Repository navigation
Epic #542: binding epoch, self-authenticating attach, durable acked delivery, one idle detector (ADR 0067) - #580
Merged
Merged
Conversation
|
The latest Buf updates on your PR. Results from workflow CI / buf (pull_request).
|
nikhilunni
added a commit
that referenced
this pull request
Jul 6, 2026
AgentSpec.binding_epoch + HarnessAttachAck.reject + the harness Cli token args in test fixtures that macOS clippy cannot see (the documented cfg(target_os) blind spot) — caught by the musl cross-check. Belongs to epic #542's change; cherry-picked down to epic/542-binding-epoch so PR #580's FC lane heals. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
nikhilunni
force-pushed
the
epic/542-binding-epoch
branch
2 times, most recently
from
July 6, 2026 15:45
e80f2d2 to
37edcb9
Compare
…livery (#542) Squashed re-integration of epic #542 onto current main. ADR 0067→0070, WIRE 9→10 (both collided with merges that landed after this branched). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014jJi2vqAaxt3Q5UKxbe4Gx
nikhilunni
force-pushed
the
epic/542-binding-epoch
branch
from
July 6, 2026 15:54
37edcb9 to
8378fcf
Compare
nikhilunni
marked this pull request as ready for review
July 6, 2026 16:09
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Implements #542 (epic: binding epoch + self-authenticating harness attach + durable acked delivery + one idle detector). ADR 0067 authored Proposed-first and flipped to Accepted with the commit chain, per convention. One commit per phase.
What this does
Phase 1 — binding epoch + self-authenticating attach (migration 0083)
PG owns
sessions.binding_epoch, minted coordinator-side at every fresh-spawn bind and carried as an attach token (ENGRAM_SANDBOX_ID+ENGRAM_BINDING_EPOCH, stamped by the backend at spawn — FC/VZ/Process uniformly). The hub validates every attach against a host-durable binding record (<work_dir>/bindings/<session>.json, monotonic in the epoch) — never an in-memory map. A restarted host-agent accepts survivor re-dials with zero rebuild pass (#447 closed by construction;rebind_survivor_sessionsdeleted); a stale generation is rejectedSupersededand exits (the fbd3794c 8-fake-resume loop is unrepresentable).Phase 2 — coordinator-durable outbox, SendPrompt 202 (migration 0084)
Prompts/answers become
session_outboxrows: receipt + echo + one INSERT + NOTIFY + immediate return. The delivery driver resumes the session behind the enqueue, forwards oldest-first, self-heals the unbound desync, and redelivers until the confirming harness event acks the row at the emit choke point. The e35ed1f eaten-message class is gone; the host replay buffers, 10s attach wait,deliver_with_reattachpoll, 60s HOLD loop, and the orchestrator's "mention me again" are deleted.Phase 3 — one idle detector, PG shell pin (migration 0085)
The PG event-log scanner (was the "L3 backstop") becomes THE detector with the host detector's exact semantics (soft 300s/hard 1800s TTLs, 10s cadence, disk brake, default-off pressure-aware gating — now reading heartbeat-persisted
hosts.utilization). Shell pins become ashell_pinned_untilcolumn stamped by the relays (issue #219 leak class structurally gone). Deleted: the host eviction tick, hub TTL scan, candidates POST path, desync watchdog + rehandshake RPC +HarnessCommand::Rehandshake, shell-pin RPCs. Heartbeat gainsharness_attachedas a disagreement alarm (metric), never a healer.Phase 4 — hub down to one leaf mutex; actor-ization moot
With seven of eight maps deleted across the phases, the planned actor rewrite would wrap one never-nested mutex in machinery. Recorded in the ADR as moot-by-deletion.
Deploy notes (⚠️ read before merge)
HarnessAttachandHarnessCommandare clean bincode breaks (variant indices re-pinned in goldens).publish-bundleson merge covers it; a stale bundle fails attach loudly (UnknownBinding), which is the designed failure.ENGRAM_IDLE_TTL_SECS/ENGRAM_IDLE_HARD_TTL_SECS/ENGRAM_IDLE_EVICT_*now belong on the coordinator deployment (values unchanged; engrams-internal follow-up).Divergences from the issue (all recorded in ADR 0067's log)
assign_session_sandbox) — the token rides spawn env, which exists before the sandbox does.sandbox_idis informational.prompt_receivedcoordination honored: the event stays the SLO receipt anchor.Testing
just checkgreen (fmt, clippy -D warnings, hakari, full workspace suite).bun test541 pass.rebind_survivor_sessionstests → fresh-hub disk-routing tests;harness_command_redelivery→ outbox re-arm live-PG test + driver; backstop/candidates nomination tests → idle_detector tests.Baselines this targets (2026-07-01 evidence): 49
sandbox not found/7d → 0 for the binding-desync fraction; SendPrompt ack decoupled from the 12.2s-p50/89s-p95 resume; eaten follow-up messages → redelivered-until-acked.🤖 Generated with Claude Code
https://claude.ai/code/session_014jJi2vqAaxt3Q5UKxbe4Gx