Conversation
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Contributor
Author
maintainability lens — UNCLEARNot logged in · Please run /login |
Contributor
Author
history lens — FAILBlocker:
Concerns:
Notes:
REVIEW_FAILED |
Contributor
Author
structure lens — UNCLEARError: Error from provider (Console): OpenCode's free tier can only be used from within OpenCode |
Contributor
Author
|
🎯 review-swarm: FAILED (M:unclear H:fail S:unclear) Lens transcripts posted as sibling comments above. |
added 12 commits
September 28, 2026 12:23
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
Session-Id: 01a0e943-46a7-7ad3-b4f8-8d5f31498018
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Merged #585 exposes the capability sandbox helper, but a normal canonical Software Garden
runnever calls it. The ordinary authored executor imports extension code in the host and refuses the matched hosted handler, so the pinned installed Babysitter is still unreachable from the canonical run surface.Change
RunCliOptions.hostedSoftwareGardenBabysittercontract carrying host-verified dispatch authority plus the one queue capabilityeffect.confirmwithout calling the external provider again.relayflowdcontrol state from reviewed source hashing, as already done for.flows,.git, andnode_modulesrunCli(["run", ...])The E2E proves exact extension provenance and branded authority, expected queue request, real journal
runId, terminal outcome, same-run retry, exactly one external capability call, timeout ordering, and receipt recovery at the receipt-written/confirm-missing crash boundary. Standalone CLI input cannot construct the non-serializable authority.Dependency / current draft gate
This branch starts from merged #585 (
86967b0ac8f1fc30062bb446d5583402e46117d0). It must be rebased onto the final approved/merged #584 SHA because #584 changes the reviewed Software Factory bytes and hosted base pin. Do not merge this draft before that rebase, exact-head Linux CI, and fresh independent review.Exact-head evidence
Head:
0b241e7826651d158b0ca7706ec617d6560ea837npm run typecheck: passnpm run typecheck:tests: passnpm run build: passnpx vitest run tests/software-garden-babysitter-canonical-run.test.ts: 5 pass, 9 Linux-only skip on macOSgit diff --check: pass109181694659: pass in 10m18s (canonical 14/14; hosted protocol 27/27; full SDK 219 files passed, 1 skipped; 3,528 tests passed, 4 skipped)90ffb895570d8e115abb4b5d199f7f2795a0d938Linux workflow 36495470184, attempt 2: pass (canonical 14/14; full SDK 219 files passed, 1 skipped; 3,527 tests passed, 4 skipped)fc105cdc59b9345a526f31634e1c727912a67d86Linux workflow 36494014754: correctly proved the 25 ms test deadline expired during sandbox startup and exposed post-settlement frame processing; both the protocol race and test setup are fixed at this head015fe9855bfd247f38c78398c55165d3947f7b05Linux workflow 36492394714: correctly failed the new pending-timeout E2E because the CLI returned an intermediate classifier result; that observed gap is fixed at this headfa2e6d97623871397a47e15efe5c599a2ba80f5cLinux workflow 36479370405: pass before the two new durability regressionsnpm test: unavailable because this host'smiseCargo shim is invalid (cargo is not a valid shim); the repository Linux workflow runs the full SDK suiteReview remediation
Preliminary independent review identified four findings: post-capability refusal misclassification, a synthetic non-journaled outcome, ignored local flags, and public sandbox binary overrides. All were fixed. A later Linux-only regression exposed the recorded-but-unconfirmed effect mismatch on provider rejection; that is fixed and covered. Independent exact-head review at
fa2e6dthen found two P1 durability gaps: terminal timeout before a pending capability settled, and a repeated provider call after receipt persistence but before confirmation. Both are fixed with focused dynamic regressions. The first Linux execution of the timeout regression then exposed a separate CLI-layer intermediate-return path; that is fixed at this head; fresh exact-head Linux is green and independent review is pending. A subsequent independent P1 found same-chunk terminal-plus-capability parsing; the parser now stops at each terminal frame boundary and a portable one-write regression proves zero post-terminal invokes. Independent review APPROVED exact head0b241e7826651d158b0ca7706ec617d6560ea837with no remaining code blocker and independently verified workflow36497914934. A final fresh review is also required after the #584 rebase.