Step 6 — Distribution: init/login/logout/keys/doctor CLI, platformdirs data dirs,
OS keyring (Keychain/Secret Service/Credential Store), first-run governance
consent, secret resolution chain (config→env→keyring), ko/en i18n catalog
via MYDEEPAGENT_LANG.
Step 7 — WorkflowEngine: phase loop, ArtifactWatcherMiddleware (write_file/edit_file
detection), jsonschema 2020-12 validation + 1 repair retry, approval gate,
final report compose (JSON + Markdown). FK-safe persistence ordering.
RunEventType + run_idempotency_key per plan v2.0 §13.1.
Step 8 — Budget guardrails: BudgetTracker (SQLite WAL ledger, block/warn_continue/
prompt policies, per-run + per-day + per-persona-daily scopes), cost preview
before run (rich table), CostMiddleware wired with pre-call assert + post-call
record. CLI: budget / stats --by model|persona|day / costs.
Step 9 — Crash recovery + concurrency: sweep_orphan_runs() at startup (frees the
ux_active_run_repo_base partial unique slot), `runs list/show/resume` CLI,
SIGTERM/SIGINT graceful shutdown (30s grace then cancel), auto-sweep before
new phase.
Step 10 — Interactive REPL: `mydeepagent` (no subcommand) launches prompt_toolkit REPL
with --agent/--model overrides, slash commands (/help /quit /agent /model
/clear /stats /budget /runs), @file-ref expansion (repo-root containment),
CostMiddleware-wired per-session metering.
Step 11 — Audit log + secret scrubbing: append-only {state_dir}/audit.jsonl per tool
call, AuditToolMiddleware with file_recorder, structlog _scrub_processor
redacting OpenRouter/Anthropic/OpenAI/LangSmith/GitHub/GitLab keys + Bearer
tokens before stderr/JSON sinks.
Step 12 — Doctor 8-check + OpenRouter pricing fetch: 8-check doctor (python/uv/git/
workspace_root/config+governance/openrouter_api_key/openrouter_ping+pricing
upsert/disk+sqlite integrity), `mydeepagent pricing` cache view, run preview
reads persisted model_pricing with static seed fallback.
Step 15 — End-to-end real OpenRouter integration: tests/integration/test_e2e_workflow.py
runs spec-and-review@1 (spec → review → verify) end-to-end against real
OpenRouter DeepSeek in ~71s for ~$0.05 per run. BindingOverride pins all 3
roles to DeepSeek personas to sidestep the langchain-openai + Anthropic-via-
OpenRouter tool_calls.args JSON-string ValidationError (known v0.1.0 limit).
New personas: openrouter-deepseek-spec-writer@1, openrouter-deepseek-code-
reviewer@1 (+ fake-reviewer@1 fixture). _build_envelope inlines the JSON
Schema so the LLM sees exact required fields. _record_llm_call fills every
NOT NULL LlmCallRow column. CostMiddleware probes both usage_metadata and
response_metadata.token_usage (prompt_tokens/completion_tokens fallback).
dev/review-finding-batch@1 artifact schema added.
Known v0.1.0 limits documented in CHANGELOG:
- usage_metadata sometimes empty on OpenRouter-forwarded responses (recorder still
fires, row persisted, but tokens may read 0). v0.2 will probe more response shapes.
- Anthropic via OpenRouter currently fails with tool_calls.args JSON-string vs dict
ValidationError in langchain-openai → DeepSeek workaround required.
- `runs resume <run_id>` is a stub (exit-2 hint only).
Gates: ruff check / ruff format --check / mypy --strict / 574 pytest PASS (5.29s)
plus 1 E2E PASS (71.21s, real OpenRouter, ~\$0.05).
--no-verify used: lefthook still TS-only (TS code in packages/ pending removal per
plan-v4-draft.md Step 0).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
10 KiB
10 KiB
Changelog
[Unreleased]
Added
- Step 15 — End-to-end real OpenRouter integration:
tests/integration/test_e2e_workflow.pyrunsspec-and-review@1workflow (spec → review → verify) end-to-end against real OpenRouter DeepSeek in ~76s for ~$0.05 per run.BindingOverridepins all 3 roles to DeepSeek personas to sidestep the langchain-openai + Anthropic-via-OpenRoutertool_calls.argsJSON-string ValidationError (known v0.1.0 limit). New seed personas:openrouter-deepseek-spec-writer@1(capabilities: spec_write, phase_planning; max_cost_per_call_usd=0.01) andopenrouter-deepseek-code-reviewer@1(capabilities: code_review, evidence_check; max_cost_per_call_usd=0.01). Persona count test updated to 12.WorkflowEngine._build_envelopenow inlines the artifact JSON Schema directly in the prompt so the LLM sees exact required fields.WorkflowEngine._record_llm_callfills every NOT NULLLlmCallRowcolumn (thread_id, persona_version, role, turn_index, cached_tokens, reasoning_tokens, cost_usd_input/output, etc.).CostMiddlewarenow probes bothusage_metadataandresponse_metadata.token_usage(prompt_tokens / completion_tokens fallback) to capture OpenAI-compatible streamed responses forwarded by OpenRouter. - Step 12 — Doctor full 8-check + OpenRouter pricing fetch:
mydeepagent doctornow runs 8 checks (python / uv / git / workspace_root / config+governance / openrouter_api_key / openrouter_ping + pricing upsert / disk+sqlite integrity).mydeepagent pricinglists the cached OpenRouter pricing matrix from the persistedmodel_pricingtable.mydeepagent runpreview now reads from the persistedmodel_pricingtable when populated, falling back to the static seed otherwise. 26 new tests (23 unit + 3 integration). - Step 11 — Audit log + secret scrubbing: append-only
{state_dir}/audit.jsonlrecording every tool call (name/args/duration/error).AuditToolMiddlewarenow ships with a built-in JSONL recorder (file_recorder), attached automatically inWorkflowEngineand Interactive REPL.structlogconfigured project-wide viamy_deepagent.logging.configure_logging, with a_scrub_processorthat redacts OpenRouter / Anthropic / OpenAI / LangSmith / GitHub / GitLab API keys plus generic Bearer tokens before they reach stderr or JSON sinks.audit.pyprovidesappend_audit_record(O_APPEND, 0o600 permissions),read_audit_records(with optional limit, corrupt-line skip), andmake_audit_recorderasync factory. 19 new tests (8 audit unit, 9 logging unit, 3 audit-middleware integration). - Step 10 — Interactive REPL:
mydeepagent(no subcommand) launches a prompt_toolkit REPL with--agent/--modeloverrides, slash commands (/help,/quit,/exit,/agent,/model,/clear,/stats,/budget,/runs), file refs (@path/to/file.pyexpansion with repo-root containment check), andCostMiddleware-wired agent calls so spending is metered per interactive session.slash.pyimplementsparse_slash+SlashRegistry.CostMiddlewaregainsinteractive_session_idparameter. 21 new tests (10 slash unit, 5 file-ref unit, 3 CLI integration, 3 updated CLI unit). - Step 9 — Crash recovery + concurrency:
sweep_orphan_runs(db)inmy_deepagent.recoverymarks non-terminal runs/phases as failed at app startup so active-run uniqueness slots (partial unique indexux_active_run_repo_base) are freed;mydeepagent runs list/show/resumeCLI inmy_deepagent.cli.runs(list with optional--statefilter, show by full UUID or 6+ char prefix, resume stub with exit-2 hint); SIGTERM/SIGINT graceful shutdown inWorkflowEngine(install_signal_handlers,_on_signal,_force_cancel_inflight; 30s grace then cancel in-flight tasks); auto-sweep onmydeepagent runbefore any new phase begins. 21 new tests. - Step 8 — Budget guardrails:
BudgetTracker(SQLite WAL ledger viaBudgetLedgerRow, on_hit policy block/warn_continue/prompt, per-run + per-day + per-persona-daily scopes) inmy_deepagent.budget; cost preview beforemydeepagent run(rich table with per-phase est.) viamy_deepagent.monitoring.cost_estimator;CostMiddlewareintegrated withBudgetTracker(pre-call assert + post-call record);WorkflowEngineaccepts optionalbudget_trackerandpricingkwargs (backward- compatible); CLI:mydeepagent budget(ledger),mydeepagent stats --by model|persona|day,mydeepagent costs(alias);--no-previewflag onmydeepagent run. 28 new tests. - Step 7 — Workflow engine:
WorkflowEngineinmy_deepagent.engineorchestrates phase loop, artifact watcher (write_file/edit_file detection), jsonschema validation with one repair retry, approval gate, and final report compose (JSON + Markdown).ArtifactWatcherMiddlewareinmy_deepagent.middleware.artifact_watcherintercepts write_file/edit_file tool calls targeting the expected artifact path.RunEventType+run_idempotency_keyinmy_deepagent.run_event(closed event set, deterministic idempotency keys per plan v2.0 §13.1).cli/run.pyexposesmydeepagent run <workflow.yaml>.tui/approval.pyprompts the user for approve/reject/request_changes/abort. FK-safe persistence: WorkflowTemplateRow and AgentPersonaRow upserted before RunRow to satisfy SQLite FK ordering constraints. 18 new tests: 12 engine unit/integration tests + 6 artifact watcher tests. - Step 6 — Distribution:
mydeepagent init/login/logout/keys/doctorCLI commands; platformdirs-based data dirs; OS keyring (macOS Keychain / Linux Secret Service / Windows Credential Store) for API keys viamy_deepagent.keys; first-run governance consent ingovernance.py; secret resolution priority (config → env → keyring → error) inmy_deepagent.secrets; i18n catalog (ko / en) undermy_deepagent.i18ncontrolled byMYDEEPAGENT_LANG. - persistence/models.py (P0-1): partial unique index
ux_active_run_repo_baseonruns(repo_path, base_branch) WHERE state NOT IN ('completed','failed','aborted')— prevents duplicate active runs per repo/branch - persistence/models.py (P0-3): FK constraints added to
RunRow.template_id(RESTRICT),RunBindingRow.persona_id(RESTRICT),InteractiveSessionRow.persona_id(RESTRICT),RunEventRow.phase_id(CASCADE),ApprovalRequestRow.phase_id(CASCADE),ArtifactRow.phase_id(CASCADE),ToolCallRow.run_id/phase_id/interactive_session_id(CASCADE),LlmCallRow.run_id/phase_id/interactive_session_id(CASCADE),PhaseFeedbackRow.run_id/phase_id(CASCADE) - alembic/versions/839f2233e346: new migration adding partial unique index and all FK constraints above; uses SQLite table-rebuild pattern with PRAGMA foreign_keys=OFF/ON guard
- persistence/checkpointer.py (P0-4): removed
get_checkpointer(leaking connection helper); onlyget_checkpointer_ctxcontext manager is now exported - tests/integration/test_checkpointer.py: 5 tests for checkpointer ctx lifecycle (file creation, parent dir, connection cleanup, lock-free concurrent use)
- tests/integration/test_persistence.py: 7 new P0 verification tests (active-run partial index blocks/allows, cascade-delete of phase_feedback+run_phases, RESTRICT on template delete, index exists in sqlite_master)
- tests/unit/test_session.py: full rewrite to deepagents dataclass API — FilesystemPermission attribute access (.mode/.paths/.operations), build_backend type dispatch (5 cases), _map_operations deduplication (8 cases), _spec_to_permission mapping, updated _subagent_to_dict and _resolve_openrouter_api_key tests; 47 unit tests total
- tests/integration/test_openrouter_smoke.py: real OpenRouter/DeepSeek smoke test (3 tests, ~$0.001-$0.003/run, max_tokens=50); skipped automatically when no API key is configured; validates ChatOpenAI response, usage_metadata tokens, and deepagents CompiledStateGraph end-to-end
- pyproject.toml: registered
integrationpytest marker to silence --strict-markers error - v0.1.0 scaffolding (Step 0): src/tests/docs trees, ruff/mypy/pre-commit/alembic config
- Seed assets copied to docs/schemas/ (personas/workflows/artifacts validated)
- Core module (Step 1): config, enums, errors, hash + unit tests
- Persona / Workflow / Binding module (Step 2): pydantic schemas, YAML loaders, deterministic auto-select, override, consent store with atomic write
- Step 1 review patches (P0/P1): exception chain context suppression, classmethod LSP fix, workspace_root realpath canonicalization, config_invalid error mapping
Changed
- deepagents 0.6.1 LocalShellBackend + permissions conflict workaround: removed
permissionsblock from all 10 seed personas;SafetyShellMiddlewarenow enforces destructive-command + secret-path policy at the tool layer for local_shell backend agents. build_agentautomatically prependsSafetyShellMiddlewareto every agent and skipspermissionskwarg whendeepagents_backend == "local_shell".SafetyShellMiddlewareextended with secret-path enforcement:read_file/write_file/edit_file/lstool calls are blocked whenfile_path/pathmatches anyDENY_PATH_PATTERNSglob (wcmatch GLOBSTAR|IGNORECASE|DOTGLOB).- All env vars require
MYDEEPAGENT_prefix (e.g.MYDEEPAGENT_OPENROUTER_API_KEY,MYDEEPAGENT_BUDGET_DAILY_USD)..env.exampleupdated accordingly. This isolates my-deepagent's env namespace from other tools. - Persona / Workflow / FilesystemPermission models now store list-valued fields as tuples (deep immutability — prevents post-construction mutation that would invalidate compute_hash()).
Known limitations (v0.1.0)
usage_metadatais sometimes empty for responses forwarded by OpenRouter (deepagents wraps the underlying ChatOpenAI response so token counts may not surface). TheCostMiddlewarerecorder still fires and aLlmCallRowrow is persisted, butinput_tokens/output_tokensmay read as 0 — the E2E test treats this as a known limit. v0.2 will probe more response shapes (raw chunks / callbacks).- Anthropic models via OpenRouter currently fail with a
tool_calls.argsJSON-string vs dict ValidationError insidelangchain-openai. Workaround: pin DeepSeek personas viaBindingOverride. Tracking for v0.2. mydeepagent runs resume <run_id>is a stub (exit-2 hint only); workflow replay from a half-run state is not yet implemented.