Compare commits
6
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
7bb5ff4719 | ||
|
|
b993ad1c64 | ||
|
|
d0006e9f71 | ||
|
|
6da68fffb8 | ||
|
|
53ce1b1a5e | ||
|
|
433f66add8 |
+98
-24
@@ -23,6 +23,7 @@ import json
|
||||
import os
|
||||
import uuid
|
||||
from dataclasses import dataclass, field
|
||||
from datetime import datetime, timezone
|
||||
from typing import Any, Mapping, Sequence
|
||||
|
||||
from control_plane_db import (
|
||||
@@ -738,6 +739,46 @@ def normalize_exclude_issue_numbers(
|
||||
return sorted(out)
|
||||
|
||||
|
||||
def _claim_expires_at(claim: Any) -> datetime | None:
|
||||
"""Parse a claim's ``expires_at``, or ``None`` when it is absent/malformed."""
|
||||
if not isinstance(claim, Mapping):
|
||||
return None
|
||||
text = str(claim.get("expires_at") or "").strip()
|
||||
if not text:
|
||||
return None
|
||||
if text.endswith("Z"):
|
||||
text = text[:-1] + "+00:00"
|
||||
try:
|
||||
parsed = datetime.fromisoformat(text)
|
||||
except ValueError:
|
||||
return None
|
||||
if parsed.tzinfo is None:
|
||||
parsed = parsed.replace(tzinfo=timezone.utc)
|
||||
return parsed.astimezone(timezone.utc)
|
||||
|
||||
|
||||
def _drop_expired_claims(
|
||||
claims: Mapping[tuple[str, int], dict[str, Any]],
|
||||
*,
|
||||
now: datetime | None = None,
|
||||
) -> dict[tuple[str, int], dict[str, Any]]:
|
||||
"""Claims minus those whose lease has already expired (#643).
|
||||
|
||||
The read-only mirror of ``expire_stale_leases``: the sweep marks such rows
|
||||
``expired`` so they stop being returned as claims, and this reaches the same
|
||||
view without writing. A claim with no parseable ``expires_at`` is **kept** —
|
||||
an unreadable expiry is not evidence that work is free.
|
||||
"""
|
||||
moment = now or datetime.now(timezone.utc)
|
||||
kept: dict[tuple[str, int], dict[str, Any]] = {}
|
||||
for key, claim in (claims or {}).items():
|
||||
expires_at = _claim_expires_at(claim)
|
||||
if expires_at is not None and expires_at <= moment:
|
||||
continue
|
||||
kept[key] = claim
|
||||
return kept
|
||||
|
||||
|
||||
def candidate_set_fingerprint(
|
||||
candidates: Sequence[WorkCandidate],
|
||||
*,
|
||||
@@ -826,12 +867,22 @@ def allocate_next_work(
|
||||
exclude_issue_numbers: Sequence[int] | None = None,
|
||||
expected_candidate_set_fingerprint: str | None = None,
|
||||
allocation_mode: str | None = None,
|
||||
side_effect_free: bool = False,
|
||||
) -> dict[str, Any]:
|
||||
"""Select and optionally reserve the next work unit via control-plane DB.
|
||||
|
||||
*apply=False* (default): dry-run selection only — no lease/assignment.
|
||||
*apply=True*: atomic ``assign_and_lease`` for the selected candidate.
|
||||
|
||||
*side_effect_free* (#643): a dry run that writes **nothing** to the
|
||||
control-plane DB. A plain ``apply=False`` still registered a session row and
|
||||
swept stale leases globally, so a caller advertising a read-only preview was
|
||||
mutating on every call. Under this flag both writes are suppressed and stale
|
||||
leases are instead filtered out of the claim map in memory, which yields the
|
||||
same selection the sweep would have produced without persisting anything.
|
||||
Incompatible with *apply* — the combination fails closed rather than
|
||||
silently reserving.
|
||||
|
||||
*allocation_mode* (#840): ``cross_role`` (default for controller) inspects
|
||||
the complete queue and returns one authoritative selection naming the
|
||||
required downstream role/profile/action. ``role_scoped`` keeps prior
|
||||
@@ -885,40 +936,57 @@ def allocate_next_work(
|
||||
"allocation_mode": (allocation_mode or "").strip() or None,
|
||||
}
|
||||
|
||||
session_id = (session_id or "").strip() or f"alloc-{uuid.uuid4().hex[:12]}"
|
||||
try:
|
||||
db.upsert_session(
|
||||
session_id=session_id,
|
||||
role=role_norm,
|
||||
profile=profile_name,
|
||||
pid=os.getpid(),
|
||||
controller_instance_id=controller_instance_id,
|
||||
)
|
||||
except Exception as exc: # noqa: BLE001 — surface structured
|
||||
# A side-effect-free run may never reserve: reserving is a write, and the
|
||||
# flag is the caller's assertion that this call writes nothing (#643).
|
||||
if side_effect_free and apply:
|
||||
return {
|
||||
"success": False,
|
||||
"outcome": OUTCOME_NO_SAFE,
|
||||
"apply": True,
|
||||
"reasons": [
|
||||
f"failed to register session in control-plane DB: {exc} "
|
||||
"(fail closed, #613)"
|
||||
"side_effect_free is incompatible with apply=True; an "
|
||||
"assignment is a write (fail closed, #643)"
|
||||
],
|
||||
"skipped": [],
|
||||
"assignment": None,
|
||||
"substrate": "control_plane_db",
|
||||
}
|
||||
|
||||
# Expire stale leases globally before selection.
|
||||
try:
|
||||
db.expire_stale_leases()
|
||||
except Exception as exc: # noqa: BLE001
|
||||
return {
|
||||
"success": False,
|
||||
"outcome": OUTCOME_NO_SAFE,
|
||||
"reasons": [f"lease expiry failed: {exc} (fail closed)"],
|
||||
"skipped": [],
|
||||
"assignment": None,
|
||||
"substrate": "control_plane_db",
|
||||
}
|
||||
session_id = (session_id or "").strip() or f"alloc-{uuid.uuid4().hex[:12]}"
|
||||
if not side_effect_free:
|
||||
try:
|
||||
db.upsert_session(
|
||||
session_id=session_id,
|
||||
role=role_norm,
|
||||
profile=profile_name,
|
||||
pid=os.getpid(),
|
||||
controller_instance_id=controller_instance_id,
|
||||
)
|
||||
except Exception as exc: # noqa: BLE001 — surface structured
|
||||
return {
|
||||
"success": False,
|
||||
"outcome": OUTCOME_NO_SAFE,
|
||||
"reasons": [
|
||||
f"failed to register session in control-plane DB: {exc} "
|
||||
"(fail closed, #613)"
|
||||
],
|
||||
"skipped": [],
|
||||
"assignment": None,
|
||||
"substrate": "control_plane_db",
|
||||
}
|
||||
|
||||
# Expire stale leases globally before selection.
|
||||
try:
|
||||
db.expire_stale_leases()
|
||||
except Exception as exc: # noqa: BLE001
|
||||
return {
|
||||
"success": False,
|
||||
"outcome": OUTCOME_NO_SAFE,
|
||||
"reasons": [f"lease expiry failed: {exc} (fail closed)"],
|
||||
"skipped": [],
|
||||
"assignment": None,
|
||||
"substrate": "control_plane_db",
|
||||
}
|
||||
|
||||
terminal = None
|
||||
try:
|
||||
@@ -953,6 +1021,12 @@ def allocate_next_work(
|
||||
"assignment": None,
|
||||
"substrate": "control_plane_db",
|
||||
}
|
||||
if side_effect_free:
|
||||
# ``list_active_claims`` filters on status alone, so without the
|
||||
# global sweep an already-expired lease would still read as a live
|
||||
# claim and the preview would report work as taken that is free.
|
||||
# Drop those in memory: same view the sweep produces, no write.
|
||||
claims = _drop_expired_claims(claims)
|
||||
|
||||
try:
|
||||
exclude_nums = normalize_exclude_issue_numbers(exclude_issue_numbers)
|
||||
|
||||
@@ -94,6 +94,7 @@ already define, and a regression test asserts each mapping matches.
|
||||
| `record_analytics_usage` | operator | gated_write | `runtime.record_analytics_usage` | Yes | No | No | 2 |
|
||||
| `system.reload_namespace` | controller | privileged | `runtime.reload_namespace` | Yes | No | No | 2 |
|
||||
| `system.restart_namespace` | admin | destructive | `runtime.restart_namespace` | Yes | **Yes** | **Yes** | 2 |
|
||||
| `initiate_workflow` | operator | gated_write | `gitea.read` | Yes | No | No | 2 |
|
||||
|
||||
**Dual control** means the acting principal may not be the sole authority: a
|
||||
second distinct principal must confirm. **Break-glass** means the action is
|
||||
@@ -112,6 +113,12 @@ by the console — both hand off to a host supervisor, and neither exposes a raw
|
||||
process kill. See
|
||||
[`sanctioned-restart-controls.md`](sanctioned-restart-controls.md) (#642).
|
||||
|
||||
`initiate_workflow` (#643) is operator-class because its outcome is a *claim*,
|
||||
not a Gitea verdict. Requesting reviewer or merger work reserves that work
|
||||
through the allocator; it does not grant the right to approve or merge, which
|
||||
stays with the MCP role profile and its own capability gates. See
|
||||
[`webui-requests.md`](webui-requests.md).
|
||||
|
||||
### Authorization decision
|
||||
|
||||
`authorize(action_id, principal, for_execution=False)` returns a decision
|
||||
@@ -126,9 +133,24 @@ record and **denies by default**. The deny reasons are closed and enumerated:
|
||||
| `phase_not_active` | Execution requested for an action whose phase is not open. |
|
||||
| `allowed_preview_only` | Authorized — preview only, execution still disabled. |
|
||||
|
||||
There is no implicit allow branch. Even the allow result reports
|
||||
`execution_enabled: false` while the console is in Phase 1, so no caller can
|
||||
read an allow as permission to mutate.
|
||||
There is no implicit allow branch.
|
||||
|
||||
`execution_enabled` on the decision reports whether the action has a live
|
||||
execution path at all, and is computed by `execution_wired(action)`. There are
|
||||
exactly two ways to be wired:
|
||||
|
||||
1. the action's `phase` is at or below `ACTIVE_PHASE`; or
|
||||
2. the action declares an `execution_env_flag` **and** that variable is set.
|
||||
|
||||
Every action that declares no flag therefore reports `execution_enabled: false`
|
||||
while the console is in Phase 1, so no caller can read an allow as permission
|
||||
to mutate. The per-action flag exists because raising `ACTIVE_PHASE` would
|
||||
enable execution for every action of that phase at once, including ones whose
|
||||
execution path is not implemented. One implemented action goes live on its own
|
||||
flag instead of dragging its unimplemented phase-mates with it.
|
||||
|
||||
`initiate_workflow` is the only action that currently declares a flag
|
||||
(`WEBUI_REQUESTS_EXECUTION`), and it stays denied until an operator sets it.
|
||||
|
||||
## Secret redaction
|
||||
|
||||
@@ -235,13 +257,22 @@ second one. The integration points are already wired and observable:
|
||||
instead of adding a parallel check.
|
||||
- **`GET /api/console/security-model`** publishes the RBAC matrix, redaction
|
||||
policy, and audit policy as JSON for operators and tests.
|
||||
- **`POST /api/v1/requests/preview` and `.../apply`** (#643) are the first
|
||||
actions to use this model for a real execution path. Preview always returns a
|
||||
decision and an audited `previewed` record; apply requires `confirm=true`,
|
||||
emits `succeeded` or `denied`, and reserves work only through the allocator.
|
||||
See [`webui-requests.md`](webui-requests.md).
|
||||
|
||||
To open Phase 2, a child issue must: raise `ACTIVE_PHASE`, implement the
|
||||
confirmation and dual-control flow the matrix already declares, emit a
|
||||
`succeeded` or `failed` record alongside the `gitea_audit` mutation record, and
|
||||
keep `viewer` unable to reach any of it. Turning on execution without the
|
||||
confirmation flow contradicts a declared requirement and is a review failure,
|
||||
not a shortcut.
|
||||
A Phase 2 action must: use `execution_wired` rather than a private enable flag,
|
||||
implement the confirmation and dual-control flow the matrix already declares,
|
||||
emit a `succeeded` or `failed` record alongside the `gitea_audit` mutation
|
||||
record, and keep `viewer` unable to reach any of it. Turning on execution
|
||||
without the confirmation flow contradicts a declared requirement and is a
|
||||
review failure, not a shortcut.
|
||||
|
||||
Raising `ACTIVE_PHASE` remains the way to open a whole phase at once, and is
|
||||
deliberately *not* what #643 did: an action-scoped opt-in cannot enable an
|
||||
action whose execution path nobody wrote.
|
||||
|
||||
## Local-dev mode
|
||||
|
||||
@@ -294,6 +325,7 @@ Until Phase 2 wires it, probe protection rests on network placement alone, as
|
||||
| `WEBUI_ROLE_MAP` | unset | JSON subject → role map |
|
||||
| `WEBUI_REQUIRE_PROBE_AUTH` | unset | Require auth for non-public probes |
|
||||
| `WEBUI_CONSOLE_AUDIT_LOG` | unset | Append-only audit sink path |
|
||||
| `WEBUI_REQUESTS_EXECUTION` | unset | Opt in to `initiate_workflow` execution (#643) |
|
||||
|
||||
All are read server-side only. None is ever rendered into a page or returned by
|
||||
an API.
|
||||
|
||||
+1
-54
@@ -85,10 +85,7 @@ status, onboarding checklist state, and the fail-closed error payloads (#635).
|
||||
| `/inventory` | Phase 1 shell stub — unified inventory (backed by #636) |
|
||||
| `/timeline` | Phase 1 shell stub — workflow event timeline |
|
||||
| `/policy` | Phase 1 shell stub — capability/role policy placeholder |
|
||||
| `/providers` | AI-provider connection status (#650) — declared registry only, no secrets |
|
||||
| `/api/v1/providers` | JSON provider connections; `502` when the registry cannot be loaded |
|
||||
| `/insights` | Evidence-backed operational insights (#650) — advisory only |
|
||||
| `/api/v1/insights` | JSON insights export with evidence refs and source availability |
|
||||
| `/insights` | Phase 1 shell stub — operational insights placeholder |
|
||||
|
||||
Most routes are GET-only. POST/PUT/PATCH/DELETE return `405` with
|
||||
`read-only-mvp`, except `/audit` and `/api/audit` which accept POST for
|
||||
@@ -332,56 +329,6 @@ Honesty rules specific to this view:
|
||||
The write-time redactor is a narrow denylist and is not relied on. The field
|
||||
itself is kept — it is the `#630` evidence naming which daemon was killed.
|
||||
|
||||
## AI providers and operational insights (#650)
|
||||
|
||||
`/providers` and `/insights` are the Phase 4 **advisory** surfaces for AI-provider
|
||||
connections and evidence-backed operational findings. They never expose API keys,
|
||||
never mutate Gitea, and never authorize review, merge, or close.
|
||||
|
||||
### Provider connections (`/providers`)
|
||||
|
||||
Status is taken from the **worker registry** declaration (`webui/data/workers.registry.json`
|
||||
or `WEBUI_WORKER_REGISTRY`):
|
||||
|
||||
| Field | Meaning |
|
||||
|-------|---------|
|
||||
| `connection_status` | `declared_available` or `declared_unavailable` from the registry `available` flag |
|
||||
| `models` | Declared model list only (not a live vendor enumeration) |
|
||||
| `worker_count` / `enabled_worker_count` | How many worker instances name this provider |
|
||||
| `secrets_exposed` | Always `false` — credentials are never loaded |
|
||||
|
||||
Live executable health is **not** probed here (that belongs to the provider adapter
|
||||
framework). The page states this probe limit explicitly so a green badge is not
|
||||
misread as a process heartbeat.
|
||||
|
||||
`GET /api/v1/providers` returns the same model (`schema_version: 1`). It answers
|
||||
`502` when the registry cannot be loaded so consumers cannot treat a fail-closed
|
||||
payload as “no providers configured”.
|
||||
|
||||
### Operational insights (`/insights`)
|
||||
|
||||
Insights are pure functions over durable console evidence:
|
||||
|
||||
| Kind | Evidence source |
|
||||
|------|-----------------|
|
||||
| `blocked_queue_pressure` | Traffic control blocked bucket (issue/PR numbers + reasons) |
|
||||
| `controller_attention` | Traffic control `needs_controller` items |
|
||||
| `stale_runtime_risk` | System-health stale_runtime / mutation_safe |
|
||||
| `provider_without_workers` | Declared-available providers with zero workers |
|
||||
| `analytics_failure_pressure` | Analytics events with failure status (when loaded) |
|
||||
|
||||
Rules:
|
||||
|
||||
* Every insight carries at least one evidence ref (`kind` + `ref` + `detail`).
|
||||
Evidence-less insights are refused, not emitted.
|
||||
* `advisory_only` is always true; `claims_action_completed` is always false.
|
||||
* Missing sources appear under `sources_unavailable` — never as a silent empty
|
||||
“all clear”.
|
||||
* Titles and details pass through console redaction before display.
|
||||
|
||||
`GET /api/v1/insights` exports the same model. The HTML page always renders
|
||||
interpretation limits so operators know these cards do not override workflow gates.
|
||||
|
||||
## Gitea issue/PR linkage (#645)
|
||||
|
||||
`/gitea` is the Phase 3 read-only linkage console: which PR carries which issue,
|
||||
|
||||
@@ -0,0 +1,160 @@
|
||||
# Web console requests: intent preview and workflow initiation (#643)
|
||||
|
||||
**Phase 2. Preview is always live and always read-only. Initiation is wired but
|
||||
denied until an operator opts in.**
|
||||
|
||||
Before this surface, starting role work meant pasting a prompt into a terminal
|
||||
and trusting the operator to have checked the allocator first. Nothing enforced
|
||||
that check, so two sessions could reach for the same issue and each believe it
|
||||
was theirs. This page replaces the paste with a *request*: a desired role, an
|
||||
issue or PR, and a stated intent, answered by an authorization decision and —
|
||||
on confirmation — an exclusive assignment from the allocator.
|
||||
|
||||
| Concern | Module |
|
||||
|---------|--------|
|
||||
| Request model, preview, initiation | `webui/request_service.py` |
|
||||
| Form and preview rendering | `webui/request_views.py` |
|
||||
| Authorization | `webui/console_authz.py` (`initiate_workflow`) |
|
||||
| Audit | `webui/console_audit.py` |
|
||||
| Ownership substrate | `allocator_service.py` + `control_plane_db.py` |
|
||||
|
||||
## Surfaces
|
||||
|
||||
| Path | Method | Purpose |
|
||||
|------|--------|---------|
|
||||
| `/requests` | GET | Request form |
|
||||
| `/requests` | POST | Render an intent preview. **Never assigns.** |
|
||||
| `/api/v1/requests/preview` | POST | Intent preview as JSON |
|
||||
| `/api/v1/requests/apply` | POST | Initiate — confirmed, audited, allocator-owned |
|
||||
|
||||
The HTML form has no initiate button on purpose. Initiating requires a
|
||||
confirmed POST to `/api/v1/requests/apply`, so a stray form submission cannot
|
||||
reserve work as a side effect.
|
||||
|
||||
## The request
|
||||
|
||||
```json
|
||||
{
|
||||
"desired_role": "author",
|
||||
"work_kind": "issue",
|
||||
"work_number": 643,
|
||||
"intent_summary": "implement request preview and initiation",
|
||||
"remote": "prgs",
|
||||
"org": "Scaled-Tech-Consulting",
|
||||
"repo": "Gitea-Tools",
|
||||
"expected_head_sha": null
|
||||
}
|
||||
```
|
||||
|
||||
`desired_role` is one of `author`, `reviewer`, `merger`, `reconciler`,
|
||||
`controller`. `work_kind` is `issue` or `pr`. `remote`/`org`/`repo` default to
|
||||
the first project in the registry when omitted; when neither the request nor
|
||||
the registry resolves them, the request is rejected rather than pointed at some
|
||||
other repository. `intent_summary` is required — it is what the audit record
|
||||
states as the reason — and is truncated to 500 characters.
|
||||
|
||||
Parsing rejects rather than corrects. An unknown role, an unknown work kind, a
|
||||
non-positive number, or a missing intent each return `400` with a `reason_code`
|
||||
and the offending `field`.
|
||||
|
||||
## Preview
|
||||
|
||||
Five checks, each with its own verdict, reason code, and detail:
|
||||
|
||||
| Check | Passes when |
|
||||
|-------|-------------|
|
||||
| `authorization` | The console principal holds `operator` or above |
|
||||
| `capability` | The desired role maps to a declared profile and MCP namespace |
|
||||
| `lease_availability` | No active claim holds the work unit |
|
||||
| `next_safe_action` | The allocator would independently select this exact work unit |
|
||||
| `head_pin` | PR work resolves to a head SHA, and a supplied SHA still matches |
|
||||
|
||||
A preview also returns the role's `allowed_actions` and `prohibited_actions`
|
||||
(from `allocator_service.ROLE_ACTIONS`), the `required_profile` and
|
||||
`required_namespace` the work must run under, and a `correlation_id` that ties
|
||||
the preview to its audit record and to any assignment that follows.
|
||||
|
||||
Preview is read-only in the strict sense: it calls the allocator with
|
||||
`apply=false` and writes nothing but an audit line. An unauthorized principal
|
||||
never reaches the allocator or the control-plane DB at all, so a denial cannot
|
||||
be used to enumerate the queue.
|
||||
|
||||
## Initiation
|
||||
|
||||
`POST /api/v1/requests/apply` refuses in this order, and every refusal returns
|
||||
before any assignment is attempted:
|
||||
|
||||
| Condition | Outcome | Status |
|
||||
|-----------|---------|--------|
|
||||
| Unparseable request | `invalid_request` | 400 |
|
||||
| Not authorized, or execution not wired | `denied` | 403 |
|
||||
| `confirm` not set | `denied` / `confirmation_required` | 409 |
|
||||
| Work unit already claimed | `blocked` / `duplicate_assignment` | 409 |
|
||||
| Allocator would select other work | `wait` / `not_next_safe_work` | 409 |
|
||||
| Allocator declines on apply | `blocked` or `wait` | 409 |
|
||||
| Evidence unavailable | `wait` / `evidence_unavailable` | 503 |
|
||||
| Assigned | `assigned_work` | 201 |
|
||||
|
||||
A success returns the assignment plus a `handoff` block naming the profile, the
|
||||
namespace, and the actions that stay forbidden — enough for the operator to
|
||||
continue in the right MCP namespace without guessing.
|
||||
|
||||
### Why apply runs the allocator twice
|
||||
|
||||
The allocator is the only source of exclusive ownership (#600 / #613), and it
|
||||
selects work; it does not take orders. So `apply` runs a dry-run first and
|
||||
proceeds only when the allocator would independently pick the requested work
|
||||
unit. If it would not, the request reports `wait` and mutates nothing.
|
||||
|
||||
A request is therefore a *confirmation* of the allocator's decision, never an
|
||||
override of it. The apply call carries the dry-run's
|
||||
`candidate_set_fingerprint` as a CAS pin (#776), so a queue that changed
|
||||
between the two calls fails closed rather than assigning against a stale view.
|
||||
The result is checked again on the way out: an assignment naming a different
|
||||
work unit is not read as success.
|
||||
|
||||
### Fail-closed defaults
|
||||
|
||||
- An unreadable control-plane DB denies. It is never treated as "nothing holds
|
||||
this work unit".
|
||||
- An incomplete queue inventory denies (#758). Ranking a partial candidate set
|
||||
can select the wrong work.
|
||||
- An allocator that raises denies.
|
||||
- PR work with no resolvable head SHA denies; a supplied SHA that no longer
|
||||
matches denies with `head_moved`.
|
||||
|
||||
## Enabling initiation
|
||||
|
||||
Execution is wired off. Set `WEBUI_REQUESTS_EXECUTION=1` to enable it for the
|
||||
`initiate_workflow` action only — see
|
||||
[`webui-authz-audit.md`](webui-authz-audit.md) for why this is an
|
||||
action-scoped flag rather than a phase bump. With the variable unset, `apply`
|
||||
returns `403` with `reason_code: unauthorized` no matter who asks.
|
||||
|
||||
Enabling execution does **not** enable approvals or merges. Those are phase 3
|
||||
console actions and remain forbidden in every path here; the console reserves
|
||||
work and hands off, and the MCP role profile enforces what that role may then
|
||||
do.
|
||||
|
||||
## Audit
|
||||
|
||||
Every preview and every apply emits a console audit record (schema in
|
||||
[`webui-authz-audit.md`](webui-authz-audit.md)):
|
||||
|
||||
| Event | `result` |
|
||||
|-------|----------|
|
||||
| Preview | `previewed` |
|
||||
| Refusal at any stage | `denied` |
|
||||
| Assignment created | `succeeded` |
|
||||
|
||||
`correlation.request_id` carries the request's `correlation_id`, and a
|
||||
successful record's `metadata` carries `assignment_id` and `lease_id`, so an
|
||||
assignment can be traced back to the intent that produced it. The operator's
|
||||
`intent_summary` travels in `metadata` and passes through the standard
|
||||
redaction pass before persistence like every other field.
|
||||
|
||||
## Non-goals
|
||||
|
||||
- No browser-initiated approve or merge, in this phase or any other.
|
||||
- No bypass of allocator exclusive ownership; no self-selection of work.
|
||||
- No auto-start from raw monitoring incidents (#612 stays downstream).
|
||||
@@ -7,6 +7,7 @@ import tempfile
|
||||
import threading
|
||||
import unittest
|
||||
from concurrent.futures import ThreadPoolExecutor, as_completed
|
||||
from datetime import datetime, timezone
|
||||
|
||||
from allocator_service import (
|
||||
OUTCOME_ASSIGNED,
|
||||
@@ -15,6 +16,7 @@ from allocator_service import (
|
||||
OUTCOME_PREVIEW,
|
||||
OUTCOME_WAIT,
|
||||
WorkCandidate,
|
||||
_drop_expired_claims,
|
||||
allocate_next_work,
|
||||
candidate_from_dict,
|
||||
classify_skip,
|
||||
@@ -362,5 +364,161 @@ class AllocatorServiceTest(unittest.TestCase):
|
||||
self.assertIn("unavailable", res["reasons"][0].lower())
|
||||
|
||||
|
||||
class SideEffectFreeAllocationTest(unittest.TestCase):
|
||||
"""``side_effect_free`` dry runs write nothing to the control plane (#643).
|
||||
|
||||
A plain ``apply=False`` still called ``upsert_session`` and
|
||||
``expire_stale_leases`` before the apply branch was consulted, so a caller
|
||||
advertising a read-only preview mutated on every call — one unreferenced
|
||||
session row per preview, plus a global lease sweep.
|
||||
"""
|
||||
|
||||
def setUp(self) -> None:
|
||||
self._tmp = tempfile.TemporaryDirectory()
|
||||
self.db = ControlPlaneDB(os.path.join(self._tmp.name, "cp.sqlite3"))
|
||||
|
||||
def tearDown(self) -> None:
|
||||
self._tmp.cleanup()
|
||||
|
||||
def _alloc(self, **kwargs):
|
||||
defaults = dict(
|
||||
db=self.db,
|
||||
session_id="s-preview",
|
||||
role="author",
|
||||
remote="prgs",
|
||||
org="org",
|
||||
repo="repo",
|
||||
candidates=[
|
||||
WorkCandidate(kind="issue", number=643, labels=("status:ready",))
|
||||
],
|
||||
apply=False,
|
||||
profile_name="prgs-author",
|
||||
username="jcwalker3",
|
||||
)
|
||||
defaults.update(kwargs)
|
||||
return allocate_next_work(**defaults)
|
||||
|
||||
def _session_ids(self) -> set[str]:
|
||||
return {str(r.get("session_id")) for r in self.db.list_sessions()}
|
||||
|
||||
def test_side_effect_free_preview_writes_no_session_row(self):
|
||||
before = self._session_ids()
|
||||
result = self._alloc(side_effect_free=True)
|
||||
self.assertEqual(result["outcome"], OUTCOME_PREVIEW)
|
||||
self.assertEqual(self._session_ids(), before)
|
||||
self.assertNotIn("s-preview", self._session_ids())
|
||||
|
||||
def test_plain_dry_run_still_registers_a_session(self):
|
||||
# The default is unchanged for every existing caller.
|
||||
self._alloc()
|
||||
self.assertIn("s-preview", self._session_ids())
|
||||
|
||||
def test_repeated_previews_do_not_accumulate_rows(self):
|
||||
for index in range(5):
|
||||
self._alloc(side_effect_free=True, session_id=f"s-{index}")
|
||||
self.assertEqual(self._session_ids(), set())
|
||||
|
||||
def test_side_effect_free_does_not_sweep_stale_leases(self):
|
||||
self.db.upsert_session(session_id="owner", role="author", pid=1)
|
||||
assigned = self.db.assign_and_lease(
|
||||
session_id="owner",
|
||||
role="author",
|
||||
remote="prgs",
|
||||
org="org",
|
||||
repo="repo",
|
||||
kind="issue",
|
||||
number=999,
|
||||
lease_ttl_seconds=-60, # already expired
|
||||
)
|
||||
self.assertEqual(assigned.outcome, "assigned")
|
||||
|
||||
self._alloc(side_effect_free=True)
|
||||
|
||||
# The expired row is still 'active' in the DB: nothing swept it.
|
||||
statuses = {
|
||||
r["lease_id"]: r["status"]
|
||||
for r in self.db.list_leases(
|
||||
remote="prgs", org="org", repo="repo",
|
||||
statuses=("active", "expired"),
|
||||
)
|
||||
}
|
||||
self.assertEqual(statuses.get(assigned.lease_id), "active")
|
||||
|
||||
def test_expired_claims_are_filtered_in_memory_so_work_stays_selectable(self):
|
||||
"""The read-only mirror of the sweep: expired claims must not block."""
|
||||
self.db.upsert_session(session_id="owner", role="author", pid=1)
|
||||
self.db.assign_and_lease(
|
||||
session_id="owner",
|
||||
role="author",
|
||||
remote="prgs",
|
||||
org="org",
|
||||
repo="repo",
|
||||
kind="issue",
|
||||
number=643,
|
||||
lease_ttl_seconds=-60, # expired: must not withhold #643
|
||||
)
|
||||
result = self._alloc(side_effect_free=True)
|
||||
self.assertEqual(result["outcome"], OUTCOME_PREVIEW)
|
||||
self.assertEqual(result["selected"]["number"], 643)
|
||||
|
||||
def test_a_live_claim_still_withholds_the_work(self):
|
||||
self.db.upsert_session(session_id="owner", role="author", pid=1)
|
||||
self.db.assign_and_lease(
|
||||
session_id="owner",
|
||||
role="author",
|
||||
remote="prgs",
|
||||
org="org",
|
||||
repo="repo",
|
||||
kind="issue",
|
||||
number=643,
|
||||
lease_ttl_seconds=3600,
|
||||
)
|
||||
result = self._alloc(side_effect_free=True)
|
||||
self.assertNotEqual(result["outcome"], OUTCOME_ASSIGNED)
|
||||
self.assertNotEqual((result.get("selected") or {}).get("number"), 643)
|
||||
|
||||
def test_side_effect_free_with_apply_fails_closed(self):
|
||||
result = self._alloc(side_effect_free=True, apply=True)
|
||||
self.assertFalse(result["success"])
|
||||
self.assertEqual(result["outcome"], OUTCOME_NO_SAFE)
|
||||
self.assertIsNone(result["assignment"])
|
||||
self.assertIn("incompatible with apply", result["reasons"][0])
|
||||
# And it reserved nothing.
|
||||
self.assertEqual(
|
||||
self.db.list_leases(remote="prgs", org="org", repo="repo"), []
|
||||
)
|
||||
|
||||
|
||||
class DropExpiredClaimsTest(unittest.TestCase):
|
||||
"""The in-memory expiry filter behind side-effect-free previews (#643)."""
|
||||
|
||||
def test_unparseable_expiry_is_kept_rather_than_assumed_free(self):
|
||||
claims = {
|
||||
("issue", 1): {"lease_id": "l1", "expires_at": "not-a-date"},
|
||||
("issue", 2): {"lease_id": "l2"},
|
||||
("issue", 3): {"lease_id": "l3", "expires_at": None},
|
||||
}
|
||||
self.assertEqual(_drop_expired_claims(claims), claims)
|
||||
|
||||
def test_expired_dropped_and_future_kept(self):
|
||||
now = datetime(2026, 7, 25, 12, 0, tzinfo=timezone.utc)
|
||||
claims = {
|
||||
("issue", 1): {"expires_at": "2026-07-25T11:59:59+00:00"},
|
||||
("issue", 2): {"expires_at": "2026-07-25T12:00:01+00:00"},
|
||||
("issue", 3): {"expires_at": "2026-07-25T12:00:00+00:00"}, # boundary
|
||||
}
|
||||
kept = _drop_expired_claims(claims, now=now)
|
||||
self.assertEqual(set(kept), {("issue", 2)})
|
||||
|
||||
def test_naive_and_zulu_timestamps_are_treated_as_utc(self):
|
||||
now = datetime(2026, 7, 25, 12, 0, tzinfo=timezone.utc)
|
||||
claims = {
|
||||
("issue", 1): {"expires_at": "2026-07-25T11:00:00"}, # naive, past
|
||||
("issue", 2): {"expires_at": "2026-07-25T13:00:00Z"}, # zulu, future
|
||||
}
|
||||
kept = _drop_expired_claims(claims, now=now)
|
||||
self.assertEqual(set(kept), {("issue", 2)})
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
unittest.main()
|
||||
|
||||
@@ -1,404 +0,0 @@
|
||||
"""Tests for AI-provider connections and evidence-backed insights (#650).
|
||||
|
||||
Covers acceptance criteria:
|
||||
|
||||
1. Provider connection status is redacted and accurate (declared registry only).
|
||||
2. At least three insight types with evidence citations.
|
||||
3. Insights never claim actions completed without proof.
|
||||
4. Evidence requirement is enforced (no evidence-less insights).
|
||||
5. Interpretation limits appear in docs-facing payloads.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
import sys
|
||||
import unittest
|
||||
from dataclasses import dataclass
|
||||
from pathlib import Path
|
||||
from unittest import mock
|
||||
|
||||
sys.path.insert(0, str(Path(__file__).resolve().parent.parent))
|
||||
|
||||
from tests.webui_testclient import TestClient
|
||||
|
||||
from webui.app import create_app
|
||||
from webui.insights_loader import (
|
||||
CONFIDENCE_HIGH,
|
||||
CONNECTION_DECLARED_AVAILABLE,
|
||||
CONNECTION_DECLARED_UNAVAILABLE,
|
||||
INSIGHT_BLOCKED_QUEUE,
|
||||
INSIGHT_CONTROLLER_ATTENTION,
|
||||
INSIGHT_PROVIDER_WITHOUT_WORKERS,
|
||||
INSIGHT_STALE_RUNTIME,
|
||||
ProviderConnection,
|
||||
build_provider_connection,
|
||||
generate_insights,
|
||||
insight_blocked_queue,
|
||||
insight_controller_attention,
|
||||
insight_providers_without_workers,
|
||||
insight_stale_runtime,
|
||||
load_insights_snapshot,
|
||||
load_provider_snapshot,
|
||||
snapshot_insights_to_dict,
|
||||
snapshot_providers_to_dict,
|
||||
)
|
||||
from webui.insights_views import render_insights_page, render_providers_page
|
||||
from webui.nav import STUB_PAGES, nav_hrefs
|
||||
from webui.worker_registry import ProviderRecord, WorkerRecord, ScheduleSpec, SchedulerSpec
|
||||
|
||||
|
||||
def _provider(
|
||||
provider_id: str = "claude",
|
||||
*,
|
||||
available: bool = True,
|
||||
models: tuple[str, ...] = ("claude-opus-4-8",),
|
||||
notes: str = "",
|
||||
) -> ProviderRecord:
|
||||
return ProviderRecord(
|
||||
id=provider_id,
|
||||
display_name=provider_id.title(),
|
||||
vendor="TestVendor",
|
||||
executable=provider_id,
|
||||
available=available,
|
||||
models=models,
|
||||
notes=notes,
|
||||
)
|
||||
|
||||
|
||||
def _worker(
|
||||
worker_id: str = "claude-author",
|
||||
*,
|
||||
provider: str = "claude",
|
||||
enabled: bool = True,
|
||||
) -> WorkerRecord:
|
||||
return WorkerRecord(
|
||||
id=worker_id,
|
||||
display_name=worker_id,
|
||||
provider=provider,
|
||||
model="m1",
|
||||
project="gitea-tools",
|
||||
role="author",
|
||||
namespace="gitea-author",
|
||||
profile="prgs-author",
|
||||
workflow="skills/llm-project-workflow/workflows/work-issue.md",
|
||||
schedule=ScheduleSpec(kind="manual", seconds=None, expression=None),
|
||||
timeout_seconds=3600,
|
||||
enabled=enabled,
|
||||
scheduler=SchedulerSpec(kind="manual", label=None),
|
||||
notes="",
|
||||
)
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class _TrafficItem:
|
||||
kind: str
|
||||
number: int
|
||||
title: str = ""
|
||||
traffic_state: str = "blocked"
|
||||
expected_role: str = "author"
|
||||
safe_for_roles: tuple[str, ...] = ()
|
||||
badges: tuple[str, ...] = ()
|
||||
block_reason: str | None = "dependency"
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class _Traffic:
|
||||
blocked: tuple = ()
|
||||
needs_controller: tuple = ()
|
||||
inventory_complete: bool = True
|
||||
fetch_error: str | None = None
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class _Stale:
|
||||
daemon_head: str | None
|
||||
checkout_head: str | None
|
||||
remote_head: str | None
|
||||
stale: bool
|
||||
determinable: bool
|
||||
mutation_safe: bool
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class _Health:
|
||||
stale_runtime: _Stale | None
|
||||
|
||||
|
||||
class TestProviderConnections(unittest.TestCase):
|
||||
def test_available_provider_status(self):
|
||||
conn = build_provider_connection(_provider(available=True), (_worker(),))
|
||||
self.assertEqual(conn.connection_status, CONNECTION_DECLARED_AVAILABLE)
|
||||
self.assertTrue(conn.available_declared)
|
||||
self.assertEqual(conn.worker_count, 1)
|
||||
self.assertEqual(conn.enabled_worker_count, 1)
|
||||
self.assertFalse(conn.to_dict()["secrets_exposed"])
|
||||
|
||||
def test_unavailable_provider_status(self):
|
||||
conn = build_provider_connection(_provider(available=False), ())
|
||||
self.assertEqual(conn.connection_status, CONNECTION_DECLARED_UNAVAILABLE)
|
||||
self.assertEqual(conn.worker_count, 0)
|
||||
|
||||
def test_notes_are_redacted(self):
|
||||
conn = build_provider_connection(
|
||||
_provider(notes="token=ghp_thisisnotarealsecretvalue0001"),
|
||||
(),
|
||||
)
|
||||
self.assertNotIn("ghp_thisisnotarealsecretvalue0001", conn.notes)
|
||||
self.assertNotIn(
|
||||
"ghp_thisisnotarealsecretvalue0001",
|
||||
json.dumps(conn.to_dict()),
|
||||
)
|
||||
|
||||
def test_load_provider_snapshot_from_injected_registry(self):
|
||||
from webui.worker_registry import WorkerRegistry
|
||||
from pathlib import Path
|
||||
|
||||
registry = WorkerRegistry(
|
||||
version=1,
|
||||
revision=3,
|
||||
updated_at="2026-07-25T00:00:00Z",
|
||||
providers=(_provider("claude"), _provider("grok", available=False)),
|
||||
workers=(_worker(),),
|
||||
source_path=Path("/tmp/workers.registry.json"),
|
||||
)
|
||||
snapshot = load_provider_snapshot(registry=registry)
|
||||
self.assertTrue(snapshot.ok)
|
||||
self.assertEqual(snapshot.registry_revision, 3)
|
||||
ids = {p.provider_id for p in snapshot.providers}
|
||||
self.assertEqual(ids, {"claude", "grok"})
|
||||
|
||||
def test_registry_failure_is_fail_closed(self):
|
||||
def _boom():
|
||||
raise RuntimeError("disk gone")
|
||||
|
||||
snapshot = load_provider_snapshot(registry_loader=_boom)
|
||||
self.assertFalse(snapshot.ok)
|
||||
self.assertIn("unavailable", snapshot.fetch_error or "")
|
||||
self.assertEqual(snapshot.providers, ())
|
||||
|
||||
|
||||
class TestInsightGenerators(unittest.TestCase):
|
||||
def test_blocked_queue_requires_evidence(self):
|
||||
traffic = _Traffic(
|
||||
blocked=(
|
||||
_TrafficItem(kind="issue", number=647, block_reason="depends #646"),
|
||||
_TrafficItem(kind="pr", number=902, block_reason="conflict"),
|
||||
)
|
||||
)
|
||||
insight = insight_blocked_queue(traffic)
|
||||
self.assertIsNotNone(insight)
|
||||
self.assertEqual(insight.kind, INSIGHT_BLOCKED_QUEUE)
|
||||
self.assertGreaterEqual(len(insight.evidence), 2)
|
||||
self.assertTrue(insight.advisory_only)
|
||||
self.assertFalse(insight.claims_action_completed)
|
||||
refs = {e.ref for e in insight.evidence}
|
||||
self.assertIn("#647", refs)
|
||||
self.assertIn("#902", refs)
|
||||
|
||||
def test_empty_blocked_queue_yields_no_insight(self):
|
||||
self.assertIsNone(insight_blocked_queue(_Traffic()))
|
||||
|
||||
def test_controller_attention_insight(self):
|
||||
traffic = _Traffic(
|
||||
needs_controller=(_TrafficItem(kind="issue", number=100, traffic_state="needs_controller"),)
|
||||
)
|
||||
insight = insight_controller_attention(traffic)
|
||||
self.assertEqual(insight.kind, INSIGHT_CONTROLLER_ATTENTION)
|
||||
self.assertEqual(insight.evidence[0].ref, "#100")
|
||||
|
||||
def test_stale_runtime_insight(self):
|
||||
health = _Health(
|
||||
stale_runtime=_Stale(
|
||||
daemon_head="aaa",
|
||||
checkout_head="bbb",
|
||||
remote_head="ccc",
|
||||
stale=True,
|
||||
determinable=True,
|
||||
mutation_safe=False,
|
||||
)
|
||||
)
|
||||
insight = insight_stale_runtime(health)
|
||||
self.assertEqual(insight.kind, INSIGHT_STALE_RUNTIME)
|
||||
self.assertIn("stale", insight.evidence[0].detail)
|
||||
self.assertFalse(insight.claims_action_completed)
|
||||
|
||||
def test_mutation_safe_runtime_yields_no_insight(self):
|
||||
health = _Health(
|
||||
stale_runtime=_Stale(
|
||||
daemon_head="aaa",
|
||||
checkout_head="aaa",
|
||||
remote_head="aaa",
|
||||
stale=False,
|
||||
determinable=True,
|
||||
mutation_safe=True,
|
||||
)
|
||||
)
|
||||
self.assertIsNone(insight_stale_runtime(health))
|
||||
|
||||
def test_provider_without_workers(self):
|
||||
providers = (
|
||||
build_provider_connection(_provider("claude"), (_worker(),)),
|
||||
build_provider_connection(_provider("grok"), ()),
|
||||
)
|
||||
insight = insight_providers_without_workers(providers)
|
||||
self.assertEqual(insight.kind, INSIGHT_PROVIDER_WITHOUT_WORKERS)
|
||||
self.assertEqual(insight.evidence[0].ref, "grok")
|
||||
|
||||
def test_generate_insights_composes_three_kinds(self):
|
||||
from webui.worker_registry import WorkerRegistry
|
||||
from pathlib import Path
|
||||
|
||||
registry = WorkerRegistry(
|
||||
version=1,
|
||||
revision=1,
|
||||
updated_at="2026-07-25T00:00:00Z",
|
||||
providers=(_provider("lonely"),),
|
||||
workers=(),
|
||||
source_path=Path("/tmp/w.json"),
|
||||
)
|
||||
provider_snapshot = load_provider_snapshot(registry=registry)
|
||||
traffic = _Traffic(
|
||||
blocked=(_TrafficItem(kind="issue", number=1),),
|
||||
needs_controller=(_TrafficItem(kind="issue", number=2),),
|
||||
)
|
||||
health = _Health(
|
||||
stale_runtime=_Stale("a", "b", "c", True, True, False)
|
||||
)
|
||||
insights, used, unavailable = generate_insights(
|
||||
traffic=traffic,
|
||||
health=health,
|
||||
provider_snapshot=provider_snapshot,
|
||||
analytics=None,
|
||||
)
|
||||
kinds = {i.kind for i in insights}
|
||||
self.assertIn(INSIGHT_BLOCKED_QUEUE, kinds)
|
||||
self.assertIn(INSIGHT_CONTROLLER_ATTENTION, kinds)
|
||||
self.assertIn(INSIGHT_STALE_RUNTIME, kinds)
|
||||
self.assertIn(INSIGHT_PROVIDER_WITHOUT_WORKERS, kinds)
|
||||
self.assertGreaterEqual(len(kinds), 3)
|
||||
self.assertIn("traffic", used)
|
||||
self.assertIn("system_health", used)
|
||||
self.assertIn("providers", used)
|
||||
self.assertTrue(any(u["source"] == "analytics" for u in unavailable))
|
||||
for insight in insights:
|
||||
self.assertTrue(insight.advisory_only)
|
||||
self.assertFalse(insight.claims_action_completed)
|
||||
self.assertGreaterEqual(len(insight.evidence), 1)
|
||||
|
||||
def test_missing_source_is_reported_not_as_healthy_empty(self):
|
||||
insights, used, unavailable = generate_insights(
|
||||
traffic=None,
|
||||
health=None,
|
||||
provider_snapshot=None,
|
||||
analytics=None,
|
||||
)
|
||||
self.assertEqual(insights, ())
|
||||
self.assertEqual(used, ())
|
||||
self.assertEqual(len(unavailable), 4)
|
||||
|
||||
|
||||
class TestViewsAndRoutes(unittest.TestCase):
|
||||
def test_providers_page_renders_connections(self):
|
||||
from webui.worker_registry import WorkerRegistry
|
||||
from pathlib import Path
|
||||
|
||||
registry = WorkerRegistry(
|
||||
version=1,
|
||||
revision=1,
|
||||
updated_at="2026-07-25T00:00:00Z",
|
||||
providers=(_provider("claude"),),
|
||||
workers=(_worker(),),
|
||||
source_path=Path("/tmp/w.json"),
|
||||
)
|
||||
snapshot = load_provider_snapshot(registry=registry)
|
||||
html = render_providers_page(snapshot)
|
||||
self.assertIn("AI provider connections", html)
|
||||
self.assertIn("claude", html)
|
||||
self.assertIn("declared_available", html)
|
||||
self.assertIn("Interpretation limits", html)
|
||||
self.assertNotIn("api_key", html.lower())
|
||||
|
||||
def test_failed_provider_snapshot_renders_no_table(self):
|
||||
snapshot = load_provider_snapshot(registry_loader=lambda: (_ for _ in ()).throw(RuntimeError("x")))
|
||||
html = render_providers_page(snapshot)
|
||||
self.assertIn("unavailable", html.lower())
|
||||
self.assertNotIn("<tbody><tr><td><code>", html)
|
||||
|
||||
def test_insights_page_lists_evidence(self):
|
||||
traffic = _Traffic(blocked=(_TrafficItem(kind="issue", number=42),))
|
||||
snapshot = load_insights_snapshot(
|
||||
traffic=traffic,
|
||||
health=_Health(None),
|
||||
provider_snapshot=load_provider_snapshot(
|
||||
registry_loader=lambda: (_ for _ in ()).throw(RuntimeError("skip"))
|
||||
),
|
||||
analytics=None,
|
||||
load_live=False,
|
||||
)
|
||||
html = render_insights_page(snapshot)
|
||||
self.assertIn("#42", html)
|
||||
self.assertIn("advisory only", html.lower())
|
||||
self.assertIn("Evidence", html)
|
||||
|
||||
def test_nav_exposes_live_insights_and_providers(self):
|
||||
self.assertIn("/insights", nav_hrefs())
|
||||
self.assertIn("/providers", nav_hrefs())
|
||||
self.assertNotIn("/insights", STUB_PAGES)
|
||||
|
||||
def test_routes_are_read_only_and_export_json(self):
|
||||
client = TestClient(create_app())
|
||||
# Use live registry from package data — should be ok.
|
||||
with mock.patch(
|
||||
"webui.app.load_provider_snapshot",
|
||||
return_value=load_provider_snapshot(
|
||||
registry=__import__(
|
||||
"webui.worker_registry", fromlist=["load_registry"]
|
||||
).load_registry()
|
||||
),
|
||||
):
|
||||
response = client.get("/providers")
|
||||
self.assertEqual(response.status_code, 200)
|
||||
self.assertIn("provider", response.text.lower())
|
||||
api = client.get("/api/v1/providers")
|
||||
self.assertEqual(api.status_code, 200)
|
||||
payload = api.json()
|
||||
self.assertTrue(payload["ok"])
|
||||
self.assertIn("interpretation_limits", payload)
|
||||
self.assertTrue(all(not p.get("secrets_exposed") for p in payload["providers"]))
|
||||
|
||||
with mock.patch(
|
||||
"webui.app.load_insights_snapshot",
|
||||
return_value=load_insights_snapshot(
|
||||
traffic=_Traffic(blocked=(_TrafficItem(kind="issue", number=7),)),
|
||||
health=_Health(None),
|
||||
provider_snapshot=load_provider_snapshot(
|
||||
registry_loader=lambda: (_ for _ in ()).throw(RuntimeError("x"))
|
||||
),
|
||||
analytics=None,
|
||||
load_live=False,
|
||||
),
|
||||
):
|
||||
page = client.get("/insights")
|
||||
self.assertEqual(page.status_code, 200)
|
||||
self.assertIn("#7", page.text)
|
||||
api = client.get("/api/v1/insights")
|
||||
self.assertEqual(api.status_code, 200)
|
||||
body = api.json()
|
||||
self.assertTrue(body["ok"])
|
||||
self.assertTrue(all(i["advisory_only"] for i in body["insights"]))
|
||||
self.assertTrue(all(not i["claims_action_completed"] for i in body["insights"]))
|
||||
self.assertTrue(all(i["evidence"] for i in body["insights"]))
|
||||
|
||||
for path in ("/providers", "/api/v1/providers", "/insights", "/api/v1/insights"):
|
||||
with self.subTest(path=path):
|
||||
self.assertEqual(client.post(path).status_code, 405)
|
||||
|
||||
def test_home_nav_links_providers_and_insights(self):
|
||||
home = TestClient(create_app()).get("/").text
|
||||
self.assertIn('href="/providers"', home)
|
||||
self.assertIn('href="/insights"', home)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
unittest.main()
|
||||
File diff suppressed because it is too large
Load Diff
+118
-39
@@ -53,13 +53,6 @@ from webui.session_loader import (
|
||||
snapshot_to_dict as session_view_snapshot_to_dict,
|
||||
)
|
||||
from webui.session_views import render_sessions_page
|
||||
from webui.insights_loader import (
|
||||
load_insights_snapshot,
|
||||
load_provider_snapshot,
|
||||
snapshot_insights_to_dict,
|
||||
snapshot_providers_to_dict,
|
||||
)
|
||||
from webui.insights_views import render_insights_page, render_providers_page
|
||||
from webui.linkage_loader import (
|
||||
load_linkage_snapshot,
|
||||
snapshot_to_dict as linkage_snapshot_to_dict,
|
||||
@@ -84,6 +77,8 @@ from webui.system_health import (
|
||||
snapshot_to_dict as system_health_to_dict,
|
||||
)
|
||||
from webui.system_health_views import render_system_health_page
|
||||
from webui import request_service
|
||||
from webui.request_views import render_requests_page
|
||||
|
||||
_READ_ONLY_METHODS = frozenset({"GET", "HEAD", "OPTIONS"})
|
||||
_AUDIT_MUTATION_PATHS = frozenset({"/audit", "/api/audit"})
|
||||
@@ -354,34 +349,6 @@ async def api_sessions(_request: Request) -> JSONResponse:
|
||||
return JSONResponse(session_view_snapshot_to_dict(load_session_view_snapshot()))
|
||||
|
||||
|
||||
async def providers(_request: Request) -> HTMLResponse:
|
||||
"""AI-provider connection status (#650) — declared registry only, no secrets."""
|
||||
return HTMLResponse(render_providers_page(load_provider_snapshot()))
|
||||
|
||||
|
||||
async def api_v1_providers(_request: Request) -> JSONResponse:
|
||||
"""JSON export of declared AI-provider connections (#650)."""
|
||||
snapshot = load_provider_snapshot()
|
||||
return JSONResponse(
|
||||
snapshot_providers_to_dict(snapshot),
|
||||
status_code=200 if snapshot.ok else 502,
|
||||
)
|
||||
|
||||
|
||||
async def insights(_request: Request) -> HTMLResponse:
|
||||
"""Evidence-backed operational insights (#650) — advisory only."""
|
||||
return HTMLResponse(render_insights_page(load_insights_snapshot()))
|
||||
|
||||
|
||||
async def api_v1_insights(_request: Request) -> JSONResponse:
|
||||
"""JSON export of evidence-backed insights (#650)."""
|
||||
snapshot = load_insights_snapshot()
|
||||
return JSONResponse(
|
||||
snapshot_insights_to_dict(snapshot),
|
||||
status_code=200 if snapshot.ok else 502,
|
||||
)
|
||||
|
||||
|
||||
def _linkage_snapshot(request: Request):
|
||||
"""Load one linkage snapshot from the request's scope and focus parameters."""
|
||||
return load_linkage_snapshot(
|
||||
@@ -415,6 +382,8 @@ async def api_v1_gitea_linkage(request: Request) -> JSONResponse:
|
||||
linkage_snapshot_to_dict(snapshot),
|
||||
status_code=200 if snapshot.ok else 502,
|
||||
)
|
||||
|
||||
|
||||
async def _parse_audit_form(request: Request) -> tuple[str, str | None]:
|
||||
if request.method == "GET":
|
||||
return "", None
|
||||
@@ -812,6 +781,109 @@ async def api_v1_analytics_ingest(request: Request) -> JSONResponse:
|
||||
)
|
||||
|
||||
|
||||
def _default_request_scope() -> dict[str, str]:
|
||||
"""Resolve remote/org/repo from the project registry for request forms.
|
||||
|
||||
Returns an empty mapping when the registry cannot be read, which makes
|
||||
``parse_request`` reject a request that did not name its own scope rather
|
||||
than letting it default to some other repository.
|
||||
"""
|
||||
from webui.queue_loader import _host_from_url # host normalisation helper
|
||||
|
||||
registry, error = _load_project_registry()
|
||||
if error is not None or not registry.projects:
|
||||
return {}
|
||||
project = registry.projects[0]
|
||||
host = _host_from_url(project.remote_host)
|
||||
return {
|
||||
"remote": _derive_remote(host),
|
||||
"org": project.gitea_owner or "",
|
||||
"repo": project.repo_name or "",
|
||||
}
|
||||
|
||||
|
||||
async def _request_payload(request: Request) -> dict[str, object]:
|
||||
"""Read a request body as JSON or form-encoded. Never raises."""
|
||||
content_type = (request.headers.get("content-type") or "").lower()
|
||||
if "application/json" in content_type:
|
||||
try:
|
||||
body = await request.json()
|
||||
except Exception:
|
||||
return {}
|
||||
return dict(body) if isinstance(body, dict) else {}
|
||||
try:
|
||||
form = await request.form()
|
||||
except Exception:
|
||||
return {}
|
||||
return {key: form[key] for key in form}
|
||||
|
||||
|
||||
async def requests_page(request: Request) -> HTMLResponse:
|
||||
"""Operator request form and intent preview (#643).
|
||||
|
||||
POST here only ever *previews*. Initiation is a separate confirmed call to
|
||||
``/api/v1/requests/apply`` so that submitting this form cannot reserve
|
||||
work as a side effect.
|
||||
"""
|
||||
submitted: dict[str, object] = {}
|
||||
preview = None
|
||||
error = None
|
||||
if request.method == "POST":
|
||||
submitted = await _request_payload(request)
|
||||
work_request, error = request_service.parse_request(
|
||||
submitted, default_scope=_default_request_scope()
|
||||
)
|
||||
if work_request is not None:
|
||||
preview = request_service.preview_request(
|
||||
work_request,
|
||||
principal=resolve_principal(headers=dict(request.headers)),
|
||||
)
|
||||
return HTMLResponse(
|
||||
render_requests_page(
|
||||
preview=preview, error=error, submitted=submitted
|
||||
)
|
||||
)
|
||||
|
||||
|
||||
async def api_v1_request_preview(request: Request) -> JSONResponse:
|
||||
"""Dry-run authorization and intent preview for a work request (#643)."""
|
||||
payload = await _request_payload(request)
|
||||
work_request, error = request_service.parse_request(
|
||||
payload, default_scope=_default_request_scope()
|
||||
)
|
||||
if work_request is None:
|
||||
return JSONResponse(error.to_dict(), status_code=400)
|
||||
preview = request_service.preview_request(
|
||||
work_request,
|
||||
principal=resolve_principal(headers=dict(request.headers)),
|
||||
)
|
||||
return JSONResponse(
|
||||
preview.to_dict(), status_code=200 if preview.authorized else 403
|
||||
)
|
||||
|
||||
|
||||
async def api_v1_request_apply(request: Request) -> JSONResponse:
|
||||
"""Initiate a previewed work request through the allocator (#643).
|
||||
|
||||
Fail-closed at every step: unauthorized, unconfirmed, not-next-safe, and
|
||||
already-claimed all return without attempting an assignment.
|
||||
"""
|
||||
payload = await _request_payload(request)
|
||||
work_request, error = request_service.parse_request(
|
||||
payload, default_scope=_default_request_scope()
|
||||
)
|
||||
if work_request is None:
|
||||
return JSONResponse(error.to_dict(), status_code=400)
|
||||
confirm = _truthy_flag(str(payload.get("confirm") or ""))
|
||||
result = request_service.apply_request(
|
||||
work_request,
|
||||
principal=resolve_principal(headers=dict(request.headers)),
|
||||
confirm=confirm,
|
||||
)
|
||||
status = int(result.pop("status_code", 403))
|
||||
return JSONResponse(result, status_code=status)
|
||||
|
||||
|
||||
async def method_not_allowed(request: Request, _exc: Exception) -> Response:
|
||||
path = request.url.path
|
||||
if path in _AUDIT_MUTATION_PATHS and request.method == "POST":
|
||||
@@ -858,10 +930,6 @@ def create_app(*, bind_host: str | None = None) -> Starlette:
|
||||
Route("/api/sessions", api_sessions, methods=["GET"]),
|
||||
Route("/api/v1/sessions", api_sessions, methods=["GET"]),
|
||||
Route("/api/v1/timeline", api_v1_timeline, methods=["GET"]),
|
||||
Route("/providers", providers, methods=["GET"]),
|
||||
Route("/api/v1/providers", api_v1_providers, methods=["GET"]),
|
||||
Route("/insights", insights, methods=["GET"]),
|
||||
Route("/api/v1/insights", api_v1_insights, methods=["GET"]),
|
||||
Route("/gitea", gitea_linkage, methods=["GET"]),
|
||||
Route("/api/v1/gitea/linkage", api_v1_gitea_linkage, methods=["GET"]),
|
||||
Route("/analytics", analytics, methods=["GET"]),
|
||||
@@ -885,6 +953,17 @@ def create_app(*, bind_host: str | None = None) -> Starlette:
|
||||
api_action_attempt,
|
||||
methods=["POST"],
|
||||
),
|
||||
Route("/requests", requests_page, methods=["GET", "POST"]),
|
||||
Route(
|
||||
"/api/v1/requests/preview",
|
||||
api_v1_request_preview,
|
||||
methods=["POST"],
|
||||
),
|
||||
Route(
|
||||
"/api/v1/requests/apply",
|
||||
api_v1_request_apply,
|
||||
methods=["POST"],
|
||||
),
|
||||
Route("/api/leases", api_leases, methods=["GET"]),
|
||||
Route("/api/v1/inventory", api_inventory, methods=["GET"]),
|
||||
Route(
|
||||
|
||||
+71
-8
@@ -115,6 +115,12 @@ class ConsoleAction:
|
||||
break_glass: bool
|
||||
phase: int
|
||||
summary: str
|
||||
# Opt-in switch for an action whose execution path is genuinely wired
|
||||
# ahead of its phase becoming globally active (#643). Naming a variable
|
||||
# here enables nothing on its own: the variable must also be set in the
|
||||
# environment. An action that leaves this ``None`` can only execute once
|
||||
# ACTIVE_PHASE reaches its phase, exactly as before.
|
||||
execution_env_flag: str | None = None
|
||||
|
||||
@property
|
||||
def mcp_permission(self) -> str:
|
||||
@@ -277,6 +283,27 @@ _ACTION_SPECS: tuple[ConsoleAction, ...] = (
|
||||
phase=2,
|
||||
summary="Restart one MCP namespace via the host supervisor.",
|
||||
),
|
||||
# #643: submit a work request — desired role, issue/PR, intent — and let
|
||||
# the allocator reserve it. This is the one Phase 2 action whose execution
|
||||
# path is actually implemented (``webui.request_service``), so it carries
|
||||
# the opt-in flag; it stays denied until an operator sets that variable.
|
||||
# Authority is operator-class because the outcome is a claim, not a Gitea
|
||||
# verdict: initiating reviewer or merger *work* does not grant the right
|
||||
# to approve or merge, which stays with the MCP role profile.
|
||||
ConsoleAction(
|
||||
action_id="initiate_workflow",
|
||||
task_key="allocate_next_work",
|
||||
action_class=CLASS_WRITE,
|
||||
minimum_role=OPERATOR,
|
||||
requires_confirmation=True,
|
||||
dual_control=False,
|
||||
break_glass=False,
|
||||
phase=2,
|
||||
summary=(
|
||||
"Preview and initiate allocator-owned workflow work for a role."
|
||||
),
|
||||
execution_env_flag="WEBUI_REQUESTS_EXECUTION",
|
||||
),
|
||||
)
|
||||
|
||||
ACTIONS: dict[str, ConsoleAction] = {a.action_id: a for a in _ACTION_SPECS}
|
||||
@@ -430,6 +457,33 @@ ALLOW_PREVIEW = "allowed_preview_only"
|
||||
# gated on this model landing; nothing here enables it.
|
||||
ACTIVE_PHASE = 1
|
||||
|
||||
_TRUTHY = frozenset({"1", "true", "yes", "on"})
|
||||
|
||||
|
||||
def execution_wired(
|
||||
action: ConsoleAction | None, env: dict[str, str] | None = None
|
||||
) -> bool:
|
||||
"""Whether *action* has a live execution path right now.
|
||||
|
||||
Two ways to be wired, and only two. The action's phase is active, or the
|
||||
action declares an opt-in environment variable *and* that variable is set.
|
||||
Everything else — including every action that never declares a flag — is
|
||||
unwired, so the default across the registry stays deny.
|
||||
|
||||
Bumping ``ACTIVE_PHASE`` would enable execution for every action of that
|
||||
phase at once. The per-action flag exists so a single implemented action
|
||||
can go live without dragging its unimplemented phase-mates with it.
|
||||
"""
|
||||
if action is None:
|
||||
return False
|
||||
if action.phase <= ACTIVE_PHASE:
|
||||
return True
|
||||
flag = (action.execution_env_flag or "").strip()
|
||||
if not flag:
|
||||
return False
|
||||
source = env if env is not None else os.environ
|
||||
return (source.get(flag) or "").strip().lower() in _TRUTHY
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class AuthorizationDecision:
|
||||
@@ -469,16 +523,19 @@ def authorize(
|
||||
principal: Principal | None = None,
|
||||
*,
|
||||
for_execution: bool = False,
|
||||
env: dict[str, str] | None = None,
|
||||
) -> AuthorizationDecision:
|
||||
"""Decide whether *principal* may invoke *action_id*. Deny by default.
|
||||
|
||||
``for_execution`` distinguishes a read-only preview from a real invocation.
|
||||
Even an allowed decision reports ``execution_enabled=False`` while the
|
||||
console is in Phase 1, so no caller can read an allow as permission to
|
||||
mutate.
|
||||
``execution_enabled`` reports whether the action has a live execution path
|
||||
at all (:func:`execution_wired`) — for every action without an explicit
|
||||
opt-in flag that stays ``False`` while the console is in Phase 1, so no
|
||||
caller can read an allow as permission to mutate.
|
||||
"""
|
||||
who = principal if principal is not None else ANONYMOUS
|
||||
action = get_action(action_id)
|
||||
wired = execution_wired(action, env)
|
||||
|
||||
if action is None:
|
||||
return AuthorizationDecision(
|
||||
@@ -497,7 +554,7 @@ def authorize(
|
||||
"requires_confirmation": action.requires_confirmation,
|
||||
"dual_control": action.dual_control,
|
||||
"break_glass": action.break_glass,
|
||||
"execution_enabled": False,
|
||||
"execution_enabled": wired,
|
||||
}
|
||||
|
||||
if not who.authenticated:
|
||||
@@ -530,13 +587,19 @@ def authorize(
|
||||
**base,
|
||||
)
|
||||
|
||||
if for_execution and action.phase > ACTIVE_PHASE:
|
||||
if for_execution and not wired:
|
||||
return AuthorizationDecision(
|
||||
allowed=False,
|
||||
reason_code=DENY_PHASE_NOT_ACTIVE,
|
||||
detail=(
|
||||
f"Action {action_id!r} belongs to phase {action.phase}; the "
|
||||
f"console is in phase {ACTIVE_PHASE}. Execution is not wired."
|
||||
f"console is in phase {ACTIVE_PHASE}"
|
||||
+ (
|
||||
f" and {action.execution_env_flag} is not set"
|
||||
if action.execution_env_flag
|
||||
else ""
|
||||
)
|
||||
+ ". Execution is not wired."
|
||||
),
|
||||
**base,
|
||||
)
|
||||
@@ -545,8 +608,8 @@ def authorize(
|
||||
allowed=True,
|
||||
reason_code=ALLOW_PREVIEW,
|
||||
detail=(
|
||||
"Principal holds the required role. Preview only — execution "
|
||||
"remains disabled until the Phase 2 action framework ships."
|
||||
"Principal holds the required role. Execution proceeds only for an "
|
||||
"action with a wired execution path; everything else is preview."
|
||||
),
|
||||
**base,
|
||||
)
|
||||
|
||||
@@ -1,713 +0,0 @@
|
||||
"""AI-provider connections and evidence-backed operational insights (#650, Phase 4).
|
||||
|
||||
Operators need two related, **advisory** surfaces:
|
||||
|
||||
1. **Provider connection status** — which AI runtimes are *declared* in the
|
||||
worker registry (#798), without ever exposing API keys or inventing a live
|
||||
probe that this process cannot perform.
|
||||
2. **Evidence-backed insights** — short cards derived only from durable
|
||||
console evidence (traffic, system health, analytics, the same registry).
|
||||
Every insight carries explicit evidence refs (issue/PR/provider/event ids).
|
||||
Insights never claim that a workflow action completed without proof, and
|
||||
they never mutate anything.
|
||||
|
||||
Design rules matching the rest of the console:
|
||||
|
||||
- **Read-only.** No endpoint registered here mutates Gitea, the control plane,
|
||||
or the registry.
|
||||
- **Advisory only.** Insights carry ``advisory_only=True`` and never emit an
|
||||
"action completed" claim. The allocator, review, and merge paths remain the
|
||||
only authorities for work selection and terminal state.
|
||||
- **Qualified absence.** When a source could not run, the insight list says so
|
||||
rather than inventing an empty-and-healthy fleet or zero blocked items.
|
||||
- **Redaction.** Free-text titles, reasons, and notes pass through
|
||||
``webui.console_redaction`` before they leave this module.
|
||||
- **No secrets.** Provider records are taken from the credential-free worker
|
||||
registry. Keys never appear in this surface.
|
||||
|
||||
Non-goals (from the issue): free-form chatbot that overrides gates, secret
|
||||
provider keys in the UI, auto-merge or auto-close from insights.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import os
|
||||
from dataclasses import dataclass
|
||||
from typing import Any, Callable, Sequence
|
||||
|
||||
from webui import console_redaction
|
||||
from webui.worker_registry import (
|
||||
ProviderRecord,
|
||||
WorkerRegistry,
|
||||
WorkerRecord,
|
||||
load_registry as load_worker_registry,
|
||||
workers_for_provider,
|
||||
)
|
||||
|
||||
INSIGHTS_SCHEMA_VERSION = 1
|
||||
|
||||
# Provider connection vocabulary. Declared availability is not a live probe —
|
||||
# the worker registry owns the declaration, and adapters (#800) own live checks.
|
||||
CONNECTION_DECLARED_AVAILABLE = "declared_available"
|
||||
CONNECTION_DECLARED_UNAVAILABLE = "declared_unavailable"
|
||||
CONNECTION_REGISTRY_UNAVAILABLE = "registry_unavailable"
|
||||
|
||||
# Insight kinds. Each generator is a pure function over one evidence source.
|
||||
INSIGHT_BLOCKED_QUEUE = "blocked_queue_pressure"
|
||||
INSIGHT_CONTROLLER_ATTENTION = "controller_attention"
|
||||
INSIGHT_STALE_RUNTIME = "stale_runtime_risk"
|
||||
INSIGHT_PROVIDER_WITHOUT_WORKERS = "provider_without_workers"
|
||||
INSIGHT_ANALYTICS_FAILURE_RATE = "analytics_failure_pressure"
|
||||
|
||||
SEVERITY_INFO = "info"
|
||||
SEVERITY_WARN = "warn"
|
||||
SEVERITY_CRITICAL = "critical"
|
||||
SEVERITY_UNPROVEN = "unproven"
|
||||
|
||||
CONFIDENCE_HIGH = "high"
|
||||
CONFIDENCE_MEDIUM = "medium"
|
||||
CONFIDENCE_LOW = "low"
|
||||
CONFIDENCE_UNPROVEN = "unproven"
|
||||
|
||||
|
||||
def _redact(value: Any) -> Any:
|
||||
if value is None:
|
||||
return None
|
||||
return console_redaction.redact_text(str(value))
|
||||
|
||||
|
||||
def _offline_test_mode() -> bool:
|
||||
return (os.environ.get("WEBUI_TEST_OFFLINE") or "").strip().lower() in {
|
||||
"1",
|
||||
"true",
|
||||
"yes",
|
||||
"on",
|
||||
}
|
||||
|
||||
|
||||
# --- Provider connection status ------------------------------------------------
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class ProviderConnection:
|
||||
"""One AI provider's declared connection status (no secrets, no live probe)."""
|
||||
|
||||
provider_id: str
|
||||
display_name: str
|
||||
vendor: str
|
||||
executable: str
|
||||
connection_status: str
|
||||
available_declared: bool
|
||||
models: tuple[str, ...]
|
||||
worker_count: int
|
||||
enabled_worker_count: int
|
||||
notes: str
|
||||
#: Explicit statement of what was *not* proven (live process health, etc.).
|
||||
probe_limit: str
|
||||
|
||||
def to_dict(self) -> dict[str, Any]:
|
||||
return {
|
||||
"provider_id": self.provider_id,
|
||||
"display_name": self.display_name,
|
||||
"vendor": self.vendor,
|
||||
"executable": self.executable,
|
||||
"connection_status": self.connection_status,
|
||||
"available_declared": self.available_declared,
|
||||
"models": list(self.models),
|
||||
"worker_count": self.worker_count,
|
||||
"enabled_worker_count": self.enabled_worker_count,
|
||||
"notes": self.notes,
|
||||
"probe_limit": self.probe_limit,
|
||||
# Always true for this surface: keys are never loaded.
|
||||
"secrets_exposed": False,
|
||||
}
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class ProviderSnapshot:
|
||||
ok: bool
|
||||
providers: tuple[ProviderConnection, ...] = ()
|
||||
registry_revision: int | None = None
|
||||
registry_path: str | None = None
|
||||
fetch_error: str | None = None
|
||||
schema_version: int = INSIGHTS_SCHEMA_VERSION
|
||||
|
||||
def to_dict(self) -> dict[str, Any]:
|
||||
return {
|
||||
"ok": self.ok,
|
||||
"schema_version": self.schema_version,
|
||||
"registry_revision": self.registry_revision,
|
||||
"registry_path": self.registry_path,
|
||||
"fetch_error": self.fetch_error,
|
||||
"providers": [p.to_dict() for p in self.providers],
|
||||
"interpretation_limits": [
|
||||
"connection_status reflects the worker registry declaration only",
|
||||
"no API keys or credential material are loaded or rendered",
|
||||
"live executable health is not probed on this surface (#800 owns that)",
|
||||
],
|
||||
}
|
||||
|
||||
|
||||
_PROBE_LIMIT = (
|
||||
"Declared status only. This console does not probe the provider executable "
|
||||
"or call vendor APIs; live health belongs to the provider adapter framework."
|
||||
)
|
||||
|
||||
|
||||
def connection_status_for(provider: ProviderRecord) -> str:
|
||||
return (
|
||||
CONNECTION_DECLARED_AVAILABLE
|
||||
if provider.available
|
||||
else CONNECTION_DECLARED_UNAVAILABLE
|
||||
)
|
||||
|
||||
|
||||
def build_provider_connection(
|
||||
provider: ProviderRecord,
|
||||
workers: Sequence[WorkerRecord],
|
||||
) -> ProviderConnection:
|
||||
enabled = sum(1 for worker in workers if worker.enabled)
|
||||
return ProviderConnection(
|
||||
provider_id=provider.id,
|
||||
display_name=str(_redact(provider.display_name) or provider.id),
|
||||
vendor=str(_redact(provider.vendor) or ""),
|
||||
executable=str(_redact(provider.executable) or ""),
|
||||
connection_status=connection_status_for(provider),
|
||||
available_declared=bool(provider.available),
|
||||
models=tuple(str(_redact(m) or m) for m in provider.models),
|
||||
worker_count=len(workers),
|
||||
enabled_worker_count=enabled,
|
||||
notes=str(_redact(provider.notes) or ""),
|
||||
probe_limit=_PROBE_LIMIT,
|
||||
)
|
||||
|
||||
|
||||
def load_provider_snapshot(
|
||||
*,
|
||||
registry: WorkerRegistry | None = None,
|
||||
registry_loader: Callable[[], WorkerRegistry] | None = None,
|
||||
) -> ProviderSnapshot:
|
||||
"""Load declared provider connections. Never raises for missing registry."""
|
||||
if registry is None:
|
||||
loader = registry_loader or load_worker_registry
|
||||
try:
|
||||
if _offline_test_mode() and registry_loader is None:
|
||||
return ProviderSnapshot(
|
||||
ok=False,
|
||||
fetch_error=(
|
||||
"provider registry not loaded in offline test mode "
|
||||
"(inject a registry for unit tests)"
|
||||
),
|
||||
)
|
||||
registry = loader()
|
||||
except Exception as exc: # fail soft — operator-visible reason
|
||||
return ProviderSnapshot(
|
||||
ok=False,
|
||||
fetch_error=str(_redact(f"worker registry unavailable: {exc}")),
|
||||
)
|
||||
|
||||
connections = tuple(
|
||||
build_provider_connection(provider, workers_for_provider(registry, provider.id))
|
||||
for provider in registry.providers
|
||||
)
|
||||
return ProviderSnapshot(
|
||||
ok=True,
|
||||
providers=connections,
|
||||
registry_revision=registry.revision,
|
||||
registry_path=str(registry.source_path),
|
||||
)
|
||||
|
||||
|
||||
# --- Evidence-backed insights --------------------------------------------------
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class EvidenceRef:
|
||||
"""One durable reference an insight is allowed to cite."""
|
||||
|
||||
kind: str # issue | pr | provider | health | analytics | traffic
|
||||
ref: str
|
||||
detail: str
|
||||
|
||||
def to_dict(self) -> dict[str, Any]:
|
||||
return {
|
||||
"kind": self.kind,
|
||||
"ref": self.ref,
|
||||
"detail": str(_redact(self.detail) or ""),
|
||||
}
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class Insight:
|
||||
"""One advisory finding. Never a claim that an action completed."""
|
||||
|
||||
insight_id: str
|
||||
kind: str
|
||||
severity: str
|
||||
confidence: str
|
||||
title: str
|
||||
summary: str
|
||||
evidence: tuple[EvidenceRef, ...]
|
||||
advisory_only: bool = True
|
||||
claims_action_completed: bool = False
|
||||
|
||||
def to_dict(self) -> dict[str, Any]:
|
||||
return {
|
||||
"insight_id": self.insight_id,
|
||||
"kind": self.kind,
|
||||
"severity": self.severity,
|
||||
"confidence": self.confidence,
|
||||
"title": str(_redact(self.title) or ""),
|
||||
"summary": str(_redact(self.summary) or ""),
|
||||
"evidence": [item.to_dict() for item in self.evidence],
|
||||
"advisory_only": self.advisory_only,
|
||||
"claims_action_completed": self.claims_action_completed,
|
||||
}
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class InsightsSnapshot:
|
||||
ok: bool
|
||||
insights: tuple[Insight, ...] = ()
|
||||
sources_used: tuple[str, ...] = ()
|
||||
sources_unavailable: tuple[dict[str, str], ...] = ()
|
||||
fetch_error: str | None = None
|
||||
schema_version: int = INSIGHTS_SCHEMA_VERSION
|
||||
|
||||
def to_dict(self) -> dict[str, Any]:
|
||||
return {
|
||||
"ok": self.ok,
|
||||
"schema_version": self.schema_version,
|
||||
"insights": [insight.to_dict() for insight in self.insights],
|
||||
"sources_used": list(self.sources_used),
|
||||
"sources_unavailable": list(self.sources_unavailable),
|
||||
"fetch_error": self.fetch_error,
|
||||
"interpretation_limits": [
|
||||
"insights are advisory only and never authorize merge, review, or close",
|
||||
"an insight without evidence refs is refused rather than emitted",
|
||||
"a missing source is listed under sources_unavailable, not as an empty success",
|
||||
"insights never claim a workflow action completed",
|
||||
],
|
||||
}
|
||||
|
||||
|
||||
def _require_evidence(evidence: Sequence[EvidenceRef]) -> tuple[EvidenceRef, ...]:
|
||||
"""Fail closed: an insight with no evidence must not be emitted."""
|
||||
items = tuple(evidence)
|
||||
if not items:
|
||||
raise ValueError("insight requires at least one evidence ref")
|
||||
return items
|
||||
|
||||
|
||||
def insight_blocked_queue(traffic: Any) -> Insight | None:
|
||||
"""Traffic blocked bucket pressure with per-item evidence."""
|
||||
blocked = tuple(getattr(traffic, "blocked", ()) or ())
|
||||
if not blocked:
|
||||
return None
|
||||
evidence = []
|
||||
for item in blocked[:20]:
|
||||
kind = str(getattr(item, "kind", "issue") or "issue")
|
||||
number = int(getattr(item, "number", 0) or 0)
|
||||
if number <= 0:
|
||||
continue
|
||||
reason = getattr(item, "block_reason", None) or "blocked"
|
||||
evidence.append(
|
||||
EvidenceRef(
|
||||
kind=kind,
|
||||
ref=f"#{number}",
|
||||
detail=f"traffic_state=blocked; reason={reason}",
|
||||
)
|
||||
)
|
||||
if not evidence:
|
||||
return None
|
||||
count = len(blocked)
|
||||
severity = SEVERITY_CRITICAL if count >= 10 else SEVERITY_WARN
|
||||
return Insight(
|
||||
insight_id=f"{INSIGHT_BLOCKED_QUEUE}:{count}",
|
||||
kind=INSIGHT_BLOCKED_QUEUE,
|
||||
severity=severity,
|
||||
confidence=(
|
||||
CONFIDENCE_HIGH
|
||||
if getattr(traffic, "inventory_complete", False)
|
||||
else CONFIDENCE_MEDIUM
|
||||
),
|
||||
title=f"{count} blocked work item(s) in traffic control",
|
||||
summary=(
|
||||
f"Traffic control reports {count} blocked item(s). "
|
||||
"This is an observation of the loaded window, not a claim that "
|
||||
"any remediation ran."
|
||||
),
|
||||
evidence=_require_evidence(evidence),
|
||||
)
|
||||
|
||||
|
||||
def insight_controller_attention(traffic: Any) -> Insight | None:
|
||||
needs = tuple(getattr(traffic, "needs_controller", ()) or ())
|
||||
if not needs:
|
||||
return None
|
||||
evidence = []
|
||||
for item in needs[:20]:
|
||||
kind = str(getattr(item, "kind", "issue") or "issue")
|
||||
number = int(getattr(item, "number", 0) or 0)
|
||||
if number <= 0:
|
||||
continue
|
||||
evidence.append(
|
||||
EvidenceRef(
|
||||
kind=kind,
|
||||
ref=f"#{number}",
|
||||
detail="traffic_state=needs_controller",
|
||||
)
|
||||
)
|
||||
if not evidence:
|
||||
return None
|
||||
count = len(needs)
|
||||
return Insight(
|
||||
insight_id=f"{INSIGHT_CONTROLLER_ATTENTION}:{count}",
|
||||
kind=INSIGHT_CONTROLLER_ATTENTION,
|
||||
severity=SEVERITY_WARN if count else SEVERITY_INFO,
|
||||
confidence=(
|
||||
CONFIDENCE_HIGH
|
||||
if getattr(traffic, "inventory_complete", False)
|
||||
else CONFIDENCE_MEDIUM
|
||||
),
|
||||
title=f"{count} item(s) need controller attention",
|
||||
summary=(
|
||||
f"Traffic control marks {count} item(s) as needs_controller. "
|
||||
"Advisory only — the controller allocator remains the authority "
|
||||
"for routing."
|
||||
),
|
||||
evidence=_require_evidence(evidence),
|
||||
)
|
||||
|
||||
|
||||
def insight_stale_runtime(health: Any) -> Insight | None:
|
||||
stale = getattr(health, "stale_runtime", None)
|
||||
if stale is None:
|
||||
return None
|
||||
mutation_safe = bool(getattr(stale, "mutation_safe", False))
|
||||
is_stale = bool(getattr(stale, "stale", False))
|
||||
determinable = bool(getattr(stale, "determinable", False))
|
||||
if mutation_safe and not is_stale:
|
||||
return None
|
||||
daemon = getattr(stale, "daemon_head", None) or "unknown"
|
||||
checkout = getattr(stale, "checkout_head", None) or "unknown"
|
||||
remote = getattr(stale, "remote_head", None) or "unknown"
|
||||
if not determinable:
|
||||
severity = SEVERITY_UNPROVEN
|
||||
confidence = CONFIDENCE_UNPROVEN
|
||||
title = "Runtime parity is not determinable"
|
||||
summary = (
|
||||
"System health could not prove mutation_safe. This is not proof "
|
||||
"that the runtime is stale — only that parity was unproven."
|
||||
)
|
||||
else:
|
||||
severity = SEVERITY_CRITICAL if is_stale else SEVERITY_WARN
|
||||
confidence = CONFIDENCE_HIGH
|
||||
title = "Stale or mutation-unsafe runtime"
|
||||
summary = (
|
||||
"System health reports a runtime that is not mutation_safe. "
|
||||
"No restart or recovery is claimed by this insight."
|
||||
)
|
||||
return Insight(
|
||||
insight_id=f"{INSIGHT_STALE_RUNTIME}:{daemon}:{checkout}",
|
||||
kind=INSIGHT_STALE_RUNTIME,
|
||||
severity=severity,
|
||||
confidence=confidence,
|
||||
title=title,
|
||||
summary=summary,
|
||||
evidence=_require_evidence(
|
||||
(
|
||||
EvidenceRef(
|
||||
kind="health",
|
||||
ref="stale_runtime",
|
||||
detail=(
|
||||
f"stale={is_stale}; mutation_safe={mutation_safe}; "
|
||||
f"determinable={determinable}; daemon={daemon}; "
|
||||
f"checkout={checkout}; remote={remote}"
|
||||
),
|
||||
),
|
||||
)
|
||||
),
|
||||
)
|
||||
|
||||
|
||||
def insight_providers_without_workers(
|
||||
providers: Sequence[ProviderConnection],
|
||||
) -> Insight | None:
|
||||
lonely = [
|
||||
provider
|
||||
for provider in providers
|
||||
if provider.available_declared and provider.worker_count == 0
|
||||
]
|
||||
if not lonely:
|
||||
return None
|
||||
evidence = tuple(
|
||||
EvidenceRef(
|
||||
kind="provider",
|
||||
ref=provider.provider_id,
|
||||
detail=(
|
||||
f"available_declared=true; worker_count=0; "
|
||||
f"vendor={provider.vendor}"
|
||||
),
|
||||
)
|
||||
for provider in lonely
|
||||
)
|
||||
return Insight(
|
||||
insight_id=f"{INSIGHT_PROVIDER_WITHOUT_WORKERS}:{len(lonely)}",
|
||||
kind=INSIGHT_PROVIDER_WITHOUT_WORKERS,
|
||||
severity=SEVERITY_INFO,
|
||||
confidence=CONFIDENCE_HIGH,
|
||||
title=f"{len(lonely)} declared-available provider(s) have no workers",
|
||||
summary=(
|
||||
"The worker registry declares these providers available but no "
|
||||
"worker instance names them. This is a configuration observation, "
|
||||
"not a claim that a provider process is running or idle."
|
||||
),
|
||||
evidence=_require_evidence(evidence),
|
||||
)
|
||||
|
||||
|
||||
def insight_analytics_failures(analytics: Any) -> Insight | None:
|
||||
"""Flag elevated non-ok stage status in analytics when events exist."""
|
||||
if analytics is None or not getattr(analytics, "ok", False):
|
||||
return None
|
||||
events = tuple(getattr(analytics, "events", ()) or ())
|
||||
if not events:
|
||||
return None
|
||||
failed = [
|
||||
event
|
||||
for event in events
|
||||
if str(getattr(event, "status", "") or "").lower()
|
||||
in {"error", "failed", "failure"}
|
||||
]
|
||||
if not failed:
|
||||
return None
|
||||
# Cap evidence so a large window stays readable.
|
||||
evidence = []
|
||||
for event in failed[:20]:
|
||||
usage_id = getattr(event, "usage_id", None)
|
||||
issue = getattr(event, "issue_number", None)
|
||||
pr = getattr(event, "pr_number", None)
|
||||
if pr is not None:
|
||||
ref_kind, ref = "pr", f"#{int(pr)}"
|
||||
elif issue is not None:
|
||||
ref_kind, ref = "issue", f"#{int(issue)}"
|
||||
else:
|
||||
ref_kind, ref = "analytics", f"usage:{usage_id}"
|
||||
evidence.append(
|
||||
EvidenceRef(
|
||||
kind=ref_kind,
|
||||
ref=ref,
|
||||
detail=(
|
||||
f"status={getattr(event, 'status', '')}; "
|
||||
f"stage={getattr(event, 'stage', '')}; "
|
||||
f"model={getattr(event, 'model', '')}"
|
||||
),
|
||||
)
|
||||
)
|
||||
if not evidence:
|
||||
return None
|
||||
rate = len(failed) / max(len(events), 1)
|
||||
return Insight(
|
||||
insight_id=f"{INSIGHT_ANALYTICS_FAILURE_RATE}:{len(failed)}:{len(events)}",
|
||||
kind=INSIGHT_ANALYTICS_FAILURE_RATE,
|
||||
severity=SEVERITY_WARN if rate >= 0.1 else SEVERITY_INFO,
|
||||
confidence=CONFIDENCE_MEDIUM,
|
||||
title=f"{len(failed)} analytics event(s) reported failure status",
|
||||
summary=(
|
||||
f"{len(failed)} of {len(events)} loaded analytics events carry a "
|
||||
"failure status. Advisory only — this is not a gate decision."
|
||||
),
|
||||
evidence=_require_evidence(evidence),
|
||||
)
|
||||
|
||||
|
||||
def generate_insights(
|
||||
*,
|
||||
traffic: Any | None = None,
|
||||
health: Any | None = None,
|
||||
provider_snapshot: ProviderSnapshot | None = None,
|
||||
analytics: Any | None = None,
|
||||
) -> tuple[tuple[Insight, ...], tuple[str, ...], tuple[dict[str, str], ...]]:
|
||||
"""Pure multi-source insight generation. Never mutates inputs."""
|
||||
insights: list[Insight] = []
|
||||
used: list[str] = []
|
||||
unavailable: list[dict[str, str]] = []
|
||||
|
||||
if traffic is None:
|
||||
unavailable.append(
|
||||
{"source": "traffic", "reason": "traffic snapshot not supplied"}
|
||||
)
|
||||
elif getattr(traffic, "fetch_error", None):
|
||||
unavailable.append(
|
||||
{
|
||||
"source": "traffic",
|
||||
"reason": str(_redact(traffic.fetch_error) or "traffic fetch failed"),
|
||||
}
|
||||
)
|
||||
else:
|
||||
used.append("traffic")
|
||||
for builder in (insight_blocked_queue, insight_controller_attention):
|
||||
try:
|
||||
item = builder(traffic)
|
||||
except ValueError:
|
||||
continue
|
||||
if item is not None:
|
||||
insights.append(item)
|
||||
|
||||
if health is None:
|
||||
unavailable.append(
|
||||
{"source": "system_health", "reason": "system health snapshot not supplied"}
|
||||
)
|
||||
else:
|
||||
used.append("system_health")
|
||||
try:
|
||||
item = insight_stale_runtime(health)
|
||||
except ValueError:
|
||||
item = None
|
||||
if item is not None:
|
||||
insights.append(item)
|
||||
|
||||
if provider_snapshot is None:
|
||||
unavailable.append(
|
||||
{"source": "providers", "reason": "provider snapshot not supplied"}
|
||||
)
|
||||
elif not provider_snapshot.ok:
|
||||
unavailable.append(
|
||||
{
|
||||
"source": "providers",
|
||||
"reason": str(
|
||||
_redact(provider_snapshot.fetch_error)
|
||||
or "provider registry unavailable"
|
||||
),
|
||||
}
|
||||
)
|
||||
else:
|
||||
used.append("providers")
|
||||
try:
|
||||
item = insight_providers_without_workers(provider_snapshot.providers)
|
||||
except ValueError:
|
||||
item = None
|
||||
if item is not None:
|
||||
insights.append(item)
|
||||
|
||||
if analytics is None:
|
||||
unavailable.append(
|
||||
{"source": "analytics", "reason": "analytics snapshot not supplied"}
|
||||
)
|
||||
elif not getattr(analytics, "ok", False):
|
||||
unavailable.append(
|
||||
{
|
||||
"source": "analytics",
|
||||
"reason": str(
|
||||
_redact(getattr(analytics, "fetch_error", None))
|
||||
or "analytics snapshot not ok"
|
||||
),
|
||||
}
|
||||
)
|
||||
else:
|
||||
used.append("analytics")
|
||||
try:
|
||||
item = insight_analytics_failures(analytics)
|
||||
except ValueError:
|
||||
item = None
|
||||
if item is not None:
|
||||
insights.append(item)
|
||||
|
||||
# Stable ordering: severity then kind.
|
||||
_sev_rank = {
|
||||
SEVERITY_CRITICAL: 0,
|
||||
SEVERITY_WARN: 1,
|
||||
SEVERITY_INFO: 2,
|
||||
SEVERITY_UNPROVEN: 3,
|
||||
}
|
||||
insights.sort(key=lambda i: (_sev_rank.get(i.severity, 9), i.kind, i.insight_id))
|
||||
return tuple(insights), tuple(used), tuple(unavailable)
|
||||
|
||||
|
||||
def load_insights_snapshot(
|
||||
*,
|
||||
traffic: Any | None = None,
|
||||
health: Any | None = None,
|
||||
provider_snapshot: ProviderSnapshot | None = None,
|
||||
analytics: Any | None = None,
|
||||
load_live: bool = True,
|
||||
) -> InsightsSnapshot:
|
||||
"""Compose insights from injected or live console evidence sources."""
|
||||
sources_unavailable: list[dict[str, str]] = []
|
||||
|
||||
if load_live and traffic is None and not _offline_test_mode():
|
||||
try:
|
||||
from webui.traffic_loader import load_traffic_snapshot
|
||||
|
||||
traffic = load_traffic_snapshot()
|
||||
except Exception as exc: # fail soft
|
||||
sources_unavailable.append(
|
||||
{
|
||||
"source": "traffic",
|
||||
"reason": str(_redact(f"traffic load failed: {exc}")),
|
||||
}
|
||||
)
|
||||
traffic = None
|
||||
|
||||
if load_live and health is None and not _offline_test_mode():
|
||||
try:
|
||||
from webui.system_health import load_system_health
|
||||
|
||||
health = load_system_health()
|
||||
except Exception as exc:
|
||||
sources_unavailable.append(
|
||||
{
|
||||
"source": "system_health",
|
||||
"reason": str(_redact(f"system health load failed: {exc}")),
|
||||
}
|
||||
)
|
||||
health = None
|
||||
|
||||
if provider_snapshot is None:
|
||||
provider_snapshot = load_provider_snapshot()
|
||||
|
||||
if load_live and analytics is None and not _offline_test_mode():
|
||||
try:
|
||||
from webui.analytics_loader import load_analytics
|
||||
|
||||
analytics = load_analytics()
|
||||
except Exception as exc:
|
||||
sources_unavailable.append(
|
||||
{
|
||||
"source": "analytics",
|
||||
"reason": str(_redact(f"analytics load failed: {exc}")),
|
||||
}
|
||||
)
|
||||
analytics = None
|
||||
|
||||
insights, used, unavailable = generate_insights(
|
||||
traffic=traffic,
|
||||
health=health,
|
||||
provider_snapshot=provider_snapshot,
|
||||
analytics=analytics,
|
||||
)
|
||||
merged_unavailable = tuple(sources_unavailable) + unavailable
|
||||
# ok when at least one source contributed or we can honestly report absence.
|
||||
ok = bool(used) or bool(merged_unavailable)
|
||||
return InsightsSnapshot(
|
||||
ok=ok,
|
||||
insights=insights,
|
||||
sources_used=used,
|
||||
sources_unavailable=merged_unavailable,
|
||||
fetch_error=None
|
||||
if used
|
||||
else (
|
||||
"no evidence sources produced a usable snapshot"
|
||||
if merged_unavailable
|
||||
else "no insight sources ran"
|
||||
),
|
||||
)
|
||||
|
||||
|
||||
def snapshot_providers_to_dict(snapshot: ProviderSnapshot) -> dict[str, Any]:
|
||||
return snapshot.to_dict()
|
||||
|
||||
|
||||
def snapshot_insights_to_dict(snapshot: InsightsSnapshot) -> dict[str, Any]:
|
||||
return snapshot.to_dict()
|
||||
@@ -1,196 +0,0 @@
|
||||
"""HTML views for AI-provider connections and operational insights (#650)."""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
from html import escape
|
||||
|
||||
from webui.insights_loader import (
|
||||
CONNECTION_DECLARED_AVAILABLE,
|
||||
CONNECTION_DECLARED_UNAVAILABLE,
|
||||
InsightsSnapshot,
|
||||
ProviderSnapshot,
|
||||
SEVERITY_CRITICAL,
|
||||
SEVERITY_INFO,
|
||||
SEVERITY_UNPROVEN,
|
||||
SEVERITY_WARN,
|
||||
)
|
||||
from webui.layout import render_page
|
||||
|
||||
_SEVERITY_CSS = {
|
||||
SEVERITY_CRITICAL: "badge-blocked",
|
||||
SEVERITY_WARN: "badge-health-degraded",
|
||||
SEVERITY_INFO: "badge-health-ok",
|
||||
SEVERITY_UNPROVEN: "badge-health-unproven",
|
||||
}
|
||||
|
||||
_CONN_CSS = {
|
||||
CONNECTION_DECLARED_AVAILABLE: "badge-health-ok",
|
||||
CONNECTION_DECLARED_UNAVAILABLE: "badge-health-degraded",
|
||||
"registry_unavailable": "badge-blocked",
|
||||
}
|
||||
|
||||
|
||||
def _badge(text: str, css: str) -> str:
|
||||
return f'<span class="badge {css}">{escape(text)}</span>'
|
||||
|
||||
|
||||
def _limits_card(lines: list[str], *, title: str) -> str:
|
||||
items = "".join(f"<li>{escape(line)}</li>" for line in lines)
|
||||
return f"""<div class="prompt-card">
|
||||
<h3>{escape(title)}</h3>
|
||||
<ul class="reasons">{items}</ul>
|
||||
<p class="muted">Advisory surface only — no review, merge, close, or provider
|
||||
mutation is available here.</p>
|
||||
</div>"""
|
||||
|
||||
|
||||
def render_providers_page(snapshot: ProviderSnapshot) -> str:
|
||||
"""Render the AI-provider connections page."""
|
||||
if not snapshot.ok:
|
||||
body = f"""<h2>AI provider connections</h2>
|
||||
<p class="meta">Phase 4 read-only provider status (#650).</p>
|
||||
<div class="health-card health-stale">
|
||||
<strong>Provider registry unavailable:</strong>
|
||||
{escape(snapshot.fetch_error or "registry could not be loaded")}.
|
||||
No connection table is rendered — an empty table would claim that no
|
||||
providers are configured.
|
||||
</div>
|
||||
{_limits_card([
|
||||
"connection_status reflects the worker registry declaration only",
|
||||
"no API keys or credential material are loaded or rendered",
|
||||
"live executable health is not probed on this surface",
|
||||
], title="Interpretation limits")}
|
||||
"""
|
||||
return render_page(title="Providers", body_html=body)
|
||||
|
||||
rows = []
|
||||
for provider in snapshot.providers:
|
||||
models = (
|
||||
", ".join(f"<code>{escape(m)}</code>" for m in provider.models)
|
||||
if provider.models
|
||||
else '<span class="muted">none declared</span>'
|
||||
)
|
||||
rows.append(
|
||||
"<tr>"
|
||||
f"<td><code>{escape(provider.provider_id)}</code></td>"
|
||||
f"<td>{escape(provider.display_name)}</td>"
|
||||
f"<td>{escape(provider.vendor)}</td>"
|
||||
f"<td><code>{escape(provider.executable)}</code></td>"
|
||||
f"<td>{_badge(provider.connection_status, _CONN_CSS.get(provider.connection_status, 'badge-health-skipped'))}</td>"
|
||||
f"<td>{provider.worker_count} "
|
||||
f"({provider.enabled_worker_count} enabled)</td>"
|
||||
f"<td>{models}</td>"
|
||||
"</tr>"
|
||||
)
|
||||
table = (
|
||||
"".join(rows)
|
||||
if rows
|
||||
else '<tr><td colspan="7" class="muted">No providers declared in the registry.</td></tr>'
|
||||
)
|
||||
|
||||
body = f"""<h2>AI provider connections</h2>
|
||||
<p class="meta">Phase 4 read-only provider status (#650). Registry revision
|
||||
<code>{escape(str(snapshot.registry_revision))}</code>.
|
||||
Declared status only — secrets never load.</p>
|
||||
|
||||
<div class="health-card">
|
||||
<h3>Declared connections</h3>
|
||||
<table class="registry">
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Provider</th><th>Name</th><th>Vendor</th><th>Executable</th>
|
||||
<th>Connection</th><th>Workers</th><th>Models (declared)</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>{table}</tbody>
|
||||
</table>
|
||||
<p class="muted">{escape(snapshot.providers[0].probe_limit if snapshot.providers else "")}</p>
|
||||
</div>
|
||||
|
||||
{_limits_card([
|
||||
"connection_status reflects the worker registry declaration only",
|
||||
"no API keys or credential material are loaded or rendered",
|
||||
"live executable health is not probed on this surface (#800 owns that)",
|
||||
], title="Interpretation limits")}
|
||||
<p class="muted">Related: <a href="/insights">Operational insights</a> ·
|
||||
<a href="/analytics">Analytics</a></p>
|
||||
"""
|
||||
return render_page(title="Providers", body_html=body)
|
||||
|
||||
|
||||
def _evidence_list(insight) -> str:
|
||||
items = "".join(
|
||||
f"<li><code>{escape(ref.kind)}:{escape(ref.ref)}</code> — "
|
||||
f"{escape(ref.detail)}</li>"
|
||||
for ref in insight.evidence
|
||||
)
|
||||
return f'<ul class="reasons">{items}</ul>'
|
||||
|
||||
|
||||
def render_insights_page(snapshot: InsightsSnapshot) -> str:
|
||||
"""Render the operational insights page."""
|
||||
if not snapshot.ok and not snapshot.insights:
|
||||
body = f"""<h2>Operational insights</h2>
|
||||
<p class="meta">Phase 4 evidence-backed insights (#650).</p>
|
||||
<div class="health-card health-stale">
|
||||
<strong>Insights unavailable:</strong>
|
||||
{escape(snapshot.fetch_error or "no sources ran")}.
|
||||
</div>
|
||||
{_limits_card([
|
||||
"insights are advisory only and never authorize merge, review, or close",
|
||||
"an insight without evidence refs is refused rather than emitted",
|
||||
], title="Interpretation limits")}
|
||||
"""
|
||||
return render_page(title="Insights", body_html=body)
|
||||
|
||||
source_bits = []
|
||||
if snapshot.sources_used:
|
||||
source_bits.append(
|
||||
"sources used: " + ", ".join(f"<code>{escape(s)}</code>" for s in snapshot.sources_used)
|
||||
)
|
||||
if snapshot.sources_unavailable:
|
||||
missing = "; ".join(
|
||||
f"{escape(item.get('source', '?'))}: {escape(item.get('reason', ''))}"
|
||||
for item in snapshot.sources_unavailable
|
||||
)
|
||||
source_bits.append(f"sources unavailable: {missing}")
|
||||
|
||||
cards = []
|
||||
for insight in snapshot.insights:
|
||||
cards.append(
|
||||
f"""<div class="prompt-card">
|
||||
<h3>{_badge(insight.severity, _SEVERITY_CSS.get(insight.severity, "badge-health-skipped"))}
|
||||
{escape(insight.title)}</h3>
|
||||
<p class="meta"><code>{escape(insight.kind)}</code> · confidence
|
||||
<code>{escape(insight.confidence)}</code> ·
|
||||
{_badge("advisory only", "badge-health-skipped")} ·
|
||||
{_badge("no action claimed", "badge-health-ok")}</p>
|
||||
<p>{escape(insight.summary)}</p>
|
||||
<h4>Evidence</h4>
|
||||
{_evidence_list(insight)}
|
||||
</div>"""
|
||||
)
|
||||
if not cards:
|
||||
cards.append(
|
||||
'<div class="prompt-card"><p class="muted">No insights met the '
|
||||
"evidence threshold in the loaded sources. That is not a claim "
|
||||
"that the fleet is healthy — only that no qualifying pattern was "
|
||||
"found.</p></div>"
|
||||
)
|
||||
|
||||
body = f"""<h2>Operational insights</h2>
|
||||
<p class="meta">Phase 4 evidence-backed insights (#650). Derived only from
|
||||
durable console evidence; never invents policy or completes workflow actions.</p>
|
||||
<p class="muted">{" · ".join(source_bits) if source_bits else ""}</p>
|
||||
{"".join(cards)}
|
||||
{_limits_card([
|
||||
"insights are advisory only and never authorize merge, review, or close",
|
||||
"an insight without evidence refs is refused rather than emitted",
|
||||
"a missing source is listed as unavailable, not as an empty success",
|
||||
"insights never claim a workflow action completed",
|
||||
], title="Interpretation limits")}
|
||||
<p class="muted">Related: <a href="/providers">Provider connections</a> ·
|
||||
<a href="/traffic">Traffic</a> · <a href="/system-health">System health</a> ·
|
||||
<a href="/analytics">Analytics</a></p>
|
||||
"""
|
||||
return render_page(title="Insights", body_html=body)
|
||||
+12
-6
@@ -4,11 +4,12 @@ Single source of truth for the console navigation so ``webui/layout.py`` and
|
||||
the ``webui/app.py`` route table stay aligned with epic #631. Read-only: every
|
||||
destination is a GET view or a Phase 1 placeholder. No mutation links.
|
||||
|
||||
Nav groups follow the #631 information architecture: Health, Traffic,
|
||||
Nav groups follow the #631 Phase 1 information architecture: Health, Traffic,
|
||||
Runtime/Sessions, Projects, Inventory, Timeline, Policy (placeholder), and
|
||||
Gitea linkage (#645) plus Phase 4 Insights/Providers (#650). Later-phase
|
||||
surfaces are declared as ``stub`` items and backed by ``STUB_PAGES`` so their
|
||||
nav links resolve to a graceful placeholder instead of a 404.
|
||||
Insights (placeholder), joined by the Phase 3 Gitea linkage group (#645).
|
||||
Later-phase surfaces are declared as ``stub`` items and
|
||||
backed by ``STUB_PAGES`` so their nav links resolve to a graceful placeholder
|
||||
instead of a 404.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
@@ -45,6 +46,7 @@ NAV_GROUPS: tuple[NavGroup, ...] = (
|
||||
NavItem("/queue", "Queue"),
|
||||
NavItem("/leases", "Leases"),
|
||||
NavItem("/actions", "Actions"),
|
||||
NavItem("/requests", "Requests"),
|
||||
)),
|
||||
NavGroup("Runtime/Sessions", (
|
||||
NavItem("/runtime", "Runtime health"),
|
||||
@@ -68,8 +70,7 @@ NAV_GROUPS: tuple[NavGroup, ...] = (
|
||||
NavItem("/prompts", "Prompts"),
|
||||
)),
|
||||
NavGroup("Insights", (
|
||||
NavItem("/insights", "Insights"),
|
||||
NavItem("/providers", "Providers"),
|
||||
NavItem("/insights", "Insights", "stub"),
|
||||
NavItem("/analytics", "Analytics"),
|
||||
NavItem("/audit", "Audit"),
|
||||
)),
|
||||
@@ -93,6 +94,11 @@ STUB_PAGES: dict[str, tuple[str, str]] = {
|
||||
"Policy",
|
||||
"Capability and role policy surface. Placeholder until a later phase.",
|
||||
),
|
||||
"/insights": (
|
||||
"Insights",
|
||||
"Aggregate operational insights and trends. Placeholder until a later "
|
||||
"phase.",
|
||||
),
|
||||
}
|
||||
|
||||
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,164 @@
|
||||
"""HTML views for the operator request surface (#643).
|
||||
|
||||
The form is deliberately a *preview* form. It has no initiate button, because
|
||||
initiating requires a confirmed POST to ``/api/v1/requests/apply`` and a stray
|
||||
form submission must not be able to produce one by accident.
|
||||
|
||||
Nothing rendered here is trusted input: every interpolated value is escaped,
|
||||
and the page renders only values the service already produced rather than
|
||||
echoing a raw request body back.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import html
|
||||
import json
|
||||
from typing import Any
|
||||
|
||||
from webui.layout import render_page
|
||||
from webui.request_service import (
|
||||
REQUESTABLE_ROLES,
|
||||
WORK_KINDS,
|
||||
RequestError,
|
||||
RequestPreview,
|
||||
)
|
||||
|
||||
REQUESTS_PATH = "/requests"
|
||||
PREVIEW_API_PATH = "/api/v1/requests/preview"
|
||||
APPLY_API_PATH = "/api/v1/requests/apply"
|
||||
|
||||
|
||||
def _escape(text: Any) -> str:
|
||||
return html.escape(str(text if text is not None else ""), quote=True)
|
||||
|
||||
|
||||
REQUEST_PAGE_STYLES = """
|
||||
<style>
|
||||
.request-form { display: grid; gap: 0.75rem; max-width: 44rem; }
|
||||
.request-form label { display: grid; gap: 0.25rem; font-size: 0.9rem; }
|
||||
.request-check { margin: 0.35rem 0; }
|
||||
.request-check .verdict-ok { color: var(--accent); }
|
||||
.request-check .verdict-fail { color: #d14; }
|
||||
.request-prohibited code { margin-right: 0.4rem; }
|
||||
</style>
|
||||
"""
|
||||
|
||||
|
||||
def _options(values: tuple[str, ...], selected: Any) -> str:
|
||||
return "".join(
|
||||
f"<option value='{_escape(value)}'"
|
||||
+ (" selected" if selected == value else "")
|
||||
+ f">{_escape(value)}</option>"
|
||||
for value in values
|
||||
)
|
||||
|
||||
|
||||
def _form(values: dict[str, Any] | None = None) -> str:
|
||||
current = dict(values or {})
|
||||
number = current.get("work_number")
|
||||
return (
|
||||
f"<form class='request-form' method='post' action='{REQUESTS_PATH}'>"
|
||||
"<label>Desired role<select name='desired_role'>"
|
||||
f"{_options(REQUESTABLE_ROLES, current.get('desired_role'))}"
|
||||
"</select></label>"
|
||||
"<label>Work kind<select name='work_kind'>"
|
||||
f"{_options(WORK_KINDS, current.get('work_kind'))}"
|
||||
"</select></label>"
|
||||
"<label>Issue or PR number"
|
||||
"<input type='number' name='work_number' min='1' required "
|
||||
f"value='{_escape(number) if number else ''}'></label>"
|
||||
"<label>Intent summary"
|
||||
"<input type='text' name='intent_summary' maxlength='500' required "
|
||||
f"value='{_escape(current.get('intent_summary'))}'></label>"
|
||||
"<label>Expected head SHA <span class='muted'>(PR work only)</span>"
|
||||
"<input type='text' name='expected_head_sha' "
|
||||
f"value='{_escape(current.get('expected_head_sha'))}'></label>"
|
||||
"<button type='submit' class='copy-btn'>Preview request</button>"
|
||||
"<p class='muted meta'>Preview is read-only and creates no assignment. "
|
||||
f"Initiating requires a confirmed POST to <code>{APPLY_API_PATH}</code>."
|
||||
"</p>"
|
||||
"</form>"
|
||||
)
|
||||
|
||||
|
||||
def _checks_block(preview: RequestPreview) -> str:
|
||||
rows = []
|
||||
for check in preview.checks:
|
||||
verdict = "PASS" if check.ok else "FAIL"
|
||||
css = "verdict-ok" if check.ok else "verdict-fail"
|
||||
rows.append(
|
||||
"<li class='request-check'>"
|
||||
f"<span class='{css}'><strong>{verdict}</strong></span> "
|
||||
f"<code>{_escape(check.name)}</code> — {_escape(check.detail)} "
|
||||
f"<span class='muted meta'>({_escape(check.reason_code)})</span>"
|
||||
"</li>"
|
||||
)
|
||||
return "<ul>" + "".join(rows) + "</ul>"
|
||||
|
||||
|
||||
def _preview_block(preview: RequestPreview) -> str:
|
||||
verdict = "AUTHORIZED" if preview.authorized else "DENIED"
|
||||
prohibited = "".join(
|
||||
f"<code>{_escape(action)}</code>" for action in preview.prohibited_actions
|
||||
)
|
||||
request = preview.request
|
||||
evidence = json.dumps(preview.allocator_evidence, indent=2, default=str)
|
||||
return (
|
||||
"<h3>Intent preview</h3>"
|
||||
f"<p><strong>{verdict}</strong> — {_escape(preview.detail)}</p>"
|
||||
"<p class='meta'>"
|
||||
f"Role <code>{_escape(request.desired_role)}</code> · "
|
||||
f"{_escape(request.work_kind)} <code>{_escape(request.display_ref)}</code>"
|
||||
f" · profile <code>{_escape(preview.required_profile)}</code> · "
|
||||
f"namespace <code>{_escape(preview.required_namespace)}</code> · "
|
||||
f"permission <code>{_escape(preview.required_permission)}</code>"
|
||||
"</p>"
|
||||
f"<p>Intent: {_escape(request.intent_summary)}</p>"
|
||||
f"{_checks_block(preview)}"
|
||||
f"<p><strong>Next safe action:</strong> "
|
||||
f"{_escape(preview.next_safe_action)}</p>"
|
||||
"<p class='request-prohibited'><strong>Prohibited for this role:</strong> "
|
||||
+ (prohibited or "<span class='muted'>none declared</span>")
|
||||
+ "</p>"
|
||||
"<p class='muted meta'>Correlation id "
|
||||
f"<code>{_escape(preview.correlation_id)}</code></p>"
|
||||
"<details><summary>Allocator evidence</summary>"
|
||||
f"<pre class='prompt-text'>{_escape(evidence)}</pre>"
|
||||
"</details>"
|
||||
)
|
||||
|
||||
|
||||
def _error_block(error: RequestError) -> str:
|
||||
field = (
|
||||
f"<p class='meta'>Field: <code>{_escape(error.field_name)}</code></p>"
|
||||
if error.field_name
|
||||
else ""
|
||||
)
|
||||
return (
|
||||
"<h3>Request rejected</h3>"
|
||||
f"<p><strong>{_escape(error.reason_code)}</strong> — "
|
||||
f"{_escape(error.detail)}</p>{field}"
|
||||
)
|
||||
|
||||
|
||||
def render_requests_page(
|
||||
*,
|
||||
preview: RequestPreview | None = None,
|
||||
error: RequestError | None = None,
|
||||
submitted: dict[str, Any] | None = None,
|
||||
) -> str:
|
||||
"""Render the request form, plus a preview or rejection when one exists."""
|
||||
body = (
|
||||
"<h2>Requests</h2>"
|
||||
"<p>Submit a work request — desired role, issue or PR, and intent — "
|
||||
"and see whether it would be authorized before anything is reserved. "
|
||||
"Initiation goes through the allocator (#600/#613); this console never "
|
||||
"self-selects work, never approves, and never merges.</p>"
|
||||
+ _form(submitted)
|
||||
+ (_error_block(error) if error is not None else "")
|
||||
+ (_preview_block(preview) if preview is not None else "")
|
||||
+ f"<p class='meta'><a href='{PREVIEW_API_PATH}'>Preview API</a> · "
|
||||
"<a href='/api/console/security-model'>RBAC model</a></p>"
|
||||
+ REQUEST_PAGE_STYLES
|
||||
)
|
||||
return render_page(title="Requests", body_html=body)
|
||||
@@ -201,6 +201,16 @@ def _candidates_from_queue_snapshot(q_snap: QueueSnapshot) -> list[WorkCandidate
|
||||
return candidates
|
||||
|
||||
|
||||
def candidates_from_queue_snapshot(q_snap: QueueSnapshot) -> list[WorkCandidate]:
|
||||
"""Public alias for :func:`_candidates_from_queue_snapshot` (#643).
|
||||
|
||||
The request-initiation service ranks the same candidate set this view
|
||||
renders, so both must agree on how a queue row becomes a candidate. One
|
||||
construction, two callers — not two that can drift apart.
|
||||
"""
|
||||
return _candidates_from_queue_snapshot(q_snap)
|
||||
|
||||
|
||||
def _claim_lease_records(inventory: dict[str, Any] | None) -> list[dict[str, Any]]:
|
||||
"""Normalize ``build_claim_inventory`` entries into lease records.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user