases they missed
pacphi Sep 28, 2026
d77ae7a
fix(setup): name the upstream AQE issue for missing Codex hooks and s…
pacphi Sep 28, 2026
6bfb4ea
chore(upstream): watch the AQE issues filed on 2026-09-27
pacphi Sep 28, 2026
e7a43db
docs(upstream-watch): the reporting standard for upstream issues
pacphi Sep 28, 2026
1b6b2a0
test(verify): own the AQE embedder environment in the unmanaged-backe…
pacphi Sep 28, 2026
fc7624f
test(aqe): compare pin file paths without assuming a separator
pacphi Sep 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 5 additions & 4 deletions .github/workflows/upstream-watch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,9 @@ name: upstream-watch
# The upstream watch (docs/UPSTREAM-WATCH.md, decision 14). The script decides
# everything: which ledger comments count, where the check starts, and the
# comment's text. This workflow only posts that text on the ledger issue and
# labels the issue when a released fix is ready to dispatch, which fires the
# dispatch routine. No model runs here.
# labels the issue when a released fix is ready to dispatch. The label is a
# marker for people reading the issue; the dispatch routine runs on its own
# daily schedule and reads the ledger. No model runs here.

on:
schedule:
Expand Down Expand Up @@ -107,14 +108,14 @@ jobs:
length=$(gh api "repos/$repo/issues/comments/$id" --jq '.body | length')
echo "Posted length $length (file $(wc -c < body.md))"
[ "$length" -gt 0 ]
- name: Signal the dispatch routine
- name: Mark the ledger issue for dispatch
if: env.POST == 'true'
run: |
[ "$(jq -r '.dispatch | length' watch.json)" -gt 0 ] || { echo 'Nothing to dispatch.'; exit 0; }
issue=$(jq -r '.watchPolicy.ledger.issue' "$REGISTRY")
repo=$(jq -r '.watchPolicy.ledger.repo' "$REGISTRY")
gh label create "$DISPATCH_LABEL" --repo "$repo" --color 5319e7 \
--description 'The upstream watch has a released fix to dispatch' --force
# Remove, then add: a label already present would fire no new event.
# Remove, then add, so the issue's timeline shows the latest run that found work.
gh issue edit "$issue" --repo "$repo" --remove-label "$DISPATCH_LABEL" || true
gh issue edit "$issue" --repo "$repo" --add-label "$DISPATCH_LABEL"
7 changes: 7 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,13 @@ test-*.log
!/.agents/skills/upstream-status/
.codex/
.mcp.json
# ak's receipts and backups beside the gitignored .mcp.json (AQE pin: aqe-project-pin.mjs;
# AQE embedding: aqe-embedding-projection.mjs). The ones beside .claude/ and .codex/ files
# are already covered by those folders.
.mcp.json.agentic-kit-aqe-pin.json
.mcp.json.ak-aqe-pin-backup.*
.mcp.json.agentic-kit-aqe-embedding.json
.mcp.json.ak-aqe-backup.*
ruvector.db
*.db
CLAUDE.md.backup
Expand Down
2 changes: 2 additions & 0 deletions MAINTAINER.md
Original file line number Diff line number Diff line change
Expand Up @@ -107,6 +107,8 @@ docs/
`docs/adr/0051-supported-peer-delegation-and-host-realignment.md`,
`docs/adr/0054-fleet-evidence-export.md`, `docs/adr/0055-aqe-embedding-lifecycle.md`,
`tests/live/aqe-external-provider-transport.test.mjs`,
`tests/live/aqe-stop-hook-conformance.test.mjs`, `tests/live/aqe-codex-guidance-conformance.test.mjs`
(opt-in AQE conformance: `pnpm test:aqe-stop-hook-live`, `pnpm test:aqe-codex-guidance-live`),
`tests/live/qe-court-participant-transport.test.mjs` (with its helper
`tests/live/disposable-memory-project.mjs`),
`tests/live/codex-context-contract.test.mjs`, and
Expand Down
4 changes: 3 additions & 1 deletion bin/agentic-kit.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -45,6 +45,7 @@
'aqe-embedding': () => import('../src/commands/x/aqe-embedding.mjs'),
'admin': () => import('../src/commands/x/admin.mjs'),
'aqe-provider': () => import('../src/commands/x/aqe-provider.mjs'),
'aqe-store': () => import('../src/commands/x/aqe-store.mjs'),
'daemon-gc': () => import('../src/commands/x/daemon-gc.mjs'),
'dashboard': () => import('../src/commands/x/dashboard.mjs'),
'harvest': () => import('../src/commands/x/harvest.mjs'),
Expand Down Expand Up @@ -93,6 +94,7 @@

Plumbing (power users) — each takes --help:
ak x aqe-embedding [status|configure|prepare|verify] AQE semantic backend lifecycle
ak x aqe-store [status|merge] [--yes] merge stray AQE stores into the project store, then archive them
ak x admin [--port N] maintainer-only telemetry admin (localhost; GitHub/npm egress)
ak x daemon-gc [--kill] list/stop stale ruflo daemons
ak x dashboard [--port N] local health and guarded maintenance dashboard (localhost only)
Expand All @@ -109,7 +111,7 @@
/** True if the arg list is asking for help rather than an action. */
const wantsHelp = (args) => args.includes('--help') || args.includes('-h');

async function main() {

Check warning on line 114 in bin/agentic-kit.mjs

View workflow job for this annotation

GitHub Actions / quality (typecheck, lint, build, audit)

Async function 'main' has a complexity of 46. Maximum allowed is 25
const argv = process.argv.slice(2);
let cmd = argv[0];
let rest = argv.slice(1);
Expand Down Expand Up @@ -218,7 +220,7 @@
// setup and host own complete mutation/reporting flows. Running the generic
// nudge after a declined trust preflight could write version-cache state and
// violate their "before any changes" boundary.
if (!values.json && !values['dry-run'] && !['sync', 'usage', 'telemetry', 'models', 'setup', 'host', 'audit', 'heal', 'maintain', 'ruflo-mcp', 'aqe-provider', 'aqe-embedding'].includes(cmd)) {
if (!values.json && !values['dry-run'] && !['sync', 'usage', 'telemetry', 'models', 'setup', 'host', 'audit', 'heal', 'maintain', 'ruflo-mcp', 'aqe-provider', 'aqe-embedding', 'aqe-store'].includes(cmd)) {
try {
const { driftReport } = await import('../src/lib/versions.mjs');
for (const r of await driftReport()) {
Expand Down
15 changes: 11 additions & 4 deletions docs/AQE-EMBEDDINGS.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,7 @@ ak x aqe-embedding verify
| Local Ollama | Recommended local, no-key setup | Downloads missing MiniLM and alias after consent; tests the selected service |
| Existing endpoint | Shared or separately operated service | Preserves selection, projects configuration and tests synthetic text; never manages remote models |
| In-process | Explicit upstream transformer-package opt-in | Tests the installed backend and existing cache; does not install the security-sensitive optional package |
| Unmanaged | Operator owns configuration, or semantic learning is deferred | Restores only unchanged owned projection values; makes no semantic readiness claim |
| Unmanaged | Operator owns configuration, or semantic learning is deferred | Restores only unchanged owned projection values; makes no semantic readiness claim; `ak x verify aqe` still runs and prints the embedding request but does not record its result for `ak status` |

```sh
ak x aqe-embedding configure --aqe-embedding-endpoint https://embed.example --yes
Expand All @@ -60,6 +60,13 @@ ak x aqe-embedding configure --aqe-embedding-mode in-process --yes
ak x aqe-embedding configure --aqe-embedding-mode unmanaged --yes
```

A passing check proves the embedder: ak sends synthetic text and gets a vector of
the expected size back. It does not prove that AQE's pattern index uses that
embedder. AQE 3.14.4 does not bind its pattern index when an embedder endpoint is
configured ([agentic-qe#754](https://github.com/proffesor-for-testing/agentic-qe/issues/754)),
so `ak status` reads "embedder verified; AQE pattern index binding unverified", and
compatibility with vectors already stored in the project is a separate question.

In-process transformers are an explicit security opt-in in AQE's published
runtime. Consult the installed AQE guidance and dependency advisories before
installing its optional package. Read-only verification never downloads weights;
Expand All @@ -84,9 +91,9 @@ old environment and may retain an earlier failed initialization.

Claude project MCP and hook settings and existing canonical Codex MCP tables
have field-level receipts. On every host, ak edits only an AQE entry started by one
of AQE's own commands: `aqe-mcp`, `aqe mcp`, `agentic-qe mcp`, `aqe-v3 mcp` or
`npx -y agentic-qe@latest mcp` (npm `.cmd` shims included). Entries with other
commands, flags or wrappers are reported as unrecognized and left unchanged. OpenCode updates immediately through a narrow operation inside its existing
of AQE's own commands: `aqe-mcp`, `aqe mcp`, `agentic-qe mcp`, `aqe-v3 mcp`, or
`npx [-y|--yes] agentic-qe[@latest|@<exact version>] mcp` (npm `.cmd` shims included).
Entries with other commands, version ranges, dist-tags, flags or wrappers are reported as unrecognized and left unchanged. OpenCode updates immediately through a narrow operation inside its existing
full-entry owner, preserving permissions, plugins and unrelated MCP entries.
Its receipt remains compatible with normal `ak sync`. Conflicting user values and unsupported TOML forms
are reported, never overwritten. Unrelated Codex keys, including dotted root keys such as
Expand Down
12 changes: 7 additions & 5 deletions docs/HOOKS.md
Original file line number Diff line number Diff line change
Expand Up @@ -139,8 +139,10 @@ consent, capability grants, and host permission state are never inferred or muta
The audit reports registry validity, evidence freshness, and installed-version applicability
separately. Opening or updating an upstream issue always requires explicit user approval. The
constraint registry may retain either a draft or the published URL/time receipt after that
approval. Agentic-QE's 3.14.0 Stop generator is tracked in
[AQE #654](https://github.com/proffesor-for-testing/agentic-qe/issues/654); historical ETIMEDOUT is
detected and attributed. Exact reviewed project copies now have the compatibility repair
above; this does not claim that all upstream-generated variants are fixed. A
workaround is retired only after a released artifact passes the relevant conformance suite.
approval. Agentic-QE's 3.14.0 Stop generator
([AQE #654](https://github.com/proffesor-for-testing/agentic-qe/issues/654)) is fixed: 3.14.1 and
later generate hooks that run `node` with timeouts in seconds, and 3.14.4 passes the offline Stop
conformance (`tests/live/aqe-stop-hook-conformance.test.mjs`), so that constraint is retired and its
findings no longer link an upstream issue. Projects generated by 3.14.0 are still detected, and exact
reviewed project copies keep the compatibility repair above. A workaround is retired only after a
released artifact passes the relevant conformance suite.
4 changes: 3 additions & 1 deletion docs/HOST-ADAPTER-FREEZE-CHECKLIST.md
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,9 @@ design and are recorded as gated, not as failures:
- `aqeProvider` is no longer an upstream freeze ceiling: Agentic-QE 3.13.12 shipped
`externalProviders` for [#628](https://github.com/proffesor-for-testing/agentic-qe/issues/628).
An adapter still must declare `aqe.provider`, pass the real `aqe-provider` tier at its current
content hash, and receive an explicit `aqeProvider` grant.
content hash, and receive an explicit `aqeProvider` grant. The kit's compatibility constraint for
#628 is retired: the live proof `tests/live/aqe-external-provider-transport.test.mjs` passes on
Agentic-QE 3.14.4 with no provider API key in its environment (it refuses to run with one).
- `statusline` runtime rendering (no `ak` render surface for a third-party TUI yet).
- Grant *consumption* last-mile: selecting an external host as primary, and a `commandStatusline`
runtime reader.
7 changes: 7 additions & 0 deletions docs/HOST-SUPPORT.md
Original file line number Diff line number Diff line change
Expand Up @@ -152,6 +152,13 @@ The dated upstream risk inventory includes:
| Default route projection | Yes | Yes | No |
| QE-Court routed seat | Full routed role | Supported, with the integrated stall risk below | May call QE tools, but cannot be an AQE provider-backed seat |
| Subscription-provider embeddings | Not supported | Not supported | Not applicable |
| One project store (AQE pin) | `.claude/settings.local.json` env and the `.mcp.json` AQE entry | The project `.codex/config.toml` AQE MCP env and `[shell_environment_policy.set]` | Not pinned (agentic-kit does not set up AQE for OpenCode) |

Agentic-kit pins `AQE_PROJECT_ROOT`, `AQE_MEMORY_PATH` and `AQE_STORAGE_PATH` to the project root,
so an AQE command, hook or MCP server started in a subfolder uses the project's store instead of
creating its own. A `.mcp.json` or project `.codex/config.toml` that git tracks is not pinned,
because a committed absolute path would not exist on a teammate's machine. `ak x aqe-store merge` merges stores AQE made in subfolders before the pin
([ADR-0062](adr/0062-aqe-project-store-integrity.md)).

The OpenCode boundary is precise: AQE can provision OpenCode agents, skills, MCP,
and permissions, but OpenCode is not a built-in AQE LLM-provider type. Agentic-kit
Expand Down
7 changes: 5 additions & 2 deletions docs/PROVIDERS.md
Original file line number Diff line number Diff line change
Expand Up @@ -410,8 +410,11 @@ Three checks establish different facts; do not collapse them:
content hash, then `ak host adapters grant <name> aqeProvider` must succeed.
2. `ak x verify providers` proves admission plus the exact project declaration, ownership receipt,
default, fallback, and override projection. It deliberately warns that this is not a served
model response. It reads AQE's billing section (`aqe health`) only in a project where
`.agentic-qe` exists, because `aqe health` initializes a store where it runs.
model response. It checks the repository that holds the current folder, from its root, even
when you run it in a subfolder; outside a repository it skips these project checks and says so.
It reads AQE's billing section (`aqe health`) only in a project where `.agentic-qe` exists, and
runs it in the root with the project pin and AQE's in-memory backend, so it does not open the
project's `memory.db`.
3. Release proof starts fresh AQE CLI and MCP processes, lists the external id through
`aqe llm providers --json`, invokes the real `test_generate_enhanced` MCP tool, and requires the
served completion to carry the fixture's provider and model markers:
Expand Down
Loading
Loading