Skip to content

feat: caregiver questions — audience-aware contracts, fail-closed policy, fixtures, UI prototype - #18

Open
obvious-autobuild[bot] wants to merge 1 commit into
masterfrom
feat/caregiver-questions
Open

obvious-autobuild[bot] wants to merge 1 commit into
masterfrom
feat/caregiver-questions

Conversation

@obvious-autobuild

Copy link
Copy Markdown
Contributor

Acceptance criteria

  1. Questions attach to existing journal content — every question points at an entries row (and one of its structured events for event targets). No standalone conversation table.
  2. Audience vs addressing stay two dimensions — who a question is DIRECTED at is stored on the question (audienceKind + addresseeIds); who MAY see it is resolved from household membership + target publication state, never fused.
  3. Fail-closed policy, executable — every deny has a code (DENY_Q_*); anonymous, no-household-path, draft-author-only, non-addressee, attribution-mismatch, invalid-target, invalid-audience, addressee-not-in-household, and lifecycle violations are pinned by tests driven from the fixture corpus.
  4. Append-only lifecycle — questions are never updated after creation; answer/resolve/reopen/handoff-marked activities append, and derived state is computed (deriveQuestionState). Reopening clears the resolution but preserves lineage (reopenedCount).
  5. Missing-vs-zero discipline — the handoff digest renders "no questions asked" (hasQuestions: false) as a different fact from "questions exist, none for handoff", and preserves explicit negative answers ("None today.") verbatim.
  6. Contracts derive, not duplicate — Convex validators for the two new tables and the operation contracts derive from the Effect schemas via the existing tested adapter; JSON Schema derivation still applies.
  7. Mobile prototype proves the UX — viewer switcher, question cards with status/reopen lineage, answer/resolve/reopen actions gated by the domain policy, handoff digest card; logic tested without a device.
  8. No live Convex writes — schema extension only; dev deployment untouched.

Verification (exact HEAD c3404b2)

  • pnpm typecheck — 7/7 packages green
  • pnpm test — 54 domain + 10 mobile logic tests pass
  • pnpm build — 3/3
  • bun test ./security — 17/17 (touched domain contracts → re-run per repo contract)
  • evaluation corpus — 6/6 fixtures; negative control (--expect-failure) fails as designed

…icy, fixtures, UI prototype

Implements the Journal & Caregiver Coordination lane's caregiver-question
contract on Effect v4 schemas:

- packages/domain: careQuestions + careQuestionActivities schemas (entry/event
  targets, directed vs household audience, append-only lifecycle), pure
  deriveQuestionState, fail-closed policy (view/ask/answer/resolve/reopen with
  deny codes), handoff digest distinguishing no-questions from unresolved,
  operation contracts, index exports, 54 fixture-driven tests
- evaluation/fixtures/agent-experience/caregiver-questions/: two-household
  synthetic corpus (lifecycle, draft visibility, directed isolation, explicit
  negatives, handoff exclusion, cross-household denial)
- apps/mobile: pure viewer logic + prototype screen (viewer switcher, answer/
  resolve/reopen gated by the domain policy, handoff digest card) + App toggle
- backend/convex: careQuestions/careQuestionActivities tables via the adapter

Verified at this commit: pnpm typecheck (7/7), pnpm test (54+10 pass),
pnpm build (3/3), bun test ./security (17/17), evaluation corpus 6/6 with
negative control failing as designed.
@obvious-autobuild
obvious-autobuild Bot force-pushed the feat/caregiver-questions branch from c3404b2 to af02da5 Compare September 17, 2026 18:55
@obvious-autobuild

Copy link
Copy Markdown
Contributor Author

Rule-5 rebase receipt (conflict repair)

Prior evidence at c3404b2 is INVALIDATED by this push — re-review follows the delta below, per repo rule 5.

New head: af02da5 = c3404b2 replayed onto origin/master 69e7bd3 (master moved twice during the repair window: first fetch had tip 3caaa08 — v0.3 fold 00581f5, handoff 652ace5, knowledge 0c65862, fixture registration e74c7be, retrieval 44856c6, thin-path port 13, then PR #19's corrections corpus landed as 69e7bd3 mid-repair).

Rebase delta (only what the replay had to adapt):

  1. packages/domain/src/contracts.ts — import block union: fold's HouseholdFields/CaptureId imports alongside my careQuestion imports. No semantic change.
  2. packages/domain/src/index.ts — type-export barrel union: knowledge type exports alongside my careQuestion/policy type exports. No semantic change.
  3. backend/convex/convex/schema.ts — three additive hunks: merged import line (KnowledgeFields + CareQuestion fields), merged doc paragraph, both table sets coexist (knowledge + careQuestions + careQuestionActivities). No semantic change.
  4. evaluation/fixtures/agent-experience/caregiver-questions/manifest.json → AREA.md — the area descriptor renamed out of the harness's *.json namespace. Reason: PR feat(evaluation): namespace-aware, manifest-driven fixture-area registration #22's loader excludes only the ROOT manifest path from area file lists (manifest.ts line 236), so a nested manifest.json would silently load as an area file; the area also remains deliberately unregistered in the root manifest (no registered sub-namespace precedent; the descriptor documents the future-registration recipe). Content preserved verbatim inside the markdown fence.
  5. pnpm-lock.yaml auto-merged; pnpm install re-run — one consumer surfaced: packages/handoff (from PR feat(handoff): since-last-seen digest + grounded follow-up prototypes #17) needed its workspace links in this worktree; no source change.

Scope: diff vs master = 16 files, all caregiver-question scope; no Event.authorId work, authorship modeled on the question schema (askedById), EventSchema untouched.

Uncached gates at af02da5: pnpm turbo run typecheck test build --force 16/16 (0 cached — domain 54 tests incl. fixtures, mobile 10, handoff + retrieval suites green), bun test ./security 17/17, evaluation corpus 6/6, negative control fails as designed (1/6).

CI: run 35261753409 — success on exactly af02da5bc494bf74616d7d0a22fcfa1b2c6b889a; PR state MERGEABLE/CLEAN.

Delta re-review is being routed to an independent lane reviewer; merge remains with the serialized merge-sweep owner.

@obvious-autobuild

Copy link
Copy Markdown
Contributor Author

Correction to the rebase receipt above (5719651231), from the independent delta re-review (verdict PASS-WITH-NOTES, findings artifact art_w8eikm2M): the domain suite at af02da5 is 104 tests across 5 files, 439 assertions (54 was the pre-fold count), mobile 10, handoff 21, retrieval 22 — all green, 0 cached. The negative control is also clarified: run.ts inverts the exit code under --expect-failure (exit 0 iff failures are found), so that step passes as designed. No other receipt fields change; CI run 35261753409 on exactly af02da5 remains the merge-gate evidence. PR is MERGEABLE/CLEAN against master 90b76d9 (PR #26 has zero file overlap with this PR's 16 files), so no further rebase — and no further rule-5 evidence invalidation — is required before merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants