Commit Graph
258 Commits
Author SHA1 Message Date
archipelago 5e71f256e4 docs: resume artifact — session 2 state (banner fix in flight, ISO cut) 2026-08-07 11:49:46 -04:00
archipelagoandClaude a3edb848e1 docs(13): correct peer-files finding per bca18c03 — code bugs, not fleet outage
Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-07 06:14:15 -04:00
archipelagoandClaude Opus 5 c9de1e6c53 wip: phase 13 AIUI paused at 6/17 (operator demo list)
Handoff carries the peer-files correction, the podman-lifecycle trap, the
concurrent-agent warning, and the release-binary drift that blocks the ISO.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-07 06:04:23 -04:00
archipelagoandClaude Opus 5 bca18c03d2 docs: resume artifact — AIUI surfaces, the peer-files correction, SearXNG
Carries the full task list with per-item status, the three commits'
rationale, the live measurements that overturned the earlier
peers-have-no-content conclusion, the browser-verification recipe, and
the binary-drift blocker that must clear before the ISO.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-07 06:00:54 -04:00
archipelagoandClaude 9cf1c12213 docs(13): operator decision — mocks isolated to demo site, not shipped code
Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-07 05:53:59 -04:00
archipelagoandClaude a7368b8b1d docs(13): assessment plan tracks b1c5d138 + demo-mode decision for mocks
Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-07 05:52:26 -04:00
archipelagoandClaude 1eb75a1ed9 docs(13): full AIUI assessment + four-wave fix plan (security/mission/content)
Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-07 05:49:43 -04:00
archipelagoandClaude Opus 5 f7c541e867 docs: measured IndeeHub content inventory — the library is empty
"What films are there from my peers" has three causes behind one answer, and
only one is being worked. The tool gap is in flight in a concurrent session
(content_list + SURFACE_TOOLS). Separately and unowned: AIUI declares six
context categories while the broker serves ten, so media/search/ai-local/notes
cannot be requested by AIUI at all — sanitizeMedia sits behind a door AIUI
cannot open, which is likely why the model claimed no capability rather than
reporting an empty library.

And the part neither fixes: measured with a real node-signed Nostr session
through the gate, /api/projects and /api/projects/private both return 0 items.
A correct "0 results" will be indistinguishable from a broken tool, so seed a
project or verify against a peer that has content before calling it done.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-07 04:49:46 -04:00
archipelagoandClaude Opus 5 289c19443a docs: resume artifact for the AIUI demo — task list, findings, traps
Persists the 17-item session task list so it can be rebuilt in a fresh session
(the task tool is session-scoped and would otherwise evaporate), with what
shipped and what each remaining item actually is.

Records the findings that change expectations rather than leaving them to be
rediscovered: the 16 federated peers are not serving content so peers_reached 0
is correct, IndeeHub's catalogue is genuinely empty, two AI permission stores
existed for the same ten categories, and tailscaled owns :443 so nginx must
bind LAN addresses explicitly or it fails EADDRINUSE and silently keeps the old
config.

STATE.md's stopped_at points at it, so /gsd-resume-work lands correctly.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-07 04:27:36 -04:00
archipelagoandClaude Opus 5 0a23c99463 fix(mesh): view crashed with a temporal-dead-zone error on load
"[Vue Error] ReferenceError: Cannot access 'b' before initialization" from
Ye.immediate, taking the whole Mesh view down.

A watcher with `immediate: true` runs DURING setup. This one calls
handleFetchContent, whose body touches consts declared further down the setup
block — so on any session where history already contained an inline
content_ref, it dereferenced a binding that did not exist yet. handleFetchContent
itself is a hoisted `function`, which is why the call site looked innocent.

The initial pass moves to onMounted, which runs after setup completes: every
binding is initialized, and already-loaded history still gets the same
treatment as new messages, which is what `immediate` was there for.

Also adds .planning/todos/pending/2026-08-07-open-task-list.md — one flat list
of everything open, including the app-lifecycle reports (fedimint guardian
installs but does not work, BTCPay wipe not wiping, Bitcoin Knots vanishing,
fedimint gateway dying at 88%), the missing app_install tool behind
"!ai install bitcoin knots", and the LND UI 401s.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-07 03:33:43 -04:00
archipelagoandClaude Opus 5 05b459a65f fix(aiui): content loads progressively — own first, peers when they arrive
Regression from wiring the peers scope: requestArchyAllContent awaited all
three scopes together, so the grid waited on the slowest. `peers` browses every
federated node over FIPS (Tor fallback) and routinely takes tens of seconds or
times out when a peer is offline. On-device that read as
"content(peers) failed: Content request timed out" plus an AIUI that felt very
slow to open — with nothing rendered meanwhile, even though local content was
ready immediately.

Now `own` paints as soon as it lands and `owned`/`peers` fold in as they
arrive. A scope that times out costs only its own results.

Also records the operator's console findings as tasks: the `files` context
timeout, the web-search CSP block (13-09, now firing on every query), the
strfry icon 404, IndeeHub's relay.nostr.band socket, and the ask that `!archy`
over mesh be able to action container commands with text responses.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-07 03:08:03 -04:00
archipelagoandClaude Opus 5 4891e1babc docs: item 2 done — grants node-side, verified across a daemon restart
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 20:58:27 -04:00
archipelagoandClaude Opus 5 9e86d18921 docs: refresh resume pointer — item 1 done and proven end to end
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 20:23:03 -04:00
archipelagoandClaude Opus 5 aeb40b93d9 docs: record the end-to-end Nostr login proof through the gate
The node signed a real NIP-98 event with its own key and presented it to
IndeeHub through the gate: 200, with a real JWT pair issued. The app's own
bearer token then rides back through the gate — /api/auth/me,
/api/projects/private and /api/projects all 200, matching loopback.
/api/projects/private was the endpoint recorded as unreachable without a
Nostr session, so item 4's private-films path is unblocked.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 20:19:11 -04:00
archipelago 3d4d329787 fix(13-13): assert the seed screen with a real mnemonic, not a stale shape fixture
secret_shaped_content_never_reaches_the_stub was RED because its fixture was
the first twelve wordlist entries — not a parseable mnemonic. The 2026-08-06
precision rewrite of screen_outbound moved from a word-run shape rule to BIP-39
checksum validation (the shape rule had blocked legitimate turns on a live node
twice); egress.rs's own test was updated to a checksum-valid fixture and this
copy was not, so it asserted behaviour that had been deliberately retired.

The named behaviour was intact throughout: screen_outbound runs on the Routstr
paid leg before any body is sent, a real mnemonic is blocked, and
checksum-invalid runs of 20+ wordlist members are still caught by
IMPLAUSIBLE_MEMBER_RUN. Fixture is now a checksum-valid mnemonic, asserted as
parseable so it cannot silently rot the same way again.

Also records the operator's rendering contract in the surfaces todo: chat gets
the mini version, the content/context surfaces expand it, nothing rich may
overflow the bubble at mobile width.
2026-08-06 20:16:48 -04:00
archipelago 36574c0230 docs: capture the content/context-surface underuse task from the operator transcript
Nine of ten turns in the exported transcript answered in markdown prose where
the content surface (grids/cards) and context surface should have carried it.
Records each turn against the surface it should drive, plus two security items
found in the same evidence: a cleartext rpcpassword rendered into the chat, and
the RED screen_outbound test that lets a seed-shaped body reach a third-party
inference provider.
2026-08-06 20:00:12 -04:00
archipelago f1c350040c docs: record the Authorization-strip root cause and the relay ownership fix
Item 1 was not an interception problem and needed no session-aware rule —
the gate was deleting the app's own Authorization header. Item 4's /relay
502 was a root-owned volume, not networking. Both deployed and verified on
archi-dev-box; the extension login itself still needs a human in a browser.
2026-08-06 19:48:43 -04:00
archipelagoandClaude Opus 5 11aa276f58 docs: resume artifact for the fix→deploy→test loop
Everything needed to continue cold: the loop protocol with real deploy and
verify commands, the ordered work list with each item's evidence, Phase 13's
exact remaining state (13-15 only, check 4 passed on-device), and the traps
that cost time tonight — verify on the node not from source, rustls does not
check key/cert pairing, build-aiui.sh hangs after succeeding, AIUI needs
VITE_BASE_PATH=/aiui/.

STATE.md's stopped_at now points at it, so /gsd-resume-work lands correctly.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 19:10:59 -04:00
archipelagoandClaude Opus 5 5f343f5ef9 docs: record the late operator asks and the deploy state of tonight's fixes
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 18:56:45 -04:00
archipelagoandClaude Opus 5 71bf4f3eaf docs: scope the media/IndeeHub/AIUI work from on-device evidence
Every item was observed on archi-dev-box or read from source, not inferred:
the content-card parser mispairing titles with the previous description (the
real cause of "idiotic responses" — the model's prose was correct), IndeeHub's
three independent faults (empty public library, Nostr-only private auth, relay
502 on loopback), the fleet-wide gate bug that 401s credential-less PWA
manifest fetches and app-owned auth endpoints, and AI Data Access grants living
in per-origin localStorage when they are a property of the node.

Input for a research + plan pass, explicitly not the plan itself.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 18:34:26 -04:00
archipelago f7bde19860 Merge branch 'main' into gsd/phase-13-aiui-functional-conversational-node-control-and-content-surf
# Conflicts:
#	.planning/config.json
2026-08-06 16:02:47 -04:00
archipelagoandClaude Opus 5 2ecd5ef8c0 docs(13): content-grid defect fixed + the peer/owned gap that blocks check 2
Records why 13-15's check 2 cannot pass as written (peers/owned scopes have no
caller) and the merge design settled before stopping, so the next session does
not rediscover that setArchyContent replaces rather than merges.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 15:46:42 -04:00
archipelagoandClaude Opus 5 23173c024a docs(13): record the app-port TLS work and its two remaining gaps
Includes the rustls finding (it does not verify key/certificate pairing) so
the explicit check is not later mistaken for redundant, and the archi-dev-box
caveat: it has no HTTPS dashboard, so it cannot reproduce the iframe failure.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 15:25:23 -04:00
archipelagoandClaude Opus 5 71a48e6dbd docs(13): record the per-node CA decision + warm-up fix in the open-tasks file
Corrects the iframe-login root cause on record: trust is per-origin including
port, and a cert interstitial cannot be accepted inside an iframe, so the
SameSite cookie was a downstream symptom rather than the cause.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 14:38:50 -04:00
archipelagoandClaude Opus 5 2c302d1479 docs(13): fold the full-tree sweep into the open-tasks file
A resume that reads STATE.md plus this file was still missing real work:
two planning docs untracked on main since 2026-08-05, the indeedhub
crash-loop on .38/.88, nine items still OPEN in RELEASE-1.7.121-TASKS.md,
and 19 uncommitted files in the archy-mesh worktree. All now listed here
so this one file is the whole picture rather than most of it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 14:25:58 -04:00
archipelagoandClaude Opus 5 4b318b4c7d docs(13): drop stale handoff/checkpoint files, refresh resume pointer
HANDOFF.json and .planning/.continue-here.md both described phase 09
(2026-08-02, BotFights demo work) which was fully reconciled and pushed
in both repos at the time they were written. They are the FIRST thing
/gsd-resume-work reads, so they made a clean resume open on the wrong
phase entirely. phases/02-ui-performance/.continue-here.md is likewise a
closed-out note from 2026-07-31.

STATE.md's Session Continuity now names the real fork: 13-15 blocked on
four operator browser checks, the four non-phase node/infra tasks, and
the follow-on A/B/C proposal.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 14:25:04 -04:00
archipelagoandClaude Opus 5 ab69400956 docs: commit the app-gate design + 2026-08-05 resume notes
Both had been sitting untracked in the working tree since 2026-08-05 —
exactly the "finished work lost because it was never committed" failure
CLAUDE.md's #1 process rule exists to prevent.

APP-PORT-AUTH-GATE.md carries the gate's design rationale ("you cannot
gate a socket you do not own") and, in its open questions, the TLS/scheme
fork that still blocks the gated-app iframe login: if the dashboard is
HTTPS and app ports are HTTP, a Secure session cookie is never sent.

RESUME-2026-08-05-appgate-fixes.md carries the .122-.125 release trail,
the two self-inflicted .124 bugs and their guards, and the open indeedhub
crash-loop (indeedhub-minio absent on .38/.88).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 14:24:51 -04:00
archipelagoandClaude Fable 5 7bb09ffe61 docs(13): persist open task list + resume pointer for a fresh session
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-06 14:16:36 -04:00
archipelagoandClaude Fable 5 31f78bdced docs(13): operator decision — web-search setting derives the AIUI CSP
The toggle must change what is POSSIBLE, not ask the frame to behave. Records
the verified mechanics: CSP is nginx-emitted (static add_header), the setting
lives only in browser localStorage today, and the node's nginx self-heal
reverts hand edits — so the setting moves node-side and the CSP derives from
it, allowlisted rather than wildcard.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-06 14:15:00 -04:00
archipelagoandClaude Fable 5 c3277a8323 docs(13): follow-on scope proposal — CSP collision, unbuilt AIUI-02/05, nostr+zaps
Drafted during 13-15 device verification from what the operator actually hit:
the 13-09 CSP blocks wss:// relays and enrichment from the embed (real
regression, needs a broker-vs-widen decision), /api/tmdb and /api/web-search
are unimplemented on the node, AIUI-02 and AIUI-05 were declared but never
planned, and nostr polish + zaps were explicitly deferred by 13-CONTEXT.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-06 14:13:27 -04:00
archipelago 706c33acaf docs(13-14): complete eval harness + confirmation-clarity plan 2026-08-06 14:08:21 -04:00
archipelagoandClaude Fable 5 857d9d4906 capture: honour AIUI web-search setting in node-delegated chat
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-06 13:18:58 -04:00
archipelagoandClaude Fable 5 52a400b3c5 capture: funding-settings modal entry point; slot into next week's UX pass
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-06 11:07:46 -04:00
archipelagoandClaude Fable 5 5fc8289436 capture: Routstr funding UX in AIUI dropdown (operator request)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-06 11:07:36 -04:00
archipelagoandClaude Fable 5 39d53d212e docs(13): defer dev3 console-noise triage — embedded web-search/rss, wiki demo spam, content timeout pairing
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-06 11:01:26 -04:00
archipelagoandClaude Fable 5 51a13da2a6 merge: bring main (v1.7.125 + .126 work) into phase-13 branch pre-deploy
63 main commits since the fork point — gate cookie-strip fix, named-volume
create fix, appgate catalog classification, RNode error surfacing — merged
so 13-14/13-15 on-device verification runs against current production code.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-06 09:33:40 -04:00
archipelagoandClaude Fable 5 171d75dc01 docs(13): STATE — 13-14 at Task 3 human-verify gate (comprehension study)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-06 07:04:33 -04:00
archipelagoandClaude Fable 5 63fa8b4558 docs(13-13): complete Routstr backend / D-05 budget ceiling plan
D-04's chain complete (Ollama -> Claude -> Routstr); D-05's prepaid
allowance is a hard arithmetic ceiling, verified by fault injection.
Task 1 decision: proceed-docs-with-probe-first (0/9 protocol claims
independently confirmed; first live call doubles as the capability probe).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-06 05:39:02 -04:00
archipelago 8548544db9 docs(13-12): complete injection-boundary/egress-screen/rate-limit plan 2026-08-05 23:13:23 -04:00
archipelago c08f8f0e83 docs(13-11): complete music library + share MIME fix plan 2026-08-05 18:35:10 -04:00
archipelagoandClaude Fable 5 dba3aecf26 docs(13-10): complete Ollama backend + node-side history plan
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-05 18:06:50 -04:00
archipelagoandClaude Fable 5 a245e5d29f docs(13-08): summary — confirm gate + trusted chrome complete, checkpoint approved
Task 3 (checkpoint:human-verify, blocking) approved by the operator after a
full on-device pass on archi-dev-box: deny/approve/read-only/fail-safe-timeout
all verified with a real Claude 4.5 Haiku backend against a real container.
cargo assistant:: 29/29 green (incl. declined_action_never_reprompts_same_turn),
vitest toolConfirm/contextBroker/chatAiuiEmbed 40/40 green. STATE.md/ROADMAP.md/
REQUIREMENTS.md updated (9/15 plans, AIUI-01/AIUI-04 marked complete for this
plan's contribution). Next: wave 4 (13-10, then 13-11).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-05 15:18:34 -04:00
archipelagoandClaude Fable 5 077a098dbf docs(13-08): Task 3 on-device evidence — deny/approve transcript + read-only no-dialog
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-05 14:58:12 -04:00
archipelagoandClaude Fable 5 44c864ac14 docs(13-08): defer AIUI-over-host background regression on mobile/companion
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-05 14:15:05 -04:00
archipelagoandClaude Fable 5 8a19e8d3f8 docs(13): STATE frontmatter — 13-08 at Task 3 blocking human-verify gate
Tasks 1+2 verified complete on HEAD (ae042db9, record commit fc09d7a2);
plan closes only after operator's on-device dialog inspection.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-05 11:49:00 -04:00
archipelagoandClaude Fable 5 ae042db951 docs(13-08): verify Task 1 + Task 2 complete on continuation, checkpoint at Task 3
Continuation of the operator-restarted 13-08 session. Verified rather than
reshaped, per the pushed-history constraint on fc09d7a2/1a664be1:

- fc09d7a2's tools.rs/grants.rs/backends/mod.rs diffs confirmed rustfmt-only
  (line-wrap reformatting), no behavior change.
- Task 1 re-verified green on current HEAD: 28/28 assistant:: tests pass,
  approval_nonce_binds_to_exact_action passes individually, dispatcher.rs
  untouched (git diff --exit-code clean).
- Task 2 was already complete in fc09d7a2's uncommitted-state snapshot: all
  10 toolConfirm.test.ts cases pass (one per <behavior> bullet including
  iframe_message_cannot_open_or_resolve_confirmation), pre-existing
  contextBroker.test.ts + chatAiuiEmbed.test.ts (28 tests) still green,
  vue-tsc --noEmit clean, and every acceptance-criteria grep passes
  (Teleport to="body", zero postMessage/v-html in the modal, distinct
  aiui:tool-confirm-request event pair not reusing aiui:install-request,
  assistant.pending RPC-fetch, ToolConfirmModal mounted in Chat.vue).

fc09d7a2 stands as the commit of record for both Task 1 and Task 2 — no new
source changes were needed. STOPPING at Task 3 (checkpoint:human-verify,
gate=blocking): the anti-spoofing and clear-signing properties are visual/
judgement calls that require a human on archi-dev-box, not cargo test.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-05 11:47:10 -04:00
archipelagoandClaude Fable 5 1a664be113 docs(13): checkpoint 13-08 mid-Task-1 for operator session restart
Task 1 test-green (28/28) at fc09d7a2; resume via continuation executor,
Task 3 remains a blocking human-verify gate.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-05 11:39:44 -04:00
archipelagoandClaude Fable 5 7025c5f26f docs(13-07): state + roadmap — 13-07 complete, next 13-08
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-04 11:34:26 -04:00
archipelagoandClaude Fable 5 17da7a7233 docs(13-07): summary — music index + music.* surface complete, 23/23 green
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-04 11:15:41 -04:00
archipelagoandClaude Fable 5 589cbb030f docs(13-04): complete music model + tag extraction plan — summary, state, config
- 13-04-SUMMARY.md: all 3 tasks, broken-pipe recovery (verbatim wip
  checkpoint be8f24b4), MP3 fixture off-by-one deviation, 7/7 tests green
- STATE.md: 13-04 complete (7/15 phase-13 plans), D-13 decision + lofty
  gate recorded in accumulated context, next = waves 3+
- config.json: fold in pre-existing use_worktrees=false from the broken
  session (wave-continue bookkeeping, intentionally kept)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-04 07:06:10 -04:00