Skip to content

feat(babysitter): pin standalone launch artifact - #616

Merged
khaliqgant merged 5 commits into
mainfrom
feat/babysitter-standalone-artifact
Oct 6, 2026
Merged

khaliqgant merged 5 commits into
mainfrom
feat/babysitter-standalone-artifact

Conversation

@kjgbot

@kjgbot kjgbot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • commit the exact standalone Babysitter launch source and digest manifest
  • pin the credential-free operator policy to agent-relay-code[bot] + babysit
  • explicitly assert enforcedAgentWriteScope: true and add a reproducibility/drift gate
  • normalize the dynamic reviewer CLI/model to required strings and make the shipped-source audit track that exact single call
  • document that Cloud must bind this exact SHA-256 to daemon-only PR read/comment authority before deployment

Artifact SHA-256: eed5e5de88d9477c3155c205310d4c4c060b8de2fcdb9ddbbe8c8c517cf22e2d (33,927 bytes)

This PR does not deploy or enable a listener.

Verification

  • node --experimental-strip-types --test examples/babysitter/tests/*.test.ts — exit 0; 92 pass, 7 deliberate TODO gates
  • cd packages/sdk && ./node_modules/.bin/vitest run tests/shipped-source-models.test.ts — 2/2 passed, including the formerly failing artifact model-pin gate
  • node examples/babysitter/build-standalone.mjs --check — exact digest reproduced
  • git diff --check — pass

Rollout prerequisite

Do not deploy this artifact through a generic launcher. Cloud #4226 pins this exact content identity, rejects profile drift, launches without a repository grant or house funding, exposes only a single-repository daemon credential with PR/check/status read plus issue-comment write, and atomically caps acting runs at 2/head and 5/PR lineage. Unknown digests and broader authority fail closed.


Note

Medium Risk
Changes standalone admission and deployment contract (digest allowlist, headSha gate, agent scope assertion); behavior is well-tested but Cloud must honor the new binding before safe rollout.

Overview
Pins the standalone Babysitter to a committed, content-addressable launch bundle under artifacts/, with a manifest recording byte size, SHA-256, credential-free standalone-policy.json (agent-relay-code[bot] / babysit), and enforcedAgentWriteScope: true for Cloud allowlisting.

Tightens launch semantics: babysitter.pullRequest.headSha is now required from Cloud; after a live GitHub reread, the flow declines if the live head does not match that server claim—before signals, agent diagnosis, or comment—so per-head admission quotas stay aligned with the diagnosable head.

Build/CI: build-standalone.mjs no longer takes an operator policy path; it always bundles the pinned policy into artifacts/ and adds --check / npm run check:standalone to block drift. New artifact tests and standalone unit tests cover head binding; SDK adds esbuild and a shipped-source waiver for the bundled flow.

Reviewed by Cursor Bugbot for commit 713ec13. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 58a3aa28-112a-4dd9-a687-299829900867
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 8 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="examples/babysitter/tests/standalone-artifact.test.ts">

<violation number="1" location="examples/babysitter/tests/standalone-artifact.test.ts:36">
P2: This test makes the babysitter suite depend on `packages/sdk/node_modules/esbuild/lib/main.js`, but the babysitter README's test setup installs only `packages/surface` deps and the `@relayflows/surface` symlink — no SDK install. On a fresh checkout following that documented path, the spawned `build-standalone.mjs` fails on its top-level `import ... from '../../packages/sdk/node_modules/esbuild/lib/main.js'` and the test fails while all other babysitter tests pass. esbuild is also not a declared dependency of `packages/sdk` (absent from its package.json), so the path is only present via transitive hoisting. Add the SDK dependency install to the babysitter test instructions in README.md (or detect the missing module and skip/diagnose clearly), otherwise this gate silently breaks the documented suite.</violation>
</file>

Comment thread examples/babysitter/tests/standalone-artifact.test.ts
Comment thread examples/babysitter/STANDALONE.md Outdated
@kjgbot

kjgbot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

maintainability lens — UNCLEAR

Not logged in · Please run /login

@kjgbot

kjgbot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

history lens — PASS

Blockers: none.

Concerns:

  • This is not yet RFC-0001 decision drive: cloud run 35c4df23 #14’s sealed bundle. build-standalone.mjs:24-57 produces generated TypeScript while leaving @relayflows/surface external, and the manifest lacks pinned dependencies, canonical spec, preflight declaration, and signature (artifacts/babysitter-standalone.manifest.json:1-14). However, the PR explicitly says it does not deploy anything and documents Cloud enforcement as a rollout prerequisite (STANDALONE.md:121-148). Under the requested scaffolding rule, that is a follow-up concern, not a contradiction warranting rejection.
  • The test name says “explicitly read-only,” but it verifies only the presence of enforcedAgentWriteScope: true (tests/standalone-artifact.test.ts:14-42). The documentation correctly admits that readonly is not currently enforced and that Cloud must supply the credential boundary (STANDALONE.md:123-143). Renaming the test to describe an asserted platform prerequisite would avoid suggesting that this repository proves enforcement.

Notes:

  • DRIVE-LOG records a prior self-certification mistake where mutable gate inputs and their hashes lived together. This diff does not repeat that mistake as a claimed trust boundary: its adjacent manifest and --check gate establish reproducibility/drift detection (build-standalone.mjs:59-73), while the actual authorization boundary is explicitly deferred to an external Cloud digest allowlist.
  • The source-level fail-closed default remains intact; only the generated, allowlist-gated artifact supplies the runtime assertion (build-standalone.mjs:27-30, STANDALONE.md:145-148).
  • The sole commit message, feat(babysitter): pin standalone launch artifact, accurately describes the added committed artifact and manifest. It makes no test or evidence claim that the diff disproves.

REVIEW_PASSED

@kjgbot

kjgbot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

structure lens — UNCLEAR

Error: Error from provider (Console): OpenCode's free tier can only be used from within OpenCode

@kjgbot

kjgbot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

🎯 review-swarm: FAILED (M:unclear H:pass S:unclear)

Lens transcripts posted as sibling comments above.

@kjgbot

kjgbot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

To use Codex here, create a Codex account and connect to github.

@barryollama barryollama left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent review of exact head 713ec13: zero actionable findings remain in the reviewed standalone Babysitter path. The server-claimed head is required and a differing live head declines before signal collection, diagnosis or comment. Verified the committed artifact matches SHA-256 eed5e5de88d9477c3155c205310d4c4c060b8de2fcdb9ddbbe8c8c517cf22e2d (33,927 bytes).

Previously executed at this unchanged head:

node --experimental-strip-types --test examples/babysitter/tests/standalone.test.ts examples/babysitter/tests/standalone-artifact.test.ts

Captured test output:

ok 1 - the committed standalone artifact is exact, reproducible, and explicitly read-only
ok 7 - a live head different from the server-claimed head declines before signals, diagnosis or comment
1..21
# tests 21
# suites 0
# pass 21
# fail 0
# cancelled 0
# skipped 0
# todo 0

Rechecked before approval: unchanged open/non-draft head, all current exact-head workflows/checks terminal success or skipped, and zero unresolved review threads.

@khaliqgant
khaliqgant merged commit fe60dd4 into main Oct 6, 2026
9 of 10 checks passed
@khaliqgant
khaliqgant deleted the feat/babysitter-standalone-artifact branch October 6, 2026 13:05
AgentRelayBot pushed a commit that referenced this pull request Oct 9, 2026
…shes

F2 in the Babysitter owner plan (Revision 1, approved by the lead). The
fixer keeps only the run's read and comment token. It checks out the bound
head, runs one agent there with the origin session's scope, and journals
one bounded proposal: a patch against the bound head plus thread replies.
Cloud publishes the proposal server-side as a fast-forward-only commit;
FIXER.md is the contract. RULING-sandbox-push-0902 forbids push
credentials in sandboxes.

- admission.ts: admission prelude shared with the diagnose body, extracted
  unchanged; every standalone test still passes.
- fix.ts: checkout, using the token as a header, never in argv or config,
  and reusing an existing checkout. Proposal limits: 36KB patch, 50 files,
  50KB total; workflow and secret paths are refused.
- fixer.ts: the body. Replies go only to inline feedback that woke the run,
  are marked and neutralised, and the origin prompt is redacted.
- Builtins load with import(), not require(). esbuild rewrites require
  into a __require shim that does not exist under `node -e`. A test runs
  the function lifted out of the shipped artifact; it was mutation-checked.
- build-standalone.mjs builds both artifacts; the drift gate covers both.
- shipped-source audit: a call-exact waiver for "babysitter-fix", like
  #616's "babysitter-diagnose".

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

Session-Id: 497569fc-550a-44a0-a906-35c233c27ba6
AgentRelayBot pushed a commit that referenced this pull request Oct 9, 2026
…shes

F2 in the Babysitter owner plan (Revision 1, approved by the lead). The
fixer keeps only the run's read and comment token. It checks out the bound
head, runs one agent there with the origin session's scope, and journals
one bounded proposal: a patch against the bound head plus thread replies.
Cloud publishes the proposal server-side as a fast-forward-only commit;
FIXER.md is the contract. RULING-sandbox-push-0902 forbids push
credentials in sandboxes.

- admission.ts: admission prelude shared with the diagnose body, extracted
  unchanged; every standalone test still passes.
- fix.ts: checkout, using the token as a header, never in argv or config,
  and reusing an existing checkout. Proposal limits: 36KB patch, 50 files,
  50KB total; workflow and secret paths are refused.
- fixer.ts: the body. Replies go only to inline feedback that woke the run,
  are marked and neutralised, and the origin prompt is redacted.
- Builtins load with import(), not require(). esbuild rewrites require
  into a __require shim that does not exist under `node -e`. A test runs
  the function lifted out of the shipped artifact; it was mutation-checked.
- build-standalone.mjs builds both artifacts; the drift gate covers both.
- shipped-source audit: a call-exact waiver for "babysitter-fix", like
  #616's "babysitter-diagnose".

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

Session-Id: 497569fc-550a-44a0-a906-35c233c27ba6

Session-Id: 497569fc-550a-44a0-a906-35c233c27ba6
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants