Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
91 changes: 91 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,10 @@ experience may change before `1.0.0`.

## [Unreleased]

_Nothing yet._

## [0.5.0] - 2026-09-21

### Added

- An acceptance-test tier modelled on the Terraform provider's `make testacc`:
Expand Down Expand Up @@ -57,6 +61,60 @@ experience may change before `1.0.0`.
messages past 300 ms ("last load: X s" from per-machine cold/warm records —
never a percentage bar), and a web encoder-warm status chip fed by
`GET /api/retrieval/health`.
- **Study Plans reach the surfaces you decide on.** One `PlanApplication`
seam (`studyloop.planning.application`) now carries every plan use case —
browse, inspect, prepare planning, active guidance, apply a change, assess —
and the CLI, the Web UI and the MCP server all go through it. Two bugs that
seam exists because of are closed: activation readiness is judged once on
the resulting document for every entry path (create-with-status and
whole-document replacement included), and a checkpoint whose database write
failed is reported as partial instead of as a clean record.
- **`studyloop now` is plan-aware.** An active plan biases the recommendation
— matching due work and a synthesised next milestone carry explicit plan and
milestone references, urgent reviews and fresh struggles can still outrank
new milestone work, several active plans are considered deterministically,
and a milestone beyond today's energy is deferred with a reason rather than
dropped. CLI `now`, Web Today, the recap and MCP `get_next_action` consume
one additive result; with no active plan the JSON is byte-identical to the
pinned golden. `get_next_action` gains `interleave` parity with the CLI.
- **Repair carries an energy demand of its own, and a body-doubling floor.**
A live struggle (`struggling`, seen within 14 days) asks for 6/10, an older
struggle or a weak teach-back for 4/10, a concept still `learning` for none;
below the day's capability a repair is deferred like new work into
`energy_deferred_repairs` — never ranked — while due recall and teach-back
reviews are never deferred. The due-review reader emits every `struggling`
row as a hands-on "guided repair" as well, so that copy carries the same
demand and defers with the repair, named once — without it the repair the
learner had just been spared came back as the primary. When nothing
plan-related fits the day and an active, ready plan exists, one low-scoring
proposal is synthesised: sit with the plan in a body-double session
(`studyloop study "<plan>" --mode co-study`), leading with the progress the
plan records and naming what is deferred. Every offered command quotes
learner-authored text as one shell word.
- **The low-energy teach-back is the one-sentence kind, with a way out.** A
concept still `learning` is offered as a *micro* teach-back
(`studyloop teachback … --type micro`) and its reason reads as the gentle
review it is, not "repair now"; the teach-back protocol gains a low-energy
fallback — when the sentence will not come, the mentor gives a short guided
explanation and asks for one phrase back, instead of walking the four-round
stuck ladder, and the blank is not scored.
- **Plan with the architect from the Web UI.** *Plans → Plan with architect*
launches the Study Plan Architect through the ordinary session machinery
(one-session authority, reconnect, the same console) with a `planning`
purpose; starting a conversation creates no draft. The manual form remains.
`studyloop plan repair <id>` opens the architect on an active plan the
readiness gate refuses to write, and `studyloop plan close <id>` reviews a
fully-checked plan against its evidence and proposes *extend* or *close* —
status never changes by itself, and a partial review never proposes a clean
close. A fully-checked plan that is not active can be closed or deleted; the
architect asks which.
- **MCP lifecycle parity for Study Plans**: `list_study_plans`,
`get_study_plan`, `get_planning_interview`, `create_study_plan`,
`update_study_plan`, `set_study_plan_status`, `set_study_plan_milestone`,
`evaluate_study_plan` and `delete_study_plan` (confirmation required), thin
adapters over the same seam; the mission is revisable through
`update_study_plan`. `studyloop doctor` reports a plan document it cannot
read by name instead of hiding it behind "all ready".

### Changed

Expand All @@ -82,6 +140,39 @@ experience may change before `1.0.0`.
ranked lists, cosine ≥ 0.999 per query); encoder load falls from ~2.9 s to
~0.2 s and a one-shot CLI hybrid search from ~2.9 s to ~0.33 s p50.

### Fixed

- The Study Plan Architect's launch from the Web UI waits at most 8 s for the
session picker's options, so a stalled `/api/session/options` cannot hold a
click forever; leaving the page before a requested launch lands leaves a
session like any other (reattachable, ended with *End*) rather than a
half-state.
- A legacy `study_progress` row with no `last_seen` no longer crashes the
struggle collector — and with it `studyloop now` — on the way to a
recommendation.
- The release gate (`scripts/check-release-consistency.py --release`) read a
folded `deferred: >-` reason in an openspec change's `.openspec.yaml` as the
literal marker `>-`, so it printed no reason and would have accepted an
empty one — the unexplained deferral the guard exists to refuse. It now
reads the indented text and refuses an empty block.
- The Study Session view's timer ran its `init()` twice per page load (Alpine's
own call plus the markup's `x-init`), each run reading `/api/session/state`.
A tab sitting on the session picker could adopt a session started in
another tab when the slower read landed — Start hidden under the live
layout, no 409, no reattach offer. `init()` now runs once per page load;
a second tab's Start reaches the server and is offered reattach. Named by
the state captured at the click in CI (third occurrence, first with
evidence) and pinned by a `node --test` replay of that race.

### Security

- The offered commands in `studyloop now` (`evidence_command`, the body-double
door) quote every learner-authored value — plan titles, concepts, topics —
as a single shell word. A plan titled `SQL $(touch pwned) Windows` used to
run its substitution when the offered line was pasted into a shell.
- `anyio` 4.12.1 → 4.15.1 for two published advisories (CVE-2026-63374,
CVE-2026-64847); both dependency audits are clean again.

### Removed

- The forbidden-token test that failed the suite whenever "KiroCrew" appeared
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
schema: spec-driven
created: 2026-09-16
Original file line number Diff line number Diff line change
Expand Up @@ -258,7 +258,7 @@ writer, through the existing gate, closes that. Kept out of item 3 so item 3's f

## Item 7 — push step (owner present; HANDOFF §3 item 7)

- [ ] **T7.1** Not run unattended. Ruleset D-I; tokens D-J. **State 2026-09-18** (HANDOFF §3 item 7's seven
- [x] **T7.1** Not run unattended. Ruleset D-I; tokens D-J. **State 2026-09-18** (HANDOFF §3 item 7's seven
steps): (1) pushes — done, owner pushed `main` three times (#20 `46262d23`, #22 `4bba58b6`, #23 `a5b9f903`),
each a fast-forward after CI green on the PR; (2) ruleset D-I — done three times (2026-09-17
`feat/knowledge-proof` + `fix/plan-integration-bugs`; 2026-09-18 `feat/plan-close` +
Expand All @@ -270,7 +270,21 @@ writer, through the existing gate, closes that. Kept out of item 3 so item 3's f
item-6 issues — done 2026-09-19: **#25** (D-D derived plan bias) and **#26** (D-E nudge + retire/snooze), both
`ready-for-agent`, bodies drawn from the proposals with every cited test id, symbol and path checked against
`main` `a03fc9bd`; #21 given a status comment from the harness receipt and **left open** (its DoD names OpenCode
in core; OpenCode stays preview on the `opencode.db` exporter and the no-completed-reply gaps). **Open:**
(5) the local tag
`archive/feat-clean-start-2026-09-15` — owner: push or discard; (6) the GitHub Support ticket text — owner;
(7) revoke both tokens and delete `~/tmp/.env` — owner (D-J).
in core; OpenCode stays preview on the `opencode.db` exporter and the no-completed-reply gaps).
**Steps 5–7 closed 2026-09-21** (owner walkthrough, each fact re-checked against the live system first; #10,
#15 and #7 closed the same morning after the owner pushed `main` to `96806feb`): (5) the tag — **pushed** by
the owner (`9ec38e72` on origin). Checked before asking: its tip `daf46c81` is on no branch, only the dotenv fix
was ever cherry-picked (`bfe0695c`), and `clean_rebuild.py`, `corpus.py`, their tests and the clean-start
cutover receipt exist nowhere else — the tooling that produced the live `sessions.db`; it was the only one of
seventeen archive tags not on origin. (6) the Support ticket — the symptom it was written for is **gone**: the
repo page's contributors fragment lists only `@claude` and `@NetDevAutomate`, and the contributors API shows
the owner alone. `refs/pull/1..6/head` still exist, all six orphaned (unreachable from any branch or tag) and
fetchable, their histories carrying 85 commits under the owner's work address that the consolidation removed
from every branch. Owner is sending the ticket **reworded to that reason** (delete the cached head refs; the
merged PRs stay). (7) the tokens — `~/tmp/.env` **no longer holds them**: rewritten 2026-09-19 into a Fabric
configuration (fourteen variables, neither `GITHUB_TOKEN` nor `AWS_BEARER_TOKEN_BEDROCK`), so the "delete
`~/tmp/.env`" step would have deleted the wrong file and revoked nothing — **not done, deliberately**. Owner
revoked both D-J tokens at source 2026-09-21. Found alongside: `gh` on this machine ran on a classic PAT with
`admin:enterprise`, `admin:org`, `delete_repo`, `repo`, `workflow` scopes — every agent shell acted with it;
replaced by a browser OAuth login (`repo`, `read:org`, `gist`, `admin:public_key`), verified via
`gh auth status`, before the PAT was revoked.
9 changes: 0 additions & 9 deletions openspec/changes/plan-integration-followons/.openspec.yaml

This file was deleted.

Loading
Loading