feat(cli): generate collision-safe service query wiring - #1664
feat(cli): generate collision-safe service query wiring#1664rickylabs wants to merge 60 commits into
Conversation
|
[PHASE: RESEARCH] Re-baselined #1355 and #1360 at Findings
Evidence: research.md Next
|
|
[PHASE: PLAN] Tier-A plan review returned Plan
T-1 — evidence class repaired
T-2 — exact lease-precondition scenarios
Determinations
Open decisions for PLAN-EVAL
Evidence: plan.md Next
|
…nerator paths Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TiYhwUCkdyjziEpFP3kgaS
[PHASE: PLAN-EVAL] [VERDICT: FAIL_PLAN] — cycle 1/2Plan Ruling on the forkDirect emit — no SDK overload. Generated constant becomes Findings
Verified and holding: all diagnoses re-derived at source (key shapes, Next
|
Fork ruled for direct emit: the overload is an identity wrapper, does not remove the trap, and would couple the CLI template to SDK >=0.0.7 so a 0.0.7 CLI generating into an sdk@0.0.6-pinned app emits a module that fails deno check. Six plan-text fixes dispatched. Cycle 2 requires a coordinator grant. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LQBHX8KpA5aYtDraq46J8a
|
[PHASE: PLAN-UPDATE] [CYCLE: 1] Repaired all six Rulings recorded
Preserved decisions
Validation
NextCoordinator verifies this exact head and separately grants PLAN-EVAL cycle 2. This implementation session does not launch it. |
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UrhsQgBYpLZWHKAhCvESi6
[PHASE: PLAN-EVAL] [VERDICT: PASS] — cycle 2/2Repaired plan Fork rulingCycle-1 ruling stands and is complied with: direct emit Checked
Implementation constraints (non-blocking; IMPL-EVAL to verify)
Next
|
Evaluator verified clientKey exists in published sdk@0.0.6 rather than inheriting cycle 1's claim, and caught that the SDK-0.0.6 test was named for a property it did not assert. C1-C3 recorded as implementation constraints. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LQBHX8KpA5aYtDraq46J8a
|
[PHASE: IMPL] [SLICE: S1] S1 is complete at Scope delivered
Tests
Focused evidence at the committed content head
Next: STOP. S2 requires a separate coordinator dispatch. |
|
[PHASE: IMPL] [SLICE: F6] [BINDING-RECOVERY] The first F6 binding-test receipt remains an append-only red:
Coordinator review established the failure as environmental. F5 had 4,226/0/19 = 4,245 results; F6 attempt 1 had 4,228/1/19 = 4,248, so the F6 delta added three results and two additional passes. The sole failure was the forbidden-command walker receiving The coordinator quarantined that tree recoverably:
The leaf did not delete, chmod, move, or mutate the residue. Attribution was committed and pushed before the rerun at Exactly one distinct environmental rerun then executed at the unchanged content head:
All three F6-added results remain present and now pass, confirming the environmental attribution. The two conditional gates then ran serially and passed at the same content head. Exact contracted passing set
All four attest The original No product, template, fixture, lockfile, documentation, expensive gate, browser, Aspire, Docker, lease, evaluator, readiness, label, or metadata change occurred. |
|
[PHASE: IMPL] [SLICE: S5] [ATTEMPT: 5] The singleton release-gate lease executed exactly once at immutable leaf evidence head Gate verdicts
The complete pretty transcript is: SHA-256: The suite-owned NDJSON event log—containing all 70 exact step IDs, verdicts, durations, and evidence—is: SHA-256: The pretty stream has 68 explicit PASS lines plus one FAIL. The 69th pass is the suite runner's synthetic The complete transcript was streamed through Runtime findingsThe repaired generator/runtime seams remained green:
The sole red was The probe failed before CDP connection, navigation, mutation, or refetch-count assertions. This is not a refetch-behavior verdict; the behavior remains unproven. At pre-implementation Cleanup and lease release
Three run-owned stopped NuGet helper processes were observed, but all exited naturally between ownership verification and the targeted TERM call; every signal attempt returned The host is proven empty and the leaf releases the singleton lease. The post-browser cleanup audit is NOT_REACHED / NOT_APPLICABLE because Durable report: Evidence commit: |
|
[PHASE: PLAN] [SLICE: F7] F7 is committed as a plan-only amendment at Measured disposition
Reviewed ceiling for a later repair
The plan names Deterministic cheap proof
Explicit precondition failure, recorded skip, and host provisioning remain coordinator-owned alternatives; this amendment chooses none. See NextFresh Tier-A review. No implementation before approval. |
|
[PHASE: PLAN] [SLICE: F7-C1] F7-C1 is committed at Corrected classification
Strict selection contractThe portable override is
Bounded diagnostics and proofThe existing two-path ceiling remains:
The 32 KiB continuously drained tail and target/status race remain. Early exit reports selection source/path, code, signal, and stderr; live target timeout preserves its cause/text and adds source/path without inventing an exit code. The proof matrix binds managed-binary version selection, override precedence, exhaustive invalid/no-fallback cases, immediate code-2 stderr, bounded chatty output, live timeout, and all F6 proofs. See |
|
[PHASE: IMPL] [SLICE: F7] [GATE-STOP] F7 stayed inside the reviewed browser-probe/test pair. Strict The serial binding sequence stopped honestly at
The sole failure is the unchanged teardown walker receiving No retry or residue mutation occurred, and the downstream gates were not started. Exact-set recomputation over the four paths is INSUFFICIENT: Evidence head pushed: |
|
[PHASE: IMPL] [SLICE: F7] [BINDING-RECOVERY] Environment-only binding recovery completed at immutable content The original Exact passing set:
Exact-set recomputation: SUFFICIENT, reasons Recovery evidence is committed at |
|
[PHASE: IMPL] [SLICE: S5-A6] [VERDICT: FAIL] Attempt 6 executed exactly once from a clean detached checkout at the leased evidence head Gate verdicts
Browser selection evidence
Suite-owned evidence
Cleanup and audits
Evidence commit: No product/test mutation, second runtime attempt, browser gate, evaluator, readiness/label/acceptance change, merge, or quarantine deletion occurred. |
|
[PHASE: PLAN] [SLICE: F8] Edited in place. This comment originally cited Contamination and repair.
Plan content (unchanged by the repair). Attempt 6 is attributed exactly: managed Chromium selection and launch are proven, while The amendment keeps the exact two-path ceiling: Artifacts at |
`d8d5ee619` carried a `leak-report.md` change the plan author did not produce: a supervisor host audit ran into the author's checkout and rewrote the `Generated` timestamp and `Worktree` line. Restore the file byte-for-byte to its blob at `2385cdb72` and record the provenance correction in the run worklog. Append-only: `d8d5ee619` is not amended or rewritten. F8 plan content is untouched. No gate, audit, or leak-check was run.
Evaluates head 4255a57 vs baseline 2385cdb (plan-only delta; no packages/**, test, template, fixture, or lockfile mutation). All six F8 criteria met: 1. CdpClient.connect and CdpClient.send identified as the only two unbounded primitives from code measurement; ledger's evidentiary limit honestly recorded. 2. Bound contract is diagnostic: CDP WebSocket connection + URL + 20000 ms vs CDP response + method + 20000 ms. 3. 20000 ms is 45x below the 900000 ms suite boundary. 4. Deterministic unit-level reproductions (inert socket and never-returning send) with watchdog tests; no browser, Aspire, Docker, or runtime suite required. 5. Path ceiling is exact, narrow, and explicitly affirmed sufficient (two paths: service-client-browser-probe.ts + service-client-runtime-probe_test.ts). 6. F6 teardown contract (no discard sink, same drain, natural-exit / active-SIGTERM / three-negative / delegation proofs) and F7 selection/startup diagnostics (strict override, runnable/version probing, bounded startup, no-versioned-cache-literal) remain green. Authority: native-quota fallback for formal_plan_evaluation per lane-policy.md:65 (Codex author quota blocked until 2026-08-20). Co-Authored-By: Claude <noreply@anthropic.com>
Reattached the docs topic supervisor against central recovery commit ba16887 and audited main 9634735 read-only. The four post-checkpoint RFC merges touch only .llm/ and rfcs/ and carry no documentation or release-compatibility drift; their 0000- numbering is the documented draft convention, not drift. #1663 and #1664 have no docs consequence. #1671 does: it is based before the new blocking docs:exports-drift step in pages.yml, and it leaves docs/site/reference/sdk/index.md teaching the old isDefinedError idiom that its own guide rewrite drops. Lane stays EXHAUSTED / PARKED at allocation [1551]. No scope taken, no merge, publish, readiness flip, runtime lease, or self-certification. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PMQqcnqEbKKQQz2ipLNf7K
Twelve supervisor-owned receipts across two attempts, plus the scoped lint/fmt regression found and closed between them. Attributed to the Tier-A supervisor, not the author. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018K6Cs9HBAeSvKNjkyQ72bf
F8 — bounded CDP transport waits: implemented, corrected, Tier-A ACCEPTEDContent head (attested by every gate): Slices
Path ceiling held on both product slices: What changed
Three new deterministic tests use a 25 ms production bound against a 1,000 ms watchdog — a 40× margin, Why one slice was returnedAt Evidence at
|
| Gate | Outcome |
|---|---|
| focused probe test file | 25 passed / 0 failed (545 ms) |
check |
PASS |
test |
PASS — 4,240 passed, 0 failed, 19 ignored |
publish-dry-run |
PASS |
arch-check |
PASS |
lint |
PASS |
fmt-check |
PASS |
scoped lint / fmt on packages/cli/e2e |
0 / 0 |
Sufficiency recomputed over the explicitly named four-receipt attempt-2 set (not a glob):
SUFFICIENT, zero reasons, every receipt gitHead == actualGitHead == 4f50b5a02. No any,
deno-lint-ignore, or as unknown as introduced. Attempt-1 receipts retained append-only.
Carried, none blocking
terminateBrowserProcess:448-449remains unbounded — F6-owned, out of F8 scope, and only now
reachable. For a later leaf.- The 20 s bound on
Runtime.evaluatenarrows one theoretical slow-but-successful case; that is the
intended trade. pendingCommandCountForTestis a contained test-only accessor:e2e/is excluded from the
@netscript/clipublish set,@netscript/cli-e2eis"publish": false, ande2e/mod.tsdoes not
re-export the probe.
Status
No scaffold.runtime, browser, Aspire, Docker, or lease was used; docker ps -a is empty.
Runtime attempt 7 is not granted — it is prohibited for this leaf and not the topic supervisor's
to grant. The green reviewed content head is reported to the coordinator for the singleton
runtime-lease decision. PR remains draft; no readiness flip, relabel, merge, or issue mutation.
One leased invocation at 388f2b6. 68/1/0, exit 1, sole red now attributable at 60s with a named stack trace instead of a silent 900s boundary kill. Neither CDP bound fired, so the transport was healthy and the repair is not credited with fixing attempt 6's hang. Three orphaned aspire-managed processes that both the cleanup gate and leak-check missed were reaped; unreadable residue moved to a recoverable quarantine. Supervisor-generated evidence; no author or product bytes changed. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018K6Cs9HBAeSvKNjkyQ72bf
S5 attempt 7 — runtime red, now attributable; cleanup and quarantine completeExecuted exactly once under coordinator lease VerdictRaw exit The failure mode changed categorically
The 900-second silent boundary kill did not recur; the gate now stops in a fifteenth of the time and What this proves — and what it does notNeither CDP bound fired. Zero matches for This does not prove F8 repaired attempt 6's hang. With no CDP timeout fired, there is no evidence The remaining red is behavioral, not transport. The optimistic row
The inter-gate audit read empty and was wrong
The one run-owned unreadable residue ( Post-quarantine re-audit is empty on every class: unreadable Preserved evidence
No retry, no product or test mutation, no evaluator, no readiness/merge/metadata action, no relabel. |
Coordinator withheld IMPL-EVAL while scaffold.runtime is red; attempt 7 closed centrally at 164c392 with no retry authorized and fresh-browser NOT_RUN. Records the green cheap evidence, the attributable runtime red, and D-20: cleanup.aspire-stop PASS plus leak-check survivors:[] is not a complete residue verdict. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018K6Cs9HBAeSvKNjkyQ72bf
Summary
Generates collision-safe per-service query clients, preserves Fresh loader cache age during hydration, and adds deterministic regeneration semantics. The implementation and cheap exact-head proofs are complete. The PR remains draft because the single authorized runtime attempt 7 ended red at the now-attributable optimistic-update behavior boundary;
fresh-browser, IMPL-EVAL, and readiness are therefore withheld.Closes #1355
Closes #1360
Current checkpoint
a257807d883ac9cd8d692d441bba1760290d4dab.4f50b5a026120b5a3b0195fa1b6f495f08e2b46c.25/0; check, test, publish dry-run, architecture, scoped lint, and scoped format receipts are exact-head PASS/SUFFICIENT; the second fresh Tier-A review passed.68 PASS / 1 FAIL / 0 skipped, exit 1. The sole red wasbehavior.service-client-refetchafter 60,134 ms: the browser never observed the optimisticSeed User*row after Rename.fresh-browserwas correctlyNOT_RUN; no retry or evaluator was run.Completed slices
cachedAtasinitialDataUpdatedAt; generated assets and package guidance updated.fresh-browser, fresh opposite-family IMPL-EVAL, and readiness checks.Runtime evidence and cleanup
s5-attempt7-scaffold-runtime-20260823-075547.log, SHA-256a4ee67d25fa7189fd183cc6478c88e7b6cadf7a8b5bb041a585e1fb29694a042.s5-attempt7-scaffold-runtime-20260823-075547.ndjson, SHA-256c0b1a450498b0027ad9acce33fad373f05fafbb0eb61c326a53463c6a6a0eff4./tmp/netscript-s5-a7-quarantine.Cy2tNS; it was not deleted.Guardrails
This leaf does not merge, publish, close issues manually, flip ready, grant itself another runtime lease, or broaden the approved paths. Every review thread, acceptance mirror, exact-head CI, close-gate, and fresh IMPL-EVAL must be complete before readiness.