Skip to content

Deferred review backlog rollup (PRs #81, #140, #142) — Medium + Low #146

Description

@Anarchid

Second harvest of review items that were raised on PRs that then merged without them. Window: 2026-05-22 → 2026-09-08; anchors verified against main fa95817 on 2026-09-08. Companion rollups exist in context-manager, connectome-host and membrane; the one blocking item from this window is filed separately as #145 (puppetToolCall idle-guard race, from #123).

Items are grouped by the PR whose review raised them. Each was either explicitly deferred by the reviewer as non-blocking, or promised as a follow-up that was never filed.

From #81 (MCPL live policy status in server listing)

Three non-blocking notes at accept; all three still present at src/framework.ts:10640-10650.

  • allowHostCommands reports config, not the connection the gate consults. :10649 is config.allowHostCommands === true, but connection.allowHostCommands (set from config at connect) is what the admission gate actually reads (src/mcpl/server-connection.ts:316). The surface's stated premise is enforced truth; if config ever mutates at runtime without a reconnect, the listing shows intent while enforcement differs. Suggested: connection?.allowHostCommands ?? config.allowHostCommands === true.
  • connection?.grant.… optional chain stops one level short. :10646 and :10648 will throw on a connection-like object without a grant field. Every real registry entry has one, but MCPL 0.5: capability grants, negotiated policy, enforcement (#76) #79 introduced CapabilityGrant.of() for exactly this class of object after test stubs found the hole — CapabilityGrant.of(connection).effectiveList() is the consistent spelling.
  • deniedCapabilities name collides with the §5.3/§5.4 wire field of the same name (the full advertised-but-denied diagnostic); here it carries §13.4 deny-by-default paths only. The docstring disambiguates — recorded so a future reader doesn't equate them.

From #140 (save_recent_image provenance)

Carried out of the round-2 approval as explicitly deferred.

  • mintLedgerNonce is not quite six random chars — it takes the last six base36 characters of a 32-bit value, which for values ≥ 36⁶ drops the leading digit. Plenty of namespace; the doc just overstates it.
  • No test for the [save, snap] batch order. The sibling barrier was verified by reading (the round loop is synchronous, so a save dispatched before its sibling still yields at the barrier's first poll), but only [snap, save] is pinned — and [save, snap] is the order a model is at least as likely to emit.
  • Byte access for reference stubs. A uri-bearing image currently fails the index with a pointer to fetch_reference; reading the bytes through the reference record was left for the durable-blob follow-up.
  • save_recent_image can skip same-turn tool images and attach an older cross-surface image #104 acceptance item 7 (send-attachment receipt) and the per-resident memory knob were both carried to that same follow-up. Partial-range shortfall stays pre-existing semantics, surfaced in the receipt note.

From #142 (tool-wrapper prose guard)

  • Recipe-side documentation of the streaming cost. With toolWrapperProseGuard: true, proseStream is never constructed for that resident — so speak-while-acting, typing preview and any streamed outgoing delivery are off for every turn, not just wrapper turns. The docs page says so; the recipe field comment in connectome-host feat: tune-out — subconscious summaries instead of unsubscribing (#77) #115 says only "default-off containment", and the recipe is where an operator flips it. (Host-side; also listed in the connectome-host rollup.)

Method

Harvested from every PR merged into this repo in the window, by pulling review bodies, review threads and non-bot PR comments and separating "raised and then addressed in a later commit" from "raised, acknowledged, merged anyway". Line anchors are current as of fa95817.

Related: #59 (previous rollup, PR #57), #62, and #145 (the puppetToolCall race from this harvest).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions