Skip to content

fix(sdk): run hosted Babysitter through canonical Software Garden - #586

Closed
kjgbot wants to merge 22 commits into
mainfrom
fix/software-garden-babysitter-canonical
Closed

kjgbot wants to merge 22 commits into
mainfrom
fix/software-garden-babysitter-canonical

Conversation

@kjgbot

@kjgbot kjgbot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Problem

Merged #585 exposed the capability sandbox helper, but a normal canonical Software Garden run still never invoked the installed Babysitter. The ordinary authored executor imports extension code in the host and refuses the matched hosted handler, so catalog metadata alone did not make the plugin executable.

Change

  • add an embedded-only RunCliOptions.hostedSoftwareGardenBabysitter composition contract carrying host-verified dispatch authority and the single queue capability
  • resolve the complete lock-pinned Babysitter installation, exact reviewed Software Garden base, compatibility, and matched handler before journal admission or tenant import
  • admit one real relayflowd step and execute the selected installed handler through the Linux capability sandbox
  • bind admission and capability authority to delivery, base source, plugin ref/digest, and manifestSha256
  • journal queue effects with record/perform/durable receipt/confirm recovery, including provider failure and receipt-written/confirm-missing cases
  • wait for the actual hosted worker completion and propagate a rejected step.complete instead of returning an intermediate outcome
  • drain an already-started, uncancellable capability before returning from any classifier/control failure, preventing a same-delivery retry from racing the first provider write
  • validate and snapshot hosted input before admission
  • allow only the conventional project .relayflowd journal tree or an external data directory, and pre-create/canonicalize the exact receipt directory so symlinked children cannot redirect writes into hosted source
  • retain compatibility with older daemons by retrying run.start without the additive watch field on the exact legacy refusal
  • accept Agent Relay 12 and 13 peer installations while retaining optional peer semantics
  • add deterministic inventory, protocol, preflight, data-directory, peer-range, and dynamic canonical-run regressions

The canonical E2E enters through runCli(["run", authoredFlowPath, ...]), resolves the installed pin, selects the exact matched handler, and observes the queue call from inside the capability sandbox. Standalone CLI input cannot mint the non-serializable authority.

Dependency state

#584 is merged at a647470b8fa620980bf482c4b382953344ecdeeb. This branch is rebased on that exact merge and updates the reviewed Software Factory source pin. No dependency gate remains; fresh exact-head CI and independent review are required before human merge.

Exact-head evidence

Head: 36918b878f4b8ae318d05ff43db77decc892dee1

  • npm run typecheck: pass
  • npm run typecheck:tests: pass
  • npm run build: pass
  • npx vitest run tests/software-garden-babysitter-canonical-run.test.ts tests/software-garden-babysitter-preflight.test.ts tests/hosted-data-directory.test.ts tests/relay-peer-compat.test.ts: 4 files passed; 16 tests passed; 11 Linux-only tests skipped on macOS
  • git diff --check: pass
  • exact-head GitHub CI: workflow 36889884520, attempt 2 / job 110470518865 passed in 20m27s; 245 files passed / 1 skipped, 3,718 tests passed / 4 skipped. Canonical Babysitter run 14/14, preflight 5/5, hosted data-directory 7/7, and Relay peer compatibility 1/1 passed on Linux.

Prior exact-head Linux evidence at 0b241e7826651d158b0ca7706ec617d6560ea837: workflow 36497914934, job 109181694659, passed with canonical 14/14, hosted protocol 27/27, and full SDK 219 files passed/1 skipped (3,528 tests passed/4 skipped).

Review remediation

This head addresses every current substantive thread:

  • retry hosted admission without watch for a legacy daemon
  • refuse an unsafe configured in-project journal directory before daemon admission
  • validate input before creating the run/admission key
  • retain and await the dispatch promise so step.complete rejection reaches the protocol-failure path
  • race outcome classification against a resolved worker-failure signal so rejected step.complete is surfaced immediately instead of waiting for the live lease
  • include the selected artifact manifestSha256 in frozen capability authority
  • drain in-flight capability settlement before closing the journal peer on classification/cancellation errors; the Linux regression aborts after the queue starts, proves no early return, retries the delivery, and requires one total queue call
  • bound capability startup waits in the timeout regression, detect premature settlement, and guarantee cleanup
  • reject symlink/non-directory receipt storage, require its canonical path beneath the canonical data root, and use that exact validated directory for durable receipt I/O
  • normalize regular-file and dangling-symlink receipt-path refusals to deterministic pre-admission plugin_source_invalid
  • reject symlink-spelled hosted data directories so daemon storage and lexical socket identity cannot diverge or be redirected after preflight
  • include all four new suites in tsconfig.tests.json, and document that dispatch construction is trusted-host attestation while low-level sandbox helpers are not owning journal actions

It also retains the earlier durability fixes for post-capability refusal classification, recorded-but-unconfirmed effects, timeout settlement ordering, durable receipt replay, and terminal-frame parsing. Fresh independent exact-head review remains required.


Agent Relay sessions

  • claude session 228bd896 · contributor · ran gh pr commands · last active 2026-10-02

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 8833581e-ba42-4d3e-87da-0f6608f162dd

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@kjgbot

kjgbot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

maintainability lens — UNCLEAR

Not logged in · Please run /login

@kjgbot

kjgbot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

history lens — FAIL

Blocker:

  • packages/sdk/src/cli/direct-run.ts:73-125 turns the hosted path into a successful run by invoking runHostedSoftwareGardenBabysitter directly and returning a completion report before daemon attachment or any JournalClient interaction. packages/sdk/src/cli.ts:414-422 forwards that option into this bypass. This newly contradicts RFC-0001’s settled boundary: SDKs must speak the journal protocol and nothing may reach around it. The resulting capability effect has no durable run/attempt journal record. Because docs/BABYSITTER-CATALOG-HANDOFF.md:16-26 and :39-41 describe this as the intended canonical hosted run contract, this is not merely an unimplemented aspiration. Blocking deployment does not cure the architectural contradiction; the scaffold itself establishes the forbidden path.

Concerns:

Notes:

  • The recent history and DRIVE-LOG reveal no previously removed Babysitter/canonical-run pattern that this diff reintroduces.
  • The two commit subjects accurately describe their touched files and make no false test or evidence claims.

REVIEW_FAILED

@kjgbot

kjgbot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

structure lens — UNCLEAR

Error: Error from provider (Console): OpenCode's free tier can only be used from within OpenCode

@kjgbot

kjgbot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

🎯 review-swarm: FAILED (M:unclear H:fail S:unclear)

Lens transcripts posted as sibling comments above.

@khaliqgant
khaliqgant marked this pull request as ready for review September 30, 2026 10:38
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T10:44:58.878683Z 0b241e7 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0b241e7826

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/sdk/src/cli/hosted-software-garden-run.ts Outdated
Comment thread packages/sdk/src/hosted-base-snapshot.ts

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread packages/sdk/src/cli/hosted-software-garden-run.ts
Comment thread packages/sdk/src/cli/hosted-software-garden-run.ts
kjgbot added 15 commits October 1, 2026 07:07
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
@kjgbot
kjgbot force-pushed the fix/software-garden-babysitter-canonical branch from 0b241e7 to 133b9e9 Compare October 1, 2026 14:31
@kjgbot

kjgbot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

To use Codex here, create a Codex account and connect to github.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread packages/sdk/src/hosted-extension-isolation.ts
Comment thread packages/sdk/tests/relay-peer-compat.test.ts
Comment thread packages/sdk/tests/software-garden-babysitter-canonical-run.test.ts Outdated

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread packages/sdk/src/cli/hosted-software-garden-run.ts

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 19 files

Requires human review: Auto-approval blocked because this review re-detected 1 unresolved issue already reported by Cubic.

Re-trigger cubic

Comment thread packages/sdk/src/cli/hosted-software-garden-run.ts
Comment thread packages/sdk/src/hosted-data-directory.ts Outdated
Comment thread packages/sdk/tests/software-garden-babysitter-canonical-run.test.ts
Comment thread docs/BABYSITTER-CATALOG-HANDOFF.md Outdated
Comment thread packages/sdk/tests/hosted-data-directory.test.ts

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 74cb66b. Configure here.

Comment thread packages/sdk/src/cli/hosted-software-garden-run.ts

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 7 files (changes from recent commits).

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="packages/sdk/src/cli/hosted-software-garden-run.ts">

<violation number="1" location="packages/sdk/src/cli/hosted-software-garden-run.ts:64">
P2: This replaces a symlinked `dataDir` with its realpath, but `socketPathFor` hashes lexical `resolve(dataDir)`, so a daemon started with the same symlink is missed. Keep the caller's `dataDir` for journal/socket operations and use the canonical result only for receipt I/O.</violation>
</file>

Tip: Review your code locally with the cubic CLI to iterate faster.

Re-trigger cubic

Comment thread packages/sdk/src/cli/hosted-software-garden-run.ts

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 2 files (changes from recent commits).

Tip: Review your code locally with the cubic CLI to iterate faster.

Re-trigger cubic

Comment thread packages/sdk/src/hosted-data-directory.ts
@kjgbot

kjgbot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Final exact-head merge gate: GO

  • Head: 36918b878f4b8ae318d05ff43db77decc892dee1
  • Base: a647470b8fa620980bf482c4b382953344ecdeeb
  • Merge state: CLEAN / MERGEABLE
  • Exact-head Linux: run 36889884520, attempt 2 / job 110470518865 passed in 20m27s
  • Full SDK: 245 files passed / 1 skipped; 3,718 tests passed / 4 skipped
  • Focused Linux evidence: canonical Babysitter run 14/14; preflight 5/5; hosted data-directory 7/7; Relay peer compatibility 1/1
  • All current checks settled green (with npm/pages intentionally skipped)
  • Review threads: 16 total, 0 unresolved
  • Independent exact-head review: code GO and final atomic MERGE GO; no remaining security/correctness finding

The first Linux attempt had one unrelated load-sensitive failure in unchanged worker-lease-lost-live.test.ts; the exact-head rerun passed the complete job without any code change.

Repository policy reserves the merge action for a human or the Relayflow Lead's narrow exception.

@khaliqgant

Copy link
Copy Markdown
Member

Closing per Khaliq (2026-10-02). Babysitter is being redesigned to be Flows-webhook-only (no Relay runtime dependency), with the original context inherited from relayhistory sessions when a webhook wakes the agent. This PR runs hosted Babysitter through the Relay-coupled path, so it is superseded. Technically it was CLEAN with CI green at 36918b8; if the peer-range and legacy-daemon pieces are still wanted they should come back as a small separate PR.

@khaliqgant khaliqgant closed this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants