Compare commits

..
Author SHA1 Message Date
eSlider e04b037b33 feat: parse all Go CLIs with flaggy; dump bash complete.
Tests / Test (push) Skipped
Tests / OCR (tesseract fixture) (push) Skipped
Tests / Release (semver) (push) Skipped
Tests / Test (pull_request) Failing after 6s
Tests / OCR (tesseract fixture) (pull_request) Failing after 4s
Tests / Release (semver) (pull_request) Skipped
stdlib flag dropped --hop after the query. One wrapper in internal/cli,
source <(./bin/cli/complete.go bash). Gitea #34.
2026-08-14 12:08:52 +01:00
43 changed files with 57 additions and 1770 deletions
-6
View File
@@ -14,9 +14,3 @@ go.work.local
models/ models/
# Purged from git history. Do not re-add. # Purged from git history. Do not re-add.
docs/crm-associations-proof.md docs/crm-associations-proof.md
# mount scaffold for the 8TB volume, never part of the repo
mnt/
# go build ./bin/mail/sync.go drops a binary named `sync` in cwd
/sync
+1 -15
View File
@@ -53,7 +53,6 @@ bin/qa/ stats.go (DuckDB quantiles / JSONL count; gcc CGO, not Zig)
bin/watch/ corpus watcher (used by bin/brain/watch.go) bin/watch/ corpus watcher (used by bin/brain/watch.go)
bin/tools/ vendored python libs behind bin/* (kblib, yamlout, websearch) bin/tools/ vendored python libs behind bin/* (kblib, yamlout, websearch)
bin/cgo/ zig zcc zc++ (CGO via zig cc, not gcc) bin/cgo/ zig zcc zc++ (CGO via zig cc, not gcc)
bin/stack/ start start-assistant stop status (compose + PicoClaw agent)
bin/docker-entrypoint container entrypoint (api: serve|search|watch; index: python) bin/docker-entrypoint container entrypoint (api: serve|search|watch; index: python)
compose.yaml docker composition (root level, not docker/) compose.yaml docker composition (root level, not docker/)
Dockerfile api (Zig CGO, no Python) + index (Python write) Dockerfile api (Zig CGO, no Python) + index (Python write)
@@ -66,20 +65,12 @@ var/ kb.lbug, var/mail/*, caches (gitignored)
```bash ```bash
bin/mail/sync.go --source onlyoffice,gmail --workers 8 --out var/mail # raw message.json + attachments bin/mail/sync.go --source onlyoffice,gmail --workers 8 --out var/mail # raw message.json + attachments
bin/mail/sync.go --source gmail --query 'from:example.com' --out var/mail # Gmail search (default in:inbox) bin/mail/sync.go --source gmail --query 'from:example.com' --out var/mail # Gmail search (default in:inbox)
bin/mail/sync.go --source m365 --env ~/.config/brain/mail.env --out var/mail # Microsoft Graph (delta)
bin/mail/import.go --from-raw var/mail # message.json → message.md (convert only) bin/mail/import.go --from-raw var/mail # message.json → message.md (convert only)
bin/brain/index.go --rebuild --with-facts --with-chats bin/brain/index.go --rebuild --with-facts --with-chats
bin/stack/start-mail-sync # compose ETL: sync→import every 300s
``` ```
- `sync` (Go) downloads messages + attachments; Gmail uses paginated list + - `sync` (Go) downloads messages + attachments; Gmail uses paginated list +
`body.attachmentId` (not partId) for attachments. Sources: `onlyoffice`, `body.attachmentId` (not partId) for attachments.
`gmail`, `m365` (client-credentials + delta link; commit after success).
- Compose `mail-sync` / `bin/stack/start-mail-sync`: ETL loop (default
`onlyoffice,gmail`, 300s). On `new>0` runs import; full `--rebuild` only if
`MAIL_SYNC_INDEX=1`. Secrets: `~/.config/brain/mail.env` + `~/.gmail-mcp`.
Case wrappers (e.g. family `gmail-sync-la-quinta.sh`) and ai-bot
`gmail-reauth.sh` reuse this sync/OAuth — do not fork corpus download.
- `import` converts body + attachments to markdown. PDFs use poppler - `import` converts body + attachments to markdown. PDFs use poppler
`pdftotext -layout` fast path (~15ms); textless/scanned PDFs use `pdftotext -layout` fast path (~15ms); textless/scanned PDFs use
`pdftoppm` + tesseract `eng+deu` (`bin/mail/ocr.go`). Optional `pdftoppm` + tesseract `eng+deu` (`bin/mail/ocr.go`). Optional
@@ -97,7 +88,6 @@ bin/facts/audit.go ["self"|"db"|"contradict"] # 2-source + D16 adjudication
bin/facts/crm.go [--dry-run] # proof person↔company/company↔project (ooCRM × corpus SoT) bin/facts/crm.go [--dry-run] # proof person↔company/company↔project (ooCRM × corpus SoT)
bin/kb/search "query" [--repo X] # deprecated wrapper → bin/brain/search.go bin/kb/search "query" [--repo X] # deprecated wrapper → bin/brain/search.go
bin/brain/search.go "query" [--root facts|info] # deduction search → YAML bin/brain/search.go "query" [--root facts|info] # deduction search → YAML
bin/brain/search.go "query" --as-of 2025-01-01 # D24 fact intervals
bin/brain/search.go "query" --no-web # local graph only bin/brain/search.go "query" --no-web # local graph only
source <(./bin/cli/complete.go bash) # flaggy completions (D23) source <(./bin/cli/complete.go bash) # flaggy completions (D23)
eval "$(bin/cgo/zig env)" # Zig cc + liblbug (not gcc) eval "$(bin/cgo/zig env)" # Zig cc + liblbug (not gcc)
@@ -108,10 +98,6 @@ bin/brain/get.go <id> [--body] [--json] # Go read; Python bin/kb/get CI
bin/brain/stats.go [--json] bin/brain/stats.go [--json]
bin/brain/eval.go [--json] # recall@5; questions in internal/brain/rank bin/brain/eval.go [--json] # recall@5; questions in internal/brain/rank
bin/brain/serve.go # HTTP :8630; GET /openapi.json POST /mcp bin/brain/serve.go # HTTP :8630; GET /openapi.json POST /mcp
bin/stack/start # brain HTTP/MCP (reuse healthy :8630)
bin/stack/start-assistant # + reasoner + PicoClaw agent
bin/stack/status # YAML health
bin/stack/stop # compose stop; volumes kept
bin/markdown/import.go [dir] # H2 leafs → YAML; Python bin/md/import fallback bin/markdown/import.go [dir] # H2 leafs → YAML; Python bin/md/import fallback
bin/git/import.go [REPO] [--json] [--limit N] # go-git history → commit leafs bin/git/import.go [REPO] [--json] [--limit N] # go-git history → commit leafs
bin/web/search.go "query" [--json] # SearXNG; throttled ≠ absence bin/web/search.go "query" [--json] # SearXNG; throttled ≠ absence
-10
View File
@@ -6,15 +6,6 @@
# API: Go + ladybug via Zig CGO (no CPython). # API: Go + ladybug via Zig CGO (no CPython).
# Index: Python write path (profile `index` until brain/add is v2). # Index: Python write path (profile `index` until brain/add is v2).
# --- mail-sync: standalone M365/OnlyOffice/Gmail puller (pure Go, no CGO) ---
FROM golang:1.26-bookworm AS mail-build
WORKDIR /src
COPY go.mod go.sum ./
RUN go mod download
COPY bin/mail ./bin/mail
COPY internal ./internal
RUN CGO_ENABLED=0 go build -o /mail-sync ./bin/mail/sync.go
# --- Python sidecar (Ladybug write / rebuild) --- # --- Python sidecar (Ladybug write / rebuild) ---
FROM python:3.12-slim AS index FROM python:3.12-slim AS index
@@ -37,7 +28,6 @@ RUN python -m pip install --no-cache-dir -r /tmp/requirements.lock.txt \
COPY . . COPY . .
RUN chmod +x /app/bin/docker-entrypoint \ RUN chmod +x /app/bin/docker-entrypoint \
&& chown -R 2dph:2dph /app && chown -R 2dph:2dph /app
COPY --from=mail-build /mail-sync /app/bin/mail-sync
USER 2dph USER 2dph
ENV PATH="/app/bin:${PATH}" \ ENV PATH="/app/bin:${PATH}" \
+5 -16
View File
@@ -9,8 +9,7 @@ v2 board: milestone [v2](https://git.produktor.io/eSlider/2dph/milestone/13) —
OCR [#6](https://git.produktor.io/eSlider/2dph/issues/6) in, OCR [#6](https://git.produktor.io/eSlider/2dph/issues/6) in,
[#29](https://git.produktor.io/eSlider/2dph/issues/29) OQ1 in, [#29](https://git.produktor.io/eSlider/2dph/issues/29) OQ1 in,
[#30](https://git.produktor.io/eSlider/2dph/issues/30) OQ3 in, [#30](https://git.produktor.io/eSlider/2dph/issues/30) OQ3 in,
[#34](https://git.produktor.io/eSlider/2dph/issues/34) D23 in, [#34](https://git.produktor.io/eSlider/2dph/issues/34) D23 in.
[#36](https://git.produktor.io/eSlider/2dph/issues/36) OQ5/D24 in.
Gap: [docs/roadmap.md](docs/roadmap.md). Gap: [docs/roadmap.md](docs/roadmap.md).
## What ## What
@@ -54,7 +53,6 @@ detective method: **a fact needs ≥2 independent sources or it is
| D21 | CGO | Ladybug/tokenizers CGO is compiled with **Zig** (`bin/cgo/zcc``zig cc -target …-linux-gnu`), not gcc. `bin/cgo/zig` pins Zig 0.14.1 + liblbug 0.19.1 + libtokenizers 1.27.0. Compose `target: api` has no CPython; write/rebuild is profile `index`. | | D21 | CGO | Ladybug/tokenizers CGO is compiled with **Zig** (`bin/cgo/zcc``zig cc -target …-linux-gnu`), not gcc. `bin/cgo/zig` pins Zig 0.14.1 + liblbug 0.19.1 + libtokenizers 1.27.0. Compose `target: api` has no CPython; write/rebuild is profile `index`. |
| D22 | analytics | **duckdb-go** in-process (`internal/duckstats`, `bin/qa/stats.go`) for quantiles/JSONL. Links with **gcc/g++**, not Zig. Ladybug stays the graph; web-search cache stays modernc sqlite. Slice small structured docs with **mikefarah/yq**, not kislyuk/jq. [#30](https://git.produktor.io/eSlider/2dph/issues/30). | | D22 | analytics | **duckdb-go** in-process (`internal/duckstats`, `bin/qa/stats.go`) for quantiles/JSONL. Links with **gcc/g++**, not Zig. Ladybug stays the graph; web-search cache stays modernc sqlite. Slice small structured docs with **mikefarah/yq**, not kislyuk/jq. [#30](https://git.produktor.io/eSlider/2dph/issues/30). |
| D23 | CLI | **flaggy** (`github.com/integrii/flaggy`, 0 deps). Flags at any position. Wrapper `internal/cli`. Bash complete: `source <(./bin/cli/complete.go bash)`. No cobra, no stdlib `flag` in Go tools. Search does not intercept the word `completion`. [#34](https://git.produktor.io/eSlider/2dph/issues/34). | | D23 | CLI | **flaggy** (`github.com/integrii/flaggy`, 0 deps). Flags at any position. Wrapper `internal/cli`. Bash complete: `source <(./bin/cli/complete.go bash)`. No cobra, no stdlib `flag` in Go tools. Search does not intercept the word `completion`. [#34](https://git.produktor.io/eSlider/2dph/issues/34). |
| D24 | fact intervals | Leaf `valid_from` / `valid_to` (YYYY-MM-DD, inclusive; empty = open/legacy). Search `--as-of` / MCP `as_of` keeps facts active that day. Not D16 `temporal_freshness` (source stale vs HEAD). Empty interval = always visible. [#36](https://git.produktor.io/eSlider/2dph/issues/36). |
## Architecture ## Architecture
@@ -86,7 +84,6 @@ detective method: **a fact needs ≥2 independent sources or it is
mail/ocr.go tesseract eng+deu (pdftoppm scans) mail/ocr.go tesseract eng+deu (pdftoppm scans)
md/import (deprecated; bin/markdown/import.go) md/import (deprecated; bin/markdown/import.go)
brain/extract brain/audit brain/deduce (thinking wrapper) brain/extract brain/audit brain/deduce (thinking wrapper)
stack/start start-assistant start-mail-sync stop status
web/search (deprecated shim → web/search.go) web/search (deprecated shim → web/search.go)
db/psql-yq (vendored) db/psql-yq (vendored)
ssh-tunnel onlyoffice pg tunnel 5433 ssh-tunnel onlyoffice pg tunnel 5433
@@ -104,8 +101,7 @@ them from each hit (1=File, 2=Commit, 3=Person). Rebuild writes
`Leaf-[:FROM_FILE]->File`; git import writes the rest. `Leaf-[:FROM_FILE]->File`; git import writes the rest.
Common props on every node/edge: `root`, `confidence`, `evidence[]`, `how`, Common props on every node/edge: `root`, `confidence`, `evidence[]`, `how`,
`where`, `when`, `source_rev`. Leaf interval of truth (D24): `valid_from`, `where`, `when`, `source_rev`.
`valid_to`.
## Config ## Config
@@ -136,14 +132,11 @@ Common props on every node/edge: `root`, `confidence`, `evidence[]`, `how`,
quantiles / JSONL count. Not a second graph. [#30](https://git.produktor.io/eSlider/2dph/issues/30). quantiles / JSONL count. Not a second graph. [#30](https://git.produktor.io/eSlider/2dph/issues/30).
- OQ4: YAML-first storage for leafs — deferred: JSON is ~10x faster to - OQ4: YAML-first storage for leafs — deferred: JSON is ~10x faster to
serialize and unambiguous; YAML only where humans edit files. serialize and unambiguous; YAML only where humans edit files.
- OQ5: **in** — fact `valid_from` / `valid_to` + `--as-of` / MCP `as_of` (D24).
Not D16 `temporal_freshness`. [#36](https://git.produktor.io/eSlider/2dph/issues/36).
## Mail pipeline (done) ## Mail pipeline (done)
1. `bin/mail/sync.go` (Go, 8 workers) — paginated Gmail / OnlyOffice / M365 1. `bin/mail/sync.go` (Go, 8 workers) — paginated Gmail/OnlyOffice download.
Graph download. Gmail attachments key off `body.attachmentId`, not MIME Gmail attachments key off `body.attachmentId`, not MIME `partId`.
`partId`. M365 uses client-credentials + delta link (commit after success).
2. `bin/mail/import.go --from-raw` — message.json → message.md; PDFs via 2. `bin/mail/import.go --from-raw` — message.json → message.md; PDFs via
`pdftotext -layout` (~15ms); textless/scanned PDFs `pdftoppm` + tesseract `pdftotext -layout` (~15ms); textless/scanned PDFs `pdftoppm` + tesseract
`eng+deu`. ICS sidecars `eng+deu`. ICS sidecars
@@ -152,11 +145,7 @@ Common props on every node/edge: `root`, `confidence`, `evidence[]`, `how`,
corrupts its WAL on bulk-insert into an already-indexed DB. Conversion and corrupts its WAL on bulk-insert into an already-indexed DB. Conversion and
indexing stay separate for crash safety. `bin/mail/index_mail` is a indexing stay separate for crash safety. `bin/mail/index_mail` is a
deprecation shim. deprecation shim.
4. Compose `mail-sync` / `bin/stack/start-mail-sync` — ETL loop (default 4. Result: 17,835 messages → 28,918 info leafs, FTS + HNSW healthy, searchable
`onlyoffice,gmail`, 300s): sync → import on `new>0`; full rebuild only if
`MAIL_SYNC_INDEX=1`. Bot digests (ai-bot) and case wrappers reuse sync/OAuth;
they do not replace the corpus path.
5. Result: 17,835 messages → 28,918 info leafs, FTS + HNSW healthy, searchable
via `bin/brain/search.go`. via `bin/brain/search.go`.
## CI/CD pipeline (D15) ## CI/CD pipeline (D15)
-6
View File
@@ -119,8 +119,6 @@ Mail is a first-class corpus (retrievable through the same search):
```bash ```bash
bin/mail/sync.go --source onlyoffice,gmail --workers 8 --out var/mail # raw sync (Go) bin/mail/sync.go --source onlyoffice,gmail --workers 8 --out var/mail # raw sync (Go)
bin/mail/sync.go --source m365 --env ~/.config/brain/mail.env # Microsoft 365 Graph
bin/stack/start-mail-sync # compose ETL (300s; no auto-rebuild)
bin/mail/import.go --from-raw var/mail # JSON → markdown bin/mail/import.go --from-raw var/mail # JSON → markdown
bin/brain/add.go --text T --root facts --source "a.md x b.md" bin/brain/add.go --text T --root facts --source "a.md x b.md"
bin/brain/index.go --rebuild --with-facts --with-chats # facts extract + chats md bin/brain/index.go --rebuild --with-facts --with-chats # facts extract + chats md
@@ -162,10 +160,6 @@ go test ./... && uv run python -m unittest discover -s bin/tools -t .
Docker (optional, cached model + var volumes): Docker (optional, cached model + var volumes):
```bash ```bash
bin/stack/start # brain HTTP/MCP :8630
bin/stack/start-assistant # + qwen3.5:9b + PicoClaw agent
bin/stack/status
bin/stack/stop
docker compose up -d brain # API (Zig CGO serve :8630) docker compose up -d brain # API (Zig CGO serve :8630)
docker compose --profile index run --rm index # Python Ladybug rebuild docker compose --profile index run --rm index # Python Ladybug rebuild
docker compose --profile picoclaw up brain-mcp # MCP on 127.0.0.1:8630 docker compose --profile picoclaw up brain-mcp # MCP on 127.0.0.1:8630
-23
View File
@@ -5,7 +5,6 @@
# serve | search | watch # serve | search | watch
# Index image (Python write path, compose profile `index`): # Index image (Python write path, compose profile `index`):
# index | extract | audit | search (deprecated python wrapper) # index | extract | audit | search (deprecated python wrapper)
# mail-sync [N] ETL loop: sync -> import; optional index (default 300s)
# #
# Usage comment starts at line 2 (self-describing convention). # Usage comment starts at line 2 (self-describing convention).
set -euo pipefail set -euo pipefail
@@ -35,27 +34,5 @@ case "$CMD" in
serve) exec /app/bin/serve "$@" ;; serve) exec /app/bin/serve "$@" ;;
extract) exec "$KB_PY" /app/bin/facts/extract "$@" ;; extract) exec "$KB_PY" /app/bin/facts/extract "$@" ;;
audit) exec "$KB_PY" /app/bin/facts/audit "$@" ;; audit) exec "$KB_PY" /app/bin/facts/audit "$@" ;;
mail-sync)
# ETL: pull mail, convert to md when new>0. Full --rebuild is opt-in
# (MAIL_SYNC_INDEX=1) — ~29k leaf rebuild is minutes, not a 10s loop.
interval="${1:-300}"
[ "$interval" -gt 0 ] 2>/dev/null || interval=300
: "${MAIL_SYNC_ENV:=/secret/mail.env}"
: "${MAIL_SYNC_SRC:=onlyoffice,gmail}"
: "${MAIL_SYNC_OUT:=/app/var/mail}"
: "${MAIL_SYNC_INDEX:=0}"
while true; do
out="$("/app/bin/mail-sync" --source "$MAIL_SYNC_SRC" --env "$MAIL_SYNC_ENV" --out "$MAIL_SYNC_OUT" 2>&1)" || true
echo "$out"
new="$(printf '%s\n' "$out" | sed -n 's/.*new=\([0-9]*\).*/\1/p' | tail -1)"
if [ -n "$new" ] && [ "$new" -gt 0 ] 2>/dev/null; then
"$KB_PY" /app/bin/mail/import --from-raw "$MAIL_SYNC_OUT" 2>&1 | tail -1
if [ "$MAIL_SYNC_INDEX" = "1" ]; then
"$KB_PY" /app/bin/kb/index --rebuild --with-mail 2>&1 | tail -1
fi
fi
sleep "$interval"
done
;;
*) echo "unknown command: $CMD" >&2; exit 2 ;; *) echo "unknown command: $CMD" >&2; exit 2 ;;
esac esac
-6
View File
@@ -65,10 +65,6 @@ def main(argv: list[str]) -> int:
p.add_argument("--how", default="brain/add") p.add_argument("--how", default="brain/add")
p.add_argument("--loc", default="") p.add_argument("--loc", default="")
p.add_argument("--type", default="reference", dest="type_") p.add_argument("--type", default="reference", dest="type_")
p.add_argument("--valid-from", default="", dest="valid_from",
help="fact interval start YYYY-MM-DD (D24)")
p.add_argument("--valid-to", default="", dest="valid_to",
help="fact interval end YYYY-MM-DD inclusive; empty=open (D24)")
args = p.parse_args(argv) args = p.parse_args(argv)
if args.json: if args.json:
@@ -90,8 +86,6 @@ def main(argv: list[str]) -> int:
"how": args.how, "how": args.how,
"loc": args.loc or args.source, "loc": args.loc or args.source,
"type": args.type_, "type": args.type_,
"valid_from": args.valid_from,
"valid_to": args.valid_to,
}] }]
for lf in leafs: for lf in leafs:
+2 -3
View File
@@ -1,9 +1,8 @@
//usr/bin/env go run "$0" "$@"; exit //usr/bin/env go run "$0" "$@"; exit
// bin/mail/sync.go - async download of OnlyOffice, Gmail and M365 mail to var/mail/. // bin/mail/sync.go - async download of OnlyOffice and Gmail mail to var/mail/.
// //
// ./bin/mail/sync.go --source onlyoffice,gmail,m365 --limit 50 --workers 8 // ./bin/mail/sync.go --source onlyoffice,gmail --limit 50 --workers 8
// ./bin/mail/sync.go --source gmail --force // ./bin/mail/sync.go --source gmail --force
// ./bin/mail/sync.go --source m365 --env .secrets/m365.env
// ./bin/mail/sync.go --dry-run // ./bin/mail/sync.go --dry-run
// //
// Writes raw message.json + attachments under var/mail/<folder>/<id>/; run // Writes raw message.json + attachments under var/mail/<folder>/<id>/; run
+3 -22
View File
@@ -55,7 +55,7 @@ func bind(v *flagVals) *flaggy.Parser {
p.Bool(&v.force, "", "force", "overwrite existing message.json") p.Bool(&v.force, "", "force", "overwrite existing message.json")
p.Bool(&v.dryRun, "", "dry-run", "list counts without writing") p.Bool(&v.dryRun, "", "dry-run", "list counts without writing")
p.String(&v.query, "", "query", "Gmail search query") p.String(&v.query, "", "query", "Gmail search query")
p.String(&v.srcs, "", "source", "comma list: onlyoffice,gmail,m365") p.String(&v.srcs, "", "source", "comma list: onlyoffice,gmail")
return p return p
} }
@@ -110,24 +110,6 @@ func ParseCLI(args []string) (CLIConfig, int, error) {
CredentialsPath: filepath.Join(home, ".gmail-mcp", "credentials.json"), CredentialsPath: filepath.Join(home, ".gmail-mcp", "credentials.json"),
KeysPath: filepath.Join(home, ".gmail-mcp", "gcp-oauth.keys.json"), KeysPath: filepath.Join(home, ".gmail-mcp", "gcp-oauth.keys.json"),
} }
case "m365":
tenant := pick(envVars["M365_TENANT"], envVars["MS_TENANT"])
cid := pick(envVars["M365_CLIENT_ID"], envVars["MS_CLIENT_ID"])
sec := pick(envVars["M365_CLIENT_SECRET"], envVars["MS_CLIENT_SECRET"])
users := pick(envVars["M365_USERS"], envVars["MS_USERS"])
if tenant == "" || cid == "" || sec == "" || users == "" {
return CLIConfig{}, 2, fmt.Errorf("m365 source needs M365_TENANT/CLIENT_ID/CLIENT_SECRET/USERS in %s", v.env)
}
var userList []string
for _, u := range strings.Split(users, ",") {
if u = strings.TrimSpace(u); u != "" {
userList = append(userList, u)
}
}
if len(userList) == 0 {
return CLIConfig{}, 2, fmt.Errorf("m365 source: M365_USERS empty")
}
cfg.M365 = &M365Credentials{Tenant: tenant, ClientID: cid, ClientSecret: sec, Users: userList}
default: default:
return CLIConfig{}, 2, fmt.Errorf("unknown source %q", s) return CLIConfig{}, 2, fmt.Errorf("unknown source %q", s)
} }
@@ -144,7 +126,7 @@ func Main(args []string) int {
return code return code
} }
if cfg.Help { if cfg.Help {
fmt.Fprintln(os.Stderr, "usage: bin/mail/sync.go [--source onlyoffice,gmail,m365] [--query GMAIL_Q] [--limit N] [--offset N] [--workers N] [--force] [--dry-run]") fmt.Fprintln(os.Stderr, "usage: bin/mail/sync.go [--source onlyoffice,gmail] [--query GMAIL_Q] [--limit N] [--offset N] [--workers N] [--force] [--dry-run]")
return 0 return 0
} }
ctx, cancel := context.WithTimeout(context.Background(), 6*time.Hour) ctx, cancel := context.WithTimeout(context.Background(), 6*time.Hour)
@@ -187,8 +169,7 @@ func readEnv(path string) map[string]string {
if !ok { if !ok {
continue continue
} }
if strings.HasPrefix(k, "ONLYOFFICE_") || strings.HasPrefix(k, "OO_") || if strings.HasPrefix(k, "ONLYOFFICE_") || strings.HasPrefix(k, "OO_") {
strings.HasPrefix(k, "M365_") || strings.HasPrefix(k, "MS_") {
out[k] = v out[k] = v
} }
} }
-382
View File
@@ -1,382 +0,0 @@
package sync
import (
"context"
"encoding/json"
"errors"
"fmt"
"io"
"net/http"
"net/url"
"os"
"path/filepath"
"strings"
"time"
)
// M365Credentials holds a Microsoft Graph app registration with the Mail.Read
// application permission. Client credentials are read from env/.env, never
// committed.
type M365Credentials struct {
Tenant string
ClientID string
ClientSecret string
Users []string // mailbox addresses to sync, e.g. info@example.com
}
// m365Token is the cached access token with expiry.
type m365Token struct {
AccessToken string
Expiry time.Time
}
// M365Client talks to the Microsoft Graph API using the client-credentials
// flow (app registration with Mail.Read application permission). GET-only:
// messages are never marked as read or deleted.
type M365Client struct {
creds M365Credentials
base string // graph base URL; default https://graph.microsoft.com
tokenEndpoint string // login endpoint; default https://login.microsoftonline.com
client *http.Client
mu chan struct{}
token *m365Token
}
func NewM365Client(creds M365Credentials) (*M365Client, error) {
if creds.Tenant == "" || creds.ClientID == "" || creds.ClientSecret == "" {
return nil, errors.New("m365 needs tenant, client id and client secret")
}
c := &M365Client{
creds: creds,
base: "https://graph.microsoft.com",
client: &http.Client{Timeout: 90 * time.Second},
mu: make(chan struct{}, 1),
}
c.mu <- struct{}{}
return c, nil
}
// accessToken returns a fresh bearer token, refreshing via the Azure AD token
// endpoint when the cached one is missing or about to expire (within 2 min).
func (c *M365Client) accessToken(ctx context.Context) (string, error) {
select {
case <-c.mu:
case <-ctx.Done():
return "", ctx.Err()
}
defer func() { c.mu <- struct{}{} }()
if c.token != nil && c.token.AccessToken != "" && time.Now().Before(c.token.Expiry.Add(-2*time.Minute)) {
return c.token.AccessToken, nil
}
return c.refreshLocked(ctx)
}
func (c *M365Client) refreshLocked(ctx context.Context) (string, error) {
form := url.Values{}
form.Set("grant_type", "client_credentials")
form.Set("client_id", c.creds.ClientID)
form.Set("client_secret", c.creds.ClientSecret)
form.Set("scope", "https://graph.microsoft.com/.default")
endpoint := c.tokenEndpoint
if endpoint == "" {
endpoint = fmt.Sprintf("https://login.microsoftonline.com/%s/oauth2/v2.0/token", c.creds.Tenant)
}
req, err := http.NewRequestWithContext(ctx, http.MethodPost, endpoint, strings.NewReader(form.Encode()))
if err != nil {
return "", err
}
req.Header.Set("Content-Type", "application/x-www-form-urlencoded")
resp, err := c.client.Do(req)
if err != nil {
return "", fmt.Errorf("m365 token: %w", err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(io.LimitReader(resp.Body, 1<<20))
if resp.StatusCode != http.StatusOK {
var e struct {
Error string `json:"error"`
Desc string `json:"error_description"`
}
_ = json.Unmarshal(body, &e)
return "", fmt.Errorf("m365 token status %d: %s (%s)", resp.StatusCode, e.Error, truncate(e.Desc, 200))
}
var out struct {
AccessToken string `json:"access_token"`
ExpiresIn int64 `json:"expires_in"`
}
if err := json.Unmarshal(body, &out); err != nil {
return "", fmt.Errorf("m365 token parse: %w", err)
}
c.token = &m365Token{
AccessToken: out.AccessToken,
Expiry: time.Now().Add(time.Duration(out.ExpiresIn) * time.Second),
}
return out.AccessToken, nil
}
// deltaPage is one response page of the Graph delta query.
type deltaPage struct {
Value []struct {
ID string `json:"id"`
RemovedReason string `json:"@odata.removedReason"`
} `json:"value"`
NextLink string `json:"@odata.nextLink"`
DeltaLink string `json:"@odata.deltaLink"`
}
// ListDeltaIDs walks the inbox delta query and returns live message ids since
// the previous deltaLink (or the full inbox when deltaLink is empty). Returns
// the new deltaLink for the next run. GET-only; nothing is mutated server-side.
func (c *M365Client) ListDeltaIDs(ctx context.Context, mailbox, deltaLink string, limit int) ([]string, string, error) {
var (
ids []string
url string
link = deltaLink
)
if link == "" {
url = fmt.Sprintf("/v1.0/users/%s/mailFolders/inbox/messages/delta", pathEscape(mailbox))
} else {
url = link
}
for url != "" {
var page deltaPage
if err := c.getJSON(ctx, url, &page); err != nil {
return ids, link, err
}
for _, m := range page.Value {
if m.RemovedReason != "" {
continue
}
if m.ID == "" {
continue
}
ids = append(ids, m.ID)
if limit > 0 && len(ids) >= limit {
if page.DeltaLink != "" {
link = page.DeltaLink
}
return ids, link, nil
}
}
if page.DeltaLink != "" {
link = page.DeltaLink
url = ""
break
}
url = page.NextLink
}
return ids, link, nil
}
// GetMessage fetches a single message by id and normalizes it to the Message
// contract. GET-only.
func (c *M365Client) GetMessage(ctx context.Context, mailbox, id string) (*Message, error) {
path := fmt.Sprintf("/v1.0/users/%s/messages/%s?$expand=attachments($select=id,name,contentType,size,isInline)",
pathEscape(mailbox), pathEscape(id))
var raw struct {
ID string `json:"id"`
Subject string `json:"subject"`
From m365Recipient `json:"from"`
ToRecipients []m365Recipient `json:"toRecipients"`
CCRecipients []m365Recipient `json:"ccRecipients"`
BCCRecipients []m365Recipient `json:"bccRecipients"`
ReceivedDateTime string `json:"receivedDateTime"`
Body m365Body `json:"body"`
BodyPreview string `json:"bodyPreview"`
InternetMessageID string `json:"internetMessageId"`
Attachments []m365Attachment `json:"attachments"`
}
if err := c.getJSON(ctx, path, &raw); err != nil {
return nil, err
}
m := &Message{
Source: "m365",
ID: raw.ID,
Folder: "m365",
Subject: raw.Subject,
From: formatRecipient(raw.From),
To: formatRecipients(raw.ToRecipients),
CC: formatRecipients(raw.CCRecipients),
BCC: formatRecipients(raw.BCCRecipients),
MimeMessageID: raw.InternetMessageID,
}
if t, err := time.Parse(time.RFC3339, raw.ReceivedDateTime); err == nil {
m.ReceivedAt = t
}
switch strings.ToLower(raw.Body.ContentType) {
case "html":
m.HTMLBody = raw.Body.Content
if raw.BodyPreview != "" {
m.TextBody = raw.BodyPreview
}
default:
m.TextBody = raw.Body.Content
if raw.BodyPreview != "" {
m.HTMLBody = raw.BodyPreview
}
}
for _, a := range raw.Attachments {
if a.IsInline || a.ID == "" || a.Name == "" {
continue
}
m.Attachments = append(m.Attachments, Attachment{
FileID: a.ID,
FileName: a.Name,
StoredName: a.Name,
Size: a.Size,
ContentType: a.ContentType,
})
}
m.HasAttachments = len(m.Attachments) > 0
return m, nil
}
type m365Recipient struct {
EmailAddress struct {
Name string `json:"name"`
Address string `json:"address"`
} `json:"emailAddress"`
}
type m365Body struct {
ContentType string `json:"contentType"`
Content string `json:"content"`
}
type m365Attachment struct {
ID string `json:"id"`
Name string `json:"name"`
ContentType string `json:"contentType"`
Size int64 `json:"size"`
IsInline bool `json:"isInline"`
ContentID string `json:"contentId"`
}
func formatRecipients(rs []m365Recipient) string {
var parts []string
for _, r := range rs {
if s := formatRecipient(r); s != "" {
parts = append(parts, s)
}
}
return strings.Join(parts, ", ")
}
func formatRecipient(r m365Recipient) string { a := r.EmailAddress.Address
n := r.EmailAddress.Name
switch {
case n == "" || n == a:
return a
case a == "":
return n
default:
return fmt.Sprintf("%s <%s>", n, a)
}
}
// DownloadAttachment fetches an attachment's raw bytes via the /$value stream.
func (c *M365Client) DownloadAttachment(ctx context.Context, mailbox, msgID, attID string) ([]byte, error) {
path := fmt.Sprintf("/v1.0/users/%s/messages/%s/attachments/%s/$value",
pathEscape(mailbox), pathEscape(msgID), pathEscape(attID))
tok, err := c.accessToken(ctx)
if err != nil {
return nil, err
}
req, err := http.NewRequestWithContext(ctx, http.MethodGet, c.base+path, nil)
if err != nil {
return nil, err
}
req.Header.Set("Authorization", "Bearer "+tok)
resp, err := c.client.Do(req)
if err != nil {
return nil, fmt.Errorf("m365 attachment: %w", err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(io.LimitReader(resp.Body, 256<<20))
if resp.StatusCode != http.StatusOK {
return nil, fmt.Errorf("m365 attachment %s: status %d: %s", attID, resp.StatusCode, truncate(string(body), 300))
}
return body, nil
}
func (c *M365Client) getJSON(ctx context.Context, path string, out any) error {
tok, err := c.accessToken(ctx)
if err != nil {
return err
}
u := path
if !strings.HasPrefix(u, "http") {
u = c.base + u
}
req, err := http.NewRequestWithContext(ctx, http.MethodGet, u, nil)
if err != nil {
return err
}
req.Header.Set("Authorization", "Bearer "+tok)
resp, err := c.client.Do(req)
if err != nil {
return fmt.Errorf("m365 %s: %w", path, err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(io.LimitReader(resp.Body, 16<<20))
if resp.StatusCode != http.StatusOK {
return fmt.Errorf("m365 %s: status %d: %s", path, resp.StatusCode, truncate(string(body), 300))
}
if out != nil {
return json.Unmarshal(body, out)
}
return nil
}
// m365Source adapts a mailbox to the Source worker-pool contract. Each mailbox
// gets its own folder under var/mail/m365/<localpart>/ and a delta state file.
type m365Source struct {
c *M365Client
mailbox string
localpart string
stateDir string
pending string // delta link to persist on Commit()
hasPending bool
}
func (s *m365Source) Folder() string { return filepath.Join("m365", s.localpart) }
func (s *m365Source) ListIDs(ctx context.Context, limit int, cursor string) ([]string, string, error) {
link, _ := os.ReadFile(filepath.Join(s.stateDir, s.localpart+".deltalink"))
ids, newLink, err := s.c.ListDeltaIDs(ctx, s.mailbox, strings.TrimSpace(string(link)), limit)
if err != nil {
return nil, "", err
}
// Buffer the new delta link; persist it only in Commit() after the full
// batch downloaded, so a failed run stays retryable without gaps.
if newLink != "" {
s.pending = newLink
s.hasPending = true
}
return ids, "", nil
}
// Commit persists the buffered delta link. Called by the sync runner only when
// every listed message downloaded successfully.
func (s *m365Source) Commit() error {
if !s.hasPending || s.pending == "" {
return nil
}
if err := os.MkdirAll(s.stateDir, 0o755); err != nil {
return err
}
return os.WriteFile(filepath.Join(s.stateDir, s.localpart+".deltalink"), []byte(s.pending), 0o644)
}
func (s *m365Source) Get(ctx context.Context, id string) (*Message, error) {
return s.c.GetMessage(ctx, s.mailbox, id)
}
func (s *m365Source) DownloadAttachment(ctx context.Context, msg *Message, att Attachment) ([]byte, error) {
return s.c.DownloadAttachment(ctx, s.mailbox, msg.ID, att.FileID)
}
func pathEscape(s string) string {
return url.PathEscape(s)
}
-188
View File
@@ -1,188 +0,0 @@
package sync
import (
"context"
"net/http"
"net/http/httptest"
"os"
"path/filepath"
"testing"
)
// newM365TestClient serves the Graph delta + message endpoints against a fake
// token endpoint, so unit tests never touch the network.
func newM365TestClient(t *testing.T, graph http.Handler) *M365Client {
t.Helper()
tok := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
w.Write([]byte(`{"access_token":"test-token","expires_in":3600}`))
}))
gr := httptest.NewServer(graph)
t.Cleanup(func() {
tok.Close()
gr.Close()
})
client, err := NewM365Client(M365Credentials{Tenant: "t.onmicrosoft.com", ClientID: "c", ClientSecret: "s"})
if err != nil {
t.Fatal(err)
}
client.base = gr.URL
client.tokenEndpoint = tok.URL
return client
}
func TestM365AccessToken(t *testing.T) {
c := newM365TestClient(t, http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {}))
got, err := c.accessToken(context.Background())
if err != nil {
t.Fatalf("accessToken: %v", err)
}
if got != "test-token" {
t.Errorf("token = %q", got)
}
// Second call must reuse the cached token (no token request).
again, err := c.accessToken(context.Background())
if err != nil || again != "test-token" {
t.Fatalf("cached token: %q, %v", again, err)
}
}
func TestM365DeltaSkipsTombstones(t *testing.T) {
first := true
graph := http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
if first {
first = false
w.Write([]byte(`{"value":[
{"id":"m1"},
{"id":"m2","@odata.removedReason":"deleted"},
{"id":"m3"}
],"@odata.deltaLink":"` + deltaNext + `"}`))
return
}
// Second call must use the stored deltaLink (points at this server).
if r.URL.Path != "/v1.0/delta-next" {
w.WriteHeader(500)
w.Write([]byte(`{"error":{"message":"unexpected path"}}`))
return
}
w.Write([]byte(`{"value":[{"id":"m4"}],"@odata.deltaLink":"` + deltaFinal + `"}`))
})
c := newM365TestClient(t, graph)
deltaNext = c.base + "/v1.0/delta-next"
deltaFinal = c.base + "/v1.0/delta-final"
ids, link, err := c.ListDeltaIDs(context.Background(), "a@x.de", "", 0)
if err != nil {
t.Fatalf("delta: %v", err)
}
if len(ids) != 2 || ids[0] != "m1" || ids[1] != "m3" {
t.Errorf("ids = %v", ids)
}
if link == "" {
t.Error("expected new deltaLink")
}
// Incremental: pass the deltaLink, get only the new id.
ids2, link2, err := c.ListDeltaIDs(context.Background(), "a@x.de", link, 0)
if err != nil {
t.Fatalf("delta incremental: %v", err)
}
if len(ids2) != 1 || ids2[0] != "m4" {
t.Errorf("ids2 = %v", ids2)
}
if link2 == "" {
t.Error("expected updated deltaLink")
}
}
func TestM365GetMessageNormalizes(t *testing.T) {
graph := http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
if pathLast(r.URL.Path) == "messages" {
w.Write([]byte(`{"value":[{"id":"m1"}]}`))
return
}
w.Write([]byte(`{
"id":"m1",
"subject":"Hallo",
"from":{"emailAddress":{"name":"Max","address":"max@x.de"}},
"toRecipients":[{"emailAddress":{"address":"a@x.de"}}],
"receivedDateTime":"2026-08-14T08:15:00Z",
"body":{"contentType":"html","content":"<p>body</p>"},
"bodyPreview":"body",
"internetMessageId":"<mid@x.de>",
"attachments":[
{"id":"att1","name":"doc.pdf","contentType":"application/pdf","size":10},
{"id":"img1","name":"logo.png","contentType":"image/png","isInline":true}
]
}`))
})
c := newM365TestClient(t, graph)
m, err := c.GetMessage(context.Background(), "a@x.de", "m1")
if err != nil {
t.Fatalf("GetMessage: %v", err)
}
if m.ID != "m1" || m.Subject != "Hallo" || m.From != "Max <max@x.de>" || m.To != "a@x.de" {
t.Errorf("headers mismatch: %+v", m)
}
if m.HTMLBody != "<p>body</p>" {
t.Errorf("html = %q", m.HTMLBody)
}
if m.ReceivedAt.IsZero() {
t.Error("receivedAt zero")
}
if m.MimeMessageID != "<mid@x.de>" {
t.Errorf("mime id = %q", m.MimeMessageID)
}
if len(m.Attachments) != 1 || m.Attachments[0].FileName != "doc.pdf" || m.Attachments[0].FileID != "att1" {
t.Errorf("atts = %+v", m.Attachments)
}
if !m.HasAttachments {
t.Error("expected hasAttachments")
}
}
func TestM365SourceDeltaState(t *testing.T) {
graph := http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
w.Write([]byte(`{"value":[{"id":"m1"}],"@odata.deltaLink":"` + deltaNext + `"}`))
})
c := newM365TestClient(t, graph)
deltaNext = c.base + "/v1.0/delta-next"
stateDir := filepath.Join(t.TempDir(), ".m365")
s := &m365Source{c: c, mailbox: "info@x.de", localpart: "info", stateDir: stateDir}
if s.Folder() != "m365/info" {
t.Errorf("folder = %q", s.Folder())
}
ids, _, err := s.ListIDs(context.Background(), 0, "")
if err != nil {
t.Fatalf("ListIDs: %v", err)
}
if len(ids) != 1 || ids[0] != "m1" {
t.Errorf("ids = %v", ids)
}
if err := s.Commit(); err != nil {
t.Fatalf("Commit: %v", err)
}
data, err := os.ReadFile(filepath.Join(stateDir, "info.deltalink"))
if err != nil {
t.Fatalf("read delta state: %v", err)
}
if string(data) != deltaNext {
t.Errorf("delta state = %q, want %q", string(data), deltaNext)
}
}
func pathLast(p string) string {
for i := len(p) - 1; i >= 0; i-- {
if p[i] == '/' {
return p[i+1:]
}
}
return p
}
// deltaNext/deltaFinal are set per-test from the fake graph server URL so
// deltaLink values always point back at the fake (never the real Graph).
var deltaNext, deltaFinal string
+1 -43
View File
@@ -106,7 +106,6 @@ func Retry(ctx context.Context, policy RetryPolicy, fn func() error) error {
type SyncConfig struct { type SyncConfig struct {
OO *OOConfig // OnlyOffice source (optional) OO *OOConfig // OnlyOffice source (optional)
Gmail *GmailCredentials // Gmail source (optional) Gmail *GmailCredentials // Gmail source (optional)
M365 *M365Credentials // Microsoft 365 Graph source (optional)
Out string // var/mail root; default <repo>/var/mail Out string // var/mail root; default <repo>/var/mail
Workers int // concurrency; default 4 Workers int // concurrency; default 4
Limit int // max messages per source (0 = all) Limit int // max messages per source (0 = all)
@@ -134,14 +133,6 @@ type Source interface {
Folder() string Folder() string
} }
// Committer is an optional Source capability: Commit is called after all listed
// ids have been downloaded successfully. Sources that only advance durable state
// on success (e.g. a Graph delta link) implement this so a killed or failed run
// stays retryable without gaps.
type Committer interface {
Commit() error
}
type ooSource struct { type ooSource struct {
c *OOClient c *OOClient
page int page int
@@ -231,22 +222,8 @@ func Run(ctx context.Context, cfg SyncConfig) (*SyncStats, error) {
} }
sources = append(sources, &gmailSource{c: gm, query: cfg.Query}) sources = append(sources, &gmailSource{c: gm, query: cfg.Query})
} }
if cfg.M365 != nil {
stateDir := filepath.Join(cfg.Out, ".m365")
for _, mb := range cfg.M365.Users {
if !strings.Contains(mb, "@") {
return nil, fmt.Errorf("m365 user %q is not an email address", mb)
}
c, err := NewM365Client(*cfg.M365)
if err != nil {
return nil, fmt.Errorf("m365 init for %s: %w", mb, err)
}
local := strings.SplitN(mb, "@", 2)[0]
sources = append(sources, &m365Source{c: c, mailbox: mb, localpart: strings.ToLower(local), stateDir: stateDir})
}
}
if len(sources) == 0 { if len(sources) == 0 {
return nil, errors.New("sync: no source configured (need OO, Gmail, M365, or a combination)") return nil, errors.New("sync: no source configured (need OO, Gmail, or both)")
} }
stats := &SyncStats{} stats := &SyncStats{}
@@ -319,25 +296,6 @@ func Run(ctx context.Context, cfg SyncConfig) (*SyncStats, error) {
close(jobsCh) close(jobsCh)
wg.Wait() wg.Wait()
// Only advance durable source state (e.g. delta links) when everything
// downloaded. A killed or failed run must be retryable without gaps.
if len(failures) == 0 {
seen := map[Source]bool{}
for _, j := range jobs {
if seen[j.src] {
continue
}
seen[j.src] = true
if c, ok := j.src.(Committer); ok {
if err := c.Commit(); err != nil {
mu.Lock()
failures = append(failures, j.src.Folder()+"/commit: "+err.Error())
mu.Unlock()
}
}
}
}
if len(failures) > 0 { if len(failures) > 0 {
fmt.Fprintf(os.Stderr, "sync: %d failures:\n %s\n", len(failures), strings.Join(failures, "\n ")) fmt.Fprintf(os.Stderr, "sync: %d failures:\n %s\n", len(failures), strings.Join(failures, "\n "))
} }
-248
View File
@@ -1,248 +0,0 @@
# bin/stack/lib.sh — compose helpers for start / start-assistant / stop / status.
# Sourced, not executed. No secrets. No host-absolute paths.
BRAIN_URL="${BRAIN_URL:-http://127.0.0.1:8630}"
REASONER_URL="${REASONER_URL:-http://127.0.0.1:11435}"
PICOCLAW_URL="${PICOCLAW_URL:-http://127.0.0.1:18790}"
REASONER_MODEL="${REASONER_MODEL:-qwen3.5:9b}"
STACK_WAIT_SECS="${STACK_WAIT_SECS:-90}"
STACK_WAIT_INTERVAL="${STACK_WAIT_INTERVAL:-2}"
STACK_PULL_SECS="${STACK_PULL_SECS:-600}"
if [[ -z "${ROOT:-}" ]]; then
STACK_DIR="$(CDPATH= cd -- "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
ROOT="$(CDPATH= cd -- "$STACK_DIR/../.." && pwd)"
fi
stack_usage() {
awk 'NR == 1 { next } /^#/ { sub(/^# ?/, ""); print; next } { exit }' "$1"
}
stack_die() {
echo "bin/stack: $*" >&2
return 1
}
compose() {
docker compose -f "$ROOT/compose.yaml" --project-directory "$ROOT" "$@"
}
http_get() {
local url=$1
local timeout=${2:-5}
curl -sS --max-time "$timeout" "$url" 2>/dev/null || return 1
}
health_ok() {
local url=$1
local timeout=${2:-5}
local body
body=$(http_get "$url" "$timeout") || return 1
printf '%s' "$body" | grep -q '"status":"ok"'
}
wait_health() {
local url=$1
local n=0
while ((n <= STACK_WAIT_SECS)); do
if health_ok "$url"; then
return 0
fi
n=$((n + 1))
if ((n <= STACK_WAIT_SECS)); then
sleep "$STACK_WAIT_INTERVAL"
fi
done
return 1
}
wait_http() {
local url=$1
local n=0
while ((n <= STACK_WAIT_SECS)); do
if http_get "$url" 5 >/dev/null; then
return 0
fi
n=$((n + 1))
if ((n <= STACK_WAIT_SECS)); then
sleep "$STACK_WAIT_INTERVAL"
fi
done
return 1
}
mcp_body() {
curl -sS --max-time 10 \
-H 'Content-Type: application/json' \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' \
"$BRAIN_URL/mcp" 2>/dev/null || return 1
}
mcp_ok() {
local body
body=$(mcp_body) || return 1
printf '%s' "$body" | grep -Eq '"name": ?"search"' || return 1
printf '%s' "$body" | grep -Eq '"name": ?"get"' || return 1
printf '%s' "$body" | grep -Eq '"name": ?"audit"' || return 1
return 0
}
reasoner_tags() {
http_get "$REASONER_URL/api/tags" 5
}
reasoner_has_model() {
local body
body=$(reasoner_tags) || return 1
printf '%s' "$body" | grep -Fq "$REASONER_MODEL"
}
ensure_mcp() {
mcp_ok || stack_die "MCP tools/list missing search/get/audit at $BRAIN_URL/mcp"
}
ensure_brain() {
if health_ok "$BRAIN_URL/health"; then
echo "brain: reuse $BRAIN_URL" >&2
else
echo "brain: compose up" >&2
compose up -d brain
wait_health "$BRAIN_URL/health" || stack_die "brain health failed at $BRAIN_URL/health"
fi
ensure_mcp
}
pull_reasoner_model() {
echo "reasoner: pulling $REASONER_MODEL (CPU, may take minutes)" >&2
curl -sS --max-time "$STACK_PULL_SECS" \
-H 'Content-Type: application/json' \
-d "{\"name\":\"$REASONER_MODEL\"}" \
"$REASONER_URL/api/pull" >/dev/null
}
ensure_reasoner() {
if reasoner_has_model; then
echo "reasoner: reuse $REASONER_URL model $REASONER_MODEL" >&2
return 0
fi
if ! reasoner_tags >/dev/null; then
echo "reasoner: compose up" >&2
compose --profile reasoner up -d reasoner
wait_http "$REASONER_URL/api/tags" || stack_die "reasoner not listening at $REASONER_URL"
fi
if reasoner_has_model; then
return 0
fi
pull_reasoner_model
reasoner_has_model || stack_die "reasoner missing model $REASONER_MODEL"
}
ensure_picoclaw() {
echo "picoclaw: compose up --no-deps (reuse healthy :8630/:11435)" >&2
compose --profile picoclaw up -d --no-deps picoclaw
wait_health "$PICOCLAW_URL/health" || stack_die "picoclaw health failed at $PICOCLAW_URL/health"
}
mail_sync_running() {
compose ps --status running --services 2>/dev/null | grep -qx mail-sync
}
stack_status() {
local bh=down mcp=down ph=down present=false ms=down
health_ok "$BRAIN_URL/health" && bh=ok
mcp_ok && mcp=ok
reasoner_has_model && present=true
health_ok "$PICOCLAW_URL/health" && ph=ok
mail_sync_running && ms=ok
cat <<EOF
brain:
url: $BRAIN_URL
health: $bh
mcp: $mcp
reasoner:
url: $REASONER_URL
model: $REASONER_MODEL
present: $present
picoclaw:
url: $PICOCLAW_URL
health: $ph
mail_sync:
service: mail-sync
running: $ms
EOF
}
stack_start() {
ensure_brain
}
stack_start_mail_sync() {
echo "mail-sync: compose up (ETL sync→import; index only if MAIL_SYNC_INDEX=1)" >&2
compose up -d mail-sync
}
stack_attach_agent() {
local opts=()
if [[ -t 0 && -t 1 ]]; then
opts+=(-it)
else
opts+=(-T)
fi
if [[ (! -t 0 || ! -t 1) && $# -eq 0 ]]; then
echo "picoclaw: no TTY. Attach with:" >&2
echo " $ROOT/bin/stack/start-assistant" >&2
echo " docker compose --profile picoclaw exec -it picoclaw picoclaw agent" >&2
return 0
fi
echo "picoclaw: agent (search → get → audit before a factual reply)" >&2
exec docker compose -f "$ROOT/compose.yaml" --project-directory "$ROOT" \
--profile picoclaw exec "${opts[@]}" picoclaw picoclaw agent "$@"
}
stack_start_assistant() {
local attach=1
local agent_args=()
while (($#)); do
case "$1" in
-h | --help)
stack_usage "$ROOT/bin/stack/start-assistant"
return 0
;;
--no-attach)
attach=0
shift
;;
--)
shift
agent_args+=("$@")
break
;;
*)
agent_args+=("$1")
shift
;;
esac
done
stack_start
ensure_reasoner
ensure_picoclaw
stack_status
if ((attach == 0)); then
echo "picoclaw: gateway $PICOCLAW_URL (agent not attached)" >&2
echo "ask the brain: $ROOT/bin/stack/start-assistant" >&2
echo "one-shot: $ROOT/bin/stack/start-assistant -- -m \"search the 2dph brain for LadybugDB\"" >&2
return 0
fi
stack_attach_agent "${agent_args[@]}"
}
stack_stop() {
case "${1:-}" in
-h | --help)
stack_usage "$ROOT/bin/stack/stop"
return 0
;;
esac
echo "stack: stop brain brain-mcp reasoner picoclaw mail-sync (volumes kept)" >&2
compose --profile picoclaw --profile reasoner stop picoclaw brain-mcp reasoner brain mail-sync
}
-21
View File
@@ -1,21 +0,0 @@
#!/usr/bin/env bash
# bin/stack/start - bring up brain HTTP/MCP and wait until search/get/audit respond.
#
# bin/stack/start
# bin/stack/status
#
# Reuses a healthy process on :8630 (host serve or compose). Does not start
# PicoClaw. Does not rebuild Ladybug.
set -euo pipefail
STACK_DIR="$(CDPATH= cd -- "$(dirname "$0")" && pwd)"
# shellcheck source=lib.sh
source "$STACK_DIR/lib.sh"
case "${1:-}" in
-h | --help)
stack_usage "$0"
exit 0
;;
esac
stack_start "$@"
stack_status
-15
View File
@@ -1,15 +0,0 @@
#!/usr/bin/env bash
# bin/stack/start-assistant - start + CPU reasoner + PicoClaw, then attach agent.
#
# bin/stack/start-assistant
# bin/stack/start-assistant --no-attach
# bin/stack/start-assistant -- -m "search the 2dph brain for LadybugDB"
#
# Pulls qwen3.5:9b if missing. Gateway :18790. Agent uses MCP search → get → audit.
# --no-attach leaves the gateway up without exec.
set -euo pipefail
STACK_DIR="$(CDPATH= cd -- "$(dirname "$0")" && pwd)"
# shellcheck source=lib.sh
source "$STACK_DIR/lib.sh"
stack_start_assistant "$@"
-21
View File
@@ -1,21 +0,0 @@
#!/usr/bin/env bash
# bin/stack/start-mail-sync - compose up mail-sync ETL (sync → import; optional index).
#
# bin/stack/start-mail-sync
#
# Default: onlyoffice,gmail every 300s into kb-var. Full --rebuild only if
# MAIL_SYNC_INDEX=1 in compose/env. Secrets: ~/.config/brain/mail.env +
# ~/.gmail-mcp (mounted). Does not start brain/picoclaw.
set -euo pipefail
STACK_DIR="$(CDPATH= cd -- "$(dirname "$0")" && pwd)"
# shellcheck source=lib.sh
source "$STACK_DIR/lib.sh"
case "${1:-}" in
-h | --help)
stack_usage "$0"
exit 0
;;
esac
stack_start_mail_sync "$@"
stack_status
-17
View File
@@ -1,17 +0,0 @@
#!/usr/bin/env bash
# bin/stack/status - YAML health for brain MCP, reasoner model, PicoClaw gateway.
#
# bin/stack/status
# bin/stack/status | yq '.picoclaw'
set -euo pipefail
STACK_DIR="$(CDPATH= cd -- "$(dirname "$0")" && pwd)"
# shellcheck source=lib.sh
source "$STACK_DIR/lib.sh"
case "${1:-}" in
-h | --help)
stack_usage "$0"
exit 0
;;
esac
stack_status
-13
View File
@@ -1,13 +0,0 @@
#!/usr/bin/env bash
# bin/stack/stop - stop compose brain / brain-mcp / reasoner / picoclaw / mail-sync.
#
# bin/stack/stop
#
# Volumes kept (kb, reasoner weights, picoclaw-home). Does not kill a host
# bin/brain/serve.go that is not a compose service.
set -euo pipefail
STACK_DIR="$(CDPATH= cd -- "$(dirname "$0")" && pwd)"
# shellcheck source=lib.sh
source "$STACK_DIR/lib.sh"
stack_stop "$@"
+14 -76
View File
@@ -62,9 +62,7 @@ def init_schema(conn: ladybug.Connection) -> None:
"CREATE NODE TABLE IF NOT EXISTS Leaf (" "CREATE NODE TABLE IF NOT EXISTS Leaf ("
" id STRING, text STRING, root STRING, confidence STRING, " " id STRING, text STRING, root STRING, confidence STRING, "
" sha256 STRING, source STRING, source_rev STRING, observed_at STRING, " " sha256 STRING, source STRING, source_rev STRING, observed_at STRING, "
" how STRING, loc STRING, type STRING, " " how STRING, loc STRING, type STRING, embedding FLOAT[256], "
" valid_from STRING, valid_to STRING, "
" embedding FLOAT[256], "
" PRIMARY KEY(id))" " PRIMARY KEY(id))"
) )
conn.execute( conn.execute(
@@ -93,46 +91,6 @@ def init_schema(conn: ladybug.Connection) -> None:
conn.execute( conn.execute(
"CREATE REL TABLE IF NOT EXISTS AUTHORED (FROM Commit TO Person)" "CREATE REL TABLE IF NOT EXISTS AUTHORED (FROM Commit TO Person)"
) )
ensure_interval_columns(conn)
def ensure_interval_columns(conn: ladybug.Connection) -> None:
"""D24: add valid_from/valid_to on older Leaf tables (idempotent ALTER)."""
for col in ("valid_from", "valid_to"):
try:
conn.execute(f"ALTER TABLE Leaf ADD {col} STRING")
except Exception:
pass
def normalize_day(s: str) -> str:
s = (s or "").strip()
if len(s) >= 10 and s[4] == "-" and s[7] == "-":
return s[:10]
return s
def active_at(valid_from: str, valid_to: str, as_of: str) -> bool:
"""D24: fact interval of truth. Empty ends = always; empty as_of = no filter."""
as_of = normalize_day(as_of)
if not as_of:
return True
fro = normalize_day(valid_from)
to = normalize_day(valid_to)
if fro and as_of < fro:
return False
if to and as_of > to:
return False
return True
def filter_as_of(hits: list[dict], as_of: str) -> list[dict]:
if not as_of:
return hits
return [
h for h in hits
if active_at(str(h.get("valid_from") or ""), str(h.get("valid_to") or ""), as_of)
]
def leaf_id(text: str, source: str) -> str: def leaf_id(text: str, source: str) -> str:
@@ -141,24 +99,19 @@ def leaf_id(text: str, source: str) -> str:
def upsert_leaf(conn: ladybug.Connection, *, text: str, root: str, confidence: str, def upsert_leaf(conn: ladybug.Connection, *, text: str, root: str, confidence: str,
source: str, source_rev: str, how: str, loc: str, type_: str, source: str, source_rev: str, how: str, loc: str, type_: str,
embedding: list[float] | None, embedding: list[float] | None) -> str:
valid_from: str = "", valid_to: str = "") -> str:
lid = leaf_id(text, source) lid = leaf_id(text, source)
obs = time.strftime("%Y-%m-%dT%H:%M:%SZ", time.gmtime()) obs = time.strftime("%Y-%m-%dT%H:%M:%SZ", time.gmtime())
vf = normalize_day(valid_from)
vt = normalize_day(valid_to)
conn.execute( conn.execute(
"MERGE (l:Leaf {id:$id}) " "MERGE (l:Leaf {id:$id}) "
"SET l.text=$text, l.root=$root, l.confidence=$confidence, " "SET l.text=$text, l.root=$root, l.confidence=$confidence, "
" l.sha256=$sha, l.source=$source, l.source_rev=$rev, l.observed_at=$obs, " " l.sha256=$sha, l.source=$source, l.source_rev=$rev, l.observed_at=$obs, "
" l.how=$how, l.loc=$location, l.type=$type, " " l.how=$how, l.loc=$location, l.type=$type"
" l.valid_from=$vf, l.valid_to=$vt"
+ (", l.embedding=$emb" if embedding else ""), + (", l.embedding=$emb" if embedding else ""),
parameters={ parameters={
"id": lid, "text": text, "root": root, "confidence": confidence, "id": lid, "text": text, "root": root, "confidence": confidence,
"sha": sha256_b64(text), "source": source, "rev": source_rev, "sha": sha256_b64(text), "source": source, "rev": source_rev,
"obs": obs, "how": how, "location": loc, "type": type_, "obs": obs, "how": how, "location": loc, "type": type_,
"vf": vf, "vt": vt,
"emb": (embedding if embedding else None), "emb": (embedding if embedding else None),
}, },
) )
@@ -168,10 +121,9 @@ def upsert_leaf(conn: ladybug.Connection, *, text: str, root: str, confidence: s
def add_leafs(conn: ladybug.Connection, leafs: list[dict]) -> list[str]: def add_leafs(conn: ladybug.Connection, leafs: list[dict]) -> list[str]:
"""Write facts+info leafs in one transaction. Safe while FTS/HNSW exist. """Write facts+info leafs in one transaction. Safe while FTS/HNSW exist.
Each leaf dict: text, source, optional root/confidence/source_rev/how/loc/type/ Each leaf dict: text, source, optional root/confidence/source_rev/how/loc/type/embedding.
embedding/valid_from/valid_to. Does not delete the database file. Measured on Does not delete the database file. Measured on Ladybug 0.19: MERGE of new
Ladybug 0.19: MERGE of new ids (and updates) stays FTS+HNSW queryable; DROP ids (and updates) stays FTS+HNSW queryable; DROP INDEX is the fatal path.
INDEX is the fatal path.
""" """
if not leafs: if not leafs:
return [] return []
@@ -196,8 +148,6 @@ def add_leafs(conn: ladybug.Connection, leafs: list[dict]) -> list[str]:
loc=str(lf.get("loc") or lf.get("source") or ""), loc=str(lf.get("loc") or lf.get("source") or ""),
type_=str(lf.get("type") or lf.get("type_") or "reference"), type_=str(lf.get("type") or lf.get("type_") or "reference"),
embedding=lf.get("embedding"), embedding=lf.get("embedding"),
valid_from=str(lf.get("valid_from") or ""),
valid_to=str(lf.get("valid_to") or ""),
) )
) )
if started: if started:
@@ -335,39 +285,29 @@ def drop_indexes(conn: ladybug.Connection) -> None:
def query_fts(conn: ladybug.Connection, text: str, limit: int = 10) -> list[dict]: def query_fts(conn: ladybug.Connection, text: str, limit: int = 10) -> list[dict]:
r = conn.execute( r = conn.execute(
"CALL QUERY_FTS_INDEX('Leaf', 'id', $q) " "CALL QUERY_FTS_INDEX('Leaf', 'id', $q) "
"RETURN node.id, node.text, node.root, score, node.valid_from, node.valid_to " "RETURN node.id, node.text, node.root, score ORDER BY score DESC LIMIT $n",
"ORDER BY score DESC LIMIT $n",
parameters={"q": text, "n": limit}, parameters={"q": text, "n": limit},
) )
return [ return [{"id": row[0], "text": row[1], "root": row[2], "score": row[3]} for row in r.get_all()]
{
"id": row[0], "text": row[1], "root": row[2], "score": row[3],
"valid_from": row[4] or "", "valid_to": row[5] or "",
}
for row in r.get_all()
]
def query_vector(conn: ladybug.Connection, embedding: list[float], limit: int = 10) -> list[dict]: def query_vector(conn: ladybug.Connection, embedding: list[float], limit: int = 10) -> list[dict]:
r = conn.execute( r = conn.execute(
"CALL QUERY_VECTOR_INDEX('Leaf', 'Leaf_vec', $q, $n) " "CALL QUERY_VECTOR_INDEX('Leaf', 'Leaf_vec', $q, $n) "
"RETURN node.id, node.text, node.root, distance, node.valid_from, node.valid_to " "RETURN node.id, node.text, node.root, distance ORDER BY distance LIMIT $n",
"ORDER BY distance LIMIT $n",
parameters={"q": embedding, "n": limit}, parameters={"q": embedding, "n": limit},
) )
out = [] out = []
for row in r.get_all(): for row in r.get_all():
# distance -> similarity reasonable for cosine
score = 1.0 - row[3] if row[3] is not None else 0.0 score = 1.0 - row[3] if row[3] is not None else 0.0
out.append({ out.append({"id": row[0], "text": row[1], "root": row[2], "score": score})
"id": row[0], "text": row[1], "root": row[2], "score": score,
"valid_from": row[4] or "", "valid_to": row[5] or "",
})
return out return out
def hybrid_search(conn: ladybug.Connection, embedding: list[float], fts_hits: list[dict], def hybrid_search(conn: ladybug.Connection, embedding: list[float], fts_hits: list[dict],
limit: int = 10, as_of: str = "") -> list[dict]: limit: int = 10) -> list[dict]:
"""Merge FTS + vector by reciprocal rank fusion; optional D24 as-of filter.""" """Merge FTS + vector by reciprocal rank fusion."""
fused: dict[str, dict] = {} fused: dict[str, dict] = {}
for rank, hit in enumerate(fts_hits): for rank, hit in enumerate(fts_hits):
fused.setdefault(hit["id"], {**hit, "rrf": 0.0})["rrf"] = 1.0 / (60 + rank + 1) fused.setdefault(hit["id"], {**hit, "rrf": 0.0})["rrf"] = 1.0 / (60 + rank + 1)
@@ -375,10 +315,8 @@ def hybrid_search(conn: ladybug.Connection, embedding: list[float], fts_hits: li
entry = fused.setdefault(hit["id"], {**hit, "rrf": 0.0}) entry = fused.setdefault(hit["id"], {**hit, "rrf": 0.0})
entry["rrf"] += 1.0 / (60 + rank + 1) entry["rrf"] += 1.0 / (60 + rank + 1)
entry.setdefault("score", hit.get("score", 0.0)) entry.setdefault("score", hit.get("score", 0.0))
entry.setdefault("valid_from", hit.get("valid_from") or "")
entry.setdefault("valid_to", hit.get("valid_to") or "")
ranked = sorted(fused.values(), key=lambda h: h.get("rrf", 0.0), reverse=True) ranked = sorted(fused.values(), key=lambda h: h.get("rrf", 0.0), reverse=True)
return filter_as_of(ranked, as_of)[:limit] return ranked[:limit]
def stats(conn: ladybug.Connection) -> dict: def stats(conn: ladybug.Connection) -> dict:
-32
View File
@@ -194,38 +194,6 @@ class KblibTest(unittest.TestCase):
self.assertEqual(person["name"], "Ada Lovelace") self.assertEqual(person["name"], "Ada Lovelace")
self.assertEqual(person["depth"], 3) self.assertEqual(person["depth"], 3)
def test_as_of_keeps_x_drops_y(self) -> None:
"""OQ5/#36: as of 2025-01-01 → works-at-X, not works-at-Y."""
kblib.upsert_leaf(
self.conn, text="Andrey works at X", root="facts",
confidence="confirmed", source="crm.md x contract.md",
source_rev="r1", how="test", loc="/tmp", type_="fact",
embedding=make_emb(0.5),
valid_from="2024-03-01", valid_to="2025-07-15",
)
kblib.upsert_leaf(
self.conn, text="Andrey works at Y", root="facts",
confidence="confirmed", source="offer.md x payroll.md",
source_rev="r1", how="test", loc="/tmp", type_="fact",
embedding=make_emb(0.6),
valid_from="2025-07-16", valid_to="",
)
kblib.ensure_indexes(self.conn)
hits = kblib.query_fts(self.conn, "Andrey works", 10)
kept = kblib.filter_as_of(hits, "2025-01-01")
texts = [h["text"] for h in kept]
self.assertTrue(any("works at X" in t for t in texts), texts)
self.assertFalse(any("works at Y" in t for t in texts), texts)
later = kblib.filter_as_of(hits, "2025-08-01")
later_texts = [h["text"] for h in later]
self.assertTrue(any("works at Y" in t for t in later_texts), later_texts)
self.assertFalse(any("works at X" in t for t in later_texts), later_texts)
def test_active_at_pure(self) -> None:
self.assertTrue(kblib.active_at("2024-03-01", "2025-07-15", "2025-01-01"))
self.assertFalse(kblib.active_at("2025-07-16", "", "2025-01-01"))
self.assertTrue(kblib.active_at("", "", "2025-01-01"))
if __name__ == "__main__": if __name__ == "__main__":
unittest.main() unittest.main()
-18
View File
@@ -186,21 +186,3 @@ class PublishedDocsTest(unittest.TestCase):
self.assertIn("epic #16", index) self.assertIn("epic #16", index)
agents = (ROOT / "AGENTS.md").read_text() agents = (ROOT / "AGENTS.md").read_text()
self.assertIn("roadmap.md", agents) self.assertIn("roadmap.md", agents)
def test_oq5_intervals_are_not_d16_stale(self) -> None:
plan = (ROOT / "PLAN.md").read_text()
design = (ROOT / "docs" / "design.md").read_text()
road = (ROOT / "docs" / "roadmap.md").read_text()
contradict = (ROOT / "internal" / "facts" / "contradict.go").read_text()
interval = (ROOT / "internal" / "facts" / "interval.go").read_text()
self.assertIn("OQ5", plan)
self.assertIn("D24", plan)
self.assertIn("issues/36", plan)
self.assertIn("valid_from", plan)
self.assertIn("--as-of", design)
self.assertIn("issues/36", road)
self.assertIn("**in**", road[road.index("OQ5"):road.index("OQ5") + 80])
self.assertIn("temporal_freshness", contradict)
self.assertNotIn("valid_from", contradict)
self.assertIn("ActiveAt", interval)
self.assertIn("NormalizeDay", interval)
-228
View File
@@ -1,228 +0,0 @@
"""bin/stack/{start,start-assistant,stop,status} — offline contract + fake PATH."""
from __future__ import annotations
import os
import stat
import subprocess
import tempfile
import unittest
from pathlib import Path
ROOT = Path(__file__).resolve().parents[2]
METHODS = ("start", "start-assistant", "start-mail-sync", "stop", "status")
class StackLayoutTest(unittest.TestCase):
def test_methods_are_bash_with_usage_comment(self) -> None:
lib = ROOT / "bin" / "stack" / "lib.sh"
self.assertTrue(lib.is_file(), "missing bin/stack/lib.sh")
for name in METHODS:
p = ROOT / "bin" / "stack" / name
self.assertTrue(p.is_file(), f"missing bin/stack/{name}")
self.assertTrue(os.access(p, os.X_OK), f"bin/stack/{name} must be executable")
lines = p.read_text().splitlines()
self.assertEqual(lines[0], "#!/usr/bin/env bash", name)
self.assertTrue(lines[1].startswith("# bin/stack/"), name)
text = "\n".join(lines)
self.assertIn("lib.sh", text, name)
self.assertNotIn("/mnt/", text, name)
self.assertNotIn("/home/", text, name)
def test_lib_has_no_host_paths_or_secrets(self) -> None:
lib = (ROOT / "bin" / "stack" / "lib.sh").read_text()
self.assertIn("stack_start", lib)
self.assertIn("stack_start_assistant", lib)
self.assertIn("stack_start_mail_sync", lib)
self.assertIn("stack_stop", lib)
self.assertIn("stack_status", lib)
self.assertIn("mail-sync", lib)
self.assertIn("qwen3.5:9b", lib)
self.assertIn("picoclaw agent", lib)
self.assertIn("--no-deps", lib)
self.assertIn("tools/list", lib)
self.assertNotIn("/mnt/", lib)
self.assertNotIn("/home/", lib)
self.assertNotIn("password", lib.lower())
self.assertNotIn("GITEA_TOKEN", lib)
def test_start_does_not_launch_picoclaw(self) -> None:
start = (ROOT / "bin" / "stack" / "start").read_text()
self.assertIn("stack_start", start)
self.assertNotIn("stack_start_assistant", start)
self.assertNotIn("picoclaw agent", start)
def test_start_mail_sync_is_etl_only(self) -> None:
src = (ROOT / "bin" / "stack" / "start-mail-sync").read_text()
self.assertIn("stack_start_mail_sync", src)
self.assertNotIn("stack_start_assistant", src)
ep = (ROOT / "bin" / "docker-entrypoint").read_text()
self.assertIn('MAIL_SYNC_SRC:=onlyoffice,gmail', ep)
self.assertIn('MAIL_SYNC_INDEX:=0', ep)
self.assertIn('interval="${1:-300}"', ep)
self.assertIn('MAIL_SYNC_INDEX" = "1"', ep)
def test_start_assistant_attaches_agent(self) -> None:
src = (ROOT / "bin" / "stack" / "start-assistant").read_text()
self.assertIn("stack_start_assistant", src)
self.assertIn("--no-attach", src)
def test_stop_does_not_down_volumes(self) -> None:
lib = (ROOT / "bin" / "stack" / "lib.sh").read_text()
self.assertIn(" compose ", lib)
self.assertRegex(lib, r"\bstop\b")
self.assertNotIn(" compose down", lib)
self.assertNotIn("compose down", lib)
def test_docs_name_stack_commands(self) -> None:
runbook = (ROOT / "docs" / "runbook.md").read_text()
pico = (ROOT / "docs" / "picoclaw.md").read_text()
agents = (ROOT / "AGENTS.md").read_text()
for text in (runbook, pico, agents):
self.assertIn("bin/stack/start", text)
self.assertIn("bin/stack/start-assistant", text)
self.assertIn("bin/stack/status", text)
self.assertIn("bin/stack/stop", text)
def test_help_prints_comments_not_source(self) -> None:
r = subprocess.run(
[str(ROOT / "bin" / "stack" / "start"), "--help"],
cwd=str(ROOT),
capture_output=True,
text=True,
check=False,
)
self.assertEqual(r.returncode, 0, r.stderr)
self.assertIn("bin/stack/start", r.stdout)
self.assertNotIn("set -euo pipefail", r.stdout)
self.assertNotIn("source ", r.stdout)
class StackFakePathTest(unittest.TestCase):
def _fake_bin(self, tmp: Path, *, health_ok: bool) -> Path:
bindir = tmp / "bin"
bindir.mkdir()
curl = bindir / "curl"
docker = bindir / "docker"
log = tmp / "docker.log"
curl.write_text(
f"""#!/usr/bin/env bash
url=""
for a in "$@"; do
case "$a" in http*) url=$a ;;
esac
done
if [ "{int(health_ok)}" = "0" ] && [[ "$url" == */health ]]; then
echo '{{"status":"down"}}'
exit 7
fi
case "$url" in
*/mcp)
echo '{{"jsonrpc":"2.0","id":1,"result":{{"tools":[{{"name":"search"}},{{"name":"get"}},{{"name":"audit"}}]}}}}'
;;
*/api/tags)
echo '{{"models":[{{"name":"qwen3.5:9b"}}]}}'
;;
*/api/pull)
echo '{{"status":"success"}}'
;;
*)
echo '{{"status":"ok"}}'
;;
esac
"""
)
docker.write_text(
f"""#!/usr/bin/env bash
echo "$*" >> "{log}"
exit 0
"""
)
curl.chmod(curl.stat().st_mode | stat.S_IEXEC)
docker.chmod(docker.stat().st_mode | stat.S_IEXEC)
return bindir
def _env(self, bindir: Path) -> dict[str, str]:
env = os.environ.copy()
env["PATH"] = f"{bindir}:{env.get('PATH', '')}"
env["STACK_WAIT_SECS"] = "1"
env["STACK_WAIT_INTERVAL"] = "0"
return env
def test_start_skips_compose_when_brain_healthy(self) -> None:
with tempfile.TemporaryDirectory() as raw:
tmp = Path(raw)
bindir = self._fake_bin(tmp, health_ok=True)
log = tmp / "docker.log"
r = subprocess.run(
[str(ROOT / "bin" / "stack" / "start")],
cwd=str(ROOT),
env=self._env(bindir),
capture_output=True,
text=True,
check=False,
)
self.assertEqual(r.returncode, 0, r.stderr)
if log.exists():
logged = log.read_text()
self.assertNotIn("up -d", logged, "healthy brain must not docker compose up")
self.assertIn("ps", logged) # status probes mail-sync via compose ps
def test_start_ups_brain_when_unhealthy(self) -> None:
with tempfile.TemporaryDirectory() as raw:
tmp = Path(raw)
bindir = self._fake_bin(tmp, health_ok=False)
log = tmp / "docker.log"
r = subprocess.run(
[str(ROOT / "bin" / "stack" / "start")],
cwd=str(ROOT),
env=self._env(bindir),
capture_output=True,
text=True,
check=False,
)
self.assertNotEqual(r.returncode, 0, "unhealthy brain without recovering compose must fail")
self.assertTrue(log.exists(), r.stderr)
logged = log.read_text()
self.assertIn("up -d", logged)
self.assertIn("brain", logged)
self.assertNotIn("picoclaw", logged)
def test_stop_stops_named_services(self) -> None:
with tempfile.TemporaryDirectory() as raw:
tmp = Path(raw)
bindir = self._fake_bin(tmp, health_ok=True)
log = tmp / "docker.log"
r = subprocess.run(
[str(ROOT / "bin" / "stack" / "stop")],
cwd=str(ROOT),
env=self._env(bindir),
capture_output=True,
text=True,
check=False,
)
self.assertEqual(r.returncode, 0, r.stderr)
logged = log.read_text()
self.assertIn("stop", logged)
self.assertNotIn(" down", logged)
for svc in ("brain", "brain-mcp", "reasoner", "picoclaw", "mail-sync"):
self.assertIn(svc, logged)
def test_start_assistant_no_attach_starts_picoclaw(self) -> None:
with tempfile.TemporaryDirectory() as raw:
tmp = Path(raw)
bindir = self._fake_bin(tmp, health_ok=True)
log = tmp / "docker.log"
r = subprocess.run(
[str(ROOT / "bin" / "stack" / "start-assistant"), "--no-attach"],
cwd=str(ROOT),
env=self._env(bindir),
capture_output=True,
text=True,
check=False,
)
self.assertEqual(r.returncode, 0, r.stderr + r.stdout)
logged = log.read_text() if log.exists() else ""
self.assertIn("picoclaw", logged)
self.assertIn("--no-deps", logged)
self.assertNotIn("picoclaw agent", logged)
-33
View File
@@ -1,6 +1,5 @@
# 2dph — docker composition # 2dph — docker composition
# #
# bin/stack/start / start-assistant / status / stop
# docker compose up -d brain # API (Zig CGO serve) # docker compose up -d brain # API (Zig CGO serve)
# docker compose --profile index run --rm index # Python rebuild # docker compose --profile index run --rm index # Python rebuild
# docker compose --profile picoclaw up -d # brain-mcp + CPU reasoner + PicoClaw gateway # docker compose --profile picoclaw up -d # brain-mcp + CPU reasoner + PicoClaw gateway
@@ -92,38 +91,6 @@ services:
tmpfs: tmpfs:
- /tmp - /tmp
# mail-sync ETL: sync → import every 300s into shared var. Full brain rebuild
# only when MAIL_SYNC_INDEX=1 (expensive on large mail corpora). Default
# sources: onlyoffice,gmail. For M365 set MAIL_SYNC_SRC=m365 and put
# M365_TENANT/CLIENT_ID/CLIENT_SECRET/USERS in ~/.config/brain/mail.env
# (or m365.env + MAIL_SYNC_ENV). Gmail OAuth: mount ~/.gmail-mcp.
# docker compose up -d mail-sync
# bin/stack/start-mail-sync
mail-sync:
image: ghcr.io/eslider/2dph:index
build:
context: .
dockerfile: Dockerfile
target: index
environment:
HF_HOME: /data/hf
KB_PY: python3
MAIL_SYNC_SRC: onlyoffice,gmail
MAIL_SYNC_ENV: /secret/mail.env
MAIL_SYNC_INDEX: "0"
HOME: /home/2dph
volumes:
- kb-model:/data/hf
- kb-var:/app/var
- ~/.config/brain:/secret:ro
- ~/.gmail-mcp:/home/2dph/.gmail-mcp:ro
command: ["mail-sync", "300"]
read_only: true
tmpfs:
- /tmp
restart: unless-stopped
stop_grace_period: 20s
# Optional local SearXNG (D3). Skip if BRAIN_SEARCH_URL already points at a # Optional local SearXNG (D3). Skip if BRAIN_SEARCH_URL already points at a
# live instance — do not run a second copy on that host. # live instance — do not run a second copy on that host.
# SEARXNG_SECRET=$(openssl rand -hex 32) docker compose --profile searxng up -d # SEARXNG_SECRET=$(openssl rand -hex 32) docker compose --profile searxng up -d
+2 -2
View File
@@ -18,9 +18,9 @@ Evidence-first knowledge graph. Facts need proof or they are
| tutorial / howto | [runbook](runbook.md) — run anywhere (uv, Go, Docker) | | tutorial / howto | [runbook](runbook.md) — run anywhere (uv, Go, Docker) |
| explanation | [design](design.md) — two roots, deduction, D17/D20/D18 | | explanation | [design](design.md) — two roots, deduction, D17/D20/D18 |
| explanation | [roadmap](roadmap.md) — gap to v1 (epic #16) | | explanation | [roadmap](roadmap.md) — gap to v1 (epic #16) |
| howto | [picoclaw](picoclaw.md) — MCP agent (`bin/stack/start-assistant`) | | howto | [picoclaw](picoclaw.md) — MCP agent profile |
| howto | [reasoner](reasoner.md) — CPU bake-off (D18) | | howto | [reasoner](reasoner.md) — CPU bake-off (D18) |
| reference | [PLAN.md](../PLAN.md) — decisions D1D24 | | reference | [PLAN.md](../PLAN.md) — decisions D1D22 |
Decisions the public face must name: **D3** SearXNG compose, **D6** Go service / Decisions the public face must name: **D3** SearXNG compose, **D6** Go service /
Python write sidecar, **D14** `bin/{subject}/{method}.go`, **D15** Gitea origin, Python write sidecar, **D14** `bin/{subject}/{method}.go`, **D15** Gitea origin,
-9
View File
@@ -68,15 +68,6 @@ binary); conversion prints leafs, brain write is `bin/brain/index.go`.
`bin/facts/audit stale` flags leafs whose observed revision is behind the `bin/facts/audit stale` flags leafs whose observed revision is behind the
corpus HEAD. corpus HEAD.
Fact **interval of truth** (D24 / OQ5): leaf props `valid_from` /
`valid_to` (YYYY-MM-DD, inclusive; empty end = open; both empty = legacy
always-active). `bin/brain/search.go --as-of YYYY-MM-DD` and MCP/HTTP
`as_of` keep hits whose interval covers that day. This is not D16
`temporal_freshness` (source freshness vs HEAD). [#36](https://git.produktor.io/eSlider/2dph/issues/36).
Existing `kb.lbug` without the columns: open/search/add runs an idempotent
`ALTER TABLE Leaf ADD …` (no full rebuild required). Fresh `--rebuild` still
creates them in `CREATE NODE TABLE`.
## Sources (auto-pairing) ## Sources (auto-pairing)
- A: runtime state — `docker ps` (container running), ports actually bound - A: runtime state — `docker ps` (container running), ports actually bound
-12
View File
@@ -6,18 +6,6 @@ CPU reasoner. Default agent model is `qwen3.5:9b` (RAM path, D18). Weights stay
in the reasoner volume, not in the 2dph image. in the reasoner volume, not in the 2dph image.
No secrets in git: Ollama needs no key; MCP is local HTTP. No secrets in git: Ollama needs no key; MCP is local HTTP.
```bash
bin/stack/start-assistant
bin/stack/start-assistant --no-attach
bin/stack/start-assistant -- -m "search the 2dph brain for LadybugDB"
bin/stack/status
bin/stack/stop
```
`start-assistant` reuses a healthy brain on `:8630`, starts the CPU reasoner,
pulls `qwen3.5:9b` if missing, brings up the gateway with `--no-deps picoclaw`,
then `picoclaw agent` (MCP `search``get``audit`). Gateway-only Compose:
```bash ```bash
docker compose --profile picoclaw up -d docker compose --profile picoclaw up -d
# already serving :8630 / :11435: # already serving :8630 / :11435:
+1 -5
View File
@@ -41,12 +41,10 @@ Epic [#16](https://git.produktor.io/eSlider/2dph/issues/16) closed.
[#29](https://git.produktor.io/eSlider/2dph/issues/29) OQ1 contradiction [#29](https://git.produktor.io/eSlider/2dph/issues/29) OQ1 contradiction
resolution — **in** (`temporal_freshness`, `authority_pairing`). resolution — **in** (`temporal_freshness`, `authority_pairing`).
[#34](https://git.produktor.io/eSlider/2dph/issues/34) D23 flaggy CLI — **in**. [#34](https://git.produktor.io/eSlider/2dph/issues/34) D23 flaggy CLI — **in**.
[#36](https://git.produktor.io/eSlider/2dph/issues/36) OQ5/D24 fact intervals /
as-of — **in** (not D16 `temporal_freshness`).
## Blockers ## Blockers
None for epic #16 (closed). Remaining v2: OQ4 (deferred). None for epic #16 (closed). Remaining v2: OQ4.
``` ```
question question
@@ -62,8 +60,6 @@ question
## Not v1 ## Not v1
OQ4 YAML-first leafs. OQ4 YAML-first leafs.
OQ5/D24 fact intervals + as-of — **in**
([#36](https://git.produktor.io/eSlider/2dph/issues/36)).
OCR (OQ2), duckdb-go (OQ3/D22), and D16 adjudication (OQ1) are in. OCR (OQ2), duckdb-go (OQ3/D22), and D16 adjudication (OQ1) are in.
## Close epic #16 when ## Close epic #16 when
+1 -17
View File
@@ -53,15 +53,12 @@ bin/brain/add.go --text "arc-1 runs Matrix" --root facts --source "compose.yml x
bin/brain/index.go --rebuild --with-facts --with-chats bin/brain/index.go --rebuild --with-facts --with-chats
bin/brain/search.go "LadybugDB vector index" # facts → info → web (D17) bin/brain/search.go "LadybugDB vector index" # facts → info → web (D17)
bin/brain/search.go "upstream flag" --no-web bin/brain/search.go "upstream flag" --no-web
bin/brain/search.go "who works where" --as-of 2025-01-01 # D24 intervals
source <(./bin/cli/complete.go bash) # D23 flaggy complete source <(./bin/cli/complete.go bash) # D23 flaggy complete
bin/brain/get.go <id> --body bin/brain/get.go <id> --body
bin/brain/stats.go bin/brain/stats.go
``` ```
`--hop N` walks File → Commit → Person from each hit. `--as-of YYYY-MM-DD` `--hop N` walks File → Commit → Person from each hit. Empty web results are `throttled`, not absence.
keeps leafs whose `valid_from`/`valid_to` cover that day (empty interval =
legacy always-on). Empty web results are `throttled`, not absence.
Gap to v1: [roadmap](roadmap.md) / [epic #16](https://git.produktor.io/eSlider/2dph/issues/16). Gap to v1: [roadmap](roadmap.md) / [epic #16](https://git.produktor.io/eSlider/2dph/issues/16).
Ladybug 0.19: never `DROP INDEX` FTS/VECTOR (ghost catalog). Fresh indexes = Ladybug 0.19: never `DROP INDEX` FTS/VECTOR (ghost catalog). Fresh indexes =
@@ -69,26 +66,13 @@ delete `var/kb.lbug` then `--rebuild`.
## HTTP / MCP ## HTTP / MCP
```bash
bin/stack/start # brain :8630, wait until MCP search/get/audit
bin/stack/status # YAML: brain / reasoner / picoclaw / mail_sync
bin/stack/start-mail-sync # compose ETL: OO+Gmail sync→import (300s; no auto-rebuild)
bin/stack/start-assistant # + qwen3.5:9b + PicoClaw agent (ask the brain)
bin/stack/start-assistant --no-attach
bin/stack/stop # compose stop; volumes kept
```
Same Compose services by hand:
```bash ```bash
docker compose up -d brain # :8630 Zig CGO serve docker compose up -d brain # :8630 Zig CGO serve
docker compose up -d mail-sync # ETL loop into kb-var
docker compose --profile index run --rm index # rebuild docker compose --profile index run --rm index # rebuild
docker compose --profile picoclaw up brain-mcp # MCP 127.0.0.1:8630 docker compose --profile picoclaw up brain-mcp # MCP 127.0.0.1:8630
``` ```
`GET /openapi.json`, `POST /mcp`. Agent tool order: `search``get``audit`. `GET /openapi.json`, `POST /mcp`. Agent tool order: `search``get``audit`.
See [picoclaw.md](picoclaw.md).
## Reasoner (optional, D18) ## Reasoner (optional, D18)
-9
View File
@@ -85,18 +85,9 @@ func openWithSandbox(epsv string) error {
closeBrain() closeBrain()
return fmt.Errorf("LOAD EXTENSION VECTOR: %w", err) return fmt.Errorf("LOAD EXTENSION VECTOR: %w", err)
} }
migrateIntervalColumns()
return nil return nil
} }
// migrateIntervalColumns adds D24 valid_from/valid_to on existing Leaf tables.
// Fresh CREATE already has them; ALTER is a no-op when the column exists.
func migrateIntervalColumns() {
for _, col := range []string{"valid_from", "valid_to"} {
_, _ = conn.Query("ALTER TABLE Leaf ADD " + col + " STRING")
}
}
func closeBrain() { func closeBrain() {
if conn != nil { if conn != nil {
conn.Close() conn.Close()
+3 -3
View File
@@ -21,8 +21,8 @@ func Ready() error {
// HTTP is the in-process API used by bin/brain/serve.go. // HTTP is the in-process API used by bin/brain/serve.go.
type HTTP struct{} type HTTP struct{}
func (HTTP) Search(ctx context.Context, query string, limit int, asOf string) ([]byte, error) { func (HTTP) Search(ctx context.Context, query string, limit int) ([]byte, error) {
hits, err := searchHits(query, "", "", limit, asOf) hits, err := searchHits(query, "", "", limit)
if err != nil { if err != nil {
return nil, err return nil, err
} }
@@ -41,7 +41,7 @@ func (HTTP) Search(ctx context.Context, query string, limit int, asOf string) ([
var buf bytes.Buffer var buf bytes.Buffer
enc := json.NewEncoder(&buf) enc := json.NewEncoder(&buf)
enc.SetEscapeHTML(false) enc.SetEscapeHTML(false)
if err := enc.Encode(toJSONOut(hits, query, "", asOf, webOut)); err != nil { if err := enc.Encode(toJSONOut(hits, query, "", webOut)); err != nil {
return nil, err return nil, err
} }
return buf.Bytes(), nil return buf.Bytes(), nil
+1 -11
View File
@@ -5,11 +5,10 @@ import (
"strconv" "strconv"
"github.com/eSlider/2dph/internal/cli" "github.com/eSlider/2dph/internal/cli"
"github.com/eSlider/2dph/internal/facts"
"github.com/integrii/flaggy" "github.com/integrii/flaggy"
) )
const Usage = `usage: bin/brain/search.go "query" [--root facts|info] [--repo REPO] [-n N] [--hop N] [--as-of YYYY-MM-DD] [--json] [--no-web] const Usage = `usage: bin/brain/search.go "query" [--root facts|info] [--repo REPO] [-n N] [--hop N] [--json] [--no-web]
bin/brain/search.go serve [port] bin/brain/search.go serve [port]
bin/brain/search.go --list-model bin/brain/search.go --list-model
source <(./bin/cli/complete.go bash)` source <(./bin/cli/complete.go bash)`
@@ -20,7 +19,6 @@ type Options struct {
Repo string Repo string
Limit int Limit int
Hop int Hop int
AsOf string
JSONOut bool JSONOut bool
ListModel bool ListModel bool
NoWeb bool NoWeb bool
@@ -37,7 +35,6 @@ func NewParser(opt *Options) *flaggy.Parser {
p.String(&opt.Repo, "", "repo", "filter by repo") p.String(&opt.Repo, "", "repo", "filter by repo")
p.Int(&opt.Limit, "n", "n", "max hits") p.Int(&opt.Limit, "n", "n", "max hits")
p.Int(&opt.Hop, "", "hop", "walk FROM_FILE depth 1-3") p.Int(&opt.Hop, "", "hop", "walk FROM_FILE depth 1-3")
p.String(&opt.AsOf, "", "as-of", "keep facts active on YYYY-MM-DD (D24)")
p.Bool(&opt.JSONOut, "", "json", "JSON output") p.Bool(&opt.JSONOut, "", "json", "JSON output")
p.Bool(&opt.NoWeb, "", "no-web", "stay local") p.Bool(&opt.NoWeb, "", "no-web", "stay local")
p.Bool(&opt.ListModel, "", "list-model", "print embedding model") p.Bool(&opt.ListModel, "", "list-model", "print embedding model")
@@ -67,13 +64,6 @@ func ParseArgs(args []string) (Options, error) {
if opt.Hop > 3 { if opt.Hop > 3 {
return opt, fmt.Errorf("--hop max is 3 (File → Commit → Person)") return opt, fmt.Errorf("--hop max is 3 (File → Commit → Person)")
} }
if opt.AsOf != "" {
day := facts.NormalizeDay(opt.AsOf)
if len(day) != 10 || day[4] != '-' || day[7] != '-' {
return opt, fmt.Errorf("--as-of must be YYYY-MM-DD, got %q", opt.AsOf)
}
opt.AsOf = day
}
if opt.Query == "" && !opt.ListModel { if opt.Query == "" && !opt.ListModel {
return opt, fmt.Errorf("no query given") return opt, fmt.Errorf("no query given")
} }
-34
View File
@@ -1,34 +0,0 @@
package rank
import "testing"
func TestFilterAsOfKeepsXDropsY(t *testing.T) {
hits := []Hit{
{ID: "x", Text: "Andrey works at X", ValidFrom: "2024-03-01", ValidTo: "2025-07-15"},
{ID: "y", Text: "Andrey works at Y", ValidFrom: "2025-07-16", ValidTo: ""},
{ID: "legacy", Text: "always true claim", ValidFrom: "", ValidTo: ""},
}
out := FilterAsOf(hits, "2025-01-01")
if len(out) != 2 {
t.Fatalf("len=%d want 2: %+v", len(out), out)
}
if out[0].ID != "x" || out[1].ID != "legacy" {
t.Fatalf("got %+v", out)
}
if FilterAsOf(hits, "") == nil || len(FilterAsOf(hits, "")) != 3 {
t.Fatal("empty as-of must keep all")
}
}
func TestParseArgsAsOf(t *testing.T) {
opt, err := ParseArgs([]string{"who works where", "--as-of", "2025-01-01", "--json"})
if err != nil {
t.Fatal(err)
}
if opt.AsOf != "2025-01-01" {
t.Fatalf("AsOf=%q", opt.AsOf)
}
if _, err := ParseArgs([]string{"q", "--as-of", "not-a-date"}); err == nil {
t.Fatal("expected bad as-of error")
}
}
+2 -4
View File
@@ -3,12 +3,10 @@ package rank
// BM25 ranks best-first, so the top hits are the *highest* scores; cosine // BM25 ranks best-first, so the top hits are the *highest* scores; cosine
// distance ranks best-first ascending. Both mirror kblib.py. // distance ranks best-first ascending. Both mirror kblib.py.
const FTSStmt = "CALL QUERY_FTS_INDEX('Leaf', 'id', $q) " + const FTSStmt = "CALL QUERY_FTS_INDEX('Leaf', 'id', $q) " +
"RETURN node.id, node.text, node.root, node.source, score, node.confidence, " + "RETURN node.id, node.text, node.root, node.source, score, node.confidence ORDER BY score DESC LIMIT $n"
"node.valid_from, node.valid_to ORDER BY score DESC LIMIT $n"
const VecStmt = "CALL QUERY_VECTOR_INDEX('Leaf', 'Leaf_vec', $q, $n) " + const VecStmt = "CALL QUERY_VECTOR_INDEX('Leaf', 'Leaf_vec', $q, $n) " +
"RETURN node.id, node.text, node.root, node.source, distance, node.confidence, " + "RETURN node.id, node.text, node.root, node.source, distance, node.confidence ORDER BY distance LIMIT $n"
"node.valid_from, node.valid_to ORDER BY distance LIMIT $n"
// HopStmt is the Cypher walk from a search hit. Depth 1 = File, 2 = Commit, 3 = Person. // HopStmt is the Cypher walk from a search hit. Depth 1 = File, 2 = Commit, 3 = Person.
func HopStmt(depth int) string { func HopStmt(depth int) string {
+4 -31
View File
@@ -5,8 +5,6 @@ package rank
import ( import (
"sort" "sort"
"strings" "strings"
"github.com/eSlider/2dph/internal/facts"
) )
type HopNode struct { type HopNode struct {
@@ -25,24 +23,17 @@ type Hit struct {
Source string `json:"-"` Source string `json:"-"`
Score float64 `json:"score"` Score float64 `json:"score"`
Snippet string `json:"snippet,omitempty"` Snippet string `json:"snippet,omitempty"`
ValidFrom string `json:"valid_from,omitempty"`
ValidTo string `json:"valid_to,omitempty"`
Hops []HopNode `json:"hops,omitempty"` Hops []HopNode `json:"hops,omitempty"`
} }
// rrfK dampens the contribution of low ranks; same constant as kblib.py. // rrfK dampens the contribution of low ranks; same constant as kblib.py.
const rrfK = 60 const rrfK = 60
// RankAndFilter fuses the two hit lists, applies --root/--repo/--as-of, then // RankAndFilter fuses the two hit lists, applies --root/--repo, then cuts to
// cuts to limit. Cutting first dropped every matching leaf ranked below the // limit. Cutting first dropped every matching leaf ranked below the cut, so
// cut, so `--root facts` came back empty whenever info leafs filled the top N. // `--root facts` came back empty whenever info leafs filled the top N.
// limit <= 0 keeps everything. asOf empty skips interval filter (D24). // limit <= 0 keeps everything.
func RankAndFilter(fts, vec []Hit, root, repo string, limit int) []Hit { func RankAndFilter(fts, vec []Hit, root, repo string, limit int) []Hit {
return RankAndFilterAsOf(fts, vec, root, repo, "", limit)
}
// RankAndFilterAsOf is RankAndFilter with D24 fact-interval filter.
func RankAndFilterAsOf(fts, vec []Hit, root, repo, asOf string, limit int) []Hit {
out := Hybrid(fts, vec, 0) out := Hybrid(fts, vec, 0)
if root != "" { if root != "" {
out = FilterRoot(out, root) out = FilterRoot(out, root)
@@ -50,30 +41,12 @@ func RankAndFilterAsOf(fts, vec []Hit, root, repo, asOf string, limit int) []Hit
if repo != "" { if repo != "" {
out = FilterRepo(out, repo) out = FilterRepo(out, repo)
} }
if asOf != "" {
out = FilterAsOf(out, asOf)
}
if limit > 0 && len(out) > limit { if limit > 0 && len(out) > limit {
out = out[:limit] out = out[:limit]
} }
return out return out
} }
// FilterAsOf keeps hits whose [valid_from, valid_to] covers asOf (D24).
// Empty intervals stay (legacy leafs). Empty asOf keeps all.
func FilterAsOf(hits []Hit, asOf string) []Hit {
if asOf == "" {
return hits
}
var out []Hit
for _, h := range hits {
if facts.ActiveAt(h.ValidFrom, h.ValidTo, asOf) {
out = append(out, h)
}
}
return out
}
// Hybrid merges FTS and vector hits by reciprocal rank fusion. // Hybrid merges FTS and vector hits by reciprocal rank fusion.
// limit <= 0 returns the full fused list. // limit <= 0 returns the full fused list.
func Hybrid(fts, vec []Hit, limit int) []Hit { func Hybrid(fts, vec []Hit, limit int) []Hit {
+6 -38
View File
@@ -55,7 +55,7 @@ func runSearch(args []string) int {
} }
defer closeBrain() defer closeBrain()
hits, err := searchHits(query, root, repo, limit, opt.AsOf) hits, err := searchHits(query, root, repo, limit)
if err != nil { if err != nil {
fmt.Fprintf(os.Stderr, "search: %v\n", err) fmt.Fprintf(os.Stderr, "search: %v\n", err)
return 1 return 1
@@ -85,7 +85,6 @@ func runSearch(args []string) int {
out := Dict{ out := Dict{
{"query", query}, {"query", query},
{"root_filter", root}, {"root_filter", root},
{"as_of", opt.AsOf},
{"count", len(results)}, {"count", len(results)},
{"results", resultsToDicts(results)}, {"results", resultsToDicts(results)},
} }
@@ -97,13 +96,13 @@ func runSearch(args []string) int {
enc := json.NewEncoder(os.Stdout) enc := json.NewEncoder(os.Stdout)
enc.SetIndent("", " ") enc.SetIndent("", " ")
enc.SetEscapeHTML(false) enc.SetEscapeHTML(false)
return b2i(enc.Encode(toJSONOut(results, query, root, opt.AsOf, webOut))) return b2i(enc.Encode(toJSONOut(results, query, root, webOut)))
} }
fmt.Print(toYAML(out, 0)) fmt.Print(toYAML(out, 0))
return 0 return 0
} }
func searchHits(query, root, repo string, limit int, asOf string) ([]Hit, error) { func searchHits(query, root, repo string, limit int) ([]Hit, error) {
emb, err := embedQuery(query) emb, err := embedQuery(query)
if err != nil { if err != nil {
return nil, fmt.Errorf("embed: %w", err) return nil, fmt.Errorf("embed: %w", err)
@@ -116,7 +115,7 @@ func searchHits(query, root, repo string, limit int, asOf string) ([]Hit, error)
if vec, err = queryVector(emb, limit*3); err != nil { if vec, err = queryVector(emb, limit*3); err != nil {
fmt.Fprintf(os.Stderr, "vec: %v\n", err) fmt.Fprintf(os.Stderr, "vec: %v\n", err)
} }
return rank.RankAndFilterAsOf(fts, vec, root, repo, asOf, limit), nil return rank.RankAndFilter(fts, vec, root, repo, limit), nil
} }
func attachHops(hits []Hit, n int) error { func attachHops(hits []Hit, n int) error {
@@ -221,35 +220,15 @@ func rowsToHits(res *lbug.QueryResult) ([]Hit, error) {
if len(vals) >= 6 { if len(vals) >= 6 {
conf = fmt.Sprint(vals[5]) conf = fmt.Sprint(vals[5])
} }
vf, vt := "", "" hits = append(hits, Hit{ID: id, Text: text, Root: root, Source: source, Score: score, Confidence: conf})
if len(vals) >= 8 {
vf = nullStr(vals[6])
vt = nullStr(vals[7])
}
hits = append(hits, Hit{
ID: id, Text: text, Root: root, Source: source, Score: score,
Confidence: conf, ValidFrom: vf, ValidTo: vt,
})
} }
return hits, nil return hits, nil
} }
func nullStr(v any) string {
if v == nil {
return ""
}
s := fmt.Sprint(v)
if s == "<nil>" {
return ""
}
return s
}
// JSON output types // JSON output types
type jsonOut struct { type jsonOut struct {
Query string `json:"query"` Query string `json:"query"`
RootFilter string `json:"root_filter"` RootFilter string `json:"root_filter"`
AsOf string `json:"as_of,omitempty"`
Count int `json:"count"` Count int `json:"count"`
Results []jsonHit `json:"results"` Results []jsonHit `json:"results"`
Web *rank.SecondSource `json:"web,omitempty"` Web *rank.SecondSource `json:"web,omitempty"`
@@ -262,12 +241,10 @@ type jsonHit struct {
Confidence string `json:"confidence,omitempty"` Confidence string `json:"confidence,omitempty"`
Score float64 `json:"score"` Score float64 `json:"score"`
Snippet string `json:"snippet,omitempty"` Snippet string `json:"snippet,omitempty"`
ValidFrom string `json:"valid_from,omitempty"`
ValidTo string `json:"valid_to,omitempty"`
Hops []rank.HopNode `json:"hops,omitempty"` Hops []rank.HopNode `json:"hops,omitempty"`
} }
func toJSONOut(hits []Hit, query, rootFilter, asOf string, web *rank.SecondSource) *jsonOut { func toJSONOut(hits []Hit, query, rootFilter string, web *rank.SecondSource) *jsonOut {
out := make([]jsonHit, len(hits)) out := make([]jsonHit, len(hits))
for i, h := range hits { for i, h := range hits {
out[i] = jsonHit{ out[i] = jsonHit{
@@ -277,15 +254,12 @@ func toJSONOut(hits []Hit, query, rootFilter, asOf string, web *rank.SecondSourc
Confidence: h.Confidence, Confidence: h.Confidence,
Score: h.Score, Score: h.Score,
Snippet: h.Snippet, Snippet: h.Snippet,
ValidFrom: h.ValidFrom,
ValidTo: h.ValidTo,
Hops: h.Hops, Hops: h.Hops,
} }
} }
return &jsonOut{ return &jsonOut{
Query: query, Query: query,
RootFilter: rootFilter, RootFilter: rootFilter,
AsOf: asOf,
Count: len(hits), Count: len(hits),
Results: out, Results: out,
Web: web, Web: web,
@@ -304,12 +278,6 @@ func resultsToDicts(hits []Hit) []any {
if h.Confidence != "" { if h.Confidence != "" {
d = append(d, KV{"confidence", h.Confidence}) d = append(d, KV{"confidence", h.Confidence})
} }
if h.ValidFrom != "" {
d = append(d, KV{"valid_from", h.ValidFrom})
}
if h.ValidTo != "" {
d = append(d, KV{"valid_to", h.ValidTo})
}
if h.Snippet != "" { if h.Snippet != "" {
d = append(d, KV{"snippet", h.Snippet}) d = append(d, KV{"snippet", h.Snippet})
} }
-44
View File
@@ -1,44 +0,0 @@
package facts
// Interval of truth for a fact leaf (D24 / OQ5). Not D16 source staleness.
//
// Empty valid_from and valid_to means "always" (legacy leafs). Empty asOf
// means "do not filter". Dates compare as YYYY-MM-DD (lexicographic).
// NormalizeDay keeps the calendar day from ISO-8601 or bare dates.
func NormalizeDay(s string) string {
s = trimSpace(s)
if len(s) >= 10 && s[4] == '-' && s[7] == '-' {
return s[:10]
}
return s
}
func trimSpace(s string) string {
i, j := 0, len(s)
for i < j && (s[i] == ' ' || s[i] == '\t' || s[i] == '\n' || s[i] == '\r') {
i++
}
for j > i && (s[j-1] == ' ' || s[j-1] == '\t' || s[j-1] == '\n' || s[j-1] == '\r') {
j--
}
return s[i:j]
}
// ActiveAt reports whether a fact with [validFrom, validTo] holds at asOf.
// validTo empty = open-ended. Both ends inclusive.
func ActiveAt(validFrom, validTo, asOf string) bool {
asOf = NormalizeDay(asOf)
if asOf == "" {
return true
}
from := NormalizeDay(validFrom)
to := NormalizeDay(validTo)
if from != "" && asOf < from {
return false
}
if to != "" && asOf > to {
return false
}
return true
}
-73
View File
@@ -1,73 +0,0 @@
package facts
import "testing"
func TestActiveAtOpenEnded(t *testing.T) {
// works at Y from 2025-07-16, no end
if !ActiveAt("2025-07-16", "", "2025-07-16") {
t.Fatal("inclusive valid_from")
}
if !ActiveAt("2025-07-16", "", "2026-01-01") {
t.Fatal("open-ended valid_to")
}
if ActiveAt("2025-07-16", "", "2025-07-15") {
t.Fatal("before valid_from must be inactive")
}
}
func TestActiveAtClosedInterval(t *testing.T) {
// works at X 2024-03-01 .. 2025-07-15
if !ActiveAt("2024-03-01", "2025-07-15", "2025-01-01") {
t.Fatal("mid interval")
}
if !ActiveAt("2024-03-01", "2025-07-15", "2024-03-01") {
t.Fatal("inclusive start")
}
if !ActiveAt("2024-03-01", "2025-07-15", "2025-07-15") {
t.Fatal("inclusive end")
}
if ActiveAt("2024-03-01", "2025-07-15", "2025-07-16") {
t.Fatal("day after end")
}
if ActiveAt("2024-03-01", "2025-07-15", "2024-02-28") {
t.Fatal("day before start")
}
}
func TestActiveAtEmptyIntervalAlwaysTrue(t *testing.T) {
// legacy leafs without intervals stay visible for any as-of
if !ActiveAt("", "", "2025-01-01") {
t.Fatal("empty interval must remain active")
}
if !ActiveAt("", "", "") {
t.Fatal("no as-of means all active")
}
}
func TestActiveAtEmptyAsOfKeepsAll(t *testing.T) {
if !ActiveAt("2099-01-01", "2099-12-31", "") {
t.Fatal("empty as-of must not filter")
}
}
func TestAsOfPickXNotY(t *testing.T) {
// Acceptance from #36: as of 2025-01-01 → X, not Y
xFrom, xTo := "2024-03-01", "2025-07-15"
yFrom, yTo := "2025-07-16", ""
asOf := "2025-01-01"
if !ActiveAt(xFrom, xTo, asOf) {
t.Fatal("X must be active as of 2025-01-01")
}
if ActiveAt(yFrom, yTo, asOf) {
t.Fatal("Y must be inactive as of 2025-01-01")
}
}
func TestNormalizeDayTrimsTime(t *testing.T) {
if NormalizeDay("2025-01-01T12:00:00Z") != "2025-01-01" {
t.Fatalf("got %q", NormalizeDay("2025-01-01T12:00:00Z"))
}
if NormalizeDay("2025-01-01") != "2025-01-01" {
t.Fatalf("got %q", NormalizeDay("2025-01-01"))
}
}
+1 -8
View File
@@ -105,18 +105,11 @@ func (s *Server) mcpCall(r *http.Request, params json.RawMessage) (any, error) {
if limit < 1 || limit > 100 { if limit < 1 || limit > 100 {
return mcpText(`{"error":"n must be int 1..100"}`, true), nil return mcpText(`{"error":"n must be int 1..100"}`, true), nil
} }
asOf := ""
if raw, ok := p.Arguments["as_of"]; ok {
asOf = strings.TrimSpace(fmt.Sprint(raw))
if asOf == "<nil>" {
asOf = ""
}
}
if !s.tryAcquire(r) { if !s.tryAcquire(r) {
return nil, fmt.Errorf("cancelled") return nil, fmt.Errorf("cancelled")
} }
defer s.release() defer s.release()
body, err = s.api.Search(r.Context(), q, limit, asOf) body, err = s.api.Search(r.Context(), q, limit)
case "get": case "get":
id := strings.TrimSpace(fmt.Sprint(p.Arguments["id"])) id := strings.TrimSpace(fmt.Sprint(p.Arguments["id"]))
if id == "" || id == "<nil>" { if id == "" || id == "<nil>" {
+4 -10
View File
@@ -24,7 +24,7 @@ import (
// API is the in-process brain surface. Production serve.go wires internal/brain. // API is the in-process brain surface. Production serve.go wires internal/brain.
type API interface { type API interface {
Search(ctx context.Context, query string, limit int, asOf string) ([]byte, error) Search(ctx context.Context, query string, limit int) ([]byte, error)
Get(ctx context.Context, id string, body bool) ([]byte, error) Get(ctx context.Context, id string, body bool) ([]byte, error)
Stats(ctx context.Context) ([]byte, error) Stats(ctx context.Context) ([]byte, error)
Audit(ctx context.Context) ([]byte, error) Audit(ctx context.Context) ([]byte, error)
@@ -85,12 +85,11 @@ func (s *Server) handleSearch(w http.ResponseWriter, r *http.Request) {
} }
limit = n limit = n
} }
asOf := strings.TrimSpace(r.URL.Query().Get("as_of"))
if !s.acquire(w, r) { if !s.acquire(w, r) {
return return
} }
defer s.release() defer s.release()
body, err := s.api.Search(r.Context(), q, limit, asOf) body, err := s.api.Search(r.Context(), q, limit)
writeAPI(w, body, err) writeAPI(w, body, err)
} }
@@ -188,18 +187,13 @@ type ExecSearcher struct {
Timeout time.Duration Timeout time.Duration
} }
func (b ExecSearcher) Search(ctx context.Context, query string, limit int, asOf string) ([]byte, error) { func (b ExecSearcher) Search(ctx context.Context, query string, limit int) ([]byte, error) {
if b.Timeout == 0 { if b.Timeout == 0 {
b.Timeout = 60 * time.Second b.Timeout = 60 * time.Second
} }
ctx, cancel := context.WithTimeout(ctx, b.Timeout) ctx, cancel := context.WithTimeout(ctx, b.Timeout)
defer cancel() defer cancel()
args := []string{"--json", "-n", strconv.Itoa(limit)} cmd := exec.CommandContext(ctx, b.CmdPath, "--json", "-n", strconv.Itoa(limit), query)
if asOf != "" {
args = append(args, "--as-of", asOf)
}
args = append(args, query)
cmd := exec.CommandContext(ctx, b.CmdPath, args...)
out, err := cmd.Output() out, err := cmd.Output()
if err != nil { if err != nil {
var exitErr *exec.ExitError var exitErr *exec.ExitError
+5 -5
View File
@@ -21,10 +21,10 @@ type fakeSearcher struct {
calls int calls int
active atomic.Int32 active atomic.Int32
maxSeen atomic.Int32 maxSeen atomic.Int32
callback func(q string, limit int, asOf string) ([]byte, error) callback func(q string, limit int) ([]byte, error)
} }
func (f *fakeSearcher) Search(ctx context.Context, query string, limit int, asOf string) ([]byte, error) { func (f *fakeSearcher) Search(ctx context.Context, query string, limit int) ([]byte, error) {
f.mu.Lock() f.mu.Lock()
f.calls++ f.calls++
f.mu.Unlock() f.mu.Unlock()
@@ -44,7 +44,7 @@ func (f *fakeSearcher) Search(ctx context.Context, query string, limit int, asOf
} }
} }
if f.callback != nil { if f.callback != nil {
return f.callback(query, limit, asOf) return f.callback(query, limit)
} }
return []byte(`{"query":"` + query + `","count":0,"results":[]}`), nil return []byte(`{"query":"` + query + `","count":0,"results":[]}`), nil
} }
@@ -109,7 +109,7 @@ func TestSearchMissingQuery(t *testing.T) {
} }
func TestSearchReturnsSearcherResult(t *testing.T) { func TestSearchReturnsSearcherResult(t *testing.T) {
fs := &fakeSearcher{callback: func(q string, limit int, asOf string) ([]byte, error) { fs := &fakeSearcher{callback: func(q string, limit int) ([]byte, error) {
return []byte(`{"query":"` + q + `","count":1,"results":[{"id":"x"}]}`), nil return []byte(`{"query":"` + q + `","count":1,"results":[{"id":"x"}]}`), nil
}} }}
h := NewServer(fs, 1) h := NewServer(fs, 1)
@@ -168,7 +168,7 @@ func TestSearchRejectsBadLimit(t *testing.T) {
} }
func TestGetLeaf(t *testing.T) { func TestGetLeaf(t *testing.T) {
fs := &fakeSearcher{callback: func(q string, limit int, asOf string) ([]byte, error) { fs := &fakeSearcher{callback: func(q string, limit int) ([]byte, error) {
return []byte(`{}`), nil return []byte(`{}`), nil
}} }}
h := NewServer(fs, 1) h := NewServer(fs, 1)
-3
View File
@@ -35,7 +35,6 @@ var Ops = []Op{
Params: []Param{ Params: []Param{
{Name: "q", In: "query", Type: "string", Description: "search query", Required: true}, {Name: "q", In: "query", Type: "string", Description: "search query", Required: true},
{Name: "n", In: "query", Type: "integer", Description: "hit limit 1..100 (default 10)"}, {Name: "n", In: "query", Type: "integer", Description: "hit limit 1..100 (default 10)"},
{Name: "as_of", In: "query", Type: "string", Description: "YYYY-MM-DD; keep facts active on that day (D24)"},
}, },
}, },
{ {
@@ -55,8 +54,6 @@ var Ops = []Op{
{Name: "text", In: "query", Type: "string", Description: "leaf text (omit for CLI hint)"}, {Name: "text", In: "query", Type: "string", Description: "leaf text (omit for CLI hint)"},
{Name: "root", In: "query", Type: "string", Description: "facts or info (default info)"}, {Name: "root", In: "query", Type: "string", Description: "facts or info (default info)"},
{Name: "source", In: "query", Type: "string", Description: "evidence pointer; facts need two sources"}, {Name: "source", In: "query", Type: "string", Description: "evidence pointer; facts need two sources"},
{Name: "valid_from", In: "query", Type: "string", Description: "fact interval start YYYY-MM-DD (D24)"},
{Name: "valid_to", In: "query", Type: "string", Description: "fact interval end YYYY-MM-DD inclusive (D24)"},
}, },
}, },
{Path: PathOpenAPI, Method: "get", ID: "openapi", Summary: "OpenAPI 3 document for this server"}, {Path: PathOpenAPI, Method: "get", ID: "openapi", Summary: "OpenAPI 3 document for this server"},
-3
View File
@@ -26,7 +26,6 @@ second independent source when local roots cannot confirm. An answer is
bin/brain/search.go "Matrix federation" # pointers + snippets, YAML bin/brain/search.go "Matrix federation" # pointers + snippets, YAML
bin/brain/search.go "onlyoffice postgres" --root facts # restrict to confirmed bin/brain/search.go "onlyoffice postgres" --root facts # restrict to confirmed
bin/brain/search.go "where is cs-lexicon" --json | yq '.[].ref' bin/brain/search.go "where is cs-lexicon" --json | yq '.[].ref'
bin/brain/search.go "who works where" --as-of 2025-01-01 # D24 intervals
bin/brain/add.go --text T --root facts --source "a.md x b.md" bin/brain/add.go --text T --root facts --source "a.md x b.md"
bin/brain/get.go <id> --body # full chunk only when needed bin/brain/get.go <id> --body # full chunk only when needed
bin/brain/stats.go # index health bin/brain/stats.go # index health
@@ -35,8 +34,6 @@ bin/brain/eval.go # recall@5 >= 0.95 gate (
`bin/kb/search` is a deprecated wrapper. `--hop N` walks `bin/kb/search` is a deprecated wrapper. `--hop N` walks
`FROM_FILE` / `HAS_VERSION` / `AUTHORED` from each hit (1=File, 3=Person). `FROM_FILE` / `HAS_VERSION` / `AUTHORED` from each hit (1=File, 3=Person).
`--as-of YYYY-MM-DD` keeps leafs whose `valid_from`/`valid_to` cover that day
(empty interval = always; not D16 source staleness).
## Rules ## Rules
-6
View File
@@ -12,12 +12,6 @@ PicoClaw speaks MCP at `POST /mcp` on `bin/brain/serve.go`. Compose profile
`picoclaw` runs the official `sipeed/picoclaw` gateway plus `brain-mcp` `picoclaw` runs the official `sipeed/picoclaw` gateway plus `brain-mcp`
(see [docs/picoclaw.md](../../docs/picoclaw.md)). (see [docs/picoclaw.md](../../docs/picoclaw.md)).
```bash
bin/stack/start-assistant # brain + qwen3.5:9b + gateway + picoclaw agent
bin/stack/status
bin/stack/stop
```
## Tool order (before a factual reply) ## Tool order (before a factual reply)
1. **`search`** — facts root first, then info. The `web` block is a second 1. **`search`** — facts root first, then info. The `web` block is a second