Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
179 commits
Select commit Hold shift + click to select a range
d14a8f4
feat(fleet): add exact cleanroom lifecycle controls
Sep 5, 2026
13ec18c
test(cleanroom): add exhaustive relay qualification workflows
Sep 5, 2026
bbea6e7
chore: refresh cleanroom lockfile on 11.10.3
Sep 5, 2026
3069380
test(cleanroom): bind fleet board to 11.10.3
Sep 5, 2026
5572e47
fix(ci): satisfy qualification dependency engine floor
Sep 5, 2026
7e15d52
docs(cleanroom): seal Relay prerelease proof
Sep 5, 2026
341a91b
style: auto-format with Prettier
github-actions[bot] Sep 5, 2026
528ecb2
fix(qualification): harden candidate evidence reads
Sep 5, 2026
23e0202
fix(deps): require patched undici
Sep 5, 2026
a4f9a02
fix(qualification): eliminate no-follow fallback race
Sep 5, 2026
d0094b7
test(pr-proof): prove immutable Fleet snapshot binding
Sep 5, 2026
ca5cda0
test(fleet): harden cleanroom acceptance proof
Sep 5, 2026
40e758c
fix(broker): require applied receipt for set-model
Sep 5, 2026
dcc6738
fix(broker): close model receipt races
Sep 5, 2026
4f827cf
feat(broker): confirm OpenCode model switches
Sep 5, 2026
c569d63
fix(qualification): harden Fleet proof boundaries
Sep 5, 2026
010d99e
fix(fleet): expose truthful model receipts in CLI
Sep 5, 2026
69f9b81
test(relayflow): prove model receipt JSON contract
Sep 5, 2026
4feef65
test(relayflow): bind receipt probe to exact checkout
Sep 5, 2026
96dad50
fix(qualification): parse semver without backtracking
Sep 5, 2026
56cceb1
fix(fleet): close model receipt review gaps
Sep 5, 2026
8c5c480
chore(trail): record model receipt review work
Sep 5, 2026
0a99096
fix(fleet): preserve confirmed model across receipt races
Sep 5, 2026
a01486e
chore(trail): record model receipt race fix
Sep 5, 2026
9dc952c
style: auto-format with Prettier
github-actions[bot] Sep 5, 2026
0dc0039
test(fleet): make receipt proof checks deterministic
Sep 5, 2026
b162a13
chore(trail): record deterministic proof checks
Sep 5, 2026
f3d7d4a
fix(qualification): close proof boundary review gaps
Sep 5, 2026
681f688
test(relayflow): avoid polling-only proof transport timeout
Sep 5, 2026
ba7f953
chore(trail): record proof transport adjustment
Sep 5, 2026
a8cd49c
fix: close model receipt review gaps
Sep 5, 2026
7e634b9
chore(trail): finalize receipt review trajectory
Sep 5, 2026
aceb06c
style: auto-format with Prettier
github-actions[bot] Sep 5, 2026
4d127c6
fix: retain correlated model receipts by request
Sep 5, 2026
7f17b09
fix(cleanroom): close fresh review gaps
Sep 5, 2026
1c2d7cd
test: cover request-specific model receipts
Sep 5, 2026
bb9b4ea
test: make receipt proof request-driven
Sep 5, 2026
c100caf
fix: narrow optional receipt request id
Sep 5, 2026
d66f4b2
fix: prune request receipts on worker release
Sep 5, 2026
6f0b971
fix: reject unknown model receipt lookups
Sep 5, 2026
7dfe5d7
fix: unblock asynchronous receipt proof
Sep 5, 2026
95a79dc
fix(qualification): harden evidence transport boundaries
Sep 5, 2026
bcd1b23
fix: harden model receipt lifecycle and polling
Sep 5, 2026
0acfd21
test: close model receipt review gaps
Sep 5, 2026
ac4ebaa
fix(cleanroom): close qualification review gaps
Sep 5, 2026
e20f555
fix: fence queued model receipts on release
Sep 5, 2026
688a86f
test: retain receipt when relaycast releases worker
Sep 5, 2026
28979c5
test: prove model receipts through broker
Sep 5, 2026
8da1796
fix: close model receipt phase races
Sep 5, 2026
5c1792e
test: wait for child exit during receipt reap
Sep 5, 2026
9614963
fix(cli): reconcile ambiguous Cloud workspace creates
Sep 5, 2026
1539f1c
test(relayfile): tolerate full-suite process contention
Sep 5, 2026
653c583
fix: preserve queued frames and qualify pty receipts
Sep 5, 2026
040b334
fix: retain and fence late model receipts
Sep 5, 2026
5584164
ci(relayflow): retain terminal Cloud failure evidence
Sep 5, 2026
44bafb3
fix: preserve app-server protocol diagnostics
Sep 5, 2026
bd25d6c
fix: tighten correlated model receipts
Sep 5, 2026
72a00db
test: prove model receipt with live opencode
Sep 5, 2026
8f32db6
test: bound proof readiness polling
Sep 5, 2026
b753b9f
test: prove AppServer model receipts on Fleet nodes
Sep 5, 2026
fec6781
docs: update Fleet qualification counts
Sep 5, 2026
03bd687
fix: run Fleet proof helper as async script
Sep 5, 2026
983765d
fix: timestamp model receipts at worker receive
Sep 6, 2026
3359f57
docs: clarify pending provider confirmation
Sep 6, 2026
081d858
style: auto-format with Prettier
github-actions[bot] Sep 6, 2026
b3d5c6b
fix: preserve queued model receipts and nested argv
Sep 6, 2026
65df4b8
style: auto-format with Prettier
github-actions[bot] Sep 6, 2026
0f0daa2
fix: fence expiry while receipts are queued
Sep 6, 2026
9956aaa
fix: keep maintenance alive after worker shutdown
Sep 6, 2026
085c71a
chore: record blocked Daytona campaign
Sep 6, 2026
4e62566
chore: record blocked Relaycast campaign retry
Sep 6, 2026
77a5623
fix: bound queued worker receipt draining
Sep 6, 2026
bb72035
chore: clarify bounded worker drain
Sep 6, 2026
fff6aba
fix: parse complete model receipt JSON
Sep 6, 2026
66e6eb6
fix: parse multiline Fleet model receipts
Sep 6, 2026
694020b
test: parse multiline model proof receipts
Sep 6, 2026
3ea4356
test: exercise queued receipt maintenance drain
Sep 6, 2026
b88825a
fix: preserve receipts across worker teardown
Sep 6, 2026
a227a75
Merge base qualification updates into model receipt
Sep 6, 2026
c7be1f1
type accepted pending model responses
Sep 6, 2026
dd6559b
bound provider proof teardown
Sep 6, 2026
5aa3f07
prove provider session cleanup
Sep 6, 2026
6dea24e
sync Fleet inventory with set-model JSON
Sep 6, 2026
047881d
sync Fleet qualification documentation
Sep 6, 2026
44b91cf
style: auto-format with Prettier
github-actions[bot] Sep 6, 2026
252159f
stabilize model receipt teardown regressions
Sep 6, 2026
0155f96
feat(cli): expose typed headless app-server spawn
Sep 6, 2026
163eb48
test(relayflow): preserve primary proof failures during cleanup
Sep 6, 2026
5308b59
test(fleet): fail cleanup gate on release errors
Sep 6, 2026
cf52654
docs: describe headless app-server spawn options
Sep 6, 2026
3a0edda
feat(fleet): add exact cleanroom lifecycle controls
Sep 5, 2026
5409a1b
test(cleanroom): add exhaustive relay qualification workflows
Sep 5, 2026
e5cdac7
chore: refresh cleanroom lockfile on 11.10.3
Sep 5, 2026
cfd8059
test(cleanroom): bind fleet board to 11.10.3
Sep 5, 2026
9cd7378
fix(ci): satisfy qualification dependency engine floor
Sep 5, 2026
af6a23d
docs(cleanroom): seal Relay prerelease proof
Sep 5, 2026
d3536e5
style: auto-format with Prettier
github-actions[bot] Sep 5, 2026
33b74ef
fix(qualification): harden candidate evidence reads
Sep 5, 2026
7d2db79
fix(deps): require patched undici
Sep 5, 2026
56cbd86
fix(qualification): eliminate no-follow fallback race
Sep 5, 2026
b9bd807
test(pr-proof): prove immutable Fleet snapshot binding
Sep 5, 2026
6231039
test(fleet): harden cleanroom acceptance proof
Sep 5, 2026
d46d260
fix(qualification): harden Fleet proof boundaries
Sep 5, 2026
d6f6fdf
fix(qualification): parse semver without backtracking
Sep 5, 2026
f49fff8
fix(qualification): close proof boundary review gaps
Sep 5, 2026
2447d10
fix(cleanroom): close fresh review gaps
Sep 5, 2026
ffee2ef
fix(qualification): harden evidence transport boundaries
Sep 5, 2026
2dcba14
fix(cleanroom): close qualification review gaps
Sep 5, 2026
5c6f303
fix(cli): reconcile ambiguous Cloud workspace creates
Sep 5, 2026
75f7969
test(relayfile): tolerate full-suite process contention
Sep 5, 2026
3551c34
ci(relayflow): retain terminal Cloud failure evidence
Sep 5, 2026
fb8a50d
Harden PR 1665 Fleet qualification evidence
Sep 6, 2026
a81f8d4
test(cli): include deferred Fleet commands in inventory
Sep 6, 2026
7b1cd73
fix(qualification): canonicalize Linux candidate npm cwd
Sep 6, 2026
87c8df1
fix(qualification): normalize artifact action digests
Sep 6, 2026
9362d9b
test(qualification): retire inert bootstrap invariant
Sep 6, 2026
040c876
fix(qualification): avoid shell for descriptor-bound npm
Sep 6, 2026
3d293ae
fix: harden cleanroom qualification evidence
Sep 6, 2026
40d25a8
test: serve fleet snapshot proof over TLS
Sep 6, 2026
439b956
test: bound fleet proof TLS fixture setup
Sep 6, 2026
c02e752
test(qualification): require distinct mount correlations
Sep 6, 2026
11e959b
fix(qualification): deliver Cloud producer request
Sep 6, 2026
0982e45
fix(qualification): isolate Cloud dispatch token
Sep 6, 2026
30bdf3a
test(qualification): require producer steps to exist
Sep 6, 2026
3bd1e65
fix(workflows): allow scoped model transport
Sep 6, 2026
a513062
test(fleet): reconcile identity views around release
Sep 6, 2026
2ca44fd
fix(pr-proof): keep failure redaction dependency-free
Sep 6, 2026
6a8cb81
fix(qualification): close cleanroom review gaps
Sep 6, 2026
b69e2cf
fix(pr-proof): fully mask declared credentials
Sep 6, 2026
0242dde
fix(pr-proof): bound redacted fallback output
Sep 6, 2026
2f48e19
fix(qualification): harden current-head reliability gates
Sep 6, 2026
275e862
fix: harden cleanroom candidate preflight
Sep 6, 2026
91c3d1f
fix: isolate qualification retries and diagnostics
Sep 6, 2026
a8e7a80
fix(qualification): close remaining cleanroom races
Sep 6, 2026
6836e84
fix(qualification): settle exact-head review findings
Sep 6, 2026
db7a601
fix(harnesses): update vulnerable Pi closure
Sep 6, 2026
bf0f0cf
fix(qualification): fail closed on retained handles
Sep 6, 2026
cec4e36
fix: close cleanroom qualification timeout gaps
Sep 6, 2026
a9a0d4a
test: account for cleanroom retry budgets
Sep 6, 2026
b2c7329
test: close qualification review gaps
Sep 6, 2026
dd53af6
test: close fresh qualification review gaps
Sep 6, 2026
63d722c
docs: align historical Fleet board count
Sep 6, 2026
51e5951
fix: close stale qualification workflow gaps
Sep 6, 2026
1be9fae
docs: drop a changelog bullet duplicated by the rebase
Sep 6, 2026
246a320
fix(cloud): keep symlinks inside the compiled permission model
Sep 7, 2026
6e28d23
fix(cloud): deny project symlinks instead of dropping or granting them
Sep 7, 2026
3c25cf0
fix(verify-fleet-daytona): install exact deps before building
Sep 7, 2026
a339d0d
Merge main into model receipt branch and preserve qualification templ…
miyaontherelay Sep 7, 2026
ffe3879
fix(cli): keep headless AppServer spawns truthful
Sep 6, 2026
8df22ae
fix(broker): let AppServer wrappers finish provider cleanup before fo…
Sep 6, 2026
77b4c56
fix(fleet): harden the AppServer model proof and its evidence gate
Sep 6, 2026
533d0be
fix(gates): derive diagnosis coverage row count and resync cleanroom …
Sep 6, 2026
9109e6a
fix(broker): keep OpenCode model receipts truthful under uncertainty
Sep 6, 2026
8125747
fix(broker): close model-receipt drain races at decision time
Sep 6, 2026
57bf615
fix(cli): drop dead headless guard in agent new
Sep 6, 2026
2a23cf6
test(fleet): keep Daytona board fixtures honest at 96 operations
Sep 6, 2026
f956738
style: auto-format with Prettier
Sep 6, 2026
5736ccd
fix(fleet): reconcile stacked base and finish model receipt review fixes
miyaontherelay Sep 7, 2026
9d47479
style: auto-format with Prettier
github-actions[bot] Sep 7, 2026
5af3b9c
Merge remote-tracking branch 'github/main' into fix/1666-review-0907
miyaontherelay Sep 7, 2026
4b52640
Merge remote-tracking branch 'github/main' into fix/1665-sync-startup…
miyaontherelay Sep 7, 2026
95410a9
Merge branch 'fix/1665-sync-startup-retry' into fix/1666-review-0907
miyaontherelay Sep 7, 2026
65d6660
fix: align fleet candidate relayflows dependencies
Sep 8, 2026
3d54dcc
test: cover Fleet qualification options
Sep 8, 2026
26b1801
test: harden Fleet option evidence fixtures
Sep 8, 2026
961747e
test: prove local Fleet connection options
Sep 8, 2026
3289f92
Merge remote-tracking branch 'origin/main' into fix/pr1666-fleet-cand…
Sep 8, 2026
db1ec95
test(fleet): prove node spawn options in cleanroom
Sep 8, 2026
436b981
fix(fleet-daytona): close credential-redaction prefix and GitHub-toke…
Sep 8, 2026
625c7f9
test(fleet): expand Daytona option and cleanup proof
Sep 8, 2026
ad0fb86
fix(fleet): close cleanroom cleanup and qualification gaps
Sep 8, 2026
8abbb20
fix(fleet): close four adversarial redaction and proof-integrity gaps
Sep 8, 2026
5dab3d1
fix(fleet): redact streaming evidence before truncation
Sep 8, 2026
ee29c3d
fix(fleet): make bounded evidence redaction chunk-safe
Sep 8, 2026
8aeb756
fix(fleet): sanitize error tails and preserve UTF-8 evidence
Sep 8, 2026
0c34492
Merge remote-tracking branch 'origin/main' into fix/pr1666-fleet-cand…
Sep 8, 2026
e3c4d34
test(fleet): prove set-model through real CLI path
Sep 9, 2026
c020928
test(fleet): remove Node 24 truncation timing flake
Sep 9, 2026
a664c05
fix(fleet): harden model receipt correlation
Sep 9, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
# Trajectory: Fix PR 1666 Node 24 truncation fixture flake

> **Status:** ✅ Completed
> **Task:** relay#1666
> **Confidence:** 97%
> **Started:** September 9, 2026 at 06:53 AM
> **Completed:** September 9, 2026 at 06:54 AM

---

## Summary

Removed scheduler sensitivity from the Node 24 Fleet evidence-bound fixture while preserving exact byte-count and truncation assertions.

**Approach:** Standard approach

---

## Key Decisions

### Make the large UTF-8 bound fixture a single-write payload
- **Chose:** Make the large UTF-8 bound fixture a single-write payload
- **Reasoning:** The adjacent test already verifies one-byte decoder splitting; repeating 36,000 setImmediate callbacks made the independent truncation assertion depend on CI scheduler pressure under Node 24.

---

## Chapters

### 1. Work
*Agent: default*

- Make the large UTF-8 bound fixture a single-write payload: Make the large UTF-8 bound fixture a single-write payload
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
{
"id": "traj_1yn3l0r7vj9m",
"version": 1,
"task": {
"title": "Fix PR 1666 Node 24 truncation fixture flake",
"source": {
"system": "plain",
"id": "relay#1666"
}
},
"status": "completed",
"startedAt": "2026-09-09T04:53:11.163Z",
"completedAt": "2026-09-09T04:54:37.845Z",
"agents": [
{
"name": "default",
"role": "lead",
"joinedAt": "2026-09-09T04:54:37.418Z"
}
],
"chapters": [
{
"id": "chap_ze0ogqtktw4a",
"title": "Work",
"agentName": "default",
"startedAt": "2026-09-09T04:54:37.418Z",
"endedAt": "2026-09-09T04:54:37.845Z",
"events": [
{
"ts": 1788929677419,
"type": "decision",
"content": "Make the large UTF-8 bound fixture a single-write payload: Make the large UTF-8 bound fixture a single-write payload",
"raw": {
"question": "Make the large UTF-8 bound fixture a single-write payload",
"chosen": "Make the large UTF-8 bound fixture a single-write payload",
"alternatives": [],
"reasoning": "The adjacent test already verifies one-byte decoder splitting; repeating 36,000 setImmediate callbacks made the independent truncation assertion depend on CI scheduler pressure under Node 24."
},
"significance": "high"
}
]
}
],
"retrospective": {
"summary": "Removed scheduler sensitivity from the Node 24 Fleet evidence-bound fixture while preserving exact byte-count and truncation assertions.",
"approach": "Standard approach",
"confidence": 0.97
},
"commits": [],
"filesChanged": [],
"projectId": "AgentWorkforce/relay",
"tags": [],
"_trace": {
"startRef": "e3c4d340b5f4bb817f2273a51d0cb71e0e781a31",
"endRef": "e3c4d340b5f4bb817f2273a51d0cb71e0e781a31"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,143 @@
# Trajectory: diagnose-relay-orchestration-reliability-workflow

> **Status:** ✅ Completed
> **Task:** cdbfa60e5594b06da6af46ef
> **Confidence:** 95%
> **Started:** September 4, 2026 at 10:37 PM
> **Completed:** September 8, 2026 at 05:01 PM

---

## Summary

Repaired Fleet Daytona cleanroom candidate: final cleanup now rejects all remaining Fleet node records and inspects every returned node, configured credentials of any nonempty length are redacted, and live runs fail early without explicit immutable snapshot qualification inputs. Added offline/stale, secret-boundary, root-mount argv, and live-prerequisite tests; validation, dry-run, focused and broader fixtures, typecheck, lint, Prettier, and diff checks pass.

**Approach:** Standard approach

---

## Key Decisions

### Qualification uses deterministic harnesses as the authoritative gate and model agents only for evidence review/signoff
- **Chose:** Qualification uses deterministic harnesses as the authoritative gate and model agents only for evidence review/signoff
- **Reasoning:** The campaign is intended to expose flaky orchestration. A model verdict cannot substitute for exact baseline-fail, packed-candidate-pass, observed runtime identities, and resource-absence evidence.

### Count Fleet spawn confirmation as provisional, not proof
- **Chose:** Count Fleet spawn confirmation as provisional, not proof
- **Reasoning:** Invocation inv_221926944412856320 returned confirmed/spawned true, then launcher cleanup failed and authoritative node inventory showed zero agents; qualification must require node-associated live presence plus PID/work product.

### Replaced registry-byte equality for source packages with a portable source-bound Linux candidate closure
- **Chose:** Replaced registry-byte equality for source packages with a portable source-bound Linux candidate closure
- **Reasoning:** A real npm pack proved @agent-relay/sdk source tarballs cannot byte-equal published multi-platform release tarballs; qualification must upload and consume the exact candidate tarballs produced from the Relay SHA, while retaining registry integrity only for external protocol packages.

### Fail closed before Cloud workspace POST until bound deployment idempotency and reconciliation APIs ship
- **Chose:** Fail closed before Cloud workspace POST until bound deployment idempotency and reconciliation APIs ship
- **Reasoning:** Current deployed Cloud ignores the unknown relayfileCloudDeploymentId field, can create a workspace, then the candidate CLI rejects the unbound reveal-once response and loses the only cleanup identity, guaranteeing orphan risk.

### Fail closed on mutable Cloud evidence and queue-only set-model acknowledgements
- **Chose:** Fail closed on mutable Cloud evidence and queue-only set-model acknowledgements
- **Reasoning:** Qualification cannot claim end-to-end behavior when evidence can be overwritten or when the CLI proves only enqueueing instead of downstream application.

### Treat node agent set-model as queue admission until a provider-correlated receipt proves application
- **Chose:** Treat node agent set-model as queue admission until a provider-correlated receipt proves application
- **Reasoning:** Current broker response is accepted=true pending=true and every runtime lacks a request ID plus provider-confirmed effective-model state; the Fleet gate must fail closed rather than relabel a PTY write as application.

### Changed the Relay package producer from every main push to a manual main-only prerelease run
- **Chose:** Changed the Relay package producer from every main push to a manual main-only prerelease run
- **Reasoning:** The candidate gate must prove source packages are both prerelease and unpublished; attaching it to ordinary main pushes makes already-published stable versions fail by construction.

### Kept clean-install proof separate from live Fleet acceptance
- **Chose:** Kept clean-install proof separate from live Fleet acceptance
- **Reasoning:** Two Daytona sandboxes proved the exact Relay candidate package, broker digest, attestation, CLI surface, tests, and cleanup, but Cloud issues 3349/3351 still prevent binding the 95-operation Fleet board to an immutable candidate workspace and Relayfile data plane.

### Make exact candidate-bound two-node Fleet qualification the sole release gate
- **Chose:** Make exact candidate-bound two-node Fleet qualification the sole release gate
- **Reasoning:** The 95-operation harness is structurally sound, but production-snapshot fallback cannot prove the candidate. Cloud #3351 must land before any Fleet GREEN verdict.

### Fail closed when O_NOFOLLOW is unavailable
- **Chose:** Fail closed when O_NOFOLLOW is unavailable
- **Reasoning:** Qualification evidence must never use an lstat-then-open fallback because it leaves a symlink swap race; the Fleet/cleanroom acceptance environment is Linux and supported macOS hosts expose O_NOFOLLOW.

### Hardened Fleet release gate to require 95 operations plus five lifecycle trials per attempt
- **Chose:** Hardened Fleet release gate to require 95 operations plus five lifecycle trials per attempt
- **Reasoning:** A catalog-only pass cannot prove targeted placement, agent responsiveness, release absence, same-name reuse, or exact candidate binaries under repeated clean Daytona execution.

### Fail closed on qualification provenance inputs and constrain preflight egress
- **Chose:** Fail closed on qualification provenance inputs and constrain preflight egress
- **Reasoning:** Fresh PR review found exploitable symlink/path/ref boundary gaps and unrestricted model preflight networking. The qualification must reject ambiguous provenance instead of weakening its clean-room gate.

### Reviewed required repo and workflow skills; using a dedicated worktree and feature branch
- **Chose:** Reviewed required repo and workflow skills; using a dedicated worktree and feature branch
- **Reasoning:** Resident root contains unrelated dirty trajectory/tool files and must remain untouched; PR review requires isolated edits and tracked trajectory evidence.

### Require explicit qualification inputs for live Fleet runs and bind snapshot args to root-mount intent
- **Chose:** Require explicit qualification inputs for live Fleet runs and bind snapshot args to root-mount intent
- **Reasoning:** The 108-operation matrix requires immutable snapshot tokens for fleet-spawn-sandbox-root-mount, and no safe provider defaults exist; failing before workspace access keeps standalone behavior honest while the qualification workflow remains compatible.

### Treat any final Fleet node record as cleanup residue and inspect every returned node
- **Chose:** Treat any final Fleet node record as cleanup residue and inspect every returned node
- **Reasoning:** Baseline qualification requires zero Fleet node records, so offline/stale records must fail rather than be skipped by an online-only inventory loop.

---

## Chapters

### 1. Planning
*Agent: orchestrator*

### 2. Execution: lead-coordinate, cloud-diagnosis, relayfile-diagnosis, data-plane-diagnosis, static-gates
*Agent: orchestrator*

### 3. Execution: lead-coordinate
*Agent: lead*

### 4. Execution: cloud-diagnosis
*Agent: cloud-specialist*

### 5. Execution: relayfile-diagnosis
*Agent: relayfile-specialist*

### 6. Execution: data-plane-diagnosis
*Agent: data-plane-specialist*

### 7. Execution: relayfile-diagnosis
*Agent: relayfile-specialist*

### 8. Execution: data-plane-diagnosis
*Agent: data-plane-specialist*

### 9. Execution: data-plane-diagnosis
*Agent: data-plane-specialist*

### 10. Execution: relayfile-diagnosis
*Agent: relayfile-specialist*

### 11. Execution: cloud-diagnosis
*Agent: cloud-specialist*

- Expanded Relay reliability campaign from diagnostic coverage to gated fix-and-proof program under resident Chief: three fix trains are active, Fleet cross-node supervision is being established, and completion requires baseline-fail/candidate-pass clean-install evidence plus dual fresh review.
- Qualification uses deterministic harnesses as the authoritative gate and model agents only for evidence review/signoff: Qualification uses deterministic harnesses as the authoritative gate and model agents only for evidence review/signoff
- Chief spawned three cross-node leads, but the initial local-only brief handoff and subsequent recipient resolution/remote attach failures blocked real work; preserved these as Fleet defects, moved the exact brief into a Relay channel message, and required Chief to verify real PTYs before counting agents. Relay focused qualification gates are green; 258 MiB source Workerd gate is green but baseline and packed-candidate proofs remain missing.
- Count Fleet spawn confirmation as provisional, not proof: Count Fleet spawn confirmation as provisional, not proof
- Replaced registry-byte equality for source packages with a portable source-bound Linux candidate closure: Replaced registry-byte equality for source packages with a portable source-bound Linux candidate closure
- Deterministic qualification is exposing real gaps: Fleet spawn success without a resident agent, DM recipient resolution failure for an existing worker, response-reset data loss in the 258 MiB candidate, and stale provenance/scheduling/idempotency assumptions. Full-tree candidate hashing and portable tarball closure are now locally green; cross-repo consumption and live cleanroom proof remain open.
- Fail closed before Cloud workspace POST until bound deployment idempotency and reconciliation APIs ship: Fail closed before Cloud workspace POST until bound deployment idempotency and reconciliation APIs ship
- Fresh review converted apparent near-green gates into concrete blockers: transitive npm closure was not locked, 258 MiB acceptance used the wrong one-file workload, Cloud candidate binding could orphan workspaces, and fixed producer semantics were incomplete. Root safety gates now fail closed while exact producer and workload proofs are being strengthened.
- Fail closed on mutable Cloud evidence and queue-only set-model acknowledgements: Fail closed on mutable Cloud evidence and queue-only set-model acknowledgements
- Harness and dry-run gates are green, but live certification remains blocked by Relayflows sandbox source/ID propagation, Cloud write-once storage, set-model application receipts, and Relayfile Cloud/Fleet-path binding.
- Treat node agent set-model as queue admission until a provider-correlated receipt proves application: Treat node agent set-model as queue admission until a provider-correlated receipt proves application
- Changed the Relay package producer from every main push to a manual main-only prerelease run: Changed the Relay package producer from every main push to a manual main-only prerelease run
- Static and dry-run harness gates are green, but live qualification remains blocked by Cloud candidate binding/write-once evidence and version-skewed Fleet nodes; generic deletion evidence was hardened to exact target IDs plus GET 404.
- Kept clean-install proof separate from live Fleet acceptance: Kept clean-install proof separate from live Fleet acceptance
- Relay package lane is sealed; Relayflows review correctly stopped promotion on deeper shared-environment and provenance defects; set-model review stopped an unsupported/no-op implementation.
- Make exact candidate-bound two-node Fleet qualification the sole release gate: Make exact candidate-bound two-node Fleet qualification the sole release gate
- Fleet critical path is now Cloud atomic workspace binding -> exact candidate snapshot -> two clean Daytona nodes -> all 95 operations twice -> lifecycle/teardown proof -> independent reviews.
- Fail closed when O_NOFOLLOW is unavailable: Fail closed when O_NOFOLLOW is unavailable
- Hardened Fleet release gate to require 95 operations plus five lifecycle trials per attempt: Hardened Fleet release gate to require 95 operations plus five lifecycle trials per attempt
- Fleet proof code and deterministic gates are integrated and locally green; live candidate campaign remains gated by Cloud candidate-bound ephemeral workspaces, Relaycast crash-idempotency, and Relayfile 258 MiB acceptance.
- Fleet qualification normal CI is green, but immutable PR proof exposed Cloud sandbox_router_no_provider before allocation. Hardened verifier against 30+ review findings, preserved strict clean-workspace baseline, and added pre-spawn absence checks for reused lifecycle identities. Cloud, Relaycast, Relayfile, and set-model repairs are proceeding on isolated branches; live candidate proof remains intentionally RED until those land in a prerelease snapshot.
- Fail closed on qualification provenance inputs and constrain preflight egress: Fail closed on qualification provenance inputs and constrain preflight egress
- Reviewed required repo and workflow skills; using a dedicated worktree and feature branch: Reviewed required repo and workflow skills; using a dedicated worktree and feature branch
- Fresh PR #1665 review findings are repaired in an isolated feature worktree: descriptor-pinned candidate output, complete symlink provenance, structural policy and wiring regressions, per-lane Cloud agents, reviewer-owned sandbox provenance, and prerelease-only release trigger. Focused and full Vitest/typecheck/format checks are green; hosted E2E and Cloud proof failures were external runtime availability failures.
- Require explicit qualification inputs for live Fleet runs and bind snapshot args to root-mount intent: Require explicit qualification inputs for live Fleet runs and bind snapshot args to root-mount intent
- Treat any final Fleet node record as cleanup residue and inspect every returned node: Treat any final Fleet node record as cleanup residue and inspect every returned node
Loading
Loading