Compare commits

..

4 Commits

Author SHA1 Message Date
claude 240d53a96a Give the stage 0 grammar set one home (V-693)
buildRouter held the real set and baselineGrammars in eval_test.go restated it
by hand, in the daemon's order, with its own comment saying so. Three test files
score against the fixture and nothing compared the two lists. They had already
drifted: BareCaptureGrammar went into the daemon with V-557 and never into the
fixture, so every routing measurement since has scored a set nobody runs. That
is the failure CLAUDE.md warns about by name, and a diff test would have caught
it one grammar late.

The list moves to router.StageZeroGrammars in internal/router/stagezero.go, with
the ordering comments, which are the load-bearing part. buildRouter and the
fixture both call it. One list cannot drift from itself.

Measured before and after on the 96-case fixture: classifier+onnx 72/96, 75.0%
intent, 33.3% destination, identical either way, and the deterministic claim and
reach hash ratchets do not move. So the missing grammar cost no measurable
accuracy. That is the point rather than a reprieve: the fixture had been scoring
the wrong set for four days and nothing could say so.

The invariants caveat is deleted, both entries, since V-692 landed the other
guard in the previous commit. The reasoning for both now sits in docs/routing.md
beside the subsystem, which is where a fix's durable record belongs.

Unrelated and pre-existing: TestONNXPersonalBoundary fails on "я рассказывал
тебе про байкал?" (personal 0.9068, world 0.9413) at the merge base too.
2026-08-11 21:02:31 +04:00
claude d8efb667c7 Refuse a heads_path that is the embedder's own model file (V-692)
CLAUDE.md, internal/config/voice.go and docs/routing.md all say the routing
heads graph is a fine-tuned copy of the embedder, never the embedder's own file.
Nothing enforced it. The daemon loaded whatever the key pointed at, so pointing
both keys at one file cost recall with no error and no log line, which reads as
ordinary drift rather than as a misconfiguration.

validateVoice now refuses it at load. Both paths are cleaned and made absolute
first, so "./m.onnx" and "$PWD/m.onnx" are one path, and then compared with
os.SameFile, which catches a copy that is a symlink or a hard link. A path that
does not stat is left to the loader, whose error message is better than this
check can give.

Refusing to start is deliberate and it differs from the loader's treatment of a
broken weights file, which logs and leaves the heads nil on purpose. That case
is a missing accelerator. This one is a working file in the wrong role, and a
daemon that cannot route well should say so rather than answer worse.

deploy/mavend.json points the two keys at different files, so the live config
still starts.
2026-08-11 21:02:16 +04:00
claude 25ed201c4d Merge PR #227 'Wire staticcheck and deadcode, and gate both on a baseline' (V-694) 2026-08-11 20:15:55 +04:00
claude a926383827 Wire staticcheck and deadcode, and gate both on a baseline (V-694)
The 2026-08-10 audit asked for three analyzers. V-682 wired the first as `make
vuln`. The other two were still absent: neither was installed on the box and no
target ran them, so every reachability claim in the audit stood unchecked.

`make lint` runs staticcheck v0.7.0 and `make deadcode` runs deadcode v0.48.0.
Both are pinned in the Makefile beside GO_VERSION and installed into deps/bin
the way govulncheck is, because a tool is not a dependency of the module. Both
carry the CGO env `test` carries, or the four CGO daemons fail to load and the
analyzer reports a build error instead of a finding. `make analyze` runs all
three. None joins `make test`: they install over the network and `test` has to
pass on a box with no route out.

Neither reports zero, so neither fails on its own output. staticcheck finds 20
and deadcode finds 13, and the audit asked for an allowlist by name, because
three of deadcode's eleven production symbols are deliberate and an unannotated
list invites deleting them. The accepted set lives in
scripts/analyzers/*.baseline, one line per finding with the reason it stays, and
scripts/analyzer-gate.sh gives the verdict. A key holds file, check id and
message, never a line number: a line number goes stale on the next edit above
it, and a gate that reports moved findings as new ones teaches the reader to
skip it. An entry whose finding is gone also fails, so a fix that leaves its
line behind does not pass.

deadcode runs with -test, because a test is a caller. Without the flag the
report is 172 lines, most of internal/router/eval, and none of it is a mistake.
With it, the 11 symbols the audit listed come back exactly, plus two test
helpers it did not count.

Three staticcheck findings were checked and are false positives, recorded as
such: the iCal determinism test must call RenderICal twice, the morning hedge
loop breaks after the first rune on purpose, and the SA9009 line is prose about
//go:embed with the real directive below it. One is V-687 already. The remaining
17 are V-701 with the judgement on each.

The analyzers caveat is deleted rather than edited. What replaces it is the
limit that is now true: the gates are green against a baseline, not against
zero.
2026-08-11 20:01:54 +04:00
15 changed files with 491 additions and 121 deletions
+11 -2
View File
@@ -54,8 +54,15 @@ carries `-count=1` and sets `MAVEN_ONNX_LIB`. Without that variable the four
make build # all 11 binaries. make build-web for one (web/waked/poll/caldav skip CGO)
make test # go test -race across ./internal/... ./cmd/... with CGO env set
make t PKG=./internal/router/eval/ RUN='TestONNX' V=1 # V=1 for -v, RACE=0 to drop -race
make analyze # staticcheck, deadcode and govulncheck. Not in `test`: all three need the network
```
**The static gates pass against a baseline, not against zero**
(`scripts/analyzers/*.baseline`, reasoning in `docs/workflow.md`). A fix must
delete its baseline entry, because the gate also fails on an entry whose finding
is gone. **`make audit` is a git-grep inventory, not analysis.** Do not cite it
as a reachability check.
## The daemons
Eleven binaries under `cmd/`, wired socket-to-socket over `internal/ipc`, not
@@ -108,13 +115,15 @@ classifier. Every stage may decline and the next one answers.
- **The classifier is the floor, not dead code.** It answers when the resident
model is off, absent, or erroring. **Any model error falls through.**
- **`baselineGrammars` in `eval_test.go` mirrors `buildRouter`.** A grammar
added to one belongs in both, or the fixture scores a set nobody runs.
- **The stage 0 set lives in `router.StageZeroGrammars`**, and both `buildRouter`
and the eval fixture call it. Add a grammar there, in the right place, and read
the comment above the line you insert after. Do not restate the list anywhere.
- **Go's `\b` is ASCII-only** and never fires after a Cyrillic letter. A Russian
pattern needs an explicit `(\s|[?!.]|$)`.
- **`PraxisGrammars()` is the only path to Praxis**, not a faster one.
- **`voice.embedder.heads_path` must never point at `model_path`.** Recall
depends on the resident e5-small scoring what it scored. Fine-tune a copy.
Refused at config load since V-692, symlinks included.
- **Routing traces are retained 14 days**, enforced on write and again on start.
- **Bump `tokenizerRev` on any change to what `encodeWord` emits**, so a
tokenizer fix triggers `ReembedAll` the way swapping the model file does.
+41 -1
View File
@@ -16,7 +16,7 @@ PIPER_BIN := $(shell pwd)/deps/piper/piper
PIPER_MODEL := $(shell pwd)/models/tts/ru_RU-irina-medium.onnx
PIPER_ESPEAK := $(shell pwd)/deps/piper/espeak-ng-data
.PHONY: t audit simulate stt-fixtures test-stt-golden all build build-stt build-tts build-daemon build-client build-waked build-web build-poll build-caldav clean test fmt-check vet run-stt run-tts run-web download-embedder deps-go deps-sentinel deps-vuln vuln tidy eval-router eval-reach eval-recall eval-phrasing eval-models build-gpud
.PHONY: t audit simulate stt-fixtures test-stt-golden all build build-stt build-tts build-daemon build-client build-waked build-web build-poll build-caldav clean test fmt-check vet run-stt run-tts run-web download-embedder deps-go deps-sentinel deps-vuln vuln deps-lint lint deadcode analyze tidy eval-router eval-reach eval-recall eval-phrasing eval-models build-gpud
all: build
@@ -119,6 +119,46 @@ vuln: deps-vuln
CGO_CFLAGS="$(CGO_CFLAGS)" CGO_LDFLAGS="$(CGO_LDFLAGS)" LD_LIBRARY_PATH="$(shell pwd)/deps/lib" \
PATH="$(shell pwd)/deps/go/go/bin:$$PATH" GOTOOLCHAIN=local $(GOVULNCHECK) ./...
# lint and deadcode — the other two analyzers the 2026-08-10 audit asked for
# (V-694). They are not part of `test` for the same reason `vuln` is not: they
# install over the network, and they are slow enough that a change to one Go
# file should not pay for them.
#
# Neither reports zero, so neither fails on its own output. The accepted set
# lives in scripts/analyzers/*.baseline and scripts/analyzer-gate.sh decides.
# What is new fails, and so does a baseline entry whose finding is gone.
#
# deadcode runs with -test, so a test file is a root. Without it the report is
# 172 lines, most of internal/router/eval, and none of it is a mistake.
STATICCHECK_VERSION := v0.7.0
DEADCODE_VERSION := v0.48.0
STATICCHECK := $(shell pwd)/deps/bin/staticcheck
DEADCODE := $(shell pwd)/deps/bin/deadcode
deps-lint: deps-sentinel
@mkdir -p deps/bin
GOTOOLCHAIN=local GOBIN=$(shell pwd)/deps/bin \
$(GO) install honnef.co/go/tools/cmd/staticcheck@$(STATICCHECK_VERSION)
GOTOOLCHAIN=local GOBIN=$(shell pwd)/deps/bin \
$(GO) install golang.org/x/tools/cmd/deadcode@$(DEADCODE_VERSION)
# Both load the packages, so both carry the CGO env `test` carries. Without it
# the four CGO daemons do not load and the analyzer reports a build error
# instead of a finding -- which analyzer-gate.sh fails on rather than filters.
ANALYZER_ENV = CGO_CFLAGS="$(CGO_CFLAGS)" CGO_LDFLAGS="$(CGO_LDFLAGS)" \
LD_LIBRARY_PATH="$(shell pwd)/deps/lib" \
PATH="$(shell pwd)/deps/go/go/bin:$$PATH" GOTOOLCHAIN=local
lint: deps-lint
@$(ANALYZER_ENV) $(STATICCHECK) ./... | scripts/analyzer-gate.sh staticcheck
deadcode: deps-lint
@$(ANALYZER_ENV) $(DEADCODE) -test ./... | scripts/analyzer-gate.sh deadcode
# Every static gate in one command. Not `check`, because it is not the thing to
# run before a commit: vuln reads the network and all three are slow.
analyze: lint deadcode vuln
# Run the tidy the sentinel makes possible. Not part of `test`: it rewrites
# go.mod, and a build target that edits the module file is a surprise.
# vendor/ is committed, so a tidy that drops a requirement must be followed by
+3 -39
View File
@@ -469,45 +469,9 @@ func buildRouter(emb router.Embedder, acts router.ActMatcher, threshold float64,
llmR *router.LLMRouter, heads *router.RouterHeads) *router.Router {
cls := router.NewClassifier(emb)
seedClassifier(cls)
grammars := router.DefaultGrammars(acts)
grammars = append(grammars, router.SystemTimeDateGrammars()...)
// After the time/date rules on purpose: "какой сегодня день" is a clock
// question and must keep reaching replySystem, while "что у меня сегодня"
// is an agenda question and must not.
grammars = append(grammars, router.AgendaQueryGrammars()...)
// Same reason as the agenda rules, for the feeds: "что нового в лентах?"
// routed system and answered "пока не умею" (Vikunja #474).
// After the agenda rules, which are the narrower claim, and BEFORE the feed
// and list rules, which are not: "что такое лента" is a definition question
// and the feed rule would take it on the noun alone (V-655).
grammars = append(grammars, router.WorldQueryGrammars()...)
grammars = append(grammars, router.FeedQueryGrammar())
// The list side of the same exposure: a phrasing with no possessive in it
// ("список дел") routed system and never reached queryTasks (Vikunja #467).
grammars = append(grammars, router.TaskListGrammar())
grammars = append(grammars, router.ListGrammars()...)
grammars = append(grammars, router.ReminderGrammar())
// Before the capture marker, because "отметь" is a capture verb and "отметь
// второй пункт" is not a note. The Praxis rules are the narrower claim — a
// lifecycle verb AND an item named — so they get first refusal (Vikunja #516).
grammars = append(grammars, router.PraxisGrammars()...)
// Last, and it matches any utterance shape — its Build is the filter. An
// explicit capture marker beats the model, which called it an act and
// rewrote the task text (Vikunja #467). After the rules above because a
// marker never collides with a clock or agenda question.
// After Praxis, whose bare "закрой" claim this rule cannot reach (it needs the
// board noun), and before the capture marker, which would otherwise read
// "убери из задач купить молоко" as a new task (Vikunja #512).
grammars = append(grammars, router.TaskStatusGrammar())
// Before the capture markers, which all need an object. A capture verb
// alone is a fact with no key, and the clarify path asks for it rather than
// letting the model invent an answer (Vikunja #557).
grammars = append(grammars, router.BareCaptureGrammar()...)
grammars = append(grammars, router.TaskCaptureGrammar())
// After the capture marker, so "запиши" still wins over "расскажи", and
// last overall because it matches on the first word alone: "расскажи про
// X" is a world question the model called a fact (Vikunja #498).
grammars = append(grammars, router.NarrativeQueryGrammars()...)
// The stage 0 set, in the router package, so the eval fixture runs the rules
// the daemon runs (V-693). Order and reasoning live with the list.
grammars := router.StageZeroGrammars(acts)
return router.New(router.Config{
Grammars: grammars,
Classifier: cls,
+8 -7
View File
@@ -21,10 +21,13 @@ caveat is the pointer between them plus the trigger.
## Index
Every entry below came from the 2026-08-10 deep audit
(`docs/evals/2026-08-10-repo-audit.md`). Two of the twenty findings are fixed
and have no entry. The unauthenticated mavgpud proxy was V-673. The 20 reachable
advisories in the toolchain and `x/text` were V-682, which left the analyzers
entry below behind under its own id.
(`docs/evals/2026-08-10-repo-audit.md`), except the last, which came from wiring
the gate the audit asked for. Five of the twenty findings are fixed and have no
entry. The unauthenticated mavgpud proxy was V-673. The 20 reachable advisories
in the toolchain and `x/text` were V-682. The missing analyzers were V-694, and
what they now report is the baseline entry under V-701. The two unguarded
invariants were V-692 and V-693, and their guards are described in
`docs/routing.md`.
| limit | severity |
| --- | --- |
@@ -40,10 +43,8 @@ entry below behind under its own id.
| [mavweb errors cannot be traced](transport.md#errors) | medium |
| [Fact enrichment is a 20-call serial waterfall](workers.md#enrichment) | medium |
| [A suppressed nudge is phrased anyway](workers.md#nudges) | medium |
| [heads_path may equal model_path](invariants.md#heads) | medium |
| [baselineGrammars is mirrored by hand](invariants.md#grammars) | medium |
| [Committed absolute paths pin the build to this box](config.md#paths) | medium |
| [The env example omits deployed variables](config.md#secrets) | medium |
| [staticcheck and deadcode are not wired into a make target](dependencies.md#analyzers) | medium |
| [The analyzers pass against a baseline, not zero](dependencies.md#baseline) | medium |
| [Domain packages depend on store and IPC types](layering.md#dtos) | low |
| [Eleven symbols are unreachable](layering.md#deadcode) | low |
+10 -11
View File
@@ -1,14 +1,13 @@
# Dependencies
## staticcheck and deadcode are not wired into a make target [#694] {#analyzers}
## The analyzers pass against a baseline, not against zero [#701] {#baseline}
Costs: two of the three analyzers the 2026-08-10 audit asked for are missing.
Neither is installed on this box and no target runs them. `make audit` is a git-grep
inventory over loc, todo, stubs, docs, tests and gaps. **Do not read it as a
static-analysis gate.** `make vuln` is the third one and it is wired (V-682):
govulncheck is pinned in the Makefile, installed into `deps/bin` and run over
`./...`. It reads the published database over the network, so it stays out of
`make test`.
Revisit when: the next dead-code claim needs checking. `deadcode` has a finding
waiting for it in [layering.md](layering.md#deadcode).
Workaround: none. Read a reachability claim as unverified until one of them runs.
Costs: `make lint` and `make deadcode` are wired and green (V-694), but green
means "nothing new since 2026-08-11". The accepted set is 19 staticcheck
findings and 13 unreachable symbols, listed with a reason each in
`scripts/analyzers/*.baseline`. Three of the unreachable symbols must stay:
[layering.md](layering.md#deadcode). One accepted staticcheck finding is V-687.
Revisit when: V-701 sweeps the baseline, or a fix deletes an entry. The gate
fails on an entry whose finding is gone, so the deletion is not optional.
Workaround: none needed. Reachability claims are checkable now. Read the
baseline before trusting that a target reporting clean means the tree is clean.
-27
View File
@@ -1,27 +0,0 @@
# Unguarded invariants
`CLAUDE.md` names these as load-bearing. Nothing enforces either one. A rule
that lives only in prose gets broken by whoever did not read the prose. Both of
these fail silently when broken.
`tokenizerRev` and `preRouteLadder` were checked and need nothing. The rev is
baked into the embedder key, so a bump triggers re-embedding. A missing ladder
rung is observable in the decision record.
## heads_path may equal model_path [#692] {#heads}
Costs: the routing heads then score with the same graph the resident e5-small
uses, and recall degrades. There is no error and no log line, so it reads as
ordinary drift rather than a misconfiguration.
Revisit when: `deploy/mavend.json` is edited by hand, or a fine-tuned heads
graph is swapped in.
Workaround: check the two keys by eye. That is the whole guard today.
## baselineGrammars is mirrored by hand [#693] {#grammars}
Costs: the eval fixture restates the stage 0 rule set in the daemon's order,
and its own comment says so. Three test files score against it. A grammar added
to `buildRouter` alone means every routing measurement scores a set nobody
runs. `CLAUDE.md` warns about this failure by name.
Revisit when: the next stage 0 grammar is added. That is when it bites.
Workaround: add to both lists, which is what the rule already says.
+17 -5
View File
@@ -1,6 +1,6 @@
# Routing
*Last verified: 2026-08-09 @ 31b5093*
*Last verified: 2026-08-11 @ 25ed201*
How an utterance becomes a `Decision`, why each stage exists, and what every
stage has measured. `CLAUDE.md` carries the rules an agent must not break. This
@@ -137,10 +137,15 @@ below.
Go's `\b` is ASCII-only and never fires after a Cyrillic letter. A pattern needs
an explicit `(\s|[?!.]|$)`.
`baselineGrammars` in `eval_test.go` mirrors `buildRouter` and has drifted before.
`WorldQueryGrammars` was wired into the daemon by V-655 and not into the mirror,
so the fixture scored a grammar set nobody runs. Fixed by V-659, worth 3 points
of destination.
The stage 0 set lives in `router.StageZeroGrammars` (`internal/router/stagezero.go`).
Both `buildRouter` and the eval fixture call it. The daemon and the measurement
cannot disagree about which rules exist, or in what order.
It was two lists until V-693 and it drifted twice. V-655 wired
`WorldQueryGrammars` into the daemon and not into the fixture. That cost 3 points
of destination and V-659 fixed it. `BareCaptureGrammar` then did the same thing,
from V-557 until V-693 found it. That one moved no number, which is the point:
the fixture had been scoring a set nobody ran and nothing said so.
### Praxis lifecycle rules
@@ -270,6 +275,13 @@ Three rules around it, each measured:
means the heads are nil. The cascade is then byte-for-byte what shipped before
them.
Pointing it at `model_path` is refused at config load (V-692). An unloadable
weights file is not fatal, because the heads are an accelerator. A working file
in the wrong role is a different thing. The heads then score with the graph the
resident embedder scored with, and recall degrades with no log line. The check
cleans and absolutises both paths, then compares them with `os.SameFile`, so a
symlinked copy is caught too.
### The tokenizer bug the heads found
`encodeWord` in `onnxembedder.go` read every long word backwards until 2026-08-08.
+38 -1
View File
@@ -1,6 +1,6 @@
# Session workflow: the five stores and the guards
*Last verified: 2026-08-09 @ a9b480a*
*Last verified: 2026-08-11 @ 557f5a3*
How a session starts, where each kind of writing belongs, and what the hooks
refuse. `CLAUDE.md` carries the commands. This file carries the reasoning.
@@ -78,3 +78,40 @@ blocks further edits past 600 changed lines on a `task/` branch.
budget read high.
`--no-verify` exists. Using it means saying why in the commit body.
## Static gates
Three analyzers, one target each, and `make analyze` for all three. The
2026-08-10 audit asked for them because none was installed on the box and
`make audit` is a git-grep inventory, not analysis. Do not read `make audit` as
a gate.
- `make vuln`, govulncheck over `./...` (V-682).
- `make lint`, staticcheck over `./...` (V-694).
- `make deadcode`, deadcode with `-test` over `./...` (V-694).
None of the three joins `make test`. All three install over the network, and
`test` has to pass on a box with no route out. `vuln` reads the advisory
database at run time as well. Run `make analyze` before a dependency or
toolchain bump lands, and before calling a symbol unreachable.
Each tool is pinned in the Makefile beside `GO_VERSION`. A gate that moves on
its own is not a gate. Each installs into `deps/bin`, because a tool is not a
dependency of the module.
**staticcheck and deadcode pass against a baseline, not against zero.** The
accepted findings live in `scripts/analyzers/*.baseline`, one line each. A key
holds file, check id and message, never a line number. A line number goes stale
on the next edit above it. The output then reports moved findings as new ones,
and the reader learns to skip it.
`scripts/analyzer-gate.sh` gives the verdict. A finding absent from the baseline
fails. So does a baseline entry whose finding is gone, which is what stops the
accepted set from outliving the repo. Deleting the entry is part of each fix.
`deadcode` runs with `-test` because a test is a caller. Without the flag the
report is 172 lines, most of `internal/router/eval`, none of it a mistake.
A baseline entry carries the reason it stays. Three reasons appear. Another task
owns the finding. The check cannot see through a false positive. A cosmetic
finding waits for a sweep.
+48
View File
@@ -2,6 +2,9 @@ package config
import (
"errors"
"fmt"
"os"
"path/filepath"
"time"
)
@@ -141,10 +144,55 @@ func (c *Config) validateVoice() error {
if e.ModelPath == "" || e.TokenizerPath == "" || e.LibPath == "" {
return errors.New("voice.embedder: all three of model_path, tokenizer_path, lib_path must be set, or remove embedder to use the floor stub")
}
if err := e.checkHeadsDistinct(); err != nil {
return err
}
}
return nil
}
// checkHeadsDistinct refuses a heads graph that is the embedder's own file
// (V-692). The rule is stated on HeadsPath above and in CLAUDE.md, and until
// now nothing enforced it: the daemon loaded whatever the key pointed at, so
// pointing both keys at one file cost recall with no error and no log line. It
// reads as ordinary drift, which is the worst kind of misconfiguration.
//
// Refusing to start is the right trade here. The heads are an accelerator and a
// broken weights file is deliberately not fatal in voicewire.go, but this is not
// a broken file. It is a working file in the wrong role, and a daemon that
// cannot route well should say so rather than answer worse.
//
// Cleaned and made absolute first, so "./m.onnx" and "$PWD/m.onnx" are one
// path. Then SameFile, which catches the copy that is a symlink or a hard link
// to the original. A path that does not stat is left to the loader, which fails
// on it with a better message than this can give.
func (e *EmbedderConfig) checkHeadsDistinct() error {
if e.HeadsPath == "" || e.ModelPath == "" {
return nil
}
heads, model := absClean(e.HeadsPath), absClean(e.ModelPath)
same := heads == model
if !same {
hi, herr := os.Stat(heads)
mi, merr := os.Stat(model)
same = herr == nil && merr == nil && os.SameFile(hi, mi)
}
if same {
return fmt.Errorf("voice.embedder: heads_path and model_path are the same file (%s) — the heads graph is a fine-tuned copy, and scoring recall with it degrades what the resident embedder already stored", heads)
}
return nil
}
// absClean — the comparable form of a path. Abs fails only when the working
// directory is unreadable, and a cleaned relative path is still worth comparing,
// so the error falls back rather than propagating.
func absClean(p string) string {
if abs, err := filepath.Abs(p); err == nil {
return abs
}
return filepath.Clean(p)
}
// VoiceConfig — the client↔core TCP surface + the stt/tts worker-module
// seams.
//
+70
View File
@@ -0,0 +1,70 @@
package config
import (
"os"
"path/filepath"
"strings"
"testing"
)
// The heads graph is a fine-tuned copy of the embedder, and pointing both keys
// at one file degrades recall with no error and no log line (V-692). These are
// the shapes that used to boot clean.
func TestHeadsPathMustNotBeTheModelFile(t *testing.T) {
dir := t.TempDir()
model := filepath.Join(dir, "model.onnx")
heads := filepath.Join(dir, "heads.onnx")
for _, p := range []string{model, heads} {
if err := os.WriteFile(p, []byte("onnx"), 0o600); err != nil {
t.Fatalf("write %s: %v", p, err)
}
}
link := filepath.Join(dir, "link.onnx")
if err := os.Symlink(model, link); err != nil {
t.Fatalf("symlink: %v", err)
}
// A path that stats and one that does not, because the guard compares the
// cleaned string before it stats anything.
for name, headsPath := range map[string]string{
"the same path": model,
"a symlink to it": link,
"an uncleaned path": filepath.Join(dir, ".", "sub", "..", "model.onnx"),
"a path on no disk": filepath.Join(dir, "absent.onnx"),
} {
t.Run(name, func(t *testing.T) {
same := headsPath != filepath.Join(dir, "absent.onnx")
err := voiceConfigWith(t, model, headsPath)
if same && err == nil {
t.Fatal("want a startup error, got a daemon that routes worse in silence")
}
if same && !strings.Contains(err.Error(), "heads_path") {
t.Fatalf("the error does not name the key: %v", err)
}
if !same && err != nil {
t.Fatalf("a distinct heads_path was refused: %v", err)
}
})
}
if err := voiceConfigWith(t, model, heads); err != nil {
t.Fatalf("two distinct files were refused: %v", err)
}
if err := voiceConfigWith(t, model, ""); err != nil {
t.Fatalf("no heads at all was refused: %v", err)
}
}
// voiceConfigWith loads a minimal enabled voice block through the real Load, so
// the test exercises the startup path and not just the check in isolation.
func voiceConfigWith(t *testing.T, model, heads string) error {
t.Helper()
body := `{"voice":{"enabled":true,"bind":"127.0.0.1:9100","embedder":{` +
`"model_path":"` + model + `","tokenizer_path":"/t.json","lib_path":"/l.so"`
if heads != "" {
body += `,"heads_path":"` + heads + `"`
}
body += `}}}`
_, err := Load(writeConfig(t, body))
return err
}
+5 -28
View File
@@ -255,35 +255,12 @@ func newBaselineClassifier(t *testing.T, emb router.Embedder) *router.Classifier
return cls
}
// baselineGrammars — the stage-0 rule set in the daemon's order (buildRouter in
// cmd/mavend/voicewire.go). Split out of newBaselineRouter so the claim
// measurement can run the same rules one at a time and see which of them
// contend for the same utterance, which the cascade hides by stopping at the
// first match.
// baselineGrammars — the stage 0 rule set the daemon runs, from the one place
// it is written down (V-693). It used to restate the list by hand, and by the
// time the guard was written the two had already drifted by one grammar.
// Kept as a name because the claim measurement reads it as "the baseline set".
func baselineGrammars(acts router.ActMatcher) []router.Grammar {
grammars := router.DefaultGrammars(acts)
grammars = append(grammars, router.SystemTimeDateGrammars()...)
// Same order as buildRouter (voicewire.go). The fixture is only worth
// anything while its grammar set is the daemon's grammar set.
grammars = append(grammars, router.AgendaQueryGrammars()...)
// After the agenda rules and before the feed and list rules, same as
// voicewire.go: "что такое лента" is a definition question and the feed
// rule would claim it on the noun alone (V-655). Missing here until V-659,
// so the fixture was scoring a grammar set the daemon does not run.
grammars = append(grammars, router.WorldQueryGrammars()...)
grammars = append(grammars, router.FeedQueryGrammar())
// The list side of the same exposure: a phrasing with no possessive in it
// ("список дел") routed system and never reached queryTasks (Vikunja #467).
grammars = append(grammars, router.TaskListGrammar())
grammars = append(grammars, router.ListGrammars()...)
grammars = append(grammars, router.ReminderGrammar())
grammars = append(grammars, router.PraxisGrammars()...)
grammars = append(grammars, router.TaskStatusGrammar())
grammars = append(grammars, router.TaskCaptureGrammar())
// "расскажи про X" is a world question the model called a fact, and the
// rule goes last because it matches on the first word alone (Vikunja #498).
grammars = append(grammars, router.NarrativeQueryGrammars()...)
return grammars
return router.StageZeroGrammars(acts)
}
// seedOrder — fixed iteration order over the corpus. Not cosmetic: a few
+65
View File
@@ -0,0 +1,65 @@
package router
// StageZeroGrammars — the stage 0 rule set, in the order the daemon runs it.
//
// It lives here because it used to live in two places (V-693). `buildRouter` in
// cmd/mavend/voicewire.go held the real set and `baselineGrammars` in
// internal/router/eval/eval_test.go restated it by hand, in the daemon's order,
// with its own comment saying so. Three test files score against the fixture,
// and nothing compared the two lists. By 2026-08-11 they had already drifted:
// BareCaptureGrammar was in the daemon and not in the fixture, so every routing
// measurement scored a set nobody ran. That is the failure CLAUDE.md warned
// about by name, and a diff test would have caught it one grammar late. One
// list cannot drift from itself.
//
// The order is the contract, not the membership. Each rule below says why it
// sits where it sits, and a rule inserted in the wrong place changes which
// utterances the cascade never reaches. Read the comment above a line before
// moving it, and read docs/routing.md before adding one.
//
// The classifier, the extractor, the threshold and the model arm are the
// daemon's to assemble. This function returns the rules and nothing else, so
// the fixture can also run them one at a time and see which of them contend for
// the same utterance, which the cascade hides by stopping at the first match.
func StageZeroGrammars(acts ActMatcher) []Grammar {
grammars := DefaultGrammars(acts)
grammars = append(grammars, SystemTimeDateGrammars()...)
// After the time/date rules on purpose: "какой сегодня день" is a clock
// question and must keep reaching replySystem, while "что у меня сегодня"
// is an agenda question and must not.
grammars = append(grammars, AgendaQueryGrammars()...)
// Same reason as the agenda rules, for the feeds: "что нового в лентах?"
// routed system and answered "пока не умею" (Vikunja #474).
// After the agenda rules, which are the narrower claim, and BEFORE the feed
// and list rules, which are not: "что такое лента" is a definition question
// and the feed rule would take it on the noun alone (V-655).
grammars = append(grammars, WorldQueryGrammars()...)
grammars = append(grammars, FeedQueryGrammar())
// The list side of the same exposure: a phrasing with no possessive in it
// ("список дел") routed system and never reached queryTasks (Vikunja #467).
grammars = append(grammars, TaskListGrammar())
grammars = append(grammars, ListGrammars()...)
grammars = append(grammars, ReminderGrammar())
// Before the capture marker, because "отметь" is a capture verb and "отметь
// второй пункт" is not a note. The Praxis rules are the narrower claim — a
// lifecycle verb AND an item named — so they get first refusal (Vikunja #516).
grammars = append(grammars, PraxisGrammars()...)
// After Praxis, whose bare "закрой" claim this rule cannot reach (it needs the
// board noun), and before the capture marker, which would otherwise read
// "убери из задач купить молоко" as a new task (Vikunja #512).
grammars = append(grammars, TaskStatusGrammar())
// Before the capture markers, which all need an object. A capture verb
// alone is a fact with no key, and the clarify path asks for it rather than
// letting the model invent an answer (Vikunja #557).
grammars = append(grammars, BareCaptureGrammar()...)
// Last, and it matches any utterance shape — its Build is the filter. An
// explicit capture marker beats the model, which called it an act and
// rewrote the task text (Vikunja #467). After the rules above because a
// marker never collides with a clock or agenda question.
grammars = append(grammars, TaskCaptureGrammar())
// After the capture marker, so "запиши" still wins over "расскажи", and
// last overall because it matches on the first word alone: "расскажи про
// X" is a world question the model called a fact (Vikunja #498).
grammars = append(grammars, NarrativeQueryGrammars()...)
return grammars
}
+97
View File
@@ -0,0 +1,97 @@
#!/usr/bin/env bash
# analyzer-gate.sh — turn an analyzer's output into a pass/fail verdict.
#
# The 2026-08-10 audit asked for staticcheck, govulncheck and deadcode
# (V-694). govulncheck needed no gate of this shape because it already
# reported zero after the toolchain bump. The other two do not: staticcheck
# reports 20 findings today and deadcode reports 11 unreachable symbols, and
# three of those eleven are deliberate. A target that fails on the first run
# is not a gate, it is a target nobody runs. So the accepted set is written
# down, and only what is NOT in it fails.
#
# staticcheck ./... | scripts/analyzer-gate.sh staticcheck
# deadcode -test ./... | scripts/analyzer-gate.sh deadcode
#
# The baseline is keyed on file, check id and message, never on line number.
# A key carrying a line number goes stale on the next edit above it and then
# reports moved findings as new ones, which trains the reader to ignore it.
# The cost of dropping the line is that two identical findings in one file
# share one key, so the second is accepted with the first. That is the right
# way round: the same check firing twice on the same file is one thing to fix.
#
# A baseline entry with no finding left also fails. Fixing something and
# leaving its entry behind is how the accepted set stops describing the repo.
# The fix is one line: delete the entry the failure names.
#
# Reads stdin, writes a report, never writes a file.
set -uo pipefail
cd "$(dirname "$0")/.." || exit 1
tool="${1:?usage: analyzer-gate.sh <staticcheck|deadcode>}"
baseline="scripts/analyzers/$tool.baseline"
[ -f "$baseline" ] || { printf 'analyzer-gate: no baseline at %s\n' "$baseline" >&2; exit 2; }
# Normalise to "<file>\t<id>\t<message>". Anything that does not parse is an
# analyzer error, not a finding, and it fails without consulting the baseline.
# staticcheck: path.go:12:34: message (SA1234)
# deadcode: path.go:12:34: unreachable func: Symbol
found=$(mktemp) || exit 2
malformed=$(mktemp) || exit 2
trap 'rm -f "$found" "$malformed"' EXIT
while IFS= read -r line; do
[ -n "$line" ] || continue
case "$tool" in
staticcheck)
if [[ "$line" =~ ^([^:]+):[0-9]+:[0-9]+:\ (.*)\ \(([A-Z]+[0-9]+)\)$ ]]; then
# SA1019 ends its message with a space. Trim, so no baseline entry
# depends on trailing whitespace surviving an editor.
msg="${BASH_REMATCH[2]}"
printf '%s\t%s\t%s\n' "${BASH_REMATCH[1]}" "${BASH_REMATCH[3]}" "${msg%"${msg##*[![:space:]]}"}" >>"$found"
else
printf '%s\n' "$line" >>"$malformed"
fi
;;
deadcode)
if [[ "$line" =~ ^([^:]+):[0-9]+:[0-9]+:\ unreachable\ func:\ (.*)$ ]]; then
printf '%s\tunreachable\t%s\n' "${BASH_REMATCH[1]}" "${BASH_REMATCH[2]}" >>"$found"
else
printf '%s\n' "$line" >>"$malformed"
fi
;;
*) printf 'analyzer-gate: unknown tool %s\n' "$tool" >&2; exit 2 ;;
esac
done
if [ -s "$malformed" ]; then
printf '%s: the analyzer said something that is not a finding:\n' "$tool" >&2
sed 's/^/ /' "$malformed" >&2
exit 1
fi
accepted=$(mktemp) || exit 2
trap 'rm -f "$found" "$malformed" "$accepted"' EXIT
grep -v '^[[:space:]]*\(#\|$\)' "$baseline" | sort -u >"$accepted"
sort -u "$found" -o "$found"
new=$(comm -23 "$found" "$accepted")
gone=$(comm -13 "$found" "$accepted")
status=0
if [ -n "$new" ]; then
printf '%s: %d finding(s) not in %s:\n' "$tool" "$(printf '%s\n' "$new" | wc -l)" "$baseline"
printf '%s\n' "$new" | sed 's/^/ /'
printf 'Fix it, or add the line to the baseline with the reason it stays.\n'
status=1
fi
if [ -n "$gone" ]; then
printf '%s: %d baseline entry/entries no longer found:\n' "$tool" "$(printf '%s\n' "$gone" | wc -l)"
printf '%s\n' "$gone" | sed 's/^/ /'
printf 'Delete them from %s.\n' "$baseline"
status=1
fi
[ "$status" -eq 0 ] && printf '%s: clean against %d accepted finding(s)\n' "$tool" "$(wc -l <"$accepted")"
exit "$status"
+32
View File
@@ -0,0 +1,32 @@
# deadcode — the unreachable symbols this repo accepts today.
#
# Keyed "<file>\t unreachable \t<symbol>", tab separated, no line numbers.
# Generated from the first gated run on 2026-08-11 and edited by hand since.
# `make deadcode` fails on anything absent here and on any entry left behind
# after its symbol is deleted.
#
# The gate runs with -test, so a test file counts as a root. Without it the
# whole of internal/router/eval is unreachable and the report is 172 lines of
# fixtures nobody wrote by mistake.
#
# Eleven of these are V-686, from the 2026-08-10 audit. Three of the eleven
# must stay and the audit says why: HisGender is a documented seam tied to
# V-399, AudioDuration should call internal/audio rather than be deleted, and
# CountWord is a safe delete. Read docs/caveats/layering.md#deadcode before
# removing any of them.
cmd/mavwaked/vad.go unreachable AudioDuration
cmd/mavwaked/vad.go unreachable PCMToF32
internal/crawl/watch.go unreachable Watcher.Watches
internal/phraser/confirm.go unreachable IsC
internal/phraser/eval/checks.go unreachable HisGender
internal/phraser/plural.go unreachable CountWord
internal/update/update.go unreachable WithClock
internal/voice/errors.go unreachable jsonMarshal
internal/voice/errors.go unreachable jsonUnmarshal
internal/webauthn/cbor.go unreachable cborValue.At
internal/worker/server.go unreachable Server.SetSynthesizer
# Two test helpers the audit did not count, because it listed production
# symbols only. A helper no test calls is dead the same way.
cmd/mavend/replier_llm_test.go unreachable assertStub
cmd/mavwaked/vad_test.go unreachable frameRMSQuick
+46
View File
@@ -0,0 +1,46 @@
# staticcheck — the findings this repo accepts today.
#
# Keyed "<file>\t<check>\t<message>", tab separated, no line numbers.
# Generated from the first gated run on 2026-08-11 and edited by hand since.
# `make lint` fails on anything absent here and on any entry left behind after
# its finding is fixed, so emptying this file is done one line at a time.
#
# The sweep that empties it is V-701, which carries the judgement on each
# entry. What follows is the short reason only.
# V-687. The dedupe check runs after the phraser has already been paid.
cmd/mavend/tick_digest.go SA4006 this value of deduped is never used
# V-686, the eleven unreachable symbols the 2026-08-10 audit listed, seen from
# the other side. Three of them must stay: docs/caveats/layering.md#deadcode.
cmd/mavend/replier_llm_test.go U1000 func assertStub is unused
cmd/mavwaked/vad_test.go U1000 func frameRMSQuick is unused
cmd/mavweb/handlers_test.go U1000 field signalErr is unused
internal/voice/errors.go U1000 func jsonMarshal is unused
internal/voice/errors.go U1000 func jsonUnmarshal is unused
# False positives, checked. The code is right and the check cannot see why.
# RenderICal is called twice because rendering twice is the assertion. The
# morning loop reads the first rune after the hedge and breaks on purpose. The
# task_phrases line is prose about //go:embed and the real directive is below it.
internal/calendar/ical_render_test.go SA4000 identical expressions on the left and right side of the '!=' operator
internal/morning/plan_test.go SA4004 the surrounding loop is unconditionally terminated
internal/router/task_phrases.go SA9009 ineffectual compiler directive due to extraneous space: "// go:embed, so the single-binary deploy is unchanged: the JSON is compiled into"
# At EOF the wake loop trims partial and returns, so audio past one frame is
# dropped. Harmless where it sits, misleading to read. V-701.
cmd/mavwaked/main.go SA4006 this value of partial is never used
# Cosmetic and mechanical. V-701 sweeps them.
cmd/mavweb/voiceproxy.go ST1013 should use constant http.StatusMethodNotAllowed instead of numeric literal 405
cmd/mavweb/voiceproxy.go ST1013 should use constant http.StatusServiceUnavailable instead of numeric literal 503
internal/ipc/client.go S1016 should convert r (type chatResp) to ChatReply instead of using struct literal
internal/ipc/server.go S1016 should convert reply (type ChatReply) to chatResp instead of using struct literal
internal/memory/behavior_test.go S1011 should replace loop with obs = append(obs, habitHistory("calendar_event_20260804_standup", time.Tuesday, 10, 0, 3, now)...)
internal/memory/behavior_test.go S1011 should replace loop with obs = append(obs, habitHistory("cooldown:water", time.Tuesday, 9, 0, 3, now)...)
cmd/mavend/continuation_test.go SA1012 do not pass a nil Context, even if a function permits it; pass context.TODO if you are unsure about which Context to use
# Deprecated since Go 1.25. Replacing it means rewriting both guards on
# golang.org/x/tools/go/packages, which is a decision and not a sweep.
internal/ipc/maperr_test.go SA1019 parser.ParseDir has been deprecated since Go 1.25 and an alternative has been available since Go 1.11: ParseDir does not consider build tags when associating files with packages. For precise information about the relationship between packages and files, use golang.org/x/tools/go/packages, which can also optionally parse and type-check the files too.
internal/phraser/persona_floor_test.go SA1019 parser.ParseDir has been deprecated since Go 1.25 and an alternative has been available since Go 1.11: ParseDir does not consider build tags when associating files with packages. For precise information about the relationship between packages and files, use golang.org/x/tools/go/packages, which can also optionally parse and type-check the files too.