Compare commits
11
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
211890f361 | ||
|
|
76f293eb28 | ||
|
|
54559aebc3 | ||
|
|
715863799f | ||
|
|
daf7ed4c2b | ||
|
|
8598537a35 | ||
|
|
6e6ca94338 | ||
|
|
d5d121a21b | ||
|
|
1ca2b50406 | ||
|
|
a81db75402 | ||
|
|
619f679077 |
+107
-6
@@ -77,7 +77,11 @@ status, onboarding checklist state, and the fail-closed error payloads (#635).
|
||||
| `/api/actions/{id}/preview` | Mutation ledger preview (GET, read-only) |
|
||||
| `/leases` | Lease and collision visibility (#433) |
|
||||
| `/api/leases` | JSON lease/collision export |
|
||||
| `/sessions` | Phase 1 shell stub — session inventory (backed by #636) |
|
||||
| `/sessions` | Runtime and session view (#641) — health + inventory sessions/namespaces/worktrees |
|
||||
| `/api/sessions` | JSON export for the runtime/session view |
|
||||
| `/api/v1/sessions` | Versioned alias of `/api/sessions` |
|
||||
| `/gitea` | Gitea issue↔PR linkage console (#645) — both directions, with the evidence for each edge |
|
||||
| `/api/v1/gitea/linkage` | JSON linkage export; `502` when the read could not be answered |
|
||||
| `/inventory` | Phase 1 shell stub — unified inventory (backed by #636) |
|
||||
| `/timeline` | Phase 1 shell stub — workflow event timeline |
|
||||
| `/policy` | Phase 1 shell stub — capability/role policy placeholder |
|
||||
@@ -284,11 +288,108 @@ The header carries two read-only status badges — an **environment** badge
|
||||
a **mode: read-only** badge — plus a **Docs** link to this document. No
|
||||
privileged action controls are present in the Phase 1 shell.
|
||||
|
||||
Not-yet-implemented surfaces (`/sessions`, `/inventory`, `/timeline`,
|
||||
`/policy`, `/insights`) resolve to graceful read-only stub pages instead of
|
||||
404s; their backing views land in later child issues of #631 (the inventory
|
||||
surfaces are backed by #636). Mutating methods on stub routes still fail closed
|
||||
with `read-only-mvp`.
|
||||
Not-yet-implemented surfaces (`/inventory`, `/timeline`, `/policy`,
|
||||
`/insights`) resolve to graceful read-only stub pages instead of 404s; their
|
||||
backing views land in later child issues of #631 (the inventory surfaces are
|
||||
backed by #636). Mutating methods on stub routes still fail closed with
|
||||
`read-only-mvp`.
|
||||
|
||||
### Runtime and sessions (#641)
|
||||
|
||||
`/sessions` is a live Phase 1 read-only view that composes:
|
||||
|
||||
* runtime health from `#430` (profile, role, identity, master parity, stale warning)
|
||||
* control-plane sessions / leases and filesystem locks / worktrees / namespaces from `#636`
|
||||
* durable contamination markers when detectable (`#630` runtime recovery, `#671` stable-branch push)
|
||||
|
||||
It surfaces stale indicators (dead PID, expired lease) and never silences an
|
||||
active contamination marker. Recovery links point only at sanctioned
|
||||
reconnect/operator restart docs (`docs/mcp-namespace-eof-recovery.md`,
|
||||
`docs/mcp-namespace-health.md`, `docs/mcp-restart-path-inventory.md`, this
|
||||
document). The page does **not** restart, kill, or take over sessions; manual
|
||||
`pkill` of MCP daemons is contamination, not recovery.
|
||||
|
||||
Honesty rules specific to this view:
|
||||
|
||||
* **Ownership columns never assert absence they cannot prove.** When the
|
||||
`leases` or `locks` section is degraded or unavailable, the Leases and
|
||||
Worktree-binding cells render `unknown (inventory <status>)` with an
|
||||
*authority unproven* badge instead of `none` / `unbound`, and a caveat names
|
||||
the unreadable sections. A worktree binding is correlated through lease work
|
||||
numbers, so it is unproven when *either* section fails to read.
|
||||
`/api/sessions` carries the same facts as `ownership_authority_complete`,
|
||||
`ownership_section_status`, and per-row `lease_authority` /
|
||||
`worktree_authority`, so a JSON consumer can tell "holds none" from "could
|
||||
not be read".
|
||||
* **Contamination text is redacted at the display boundary.** Marker payloads
|
||||
(`command_summary`, `reason_class`, `session_id`, `role`) are
|
||||
operator-supplied free text that does not arrive through inventory scrubbing,
|
||||
so they pass through `webui.inventory.scrub_text`, which collapses `$HOME` and
|
||||
redacts credential-shaped tokens and URL userinfo *anywhere* in the string.
|
||||
The write-time redactor is a narrow denylist and is not relied on. The field
|
||||
itself is kept — it is the `#630` evidence naming which daemon was killed.
|
||||
|
||||
## Gitea issue/PR linkage (#645)
|
||||
|
||||
`/gitea` is the Phase 3 read-only linkage console: which PR carries which issue,
|
||||
which issues are claimed by more than one PR, and what the latest Canonical
|
||||
Thread Handoff on a thread said. Gitea remains the source of truth — this
|
||||
surface reads it and never writes to it. There is no issue/PR editor, no review,
|
||||
and no merge control.
|
||||
|
||||
Query parameters (all optional):
|
||||
|
||||
| Parameter | Meaning |
|
||||
|-----------|---------|
|
||||
| `project` | Registry project id to scope the read (default: first registry entry) |
|
||||
| `state` | `open` (default) or `all`; `all` widens the window to merged/closed items, where a landed edge lives |
|
||||
| `issue=N` / `pr=N` | Focus one thread and load *its* latest canonical handoff |
|
||||
|
||||
`GET /api/v1/gitea/linkage` returns the same model as JSON
|
||||
(`schema_version: 1`). It answers `502` when the read could not be answered, so
|
||||
an automated consumer cannot mistake a fail-closed payload for "no links exist".
|
||||
The HTML page always answers `200` and renders the reason instead — an operator
|
||||
view must show why a read failed rather than withhold the page.
|
||||
|
||||
### How an edge is found
|
||||
|
||||
Each edge carries the evidence that produced it, strongest first:
|
||||
|
||||
| Evidence | Meaning |
|
||||
|----------|---------|
|
||||
| `closes_keyword` | The PR title or body declares `closes/fixes/resolves #N`. Gitea itself acts on this keyword. |
|
||||
| `branch_marker` | The PR head branch carries the canonical `(fix\|feat\|docs\|chore)/issue-N-…` marker minted by the issue lock. |
|
||||
| `body_reference` | The PR body mentions `#N` with no closing keyword. A mention is not a claim to close. |
|
||||
|
||||
Only closing and branch-marker edges populate the **issue → PR** direction: a
|
||||
bare mention is a cross-link, and counting it as ownership would invent
|
||||
contested issues out of ordinary references. The mention stays visible on the
|
||||
**PR → issue** side, labelled as such. A PR whose two strongest edges tie is
|
||||
flagged `ambiguous`; an issue claimed by two PRs is flagged `contested`.
|
||||
|
||||
### Honesty rules specific to this view
|
||||
|
||||
* **A partial read never reads as an absence.** Linkage is a claim about the
|
||||
loaded window only. When pagination did not complete, every empty edge cell
|
||||
renders `none found (partial inventory)` rather than `none`, and the JSON
|
||||
carries `inventory_complete: false` plus per-row `links_authoritative: false`.
|
||||
* **A failed read renders no table at all.** Missing credentials, an unknown
|
||||
project, or a fetch error produce `ok: false` with a reason. An empty linkage
|
||||
table would assert that no issue is linked to any PR, which such a read is not
|
||||
in a position to claim.
|
||||
* **Handoffs are loaded, never assumed.** CTH comments are thread-scoped, so
|
||||
only the focused issue or PR has its comments fetched. Every other row reports
|
||||
`not_loaded` with the reason; a thread whose comments *were* loaded and carried
|
||||
no CTH says exactly that. A comment-source failure degrades the handoff alone —
|
||||
the linkage tables still render.
|
||||
* **Unrecognised handoff headings are reported, not republished.** A `## CTH:`
|
||||
heading outside `CTH_TYPES` renders as `unrecognized`.
|
||||
* **Redaction precedes display.** Titles, labels, handoff fields, and error
|
||||
reasons pass through `webui.console_redaction` before serialization, and the
|
||||
page HTML-escapes everything it renders.
|
||||
* **Deep links are opt-in.** A link out to the Gitea web UI appears only when
|
||||
`GITEA_MCP_REVEAL_ENDPOINTS=1` is set server-side, matching how the MCP tools
|
||||
gate URL exposure. Item numbers stay usable without it.
|
||||
|
||||
## System-health dashboard (#639)
|
||||
|
||||
|
||||
+296
-70
@@ -9552,15 +9552,13 @@ def gitea_edit_pr(
|
||||
if closing:
|
||||
gate_reasons = _profile_operation_gate("gitea.pr.close")
|
||||
if gate_reasons:
|
||||
return {
|
||||
"success": False,
|
||||
"performed": False,
|
||||
"pr_number": pr_number,
|
||||
"requested_state": "closed",
|
||||
"required_permission": "gitea.pr.close",
|
||||
"reasons": gate_reasons,
|
||||
"permission_report": _permission_block_report("gitea.pr.close"),
|
||||
}
|
||||
return _build_operation_gate_refusal(
|
||||
"gitea.pr.close",
|
||||
gate_reasons,
|
||||
pr_number=pr_number,
|
||||
requested_state="closed",
|
||||
required_permission="gitea.pr.close",
|
||||
)
|
||||
|
||||
h, o, r = _resolve(remote, host, org, repo)
|
||||
auth = _auth(h)
|
||||
@@ -13823,13 +13821,17 @@ def gitea_view_issue(
|
||||
|
||||
def _permission_block_report(required_operation: str,
|
||||
identity: str | None = None) -> dict:
|
||||
"""Structured, LLM-safe explanation of a permission denial (#142).
|
||||
"""Structured, LLM-safe explanation of a permission denial (#142, #897).
|
||||
|
||||
Built only after a gate has already refused; it adds guidance to the
|
||||
refusal and never widens any permission, performs network I/O, or
|
||||
raises (fail-soft: degrades to a minimal fail-closed report). Names
|
||||
configured profiles only — never auth references, tokens, endpoint
|
||||
URLs, or keychain IDs.
|
||||
|
||||
#897: never fabricate a missing permission when the active profile
|
||||
already allows the operation. That path is a diagnostic defect (the
|
||||
refusal was not a permission denial), not a cue to switch profiles.
|
||||
"""
|
||||
report = {
|
||||
"requested_operation": required_operation,
|
||||
@@ -13841,6 +13843,7 @@ def _permission_block_report(required_operation: str,
|
||||
"matching_configured_profiles": [],
|
||||
"runtime_switching_supported": False,
|
||||
"different_mcp_namespace_required": True,
|
||||
"diagnostic_defect": False,
|
||||
"exact_safe_next_action": (
|
||||
"Ask the operator to fix GITEA_MCP_CONFIG/GITEA_MCP_PROFILE; "
|
||||
"the active profile could not be resolved (fail closed)."),
|
||||
@@ -13855,6 +13858,32 @@ def _permission_block_report(required_operation: str,
|
||||
report["active_allowed_operations"] = (
|
||||
profile.get("allowed_operations") or [])
|
||||
|
||||
# #897: fail closed as a diagnostic defect when the active profile
|
||||
# already holds the operation — callers must not invent "missing".
|
||||
try:
|
||||
holds, _hold_reason = gitea_config.check_operation(
|
||||
required_operation,
|
||||
profile.get("allowed_operations") or [],
|
||||
profile.get("forbidden_operations") or [],
|
||||
)
|
||||
except Exception:
|
||||
holds = False
|
||||
if holds:
|
||||
report["missing_permission"] = None
|
||||
report["required_permission"] = required_operation
|
||||
report["diagnostic_defect"] = True
|
||||
report["different_mcp_namespace_required"] = False
|
||||
report["exact_safe_next_action"] = (
|
||||
"Diagnostic defect: the active profile already allows "
|
||||
f"{required_operation}. This is not a permission denial — "
|
||||
"inspect blocker_kind / reasons (stale-runtime or runtime-mode). "
|
||||
"Do not call gitea_activate_profile or switch MCP sessions."
|
||||
)
|
||||
report["matching_configured_profiles"] = [
|
||||
p for p in [profile.get("profile_name")] if p
|
||||
]
|
||||
return report
|
||||
|
||||
matching = []
|
||||
try:
|
||||
config = gitea_config.load_config() or {}
|
||||
@@ -13903,6 +13932,205 @@ def _permission_block_report(required_operation: str,
|
||||
return report
|
||||
|
||||
|
||||
def _reason_is_stale_runtime(reason: str) -> bool:
|
||||
"""True when *reason* is a master-parity / stale-daemon refusal (#897)."""
|
||||
r = (reason or "").lower()
|
||||
if not r:
|
||||
return False
|
||||
if "stale relative to live master" in r:
|
||||
return True
|
||||
if "server code is stale" in r:
|
||||
return True
|
||||
if "daemon is stale" in r:
|
||||
return True
|
||||
if "started at commit" in r and "workspace master is now" in r:
|
||||
return True
|
||||
if "mcp server started at" in r and "stale" in r:
|
||||
return True
|
||||
if "restart the server to load the current capability gates" in r:
|
||||
return True
|
||||
if "restart/reconnect before mutating" in r:
|
||||
return True
|
||||
return False
|
||||
|
||||
|
||||
def _reason_is_runtime_mode(reason: str) -> bool:
|
||||
"""True when *reason* is a stable-control / runtime-mode refusal (#897)."""
|
||||
r = (reason or "").lower()
|
||||
if not r:
|
||||
return False
|
||||
if _reason_is_stale_runtime(reason):
|
||||
return False
|
||||
if "runtime mode could not be assessed" in r:
|
||||
return True
|
||||
if "runtime mode is" in r:
|
||||
return True
|
||||
if "stable control runtime" in r:
|
||||
return True
|
||||
if "dev-test" in r and ("runtime" in r or "production" in r):
|
||||
return True
|
||||
if "development worktree" in r or "dev worktree" in r:
|
||||
return True
|
||||
if "launched from a 'branches/" in r or "launched from a \"branches/" in r:
|
||||
return True
|
||||
if "process-root / active-workspace alignment" in r:
|
||||
return True
|
||||
if "namespace" in r and "reproof" in r:
|
||||
return True
|
||||
return False
|
||||
|
||||
|
||||
def _reason_is_permission(reason: str) -> bool:
|
||||
"""True when *reason* is a genuine profile-permission denial (#897)."""
|
||||
r = (reason or "").lower()
|
||||
if not r:
|
||||
return False
|
||||
if _reason_is_stale_runtime(reason) or _reason_is_runtime_mode(reason):
|
||||
return False
|
||||
if "profile could not be resolved" in r:
|
||||
return True
|
||||
if "profile has no configured allowed operations" in r:
|
||||
return True
|
||||
if "profile forbids" in r:
|
||||
return True
|
||||
if "profile is not allowed to" in r:
|
||||
return True
|
||||
if "unrecognized forbidden operation" in r:
|
||||
return True
|
||||
return False
|
||||
|
||||
|
||||
def _classify_operation_gate_reasons(reasons: list[str]) -> dict:
|
||||
"""Partition gate reasons into stale / runtime-mode / permission (#897)."""
|
||||
stale: list[str] = []
|
||||
runtime_mode: list[str] = []
|
||||
permission: list[str] = []
|
||||
other: list[str] = []
|
||||
for reason in reasons or []:
|
||||
if _reason_is_stale_runtime(reason):
|
||||
stale.append(reason)
|
||||
elif _reason_is_runtime_mode(reason):
|
||||
runtime_mode.append(reason)
|
||||
elif _reason_is_permission(reason):
|
||||
permission.append(reason)
|
||||
else:
|
||||
other.append(reason)
|
||||
return {
|
||||
"stale_runtime": stale,
|
||||
"runtime_mode": runtime_mode,
|
||||
"permission": permission,
|
||||
"other": other,
|
||||
}
|
||||
|
||||
|
||||
def _stale_runtime_reconnect_action() -> str:
|
||||
"""Sanctioned recovery for a stale daemon — reconnect only (#685/#897)."""
|
||||
return (
|
||||
"Reconnect the IDE/client MCP session so the server reloads at the "
|
||||
"current master head. Do not call gitea_activate_profile or switch "
|
||||
"MCP role sessions — profile switching does not clear a stale daemon."
|
||||
)
|
||||
|
||||
|
||||
def _build_operation_gate_refusal(
|
||||
required_operation: str,
|
||||
reasons: list[str],
|
||||
**extra_fields,
|
||||
) -> dict:
|
||||
"""Structured gate refusal with typed blockers (#897).
|
||||
|
||||
Stale-runtime and runtime-mode refusals never attach a
|
||||
``permission_report`` and never recommend profile switching. True
|
||||
permission denials still get ``permission_report``. When both apply,
|
||||
causes are reported separately under distinct fields.
|
||||
"""
|
||||
classified = _classify_operation_gate_reasons(reasons)
|
||||
stale = classified["stale_runtime"]
|
||||
runtime_mode = classified["runtime_mode"]
|
||||
permission = classified["permission"]
|
||||
other = classified["other"]
|
||||
|
||||
blocked: dict = {
|
||||
"success": False,
|
||||
"performed": False,
|
||||
"reasons": list(reasons),
|
||||
"mutation_performed": False,
|
||||
"session_context_audit": session_ctx.mutation_context_audit_fields(),
|
||||
"gate_reason_classes": {
|
||||
"stale_runtime": list(stale),
|
||||
"runtime_mode": list(runtime_mode),
|
||||
"permission": list(permission),
|
||||
"other": list(other),
|
||||
},
|
||||
}
|
||||
|
||||
if stale:
|
||||
parity = _current_master_parity()
|
||||
blocked["blocker_kind"] = "runtime_reconnect_required"
|
||||
blocked["restart_required"] = True
|
||||
blocked["stop_required"] = True
|
||||
blocked["startup_head"] = parity.get("startup_head")
|
||||
blocked["current_head"] = parity.get("current_head")
|
||||
blocked["daemon_start_head"] = (
|
||||
parity.get("daemon_start_head") or parity.get("startup_head")
|
||||
)
|
||||
blocked["local_head"] = (
|
||||
parity.get("local_head") or parity.get("current_head")
|
||||
)
|
||||
blocked["live_remote_head"] = parity.get("live_remote_head")
|
||||
blocked["live_stale"] = bool(parity.get("live_stale"))
|
||||
blocked["live_known"] = bool(parity.get("live_known"))
|
||||
blocked["exact_safe_next_action"] = _stale_runtime_reconnect_action()
|
||||
if permission or other:
|
||||
blocked["permission_block_reasons"] = list(permission) + list(other)
|
||||
blocked["stale_runtime_reasons"] = list(stale)
|
||||
# Never attach permission_report for a staleness refusal.
|
||||
blocked.update(extra_fields)
|
||||
return blocked
|
||||
|
||||
if runtime_mode:
|
||||
blocked["blocker_kind"] = "runtime_mode_blocked"
|
||||
blocked["restart_required"] = False
|
||||
blocked["stop_required"] = True
|
||||
blocked["exact_safe_next_action"] = (
|
||||
"Real workflow mutations run only on the promoted stable control "
|
||||
"runtime. Promote/reload the stable runtime; do not call "
|
||||
"gitea_activate_profile or switch MCP role sessions to clear a "
|
||||
"runtime-mode block."
|
||||
)
|
||||
if permission or other:
|
||||
blocked["permission_block_reasons"] = list(permission) + list(other)
|
||||
blocked["runtime_mode_reasons"] = list(runtime_mode)
|
||||
blocked.update(extra_fields)
|
||||
return blocked
|
||||
|
||||
# Pure permission (or unclassified-as-permission) denial.
|
||||
blocked["blocker_kind"] = "permission_denied"
|
||||
blocked["permission_report"] = _permission_block_report(required_operation)
|
||||
blocked.update(extra_fields)
|
||||
return blocked
|
||||
|
||||
|
||||
def _permission_report_for_gate_reasons(
|
||||
required_operation: str,
|
||||
reasons: list[str] | None,
|
||||
) -> dict | None:
|
||||
"""Attach ``permission_report`` only for true permission denials (#897).
|
||||
|
||||
Call sites that historically always attached a permission report after
|
||||
``_profile_operation_gate`` should use this so stale/runtime refusals
|
||||
do not emit a fabricated missing-permission payload.
|
||||
"""
|
||||
if not reasons:
|
||||
return None
|
||||
classified = _classify_operation_gate_reasons(reasons)
|
||||
if classified["stale_runtime"] or classified["runtime_mode"]:
|
||||
return None
|
||||
if not (classified["permission"] or classified["other"]):
|
||||
return None
|
||||
return _permission_block_report(required_operation)
|
||||
|
||||
|
||||
def _role_for_operation(op: str) -> str | None:
|
||||
# Normalize op first
|
||||
try:
|
||||
@@ -14079,7 +14307,7 @@ def _master_parity_block(op: str) -> list[str]:
|
||||
|
||||
|
||||
def _profile_operation_gate(op: str) -> list[str]:
|
||||
"""Profile permission check for a single gated operation (#126, #216, #420).
|
||||
"""Profile permission check for a single gated operation (#126, #216, #420, #897).
|
||||
|
||||
Issue discussion comments are gated separately from the gitea.pr.*
|
||||
review/merge family: listing requires ``gitea.read``, creating requires
|
||||
@@ -14092,21 +14320,26 @@ def _profile_operation_gate(op: str) -> list[str]:
|
||||
capability gate that has since been merged, and when the runtime itself is
|
||||
not the promoted stable control runtime (#615) -- a dev/test or unknown
|
||||
runtime holds production credentials but has not been promoted.
|
||||
|
||||
#897: collect *all* independent refusal classes (stale, runtime-mode,
|
||||
permission) rather than short-circuiting after the first. Callers that
|
||||
only need a boolean still treat any non-empty list as blocked; typed
|
||||
consumers (``_build_operation_gate_refusal``) can separate causes.
|
||||
"""
|
||||
stale_reasons = _master_parity_block(op)
|
||||
if stale_reasons:
|
||||
return stale_reasons
|
||||
runtime_reasons = _runtime_mode_block(op)
|
||||
if runtime_reasons:
|
||||
return runtime_reasons
|
||||
reasons: list[str] = []
|
||||
reasons.extend(_master_parity_block(op))
|
||||
reasons.extend(_runtime_mode_block(op))
|
||||
try:
|
||||
profile = get_profile()
|
||||
except Exception as exc:
|
||||
return [f"profile could not be resolved (fail closed): {_redact(str(exc))}"]
|
||||
reasons.append(
|
||||
f"profile could not be resolved (fail closed): {_redact(str(exc))}"
|
||||
)
|
||||
return reasons
|
||||
op_ok, op_reason = gitea_config.check_operation(
|
||||
op, profile["allowed_operations"], profile["forbidden_operations"])
|
||||
if op_ok:
|
||||
return []
|
||||
return reasons
|
||||
|
||||
if _try_auto_switch_for_operation(op):
|
||||
try:
|
||||
@@ -14114,17 +14347,26 @@ def _profile_operation_gate(op: str) -> list[str]:
|
||||
op_ok, op_reason = gitea_config.check_operation(
|
||||
op, profile["allowed_operations"], profile["forbidden_operations"])
|
||||
if op_ok:
|
||||
return []
|
||||
return reasons
|
||||
except Exception as exc:
|
||||
return [f"profile could not be resolved (fail closed): {_redact(str(exc))}"]
|
||||
reasons.append(
|
||||
f"profile could not be resolved (fail closed): {_redact(str(exc))}"
|
||||
)
|
||||
return reasons
|
||||
|
||||
if op_reason == "no-allowed-operations":
|
||||
return ["profile has no configured allowed operations (fail closed)"]
|
||||
if op_reason == "forbidden":
|
||||
return [f"profile forbids '{op}'"]
|
||||
if op_reason == "invalid-forbidden-entry":
|
||||
return ["profile has an unrecognized forbidden operation entry (fail closed)"]
|
||||
return [f"profile is not allowed to {op}"]
|
||||
reasons.append(
|
||||
"profile has no configured allowed operations (fail closed)"
|
||||
)
|
||||
elif op_reason == "forbidden":
|
||||
reasons.append(f"profile forbids '{op}'")
|
||||
elif op_reason == "invalid-forbidden-entry":
|
||||
reasons.append(
|
||||
"profile has an unrecognized forbidden operation entry (fail closed)"
|
||||
)
|
||||
else:
|
||||
reasons.append(f"profile is not allowed to {op}")
|
||||
return reasons
|
||||
|
||||
|
||||
def _mutation_config_authority_block(required_operation: str) -> dict | None:
|
||||
@@ -14344,10 +14586,14 @@ def _session_context_mutation_block(
|
||||
|
||||
|
||||
def _profile_permission_block(required_operation: str, **extra_fields) -> dict | None:
|
||||
"""Structured permission denial for gated tools (#69, #142).
|
||||
"""Structured operation-gate denial for gated tools (#69, #142, #897).
|
||||
|
||||
Returns a block dict when the active profile forbids *required_operation*,
|
||||
or ``None`` when the gate passes. Never performs network I/O.
|
||||
the daemon is stale, or the runtime mode is not mutation-safe — or
|
||||
``None`` when the gate passes. Never performs network I/O.
|
||||
|
||||
#897: stale-runtime and runtime-mode refusals are typed
|
||||
(``blocker_kind``) and never carry a ``permission_report``.
|
||||
"""
|
||||
req_role = "reviewer" if any(required_operation.startswith(p) for p in (
|
||||
"gitea.pr.approve", "gitea.pr.merge", "gitea.pr.request_changes", "gitea.pr.review"
|
||||
@@ -14357,15 +14603,9 @@ def _profile_permission_block(required_operation: str, **extra_fields) -> dict |
|
||||
|
||||
reasons = _profile_operation_gate(required_operation)
|
||||
if reasons:
|
||||
blocked = {
|
||||
"success": False,
|
||||
"performed": False,
|
||||
"reasons": reasons,
|
||||
"permission_report": _permission_block_report(required_operation),
|
||||
"session_context_audit": session_ctx.mutation_context_audit_fields(),
|
||||
}
|
||||
blocked.update(extra_fields)
|
||||
return blocked
|
||||
return _build_operation_gate_refusal(
|
||||
required_operation, reasons, **extra_fields
|
||||
)
|
||||
|
||||
auth_block = _mutation_config_authority_block(required_operation)
|
||||
if auth_block is not None:
|
||||
@@ -14494,20 +14734,14 @@ def gitea_acquire_reviewer_pr_lease(
|
||||
"""Acquire a per-PR reviewer lease before review/merge mutations (#407)."""
|
||||
read_block = _profile_operation_gate("gitea.read")
|
||||
if read_block:
|
||||
return {
|
||||
"success": False,
|
||||
"acquired": False,
|
||||
"reasons": read_block,
|
||||
"permission_report": _permission_block_report("gitea.read"),
|
||||
}
|
||||
return _build_operation_gate_refusal(
|
||||
"gitea.read", read_block, acquired=False
|
||||
)
|
||||
comment_block = _profile_operation_gate("gitea.pr.comment")
|
||||
if comment_block:
|
||||
return {
|
||||
"success": False,
|
||||
"acquired": False,
|
||||
"reasons": comment_block,
|
||||
"permission_report": _permission_block_report("gitea.pr.comment"),
|
||||
}
|
||||
return _build_operation_gate_refusal(
|
||||
"gitea.pr.comment", comment_block, acquired=False
|
||||
)
|
||||
|
||||
# task=acquire_reviewer_pr_lease so verify_preflight_purity runs shared #604
|
||||
# anti-stomp for the declared lease-acquire mutation inventory entry.
|
||||
@@ -14623,20 +14857,14 @@ def gitea_acquire_merger_pr_lease(
|
||||
"""
|
||||
read_block = _profile_operation_gate("gitea.read")
|
||||
if read_block:
|
||||
return {
|
||||
"success": False,
|
||||
"acquired": False,
|
||||
"reasons": read_block,
|
||||
"permission_report": _permission_block_report("gitea.read"),
|
||||
}
|
||||
return _build_operation_gate_refusal(
|
||||
"gitea.read", read_block, acquired=False
|
||||
)
|
||||
comment_block = _profile_operation_gate("gitea.pr.comment")
|
||||
if comment_block:
|
||||
return {
|
||||
"success": False,
|
||||
"acquired": False,
|
||||
"reasons": comment_block,
|
||||
"permission_report": _permission_block_report("gitea.pr.comment"),
|
||||
}
|
||||
return _build_operation_gate_refusal(
|
||||
"gitea.pr.comment", comment_block, acquired=False
|
||||
)
|
||||
merge_block = _profile_operation_gate("gitea.pr.merge")
|
||||
if merge_block:
|
||||
return {
|
||||
@@ -19375,14 +19603,12 @@ def gitea_update_pr_branch_by_merge(
|
||||
# Permission: author branch push / PR mutation surface.
|
||||
push_block = _profile_operation_gate("gitea.branch.push")
|
||||
if push_block:
|
||||
return {
|
||||
"success": False,
|
||||
"performed": False,
|
||||
"mutation_allowed": False,
|
||||
"reasons": push_block,
|
||||
"permission_report": _permission_block_report("gitea.branch.push"),
|
||||
"role_kind": role,
|
||||
}
|
||||
return _build_operation_gate_refusal(
|
||||
"gitea.branch.push",
|
||||
push_block,
|
||||
mutation_allowed=False,
|
||||
role_kind=role,
|
||||
)
|
||||
|
||||
if role != "author":
|
||||
pre = pr_sync_status.assess_update_pr_branch_preflight(
|
||||
|
||||
@@ -0,0 +1,453 @@
|
||||
"""#897: stale-runtime / runtime-mode refusals must not look like permission denials.
|
||||
|
||||
Acceptance criteria (issue #897):
|
||||
|
||||
* Stale-runtime and runtime-mode refusals are typed distinctly from
|
||||
profile-permission refusals (distinct ``blocker_kind``).
|
||||
* A refusal caused by staleness or runtime mode never emits a
|
||||
``permission_report`` and never names a permission the active profile holds.
|
||||
* ``_permission_block_report`` verifies the active profile actually lacks the
|
||||
operation before reporting it missing.
|
||||
* A stale-runtime refusal reports reconnect-only recovery and never recommends
|
||||
``gitea_activate_profile`` or an MCP session switch.
|
||||
* The blocker payload states the observed heads (parity fields).
|
||||
* Matrix across author / reviewer / merger / reconciler profiles.
|
||||
* Regression: ``gitea_create_issue`` on a stale daemon under ``prgs-author``
|
||||
never returns ``missing_permission: gitea.issue.create``.
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import os
|
||||
import sys
|
||||
import unittest
|
||||
from unittest.mock import patch
|
||||
|
||||
sys.path.insert(0, str(__import__("pathlib").Path(__file__).resolve().parent.parent))
|
||||
|
||||
import gitea_config # noqa: E402
|
||||
import gitea_mcp_server as mcp_server # noqa: E402
|
||||
|
||||
SHA_START = "7af40fb5ff7debd5e9165fe97d9c7c279358e175"
|
||||
SHA_LIVE = "2f4dec832327513118f2fe92b74da25d124a01cb"
|
||||
|
||||
ROLE_MATRIX = (
|
||||
(
|
||||
"prgs-author",
|
||||
"author",
|
||||
"gitea.issue.create",
|
||||
[
|
||||
"gitea.read",
|
||||
"gitea.issue.create",
|
||||
"gitea.issue.comment",
|
||||
"gitea.issue.close",
|
||||
"gitea.branch.create",
|
||||
"gitea.branch.push",
|
||||
"gitea.pr.create",
|
||||
"gitea.pr.comment",
|
||||
"gitea.repo.commit",
|
||||
],
|
||||
["gitea.pr.approve", "gitea.pr.merge", "gitea.pr.request_changes"],
|
||||
"gitea.pr.merge", # forbidden op for pure-permission case
|
||||
),
|
||||
(
|
||||
"prgs-reviewer",
|
||||
"reviewer",
|
||||
"gitea.pr.review",
|
||||
[
|
||||
"gitea.read",
|
||||
"gitea.pr.review",
|
||||
"gitea.pr.approve",
|
||||
"gitea.pr.request_changes",
|
||||
"gitea.pr.comment",
|
||||
"gitea.issue.comment",
|
||||
],
|
||||
["gitea.branch.push", "gitea.pr.create"],
|
||||
"gitea.branch.push",
|
||||
),
|
||||
(
|
||||
"prgs-merger",
|
||||
"merger",
|
||||
"gitea.pr.merge",
|
||||
[
|
||||
"gitea.read",
|
||||
"gitea.pr.merge",
|
||||
"gitea.pr.comment",
|
||||
"gitea.issue.comment",
|
||||
],
|
||||
["gitea.pr.approve", "gitea.branch.push", "gitea.pr.create"],
|
||||
"gitea.branch.push",
|
||||
),
|
||||
(
|
||||
"prgs-reconciler",
|
||||
"reconciler",
|
||||
"gitea.branch.delete",
|
||||
[
|
||||
"gitea.read",
|
||||
"gitea.branch.delete",
|
||||
"gitea.pr.comment",
|
||||
"gitea.issue.comment",
|
||||
"gitea.pr.close",
|
||||
"gitea.issue.close",
|
||||
],
|
||||
["gitea.pr.approve", "gitea.pr.merge"],
|
||||
"gitea.pr.merge",
|
||||
),
|
||||
)
|
||||
|
||||
|
||||
def _profile(name: str, role: str, allowed: list[str], forbidden: list[str]) -> dict:
|
||||
return {
|
||||
"profile_name": name,
|
||||
"role": role,
|
||||
"role_kind": role,
|
||||
"allowed_operations": list(allowed),
|
||||
"forbidden_operations": list(forbidden),
|
||||
"identity": "test-user",
|
||||
}
|
||||
|
||||
|
||||
def _config(profiles: dict) -> dict:
|
||||
return {
|
||||
"version": 2,
|
||||
"profiles": {
|
||||
name: {
|
||||
"role": p["role"],
|
||||
"allowed_operations": p["allowed_operations"],
|
||||
"forbidden_operations": p["forbidden_operations"],
|
||||
}
|
||||
for name, p in profiles.items()
|
||||
},
|
||||
"rules": {"allow_runtime_switching": True},
|
||||
}
|
||||
|
||||
|
||||
class Issue897Helpers(unittest.TestCase):
|
||||
def test_classify_stale_reason_strings(self):
|
||||
stale = (
|
||||
f"live remote master is {SHA_LIVE[:12]} but the MCP server started "
|
||||
f"at {SHA_START[:12]}; the daemon is stale relative to live master "
|
||||
"-- restart/reconnect before mutating"
|
||||
)
|
||||
classified = mcp_server._classify_operation_gate_reasons([stale])
|
||||
self.assertEqual(classified["stale_runtime"], [stale])
|
||||
self.assertEqual(classified["permission"], [])
|
||||
self.assertEqual(classified["runtime_mode"], [])
|
||||
|
||||
def test_classify_permission_reason(self):
|
||||
reason = "profile is not allowed to gitea.pr.merge"
|
||||
classified = mcp_server._classify_operation_gate_reasons([reason])
|
||||
self.assertEqual(classified["permission"], [reason])
|
||||
self.assertEqual(classified["stale_runtime"], [])
|
||||
|
||||
def test_classify_runtime_mode_reason(self):
|
||||
reason = (
|
||||
"runtime mode is 'dev-test' and the mutation targets the "
|
||||
"production repository; dev/test runtimes must not mutate real "
|
||||
"issues or PRs (ADR: stable control runtime vs dev runtime)"
|
||||
)
|
||||
classified = mcp_server._classify_operation_gate_reasons([reason])
|
||||
self.assertEqual(classified["runtime_mode"], [reason])
|
||||
self.assertEqual(classified["stale_runtime"], [])
|
||||
|
||||
|
||||
class Issue897PermissionBlockReport(unittest.TestCase):
|
||||
def test_holds_op_is_diagnostic_defect_not_missing_permission(self):
|
||||
profile = _profile(
|
||||
"prgs-author",
|
||||
"author",
|
||||
["gitea.read", "gitea.issue.create", "gitea.issue.comment"],
|
||||
[],
|
||||
)
|
||||
with patch.object(mcp_server, "get_profile", return_value=profile), patch.object(
|
||||
mcp_server.gitea_config, "load_config", return_value=_config({"prgs-author": profile})
|
||||
), patch.object(
|
||||
mcp_server.gitea_config, "is_runtime_switching_enabled", return_value=True
|
||||
):
|
||||
report = mcp_server._permission_block_report("gitea.issue.create")
|
||||
self.assertTrue(report.get("diagnostic_defect"), report)
|
||||
self.assertIsNone(report.get("missing_permission"), report)
|
||||
action = (report.get("exact_safe_next_action") or "").lower()
|
||||
# Must not *recommend* profile switching; mentioning the forbidden
|
||||
# action in a "do not call" instruction is fine.
|
||||
self.assertNotIn("call gitea_activate_profile with", action)
|
||||
self.assertNotIn("switch to the author mcp session", action)
|
||||
self.assertNotIn("switch to the reviewer mcp session", action)
|
||||
self.assertIn("diagnostic defect", action)
|
||||
|
||||
def test_true_missing_permission_still_reports(self):
|
||||
profile = _profile(
|
||||
"prgs-author",
|
||||
"author",
|
||||
["gitea.read", "gitea.issue.create"],
|
||||
["gitea.pr.merge"],
|
||||
)
|
||||
reviewer = _profile(
|
||||
"prgs-reviewer",
|
||||
"reviewer",
|
||||
["gitea.read", "gitea.pr.merge", "gitea.pr.approve"],
|
||||
[],
|
||||
)
|
||||
with patch.object(mcp_server, "get_profile", return_value=profile), patch.object(
|
||||
mcp_server.gitea_config,
|
||||
"load_config",
|
||||
return_value=_config({"prgs-author": profile, "prgs-reviewer": reviewer}),
|
||||
), patch.object(
|
||||
mcp_server.gitea_config, "is_runtime_switching_enabled", return_value=True
|
||||
):
|
||||
report = mcp_server._permission_block_report("gitea.pr.merge")
|
||||
self.assertFalse(report.get("diagnostic_defect"), report)
|
||||
self.assertEqual(report.get("missing_permission"), "gitea.pr.merge")
|
||||
self.assertIn("prgs-reviewer", report.get("matching_configured_profiles") or [])
|
||||
|
||||
|
||||
class Issue897GateRefusalMatrix(unittest.TestCase):
|
||||
def _stale_parity(self) -> dict:
|
||||
return {
|
||||
"in_parity": True,
|
||||
"stale": False,
|
||||
"restart_required": True,
|
||||
"determinable": True,
|
||||
"startup_head": SHA_START,
|
||||
"current_head": SHA_START,
|
||||
"daemon_start_head": SHA_START,
|
||||
"local_head": SHA_START,
|
||||
"live_remote_head": SHA_LIVE,
|
||||
"live_known": True,
|
||||
"live_stale": True,
|
||||
"mutation_safe": False,
|
||||
"reasons": [
|
||||
f"live remote master is {SHA_LIVE[:12]} but the MCP server "
|
||||
f"started at {SHA_START[:12]}; the daemon is stale relative "
|
||||
"to live master -- restart/reconnect before mutating"
|
||||
],
|
||||
}
|
||||
|
||||
def test_stale_plus_permitted_op_all_roles(self):
|
||||
for name, role, permitted_op, allowed, forbidden, _forbidden_op in ROLE_MATRIX:
|
||||
with self.subTest(profile=name, op=permitted_op):
|
||||
profile = _profile(name, role, allowed, forbidden)
|
||||
parity = self._stale_parity()
|
||||
with patch.object(mcp_server, "get_profile", return_value=profile), patch.object(
|
||||
mcp_server, "_current_master_parity", return_value=parity
|
||||
), patch.object(
|
||||
mcp_server, "_master_parity_block", return_value=list(parity["reasons"])
|
||||
), patch.object(
|
||||
mcp_server, "_runtime_mode_block", return_value=[]
|
||||
), patch.object(
|
||||
mcp_server, "_ensure_matching_profile", return_value=None
|
||||
), patch.object(
|
||||
mcp_server.session_ctx,
|
||||
"mutation_context_audit_fields",
|
||||
return_value={"session_profile": name},
|
||||
):
|
||||
blocked = mcp_server._profile_permission_block(permitted_op)
|
||||
self.assertIsNotNone(blocked, name)
|
||||
assert blocked is not None
|
||||
self.assertEqual(
|
||||
blocked.get("blocker_kind"),
|
||||
"runtime_reconnect_required",
|
||||
blocked,
|
||||
)
|
||||
self.assertNotIn("permission_report", blocked, blocked)
|
||||
self.assertTrue(blocked.get("restart_required"), blocked)
|
||||
self.assertEqual(blocked.get("startup_head"), SHA_START, blocked)
|
||||
self.assertEqual(blocked.get("live_remote_head"), SHA_LIVE, blocked)
|
||||
action = (blocked.get("exact_safe_next_action") or "").lower()
|
||||
self.assertIn("reconnect", action)
|
||||
self.assertNotIn("call gitea_activate_profile with", action)
|
||||
self.assertNotIn("switch to the author mcp session", action)
|
||||
self.assertNotIn("switch to the reviewer mcp session", action)
|
||||
|
||||
def test_fresh_plus_forbidden_op_all_roles(self):
|
||||
for name, role, _permitted, allowed, forbidden, forbidden_op in ROLE_MATRIX:
|
||||
with self.subTest(profile=name, op=forbidden_op):
|
||||
profile = _profile(name, role, allowed, forbidden)
|
||||
with patch.object(mcp_server, "get_profile", return_value=profile), patch.object(
|
||||
mcp_server, "_master_parity_block", return_value=[]
|
||||
), patch.object(
|
||||
mcp_server, "_runtime_mode_block", return_value=[]
|
||||
), patch.object(
|
||||
mcp_server, "_ensure_matching_profile", return_value=None
|
||||
), patch.object(
|
||||
mcp_server.session_ctx,
|
||||
"mutation_context_audit_fields",
|
||||
return_value={"session_profile": name},
|
||||
), patch.object(
|
||||
mcp_server.gitea_config,
|
||||
"load_config",
|
||||
return_value=_config({name: profile}),
|
||||
), patch.object(
|
||||
mcp_server.gitea_config, "is_runtime_switching_enabled", return_value=False
|
||||
):
|
||||
blocked = mcp_server._profile_permission_block(forbidden_op)
|
||||
self.assertIsNotNone(blocked, name)
|
||||
assert blocked is not None
|
||||
self.assertEqual(blocked.get("blocker_kind"), "permission_denied", blocked)
|
||||
self.assertIn("permission_report", blocked, blocked)
|
||||
report = blocked["permission_report"]
|
||||
self.assertEqual(report.get("missing_permission"), forbidden_op, report)
|
||||
self.assertFalse(report.get("diagnostic_defect"), report)
|
||||
# No runtime reconnect fields for pure permission denial
|
||||
self.assertNotEqual(
|
||||
blocked.get("blocker_kind"), "runtime_reconnect_required"
|
||||
)
|
||||
|
||||
def test_stale_plus_forbidden_op_both_causes_separated(self):
|
||||
for name, role, _permitted, allowed, forbidden, forbidden_op in ROLE_MATRIX:
|
||||
with self.subTest(profile=name, op=forbidden_op):
|
||||
profile = _profile(name, role, allowed, forbidden)
|
||||
parity = self._stale_parity()
|
||||
stale_reason = parity["reasons"][0]
|
||||
with patch.object(mcp_server, "get_profile", return_value=profile), patch.object(
|
||||
mcp_server, "_current_master_parity", return_value=parity
|
||||
), patch.object(
|
||||
mcp_server, "_master_parity_block", return_value=[stale_reason]
|
||||
), patch.object(
|
||||
mcp_server, "_runtime_mode_block", return_value=[]
|
||||
), patch.object(
|
||||
mcp_server, "_ensure_matching_profile", return_value=None
|
||||
), patch.object(
|
||||
mcp_server.session_ctx,
|
||||
"mutation_context_audit_fields",
|
||||
return_value={"session_profile": name},
|
||||
):
|
||||
# Gate collects both classes; force permission reason too.
|
||||
with patch.object(
|
||||
mcp_server,
|
||||
"_profile_operation_gate",
|
||||
return_value=[
|
||||
stale_reason,
|
||||
f"profile is not allowed to {forbidden_op}",
|
||||
],
|
||||
):
|
||||
blocked = mcp_server._profile_permission_block(forbidden_op)
|
||||
self.assertIsNotNone(blocked)
|
||||
assert blocked is not None
|
||||
self.assertEqual(
|
||||
blocked.get("blocker_kind"), "runtime_reconnect_required", blocked
|
||||
)
|
||||
self.assertNotIn("permission_report", blocked, blocked)
|
||||
self.assertIn("permission_block_reasons", blocked, blocked)
|
||||
self.assertIn("stale_runtime_reasons", blocked, blocked)
|
||||
classes = blocked.get("gate_reason_classes") or {}
|
||||
self.assertTrue(classes.get("stale_runtime"), classes)
|
||||
self.assertTrue(classes.get("permission"), classes)
|
||||
|
||||
def test_runtime_mode_block_no_permission_report(self):
|
||||
profile = _profile(
|
||||
"prgs-author",
|
||||
"author",
|
||||
["gitea.read", "gitea.issue.create"],
|
||||
[],
|
||||
)
|
||||
runtime_reason = (
|
||||
"runtime mode is 'dev-test' and the mutation targets the "
|
||||
"production repository; dev/test runtimes must not mutate real "
|
||||
"issues or PRs (ADR: stable control runtime vs dev runtime)"
|
||||
)
|
||||
with patch.object(mcp_server, "get_profile", return_value=profile), patch.object(
|
||||
mcp_server, "_master_parity_block", return_value=[]
|
||||
), patch.object(
|
||||
mcp_server, "_runtime_mode_block", return_value=[runtime_reason]
|
||||
), patch.object(
|
||||
mcp_server, "_ensure_matching_profile", return_value=None
|
||||
), patch.object(
|
||||
mcp_server.session_ctx,
|
||||
"mutation_context_audit_fields",
|
||||
return_value={"session_profile": "prgs-author"},
|
||||
):
|
||||
blocked = mcp_server._profile_permission_block("gitea.issue.create")
|
||||
self.assertIsNotNone(blocked)
|
||||
assert blocked is not None
|
||||
self.assertEqual(blocked.get("blocker_kind"), "runtime_mode_blocked", blocked)
|
||||
self.assertNotIn("permission_report", blocked, blocked)
|
||||
action = (blocked.get("exact_safe_next_action") or "").lower()
|
||||
self.assertNotIn("call gitea_activate_profile with", action)
|
||||
self.assertIn("stable control runtime", action)
|
||||
|
||||
|
||||
class Issue897CreateIssueRegression(unittest.TestCase):
|
||||
def test_create_issue_stale_daemon_never_missing_issue_create(self):
|
||||
"""Regression AC: stale prgs-author create_issue must not claim missing create."""
|
||||
profile = _profile(
|
||||
"prgs-author",
|
||||
"author",
|
||||
[
|
||||
"gitea.read",
|
||||
"gitea.issue.create",
|
||||
"gitea.issue.comment",
|
||||
"gitea.branch.create",
|
||||
"gitea.branch.push",
|
||||
"gitea.pr.create",
|
||||
"gitea.pr.comment",
|
||||
"gitea.repo.commit",
|
||||
],
|
||||
[],
|
||||
)
|
||||
stale_reason = (
|
||||
f"live remote master is {SHA_LIVE[:12]} but the MCP server started "
|
||||
f"at {SHA_START[:12]}; the daemon is stale relative to live master "
|
||||
"-- restart/reconnect before mutating"
|
||||
)
|
||||
parity = {
|
||||
"in_parity": True,
|
||||
"stale": False,
|
||||
"restart_required": True,
|
||||
"determinable": True,
|
||||
"startup_head": SHA_START,
|
||||
"current_head": SHA_START,
|
||||
"daemon_start_head": SHA_START,
|
||||
"local_head": SHA_START,
|
||||
"live_remote_head": SHA_LIVE,
|
||||
"live_known": True,
|
||||
"live_stale": True,
|
||||
"mutation_safe": False,
|
||||
"reasons": [stale_reason],
|
||||
}
|
||||
|
||||
with patch.object(mcp_server, "get_profile", return_value=profile), patch.object(
|
||||
mcp_server, "_current_master_parity", return_value=parity
|
||||
), patch.object(
|
||||
mcp_server, "_master_parity_block", return_value=[stale_reason]
|
||||
), patch.object(
|
||||
mcp_server, "_runtime_mode_block", return_value=[]
|
||||
), patch.object(
|
||||
mcp_server, "_ensure_matching_profile", return_value=None
|
||||
), patch.object(
|
||||
mcp_server.session_ctx,
|
||||
"mutation_context_audit_fields",
|
||||
return_value={"session_profile": "prgs-author"},
|
||||
), patch.object(
|
||||
mcp_server, "_mutation_config_authority_block", return_value=None
|
||||
), patch.object(
|
||||
mcp_server, "_session_context_mutation_block", return_value=None
|
||||
):
|
||||
blocked = mcp_server._profile_permission_block(
|
||||
"gitea.issue.create", remote="prgs"
|
||||
)
|
||||
|
||||
self.assertIsNotNone(blocked)
|
||||
assert blocked is not None
|
||||
self.assertEqual(blocked.get("blocker_kind"), "runtime_reconnect_required")
|
||||
self.assertNotIn("permission_report", blocked)
|
||||
# Even if a caller still built a raw report, holds-check must not claim missing.
|
||||
with patch.object(mcp_server, "get_profile", return_value=profile):
|
||||
raw = mcp_server._permission_block_report("gitea.issue.create")
|
||||
self.assertIsNone(raw.get("missing_permission"), raw)
|
||||
self.assertNotEqual(raw.get("missing_permission"), "gitea.issue.create")
|
||||
|
||||
def test_permission_report_for_gate_reasons_skips_stale(self):
|
||||
stale = (
|
||||
f"live remote master is {SHA_LIVE[:12]} but the MCP server started "
|
||||
f"at {SHA_START[:12]}; the daemon is stale relative to live master "
|
||||
"-- restart/reconnect before mutating"
|
||||
)
|
||||
self.assertIsNone(
|
||||
mcp_server._permission_report_for_gate_reasons(
|
||||
"gitea.issue.comment", [stale]
|
||||
)
|
||||
)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
unittest.main()
|
||||
@@ -0,0 +1,511 @@
|
||||
"""Tests for the Gitea issue↔PR linkage console (#645, Phase 3).
|
||||
|
||||
Covers the acceptance criteria of the issue:
|
||||
|
||||
* AC1 — issue↔PR linkage is visible for the selected project/repo, in both
|
||||
directions, with the evidence that produced each edge.
|
||||
* AC2 — the latest canonical handoff (CTH) is summarized for a focused thread.
|
||||
* AC3 — an external Gitea link appears only under the admin reveal opt-in.
|
||||
* AC4 — every case is driven by mocked Gitea payloads; no network.
|
||||
|
||||
Plus the invariants this console must not violate: a partial or failed read is
|
||||
never rendered as "no link exists", an unfetched thread is never rendered as
|
||||
"no handoff", redaction happens before display, and the surface stays read-only.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
import os
|
||||
import sys
|
||||
import unittest
|
||||
from pathlib import Path
|
||||
from unittest import mock
|
||||
|
||||
sys.path.insert(0, str(Path(__file__).resolve().parent.parent))
|
||||
|
||||
from tests.webui_testclient import TestClient
|
||||
|
||||
from canonical_thread_handoff import format_cth_body
|
||||
from webui.app import create_app
|
||||
from webui.linkage_loader import (
|
||||
EVIDENCE_BRANCH,
|
||||
EVIDENCE_CLOSES,
|
||||
EVIDENCE_REFERENCE,
|
||||
HANDOFF_LOADED,
|
||||
HANDOFF_NOT_LOADED,
|
||||
HANDOFF_UNAVAILABLE,
|
||||
LinkageSnapshot,
|
||||
load_linkage_snapshot,
|
||||
resolve_linkage,
|
||||
resolve_pr_links,
|
||||
snapshot_to_dict,
|
||||
summarize_handoff,
|
||||
)
|
||||
from webui.linkage_views import render_linkage_page
|
||||
from webui.nav import nav_hrefs
|
||||
from webui.queue_loader import PaginationMeta
|
||||
|
||||
|
||||
def _pagination(*, complete: bool = True, count: int = 0) -> PaginationMeta:
|
||||
return PaginationMeta(
|
||||
page=1,
|
||||
per_page=50,
|
||||
returned_count=count,
|
||||
has_more=not complete,
|
||||
is_final_page=complete,
|
||||
inventory_complete=complete,
|
||||
pages_fetched=1,
|
||||
)
|
||||
|
||||
|
||||
def _pr(
|
||||
number: int,
|
||||
*,
|
||||
title: str = "",
|
||||
body: str = "",
|
||||
head: str = "",
|
||||
state: str = "open",
|
||||
labels: tuple[str, ...] = (),
|
||||
) -> dict:
|
||||
return {
|
||||
"number": number,
|
||||
"title": title or f"pr {number}",
|
||||
"body": body,
|
||||
"state": state,
|
||||
"head": {"ref": head},
|
||||
"labels": [{"name": name} for name in labels],
|
||||
}
|
||||
|
||||
|
||||
def _issue(
|
||||
number: int,
|
||||
*,
|
||||
title: str = "",
|
||||
state: str = "open",
|
||||
labels: tuple[str, ...] = (),
|
||||
) -> dict:
|
||||
return {
|
||||
"number": number,
|
||||
"title": title or f"issue {number}",
|
||||
"state": state,
|
||||
"labels": [{"name": name} for name in labels],
|
||||
}
|
||||
|
||||
|
||||
def _fetcher(items: list[dict], *, complete: bool = True):
|
||||
def _fetch(*_args, **_kwargs):
|
||||
return items, _pagination(complete=complete, count=len(items))
|
||||
|
||||
return _fetch
|
||||
|
||||
|
||||
def _load(
|
||||
issues: list[dict],
|
||||
prs: list[dict],
|
||||
*,
|
||||
complete: bool = True,
|
||||
**kwargs,
|
||||
) -> LinkageSnapshot:
|
||||
return load_linkage_snapshot(
|
||||
fetch_prs=_fetcher(prs, complete=complete),
|
||||
fetch_issues=_fetcher(issues, complete=complete),
|
||||
**kwargs,
|
||||
)
|
||||
|
||||
|
||||
def _cth(comment_id: int, *, created_at: str, status: str, next_owner: str) -> dict:
|
||||
return {
|
||||
"id": comment_id,
|
||||
"created_at": created_at,
|
||||
"user": {"login": "jcwalker3"},
|
||||
"body": format_cth_body(
|
||||
cth_type="Author Handoff",
|
||||
status=status,
|
||||
next_owner=next_owner,
|
||||
current_blocker="none",
|
||||
decision="implemented",
|
||||
proof="full suite green",
|
||||
next_action="review PR",
|
||||
ready_to_paste_prompt="Review PR #902 now.",
|
||||
),
|
||||
}
|
||||
|
||||
|
||||
class TestLinkageEvidence(unittest.TestCase):
|
||||
"""AC1 — every edge records how it was found, and keeps all candidates."""
|
||||
|
||||
def test_closes_keyword_in_body_is_strongest_evidence(self):
|
||||
links = resolve_pr_links(_pr(902, body="Closes #643"))
|
||||
self.assertEqual([link.issue_number for link in links], [643])
|
||||
self.assertEqual(links[0].evidence, (EVIDENCE_CLOSES,))
|
||||
self.assertTrue(links[0].closes)
|
||||
|
||||
def test_closes_keyword_in_title_counts(self):
|
||||
links = resolve_pr_links(_pr(902, title="feat(webui): preview (Closes #643)"))
|
||||
self.assertEqual(links[0].evidence, (EVIDENCE_CLOSES,))
|
||||
|
||||
def test_canonical_branch_marker_links_without_a_keyword(self):
|
||||
links = resolve_pr_links(_pr(902, head="feat/issue-643-request-preview"))
|
||||
self.assertEqual([link.issue_number for link in links], [643])
|
||||
self.assertEqual(links[0].evidence, (EVIDENCE_BRANCH,))
|
||||
self.assertFalse(links[0].closes)
|
||||
|
||||
def test_non_canonical_branch_is_not_treated_as_a_marker(self):
|
||||
self.assertEqual(resolve_pr_links(_pr(902, head="issue-643-preview")), ())
|
||||
|
||||
def test_bare_mention_is_recorded_as_the_weakest_evidence(self):
|
||||
links = resolve_pr_links(_pr(902, body="context in #643"))
|
||||
self.assertEqual(links[0].evidence, (EVIDENCE_REFERENCE,))
|
||||
self.assertFalse(links[0].closes)
|
||||
|
||||
def test_several_evidence_kinds_merge_onto_one_edge(self):
|
||||
links = resolve_pr_links(
|
||||
_pr(902, body="Closes #643 — see #643", head="feat/issue-643-preview")
|
||||
)
|
||||
self.assertEqual(len(links), 1)
|
||||
self.assertEqual(
|
||||
links[0].evidence,
|
||||
(EVIDENCE_CLOSES, EVIDENCE_BRANCH, EVIDENCE_REFERENCE),
|
||||
)
|
||||
|
||||
def test_stronger_evidence_sorts_first(self):
|
||||
links = resolve_pr_links(_pr(902, body="Closes #643, related #700"))
|
||||
self.assertEqual([link.issue_number for link in links], [643, 700])
|
||||
|
||||
def test_self_reference_is_not_linkage(self):
|
||||
links = resolve_pr_links(_pr(902, body="supersedes #902"))
|
||||
self.assertEqual(links, ())
|
||||
|
||||
def test_every_candidate_is_kept_never_collapsed_to_a_guess(self):
|
||||
links = resolve_pr_links(_pr(902, body="Closes #643\nCloses #644"))
|
||||
self.assertEqual([link.issue_number for link in links], [643, 644])
|
||||
|
||||
|
||||
class TestLinkageIndex(unittest.TestCase):
|
||||
def test_issue_direction_ignores_mention_only_edges(self):
|
||||
index = resolve_linkage([_pr(902, body="context in #643")])
|
||||
self.assertIsNone(index.issue_prs.get(643))
|
||||
self.assertEqual(index.pr_links[902][0].evidence, (EVIDENCE_REFERENCE,))
|
||||
|
||||
def test_contested_issue_is_reported_when_two_prs_claim_it(self):
|
||||
index = resolve_linkage(
|
||||
[_pr(902, body="Closes #643"), _pr(903, head="feat/issue-643-again")]
|
||||
)
|
||||
self.assertEqual(index.contested_issues(), (643,))
|
||||
self.assertEqual(index.issue_prs[643], (902, 903))
|
||||
|
||||
def test_single_claim_is_not_contested(self):
|
||||
index = resolve_linkage([_pr(902, body="Closes #643")])
|
||||
self.assertEqual(index.contested_issues(), ())
|
||||
|
||||
def test_ambiguous_when_two_issues_tie_at_the_strongest_evidence(self):
|
||||
index = resolve_linkage([_pr(902, body="Closes #643\nCloses #644")])
|
||||
self.assertTrue(index.ambiguous(902))
|
||||
|
||||
def test_weaker_candidate_alongside_a_stronger_one_is_not_ambiguous(self):
|
||||
index = resolve_linkage([_pr(902, body="Closes #643, see #700")])
|
||||
self.assertFalse(index.ambiguous(902))
|
||||
self.assertEqual(index.primary_issue(902).issue_number, 643)
|
||||
|
||||
def test_malformed_pr_row_is_skipped_not_raised_on(self):
|
||||
index = resolve_linkage([{"title": "no number"}, _pr(902, body="Closes #643")])
|
||||
self.assertEqual(sorted(index.pr_links), [902])
|
||||
|
||||
|
||||
class TestLinkageSnapshot(unittest.TestCase):
|
||||
"""AC1 — linkage is visible per project/repo, in both directions."""
|
||||
|
||||
def test_both_directions_are_populated(self):
|
||||
snapshot = _load([_issue(643)], [_pr(902, body="Closes #643")])
|
||||
self.assertTrue(snapshot.ok)
|
||||
self.assertEqual([node.number for node in snapshot.issues], [643])
|
||||
self.assertEqual(snapshot.issues[0].linked_prs, (902,))
|
||||
self.assertEqual(snapshot.prs[0].links[0].issue_number, 643)
|
||||
|
||||
def test_repo_scope_comes_from_the_registry_project(self):
|
||||
snapshot = _load([], [])
|
||||
self.assertIn("/", snapshot.repo_label)
|
||||
self.assertTrue(snapshot.project_id)
|
||||
|
||||
def test_unknown_project_fails_closed_with_a_reason(self):
|
||||
snapshot = _load([_issue(643)], [], project_id="no-such-project")
|
||||
self.assertFalse(snapshot.ok)
|
||||
self.assertIn("not found in registry", snapshot.fetch_error)
|
||||
self.assertEqual(snapshot.issues, ())
|
||||
|
||||
def test_orphan_pr_is_identifiable(self):
|
||||
snapshot = _load([], [_pr(902), _pr(903, body="Closes #643")])
|
||||
self.assertEqual([node.number for node in snapshot.orphan_prs], [902])
|
||||
|
||||
def test_state_scope_defaults_to_open_and_is_reported(self):
|
||||
self.assertEqual(_load([], []).state_scope, "open")
|
||||
self.assertEqual(_load([], [], state="all").state_scope, "all")
|
||||
|
||||
def test_unsupported_state_falls_back_to_open(self):
|
||||
self.assertEqual(_load([], [], state="../etc").state_scope, "open")
|
||||
|
||||
def test_state_is_passed_through_to_the_fetchers(self):
|
||||
seen: list[str] = []
|
||||
|
||||
def _fetch(*_args, **kwargs):
|
||||
seen.append(kwargs.get("state", ""))
|
||||
return [], _pagination()
|
||||
|
||||
load_linkage_snapshot(state="all", fetch_prs=_fetch, fetch_issues=_fetch)
|
||||
self.assertEqual(seen, ["all", "all"])
|
||||
|
||||
|
||||
class TestPartialInventoryIsNotAnAbsenceClaim(unittest.TestCase):
|
||||
"""An empty edge list from a partial read must never read as 'no link'."""
|
||||
|
||||
def test_incomplete_pagination_marks_links_non_authoritative(self):
|
||||
snapshot = _load([_issue(643)], [], complete=False)
|
||||
self.assertFalse(snapshot.inventory_complete)
|
||||
self.assertFalse(snapshot.issues[0].links_authoritative)
|
||||
|
||||
def test_complete_pagination_marks_links_authoritative(self):
|
||||
snapshot = _load([_issue(643)], [], complete=True)
|
||||
self.assertTrue(snapshot.inventory_complete)
|
||||
self.assertTrue(snapshot.issues[0].links_authoritative)
|
||||
|
||||
def test_partial_window_renders_a_qualified_empty_cell(self):
|
||||
html = render_linkage_page(_load([_issue(643)], [], complete=False))
|
||||
self.assertIn("none found (partial inventory)", html)
|
||||
|
||||
def test_complete_window_renders_a_plain_none(self):
|
||||
html = render_linkage_page(_load([_issue(643)], [], complete=True))
|
||||
self.assertNotIn("partial inventory", html)
|
||||
self.assertIn(">none<", html)
|
||||
|
||||
def test_missing_credentials_fail_closed_without_a_table(self):
|
||||
with mock.patch(
|
||||
"webui.linkage_loader._offline_test_mode", return_value=False
|
||||
), mock.patch("webui.linkage_loader.get_auth_header", return_value=""):
|
||||
snapshot = load_linkage_snapshot()
|
||||
self.assertFalse(snapshot.ok)
|
||||
self.assertIn("credentials unavailable", snapshot.fetch_error)
|
||||
html = render_linkage_page(snapshot)
|
||||
self.assertIn("Linkage unavailable", html)
|
||||
self.assertNotIn("Issues → pull requests", html)
|
||||
|
||||
def test_fetch_failure_is_reported_not_raised(self):
|
||||
def _boom(*_args, **_kwargs):
|
||||
raise RuntimeError("gitea 502")
|
||||
|
||||
snapshot = load_linkage_snapshot(fetch_prs=_boom, fetch_issues=_boom)
|
||||
self.assertFalse(snapshot.ok)
|
||||
self.assertIn("Gitea fetch failed", snapshot.fetch_error)
|
||||
|
||||
|
||||
class TestHandoffSummary(unittest.TestCase):
|
||||
"""AC2 — the latest canonical handoff is summarized for a focused thread."""
|
||||
|
||||
def test_latest_cth_wins(self):
|
||||
summary = summarize_handoff([
|
||||
_cth(1, created_at="2026-07-24T10:00:00Z", status="in progress",
|
||||
next_owner="author"),
|
||||
_cth(2, created_at="2026-07-25T10:00:00Z", status="PR-open",
|
||||
next_owner="reviewer"),
|
||||
])
|
||||
self.assertEqual(summary.comment_id, 2)
|
||||
self.assertEqual(summary.status, "PR-open")
|
||||
self.assertEqual(summary.next_owner, "reviewer")
|
||||
self.assertTrue(summary.cth_type_known)
|
||||
|
||||
def test_thread_without_a_cth_summarizes_to_none(self):
|
||||
self.assertIsNone(summarize_handoff([{"id": 1, "body": "ordinary comment"}]))
|
||||
|
||||
def test_unknown_heading_is_reported_not_republished(self):
|
||||
summary = summarize_handoff([
|
||||
{
|
||||
"id": 5,
|
||||
"created_at": "2026-07-25T10:00:00Z",
|
||||
"user": {"login": "someone"},
|
||||
"body": "<!-- cth:v1 -->\n## CTH: Totally Made Up\n\nStatus: odd\n",
|
||||
}
|
||||
])
|
||||
self.assertFalse(summary.cth_type_known)
|
||||
self.assertEqual(summary.cth_type, "unrecognized")
|
||||
self.assertNotIn("Totally Made Up", json.dumps(summary.to_dict()))
|
||||
|
||||
def test_focused_pr_loads_its_handoff(self):
|
||||
snapshot = _load(
|
||||
[_issue(643)],
|
||||
[_pr(902, body="Closes #643")],
|
||||
pr=902,
|
||||
comment_source=lambda kind, number: [
|
||||
_cth(2, created_at="2026-07-25T10:00:00Z", status="PR-open",
|
||||
next_owner="reviewer")
|
||||
],
|
||||
)
|
||||
self.assertEqual(snapshot.handoff_status.state, HANDOFF_LOADED)
|
||||
self.assertEqual(snapshot.focus, ("pr", 902))
|
||||
self.assertEqual(snapshot.prs[0].handoff.status, "PR-open")
|
||||
|
||||
def test_unfocused_rows_report_not_loaded_never_none(self):
|
||||
snapshot = _load(
|
||||
[_issue(643)],
|
||||
[_pr(902, body="Closes #643"), _pr(903)],
|
||||
pr=902,
|
||||
comment_source=lambda kind, number: [],
|
||||
)
|
||||
other = next(node for node in snapshot.prs if node.number == 903)
|
||||
self.assertIsNone(other.handoff)
|
||||
self.assertEqual(other.handoff_status.state, HANDOFF_NOT_LOADED)
|
||||
self.assertIn("not loaded", render_linkage_page(snapshot))
|
||||
|
||||
def test_no_focus_means_no_thread_is_claimed_handoff_free(self):
|
||||
snapshot = _load([_issue(643)], [])
|
||||
self.assertEqual(snapshot.handoff_status.state, HANDOFF_NOT_LOADED)
|
||||
self.assertIn("thread-scoped", snapshot.handoff_status.reason)
|
||||
|
||||
def test_comment_source_failure_degrades_only_the_handoff(self):
|
||||
def _boom(_kind, _number):
|
||||
raise RuntimeError("comments 500")
|
||||
|
||||
snapshot = _load(
|
||||
[_issue(643)], [_pr(902, body="Closes #643")], pr=902, comment_source=_boom
|
||||
)
|
||||
self.assertTrue(snapshot.ok)
|
||||
self.assertEqual(snapshot.handoff_status.state, HANDOFF_UNAVAILABLE)
|
||||
self.assertEqual(snapshot.issues[0].linked_prs, (902,))
|
||||
self.assertIn("unavailable", render_linkage_page(snapshot))
|
||||
|
||||
def test_loaded_thread_with_no_cth_says_so_explicitly(self):
|
||||
snapshot = _load(
|
||||
[_issue(643)],
|
||||
[_pr(902, body="Closes #643")],
|
||||
pr=902,
|
||||
comment_source=lambda kind, number: [{"id": 1, "body": "hi"}],
|
||||
)
|
||||
self.assertIn(
|
||||
"no Canonical Thread Handoff comment found", render_linkage_page(snapshot)
|
||||
)
|
||||
|
||||
|
||||
class TestDeepLinks(unittest.TestCase):
|
||||
"""AC3 — an external Gitea link is emitted only when permitted."""
|
||||
|
||||
def test_deep_links_are_withheld_by_default(self):
|
||||
with mock.patch.dict(os.environ, {"GITEA_MCP_REVEAL_ENDPOINTS": ""}):
|
||||
snapshot = _load([_issue(643)], [])
|
||||
html = render_linkage_page(snapshot)
|
||||
self.assertFalse(snapshot.deep_links_enabled)
|
||||
self.assertIsNone(snapshot.issues[0].deep_link)
|
||||
self.assertIn("Gitea deep links are withheld", html)
|
||||
|
||||
def test_reveal_opt_in_emits_the_link(self):
|
||||
with mock.patch.dict(os.environ, {"GITEA_MCP_REVEAL_ENDPOINTS": "1"}):
|
||||
snapshot = _load([_issue(643)], [_pr(902, body="Closes #643")])
|
||||
html = render_linkage_page(snapshot)
|
||||
self.assertTrue(snapshot.deep_links_enabled)
|
||||
self.assertIn("/issues/643", snapshot.issues[0].deep_link)
|
||||
self.assertIn("/pulls/902", snapshot.prs[0].deep_link)
|
||||
self.assertIn(f'href="{snapshot.issues[0].deep_link}"', html)
|
||||
|
||||
|
||||
class TestRedactionBoundary(unittest.TestCase):
|
||||
def test_secret_shaped_title_is_redacted_before_display(self):
|
||||
snapshot = _load(
|
||||
[_issue(643, title="token=ghp_thisisnotarealsecretvalue0001")], []
|
||||
)
|
||||
payload = json.dumps(snapshot_to_dict(snapshot))
|
||||
self.assertNotIn("ghp_thisisnotarealsecretvalue0001", payload)
|
||||
self.assertNotIn(
|
||||
"ghp_thisisnotarealsecretvalue0001", render_linkage_page(snapshot)
|
||||
)
|
||||
|
||||
def test_handoff_fields_are_redacted(self):
|
||||
comment = _cth(
|
||||
2, created_at="2026-07-25T10:00:00Z", status="ok", next_owner="reviewer"
|
||||
)
|
||||
comment["body"] += "\nDecision: password=hunter2hunter2\n"
|
||||
snapshot = _load(
|
||||
[_issue(643)],
|
||||
[_pr(902, body="Closes #643")],
|
||||
pr=902,
|
||||
comment_source=lambda kind, number: [comment],
|
||||
)
|
||||
self.assertNotIn("hunter2hunter2", json.dumps(snapshot_to_dict(snapshot)))
|
||||
self.assertNotIn("hunter2hunter2", render_linkage_page(snapshot))
|
||||
|
||||
def test_html_escapes_markup_in_a_title(self):
|
||||
snapshot = _load([_issue(643, title="<script>alert(1)</script>")], [])
|
||||
html = render_linkage_page(snapshot)
|
||||
self.assertNotIn("<script>alert(1)</script>", html)
|
||||
self.assertIn("<script>", html)
|
||||
|
||||
|
||||
class TestLinkageRoutes(unittest.TestCase):
|
||||
def setUp(self):
|
||||
self.snapshot = _load(
|
||||
[_issue(643, labels=("status:ready",))],
|
||||
[_pr(902, body="Closes #643", labels=("status:pr-open",))],
|
||||
)
|
||||
self.client = TestClient(create_app())
|
||||
|
||||
def test_page_renders_both_tables(self):
|
||||
with mock.patch("webui.app.load_linkage_snapshot", return_value=self.snapshot):
|
||||
response = self.client.get("/gitea")
|
||||
self.assertEqual(response.status_code, 200)
|
||||
self.assertIn("Issues → pull requests", response.text)
|
||||
self.assertIn("Pull requests → issues", response.text)
|
||||
self.assertIn("#643", response.text)
|
||||
|
||||
def test_api_exports_the_same_model(self):
|
||||
with mock.patch("webui.app.load_linkage_snapshot", return_value=self.snapshot):
|
||||
response = self.client.get("/api/v1/gitea/linkage")
|
||||
self.assertEqual(response.status_code, 200)
|
||||
payload = response.json()
|
||||
self.assertTrue(payload["ok"])
|
||||
self.assertEqual(payload["issues"][0]["linked_prs"], [902])
|
||||
self.assertEqual(payload["prs"][0]["links"][0]["issue_number"], 643)
|
||||
self.assertEqual(payload["schema_version"], 1)
|
||||
|
||||
def test_api_declares_the_evidence_vocabulary(self):
|
||||
with mock.patch("webui.app.load_linkage_snapshot", return_value=self.snapshot):
|
||||
payload = self.client.get("/api/v1/gitea/linkage").json()
|
||||
names = {entry["name"] for entry in payload["evidence_kinds"]}
|
||||
self.assertEqual(names, {EVIDENCE_CLOSES, EVIDENCE_BRANCH, EVIDENCE_REFERENCE})
|
||||
|
||||
def test_api_fails_closed_with_a_non_200_when_the_read_failed(self):
|
||||
failed = _load([], [], project_id="no-such-project")
|
||||
with mock.patch("webui.app.load_linkage_snapshot", return_value=failed):
|
||||
response = self.client.get("/api/v1/gitea/linkage")
|
||||
self.assertEqual(response.status_code, 502)
|
||||
self.assertFalse(response.json()["ok"])
|
||||
|
||||
def test_page_still_renders_when_the_read_failed(self):
|
||||
failed = _load([], [], project_id="no-such-project")
|
||||
with mock.patch("webui.app.load_linkage_snapshot", return_value=failed):
|
||||
response = self.client.get("/gitea")
|
||||
self.assertEqual(response.status_code, 200)
|
||||
self.assertIn("Linkage unavailable", response.text)
|
||||
|
||||
def test_query_parameters_reach_the_loader(self):
|
||||
with mock.patch(
|
||||
"webui.app.load_linkage_snapshot", return_value=self.snapshot
|
||||
) as loader:
|
||||
self.client.get("/gitea?project=gitea-tools&state=all&pr=902")
|
||||
loader.assert_called_once()
|
||||
args, kwargs = loader.call_args
|
||||
self.assertEqual(args[0], "gitea-tools")
|
||||
self.assertEqual(kwargs["state"], "all")
|
||||
self.assertEqual(kwargs["pr"], 902)
|
||||
self.assertIsNone(kwargs["issue"])
|
||||
|
||||
def test_surface_stays_read_only(self):
|
||||
for path in ("/gitea", "/api/v1/gitea/linkage"):
|
||||
with self.subTest(path=path):
|
||||
self.assertEqual(self.client.post(path).status_code, 405)
|
||||
|
||||
def test_nav_exposes_the_linkage_page_as_live(self):
|
||||
self.assertIn("/gitea", nav_hrefs())
|
||||
home = self.client.get("/").text
|
||||
self.assertIn('href="/gitea"', home)
|
||||
self.assertIn(">Gitea<", home)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
unittest.main()
|
||||
@@ -0,0 +1,739 @@
|
||||
"""Tests for the Runtime and session view (Phase 1, #641).
|
||||
|
||||
Covers clean and stale session rendering, contamination marker surfacing,
|
||||
worktree binding display, sanctioned recovery links (no pkill), nav/live
|
||||
status, and the JSON API export.
|
||||
|
||||
Also pins the two invariants a reviewer found violated at head a81db754:
|
||||
degraded ownership sections must render as *unknown* rather than as an
|
||||
affirmative "none"/"unbound", and contamination payload text must be redacted
|
||||
at the display boundary rather than trusted from the write-time denylist.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import os
|
||||
import sys
|
||||
import unittest
|
||||
from pathlib import Path
|
||||
from unittest import mock
|
||||
|
||||
sys.path.insert(0, str(Path(__file__).resolve().parent.parent))
|
||||
|
||||
from tests.webui_testclient import TestClient
|
||||
|
||||
from webui.app import create_app
|
||||
from webui.inventory import (
|
||||
AUTHORITY_CONTROL_PLANE_DB,
|
||||
AUTHORITY_FILESYSTEM,
|
||||
InventorySection,
|
||||
InventorySnapshot,
|
||||
STATUS_DEGRADED,
|
||||
STATUS_OK,
|
||||
STATUS_UNAVAILABLE,
|
||||
)
|
||||
from webui.nav import NAV_GROUPS, STUB_PAGES, iter_nav_items
|
||||
from webui.runtime_health import FileHash, RuntimeSnapshot
|
||||
from webui.session_loader import (
|
||||
ContaminationMarker,
|
||||
SessionRow,
|
||||
SessionViewSnapshot,
|
||||
_build_session_rows,
|
||||
_inspect_contamination,
|
||||
load_session_view_snapshot,
|
||||
snapshot_to_dict,
|
||||
)
|
||||
from webui.session_views import render_sessions_page
|
||||
|
||||
|
||||
def _runtime(
|
||||
*,
|
||||
stale: str | None = None,
|
||||
profile: str = "prgs-author",
|
||||
role: str = "author",
|
||||
) -> RuntimeSnapshot:
|
||||
return RuntimeSnapshot(
|
||||
project_id="gitea-tools",
|
||||
repo_root="/tmp/repo",
|
||||
remote="prgs",
|
||||
host="gitea.prgs.cc",
|
||||
profile_name=profile,
|
||||
role_kind=role,
|
||||
config_model="v2-contexts",
|
||||
profile_mode="dynamic-profile",
|
||||
profile_source="config file profile",
|
||||
authenticated_username="jcwalker3",
|
||||
identity_error=None,
|
||||
repo_sha="a" * 40,
|
||||
remote_master_sha="a" * 40,
|
||||
commits_behind_master=0,
|
||||
stale_runtime_warning=stale,
|
||||
shell_health={"shell_use_allowed": True, "consecutive_spawn_failures": 0},
|
||||
workflow_hashes=(
|
||||
FileHash(label="SKILL.md", path="skills/llm-project-workflow/SKILL.md", sha256="abc"),
|
||||
),
|
||||
schema_hashes=(),
|
||||
restart_guidance="docs/mcp-namespace-eof-recovery.md",
|
||||
fetch_error=None,
|
||||
)
|
||||
|
||||
|
||||
def _inventory(
|
||||
*,
|
||||
sessions: tuple[dict, ...] = (),
|
||||
leases: tuple[dict, ...] = (),
|
||||
locks: tuple[dict, ...] = (),
|
||||
worktrees: tuple[dict, ...] = (),
|
||||
namespaces: tuple[dict, ...] = (),
|
||||
statuses: dict[str, str] | None = None,
|
||||
) -> InventorySnapshot:
|
||||
"""Build a snapshot; ``statuses`` degrades named sections (default all ok)."""
|
||||
status_of = statuses or {}
|
||||
|
||||
def _status(name: str) -> str:
|
||||
return status_of.get(name, STATUS_OK)
|
||||
|
||||
sections = (
|
||||
InventorySection(
|
||||
name="sessions",
|
||||
authority=AUTHORITY_CONTROL_PLANE_DB,
|
||||
status=_status("sessions"),
|
||||
items=sessions,
|
||||
),
|
||||
InventorySection(
|
||||
name="leases",
|
||||
authority=AUTHORITY_CONTROL_PLANE_DB,
|
||||
status=_status("leases"),
|
||||
items=leases,
|
||||
),
|
||||
InventorySection(
|
||||
name="locks",
|
||||
authority=AUTHORITY_FILESYSTEM,
|
||||
status=_status("locks"),
|
||||
items=locks,
|
||||
),
|
||||
InventorySection(
|
||||
name="worktrees",
|
||||
authority=AUTHORITY_FILESYSTEM,
|
||||
status=_status("worktrees"),
|
||||
items=worktrees,
|
||||
),
|
||||
InventorySection(
|
||||
name="namespaces",
|
||||
authority=AUTHORITY_FILESYSTEM,
|
||||
status=_status("namespaces"),
|
||||
items=namespaces
|
||||
or (
|
||||
{
|
||||
"profile_name": "prgs-author",
|
||||
"role": "author",
|
||||
"mcp_namespace": "gitea-author",
|
||||
"capability_summary": {
|
||||
"can_author": True,
|
||||
"can_review": False,
|
||||
"can_merge": False,
|
||||
},
|
||||
"active": True,
|
||||
},
|
||||
),
|
||||
reason="only the profile serving this web process is observable",
|
||||
),
|
||||
)
|
||||
index = {section.name: section for section in sections}
|
||||
return InventorySnapshot(
|
||||
generated_at="2026-07-25T00:00:00+00:00",
|
||||
sections=sections,
|
||||
collisions=(),
|
||||
correlations=(),
|
||||
scan_ms=1.0,
|
||||
_section_index=index,
|
||||
)
|
||||
|
||||
|
||||
def _clean_session() -> dict:
|
||||
return {
|
||||
"session_id": "prgs-author-111-clean",
|
||||
"role": "author",
|
||||
"profile": "prgs-author",
|
||||
"namespace": "gitea-author",
|
||||
"pid": 1111,
|
||||
"pid_alive": True,
|
||||
"status": "active",
|
||||
"started_at": "2026-07-25T00:00:00Z",
|
||||
"last_heartbeat_at": "2026-07-25T01:00:00Z",
|
||||
}
|
||||
|
||||
|
||||
def _stale_session() -> dict:
|
||||
return {
|
||||
"session_id": "prgs-author-222-stale",
|
||||
"role": "author",
|
||||
"profile": "prgs-author",
|
||||
"namespace": "gitea-author",
|
||||
"pid": 2222,
|
||||
"pid_alive": False,
|
||||
"status": "active",
|
||||
"started_at": "2026-07-24T00:00:00Z",
|
||||
"last_heartbeat_at": "2026-07-24T01:00:00Z",
|
||||
}
|
||||
|
||||
|
||||
class TestBuildSessionRows(unittest.TestCase):
|
||||
def test_clean_session_has_no_stale_or_contamination_flags(self):
|
||||
inventory = _inventory(
|
||||
sessions=(_clean_session(),),
|
||||
leases=(
|
||||
{
|
||||
"lease_id": "lease-clean",
|
||||
"session_id": "prgs-author-111-clean",
|
||||
"status": "active",
|
||||
"expired": False,
|
||||
"work_kind": "issue",
|
||||
"work_number": 641,
|
||||
},
|
||||
),
|
||||
locks=(
|
||||
{
|
||||
"issue_number": 641,
|
||||
"branch_name": "feat/issue-641-runtime-session-view",
|
||||
"worktree_path": "~/Development/Gitea-Tools/branches/feat-issue-641",
|
||||
"live": True,
|
||||
},
|
||||
),
|
||||
)
|
||||
rows = _build_session_rows(inventory, contamination=())
|
||||
self.assertEqual(len(rows), 1)
|
||||
row = rows[0]
|
||||
self.assertEqual(row.session_id, "prgs-author-111-clean")
|
||||
self.assertEqual(row.role, "author")
|
||||
self.assertEqual(row.namespace, "gitea-author")
|
||||
self.assertEqual(row.pid_alive, True)
|
||||
self.assertEqual(row.lease_ids, ("lease-clean",))
|
||||
self.assertEqual(row.work_refs, ("issue#641",))
|
||||
self.assertTrue(row.worktree_paths)
|
||||
self.assertEqual(row.stale_flags, ())
|
||||
self.assertEqual(row.contamination_flags, ())
|
||||
|
||||
def test_stale_session_flags_dead_pid(self):
|
||||
inventory = _inventory(sessions=(_stale_session(),))
|
||||
rows = _build_session_rows(inventory, contamination=())
|
||||
self.assertEqual(rows[0].stale_flags, ("pid-dead",))
|
||||
|
||||
def test_contamination_marker_binds_to_session(self):
|
||||
inventory = _inventory(sessions=(_clean_session(),))
|
||||
marker = ContaminationMarker(
|
||||
kind="runtime_recovery_contamination",
|
||||
on_disk=True,
|
||||
has_payload=True,
|
||||
summary="manual daemon kill",
|
||||
reason_class="manual_daemon_kill",
|
||||
session_id="prgs-author-111-clean",
|
||||
role="author",
|
||||
command_summary="pkill -f mcp_server.py",
|
||||
cleared=False,
|
||||
)
|
||||
rows = _build_session_rows(inventory, contamination=(marker,))
|
||||
self.assertIn("runtime_recovery_contamination", rows[0].contamination_flags)
|
||||
|
||||
def test_process_wide_contamination_surfaces_on_all_sessions(self):
|
||||
inventory = _inventory(sessions=(_clean_session(), _stale_session()))
|
||||
marker = ContaminationMarker(
|
||||
kind="stable_branch_contamination",
|
||||
on_disk=True,
|
||||
has_payload=True,
|
||||
summary="direct master push attempt",
|
||||
reason_class="stable_branch_push",
|
||||
session_id=None,
|
||||
cleared=False,
|
||||
)
|
||||
rows = _build_session_rows(inventory, contamination=(marker,))
|
||||
self.assertEqual(len(rows), 2)
|
||||
for row in rows:
|
||||
self.assertTrue(
|
||||
any("stable_branch_contamination" in f for f in row.contamination_flags)
|
||||
)
|
||||
|
||||
|
||||
class TestRenderSessionsPage(unittest.TestCase):
|
||||
def _snapshot(
|
||||
self,
|
||||
*,
|
||||
sessions: tuple[dict, ...],
|
||||
contamination: tuple[ContaminationMarker, ...] = (),
|
||||
stale_runtime: str | None = None,
|
||||
) -> SessionViewSnapshot:
|
||||
inventory = _inventory(
|
||||
sessions=sessions,
|
||||
leases=(
|
||||
{
|
||||
"lease_id": "lease-1",
|
||||
"session_id": sessions[0]["session_id"] if sessions else "",
|
||||
"status": "active",
|
||||
"expired": False,
|
||||
"work_kind": "issue",
|
||||
"work_number": 641,
|
||||
},
|
||||
)
|
||||
if sessions
|
||||
else (),
|
||||
locks=(
|
||||
{
|
||||
"issue_number": 641,
|
||||
"worktree_path": "branches/feat-issue-641",
|
||||
},
|
||||
)
|
||||
if sessions
|
||||
else (),
|
||||
worktrees=(
|
||||
{
|
||||
"rel_path": "branches/feat-issue-641",
|
||||
"branch": "feat/issue-641-runtime-session-view",
|
||||
"classification": "active_issue_work",
|
||||
"registered_worktree": True,
|
||||
"dirty": False,
|
||||
},
|
||||
),
|
||||
)
|
||||
rows = _build_session_rows(inventory, contamination)
|
||||
return SessionViewSnapshot(
|
||||
runtime=_runtime(stale=stale_runtime),
|
||||
inventory=inventory,
|
||||
sessions=rows,
|
||||
contamination_markers=contamination,
|
||||
)
|
||||
|
||||
def test_clean_session_render(self):
|
||||
html = render_sessions_page(self._snapshot(sessions=(_clean_session(),)))
|
||||
self.assertIn("Runtime and sessions", html)
|
||||
self.assertIn("prgs-author-111-clean", html)
|
||||
self.assertIn("gitea-author", html)
|
||||
self.assertIn("branches/feat-issue-641", html)
|
||||
self.assertIn("Sanctioned recovery", html)
|
||||
self.assertIn("docs/mcp-namespace-eof-recovery.md", html)
|
||||
# Recovery section must name reconnect and forbid manual kill.
|
||||
recovery_idx = html.lower().find("sanctioned recovery")
|
||||
self.assertGreaterEqual(recovery_idx, 0)
|
||||
recovery = html[recovery_idx:].lower()
|
||||
self.assertIn("reconnect", recovery)
|
||||
self.assertIn("contamination", recovery)
|
||||
self.assertIn("not recovery", recovery)
|
||||
self.assertNotIn("run pkill", recovery)
|
||||
self.assertNotIn("killall", recovery)
|
||||
|
||||
def test_stale_session_render(self):
|
||||
html = render_sessions_page(self._snapshot(sessions=(_stale_session(),)))
|
||||
self.assertIn("prgs-author-222-stale", html)
|
||||
self.assertIn("pid-dead", html)
|
||||
self.assertIn("badge-stale", html)
|
||||
|
||||
def test_contamination_render_is_not_silent(self):
|
||||
marker = ContaminationMarker(
|
||||
kind="runtime_recovery_contamination",
|
||||
on_disk=True,
|
||||
has_payload=True,
|
||||
summary="manual kill",
|
||||
reason_class="manual_daemon_kill",
|
||||
session_id="prgs-author-111-clean",
|
||||
command_summary="pkill -f mcp_server.py",
|
||||
cleared=False,
|
||||
)
|
||||
html = render_sessions_page(
|
||||
self._snapshot(sessions=(_clean_session(),), contamination=(marker,))
|
||||
)
|
||||
self.assertIn("Contamination markers", html)
|
||||
self.assertIn("runtime_recovery_contamination", html)
|
||||
self.assertIn("ACTIVE", html)
|
||||
self.assertIn("badge-blocked", html)
|
||||
|
||||
def test_stale_runtime_banner(self):
|
||||
html = render_sessions_page(
|
||||
self._snapshot(
|
||||
sessions=(_clean_session(),),
|
||||
stale_runtime="server behind master by 3 commits",
|
||||
)
|
||||
)
|
||||
self.assertIn("Stale runtime", html)
|
||||
self.assertIn("server behind master", html)
|
||||
|
||||
|
||||
class TestSessionLoaderComposition(unittest.TestCase):
|
||||
def test_load_with_injected_sources(self):
|
||||
inventory = _inventory(sessions=(_clean_session(), _stale_session()))
|
||||
snap = load_session_view_snapshot(
|
||||
load_runtime=lambda: _runtime(),
|
||||
load_inventory=lambda: inventory,
|
||||
inspect_contamination=lambda **_k: {
|
||||
"on_disk": False,
|
||||
"has_payload": False,
|
||||
"summary": "absent",
|
||||
},
|
||||
load_contamination_payload=lambda **_k: None,
|
||||
)
|
||||
self.assertEqual(len(snap.sessions), 2)
|
||||
self.assertEqual(snap.stale_session_count, 1)
|
||||
self.assertEqual(snap.contaminated_session_count, 0)
|
||||
data = snapshot_to_dict(snap)
|
||||
self.assertEqual(data["view"], "runtime-sessions")
|
||||
self.assertEqual(data["issue"], 641)
|
||||
self.assertTrue(data["read_only"])
|
||||
self.assertEqual(data["session_counts"]["total"], 2)
|
||||
self.assertEqual(data["session_counts"]["stale"], 1)
|
||||
self.assertIn("recovery_docs", data)
|
||||
|
||||
|
||||
class TestSessionsRoutes(unittest.TestCase):
|
||||
def setUp(self):
|
||||
self.client = TestClient(create_app())
|
||||
inventory = _inventory(
|
||||
sessions=(_clean_session(), _stale_session()),
|
||||
leases=(
|
||||
{
|
||||
"lease_id": "lease-x",
|
||||
"session_id": "prgs-author-111-clean",
|
||||
"status": "active",
|
||||
"expired": False,
|
||||
"work_kind": "issue",
|
||||
"work_number": 641,
|
||||
},
|
||||
),
|
||||
locks=(
|
||||
{
|
||||
"issue_number": 641,
|
||||
"worktree_path": "branches/feat-issue-641",
|
||||
},
|
||||
),
|
||||
worktrees=(
|
||||
{
|
||||
"rel_path": "branches/feat-issue-641",
|
||||
"branch": "feat/issue-641-runtime-session-view",
|
||||
"classification": "active_issue_work",
|
||||
"registered_worktree": True,
|
||||
"dirty": False,
|
||||
},
|
||||
),
|
||||
)
|
||||
rows = _build_session_rows(inventory, contamination=())
|
||||
self.snapshot = SessionViewSnapshot(
|
||||
runtime=_runtime(stale="stale for test"),
|
||||
inventory=inventory,
|
||||
sessions=rows,
|
||||
contamination_markers=(),
|
||||
)
|
||||
self._patch = mock.patch(
|
||||
"webui.app.load_session_view_snapshot",
|
||||
return_value=self.snapshot,
|
||||
)
|
||||
self._patch.start()
|
||||
|
||||
def tearDown(self):
|
||||
self._patch.stop()
|
||||
|
||||
def test_sessions_page_live(self):
|
||||
response = self.client.get("/sessions")
|
||||
self.assertEqual(response.status_code, 200)
|
||||
self.assertIn("Runtime and sessions", response.text)
|
||||
self.assertIn("prgs-author-111-clean", response.text)
|
||||
self.assertIn("prgs-author-222-stale", response.text)
|
||||
self.assertIn("pid-dead", response.text)
|
||||
self.assertIn("Sanctioned recovery", response.text)
|
||||
self.assertNotIn("Phase 1 shell placeholder", response.text)
|
||||
self.assertNotIn("child issue of #425", response.text.lower())
|
||||
|
||||
def test_api_sessions_json(self):
|
||||
for path in ("/api/sessions", "/api/v1/sessions"):
|
||||
response = self.client.get(path)
|
||||
self.assertEqual(response.status_code, 200, path)
|
||||
data = response.json()
|
||||
self.assertEqual(data["view"], "runtime-sessions")
|
||||
self.assertEqual(data["session_counts"]["total"], 2)
|
||||
self.assertEqual(data["session_counts"]["stale"], 1)
|
||||
self.assertTrue(data["read_only"])
|
||||
self.assertEqual(data["mutations"], [])
|
||||
|
||||
def test_nav_marks_sessions_live(self):
|
||||
sessions_items = [
|
||||
item for item in iter_nav_items() if item.href == "/sessions"
|
||||
]
|
||||
self.assertEqual(len(sessions_items), 1)
|
||||
self.assertEqual(sessions_items[0].status, "live")
|
||||
self.assertNotIn("/sessions", STUB_PAGES)
|
||||
# Home page should not mark Sessions as stub.
|
||||
home = self.client.get("/")
|
||||
self.assertEqual(home.status_code, 200)
|
||||
self.assertIn('href="/sessions"', home.text)
|
||||
# Stub marker only appears next to remaining stub destinations.
|
||||
self.assertNotIn(
|
||||
'href="/sessions">Sessions</a> <span class="muted">(stub)</span>',
|
||||
home.text,
|
||||
)
|
||||
|
||||
|
||||
class TestDegradedOwnershipAuthority(unittest.TestCase):
|
||||
"""B1: a section that could not be read must never render as absence."""
|
||||
|
||||
def _snapshot(self, inventory: InventorySnapshot) -> SessionViewSnapshot:
|
||||
return SessionViewSnapshot(
|
||||
runtime=_runtime(),
|
||||
inventory=inventory,
|
||||
sessions=_build_session_rows(inventory, contamination=()),
|
||||
contamination_markers=(),
|
||||
)
|
||||
|
||||
def test_unavailable_leases_mark_row_authority_unproven(self):
|
||||
inventory = _inventory(
|
||||
sessions=(_clean_session(),),
|
||||
statuses={"leases": STATUS_UNAVAILABLE},
|
||||
)
|
||||
row = _build_session_rows(inventory, contamination=())[0]
|
||||
self.assertEqual(row.lease_ids, ())
|
||||
self.assertEqual(row.lease_authority, STATUS_UNAVAILABLE)
|
||||
# Worktree binding is correlated through lease work numbers, so it
|
||||
# inherits the unreadable lease section.
|
||||
self.assertEqual(row.worktree_authority, STATUS_UNAVAILABLE)
|
||||
self.assertFalse(row.ownership_authority_complete)
|
||||
|
||||
def test_readable_locks_are_not_reported_unbound_when_leases_degrade(self):
|
||||
# The narrow variant: locks hold a real worktree_path and read cleanly,
|
||||
# but the lease section that supplies the correlating work number does
|
||||
# not. The row must say unknown, not "unbound".
|
||||
inventory = _inventory(
|
||||
sessions=(_clean_session(),),
|
||||
locks=(
|
||||
{
|
||||
"issue_number": 641,
|
||||
"worktree_path": "branches/feat-issue-641",
|
||||
},
|
||||
),
|
||||
statuses={"leases": STATUS_DEGRADED},
|
||||
)
|
||||
row = _build_session_rows(inventory, contamination=())[0]
|
||||
self.assertEqual(row.worktree_paths, ())
|
||||
self.assertEqual(row.worktree_authority, STATUS_DEGRADED)
|
||||
self.assertFalse(row.ownership_authority_complete)
|
||||
|
||||
def test_degraded_render_says_unknown_not_none_or_unbound(self):
|
||||
inventory = _inventory(
|
||||
sessions=(_clean_session(),),
|
||||
statuses={"leases": STATUS_UNAVAILABLE, "locks": STATUS_UNAVAILABLE},
|
||||
)
|
||||
html = render_sessions_page(self._snapshot(inventory))
|
||||
self.assertIn("unknown (inventory unavailable)", html)
|
||||
self.assertIn("authority unproven", html)
|
||||
self.assertIn("Ownership authority incomplete", html)
|
||||
# The affirmative-absence strings must be gone from the row entirely.
|
||||
self.assertNotIn(">none<", html)
|
||||
self.assertNotIn(">unbound<", html)
|
||||
|
||||
def test_clean_inventory_still_renders_affirmative_absence(self):
|
||||
# Guards against over-correcting B1 into "everything is unknown".
|
||||
inventory = _inventory(sessions=(_clean_session(),))
|
||||
html = render_sessions_page(self._snapshot(inventory))
|
||||
self.assertIn(">none<", html)
|
||||
self.assertIn(">unbound<", html)
|
||||
# The column legend mentions "unknown (inventory …)" as static copy, so
|
||||
# assert on the per-row marker and the concrete statuses instead.
|
||||
self.assertNotIn("authority unproven", html)
|
||||
self.assertNotIn("unknown (inventory unavailable)", html)
|
||||
self.assertNotIn("unknown (inventory degraded)", html)
|
||||
self.assertNotIn("Ownership authority incomplete", html)
|
||||
|
||||
def test_json_export_carries_snapshot_and_per_row_authority(self):
|
||||
inventory = _inventory(
|
||||
sessions=(_clean_session(),),
|
||||
statuses={"locks": STATUS_UNAVAILABLE},
|
||||
)
|
||||
data = snapshot_to_dict(self._snapshot(inventory))
|
||||
self.assertFalse(data["ownership_authority_complete"])
|
||||
self.assertEqual(
|
||||
data["ownership_section_status"]["locks"], STATUS_UNAVAILABLE
|
||||
)
|
||||
self.assertEqual(data["ownership_section_status"]["leases"], STATUS_OK)
|
||||
self.assertIn("unknown, not unowned", data["ownership_note"])
|
||||
|
||||
row = data["sessions"][0]
|
||||
self.assertTrue(row["lease_authority_complete"])
|
||||
self.assertFalse(row["worktree_authority_complete"])
|
||||
self.assertEqual(row["worktree_authority"], STATUS_UNAVAILABLE)
|
||||
self.assertFalse(row["ownership_authority_complete"])
|
||||
self.assertIn("unknown, not unowned", row["ownership_note"])
|
||||
|
||||
def test_json_export_is_affirmative_when_every_source_reads(self):
|
||||
inventory = _inventory(sessions=(_clean_session(),))
|
||||
data = snapshot_to_dict(self._snapshot(inventory))
|
||||
self.assertTrue(data["ownership_authority_complete"])
|
||||
self.assertTrue(data["sessions"][0]["ownership_authority_complete"])
|
||||
|
||||
def test_missing_session_list_is_not_reported_as_no_sessions(self):
|
||||
inventory = _inventory(statuses={"sessions": STATUS_UNAVAILABLE})
|
||||
html = render_sessions_page(self._snapshot(inventory))
|
||||
self.assertIn("could not be read", html)
|
||||
self.assertIn("not evidence that no sessions exist", html)
|
||||
|
||||
def test_expired_lease_flags_row_as_stale(self):
|
||||
inventory = _inventory(
|
||||
sessions=(_clean_session(),),
|
||||
leases=(
|
||||
{
|
||||
"lease_id": "lease-expired-1",
|
||||
"session_id": "prgs-author-111-clean",
|
||||
"status": "active",
|
||||
"expired": True,
|
||||
"work_kind": "issue",
|
||||
"work_number": 641,
|
||||
},
|
||||
),
|
||||
)
|
||||
row = _build_session_rows(inventory, contamination=())[0]
|
||||
self.assertIn("lease-expired", row.stale_flags)
|
||||
self.assertIn("active-lease-past-expiry", row.stale_flags)
|
||||
|
||||
|
||||
class TestContaminationRedaction(unittest.TestCase):
|
||||
"""B2: marker payload text is redacted at the display boundary."""
|
||||
|
||||
def _marker(self, payload: dict) -> ContaminationMarker:
|
||||
return _inspect_contamination(
|
||||
"runtime_recovery_contamination",
|
||||
remote="prgs",
|
||||
inspect=lambda **_k: {
|
||||
"on_disk": True,
|
||||
"has_payload": True,
|
||||
"summary": "",
|
||||
},
|
||||
load=lambda **_k: payload,
|
||||
)
|
||||
|
||||
def test_home_paths_are_collapsed(self):
|
||||
home = os.path.expanduser("~")
|
||||
marker = self._marker(
|
||||
{"command_summary": f"pkill -f {home}/Development/Gitea-Tools/x.py"}
|
||||
)
|
||||
self.assertNotIn(home, marker.command_summary)
|
||||
self.assertIn("~/Development/Gitea-Tools/x.py", marker.command_summary)
|
||||
|
||||
def test_secrets_missed_by_the_write_time_denylist_are_redacted(self):
|
||||
# Each of these was verified in review to survive
|
||||
# stable_branch_push_guard.redact_command untouched.
|
||||
cases = (
|
||||
("curl -H 'X-Api-Key: SUPERSECRET123' https://example.invalid", "SUPERSECRET123"),
|
||||
("cmd --password hunter2 origin master", "hunter2"),
|
||||
("PRIVATE_KEY=abc123 python deploy.py", "abc123"),
|
||||
("fetch https://user:[email protected]/x.git", "user:pw"),
|
||||
)
|
||||
for raw, secret in cases:
|
||||
with self.subTest(raw=raw):
|
||||
marker = self._marker({"command_summary": raw})
|
||||
self.assertNotIn(secret, marker.command_summary)
|
||||
self.assertIn("[redacted]", marker.command_summary)
|
||||
|
||||
def test_command_summary_is_redacted_not_removed(self):
|
||||
# It is legitimate #630 evidence: the operator must still see which
|
||||
# daemon was killed.
|
||||
marker = self._marker(
|
||||
{
|
||||
"command_summary": "pkill -f gitea_mcp_server.py",
|
||||
"reason_class": "manual_daemon_kill",
|
||||
"session_id": "prgs-author-111-clean",
|
||||
"role": "author",
|
||||
}
|
||||
)
|
||||
self.assertIn("pkill -f gitea_mcp_server.py", marker.command_summary)
|
||||
self.assertEqual(marker.reason_class, "manual_daemon_kill")
|
||||
self.assertEqual(marker.session_id, "prgs-author-111-clean")
|
||||
self.assertEqual(marker.role, "author")
|
||||
|
||||
def test_rendered_page_exposes_no_home_path_from_a_marker(self):
|
||||
home = os.path.expanduser("~")
|
||||
marker = self._marker(
|
||||
{
|
||||
"command_summary": f"pkill -f {home}/Development/Gitea-Tools/x.py",
|
||||
"reason_class": "manual_daemon_kill",
|
||||
}
|
||||
)
|
||||
inventory = _inventory(sessions=(_clean_session(),))
|
||||
html = render_sessions_page(
|
||||
SessionViewSnapshot(
|
||||
runtime=_runtime(),
|
||||
inventory=inventory,
|
||||
sessions=_build_session_rows(inventory, (marker,)),
|
||||
contamination_markers=(marker,),
|
||||
)
|
||||
)
|
||||
self.assertIn("Contamination markers", html)
|
||||
self.assertNotIn(home, html)
|
||||
|
||||
|
||||
class TestSessionsPageEscaping(unittest.TestCase):
|
||||
"""Hostile values from every rendered source stay inert (N2)."""
|
||||
|
||||
HOSTILE = '<script>alert("xss")</script>'
|
||||
|
||||
def test_hostile_session_and_marker_values_are_escaped(self):
|
||||
session = dict(_clean_session())
|
||||
session["session_id"] = f"sid-{self.HOSTILE}"
|
||||
session["role"] = self.HOSTILE
|
||||
session["profile"] = self.HOSTILE
|
||||
session["namespace"] = self.HOSTILE
|
||||
session["status"] = self.HOSTILE
|
||||
inventory = _inventory(
|
||||
sessions=(session,),
|
||||
leases=(
|
||||
{
|
||||
"lease_id": self.HOSTILE,
|
||||
"session_id": session["session_id"],
|
||||
"status": "active",
|
||||
"expired": False,
|
||||
"work_kind": self.HOSTILE,
|
||||
"work_number": 641,
|
||||
},
|
||||
),
|
||||
locks=(
|
||||
{
|
||||
"issue_number": 641,
|
||||
"worktree_path": self.HOSTILE,
|
||||
},
|
||||
),
|
||||
)
|
||||
marker = ContaminationMarker(
|
||||
kind="runtime_recovery_contamination",
|
||||
on_disk=True,
|
||||
has_payload=True,
|
||||
summary=self.HOSTILE,
|
||||
reason_class=self.HOSTILE,
|
||||
session_id=session["session_id"],
|
||||
role=self.HOSTILE,
|
||||
command_summary=self.HOSTILE,
|
||||
cleared=False,
|
||||
)
|
||||
html = render_sessions_page(
|
||||
SessionViewSnapshot(
|
||||
runtime=_runtime(),
|
||||
inventory=inventory,
|
||||
sessions=_build_session_rows(inventory, (marker,)),
|
||||
contamination_markers=(marker,),
|
||||
)
|
||||
)
|
||||
self.assertNotIn("<script>", html)
|
||||
self.assertNotIn('alert("xss")', html)
|
||||
self.assertIn("<script>", html)
|
||||
|
||||
def test_hostile_values_in_a_degraded_render_are_escaped(self):
|
||||
inventory = _inventory(
|
||||
sessions=(dict(_clean_session(), session_id=f"sid-{self.HOSTILE}"),),
|
||||
statuses={"leases": STATUS_UNAVAILABLE, "locks": STATUS_DEGRADED},
|
||||
)
|
||||
html = render_sessions_page(
|
||||
SessionViewSnapshot(
|
||||
runtime=_runtime(),
|
||||
inventory=inventory,
|
||||
sessions=_build_session_rows(inventory, contamination=()),
|
||||
contamination_markers=(),
|
||||
)
|
||||
)
|
||||
self.assertNotIn("<script>", html)
|
||||
self.assertIn("<script>", html)
|
||||
self.assertIn("unknown (inventory", html)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
unittest.main()
|
||||
@@ -48,6 +48,16 @@ from webui.worktree_scanner import load_hygiene_snapshot, snapshot_to_dict as wo
|
||||
from webui.worktree_views import render_worktrees_page
|
||||
from webui.runtime_health import load_runtime_snapshot, snapshot_to_dict as runtime_snapshot_to_dict
|
||||
from webui.runtime_views import render_runtime_page
|
||||
from webui.session_loader import (
|
||||
load_session_view_snapshot,
|
||||
snapshot_to_dict as session_view_snapshot_to_dict,
|
||||
)
|
||||
from webui.session_views import render_sessions_page
|
||||
from webui.linkage_loader import (
|
||||
load_linkage_snapshot,
|
||||
snapshot_to_dict as linkage_snapshot_to_dict,
|
||||
)
|
||||
from webui.linkage_views import render_linkage_page
|
||||
from webui.inventory import (
|
||||
SECTION_NAMES as _INVENTORY_SECTIONS,
|
||||
load_inventory_snapshot,
|
||||
@@ -87,6 +97,7 @@ _LEGACY_PAGES = (
|
||||
("/projects", "Projects", "registry and onboarding (#427)"),
|
||||
("/prompts", "Prompts", "canonical workflow prompt library (#428)"),
|
||||
("/runtime", "Runtime", "MCP health and stale-runtime detection (#430)"),
|
||||
("/sessions", "Sessions", "runtime and session view (#641)"),
|
||||
("/audit", "Audit", "final-report paste and validator preview (#431)"),
|
||||
("/worktrees", "Worktrees", "branch hygiene dashboard (#432)"),
|
||||
("/leases", "Leases", "collision and lease visibility (#433)"),
|
||||
@@ -325,6 +336,52 @@ async def api_runtime(_request: Request) -> JSONResponse:
|
||||
return JSONResponse(runtime_snapshot_to_dict(load_runtime_snapshot()))
|
||||
|
||||
|
||||
async def sessions(_request: Request) -> HTMLResponse:
|
||||
"""Runtime and session view (#641) — read-only composition of health + inventory."""
|
||||
snapshot = load_session_view_snapshot()
|
||||
return HTMLResponse(render_sessions_page(snapshot))
|
||||
|
||||
|
||||
async def api_sessions(_request: Request) -> JSONResponse:
|
||||
"""JSON export for the runtime/session view (#641)."""
|
||||
return JSONResponse(session_view_snapshot_to_dict(load_session_view_snapshot()))
|
||||
|
||||
|
||||
def _linkage_snapshot(request: Request):
|
||||
"""Load one linkage snapshot from the request's scope and focus parameters."""
|
||||
return load_linkage_snapshot(
|
||||
request.query_params.get("project") or None,
|
||||
state=request.query_params.get("state"),
|
||||
issue=_query_int(request, "issue"),
|
||||
pr=_query_int(request, "pr"),
|
||||
)
|
||||
|
||||
|
||||
async def gitea_linkage(request: Request) -> HTMLResponse:
|
||||
"""Gitea issue↔PR linkage console (#645) — read-only.
|
||||
|
||||
Always 200, including on a failed read: this is an operator view, and it
|
||||
must render *why* linkage could not be loaded rather than withhold the page.
|
||||
The snapshot itself carries ``ok=False`` and the page refuses to draw a
|
||||
linkage table it cannot stand behind.
|
||||
"""
|
||||
return HTMLResponse(render_linkage_page(_linkage_snapshot(request)))
|
||||
|
||||
|
||||
async def api_v1_gitea_linkage(request: Request) -> JSONResponse:
|
||||
"""JSON export of the issue↔PR linkage model (#645).
|
||||
|
||||
Unlike the HTML view, the API answers with 502 when the snapshot could not
|
||||
be loaded, so an automated consumer cannot read a fail-closed payload as a
|
||||
successful "no links exist" result.
|
||||
"""
|
||||
snapshot = _linkage_snapshot(request)
|
||||
return JSONResponse(
|
||||
linkage_snapshot_to_dict(snapshot),
|
||||
status_code=200 if snapshot.ok else 502,
|
||||
)
|
||||
|
||||
|
||||
async def _parse_audit_form(request: Request) -> tuple[str, str | None]:
|
||||
if request.method == "GET":
|
||||
return "", None
|
||||
@@ -764,7 +821,12 @@ def create_app(*, bind_host: str | None = None) -> Starlette:
|
||||
Route("/api/prompts", api_prompts, methods=["GET"]),
|
||||
Route("/runtime", runtime, methods=["GET"]),
|
||||
Route("/api/runtime", api_runtime, methods=["GET"]),
|
||||
Route("/sessions", sessions, methods=["GET"]),
|
||||
Route("/api/sessions", api_sessions, methods=["GET"]),
|
||||
Route("/api/v1/sessions", api_sessions, methods=["GET"]),
|
||||
Route("/api/v1/timeline", api_v1_timeline, methods=["GET"]),
|
||||
Route("/gitea", gitea_linkage, methods=["GET"]),
|
||||
Route("/api/v1/gitea/linkage", api_v1_gitea_linkage, methods=["GET"]),
|
||||
Route("/analytics", analytics, methods=["GET"]),
|
||||
Route("/api/analytics", api_v1_analytics, methods=["GET"]),
|
||||
Route("/api/v1/analytics", api_v1_analytics, methods=["GET"]),
|
||||
|
||||
@@ -76,6 +76,35 @@ _CREDENTIAL_KEY_RE = re.compile(
|
||||
)
|
||||
_REDACTED = "[redacted]"
|
||||
|
||||
#: Credential-shaped *name* as it appears inside a free-form command line. This
|
||||
#: is deliberately broader than :data:`_CREDENTIAL_KEY_RE` — it also matches a
|
||||
#: bare ``key`` component, so ``PRIVATE_KEY=`` is caught. Over-redacting a
|
||||
#: displayed string is safe; under-redacting one is not.
|
||||
_TEXT_CREDENTIAL_NAME = (
|
||||
r"[A-Za-z0-9_.\-]*"
|
||||
r"(?:token|secret|password|passwd|key|authorization|bearer|credential)"
|
||||
r"[A-Za-z0-9_.\-]*"
|
||||
)
|
||||
#: A value following such a name: single-quoted, double-quoted, or bare. The
|
||||
#: bare form stops at a quote so an enclosing quote survives the redaction.
|
||||
_TEXT_CREDENTIAL_VALUE = r"'[^']*'|\"[^\"]*\"|[^\s'\"]+"
|
||||
|
||||
_TEXT_CREDENTIAL_FLAG_RE = re.compile(
|
||||
rf"(?P<key>(?<![\w\-])--?{_TEXT_CREDENTIAL_NAME})"
|
||||
rf"(?P<sep>[=\s]+)"
|
||||
rf"(?P<value>{_TEXT_CREDENTIAL_VALUE})",
|
||||
re.IGNORECASE,
|
||||
)
|
||||
_TEXT_CREDENTIAL_ASSIGN_RE = re.compile(
|
||||
rf"(?P<key>(?<![\w\-]){_TEXT_CREDENTIAL_NAME})"
|
||||
rf"(?P<sep>\s*[:=]\s*)"
|
||||
rf"(?P<value>{_TEXT_CREDENTIAL_VALUE})",
|
||||
re.IGNORECASE,
|
||||
)
|
||||
_TEXT_URL_USERINFO_RE = re.compile(
|
||||
r"(?P<scheme>\b[A-Za-z][A-Za-z0-9+.\-]*://)[^\s/@]+@"
|
||||
)
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class InventorySection:
|
||||
@@ -225,6 +254,42 @@ def scrub(value: Any, *, key: str | None = None) -> Any:
|
||||
return repr(value)
|
||||
|
||||
|
||||
def collapse_home(text: str) -> str:
|
||||
"""Collapse every ``$HOME`` occurrence *inside* a string, not just a prefix."""
|
||||
home = os.path.expanduser("~")
|
||||
if not home or home == "/":
|
||||
return text
|
||||
return text.replace(home, "~")
|
||||
|
||||
|
||||
def scrub_text(value: Any) -> Any:
|
||||
"""Redact a free-form text blob such as a recorded command line.
|
||||
|
||||
:func:`scrub` keys off structured field *names* and whole-value prefixes,
|
||||
which is right for inventory records but blind to a secret embedded in the
|
||||
middle of a sentence. This collapses ``$HOME`` and redacts credential-shaped
|
||||
tokens and URL userinfo *anywhere* in the string, so operator-supplied text
|
||||
rendered verbatim — contamination ``command_summary`` (#630) above all — is
|
||||
held to the same standard as every other field on the page.
|
||||
|
||||
Returns ``None`` unchanged so callers can keep "absent" distinct from "".
|
||||
"""
|
||||
if value is None:
|
||||
return None
|
||||
text = value if isinstance(value, str) else str(value)
|
||||
text = collapse_home(text)
|
||||
text = _TEXT_URL_USERINFO_RE.sub(
|
||||
lambda m: f"{m.group('scheme')}{_REDACTED}@", text
|
||||
)
|
||||
text = _TEXT_CREDENTIAL_FLAG_RE.sub(
|
||||
lambda m: f"{m.group('key')}{m.group('sep')}{_REDACTED}", text
|
||||
)
|
||||
text = _TEXT_CREDENTIAL_ASSIGN_RE.sub(
|
||||
lambda m: f"{m.group('key')}{m.group('sep')}{_REDACTED}", text
|
||||
)
|
||||
return text
|
||||
|
||||
|
||||
# ── control-plane database (read-only) ───────────────────────────────────────
|
||||
|
||||
|
||||
|
||||
@@ -0,0 +1,771 @@
|
||||
"""Gitea issue↔PR linkage model for the console (#645, Phase 3).
|
||||
|
||||
Operators lose context between an issue and the PR that closes it: which PR
|
||||
carries which issue, whether two PRs claim the same issue, and what the latest
|
||||
canonical handoff on that thread said. The evidence exists in Gitea, but only
|
||||
as free text scattered across PR titles, bodies, and branch names.
|
||||
|
||||
This module resolves that linkage into one read-only model:
|
||||
|
||||
* :func:`resolve_linkage` is a pure function from raw Gitea issue/PR payloads to
|
||||
a :class:`LinkageIndex`. It records *how* each edge was found (a ``Closes #N``
|
||||
keyword, the canonical ``feat/issue-N-…`` branch marker, or a bare ``#N``
|
||||
body reference) and never collapses several candidates into one silent guess.
|
||||
* :func:`load_linkage_snapshot` scopes that index to a registry project and
|
||||
optionally attaches the latest Canonical Thread Handoff (CTH) summary for one
|
||||
focused issue or PR.
|
||||
|
||||
Design rules, matching the rest of the console:
|
||||
|
||||
- **Read-only.** Gitea is read through the shared authenticated helpers. No
|
||||
endpoint here mutates anything, and no write action is registered.
|
||||
- **Qualified absence.** Linkage is a claim about a *loaded* window of Gitea.
|
||||
When pagination did not complete, when credentials were unavailable, or when
|
||||
only open items were fetched, the snapshot says so and every "no linked PR"
|
||||
is marked non-authoritative. An empty edge list from a partial read is not
|
||||
evidence that no link exists.
|
||||
- **Handoff is loaded, never assumed.** CTH comments are thread-scoped, so they
|
||||
are fetched only for an explicitly focused issue or PR. Every other row
|
||||
reports ``not_loaded`` rather than rendering as "no handoff".
|
||||
- **Redaction at the boundary.** Titles, labels, handoff fields, and error
|
||||
reasons are free text from Gitea and cross :mod:`webui.console_redaction`
|
||||
before they leave this module.
|
||||
- **Deep links are opt-in.** A link to the Gitea web UI is emitted only under
|
||||
the ``GITEA_MCP_REVEAL_ENDPOINTS`` admin opt-in, exactly as the MCP tools
|
||||
gate their own URL exposure.
|
||||
|
||||
Non-goals (from the issue): no issue/PR editor, no browser review or merge, no
|
||||
reimplementation of Gitea search.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import os
|
||||
import re
|
||||
from dataclasses import dataclass
|
||||
from typing import Any, Callable, Iterable, Sequence
|
||||
|
||||
from gitea_auth import api_fetch_page, get_auth_header, gitea_url, repo_api_url
|
||||
|
||||
from webui import console_redaction
|
||||
from webui.project_registry import ProjectRecord, load_registry
|
||||
from webui.queue_loader import (
|
||||
PaginationMeta,
|
||||
_fetch_issues,
|
||||
_fetch_prs,
|
||||
_host_from_url,
|
||||
)
|
||||
|
||||
#: Version of the serialized linkage contract. Bump on any breaking change.
|
||||
LINKAGE_SCHEMA_VERSION = 1
|
||||
|
||||
# --- Linkage evidence -------------------------------------------------------
|
||||
# Ordered strongest to weakest. The strength ordering is what makes an
|
||||
# ambiguous PR detectable: two candidates at the same strength are a genuine
|
||||
# ambiguity, while a weaker candidate alongside a stronger one is not.
|
||||
EVIDENCE_CLOSES = "closes_keyword"
|
||||
EVIDENCE_BRANCH = "branch_marker"
|
||||
EVIDENCE_REFERENCE = "body_reference"
|
||||
|
||||
EVIDENCE_ORDER: tuple[str, ...] = (
|
||||
EVIDENCE_CLOSES,
|
||||
EVIDENCE_BRANCH,
|
||||
EVIDENCE_REFERENCE,
|
||||
)
|
||||
_EVIDENCE_RANK = {name: rank for rank, name in enumerate(EVIDENCE_ORDER)}
|
||||
|
||||
EVIDENCE_DESCRIPTIONS: dict[str, str] = {
|
||||
EVIDENCE_CLOSES: (
|
||||
"the PR title or body declares 'closes/fixes/resolves #N' — Gitea itself "
|
||||
"acts on this keyword, so it is the strongest available evidence"
|
||||
),
|
||||
EVIDENCE_BRANCH: (
|
||||
"the PR head branch carries the canonical issue marker "
|
||||
"'(fix|feat|docs|chore)/issue-N-…' minted by the issue lock"
|
||||
),
|
||||
EVIDENCE_REFERENCE: (
|
||||
"the PR body mentions '#N' without a closing keyword; a mention is not "
|
||||
"a claim that the PR closes that issue"
|
||||
),
|
||||
}
|
||||
|
||||
_CLOSES_RE = re.compile(r"(?:closes|fixes|resolves)\s+#(\d+)", re.IGNORECASE)
|
||||
_REFERENCE_RE = re.compile(r"#(\d+)")
|
||||
_BRANCH_MARKER_RE = re.compile(
|
||||
r"^(?:fix|feat|docs|chore)/issue-(\d+)(?:[-/]|$)", re.IGNORECASE
|
||||
)
|
||||
|
||||
# Handoff-source states. ``not_loaded`` is deliberately distinct from "none
|
||||
# found": a row whose comments were never fetched proves nothing about whether
|
||||
# a handoff exists on that thread.
|
||||
HANDOFF_NOT_LOADED = "not_loaded"
|
||||
HANDOFF_LOADED = "loaded"
|
||||
HANDOFF_UNAVAILABLE = "unavailable"
|
||||
|
||||
# Which item states were fetched. Linkage claims are scoped to this window.
|
||||
STATE_OPEN = "open"
|
||||
STATE_ALL = "all"
|
||||
_SUPPORTED_STATES = (STATE_OPEN, STATE_ALL)
|
||||
|
||||
|
||||
def _redact(value: Any) -> Any:
|
||||
"""Redact one free-text field, failing closed to the placeholder."""
|
||||
if value is None:
|
||||
return None
|
||||
return console_redaction.redact_text(str(value))
|
||||
|
||||
|
||||
def deep_links_enabled(env: dict[str, str] | None = None) -> bool:
|
||||
"""Whether Gitea web-UI deep links may be emitted (admin/debug opt-in)."""
|
||||
source = env if env is not None else os.environ
|
||||
return (source.get("GITEA_MCP_REVEAL_ENDPOINTS") or "").strip().lower() in {
|
||||
"1",
|
||||
"true",
|
||||
"yes",
|
||||
"on",
|
||||
}
|
||||
|
||||
|
||||
def _deep_link(host: str, org: str, repo: str, kind: str, number: int) -> str | None:
|
||||
"""Build a Gitea web link for one item, or None when reveal is not enabled."""
|
||||
if not deep_links_enabled() or not (host and org and repo):
|
||||
return None
|
||||
segment = "pulls" if kind == "pr" else "issues"
|
||||
try:
|
||||
return gitea_url(host, f"/{org}/{repo}/{segment}/{int(number)}")
|
||||
except Exception:
|
||||
return None
|
||||
|
||||
|
||||
# --- Pure linkage resolution -------------------------------------------------
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class IssueLink:
|
||||
"""One resolved edge from a PR to an issue, with the evidence that found it."""
|
||||
|
||||
issue_number: int
|
||||
evidence: tuple[str, ...]
|
||||
|
||||
@property
|
||||
def strength(self) -> int:
|
||||
"""Rank of the strongest evidence backing this edge (lower is stronger)."""
|
||||
return min(
|
||||
(_EVIDENCE_RANK.get(name, len(EVIDENCE_ORDER)) for name in self.evidence),
|
||||
default=len(EVIDENCE_ORDER),
|
||||
)
|
||||
|
||||
@property
|
||||
def closes(self) -> bool:
|
||||
"""True only when the PR *declares* it closes the issue."""
|
||||
return EVIDENCE_CLOSES in self.evidence
|
||||
|
||||
def to_dict(self) -> dict[str, Any]:
|
||||
return {
|
||||
"issue_number": self.issue_number,
|
||||
"evidence": list(self.evidence),
|
||||
"closes": self.closes,
|
||||
}
|
||||
|
||||
|
||||
def _sorted_links(links: Iterable[IssueLink]) -> tuple[IssueLink, ...]:
|
||||
return tuple(sorted(links, key=lambda link: (link.strength, link.issue_number)))
|
||||
|
||||
|
||||
def resolve_pr_links(pr: dict[str, Any]) -> tuple[IssueLink, ...]:
|
||||
"""Resolve every issue a PR points at, strongest evidence first.
|
||||
|
||||
Every candidate is kept. Collapsing to a single "linked issue" is what makes
|
||||
a mislinked or double-claimed PR invisible, so the caller decides what to do
|
||||
with several candidates rather than being handed one guess.
|
||||
"""
|
||||
found: dict[int, set[str]] = {}
|
||||
|
||||
def _add(number: Any, evidence: str) -> None:
|
||||
try:
|
||||
issue_number = int(number)
|
||||
except (TypeError, ValueError):
|
||||
return
|
||||
if issue_number <= 0:
|
||||
return
|
||||
found.setdefault(issue_number, set()).add(evidence)
|
||||
|
||||
title = str(pr.get("title") or "")
|
||||
body = str(pr.get("body") or "")
|
||||
for text in (title, body):
|
||||
for match in _CLOSES_RE.finditer(text):
|
||||
_add(match.group(1), EVIDENCE_CLOSES)
|
||||
|
||||
head_ref = str((pr.get("head") or {}).get("ref") or "")
|
||||
branch_match = _BRANCH_MARKER_RE.match(head_ref.strip())
|
||||
if branch_match:
|
||||
_add(branch_match.group(1), EVIDENCE_BRANCH)
|
||||
|
||||
# The ``#N`` inside "Closes #N" is the *same* textual occurrence as the
|
||||
# closing keyword, not a second, independent mention. Blanking the closing
|
||||
# phrases first keeps "mention" meaning what the legend says it means: a
|
||||
# reference the PR made without claiming to close anything.
|
||||
for match in _REFERENCE_RE.finditer(_CLOSES_RE.sub(" ", body)):
|
||||
_add(match.group(1), EVIDENCE_REFERENCE)
|
||||
|
||||
# A PR's own number appearing in its body is self-reference, not linkage.
|
||||
try:
|
||||
found.pop(int(pr.get("number")), None)
|
||||
except (TypeError, ValueError):
|
||||
pass
|
||||
|
||||
return _sorted_links(
|
||||
IssueLink(
|
||||
issue_number=number,
|
||||
evidence=tuple(name for name in EVIDENCE_ORDER if name in evidence),
|
||||
)
|
||||
for number, evidence in found.items()
|
||||
)
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class LinkageIndex:
|
||||
"""Resolved linkage over one loaded window of issues and PRs."""
|
||||
|
||||
pr_links: dict[int, tuple[IssueLink, ...]]
|
||||
issue_prs: dict[int, tuple[int, ...]]
|
||||
|
||||
def primary_issue(self, pr_number: int) -> IssueLink | None:
|
||||
"""The strongest edge for a PR, or None when it points at no issue."""
|
||||
links = self.pr_links.get(int(pr_number)) or ()
|
||||
return links[0] if links else None
|
||||
|
||||
def ambiguous(self, pr_number: int) -> bool:
|
||||
"""True when two or more issues tie at the PR's strongest evidence."""
|
||||
links = self.pr_links.get(int(pr_number)) or ()
|
||||
if len(links) < 2:
|
||||
return False
|
||||
best = links[0].strength
|
||||
return sum(1 for link in links if link.strength == best) > 1
|
||||
|
||||
def contested_issues(self) -> tuple[int, ...]:
|
||||
"""Issues claimed by more than one PR in the loaded window."""
|
||||
return tuple(
|
||||
number for number, prs in sorted(self.issue_prs.items()) if len(prs) > 1
|
||||
)
|
||||
|
||||
|
||||
def resolve_linkage(prs: Sequence[dict[str, Any]]) -> LinkageIndex:
|
||||
"""Build the bidirectional linkage index for a loaded window of PRs.
|
||||
|
||||
Only *closing* and *branch-marker* edges populate the issue→PR direction: a
|
||||
bare ``#N`` mention is a reference, and treating it as "this PR is the work
|
||||
for issue N" would invent contested issues out of ordinary cross-links. The
|
||||
weaker edge stays visible on the PR→issue side, where it is labelled.
|
||||
"""
|
||||
pr_links: dict[int, tuple[IssueLink, ...]] = {}
|
||||
issue_prs: dict[int, list[int]] = {}
|
||||
for pr in prs or []:
|
||||
try:
|
||||
pr_number = int(pr["number"])
|
||||
except (KeyError, TypeError, ValueError):
|
||||
continue
|
||||
links = resolve_pr_links(pr)
|
||||
pr_links[pr_number] = links
|
||||
for link in links:
|
||||
if link.evidence == (EVIDENCE_REFERENCE,):
|
||||
continue
|
||||
bucket = issue_prs.setdefault(link.issue_number, [])
|
||||
if pr_number not in bucket:
|
||||
bucket.append(pr_number)
|
||||
return LinkageIndex(
|
||||
pr_links=pr_links,
|
||||
issue_prs={number: tuple(sorted(items)) for number, items in issue_prs.items()},
|
||||
)
|
||||
|
||||
|
||||
# --- Canonical handoff summary ----------------------------------------------
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class HandoffSummary:
|
||||
"""The latest CTH comment on one thread, redacted for display."""
|
||||
|
||||
comment_id: int | None
|
||||
created_at: str | None
|
||||
author: str | None
|
||||
cth_type: str
|
||||
cth_type_known: bool
|
||||
status: str | None
|
||||
next_owner: str | None
|
||||
current_blocker: str | None
|
||||
decision: str | None
|
||||
next_action: str | None
|
||||
|
||||
def to_dict(self) -> dict[str, Any]:
|
||||
return {
|
||||
"comment_id": self.comment_id,
|
||||
"created_at": self.created_at,
|
||||
"author": self.author,
|
||||
"cth_type": self.cth_type,
|
||||
"cth_type_known": self.cth_type_known,
|
||||
"status": self.status,
|
||||
"next_owner": self.next_owner,
|
||||
"current_blocker": self.current_blocker,
|
||||
"decision": self.decision,
|
||||
"next_action": self.next_action,
|
||||
}
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class HandoffStatus:
|
||||
"""Why a thread's handoff summary is present, absent, or unknown."""
|
||||
|
||||
state: str
|
||||
reason: str | None = None
|
||||
target: str | None = None
|
||||
|
||||
@property
|
||||
def loaded(self) -> bool:
|
||||
return self.state == HANDOFF_LOADED
|
||||
|
||||
def to_dict(self) -> dict[str, Any]:
|
||||
return {"state": self.state, "reason": self.reason, "target": self.target}
|
||||
|
||||
|
||||
def summarize_handoff(comments: Sequence[dict[str, Any]]) -> HandoffSummary | None:
|
||||
"""Summarize the newest CTH comment in *comments*, or None when there is none.
|
||||
|
||||
Every field is redacted before it is returned: a handoff body is operator
|
||||
free text that regularly quotes commands, and it is rendered verbatim on the
|
||||
page this feeds.
|
||||
"""
|
||||
from canonical_thread_handoff import find_latest_cth, is_known_cth_type
|
||||
|
||||
try:
|
||||
latest = find_latest_cth(list(comments or []))
|
||||
except Exception:
|
||||
return None
|
||||
if not latest:
|
||||
return None
|
||||
fields = latest.get("fields") or {}
|
||||
cth_type = str(latest.get("cth_type") or "").strip()
|
||||
known = is_known_cth_type(cth_type)
|
||||
try:
|
||||
comment_id: int | None = int(latest.get("comment_id"))
|
||||
except (TypeError, ValueError):
|
||||
comment_id = None
|
||||
return HandoffSummary(
|
||||
comment_id=comment_id,
|
||||
created_at=_redact(latest.get("created_at")),
|
||||
author=_redact(latest.get("author")),
|
||||
# An unrecognised heading is reported as such rather than republished:
|
||||
# the heading is free text, and CTH_TYPES is the only authority for what
|
||||
# a handoff type may be.
|
||||
cth_type=cth_type if known else "unrecognized",
|
||||
cth_type_known=known,
|
||||
status=_redact(fields.get("status")),
|
||||
next_owner=_redact(fields.get("next owner")),
|
||||
current_blocker=_redact(fields.get("current blocker")),
|
||||
decision=_redact(fields.get("decision")),
|
||||
next_action=_redact(fields.get("next action")),
|
||||
)
|
||||
|
||||
|
||||
CommentSource = Callable[[str, int], list[dict[str, Any]]]
|
||||
|
||||
|
||||
def build_comment_source(host: str, org: str, repo: str) -> CommentSource | None:
|
||||
"""Build an authenticated ``(kind, number) -> comments`` fetcher, or None.
|
||||
|
||||
Returns None when the console is running in offline test mode or when no
|
||||
credential is available for *host*, so the caller reports the handoff source
|
||||
as unavailable instead of as an empty thread.
|
||||
"""
|
||||
if _offline_test_mode() or not (host and org and repo):
|
||||
return None
|
||||
auth = get_auth_header(host)
|
||||
if not auth:
|
||||
return None
|
||||
|
||||
def _fetch(kind: str, number: int) -> list[dict[str, Any]]:
|
||||
segment = "pulls" if kind == "pr" else "issues"
|
||||
url = f"{repo_api_url(host, org, repo)}/{segment}/{int(number)}/comments"
|
||||
comments: list[dict[str, Any]] = []
|
||||
page = 1
|
||||
while page <= 20:
|
||||
raw, meta = api_fetch_page(url, auth, page=page, limit=50)
|
||||
comments.extend(raw)
|
||||
if bool(meta["is_final_page"]):
|
||||
break
|
||||
page += 1
|
||||
return comments
|
||||
|
||||
return _fetch
|
||||
|
||||
|
||||
# --- Snapshot ----------------------------------------------------------------
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class LinkageNode:
|
||||
"""One issue or PR row with its resolved links and display metadata."""
|
||||
|
||||
kind: str
|
||||
number: int
|
||||
title: str
|
||||
state: str
|
||||
labels: tuple[str, ...] = ()
|
||||
links: tuple[IssueLink, ...] = ()
|
||||
linked_prs: tuple[int, ...] = ()
|
||||
ambiguous: bool = False
|
||||
contested: bool = False
|
||||
deep_link: str | None = None
|
||||
handoff: HandoffSummary | None = None
|
||||
handoff_status: HandoffStatus = HandoffStatus(HANDOFF_NOT_LOADED)
|
||||
links_authoritative: bool = True
|
||||
|
||||
def to_dict(self) -> dict[str, Any]:
|
||||
return {
|
||||
"kind": self.kind,
|
||||
"number": self.number,
|
||||
"title": self.title,
|
||||
"state": self.state,
|
||||
"labels": list(self.labels),
|
||||
"links": [link.to_dict() for link in self.links],
|
||||
"linked_prs": list(self.linked_prs),
|
||||
"ambiguous": self.ambiguous,
|
||||
"contested": self.contested,
|
||||
"deep_link": self.deep_link,
|
||||
"links_authoritative": self.links_authoritative,
|
||||
"handoff": self.handoff.to_dict() if self.handoff else None,
|
||||
"handoff_status": self.handoff_status.to_dict(),
|
||||
}
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class LinkageSnapshot:
|
||||
"""One answered linkage query over a scoped window of a Gitea repo."""
|
||||
|
||||
ok: bool
|
||||
project_id: str
|
||||
repo_label: str
|
||||
host: str
|
||||
state_scope: str
|
||||
issues: tuple[LinkageNode, ...] = ()
|
||||
prs: tuple[LinkageNode, ...] = ()
|
||||
contested_issues: tuple[int, ...] = ()
|
||||
focus: tuple[str, int] | None = None
|
||||
inventory_complete: bool = False
|
||||
deep_links_enabled: bool = False
|
||||
handoff_status: HandoffStatus = HandoffStatus(HANDOFF_NOT_LOADED)
|
||||
fetch_error: str | None = None
|
||||
|
||||
@property
|
||||
def orphan_prs(self) -> tuple[LinkageNode, ...]:
|
||||
"""PRs in the loaded window that point at no issue at all."""
|
||||
return tuple(node for node in self.prs if not node.links)
|
||||
|
||||
def to_dict(self) -> dict[str, Any]:
|
||||
return {
|
||||
"ok": self.ok,
|
||||
"schema_version": LINKAGE_SCHEMA_VERSION,
|
||||
"project_id": self.project_id,
|
||||
"repo": self.repo_label,
|
||||
"state_scope": self.state_scope,
|
||||
"inventory_complete": self.inventory_complete,
|
||||
"deep_links_enabled": self.deep_links_enabled,
|
||||
"focus": (
|
||||
None
|
||||
if self.focus is None
|
||||
else {"kind": self.focus[0], "number": self.focus[1]}
|
||||
),
|
||||
"handoff_source": self.handoff_status.to_dict(),
|
||||
"fetch_error": self.fetch_error,
|
||||
"contested_issues": list(self.contested_issues),
|
||||
"issues": [node.to_dict() for node in self.issues],
|
||||
"prs": [node.to_dict() for node in self.prs],
|
||||
"evidence_kinds": [
|
||||
{"name": name, "description": EVIDENCE_DESCRIPTIONS[name]}
|
||||
for name in EVIDENCE_ORDER
|
||||
],
|
||||
}
|
||||
|
||||
|
||||
def snapshot_to_dict(snapshot: LinkageSnapshot) -> dict[str, Any]:
|
||||
"""JSON-serializable export for ``/api/v1/gitea/linkage``."""
|
||||
return snapshot.to_dict()
|
||||
|
||||
|
||||
def _offline_test_mode() -> bool:
|
||||
return (os.environ.get("WEBUI_TEST_OFFLINE") or "").strip().lower() in {
|
||||
"1",
|
||||
"true",
|
||||
"yes",
|
||||
}
|
||||
|
||||
|
||||
def _labels_of(item: dict[str, Any]) -> tuple[str, ...]:
|
||||
return tuple(
|
||||
str(_redact(label.get("name")))
|
||||
for label in (item.get("labels") or [])
|
||||
if label.get("name")
|
||||
)
|
||||
|
||||
|
||||
def _failed_snapshot(
|
||||
*,
|
||||
project_id: str,
|
||||
repo_label: str,
|
||||
host: str,
|
||||
state_scope: str,
|
||||
reason: str,
|
||||
) -> LinkageSnapshot:
|
||||
"""A read that could not be answered. Never an empty-and-healthy snapshot."""
|
||||
return LinkageSnapshot(
|
||||
ok=False,
|
||||
project_id=project_id,
|
||||
repo_label=repo_label,
|
||||
host=host,
|
||||
state_scope=state_scope,
|
||||
inventory_complete=False,
|
||||
deep_links_enabled=deep_links_enabled(),
|
||||
handoff_status=HandoffStatus(
|
||||
HANDOFF_UNAVAILABLE, reason="linkage inventory could not be loaded"
|
||||
),
|
||||
fetch_error=str(_redact(reason)),
|
||||
)
|
||||
|
||||
|
||||
def _resolve_project(project_id: str | None) -> ProjectRecord | None:
|
||||
registry = load_registry()
|
||||
if project_id:
|
||||
for entry in registry.projects:
|
||||
if entry.id == project_id:
|
||||
return entry
|
||||
return None
|
||||
return registry.projects[0] if registry.projects else None
|
||||
|
||||
|
||||
def _normalize_state(state: str | None) -> str:
|
||||
text = (state or STATE_OPEN).strip().lower()
|
||||
return text if text in _SUPPORTED_STATES else STATE_OPEN
|
||||
|
||||
|
||||
def load_linkage_snapshot(
|
||||
project_id: str | None = None,
|
||||
*,
|
||||
state: str | None = None,
|
||||
issue: int | None = None,
|
||||
pr: int | None = None,
|
||||
fetch_prs: Callable[..., tuple[list[dict], PaginationMeta]] | None = None,
|
||||
fetch_issues: Callable[..., tuple[list[dict], PaginationMeta]] | None = None,
|
||||
comment_source: CommentSource | None = None,
|
||||
) -> LinkageSnapshot:
|
||||
"""Load issue↔PR linkage for a registry project.
|
||||
|
||||
``issue``/``pr`` focus one thread: the focused row is the only one whose
|
||||
Canonical Thread Handoff comments are fetched, because handoff comments are
|
||||
thread-scoped and loading them for a whole queue would be one request per
|
||||
row. Every unfocused row reports its handoff as ``not_loaded``.
|
||||
"""
|
||||
state_scope = _normalize_state(state)
|
||||
try:
|
||||
project = _resolve_project(project_id)
|
||||
except Exception as exc: # registry invalid — fail closed with the reason
|
||||
return _failed_snapshot(
|
||||
project_id=project_id or "",
|
||||
repo_label="",
|
||||
host="",
|
||||
state_scope=state_scope,
|
||||
reason=f"project registry unavailable: {exc}",
|
||||
)
|
||||
|
||||
if project is None:
|
||||
return _failed_snapshot(
|
||||
project_id=project_id or "",
|
||||
repo_label="",
|
||||
host="",
|
||||
state_scope=state_scope,
|
||||
reason=(
|
||||
f"project {project_id!r} not found in registry"
|
||||
if project_id
|
||||
else "no projects registered"
|
||||
),
|
||||
)
|
||||
|
||||
host = _host_from_url(project.remote_host)
|
||||
repo_label = f"{project.gitea_owner}/{project.repo_name}"
|
||||
offline_test = _offline_test_mode()
|
||||
|
||||
def _empty_fetch(*_args, **_kwargs):
|
||||
return [], PaginationMeta(
|
||||
page=1,
|
||||
per_page=50,
|
||||
returned_count=0,
|
||||
has_more=False,
|
||||
is_final_page=True,
|
||||
# An offline stub loaded nothing; claiming a complete inventory here
|
||||
# would let the page assert that no issue has a linked PR.
|
||||
inventory_complete=False,
|
||||
pages_fetched=0,
|
||||
)
|
||||
|
||||
pr_fetch = fetch_prs or (_empty_fetch if offline_test else _fetch_prs)
|
||||
issue_fetch = fetch_issues or (_empty_fetch if offline_test else _fetch_issues)
|
||||
using_live_fetch = not offline_test and (fetch_prs is None or fetch_issues is None)
|
||||
auth = get_auth_header(host) if using_live_fetch else "test-auth"
|
||||
if using_live_fetch and not auth:
|
||||
return _failed_snapshot(
|
||||
project_id=project.id,
|
||||
repo_label=repo_label,
|
||||
host=host,
|
||||
state_scope=state_scope,
|
||||
reason=(
|
||||
f"Gitea credentials unavailable for {host}; linkage cannot be "
|
||||
"loaded (fail closed — not rendering an empty linkage table)"
|
||||
),
|
||||
)
|
||||
|
||||
try:
|
||||
raw_prs, pr_pagination = pr_fetch(
|
||||
host, project.gitea_owner, project.repo_name, auth, state=state_scope
|
||||
)
|
||||
raw_issues, issue_pagination = issue_fetch(
|
||||
host, project.gitea_owner, project.repo_name, auth, state=state_scope
|
||||
)
|
||||
except Exception as exc: # noqa: BLE001 — operator-visible fetch failure
|
||||
return _failed_snapshot(
|
||||
project_id=project.id,
|
||||
repo_label=repo_label,
|
||||
host=host,
|
||||
state_scope=state_scope,
|
||||
reason=f"Gitea fetch failed: {exc}",
|
||||
)
|
||||
|
||||
inventory_complete = bool(
|
||||
getattr(pr_pagination, "inventory_complete", False)
|
||||
and getattr(issue_pagination, "inventory_complete", False)
|
||||
)
|
||||
|
||||
index = resolve_linkage(raw_prs)
|
||||
contested = index.contested_issues()
|
||||
|
||||
focus: tuple[str, int] | None = None
|
||||
if pr is not None:
|
||||
focus = ("pr", int(pr))
|
||||
elif issue is not None:
|
||||
focus = ("issue", int(issue))
|
||||
|
||||
unfocused_reason = (
|
||||
"canonical handoff comments are thread-scoped; focus one issue or PR "
|
||||
"to load its latest handoff"
|
||||
)
|
||||
handoff_status = HandoffStatus(HANDOFF_NOT_LOADED, reason=unfocused_reason)
|
||||
focus_handoff: HandoffSummary | None = None
|
||||
if focus is not None:
|
||||
source = comment_source
|
||||
if source is None and not offline_test:
|
||||
source = build_comment_source(host, project.gitea_owner, project.repo_name)
|
||||
target = f"{focus[0]}#{focus[1]}"
|
||||
if source is None:
|
||||
handoff_status = HandoffStatus(
|
||||
HANDOFF_UNAVAILABLE,
|
||||
reason="no authenticated comment source available for this read",
|
||||
target=target,
|
||||
)
|
||||
else:
|
||||
try:
|
||||
focus_handoff = summarize_handoff(source(focus[0], focus[1]) or [])
|
||||
handoff_status = HandoffStatus(HANDOFF_LOADED, target=target)
|
||||
except Exception as exc: # fail soft: degrade this source only
|
||||
handoff_status = HandoffStatus(
|
||||
HANDOFF_UNAVAILABLE,
|
||||
reason=str(_redact(f"handoff fetch failed: {exc}")),
|
||||
target=target,
|
||||
)
|
||||
|
||||
def _node_handoff(
|
||||
kind: str, number: int
|
||||
) -> tuple[HandoffSummary | None, HandoffStatus]:
|
||||
"""Attach the handoff only to the focused row; qualify every other row."""
|
||||
if focus == (kind, number):
|
||||
return (focus_handoff, handoff_status)
|
||||
return (
|
||||
None,
|
||||
HandoffStatus(
|
||||
HANDOFF_NOT_LOADED,
|
||||
reason=unfocused_reason if focus is None else "not the focused thread",
|
||||
),
|
||||
)
|
||||
|
||||
def _number_of(raw: dict[str, Any]) -> int | None:
|
||||
try:
|
||||
return int(raw["number"])
|
||||
except (KeyError, TypeError, ValueError):
|
||||
return None
|
||||
|
||||
def _sort_key(raw: dict[str, Any]) -> int:
|
||||
number = _number_of(raw)
|
||||
return -1 if number is None else number
|
||||
|
||||
issue_nodes: list[LinkageNode] = []
|
||||
for raw in sorted(raw_issues or [], key=_sort_key, reverse=True):
|
||||
number = _number_of(raw)
|
||||
if number is None:
|
||||
continue
|
||||
node_handoff, node_status = _node_handoff("issue", number)
|
||||
linked_prs = index.issue_prs.get(number, ())
|
||||
issue_nodes.append(
|
||||
LinkageNode(
|
||||
kind="issue",
|
||||
number=number,
|
||||
title=str(_redact(raw.get("title")) or ""),
|
||||
state=str(raw.get("state") or ""),
|
||||
labels=_labels_of(raw),
|
||||
linked_prs=linked_prs,
|
||||
contested=len(linked_prs) > 1,
|
||||
deep_link=_deep_link(
|
||||
host, project.gitea_owner, project.repo_name, "issue", number
|
||||
),
|
||||
handoff=node_handoff,
|
||||
handoff_status=node_status,
|
||||
links_authoritative=inventory_complete,
|
||||
)
|
||||
)
|
||||
|
||||
pr_nodes: list[LinkageNode] = []
|
||||
for raw in sorted(raw_prs or [], key=_sort_key, reverse=True):
|
||||
number = _number_of(raw)
|
||||
if number is None:
|
||||
continue
|
||||
node_handoff, node_status = _node_handoff("pr", number)
|
||||
links = index.pr_links.get(number, ())
|
||||
pr_nodes.append(
|
||||
LinkageNode(
|
||||
kind="pr",
|
||||
number=number,
|
||||
title=str(_redact(raw.get("title")) or ""),
|
||||
state=str(raw.get("state") or ""),
|
||||
labels=_labels_of(raw),
|
||||
links=links,
|
||||
ambiguous=index.ambiguous(number),
|
||||
contested=any(link.issue_number in contested for link in links),
|
||||
deep_link=_deep_link(
|
||||
host, project.gitea_owner, project.repo_name, "pr", number
|
||||
),
|
||||
handoff=node_handoff,
|
||||
handoff_status=node_status,
|
||||
links_authoritative=inventory_complete,
|
||||
)
|
||||
)
|
||||
|
||||
return LinkageSnapshot(
|
||||
ok=True,
|
||||
project_id=project.id,
|
||||
repo_label=repo_label,
|
||||
host=host,
|
||||
state_scope=state_scope,
|
||||
issues=tuple(issue_nodes),
|
||||
prs=tuple(pr_nodes),
|
||||
contested_issues=contested,
|
||||
focus=focus,
|
||||
inventory_complete=inventory_complete,
|
||||
deep_links_enabled=deep_links_enabled(),
|
||||
handoff_status=handoff_status,
|
||||
)
|
||||
@@ -0,0 +1,364 @@
|
||||
"""HTML views for the Gitea issue↔PR linkage console (#645, Phase 3).
|
||||
|
||||
Read-only renderer over :mod:`webui.linkage_loader`. The page's job is to make
|
||||
three things impossible to misread:
|
||||
|
||||
* **why** an edge exists — every link carries its evidence badge, so a bare
|
||||
``#N`` mention never looks like a closing claim;
|
||||
* **what was not loaded** — a partial inventory, an unfocused thread, or an
|
||||
unavailable handoff source renders as an explicit qualifier, never as an
|
||||
affirmative "none";
|
||||
* **that nothing here mutates** — there is no review, merge, or edit control,
|
||||
and the deep link out to Gitea appears only under the admin reveal opt-in.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
from html import escape
|
||||
from typing import Sequence
|
||||
|
||||
from webui.layout import render_page
|
||||
from webui.linkage_loader import (
|
||||
EVIDENCE_BRANCH,
|
||||
EVIDENCE_CLOSES,
|
||||
EVIDENCE_DESCRIPTIONS,
|
||||
EVIDENCE_ORDER,
|
||||
EVIDENCE_REFERENCE,
|
||||
HANDOFF_LOADED,
|
||||
HANDOFF_NOT_LOADED,
|
||||
HandoffSummary,
|
||||
LinkageNode,
|
||||
LinkageSnapshot,
|
||||
)
|
||||
|
||||
_EVIDENCE_CSS = {
|
||||
EVIDENCE_CLOSES: "badge-health-ok",
|
||||
EVIDENCE_BRANCH: "badge-health-skipped",
|
||||
EVIDENCE_REFERENCE: "badge-health-unproven",
|
||||
}
|
||||
|
||||
_EVIDENCE_LABEL = {
|
||||
EVIDENCE_CLOSES: "closes",
|
||||
EVIDENCE_BRANCH: "branch",
|
||||
EVIDENCE_REFERENCE: "mention",
|
||||
}
|
||||
|
||||
|
||||
def _badge(text: str, css: str) -> str:
|
||||
return f'<span class="badge {css}">{escape(text)}</span>'
|
||||
|
||||
|
||||
def _labels(names: Sequence[str]) -> str:
|
||||
if not names:
|
||||
return '<span class="muted">—</span>'
|
||||
return " ".join(_badge(name, "badge-health-skipped") for name in names)
|
||||
|
||||
|
||||
def _ref(node: LinkageNode) -> str:
|
||||
"""Render an item reference, hyperlinked only when deep links are revealed."""
|
||||
label = f"#{node.number}"
|
||||
if node.deep_link:
|
||||
return f'<a href="{escape(node.deep_link)}"><code>{escape(label)}</code></a>'
|
||||
return f"<code>{escape(label)}</code>"
|
||||
|
||||
|
||||
def _scope_card(snapshot: LinkageSnapshot) -> str:
|
||||
focus = (
|
||||
"none"
|
||||
if snapshot.focus is None
|
||||
else f"{snapshot.focus[0]}#{snapshot.focus[1]}"
|
||||
)
|
||||
completeness = (
|
||||
_badge("complete", "badge-health-ok")
|
||||
if snapshot.inventory_complete
|
||||
else _badge("partial", "badge-health-degraded")
|
||||
)
|
||||
links_note = (
|
||||
"Every linkage edge below is a claim about this loaded window only."
|
||||
if snapshot.inventory_complete
|
||||
else (
|
||||
"Pagination did not complete for this window, so an empty link list "
|
||||
"means <em>none found in what was loaded</em> — not that no link exists."
|
||||
)
|
||||
)
|
||||
deep_links = (
|
||||
_badge("enabled", "badge-health-ok")
|
||||
if snapshot.deep_links_enabled
|
||||
else _badge("hidden", "badge-health-skipped")
|
||||
)
|
||||
return f"""<div class="health-card">
|
||||
<h3>Scope</h3>
|
||||
<table class="detail">
|
||||
<tr><th>Project</th><td><code>{escape(snapshot.project_id or "—")}</code></td></tr>
|
||||
<tr><th>Repository</th><td><code>{escape(snapshot.repo_label or "—")}</code></td></tr>
|
||||
<tr><th>Item state</th><td><code>{escape(snapshot.state_scope)}</code></td></tr>
|
||||
<tr><th>Focused thread</th><td><code>{escape(focus)}</code></td></tr>
|
||||
<tr><th>Inventory</th><td>{completeness}</td></tr>
|
||||
<tr><th>Gitea deep links</th><td>{deep_links}</td></tr>
|
||||
</table>
|
||||
<p class="muted">{links_note}</p>
|
||||
</div>"""
|
||||
|
||||
|
||||
def _error_card(snapshot: LinkageSnapshot) -> str:
|
||||
if snapshot.ok and not snapshot.fetch_error:
|
||||
return ""
|
||||
return (
|
||||
'<div class="health-card health-stale"><strong>Linkage unavailable:</strong> '
|
||||
f"{escape(snapshot.fetch_error or 'the linkage read did not complete')}. "
|
||||
"No linkage table is rendered: an empty table would read as "
|
||||
"<em>no issue is linked to any PR</em>, which this read cannot claim."
|
||||
"</div>"
|
||||
)
|
||||
|
||||
|
||||
def _contested_card(snapshot: LinkageSnapshot) -> str:
|
||||
if not snapshot.contested_issues:
|
||||
return ""
|
||||
refs = ", ".join(f"<code>#{number}</code>" for number in snapshot.contested_issues)
|
||||
return (
|
||||
'<div class="health-card health-stale">'
|
||||
f"<strong>Contested issues:</strong> {refs}. More than one PR in this "
|
||||
"window claims each of these — duplicate work or a superseded PR. "
|
||||
"Resolution stays in Gitea and the workflow; this console only reports it."
|
||||
"</div>"
|
||||
)
|
||||
|
||||
|
||||
def _evidence_badges(evidence: Sequence[str]) -> str:
|
||||
return " ".join(
|
||||
_badge(
|
||||
_EVIDENCE_LABEL.get(name, name),
|
||||
_EVIDENCE_CSS.get(name, "badge-health-skipped"),
|
||||
)
|
||||
for name in EVIDENCE_ORDER
|
||||
if name in evidence
|
||||
)
|
||||
|
||||
|
||||
def _handoff_inline(handoff: HandoffSummary) -> str:
|
||||
type_css = "badge-health-ok" if handoff.cth_type_known else "badge-health-degraded"
|
||||
return (
|
||||
f'{_badge(handoff.cth_type or "—", type_css)}'
|
||||
f'<div class="muted" style="font-size:0.82rem;">'
|
||||
f'{escape(handoff.status or "—")} → {escape(handoff.next_owner or "—")}</div>'
|
||||
)
|
||||
|
||||
|
||||
def _handoff_cell(node: LinkageNode) -> str:
|
||||
"""Render the handoff column, distinguishing 'none found' from 'not loaded'."""
|
||||
status = node.handoff_status
|
||||
if status.state == HANDOFF_LOADED:
|
||||
if node.handoff is None:
|
||||
return '<span class="muted">no canonical handoff on this thread</span>'
|
||||
return _handoff_inline(node.handoff)
|
||||
if status.state == HANDOFF_NOT_LOADED:
|
||||
return (
|
||||
f'{_badge("not loaded", "badge-health-skipped")}'
|
||||
f'<div class="muted" style="font-size:0.82rem;">'
|
||||
f'{escape(status.reason or "")}</div>'
|
||||
)
|
||||
return (
|
||||
f'{_badge("unavailable", "badge-health-degraded")}'
|
||||
f'<div class="muted" style="font-size:0.82rem;">'
|
||||
f'{escape(status.reason or "")}</div>'
|
||||
)
|
||||
|
||||
|
||||
def _issue_rows(snapshot: LinkageSnapshot) -> str:
|
||||
rows = []
|
||||
for node in snapshot.issues:
|
||||
if node.linked_prs:
|
||||
linked = ", ".join(f"<code>#{number}</code>" for number in node.linked_prs)
|
||||
if node.contested:
|
||||
linked += " " + _badge("contested", "badge-blocked")
|
||||
elif node.links_authoritative:
|
||||
linked = '<span class="muted">none</span>'
|
||||
else:
|
||||
# The distinction an operator needs: nothing found in a window that
|
||||
# was not fully loaded is not the same as nothing existing.
|
||||
linked = '<span class="muted">none found (partial inventory)</span>'
|
||||
rows.append(
|
||||
"<tr>"
|
||||
f"<td>{_ref(node)}</td>"
|
||||
f"<td>{escape(node.title)}</td>"
|
||||
f"<td>{escape(node.state or '—')}</td>"
|
||||
f"<td>{_labels(node.labels)}</td>"
|
||||
f"<td>{linked}</td>"
|
||||
f"<td>{_handoff_cell(node)}</td>"
|
||||
"</tr>"
|
||||
)
|
||||
if not rows:
|
||||
return '<tr><td colspan="6" class="muted">No issues in the loaded window.</td></tr>'
|
||||
return "".join(rows)
|
||||
|
||||
|
||||
def _pr_rows(snapshot: LinkageSnapshot) -> str:
|
||||
rows = []
|
||||
for node in snapshot.prs:
|
||||
if node.links:
|
||||
linked = "".join(
|
||||
f"<div><code>#{link.issue_number}</code> "
|
||||
f"{_evidence_badges(link.evidence)}</div>"
|
||||
for link in node.links
|
||||
)
|
||||
if node.ambiguous:
|
||||
linked += _badge("ambiguous", "badge-blocked")
|
||||
if node.contested:
|
||||
linked += " " + _badge("contested", "badge-blocked")
|
||||
elif node.links_authoritative:
|
||||
linked = '<span class="muted">no issue reference</span>'
|
||||
else:
|
||||
linked = '<span class="muted">none found (partial inventory)</span>'
|
||||
rows.append(
|
||||
"<tr>"
|
||||
f"<td>{_ref(node)}</td>"
|
||||
f"<td>{escape(node.title)}</td>"
|
||||
f"<td>{escape(node.state or '—')}</td>"
|
||||
f"<td>{_labels(node.labels)}</td>"
|
||||
f"<td>{linked}</td>"
|
||||
f"<td>{_handoff_cell(node)}</td>"
|
||||
"</tr>"
|
||||
)
|
||||
if not rows:
|
||||
return (
|
||||
'<tr><td colspan="6" class="muted">No pull requests in the loaded '
|
||||
"window.</td></tr>"
|
||||
)
|
||||
return "".join(rows)
|
||||
|
||||
|
||||
def _focus_card(snapshot: LinkageSnapshot) -> str:
|
||||
"""Render the focused thread's latest canonical handoff, when one was loaded."""
|
||||
if snapshot.focus is None:
|
||||
return f"""<div class="prompt-card">
|
||||
<h3>Canonical handoff</h3>
|
||||
<p class="muted">{escape(snapshot.handoff_status.reason or "")}
|
||||
Add <code>?issue=N</code> or <code>?pr=N</code> to load the latest
|
||||
Canonical Thread Handoff for one thread.</p>
|
||||
</div>"""
|
||||
|
||||
kind, number = snapshot.focus
|
||||
target = f"{kind} #{number}"
|
||||
if not snapshot.handoff_status.loaded:
|
||||
return f"""<div class="prompt-card">
|
||||
<h3>Canonical handoff — {escape(target)}</h3>
|
||||
<p class="muted">{_badge("unavailable", "badge-health-degraded")}
|
||||
{escape(snapshot.handoff_status.reason or "handoff source did not run")}.
|
||||
This is not evidence that the thread carries no handoff.</p>
|
||||
</div>"""
|
||||
|
||||
handoff = next(
|
||||
(
|
||||
node.handoff
|
||||
for node in (snapshot.issues + snapshot.prs)
|
||||
if node.kind == kind and node.number == number and node.handoff
|
||||
),
|
||||
None,
|
||||
)
|
||||
if handoff is None:
|
||||
return f"""<div class="prompt-card">
|
||||
<h3>Canonical handoff — {escape(target)}</h3>
|
||||
<p class="muted">Comments loaded; no Canonical Thread Handoff comment found on
|
||||
this thread.</p>
|
||||
</div>"""
|
||||
|
||||
type_css = "badge-health-ok" if handoff.cth_type_known else "badge-health-degraded"
|
||||
unknown_note = (
|
||||
""
|
||||
if handoff.cth_type_known
|
||||
else (
|
||||
'<p class="muted">The comment\'s heading is not a declared CTH type, '
|
||||
"so it is reported as unrecognized rather than republished.</p>"
|
||||
)
|
||||
)
|
||||
return f"""<div class="prompt-card">
|
||||
<h3>Canonical handoff — {escape(target)}</h3>
|
||||
<p class="meta">{_badge(handoff.cth_type or "—", type_css)}
|
||||
by <code>{escape(handoff.author or "unknown")}</code>
|
||||
at <code>{escape(handoff.created_at or "unknown")}</code></p>
|
||||
{unknown_note}
|
||||
<table class="detail">
|
||||
<tr><th>Status</th><td>{escape(handoff.status or "—")}</td></tr>
|
||||
<tr><th>Next owner</th><td>{escape(handoff.next_owner or "—")}</td></tr>
|
||||
<tr><th>Current blocker</th><td>{escape(handoff.current_blocker or "—")}</td></tr>
|
||||
<tr><th>Decision</th><td>{escape(handoff.decision or "—")}</td></tr>
|
||||
<tr><th>Next action</th><td>{escape(handoff.next_action or "—")}</td></tr>
|
||||
</table>
|
||||
<p class="muted">Full event history:
|
||||
<a href="/api/v1/timeline?{escape(kind)}={number}"><code>/api/v1/timeline</code></a></p>
|
||||
</div>"""
|
||||
|
||||
|
||||
def _legend_card(snapshot: LinkageSnapshot) -> str:
|
||||
items = "".join(
|
||||
f"<li>{_badge(_EVIDENCE_LABEL[name], _EVIDENCE_CSS[name])} — "
|
||||
f"{escape(EVIDENCE_DESCRIPTIONS[name])}</li>"
|
||||
for name in EVIDENCE_ORDER
|
||||
)
|
||||
reveal_note = (
|
||||
"Gitea deep links are shown because the "
|
||||
"<code>GITEA_MCP_REVEAL_ENDPOINTS</code> admin opt-in is set."
|
||||
if snapshot.deep_links_enabled
|
||||
else (
|
||||
"Gitea deep links are withheld. Set "
|
||||
"<code>GITEA_MCP_REVEAL_ENDPOINTS=1</code> server-side to reveal "
|
||||
"them; item numbers stay usable without them."
|
||||
)
|
||||
)
|
||||
return f"""<div class="prompt-card">
|
||||
<h3>How an edge was found</h3>
|
||||
<ul class="reasons">{items}</ul>
|
||||
<p class="muted">{reveal_note}</p>
|
||||
<p class="muted">Read-only surface: no issue or PR editing, no review, and no merge.
|
||||
JSON export: <a href="/api/v1/gitea/linkage"><code>/api/v1/gitea/linkage</code></a></p>
|
||||
</div>"""
|
||||
|
||||
|
||||
def render_linkage_page(snapshot: LinkageSnapshot) -> str:
|
||||
"""Render the full HTML page for the Gitea linkage console."""
|
||||
if not snapshot.ok:
|
||||
return render_page(
|
||||
title="Gitea linkage",
|
||||
body_html=f"""<h2>Gitea issue and PR linkage</h2>
|
||||
<p class="meta">Phase 3 read-only linkage console (#645).</p>
|
||||
{_error_card(snapshot)}
|
||||
{_scope_card(snapshot)}""",
|
||||
)
|
||||
|
||||
body = f"""<h2>Gitea issue and PR linkage</h2>
|
||||
<p class="meta">Phase 3 read-only linkage console (#645). Gitea remains the source of
|
||||
truth; this page reads it and never writes to it.</p>
|
||||
{_scope_card(snapshot)}
|
||||
{_contested_card(snapshot)}
|
||||
|
||||
<div class="prompt-card">
|
||||
<h3>Issues → pull requests</h3>
|
||||
<table class="registry">
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Issue</th><th>Title</th><th>State</th><th>Labels</th>
|
||||
<th>Linked PRs</th><th>Latest handoff</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>{_issue_rows(snapshot)}</tbody>
|
||||
</table>
|
||||
</div>
|
||||
|
||||
<div class="prompt-card">
|
||||
<h3>Pull requests → issues</h3>
|
||||
<table class="registry">
|
||||
<thead>
|
||||
<tr>
|
||||
<th>PR</th><th>Title</th><th>State</th><th>Labels</th>
|
||||
<th>Linked issues</th><th>Latest handoff</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>{_pr_rows(snapshot)}</tbody>
|
||||
</table>
|
||||
</div>
|
||||
|
||||
{_focus_card(snapshot)}
|
||||
{_legend_card(snapshot)}
|
||||
"""
|
||||
return render_page(title="Gitea linkage", body_html=body)
|
||||
+6
-7
@@ -6,7 +6,8 @@ destination is a GET view or a Phase 1 placeholder. No mutation links.
|
||||
|
||||
Nav groups follow the #631 Phase 1 information architecture: Health, Traffic,
|
||||
Runtime/Sessions, Projects, Inventory, Timeline, Policy (placeholder), and
|
||||
Insights (placeholder). Later-phase surfaces are declared as ``stub`` items and
|
||||
Insights (placeholder), joined by the Phase 3 Gitea linkage group (#645).
|
||||
Later-phase surfaces are declared as ``stub`` items and
|
||||
backed by ``STUB_PAGES`` so their nav links resolve to a graceful placeholder
|
||||
instead of a 404.
|
||||
"""
|
||||
@@ -48,7 +49,7 @@ NAV_GROUPS: tuple[NavGroup, ...] = (
|
||||
)),
|
||||
NavGroup("Runtime/Sessions", (
|
||||
NavItem("/runtime", "Runtime health"),
|
||||
NavItem("/sessions", "Sessions", "stub"),
|
||||
NavItem("/sessions", "Sessions"),
|
||||
)),
|
||||
NavGroup("Projects", (
|
||||
NavItem("/projects", "Projects"),
|
||||
@@ -60,6 +61,9 @@ NAV_GROUPS: tuple[NavGroup, ...] = (
|
||||
NavGroup("Timeline", (
|
||||
NavItem("/timeline", "Timeline", "stub"),
|
||||
)),
|
||||
NavGroup("Gitea", (
|
||||
NavItem("/gitea", "Issue/PR linkage"),
|
||||
)),
|
||||
NavGroup("Policy", (
|
||||
NavItem("/policy", "Policy", "stub"),
|
||||
NavItem("/prompts", "Prompts"),
|
||||
@@ -76,11 +80,6 @@ NAV_GROUPS: tuple[NavGroup, ...] = (
|
||||
# issues of epic #631. Each maps a path to (title, description). Routes are
|
||||
# registered so nav links resolve to a graceful, read-only stub page.
|
||||
STUB_PAGES: dict[str, tuple[str, str]] = {
|
||||
"/sessions": (
|
||||
"Sessions",
|
||||
"Active session, capability, and role inventory. Backed by the unified "
|
||||
"inventory API (#636) once it lands.",
|
||||
),
|
||||
"/inventory": (
|
||||
"Inventory",
|
||||
"Unified sessions, leases, locks, namespaces, and worktree inventory. "
|
||||
|
||||
+27
-2
@@ -211,6 +211,19 @@ def _pagination_from_pages(
|
||||
)
|
||||
|
||||
|
||||
_SUPPORTED_FETCH_STATES = ("open", "closed", "all")
|
||||
|
||||
|
||||
def _safe_state(state: str | None) -> str:
|
||||
"""Constrain a caller-supplied item state before it reaches a query string.
|
||||
|
||||
The value is interpolated into the Gitea URL, so an unrecognised state falls
|
||||
back to ``open`` rather than being passed through.
|
||||
"""
|
||||
text = (state or "open").strip().lower()
|
||||
return text if text in _SUPPORTED_FETCH_STATES else "open"
|
||||
|
||||
|
||||
def _fetch_prs(
|
||||
host: str,
|
||||
org: str,
|
||||
@@ -218,8 +231,15 @@ def _fetch_prs(
|
||||
auth: str,
|
||||
*,
|
||||
per_page: int = 50,
|
||||
state: str = "open",
|
||||
) -> tuple[list[dict], PaginationMeta]:
|
||||
url = f"{repo_api_url(host, org, repo)}/pulls?state=open"
|
||||
"""Fetch PRs in *state* (``open``, ``closed``, or ``all``).
|
||||
|
||||
The queue dashboard only ever wants the open window, so ``open`` stays the
|
||||
default. The linkage console (#645) widens it, because a landed issue↔PR
|
||||
edge lives on a merged PR.
|
||||
"""
|
||||
url = f"{repo_api_url(host, org, repo)}/pulls?state={_safe_state(state)}"
|
||||
all_raw: list[dict] = []
|
||||
pages_fetched = 0
|
||||
is_final = False
|
||||
@@ -248,8 +268,13 @@ def _fetch_issues(
|
||||
auth: str,
|
||||
*,
|
||||
per_page: int = 50,
|
||||
state: str = "open",
|
||||
) -> tuple[list[dict], PaginationMeta]:
|
||||
url = f"{repo_api_url(host, org, repo)}/issues?state=open&type=issues"
|
||||
"""Fetch issues in *state* (``open``, ``closed``, or ``all``); see :func:`_fetch_prs`."""
|
||||
url = (
|
||||
f"{repo_api_url(host, org, repo)}/issues"
|
||||
f"?state={_safe_state(state)}&type=issues"
|
||||
)
|
||||
all_raw: list[dict] = []
|
||||
page = 1
|
||||
pages_fetched = 0
|
||||
|
||||
@@ -88,5 +88,7 @@ def render_runtime_page(snapshot: RuntimeSnapshot) -> str:
|
||||
"<p class='muted'>MVP is read-only — restart MCP servers from your IDE/operator "
|
||||
"workflow. Related issue: <code>#420</code>. Guidance: "
|
||||
f"<code>{html.escape(snapshot.restart_guidance)}</code></p>"
|
||||
"<p class='muted'>This page does not expose tokens or perform MCP restarts.</p>"
|
||||
"<p class='muted'>This page does not expose tokens or perform MCP restarts. "
|
||||
"Correlated sessions, worktree bindings, and contamination markers: "
|
||||
"<a href='/sessions'>/sessions</a> (#641).</p>"
|
||||
)
|
||||
@@ -0,0 +1,517 @@
|
||||
"""Compose runtime health + inventory into a sessions/runtime view (#641).
|
||||
|
||||
Phase 1 is read-only. It correlates namespaces, sessions, capabilities,
|
||||
worktree bindings, lease ownership, stale flags, and contamination markers
|
||||
when they are detectable on disk (#630 / #671). It never restarts, kills, or
|
||||
takes over a session.
|
||||
|
||||
Sources:
|
||||
|
||||
* :mod:`webui.runtime_health` — profile, role, stale runtime, shell health.
|
||||
* :mod:`webui.inventory` — sessions, leases, locks, worktrees, namespaces
|
||||
and collision signals from the control-plane DB + filesystem.
|
||||
* :mod:`mcp_session_state` — durable contamination markers (inspect only).
|
||||
|
||||
Secrets are never read. Inventory-sourced values arrive already redacted by
|
||||
:func:`webui.inventory.scrub`; free-form marker text this module loads itself is
|
||||
put through :func:`webui.inventory.scrub_text`, which collapses ``$HOME`` and
|
||||
redacts credential-shaped tokens *inside* a string rather than only at its start.
|
||||
|
||||
Ownership columns are authority-aware. A lease or lock section that could not be
|
||||
read renders as ``unknown``, never as ``none`` or ``unbound``: a lease the reader
|
||||
could not load is not an absent lease (see
|
||||
:attr:`webui.inventory.InventorySnapshot.ownership_authority_complete`).
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
from dataclasses import dataclass
|
||||
from typing import Any, Callable
|
||||
|
||||
import mcp_session_state
|
||||
from webui.inventory import (
|
||||
OWNERSHIP_SECTIONS,
|
||||
STATUS_OK,
|
||||
InventorySection,
|
||||
InventorySnapshot,
|
||||
load_inventory_snapshot,
|
||||
scrub_text,
|
||||
snapshot_to_dict as inventory_snapshot_to_dict,
|
||||
)
|
||||
from webui.runtime_health import (
|
||||
RuntimeSnapshot,
|
||||
load_runtime_snapshot,
|
||||
snapshot_to_dict as runtime_snapshot_to_dict,
|
||||
)
|
||||
|
||||
# Sanctioned recovery pointers only — never pkill / killall (#630).
|
||||
SANCTIONED_RECOVERY_DOCS: tuple[dict[str, str], ...] = (
|
||||
{
|
||||
"label": "MCP namespace EOF recovery (reconnect only)",
|
||||
"path": "docs/mcp-namespace-eof-recovery.md",
|
||||
"note": "IDE/client reconnect or operator-owned restart; never kill daemons.",
|
||||
},
|
||||
{
|
||||
"label": "MCP namespace health",
|
||||
"path": "docs/mcp-namespace-health.md",
|
||||
"note": "client_namespace probe proves namespace health.",
|
||||
},
|
||||
{
|
||||
"label": "Restart path inventory",
|
||||
"path": "docs/mcp-restart-path-inventory.md",
|
||||
"note": "Catalog of sanctioned reconnect/restart paths.",
|
||||
},
|
||||
{
|
||||
"label": "Local web UI recovery",
|
||||
"path": "docs/webui-local-dev.md",
|
||||
"note": "Operator console start and documented recovery sequence.",
|
||||
},
|
||||
)
|
||||
|
||||
_CONTAMINATION_KINDS: tuple[str, ...] = (
|
||||
mcp_session_state.KIND_RUNTIME_RECOVERY_CONTAMINATION,
|
||||
mcp_session_state.KIND_STABLE_BRANCH_CONTAMINATION,
|
||||
)
|
||||
|
||||
#: Status recorded on a row when the backing inventory section is absent
|
||||
#: entirely — distinct from a section that reported itself degraded.
|
||||
AUTHORITY_MISSING = "missing"
|
||||
|
||||
|
||||
def _section_status(section: InventorySection | None) -> str:
|
||||
"""Status of an ownership section, treating an absent section as missing."""
|
||||
if section is None:
|
||||
return AUTHORITY_MISSING
|
||||
return section.status
|
||||
|
||||
|
||||
def _combined_authority(*statuses: str) -> str:
|
||||
"""Worst status of the sections a derived column depends on.
|
||||
|
||||
A column proved from two sections is only trustworthy when *both* read
|
||||
cleanly, so the first non-``ok`` status wins.
|
||||
"""
|
||||
for status in statuses:
|
||||
if status != STATUS_OK:
|
||||
return status
|
||||
return STATUS_OK
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class ContaminationMarker:
|
||||
"""A detectable durable contamination marker (audit-safe summary)."""
|
||||
|
||||
kind: str
|
||||
on_disk: bool
|
||||
has_payload: bool
|
||||
summary: str
|
||||
reason_class: str | None = None
|
||||
session_id: str | None = None
|
||||
role: str | None = None
|
||||
command_summary: str | None = None
|
||||
cleared: bool = False
|
||||
|
||||
def to_dict(self) -> dict[str, Any]:
|
||||
return {
|
||||
"kind": self.kind,
|
||||
"on_disk": self.on_disk,
|
||||
"has_payload": self.has_payload,
|
||||
"summary": self.summary,
|
||||
"reason_class": self.reason_class,
|
||||
"session_id": self.session_id,
|
||||
"role": self.role,
|
||||
"command_summary": self.command_summary,
|
||||
"cleared": self.cleared,
|
||||
"active": self.on_disk and self.has_payload and not self.cleared,
|
||||
}
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class SessionRow:
|
||||
"""One correlated session row for the sessions table."""
|
||||
|
||||
session_id: str
|
||||
role: str | None
|
||||
profile: str | None
|
||||
namespace: str | None
|
||||
pid: int | None
|
||||
pid_alive: bool | None
|
||||
status: str | None
|
||||
started_at: str | None
|
||||
last_heartbeat_at: str | None
|
||||
lease_ids: tuple[str, ...] = ()
|
||||
work_refs: tuple[str, ...] = ()
|
||||
worktree_paths: tuple[str, ...] = ()
|
||||
stale_flags: tuple[str, ...] = ()
|
||||
contamination_flags: tuple[str, ...] = ()
|
||||
#: Status of the section backing ``lease_ids``/``work_refs``. While this is
|
||||
#: not ``ok`` those tuples mean "could not be read", never "none held".
|
||||
lease_authority: str = STATUS_OK
|
||||
#: Worst status across the sections backing ``worktree_paths`` (locks are
|
||||
#: correlated through lease work numbers, so both must read cleanly).
|
||||
worktree_authority: str = STATUS_OK
|
||||
|
||||
@property
|
||||
def ownership_authority_complete(self) -> bool:
|
||||
"""True only when this row's ownership columns are provable."""
|
||||
return self.lease_authority == STATUS_OK and self.worktree_authority == STATUS_OK
|
||||
|
||||
def to_dict(self) -> dict[str, Any]:
|
||||
return {
|
||||
"session_id": self.session_id,
|
||||
"role": self.role,
|
||||
"profile": self.profile,
|
||||
"namespace": self.namespace,
|
||||
"pid": self.pid,
|
||||
"pid_alive": self.pid_alive,
|
||||
"status": self.status,
|
||||
"started_at": self.started_at,
|
||||
"last_heartbeat_at": self.last_heartbeat_at,
|
||||
"lease_ids": list(self.lease_ids),
|
||||
"work_refs": list(self.work_refs),
|
||||
"worktree_paths": list(self.worktree_paths),
|
||||
"stale_flags": list(self.stale_flags),
|
||||
"contamination_flags": list(self.contamination_flags),
|
||||
"is_stale": bool(self.stale_flags),
|
||||
"is_contaminated": bool(self.contamination_flags),
|
||||
"lease_authority": self.lease_authority,
|
||||
"worktree_authority": self.worktree_authority,
|
||||
"lease_authority_complete": self.lease_authority == STATUS_OK,
|
||||
"worktree_authority_complete": self.worktree_authority == STATUS_OK,
|
||||
"ownership_authority_complete": self.ownership_authority_complete,
|
||||
"ownership_note": (
|
||||
"Lease and worktree columns are proved from sections that read "
|
||||
"cleanly."
|
||||
if self.ownership_authority_complete
|
||||
else "An ownership source could not be read; empty lease_ids or "
|
||||
"worktree_paths on this row mean unknown, not unowned."
|
||||
),
|
||||
}
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class SessionViewSnapshot:
|
||||
"""Composed runtime + session inventory view (#641)."""
|
||||
|
||||
runtime: RuntimeSnapshot
|
||||
inventory: InventorySnapshot
|
||||
sessions: tuple[SessionRow, ...]
|
||||
contamination_markers: tuple[ContaminationMarker, ...]
|
||||
recovery_docs: tuple[dict[str, str], ...] = SANCTIONED_RECOVERY_DOCS
|
||||
fetch_error: str | None = None
|
||||
|
||||
@property
|
||||
def stale_session_count(self) -> int:
|
||||
return sum(1 for row in self.sessions if row.stale_flags)
|
||||
|
||||
@property
|
||||
def contaminated_session_count(self) -> int:
|
||||
return sum(1 for row in self.sessions if row.contamination_flags)
|
||||
|
||||
@property
|
||||
def active_contamination(self) -> tuple[ContaminationMarker, ...]:
|
||||
return tuple(m for m in self.contamination_markers if m.to_dict()["active"])
|
||||
|
||||
@property
|
||||
def ownership_authority_complete(self) -> bool:
|
||||
"""False while any ownership section is degraded, absent, or unavailable."""
|
||||
return self.inventory.ownership_authority_complete
|
||||
|
||||
@property
|
||||
def ownership_section_status(self) -> dict[str, str]:
|
||||
"""Per-section status for the three ownership-bearing sections."""
|
||||
return {
|
||||
name: _section_status(self.inventory.section(name))
|
||||
for name in OWNERSHIP_SECTIONS
|
||||
}
|
||||
|
||||
|
||||
def _inspect_contamination(
|
||||
kind: str,
|
||||
*,
|
||||
remote: str | None,
|
||||
inspect: Callable[..., dict[str, Any]] | None = None,
|
||||
load: Callable[..., dict[str, Any] | None] | None = None,
|
||||
) -> ContaminationMarker:
|
||||
"""Inspect one contamination kind; never raises into the page render path."""
|
||||
inspect_fn = inspect or mcp_session_state.inspect_state_envelope
|
||||
load_fn = load or mcp_session_state.load_state
|
||||
try:
|
||||
envelope = inspect_fn(kind=kind, remote=remote)
|
||||
except Exception as exc: # noqa: BLE001 — fail soft for the dashboard
|
||||
return ContaminationMarker(
|
||||
kind=kind,
|
||||
on_disk=False,
|
||||
has_payload=False,
|
||||
summary=f"contamination inspect failed: {type(exc).__name__}",
|
||||
)
|
||||
|
||||
reason_class = None
|
||||
session_id = None
|
||||
role = None
|
||||
command_summary = None
|
||||
cleared = False
|
||||
summary = scrub_text(str(envelope.get("summary") or ""))
|
||||
|
||||
if envelope.get("on_disk") and envelope.get("has_payload"):
|
||||
try:
|
||||
payload = load_fn(kind=kind, remote=remote) or {}
|
||||
except Exception: # noqa: BLE001
|
||||
payload = {}
|
||||
if isinstance(payload, dict):
|
||||
reason_class = payload.get("reason_class")
|
||||
session_id = payload.get("session_id")
|
||||
role = payload.get("role")
|
||||
command_summary = payload.get("command_summary") or payload.get("detail")
|
||||
cleared = bool(payload.get("cleared_by_reconciler"))
|
||||
if not summary:
|
||||
summary = scrub_text(
|
||||
f"{kind}: {reason_class or 'present'}"
|
||||
+ (" (cleared)" if cleared else "")
|
||||
)
|
||||
|
||||
# Marker payloads are operator-supplied free text and are the one thing on
|
||||
# this page that does not arrive through inventory scrubbing. The write-time
|
||||
# redactor is a narrow denylist, so redact again at the display boundary:
|
||||
# it leaves $HOME paths, `-H 'X-Api-Key: …'`, `--password …`, and
|
||||
# `PRIVATE_KEY=…` intact. The field itself stays — it is #630 evidence.
|
||||
return ContaminationMarker(
|
||||
kind=kind,
|
||||
on_disk=bool(envelope.get("on_disk")),
|
||||
has_payload=bool(envelope.get("has_payload")),
|
||||
summary=summary or f"{kind}: not present",
|
||||
reason_class=scrub_text(str(reason_class)) if reason_class else None,
|
||||
session_id=scrub_text(str(session_id)) if session_id else None,
|
||||
role=scrub_text(str(role)) if role else None,
|
||||
command_summary=scrub_text(str(command_summary)) if command_summary else None,
|
||||
cleared=cleared,
|
||||
)
|
||||
|
||||
|
||||
def _load_contamination_markers(
|
||||
*,
|
||||
remote: str | None,
|
||||
inspect: Callable[..., dict[str, Any]] | None = None,
|
||||
load: Callable[..., dict[str, Any] | None] | None = None,
|
||||
) -> tuple[ContaminationMarker, ...]:
|
||||
return tuple(
|
||||
_inspect_contamination(kind, remote=remote, inspect=inspect, load=load)
|
||||
for kind in _CONTAMINATION_KINDS
|
||||
)
|
||||
|
||||
|
||||
def _build_session_rows(
|
||||
inventory: InventorySnapshot,
|
||||
contamination: tuple[ContaminationMarker, ...],
|
||||
) -> tuple[SessionRow, ...]:
|
||||
sessions_section = inventory.section("sessions")
|
||||
leases_section = inventory.section("leases")
|
||||
locks_section = inventory.section("locks")
|
||||
|
||||
# Ownership columns may only assert absence when their source read cleanly.
|
||||
lease_authority = _section_status(leases_section)
|
||||
# Locks carry claimant profile/username, not control-plane session ids, so a
|
||||
# worktree binding is correlated through lease work numbers: it depends on
|
||||
# the locks *and* the leases section.
|
||||
worktree_authority = _combined_authority(
|
||||
lease_authority, _section_status(locks_section)
|
||||
)
|
||||
|
||||
leases_by_session: dict[str, list[dict[str, Any]]] = {}
|
||||
for lease in (leases_section.items if leases_section else ()):
|
||||
sid = str(lease.get("session_id") or "")
|
||||
if sid:
|
||||
leases_by_session.setdefault(sid, []).append(lease)
|
||||
|
||||
active_markers = [m for m in contamination if m.to_dict()["active"]]
|
||||
marker_session_ids = {
|
||||
m.session_id for m in active_markers if m.session_id
|
||||
}
|
||||
|
||||
rows: list[SessionRow] = []
|
||||
for raw in sessions_section.items if sessions_section else ():
|
||||
sid = str(raw.get("session_id") or "")
|
||||
if not sid:
|
||||
continue
|
||||
session_leases = leases_by_session.get(sid, [])
|
||||
lease_ids = tuple(
|
||||
str(lease["lease_id"])
|
||||
for lease in session_leases
|
||||
if lease.get("lease_id")
|
||||
)
|
||||
work_refs: list[str] = []
|
||||
work_numbers: list[int] = []
|
||||
for lease in session_leases:
|
||||
kind = lease.get("work_kind")
|
||||
number = lease.get("work_number")
|
||||
if kind and number is not None:
|
||||
work_refs.append(f"{kind}#{number}")
|
||||
try:
|
||||
work_numbers.append(int(number))
|
||||
except (TypeError, ValueError):
|
||||
pass
|
||||
|
||||
worktree_paths: list[str] = []
|
||||
for lock in (locks_section.items if locks_section else ()):
|
||||
try:
|
||||
issue_no = int(lock.get("issue_number"))
|
||||
except (TypeError, ValueError):
|
||||
continue
|
||||
if issue_no in work_numbers and lock.get("worktree_path"):
|
||||
worktree_paths.append(str(lock["worktree_path"]))
|
||||
|
||||
stale_flags: list[str] = []
|
||||
if raw.get("pid_alive") is False:
|
||||
stale_flags.append("pid-dead")
|
||||
status = str(raw.get("status") or "").lower()
|
||||
if status and status not in {"active", "alive", "running", "ok"}:
|
||||
stale_flags.append(f"status:{status}")
|
||||
for lease in session_leases:
|
||||
if lease.get("expired") is True:
|
||||
stale_flags.append("lease-expired")
|
||||
if str(lease.get("status") or "").lower() == "active" and lease.get(
|
||||
"expired"
|
||||
) is True:
|
||||
stale_flags.append("active-lease-past-expiry")
|
||||
|
||||
contamination_flags: list[str] = []
|
||||
if sid in marker_session_ids:
|
||||
for marker in active_markers:
|
||||
if marker.session_id == sid:
|
||||
contamination_flags.append(marker.kind)
|
||||
# Process-wide contamination with no session binding still surfaces
|
||||
# against every live session so it cannot be silent (#630).
|
||||
for marker in active_markers:
|
||||
if not marker.session_id and marker.kind not in contamination_flags:
|
||||
contamination_flags.append(f"{marker.kind}:process-wide")
|
||||
|
||||
rows.append(
|
||||
SessionRow(
|
||||
session_id=sid,
|
||||
role=raw.get("role"),
|
||||
profile=raw.get("profile"),
|
||||
namespace=raw.get("namespace"),
|
||||
pid=raw.get("pid") if isinstance(raw.get("pid"), int) else None,
|
||||
pid_alive=raw.get("pid_alive")
|
||||
if isinstance(raw.get("pid_alive"), bool)
|
||||
else None,
|
||||
status=raw.get("status"),
|
||||
started_at=raw.get("started_at"),
|
||||
last_heartbeat_at=raw.get("last_heartbeat_at"),
|
||||
lease_ids=lease_ids,
|
||||
work_refs=tuple(work_refs),
|
||||
worktree_paths=tuple(worktree_paths),
|
||||
stale_flags=tuple(dict.fromkeys(stale_flags)),
|
||||
contamination_flags=tuple(dict.fromkeys(contamination_flags)),
|
||||
lease_authority=lease_authority,
|
||||
worktree_authority=worktree_authority,
|
||||
)
|
||||
)
|
||||
|
||||
return tuple(rows)
|
||||
|
||||
|
||||
def load_session_view_snapshot(
|
||||
*,
|
||||
load_runtime: Callable[..., RuntimeSnapshot] | None = None,
|
||||
load_inventory: Callable[..., InventorySnapshot] | None = None,
|
||||
inspect_contamination: Callable[..., dict[str, Any]] | None = None,
|
||||
load_contamination_payload: Callable[..., dict[str, Any] | None] | None = None,
|
||||
) -> SessionViewSnapshot:
|
||||
"""Build the composed sessions/runtime view. Fail-soft on partial sources."""
|
||||
runtime_loader = load_runtime or load_runtime_snapshot
|
||||
inventory_loader = load_inventory or load_inventory_snapshot
|
||||
fetch_error: str | None = None
|
||||
|
||||
try:
|
||||
runtime = runtime_loader()
|
||||
except Exception as exc: # noqa: BLE001
|
||||
fetch_error = f"runtime snapshot failed: {type(exc).__name__}: {exc}"
|
||||
# Minimal placeholder so the page still renders inventory + recovery.
|
||||
from webui.runtime_health import RuntimeSnapshot as _RS
|
||||
|
||||
runtime = _RS(
|
||||
project_id="unknown",
|
||||
repo_root="",
|
||||
remote="",
|
||||
host="",
|
||||
profile_name="unknown",
|
||||
role_kind="unknown",
|
||||
config_model="unknown",
|
||||
profile_mode="unknown",
|
||||
profile_source="unknown",
|
||||
authenticated_username=None,
|
||||
identity_error=str(exc),
|
||||
repo_sha=None,
|
||||
remote_master_sha=None,
|
||||
commits_behind_master=None,
|
||||
stale_runtime_warning=None,
|
||||
shell_health={},
|
||||
workflow_hashes=(),
|
||||
schema_hashes=(),
|
||||
restart_guidance="docs/mcp-namespace-eof-recovery.md",
|
||||
fetch_error=str(exc),
|
||||
)
|
||||
|
||||
try:
|
||||
inventory = inventory_loader()
|
||||
except Exception as exc: # noqa: BLE001
|
||||
msg = f"inventory snapshot failed: {type(exc).__name__}: {exc}"
|
||||
fetch_error = f"{fetch_error}; {msg}" if fetch_error else msg
|
||||
inventory = load_inventory_snapshot(
|
||||
db_path="/nonexistent-for-fail-soft",
|
||||
lock_dir="/nonexistent-for-fail-soft",
|
||||
)
|
||||
|
||||
remote = getattr(runtime, "remote", None)
|
||||
contamination = _load_contamination_markers(
|
||||
remote=remote,
|
||||
inspect=inspect_contamination,
|
||||
load=load_contamination_payload,
|
||||
)
|
||||
sessions = _build_session_rows(inventory, contamination)
|
||||
return SessionViewSnapshot(
|
||||
runtime=runtime,
|
||||
inventory=inventory,
|
||||
sessions=sessions,
|
||||
contamination_markers=contamination,
|
||||
fetch_error=fetch_error,
|
||||
)
|
||||
|
||||
|
||||
def snapshot_to_dict(snapshot: SessionViewSnapshot) -> dict[str, Any]:
|
||||
"""JSON export for ``/api/sessions`` (read-only)."""
|
||||
return {
|
||||
"api_version": "v1",
|
||||
"view": "runtime-sessions",
|
||||
"issue": 641,
|
||||
"fetch_error": snapshot.fetch_error,
|
||||
"runtime": runtime_snapshot_to_dict(snapshot.runtime),
|
||||
"inventory": inventory_snapshot_to_dict(snapshot.inventory),
|
||||
"sessions": [row.to_dict() for row in snapshot.sessions],
|
||||
"session_counts": {
|
||||
"total": len(snapshot.sessions),
|
||||
"stale": snapshot.stale_session_count,
|
||||
"contaminated": snapshot.contaminated_session_count,
|
||||
},
|
||||
"ownership_authority_complete": snapshot.ownership_authority_complete,
|
||||
"ownership_section_status": snapshot.ownership_section_status,
|
||||
"ownership_note": (
|
||||
"Every ownership source read cleanly; a session with no lease and no "
|
||||
"worktree path genuinely holds neither."
|
||||
if snapshot.ownership_authority_complete
|
||||
else "An ownership source is degraded or unavailable. Empty lease_ids "
|
||||
"and worktree_paths mean unknown, not unowned; consult each row's "
|
||||
"lease_authority and worktree_authority."
|
||||
),
|
||||
"contamination_markers": [
|
||||
marker.to_dict() for marker in snapshot.contamination_markers
|
||||
],
|
||||
"active_contamination": [
|
||||
marker.to_dict() for marker in snapshot.active_contamination
|
||||
],
|
||||
"recovery_docs": [dict(doc) for doc in snapshot.recovery_docs],
|
||||
"read_only": True,
|
||||
"phase": 1,
|
||||
"mutations": [],
|
||||
}
|
||||
@@ -0,0 +1,403 @@
|
||||
"""HTML views for the Runtime and session view (Phase 1, #641).
|
||||
|
||||
Read-only composition of runtime health (#430) and inventory sessions /
|
||||
namespaces / worktrees (#636). Surfaces stale and contamination indicators
|
||||
when detectable. Recovery links point only at sanctioned reconnect/restart
|
||||
docs — never at manual process kill (#630).
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
from html import escape
|
||||
from typing import Sequence
|
||||
|
||||
from webui.inventory import STATUS_OK
|
||||
from webui.layout import render_page
|
||||
from webui.session_loader import (
|
||||
ContaminationMarker,
|
||||
SessionRow,
|
||||
SessionViewSnapshot,
|
||||
)
|
||||
|
||||
|
||||
def _badge(text: str, css: str) -> str:
|
||||
return f'<span class="badge {css}">{escape(text)}</span>'
|
||||
|
||||
|
||||
def _flags(flags: Sequence[str], *, css: str) -> str:
|
||||
if not flags:
|
||||
return '<span class="muted">—</span>'
|
||||
return " ".join(_badge(flag, css) for flag in flags)
|
||||
|
||||
|
||||
def _unproven_cell(status: str) -> str:
|
||||
"""Render an ownership column whose backing inventory section failed to read.
|
||||
|
||||
Never "none" and never "unbound": an unreadable source proves nothing about
|
||||
ownership, and claiming otherwise is the exact failure the
|
||||
``ownership_authority_complete`` invariant exists to prevent.
|
||||
"""
|
||||
return (
|
||||
f'<span class="muted">unknown (inventory {escape(status)})</span><br>'
|
||||
f'{_badge("authority unproven", "badge-health-degraded")}'
|
||||
)
|
||||
|
||||
|
||||
def _runtime_banner(snapshot: SessionViewSnapshot) -> str:
|
||||
runtime = snapshot.runtime
|
||||
stale = runtime.stale_runtime_warning
|
||||
stale_html = ""
|
||||
if stale:
|
||||
stale_html = (
|
||||
f'<div class="health-card health-stale" style="margin-top:0.75rem;">'
|
||||
f"<strong>Stale runtime:</strong> {escape(stale)}</div>"
|
||||
)
|
||||
identity = runtime.authenticated_username or "unresolved"
|
||||
if runtime.identity_error:
|
||||
identity = f"unresolved ({runtime.identity_error})"
|
||||
|
||||
return f"""<div class="health-card">
|
||||
<h3>Runtime context</h3>
|
||||
<table class="detail">
|
||||
<tr><th>Profile</th><td><code>{escape(runtime.profile_name)}</code></td></tr>
|
||||
<tr><th>Role kind</th><td>{escape(runtime.role_kind)}</td></tr>
|
||||
<tr><th>Identity</th><td>{escape(str(identity))}</td></tr>
|
||||
<tr><th>Remote / host</th>
|
||||
<td><code>{escape(runtime.remote)}</code> · <code>{escape(runtime.host)}</code></td>
|
||||
</tr>
|
||||
<tr><th>Local HEAD</th>
|
||||
<td><code>{escape(runtime.repo_sha or "unknown")}</code></td>
|
||||
</tr>
|
||||
<tr><th>Remote master</th>
|
||||
<td><code>{escape(runtime.remote_master_sha or "unknown")}</code></td>
|
||||
</tr>
|
||||
<tr><th>Commits behind</th>
|
||||
<td>{escape(str(runtime.commits_behind_master if runtime.commits_behind_master is not None else "unknown"))}</td>
|
||||
</tr>
|
||||
</table>
|
||||
<p class="muted">Full runtime detail: <a href="/runtime">/runtime</a> ·
|
||||
Inventory API: <a href="/api/v1/inventory"><code>/api/v1/inventory</code></a></p>
|
||||
{stale_html}
|
||||
</div>"""
|
||||
|
||||
|
||||
def _summary_bar(snapshot: SessionViewSnapshot) -> str:
|
||||
total = len(snapshot.sessions)
|
||||
stale = snapshot.stale_session_count
|
||||
contaminated = snapshot.contaminated_session_count
|
||||
active_markers = len(snapshot.active_contamination)
|
||||
inv_status = snapshot.inventory.status
|
||||
authority_complete = snapshot.ownership_authority_complete
|
||||
authority_text = "complete" if authority_complete else "incomplete"
|
||||
authority_css = "badge-health-ok" if authority_complete else "badge-health-degraded"
|
||||
return f"""<div class="health-card" style="display:flex; flex-wrap:wrap; gap:1rem; align-items:center;">
|
||||
<div><strong>Sessions:</strong> <span class="badge badge-health-ok">{total}</span></div>
|
||||
<div><strong>Stale:</strong> <span class="badge badge-stale">{stale}</span></div>
|
||||
<div><strong>Contaminated:</strong> <span class="badge badge-blocked">{contaminated}</span></div>
|
||||
<div><strong>Active markers:</strong> <span class="badge badge-health-unproven">{active_markers}</span></div>
|
||||
<div><strong>Inventory:</strong> <span class="badge badge-health-skipped">{escape(inv_status)}</span></div>
|
||||
<div><strong>Ownership authority:</strong> <span class="badge {authority_css}">{authority_text}</span></div>
|
||||
</div>"""
|
||||
|
||||
|
||||
def _ownership_caveat(snapshot: SessionViewSnapshot) -> str:
|
||||
"""Name the unreadable ownership sections, or render nothing when all read."""
|
||||
if snapshot.ownership_authority_complete:
|
||||
return ""
|
||||
degraded = ", ".join(
|
||||
f"{name}: {status}"
|
||||
for name, status in snapshot.ownership_section_status.items()
|
||||
if status != STATUS_OK
|
||||
)
|
||||
return (
|
||||
'<div class="health-card health-stale">'
|
||||
"<strong>Ownership authority incomplete:</strong> "
|
||||
f"{escape(degraded)}. Columns marked <em>unknown</em> could not be read. "
|
||||
"No session below may be treated as holding no lease or no worktree "
|
||||
"binding — absence of evidence is not evidence of absence.</div>"
|
||||
)
|
||||
|
||||
|
||||
def _render_session_row(row: SessionRow) -> str:
|
||||
pid = "—" if row.pid is None else str(row.pid)
|
||||
pid_alive = "—" if row.pid_alive is None else ("alive" if row.pid_alive else "dead")
|
||||
pid_css = (
|
||||
"badge-health-ok"
|
||||
if row.pid_alive is True
|
||||
else ("badge-blocked" if row.pid_alive is False else "badge-health-skipped")
|
||||
)
|
||||
# An empty tuple only means "holds none" when its source read cleanly.
|
||||
if row.lease_authority != STATUS_OK:
|
||||
lease_cell = _unproven_cell(row.lease_authority)
|
||||
else:
|
||||
leases = (
|
||||
", ".join(f"<code>{escape(lid)}</code>" for lid in row.lease_ids)
|
||||
if row.lease_ids
|
||||
else '<span class="muted">none</span>'
|
||||
)
|
||||
work = (
|
||||
", ".join(escape(ref) for ref in row.work_refs)
|
||||
if row.work_refs
|
||||
else '<span class="muted">—</span>'
|
||||
)
|
||||
lease_cell = (
|
||||
f'{leases}<div class="muted" style="font-size:0.82rem; '
|
||||
f'margin-top:0.2rem;">{work}</div>'
|
||||
)
|
||||
|
||||
if row.worktree_authority != STATUS_OK:
|
||||
worktrees = _unproven_cell(row.worktree_authority)
|
||||
else:
|
||||
worktrees = (
|
||||
"<br>".join(f"<code>{escape(path)}</code>" for path in row.worktree_paths)
|
||||
if row.worktree_paths
|
||||
else '<span class="muted">unbound</span>'
|
||||
)
|
||||
return f"""<tr>
|
||||
<td><code>{escape(row.session_id)}</code></td>
|
||||
<td>
|
||||
<div><code>{escape(str(row.role or "—"))}</code> / <code>{escape(str(row.profile or "—"))}</code></div>
|
||||
<div class="muted" style="font-size:0.82rem;">ns: <code>{escape(str(row.namespace or "—"))}</code></div>
|
||||
</td>
|
||||
<td>
|
||||
<code>{escape(pid)}</code>
|
||||
{_badge(pid_alive, pid_css)}
|
||||
</td>
|
||||
<td>{escape(str(row.status or "—"))}<div class="muted" style="font-size:0.82rem;">{escape(str(row.last_heartbeat_at or ""))}</div></td>
|
||||
<td>{lease_cell}</td>
|
||||
<td>{worktrees}</td>
|
||||
<td>{_flags(row.stale_flags, css="badge-stale")}</td>
|
||||
<td>{_flags(row.contamination_flags, css="badge-blocked")}</td>
|
||||
</tr>"""
|
||||
|
||||
|
||||
def _sessions_table(snapshot: SessionViewSnapshot) -> str:
|
||||
rows: Sequence[SessionRow] = snapshot.sessions
|
||||
if not rows:
|
||||
sessions_status = snapshot.ownership_section_status.get("sessions", STATUS_OK)
|
||||
if sessions_status != STATUS_OK:
|
||||
return (
|
||||
'<p class="muted">Session inventory is '
|
||||
f"<strong>{escape(sessions_status)}</strong> — the session list "
|
||||
"could not be read. This is not evidence that no sessions "
|
||||
"exist.</p>"
|
||||
)
|
||||
return (
|
||||
'<p class="muted">No control-plane sessions recorded. Inventory may '
|
||||
"be unavailable, or no MCP workers have registered yet.</p>"
|
||||
)
|
||||
body = "".join(_render_session_row(row) for row in rows)
|
||||
return f"""<table class="registry">
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Session</th>
|
||||
<th>Role / profile / namespace</th>
|
||||
<th>PID</th>
|
||||
<th>Status</th>
|
||||
<th>Leases / work</th>
|
||||
<th>Worktree binding</th>
|
||||
<th>Stale</th>
|
||||
<th>Contamination</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{body}
|
||||
</tbody>
|
||||
</table>"""
|
||||
|
||||
|
||||
def _namespaces_section(snapshot: SessionViewSnapshot) -> str:
|
||||
section = snapshot.inventory.section("namespaces")
|
||||
if section is None:
|
||||
return (
|
||||
'<div class="prompt-card"><h3>Namespaces</h3>'
|
||||
'<p class="muted">Namespaces section not loaded.</p></div>'
|
||||
)
|
||||
if not section.ok:
|
||||
return f"""<div class="prompt-card">
|
||||
<h3>Namespaces {_badge(section.status, "badge-health-degraded")}</h3>
|
||||
<p class="muted">{escape(section.reason or "unavailable")}</p>
|
||||
</div>"""
|
||||
|
||||
rows = []
|
||||
for item in section.items:
|
||||
caps = item.get("capability_summary") or {}
|
||||
cap_bits = ", ".join(
|
||||
name for name, ok in sorted(caps.items()) if ok
|
||||
) or "none"
|
||||
rows.append(
|
||||
"<tr>"
|
||||
f"<td><code>{escape(str(item.get('mcp_namespace') or '—'))}</code></td>"
|
||||
f"<td><code>{escape(str(item.get('profile_name') or '—'))}</code></td>"
|
||||
f"<td>{escape(str(item.get('role') or '—'))}</td>"
|
||||
f"<td>{escape(cap_bits)}</td>"
|
||||
f"<td>{'yes' if item.get('active') else 'no'}</td>"
|
||||
"</tr>"
|
||||
)
|
||||
reason = (
|
||||
f'<p class="muted">{escape(section.reason)}</p>'
|
||||
if section.reason
|
||||
else ""
|
||||
)
|
||||
return f"""<div class="prompt-card">
|
||||
<h3>Namespaces / capabilities</h3>
|
||||
{reason}
|
||||
<table class="registry">
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Namespace</th>
|
||||
<th>Profile</th>
|
||||
<th>Role</th>
|
||||
<th>Capabilities</th>
|
||||
<th>Active in process</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{"".join(rows) if rows else '<tr><td colspan="5" class="muted">No namespace rows.</td></tr>'}
|
||||
</tbody>
|
||||
</table>
|
||||
</div>"""
|
||||
|
||||
|
||||
def _worktrees_section(snapshot: SessionViewSnapshot) -> str:
|
||||
section = snapshot.inventory.section("worktrees")
|
||||
if section is None:
|
||||
return ""
|
||||
if not section.ok and not section.items:
|
||||
return f"""<div class="prompt-card">
|
||||
<h3>Worktrees {_badge(section.status, "badge-health-degraded")}</h3>
|
||||
<p class="muted">{escape(section.reason or "unavailable")}</p>
|
||||
</div>"""
|
||||
|
||||
rows = []
|
||||
for item in section.items[:50]:
|
||||
rows.append(
|
||||
"<tr>"
|
||||
f"<td><code>{escape(str(item.get('rel_path') or item.get('path') or '—'))}</code></td>"
|
||||
f"<td><code>{escape(str(item.get('branch') or '—'))}</code></td>"
|
||||
f"<td>{escape(str(item.get('classification') or '—'))}</td>"
|
||||
f"<td>{'yes' if item.get('registered_worktree') else 'no'}</td>"
|
||||
f"<td>{'dirty' if item.get('dirty') else 'clean'}</td>"
|
||||
"</tr>"
|
||||
)
|
||||
more = ""
|
||||
if len(section.items) > 50:
|
||||
more = f'<p class="muted">Showing 50 of {len(section.items)}. Full list: <a href="/worktrees">/worktrees</a>.</p>'
|
||||
return f"""<div class="prompt-card">
|
||||
<h3>Worktree bindings</h3>
|
||||
<p class="muted">Registered issue worktrees under <code>branches/</code>. Hygiene detail: <a href="/worktrees">/worktrees</a>.</p>
|
||||
<table class="registry">
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Path</th>
|
||||
<th>Branch</th>
|
||||
<th>Classification</th>
|
||||
<th>Registered</th>
|
||||
<th>State</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{"".join(rows) if rows else '<tr><td colspan="5" class="muted">No worktrees recorded.</td></tr>'}
|
||||
</tbody>
|
||||
</table>
|
||||
{more}
|
||||
</div>"""
|
||||
|
||||
|
||||
def _contamination_section(markers: Sequence[ContaminationMarker]) -> str:
|
||||
if not markers:
|
||||
return (
|
||||
'<div class="prompt-card"><h3>Contamination markers</h3>'
|
||||
'<p class="muted">No contamination kinds inspected.</p></div>'
|
||||
)
|
||||
rows = []
|
||||
for marker in markers:
|
||||
active = marker.to_dict()["active"]
|
||||
status = "ACTIVE" if active else ("cleared" if marker.cleared else "absent")
|
||||
css = "badge-blocked" if active else "badge-health-ok"
|
||||
rows.append(
|
||||
"<tr>"
|
||||
f"<td><code>{escape(marker.kind)}</code></td>"
|
||||
f"<td>{_badge(status, css)}</td>"
|
||||
f"<td>{escape(marker.reason_class or '—')}</td>"
|
||||
f"<td><code>{escape(marker.session_id or '—')}</code></td>"
|
||||
f"<td>{escape(marker.command_summary or marker.summary)}</td>"
|
||||
"</tr>"
|
||||
)
|
||||
return f"""<div class="prompt-card">
|
||||
<h3>Contamination markers (#630 / #671)</h3>
|
||||
<p class="muted">Durable markers only — never silent when present. Clearance is reconciler-only.</p>
|
||||
<table class="registry">
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Kind</th>
|
||||
<th>State</th>
|
||||
<th>Reason class</th>
|
||||
<th>Session</th>
|
||||
<th>Summary</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{"".join(rows)}
|
||||
</tbody>
|
||||
</table>
|
||||
</div>"""
|
||||
|
||||
|
||||
def _recovery_section(snapshot: SessionViewSnapshot) -> str:
|
||||
items = []
|
||||
for doc in snapshot.recovery_docs:
|
||||
items.append(
|
||||
"<li>"
|
||||
f"<code>{escape(doc['path'])}</code> — "
|
||||
f"<strong>{escape(doc['label'])}</strong>: {escape(doc['note'])}"
|
||||
"</li>"
|
||||
)
|
||||
return f"""<div class="prompt-card">
|
||||
<h3>Sanctioned recovery (read-only)</h3>
|
||||
<p class="muted">This view does <strong>not</strong> restart, kill, or take over sessions.
|
||||
Manual <code>pkill</code> / <code>kill</code> of MCP daemons is contamination (#630), not recovery.</p>
|
||||
<ul class="reasons">
|
||||
{"".join(items)}
|
||||
<li>Prefer IDE/client reconnect (<code>/mcp reconnect</code>) or an operator-owned restart recorded in the restart inventory.</li>
|
||||
</ul>
|
||||
</div>"""
|
||||
|
||||
|
||||
def render_sessions_page(snapshot: SessionViewSnapshot) -> str:
|
||||
"""Render the full HTML body for the runtime/session view."""
|
||||
error_block = ""
|
||||
if snapshot.fetch_error:
|
||||
error_block = (
|
||||
f'<div class="health-card health-stale"><strong>Partial load:</strong> '
|
||||
f"{escape(snapshot.fetch_error)}</div>"
|
||||
)
|
||||
if snapshot.runtime.fetch_error:
|
||||
error_block += (
|
||||
f'<div class="health-card health-stale"><strong>Runtime note:</strong> '
|
||||
f"{escape(snapshot.runtime.fetch_error)}</div>"
|
||||
)
|
||||
|
||||
body = f"""
|
||||
{error_block}
|
||||
{_runtime_banner(snapshot)}
|
||||
{_summary_bar(snapshot)}
|
||||
|
||||
<div class="prompt-card">
|
||||
<h3>Sessions</h3>
|
||||
<p class="muted">Control-plane sessions correlated with leases and worktree bindings.
|
||||
Stale and contamination flags are fail-soft: absence of a marker is not proof of cleanliness when inventory is degraded.
|
||||
Lease and worktree columns read <em>unknown (inventory …)</em> when their source could not be loaded.</p>
|
||||
{_ownership_caveat(snapshot)}
|
||||
{_sessions_table(snapshot)}
|
||||
</div>
|
||||
|
||||
{_namespaces_section(snapshot)}
|
||||
{_worktrees_section(snapshot)}
|
||||
{_contamination_section(snapshot.contamination_markers)}
|
||||
{_recovery_section(snapshot)}
|
||||
"""
|
||||
return render_page(title="Sessions", body_html=f"""<h2>Runtime and sessions</h2>
|
||||
<p class="meta">Phase 1 read-only view (#641). Combines runtime health (#430) with
|
||||
unified inventory sessions/namespaces/worktrees (#636). No restart or session-takeover controls.</p>
|
||||
{body}""")
|
||||
@@ -278,8 +278,10 @@ def _recovery_card() -> str:
|
||||
"controls arrive in Phase 2 (#642); until then recovery runs through "
|
||||
"the sanctioned client reconnect / operator restart path.</p>"
|
||||
"<ul class='reasons'>"
|
||||
"<li><a href='/runtime'>Runtime and session view</a> — active profile, "
|
||||
"workflow hashes, and shell health.</li>"
|
||||
"<li><a href='/runtime'>Runtime health</a> — active profile, workflow "
|
||||
"hashes, and shell health.</li>"
|
||||
"<li><a href='/sessions'>Runtime and sessions</a> — namespaces, session "
|
||||
"rows, worktree bindings, and contamination markers (#641).</li>"
|
||||
"<li>Reconnect the MCP client from the IDE, then re-run the blocked "
|
||||
"cycle. Never kill the daemon process manually: unmanaged kills are "
|
||||
"recorded as runtime contamination (#630).</li>"
|
||||
|
||||
Reference in New Issue
Block a user