Planens §3 sa at `ingest.materialize` er repoets ENE skrivepunkt på Door A, og det premisset ble felt av måling FØR bygging: `materialize` er en ren delegasjon til pinnet llm_ingestion_okf v0.3.2s `materialize_bundle`, som stager i minnet og utfører sin egen disk-fase. Det finnes ingen callback mellom de to, så en gate plassert der kunne bare kjørt ETTER at bytene landet — en opprydding, ikke en gate. Sømmen ble i stedet kopier bundelen → materialiser inn i kopien → skann det som ble generert → publiser eller forkast. Kopien er bærende, ikke bekvemmelighet: bibliotekets §3 eierskaps-skann, kollisjonsgaten mot kuratert innhold og §6 index-merge leser alle den EKSISTERENDE bundelen. Staging i tom katalog mister alle tre og publiserer en bundle uten kuraterte naboer — datatap forkledd som sikkerhetsfiks. De fire §4-beslutningene, tatt og målt: (1) ingen av guardens to preset — Origin.EXTERNAL/AUTOMATIC, fordi trust_for utleder policy fra origin alene og PRESET_USER_UPLOAD bærer en quarantine-semantikk Door A ikke har; (2) utfall per BUNDLE, diagnostikk per DOKUMENT — delvis publisering ville etterlatt bundle + index som svarer til intet manifest, men import_bundle itererer forbi første avvisning; (3) Report til log.md, aldri konsept-frontmatter, der fire golden-suiter pinner bytene; (4) mypy-override OG adapter, siden override alene gjør sømmen type-blind i stedet for type-sikker. `materialize` forblir ugatet med vilje — goldenene pinner den, og en kaller som vil ha gaten ber om den ved navn. Fem mutasjoner alle røde + grønn kontroll (hele suiten, ~120 s hver): detach gaten · la den fyre ETTER publisering · Origin.INTERNAL · tom staging-katalog · rapporter kun første avvisning. Målingen felte en VAKUØS test først: en hard injeksjon scorer fail_secure under BEGGE trust-tierene, så Origin.INTERNAL-mutasjonen lot alle tre avvisningstestene stå grønne — beslutning 1 så dekket ut uten å være testet. Båndet der tieren faktisk avgjør er høy-entropi-innhold (quarantine_review vs warn), og testen ble skrevet mot nøyaktig det før mutasjonen ble re-målt. Mutasjon 4 ble på sin side felt av KUN én test; 809 andre merket ikke at bundle-kopien forsvant. Laveste disposition er `warn`, ikke `allow` — `allow` finnes ikke i guarden. En gate skrevet mot == allow ville avvist hvert dokument som noensinne ingestes. Kriterium 5 står: demo-stdout er byte-identisk med tests/golden/demo-transcript.stdout, målt både i suiten og ved eksplisitt kjøring. shared/ er urørt. 801 -> 810 passed / 4 skipped. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DDu94KoyxAmhJsG2n63X8Q
97 lines
6.3 KiB
TOML
97 lines
6.3 KiB
TOML
[project]
|
||
name = "portfolio-optimiser"
|
||
version = "0.1.0"
|
||
description = "Generic framework on Microsoft Agent Framework for per-project cost-savings optimization"
|
||
readme = "README.md"
|
||
requires-python = ">=3.10"
|
||
dependencies = [
|
||
# MAF — GA-pakker, IKKE meta-pakken `agent-framework`. Metaen drar `agent-framework-core[all]`,
|
||
# og `[all]` trekker inn de fortsatt-beta integrasjonene (azure-ai-search/cosmos/ollama/…) som
|
||
# tvinger pre-releases og drar med en ALPHA pydantic. Offisiell guide: installer kun det du trenger.
|
||
# Beta-integrasjoner legges til per-fase (med snevert pre-release-scope) når de faktisk trengs.
|
||
"agent-framework-core>=1.9.0,<2", # kjerne (GA) — to-sidig pin (S2.5): major-bump krever re-verifisering av privat-API-premissene (test_maf_version_guard)
|
||
"agent-framework-foundry>=1.8.2", # Azure/Foundry-profil: FoundryChatClient (GA)
|
||
"azure-identity>=1.25", # S4.1: AzureFoundryBackend passes an explicit AzureCliCredential (Foundry requires it); already transitive via foundry — promoted to a declared direct dep (zero new install weight)
|
||
"agent-framework-openai>=1.8.2", # OpenAI + OpenAI-kompatible lokale endpoints (GA) → lokal profil
|
||
# Promotert dev→core i Fase 2 (MVP-runtime, ikke lenger spike-only):
|
||
"agent-framework-orchestrations>=1.0.0", # GA orchestration builders (GroupChat/Concurrent/Magentic); resolves med core 1.9.0
|
||
"pulp>=2.8", # deterministisk validator-solver; PuLP bundler CBC i wheelen (R2). Installert 3.3.2.
|
||
# PuLP 4.0 vil kreve `pip install pulp[cbc]` + COIN_CMD (Fase-migrasjonsnotat).
|
||
"mcp>=1.28.0", # tynn lokal-mappe MCP-server (Step 7) — GA (resolverte 1.28.0) per Step 1-beslutning
|
||
"anyio>=4.14", # kø-(z): ingest_mcp.py bruker anyio.fail_after direkte (MCP-timeout-stien); allerede transitiv via mcp — promotert til deklarert direkte dep (zero new install weight, resolverte 4.14.0)
|
||
"pydantic>=2.11,<3", # IR/validering (B1) — eksplisitt pin til STABIL 2.x, aldri alpha
|
||
# S3.1: brute-force cosine for the hybrid verdict retriever — MAF-free, offline (D-C).
|
||
# Upper bound is <2.3, NOT <3, and it is load-bearing twice over: numpy 2.3+ requires
|
||
# Python >=3.11 (2.4+ requires >=3.12), so a wider range silently contradicts this project's
|
||
# `requires-python = ">=3.10"`; and numpy 2.3+ stubs use PEP 695 `type` statements, which
|
||
# mypy refuses to parse under `python_version = 3.10` (python/mypy#18701) — breaking
|
||
# `uv run mypy src` outright. Raise both floors together or not at all.
|
||
"numpy>=2.0,<2.3",
|
||
"llm-ingestion-okf", # Door A ingest (§4–§6) — the shared implementation of shared/ingest-spec.md; zero runtime deps, MAF-free (D7)
|
||
"llm-ingestion-guard", # Door A content gate — scans materialized concepts before they reach the bundle; zero runtime deps, MAF-free (D7)
|
||
]
|
||
|
||
# Console entry points — the install surface a fresh clone gets from `uv sync` (P4 pkt. 5).
|
||
# Deliberately TWO, not five: `run` is the framework CLI (three documented modes) and `simulation`
|
||
# is the offline end-to-end proof the README points a newcomer at. `costsim` / `hitl` / `preflight`
|
||
# keep the `python -m` form — they are operator utilities, not the product's front door, and every
|
||
# name here is a name the freeze has to carry. Pinned by tests/test_console_entry_points.py.
|
||
[project.scripts]
|
||
portfolio-optimiser = "portfolio_optimiser.run:main"
|
||
portfolio-optimiser-demo = "portfolio_optimiser.simulation:main"
|
||
|
||
# Distribution channel for the shared ingest library (mirrors portfolio-optimiser-claude,
|
||
# verified in consumer CI): git pin against the public Forgejo repo — reproducible for every
|
||
# consumer, uv.lock pins the exact commit behind the tag. Bump the rev on a new library tag.
|
||
[tool.uv.sources]
|
||
llm-ingestion-okf = { git = "https://git.fromaitochitta.com/open/llm-ingestion-okf.git", rev = "v0.3.2" }
|
||
# Pinned to a TAG, never a floating ref — a security component whose version can move under a
|
||
# `uv sync` is a gate that can stop gating without a local diff (the okf `generated`-literal
|
||
# lesson, measured 2026-08-09). Bumping this is a decision, not maintenance.
|
||
llm-ingestion-guard = { git = "https://git.fromaitochitta.com/open/llm-ingestion-pipeline-security.git", rev = "v0.3.4" }
|
||
|
||
# Dev tooling as a PEP 735 dependency-group (uv includes it by default in `uv sync`/`uv run`),
|
||
# so the documented bare `uv sync` + `uv run pytest` workflow installs it without `--extra`.
|
||
#
|
||
# INTENTIONAL, RECORDED DEVIATION (Fase 2 review F4): the original plan Step 1 authorized only
|
||
# moving `agent-framework-orchestrations` + `pulp` from the dev extra into core. Migrating the
|
||
# dev group from `[project.optional-dependencies]` to this PEP 735 `[dependency-groups]` block
|
||
# went beyond that stated scope, but is KEPT (not reverted) because it is what makes the brief's
|
||
# Success Criterion SC1 ("bare `uv sync` + `uv run pytest`") install dev tooling without
|
||
# `--extra` — reverting would break SC1. Logged here so the deviation is no longer silent.
|
||
[dependency-groups]
|
||
dev = [
|
||
"pytest>=8",
|
||
"ruff>=0.6",
|
||
"mypy>=1.11",
|
||
"pytest-asyncio>=0.24", # MAF orchestrations are async (await workflow.run(...)) — test-only
|
||
]
|
||
|
||
[build-system]
|
||
requires = ["hatchling"]
|
||
build-backend = "hatchling.build"
|
||
|
||
[tool.hatch.build.targets.wheel]
|
||
packages = ["src/portfolio_optimiser"]
|
||
|
||
[tool.ruff]
|
||
line-length = 100
|
||
src = ["src", "tests", "spikes"]
|
||
|
||
[tool.pytest.ini_options]
|
||
pythonpath = ["src", "."]
|
||
testpaths = ["tests"]
|
||
asyncio_mode = "auto"
|
||
|
||
[tool.mypy]
|
||
python_version = "3.10"
|
||
|
||
# Third-party libs without bundled type stubs (py.typed) — analysed as untyped, not errors.
|
||
[[tool.mypy.overrides]]
|
||
module = ["pulp.*", "agent_framework_foundry.*", "llm_ingestion_guard.*"]
|
||
ignore_missing_imports = true
|
||
# NOTE on `llm_ingestion_guard`: the override alone would make the seam type-BLIND, not
|
||
# type-safe — every symbol arrives as `Any`, so a field rename upstream would type-check
|
||
# happily and fail at runtime. `ingest.materialize_gated` therefore coerces each value it
|
||
# reads off the guard's result objects to a concrete type at the boundary (the okf precedent),
|
||
# and the seam's behaviour is pinned by tests/test_ingest_content_gate_loadbearing.py.
|