Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
266 commits
Select commit Hold shift + click to select a range
71d53fc
Supply explicit query bounds in real Vespa smoke
rohans0509 Sep 30, 2026
adfc89e
Pin CI Vespa to the verified engine image
rohans0509 Sep 30, 2026
b65dea7
Build and verify the staging container in CI without publishing
rohans0509 Sep 30, 2026
d3e0649
Select captured calendars and revoke withdrawn or inaccessible scopes
rohans0509 Sep 30, 2026
9e6c9fd
test: verify owned source lifecycle across fresh processes
rohans0509 Sep 30, 2026
086577d
Reuse private HTTP handoff for actual Calendar consumer proof
rohans0509 Sep 30, 2026
ad3ee37
Exercise captured blob projection and owned search against real Vespa
rohans0509 Sep 30, 2026
264609c
test: bound full Drive lifecycle and report incomplete capture
rohans0509 Sep 30, 2026
9aefba3
Expose the verified container build through the maintainer Makefile
rohans0509 Sep 30, 2026
e6626ca
test: verify full Drive capture and fresh changes-token resume
rohans0509 Sep 30, 2026
408b4ec
Reconcile lost container membership without retaining readable metadata
rohans0509 Sep 30, 2026
5cf771f
fix: honor Slack retry windows across managed transport
rohans0509 Sep 30, 2026
2ebd710
Allow source workers without optional OCR and document staging depend…
rohans0509 Sep 30, 2026
71ac92f
test: exercise Slack and Wispr lifecycle failure boundaries
rohans0509 Sep 30, 2026
0f1922b
Expose verified captured Gmail thread identity in owned search
rohans0509 Sep 30, 2026
2e7c311
test: verify persisted service key authorization over record HTTP routes
rohans0509 Sep 30, 2026
834f87e
Persist fenced whole-scope scan pages and bounded reconciliation
rohans0509 Sep 30, 2026
c4422e4
test: retain Slack backoff deadline evidence and fix cancellation fix…
rohans0509 Sep 30, 2026
2ce5196
fix: require positive critical dependency health for staging readiness
rohans0509 Sep 30, 2026
272980c
fix: retry critical Temporal initialization through process startup
rohans0509 Sep 30, 2026
13e5b46
docs: distinguish actual staging pool limits from cost estimates
rohans0509 Sep 30, 2026
4856e25
Fence scoped capture with durable cycle ownership and finalization
rohans0509 Sep 30, 2026
b19e655
Allow explicit fenced CAS restart of unfinished capture cycles
rohans0509 Sep 30, 2026
63f4718
test: preserve Gmail locator observation provenance
rohans0509 Sep 30, 2026
b682686
Resume Slack pages through fenced canonical capture cycles
rohans0509 Sep 30, 2026
0889448
Preserve source-audited reasons when withdrawing unavailable scopes
rohans0509 Sep 30, 2026
6a5b35b
Capture selected Linear issue scopes through canonical pages
rohans0509 Sep 30, 2026
1b46aac
test: verify bounded cross-process Slack capture resume
rohans0509 Sep 30, 2026
82464bd
Wire owned file storage into durable page capture
rohans0509 Sep 30, 2026
02deb92
Retain bounded Linear files and project captured originals offline
rohans0509 Sep 30, 2026
d796f92
Preserve status classification for unread source error streams
rohans0509 Sep 30, 2026
01719fc
Confirm Linear scope loss through exact-ID connections
rohans0509 Sep 30, 2026
6344225
Read exact captured Calendar identities with bounded version resolution
rohans0509 Sep 30, 2026
ebb0bbd
Pin private staging dependencies and separate schema bootstrap
rohans0509 Sep 30, 2026
587e741
Exercise real MiniLM retrieval against synthetic Vespa corpus
rohans0509 Sep 30, 2026
7073a6e
Preserve Vespa date units and fractional filter boundaries
rohans0509 Sep 30, 2026
4061dfb
Use actual transformer readiness endpoint across runtime and deployment
rohans0509 Sep 30, 2026
638c86a
Keep readiness test fixture compliant with lint
rohans0509 Sep 30, 2026
792d4d7
Exercise actual BM25 document and query vectors in search baseline
rohans0509 Sep 30, 2026
4e180f9
Prefilter canonical dates and types with explicit scoped re-projection
rohans0509 Sep 30, 2026
1bf91a3
Exercise canonical type and unknown date prefilter exclusions
rohans0509 Sep 30, 2026
b825159
Initialize new canonical syncs with current projection metadata version
rohans0509 Sep 30, 2026
45f0ef5
Include document titles in default keyword retrieval
rohans0509 Sep 30, 2026
2e30c5b
Make unknown-date and wrong-type fixtures independently match date bo…
rohans0509 Sep 30, 2026
fc8e91c
Exercise canonical source captures and sync creation in correctness c…
rohans0509 Sep 30, 2026
dc036d9
Attest canonical record forest visibility across ancestor changes
rohans0509 Sep 30, 2026
d433a8e
Support nested capture scopes with exact parent ownership
rohans0509 Sep 30, 2026
4b70525
feat: capture selected GitHub originals with durable nested recovery
rohans0509 Sep 30, 2026
37e6526
fix: confirm GitHub issue transfers before withdrawing old scope
rohans0509 Sep 30, 2026
2508288
Distinguish discovery policies from exhaustive scope reconciliation
rohans0509 Sep 30, 2026
10c6549
Prove completed discovery cycles remain explicitly incomplete
rohans0509 Sep 30, 2026
fd8a777
Resume Wispr meeting capture through durable discovery scopes
rohans0509 Sep 30, 2026
f8104da
Correct Wispr trial documentation after page-source migration
rohans0509 Sep 30, 2026
7438ee6
Add bounded cross-process Wispr recovery proof mode
rohans0509 Sep 30, 2026
0dce24a
Admit verified discovery roots atomically with canonical scan pages
rohans0509 Sep 30, 2026
dff605a
Diagnose Wispr setup failures without retaining private errors
rohans0509 Sep 30, 2026
21958fa
Allow account-bound Notion API proxy transport
rohans0509 Sep 30, 2026
2479e0e
Verify managed account and explicit user identities
rohans0509 Sep 30, 2026
cf14b4e
Preserve discovery policy when validating page pipeline topology
rohans0509 Sep 30, 2026
19776c5
Record bounded Wispr capture and incomplete live recovery proof
rohans0509 Sep 30, 2026
2318901
Record bounded Wispr interruption result and remaining proof budget
rohans0509 Sep 30, 2026
78e7f37
Record verified live Wispr fresh-process recovery
rohans0509 Sep 30, 2026
5b6c061
Capture native Notion roots and blocks with explicit discovery limits
rohans0509 Sep 30, 2026
3790883
Document verified live Wispr body recovery without full-sync claims
rohans0509 Sep 30, 2026
6fb78b3
Keep a rolling Notion cursor history without limiting pagination
rohans0509 Sep 30, 2026
b37c245
Project retained Notion metadata and block text for search
rohans0509 Sep 30, 2026
2bb84cf
Retain complete native Notion property responses atomically per property
rohans0509 Sep 30, 2026
3f6d496
Bound Gmail history page hydration and validate replay identity
rohans0509 Sep 30, 2026
45b9286
Separate full capture evidence from fenced provider changes checkpoints
rohans0509 Sep 30, 2026
aa6d358
Wire checkpointed page sources through existing capture lifecycle
rohans0509 Sep 30, 2026
75e318b
Verify full capture metadata in indexed search response
rohans0509 Sep 30, 2026
d557252
Distinguish verified inference CI from pending staging readiness
rohans0509 Sep 30, 2026
7d42c8a
Prepare bounded fresh-process Gmail recovery probe
rohans0509 Sep 30, 2026
0ac9abe
Restart Slack inventory when a queued thread disappears
rohans0509 Sep 30, 2026
75d85b5
Capture Gmail through resumable baseline and history pages
rohans0509 Sep 30, 2026
6c45db8
Supply explicit sync mode in live lifecycle context
rohans0509 Sep 30, 2026
965f6e6
Exercise actual Gmail lifecycle child with synthetic provider
rohans0509 Sep 30, 2026
cd423b8
Record bounded live Gmail recovery and cleanup evidence
rohans0509 Sep 30, 2026
912ee37
Record failed bounded Gmail query trial without completion claim
rohans0509 Sep 30, 2026
d9f9629
Restore Gmail request retries and verify failed-job continuation
rohans0509 Sep 30, 2026
1b28bf7
Retry bounded Gmail proxy transients without early rate-limit retries
rohans0509 Sep 30, 2026
06d9ec6
Capture Drive files with durable full and changes pages
rohans0509 Sep 30, 2026
3357dd4
Use disposable fixture database in offline lifecycle child test
rohans0509 Sep 30, 2026
de7ed36
Discard Calendar delta token when occurrence access is lost
rohans0509 Sep 30, 2026
35cb5fb
Record two completed Gmail query cycles after retry correction
rohans0509 Sep 30, 2026
4617267
Verify Drive lifecycle against durable page checkpoints
rohans0509 Sep 30, 2026
b61f73b
Persist fenced per-scope full and changes capture evidence
rohans0509 Sep 30, 2026
323b8f4
Record live Drive delta proof and migrate lifecycle harnesses
rohans0509 Sep 30, 2026
7bbcdf6
Export SQL mixed coverage after completed change scopes
rohans0509 Sep 30, 2026
6d9cabf
Capture Calendar scopes durably and publish authorized observed ranges
rohans0509 Sep 30, 2026
826a2c1
Verify Calendar lifecycle from published scoped checkpoints
rohans0509 Sep 30, 2026
6987d61
Record live scoped Calendar delta and HTTP consumer proof
rohans0509 Sep 30, 2026
33e7ed2
Report live token reuse independently of full capture evidence
rohans0509 Sep 30, 2026
f47eb90
Retain native Slack timestamps for canonical date filters
rohans0509 Sep 30, 2026
b070aab
Record existing Drive account native Docs access proof
rohans0509 Sep 30, 2026
fc7ae61
Define retained Docs representations without changing legacy blob hashes
rohans0509 Sep 30, 2026
89aadd0
feat: read and project retained native Google Docs
rohans0509 Sep 30, 2026
6927ca1
feat(records): authorize exact stored native document reads
rohans0509 Sep 30, 2026
2fc0868
Capture native Docs and export representations under Drive ownership
rohans0509 Sep 30, 2026
85603b0
test: qualify stored Docs capture through fresh HTTP reader
rohans0509 Sep 30, 2026
9b44828
test: record bounded live Docs storage and HTTP verification
rohans0509 Sep 30, 2026
69d0296
test: connect document capture probe to the Almanac CLI consumer
rohans0509 Sep 30, 2026
8927e48
test: record real Docs capture through Almanac CLI
rohans0509 Sep 30, 2026
d6c8d3e
fix: reject ambiguous Wispr text continuation markers
rohans0509 Sep 30, 2026
1e5d1c6
fix: preserve safe Wispr rate signals without invented retry timing
rohans0509 Sep 30, 2026
9f34ade
Capture native Attio records and memberships with durable note pagina…
rohans0509 Sep 30, 2026
11bd8cc
feat: project retained Attio originals with managed account binding
rohans0509 Sep 30, 2026
d6f74e2
Capture Wispr scratchpad notes with durable inventory and body recovery
rohans0509 Sep 30, 2026
eded561
Project retained Wispr scratchpad notes into search
rohans0509 Sep 30, 2026
01cd82b
Run all owned source projection contracts in capture verification
rohans0509 Sep 30, 2026
ec3338f
fix(gmail): retry structured native quota failures without losing evi…
rohans0509 Sep 30, 2026
d5a906b
test(gmail): cover malformed quota response bytes
rohans0509 Sep 30, 2026
20ad9a5
Qualify Wispr resume probes for mixed meeting and scratchpad capture
rohans0509 Sep 30, 2026
d4f9885
Keep Gmail error tests focused on distinct failure boundaries
rohans0509 Sep 30, 2026
ddb5ea5
Index retained Gmail body when attachment capture is partial
rohans0509 Sep 30, 2026
4a63b6b
Require pinned native mailbox identity before owned Gmail capture
rohans0509 Sep 30, 2026
466fa92
Allow retained XLSX files through the search text pipeline
rohans0509 Sep 30, 2026
28f8fe9
Gate owned Calendar capture on pinned primary calendar identity
rohans0509 Sep 30, 2026
ab8d043
Label Calendar probe evidence by native primary identity
rohans0509 Sep 30, 2026
2b00e3d
Require native Drive principal attestation for owned capture
rohans0509 Sep 30, 2026
918e459
Require explicit trusted Google identities in owned capture configura…
rohans0509 Sep 30, 2026
b54561d
Reject limited Slack history before exhaustive reconciliation
rohans0509 Sep 30, 2026
b661c73
Update native Docs recovery fixture for Drive identity attestation
rohans0509 Sep 30, 2026
77a096a
Attest Slack workspace and user before owned capture
rohans0509 Sep 30, 2026
337a1be
Add durable owned provisioning intent and capture generation schema
rohans0509 Sep 30, 2026
2f0479a
Publish truthful per-part extraction coverage with partial searchable…
rohans0509 Sep 30, 2026
4b1f67c
Fence source construction with authoritative job generation admission
rohans0509 Sep 30, 2026
63c99f8
Fence capture by verified connection generation and integrate extract…
rohans0509 Sep 30, 2026
39fd26e
Provision owned sources with durable generation and execution recovery
rohans0509 Sep 30, 2026
21fb93c
Support reversible owned capture pause with preserved native identity
rohans0509 Sep 30, 2026
d509000
Require owned provisioning and scheduling recovery checks in CI
rohans0509 Sep 30, 2026
25a0561
Provision Slack capture with native workspace and user binding
rohans0509 Sep 30, 2026
498c4cd
Record bounded Wispr identity probe and native attestation limitation
rohans0509 Sep 30, 2026
4adfc99
Add strict idempotent exact-object storage deletion for projection cl…
rohans0509 Sep 30, 2026
fcc1ec0
Retain complete derived text with index publication and fenced reads
rohans0509 Sep 30, 2026
f36abeb
Include retained text schema in live capture proof
rohans0509 Sep 30, 2026
bb49abe
Add retained local evaluation through owned capture and search APIs
rohans0509 Sep 30, 2026
f63f36e
Project retained Gmail bodies despite native size drift and unavailab…
rohans0509 Sep 30, 2026
0f9427e
Report uncaptured Drive originals as unavailable extraction
rohans0509 Sep 30, 2026
48af3ec
Extend retained trials with native Calendar and Slack identities
rohans0509 Sep 30, 2026
bf4aa3b
Batch exact publication checks across search candidates
rohans0509 Sep 30, 2026
147c472
Assert Wispr recovery against the actual failed scope
rohans0509 Sep 30, 2026
0758d17
Reuse query embeddings within owned multi-collection searches
rohans0509 Sep 30, 2026
0f98717
Record repeated search stage timings and follow-up boundaries
rohans0509 Sep 30, 2026
e37d018
Cancel owned index search when its HTTP client disconnects
rohans0509 Sep 30, 2026
a539e40
Record native Vespa and worker latency decomposition
rohans0509 Sep 30, 2026
71fc2f4
Project only retained search card fields during enrichment
rohans0509 Oct 1, 2026
bc26255
Capture bounded native Sheets under existing Drive ownership
rohans0509 Oct 1, 2026
30a88f9
Prove blank Sheets ranges preserve coverage with shared bytes
rohans0509 Oct 1, 2026
a32b61d
Release search database connections across remote waits
rohans0509 Oct 1, 2026
3af25e4
Wire retained spreadsheet reads and phase-owned search route
rohans0509 Oct 1, 2026
0bb78eb
Compare repeated capture evidence without exposing originals
rohans0509 Oct 1, 2026
3002471
Never refresh provider credentials for unauthenticated file downloads
rohans0509 Oct 1, 2026
f8fa47a
Account for retained and unavailable Slack attachment parts
rohans0509 Oct 1, 2026
626abd0
Allow canonical file capture to reject native redirects
rohans0509 Oct 1, 2026
a12eb51
Define retained Slack file acquisition evidence
rohans0509 Oct 1, 2026
919001e
Validate Slack file acquisition manifests during projection
rohans0509 Oct 1, 2026
8c50d87
Validate declared file response MIME before retaining bytes
rohans0509 Oct 1, 2026
7ecc975
Capture Slack originals before page progress commits
rohans0509 Oct 1, 2026
f2fe8ba
Attest full child scope parent epochs before acquisition
rohans0509 Oct 1, 2026
3d57a1c
List authorized direct children by canonical parent record ID
rohans0509 Oct 1, 2026
db2159b
Project durable Slack file children under explicit capture topology
rohans0509 Oct 1, 2026
e02c940
Capture Slack files as resumable message-owned children
rohans0509 Oct 1, 2026
11d6c83
Verify Slack membership with configured capture topology
rohans0509 Oct 1, 2026
495c6b7
Preserve native Slack bodies in shared retained text projection
rohans0509 Oct 1, 2026
0a09f43
Add typed Cohere embedding adapter with explicit query intent
rohans0509 Oct 1, 2026
4b29b18
Add isolated retrieval relevance and latency evaluation
rohans0509 Oct 1, 2026
1e4421e
Admit native snapshots with authoritative revision ordering
rohans0509 Oct 1, 2026
7bf81fd
Batch native snapshot admission reads under the writer lock
rohans0509 Oct 1, 2026
6240946
Project native knowledge and original conversation text into shared s…
rohans0509 Oct 1, 2026
5231b9e
Treat canonical search locators without web URLs as valid
rohans0509 Oct 1, 2026
915489d
ci: exercise native ingestion and retrieval evaluation
rohans0509 Oct 1, 2026
ff58a84
fix: reserve native source mutations for import lifecycle
rohans0509 Oct 1, 2026
92da4c8
Compose native snapshot admission with atomic scan pages
rohans0509 Oct 1, 2026
7c36559
test: qualify native test modules in combined store suite
rohans0509 Oct 1, 2026
36c45fc
Add backend-only immutable native source binding API
rohans0509 Oct 1, 2026
136faf0
feat: persist native import identity and atomic writer start
rohans0509 Oct 1, 2026
4dc2b65
Expose authenticated native import start and recovery
rohans0509 Oct 1, 2026
378a675
feat: retain atomic native page retry receipts
rohans0509 Oct 1, 2026
d281362
Bound native import child work to observed membership
rohans0509 Oct 1, 2026
278965a
feat: expose native scope capture and recovery workflow
rohans0509 Oct 1, 2026
ff99a07
Finalize native imports with durable capture outcomes
rohans0509 Oct 1, 2026
fd8fb64
fix: route native job cancellation through import ownership
rohans0509 Oct 1, 2026
53d819d
test: surface early search failures and clean up interrupted probes
rohans0509 Oct 1, 2026
7c9bf4c
docs: describe current native import lifecycle without stale gates
rohans0509 Oct 1, 2026
0e5604f
test: align Vespa fixture with embedding purpose contract
rohans0509 Oct 1, 2026
b4678a1
Publish staged native snapshots with resumable bounded imports
rohans0509 Oct 1, 2026
955c65b
Add bounded native import operator CLI without server credentials
rohans0509 Oct 1, 2026
cd5d380
Route native retained records through canonical projection activity
rohans0509 Oct 1, 2026
4fab962
Keep native imports outside provider timeout maintenance
rohans0509 Oct 1, 2026
6ad087b
Select bounded fresh projection work for native recovery
rohans0509 Oct 1, 2026
0513c37
Recover pending native publications through existing Temporal mainten…
rohans0509 Oct 1, 2026
e7fa08f
ci: verify owned projection recovery workflows
rohans0509 Oct 1, 2026
ff9f227
Bind Outlook managed Graph reads to an attested native principal
rohans0509 Oct 1, 2026
0d44705
Keep raw HTTP transport traces out of service debug logs
rohans0509 Oct 1, 2026
1822eee
Retain resumable mailbox-owned Outlook originals and project MIME off…
rohans0509 Oct 1, 2026
a37f5dd
Wire owned Outlook originals into source lifecycle
rohans0509 Oct 1, 2026
f28bc5b
Batch root coverage evidence without changing sync authority
rohans0509 Oct 1, 2026
fd08ffb
Allow isolated worker control and metrics bindings
rohans0509 Oct 1, 2026
a35cd82
fix: flush verified source readiness before job admission
rohans0509 Oct 1, 2026
654f2b8
fix: recover mislabeled UTF-8 MIME text with extraction evidence
rohans0509 Oct 1, 2026
c36c757
fix: serialize validated source configuration for JSON persistence
rohans0509 Oct 1, 2026
65559cc
fix: preserve Drive representation omissions in search coverage
rohans0509 Oct 1, 2026
73ae112
Add bounded optional local OCR and per-file fallback
rohans0509 Oct 1, 2026
e5785db
Reject disabled Composio accounts and auth configurations
rohans0509 Oct 1, 2026
eb07ba7
Retain Wispr notes when transcripts are explicitly absent
rohans0509 Oct 1, 2026
3791d83
Load publication visibility with the locked canonical record
rohans0509 Oct 1, 2026
780a3aa
Report explicitly judged duplicate crowding in retrieval evaluation
rohans0509 Oct 1, 2026
9d2872b
Add account-bound Stripe original capture and offline projection
rohans0509 Oct 1, 2026
07979dd
Bound Stripe capture response bodies through streamed reads
rohans0509 Oct 1, 2026
31a18dd
Provision Stripe captures without allowing reconnect scope changes
rohans0509 Oct 1, 2026
06b9a3b
Rerank validated owned-source candidates through the existing model port
rohans0509 Oct 1, 2026
4861594
Group eligible conversation matches while preserving exact originals
rohans0509 Oct 1, 2026
908d2ab
Preserve extraction evidence when converting grouped matches
rohans0509 Oct 1, 2026
b7484e2
test: cover scoped retrieval across all Vespa schemas
rohans0509 Oct 1, 2026
86414dc
Preserve scoped semantic candidates with standard filtered HNSW trave…
rohans0509 Oct 1, 2026
d4f2a68
Distinguish conversation ranking from displayed-original relevance
rohans0509 Oct 1, 2026
20774df
Capture Outlook folder deltas with mailbox-owned recovery checkpoints
rohans0509 Oct 1, 2026
191739d
Validate omitted Slack messages without treating them as channels
rohans0509 Oct 1, 2026
32d56eb
Preserve Slack recovery with fenced exact attachment-owner validation
rohans0509 Oct 1, 2026
3dbaedf
Reject unversioned Wispr multi-range captures
rohans0509 Oct 1, 2026
6d805a6
Bound Wispr streamed responses and retained body archives
rohans0509 Oct 1, 2026
fae431a
Provision owned Linear and Attio sources with fixed workspace scope
rohans0509 Oct 1, 2026
0773676
Qualify GitHub native identity and standalone provisioning
rohans0509 Oct 1, 2026
14dcea8
Bind Notion provisioning and capture to native workspace and bot
rohans0509 Oct 1, 2026
a1dd4f6
Project retained Notion property archives without provider fetches
rohans0509 Oct 1, 2026
572a19c
Add fenced native record withdrawal and explicit access renewal
rohans0509 Oct 1, 2026
1784e39
Preserve native filenames on retained source blobs
rohans0509 Oct 1, 2026
a0f9687
Index selected structured fields from native knowledge originals
rohans0509 Oct 1, 2026
32038d6
Retain Outlook calendar originals with resumable scoped capture and o…
rohans0509 Oct 1, 2026
45e959c
Capture verified Slack file children before history completes
rohans0509 Oct 1, 2026
c56fa88
Project authenticated canonical records during active capture
rohans0509 Oct 1, 2026
ab03a34
Include projection admission workflow gates in worker checks
rohans0509 Oct 1, 2026
46ca83d
Attest child inventories atomically with fresh source pages
rohans0509 Oct 1, 2026
f10e456
Wake and serialize worker shutdown across startup and signal handlers
rohans0509 Oct 1, 2026
380b4db
Evaluate delivered search cards against frozen source identities
rohans0509 Oct 1, 2026
7c7d06a
Add frozen-corpus HTTP search replay and pure wire models
rohans0509 Oct 1, 2026
3fdf1c4
Use production HTTP app in retained evaluation server
rohans0509 Oct 2, 2026
95318cc
Keep indexed record read contract independent of provider setup
rohans0509 Oct 2, 2026
cdc5b94
feat(search): preserve full chunks while selecting lexical snippets
rohans0509 Oct 2, 2026
bd2739d
test(search): qualify lexical snippets against real Vespa in CI
rohans0509 Oct 2, 2026
c0632c2
Render Vespa fragment separators as plain text
rohans0509 Oct 2, 2026
4c938cc
Document real Vespa snippet qualification and rollout limits
rohans0509 Oct 2, 2026
807505b
Share provider-scoped policy for intentional search exclusions
rohans0509 Oct 2, 2026
94fb371
Attest complete selected transcripts without reconciling other sessions
rohans0509 Oct 2, 2026
2bf2c55
Use valid native originals in grouping and visibility fixtures
rohans0509 Oct 2, 2026
48fbd5d
test: remove superseded private Wispr listing mapper check
rohans0509 Oct 2, 2026
d1e3685
fix: preserve Wispr transcript range text boundaries
rohans0509 Oct 2, 2026
d54209e
fix: preserve plain Gmail content when HTML alternative is empty
rohans0509 Oct 2, 2026
b4dcc13
test: cover change-feed continuation after access withdrawal
rohans0509 Oct 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
14 changes: 6 additions & 8 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -14,15 +14,15 @@ REDIS_HOST=localhost
REDIS_PORT=6379

# Authentication
# Generated by start.sh if empty
FIRST_SUPERUSER=
# Generated by start.sh if empty
FIRST_SUPERUSER_PASSWORD=
# Local demo bootstrap only; omit these in api_key mode.
# FIRST_SUPERUSER=
# FIRST_SUPERUSER_PASSWORD=
ENCRYPTION_KEY=
AUTH_ENABLED=false
AUTH_MODE=api_key
# Opt into AUTH_MODE=local only for isolated local development.
STATE_SECRET=

# Auth0 Configuration (required if AUTH_ENABLED=true)
# Auth0 Configuration (required if AUTH_MODE=auth0)
AUTH0_DOMAIN=
AUTH0_AUDIENCE=
AUTH0_RULE_NAMESPACE=
Expand Down Expand Up @@ -123,8 +123,6 @@ ADDITIONAL_CORS_ORIGINS=
# Other Settings
PROJECT_NAME=Airweave
LOG_LEVEL=INFO
RUN_ALEMBIC_MIGRATIONS=true
RUN_DB_SYNC=true
CODE_SUMMARIZER_ENABLED=false

SVIX_URL=http://localhost:8071
Expand Down
8 changes: 2 additions & 6 deletions .github/workflows/monke.yml
Original file line number Diff line number Diff line change
@@ -1,13 +1,9 @@
name: Monke – parallel runners

on:
# The owned fork uses credential-free source-store checks on pull requests.
# Upstream's live connector mutators require separate disposable accounts.
workflow_dispatch:
pull_request:
paths:
# Only trigger on platform-related changes (reduced footprint)
- "monke/**"
- "backend/airweave/platform/**"
- ".github/workflows/monke.yml"

concurrency:
group: monke-${{ github.ref }}
Expand Down
126 changes: 126 additions & 0 deletions .github/workflows/owned-source-store.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,126 @@
name: Owned source store

on:
pull_request:
branches: [dev, main]
paths:
- backend/**
- evaluation/**
- vespa/app/**
- Makefile
- .github/workflows/owned-source-store.yml
push:
branches: [dev]
paths:
- backend/**
- evaluation/**
- vespa/app/**
- Makefile
- .github/workflows/owned-source-store.yml

permissions:
contents: read

concurrency:
group: owned-store-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

jobs:
evaluation:
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405
with:
python-version: '3.13'
- name: Verify offline retrieval metrics and file boundaries
run: |
python -m venv .venv-evaluation
.venv-evaluation/bin/python -m pip install ir-measures==0.4.3 pydantic==2.11.9 pytest==8.3.5
.venv-evaluation/bin/python -m pytest evaluation/tests -q --confcutdir=evaluation

correctness:
runs-on: ubuntu-latest
timeout-minutes: 25
services:
vespa:
image: vespaengine/vespa@sha256:5c30f5c41e7563498c4f925db6a837a3848f04726a3ed26aed4a7c8ab69f18fd
ports:
- 8081:8081
- 19071:19071
options: >-
--hostname vespa
--health-cmd "curl -f http://localhost:19071/state/v1/health"
--health-interval 10s --health-timeout 5s --health-retries 30
minilm:
image: semitechnologies/transformers-inference@sha256:c9c13f047ee31488e686c4a7b2ea7ccfcdec16ee825447450dc047cf97791590
env:
ENABLE_CUDA: '0'
ports:
- 8080:8080
options: --memory=2g --cpus=2
postgres:
image: postgres:16.15
env:
POSTGRES_USER: sync_test
POSTGRES_PASSWORD: disposable-ci-only
POSTGRES_DB: sync_tests
ports:
- 5432:5432
options: >-
--health-cmd "pg_isready -U sync_test -d sync_tests"
--health-interval 5s --health-timeout 5s --health-retries 10
env:
CANONICAL_TEST_DATABASE_URL: postgresql+asyncpg://sync_test:disposable-ci-only@localhost:5432/sync_tests
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405
with:
python-version: '3.13'
- uses: snok/install-poetry@76e04a911780d5b312d89783f7b1cd627778900a
with:
version: 2.3.2
virtualenvs-create: true
virtualenvs-in-project: true
- name: Install locked dependencies
working-directory: backend
run: poetry install --with dev,lint --no-root --no-interaction
- name: Verify durable records and publication
run: make test-store
- name: Verify source capture and transport
run: make test-capture
- name: Verify connection provisioning and recovery
run: make test-provisioning
- name: Verify indexed retrieval and visibility
run: make test-search
- name: Verify service authentication
run: make test-auth
- name: Verify dependency readiness
run: make test-health
- name: Verify OCR execution boundaries and fallback
run: make test-ocr
- name: Verify projection recovery and maintenance workflows
run: make test-worker
- name: Record tested Vespa image
run: docker image inspect vespaengine/vespa@sha256:5c30f5c41e7563498c4f925db6a837a3848f04726a3ed26aed4a7c8ab69f18fd --format '{{json .RepoDigests}}'
- name: Verify real Vespa schema and retrieval
env:
OWNED_VESPA_TEST: '1'
OWNED_MINILM_TEST: '1'
EMBEDDING_DIMENSIONS: '384'
run: make test-index

image:
needs: correctness
runs-on: ubuntu-latest
timeout-minutes: 25
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd
- name: Build the deployable image without publishing
run: make build IMAGE=almanac-source-store:ci
- name: Verify packaged Python and entrypoint syntax
run: |
docker run --rm --entrypoint python almanac-source-store:ci -m compileall -q airweave
docker run --rm --entrypoint /bin/sh almanac-source-store:ci -n /app/entrypoint.sh
docker run --rm --entrypoint python almanac-source-store:ci -m scripts.smoke_local_ocr --tessdata /usr/share/tessdata
67 changes: 67 additions & 0 deletions Makefile
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
.DEFAULT_GOAL := help
BACKEND := backend
PYTHON := .venv/bin/python
PYTEST := .venv/bin/pytest
IMAGE ?= almanac-source-store:local

.PHONY: help setup check test-store test-provisioning test-capture test-search test-auth test-health test-worker test-ocr test-index validate-deploy build

help:
@echo 'setup Install the locked backend and development dependencies'
@echo 'build Build the backend image locally; set IMAGE to choose its tag'
@echo 'test-store Verify record transactions and publication on disposable PostgreSQL'
@echo 'test-capture Verify source capture, transport and blob handling'
@echo 'test-search Verify search services and visibility behavior'
@echo 'test-auth Verify service-key and source authorization boundaries'
@echo 'test-health Verify dependency probes and readiness behavior'
@echo 'test-worker Verify owned projection, recovery and maintenance workflows'
@echo 'test-ocr Verify local OCR boundaries and per-file fallback'
@echo 'test-index Deploy/test schemas on explicitly disposable local Vespa'
@echo 'check Run store, capture, search, authentication and health checks'
@echo 'validate-deploy Validate the Porter application manifest locally (no deployment)'
@echo ''
@echo 'test-store requires CANONICAL_TEST_DATABASE_URL; it creates and removes test schemas.'
@echo 'See deploy/README.md for staging prerequisites and explicit deployment steps.'

build:
docker build --tag "$(IMAGE)" $(BACKEND)

validate-deploy:
porter apply validate -f porter.yaml

setup:
cd $(BACKEND) && POETRY_VIRTUALENVS_IN_PROJECT=true uvx --from poetry==2.3.2 poetry install --with dev,lint --no-root --no-interaction

test-store:
@test -n "$$CANONICAL_TEST_DATABASE_URL" || (echo 'Set CANONICAL_TEST_DATABASE_URL to a disposable PostgreSQL database.' >&2; exit 1)
cd $(BACKEND) && $(PYTEST) -q -o log_cli=false airweave/domains/entities/canonical/tests airweave/domains/native_ingestion/tests airweave/domains/syncs/tests

test-capture:
cd $(BACKEND) && $(PYTEST) -q -o log_cli=false airweave/platform/sources/tests tests/unit/platform/sources/records tests/unit/platform/sources/test_*_capture.py tests/unit/domains/entities tests/unit/platform/http_client/test_composio_transport.py tests/unit/platform/http_client/test_logging_privacy.py airweave/domains/storage/tests/test_file_service.py

test-provisioning:
@test -n "$$CANONICAL_TEST_DATABASE_URL" || (echo 'Set CANONICAL_TEST_DATABASE_URL to a disposable PostgreSQL database.' >&2; exit 1)
cd $(BACKEND) && $(PYTEST) -q -o log_cli=false airweave/domains/owned_provisioning/tests airweave/domains/source_connections/tests airweave/domains/temporal/tests airweave/domains/sources/tests/test_lifecycle.py airweave/domains/sync_pipeline/tests/test_factory.py

test-search:
cd $(BACKEND) && $(PYTEST) -q -o log_cli=false airweave/domains/search airweave/domains/embedders
PYTHONPATH=$(BACKEND):. $(BACKEND)/$(PYTEST) -q -o log_cli=false $(BACKEND)/tests/unit/search/test_owned_evaluation.py $(BACKEND)/tests/unit/search/test_owned_replay.py

test-auth:
cd $(BACKEND) && $(PYTEST) -q -o log_cli=false airweave/api/tests/test_service_auth.py airweave/api/tests/test_sync_authorization.py airweave/api/tests/test_context_resolver_auth.py

test-health:
cd $(BACKEND) && $(PYTEST) -q -o log_cli=false airweave/core/health/tests airweave/adapters/health/tests airweave/core/container/tests/test_health_wiring.py

test-worker:
@test -n "$$CANONICAL_TEST_DATABASE_URL" || (echo 'Set CANONICAL_TEST_DATABASE_URL to a disposable PostgreSQL database.' >&2; exit 1)
cd $(BACKEND) && $(PYTEST) -q -o log_cli=false airweave/domains/temporal/activities/tests/test_project_canonical_records.py airweave/domains/temporal/activities/tests/test_discover_native_projection.py airweave/domains/temporal/activities/tests/test_cleanup_stuck_sync_jobs.py airweave/domains/temporal/workflows/tests/test_native_projection_recovery.py airweave/domains/temporal/workflows/tests/test_source_projection_replay.py airweave/domains/temporal/workflows/tests/test_reproject_command.py airweave/domains/temporal/workflows/tests/test_cleanup_workflows.py airweave/domains/temporal/workflows/tests/test_canonical_projection.py airweave/domains/temporal/worker/tests/test_wiring.py airweave/domains/temporal/worker/tests/test_config.py airweave/domains/temporal/worker/tests/test_worker.py airweave/domains/temporal/worker/tests/test_worker_ocr_guard.py

test-ocr:
cd $(BACKEND) && $(PYTEST) -q -o log_cli=false airweave/domains/ocr/tests airweave/core/container/tests/test_ocr_wiring.py

test-index:
@test "$$OWNED_VESPA_TEST" = 1 || (echo 'Set OWNED_VESPA_TEST=1 only for a disposable Vespa at localhost:8081/19071; this deploys schemas.' >&2; exit 1)
cd $(BACKEND) && $(PYTEST) -q -o log_cli=false tests/integration/test_owned_vespa.py tests/integration/test_canonical_search_prefilters.py airweave/domains/entities/canonical/tests/test_real_vespa_projection.py

check: test-store test-provisioning test-capture test-search test-auth test-health test-worker test-ocr
7 changes: 7 additions & 0 deletions backend/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,13 @@ COPY pyproject.toml poetry.lock ./
RUN --mount=type=cache,target=/opt/poetry-cache \
poetry install --only=main --no-interaction --no-ansi --no-root

# Optional local OCR models: pinned upstream artifacts, verified by BuildKit.
# Inference never downloads weights. Enable explicitly with LOCAL_OCR_TESSDATA_PATH.
ADD --chmod=644 --checksum=sha256:7d4322bd2a7749724879683fc3912cb542f19906c83bcc1a52132556427170b2 https://raw.githubusercontent.com/tesseract-ocr/tessdata_fast/87416418657359cb625c412a48b6e1d6d41c29bd/eng.traineddata /usr/share/tessdata/eng.traineddata
ADD --chmod=644 --checksum=sha256:4c73ffc59d497c186b19d1e90f5d721d678ea6b2e277b719bee4e2af12271825 https://raw.githubusercontent.com/tesseract-ocr/tessdata_fast/87416418657359cb625c412a48b6e1d6d41c29bd/hin.traineddata /usr/share/tessdata/hin.traineddata

ADD --chmod=644 --checksum=sha256:cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30 https://raw.githubusercontent.com/tesseract-ocr/tessdata_fast/87416418657359cb625c412a48b6e1d6d41c29bd/LICENSE /usr/share/tessdata/LICENSE

# Copy entrypoint script with proper permissions
COPY --chmod=755 entrypoint.sh /app/entrypoint.sh

Expand Down
55 changes: 55 additions & 0 deletions backend/SERVICE_AUTH.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
# Standalone service authentication and database setup

Use `AUTH_MODE=api_key` for the owned service. Every ordinary API request needs
an existing organization-scoped `X-API-Key`. The default is `api_key`: omitting
credentials does not select a demo user. This mode makes no Auth0 network calls
and does not create users from service credentials. User-only routes still
require user authentication; existing Connect sessions retain their own token
and scope checks. Auth0 mode preserves the existing user-first authentication
precedence when both user and API-key credentials are supplied.

`AUTH_MODE=auth0` retains hosted Auth0 user authentication and API-key access.
The existing Auth0 configuration remains required in that mode.
`AUTH_MODE=local` explicitly enables insecure demo authentication and is allowed
only for `ENVIRONMENT=local` or `test`. Never deploy local mode. The deprecated
`AUTH_ENABLED=true/false` is accepted as a migration input mapping to auth0/local;
contradicting it with AUTH_MODE is an error. Remove AUTH_ENABLED when adopting
AUTH_MODE. The environment label is operator-controlled, not an isolation boundary.

Keys are checked against persisted credentials on every request; expiry and
revocation take effect without waiting for a key-to-organization cache. All
record and job authorization still uses the key's organization. Authenticated
sync SSE subscriptions authorize job ownership before subscribing.

## Explicit database setup

Neither API startup nor the container entrypoint migrates the database or seeds
users, organizations, or keys. `RUN_ALEMBIC_MIGRATIONS` is no longer a runtime
switch. Run setup as a separately authorized deployment job with reviewed,
isolated database credentials:

```sh
# From backend/, against the intended isolated target only:
poetry run alembic upgrade head
poetry run python -m airweave.db.bootstrap
```

The second command installs native destination definitions and the initial embedding
metadata. Ordinary startup validates that metadata without inserting it. Service
mode does not require FIRST_SUPERUSER or FIRST_SUPERUSER_PASSWORD; these are
local bootstrap inputs only. Provision the
intended service organization and key through the existing model/CRUD operator
workflow, store the key in secret management, then start the API and workers.
Do not print keys in logs. Runtime replicas should not need migration privileges.
Temporal database setup is separate and must also target isolated resources.

For a disposable local demo only:

```sh
AUTH_MODE=local poetry run python -m airweave.db.bootstrap --local-superuser
```

This opts into the legacy demo user/org/key provisioning. It is refused in
api_key or auth0 mode. The production entrypoint starts Uvicorn without reload.
Almanac/WorkOS remains end-user identity authority; this service does not
introduce an independent customer login system.
10 changes: 8 additions & 2 deletions backend/airweave/adapters/health/temporal.py
Original file line number Diff line number Diff line change
Expand Up @@ -15,17 +15,23 @@ class TemporalHealthProbe(HealthProbe):
"""Probes Temporal via the gRPC health check on its service client."""

def __init__(self, get_client: Callable[[], TemporalClientType | None]) -> None:
"""Use the application's current connection without creating a probe-owned client."""
self._get_client = get_client

@property
def name(self) -> str:
"""Identify this dependency in readiness configuration and responses."""
return "temporal"

async def check(self) -> DependencyCheck:
"""Report the actual service health, or skipped until a client is available."""
client = self._get_client()
if client is None:
return DependencyCheck(status=CheckStatus.skipped)
start = time.perf_counter()
await client.service_client.check_health()
serving = await client.service_client.check_health()
latency = (time.perf_counter() - start) * 1000
return DependencyCheck(status=CheckStatus.up, latency_ms=round(latency, 2))
return DependencyCheck(
status=CheckStatus.up if serving else CheckStatus.down,
latency_ms=round(latency, 2),
)
13 changes: 11 additions & 2 deletions backend/airweave/adapters/health/tests/test_health_probes.py
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,6 @@

from airweave.schemas.health import CheckStatus


# ---------------------------------------------------------------------------
# PostgresHealthProbe
# ---------------------------------------------------------------------------
Expand Down Expand Up @@ -104,7 +103,7 @@ async def test_client_available_returns_up(self):
from airweave.adapters.health.temporal import TemporalHealthProbe

client = MagicMock()
client.service_client.check_health = AsyncMock()
client.service_client.check_health = AsyncMock(return_value=True)
probe = TemporalHealthProbe(lambda: client)

result = await probe.check()
Expand All @@ -114,6 +113,16 @@ async def test_client_available_returns_up(self):
assert result.latency_ms >= 0
client.service_client.check_health.assert_awaited_once()

@pytest.mark.asyncio
async def test_server_not_serving_returns_down(self):
from airweave.adapters.health.temporal import TemporalHealthProbe

client = MagicMock()
client.service_client.check_health = AsyncMock(return_value=False)
result = await TemporalHealthProbe(lambda: client).check()

assert result.status == CheckStatus.down

@pytest.mark.asyncio
async def test_client_available_but_unhealthy(self):
from airweave.adapters.health.temporal import TemporalHealthProbe
Expand Down
4 changes: 2 additions & 2 deletions backend/airweave/adapters/identity/auth0.py
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@
wait_exponential,
)

from airweave.core.config import settings
from airweave.core.config import AuthMode, settings
from airweave.core.logging import logger
from airweave.core.protocols.identity import (
IdentityProvider,
Expand Down Expand Up @@ -416,7 +416,7 @@ async def add_enabled_connection_to_organization(
# ---------------------------------------------------------------------------

auth0_management_client: Optional[Auth0ManagementClient] = None
if settings.AUTH_ENABLED:
if settings.AUTH_MODE == AuthMode.AUTH0:
auth0_management_client = Auth0ManagementClient()


Expand Down
Loading
Loading