Repository navigation
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
maintainability lens — UNCLEARNot logged in · Please run /login |
history lens — FAILBlocker:
Concerns:
Notes:
REVIEW_FAILED |
structure lens — UNCLEARError: Error from provider (Console): OpenCode's free tier can only be used from within OpenCode |
|
🎯 review-swarm: FAILED (M:unclear H:fail S:unclear) Lens transcripts posted as sibling comments above. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0b241e7826
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
0b241e7 to
133b9e9
Compare
|
@codex review |
|
To use Codex here, create a Codex account and connect to github. |
There was a problem hiding this comment.
All reported issues were addressed
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed across 19 files
Requires human review: Auto-approval blocked because this review re-detected 1 unresolved issue already reported by Cubic.
Re-trigger cubic
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 74cb66b. Configure here.
There was a problem hiding this comment.
1 issue found across 7 files (changes from recent commits).
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="packages/sdk/src/cli/hosted-software-garden-run.ts">
<violation number="1" location="packages/sdk/src/cli/hosted-software-garden-run.ts:64">
P2: This replaces a symlinked `dataDir` with its realpath, but `socketPathFor` hashes lexical `resolve(dataDir)`, so a daemon started with the same symlink is missed. Keep the caller's `dataDir` for journal/socket operations and use the canonical result only for receipt I/O.</violation>
</file>
Tip: Review your code locally with the cubic CLI to iterate faster.
Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed across 2 files (changes from recent commits).
Tip: Review your code locally with the cubic CLI to iterate faster.
Re-trigger cubic
|
Final exact-head merge gate: GO
The first Linux attempt had one unrelated load-sensitive failure in unchanged Repository policy reserves the merge action for a human or the Relayflow Lead's narrow exception. |
|
Closing per Khaliq (2026-10-02). Babysitter is being redesigned to be Flows-webhook-only (no Relay runtime dependency), with the original context inherited from relayhistory sessions when a webhook wakes the agent. This PR runs hosted Babysitter through the Relay-coupled path, so it is superseded. Technically it was CLEAN with CI green at 36918b8; if the peer-range and legacy-daemon pieces are still wanted they should come back as a small separate PR. |

Problem
Merged #585 exposed the capability sandbox helper, but a normal canonical Software Garden
runstill never invoked the installed Babysitter. The ordinary authored executor imports extension code in the host and refuses the matched hosted handler, so catalog metadata alone did not make the plugin executable.Change
RunCliOptions.hostedSoftwareGardenBabysittercomposition contract carrying host-verified dispatch authority and the single queue capabilitymanifestSha256step.completeinstead of returning an intermediate outcome.relayflowdjournal tree or an external data directory, and pre-create/canonicalize the exact receipt directory so symlinked children cannot redirect writes into hosted sourcerun.startwithout the additivewatchfield on the exact legacy refusalThe canonical E2E enters through
runCli(["run", authoredFlowPath, ...]), resolves the installed pin, selects the exact matched handler, and observes the queue call from inside the capability sandbox. Standalone CLI input cannot mint the non-serializable authority.Dependency state
#584 is merged at
a647470b8fa620980bf482c4b382953344ecdeeb. This branch is rebased on that exact merge and updates the reviewed Software Factory source pin. No dependency gate remains; fresh exact-head CI and independent review are required before human merge.Exact-head evidence
Head:
36918b878f4b8ae318d05ff43db77decc892dee1npm run typecheck: passnpm run typecheck:tests: passnpm run build: passnpx vitest run tests/software-garden-babysitter-canonical-run.test.ts tests/software-garden-babysitter-preflight.test.ts tests/hosted-data-directory.test.ts tests/relay-peer-compat.test.ts: 4 files passed; 16 tests passed; 11 Linux-only tests skipped on macOSgit diff --check: passPrior exact-head Linux evidence at
0b241e7826651d158b0ca7706ec617d6560ea837: workflow 36497914934, job109181694659, passed with canonical 14/14, hosted protocol 27/27, and full SDK 219 files passed/1 skipped (3,528 tests passed/4 skipped).Review remediation
This head addresses every current substantive thread:
watchfor a legacy daemonstep.completerejection reaches the protocol-failure pathstep.completeis surfaced immediately instead of waiting for the live leasemanifestSha256in frozen capability authorityplugin_source_invalidtsconfig.tests.json, and document that dispatch construction is trusted-host attestation while low-level sandbox helpers are not owning journal actionsIt also retains the earlier durability fixes for post-capability refusal classification, recorded-but-unconfirmed effects, timeout settlement ordering, durable receipt replay, and terminal-frame parsing. Fresh independent exact-head review remains required.
Agent Relay sessions
claudesession228bd896· contributor · rangh prcommands · last active 2026-10-02