Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
43 commits
Select commit Hold shift + click to select a range
f802fae
feat(ingest): tagger, compiler, and bulk ingestion CLI (P2-D/E/F) (#17)
febuz Jun 23, 2026
97bde9b
feat(agent-army): certification test generator (P3-A) (#18)
febuz Jun 23, 2026
fbbe437
docs(features): epic-organized feature list with shipped/planned brea…
Jun 23, 2026
84ffea9
feat(agent-army): agent roles and certification runner P3-B (#19)
febuz Jun 25, 2026
34b5305
chore: move OpenChem page to dedicated repo
febuz Jun 28, 2026
c468393
feat: inference scaling — Fases 1-4 (#22)
febuz Jul 16, 2026
bd21a83
fix: Resolve test isolation pollution in throughput governor unit tes…
febuz Jul 16, 2026
e13a7d2
refactor: Implement Fill's agent orchestrator spec (Task 1.3 corrected)
Jul 16, 2026
4f0c820
fix: Remove dead guardrails code blocking build
Jul 16, 2026
4123cf5
feat: Task 4.1 phase 1 — WebSocket service for real-time dashboard
Jul 16, 2026
6b872a0
feat: Task 4.1 phase 2 — Integrate RealtimeDashboard into HTTP server
Jul 16, 2026
1f03773
feat: Task 4.1 phase 3 — WebSocket client for real-time dashboard
Jul 16, 2026
974e72f
feat: Task 4.1 phase 4 — Add token usage monitoring to dashboard
Jul 16, 2026
1630fcf
feat: Implement Hive Mind shared agent memory (PR 1/3) (#25)
febuz Jul 17, 2026
c65945a
feat: Bot utility functions (PR 2/3) (#26)
febuz Jul 17, 2026
05a9e70
feat: Agent Notes Vault — agent brainstorming wiki (PR 3/3) (#27)
febuz Jul 17, 2026
8b417db
merge: sync Knitweb VirtualPC features and add exports
Jul 21, 2026
ba0f9fb
fix: restore 0.1 baseline and export runtime state
Jul 21, 2026
fd2caf0
docs: record VirtualPC parity audit
Jul 21, 2026
3e16ba1
docs: define Ethereum polyglot persistence roadmap
Jul 21, 2026
4344cd8
fix: keep 0.1 metrics evidence-based
Jul 21, 2026
bbad4a6
test: cover export and four-tier contracts
Jul 21, 2026
8a9406b
make reset metrics internally consistent
Jul 21, 2026
ae3b105
align note vault test with traversal rejection
Jul 21, 2026
863d033
fix: serve multi-agent dashboard at root
Jul 21, 2026
0cd2b7e
add Grok Build Python harness backlog
Jul 21, 2026
6d7d8e5
chore: point VirtualPC links to VirtuAnalytica
Jul 21, 2026
fa7975f
Merge pull request #30 from virtuanalytica/agent/virtuanalytica-repo-…
febuz Jul 21, 2026
60516bf
Merge pull request #29 from virtuanalytica/agent/grok-build-python-ha…
febuz Jul 21, 2026
7d9bb9c
Fix migrated-repo CI: drop unused chromedriver, heal SARIF uploads, r…
Jul 21, 2026
95b08df
CI: upgrade upload-artifact to v4, fix the one blocking lint error
Jul 21, 2026
6739ca1
Point the last two knitweb/virtualpc references to virtuanalytica
Jul 21, 2026
d973b50
Flip validate-repo stale-name policy for the virtuanalytica migration
Jul 21, 2026
717c632
Fix /api/backlog/create losing items: create a real task-engine task
Jul 21, 2026
6189b34
Merge pull request #31 from virtuanalytica/chore/ci-migration-fixes
febuz Jul 21, 2026
ac0ec65
Fix backup workflow: tar excludes must precede paths; checkout v3->v4
Jul 21, 2026
4aa39c6
Merge pull request #32 from virtuanalytica/fix/backup-tar-args
febuz Jul 21, 2026
94ef08d
chore(deps): bump body-parser from 1.20.5 to 1.20.6
dependabot[bot] Jul 21, 2026
76ee106
Merge pull request #33 from virtuanalytica/dependabot/npm_and_yarn/bo…
febuz Jul 21, 2026
1f67928
fix: make reset activity metrics evidence-based
Jul 21, 2026
8d00e3b
Merge pull request #34 from virtuanalytica/agent/fix-truthful-virtual…
febuz Jul 21, 2026
b264016
feat(finance): add Jev decision experiment stack
Sep 18, 2026
0a18e4b
Merge pull request #49 from virtuanalytica/feat/jev-finance
febuz Sep 19, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
30 changes: 30 additions & 0 deletions .backlog/ETHEREUM-P2P-PULSE-ROADMAP.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
# Ethereum / P2P / Pulse roadmap — MOLGANG 0.1

**Status:** planned, not deployed

## Scope

Ethereum provides settlement and verifiable provenance. IPFS/P2P provides
content-addressed asset distribution. Pulse provides the local signed event
journal. VirtualPC remains the gateway and review/orchestration layer.

## Delivery gates

1. Define and version `GameEvent`, `AssetManifest` and `TaskExport` schemas.
2. Implement a pure local adapter with deterministic digest generation and
`local`/`signed`/`on_chain` status transitions.
3. Add an EVM testnet adapter for `GameEventAnchor`; verify chain id, nonce,
replay protection, receipt confirmation and indexed event decoding.
4. Anchor one sanitized export-root digest and one asset-manifest digest on an
L2 testnet. Keep GLB/FBX bytes, hands, chat, telemetry and private player
data off-chain.
5. Add an indexer/read model so Web, Roblox tooling, Unity 6 and Snap AR read
confirmed anchors without querying the chain in every frame.
6. Require threat modeling, gas/cost limits, key management and independent
contract review before any production or mainnet deployment.

## Non-goals for 0.1

- No real-money promise, token sale or mainnet deployment.
- No wallet signing in the local demo unless the user explicitly enables it.
- No claim that a Pulse event is on-chain without a transaction receipt.
2 changes: 1 addition & 1 deletion .backlog/FEBUZ.md
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,7 @@ niets hiervan is ooit *gerenderd*. Dit is dé openstaande "werkt het echt"-vraag
## 🔐 VIRTUALPC — PR-review & operationeel (menselijk oordeel)

### FB-V1 — Review + merge PR #18 (security/stability)
- **Wat:** `gh pr view 18 --repo knitweb/virtualpc`. 6 codebase-gegronde fixes (o.a.
- **Wat:** `gh pr view 18 --repo virtuanalytica/virtualpc`. 6 codebase-gegronde fixes (o.a.
de 196 MB `task-state.json` workLog-cap, credential-encryptie #31,
path-traversal guard). Alles `tsc` clean, 2 unit-test suites.
- **Waarom mens:** mergen naar een live repo is jouw beslissing.
Expand Down
114 changes: 114 additions & 0 deletions .backlog/FOUR-TIER-POLYGLOT-MOLGANG.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,114 @@
# Four-tier polyglot architecture — MOLGANG / VirtualPC

**Status:** DESIGN BASELINE · implementation tracked separately
**Version:** 0.1

“Four-tier polyglot” is used here as a project architecture label, not as an
industry standard. Each tier has one clear responsibility and an explicit
contract with the next tier.

## Tier 1 — Presentation and clients

- MOLGANG Web: Next.js/TypeScript, WebGPU/WebGL fallback.
- Roblox: Lua client/server gameplay and Restaurant Mahjong table.
- Unity 6: asset-gallery and XR review client when Unity is installed.
- Snap AR/Spectacles: Lens Studio geospatial presentation using the shared GLB
catalog and location anchors.

Client rules:

- Clients send intent, never authoritative task, score, inventory or wallet
mutations.
- P2P/IPFS assets are content-addressed and may fall back to a packaged local
asset.
- Pulse events are labeled `local`, `signed`, or `on_chain`; no adapter means
no on-chain claim.

## Tier 2 — Gateway and orchestration

- VirtualPC Node.js/TypeScript on `127.0.0.1:3100`.
- REST for browser and tooling compatibility.
- WebSocket/Socket.IO for live task and playtest events.
- Rate limiting, local-only binding, export routes, audit logging and agent
routing live here.

Contract rules:

- JSON contracts are versioned (`virtualpc.export.v1`, game event versions).
- Long-running work is asynchronous and returns an id/status endpoint.
- Gateway endpoints expose source-backed statistics only; no hardcoded demo
progress or token usage.

## Tier 3 — Application and domain services

- Python FastAPI: chemistry, mahjong validation, player/inventory and audio
routes already present in MOLGANG Web.
- TypeScript VirtualPC: task engine, agent roles, token accounting, P2P/Pulse
orchestration and review gates.
- Lua: Roblox authoritative turn loop and restaurant gameplay.
- Future Rust/Go services are optional only after a measured bottleneck.

Communication choice:

- REST/JSON first for public local demo APIs and cross-language portability.
- WebSocket for live UI updates.
- gRPC only when profiling demonstrates high-volume internal calls where REST
overhead matters; do not add it as ceremony in 0.1.

## Tier 4 — Polyglot persistence and operations

- JSON/JSONL snapshots on EDS2 for the 0.1 VirtualPC state and audit exports.
- IPFS for immutable 3D asset content-addressing.
- Ethereum is the settlement/provenance anchor, preferably an EVM-compatible
L2 for gameplay-scale writes. Store compact identifiers, hashes, ownership,
settlement and emitted event references on-chain; keep large assets and
mutable gameplay state off-chain.
- Pulse journal/hash chain remains the local signed event layer. A real
Ethereum contract adapter is a separate deployment gate; `on_chain` is never
reported until a confirmed transaction receipt exists.
- PostgreSQL/Redis/vector storage remain planned integrations, not claims of
being operational in the fresh baseline.
- Blender/Unity/Snap asset build outputs are reproducible artifacts, not live
game state.

### Ethereum persistence boundary

| Data | Authoritative home | Ethereum representation |
| --- | --- | --- |
| Wallet ownership, asset rights and settlement | Ethereum/L2 contract | compact ids, balances and receipts |
| Asset bytes and manifests | IPFS/P2P with EDS2 build cache | CID or digest anchor |
| Live match, Mahjong hand and session state | domain service + EDS2/PostgreSQL later | signed event digest only when required |
| Agent tasks, worklog and exports | VirtualPC JSON/JSONL, PostgreSQL later | optional export-root digest |
| Cache, presence and transient queues | Redis later / gateway memory | not on-chain |
| Agent retrieval embeddings | vector store later | not on-chain |

The first contract candidate is `GameEventAnchor`: it accepts a schema version,
event hash, asset-CID digest and actor, then emits an indexed anchor event.
`PulseRegistry` may reference approved Pulse manifests, but neither contract is
deployed in the 0.1 demo. Mainnet deployment requires a threat model, contract
tests, gas limits, wallet/network configuration and an external security review.

## Required contracts

- `AssetManifest`: id, CID, runtime format, source format, SHA-256 and fallback.
- `GameEvent`: event id, actor, match/session, type, payload schema, timestamp,
previous hash and provenance status.
- `TaskExport`: schema, version, generated time, stats, backlog, worklog and
token summary; implemented at `/api/export/backlog`.
- `AgentTask`: owner role, input, output artifact, review gate and evidence.

## Acceptance criteria

- [ ] A contract test proves one event can travel Web → VirtualPC → Python and
back as a versioned JSON response.
- [ ] Roblox, Web, Unity and Snap asset manifests resolve the same CID or an
explicit local fallback.
- [ ] A failure in one tier produces a visible degraded status, not fabricated
success.
- [x] Data-role ownership is recorded for schema, lineage, retention and export
in MOLGANG `shared/agent-review-contracts.json` and covered by the
four-tier contract test.
- [ ] Ethereum adapter tests cover chain id, nonce/replay handling, receipt
confirmation, event decoding and explicit `local`/`signed`/`on_chain` status.
- [ ] An L2 testnet demo anchors one export or game event by digest; no gameplay
asset bytes or private player data are written to the chain.
61 changes: 61 additions & 0 deletions .backlog/GROK-BUILD-PYTHON-HARNESS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
# Gither/Grok Build → pure-Python ClaudeClaw_Fill harness

Status: `blocked-on-preflight`

This is a VirtualPC coordination item, not an instruction to start agents
immediately. The ClaudeClaw_Fill harness must be healthy and reviewed before
any dependent MOLGANG 0.1 task moves from `pending` to `in-progress`.

## Source

- Upstream: <https://github.com/xai-org/grok-build>
- Repository: `xai-org/grok-build`
- Reviewed upstream commit: `a881e6703f46b01d8c7d4a5437683546df30449d`
- Upstream license reported by GitHub: Apache-2.0
- Upstream description: coding-agent harness and interactive TUI
- Target: pure Python implementation on the VirtualPC stack

The port must preserve attribution and license notices. It must not copy
undocumented services, credentials, or provider-specific secrets.

## Agent ownership

| Stage | Owner | Required output |
|---|---|---|
| Harness preflight and unlock | Fill | VirtualPC/ClaudeClaw_Fill capability probe, dry-run receipt, unlock decision |
| Source inventory and boundary | Kimi | upstream-to-Python mapping, supported/unsupported interface record |
| Python port and adapter | Zip | isolated pure-Python package/CLI, offline provider mock, draft PR |
| VirtualPC integration | Kai | task context, tool ACL, EDS2 workspace boundary, provenance receipt |
| UX and agent acceptance | Mira | TUI/player-facing acceptance notes and scoped PR feedback |
| Principal PR review | Athena | security, tests, license, data-egress and reproducibility review |
| Final arbitration | Alexander | explicit merge authorization or request-changes decision |

## Acceptance gates

1. `claudeclaw_fill` harness health is green on the VirtualPC stack.
2. A dry-run dispatch proves agent identity, task context, tool permissions,
workspace boundary, evidence capture and draft-PR handoff.
3. The Python port runs without the upstream runtime as a required dependency.
4. Offline tests cover provider failure, retry, cancellation and malformed
tool output; secrets never appear in logs or receipts.
5. The VirtualPC backlog remains the source of truth and no dependent MOLGANG
item starts before this file's preflight is accepted.
6. Athena reviews every candidate PR; Alexander is the final arbiter.
7. Merge authorization stays `false` until explicit human coordination and
all evidence gates are recorded.

## Live VirtualPC task links

These were created through `POST /api/backlog/items` and must remain pending
until the preflight is accepted:

- `task-1784621289645-582` — Fill: ClaudeClaw_Fill harness preflight
- `task-1784621289656-172` — Kimi: Grok Build integration research
- `task-1784621289659-197` — Kai: VirtualPC adapter and bridge
- `task-1784621289661-153` — Zip: offline smoke and PR handoff
- `task-1784621289664-415` — Athena: mandatory PR review
- `task-1784621289666-77` — Alexander: final arbiter
- `task-1784621312818-730` — Zip: pure-Python port

No implementation is authorized by this document alone; the agents must raise
reviewable PRs and attach reproducible evidence to their tasks.
47 changes: 47 additions & 0 deletions .backlog/MOLGANG-0.1-RESET-EXPORT-SYNC.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
# MOLGANG 0.1 — VirtualPC reset, export en GitHub-sync

**Status:** ACTIVE · baseline reset uitgevoerd op 2026-07-21

## Baseline

- Version: `0.1`
- Completed tasks: `0`
- Daily updates: `0`
- Qwen tokens used: `0`
- Uptime: process counter from the latest VirtualPC start
- Historical task state: archived under `/media/knight2/EDS2/virtualpc-state/archive/`

## Delivered

- `GET /api/export/backlog?format=json`
- `GET /api/export/backlog?format=csv`
- `GET /api/export/backlog?format=markdown`
- Export includes current game stats, visible backlog, last 1000 work-log entries and token summary.
- GitHub `virtuanalytica/virtualpc` master synchronized with local source.
- Hive Mind, bot utility and Agent Notes Vault features merged from GitHub.
- Broken upstream orchestrator/OpenClaw compatibility restored so TypeScript builds.

## Parity audit 2026-07-21

- Local `HEAD`: `ba0f9fbb`; `knitweb/master`: `ba0f9fbb`.
- No open GitHub PRs remain.
- Merged PRs 25, 26 and 27 are present locally and live on port 3100.
- Closed/unmerged branches such as `feat/virtuanalytica-demo` remain review-only;
they are not copied into production runtime without a validated diff.

## Acceptance checks

- [x] `npm run build`
- [x] `GET /api/health` returns version `0.1`.
- [x] `GET /api/metrics` returns zeroed new-baseline counters and reports
whether autonomous synthetic ticks are explicitly enabled.
- [x] JSON, CSV and Markdown export routes return successfully.
- [x] One-shot reset flag removed after the reset; subsequent restarts preserve the new state.
- [x] Autonomous synthetic ticks are disabled by default; fresh 0.1 tasks remain
reviewable without fabricated completions.
- [x] Add automated API tests for export schema and content-disposition headers
(`tests/unit/exportRoute.test.ts`).
- [ ] Add a scheduled GitHub/local parity audit and report drift in VirtualPC.
- [x] Implement four-tier polyglot contract tests before adding gRPC,
PostgreSQL, Redis or vector persistence to the 0.1 runtime
(`tests/unit/fourTierContracts.test.ts`).
45 changes: 45 additions & 0 deletions .eslintrc.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
{
"env": {
"node": true,
"es2021": true,
"jest": true
},
"globals": {
"NodeJS": "readonly"
},
"extends": [
"eslint:recommended"
],
"parser": "@typescript-eslint/parser",
"parserOptions": {
"ecmaVersion": "latest",
"sourceType": "module",
"project": "./tsconfig.json"
},
"plugins": [
"@typescript-eslint"
],
"rules": {
"no-console": "warn",
"no-unused-vars": "off",
"no-empty": "warn",
"no-useless-escape": "warn",
"no-undef": "off",
"@typescript-eslint/no-unused-vars": [
"warn",
{
"argsIgnorePattern": "^_",
"varsIgnorePattern": "^_"
}
],
"@typescript-eslint/explicit-module-boundary-types": "off",
"@typescript-eslint/no-explicit-any": "warn"
},
"ignorePatterns": [
"dist",
"build",
"node_modules",
"coverage",
"*.d.ts"
]
}
13 changes: 6 additions & 7 deletions .github/workflows/backup-system-files.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ jobs:
runs-on: ubuntu-latest

steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v4

- name: Create backup archive
run: |
Expand All @@ -22,15 +22,14 @@ jobs:
mkdir -p backup-archive

# Backup all system files
tar -czf backup-archive/system-files-$(date +%Y%m%d-%H%M%S).tar.gz \
# tar excludes are positional: they must precede the paths they filter
tar --exclude=node_modules --exclude=dist --exclude=.git \
-czf backup-archive/system-files-$(date +%Y%m%d-%H%M%S).tar.gz \
.admin/ \
.governance/ \
.creative/ \
.operations/ \
.backlog/ \
--exclude=node_modules \
--exclude=dist \
--exclude=.git
.backlog/

echo "✓ Backup created"
ls -lh backup-archive/
Expand All @@ -57,7 +56,7 @@ jobs:
cat backup-archive/MANIFEST.txt

- name: Upload backup artifacts
uses: actions/upload-artifact@v3
uses: actions/upload-artifact@v4
with:
name: system-backup-$(date +%Y%m%d)
path: backup-archive/
Expand Down
4 changes: 3 additions & 1 deletion .github/workflows/build-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -84,7 +84,9 @@ jobs:
output: 'trivy-results.sarif'

- name: Upload Trivy results to GitHub Security tab
uses: github/codeql-action/upload-sarif@v2
# Code-scanning upload needs GHAS on this private repo; do not fail CI on it.
continue-on-error: true
uses: github/codeql-action/upload-sarif@v3
if: always()
with:
sarif_file: 'trivy-results.sarif'
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/ci-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,7 @@ jobs:

- name: Upload build artifacts
if: success()
uses: actions/upload-artifact@v3
uses: actions/upload-artifact@v4
with:
name: build-${{ matrix.node-version }}
path: |
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/deploy-production.yml
Original file line number Diff line number Diff line change
Expand Up @@ -65,7 +65,7 @@ jobs:
tar czf virtualpc-deployment-${{ github.sha }}.tar.gz deploy-artifact/

- name: Upload deployment artifact
uses: actions/upload-artifact@v3
uses: actions/upload-artifact@v4
with:
name: deployment-package
path: virtualpc-deployment-${{ github.sha }}.tar.gz
Expand Down
4 changes: 3 additions & 1 deletion .github/workflows/security-audit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,9 @@ jobs:
output: 'trivy-image-results.sarif'

- name: Upload Trivy results
uses: github/codeql-action/upload-sarif@v2
# Code-scanning upload needs GHAS on this private repo; do not fail CI on it.
continue-on-error: true
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: 'trivy-image-results.sarif'

Expand Down
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -86,3 +86,4 @@ __pycache__/
.ai/tasks/*/index.json
.ai/deliberation/**/*.json
.ai/deliberation/**/*.md
data/codex-game-dev/workspaces/
Loading
Loading