Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1f9bdb0bf6 | ||
|
|
0a05803f4b | ||
|
|
ad83e2a12f | ||
|
|
d894c6609f | ||
|
|
ff80359684 |
@@ -3,6 +3,7 @@
|
||||
var
|
||||
.git
|
||||
.github
|
||||
lib-ladybug
|
||||
__pycache__
|
||||
*.pyc
|
||||
*.lbug
|
||||
|
||||
@@ -37,6 +37,9 @@ jobs:
|
||||
bash -n bin/db/ssh-tunnel
|
||||
bash -n bin/docker-entrypoint
|
||||
bash -n bin/kb/search
|
||||
bash -n bin/cgo/zig
|
||||
sh -n bin/cgo/zcc
|
||||
sh -n bin/cgo/zc++
|
||||
|
||||
- name: Python unit tests (offline, vendored tools)
|
||||
run: |
|
||||
@@ -54,9 +57,10 @@ jobs:
|
||||
run: |
|
||||
./bin/facts/audit self 2>/dev/null || echo "audit: not yet implemented; gate skipped"
|
||||
|
||||
- name: kb/eval recall gate
|
||||
- name: CGO via Zig (compile brain/search)
|
||||
run: |
|
||||
./bin/kb/eval 2>/dev/null || echo "eval: not yet implemented; gate skipped"
|
||||
chmod +x bin/cgo/zig bin/cgo/zcc bin/cgo/zc++
|
||||
bin/cgo/zig go build -tags system_ladybug -o /tmp/brain-search ./bin/brain/search.go
|
||||
|
||||
release:
|
||||
name: Release (semver)
|
||||
|
||||
@@ -15,6 +15,9 @@ Read first: [PLAN](PLAN.md) → [docs](docs/).
|
||||
- `info` root = descriptive/narrative leafs, searchable, never asserted as fact.
|
||||
- Search is deduction: `facts` → `info` → `web-search` (second independent
|
||||
source). An answer is `confirmed` only if it comes off the facts root.
|
||||
- Fact-check every *claim* (facts → info → live → web), not every edit or
|
||||
syntax tweak. PicoClaw: `search` then `get` then `audit` before a factual
|
||||
reply (`skills/picoclaw/SKILL.md`). `throttled` is not a negative finding.
|
||||
|
||||
## Hard rules
|
||||
|
||||
@@ -46,9 +49,10 @@ bin/web/ search.go (SearXNG; Python shim execs it)
|
||||
internal/ shared Go (brain/rank is cgo-free; chats parsers; gitlog; websearch)
|
||||
bin/watch/ corpus watcher (used by bin/brain/watch.go)
|
||||
bin/tools/ vendored python libs behind bin/* (kblib, yamlout, websearch)
|
||||
bin/docker-entrypoint container entrypoint (brain index|search|serve|watch)
|
||||
bin/cgo/ zig zcc zc++ (CGO via zig cc, not gcc)
|
||||
bin/docker-entrypoint container entrypoint (api: serve|search|watch; index: python)
|
||||
compose.yaml docker composition (root level, not docker/)
|
||||
Dockerfile multi-stage: python deps + static Go binaries
|
||||
Dockerfile api (Zig CGO, no Python) + index (Python write)
|
||||
var/ kb.lbug, var/mail/*, caches (gitignored)
|
||||
.venv/ ladybug + model2vec + mistune
|
||||
```
|
||||
@@ -82,9 +86,11 @@ bin/facts/crm.go [--dry-run] # proof person↔company/comp
|
||||
bin/kb/search "query" [--repo X] # deprecated wrapper → bin/brain/search.go
|
||||
bin/brain/search.go "query" [--root facts|info] # deduction search → YAML
|
||||
bin/brain/search.go "query" --no-web # local graph only
|
||||
eval "$(bin/cgo/zig env)" # Zig cc + liblbug (not gcc)
|
||||
bin/brain/get.go <id> [--body] [--json] # Go read; Python bin/kb/get CI fallback
|
||||
bin/brain/stats.go [--json]
|
||||
bin/brain/eval.go [--json] # recall@5; questions in internal/brain/rank
|
||||
bin/brain/serve.go # HTTP :8630; GET /openapi.json POST /mcp
|
||||
bin/markdown/import.go [dir] # mistune leaves → YAML
|
||||
bin/git/import.go [REPO] [--json] [--limit N] # go-git history → commit leafs
|
||||
bin/web/search.go "query" [--json] # SearXNG; throttled ≠ absence
|
||||
|
||||
+56
-16
@@ -1,5 +1,13 @@
|
||||
# syntax=docker/dockerfile:1
|
||||
FROM python:3.12-slim AS base
|
||||
#
|
||||
# docker build --target api -t 2dph:api .
|
||||
# docker build --target index -t 2dph:index .
|
||||
#
|
||||
# API: Go + ladybug via Zig CGO (no CPython).
|
||||
# Index: Python write path (profile `index` until brain/add is v2).
|
||||
|
||||
# --- Python sidecar (Ladybug write / rebuild) ---
|
||||
FROM python:3.12-slim AS index
|
||||
|
||||
ENV PYTHONUNBUFFERED=1 \
|
||||
PYTHONDONTWRITEBYTECODE=1 \
|
||||
@@ -9,25 +17,11 @@ ENV PYTHONUNBUFFERED=1 \
|
||||
WORKDIR /app
|
||||
RUN id -u 2dph 2>/dev/null || useradd --create-home --uid 1001 2dph
|
||||
|
||||
# deps layer-first: rebuild only on dependency change
|
||||
COPY requirements.lock.txt /tmp/requirements.lock.txt
|
||||
RUN python -m pip install --no-cache-dir -r /tmp/requirements.lock.txt \
|
||||
&& rm /tmp/requirements.lock.txt
|
||||
|
||||
# Go services: static binaries, no interpreter at runtime
|
||||
FROM golang:1.25 AS go-build
|
||||
WORKDIR /src
|
||||
COPY go.mod ./
|
||||
COPY bin/server ./bin/server
|
||||
COPY bin/watch ./bin/watch
|
||||
RUN CGO_ENABLED=0 go build -o /serve ./bin/server \
|
||||
&& CGO_ENABLED=0 go build -o /watch ./bin/watch
|
||||
|
||||
# runtime: python toolchain + Go services
|
||||
FROM base
|
||||
COPY . .
|
||||
COPY --from=go-build /serve /app/bin/serve
|
||||
COPY --from=go-build /watch /app/bin/watch
|
||||
RUN chmod +x /app/bin/docker-entrypoint \
|
||||
&& chown -R 2dph:2dph /app
|
||||
USER 2dph
|
||||
@@ -37,5 +31,51 @@ ENV PATH="/app/bin:${PATH}" \
|
||||
KB_ROOT=/app
|
||||
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
|
||||
CMD python -c "import model2vec, ladybug, mistune; print('ok')" || exit 1
|
||||
|
||||
ENTRYPOINT ["/app/bin/docker-entrypoint"]
|
||||
|
||||
# --- Go API: CGO with Zig, not gcc ---
|
||||
FROM golang:1.26-bookworm AS api-build
|
||||
WORKDIR /src
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends curl xz-utils ca-certificates \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
COPY bin/cgo ./bin/cgo
|
||||
RUN chmod +x bin/cgo/zig bin/cgo/zcc bin/cgo/zc++ \
|
||||
&& ./bin/cgo/zig env >/dev/null
|
||||
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
|
||||
COPY . .
|
||||
ENV CGO_RPATH=/usr/local/lib
|
||||
RUN eval "$(./bin/cgo/zig env)" \
|
||||
&& go build -tags brain_serve,system_ladybug -o /out/brain-serve ./bin/brain/serve.go \
|
||||
&& go build -tags system_ladybug -o /out/brain-search ./bin/brain/search.go \
|
||||
&& CGO_ENABLED=0 go build -tags brain_watch -o /out/brain-watch ./bin/brain/watch.go
|
||||
|
||||
FROM debian:bookworm-slim AS api
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends libssl3 ca-certificates wget \
|
||||
&& rm -rf /var/lib/apt/lists/* \
|
||||
&& useradd --create-home --uid 1001 2dph
|
||||
COPY --from=api-build /out/brain-serve /usr/local/bin/brain-serve
|
||||
COPY --from=api-build /out/brain-search /usr/local/bin/brain-search
|
||||
COPY --from=api-build /out/brain-watch /usr/local/bin/brain-watch
|
||||
COPY --from=api-build /src/lib-ladybug/liblbug.so.0.19.1 /usr/local/lib/liblbug.so.0.19.1
|
||||
COPY bin/docker-entrypoint /usr/local/bin/docker-entrypoint
|
||||
RUN chmod +x /usr/local/bin/docker-entrypoint \
|
||||
&& ln -s liblbug.so.0.19.1 /usr/local/lib/liblbug.so.0 \
|
||||
&& ln -s liblbug.so.0 /usr/local/lib/liblbug.so \
|
||||
&& ldconfig
|
||||
USER 2dph
|
||||
ENV KB_ROOT=/data \
|
||||
KB_PORT=8630 \
|
||||
LD_LIBRARY_PATH=/usr/local/lib \
|
||||
HF_HOME=/data/hf
|
||||
WORKDIR /data
|
||||
EXPOSE 8630
|
||||
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
|
||||
CMD wget -qO- http://127.0.0.1:8630/health || exit 1
|
||||
ENTRYPOINT ["/usr/local/bin/docker-entrypoint"]
|
||||
CMD ["serve"]
|
||||
|
||||
@@ -29,7 +29,7 @@ detective method: **a fact needs ≥2 independent sources or it is
|
||||
| D3 | web search | Go client `bin/web/search.go` (`internal/websearch`). SearXNG URL is config (`BRAIN_SEARCH_URL`). Optional Compose profile `searxng` (sanitized settings). Do not run a second copy on a host that already has one. Empty/`throttled` ≠ “nothing exists”. |
|
||||
| D4 | embeddings | **model2vec** `minishlab/potion-multilingual-128M` instead of embeddinggemma. |
|
||||
| D5 | parser | **mistune** for MD → leaf extraction (duckdb-md documented as future optional SQL/export layer, not v1). |
|
||||
| D6 | graph engine | **LadybugDB**. Go is the service (`bin/brain/search.go`, `bin/brain/serve.go` in-process, `internal/brain`). Read path (`get.go` / `stats.go` / `eval.go`) is Go + cgo. Python `bin/kb/{get,stats,eval}` is the CI fallback (GitHub runners have no ladybug cgo). Index/write stays Python until the Go write path is safe. |
|
||||
| D6 | graph engine | **LadybugDB**. Go is the service (`bin/brain/search.go`, `bin/brain/serve.go` in-process, `internal/brain`). Read path is Go + Zig CGO (D21). Python `bin/kb/{get,stats,eval}` is the CI fallback when Zig/libs are not fetched. Index/write stays Python (`compose --profile index`) until the Go write path is safe. |
|
||||
| D7 | db access | `db-yaml`/`psql-yq`-style, read-only, YAML out. OnlyOffice Postgres via SSH tunnel (`127.0.0.1:5433`). |
|
||||
| D8 | evidence | detective method: ≥2 independent sources or `(not confirmed)`. Auto-pair docker ps × compose × ssh-config × docs. |
|
||||
| D9 | facts/goal model | Who / What / How / Where / When + evidence + confidence on every edge. |
|
||||
@@ -43,6 +43,8 @@ detective method: **a fact needs ≥2 independent sources or it is
|
||||
| D17 | assertion gate | Fact-check every *claim* (facts → info → live → web), not every edit. `bin/brain/search.go` adds a `web` block when there is no facts hit (`throttled`/`skipped`/`refused` ≠ absence). `--root` and `--no-web` stay local. Missing graph ≠ “does not exist”. |
|
||||
| D18 | reasoner | Pluggable OpenAI-compatible URL. RAM: Qwen3.5-9B. Quality: Bonsai-27B or Qwen3.6-27B. No official Qwen3.6-9B. |
|
||||
| D19 | git history | [go-git](https://github.com/go-git/go-git) via `bin/git/import.go`. No subprocess of the git binary. Conversion prints commit leafs; brain write is `bin/brain/index.go`. |
|
||||
| D20 | agent API | OpenAPI + MCP are generated from the same `internal/httpapi.Ops` table as `bin/brain/serve.go` handlers. `GET /openapi.json`, `POST /mcp` (JSON-RPC tools/list + tools/call). Tool names match OpenAPI paths (`search`/`get`/`stats`/`audit`). |
|
||||
| D21 | CGO | Ladybug/tokenizers CGO is compiled with **Zig** (`bin/cgo/zcc` → `zig cc -target …-linux-gnu`), not gcc. `bin/cgo/zig` pins Zig 0.14.1 + liblbug 0.19.1 + libtokenizers 1.27.0. Compose `target: api` has no CPython; write/rebuild is profile `index`. |
|
||||
|
||||
## Architecture
|
||||
|
||||
@@ -50,7 +52,7 @@ detective method: **a fact needs ≥2 independent sources or it is
|
||||
2dph/
|
||||
PLAN.md / AGENTS.md
|
||||
docs/ published docs (this conversation → docs/ as md)
|
||||
skills/ in-project skills (web-search, db-yaml, brain, diataxis-docs)
|
||||
skills/ in-project skills (web-search, postgres, brain, picoclaw, diataxis-docs)
|
||||
bin/
|
||||
facts/extract.go audit.go crm.go # D14 shebang; Python implementation
|
||||
kb/index Python write path (called by bin/brain/index.go)
|
||||
@@ -58,7 +60,8 @@ detective method: **a fact needs ≥2 independent sources or it is
|
||||
brain/get.go stats.go eval.go # Go read (cgo); Python bin/kb/* CI fallback
|
||||
brain/watch.go
|
||||
brain/search.go deduction: facts → info → web-search
|
||||
brain/serve.go HTTP API in-process (internal/httpapi + internal/brain)
|
||||
brain/serve.go HTTP API in-process + OpenAPI/MCP (D20); Zig CGO (D21)
|
||||
cgo/zig zcc zc++ CGO toolchain (zig cc, not gcc)
|
||||
mail/import.go JSON → markdown (no brain write)
|
||||
markdown/import.go mistune leaves
|
||||
postgres/query.go read-only YAML (wraps bin/db/psql-yq)
|
||||
@@ -133,10 +136,8 @@ Common props on every node/edge: `root`, `confidence`, `evidence[]`, `how`,
|
||||
2. `go test ./internal/brain/rank` (cgo-free ranking + flag parser)
|
||||
3. python -m unittest discover -s bin/tools (includes published-docs SoT)
|
||||
4. `bin/facts/audit self` (lexicon internal consistency; `bin/facts/audit.go` is the D14 wrapper)
|
||||
5. `bin/kb/eval` (recall@5 ≥ 0.95). Local SoT is `bin/brain/eval.go`; CI uses
|
||||
the Python twin until the runner has ladybug cgo. Questions live in
|
||||
`internal/brain/rank`.
|
||||
6. md-docs build/lint if docs tooling arrives.
|
||||
5. `bin/kb/eval` (recall@5 ≥ 0.95). Local SoT is `bin/brain/eval.go` via Zig CGO.
|
||||
6. `bin/cgo/zig go build -tags system_ladybug` (compile search with zig cc; fetches pinned zig+libs).
|
||||
|
||||
Feedback loop: every commit → PR → CI → green/gate → merge. Same discipline as
|
||||
`db/tech-poc`: contract first where there is an OpenAPI/message shape.
|
||||
@@ -145,7 +146,7 @@ Feedback loop: every commit → PR → CI → green/gate → merge. Same discipl
|
||||
|
||||
1. scaffold repo (:done after this file + AGENTS.md + .gitignore + ci)
|
||||
2. gh repo create eSlider/2dph --private + initial commit + CI
|
||||
3. vendored skill integration (web-search, db-yaml, brain, diataxis-docs) — no remote links
|
||||
3. vendored skill integration (web-search, postgres, brain, diataxis-docs) — no remote links
|
||||
4. .venv: ladybug + model2vec + mistune
|
||||
5. schema + tools with TDD (kb + md + facts + brain)
|
||||
6. ~/.config/brain config
|
||||
|
||||
@@ -126,7 +126,7 @@ bin/brain/search.go "invoice from last week" # same s
|
||||
|
||||
- **LadybugDB** — single `var/kb.lbug`, Cypher property graph, HNSW + BM25
|
||||
in one engine, embedded (no server), ACID, read-only-safe for concurrent
|
||||
readers. Read tools (`get` / `stats` / `eval`) are Go + cgo; Python
|
||||
readers. Read tools (`get` / `stats` / `eval`) are Go + Zig CGO (`bin/cgo/zcc`); Python
|
||||
`bin/kb/{get,stats,eval}` is the CI fallback. **Never `DROP INDEX` FTS/VECTOR** on Ladybug 0.19: DROP leaves
|
||||
ghost catalog tables (`_0_Leaf_vec_UPPER`) so recreate fails while
|
||||
`SHOW_INDEXES` omits HNSW. Fresh indexes = delete `var/kb.lbug` +
|
||||
@@ -141,7 +141,7 @@ bin/brain/search.go "invoice from last week" # same s
|
||||
`bin/{subject}/{method}.go` — self-describing: shebang on line 1, usage comment
|
||||
from line 2. Shared code in `internal/`. YAML default output, `--json` for
|
||||
machines. Tests gate every commit. HTTP: `bin/brain/serve.go` calls
|
||||
`internal/brain` in-process (`/health` `/search` `/get` `/stats` `/audit` `/ingest`).
|
||||
`internal/brain` in-process (`/health` `/search` `/get` `/stats` `/audit` `/ingest` `/openapi.json` `/mcp`).
|
||||
|
||||
## Development
|
||||
|
||||
@@ -155,9 +155,9 @@ go test ./... && python -m unittest discover -s bin/tools -t .
|
||||
Docker (optional, cached model + var volumes):
|
||||
|
||||
```bash
|
||||
docker compose run --rm brain index # (re)index corpus
|
||||
docker compose run --rm brain search "query" # one-shot query
|
||||
docker compose run --rm brain serve # bin/brain/serve.go
|
||||
docker compose up -d brain # API (Zig CGO serve :8630)
|
||||
docker compose --profile index run --rm index # Python Ladybug rebuild
|
||||
docker compose --profile picoclaw up brain-mcp # MCP on 127.0.0.1:8630
|
||||
docker compose up brain-watch # auto re-index on change
|
||||
```
|
||||
|
||||
@@ -166,7 +166,7 @@ docker compose up brain-watch # auto re-index on change
|
||||
- [go-second-brain](https://github.com/eSlider/go-second-brain) — the earlier
|
||||
Neo4j + Qdrant + Matrix RAG brain
|
||||
- [agent-skills](https://github.com/eSlider/agent-skills) — upstream
|
||||
skills (`web-search`, `db-yaml`, …) that 2dph integrates
|
||||
skills (`web-search`, `postgres`, …) that 2dph integrates
|
||||
- detective method — the two-source method
|
||||
|
||||
Work board (issues): [git.produktor.io/eSlider/2dph/issues](https://git.produktor.io/eSlider/2dph/issues).
|
||||
|
||||
@@ -8,6 +8,7 @@
|
||||
// ./bin/brain/get.go <id> --json
|
||||
//
|
||||
// Needs CGO + libladybug. Python bin/kb/get is the CI fallback (no cgo).
|
||||
// CGO compiler is Zig (`eval "$(bin/cgo/zig env)"`), not gcc.
|
||||
// NOTE: never run `gofmt -w` on this file — it breaks the shebang.
|
||||
package main
|
||||
|
||||
|
||||
+1
-1
@@ -7,7 +7,7 @@
|
||||
// ./bin/brain/search.go serve [port]
|
||||
// ./bin/brain/search.go --list-model
|
||||
//
|
||||
// Needs CGO + libladybug (CGO_CFLAGS/CGO_LDFLAGS). Prefer the wrapper
|
||||
// Needs CGO + libladybug via Zig (`eval "$(bin/cgo/zig env)"`), not gcc.
|
||||
// bin/kb/search which sets those and builds a binary for the embed daemon.
|
||||
// NOTE: never run `gofmt -w` on this file — it breaks the shebang.
|
||||
package main
|
||||
|
||||
@@ -6,6 +6,9 @@
|
||||
// KB_ROOT=/path/to/2dph ./bin/brain/serve.go
|
||||
// KB_WORKERS=4 KB_PORT=8630 ./bin/brain/serve.go
|
||||
//
|
||||
// GET /openapi.json same Ops table as the handlers
|
||||
// POST /mcp JSON-RPC tools/list + tools/call
|
||||
//
|
||||
// Needs CGO + libladybug (same as bin/brain/search.go).
|
||||
// NOTE: never run `gofmt -w` on this file — it breaks the shebang.
|
||||
package main
|
||||
|
||||
Executable
+23
@@ -0,0 +1,23 @@
|
||||
#!/bin/sh
|
||||
# bin/cgo/zc++ — CGO CXX. Zig, not g++.
|
||||
set -eu
|
||||
ROOT="$(CDPATH= cd -- "$(dirname "$0")/../.." && pwd)"
|
||||
case "$(uname -m)" in
|
||||
x86_64|amd64) TARGET=x86_64-linux-gnu ;;
|
||||
aarch64|arm64) TARGET=aarch64-linux-gnu ;;
|
||||
*)
|
||||
echo "zc++: unsupported arch $(uname -m)" >&2
|
||||
exit 2
|
||||
;;
|
||||
esac
|
||||
if [ -n "${ZIG:-}" ] && [ -x "$ZIG" ]; then
|
||||
:
|
||||
elif [ -x "$ROOT/var/zig/zig" ]; then
|
||||
ZIG="$ROOT/var/zig/zig"
|
||||
elif command -v zig >/dev/null 2>&1; then
|
||||
ZIG="$(command -v zig)"
|
||||
else
|
||||
echo "zc++: zig missing; run bin/cgo/zig first" >&2
|
||||
exit 127
|
||||
fi
|
||||
exec "$ZIG" c++ -target "$TARGET" "$@"
|
||||
Executable
+24
@@ -0,0 +1,24 @@
|
||||
#!/bin/sh
|
||||
# bin/cgo/zcc — CGO CC. Zig, not gcc.
|
||||
# Go invokes CC with many args; a wrapper avoids spaces in $CC.
|
||||
set -eu
|
||||
ROOT="$(CDPATH= cd -- "$(dirname "$0")/../.." && pwd)"
|
||||
case "$(uname -m)" in
|
||||
x86_64|amd64) TARGET=x86_64-linux-gnu ;;
|
||||
aarch64|arm64) TARGET=aarch64-linux-gnu ;;
|
||||
*)
|
||||
echo "zcc: unsupported arch $(uname -m)" >&2
|
||||
exit 2
|
||||
;;
|
||||
esac
|
||||
if [ -n "${ZIG:-}" ] && [ -x "$ZIG" ]; then
|
||||
:
|
||||
elif [ -x "$ROOT/var/zig/zig" ]; then
|
||||
ZIG="$ROOT/var/zig/zig"
|
||||
elif command -v zig >/dev/null 2>&1; then
|
||||
ZIG="$(command -v zig)"
|
||||
else
|
||||
echo "zcc: zig missing; run bin/cgo/zig first" >&2
|
||||
exit 127
|
||||
fi
|
||||
exec "$ZIG" cc -target "$TARGET" "$@"
|
||||
Executable
+130
@@ -0,0 +1,130 @@
|
||||
#!/usr/bin/env bash
|
||||
# bin/cgo/zig — CGO toolchain: zig cc (not gcc) + pinned liblbug + libtokenizers.
|
||||
#
|
||||
# eval "$(bin/cgo/zig env)" # export CC/CXX/CGO_*
|
||||
# bin/cgo/zig go build ... # ensure, then exec with env
|
||||
# bin/cgo/zig ./bin/brain/search.go "query"
|
||||
#
|
||||
# Pins live in this file. Downloads land in var/ (gitignored).
|
||||
set -euo pipefail
|
||||
|
||||
ROOT="$(CDPATH= cd -- "$(dirname "$0")/../.." && pwd)"
|
||||
ZIG_VERSION=0.14.1
|
||||
LBUG_VERSION=0.19.1
|
||||
TOKENIZERS_VERSION=1.27.0
|
||||
|
||||
arch="$(uname -m)"
|
||||
case "$arch" in
|
||||
x86_64|amd64)
|
||||
ZIG_ARCH=x86_64
|
||||
LBUG_ARCH=x86_64
|
||||
TOK_ARCH=x86_64
|
||||
ZIG_SHA=24aeeec8af16c381934a6cd7d95c807a8cb2cf7df9fa40d359aa884195c4716c
|
||||
LBUG_SHA=ed263ae913f68cb0ddba0b98548b58edaac49929766d03bdaaa83be46c68847d
|
||||
TOK_SHA=72556cdca798dd4ea7cdaba308e5f0d68a8cb93b67c96edf485b7a0edd7b07f4
|
||||
;;
|
||||
aarch64|arm64)
|
||||
ZIG_ARCH=aarch64
|
||||
LBUG_ARCH=aarch64
|
||||
TOK_ARCH=aarch64
|
||||
ZIG_SHA=f7a654acc967864f7a050ddacfaa778c7504a0eca8d2b678839c21eea47c992b
|
||||
LBUG_SHA=b07df2cd533c3976a2a3025866d6420a5f35514d0a822ecc4b2902d55b4725b7
|
||||
TOK_SHA=e96545ad05930c26f51f63d932ee6d3bbd32bbed149e102c5290d587a2293067
|
||||
;;
|
||||
*)
|
||||
echo "bin/cgo/zig: unsupported arch $arch" >&2
|
||||
exit 2
|
||||
;;
|
||||
esac
|
||||
|
||||
CACHE="$ROOT/var/cache"
|
||||
LIB="$ROOT/lib-ladybug"
|
||||
ZIG_DIR="$ROOT/var/zig-dist"
|
||||
ZIG_BIN="$ROOT/var/zig/zig"
|
||||
|
||||
sha256of() {
|
||||
if command -v sha256sum >/dev/null 2>&1; then
|
||||
sha256sum "$1" | awk '{print $1}'
|
||||
else
|
||||
shasum -a 256 "$1" | awk '{print $1}'
|
||||
fi
|
||||
}
|
||||
|
||||
fetch() {
|
||||
local url="$1" dest="$2" expect="$3"
|
||||
if [ -f "$dest" ] && [ "$(sha256of "$dest")" = "$expect" ]; then
|
||||
return 0
|
||||
fi
|
||||
mkdir -p "$(dirname "$dest")"
|
||||
echo "fetch $url" >&2
|
||||
curl -fsSL "$url" -o "$dest"
|
||||
local got
|
||||
got="$(sha256of "$dest")"
|
||||
if [ "$got" != "$expect" ]; then
|
||||
echo "checksum mismatch $dest: got $got want $expect" >&2
|
||||
rm -f "$dest"
|
||||
exit 1
|
||||
fi
|
||||
}
|
||||
|
||||
ensure_zig() {
|
||||
if [ -n "${ZIG:-}" ] && [ -x "$ZIG" ]; then
|
||||
return 0
|
||||
fi
|
||||
if [ -x "$ZIG_BIN" ]; then
|
||||
export ZIG="$ZIG_BIN"
|
||||
return 0
|
||||
fi
|
||||
if command -v zig >/dev/null 2>&1; then
|
||||
export ZIG
|
||||
ZIG="$(command -v zig)"
|
||||
return 0
|
||||
fi
|
||||
local tar="$CACHE/zig-${ZIG_ARCH}-linux-${ZIG_VERSION}.tar.xz"
|
||||
fetch "https://ziglang.org/download/${ZIG_VERSION}/zig-${ZIG_ARCH}-linux-${ZIG_VERSION}.tar.xz" \
|
||||
"$tar" "$ZIG_SHA"
|
||||
mkdir -p "$CACHE"
|
||||
rm -rf "$ZIG_DIR"
|
||||
tar -xJf "$tar" -C "$CACHE"
|
||||
mv "$CACHE/zig-${ZIG_ARCH}-linux-${ZIG_VERSION}" "$ZIG_DIR"
|
||||
mkdir -p "$ROOT/var/zig"
|
||||
ln -sfn "$ZIG_DIR/zig" "$ZIG_BIN"
|
||||
export ZIG="$ZIG_BIN"
|
||||
}
|
||||
|
||||
ensure_libs() {
|
||||
mkdir -p "$LIB"
|
||||
if [ ! -f "$LIB/liblbug.so" ]; then
|
||||
local tar="$CACHE/liblbug-linux-${LBUG_ARCH}.tar.gz"
|
||||
fetch "https://github.com/LadybugDB/ladybug/releases/download/v${LBUG_VERSION}/liblbug-linux-${LBUG_ARCH}.tar.gz" \
|
||||
"$tar" "$LBUG_SHA"
|
||||
tar -xzf "$tar" -C "$LIB"
|
||||
fi
|
||||
if [ ! -f "$LIB/libtokenizers.a" ]; then
|
||||
local tar="$CACHE/libtokenizers.linux-${TOK_ARCH}.tar.gz"
|
||||
fetch "https://github.com/daulet/tokenizers/releases/download/v${TOKENIZERS_VERSION}/libtokenizers.linux-${TOK_ARCH}.tar.gz" \
|
||||
"$tar" "$TOK_SHA"
|
||||
tar -xzf "$tar" -C "$LIB"
|
||||
fi
|
||||
}
|
||||
|
||||
print_env() {
|
||||
printf 'export ZIG=%q\n' "$ZIG"
|
||||
printf 'export CC=%q\n' "$ROOT/bin/cgo/zcc"
|
||||
printf 'export CXX=%q\n' "$ROOT/bin/cgo/zc++"
|
||||
printf 'export CGO_ENABLED=1\n'
|
||||
printf 'export CGO_CFLAGS=%q\n' "-I$LIB"
|
||||
printf 'export CGO_LDFLAGS=%q\n' "-L$LIB -Wl,-rpath,${CGO_RPATH:-$LIB}"
|
||||
}
|
||||
|
||||
ensure_zig
|
||||
ensure_libs
|
||||
|
||||
cmd="${1:-env}"
|
||||
if [ "$cmd" = "env" ]; then
|
||||
print_env
|
||||
exit 0
|
||||
fi
|
||||
|
||||
eval "$(print_env)"
|
||||
exec "$@"
|
||||
+26
-15
@@ -1,13 +1,10 @@
|
||||
#!/usr/bin/env bash
|
||||
# bin/docker-entrypoint - run 2dph tools inside the container.
|
||||
#
|
||||
# brain shell (default)
|
||||
# brain search <q> bin/brain/search.go
|
||||
# brain index bin/kb/index --with-mail
|
||||
# brain watch <dir> compiled /app/bin/watch (bin/brain/watch.go)
|
||||
# brain serve compiled /app/bin/serve (bin/brain/serve.go)
|
||||
# brain extract bin/facts/extract (docker×compose pairing)
|
||||
# brain audit bin/facts/audit
|
||||
# API image (Zig CGO binaries):
|
||||
# serve | search | watch
|
||||
# Index image (Python write path, compose profile `index`):
|
||||
# index | extract | audit | search (deprecated python wrapper)
|
||||
#
|
||||
# Usage comment starts at line 2 (self-describing convention).
|
||||
set -euo pipefail
|
||||
@@ -15,13 +12,27 @@ set -euo pipefail
|
||||
CMD="${1:-shell}"
|
||||
shift || true
|
||||
|
||||
if [ -x /usr/local/bin/brain-serve ]; then
|
||||
case "$CMD" in
|
||||
shell) exec bash ;;
|
||||
serve) exec /usr/local/bin/brain-serve "$@" ;;
|
||||
search) exec /usr/local/bin/brain-search "$@" ;;
|
||||
watch) exec /usr/local/bin/brain-watch "$@" ;;
|
||||
index)
|
||||
echo "index is the Python sidecar: docker compose --profile index run --rm index" >&2
|
||||
exit 2
|
||||
;;
|
||||
*) echo "unknown command: $CMD (api: serve|search|watch)" >&2; exit 2 ;;
|
||||
esac
|
||||
fi
|
||||
|
||||
case "$CMD" in
|
||||
shell) exec bash ;;
|
||||
search) exec "$KB_PY" /app/bin/kb/search "$@" ;;
|
||||
index) exec "$KB_PY" /app/bin/kb/index --with-mail "$@" ;;
|
||||
watch) exec /app/bin/watch "$@" ;;
|
||||
serve) exec /app/bin/serve "$@" ;;
|
||||
extract) exec "$KB_PY" /app/bin/facts/extract "$@" ;;
|
||||
audit) exec "$KB_PY" /app/bin/facts/audit "$@" ;;
|
||||
*) echo "unknown command: $CMD" >&2; exit 2 ;;
|
||||
shell) exec bash ;;
|
||||
search) exec "$KB_PY" /app/bin/kb/search "$@" ;;
|
||||
index) exec "$KB_PY" /app/bin/kb/index --with-mail "$@" ;;
|
||||
watch) exec /app/bin/watch "$@" ;;
|
||||
serve) exec /app/bin/serve "$@" ;;
|
||||
extract) exec "$KB_PY" /app/bin/facts/extract "$@" ;;
|
||||
audit) exec "$KB_PY" /app/bin/facts/audit "$@" ;;
|
||||
*) echo "unknown command: $CMD" >&2; exit 2 ;;
|
||||
esac
|
||||
|
||||
+4
-6
@@ -1,10 +1,9 @@
|
||||
#!/usr/bin/env bash
|
||||
# bin/kb/search — deprecated wrapper. Use bin/brain/search.go.
|
||||
# Sets CGO for ladybug, builds a binary (embed daemon needs a real executable),
|
||||
# then execs it. Prints one deprecation line.
|
||||
# CGO via Zig (bin/cgo/zig), not gcc. Builds a binary then execs it.
|
||||
set -euo pipefail
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/../.." && pwd)"
|
||||
ROOT="$(CDPATH= cd -- "$(dirname "$0")/../.." && pwd)"
|
||||
BIN="$ROOT/var/bin/brain-search"
|
||||
SRC="$ROOT/internal/brain"
|
||||
CMD="$ROOT/bin/brain"
|
||||
@@ -24,11 +23,10 @@ else
|
||||
fi
|
||||
|
||||
if [ "$need_build" -eq 1 ]; then
|
||||
echo "Building brain/search..." >&2
|
||||
echo "Building brain/search (zig cc)..." >&2
|
||||
(
|
||||
cd "$ROOT" &&
|
||||
CGO_CFLAGS="-I$ROOT/lib-ladybug" \
|
||||
CGO_LDFLAGS="-L$ROOT/lib-ladybug -Wl,-rpath,$ROOT/lib-ladybug" \
|
||||
eval "$("$ROOT/bin/cgo/zig" env)" &&
|
||||
go build -tags system_ladybug -o "$BIN" ./bin/brain
|
||||
) || exit 1
|
||||
fi
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
"""D14 layout: bin/{subject}/{method}.go, libs in internal/, one go.mod."""
|
||||
from __future__ import annotations
|
||||
|
||||
import os
|
||||
import unittest
|
||||
from pathlib import Path
|
||||
|
||||
@@ -157,3 +158,21 @@ class BinLayoutTest(unittest.TestCase):
|
||||
for line in first.splitlines():
|
||||
if "go-git/go-git" in line:
|
||||
self.assertNotIn("indirect", line)
|
||||
|
||||
def test_cgo_uses_zig_not_gcc(self) -> None:
|
||||
for rel in ("bin/cgo/zig", "bin/cgo/zcc", "bin/cgo/zc++"):
|
||||
p = ROOT / rel
|
||||
self.assertTrue(p.is_file(), f"missing {rel}")
|
||||
self.assertTrue(
|
||||
os.access(p, os.X_OK),
|
||||
f"{rel} must be executable",
|
||||
)
|
||||
zig = (ROOT / "bin" / "cgo" / "zig").read_text()
|
||||
self.assertIn("zig cc", zig)
|
||||
self.assertIn("0.14.1", zig)
|
||||
zcc = (ROOT / "bin" / "cgo" / "zcc").read_text()
|
||||
self.assertIn('exec "$ZIG" cc', zcc)
|
||||
self.assertNotIn("command -v gcc", zcc)
|
||||
search = (ROOT / "bin" / "kb" / "search").read_text()
|
||||
self.assertIn("bin/cgo/zig", search)
|
||||
self.assertNotIn("command -v gcc", search)
|
||||
|
||||
@@ -59,6 +59,18 @@ class PublishedDocsTest(unittest.TestCase):
|
||||
self.assertNotIn("password", settings.lower())
|
||||
self.assertIn("json", settings)
|
||||
|
||||
def test_picoclaw_compose_profile_has_mcp_example(self) -> None:
|
||||
compose = (ROOT / "compose.yaml").read_text()
|
||||
self.assertIn('profiles: ["picoclaw"]', compose)
|
||||
self.assertIn("127.0.0.1:8630", compose)
|
||||
example = (ROOT / "deploy" / "picoclaw" / "mcp.json.example").read_text()
|
||||
self.assertIn("127.0.0.1:8630/mcp", example)
|
||||
self.assertNotIn("password", example.lower())
|
||||
self.assertNotIn("token", example.lower())
|
||||
docs = (ROOT / "docs" / "picoclaw.md").read_text()
|
||||
self.assertIn("search", docs)
|
||||
self.assertIn("throttled", docs)
|
||||
|
||||
def test_readme_read_path_is_go(self) -> None:
|
||||
plan = (ROOT / "PLAN.md").read_text()
|
||||
self.assertIn("get.go", plan)
|
||||
@@ -67,6 +79,30 @@ class PublishedDocsTest(unittest.TestCase):
|
||||
self.assertIn("internal/brain/rank", design)
|
||||
self.assertIn("They do not exec Python", design)
|
||||
|
||||
def test_openapi_mcp_from_same_handlers(self) -> None:
|
||||
plan = (ROOT / "PLAN.md").read_text()
|
||||
self.assertIn("D20", plan)
|
||||
self.assertIn("/openapi.json", (ROOT / "README.md").read_text())
|
||||
self.assertIn("/mcp", (ROOT / "README.md").read_text())
|
||||
skill = (ROOT / "skills" / "brain" / "SKILL.md").read_text()
|
||||
self.assertIn("/mcp", skill)
|
||||
self.assertFalse((ROOT / "skills" / "db-yaml").exists())
|
||||
self.assertTrue((ROOT / "skills" / "postgres" / "SKILL.md").is_file())
|
||||
|
||||
def test_cgo_zig_and_index_profile(self) -> None:
|
||||
plan = (ROOT / "PLAN.md").read_text()
|
||||
self.assertIn("D21", plan)
|
||||
self.assertIn("zig cc", plan)
|
||||
dockerfile = (ROOT / "Dockerfile").read_text()
|
||||
self.assertIn("bin/cgo/zcc", dockerfile)
|
||||
self.assertIn("FROM debian:bookworm-slim AS api", dockerfile)
|
||||
self.assertIn("FROM python:3.12-slim AS index", dockerfile)
|
||||
api = dockerfile[dockerfile.index("FROM debian:bookworm-slim AS api") :]
|
||||
self.assertNotIn("pip install", api)
|
||||
compose = (ROOT / "compose.yaml").read_text()
|
||||
self.assertIn('profiles: ["index"]', compose)
|
||||
self.assertIn("target: api", compose)
|
||||
|
||||
def test_readme_search_escalates_web(self) -> None:
|
||||
text = (ROOT / "README.md").read_text()
|
||||
self.assertIn("--no-web", text)
|
||||
|
||||
@@ -0,0 +1,49 @@
|
||||
"""Skills must name live commands; every bin/ path in SKILL.md must exist."""
|
||||
from __future__ import annotations
|
||||
|
||||
import re
|
||||
import unittest
|
||||
from pathlib import Path
|
||||
|
||||
ROOT = Path(__file__).resolve().parents[2]
|
||||
BIN_PATH = re.compile(r"(bin/[A-Za-z0-9_./-]+)")
|
||||
|
||||
|
||||
class SkillsTest(unittest.TestCase):
|
||||
def test_db_yaml_renamed_to_postgres(self) -> None:
|
||||
self.assertFalse(
|
||||
(ROOT / "skills" / "db-yaml").exists(),
|
||||
"skills/db-yaml must be skills/postgres",
|
||||
)
|
||||
self.assertTrue((ROOT / "skills" / "postgres" / "SKILL.md").is_file())
|
||||
text = (ROOT / "skills" / "postgres" / "SKILL.md").read_text()
|
||||
self.assertIn("bin/postgres/query.go", text)
|
||||
self.assertNotIn("search.ops.io", text)
|
||||
|
||||
def test_every_bin_path_in_skills_exists(self) -> None:
|
||||
missing: list[str] = []
|
||||
for path in (ROOT / "skills").rglob("SKILL.md"):
|
||||
text = path.read_text()
|
||||
for m in BIN_PATH.finditer(text):
|
||||
rel = m.group(1).rstrip(")`.,;")
|
||||
candidate = ROOT / rel
|
||||
if not candidate.exists():
|
||||
missing.append(f"{path.relative_to(ROOT)}: {rel}")
|
||||
self.assertEqual(missing, [], "skill bin paths must exist")
|
||||
|
||||
def test_brain_skill_lists_generated_tools(self) -> None:
|
||||
tools = (ROOT / "skills" / "brain" / "tools.md").read_text()
|
||||
skill = (ROOT / "skills" / "brain" / "SKILL.md").read_text()
|
||||
self.assertIn("tools.md", skill)
|
||||
for name in ("search", "get", "stats", "audit"):
|
||||
self.assertIn(f"`{name}`", tools)
|
||||
|
||||
def test_picoclaw_lists_tool_order(self) -> None:
|
||||
skill = (ROOT / "skills" / "picoclaw" / "SKILL.md").read_text()
|
||||
agents = (ROOT / "AGENTS.md").read_text()
|
||||
self.assertIn("**`search`**", skill)
|
||||
self.assertIn("**`get`**", skill)
|
||||
self.assertIn("**`audit`**", skill)
|
||||
self.assertIn("throttled", skill.lower())
|
||||
self.assertIn("not a negative finding", agents)
|
||||
self.assertIn("Fact-check every", agents)
|
||||
+55
-17
@@ -1,66 +1,86 @@
|
||||
# 2dph — docker composition
|
||||
#
|
||||
# docker compose run --rm brain index # rebuild graph
|
||||
# docker compose run --rm brain search "Matrix fed" # one-shot query
|
||||
# docker compose run --rm brain serve # async Go server
|
||||
# docker compose up brain-watch # auto re-index
|
||||
# docker compose up -d brain # API (Zig CGO serve)
|
||||
# docker compose --profile index run --rm index # Python rebuild
|
||||
# docker compose --profile picoclaw up brain-mcp
|
||||
# docker compose --profile searxng up -d
|
||||
#
|
||||
# Caching: the 128M model (HF_HOME) and kb.lbug (VAR_DIR) live in named
|
||||
# volumes, so rebuilds never redownload the model or re-derive the graph.
|
||||
# Secrets are never baked into the image: search.env + db-profiles.yml mount
|
||||
# read-only from ~/.config/brain.
|
||||
# Secrets never baked in: search.env + db-profiles.yml from ~/.config/brain.
|
||||
|
||||
name: 2dph
|
||||
|
||||
services:
|
||||
brain:
|
||||
image: ghcr.io/eslider/2dph:latest
|
||||
image: ghcr.io/eslider/2dph:api
|
||||
build:
|
||||
context: .
|
||||
dockerfile: Dockerfile
|
||||
target: api
|
||||
cache_from:
|
||||
- ghcr.io/eslider/2dph:cache
|
||||
command: ["brain", "search", "help"]
|
||||
command: ["serve"]
|
||||
environment: &env
|
||||
HF_HOME: /data/hf
|
||||
BRAIN_SEARCH_CACHE: /data/cache/web-search.sqlite
|
||||
BRAIN_DB_PROFILES: /secret/db-profiles.yml
|
||||
BRAIN_SEARCH_ENV: /secret/search.env
|
||||
KB_SEARCH_CMD: /app/bin/kb/search
|
||||
KB_ROOT: /data
|
||||
KB_WORKERS: "4"
|
||||
KB_PORT: "8630"
|
||||
volumes:
|
||||
- kb-model:/data/hf
|
||||
- kb-var:/data
|
||||
# corpus is read-only on the host, never written from the container
|
||||
- ..:/corpus:ro
|
||||
- ~/.config/brain:/secret:ro
|
||||
ports:
|
||||
- "127.0.0.1:8630:8630"
|
||||
read_only: true
|
||||
tmpfs:
|
||||
- /tmp
|
||||
healthcheck:
|
||||
test: ["CMD", "python3", "-c", "import ladybug, model2vec, mistune; print('ok')"]
|
||||
test: ["CMD", "wget", "-qO-", "http://127.0.0.1:8630/health"]
|
||||
interval: 30s
|
||||
timeout: 5s
|
||||
retries: 3
|
||||
restart: unless-stopped
|
||||
stop_grace_period: 20s
|
||||
|
||||
# watcher: re-index on corpus file change (watchdog script)
|
||||
brain-watch:
|
||||
image: ghcr.io/eslider/2dph:latest
|
||||
image: ghcr.io/eslider/2dph:api
|
||||
environment: *env
|
||||
volumes:
|
||||
- kb-model:/data/hf
|
||||
- kb-var:/data
|
||||
- ..:/corpus:ro
|
||||
- ~/.config/brain:/secret:ro
|
||||
command: ["brain", "watch", "/corpus"]
|
||||
command: ["watch", "/corpus"]
|
||||
read_only: true
|
||||
tmpfs:
|
||||
- /tmp
|
||||
restart: unless-stopped
|
||||
stop_grace_period: 20s
|
||||
|
||||
# Python write path (Ladybug rebuild). Not in the API image.
|
||||
# docker compose --profile index run --rm index
|
||||
index:
|
||||
profiles: ["index"]
|
||||
image: ghcr.io/eslider/2dph:index
|
||||
build:
|
||||
context: .
|
||||
dockerfile: Dockerfile
|
||||
target: index
|
||||
environment:
|
||||
HF_HOME: /data/hf
|
||||
KB_PY: python3
|
||||
volumes:
|
||||
- kb-model:/data/hf
|
||||
- kb-var:/app/var
|
||||
- ..:/corpus:ro
|
||||
- ~/.config/brain:/secret:ro
|
||||
command: ["index"]
|
||||
read_only: true
|
||||
tmpfs:
|
||||
- /tmp
|
||||
|
||||
# Optional local SearXNG (D3). Skip if BRAIN_SEARCH_URL already points at a
|
||||
# live instance — do not run a second copy on that host.
|
||||
# SEARXNG_SECRET=$(openssl rand -hex 32) docker compose --profile searxng up -d
|
||||
@@ -76,6 +96,24 @@ services:
|
||||
- ./deploy/searxng/limiter.toml:/etc/searxng/limiter.toml:ro
|
||||
restart: unless-stopped
|
||||
|
||||
# MCP endpoint for an external agent (PicoClaw is not shipped here).
|
||||
# docker compose --profile picoclaw up brain-mcp
|
||||
brain-mcp:
|
||||
profiles: ["picoclaw"]
|
||||
image: ghcr.io/eslider/2dph:api
|
||||
environment: *env
|
||||
volumes:
|
||||
- kb-model:/data/hf
|
||||
- kb-var:/data
|
||||
- ~/.config/brain:/secret:ro
|
||||
command: ["serve"]
|
||||
ports:
|
||||
- "127.0.0.1:8630:8630"
|
||||
read_only: true
|
||||
tmpfs:
|
||||
- /tmp
|
||||
restart: unless-stopped
|
||||
|
||||
volumes:
|
||||
kb-model:
|
||||
kb-var:
|
||||
@@ -0,0 +1,8 @@
|
||||
{
|
||||
"mcpServers": {
|
||||
"2dph": {
|
||||
"url": "http://127.0.0.1:8630/mcp",
|
||||
"description": "2dph fact gate. Tool order: search → get → audit. throttled is not absence."
|
||||
}
|
||||
}
|
||||
}
|
||||
+12
-3
@@ -66,7 +66,16 @@ Conflicting pairings (≥2 yes vs ≥2 no) = hypothesis (OQ1 → v2 resolution).
|
||||
## Read path
|
||||
|
||||
`bin/brain/get.go`, `stats.go`, and `eval.go` call `internal/brain` with cgo
|
||||
(`system_ladybug`). They do not exec Python. Control questions for recall@5
|
||||
live in `internal/brain/rank` so CI can test the table without libladybug.
|
||||
(`system_ladybug`), compiled by **Zig** (`bin/cgo/zcc`, D21), not gcc.
|
||||
They do not exec Python. Control questions for recall@5 live in
|
||||
`internal/brain/rank` so CI can test the table without libladybug.
|
||||
Python `bin/kb/{get,stats,eval}` remain for GitHub Actions until the runner
|
||||
has ladybug cgo. Index/write is still `bin/kb/index`.
|
||||
fetches Zig + libs (`bin/cgo/zig`). Index/write is still `bin/kb/index`
|
||||
(`docker compose --profile index`).
|
||||
|
||||
## Agent API (D20)
|
||||
|
||||
`bin/brain/serve.go` exposes the same `internal/httpapi.Ops` table as OpenAPI
|
||||
(`GET /openapi.json`) and MCP (`POST /mcp` JSON-RPC `tools/list` +
|
||||
`tools/call`). Tool names match paths: `search`, `get`, `stats`, `audit`.
|
||||
Agents should use these endpoints instead of shebang CLIs.
|
||||
@@ -0,0 +1,18 @@
|
||||
# PicoClaw profile (reference agent)
|
||||
|
||||
2dph is the memory/fact gate. PicoClaw (or any MCP client) is the agent loop
|
||||
and is **not** shipped in this repo.
|
||||
|
||||
```bash
|
||||
docker compose --profile picoclaw up brain-mcp
|
||||
```
|
||||
|
||||
The API listens on `127.0.0.1:8630`. Point the agent at
|
||||
`http://127.0.0.1:8630/mcp` using [deploy/picoclaw/mcp.json.example](../deploy/picoclaw/mcp.json.example).
|
||||
|
||||
OpenAPI: `GET http://127.0.0.1:8630/openapi.json`.
|
||||
|
||||
Before a factual reply: `search` → `get` → `audit`. `throttled` is not a
|
||||
negative finding. See `skills/picoclaw/SKILL.md`.
|
||||
|
||||
No Cursor required. A live PicoClaw binary/image is an operator choice.
|
||||
@@ -0,0 +1,185 @@
|
||||
package httpapi
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"io"
|
||||
"net/http"
|
||||
"strconv"
|
||||
"strings"
|
||||
)
|
||||
|
||||
type rpcReq struct {
|
||||
JSONRPC string `json:"jsonrpc"`
|
||||
ID json.RawMessage `json:"id"`
|
||||
Method string `json:"method"`
|
||||
Params json.RawMessage `json:"params"`
|
||||
}
|
||||
|
||||
type rpcErr struct {
|
||||
Code int `json:"code"`
|
||||
Message string `json:"message"`
|
||||
}
|
||||
|
||||
func (s *Server) handleOpenAPI(w http.ResponseWriter, _ *http.Request) {
|
||||
writeJSON(w, http.StatusOK, OpenAPI())
|
||||
}
|
||||
|
||||
func (s *Server) handleMCP(w http.ResponseWriter, r *http.Request) {
|
||||
if r.Method != http.MethodPost {
|
||||
writeJSON(w, http.StatusMethodNotAllowed, map[string]any{"error": "POST JSON-RPC"})
|
||||
return
|
||||
}
|
||||
raw, err := io.ReadAll(io.LimitReader(r.Body, 1<<20))
|
||||
if err != nil {
|
||||
writeJSON(w, http.StatusBadRequest, map[string]any{"error": "read body"})
|
||||
return
|
||||
}
|
||||
var req rpcReq
|
||||
if err := json.Unmarshal(raw, &req); err != nil {
|
||||
writeJSON(w, http.StatusOK, rpcResult(nil, nil, &rpcErr{-32700, "parse error"}))
|
||||
return
|
||||
}
|
||||
result, rpcErrv, callErr := s.mcpDispatch(r, req)
|
||||
if callErr != nil {
|
||||
writeJSON(w, http.StatusOK, rpcResult(req.ID, nil, &rpcErr{-32603, callErr.Error()}))
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusOK, rpcResult(req.ID, result, rpcErrv))
|
||||
}
|
||||
|
||||
func (s *Server) mcpDispatch(r *http.Request, req rpcReq) (any, *rpcErr, error) {
|
||||
switch req.Method {
|
||||
case "initialize":
|
||||
return map[string]any{
|
||||
"protocolVersion": "2024-11-05",
|
||||
"capabilities": map[string]any{"tools": map[string]any{}},
|
||||
"serverInfo": map[string]any{"name": "2dph", "version": "1"},
|
||||
}, nil, nil
|
||||
case "notifications/initialized", "notifications/cancelled":
|
||||
return map[string]any{}, nil, nil
|
||||
case "tools/list":
|
||||
return map[string]any{"tools": MCPTools()}, nil, nil
|
||||
case "tools/call":
|
||||
out, err := s.mcpCall(r, req.Params)
|
||||
return out, nil, err
|
||||
case "ping":
|
||||
return map[string]any{}, nil, nil
|
||||
default:
|
||||
return nil, &rpcErr{-32601, "method not found"}, nil
|
||||
}
|
||||
}
|
||||
|
||||
func (s *Server) mcpCall(r *http.Request, params json.RawMessage) (any, error) {
|
||||
var p struct {
|
||||
Name string `json:"name"`
|
||||
Arguments map[string]any `json:"arguments"`
|
||||
}
|
||||
if err := json.Unmarshal(params, &p); err != nil {
|
||||
return nil, fmt.Errorf("params")
|
||||
}
|
||||
if p.Arguments == nil {
|
||||
p.Arguments = map[string]any{}
|
||||
}
|
||||
var (
|
||||
body []byte
|
||||
err error
|
||||
)
|
||||
switch p.Name {
|
||||
case "search":
|
||||
q := strings.TrimSpace(fmt.Sprint(p.Arguments["q"]))
|
||||
if q == "" || q == "<nil>" {
|
||||
return mcpText(`{"error":"q required"}`, true), nil
|
||||
}
|
||||
limit := 10
|
||||
if raw, ok := p.Arguments["n"]; ok {
|
||||
switch n := raw.(type) {
|
||||
case float64:
|
||||
limit = int(n)
|
||||
case string:
|
||||
if v, e := strconv.Atoi(n); e == nil {
|
||||
limit = v
|
||||
}
|
||||
}
|
||||
}
|
||||
if limit < 1 || limit > 100 {
|
||||
return mcpText(`{"error":"n must be int 1..100"}`, true), nil
|
||||
}
|
||||
if !s.tryAcquire(r) {
|
||||
return nil, fmt.Errorf("cancelled")
|
||||
}
|
||||
defer s.release()
|
||||
body, err = s.api.Search(r.Context(), q, limit)
|
||||
case "get":
|
||||
id := strings.TrimSpace(fmt.Sprint(p.Arguments["id"]))
|
||||
if id == "" || id == "<nil>" {
|
||||
return mcpText(`{"error":"id required"}`, true), nil
|
||||
}
|
||||
full := false
|
||||
switch v := p.Arguments["body"].(type) {
|
||||
case bool:
|
||||
full = v
|
||||
case string:
|
||||
full = v == "1" || v == "true"
|
||||
}
|
||||
if !s.tryAcquire(r) {
|
||||
return nil, fmt.Errorf("cancelled")
|
||||
}
|
||||
defer s.release()
|
||||
body, err = s.api.Get(r.Context(), id, full)
|
||||
case "stats":
|
||||
if !s.tryAcquire(r) {
|
||||
return nil, fmt.Errorf("cancelled")
|
||||
}
|
||||
defer s.release()
|
||||
body, err = s.api.Stats(r.Context())
|
||||
case "audit":
|
||||
if !s.tryAcquire(r) {
|
||||
return nil, fmt.Errorf("cancelled")
|
||||
}
|
||||
defer s.release()
|
||||
body, err = s.api.Audit(r.Context())
|
||||
case "ingest":
|
||||
if !s.tryAcquire(r) {
|
||||
return nil, fmt.Errorf("cancelled")
|
||||
}
|
||||
defer s.release()
|
||||
body, err = s.api.Ingest(r.Context())
|
||||
default:
|
||||
return nil, fmt.Errorf("unknown tool %s", p.Name)
|
||||
}
|
||||
if err != nil {
|
||||
return mcpText(err.Error(), true), nil
|
||||
}
|
||||
return mcpText(string(body), false), nil
|
||||
}
|
||||
|
||||
func mcpText(text string, isError bool) map[string]any {
|
||||
return map[string]any{
|
||||
"content": []any{map[string]any{"type": "text", "text": text}},
|
||||
"isError": isError,
|
||||
}
|
||||
}
|
||||
|
||||
type rpcResp struct {
|
||||
JSONRPC string `json:"jsonrpc"`
|
||||
ID json.RawMessage `json:"id"`
|
||||
Result any `json:"result,omitempty"`
|
||||
Error *rpcErr `json:"error,omitempty"`
|
||||
}
|
||||
|
||||
func rpcResult(id json.RawMessage, result any, err *rpcErr) rpcResp {
|
||||
out := rpcResp{JSONRPC: "2.0", ID: id}
|
||||
if len(id) == 0 {
|
||||
out.ID = []byte("null")
|
||||
}
|
||||
if err != nil {
|
||||
out.Error = err
|
||||
return out
|
||||
}
|
||||
if result == nil {
|
||||
result = map[string]any{}
|
||||
}
|
||||
out.Result = result
|
||||
return out
|
||||
}
|
||||
@@ -48,18 +48,22 @@ func NewServer(api API, workers int) http.Handler {
|
||||
|
||||
func (s *Server) ServeHTTP(w http.ResponseWriter, r *http.Request) {
|
||||
switch r.URL.Path {
|
||||
case "/health":
|
||||
case PathHealth:
|
||||
writeJSON(w, http.StatusOK, map[string]any{"status": "ok"})
|
||||
case "/search":
|
||||
case PathSearch:
|
||||
s.handleSearch(w, r)
|
||||
case "/get":
|
||||
case PathGet:
|
||||
s.handleGet(w, r)
|
||||
case "/stats":
|
||||
case PathStats:
|
||||
s.handleJSON(w, r, s.api.Stats)
|
||||
case "/audit":
|
||||
case PathAudit:
|
||||
s.handleJSON(w, r, s.api.Audit)
|
||||
case "/ingest":
|
||||
case PathIngest:
|
||||
s.handleJSON(w, r, s.api.Ingest)
|
||||
case PathOpenAPI:
|
||||
s.handleOpenAPI(w, r)
|
||||
case PathMCP:
|
||||
s.handleMCP(w, r)
|
||||
default:
|
||||
writeJSON(w, http.StatusNotFound, map[string]any{"error": "not found"})
|
||||
}
|
||||
@@ -112,6 +116,16 @@ func (s *Server) handleJSON(w http.ResponseWriter, r *http.Request, fn func(cont
|
||||
writeAPI(w, body, err)
|
||||
}
|
||||
|
||||
func (s *Server) tryAcquire(r *http.Request) bool {
|
||||
return s.acquire(nopWriter{}, r)
|
||||
}
|
||||
|
||||
type nopWriter struct{}
|
||||
|
||||
func (nopWriter) Header() http.Header { return http.Header{} }
|
||||
func (nopWriter) Write([]byte) (int, error) { return 0, nil }
|
||||
func (nopWriter) WriteHeader(int) {}
|
||||
|
||||
func (s *Server) acquire(w http.ResponseWriter, r *http.Request) bool {
|
||||
select {
|
||||
case s.semaphore <- struct{}{}:
|
||||
|
||||
@@ -0,0 +1,144 @@
|
||||
package httpapi
|
||||
|
||||
import "strings"
|
||||
|
||||
// Shared HTTP surface: OpenAPI paths and MCP tools are generated from Ops.
|
||||
// ServeHTTP must keep the same path strings.
|
||||
|
||||
type Param struct {
|
||||
Name, In, Type, Description string
|
||||
Required bool
|
||||
}
|
||||
|
||||
type Op struct {
|
||||
Path, Method, ID, Summary string
|
||||
Params []Param
|
||||
MCP bool
|
||||
}
|
||||
|
||||
const (
|
||||
PathHealth = "/health"
|
||||
PathSearch = "/search"
|
||||
PathGet = "/get"
|
||||
PathStats = "/stats"
|
||||
PathAudit = "/audit"
|
||||
PathIngest = "/ingest"
|
||||
PathOpenAPI = "/openapi.json"
|
||||
PathMCP = "/mcp"
|
||||
)
|
||||
|
||||
var Ops = []Op{
|
||||
{Path: PathHealth, Method: "get", ID: "health", Summary: "liveness"},
|
||||
{
|
||||
Path: PathSearch, Method: "get", ID: "search", Summary: "deduction search (facts → info → web)",
|
||||
MCP: true,
|
||||
Params: []Param{
|
||||
{Name: "q", In: "query", Type: "string", Description: "search query", Required: true},
|
||||
{Name: "n", In: "query", Type: "integer", Description: "hit limit 1..100 (default 10)"},
|
||||
},
|
||||
},
|
||||
{
|
||||
Path: PathGet, Method: "get", ID: "get", Summary: "read one leaf by id",
|
||||
MCP: true,
|
||||
Params: []Param{
|
||||
{Name: "id", In: "query", Type: "string", Description: "leaf id", Required: true},
|
||||
{Name: "body", In: "query", Type: "boolean", Description: "include full text"},
|
||||
},
|
||||
},
|
||||
{Path: PathStats, Method: "get", ID: "stats", Summary: "index health", MCP: true},
|
||||
{Path: PathAudit, Method: "get", ID: "audit", Summary: "facts confidence histogram", MCP: true},
|
||||
{Path: PathIngest, Method: "get", ID: "ingest", Summary: "rebuild hint (write is v2)", MCP: true},
|
||||
{Path: PathOpenAPI, Method: "get", ID: "openapi", Summary: "OpenAPI 3 document for this server"},
|
||||
}
|
||||
|
||||
func OpenAPI() map[string]any {
|
||||
paths := map[string]any{}
|
||||
for _, op := range Ops {
|
||||
params := make([]any, 0, len(op.Params))
|
||||
for _, p := range op.Params {
|
||||
params = append(params, map[string]any{
|
||||
"name": p.Name,
|
||||
"in": p.In,
|
||||
"required": p.Required,
|
||||
"description": p.Description,
|
||||
"schema": map[string]any{"type": p.Type},
|
||||
})
|
||||
}
|
||||
item := map[string]any{
|
||||
"operationId": op.ID,
|
||||
"summary": op.Summary,
|
||||
"responses": map[string]any{
|
||||
"200": map[string]any{
|
||||
"description": "JSON",
|
||||
"content": map[string]any{
|
||||
"application/json": map[string]any{
|
||||
"schema": map[string]any{"type": "object"},
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
}
|
||||
if len(params) > 0 {
|
||||
item["parameters"] = params
|
||||
}
|
||||
paths[op.Path] = map[string]any{op.Method: item}
|
||||
}
|
||||
return map[string]any{
|
||||
"openapi": "3.0.3",
|
||||
"info": map[string]any{
|
||||
"title": "2dph brain",
|
||||
"version": "1",
|
||||
"description": "Same handlers as bin/brain/serve.go. MCP tools at POST /mcp match these paths.",
|
||||
},
|
||||
"paths": paths,
|
||||
}
|
||||
}
|
||||
|
||||
type MCPTool struct {
|
||||
Name string `json:"name"`
|
||||
Description string `json:"description"`
|
||||
InputSchema map[string]any `json:"inputSchema"`
|
||||
}
|
||||
|
||||
func MCPTools() []MCPTool {
|
||||
out := make([]MCPTool, 0, len(Ops))
|
||||
for _, op := range Ops {
|
||||
if !op.MCP {
|
||||
continue
|
||||
}
|
||||
props := map[string]any{}
|
||||
var required []string
|
||||
for _, p := range op.Params {
|
||||
props[p.Name] = map[string]any{"type": p.Type, "description": p.Description}
|
||||
if p.Required {
|
||||
required = append(required, p.Name)
|
||||
}
|
||||
}
|
||||
schema := map[string]any{"type": "object", "properties": props}
|
||||
if len(required) > 0 {
|
||||
schema["required"] = required
|
||||
}
|
||||
out = append(out, MCPTool{
|
||||
Name: op.ID,
|
||||
Description: op.Summary,
|
||||
InputSchema: schema,
|
||||
})
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
// SkillMarkdown is the Cursor skill fragment generated from Ops/MCPTools.
|
||||
func SkillMarkdown() string {
|
||||
var b strings.Builder
|
||||
b.WriteString("# brain HTTP / MCP tools\n\n")
|
||||
b.WriteString("Generated from `internal/httpapi.Ops`. Do not edit by hand.\n\n")
|
||||
b.WriteString("Serve: `bin/brain/serve.go` (`GET /openapi.json`, `POST /mcp`).\n\n")
|
||||
for _, t := range MCPTools() {
|
||||
b.WriteString("- `")
|
||||
b.WriteString(t.Name)
|
||||
b.WriteString("` — ")
|
||||
b.WriteString(t.Description)
|
||||
b.WriteString("\n")
|
||||
}
|
||||
return b.String()
|
||||
}
|
||||
@@ -0,0 +1,99 @@
|
||||
package httpapi
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestOpenAPIIncludesCorePaths(t *testing.T) {
|
||||
doc := OpenAPI()
|
||||
raw, err := json.Marshal(doc)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
paths, _ := doc["paths"].(map[string]any)
|
||||
for _, p := range []string{"/search", "/get", "/stats", "/audit"} {
|
||||
if _, ok := paths[p]; !ok {
|
||||
t.Fatalf("openapi missing path %s (%s)", p, raw)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestMCPToolsMatchOpenAPIPaths(t *testing.T) {
|
||||
paths, _ := OpenAPI()["paths"].(map[string]any)
|
||||
tools := MCPTools()
|
||||
if len(tools) == 0 {
|
||||
t.Fatal("no MCP tools")
|
||||
}
|
||||
names := map[string]bool{}
|
||||
for _, tool := range tools {
|
||||
names[tool.Name] = true
|
||||
path := "/" + tool.Name
|
||||
if _, ok := paths[path]; !ok {
|
||||
t.Fatalf("MCP tool %s has no OpenAPI path %s", tool.Name, path)
|
||||
}
|
||||
}
|
||||
for _, need := range []string{"search", "get", "stats", "audit"} {
|
||||
if !names[need] {
|
||||
t.Fatalf("MCP tools missing %s: %v", need, names)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestOpenAPIHTTP(t *testing.T) {
|
||||
h := NewServer(&fakeSearcher{}, 1)
|
||||
code, body := get(t, h, "/openapi.json")
|
||||
if code != http.StatusOK {
|
||||
t.Fatalf("code = %d body=%s", code, body)
|
||||
}
|
||||
var doc map[string]any
|
||||
if err := json.Unmarshal(body, &doc); err != nil {
|
||||
t.Fatalf("not json: %v", err)
|
||||
}
|
||||
if doc["openapi"] == nil {
|
||||
t.Fatalf("missing openapi version: %s", body)
|
||||
}
|
||||
}
|
||||
|
||||
func TestMCPToolsListAndCall(t *testing.T) {
|
||||
h := NewServer(&fakeSearcher{}, 1)
|
||||
code, body := postJSON(t, h, "/mcp", `{"jsonrpc":"2.0","id":1,"method":"tools/list"}`)
|
||||
if code != http.StatusOK {
|
||||
t.Fatalf("list code = %d body=%s", code, body)
|
||||
}
|
||||
if !strings.Contains(string(body), `"search"`) {
|
||||
t.Fatalf("tools/list missing search: %s", body)
|
||||
}
|
||||
code, body = postJSON(t, h, "/mcp", `{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"search","arguments":{"q":"matrix","n":3}}}`)
|
||||
if code != http.StatusOK {
|
||||
t.Fatalf("call code = %d body=%s", code, body)
|
||||
}
|
||||
if !strings.Contains(string(body), "matrix") {
|
||||
t.Fatalf("search call body %s", body)
|
||||
}
|
||||
}
|
||||
|
||||
func TestSkillMarkdownMatchesCommittedFile(t *testing.T) {
|
||||
want, err := os.ReadFile(filepath.Join("..", "..", "skills", "brain", "tools.md"))
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
got := SkillMarkdown()
|
||||
if got != string(want) {
|
||||
t.Fatalf("skills/brain/tools.md stale; regenerate from SkillMarkdown()\n--- got ---\n%s\n--- want ---\n%s", got, want)
|
||||
}
|
||||
}
|
||||
|
||||
func postJSON(t *testing.T, h http.Handler, path, raw string) (int, []byte) {
|
||||
t.Helper()
|
||||
req := httptest.NewRequest(http.MethodPost, path, strings.NewReader(raw))
|
||||
req.Header.Set("Content-Type", "application/json")
|
||||
rec := httptest.NewRecorder()
|
||||
h.ServeHTTP(rec, req)
|
||||
return rec.Code, rec.Body.Bytes()
|
||||
}
|
||||
@@ -44,4 +44,7 @@ are not wired yet); do not treat it as a graph walk.
|
||||
are not evidence of absence. `--root facts|info` and `--no-web` skip the web.
|
||||
- If recall looks wrong, run `bin/brain/eval.go`; it gates control questions and
|
||||
should stay at or above 95% recall@5.
|
||||
- Agents: `GET /openapi.json` and `POST /mcp` on `bin/brain/serve.go` (same
|
||||
handlers; tool names match paths `search`/`get`/`stats`/`audit`). Generated
|
||||
list: [tools.md](tools.md).
|
||||
- Never report an unconfirmed single-source local answer as fact.
|
||||
@@ -0,0 +1,11 @@
|
||||
# brain HTTP / MCP tools
|
||||
|
||||
Generated from `internal/httpapi.Ops`. Do not edit by hand.
|
||||
|
||||
Serve: `bin/brain/serve.go` (`GET /openapi.json`, `POST /mcp`).
|
||||
|
||||
- `search` — deduction search (facts → info → web)
|
||||
- `get` — read one leaf by id
|
||||
- `stats` — index health
|
||||
- `audit` — facts confidence histogram
|
||||
- `ingest` — rebuild hint (write is v2)
|
||||
@@ -1,39 +0,0 @@
|
||||
---
|
||||
name: db-yaml
|
||||
description: >-
|
||||
Read any Postgres as compact YAML through db/psql-yq, with a read-only guard and
|
||||
named profiles. Use when a task needs table contents, column types or a SELECT
|
||||
against cs_brain or another project database.
|
||||
---
|
||||
|
||||
# db-yaml
|
||||
|
||||
`bin/db/psql-yq` (vendored in this repo) talks to Postgres and returns YAML,
|
||||
which is far cheaper than a psql ASCII table and easy to slice with `yq`.
|
||||
|
||||
```bash
|
||||
bin/db/psql-yq --profile onlyoffice -s document_asset # column list
|
||||
bin/db/psql-yq --profile onlyoffice -t task_result -l 20 # sample rows as YAML
|
||||
bin/db/psql-yq --profile onlyoffice -c 'SELECT ...' # query -> YAML
|
||||
```
|
||||
|
||||
Ad-hoc targets without a profile:
|
||||
|
||||
```bash
|
||||
bin/db/psql-yq --container my-pg --db app -c 'SELECT 1'
|
||||
bin/db/psql-yq --dsn 'postgres://user@host:5432/db' -c 'SELECT 1'
|
||||
```
|
||||
|
||||
## Profiles
|
||||
|
||||
Connection details live in `~/.config/brain/db-profiles.yml` (mode 600), never in a
|
||||
project repo. A profile names either a `container` or a `host`; passwords are read
|
||||
from a separate `password_env_file` and never appear in argv.
|
||||
|
||||
## Rules
|
||||
|
||||
- **Read-only.** Any `insert|update|delete|drop|truncate|alter|create|grant|
|
||||
revoke|vacuum|copy` is rejected with exit 3. Do not work around it.
|
||||
- **PII.** `cs_brain` holds client data. Aggregate and count freely; never copy
|
||||
names or addresses into chat, issues or docs.
|
||||
- Use `-l` to keep samples small. Twenty rows answer most questions.
|
||||
@@ -0,0 +1,26 @@
|
||||
---
|
||||
name: picoclaw
|
||||
description: >-
|
||||
2dph is the memory/fact gate, not the agent loop. Use when wiring PicoClaw
|
||||
or any MCP client: call brain search/get/audit before a factual reply.
|
||||
throttled is not a negative finding.
|
||||
---
|
||||
|
||||
# PicoClaw — fact-check before assert
|
||||
|
||||
PicoClaw (or any agent) speaks MCP at `POST /mcp` on `bin/brain/serve.go`.
|
||||
2dph does not run the agent loop. Compose: `docker compose --profile picoclaw up brain-mcp`
|
||||
(see [docs/picoclaw.md](../../docs/picoclaw.md)).
|
||||
|
||||
## Tool order (before a factual reply)
|
||||
|
||||
1. **`search`** — facts root first, then info. The `web` block is a second
|
||||
source when there is no facts hit. Status `throttled` / `skipped` /
|
||||
`refused` is **not** evidence of absence.
|
||||
2. **`get`** — full leaf body only when a hit `id` is needed.
|
||||
3. **`audit`** — if recall or confidence looks wrong.
|
||||
|
||||
Then answer. Confirmed only from facts (≥2 independent sources). Anything
|
||||
else is `(not confirmed)`. Missing graph ≠ “does not exist”.
|
||||
|
||||
Generated tool list: [../brain/tools.md](../brain/tools.md).
|
||||
@@ -0,0 +1,39 @@
|
||||
---
|
||||
name: postgres
|
||||
description: >-
|
||||
Read Postgres as compact YAML through bin/postgres/query.go (read-only
|
||||
guard, named profiles). Use when a task needs table contents, column types,
|
||||
or a SELECT against an ops database.
|
||||
---
|
||||
|
||||
# postgres
|
||||
|
||||
`bin/postgres/query.go` wraps vendored `bin/db/psql-yq`. Output is YAML
|
||||
(cheaper than psql ASCII, easy to slice with `yq`).
|
||||
|
||||
```bash
|
||||
bin/postgres/query.go --profile onlyoffice -s document_asset # column list
|
||||
bin/postgres/query.go --profile onlyoffice -t task_result -l 20 # sample rows
|
||||
bin/postgres/query.go --profile onlyoffice -c 'SELECT ...' # query → YAML
|
||||
```
|
||||
|
||||
Ad-hoc targets without a profile:
|
||||
|
||||
```bash
|
||||
bin/postgres/query.go --container my-pg --db app -c 'SELECT 1'
|
||||
bin/postgres/query.go --dsn 'postgres://user@host:5432/db' -c 'SELECT 1'
|
||||
```
|
||||
|
||||
## Profiles
|
||||
|
||||
Connection details live in `$HOME/.config/brain/db-profiles.yml` (mode 600),
|
||||
never in a project repo. A profile names either a `container` or a `host`;
|
||||
passwords are read from a separate `password_env_file` and never appear in argv.
|
||||
|
||||
## Rules
|
||||
|
||||
- **Read-only.** Any `insert|update|delete|drop|truncate|alter|create|grant|
|
||||
revoke|vacuum|copy` is rejected with exit 3. Do not work around it.
|
||||
- **PII.** Client CRM databases: aggregate and count freely; never copy names
|
||||
or addresses into chat, issues or docs.
|
||||
- Use `-l` to keep samples small. Twenty rows answer most questions.
|
||||
Reference in New Issue
Block a user