* feat(a2a): deliver latest incoming message preview into the claim briefing
list_unread_a2a now carries last_message_preview (the latest message from the
OTHER agent, never the agent's own reply), fetched via a correlated subquery in
the same query — no N+1 on the per-verb briefing path.
* feat(a2a): read_a2a verb delivers unread message bodies to the agent
A2AService.get_unread_messages returns the caller's unread INCOMING messages
(never its own sends), marking exactly those rows read atomically so a message
arriving mid-call is preserved. Wired as the read_a2a content verb (route +
do_server tool + granted to every delivery role) — the content-bearing read the
A2A inbox lacked (read_messages only zeroed the counter).
* docs(rag): document read_a2a as the A2A content-read path
* fix(task): backlog activation no longer requires a discussion session
Removes the SessionTaskTable gate in activate() (and its dangling log field),
deletes _inherit_parent_session + its create() call, and drops the now-unused
SessionTaskTable import. Coordination rides task state; the session subsystem is
being retired. Tests updated to the new (no-session) behavior.
* fix(orchestrator): drop session sweep from _run_sweep
Removes the messaging import + sweep_timed_out_sessions call. That import sat
outside the try/except, so once messaging.py is deleted it would have killed the
entire sweep cascade (budget kill-switch, token rollups, retention, image prune,
superseded-PR reconcile). Notification sweep + all maintenance sweeps unchanged.
* release-manager --no-tags read-clone fix
* test: update evidence_repo unit test for a2a last_message_preview
* refactor(gateway): drop session propagation on delegate
Removes propagate_sessions_to_subtask from delegate(), the ChoreographerDeps
messaging field + property, and the ChoreographerDeps messaging arg in deps.py
(ContentActions messaging + import stay until the verbs are removed). Deletes the
propagation test; strips the now-invalid messaging kwarg from ChoreographerDeps
test builders.
* refactor(gateway): remove say/open_session/link_session/channels verbs
Removes the four channel/session verbs across content_actions (impls +
ContentActionsDeps.messaging), do_server (tools + registry), role_config (grants
+ _CHANNEL_DISCOVERY), do.py (routes), schemas/v1/do.py (request models), and
deps.py (MessagingService import + construction). Regenerates the prompt verb
tables. dm/notify/read_messages/read_a2a stay. Tests deleted/updated accordingly.
* uv.lock Upgrade
* refactor: remove conversation RAG indexing; Secretary announces via notification
Drops the CONVERSATIONS index (index_conversation, ConversationsIndexPlugin,
IndexType.CONVERSATIONS enum, IndexConversationParams, mentor.py type-label, the
messaging index hook) and its chunk-table manifest entries. The Secretary's
ANNOUNCE/RELAY_MESSAGE now fan out a BROADCAST notification to every agent's
inbox (NotificationService.broadcast) instead of posting to a dead channel.
* fix(panel): label RAG health error lines by subsystem
A red llm_error (e.g. the glm-5.2:cloud weekly-limit 429) rendered under
the 'Embedding: ok' header with no label, reading as an embedding failure.
Prefix each error line with LLM / Embedding / Vector store.
* refactor: remove channel/message reads from metrics, dashboard, git, events
MetricsService drops get_communication_volume + the MessageTable
message-count in get_agent_metrics (and the now-dead messages_sent_week
field). DashboardService drops get_channel_feeds/_compute_channel_status
and the message read in get_recent_activity (task activity kept);
get_auditor_metrics no longer reports communication_volume.
GitService's two primary-session-id helpers always return None now
(callers already treat None as "no primary session"). events/handlers.py
drops the SESSION_CLOSED/SESSION_TIMEOUT subscriptions + the
handle_session_boundary handler.
Forced follow-on: api/routes/dashboard.py + api/schemas/dashboard.py
dropped the now-dangling live_feeds/ChannelFeed surface and the
/metrics/communication route, which wrapped the removed service calls
directly (mypy would otherwise fail on the missing attributes).
* refactor: delete MessagingService + channel seeding
Edited db/__init__.py and services/__init__.py first (drop the unconditional
Channel/Group/Message/Session table + MessagingService re-exports), then
deleted services/messaging.py, then trimmed db/seed.py to only create_agents
(create_channels/create_channel_memberships/create_initial_messages gone).
Forced expansion: api/routes/{channels,groups,sessions,messages}.py import
roboco.services.messaging directly (not through the package __init__), as
does api/routes/tasks.py (the session-links embed on GET /tasks/{id} and the
GET /{id}/sessions route). Deleting messaging.py without addressing these
breaks `import roboco.api.app` immediately, since app.py eagerly imports all
route modules at startup. Since the 4 CRUD route files are 100%
MessagingService-backed with zero independent logic (and are wholesale
deletes in the plan's later API-routes task anyway), deleted them now +
unmounted from app.py/routes/__init__.py; tasks.py got the same surgical
trim its later task already specified (drop session-links embed +
TaskSessionLinkResponse/TaskResponse.sessions). This pulls a slice of that
later work forward — the routes/schemas for channels/groups/sessions/messages
still need their own pass, but their messaging-coupled parts are gone.
Verified with a full-suite collection sweep (12010 tests collected, zero
import errors) beyond the directly touched test dirs, given the expanded
blast radius.
* refactor: remove channel/session/message models, tables, and channel policy
Models: deleted channel.py/group.py/session.py/messaging.py wholesale
(zero external consumers besides the models/__init__.py re-export).
message.py surgically trimmed: removed MessageCreate (dead) and MessageEdit
(never instantiated; ExtractedMessage.edit_history retyped to
list[dict[str, Any]] to match how it's actually persisted — confirmed
ExtractedMessage was never written to any DB table, so MessageTable's
removal carries no functional risk to the kept extraction pipeline).
base.py: removed SessionStatus + ChannelType, kept MessageType. Also
removed the confirmed-dead channels_read/channels_write fields from
models/agent.py:AgentPermissions and models/dashboard.py:ChannelFeedData.
db/tables.py: deleted ChannelTable/GroupTable/SessionTable/SessionTaskTable/
MessageTable, TaskTable.session_links, and JournalEntryTable.session_id —
cascaded through models/journal.py, services/journal.py, and
api/schemas+routes/journals.py (22 plumbing sites).
foundation/policy/communications.py: removed the ChannelSpec/CHANNELS
catalog + TEAM_SCOPED_ROLES/_CELL_*/_AUDITOR_ONLY helpers, kept the
notification policy (Priority/parse_priority/NOTIFY_SENDER_ROLES/
ACK_REQUIRED_BY_TYPE). enforcement/channel_access.py deleted (confirmed
fully dead in production). agents_config.py: removed CHANNEL_ACCESS
(kept A2A_ALLOWED_PAIRS). seeds/initial_data.py: removed
DEFAULT_CHANNELS/CHANNEL_MEMBERSHIPS/AUDITOR_SILENT_ACCESS + the
never-consumed INITIAL_MESSAGES. config.py: removed
session_idle_timeout_seconds (zero consumers). exceptions.py: removed
dead ChannelError/ChannelAccessDeniedError/SessionClosedError.
Forced expansion beyond the original file list — ChannelType cascaded
into a live, mounted surface the plan didn't trace: agents_config.
CHANNEL_ACCESS -> services/permissions.py's channel-RBAC methods (not
models/permissions.py, which turned out to have no channel code at all)
-> two real endpoints in api/routes/stream.py (GET /permissions,
GET /permissions/channel/{name}) and two dependency factories in
api/deps.py. Removed the channel methods + fields, deleted the
channel-specific stream.py endpoint, deleted require_channel_read/write.
Also deleted api/schemas/{channels,sessions}.py (hard dependency on the
removed enums; already fully dead after the Task 10 route deletions) and
api/schemas/messages.py (a TYPE_CHECKING-only import of the deleted
MessageTable; likewise already fully dead) + its dedicated test file.
Test updates: test_permissions.py -14 channel tests (matches the planned
count exactly), test_communications.py / test_communications_consumers.py
split to keep only notification-policy coverage, test_exceptions.py -9,
test_deps.py -4, plus the journal/stream/foundation-smoke fallout. Also
fixed a pre-existing (Task 7) broken assertion in
test_foundation_phase3_smoke.py that inspected a `say()` method already
removed from ContentActions.
Verified: full-suite collection (11961 tests, zero import errors) and a
complete test run (11567 passed, 394 skipped, 0 failed) in addition to
the targeted suites.
* migration: drop channels/groups/sessions/session_tasks/messages + enum types
alembic/versions/060_drop_messaging.py: drop_column journal_entries.
session_id (sidesteps hardcoding the FK constraint name — verified
empirically against a live migrated DB that it's actually
fk_journal_entries_session_id_sessions, but drop_column doesn't care
either way); drop_table in FK order (messages -> session_tasks ->
sessions -> groups -> channels); DROP TABLE IF EXISTS chunks_conversations
(runtime-provisioned, not alembic-managed, would otherwise orphan); DROP
TYPE IF EXISTS for messagetype/sessionstatus/sessionscope/channeltype
(messagetype's Python enum stays for ExtractedMessage, but the DB type
had zero live columns left once MessageTable was dropped in the prior
commit). downgrade() raises NotImplementedError — one-way removal.
Pruned scripts/reset_runtime_state.sql + .sh: removed the DELETE/COUNT
lines for messages/session_tasks/sessions/groups/channels and the
groups.active_session_id reset block.
Verified end-to-end against a scratch Postgres DB: full migration chain
001->060 applies cleanly, alembic heads shows a single head, all 6 dropped
tables + 4 enum types + the journal_entries.session_id column are
confirmed gone, journal_entries keeps only its journal_id/task_id FKs,
downgrade correctly raises NotImplementedError without corrupting DB
state, and the pruned reset_runtime_state.sql runs clean (no errors)
against a fully-migrated DB.
* refactor(api): remove channel/session/message routes + WS streams
Most of this task's file list was already forced through in earlier
commits (routes/{channels,groups,sessions,messages}.py + app.py/__init__.py
unmounting in the MessagingService-deletion commit; tasks.py's
session-links embed + GET /{id}/sessions + schemas/tasks.py's
TaskResponse.sessions in that same commit; deps.py's require_channel_read/
write + schemas/{channels,sessions}.py in the models/tables commit). This
closes out what was left:
- api/websocket.py: deleted the channel_stream + session_stream routes,
ConnectionManager's channel_connections/session_connections dicts,
connect_channel/connect_session, broadcast_to_channel/broadcast_to_session,
get_channel_subscriber_count, and their cleanup lines in disconnect().
Agent streams, notification streams, and the operator system stream are
untouched.
- api/websocket_bridge.py: deleted _handle_session_event +
_handle_message_event and their SESSION_CREATED/SESSION_CLOSED/
SESSION_TIMEOUT/MESSAGE_SENT subscriptions. The A2A live-view, rate-limit,
usage, agent-lifecycle, and notification bridges are untouched.
- api/schemas/websocket.py: removed NewMessageBroadcast, WSMessageNew,
WSMessageEdit, WSMessageDelete, WSSessionClosed — kept the WSMessage base
class (still subclassed by the kept WSAgentStream/WSNotification) plus
those two.
- api/schemas/groups.py: deleted (already fully orphaned since routes/
groups.py was removed; its GroupResponse/GroupDetailResponse had zero
consumers).
Updated the 5 websocket test files accordingly (removed the channel/
session-specific tests + fixed imports); test_websocket_bridge.py's
registration-coverage test dropped the SESSION_*/MESSAGE_SENT assertions.
Verified: full-suite collection (11943 tests, zero import errors) and a
complete test run (11549 passed, 394 skipped, 0 failed).
* docs: retire channels/sessions/messages from agent-facing docs + CLAUDE.md
Rewrites docs/rag (RAG-indexed) + docs/map + CLAUDE.md to reflect A2A (dm +
read_a2a) as primary agent comms; deletes the channel docs, splits messaging-tools
+ messaging-notification (renamed notification.md), swaps the WS worked example to
A2A_MESSAGE_SENT. _complete_map.md still needs regeneration (generated file).
* refactor(panel): remove Communications surface (channels/sessions)
Deletes the /communications routes, message components, task-detail Sessions tab,
use-channels + channel/session WS hooks, and the channels/sessions/messages/groups
api clients; prunes the Channel/Session/Message/Group types + mock data. (Auditor
live-feeds + dashboard.ts dead-route cleanup is a follow-up.)
* refactor(panel): drop auditor channel-feed + dead communication-metric route
* docs(map): regenerate _complete_map from updated slices
* fix(a2a): reduce get_unread_messages complexity below xenon C + stale comments
Extract the per-conversation unread-counter recompute into _reset_unread_counter
(the CI quality gate flagged get_unread_messages as rank C). Also drop the deleted
open_session from a content_actions comment and reword an evidence_repo docstring
that cited the removed messaging._notify_mentions.
---------
Co-authored-by: Renn F <rennf93@users.noreply.github.com>
32 KiB
models slice
Purpose
The Pydantic/dataclass domain surface of RoboCo — the typed contract the API, services, orchestrator, and agent runtimes all speak. These are not the ORM tables (roboco/db/tables.py owns persistence); models here are request/response schemas, domain aggregates, runtime DTOs, and enums that get crossed into SQLAlchemy rows by the service layer. Validation (RobocoBase: extra="forbid", validate_assignment, use_enum_values) lives here, and several files (agents.py, runtime.py, optimal.py, metrics.py, llm.py, audit.py, dashboard.py, transcription.py, extraction.py, permissions.py) are pure dataclasses/StrEnums with no Pydantic model at all — runtime value types the orchestrator and services pass around.
Files
| Path | Role | approx LOC |
|---|---|---|
__init__.py |
Public re-export surface (Agent, Task, Notification, Journal, CommitRef, enums, get_column_config, …) |
149 |
base.py |
All shared StrEnums (TaskStatus, TaskType, AgentStatus, ModelProvider, JournalEntryType, …) + RobocoBase/TimestampMixin + AgentRole/Team aliases to foundation.identity |
275 |
task.py |
Task aggregate + CommitRef/DocRef/ProgressUpdate/Checkpoint/SubTask/TaskPlan + TaskCreate/TaskUpdate/TaskCreateRequest |
502 |
a2a.py |
A2A protocol wire models (AgentCard, A2ATask, A2AMessage, parts) + persistent conversation models (A2AConversation, A2AChatMessage) + state mappers |
592 |
agents.py |
Agent runtime domain types — per-role phase enums (DevTaskPhase, QATaskPhase, CellPMPhase, …), AgentConfig/AgentState, TaskContext/ReviewContext/DocContext, AuditFlag/AuditReport |
405 |
journal.py |
Journal/JournalEntry + 5 factory param dataclasses + create_*_entry factories + JournalStats/GrowthMetrics |
374 |
permissions.py |
PermissionLevel IntEnum, ROLE_LEVELS (built from agents_config), AgentContext, COMMUNICATION_MATRIX, TASK_PERMISSIONS, KB_PERMISSIONS |
284 |
optimal.py |
RAG domain types — IndexType, SearchResult/SearchOutcome/RAGResponse, ErrorPattern/Decision/Standard, MentorResponse, CodeReviewResult |
275 |
metrics.py |
VelocityMetrics/BlockerMetrics/TeamMetrics/AgentMetrics + v0.10.0 observability: StageTiming/StageBottleneck/BottleneckReport/AgentReworkRate/ReworkReport/Scorecard |
249 |
events.py |
EventType StrEnum + Event dataclass (JSON round-trip) + NotificationServiceProtocol/OrchestratorAccessProtocol/EventContext DI container |
199 |
handoff.py |
DocumenterHandoff + CodeSample/DocumentationItem/ConversationRef + HandoffCreate (RESERVED — see file header) |
202 |
project.py |
Project + BranchReason + ProjectCreate/ProjectUpdate (CI-watch, dep-update, quality_command fields) |
178 |
agent.py |
Agent API model + ModelConfig/AgentPermissions/AgentMetrics + AgentCreate/AgentUpdate |
172 |
kanban.py |
KanbanBoard/KanbanColumn/KanbanCard/KanbanSwimlane + per-role column configs + get_column_config |
159 |
llm_catalog.py |
CatalogEntry + MODEL_CATALOG/MODEL_CATALOG_BY_NAME/provider_type_for_model + OLLAMA_ROLE_DEFAULTS/OLLAMA_DEFAULT_MODEL (Settings dropdown source of truth) |
132 |
message.py |
ExtractedMessage + RawStream |
137 |
runtime.py |
Orchestrator runtime types — OrchestratorAgentState, SpawnGitContext, OrchestratorAgentConfig, AgentInstance, WaitingRecord, MODEL_MAP, ROLE_MODEL_MAP |
128 |
transcription.py |
StreamBuffer (flush heuristic) + TranscriptionConfig |
119 |
llm.py |
LLMUsage/ToonConfig/EncodedBlock/ToonMetrics (token + TOON serialization metrics) |
118 |
notification.py |
Notification + NotificationCreate + CreateNotificationParams |
117 |
work_session.py |
WorkSession + WorkSessionStatus + WorkSessionCreate/WorkSessionUpdate |
117 |
pitch.py |
Pitch + PitchStatus + PitchCreate (Board proposal → provisioning) |
73 |
extraction.py |
ExtractionContext/ExtractionResult/ExtractionConfig |
68 |
product.py |
Product + ProductCellMapping (cell→Project map; validator enforces cell-only) + create/update DTOs |
69 |
playbook.py |
Playbook + PlaybookCreate/PlaybookUpdate (curated procedure; from_attributes for ORM load) |
58 |
audit.py |
AuditEventType StrEnum + PermissionDenialContext/StateTransitionDenialContext dataclasses |
58 |
dashboard.py |
FlagData/ReportData/TeamHealthData/AuditQueueItem/CreateFlagParams/DashboardStorage |
96 |
secretary.py |
DirectiveKind/DirectiveStatus StrEnums + GATED_KINDS frozenset |
41 |
README.md |
Architecture doc for the models package | ~250 |
Key Symbols
| Name | Kind | File:Line | Responsibility |
|---|---|---|---|
Task |
Pydantic model | task.py:132 | Atomic unit of work; carries status, branch, PR, batch surface, ACs, gateway lock, structured notes |
TaskStatus |
StrEnum | base.py:31 | 15-state lifecycle (backlog→pending→claimed→…→completed/cancelled) |
TaskType |
StrEnum | base.py:63 | code/documentation/research/planning/design/administrative |
TaskNature |
StrEnum | base.py:74 | technical/non_technical |
CommitRef |
Pydantic model | task.py:31 | Git commit reference (hash/message/timestamp/author) |
DocRef |
Pydantic model | task.py:42 | Document reference with version + author trail |
TaskPlan |
Pydantic model | task.py:109 | Approach + ordered SubTasks + risks/open_questions |
TaskCreate |
Pydantic schema | task.py:350 | Request schema; _exactly_one_target validator (project_id / product_id / cell_projects) |
TaskCreateRequest |
dataclass | task.py:456 | Service-layer create params mirroring TASK_AT_CREATE (no silent defaults) |
Agent |
Pydantic model | agent.py:79 | API agent model (role, team, model config, permissions, metrics, journal_id) |
AgentRole |
alias | base.py:23 | = identity.Role — canonical Role enum lives in foundation/identity |
Team |
alias | base.py:24 | = identity.Team — canonical Team enum lives in foundation/identity |
ModelProvider |
StrEnum | base.py:197 | anthropic/ollama_cloud/openai/local/grok |
ModelConfig |
Pydantic model | agent.py:27 | provider + name + fallback + temperature + max_tokens |
AgentPermissions |
Pydantic model | agent.py:45 | can_notify |
WorkSession |
Pydantic model | work_session.py:25 | Branch/PR/merge tracking for a (project, task, agent) work episode |
WorkSessionStatus |
StrEnum | work_session.py:17 | active/completed/abandoned |
Project |
Pydantic model | project.py:47 | Git repo config + CI/dep-update/sandbox_services opt-ins + assigned_cell |
BranchReason |
StrEnum | project.py:18 | feature/bug/chore/docs/hotfix (branch-name prefixes) |
ExtractedMessage |
Pydantic model | message.py:51 | Stored message with embedding, edit_history, mentions, task_id |
MessageType |
StrEnum | base.py:128 | reasoning/dialogue/decision/action/blocker/technical |
RawStream |
Pydantic model | message.py:32 | Ephemeral WebSocket chunk payload |
Notification |
Pydantic model | notification.py:26 | Formal signal requiring ACK; from/to_agents, acked_by, acked_at |
NotificationType |
StrEnum | base.py:139 | task_assignment/priority_change/blocker_escalation/review_request/…/a2a_request |
Journal |
Pydantic model | journal.py:75 | Agent's personal journal; entries_by_type, latest_summary |
JournalEntry |
Pydantic model | journal.py:25 | Reflection/learning/struggle/decision entry with embedding + is_private |
JournalEntryType |
StrEnum | base.py:172 | task_reflection/decision_log/learning/struggle/general |
Playbook |
Pydantic model | playbook.py:17 | Curated procedure (draft→approved/archived); from_attributes for ORM load |
PlaybookStatus |
StrEnum | base.py:112 | draft/approved/archived |
AuditEventType |
StrEnum | audit.py:13 | permission_denied/unauthorized_access/role_changed/pm_override/… |
A2ATask |
Pydantic model | a2a.py:265 | A2A protocol work unit (maps to internal TaskTable) |
A2AMessage |
Pydantic model | a2a.py:212 | A2A communication turn with Part union (text/file/data/artifact) |
AgentCard |
Pydantic model | a2a.py:103 | A2A agent discovery card (published at /.well-known/agent.json) |
A2AConversation |
Pydantic model | a2a.py:468 | Persistent agent-pair conversation (canonical agent_a<agent_b ordering) |
A2AChatMessage |
Pydantic model | a2a.py:512 | Stored A2A chat message (distinct from wire A2AMessage) |
A2ATaskState |
StrEnum | a2a.py:28 | submitted/working/completed/failed/cancelled/input_required/rejected/auth_required |
Event |
dataclass | events.py:81 | Event bus envelope with JSON round-trip + correlation_id |
EventType |
StrEnum | events.py:18 | task./session./message./agent./notification./rate_limit./usage.snapshot |
OrchestratorAgentState |
StrEnum | runtime.py:15 | offline/starting/active/waiting_short/waiting_long/idle/stopping |
AgentInstance |
dataclass | runtime.py:70 | Running Claude Code container record + usage_session_id |
SpawnGitContext |
dataclass | runtime.py:28 | Git context for spawn (project_slug, branch, task_short_id for worktree) |
MODEL_MAP |
dict | runtime.py:106 | short-name→full Claude id (opus→claude-opus-4-6, sonnet→claude-sonnet-5, haiku→…) |
ROLE_MODEL_MAP |
dict | runtime.py:114 | per-role default tier: developer/cell_pm/main_pm→sonnet, qa/documenter→haiku, pr_reviewer/auditor/board/ceo→opus (qa→haiku, main_pm→sonnet, pr_reviewer→opus are the cost-tuned defaults) |
ROLE_EFFORT_MAP |
dict | runtime.py | per-role CLAUDE_CODE_EFFORT_LEVEL override injected at spawn; empty/inert by default (opt-in per role after verifying the level moves usage) |
MODEL_CATALOG |
tuple | llm_catalog.py:67 | Settings-dropdown source of truth; Anthropic entries derived from MODEL_MAP |
OLLAMA_ROLE_DEFAULTS |
dict | llm_catalog.py:107 | Per-role model for "pure Ollama" mode |
PermissionLevel |
IntEnum | permissions.py:15 | CEO=0/BOARD=1/MAIN_PM=2/CELL_PM=3/CELL_MEMBER=4/AUDITOR=99 |
COMMUNICATION_MATRIX |
dict | permissions.py:83 | Who can directly communicate with whom (role→role set) |
IndexType |
StrEnum | optimal.py:13 | code/documentation/conversations/journals/errors/standards/decisions/reviews/learnings/playbooks |
SearchResult |
dataclass | optimal.py:32 | RAG hit (content/source/score/index_type/metadata) |
RAGResponse |
dataclass | optimal.py:58 | RAG answer + citations + per-index stats |
BottleneckReport |
dataclass | metrics.py:160 | Cumulative dwell + parked-now per lifecycle stage |
ReworkReport |
dataclass | metrics.py:205 | Bounce rate to needs_revision by team/agent + rework_cost_usd |
Scorecard |
dataclass | metrics.py:227 | Fused per-agent/per-cell delivery scorecard |
Product |
Pydantic model | product.py:38 | Groups per-cell Project mapping for a repo topology |
ProductCellMapping |
Pydantic model | product.py:13 | One cell→Project assignment; validator enforces cell-only Team |
Pitch |
Pydantic model | pitch.py:43 | Board-authored product proposal → provisioning |
DirectiveKind |
StrEnum | secretary.py:13 | relay_message/update_charter/control_task/approve_pitch/announce |
GATED_KINDS |
frozenset | secretary.py:34 | High-impact directives that bounce back for CEO confirmation |
KanbanBoard |
Pydantic model | kanban.py:79 | Board view with columns/swimlanes; get_column_config per board_type |
DocumenterHandoff |
Pydantic model | handoff.py:69 | Dev→Doc handoff (RESERVED — not yet wired in service layer) |
RobocoBase |
Pydantic BaseModel | base.py:238 | Base config: extra="forbid", validate_assignment, use_enum_values |
TimestampMixin |
Pydantic model | base.py:271 | created_at/updated_at mixin |
AgentConfig |
Pydantic model | agents.py:27 | Runtime agent config (distinct from API Agent); convenience provider/model props |
LLMUsage |
dataclass | llm.py:34 | Token accounting incl. cache creation/read |
StreamBuffer |
dataclass | transcription.py:13 | Stream accumulator with flush heuristic |
Data Flow
API request bodies → Pydantic *Create/*Update schemas (validation boundary, extra="forbid") → route handlers → services. Services translate between these models and the SQLAlchemy ORM tables in roboco/db/tables.py (e.g. TaskTable, WorkSessionTable, ProjectTable, NotificationTable, JournalTable, JournalEntryTable, AgentTable, PlaybookTable, ProductTable, PitchTable): the ORM row is the persistence shape; the Pydantic model is the contract shape. Several ORM tables load back into a model via model_config = ConfigDict(from_attributes=True) (Playbook at playbook.py:20, Product/ProductCellMapping via RobocoBase). Runtime-only DTOs (AgentInstance, WaitingRecord, SpawnGitContext, Event, ExtractionResult, StreamBuffer, the metrics/observability dataclasses, AuditFlag/AuditReport) never touch the DB directly — they are orchestrator/service in-process values. Enum parity between model and ORM is enforced by the test gate (enum columns in tables.py reference the same StrEnum classes from base.py/foundation.identity). agent.py Agent is the API/persistence model; agents.py AgentConfig is the runtime analogue used by the agent implementations — the comment at agents.py:7 calls this split out explicitly. Validation lives almost entirely on the Pydantic schemas (min_length, ge/le, pattern, model_validator); the dataclass models are intentionally validation-light.
Mermaid
erDiagram
Project ||--o{ Task : "project_id"
Product ||--o{ Task : "product_id"
Product ||--o{ ProductCellMapping : cells
Task ||--o{ Task : "parent_task_id"
Task ||--o{ Task : "dependency_ids"
Task ||--o{ CommitRef : commits
Task ||--o{ DocRef : documents
Task ||--o{ ProgressUpdate : progress_updates
Task ||--o{ Checkpoint : checkpoints
Task ||--|| TaskPlan : plan
TaskPlan ||--o{ SubTask : sub_tasks
Task ||--o| WorkSession : "work_session_id"
WorkSession }o--|| Project : "project_id"
WorkSession }o--|| Task : "task_id"
WorkSession }o--|| Agent : "agent_id"
Agent ||--o{ Journal : "journal_id"
Journal ||--o{ JournalEntry : entries
JournalEntry }o--o| Task : task_id
ExtractedMessage }o--|| Agent : "agent_id"
Agent ||--o{ Notification : "from_agent"
Notification }o--o{ Task : "related_task_id"
Task ||--o| Playbook : "source_task_ids"
Pitch ||--o| Product : "provisioned_product_id"
Pitch ||--o{ Project : "provisioned_project_ids"
Logical Tree
models/
├── tasks
│ ├── task.py Task, TaskCreate, TaskUpdate, TaskCreateRequest, CommitRef, DocRef, ProgressUpdate, Checkpoint, SubTask, TaskPlan
│ ├── kanban.py KanbanBoard, KanbanCard, KanbanColumn, KanbanSwimlane, column configs
│ ├── handoff.py DocumenterHandoff, CodeSample, DocumentationItem, ConversationRef, HandoffCreate
│ └── product.py Product, ProductCellMapping, ProductCreate, ProductUpdate
├── agents
│ ├── agent.py Agent, AgentCreate, AgentUpdate, ModelConfig, AgentPermissions, AgentMetrics
│ ├── agents.py AgentConfig, AgentState, DevTaskPhase/QATaskPhase/CellPMPhase/MainPMPhase/DocTaskPhase/ProductOwnerPhase/HeadMarketingPhase/AuditorPhase, TaskContext/ReviewContext/DocContext, AuditFlag, AuditReport
│ └── permissions.py PermissionLevel, ROLE_LEVELS, AgentContext, COMMUNICATION_MATRIX, TASK_PERMISSIONS, KB_PERMISSIONS
├── comms
│ ├── message.py ExtractedMessage, RawStream
│ ├── notification.py Notification, NotificationCreate, CreateNotificationParams
│ ├── a2a.py AgentCard, A2ATask, A2AMessage, parts, A2AConversation, A2AChatMessage, state mappers
│ ├── extraction.py ExtractionContext, ExtractionResult, ExtractionConfig
│ └── transcription.py StreamBuffer, TranscriptionConfig
├── git / work-session
│ ├── work_session.py WorkSession, WorkSessionStatus, WorkSessionCreate, WorkSessionUpdate
│ └── project.py Project, BranchReason, ProjectCreate, ProjectUpdate
├── journal / audit
│ ├── journal.py Journal, JournalEntry, JournalEntryCreate, factory params, create_*_entry, JournalStats, GrowthMetrics
│ ├── audit.py AuditEventType, PermissionDenialContext, StateTransitionDenialContext
│ └── dashboard.py FlagData, ReportData, TeamHealthData, AuditQueueItem, DashboardStorage
├── llm
│ ├── llm.py LLMUsage, ToonConfig, EncodedBlock, ToonMetrics
│ ├── llm_catalog.py CatalogEntry, MODEL_CATALOG, provider_type_for_model, OLLAMA_ROLE_DEFAULTS, OLLAMA_DEFAULT_MODEL
│ └── runtime.py OrchestratorAgentState, SpawnGitContext, OrchestratorAgentConfig, AgentInstance, WaitingRecord, MODEL_MAP, ROLE_MODEL_MAP
├── metrics
│ └── metrics.py VelocityMetrics, BlockerMetrics, TeamMetrics, AgentMetrics, StageTiming, StageBottleneck, BottleneckReport, AgentReworkRate, TeamReworkRate, ReworkReport, Scorecard
├── optimal (RAG)
│ └── optimal.py IndexType, SearchResult, SearchOutcome, RAGResponse, QueryContext, ErrorPattern, Decision, Standard, MentorResponse, CodeReviewResult, ValidationResult
├── events
│ └── events.py EventType, Event, NotificationServiceProtocol, OrchestratorAccessProtocol, EventContext
├── company / strategy
│ ├── pitch.py Pitch, PitchStatus, PitchCreate
│ ├── secretary.py DirectiveKind, DirectiveStatus, GATED_KINDS
│ └── playbook.py Playbook, PlaybookCreate, PlaybookUpdate
└── base
└── base.py RobocoBase, TimestampMixin, all shared StrEnums, AgentRole/Team aliases, Annotated ID types
Dependencies
- Pydantic (
BaseModel,ConfigDict,Field,model_validator,field_validator) — everyRobocoBasesubclass. - stdlib
dataclasses,enum.StrEnum,datetime,uuid,typing— the pure-dataclass files. roboco.foundation.identity—base.py:21importsidentityand aliasesAgentRole = identity.Role,Team = identity.Team.product.pyandpitch.pyimportCELL_TEAMS/Teamdirectly fromfoundation.identity.roboco.agents_config—permissions.py:11importsROLE_PERMISSION_LEVELSto buildROLE_LEVELSat import time.roboco.models.runtime—llm_catalog.py:22importsMODEL_MAPto derive Anthropic catalog entries.roboco.models.message—extraction.py:12importsExtractedMessage.roboco.models.product—task.py:24importsProductCellMapping(thecell_projectsfield).- Internal cross-imports are otherwise minimal;
__init__.pyis the single aggregation point.
Entry Points
from roboco.models import …— the canonical import surface (__init__.pyre-exports the API/Pydantic models + enums +get_column_config).- Direct module imports for the dataclass-only files:
from roboco.models.runtime import AgentInstance, WaitingRecord, MODEL_MAP,from roboco.models.events import Event, EventType,from roboco.models.metrics import BottleneckReport, ReworkReport, Scorecard,from roboco.models.optimal import SearchResult, RAGResponse,from roboco.models.agents import AgentConfig, DevTaskPhase,from roboco.models.llm_catalog import MODEL_CATALOG, provider_type_for_model. roboco.models.base— importRobocoBase,TimestampMixin, and any shared enum when building a new model.
Config Flags
None — pure models, no flags. (The Project model carries opt-in fields ci_watch_enabled, dep_update_command, dep_update_paths, sandbox_services (project.py:142, validated against VALID_SANDBOX_SERVICES — sandboxed dev DB/Redis, gated by ROBOCO_SANDBOX_DB_ENABLED elsewhere) that other layers gate on, and llm_catalog carries the "pure Ollama" defaults, but the models package itself reads no env / toggles nothing.)
Gotchas
AgentRoleandTeamare not defined inmodels/base.py— they areidentity.Role/identity.Teamaliased at base.py:23–24. The comment says "Removed in Phase 4 housekeeping after every consumer is migrated." SQLAlchemysa.Enum(AgentRole, name="agentrole")still works because Python identity is preserved. New code should import fromroboco.foundation.identitydirectly.ProductCellMappingdeliberately overridesuse_enum_values=False(product.py:22) soteamstays a realTeamenum foris-checks and the validator's.valueerror — the only model that deviates fromRobocoBase'suse_enum_values=True.Taskmutations are not done on the model;task.py:337directs callers toTaskService(claim,start,block,complete, …). Same pattern forNotification,Journal,WorkSession— service-owned state.TaskCreatehas no silent defaults fortask_type/nature/estimated_complexity(task.py:350 docstring) — mirrorsfoundation.policy.task_completeness.TASK_AT_CREATE. The 2026-05-08 trace of agents omittingtask_typeand deadlocking the lifecycle is the reason.TaskCreate._exactly_one_target(task.py:405) enforces exactly one ofproject_id/product_id/cell_projects. Old callers passingcell_projectsalongside either of the others now fail.- The "one active WorkSession per task" invariant is not in the model — it's a DB partial-unique index (migration 047) + service-layer guard. The model alone won't stop you constructing two active
WorkSessions. handoff.pyis RESERVED (file header, handoff.py:7) —DocumenterHandoff/HandoffStatusare defined but not wired into the service layer; current flow usesdev_notes+handoff_summaryonTask.a2a.pyhas two parallel model families: the wire/protocol models (AgentCard,A2ATask,A2AMessage, parts — A2A spec) and the persistent models (A2AConversation,A2AChatMessage,A2AInboxSummary— DB storage).A2AMessage(wire) ≠A2AChatMessage(stored).task_status_to_a2a_state/a2a_state_to_task_statusbridge RoboCoTaskStatus↔A2ATaskState(lossy — many states collapse toWORKING).agents.pyAgentState(agents.py:81) is a different class from the APIAgent.status/AgentStatusenum — runtime vs persistence. Same forAgentConfigvsAgent.events.pycarries aTYPE_CHECKINGimport ofWaitingRecordfromroboco.runtime.orchestrator— a rare upward reference, kept out of runtime by theProtocolseam.permissions.pyROLE_LEVELSis built at import time fromagents_config.ROLE_PERMISSION_LEVELS; entries that don't parse are silently skipped (except (ValueError, KeyError): passat permissions.py:35).llm_catalog.pyAnthropic entries are derived fromruntime.MODEL_MAP— bumping a Claude id there updates the catalog automatically. Ollama Cloud entries are hand-maintained.Playbookusesfrom_attributes=True(playbook.py:20) to load from the ORMPlaybookTable; most other models do not (they're constructed explicitly).
Drift from CLAUDE.md
- CLAUDE.md "Agent/Role/Team/ModelProvider in agent.py+base.py" —
RoleandTeamare no longer defined inbase.py; they are aliases toroboco/foundation/identity.py(base.py:21–24). The CLAUDE.md note aboutModelProvider(ANTHROPIC/GROK/LOCAL/OLLAMA_CLOUD/OPENAIreserved) matches base.py:197–218 exactly. - CLAUDE.md lists the
Taskmodel key fields (task_type,project_id,branch_name,work_session_id,pr_number,pr_url,docs_complete,pr_created,commits: list[CommitRef]) — all present onTask(task.py:163–255). CLAUDE.md does not mentioncell_projects(task.py:179) orbatch_id/intends_to_touch/adds_migration/touches_shared(task.py:225–236), which the MegaTask/sequencing sections elsewhere in CLAUDE.md do cover — so the model is ahead of the "Data Models" prose but consistent with the MegaTask section. - CLAUDE.md "A task has at most one active WorkSession" — enforced by DB partial-unique index (migration 047) + service layer, not by the
WorkSessionmodel itself (work_session.py has no such constraint). Consistent with CLAUDE.md's "enforced both at the service layer and by a DB partial-unique index". - The slice prompt named
AuditEventandA2AEnvelopeas landmarks; the actual symbols areAuditEventType(audit.py:13, noAuditEventclass) and there is noA2AEnvelopeina2a.py(the gatewayEnvelopelives inservices/gateway/, not here). Listed the real landmarks instead. - Otherwise:
TaskStatus15-state enum,TaskType6 values,NotificationType/JournalEntryTypeall match CLAUDE.md verbatim. - v0.17.0 delta: the three new ORM tables backing cloud auth + the X engine (
UserTable,XCredentialsTable,XSeenMentionTable— migrations 058/059) have no Pydantic counterpart in this package — cloud auth'sUserTableis consumed directly byfastapi_users/roboco.api.auth.*and the X engine's two tables are read/written directly off the ORM row byroboco.services.x_*. They are documented as ORMKey Symbolsindb-migrations.md, not here, consistent with this file's own Purpose statement ("these are not the ORM tables").
Changes Since Baseline
Range fd10cc862c2020b3f639cdb686d427b0198a2441..HEAD, git log -- roboco/models/ → 2 commits (both the same MegaTask per-cell project-map feature, PRs #283/#285). git diff --stat:
roboco/models/llm_catalog.py | 30 +++++++++++++++---------------
roboco/models/runtime.py | 6 ++++++
roboco/models/task.py | 36 ++++++++++++++++++++++++++++++------
3 files changed, 51 insertions(+), 21 deletions(-)
Logic-touching commits:
15effce0/3aff6e04— "Chore: 141 Gaps fill-in (#283)" / "Chore: Close gaps (#285)" (MegaTask per-cell project map + Ollama catalog refresh)task.py: addedcell_projects: list[ProductCellMapping]field toTask(task.py:171),TaskCreate(task.py:390), andTaskCreateRequest(task.py:482); importedProductCellMappingfromproduct.py; renamed_project_or_product→_exactly_one_targetand widened from 2-way (project_id/product_id) to 3-way (+ cell_projects) withsum(targets) != 1rejection. Impact: a MegaTask root-subtask can now target an ad-hoc per-cell project map; old callers passing neither target still fail; callers passingcell_projectsalongside another target now fail (previously silently passed becausecell_projectsdidn't exist).runtime.py:SpawnGitContextgainedtask_short_id: str | None = None(runtime.py:38) — the per-task worktree id the agent must edit in; branchless coordination roots leave itNone. Impact: additive, backward-compatible.llm_catalog.py:glm-5.1:cloud→glm-5.2:cloudinMODEL_CATALOGandOLLAMA_ROLE_DEFAULTS; role defaults reshuffled (developerminimax-m3 → kimi-k2.7-code,cell_pm/main_pm/auditorkimi-k2.6 → kimi-k2.7-code,product_owner/head_marketing/ceokimi-k2.6 → glm-5.2,documenterglm-5.1 → kimi-k2.7-code);OLLAMA_DEFAULT_MODELminimax-m3 → kimi-k2.7-code. Impact: catalog/UI labels + "pure Ollama" mode defaults only — persistedmodel_assignmentsDB rows are not touched (spawn model = persisted DB row, per the standing memory note), so an existing fleet doesn't silently switch models; only new "pure Ollama" provisioning picks the new defaults.
Post-snapshot updates (since 2026-06-29): 4 additional commits touched
roboco/models/.
c71f9b3b[chore] logical-gaps: kanban board column coverage + status-class fixes—kanban.py:DEV_COLUMNSexpanded from 7 to 15 entries (allTaskStatusvalues now covered);QA_COLUMNSdropped theVERIFYING→"In Review"entry (VERIFYING is the dev's self-check, not a QA state);PM_COLUMNSwidened to include all gate/revision/paused/cancelled/backlog columns. No model API surface change; internal column configs only.d8a5bb48[chore] logical-gaps: a2a service hierarchy gate + persist skill on message row—a2a.py:A2AChatMessagegainedskill: str | Nonefield (migration 054 adds the DB column). Thesend()verb now persists which capability the A2A is about so the receiver and inbox can surface it.536bbb64[chore] logical-gaps sweep (#286)—task.py:DocRefgainedcommit_status: str | None(whether the doc reached the project repo:committed/skipped/failed); this 8-line insertion shifts all subsequent task.py line numbers by +8 vs the baseline annotations above.playbook.py:Playbookgainedarchived_by: UUID | Noneandarchived_at: datetime | Noneto support the archive curation path.76ce53e3[fix] chat: wire live message delivery end-to-end (MESSAGE_SENT)—events.py: addedEventType.MESSAGE_SENT = "message.sent"; the bridge forwarded it to/ws/sessions/{id}and/ws/channels/{id}subscribers. Now removed by the comms-subsystem teardown (docs/internal/specs/2026-07-03-comms-teardown-trace.md) — the/ws/sessions//ws/channelsbridge and the tables it served are gone;EventType.MESSAGE_SENTitself is left as a dead/inert enum member, not deleted.
Regression Risks
| Title | File:Line | Claim | Severity |
|---|---|---|---|
TaskCreate._exactly_one_target 3-way validator |
task.py:405 | Tests/clients asserting the old 2-way error message ("a task needs either a project_id… or a product_id…") will fail against the new message ("a task needs exactly one target: … or cell_projects …"). Any caller that constructed a TaskCreate with both project_id and product_id was already rejected; callers passing cell_projects + another target are newly rejected. |
Medium |
Task.cell_projects requires migration 052 |
task.py:179 | The cell_projects field exists on the model regardless of DB state, but persistence (TaskTable.cell_projects relationship + task_cell_projects table) needs migration 052. On a DB where 052 hasn't run, TaskService.create with a non-empty cell_projects will fail at insert. |
Medium |
SpawnGitContext.task_short_id consumer parity |
runtime.py:38 | The field is additive with a None default, but every spawn-path consumer that should route the agent into the per-task worktree must read it; a missed consumer silently falls back to the clone root (the old behavior). |
Low |
| Ollama catalog defaults vs persisted assignments | llm_catalog.py:107 | OLLAMA_ROLE_DEFAULTS / OLLAMA_DEFAULT_MODEL changed, but spawn reads persisted model_assignments rows — so the defaults only apply when no row exists. An operator who deletes the model_assignments rows (the documented "kill stale fleet model" procedure) will now get kimi-k2.7-code / glm-5.2 instead of minimax-m3 / kimi-k2.6. Verify the new tags actually work on the Ollama Cloud plan before relying on this. |
Low |
ProductCellMapping import cycle risk |
task.py:24 | task.py now imports from product.py at module load. product.py imports only from foundation.identity and base.py — no cycle today, but a future product.py → task.py import would create one. |
Low |
AgentRole/Team alias removal pending |
base.py:21–24 | The aliases to foundation.identity are a migration shim ("Removed in Phase 4 housekeeping"). Consumers still importing AgentRole/Team from roboco.models.base will break when the shim is removed. |
Low |
Health
The models package is coherent and well-layered: a single RobocoBase config drives consistency, enums are centralized in base.py (with the AgentRole/Team alias-to-foundation.identity migration clearly commented), and the API/Pydantic vs runtime/dataclass split is explicit (agent.py vs agents.py, with a docstring calling it out). The recent MegaTask per-cell-map change is small, additive, and validator-guarded; the main follow-on risk is migration 052 parity and test assertions on the renamed validator message — both mechanical. Two long-standing cleanliness items linger: handoff.py is a reserved-but-unwired model (file header says so), and several files (dashboard.py, transcription.py, extraction.py) are pure dataclasses that read as service-layer DTOs rather than domain models — harmless but slightly muddies the "models = typed contract surface" framing. Enum parity with the ORM (tables.py) is enforced by the test gate. No blocking issues; the package is in good shape.