Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
{
"id": "compact_evj1c14lvl5i",
"version": 1,
"type": "compacted",
"compactedAt": "2026-09-09T18:43:45.715Z",
"sourceTrajectories": [
"traj_yzfk3s3ayol8"
],
"dateRange": {
"start": "2026-09-09T18:16:43.036Z",
"end": "2026-09-09T18:43:04.851Z"
},
"summary": {
"totalDecisions": 1,
"totalEvents": 1,
"uniqueAgents": [
"default"
]
},
"decisionGroups": [
{
"category": "api",
"decisions": [
{
"question": "Keep local-only capabilities fixed through reconciliation",
"chosen": "Keep local-only capabilities fixed through reconciliation",
"reasoning": "Recovered connectivity drains durable audit records without republishing DMs, which could execute work twice or route local names to another machine. Fleet capabilities require a deliberate normal restart.",
"fromTrajectory": "traj_yzfk3s3ayol8"
}
]
}
],
"keyLearnings": [],
"keyFindings": [
"Explicit --local-only starts without Relaycast, confines the API to loopback, suppresses fleet connections and worker credentials/MCP injection, and reports degradation in startup, health, session, connection metadata and CLI status.",
"Local delivery is saved before acceptance. Pending work waits for a restarted recipient; a bounded, destination-pinned audit outbox survives restart and reconciles with stable event IDs without replaying DMs.",
"Validation: 1065 Rust tests passed (4 ignored), 107 CLI tests passed, TypeScript typecheck and Clippy passed. Compiled base/head proof verified outage startup failure on base and local spawn, send, terminal IO, restart retention and reconnect audit replay on head.",
"Inherited GIT_CONFIG_COUNT and RELAY_ATTEST_SESSION_ID alter isolated Git hook fixtures. Unsetting only those variables for the test subprocess yields a passing full suite; repository commit hooks remain enabled.",
"GitHub API authentication returns HTTP 401; SSH access works. PR creation and subsequent CI/review follow-through require restored API authentication. No merge authorized."
],
"filesAffected": [
"crates/broker/src/runtime/degraded.rs",
"crates/broker/src/runtime/init.rs",
"crates/broker/src/runtime/delivery.rs",
"crates/broker/src/listen_api.rs",
"packages/cli/src/cli/lib/broker-lifecycle.ts",
"tests/relayflows/cases/broker-local-only/run.mjs"
],
"commits": []
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
# Broker local-only operation

Explicit --local-only starts without Relaycast, confines the API to loopback, suppresses fleet connections and worker credentials/MCP injection, and reports degradation in startup, health, session, connection metadata and CLI status.

Local delivery is saved before acceptance. Pending work waits for a restarted recipient; a bounded, destination-pinned audit outbox survives restart and reconciles with stable event IDs without replaying DMs.

Validation: 1065 Rust tests passed (4 ignored), 107 CLI tests passed, TypeScript typecheck and Clippy passed. Compiled base/head proof verified outage startup failure on base and local spawn, send, terminal IO, restart retention and reconnect audit replay on head.

Inherited GIT_CONFIG_COUNT and RELAY_ATTEST_SESSION_ID alter isolated Git hook fixtures. Unsetting only those variables for the test subprocess yields a passing full suite; repository commit hooks remain enabled.

GitHub API authentication returns HTTP 401; SSH access works. PR creation and subsequent CI/review follow-through require restored API authentication. No merge authorized.

Decision: Recovered connectivity drains durable audit records without republishing DMs, which could execute work twice or route local names to another machine. Fleet capabilities require a deliberate normal restart.
Original file line number Diff line number Diff line change
@@ -0,0 +1,75 @@
{
"id": "compact_fzz26f8hgo9y",
"version": 1,
"type": "compacted",
"compactedAt": "2026-09-10T11:35:10.845Z",
"sourceTrajectories": [
"traj_bl7fngii53oq"
],
"dateRange": {
"start": "2026-09-10T05:19:58.099Z",
"end": "2026-09-10T11:35:09.983Z"
},
"summary": {
"totalDecisions": 2,
"totalEvents": 4,
"uniqueAgents": [
"default"
]
},
"decisionGroups": [
{
"category": "testing",
"decisions": [
{
"question": "Pin unscoped nonempty outboxes and retain exhausted local deliveries during recipient absence",
"chosen": "Pin unscoped nonempty outboxes and retain exhausted local deliveries during recipient absence",
"reasoning": "CodeRabbit identified valid privacy and data-integrity holes. Regression tests failed on the prior implementation. Reset the handoff failure budget while waiting so a respawn can actually receive retained work, and preserve original outbox bytes on destination mismatch.",
"fromTrajectory": "traj_bl7fngii53oq"
},
{
"question": "Preserve roster and identity safety across the main rebase",
"chosen": "Preserve roster and identity safety across the main rebase",
"reasoning": "Read merged software-garden#510 and relaycast#401 diffs. Stale roster snapshots are dispatch-only evidence; offline owners and all durable node associations remain protected. Combined upstream status timeout warnings and startup/cleanup tests with local degraded behavior. Local workers create no Relaycast identity, so exclude them from remote owned-generation cleanup and prove exited names can respawn during an outage.",
"fromTrajectory": "traj_bl7fngii53oq"
}
]
}
],
"keyLearnings": [],
"keyFindings": [],
"filesAffected": [
".agentworkforce/trajectories/active/traj_bl7fngii53oq/trajectory.json",
".agentworkforce/trajectories/compacted/compact_ah4a5rcyq7wq_2026-09-09.json",
".agentworkforce/trajectories/compacted/compact_ah4a5rcyq7wq_2026-09-09.md",
"CHANGELOG.md",
"crates/broker/src/cli/mod.rs",
"crates/broker/src/listen_api.rs",
"crates/broker/src/relaycast/ws.rs",
"crates/broker/src/runtime/api.rs",
"crates/broker/src/runtime/degraded.rs",
"crates/broker/src/runtime/delivery.rs",
"crates/broker/src/runtime/event_loop.rs",
"crates/broker/src/runtime/fleet.rs",
"crates/broker/src/runtime/init.rs",
"crates/broker/src/runtime/mod.rs",
"crates/broker/src/runtime/session.rs",
"crates/broker/src/runtime/tests.rs",
"crates/broker/src/worker.rs",
"packages/cli/README.md",
"packages/cli/src/cli/commands/core.test.ts",
"packages/cli/src/cli/commands/core.ts",
"packages/cli/src/cli/commands/node.ts",
"packages/cli/src/cli/commands/status.test.ts",
"packages/cli/src/cli/commands/status.ts",
"packages/cli/src/cli/lib/broker-lifecycle.ts",
"packages/harness-driver/src/protocol.ts",
"tests/relayflows/cases/broker-local-only/case.json",
"tests/relayflows/cases/broker-local-only/run.mjs"
],
"commits": [
"8f3bb080b0593815f7512d6f47ee77c876c158cb",
"bc4c177dcfab13777dd859f11e4723deb7f3c10c",
"5717d1b9bcbf1df81f2978883a0325b99af1d280"
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
# PR 1726 review fixes and main rebase

The four review findings are fixed: nonempty unscoped outboxes cannot acquire an upload destination; exhausted local deliveries wait for absent recipients and retry after reconnect; taskless spawns remain idle; IPv6 listener and discovery addresses are bracketed. The outage proof records unexpected traffic during the outage as well as after recovery.

Read the merged software-garden#510 and relaycast#401 diffs before resolving the rebase. Stale roster snapshots remain dispatch-only evidence; offline or inactive ownership never proves an identity can be deleted. Preserved main's bounded status probes, startup ordering, cleanup safeguards, and release notes. Local workers now stay out of remote identity ownership bookkeeping; the process proof rejects a remote identity deletion request without stopping the local worker, and verifies local exit/respawn.

Rebased onto main b90248a39 (v12.0.0). Validation passed: 1,099 Rust tests (four ignored), 163 CLI tests, typecheck, strict Clippy, and local red/green process proofs using the exact base and rebased harness. Both the outbox/retry regressions and the local identity-ownership regression were observed failing before their fixes.

GitHub reports the PR mergeable. CI run 34470354002 passed proof metadata validation and exact artifact verification, then Cloud failed before either proof arm: registering base-prover returned workspace_busy with a 60-second retry interval. The uploaded cloud.log confirms this is a pre-test infrastructure failure. A normal Actions rerun was rejected by GitHub authentication; this durable record also supplies the branch update for a fresh CI run after cooldown. CI is still pending at the time of this record. No merge was performed.
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
{
"id": "compact_kr0gviod7ik8",
"version": 1,
"type": "compacted",
"compactedAt": "2026-09-10T12:42:58.526Z",
"sourceTrajectories": [
"traj_4rcc69em81p7"
],
"dateRange": {
"start": "2026-09-10T12:36:24.740Z",
"end": "2026-09-10T12:42:57.920Z"
},
"summary": {
"totalDecisions": 1,
"totalEvents": 1,
"uniqueAgents": [
"default"
]
},
"decisionGroups": [
{
"category": "testing",
"decisions": [
{
"question": "Preserve privacy opt-outs and existing identity recovery; constrain audit transport and normalize effective persistence",
"chosen": "Preserve privacy opt-outs and existing identity recovery; constrain audit transport and normalize effective persistence",
"reasoning": "The delayed review correctly identified state-dir lease expiry and bind trimming. Privacy opt-outs must stay enabled rather than be removed. Audit payloads must never follow redirects; the existing registration SDK strips cross-origin Authorization, verified by a regression test. A separate trajectory data directory avoids modifying an unrelated active task.",
"fromTrajectory": "traj_4rcc69em81p7"
}
]
}
],
"keyLearnings": [],
"keyFindings": [],
"filesAffected": [],
"commits": []
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# Trajectory Compaction: Sep 10, 2026 - Sep 10, 2026

## Summary
- Sessions: 1
- Decisions: 1
- Events: 1
- Agents: default
- Files: 0
- Commits: 0

## Testing
- Preserve privacy opt-outs and existing identity recovery; constrain audit transport and normalize effective persistence -> Preserve privacy opt-outs and existing identity recovery; constrain audit transport and normalize effective persistence (traj_4rcc69em81p7)

## Key Learnings
- None

## Key Findings
- None
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
# PR 1726 follow-up review — 2026-09-10

New CodeRabbit and Cursor findings arrived after the rebase validation.

- Reset restored local deliveries' failed transport budget at load time. The new regression reproduced a dropped delivery when the worker was already registered before the first retry, then passed after the fix. Remote retry budgets remain unchanged.
- Normalize bracketed IPv6 before local-only loopback validation; the process proof now starts with `[::1]`.
- Remove Relaycast identity and telemetry variables after all child environment injection. A real shell child proves the variables and credentials are absent.
- Clarify that absent local recipients retain queued work, restarted recipients receive a fresh transport budget, and only a configured digest-matching audit destination can drain a backlog.
- Keep `[Unreleased - Minor]`: AGENTS.md explicitly requires a release level for pending user-visible changes. The review suggestion to remove the level conflicts with that instruction.

Validation: 1,100 Rust tests passed (4 ignored), strict Clippy passed, formatting and diff checks passed, and the updated local process proof passed. The preceding head's Cloud red-green proof passed in run 34472224310. New-head CI remains pending at this record's creation.

The delayed review was recorded through the trajectory tool as `traj_4rcc69em81p7`, using an isolated data directory so the unrelated subscription-demo trajectory remains untouched. Its completed, compacted record is tracked alongside this note.


## Hosted validation follow-through

Head 64b34f7cb passed every code/build/lint/security/smoke check. The standalone
macOS smoke also passed locally, including workspace reuse and confirmed cleanup.
All nine code/documentation review threads are resolved. The remaining changelog
thread contradicts AGENTS.md's explicit pending-release-level rule; its prepared
reply could not be posted because GitHub write authentication is unavailable.

Cloud run 34473632153 failed before executing either proof arm: the executor
could not register `base-prover` after transient retries because Relaycast returned
`workspace_busy` with Retry-After 60 seconds. This is the same pre-case service
failure seen before the successful Cloud run 34472224310. The implementation and
proof assertions remain unchanged; this evidence update triggers a fresh CI run.


## Delayed review fixes

Use effective `paths.persist` for owner leases and the renew-lease response; the
process proof now starts using only `--state-dir` and asserts persistent state
with no expiry. Normalize padded IPv6 consistently before binding and discovery.

Audit endpoints require HTTPS except for literal loopback HTTP development
endpoints. Audit records use a pooled HTTP client that refuses redirects, with
a regression proving a redirected destination receives neither credentials nor
private work. The existing registration SDK's cross-host/port Authorization
stripping has a separate regression; identity ownership and recovery stay intact.

Keep `AGENT_RELAY_TELEMETRY_DISABLED`, `DO_NOT_TRACK`, and
`AGENT_RELAY_NO_DEBUG_FILES` set to 1 in local children. They are privacy opt-outs,
not Relaycast identity; the review's assertion that they must be absent is not
part of the contract. The real-child proof now asserts those values explicitly.

Validation: 1,102 full-suite Rust tests passed (4 ignored), plus the new SDK
redirect regression passed; strict Clippy and the updated process proof passed.
Cloud attempts 34475219721 and 34476269829 failed before case execution, at
sandbox launch and workspace registration respectively. Hosted CI must be
rechecked after this change; no green result is claimed here.
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
{
"id": "compact_vx8338g80q6c",
"version": 1,
"type": "compacted",
"compactedAt": "2026-09-10T19:36:29.991Z",
"sourceTrajectories": [
"traj_sn0ch8h9fihu"
],
"dateRange": {
"start": "2026-09-10T19:32:41.173Z",
"end": "2026-09-10T19:36:29.408Z"
},
"summary": {
"totalDecisions": 1,
"totalEvents": 1,
"uniqueAgents": [
"default"
]
},
"decisionGroups": [
{
"category": "testing",
"decisions": [
{
"question": "Treat prior local reconciliation as optional during normal startup",
"chosen": "Treat prior local reconciliation as optional during normal startup",
"reasoning": "The real-process regression exits before normal readiness when an unscoped backlog meets a configured destination. Preserve strict local-only startup checks, but retain an unmatched backlog with a warning and continue normal mode. Add process assertions for unscoped and differently scoped files, unchanged bytes, and no private audit upload. Reviewed the related Garden roster-cache and Relaycast retention changes; this does not change either ownership or roster policy.",
"fromTrajectory": "traj_sn0ch8h9fihu"
}
]
}
],
"keyLearnings": [],
"keyFindings": [],
"filesAffected": [],
"commits": []
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# Trajectory Compaction: Sep 10, 2026 - Sep 10, 2026

## Summary
- Sessions: 1
- Decisions: 1
- Events: 1
- Agents: default
- Files: 0
- Commits: 0

## Testing
- Treat prior local reconciliation as optional during normal startup -> Treat prior local reconciliation as optional during normal startup (traj_sn0ch8h9fihu)

## Key Learnings
- None

## Key Findings
- None
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
{
"id": "compact_drrcx6ih8b5e",
"version": 1,
"type": "compacted",
"compactedAt": "2026-09-10T19:24:28.621Z",
"sourceTrajectories": [
"traj_glcziiq16vc3"
],
"dateRange": {
"start": "2026-09-10T19:16:15.407Z",
"end": "2026-09-10T19:24:27.985Z"
},
"summary": {
"totalDecisions": 2,
"totalEvents": 3,
"uniqueAgents": [
"default"
]
},
"decisionGroups": [
{
"category": "testing",
"decisions": [
{
"question": "Preserve both changelog entries and strengthen delivery proof",
"chosen": "Preserve both changelog entries and strengthen delivery proof",
"reasoning": "Only CHANGELOG conflicted on latest main. All four pending-review replies were already posted and resolved. The queue regression must test live exhausted state before load resets the budget; the process proof must verify retained worker delivery separately from audit reconciliation.",
"fromTrajectory": "traj_glcziiq16vc3"
}
]
},
{
"category": "other",
"decisions": [
{
"question": "Validate both live retry ordering and crash recovery against pre-fix delivery code",
"chosen": "Validate both live retry ordering and crash recovery against pre-fix delivery code",
"reasoning": "The strengthened unit regression fails with exhaustion before absence handling (exit 101). The expanded real-process proof passes fixed code and fails with delivery.rs from initial feature commit 0aaac651e (exit 1, absent work dead-lettered). The marker was shortened to fit the PTY line width after confirming payload rendering.",
"fromTrajectory": "traj_glcziiq16vc3"
}
]
}
],
"keyLearnings": [],
"keyFindings": [],
"filesAffected": [
"CHANGELOG.md",
"packages/cli/src/cli/commands/fleet.test.ts",
"packages/cli/src/cli/commands/fleet.ts",
"packages/cloud/src/fleet-sandbox.test.ts",
"packages/cloud/src/fleet-sandbox.ts",
"tests/relayflows/cases/1630-scoped-relayfile-sandbox-mount/run.mjs",
"tests/relayflows/cases/1732-daytona-provider-sandbox-identity/case.json",
"tests/relayflows/cases/1732-daytona-provider-sandbox-identity/run.mjs"
],
"commits": [
"4ea088d93",
"10a7bac1c",
"2bac41acb",
"94138ffbc",
"0930799d6",
"6c816f0bb",
"7c9aa708b",
"0531e38f5",
"0aaac651e",
"6e44912d9",
"39ca68f5d"
]
}
Loading
Loading