### CHANGELOG # CHANGELOG Workspace lab notebook for long-running or resumable research work. Use this file to track chronology, not release notes. Keep entries short, factual, and operational. ### 2026-08-15 13:36 EDT — intake-sweep-0.3.23-post-release - Objective: Refresh the complete Feynman AI-researcher intake after the `0.3.23` release and persist the verified state. - Intake: Open issues and PRs are empty. The recent merged PR `#230` is released and verified. All 30 newest forks are behind `main` except `NioZow/feynman`, which is 1 commit ahead and 108 behind with only an old Nix packaging commit; no port target exists. - Upstream: Pi `0.84.2`, `pi-web-access` `0.23.0`, `pi-docparser` `4.0.0`, `pi-btw` `0.4.1`, and `pi-otel` `0.1.0` are current. `pi-subagents` `0.50.0` is current upstream, but its 391-commit `0.40.0...0.50.0` migration adds missions, schedules, workflows, FleetView, Herdr, worktrees, and administration rather than fixing a Feynman research defect; the bundled `0.40.0` remains the correct scoped choice. - Security and freshness: Dependabot and repository advisory queues are empty; code scanning has no analysis. Root and website production audits report zero vulnerabilities. `npm outdated` reports non-security upgrades for general dependencies only; no coordinated research-runtime update is required. - Verified: `784/784` tests, typecheck, build, architecture check, website lint/typecheck/build (`34` pages), root and website audits, diff check, dry and real packs, installed artifact verification, installed RPC/TypeBox/Copilot checks, and document parse/search/screenshot passed. The real pack is `114,755,952` bytes with `29,134` files and SHA-256 `95940c60ff9842b568b0c9b7af507081012353d7ad6fe54c53b567de05d0a1dd`. - State: `verified` and production-live on synchronized `main` `316e7a6`. The nested dirty `website` checkout and existing ignored research artifacts remain preserved and untouched. Next: refresh the queues on the next scheduled sweep. ### 2026-08-15 12:30 EDT — pi-copilot-rate-limit-0.3.23-final - Objective: Complete merge, publication, release identity, published-install, intake, and cleanup gates for Feynman `0.3.23`. - Delivery: PR `#230` passed run `31889957676` and merged as `413f37e17b3ceeb5037f029f34e86a1ce75741bd`. Publish run `31892303159` passed every package, consumer, native, npm, GitHub release, and published-state job. - Published proof: npm `0.3.23` is latest with integrity `sha512-3pk6i0K/c5aPxuRBDwthh+Vg6QQKi2HMVSjgNJB0QojPFyUuK6qcqF+dXxj2JxxemLW03LN8uJ+H/LZp0vFY8Q==`. Its verified SLSA provenance resolves to `413f37e`; a clean registry install passed audit, package verification, CLI smoke, Pi RPC, TypeBox, Copilot, and document parse/search/screenshot checks. - Release proof: GitHub `v0.3.23` and its tag target `413f37e`. All five native assets are valid archives, their downloaded SHA-256 values match `SHA256SUMS`, and all six downloaded files match GitHub's provider digests. - Live proof: Post-release run `31895320515` passed published npm installs on Linux, macOS, and Windows across Node `22`, `24`, and `25`; live model and researcher-child runs passed. The live native installers passed on Linux, macOS, and Windows. - Intake: Open issues and PRs are empty. All 30 recent forks were compared; only `NioZow/feynman` is ahead, by one old generic Nix packaging commit that remains rejected. Dependabot alerts and repository advisories are empty; code scanning has no analysis. Pi `0.84.2`, `pi-web-access@0.23.0`, and `pi-docparser@4.0.0` remain current; `pi-subagents@0.50.0` remains rejected for adjacent workflow scope. - Cleanup: Deleted the release branch, exact owned package, consumer, audit, home, upstream, release-download, and intake temporary paths. Daytona sandbox `0f5c5798-798a-4b71-aea4-b506b10cea9b` was deleted and now returns Not Found. Older user-owned sandboxes and the unrelated dirty nested website repository remain untouched. - State: `verified` and production-live. Next: start the next intake sweep from synchronized `main`. ### 2026-08-15 09:38 EDT — pi-copilot-rate-limit-0.3.23 - Objective: Port Pi's merged GitHub Copilot login fixes into the current `0.84.2` runtime and qualify Feynman `0.3.23`. - Intake: Open Feynman issues and pull requests remain empty. No issue or PR changed after the prior automation cutoff. The 30 newest forks are behind or equal to `main` except `NioZow/feynman`, whose old Nix packaging commit remains rejected. Security alert and advisory queues are empty. - Fixed: Applied upstream Pi commits `d5278ea` and `086c32e` to every root, nested, vendored, and agent-managed Pi AI runtime copy. Copilot policy updates now run sequentially, and model discovery honors `Retry-After` before one bounded retry. - Fixed: Consolidated embedded Pi AI target discovery after the first full test found `scripts/patch-embedded-pi.mjs` above the architecture limit. The script is now `1,170` lines without weakening the guard. - Verified: Focused patch tests passed (`9/9`), and the full suite passed (`784/784`). Typecheck, build, architecture, website lint/typecheck/build (`34` pages), root/website/runtime audits, package freshness review, and diff checks passed. The mocked Copilot login proved one active policy request and a successful second model request after `429`. - Package proof: Dry and real packs matched at `114,755,955` bytes and `29,134` files. The tarball SHA-256 is `0c7db229e9cd6d1ae45fd80319f0d82311196c3a77cb65c3d64fdc365ca78728`; clean source/runtime/consumer audits and package, stale-upgrade, 15-tool/9-command RPC, TypeBox, Copilot, and document parse/search/screenshot verifiers passed. - State: `unverified` for exact-commit Daytona, PR CI, merge, publication, and post-release identity. Next: finish those gates, then publish and verify `0.3.23`. ### 2026-08-15 06:32 EDT — intake-sweep-v0-3-22-daytona-proof - Objective: Complete clean-machine proof for the published Feynman `0.3.22` release and close the intake sweep. - Clean machine: The first 1 GB Daytona sandbox hit host exit `137` during package build. It was deleted. A replacement 4 GB sandbox checked out exact commit `586b7419d88e0cc95475eccff92e95b6b14f6ed2`, passed `783/783` tests, typecheck, build, architecture check, website lint/typecheck/build, root and website production audits, outdated review, and diff check, then remained clean. - Package proof: Dry and real `npm pack` passed with `29,134` files and `116,449,033` bytes. The real tarball SHA-256 is `f9d65a0b2d202bf6f65a75c1af33eaf06621d3695a7ccda0012086ff821824e7`. A clean consumer install passed audit, CLI version/help, package/search status, package-artifact verification, installed 15-tool/9-command RPC and TypeBox checks, and document parse/search/screenshot. - Intake and delivery: Live GitHub queues remain empty. The release commit remains `586b7419d88e0cc95475eccff92e95b6b14f6ed2`; `main` is now clean and synchronized at docs commit `35cf83c6cc96a7c55d152930b2d2f17ad41201be`. GitHub `v0.3.22`, npm `0.3.22`, publish runs `31860841967`, `31877648696`, `31878044250`, and main synchronization run `31879771165` remain successful. The replacement sandbox and prior failed sandbox were deleted; the two older user-owned sandboxes remain untouched. - State: `verified` and production-live. No code or dependency changes were made in this run. Next: start the next sweep from synchronized `main`. ### 2026-08-15 05:41 EDT — intake-sweep-v0-3-22-completion - Objective: Finish the `0.3.22` release receipts and refresh the full Feynman intake queue. - Intake: Open issues and pull requests are empty. The 30 newest forks are behind `main`; `NioZow/feynman` is 1 commit ahead but 102 behind with only Nix packaging files, so it is rejected. Issue `#217` is closed with the semantic-version security-floor fix in `v0.3.13`. Dependabot alerts and repository advisories are empty. `pi-subagents@0.50.0` is rejected: its upstream `v0.49.0...v0.50.0` diff changes 131 files for async missions, schedules, FleetView, Herdr, worktrees, administration, and related control-plane surfaces without fixing a current Feynman research defect. - Release: PR `#229` merged as `586b7419d88e0cc95475eccff92e95b6b14f6ed2`. Publish run `31860841967` passed source verification, all six Linux/macOS/Windows package consumers, five native bundles, npm publication, GitHub release creation, provenance, checksums, and published-state verification. GitHub `v0.3.22` targets `586b741`; npm `@companion-ai/feynman@0.3.22` is latest with integrity `sha512-yAJepY8ZGPF7ppNDB4pCEjIBkEbJOqvhwvnn1UDlL0iHC74Gcz/GUdR9AJ0iVAA5tRpLKz4z837HA8xplETgIQ==`. - Verified locally: `npm test` passed `783/783`; typecheck, build, architecture check, production audit, and diff check passed. Dry and real packs both report `114,751,448` bytes, `298,731,472` unpacked bytes, and `29,134` files. A clean installed tarball passed consumer audit, package-artifact verification, 15-tool/9-command RPC and TypeBox checks, and document parse/search/screenshot. A fresh registry install passed the same runtime/document gates and audit; npm provenance resolves to `586b741`. - State: `verified` and production-live. Post-release workflow `31877648696` passed all six published-package jobs, three native installer jobs, live model smokes, and researcher-child smokes. The nested dirty `website` repository remains unchanged and preserved. Next: keep `main` synchronized. ### 2026-08-14 22:25 EDT — intake-sweep-pi-0.84.2-web-0.23.0 - Objective: Adopt the current Pi and web research runtimes, reconcile the empty intake queues, and qualify Feynman `0.3.22`. - Intake: Open issues and PRs are empty. The 30 newest forks are behind `main`; `NioZow/feynman` is 1 commit ahead but 100 behind with only stale Nix packaging work, so it is rejected. Dependabot and published advisory counts are zero. Main workflow runs through `31706066442` are successful. npm and GitHub latest remain `0.3.21`. - Changed: Updated the coordinated Pi package train to `0.84.2`, `pi-web-access` to `0.23.0`, exact source fixtures and patch gates, runtime locks and archive, and `0.3.22` release docs. Updated installed TypeBox checks to match Pi `0.84.2`: optional non-nullable `null` values are omitted and malformed non-null values remain rejected. Repaired a stale packaged web verifier marker for the `0.23.0` registration layout. - Verified locally: Focused checks, full `npm test` (`783/783`), typecheck, build, architecture check, website lint/typecheck/build, root/site production audits, outdated review, diff check, package budget, package-artifact verification, clean installed tarball audit, installed 15-tool/9-command RPC and TypeBox checks, installed document parse/search/screenshot, and a live installed `openai/gpt-5.5` smoke returning `PONG` passed. Final pack is `114,751,448` bytes, `29,134` files; runtime SHA-256 is `e22e5661f4a8d4a65cb403bbbca20e2d03dbeb2843341232e42249e74944e306`. - State: `unverified` for the exact commit in Daytona, remote CI, merge, npm/GitHub/native publication, and post-release delivery proof. No GitHub or npm writes occurred. Existing nested dirty `website` work remains preserved. Next: commit the candidate, run and delete Daytona, then push the exact tested SHA and complete CI and release verification. ### 2026-08-13 07:21 CDT — liteparse-2.12.0-0.3.21-release - Objective: Complete the LiteParse `2.12.0` research-runtime intake through publication, delivery proof, and cleanup. - Persistence: PR `#228` exact head `c0b388c4eee1de9d6fcb84c55d4cabdcb8daaa24` passed run `31690228104` and merged as `186c226ecb4168c7fb5fb4026f99649be1920441`. - Clean-machine proof: Exact head passed the Daytona package, runtime, document, consumer, and release ladder in sandbox `73c70fbf-bc65-4f81-b0eb-7ccb80df5f70`; the sandbox was deleted and confirmed absent. - Delivery: Publish run `31693465638` passed source and package verification, six consumers, five native bundles, npm publication, GitHub release creation, provenance, checksums, and published-state verification. npm `@companion-ai/feynman@0.3.21` is latest with integrity `sha512-naoZamvsJRxzcjD0iaUyv3WykWmlSN0lMn7xSUkTJwRkUFad+t5JibP7qbmrOj8hZojI7Kw+FR8eWfilLX4yaQ==`, SHA-256 `3026f1111823a1406fccf432825758f738382d3c0b27776c004abbf63cbf3e60`, and provenance resolving to `186c226`. - Published proof: GitHub `v0.3.21` targets `186c226` and contains five native assets plus `SHA256SUMS`; all asset digests match the manifest. Post-release run `31698860122` passed all six published package installs, all three live native installers, model smokes, and researcher-child smokes on Linux, macOS, and Windows. - Intake and final state: Open issue and PR queues are empty. Dependabot and repository advisory queues are empty. Main is clean and synchronized. State: `verified` and production-live. Next: start the next sweep from clean synchronized `main`. ### 2026-08-12 08:55 CDT — managed-packages-current-date-0.3.20-release - Objective: Complete the managed-package reconciliation and current-date context intake through merge, publication, delivery proof, and cleanup. - Persistence: PR `#227` exact head `ba87fd7dca38717af0260280aa707be08a4c08b6` passed the release candidate, six Linux/macOS/Windows consumers, and Windows native installer checks, then merged as `33685eeea271a28b68f746f7687a31bbe9eb7293`. - Clean-machine proof: Exact head `ba87fd7` passed `783/783` tests, typecheck, build, architecture, website, audit, package, runtime, document, model, and researcher-child gates in Daytona. The sandbox was deleted and confirmed absent. - Delivery: Publish run `31597429220` passed source and package verification, six consumers, five native bundles, npm publication, GitHub release creation, provenance, checksums, and published-state verification. npm `@companion-ai/feynman@0.3.20` is latest with integrity `sha512-9atWIA/Jj1K5BRavBTu31mkXIEizU/6SgpWFzfZGXOOHwsQW/HT26GkQ0FTuP+B0wOhyDznNPDSXw/udV+RFfQ==`; the `122,787,315`-byte registry tarball has SHA-256 `6ff5e7ddd673b67a0771162ee5abe536ee27ecc14f34ead6f6952fd1d8fac7ca` and provenance resolving to the merge commit. - Published proof: GitHub `v0.3.20` targets `33685ee`; all five native asset digests match `SHA256SUMS`. Post-release run `31603093191` passed all six published package installs, all three live native installers, model smokes, and researcher-child smokes on Linux, macOS, and Windows. A fresh registry consumer passed audit, package, RPC, TypeBox, and document parse/search/screenshot checks. - Intake and final state: Open issue and PR queues are empty. All `1,019` forks added no current port target. `pi-subagents@0.47.1` remains rejected because its broad workflow, mission, scheduling, worktree, and administration scope replaces Feynman's focused task and chain surface without fixing a current research defect. State: `verified` and production-live. Next: start the next sweep from clean synchronized `main`. ### 2026-08-12 05:18 CDT — intake-sweep-managed-packages-current-date-0.3.20 - Objective: Repair stale Feynman-managed package trees and give current research turns an explicit local date. - Intake: Open issue and PR queues are empty. Current Pi, `pi-web-access`, `pi-docparser`, LiteParse, `pi-btw`, `pi-otel`, and alpha-hub releases remain adopted. `pi-subagents@0.47.1` remains rejected because its broad async workflow and administration scope does not fix this intake. Recent `TheTechOddBug`, `nagyist`, and `dubbypanda` forks match main; `sk-surya` is stale; `randomm` contributed only the current-date principle. - Changed: Managed historical package sources now reconcile to exact bundled presets before launch. Feynman removes stale managed shadow installs and seeds bundled packages without replacing custom selectors, filtered package objects, or optional packages. Parent and researcher-child turns receive the local current date through Pi's supported `before_agent_start` system-prompt result. - Verified locally: Adversarial review found and repaired degraded-runtime launch failure, stale usable prefix handling, custom-prefix preservation, and omitted historical pins. Focused tests passed `70/70`; the full suite passed `782/782`; typecheck, build, architecture, website lint/typecheck/build, production audits, and diff checks passed. Dry and real packs matched at `121,045,848` bytes and `40,224` files; local/global consumers, extracted-runtime audit, stale-upgrade, package, RPC, TypeBox, current-date, and docparser checks passed. A live `openai/gpt-5.5` probe returned `DATE=2026-08-12`. - State: `unverified` for exact-SHA Daytona, PR CI, merge, and `0.3.20` publication. Next: persist the candidate, pass clean-machine and CI gates, then publish and verify exact release identity. ### 2026-08-11 23:28 CDT — pi-web-access-0.22.0-and-feynman-0.3.19-release - Objective: Complete the `pi-web-access@0.22.0` research-runtime intake through merge, publication, delivery proof, and cleanup. - Persistence: PR `#226` candidate `be39b4859ffa57337c71733435bb607f5344ebbc` passed its source, package, six-consumer, and native checks, then merged as `fecb7faee6ebebafc71ee2f414573eae3c24a79e`. The release branch was removed from origin. - Clean-machine proof: The exact merged SHA passed the full validation ladder in the larger Daytona sandbox after the initial resource-pressure failure in the smaller sandbox. - Delivery: Publish run `31559441208` passed source verification, six package consumers, five native bundles, npm publication, GitHub release creation, provenance, checksums, and published-state verification. npm `@companion-ai/feynman@0.3.19` is latest with integrity `sha512-rQZgsi4kFewieuBgulJyJI7ECPbPaxBhjmJDjlSkf+aBGFEYkas4SAqWytIkPIfgU5fwwgcJMPpox3IW9BD/wg==`. GitHub `v0.3.19` targets `fecb7fa` and contains five native archives plus `SHA256SUMS`. - Published proof: Post-release run `31562633273` passed all six published global installs, all three native installers, and the model and researcher-child smokes, including `RESULT=PONG`. Open issue and PR queues remain empty; Dependabot alerts remain empty. - Cleanup: Deleted owned Daytona sandboxes `06f1ad9a-388e-4249-92d5-89266cd8a4ef` and `b18763b2-f19c-4155-b7d5-ca5ec4414dc0`, removed the generated runtime archive and `436` owned temporary directories, and confirmed no owned process remains. - State: `verified` and production-live. Successor release identity is verified on the completion commit; no fixable residual work remains. ### 2026-08-11 17:05 CDT — intake-sweep-pi-web-access-0.22.0 - Objective: Adopt the current web-research runtime without reopening adjacent package or control-plane scope. - Intake: Open issues and pull requests are empty. `dubbypanda/feynman` is the only fork changed since the prior sweep and matches main. Root and website production audits are clean. `pi-subagents@0.47.0` remains rejected because it replaces Feynman's task and chain contract with broader async workflow and mission surfaces without fixing a current defect. - Changed: Updated `pi-web-access` to `0.22.0`, adopted upstream fetched-content cache hardening, added Bocha search and configurable 30,000–200,000-character content slices, and preserved Feynman's exact config path, private cache, model scope, browser-cookie opt-in, raw-result default, and 90-second primary-search deadline. - State: `unverified` for cumulative tests, clean package consumers, Daytona, CI, merge, and release. Next: pass every source, website, package, runtime, clean-machine, CI, and publication gate for exact `0.3.19`. ### 2026-08-11 11:28 EDT — intake-sweep-windows-consumer-budget-0.3.18 - Objective: Resume the `0.3.18` publication after main run `31499996075` exhausted its Windows Node `25` consumer job budget. - Evidence: The first clean tarball install passed after `33` minutes. The second clean global install was still running when GitHub cancelled the job at `60` minutes. The same matrix completed in prior runs when both installs finished sooner. - Changed: Raised the PR and publish package-consumer job budgets from `60` to `90` minutes. All local/global install, audit, package, runtime, RPC, TypeBox, and document gates remain unchanged. - State: `unverified` for the successor PR and publish run. Next: pass focused and cumulative checks, merge exact green CI, then finish npm/GitHub/native publication and post-release proof. ### 2026-08-11 01:35 EDT — intake-sweep-web-cache-hardening-0.3.17 - Objective: Complete the post-`0.3.16` fetched-content reliability intake without broadening Feynman beyond the research loop. - Intake: Feynman has no open issue or PR. The refreshed `1,018`-fork snapshot has no push after the `0.3.16` merge. GitHub advisory and Dependabot queues are empty. The nested dirty website repository remains preserved at `67186845`. - Root causes: Short successful `fetch_content` results kept `responseId` only in hidden tool details, so a live model guessed `fetch_content` and `get_search_content` failed. The new external cache also lacked count and byte limits, stale temporary-file cleanup, permission repair, and symlink checks. - Changed: Every single-URL fetch now exposes its stored response ID in model-visible text. The exact-gated `pi-web-access@0.21.0` patch ports upstream PR `#241` at `b3e784f`, bounds cache use to 128 entries and 128 MiB, evicts oldest entries, normalizes POSIX permissions, rejects symlinks, writes through exclusive random temporary files, and treats concurrent missing prune targets as success. Exact-source hashes normalize Windows line endings. Cache-specific tests now live in a separate file instead of growing the general web patch suite beyond the architecture threshold. - Verified locally: Upstream PR `#241` passes `13/13` focused tests, `446/446` cumulative tests, typecheck, and runtime audit. Feynman passes `24/24` focused tests, `65/65` affected tests, `767/767` cumulative tests, typecheck, build, architecture, actionlint, website lint/typecheck/build, root/site/runtime/consumer audits, registry signatures, dry and real packs, package budget, local/global installed runtime and document checks, and a four-process cache stress. - Live proof: Installed `openai/gpt-5.5` saw response ID `mso97v8wmxdxvf`, reused that exact ID with `get_search_content`, and returned `WEB_CACHE_0317_OK mso97v8wmxdxvf`. The final cache used `0700` directory and `0600` file modes. - State: Candidate `0.3.17` is locally verified and uncommitted. Next: commit the exact candidate, prove it in Daytona and CI, then merge and verify npm, GitHub, native, provenance, and live research delivery. ### 2026-08-10 13:12 EDT — intake-sweep-deepseek-v4-pro-0.3.15-release - Objective: Carry the exact DeepSeek V4 Pro research-model correction through clean-machine proof, merge, publication, delivery checks, and cleanup. - Persistence: PR `#221` exact head `9debe8def114a3443bb6e7624cb35ded5e6596bb` passed run `31395933747` and merged as `4fc5a6874d91d1841069d1a4625cac3cb7a9b169`. The port keeps Pi's exact DeepSeek IDs and rejects the source fork's broad Pro bypass, provider scripts, duplicate parallel-search bundle, and stale agent changes. - Clean-machine proof: Exact merge `4fc5a687` passed focused `105/105`, cumulative `755/755`, typecheck, build, architecture, website lint/typecheck/build, audits, pack, clean consumer, stale-Pi, RPC/TypeBox, and document gates in Daytona sandbox `4c3e449a-f0c1-48de-a59a-7bf2c0419f90` on Node `25.9.0`. Its `122,765,124`-byte package had SHA-256 `cabdcac428a7ba32e11978f084991d3606eb5b018b72ce4b4bf72b603c2fc769`; the sandbox was deleted and confirmed absent. - Delivery: Publish run `31401997236` passed and released npm/GitHub `0.3.15` from the merge commit. The `122,765,082`-byte registry tarball has SHA-256 `28a5a854f4fcb3c955573c5dc78333e8dc2de8aa91cba766ac082fdd00c715f2`, integrity `sha512-nIfGSLzFqjimz2WZeLs3y4H2zozxE5XRn81GJuDs4j9Y5P2vnbEvnlWly3s/YQwsiuF1rTfYa/4ls231mztYSQ==`, and verified provenance resolving to `4fc5a687`. GitHub `v0.3.15` targets the same commit; all five native asset digests match `SHA256SUMS`. Production release docs and both live installers match source. - Published proof: A fresh registry consumer passed zero-vulnerability package, embedded-runtime, and extracted-runtime audits; `96` signatures with `192` attestations; package/runtime/stale-Pi/RPC/TypeBox/document gates; and exact default persistence. Its model list showed `nebius/deepseek-ai/DeepSeek-V4-Pro` as current and recommended, the removed environment bypass still rejected Gemini Pro, and a streamed prompt reached `/v1/chat/completions` with the exact DeepSeek ID and returned `DEEPSEEK_V4_PRO_OK`. - Final state: Canonical post-release run `31409934882` passed all six Linux/macOS/Windows Node `22`/`24`/`25` consumers and all three live native installers. Issue and PR queues are empty, security advisory queues are empty, and the unrelated nested website repository remains preserved. State: `verified` and production-live. Next: start the next sweep from clean synchronized `main`. ### 2026-08-10 09:35 EDT — intake-sweep-deepseek-v4-pro-0.3.15 - Objective: Port the valid research-model correction from `randomm/feynman` without importing its fork-only provider scripts, broad Pro bypass, or duplicate parallel-search surface. - Intake: Open issues and PRs are empty. All `1,017` forks were refreshed; only `nagyist/feynman` and `randomm/feynman` changed after the cutoff. `nagyist/main` has no commit ahead of upstream. `randomm/main` contributes the DeepSeek correction in `2fa0437`; its parallel-search and agent-discovery commits remain rejected because current `pi-web-access@0.20.0` already batches web queries, and removing bundled `pi-subagents@0.40.0` would remove Feynman's verified subagent runtime. - Changed: Exact DeepSeek V4 Pro IDs from Pi's direct, DeepSeek, Nebius, and Fireworks catalogs now pass the Pro-class cost guard. Premium service models such as Gemini Pro and `o1-pro` remain blocked. No `FEYNMAN_ALLOW_PRO_MODELS` or other broad bypass exists. Updated model listing, recommendation, explicit selection, default persistence and repair, CLI copy, command metadata, setup guidance, website documentation, release notes, and candidate version `0.3.15`. - Verified locally: Focused model and content coverage passed `105/105`; the cumulative suite passed `755/755`. Typecheck, build, architecture check, website lint/typecheck/build (`34` pages), root/site/runtime/consumer/extracted-runtime production audits, package freshness review, and `git diff --check` passed. Only existing dependency build warnings and recorded architecture debt remain. - Package proof: The rebuilt candidate contains `40,223` files, is `121,026,469` bytes compressed and `342,291,561` bytes unpacked, and has SHA-256 `91f55cfd83deb14cc917bed444750cdb5ff439e375be06cb93a2195ab7c66811`. A clean installed consumer passed package, stale-Pi, `9` RPC command, `15` tool/TypeBox schema, document parse/search/screenshot, and all runtime audits. - User path: An installed-package model list exposed `nebius/deepseek-ai/DeepSeek-V4-Pro` as current and recommended, `model set` persisted it, `FEYNMAN_ALLOW_PRO_MODELS=1` did not expose a premium Gemini model, and a mocked OpenAI-compatible prompt reached `/v1/chat/completions` with the exact DeepSeek model ID and returned `DEEPSEEK_V4_PRO_OK`. - State: `verified` locally and `unverified` for the exact commit in Daytona, PR CI, merge, and npm/GitHub/native publication. Next: commit with contributor attribution, prove the exact pushed SHA in Daytona and CI, then merge and verify every `0.3.15` delivery surface. ### 2026-08-10 09:13 EDT — intake-sweep-pi-web-access-0.20.0-release - Objective: Carry the verified `pi-web-access@0.20.0` research-runtime candidate through merge, publication, independent delivery proof, and cleanup. - Persistence: PR `#220` exact head `22fa33604307ec82dbd6ad41f563964c5ec1a4f0` passed run `31380143935`, including the release candidate, six Linux/macOS/Windows Node `22`/`24`/`25` consumers, and Windows PowerShell `5.1`/Core native installation. It merged as `3d59c3d7130d0e7ae87c09e61c3669977c8d1575`; origin now exposes only `main`. - Clean-machine proof: Exact head `22fa336` passed the complete source, website, package, runtime, document, model, DuckDuckGo, Datalab, and AlphaXiv ladder in Daytona sandbox `155e1fa0-5b19-4690-a7a0-81c101d8eedb`. The successful sandbox and low-memory diagnostic sandbox `f522149f-00dc-47d3-9765-e2b869c80b51` were deleted and confirmed absent. - Delivery: Main run `31383652197` passed source/package verification, all six package consumers, five native builds, npm publication, GitHub release creation, provenance, checksums, and published-state verification. npm `@companion-ai/feynman@0.3.14` is `latest`; its `122,764,823`-byte registry tarball is byte-identical to the CI artifact at SHA-256 `d3d7bee2579be5220f8ab0386710a033e2e1d608c61d05c575d4a97449bddc3c`, and its attestation resolves to the merge commit. GitHub `v0.3.14` targets the same commit with five nonempty native archives plus `SHA256SUMS`; every provider digest matches the manifest. - Published proof: A clean registry consumer passed zero-vulnerability audit, `96` package signatures with `192` attestations, package/runtime/RPC/TypeBox/document gates, two live domain-filtered arXiv results through DuckDuckGo, Datalab missing-key handling, `openai/gpt-5.5`, and the authenticated `36,090`-byte AlphaXiv paper question. Canonical post-release run `31390092634` passed all six published consumers and all three live native installers for exact version `0.3.14`. - Intake and preservation: The issue and PR queues are empty, all `1,017` forks added no port target, the release branch is deleted, and deployed release docs plus both live installers match source. Concurrent unrelated work on local branch `codex/non-premium-pro-models` remains untouched with its `12` dirty model/release paths. State: `verified` and production-live. Next: start the next sweep from synchronized `main` while preserving that separate work. ### 2026-08-10 05:21 EDT — intake-sweep-pi-web-access-0.20.0 - Objective: Refresh the complete maintainer intake and adopt only current package changes that improve Feynman's research retrieval, document extraction, or runtime reliability. - Intake: Open issues and PRs are empty. Origin exposes only `main`; all `1,017` forks were inspected, and none changed after the prior cutoff. No active workflow, Dependabot alert, or repository advisory exists. The unrelated nested dirty website repository remains preserved. - Changed: Updated bundled `pi-web-access` from `0.19.0` to `0.20.0`, retained Feynman's exact config path, project-local fetch cache, session model scope, browser-cookie opt-in, and search deadline patches, and added migration from the `0.3.13` package set. Added package gates for keyless DuckDuckGo search and optional Datalab PDF-to-Markdown extraction. Updated root and packaged runtime `ip-address` to `10.5.0` for graceful non-IPv6 parsing. Bumped the candidate and public release notes to `0.3.14`. - Source proof: Registry `pi-web-access@0.20.0` resolves to upstream commit `00b2271d0f1603ac780df3f324aed0fc92f3e849`, whose exact source passed `425/425` tests, typecheck, production audit, and package inspection. Registry `ip-address@10.5.0` resolves to `ef98e0a0e77fbef1fdf8bc3bd33288b00b3103c9`; upstream CI run `31359175734` passed. Kept `typebox@1.3.7` because the current `1.3.11` changes schema-engine semantics without a current defect, and kept `pi-subagents@0.40.0` because `0.45.2` still replaces Feynman's task/chain contract with broad async mission, schedule, Herdr, worktree, and administration surfaces. - Verified locally: Focused affected coverage passed `102/102`; all tests passed `751/751`. Typecheck, build, architecture check, website lint/typecheck/build (`34` pages), actionlint, root/site/runtime/consumer audits, registry signatures (`760` packages and `188` attestations), package freshness review, and `git diff --check` passed. The rebuilt runtime carries `pi-web-access@0.20.0` and `ip-address@10.5.0` with archive SHA-256 `f6b27fbdf1cf976fc7ec9c2970407e36dacb0e63f8d4cc2e7df2a825985ecc65`. - Package proof: Dry and real packs matched at `121,025,688` bytes, `342,289,989` unpacked bytes, and `40,223` files; the tarball SHA-256 is `6bfd9ef05ae1317a3e9158b526a22c873f0a87f810e5fe981371fc4e0f017a96`. Clean local and global installs passed package, stale-Pi, `9` RPC command, `15` tool/TypeBox schema, and document parse/search/screenshot gates. The installed runtime returned two live domain-filtered arXiv results through DuckDuckGo, rejected Datalab without a key, returned `INTAKE_0314_OK` from `openai/gpt-5.5`, and returned `36,090` bytes from the exact authenticated AlphaXiv paper question with empty stderr. - State: `verified` for source, local cumulative checks, packaging, installed runtime, and live research paths. Exact-commit Daytona, PR CI, merge, and npm/GitHub/native publication remain unverified. Next: commit the exact candidate, validate it in Daytona and CI, then merge and verify every `0.3.14` delivery surface. ### 2026-08-09 18:19 EDT — intake-sweep-nanoid-3.3.18-audit-repair - Objective: Refresh the complete maintainer intake and clear every current production audit finding without broadening Feynman's research scope. - Intake: Open issues and PRs were empty. All `1,016` forks were refreshed; `nagyist`, `pseudoctor`, and `TheTechOddBug` matched upstream, while `sk-surya` exposed only stale Dependabot branches `196` commits behind. Dependabot and repository-advisory queues were empty. Code scanning has no analysis, and secret scanning is disabled. - Root cause: Root and website locks still selected `nanoid@3.3.16`, affected by `GHSA-2v37-7h3g-55p8`. Upstream `3.3.17` repaired most zero-size loops, while `3.3.18` also repaired the omitted React Native async path. - Changed: Root and website overrides now require exact `nanoid@3.3.18`; both locks were refreshed, and the package security regression enforces the patched resolution. Kept `pi-subagents@0.40.0`; current `0.45.1` removes Feynman's task/chain contract and adds async missions, schedules, Herdr, worktrees, and administration without fixing a current defect. - Local and clean-machine proof: Focused regressions passed `15/15`; the cumulative suite passed `750/750`. Typecheck, build, architecture, website lint/typecheck/build, actionlint, root/site/runtime audits, registry signatures, dry and real pack, clean consumer/global installs, package/runtime/RPC/TypeBox checks, and document parse/search/screenshot passed. Exact head `ed067e14bb29e1aad88b81b59d563fa04f883e9c` passed the same ladder in Daytona on Node `25.9.0`; its `122,763,413`-byte tarball had SHA-256 `31dcd53fcb6147f0ab87b675531a6679287300f6291366b714448d76f331e683`. - Persistence: PR `#219` passed run `31336147879`, including all Linux/macOS/Windows Node `22`/`24`/`25` consumers and Windows PowerShell `5.1`/Core native installation. It merged as `c0231bf8edfda15d72e9cdd63c63ba9812a23c45`; the local and remote repair branches were deleted. - Release state: Main run `31338927707` passed version identity and correctly skipped republication because version `0.3.13` already exists. npm `0.3.13` and GitHub `v0.3.13` remain unchanged, and a fresh published consumer audit found zero vulnerabilities. Vercel reported a successful exact-main deployment. - Cleanup: The exact-head Daytona sandbox and current-run consumer were deleted. The unrelated nested dirty website repository remains unchanged at `67186845` with `51` paths. State: `verified` on main with empty intake queues and no fixable residual item. Next: start the next sweep from clean synchronized `main`. ### 2026-08-09 07:50 EDT — intake-sweep-brace-forward-compat-0.3.13-release - Objective: Carry issue `#217` through exact-candidate verification, merge, publication, delivery proof, and cleanup. - Persistence: PR `#218` exact head `5177a12785972d09a023b35c418b8e57ea2390b9` passed the complete install matrix and merged as `f7ead4144746ff34cd8f6dc18c1cb2e2a9f6c891`. The source and remote release branches were deleted. - Clean-machine proof: Daytona sandbox `99ff14c2-8913-405a-a45b-11f27518bd76` checked out exact head `5177a12` on Node `25.9.0` and passed `750/750` tests, typecheck, build, architecture, website checks, all production audits, pack and consumer/global installation, package/runtime/RPC/document verification, stale-Pi repair, and a fabricated `brace-expansion@5.0.10` launch. Its sandbox and the earlier undersized exit-`137` sandbox were deleted. - CI and delivery: PR run `31306432848` passed the release candidate, six Node `22`/`24`/`25` Linux/macOS/Windows consumers, and Windows PowerShell `5.1`/Core native installation. Main run `31308625569` passed source/package verification, the same consumer matrix, five native builds, npm publication, GitHub release creation, provenance, checksums, and published-state verification. - Release identity: npm `@companion-ai/feynman@0.3.13` has integrity `sha512-UkXPQz+jv1OTI42pIwNW5jr0IwUc1RErwsFulaj50Xfml2KQ3jmEPRNw47oc9wq+4kKmAzduDTnb/dhObcsK7Q==`; its attestation resolves to `f7ead414`. GitHub `v0.3.13` targets the same commit and exposes exactly five nonempty native archives plus `SHA256SUMS`; each provider digest matches the checksum manifest. - Published smoke: Fresh local and global npm installs passed zero-vulnerability consumer audit, version/help/package/search commands, package-artifact verification, installed runtime verification, and document parse/search/screenshot. Issue `#217` was commented with these receipts and closed. - Intake and cleanup: The issue and PR queues are empty. No duplicate PR, temporary tarball, consumer, process, release branch, or Daytona sandbox remains. The unrelated dirty nested website repository and prunable Lima worktree record remain preserved. - State: `verified` and production-live. `pi-subagents@0.45.0` remains intentionally unadopted because its broad task/chain, async, schedules, missions, Herdr, worktree, and administration migration does not serve this issue-specific research-runtime fix. ### 2026-08-09 05:15 EDT — intake-sweep-brace-forward-compat-0.3.13 - Objective: Resolve issue `#217` without weakening Pi's launch-time dependency repair, then release the exact verified candidate. - Intake: Issue `#217` is the only open issue and no PR is open. Two forks changed after the automation cutoff; both still match upstream `main`. The other `1,014` inspected forks add no current port target. The preserved Lima worktree is `92` commits behind `main` with no unique commit. The unrelated nested website repository remains dirty and unchanged outside the tracked release page. - Root cause: The security patch accepted only exact reviewed `brace-expansion` versions. Pi's agent-managed `/npm` tree can resolve a later secure release, so the next registry update would stop Feynman before CLI startup. Advisory `GHSA-rgw5-rvv9-x895` confirms `5.0.9` as the patched 5.x floor. - Changed: Valid semantic versions at or above `5.0.9` now remain intact in Pi shrinkwraps, owning locks, and installed trees. Reviewed vulnerable `5.0.6` through `5.0.8` trees still upgrade to exact `5.0.9`; malformed and older unsupported versions still fail closed. Added source, package-lock, installed-tree, and exact agent-managed runtime regressions. Bumped the candidate and public release notes to `0.3.13`. - Verified locally: Focused regressions passed `70/70`; all tests passed `750/750`; typecheck, build, architecture check, website lint/typecheck/build (`34` pages), root/site/runtime/consumer audits, npm registry signatures, and `git diff --check` passed. Clean local and global tarball installs passed version/help/package/search, stale-Pi upgrade, source and installed artifact verification, installed RPC/TypeBox tools, document parse/search/screenshot, and a fabricated agent-managed `brace-expansion@5.0.10` launch. - Package proof: Dry and real packs matched at `121,011,306` bytes, `342,270,111` unpacked bytes, and `40,223` entries. The tarball SHA-256 is `c7d1a439af9a9d70e3f90375efd03ba776f4af85e1d8346192861b3d4987c7e0`; the embedded runtime SHA-256 is `d803f701a3e32ff90a38d175891b413d83ca4f722ecf20f89f6b0ae2715f058d`. - Freshness: `pi-subagents@0.45.0` was reviewed but not adopted. Versions after bundled `0.40.0` remove public task/chain surfaces, make launches asynchronous by default, and add schedules, missions, Herdr, and administration paths. That broad contract migration has no issue-specific security or research-loop requirement. Other root and website drift has no current advisory or proven defect. - State: `verified` locally and `unverified` for the exact commit in Daytona, PR CI, merge, and npm/GitHub/native publication. Next: commit the candidate, prove that exact SHA in Daytona and CI, then merge, publish, verify delivery, and close `#217`. ### 2026-08-08 21:44 EDT — intake-sweep-0.3.12-release-completion - Objective: Complete issue `#214` through merge, publication, live delivery proof, and queue cleanup. - Persistence: PR `#216` exact head `3922342c4e9f8576627a661eadc953b5ee0e514e` merged as `bf6e415c83d702c6b3c280b463ed7a7e998861d3`. PR `#215` closed as superseded because it retained the obsolete alphaXiv fallback and added no unique repair. Origin now exposes only `main`. - Delivery: Publish run `31285624271` passed every source, package, Linux, macOS, Windows, native-bundle, provenance, release, and published-state job. npm `0.3.12` is `latest`; its attestation resolves to the merge commit. GitHub `v0.3.12` targets that commit with five nonempty native archives and matching `SHA256SUMS`. - User path: A clean global install of the published package authenticated with alphaXiv. The exact reported `feynman alpha ask 2401.12345 "What optimizer did they use?"` command returned paper content without MCP error `-32602`. - Live verification: Post-release run `31288182374` passed six npm consumers on Linux, macOS, and Windows across Node 22, 24, and 25. It also passed all three live native installers plus every enabled one-shot model, text-model, and subagent call. - Intake: Issue `#214` closed with delivery receipts and no issue or PR remains open. The sweep checked all `1,015` forks and every branch in the 20 forks active since August 1. The duplicate alphaXiv branch was superseded; stale security branches were already covered; the fork-only parallel-search prompt bundle remained outside the focused research-runtime fix. - Freshness: Pi `0.84.1`, `pi-web-access@0.19.0`, `pi-docparser@4.0.0`, and LiteParse `2.11.1` remain current. `pi-subagents@0.44.0` was reviewed but not adopted: its post-`0.40.0` line makes direct launches asynchronous and adds default schedules, missions, Herdr, worktree, and administration surfaces that cross Feynman's research-only boundary. Other root and website drift has no current advisory or proven research-loop defect. - State: `verified` and production-live. Root, website, runtime, and installed-consumer audits found zero vulnerabilities. The next daily sweep should start from npm/GitHub `0.3.12`, clean `main`, and an empty issue/PR queue. ### 2026-08-08 05:10 EDT — intake-sweep-alpha-ask-0.3.12 - Objective: Fix issue `#214`, reconcile the preserved `0.3.12` candidate, and complete its unpublished release without adding a new product surface. - Intake: Issue `#214` is the only open issue and no PR is open. Live `main` remains `daa7f47`; GitHub and npm still serve `0.3.11`. Recent active forks either match or trail `main`; `fuzzywigg` security commits are superseded, and `randomm` documents its provider-specific `parallel-cli` bundle as fork-only, so neither earns a port. - Root cause: `@companion-ai/alpha-hub@0.1.3` sends `answer_pdf_queries` first as `{ urls, queries }`, then retries as `{ url, query }`. The current alphaXiv contract requires `{ paper, queries }`, matching the provider's reported validation schema. - Changed: The removable alpha-hub package patch now sends `{ paper: url, queries: [query] }`, repairs an already search-patched runtime, fails closed on unknown Q&A layouts, and is enforced in source and archived package verification. Public `0.3.12` release notes now describe the user-visible repair. - Reconciled: The preserved candidate now includes Pi `0.84.1`, `pi-web-access@0.19.0`, LiteParse `2.11.1`, PDF.js `6.2.108`, current root and website security resolutions, and Pi delta-only Workbench RPC text updates. The open contributor PR duplicates the alphaXiv repair but retains the obsolete fallback, so it adds no change to port. - Adversarial repair: The first package-artifact run found the verifier checking nested Pi's obsolete `dist/tui.js` after Pi moved rendering to `dist/tui-main-screen.js`; the verifier and its regression now target the actual patched module. Review also corrected both public release surfaces from LiteParse `2.11.0` to the exact runtime `2.11.1`. - Verified locally: The exact source tree passed focused patch and release regressions, all `748/748` tests, typecheck, production build, architecture check, website lint/typecheck/build (`34` pages), root and website production audits (`0 vulnerabilities`), actionlint, and `git diff --check`. Live `feynman alpha ask 2401.12345 "What optimizer did they use?"` returned paper content without an MCP schema error. - CI repair: PR `#216` proved the Linux-built npm tarball on Linux, but its macOS and Windows consumers could not load LiteParse's matching native module because the archived runtime only carries its build host's optional package. The published package now requests every supported LiteParse native package as an optional dependency, allowing npm to install the consumer's matching binary outside the portable runtime archive. - Verified CI repair locally: Focused regressions and all `748/748` tests passed. The source, website, audit, build, architecture, and diff ladders stayed green. A 121,011,394-byte tarball passed budget, runtime audit, clean macOS consumer and global installs, artifact/runtime verification, and document parse/search/screenshot with the installed `darwin-arm64` package. - State: `verified` for the successor local source and macOS package paths, plus exact-SHA Daytona for predecessor `fb3cc6f`. PR CI must prove the successor across Linux, macOS, Windows, and native installers. Next: push the focused native-package repair, merge only green CI, then verify every `0.3.12` delivery surface. ### 2026-08-05 01:00 EDT — intake-sweep-0.3.12-release-hardening - Objective: Repair the remaining packaged web-config and document-tool verification gaps, adopt current research-runtime dependencies, and complete the unpublished `0.3.12` release. - Intake: Open issues and PRs are empty. `main` and `origin/main` match merge `daa7f47`; npm and GitHub still serve `0.3.11`. Recent forks are behind `main` except NioZow's stale one-commit Nix packaging branch, which is broad platform work with no current research defect or current-release validation and is not ported. The Lima worktree is clean and has no unique commit. - Changed: Web configuration now reads and writes through `getWebSearchConfigPath()` and creates that exact file's parent. Added an installed verifier that loads `pi-docparser` through Pi's bundled Jiti and executes parse, search, and screenshot tools in package, consumer, native, publish, and live-delivery gates. Updated direct, nested Pi, and runtime Undici to `8.10.0`; overrode `pi-docparser`'s LiteParse `2.10.1` pin with removable runtime version `2.11.0`. - Source proof: Undici `8.10.0` is official release commit `c8d80e6` with idle-loop, readable-body, retry, HTTP/2, proxy IPv6, and DNS-origin fixes. LiteParse `2.11.0` is official package commit `0f579ee`; its reviewed range adds document provenance, RTL/LTR ordering, table extraction improvements, and PDFium `1.5.0`. `pi-docparser@4.0.0` and its current upstream `main` still pin LiteParse `2.10.1`, which defines the override removal condition. - Verified so far: Dependency, runtime, package-seeding, exact web-fixture, release-workflow, and runtime-lock regressions passed `59/59`. The installed document verifier parsed one page, found one exact phrase hit, and wrote a nonempty `22,539`-byte PNG. Package-artifact verification passed with runtime SHA-256 `a7211debc8cc2cd254bf4e4b7cfb613d5e7332f6f3917fd159ae1e8995fbb093`. - State: `verified` for focused local paths and `unverified` for the cumulative local ladder, exact-commit Daytona, PR CI, merge, and published delivery. Next: complete every local gate, commit the exact candidate, prove it in Daytona and CI, then merge and verify npm, GitHub, native assets, and live installers. ### 2026-08-04 21:21 EDT — intake-sweep-0.3.12-final-candidate - Objective: Finish the open `0.3.12` web-runtime follow-up after its Windows installer verifier failed, refresh the complete maintainer intake, and add the smallest current document-research and security repairs before publication. - Changed: Made the `pi-web-access@0.18.0` patch validate every target before any write, reject unsupported versions and layouts, and verify all live session-scope paths in the packaged runtime. Updated `pi-docparser` to `4.0.0` for isolated cancellable native workers, atomic bounded outputs, stable JSON, and LiteParse `2.10.1`. Updated the audited Hono, `fast-uri`, `ip-address`, `express-rate-limit`, and website `brace-expansion` overrides. The Windows verifier now buffers the mutable checksum file while continuing to stream the large archive, which removes the retained checksum handle that failed the previous Windows job. - Intake: No open issues exist. PR `#213` is the only open PR and remains the owning merge path. PR `#212` already owns the `0.3.12` version. The newest `kunalkcube`, `gs034`, and `Interested-Deving-1896` forks match `main`; the other sampled recent forks are behind with no ahead commits. Dependabot and repository security-advisory queues are empty. Code scanning and secret scanning are not enabled, so those two empty-state claims remain unavailable rather than inferred. - Source proof: npm `pi-docparser@4.0.0` resolves to upstream commit `931a0995067062c91bd81798ef226d120c31bd84`, whose workflow `30816481652` and local upstream `57/57` check passed. npm latest remains Pi `0.83.0`, `pi-web-access@0.18.0`, `pi-subagents@0.40.0`, and `pi-docparser@4.0.0`. - Verified locally: Final focused runtime, package, release, and Windows coverage passed `97/97`; the exact upstream web fixture and fail-closed artifact coverage passed `25/25`; the full suite passed `737/737`. Root typecheck, build, architecture check, website lint/typecheck/build (`34` pages), root/site/runtime/extracted-runtime/consumer audits, actionlint, registry signature verification (`754` packages and `182` attestations, zero missing or invalid), package freshness review, and `git diff --check` passed. The exact bundled runtime SHA-256 is `62a11862fc7cec8235c7d17111b5520dbd52371a1177ccdab158c9d0b02f40ef`. - Runtime proof: Clean local and global tarball consumers, package-artifact verification, stale-Pi migration, RPC extension loading, and TypeBox validation passed. The final installed tarball retained a textual HTTP `418`, found a stored `teapot` passage case-insensitively, and registered all three web tools. A generated two-page PDF passed `document_parse`, `document_search`, and `document_screenshot`; the final screenshot was a nonempty `47,023`-byte PNG. A final installed `openai/gpt-5.5` request returned exact `PONG`. - Package proof: Final dry and real packs match at `119,891,973` bytes, `336,971,093` unpacked bytes, and `39,702` files. The tarball SHA-1 is `168932760db4c3733961b1807219c0e0dc57c427`, its SHA-256 is `26137da41f64b7cab7ba75c1041d5177a30fc1ded735632b837330aac5d7623e`, and its embedded runtime SHA-256 is `62a11862fc7cec8235c7d17111b5520dbd52371a1177ccdab158c9d0b02f40ef`. - State: `verified` locally and `unverified` for the successor exact commit in Daytona, successor PR CI, merge, and npm/GitHub/native/live-installer publication. Next: commit and push the exact candidate, prove it in a disposable Daytona sandbox and required CI, merge only that head, then verify every `0.3.12` delivery surface. ### 2026-08-02 23:53 PDT — intake-sweep-pi-web-access-0.18 - Objective: Refresh the empty issue/PR queue and recent contributor/fork state, then qualify `pi-web-access@0.18.0` as the smallest current research-retrieval upgrade from the clean `0.3.11` release baseline. - Changed: Updated Feynman's bundled/default/runtime-locked web package to `0.18.0`, retained migration for the `0.3.11`, `0.3.10`, and older bundled defaults, and bumped the release candidate to `0.3.12`. Adopted upstream raw and page-grounded fetches, direct images, stored-content passage lookup, provider additions, curator isolation, and Git cancellation while preserving project-local PDF scratch files, opt-in browser cookies, no-curator defaults, and the bounded primary-search deadline. Nested page-answer and summary model calls now follow Pi's live resolved session scope instead of rereading `.pi` settings; exact-version and artifact gates fail closed around the local patch. BSD runtime archives omit host ACL, flags, macOS metadata, and xattrs so those host records no longer change package bytes. - Intake: GitHub has no open issues or PRs, origin exposes only `main`, and the preserved Lima worktree at `6a81316` has no unique commits. Recently pushed forks are identical to or behind `main`; `fuzzywigg/feynman` is 128 commits behind and its security changes are superseded by current safe versions. No contributor change earned a port. - Source proof: npm `pi-web-access@0.18.0` resolves to upstream git head `d2aab00dcf0547572276d9de4bc4a2a49d640e13`. Its exact source passed `363/363` tests, typecheck, production audit, and a 58-file dry pack before integration. - Verified locally: Focused final model-scope/runtime/package coverage passed `47/47`, and the full suite passed `734/734`; root typecheck, build, architecture check, root/site/runtime/consumer audits, website lint/typecheck/build (`34` pages), registry signatures (`754` packages and `181` attestations), actionlint, package freshness review, and `git diff --check` passed. The exact installed web extension retained a textual HTTP `418` response, found a stored `TEAPOT` passage case-insensitively, registered `fetch_content`, `get_search_content`, and `web_search`, rejected an out-of-scope answer override, and enforced a scope narrowed after context creation. - Package proof: Dry and real packs were byte-identical at `111,490,673` bytes, `328,503,777` unpacked bytes, and `39,705` files. The tarball SHA-1 is `66b878d0d5ca64617c56e4c45db72617fed99e05`, its SHA-256 is `33f183d6d31658083ce2e2d71fbe2d586a15b99509f664c06b1ae9415dec8fc4`, and the embedded runtime SHA-256 is `7784202e9e3019bc86d01de9292936add9698b653f5c01ec3d5c6db01e25e8d3`; the runtime archive contains no host PAX/xattr metadata. Clean local/global installs, stale-Pi upgrade, CLI/package/search flows, package-artifact verification, extracted-runtime/consumer audits, installed RPC, extension loading, TypeBox checks, and a real installed `openai/gpt-5.5` prompt returning `PONG` passed. - State: `verified` locally and `unverified` for committed exact-SHA Daytona, PR CI, merge, and npm/GitHub/native/live-installer publication. Next: commit the exact candidate, prove it in a disposable Daytona sandbox and required CI, merge only the green head, then verify every `0.3.12` delivery surface. ### 2026-08-02 00:45 PDT — intake-sweep-0.3.11-release-completion - Objective: Finish the `pi-subagents@0.40.0` intake through exact-commit proof, publication, live installer verification, successor CI, and queue/worktree reconciliation. - Exact-head proof: Candidate `03fdb2a4c816e2de5c128821c0e48bf0011b2f73` passed the full local `728/728` ladder, authenticated parent/subagent smokes, exact-commit Daytona sandbox `7e3db21f-b329-4331-b4e2-4ce07e156dc4`, and PR run `30733954782`; PR `#210` merged as `26a55bd0cf9acf539413c3177da9ddb27029a5ce`. - Released: Main run `30735432891` passed source/package verification, all six Linux/macOS/Windows Node consumers, all five native builds, npm publication, GitHub release creation, and published-state verification. npm latest is `@companion-ai/feynman@0.3.11` with integrity `sha512-L/cWUqE1MitHhTntq57wcZdZEjQT2x2NZytMjXFn+JxeeVE5wmnearF5+/kMKiHq/tSArrqpBTMaFM/mUJ62bA==`; the 113,095,746-byte registry tarball has SHA-256 `12d36457caa982e8d4cdde292c4aef70a935a7d06aeabad52a1108c51859fada`, exactly matches the main workflow artifact, and verified provenance resolves to `26a55bd`. - Release identity: GitHub `v0.3.11` targets `26a55bd` and contains five nonempty native archives plus `SHA256SUMS`; every GitHub asset digest matches the manifest. Clean registry local/global consumers, source/runtime audits, package-artifact verification, installed RPC/TypeBox checks, the direct macOS one-line installer, and deployed `feynman.is` release docs all passed. - Installer gate: PR `#211` added durable post-release checks for the public Unix and Windows one-line installers and merged as `b67abf280d19eecc6c978fcfddeb2201b6178e1c` after local `729/729` validation and PR run `30736017829`. Dispatch `30737679781` passed all six published-package jobs plus live native installation on Ubuntu, macOS, and Windows; successor main run `30738324530` verified the existing release identity and skipped rebuild/publication. - Reconciled: Open issue and PR queues are empty; recent fork heads are behind `main`; root, website, and bundled runtime audits are clean; the unrelated Lima worktree remains preserved at `6a81316`. State: `completed`. Next: start future intake from the clean `0.3.11` release baseline. ### 2026-08-01 22:00 PDT — intake-sweep-pi-subagents-0.40 - Objective: Process the only post-`0.3.10` in-scope intake change, preserve the clean unrelated Lima worktree, and carry `pi-subagents@0.40.0` through a `0.3.11` release. - Changed: Updated the bundled/default/runtime-locked subagent package to `0.40.0`; retained automatic migration for both the `0.3.10` (`pi-subagents@0.38.0`) and `0.3.6` (`0.37.2`) default package sets; bumped Feynman to `0.3.11`; and added matching repository/website release notes. TypeBox remains at Pi `0.83.0`'s exact `1.3.7` contract. - Source proof: npm `pi-subagents@0.40.0` resolves to upstream tag commit `d4d2ab706b612ccd173caad2bc202eef07e7eda3`; upstream CI `30721272104` passed Ubuntu and Windows. The installed package exposes the reviewed capability ceilings, usage budgets, approval checkpoints, runtime-extension acknowledgement, signal status, process/output separation, and model/thinking visibility paths. - Verified locally: Focused package/settings/runtime/release coverage passed `92/92`; full tests passed `728/728`; typecheck, build, architecture check, website lint/typecheck/build (`34` pages), root/site/runtime/consumer audits, package freshness review, `git diff --check`, package-artifact verification, stale-Pi upgrade, and clean local/global installed-runtime RPC/TypeBox checks passed. Registry signature audit reported zero invalid or missing packages, and real authenticated `openai/gpt-5.5` parent plus `researcher` subagent smokes returned `PARENT_OK` and `RESULT=PONG`. - Package proof: Dry and real packs matched at `112,546,426` bytes, `329,608,636` unpacked bytes, and `39,705` files. The tarball SHA-256 is `79f8a976fc9dc4a4e2d4ffd1616b42798a6fd18ad0716241e35ab6933a108612`; the embedded runtime SHA-256 is `cad4ab09354c89cc5026ecbf78573ff6e0a4b08ae95b72a5205a6b3be7471ab3`. - State: `verified` locally and `unverified` for exact-commit Daytona, PR CI, merge, and npm/GitHub/native publication. Next: commit and push the candidate, prove that exact commit in a disposable Daytona sandbox and required CI, then merge and verify every `0.3.11` release surface. ### 2026-08-01 10:00 PDT — intake-sweep-0.3.10-release-completion - Objective: Finish the Pi `0.83.0` migration, Windows installer, package-update, and blocked-telemetry queue through exact-head proof, merge, publication, issue reconciliation, and cleanup. - Exact-head proof: Commit `b5c43a1508b26e7be12f0f54a09b3089c181bd40` passed the complete `727/727` suite, typecheck, build, architecture check, website lint/typecheck/build, all production audits, dry and real packs, package budget, clean local/global installs, stale-Pi and package-artifact verification, and installed RPC/TypeBox checks in Daytona sandbox `8423796e-c70c-4c61-bab4-d43ab8aa188f`. Its 113,079,330-byte, 39,702-file tarball had SHA-256 `e68cdab8074ec84d6833d4c296aeddf68fe5e6a5e8f3365c88eec1002559d365`; the sandbox was deleted and confirmed absent. - CI and merge: PR run `30704056177` passed the release candidate, both Windows PowerShell installer paths, and all six Linux/macOS/Windows Node `22.22.0`/`24.18.0`/`25` consumers. PR `#206` merged as `162a26a14c07576e44f2e579bc97a56de81a169e`; the release branch was deleted and local `main` fast-forwarded. - Released: Main run `30705796129` passed source/package verification, all six package consumers, all five native bundles, npm publication, GitHub release creation, and published-state verification. npm `@companion-ai/feynman@0.3.10` has integrity `sha512-yZQSjB6GmTo/m41lra8WaavQ3jFFxbWQkNvcmw1EV7zZAO8xSSdZ/G81Pd1UKBKJS/wJ5uR32PLtyiQvjTGhvQ==`; its verified SLSA/Fulcio provenance resolves to `162a26a`, and the registry tarball exactly matches the Daytona SHA-256. - Release identity: GitHub `v0.3.10` targets `162a26a` and contains five native archives plus `SHA256SUMS`; every provider asset digest matches the manifest. GitHub latest resolves to `v0.3.10`, the live Unix and Windows installer bytes match `main`, and the deployed release page names `v0.3.10`. - Reconciled: Issues `#207`, `#208`, and `#209` are closed with release receipts; the open issue and PR queues are empty. State: `completed`. Next: start future intake from the clean `0.3.10` release baseline and remove the remaining temporary fork-inspection refs. ### 2026-08-01 07:30 PDT — intake-sweep-native-nested-pi-repair - Failed: Exact-SHA PR run `30703039353` reached the Windows native bundle and rejected the freshly installed nested `@earendil-works/pi-agent-core` because `patch-embedded-pi.mjs` patched only hoisted and runtime-workspace copies before artifact verification. - Fixed: The embedded patch now applies the reviewed AgentCore, TUI, editor, and package-update-notice repairs to hoisted and nested Pi copies in both the application dependency tree and vendored runtime workspace, with exact Pi-version guards. - Verified: A clean production-only dependency install began with all four affected files unpatched, then the embedded patch added every required marker; focused embedded/runtime regressions passed `8/8`; full tests passed `727/727`; typecheck, build, architecture check, and `git diff --check` passed. - State: `verified` locally and `unverified` for successor-SHA Daytona, Windows native CI, merge, and publication. Next: push the repair, prove the exact successor commit in Daytona and CI, then merge and reconcile the release. ### 2026-08-01 06:12 PDT — intake-sweep-0.3.10-current-queue - Objective: Finish PR `#206` and issues `#207/#208/#209` as one `0.3.10` reliability release without losing the coordinated Pi `0.83.0` candidate. - Fixed: The Windows installer now extracts through a unique short same-volume drive and cleans up transactionally; package updates target the effective managed/project root and verify the update actually landed; PostHog transport failures open a silent per-process circuit breaker; TypeBox schemas reject null arrays; installed RPC verification reaps complete process trees; Pi package notices use the supported `feynman update` command; and the bundled `pi-subagents@0.38.0` / `pi-web-access@0.17.1` defaults now migrate consistently across settings, runtime, package-list, and release surfaces. - Hardened: Adversarial review replaced version-dependent Windows path lengths with a calculated boundary fixture, requires successful `taskkill`, corrects patch removal conditions, resolves hoisted direct dependencies during artifact verification, prevents tests from mutating the vendored Pi tree through legacy symlinks, and follows symlinked temp paths when deciding whether the installed verifier should execute. A final review also restricted exact-pin reconciliation to valid semantic versions while preserving range/tag selectors, and changed the bundled tracer preflight to an authenticated, status-checked `OPTIONS` request so retriable HTTP failures never enable the exporter. - Verified locally: focused review regressions passed `54/54`; full tests passed `726/726`; typecheck, build, architecture check, actionlint, website lint/typecheck/build (`34` pages), source/runtime/site/consumer audits, source and installed artifact checks, runtime tree reconciliation, stale-Pi upgrade, local/global installed RPC checks, healthy PostHog/OTLP log/trace delivery, blocked-collector silence, and `git diff --check` passed. - Package proof: dry and real packs matched at `112,524,540` bytes, `329,580,850` unpacked bytes, `39,705` files, SHA-1 `bfecb172351c30fddfe3a5b2aedfe8dea708e4d6`, and integrity `sha512-bZMJhGiA0F5YzasK6ehOLciAWfkv5WQMCKrmsdk2ja7Utn7aTSM4qmcukVE2fZTmERKiyuas2nzB3NUBeClo1w==`. Tarball SHA-256 is `1c459ea70d98f1f09e66057d1192bd23bf592e7674c0fd464bcfbe18411f1617`; runtime SHA-256 is `fa4828de88c37d559de58eef449be255f5b97d2de0f9a6a6eb8a66f2a2c1d069`. - State: `verified` locally and `unverified` for committed exact-SHA Daytona, PR CI, merge, published `0.3.10`, and terminal issue reconciliation. Next: commit/push the exact candidate, run and delete Daytona, require green Windows/consumer CI, merge, verify npm/GitHub/native release identity, then close `#207/#208/#209`. ### 2026-07-30 02:02 PDT — intake-sweep-0.3.10-release-candidate - Fixed: PaperRank now reads only Pi's finalized assistant message and rejects provider errors, aborts, output-limit truncation, and other non-completion stop reasons before generated synthesis is written. Pi's top-level `cli` extension source classification no longer hides Feynman's 15 built-in research tools. - Hardened: Installed-package verification now inventories 9 Feynman commands and 15 tools over RPC, compiles all 15 installed schemas, exercises a genuinely nullable array through Pi's TypeBox tool path, and proves malformed arguments fail before tool execution. - Verified locally: focused release gates passed `10/10`; full tests passed `688/688`; typecheck, build, architecture check, website lint/typecheck/build, `git diff --check`, root/site/runtime/consumer audits, mixed-Pi rejection, stale-Pi upgrade, package-artifact verification, dry/real pack, package budget, clean consumer install, and global install all passed. The real tarball is 112,476,954 bytes with 39,700 files; runtime archive SHA-256 is `ec22f6bae0eadbe56012818ebc4fa9c42345159adbd8a2c540efd436f3a26bb7`. - Verified user paths: the installed runtime exposed all 9 commands and 15 tools, rejected malformed TypeBox input, completed a real authenticated `openai/gpt-5.5` prompt, and generated a real PaperRank synthesis artifact from the fixture source. - State: `verified` locally and `unverified` for exact-SHA Daytona, PR CI, merge, and published `0.3.10` reconciliation. Next: commit and push the exact candidate, run Daytona, merge only green CI, then verify npm provenance and GitHub/native assets. ### 2026-07-29 16:07 PDT — intake-sweep-0.3.10-pi-0.83 - Objective: Continue the terminal intake from released `0.3.9` and adopt the new coordinated Pi runtime rather than leave a fixable dependency migration deferred. - Found: Pi `0.83.0` was published from upstream commit `845d6ff1` during this sweep. Its TypeBox `1.3.7` change requires an explicit compatibility pass; its llama.cpp source now requests streaming usage, but old `models-store.json` entries still preserve the false capability. Upstream issues `#7150` and `#7053` remain open, and Pi's shrinkwrap still carries vulnerable `brace-expansion@5.0.7` plus proxy-broken Undici `8.5.0`. - Fixed: Moved all four Pi packages, root/runtime locks, fallback pins, correctness gates, declarations, artifact checks, and fixtures to exact `0.83.0`. Retained the compaction-loss and eager parallel-result repairs, rebased llama.cpp handling to keep only the serialized cached-metadata migration on top of Pi's upstream usage fix, and reapplied the exact `brace-expansion@5.0.8` and Undici `8.9.0` repairs. Mixed Pi trains and unreviewed older/newer versions now fail closed. - Verified so far: Focused runtime, llama.cpp, TypeBox-compatible extension/model, package, audit, integrity, and release-workflow tests passed `92/92`; root and generated-runtime production audits, typecheck, architecture check, and `git diff --check` passed. npm metadata and the official `v0.83.0` tag/release all resolve the four-package train to `845d6ff1`. - State: `verified` for the focused migration and `unverified` for the full source/site/package/native/clean-machine/CI/release ladder. Next: complete cumulative validation, exact-SHA Daytona proof, PR CI, merge, and `0.3.10` npm/GitHub/native release reconciliation. ### 2026-07-29 05:18 PDT — intake-sweep-0.3.9-runtime-correctness - Objective: Close the post-`0.3.8` release-gate findings and current Pi `0.82.1` runtime correctness gaps instead of leaving them as upstream or dependency deferrals. - Found: The stale-Pi gate omitted the shrinkwrap-owned security subtree, allowed Windows `.cmd` launches through Node's deprecated shell-with-arguments path, and recorded the prior release date incorrectly. Current Pi also acknowledges then drops a default RPC prompt during manual compaction, delays every parallel tool result behind the slowest sibling before persistence, pins Undici `8.5.0`, whose `EnvHttpProxyAgent` tunnels plain HTTP proxy traffic, and disables llama.cpp streaming usage so session token totals remain zero. The first correctness candidate persisted completed results only after extension dispatch, accepted extension-rewritten tool-call identities that could duplicate accounting, and verified broad artifact markers without Pi's own shrinkwrap metadata. - Fixed: Bound stale verification to the exact source/npm/native candidate and pre-launch runtime baselines; require complete core-fixture mutation accounting, exact trusted brace/pi-otel trees, dereferenced second-pass identity, and explicitly escaped `ComSpec` launches. Added removable, exact-version-gated Pi `0.82.1` patches that reject manual-compaction prompts before a success acknowledgment and eagerly persist completed parallel tool results before extension dispatch while restoring source order. Extension-modified results now replace that eager entry under the original protocol identity instead of duplicating session usage. Updated Feynman's direct, nested Pi, committed runtime, and current user/global Pi Undici resolution to `8.9.0` while leaving stale Pi versions untouched. Ported upstream Pi PR `#7258`, repaired stale llama.cpp `models-store.json` capability metadata in place, and serialized that migration against concurrent network catalog refreshes. Artifact verification now checks every load-bearing correctness fragment and exact Pi shrinkwrap Undici version, resolved URL, and integrity. - Verified so far: Adversarial review findings were closed with exact migration, real file-store, concurrent-refresh, mock SSE usage, and semantic artifact-mutation regressions. Full tests passed `681/681`; typecheck, build, architecture check, actionlint, website lint/typecheck/build (`34` pages), root/site/runtime/consumer production audits, freshness review, source artifact verification, and `git diff --check` passed. Dry and real packs matched at `112,154,998` bytes / `39,706` entries with tarball SHA-256 `c0e0e1947d1de0882ca7ed1bd01cd10554a180ac2278f7a0b29f11d2deb04571` and runtime SHA-256 `8224927047fadd5cf77fb012cc70574ec660980ee77e0aeb1fd6d5689b3940eb`. A clean local/global install passed version/help/package/search, two-launch stale-Pi, real RPC (`112` commands), runtime and consumer audits, artifact verification, and persisted llama.cpp cache repair. The macOS arm64 native bundle passed version/help and the same stale-Pi gate at SHA-256 `535ab3f514fb79b5f7c67d0f6c73ad8f8ea6fb24dcd4d73fef60eeec4cf28af9`. - Release gate: PR run `30464663836` passed the complete source/site/package matrix, every Linux/macOS/Windows Node consumer, and the Windows installer at exact head `e6ecd34`; PR `#204` merged as `d062cd3`. Main run `30468941628` then exposed a Windows-native-only verifier defect after every source, package-consumer, and other native job passed: fixture snapshots combined a slash-bearing scoped package label with Windows path separators, so the valid nested brace-expansion repair missed its allowlist. Snapshot and allowlist keys now use one canonical separator. The focused path/workflow suite passed `9/9`, typecheck and `git diff --check` passed, and the local two-launch stale-Pi verifier passed. - Final exact-head proof: Commit `8fc4ed9` passed the focused path/workflow suite (`12/12`), full tests (`683/683`), typecheck, build, architecture check, website lint/typecheck/build, source/runtime/consumer audits, dry/real pack, installed package and Linux native smokes, artifact verification, and the stale-Pi gate. Disposable Daytona sandbox `feynman-039-path-20260729204251` repeated the complete ladder on Node `25.9.0` / npm `11.12.1`; its `112,753,043`-byte tarball had SHA-256 `4eb46f2ca02ca18b0a53195813475dd99a614f90c8bd7f2edc857198b4af4028`. The sandbox was deleted and confirmed absent. PR run `30489379792` then passed the release candidate, all six Linux/macOS/Windows Node consumers, and both Windows PowerShell installer paths. - Released: PR `#205` merged as `8dac290`. Main run `30491968966` passed source verification, all six package consumers, all five native bundles, npm publication, GitHub release creation, and published-state verification. npm `@companion-ai/feynman@0.3.9` integrity is `sha512-dX6A9lghZazeT83tKUv8KVoIL77xsm6RPMonzqDF50J8+xmKcXXBQGxPPIEA/oL1wWm+yyvm/JWOxDfFrDYxVA==`; independently verified SLSA/Fulcio provenance resolves to `8dac290`. GitHub `v0.3.9` targets the same commit and contains five nonempty native assets plus `SHA256SUMS`, with every provider digest matching the manifest. A clean registry consumer and global install passed version/help/package/search, runtime and consumer audits, artifact verification, and the two-launch stale-Pi smoke. - State: `completed`. The existing `v0.3.8` GitHub release body was reconciled to the corrected July 29 source notes. Next: continue future intake from the clean `0.3.9` release baseline. ### 2026-07-29 01:45 PDT — intake-sweep-0.3.8-windows-native-cleanup - Objective: Finish the `0.3.8` release after all source and package-consumer gates passed but the Windows native stale-Pi smoke failed. - Found: Main run `30432364527` passed source verification, all six Linux/macOS/Windows package consumers, and four native bundles. The Windows native smoke then ran exactly to the verifier's 120-second launch limit; its primary timeout was hidden when immediate temp-tree removal hit a live Windows handle and threw `EPERM`. - Fixed: Give Windows native runtime extraction and launch a bounded five-minute pass budget, retry only transient filesystem cleanup errors with capped backoff, preserve a verification error when cleanup also fails, and keep a successful verification red when cleanup cannot complete. - Verified locally: Focused cleanup/workflow tests passed `12/12`; full tests passed `659/659`; typecheck, build, architecture check, actionlint, website lint/typecheck/build (`34` pages), full and production audits, package freshness review, and `git diff --check` passed. A clean installed tarball passed budget, artifact, consumer/runtime audit, version/help/package/search, and two-launch stale-Pi gates. A separate exact Pi `0.82.0` user-root reproduction launched twice with all four stale Pi versions and affected core-file hashes unchanged. - Clean machine: Disposable Daytona sandbox `ab03dc5c-7228-485b-b1cc-88eaf4d2f131` verified exact `544832028368fc28bb408b3054a77782356b7736` on Node `24.18.0` and npm `11.16.0` through the same `659` tests, source/site/package/runtime/consumer ladder, and stale-upgrade smoke. Its tarball SHA-256 was `b3f5ddb109a4a724d746229cb829bf19ec4ea86128068ba98b3dec3b495578d8`; runtime SHA-256 was `05da056664d0009df87795a834e480998546db9393cf3752a9912e1b9aa8893c`. The sandbox was deleted and confirmed absent. - Released: Main run `30437805935` passed all source gates, six package consumers, five native bundles, npm publish, GitHub release, and published-state verification. The repaired Windows native stale-Pi smoke passed twice in `2m52s`. npm `0.3.8` integrity is `sha512-6y6Yf7NgOFsht/HxpdncV+8AfjxYo+C3F04ymSqEDF8Iq6B5qVBGwcwoI/ZGk/9iAlAZLBGf3uwaFgCwosy4Ag==`; verified SLSA provenance, GitHub tag, and release all resolve to `5448320`. All five nonempty native asset digests match `SHA256SUMS`. - State: `completed`. Issue `#202` received the release and exact Pi `0.82.0` receipts. Next: keep the stale-user-package gates in future releases and re-run the intake from this terminal baseline. ### 2026-07-28 21:20 PDT — intake-sweep-stale-pi-editor-upgrade - Objective: Reproduce and fix issue `#202`, where a standalone `0.3.7` install failed at launch with `Unsupported Pi editor layout: required import patch anchor was not found`. - Found: Pi stores user packages under `/npm`. An upgrade can retain Pi `0.80.6` core dependencies there. The exact published `0.3.7` RPC launch failed against the official stale editor, and a one-anchor editor compatibility patch then failed against the same release's ModelRegistry. Pi `0.82.1` already aliases extension peer imports to the current bundled core, so patching each historical core layout is unnecessary and brittle. - Fixed: Resolve Feynman's bundled Pi version from package metadata and skip core patchers only for Pi packages with a different explicit version. Security, MCP, and extension patching still covers user roots. Package and native release gates now launch twice with staged stale editor and ModelRegistry files, prove those core files remain byte-identical, and prove extension patching remains idempotent. - Verified locally: Fresh official Pi `0.80.6` packages passed two idempotent patch passes (`true`, then `false`) with editor and ModelRegistry hashes unchanged, followed by two clean RPC launches. Focused tests passed `22/22`; full tests passed `655/655`; typecheck, build, architecture check, actionlint, website lint/typecheck/build (`34` pages), root/website/runtime/clean-consumer audits, and `git diff --check` passed. Dry and real packs matched at `111,634,612` bytes / `39,692` entries with SHA-256 `daaf0e114b4e708269629edc99b166f782990f0940105265f6efa2dade0c1376`. The clean installed tarball passed artifact verification and the two-pass stale upgrade smoke with runtime archive SHA-256 `5dee5447b585bab835bcb3dd74b5a832a69b4e7cbea57aa4ca3d75794242d788`; the native macOS arm64 bundle passed the same smoke at SHA-256 `6db6e81d58b91a0b78d043e9532b078341aaae0bf965dfa8c65d158690c1660f`. - State: `verified` locally. Next: prove the exact commit in Daytona and required GitHub CI, then merge and verify the `0.3.8` npm/GitHub/native release before closing `#202`. ### 2026-07-29 00:35 PDT — intake-sweep-0.3.8-windows-release-budget - Objective: Finish the merged `0.3.8` release without dropping the supported Windows Node `24.18.0` local/global installation gate. - Failed: Main run `30428654129` passed source/package verification and the Linux, macOS, and Windows Node `25` consumers. The Windows Node `24.18.0` consumer spent `26m` on the first exact-tarball install, then the former 45-minute job budget cancelled the second required global install before runtime audit and artifact verification; npm/GitHub remained at `0.3.7`. - Fixed: Keep every package, audit, local/global launch, runtime extraction, and artifact check intact while raising only the PR and release package-consumer job budget to a bounded 60 minutes. Next: validate, push, and require the successor main release run to publish and verify `0.3.8`. ### 2026-07-28 14:30 PDT — intake-sweep-global-npm-install - Objective: Re-run the terminal intake after `0.3.6`, including the documented global npm install path rather than treating a clean project-prefix consumer as equivalent. - Found: Both an upgrade under `~/.npm-global` and a fresh disposable `npm install --prefix ... @companion-ai/feynman@0.3.6` produced an empty `node_modules/@opentelemetry/api` directory. `feynman --version` then failed before command dispatch from the direct telemetry import, while the existing non-global consumer gate passed because npm could hoist `@opentelemetry/api@1.9.1` above the package root. - Fixed: Bundle the exact direct OpenTelemetry API with the five existing runtime packages, and exercise the exact global install/version/help path across every supported package-consumer matrix plus post-publication registry verification. - Exact-head CI: Run `30402843325` passed the release candidate, all Linux/macOS consumers, Windows Node `25`, and the native installer. Windows Node `24.18.0` completed both local and global version/help checks but hit the former 30-minute job limit six seconds into runtime extraction; the identical Node `25` path completed in `29m38s`. Both PR and release consumer matrices now use a bounded 45-minute timeout. - Verified locally: Scoped workflow tests passed (`7/7`); the complete suite passed (`654/654`); typecheck, build, architecture check, actionlint, website lint/typecheck/build (`34` pages), root and website full/production audits, package freshness review, and `git diff --check` passed. Dry and real packs matched at 111,637,876 bytes / 328,227,251 unpacked / 39,692 files with npm integrity `sha512-PFChM+N8VQsNZQ64uFLb9EDytP96vKFvThpooai5P0KnmYfyspXyFrleW5gHeQipEH5zuIxTZnbJZ2Fv/jC/SQ==` and tarball SHA-256 `941389ca83a06b49105a4c07515fad1e250617ced593192ad2a90c4b851b61a0`. - Installed proof: A clean consumer and extracted runtime each audited at zero, artifact verification passed with runtime SHA-256 `c31b7db649f47997abfc6a3622c5af1758af71789a5eae9c96c98932c3d96ac1`, and clean global installs under npm `11.16.0` and `11.18.0` each contained nonempty bundled OpenTelemetry API `1.9.1` trees and passed version/help. Installed RPC loaded `112` commands including `thinking` and `web-results`. - Released: PR `#201` merged as `6248ac3`; push run `30408266001` passed source verification, all six package consumers, all five native bundles, npm publication, GitHub release creation, and published-state verification. Windows Node `24.18.0` completed the release consumer path in `39m`. - Registry proof: npm latest is `0.3.7` with integrity `sha512-zl9Jov8XYoJHE+pbfAeO9iwvciyyWerYq68ryEg+TpH3ehijMwOlTa7YIeDhgDoTd23GqIBZ0se/rVMGsTvdxQ==`; its verified SLSA provenance resolves to `6248ac3`. GitHub `v0.3.7` targets the same commit and has five nonempty native archives plus a `SHA256SUMS` file that matches every GitHub asset digest. - User install: The broken `~/.npm-global` `0.3.6` install reproduced the missing OpenTelemetry entry point, then an in-place registry upgrade passed version/help and installed `@opentelemetry/api@1.9.1` with `588` files. The package artifact verifier passed with runtime archive SHA-256 `5599cb62bfa015479cc942b5051c8335b637999dc276deeb853ea5b6cdf86e88`. - State: `completed`. Next: keep the global-install and bounded Windows consumer gates in every future release. ### 2026-07-28 08:30 PDT — intake-sweep-manual-release-provenance-gate - Objective: Keep manual release recovery from creating an immutable npm package whose provenance the push-only identity policy would reject. - Found: `workflow_dispatch` could publish a previously absent version, but npm would correctly attest the certificate trigger as `workflow_dispatch`; post-publish and every later reconciliation would then fail the required `push` identity check. - Fixed: Manual runs may reconcile an already-published npm version and complete its GitHub release, but they fail before authorizing npm publication for a new version. The `publish-npm` job independently requires a push event. - Verified: The gate is scoped to `version-check`, executes before `should_publish_npm=true`, and the publication job has a second event guard. Adversarial review confirmed manual reconciliation remains fail-closed and found one test-only hardening gap, now fixed by scoping downstream skip-condition assertions to their owning jobs. Focused provenance/workflow tests (`7/7`), full tests (`652/652`), actionlint, and `git diff --check` pass. - Completed: Commit `a3aebe4` is on `main`; run `30375131813` verified the complete `0.3.6` identity without republishing. A disposable Daytona `daytona-large` sandbox re-ran the exact commit's focused suite (`7/7`), full suite (`652/652`), full/production audits, and clean-tree check on Node `24.18.0`, then was deleted. ### 2026-07-28 08:16 PDT — intake-sweep-0.3.6-release-completion - Objective: Complete the `0.3.6` npm/GitHub release, reconcile every tracked user issue, and preserve the final development-audit refresh. - Published: Main run `30367434326` published the exact verified 39,102-file npm tarball and six-asset GitHub release from `ccc8030c1090efb6afab8c4f907115309d1eb788`. The package integrity is `sha512-DKIzet0eGtJt8lAN307j6pfGrpT+Vu+Lmrju/YbW+DDHJ+/hO/jmxavu494EwqPk2Sied3kvmtGQzhqb6Eqo0g==`; GitHub targets the same commit and publishes five nonempty native archives plus `SHA256SUMS`. - Failed: npm `11.18.0` does not add `gitHead` when publishing a prebuilt tarball, so the original final verification stopped before testing the installed package and release assets even though npm's signed SLSA provenance binds the package digest to `ccc8030`. - Fixed: Release reconciliation now uses `npm audit signatures --include-attestations`, validates the verified SLSA subject digest and source claims, and binds them to the Fulcio certificate's GitHub workflow SAN plus OIDC issuer, workflow/ref, source SHA, push trigger, invocation, public visibility, and repository-subject extensions instead of relying on optional registry `gitHead` metadata. - Verified: The live npm attestation resolves only to `ccc8030`; adversarial certificate/source/commit/invocation mismatches fail closed. Focused provenance/workflow tests pass (`7/7`), full tests pass (`652/652`), typecheck, build, architecture check, actionlint, root and website full/production audits, website lint/typecheck/build (`34` pages), and `git diff --check` pass. The post-release dry/real package remains within its release budgets; source, clean installed-consumer, and extracted-runtime verification/audits pass. - Completed: Commit `d2cce1f` persisted the provenance verifier and dev-lock refresh. Successor run `30373237537` verified the published npm/GitHub identity without republishing; issues `#182/#185/#186/#187/#188/#190/#193/#196` were closed with release receipts, and the two superseded remote branches were deleted. ### 2026-07-28 07:30 PDT — intake-sweep-root-dev-audit-refresh - Objective: Clear the one remaining root development-only advisory without changing the validated `0.3.6` production graph. - Fixed: Refreshed Vite's transitive `postcss` from `8.5.16` to patched `8.5.24` and its `nanoid` dependency from `3.3.15` to `3.3.16` in the root lockfile. `package.json`, the runtime lock, website dependencies, and published package inputs remain unchanged. - Verified: Root full and production audits, website full and production audits, focused release tests (`5/5`), full tests (`650/650`), typecheck, build, architecture check, website lint/typecheck/build (`34` pages), and `git diff --check` pass. Non-security package drift remains intentionally deferred. - Next: Persist the lock refresh after the in-flight `0.3.6` release reaches terminal identity, then require the successor main workflow to skip release work cleanly at the already-published version. ### 2026-07-28 07:12 PDT — intake-sweep-release-tarball-publish-path - Objective: Repair npm publication after all successor package consumers and native bundles passed. - Found: Run `30364141613` passed source verification, all six Linux/macOS/Windows consumer jobs, and all five native bundles. `publish-npm` job `90300538798` then passed the downloaded artifact as bare relative path `npm-package/companion-ai-feynman-0.3.6.tgz`; npm `11.18.0` interpreted that as a Git dependency and attempted `ssh://git@github.com/npm-package/...tgz.git`. npm `0.3.6` and GitHub `v0.3.6` remain absent, so no partial release occurred. - Fixed: Resolve the single downloaded tarball to an absolute filesystem path before inspecting and publishing it, and scope the regression to the `publish-npm` job. - Verified: Full tests (`650/650`), the focused workflow suite (`5/5`), actionlint, and `git diff --check` pass. - Next: Push the exact successor, then require npm provenance publication, six GitHub assets, checksums, installability, and final release identity before issue closure. ### 2026-07-28 06:32 PDT — intake-sweep-release-consumer-job-path - Objective: Correct the first release-workflow repair after successor run `30361556647` repeated the Windows runtime-audit failure. - Found: Commit `c67c99c` normalized the source-verification consumer block, but the failing cross-platform `verify-package-consumers` matrix was a separate duplicated block and remained unchanged. The regression asserted against the whole workflow, so the unrelated first block satisfied it. Both Windows Node `24.18.0` and `25` receipts show the old native `D:\...` archive argument at the failure. - Fixed: Normalize the runtime archive and extraction paths inside the matrix job itself, and scope the regression to the `verify-package-consumers` job so another block cannot false-green it. - Verified: Full tests (`650/650`), the focused workflow suite (`5/5`), actionlint, and `git diff --check` pass. - Next: Push the exact successor and require both Windows consumers plus native/publish/release identity to pass before issue closure. ### 2026-07-28 06:00 PDT — intake-sweep-release-windows-runtime-path - Objective: Repair the first post-merge `0.3.6` release run without allowing a partially published release. - Fixed: Main run `30359204278` passed source/package verification and Linux/macOS consumers, then Windows Node `25` job `90277101520` proved that the publish workflow handed GNU tar the native `D:\...` path of the installed runtime archive. Git Bash interpreted the drive colon as a remote host separator. The release consumer now converts the runtime archive and extraction destination through `cygpath`, matching the already-green PR consumer path. - Verified: npm publication and GitHub release jobs remained gated and never started; the failed run was cancelled after the discriminator receipt was retained. Full tests (`650/650`), typecheck, focused workflow tests (`5/5`), actionlint, and `git diff --check` pass. Exact successor Windows consumers and terminal release identity remain pending. - Next: Validate and push the workflow-only repair to `main`, require the successor release run to pass every consumer/native/publish job, then verify npm/GitHub assets and close the eight released issues. ### 2026-07-28 01:49 PDT — intake-sweep-pi-web-access-0-15 - Objective: Resolve the post-cutoff `pi-web-access@0.15.0` research-search release before publishing Feynman `0.3.6`. - Changed: Pinned the bundled and seeded web-access package to `0.15.0`, refreshed the committed runtime lock/archive, documented simultaneous all-provider search, TinyFish search/extraction, and configurable OpenAI Responses-compatible gateways, and extended Feynman's package patch so current upstream `utils.ts` continues to honor the exact `FEYNMAN_WEB_SEARCH_CONFIG` file instead of falling back to Pi's agent directory. - Verified: The exact upstream tag/commit passed its patched test suite (`215/215`), typecheck, runtime production audit, idempotency, and diff check. Focused Feynman package/runtime/settings/integrity regressions passed (`50/50`); full tests passed (`649/649`); typecheck, build, architecture, actionlint, website lint/typecheck/build, root/site/runtime/consumer audits, and diff check passed. Dry and real packs matched at SHA-1 `ae23ce2976abe5a3d5920435ad4f4f9a68a8a395`; the real tarball SHA-256 is `b6d10e01f6bea37984016b7b4a294a8a038ac5e295ccc38c826040583cfa025d`. Clean installed-artifact verification reports Pi `0.82.1`, `pi-web-access@0.15.0`, and runtime SHA-256 `2ec33eae33d1d994b73a6826703200daf0883295b2e52a786ea268f5b94375ef`; isolated RPC loaded `web-results` while ignoring an intentionally invalid agent-directory web config in favor of Feynman's exact config path. - Next: Commit and push the exact candidate, run the clean Daytona ladder at that SHA, require the final GitHub Windows/Node matrix to pass, then merge and verify npm/GitHub release identity. ### 2026-07-28 01:24 PDT — intake-sweep-windows-consumer-path - Objective: Repair the final exact-head PR `#192` platform failure without weakening the shared candidate-tarball gate. - Fixed: Run `30341296771` proved that both Windows Node `24.18.0` and Node `25` consumers converted the downloaded tarball to a native `D:\...` path, which GNU tar interpreted as a remote host. The PR consumer gate now retains a native absolute tarball for npm, derives an MSYS path for GNU tar, and normalizes shell-owned consumer and runtime extraction paths under Git Bash. - Verified: The exact parent candidate passed the GitHub release-candidate source/package job and entered both Windows installer hosts; actionlint, the focused release-workflow suite (`5/5`), and `git diff --check` pass with the path repair. Exact successor CI, final clean Daytona verification, merge, and publication remain pending. - Next: Commit and push the repair, require every Windows/Node/native job to pass, rerun clean-machine proof at the successor SHA, then merge and verify the `0.3.6` release. ### 2026-07-28 01:07 PDT — intake-sweep-0-3-6-final-candidate - Objective: Finish PR `#192` as the single release path for issues `#182/#185/#186/#187/#188/#190/#193/#196`, including the remaining Windows, supported-Node, packaged-runtime, and live-auth gates. - Fixed: Raised the Node 22 floor to `22.22.0`; made candidate-tarball paths absolute; kept the PowerShell launcher while validating it under execution-policy bypass; normalized Windows runtime hardlinks; updated MCP to `1.30.0`, Hono to `2.0.12`, and `pi-subagents` to `0.37.2`; made installed-consumer CI audit the extracted runtime archive; made runtime recovery verify every manifest package; and made both alphaXiv status paths refresh and verify credentials against live user-info. - Verified: Full tests passed (`648/648`); typecheck, build, architecture, actionlint, website lint/typecheck/build (`34` pages), root/site/runtime/consumer audits, and `git diff --check` passed. Final tarball SHA-256 is `06cdfd606a52e5a59d15d7276c68a9e542f3b40dfa120a4fda5a970e2676fa2b` (`111572902` bytes, `327212330` unpacked, `39105` files); source and installed artifact verification passed with Pi `0.82.1` and runtime SHA-256 `7a858a29c51dcf977be07ba6be1c64ba023b4eaad3aacf0f7ed03414c9679056`. Exact-package RPC proved extension/prompt loading, direct bash, and `/thinking` clamping; live OpenAI model, researcher subagent, and refreshed alphaXiv user-info smokes passed. - Next: Commit and push the exact candidate, run and delete a disposable Daytona sandbox at that SHA, require the full GitHub Windows and Node `22/24/25` matrix to pass, merge, then verify npm/GitHub/native release identity and issue closure. ### 2026-07-26 17:48 PDT — intake-sweep-windows-runtime-hardlinks - Objective: Repair PR `#192` Windows native job `89859997454` at exact head `8bf9f1a2e5af48787c2eb47eae3726b86cacb9c1` without weakening runtime archive integrity. - Fixed: Windows tar preserved npm-created NTFS hardlinks, while the live workspace hash treated each hardlink as its regular-file contents and the archive hash treated it as a distinct entry type. Runtime archive verification now resolves in-archive hardlinks to their target file or symlink content, rejects targets outside `npm/`, duplicate entries, missing targets, and cycles, and compares the same logical tree on every platform. - Further fixed: All public Windows PowerShell downloads now use `-UseBasicParsing`, which Microsoft requires after the CVE-2025-54100 PowerShell 5.1 update to avoid an interactive script-execution prompt. PR and publish gates now reuse the exact packed candidate across Node `22.19.0`, `24.18.0`, and `25`, including Windows Node 25 plus macOS and Windows Node 24 consumers, instead of leaving the supported-major matrix manual and post-publication. - Verified: A minimal hardlink repro failed against the prior archive parser; the focused archive/runtime regression suite passes (`8/8`), the installer/workflow suite passes (`8/8`), actionlint passes, both public Windows installers are byte-identical, and root typecheck/full tests/build/architecture plus `git diff --check` passed at the hardlink commit (`642/642`). Exact Windows native/install and supported-major consumer proof remain pending the next pushed-head CI run. - Next: Push the remaining gate repairs, require the complete PR matrix to pass, then finish clean-machine, merge, and release verification. ### 2026-07-26 17:16 PDT — intake-sweep-0-3-6-windows-ci-repair - Objective: Repair the first exact-head PR CI failure at `f5974f96ae9b1950ced68093c6ee1abdb9acc5d9` without weakening the release verifier. - Fixed: Windows native build run `30226243548`, job `89856784343`, proved that the production dependency install replaced the patched MCP manifest before artifact verification. The embedded runtime patch now repairs MCP manifests in the installed package and vendored workspace graphs. The Windows installer also validates downloaded PowerShell launchers through the current host with a process-scoped execution-policy bypass, preserving the public in-memory installer under Windows PowerShell's default Restricted policy. A follow-up adversarial check found that the StrictMode verifier used `$installBinDir` without defining it; the verifier now derives that path explicitly and tests the assignment. - Verified: Focused archive, installer, MCP, runtime-patch, and release-workflow tests passed (`18/18`) before the StrictMode follow-up; both public Windows installer copies are byte-identical; actionlint and `git diff --check` passed. Exact Windows native/install proof remains pending the next pushed-head CI run. - Next: Commit and push the repair, require both Windows PowerShell 5.1 and PowerShell Core jobs to pass, then continue clean-machine and release verification. ### 2026-07-26 16:48 PDT — intake-sweep-0-3-6-release-candidate - Objective: Reconcile the inherited 0.3.6 work into PR `#192`, finish the Pi 0.82.1/security/package/installer release blockers, and prove the exact candidate before merge and publication. - Changes: Migrated Feynman's model/auth/session paths to Pi 0.82.1 `ModelRuntime`; added model-aware `/thinking`; preserved Pi follow-up while adding Option+Enter newline input; pinned and integrity-bound the packaged runtime graph; repaired Pi brace-expansion and MCP/Hono consumer advisories; made runtime/native archives deterministic; made Windows replacement transactional and checksum-ambiguous inputs fail closed; added Windows Desktop/Core, clean-consumer, package-budget, native matrix, exact-tarball publication, and release-reconciliation gates. The publish gate now accepts a complete npm/GitHub release at an ancestor commit while still requiring exact commit identity for incomplete-release recovery, so ordinary later main commits do not false-fail the prior release. - Intake: PR `#192` is the owning merge path. PR `#200` is superseded by the independently prepared model-aware implementation and should close after the replacement commit is pushed. Issues `#182/#185/#186/#187/#188/#190/#193/#196` are implemented and remain open only until exact-head CI, merge, and release verification. - Verified locally: Focused regressions passed (`64/64`); full `npm test` passed (`639/639`); typecheck, build, architecture check, website lint/typecheck/build (`34` pages), actionlint, root/site/runtime/consumer production audits, and `git diff --check` passed. Exact tarball `companion-ai-feynman-0.3.6.tgz` is `111547961` bytes with `39088` files, SHA-256 `d95cd2bdce96069653707b85f06a6d1e453113893a354d46a02f676d25503e26`; source and installed artifact verification passed with Pi `0.82.1` and runtime archive SHA-256 `0bb4e8c6049a1a9d3742f36350cd978c46d249d22c4cbf6942fac8ff6d4dd8ae`. An installed Pi session reached the expected missing OpenAI credential only after runtime load and workspace scaffolding. - Next: Commit and push the exact candidate, run and delete a disposable Daytona proof, repair PR CI to green, merge, then verify npm/GitHub/native release identity and terminally reconcile the eight issues plus PR `#200`. ### 2026-07-22 20:10 EDT — intake-sweep-package-floor - Objective: Finish the `check-new-issues` release-candidate proof after the queue audit, preserve the existing PR branch, and correct package metadata that made supported Node 22 installs noisy or inconsistent. - Changes: Raised the website engine contract from Node `>=20.19.0 <25` to `>=22.19.0 <26`, matching Astro 7 and the root Feynman runtime. Moved `ketcher-core`, `ketcher-react`, and `ketcher-standalone` from production dependencies to exact `3.15.0` development dependencies because they are build-only inputs already bundled into `dist`. - Verified: Clean root and website installs passed; the complete suite passed (`595/595`); focused runtime/MCP tests passed (`24/24`); root typecheck/build and architecture checks passed with existing warnings; website lint/typecheck/build passed (`34` pages); website audit found `0 vulnerabilities`; root audit still reports only Pi-shrinkwrapped `brace-expansion@5.0.6` and `protobufjs@7.6.4`; `npm pack --dry-run --json` passed with `402` entries. The exact tarball `/tmp/feynman-pack-release-20260722-2010/companion-ai-feynman-0.3.6.tgz` is `71043279` bytes with SHA-256 `6b9e4150f6b28233345bd99b4f3222371fe3d0e354ec7665740dac6a03cc9732`. - Installed smoke: A fresh Node `22.22.3` install emitted no Ketcher engine warnings and passed version/help, alpha help, package listing, unknown `--extensions` guidance, `alt+enter`, packaged workspace scaffold creation, launch-before-spawn wiring, alphaXiv OAuth markers, project-local fetch-cache markers, and runtime archive entries for Pi `0.80.6`, `pi-btw` `0.4.1`, and `pi-web-access` `0.13.0`. - Blocked: A consumer-side tarball audit additionally resolves `@modelcontextprotocol/sdk@1.29.0` to vulnerable `@hono/node-server@1.19.14`. The repository is clean because its root override selects `2.0.11`, but npm package overrides do not propagate to consumers and the latest MCP SDK still declares `@hono/node-server@^1.19.9`; no safe package-local version bump is currently available. - Next: Keep PR `#192` unmerged and unpublished without explicit authorization; verify issue `#199` on a tool-capable Ubuntu/Ollama model before calling it fully fixed; resolve or explicitly accept the consumer-install MCP/Hono audit blocker before publishing `0.3.6`. ### 2026-07-22 15:36 EDT — intake-sweep-workspace-scaffold - Objective: Re-run `check-new-issues`, preserve existing dirty release-candidate work, refresh live GitHub/release/package/workflow state, classify open issues/PRs/contributor refs, and fix safe repo-local validation or artifact failures without GitHub writes. - Checked: New issue `#199` reports fresh Ubuntu/Ollama runs printing planned `outputs/.plans` writes without actually creating files because the workspace lacks `outputs/.plans`. Open issues are now `#199`, `#198`, `#196`, `#193`, `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`; open PRs remain `#197`, `#192`, `#191`, and `#189`. Latest `main` `Publish and Release` run remains green at `54d08a3`; GitHub release and npm latest remain `v0.3.5` / `0.3.5`; local package remains `0.3.6`; bundled Pi remains `0.80.6`; npm Pi latest remains `0.81.1`. - Decisions: Ported a smallest root-cause local fix for `#199`: Pi launch now scaffolds `outputs/.plans`, `outputs/.drafts`, `papers`, and `notes` under the selected `--cwd` before the child runtime starts. PR `#192` remains merge/defer pending explicit authorization; PR `#189` remains already ported into `#192`; PR `#191` remains reject/defer as broader extension inventory surface; PR `#197` remains reject/defer as generic provider catalog expansion. Issue `#198` remains outside the AI-researcher product bar; `#196` remains upstream Pi TUI slash-command scope; `#193/#182/#190/#188/#187/#186/#185` remain covered by `#192`; `#184` remains support/content scope. - Contributor refs: Remote refs were refreshed. `origin/fix/deepresearch-local-model-warning` remains `74` behind / `1` ahead; `pr4fork/main` remains `73` behind / `0` ahead; visible fork refs did not introduce a fresh safe research-loop port target. - Freshness: Root and website `npm outdated --json` show non-security drift. No dependency edit was made because the actionable defect was workspace artifact scaffolding, not dependency freshness. - Verified: `npm test` passed (`595/595`); root `npm run typecheck`; root `npm run build` with existing RDKit/3Dmol/direct-eval/chunk warnings; `npm run architecture:check` with existing split-debt warnings; website lint/typecheck/build passed (`34` pages); website audit found `0 vulnerabilities`; root audit remains blocked by Pi-shrinkwrapped `brace-expansion@5.0.6` and `protobufjs@7.6.4`; `git diff --check` passed; `npm pack --dry-run --json` passed with `entryCount: 402`, shasum `ff8c9b527f00bee5588e7fbb43bc3660d97d044b`, size `71041173`; installed-tarball smoke passed for package `0.3.6`, help, and fresh-workspace scaffold creation. - Next: Review/commit the scaffold fix with the existing `0.3.6` release-candidate work; merge/publish PR `#192` only when authorized; keep dependency freshness drift separate from `#199`. ### 2026-07-22 07:32 EDT — intake-sweep-copilot-review-rejected - Objective: Re-run `check-new-issues` from `/Users/advaitpaliwal/Companion/Code/feynman`, preserve the existing dirty release-candidate worktree, refresh live GitHub/release/package/workflow state, classify open issues/PRs/contributor refs, and validate the local `0.3.6` package without GitHub writes. - Checked: Open issues are `#198`, `#196`, `#193`, `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`; open PRs are `#197`, `#192`, `#191`, and `#189`. Latest `main` `Publish and Release` run remains green at `54d08a3`; GitHub release and npm latest remain `v0.3.5` / `0.3.5`; local package remains `0.3.6`; bundled Pi remains `0.80.6`; npm Pi latest remains `0.81.1`; alpha-hub remains `0.1.3`; `pi-btw` remains `0.4.1`. - Decisions: Issue `#198` is reject/defer because Microsoft Copilot reviewer/checklist automation is external review/admin workflow rather than a concrete Feynman-owned research-loop defect or smallest research artifact verification improvement. PR `#192` remains merge/defer pending explicit authorization; PR `#189` remains already ported into `#192`; PR `#191` remains reject/defer as broader extension inventory surface; PR `#197` remains reject/defer as generic curated provider expansion. Issue `#196` remains upstream Pi TUI slash-command scope; `#193/#182/#190/#188/#187/#186/#185` remain covered by `#192`; `#184` remains support/content scope. - Contributor refs: Remote refs were refreshed. `origin/fix/deepresearch-local-model-warning`, `pr4fork/main`, and visible fork refs did not introduce a fresh safe research-loop port target. - Freshness: Root and website `npm outdated --json` show non-security drift. No dependency edit was made because no queue-specific root-cause failure requires dependency churn and the remaining root audit blocker is still Pi-owned nested shrinkwrap state. - Verified: Focused runtime test passed (`15/15`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/direct-eval/chunk warnings; `npm run architecture:check` with existing split-debt warnings; `npm test` passed (`594/594`); website lint/typecheck/build passed (`34` pages); website audit found `0 vulnerabilities`; root audit remains blocked only by Pi-shrinkwrapped `brace-expansion@5.0.6` and `protobufjs@7.6.4`; `git diff --check` passed; `npm pack --dry-run --json` passed with `entryCount: 402`, shasum `c698bb6c66c37756ba677c0a45af49c532f6a6d9`, size `71041144`; installed-tarball smoke passed for `0.3.6`, help, alpha help, `packages list` including `pi-btw` and `pi-web-access`, `update --extensions` help hint, `alt+enter`, runtime archive markers, alpha auth patch, and project-local fetch cache patch. - Next: Merge/publish PR `#192` only when authorized; keep `#198`, `#197`, and `#191` out unless product scope explicitly changes. ### 2026-07-13 23:35 PDT — intake-sweep-pr-192-still-clean - Objective: Re-run `check-new-issues` from `/Users/advaitpaliwal/Companion/Code/feynman`, preserve existing dirty local work, refresh GitHub issue/PR/workflow/release/package/branch state, classify the queue against the AI-researcher product bar, and validate the local package without GitHub writes. - Checked: Current branch remains `codex/fix-feynman-user-issues`; open issues remain `#193`, `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`; open PRs remain `#192`, `#191`, and `#189`. Latest `main` `Publish and Release` run remains `28835967900`, green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` remains `0.3.5`; local package remains `0.3.6`; Pi remains `0.80.6`; `@companion-ai/alpha-hub` remains `^0.1.3`. - Decisions: No new code changes. Keep draft PR `#192` as the merge path for `#182`, `#185`, `#186`, `#187`, `#188`, `#190`, and `#193`; it already includes PR `#189` as cherry-pick `79aa7b2`. Reject/defer PR `#191` because `feynman extensions` is still a broader extension-inventory surface than the reported update/help failure requires and its Vercel status remains failing. Issue `#184` remains outside Feynman's AI-researcher product bar. - Contributor refs: Remote refs were refreshed. `origin/fix/deepresearch-local-model-warning` remains stale local-model warning work; visible fork refs were prompt/Overleaf/admin surfaces, provider/platform changes, fork docs, broad Windows rewrites, or already-covered installer/runtime/auth work. No new safe port target was found. - Freshness: Root and website `npm outdated --json` show dependency drift only; root and website `npm audit --omit=dev` found `0 vulnerabilities`. No dependency change was made. - Verified: Focused runtime test passed (`15/15`); `npm test` passed (`594/594`); root `npm run typecheck`; root `npm run build` with existing Vite/RDKit/3Dmol/chunk warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); root and website `npm audit --omit=dev`; `git diff --check`; `npm pack --dry-run --json` (`entryCount: 402`, shasum `f0b50e989c04095e9a4b3b65628bcf6def9921aa`); installed-tarball smoke proved package `0.3.6`, CLI help, `feynman alpha --help`, `feynman packages list` including `npm:pi-btw` and `npm:pi-web-access`, runtime archive presence, and the hoisted alpha CLI resolver. - Note: The installed tarball emitted dependency deprecation warnings during `npm install`, but completed successfully. No GitHub write was made. - Next: Commit the hoisted alpha CLI resolver and merge/publish PR `#192` when authorized; keep PR `#191` out unless product scope explicitly expands to extension inventory. ### 2026-07-13 11:34 PDT — intake-sweep-alpha-193-covered - Objective: Re-run `check-new-issues` from `/Users/advaitpaliwal/Companion/Code/feynman`, preserve existing dirty local work, refresh GitHub issue/PR/workflow/release/package state, classify the queue against the AI-researcher product bar, and validate the local package without GitHub writes. - Checked: Current branch remains `codex/fix-feynman-user-issues` at `8ad8d55` tracking `origin/codex/fix-feynman-user-issues`; `origin/main` remains `54d08a3`. Open issues are now `#193`, `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`; open PRs remain `#192`, `#191`, and `#189`. Latest `main` `Publish and Release` run remains `28835967900`, green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` remains `0.3.5`; local package remains `0.3.6`; Pi latest/current remains `0.80.6`; `@companion-ai/alpha-hub` latest/current remains `0.1.3`. - Decisions: No GitHub writes. Treat new issue `#193` as covered by the `#192` alphaXiv auth patch plus the current local hoisted-alpha CLI resolver in `src/cli.ts`; `clerk.alphaxiv.org` still fails with `ENOTFOUND`, while local patched alpha-hub uses `https://api.alphaxiv.org/auth`. Keep draft PR `#192` as the merge path for `#182`, `#185`, `#186`, `#187`, `#188`, `#190`, and `#193`; it already includes contributor PR `#189` as cherry-pick `79aa7b2`. Reject/defer PR `#191` because `feynman extensions` remains broader than the update/help failure requires and its Vercel status remains failing. Issue `#184` remains outside Feynman's AI-researcher product bar. - Contributor refs: Remote refs were refreshed. No new safe port target was found beyond `#189`, already included in `#192`; visible fork refs remain stale, broader provider/platform/admin work, docs/export material, or already-covered installer/runtime/auth work. - Freshness: Root and website `npm outdated --json` show non-security drift only. No dependency change was made. - Verified: Focused alpha/runtime tests passed (`20/20`); `npm test` passed (`594/594`); root `npm run typecheck`; root `npm run build` with existing Vite/RDKit/3Dmol/chunk warnings; `npm run architecture:check` with existing split-debt warnings; root and website `npm audit --omit=dev` (`0 vulnerabilities`); website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 402`, shasum `f0b50e989c04095e9a4b3b65628bcf6def9921aa`); installed-tarball smoke proved package `0.3.6`, CLI help, `feynman alpha --help`, hoisted alpha resolver presence, and installed alpha-hub auth issuer `https://api.alphaxiv.org/auth`. - Note: Early focused and pack probes failed only from invocation/parser assumptions: raw `node --test` on TS files without `tsx`, then mixed `npm pack --json` output containing prepack `[feynman]` logs. Corrected commands passed. - Next: Commit the hoisted alpha CLI resolver and merge/publish PR `#192` when authorized; keep PR `#191` out unless product scope explicitly expands to extension inventory. ### 2026-07-13 03:37 PDT — intake-sweep-pr-192-still-clean - Objective: Re-run `check-new-issues` from `/Users/advaitpaliwal/Companion/Code/feynman`, preserve existing dirty local work, refresh GitHub/package/release/branch state, classify open issues/PRs/contributor refs, and run repo-local validation without GitHub writes. - Checked: Current branch remains `codex/fix-feynman-user-issues` at `8ad8d55` tracking `origin/codex/fix-feynman-user-issues`; `origin/main` remains `54d08a3`. Open issues remain `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`; open PRs remain `#192`, `#191`, and `#189`. Latest `main` `Publish and Release` run remains `28835967900`, green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` remains `0.3.5`; local package remains `0.3.6`; Pi latest/current remains `0.80.6`; `@companion-ai/alpha-hub` latest/current remains `0.1.3`. - Decisions: No new code changes. Keep draft PR `#192` as the merge path for `#182`, `#185`, `#186`, `#187`, `#188`, and `#190`; it includes contributor PR `#189` as cherry-pick `79aa7b2`, has green Vercel status, and the latest PR comment still reports the alpha auth patch worked for another user. Reject/defer PR `#191` because `feynman extensions` is broader than the update/help failure requires and its Vercel status is still failing. Issue `#184` remains outside Feynman's AI-researcher product bar. - Contributor refs: Remote refs and recent public forks were refreshed/spot-checked. No new safe port target was found beyond `#189`, already included in `#192`; recent visible forks were either at `54d08a3`, behind, broader provider/platform work, docs/export material, or already-covered Windows/install/auth work. - Freshness: `npm outdated --json` shows non-security drift only in root and website packages. No dependency change was made. - Verified: Focused runtime/auth/web/install regressions passed (`51/51`); `npm test` passed (`594/594`); root `npm run typecheck`; root `npm run build` with existing Vite/RDKit/3Dmol/chunk warnings; `npm run architecture:check` with existing split-debt warnings; root and website `npm audit --omit=dev` (`0 vulnerabilities`); website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 402`, shasum `f0b50e989c04095e9a4b3b65628bcf6def9921aa`); corrected installed-tarball smoke proved package/CLI `0.3.6`, CLI help, package listing, `alpha status`, bundled `alt+enter`, runtime archive, alphaXiv OAuth2 patch, project-local fetch cache patch, and archive entries for `pi-btw`, `pi-web-access`, and `@earendil-works/pi-coding-agent`. - Note: Early smoke wrappers failed only from probe assumptions: mixed `npm pack --json` parsing, stale alpha-hub archive path, and stale pi-web-access source path. The corrected smoke used actual archive paths and passed; temp artifacts were cleaned. - Next: Review/merge/publish PR `#192` when authorized; keep PR `#191` out unless product scope explicitly expands to extension inventory. ### 2026-07-12 06:15 EDT — intake-sweep-pr-192-still-clean - Objective: Re-run `check-new-issues` from `/Users/advaitpaliwal/Companion/Code/feynman`, preserve unrelated local work, refresh GitHub/package/release/branch state, classify open issues/PRs/contributor refs, and run repo-local validation without GitHub writes. - Checked: Current branch remains `codex/fix-feynman-user-issues` at `8ad8d55` tracking `origin/codex/fix-feynman-user-issues`; `origin/main` remains `54d08a3`. Open issues remain `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`; open PRs remain `#192`, `#191`, and `#189`. Latest `main` `Publish and Release` run remains `28835967900`, green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` remains `0.3.5`; local package remains `0.3.6`; Pi latest/current remains `0.80.6`; `@companion-ai/alpha-hub` latest/current remains `0.1.3`. - Decisions: No new code changes. Keep draft PR `#192` as the merge path for `#182`, `#185`, `#186`, `#187`, `#188`, and `#190`; it includes contributor PR `#189` as cherry-pick `79aa7b2`, has green Vercel status, and the latest PR comment still reports the alpha auth patch worked for another user. Reject/defer PR `#191` because `feynman extensions` is broader than the update/help failure requires and its Vercel status is still failing. Issue `#184` remains outside Feynman's AI-researcher product bar. - Contributor refs: Remote refs were refreshed. No new safe port target was found beyond `#189`, already included in `#192`; older visible refs remain stale, broader provider/platform work, docs/export material, or already-covered Windows/install/auth work. - Freshness: `npm outdated --json` shows non-security drift only in root and website packages. No dependency change was made. - Verified: `npm run architecture:check` with existing split-debt warnings; `npm test` passed (`593/593`); root `npm run typecheck`; root `npm run build` with existing Vite/RDKit/3Dmol/chunk warnings; root and website `npm audit --omit=dev` (`0 vulnerabilities`); website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 402`, shasum `167a902ecc8b2ea71e6b3402052f3a45c7ab2b11`); corrected installed-tarball smoke proved package `0.3.6`, CLI `--version`, CLI `--help` exit, `packages list`, `alpha status`, runtime archive entries for `pi-btw` and `pi-web-access`, and the alphaXiv OAuth2 patch in the runtime archive. - Note: One early smoke wrapper failed only from a mixed `npm pack --json` parser grabbing an inner `files` array. The corrected parser and smoke passed; temp installs and tarballs were cleaned. - Next: Review/merge/publish PR `#192` when authorized; keep PR `#191` out unless product scope explicitly expands to extension inventory. ### 2026-07-12 02:15 EDT — intake-sweep-pr-192-still-clean - Objective: Re-run `check-new-issues` from `/Users/advaitpaliwal/Companion/Code/feynman`, preserve unrelated local work, refresh GitHub/package/release/branch state, classify open issues/PRs/contributor refs, and run repo-local validation without GitHub writes. - Checked: Current branch remains `codex/fix-feynman-user-issues` at `8ad8d55` tracking `origin/codex/fix-feynman-user-issues`; `origin/main` remains `54d08a3`. Open issues remain `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`; open PRs remain `#192`, `#191`, and `#189`. Latest `main` `Publish and Release` run remains `28835967900`, green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` remains `0.3.5`; local package remains `0.3.6`; Pi latest/current remains `0.80.6`; `@companion-ai/alpha-hub` latest/current remains `0.1.3`. - Decisions: No new code changes. Keep draft PR `#192` as the merge path for `#182`, `#185`, `#186`, `#187`, `#188`, and `#190`; it includes contributor PR `#189` as cherry-pick `79aa7b2`, has green Vercel status, and the latest PR comment still reports the alpha auth patch worked for another user. Reject/defer PR `#191` because `feynman extensions` is broader than the update/help failure requires and its Vercel status is still failing. Issue `#184` remains outside Feynman's AI-researcher product bar. - Contributor refs: Remote refs were refreshed. No new safe port target was found beyond `#189`, already included in `#192`; older visible refs remain stale, broader provider/platform work, docs/export material, or already-covered Windows/install/auth work. - Freshness: `npm outdated --json` shows non-security drift only in root and website packages. No dependency change was made. - Verified: `npm test` passed (`593/593`); root `npm run typecheck`; root `npm run build` with existing Vite/RDKit/3Dmol/chunk warnings; root and website `npm audit --omit=dev` (`0 vulnerabilities`); `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 402`, shasum `167a902ecc8b2ea71e6b3402052f3a45c7ab2b11`); corrected installed-tarball smoke proved package `0.3.6`, CLI `--version`, `packages list`, `alpha status`, bundled `alt+enter`, runtime archive entries for `pi-btw` and `pi-web-access`, and the alphaXiv OAuth2 patch in the runtime archive. - Note: Two early smoke wrappers failed only from probe assumptions: first parsing the `[feynman]` prepack log prefix as JSON, then sampling archive paths under `pipefail`/a stale alpha-hub path. The corrected checks passed and temp artifacts were cleaned. - Next: Review/merge/publish PR `#192` when authorized; keep PR `#191` out unless product scope explicitly expands to extension inventory. ### 2026-07-11 22:11 EDT — intake-sweep-pr-192-still-clean - Objective: Re-run `check-new-issues` from `/Users/advaitpaliwal/Companion/Code/feynman`, preserve unrelated local work, refresh GitHub/package/release/branch state, classify open issues/PRs/contributor refs, and run repo-local validation without GitHub writes. - Checked: Current branch remains `codex/fix-feynman-user-issues` at `8ad8d55` tracking `origin/codex/fix-feynman-user-issues`; `origin/main` remains `54d08a3`. Open issues remain `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`; open PRs remain `#192`, `#191`, and `#189`. Latest `main` `Publish and Release` run remains `28835967900`, green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` remains `0.3.5`; local package remains `0.3.6`; Pi latest/current remains `0.80.6`; `@companion-ai/alpha-hub` latest/current remains `0.1.3`. - Decisions: No new code changes. Keep draft PR `#192` as the merge path for `#182`, `#185`, `#186`, `#187`, `#188`, and `#190`; it includes contributor PR `#189` as cherry-pick `79aa7b2`, and the latest PR comment still reports the alpha auth patch worked for another user. Reject/defer PR `#191` because `feynman extensions` is broader than the update/help failure requires and its Vercel status is still failing. Issue `#184` remains outside Feynman's AI-researcher product bar. - Contributor refs: Remote refs were refreshed. No new safe port target was found beyond `#189`, already included in `#192`; older visible refs remain stale, broader provider/platform work, docs/export material, or already-covered Windows/install/auth work. - Freshness: `npm outdated --json` shows non-security drift only in root and website packages. No dependency change was made. - Verified: `npm test` passed (`593/593`); root `npm run typecheck`; root and website `npm audit --omit=dev` (`0 vulnerabilities`); root `npm run build` with existing Vite/RDKit/3Dmol/chunk warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); `npm run architecture:check` with existing split-debt warnings; `git diff --check`; `npm pack --dry-run --json` (`entryCount: 402`, shasum `167a902ecc8b2ea71e6b3402052f3a45c7ab2b11`); corrected installed-tarball smoke proved package `0.3.6`, CLI `--version`, `--help`, `packages list`, `alpha status`, bundled `alt+enter`, runtime archive, and archive entries for `pi-btw`, `pi-web-access`, and `@earendil-works/pi-coding-agent`. - Note: One installed-smoke wrapper failed from a bad mixed-log JSON parser; the corrected strict smoke passed and temp artifacts were cleaned. - Next: Review/merge/publish PR `#192` when authorized; keep PR `#191` out unless product scope explicitly expands to extension inventory. ### 2026-07-11 18:09 EDT — intake-sweep-pr-192-still-clean - Objective: Re-run `check-new-issues` from `/Users/advaitpaliwal/Companion/Code/feynman`, preserve unrelated local work, refresh GitHub/package/release/branch state, classify open issues/PRs/contributor refs, and run repo-local validation without GitHub writes. - Checked: Current branch remains `codex/fix-feynman-user-issues` at `8ad8d55` tracking `origin/codex/fix-feynman-user-issues`; `origin/main` remains `54d08a3`. Open issues remain `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`; open PRs remain `#192`, `#191`, and `#189`. Latest `main` `Publish and Release` run remains `28835967900`, green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` remains `0.3.5`; local package remains `0.3.6`; Pi latest/current remains `0.80.6`; alpha-hub latest/current remains `0.1.3`. - Decisions: No new code changes. Keep draft PR `#192` as the merge path for `#182`, `#185`, `#186`, `#187`, `#188`, and `#190`; it includes contributor PR `#189` as cherry-pick `79aa7b2`, and the latest PR comment reports the alpha auth patch worked for another user. Reject/defer PR `#191` because `feynman extensions` is broader than the update/help failure requires and its Vercel status is still failing. Issue `#184` remains outside Feynman's AI-researcher product bar. - Contributor refs: Remote refs were refreshed. No new safe port target was found beyond `#189`, already included in `#192`; older visible refs remain stale, broader provider/platform work, docs/export material, or already-covered Windows/install/auth work. - Freshness: `npm outdated --json` shows non-security drift only in root and website packages. No dependency change was made. - Verified: `npm test` passed (`593/593`); root `npm run typecheck`; website `npm run lint` and `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `npm run architecture:check` with existing split-debt warnings; root `npm run build` with existing Vite/RDKit/3Dmol/chunk warnings; website `npm run build` (`34` pages); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 402`, shasum `167a902ecc8b2ea71e6b3402052f3a45c7ab2b11`); strict installed-tarball smoke proved package `0.3.6`, CLI `--version`, `--help`, `packages list`, `alpha status`, bundled `alt+enter`, runtime archive, and archive entries for `pi-btw`, `pi-web-access`, and `@earendil-works/pi-coding-agent`. - Note: One installed-smoke wrapper failed from a bad mixed-log JSON parser and missing `set -e`; the corrected strict smoke passed and temp artifacts were cleaned. - Next: Review/merge/publish PR `#192` when authorized; keep PR `#191` out unless product scope explicitly expands to extension inventory. ### 2026-07-11 09:16 EDT — intake-sweep-pr-192-still-clean - Objective: Re-run `check-new-issues` from `/Users/advaitpaliwal/Companion/Code/feynman`, preserve the existing dirty `CHANGELOG.md`, refresh GitHub/package/release/branch state, classify open issues/PRs/contributor refs, and run repo-local validation without GitHub writes. - Checked: Current branch remains `codex/fix-feynman-user-issues` at `8ad8d55` tracking `origin/codex/fix-feynman-user-issues`; `origin/main` remains `54d08a3`. Open issues remain `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`; open PRs remain `#192`, `#191`, and `#189`. Latest `main` `Publish and Release` run remains `28835967900`, green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` remains `0.3.5`; local package remains `0.3.6`; Pi latest/current remains `0.80.6`; alpha-hub latest/current remains `0.1.3`. - Decisions: No new code changes. Keep draft PR `#192` as the merge path for `#182`, `#185`, `#186`, `#187`, `#188`, and `#190`; it includes contributor PR `#189` as cherry-pick `79aa7b2`. Reject/defer PR `#191` because `feynman extensions` is broader than the update/help failure requires and its Vercel status is failing. Issue `#184` remains outside Feynman's AI-researcher product bar. - Contributor refs: `origin/fix/deepresearch-local-model-warning`, `pr4fork/main`, and fork refs were checked. No new safe port target was found: visible refs were either already represented in `#192`, broader platform/provider/admin work, docs-only walkthrough/export material, fork-specific changes, or stale Windows/install work already covered by the current branch. - Freshness: `npm outdated --long` shows non-security drift only (`@clack/prompts`, OpenTelemetry packages, TypeBox, Node types, fast-xml-parser, lucide-react, patristic, posthog-node, radix-ui, tsx, TypeScript, undici, vite). No dependency change was made. - Verified: `npm test` passed (`593/593`); `npm run typecheck`; `npm run architecture:check` with existing split-debt warnings; root `npm run build` with existing Vite/RDKit/3Dmol warnings; root and website `npm audit --omit=dev` (`0 vulnerabilities`); website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 402`, shasum `167a902ecc8b2ea71e6b3402052f3a45c7ab2b11`); installed-tarball smoke proved package `0.3.6`, CLI `--version`, `--help`, `packages list`, `alpha status`, bundled `alt+enter`, and runtime archive entries for `pi-btw`, `pi-web-access`, and `@earendil-works/pi-coding-agent`. - Note: Two initial smoke wrappers failed only from probe assumptions: first reading hoisted dependencies under the package-local `node_modules`, then resolving non-exported dependency `package.json` files. The final smoke used CLI/archive checks and passed; generated temp installs and tarballs were removed. - Next: Review/merge/publish PR `#192` when authorized; keep PR `#191` out unless product scope explicitly expands to extension inventory. ### 2026-07-11 05:15 EDT — intake-sweep-pr-192-still-clean - Objective: Re-run `check-new-issues` from `/Users/advaitpaliwal/Companion/Code/feynman`, preserve the existing dirty `CHANGELOG.md`, refresh live GitHub/package/release/branch state, classify open issues/PRs, and run repo-local validation without GitHub writes. - Checked: Current branch remains `codex/fix-feynman-user-issues` at `8ad8d55` tracking `origin/codex/fix-feynman-user-issues`; `origin/main` remains `54d08a3`. Live queue remains issues `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, `#182` and PRs `#192`, `#191`, `#189`. Latest `main` `Publish and Release` run remains `28835967900`, green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` remains `0.3.5`; local candidate remains `0.3.6`; Pi remains latest/current at `0.80.6`; alpha-hub remains latest/current at `0.1.3`. - Decisions: No new code changes. Keep draft PR `#192` as the merge path for `#182`, `#185`, `#186`, `#187`, `#188`, and `#190`; it already includes contributor PR `#189` as cherry-pick `79aa7b2` with original authorship. Reject/defer PR `#191` because a new `feynman extensions` inventory command is broader than the `update --extensions` help/update failure requires and its Vercel check is failing. Issue `#184` remains outside Feynman's AI-researcher product bar. - Contributor refs: `origin/fix/deepresearch-local-model-warning`, `pr4fork/main`, and older fork refs were checked as remote branch state; none introduced a current safe port target beyond `#189`, already included in `#192`. - Freshness: `npm outdated --long` shows non-security drift only (`@clack/prompts`, OpenTelemetry packages, TypeBox, Node types, fast-xml-parser, lucide-react, patristic, posthog-node, radix-ui, tsx, TypeScript, undici, vite). No dependency change was made. - Verified: `npm test` passed (`593/593`); `npm run typecheck`; `npm run architecture:check` with existing split-debt warnings; root `npm run build` with existing Vite/RDKit/3Dmol warnings; root and website `npm audit --omit=dev` (`0 vulnerabilities`); website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 402`, shasum `167a902ecc8b2ea71e6b3402052f3a45c7ab2b11`); corrected installed-tarball smoke proved `feynman --version`, `feynman --help`, `feynman packages list`, `feynman alpha status`, package `0.3.6`, Pi `0.80.6`, alpha-hub `^0.1.3`, bundled `alt+enter`, and runtime archive entries for `pi-btw`, `pi-web-access`, and `@earendil-works/pi-coding-agent`. - Note: An initial installed-smoke wrapper hit the known mixed `npm pack --json` log parser issue; it was rerun with a stricter extractor and passed. Generated temp installs and tarballs were removed. - Next: Review/merge/publish PR `#192` when authorized; keep PR `#191` out unless product scope explicitly expands to extension inventory. ### 2026-07-11 01:29 EDT — intake-sweep-pr-192-still-clean - Objective: Re-run `check-new-issues` from `/Users/advaitpaliwal/Companion/Code/feynman`, preserve existing local work, refresh live GitHub/package/release/branch state, classify every open issue/PR, and run repo-local validation without GitHub writes. - Checked: Current branch remains `codex/fix-feynman-user-issues` at `8ad8d55` tracking `origin/codex/fix-feynman-user-issues`; pre-existing dirty state was `CHANGELOG.md` only. Live queue remains issues `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, `#182` and PRs `#192`, `#191`, `#189`. Latest `main` `Publish and Release` run remains `28835967900`, green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` remains `0.3.5`; local candidate remains `0.3.6`; Pi remains latest/current at `0.80.6`; alpha-hub remains latest/current at `0.1.3`. - Decisions: No new code changes. Keep PR `#192` as the merge path for `#182`, `#185`, `#186`, `#187`, `#188`, and `#190`; it already includes contributor PR `#189` as cherry-pick `79aa7b2`. Reject/defer PR `#191` because `feynman extensions` is broader extension-inventory surface than the reported update/help failure needs and has a failing Vercel status. Issue `#184` remains outside Feynman's AI-researcher product bar. - Contributor refs: `origin/fix/deepresearch-local-model-warning`, `pr4fork/main`, and older fork refs were observed; none introduced a current safe port target beyond `#189`, already included in `#192`. - Verified: `npm test` passed (`593/593`); `npm run typecheck`; `npm run architecture:check` with existing split-debt warnings; root `npm run build` with existing Vite/RDKit/3Dmol warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 402`, shasum `167a902ecc8b2ea71e6b3402052f3a45c7ab2b11`); installed tarball smoke proved `feynman --version`, `feynman --help`, `feynman packages list`, `feynman alpha status`, package `0.3.6`, Pi `0.80.6`, alpha-hub `0.1.3`, bundled `alt+enter`, staged Windows installer extraction, fetch cache patch, and alphaXiv OAuth2 patch. Direct archive listing proved bundled `pi-btw` and `pi-web-access`. - Note: Earlier smoke wrappers failed only from parser/probe mistakes: mixed `npm pack --json` logs, package export restrictions on direct `package.json` requires, and a stale runtime archive prefix. Corrected checks passed and temp artifacts were removed. - Next: Review/merge/publish PR `#192` when authorized; keep PR `#191` out unless product scope explicitly expands to extension inventory. ### 2026-07-10 21:13 EDT — intake-sweep-pr-192-still-clean - Objective: Re-run `check-new-issues` from `/Users/advaitpaliwal/Companion/Code/feynman`, preserve existing local work, refresh live GitHub/package/release state, classify every open issue/PR, and run repo-local validation without GitHub writes. - Checked: Current branch is `codex/fix-feynman-user-issues` at `8ad8d55` tracking `origin/codex/fix-feynman-user-issues`; pre-existing dirty state was `CHANGELOG.md` only. Live queue remains issues `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, `#182` and PRs `#192`, `#191`, `#189`. Latest `main` `Publish and Release` run remains `28835967900`, green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` remains `0.3.5`; local candidate remains `0.3.6`; Pi remains latest/current at `0.80.6`; alpha-hub remains latest/current at `0.1.3`. - Decisions: No new code changes. Keep PR `#192` as the merge path for `#182`, `#185`, `#186`, `#187`, `#188`, and `#190`; it already includes contributor PR `#189` as cherry-pick `79aa7b2`. Reject/defer PR `#191` because `feynman extensions` is broader extension-inventory surface than the reported update/help failure needs. Issue `#184` remains outside Feynman's AI-researcher product bar. - Contributor refs: `origin/fix/deepresearch-local-model-warning` and `pr4fork/main` were the only non-main refs observed; neither introduced a current safe port target for this queue. - Verified: `npm test` passed (`593/593`); `npm run typecheck`; `npm run architecture:check` with existing split-debt warnings; root `npm run build` with existing Vite/RDKit/3Dmol warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 402`, shasum `167a902ecc8b2ea71e6b3402052f3a45c7ab2b11`); installed tarball smoke proved `feynman --version`, `feynman --help`, `feynman packages list`, package `0.3.6`, Pi `0.80.6`, bundled `alt+enter`, staged Windows installer extraction, fetch cache patch, alphaXiv OAuth2 patch, runtime archive, and bundled `pi-btw`/`pi-web-access` archive entries. - Note: The smoke command exited `141` only after successful checks because `tar | grep | head` hit SIGPIPE under `pipefail`; temp install and tarball artifacts were removed. - Next: Review/merge/publish PR `#192` when authorized; keep PR `#191` out unless product scope explicitly expands to extension inventory. ### 2026-07-10 17:12 EDT — intake-sweep-pr-192-validated - Objective: Re-run `check-new-issues` from the current `codex/fix-feynman-user-issues` checkout, preserve local branch state, and classify the now-open issues/PRs without GitHub writes. - Checked: Current branch tracks `origin/codex/fix-feynman-user-issues` at `8ad8d55` with no dirty files. Open issues are `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`. Open PRs are `#192`, `#191`, and `#189`. Latest `main` `Publish and Release` run remains `28835967900`, green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest remains `0.3.5`; local candidate is `0.3.6`; Pi latest/current is `0.80.6`; alpha-hub latest/current is `0.1.3`. - Decisions: PR `#192` is the preferred merge path after review because it bundles the smallest research-loop reliability fixes for `#182`, `#185`, `#186`, `#187`, `#188`, and `#190`, includes contributor PR `#189` as a cherry-pick, and leaves `#191` out. PR `#189` should be ported via `#192` rather than merged separately. PR `#191` should be rejected/deferred because a new `feynman extensions` management/discovery surface is broader than the issue requires; update guidance is enough for `#187`. Issue `#184` remains outside the AI-researcher product bar as support/advice. - Contributor refs: Existing fork refs remain stale or broad provider/admin/platform churn. No additional contributor branch was ported beyond `#189`, which is already included in local PR `#192` as commit `79aa7b2`. - Freshness: `npm outdated --long` shows non-security dependency drift only (`@clack/prompts`, OpenTelemetry packages, TypeBox, Node types, fast-xml-parser, lucide-react, patristic, posthog-node, radix-ui, tsx, TypeScript, undici, vite). No queue-specific freshness patch was needed. - Verified: Focused regressions passed (`88/88`); full `npm test` passed (`593/593`), including the two workbench tests that failed in the prior run; `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/chunk warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 402`, shasum `167a902ecc8b2ea71e6b3402052f3a45c7ab2b11`); installed tarball smoke passed for `feynman --version`, `feynman --help`, `feynman packages list`, package `0.3.6`, Pi `0.80.6`, bundled `alt+enter` keybinding, staged Windows installer extraction, runtime archive presence, fetch cache patch, and alphaXiv OAuth2 patch. - Note: A first installed-smoke helper failed only because it parsed mixed `npm pack --json` logs and then used overly literal probe strings. The corrected smoke passed and temp tarball artifacts were removed. - Next: Review and merge/publish PR `#192` when authorized; leave `#191` out unless the product scope explicitly expands to extension inventory. ### 2026-07-10 13:14 EDT — intake-sweep-current-queue-flaky-workbench - Objective: Re-run `check-new-issues` against the current dirty checkout, preserve pending Pi `0.80.6`, alpha OAuth, and Windows installer work, and verify whether the live queue or local validation requires another local fix. - Checked: Local `main` remains aligned with `origin/main` at `54d08a3`. Live GitHub queue still has open issues `#186`, `#185`, `#184`, and `#182`, with zero open PRs. Latest `main` `Publish and Release` run `28835967900` is green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest/current remains `0.3.5`; `@earendil-works/pi-coding-agent` latest/current is `0.80.6`; `@companion-ai/alpha-hub` latest/current is `0.1.3`. - Decisions: No new code changes were needed. Issue `#186` remains covered by the pending staged Windows installer extraction fix; issue `#185` remains covered by bundled `pi-btw`; issue `#184` remains outside the AI-researcher product bar as support/advice; issue `#182` remains covered by the pending alphaXiv OAuth2 endpoint patch. No PRs were available to merge, port, reject, or defer. - Contributor refs: `origin/fix/deepresearch-local-model-warning` is behind current `main` with one already-covered ahead commit. Sampled fork refs were behind by 91-142 commits with Bedrock/provider setup, Overleaf/export/admin prompts, Claude CLI bypass, architecture notes, fork-specific search tooling, or broad Windows/platform churn; no clean core-research patch was ported. - Freshness: Root `npm outdated --json` shows non-security dependency drift only, with Pi already current at `0.80.6`. Root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: Root `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/chunk/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `78cbe7bc2a43ce7aec95c42c10077b4754a9afe1`); installed tarball smoke reached `feynman --version`, `feynman --help`, `feynman packages list`, `feynman alpha status`, packaged `scripts/install/install.ps1` staged-extraction checks, and runtime archive inspection showing `api.alphaxiv.org/auth`, `oauth2/authorize`, and `openid profile email offline_access`. - Validation note: The full `npm test` run failed `2/589` in `tests/workbench.test.ts` (`notebook Python session kernel persists variables across cells` saw one execution record instead of two; `workbench server streams chat messages through the authenticated API` saw missing final message status). The same two tests passed when rerun in isolation with `node --import tsx --test --test-concurrency=1 --test-name-pattern='notebook Python session kernel persists variables across cells|workbench server streams chat messages through the authenticated API' tests/workbench.test.ts`, so this remains a repo-local full-suite flake/failure to investigate. - Note: The first real-pack smoke parser failed on mixed `npm pack --json` logs, and the corrected smoke later failed only because it expected `website/public/install.ps1` inside the npm package. The shipped package includes `scripts/install/install.ps1`, which was verified; temp smoke artifacts and the root tarball were removed. - Next: Investigate the two full-suite workbench flakes before claiming a fully green local validation ladder; commit or push only when explicitly authorized. ### 2026-07-10 09:09 EDT — intake-sweep-windows-installer-staging - Objective: Re-run `check-new-issues` against the current dirty checkout, preserve the pending Pi `0.80.6` and alpha OAuth work, and evaluate the new Windows installer issue. - Checked: Local `main` remains aligned with `origin/main` at `54d08a3`. Live GitHub queue has open issues `#186`, `#185`, `#184`, and `#182`, with zero open PRs. Latest `main` `Publish and Release` run `28835967900` is green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest/current remains `0.3.5`; `@companion-ai/alpha-hub` latest/current remains `0.1.3`; `@earendil-works/pi-*` remains `0.80.6`; root and website have non-security dependency drift only. - Decisions: Ported the smallest safe fix for issue `#186` because install reliability supports Feynman's research-loop reliability. The Windows installer now extracts the release zip into temp staging, validates the expected bundle directory, then swaps that bundle into `%LOCALAPPDATA%\Programs\feynman`, avoiding `Expand-Archive -Force` cleanup against the live install root. Issue `#185` remains covered by bundled `pi-btw`; issue `#184` remains outside the AI-researcher product bar; issue `#182` remains covered by the pending alphaXiv OAuth2 endpoint patch. No PRs to merge, port, reject, or defer. - Contributor refs: Configured refs remain stale or non-actionable. `origin/fix/deepresearch-local-model-warning` is behind current `main` with one already-covered ahead commit; `pr4fork/main` is behind with zero ahead. Sampled fork refs remain older provider/setup/platform/admin or broad fork work rather than a fresh core research-loop fix. - Changed: Updated `scripts/install/install.ps1`, synced `website/public/install.ps1`, and added `tests/install-windows.test.ts`. Existing dirty changes in `package.json`, `package-lock.json`, `scripts/lib/alpha-hub-auth-patch.mjs`, `scripts/prepare-runtime-workspace.mjs`, `src/pi/package-ops.ts`, and `tests/alpha-hub-auth-patch.test.ts` were preserved. - Verified: Focused installer tests passed (`6/6`); full `npm test` passed (`588/588`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/chunk/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `53c8090ca3fb238122d5f0942b0fee5c99b692b0`); real installed tarball smoke passed for `feynman --version`, `feynman --help`, `feynman packages list`, `feynman alpha status`, and packaged `install.ps1` staged-extraction checks. No local PowerShell runtime was available for a live Windows script execution. - Next: Commit or push only when explicitly authorized; otherwise keep the Windows installer staging fix, Pi `0.80.6` refresh, and alpha OAuth patch local-only. ### 2026-07-09 21:15 EDT — intake-sweep-pi-0806-refresh - Objective: Re-run the `check-new-issues` intake sweep against the current dirty checkout, preserve unrelated local work, and port only safe core-research/runtime fixes. - Checked: Local `main` remains aligned with `origin/main` at `54d08a3`. Live GitHub queue still has open issues `#185`, `#184`, and `#182`, with zero open PRs. Latest `main` `Publish and Release` run `28835967900` is green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest/current remains `0.3.5`; `@companion-ai/alpha-hub` latest/current remains `0.1.3`; `pi-btw` latest/current remains `0.4.1`; `@earendil-works/pi-*` latest is now `0.80.6`. - Decisions: Ported the smallest safe runtime freshness fix by bumping Feynman's pinned Pi runtime packages from the pending `0.80.5` refresh to `0.80.6`. The upstream package diff directly affects the research loop: post-compaction output-token budgeting, GPT-5.6/GPT-5.5 long-context cost accounting, OpenAI cache-write usage accounting, GPT-5.6 Codex metadata, `max` thinking-level support, Claude thinking-block preservation, and `shellPath` home expansion. Issue `#182` remains locally covered by the pending alphaXiv OAuth2 endpoint patch; issue `#185` remains covered by bundled `pi-btw`; issue `#184` remains outside Feynman's AI-researcher product bar as support/advice. No PRs to merge, port, reject, or defer. - Contributor refs: Configured refs remain stale or non-actionable. `origin/fix/deepresearch-local-model-warning` is behind current `main` with one already-covered ahead commit; `pr4fork/main` is behind with zero ahead. Sampled fork refs are still behind current `main` with small ahead diffs in old provider/setup/platform/fork-specific lanes rather than fresh core research-loop fixes. - Changed: Updated `package.json` and `package-lock.json` to `@earendil-works/pi-agent-core`, `pi-ai`, `pi-coding-agent`, and `pi-tui` `0.80.6`; updated Pi runtime fallback constants in `src/pi/package-ops.ts` and `scripts/prepare-runtime-workspace.mjs`. - Freshness: Root `npm outdated --long --json` now shows non-Pi dependency drift only; website drift remains non-security dependency drift. Root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: Focused package/runtime/alpha tests passed (`27/27`); full `npm test` passed (`586/586`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/chunk/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `35c88e81b93f395c695cab93e46bbde1f6f27bd6`); real tarball smoke passed for `feynman --version`, current help, `feynman packages list` showing `npm:pi-btw`, `feynman alpha status`, installed Pi `0.80.6`, runtime archive Pi `0.80.6`, runtime `pi-btw` `0.4.1`, and alpha OAuth2 runtime archive inspection. - Note: The real-pack metadata parser again hit mixed prepack logs/JSON after the tarball was created; the produced tarball was used directly. A first installed-smoke assertion looked for Pi under a nested dependency path and failed after npm hoisted Pi to top-level; the corrected direct package metadata check passed. Temp smoke artifacts and the root tarball were removed. - Next: Commit or push only when explicitly authorized; otherwise keep the local Pi `0.80.6` refresh plus existing alpha OAuth patch local-only. ### 2026-07-08 21:03 EDT — intake-sweep-no-new-action - Objective: Re-run the `check-new-issues` intake sweep against the current Feynman checkout, preserving the pending alpha-auth patch while checking live GitHub issues/PRs, contributor refs, main workflows, release/package state, freshness, and local validation. - Checked: Local `main` and `origin/main` both resolve to `54d08a3` after fetch. Open issues remain `#185`, `#184`, and `#182`; open PR list is empty. Latest `main` `Publish and Release` run remains `28835967900`, succeeded at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest remains `0.3.5`; Pi latest/current remains `0.80.3`; alpha-hub latest/current remains `0.1.3`; `pi-btw` latest/current remains `0.4.1`. - Decisions: No new queue-driven code changes were needed. `#182` remains locally actionable but already covered by the pending local alpha-hub auth compatibility patch that rewrites bundled auth to `https://api.alphaxiv.org/auth/oauth2/*` with `openid profile email offline_access`. `#185` remains covered by bundled `pi-btw`, which directly improves long-running research-loop steering. `#184` remains outside Feynman's AI-researcher product bar as support/advice rather than a repo feature. There were no PRs to merge, port, reject, or defer. - Contributor state: Configured contributor refs are stale, behind, or non-actionable. `origin/fix/deepresearch-local-model-warning` is behind by 74 commits with one ahead local-model-warning commit; `pr4fork/main` is behind by 73 with zero ahead. Sampled fork refs were behind by 91-142 commits with small ahead diffs focused on provider setup, Overleaf/export/admin prompts, Claude CLI bypass, architecture notes, fork-specific search tooling, broad platform churn, or runtime/setup churn; none was a clean core-research patch to port in this run. - Freshness: Root and website have dependency drift only. Root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: Focused alpha/runtime tests passed (`16/16`); full `npm test` passed (`586/586`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/chunk/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `01d621ba42cd8d159489a18aef58778887ade7e9`); real installed tarball smoke passed for `feynman --version`, `feynman --help`, `feynman packages list`, `feynman alpha status`, alpha OAuth2 runtime archive inspection, and bundled `pi-btw` archive files. The first installed-smoke wrapper failed before install because it parsed `[feynman]` prepack logs as JSON; the corrected parser succeeded, and temp smoke artifacts were removed. - Next: Commit or push only if explicitly authorized; otherwise keep the local alpha auth compatibility patch pending review. ### 2026-07-08 16:58 EDT — intake-sweep-no-new-action - Objective: Re-run the `check-new-issues` intake sweep against the current Feynman checkout, preserving existing local alpha-auth patch work while checking live GitHub issues/PRs, contributor branches, main workflows, release/package state, freshness, and validation. - Checked: Local `main` and `origin/main` both resolve to `54d08a3`. Open issues are `#185`, `#184`, and `#182`; open PR list is empty. Latest `main` `Publish and Release` run remains `28835967900`, succeeded at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest remains `0.3.5`; Pi latest/current remains `0.80.3`; alpha-hub latest/current remains `0.1.3`; `pi-btw` latest/current remains `0.4.1`. - Decisions: No new queue-driven code changes were needed. `#182` remains locally actionable but already covered by the pending local alpha-hub auth compatibility patch. `#185` remains covered by bundled `pi-btw`, which directly improves long-running research-loop steering. `#184` remains outside Feynman's AI-researcher product bar as support/advice rather than a repo feature. There were no PRs to merge, port, reject, or defer. - Contributor state: Configured contributor refs are stale, behind, or non-actionable. `origin/fix/deepresearch-local-model-warning` is behind by 74 commits with one local-model-warning commit ahead; `pr4fork/main` is behind by 73 with zero ahead. Sampled fork refs were behind by 91-142 commits with small ahead diffs focused on Overleaf/export/admin prompts, broad platform churn, provider setup, Claude CLI bypass, architecture notes, or fork-specific search tooling; none was a clean core-research patch to port in this run. - Freshness: Root and website have dependency drift only. Root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: Focused alpha/runtime tests passed (`16/16`); full `npm test` passed (`586/586`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/chunk/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34 pages`); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `01d621ba42cd8d159489a18aef58778887ade7e9`); real installed tarball smoke from `/tmp/feynman-pack-smoke-lcIijJ/` passed for `feynman --version`, `feynman --help`, `feynman packages list`, `feynman alpha status`, alpha OAuth2 runtime archive inspection, and bundled `pi-btw` archive files. The temp smoke directory and root tarball were removed. - Next: Commit or push only if explicitly authorized; otherwise keep the local alpha auth compatibility patch pending review. ### 2026-07-08 12:56 EDT — intake-sweep-no-new-action - Objective: Re-run the `check-new-issues` intake sweep against the current Feynman checkout, preserving existing local work while checking live GitHub issues/PRs, contributor branches/forks, main workflows, release/package state, freshness, and local validation. - Checked: Local `main` is aligned with `origin/main` at `54d08a3` after fetch. Open issues remain `#185`, `#184`, and `#182`; open PR list is empty. Issue `#182`'s newest comment still matches the already-pending alphaXiv OAuth2 endpoint/scope patch. Latest `main` `Publish and Release` run is `28835967900`, succeeded at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest/current remains `0.3.5`; Pi latest/current remains `0.80.3`; alpha-hub latest/current remains `0.1.3`; `pi-btw` latest/current remains `0.4.1`. - Decisions: No new queue-driven code changes were needed. `#182` remains the only locally actionable issue and is already covered by the pending local alpha-hub auth compatibility patch that rewrites bundled auth to `https://api.alphaxiv.org/auth/oauth2/*` with `openid profile email offline_access`. `#185` remains covered by bundled `pi-btw`, which directly improves long-running research-loop steering. `#184` remains outside Feynman's AI-researcher product bar as support/advice rather than a repo feature. There were no PRs to merge, port, reject, or defer. - Contributor/fork state: Configured contributor refs are behind, stale, or old already-reviewed changes. `origin/fix/deepresearch-local-model-warning` is behind by 74 commits with one ahead local-model warning commit; `pr4fork/main` is behind by 73 commits with zero ahead commits. Recent public fork heads checked: `QuantumKuba/feynman`, `ivnvalex/feynman`, and `colindomoney/feynman` match `54d08a3`; `ussdeveloper/feynman` is behind at `fa26693`; `advaitpaliwal/feynman` is behind at `cb5fa56`. - Freshness: Root and website have dependency drift only. Root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: Focused alpha/runtime tests passed (`16/16`); full `npm test` passed (`586/586`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/chunk/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34 pages`); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `01d621ba42cd8d159489a18aef58778887ade7e9`); real installed tarball smoke from `/tmp/feynman-pack-smoke-OqsQM0/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, `feynman --help`, `feynman packages list`, `feynman alpha status`, and runtime archive inspection for `api.alphaxiv.org/auth`, `oauth2/authorize`, `oauth2/token`, `oauth2/register`, `oauth2/userinfo`, `openid profile email offline_access`, and bundled `pi-btw`. - Next: Commit or push only if explicitly authorized; otherwise keep the local alpha auth compatibility patch pending review. ### 2026-07-08 08:54 EDT — intake-sweep-no-new-action - Objective: Re-run the `check-new-issues` intake sweep against the current Feynman checkout, preserving existing local work while checking live GitHub issues/PRs, contributor refs/forks, workflows, release/package state, freshness, and local validation. - Checked: Local `main` is aligned with `origin/main` at `54d08a3` after fetch. Open issues remain `#185`, `#184`, and `#182`; open PR list is empty. Issue `#182` has a new comment suggesting the same alphaXiv OAuth2 endpoint/scope rewrite already present in the pending local patch. Latest `main` `Publish and Release` run is `28835967900`, succeeded at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest/current remains `0.3.5`; Pi latest/current remains `0.80.3`; alpha-hub latest/current remains `0.1.3`; `pi-btw` latest/current remains `0.4.1`. - Decisions: No new queue-driven code changes were needed. `#182` remains the only locally actionable issue and is already covered by the pending local alpha-hub auth compatibility patch that rewrites bundled auth to `https://api.alphaxiv.org/auth/oauth2/*` with `openid profile email offline_access`. `#185` remains covered by bundled `pi-btw`, which directly improves long-running research-loop steering. `#184` remains outside Feynman's AI-researcher product bar as support/advice rather than a repo feature. There were no PRs to merge, port, reject, or defer. - Contributor/fork state: Configured contributor refs are behind, stale, or old already-reviewed changes. `origin/fix/deepresearch-local-model-warning` is behind by 74 commits with one ahead local-model warning commit; `pr4fork/main` is behind by 73 commits with zero ahead commits. Recent public fork discovery showed `colindomoney/feynman` identical to `main`; `ussdeveloper/feynman` and `advaitpaliwal/feynman` are behind with zero ahead commits. - Freshness: Root and website have dependency drift only. Root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: Focused alpha/runtime tests passed (`16/16`); full `npm test` passed (`586/586`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/chunk/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34 pages`); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `01d621ba42cd8d159489a18aef58778887ade7e9`); real installed tarball smoke from `/tmp/feynman-pack-smoke-x31nAy/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, `feynman --help`, `feynman packages list`, `feynman alpha status`, and runtime archive inspection for `api.alphaxiv.org/auth`, `oauth2/authorize`, `oauth2/token`, `oauth2/register`, `oauth2/userinfo`, `openid profile email offline_access`, and bundled `pi-btw`. - Note: The first installed-smoke wrapper exited nonzero after successful CLI checks because it looked for `package/npm/...` inside the nested runtime archive; the correct nested path is `npm/node_modules/...`, and the follow-up archive inspection passed. The temp smoke directory was removed. - Next: Commit or push only if explicitly authorized; otherwise keep the local alpha auth compatibility patch pending review. ### 2026-07-08 04:53 EDT — intake-sweep-no-new-action - Objective: Re-run the `check-new-issues` intake sweep against the current Feynman checkout, preserving existing local work while checking live GitHub issues/PRs, contributor refs/forks, workflows, release/package state, freshness, and local validation. - Checked: Local `main` is aligned with `origin/main` at `54d08a3` after fetch. Open issues remain `#185`, `#184`, and `#182`; open PR list is empty. Latest `main` `Publish and Release` run is `28835967900`, succeeded at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest/current remains `0.3.5`; Pi latest/current remains `0.80.3`; alpha-hub latest/current remains `0.1.3`; `pi-btw` latest/current remains `0.4.1` with Pi peer range `>=0.74.0 <1`. - Decisions: No new queue-driven code changes were needed. `#182` remains the only locally actionable issue and is already covered by the pending local alpha-hub auth compatibility patch that rewrites bundled auth to `https://api.alphaxiv.org/auth/oauth2/*` with `openid profile email offline_access`. `#185` remains covered by bundled `pi-btw`, which directly improves long-running research-loop steering. `#184` remains outside Feynman's AI-researcher product bar as support/advice rather than a repo feature. There were no PRs to merge, port, reject, or defer. - Contributor/fork state: Configured contributor refs are behind, stale, or broad fork-specific churn. `pr4fork/main` is behind by 73 commits with zero ahead commits; `origin/fix/deepresearch-local-model-warning` is behind by 74 commits with one already-considered ahead commit. Public fork discovery showed only `advaitpaliwal/feynman` as recently pushed, still behind current `origin/main` at `cb5fa56`. - Freshness: Root and website have dependency drift only. Root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: Focused alpha/runtime tests passed (`16/16`); full `npm test` passed (`586/586`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/chunk/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34 pages`); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `01d621ba42cd8d159489a18aef58778887ade7e9`); real installed tarball smoke from `/tmp/feynman-pack-smoke-nGtsGm/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, `feynman --help`, `feynman packages list`, `feynman alpha status`, and runtime archive inspection for `api.alphaxiv.org/auth`, `oauth2/authorize`, `openid profile email offline_access`, and bundled `pi-btw`. - Next: Commit or push only if explicitly authorized; otherwise keep the local alpha auth compatibility patch pending review. ### 2026-07-08 00:52 EDT — intake-sweep-alpha-auth-patch-validated - Objective: Re-run the `check-new-issues` intake sweep against the current Feynman checkout, preserve existing local work, and verify whether fresh GitHub, release, package, contributor, or validation state requires another change. - Checked: Live GitHub queue still has open issues `#185`, `#184`, and `#182`, with zero open PRs. Latest `main` publish run is `Publish and Release` `28835967900`, green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest/current remains `0.3.5`; Pi latest/current is `0.80.3`; alpha-hub latest/current is `0.1.3`; `pi-btw` latest/current is `0.4.1` with Pi peer range `>=0.74.0 <1`. The newest public forks checked, `founderqiang/feynman` and `colindomoney/feynman`, are identical to `main`; `ussdeveloper/feynman`, `Sourabhsubhasish/feynman`, and `advaitpaliwal/feynman` are behind with zero ahead commits. Configured contributor remotes remain stale or behind. - Decisions: No new code changes were needed beyond the existing local `#182` alpha auth compatibility patch. Issue `#182` remains the only locally actionable queue item because its newest comment points at alphaXiv's migrated OAuth endpoints and the local package patch already rewrites bundled alpha-hub auth to `https://api.alphaxiv.org/auth/oauth2/*` with `openid profile email offline_access`. Issue `#185` remains covered by bundled `pi-btw`, which directly improves long-running research-loop steering. Issue `#184` remains outside Feynman's AI-researcher product bar as support/advice, not a repo feature. No PRs to merge, port, reject, or defer. - Freshness: Root and website have dependency drift only. Root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: Full `npm test` passed (`586/586`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34 pages`); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `01d621ba42cd8d159489a18aef58778887ade7e9`); real tarball smoke from `/tmp/feynman-pack-smoke-8S4oAQ/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, `feynman --help`, `feynman packages list`, `feynman alpha status`, and runtime archive inspection for `api.alphaxiv.org/auth`, `oauth2/authorize`, `openid profile email offline_access`, and bundled `pi-btw`. - Next: Commit or push only when explicitly authorized; otherwise keep the local alpha auth compatibility patch pending review. ### 2026-07-07 21:07 EDT — check-new-issues-alpha-auth-endpoint - Objective: Run the recurring Feynman intake sweep against live GitHub issues, PRs, contributor branches/forks, recent main workflows, release/npm state, package freshness, and local validation while preserving unrelated worktree changes. - Checked: Live open issues stayed `#185`, `#184`, and `#182`; open PR list was empty; local `main` is aligned with `origin/main` at `54d08a3`; latest `main` `Publish and Release` run `28835967900` succeeded at `54d08a3`; latest GitHub release and npm package remain `v0.3.5` / `@companion-ai/feynman@0.3.5`; runtime/package versions remain `@earendil-works/pi-coding-agent@0.80.3`, `@companion-ai/alpha-hub@0.1.3`, and `pi-btw@0.4.1`. New public fork `colindomoney/feynman` is identical to `main`; recent forks `ussdeveloper`, `advaitpaliwal`, `skandanyal`, and `gaurav-g-alva` are behind with zero ahead commits; configured contributor refs are old/behind or non-actionable. - Decisions: Ported the safe core of the new `#182` evidence by updating Feynman's alpha-hub runtime patch to use alphaXiv's current `https://api.alphaxiv.org/auth/oauth2/*` endpoints and `openid profile email offline_access` scope. This directly restores a research-source login path without taking the fork's broader search-mode collapse or manual-token workflow. `#185` remains covered on `main` by bundled `pi-btw`; `#184` remains outside the AI-researcher product bar as support/advice. No open PRs needed merge/port/reject/defer action. - Changed: `scripts/lib/alpha-hub-auth-patch.mjs` rewrites legacy Clerk endpoint constants to the current alphaXiv OAuth2 host; `scripts/prepare-runtime-workspace.mjs` now hashes/imports/applies the auth patch when building `.feynman/runtime-workspace.tgz`; `tests/alpha-hub-auth-patch.test.ts` covers the endpoint rewrite. - Verified: `node --import tsx --test --test-concurrency=1 tests/alpha-hub-auth-patch.test.ts tests/package-seeding.test.ts` (`16/16`); full `npm test` twice after the endpoint patch (`586/586`, final run `586/586` after the runtime-archive fix); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34 pages`); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` with `entryCount: 401`, shasum `01d621ba42cd8d159489a18aef58778887ade7e9`; actual temp tarball smoke from `/tmp/feynman-pack-smoke-e3qffD/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, `feynman --help`, `feynman packages list` showing `npm:@companion-ai/alpha-hub` and `npm:pi-btw`, `feynman alpha status`, and nested runtime archive inspection showing `api.alphaxiv.org/auth`, `oauth2/authorize`, and `openid profile email offline_access`. - Next: Keep the patch local until explicitly authorized to commit/push; issue `#182` can be rechecked with a fresh logged-out login flow when an affected user or release test environment is available. ### 2026-07-07 12:50 EDT — check-new-issues-clean-main - Objective: Run the recurring Feynman intake sweep against live GitHub issues, PRs, contributor branches/forks, recent main workflows, release/npm state, package freshness, and local validation while preserving unrelated worktree changes. - Checked: Live open issues stayed `#185`, `#184`, and `#182`; open PR list was empty; local `main` is aligned with `origin/main` at `54d08a3`; latest `main` `Publish and Release` run `28835967900` succeeded at `54d08a3`; latest GitHub release and npm package remain `v0.3.5` / `@companion-ai/feynman@0.3.5`; runtime/package versions remain `@earendil-works/pi-coding-agent@0.80.3`, `@companion-ai/alpha-hub@0.1.3`, and `pi-btw@0.4.1`; recent public forks checked (`nagyist/feynman`, `TheTechOddBug/feynman`, and `dubbypanda/feynman`) are identical to `main`, while `founderqiang/feynman`, `gaadha1985/feynman`, and `ussdeveloper/feynman` are behind by three commits with zero ahead commits. Configured contributor refs are old/behind or non-actionable. - Decisions: No queue-driven code changes were needed. `#185` remains covered on `main` by bundling existing `pi-btw` in the core Pi package stack because it improves long-running research-loop steering without inventing a Feynman-owned interrupt protocol. `#184` remains outside the AI-researcher product bar because it is a thesis-planning/support request, not a repo feature or defect. `#182` has one new affected-user comment but no new Feynman-owned repro or diagnostic; it remains deferred/external because Feynman delegates alpha auth to `@companion-ai/alpha-hub`, the installed alpha-hub source owns Clerk registration, localhost callback, token exchange, and auth storage, issue diagnostics still point at alphaXiv/Clerk redirect/token handoff outside Feynman, and the current installed-tarball `alpha status` succeeds. No open PRs needed merge/port/reject/defer action. - Freshness: Root and website have dependency drift only; root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: `npm test` (`585/585`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34 pages`); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` with `entryCount: 401`, shasum `dff26e588536c8184e30f2e39e208a47bea011c3`; actual temp tarball smoke from `/tmp/feynman-pack-smoke-I0Ypru/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, `feynman --help`, `feynman packages list` showing `npm:pi-btw` in Core, `feynman alpha status`, and runtime archive inspection for `npm/node_modules/pi-btw/package.json` plus `npm/node_modules/pi-btw/extensions/btw.ts`. - Next: Keep sweeps read-only unless a fresh Feynman-owned repro or core-research PR appears; current main contains unreleased workbench commits after `v0.3.5`. ### 2026-07-07 08:49 EDT — check-new-issues-clean-main - Objective: Run the recurring Feynman intake sweep against live GitHub issues, PRs, contributor branches/forks, recent main workflows, release/npm state, package freshness, and local validation while preserving unrelated worktree changes. - Checked: Live open issues stayed `#185`, `#184`, and `#182`; open PR list was empty; local `main` is aligned with `origin/main` at `54d08a3`; latest `main` `Publish and Release` run `28835967900` succeeded at `54d08a3`; latest GitHub release and npm package remain `v0.3.5` / `@companion-ai/feynman@0.3.5`; runtime/package versions remain `@earendil-works/pi-coding-agent@0.80.3`, `@companion-ai/alpha-hub@0.1.3`, and `pi-btw@0.4.1`; the newest public forks checked (`nagyist/feynman`, `TheTechOddBug/feynman`, and `dubbypanda/feynman`) are identical to `main`, while `founderqiang/feynman`, `gaadha1985/feynman`, and `ussdeveloper/feynman` are behind by three commits with zero ahead commits. Configured contributor refs are old/behind or non-actionable. - Decisions: No queue-driven code changes were needed. `#185` remains covered on `main` by bundling existing `pi-btw` in the core Pi package stack because it improves long-running research-loop steering without inventing a Feynman-owned interrupt protocol. `#184` remains outside the AI-researcher product bar because it is a thesis-planning/support request, not a repo feature or defect. `#182` remains deferred/external because Feynman delegates alpha auth to `@companion-ai/alpha-hub`, issue diagnostics point at alphaXiv/Clerk redirect/token handoff outside Feynman, and the current installed-tarball `alpha status` succeeds. No open PRs needed merge/port/reject/defer action. - Freshness: Root and website have dependency drift only; root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: `npm test` (`585/585`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34 pages`); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` with `entryCount: 401`, shasum `dff26e588536c8184e30f2e39e208a47bea011c3`; actual temp tarball smoke from `/tmp/feynman-pack-smoke-C38rex/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, `feynman --help`, `feynman packages list` showing `npm:pi-btw` in Core, `feynman alpha status`, and runtime archive inspection for `npm/node_modules/pi-btw/package.json` plus `npm/node_modules/pi-btw/extensions/btw.ts`. - Note: one real-pack metadata parser attempt failed after successful tarball creation because mixed prepack logs preceded/embedded JSON; the produced tarball was used directly for archive inspection and installed smoke. - Next: Keep sweeps read-only unless a fresh Feynman-owned repro or core-research PR appears; current main contains unreleased workbench commits after `v0.3.5`. ### 2026-07-07 04:48 EDT — check-new-issues-clean-main - Objective: Run the recurring Feynman intake sweep against live GitHub issues, PRs, contributor branches/forks, recent main workflows, release/npm state, package freshness, and local validation while preserving unrelated worktree changes. - Checked: Live open issues stayed `#185`, `#184`, and `#182`; open PR list was empty; local `main` is aligned with `origin/main` at `54d08a3`; latest `main` `Publish and Release` run `28835967900` succeeded at `54d08a3`; latest GitHub release and npm package remain `v0.3.5` / `@companion-ai/feynman@0.3.5`; runtime/package versions remain `@earendil-works/pi-coding-agent@0.80.3`, `@companion-ai/alpha-hub@0.1.3`, and `pi-btw@0.4.1`; the newest public fork checked (`ussdeveloper/feynman`) is behind main by three commits with zero ahead commits, and configured contributor refs are old/behind or non-actionable. - Decisions: No queue-driven code changes were needed. `#185` remains covered on `main` by bundling existing `pi-btw` in the core Pi package stack because it improves long-running research-loop steering without inventing a Feynman-owned interrupt protocol. `#184` remains outside the AI-researcher product bar because it is a thesis-planning/support request, not a repo feature or defect. `#182` remains deferred/external because Feynman delegates alpha auth to `@companion-ai/alpha-hub`, issue diagnostics point at alphaXiv/Clerk redirect/token handoff outside Feynman, and the current installed-tarball `alpha status` succeeds. No open PRs needed merge/port/reject/defer action. - Freshness: Root and website have dependency drift only; root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: `npm test` (`585/585`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34 pages`); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` with `entryCount: 401`, shasum `dff26e588536c8184e30f2e39e208a47bea011c3`; actual temp tarball smoke from `/tmp/feynman-pack-smoke-T0C0Hw/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, `feynman --help`, `feynman packages list` showing `npm:pi-btw` in Core, `feynman alpha status`, and runtime archive inspection for `npm/node_modules/pi-btw/package.json` plus `npm/node_modules/pi-btw/extensions/btw.ts`. - Next: Keep sweeps read-only unless a fresh Feynman-owned repro or core-research PR appears; current main contains unreleased workbench commits after `v0.3.5`. ### 2026-07-07 00:53 EDT — check-new-issues-clean-main - Objective: Run the recurring Feynman intake sweep against live GitHub issues, PRs, contributor branches/forks, recent main workflows, release/npm state, package freshness, and local validation while preserving unrelated worktree changes. - Checked: Live open issues stayed `#185`, `#184`, and `#182`; open PR list was empty; local `main` is aligned with `origin/main` at `54d08a3`; latest `main` `Publish and Release` run `28835967900` succeeded at `54d08a3`; latest GitHub release and npm package remain `v0.3.5` / `@companion-ai/feynman@0.3.5`; runtime/package versions remain `@earendil-works/pi-coding-agent@0.80.3`, `@companion-ai/alpha-hub@0.1.3`, and `pi-btw@0.4.1`; the two most recently pushed public forks (`founderqiang/feynman`, `ussdeveloper/feynman`) are both behind main by three commits with zero ahead commits, and configured contributor refs are old/behind or non-actionable. - Decisions: No queue-driven code changes were needed. `#185` remains covered on `main` by bundling existing `pi-btw` in the core Pi package stack because it improves long-running research-loop steering without inventing a Feynman-owned interrupt protocol. `#184` remains outside the AI-researcher product bar because it is a thesis-planning/support request, not a repo feature or defect. `#182` remains deferred/external because Feynman delegates alpha auth to `@companion-ai/alpha-hub`, issue diagnostics point at alphaXiv/Clerk redirect/token handoff outside Feynman, and the current installed-tarball `alpha status` succeeds. No open PRs needed merge/port/reject/defer action. - Freshness: Root and website have dependency drift only; root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: `npm test` (`585/585`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34 pages`); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` with `entryCount: 401`, shasum `dff26e588536c8184e30f2e39e208a47bea011c3`; actual temp tarball smoke from `/tmp/feynman-pack-smoke-PknUYQ/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, `feynman --help`, `feynman packages list` showing `npm:pi-btw` in Core, `feynman alpha status`, and runtime archive inspection for `npm/node_modules/pi-btw/package.json` plus `npm/node_modules/pi-btw/extensions/btw.ts`. - Next: Keep sweeps read-only unless a fresh Feynman-owned repro or core-research PR appears; current main contains unreleased workbench commits after `v0.3.5`. ### 2026-07-06 EDT — workbench-light-theme-parity - Objective: Close the biggest visual 1:1 gap. Drove the installed Claude Science app live (authenticated via `claude-science url`) and captured its real project frame: it is a clean LIGHT UI (`rgb(253,253,252)` background, near-black text, blue accent), not the dark-green theme the workbench had. Owner decision: match Claude's light layout with Feynman green as the single accent, and simplify the frame chrome. - Changed: Appended a light-theme override layer to `workbench-web/src/styles.css` that re-skins the frame surfaces (rail, conversation canvas, messages, generated tiles, composer, tab strip, files/side panels) to neutral light with `--cs-*` tokens and Feynman green (`#2f6a3d`) as the accent (links, active tab, selected session, send button). Hides the reference-absent chrome — top-bar status pills, model/session menus, and the context metric strip — to match Claude's quiet frame. Fixed the selected-session pill to a light-gray pill. - Verified: Focused source-contract tests pass; full `npm test` (`585/585`, Node 24); `build:workbench-web` green; live headless render on `/projects/workspace/frames/playwright` shows white rail/conversation/composer, hidden metric strip, green accent, and no console errors, matching the captured Claude Science reference frame. - Next: Tighten remaining details (composer column max-width/centering, generated-tile spacing) against the reference; regenerate stale dark-UI artifact thumbnails. ### 2026-07-06 EDT — workbench-center-tab-strip-parity - Objective: Finish the in-flight Claude Science parity slice that adds a Chat/Files tab strip to the workbench frame center pane, so Files can open in-place instead of only as a right-side panel. - Changed: Added a `CenterPane` state (`chat` | `files`) and a `.workspace-tab-strip` nav under the frame header; the transcript+composer render only on the Chat tab, and the existing `FilesPanel` (factored out once as `filesPanelElement` and reused by the side panel) mounts in a `.center-files-panel` on the Files tab. Rail Files button and the files toggle now switch the center pane. New session / run navigation resets the pane to Chat. - Verified: Full `npm test` (`585/585`) under Node 24; typecheck and `build:workbench-web` green; live headless render on `/projects/workspace/frames/playwright` confirmed both tabs present, Files tab shows the center files panel and hides the composer, Chat tab restores it, zero console errors. - Next: Continue the visual 1:1 parity pass against the installed Claude Science app. ### 2026-07-06 12:44 EDT — check-new-issues-clean-main - Objective: Run the recurring Feynman intake sweep against live GitHub issues, PRs, contributor branches, recent main workflows, release/npm state, package freshness, and repo-local validation while preserving active worktree edits. - Checked: Live open issues stayed `#185`, `#184`, and `#182`; open PR list was empty; `origin/main` stayed aligned with local `main` at `fa26693`; latest `main` `Publish and Release` run `28755882698` succeeded at `fa26693`; latest GitHub release and npm package remain `v0.3.5` / `@companion-ai/feynman@0.3.5`; installed/runtime package versions remain `@earendil-works/pi-coding-agent@0.80.3`, `@companion-ai/alpha-hub@0.1.3`, and `pi-btw@0.4.1`; contributor refs were stale behind `origin/main`, had no ahead diff, or contained provider/platform/export/prompt/admin/docs churn rather than a fresh research-loop fix. - Decisions: `#185` remains locally covered by bundling existing `pi-btw` in the core Pi package stack because it improves long-running research-loop steering without inventing a Feynman-owned interrupt mechanism. `#184` remains outside the AI-researcher product bar because it is a thesis-planning/support request, not a repo feature or defect. `#182` remains deferred/external because Feynman delegates alpha auth to `@companion-ai/alpha-hub`, issue diagnostics point to alphaXiv/Clerk redirecting away before localhost receives `code`, and the current installed-tarball `alpha status` succeeds. No open PRs needed merge/port/reject/defer action. No new queue-driven code changes were needed in this run. - Verified: `npm test` (`585/585`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`), and `npm run build` (`34 pages`); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` with `entryCount: 401`, shasum `cc7a11600c6ebf36481195626203769be3c52dcb`; actual temp tarball smoke from `/tmp/feynman-pack-smoke-dmOqSI/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, `feynman --help`, `feynman packages list` showing `npm:pi-btw` in Core, and `feynman alpha status` (`Logged in to alphaXiv as Advait Paliwal`); runtime archive inspection confirmed `npm/node_modules/pi-btw/package.json` and `npm/node_modules/pi-btw/extensions/btw.ts`. - Note: one first archive-inspection helper hit `ENOBUFS` because it buffered the embedded runtime tarball in Node; a second `tar`-based inspection verified the archive paths directly. - Next: Keep intake sweeps read-only unless a fresh Feynman-owned repro or core-research PR appears; the remaining dirty files are preserved active workbench/docs/package-stack edits plus append-only run notes. ### 2026-07-05 21:18 EDT — workbench-compact-composer-parity - Objective: Fix the live Claude Science parity mismatch where Feynman's frame composer stretched into a tall pale input slab with chunky light controls. - Changed: The React workbench composer now opts out of grid stretching, renders as a compact dark input strip, uses a transparent textarea with light text, and keeps the composer action/send buttons at compact 32px dark/green sizes. - Verified: Focused React/file-surface tests passed (`17/17`); root/workbench typecheck passed; `npm run build:workbench-web` passed with existing RDKit/3Dmol/patristic bundle warnings; headless browser verification on `session-20260705210923-1cb3e7` measured composer height `52.9px` instead of `304px`, 32px controls, transparent textarea background, and no side panel; full `npm test` passed (`585/585`). - Next: Continue the 1:1 workbench parity goal with the next live rendered mismatch. ### 2026-07-05 20:45 EDT — check-new-issues-clean-main - Objective: Run the recurring Feynman intake sweep against live GitHub issues, PRs, contributor branches, recent main workflows, release/npm state, package freshness, and repo-local validation while preserving active workbench edits. - Checked: Live open issues stayed `#182` and `#184`; open PR list was empty; `origin/main` is `fa26693`; latest `main` `Publish and Release` run `28755882698` succeeded at `fa26693`; latest GitHub release and npm package remain `v0.3.5` / `@companion-ai/feynman@0.3.5`; installed/runtime package versions remain `@earendil-works/pi-coding-agent@0.80.3` and `@companion-ai/alpha-hub@0.1.3`; contributor refs were stale relative to current `origin/main`, had no ahead diff, or contained adjacent platform/admin/export/prompt churn rather than a new research-loop fix. - Decisions: `#182` remains deferred/external because Feynman delegates alpha auth to `@companion-ai/alpha-hub`, issue diagnostics still point to alphaXiv/Clerk redirecting to the landing page before localhost receives `code`, and the current installed-tarball alpha status succeeds. `#184` remains outside the AI-researcher product bar because it is a thesis-planning/support request, not a repo feature or defect. No open PRs needed merge/port/reject/defer action. No queue-driven code changes were needed. - Verified: `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/patristic warnings; `npm run architecture:check` with existing split-debt warnings; full `npm test` (`585/585`); root and website `npm audit --omit=dev` (`0 vulnerabilities`); website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`), and `npm run build` (`34 pages`); `git diff --check`; `npm pack --dry-run --json` with `entryCount: 401`, shasum `047d3783178ab6ab5caa05d9c98b3cee005e28ff`; actual temp tarball smoke from `/tmp/feynman-pack-smoke-P1QWmm/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, `feynman --help`, and `feynman alpha status`. - Next: Keep intake sweeps read-only unless a fresh Feynman-owned repro or core-research PR appears; the remaining dirty files are unrelated active workbench edits plus append-only run notes. ### 2026-07-05 16:49 EDT — check-new-issues-clean-main - Objective: Run the recurring Feynman intake sweep against live GitHub issues, PRs, contributor branches, recent main workflows, release/npm state, package freshness, and local validation without disturbing unrelated workbench edits. - Checked: Live open issues stayed `#182` and `#184`; open PR list was empty; refreshed `origin/main` now points at `0fd15dd`; latest `main` `Publish and Release` run `28754199423` succeeded at `0fd15dd`; latest GitHub release and npm package remain `v0.3.5` / `@companion-ai/feynman@0.3.5`; installed runtime dependencies remain `@earendil-works/pi-coding-agent@0.80.3` and `@companion-ai/alpha-hub@0.1.3`; contributor refs were stale relative to `origin/main` or had no ahead diff. - Decisions: `#182` remains deferred/external because Feynman delegates alpha auth to `@companion-ai/alpha-hub`, the installed auth source owns the Clerk registration/localhost callback/token exchange flow, the issue evidence points to alphaXiv/Clerk redirecting away before localhost receives `code`, and current installed-tarball alpha status succeeds. `#184` remains outside the AI-researcher product bar because it is a thesis-planning/support request, not a repo feature or defect. No PRs to merge, port, reject, or defer. No queue-driven code changes were needed. - Verified: `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/patristic warnings; `npm run architecture:check` with existing split-debt warnings; full `npm test` (`585/585`); root `npm audit --omit=dev` (`0 vulnerabilities`); website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`), `npm run build` (`34 pages`), and `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` with `entryCount: 401`, shasum `5ed1945fd2a13d3a46ad44a41319815b06c5fa53`; actual temp tarball smoke from `/tmp/feynman-pack-smoke-MewoZd/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, `feynman --help`, and `feynman alpha status`. - Next: Keep intake sweeps read-only unless a fresh Feynman-owned repro or core-research PR appears; the remaining dirty files are unrelated active workbench edits plus append-only run notes. ### 2026-07-05 13:35 EDT — workbench-dark-main-surface-parity - Objective: Continue the Claude Science 1:1 workbench parity goal by moving the frame conversation surface from a light card-heavy canvas toward the reference dark project workspace. - Changed: The React workbench conversation area now uses a dark green canvas, dark topbar/context strip borders and chips, dark assistant/user message surfaces, light transcript text, and a dark disabled-send state while keeping the composer input readable. The change is scoped to the in-frame workbench surface and leaves menus, launcher cards, and the underlying chat/artifact mechanics intact. - Verified: Focused React/file-surface tests passed (`17/17`); root/workbench typecheck passed; `npm run build:workbench-web` passed with existing science-viewer bundle warnings; headless browser verification on `session-20260705160452-ae55be` showed conversation background `rgb(32, 37, 31)`, topbar border `rgb(52, 60, 50)`, title color `rgb(245, 248, 238)`, context chip background `rgb(42, 51, 40)`, assistant message background `rgb(29, 35, 28)`, assistant text `rgb(237, 244, 232)`, user message background `rgb(34, 48, 32)`, composer border `rgb(58, 66, 55)`, and readable composer text; architecture check passed with existing split-debt warnings; `git diff --check` passed; and full `npm test` passed (`585/585`). - Next: Commit the focused dark main-surface slice, then continue with the next live rendered parity mismatch. ### 2026-07-05 13:26 EDT — workbench-dark-wide-rail-parity - Objective: Continue the Claude Science 1:1 workbench parity goal by matching the reference rail's wide dark project-pane structure while keeping Feynman's green identity. - Changed: The React workbench grid now uses a responsive `--rail-width` up to `358px` instead of a fixed `256px`. The in-project rail uses a dark green surface, transparent large action rows, a divider under `Files`, dark hover/selection states, and lighter session text so project/session names truncate less aggressively and read closer to the Claude Science rail. Launcher/setup brand styles remain separate and intact. - Verified: Focused React/file-surface tests passed (`17/17`); root/workbench typecheck passed; `npm run build:workbench-web` passed with existing science-viewer bundle warnings; headless browser verification on `session-20260705160452-ae55be` showed rail width `358px`, rail background `rgb(29, 35, 28)`, transparent `44px` rail actions exactly `New chat`, `Customize`, `Files`, divider `rgb(58, 66, 55)`, selected row background `rgb(16, 21, 15)`, no `project-card` or `brand-row`, and main content starting at `x=358`; launcher verification still found `brand-mark`, `brand-title`, and `brand-subtitle` intact; architecture check passed with existing split-debt warnings; `git diff --check` passed; and full `npm test` passed (`585/585`). - Next: Commit the focused dark/wide rail slice, then continue with the next live rendered parity mismatch. ### 2026-07-05 13:18 EDT — workbench-flat-project-header-parity - Objective: Continue the Claude Science 1:1 workbench parity goal by removing the extra card-like rail project summary that made the Feynman project rail denser and more decorated than the reference. - Changed: The React workbench rail now uses one compact flat project header with the Feynman mark and active project name, then immediately flows into `New chat`, `Customize`, `Files`, and the session list. The old rounded project summary card and rail description copy are removed from the in-project rail only. - Verified: Focused React/file-surface tests passed (`17/17`); root/workbench typecheck passed; `npm run build:workbench-web` passed with existing science-viewer bundle warnings; headless browser verification on `session-20260705160452-ae55be` showed `projectCard: null`, `brandRow: null`, rendered rail actions exactly `New chat`, `Customize`, `Files`, and the first action at `y=72` under a `46px` flat project header; architecture check passed with existing split-debt warnings; `git diff --check` passed; and full `npm test` passed (`585/585`). - Next: Commit the focused header slice, then continue with the next live rendered parity mismatch. ### 2026-07-05 13:12 EDT — workbench-project-rail-parity - Objective: Continue the Claude Science 1:1 workbench parity goal by making the in-project rail match the reference project action structure. - Changed: The React workbench rail now exposes only the primary project actions in reference order: `New chat`, `Customize`, and `Files`. Search remains available through the command palette/search surfaces, and notebook, compute, and memory remain available through their owned workbench surfaces instead of appearing as peer rail actions. - Verified: Focused React/file-surface tests passed (`17/17`); root/workbench typecheck passed; `npm run build:workbench-web` passed with existing science-viewer bundle warnings; headless browser verification on `session-20260705160452-ae55be` showed rendered rail actions exactly `New chat`, `Customize`, `Files`, no side panel, shell class `app-shell`, and conversation width `924px` at `1180px` viewport; architecture check passed with existing split-debt warnings; `git diff --check` passed; and full `npm test` passed (`585/585`). - Next: Commit the focused rail slice, then continue with the next live rendered parity mismatch. ### 2026-07-05 12:52 EDT — workbench-empty-frame-layout-parity - Objective: Continue the Claude Science 1:1 workbench parity goal by fixing the blank/new-frame layout mismatch found in the live Feynman route. - Changed: The React workbench shell no longer opens Files by default for empty runs. The shell now uses two columns unless a side panel is present, grows to a third column only for active side panels on wide screens, and preserves full conversation width behind the fixed overlay side panel at narrower viewports. Artifact-bearing runs still auto-open the selected primary artifact. - Verified: Live in-app browser checks on `session-20260705160452-ae55be` showed no side panel, no selected artifact, rail `224px`, conversation `710px`, and body width `934px`. Live checks on `session-20260705035324-621b20` still showed the side panel open with `End-to-End Workbench Proof` selected while the conversation stayed `710px` instead of being squeezed to `278px`. Focused React/file-surface tests passed (`17/17`); workbench web typecheck passed; `npm run build:workbench-web` passed with existing science-viewer bundle warnings; root typecheck passed; architecture check passed with existing split-debt warnings; `git diff --check` passed; and full `npm test` passed (`585/585`). - Next: Continue with the next live rendered parity mismatch. ### 2026-07-05 12:41 EDT — check-new-issues-clean-main - Objective: Run the recurring Feynman intake sweep against live GitHub, package, release, workflow, contributor-branch, freshness, and local validation state. - Checked: Live open issues stayed `#182` and `#184`; open PR list was empty; recent `main` workflow runs were successful through `e417a8c`; latest GitHub release and npm package remain `v0.3.5` / `@companion-ai/feynman@0.3.5`; installed runtime dependencies remain `@earendil-works/pi-coding-agent@0.80.3` and `@companion-ai/alpha-hub@0.1.3`; contributor branch diffs were behind current `origin/main` and did not contain a new core-research fix to port. - Decisions: `#182` remains deferred/external because the issue evidence points at the alphaXiv/Clerk redirect before Feynman can exchange a token, and the installed package still reports alphaXiv status successfully. `#184` remains outside the AI-researcher product bar because it is a thesis-planning/support request, not a repo feature or defect. No PRs to merge, port, reject, or defer. No code changes were needed. - Verified: `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/patristic warnings; `npm run architecture:check` with existing split-debt warnings; full `npm test` (`585/585`); website `npm run lint`, `npm run typecheck` (`0 errors`), and `npm run build` (`34 pages`); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` with `entryCount: 401`, shasum `c15eb404a3594619fc1824e1943b60feb35914af`; actual temp tarball smoke from `/tmp/feynman-pack-smoke-8KRbQH/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, `feynman --help`, and `feynman alpha status`. - Next: Keep queue read-only unless a fresh Feynman-owned repro or core-research PR appears; release state is unreleased `main` work after `v0.3.5`, with successful publish workflows but no newer version tag. ### 2026-07-05 04:18 EDT — html-annotation-overlay-parity - Objective: Close the reference `HtmlAnnotationOverlay` chunk with a Feynman-owned iframe annotation bridge. - Changed: HTML artifact previews now inject a sandboxed annotation bridge, expose Annotate mode, capture clicked element selector/descriptor/text plus iframe geometry, paint saved selector badges, and route selected HTML elements through Feynman's owned artifact annotation/refinement path. Gap manifest screen/chunk status is now `52 done / 0 stub / 0 missing`. - Verified: Focused HTML annotation/source/React tests passed (`21/21` across `tests/workbench-files-surface.test.ts`, `tests/workbench-annotations.test.ts`, and `tests/workbench-react-shell.test.ts`); root/workbench typecheck passed; root build passed with existing RDKit/3Dmol/large-chunk warnings; website typecheck passed (`0` errors, `0` warnings); website build passed (`34` pages); architecture check passed with existing split-debt warnings including `science-database-variants.ts`; and `git diff --check` passed. Rendered in-app browser smoke opened the packaged CRISPR seed `design_report.html`, verified the iframe has `sandbox="allow-scripts"`, toggled Annotate mode, clicked the report heading inside the iframe, opened the artifact refinement panel with selector `body > h1:nth-child(1)`, saved a smoke annotation, verified one saved annotation plus an iframe `#1` badge, captured `outputs/.plans/feynman-e2e-screenshots/07-html-annotation-overlay.png`, then removed the smoke annotation and confirmed `remainingSmoke: 0`. - Next: Continue on SQLite migration status stubs and full package verification. ### 2026-07-05 04:12 EDT — files-hosts-parity - Objective: Close the reference `useFilesHosts` hook with Feynman-owned Files host inventory. - Changed: Files panel and full Files overlay now show a host selector for local workspace artifacts, SSH/BYOC compute hosts, and cloud buckets derived from Feynman's compute provider and credential-backed storage state. Gap manifest screen/chunk status is now `51 done / 1 stub / 0 missing`. - Verified: Focused Files/source/React tests passed (`16/16` across `tests/workbench-files-surface.test.ts` and `tests/workbench-react-shell.test.ts`); root/workbench typecheck passed; root build passed with existing RDKit/3Dmol/large-chunk warnings; website typecheck passed (`0` errors, `0` warnings); website build passed (`34` pages); architecture check passed with existing split-debt warnings including `science-database-variants.ts`; and `git diff --check` passed. - Next: Continue on the last real UI stub: `HtmlAnnotationOverlay`. ### 2026-07-05 04:10 EDT — project-section-status-parity - Objective: Close the reference `ProjectSection` chunk where Feynman's launcher and workbench rail already own the project behavior. - Changed: Marked `ProjectSection` done in the gap manifest. Feynman owns project cards, project/session counts, new-project creation, project opening, seed workflow grouping, and project/run route navigation through the launcher and in-workbench rail. Gap manifest screen/chunk status is now `50 done / 2 stub / 0 missing`. - Verified: Focused project/session/source coverage passed (`26/26` across `tests/workbench-files-surface.test.ts`, `tests/workbench-new-sessions.test.ts`, and `tests/workbench-react-shell.test.ts`); workbench web typecheck passed; and `git diff --check` passed. - Next: Continue on the two remaining real UI stubs: `HtmlAnnotationOverlay` and `useFilesHosts`. ### 2026-07-05 04:09 EDT — text-preview-status-parity - Objective: Close the reference `TextPreview` and `RemoteTextPreview` chunks where Feynman's existing artifact inspector already owns the behavior. - Changed: Marked `TextPreview` and `RemoteTextPreview` done in the gap manifest. Feynman's authenticated file preview path fetches workspace artifact text through `/api/file`, handles loading/truncation, routes rich formats to owned preview components, renders plain text in the artifact inspector, and captures keyboard/mouse selection for annotation/refinement. Left `HtmlAnnotationOverlay` open because iframe DOM-region annotation is not yet equivalent to the reference overlay. Gap manifest screen/chunk status is now `49 done / 3 stub / 0 missing`. - Verified: Focused source/React tests passed (`16/16` across `tests/workbench-files-surface.test.ts` and `tests/workbench-react-shell.test.ts`); workbench web typecheck passed; and `git diff --check` passed. - Next: Continue on the remaining real UI stubs: `HtmlAnnotationOverlay`, `ProjectSection`, and `useFilesHosts`. ### 2026-07-05 04:07 EDT — note-preview-modal-parity - Objective: Close the reference `NotePreviewModal` screen stub with a Feynman-owned note context preview. - Changed: Existing artifact notes now include a Preview action that opens a read-only modal with note content, target type/name, session id, artifact path, timestamp, and Open artifact navigation. The modal uses Feynman's existing target-note and artifact state, with no reference-app runtime dependency. Updated public README, release notes, website docs, source guards, and the gap manifest; screen/chunk status is now `47 done / 5 stub / 0 missing`. - Verified: Focused source/memory/React tests passed (`18/18` across `tests/workbench-files-surface.test.ts`, `tests/workbench-memory.test.ts`, and `tests/workbench-react-shell.test.ts`); root/workbench typecheck passed; root build passed with existing RDKit/3Dmol/large-chunk warnings; architecture check passed with existing split-debt warnings including `science-database-variants.ts`; website typecheck passed (`0` errors, `0` warnings); website build passed (`34` pages); and `git diff --check` passed. - Next: Continue on the remaining preview/Files host UI stubs. ### 2026-07-05 04:05 EDT — reference-hook-status-parity - Objective: Close reference hook chunks that are already covered by Feynman-owned state and APIs, without hiding remaining behavior gaps. - Changed: Marked `useComputeProviders`, `useFrameMessages`, and `useOpenSessionInProject` done in the gap manifest. Feynman already owns compute provider state/actions, durable frame message rows and authenticated state, and project/run/artifact navigation through the React route helpers. Left `useFilesHosts` open because the reference's unified local/SSH/cloud host picker is not yet implemented as a Files surface. Gap manifest screen/chunk status is now `46 done / 6 stub / 0 missing`. - Verified: Focused hook/status coverage passed (`41/41` across `tests/workbench-compute-provider-records.test.ts`, `tests/workbench-frame-messages.test.ts`, `tests/workbench-react-shell.test.ts`, and `tests/workbench.test.ts`); `git diff --check` passed. - Next: Implement the next real remaining UI stub instead of marking the Files-host picker done prematurely. ### 2026-07-05 04:03 EDT — cloud-storage-modal-parity - Objective: Close the reference `CloudStorageModal` and cloud-credential hook stubs with Feynman-owned storage UI and state. - Changed: Customize > Storage now opens a Cloud storage modal with credential rows, provider/status badges, target details, configured/missing connection-reference feedback, Delete credential, and Go to Credentials. The modal reads Feynman's owned `cloudCredentials` and `cloudExportTargets` state and removes entries through the existing settings API instead of depending on a reference-app credential hook. Updated public README, release notes, website docs, source guards, and the gap manifest; screen/chunk status is now `43 done / 9 stub / 0 missing`. - Verified: Focused cloud export/source/React tests passed (`18/18` across `tests/workbench-cloud-export.test.ts`, `tests/workbench-files-surface.test.ts`, and `tests/workbench-react-shell.test.ts`); root/workbench typecheck passed; root build passed with existing RDKit/3Dmol/large-chunk warnings; architecture check passed with existing split-debt warnings including `science-database-variants.ts`; website typecheck passed (`0` errors, `0` warnings); website build passed (`34` pages); and `git diff --check` passed. - Next: Continue the active 1:1 parity goal on the remaining screen/migration stubs. ### 2026-07-05 03:59 EDT — note-modal-parity - Objective: Close the reference `NoteModal` screen stub with a Feynman-owned artifact note surface. - Changed: Artifact actions now include Notes, which opens a modal with target context, existing note count, add/edit/delete controls, and Cmd/Ctrl+Enter save. The modal writes through Feynman's existing `/api/notes` path and target-note ledger, so notes stay attached to artifact/project/session context without any reference-app runtime dependency. Updated public README, release notes, website docs, source guards, and the gap manifest; screen/chunk status is now `41 done / 11 stub / 0 missing`. - Verified: Focused source/memory/React tests passed (`18/18` across `tests/workbench-files-surface.test.ts`, `tests/workbench-memory.test.ts`, and `tests/workbench-react-shell.test.ts`); root/workbench typecheck passed; root build passed with existing RDKit/3Dmol/large-chunk warnings; architecture check passed with existing split-debt warnings including `science-database-variants.ts`; website typecheck passed (`0` errors, `0` warnings) after rerunning it without the parallel content-store race; website build passed (`34` pages); and `git diff --check` passed. - Next: Continue the active 1:1 parity goal on the remaining screen/migration stubs from `outputs/.plans/claude-science-gap-manifest.md`. ### 2026-07-05 03:55 EDT — export-to-cloud-modal-parity - Objective: Close the reference `ExportToCloudModal` screen stub with a Feynman-owned artifact export surface. - Changed: Artifact Cloud export now opens a modal instead of firing a hidden one-click action. The modal shows configured and missing cloud storage targets, lets the user choose a destination path, disables export until a configured target is selected, calls Feynman's existing `/api/artifact/export-cloud` endpoint, and records exports through the owned cloud-export audit log. Updated public README, release notes, website docs, source guards, and the gap manifest; screen/chunk status is now `40 done / 12 stub / 0 missing`. - Verified: Focused cloud export/source tests passed (`18/18` across `tests/workbench-files-surface.test.ts`, `tests/workbench-react-shell.test.ts`, and `tests/workbench-cloud-export.test.ts`); root/workbench typecheck passed; root build passed with existing RDKit/3Dmol/large-chunk warnings; architecture check passed with existing split-debt warnings including `science-database-variants.ts`; website typecheck passed (`0` errors); website build passed (`34` pages); and `git diff --check` passed. - Next: Continue the active 1:1 parity goal on the remaining screen/migration stubs from `outputs/.plans/claude-science-gap-manifest.md`. ### 2026-07-05 03:51 EDT — chat-stream-state-parity - Objective: Close the browser-proven core-loop gap where chat-written artifacts appeared in Workspace but the active run/project counters could remain stale at `0`. - Changed: The authenticated chat streaming endpoint now attaches a freshly rebuilt workbench state to final `done` and `error` SSE frames, and the React shell applies that state immediately. The final stream event now carries the updated artifact/project/run ownership after Pi writes files under `outputs/`, `papers/`, or `notes/`. - Verified: Focused stream/server/client regression now writes `outputs/stream-artifact.md` during a streamed turn and asserts the final `done` SSE state includes that artifact under the active run and workspace project. Focused workbench tests passed (`41/41` across `tests/workbench.test.ts`, `tests/workbench-react-shell.test.ts`, and `tests/workbench-artifact-snapshots.test.ts`); root/workbench typecheck passed; root build passed with existing RDKit/3Dmol/large-chunk warnings; website typecheck passed (`0` errors); architecture check passed with existing split-debt warnings including `science-database-variants.ts`; and `git diff --check` passed. - Next: Continue the active 1:1 parity goal on the remaining screen/migration stubs from `outputs/.plans/claude-science-gap-manifest.md`. ### 2026-07-05 04:34 EDT — variants-named-tool-parity - Objective: Close the installed reference variants exact-name gap while keeping Feynman Bio Tools standalone and Feynman-owned. - Changed: Added exact variant query modes for `get_variant`, `search_variants`, `gene_variants`, `gene_constraint`, `region_variants`, `liftover_variant`, `clinvar_variants`, `structural_variants`, `get_structural_variant`, `mitochondrial_variants`, `cadd_variant_score`, `cadd_position_scores`, `cadd_range_scores`, `clinvar_search`, `clinvar_get_records`, `clinvar_variant_by_rsid`, `dbsnp_get_rsids`, and `dbsnp_search_by_region`. These route through owned gnomAD GraphQL, CADD REST, NCBI ClinVar E-utilities, NCBI dbSNP E-utilities, and NCBI Variation Services endpoint calls. Updated runtime tool guidance, README, release notes, website pages, command metadata, and the 1:1 gap manifest. - Verified: Focused variants exact-name tests passed (`1/1`) across all eighteen names; full science-database tests passed (`84/84`); root/workbench typecheck passed; website lint/typecheck/build passed (`34` pages); root build passed with existing RDKit/3Dmol/large-chunk warnings; architecture check passed with existing split-debt warnings and newly flagged `science-database-variants.ts` split debt; `git diff --check` passed; full `npm test` passed (`581/581`); and `npm pack --dry-run --json` passed with `entryCount: 401`, shasum `df89bfee330715aa527c2572f9bc772e30ccdcb0`. - Next: Continue on non-Bio Tool parity gaps because active Bio Tool coverage is now `247 done / 0 stub / 0 missing`. ### 2026-07-05 04:02 EDT — regulation-named-tool-parity - Objective: Close the installed reference regulation exact-name gap while keeping Feynman Bio Tools standalone and Feynman-owned. - Changed: Added exact regulation query modes for `encode_search_experiments`, `encode_search_biosamples`, `encode_list_files`, `encode_get_experiment`, `encode_get_file`, `encode_get_biosample`, `jaspar_get_matrix`, `jaspar_matrix_versions`, `jaspar_list_matrices`, `jaspar_list_species`, `jaspar_list_taxa`, `jaspar_list_collections`, `jaspar_list_releases`, `unibind_search_tfbs`, `unibind_get_dataset`, and `unibind_tfbs_in_region`. These route through owned ENCODE REST, JASPAR REST, UniBind REST, and UCSC hub-backed endpoint calls. Updated runtime tool guidance, README, release notes, website pages, command metadata, and the 1:1 gap manifest. - Verified: Installed reference regulation modules were inspected for exact names, payload shape, stable ENCODE projections, JASPAR catalog/version behavior, and UniBind dataset/region behavior. Official/current ENCODE REST, JASPAR API, UniBind genome-track, and UCSC Genome Browser API docs were checked for public endpoint shape. Focused regulation exact-name tests passed (`1/1`) across all sixteen names; full science-database tests passed (`83/83`); root/workbench typecheck passed; website lint/typecheck/build passed (`34` pages); root build passed with existing RDKit/3Dmol/large-chunk warnings; architecture check passed with existing split-debt warnings only; `git diff --check` passed; full `npm test` passed (`580/580`); and `npm pack --dry-run --json` passed with `entryCount: 401`, shasum `014c0ec784c3b05e22a79c59f9af10bb64f2e46f`. - Next: Continue the exact named-tool parity run with the next manifest domain, `variants`. ### 2026-07-05 03:27 EDT — omics-archives-named-tool-parity - Objective: Close the installed reference omics-archive exact-name gap while keeping Feynman Bio Tools standalone and Feynman-owned. - Changed: Added exact archive query modes for `arrayexpress_search_experiments`, `arrayexpress_get_experiment`, `arrayexpress_get_experiment_files`, `arrayexpress_get_experiment_samples`, `geo_search_series`, `geo_get_series`, `metabolights_list_studies`, `metabolights_get_studies`, `metabolights_get_study_files`, `metabolights_search_data_files`, `mgnify_search_studies`, `mgnify_get_studies`, `mgnify_get_study_analyses`, `pride_search_projects`, `pride_get_projects`, `pride_search_project_proteins`, and `pride_find_projects_for_protein`. These route through owned BioStudies, NCBI E-utilities, MetaboLights, MGnify v2, and PRIDE Archive endpoint calls. Updated runtime tool guidance, docs, website pages, command metadata, and the 1:1 gap trackers. - Verified: Installed reference omics-archive modules were inspected for exact names, payload shape, sample/file/protein behavior, and parsers. Official/current BioStudies/ArrayExpress, NCBI E-utilities/GEO, MetaboLights, MGnify API v2, and PRIDE Archive docs plus live endpoint probes were checked for public endpoint shape. Focused omics-archive exact-name tests passed (`1/1`) across all seventeen names; full science-database tests passed (`82/82`); root/workbench typecheck passed; website lint/typecheck/build passed (`34` pages); root build passed with existing RDKit/3Dmol/large-chunk warnings; architecture check passed with existing split-debt warnings only; `git diff --check` passed; full `npm test` passed (`579/579`); and `npm pack --dry-run --json` passed with `entryCount: 400`, shasum `40eac670a5f6418c9e69a5e32a30d3490c4b150f`. - Next: Continue the exact named-tool parity run with the next manifest domain, `regulation`. ### 2026-07-05 03:03 EDT — rna-named-tool-parity - Objective: Close the installed reference RNA/Rfam exact-name gap while keeping Feynman Bio Tools standalone and Feynman-owned. - Changed: Added `extensions/research-tools/science-database-rfam-exact.ts` and exact Rfam query modes for `get_family`, `accession_to_id`, `id_to_accession`, `get_seed_alignment`, `get_covariance_model`, `get_tree`, `get_sequence_regions`, `get_structure_mapping`, and `search_sequence`. Family, alignment, model, tree, region, and structure modes use documented Rfam endpoints; sequence search uses the current documented Rfam batch submit/result flow. Updated runtime tool guidance, docs, website pages, command metadata, and the 1:1 gap trackers. - Verified: Installed reference RNA/Rfam modules were inspected for exact names, payload shape, checksums, text capping, and parsers. Official Rfam API docs were checked for public endpoint shape. Focused Rfam exact-name tests passed (`8/8` for the reference-parity file); full science-database tests passed (`81/81`); root/workbench typecheck passed; website lint/typecheck/build passed (`34` pages); root build passed with existing RDKit/3Dmol/large-chunk warnings; architecture check passed with existing split-debt warnings only; full `npm test` passed (`578/578`); `git diff --check` passed; and `npm pack --dry-run --json` passed with `entryCount: 399`, shasum `937d1a61b92ce02550d56fe3cdace6cbf846fc03`. - Next: Continue the next exact named-tool parity domain. ### 2026-07-05 02:44 EDT — research-resources-named-tool-parity - Objective: Close the installed reference research-resource exact-name gap while keeping Feynman Bio Tools standalone and Feynman-owned. - Changed: Added `grantsgov` as a built-in science database source and added exact research-resource query modes for `search_antibodies`, `get_antibody`, `find_antibodies_by_catalog`, `get_antibody_registry_stats`, and `search_grants`. Antibody Registry modes use the public SciCrunch API; Grants.gov uses the unauthenticated Search2 POST endpoint with keyword, opportunity number, ALN, agency, status, eligibility, funding category, and funding instrument filters. Updated runtime tool guidance, docs, website pages, command metadata, and the 1:1 gap trackers. - Verified: Installed reference research-resource modules and Grants.gov client/spec code were inspected for exact names and payload shape. Official Antibody Registry OpenAPI and Grants.gov Search2 docs were checked for public endpoint shape. Focused research-resource exact-name tests passed (`2/2`); full science-database tests passed (`80/80`); root/workbench typecheck passed; website lint/typecheck/build passed (`34` pages); root build passed with existing RDKit/3Dmol/large-chunk warnings; architecture check passed with existing split-debt warnings only; full `npm test` passed (`577/577`); `git diff --check` passed; and `npm pack --dry-run --json` passed with `entryCount: 398`, shasum `f4e58ae1276c00cd64719d97d9086427c7210177`. - Next: Continue the exact named-tool parity run with the `rna` domain. ### 2026-07-05 02:43 EDT — protein-annotation-named-tool-parity - Objective: Close the installed reference protein-annotation Bio Tool domain while keeping Feynman standalone and avoiding any runtime dependency on `~/.claude-science`. - Changed: Added `extensions/research-tools/science-database-protein-annotation.ts` and exact query modes for `get_domain_architecture`, `search_interpro_entries`, `get_interpro_entry`, `search_pfam_clans`, `get_pfam_clan`, `get_pfam_family_proteins`, `get_pfam_family_proteomes`, `get_protein_atlas_gene`, `search_protein_atlas`, `map_string_ids`, `get_string_network`, `get_string_similarity_scores`, and `get_string_best_similarity_hits`. These route through owned InterPro/Pfam, Human Protein Atlas, and STRING endpoint calls inside `feynman_science_database_search`. - Verified: Installed reference protein-annotation modules were used only as local reference structure; official InterPro, Human Protein Atlas, and STRING API docs were checked for endpoint shape. Focused protein-annotation exact-name tests passed (`1/1`), focused protein/public-atlas/reference/database tests passed (`24/24`), full science database tests passed (`79/79`), root/workbench typecheck passed, website typecheck passed (`0 errors`), root build passed with existing RDKit/3Dmol/large-chunk warnings, website lint and build passed (`34` pages), architecture check passed with existing split-debt warnings only, `git diff --check` passed, full `npm test` passed (`576/576`), and `npm pack --dry-run --json` passed with `entryCount: 398`, shasum `8a355fae8ff28860d34cb18127486acc89824275`. - Next: Continue remaining Bio Tool stub domains from `outputs/.plans/claude-science-gap-manifest.md`. ### 2026-07-05 02:18 EDT — literature-named-tool-parity - Objective: Close the installed reference literature Bio Tool domain while keeping Feynman standalone and avoiding any runtime dependency on `~/.claude-science`. - Changed: Added exact OpenAlex and arXiv query modes to Feynman's owned Bio Tools. `feynman_science_database_search` now accepts `openalex_search_works`, `openalex_get_work`, `openalex_citations`, `openalex_references`, `openalex_search_authors`, `openalex_get_author`, `openalex_venue_info`, `arxiv_search`, and `arxiv_get_papers`, with reference-shaped snake_case records, DOI claimant accounting, arXiv category/date/sort windows, and batch duplicate/not-found accounting. Added focused regression tests, command metadata, README/release-note/website docs, and parity tracker updates. - Verified: Installed reference literature modules were used only as local reference structure; official OpenAlex and arXiv API docs were checked for endpoint shape. Focused literature exact-name tests passed (`1/1`), focused literature/OpenAlex/database tests passed (`8/8`), full science database tests passed (`78/78`), root/workbench typecheck passed, website typecheck passed (`0 errors`), root build passed with existing RDKit/3Dmol/large-chunk warnings, website lint and build passed (`34` pages), architecture check passed with existing split-debt warnings only after extracting arXiv and exact OpenAlex helpers, `git diff --check` passed, full `npm test` passed (`575/575`), and `npm pack --dry-run --json` passed with `entryCount: 395`, shasum `a67f16a5c337083f4370e3fda5613146dc7acf10`. - Next: Continue remaining Bio Tool stub domains from `outputs/.plans/claude-science-gap-manifest.md`. ### 2026-07-05 01:58 EDT — human-genetics-named-tool-parity - Objective: Close the installed reference human-genetics Bio Tool domain while keeping Feynman standalone and avoiding any runtime dependency on `~/.claude-science`. - Changed: Added exact GWAS Catalog, eQTL Catalogue, and PheWeb/FinnGen PheWAS query modes to Feynman's owned Bio Tools. `feynman_science_database_search` now accepts `gwas_associations_for_variant`, `gwas_associations_for_gene`, `gwas_associations_for_trait`, `gwas_search_traits`, `gwas_search_studies`, `gwas_get_study`, `gwas_get_variant`, `eqtl_list_datasets`, `eqtl_associations`, `phewas_instances`, `phewas_variant`, `phewas_finngen_gene`, `phewas_list_phenotypes`, and `phewas_search_phenotypes`. Added the Feynman-owned `pheweb` source, focused regression tests, command metadata, README/release-note/website docs, and parity tracker updates. - Verified: Installed reference `mcp_human_genetics` plus GWAS/eQTL/PheWeb helper modules were used only as local reference structure; public EBI GWAS Catalog v2, eQTL Catalogue API, PheWeb, and FinnGen PheWeb docs were checked for endpoint shape. Focused human-genetics tests passed (`3/3`), focused atlas/human-genetics tests passed (`13/13`), broader science database tests passed (`77/77`), full `npm test` passed (`574/574`), root/workbench typecheck passed, website typecheck passed (`0 errors`), root build passed with existing RDKit/3Dmol/large-chunk warnings, website lint and build passed (`34` pages), architecture check passed with existing split-debt warnings only, `git diff --check` passed, and `npm pack --dry-run --json` passed with `entryCount: 395`, shasum `737d8378a8f8a5a2e7f8c6f238c9597d5fca6540`. - Next: Continue remaining Bio Tool stub domains from `outputs/.plans/claude-science-gap-manifest.md`. ### 2026-07-05 00:24 EDT — genomes-named-tool-parity - Objective: Close the installed reference genomes Bio Tool domain while keeping Feynman standalone and avoiding any runtime dependency on `~/.claude-science`. - Changed: Added `extensions/research-tools/science-database-ensembl.ts` with Feynman-owned Ensembl REST support for `ensembl_lookup`, `ensembl_xrefs`, `ensembl_vep_variant`, `ensembl_homology`, `ensembl_sequence`, and `ensembl_overlap_region`; extended the UCSC adapter with exact `ucsc_list_tracks`, `ucsc_chrom_sizes`, `ucsc_track_data`, `ucsc_conservation`, and `ucsc_tfbs_clusters` query names; and updated README, release notes, website docs, command metadata, Pi tool guidance, and parity trackers. - Verified: Installed reference genome modules and public Ensembl/UCSC docs were checked for argument names and endpoint shape. Focused exact-name tests passed (`2/2`) for all eleven genome names; full science database tests passed (`74/74`); root/workbench typecheck passed; website typecheck passed (`0 errors`); root build passed with existing RDKit/3Dmol/large-chunk warnings; website lint and build passed (`34` pages); architecture check passed with existing split-debt warnings only; `git diff --check` passed; full `npm test` passed (`571/571`); and `npm pack --dry-run --json` passed with `entryCount: 394`, shasum `8c05dccadde132d611d431205875c13958f44efd`. - Next: Continue to the next remaining Bio Tool stub domain from `outputs/.plans/claude-science-gap-manifest.md`. ### 2026-07-05 00:16 EDT — chat-artifact-run-project-ownership - Objective: Fix the live workbench parity gap where Pi chat-created artifacts appeared in Workspace with preview/provenance but not in the producing Run or Project scopes when the artifact slug differed from the chat frame id. - Changed: Added explicit `artifactPaths` ownership to workbench runs, augmented runs from execution output paths and artifact snapshot producer ids, switched custom project/file-scope/header artifact counts to the same path-aware ownership rule, and documented the behavior in README, release notes, and the website workbench docs. - Verified: Focused artifact snapshot, React shell, and architecture tests passed (`19/19`); full `npm test` passed (`556/556`); root/workbench typecheck passed; root build passed with existing RDKit/3Dmol/large-chunk warnings; website lint/typecheck/build passed (`34` pages); architecture check passed with existing split-debt warnings only; `git diff --check` passed; and `npm pack --dry-run --json` passed with `entryCount: 390`, shasum `3a36f1019d05cee086a09b412452058303dcc82b`. The rebuilt browser route for `biology-evidence-map-2 / session-20260705035324-621b20` now shows `ARTIFACTS 1`, `Run 1`, `Project 1`, and the `outputs/e2e-workbench-proof.md` row in Run scope. Screenshot: `outputs/.plans/feynman-e2e-screenshots/07-run-project-artifact-counts-fixed.png`. - Next: Continue only on concrete remaining 1:1 parity gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-05 00:14 EDT — browser-e2e-workbench-proof - Objective: Prove the core Feynman workbench loop end to end in the running app before doing more connector breadth. - Changed: Created proof screenshots under `outputs/.plans/feynman-e2e-screenshots/` and added `outputs/e2e-workbench-proof.md` through a real Pi-backed chat turn. - Verified: Fresh workbench launched on port `6190`; browser flow created project `biology-evidence-map-2`, opened frame `session-20260705035324-621b20`, streamed a chat turn, wrote `outputs/e2e-workbench-proof.md`, opened it in Files, inspected Preview and Provenance, ran a Bash notebook cell in verification mode, and saw the artifact provenance update with `Feynman notebook` version, verified execution row, claim row, and `VERIFICATION ... pass`. - Gap: The artifact attaches to Workspace discovery and artifact provenance/history, but active Run and Project artifact counters stayed at `0`; next fix is active frame/project artifact attachment for chat-written files. - Next: Fix the Run/Project artifact attachment gap, then rerun the browser proof. ### 2026-07-05 00:04 EDT — reference-gap-manifest - Objective: Stop one-gap-at-a-time discovery and create the full installed Claude Science reference-surface manifest required by the owner directive. - Changed: Added `outputs/.plans/claude-science-gap-manifest.md` with screen chunks, migrations, Bio Tool domains/tools, license-deferred tools, skills, seed workflows, coarse status, and immediate next work. - Verified: Generated directly from `~/.claude-science/runtime/0.1.15-dev.20260701.t220242.shaaa553de-release`, including `web-dist`, `drizzle/sqlite`, `mcp_bio/domains.json`, `mcp_bio/deferred.json`, and `skills`, plus Feynman's local `skills` and `fixtures/open-science-seeds`. Manifest counts: 299 web assets, 112 JS chunks, 52 screen-like chunks, 96 migrations, 23 Bio Tool domains, 247 active Bio Tools, 14 license-deferred Bio Tools, 29 reference skills, and four seed workflow families. - Next: Browser-prove the running workbench loop end to end before more connector breadth. ### 2026-07-04 23:58 EDT — kegg-link-conv-parity - Objective: Close the in-flight KEGG reference-tool gap while keeping the connector Feynman-owned, then return to the bulk-manifest/end-to-end directive. - Changed: Added KEGG `link: ` and `conv: ` modes to `feynman_science_database_search`, including 10-id batching, two-column row normalization, operation/source/target/batch/request metadata, endpoint provenance, and missing-id reporting. Updated Pi prompt guidance, README, release notes, website homepage, website workbench guide, CLI command docs, command metadata, and parity trackers. - Verified: Installed reference KEGG code and the official KEGG API manual were checked for `/link`, `/conv`, tab-delimited output, `+`-joined multi-entry calls, batching, request provenance, and missing-id behavior. Live Feynman tool smoke against real KEGG returned `58` pathway rows for `link:pathway hsa:7157 hsa:672` and `2` NCBI GeneID conversion rows for `conv:ncbi-geneid hsa:7157 hsa:672`. Final gates passed: full `npm test` (`555/555`), root/workbench typecheck, website lint, website typecheck (`0 errors`), root build with existing RDKit/3Dmol/large-chunk warnings, website build (`34 pages`), architecture check with split-debt warnings only, `git diff --check`, and `npm pack --dry-run --json` (`entryCount: 389`, shasum `1ae30d0843e83ff850251e58b7316875b0610b03`). - Next: Build the full reference-surface gap manifest and browser end-to-end proof before more connector breadth. ### 2026-07-04 23:41 EDT — OWNER DIRECTIVE: switch to bulk-port method - Directive (supersedes prior "Next" lines): stop the one-connector-per-slice grind; it is too slow. Keep the standalone boundary exactly as-is (Feynman-owned code, no `~/.claude-science` runtime dependency). - Do this instead: (1) build ONE full reference-surface gap manifest — every screen (web-dist chunk names), all 94 drizzle migrations, all 247 bio-tools, all 29 skills, all seed workflows — marked done/stub/missing; (2) bulk-port remaining bio-tools/schema/previews by category in a single sweep (generate the tools from a table off their shared HTTP+dispatch shape, do not hand-write each), running the full gate ONCE at the end; (3) prove the whole app loop END-TO-END in the browser — create project → chat/stream run → produce artifact → open provenance/history → run a verification check — screenshotting each step and reporting what works in the running app vs only in tests. - Priority: whole app loop working 1:1 end-to-end FIRST; specialist bio-tool long tail AFTER. Do not spend another slice on a single preview/connector format. - Next: build the gap manifest, then run the first bulk-port sweep; record results here and in `outputs/.plans/claude-science-1to1.md`. ### 2026-07-04 23:34 EDT — panglaodb-marker-source - Objective: Continue science-tool parity by porting PanglaoDB as a Feynman-owned no-login single-cell marker source instead of relying on the reference runtime. - Changed: Added `panglaodb` to `feynman_science_database_search`, tool schema, runtime prompt context, Settings/Customize connector catalog, README, release notes, website homepage, website workbench guide, command metadata, and parity trackers. `extensions/research-tools/science-database-panglaodb.ts` now downloads or reads the frozen PanglaoDB marker TSV, checksum-verifies the gzip by default, parses marker rows, and supports `cell:`, `markers:`, `gene:`, synonym lookup, `options`, species, organ, canonical-marker, sensitivity, and specificity filters. The first implementation briefly pushed `science-database-longtail.ts` over the architecture split threshold, then was corrected by moving PanglaoDB into its own module. - Verified: Installed reference `panglaodb_markers` code and public PanglaoDB marker pages were checked for TSV URL, checksum behavior, marker rows, options, reverse lookup, 8,286 associations, 178 cell types, 4,679 gene symbols, 29 tissues, and 27 Mar 2020 update. Live Feynman tool smoke returned `8286` total rows, `49` canonical human T-cell marker rows, and first returned genes `BATF3`, `BRAF`, and `CCL20` from the real PanglaoDB gzip. Final gates passed: root/workbench typecheck, website lint, website typecheck (`0 errors`), root build with existing RDKit/3Dmol/large-chunk warnings, website build (`34 pages`), architecture check with split-debt warnings only and no new long-tail warning, `git diff --check`, full `npm test` (`554/554`), and `npm pack --dry-run --json` (`entryCount: 389`, shasum `435760c36e61387ec964e2c1bcf8f917f34b020d`). - Next: Continue only on concrete remaining 1:1 parity gaps found by reference and seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-04 22:56 EDT — ketcher-sketch-format-preview - Objective: Close the reference Ketcher format loop so Feynman-owned KET/RXN/CDXML chemistry artifacts created by chat tools open as first-class workbench science previews. - Changed: Added `.ket`, `.rxn`, `.cdxml`, and `.cxsmiles` to the scanner previewable file table, content-type/language mapping, React artifact classifier, and molecule preview parser. KET previews now summarize Ketcher atom/bond nodes, RXN previews summarize reaction member molecules, CDXML previews summarize ChemDraw atom/bond nodes, and CXSMILES previews follow the SMILES parser. The RDKit preview now reports that Ketcher-only formats should open in Ketcher instead of attempting a bad RDKit parse, while the Ketcher editor receives raw KET/RXN/CDXML content. Updated README, release notes, website workbench docs, website release notes, command metadata, and parity trackers. - Verified: Focused preview/editor/backend tests passed (`24/24`) for chemistry sketcher creation, KET/RXN/CDXML/CXSMILES classification and parsing, backend KET artifact edit/snapshot behavior, and React artifact helper contracts. Final gates passed: root/workbench typecheck, website lint, website typecheck (`0 errors`), root build with existing RDKit/3Dmol/large-chunk warnings, website build (`34 pages`), architecture check with split-debt warnings only, `git diff --check`, full `npm test` (`553/553`), and `npm pack --dry-run --json` (`entryCount: 388`, shasum `478d3f5a9ac51faf7aa31de749b3c20e64f4a6a3`). - Next: Continue only on concrete remaining 1:1 parity gaps found by reference and seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-04 19:42 EDT — ketcher-chemistry-sketcher - Objective: Close the reference-app chemistry MCP gap where Feynman had Ketcher artifact editing but no chat-callable, Feynman-owned sketcher seed tool mirroring the reference `open_sketcher` shape. - Changed: Added `feynman_open_chemistry_sketcher` in `extensions/research-tools/chemistry-sketcher.ts`. The tool accepts KET, RXN, Molfile, or SMILES seeds, prefers KET when present, writes an editable workspace artifact under `outputs/chemistry-sketches/`, and returns artifact path/format/mime metadata for the local Ketcher editor. The Customize connector catalog now marks Ketcher Chemistry as a configured built-in science workbench tool. Updated README, release notes, website workbench docs, website release notes, command metadata, and parity trackers. - Verified: Installed reference Ketcher MCP server was inspected for its `open_sketcher` tool, UI resource, accepted seed formats, KET preference, save metadata, and supported extensions. Public Ketcher docs were checked for browser molecule/reaction editing and supported file formats. Final gates passed: focused chemistry/settings tests (`6/6`), root/workbench typecheck, website lint, website typecheck (`0 errors`), root build with existing RDKit/3Dmol/large-chunk warnings, website build (`34 pages`), architecture check with split-debt warnings only, full `npm test` (`553/553`), and `npm pack --dry-run --json` (`entryCount: 388`, shasum `d913c79d96722e1555335eff60bf067f645e43e7`). - Next: Run final `git diff --check`, then continue only on concrete remaining 1:1 parity gaps found by reference and seed-workflow probes. ### 2026-07-04 09:18 PDT — org-database-reference-ledger-envelopes - Objective: Close the remaining product-structure gap where Feynman's state coverage map had reference-shaped ledgers that were not yet physical tables in the owned org database. - Changed: Added `src/workbench/org-database-ledgers.ts` and wired it into `src/workbench/org-database.ts` so `~/.feynman/orgs//feynman-workbench.db` creates compact table envelopes for every remaining reference-shaped workbench ledger already owned in Feynman state. The envelope tables cover agents, bundled-agent settings, agent-skill assignments, custom skills/prompts, custom MCP servers/assignments, directory attachments, OAuth tokens, user secrets, Anthropic key rows, cloud credentials, setup decisions, marketplace rows, skill license assents, use-intent declarations, user agents, events, notifications, queued user messages, session seen marks, session concurrency, compaction archives, frame branch archives, frame system prompts, frame backfill poison, artifact dependencies, content snapshots, host grants, host call log, safety feedback, compute usage, compute pending terminations, poller leases, transcript annotations, and session claims. Updated README, release notes, website workbench docs, website release notes, and parity trackers. - Verified: Focused org database tests passed (`2/2`) for physical table presence across the full reference coverage map, seeded event/session-claim rows, payload preservation, active-org database placement, and no `.claude-science`/`operon-cli` path coupling. Final gates passed: focused path/data-root/org-db/settings/resource tests (`22/22`), root/workbench typecheck, website lint, website typecheck (`0 errors`), root build with existing RDKit/3Dmol/large-chunk warnings, website build (`34 pages`), architecture check with split-debt warnings only, `git diff --check`, full `npm test` (`551/551`), and `npm pack --dry-run --json` (`entryCount: 387`, shasum `338b28e19ded8e1f1c9568ad1d4b91eca1df71f9`). - Next: Continue only on concrete remaining 1:1 parity gaps found by reference and seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-04 08:25 PDT — org-database-spine - Objective: Close the product-structure gap where Feynman had an active org folder but no Feynman-owned org database mirror like the reference app's durable control-plane database. - Changed: Added `~/.feynman/orgs//feynman-workbench.db` via `src/workbench/org-database.ts`, with reference-shaped `projects`, `frames`, `frame_messages`, `artifacts`, `artifact_versions`, `execution_log`, `verification_checks`, `memories`, `notes`, `annotations`, `frame_read_cursors`, `artifact_folders`, `compute_providers`, `mcp_tool_grants`, `memory_categories`, `routine_schedules`, `managed_endpoints`, and `capability_settings` tables plus `feynman_state_payloads` for Feynman-specific fields. The served workbench refreshes the database from Feynman's own state. Updated README, release notes, website configuration/workbench docs, website release notes, and parity trackers to describe the owned org database. - Verified: Focused extended org database tests passed (`2/2`) for schema metadata, table names, row counts, payload preservation, active-org database placement, extended control-plane rows, and no `.claude-science`/`operon-cli` path coupling. Final gates passed: focused path/data-root/org-db/settings/resource tests (`22/22`), root/workbench typecheck, website lint, website typecheck (`0 errors`), root build with existing RDKit/3Dmol/large-chunk warnings, website build (`34 pages`), architecture check with existing split-debt warnings only, `git diff --check`, full `npm test` (`551/551`), and `npm pack --dry-run --json` (`entryCount: 386`, shasum `005f89772e47e7b2393d1647189f3b9d24d4b638`). - Next: Continue only on concrete remaining 1:1 parity gaps found by reference and seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-04 07:42 PDT — app-org-home-spine - Objective: Close the product-structure gap where Feynman had a `~/.feynman` home but did not yet mirror Claude Science's active-org/app-home spine. - Changed: Added Feynman-owned active org support in `src/config/paths.ts`: `~/.feynman/active-org.json`, `~/.feynman/orgs//`, and preservation of existing reference-shaped org manifests. Moved default workbench app data from the previous home-level `~/.feynman/workbench/workspaces//` path into `~/.feynman/orgs//workbench/workspaces//`, added per-workspace manifests plus an org-level `workspaces.json` index, and kept first-access migration from both legacy home-level workbench state and checkout-local `.feynman/workbench` records. Updated README, release notes, website configuration/workbench docs, website release notes, and parity trackers to describe the org-scoped home. - Verified: Installed Claude Science home was checked for `active-org.json` and `orgs//operon-cli.db`. Focused path/data-root tests passed (`14/14`), broader path/settings/resource tests passed (`19/19`), and final gates passed: root/workbench typecheck, website lint, website typecheck (`0 errors`), root build with existing RDKit/3Dmol/large-chunk warnings, website build (`34 pages`), architecture check with existing split-debt warnings only, `git diff --check`, full `npm test` (`548/548`), and `npm pack --dry-run --json` (`entryCount: 385`, shasum `d787072c9f65f287ff5a94c811aafaf18d07b7ee`). - Next: Continue only on concrete remaining 1:1 parity gaps found by reference and seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-04 07:07 PDT — pubmed-workflow-parity - Objective: Continue Claude Science 1:1 science-tool parity by replacing Feynman's shallow PubMed keyword search with a Feynman-owned adapter matching the reference PubMed MCP workflow modes. - Changed: Added `extensions/research-tools/science-database-pubmed.ts` with existing PubMed ESearch/ESummary search plus EFetch XML article metadata, PMC ID Converter PMID/PMCID/DOI conversion, ELink related articles and PMC links, Europe PMC-backed PMC full-text routing with bounded section snippets, PubMed/PMC copyright and license status, and ECitMatch citation lookup. Routed `source: "pubmed"` through the dedicated adapter, added focused tests, and updated README, website docs/homepage/release notes, CLI command docs, command metadata, Settings resources, runtime context, Pi tool prompt guidance, and parity trackers. - Verified: Installed reference `mcp_pubmed` exposed `search_articles`, `get_article_metadata`, `convert_article_ids`, `find_related_articles`, `get_full_text_article`, `get_copyright_status`, and `lookup_article_by_citation`. Official NCBI E-utilities docs were checked for ESearch, ESummary, EFetch, ELink, and ECitMatch; official PMC ID Converter docs were checked for `ids`, `idtype`, PMID/PMCID/DOI conversion, and multi-ID behavior; Europe PMC REST docs were checked for search and `/{id}/fullTextXML`. Focused PubMed plus shared science database tests passed (`7/7`); a stale workbench prompt assertion was updated to protect the richer PubMed mode list and its focused context test passed (`5/5`). Final gates passed: root typecheck, website lint, website typecheck (`0 errors`), root build with existing RDKit/3Dmol/large-chunk warnings, website build (`34 pages`), architecture check with existing split-debt warnings only, `git diff --check`, full `npm test` (`543/543`), and `npm pack --dry-run --json` (`entryCount: 385`, shasum `66d927c9f6d7cfd150d976c7edb61d4654e59938`). - Next: Continue only on concrete remaining 1:1 parity gaps found by reference and seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-04 06:25 PDT — chembl-molecular-pharmacology-parity - Objective: Continue Claude Science 1:1 science-tool parity by replacing Feynman's shallow ChEMBL molecule/target/assay search with a Feynman-owned adapter matching the reference chemistry MCP modes. - Changed: Added `extensions/research-tools/science-database-chembl.ts` with legacy ChEMBL entity search plus compound name search, SMILES similarity/substructure search, drug indication and warning lookup, calculated ADMET properties, ligand-target bioactivity filters, mechanism records, and target/gene/organism filters. Routed `source: "chembl"` through the dedicated adapter, added focused tests, and updated README, website docs/homepage/release notes, CLI command docs, command metadata, Settings resources, workbench runtime context, Pi tool prompt guidance, and parity trackers. - Verified: Installed reference `mcp_chembl` exposed `compound_search`, `drug_search`, `get_admet`, `get_bioactivity`, `get_mechanism`, and `target_search`. Public ChEMBL web-service docs were checked for molecule, drug indication, drug warning, mechanism, target, activity, similarity, substructure, filter syntax, `only`, and `order_by` support. Focused tests passed (`7/7`). Live smokes returned imatinib `CHEMBL941`, ADMET properties for `CHEMBL941`, ABL1 bioactivity against `CHEMBL1862` with `IC50=38nM` and `pChEMBL=7.42`, mechanism id `304` with action type `INHIBITOR`, leukemia drug indication row for `CHEMBL1096882` with black-box warning summaries, and target `CHEMBL1862` with gene symbol `ABL1`. Final gates passed: root typecheck, website lint, website typecheck (`0 errors`), root build with existing RDKit/3Dmol/large-chunk warnings, website build (`34 pages`), architecture check with existing split-debt warnings only after splitting the ChEMBL regression into `tests/science-database-chembl.test.ts`, `git diff --check`, full `npm test` (`542/542`), and `npm pack --dry-run --json` (`entryCount: 383`, shasum `1c8377d30cb37b09b5a65c4f642953b984bd7017`). - Next: Continue only on concrete remaining 1:1 parity gaps found by reference and seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-04 06:00 PDT — openfda-drugsfda-parity - Objective: Continue Claude Science 1:1 science-tool parity by replacing Feynman's shallow openFDA label/event/recall search with a Feynman-owned adapter matching the reference drug-regulatory MCP modes. - Changed: Added `extensions/research-tools/science-database-openfda.ts` with FDA label, adverse-event, recall, structured label filter, Drugs@FDA application detail/search, application count, statistics, pharmacologic-class, and generic-equivalent active-ingredient-set modes. Routed `source: "openfda"` through the dedicated adapter, added focused tests, and updated README, website docs/homepage/release notes, CLI command docs, command metadata, Pi tool prompt guidance, and parity trackers. - Verified: Installed reference `mcp_drug_regulatory` exposed `search_drug_applications`, `get_drug_application`, `count_drug_applications`, `get_drug_statistics`, `list_pharmacologic_classes`, `get_generic_equivalents`, and `search_drug_labels`. Public openFDA Drugs@FDA and label docs were checked for application/product/submission/openfda sections, searchable fields, query syntax, and `{term,count}` aggregation rows. Focused tests passed (`16/16`). Live smokes returned application `NDA020503`, Keytruda application `BLA125514`, Keytruda sponsor count `MERCK SHARP DOHME`, pharmacologic class `Corticosteroid Hormone Receptor Agonists [MoA]`, Advil generic-equivalent active-ingredient sets, and Tylenol oral-label row `015a6179-bacb-452d-b594-4de628ddc11d`. Final gates passed: focused science tests (`16/16`), root typecheck, website lint, website typecheck (`0 errors`), root build with existing RDKit/3Dmol/large-chunk warnings, website build (`34 pages`), architecture check with existing split-debt warnings only, `git diff --check`, full `npm test` (`541/541`), and `npm pack --dry-run --json` (`entryCount: 382`, shasum `839239dd94e224603913471ae6fabe9f007ed584`). - Next: Continue only on concrete remaining 1:1 parity gaps found by reference and seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-04 04:31 PDT — clinical-trials-parity - Objective: Continue Claude Science 1:1 science-tool parity by replacing Feynman's shallow ClinicalTrials.gov search with a Feynman-owned adapter matching the reference clinical-trials MCP modes. - Changed: Added `extensions/research-tools/science-database-clinical-trials.ts` with general study search, direct NCT details, sponsor-specific programs, eligibility filters with ClinicalTrials.gov age-unit normalization, investigator/contact discovery from overall officials, responsible parties, and site contacts, and endpoint summaries across trial outcome measures. Routed `source: "clinicaltrials"` through the dedicated adapter, added focused tests, and updated README, website docs/homepage/release notes, CLI command docs, command metadata, Pi tool prompt guidance, and parity trackers. - Verified: Installed reference `mcp_clinical_trials` exposed `analyze_endpoints`, `get_trial_details`, `search_by_eligibility`, `search_by_sponsor`, `search_investigators`, and `search_trials`. Public ClinicalTrials.gov v2 endpoints were checked for `/studies`, `/studies/{nctId}`, `query.*`, `filter.*`, `fields`, `countTotal`, and `/version`. Focused tests passed (`11/11`). Live smokes returned detail record `NCT04280705`, melanoma eligibility rows with brain-metastases criteria, phase-3 melanoma endpoint summaries, Merck sponsor rows (`totalCount: 9`), and Rosenberg investigator rows from `overallOfficials`. Final gates passed: root typecheck, website typecheck (`0 errors`), root build with existing RDKit/3Dmol/large-chunk warnings, website build (`34 pages`), architecture check with existing split-debt warnings only, `git diff --check`, full `npm test` (`536/536`), and `npm pack --dry-run --json` (`entryCount: 381`, shasum `002ff0af57cbfcc8d9c56409dccf15a02d84a3ce`). - Next: Continue only on concrete remaining 1:1 parity gaps found by reference and seed-workflow probes. ### 2026-07-04 02:17 PDT — app-data-root - Objective: Close the product-structure gap where Feynman had a home `~/.feynman` folder but still treated checkout-local `.feynman/workbench` as the primary app state store. - Changed: Added `src/workbench/data-root.ts` with deterministic per-workspace app data roots under `~/.feynman/workbench/workspaces//`, legacy `.feynman/workbench` migration on first access, and shared stored-path resolution. Moved workbench settings, chat sessions, uploads, memory, artifact annotations/actions/trash, transcript annotations, safety feedback, read cursors, onboarding profile, project rows, OAuth token/pending stores, notebook execution logs, environment action logs, managed Python/R environment roots, Modal CLI/job paths, artifact snapshots, cloud-export logs, compute pending-terminate rows, endpoint timestamp probes, Pi-side connector/context settings readers, and Settings/Storage resource cards onto the shared app-data root. Research artifacts still remain in `outputs/`, `papers/`, and `notes/`. - Verified: Focused app-data/workbench regression passed (`59/59`) after moving stale fixtures to the app-data root and canonicalizing symlinked workspace paths. Final gates passed: root typecheck, root build, website lint, website typecheck (`0 errors`), website build (`34 pages`), architecture check with existing split-debt warnings only, `git diff --check`, full `npm test` (`530/530`), and `npm pack --dry-run --json` (`entryCount: 379`, shasum `e90b924e32a5668fb061674e536be180fb9a1e40`). - Next: Continue remaining Claude Science parity gaps from the current reference/seed probes. ### 2026-07-04 01:58 PDT — zinc-source - Objective: Continue science-tool parity by turning the existing ZINC Settings preset into an executable Feynman-owned CartBlanche22/ZINC source instead of a reference-shaped placeholder. - Changed: Added `zinc` to `feynman_science_database_search`. The source submits form-encoded CartBlanche22 tasks, polls `/search/result/`, caps response reads, canonicalizes short ZINC IDs, supports ZINC ID lookup, SMILES exact/analog search with `dist`/`adist`, supplier catalog-code lookup, random screening-set samples, and 3D tranche-location metadata when current records expose a tranche code. Settings/Customize now marks ZINC as a configured built-in Feynman Bio Tools source, and the Pi prompt context, README, release notes, website homepage, website workbench guide, website release docs, and parity trackers describe the owned ZINC path. - Verified: The installed reference `mcp_zinc` module, public ZINC/CartBlanche search pages, and live CartBlanche submit/poll behavior were checked. Focused database/context/settings tests passed (`17/17`). Live Feynman adapter smoke for `id:ZINC12` returned `ZINC000000000012`, one `zinc20` record, SMILES `O=C(C[S@@](=O)C(c1ccccc1)c1ccccc1)NO`, `75` supplier catalog rows, source counts, and tranche properties. Final gates passed: root typecheck, website lint, website typecheck (`0 errors`), root build, website build (`34 pages`), architecture check with existing split-debt warnings only, full `npm test` (`530/530`), `git diff --check`, public product/source reference-leakage scan, stale wording scan, and `npm pack --dry-run --json` (`entryCount: 378`, shasum `670050ec1f7595b7094d0429f91f18205046e866`). - Next: Continue only on concrete remaining 1:1 parity gaps found by reference and seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-04 01:26 PDT — europepmc-fulltext - Objective: Continue science-tool parity by porting the Claude Science-shaped Europe PMC full-text path into Feynman's owned `feynman_science_database_search` tool instead of relying on the reference runtime. - Changed: Added Europe PMC full-text mode behind the existing `europepmc` source. Queries such as `fulltext:PMC5815332`, `pmid:29456894`, `fulltext pmid=...`, and supported article URLs now resolve availability through Europe PMC `/search` with `resultType=core`, fetch `/{PMCID}/fullTextXML` only for open-access PMCID records, extract title, abstract, section inventory, bounded section snippets, figure/table captions, and reference counts, and report explicit `retrieved`, `not_open_access`, `no_pmcid`, `xml_not_available`, `not_found`, `invalid_id`, or `not_processed` statuses without returning raw XML. Updated tool prompts, runtime context, Settings/Customize resource copy, README, release notes, website homepage, website workbench guide, website release docs, and parity trackers. - Verified: The installed reference `europepmc_fulltext` module, Europe PMC RESTful API docs, and rOpenSci Europe PMC docs were checked for PMCID/PMID availability, Open Access full-text XML, section extraction, and non-OA behavior. Focused database/context/settings tests passed (`18/18`). Live Feynman adapter smokes returned `retrieved` for `fulltext:PMC5815332` and `pmid:29456894`, resolved PMID `29456894` to PMCID `PMC5815332`, extracted `6` sections, `6` figures, `3` tables, and `52` references, and preserved `/search` plus `/fullTextXML` endpoint provenance. Final gates passed: root typecheck, website lint, website typecheck (`0 errors`), root build, website build (`34 pages`), architecture check with existing split-debt warnings only, `git diff --check`, full test suite (`528/528`), `npm pack --dry-run --json` (`entryCount: 377`, shasum `b5a9c25f963cd072d0c7149c3a34f79f91706bfe`), public product/source reference-leakage scan, and stale-gate wording scan. - Next: Continue only on concrete remaining 1:1 parity gaps. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-04 01:01 PDT — unibind-source - Objective: Continue science-tool parity by porting UniBind as a Feynman-owned no-login direct TF-DNA interaction and TFBS region source instead of relying on the reference runtime. - Changed: Added `unibind` to the `feynman_science_database_search` adapter, tool schema, runtime prompt context, Settings/Customize connector catalog, README, release notes, website homepage, website workbench guide, website release docs, and parity trackers. UniBind now searches TF/cell-line/JASPAR datasets, resolves exact dataset detail/model rows with BED/FASTA/plot URLs, and fetches bounded UCSC hub-backed TFBS region rows for Robust or Permissive collections while preserving source endpoints and hub URLs. - Verified: The installed reference module, UniBind public genome-track documentation, and UCSC REST API contract were checked for dataset/detail/hub-region behavior. Focused database/context/settings tests passed (`24/24`). Live tool smoke returned `968` CTCF datasets, exact CTCF dataset `ENCSR000AUE.A549_lung_carcinoma.CTCF` with `57900` peaks and one DAMO model, and a Robust hg38 `chr17:7661779-7687546` GATA3 region scan with `1949` TFBS rows scanned, `18` GATA3 rows, and first row `ENCSR000EWS_MCF-7_GATA3_MA0037.3`. Final gates passed: root typecheck, website typecheck (`0 errors`), root build, website build (`34 pages`), architecture check with existing split-debt warnings only, `git diff --check`, full test suite (`525/525`), `npm pack --dry-run --json` (`entryCount: 376`, shasum `232a6e80233c0b6a93dc52520c6bedb09942bc16`), and public product/source reference-leakage scan. - Next: Continue only on concrete remaining 1:1 parity gaps. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-04 00:42 PDT — openalex-source - Objective: Continue science-tool parity by porting OpenAlex as a Feynman-owned credential-aware literature/citation-graph source instead of relying on the reference runtime. - Changed: Added `openalex` to the `feynman_science_database_search` adapter, tool schema, runtime prompt context, Settings/Customize connector catalog, README, release notes, website homepage, website workbench guide, website release docs, and parity trackers. OpenAlex now searches works, resolves W-id and DOI work detail through the DOI claimant filter route, returns incoming citations and outgoing references, searches and resolves authors and sources/venues, reports open-access status, reconstructs abstracts only for declared open licenses, redacts API keys from provenance/errors, and returns structured `openalex_key_required` rate-limit diagnostics when `OPENALEX_API_KEY` is missing. - Verified: Official OpenAlex docs and installed reference modules were checked for works/authors/sources, API-key/rate-limit, citation/reference traversal, DOI claimant resolution, and source/author ID contracts. Focused database/context/settings tests passed (`24/24`). Live no-key tool smoke returned `W3161425918` for CRISPR base editing, `W2064815984` detail and DOI-filter resolution for `10.1126/science.1231143`, `15549` incoming citations, `32` outgoing references, author `A5067184382` for Jennifer Doudna search, source `S106963461` for Nature Biotechnology, and structured `openalex_key_required` for rate-limit. Final gates passed: root typecheck, website typecheck (`0 errors`), root build, website build (`34 pages`), architecture check with existing split-debt warnings only, `git diff --check`, full test suite (`524/524`), `npm pack --dry-run --json` (`entryCount: 375`, shasum `bea248aa0664c8325ddf75002779b8137c4cfa52`), public-doc reference leakage scan, and stale-gate wording scan. - Next: Continue only on concrete remaining 1:1 parity gaps. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-04 00:23 PDT — intake-sweep-clean-queue - Objective: Run the `check-new-issues` intake sweep against live GitHub/package/runtime state while preserving the dirty workbench/science-tools tree. - Checked: Local `main` is still two commits ahead of `origin/main` with the existing dirty workbench/science-tools changes preserved. Live GitHub has open issues `#184` and `#182`, zero open PRs, latest `main` workflow run `Publish and Release` `28343487961` succeeded at `cb5fa56`, latest GitHub release is `v0.3.5` with four native assets, npm latest is `@companion-ai/feynman@0.3.5`, bundled Pi latest/current is `0.80.3`, and `@companion-ai/alpha-hub` remains `0.1.3`. - Decisions: `#184` remains a support/research-topic issue outside Feynman's AI-researcher product bar. `#182` remains deferred/externally blocked absent a fresh Feynman-owned repro; the current package still delegates alpha login/status through alpha-hub. No open PRs existed. Contributor branch `origin/fix/deepresearch-local-model-warning` remains already absorbed by local warning behavior and tests; other contributor branches were rejected/deferred as admin/export/provider/platform churn rather than core research-loop fixes. - Verified: `npm run typecheck`, `npm run build`, `npm run architecture:check`, full `npm test` (`523/523`), `git diff --check`, root and website `npm audit --omit=dev`, website lint/typecheck/build, `npm pack --dry-run --json` (`entryCount: 375`, shasum `d0919d30bb22de57f0a388d290ebe00aa1b8f944`), actual temp tarball pack, and disposable installed-tarball smoke for `feynman --version`, `feynman --help`, and `feynman alpha status` passed. - Next: Keep `#184` as manual GitHub support if desired; keep `#182` deferred until alphaXiv/Clerk/alpha-hub behavior changes or a new local repro points at Feynman code. ### 2026-07-04 00:09 PDT — antibody-registry-source - Objective: Continue science-tool parity by porting Antibody Registry as a Feynman-owned no-login reagent/RRID source instead of relying on the reference runtime. - Changed: Added `antibodyregistry` to the `feynman_science_database_search` adapter, tool schema, runtime prompt context, Settings/Customize connector catalog, README, release notes, website homepage, website workbench guide, website release docs, and parity trackers. Antibody Registry now searches antibody RRIDs, resolves AB/RRID detail records, performs catalog-number lookup with vendor filtering, lists vendors, and returns registry statistics with endpoint provenance. - Verified: Installed reference modules, Antibody Registry public pages/OpenAPI, RRID guidance, and live Antibody Registry service behavior were checked for FTS search, detail, catalog, vendor, and stats contracts. Focused database/context/settings tests passed (`35/35`). Live tool-level smoke returned TP53 `RRID:AB_3717446`, AB_330944 detail, catalog `9205` as `RRID:AB_330944`, vendor rows from `5814` registered vendors, and registry stats of `3186152` antibodies with last update `2026-07-03`. Final gates passed: root typecheck, website typecheck (`0 errors`), root build, website build (`34 pages`), architecture check with existing split-debt warnings only, `git diff --check`, full test suite (`523/523`), `npm pack --dry-run --json` (`entryCount: 374`, shasum `f9c91eb2d9e9fa68d93ba752ac7ddb149022f2ed`), public-doc reference leakage scan, and stale-gate wording scan. - Next: Continue only on concrete remaining 1:1 parity gaps. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 23:26 PDT — cellguide-source - Objective: Continue science-tool parity by porting CellGuide as a Feynman-owned no-login cell-type source instead of relying on the reference runtime. - Changed: Added `cellguide` to the `feynman_science_database_search` adapter, tool schema, runtime prompt context, Settings/Customize connector catalog, README, release notes, website homepage, website workbench guide, website release docs, and parity trackers. CellGuide now searches Cell Ontology cell types, resolves CL ids, returns validated descriptions, computational and canonical marker genes, tissue occurrence rows, and CELLxGENE source collections with snapshot and endpoint provenance. - Verified: Installed reference modules, the public CellGuide surface, public marker-gene docs, and live CellGuide service behavior were checked for snapshot, metadata, marker, source-collection, and tissue-mapping contracts. Focused database/context/settings tests passed (`34/34`). Live tool-level smoke returned T cell `CL:0000084`, CellGuide snapshot `1764612212`, computational/canonical marker rows, `165` source collections, and `56` tissue mappings from the public CellGuide service. Final gates passed: root typecheck, website typecheck (`0 errors`), root build, website build (`34 pages`), architecture check with existing split-debt warnings only, `git diff --check`, full test suite (`522/522`), `npm pack --dry-run --json` (`entryCount: 373`, shasum `faf45078c3f655672662287aa0e501876137bbf0`), public-doc reference leakage scan, and stale-gate wording scan. - Next: Continue only on concrete remaining 1:1 parity gaps. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 23:16 PDT — ucsc-source - Objective: Continue science-tool parity by porting UCSC Genome Browser as a Feynman-owned no-login genomics source instead of relying on the reference runtime. - Changed: Added `ucsc` to the `feynman_science_database_search` adapter, tool schema, runtime prompt context, Settings/Customize connector catalog, README, release notes, website homepage, website workbench guide, website release docs, and parity trackers. UCSC now lists assemblies, searches track metadata, returns chromosome sizes, fetches bounded genomic region track rows while preserving UCSC truncation state, computes conservation score summaries, and exposes ENCODE TFBS cluster rows with endpoint provenance. - Verified: Official UCSC REST API docs, installed reference modules, and live UCSC service behavior were checked for assembly, track search, chromosome-size, bounded track-data, conservation, and TFBS-cluster contracts. Focused database/context/settings tests passed (`33/33`). Live tool-level smoke returned hg38 `chr17` size `83257441`, TP53 `knownGene` rows with UCSC truncation flagged, `phyloP100way` conservation scores over `chr17:7676150-7676170`, and ClinVar track-search metadata from the UCSC REST API. Final gates passed: root typecheck, website typecheck (`0 errors`), root build, website build (`34 pages`), architecture check with existing split-debt warnings only, `git diff --check`, full test suite (`521/521`), `npm pack --dry-run --json` (`entryCount: 373`), public-doc reference leakage scan, and stale-gate wording scan. - Next: Continue only on concrete remaining 1:1 parity gaps. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 22:50 PDT — metabolights-source - Objective: Continue science-tool parity by porting MetaboLights as a Feynman-owned no-login metabolomics source instead of relying on the reference runtime. - Changed: Added `metabolights` to the long-tail `feynman_science_database_search` adapter, tool schema, runtime prompt context, Settings/Customize connector catalog, README, release notes, website homepage, website workbench guide, website release docs, and parity trackers. MetaboLights now lists public MTBLS study accessions, fetches public study metadata, returns study-folder file listings, and supports public data-file listings by accession/pattern with endpoint provenance. - Verified: Official MetaboLights public pages and the EBI MetaboLights utility surface were checked for repository scope, public study listing, metadata/file usage, and ISA-Tab public-study workflows. Focused database/context/settings tests passed (`32/32`). Live tool-level smoke returned `MTBLS1` study metadata, `MTBLS1` folder listings, a valid empty public `*.mzML` data-file listing, and public accession list metadata from the EBI MetaboLights service. Final gates passed: root typecheck, website typecheck (`0 errors`), root build, website build (`34 pages`), architecture check with existing split-debt warnings only, `git diff --check`, full test suite (`520/520`), `npm pack --dry-run --json` (`entryCount: 372`), public-doc reference leakage scan, and stale-gate wording scan. - Next: Continue only on concrete remaining 1:1 parity gaps. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 22:32 PDT — biomart-source - Objective: Continue science-tool parity by turning the existing BioMart Settings preset into an executable Feynman-owned no-login source instead of a reference-shaped placeholder. - Changed: Added `extensions/research-tools/science-database-biomart.ts` and routed `biomart` through `feynman_science_database_search`. BioMart now lists Ensembl mart registry rows, datasets, common/all attributes, filters, and constrained gene/data table rows with BioMart completion-stamp checks and endpoint provenance. Updated the tool schema, runtime prompt context, Settings/Customize connector catalog, README, release notes, website homepage, website workbench guide, website release docs, and parity trackers. - Verified: Installed reference modules and live Ensembl martservice probes were checked for registry, dataset, attribute/filter, and TSV data-query contracts. Focused database/context/settings tests passed (`31/31`). Live tool-level smoke returned TP53 as `ENSG00000141510` plus registry row `ENSEMBL_MART_ENSEMBL`. Final gates passed: root typecheck, website typecheck (`0 errors`), root build, website build (`34 pages`), architecture check with existing split-debt warnings only, `git diff --check`, full test suite (`519/519`), `npm pack --dry-run --json` (`entryCount: 372`), public-doc reference leakage scan, and stale-gate wording scan. - Next: Continue only on concrete remaining 1:1 parity gaps. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 21:59 PDT — gwas-catalog-source - Objective: Continue science-tool parity by porting a stable no-login human-genetics source from the reference bio-tool surface while keeping Feynman Bio Tools standalone. - Changed: Added `gwascatalog` to `extensions/research-tools/science-database-public-atlases.ts` and routed it through `feynman_science_database_search`. GWAS Catalog now returns curated association rows by rsID, mapped gene, EFO id, or EFO trait; trait rows by text search; and study rows by GCST accession or PubMed id. Updated the tool schema, workbench runtime prompt guidance, Settings/Customize connector catalog, README, release notes, website homepage, website workbench guide, website release docs, and parity trackers. - Verified: Official/public docs and the installed reference module were checked for the GWAS Catalog v2 REST API surface. Focused database/context/settings tests passed (`23/23`). Live tool-level smoke returned one record each from GWAS association search (`101326235`), GWAS trait search (`MONDO_0956975`), and GWAS PMID study search (`GCST90103431`). Final gates passed: root typecheck, website typecheck (`0 errors`), root build, website build (`34 pages`), architecture check with existing split-debt warnings only, `git diff --check`, full test suite (`517/517`), `npm pack --dry-run --json` (`entryCount: 371`), public-doc reference leakage scan, and stale-gate wording scan. - Next: Continue only on concrete remaining 1:1 parity gaps. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 21:11 PDT — public-atlas-regulatory-sources - Objective: Continue science-tool parity by adding more stable no-login public sources from the reference bio-tool surface while keeping Feynman Bio Tools fully Feynman-owned. - Changed: Added `extensions/research-tools/science-database-public-atlases.ts` and routed `openfda`, `proteinatlas`, and `eqtlcatalogue` through `feynman_science_database_search`. openFDA returns drug label, adverse-event, and recall/enforcement records; Human Protein Atlas returns gene, synonym, Ensembl, UniProt, and tissue-expression fields; eQTL Catalogue returns v3 association, study, and dataset rows. Updated the tool schema, workbench runtime prompt guidance, Settings/Customize connector catalog, README, release notes, website homepage, website workbench guide, website release docs, and parity trackers. - Verified: Official/public docs were checked for openFDA, Human Protein Atlas, and eQTL Catalogue API surfaces. Focused database/context/settings tests passed (`21/21`). Live tool-level smoke returned one record each from openFDA (`008ee85b-5cac-45a6-a857-a828f8125175`), Human Protein Atlas (`ENSG00000141510`), and eQTL Catalogue (`chr17_6690037_T_G`). Final gates passed: root typecheck, website typecheck (`0 errors`), root build, website build (`34 pages`), architecture check with existing split-debt warnings only, `git diff --check`, full test suite (`515/515`), `npm pack --dry-run --json` (`entryCount: 371`), public-doc reference leakage scan, and stale-gate wording scan. - Next: Continue only on concrete remaining 1:1 parity gaps. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 20:25 PDT — ebi-structural-interactions-sources - Objective: Continue science-tool parity by adding more no-login public EBI sources from the installed reference bio-tool catalog while keeping Feynman Bio Tools standalone. - Changed: Added `extensions/research-tools/science-database-ebi-structural.ts` and routed `chebi`, `complexportal`, `intact`, and `emdb` through `feynman_science_database_search`. ChEBI returns compound accessions, formula/mass/structure identifiers, synonyms, and ontology detail records; Complex Portal returns CPX accessions, species, participant accessions, and complex metadata; IntAct returns interaction accessions, participants, MI scores, detection methods, and PubMed evidence; EMDB returns cryo-EM map accessions, resolution, fitted PDB ids, release dates, and map metadata. Updated the tool schema, runtime prompt guidance, Settings/Customize connector catalog, README, release notes, website homepage, website workbench guide, website release docs, and parity trackers. - Verified: Official/public docs were checked for IntAct, ChEBI, EMDB, and Complex Portal API surfaces. Focused database/context/settings tests passed (`18/18`). Live tool-level smoke returned one record each from ChEBI (`CHEBI:759292`), Complex Portal (`CPX-6093`), IntAct (`EBI-1562402`), and EMDB (`EMD-77042`). Final gates passed: root typecheck, website typecheck (`0 errors`), root build, website build (`34 pages`), architecture check with existing split-debt warnings only, `git diff --check`, full test suite (`512/512`), `npm pack --dry-run --json` (`entryCount: 370`), public-doc reference leakage scan, and stale-gate wording scan. - Next: Continue only on concrete remaining 1:1 parity gaps. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 19:56 PDT — reference-longtail-science-sources - Objective: Continue Claude Science science-tool parity by adding concrete no-login public sources from the installed reference bio-tool catalog while keeping the runtime Feynman-owned. - Changed: Added `extensions/research-tools/science-database-longtail.ts` and routed `alphafold`, `arrayexpress`, `jaspar`, `mgnify`, and `mygene` through the existing `feynman_science_database_search` tool. AlphaFold DB returns UniProt-linked predicted structure records and PDB/CIF/PAE links; ArrayExpress/BioStudies returns migrated functional-genomics studies; JASPAR returns transcription-factor matrix records; MGnify returns metagenomics study/biome/ENA metadata; MyGene.info returns gene annotation ids and summaries. Updated the tool schema, Pi prompt guidance, runtime context, Settings/Customize connector catalog, README, release notes, website homepage, website workbench guide, and parity trackers. - Verified: Official/public docs were checked for AlphaFold DB API access, JASPAR API, MyGene query service, BioStudies/ArrayExpress migration/API, and MGnify REST API. Focused database/context/settings tests passed (`14/14`). Live tool-level smoke returned one record each from AlphaFold DB (`AF-P05067-F1`), ArrayExpress/BioStudies (`E-GEOD-17155`), JASPAR (`MA0106.1`), MGnify (`MGYS00006825`), and MyGene.info (`TP53`). Final gates passed: root typecheck, website typecheck (`0 errors`), root build, website build (`34 pages`), architecture check with existing split-debt warnings only, full test suite (`508/508`), `npm pack --dry-run --json` (`entryCount: 369`), `git diff --check`, public-doc reference leakage scan, and stale-gate wording scan. GWAS Catalog was deferred in that slice because the first endpoint probes returned 404/406 before the later v2 contract check. - Next: Keep looking for concrete remaining no-login reference sources or specialist workflow gaps. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 19:12 PDT — reference-artifact-viewer-parity - Objective: Close the reference bundle's remaining media/document artifact viewer gap while keeping previews implemented in Feynman-owned React code. - Changed: Expanded artifact kind classification and workbench previews for audio, video, XLSX spreadsheets, Jupyter notebooks, and LaTeX/TeX files. Spreadsheet previews parse bounded workbook sheets with JSZip plus `fast-xml-parser`; notebook previews summarize kernels, cells, outputs, and source snippets; LaTeX previews summarize sections, equations, citations, labels, bibliography commands, and source. Added a shared text-preview fetch policy so binary/media/XLSX panes use download or media URLs instead of the text preview endpoint. Updated scan/file-type handling, React artifact inspector components, preview styling, source tests, README, release notes, website docs, and parity trackers. - Verified: The installed reference bundle was checked for separate audio, video, spreadsheet, notebook, and LaTeX preview chunk names. Focused React/source tests passed (`18/18`) for preview classification, fetch policy, parsers, and source/CSS ownership. Rendered browser smoke in a disposable workspace opened XLSX, IPYNB, LaTeX, audio, and video artifacts with zero overflow, zero console errors, and zero failed responses; screenshots were written under `outputs/playwright/feynman-artifact-preview-*.png`. Final gates passed: root typecheck, website typecheck (`0 errors`), root build, website build (`34 pages`), architecture check with existing split-debt warnings only, full test suite (`505/505`), `npm pack --dry-run --json` (`entryCount: 368`), `git diff --check`, public-doc reference leakage scan, and stale-gate wording scan. - Next: Continue only on concrete remaining 1:1 parity gaps found by reference or seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 18:13 PDT — frame-backfill-poison-parity - Objective: Close the Claude Science `frame_backfill_poison` structural gap while keeping Feynman's default state honest when no frame backfill failures exist. - Changed: Added `src/workbench/frame-backfill-poison.ts`, expanded workbench ledger/state types with `frameBackfillPoison`, and expose frame-scoped backfill health rows through `/api/state`. The ledger reads Feynman's own `.feynman/workbench/frame-backfill-poison.json` when present, accepts both reference-shaped snake-case and Feynman camel-case fields, filters rows to live frame ids, and returns an empty array for clean workspaces. Added `tests/workbench-reference-table-coverage.test.ts` so every audited reference table maps to a Feynman-owned `WorkbenchState` key. Updated README, release notes, website homepage copy, website release notes, the Science Workbench guide, and parity trackers to mention frame backfill health records. - Verified: The installed Claude Science DB and migration were checked for `frame_backfill_poison`; the local reference table currently has zero rows and defines `frame_id`, `fail_count`, `terminal`, `reason`, and `updated_at`. Focused frame/workbench tests passed (`27/27`) for persisted row normalization, live-frame filtering, empty API default, and existing frame/frame-message behavior; focused reference-table coverage tests passed (`3/3`). Final gates passed: root typecheck, website typecheck (`0 errors`), root build, website build (`34 pages`), architecture check with existing split-debt warnings only, full test suite (`504/504`), `npm pack --dry-run --json` (`entryCount: 368`, including `dist/workbench/frame-backfill-poison.js`), and `git diff --check`. - Next: Continue only on concrete remaining 1:1 parity gaps found by reference or seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 17:40 PDT — project-metadata-parity - Objective: Close the Claude Science `projects` metadata gap while keeping Feynman's project rows derived from owned workspace project, run, artifact, and upload-frame state. - Changed: Expanded `WorkbenchProject` and project derivation with local user id, upload-frame id linkage, context, memory-enabled state, created timestamps, updated timestamps, run slugs, artifact paths, session counts, and artifact counts. Custom project context now appears as reference-shaped project context while the chat prompt still reads the stored Feynman project file. Updated README, release notes, website homepage copy, website release notes, the Science Workbench guide, and the parity trackers to mention project metadata and upload-frame linkage. - Verified: The installed Claude Science DB was checked for `projects`; local reference rows expose id, name, description, context, created/updated timestamps, user id, uploads frame id, and memory-enabled state. Focused project/frame/React tests passed (`27/27`) for project metadata, upload-frame linkage, created timestamps, custom project context, and typed React fixtures. Full gates passed: root typecheck, website typecheck (`0 errors`), root build, website build (`34 pages`), architecture check with existing split-debt warnings only, full test suite (`503/503`), `npm pack --dry-run --json` (`entryCount: 367`), and `git diff --check`. - Next: Continue only on concrete remaining 1:1 parity gaps found by reference or seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 17:14 PDT — frames-ledger-parity - Objective: Close the Claude Science `frames` structural gap while keeping Feynman's frame spine derived from owned projects, chat sessions, artifact runs, and upload areas. - Changed: Added `src/workbench/frames.ts`, expanded workbench ledger/state types with `frames`, and expose first-class frame rows through `/api/state`. Rows include root/parent frame identity, project id, agent/delegate names, conversation type, status, bounded input/output/context JSON, model and compute settings, artifact references, timestamps, root sequence, and source ownership. Updated README, release notes, website homepage copy, website release notes, the Science Workbench guide, and the parity trackers to mention frame records. - Verified: The installed Claude Science DB was checked for `frames`; the local reference DB exposes `agent` and `uploads` conversation types with parent/root ids, project ids, agent/delegate names, task summaries, hidden flags, root sequence, token/cost columns, and timestamps. Focused frame/workbench tests passed (`27/27`) for session-derived frames, artifact-run frames, upload frames, structured JSON payloads, frame-message linkage, and authenticated `/api/state` exposure. Final gates passed: `npm run typecheck`, website `npm --prefix website run typecheck`, `npm run build`, website `npm --prefix website run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`503/503`), and `npm pack --dry-run --json` (`366` files, including `dist/workbench/frames.js`). - Next: Continue only on concrete remaining 1:1 parity gaps found by reference or seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 16:18 PDT — frame-messages-parity - Objective: Close the Claude Science `frame_messages` structural gap while keeping Feynman's chat transcript state derived from owned workbench session files. - Changed: Added `src/workbench/frame-messages.ts`, expanded workbench ledger/state types with `frameMessages`, and expose one row per persisted chat turn through `/api/state`. Rows include frame id, message index, structured message JSON with `_uuid`, role, text content, status, creation timestamp, Feynman message metadata, and bounded tool-event payloads. Updated README, release notes, website homepage copy, website release notes, the Science Workbench guide, and the parity trackers to mention frame message rows. - Verified: The installed Claude Science DB was checked for `frame_messages`; the local reference DB currently has 592 rows and stores `frame_id`, `idx`, and JSON `msg_json` with `_uuid`, role, and content blocks. Focused frame-message/workbench tests passed (`25/25`) for direct state derivation, structured JSON shape, tool-event payloads, and authenticated `/api/state` exposure. Final gates passed: `npm run typecheck`, website `npm --prefix website run typecheck`, `npm run build`, website `npm --prefix website run build`, `npm run architecture:check`, full `npm test` (`501/501`), and `npm pack --dry-run --json` (`365` files, including `dist/workbench/frame-messages.js`). - Next: Continue only on concrete remaining 1:1 parity gaps found by reference or seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 15:52 PDT — safety-feedback-parity - Objective: Close the Claude Science `safety_feedback` structural gap while keeping Feynman's review-feedback state tied to owned review requests and bounded context. - Changed: Added `src/workbench/safety-feedback.ts`, expanded workbench ledger/state types with `safetyFeedback`, and record one review feedback row per frame/user/type when the existing workbench Request review action runs. Rows include root frame id, local user id, feedback type, optional model, reviewer response id, reason, bounded context snapshot, creation timestamp, and review-request source. Updated README, release notes, website homepage copy, website release notes, the Science Workbench guide, and the parity trackers to mention review feedback rows. - Verified: The installed Claude Science DB and migration were checked for `safety_feedback`; the local reference table currently has zero rows. Focused safety-feedback/review tests passed (`3/3`) for direct review requests, uniqueness by frame/user/type, bounded context snapshots, secret scan assertions, and authenticated `/api/state` exposure. Final gates passed: `npm run typecheck`, website `npm --prefix website run typecheck`, `npm run build`, website `npm --prefix website run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`499/499`), and `npm pack --dry-run --json` (`364` files, including `dist/workbench/safety-feedback.js`). - Next: Continue only on concrete remaining 1:1 parity gaps found by reference or seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 15:23 PDT — poller-lease-parity - Objective: Close the Claude Science `poller_lease` structural gap while keeping Feynman's compute polling state truthful and derived from owned runtime state. - Changed: Added `src/workbench/poller-leases.ts`, expanded workbench ledger/state types with `pollerLeases`, and derive provider `*` compute-polling lease rows from active compute jobs and pending compute termination records. Updated README, release notes, website homepage copy, website release notes, the Science Workbench guide, and the parity trackers to mention compute poller lease rows. - Verified: The installed Claude Science DB and migration were checked for `poller_lease`; the local reference DB currently has one provider `*` lease row. Focused compute lifecycle tests passed (`2/2`) for active local compute and pending Modal termination lease exposure. Final gates passed: `npm run typecheck`, website `npm --prefix website run typecheck`, `npm run build`, website `npm --prefix website run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`497/497`), and `npm pack --dry-run --json` (`363` files, including `dist/workbench/poller-leases.js`). - Next: Continue only on concrete remaining 1:1 parity gaps found by reference or seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 14:58 PDT — setup-decisions-parity - Objective: Close the Claude Science `contact_email_decisions` and `credential_ask_decisions` structural gap while keeping Feynman's setup state standalone and secret-safe. - Changed: Added `src/workbench/setup-decision-ledgers.ts`, expanded workbench ledger/state types with `contactEmailDecisions` and `credentialAskDecisions`, and derive public scientific API contact-email consent from `NCBI_EMAIL`/`ENTREZ_EMAIL`/`CROSSREF_MAILTO` plus provider credential readiness from Feynman's redacted settings/env/Pi-auth credential records. Updated README, release notes, website homepage copy, website release notes, the Science Workbench guide, and the parity trackers to mention setup decision rows. - Verified: The installed Claude Science DB and migrations were checked for `contact_email_decisions` and `credential_ask_decisions`; both local reference tables currently have zero rows. Focused setup decision tests passed (`2/2`) for direct state, authenticated `/api/state` exposure, contact-email de-duplication, accepted/pending credential decisions, and secret-redaction assertions. Final gates passed: focused regression bundle (`5/5`), `npm run typecheck`, website `npm --prefix website run typecheck`, `npm run build`, website `npm --prefix website run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`497/497`), and `npm pack --dry-run --json` (`362` files, including `dist/workbench/setup-decision-ledgers.js`). - Next: Continue only on concrete remaining 1:1 parity gaps found by reference or seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 14:27 PDT — routine-schedules-parity - Objective: Close the Claude Science `routine_schedules` structural gap while preserving Feynman's honest `/watch` contract: a recurring routine exists only when scheduling tooling is actually available. - Changed: Added `src/workbench/routine-schedules.ts`, expanded workbench ledger/state types with `routineSchedules`, and derive watch routine rows from durable `outputs/.plans/.md` watch plans plus `outputs/-baseline.md` baselines. Rows include root frame id, owner, label, JSON tick payload, cadence, enabled/blocked state, next due timestamp, last baseline result, and plan/baseline paths. Updated README, release notes, website homepage copy, website release notes, and the Science Workbench guide to mention watch routine state. - Verified: The installed Claude Science DB and migration were checked for `routine_schedules`; the local reference table currently has zero rows. Focused routine schedule tests passed (`2/2`) for direct state and authenticated `/api/state` exposure. Final gates passed: `npm run typecheck`, website `npm --prefix website run typecheck`, `npm run build`, website `npm --prefix website run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`495/495`), and `npm pack --dry-run --json` (`361` files, including `dist/workbench/routine-schedules.js`). - Next: Continue only on concrete remaining 1:1 parity gaps found by reference or seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 13:59 PDT — skill-source-license-parity - Objective: Close the Claude Science `marketplace_sources` and `skill_license_assents` structural gap while keeping Feynman's skill catalog Feynman-owned and local. - Changed: Added `src/workbench/marketplace-ledgers.ts`, expanded workbench ledger/state types with `marketplaceSources` and `skillLicenseAssents`, and derive a pinned `Feynman Science Skill Pack` source plus per-skill license-assent rows from Feynman's local `skills/**/SKILL.md` catalog and package license. Updated README, release notes, website homepage copy, website release notes, and the Science Workbench guide to mention skill source/license state without introducing an external marketplace runtime dependency. - Verified: The installed Claude Science DB and migrations were checked for `marketplace_sources` and `skill_license_assents`. Focused skill-ledger tests passed (`2/2`) for direct state and authenticated `/api/state` exposure. Final gates passed: `npm run typecheck`, website `npm --prefix website run typecheck`, `npm run build`, website `npm --prefix website run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`493/493`), and `npm pack --dry-run --json` (`360` files, including `dist/workbench/marketplace-ledgers.js`). - Next: Continue only on concrete remaining 1:1 parity gaps found by reference or seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 13:27 PDT — use-intent-and-docs-parity - Objective: Close the Claude Science `use_intent_declarations` structural gap and make the public README/website/docs describe the standalone Feynman science workbench rather than only the terminal CLI. - Changed: Added `src/workbench/use-intent-declarations.ts`, expanded workbench ledger/state types with `useIntentDeclarations`, and derive onboarding-backed intent rows for field, goal, workflow, task, specialist, compute default, tools, bottlenecks, permissions, Feynman Bio Tools connector suggestions, and seed workflow suggestions. Updated the root README, `RELEASES.md`, website homepage, website command reference, setup/quickstart/install docs, release docs, docs sidebar, and a new Science Workbench guide to describe `feynman serve`, Feynman Bio Tools, redacted credential availability, onboarding intent context, and the standalone no-reference-runtime boundary. - Verified: Focused workbench new-session and secret-ledger tests passed (`11/11`) after the use-intent implementation. Final gates passed: `npm run typecheck`, website `npm --prefix website run typecheck`, `npm run build`, website `npm --prefix website run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`493/493`), and `npm pack --dry-run --json` (`359` files). Rendered website smoke captured `outputs/playwright/feynman-website-workbench-docs.png` and `outputs/playwright/feynman-website-home-mobile.png`; the built HTML contains the new workbench route, sidebar link, `feynman serve` command reference, Feynman Bio Tools copy, standalone boundary text, and corrected Node engine range. - Next: Finish the gate sweep and then continue only on concrete remaining 1:1 parity gaps found by reference or seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 06:32 PDT — session-activity-ledger-parity - Objective: Close the Claude Science `events`/`notifications`/`queued_user_messages`/`session_seen_marks` structural gap while keeping the activity ledger Feynman-owned and research-scoped. - Changed: Added `src/workbench/session-activity.ts`, `src/workbench/summary.ts`, state arrays for `events`, `notifications`, `queuedUserMessages`, `sessionSeenMarks`, and `sessionActivity`, plus summary counters for activity, notifications, queued messages, and unread activity. The launcher Research queue now surfaces unread/queued/running/failed session activity alongside plan and compute cards. - Verified: The installed Claude Science DB was checked for the reference tables, and the local reference bundle was checked for queued-user-message and notification rendering paths. Focused session-activity/read-cursor/React-source tests passed. Fresh-server API smoke returned `15` events, `13` notifications, `0` queued user messages, `1` seen mark, and `25` session activity items. Browser smoke rendered five visible `Unread` session activity cards, zero console errors, zero failed responses, and no horizontal overflow (`1440/1440`, queue `1074/1074`). Final gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`464/464`), and `npm pack --dry-run` (`331` files). - Next: Continue only on the next concrete 1:1 parity gap from reference or seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 06:12 PDT — session-claims-ledger-parity - Objective: Close the Claude Science `session_claims`/verification-check claim-linkage gap while keeping the claim ledger Feynman-owned and research-scoped. - Changed: Added `src/workbench/claims.ts`, `state.claims`, `summary.claimCount`, deterministic `claimId`s on verification checks, artifact metadata claim export, and a Claims section in the artifact Provenance tab. Explicit `Claim:`, `Finding:`, `Conclusion:`, and `Verified:` markers in research Markdown become structured claim records, and verification checks merge into the same ledger. - Verified: The installed Claude Science DB was checked for `session_claims` and verification-check claim linkage. Focused claim/state/UI tests passed. Fresh-server API smoke returned `10` claims, `10` checks, and `summary.claimCount: 10`. Browser smoke opened `outputs/reference-audit/verification-matrix.md`, rendered two Claims rows with zero console errors, zero failed responses, and no horizontal overflow (`1440/1440`, panel `432/432`). Final gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`463/463`), and `npm pack --dry-run` (`329` files). - Next: Continue only on the next concrete 1:1 parity gap from reference or seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 06:00 PDT — memory-notes-screen-parity - Objective: Close the Claude Science MemoryScreen/NoteModal/NotePreviewModal gap while keeping memory and notes Feynman-owned and standalone. - Changed: Added `.feynman/workbench/memory.json` as the local workbench memory store, authenticated `/api/memory` and `/api/notes` mutation routes, `memories` and `notes` in workbench state, memory resource counts in Settings/Customize, and a React Memory rail panel. The panel saves profile/project/session/artifact/category scoped memory rows, saves target notes for the active session or artifact, shows saved-row metadata, and deletes records without using `~/.claude-science` at runtime. - Verified: The installed Claude Science DB and bundle were checked for `notes`, `memories`, `memory_categories`, `MemoryScreen`, `NoteModal`, and `NotePreviewModal`. Focused memory/resource tests passed. Browser smoke on the seed workflow route saved a scoped session memory plus a session target note, verified both through `/api/state`, removed both through `/api/memory` and `/api/notes`, confirmed no smoke strings remained in `.feynman/workbench/memory.json`, measured no horizontal overflow (`1440/1440`, panel `460/460`), recorded zero console errors, and captured `outputs/playwright/feynman-memory-notes-panel.png`. Final gates passed: `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`462/462`), and `npm pack --dry-run` (`328` files). - Next: Continue only on the next concrete 1:1 parity gap from reference or seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 — composer-reference-mentions-parity - Objective: Close the Claude Science-style composer affordance gap so the React workbench can reference project artifacts, sessions, and commands directly from chat. - Changed: Added a Feynman-owned composer mention model and UI. Typing or clicking `@` opens artifact suggestions, `#` opens session suggestions, and `/` opens command/skill suggestions from the real workbench state. Suggestions insert the concrete artifact path, session slug, or executable command. Command ranking now prioritizes resource names and command strings over incidental description matches. Mobile workbench routes now open chat-first instead of letting the default Files side panel cover the composer. - Verified: Focused React shell tests passed (`15/15`) with new composer helper coverage. Desktop browser smoke on the seed-workflow route inserted `@outputs/open-science-seeds/example_enzyme_engineering/plddt.npy`, `#example_crispr_screen`, and `/lit`, with zero browser errors and no horizontal overflow. Mobile browser smoke at `390x740` confirmed the side panel is closed by default, the suggestion menu fits the viewport, the composer tool row wraps above the textarea, and no horizontal overflow occurs. Full gates passed: `npm run typecheck`, `npm run build` through `npm pack --dry-run`, `npm run architecture:check`, `git diff --check`, full `npm test` (`454/454`), and `npm pack --dry-run`. Screenshots: `outputs/playwright/feynman-composer-mentions.png` and `outputs/playwright/feynman-composer-mentions-mobile.png`. - Next: Continue only on concrete remaining 1:1 parity gaps; hosted NVIDIA ESMFold remains credential-gated until `NVIDIA_API_KEY` exists. ### 2026-07-03 — numpy-tensor-artifact-preview-parity - Objective: Close the Claude Science-style tensor artifact gap for Feynman's packaged enzyme-engineering seed workflow while keeping tensor parsing and rendering inside Feynman-owned code. - Changed: Added `.npy` and `.npz` artifact content types, routed them through authenticated binary downloads instead of UTF-8 text previews, added a React tensor preview using `npyjs` and `jszip`, and rendered array cards with dtype/shape/order metadata, bounded stats, vector plots, matrix heatmaps, archive member lists, and sample values. - Verified: Focused tensor/workbench tests passed (`37/37`). Full gates passed: `npm run typecheck`, `npm run build` through `npm pack --dry-run`, `npm run architecture:check`, `git diff --check`, full `npm test` (`453/453`), and `npm pack --dry-run` with the packaged seed `.npy`/`.npz` artifacts included. Browser smoke opened the Feynman-owned `is621_esmfold.npz` and `plddt.npy` seed artifacts, rendered `NPZ tensor preview | 4 arrays` and `NPY tensor preview | 1 array`, verified four NPZ array cards, heatmap/vector geometry, correct binary content types, no page-level horizontal overflow, and zero console/page/request failures. Screenshots: `outputs/playwright/feynman-tensor-npz-preview.png` and `outputs/playwright/feynman-tensor-npy-preview.png`. - Next: Continue only on concrete remaining 1:1 parity gaps; hosted NVIDIA ESMFold remains credential-gated until `NVIDIA_API_KEY` exists. ### 2026-07-03 — open-science-genome-browser-parity - Objective: Close the Claude Science-style genome/variant artifact viewer gap while keeping Feynman standalone and library-backed. - Changed: Added `igv@3.8.4` and wired VCF/BED/GFF previews to an embedded IGV.js genome browser inside the existing artifact inspector. Feynman now infers loci from the selected artifact, mounts IGV through an empty imperative stage to avoid React/IGV DOM ownership conflicts, keeps parsed rows/stat cards underneath for provenance, and widens the Files side panel for genome/molecule/structure artifacts so scientific viewers are not cramped. - Verified: Focused React shell tests passed (`13/13`) with VCF/BED/GFF/GenBank track inference coverage. Browser smoke on a disposable workspace opened `outputs/variants.vcf` at `/projects/workspace/frames/variants`, rendered `IGV 3.8.4 | VCF at chr1:100000-100001`, confirmed IGV shadow-DOM controls, panel width `640px`, stage width `585px`, no page-level horizontal overflow, hidden stage overflow, and zero console/page/request failures. Expected IGV warning was limited to unindexed tiny VCF preview loading. Screenshots: `outputs/playwright/feynman-igv-genome-preview.png` and `outputs/playwright/feynman-igv-stage.png`. Full gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`452/452`), and `npm pack --dry-run` with `dist/workbench-web/assets/igv-*.js` included. - Next: Continue only on remaining concrete 1:1 parity gaps; hosted NVIDIA ESMFold remains credential-gated until `NVIDIA_API_KEY` exists. ### 2026-07-03 — open-science-model-endpoint-parity - Objective: Close the Claude Science-style model-endpoint control-plane gap while keeping Feynman standalone and Feynman-owned. - Changed: Added `feynman_model_endpoint_call`, an executable Pi tool for NVIDIA BioNeMo/NIM-style scientific model calls. Hosted ESMFold uses `NVIDIA_API_KEY`; self-hosted/local AlphaFold2 NIM accepts an `endpointUrl`. Endpoint responses now save under `outputs/model-endpoints` with a provenance sidecar, and Settings/runtime context expose the tool as the NVIDIA BioNeMo NIM model endpoint path. - Verified: Focused endpoint/settings/context/chat tests passed (`12/12`), `npm run typecheck` passed, and a real local HTTP smoke through the registered tool wrote PDB/provenance artifacts. Full gates passed: `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`452/452`), and `npm pack --dry-run` with `extensions/research-tools/model-endpoints.ts` included. Browser smoke on fresh server `127.0.0.1:6188` verified Customize exposes `NVIDIA BioNeMo NIM`, `feynman_model_endpoint_call`, and `outputs/model-endpoints`, with no console/page/network failures and no horizontal overflow; screenshot `outputs/playwright/feynman-model-endpoint-settings.png`. The local environment has no `NVIDIA_API_KEY`, so hosted NVIDIA ESMFold execution remains unverified instead of falsely claimed. - Next: Keep hosted NVIDIA execution marked credential-gated until `NVIDIA_API_KEY` exists, then run one hosted ESMFold smoke. ### 2026-07-03 — open-science-reference-connector-parity - Objective: Close the remaining no-login Claude Science bio-tool source gap while keeping Feynman standalone and Feynman-owned. - Changed: Added built-in `feynman_science_database_search` sources for PubChem, BindingDB, STRING, KEGG, Rhea, and Rfam; exposed them in Feynman Bio Tools and the Settings/Customize connector catalog; promoted Chemistry, RNA, and Structures & Interactions presets to executable built-ins where appropriate. - Verified: Focused source/settings tests passed for the six new sources and connector catalog exposure. Live Feynman-tool smoke succeeded against PubChem `aspirin`, BindingDB `uniprot:P35355 cutoff=100`, STRING `TP53,BRCA1 species=9606 score=700`, KEGG `find:compound aspirin`, Rhea `glucose`, and Rfam `RF00005`. `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, `npm pack --dry-run`, and full `npm test` passed (`449/449`). - Next: Continue compute/runtime/provider parity; hosted NVIDIA NIM execution stays unverified until `NVIDIA_API_KEY` exists. ### 2026-07-03 — open-science-seed-fixture-parity - Objective: Close the Claude Science seed-workflow parity gap without leaving Feynman dependent on `~/.claude-science` or ignored workspace outputs. - Changed: Added package-owned `fixtures/open-science-seeds` with the four workflow families, included `fixtures/` in the package manifest, added a startup sync that materializes missing seed files into `outputs/open-science-seeds`, and preserved existing workspace edits by skipping files that already exist. - Verified: The fixture inventory has 83 artifacts across CRISPR screen (20), enzyme engineering (28), extremophile protein (19), and immunotherapy scRNA-seq (16). `npm test -- --test-name-pattern="seed fixture|seed workflows"` ran the repo harness and passed (`446/446`). - Next: Continue 1:1 parity on remaining science connector/tool depth or long-tail artifact action states while NVIDIA hosted execution waits on `NVIDIA_API_KEY`. ### 2026-07-02 19:17 PDT — intake-sweep-open-184 - Objective: Run the `check-new-issues` intake sweep against live GitHub/package/runtime state while preserving the existing dirty React workbench tree. - Checked: Local `main` is still one commit ahead of `origin/main` at `6c84b24` with the existing dirty workbench/package slice preserved. Live GitHub has open issues `#184` and `#182`, zero open PRs, latest `main` workflow run `Publish and Release` `28343487961` succeeded at `cb5fa56`, latest GitHub release is `v0.3.5` with four native assets, npm latest is `@companion-ai/feynman@0.3.5`, Pi latest/current is `0.80.3`, and `@companion-ai/alpha-hub` remains `0.1.3`. - Decisions: `#184` is a user research-topic support request, not a repo defect or feature to port. `#182` remains deferred/externally blocked because evidence points to alphaXiv/Clerk OAuth redirect behavior before Feynman/alpha-hub receives a callback, while unauthenticated alphaXiv search remains available. No open PRs were available to merge or port. Contributor branch `origin/fix/deepresearch-local-model-warning` is not an open PR and its core warning behavior is already present in the local dirty tree with tests, so no additional port was made. - Verified: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, root `npm audit --omit=dev`, website `npm audit --omit=dev`, full `npm test` (`431/431`), `npm pack --dry-run`, and a disposable installed-tarball smoke from `/tmp/feynman-pack-smoke-ZWjC2U/companion-ai-feynman-0.3.5.tgz` running `feynman --help` and `feynman packages --help` passed. Package freshness checks found only non-security drift in root and website dependencies. - Next: Keep `#184` as non-product GitHub support unless someone wants to answer it manually; keep `#182` deferred until alphaXiv/Clerk OAuth redirect behavior changes or alpha-hub ships a supported auth alternative. ### 2026-07-02 08:58 PDT — react-shell-streaming-chat - Objective: Move the React/Vite workbench shell from blocking chat submission toward Claude Science's live research-chat loop with streamed assistant text and visible tool progress. - Researched: Rechecked the installed Claude Science runtime bundle at `~/.claude-science/runtime/0.1.0-dev.20260630.t160235.sha2e3e6f9-release/web-dist/assets/`, confirming the shell modules `MessageBubble`, `useFrameMessages`, `ProjectControlPlane`, `FilesOverlay`, and `ArtifactTile`. Rechecked the local Claude Science SQLite frame message store, which now has 592 frame messages; seeded tool-use blocks include `generate_plan`, `manage_environments`, `skill`, and `bash` with user-facing descriptions such as `Planning scRNA-seq immunotherapy response analysis`, `Listing envs for scanpy availability`, and `Downloading GSE120575 supplementary files`. - Changed: The React shell composer now uses `/api/chat/message/stream` instead of blocking `/api/chat/message`, parses SSE frames, streams assistant deltas into the transcript, merges streamed tool events into the latest assistant message, lets follow-up text steer a running Pi turn through `/api/chat/message/steer`, and exposes a Stop control backed by `/api/chat/abort`. Stream parsing and assistant tool merging now live in `workbench-web/src/stream.ts` with direct tests, and `npm run typecheck` now includes `workbench-web/tsconfig.json` so TSX is covered by the normal gate. - Verified: Temporary prompt-executor server `http://127.0.0.1:54812/app-shell/projects/active-plans/frames/open-science-workbench?token=react-stream-smoke` streamed `Streamed React shell reply: stream a quick verification update` into the React transcript and rendered the tool row `Run verification notebook complete` with zero console warnings/errors; screenshot `outputs/playwright/feynman-react-shell-stream-smoke.png`. `npm run typecheck`, `npm run build:workbench-web`, `npm run build`, `npm run architecture:check`, `git diff --check`, focused React/workbench tests (`25/25`), and full `npm test` passed (`417/417`). - Next: Continue React shell parity on artifact preview/open actions, Files overlay behavior, Customize mutations, notebook/compute panes, and annotation/refinement flows before switching `/projects/...` to React. ### 2026-07-02 08:39 PDT — open-science-workbench-react-shell - Objective: Stop growing the crowded string-rendered workbench shell and start the Claude Science-shaped React/Vite app shell on top of the existing Feynman/Pi APIs. - Researched: Rechecked the live Claude Science product page, OpenCode's desktop/app package split, and Conductor's React/Vite dashboard structure. The reference direction is a backend-backed app shell with a narrow project/session rail, central chat, explicit Files/Customize surfaces, pane-local scroll, artifact state, and provenance rather than an always-expanded dashboard. - Changed: Added `workbench.vite.config.ts`, `workbench-web/`, React/Vite/lucide dependencies, a `build:workbench-web` build step, authenticated `/app-shell/...` static serving through `src/workbench/static-shell.ts`, and `tests/workbench-react-shell.test.ts`. The React shell reads `/api/state`, opens real workbench chat sessions, sends messages through `/api/chat/message`, shows project/session rail, central transcript/composer, Files artifact panel, and Customize resource panel. The rail caps at six visible sessions plus an overflow count and hides its scrollbar chrome. - Verified: Fresh server `http://127.0.0.1:51274/app-shell/projects/active-plans/frames/open-science-workbench?token=cxf8y2kVEXs0PJs3Zjpv1WGORRRtWyfc` measured default viewport `1280x720`, no document overflow, `bodyOverflow:hidden`, rail `256x720`, conversation `678.4x720`, side panel `345.6x720`, six visible session rows, `10 more sessions`, session-list overflow hidden, and zero console warnings/errors. Mobile `390x740` measured no document overflow, hidden rail, overlay side panel, and zero warnings/errors. Screenshots: `outputs/playwright/feynman-react-shell.png` and `outputs/playwright/feynman-react-shell-no-rail-scroll.png`. `npm run build:workbench-web`, `npm run build`, `npm run typecheck`, `npm run architecture:check`, focused shell/UI tests, and full `npm test` passed (`416/416`). - Next: Continue migrating the default `/projects/...` surface to the React shell only after stream handling, artifact preview actions, Files overlay parity, and Customize mutations reach feature parity with the existing workbench. ### 2026-07-02 08:00 PDT — open-science-workbench-density-framework - Objective: Re-anchor the crowded active frame to the installed Claude Science app and choose the durable UI framework direction instead of continuing ad hoc template sprawl. - Researched: Launched the installed `/Applications/Claude Science.app` through a fresh `claude-science url`, captured launcher/project screenshots, and inspected the bundled Vite web app modules plus local SQLite schema. The reference structure is a sparse project launcher, narrow project/session rail, central conversation, explicit Files/Customize/Workspace surfaces, pane-local scrolling, and artifact/provenance drawers rather than a document page with every surface visible at once. - Changed: Collapsed the active rail session list to the active session plus six recent rows with a quiet overflow count, preserving session navigation while removing the all-history rail dump. Recorded the framework decision: keep Feynman's Pi/workbench backend, but move durable UI work toward a React/Vite app shell rather than growing string-rendered HTML and global CSS. - Verified: Fresh server `http://127.0.0.1:64584/projects/active-plans/frames/open-science-workbench?token=O0GFnV3ygqfjrLo1TihaZt0T3mbft-LI` measured no document overflow, `body` overflow hidden, rail `196x720`, central chat `1084x720`, transcript `878x523.4` with hidden scrollbar chrome, hidden right pane by default, hidden model/config chips by default, seven visible session rows, `9 more sessions`, and zero console errors. Screenshot: `outputs/playwright/feynman-patched-collapsed-rail.png`. Focused workbench UI/new-session tests passed (`7/7`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` passed (`415/415`). - Next: Run the full gate, then start the React/Vite shell migration in slices around project rail, chat transcript, composer, artifact viewer, Files overlay, and Customize settings without changing the Pi-backed API contract. ### 2026-07-02 07:34 PDT — open-science-workbench-gnomad-and-rail-cleanup - Objective: Continue the Claude Science parity pass by adding the installed app's gnomAD-style variant source and removing the remaining crowded rail/search chrome from the active frame. - Researched: Rechecked the public Claude Science page and stored installed-app screenshots. The reference frames Claude Science as a workbench around scientific tools, database connections, compute, reproducible artifacts, and provenance, with a light current-project/session rail rather than an all-project dashboard inside the project view. Re-read the installed Claude Science gnomAD client/query source, which uses the public gnomAD GraphQL API, `gnomad_r4`, and a longer request timeout. - Changed: Added `gnomad` to the built-in `feynman_science_database_search` source set for rsID search, direct variant allele-frequency lookup, and gene constraint lookup; updated runtime prompt/settings resources/tests for gnomAD; tightened the active frame rail to the current project only, hid the rail filter box in the compact frame shell, fixed session-list horizontal overflow, narrowed the rail to `196px`, and capped the chat/composer column to `880px` so the screen reads as chat-first instead of dashboard-wide. - Verified: Browser smoke on `http://127.0.0.1:6174/projects/active-plans/frames/open-science-workbench?token=JjwtbTyutG_ANMCEMJlq21OnR9dvBOmn` measured default columns `196px 1084px`, visible project rows `["Active Plans"]`, search input `display:none`, document overflow `0/0`, session list `scrollbarWidth:none` with no horizontal overflow, hidden right pane, and screenshots `outputs/playwright/feynman-open-science-workbench-claude-rail-fixed.png` plus `outputs/playwright/feynman-open-science-workbench-claude-rail-fixed.json`. Split mode measured `workspace-open artifact-view-open`, columns `196px 546.406px 537.594px`, right tabs/tab panel/artifact strip/preview tabs hidden, preview scrollbar chrome hidden, and screenshot `outputs/playwright/feynman-open-science-workbench-claude-rail-split.png`. Focused UI/database/settings/context tests passed (`15/15`), `npm run typecheck` passed, full `npm test` passed (`415/415`), and `git diff --check` passed. - Next: Continue with exact PDF renderer glyph anchoring, deeper variant annotation flows, and NVIDIA hosted execution once credentials exist. ### 2026-07-02 07:11 PDT — open-science-workbench-artifact-view-and-gtex - Objective: Continue correcting the active Open Science Workbench frame toward Claude Science's control-plane structure and add more no-setup science sources from the installed reference app. - Researched: Rechecked the installed Claude Science project view screenshot and current Feynman route. The reference keeps the default frame as rail + conversation, then uses the right side as an intentional selected-artifact viewer; Feynman's explicit artifact Open path still showed the Files browser, tabs, artifact tabs, and preview stacked together, which made the split state crowded. - Changed: Made frame/project navigation leave the artifact viewer closed and unselected by default; tightened sidebar session rows to one-line `32px` rail items with hidden scrollbar chrome; made explicit artifact selection open the split viewer; added an `artifact-view-open` mode that hides the right-pane tab/file-browser chrome so the selected artifact gets the whole right pane; expanded `feynman_science_database_search` with GTEx tissue-expression lookup and QuickGO UniProt GO-annotation lookup; updated runtime prompt, Customize connector presets, and tests for the twenty built-in read-only science sources. - Verified: Restarted the local server at `http://127.0.0.1:6174/?token=8DGNU6J1WVLjPmwV0tn2M530nGxXyla9`. Browser metrics for `/projects/active-plans/frames/open-science-workbench` show default `workspaceOpen:false`, `artifactViewOpen:false`, two columns `204px 1236px`, right pane `display:none`, session row height `32`, and session scrollbar `none`; after clicking the artifact Open button, metrics show `workspaceOpen:true`, `artifactViewOpen:true`, columns `204px 631.203px 604.797px`, right pane rows `960px`, and right tabs/tab panel/artifact tabs/preview tabs all hidden. Screenshots: `outputs/playwright/feynman-open-science-workbench-artifact-mode-default.png` and `outputs/playwright/feynman-open-science-workbench-artifact-mode-split.png`. Focused tests passed (`15/15`), full `npm test` passed (`415/415`), `npm run typecheck` passed, and `git diff --check` passed. - Next: Continue with gnomAD/variant catalogs and exact PDF renderer glyph anchoring without reopening the default frame into a crowded workspace pane. ### 2026-07-02 06:47 PDT — open-science-workbench-collapse-and-specialty-bio - Objective: Fix the visibly crowded active Open Science Workbench frame and continue moving the chat tool layer toward Claude Science's bundled scientific database behavior. - Researched: Rechecked the live installed Claude Science project control plane, which uses a project rail, central research chat, generated artifact tray, and right artifact preview for useful selected artifacts; rechecked Feynman's current rendered route and found the right artifact/workspace column was being served from stale server CSS and, when open, defaulted to a long plan artifact that made the route feel like a scroll-heavy document pane instead of a chat. - Changed: Made the desktop right workspace truly on-demand by defaulting the workbench frame to the project rail plus chat column and only adding the right column when `workspace-open` is active. Added `extensions/research-tools/science-database-specialty.ts` and wired `feynman_science_database_search` to six Claude Science-style public bio sources: OLS, ENCODE, InterPro, GEO, PRIDE, and Reactome, with stable ids/source URLs/provenance returned through the same Pi tool contract. - Verified: Restarted the local server on `http://127.0.0.1:6174/?token=wrj4sU01wZGHTJx5fipIgcWxlhlCqDOL`; the active frame screenshot `outputs/playwright/feynman-open-science-workbench-after-restart.png` shows the crowded right pane gone on first load, and served HTML contains the two-column default plus `body.workspace-open` three-column override. Captured Claude Science dashboard/project references at `outputs/playwright/claude-science-reference-dashboard.png` and `outputs/playwright/claude-science-reference-project-direct.png`. Focused tests passed (`7/7`), `npm run typecheck` passed, and full `npm test` passed (`415/415`). - Next: Continue functional parity on GTEx/QuickGO/variant catalogs, better artifact-selection defaults for frame routes, and exact PDF renderer glyph anchoring without reintroducing always-on dashboard chrome. ### 2026-07-02 06:24 PDT — open-science-workbench-claude-column-frame - Objective: Replace the crowded active frame with a Claude Science-shaped research workbench structure and keep expanding no-setup science sources. - Researched: Used the installed Claude Science runtime/page evidence already captured for projects/frames/chat/artifact history, then rechecked the live Feynman route and the current Pi/workbench code path before patching. - Changed: Reworked the active frame into a persistent desktop project rail, full-height chat column, and right artifact inspector; restored a compact topbar/drawer structure for mobile; made Files open the full overlay from the visible rail; split Markdown preview rendering/styles out of oversized preview modules; and expanded the built-in database tool to bioRxiv, medRxiv, UniProt, RCSB PDB, and Ensembl in addition to the existing seven sources. - Verified: Fresh server `http://127.0.0.1:6174/projects/active-plans/frames/open-science-workbench?token=b3R6bfbeh5Y9ubiNzoVlV73qy6vgoPmX` measured no desktop/mobile document overflow, desktop columns `204px / 573.6px / 662.4px`, visible Markdown preview, Files overlay `1440x904`, mobile chat under the `390x80` topbar with overlap `0`, and zero browser console/request failures. Live API smoke returned records from UniProt, RCSB PDB, Ensembl, bioRxiv, and medRxiv. `git diff --check`, `npm run typecheck`, `npm run build`, `npm run architecture:check`, focused tests, and full `npm test` passed (`414/414`). - Next: Continue parity on pathway/variant sources such as gnomAD, GTEx, ENCODE, and Reactome, plus exact PDF renderer glyph anchoring. ### 2026-07-02 05:27 PDT — open-science-workbench-frame-layout-correction - Objective: Fix the active Open Science Workbench frame feeling crowded/broken by correcting the Claude-style chat/artifact split layout. - Researched: Reused the installed Claude Science app/runtime evidence for the quiet chat-first frame with secondary Files/Workspace surfaces; remeasured the live Feynman route before patching and found the transcript was only `222px` tall inside a `743px` conversation card because the frame grid still reserved an empty second row. - Changed: Made the transcript own the full middle column, hid nonessential topbar version/refresh chrome, removed the visible `State` kicker, widened the desktop Workspace drawer to `720px`, structured the drawer file controls, hid the redundant drawer grid/list toggle, and made mobile preview actions wrap. - Verified: Fresh server `http://127.0.0.1:6174/projects/active-plans/frames/open-science-workbench?token=GCh6fz2gmA_zyZcjE7NGkMoWIeEClacJ` measured desktop/mobile closed/open layouts with no document overflow and zero console errors; desktop transcript is now `1014x741`, Workspace drawer is `720x924`, and mobile drawer preview controls fit in `361px`. Screenshots saved under `outputs/playwright/open-science-workbench-layout-*.png`. `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check -- src/workbench/ui-style-frame.ts`, and full `npm test` passed (`413/413`). - Next: Continue parity on deeper specialty science database execution and exact PDF renderer glyph/page anchoring. ### 2026-07-02 00:51 PDT — open-science-workbench-read-cursors - Objective: Close the Claude Science frame read-cursor gap so long research frames remember the last read transcript message across reloads. - Researched: Re-opened the installed Claude Science migration `0055_frame_read_cursors.sql`, which stores `root_frame_id`, `message_uuid`, `message_index`, and `updated_at`. - Changed: Added a local `.feynman/workbench/read-cursors.json` store, `WorkbenchFrameReadCursor` state, authenticated `/api/read-cursor`, per-message transcript ids, unread/current labels, first-unread jump behavior, and a `Mark read` action that persists the current frame cursor. - Verified: Focused read-cursor/files tests passed (`4/4`); `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` passed (`407/407`). Rebuilt in-app browser smoke on `http://127.0.0.1:6174/projects/workspace/frames/open-science-workbench?token=ncHp5CGU6uIcN_Wk1PPkZKzBeX_EQuEW` showed `2 new messages`, clicked `Mark read`, reloaded, verified `Current`, verified the saved cursor at `messageIndex: 1` / `messageCount: 2`, and recorded zero browser errors. - Next: Continue parity on richer PDF text-selection/page-rect anchoring and live science database/tool connector execution. ### 2026-07-02 00:32 PDT — open-science-workbench-media-annotations - Objective: Close the Claude Science figure/PDF annotation gap by making image and PDF artifacts markable with coordinates that Pi can use in follow-up chat. - Researched: Re-opened the public Claude Science page and the installed local app bundle. The reference product promises plain-language figure iteration, artifact history, protein/genomic/chemical/PDF renderers, reviewer checks, persistent kernels, databases, skills, and connectors. The installed bundle uses unified `annotations` records, image point/region overlays, PDF text-selection annotations with page/rect metadata, and HTML element overlays. - Changed: Extended Feynman artifact annotations with `anchorKind`, page/line fields, selection prefix, and percent x/y/width/height geometry. Image and PDF previews now expose an `Annotate` control, click/drag point-or-region capture, saved numbered badges/boxes, annotation target summaries, API persistence, and prompt injection of anchor type/page/coordinates so the Pi-backed chat sees the selected scientific artifact region. - Verified: Focused annotation/files tests passed (`6/6`); `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` passed (`405/405`). Rebuilt in-app browser smoke on a throwaway workbench at `http://127.0.0.1:51355/projects/workspace/frames/figure?token=IfCJ1XQX2eRpINetxYqzr366VMgrmjlC` dragged an image region, created `Image region x=20.1%, y=21.9%, w=45.8%, h=35.2%`, saved a revision note, verified one saved region box on the image preview, verified `.feynman/workbench/annotations.json` stored percent geometry, recorded zero browser errors, and captured `/tmp/feynman-media-annotation-rebuilt-smoke.png`. - Next: Continue parity on persistent read cursors, richer PDF text-selection/page anchoring, and live science database/tool connectors. ### 2026-07-02 00:08 PDT — open-science-workbench-refinement-apply - Objective: Match Claude Science's artifact refinement loop where selected text can produce a model suggestion, preview the replacement as a diff, and apply the edit back into the artifact with version history. - Researched: Re-opened the installed Claude Science runtime and bundle. `AnnotationRefinementPanel` calls `annotations/suggestEdit`, renders `Ask`/`Edit`, `Generating suggestion`, `Diff`/`Full`, an editable suggestion textarea, and `Apply`; `ArtifactTile` then calls `annotations/applyEdit` and swaps to the returned artifact version with carried annotations. - Changed: Replaced the direct-chat refinement edit path with authenticated `/api/artifact/refinement/suggest` and `/api/artifact/refinement/apply` routes. Feynman now validates the selected text and offsets against the current artifact, asks the workbench/Pi prompt executor for a JSON suggestion, renders a Claude-style suggestion card with word diff/full modes and editable replacement text, and applies only the selected span through the existing snapshot/version writer. - Verified: Focused artifact/files tests passed (`7/7`); `npm run typecheck`, `npm run build`, `npm run architecture:check`, and full `npm test` passed (`404/404`). In-app browser verification on the real `6174` workbench opened the artifact preview and confirmed the selected-text panel exposes `Editing selection`, `Save note`, `Ask`, and `Edit`. A second in-app browser smoke used a throwaway server at `http://127.0.0.1:64727/?token=KLI24zZSqpfkJ3UEoY_Dx_kbZmAO39Ay`, generated a fake model suggestion, displayed the diff/apply state, clicked `Apply`, verified `outputs/apply.md` changed to include the sample-size caveat, and verified before/after snapshots under `.feynman/workbench/artifact-snapshots/`. - Next: Continue parity on persistent read cursors, richer PDF/image region annotations, and live science-specific tool/database connectors. ### 2026-07-01 23:43 PDT — open-science-workbench-artifact-edit - Objective: Match Claude Science's editable artifact viewer by turning Feynman's right artifact pane into a real inline text editor with auditable save/version behavior. - Researched: Re-read the installed Claude Science bundle modules for `EditableTextPreview`, `EditableMarkdownPreview`, `ArtifactTile`, and `AnnotationRefinementPanel`. Claude's editor swaps text/markdown previews into a focused textarea with original/edited content state; the refinement panel calls a suggestion path and shows `Apply` after an edit suggestion. Feynman's existing artifact snapshot/version code already had the correct local history spine for this behavior. - Changed: Added authenticated artifact edit read/save APIs, a backend text-artifact edit module limited to tracked `outputs/`, `papers/`, and `notes/` artifacts, before/after snapshot recording on every changed save, and a green Feynman-styled `Edit content` action in the artifact menu. The content tab now opens a textarea editor with `Save changes` and `Cancel`, refreshes the preview after saving, and records the result in the existing Versions tab for diff/restore. - Verified: Focused edit/files UI tests passed (`5/5`); `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` passed (`402/402`). Fresh Playwright smoke on a throwaway workbench opened `outputs/smoke.md`, used `Edit content`, loaded the real file body through `/api/artifact/edit`, saved revised text, verified the file bytes, verified `.feynman/workbench/artifact-snapshots/workbench-edit.jsonl`, opened the Versions tab, recorded zero browser errors, and captured `/tmp/feynman-artifact-edit-smoke.png`. - Next: Continue parity on model-generated suggestion/apply diffs, read cursors, and richer PDF/image region annotations. ### 2026-07-01 23:31 PDT — open-science-workbench-refinement-panel - Objective: Match Claude Science's plain-language artifact/figure iteration flow by turning selected artifact text into an anchored refinement interaction instead of only a manual annotation form. - Researched: Re-opened the public Claude Science page, which names figure iteration in plain language, reproducible artifact history, scientific renderers, reviewer checks, persistent kernels, and compute/database integration as the product bar. Drove the installed Claude Science Example project, opened a generated report artifact, and inspected the local bundle modules imported by text/PDF previews. `AnnotationRefinementPanel-BlsUc42k.js` renders `Editing selection`, a selected-passage preview, a `Describe the edit you'd like...` textarea, `Ask`, `Edit`, generated suggestion, and `Apply`; the PDF preview shows an `Annotate` popover on selected text and passes anchored text/rect metadata. The SQLite migrations show Claude moved from transcript/file annotations into a unified `annotations` table keyed by project, target kind/key, label index, checksum, and JSON body. - Changed: Added a focused workbench refinement client and style module. Selecting text inside an annotatable artifact preview now opens a sticky `Editing selection` panel over the preview, preserves the selected anchor and start/end offsets, accepts an edit instruction, enables `Save note`, `Ask`, and `Edit`, saves revision annotations through the existing authenticated annotation API, and sends Ask/Edit prompts through the existing in-app Pi chat stream so the refinement stays attached to the active research frame. - Verified: Focused annotation/files UI tests passed (`5/5`); `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` passed (`399/399`). Fresh Playwright smoke on a throwaway workbench at `http://127.0.0.1:6215/?token=refine-smoke` selected `responder signal is strong`, opened the refinement panel, saved `Add a sample-size caveat before making the response claim.`, verified the Annotations tab row, verified `.feynman/workbench/annotations.json` stored the anchor plus `startOffset: 30` and `endOffset: 56`, recorded zero browser errors, and captured `/tmp/feynman-refinement-panel-smoke.png`. Refreshed the visible local server on port `6174` and verified `http://127.0.0.1:6174/projects/verification/frames/reference-audit?token=sEs1AdjRRwW1qHX6ckWlJ4QWAZvmrQ1X` opens the `Editing selection` panel from selected text in `outputs/reference-audit/handoff.md`, with zero browser errors and screenshot `/tmp/feynman-live-refinement-panel.png`. - Next: Continue parity on direct editable artifact contents, suggestion/apply diffs, Claude-style read cursors, and richer PDF/image region annotations. ### 2026-07-01 23:17 PDT — open-science-workbench-cloud-export - Objective: Match Claude Science's artifact `Export to Cloud` action with a real credential-backed flow instead of a disabled placeholder. - Researched: Drove the installed local Claude Science Example project and clicked `Export to Cloud`; with no cloud credentials it opened Settings → Storage with `No cloud storage configured` and `Go to Credentials`. Read the installed app bundle modules for `ExportToCloudModal`, `CloudStorageModal`, and `useCloudCredentials`; the reference supports credential selection, bucket selection, destination path, provider credential tests, and a no-secrets credential model. - Changed: Added workbench cloud export target discovery from credential references, exposed targets in `WorkbenchState`, updated the Storage settings card, added authenticated `/api/artifact/export-cloud`, implemented real `file://`/absolute-path exports plus `aws s3 cp` and `gcloud storage cp`/`gsutil cp` execution paths, wrote `.feynman/workbench/cloud-exports.jsonl` audit records, enabled the artifact menu action, and added a green Feynman-styled export modal with the Claude-style empty state and `Go to Credentials` path. - Verified: Focused cloud/artifact/files tests passed (`6/6`); `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` passed (`399/399`). Fresh Playwright smoke on a throwaway workbench at `http://127.0.0.1:6214/?token=cloud-smoke` opened the artifact menu, confirmed `Export to Cloud` was enabled, exported `outputs/alpha.md` to a configured `file://` target, verified the copied file contents, recorded zero browser errors, and captured `/tmp/feynman-cloud-export-smoke.png`. Refreshed the visible local server on port `6174` and verified `http://127.0.0.1:6174/projects/verification/frames/reference-audit?token=6InrvzybxhndI__VaLGgZdu4x-sEBgC-` shows the enabled action and the no-storage modal with zero browser errors, captured at `/tmp/feynman-live-cloud-export-menu.png`. - Next: Continue parity on editable artifact/version flows, Claude-style read cursors, and annotation refinement drawers. ### 2026-07-01 22:53 PDT — open-science-workbench-artifact-actions - Objective: Match Claude Science's artifact preview action menu with real local actions instead of placeholder preview chrome. - Researched: Re-drove the installed local Claude Science Example project and captured the artifact menu at `/tmp/claude-science-probe-artifact-menu.png`. The reference menu exposes `Star`, `Hide`, `View in context`, `Provenance`, `Copy link`, `Rename`, `Export Metadata`, `Export to Cloud`, and `Delete` from the preview's More actions button. - Changed: Added a persisted artifact-action store under `.feynman/workbench/artifact-actions.json`, applied starred/renamed/hidden/deleted state during workspace scans, exposed hidden/deleted action records in state, added authenticated `/api/artifact/action`, and wired the right preview plus Files overlay menus to Star/Unstar, Hide, Rename, soft Delete, Unhide, and Restore. Delete moves the artifact into `.feynman/workbench/artifact-trash/` instead of destroying it, and the Files overlay now has a `Hidden & trash` recovery source. - Verified: Focused artifact/files UI tests passed (`4/4`); `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` passed (`397/397`). Fresh Playwright smoke on a throwaway workspace at `http://127.0.0.1:6212/projects/workspace/frames/alpha?token=KF0HeeBmYSmGDFjkEbtxu7o9wD1kb1Mk` verified the full action menu text, starred `outputs/alpha.md`, renamed it through the browser prompt, hid it, deleted `outputs/beta.md` through the confirm flow, confirmed the file moved to workbench trash, recorded zero browser errors, and captured `/tmp/feynman-artifact-actions-smoke.png`. A second throwaway Playwright smoke at `http://127.0.0.1:6213/projects/workspace/frames/alpha?token=MRRyHatMiGQBaMv5VT_YpkJHsAEkAuLh` opened Files → `Hidden & trash`, unhid `outputs/alpha.md`, restored `outputs/beta.md`, verified both artifacts returned to visible state, recorded zero browser errors, and captured `/tmp/feynman-archive-restore-smoke.png`. - Next: Continue parity on editable artifact/version flows, Claude-style read cursors, annotation refinement drawers, and cloud-export endpoint configuration. ### 2026-07-01 22:34 PDT — open-science-workbench-files-overlay - Objective: Match Claude Science's dedicated file-browser surface so the left rail `Files` control opens a full-height browse/inspect flow instead of only swapping the right-side tab. - Researched: Continued from the installed Claude Science bundle/live-app evidence for `FilesOverlay`, `FileBrowserPane`, persistent right preview actions, and the frame-level Files rail. - Changed: Added a focused Files overlay client and style module plus static shell markup. The overlay reuses the existing artifact/upload/file-card model, supports session/project source switching, search, grid/list layout, import, artifact selection, right-preview synchronization, selected-file details, and actions for open preview, provenance, download, copy link, and metadata JSON. The left-rail Files button and Files-pane Expand button now open the overlay while preserving the existing side preview. - Verified: Focused workbench UI tests passed (`2/2`); `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` passed (`395/395`). Fresh Playwright smoke on `http://127.0.0.1:6211/projects/workspace/frames/reference-audit?token=mJHzzXZpKjB5YkJSaLDF0okdRGYfffQr` opened the Files overlay from the left rail, switched list mode, searched `verification`, selected `outputs/reference-audit/verification-matrix.md`, confirmed the preview title and five overlay actions, closed the overlay, recorded zero browser errors, and captured `/tmp/feynman-files-overlay-smoke.png`. - Next: Continue parity on persistent frame read state, richer file annotations/drawers, and Claude-style message/read cursors. ### 2026-07-01 22:26 PDT — open-science-workbench-transcript-tools - Objective: Match Claude Science's conversation-level execution trace, where tool runs appear as grouped transcript cards with step chips, command/code context, and collapsible output instead of a flat debug dump. - Researched: Reused the installed Claude Science live-app audit and screenshots showing `tool-group-header`, `tool-chip`, BASH/ENV code cards, and `Show output` disclosures embedded in the chat while the right file preview remains visible. - Changed: Added focused transcript tool-event client and style modules that override the existing flat renderer without growing the 1200-line main client. Tool events now render a group header, per-step status chips, normalized tool kind badges, code/environment cards from existing Pi inputs/details, output disclosures, and existing connector approval cards. - Verified: Focused workbench UI tests passed (`2/2`); `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` passed (`395/395`). Fresh Playwright smoke on `http://127.0.0.1:6211/projects/workspace/frames/reference-audit?token=eRkiuEWztANZV4qXzLsghL0sRBJ9dyFU` injected only an in-memory chat session, verified 3 transcript tool events, 3 code cards, 3 output toggles, zero browser errors, and captured `/tmp/feynman-transcript-tool-events-final.png`. - Next: Continue parity on exact Claude-style file overlay/actions and persistent frame messaging/read state. ### 2026-07-01 22:05 PDT — open-science-workbench-artifact-tray-overflow - Objective: Match Claude Science's generated-artifact tray behavior where a long artifact set shows several cards plus a `+N more` card that opens the full file surface. - Changed: Added a focused artifact-tray override module that keeps five visible generated artifact cards, adds a `+N more` overflow card for larger runs, and routes that card to the Files pane. Added a small dashed-card style and static bundle coverage without growing the already-large main client module. - Verified: Focused workbench UI tests passed (`2/2`); `npm run typecheck`, `npm run build`, `npm run architecture:check`, and `git diff --check` passed. Fresh Playwright smoke on `http://127.0.0.1:6211/projects/workspace/frames/reference-audit?token=NG5xpAXqxzwdL07GTGJ4V3qm_mmQp0j0` verified 5 visible tray cards, a `+17 more` overflow card, click-through to the Files tab, 22 rendered file cards, zero browser errors, and screenshot `/tmp/feynman-turn-tray-more-smoke.png`. Full `npm test` passed (`395/395`). - Next: Continue parity on exact Claude-style file overlay/actions. ### 2026-07-01 22:00 PDT — open-science-workbench-inline-artifacts - Objective: Match Claude Science's inline generated-file affordance where artifact filenames in assistant messages are direct file anchors, not only separate tray or Files-pane entries. - Changed: Added a focused message-artifact renderer that detects known artifact paths and filenames from the active run/project, renders them as safe inline file chips in transcript message bodies, and routes clicks through the existing artifact preview path. Added a compact green chip style and static bundle coverage. - Verified: Focused workbench UI tests passed (`8/8`); `npm run typecheck`, `npm run build`, `npm run architecture:check`, and `git diff --check` passed. Fresh Playwright smoke on `http://127.0.0.1:6211/?token=dZ7xAfZh8aPSWNqFX9KM953EVptxlvrw` injected an in-memory transcript message mentioning `outputs/.plans/open-science-workbench.md` and `open-science-workbench.md`, verified two inline artifact refs, clicked one, confirmed the preview title became `Open Science Workbench`, recorded zero browser errors, and captured `/tmp/feynman-message-artifact-ref-smoke.png`. Full `npm test` passed (`395/395`). - Next: Continue parity on exact Claude-style file overlay/actions. ### 2026-07-01 21:54 PDT — open-science-workbench-activity-pane - Objective: Close the Claude Science frame-activity gap by making the active research frame browseable as messages, tools, files, plan steps, and review events instead of scattering that state across separate panes. - Researched: Re-drove the installed local Claude Science project view and extracted its active project snapshot. The reference frame showed grouped tool chips, generated artifact cards, reviewer status, inline file references, and a persistent right preview working together as one session surface. - Changed: Added an `Activity` tab to the right science pane, backed by a focused client module and style module. The pane builds one chronological frame model from chat messages, tool events, Pi/execution records, generated artifacts, uploads, plan steps, and review checks, with filters for All, Messages, Tools, Files, Plan, and Review plus artifact-opening links. - Verified: Focused workbench UI tests passed (`8/8`); `npm run typecheck`, `npm run build`, `npm run architecture:check`, and `git diff --check` passed. Fresh Playwright smoke on `http://127.0.0.1:6211/?token=kw85w811IijZKfmp4-sDZzkT1raNeF5T` opened the workspace frame, switched to Activity, verified 10 events across Messages/Tools/Files/Plan filters, recorded zero browser errors, and captured `/tmp/feynman-activity-smoke.png`. Full `npm test` passed (`395/395`). - Next: Continue parity on richer artifact reference chips and exact Claude-style file overlay/actions. ### 2026-07-01 21:41 PDT — open-science-workbench-file-import - Objective: Turn the Files pane into a real research intake surface so users can import session evidence, inspect it, download it, and remove it without hiding the capability behind the composer plus menu. - Changed: Added a visible `Import` control to the Files toolbar, made uploaded files render as actionable upload cards, added upload preview/download/remove handling in a focused client script, exposed a session-bound authenticated `/api/chat/attachment/download` route, kept upload previews in the right preview pane, and split attachment API coverage into `tests/workbench-attachments.test.ts` to keep `tests/workbench.test.ts` below the architecture hard cap. - Verified: Focused workbench/import tests passed (`31/31`); `npm run typecheck`, `npm run build`, `npm run architecture:check`, and `git diff --check` passed; full `npm test` passed (`395/395`). Fresh Playwright smoke on `http://127.0.0.1:6211/?token=DyD7POAc5Y8BE_iWvZDDqxi1suW_CN33` created a throwaway project, clicked the visible Files `Import` button, uploaded `import-smoke.csv`, verified preview text, downloaded exact uploaded bytes through `/api/chat/attachment/download`, removed the upload card, measured the search box at 72px after the toolbar fit fix, captured `/tmp/feynman-files-import-smoke.png`, and removed the temporary project/session/upload files. - Next: Continue parity on turn-level artifact opening and denser live activity trace. ### 2026-07-01 21:28 PDT — open-science-workbench-project-create - Objective: Close the Claude Science project-creation gap so the dashboard can create a real research project and immediately open a chat frame instead of showing a disabled placeholder. - Researched: Drove the installed local Claude Science app through its dashboard `New project` flow. The reference modal has `Name`, `Description`, and `Agent Context`; the description is shown in the project list and is not included in the agent prompt, while agent context is included in every project agent prompt. - Changed: Added persisted custom workbench projects under `.feynman/workbench/projects.json`, included custom projects in scanned state/project rails, added authenticated `/api/project/new`, created an initial blank chat session for each new project, added a Claude-style dashboard modal in Feynman's green workbench UI, wired the client flow through state/URL/session rendering, and injected only project name plus agent context into Pi prompts. - Verified: Focused workbench tests passed (`10/10`); `npm run typecheck`, `npm run build`, `npm run architecture:check`, and `git diff --check` passed; full `npm test` passed (`395/395`). Fresh Playwright smoke on `http://127.0.0.1:6211/?token=S-tfIKiPXkoABTK5IEQqRM8JnPyvXkoM` clicked `New project`, filled all three reference fields, created a custom project, verified `/api/state` project/session rows and agent context, captured `/tmp/feynman-new-project-smoke.png`, and removed the temporary smoke project/session files. - Next: Continue parity on turn-level artifact opening, import/attachment affordances, and denser live activity trace. ### 2026-07-01 18:30 PDT — open-science-workbench-managed-environments - Objective: Close the Claude Science environment-management gap by turning runtime discovery into real Python/R create/install actions for notebook work. - Researched: Re-read the installed Claude Science local runtime and transcript evidence for `manage_environments(mode="list")`, `manage_environments(mode="create", name="scanpy", packages=[...])`, `manage_packages(mode="install", ...)`, execution `conda_env`, and `environment_snapshot` behavior. - Changed: Added `/api/notebook/environment`, persisted `feynman.notebookEnvironmentAction.v1` records under `.feynman/workbench/environment-actions.jsonl`, created project-local Python venv and R library paths under `.feynman/workbench/environments/`, made Python execution prefer the managed venv when present, made R kernels/processes inherit the managed library through `R_LIBS_USER`, and added a Notebook-pane Managed environment form with Create/Install controls and managed-runtime/action metadata. - Verified: Focused managed-environment tests passed (`3/3`), full `npm test` passed (`381/381`), and `npm run typecheck`, `npm run build`, `npm run architecture:check`, and `git diff --check` passed. Fresh server `http://127.0.0.1:6188/?token=TWJPoamvuIZP7am9-mo5T3-6jtR4Bhd6` created the managed Python venv, ran an isolated Python notebook cell through `/Users/advaitpaliwal/Companion/Code/feynman/.feynman/workbench/environments/python-venv/bin/python`, and recorded that executable/version in the environment snapshot. Playwright smoke verified the Notebook UI Create path, managed Python row, no console errors, and screenshot `/tmp/feynman-managed-env-click-smoke.png`. - Next: Add live compute job lifecycle controls: queued/running state, cancel/terminate/retry, and pending terminate records for long-running local/cloud jobs. ### 2026-07-01 18:16 PDT — open-science-workbench-runtime-inventory - Objective: Make notebook runtime/kernel state visible in the workbench the way Claude Science exposes environment status and frame kernels. - Changed: Added first-class `environments` and `kernels` to workbench state. Environment records now expose Python, managed R/Rscript, and Bash command source, executable, version, modes, session/execution counts, and lockfile snapshot counts. Kernel records expose persisted session kernel ids, active process state, runtime source, executable/version, and latest execution metadata. The Notebook pane now shows live session kernels above the runtime catalog, with compact cards that keep active state visible in the split pane. - Verified: Full `npm test` passed (`378/378`); `npm run typecheck` and `npm run build` passed after the final UI filter/layout fix. Fresh rebuilt server `http://127.0.0.1:6187/?token=science-runtimes-20260701c` ran a real managed R session cell, printed `42`, and reported active kernel `session:runtime-parity-smoke:r` on `/Users/advaitpaliwal/.claude-science/conda/envs/r/bin/R` with `R version 4.5.3 (2026-03-11)`. Playwright/Chrome verified the active R kernel renders above the runtime catalog and saved `/tmp/feynman-notebook-final-runtimes.png`. - Next: Add managed environment create/install actions for Python/R notebook runtimes, matching the `manage_environments` behavior observed in the installed Claude Science transcripts. ### 2026-07-01 17:27 PDT — open-science-workbench-r-session-kernel - Objective: Close the persistent-kernel parity gap where Feynman had session kernels for Python/Bash but R cells still fell back to isolated process mode. - Changed: Added a persistent R notebook kernel using a long-lived `R --vanilla --slave` process, global-environment evaluation, per-cell completion markers, bounded stdout/stderr capture, timeout shutdown, and session kernel ids like `session::r`. Runtime environment probes now tolerate missing runtime stdout, so absent R/Rscript reports as unavailable context instead of crashing environment capture. - Verified: Focused `tests/workbench-r-kernel.test.ts` passes with a fake R process proving variables persist across cells and notebook records keep `session:r-memory:r`. Full `npm test` passed (`377/377`). `npm run typecheck`, `npm run build`, `npm run architecture:check`, and `git diff --check` passed after splitting the R test out of `tests/workbench.test.ts`. Fresh server HTML contains the R language option, Session kernel runtime option, and Modal cloud runtime option. Local machine still has no `R`/`Rscript`, so live R execution is unverified here until R is installed. - Next: Keep provider work focused on real science jobs and NVIDIA only when `NVIDIA_API_KEY` is present. ### 2026-07-01 17:05 PDT — open-science-workbench-modal-notebook - Objective: Close one provider execution-depth gap by making Modal a real Notebook runtime mode instead of only a credential/status card. - Researched: Re-read the repo's `skills/modal-compute/SKILL.md`, which scopes Modal to bounded research experiments when the `modal` CLI is available. Rechecked Modal docs for `modal run`, `App`, `local_entrypoint`, `Image.debian_slim`, and current local-data guidance. Local machine has `~/.modal.toml` and Python/pip; latest PyPI Modal is `1.2.6`. - Changed: Added a Modal notebook execution bridge. Python cells can now use `executionMode: "modal"`, which writes an auditable Modal app script under `.feynman/workbench/modal-jobs/`, runs `modal run `, then asserted the graph explorer script-data payload uses escaped JSON and both graph explorer plus dashboard HTML avoid raw `` or script-breakout markup. - Verified: Focused `tests/paper-rank.test.ts` passed 44/44, full `npm test` passed 287/287, `npm run typecheck`, `git diff --check`, and `git diff --cached --check` passed. - Next: Continue review from remaining live/provider/runtime surfaces; commit/push only after confirming this staged package is the intended release unit. ### 2026-06-21 17:40 PDT — codebase-review-model-fixtures - Objective: Continue the whole-codebase AI-researcher review by checking whether model-selection tests or fixtures still imply stale or Pro-class models as current choices. - Changed: Replaced hardcoded `gpt-5.4` model-set/setup fixtures with the current recommended authenticated OpenAI model from the installed Pi catalog, removed Pro-specific test fixtures and rejection tests instead of synthesizing fake Pro models, and kept the runtime arg builder test on a fake model id because it only verifies argument forwarding. - Verified: Focused model/runtime/PaperRank/content tests passed 123/123 after the Pro-specific test removals. Full `npm test` passed 286/286, `npm run typecheck`, `npm run build`, `npm audit --omit=dev`, website lint/typecheck/build/audit, `npm pack --dry-run`, `git diff --check`, and `git diff --cached --check` passed. Follow-up scans found no explicit Pro-model test fixtures; the only test-tree `pro` hit is `method_repro_heavy`. - Next: Continue codebase review from remaining runtime/package/provider boundaries; commit/push only after confirming this staged package is the intended release unit. ### 2026-06-21 17:31 PDT — codebase-review-runtime-cache-inputs - Objective: Continue the whole-codebase AI-researcher review by checking whether the packaged Pi runtime archive cache is invalidated by the real patch files that shape Feynman's research runtime. - Changed: Removed the deleted `pi-package-manager-patch.mjs` input from the runtime workspace hash and moved package/runtime seeding guards into `tests/package-seeding.test.ts`, so `npm test` executes them in the normal suite instead of leaving them hidden in `tests/package-ops.test.ts`. - Verified: Source review found the stale hash input after the package-manager patch had been deleted. `node scripts/prepare-runtime-workspace.mjs` refreshed the vendored runtime workspace, focused package/runtime tests passed 21/21, full `npm test` passed 291/291, and `npm run typecheck`, `npm run build`, `npm audit --omit=dev`, and `npm pack --dry-run` passed. - Next: Continue staged review from remaining provider/runtime boundaries and command artifact paths; commit/push only after confirming this staged package is the intended release unit. ### 2026-06-21 17:24 PDT — codebase-review-cwd-fixture-inputs - Objective: Continue the whole-codebase AI-researcher review by checking whether `--cwd` truly applies to PaperRank and paper-access input fixtures, not only generated outputs. - Changed: Added workspace-relative fixture path resolution for `feynman rank` source, calibration, and reproduction fixtures, plus `feynman paper --source-fixture`, so relative fixture paths are resolved under the requested workspace. - Verified: A direct repro showed `feynman --cwd rank ... --source-fixture openalex-rank.json` tried to read the caller directory before the fix. Focused `tests/paper-rank.test.ts` passed 44/44 after adding CLI coverage for workspace-relative rank and paper fixtures under `--cwd`. - Next: Run broad verification, stage this fix, then continue review from model/runtime and artifact-boundary risks; commit/push only after confirming this staged package is the intended release unit. ### 2026-06-21 17:19 PDT — codebase-review-otel-env-boundary - Objective: Continue the whole-codebase AI-researcher review by checking the Pi telemetry handoff for prompt/path/privacy leaks through inherited OpenTelemetry environment variables. - Changed: Feynman's PostHog OTLP env builder now explicitly masks inherited generic `OTEL_EXPORTER_OTLP_ENDPOINT`, `OTEL_EXPORTER_OTLP_HEADERS`, and `OTEL_EXPORTER_OTLP_PROTOCOL` when configuring Pi telemetry, so only the PostHog trace/log-specific variables are passed to the child runtime. - Verified: Focused telemetry/runtime tests passed 25/25 and runtime patch tests passed 4/4, including a regression where inherited generic OTLP headers contain a private bearer token. Full `npm test` passed 281/281, and `npm run typecheck`, `npm run build`, `npm audit --omit=dev`, and `npm pack --dry-run` passed. - Next: Continue staged review from PaperRank artifact boundaries, Pi runtime handoff, and provider command routing; commit/push only after confirming this staged package is the intended release unit. ### 2026-06-21 17:17 PDT — codebase-review-stale-model-default - Objective: Continue the whole-codebase AI-researcher review by checking whether the current non-Pro model policy actually prevents stale default model launches. - Changed: `normalizeFeynmanSettings` now replaces an unavailable stale default model with the current authenticated non-Pro recommendation when one exists, instead of only repairing missing or Pro-class defaults. - Verified: A direct repro showed `anthropic/claude-opus-1` was preserved despite an authenticated OpenAI non-Pro replacement being available. Focused `tests/pi-settings.test.ts` passed 14/14, focused model/catalog harnesses passed 46/46, full `npm test` passed 281/281, and `npm run typecheck`, `npm run build`, `npm audit --omit=dev`, and `npm pack --dry-run` passed. A built CLI smoke with a temp `FEYNMAN_HOME` rewrote stale `anthropic/claude-opus-1` to the current OpenAI non-Pro recommendation and `feynman model list` marked it current/recommended. - Next: Continue the staged review from PaperRank artifact boundaries, Pi runtime handoff, and provider command routing; commit/push only after confirming this staged package is the intended release unit. ### 2026-06-21 17:11 PDT — codebase-review-alpha-cwd-passthrough - Objective: Continue the whole-codebase AI-researcher review by checking alphaXiv command routing under existing Feynman global flags. - Changed: Fixed `feynman --cwd alpha ...` and `feynman --cwd= alpha ...` so leading `--cwd` is resolved before dispatch and alphaXiv receives its own flags unchanged. The parsed `alpha` path now also launches the bundled alpha CLI from Feynman's resolved working directory. - Verified: Before the fix, built CLI smokes for `--cwd alpha --help` and `--cwd= alpha --help` printed Feynman's top-level help instead of Alpha Hub help. After the fix, focused `tests/model-harness.test.ts` passed 34/34, full `npm test` passed 280/280, and `npm run typecheck`, `npm run build`, `npm audit --omit=dev`, website typecheck/lint/build/audit, and `npm pack --dry-run` passed. Built CLI smokes for both `--cwd` forms now print `Alpha Hub - search papers and annotate what you learn`. - Next: Continue the staged codebase review from paper-access, ranking, observability, and Pi runtime boundaries; commit/push only after confirming this staged review package is the intended release unit. ### 2026-06-21 17:05 PDT — codebase-review-doi-identity-boundary - Objective: Continue the whole-codebase AI-researcher review by checking paper-access DOI/title identity resolution across the CLI, PaperRank resolver, telemetry-safe artifacts, Pi runtime wrapper, package contents, and docs/scope surfaces. - Changed: Added strict user-input DOI classification so only explicit DOI inputs (`doi:...`, DOI URLs, or bare DOI strings) use the OpenAlex DOI lookup path. Title queries containing DOI-like substrings now remain OpenAlex title searches. Provider DOI normalization for OpenAlex/Europe PMC metadata and canonical DOI URLs remains unchanged. - Verified: Focused `tests/paper-rank.test.ts` passed 44/44, full `npm test` passed 278/278, and `npm run typecheck`, `npm run build`, `npm audit --omit=dev`, website typecheck/lint/build/audit, `npm pack --dry-run`, `git diff --check`, and `git diff --cached --check` passed. Built CLI smokes passed for `--version`, fixture-backed `rank`, fixture-backed `paper --fetch-full-text`, Pro synthesis override rejection, and `alpha --help`. Live resolver smokes confirmed explicit DOI input uses OpenAlex `filter=doi:https://doi.org/10.7717/peerj.4375`, a DOI-like title uses `search=Retrieval benchmark 10.1234/failure modes`, and explicit `doi: 10.1234/example` uses the DOI filter path. - Next: Commit/push only after confirming this staged review package is the intended release unit; remaining broad-scope risk is live-use evaluation beyond deterministic local and provider smokes. ### 2026-06-21 16:57 PDT — codebase-review-arxiv-identity-boundary - Objective: Continue the whole-codebase AI-researcher review by checking paper-access identity resolution so title queries, OpenAlex IDs, and arXiv IDs do not cross wires. - Changed: Tightened arXiv ID extraction to accept bare IDs, explicit `arxiv:`/`arxiv ` prefixes, and arXiv URL paths only, instead of treating any arXiv-shaped number embedded in a title as an arXiv identifier. Added a resolver regression where `Retrieval benchmark 2024.12345 failure modes` remains an OpenAlex title search with `per-page=1` and does not hit arXiv fallback. - Verified: Focused `tests/paper-rank.test.ts` passed 42/42. Full `npm test` passed 276/276, and `npm run typecheck`, `npm run build`, `npm audit --omit=dev`, website typecheck/lint/build/audit, `npm pack --dry-run`, `git diff --check`, and `git diff --cached --check` passed. Live OpenAlex smokes confirmed `W2741809807` resolves through the OpenAlex-ID path and the title-like numeric query builds a normal OpenAlex search with `per-page=1`. - Next: Commit/push only after confirming this staged review package is the intended release unit; remaining broad-scope risk is live-use evaluation beyond deterministic local gates. ### 2026-06-21 16:52 PDT — codebase-review-synthesis-prompt-boundaries - Objective: Continue the whole-codebase AI-researcher review by checking the PaperRank model-synthesis handoff and remaining generated Markdown reports for untrusted topic/title/paper-text boundary defects. - Changed: Hardened the model-synthesis prompt so provider-controlled packet JSON is wrapped in a fence longer than any backtick run in the packet, and added an explicit rule that Evidence Packet values are untrusted data rather than instructions. Escaped the remaining raw topic headings in calibration and critique reports. Replaced double-quoted topic rerun snippets with single-quoted shell arguments in calibration and reproduction templates so newline, quote, and command-substitution characters cannot reshape copy-paste commands. - Verified: Focused `tests/paper-rank.test.ts` passed 41/41. Full `npm test` passed 275/275, and `npm run typecheck`, `npm run build`, `npm audit --omit=dev`, website typecheck/lint/build/audit, `npm pack --dry-run`, `git diff --check`, and `git diff --cached --check` passed. Raw-topic and legacy double-quoted command scans no longer find unsafe generated Markdown headings or `feynman rank ""` snippets. - Next: Commit/push only after confirming this staged review package is the intended release unit; remaining broad-scope risk is live-use evaluation beyond deterministic local gates. ### 2026-06-21 16:46 PDT — codebase-review-markdown-artifact-boundaries - Objective: Continue the whole-codebase AI-researcher review by checking PaperRank and paper-access generated artifacts for provider-controlled Markdown/report-boundary defects. - Changed: Normalized accepted provider URLs to parsed `URL.href`, rendered generated Markdown links with angle-bracket link targets, escaped/collapsed provider and user-supplied text in headings, tables, provenance, paper URLs, model-synthesis metadata, and research-agenda provenance, and added a regression proving malicious-looking OpenAlex titles/landing URLs cannot inject extra Markdown headings or bare links. - Verified: Focused `tests/paper-rank.test.ts` passed 40/40. Full `npm test` passed 274/274, and `npm run typecheck`, `npm run build`, `npm audit --omit=dev`, website typecheck/lint/build/audit, `npm pack --dry-run`, `git diff --check`, and `git diff --cached --check` passed. - Next: Commit/push only after confirming this staged review package is the intended release unit; remaining broad-scope risk is live-use evaluation beyond deterministic local gates. ### 2026-06-21 16:35 PDT — codebase-review-optional-recall-and-visuals - Objective: Continue the whole-codebase AI-researcher review by checking remaining docs and subagent prompts for false built-in capability claims and unnecessary workflow promises. - Changed: Tightened session-search docs and skill wording so recall is documented as an optional live package with a direct JSONL file-search fallback, not a guaranteed automatic memory layer. Replaced inflated "workflow orchestrator"/automatic-dispatch copy with Pi `subagent` tool wording and lead-owned narrow-task boundaries. Removed the summarize and quickstart human-time promises. Fixed the writer subagent's stale `pi-charts`/`pi-generative-ui` instructions so charts or interactive views are used only when visible tools exist and evidence supports them. - Verified: Focused `tests/content-policy.test.ts` passed 24/24 and focused `tests/pi-settings.test.ts` passed 13/13. Full `npm test` passed 273/273, and `npm run typecheck`, `npm run build`, `npm audit --omit=dev`, website typecheck/lint/build/audit, `npm pack --dry-run`, `git diff --check`, and `git diff --cached --check` passed. Stale-promise grep only finds guarded tests, optional package source, or historical release-note references for the removed package/model phrases. - Next: Commit/push only after confirming this staged review package is the intended release unit; remaining broad-scope risk is live-use evaluation beyond deterministic local gates. ### 2026-06-21 16:28 PDT — codebase-review-replication-and-url-boundaries - Objective: Continue the whole-codebase AI-researcher review from the staged PaperRank/CLI surface, focusing on false execution promises and unsafe artifact boundaries. - Changed: Tightened `/replicate` README, prompt, skill, and docs so replication is plan-first and execution-gated on an explicit environment choice; removed stale claims that Feynman simply replicates experiments or monitors training runs. Hardened PaperRank OpenAlex URL normalization so generated reports and HTML inspection views only receive `http`/`https` provider links, while DOI entries are stored as canonical `https://doi.org/...` URLs. - Verified: Focused `tests/content-policy.test.ts` passed 21/21 and focused `tests/paper-rank.test.ts` passed 39/39. Full `npm test` passed 270/270, and `npm run typecheck`, `npm run build`, `npm audit --omit=dev`, website typecheck/lint/build/audit, `npm pack --dry-run`, `git diff --check`, and `git diff --cached --check` passed. Live alphaXiv checks passed: `node bin/feynman.js alpha --help`, `node bin/feynman.js doctor` with alphaXiv auth OK, `node bin/feynman.js alpha --json search --mode keyword "sparse autoencoders"` returning structured paper results, and `node bin/feynman.js alpha get 2309.08600` returning the paper analysis. One alpha detail remains observed but non-blocking: `alpha --json status` still prints human-readable status from the upstream alpha CLI. - Next: Commit/push only after confirming this staged review package is the intended release unit; remaining broad-scope risk is live-use evaluation beyond deterministic local gates. ### 2026-06-21 16:20 PDT — scope-gate-visualization-package-promises - Objective: Continue the whole-codebase review by checking prompt/system claims against the current lean default runtime package set. - Changed: Gated chart and visualization instructions on visible chart/rendering tools instead of promising the unshipped `pi-charts` package. `/lit`, `/compare`, and `/draft` now write chart specifications or source-backed tables when no chart tool is visible, while preserving the source-backed quantitative-data requirement for charts and figures. - Verified: Focused `tests/content-policy.test.ts` passed 20/20. Grep shows no shipped system or prompt references to `pi-charts`, `@walterra/pi-charts`, or generic visualization packages; the only remaining hits are the legacy package-pruning source/test and the content-policy guard. Full `npm test` passed 268/268, and `npm run typecheck`, `npm run build`, `npm audit --omit=dev`, website typecheck/lint/build/audit, `npm pack --dry-run`, `git diff --check`, and `git diff --cached --check` passed. - Next: Commit/push only after confirming this staged review package is the intended release unit; remaining broad-scope risk is live-use evaluation beyond deterministic local gates. ### 2026-06-21 16:15 PDT — scope-gate-live-package-promises - Objective: Continue the whole-codebase review by checking user-facing workflows for claims about package capabilities that are not in the current default Feynman package set. - Changed: Gated scheduling, process-management, and preview instructions on visible tools instead of promising unshipped `pi-schedule-prompt`, `pi-processes`, or `pi-markdown-preview` behavior. `/watch` now writes a baseline and marks scheduling blocked when `schedule_prompt` is unavailable; `/jobs` reports visible process/scheduler state plus durable artifacts; Preview docs/skill treat `/preview` as an optional live-package command with shell fallbacks. - Verified: Focused `tests/content-policy.test.ts` passed 19/19. Full `npm test` passed 267/267. `npm run typecheck`, `npm run build`, website typecheck/lint/build, and stale-promise grep checks passed. Grep shows stale package/background/autoresearch/preview promises are gone from shipped prompts, skills, command docs, README, metadata, and current website docs except for guarded test assertions, one historical release note, and conditional preview command rows. - Next: Commit/push only after confirming this staged review package is the intended release unit; remaining broad-scope risk is live-use evaluation beyond deterministic local gates. ### 2026-06-21 16:08 PDT — codebase-review-parser-and-autoresearch-scope - Objective: Continue the whole-codebase review by checking remaining AI-researcher surfaces for scope drift, false runtime promises, stale model policy, and option-parsing defects. - Changed: Made PaperRank numeric options and rank synthesis timeout parsing reject partial numeric strings such as `3papers`, `1.5`, and `120000ms` instead of silently accepting the numeric prefix. Tightened `/autoresearch` from an unshipped package/background-job promise into a bounded foreground experiment loop that logs benchmark result, evidence, and decision, and aligned README/website copy with that shipped behavior. - Verified: Focused `tests/paper-rank.test.ts` passed 38/38, focused `tests/model-harness.test.ts` passed 32/32, and focused `tests/content-policy.test.ts` passed 17/17. Full `npm test` passed 265/265. `npm run typecheck`, `npm run build`, `npm audit --omit=dev`, website typecheck/lint/build/audit, `git diff --check`, `git diff --cached --check`, and `npm pack --dry-run` passed. Grep checks found no shipped stale OpenAI/Pro model defaults, no grant/proposal/admin feature lane, and no autoresearch background/package promise outside legacy package-pruning source. - Next: Commit/push only after confirming this staged review package is the intended release unit; remaining broad-scope risk is live-use evaluation beyond deterministic local gates. ### 2026-06-21 15:54 PDT — codebase-review-model-and-rank-tightening - Objective: Continue the full codebase review after the staged AI-researcher core set, specifically checking for feature bloat, stale model policy, and PaperRank reliability gaps. - Changed: Reframed top-level PaperRank copy around the user outcome of read-first triage instead of artifact inventory. Removed stale user-facing OpenAI model examples from docs and LiteLLM setup fallback. Replaced exact Claude/GPT catalog preference pins with family-ranked selection that uses Pi's current authenticated model list, rejects Pro-class models, and treats Claude date suffixes as build metadata instead of newer semantic versions. Added abortable timeouts for OpenAlex, Europe PMC, and arXiv network fetches in PaperRank/paper-access. - Verified: Focused model/catalog/settings/content tests passed 72/72 after catching and fixing the Claude date-suffix ranking regression. Focused PaperRank tests passed 38/38 with coverage that provider calls receive abort signals. Focused content policy tests passed 16/16 and now guard against artifact-led PaperRank copy plus stale OpenAI setup pins. Full `npm test` passed 263/263 after fixing a brittle Pi subagent schema patch that had matched an exact upstream model example. `npm run typecheck`, `npm run build`, `npm audit --omit=dev`, website typecheck/lint/build/audit, `git diff --check`, `git diff --cached --check`, and `npm pack --dry-run` passed. - Next: Commit/push only after confirming this staged review package is the intended release unit; remaining broad-scope risk is that the AI-researcher goal itself still needs ongoing live-use evaluation beyond deterministic local gates. ### 2026-06-21 15:12 PDT — full-codebase-review-final-fixes - Objective: Finish the full Feynman AI-researcher codebase review with no Pro-model escape hatch, no feature-inventory bloat, and clean end-to-end validation. - Changed: Fixed `feynman rank` so `--synthesis-model ...-pro` and `--model ...-pro` are rejected at the CLI boundary before PaperRank writes artifacts. Added a regression test for both rank Pro override paths. Removed duplicate artifact lines from PaperRank provenance. Tightened README/release/CLI reference copy so PaperRank is framed as read-order triage with evidence, not a feature pile. Tightened the alphaXiv docs so they promise source-specific paper text when available, not arbitrary complete-PDF parsing. Hardened command telemetry so unknown prompt text, malformed mode values, and malformed numeric flag values cannot become telemetry labels or properties. Fixed `rank` and `paper` so default/relative artifact output directories resolve under `--cwd`, matching the documented working-directory contract. Updated website overrides from `hono@4.12.23` to `4.12.26` and `vite@7.3.3` to `7.3.5` after the website production audit found current advisories. - Verified: Focused `tests/paper-rank.test.ts` passed 37/37 and focused `tests/telemetry.test.ts` passed 10/10. Full `npm test` passed 260/260. `npm run typecheck`, `npm run build`, `npm audit --omit=dev`, website lint/typecheck/build, website production audit, `git diff --check`, `git diff --cached --check`, and `npm pack --dry-run` passed. Built CLI smokes passed for `model list`, PaperRank fixture output, paper-access fixture output, raw-full-text omission, duplicate-provenance absence, Pro synthesis override rejection, and `rank`/`paper` default output placement under `--cwd`. Source inspection of the vendored `pi-otel` package confirmed trace-specific OTLP env handling and no `pi.cwd`/`ATTR_PI_CWD` in the patched package. - Next: Commit/push only after confirming this staged review slice is the intended release unit; remaining non-blocking product risk is that `src/rank/paper-rank.ts` is large and should be split later when doing so reduces complexity without adding surface. ### 2026-06-21 14:58 PDT — staged-ai-researcher-core-set - Objective: Remove the landing risk where the verified Feynman AI-researcher core existed partly as untracked files and could be omitted from a commit or PR. - Changed: Staged the full verified AI-researcher change set, including PaperRank, paper access, PostHog/Pi telemetry, Pi OTEL patching, model non-Pro policy, alpha tool routing, fixtures, tests, docs, and release notes. No commit or push was made. - Verified: `git diff --cached --name-status` now includes the previously untracked core files (`src/rank/paper-rank.ts`, `src/telemetry/posthog.ts`, PaperRank fixtures/tests, telemetry tests, Pi OTEL patch files, and paper workflow docs). `git ls-files --others --exclude-standard` is empty. `git diff --cached --check`, `git diff --check`, `npm run typecheck`, `npm run build`, `npm audit --omit=dev`, and full `npm test` passed 254/254 on the staged state. - Next: Review the staged diff as the commit/PR unit, then commit/push only after confirming the staged package scope is the intended release slice. ### 2026-06-21 14:51 PDT — arxiv-access-metadata-fallback - Objective: Continue the full Feynman AI-researcher codebase review by making single-paper arXiv access resolve useful metadata when OpenAlex does not return a validated arXiv match. - Changed: Widened OpenAlex candidate retrieval for arXiv identifiers from one search hit to ten while keeping strict arXiv identity matching. Added arXiv Atom API fallback metadata enrichment for arXiv IDs so paper-access artifacts can record real title, authors, abstract, year/date, categories, links, and provenance instead of a bare `arXiv ` placeholder. Added pinned direct `fast-xml-parser@5.7.3` for structured Atom parsing and deduped it with the existing Pi/AWS runtime dependency instead of shipping a second parser version. Fixed access-candidate provenance so arXiv URLs are labeled as arXiv rather than OpenAlex. - Verified: Focused `tests/paper-rank.test.ts` passed 34/34, including regressions for multi-candidate arXiv lookup, arXiv API fallback metadata, and arXiv-labeled access candidates. Root `npm run typecheck`, `npm run build`, full `npm test` passed 254/254, `git diff --check` passed, `npm audit --omit=dev` reported `found 0 vulnerabilities`, and `npm pack --dry-run` passed. `npm ls fast-xml-parser fast-xml-builder --all` shows root `fast-xml-parser@5.7.3` plus Pi/AWS `5.7.3` copies with the AWS path deduped to root. Live compiled `node bin/feynman.js paper 2309.08600 --json` now returns title `Sparse Autoencoders Find Highly Interpretable Features in Language Models`, source `arxiv`, source URL `https://export.arxiv.org/api/query?id_list=2309.08600`, arXiv API provenance, and only `alphaXiv`/`arXiv` access candidates for arXiv URLs. - Next: Continue the codebase review from remaining untracked change risk and evidence/provenance correctness before staging the AI-researcher core set. ### 2026-06-21 14:39 PDT — openalex-secondary-arxiv-identity - Objective: Continue the full Feynman AI-researcher codebase review by fixing a PaperRank identity gap where OpenAlex arXiv metadata present only in secondary access locations could be used for full-text candidates but missed for paper identity. - Changed: Changed OpenAlex work normalization to extract arXiv ids from `ids`, primary location, all reported locations, best open-access location, and `open_access.oa_url`. Updated OpenAlex provenance field accounting to include the location/access fields that now drive identity and access decisions. - Verified: Focused `tests/paper-rank.test.ts` passed 32/32, including new regressions for secondary-location arXiv id extraction and `resolvePaperAccess` preserving the matched OpenAlex paper instead of falling back to an arXiv-only stub. Root `npm run typecheck`, `npm run build`, full `npm test` passed 252/252, `git diff --check` passed, `npm pack --dry-run` passed, and compiled `node bin/feynman.js rank "mechanistic interpretability sparse autoencoders" --limit 3 --source-fixture tests/fixtures/openalex-rank.json --output-dir /tmp/feynman-cli-smoke.Mlc77C --json` passed. - Next: Continue the codebase review from remaining untracked change risk and any evidence-quality defects, then stage/commit only the simple AI-researcher core set once the final review is done. ### 2026-06-21 14:33 PDT — telemetry-artifact-error-redaction - Objective: Continue the full Feynman AI-researcher codebase review by fixing places where observability or PaperRank artifacts could leak private prompt, path, provider, or resolver exception text. - Changed: Changed Feynman telemetry spans to record sanitized OTEL exceptions with only a safe error kind and `error_message_hash`, while event/log properties continue to use hash-only error metadata. Changed CLI telemetry metadata so prompt text after `--` cannot become the telemetry command label. Changed PaperRank model-synthesis and full-text failure paths so durable report/provenance/JSON artifacts store subsystem plus hash instead of raw provider/resolver messages. - Verified: Focused `tests/telemetry.test.ts` passed 8/8. Focused `tests/paper-rank.test.ts` passed 30/30, including regression coverage for sanitized full-text fetcher failures and sanitized model-synthesis failure artifacts. Root `npm run typecheck`, `npm run build`, full `npm test` passed 250/250, `git diff --check` passed, and `npm pack --dry-run` passed. An isolated compiled CLI smoke with `node bin/feynman.js rank "mechanistic interpretability sparse autoencoders" --limit 3 --source-fixture tests/fixtures/openalex-rank.json --json` passed after `npm pack --dry-run`. - Failed / learned: The first compiled CLI smoke was run concurrently with `npm pack --dry-run`, whose prepack step removes and rebuilds `dist/`; rerunning the smoke after pack completed passed. - Next: Continue the AI-researcher review from ranking/evidence correctness and decide whether to stage the untracked core change set before any PR. ### 2026-06-21 14:18 PDT — codebase-review-core-corrections - Objective: Review the current Feynman codebase for AI-researcher correctness, scope drift, runtime packaging, and end-to-end verification risks. - Changed: Fixed PaperRank paper-access candidate normalization so each OpenAlex landing/PDF candidate carries its own `isOpenAccess` flag instead of inheriting the paper-level open-access summary from unrelated locations. Added launch-time `pi-otel` patch coverage to `patchPiRuntimeNodeModules` so user-global, agent-local, and vendored runtime installs all honor trace-specific PostHog OTLP env vars. Reworded the slash-command docs from "project management tools" to "research-session utilities" to match the simple AI-researcher feature gate. - Verified: Focused PaperRank test passed 28/28 and now proves a closed publisher landing candidate remains closed while the repository PDF/landing candidates are open. Focused runtime/otel/telemetry tests passed 12/12 and now cover vendored, user-global, and Pi-agent `pi-otel` installs. Root `npm run typecheck`, `npm run build`, and full `npm test` passed 245/245. Compiled `feynman paper` fixture smoke wrote bounded access artifacts without a raw `fullText` body. - Review note: Several core additions remain untracked in Git, including PaperRank, telemetry, new tests, and workflow docs. They work in this dirty tree, but they will not land in a commit or PR until staged. - Next: Run final website/package gates, then decide whether to stage/commit the current AI-researcher change set. ### 2026-06-21 14:10 PDT — openalex-location-access-coverage - Objective: Improve Feynman paper access coverage by using OpenAlex's full location metadata without adding a new workflow surface. - Changed: Added OpenAlex `locations` to the selected work fields, normalized every reported location landing/PDF URL into the existing access-candidate plan, and treated any open-access location as open-access evidence. Updated the paper-access docs to state that Feynman uses primary, best open-access, and all reported OpenAlex locations. - Verified: Read OpenAlex work docs showing `locations` as all unique places where a work lives and location objects carrying `landing_page_url`/`pdf_url`. Focused `tests/paper-rank.test.ts` passed 28/28. Root `npm run typecheck`, `npm run build`, and full `npm test` passed 245/245. Live compiled `feynman paper 10.7717/peerj.4375 --json` wrote an artifact whose OpenAlex source URL selects `locations`, returned 12 access candidates including 9 OpenAlex location landing candidates such as `https://digitalcommons.unl.edu/scholcom/142`, and did not write a raw `fullText` body. `git diff --check`, website typecheck/lint/build, `npm audit --omit=dev`, and `npm pack --dry-run` passed. - Next: Continue auditing evidence-quality gaps in paper/ranking/reproduction behavior before adding any new surface. ### 2026-06-21 14:04 PDT — pi-otel-posthog-traces-endpoint - Objective: Keep Feynman observability simple and correct by using Pi's `pi-otel` extension for Pi runtime traces while matching PostHog's current AI OTLP setup guidance. - Changed: Updated the carried `pi-otel` runtime patch so `pi-otel` resolves `OTEL_EXPORTER_OTLP_TRACES_ENDPOINT`, `OTEL_EXPORTER_OTLP_TRACES_PROTOCOL`, and `OTEL_EXPORTER_OTLP_TRACES_HEADERS` before generic OTLP variables. Changed Feynman's Pi child env to stop setting the generic `OTEL_EXPORTER_OTLP_ENDPOINT` to the PostHog AI endpoint and instead set the trace-specific PostHog AI endpoint. Kept `PI_OTEL_CAPTURE_CONTENT=metadata_only`, logs/metrics disabled for `pi-otel`, and the existing Feynman CLI PostHog events/logs/traces path. Clarified docs that Pi runtime observability is provided by bundled `pi-otel`. - Verified: Read installed Pi extension docs and bundled `pi-otel` source before editing. Focused telemetry/runtime suite passed 33/33. Full `npm test` passed 244/244. `npm run typecheck`, `npm run build`, `npm audit --omit=dev`, `npm pack --dry-run`, `git diff --check`, website lint, website typecheck, and website build all passed. Rebuilt the vendored runtime workspace; the bundled and archived `pi-otel/dist/config.js` now reads trace-specific OTLP env vars first, and archive inspection found no `ATTR_PI_CWD`, `pi.cwd`, `cfg.cwd`, or `this.opts.cwd` in the patched `pi-otel` runtime files. - Next: Continue checking Feynman's AI-researcher core by auditing evidence quality and runtime behavior, not by adding adjacent workflow surface. ### 2026-06-21 13:53 PDT — paper-access-correctness-fix - Objective: Fix the code-review blockers that prevented Feynman paper access and PaperRank from behaving like a reliable AI-researcher core. - Changed: Made `feynman paper ` treat the arXiv ID as an identity constraint, accepting OpenAlex only when the returned work carries the same arXiv ID and otherwise falling back to an arXiv-only access record instead of a wrong search hit. Changed the default PaperRank full-text fetcher to call Europe PMC for DOI/PMID-only papers, allowing its existing DOI/PMID-to-PMCID lookup to fetch `fullTextXML`. Aligned `src/pi/package-ops.ts` fallback Pi runtime seeding to `0.79.8` and added tests that pin runtime fallback constants plus installed peer specs to the bundled Pi version. - Verified: Focused `tests/paper-rank.test.ts` passed 27/27 and includes regressions for DOI-only Europe PMC full-text enrichment plus unrelated OpenAlex hits for arXiv IDs. Focused `tests/package-ops.test.ts` passed 7/7, and the direct `Pi runtime fallback` name-pattern test passed 1/1. Root `npm run typecheck`, `npm run build`, and full `npm test` passed 243/243. Live compiled CLI smoke for `node bin/feynman.js paper 2309.08600 --json` returned source `arxiv`, title `arXiv 2309.08600`, and arXiv ID `2309.08600` instead of the previous unrelated medical OpenAlex hit. Live compiled CLI smoke for DOI `10.7717/peerj.4375 --fetch-full-text` returned PMID `29456894`, PMCID `PMC5815332`, full text source `Europe PMC fullTextXML`, and length `70012`. `npm audit --omit=dev`, `npm pack --dry-run`, `git diff --check`, website lint, website typecheck, and website build all passed. - Next: Keep rejecting adjacent features; the next useful AI-researcher work should be another correctness or evidence-quality gap in the paper/ranking/reproduction loop, not new workflow surface. ### 2026-06-21 01:32 PDT — paper-access-ai-researcher-workflow - Objective: Close the useful AI-researcher gaps from the external Feynman feedback without adding decorative or adjacent-product features: single-paper full-text access, source-backed PaperRank enrichment, and speed observability. - Changed: Added `feynman paper ` with durable `-paper-access.md` and `-paper-access.json` artifacts, legal access candidates from OpenAlex/DOI/arXiv/alphaXiv/Europe PMC, optional source-specific `--fetch-full-text`, and raw-full-text omission. Changed PaperRank full-text enrichment to use the shared source-specific resolver instead of alphaXiv-only fetching, including Europe PMC `fullTextXML` for open-access PMC deposits while keeping PDFs as access links rather than arbitrary PDF parsing. Added PaperRank JSON `durationMs` so speed is visible in the product output as well as telemetry. Removed the proposed grants workflow, prompt, command surface, docs, and tests because grant applying is outside Feynman's AI-researcher scope. Added a repo-level `AGENTS.md` feature-scope gate requiring every new command, prompt, tool, extension, dashboard, document page, or release-note item to serve a concrete AI-researcher job. - Verified: After the grants removal, focused `node --import tsx --test --test-concurrency=1 tests/content-policy.test.ts tests/model-harness.test.ts` passed 43/43, then the feature-bar guard was added and full `npm test` passed 241/241. `npm run typecheck`, `npm run build`, website lint/typecheck/build, production audit with `found 0 vulnerabilities`, `npm pack --dry-run`, and `git diff --check` passed. Help and source smokes found no `feynman grants`, `/grants`, `prompts/grants`, grant-map, or writer-ready proposal workflow surface. Previous compiled CLI smokes showed `node bin/feynman.js model list` as `openai/gpt-5.5 (current, recommended)` and explicit `openai/gpt-5.5-pro` exits with `Pro-class model disabled`. Previous live `node bin/feynman.js paper 10.7717/peerj.4375 --fetch-full-text` resolved OpenAlex work `W2741809807`, DOI `10.7717/peerj.4375`, PMID `29456894`, PMCID `PMC5815332`, selected Europe PMC `fullTextXML`, fetched 70012 chars / 3 sections, and wrote bounded access artifacts without a raw `fullText` body. - Next: Keep this change set as the current GitHub-ready local candidate; split or stage it only after deciding how to package it against the existing dirty main worktree. ### 2026-06-19 23:24 PDT — daytona-full-gate-and-live-nonpro-smokes - Objective: Finish the Daytona cross-environment verification, prove the no-Pro model policy with real OpenAI auth, and avoid adding diagram features that do not create a new research job. - Changed: Re-synced the refreshed dependency patch and untracked PaperRank files into Daytona sandbox `8aa523a3-5a33-479c-9129-49910272c413`. Wrote the local OpenAI auth only inside the sandbox for live CLI smokes. Updated the PaperRank plan to replace the stale Daytona-blocked note with the completed Linux sandbox evidence and to record that extra diagrams are rejected unless they add a new research decision beyond the existing graph explorer and dashboard. - Verified: Local full gate passed: `npm test` 229/229, root typecheck/build, production audit with `found 0 vulnerabilities`, website lint/typecheck/build, `npm pack --dry-run`, and `git diff --check`. Daytona full gate passed: remote `npm test` 229/229, remote `npm audit --omit=dev` with `found 0 vulnerabilities`, remote dependency tree showing Pi packages `0.79.8`, `hono@4.12.26`, `protobufjs@7.6.4`, `ws@8.21.0`, and `undici@8.5.0`, remote root typecheck/build, website lint/typecheck/build, `npm pack --dry-run`, and `git diff --check`. Remote authenticated smokes showed `openai/gpt-5.5 (current, recommended)`, no `gpt-5.5-pro` in `model list`, `Model: openai/gpt-5.5` and `Recommended model: openai/gpt-5.5` in `status`, one-shot chat returned `OK`, PaperRank synthesis generated with `openai/gpt-5.5`, and Pro chat/env/PaperRank synthesis paths were rejected. Daytona delete returned HTTP 200, and the final sandbox list showed no Feynman-labeled sandboxes. - Next: Keep the graph/dashboard surfaces as the only diagram additions until a new diagram earns a distinct user job. ### 2026-06-19 23:18 PDT — daytona-audit-runtime-refresh - Objective: Continue the Daytona clean-room verification and fix any real errors it exposes. - Changed: Used the valid Daytona API key from the prior local transcript to create sandbox `8aa523a3-5a33-479c-9129-49910272c413`, cloned Feynman, applied the current dirty worktree patch plus untracked PaperRank files, and ran the root suite on Linux Node 25. Daytona exposed a real production audit failure after `npm ci`: vulnerable `hono`, `protobufjs`, `undici`, and `ws` paths through Pi/MCP dependencies. Refreshed all direct Pi runtime packages to `0.79.8`, bumped direct `undici` to `8.5.0`, updated the `hono` override to `4.12.26`, updated the `protobufjs` override to `7.6.4`, and aligned `PI_RUNTIME_FALLBACK_VERSION` to `0.79.8`. - Verified: Daytona root `npm test` passed 229/229 before the audit fix, proving the patched worktree applied and ran in the sandbox. Local `npm install` and `npm audit --omit=dev` now report `found 0 vulnerabilities`; `npm ls` shows Pi packages at `0.79.8`, `undici@8.5.0`, `hono@4.12.26`, `protobufjs@7.6.4`, and `ws@8.21.0`. - Next: Re-run the full local validation sweep and re-sync the updated patch to Daytona for production audit, typecheck, build, website, pack, and live CLI smokes; delete the sandbox after capture. ### 2026-06-19 22:50 PDT — daytona-environment-sweep - Objective: Run or unblock a Daytona cross-environment test for the current Feynman changes. - Changed: Installed the official Daytona CLI (`daytona` v0.189.0) via Homebrew from the Daytona tap so the machine has the documented sandbox create/list/exec/delete surface available. - Verified: `daytona --version` returned `Daytona CLI version v0.189.0`; `daytona --help` exposes `create`, `list`, `exec`, and `delete`. The Daytona config at `/Users/advaitpaliwal/Library/Application Support/daytona/config.json` contains no active profile and no profiles. `daytona list` fails before any sandbox operation with `no profiles found. Run \`daytona login\` to authenticate`. Local searches found no `DAYTONA_API_KEY` or Daytona credential in the process environment, shell/config files, the macOS generic-password lookup, 1Password item titles, `/Users/advaitpaliwal/.daytona`, `/Users/advaitpaliwal/.config/daytona`, or the active Daytona application-support config. - Blockers: Daytona cloud sandbox execution was not run because this Mac has no authenticated Daytona profile or discoverable local API key. The local Feynman test/build/package/browser smokes remain the verified gate for this change set. - Next: Log in with a Daytona API key, then run the same package/test smoke inside a fresh sandbox and delete the sandbox after capture. ### 2026-06-19 22:32 PDT — tui-header-overflow-178 - Objective: Fix GitHub issue #178, where renaming a session could crash the TUI because a long slash-workflow name overflowed the header column. - Changed: Made the shared header padding helper clip to visible width before padding, changed wide workflow rows to use clipped command names with an explicit separator before descriptions, and changed the narrow workflow branch to use the same clipped padding path instead of raw `padEnd`. - Verified: Live GitHub sweep found issue #178 as the only open issue and no open PRs. Added `tests/header.test.ts`, which renders the actual Feynman header with `/gather-context-and-clarify` at 121 and 50 columns and asserts every line fits plus the command name does not glue to the description. Focused header/runtime tests passed 11/11. Full `npm test` passed 229/229. `npm run typecheck`, `npm run build`, website lint/typecheck/build, `npm pack --dry-run`, and `git diff --check` passed after the fix. - Failed / learned: Running Astro typecheck and build concurrently can race on `website/node_modules/.astro/data-store.json`; the sequential website build passed. - Next: Continue the Daytona environment sweep. ### 2026-06-19 22:23 PDT — paper-rank-pro-override-block-and-feature-audit - Objective: Enforce the user's no-Pro constraint everywhere Feynman can choose a model, and audit PaperRank outputs so added artifacts are useful rather than ornamental. - Changed: Split authenticated model records from non-Pro available records, kept model list/status/setup/model-set on the non-Pro surface, rejected Pro-class IDs in explicit chat `--model`, `FEYNMAN_MODEL`, PaperRank `--synthesis-model`, and PaperRank `--model` synthesis overrides, and made settings normalization replace or clear stale Pro-class defaults. Updated PaperRank/setup/config docs to say explicit overrides are non-Pro only. Added a feature-survival audit to `outputs/.plans/paper-rank-ai-researcher.md` that maps each output to the research job it earns and bars future duplicate/decorative artifacts. - Verified: Focused validation passed 99/99 with `node --import tsx --test --test-concurrency=1 tests/model-harness.test.ts tests/catalog-snapshot.test.ts tests/pi-settings.test.ts tests/pi-subagents-patch.test.ts tests/paper-rank.test.ts`. Full `npm test` passed 228/228. `npm run typecheck`, `npm run build`, website lint/typecheck/build, `npm pack --dry-run`, and `git diff --check` passed. Compiled CLI smokes rejected `node bin/feynman.js --model openai/gpt-5.5-pro --prompt noop` and `FEYNMAN_MODEL=openai/gpt-5.5-pro node bin/feynman.js --prompt noop` with `Pro-class model disabled`; fixture PaperRank with `--synthesis-model openai/gpt-5.5-pro` reported synthesis `failed` without using Pro while preserving deterministic artifacts; fixture PaperRank with `--synthesis-model openai/gpt-5.5` generated synthesis with `modelSelection.reason: explicit non-Pro CLI override`. `node bin/feynman.js model list` showed `openai/gpt-5.5 (current, recommended)` and no standalone Pro IDs; `node bin/feynman.js status` showed `Model: openai/gpt-5.5`, `Model valid: yes`, and `Recommended model: openai/gpt-5.5`. - Next: Continue the GitHub issue/PR and Daytona environment sweep. ### 2026-06-18 17:51 PDT — paper-rank-non-pro-model-selection - Objective: Correct the model-selection fix after the user rejected `openai/gpt-5.5-pro` as too slow and expensive. - Changed: Removed OpenAI Pro-class IDs from static research recommendations, changed automatic model preference/default setup to skip standalone `pro` model IDs, filtered Pro-class IDs out of the available-model surface used by model list/status/setup/model-set resolution, changed the LiteLLM fallback and setup/configuration examples to `gpt-5.5`, updated PaperRank synthesis errors to require a non-Pro model for automatic selection, and reset the local Feynman default model from `openai/gpt-5.5-pro` to `openai/gpt-5.5`. Kept Pro-class strings only as negative test fixtures proving they are not automatically recommended. - Verified: Focused validation passed with 96 tests: `node --import tsx --test --test-concurrency=1 tests/model-harness.test.ts tests/catalog-snapshot.test.ts tests/pi-settings.test.ts tests/pi-subagents-patch.test.ts tests/paper-rank.test.ts`. Full `npm test` passed 225/225. `npm run typecheck`, `npm run build`, website lint/typecheck/build, `npm pack --dry-run`, and `git diff --check` passed. The model tests now assert OpenAI-only recommendation and first-run default use `openai/gpt-5.5`, available-model records contain `openai/gpt-5.5` and no standalone `pro` IDs, automatic recommendations skip Pro-class IDs, and PaperRank fixture E2E still writes bounded synthesis/model-selection artifacts without raw full text. A source-level local settings check confirmed `/Users/advaitpaliwal/.feynman/agent/settings.json` resolves to `openai/gpt-5.5`; after `npm run build`, `node bin/feynman.js model list` showed `openai/gpt-5.5 (current, recommended)` with no Pro-class IDs listed, and `node bin/feynman.js status` showed `Model: openai/gpt-5.5` and `Recommended model: openai/gpt-5.5`. Live OpenAlex/alphaXiv/model-synthesis smoke returned 3 ranked papers, 16 graph papers, 13 expanded papers, 1/1 full texts available, 2 deterministic paper reviews, calibration `insufficient_overlap`, reproduction evidence `insufficient_overlap`, research agenda 4 actions, and generated synthesis from `openai/gpt-5.5`; graph explorer, dashboard, provenance, synthesis Markdown, and synthesis packet checks passed with no raw full-text leakage. Headless Chrome loaded the live dashboard and graph explorer, searched graph nodes, clicked a detail row, verified ReadFirst/citation graph detail text, and captured `/tmp/feynman-rank-nonpro-dashboard.png` plus `/tmp/feynman-rank-nonpro-graph-explorer.png`. - Failed / learned: The previous pass treated the local Pro-suffixed default as a better current model. That was the wrong product decision because it optimized for "newest/strongest" instead of the user's cost/latency constraint. - Next: Collect filled researcher preference fixtures and completed reproduction notes across multiple topics; the local implementation and non-Pro model policy are verified. ### 2026-06-18 13:40 PDT — paper-rank-research-agenda-and-model-provenance - Objective: Address the stale-model complaint by making rank model selection visible and turn PaperRank from a scored-paper surface into an explicit next-action AI-researcher loop. - Changed: Added model-selection metadata to optional model synthesis, including recommended-vs-explicit source, requested model, resolved model, and reason; surfaced the resolved model in CLI output, generated synthesis Markdown, JSON summary, and provenance. Renamed the critique CLI line to `2 deterministic paper reviews` so deterministic reviewer critique is not confused with model-generated critique. Added always-written `-research-agenda.md` and `-research-agenda.json`, with agenda status, recommended score profile, prioritized next actions, replication/calibration action counts, evidence basis, and limits. Wired the research agenda into the main report, research memo, replication plan, dashboard, provenance, synthesis packet, synthesis prompt, CLI JSON summary, README, website docs, command metadata, release notes, and tests. - Verified: Local model state showed default provider/model `openai`/`gpt-5.5-pro`; `feynman model list` showed `openai/gpt-5.5-pro (current, recommended)`; diagnostic `chooseRecommendedModel` returned `openai/gpt-5.5-pro`. Focused model tests passed 29/29. Focused PaperRank tests passed 21/21. Full `npm test` passed 223/223. `npm run typecheck`, `npm run build`, website lint/typecheck/build, `npm pack --dry-run`, and `git diff --check` passed. A live no-explicit-model synthesis smoke printed `Model synthesis: generated by openai/gpt-5.5-pro (recommended current research model; resolved openai/gpt-5.5-pro)` and wrote the same selection into model-synthesis and provenance artifacts. A full fixture-backed rank/model smoke returned 4 ranked papers, 3 graph edges, calibration `evaluated`, reproduction evidence `evaluated`, agenda `ready` with 6 actions and 3 high-priority actions, and generated synthesis from `openai/gpt-5.5-pro`. Agenda Markdown/JSON, report, research memo, dashboard, provenance, and model synthesis were checked for agenda/profile/model-selection content. - Failed / learned: The root defect behind the model complaint was output opacity, not the actual current default: current/recommended was already `openai/gpt-5.5-pro`, but normal rank output only said `Model synthesis: generated` and reviewer critique output could be misread as two model-written critiques. The Playwright wrapper binary was unavailable, and Chrome GUI inspection was blocked by the locked Mac screen, so browser verification used a temporary HTTP server plus headless Chrome/CDP. - Browser verification: Headless Chrome rendered the live dashboard screenshot at `/tmp/feynman-rank-dashboard-headless.png` with score matrix, citation graph snapshot, `Agenda actions` metric, and `Research agenda ready; 3 high-priority action(s)`. Headless Chrome rendered the graph explorer screenshot at `/tmp/feynman-rank-graph-headless.png`; CDP set graph search to `attention`, found one result, clicked it, and verified the detail panel selected `Interpreting Attention Layer Outputs with Sparse Autoencoders` with read-first score and citation graph text. Dashboard CDP verified title text, `6\nAgenda actions`, and `Research agenda\nready; 3 high-priority action(s)`. - Blockers: None for the deterministic PaperRank AI-researcher workflow. Real calibration and reproduction quality still require filled researcher preference fixtures and completed experiment notes across real topics. - Next: Collect cross-topic filled calibration fixtures and completed reproduction notes, compare agenda quality and profile recommendations, then decide whether PaperRank should automatically recommend topic-specific weight profiles or schedule actual replication runs. ### 2026-06-18 13:11 PDT — paper-rank-reproduction-ledger - Objective: Finish the AI-researcher PaperRank slice by separating completed reproduction evidence from planned replication checks and removing stale model selection from model synthesis. - Changed: Added a default `-reproduction-ledger.json` and `-reproduction-notes-template.json`, wired `--reproduction-fixture` through the CLI/env path, report, research memo, replication plan, synthesis packet, dashboard, provenance, README, website docs, command metadata, release notes, and tests. The ledger records externally supplied `reproduced`, `partially_reproduced`, `failed`, and `not_runnable` notes, counts out-of-run notes as ignored, and does not execute experiments or embed raw full text. Fixed the research model selector so current same-family Pro/newer-version models outrank older hardcoded aliases; local Feynman default is now `openai/gpt-5.5-pro`. - Verified: Focused PaperRank test passed 21/21. Model selector focused tests passed 50/50. Full `npm test` passed 222/222. `npm run typecheck`, `npm run build`, website lint/typecheck/build, `npm pack --dry-run`, `git diff --check`, and CLI help smoke passed. Rebuilt `feynman model list` showed `openai/gpt-5.5-pro (current, recommended)`. A live OpenAlex/alphaXiv/model-synthesis smoke for `mechanistic interpretability sparse autoencoders` returned 3 ranked papers, 16 graph papers, 20 graph edges, 2 critiques, 1/1 full texts available, calibration `insufficient_overlap`, reproduction evidence `insufficient_overlap` with 0 evaluated and 3 ignored notes, and generated model synthesis from `openai/gpt-5.5-pro`; ledger/template/packet/report/plan/dashboard/provenance checks passed with no raw full-text leakage. Chromium rendered the live dashboard and graph explorer, filtered graph search, clicked a graph detail, and captured screenshots at `/tmp/feynman-rank-live-dashboard.png` and `/tmp/feynman-rank-live-graph-explorer.png`. - Failed / learned: The Playwright skill wrapper and `@playwright/test` runner did not resolve their binaries/modules in this environment, so browser verification used the cached `playwright` package through `NODE_PATH`. The first browser assertion guessed the wrong visible title and selector; the actual rendered strings/selectors were `FEYNMAN PAPERRANK DASHBOARD` and `.node-button[data-id]`. - Blockers: None for this PaperRank AI-researcher slice. Real reproduction evidence still depends on researcher-run experiments supplied through filled reproduction fixtures. - Next: Use filled researcher read-order fixtures and completed reproduction notes across multiple topics to calibrate weighting profiles and decide whether PaperRank should recommend topic-specific weights or schedule actual replication runs. ### 2026-06-18 10:59 PDT — paper-rank-field-map - Objective: Move PaperRank from ranked papers toward a local research map that shows field structure and relative paper roles. - Changed: Added a default `-field-map.json` artifact with OpenAlex topic/concept clusters across seed and citation-neighborhood papers, plus ranked seed-paper roles such as foundation, frontier, bridge, methodology anchor, reproducibility anchor, and candidate lead. Wired the field map into run results, CLI output, the main report, research memo, dashboard, provenance, README, website docs, release notes, and tests. The field map uses score, citation-degree, graph-prestige, recency, methodology, and reproducibility evidence while omitting raw full-text bodies. - Verified: `npm test -- tests/paper-rank.test.ts` passed 215/215, including field-map cluster/role generation, field-map artifact creation, report/memo/dashboard/provenance links, JSON artifact path output, and raw full-text omission checks. `npm run typecheck`, `npm run build`, website lint/typecheck/build, and `npm pack --dry-run` passed. A live isolated `feynman rank "mechanistic interpretability sparse autoencoders" --limit 5 --expand-citations 1 --full-text-top 1 --critique-top 3 --json` smoke returned 5 ranked seed papers, 36 graph papers, 31 expanded nodes, 45 graph edges, 1/1 full texts available, 3/3 critiques generated, 12 field-map clusters, 5 ranked-paper roles, foundation and bridge roles present, report/memo/dashboard field-map sections present, no raw full text in `papers.jsonl`, no known full-text body copied into the field map, and 0 false `code` markers from `autoencoder` text. - Blockers: None for deterministic field-map generation. Remaining research-quality gaps are a model-backed synthesis layer over the same evidence contract and richer interactive graph exploration. - Next: Add a model-backed synthesis layer over the same evidence contract or a richer interactive graph exploration surface. ### 2026-06-18 10:50 PDT — paper-rank-research-memo - Objective: Move PaperRank from ranked evidence and critique cards toward an AI-researcher decision memo that explains what to read, what to verify, and why. - Changed: Added a default `-research-memo.md` artifact with bottom-line read order, run confidence, evidence snapshot, per-paper verification checks, cross-paper signal/gap patterns, next research actions, scientific basis, and limits. Wired the memo into artifact paths, the main report, dashboard artifact list, provenance, CLI output, README, website docs, release notes, and fixture tests. The memo uses score, citation graph, critique, source-span, and rubric evidence while omitting raw full-text bodies. - Verified: `npm test -- tests/paper-rank.test.ts` passed 214/214, including memo artifact creation, report/dashboard/provenance links, JSON artifact path output, read-order/checks/next-action sections, scientific-basis section, triage caveat, and raw full-text omission checks. `npm run typecheck`, `npm run build`, website lint/typecheck/build, and `npm pack --dry-run` passed. A live isolated `feynman rank "mechanistic interpretability sparse autoencoders" --limit 5 --expand-citations 1 --full-text-top 1 --critique-top 3 --json` smoke returned 5 ranked seed papers, 36 graph papers, 31 expanded nodes, 45 graph edges, 1/1 full texts available, 3/3 critiques generated, memo bottom-line/read-order/next-action/scientific-basis sections present, memo triage caveat present, report/dashboard memo links present, no raw full text in `papers.jsonl`, no known full-text body copied into the memo, and 0 false `code` markers from `autoencoder` text. - Blockers: None for deterministic memo generation. Remaining research-quality gaps are a model-backed synthesis layer over the same evidence contract and richer graph exploration. - Next: Add a model-backed synthesis layer over the same evidence contract or a richer graph exploration surface. ### 2026-06-18 10:58 PDT — paper-rank-dashboard - Objective: Make PaperRank inspectable as an end-to-end AI-researcher cockpit instead of scattered Markdown/JSONL outputs. - Changed: Added a default `-dashboard.html` artifact with summary metrics, score component bars, critique gaps, a bounded SVG citation graph snapshot, scientific-basis links, and artifact links. Wired dashboard artifact paths into report/provenance/CLI output/docs/release notes and added fixture tests that assert the dashboard exists while omitting raw full-text fields/body text. - Verified: `npm test -- tests/paper-rank.test.ts` passed 214/214, including dashboard artifact creation, score matrix/graph/critique sections, JSON artifact path output, and raw full-text omission checks. `npm run typecheck`, `npm run build`, website lint/typecheck/build, and `npm pack --dry-run` passed. A live isolated `feynman rank "mechanistic interpretability sparse autoencoders" --limit 5 --expand-citations 1 --full-text-top 1 --critique-top 3 --json` smoke returned 5 ranked seed papers, 36 graph papers, 31 expanded nodes, 45 graph edges, 1/1 full texts available, 3/3 critiques generated, dashboard marker/score matrix/SVG graph/critique sections present, no raw full text in `papers.jsonl`, no known full-text body copied into the dashboard, and 0 false `code` markers from `autoencoder` text. - Blockers: None for the static dashboard artifact. Remaining research-quality gaps are a model-written critique layer over the same evidence contract and richer graph exploration. - Next: Add a model-written critique layer over the same evidence contract or a richer graph exploration surface. ### 2026-06-18 10:40 PDT — paper-rank-reviewer-critique - Objective: Move PaperRank from ranked evidence tables toward an AI-researcher review loop by adding reviewer-style strengths, concerns, and follow-up questions grounded in the existing score evidence. - Changed: Added `--critique-top N`, deterministic PaperRank critique generation, `-critique.md`, critique entries in the main report/provenance, JSON summary counts, CLI/help/docs/release-note updates, and fixture-backed tests for critique generation plus sidecar artifacts. The critique uses PaperRank scores, warnings, source spans, and NeurIPS-style rubric gaps; it does not claim to be an external peer-review decision. - Verified: `npm test -- tests/paper-rank.test.ts` passed 214/214, including critique generation, critique sidecar artifact creation, JSON summary counts, report/provenance entries, and CLI fixture E2E with `--critique-top`. `npm run typecheck`, `npm run build`, website lint/typecheck/build, and `npm pack --dry-run` passed. A live isolated `feynman rank "mechanistic interpretability sparse autoencoders" --limit 5 --expand-citations 1 --full-text-top 1 --critique-top 3 --json` smoke against OpenAlex/alphaXiv returned 5 ranked seed papers, 36 graph papers, 31 expanded nodes, 45 graph edges, 1/1 full texts available, 3/3 critiques generated, reviewer critique sections and follow-up questions present, no raw full text in `papers.jsonl`, and 0 false `code` markers from `autoencoder` text. - Blockers: None for deterministic reviewer critique. Remaining research-quality gaps are a model-written critique layer over the same evidence contract and a dashboard. - Next: Add a dashboard or a model-written critique layer over the same evidence contract. ### 2026-06-18 10:18 PDT — paper-rank-citation-expansion - Objective: Make PaperRank's PageRank-style graph less myopic by expanding beyond the initial search result set while keeping ranked seed papers and expanded graph-context papers separate. - Changed: Added `--expand-citations N`, OpenAlex batch fetch by work ID, incoming citation fetches with `cites:`, fixture-backed citation expansion, seed/expanded graph node roles, citation expansion summary fields in JSON/report/provenance/graph artifacts, and deterministic fixture papers for outgoing-reference and incoming-citation expansion. Tightened evidence-marker matching to require word/phrase boundaries so `code` no longer matches inside `autoencoders`. Updated README, website docs, release notes, and the PaperRank plan artifact. - Verified: `npm test -- tests/paper-rank.test.ts` passed 213/213, including outgoing/incoming citation expansion, graph node roles, expanded graph artifacts, marker-boundary regression coverage, and CLI fixture E2E with `--expand-citations`. `npm run typecheck`, `npm run build`, website lint/typecheck/build, and `npm pack --dry-run` passed. A live isolated `feynman rank "mechanistic interpretability sparse autoencoders" --limit 5 --expand-citations 1 --full-text-top 1 --json` smoke against OpenAlex/alphaXiv returned 5 ranked seed papers, 36 graph papers, 31 expanded nodes, 45 graph edges, 1/1 full texts available, all 5 top-paper rubric items evaluated, no raw full text in `papers.jsonl`, and 0 false `code` markers from `autoencoder` text. - Failed / learned: OpenAlex rejected `sort=-cited_by_count` for citing-work fetches; `sort=cited_by_count:desc` is the working syntax for the live `cites:` endpoint. The first live smoke also exposed substring evidence matching, which is now fixed with boundary-aware marker matching. - Blockers: None for bounded citation-neighborhood expansion. Remaining research-quality gaps are LLM critique over extracted evidence spans and a dashboard. - Next: Add LLM critique over extracted evidence spans or a dashboard. ### 2026-06-18 10:08 PDT — paper-rank-section-rubric - Objective: Move PaperRank from full-text marker matching toward a more legible AI-researcher audit by extracting paper sections and answering checklist-style rubric items. - Changed: Added canonical full-text section extraction with absolute offsets, section-specific `full_text:
` spans, deterministic rubric answers for limitations, reproducibility path, experimental details, statistical significance, and compute resources, rubric-backed methodology/reproducibility scoring, report rendering for section rubric findings, and JSONL/`papers.jsonl` serialization that keeps section boundaries without writing raw section bodies. Updated fixture full text, tests, docs, release notes, and the PaperRank plan artifact. - Verified: `npm test -- tests/paper-rank.test.ts` passed 211/211, including section extraction, rubric answers, durable artifacts, and fixture CLI E2E. `npm run typecheck`, `npm run build`, `npm --prefix website run lint`, `npm --prefix website run typecheck`, `npm --prefix website run build`, and `npm pack --dry-run` passed. An isolated live `feynman rank "mechanistic interpretability sparse autoencoders" --limit 5 --full-text-top 1 --json` smoke returned five papers, enriched 1/1 requested full texts, wrote the rubric section, produced 25 rubric answers, produced three section-specific full-text spans, and serialized three full-text section boundaries. - Blockers: None for deterministic section-aware rubric screening. The remaining research-quality gap is LLM critique over the extracted spans and broader citation expansion beyond the first OpenAlex candidate set. - Next: Run typecheck/build/website/package/live smoke, then add citation expansion or a dashboard slice. ### 2026-06-18 10:00 PDT — paper-rank-full-text-enrichment - Objective: Move PaperRank closer to an AI researcher by letting the ranking inspect full-paper content for top arXiv candidates instead of relying only on metadata and abstracts. - Changed: Added `--full-text-top N` to `feynman rank`, pre-ranking from OpenAlex metadata, fetching full text for top arXiv candidates through the bundled alphaXiv client, recording per-paper full-text status, rescoring with `full_text` source spans, and omitting raw paper bodies from `papers.jsonl` while keeping `fullTextLength` and score evidence spans. Updated README, CLI help metadata, website docs, release notes, fixture data, tests, and the PaperRank plan artifact. - Verified: `npm test -- tests/paper-rank.test.ts` passed 209/209, including deterministic fixture CLI full-text enrichment; `npm run typecheck`, `npm run build`, `npm --prefix website run lint`, `npm --prefix website run typecheck`, `npm --prefix website run build`, and `npm pack --dry-run` passed. `node bin/feynman.js help | rg "full-text-top|Rank papers"` showed the new help line. An isolated live `feynman rank "mechanistic interpretability sparse autoencoders" --limit 5 --full-text-top 1 --json` smoke returned five papers, enriched 1/1 requested full texts, and wrote artifacts with 51 span-backed evidence entries including 31 `full_text` spans. - Failed / learned: An earlier live smoke failed only because it ran concurrently with `npm pack --dry-run`, whose prepack step cleans and rebuilds `dist/`; the isolated rerun passed. - Blockers: None for optional full-text enrichment. The remaining research-quality gap is section-aware extraction and rubric answers over cited full-paper spans. - Next: Add citation expansion beyond the first OpenAlex candidate set, section-aware extraction, rubric answers over full-paper spans, and a local dashboard. ### 2026-06-18 09:50 PDT — paper-rank-source-spans - Objective: Make PaperRank methodology and reproducibility scoring explainable with concrete source text, not only marker counts. - Changed: Added source-span extraction for methodology and reproducibility markers, preserved span objects in score evidence (`source`, `field`, `marker`, start/end offsets, and surrounding text), surfaced top evidence snippets in the Markdown report, and updated PaperRank docs/plan language to describe span-backed screening. - Verified: `npm test -- tests/paper-rank.test.ts` passed 208/208, including span extraction and CLI artifact assertions; `npm run typecheck`, `npm run build`, website lint/typecheck/build, and `npm pack --dry-run` passed. A live `feynman rank "mechanistic interpretability sparse autoencoders" --limit 5 --json` smoke wrote artifacts whose report contains the evidence section and whose scores JSONL contained 20 span-backed evidence entries. - Failed / learned: Running website `astro check` and `astro build` in parallel caused a transient `.astro/data-store.json` rename race; rerunning typecheck by itself passed. - Blockers: None for metadata/abstract source spans. Full-text methodology review still requires an AlphaXiv/full-paper pass with section-level spans. - Next: Add optional full-text enrichment for top-ranked arXiv papers, then move from marker screening to rubric answers grounded in extracted paper sections. ### 2026-06-18 09:43 PDT — paper-rank-ai-researcher - Objective: Move Feynman from research strategy toward a tested end-to-end AI researcher by shipping a first PaperRank workflow for transparent paper ranking. - Changed: Added `feynman rank ` backed by OpenAlex-shaped work metadata, normalized paper records, local citation-graph construction, PageRank-style graph prestige, citation impact/velocity, deterministic methodology and reproducibility screening, and durable artifacts (`-paper-rank.md`, `-papers.jsonl`, `-scores.jsonl`, `-citation-graph.json`, `-rank.provenance.md`). Added docs, release notes, command registry wiring, fixture data, unit tests, and a CLI fixture e2e test. - Verified: `npm test` passed 207/207; `npm run typecheck`, `npm run build`, website lint/typecheck/build, `npm pack --dry-run`, and `node bin/feynman.js help | rg 'feynman rank|PaperRank|Rank papers'` passed. A live `node bin/feynman.js rank "mechanistic interpretability sparse autoencoders" --limit 5 --json` run against OpenAlex returned five papers and wrote all five artifacts in a temp output directory. - Failed / learned: A help smoke run failed once while `npm pack --dry-run` was deleting and rebuilding `dist/`; rerunning after pack passed. The live 5-paper OpenAlex set had no candidate-to-candidate citation edges and missing abstract-visible methodology evidence for the top paper, and PaperRank correctly marked those components unavailable instead of fabricating them. - Blockers: None for the first PaperRank slice. Full methodology peer review still requires a later full-text/AlphaXiv evidence-span pass rather than abstract-only screening. - Next: Extend PaperRank with citation expansion, full-text methodology extraction, source-span-backed rubric answers, and a dashboard. ### 2026-06-18 09:30 PDT — alphaxiv-cli-repair - Objective: Fix broken alphaXiv access end to end, including the Feynman agent shell path that was resolving an old global `feynman` binary. - Changed: Added `feynman alpha ...` pass-through to Feynman's bundled patched alphaXiv client, documented the full alpha command surface, updated bundled prompts/skills/agent guidance to avoid the user's bare global `alpha` binary, patched the user's global alpha-hub install on this machine, and added a per-Feynman-home `bin/feynman` shim so Pi bash sessions resolve this repo's CLI before stale global installs. - Verified: `npm test` passed 200/200; root `npm run typecheck`, root `npm run build`, website `npm --prefix website run lint`, website `npm --prefix website run typecheck`, website `npm --prefix website run build`, and `npm pack --dry-run` passed. Live smokes passed for `node bin/feynman.js --version`, `node bin/feynman.js alpha status`, bundled `feynman alpha search "transformer scaling laws" --mode semantic --json`, bundled `feynman alpha get 2001.08361 --json`, and global `/Users/advaitpaliwal/.npm-global/bin/alpha search "transformer scaling laws" --mode keyword --json`. A forced one-shot agent bash test ran `feynman alpha search "transformer scaling laws" --mode semantic --json` and returned `RESULT_COUNT=10 FIRST_ID=2411.06646`. - Failed / learned: Direct package-local alpha-hub already worked; the user-visible failure came from stale global alpha-hub search fallback and, separately, from Pi bash resolving global `feynman 0.2.49` instead of the current repo CLI. - Blockers: Remote CI and release publication were not run from this local repair pass. - Next: Publish the pending `0.3.4` refresh when ready, then run the remote end-to-end install workflow against the packaged release. ### 2026-06-16 00:00 PDT — feynman-ai-researcher - Objective: Research how to convert Feynman into a deeper AI researcher and whether to build a PageRank-style paper-importance/methodology scoring product. - Changed: Wrote a source-backed strategy package: `outputs/.plans/feynman-ai-researcher.md`, `outputs/.drafts/feynman-ai-researcher-research-direct.md`, `outputs/.drafts/feynman-ai-researcher-cited.md`, `outputs/.drafts/feynman-ai-researcher-verification.md`, `outputs/feynman-ai-researcher.md`, and `outputs/feynman-ai-researcher.provenance.md`. - Verified: Local Feynman README/AGENTS/prompts/skills/extensions/docs were read; external sources were opened for Semantic Scholar, OpenAlex, Elicit, ResearchRabbit, Litmaps, Consensus, SciSpace, Undermind, PaperQA2, OpenScholar, Agent Laboratory, AI Scientist, Eigenfactor, time-aware PageRank, PRISMA, EQUATOR, Cochrane RoB 2/ROBINS-I, GRADE, and NeurIPS/ML reproducibility checklists. Artifact existence and key final sections were checked with `stat` and `rg`. - Failed / learned: Scite pages were sparse behind JavaScript in this environment and were not used for final claims. Live OpenAlex/Semantic Scholar API limits and pricing were not smoke-tested, so implementation must re-check provider limits before coding. - Blockers: None for the research artifact. The PaperRank score weights remain a product hypothesis that need empirical validation against real paper-selection tasks. - Next: Implement `feynman rank ` as the first product slice: normalized paper records, local citation graph, component scoring, methodology/reproducibility rubrics with source spans, JSONL outputs, and a local dashboard. ### 2026-06-14 11:23 PDT — daily-issue-sweep - Objective: Re-check live GitHub issues/PRs, dependency/audit freshness, CI/release status, and repo-local validation against the pending `0.3.4` refresh. - Changed: No open GitHub issues or PRs required product fixes. Updated the remaining stale website devDependency `eslint-plugin-react-refresh` from `^0.5.2` to `^0.5.3`, preserving the existing pending `0.3.4` maintenance refresh. - Verified: `gh issue list --state open ...` returned `[]`; `gh pr list --state open ...` returned `[]`; `gh run list --limit 15 ...` still shows latest successful `Publish and Release` run `27438650693` and latest successful `End-to-End Install Tests` run `27394423414`; `gh release list --limit 10` and `npm view @companion-ai/feynman version` still show `v0.3.3` / `0.3.3` latest while the local package is `0.3.4`. Root and website `npm outdated --json` now return `{}`; root and website `npm audit --omit=dev` both report zero vulnerabilities. `npm test` passed 198/198, root `npm run typecheck`, root `npm run build`, website `npm run lint`, website `npm run typecheck`, website `npm run build`, `npm pack --dry-run`, and `node bin/feynman.js --version` all passed. - Failed / learned: The only new actionable item was the website lint-plugin patch update; no new issue, PR, audit, CI, or local validation failure required a code-path fix. - Blockers: None for this local sweep. - Next: Push the pending `0.3.4` maintenance refresh when ready, then let release CI publish and rerun e2e. ### 2026-06-14 03:56 PDT — daily-issue-sweep - Objective: Re-check live GitHub issues/PRs, dependency/audit freshness, CI/release status, and repo-local validation after the prior pending `0.3.4` maintenance refresh. - Changed: No product code changes. No open GitHub issues or PRs required action, and the pending `0.3.4` dependency/runtime refresh remained the only local code change set. - Verified: `gh issue list --state open ...` returned `[]`; `gh pr list --state open ...` returned `[]`; `gh run list --limit 20 ...` still shows latest successful `Publish and Release` run `27438650693` and latest successful `End-to-End Install Tests` run `27394423414`; `gh release list --limit 10` still shows `v0.3.3` latest. Root and website `npm outdated --json` returned `{}`; root and website `npm audit --omit=dev` both reported `found 0 vulnerabilities`. `npm test` passed 198/198, root `npm run typecheck`, root `npm run build`, website `npm run typecheck`, website `npm run build`, `npm pack --dry-run`, and `node bin/feynman.js --version` all passed. `npm ls esbuild` confirms `esbuild@0.28.1` under root `tsx` and website Astro/Vite. - Failed / learned: No new actionable remote issue, PR, dependency, audit, CI, release, or local validation failure was present in this sweep. - Blockers: None for this local sweep. - Next: Push the pending `0.3.4` maintenance refresh when ready, then let release CI publish and rerun e2e. ### 2026-06-12 — windows-agent-npm-subagent-root - Objective: Make the Windows subagent spawn work from the published package and prove it with the multi-OS e2e workflow. - Changed: Added regression coverage for launch-time pi-subagents patching in both the Feynman npm-global package root and Pi's `/npm/node_modules` package root; bumped the package to `0.3.3` for a release containing the already-committed `/npm/node_modules` runtime patch. - Verified: Run `27392984208` failed only on Windows live subagent smoke; its instrumentation showed `D:\a\_temp\feynman-home\.feynman\agent\npm\node_modules\pi-subagents` existed with `patched(wrapperPiCliPath): false`, while the failure still imported `D:\a\feynman\feynman\--mode` through Feynman's wrapper. Focused local patch tests, `npm test` (198/198), `npm run typecheck`, `npm run build`, `node bin/feynman.js --version`, and a local live subagent smoke returning `RESULT=PONG` passed. - Failed / learned: The 0.3.2 fix covered the npm-global copy but not Pi 0.79's own agent-local package install root after `FEYNMAN_HOME` is set. - Blockers: Need publish confirmation, e2e green on all six jobs, diagnostics cleanup, and a final green e2e run. - Next: Push `0.3.3`, verify npm latest, and dispatch e2e. ### 2026-06-13 — daily-issue-sweep - Objective: Re-run the daily issue/PR, dependency freshness, CI/release, audit, and local validation sweep against the current checkout. - Changed: No open GitHub issues or PRs required action. Advanced the pending `0.3.4` maintenance refresh from Pi `0.79.2` to `0.79.3`, kept the runtime fallback constants aligned, and updated website in-range stale packages (`@tailwindcss/vite`, `tailwindcss`, `lucide-react`, `eslint`). Preserved the existing `esbuild: 0.28.1` audit overrides. - Verified: `gh issue list --state open ...` returned `[]`; `gh pr list --state open ...` returned `[]`; `gh run list --branch main --limit 10 ...` still shows latest successful `Publish and Release` run `27438650693` and latest successful `End-to-End Install Tests` run `27394423414`; `gh release list --limit 10` still shows `v0.3.3` latest. Root and website `npm outdated --json` now return `{}`; root and website `npm audit --omit=dev` both report `found 0 vulnerabilities`. `npm test` passed 198/198, root `npm run typecheck`, root `npm run build`, website `npm run typecheck`, website `npm run build`, `npm pack --dry-run`, and `node bin/feynman.js --version` all passed. `npm ls esbuild` confirms `esbuild@0.28.1` under root `tsx` and website Astro/Vite. Runtime archive inspection confirms all four bundled Pi packages lock to `0.79.3`. - Failed / learned: The first archive inspection used the wrong extracted root path; the archive top-level is `npm/`, and the rerun against that path passed. - Blockers: None for this local sweep. - Next: Push the pending `0.3.4` maintenance refresh when ready, then let release CI publish and rerun e2e. ### 2026-06-12 13:24 PDT — daily-issue-sweep - Objective: Sweep live GitHub issue/PR state, dependency/audit freshness, CI/release status, and repo-local validation for safe actionable fixes. - Changed: No open GitHub issues or PRs required action. Refreshed the bundled Pi runtime from `0.79.1` to `0.79.2` across direct deps plus the packaged runtime fallback constants, added a root `esbuild: 0.28.1` override to clear the new `tsx -> esbuild 0.28.0` advisory, added the same website override for Astro/Vite's `esbuild <0.28.1` advisory path, and bumped the package version to `0.3.4` with release notes. - Verified: `gh issue list --state open --json ...` returned `[]`; `gh pr list --state open --json ...` returned `[]`; `gh run list --limit 12 --json ...` still shows the latest successful `Publish and Release` run `27438650693` and `End-to-End Install Tests` run `27394423414`; `gh release list --limit 10` still shows `v0.3.3` as latest before this local bump. `npm outdated --json` is now `{}`. Root `npm install` and website `npm install` both ended with `found 0 vulnerabilities`. Root `npm audit --json` first exposed `esbuild` advisory `GHSA-gv7w-rqvm-qjhr` through `tsx@4.22.4`; after the override, root `npm audit --omit=dev`, `npm test` (198/198), `npm run typecheck`, `npm run build`, `npm pack --dry-run`, `node bin/feynman.js --version`, and `npm ls esbuild` all passed. Website `npm audit --omit=dev`, `npm run typecheck`, `npm run build`, and `npm ls esbuild` also passed with `esbuild@0.28.1` forced under Astro/Vite. - Failed / learned: A concurrent `node bin/feynman.js --version` run failed once because `npm pack --dry-run` intentionally deletes and rebuilds `dist/` during `prepack`; rerunning it after the pack step passed, so that was a validation race, not a repo defect. - Blockers: None. - Next: Push the `0.3.4` maintenance refresh when ready so release CI can publish the Pi/runtime-security sweep. ### 2026-06-12 13:22 PDT — daily-issue-sweep - Objective: Refresh live GitHub issue/PR state, dependency/audit freshness, CI/release status, and repo-local validation for any safe actionable fix. - Changed: No product code changes; recorded that the repo currently has no open GitHub issues or PRs and that the latest publish/e2e flows for `main` are green after `v0.3.3`. - Verified: `gh issue list --state open --json ...` returned `[]`; `gh pr list --state open --json ...` returned `[]`; `gh run list --limit 12 --json ...` shows latest successful `Publish and Release` run `27438650693` on 2026-06-12 19:38Z and latest successful `End-to-End Install Tests` run `27394423414` on 2026-06-12 04:25Z; `gh release list --limit 10` shows `v0.3.3` as latest; root `npm outdated --json` returned `{}`; root and website `npm audit --omit=dev` found `0` vulnerabilities; `npm test` passed `198/198`; `npm run typecheck`; `npm run build`; `npm pack --dry-run`; `node bin/feynman.js --version`; and `cd website && npm run build` all passed. - Failed / learned: No actionable remote issue, PR, dependency, audit, CI, release, or local validation failure was present in this sweep. - Blockers: None. - Next: On the next sweep, only dig deeper if a new issue/PR opens, a workflow regresses, or one of the validation commands starts failing. ### 2026-06-12 06:22 PDT — daily-issue-sweep - Objective: Sweep live GitHub issues/PRs, dependency/audit freshness, CI/release state, and repo-local validation for safe actionable fixes. - Changed: No repo code changes; recorded that there are still no open GitHub issues, PR `#173`'s Windows `explorer` hardening is already present in `src/system/open-url.ts` plus `tests/open-url.test.ts`, and PR `#175`'s MiniMax M3 preference is already present in `src/model/catalog.ts`. - Verified: `gh issue list --json ...` returned `[]`; `gh pr list` still shows only `#173`, `#175`, and `#176`; `gh run list --limit 12` shows the latest `Publish and Release` and `End-to-End Install Tests` runs succeeded on 2026-06-12; `gh release list --limit 10` shows `v0.3.3` as latest; root `npm outdated --json` returned `{}`; root and website `npm audit --omit=dev` both found `0` vulnerabilities; `npm test` passed `198/198`; `npm run typecheck`; `npm run build`; `npm pack --dry-run`; `node bin/feynman.js --version`; and `cd website && npm run build` all passed. - Failed / learned: PR `#176` is still the only open change not reflected in `main`, but its diff only adds README sponsorship copy plus `atlascloud` labels/setup-list entries. It still lacks repo-local runtime proof that Atlas Cloud is a validated Feynman provider contract rather than an OpenAI-compatible custom-provider marketing claim. - Blockers: Need actual Atlas runtime evidence for `#176` such as a docs-backed API contract plus a real `models.json` or setup-path verification before it is safe to merge or port. - Next: Keep `#173` and `#175` treated as stale/superseded by `main`; require concrete provider integration evidence before touching `#176`. ### 2026-06-11 23:18 PDT — daily-issue-sweep - Objective: Sweep live GitHub issues/PRs plus local dependency, CI, release, and validation health for actionable safe fixes. - Changed: No repo code changes; recorded that `main` already contains the Windows `open-url` hardening and the MiniMax M3 research preference that open PRs `#173` and `#175` propose. - Verified: `gh issue list` showed no open issues; `gh pr list` showed only `#173`, `#175`, and `#176`; `gh run list` showed the latest `Publish and Release` and `End-to-End Install Tests` runs green for `v0.3.3`; `gh release list` shows `v0.3.3` as latest; `npm audit --omit=dev` returned zero vulns; `npm outdated --json` returned `{}`; `npm test` passed `198/198`; `npm run typecheck`; `npm run build`; `npm pack --dry-run`; and `node bin/feynman.js --version` returned `0.3.3`. - Failed / learned: PR `#176` is the only still-open change not already present in `main`, but the current PR evidence only shows label/sort-order/API-key-list docs wiring; it does not show a verified Atlas Cloud runtime path or model-catalog proof beyond README marketing copy. - Blockers: Need actual provider integration evidence for `#176` before treating it as safe to merge or port. - Next: Either close `#173` and `#175` as stale/superseded, or comment with `main` evidence; ask `#176` for a real runtime repro or docs-backed provider contract before merging. ## Entry template ### YYYY-MM-DD HH:MM TZ — [slug or objective] - Objective: ... - Changed: ... - Verified: ... - Failed / learned: ... - Blockers: ... - Next: ... ### 2026-06-11 19:54 PDT — pi-subagents-userdir - Objective: Fix the `userDir is not defined` Pi subagent launch failure and make Feynman's pi-subagents patcher fail closed when upstream patch anchors drift. - Changed: Made grouped pi-subagents source edits transactional, stopped rewriting the current upstream `getAgentDir()` agents path shape, repaired already half-patched current `agents.ts` inputs, and updated runtime/patch regression fixtures. - Verified: `npm test`, `npm run typecheck`, focused patch tests, and live/tarball pi-subagents patch invariant checks passed. - Failed / learned: Current upstream `pi-subagents@0.28.0` already honors `PI_CODING_AGENT_DIR`, and Feynman already sets it alongside `FEYNMAN_CODING_AGENT_DIR`; the old agents path rewrite is unnecessary for that shape and caused the mixed-state failure. - Blockers: None. - Next: Release when ready; do not re-enable current-shape agents path rewrites unless upstream stops honoring `PI_CODING_AGENT_DIR`. ### 2026-05-16 17:43 PDT — hindsight-memory-preset - Objective: Address issue `#166` by making Hindsight memory installable through Feynman's optional package preset system. - Changed: Added a `hindsight` optional preset for `@luxusai/pi-hindsight`, added `hindsight` and `pi-hindsight` update aliases, bumped the package to `0.2.58`, and updated release, package-stack, and setup docs. - Verified: Live npm metadata and README for Hindsight Pi packages were checked; full root tests, typecheck, root build, root and website production audits, website build, package dry-run, package-list smoke, and a temp-home `feynman packages install hindsight` smoke passed locally. - Failed / learned: The issue body was empty, but live npm package research found multiple Hindsight Pi packages; `@luxusai/pi-hindsight` is the most current docs-backed fit for Feynman's newer Pi runtime namespace while remaining optional. - Blockers: Need commit, push, release workflow confirmation, npm latest verification, and issue update. - Next: Push `main`, watch release CI, verify npm latest, then update and close `#166`. ### 2026-05-15 03:07 PDT — editor-input-contrast - Objective: Fix issue `#165`, where macOS/iTerm users could not read typed text in Feynman's dark interactive input box. - Changed: Centralized the Pi TUI editor/theme patch, added an explicit editor input foreground, applied the patch to package-local Pi files, launch-time runtime patching, and the vendored runtime archive path; bumped the package to `0.2.57`; added release notes; and updated the website lockfile `devalue` transitive to `5.8.1` after audit flagged the older release. - Verified: Focused Pi TUI tests, full root tests, typecheck, root build, root production audit, website production audit, website build, runtime archive content inspection, package dry-run, packed tarball inspection, and clean installed-tarball `feynman --version` plus `feynman doctor` passed locally. - Failed / learned: The placeholder was readable because it already used a themed foreground; typed input inherited the terminal default foreground after Feynman added the dark editor background. - Blockers: Need commit, push, release workflow confirmation, npm latest verification, and issue closure. - Next: Push `main`, watch release CI, verify npm latest, then close `#165`. ### 2026-05-13 11:55 PDT — audit-detail-sweep - Objective: Tighten the current Feynman release line after a broad detail sweep. - Changed: Bumped the root `protobufjs` override to `7.5.8`, refreshed the lockfile, added `0.2.56` release notes, and kept the package line publishable with a new patch version. - Verified: Tracker and PR lists were empty; root tests, typecheck, build, root and website production audits, website build, diff whitespace check, package dry-run, and clean installed-tarball `feynman --version` plus `feynman doctor` passed after the override refresh. - Failed / learned: The first root production audit exposed a new `protobufjs <=7.5.5` advisory from the existing override, so `0.2.55` needed a follow-up security patch rather than a no-op sweep. - Blockers: Need commit, push, release workflow confirmation, and npm latest verification for `0.2.56`. - Next: Push `main`, watch release CI, then verify npm latest. ### 2026-05-09 16:20 PDT — skills-install-targets - Objective: Make standalone skills installs unambiguous for Codex, Claude/agent repo-local use, and OpenCode. - Changed: Added explicit Codex installer scopes, documented target-specific commands, and added Codex smoke coverage. - Verified: Focused installer tests, full root test suite, root typecheck, root build, package dry-run, diff whitespace check, website typecheck, and website build passed locally. - Failed / learned: The existing default was already Codex, but the named scopes did not expose that clearly. - Blockers: None. - Next: Push `0.2.50` and answer issue #161 with the Codex, repo-local, and OpenCode commands. ### 2026-05-09 17:05 PDT — pi-package-peer-deps - Objective: Address the missing peer-runtime dependency class reported as a follow-up on issue #80 and stop the issue monitor from missing new comments. - Changed: Updated the issue heartbeat to include new comments; changed Pi package npm installs/updates to install the pinned Pi runtime peer packages beside Pi packages; bumped to `0.2.51`. - Verified: Focused package-manager tests, full root test suite, root typecheck, root build, package dry-run, diff whitespace check, website typecheck, and website build passed locally. - Failed / learned: The pasted `@earendil-works/pi-coding-agent` imports do not match the current npm tarballs for `pi-btw@0.3.7` or `pi-markdown-preview@0.9.7`, which currently import `@mariozechner/*`; the real Feynman-side bug is legacy peer dependency mode leaving peer-only runtime packages absent. - Blockers: None. - Next: Push `0.2.51`, watch release CI, and report the monitor/fix status. ### 2026-05-07 15:05 PDT — node24-core-researcher - Objective: Fix the Node 24 regression from the default Pi package set while keeping Feynman focused on the core AI researcher path. - Changed: Restored Node 24 support, slimmed default packages to alphaXiv/subagents/doc parsing/web access, moved memory and session search to optional presets, and upgraded the website stack to patched Astro 6/Vite 7 with the current content-layer config. - Verified: Root build, typecheck, full tests, package dry-run, native bundle build, website build/typecheck/lint, and production audits passed locally. - Failed / learned: The native bundle and website build still had stale assumptions: native validation expected `better-sqlite3`, and the Astro 6 upgrade needed the Vite override lifted to Vite 7 before static pages rendered. - Blockers: None. - Next: Push `main` and use release CI to publish `0.2.49`. ### 2026-05-07 04:00 PDT — pi-runtime-refresh - Objective: Run another broad Feynman health sweep and take useful dependency/runtime fixes without bloating the wrapper. - Changed: Updated `@mariozechner/pi-ai` and `@mariozechner/pi-coding-agent` to `0.73.0`; updated `@clack/prompts` to `1.3.0`; bumped the package to `0.2.45`; added release notes. - Verified: Working tree started clean; open GitHub issues and PRs were empty; latest main release workflow was green; `npm test` passed with 154/154; typecheck, root build, website build, `feynman doctor`, `npm audit --omit=dev`, and `npm pack --dry-run` passed; JSONL RPC `get_state` plus `bash` returned `FEYNMAN_RPC_OK`; release CI published npm `0.2.45`, built native bundles, and created the GitHub release; global `feynman@0.2.45` installed and passed doctor plus RPC smoke. - Failed / learned: TypeScript `6.0.3` is available as a major upgrade, but this pass intentionally did not take that compiler jump because the runtime wrapper benefit is low relative to release risk. - Blockers: None for the runtime refresh. - Next: Keep TypeScript 6 as a separate deliberate migration, not part of a runtime refresh. ### 2026-05-07 05:20 PDT — ml-recipe-workflow - Objective: Review and finish the pending ML recipe workflow instead of leaving it as unverified local drift. - Changed: Added the `/recipe` workflow, read-only Hugging Face Hub inspection tools, researcher recipe-mode guidance, docs, and focused Hugging Face tool tests; bumped the package to `0.2.46`. - Verified: Context7 docs for Hugging Face.js confirm the Hub list/download model; live Hub checks returned HTTP 200 for dataset metadata, dataset tree, model tree, and README reads; mocked unit tests cover tool registration, auth, encoded URLs, limits, and truncation; `npm test` passed with 156/156; typecheck, root build, website build, CLI help, and `git diff --check` passed. - Failed / learned: The global `0.2.45` release correctly did not include the pending recipe workflow, so this needs its own versioned release instead of being described under `0.2.45`. - Blockers: Need post-bump pack/audit validation, commit, push, release workflow confirmation, and global install update to `0.2.46`. - Next: Run final validation, push `main`, watch release CI, then install `@companion-ai/feynman@0.2.46` globally. ### 2026-05-07 05:35 PDT — docs-test-cleanup - Objective: Clear the remaining local doc/test corrections without pushing a duplicate package version. - Changed: Linked upstream Pi and Hugging Face docs from README and website docs; clarified Hugging Face binary-file refusal behavior; tightened the binary-refusal test assertion; bumped the package to `0.2.47`. - Verified: Pending final validation before push. - Failed / learned: `0.2.46` released successfully, so any further pushed changes need a new package version to keep the release workflow green. - Blockers: Need validation, push, release workflow confirmation, and global install update to `0.2.47`. - Next: Run tests/build/audit/pack, push `main`, watch release CI, then install latest globally. ### 2026-05-06 19:04 PDT — audit-cleanup - Objective: Run a broad maintenance pass after tracker cleanup and fix anything that materially helps Feynman. - Changed: Updated transitive dependency override pins for `basic-ftp`, `hono`, `express-rate-limit`, `ip-address`, AWS XML parsing dependencies, and MCP SDK resolution; bumped the package to `0.2.44`; added release notes. - Verified: Open GitHub issues and PRs were both empty; installed CLI and npm latest were `0.2.43` before this pass; full `npm test` passed with 154/154; typecheck, root build, website build, `feynman doctor`, and production `npm audit --omit=dev` passed. - Failed / learned: The remaining audit issues were caused by repo-level overrides pinning vulnerable transitive versions; local npm `min-release-age=7` required disabling the delay to install newly patched Hono. - Blockers: Need final post-bump validation, commit, push, release workflow confirmation, and installed CLI update. - Next: Re-run validation after the version bump, push `main`, watch release CI, then install `@companion-ai/feynman@0.2.44` globally. ### 2026-05-06 03:34 PDT — web-search-config-perms - Objective: Integrate the remaining open PR for web-search credential file permissions and ship it through the npm release path. - Changed: Restricted `.feynman/web-search.json` to `0600` after writes, added POSIX regression coverage, bumped the package to `0.2.43`, and added release notes. - Verified: Focused `pi-web-access` test passed; final post-bump `npm test` passed with 154/154; typecheck, build, diff check, package-lock version check, and `npm pack --dry-run` passed. - Failed / learned: A code-only commit would not publish because `0.2.42` was already on npm, so this fix needs a version bump. - Blockers: Need push, GitHub Actions release confirmation, and PR #154 closure. - Next: Push `main`, watch the release workflow, then close PR #154 as integrated. ### 2026-05-06 00:00 local — github-issues-150-153 - Objective: Read the current Feynman GitHub issues and fix the open tracker items end to end. - Changed: Fixed bundled package seeding so copied runtime packages satisfy startup package checks; seeded bundles before interactive setup reports missing packages; restricted Feynman and sqlite-backed native package support to Node 22; moved release CI to Node 22; restored token-based npm publishing; made GitHub native releases independent of the npm publish result; applied the biomedical literature review docs from PR #152; bumped the package to `0.2.41`. - Verified: Ran `npm test` with 151/151 passing, `npm run typecheck`, `npm run build`, `cd website && npm run build`, `node bin/feynman.js --version`, and a fresh `FEYNMAN_HOME` package-detection smoke that reported zero missing startup packages. - Failed / learned: The package seeding bug was not just missing files; copied bundled packages were present but not counted as seeded because the check only recognized symlink targets. - Blockers: npm publish is still blocked by registry credentials returning 404 for `@companion-ai/feynman@0.2.41`; GitHub native release still needs observation. - Next: Confirm the follow-up release run publishes the GitHub native bundles, then close/comment issues #150, #151, #153 and PR #152. ### 2026-04-12 00:00 local — capital-france - Objective: Run an unattended deep-research workflow for the question "What is the capital of France?" - Changed: Created plan artifact at `outputs/.plans/capital-france.md`; scoped the workflow as a narrow fact-verification run with direct lead-agent evidence gathering instead of researcher subagents. - Verified: Read existing `CHANGELOG.md` and recalled prior saved plan memory for `capital-france` before finalizing the new run plan. - Failed / learned: None yet. - Blockers: Need at least two current independent authoritative sources and a quick ambiguity check before drafting. - Next: Collect current official/public sources, resolve any legal nuance, then draft and verify the brief. ### 2026-04-12 00:20 local — capital-france - Objective: Complete evidence gathering and ambiguity check for the capital-of-France workflow. - Changed: Wrote `notes/capital-france-research-web.md` and `notes/capital-france-legal-context.md`; identified Insee (2024) and a Sénat report as the two main corroborating sources. - Verified: Cross-read current public French sources that explicitly describe Paris as the capital/capital city of France; found no current contradiction. - Failed / learned: The Presidency homepage was useful contextual support but not explicit enough to carry the core claim alone. - Blockers: Need citation pass and final review pass before promotion. - Next: Draft the brief, then run verifier and reviewer passes. ### 2026-04-12 00:35 local — capital-france - Objective: Move from gathered evidence to a citable draft. - Changed: Wrote `outputs/.drafts/capital-france-draft.md` and updated the plan ledger to mark drafting complete. - Verified: Kept the core claim narrowly scoped to what the Insee and Sénat sources explicitly support; treated the Élysée page as contextual only. - Failed / learned: None. - Blockers: Need verifier URL/citation pass and reviewer verification pass before final promotion. - Next: Run verifier on the draft, then review and promote the final brief. ### 2026-04-12 00:50 local — capital-france - Objective: Complete citation, verification, and final promotion for the capital-of-France workflow. - Changed: Produced `outputs/capital-france-brief.md`, ran verification into `notes/capital-france-verification.md`, promoted the final brief to `outputs/capital-france.md`, and wrote `outputs/capital-france.provenance.md`. - Verified: Reviewer found no FATAL or MAJOR issues. Core claim remains backed by two independent French public-institution sources, with Insee as the primary explicit source and the Sénat report as corroboration. - Failed / learned: The runtime did not expose a named `verifier` subagent, so I used an available worker in a verifier-equivalent role and recorded that deviation in the plan. - Blockers: None. - Next: If needed, extend the brief with deeper legal-historical sourcing, but the narrow factual question is sufficiently answered. ### 2026-04-12 10:05 local — capital-france - Objective: Run the citation-verification pass on the capital-of-France draft and promote a final cited brief. - Changed: Verified the three draft source URLs were live (HTTP 200 at check time), added numbered inline citations, downgraded unsupported phrasing around the Élysée/context and broad ambiguity claims, and wrote `outputs/capital-france-brief.md`. - Verified: Confirmed Insee explicitly says Paris is the capital of France; confirmed the Sénat report describes Paris’s capital status and the presence of national institutions; confirmed the Élysée homepage is contextual only and not explicit enough to carry the core claim. - Failed / learned: The draft wording about the Presidency being seated in Paris was not directly supported by the cited homepage, so it was removed rather than carried forward. - Blockers: Reviewer pass still pending if the workflow requires an adversarial final check. - Next: If needed, run a final reviewer pass; otherwise use `outputs/capital-france-brief.md` as the canonical brief. ### 2026-04-12 10:20 local — capital-france - Objective: Close the workflow with final review, final artifact promotion, and provenance. - Changed: Ran a reviewer pass recorded in `notes/capital-france-verification.md`; promoted the cited brief into `outputs/capital-france.md`; wrote `outputs/capital-france.provenance.md`; updated the run plan to mark all tasks complete. - Verified: Reviewer verdict was PASS WITH MINOR REVISIONS only; those minor wording fixes were applied before delivery. - Failed / learned: The runtime did not expose a project-named `verifier` agent, so the citation pass used an available worker agent as a verifier-equivalent step. - Blockers: None. - Next: Optional only — produce a legal memorandum on the basis of Paris's capital status if requested. ### 2026-04-14 12:00 local — capital-belgium - Objective: Run a deep-research workflow for the question "What is the capital of Belgium?" - Changed: Created plan artifact at `outputs/.plans/capital-belgium.md`; gathered evidence into `notes/capital-belgium-research-web.md` from Belgium.be, FPS Foreign Affairs, Britannica, and a Belgian Senate constitution check. - Verified: Found two explicit current Belgian government statements that Brussels is the federal capital of Belgium, plus independent Britannica corroboration; no conflicting nuance surfaced in the consulted legal text. - Failed / learned: This is narrow enough that researcher subagents would add overhead without increasing evidence quality. - Blockers: Need draft, citation/URL verification pass, final review pass, and promotion. - Next: Draft the brief, run verifier-equivalent and reviewer passes, then promote final output with provenance. ### 2026-04-14 12:25 local — capital-belgium - Objective: Complete citation, verification, and final promotion for the capital-of-Belgium workflow. - Changed: Wrote `outputs/.drafts/capital-belgium-draft.md`; produced cited brief `outputs/capital-belgium-brief.md`; ran verification into `notes/capital-belgium-verification.md`; promoted final output to `outputs/capital-belgium.md`; wrote `outputs/capital-belgium.provenance.md`; updated the plan ledger and verification log. - Verified: Core claim is now backed by Belgium.be, Belgian Foreign Affairs, Britannica, and direct constitutional text from Senate-hosted Article 194 stating that Brussels is the capital of Belgium and the seat of the federal government. - Failed / learned: The runtime did not expose a named `verifier` subagent, so a worker performed a verifier-equivalent citation/URL check; reviewer surfaced a stronger constitutional source than the first draft had emphasized. - Blockers: None. - Next: Optional only — if requested, expand this into a legal-historical note on Brussels’s capital status and the distinction between city, region, and federal institutions. ### 2026-03-25 00:00 local — scaling-laws - Objective: Set up a deep research workflow for scaling laws. - Changed: Created plan artifact at `outputs/.plans/scaling-laws.md`; defined 4 disjoint researcher dimensions and acceptance criteria. - Verified: Read `CHANGELOG.md` and checked prior memory for related plan `scaling-laws-implications`. - Failed / learned: No prior run-specific changelog entries existed beyond the template. - Blockers: Waiting for user confirmation before launching researcher round 1. - Next: On confirmation, spawn 4 parallel researcher subagents and begin evidence collection. ### 2026-03-25 00:30 local — scaling-laws (T4 inference/time-scale pass) - Objective: Complete T4 on inference/test-time scaling and reasoning-time compute, scoped to 2023–2026. - Changed: Wrote `notes/scaling-laws-research-inference.md`; updated `outputs/.plans/scaling-laws.md` to mark T4 done and log the inference-scaling verification pass. - Verified: Cross-read 13 primary/official sources covering Tree-of-Thoughts, PRMs, repeated sampling, compute-optimal test-time scaling, provable laws, o1, DeepSeek-R1, s1, verifier failures, Anthropic extended thinking, and OpenAI reasoning API docs. - Failed / learned: OpenAI blog fetch for `learning-to-reason-with-llms` returned malformed content, so the note leans on the o1 system card and API docs instead of that blog post. - Blockers: T2 and T5 remain open before final synthesis; no single unified law for inference-time scaling emerged from public sources. - Next: Complete T5 implications synthesis, then reconcile T3/T4 with foundational T2 before drafting the cited brief. ### 2026-03-25 11:20 local — scaling-laws (T6 draft synthesis) - Objective: Synthesize the four research notes into a single user-facing draft brief for the scaling-laws workflow. - Changed: Wrote `outputs/.drafts/scaling-laws-draft.md` with an executive summary, curated reading list, qualitative meta-analysis, core-paper comparison table, explicit training-vs-inference distinction, and numbered inline citations with direct-URL sources. - Verified: Cross-checked the draft against `notes/scaling-laws-research-foundations.md`, `notes/scaling-laws-research-revisions.md`, `notes/scaling-laws-research-inference.md`, and `notes/scaling-laws-research-implications.md` to ensure the brief explicitly states the literature is too heterogeneous for a pooled effect-size estimate. - Failed / learned: The requested temp-run `context.md` and `plan.md` were absent, so the synthesis used `outputs/.plans/scaling-laws.md` plus the four note files as the working context. - Blockers: Citation/claim verification pass still pending; this draft should be treated as pre-verification. - Next: Run verifier/reviewer passes, then promote the draft into the final cited brief and provenance sidecar. ### 2026-03-25 11:28 local — scaling-laws (final brief + pdf) - Objective: Deliver a paper guide and qualitative meta-analysis on AI scaling laws. - Changed: Finalized `outputs/scaling-laws.md` and sidecar `outputs/scaling-laws.provenance.md`; rendered preview PDF at `outputs/scaling-laws.pdf`; updated plan ledger and verification log in `outputs/.plans/scaling-laws.md`. - Verified: Ran a reviewer pass recorded in `notes/scaling-laws-verification.md`; spot-checked key primary papers via alpha-backed reads for Kaplan 2020, Chinchilla 2022, and Snell 2024; confirmed PDF render output exists. - Failed / learned: A pooled statistical meta-analysis would be misleading because the literature mixes heterogeneous outcomes, scaling axes, and evaluation regimes; final deliverable uses a qualitative meta-analysis instead. - Blockers: None for this brief. - Next: If needed, extend into a narrower sub-survey (e.g. only pretraining laws, only inference-time scaling, or only post-Chinchilla data-quality revisions). ### 2026-03-25 14:52 local — skills-only-install - Objective: Let users download the Feynman research skills without installing the full terminal runtime. - Changed: Added standalone skills-only installers at `scripts/install/install-skills.sh` and `scripts/install/install-skills.ps1`; synced website-public copies; documented user-level and repo-local install flows in `README.md`, `website/src/content/docs/getting-started/installation.md`, and `website/src/pages/index.astro`. - Verified: Ran `sh -n scripts/install/install-skills.sh`; ran `node scripts/sync-website-installers.mjs`; ran `cd website && npm run build`; executed `sh scripts/install/install-skills.sh --dir ` and confirmed extracted `SKILL.md` files land in the target directory. - Failed / learned: PowerShell installer behavior was not executed locally because PowerShell is not installed in this environment. - Blockers: None for the Unix installer flow; Windows remains syntax-only by inspection. - Next: If users want this exposed more prominently, add a dedicated docs/reference page and a homepage-specific skills-only CTA instead of a text link. ### 2026-03-26 18:08 PDT — installer-release-unification - Objective: Remove the moving `edge` installer channel and unify installs on tagged releases only. - Changed: Updated `scripts/install/install.sh`, `scripts/install/install.ps1`, `scripts/install/install-skills.sh`, and `scripts/install/install-skills.ps1` so the default target is the latest tagged release, latest-version resolution uses public GitHub release pages instead of `api.github.com`, and explicit `edge` requests now fail with a removal message; removed the `release-edge` job from `.github/workflows/publish.yml`; updated `README.md` and `website/src/content/docs/getting-started/installation.md`; re-synced `website/public/install*`. - Verified: Ran `sh -n` on the Unix installer copies; confirmed `sh scripts/install/install.sh edge` and `sh scripts/install/install-skills.sh edge --dir ` fail with the intended removal message; executed `sh scripts/install/install.sh` into temp dirs and confirmed the installed binary reports `0.2.14`; executed `sh scripts/install/install-skills.sh --dir ` and confirmed extracted `SKILL.md` files; ran `cd website && npm run build`. - Failed / learned: The install failure was caused by unauthenticated GitHub API rate limiting on the `edge` path, so renaming channels without removing the API dependency would not have fixed the root cause. - Blockers: `npm run build` still emits a pre-existing duplicate-content warning for `getting-started/installation`; the build succeeds. - Next: If desired, remove the now-unused `stable` alias too and clean up the duplicate docs-content warning separately. ### 2026-03-27 11:58 PDT — release-0.2.15 - Objective: Make the non-Anthropic subagent/auth fixes and contributor-guide updates releasable to tagged-install users instead of leaving them only on `main`. - Changed: Bumped the package version from `0.2.14` to `0.2.15` in `package.json` and `package-lock.json`; updated pinned installer examples in `README.md` and `website/src/content/docs/getting-started/installation.md`; aligned the local-development docs example to the npm-based root workflow; added `CONTRIBUTING.md` plus the bundled `skills/contributing/SKILL.md`. - Verified: Confirmed the publish workflow keys off `package.json` versus the currently published npm version; confirmed local `npm test`, `npm run typecheck`, and `npm run build` pass before the release bump. - Failed / learned: The open subagent issue is fixed on `main` but still user-visible on tagged installs until a fresh release is cut. - Blockers: Need the GitHub publish workflow to finish successfully before the issue can be honestly closed as released. - Next: Push `0.2.15`, monitor the publish workflow, then update and close the relevant GitHub issue/PR once the release is live. ### 2026-03-28 15:15 PDT — pi-subagents-agent-dir-compat - Objective: Debug why tagged installs can still fail subagent/auth flows after `0.2.15` when users are not on Anthropic. - Changed: Added `scripts/lib/pi-subagents-patch.mjs` plus type declarations and wired `scripts/patch-embedded-pi.mjs` to rewrite vendored `pi-subagents` runtime files so they resolve user-scoped paths from `PI_CODING_AGENT_DIR` instead of hardcoded `~/.pi/agent`; added `tests/pi-subagents-patch.test.ts`. - Verified: Materialized `.feynman/npm`, inspected the shipped `pi-subagents@0.11.11` sources, confirmed the hardcoded `~/.pi/agent` paths in `index.ts`, `agents.ts`, `artifacts.ts`, `run-history.ts`, `skills.ts`, and `chain-clarify.ts`; ran `node scripts/patch-embedded-pi.mjs`; ran `npm test`, `npm run typecheck`, and `npm run build`. - Failed / learned: The earlier `0.2.15` fix only proved that Feynman exported `PI_CODING_AGENT_DIR` to the top-level Pi child; it did not cover vendored extension code that still hardcoded `.pi` paths internally. - Blockers: Users still need a release containing this patch before tagged installs benefit from it. - Next: Cut the next release and verify a tagged install exercises subagents without reading from `~/.pi/agent`. ### 2026-03-28 21:46 PDT — release-0.2.16 - Objective: Ship the vendored `pi-subagents` agent-dir compatibility fix to tagged installs. - Changed: Bumped the package version from `0.2.15` to `0.2.16` in `package.json` and `package-lock.json`; updated pinned installer examples in `README.md` and `website/src/content/docs/getting-started/installation.md`. - Verified: Re-ran `npm test`, `npm run typecheck`, and `npm run build`; ran `cd website && npm run build`; ran `npm pack` and confirmed the `0.2.16` tarball includes the new `scripts/lib/pi-subagents-patch.*` files. - Failed / learned: An initial local `build:native-bundle` check failed because `npm pack` and `build:native-bundle` were run in parallel, and `prepack` intentionally removes `dist/release`; rerunning `npm run build:native-bundle` sequentially succeeded. - Blockers: None in the repo; publishing still depends on the GitHub workflow running on the bumped version. - Next: Push the `0.2.16` release bump and monitor npm/GitHub release publication. ### 2026-03-31 10:45 PDT — pi-maintenance-issues-prs - Objective: Triage open Pi-related issues/PRs, fix the concrete package update regression, and refresh Pi dependencies against current upstream releases. - Changed: Pinned direct package-manager operations (`feynman update`, `feynman packages install`) to Feynman's npm prefix by exporting `FEYNMAN_NPM_PREFIX`, `NPM_CONFIG_PREFIX`, and `npm_config_prefix` before invoking Pi's `DefaultPackageManager`; bumped `@mariozechner/pi-ai` and `@mariozechner/pi-coding-agent` from `0.62.0` to `0.64.0`; adapted `src/model/registry.ts` to the new `ModelRegistry.create(...)` factory; integrated PR #15's `/feynman-model` command on top of current `main`. - Verified: Ran `npm test`, `npm run typecheck`, and `npm run build` successfully after the dependency bump and PR integration; confirmed upstream `pi-coding-agent@0.64.0` still uses `npm install -g` for user-scope package updates, so the Feynman-side prefix fix is still required. - Failed / learned: PR #14 is a stale branch with no clean merge path against current `main`; the only user-facing delta is the ValiChord prompt/skill addition, and the branch also carries unrelated release churn plus demo-style material, so it was not merged in this pass. - Blockers: None in the local repo state; remote merge/push still depends on repository credentials and branch policy. - Next: If remote write access is available, commit and push the validated maintenance changes, then close issue #22 and resolve PR #15 as merged while leaving PR #14 unmerged pending a cleaned-up, non-promotional resubmission. ### 2026-03-31 12:05 PDT — pi-backlog-cleanup-round-2 - Objective: Finish the remaining high-confidence open tracker items after the Pi 0.64.0 upgrade instead of leaving the issue list half-reconciled. - Changed: Added a Windows extension-loader patch helper so Feynman rewrites Pi extension imports to `file://` URLs on Windows before interactive startup; added `/commands`, `/tools`, and `/capabilities` discovery commands and surfaced `/hotkeys` plus `/service-tier` in help metadata; added explicit service-tier support via `feynman model tier`, `--service-tier`, status/doctor output, and a provider-payload hook that passes `service_tier` only to supported OpenAI/OpenAI Codex/Anthropic models; added Exa provider recognition to Feynman's web-search status layer and vendored `pi-web-access`. - Verified: Ran `npm test`, `npm run typecheck`, and `npm run build`; smoke-imported the modified vendored `pi-web-access` modules with `node --import tsx`. - Failed / learned: The remaining ValiChord PR is still stale and mixes a real prompt/skill update with unrelated branch churn; it is a review/triage item, not a clean merge candidate. - Blockers: No local build blockers remain; issue/PR closure still depends on the final push landing on `main`. - Next: Push the verified cleanup commit, then close issues fixed by the dependency bump plus the new discoverability/service-tier/Windows patches, and close the stale ValiChord PR explicitly instead of leaving it open indefinitely. ### 2026-04-09 09:37 PDT — windows-startup-import-specifiers - Objective: Fix Windows startup failures where `feynman` exits before the Pi child process initializes. - Changed: Converted the Node preload module paths passed via `node --import` in `src/pi/launch.ts` to `file://` specifiers using a new `toNodeImportSpecifier(...)` helper in `src/pi/runtime.ts`; expanded `scripts/patch-embedded-pi.mjs` so it also patches the bundled workspace copy of Pi's extension loader when present. - Verified: Added a regression test in `tests/pi-runtime.test.ts` covering absolute-path to `file://` conversion for preload imports; ran `npm test`, `npm run typecheck`, and `npm run build`. - Failed / learned: The raw Windows `ERR_UNSUPPORTED_ESM_URL_SCHEME` stack is more consistent with Node rejecting the child-process `--import C:\\...` preload before Pi starts than with a normal in-app extension load failure. - Blockers: Windows runtime execution was not available locally, so the fix is verified by code path inspection and automated tests rather than an actual Windows shell run. - Next: Ask the affected user to reinstall or update to the next published package once released, and confirm the Windows REPL now starts from a normal PowerShell session. ### 2026-04-09 11:02 PDT — tracker-hardening-pass - Objective: Triage the open repo backlog, land the highest-signal fixes locally, and add guardrails against stale promotional workflow content. - Changed: Hardened Windows launch paths in `bin/feynman.js`, `scripts/build-native-bundle.mjs`, and `scripts/install/install.ps1`; set npm prefix overrides earlier in `scripts/patch-embedded-pi.mjs`; added a `pi-web-access` runtime patch helper plus `FEYNMAN_WEB_SEARCH_CONFIG` env wiring so bundled web search reads the same `~/.feynman/web-search.json` that doctor/status report; taught `src/pi/web-access.ts` to honor the legacy `route` key; fixed bundled skill references and expanded the skills-only installers/docs to ship the prompt and guidance files those skills reference; added regression tests for config paths, catalog snapshot edges, skill-path packaging, `pi-web-access` patching, and blocked promotional content. - Verified: Ran `npm test`, `npm run typecheck`, and `npm run build` successfully after the full maintenance pass. - Failed / learned: The skills-only install issue was not just docs drift; the shipped `SKILL.md` files referenced prompt paths that only made sense after installation, so the repo needed both path normalization and packaging changes. - Blockers: Remote issue/PR closure and merge actions still depend on the final reviewed branch state being pushed. - Next: Push the validated fixes, close the duplicate Windows/reporting issues they supersede, reject the promotional ValiChord PR explicitly, and then review whether the remaining docs-only or feature PRs should be merged separately. ### 2026-04-09 10:28 PDT — verification-and-security-pass - Objective: Run a deeper install/security verification pass against the post-cleanup `0.2.17` tree instead of assuming the earlier targeted fixes covered the shipped artifacts. - Changed: Reworked `extensions/research-tools/header.ts` to use `@mariozechner/pi-tui` width-aware helpers for truncation/wrapping so wide Unicode text does not overflow custom header rows; changed `src/pi/launch.ts` to stop mirroring child crash signals back onto the parent process and instead emit a conventional exit code; added `FEYNMAN_INSTALL_SKILLS_ARCHIVE_URL` overrides to the skills installers for pre-release smoke testing; aligned root and website dependency trees with patched transitive versions using npm `overrides`; fixed `src/pi/web-access.ts` so `search status` respects `FEYNMAN_HOME` semantics instead of hardcoding the current shell home directory; added `tests/pi-launch.test.ts`. - Verified: Ran `npm test`, `npm run typecheck`, `npm run build`, `cd website && npm run build`, `npm run build:native-bundle`; smoke-tested `scripts/install/install.sh` against a locally served `dist/release/feynman-0.2.17-darwin-arm64.tar.gz`; smoke-tested `scripts/install/install-skills.sh` against a local source archive; confirmed installed `feynman --version`, `feynman --help`, `feynman doctor`, and packaged `feynman search status` work from the installed bundle; `npm audit --omit=dev` is clean in the root app and website after overrides. - Failed / learned: The first packaged `search status` smoke test still showed the user home path because the native bundle had been built before the `FEYNMAN_HOME` path fix; rebuilding the native bundle resolved that mismatch. - Blockers: PowerShell runtime was unavailable locally, so Windows installer execution remained code-path validated rather than actually executed. - Next: Push the second-pass hardening commit, then keep issue `#46` and issue `#47` open until users on the affected Linux/CJK environments confirm whether the launcher/header fixes fully resolve them. ### 2026-04-09 10:36 PDT — remaining-tracker-triage-pass - Objective: Reduce the remaining open tracker items by landing the lowest-risk missing docs/catalog updates and a targeted Cloud Code Assist compatibility patch instead of only hand-triaging them. - Changed: Added MiniMax M2.7 recommendation preferences in `src/model/catalog.ts`; documented model switching, authenticated-provider visibility, and `/feynman-model` subagent overrides in `website/src/content/docs/getting-started/configuration.md` and `website/src/content/docs/reference/slash-commands.md`; added a runtime patch helper in `scripts/lib/pi-google-legacy-schema-patch.mjs` and wired `scripts/patch-embedded-pi.mjs` to normalize JSON Schema `const` into `enum` for the legacy `parameters` field used by Cloud Code Assist Claude models. - Verified: Ran `npm test`, `npm run typecheck`, `npm run build`, and `cd website && npm run build` after the patch/helper/docs changes. - Failed / learned: The MiniMax provider catalog in Pi already uses canonical IDs like `MiniMax-M2.7`, so the only failure during validation was a test assertion using the wrong casing rather than a runtime bug. - Blockers: The Cloud Code Assist fix is validated by targeted patch tests and code-path review rather than an end-to-end Google account repro in this environment. - Next: Push the tracker-triage commit, close the docs/MiniMax PRs as superseded by main, close the support-style model issues against the new docs, and decide whether the remaining feature requests should be left open or closed as not planned/upstream-dependent. ### 2026-04-10 10:22 PDT — web-access-stale-override-fix - Objective: Fix the new `ctx.modelRegistry.getApiKeyAndHeaders is not a function` / stale `search-filter.js` report without reintroducing broad vendor drift. - Changed: Removed the stale `.feynman/vendor-overrides/pi-web-access/*` files and removed `syncVendorOverride` from `scripts/patch-embedded-pi.mjs`; kept the targeted `pi-web-access` runtime config-path patch; added `feynman search set [api-key]` and `feynman search clear` commands with a shared save path in `src/pi/web-access.ts`. - Verified: Ran `npm test`, `npm run typecheck`, `npm run build`; ran `node scripts/patch-embedded-pi.mjs`, confirmed the installed `pi-web-access/index.ts` has no `search-filter` / condense helper references, and smoke-imported `./.feynman/npm/node_modules/pi-web-access/index.ts`; ran `npm pack --dry-run` and confirmed stale `vendor-overrides` files are no longer in the package tarball. - Failed / learned: The public Linux installer Docker test was attempted but Docker Desktop became unresponsive even for simple `docker run node:22-bookworm node -v` commands; the earlier Linux npm-artifact container smoke remains valid, but this specific public-installer run is blocked by the local Docker daemon. - Blockers: Issue `#54` is too underspecified to fix directly without logs; public Linux installer behavior still needs a stable Docker daemon or a real Linux shell to reproduce the user's exact npm errors. - Next: Push the stale-override fix, close PR `#52` and PR `#53` as superseded/merged-by-main once pushed, and ask for logs on issue `#54` instead of guessing. ### 2026-04-10 10:49 PDT — rpc-and-website-verification-pass - Objective: Exercise the Feynman wrapper's RPC mode and the website quality gates that were not fully covered by the prior passes. - Changed: Added `--mode ` pass-through support in the Feynman wrapper and skipped terminal clearing in RPC mode; added `@astrojs/check` to the website dev dependencies, fixed React Refresh lint violations in the generated UI components by exporting only components, and added safe website dependency overrides for dev-audit findings. - Verified: Ran a JSONL RPC smoke test through `node bin/feynman.js --mode rpc` with `get_state`; ran `npm test`, `npm run typecheck`, `npm run build`, `cd website && npm run lint`, `cd website && npm run typecheck`, `cd website && npm run build`, full root `npm audit`, full website `npm audit`, and `npm run build:native-bundle`. - Failed / learned: Website typecheck was previously a no-op prompt because `@astrojs/check` was missing; installing it exposed dev-audit findings that needed explicit overrides before the full website audit was clean. - Blockers: Docker Desktop remained unreliable after restart attempts, so this pass still does not include a second successful public-installer Linux Docker run. - Next: Push the RPC/website verification commit and keep future Docker/public-installer validation separate from repo correctness unless Docker is stable. ### 2026-04-12 09:32 PDT — pi-0.66.1-upgrade-pass - Objective: Update Feynman from Pi `0.64.0` to the current `0.66.1` packages and absorb any downstream SDK/runtime compatibility changes instead of leaving the repo pinned behind upstream. - Changed: Bumped `@mariozechner/pi-ai` and `@mariozechner/pi-coding-agent` to `0.66.1` plus `@companion-ai/alpha-hub` to `0.1.3` in `package.json` and `package-lock.json`; updated `extensions/research-tools.ts` to stop listening for the removed `session_switch` extension event and rely on `session_start`, which now carries startup/reload/new/resume/fork reasons in Pi `0.66.x`. - Verified: Ran `npm test`, `npm run typecheck`, and `npm run build` successfully after the upgrade; smoke-ran `node bin/feynman.js --version`, `node bin/feynman.js doctor`, and `node bin/feynman.js status` successfully; checked upstream package diffs and confirmed the breaking change that affected this repo was the typed extension lifecycle change in `pi-coding-agent`, while `pi-ai` mainly brought refreshed provider/model catalog code including Bedrock/OpenAI provider updates and new generated model entries. - Failed / learned: `ctx7` resolved Pi correctly to `/badlogic/pi-mono`, but its docs snapshot was not release-note oriented; the concrete downstream-impact analysis came from the actual `0.64.0` → `0.66.1` package diffs and local validation, not from prose docs alone. - Failed / learned: The first post-upgrade CLI smoke test failed before Feynman startup because `@companion-ai/alpha-hub@0.1.2` shipped a zero-byte `src/lib/auth.js`; bumping to `0.1.3` fixed that adjacent runtime blocker. - Blockers: `npm install` reports two high-severity vulnerabilities remain in the dependency tree; this pass focused on the Pi upgrade and did not remediate unrelated audit findings. - Next: Push the Pi upgrade, then decide whether to layer the pending model-command fixes on top of this branch or land them separately to keep the dependency bump easy to review. ### 2026-04-12 13:00 PDT — model-command-and-bedrock-fix-pass - Objective: Finish the remaining user-facing model-management regressions instead of stopping at the Pi dependency bump. - Changed: Updated `src/model/commands.ts` so `feynman model login ` resolves both OAuth and API-key providers; `feynman model logout ` clears either auth mode; `feynman model set` accepts both `provider/model` and `provider:model`; ambiguous bare model IDs now prefer explicitly configured providers from auth storage; added an `amazon-bedrock` setup path that validates the AWS credential chain with the AWS SDK and stores Pi's `` sentinel so Bedrock models appear in `model list`; synced `src/cli.ts`, `metadata/commands.mjs`, `README.md`, and the website docs to the new behavior. - Verified: Added regression tests in `tests/model-harness.test.ts` for `provider:model`, API-key provider resolution, and ambiguous bare-ID handling; ran `npm test`, `npm run typecheck`, `npm run build`, and `cd website && npm run build`; exercised command-level flows against throwaway `FEYNMAN_HOME` directories: interactive `node bin/feynman.js model login google`, `node bin/feynman.js model set google:gemini-3-pro-preview`, `node bin/feynman.js model set gpt-5.4` with only OpenAI configured, and `node bin/feynman.js model login amazon-bedrock`; confirmed `model list` shows Bedrock models after the new setup path; ran a live one-shot prompt `node bin/feynman.js --prompt "Reply with exactly OK"` and got `OK`. - Failed / learned: The website build still emits duplicate-id warnings for a handful of docs pages, but it completes successfully; those warnings predate this pass and were not introduced by the model-command edits. - Blockers: The Bedrock path is verified with the current shell's AWS credential chain, not with a fresh machine lacking AWS config; broader upstream Pi behavior around IMDS/default-profile autodiscovery without the sentinel is still outside this repo. - Next: Commit and push the combined Pi/model/docs maintenance branch, then decide whether to tackle the deeper search/deepresearch hang issues separately or leave them for focused repro work. ### 2026-04-12 13:35 PDT — workflow-unattended-and-search-curator-fix-pass - Objective: Fix the remaining workflow deadlocks instead of leaving `deepresearch` and terminal web search half-functional after the maintenance push. - Changed: Updated the built-in research workflow prompts (`deepresearch`, `lit`, `review`, `audit`, `compare`, `draft`, `watch`) so they present the plan and continue automatically rather than blocking for approval; extended the `pi-web-access` runtime patch so Feynman rewrites its default workflow from browser-based `summary-review` to `none`; added explicit `workflow: "none"` persistence in `src/search/commands.ts` and `src/pi/web-access.ts`, plus surfaced the workflow in doctor/status-style output. - Verified: Reproduced the original `deepresearch` failure mode in print mode, where the run created `outputs/.plans/capital-france.md` and then stopped waiting for user confirmation; after the prompt changes, reran `deepresearch "What is the capital of France?"` and confirmed it progressed beyond planning and produced `outputs/.drafts/capital-france-draft.md`; inspected `pi-web-access@0.10.6` and confirmed the exact `waiting for summary approval...` string and `summary-review` default live in that package; added regression tests for the new `pi-web-access` patch and workflow-none status handling; reran `npm test`, `npm run typecheck`, and `npm run build`; smoke-tested `feynman search set exa exa_test_key` under a throwaway `FEYNMAN_HOME` and confirmed it writes `"workflow": "none"` to `web-search.json`. - Failed / learned: The long-running deepresearch session still spends substantial time in later reasoning/writing steps for even a narrow query, but the plan-confirmation deadlock itself is resolved; the remaining slowness is model/workflow behavior, not the original stop-after-plan bug. - Blockers: I did not install and execute the full optional `pi-session-search` package locally, so the terminal `summary approval` fix is validated by source inspection plus the Feynman patch path and config persistence rather than a local end-to-end package install. - Next: Commit and push the workflow/search fix pass, then close or answer the remaining deepresearch/search issues with the specific root causes and shipped fixes. ### 2026-04-12 14:05 PDT — final-artifact-hardening-pass - Objective: Reduce the chance of unattended research workflows stopping at intermediate artifacts like `-brief.md` without promoting the final deliverable and provenance sidecar. - Changed: Tightened `prompts/deepresearch.md` so the agent must verify on disk that the plan, draft, cited brief, promoted final output, and provenance sidecar all exist before stopping; tightened `prompts/lit.md` so it explicitly checks for the final output plus provenance sidecar instead of stopping at an intermediate cited draft. - Verified: Cross-read the current deepresearch/lit deliver steps after the earlier unattended-run reproductions and confirmed the missing enforcement point was the final on-disk artifact check, not the naming convention itself. - Failed / learned: This is still prompt-level enforcement rather than a deterministic post-processing hook, so it improves completion reliability but does not provide the same guarantees as a dedicated artifact-finalization wrapper. - Blockers: I did not rerun a full broad deepresearch workflow end-to-end after this prompt-only hardening because those runs are materially longer and more expensive than the narrow reproductions already used to isolate the earlier deadlocks. - Next: Commit and push the prompt hardening, then, if needed, add a deterministic wrapper around final artifact promotion instead of relying only on prompt adherence. ### 2026-04-14 09:30 PDT — wsl-login-and-uninstall-docs-pass - Objective: Fix the remaining WSL setup blocker and close the last actionable support issue instead of leaving the tracker open after the earlier workflow/model fixes. - Changed: Added a dedicated alpha-hub auth patch helper and tests; extended the alphaXiv login patch so WSL uses `wslview` when available and falls back to `cmd.exe /c start`, while also printing the auth URL explicitly for manual copy/paste if browser launch still fails; documented standalone uninstall steps in `README.md` and `website/src/content/docs/getting-started/installation.md`. - Verified: Added regression tests for the alpha-hub auth patch, reran `npm test`, `npm run typecheck`, and `npm run build`, and smoke-checked the patched alpha-hub source rewrite to confirm it injects both the WSL browser path and the explicit auth URL logging. - Failed / learned: This repo can patch alpha-hub's login UX reliably, but it still does not ship a destructive `feynman uninstall` command; the practical fix for the support issue is documented uninstall steps rather than a rushed cross-platform remover. - Blockers: I did not run a true WSL shell here, so the WSL fix is validated by the deterministic source patch plus tests rather than an actual Windows-hosted browser-launch repro. - Next: Push the WSL/login pass and close the stale issues and PRs that are already superseded by `main`. ### 2026-04-14 09:35 PDT — review-findings-and-audit-cleanup - Objective: Fix the remaining concrete issues found in the deeper review pass instead of stopping at tracker cleanup. - Changed: Updated the `pi-web-access` patch so Feynman defaults search workflow to `none` without disabling explicit `summary-review`; softened the research workflow prompts so only unattended/one-shot runs auto-continue while interactive users still get a chance to request plan changes; corrected uninstall docs to mention `~/.ahub` alongside `~/.feynman`; bumped the root `basic-ftp` override from `5.2.1` to `5.2.2`. - Verified: Ran `npm test`, `npm run typecheck`, `npm run build`, `cd website && npm run build`, and `npm audit`; root audit is now clean. - Failed / learned: Astro still emits a duplicate-content-id warning for `website/src/content/docs/getting-started/installation.md`, but the website build succeeds and I did not identify a low-risk repo-side fix for that warning in this pass. - Blockers: The duplicate-id warning remains as a build warning only, not a failing correctness gate. - Next: If desired, isolate the Astro duplicate-id warning separately with a minimal reproduction rather than mixing it into runtime/CLI maintenance. ### 2026-04-14 10:55 PDT — summarize-workflow-restore - Objective: Restore the useful summarization workflow that had been closed in PR `#69` without being merged. - Changed: Added `prompts/summarize.md` as a top-level CLI workflow so `feynman summarize ` is available again; kept the RLM-based tiering approach from the original proposal and aligned Tier 3 confirmation behavior with the repo's unattended-run conventions. - Verified: Confirmed `feynman summarize ` appears in CLI help; ran `node bin/feynman.js summarize /tmp/feynman-summary-smoke.txt` against a local smoke file and verified it produced `outputs/feynman-summary-smoke-summary.md` plus the raw fetched note artifact under `outputs/.notes/`. - Failed / learned: None in the restored Tier 1 path; broader Tier 2/Tier 3 behavior still depends on runtime/model/tool availability, just like the other prompt-driven workflows. - Blockers: None for the prompt restoration itself. - Next: If desired, add dedicated docs for `summarize` and decide whether to reopen PR `#69` for historical continuity or leave it closed as superseded by the landed equivalent on `main`. ### 2026-05-11 09:17 PDT — issue-162-163-runtime-followup - Objective: Fix the current actionable GitHub reports after the org migration and keep issue checking on a daily repair loop. - Changed: Updated the `check-new-issues` heartbeat to run daily and attempt actionable fixes; added a final alphaXiv REST fast-search fallback after the removed MCP search tools and `discover_papers`; aliased `@earendil-works/*` Pi runtime imports to the same initialized bundled runtime as `@mariozechner/*`; wired that loader patch into the vendored runtime archive path; bumped Feynman to `v0.2.53`. - Verified: Focused alpha-hub and Pi extension-loader regression tests passed locally; full `npm test`, `npm run typecheck`, root `npm run build`, `node scripts/prepare-runtime-workspace.mjs`, package dry-run, and website build with Node 24 passed; the packaged runtime archive contains the alphaXiv REST fallback and dual namespace loader aliases; GitHub release `v0.2.53` built all native assets. - Failed / learned: The previous `v0.2.52` search patch was too narrow because it assumed `discover_papers` was always present when the older search tools disappeared. The first `v0.2.53` publish workflow failed at npm publish with `ENEEDAUTH` after the org move, while GitHub native release assets succeeded. - Blockers: npm `latest` remains `0.2.52` until the npm trusted publisher is updated for `companion-inc/feynman` or an `NPM_TOKEN` secret is provided. - Next: Re-run the publish workflow after npm auth is fixed, then report release evidence on issues `#162` and `#163`. ### 2026-05-11 09:50 PDT — packed-install-e2e - Objective: Run a true packed-install E2E for the latest Feynman runtime fixes. - Changed: Fixed packed npm installs that hoist dependencies outside Feynman's package root by falling back to the vendored `.feynman/npm` Pi runtime; patched both package-local and vendored runtime node_modules; bumped Feynman to `v0.2.54`. - Verified: Focused runtime tests, full `npm test`, `npm run typecheck`, root build, runtime workspace prep, packed tarball install into a clean temp prefix/home, `feynman doctor`, prompt launch past Pi resolution, issue-specific installed runtime patch inspection, `node bin/feynman.js --version`, diff whitespace check, and website build with Node 24 passed. - Failed / learned: The first packed-install E2E showed `feynman --mode json --prompt ...` failed before Pi launch with `Pi CLI not found` because runtime resolution only checked package-local `node_modules`. - Blockers: npm publishing is still externally blocked until npm trusted publishing or `NPM_TOKEN` is updated for `companion-inc/feynman`. - Next: Push `v0.2.54`, watch release CI, and rerun npm publish after npm trust/secret access is fixed. ### 2026-04-12 13:20 PDT — capital-france (citation verification brief) - Objective: Verify citations in the capital-of-France draft and produce a cited verifier brief. - Changed: Read `outputs/.drafts/capital-france-draft.md`, `notes/capital-france-research-web.md`, and `notes/capital-france-legal-context.md`; fetched the three draft URLs directly; wrote `notes/capital-france-brief.md` with inline numbered citations and a numbered direct-URL sources list. - Verified: Confirmed the Insee, Sénat, and Élysée URLs were reachable on 2026-04-12; confirmed Insee and Sénat support the core claim that Paris is the capital of France; marked the Élysée homepage as contextual-only support. - Failed / learned: The Élysée homepage does not explicitly state the core claim, so it should not be used as sole evidence for capital status. - Blockers: None for the verifier brief; any stronger legal memo would still need a more direct constitutional/statutory basis if that specific question is asked. - Next: Promote the brief into the final output or downgrade/remove any claim that leans on the Élysée URL alone. ### 2026-04-20 17:25 PDT — gemini-browser-fallback-opt-in - Objective: Stop `/deepresearch` web search from reaching Chromium cookie access by default after users reported macOS Keychain prompts from Gemini Web fallback. - Changed: Updated the `pi-web-access` runtime patch so `isGeminiWebAvailable` returns unavailable unless `web-search.json` explicitly sets `geminiBrowser`/`allowBrowserAuth`/`browserAuth` true; changed search status output and docs to report Gemini browser fallback as disabled by default; made `feynman search set` and `feynman search clear` write `geminiBrowser: false`; corrected web-search docs to recommend Exa, Perplexity, or Gemini API keys for `/deepresearch`. - Verified: Added regression coverage for the browser fallback opt-in patch and status output; ran focused web-access/search-command tests, full `npm test`, `npm run typecheck`, root `npm run build`, and website `npm run build`. - Failed / learned: Website build still emits duplicate-content-id warnings for docs pages, but it completes; this pass did not address the pre-existing Astro warning. - Blockers: Did not run a live `/deepresearch` smoke test because the risk being fixed is source-level keychain probing, which is covered by the deterministic `pi-web-access` patch tests. - Next: Release the runtime patch and answer the security concern by explaining that browser-cookie access is now explicit opt-in rather than the default fallback. ### 2026-05-03 21:19 PDT — github-issues-e2e - Objective: Read all currently open GitHub issues, separate concrete regressions from feature-scale requests, and finish the scoped fixes with source, CLI, installer, runtime, and RPC verification. - Changed: Added a reusable `pi-tui` patch that truncates overwide rendered lines with `sliceByColumn` instead of crashing; wired that patch into startup node_modules patching and vendored runtime preparation; added explicit OpenCode skills installer support for `.opencode/skills/feynman` on Unix and PowerShell; synced README, website docs, and public website installer copies; wrote `outputs/.plans/github-issues-e2e.md` as the run ledger. - Verified: Checked current Pi and OpenCode docs through Context7; confirmed latest upstream `pi-tui` still has the terminal-width throw so upgrading alone would not fix `#148`; ran focused patch/installer tests, full `npm test` (146 tests), `npm run typecheck`, root `npm run build`, and website `npm run build`; ran `node scripts/prepare-runtime-workspace.mjs` and extracted `.feynman/runtime-workspace.tgz` to verify the packaged `pi-tui` patch and `pruneVersion: 5`; smoke-tested `feynman --help`, `feynman search status`, and `--mode rpc` with a temp custom model plus JSONL `get_state`. - Failed / learned: A direct CLI smoke with `/usr/local/bin/node` failed because that shell resolves Node `20.17.0`, below Feynman's `>=20.19.0` floor; rerunning with the bundled supported Node `24.14.0` passed. The first RPC smoke from the repo cwd loaded project-local optional packages and hit the existing `pi-web-access` source parse issue, so the accepted RPC smoke used an isolated `--cwd` and temp settings to test the RPC protocol itself. - Blockers: Issues `#135`-`#139` are larger provider/runtime backend feature proposals, not safe one-pass bug fixes; they were read and classified but not implemented here. - Next: Close or respond to `#148` and `#143` with the shipped fixes and test evidence, then decide separately whether the provider/runtime proposals belong in a roadmap issue or implementation specs. ### 2026-05-03 23:40 PDT — pi-upstream-alignment - Objective: Keep Feynman as a thin wrapper over upstream Pi runtime behavior while preserving the curated package stack and Feynman research/theme surface. - Changed: Upgraded direct Pi packages to `@mariozechner/pi-ai@0.72.1` and `@mariozechner/pi-coding-agent@0.72.1`; restored the curated core package stack with `@devkade/pi-opentelemetry`; extended `pi-web-access` patches for current upstream `gemini-web-config.ts` and older `gemini-web.ts`; wired `pi-web-access` and `pi-tui` patches into the vendored runtime archive path; bumped runtime archive `pruneVersion` to `6`; documented the run in `outputs/.plans/pi-upstream-alignment.md`. - Verified: Ran Context7 against current Pi docs; ran `npm test` (147 tests), `npm run typecheck`, root `npm run build`, and website `npm run build`; rebuilt `.feynman/runtime-workspace.tgz` with bundled Node `24.14.0`; extracted the archive and verified the packaged `pi-tui`, `pi-web-access`, and manifest patches; ran live one-shot prompts via stored Anthropic OAuth and received `OK` and `42`; reran `feynman model list` and confirmed Anthropic models; ran isolated RPC `get_state` successfully with a temp custom model; ran `feynman search status` and confirmed Gemini browser fallback remains disabled. - Failed / learned: The packaging script initially omitted the `pi-web-access` patch path, so the local installed package was fixed but the release archive was not; wiring the patch into `prepare-runtime-workspace.mjs` fixed the packaged path. No env API keys were present for OpenAI, Anthropic, Gemini, Google, Exa, Perplexity, Mistral, or OpenRouter, so live non-Anthropic provider/API-search checks remain blocked. - Blockers: Live web search through Exa/Perplexity/Gemini API could not be tested without keys; browser-cookie Gemini fallback is intentionally disabled by default. `/usr/local/bin/node` remains below Feynman's Node floor, so supported runtime smokes used the bundled Node. - Next: Review/stage the intended subset, then split unrelated pre-existing local changes if needed before commit/release. ### 2026-05-04 01:45 PDT — pi-thin-wrapper-live-e2e - Objective: Finish the Pi-thin-wrapper cleanup with local credentials, live providers, RPC, and packaged runtime verification instead of relying only on unit tests. - Changed: Removed the Feynman-only Anthropic model overlay so `createModelRegistry` now trusts upstream Pi's model catalog; moved the `pi-web-access` `/search` to `/web-results` rename into the shared patch path so local and archived runtimes match; removed the stale Google legacy schema patch that no longer matches `@mariozechner/pi-ai@0.72.1`. - Verified: Used local credentials without printing secret values; live Feynman one-shots passed for Anthropic OAuth, Anthropic API key, OpenAI API key, Gemini API key, and OpenRouter API key; direct `pi-web-access` smokes passed for Exa no-key MCP fallback and Gemini API search; Perplexity correctly reported unavailable because no key was found; final RPC `get_state` and `get_available_models` passed through `feynman --mode rpc`; rebuilt and extracted `.feynman/runtime-workspace.tgz` and verified packaged `web-results`, `FEYNMAN_WEB_SEARCH_CONFIG`, Gemini browser opt-in aliases, escaped Gemini messaging, `pi-tui` truncation, `pruneVersion: 6`, Pi `0.72.1`, and `@devkade/pi-opentelemetry`; ran full `npm test` (144 tests), `npm run typecheck`, root `npm run build`, and website `npm run build` with the bundled Node `24.14.0`. - Failed / learned: OpenCode OAuth stores for Anthropic, Google, and OpenAI were expired, while usable API keys existed in project env files; the first OpenAI final sentinel used hyphens while also asking for no punctuation, so the model removed the hyphens and the smoke was rerun with `OAIFINALOK`; Perplexity remains blocked by no local key. - Blockers: No Perplexity live API check until a real `PERPLEXITY_API_KEY` is provided; `/usr/local/bin/node` is still `20.17.0`, below Feynman's runtime floor. - Next: Stage the intended repo changes, keep the Feynman theme/package stack, and avoid adding provider aliases or runtime patches unless they are backed by upstream gaps plus packaged-runtime tests. ### 2026-05-04 19:46 PDT — telemetry-noise-removal - Objective: Remove the default OpenTelemetry package from Feynman so local and public TUI sessions do not show telemetry status noise or invite end-user telemetry setup by default. - Changed: Removed `@devkade/pi-opentelemetry` from the bundled package stack and user-facing docs; removed default OTEL service env injection; kept a legacy settings prune path so existing default installs that only gained telemetry from the curated stack are normalized back to the current core package list; added startup pruning for stale bundled-package symlinks so upgrades remove the old `@opentelemetry` links from Feynman's managed npm prefix. - Changed: Reviewed open GitHub issues and PRs, folded in the useful parts of PRs `#133`, `#144`, and `#149`, and left PR `#141` unmerged because the local `geminiBrowser` opt-in path is stricter and already patched into the vendored runtime. - Verified: Ran `npm test` (150 tests), `npm run typecheck`, root `npm run build`, and website `npm run build`; repacked and globally installed `@companion-ai/feynman@0.2.40`; confirmed the packaged tarball and active settings contain no telemetry package; confirmed the installed startup path removes leftover `@opentelemetry` symlinks; ran a live one-shot through the installed CLI, RPC `get_state`/`get_available_models`, direct Gemini API web search, and an actual TUI launch with no `otel active` footer. - Failed / learned: Historical changelog entries still mention earlier telemetry verification because those entries describe past runs; the first stale-link check ran before `feynman status` had finished, so it still saw old links until the newly installed startup pruning executed. - Blockers: None for source removal. - Next: Commit and push the validated cleanup. ### 2026-05-05 22:17 PDT — rpc-package-sync-fix - Objective: Re-test the shipped issue fixes through the real installed/RPC path after discovering `v0.2.41` had not been exercised deeply enough. - Changed: Added an embedded Pi package-manager patch so runtime npm installs include `--legacy-peer-deps`; wired it into packaged runtime preparation; bumped Feynman to `v0.2.42`; documented the release. - Verified: Reproduced the `v0.2.41` RPC startup failure in the real release binary from the repo cwd: Pi attempted project package sync for `@aliou/pi-processes` and failed on peer dependency resolution before RPC could complete. After the patch, local `0.2.42` RPC accepted a JSONL `prompt`, streamed `Feynman RPC OK`, emitted `turn_end`, and emitted `agent_end`. - Failed / learned: Running `feynman --mode rpc "prompt"` is not a valid deep RPC smoke; the actual protocol requires JSON-line commands on stdin and keeping stdin open. - Blockers: Need push `v0.2.42`, wait for native release assets, then re-run the same RPC smoke against the released native asset before closing this loop. - Next: Commit, push, verify CI/native release, and test the released `v0.2.42` asset end to end. ### 2026-05-09 18:38 PDT — issue-158-160-runtime-sweep - Objective: Address the current open tracker items rather than only the already-shipped package-peer fix. - Changed: Added top-of-prompt tool discipline to every workflow; extended the Pi agent-core runtime patch to normalize common hallucinated tool aliases (`search_web` to `web_search`, bare `fetch` / `WebFetch` / `read_url_content` to `fetch_content`); patched bundled alpha-hub search to fall back to `discover_papers` when alphaXiv removes older search tool names; seeded bundled runtime packages before package updates; included `typebox` plus both legacy `@mariozechner/*` and current `@earendil-works/*` Pi runtime peers; applied the Windows docker-probe fix from PR `#157`; bumped to `v0.2.52`. - Verified: `npm test`, `npm run typecheck`, `npm run build`, root and website production `npm audit`, website typecheck/build, `feynman doctor`, `feynman update`, `npm pack --dry-run`, and runtime archive extraction all passed. The installed Feynman prefix now has bundled links for `typebox` and `@earendil-works/pi-coding-agent`. - Failed / learned: The public alphaXiv MCP docs still list the older search tools, but issue `#159` reports a live authenticated tools/list response with only `discover_papers`; the fix therefore keeps old-tool calls first and only falls back on specific `Tool ... not found` failures. The comment on issue `#160` cited old `pi-btw` / `pi-markdown-preview` versions, but the current npm tarballs are the ones importing `@earendil-works/*`, so the repair path covers both namespaces. - Blockers: Push/release and GitHub issue/PR comments are still pending in this run. - Next: Commit, push `v0.2.52`, wait for the publish workflow, then close/comment the resolved tracker items with exact release evidence. ### 2026-06-08 22:20 PDT — issue-update-sweep - Objective: Bring Feynman up to date, fold in actionable current GitHub issue/PR fixes, and set up a once-daily repo sweep. - Changed: Updated root and website dependencies/overrides to current safe in-range versions; made launch-time runtime patching cover package-local and vendored alpha-hub, pi-web-access, pi-subagents, and Pi package-manager modules; added current `pi-subagents@0.28.0` `src/...` patch targets; made normal interactive `feynman` launches pass Pi `--continue` while `--new-session`, RPC/JSON, and prompt/workflow launches stay fresh; switched Windows URL opening to `explorer`; made package installs prefer adjacent `npm-cli.js` on Windows; added MiniMax-M3 to research model preferences; updated regression coverage. - Verified: `npm install` in root and `website/` reported zero vulnerabilities; `npm test` passed 177 tests; `npm run typecheck`, root `npm run build`, root and website `npm audit --omit=dev`, website `npm run typecheck`, website `npm run build`, and `npm pack --dry-run` all passed. `npm pack --dry-run` rebuilt and included `.feynman/runtime-workspace.tgz`. - Failed / learned: GitHub issue `#171` has only a title and no reproduction/body, so it remains evidence-blocked rather than patched speculatively. `npm outdated` still reports only major-version jumps outside declared ranges: root `@types/node@25`, and website ESLint/Globals/TypeScript majors. - Next: Review/stage the intended changes, decide whether to release/comment on issues `#167`-`#173`, and handle `#171` only after a reproducible ByteString source is available. ### 2026-06-08 23:50 PDT — opencode-pi-hermes-sweep - Objective: Re-check the broader OpenCode, OpenClaw, Pi, and Hermes references before calling the repo current. - Changed: Promoted OpenCode Zen and OpenCode Go to first-class Feynman model recommendations and provider ordering; centralized settings/model recommendation selection; migrated direct Pi imports and dependencies to `@earendil-works/*@0.74.2`; kept legacy `@mariozechner/*` compatibility through runtime aliases; updated runtime path resolution, patching, embedded patching, pruning, and runtime workspace preparation for both package scopes; updated regression coverage. - Verified: Official OpenCode docs, Context7 docs lookup, local OpenClaw provider/Hermes migration docs, Pi package docs/registry, npm dist-tags, local Hermes status, live GitHub issues `#167`-`#172`, PRs `#173`-`#175`, and latest `main` GitHub Actions status were checked. Focused model/runtime tests passed 72 tests; full `npm test` passed 184 tests; root typecheck/build/audit, website lint/typecheck/build/audit, `npm pack --dry-run`, runtime archive inspection, `node bin/feynman.js --version`, `doctor`, `search status`, `packages list`, `update`, native bundle build, and extracted native launcher `--version`/`--help` all passed. Direct live/tool smokes passed for patched alphaXiv search and parallel `web_search` with `includeContent: true`. - Failed / learned: The first runtime archive manifest inspection used the wrong path and was rerun successfully against `npm/.runtime-manifest.json`. Latest Pi `0.79.0` requires Node `>=22.19.0`, so Feynman remains on the `legacy-node20` dist-tag while it declares Node `>=20.19.0 <25`. - Next: Decide separately whether to raise Feynman's Node floor and move Pi to the latest `0.79.x` line; otherwise stage/release the Node 20-compatible sweep and close/comment the covered tracker items with the validation evidence. ### 2026-06-11 — open-issue fix sweep and v0.2.59 prep - Objective: Fix all open GitHub issues (#167-#172, #177), test, and release. - Changed: Patched alpha-hub's `parsePaperSearchResults` to handle the structured JSON payloads alphaXiv search tools now return (#167 — the MCP tools work; the old numbered-text parser silently dropped every result). Closed three web_search hang holes (#169): cancel-then-assign on the shared `pendingCurate` slot so a clobbered parallel curate session resolves instead of leaking (pi-agent-core's Promise.all otherwise withholds every toolResult in the batch), a 90s deadline around each search() call in both execute loops, and a 2-minute browser-connect deadline in the curator watchdog (previously `if (!browserConnected) return` skipped never-connected sessions forever). Made `scripts/check-node-version.mjs` warn-and-continue on too-new Node so npm upgrades stop rolling back and pinning users to old releases (#177); the bin/feynman.js runtime gate still blocks with instructions. Added `src/system/self-update.ts` + a `feynman update` notice when a newer CLI release exists on the registry, with install-type-specific upgrade command. Staged the prior uncommitted sweep (earendil scope migration, pi-subagents src/ patch targets for #172, Windows npm-cli.js spawn for #170, `--continue` resume for #168). - Verified: 192 tests pass, typecheck, build. Live smokes: all five alpha_search modes return 10 results through the patched parser and end-to-end through the model (RESULT_COUNT=10); two parallel web_search toolCalls with includeContent:true returned toolResults and the turn completed; `feynman update`, `doctor`, `--version` clean; patches apply idempotently to the installed workspace sources and parse as TS. - Failed / learned: Issue #171 (ByteString 20320 on Chinese Windows) is still evidence-blocked — title-only issue, no stack trace; no header construction in Feynman/alpha-hub/pi-web-access uses OS-identity or user strings, so the throw site is unknown. Asked the reporter for the full trace rather than patching speculatively. - Next: Push, watch publish workflow for v0.2.59, then comment on the fixed issues with release evidence. ### 2026-06-11 (later) — Node 25, #171 root cause, multi-OS e2e - Objective: Finish the "fix everything, test everything end to end" pass — verify the Windows fixes on real Windows machines, support Node 25, and root-cause #171. - Changed: Raised MAX_NODE_MAJOR to 25 / engines to <26 after the full suite and live CLI smokes passed on Node 20.20.2, 24.14.0, and 25.9.0 locally. Reproduced #171 deterministically: a models.json custom provider header containing Chinese characters produces undici's ByteString error verbatim; added scripts/lib/pi-model-registry-patch.mjs which validates header values and API keys at request assembly in Pi's getApiKeyAndHeaders and throws an error naming the provider, header, index, and code point. Added .github/workflows/e2e.yml (workflow_dispatch): installs the published package on ubuntu/macos/windows runners at Node 24 and 25, asserts launch-time patches applied (#167, #172 sources), and runs live model + subagent smokes via an OPENAI_API_KEY repo secret. - Verified: 194 tests on Node 24 and 25 (192 on Node 20 before the new tests), typecheck/build, live repro before/after shows the cryptic error replaced by the actionable one, clean-provider smoke unaffected. Daytona was considered for Windows access but no API keys exist on this machine and Daytona sandboxes are Linux; GitHub Actions windows-latest runners are the Windows machines. - Next: Push v0.2.60, dispatch the e2e workflow against the published version, comment on #171/#177 with results. ### 2026-06-11 (e2e findings) — Windows workspace extraction and npm spawn fixes - Objective: Act on the first multi-OS e2e run's findings. - Changed: The e2e run proved install/version/update pass on real Windows (Node 24+25) but caught two live Windows bugs in scripts/patch-embedded-pi.mjs: tar extraction of runtime-workspace.tgz fails because GNU tar parses "C:\..." as a remote host, and the npm fallback spawns bare "npm" without a shell (EINVAL) — together these produced the "[feynman] npm failed while setting up bundled packages" loop from #177/#170 reports. Fixed by extracting with cwd-relative paths and invoking npm via the shared scripts/lib/npm-command.mjs helper (node + npm-cli.js); package-ops.ts now imports the same helper. Also patch the workspace alpha-hub copy at launch and tightened the e2e workflow assertions to require the patch on every existing copy. - Verified: 194 tests, typecheck, build, pack includes the new lib files, bsdtar relative extraction sanity-checked locally. - Next: Release v0.2.61, re-run e2e workflow, expect all 5 matrix jobs green. ### 2026-06-11 (Pi 0.79 upgrade) — runtime modernization sweep - Objective: Update everything — Pi runtime to latest, prune dead code/deps, keep e2e green. - Changed: Pi 0.74.2 → 0.79.1 (all four packages, direct deps now include pi-agent-core/pi-tui/undici; dropped unused dotenv). Node floor 20.19 → 22.19 (Pi requirement; Node 20 is EOL), cap stays 25. OAuth login gained onDeviceCode/onSelect handlers for Pi's new callback contract. pi-tui editor patch rebuilt for the 0.76+ Unicode rework: dual import anchors, upstream IME fix (emitCursorMarker = focused) folded in, and an unknown-layout guard so a future import change can never again produce a render that references an unimported helper. Deleted pi-package-manager-patch (upstreamed in Pi 0.76 as getNpmInstallArgs --legacy-peer-deps). PI_RUNTIME_FALLBACK_VERSION 0.79.1. Model-recommendation tests updated for the 0.79 catalog (opus-4-8, MiniMax-M3). e2e matrix gained ubuntu/node 22. Website in-range dep updates. Kept the extension-loader alias halves (self-deactivating, still cover mixed-scope transitions) and the @mariozechner aliases (upgrade path). - Verified: 192 tests/typecheck/build/pack on Node 24; tests also green on Node 22 floor logic and 25; workspace rebuilt at 0.79.1; live smokes on 0.79.1 (alpha_search=10, parallel web_search BOTH_OK, subagent SUBAGENT_DONE); patched editor exercised directly via render harness (placeholder/text/narrow/unfocused — no ReferenceError); project-trust audit: headless runs default untrusted without prompting, explicit --extension unaffected. - Failed / learned: pi-tui 0.76 changed the editor import line, which made the old patch half-apply (render rewritten, import missing) — patches that rewrite a body must fail closed when their import anchor is unknown. Pi upstreamed our --legacy-peer-deps patch in 0.76 (#4907). - Next: Push v0.3.0, watch publish, dispatch e2e (now incl. node 22), update memory. ### 2026-06-12 — deep e2e in Daytona + remaining upgrades - Objective: Test everything in depth myself; upgrade what remained. - Changed: Website dev majors (eslint 10.4, @eslint/js 10, globals 17, typescript 6.0) after dropping the stale global brace-expansion@1.1.13 override that forced the v1 API onto eslint's minimatch (CVE fixed in-range on both major lines; audit clean). publish.yml artifact actions v4 → upload v7 / download v8. e2e workflow: auth fixture corrected to Pi's `type: "api_key"` (was "key", which AuthStorage silently ignores) and a text-mode model smoke added — json mode tolerates a malformed credential, text/interactive does not, so CI previously could not catch interactive auth breakage. - Verified (Daytona clean-room, published 0.3.0): interactive TUI via tmux — patched editor rendered, typed prompt answered, token/cost status bar live; `/quit` + relaunch resumed the session (model recalled a number from the prior session, #168 end to end); full `feynman lit` workflow produced outputs/lora-paper.md + provenance record; both npm-global and standalone-installer installs; both json and text one-shot modes. Local: website lint/typecheck/build green on the new majors, 192 root tests pass. - Failed / learned: my interactive "No API key" scare was my own malformed auth fixture, not a product bug — Pi stores API keys as `type: "api_key"`; json-mode one-shots resolve keys leniently while interactive is strict, which had masked the bad fixture in every earlier CI smoke. Local sandboxed Bash cannot allocate ptys (tmux/script fail) — interactive testing needs the Daytona box. - Next: Push, verify CI, dispatch e2e with the new text-mode smoke. ### 2026-06-12 — windows-subagent-spawn - Objective: Root-cause and fix the Windows-only subagent spawn regression in published `@companion-ai/feynman@0.3.0` without pushing. - Changed: Upgraded the `pi-subagents` `pi-spawn.ts` patch to recover the real Pi CLI from the Feynman wrapper's `argv2` main-module argument when `argv1` is `pi-cli-wrapper.js`; made `pi-cli-wrapper.ts` stamp `FEYNMAN_PI_CLI_PATH` from `piMainPath` if the env var is missing; added regression coverage for fresh and already-patched `pi-spawn.ts` sources. - Verified: Extracted the published `0.3.0` tarball and runtime workspace into `/tmp/codex-172`, wrote `/tmp/codex-172/FINDINGS.md`, confirmed the earlier green Windows run was actually `0.2.61` while the failing run was `0.3.0`, ran focused patch/runtime tests (32 passed), full `npm test` (194 passed), `npm run typecheck`, and `git diff --check`. - Failed / learned: The exact first trigger that bypassed `FEYNMAN_PI_CLI_PATH` inside the Windows child is not directly logged; the proven failure is wrapper invocation without the required Pi main-module argument, causing `--mode` to be imported as a module path. - Next: Review/stage the intended fix, then publish and rerun the Windows e2e smoke from the released package. ### 2026-06-12 (codex-assisted) — Windows subagent spawn recurrence fixed (v0.3.1) - Objective: Root-cause the Windows-only return of the #172 --mode failure caught by the e2e run on 0.3.0. - Changed: Dispatched the investigation to codex (gpt-5.5 xhigh) with a full spec; it audited the published 0.3.0 tarball + runtime workspace and proved the defect: with FEYNMAN_PI_CLI_PATH absent/unusable in the child, pi-spawn skips the wrapper argv1 but the fallback chain can still land back on the wrapper without the Pi main path. Fix (codex, reviewed here): pi-spawn now derives cli.js from argv[2] (the real Pi main module the wrapper was launched with) when argv1 is the wrapper, and pi-cli-wrapper.ts self-heals FEYNMAN_PI_CLI_PATH from its piMainPath. I caught and fixed one flaw in codex's patch: the SpawnDeps argv2 interface insertion wasn't idempotent (re-appended on every launch); guarded + regression test added. Also corrected the record: the "passing 0.3.0" comparison run was actually 0.2.61 — and the earlier 0.3.0 e2e pass on Windows used the malformed auth fixture, so its subagent smoke was weaker evidence than it appeared. - Verified: 195 tests, typecheck, build; patch applies idempotently to the live workspace source; e2e workflow on 0.3.1 (esp. windows subagent smoke) is the deterministic gate. - Failed / learned: codex exec hangs without stdin EOF in background shells — pipe the spec via stdin. Patch modules that append interface members must guard against re-application. ### 2026-06-12 (evidence-driven) — npm-global patch root closes #172 for real (v0.3.2) - Objective: Kill the recurring Windows --mode failure with runtime evidence instead of theory. - Changed: CI instrumentation (console.error injected into getPiSpawnCommand on the runner) proved the patched pi-spawn NEVER EXECUTES on Windows — "NO DIAG LINES". The executing copy is Pi's user-scope package root at ~/.feynman/npm-global/lib/node_modules/pi-subagents: a symlink into the patched workspace on macOS/Linux, but a real unpatched directory on Windows when junction creation falls back or `feynman update` reinstalls. Added that root to patchPiRuntimeNodeModules (now takes feynmanAgentDir) and to patch-embedded-pi's pi-subagents loop (realpath-deduped so the symlinked case isn't double-patched). Also shipped codex's agents.ts userDir repair + transactional patch groups, and hardened the e2e subagent smoke to require RESULT=PONG relayed from the child. - Verified: 197 tests/typecheck/build; launcher patches the npm-global copy locally; local subagent returns RESULT=PONG live. - Failed / learned: three releases patched the right code in the wrong place — the lesson is to instrument the failing runtime and let it tell you WHICH file executes before patching anything. CI asserts that check "a patched copy exists" are weaker than "the loaded copy is patched". ### 2026-06-18 — paper-rank-ai-researcher model synthesis handoff - Objective: Continue the PaperRank AI-researcher workflow toward model-backed synthesis while preserving deterministic evidence and auditability. - Changed: Added default `-synthesis-packet.json` and `-synthesis-prompt.md` artifacts, `--synthesis-top`, and optional `--synthesize` model synthesis that writes `-model-synthesis.md`. The model bridge now uses Feynman's recommended available research model by default instead of inheriting a stale chat default; `--synthesis-model` or `--model` still explicitly overrides it. Added default `-score-audit.md` so each paper has user-readable component scores, normalized applied weights, contribution math, field role, critique status, source excerpts, missing evidence, and rubric checks. The packet includes ranked-paper score explanations, field roles, critique summaries, rubric gaps, bounded source-span excerpts, source references, and verification limits while omitting raw full-text bodies. The report, memo, dashboard, provenance, CLI JSON summary, README, website docs, release notes, and plan now expose the model handoff and score-audit state. - Verified: Focused PaperRank/root test run passed 216 tests, including bounded packet/prompt assertions, deterministic injected model-synthesis artifact generation, CLI fixture E2E, and raw full-text omission checks. After the stale-default bug was caught, `npm test -- tests/model-harness.test.ts tests/paper-rank.test.ts` passed 217 tests with a regression asserting no-explicit-model synthesis resolves to `openai/gpt-5.5` instead of stale `openai/gpt-4.1-mini`. After the score-audit addition, `npm test -- tests/paper-rank.test.ts` passed 217 tests with assertions for the score-audit artifact, applied weights, contribution math, why-rank section, rubric checks, report/dashboard/provenance links, CLI JSON path, and raw full-text omission. `npm run typecheck`, `npm run build`, website lint/typecheck/build, `npm pack --dry-run`, and `git diff --check` passed. A live no-explicit-model `feynman rank "mechanistic interpretability sparse autoencoders" --limit 2 --source-fixture tests/fixtures/openalex-rank.json --synthesize --json` smoke generated model synthesis from `openai/gpt-5.5`, wrote packet/prompt/model-synthesis artifacts, and omitted raw full text from the synthesis packet. A live OpenAlex/alphaXiv `feynman rank "mechanistic interpretability sparse autoencoders" --limit 3 --expand-citations 1 --full-text-top 1 --critique-top 2 --synthesis-top 3 --json` smoke returned 3 ranked papers, 16 graph papers, 13 expanded papers, 1/1 full text available, 2 critiques, and a score-audit artifact with applied weights, contribution math, why-rank, rubric checks, source evidence, report/dashboard/provenance links, and no raw full-text field. - Next: Consider a richer interactive graph exploration surface or empirical score calibration against real researcher read-order decisions. ### 2026-06-18 — paper-rank-sensitivity - Objective: Make PaperRank show whether the read order is robust to the scoring weights rather than treating the default weight vector as absolute. - Changed: Added default `-rank-sensitivity.json` with balanced, influence-heavy, method/reproducibility-heavy, frontier-heavy, and topic-heavy profiles. The artifact reruns the same score signals with the same missing-component normalization, records per-profile rank/score/applied weights, rank range, score range, stable/sensitive/volatile labels, and drivers for each paper. The report, research memo, dashboard, provenance, CLI JSON summary, README, website docs, release notes, and plan now expose rank-sensitivity state. - Verified: `npm test -- tests/paper-rank.test.ts` passed 218 tests with fixture assertions for sensitivity generation, profile counts, per-paper profile ranks, report/dashboard/provenance links, JSON summary counts/path, and raw full-text omission. `npm run typecheck`, `npm run build`, website lint/typecheck/build, `npm pack --dry-run`, and `git diff --check` passed. Live OpenAlex/alphaXiv smoke returned 3 ranked papers, 16 graph papers, 13 expanded papers, 1/1 full text available, 2 critiques, 5 sensitivity profiles, 3 sensitivity papers, report/dashboard/provenance sensitivity links, score-audit contribution math, and no raw full-text leakage. A no-explicit-model synthesis smoke generated with `openai/gpt-5.5`, wrote model synthesis plus sensitivity artifacts, and omitted raw full text. - Next: Consider a richer interactive graph exploration surface or empirical score calibration against real researcher read-order decisions. ### 2026-06-18 — paper-rank-score-calibration - Objective: Make PaperRank distinguish uncalibrated product weights from empirically checked read-order preferences. - Changed: Added always-written `-score-calibration.json`, `--calibration-fixture`, and `FEYNMAN_RANK_CALIBRATION_FIXTURE`. The fixture accepts `rankedPaperIds` and pairwise `preferences`, derives pairwise order checks, evaluates default and sensitivity-profile agreement rates, counts out-of-run preferences as ignored, and records `not_provided` when no fixture exists. Report, research memo, dashboard, provenance, CLI JSON summary, README, website docs, release notes, command metadata, and plan now expose calibration status. - Verified: `npm test -- tests/paper-rank.test.ts` passed 220 tests with fixture assertions for evaluated calibration, default agreement, ignored preferences, CLI `--calibration-fixture`, default `not_provided` artifact state, report/dashboard/provenance links, JSON summary counts/path, and raw full-text omission. `npm run typecheck`, `npm run build`, website lint/typecheck/build, `npm pack --dry-run`, and `git diff --check` passed. Live OpenAlex/alphaXiv calibration smoke returned 3 ranked papers, 16 graph papers, 13 expanded papers, 1/1 full text available, 2 critiques, calibration status `insufficient_overlap`, 7 ignored preferences, report/dashboard/provenance calibration links, and no raw full-text leakage. - Next: Collect real researcher read-order fixtures for empirical weight learning or build a richer interactive graph exploration surface. ### 2026-06-18 12:18 PDT — paper-rank-graph-explorer - Objective: Make the citation graph inspectable as an AI-researcher surface rather than only a static dashboard snapshot or JSON artifact. - Changed: Added default `-graph-explorer.html` with searchable/filterable seed and expanded graph nodes, clickable citation graph nodes, paper detail panel, local citation links, source URLs, score summaries, field roles, critique verdicts, graph degree/PageRank values, and explicit limits. Wired the artifact into report, dashboard, provenance, CLI output/JSON artifacts, README, website docs, release notes, command metadata, tests, and the durable PaperRank plan. The explorer embeds bounded graph metadata and omits raw full-text bodies. - Verified: `node --import tsx --test --test-concurrency=1 tests/paper-rank.test.ts` passed 19 tests with graph-explorer artifact/path/link/no-raw-full-text assertions. `npm test` passed 220 tests; `npm run typecheck`, `npm run build`, website lint/typecheck/build, `npm pack --dry-run`, and `git diff --check` passed. Live OpenAlex/alphaXiv smoke returned 3 ranked papers, 16 graph papers, 13 expanded papers, 1/1 full text available, 2 critiques, calibration status `insufficient_overlap`, explorer/report/dashboard/provenance links present, and no raw full-text leakage. Chrome headless opened the generated explorer and verified search/filter/click-detail interaction over 16 graph nodes. A no-explicit-model synthesis smoke generated with `openai/gpt-5.5`, wrote model synthesis plus graph explorer, and kept raw full text out of the synthesis packet and explorer. - Next: Collect real researcher read-order fixtures for empirical weight learning and use them to decide whether PaperRank should alter its default weight profiles. ### 2026-06-18 12:27 PDT — paper-rank-calibration-template - Objective: Give PaperRank a safe path from transparent scoring hypotheses to empirical researcher read-order data. - Changed: Added default `-calibration-template.json` and `-calibration-guide.md`. The template uses the same `source`, `rankedPaperIds`, and `preferences` fields consumed by `--calibration-fixture`, but leaves `rankedPaperIds` and `preferences` empty by default so an unchanged template cannot validate PaperRank against its own order. It includes candidate paper summaries and pairwise questions for data collection. The guide explains how to fill the fixture and re-run calibration. Report, dashboard, provenance, CLI output/JSON artifacts, README, website docs, release notes, command metadata, tests, and the durable plan now expose the calibration handoff. - Verified: `node --import tsx --test --test-concurrency=1 tests/paper-rank.test.ts` passed 19 tests with calibration-template and calibration-guide artifact/path/link/schema/empty-field/pairwise/no-raw-full-text assertions. `npm test` passed 220 tests; `npm run typecheck`, `npm run build`, website lint/typecheck/build, `npm pack --dry-run`, and `git diff --check` passed. Live OpenAlex/alphaXiv smoke returned 3 ranked papers, 16 graph papers, 13 expanded papers, 1/1 full text available, 2 critiques, calibration status `insufficient_overlap`, an empty-safe calibration template with 3 candidate papers and 2 pairwise questions, calibration guide instructions, report/dashboard/provenance links, and no raw full-text leakage. - Next: Collect filled researcher preference fixtures across multiple topics and use them to compare or recommend topic-specific weighting profiles. ### 2026-06-18 12:40 PDT — paper-rank-replication-plan - Objective: Turn PaperRank from read-order triage into an actionable AI-researcher workflow that tells the user what to verify next. - Changed: Added default `-replication-plan.md`. The plan turns ranked papers, reviewer concerns, rubric gaps, source-span markers, field roles, rank sensitivity, calibration status, graph context, and model-synthesis state into priority reproduction targets, evidence already found, checks to perform, acceptance criteria, artifact pointers, and cross-paper verification gates. Report, dashboard, provenance, CLI output/JSON artifacts, README, website docs, release notes, command metadata, tests, and the durable plan now expose the replication plan. The artifact explicitly says it is not a completed replication and omits raw full-text bodies. - Verified: `node --import tsx --test --test-concurrency=1 tests/paper-rank.test.ts` passed 19 tests with replication-plan artifact/path/link/content/no-raw-full-text assertions. `npm test` passed 220 tests; `npm run typecheck`, `npm run build`, website lint/typecheck/build, `npm pack --dry-run`, and `git diff --check` passed. CLI help shows the replication-plan description. Live OpenAlex/alphaXiv/model-synthesis smoke returned 3 ranked papers, 16 graph papers, 13 expanded papers, 1/1 full text available, 2 critiques, synthesis status `generated` with `openai/gpt-5.5`, calibration status `insufficient_overlap`, replication-plan report/dashboard/provenance links, priority targets, acceptance criteria, cross-paper checks, and no raw full-text leakage. - Next: Use filled preference fixtures and completed reproduction notes to decide whether PaperRank should recommend topic-specific weight profiles or schedule actual replication runs. ### 2026-06-20 08:13 PDT — posthog-telemetry - Objective: Create a Feynman PostHog project and route useful analytics, logs, and traces into it. - Changed: Created PostHog workspace/project `Feynman` with project ID `478873` after the existing Companion org hit its 6-project limit. Added first-party telemetry in `src/telemetry/posthog.ts`: `posthog-node` events, OpenTelemetry logs, OpenTelemetry traces, CLI command lifecycle events, PaperRank run events, PaperRank model-synthesis events, hashed error metadata, and Pi child OTLP env propagation. Telemetry avoids raw prompts, rank topics, filesystem paths, paper text, and model prompt bodies. - Verified: `npm run typecheck`, focused telemetry/runtime tests, `npm run build`, and `npm test` passed with 234 tests. Live fixture smoke wrote a PaperRank result with temp `FEYNMAN_HOME`. PostHog Activity showed `feynman_command_started`, `feynman_paperrank_started`, `feynman_command_completed`, and `feynman_paperrank_completed`; Logs showed the Feynman command/PaperRank log messages; Tracing showed `feynman.cli.command` and `feynman.paperrank.run` spans with OK status. - Next: Add model-synthesis cost/token properties only after the model layer exposes reliable usage numbers. ### 2026-06-20 10:37 PDT — posthog-companion-project - Objective: Move Feynman telemetry into the existing Companion PostHog organization and clean up the stale project slot. - Changed: Put stale Companion PostHog project `prod` (`169469`) into PostHog pending-deletion state after verifying it was superseded by active projects. Renamed `Companion Web` (`389330`) to `Companion`, `Companion Web Staging` (`391525`) to `Companion Staging`, and `Companion Web Dev` (`391691`) to `Companion Dev`; project IDs and tokens are unchanged. Created `Feynman` inside the Companion organization as project `479027` and repointed Feynman defaults from the temporary standalone project `478873` to `479027`. - Verified: PostHog project-list API showed the renamed Companion projects and new Companion-org `Feynman` project. `prod` loaded `Project Pending Deletion` after confirmation. `npm run typecheck`, focused telemetry/Pi tests, `npm run build`, and `npm test` passed with 234 tests. Live fixture smoke emitted into project `479027`; PostHog showed Feynman event definitions/events, 4 logs, and 2 OK spans for `feynman-cli`. ### 2026-06-20 11:18 PDT — posthog-pi-otel - Objective: Wire Pi plugin/runtime observability through an existing Pi telemetry package instead of a custom Feynman extension. - Changed: Added `pi-otel` to the core Pi package set and bundled settings; configured Pi child env for PostHog's AI OTLP endpoint with metadata-only content capture; kept first-party Feynman events/logs/traces on the existing PostHog project defaults. - Verified: `npm run typecheck`, `npm run build`, and full `npm test` passed with 236 tests. Rebuilt/checked the vendored runtime archive and verified bundled `pi-otel` has a Pi extension manifest plus no `pi.cwd`/cwd attributes. A live bundled-extension smoke wired `pi-otel` to PostHog AI OTLP with `metadata_only` capture, then PostHog AI Observability showed trace `067f310b5c0b579459c57407eaed45de` with `pi.interaction`, `pi.turn`, `pi.llm_request`, and `pi.tool.read_file`; trace detail/raw views did not contain the smoke prompt/output/tool/path sentinel strings or `pi.cwd`. A normal fixture `rank` smoke emitted fresh Activity events, Logs, and Tracing spans in project `479027`. Follow-up audit narrowed the `pi-otel` patch from a broad HTTPS bypass to a `probeEndpoint()` default-port fix, rebuilt the runtime archive, and verified trace `fa86a360ccd9a5d9eec6d5b10f17c85a` with raw privacy checks clean. - Next: Delete the temporary standalone Feynman organization/project only after an explicit confirmation, since project deletion is irreversible and the code no longer points to it. ### 2026-06-22 01:14 PDT — telemetry-off-and-readback - Objective: Verify the PostHog route after the reference audit and close the inherited-telemetry leak when telemetry is disabled. - Changed: `getPostHogOtelEnv()` now clears Feynman/PostHog, generic OTLP, Pi OTel, and OTel service env keys before returning child-process telemetry env. When `FEYNMAN_TELEMETRY=off`, Pi child processes no longer inherit a parent shell's private collectors or content-capture settings. - Verified: Focused telemetry/runtime tests passed 31/31. A live smoke emitted `feynman_telemetry_smoke` into PostHog project `479027`; HogQL read-back with a personal key returned that event at `2026-06-22T08:04:27.907Z`. The same smoke emitted one PostHog log row at `2026-06-22T08:04:27.468Z` for service `feynman-cli-smoke` with body `feynman telemetry smoke`. Querying the project token against the private HogQL API returned `403 authentication_failed`, matching PostHog's private-API boundary; the local CLI credential returned `permission_denied` for project `479027`, while the Companion staging personal key could read the Feynman project. - Failed / learned: Generic `traces` and `spans` HogQL tables are not exposed under those names for this project, and this synthetic smoke did not create `$ai_` rows in `posthog.ai_events` because it did not execute an LLM/provider call. Prior Pi OTel live UI traces remain the trace-side proof for agent/model spans. - Next: Use the Companion PostHog personal key, not the project token or old CLI token, for future read-back checks on project `479027`. ### 2026-06-22 05:58 PDT — paper-access-pmid-pmcid - Objective: Tighten the single-paper access resolver for the AI-researcher loop instead of adding another adjacent workflow. - Changed: `feynman paper` now treats explicit PMID and PMCID inputs as first-class paper identifiers, routes them through OpenAlex exact `pmid`/`pmcid` filters, and keeps title searches from accidentally matching PMID/PMCID substrings. Public CLI metadata, README, website docs, and release notes now name PMID/PMCID support on the existing paper-access surface. - Verified: Focused PaperRank/content-policy tests passed 81/81 with exact OpenAlex ID, PMID, and PMCID routing regressions. Full `npm test` passed 311/311; `npm run typecheck`, `npm run build`, website lint/typecheck/build, production audits, `npm pack --dry-run`, and diff checks passed. A live compiled binary smoke for `feynman paper pmid:29456894 --fetch-full-text --json` resolved OpenAlex `W2741809807`, found PMCID `PMC5815332`, fetched Europe PMC fullTextXML, and generated artifacts without a raw full-text string field. Live compiled binary smokes for short and URL OpenAlex IDs resolved the same work through the packaged entrypoint. - Next: Keep paper-access improvements inside exact identifier/source routing unless a real researcher task proves a broader retrieval connector is necessary. ### 2026-06-22 06:03 PDT — paper-access-title-match - Objective: Prevent a weak title query from silently anchoring a research run on the wrong OpenAlex result. - Changed: `feynman paper ` now asks OpenAlex for multiple candidates, scores title overlap, accepts the best sufficiently related title, and rejects unrelated title-search results instead of blindly taking the first provider hit. Exact DOI, arXiv ID, OpenAlex ID, PMID, and PMCID paths remain exact-filter lookups. - Verified: Focused PaperRank/content-policy tests passed 83/83 with regressions for matching title candidates, rejecting unrelated title hits, and preserving exact identifier routes. Full `npm test` passed 313/313; root typecheck/build, website lint/typecheck/build, root/website production audits, `npm pack --dry-run`, and diff checks passed. A live compiled binary smoke for the title `Sparse Autoencoders Find Highly Interpretable Features in Language Models` resolved OpenAlex `W4386839891`, DOI `10.48550/arxiv.2309.08600`, and arXiv `2309.08600` through the packaged entrypoint. A live compiled binary PMID full-text smoke still resolved OpenAlex `W2741809807`, found PMCID `PMC5815332`, fetched Europe PMC fullTextXML, and generated artifacts without a raw full-text string field. - Next: Keep title search as a guarded resolver path; use `feynman rank` for broad discovery. ### 2026-06-22 06:13 PDT — non-pro-model-surface-wording - Objective: Keep the visible model setup surface aligned with the no-Pro policy after the reference audit. - Changed: The successful `feynman model set` message now says it set the non-Pro default model, and the installation docs post-install setup handoff now says setup selects a non-Pro default model. Added regressions for the command output string and installation-doc wording. - Verified: Focused model/content-policy tests passed 66/66. A stale generic-model wording scan found only the new regression assertions and corrected source string for `Non-Pro default model set to`. - Next: Run the broad package gates again, then stage the wording fix with the existing AI-researcher package. Commit/push/release remains unauthorized. ### 2026-06-22 06:23 PDT — paperrank-provenance-product-language - Objective: Keep generated PaperRank provenance as a real research audit trail, not a test-fixture-shaped artifact. - Changed: Default PaperRank provenance now says calibration artifacts require a preference file and reproduction artifacts require reproduction notes. Removed the stale `reproduction fixture` / `needs repair` wording from generated provenance and added a default-run regression. - Verified: Focused PaperRank/content-policy tests passed 83/83. Full `npm test` passed 313/313. `npm run typecheck`, `npm run build`, website lint/typecheck/build, website build, root/website production audits, `npm pack --dry-run`, and diff checks passed. A compiled `bin/feynman.js rank ... --json` smoke generated provenance with `preference file is supplied` and `reproduction notes are supplied`, and no stale fixture wording. - Next: Keep reviewing generated artifacts for decision-corrupting wording or broken pointers; commit/push/release remains unauthorized. ### 2026-06-22 06:31 PDT — paperrank-review-boundary-language - Objective: Keep generated PaperRank artifacts framed as research triage and source inspection, not academic peer-review authority. - Changed: Replaced the remaining generated `peer-review verdict` boundary text in the score audit and provenance with claim-validation/reproduction language. Added regressions so the phrase does not return in PaperRank copy or generated default artifacts. - Verified: Focused PaperRank/content-policy tests passed 83/83 and the stale active-surface scan found the old phrases only in negative regression assertions. Full `npm test` passed 313/313. `npm run typecheck`, `npm run build`, website lint/typecheck/build, website build, root/website production audits, diff checks, and `npm pack --dry-run` passed. Rendered website internal-link check passed with 33 HTML files and 0 missing links. A compiled `bin/feynman.js rank ... --json` smoke generated score-audit/provenance artifacts with no stale `peer-review verdict` or fixture wording. - Next: Stage the final PaperRank wording patch with the existing AI-researcher package. Commit/push/release remains unauthorized. ### 2026-06-22 06:44 PDT — paperrank-peer-review-frame-removal - Objective: Remove the remaining peer-review frame from PaperRank, which is a read-first ranking and verification-planning workflow rather than a review workflow. - Changed: Replaced PaperRank methodology, report, synthesis-prompt, replication-plan, and workflow-doc mentions of peer review with claim-validation/reproduction language. Added regressions so PaperRank source/docs and generated score audit, report, synthesis prompt, and replication plan do not reintroduce `peer review`. - Verified: Focused PaperRank/content-policy tests passed 83/83. Targeted scans found `peer review` in PaperRank files only inside negative regression assertions; remaining active mentions are review-workflow boundary text or biomedical evidence-type labels. Full `npm test` passed 313/313. `npm run typecheck`, `npm run build`, website lint/typecheck/build, website build, root/website production audits, diff checks, and `npm pack --dry-run` passed. Rendered website internal-link check passed with 33 HTML files and 0 missing links. A compiled no-model `bin/feynman.js rank ... --json` smoke checked generated report, score audit, provenance, and replication plan for stale peer-review/fixture wording. A parallel compiled smoke with `--synthesize` was stopped before using it as evidence because it entered the model path; synthesis-prompt wording is covered by focused tests. - Next: Stage the final PaperRank peer-review frame removal with the existing AI-researcher package. Commit/push/release remains unauthorized. ### 2026-06-22 06:58 PDT — paperrank-release-artifact-truth - Objective: Keep public release docs aligned with PaperRank's lean default artifact boundary. - Changed: Fixed the website release note that still claimed every PaperRank run writes an empty-safe reproduction notes template. It now says reproduction ledgers, notes templates, and replication plans are written only when `--reproduction-notes` supplies completed reproduction evidence. Added a content-policy guard for the stale sentence. - Verified: Focused content-policy tests passed 32/32. Full `npm test` passed 313/313. `npm run typecheck` passed. Website build passed and generated 33 pages. Rendered website internal-link check passed with 33 HTML files and 0 missing links. Active stale-sentence scan found the removed reproduction-template claim only in the new negative regression assertion. - Next: Stage the release-doc artifact-boundary fix with the existing AI-researcher package. Commit/push/release remains unauthorized. ### 2026-06-22 07:28 PDT — source-access-promise-boundary - Objective: Keep source-access docs honest and bounded so Feynman reads available evidence instead of implying arbitrary complete web or paper access. - Changed: Tightened web-search docs from complete page content to provider-available page text, and tightened alphaXiv docs from broad full-text access to citation metadata, discussion threads, and source-specific paper text when available. Added content-policy guards for the stale phrases. - Verified: Focused content-policy tests passed 32/32. Full `npm test` passed 313/313. `npm run typecheck`, website typecheck, and website build passed; website build generated 33 pages. Rendered website internal-link check passed with 33 HTML files and 0 missing links. Active scan found the removed complete-content/full-text-access phrases only in negative regression assertions. - Next: Stage the source-access promise-boundary fix with the existing AI-researcher package. Commit/push/release remains unauthorized. ### 2026-06-22 07:43 PDT — session-search-session-dir-fix - Objective: Make the optional session-search package actually recall Feynman research sessions instead of looking in upstream Pi's default session directory. - Changed: Added a carried `pi-session-search` patch that makes its indexer prefer `FEYNMAN_SESSION_DIR` or `PI_SESSION_DIR` before falling back to `~/.pi/agent/sessions`. Wired the patch through runtime startup, vendored runtime workspace preparation, and the embedded postinstall patch script. Added direct patch tests and runtime-root coverage for package-local, vendored, user-global, and Pi-agent npm installs. Also tightened preview docs so optional preview rendering is described as renderer-dependent, not guaranteed perfect LaTeX/table rendering. - Verified: `npm view` still reports `0.79.10` for all four scoped Pi runtime packages. Focused package/runtime/content tests passed 75/75. Full `npm test` passed 315/315. `npm run typecheck`, `npm run build`, website typecheck, and website build passed; website build generated 33 pages. Rendered website internal-link check passed with 33 HTML files and 0 missing links. Root and website production audits reported 0 vulnerabilities. `npm pack --dry-run` passed and packed 132 files, including the new session-search patch helper. - Next: Stage the session-search runtime fix with the existing AI-researcher package. Commit/push/release remains unauthorized. ### 2026-06-22 07:47 PDT — package-install-runtime-patch - Objective: Make optional Pi package installs and updates leave Feynman's patched research runtime correct immediately, not only after a later launch-time patch pass. - Changed: `installPackageSources` and `updateConfiguredPackages` now run the runtime patch pass after successful installs or updates, so freshly installed Pi packages in Feynman's user npm prefix are patched before the command returns. Added regressions that simulate supported Node 22 session-search installs/updates and inspect the installed `@kaiserlich-dev/pi-session-search/extensions/indexer.ts` file for Feynman's session directory handoff. - Verified: Focused package/runtime/content tests passed 84/84, including package install and update regressions for the patched session-search indexer. Full `npm test` passed 317/317. `npm run typecheck`, `npm run build`, website lint/typecheck/build, root and website production audits, rendered website internal-link check, `npm pack --dry-run`, and diff checks passed. Website build generated 33 pages; rendered link check found 0 missing internal targets. - Next: Stage the package-operation patch with the existing AI-researcher package. Commit/push/release remains unauthorized. ### 2026-06-22 07:52 PDT — paperrank-generated-fixture-language - Objective: Keep generated PaperRank artifacts in researcher-facing product language instead of leaking stale test-fixture terminology. - Changed: Replaced generated synthesis-packet wording from `explicit fixture` to `explicit reproduction notes file`, and replaced the calibration-guide limit from `small fixture` to `small preference file`. Added regressions covering both generated artifacts and the active PaperRank source/docs surface. - Verified: Focused PaperRank/content-policy tests passed 83/83. Targeted stale-language scan now finds the removed fixture phrases only in negative regression assertions. Full `npm test` passed 317/317. `npm run typecheck`, `npm run build`, website lint/typecheck/build, root and website production audits, rendered website internal-link check, `npm pack --dry-run`, and diff checks passed. Website build generated 33 pages; rendered link check found 0 missing internal targets. - Next: Stage the generated-artifact wording fix with the existing AI-researcher package. Commit/push/release remains unauthorized. ### 2026-06-22 08:01 PDT — telemetry-child-env-scrub - Objective: Keep Feynman's observability useful without leaking or inheriting private parent-shell OTEL/Pi telemetry settings into the research runtime. - Changed: The PostHog OTEL child-env builder now starts from a scrubbed telemetry environment and clears inherited OTEL logs/metrics routes, resource attributes, exporter controls, Pi OTEL disable/service overrides, and OTEL log level before setting Feynman's PostHog trace/log routes. Added regressions for enabled and disabled telemetry paths. - Verified: Focused telemetry/runtime/content tests passed 57/57. Full `npm test` passed 318/318. `npm run typecheck`, `npm run build`, website typecheck/lint/build, root and website production audits, rendered website internal-link check, `npm pack --dry-run`, and diff checks passed. Website build generated 33 pages; rendered link check found 0 missing internal targets; pack dry-run included 132 files. - Next: Stage the telemetry scrub with the existing AI-researcher package. Commit/push/release remains unauthorized. ### 2026-06-22 08:07 PDT — paper-access-source-label-escaping - Objective: Keep single-paper access reports safe when provider or test fetchers return source labels, so generated Markdown cannot be shaped by untrusted labels. - Changed: Escaped the full-text source label in paper-access Markdown reports and added a regression with a provider label containing a pipe, newline heading, and Markdown link syntax. - Verified: Focused PaperRank/content-policy tests passed 84/84. Full `npm test` passed 319/319. `npm run typecheck`, `npm run build`, website typecheck/lint/build, root and website production audits, rendered website internal-link check, `npm pack --dry-run`, and diff checks passed. Website build generated 33 pages; rendered link check found 0 missing internal targets; pack dry-run included 132 files. - Next: Stage the generated-artifact boundary fix with the existing AI-researcher package. Commit/push/release remains unauthorized. ### 2026-06-22 08:14 PDT — paperrank-markdown-html-escaping - Objective: Keep PaperRank and paper-access Markdown artifacts structurally trustworthy when provider-controlled paper titles, source labels, or evidence text contain HTML-like input. - Changed: The shared Markdown escape helper now entity-escapes `&`, `<`, and `>` before Markdown control characters, so paper/provider text cannot render as raw HTML in generated reports. Extended paper-access regressions with hostile title and full-text source labels containing raw HTML tags. - Verified: Focused PaperRank/content-policy tests passed 84/84. Full `npm test` passed 319/319. `npm run typecheck`, `npm run build`, website typecheck/lint/build, root and website production audits, rendered website internal-link check, `npm pack --dry-run`, and diff checks passed. Website build generated 33 pages; rendered link check found 0 missing internal targets; pack dry-run included 132 files. - Next: Stage the Markdown/HTML escaping hardening with the existing AI-researcher package and continue the generated-artifact audit. Commit/push/release remains unauthorized. ### 2026-06-22 08:18 PDT — paperrank-provenance-source-meta-fence - Objective: Keep PaperRank provenance auditable when source metadata contains Markdown backticks, headings, or HTML-like text. - Changed: Provenance now writes source metadata as a fenced JSON block using the existing adaptive fence helper instead of an inline code span. Added a regression where fixture metadata contains a triple-backtick sequence, injected heading text, and script-like markup, then asserted the metadata stays under the source-meta fence. - Verified: Focused PaperRank/content-policy tests passed 84/84. Full `npm test` passed 319/319. `npm run typecheck`, `npm run build`, website typecheck/lint/build, root and website production audits, rendered website internal-link check, `npm pack --dry-run`, and diff checks passed. Website build generated 33 pages; rendered link check found 0 missing internal targets; pack dry-run included 132 files. - Next: Stage the provenance fence fix with the existing AI-researcher package and continue artifact-boundary review. Commit/push/release remains unauthorized. ### 2026-06-22 08:22 PDT — paperrank-model-synthesis-html-escape - Objective: Keep model-generated PaperRank synthesis readable while preventing raw HTML from rendering inside the audit artifact. - Changed: `*-model-synthesis.md` now escapes raw HTML characters in model synthesis text while preserving line breaks and Markdown structure. Extended the generated-synthesis regression with model output containing raw `<script>` and `<img>` tags, and asserted the artifact renders escaped text instead of raw tags. - Verified: Focused PaperRank/content-policy tests passed 84/84. Full `npm test` passed 319/319. `npm run typecheck`, `npm run build`, website typecheck/lint/build, root and website production audits, rendered website internal-link check, `npm pack --dry-run`, and diff checks passed. Website build generated 33 pages; rendered link check found 0 missing internal targets; pack dry-run included 132 files. - Next: Stage the synthesis HTML escape with the existing AI-researcher package and continue artifact-boundary review. Commit/push/release remains unauthorized. ### 2026-06-22 08:31 PDT — installed-tarball-e2e-research-smoke - Objective: Prove the staged package works as an installed user-facing research CLI, not only through source tests. - Changed: No product code changed. Ran a clean tarball install under `/tmp/feynman-e2e.kvlIB5`, then exercised the installed `feynman` binary with fresh `FEYNMAN_HOME` directories and telemetry disabled. - Verified: `npm pack` produced `@companion-ai/feynman@0.3.4` with 132 files; clean temp `npm install --omit=dev` installed 364 packages with 0 vulnerabilities; installed `feynman --version` returned `0.3.4`. Installed CLI smokes passed for top-level help, bundled `feynman alpha --help`, PaperRank fixture run with citation expansion/full-text/critique (`4` ranked papers, `6` graph papers, `2/2` full-text available, `2` critiques, `10` artifacts), and paper-access fixture run with full text available. Live provider smokes passed: `feynman paper 10.7717/peerj.4375 --fetch-full-text --json` resolved via OpenAlex with `12` access candidates and available full text, and `feynman alpha search "sparse autoencoders"` returned `10` parsed result rows. - Next: Keep the package staged as the current local release candidate; commit/push/release remains unauthorized. ### 2026-06-23 04:50 PDT — code-organization-reference-pass - Objective: Deeply compare Feynman's shape against Codex, Claude Code, OpenCode, Hermes Agent, and Hugging Face ML Intern, then apply only the structural improvements that keep Feynman a simple, potent AI researcher. - Changed: Added a durable code-organization research handbook under `outputs/.plans/code-organization-review/`, cloned/read the reference repos in `_agent-research/feynman-code-organization/`, and added `scripts/check-architecture.mjs` plus `npm run architecture:check`. The guard names existing oversized debt (`src/rank/paper-rank.ts`, `tests/paper-rank.test.ts`, `src/cli.ts`), warns on files nearing core debt (`src/model/commands.ts`, `scripts/patch-embedded-pi.mjs`), and blocks new unallowlisted oversized files or domain modules importing CLI/UI/setup layers. - Verified: `npm run architecture:check` passed and checked 114 source files. No user-facing feature surface was added; the next recommended implementation step is mechanical PaperRank/CLI extraction, followed by a `ResearchRun`/research-recipe artifact contract. - Next: Split PaperRank into papers/evidence/rank/artifact modules without changing ranking behavior, then split CLI command handlers and keep the architecture guard green. ### 2026-06-22 08:48 PDT — contributor-pr-intake-and-legacy-alias-fix - Objective: Turn contributor intake into a repeatable AI-researcher product loop and port only the PR changes that fix real package reliability. - Changed: Reactivated the existing Codex automation `check-new-issues` as `Feynman AI researcher intake sweep`, with explicit PR/issue classification rules, feature-fight criteria, and no push/merge/comment authority. Evaluated open PRs: `#179` is not mergeable as-is because it adds a separate Bernoulli prompt tree and outreach/admin workflow; `#181` fixes issue `#180`, so ported its root-cause package fix. `resolveRuntimePeerSpec` now reads both `name` and `version` from installed runtime package manifests and emits `npm:` alias specs when legacy `@mariozechner/*` directories contain current `@earendil-works/*` package names. - Verified: Focused package/runtime tests passed 27/27. Full `npm test` passed 320/320. `npm run typecheck`, `npm run build`, root production audit, `npm pack --dry-run`, diff checks, and clean installed-tarball smoke passed. The installed tarball returned `0.3.4` and `feynman packages list` rendered the core/optional package surface from a fresh temp install. - Next: Stage the alias fix and automation notebook entry with the existing AI-researcher package. Commit/push/release remains unauthorized. ### 2026-06-23 05:31 PDT — code-organization-daytona-hardening - Objective: Finish the deep code-organization pass with clean install/runtime proof, keep Feynman focused on AI research, and remove the Daytona pack/install failure. - Changed: Added the architecture guard and durable code-organization notes; patched Pi package metadata before CLI import so fresh source installs use Feynman's `.feynman` config; made runtime workspace preparation install current Pi packages once and symlink legacy `@mariozechner/*` aliases to `@earendil-works/*` instead of installing duplicate dependency trees. - Verified: Daytona fresh clone passed `npm ci`, `npm run architecture:check`, `npm test` (`323/323`), `npm run typecheck`, isolated `npm run build`, root production audit, diff checks, website install/lint/typecheck/build/audit, rendered internal-link check (`33` HTML files, `0` missing links), and `npm pack --dry-run` (`133` files, `50.9 MB`, shasum `85d92d0cffb5f01296a0599b45ac93b6b2771b62`). The vendored runtime package prep completed in 27 seconds and legacy Pi namespace entries were verified as symlinks. - Next: Commit and push this release candidate, then split PaperRank into source/access/evidence/rank/artifact modules before adding any plugin or MCP public surface. ### 2026-06-23 14:08 PDT — research-run-product-spine - Objective: Turn the BioNeMo-style lesson into a Feynman product repair without adding a random life-science workflow. - Changed: Added the first code-level `ResearchRun` contract and validator, added research-plugin manifest validation with `entity_extractors` and `experiment_runners`, and made PaperRank emit `<slug>-research-run.json` as the typed spine for sources, papers, tools, artifacts, verification state, constraints, and next actions. Updated PaperRank docs and the architecture handbook to treat molecular diagram parsing as an entity extractor and BioNeMo-style model calls as experiment runners. - Verified: Full local root suite passed `325/325`; local typecheck, build, architecture guard, root audit, diff check, website lint/typecheck/build/audit, rendered docs link check (`33` HTML files, `0` missing internal links), and `npm pack --dry-run` passed. After the final manifest completion-marker ordering fix, local root tests, typecheck, build, architecture guard, diff check, and package dry-run were rerun; final pack shasum is `0442fe1352718f10b347c53b182b84d335713451`. Local installed-tarball E2E installed the package into a fresh temp project, returned version `0.3.4`, ran PaperRank through the shipped binary, and verified the emitted `feynman.researchRun.v1` manifest with `4` papers, top paper `WFOUNDATION`, `11` artifacts, and `rawFullTextStored: false`. Daytona sandbox `feynman-researchrun-e2e` passed clean `npm ci`, architecture guard, `npm test` (`325/325`), typecheck, build, root audit, and `npm pack --dry-run`; sandbox was deleted after verification. - Next: Commit and push this focused product-architecture patch, then continue into mechanical PaperRank module extraction. The next install-speed target is reducing the 51-52 MB vendored runtime archive and 417-package runtime prep path. ### 2026-07-01 00:52 PDT — open-science-workbench-chat-provenance - Objective: Move Feynman's local open-science workbench closer to the real Claude Science session shape instead of stopping at a static artifact dashboard. - Changed: Read Pi 0.80.3 SDK/RPC/session docs and matched the UI to the observed Claude Science composer/session-options/artifact menu behavior. Workbench sessions now default to Delegation off, Auto-review off, Memory off, Specialist None, Compute Local, with a legacy migration for old auto-created all-on `Default` sessions. The composer advertises `@` artifacts, `#` sessions, and `/` skills; running turns label the send action as Steer; transcript tool cards show Pi inputs/details; artifact previews now have a More menu and inline Code/Review provenance overlay. - Verified: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` passed (`346/346`). In-app browser smoke on the live local `reference-audit` route verified the new composer placeholder, Specialist None/default-off config rows, artifact More menu, and inline Provenance Code/Review overlay. - Next: Add direct notebook/composer code execution and first-class structured verification checks so Feynman can run and review new scientific work from the UI, not only inspect existing artifacts. ### 2026-07-01 01:22 PDT — open-science-workbench-notebook-checks - Objective: Make the workbench behave more like Claude Science's active experiment surface by letting users run notebook cells and record verification checks from inside the app. - Changed: Added a persisted notebook execution runner for Python, R, and Bash. The Notebook pane now exposes Run cell with Explore/Check mode; executions run in the local workspace, persist under `.feynman/workbench/notebook-executions/`, and flow back into the execution ledger as code cells with output, exit/duration details, and exact evidence paths. Check-mode executions now create structured `state.checks` records and render in the Provenance pane beside existing verification artifacts. - Verified: Rechecked Pi RPC/session docs and Claude Science runtime evidence for execution-log, compute submit-cell, artifact-version, and verification-check primitives. `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, targeted `tests/workbench.test.ts`, and full `npm test` passed (`348/348`). Fresh-server in-app browser smoke on `reference-audit` executed a Bash Check cell, rendered the verified notebook cell, and showed the new pass record in Provenance Checks. - Next: Wire Customize/Agent to discovered Feynman specialists, skills, MCP packages, prompt templates, and compute choices from real local resources. ### 2026-07-01 01:46 PDT — open-science-workbench-resource-customize - Objective: Make the open-science workbench's Customize/chat layer structurally closer to Claude Science by wiring it to real Feynman/Pi resources instead of static placeholder cards. - Changed: Added typed resource groups to workbench state for specialists, skills, prompt templates, connectors, compute, permissions, credentials, storage, and memory. Customize now discovers `.feynman/agents/*.md`, `skills/**/SKILL.md`, `prompts/*.md`, configured Pi packages, and project extensions, then renders them as action cards. Specialist cards update the active chat session config; skill/prompt cards insert the real Pi command into the composer. Pi command messages starting with `/` or `!` now reach Pi raw so RPC can expand skills, prompt templates, extension commands, and bash-style input instead of losing command semantics inside the workbench context wrapper. Fixed a resource-card overlap bug that physically covered action buttons. - Verified: Rechecked Claude Science public docs/news, local Claude Science runtime assets/DB shape, and Pi 0.80.3 RPC/skills/extensions/prompt-template/package/session docs. `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, targeted `tests/workbench.test.ts`, and full `npm test` passed (`349/349`). Fresh-server in-app browser smoke on `reference-audit` verified live resource counts, `/skill:literature-review` insertion, Researcher specialist session update, no console errors, and the fixed hit target after the card-layout patch. - Next: Add artifact version history and lineage drawers from local artifacts, execution records, Pi messages, and notebook execution records; then promote resource discovery to live Pi `get_commands` where command provenance matters. ### 2026-07-01 02:03 PDT — open-science-workbench-artifact-versions - Objective: Close the Claude Science artifact-version/provenance gap with a real version model instead of a static `v1` label. - Changed: Added first-class `artifactVersions` to workbench state. Versions are derived from scanned artifacts and explicit Pi/chat/notebook producer records, with content type, file size, SHA-256 checksum, source, parent link, producer execution/source ids, agent name, language, code, producer messages, environment details, input/output paths, checkpoint/intermediate flags, and annotations. Artifact preview now has a Versions tab; Lineage renders version rows beside upstream/downstream artifacts; metadata export includes the version graph. Fixed the Versions header spacing after browser screenshot review. - Verified: Relaunched and drove the installed Claude Science app, inspected its local SQLite schema/runtime assets for `artifact_versions`, `artifact_dependencies`, execution logs, provenance drawers, lineage messages, and environment snapshots; reread Pi 0.80.3 RPC/SDK/session/package/extension docs. `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, targeted `tests/workbench.test.ts`, and full `npm test` passed (`349/349`). Fresh-server browser smoke on `reference-audit` verified 122 artifacts, 122 artifact versions, the rendered Versions tab, the Lineage tab version row, full checksum metadata for `outputs/reference-audit/handoff.md`, and no console/page errors. - Next: Promote notebook execution from isolated local processes to persistent kernel/Pi RPC continuity where variable/env continuity matters, and upgrade resource discovery to live Pi `get_commands` for command provenance. ### 2026-07-01 02:24 PDT — open-science-workbench-persistent-kernels - Objective: Make the Notebook runner behave like a continuing research session instead of a per-cell process launcher. - Changed: Added long-lived Python and Bash session kernels keyed by workbench session, with explicit Session kernel versus Isolated process runtime selection in the Notebook UI. Python cells now preserve variables across runs; Bash cells preserve env and cwd across runs. Notebook records persist `executionMode` and `kernelId`, the execution ledger labels session-kernel provenance, and server shutdown closes both Pi RPC clients and notebook kernels. Split kernel lifecycle code into `src/workbench/notebook-kernels.ts` so `notebook-execution.ts` stays focused. - Verified: Re-read Pi 0.80.3 SDK/RPC/session docs for embedded sessions, JSONL session trees, and bash execution semantics. `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, targeted `tests/workbench.test.ts`, and full `npm test` passed (`351/351`). Fresh-server in-app browser smoke on `reference-audit` verified the chat/composer surface, Runtime default `Session kernel`, a two-cell Python UI run where the second cell printed `124` from state defined in the first cell, zero console errors, and screenshot `/tmp/feynman-notebook-kernel-smoke.png`. - Next: Promote resource discovery to live Pi `get_commands` and richer connector/package state, then persist before/after artifact snapshots for mutations during active workbench sessions. ### 2026-07-01 03:12 PDT — open-science-workbench-live-pi-commands - Objective: Replace the remaining guessed command/resource layer with live Pi command provenance so the workbench chat surface behaves like a real local science agent cockpit. - Changed: Added Pi RPC `get_commands` integration for the workbench. Opening Customize now asks the active Pi session for invokable extension commands, prompt templates, and skill commands, merges a live `Pi Commands` resource group after Skills, preserves Pi's canonical `sourceInfo` provenance, and inserts the exact slash command into the composer. The command normalizer keeps older `location/path` fields only as a compatibility fallback. - Verified: Rechecked the current Claude Science page for persistent kernels, traceable artifacts, scientific databases, skills, connectors, internal APIs, ELNs, and pipeline connectors; reread installed Pi RPC/extension docs and source for `get_commands` and `sourceInfo`. The authenticated local endpoint returned 91 live Pi commands and the in-app browser verified `Pi Commands 91 items`, real command cards such as `/audit` and `/deepresearch`, `/audit` composer insertion, and zero console errors on `reference-audit`. `npm run typecheck`, `npm run build`, `npm run architecture:check`, targeted workbench tests, and full `npm test` passed (`352/352`). - Next: Add richer connector/package detail, grant, credential, and enable/disable state; then persist before/after artifact snapshots for notebook/chat mutations. ### 2026-07-01 03:44 PDT — open-science-workbench-connector-state - Objective: Move Connector cards from discovered labels toward the live control-plane state Claude Science exposes for skills/connectors/credentials. - Changed: Connector resources now parse Pi package settings in string and object-filter form, read installed package manifests from `.feynman/npm/node_modules`, show package versions, declared Pi extension/skill/prompt/theme counts, core versus optional state, installed/not-installed tags, and package filter details. Added real package action metadata, a token-protected `/api/resources/package` route, and UI Enable/Disable buttons that mutate project `.feynman/settings.json` and refresh state. Split package connector scanning into `src/workbench/package-resources.ts`. - Verified: Rechecked Pi package docs for package sources, filtering, enable/disable, scope, and deduplication. Live state showed five configured core package cards with versions/counts plus available `pi-memory` and `pi-hindsight` optional cards. The package route was live-tested by enabling `npm:@samfp/pi-memory`, verifying configured state, disabling it, and confirming settings returned to the five core package sources. `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, targeted workbench/package tests, and full `npm test` passed (`354/354`). Browser automation failed to attach after earlier snapshot timeouts, so this slice's rendered proof used server HTML plus authenticated state/API. - Next: Persist before/after artifact snapshots for live notebook/chat mutations, then add connector-specific credential/grant diagnostics. ### 2026-07-01 04:20 PDT — open-science-workbench-artifact-snapshots - Objective: Make artifact history real during live notebook/chat work instead of reconstructing every version from the current file. - Changed: Added persisted before/after artifact snapshots under `.feynman/workbench/artifact-snapshots/` for notebook cells and Pi-backed chat turns. Notebook execution records now store `snapshotIds`; chat turns record changed `outputs/`, `papers/`, and `notes/` artifacts even when the assistant reply omits the path. Artifact versions now prefer persisted snapshot checksums/content paths and expose snapshot id/path, previous snapshot path, previous checksum/size, and content-changed state in Versions, Lineage, and metadata export. - Verified: Re-read Pi 0.80.3 RPC/session docs and Feynman's Pi chat wrapper. Focused temp-workspace tests proved notebook and chat mutations persist exact before/after content and render snapshot-backed artifact versions. `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, targeted workbench/snapshot tests, and full `npm test` passed (`356/356`). Fresh-server browser smoke on `reference-audit` verified the in-page Pi chat/composer, Pi session file identity, and files/notebook/execution/compute/agent/provenance panes on the current code. - Next: Add connector-specific credential/grant diagnostics, then expose snapshot diff/restore controls now that before/after content exists. ### 2026-07-01 08:56 PDT — open-science-workbench-chat-context-diagnostics - Objective: Respond to the source-backed gap that the workbench chat must actually use the local research session state, not merely sit beside notebook and connector panes. - Changed: Re-read Pi RPC/SDK/session/package/security docs and rechecked the current Claude Science public page plus local Claude Science runtime/SQLite shape. Normal workbench chat prompts now include the latest executed notebook cells from the same session, including code, output, runtime, artifact paths, and snapshot ids, while raw Pi `/` and `!` command inputs still pass through untouched. Connector cards now render first-class diagnostics for project config, install state, declared package resources, active filters, preset class, and the Pi trust/grant boundary. - Verified: Targeted tests prove notebook output is included in the next same-session prompt and excluded across sessions, and package-resource tests prove connector diagnostics cover settings, install paths, filters, disabled core packages, optional presets, and trust boundaries. `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, targeted workbench/package tests, and full `npm test` passed (`357/357`). Fresh server at `http://127.0.0.1:6174/?token=hs__bXKzFHXIAJGG3cMNp33MyRt7W8NW` returned authenticated state with 4 projects, 43 runs, 122 artifacts, 8 connectors, and connector diagnostics. Playwright screenshot verified the deep-linked project route renders transcript, composer, files, and artifact preview. Codex blocked direct Computer Use against its own in-app browser window, and transient Playwright Test package imports were not available without adding a repo dependency, so clicked Customize-panel visual verification is API/state-backed rather than screenshot-backed. - Next: Add user-visible snapshot diff/restore controls for the persisted artifact snapshots. ### 2026-07-01 09:22 PDT — open-science-workbench-snapshot-diff-restore - Objective: Make persisted artifact snapshots user-controllable in the workbench so researchers can inspect and restore saved scientific outputs instead of only seeing that history exists. - Changed: Added snapshot-backed artifact version actions. The Versions tab now shows Diff and Restore controls for saved snapshots, renders bounded inline text diffs with added/removed/context lines, reports binary snapshots explicitly, and sends restore actions through a token-protected server route. Restores validate that artifact paths stay under `outputs/`, `papers/`, or `notes/`, validate snapshot content stays inside `.feynman/workbench/artifact-snapshots/files/`, write the selected snapshot back to the workspace, and record the restore as a new `workspace` snapshot event for auditability. - Verified: Re-read the installed Pi 0.80.3 extension/session docs, local Claude Science runtime/schema evidence for artifact versions and provenance, current OpenCode source for session UI/runtime split, and Microsoft Conductor source/docs for dashboard/event/gate visibility. `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, targeted workbench snapshot/action tests, focused workbench tests, and full `npm test` passed (`361/361`). The diff/restore endpoints were exercised through a live temp workbench server and verified to restore file content while creating a new restore version. The real workbench was restarted on `127.0.0.1:6174`; in-app browser smoke verified the fresh `reference-audit` route, chat composer, Versions tab, selected Handoff artifact, and zero console errors. The real workspace currently has `0` snapshot-backed versions, so no fake artifact was created just to display Diff/Restore buttons. - Next: Continue into richer connector credential/grant surfaces and environment snapshots; the first real notebook/chat artifact mutation will expose the Diff/Restore controls in the live workspace. ### 2026-07-01 10:27 PDT — open-science-workbench-mutable-settings - Objective: Make the Claude Science-shaped Customize/Settings surface actually mutable instead of only inventorying resources. - Changed: Added local settings persistence under `.feynman/workbench/settings.json` plus authenticated `/api/resources/settings` upsert/remove routes. Customize now has add/remove flows for custom MCP-style connectors, SSH compute hosts, allowed domains, environment-backed credential references, permission grants, and memory categories. The records flow back into the same resource groups, and the client click delegation now handles text-node targets so settings submit/remove buttons work reliably. - Verified: Re-drove installed Claude Science Settings forms and reread Pi 0.80.3 settings/package/extension/RPC docs. `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, focused workbench/settings tests, and full `npm test` passed (`363/363`). Fresh in-app browser smoke on `reference-audit` verified all mutable forms, then added and removed a temporary allowed domain through the UI; the real settings file returned to empty custom arrays after cleanup. - Next: Bridge saved custom connectors, credentials, and grants into real Pi/MCP execution/enforcement paths and record richer notebook/Pi environment snapshots. ### 2026-07-01 11:57 PDT — open-science-workbench-connector-approval - Objective: Move custom connector chat behavior closer to Claude Science by replacing the blunt allow-only gate with persisted ask requests and Claude-shaped connector setup fields. - Changed: Custom connector settings now store per-connector `skipApprovals` and expose Remote/Local, remote URL, command line, OAuth client/server/scopes, headers helper, environment variables, description, and skip-approval fields. `feynman_connector_call` now creates a pending `ask` permission grant before any connector HTTP request or local process spawn when a tool is missing approval, while skip approvals acts as an explicit connector-level allow. Permission cards now render Allow, Block, and Remove actions for pending ask grants. - Verified: Re-drove installed Claude Science connector Settings and inspected its local runtime/SQLite MCP tables and built-in stdio/HTTP MCP logs; reread Pi 0.80.3 extension/session docs. `npm run typecheck`, `npm run build`, and focused connector/settings/context tests passed. Earlier in the slice the full test suite passed (`372/372`). Fresh in-app browser smoke on `http://127.0.0.1:6177/projects/verification/frames/reference-audit?token=science-parity-20260701c` verified project rendering, connector form fields, pending ask Allow/Block/Remove actions, exact scope encoding, and cleanup back to zero permission grants. - Next: Add SSE connector transport, move ask approval from Settings-only into the chat transcript as an approval card, then add agent-specific connector assignment/excluded-tool semantics. ### 2026-07-01 17:49 PDT — open-science-workbench-compute-jobs - Objective: Make the Compute pane behave like a Claude Science control-plane surface by showing real job history, not only provider inventory. - Changed: Added `computeJobs` to workbench state from persisted notebook executions. Jobs now capture provider/tier/status/intent/session/project/run/language/environment/command, Modal remote URL and handle, script path, input/output paths, timing, and bounded error detail. The Compute pane now renders job history first, with cloud-run links and session-kernel rows, then provider setup cards. Compute-specific CSS moved to `src/workbench/ui-style-compute.ts`. - Verified: Rechecked installed Claude Science local runtime/DB/log evidence and the public Claude Science page for compute providers, compute usage, execution logs, environment snapshots, lineage, and provider surfaces. Full `npm test` passed (`377/377`); `npm run typecheck`, `npm run build`, `npm run architecture:check`, and `git diff --check` passed. Fresh server `/api/state` returned 5 compute jobs and 2 Modal jobs; Playwright/Chrome smoke on the `reference-audit` run verified the rendered Compute pane shows 5 jobs, Modal cloud rows, cloud-run links, and stable status-pill geometry. - Next: Add managed scientific environment discovery so the local R/Python notebook kernels can use configured conda/micromamba runtimes when system tools are missing. ### 2026-07-01 18:05 PDT — open-science-workbench-managed-runtimes - Objective: Make local notebook execution use managed scientific runtimes the way Claude Science does, instead of failing when only system `R` is missing. - Changed: Added a shared notebook runtime resolver. It prefers explicit env configuration, then managed local scientific runtimes, then PATH. R session kernels, isolated R cells, Python cells, and environment snapshots now use that resolver. On this Mac, R/Rscript resolve to the installed Claude Science conda env under `~/.claude-science/conda/envs/r/bin/`. Customize → General now shows a `Notebook runtimes` card with command source diagnostics. - Verified: Focused R tests passed, including isolated R through `FEYNMAN_RSCRIPT` with the exact executable recorded in the environment snapshot. A live temp-workspace R smoke with no R env vars set used `/Users/advaitpaliwal/.claude-science/conda/envs/r/bin/R`, preserved session state, printed `42`, and recorded `R version 4.5.3 (2026-03-11)`. Full `npm test` passed (`378/378`); `npm run typecheck`, `npm run build`, `npm run architecture:check`, and `git diff --check` passed. Fresh server `/api/state` and Playwright/Chrome Customize → General smoke verified the managed runtime card. - Next: Add live queued/running compute lifecycle controls and first-class managed environment create/list/install flows. ### 2026-07-01 18:54 PDT — open-science-workbench-compute-lifecycle - Objective: Close the Claude Science compute lifecycle gap by making notebook jobs visible and controllable while they are running. - Changed: Notebook execution now creates a stable job id before launch, tracks active jobs in `/api/state`, and supports `/api/compute/job/action` for cancel/terminate and retry. Local process cells, Modal CLI cells, and persistent session kernels now terminate process groups on Stop. Modal cancellations append pending terminate records under `.feynman/workbench/compute-pending-terminate.jsonl`. The Notebook pane now shows Stop while a cell runs, and Compute rows expose Stop for active jobs plus Retry for stored notebook jobs. - Verified: Focused lifecycle tests prove an authenticated long-running Bash job appears as running, Stop persists a stopped compute record, Retry creates a completed rerun, and Modal cancellation records a pending terminate row. Full `npm test` passed (`383/383`); `npm run typecheck`, `npm run build`, `npm run architecture:check`, and `git diff --check` passed. Fresh server `http://127.0.0.1:6191/?token=compute-lifecycle-20260702` browser smoke verified Notebook Stop, Compute row Retry, one stopped plus one completed matching compute job, zero console errors, and screenshot `/tmp/feynman-compute-lifecycle-smoke.png`. - Next: Run a bounded Modal-backed research/replication job that returns real artifacts, then wire remaining NVIDIA NIM and connector OAuth gaps. ### 2026-07-01 19:05 PDT — open-science-workbench-reviewer-strip - Objective: Make the transcript feel like Claude Science's reviewed research flow by surfacing verification confidence inline, not only in a separate provenance pane. - Changed: Added a compact transcript reviewer strip sourced from real `state.checks` records. The strip shows reviewer status and check count, expands into individual pass/fail/warning rows, and routes `Jump to claim` to Provenance checks/evidence plus `Go to transcript` to the Execution trace. - Verified: Re-drove the installed Claude Science example project and observed the live reviewer strip/action pattern. Fresh server `http://127.0.0.1:6192/projects/verification/frames/reference-audit?token=reviewer-strip-20260702` browser smoke verified one reviewer strip, five expanded checks, working claim/transcript actions, zero console errors, and screenshot `/tmp/feynman-reviewer-strip-smoke.png`. `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` passed (`383/383`). - Next: Run a bounded Modal-backed research/replication job that returns real artifacts, then wire remaining NVIDIA NIM and connector OAuth gaps. ### 2026-07-01 19:14 PDT — open-science-workbench-modal-replication - Objective: Prove the cloud-compute research loop with a real Modal-backed analysis that returns artifacts into the Feynman workbench, not just a smoke cell. - Changed: Ran a Modal cloud Python notebook job through the authenticated `/api/notebook/execute` product path with `executionMode: "modal"`. The job generated a bounded Michaelis-Menten parameter-recovery analysis and returned `outputs/modal-replication-demo/brief.md`, `outputs/modal-replication-demo/fit-grid.csv`, and `outputs/modal-replication-demo/summary.json` through the Modal artifact collector. - Verified: Execution `5c67ac47-9f74-4e95-851c-e95329edd276` completed with Modal remote run `https://modal.com/apps/companion/main/ap-nn6L8TyxGLxlNVxiau9AtB`, three output paths, and three artifact snapshots. Fresh browser smoke on `http://127.0.0.1:6192/projects/workspace/frames/modal-replication-demo?token=reviewer-strip-20260702` verified the new workspace run, returned artifacts, Compute pane cloud job row, Notebook pane code/output provenance, zero console/page errors, and screenshots `/tmp/feynman-modal-replication-run.png`, `/tmp/feynman-modal-replication-compute.png`, and `/tmp/feynman-modal-replication-notebook.png`. `git diff --check` and full `npm test` passed (`383/383`) after the generated workspace artifacts landed. - Next: Implement connector OAuth handshake beyond stored OAuth metadata, then wire NVIDIA hosted NIM calls when `NVIDIA_API_KEY` is available. ### 2026-07-01 19:48 PDT — open-science-workbench-connector-oauth - Objective: Close the connector OAuth gap so custom science connectors can authenticate like the Claude Science connector surface instead of only storing OAuth metadata. - Changed: Added local OAuth token and pending-state stores, PKCE start/callback/disconnect API routes, Customize/resource Connect/Reconnect/Disconnect OAuth actions, bearer-token injection for Streamable HTTP/SSE connector requests, and redacted OAuth diagnostics. Duplicate callback loads now return the already persisted token for recently completed states, so browser/provider retries do not turn a successful connection into a false state-missing failure page. - Verified: Focused OAuth/connector/settings tests passed (`12/12`), including PKCE exchange, duplicate callback idempotence, disconnect cleanup, redacted diagnostics, and bearer Authorization forwarding into MCP requests. Fresh browser smoke on `http://127.0.0.1:6194/projects/workspace/frames/modal-replication-demo?token=oauth-clean-smoke-20260702` completed a real Customize OAuth popup/callback through a local provider, reloaded the route, showed `Disconnect OAuth`, captured `/tmp/feynman-oauth-connector-smoke.png`, restored settings/token files, and recorded zero browser console or failed-response errors. `git diff --check`, `npm run typecheck`, `npm run build`, `npm run architecture:check`, and full `npm test` passed (`385/385`). - Next: Wire NVIDIA hosted NIM calls once `NVIDIA_API_KEY` is present, and visually verify Diff/Restore on the next real snapshot-backed mutation. ### 2026-07-01 19:52 PDT — open-science-workbench-diff-restore-visual - Objective: Close the remaining visual verification gap for artifact version Diff/Restore controls on a real snapshot-backed workspace artifact. - Changed: No product code changed in this slice. The smoke temporarily added a valid JSON field to `outputs/modal-replication-demo/summary.json`, used the live browser UI to open the artifact `Versions` pane, clicked `Diff`, clicked `Restore`, and let the workbench record the restore action through the existing artifact-version path. - Verified: Fresh browser smoke on `http://127.0.0.1:6196/projects/workspace/frames/modal-replication-demo?token=VizUS6A9Y3ZzBRytMzwmCYhNpsvbyEX7` rendered the snapshot diff, restored the saved snapshot, and returned `outputs/modal-replication-demo/summary.json` to checksum `3c0ffb448e54595441e0ddb573dea95d9df3dc7358f5cdada824468fe897d6d0`. Screenshots: `/tmp/feynman-diff-restore-diff.png` and `/tmp/feynman-diff-restore-restored.png`. Browser console and failed-response counts were zero. - Next: Wire NVIDIA hosted NIM calls once `NVIDIA_API_KEY` is present. ### 2026-07-01 20:09 PDT — open-science-workbench-annotations - Objective: Close the Claude Science artifact feedback loop where researchers mark an artifact and ask the agent to revise from that marked context. - Changed: Added local artifact annotation persistence under `.feynman/workbench/annotations.json`, authenticated `/api/artifact/annotation` upsert/remove, `artifactAnnotations` in `/api/state`, annotation records attached to artifact versions, an Annotations tab in the artifact preview, selection-to-anchor capture for text previews, save/delete controls, and a revision-request bridge into the real chat composer. Workbench chat prompts now include matching artifact annotations so Pi sees saved revision notes during follow-up turns. - Verified: Focused annotation/workbench tests passed (`27/27`) for storage, state/version exposure, API mutation, and prompt injection. Fresh browser smoke on `http://127.0.0.1:6204/?token=hONlJxNcv4GEKynI7PKPtLhj2_7wmg9J` saved a real annotation, verified state, populated the composer with the revision request, measured no annotation-panel horizontal overflow, captured `/tmp/feynman-artifact-annotation-smoke.png`, recorded zero browser errors, and removed the smoke annotation. Final gate passed: `git diff --check`, `npm run typecheck`, `npm run build`, `npm run architecture:check`, and full `npm test` (`388/388`). - Next: Wire NVIDIA hosted NIM calls once `NVIDIA_API_KEY` is present. ### 2026-07-01 20:30 PDT — open-science-workbench-new-sessions - Objective: Match Claude Science's project-local `New` session affordance so Feynman can start a blank research chat frame instead of only treating artifact groups as sessions. - Changed: Persisted chat sessions now appear as first-class workbench runs with `source: "chat"` and `status: "chat"`, project/session counts include chat-only frames, and the session rail has a `New` button backed by authenticated `/api/chat/session/new`. Blank frames navigate to `/projects/<project>/frames/<session-id>`, open with no selected artifact, and render an empty transcript rather than seeded artifact messages. The chat-run conversion and new-session tests live in split files to keep architecture limits intact. - Verified: Re-drove the installed Claude Science example project and observed the real `New` project-session control before implementing. Focused new-session/workbench tests passed (`26/26`), and a fresh Playwright smoke on `http://127.0.0.1:6204/?token=M_b2Y0RWVAlAphyYUMsHfwqWwt1ZBaqF` clicked `New`, landed on `/projects/workspace/frames/session-20260702032846-709a90`, saw a `chat` session with `0 artifacts`, rendered `No transcript yet`, confirmed zero active artifact rows and zero console errors, captured `/tmp/feynman-new-session-smoke.png`, and removed the temporary session file. Final gate passed: `git diff --check`, `npm run typecheck`, `npm run build`, `npm run architecture:check`, and full `npm test` (`390/390`). - Next: Continue Claude Science parity on session files/lineage and richer chat-side approval or tool activity surfaces. ### 2026-07-01 21:02 PDT — open-science-workbench-files-session-tools-and-models - Objective: Continue Claude Science parity by making Files a first-class project rail surface, making the chat transcript read like a science session with visible tools/agents/compute/review state, and adding a real model selector that routes into Pi instead of a cosmetic dropdown. - Changed: Added Claude-style project rail actions (`New`, `Customize`, `Files`) and moved `New` out of the session header. The `Files` rail opens a project-wide artifact browser with search, source selector, grid/list toggles, grouped session sections, upload cards, thumbnails for image artifacts, and stable list fallback. Added transcript jump controls plus a bounded science-session tool shelf that renders real Feynman resources as grouped chips: research commands fill the composer, specialist chips update session config, connector chips open Customize, and compute chips open the Compute pane. Added a composer `model-selector` that defaults to Auto, can pin a `provider/model` value per session, persists through the chat config API, and passes that value to Pi as `explicitModelSpec`. Split new helpers into `src/workbench/ui-client-science-tools.ts` and `src/workbench/ui-client-model-selector.ts` so architecture stays green. - Verified: Re-drove the installed Claude Science app, including dashboard/project/files/customize/session screenshots and route/API/testid traces, before implementing. Focused Files/New/model tests passed (`8/8`). Fresh Playwright smoke on `http://127.0.0.1:6210/projects/workspace/frames/open-science-workbench?token=688ja4Amkp1ylwJt9uiaY7QZIHwqL3mW` verified 4 tool groups, 22 real tool chips, visible bounded tool-shelf geometry, skill-chip-to-composer insertion, compute-chip right-pane switching, zero console errors, zero failed responses, and screenshot `/tmp/feynman-science-session-tool-shelf.png`. A second Playwright smoke on `http://127.0.0.1:6210/projects/workspace/frames/open-science-workbench?token=Xxchw4rYq_Npb-aTOnU4dTYqB1CaiVe_` pinned `openai/gpt-5.5`, verified persisted session config, cleared back to Auto, recorded zero console/network errors, and captured `/tmp/feynman-model-selector-smoke.png`. Final gate passed: `git diff --check`, `npm run typecheck`, `npm run build`, `npm run architecture:check`, and full `npm test` (`393/393`). - Next: Continue Claude Science parity on turn-level artifact opening, composer attachment/import affordances, and live tool/activity trace density. ### 2026-07-02 01:28 PDT — open-science-workbench-focused-layout-and-pdf-text - Objective: Remove the crowded three-column workbench frame and move closer to Claude Science's focused project/chat plus artifact-drawer structure while adding document-grade PDF selection anchors. - Changed: Reworked the active frame into a single centered science session column with the project sidebar hidden, the transcript capped, the composer visible in the first viewport, and the Files/artifact drawer below the chat instead of squeezing the chat from the side. Muted scrollbar styling and disabled horizontal page overflow. Added `pdfjs-dist` PDF text extraction through `/api/file/pdf-text`, split PDF/selection client scripts out of the preview bundle, rendered selectable PDF text pages under the PDF iframe, and persisted PDF annotation page/line/prefix metadata into Pi revision prompts. - Verified: Live in-app browser on `http://127.0.0.1:6174/projects/active-plans/frames/open-science-workbench?token=Vw1tKOGiTyDv9WUylMEPsP07O3quWKKf` measured composer input at 568-628.6px in a 720px viewport, drawer start at 655.6px, project sidebar `display:none`, zero horizontal overflow offenders, muted scrollbar colors, and zero console errors; screenshot `/tmp/feynman-open-science-workbench-final.png`. Live PDF route extracted 11 pages from `outputs/scaling-laws.pdf` without truncation. Focused annotation/files tests passed (`7/7`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` passed (`408/408`). - Next: Continue Claude Science parity by making live Pi tool/activity cards and artifact opening feel native inside the transcript, then wire remaining connector/tool approvals into the chat flow. ### 2026-07-02 01:50 PDT — open-science-workbench-claude-frame-density - Objective: Correct the workbench structure back toward the installed Claude Science project frame after the focused single-column pass proved too unlike the reference and too crowded in practice. - Changed: Added `ui-style-frame.ts` as the final layout override to restore the desktop left project rail, center transcript/composer, and right files/activity/preview split. Removed top-level page scrolling and horizontal overflow, wrapped the right-pane tabs instead of forcing a horizontal scrollbar, compacted the transcript execution plan to a single next-step card, compacted the research trace to one latest-artifact row, and made transcript tool groups open the right-side Activity pane filtered to tools. - Verified: Live in-app browser on `http://127.0.0.1:6174/projects/active-plans/frames/open-science-workbench?token=hLeE2tyPWWPFMZ6A7ZsMKmwQCIiv8Ecj` measured a 1280x720 three-pane frame with no horizontal overflow, document scroll height equal to viewport height, body overflow hidden, project/sidebar/conversation/right-pane heights all 664px, zero inline plan rows, one compact plan preview row, and one tool-group activity opener. Clicking the compact tool group switched the right pane to Activity, activated the Tools filter, showed two activity rows, and recorded zero console errors. Screenshots: `/tmp/feynman-frame-final-rendered.png` and `/tmp/feynman-frame-activity.png`. Gates passed: focused workbench HTML tests (`2/2`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`; full `npm test` passed earlier in the slice before the final density compaction (`408/408`). - Next: Continue Claude Science parity by making generated artifact tiles and open artifact tabs behave like the Claude right-pane tab strip, then wire viewport context from the active preview into chat turns. ### 2026-07-02 02:25 PDT — open-science-workbench-artifact-tabs-context - Objective: Continue Claude Science parity by making the right pane behave like an artifact/file tab workspace and by giving chat turns the active preview context. - Changed: Added open artifact tabs with active/close behavior, capped at eight paths, plus a `viewportContext` payload for chat, stream, and steer requests. Workbench prompts now include the active preview path, open artifact tabs, selected preview tab, right pane tab, and bounded previews for open text artifacts. The frame now uses a wider left rail, capped project switcher, single-row horizontally scrollable right-pane mode tabs, and compact right-pane file rows so artifacts are selectable without being clipped by the preview pane. - Verified: Installed Claude Science source showed `openTabs`, `activeTabId`, artifact tab binding, and `viewport_context` as the reference behavior. Live in-app browser verified two artifact tabs could open, the active tab changed, closing the last tab reduced the count to `0`, reset the preview header to `Preview / ready`, kept body/document overflow off, and kept the right mode tabs to a single `47px` row. Latest served HTML on `http://127.0.0.1:6174/projects/active-plans/frames/code-organization-review?token=-L1Qfu5Blf4n_cSblY--q4Y6VL5qmc4w` includes the new three-pane grid, compact right-pane file-row CSS, and explicit `closeArtifactTab` path. Gates passed: focused workbench tests (`6/6`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`409/409`). - Next: Continue Claude Science parity on actual chat/tool execution affordances: streaming Pi tool calls into the transcript with less chrome, and making open artifact tabs feed every message turn while the user chats in the same project frame. ### 2026-07-02 02:52 PDT — open-science-workbench-transcript-tool-density - Objective: Make the active Feynman frame feel like a Claude Science-style research chat instead of a crowded debug dashboard, especially around Pi/tool activity and visible scrollbars. - Changed: Collapsed transcript tool events into a single compact bundle with an Activity jump, auto-opening only for approvals/errors. Collapsed the science session tool shelf into a 42px `Session tools` row with status chips, kept the full tool grid available behind the drawer, widened the center conversation by resizing the three-pane frame, hid the transcript scrollbar while preserving scroll, and fixed first-render transcript scroll so the Pi status card is not clipped on load. - Verified: Live served frame at `http://127.0.0.1:6174/projects/active-plans/frames/open-science-workbench?token=PhwLFMn5VKpJ38mjTyAYHsa8xQVC4v1V` rendered the center-first three-pane layout with `scrollbarWidth: none`, first-render `scrollTop: 0`, closed `Session tools` row at `42px`, closed tool bundle at `48px`, and visible Activity jump. Final screenshot kept at `outputs/playwright/open-science-workbench-frame-1440-final.png`. Gates passed: focused workbench tests (`29/29`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`409/409`). - Next: Continue Claude Science parity on live chat execution: richer approval prompts, real running tool progress, and tighter message/artifact handoff while preserving the now-compact frame. ### 2026-07-02 03:34 PDT — open-science-workbench-frame-declutter-and-native-previews - Objective: Correct the active Open Science Workbench frame after the visible UI still felt crowded, with too many transcript cards and exposed scrollbars compared with the Claude Science research-chat frame. - Changed: Collapsed the transcript's trace, plan, and reviewer card stack into one compact `Research state` strip with Plan/Notebook/Review actions. Kept Files, Activity, Plan, and Notebook as primary right-pane modes and moved Library, Execution, Compute, Agent, and Provenance behind a More selector. Moved artifact preview secondary tabs behind a More selector. Hid internal transcript/right-pane/preview scrollbars while preserving scroll. Split the new research-state and science-preview code into dedicated modules so the architecture gate stays green. Added shared file-type handling plus genome, molecule, and mmCIF/PDB preview paths for science artifacts. - Verified: Fresh server `http://127.0.0.1:6174/projects/active-plans/frames/open-science-workbench?token=k_oJ0u1Y9nwhiNSmJksAqtMOMZ0u3Wzg` rendered a two-column frame with `project-sidebar display:none`, no horizontal overflow, `body overflow:hidden`, transcript/right-pane/preview `scrollbarWidth:none`, one `Research state` strip, zero rendered trace cards, zero rendered plan cards, zero rendered reviewer cards, one artifact tray, four primary right tabs plus More, preview More selector, zero console errors, zero failed responses, and screenshot `outputs/playwright/open-science-workbench-frame-1440-final.png`. Final gates passed: focused workbench tests (`25/25`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`409/409`). - Next: Continue Claude Science parity on live chat/tool execution and live science connector/database execution. ### 2026-07-02 03:58 PDT — open-science-workbench-claude-quiet-frame - Objective: Correct the still-crowded active frame against the live installed Claude Science app, whose first screen is a quiet project list and whose deeper project/session surfaces keep files and artifacts behind explicit workspace affordances. - Changed: Reworked the active frame default into a centered 1016px session/chat column with no permanent right rail, hid the transcript header/Pi strip/science tool shelf/session action buttons from the first viewport, moved `New`, `Files`, and `Workspace` into the top bar, changed the right pane into a slide-in workspace drawer with Close, routed `Files` to the full artifact overlay, and split drawer behavior into `src/workbench/ui-client-workspace.ts`. Removed stale research-trace/reviewer-card client code after the compact `Research state` strip replaced those surfaces. - Verified: Fresh server `http://127.0.0.1:6174/projects/active-plans/frames/open-science-workbench?token=j3xplTFrbdyk-FeWK2V1zPjonOH9zuo2` rendered the default frame with `controlGrid: 1016px`, `conversationRect.width: 1016`, right pane hidden off-canvas at `x:1442`, `horizontalOverflow:0`, `bodyOverflowY:hidden`, transcript header/Pi strip/science tools/session actions all `display:none`, and screenshot `outputs/playwright/open-science-workbench-declutter-chat.png`. The Workspace button opened the drawer at `x:880`, Close hid it again, and Files opened the full overlay with the drawer still hidden; screenshots: `outputs/playwright/open-science-workbench-declutter-workspace.png` and `outputs/playwright/open-science-workbench-declutter-files.png`. Gates passed: focused workbench tests (`25/25`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`409/409`). - Next: Continue Claude Science parity on live chat/tool execution and live science connector/database execution. ### 2026-07-02 04:10 PDT — open-science-workbench-chat-frame-cleanup - Objective: Remove the remaining visible crowding in the Claude-style active frame after the first quiet-frame pass still exposed internal Pi/tool noise and a bulky research-state block in the default chat. - Changed: Filtered completed low-signal internal Pi session/tool events out of the default transcript while preserving active, failed, output-bearing, and approval-bearing tool events. Compacted `Research state` into a skinny status row with clickable state pills instead of duplicated action buttons. Reduced the session header to a quiet title row, tightened the frame vertical spacing, and made turn artifact cards smaller so the chat remains the first-viewport focus. - Verified: Restarted the local workbench at `http://127.0.0.1:6174/?token=gzldpwh2Jc93yqi2bS90P6Hlg-455Jkv` and opened the patched frame in the in-app browser at `/projects/active-plans/frames/open-science-workbench`. Headless browser metrics showed `horizontalOverflow:0`, `bodyOverflowY:hidden`, no visible scrollbars, a `44px` session header, zero visible transcript tool groups, one compact state row, and screenshot `outputs/playwright/open-science-workbench-quiet-v2.png`. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, focused workbench tests (`25/25`), and full `npm test` (`409/409`). - Next: Continue Claude Science parity on live science connector/database execution and richer running-tool/approval progress without reintroducing dashboard chrome. ### 2026-07-02 04:22 PDT — open-science-workbench-built-in-database-search - Objective: Move Feynman closer to Claude Science's bundled science database behavior by making core public database search executable from chat without requiring the user to add an MCP connector first. - Changed: Added the read-only Pi tool `feynman_science_database_search` for PubMed, ClinicalTrials.gov, and ChEMBL. Workbench chat prompts now advertise the built-in database path even in a clean workspace, and the PubMed, Clinical Trials, and ChEMBL connector cards now show as configured built-in read-only sources with the executable tool listed. - Verified: Focused tests passed for the new tool and prompt/resource exposure (`10/10`). A live smoke called the real public APIs and returned PubMed PMID `30684591` with DOI `10.1016/j.canlet.2019.01.017`, ClinicalTrials.gov `NCT04397926`, and ChEMBL molecule `CHEMBL941`. The restarted workbench at `http://127.0.0.1:6174/projects/active-plans/frames/open-science-workbench?token=vDUiiuw3S85PVwK3gWt1M1PxEjxuL1Hp` showed PubMed, Clinical Trials, and ChEMBL as `CONFIGURED` built-in database tools in Customize, kept `horizontalOverflow:0`, and returned to the quiet chat frame. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`412/412`). - Next: Continue on richer running-tool/approval progress without reintroducing dashboard chrome, then broaden the built-in database set beyond PubMed, ClinicalTrials.gov, and ChEMBL. ### 2026-07-02 04:43 PDT — open-science-workbench-tool-progress - Objective: Make live Pi/tool activity read like Claude Science's scientific work log instead of a raw debug feed, while keeping the quiet chat frame and hidden scrollbars. - Changed: The Pi stream mapper now keeps raw `toolName` for provenance and promotes `human_description` to the visible transcript label. Transcript tool groups now render one compact research-progress header, progress chips, plan/environment/artifact/database/code classification, human step summaries, and stripped argument details so the user sees `Running ESMFold on IS621 sequence` rather than raw `bash`/JSON noise. - Verified: Focused workbench tests passed (`25/25`). Final gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`412/412`). Fresh browser metrics on `http://127.0.0.1:6174/projects/active-plans/frames/open-science-workbench?token=fCnVsluWSNNZKc9Ieo2mHQSSdW4xuxgr` showed `horizontalOverflow:0`, `bodyOverflowY:hidden`, transcript `scrollbarWidth:none`, one compact state row, and zero persisted transcript tool groups after removing the temporary smoke session. A non-persistent smoke frame rendered Claude-shaped tool progress with human labels, active/plan/artifact/environment chips, and screenshot `outputs/playwright/open-science-workbench-tool-progress-smoke.jpg`. - Next: Broaden live science database/tool execution beyond PubMed, ClinicalTrials.gov, and ChEMBL, then improve PDF text-selection rectangle anchoring. ### 2026-07-02 04:55 PDT — open-science-workbench-expanded-databases - Objective: Move the built-in database tool closer to Claude Science's broad science-search behavior without depending on custom MCP setup or anonymous APIs that are currently rate-limited. - Changed: Expanded `feynman_science_database_search` from PubMed, ClinicalTrials.gov, and ChEMBL to seven no-setup public sources: PubMed, Europe PMC, Crossref, arXiv, DataCite, ClinicalTrials.gov, and ChEMBL. The tool now normalizes PMIDs/PMCIDs, arXiv IDs, DOIs, dataset DOI metadata, NCT IDs, ChEMBL IDs, citation counts, source URLs, and endpoint provenance. Customize marks all seven as configured built-in database tools, and the workbench prompt advertises the expanded source list. - Verified: OpenAlex and Semantic Scholar anonymous searches were probed and returned rate-limit responses, so they were left out of the no-setup built-ins. Focused database/settings/context tests passed (`11/11`). Live tool smokes returned Crossref DOI `10.1089/crispr.2020.29090.ede`, Europe PMC PMID `36357583`, arXiv ID `2607.01232v1`, and DataCite DOI `10.17632/ys4gwt7m6n.1`. Browser state and Customize UI on `http://127.0.0.1:6174/projects/active-plans/frames/open-science-workbench?token=620MatmBZMg3AGe93SsO04HWZr1813aO` showed all seven sources configured with `feynman_science_database_search` and `horizontalOverflow:0`. Final gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`413/413`). - Next: Improve PDF text-selection rectangle anchoring, then add deeper specialty public databases where the API is stable enough for a no-setup built-in. ### 2026-07-02 05:22 PDT — open-science-workbench-pdf-text-selection-rectangles - Objective: Make PDF selections behave like visible scientific artifact annotations rather than metadata-only line anchors. - Changed: PDF text selections now capture selected rectangle coordinates from the extracted text layer, carry those coordinates through the refinement panel and annotation save API, render saved PDF text-selection markers as quiet green boxes over the selectable text, clear draft markers after save, and remove the nested scrollbar from the PDF text layer. - Verified: Focused annotation/files tests passed (`7/7`), `npm run typecheck`, `npm run build`, `git diff --check`, and the full suite passed (`413/413`) before the final duplicate-marker cleanup, with focused tests/typecheck/build rerun afterward. Rebuilt browser smoke on `http://127.0.0.1:6174/projects/workspace/frames/scaling-laws?token=Lnirs5Lc5QknwV1cOvC7N_W4hNf59kpt` rendered one marker for a temporary annotation on `outputs/scaling-laws.pdf`, measured `pdfLayerOverflowY: visible` and `horizontalOverflow:0`, captured `outputs/playwright/open-science-workbench-pdf-selection-marker-centered.jpg`, and removed the temporary annotation afterward. The active Open Science Workbench frame also measured `bodyOverflowY:hidden`, no horizontal or vertical document overflow, transcript `scrollbarWidth:none`, zero visible tool groups, one compact state row, one artifact card, and the workspace drawer off-canvas. - Next: Add deeper specialty public science sources where no-setup API behavior is stable enough, and keep exact PDF-renderer glyph anchoring as a later renderer-level improvement. ### 2026-07-02 08:54 PDT — react-shell-artifact-inspector - Objective: Continue the React/Vite workbench migration by replacing the cramped raw artifact text dump with a Claude Science-shaped artifact inspector backed by Feynman's real version, execution, and verification state. - Changed: Added `workbench-web/src/artifacts.ts` for artifact preview classification, CSV/TSV parsing, download URLs, byte formatting, and provenance selectors. The React Files panel now opens artifacts into Preview and Provenance modes with download/copy-path actions, bounded internal text scrolling, table/image/PDF/text preview paths, file metadata, version rows, execution rows, verification rows, and a wider/muted-scrollbar right rail. - Verified: In-app browser smoke on `http://127.0.0.1:51274/app-shell/projects/active-plans/frames/open-science-workbench?token=cxf8y2kVEXs0PJs3Zjpv1WGORRRtWyfc` selected the real `Open Science Workbench` artifact, verified the encoded download route, measured no document overflow, kept the panel scroller bounded, and rendered Provenance sections `Versions`, `Execution`, and `Verification`; screenshot `outputs/playwright/feynman-react-shell-artifact-preview.png`. Gates passed: `npm run typecheck`, `npm run build:workbench-web`, `npm run build`, `npm run architecture:check`, `git diff --check`, focused React shell tests (`4/4`), and full `npm test` (`419/419`). - Next: Continue React/Vite parity on Files overlay parity, Customize mutations, notebook/compute panes, artifact edit/diff/restore actions, and annotation/refinement flows before flipping the default `/projects/...` route. ### 2026-07-02 09:02 PDT — react-shell-files-scope-browser - Objective: Make the React Files surface behave like a project/workspace file browser instead of a cramped current-run-only list. - Changed: Added `workbench-web/src/files.ts` for Run/Project/Workspace artifact scoping, scope counts, category counts, category filtering, and search filtering. The Files panel now renders compact scope tabs, category chips, run-aware file row metadata, and an internally scrolling artifact list that can handle the whole workspace without creating page overflow. - Verified: In-app browser smoke on the React shell measured Project scope with `53` artifacts and Workspace scope with `202` artifacts, category filters including plan/data/visual/output groups, zero document overflow, side panel `410x720` at `x=870`, and empty app console warnings/errors; screenshot artifact saved at `outputs/playwright/feynman-react-shell-files-scope.png`. Gates passed: `npm run typecheck`, `npm run build:workbench-web`, `npm run build`, `npm run architecture:check`, `git diff --check`, focused React shell tests (`5/5`), and full `npm test` (`420/420`). - Next: Continue React/Vite parity on full Files overlay/import/upload actions, Customize mutations, notebook/compute panes, artifact edit/diff/restore actions, and annotation/refinement flows before flipping the default `/projects/...` route. ### 2026-07-02 09:16 PDT — react-shell-artifact-edit-version-actions - Objective: Bring Claude Science-style editable artifact history into the React/Vite shell without faking the behavior. - Changed: Added React artifact action helpers for the existing authenticated `/api/artifact/edit`, `/api/artifact/version/diff`, and `/api/artifact/version/restore` contracts. The selected artifact inspector now has an Edit action for text artifacts, an inline textarea editor with Save/Cancel and disabled-save state, preview refresh after save, per-version Diff/Restore controls, and a bounded diff panel with added/removed counts. - Verified: In-app browser smoke opened the real `Open Science Workbench` markdown artifact, loaded a 92 KB inline editor with Save disabled before changes and no document overflow, then selected `outputs/modal-replication-demo/summary.json` from Workspace scope and rendered a saved snapshot diff showing `+1/-2`, two Diff buttons, two Restore buttons, and no horizontal diff scroll. Gates passed: `npm run typecheck`, `npm run build:workbench-web`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`421/421`). - Next: Continue React/Vite parity on full Files overlay/import/upload actions, Customize mutations, notebook/compute panes, and annotation/refinement flows before flipping the default `/projects/...` route. ### 2026-07-02 09:28 PDT — react-shell-files-overlay-import - Objective: Bring Claude Science-style Files browsing and import into the React/Vite shell using the real Feynman attachment APIs. - Changed: Added `workbench-web/src/uploads.ts` for attachment download/filter/preview helpers. The React shell now has a hidden multi-file input, composer and Files-panel Import controls, selectable upload rows, upload preview/download/remove actions, and a full-viewport Files overlay with scope tabs, search, category filters, upload rows, artifact rows, and shared selected preview behavior. - Verified: Seeded a disposable `react-import-smoke.csv` through the authenticated `/api/chat/attachment` endpoint, reloaded the React shell, verified the visible upload row, preview text, exact download route, full overlay geometry, and no document overflow, then removed the upload through the React UI and confirmed the session had no smoke attachment left. Gates passed: `npm run typecheck`, `npm run build:workbench-web`, `npm run build`, `npm run architecture:check`, `git diff --check`, focused React shell tests (`7/7`), and full `npm test` (`422/422`). - Next: Continue React/Vite parity on Customize mutations, notebook/compute panes, and annotation/refinement flows before flipping the default `/projects/...` route. ### 2026-07-02 09:39 PDT — react-shell-customize-actions - Objective: Make the React Customize surface actionable instead of a read-only catalog. - Changed: Added `workbench-web/src/resources.ts` for resource action derivation. React Customize cards now show metadata, diagnostics, tags, and actions for inserting Pi commands, selecting specialists, toggling package sources, removing stored settings records, and connector OAuth connect/disconnect. - Verified: Browser smoke rendered `42` resource cards with `14` action buttons, inserted `/skill:alpha-research` into the composer, selected the `Researcher` specialist through `/api/chat/config`, measured no document overflow, then reset the session config back to Specialist `None` and reloaded the route to clear local composer text. Gates passed: `npm run typecheck`, `npm run build:workbench-web`, `npm run build`, `npm run architecture:check`, `git diff --check`, focused React shell tests (`8/8`), and full `npm test` (`423/423`). - Next: Continue React/Vite parity on notebook/compute panes and annotation/refinement flows before flipping the default `/projects/...` route. ### 2026-07-02 10:41 PDT — standalone-feynman-correction - Objective: Make Feynman stand alone while keeping Claude Science as a local reference/extraction source only. - Changed: Removed the product path that registered `Claude Science Bio MCP` as a custom local connector and removed onboarding/settings dependence on `~/.claude-science`. Onboarding now suggests and grants `Feynman Bio Tools` through `builtin:feynman_science_database_search`; the connector catalog leads with a configured Feynman-owned bio tools resource; the installed app is represented only as an internal reference diagnostic. Seed fixtures now live under `outputs/open-science-seeds/` and scan as `Open Science Seed Workflows`. R runtime resolution no longer borrows the Claude Science private R conda env. - Verified: Source/state grep found no banned connector/runtime strings after cleanup. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`427/427`). Fresh server `http://127.0.0.1:6224/app-shell/?token=open-science-standalone-20260702` showed onboarding `Feynman Bio Tools`, connector catalog headed by `Feynman Bio Tools`, `Open Science Seed Workflows` with 4 seed runs, no `Claude Science Bio MCP`, no horizontal overflow, and zero browser console errors. Screenshots: `outputs/playwright/feynman-standalone-launcher.png`, `outputs/playwright/feynman-standalone-customize.png`, and `outputs/playwright/feynman-standalone-connectors.png`. - Next: Continue React/Vite parity on notebook/compute panes and annotation/refinement flows, with Claude Science used as a blueprint only. ### 2026-07-02 10:56 PDT — react-shell-notebook-lifecycle - Objective: Bring the React/Vite Notebook pane up to the existing Feynman notebook/compute lifecycle instead of leaving it as a run-only editor. - Changed: Added stable notebook job ids, active-state polling during notebook execution, a React Stop button backed by `/api/compute/job/action`, and a managed-environment form backed by `/api/notebook/environment`. The Notebook Env tab now exposes Python/R create/install controls, action output, session kernels, and environment rows inside the bounded right pane. - Verified: Checked the relevant React controlled-form and Radix Tabs docs before changing the form/tab surface. Focused compute/environment/React tests passed (`15/15`). Browser smoke on `http://127.0.0.1:60062/app-shell/projects/active-plans/frames/open-science-workbench?token=react-notebook-lifecycle-20260702` rendered the Env controls, ran a disposable long Bash cell, observed the running compute job in `/api/state`, stopped it through React, rendered a stopped Compute row with Retry, measured no document overflow, and recorded zero console or failed-response errors. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`427/427`). Screenshots: `outputs/playwright/feynman-react-shell-notebook-lifecycle.png` and `outputs/playwright/feynman-react-shell-notebook-env.png`. - Next: Continue React/Vite parity on annotation/refinement flows, with Claude Science remaining a blueprint rather than a Feynman runtime dependency. ### 2026-07-02 11:18 PDT — react-shell-annotation-refinement - Objective: Bring Claude Science-shaped artifact annotation and refinement into the React/Vite shell while keeping the implementation Feynman-owned. - Changed: Added `workbench-web/src/artifact-refinement.ts` for text-selection, annotation, suggest/apply, and diff helpers. The React artifact inspector now captures selected text from previews and unchanged editors, opens a bounded refinement panel, saves revision notes through `/api/artifact/annotation`, requests Ask/Draft edit suggestions through `/api/artifact/refinement/suggest`, applies edits through `/api/artifact/refinement/apply`, refreshes preview content, records version snapshots, and renders removable annotation rows in both the side Files panel and full Files overlay. - Verified: Focused annotation/edit/React tests passed (`21/21`). Browser smoke in a temporary workspace selected `Original claim.`, saved a Feynman annotation, generated a deterministic edit suggestion, applied it to the artifact file, verified a version record through `/api/state`, captured `outputs/playwright/feynman-react-refinement-smoke.png`, and reported zero console or failed-response errors. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`428/428`). - Next: Run exact React-vs-legacy parity checks and prepare the default `/projects/...` route flip, while keeping media-region React annotations and exact PDF glyph anchoring as separate artifact-preview follow-ups. ### 2026-07-02 11:48 PDT — react-shell-media-annotations - Objective: Bring the React/Vite artifact inspector to parity with Feynman's existing image/PDF point-region annotation model without depending on Claude Science at runtime. - Changed: Image and PDF previews now expose a React `Annotate` toolbar, point/drag-region capture, percent geometry and PDF page metadata, draft and saved media markers, annotation save/remove rows, and `Use in chat` composer insertion. Media artifacts now stay on the media preview path instead of fetching binary/PDF/image files through text preview. - Verified: Focused React/refinement/annotation tests passed (`16/16`). Browser smoke in a temporary workspace saved an image region annotation and a PDF point annotation, verified persisted `/api/state` anchors, rendered saved markers, inserted the image annotation into chat, captured `outputs/playwright/feynman-react-media-annotations.png`, and reported zero console or failed-response errors. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`428/428`). - Next: Run exact React-vs-legacy parity checks and prepare the default `/projects/...` route flip, with exact PDF renderer glyph anchoring left as the artifact-preview follow-up. ### 2026-07-02 15:08 PDT — react-shell-default-route - Objective: Make the React/Vite workbench the default Feynman product route instead of a side `/app-shell` preview. - Changed: `/`, `/index.html`, `/projects`, and `/projects/...` now serve the authenticated React workbench index. `/app-shell/...` remains as a dev/smoke alias and asset namespace. React route helpers now parse and generate both default product paths and `/app-shell` alias paths, so navigation stays in the route family the user opened. - Verified: Browser smoke on `http://127.0.0.1:6244/projects/active-plans/frames/open-science-workbench?token=...` mounted the React shell at `/projects/active-plans/frames/open-science-workbench`, loaded assets from `/app-shell/assets`, rendered Open Science Workbench and Files, reported no legacy shell, no document overflow, zero console errors, and zero failed responses; `/app-shell/projects/...` and `/` launcher also loaded. Screenshot: `outputs/playwright/feynman-react-default-route-flip.png`. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, focused React/server tests, and full `npm test` (`429/429`). - Next: Continue post-flip React hardening on artifact action/menu parity and edge-case route/browser behavior, with exact PDF renderer glyph anchoring left as the artifact-preview follow-up. ### 2026-07-02 18:26 PDT — react-artifact-action-menu - Objective: Close the post-flip React artifact action/menu gap using Feynman-owned APIs and keep Claude Science as a reference only. - Changed: The React artifact inspector now exposes Star/Unstar, Hide/Unhide, Rename, Delete/Restore, View context, Copy link, Export metadata, and configured cloud export. Hidden/deleted artifacts render a bounded recovery list in the side Files panel and full Files overlay, artifact links select via `?artifact=...`, and metadata export includes version, execution, annotation, check, preview, and link context. - Verified: Focused helper/API tests passed (`14/14`). Browser smoke in a disposable workspace on `/projects/workspace/frames/react-action-smoke` selected from the artifact query link, starred, renamed, opened context, copied a deep link, downloaded metadata, exported to a configured local target, verified the cloud export ledger, hid/unhid, deleted/restored, reloaded the copied link, measured no horizontal overflow, and recorded zero console errors and zero failed responses. Screenshot: `outputs/playwright/feynman-react-artifact-actions-smoke.png`. Gates passed: `git diff --check`, `npm run typecheck`, `npm run build`, `npm run architecture:check`, and full `npm test` (`429/429`). - Next: Continue post-flip React hardening on live Pi/tool approval progress, less common route/action edge cases, and shrinking legacy string-rendered shell code once direct callers are covered. ### 2026-07-02 18:47 PDT — react-tool-approval-progress - Objective: Bring live Pi/tool progress and connector approval cards into the default React workbench without introducing any Claude Science runtime dependency. - Changed: Added `workbench-web/src/tool-activity.ts` for Feynman-owned tool-event normalization, status labels, connector approval scope parsing, and permission-record creation. The React transcript now shows compact research-activity cards with bounded payload details, turns pending connector grants into inline Allow tool, Block, Allow connector, and Open Permissions actions, and writes decisions through the existing `/api/resources/settings` endpoint. - Verified: Rechecked the installed Claude Science bundle for inline tool/approval structure and Feynman's Pi stream/connector grant code for the actual event contract. Browser smoke in a disposable workspace rendered a complete `feynman_science_database_search` event and a pending `feynman_connector_call` approval, clicked Allow tool, observed `/api/resources/settings` return `200`, verified `/api/state` contained `connector:lab-mcp:search_pubmed | allow`, measured no horizontal overflow, and recorded zero console errors and zero failed responses. Screenshot: `outputs/playwright/feynman-react-tool-activity-smoke.png`. Gates passed: `git diff --check`, `npm run typecheck`, `npm run build`, `npm run architecture:check`, focused React/connector tests (`20/20`), and full `npm test` (`430/430`). - Next: Continue post-flip React hardening on route/browser edge cases, post-approval retry/continuation, and legacy string-rendered shell retirement once direct callers are covered. ### 2026-07-02 18:54 PDT — react-tool-approval-retry - Objective: Let an approved connector call continue from the same activity card after Pi stops on the approval gate. - Changed: Added a `Retry approved tool` action for approved connector cards. It sends a normal streamed chat continuation through the same authenticated path as the composer, including connector name, tool name, grant scope, and original arguments. Refactored the React send path into `sendChatText` so form submit and approval retry share optimistic transcript, steer-while-busy, stream parsing, and state refresh behavior. - Verified: Browser smoke in a disposable workspace rendered a pending `Local Lab MCP` approval, allowed it, retried from the approved card, verified the second streamed user message carried `Grant: connector:lab-mcp:search_pubmed`, verified the second assistant response rendered a successful `Run Local Lab MCP search_pubmed` event with `PMID 98765`, confirmed `/api/state` still held the allow grant, measured no horizontal overflow, and recorded zero console errors and zero failed responses. Screenshot: `outputs/playwright/feynman-react-tool-retry-smoke.png`. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, focused React/connector tests (`20/20`), and full `npm test` (`430/430`). - Next: Continue post-flip React route/browser edge-case hardening and retire legacy string-rendered shell code only after direct callers are covered. ### 2026-07-02 19:04 PDT — react-route-canonicalization - Objective: Harden default React project/frame routes before retiring legacy shell code. - Changed: Added state-backed route canonicalization in `workbench-web/src/routes.ts` and wired React initial load plus browser back/forward to resolve stale `/projects/:projectId/frames/:runSlug` links. Known routes stay stable, stale frame slugs fall back to the project primary run, unknown projects fall back to the default workbench route, invalid `?artifact=` queries are stripped, and valid artifact deep links are preserved on the canonical route. - Verified: Browser smoke in a disposable workspace opened a stale run with an invalid artifact query and observed replacement to `/projects/workspace/frames/route-smoke`, then opened a stale run with `?artifact=outputs%2Froute-smoke.md` and observed replacement to `/projects/workspace/frames/route-smoke?artifact=outputs%2Froute-smoke.md` with the artifact inspector selected. No horizontal overflow, zero console errors, and zero failed responses. Screenshot: `outputs/playwright/feynman-react-route-canonical-smoke.png`. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, focused React tests (`13/13`), and full `npm test` (`431/431`). - Next: Audit direct callers of the legacy string-rendered shell and retire or shrink only the covered legacy paths. ### 2026-07-02 19:17 PDT — react-legacy-shell-retirement - Objective: Remove the obsolete string-rendered workbench shell now that authenticated product routes serve the React/Vite workbench. - Changed: Converted the last `renderWorkbenchHtml` static test into a React source/CSS contract test covering Files, artifact recovery/actions, refinement, media annotations, chat tool activity, connector approvals, Notebook, Compute, and Customize. Deleted the orphaned `src/workbench/ui.ts`, `src/workbench/ui-client-*`, and `src/workbench/ui-style-*` legacy shell modules. Production now has one workbench UI path: `src/workbench/static-shell.ts` serving the Vite app and `/app-shell/assets`. - Verified: Import scan found no remaining `renderWorkbenchHtml`, `WORKBENCH_*_SCRIPT`, `WORKBENCH_*_STYLES`, `ui-client-*`, or `ui-style-*` references in source/tests/workbench-web. Focused React/source tests passed (`15/15`), combined workbench/server tests passed (`38/38`), and full `npm test` passed (`431/431`). Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, and `git diff --check`. Temp Chrome smoke on `http://127.0.0.1:6255/projects/active-plans/frames/open-science-workbench?token=...` loaded `/app-shell/assets/index-C7ZTOfMm.js`, rendered `.app-shell`, opened the React Files overlay, found no legacy `.dashboard-view`/`.control-view` DOM, measured no horizontal overflow, and recorded zero console errors and zero failed responses. Screenshot: `outputs/playwright/feynman-react-legacy-retirement-smoke.png`. - Next: Deepen Feynman-owned variant/clinical database coverage beyond gnomAD, keeping exact PDF renderer glyph anchoring as the later artifact-preview follow-up. ### 2026-07-02 19:36 PDT — feynman-owned-variant-databases - Objective: Deepen the standalone Feynman Bio Tools connector with owned variant/clinical database coverage instead of depending on Claude Science at runtime. - Changed: Added `extensions/research-tools/science-database-variants.ts` with ClinVar, dbSNP, and CADD adapters behind `feynman_science_database_search`. ClinVar uses NCBI ESearch/ESummary and normalizes VCV/RCV-style accessions, review status, genes, locations, rsIDs, and supporting submissions. dbSNP uses NCBI Variation Services RefSNP lookup and normalizes placements, HGVS/SPDI alleles, frequencies, ClinVar cross-references, citations, and gene context. CADD uses the official single-SNV API with explicit version parsing and RawScore/PHRED output. Runtime prompt context, Settings resources, and Feynman Bio Tools source counts now include ClinVar, dbSNP, and CADD. - Verified: Official ClinVar/E-utilities, NCBI Variation Services, and CADD API docs were checked, with installed Claude Science modules used only as reference structure. Focused mocked database/context/settings tests passed (`14/14`). Live API smoke through the actual tool returned one normalized ClinVar record for `APOE rs7412`, one dbSNP record for `rs7412`, and one CADD record for `GRCh38-v1.7 19-44908822-C-T`. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`432/432`). - Next: Continue deeper Feynman-owned variant utilities: HGVS/SPDI normalization, structural/mitochondrial variant lookup, batch variant handling, and cancer/clinical curation sources. ### 2026-07-02 19:52 PDT — feynman-owned-hgvs-spdi-normalization - Objective: Turn the next Claude Science-style variant utility into a Feynman-owned science source instead of a runtime dependency on the local reference app. - Changed: Added the `variation` source to `feynman_science_database_search` for NCBI Variation Services HGVS/SPDI normalization. The tool now accepts HGVS or SPDI input, supports optional `assembly=...`, returns contextual SPDI, canonical representative SPDI when available, right-shifted HGVS, VCF fields, RSIDs when available, endpoint provenance, and scoped warnings for recoverable endpoint failures. Settings and runtime context expose it as `NCBI Variation Services` under Feynman Bio Tools. - Verified: Official NCBI Variation Services OpenAPI docs and the NCBI SPDI/HGVS service example were checked. Focused database/context/settings tests passed (`14/14`). Live smoke through the actual Feynman tool returned HGVS contextual/canonical output for `NM_000518.4:c.27dupG`; SPDI smoke for `NC_000001.10:12345:0:C` returned contextual/canonical SPDI, HGVS, VCF fields, and an RSID warning instead of failing. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`432/432`). - Next: Continue Feynman-owned variant coverage with structural-variant, mitochondrial-variant, batch-variant, and cancer/clinical curation flows. ### 2026-07-02 20:00 PDT — feynman-owned-batch-hgvs-normalization - Objective: Add responsible batch variant normalization to the Feynman-owned science connector instead of leaving HGVS/SPDI parity at one variant per call. - Changed: The `variation` source now accepts newline- or semicolon-separated HGVS lists and calls NCBI Variation Services `POST /hgvs/batch/contextuals` once. Batch results preserve input order, per-input HGVS validity, contextual SPDI objects/strings, endpoint provenance, truncation state, and optional assembly parameter. SPDI remains single-input because the public batch endpoint is HGVS-specific. - Verified: Official NCBI Variation OpenAPI batch docs were checked and a live POST with two HGVS expressions returned valid contextual SPDI rows. Focused database/context/settings tests passed (`14/14`) including the exact POST body. Live Feynman-tool smoke returned `NM_000518.4:76:G:GG` and `NC_000001.10:12344:T:A` for a two-item batch. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`432/432`). - Next: Continue Feynman-owned variant coverage with structural-variant, mitochondrial-variant, and cancer/clinical curation flows. ### 2026-07-02 20:16 PDT — feynman-owned-gnomad-sv-mitochondrial - Objective: Close the structural-variant and mitochondrial-variant parity gap with Feynman-owned gnomAD GraphQL code, using Claude Science only as a local reference. - Changed: Added `extensions/research-tools/science-database-gnomad.ts` and routed `source: "gnomad"` through it. The tool now supports rsID/short variant search, direct short variant lookup, gene constraint, `sv:<gene>`, `sv-id:<id>` or raw SV IDs, `mito:<gene>`, `mito:<start>-<stop>`, and `mito-id:<id>` or raw `M-...` IDs. Structural consequence genes are bounded with `geneCount` and `genesTruncated` to keep chat output usable. Runtime prompt context and Settings resources now describe gnomAD short/SV/mitochondrial fields, including heteroplasmy. - Verified: Official gnomAD browser/API source and live GraphQL probes confirmed the `gnomad_sv_r4` structural and `gnomad_r4` mitochondrial query families. Focused database/context/settings tests passed (`14/14`). Live Feynman-tool smoke returned TP53 SVs from `gnomad_sv_r4`, chrM `1-50` mitochondrial variants with `M-3-T-C` and `maxHeteroplasmy: 0.997`, and single mitochondrial variant `M-3243-A-G` with `rs199474657`. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`432/432`). - Next: Continue Feynman-owned cancer/clinical curation sources; keep exact PDF renderer glyph anchoring as the artifact-preview follow-up. ### 2026-07-02 20:33 PDT — feynman-owned-civic-cancer-curation - Objective: Add the next cancer/clinical curation slice as Feynman-owned code, with Claude Science kept as a reference source only. - Changed: Added `extensions/research-tools/science-database-civic.ts` and routed `source: "civic"` through `feynman_science_database_search`. The tool now searches CIViC molecular profiles, accepted evidence items, accepted assertions, and exact Entrez gene records through CIViC's public GraphQL API. Runtime prompt context, Settings resources, and Feynman Bio Tools source lists now preserve CIViC profile/evidence/assertion ids, AMP levels, evidence levels, diseases, therapies, and PubMed-backed source URLs. - Verified: CIViC API docs/GraphiQL/help pages and live public GraphQL probes confirmed the query families. Focused database/context/settings tests passed (`15/15`) after splitting CIViC coverage into `tests/science-database-civic.test.ts`, keeping the shared science database test under the hard architecture cap. Live Feynman-tool smoke for `BRAF V600E` returned accepted evidence count `94`, assertion `AID7`, `109` accepted evidence items, and PubMed source `https://pubmed.ncbi.nlm.nih.gov/23031422/`. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`433/433`). - Next: Continue exact PDF renderer glyph anchoring, then add broader Feynman-owned clinical/canceromics utilities where public APIs are stable enough. ### 2026-07-02 20:56 PDT — react-pdf-renderer-glyph-anchoring - Objective: Replace the raw PDF iframe with Feynman-owned PDF.js rendering and exact page-local text/region anchors, using Claude Science only as a reference for behavior. - Changed: Added a React `PdfArtifactPreview` backed by bundled `pdfjs-dist`, the PDF.js worker asset, rendered page canvases, selectable text layers, same-page selection capture, line/prefix inference, saved highlight rectangles, and per-page region annotation overlays. Annotation persistence, exported artifact metadata, and Pi prompt context now carry `rects` arrays in addition to page, line, and bounding-box coordinates. PDF text selections are saved as durable artifact annotations and chat context rather than pretending binary PDFs are inline-editable text artifacts. The static workbench server now serves `.mjs` assets as JavaScript so the bundled PDF worker loads in Chromium. - Verified: Official PDF.js examples and the installed `pdfjs-dist` 6.1.200 API/types were checked, while the installed Claude Science `PdfPreview` bundle was used only as a reference shape. Focused annotation/refinement/source tests passed (`21/21`). Headless rendered browser smoke in a disposable workspace loaded the real React workbench, rendered one PDF canvas and text layer, selected `TP53 responder signal`, saved a PDF text annotation, re-rendered one saved highlight, persisted a rectangle-backed page/line anchor, measured no document overflow, and recorded zero console warnings/errors. Screenshot: `outputs/playwright/feynman-react-pdf-renderer-smoke.png`. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`433/433`). - Next: Continue broader Feynman-owned clinical/canceromics utilities where public APIs are stable enough; keep NVIDIA hosted execution blocked until `NVIDIA_API_KEY` exists locally. ### 2026-07-02 21:12 PDT — feynman-owned-cbioportal-canceromics - Objective: Add the next broader clinical/canceromics utility as Feynman-owned code, using Claude Science only as a local reference and extraction source. - Changed: Added `extensions/research-tools/science-database-cbioportal.ts` and routed `source: "cbioportal"` through the existing `feynman_science_database_search` tool. The source now supports cBioPortal study search, exact study detail with sample/patient counts and molecular profiles, cancer-type lookup, sample listing, clinical-attribute listing, and bounded gene mutation rows via cBioPortal's public REST API. Settings/Customize now lists cBioPortal as a configured Directory source, backs the Cancer Models preset with the built-in source, and runtime prompt context preserves cBioPortal study IDs, cancer type IDs, molecular profile IDs, sample/patient IDs, gene symbols, Entrez IDs, mutation coordinates, protein changes, source URLs, and endpoint provenance. - Verified: Official cBioPortal API docs and live `/api/v2/api-docs`/REST probes confirmed the study, profile, clinical-attribute, sample, cancer-type, gene, and mutation-fetch route shapes. The installed Claude Science `cbioportal_studies` module was used only as reference structure. Focused mocked cBioPortal/context/settings tests passed (`10/10`), focused science database tests passed (`9/9`), and live Feynman-tool smoke returned melanoma study search results, `msk_impact_2017` detail with `10945` samples and mutation/CNA/SV profiles, plus `BRAF` mutation rows with total count `592`. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`435/435`). - Next: Continue broader Feynman-owned clinical/canceromics utilities with ClinGen, Open Targets, DepMap download-compatible paths, and COSMIC-compatible public routes where stable/no-setup access exists. ### 2026-07-02 21:23 PDT — feynman-owned-open-targets-clinical-genomics - Objective: Add Open Targets as a Feynman-owned clinical-genomics source for target-disease-drug evidence, without exposing a raw Claude Science GraphQL connector or requiring `~/.claude-science`. - Changed: Added `extensions/research-tools/science-database-open-targets.ts` and routed `source: "opentargets"` through `feynman_science_database_search`. The source supports entity search, exact target records with associated diseases and clinical candidates, disease records with associated targets and clinical candidates, disease-target and disease-drug focused modes, drug mechanism records, and bounded target-disease evidence rows. Settings/Customize now lists Open Targets as a configured Directory source and backs the Human Genetics preset with the built-in source. Runtime prompt context now preserves Open Targets Ensembl IDs, EFO/MONDO IDs, ChEMBL drug IDs, association scores, datasource IDs, clinical stages, mechanisms/action types, source URLs, and endpoint provenance. - Verified: Official Open Targets GraphQL docs and live public GraphQL probes confirmed search, target, disease, drug, disease-target, disease-drug, and evidence query shapes. The installed Claude Science `mcp_clinical_genomics/open_targets.py` and wrapper tools were used only as reference structure. Focused mocked Open Targets/context/settings tests passed (`10/10`), focused science database tests passed (`11/11`), and live Feynman-tool smoke returned `BRAF melanoma` search hits, BRAF target disease/candidate context, cancer-associated targets, bevacizumab mechanism, and BRAF-melanoma evidence rows. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`437/437`). - Next: Continue broader Feynman-owned clinical/canceromics utilities with ClinGen, DepMap download-compatible paths, and COSMIC-compatible public routes where stable/no-setup access exists. ### 2026-07-02 21:38 PDT — feynman-owned-clingen-clinical-curation - Objective: Add ClinGen as a Feynman-owned clinical curation source for gene validity, dosage sensitivity, actionability, and VCEP variant classifications without depending on the local Claude Science runtime. - Changed: Added `extensions/research-tools/science-database-clingen.ts` and routed `source: "clingen"` through `feynman_science_database_search`. Plain gene queries such as `BRCA1` now assemble a ClinGen summary; focused modes include `validity:BRCA1`, `dosage:BRCA1`, `region:ISCA-...`, `actionability:BRCA1 adult`, `classifications:BRCA1`, `caid:CA003681`, `cv:55607`, and `hgvs:NM_007294.4:c.5509T>G`. Settings/Customize now lists ClinGen as a configured Directory source, and runtime context preserves CGGV assertion IDs, HGNC IDs, MONDO IDs, dosage labels, actionability document IDs, CAIDs, ClinVar variation IDs, evidence codes, expert panels, source URLs, and endpoint provenance. - Verified: Official ClinGen File Downloads & APIs, Actionability API wiki, ERepo API wiki, and terms/citation page were checked; the installed Claude Science `clingen_curations` module was used only as reference structure. Focused mocked ClinGen/context/settings tests passed (`11/11`), combined science database tests passed (`14/14`), and live Feynman-tool smoke returned BRCA1 validity, dosage, ERepo classification, and HGVS classification records. The actionability host returned a transient nginx `502` during direct live probes, and Feynman now returns bounded warnings for that endpoint instead of failing the whole source. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`440/440`). - Next: Evaluate DepMap download-compatible paths and COSMIC-compatible public routes; implement only the public/no-setup source that returns useful bounded evidence. ### 2026-07-02 21:50 PDT — feynman-owned-depmap-cosmic-canceromics - Objective: Add DepMap/COSMIC-compatible clinical-canceromics sources as Feynman-owned code, using Claude Science only as a local reference and avoiding account-gated runtime dependencies. - Changed: Added `extensions/research-tools/science-database-depmap.ts` and `extensions/research-tools/science-database-cosmic.ts`, then routed `source: "depmap"` and `source: "cosmic"` through `feynman_science_database_search`. DepMap uses the public Sanger Cell Model Passports JSON:API for model search/detail, model lists, gene lookup, and gene-scoped CRISPR dependency rows. COSMIC uses the public NLM Clinical Tables COSMIC route for bounded mutation search with GRCh37/38 selection. Settings/Customize now lists DepMap and COSMIC as configured Directory sources, and runtime context preserves COSMIC mutation IDs, legacy/genomic mutation IDs, COSG/COSO IDs, GRCh versions, mutation fields, primary site/histology, PubMed IDs, DepMap SIDM/SIDG/HGNC IDs, tissue/cancer type labels, model availability flags, dependency scores, source URLs, and endpoint provenance. - Verified: Official Sanger DepMap API docs, Cell Model Passports Swagger JSON, NLM Clinical Tables COSMIC docs, and COSMIC licensing/access pages were checked; the installed Claude Science `depmap_models` module was used only as reference structure. The Broad DepMap download-file index currently returns a Turnstile verification page to command-line fetches, so it was not shipped as a no-setup built-in runtime dependency. Focused mocked DepMap/COSMIC/context/settings tests passed (`10/10`), combined science database tests passed (`16/16`), and live Feynman-tool smoke returned `SNU-1033` / `SIDM00192`, `Large Intestine`, `Colorectal Carcinoma`, `BRAF` / `SIDG02491`, a `BRAF@SIDM00192` dependency row, and COSMIC `BRAF V600E` mutation `224203145` with PubMed IDs. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`442/442`). - Next: Continue hosted NVIDIA execution once `NVIDIA_API_KEY` exists locally or deepen long-tail artifact preview/action states. ### 2026-07-05 00:26 EDT — cancer-models-named-tool-parity - Objective: Close the Claude Science reference `cancer-models` bio-tool stub while keeping Feynman standalone and Feynman-owned. - Changed: Added exact reference-name query modes for the cancer-models domain inside `feynman_science_database_search`. cBioPortal now accepts `cbioportal_list_studies`, `cbioportal_get_study`, `cbioportal_clinical_attributes`, `cbioportal_mutations_in_gene`, `cbioportal_mutation_frequency`, and `cbioportal_cna_in_gene`; DepMap now accepts `list_models`, `get_model`, `search_models`, `search_genes`, and `gene_dependencies`. The cBioPortal adapter now implements cross-study mutation frequency and discrete CNA event retrieval through the public cBioPortal REST API with endpoint provenance. - Verified: Installed Claude Science `mcp_cancer_models`, `cbioportal_studies`, and `depmap_models` were used only as local reference structure; official cBioPortal REST API docs and Swagger were checked for the public API surface. Focused cBioPortal/DepMap/COSMIC tests passed (`6/6`), broader science database tests passed (`61/61`), full `npm test` passed (`558/558`), root/workbench typecheck passed, root build passed with existing RDKit/3Dmol/large-chunk warnings, website lint/typecheck/build passed (`34` pages), architecture check passed with existing split-debt warnings only, `git diff --check` passed, and `npm pack --dry-run --json` passed with `entryCount: 390`, shasum `f22f0e0e879917dc03ebfc3ec41936b88b1bcc49`. The gap manifest now marks `cancer-models` done and updates Bio Tool coverage to `78 done / 169 stub / 0 missing`. - Next: Continue the remaining stubbed bio-tool domains, starting with the highest-impact chemistry or expression domain exact-name probes. ### 2026-07-05 00:54 EDT — chemistry-named-tool-parity - Objective: Close the Claude Science reference `chemistry` bio-tool stub while keeping Feynman standalone and Feynman-owned. - Changed: Added exact reference-name query modes for the chemistry domain inside `feynman_science_database_search`. PubChem now accepts `pubchem_search_compounds`, `pubchem_get_compounds`, `pubchem_similarity_search`, `pubchem_get_bioassay_summary`, and `pubchem_get_safety`; ChEBI accepts `chebi_search`, `chebi_get_entity`, and `chebi_get_ontology`; BindingDB accepts `bindingdb_ligands_by_target` and `bindingdb_targets_by_compound`; Rhea accepts `rhea_search_reactions` and `rhea_get_reaction`. Updated README, release notes, website workbench docs, command metadata, prompt guidance, and the 1:1 parity trackers. - Verified: Installed Claude Science `mcp_chemistry`, `pubchem_compounds`, `chebi_ontology`, and `rhea_reactions` were used only as local reference structure; official PubChem PUG REST/PUG View, ChEBI API, BindingDB REST, and Rhea REST/SPARQL docs were checked for the public API surface. Focused PubChem/ChEBI/BindingDB/Rhea tests passed (`12/12`), broader science database tests passed (`65/65`), full `npm test` passed (`562/562`), root/workbench typecheck passed, root build passed with existing RDKit/3Dmol/large-chunk warnings, website lint/typecheck/build passed (`34` pages), architecture check passed with existing split-debt warnings only after moving chemistry out of `science-database-reference-parity.ts`, `git diff --check` passed, and `npm pack --dry-run --json` passed with `entryCount: 391`, shasum `2db740ee9b525d9e26ca20478635f70528e1a93b`. The gap manifest now marks `chemistry` done and updates Bio Tool coverage to `90 done / 157 stub / 0 missing`. - Next: Continue the remaining stubbed bio-tool domains, likely clinical-genomics or expression exact-name probes. ### 2026-07-05 01:23 EDT — clinical-genomics-named-tool-parity - Objective: Close the Claude Science reference `clinical-genomics` bio-tool stub while keeping Feynman standalone and Feynman-owned. - Changed: Added exact reference-name query modes for CIViC, ClinGen, and Open Targets inside `feynman_science_database_search`. CIViC now accepts `civic_search_genes`, `civic_gene_variants`, `civic_get_variant`, `civic_search_variants`, `civic_get_evidence_item`, `civic_search_evidence`, `civic_get_assertion`, `civic_search_assertions`, `civic_get_molecular_profile`, `civic_search_molecular_profiles`, `civic_search_diseases`, and `civic_search_therapies`; ClinGen accepts `clingen_gene_validity`, `clingen_dosage_sensitivity`, `clingen_actionability`, and `clingen_variant_classifications`; Open Targets accepts `open_targets_graphql`, `open_targets_disease_drugs`, `open_targets_disease_targets`, and `open_targets_drug`. Updated README, release notes, website workbench docs, command metadata, prompt guidance, and the 1:1 parity trackers. - Verified: Installed Claude Science `mcp_clinical_genomics`, `civic_evidence`, and `clingen_curations` were used only as local reference structure; official CIViC GraphQL, ClinGen API/download, and Open Targets GraphQL docs were checked for the public API surface. Focused CIViC/ClinGen/Open Targets tests passed (`9/9`), broader science database tests passed (`68/68`), full `npm test` passed (`565/565`), root/workbench typecheck passed, root build passed with existing RDKit/3Dmol/large-chunk warnings, website lint/typecheck/build passed (`34` pages), architecture check passed with existing split-debt warnings only, `git diff --check` passed, and `npm pack --dry-run --json` passed with `entryCount: 391`, shasum `be0f60dc0dbc10675b3066f171c843de63571e59`. The gap manifest now marks `clinical-genomics` done and updates Bio Tool coverage to `110 done / 137 stub / 0 missing`. - Next: Continue the remaining stubbed bio-tool domains, likely expression or genes-ontologies exact-name probes. ### 2026-07-05 02:09 EDT — expression-named-tool-parity - Objective: Close the Claude Science reference `expression` bio-tool stub while keeping Feynman standalone and Feynman-owned. - Changed: Split GTEx into `extensions/research-tools/science-database-gtex.ts` and added exact reference-name query modes for GTEx dataset info, tissue sites, sample info, gene resolution, median expression, expression summaries, gene-expression rows, top expressed genes, eGene rows, single-tissue eQTLs, multi-tissue eQTLs, and dynamic eQTL checks. Added exact PanglaoDB query aliases for marker genes, gene-to-cell-type lookup, and options over the existing checksum-verified marker TSV. Updated README, release notes, website docs, command metadata, prompt guidance, and the 1:1 parity trackers. - Verified: Installed Claude Science `mcp_expression`, `gtex_expression`, and `panglaodb_markers` were used only as local reference structure; official GTEx API docs and PanglaoDB marker pages were checked for the public API/source-data surface. Focused expression tests passed (`2/2`) for all 15 exact reference expression tool names, broader science database tests passed (`70/70`), full `npm test` passed (`567/567`), root/workbench typecheck passed, root build passed with existing RDKit/3Dmol/large-chunk warnings, website lint/typecheck/build passed (`34` pages), architecture check passed with existing split-debt warnings only, `git diff --check` passed, and `npm pack --dry-run --json` passed with `entryCount: 392`, shasum `e032f14333d14dcfd666b0e1543c3ced566b39ce`. The gap manifest now marks `expression` done and updates Bio Tool coverage to `125 done / 122 stub / 0 missing`. - Next: Continue the remaining stubbed bio-tool domains, likely genes-ontologies or genomes exact-name probes. ### 2026-07-02 22:03 PDT — react-science-artifact-previews - Objective: Bring React artifact previews closer to Claude Science’s scientific artifact behavior without relying on Claude Science runtime code. - Changed: Added native React inspector previews for sequence/FASTA, genome/variant interval files, molecule files, and PDB/mmCIF structure files. The preview parsers live in `workbench-web/src/artifacts.ts`, and the React inspector now renders compact stats, chips, and row tables for those artifact kinds instead of falling back to raw text. - Verified: Focused React shell tests passed (`13/13`) with FASTA/VCF/SDF/PDB parser coverage. A disposable workbench server rendered FASTA, VCF, SDF, and PDB artifacts through Playwright CLI screenshots waiting on `.science-preview`: `outputs/playwright/feynman-react-science-preview-fasta.png`, `outputs/playwright/feynman-react-science-preview-vcf.png`, `outputs/playwright/feynman-react-science-preview-sdf.png`, and `outputs/playwright/feynman-react-science-preview-pdb.png`. Gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and full `npm test` (`442/442`). - Next: Continue hosted NVIDIA execution once `NVIDIA_API_KEY` exists locally or deepen remaining long-tail artifact action/viewer states. ### 2026-07-02 22:16 PDT — standalone-reference-boundary - Objective: Make the Claude Science local install a blueprint/debug input only, not a default runtime or product resource. - Changed: Normal Settings/Customize resource builds no longer read or display the local Claude Science install. The reference extractor is now gated behind `FEYNMAN_DEBUG_CLAUDE_SCIENCE_REFERENCE=1` or `true`, and the unused extractor field that assembled a Claude Science local MCP server command was removed. The default product resource path starts with `Feynman Bio Tools` and remains backed by `builtin:feynman_science_database_search`. - Verified: Focused settings/React tests passed (`16/16`) and assert the default resource build exposes `Feynman Bio Tools` first with no visible Claude Science resource. Source grep found no `Claude Science Bio MCP`, `operon-mcp`, `run_server.py`, `.claude-science/conda`, or `bioConnectorCommand` path in `src/`, `tests/`, `workbench-web/`, or `extensions/` beyond the explicit debug extractor and reference-only test. - Next: Continue hosted NVIDIA execution once `NVIDIA_API_KEY` exists locally or deepen remaining long-tail artifact action/viewer states. ### 2026-07-03 — react-rdkit-3dmol-science-viewers - Objective: Replace the text-only molecule/structure preview gap with Feynman-owned scientific renderers, using Claude Science only as the reference shape. - Changed: Added `workbench-web/src/science-viewers.tsx` with lazy RDKit.js SVG rendering for SMILES/MOL/SDF and lazy 3Dmol WebGL rendering for MOL/SDF/PDB/mmCIF/CIF. Added the bundled RDKit WASM asset path, served `.wasm` as `application/wasm`, and kept the existing compact parser/stat cards above the visual render panes. - Verified: Official RDKit.js and 3Dmol docs were checked before coding. Focused React/source tests passed (`15/15`), `npm run typecheck:workbench-web`, `npm run build:workbench-web`, and `npm run typecheck` passed before browser smoke. Disposable-workspace Playwright smoke rendered caffeine SMILES, ethanol SDF, and a mini PDB with ready RDKit/3Dmol panes, `horizontalOverflow:0`, nonblank renderer screenshots, a correctly served `RDKit_minimal-*.wasm` response, and no failed responses. A 390px mobile smoke also passed for RDKit and 3Dmol with zero horizontal overflow and nonblank render panes. Final gates passed: `git diff --check`, `npm run typecheck`, `npm run build`, `npm run architecture:check`, and full `npm test` (`442/442`). Screenshots: `outputs/playwright/feynman-rdkit-smiles-preview.png`, `outputs/playwright/feynman-rdkit-3dmol-sdf-preview.png`, `outputs/playwright/feynman-3dmol-pdb-preview.png`, `outputs/playwright/feynman-rdkit-smiles-mobile.png`, and `outputs/playwright/feynman-3dmol-pdb-mobile.png`. - Next: Add Claude-style 3Dmol viewer mode controls for structure artifacts, then continue hosted NVIDIA execution once `NVIDIA_API_KEY` exists locally or deepen remaining long-tail artifact action/viewer states. ### 2026-07-03 — react-3dmol-viewer-controls - Objective: Close the next Claude Science structure-viewer gap by giving Feynman's 3Dmol pane real display modes instead of a single fixed render style. - Changed: Added a compact in-pane 3Dmol toolbar. Structure previews now support Cartoon, Stick, Sphere, Surface, Line, and Reset; molecule 3D previews support Ball, Stick, Sphere, Line, and Reset. Surface mode uses 3Dmol's VDW surface path with a Feynman-green tint, and the controls wrap within the artifact pane on narrow screens. - Verified: Installed 3Dmol README/types were checked for `setStyle`, supported style families, `addSurface`, and `SurfaceType.VDW`. Focused React/source tests passed (`15/15`), `npm run typecheck:workbench-web`, and `npm run build:workbench-web` passed. Disposable-workspace Playwright smoke clicked Cartoon, Surface, Line, and Reset on a PDB artifact, verified the active mode/status, measured `horizontalOverflow:0`, recorded zero failed responses, and confirmed a nonblank visibly green Surface render. A 390px mobile smoke verified the toolbar wraps to two rows with zero horizontal overflow. Final gates passed: `git diff --check`, `npm run typecheck`, `npm run build`, `npm run architecture:check`, focused React/source tests (`15/15`), and full `npm test` (`442/442`). Screenshots: `outputs/playwright/feynman-3dmol-pdb-surface-controls.png`, `outputs/playwright/feynman-3dmol-pdb-surface-render.png`, and `outputs/playwright/feynman-3dmol-pdb-controls-mobile.png`. - Next: Continue hosted NVIDIA execution once `NVIDIA_API_KEY` exists locally or deepen remaining long-tail artifact action/viewer states. ### 2026-07-03 — science-skill-pack-parity - Objective: Close the bundled science-skill catalog gap while keeping Claude Science as a local reference only and Feynman as the standalone product. - Changed: Added Feynman-owned skill entries for the reference-shaped science app structure: structure prediction, protein design, regulatory genomics, single-cell analysis, figure and paper workflows, PDF exploration, indication dossiers, compute setup, Modal/SSH remote compute, managed endpoints, endpoint use, customization, skill creation, product self-knowledge, and session self-awareness. Added `outputs/.plans/claude-science-1to1.md` as the hard parity tracker for the active 1:1 goal. - Verified: Added `tests/skill-paths.test.ts` coverage that requires the Feynman-owned science workbench skill pack and rejects local reference-runtime path leakage inside those skills. Two focused invocations both covered the full suite and passed (`443/443` each). Gates passed: `git diff --check`, `npm run typecheck`, `npm run build`, and `npm run architecture:check`. - Next: With no `NVIDIA_API_KEY` present locally, continue the next fully verifiable 1:1 slice: richer Feynman-owned seed workflow fixtures or remaining long-tail artifact action states. ### 2026-07-03 — ketcher-chemistry-editing-parity - Objective: Close Claude Science-style molecule editing parity while keeping Feynman standalone and Feynman-owned. - Changed: Added a lazy standalone Ketcher editor to the molecule artifact preview using `ketcher-react` and `ketcher-standalone`. SMILES/MOL/SDF artifacts can be opened in Ketcher, exported, and saved through Feynman's artifact edit/version endpoint. The Ketcher loader now shims browser `global` only for that dependency, and Save is separated from Copy so clipboard permission failures cannot block persistence. The backend editable artifact policy now accepts the same previewable science text formats used by the workbench scanner. - Verified: `npm run typecheck`, `npm run build`, source/workbench tests (`443/443`), and molecule edit regression tests (`444/444`) passed. Disposable-workspace Playwright smokes verified onboarding-created project/session state, selected `outputs/ethanol.smi`, opened Ketcher, rendered SVG content with no horizontal document overflow, saved SMILES through `/api/artifact/edit` with HTTP 200, and downloaded final artifact content as `CCO`. Screenshot: `outputs/playwright/feynman-ketcher-editor-smoke.png`. - Next: Continue the 1:1 goal with richer Feynman-owned seed workflow fixtures or remaining long-tail artifact action states while hosted NVIDIA execution remains blocked on missing `NVIDIA_API_KEY`. ### 2026-07-03 — html-report-artifact-preview-parity - Objective: Close the scientific HTML report preview gap exposed by the packaged CRISPR seed workflow and Feynman's own graph/report artifacts. - Changed: `.html` and `.htm` are now first-class previewable artifact extensions with `text/html` content types and `html` language metadata. The React artifact classifier now routes HTML reports to a dedicated sandboxed iframe preview instead of the raw text preview, and the Files side panel uses the wider science-artifact layout for HTML reports so self-contained science reports are readable in place. - Verified: Full `npm test` passed (`452/452`). Final gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and `npm pack --dry-run` (`321` files). Disposable-workspace browser smoke opened `outputs/design_report.html` at `/projects/workspace/frames/design_report`, verified the iframe rendered `CRISPR Kinome Design Report` with two table rows, kept `sandbox=""`, used the widened side panel, measured no horizontal overflow (`1440/1440`), recorded zero console/page/request failures, and captured `outputs/playwright/feynman-html-report-preview.png`. - Next: Continue the active 1:1 parity goal on concrete remaining artifact/viewer gaps, especially tree/NPY/NPZ-class science artifacts, while hosted NVIDIA execution remains blocked on missing `NVIDIA_API_KEY`. ### 2026-07-03 — phylogenetic-tree-artifact-preview-parity - Objective: Close the phylogenetic tree artifact gap exposed by the packaged extremophile seed workflow while keeping the viewer Feynman-owned. - Changed: `.nwk`, `.newick`, `.tree`, `.treefile`, and `.iqtree` are now previewable text artifacts with Newick/IQ-TREE metadata. The React artifact classifier routes them to a `tree` science preview, extracts embedded Newick from IQ-TREE reports, parses branch/leaf/support statistics with `patristic`, and renders an interactive TidyTree SVG viewer with horizontal, vertical, circular, weighted, tree, dendrogram, labels, and reset controls. The integration avoids TidyTree's old `d3.event` recenter path and keeps React-owned loading text out of the imperative SVG mount node. - Verified: Full `npm test` passed (`452/452`). Final gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, and `npm pack --dry-run` (`323` files). Disposable-workspace browser smoke opened the owned `outputs/open-science-seeds/example_extremophile/nif3_rooted.nwk` seed artifact at `/projects/workspace/frames/example_extremophile`, rendered `TidyTree NEWICK | 45 leaves | horizontal weighted` with `89` circles and `89` paths, switched to circular mode, toggled labels without removing geometry, measured no horizontal overflow (`1440/1440`), recorded zero console/page/request failures, and captured `outputs/playwright/feynman-tidytree-newick-preview.png`. - Next: Continue the active 1:1 parity goal on concrete remaining artifact/viewer gaps, especially NPY/NPZ tensor-like science artifacts, while hosted NVIDIA execution remains blocked on missing `NVIDIA_API_KEY`. ### 2026-07-03 02:18 PDT — intake-sweep-clean-queue-validation - Objective: Run the recurring Feynman intake sweep against live GitHub issues, PRs, branches/forks, release state, package freshness, and local validation without disturbing the active dirty workbench/science-viewer slice. - Checked: Open issues were `#182` (`feynman alpha login`) and `#184` (thesis-help request); open PR list was empty. `#182` stays deferred to the alphaXiv/alpha-hub callback boundary unless a fresh Feynman-local repro appears; `#184` is outside Feynman's AI-researcher repo/product bar and needs no code change. `origin` only has `main` and `fix/deepresearch-local-model-warning`; recent public forks checked were identical to `main` or behind it, with no ahead contributor branch. Latest GitHub release and npm package remain `v0.3.5` / `0.3.5`; bundled Pi packages are current at `0.80.3`; `@companion-ai/alpha-hub` remains current at `0.1.3`. - Verified: Gates passed: `npm run architecture:check`, `npm run typecheck`, `npm run build`, full `npm test` (`452/452`), root `npm audit --omit=dev`, website `npm run lint`, website `npm run typecheck`, website `npm run build`, website `npm audit --omit=dev`, `git diff --check`, `npm pack --dry-run --json`, actual `npm pack --json`, and temp installed-tarball smoke for `feynman --version`, `feynman --help`, and `feynman alpha status`. The first package dry run failed because an earlier package process was still installing into ignored `.feynman/npm`; after that process finished, the rerun passed. - Next: No intake-sweep code change is needed. Continue the active workbench/science-viewer lane separately; keep future sweeps read-only unless a queue item reproduces as a Feynman-local research-loop defect. ### 2026-07-03 — json-artifact-preview-parity - Objective: Close the JSON seed-artifact viewer gap exposed by the packaged open-science workflows while keeping Feynman standalone and library-backed. - Changed: Added JSON/JSONL as a first-class React artifact preview kind. The preview uses `react-json-view-lite`, structured `JSON.parse`/JSONL parsing, summary stats, top-level key chips, invalid JSONL line reporting, and Summary/Expand/Collapse tree modes. Artifact deep links now open the Files panel on mobile only when an artifact is explicitly linked, so JSON deep links render without undoing the chat-first mobile frame. - Verified: Focused JSON/React shell tests passed (`16/16`) with classifier/parser coverage for real seed `top5.json`, real seed `signature_genes.json`, JSONL records, and invalid-line reporting. Disposable-server browser smoke opened `outputs/open-science-seeds/example_enzyme_engineering/top5.json`, rendered `JSON artifact preview`, clicked Expand and Summary, showed `5` items and `46` nodes, measured no horizontal overflow on desktop (`1280/1280`) or mobile (`390/390`), recorded zero console/page/request failures, and captured `outputs/playwright/feynman-json-preview.png`, `outputs/playwright/feynman-json-preview-focused.png`, and `outputs/playwright/feynman-json-preview-mobile.png`. Final gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`455/455`), and `npm pack --dry-run` (`323` files). - Next: Continue only on concrete remaining 1:1 parity gaps from reference and seed-workflow probes. ### 2026-07-03 03:18 PDT — composer-action-menu-parity - Objective: Match the Claude Science composer action structure while keeping the actions Feynman-owned and backed by the existing workbench APIs. - Changed: Replaced the loose file/open controls in the React composer with a compact plus menu containing `Attach files`, `Your files`, `View plan`, `Request review`, and `Save as skill`. The closed composer now keeps the reference-shaped visible controls: plus, `@` artifact reference, `#` session reference, `/` command insertion, and send/stop. `View plan` opens or generates a local workbench plan artifact through `/api/chat/plan/generate`; `Request review` dispatches the existing `/api/chat/review/request` path; `Save as skill` inserts `/skill:skill-creator`. - Verified: Focused composer/source tests passed (`17/17`), `npm run typecheck:workbench-web`, `npm run build:workbench-web`, and `git diff --check` passed before the browser smoke. Fresh disposable-server Playwright smoke opened the owned seed workflow route, verified the closed composer controls, opened the plus menu with labels in order, inserted `/skill:skill-creator`, opened the Files overlay from `Your files`, generated and opened `outputs/.plans/example_enzyme_engineering.workbench-plan.json` from `View plan`, measured no horizontal overflow on desktop (`1280/1280`) or mobile (`390/390`), recorded zero console/page/request failures, and captured `outputs/playwright/feynman-composer-action-menu.png`, `outputs/playwright/feynman-composer-view-plan.png`, and `outputs/playwright/feynman-composer-action-menu-mobile.png`. Final gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`455/455`), and `npm pack --dry-run` (`323` files). - Next: Continue only on concrete remaining 1:1 parity gaps from reference and seed-workflow probes. ### 2026-07-03 03:35 PDT — session-model-menu-parity - Objective: Match the Claude Science session/model control-plane shape in the React topbar while keeping model selection Feynman-owned and state-backed. - Changed: Added a model-status snapshot to authenticated workbench state using Feynman's existing model catalog and CLI auth/settings paths. The React topbar now exposes a Model menu with Default, the top available authenticated model specs, and More models; it also exposes Session options for Delegation, Auto-review, Memory, Specialist, and Compute. Menu actions persist through `/api/chat/config`, so selected specialist/model/session toggles flow into the Pi prompt and launch path instead of being visual-only. - Verified: Focused source/API tests passed (`12/12`) and assert the visible model/session controls plus `/api/state` model status. A first Playwright smoke caught a real layout bug where the model menu covered the session button; the topbar was fixed to keep two menu buttons on one row and ellipsize the title. Fresh disposable-server Playwright smoke then verified both topbar buttons, model menu, session options, state-backed current/recommended model data, desktop/mobile no-overflow measurements (`1280/1280`, `390/390`), zero console/page/request failures, and screenshots `outputs/playwright/feynman-model-menu.png`, `outputs/playwright/feynman-session-options-menu.png`, and `outputs/playwright/feynman-session-options-menu-mobile.png`. Final gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`456/456`), and `npm pack --dry-run` (`323` files). - Next: Continue only on concrete remaining 1:1 parity gaps from reference and seed-workflow probes. ### 2026-07-03 03:53 PDT — plan-control-plane-parity - Objective: Match Claude Science's awaiting-plan-approval product structure with a Feynman-owned actionable plan artifact surface. - Changed: Generated `feynman.workbenchPlan.v1` artifacts now render as first-class workbench plans instead of generic JSON. The React artifact inspector shows plan status, feasibility, task summary, execution steps, linked artifact chips, Approve/Reject/Reopen controls, and per-step Pending/Running/Complete/Blocked controls. The controls call `/api/chat/plan/action` and `/api/chat/plan/step`, updating the durable plan file and chat session through existing Feynman APIs. - Verified: Focused source/API tests passed (`25/25`). Fresh rebuilt-server Playwright smoke opened `View plan` on the seed workflow route, verified the plan preview, clicked Approve, verified Reopen, returned the plan to `awaiting_approval`, measured no horizontal overflow on desktop (`1280/1280`) or mobile (`390/390`), recorded zero console/page/request failures, and captured `outputs/playwright/feynman-plan-preview.png`, `outputs/playwright/feynman-plan-preview-approved.png`, and `outputs/playwright/feynman-plan-preview-mobile.png`. Final gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`456/456`), and `npm pack --dry-run` (`323` files). - Next: Continue only on concrete remaining 1:1 parity gaps from reference and seed-workflow probes; hosted NVIDIA execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 04:07 PDT — launcher-queue-parity - Objective: Match the Claude Science dashboard now-zone structure with a standalone Feynman launcher queue. - Changed: Added a Research queue to the React launcher. It derives Plan ready, Needs revision, Running/Queued, Failed/Stopped, Completed/Verified cards from Feynman's generated plans and compute jobs. Plan-ready cards open the matching project/session with the generated plan artifact already selected, so awaiting approval is visible before entering a frame and actionable after click-through. - Verified: Focused source/web checks passed. Fresh rebuilt-server Playwright smoke verified the launcher Research queue, one Plan ready card, six queue cards, click-through into the plan artifact, no horizontal overflow on desktop (`1280/1280`) or mobile (`390/390`), zero console/page/request failures, and screenshots `outputs/playwright/feynman-launcher-queue.png`, `outputs/playwright/feynman-launcher-queue-plan-open.png`, and `outputs/playwright/feynman-launcher-queue-mobile.png`. Final gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`456/456`), and `npm pack --dry-run` (`323` files). - Next: Continue only on concrete remaining 1:1 parity gaps from reference and seed-workflow probes; hosted NVIDIA execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 04:19 PDT — dashboard-command-palette-parity - Objective: Match the Claude Science dashboard command palette while keeping search and routing Feynman-owned. - Changed: Added a global Search command palette to the React launcher and workbench. `mod+k` and the visible Search button open a grouped modal over Feynman's projects, sessions, artifacts, and New project action. Artifact rows use durable filenames and deep-link into the selected artifact viewer with `artifact=` preserved in the route. - Verified: The installed Claude Science bundle was checked for `DashboardCommandPalette`, `mod+k`, grouped projects/results, `Search projects, artifacts, sessions...`, and a New project row. Focused source tests passed, `npm run typecheck:workbench-web` passed, and `npm run build:workbench-web` passed. Fresh rebuilt-server Playwright smoke verified keyboard open, visible Search open, `plddt.npy` artifact search, click-through to `outputs/open-science-seeds/example_enzyme_engineering/plddt.npy`, rendered tensor preview, desktop/mobile no-overflow (`1280/1280`, `390/390`), mobile palette width `370px`, zero console/page/request failures, and screenshots `outputs/playwright/feynman-command-palette.png`, `outputs/playwright/feynman-command-palette-artifact-open.png`, and `outputs/playwright/feynman-command-palette-mobile.png`. Final gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`456/456`), and `npm pack --dry-run` (`323` files). - Next: Continue only on concrete remaining 1:1 parity gaps from reference and seed-workflow probes; hosted NVIDIA execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 04:46 PDT — msa-alignment-preview-parity - Objective: Close the Claude Science MSA/alignment preview gap using Feynman-owned artifact classification and a packaged viewer dependency. - Changed: Added `msa` as a first-class React artifact kind. Feynman now detects aligned FASTA content plus dedicated alignment extensions, parses FASTA/CLUSTAL/Stockholm/plain alignment rows, computes sequence/column/gap/conserved/variable/consensus stats, and renders a Nightingale-backed alignment canvas with a Feynman-owned label rail so the drawer opens readable and green-styled. - Verified: `@nightingale-elements/nightingale-msa@5.6.0` package source was checked for the web-component contract. Focused React/source tests passed (`18/18` after splitting MSA coverage into its own file), `npm run typecheck` passed, `npm run build` passed, `npm run architecture:check` passed, and `git diff --check` passed. Fresh rebuilt-server Playwright smoke opened `outputs/open-science-seeds/example_extremophile/nif3_aligned.fasta`, verified `45` sequences, `488` columns, `42.3%` gaps, the first label row at the stage origin, Nightingale custom element registration, `2` canvases, color switch to `nucleotide`, desktop/mobile no body overflow, zero console/page failures, and screenshots `outputs/playwright/feynman-msa-preview-panel-final.png`, `outputs/playwright/feynman-msa-render-stage-final.png`, `outputs/playwright/feynman-msa-preview.png`, and `outputs/playwright/feynman-msa-preview-mobile.png`. Final gates passed: full `npm test` (`457/457`) and `npm pack --dry-run` (`324` files). - Next: Continue only on concrete remaining 1:1 parity gaps from reference and seed-workflow probes. ### 2026-07-03 05:13 PDT — compute-provider-control-plane-parity - Objective: Close the Claude Science compute-provider control-plane gap while keeping Modal, NVIDIA, SSH, Pi, and local providers Feynman-owned and standalone. - Changed: Promoted compute providers into canonical workbench state with enabled/checked state, tier, detail, diagnostics, tool metadata, and actions. The Compute pane Providers tab now shows Local Workspace, Pi Research Agents, Artifact Provenance, Modal, NVIDIA BioNeMo NIM, and configured SSH hosts with persisted Enable/Disable controls and SSH removal. Provider preferences are saved in `.feynman/workbench/settings.json`; disabled SSH hosts drop out of runtime context, and disabled model endpoints are marked disabled for Pi prompts. Settings/Customize now reads the same canonical providers instead of duplicating Modal/NVIDIA/SSH rows. - Verified: The installed Claude Science bundle was checked for `useComputeProviders`, provider checked state, provider details/probing, SSH add/remove, inference-provider remove, and managed endpoint stop actions. Focused gates passed: `npm run typecheck`, `npm run architecture:check`, `npm run build`, `git diff --check`, and 47 targeted workbench tests. In-app browser smoke opened `/projects/seed-workflows/frames/example_enzyme_engineering`, rendered the Compute Providers tab with 5 provider rows, Modal, NVIDIA BioNeMo NIM, `feynman_model_endpoint_call`, `NVIDIA_API_KEY`, Session enabled state, action buttons, zero console errors, and no horizontal overflow (`1280/1280`); metrics are saved at `outputs/playwright/feynman-compute-provider-control.json`. Final gates passed: full `npm test` (`458/458`) and `npm pack --dry-run` (`326` files). - Next: Continue only on concrete remaining 1:1 parity gaps from reference and seed-workflow probes. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 05:31 PDT — model-endpoint-compute-history-parity - Objective: Close the managed-endpoint history gap from the Claude Science compute-provider reference without adding any runtime dependency on `~/.claude-science`. - Changed: Added a Feynman-owned endpoint usage scanner that reads `outputs/model-endpoints/*.provenance.md` sidecars and promotes saved hosted/self-hosted model endpoint calls into the workbench compute timeline and execution ledger. Endpoint records now carry provider, model, endpoint URL, auth source, status, sequence length, output format, command, provenance path, and output artifacts; the Compute tab shows them beside notebook and Modal jobs. - Verified: The installed Claude Science bundle was checked for `useComputeProviders`, `removeInferenceProvider`, managed endpoint invalidation, and `stopManagedEndpoint`. Focused tests passed for hosted ESMFold output, missing hosted credential failure, self-hosted AlphaFold2 output, Modal job preservation, and endpoint-history promotion (`5/5`). `npm run typecheck`, `npm run build`, `npm run architecture:check`, and `git diff --check` passed. A temporary-workspace browser smoke opened `/projects/workspace/frames/model-endpoints`, verified `Model endpoint: ESMFold`, `NVIDIA BioNeMo NIM`, `200 OK`, no horizontal overflow (`1440/1440`), and zero console errors; metrics are saved at `outputs/playwright/feynman-model-endpoint-compute-frame.json`. Final gates passed: full `npm test` (`459/459`) and `npm pack --dry-run` (`327` files). - Next: Continue only on the next concrete reference/seed parity gap. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 05:40 PDT — capabilities-directory-parity - Objective: Close the Claude Science capabilities/connectors directory gap while keeping Feynman standalone and Feynman-owned. - Changed: Reworked the React Customize panel into a full capabilities directory instead of a capped sampler. It now shows catalog counts, search, status filters, group filters, diagnostics, tool chips, and tag chips across Skills, Connectors, Specialists, Memory, Compute, Network, Permissions, Credentials, Storage, Usage, and General. `Feynman Bio Tools` remains the visible science connector; no normal product path depends on `~/.claude-science`. - Verified: The installed Claude Science bundle was checked for its capabilities/connectors/skills/permissions shelf, connector directory tiles, and research model skill directory copy. Focused React/resource tests passed (`16/16`). Temporary-workspace browser smoke verified Customize renders `119` resource cards across `9` groups, including `Feynman Bio Tools`, `Open Targets`, `Clinical Trials`, and `ZINC`; search for `Open Targets` keeps `feynman_science_database_search` visible, no horizontal overflow appears (`1440/1440`), and browser console errors stayed at zero. Final gates passed: `npm run typecheck`, `npm run build:workbench-web`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`460/460`), and `npm pack --dry-run` (`327` files). - Next: Continue only on the next concrete reference/seed parity gap. Hosted NVIDIA ESMFold execution remains credential-gated until `NVIDIA_API_KEY` exists locally. ### 2026-07-03 06:48 PDT — transcript-annotations-ledger-parity - Objective: Close the Claude Science transcript annotation/bookmark gap while keeping transcript state Feynman-owned and usable by the Pi-backed research loop. - Changed: Added `.feynman/workbench/transcript-annotations.json`, `state.transcriptAnnotations`, `summary.transcriptAnnotationCount`, authenticated `/api/transcript/annotation` mutations, Pi prompt context injection for saved transcript bookmarks, and compact chat UI controls for bookmarking a message, rendering the saved anchor/note, using it in chat, and removing it. - Verified: The installed Claude Science DB was checked for `transcript_annotations`, and the reference bundle was checked for `AnnotatableBlock`, text-annotation anchor/highlight test ids, and detached bookmark hooks. Focused transcript/server/source tests passed. Disposable-workspace browser smoke clicked `Bookmark transcript message`, rendered the bookmark row with `Use in chat` and `Remove`, verified one transcript annotation in `/api/state`, measured no horizontal overflow (`1440/1440`), and recorded zero console errors or failed requests. Final gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`466/466`), and `npm pack --dry-run` (`332` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 06:55 PDT — frame-system-prompts-parity - Objective: Close the Claude Science `frame_system_prompts` structural gap while keeping prompt snapshots Feynman-owned and tied to the local workbench state. - Changed: Added `src/workbench/frame-system-prompts.ts`, `state.frameSystemPrompts`, and web type exports. Each Feynman chat frame now carries a stable standalone-Feynman prompt contract, dynamic workspace/project/session/config/resource context, SHA-256 payload hash, and update timestamp through `/api/state`. - Verified: The installed Claude Science DB was checked for `frame_system_prompts` schema and payload shape. Focused state/server tests passed for stable boundary text, dynamic project/frame/config/model/resource context, and 64-character hashes. Final gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`468/468`), and `npm pack --dry-run` (`333` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 07:05 PDT — directory-attachments-ledger-parity - Objective: Close the Claude Science `directory_attachments` structural gap while keeping connector attachment state Feynman-owned and derived from Feynman's own connector catalog/settings. - Changed: Added `src/workbench/directory-attachments.ts`, `state.directoryAttachments`, web type exports, and sanitized custom connector `settingsRecord` metadata for assigned specialists, excluded tools, and stored timestamps. Configured built-in/package/custom connectors now expose stable server UUIDs, agent names, local user id, connector kind/source/status, excluded tools, tool names, and created timestamps through `/api/state`. - Verified: The installed Claude Science DB was checked for `directory_attachments` schema and row shape. Focused connector/settings tests passed for built-in PubMed/Feynman Bio Tools rows, no Claude Science product-source leakage, custom Lab MCP rows split across Researcher and Verifier, excluded-tool preservation, stable UUID shape, and authenticated `/api/state` exposure. Final gates passed: focused tests (`14/14`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`470/470`), and `npm pack --dry-run` (`334` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 07:14 PDT — mcp-tool-grants-ledger-parity - Objective: Close the Claude Science `mcp_tool_grants` structural gap while keeping approvals and grants backed by Feynman's own permission settings. - Changed: Added `src/workbench/mcp-tool-grants.ts`, `state.mcpToolGrants`, and web type exports. Permission grants now expose Claude-style rows with deterministic grant UUIDs, local user id, server id, tool name, decision, source scope, optional description, settings record id, and created timestamp through `/api/state`. - Verified: The installed Claude Science DB was checked for `mcp_tool_grants` schema and row shape. Focused grant/connector/settings tests passed for connector grant parsing, built-in tool grant parsing, stable UUID shape, local user id, decision/source preservation, and authenticated `/api/state` exposure. Final gates passed: focused tests (`16/16`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`472/472`), and `npm pack --dry-run` (`335` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 07:45 PDT — custom-mcp-ledgers-parity - Objective: Close the Claude Science `custom_mcp_servers` and `mcp_agent_assignments` structural gap while keeping connector runtime behavior backed by Feynman's own custom connector settings. - Changed: Added `src/workbench/custom-mcp-ledgers.ts`, `src/workbench/mcp-ledgers.ts`, `src/workbench/mcp-types.ts`, `state.customMcpServers`, and `state.mcpAgentAssignments`. Custom connectors now expose Claude-style server rows with stable UUIDs, local user id, name, description, URL/transport/OAuth/header metadata, source, resource identifier, settings record id, and timestamps; assigned specialists now expose per-agent assignment rows with excluded-tool lists. `src/workbench/types.ts` was split back under the 800-line warning threshold. - Verified: The installed Claude Science DB was checked for both schemas and row shapes. Focused custom MCP/connector/settings/grant tests passed for remote Streamable HTTP rows, local command rows, OAuth/header metadata, stable UUIDs, default `feynman` assignment, Researcher/Verifier assignments, excluded-tool preservation, and authenticated `/api/state` exposure. Final gates passed: focused tests (`18/18`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`474/474`), and `npm pack --dry-run` (`338` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 08:14 PDT — skill-agent-ledgers-parity - Objective: Close the Claude Science `custom_skills`, `agent_skill_assignments`, and `custom_agent_prompts` structural gap while keeping skills and specialists Feynman-owned. - Changed: Added `src/workbench/skill-ledgers.ts`, `src/workbench/skill-types.ts`, `state.customSkills`, `state.agentSkillAssignments`, and `state.customAgentPrompts`. Project `skills/*/SKILL.md` now expose Claude-style custom skill rows with stable UUIDs, local user id, name, description, content snapshot, source, path, and timestamps. The same skills produce default `feynman` assignment rows, and `.feynman/agents/*.md` now expose custom agent prompt rows through `/api/state`. - Verified: The installed Claude Science DB was checked for all three reference schemas and row shapes. Focused state/server tests passed for custom skill content, deterministic UUIDs, default skill assignment, custom agent prompt capture, and authenticated `/api/state` exposure. Final gates passed: focused tests (`28/28`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`476/476`), and `npm pack --dry-run` (`340` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 10:23 PDT — artifact-folders-ledger-parity - Objective: Close the Claude Science `artifact_folders` structural gap while keeping Files organization derived from Feynman's own projects, runs, and artifacts. - Changed: Added `src/workbench/artifact-folders.ts`, `src/workbench/ledger-types.ts`, `src/workbench/state-ledgers.ts`, and `state.artifactFolders`. Feynman now exposes one `User Uploads` folder per project plus conversation folders for project runs, with stable UUIDs, project ids, root frame ids, sort order, folder-role flags, artifact counts, and timestamps. The scanner now uses a shared state-ledger aggregator for artifact folders, MCP ledgers, and skill ledgers, reducing `src/workbench/scan.ts` to `1193` lines. - Verified: The installed Claude Science DB was checked for `artifact_folders` schema and local rows. Focused ledger/server tests passed for user-upload folders, conversation folders, stable UUIDs, run/root-frame linkage, artifact counts, timestamps, and authenticated `/api/state` exposure. Final gates passed: focused tests (`33/33`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`478/478`), and `npm pack --dry-run` (`343` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 10:32 PDT — user-agents-ledger-parity - Objective: Close the Claude Science `user_agents` structural gap while keeping the default agent profile Feynman-owned. - Changed: Added `src/workbench/user-agents.ts`, expanded `src/workbench/ledger-types.ts`, and added `state.userAgents`. Feynman now exposes a default `FEYNMAN` user-agent profile derived from `.feynman/SYSTEM.md` and local skill rows, including stable UUID, local user id, display name, description, system prompt, icon/color keys, tags, sorted skill names, enabled state, tombstones, unrestricted flag, and timestamps through `/api/state`. - Verified: The installed Claude Science DB was checked for `user_agents` schema and the local default `OPERON` row. Focused tests passed for the Feynman user-agent row, system prompt capture, skill list derivation, stable UUIDs, enabled/tombstone/unrestricted fields, timestamps, and authenticated `/api/state` exposure. Final gates passed: focused tests (`31/31`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`480/480`), and `npm pack --dry-run` (`344` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 10:42 PDT — capability-settings-ledger-parity - Objective: Close the Claude Science `capability_settings` structural gap while keeping capability state derived from Feynman's own Settings/Customize resources. - Changed: Added `src/workbench/capability-settings.ts`, expanded `src/workbench/ledger-types.ts`, and added `state.capabilitySettings`. Feynman now emits Claude-style user/kind/key/enabled/updated rows from resource groups and compute provider state, including disabled compute providers, denied permission grants, configured allowed domains, settings record ownership, source/status metadata, and timestamps through `/api/state`. - Verified: The installed Claude Science DB and migration were checked for the `capability_settings` schema. Focused tests passed for resource-derived rows, disabled `nvidia-bionemo`, configured allowed-domain ownership, denied permission-grant disable state, timestamps, and authenticated `/api/state` exposure. Final gates passed: focused tests (`10/10`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`482/482`), and `npm pack --dry-run` (`345` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 10:49 PDT — host-grants-ledger-parity - Objective: Close the Claude Science `host_grants` structural gap while keeping file-access grants derived from Feynman's own research artifact boundaries. - Changed: Added `src/workbench/host-grants.ts`, expanded `src/workbench/ledger-types.ts`, and added `state.hostGrants`. Feynman now emits Claude-style host grant rows for `outputs`, `papers`, `notes`, and `CHANGELOG.md`, with stable UUIDs, local user id, absolute host paths, mount names, `rw` artifact modes, `ro` lab-notebook mode, source labels, existence flags, and timestamps through `/api/state`. - Verified: The installed Claude Science DB and migrations were checked for the `host_grants` schema and `mode` column. Focused tests passed for stable UUIDs, local user id, absolute host paths, mount modes, timestamps, and authenticated `/api/state` exposure. Final gates passed: focused tests (`8/8`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`484/484`), and `npm pack --dry-run` (`346` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 10:58 PDT — compute-providers-ledger-parity - Objective: Close the Claude Science `compute_providers` structural gap while keeping provider records derived from Feynman's own compute control plane. - Changed: Added `src/workbench/compute-provider-records.ts`, expanded `src/workbench/ledger-types.ts`, and added `state.computeProviders`. Feynman now emits Claude-style compute provider rows with provider name/display name, family, memory markdown, environments, memory revision, scratch roots, schedulers, probe timestamps, data roots, SSH overrides, enabled state, scratch-root source, home, inference config, app/modal names, egress policy, status, tier, and settings ownership through `/api/state`. - Verified: The installed Claude Science DB was checked for the `compute_providers` schema. Focused tests passed for local workspace rows, disabled `nvidia-bionemo`, NVIDIA inference config/data roots, SSH scheduler/scratch root/overrides, settings ownership, and authenticated `/api/state` exposure. Final gates passed: focused tests (`10/10`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`486/486`), and `npm pack --dry-run` (`347` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 11:08 PDT — compute-usage-ledger-parity - Objective: Close the Claude Science `compute_usage` and `compute_pending_terminate` structural gap while keeping usage rows derived from Feynman's own notebook/model endpoint compute history. - Changed: Expanded `src/workbench/compute-usage.ts`, `src/workbench/ledger-types.ts`, and `state` with `computeUsage` and `computePendingTerminates`. Feynman now emits Claude-style compute usage rows with stable ids, job ids, environment, tier, provider, frame/project ids, started/ended timestamps, active-job expiry timestamps, and status. Pending termination rows now expose sandbox id, provider, enqueue timestamp, attempts, job id, remote handle when present, and pending status through `/api/state`. - Verified: The installed Claude Science DB was checked for the `compute_usage` and `compute_pending_terminate` schemas. Focused tests passed for running usage rows without `endedAt`, stopped usage rows with `endedAt`, provider/frame/project mapping, active expiry timestamps, and Modal pending-terminate rows. Final gates passed: focused tests (`5/5`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`486/486`), and `npm pack --dry-run` (`347` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 11:16 PDT — memory-categories-ledger-parity - Objective: Close the Claude Science `memory_categories` structural gap while keeping memory categories derived from Feynman's own settings. - Changed: Added `src/workbench/memory-categories.ts`, expanded `src/workbench/ledger-types.ts`, and added `state.memoryCategories`. Feynman now emits Claude-style memory category rows with stable ids, local user id, name, lowercased unique name, guidance, auto-recall state, created/updated timestamps, and settings record ownership through `/api/state`. - Verified: The installed Claude Science DB was checked for the `memory_categories` schema. Focused tests passed for settings-derived category rows, stable UUID shape, lowercased names, guidance, auto-recall state, timestamps, settings ownership, and authenticated settings mutation returning the ledger through state. Final gates passed: focused tests (`8/8`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`486/486`), and `npm pack --dry-run` (`348` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 11:25 PDT — cloud-credentials-ledger-parity - Objective: Close the Claude Science `cloud_credentials` structural gap while keeping credentials derived from Feynman's own Settings/Cloud export credential references. - Changed: Added `src/workbench/cloud-credentials.ts`, expanded `src/workbench/ledger-types.ts`, and added `state.cloudCredentials`. Feynman now emits Claude-style cloud credential rows with stable ids, local user id, provider, name, credential type, env-backed encrypted credential reference, safe default bucket/container metadata, created/updated timestamps, status, env var, and settings ownership through `/api/state` without exposing raw credential values or cloud target secrets. - Verified: The installed Claude Science DB was checked for the `cloud_credentials` schema. Focused tests passed for configured local export rows, missing S3 rows, stable UUID shape, env-reference payloads, default bucket parsing, status, timestamps, settings ownership, and authenticated cloud-export API state exposure. Final gates passed: focused tests (`8/8`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`486/486`), and `npm pack --dry-run` (`349` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 11:34 PDT — managed-endpoints-ledger-parity - Objective: Close the Claude Science `managed_endpoints` structural gap while deriving endpoint rows from Feynman's own runtime model endpoint inventory. - Changed: Added `src/workbench/managed-endpoints.ts`, expanded `src/workbench/ledger-types.ts`, and added `state.managedEndpoints`. Feynman now emits Claude-style managed endpoint rows with name, URL, port, credential name, skill name, start/stop scripts, readiness path, approved script hash, state, state-changed timestamp, last error, created timestamp, registered-by metadata, provider, models, and sanitized credential status through `/api/state`. - Verified: The installed Claude Science DB was checked for the `managed_endpoints` schema, and the reference bundle was checked for hosted/managed endpoint registration and detail rendering. Focused tests passed for the NVIDIA BioNeMo/NIM endpoint row, HTTPS port/live path parsing, credential name, claimed skill, empty hosted start/stop scripts, stable 64-character approved hash, missing-credential stopped state, present-credential live state, registered-by metadata, model list, timestamps, and authenticated `/api/state` exposure. Final gates passed: focused tests (`8/8`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`487/487`), and `npm pack --dry-run` (`350` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 11:41 PDT — oauth-tokens-ledger-parity - Objective: Close the Claude Science `oauth_tokens` structural gap while keeping raw connector tokens private in Feynman's own OAuth token store. - Changed: Added `src/workbench/oauth-token-ledger.ts`, expanded `src/workbench/ledger-types.ts`, and added `state.oauthTokens`. Feynman now emits Claude-style OAuth token rows with id, local user id, custom MCP server id, encrypted access/refresh token references, token type, expiry, scopes, created/updated timestamps, client id, connector/settings ownership, and active/expired status through `/api/state` without exposing raw access or refresh token values. - Verified: The installed Claude Science DB was checked for the `oauth_tokens` schema. Focused OAuth/MCP tests passed through the real OAuth start/callback/disconnect flow and verified custom MCP server foreign-key mapping, local user id, encrypted access/refresh token references, token type, expiry, scopes, client id, connector/settings ownership, active status, raw token redaction, and post-disconnect row removal. Final gates passed: focused tests (`11/11`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`487/487`), and `npm pack --dry-run` (`351` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 11:52 PDT — artifact-provenance-ledgers-parity - Objective: Close the Claude Science `artifact_dependencies` and `content_snapshots` structural gaps while deriving rows from Feynman's own artifact versions and snapshot files. - Changed: Added `src/workbench/artifact-provenance-ledgers.ts`, expanded `src/workbench/ledger-types.ts`, and added `state.artifactDependencies` and `state.contentSnapshots`. Feynman now emits Claude-style artifact dependency rows from artifact-version input/output lineage and bounded content snapshot rows from saved artifact snapshot files, with stable ids/hashes, version pair references, reference names, content size, created timestamps, snapshot ownership, and truncation flags. - Verified: The installed Claude Science DB was checked for the `artifact_dependencies` and `content_snapshots` schemas. Focused snapshot/edit tests passed for saved snapshot content rows, hash/content/size/timestamp metadata, dependency rows from notebook input artifacts, stable UUIDs, reference names, and version timestamp matching. Final gates passed: focused tests (`13/13`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`488/488`), and `npm pack --dry-run` (`352` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 12:01 PDT — host-call-log-ledger-parity - Objective: Close the Claude Science `host_call_log` structural gap while deriving host-call audit rows from Feynman's own execution provenance. - Changed: Added `src/workbench/host-call-log.ts`, expanded `src/workbench/ledger-types.ts`, and added `state.hostCallLog`. Feynman now emits Claude-style execution-linked host call rows from artifact input paths, with numeric ids, execution log ids, per-execution sequence numbers, `artifact_path` methods, JSON args, derivable state, byte counts, and created timestamps through `/api/state`. - Verified: The installed Claude Science DB was checked for the `host_call_log` schema and local rows. Focused artifact snapshot/edit tests passed for notebook-derived `artifact_path` rows, numeric ids, execution log ids, code-order sequence, JSON args, derivable state, byte counts, and execution timestamps. Final gates passed: focused tests (`13/13`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`488/488`), and `npm pack --dry-run` (`353` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 12:09 PDT — agent-ledgers-parity - Objective: Close the Claude Science `agents` and `bundled_agent_settings` structural gaps while deriving specialist rows from Feynman's own bundled agent prompts. - Changed: Added `src/workbench/agent-ledgers.ts`, expanded `src/workbench/ledger-types.ts`, and added `state.agents` and `state.bundledAgentSettings`. Feynman now emits Claude-style agent registry rows and bundled-agent setting rows from `.feynman/agents/*.md`, with stable ids, `feynman://agents/<name>` URLs, descriptions, JSON parameters, timestamps, local user ids, and enabled state through `/api/state`. - Verified: The installed Claude Science DB and migrations were checked for the `agents` and `bundled_agent_settings` schemas, and the installed reference runtime was checked for bundled agent metadata under `agents/*/metadata.yaml`. Focused agent/skill/user-agent tests passed for owned agent-file derivation and authenticated `/api/state` exposure. Final gates passed: focused tests (`6/6`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`490/490`), and `npm pack --dry-run` (`354` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 12:26 PDT — session-archives-ledger-parity - Objective: Close the Claude Science `session_concurrency`, `compaction_archives`, and `frame_branch_archives` structural gaps while deriving rows from Feynman's own workbench sessions and Pi JSONL tree files. - Changed: Added `src/workbench/session-archives.ts`, expanded `src/workbench/ledger-types.ts`, and added `state.sessionConcurrency`, `state.compactionArchives`, and `state.frameBranchArchives`. Feynman now emits Claude-style per-frame concurrency rows, compaction archive rows from Pi `compaction` entries, and branch archive rows from branched Pi session leaves through `/api/state`. - Verified: The installed Claude Science DB was checked for the `session_concurrency`, `compaction_archives`, and `frame_branch_archives` schemas. Pi docs/runtime were checked for JSONL tree sessions, `/tree` branch behavior, `/fork` and `/clone`, `CompactionEntry`, `BranchSummaryEntry`, and `SessionManager` traversal. Focused archive tests passed for authenticated API exposure, message-count/token-count archive metadata, compacted-message exclusion of kept turns, branch payloads, branch point ids, and active branch marking. Final gates passed: focused tests (`2/2`), `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` (`492/492`), and `npm pack --dry-run` (`355` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-03 13:14 PDT — secret-ledgers-parity - Objective: Close the Claude Science `user_secrets` and `anthropic_api_keys` structural gaps while keeping all credential values private and sourced from Feynman-owned settings, environment variables, and Pi auth storage. - Changed: Added `src/model/api-key-providers.ts`, `src/workbench/credential-catalog.ts`, and `src/workbench/secret-ledgers.ts`; expanded `src/workbench/ledger-types.ts`, `src/workbench/types.ts`, and `state` with `userSecrets` and `anthropicApiKeys`. Feynman now emits redacted Claude-style user secret rows and Anthropic API key rows through `/api/state`, shares the model provider credential catalog between the CLI and workbench Settings, dedupes settings-backed env refs, and never exposes raw secret values. - Verified: The installed Claude Science DB and migrations were checked for the `user_secrets` and `anthropic_api_keys` schemas; Pi auth storage was checked for API-key/OAuth credential shape and non-secret status behavior. The new secret-ledger coverage passed inside two full suite runs and verified settings/env/auth rows, configured and missing status, Anthropic key derivation, provider catalog exposure, and raw secret redaction. Final gates passed: `npm run typecheck`, `npm run build`, `npm run architecture:check`, `git diff --check`, full `npm test` twice (`493/493`), and `npm pack --dry-run` (`358` files). - Next: Continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-04 15:35 PDT — preprint-connector-parity - Objective: Close the reference bioRxiv/medRxiv connector behavior gap without depending on the installed Claude Science runtime. - Changed: Added `extensions/research-tools/science-database-preprints.ts` and routed `biorxiv`/`medrxiv` through it from `feynman_science_database_search`. Feynman now supports preprint DOI lookup, 60-day default windows, explicit date windows, category filters, category listing, published-preprint links, bioRxiv publisher-prefix links, funder/ROR lookup, bioRxiv content statistics, and server-specific usage statistics. README, release notes, website docs, CLI docs, command metadata, and Pi tool guidance now describe the concrete preprint modes. - Verified: Installed reference `mcp_biorxiv` was checked for the seven preprint tools, and public bioRxiv/medRxiv API docs were checked for details, published-link, funder, summary, and usage endpoints. Focused science-database tests passed (`7/7`). Live Feynman-tool smoke returned a bioRxiv category-window result, medRxiv usage stats, bioRxiv yearly content stats, and a bioRxiv funder/ROR result with endpoint provenance. Final gates passed: root typecheck, website typecheck (`0 errors`), root build with existing RDKit/3Dmol/large-chunk warnings, website build (`34 pages`), architecture check with existing split-debt warnings only, `git diff --check`, full `npm test` (`531/531`), and `npm pack --dry-run --json` (`entryCount: 380`, shasum `332b8564bea6d769e50d3ee75599ed8197056857`). - Next: Run full root and website gates, then continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-05 00:49 EDT — intake-sweep-clean-queue - Objective: Run the `check-new-issues` intake sweep against the current dirty Feynman checkout without disturbing unrelated work. - Checked: Live GitHub queue still has open issues `#182` and `#184`, zero open PRs, latest main `Publish and Release` run green at `cb5fa56`, GitHub release `v0.3.5`, npm `@companion-ai/feynman@0.3.5`, Pi `0.80.3`, and alpha-hub `0.1.3`. The newly pushed `founderqiang/feynman` fork points at `cb5fa56`, and configured `pr4fork/main` has no ahead diff. - Decisions: No repo code change was needed. `#182` remains deferred/external because Feynman delegates alpha login to alpha-hub and the issue evidence shows the Clerk authorize flow does not redirect to localhost before Feynman can exchange a token. `#184` remains outside the AI-researcher product bar as support/advice, not a Feynman feature. No open PRs to merge, port, reject, or defer. - Verified: `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/large-chunk warnings; `npm run architecture:check` with existing split-debt warnings; first full `npm test` hit two non-repro reference-chemistry failures, affected focused tests passed (`7/7`), and the full rerun passed (`562/562`); website `lint`, `typecheck` (`0 errors`), and `build` (`34 pages`); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 391`, shasum `f34eeb54bd74ccf3660deee0b183cd7519352d33`); strict installed-tarball smoke passed for `feynman --version`, `feynman --help`, and `feynman alpha status`. - Next: Keep the existing dirty workbench/science-database lane intact; act only on a fresh Feynman-owned repro or a PR with a direct research-loop fix. ### 2026-07-05 01:42 EDT — genes-ontologies-named-tool-parity - Objective: Close the Claude Science genes/ontologies Bio Tools stub group while keeping Feynman standalone and Feynman-owned. - Changed: Added exact `feynman_science_database_search` query modes for `query_genes`, `list_ontologies`, `search_ontology_terms`, `get_ontology_term`, `get_go_annotations`, `get_uniprot_entries`, `map_reactome_pathways`, `get_kegg_entries`, `search_kegg`, and `link_kegg_ids`. These route through owned MyGene.info, OLS4, QuickGO, UniProt REST, Reactome AnalysisService, and KEGG REST adapters with endpoint provenance, bounded results, and no `~/.claude-science` runtime dependency. Updated README, releases, website docs, command metadata, tool guidance, the 1:1 tracker, and the gap manifest. - Verified: Installed reference genes/ontologies, KEGG, and UniProt modules were checked for argument names, batching, and result behavior; public service docs were checked for endpoint shape. Focused exact-name tests passed (`2/2`); the full science database suite passed (`72/72`); root typecheck passed; root build passed with existing RDKit/3Dmol/large-chunk warnings; architecture check passed with only existing split-debt warnings after extracting the new exact helpers; website lint/typecheck/build passed (`34` pages); full `npm test` passed (`569/569`); `git diff --check` passed; and `npm pack --dry-run --json` passed (`entryCount: 393`, shasum `ccaaa2cabc370550fe6d291ce4213ff3ea3fc8f7`). - Next: Continue the next Bio Tool stub domain from `outputs/.plans/claude-science-gap-manifest.md`. ### 2026-07-05 04:25 EDT — schema-stub-closure-parity - Objective: Close the remaining active Claude Science SQLite migration stubs while keeping Feynman's workbench standalone and Feynman-owned. - Changed: Added physical `egress_policy` and `modal_environment` columns to Feynman's org-level `compute_providers` mirror with idempotent old-database upgrade guards. Tightened Feynman-owned ledger coverage for split science directory attachments, split MCP tool grants, and custom MCP `resourceIdentifier` rows, with no `bundled:bio` or reference-runtime dependency. - Verified: Focused migration coverage passed (`12/12`) across directory attachments, MCP grants, compute-provider rows, custom MCP ledgers, org-database materialization, and reference-table coverage. Reference-table coverage now also guards that legacy `canvas_drafts` and `child_landed` cleanup surfaces stay absent from Feynman's owned database. The gap manifest now marks screens/chunks `52 done / 0 stub / 0 missing` and SQLite migrations `96 done / 0 stub / 0 missing`. - Next: Run full root and website gates, then continue only on concrete remaining 1:1 gaps found in real shipped science artifacts or reference-backed science workflow behavior. ### 2026-07-05 08:41 EDT — intake-sweep-clean-queue - Objective: Run the `check-new-issues` intake sweep against the current dirty Feynman checkout without disturbing unrelated local work. - Checked: Live GitHub queue still has open issues `#182` and `#184`, zero open PRs, latest main `Publish and Release` run green at `cb5fa56`, GitHub release `v0.3.5`, npm `@companion-ai/feynman@0.3.5`, Pi `0.80.3`, and alpha-hub `0.1.3`. Recently pushed forks checked against `companion-inc:main` were identical, and configured `pr4fork/main` had no ahead diff after fetch. - Decisions: No repo code change was needed. `#182` remains deferred/external because Feynman delegates alpha login to alpha-hub and the installed auth source owns the Clerk/local callback flow; current installed `feynman alpha status` works. `#184` remains outside the AI-researcher product bar as support/advice, not a Feynman feature. No open PRs to merge, port, reject, or defer. - Verified: `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/large-chunk warnings; `npm run architecture:check` with existing split-debt warnings; full `npm test` (`583/583`); website `lint`, `typecheck` (`0 errors`), and `build` (`34 pages`); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `bde0f2997a29c79dc979080b39b0c32a6fb7aad8`); installed-tarball smoke passed for `feynman --version`, `feynman --help`, and `feynman alpha status`. - Next: Keep the existing dirty workbench/science-database lane intact; act only on a fresh Feynman-owned repro or a PR with a direct research-loop fix. ### 2026-07-05 11:56 EDT — workbench-artifact-pane-default - Objective: Fix frame routes with run artifacts opening without the right-side artifact pane selected. - Changed: Added a shared default-artifact resolver that selects `run.primaryArtifact.path` when it exists, falls back to the first existing run artifact path, and uses that default on direct frame loads, browser back/forward, run-list selection, launcher navigation, and command-palette project/run opens. - Verified: The live frame `session-20260705035324-621b20` exposes `outputs/e2e-workbench-proof.md` as its primary artifact through `/api/state`; after rebuilding, the in-app browser rendered one right-side panel, one selected artifact row, and the preview for `End-to-End Workbench Proof` at the exact frame URL without a query-string artifact parameter. Focused React/file-surface tests passed (`17/17`), `npm run typecheck` passed, `npm run build:workbench-web` passed with existing science-viewer bundle warnings, `npm run architecture:check` passed with existing split-debt warnings, `git diff --check` passed, and full `npm test` passed (`585/585`). - Next: Continue closing concrete workbench parity gaps from the live Feynman frame and installed Claude Science reference behavior. ### 2026-07-05 13:48 EDT — generated-artifact-tiles-parity - Objective: Match the Claude Science project-frame behavior where artifact-only science runs show generated artifact cards in the main conversation surface, not only in the Files pane. - Changed: Empty-message frames with run artifacts now render a `Generated` artifact grid in the transcript, using Feynman-owned artifact metadata and `/api/file/download` thumbnails for image artifacts. The tiles prioritize output, visual, and data artifacts, open the existing artifact inspector on click, and keep the right Files pane usable without covering cards. The side-pane breakpoints now reserve transcript space on desktop and use a mobile bottom sheet instead of a full-height overlay. - Verified: Focused React/file-surface tests passed (`17/17`), `npm run typecheck` passed, and `npm run build:workbench-web` passed with existing RDKit/3Dmol/large-chunk warnings. Browser verification on `example_immunotherapy` rendered `8` generated tiles with `7` image thumbnails, no empty state, no transcript messages, desktop cards ending at `929px` before the Files pane starting at `945px`, and mobile cards at `362px` width with the bottom sheet starting below the first tile. Clicking the first generated tile selected `Single-cell dissection of immune cell states before and during checkpoint immunotherapy in melanoma`. - Next: Run the broader repo gates, commit this parity slice, then continue to the next visible Claude Science workbench gap. ### 2026-07-05 14:05 EDT — generated-frame-default-pane-parity - Objective: Match the Claude Science generated-artifact frame default: main artifact cards visible first, Files pane opened by explicit file action or artifact route only. - Changed: Direct frame loads, browser back/forward, rail session selection, and generic project/run opens no longer auto-open the right Files pane merely because a run has artifacts. Feynman still keeps the default artifact selected for context, opens Files after a generated tile click, and opens Files for explicit `artifact=` URLs. The conversation grid now has an explicit constrained column so the generated-card grid cannot overflow the viewport when the side pane is closed. - Verified: Browser verification on `example_immunotherapy` showed direct load with no side panel, `8` generated tiles, `7` image thumbnails, body width equal to the `1280px` viewport, conversation width `922px`, generated grid ending at `1199px`, tile click opening Files with the selected immunotherapy report artifact, and explicit artifact URL loading with Files open. Final gates passed: focused React/file-surface tests (`17/17`), `npm run typecheck`, `npm run build:workbench-web` with existing science-viewer bundle warnings, `npm run architecture:check` with existing split-debt warnings, `git diff --check`, and full `npm test` (`585/585`). - Next: Commit this default-pane parity slice, then continue to the next visible Claude Science workbench gap. ### 2026-07-05 14:23 EDT — rail-header-reference-parity - Objective: Match Claude Science's project rail header structure while keeping Feynman-owned navigation behavior. - Changed: Replaced the old branded rail header with a compact back button, truncated project switcher/dropdown button, and split-pane toggle. Back returns to the project launcher, the title opens the command palette, and the split control toggles Files. The old `project-mark` header visual no longer renders in the workbench rail. - Verified: Browser verification on `example_immunotherapy` showed header width `329px`, two `38px` icon controls, `Feynman Workspace` title button, no `.project-mark`, rail actions still limited to `New chat`, `Customize`, and `Files`, no default side panel, and body width equal to the `1280px` viewport. Final gates passed: focused React/file-surface tests (`17/17`), `npm run typecheck`, `npm run build:workbench-web` with existing science-viewer bundle warnings, `npm run architecture:check` with existing split-debt warnings, `git diff --check`, and full `npm test` (`585/585`). - Next: Commit this rail-header parity slice, then continue to topbar/context density parity. ### 2026-07-05 17:10 EDT — topbar-context-density-parity - Objective: Match Claude Science's project-frame top chrome by making the main canvas title-first and removing Feynman's heavy status/control and run-metric rows from the first viewport. - Changed: Removed the visible `Science workbench` eyebrow, hid the topbar status/model/session controls from the frame header, hid the context metric strip, and restyled the topbar as a quiet title band aligned with the generated artifact canvas. Model/session controls remain in source for existing configuration paths, while the visible frame no longer spends first-viewport space on them. - Verified: Browser verification on `example_immunotherapy` showed title x/y `432/44`, no visible topbar status, `.topbar-right` display `none`, `.context-strip` display `none`, `8` generated tiles, `7` image thumbnails, no side panel, and body width equal to the `1280px` viewport. Final gates passed: focused React/file-surface tests (`17/17`), `npm run typecheck`, `npm run build:workbench-web` with existing science-viewer bundle warnings, `npm run architecture:check` with existing split-debt warnings, `git diff --check`, and full `npm test` (`585/585`). - Next: Commit this topbar/context parity slice, then continue to the next visible Claude Science workbench mismatch. ### 2026-07-06 00:47 EDT — intake-sweep-btw-core-package - Objective: Run the `check-new-issues` intake sweep against the current Feynman checkout and preserve unrelated local worktree changes. - Checked: Live GitHub queue has open issues `#185`, `#184`, and `#182`, with zero open PRs. Latest `main` publish run is `Publish and Release` `28755882698`, green at `fa26693`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest/current remains `0.3.5`; Pi latest/current is `0.80.3`; alpha-hub latest/current is `0.1.3`. Refreshed contributor refs are stale behind `origin/main`, have no ahead diff, or contain old platform/provider/admin/export/prompt churn rather than a fresh research-loop fix. - Decisions: Ported the safe core of issue `#185` by restoring the existing `pi-btw` package to Feynman's default Pi package stack; this directly improves research-loop reliability during long-running turns without inventing a Feynman-owned interrupt mechanism. `#184` remains outside Feynman's AI-researcher product bar as support/advice, not a repo feature. `#182` remains deferred/external because diagnostics still point at the alphaXiv/Clerk OAuth redirect before Feynman can exchange a token, while current installed-package `alpha status` succeeds. No open PRs to merge, port, reject, or defer. - Changed: Added `npm:pi-btw` to `CORE_PACKAGE_SOURCES` and bundled `.feynman/settings.json`, updated settings regression coverage, README slash-command docs, public release notes, and website package/setup/CLI/slash docs. - Verified: `npm test` passed (`585/585`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`), and `npm run build` (`34 pages`); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `cc7a11600c6ebf36481195626203769be3c52dcb`); runtime archive inspection found `npm/node_modules/pi-btw/package.json` and `extensions/btw.ts`; installed-tarball smoke from `/tmp/feynman-pack-smoke-UVJiTx/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, `feynman --help`, `feynman packages list` showing `npm:pi-btw` in Core, `feynman alpha status`, and installed runtime archive inspection. - Next: Commit or push only when explicitly authorized; otherwise keep the unrelated active workbench edits intact and treat `#185` as locally fixed pending review. ### 2026-07-06 04:47 EDT — intake-sweep-btw-validation-fix - Objective: Re-run the `check-new-issues` intake sweep from the current dirty checkout, preserve unrelated local work, and validate the uncommitted `#185` package-stack slice. - Checked: Live GitHub queue still has open issues `#185`, `#184`, and `#182`, with zero open PRs. Latest `main` publish run remains `Publish and Release` `28755882698`, green at `fa26693`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest/current remains `0.3.5`; Pi latest/current is `0.80.3`; alpha-hub latest/current is `0.1.3`; `pi-btw` latest/current inspected is `0.4.1`. Configured contributor refs are stale behind `origin/main`, have no ahead diff, or contain old platform/provider/admin/export/prompt churn; recent GitHub forks have no open PRs. - Decisions: Kept the prior safe `#185` local port because bundled `pi-btw` directly improves long-running research-loop steering without adding a Feynman-owned interrupt mechanism. `#184` remains outside the AI-researcher product bar as support/advice. `#182` remains deferred/external because issue evidence still points at alphaXiv/Clerk redirect behavior before Feynman receives a callback, while installed-package `alpha status` succeeds. No PRs to merge, port, reject, or defer. - Changed: Fixed stale package-install regression tests that still used `npm:pi-btw` as an external Pi-package fixture after `pi-btw` became a bundled core package; the tests now use `npm:@luxusai/pi-hindsight` to exercise runtime peer installation. - Verified: Focused `tests/package-ops.test.ts` passed (`10/10`) and `tests/pi-settings.test.ts` passed (`13/13`); full `npm test` passed (`585/585`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`), and `npm run build` (`34 pages`); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `cc7a11600c6ebf36481195626203769be3c52dcb`); runtime archive inspection found bundled `pi-btw` files; installed-tarball smoke from `/tmp/feynman-pack-smoke-wNU13j/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, `feynman --help`, `feynman packages list` showing `npm:pi-btw` in Core, and `feynman alpha status`. - Next: Commit or push only when explicitly authorized; otherwise keep the local `#185` fix plus unrelated workbench edits intact. ### 2026-07-06 08:43 EDT — intake-sweep-btw-still-current - Objective: Re-run the `check-new-issues` intake sweep against the current dirty checkout, preserve unrelated local work, and verify whether new GitHub queue, release, package, contributor, or validation state requires another local fix. - Checked: Live GitHub queue still has open issues `#185`, `#184`, and `#182`, with zero open PRs. Latest `main` publish run remains `Publish and Release` `28755882698`, green at `fa26693`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest/current remains `0.3.5`; Pi latest/current is `0.80.3`; alpha-hub latest/current is `0.1.3`; `pi-btw` latest/current is `0.4.1`. Configured contributor refs remain stale behind `origin/main`, have no ahead diff, or contain old provider/platform/export/prompt/admin churn instead of a fresh research-loop fix. - Decisions: No new code changes were needed. Issue `#185` remains locally covered by the uncommitted `pi-btw` core-package slice. Issue `#184` remains outside Feynman's AI-researcher product bar as support/advice. Issue `#182` remains deferred/external because issue evidence still points at alphaXiv/Clerk redirect behavior before Feynman receives a callback, while installed-package `alpha status` succeeds. No PRs to merge, port, reject, or defer. - Verified: Focused package/settings tests passed (`23/23`); full `npm test` passed (`585/585`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/patristic warnings; `npm run architecture:check` with existing split-debt warnings; root and website `npm audit --omit=dev` (`0 vulnerabilities`); website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`), and `npm run build` (`34 pages`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `cc7a11600c6ebf36481195626203769be3c52dcb`); real tarball smoke from `/tmp/feynman-pack-smoke-iA1hyV/companion-ai-feynman-0.3.5.tgz` found bundled `pi-btw` files and passed `feynman --version`, `feynman --help`, `feynman packages list` showing `npm:pi-btw` in Core, and `feynman alpha status`. - Next: Commit or push only when explicitly authorized; otherwise keep the local `#185` fix plus unrelated workbench edits intact. ### 2026-07-06 16:46 EDT — intake-sweep-no-new-action - Objective: Re-run the `check-new-issues` intake sweep against the current dirty checkout, preserve unrelated local work, and check whether fresh GitHub, release, package, contributor, or validation state requires another local fix. - Checked: Live GitHub queue still has open issues `#185`, `#184`, and `#182`, with zero open PRs. Latest `main` publish run remains `Publish and Release` `28755882698`, green at `fa26693`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest/current remains `0.3.5`; Pi latest/current is `0.80.3`; alpha-hub latest/current is `0.1.3`; `pi-btw` latest/current is `0.4.1` with Pi peer range `>=0.74.0 <1`. Configured contributor refs remain stale behind `origin/main`, have no ahead diff, or contain old provider/platform/export/prompt/admin churn instead of a fresh research-loop fix. Recently pushed forks `gaadha1985`, `nagyist`, `TheTechOddBug`, `dubbypanda`, and `ussdeveloper` point at current `fa26693`; `founderqiang` points at already-merged `209fe2f`. - Decisions: No new code changes were needed. Issue `#185` remains locally covered by the uncommitted `pi-btw` core-package slice because it improves long-running research-loop steering without adding a Feynman-owned interrupt protocol. Issue `#184` remains outside Feynman's AI-researcher product bar as support/advice. Issue `#182` remains deferred/external because issue evidence still points at alphaXiv/Clerk redirect behavior before Feynman receives a callback, while installed-package `alpha status` succeeds. No PRs to merge, port, reject, or defer. - Freshness: Root and website have dependency drift only; root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: Full `npm test` passed (`585/585`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/patristic warnings; `npm run architecture:check` with existing split-debt warnings; root and website `npm audit --omit=dev` (`0 vulnerabilities`); website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34 pages`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `cc7a11600c6ebf36481195626203769be3c52dcb`); real tarball smoke from `/tmp/feynman-pack-smoke-NGGFzK/companion-ai-feynman-0.3.5.tgz` found bundled `pi-btw` files and passed `feynman --version`, `feynman --help`, `feynman packages list` showing `npm:pi-btw` in Core, and `feynman alpha status`. - Next: Commit or push only when explicitly authorized; otherwise keep the local `#185` fix plus unrelated workbench edits intact. ### 2026-07-06 20:45 EDT — intake-sweep-no-new-action - Objective: Re-run the `check-new-issues` intake sweep against the current dirty checkout, preserve unrelated local work, and check whether fresh GitHub, release, package, contributor, or validation state requires another local fix. - Checked: Live GitHub queue still has open issues `#185`, `#184`, and `#182`, with zero open PRs. Latest `main` publish run remains `Publish and Release` `28755882698`, green at `fa26693`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest/current remains `0.3.5`; Pi latest/current is `0.80.3`; alpha-hub latest/current is `0.1.3`; `pi-btw` latest/current is `0.4.1` with Pi peer range `>=0.74.0 <1`. Configured contributor refs remain stale behind `origin/main`, have no ahead diff, or contain old provider/platform/export/prompt/admin churn instead of a fresh research-loop fix. Recent public forks checked were current at `fa26693` or old at already-published `cb5fa56`. - Decisions: No new code changes were needed. Issue `#185` remains locally covered by the uncommitted `pi-btw` core-package slice because it improves long-running research-loop steering without adding a Feynman-owned interrupt protocol. Issue `#184` remains outside Feynman's AI-researcher product bar as support/advice. Issue `#182` remains deferred/external because issue evidence still points at alphaXiv/Clerk redirect behavior before Feynman receives a callback, while installed-package `alpha status` succeeds. No PRs to merge, port, reject, or defer. - Freshness: Root and website have dependency drift only; root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: Full `npm test` passed (`585/585`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/patristic warnings; `npm run architecture:check` with existing split-debt warnings; root `npm audit --omit=dev` (`0 vulnerabilities`); website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), `npm run build` (`34 pages`), and `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `cc7a11600c6ebf36481195626203769be3c52dcb`); real tarball smoke from `/tmp/feynman-pack-smoke-uvbzpV/companion-ai-feynman-0.3.5.tgz` found bundled `pi-btw` files and passed `feynman --version`, `feynman --help`, `feynman packages list` showing `npm:pi-btw` in Core, and `feynman alpha status`. - Note: The first real-pack metadata parser hit the known mixed-log JSON shape after the tarball was created; the produced tarball was used directly for archive inspection and installed-package smoke. - Next: Commit or push only when explicitly authorized; otherwise keep the local `#185` fix plus unrelated workbench edits intact. ### 2026-07-09 00:59 EDT — intake-sweep-alpha-oauth-current - Objective: Re-run the `check-new-issues` intake sweep against the current dirty checkout, preserve unrelated local work, and verify whether fresh GitHub, release, package, contributor, or validation state requires another safe local fix. - Checked: Live GitHub queue still has open issues `#185`, `#184`, and `#182`, with zero open PRs. Latest `main` `Publish and Release` run is `28835967900`, green at `54d08a3`; local `main` is aligned with `origin/main` at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest/current remains `0.3.5`; Pi latest/current is `0.80.3`; alpha-hub latest/current is `0.1.3`; `pi-btw` latest/current is `0.4.1`. - Decisions: No new code changes were needed. Issue `#182` is locally covered by the existing pending alphaXiv OAuth2 endpoint patch in `scripts/lib/alpha-hub-auth-patch.mjs`, `scripts/prepare-runtime-workspace.mjs`, and `tests/alpha-hub-auth-patch.test.ts`; installed-tarball archive inspection verified the patched `@companion-ai/alpha-hub/src/lib/auth.js` uses `https://api.alphaxiv.org/auth`, `oauth2/authorize`, and `openid profile email offline_access`. Issue `#185` remains covered by bundled `pi-btw`. Issue `#184` remains outside Feynman's AI-researcher product bar as support/advice. No PRs to merge, port, reject, or defer. - Contributor refs: `origin/fix/deepresearch-local-model-warning` is stale behind `origin/main` and its useful local-model warning behavior is already present in current source/tests. Other sampled fork refs are behind `origin/main` with provider setup, Overleaf/export/admin prompts, Claude CLI bypass, architecture notes, fork-specific search tooling, broad platform churn, or runtime/setup churn; no clean core-research patch was ported. - Freshness: Root and website `npm outdated --json` show dependency drift only; root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: Focused alpha/runtime tests passed (`27/27`); full `npm test` passed (`586/586`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/chunk/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `01d621ba42cd8d159489a18aef58778887ade7e9`); installed tarball smoke from `/tmp/feynman-pack-smoke-QRXTHd/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, `feynman --help`, `feynman packages list` showing `npm:pi-btw`, `feynman alpha status`, bundled `pi-btw` files, and alpha OAuth2 runtime archive inspection. - Note: The first archive-inspection path in the smoke used a stale `package/npm/...` prefix and failed after install; the corrected archive path `npm/node_modules/@companion-ai/alpha-hub/src/lib/auth.js` passed. - Next: Commit or push only when explicitly authorized; otherwise keep the local alpha OAuth patch and lab notebook entry local-only. ### 2026-07-09 10:22 EDT — intake-sweep-alpha-oauth-still-current - Objective: Re-run the `check-new-issues` intake sweep against the current dirty checkout, preserve unrelated local work, and verify whether fresh GitHub, release, package, contributor, or validation state requires another local fix. - Checked: Live GitHub queue still has open issues `#185`, `#184`, and `#182`, with zero open PRs. Local `main` is aligned with `origin/main` at `54d08a3`; latest main `Publish and Release` run `28835967900` is green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest/current remains `0.3.5`; Pi latest/current is `0.80.3`; alpha-hub latest/current is `0.1.3`; `pi-btw` bundled runtime package is `0.4.1`. - Decisions: No new code changes were needed. Issue `#182` remains locally covered by the pending alphaXiv OAuth2 endpoint patch in `scripts/lib/alpha-hub-auth-patch.mjs`, `scripts/prepare-runtime-workspace.mjs`, and `tests/alpha-hub-auth-patch.test.ts`; direct source and installed-tarball archive checks verified the patched `@companion-ai/alpha-hub/src/lib/auth.js` uses `https://api.alphaxiv.org/auth`, `oauth2/authorize`, and `openid profile email offline_access`. Issue `#185` remains covered by bundled `pi-btw`. Issue `#184` remains outside Feynman's AI-researcher product bar as support/advice. No PRs to merge, port, reject, or defer. - Contributor refs: Configured remote refs remain stale or non-actionable: `origin/fix/deepresearch-local-model-warning` is behind current `main`, `pr4fork/main` contains old runtime/telemetry churn, and sampled fork refs contain old provider/export/admin/prompt/platform changes rather than a fresh core research-loop fix. - Freshness: Root and website `npm outdated --long` show dependency drift only; root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: Full `npm test` passed (`586/586`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/chunk/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `01d621ba42cd8d159489a18aef58778887ade7e9`); installed tarball smoke from `/tmp/feynman-pack-smoke-ljaPtX/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, `feynman --help`, `feynman packages list` showing `npm:pi-btw`, `feynman alpha status`, bundled `pi-btw` files, and alpha OAuth2 runtime archive inspection. - Next: Commit or push only when explicitly authorized; otherwise keep the local alpha OAuth patch and lab notebook entry local-only. ### 2026-07-09 13:09 EDT — intake-sweep-alpha-oauth-still-current - Objective: Re-run the `check-new-issues` intake sweep against the current dirty checkout, preserve unrelated local work, and verify whether fresh GitHub, release, package, contributor, or validation state requires another local fix. - Checked: Local `main` is aligned with `origin/main` at `54d08a3`. Live GitHub queue still has open issues `#185`, `#184`, and `#182`, with zero open PRs. Latest main `Publish and Release` run `28835967900` is green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest/current remains `0.3.5`; `@earendil-works/pi-coding-agent` latest/current remains `0.80.3`; alpha-hub latest/current remains `0.1.3`; `pi-btw` latest/current remains `0.4.1`. - Decisions: No new code changes were needed. Issue `#182` remains locally covered by the pending alphaXiv OAuth2 endpoint patch in `scripts/lib/alpha-hub-auth-patch.mjs`, `scripts/prepare-runtime-workspace.mjs`, and `tests/alpha-hub-auth-patch.test.ts`; installed-tarball archive checks verified the patched `@companion-ai/alpha-hub/src/lib/auth.js` uses `https://api.alphaxiv.org/auth`, `oauth2/authorize`, `oauth2/token`, `oauth2/register`, `oauth2/userinfo`, and `openid profile email offline_access`. Issue `#185` remains covered by bundled `pi-btw`. Issue `#184` remains outside Feynman's AI-researcher product bar as support/advice. No PRs to merge, port, reject, or defer. - Contributor refs: No checked contributor branch or fork was ahead of `origin/main`. Recent public forks `ifr1m`, `QuantumKuba`, `ivnvalex`, and `colindomoney` match `54d08a3`; `ussdeveloper` is behind by 3 commits; `advaitpaliwal`, `skandanyal`, and `gaurav-g-alva` are behind by 18 commits. Configured remote refs remain stale or non-actionable: `origin/fix/deepresearch-local-model-warning` is behind by 74 with one already-covered ahead commit, and `pr4fork/main` is behind by 73 with zero ahead. - Freshness: Root and website `npm outdated --long --json` show dependency drift only; root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: Focused alpha/runtime/settings tests passed (`31/31`); full `npm test` passed (`586/586`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/chunk/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `01d621ba42cd8d159489a18aef58778887ade7e9`); real installed tarball smoke from `/tmp/feynman-pack-smoke-CUZfeY/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, current styled help, `feynman packages list` showing `npm:pi-btw`, `feynman alpha status`, bundled `pi-btw` files, and alpha OAuth2 runtime archive inspection. - Note: The first installed-smoke archive inspection hit the known `tar -tzf` `ENOBUFS` failure from buffer-based archive listing, and a stale help assertion expected `Usage: feynman`; the streamed archive check plus current-help assertion passed. Temp smoke artifacts were removed. - Next: Commit or push only when explicitly authorized; otherwise keep the local alpha OAuth patch and lab notebook entry local-only. ### 2026-07-09 17:17 EDT — intake-sweep-pi-0805-refresh - Objective: Re-run the `check-new-issues` intake sweep against the current dirty checkout, preserve unrelated local work, and port only safe core-research fixes. - Checked: Local `main` is aligned with `origin/main` at `54d08a3`. Live GitHub queue still has open issues `#185`, `#184`, and `#182`, with zero open PRs. Latest main `Publish and Release` run `28835967900` is green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest/current remains `0.3.5`; `@companion-ai/alpha-hub` latest/current remains `0.1.3`; `pi-btw` latest/current remains `0.4.1`; `@earendil-works/pi-*` latest is now `0.80.5`. - Decisions: Ported the smallest safe package freshness fix by bumping Feynman's pinned Pi runtime packages from `0.80.3` to `0.80.5`, because upstream `0.80.5` includes research-loop reliability fixes around provider retries/errors, truncated tool calls, session/context handling, extension lifecycle, and cache visibility. Issue `#182` remains locally covered by the pending alphaXiv OAuth2 endpoint patch; issue `#185` remains covered by bundled `pi-btw`; issue `#184` remains outside Feynman's AI-researcher product bar as support/advice. No PRs to merge, port, reject, or defer. - Contributor refs: `origin/fix/deepresearch-local-model-warning` is behind current `main` with one already-covered ahead commit; `pr4fork/main` is behind with zero ahead. Sampled fork refs contain old Overleaf/export, provider setup, Claude bypass, platform churn, architecture notes, or fork-specific search changes rather than a fresh core research-loop fix. - Changed: Updated `package.json` and `package-lock.json` to `@earendil-works/pi-agent-core`, `pi-ai`, `pi-coding-agent`, and `pi-tui` `0.80.5`; updated Pi runtime fallback constants in `src/pi/package-ops.ts` and `scripts/prepare-runtime-workspace.mjs`. - Freshness: Root `npm outdated --long --json` now shows only non-Pi dependency drift; website drift remains non-security dependency drift. Root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: Focused package/runtime tests passed (`39/39`); full `npm test` passed (`586/586`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/chunk/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `3ac05c3ab4e19620ea6ad8946c91809e7ba47a70`); real tarball smoke from `/tmp/feynman-pack-smoke-XpXZOs/companion-ai-feynman-0.3.5.tgz` passed for `feynman --version`, current styled help, `feynman packages list` showing `npm:pi-btw`, `feynman alpha status`, installed Pi `0.80.5`, runtime archive Pi `0.80.5`, and alpha OAuth2 runtime archive inspection. - Note: The first tarball install attempt failed because a stale `/tmp/feynman-pack-smoke-*` directory plus npm cache left only `175M` free; cleared only Feynman smoke temp directories and npm cache, then reran the smoke successfully. The initial corrected smoke used a stale alpha-hub `cli/src` archive path; the actual packaged path is `npm/node_modules/@companion-ai/alpha-hub/src/lib/auth.js` and passed. - Next: Commit or push only when explicitly authorized; otherwise keep the local Pi `0.80.5` refresh plus existing alpha OAuth patch local-only. ### 2026-07-10 01:12 EDT — intake-sweep-pi-0806-still-current - Objective: Re-run the `check-new-issues` intake sweep against the current dirty checkout, preserve unrelated local work, and verify whether fresh GitHub, release, package, contributor, or validation state requires another local fix. - Checked: Local `main` is aligned with `origin/main` at `54d08a3`. Live GitHub queue still has open issues `#185`, `#184`, and `#182`, with zero open PRs. Latest main `Publish and Release` run `28835967900` is green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest/current remains `0.3.5`; `@companion-ai/alpha-hub` remains `0.1.3`; `pi-btw` remains `0.4.1`; `@earendil-works/pi-*` remains `0.80.6`. - Decisions: No new code changes were needed. Issue `#182` remains locally covered by the pending alphaXiv OAuth2 endpoint patch; issue `#185` remains covered by bundled `pi-btw`; issue `#184` remains outside Feynman's AI-researcher product bar as support/advice. No PRs to merge, port, reject, or defer. - Contributor refs: `origin/fix/deepresearch-local-model-warning` is behind current `main` with one already-covered ahead commit; `pr4fork/main` is behind with zero ahead. Sampled fork refs contain old Bedrock/provider/export/admin/prompt/platform/search changes rather than a fresh core research-loop fix. - Freshness: Root and website `npm outdated --long --json` show dependency drift only; root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: Full `npm test` passed (`586/586`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/chunk/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `35c88e81b93f395c695cab93e46bbde1f6f27bd6`); real installed tarball smoke passed for `feynman --version`, `feynman packages list` showing `npm:pi-btw`, `feynman alpha status`, installed Pi `0.80.6`, bundled runtime `pi-btw`, and alpha OAuth2 runtime archive inspection. - Note: The first installed-smoke metadata assertion used a package-local Pi path and failed after npm hoisted Pi top-level; the corrected filesystem metadata and runtime archive checks passed. Temp smoke artifacts and the root tarball were removed. - Next: Commit or push only when explicitly authorized; otherwise keep the local Pi `0.80.6` refresh plus existing alpha OAuth patch local-only. ### 2026-07-10 05:08 EDT — intake-sweep-pi-0806-still-current - Objective: Re-run the `check-new-issues` intake sweep against the current dirty checkout, preserve unrelated local work, and verify whether fresh GitHub, release, package, contributor, or validation state requires another local fix. - Checked: Local `main` is aligned with `origin/main` at `54d08a3`. Live GitHub queue still has open issues `#185`, `#184`, and `#182`, with zero open PRs. Latest main `Publish and Release` run `28835967900` is green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` latest/current remains `0.3.5`; `@companion-ai/alpha-hub` remains `0.1.3`; `pi-btw` remains `0.4.1`; `@earendil-works/pi-*` remains `0.80.6`. - Decisions: No new code changes were needed. Issue `#182` remains locally covered by the pending alphaXiv OAuth2 endpoint patch; issue `#185` remains covered by bundled `pi-btw`; issue `#184` remains outside Feynman's AI-researcher product bar as support/advice. No PRs to merge, port, reject, or defer. - Contributor refs: `origin/fix/deepresearch-local-model-warning` is behind current `main` with one already-covered ahead commit; `pr4fork/main` is behind with zero ahead. Sampled fork refs contain old Overleaf/export, MiniMax/provider setup, Claude bypass, Bedrock setup, architecture notes, fork-specific search tooling, or Windows/platform churn rather than a fresh core research-loop fix. - Freshness: Root and website `npm outdated --long --json` show dependency drift only; root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: Full `npm test` passed (`586/586`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/chunk/patristic warnings; `npm run architecture:check` with existing split-debt warnings; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 401`, shasum `35c88e81b93f395c695cab93e46bbde1f6f27bd6`); real installed tarball smoke passed for `feynman --version`, `feynman --help`, `feynman packages list` showing `npm:pi-btw`, `feynman alpha status`, installed Pi `0.80.6`, runtime archive Pi `0.80.6`, bundled runtime `pi-btw`, and alpha OAuth2 runtime archive inspection. - Next: Commit or push only when explicitly authorized; otherwise keep the local Pi `0.80.6` refresh plus existing alpha OAuth patch local-only. ### 2026-07-10 13:24 EDT — feynman-e2e-oauth-mcp-repair - Objective: Reproduce the current user-reported failures and verify Feynman across source, real OAuth/provider flows, MCP transports, cloud clean-room execution, research output, and the packed npm artifact. - Live queue: Classified issues `#182`, `#184`, `#185`, and `#186`; there are zero open PRs. `#182` and `#186` have local fixes, `#185` is implemented on `main` but unreleased, and `#184` is support rather than a product defect. Public npm/GitHub release remains `0.3.5`. - Fixed: Extended the alpha-hub runtime patch to reject missing or mismatched OAuth callback state. Fixed a separate workbench data-loss race discovered by the full suite: valid `active-org.json` manifests are no longer rewritten on every lookup, creation and required upgrades are atomic, and concurrent readers no longer mint new org UUIDs after observing a truncated file. - State recovery: The race had redirected the live pointer to a test-only org created during the suite. Restored it to the most recent org containing the real Feynman workspace, backed up the prior pointer at `~/.feynman/.state/active-org-pre-recovery-20260710-1324.json`, and deleted or merged no org data. Twenty repeated lookups preserved the same mode-`0600` manifest; the recovered workbench exposed 6 projects, 60 runs, and 445 artifacts. - Live verification: Fresh alphaXiv browser OAuth, authenticated keyword/semantic search, and paper retrieval passed; OpenAI model execution returned the required sentinel; custom MCP Streamable HTTP, SSE, stdio, bearer OAuth, grants, and callback/disconnect passed; `/btw` returned `BTW_E2E_OK` during a rate-limited `/lit` run. Anthropic OAuth reached the real provider page but remained blocked by the logged-out external account. - Compute and artifacts: Authenticated Daytona CLI created a clean sandbox, cloned and tested the checkout, and deleted the sandbox. `/lit` produced `outputs/loopback-oauth-pkce.md`, its provenance sidecar, and a verification record. No E2B credential was promoted or tested. - Verified: Full tests passed (`590/590`); typecheck, root build, architecture check, website lint/typecheck/build, root and website production audits (`0 vulnerabilities`), and `git diff --check` passed. `npm pack --dry-run` and a real clean-home tarball install passed; the shipped runtime contains Pi `^0.80.6`, `pi-btw` `^0.4.1`, current alphaXiv endpoints, and loopback state validation. - Security: The inherited Daytona key is usable but remains as a literal in a mode-`0644` shell file and entered an internal tool transcript during discovery. Rotate it and move the replacement into a user-only secret store; do not reuse the exposed value. - Persistence: Local-only and uncommitted. Next: run the installer on Windows 11, complete any required Anthropic OAuth from a signed-in account, bump the version, and publish before describing the fixes as user-visible. ### 2026-07-10 15:41 EDT — feynman-e2e-user-issue-release - Objective: Finish the live issue sweep, repair every actionable user-facing failure, verify the release artifact, and publish the work for review. - Fixed: Added the packaged Option+Enter newline binding without overwriting user keybindings; moved `fetch_content` PDF scratch output from `~/Downloads` to project-local `.feynman/cache/fetch-content` with an environment override; added actionable help for unknown CLI flags; documented that package updates already include extensions; retained the alphaXiv OAuth, Windows staged-installer, active-org atomicity, Pi `0.80.6`, and bundled `pi-btw` fixes from the preceding repair. - GitHub: Ported contributor PR `#189` with its original attribution. Left PR `#191` unported because it adds a broader extensions-management surface while issue `#187` only requires clear update behavior and error guidance. Issue `#184` remains a support request rather than a Feynman product defect. - Verified: Focused regression suites passed (`98/98`); the complete suite passed (`593/593`); typecheck, production build, architecture guard, website lint/typecheck/build (`34` pages), root and website production audits (`0 vulnerabilities`), `git diff --check`, and a gitleaks diff scan passed. A clean installed `0.3.6` tarball passed version, main help, alpha help, package listing, unknown `--extensions` guidance, packaged keybindings, Windows installer equality, Pi `^0.80.6`, `pi-btw` `^0.4.1`, current alphaXiv OAuth endpoints, and project-local PDF-cache inspection. - Security: Moved the Daytona API key from plaintext `~/.zshrc` into macOS Keychain, verified a fresh shell loads the same credential, and passed an authenticated `daytona list`. The existing key was not revoked because Daytona deletion is immediate and this machine has neither a manager JWT nor an account-wide consumer inventory; rotate it after identifying every consumer. - Environment: The first full-suite attempt failed only with `ENOSPC` across 112 temp-directory creations; removed 5,394 stale Feynman test workspaces and reran cleanly. Tarball verification also required clearing reproducible npm/Bun/Homebrew/module/updater caches because the data volume remained effectively full. - Persistence: Published for review on `codex/fix-feynman-user-issues`. Next: merge only after review, let the main-branch publish workflow validate the package on Ubuntu, then dispatch the published-package macOS/Linux/Windows install matrix before calling the Win11 fix live-verified. ### 2026-07-14 03:39 PDT — intake-sweep-pr192-plus-thinking-request - Objective: Re-run the `check-new-issues` intake sweep against the current dirty checkout, preserve unrelated local work, and classify new issue/PR/release/package state against the AI-researcher product bar. - Checked: Live GitHub queue now has open issues `#196`, `#193`, `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`. Open PRs remain `#192`, `#191`, and `#189`. Latest main `Publish and Release` run remains green at `54d08a3`; GitHub release and npm latest remain `v0.3.5` / `0.3.5`; local package remains `0.3.6`; bundled Pi remains `0.80.6`; alpha-hub remains `0.1.3`. - Decisions: No new code changes were needed. Issue `#196` is relevant to research-loop TUI ergonomics but defers upstream to Pi's interactive slash-command layer because Feynman already exposes CLI `--thinking`, model picker, persisted thinking state, and docs/keybinding coverage while Pi owns builtin slash-command dispatch. Issues `#193` and `#182` remain covered by pending `#192` alphaXiv OAuth/hoisted alpha CLI work; `#190`, `#188`, `#187`, `#186`, and `#185` remain covered by PR `#192`; `#184` remains outside the AI-researcher product bar. - PR decisions: `#192` remains the merge path with green Vercel and four commits. `#189` remains already ported into `#192` as cherry-pick `79aa7b2`. `#191` remains reject/defer because it adds a broader `feynman extensions` inventory surface and still has failing Vercel while `#187` only requires update/help guidance. - Contributor refs: `origin/fix/deepresearch-local-model-warning` is `74` behind / `1` ahead; `pr4fork/main` is `73` behind / `0` ahead. Visible fork refs ahead of `origin/main` are Overleaf/admin prompts, MiniMax/provider/platform changes, Claude bypass, Bedrock setup, fork docs/search tooling, architecture notes, or broad Windows rewrites already covered by `#192`; no new safe port target was found. - Freshness: Root and website `npm outdated --json` show dependency drift only; root and website `npm audit --omit=dev` both found `0 vulnerabilities`. - Verified: `npm run typecheck`; `npm run build` with existing Vite/RDKit/3Dmol/chunk warnings; `npm run architecture:check` with existing split-debt warnings; `npm test` passed (`594/594`); website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); root and website `npm audit --omit=dev`; `git diff --check`; `npm pack --dry-run --json` (`entryCount: 402`, shasum `f0b50e989c04095e9a4b3b65628bcf6def9921aa`); real installed-tarball smoke passed for version/help, alpha help/status, packages list including `npm:pi-btw` and `npm:pi-web-access`, hoisted alpha resolver, unknown `--extensions` help hint, and packaged `alt+enter` newline binding. - Probe caveat: An initial string probe expected old built-output/keybinding shapes and reported false negatives; the corrected installed CLI behavior and packaged JSON checks passed. No GitHub writes were made. - Next: Merge/publish PR `#192` when authorized; treat `#196` as a Pi upstream slash-command request unless a Feynman-owned packaging or docs defect is reproduced. ### 2026-07-14 18:43 PDT — intake-sweep-pr192-still-clean - Objective: Re-run `check-new-issues` from `/Users/advaitpaliwal/Companion/Code/feynman`, preserve pre-existing dirty files, refresh GitHub/package/release/branch state, classify open issues/PRs/contributor refs, and run repo-local validation without GitHub writes. - Checked: Current branch remains `codex/fix-feynman-user-issues` at `8ad8d55` tracking `origin/codex/fix-feynman-user-issues`; pre-existing dirty files remained `CHANGELOG.md`, `src/cli.ts`, and `tests/pi-runtime.test.ts`. Open issues remain `#196`, `#193`, `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`; open PRs remain `#192`, `#191`, and `#189`. Latest `main` `Publish and Release` run remains `28835967900`, green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` remains `0.3.5`; local package remains `0.3.6`; Pi latest is `0.80.7` while the local release candidate remains pinned to `0.80.6`; alpha-hub remains `0.1.3`; `pi-btw` remains `0.4.1`. - Decisions: No new code changes were needed. PR `#192` remains the merge/defer path for the local `0.3.6` fix set covering `#182`, `#193`, `#190`, `#188`, `#187`, `#186`, and `#185`; it is still draft, merge-clean, and Vercel green. PR `#189` remains already ported into `#192` as cherry-pick `79aa7b2`. PR `#191` remains reject/defer because it adds a broader `feynman extensions` inventory command while `#187` only requires accurate update/help guidance and the PR's Vercel status remains failing. Issue `#196` remains defer/reject for this sweep because slash-command dispatch belongs to Pi's TUI layer; `#184` remains outside the AI-researcher product bar as a support/content request. - Contributor refs: `origin/fix/deepresearch-local-model-warning` remains `74` behind / `1` ahead; `pr4fork/main` remains `73` behind / `0` ahead. Visible fork refs are stale or broad provider/platform/docs/admin/search changes rather than a current safe research-loop port target. - Freshness: Root and website `npm outdated --json` show non-security drift only, including Pi `0.80.7`, OpenTelemetry, Ketcher, Vite, TypeBox, Astro, Tailwind, and other minor/package updates. No dependency edit was made because no queue-specific root-cause failure required it and the branch is already a validated release candidate. - Verified: `npm run typecheck`; `npm run build` with existing Vite/RDKit/3Dmol/direct-eval/chunk warnings; `npm run architecture:check` with existing split-debt warnings; `npm test` passed (`594/594`); website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 402`, shasum `f0b50e989c04095e9a4b3b65628bcf6def9921aa`, size about `71.9 MB`); corrected installed-tarball smoke passed for package/CLI `0.3.6`, CLI help, alpha help/status, packages list including `npm:pi-btw` and `npm:pi-web-access`, unknown `--extensions` help hint, bundled `alt+enter`, runtime archive entries for `pi-btw`, `pi-web-access`, and Pi, alphaXiv OAuth2 patch, and project-local fetch cache patch. - Probe caveat: Early smoke wrappers failed only from harness assumptions: mixed `npm pack --json` lifecycle output and a stale inner runtime archive `package/` prefix. The corrected smoke used the deterministic tarball filename plus actual inner archive paths and passed; generated tarballs and temp installs were removed. - Next: Merge/publish PR `#192` only when authorized; keep `#191` out unless product scope explicitly expands to extension inventory, and treat Pi `0.80.7` as freshness drift until a research-loop fix justifies changing the validated release candidate. ### 2026-07-16 05:44 PDT — intake-sweep-atlascloud-pr197 - Objective: Re-run `check-new-issues` from `/Users/advaitpaliwal/Companion/Code/feynman`, preserve pre-existing dirty files, refresh GitHub/package/release/branch state, classify the new queue item, and validate the local release candidate without GitHub writes. - Checked: Current branch remains `codex/fix-feynman-user-issues` at `8ad8d55` tracking `origin/codex/fix-feynman-user-issues`; pre-existing dirty files remained `CHANGELOG.md`, `src/cli.ts`, and `tests/pi-runtime.test.ts`. Open issues remain `#196`, `#193`, `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`. Open PRs are now `#197`, `#192`, `#191`, and `#189`. Latest `main` `Publish and Release` run remains `28835967900`, green at `54d08a3`; GitHub release remains `v0.3.5`; npm `@companion-ai/feynman` remains `0.3.5`; local package remains `0.3.6`; Pi latest remains `0.80.7`; alpha-hub remains `0.1.3`; `pi-btw` remains `0.4.1`. - Decisions: No functional repo edits were made. PR `#197` is reject/defer for this sweep: it hard-codes a new Atlas Cloud setup lane and model IDs even though the existing custom OpenAI-compatible provider flow already covers this class of provider, it is not tied to a current Feynman research-loop defect, and its only status check is a Vercel authorization failure. PR `#192` remains the merge/defer path for the local `0.3.6` fix set covering `#182`, `#193`, `#190`, `#188`, `#187`, `#186`, and `#185`. PR `#189` remains already ported into `#192` as cherry-pick `79aa7b2`. PR `#191` remains reject/defer because it adds a broader `feynman extensions` inventory command while `#187` only requires accurate update/help guidance. Issue `#196` remains defer/reject to Pi's TUI slash-command layer; `#184` remains outside the AI-researcher product bar. - Contributor refs: `origin/fix/deepresearch-local-model-warning` remains `74` behind / `1` ahead; `pr4fork/main` remains `73` behind / `0` ahead. Visible fork refs remain stale or broad provider/platform/docs/admin/search work rather than a current safe research-loop port target. - Freshness: Root and website `npm outdated --json` show non-security drift only, including Pi `0.80.7`, OpenTelemetry, Ketcher, Vite, TypeBox, Astro, Tailwind, shadcn, and related minor/package updates. No dependency edit was made because no queue-specific root-cause failure required it and the branch is already a validated release candidate. - Verified: Focused runtime test passed (`15/15`); `npm run typecheck`; `npm run build` with existing Vite/RDKit/3Dmol/direct-eval/chunk warnings; `npm run architecture:check` with existing split-debt warnings; `npm test` passed (`594/594`); website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages); root and website `npm audit --omit=dev` (`0 vulnerabilities`); `git diff --check`; `npm pack --dry-run --json` (`entryCount: 402`, shasum `f0b50e989c04095e9a4b3b65628bcf6def9921aa`, size about `71.9 MB`); installed-tarball smoke passed for package/CLI `0.3.6`, CLI help, alpha help, packages list including `npm:pi-btw` and `npm:pi-web-access`, unknown `--extensions` help hint, bundled `alt+enter`, runtime archive entries for Pi, `pi-btw`, and `pi-web-access`, alphaXiv OAuth2 patch, and project-local fetch cache patch. - Next: Merge/publish PR `#192` only when authorized; do not port `#197` unless Feynman intentionally expands curated provider setup and verifies Atlas Cloud from trusted docs plus current runtime behavior. ### 2026-07-17 05:35 PDT — intake-sweep-pr197-still-deferred - Objective: Re-run `check-new-issues` from `/Users/advaitpaliwal/Companion/Code/feynman`, preserve pre-existing dirty files, refresh live GitHub/release/package/workflow state, classify open issues and PRs, and validate the local `0.3.6` candidate without GitHub writes. - Checked: Current branch remains `codex/fix-feynman-user-issues` tracking `origin/codex/fix-feynman-user-issues`; pre-existing dirty files remained `CHANGELOG.md`, `src/cli.ts`, and `tests/pi-runtime.test.ts`. Open issues remain `#196`, `#193`, `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`. Open PRs remain `#197`, `#192`, `#191`, and `#189`. Latest `main` `Publish and Release` run remains `28835967900`, green at `54d08a3` on 2026-07-07. GitHub release remains `v0.3.5`; npm latest remains `0.3.5`; local package remains `0.3.6`; bundled Pi remains `0.80.6`; alpha-hub remains `0.1.3`. - Decisions: No new functional edits were made. PR `#197` remains reject/defer because it hard-codes Atlas Cloud as a curated provider and model list while the existing custom OpenAI-compatible provider path covers that class and no current Feynman-owned research-loop defect requires the vendor lane; its Vercel check still fails on authorization. PR `#192` remains the merge/defer path for the coherent `0.3.6` fix set covering `#182`, `#193`, `#190`, `#188`, `#187`, `#186`, and `#185`. PR `#189` remains already ported into `#192` as cherry-pick `79aa7b2`. PR `#191` remains reject/defer because it adds a broader `feynman extensions` inventory command while `#187` only needs accurate update/help guidance. Issue `#196` remains upstream to Pi's TUI slash-command layer; issue `#184` remains outside the AI-researcher product bar. - Contributor refs: `origin/fix/deepresearch-local-model-warning` remains `74` behind / `1` ahead; `pr4fork/main` remains `73` behind / `0` ahead. No contributor branch introduced a fresh safe research-loop port target. - Freshness: Root `npm outdated --json` shows non-security drift including Pi `0.80.10`, OpenTelemetry, Ketcher, Vite, TypeBox, and related package updates; website drift includes Astro, Tailwind, shadcn, and related packages. No dependency edit was made because dependency churn alone is not a queue-specific root-cause fix and the local release candidate remains validated. - Verified: Focused runtime test passed (`15/15`); `npm run typecheck`; `npm run build` with existing Vite/RDKit/3Dmol/direct-eval/chunk warnings; `npm run architecture:check` with existing split-debt warnings; `npm test` passed (`594/594`); root and website `npm audit --omit=dev` found `0 vulnerabilities`; website `npm run lint`, `npm run typecheck` (`0 errors`, `0 warnings`, `0 hints`), and `npm run build` (`34` pages) passed; `git diff --check` passed; `npm pack --dry-run --json` passed with `entryCount: 402`, shasum `f0b50e989c04095e9a4b3b65628bcf6def9921aa`, and size about `71.9 MB`; real installed-tarball smoke passed for installed `0.3.6`, CLI help, alpha help, packages list containing `npm:pi-btw` and `npm:pi-web-access`, `update --extensions` exiting `1` with the help hint, runtime archive entries for `pi-btw` and `pi-web-access`, alphaXiv OAuth2 markers, and project-local fetch cache markers. - Next: Merge/publish PR `#192` only when authorized; leave `#197` out unless curated Atlas Cloud setup becomes an explicit product decision backed by trusted docs and live runtime verification. ### 2026-07-20 22:06 EDT — intake-sweep-security-freshness - Objective: Re-run `check-new-issues`, preserve existing dirty work, refresh live issue/PR/workflow/release/package state, classify the queue, and repair repo-local validation failures where safe. - Checked: Open issues remain `#198`, `#196`, `#193`, `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`; open PRs remain `#197`, `#192`, `#191`, and `#189`. Latest `main` `Publish and Release` run remains green at `54d08a3`; GitHub release and npm latest remain `v0.3.5` / `0.3.5`; local package remains `0.3.6`; bundled Pi remains `0.80.6`; npm Pi latest remains `0.80.10`. - Decisions: PR `#192` remains merge/defer pending explicit authorization; PR `#189` remains already ported into `#192`; PR `#191` remains reject/defer as broader extension inventory surface; PR `#197` remains reject/defer as generic provider catalog expansion. Issue `#198` remains outside the AI-researcher product bar; `#196` remains upstream Pi TUI slash-command scope; `#193/#182/#190/#188/#187/#186/#185` remain covered by `#192`; `#184` remains support/content scope. - Fixed: Root `body-parser` and hoisted `protobufjs` audit resolutions were refreshed; website dependencies moved to Astro `7.1.3`, `@astrojs/react` `6.0.1`, Vite `8.1.5`, and `body-parser` `2.3.0`; the stricter Astro 7 compiler exposed and fixed one missing nav `</div>` in `website/src/layouts/main.astro`. - Blocked: Root `npm audit --omit=dev` still reports Pi-shrinkwrapped `@earendil-works/pi-coding-agent/node_modules/brace-expansion@5.0.6` and `protobufjs@7.6.4`. Latest Pi `0.80.10` still ships the same nested versions, and npm overrides do not penetrate Pi's package shrinkwrap, so no safe Feynman-local fix remains without an upstream Pi package update or replacing the Pi artifact. - Verified: Focused runtime test passed (`15/15`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/chunk warnings; `npm run architecture:check`; `npm test` passed (`594/594`); website lint/typecheck/build passed (`34` pages); website audit found `0 vulnerabilities`; `git diff --check` passed; `npm pack --dry-run --json` passed with `entryCount: 402`, shasum `9fffb39c1002616276e0c7f860bae5533ac91c2d`, size `71025824`; installed-tarball smoke passed for `0.3.6`, help, alpha help, `update --extensions` help hint, `pi-btw`, `pi-web-access`, alpha resolver, `alt+enter`, and runtime archive. - Next: Keep the dependency/security patch local for review; merge/publish `#192` only when authorized; track the remaining root audit blocker to a Pi package release that updates its shrinkwrapped nested dependencies. ### 2026-07-21 19:32 EDT — intake-sweep-website-audit-refresh - Objective: Re-run `check-new-issues`, preserve the existing dirty release-candidate worktree, refresh live GitHub/release/package/workflow state, classify open issues/PRs, and repair any safe repo-local validation failures without GitHub writes. - Checked: Open issues remain `#198`, `#196`, `#193`, `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`; open PRs remain `#197`, `#192`, `#191`, and `#189`. Latest `main` `Publish and Release` run remains green at `54d08a3`; GitHub release and npm latest remain `v0.3.5` / `0.3.5`; local package remains `0.3.6`; bundled Pi remains `0.80.6`; npm Pi latest remains `0.81.1`. - Decisions: PR `#192` remains merge/defer pending explicit authorization; PR `#189` remains already ported into `#192`; PR `#191` remains reject/defer as broader extension inventory surface; PR `#197` remains reject/defer as generic provider catalog expansion. Issue `#198` remains outside the AI-researcher product bar; `#196` remains upstream Pi TUI slash-command scope; `#193/#182/#190/#188/#187/#186/#185` remain covered by `#192`; `#184` remains support/content scope. - Fixed: Website audit newly reported `sharp <0.35.0` and `svgo 4.0.0 - 4.0.1`; added website overrides for `sharp@0.35.3` and `svgo@4.0.2` and refreshed `website/package-lock.json`. - Blocked: Root `npm audit --omit=dev` still reports Pi-shrinkwrapped `@earendil-works/pi-coding-agent/node_modules/brace-expansion@5.0.6` and `protobufjs@7.6.4`. Latest Pi `0.81.1` ships `brace-expansion@5.0.7` but still shrinkwraps `protobufjs@7.6.4`, so a Pi bump would be a runtime upgrade and would not fully clear the audit blocker. - Verified: Focused runtime test passed (`15/15`); `npm run typecheck`; `npm run build` with existing RDKit/3Dmol/chunk warnings; `npm run architecture:check`; `npm test` passed (`594/594`); website lint/typecheck/build passed (`34` pages); website audit found `0 vulnerabilities`; root audit remains blocked only by Pi shrinkwrap; `git diff --check` passed; `npm pack --dry-run --json` passed with `entryCount: 402`, shasum `c698bb6c66c37756ba677c0a45af49c532f6a6d9`, size `71041144`; installed-tarball smoke passed for `0.3.6`, help, alpha help, `update --extensions` help hint, `pi-btw`, `pi-web-access`, alpha resolver, `alt+enter`, and runtime archive entries. - Next: Keep the website audit patch local for review; merge/publish `#192` only when authorized; track the remaining root audit blocker to an upstream Pi release that also updates nested `protobufjs`. ### 2026-07-23 04:22 EDT — intake-sweep-model-spec-package-runtime - Objective: Re-run `check-new-issues`, preserve the existing release-candidate worktree, classify the live issue/PR/branch/release queue, and port only safe research-loop reliability fixes. - Checked: Open issues are `#199`, `#198`, `#196`, `#193`, `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`; open PRs are `#197`, `#192`, `#191`, and `#189`. GitHub/npm latest remain `v0.3.5` / `0.3.5`, the local candidate remains `0.3.6`, and bundled Pi remains `0.80.6` versus latest `0.81.1`. - Decisions: PR `#192` remains defer pending complete release proof and explicit merge authorization; `#197` is rejected as redundant hard-coded provider catalog work; `#191` is rejected as generic extension inventory; `#189` was already ported in `79aa7b2`. Issue `#199` remains unresolved: the scaffold exists, but a real Ollama run changed the requested relative artifact path to `/outputs/...`, failed both write tools, and falsely replied `DONE`. Issues `#193/#190/#188/#187/#186/#182` remain covered by `#192`; `#185` is implemented but unpublished; `#196` remains Pi TUI ownership; `#198/#184` remain outside the reusable AI-researcher product bar. - Fixed: Model overrides now resolve slash and colon candidates against Pi's registry and forward the canonical `provider/model-id` form, preserving model IDs such as `qwen3:0.6b`. The package manifest now includes four TypeScript source modules imported by source-loaded packaged extensions, preventing installed-package extension load failures. - Verified: Focused model/runtime tests passed (`53/53`); final full `npm test` passed (`597/597`); typecheck, build, architecture check, and `git diff --check` passed with existing warnings. Final pack dry-run and real pack contain `406` entries; the tarball is `71,011,267` bytes with SHA-256 `b45e3d94cc55cd6104ae9c3b96ad4f17a5f5bb164c69feb62b995476a8aa4038`. A clean installed-tarball smoke passed version/help, confirmed all four source modules, loaded the Pi extensions, canonicalized `ollama:qwen3:0.6b`, reached Ollama as `provider=ollama` and `model=qwen3:0.6b`, and failed only with the expected missing-model `404`. - Blocked: Root release audit still has Pi-shrinkwrapped `brace-expansion@5.0.6` and `protobufjs@7.6.4`; a fresh consumer install also resolves vulnerable `@hono/node-server@1.19.14` through MCP SDK `1.29.0`. Package-level overrides do not propagate, and Pi `0.81.1` does not clear all findings. - Persistence: Local-only at `1ab61217`; no commit, push, merge, close, comment, release, or other GitHub write was made. Next: fix and verify `#199` with a tool-capable model, resolve or explicitly accept the release-audit blockers, then review `#192` before any merge or publish. ### 2026-07-24 00:10 EDT — intake-sweep-issue199-validation - Objective: Refresh the live intake queue and release state, challenge issue `#199` with clean local-model probes, and revalidate the unchanged `0.3.6` candidate without disturbing inherited worktree changes. - Checked: The open issue and PR sets are unchanged. PR decisions remain `#192` defer, `#197` reject, `#191` reject, and `#189` port complete in `79aa7b2`; no contributor branch contains a fresh research-loop port target. The latest `main` workflow run `28835967900` only passed `version-check`, while verify, native, npm publish, and GitHub release jobs were skipped; the last real publication remains run `28343027426` for `v0.3.5`. - Issue `#199`: Workspace scaffolding and Pi's relative-path write behavior are present, but fresh isolated Ollama runs with `qwen3:4b` and `qwen3:0.6b` either remained in repetitive reasoning or timed out without tool execution or an artifact. Keep the issue open; local-model artifact reliability is not verified. - Fixed: The local-model probes exposed a Feynman-owned `pi-otel` startup failure because the runtime can resolve either OpenTelemetry Resources 1.x or 2.x while the patch assumed one API. The patch now chooses `resourceFromAttributes` when available and falls back to `Resource`, repairs both previously patched forms, and has focused regression coverage. - Freshness and audits: GitHub/npm latest remain `v0.3.5` / `0.3.5`; local is `0.3.6`; bundled Pi is `0.80.6` versus `0.81.1`. Root audit still reports Pi-shrinkwrapped `brace-expansion@5.0.6` and `protobufjs@7.6.4`; Pi `0.81.1` fixes only the first. A clean consumer install additionally resolves vulnerable `@hono/node-server@1.19.15` through MCP SDK `1.29.0`; package overrides do not propagate to consumers. Website audit is clean. - Verified: Focused model/runtime tests passed (`53/53`), focused `pi-otel`/runtime tests passed (`21/21`), full tests passed (`598/598`), and root typecheck, build, architecture check, website lint/typecheck/build (`34` pages), and `git diff --check` passed with only existing build and split-debt warnings. Direct runtime probes initialized and shut down `pi-otel` against both OpenTelemetry API generations. Pack dry-run and real pack contain `406` entries at `71,044,856` bytes; a clean installed-tarball launch loaded all extensions without error, canonicalized a colon-bearing Ollama model id, reached Ollama with the exact model id, and failed only with the expected missing-model `404`. The real tarball SHA-256 is `9e17ec9a2f05a2b08b6ed34cda254bd2ab83174c95226e598608174f8e7ac474`. - Persistence: The `pi-otel` compatibility patch, its focused test, and this lab-notebook entry are local-only and uncommitted. No push, merge, close, comment, release, or other GitHub write was made. Next: prove issue `#199` with a reliably tool-capable local model and resolve or explicitly accept consumer audit blockers before treating PR `#192` as release-ready. ### 2026-07-24 03:50 EDT — intake-sweep-pi-082-deferred - Objective: Refresh the complete issue, PR, contributor-ref, workflow, release, package, and validation state while preserving the inherited `0.3.6` release-candidate worktree. - Checked: Open issues remain `#199`, `#198`, `#196`, `#193`, `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`; open PRs remain `#197`, `#192`, `#191`, and `#189`. No Feynman queue, branch, workflow, or release item changed after the prior sweep. PR decisions remain `#192` defer, `#189` port complete in `79aa7b2`, and `#191/#197` reject. - Freshness: Pi `0.82.0` is newly published and its packed shrinkwrap updates `brace-expansion` to `5.0.7` and `protobufjs` to `7.6.5`, clearing Pi's two nested audit findings. The upgrade is not a safe pin-only change: Feynman's `AuthStorage`, `ModelRegistry.create(...)`, and `createAgentSession({ authStorage, modelRegistry })` integration must migrate to Pi's async `ModelRuntime` contract and all local runtime patches must be revalidated. - Blocked: The current root audit still reports the two Pi `0.80.6` findings. A clean installed-Feynman consumer reports ten affected package nodes representing the two Pi advisories plus the MCP SDK / `@hono/node-server <2.0.5` path-traversal advisory; package overrides still do not propagate to consumers. Issue `#199` remains only partially covered by workspace scaffolding because reliable local-model tool execution and artifact creation are still unverified. - Verified: Focused model, runtime, and `pi-otel` tests passed (`57/57`); full tests passed (`598/598`); root typecheck, build, architecture check, and `git diff --check` passed with existing warnings; website lint, typecheck, build (`34` pages), and production audit passed; package dry-run and real pack contain `406` entries at `71,044,856` bytes. The clean installed-tarball smoke passed `0.3.6` version/help, package inventory, required source modules, unknown-flag guidance, and packaged `pi-otel` compatibility markers; SHA-256 is `9e17ec9a2f05a2b08b6ed34cda254bd2ab83174c95226e598608174f8e7ac474`. - Persistence: No product code, dependency, commit, branch, PR, release, or GitHub state changed in this sweep; only this lab-notebook entry was added. Next: migrate and validate Pi `0.82.0` as a dedicated runtime change, then reconcile the remaining local `0.3.6` work into PR `#192` before any merge or release decision. ### 2026-07-25 20:04 EDT — intake-sweep-runtime-freshness-audit - Objective: Refresh the issue, PR, contributor-ref, workflow, release, package, and validation state for the local `0.3.6` candidate while preserving the inherited dirty release worktree and keeping GitHub read-only. - Queue: Open issues are `#198`, `#196`, `#193`, `#190`, `#188`, `#187`, `#186`, `#185`, `#184`, and `#182`; `#199` is closed after the reporter attributed the missing artifacts to an Ollama context window of `4096` and reported success at `65536`. Open PR decisions remain `#192` defer, `#189` port complete in `79aa7b2`, and `#191/#197` reject. No issue or PR changed after the automation cutoff, and contributor branches/forks exposed no new safe research-loop port target. - Fixed: Website production audit newly reported three high findings. Added website-only overrides for `brace-expansion@5.0.8` and `postcss@8.5.23`, refreshed `website/package-lock.json`, and returned the website production audit to zero findings without touching inherited product changes. - Freshness: A clean runtime rebuild picked up `pi-web-access@0.14.0` and `pi-subagents@0.37.0`; the shipped archive still uses Pi `0.80.6`, `pi-btw@0.4.1`, `pi-docparser@3.0.1`, `pi-otel@0.1.0`, and `typebox@1.1.38`. Pi `0.82.1` remains a coordinated `ModelRuntime` migration rather than a safe pin-only update because Feynman still uses the removed `AuthStorage`, synchronous `ModelRegistry.create(...)`, and legacy `createAgentSession` service inputs. - Release truth: GitHub/npm latest remain `v0.3.5` / `0.3.5`; local is `0.3.6`. Main run `28835967900` is green only for `version-check`, with verify, native bundle, npm publish, and GitHub release jobs skipped; the last actual publication remains run `28343027426`. - Verified: Fresh `pi-web-access@0.14.0` passed `201/201` upstream tests, typecheck, and production audit; focused Feynman runtime/model/package tests passed `97/97`; full `npm test` passed `598/598`; root typecheck, build, architecture check, website lint/typecheck/build, website production audit, and `git diff --check` passed. Root production audit remains blocked by Pi-shrinkwrapped `brace-expansion@5.0.6` (high) and `protobufjs@7.6.4` (moderate). A fresh installed-tarball consumer audit reports `10` affected nodes: the same Pi advisories plus the MCP SDK / `@hono/node-server <2.0.5` path, with no compatible consumer fix for that chain. Package dry-run and real pack contain `406` entries at `72,176,110` bytes; the real tarball SHA-256 is `4786f4eb92339c1395e5f1e1ed7082d670f1c8a8892cac7d47a3e9c8d71138bd`. - Installed-tarball proof: A clean install returned `0.3.6`, rendered help and package inventory, extracted Pi `0.80.6`, `pi-web-access@0.14.0`, and `pi-subagents@0.37.0`, loaded Feynman's research tools plus `pi-web-access` and `pi-otel` with zero extension errors, registered `source_check`, preserved `ollama:qwen3:0.6b` canonicalization, and initialized/shut down the patched `pi-otel` SDK. - Persistence: Only the website audit override/lock refresh and this lab entry were added by this sweep; all other dirty files were inherited and preserved. No commit, push, merge, close, comment, release, or other GitHub write was made. Next: reconcile the local fixes into PR `#192`, migrate Pi deliberately, and resolve or explicitly accept the Pi shrinkwrap plus consumer MCP/Hono release-audit blockers before publish. ### 2026-07-28 02:33 PDT — 0.3.6-windows-node25-archive-verifier - Objective: Finish PR `#192` at exact release-candidate SHA `8415be8eef305ecb0d564b025ec88bac47302329`, including clean Daytona proof, all supported-node consumers, merge, and `0.3.6` publication. - Verified: A fresh Linux Daytona sandbox passed all `649` tests at `8415be8`, typecheck, build, architecture check, website lint/typecheck/build, all production audits, dry and real pack, clean installed-consumer/runtime audits, artifact verification, and installed RPC extension loading. Its 112,175,141-byte tarball matched the GitHub PR artifact byte-for-byte at SHA-256 `34ae1c9d053d724c6eadc9781beb2f865a2c372fe0255dd1fbe93a360a167f4c`. - Failed: GitHub run `30344883546` exposed one exact Windows/Node `25.9.0` portability defect after otherwise successful install, version/help, package/search, and audits: `readArchiveEntry` delegated to the host `tar`, which failed to read `npm/package-lock.json` from the valid runtime archive. - Fixed: Runtime archive entry reads now use Feynman's in-process gzip/tar parser instead of an external executable, with a regression that removes `PATH` before reading the deterministic archive. - Verified: The repaired tree passed the focused regression (`8/8`), full `npm test` (`650/650`), typecheck, build, architecture check, root and website production audits, website lint/typecheck/build, package freshness review, and `git diff --check`. Dry and real pack were byte-identical at 111,577,262 bytes / 39,105 entries with SHA-256 `fc1d5913f2e3435e3377af883771aac2e8013f63259185dd7e54edb49002e4f9`; clean source/runtime/consumer audits, installed artifact verification, and installed Pi RPC loading (`112` commands, including `web-results`) passed. - Verified: Exact `1433b387913b84e4f2281f3fc5dba2bfe6ef5cb4` passed the same full ladder in a fresh Daytona sandbox on Node `24.18.0`; its 112,175,500-byte tarball matched the GitHub PR artifact at SHA-256 `f1973a38b017cec3df023260bd7d14be9d1e438624cafd2c9ed0025b86cf8ee0`. Installed verification also passed on Node `25.9.0` with `PATH` empty. GitHub run `30347794537` passed every Linux/macOS/Windows Node consumer, including the original Windows artifact failure, but its native installer job exhausted the 60-minute budget during the second exact Windows PowerShell 5.1 extraction; `Expand-Archive` spent over 25 minutes on the 52,956-file candidate. - Fixed: The public Windows installer now uses the supported .NET `System.IO.Compression.ZipFile.ExtractToDirectory` API instead of the pathologically slow `Expand-Archive` cmdlet, preserving the exact staging and transactional replacement boundary while making repeated Windows PowerShell 5.1/Core verification practical. - Measured: Exact successor `b098c3809b9b148a4bea2829c16faa07bf464015` passed all six supported-node consumers, but the Windows PowerShell 5.1 verifier still spent over 30 minutes repeating the 530 MiB download for independent checksum and rollback cases. The verifier now uses the exact native candidate for clean-install and replacement proof in each PowerShell host, then runs the same checksum and rollback paths against a compact valid bundle. - State: `verified` through the exact package/consumer matrix and Daytona ladder; exact successor-SHA Windows PowerShell 5.1/Core installer completion remains required before merge. Next: require the bounded Windows verifier and all CI jobs green, then merge and verify the GitHub/npm release. ### 2026-08-11 05:07 EDT — 0.3.18-researcher-child-tools - Objective: Repair the published `0.3.17` researcher-child launch failure from post-release run `31474740525`, then validate and release the smallest root-cause fix. - Checked: `main`, npm, and GitHub release `v0.3.17` agree at `03754b0`; no issues or pull requests are open. The macOS job failed because the researcher strictly allowlisted `hf_dataset_info`, `hf_repo_files`, and `hf_repo_read_file` without loading their provider extension. - Fixed: Default settings now add Feynman's absolute `extensions/research-tools.ts` path through `subagents.agentOverrides.researcher.subagentOnlyExtensions`. Existing explicit researcher overrides remain unchanged. The published smoke now rejects unavailable-child-tool diagnostics. - Verified: Focused settings tests passed (`67/67`); the full suite passed (`769/769`); typecheck, build, architecture check, website lint/typecheck/build (`34` pages), root and website production audits (`0 vulnerabilities`), package freshness review, and `git diff --check` passed. - Package proof: Dry and real packs matched at `121,036,187` bytes and `40,224` files. The real tarball SHA-256 is `a9eb0dea17141d1763bddd562ec69486751bd07738d625760772655bd85d13fd`; source/runtime/consumer audits and package, RPC, TypeBox, and document-parser verifiers passed. - Live proof: Local source and clean installed-tarball macOS runs returned `RESULT=PONG`; both configured an existing absolute researcher extension path and emitted no unavailable-child-tool diagnostic. - State: `unverified` for exact-head Daytona, pull-request CI, merge, and publication. Next: complete those gates and publish `0.3.18`. ### 2026-08-13 05:55 CDT — liteparse-2.12.0-0.3.21 - Objective: Adopt LiteParse `2.12.0` for the bundled document research runtime and qualify Feynman `0.3.21`. - Intake: Open issues, open PRs, active workflows, security advisories, and contributor port targets are empty. LiteParse `node-v2.12.0` resolves to upstream `2fd644a`; npm integrity and direct parse, page-count, screenshot, and batch probes passed. - Candidate: Updated the seven platform packages, runtime override and lock, artifact verifier, release notes, website release page, and focused tests. The candidate remains uncommitted and unpushed. - State: `unverified` for cumulative package checks, clean-machine proof, CI, merge, publication, and release identity. Next: run the full validation ladder, then persist the exact tested candidate. ### 2026-08-13 08:45 CDT — intake-sweep-0.3.21-final - Objective: Reconcile the post-release Feynman AI-researcher intake after LiteParse `2.12.0` publication. - Queue: Open issues, open PRs, active workflows, contributor branches, Dependabot alerts, repository advisories, and code-scanning alerts are empty. TheTechOddBug/feynman is one commit behind and zero ahead of `main`; no port target exists. - Release: PR `#228` merged as `186c226`; publish run `31693465638`, post-release run `31698860122`, and successor identity run `31699981995` passed. npm and GitHub release `0.3.21` agree; tag `v0.3.21` targets `186c226`, native asset digests match `SHA256SUMS`, and Vercel is green on `db02b11`. - Repaired: The local generated root and vendored runtime trees were stale at LiteParse `2.11.1` after release. Rebuilt only owned generated state; both trees now resolve `2.12.0`. The first rebuild and pack attempts hit host `ENOSPC`, not a product defect. Removed owned generated trees and test temporaries after each failed attempt. - Verified: Focused and full tests passed (`783/783`); root typecheck, build, architecture check, root/website/runtime audits, website lint/typecheck/build (`34` pages), diff checks, and installed docparser parse/search/screenshot passed. Clean Daytona attempts were made for exact-head proof; one failed because the sandbox command used an unwritable path, and the second timed out at 300 seconds during the cumulative ladder. Both sandboxes were deleted. The local runtime archive rebuilt successfully with LiteParse `2.12.0` and passed tar listing. - State: `verified` for published release identity and local validation; exact clean-machine cumulative proof for this no-code revalidation is not newly complete because the available Daytona execution timed out. Main is clean and synchronized at `db02b11`; the unrelated nested website repository remains preserved. Next: rerun only the clean-machine ladder when disk and Daytona execution capacity allow. ---