Vikunja #268 (P0): handleHexisAct swallowed genuine Nexus resolve errors
and Hexis capability-discovery errors into "" or an empty capability list,
which fell through to the local system command executor — a dependency
outage silently looked identical to "not an ecosystem entity" or "no
capabilities registered", violating the spec's degrade-independently /
never-silent-all-clear invariant.
- resolveEntityReference's error is now distinguished from a legitimate
not_found: only the latter falls through.
- discoverCapabilities now returns (caps, err) instead of collapsing a
Hexis failure into an empty slice; a real error stops the action with
a degraded-mode spoken reply instead of reaching h.tools.Exec.
- nexusResolveResult gains a custom UnmarshalJSON to accept the flat
entity_id/entity_type/display_name shape from ECOSYSTEM-SPEC.md §1.5
(Nexus now emits both shapes; Maven now reads both).
- Added regression tests: flat-shape resolve, Nexus error fails closed,
Hexis error fails closed, not_found still falls through to local exec.
Bring the Nexus/Praxis/Hexis integration in line with
MAVEN_ECOSYSTEM_ARCHITECTURE.md:
- Praxis over HTTP: drop the in-process praxis.db open (praxisstore/
praxistools) and call praxisd's /api/v1/tools/* API via a new praxisClient.
Honors the "no component reads another's DB" invariant (AC#12).
PraxisConfig.DBPath -> URL.
- Hexis confirmation gate: mutating capabilities (ReadOnly=false) now park a
bound pendingHexis confirmation and require a spoken "да" before executing;
read-only run immediately (AC#7, no auto attention->action).
- Capability safety: >1 verb match is ambiguous -> ask instead of firing the
first; ambiguous Nexus resolution asks for clarification (AC#2).
- Correlation IDs on Hexis execute, recorded in the cross-service trace.
- Bug: importance arrives as JSON float64 over HTTP, not int.
- Tests: confirm-gate, decline, read-only, and ambiguity paths.
Build: vendor/ bakes in the hexis client (replace-directed at a sibling repo
outside the Docker context); Dockerfile builds from vendor and no longer
`go mod download`s the unreachable replace paths.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>