Peter Steinberger
fa03d9b913
refactor: consolidate coercion helpers ( #121366 )
...
* refactor: consolidate coercion helpers
* fix: remove duplicate coercion imports
* fix: preserve serialized coercion guard
* chore: ratchet coercion helper carve-outs
* fix(test): keep gauntlet subprocess startup lean
* fix: preserve imported session timestamp semantics
* fix: preserve catalog timestamp string semantics
* chore: align plugin SDK surface ratchet
* fix: preserve trajectory and SDK string contracts
* fix(test): preserve QA record assertion semantics
* fix: complete standalone record guard rename
* refactor(cron): use canonical string coercion
* fix(acpx): preserve Pi timestamp parsing
* test(channels): adapt custody test harnesses
* test(telegram): classify media harness as test support
* test(acpx): split timestamp contract coverage
* test(channels): support generated custody contracts
* chore: ban the full coercion helper name set
Extends the declaration guard to all eleven consolidated helper names and
renames the cron schedule-identity readNumber wrapper to readScheduleInteger
so the banned generic name cannot regrow.
* fix(scripts): repair release-validation guard drift and lint cause
Restores the renamed isJsonRecord guard in assertTrustedWorkflowHarness after
main added isRecord call sites in parallel, and attaches the caught YAML error
as the thrown error cause (preserve-caught-error was red on main).
* fix: preserve Claude timestamp string semantics
* fix: preserve persisted timestamp string semantics
* fix: preserve date-first timestamp contracts
* fix(openai): harden delegation failure formatting
* chore: close coercion helper guard gaps
* test(openai): model non-error delegation rejection
* chore: refresh plugin SDK API contract
* fix(tasks): use canonical string field reader
* fix(ai): use canonical provider error field coercion
* fix(browser): migrate native bootstrap coercion
* docs(plugin-sdk): clarify text record export compatibility
* fix(gateway): normalize approval execution identity
* test(outbound): isolate message action poll harness
2026-08-11 00:02:18 -07:00
Josh Avant
73a9eed95b
refactor(audit): add canonical admitted-run context ( #120534 )
...
* feat(audit): carry canonical admitted execution context
* fix(agents): preserve admitted context across retries
* fix(worker): fence legacy launch dialect
* test(gateway): track approval temp dirs
* fix(plugin-sdk): preserve harness attempt compatibility
* fix: close delegated run authority at owner boundaries
* fix: internalize delegated authority validators
* refactor: split delegated authority proof surfaces
* refactor: centralize command admission identity
* test: claim runtime tool authority
* fix(gateway): keep lifecycle cleanup within static budgets
* fix(agents): revalidate harness policy authority
* fix(agents): fence awaited approval capability results
* test(copilot): supply required harness capability fixtures
* fix(agent): preserve scoped embedded run admission
* fix(agent): preserve keyless and worker authority
* test(agent): bind incomplete-turn authority
* docs: preserve execution authority invariants
* chore(plugin-sdk): regenerate API baseline
* fix(gateway): notify pending claim closure
* fix(gateway): revalidate delegated tool authority
* fix(plugin-sdk): keep source guard internal
* fix: close delegated authority races
* fix: revalidate delegated side effects
* fix: close harness authority projection gaps
* fix: align authority integration types
* fix: isolate settled harness finalization
* fix: fence recovery identity finalization
* fix: preserve committed session worktrees
* fix: preserve worker placement agent identity
* fix: fence active harness tool work
* fix(plugins): restore embedded run admission owner
* chore(plugin-sdk): compose integrated surface budgets
* fix(copilot): keep finalization attempt type internal
* fix(plugins): complete admission owner type imports
* test(harness): use settled finalization attempt shape
* fix(security): retain exact side-run and approval authority
* fix(security): preserve protected authority through terminal sweep
* fix(agents): follow moved recovery store owner
* fix(ci): align integrated authority owners with gates
* fix(plugins): distinguish embedded agent adapter export
* chore(plugin-sdk): regenerate API baseline after rolling integration
* refactor(gateway): keep session authority within owner budgets
* fix(gateway): keep session helpers private
* docs(plugin-sdk): name the V2 parameter subpath
* chore(integration): reconcile worker and SDK surfaces
* docs(plugin-sdk): require the V2 host API floor
* chore(plugin-sdk): regenerate after proxy-auth integration
2026-08-10 23:15:20 -05:00
Peter Steinberger
b5d5ec340f
feat(cloud-workers): add desktop apps and browser autonomy ( #121475 )
...
* feat(cloud-workers): add desktop apps and browser autonomy
provider-attested Browser/Terminal launchers, shared visible loopback CDP Browser tool, no MCP/cookies/generic command.
* feat(ui): add cloud desktop app launcher
* docs(gateway): document cloud desktop apps and browser autonomy
* perf(ui): trim desktop launcher startup copy
* refactor(ui): simplify desktop launch feedback
* perf(ui): reuse desktop app labels
* fix(ui): keep desktop launch failures actionable
* fix(crabbox): allow browser bootstrap to finish
* fix(cloud-workers): honor provider provision budgets
* fix(cloud-workers): persist browser screenshot receipts
* fix(cloud-workers): bound browser screenshot lifecycle
* fix(cloud-workers): avoid replaying desktop launches
* test(cloud-workers): isolate browser runtime integration
* refactor(cloud-workers): tighten desktop runtime boundaries
* test(cloud-workers): keep browser runtime mock synchronous
* fix(cloud-workers): break gateway type import cycle
* fix(ci): settle admitted setup sessions in tests
* build(plugin-sdk): refresh desktop app contract
* ci: refresh merge-tree validation
* build(plugin-sdk): regenerate desktop app baseline
* style(gateway): format merged method order test
2026-08-10 20:31:07 -07:00
Peter Steinberger
d6f70a96cb
fix(plugins): native commands execute the selected plugin ( #121544 )
...
* fix(plugins): preserve selected command identity
* test(telegram): use scoped command registries
* test(telegram): isolate command runtime fixtures
* test(telegram): warm native command runtime
* refactor(plugins): keep command metadata private
* fix(plugins): accept synchronous command handlers
* fix(plugins): scope command drain bypass to live execution
* test(telegram): use scoped command registry fixtures
* test(telegram): isolate native menu runtime fixtures
* test(telegram): isolate login session store
* test(telegram): surface login flow failures
* test(telegram): preload native login module
* test(telegram): scope native command registries
* fix(plugins): complete command dispatch contracts
* fix(plugins): break command dispatch import cycles
* fix(plugins): stabilize command dispatch contracts
* fix(channels): keep plugin dispatch options internal
* fix(plugins): keep command dispatch carrier opaque
* test(channels): align delivery adapter fixtures
* test(delivery): align custody ownership coverage
* test(delivery): align latest queue reconciliation
* test(channels): drop obsolete delivery wrappers
* fix(plugins): rebind channel reload starts
* fix(plugins): scope command catalog reloads
* fix(ci): align current runtime contracts
* chore(plugin-sdk): refresh API baseline
2026-08-10 19:30:47 -07:00
Ayaan Zaidi
9935ca3b30
fix(approvals): bind native requests to channel accounts ( #121673 )
...
Native approval delivery and resolution now stay bound to the originating or explicitly targeted channel account. Unbound requests fail closed across multiple eligible accounts; trusted reviewer-less SDK callers remain compatible.
Co-authored-by: Ayaan Zaidi <hi@obviy.us >
2026-08-11 01:42:41 +05:30
Peter Steinberger
8ee945b907
refactor(channels): flatten channel-turn dispatch naming layers ( #121308 )
...
* refactor(channels): flatten channel turn dispatch naming
* docs(plugin-sdk): narrow inbound reply compat guidance
* docs(channels): point stale references at turn defining modules
* fix(channels): preserve dispatch contracts after flattening
* chore(plugin-sdk): ratchet surface budgets after flattening
* chore(channels): ratchet removed export collisions
* fix(plugin-sdk): restore inbound reply compat exports
Restore eight still-existing legacy callable re-exports from canonical SDK seams and cover the deprecated package subpath with a table-driven compatibility test.
Raise the public export, callable export, and deprecated export budgets by exactly eight; the three maintainer-authorized zero-consumer symbols remain removed.
* test(channels): split channel turn kernel coverage
Replace the oversized kernel test with independently mocked delivery, pipeline, and finalize suites, preserving all 51 tests while removing the max-lines suppression and stale ratchet entry.
* chore(plugin-sdk): refresh inbound reply API hash
* fix(ci): align channel turn review fixes
Restore the test-local DeliveryResult type removed during the split.
Ratchet the public export, callable export, and deprecated export budgets by exactly seven: six channel-inbound plus one channel-outbound legacy re-export.
2026-08-09 22:22:46 -07:00
Peter Steinberger
c71c29ecae
fix: preserve exec completion identity across poll and heartbeat ( #120575 )
...
* fix(agents): bind terminal polls to exact process
UUID-owned completion receipts and ProcessSession-bound finished snapshots prevent same-slug successor consumption.
* chore(plugin-sdk): refresh API baseline
Refresh declaration-closure hashes for the internal system-event receipt boundary.
2026-08-09 17:18:32 -07:00
Peter Steinberger
0efd5b4bc9
refactor(channels): move owner policy into plugins ( #121257 )
...
* refactor(channels): move owner policy into plugins
* test(plugin-sdk): lower surface budget after export removal
2026-08-09 15:46:18 -07:00
Peter Steinberger
ce53f7e82e
refactor(agents)!: remove the session write lease ( #121113 )
...
* refactor(agents): remove session write lease
* refactor(plugin-sdk): deprecate session write lease
* refactor(doctor): remove session lock checks
* test(agents): remove session lease fixtures
* test(agents): align writer rebound assertion
* refactor(infra): remove retired session lock exports
* test(tooling): preserve embedded abort race shard
2026-08-09 15:30:48 -07:00
Peter Steinberger
6ee409ca7b
refactor(commands): share native plugin command merging ( #120972 )
2026-08-09 14:57:45 -07:00
Peter Steinberger
8fdf7570a1
feat(gateway): live Desktop observer for cloud workers (Labs) ( #120727 )
...
* feat(gateway): live desktop observer for cloud workers
Adds live observation for cloud worker desktops through the gateway and Crabbox plugin, including desktop provisioning, persisted desktop metadata, tunneled WebSocket proxying, and the worker.desktop.observe protocol method.
The gateway, Crabbox plugin, and gateway protocol surfaces remain off by default behind the cloudWorkers.desktop Labs flag.
* feat(ui): Desktop panel for cloud worker observation
* docs(gateway): document cloud worker desktop lab
* fix(ci): regenerate contract baselines after rebase
* fix(protocol): regenerate Android gateway methods
* fix(ci): align rebased SDK and lint baselines
* fix(gateway): enforce view-only RFB boundary and fence desktop teardown
* fix(gateway): tighten RFB filter surface
* fix(state): keep pre-desktop databases readable and harden view-only RFB
* fix(gateway): fence desktop observer upgrades behind work admission
* fix(gateway): bind desktop observer tokens to their owner epoch
* fix(ci): regenerate config and SDK baselines after rebase
* fix(ci): regenerate native protocol and SDK baselines
* fix(ci): regenerate contracts after main rebase
* fix(state): register desktop metadata as lazy additive
* fix(ci): regenerate SDK baseline after final direct-merge rebase
2026-08-09 09:37:01 -07:00
Peter Steinberger
9a96375e60
feat(gateway): session-catalog terminal start plans behind cliAgents gate ( #121020 )
...
* feat(gateway): add session-catalog terminal start plans
* refactor(gateway): split catalog terminal start handler
* fix(gateway): enforce catalog terminal start eligibility
* test(gateway): split session catalog snapshot coverage
2026-08-09 08:13:39 -07:00
Peter Steinberger
c70aee247e
refactor(scripts): migrate JavaScript tools to TypeScript ( #121005 )
...
* refactor(scripts): migrate JavaScript tools to TypeScript
* fix(ci): keep changed-scope preflight zero-install
* fix(ci): preserve zero-install script owners
* fix(ci): complete script migration follow-through
* fix(release): keep stable closeout zero-install
* fix(scripts): preserve standalone execution boundaries
* fix(scripts): repair standalone loader boundaries
* fix(scripts): normalize gateway observation ids
* fix(scripts): keep Docker packager standalone
* test(scripts): preserve rebase cleanup helpers
* test(sessions): use tracked temp directory
2026-08-09 07:21:35 -07:00