Skip to content

fix(sdk): run hosted Babysitter through canonical Software Garden - #586

Draft
kjgbot wants to merge 14 commits into
mainfrom
fix/software-garden-babysitter-canonical
Draft

kjgbot wants to merge 14 commits into
mainfrom
fix/software-garden-babysitter-canonical

Conversation

@kjgbot

@kjgbot kjgbot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Problem

Merged #585 exposes the capability sandbox helper, but a normal canonical Software Garden run never calls it. The ordinary authored executor imports extension code in the host and refuses the matched hosted handler, so the pinned installed Babysitter is still unreachable from the canonical run surface.

Change

  • add an embedded-only RunCliOptions.hostedSoftwareGardenBabysitter contract carrying host-verified dispatch authority plus the one queue capability
  • preflight the exact reviewed Software Garden base, complete lock-backed install, compatibility, and matched route before daemon admission or tenant import
  • admit one real relayflowd journal step and invoke the exact selected installed handler inside the existing Linux capability sandbox
  • journal the queue write with effect record/perform/atomic receipt/confirm and bind run admission to delivery plus exact base/plugin pins
  • recover an identical delivery as the same run and replay the durable receipt without a second queue write
  • recover a receipt persisted before a missing effect.confirm without calling the external provider again
  • preserve a recorded-but-unconfirmed effect when the external provider rejects or throws, so terminal failure matches the durable journal fact
  • defer a timeout's terminal protocol result until an uncancellable pending capability settles and its effect is accounted for
  • keep the canonical runner attached to its live hosted dispatch and classify the dispatch's actual journal outcome before returning
  • classify all post-admission errors as terminal journaled step failures; retain typed pre-admission plugin refusals
  • reject hosted authority on every other command/path surface and reject unsupported local-worker flags rather than ignoring them
  • keep sandbox executable overrides out of the public embedded contract
  • exclude .relayflowd control state from reviewed source hashing, as already done for .flows, .git, and node_modules
  • add deterministic inventory/type assertions and dynamic Linux/bubblewrap E2E coverage through runCli(["run", ...])

The E2E proves exact extension provenance and branded authority, expected queue request, real journal runId, terminal outcome, same-run retry, exactly one external capability call, timeout ordering, and receipt recovery at the receipt-written/confirm-missing crash boundary. Standalone CLI input cannot construct the non-serializable authority.

Dependency / current draft gate

This branch starts from merged #585 (86967b0ac8f1fc30062bb446d5583402e46117d0). It must be rebased onto the final approved/merged #584 SHA because #584 changes the reviewed Software Factory bytes and hosted base pin. Do not merge this draft before that rebase, exact-head Linux CI, and fresh independent review.

Exact-head evidence

Head: 0b241e7826651d158b0ca7706ec617d6560ea837

  • npm run typecheck: pass
  • npm run typecheck:tests: pass
  • npm run build: pass
  • npx vitest run tests/software-garden-babysitter-canonical-run.test.ts: 5 pass, 9 Linux-only skip on macOS
  • focused portable pending-timeout protocol regression: 1 pass
  • git diff --check: pass
  • exact-head Linux workflow 36497914934, job 109181694659: pass in 10m18s (canonical 14/14; hosted protocol 27/27; full SDK 219 files passed, 1 skipped; 3,528 tests passed, 4 skipped)
  • prior head 90ffb895570d8e115abb4b5d199f7f2795a0d938 Linux workflow 36495470184, attempt 2: pass (canonical 14/14; full SDK 219 files passed, 1 skipped; 3,527 tests passed, 4 skipped)
  • prior head fc105cdc59b9345a526f31634e1c727912a67d86 Linux workflow 36494014754: correctly proved the 25 ms test deadline expired during sandbox startup and exposed post-settlement frame processing; both the protocol race and test setup are fixed at this head
  • prior head 015fe9855bfd247f38c78398c55165d3947f7b05 Linux workflow 36492394714: correctly failed the new pending-timeout E2E because the CLI returned an intermediate classifier result; that observed gap is fixed at this head
  • prior head fa2e6d97623871397a47e15efe5c599a2ba80f5c Linux workflow 36479370405: pass before the two new durability regressions
  • full local npm test: unavailable because this host's mise Cargo shim is invalid (cargo is not a valid shim); the repository Linux workflow runs the full SDK suite

Review remediation

Preliminary independent review identified four findings: post-capability refusal misclassification, a synthetic non-journaled outcome, ignored local flags, and public sandbox binary overrides. All were fixed. A later Linux-only regression exposed the recorded-but-unconfirmed effect mismatch on provider rejection; that is fixed and covered. Independent exact-head review at fa2e6d then found two P1 durability gaps: terminal timeout before a pending capability settled, and a repeated provider call after receipt persistence but before confirmation. Both are fixed with focused dynamic regressions. The first Linux execution of the timeout regression then exposed a separate CLI-layer intermediate-return path; that is fixed at this head; fresh exact-head Linux is green and independent review is pending. A subsequent independent P1 found same-chunk terminal-plus-capability parsing; the parser now stops at each terminal frame boundary and a portable one-write regression proves zero post-terminal invokes. Independent review APPROVED exact head 0b241e7826651d158b0ca7706ec617d6560ea837 with no remaining code blocker and independently verified workflow 36497914934. A final fresh review is also required after the #584 rebase.

Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
@kjgbot

kjgbot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

maintainability lens — UNCLEAR

Not logged in · Please run /login

@kjgbot

kjgbot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

history lens — FAIL

Blocker:

  • packages/sdk/src/cli/direct-run.ts:73-125 turns the hosted path into a successful run by invoking runHostedSoftwareGardenBabysitter directly and returning a completion report before daemon attachment or any JournalClient interaction. packages/sdk/src/cli.ts:414-422 forwards that option into this bypass. This newly contradicts RFC-0001’s settled boundary: SDKs must speak the journal protocol and nothing may reach around it. The resulting capability effect has no durable run/attempt journal record. Because docs/BABYSITTER-CATALOG-HANDOFF.md:16-26 and :39-41 describe this as the intended canonical hosted run contract, this is not merely an unimplemented aspiration. Blocking deployment does not cure the architectural contradiction; the scaffold itself establishes the forbidden path.

Concerns:

Notes:

  • The recent history and DRIVE-LOG reveal no previously removed Babysitter/canonical-run pattern that this diff reintroduces.
  • The two commit subjects accurately describe their touched files and make no false test or evidence claims.

REVIEW_FAILED

@kjgbot

kjgbot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

structure lens — UNCLEAR

Error: Error from provider (Console): OpenCode's free tier can only be used from within OpenCode

@kjgbot

kjgbot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

🎯 review-swarm: FAILED (M:unclear H:fail S:unclear)

Lens transcripts posted as sibling comments above.

kjgbot added 12 commits September 28, 2026 12:23
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant