mirror of
https://github.com/ruvnet/RuView
synced 2026-07-20 17:03:24 +00:00
e6f26e9ac9
* docs(adr): deep review of the RuView npm surface — ADR-263/264/265 optimization strategies
ADR-263 — @ruvnet/ruview@0.1.0 harness review (O1–O9):
- HIGH: claim-check CLI fails open on empty input (no --text/--file -> PASS exit 0)
- HIGH: MCP stdio server head-of-line blocking (spawnSync verify/calibrate up to 600s)
- MEASURED: optionalDependencies triple the cold npx install (4 pkgs/620kB/71 files
vs 1 pkg/172kB/22 files with --omit=optional) for a path that never imports them
- maxBuffer truncation, python -c port interpolation, version drift, duplicate skills,
guardrail METRIC_TERMS substring false positives ('map'/'F1' — found by dogfooding
claim-check on these very ADRs), zero CI
ADR-264 — @ruvnet/rvagent@0.1.0 + @ruv/ruview-cli review (O1–O9), verified against
the published registry tarball:
- HIGH: exports.require -> dist/index.cjs which is never built nor published
- MEASURED: 44 dead source-map files = 62,698B of the 188kB unpacked payload
- stdio-only server described as dual-transport; mixed dot/underscore tool names;
double Zod validation + hand-duplicated advertised schemas; 2-fd leak per training
job; unbounded body in the unwired HTTP scaffold; dead detectCogBinary candidates;
ruview bin-name collision
ADR-265 — cross-cutting npm distribution strategy: npm-packages.yml CI matrix
(test + pack-content/size gate + tarball-install smoke test), publish-from-CI-only
with npm provenance, version single-sourcing from package.json, bin/namespace
ownership (ruview bin belongs to @ruvnet/ruview), claim-check on package READMEs.
Docs only — no runtime code changed. Index/CHANGELOG/CLAUDE.md/README counts updated.
Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01WrGfTGKv1oWZ6iwXZACULz
* fix(npm): implement ADR-263/264/265 — harness fail-closed + async MCP, rvagent packaging/transport/naming, npm CI+provenance gate
ADR-263 (@ruvnet/ruview 0.2.0), O1-O9:
- claim-check fails closed on empty input (CLI exit 2, empty_text tool error)
- MCP stdio server dispatches tools/call asynchronously (promise-based spawn);
ping answers while a 3s fake verify runs — pinned by new e2e test
- optionalDependencies dropped: cold npx installs exactly 1 package
(MEASURED: was 4 pkgs/620kB/71 files via npm i in a clean prefix)
- bounded rolling output tails replace spawnSync 1MiB maxBuffer
- node_monitor port passed via sys.argv, never spliced into python -c source
- serverInfo.version read from package.json; resources/prompts stubs
- skills single-sourced: prepack sync script generates .claude/skills/ copies
- which() = memoized dep-free PATH scan
- tools underscore-canonical (ruview_claim_check, ...) + dotted aliases
- guardrail precision: word-boundary map/f1/auc/iou, code-span + F1/O2 label
scrubbing, quantitative-claims-only; packaging reproducer hints
- 30/30 tests (was 17), incl. concurrency e2e + fail-open regression pins
ADR-264 (@ruvnet/rvagent 0.2.0), O1-O9:
- exports fixed: types-first, phantom dist/index.cjs require target removed
- tarball map-free: 127,704B unpacked / 46 files / 0 maps (MEASURED,
npm pack --dry-run; was 188kB incl. 44 maps referencing unshipped src)
- Streamable HTTP actually wired behind RVAGENT_HTTP_PORT: one transport +
one MCP server per session (mcp-session-id routing), 1MiB body cap (413),
port-aware localhost origin gate; dual-transport description now true
- tools renamed underscore-canonical with dotted router-only aliases
- single Zod validation gate; advertised inputSchema generated from the same
Zod source (zod-to-json-schema)
- train_count: parent log fds closed (was leaking 2/job); job records
persisted to <jobsDir>/<id>.json (job_status survives restarts); bounded
log-tail reads
- detectCogBinary probes its candidates instead of dead-coding them
- version from package.json; @types/express dropped; @types/jest -> 29
- README rewritten to match reality (no phantom subcommands/policy layer)
- 99/99 jest tests (incl. new session/body-cap suite + previously-broken
manifest suite); stdio handshake + HTTP session flow smoke-tested live
ADR-265 D1-D4:
- .github/workflows/npm-packages.yml: 3-package x Node 20/22 gate — tests,
version-literal grep (D3), pack-content/size gate, tarball-install smoke
test (catches the ADR-264 F1 class), README claim-check (D4)
- .github/workflows/ruview-npm-release.yml: publish from CI only with
npm publish --provenance
- @ruv/ruview-cli bin renamed ruview-cli (ruview bin belongs to
@ruvnet/ruview); version single-sourced
- ci.yml NODE_VERSION 18 -> 20
ADR statuses updated to Accepted/implemented; harness manifest re-pinned;
ADR-263/264/265 + both package READMEs pass claim-check.
Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01WrGfTGKv1oWZ6iwXZACULz
* perf(rvagent): lazy-load HTTP transport + memoize generated tool schemas
stdio time-to-first-response ~242ms -> ~189ms (-22%; MEASURED, median of
repeated initialize round-trips against dist/index.js in this container).
- ./http-transport.js now imported lazily inside the RVAGENT_HTTP_PORT
branch: it chain-loads the MCP SDK streamableHttp module (~48ms MEASURED
via per-module import() timing) which the default stdio path never uses
- toolInputJsonSchema memoized per tool: schemas are static for the process
lifetime; under the session-per-server HTTP model every session calls
tools/list, so stop re-walking the Zod tree each time
No behavior change: 99/99 jest tests; HTTP session flow re-smoke-tested
through the lazy import path (initialize -> 200 + mcp-session-id).
Profiled @ruvnet/ruview too and left it alone: 50ms CLI startup vs ~29ms
bare 'node -e ""' floor on the same box (MEASURED) — already near the
interpreter floor with zero dependencies.
Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01WrGfTGKv1oWZ6iwXZACULz
* ci(ruview-cli): pass jest --passWithNoTests so the private no-test package doesn't fail the npm-packages matrix
Co-Authored-By: claude-flow <ruv@ruv.net>
* fix(npm): address 10 verified review findings in harness + rvagent before 0.2.0 publish
harness/ruview (@ruvnet/ruview):
- guardrails: digit gate now sees numbers inside code spans; F1-style
metric tokens followed by ':' or a nearby number are no longer scrubbed
(fail-open regressions in the honesty gate)
- mcp-server: tools/call requests serialize through a FIFO promise chain
(hardware/mutating tools never overlap) while ping/tools/list stay
immediate; stdin close drains in-flight responses before exit
- tools: which() no longer memoizes negative lookups
tools/ruview-mcp (@ruvnet/rvagent):
- index: realpath invoked-directly guard — library import no longer
connects a stdio transport to the consumer's process
- http-transport: explicit allowedOrigins is exact-match only (localhost
any-port convenience applies only with no configured allowlist);
session map gains maxSessions=64 + 5min idle TTL sweep
- train-count: job records persist the child pid and reconcile stale
'running' status after a server restart (exit-code marker or dead pid)
- config: cog binary candidates ordered by process.arch
.github/workflows/ruview-npm-release.yml: port the full ADR-265 D1 gate
(version-literal check, unpacked-size budget, tarball-install smoke test)
from npm-packages.yml so the publish path enforces what the header claims.
Tests: harness 30→36, rvagent 99→112, all passing.
Co-Authored-By: claude-flow <ruv@ruv.net>
---------
Co-authored-by: Claude <noreply@anthropic.com>
87 lines
3.0 KiB
TypeScript
87 lines
3.0 KiB
TypeScript
/**
|
|
* Configuration loader for the RuView MCP server.
|
|
*
|
|
* All settings can be overridden via environment variables. No config file is
|
|
* required — the server is designed to work out of the box with a locally-running
|
|
* sensing-server on the default port.
|
|
*/
|
|
|
|
import os from "node:os";
|
|
import path from "node:path";
|
|
import { existsSync } from "node:fs";
|
|
import type { RuviewConfig } from "./types.js";
|
|
|
|
function env(key: string): string | undefined {
|
|
return process.env[key];
|
|
}
|
|
|
|
function envOrDefault(key: string, fallback: string): string {
|
|
return env(key) ?? fallback;
|
|
}
|
|
|
|
/**
|
|
* Load the effective RuviewConfig from environment variables.
|
|
*
|
|
* Environment variables:
|
|
* RUVIEW_SENSING_SERVER_URL — base URL of the sensing-server (default: http://localhost:3000)
|
|
* RUVIEW_API_TOKEN — Bearer token for /api/v1/* routes (no default; auth disabled when absent)
|
|
* RUVIEW_POSE_COG_BINARY — path to cog-pose-estimation binary
|
|
* RUVIEW_COUNT_COG_BINARY — path to cog-person-count binary
|
|
* RUVIEW_JOBS_DIR — directory for job logs (default: ~/.ruview/jobs)
|
|
*/
|
|
export function loadConfig(): RuviewConfig {
|
|
return {
|
|
sensingServerUrl: envOrDefault(
|
|
"RUVIEW_SENSING_SERVER_URL",
|
|
"http://localhost:3000"
|
|
),
|
|
apiToken: env("RUVIEW_API_TOKEN"),
|
|
poseCogBinary: envOrDefault(
|
|
"RUVIEW_POSE_COG_BINARY",
|
|
detectCogBinary("cog-pose-estimation")
|
|
),
|
|
countCogBinary: envOrDefault(
|
|
"RUVIEW_COUNT_COG_BINARY",
|
|
detectCogBinary("cog-person-count")
|
|
),
|
|
jobsDir: envOrDefault(
|
|
"RUVIEW_JOBS_DIR",
|
|
path.join(os.homedir(), ".ruview", "jobs")
|
|
),
|
|
};
|
|
}
|
|
|
|
/**
|
|
* Ordered cog-binary candidate paths for a host of the given CPU architecture.
|
|
* The native-arch build is probed FIRST: an appliance that ships both
|
|
* `cog-<id>-arm` and `cog-<id>-x86_64` must never hand back the wrong-arch
|
|
* binary (ADR-264 F8/O7 — the pre-review order tried `-arm` unconditionally).
|
|
* The `/usr/local/bin` and bare-name (PATH) fallbacks follow, arch-agnostic.
|
|
*
|
|
* Pure and arch-injectable so the ordering is unit-testable.
|
|
*/
|
|
export function cogBinaryCandidates(
|
|
name: string,
|
|
arch: string = process.arch
|
|
): string[] {
|
|
const id = name.replace("cog-", "");
|
|
const dir = `/var/lib/cognitum/apps/${id}`;
|
|
const arm = `${dir}/cog-${id}-arm`;
|
|
const x86 = `${dir}/cog-${id}-x86_64`;
|
|
// arm64 → prefer -arm; everything else (notably x64) → prefer -x86_64.
|
|
const archOrdered = arch === "arm64" ? [arm, x86] : [x86, arm];
|
|
return [...archOrdered, `/usr/local/bin/${name}`];
|
|
}
|
|
|
|
/**
|
|
* Locate a cog binary in the common appliance install locations, probing each
|
|
* candidate in native-arch-first order. Falls back to the bare name (PATH
|
|
* resolution at spawn time) when no candidate exists.
|
|
*/
|
|
function detectCogBinary(name: string): string {
|
|
for (const candidate of cogBinaryCandidates(name)) {
|
|
if (existsSync(candidate)) return candidate;
|
|
}
|
|
return name; // bare name — rely on PATH; spawn fails gracefully if absent
|
|
}
|