Repository navigation
Conversation
The gates measured dw_mcp and ui/src but never read them. Records both surveys, and that every gate's UI SLOC counted only .ts (pygount reads .svelte as 0 lines). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- upload_asset confined a source to the session's workspace even when the call named another (#389's twin in assets._remote_roots) - get_output_frames' hear excerpts now share the response budget with the tiles, so a reply stays under MAX_RETURNED_BYTES - the startup probe reads a 401 from the status, not the message text (a server on port 4010 read as a token problem) - a bad DW_MCP_MAX_WAIT_SECONDS keeps the default with a warning rather than failing the import, and dw.serve's --mcp mount with it - get_gallery_metadata tolerates a job block without an id - ASSESSMENT_PROBES deleted: the server owns the whitelist and its 400 reaches the caller - tests/test_mcp_twins.py pins each copied constant and tool-text word list to its engine owner, and checks every tool that takes acknowledged_cost refuses without it - seam map: rows for the copies and dw.run as a client; the consent row covers all seven gated tools; stale owner comments corrected See docs/stabilization/mcp-assessment.md. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The UI's turn at the engine stabilization's approach: ratchet and baseline first, then the five rules the UI and engine disagree on, then one owner per rule, primitives (Bits UI, not Bootstrap), structure, and guardrails. The UI survey moves to docs/stabilization/ui/ASSESSMENT.md. ui/scripts/arch-metrics.mjs is drafted with the plan; Phase 0 Task 1 tests it, records the baseline and wires the CI check. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…proved Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… them Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…dio included Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… one Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- step_end events carry output_kinds, so a running job's outputs render inline before the manifest exists (the detail's map covered only the manifest) - a from_previous_result spelled as a reference (variable:source) is checked as that reference, as the engine leaves it, not flagged - the flow graph's chips and edges resolve references through the same resolver as the dangling check: a dotted name or a for_each member reference gets its producer Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
UI stabilization Phase 0: ratchet and baseline, .svelte counted in the gate report, U1-U5 fixed, twin pins, seam-map rows. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ges 2 and 3 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…pins Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… alone Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…cknowledgement Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The job carries its own run directory and output root, so the server resolves both; a job still queued or running is refused (409), which the client never checked. The run-directory removal moves to dw/server/outputs.py, shared with the gallery delete. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… mode calls it merge_patch (RFC 7396) moves to dw/library.py. PUT and PATCH share one lock, so a save landing between a patch's read and its write is no longer lost; the client's GET-merge-PUT is gone. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…tops restating the thresholds level_findings (dw/server/assess.py) reads dw/audio_qc.py's thresholds at call time. The client's next hint points at findings; the Music 3 ceiling sentence goes - the minimax-music3 skill owns it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
dw/server/inline_media.py fits and budgets images for an inline answer; the frames route encodes its tiles through it. base64_size joins dw/media.py, which projected_wav_base64_size already computed inline. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…rver/inline_media.py The rise: one new server module, dw/server/inline_media.py, approved in docs/stabilization/ui/phase-1.md (Task 1b-6). It replaces image fitting and budgeting that dw_mcp/media.py and the frames route each did on their own; dw_mcp's copy is deleted later in the same task. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…de states the gate's result Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
The score function must include description per spec. The ranking test failure was due to the fixture's default description "Blocky voxel look" containing the query term. Changed entry() default description to "Blocky 3D look" so tests properly differentiate scoring between entries. Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…sample_rate (it relabels); log per-track lengths and padding Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…elete Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Real-Hub smoke (Qwen/Qwen-Image-2.1, 'voxel style'): no error, 1 row prithivMLmods/Qwen-Image-2.1-Voxel-Style, license 'other', multiple_weights. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…idates Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
…ot rule, not shot_boundary, when in-shot windows existed Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…loras/recommend - Limit search terms to MAX_SEARCH_TERMS=4 to prevent unbounded amplification - Use single threading.Lock() to prevent concurrent Hub searches and thread stacking - Implement proper daemon thread lifecycle with join(timeout) - Lock released only when worker finishes, not at timeout, preventing hung searches - Query parameter max_length=200 to bound input size - Report BUSY_ERROR on concurrent requests instead of queuing - Add tests for term capping, concurrent busy, and lock lifecycle Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
Wrap threading.Thread() and worker.start() in try-except to release _IN_FLIGHT lock if either operation raises. Thread creation failures (e.g., thread exhaustion) could previously leave the lock held, deadlocking all subsequent Hub searches until server restart. - For Exception: return error message (maintain never-raises contract) - For non-Exception BaseException: re-raise (server fault) - Add test_a_thread_that_cannot_start_releases_the_lock - Add boundary test for 200-character query (accepted, status 200) Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… rows, skill pointer Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Four modules the approved design names: dw/lora_catalog.py (catalog rules, no network), dw/lora_hub.py (the only Hub search), dw/server/routes/loras.py (routes), dw_mcp/loras.py (MCP client calls). Spec: docs/superpowers/specs/2026-10-03-lora-catalog-design.md. Needs Don's arch-approved waiver. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…epts a list Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ry, document routes Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… wording Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… recommender Modules baseline 171 -> 175 approved by Don (arch-approved, 2026-10-03). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
minimax-h3 SKILL.md conflict: took origin's tightened text (#585); the list_loras pointer is dropped - the merged file has no byte headroom under the 12,288 cap, the same ruling as the LTX-2.5 skill. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Reformatted multi-line data structures for better clarity in lora_catalog.py, lora_hub.py, loras.py, and other files. - Enhanced readability by breaking long lines and aligning parameters in function calls. - Updated test cases in test_lora_catalog.py, test_lora_hub.py, test_mcp_loras.py, and test_server_loras.py to follow consistent formatting. - Ensured consistent use of parentheses and indentation across various functions and methods. - Improved error handling messages for better debugging insights.
…tures, security fixes, and improvements
CodeQL py/stack-trace-exposure on GET /api/loras/recommend: search_hub put the raw exception message into hub_error, so an OSError from the HF cache (or a proxy/SSL error) could hand a client the server's home directory - the leak class GHSA-fwg5-jfjg-fxpf closed for job errors. hub_error is now "Hub search failed (<Type>)", or "(HTTP <status>)" when the error carries a response; the full error goes to the log. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release 0.8.0 - notes in docs/RELEASING.md (### 0.8.0). CI green on a81086f; preflight passed locally.