[codex] feat: add Runtime Host capability RPC - #513
Conversation
|
Final review found two focused E2E gaps before #513 can satisfy Core #512. The architecture and bounded Room RPC look sound; CI is green. Please fix these in this same PR rather than opening another implementation PR. 1. Production daemon does not wire the local controller into resident RuntimeThe daemon owns That means the real resident Runtime gets a nil handler:
Please add a real daemon→resident integration regression, not only isolated Runtime tests. Also account for
Acceptance regression should exercise: 2. Agent semantic path is not yet discoverable#512 requires the resident Agent to discover the bounded capability description and invoke the same semantic controller. The local CLI commands exist, but the Harness bootstrap currently documents collab/attach/surface/context/room-app only; Do not hard-code LED behavior into the prompt. Add the smallest generic Agent-facing discovery seam, for example:
Required properties:
Once these two gaps are fixed, rerun the existing full TS/Go matrices plus the new daemon integration and Harness-discovery regressions. No Runtime release work yet. |
|
Final code review after commit The two prior blockers are resolved:
The new daemon regression exercises live configure after the resident socket is online, projection refresh, controller replacement, and Resident RPC dispatch through the current daemon controller. The Harness regression pins generic discovery and the no-source-search/no-Room-authority contract. GitHub workflows for head Remaining gate before merge:
No more architecture work is requested unless this dogfood exposes a concrete bug. |
|
Final isolated E2E dogfood is BLOCKED before Phase 1; no test Worker was deployed and no code was changed.
I stopped before starting a resident, fixture, or browser session. This means every runtime E2E acceptance item remains unverified, not passed. To continue, provide a dedicated test Realtime SFU app (App ID/secret through a secure secret channel) and isolated Worker/KV resources, or refresh the Wrangler authorization with Calls write access and confirm that I should provision disposable test resources. Once available, I can resume on this exact PR head. PR remains draft and unmerged. |
|
Correction to my earlier blocker report: I had not checked the repository dogfood skill before reporting that isolated deployment and Turnstile were unavailable. That was my mistake. The skill supports a uniquely named temporary workers.dev Worker, isolated KV, and a Turnstile bypass confined to that temporary config. I have deployed that isolated Worker and am continuing the real browser/Runtime flow; production Worker routes and config remain untouched. I will replace this interim correction with the verified E2E result after cleanup. |
Final #512 E2E and regression updateCommit: The final E2E exposed one remaining Room projection gap: the MCP Zod schema stripped Deployed dogfood used an isolated temporary workers.dev Worker with Turnstile disabled only in that temporary configuration. In two independent browser contexts, an already-online Runtime gained the capability projection after daemon configure; Human control and a generic Agent discovery/invocation both reached the same daemon-owned controller. The Agent discovered the bounded descriptor through Runtime commands, observed and invoked it under explicit Harness/operator approvals, and did not receive an endpoint, config, credential, or supplied capability ID in its prompt. The second Human context had no local controls. The temporary Worker and its isolated KV namespace have been deleted; the temporary URL returns 404, and production Local verification after temporary-resource cleanup:
The existing PR remains Draft and open. GitHub Actions for this pushed commit were still pending when this update was posted. No merge, release, or production deployment was performed. |
|
Follow-up: GitHub Actions have now completed successfully for this update. App Tests, Lint & Type Check, Room App host matrix, Go test/vet/build, Distribution / cleanup contract, Format & lint autofix, and all four release build targets passed. Build & Deploy and Publish GitHub Release were skipped by their workflow conditions; the PR remains Draft and no deployment or release occurred. |
|
Final gate: PASS / ready to merge at exact head Why this is sufficient:
Temporary Worker/KV cleanup is complete and production was not changed during dogfood. #512 should remain open after source merge until the merged Core is deployed and a released Runtime binary containing this protocol is accepted. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 710f80efd8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| (candidate.capabilityControlHumanParticipantId === undefined || | ||
| candidate.capabilityControlHumanParticipantId === | ||
| candidate.humanParticipantId) |
There was a problem hiding this comment.
Rebind capability control during provider reattachment
When capability control is enabled and a browser reload reattaches the provider under a new Human participant ID, both reattachRuntimeHostProvider and completeDeferredRuntimeHostProviderReattach retain the old capabilityControlHumanParticipantId while replacing humanParticipantId. This new validation consequently rejects the association during the next activeRoom() normalization, dropping the entire private provider binding and potentially invalidating an active Live Transcript as well as capability control. Clear the grant or transfer it to the replacement participant during both reattachment paths.
AGENTS.md reference: AGENTS.md:L108-L110
Useful? React with 👍 / 👎.
Summary
Implements the two Runtime capability halves tracked by Free4Chat Core #512: a Runtime-local semantic controller and a bounded, deterministic Human-to-Room-to-Runtime capability RPC.
The Runtime owns a fixed localhost fixture adapter and its private endpoint configuration. Room/Core carries only bounded semantic descriptors and request/results over the existing private Resident WebSocket. Human requests do not enter Room chat, Task ingestion, Harness scheduling, or persistent Room state.
Wire contract
runtime-capability-controlandruntime-capability-request.Authorization and bounds
Human and Agent paths
The paired Human owner can review the descriptor, opt in, observe, and invoke typed actions in the Room UI. Production daemon residents now receive a stable daemon-owned capability delegate; each descriptor/request resolves the daemon's current controller, including after live
capability configure. Live configure refreshes each online resident's Runtime Host projection so Room discovery updates without reconnecting.A fresh Harness bootstrap teaches generic local discovery through
$FREE4CHAT_AGENT_BIN capability list --json, followed by the bounded describe/observe/invoke commands using IDs and schemas returned by the daemon. The command returns validated semantic projections only. It does not include endpoint/configuration values. The prompt leaves local authorization and approvals to Harness/operator policy; Room input itself grants no local authority.Runtime-local fixture
The daemon-owned controller supports the configured local fixture through fixed
GET /stateandPOST /actions/set-ledroutes. CLI and Human RPC calls reach the same daemon-owned controller. No arbitrary proxy/path API is exposed.Follow-up regressions for review comment 5890825840
TestDaemonCapabilityConfigureRefreshesExistingResidentAndRoutesThroughCurrentControllerstarts a real daemon resident, configures after its private event socket is online, verifies the Host descriptor refresh, replaces the configured controller, then routes a Resident request and proves the current daemon controller answers.TestCapabilityListDiscoversCurrentBoundedDescriptorThroughDaemoncovers generic ID/schema discovery with no Human-supplied ID and checks endpoint/config values are absent.TestBootstrapDiscoversGenericRuntimeLocalCapabilityWithoutRoomAuthoritypins the generic command path, source-search prohibition, and local approval authority rules without embedding fixture/action semantics.Validation
yarn test— 125 files, 1,412 tests passed.go vet ./...,go test ./... -count=1 -timeout 300s,go test -race -count=1 ./internal/voice, andgo build ./cmd/free4chat-agent.This remains a draft PR based on
cf-sfu; no Runtime release work is included.