Commit graph

5 commits

Author SHA1 Message Date
Ouroboros
acccf4c84d wip: integrate Processing transport, tier billing and account catalog consumers 2026-09-13 08:32:50 +03:00
Ouroboros
09ac51b2f0 acceptance packet / custody: durable omissions dispatch, custody-only settlement receipts, cross-process retirement lock, one packet budget
Fifth authoritative review: leading omissions and recaps with a durable
get_task_result reference are not_materialized_for_reviewer again (dispatchable,
non-resolving) — only source-less rows withhold the panel; contributor receipts
take agent-session settlement exclusively from the final custody replay, and a
missing or unreadable custody row is a typed mismatch instead of trusting the
response's self-report; the skill-history projection discloses rows scanned,
truncation, gap reasons and a canonical source, and an incomplete projection is
non-resolving; settlement publication and last-sibling retirement sit under a
stable project-digest file lock that holds across worker processes; the host's
late acceptance fields enter the packet builder before the single budget
enforcement; ARCHITECTURE names all four window-aware surfaces and documents
SETTLED before registration retirement. loop.py 282 903 bytes (−765). Manifest
untouched.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-04 03:21:07 +03:00
Ouroboros
5a06e06458 acceptance packet: empty-ref recaps abstain, narrow-route calibration honoured, settlement and retirement in one critical section
Fourth authoritative review: a recapped result or leading omission WITHOUT an
actor-readable source is now typed source_unavailable, so a zero-physical
acceptance abstains instead of passing through another resolving ref; the
240 000-character floor applies only when calibration is absent, failed or
non-positive, so a narrow route sheds the packet instead of being refused;
settle_run publishes SETTLED and takes the last-sibling retirement decision
inside one per-project critical section (two live concurrent settlements retire
exactly once); the root-task projection append scans the whole file under its
lock, so a retried identity after many newer rows is not duplicated (reads stay
bounded). delegate_custody.py stays at exactly 1 600 lines; manifest untouched.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-04 02:21:44 +03:00
Ouroboros
4a7fa18bee acceptance packet: partial sections never resolve, whole-record panel projection, bounded skill projection, serialized retirement
Third authoritative review (first with consistent receipts): a budget-truncated
repo_diff and a trajectory with omitted leading rows or recapped results were
still classified as resolving for API-only acceptance — both now carry explicit
incompleteness metadata and the vocabulary types them `partial`; the prompt
projection no longer ends in a hard slice — panels are projected as whole
records with an exact `records_omitted` count and the remainder goes through
disclosed truncation with a canonical `get_task_result` reference;
ARCHITECTURE/DEVELOPMENT map the new `state/skill_review_root_tasks.jsonl`
(producer, consumer, authority, retention, 20 MB threshold) and count seven hot
stores; the projection append is idempotent under a lock and acceptance reads it
newest-first, bounded (512 rows / 1 MiB, task-start cutoff); project retirement
is serialized by a striped per-project lock with custody re-read inside the
critical section (concurrent final siblings retire once); the shared trace
inventory recognises run_command/run_script with cwd=skill_payload and
delegate_start(root=skill_payload). delegate_custody.py stays at exactly 1 600
lines; manifest untouched (one regeneration at synthesis).

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-04 01:32:32 +03:00
Anton Razzhigaev
0724144f6b Persistent stable-target registrations survive settlement (#362, #364)
Ports the f9356572 A3 remediation onto the sharer-aware custody core: a run
that registers the user's STABLE target root (workspaceRoot-capable engine +
workspace_write) marks the registration project_persistent, and every retire
path — retire_project, settle summaries, the recovered-invocation refusal
path, the pending projection and the retry binding — honours the marker
instead of deleting the user's own project at settlement. The persistence
decision and the STARTED-row field tables live in a new policy leaf
(delegate_registration_policy.py): both delegate_custody.py and
tools/delegate.py sit exactly on the 1600-line gate, so the marker is paid
for by extraction (the deadline_expired helper also moves to its
deadline_utils family home, and registration resolution folds into the
policy leaf to keep _delegate_start under the function gate).

The "3.8.1" workspaceRoot floor moves from a subagents.py literal to the
config SSOT (CLAUDEXOR_DELEGATED_WORKSPACE_ROOT_MIN_VERSION), beside its
protocol/marker floor siblings.

#364 remainder: the replacement_requires_settlement refusal already existed;
its detail now names the live run/invocation ids and the retry_of escape
hatch, as the issue asks.

Regression tests: the registration survives retirement and settlement (with
replay carrying the marker), pending recovery retains the marker while a
plain owned record still retires, the persistence predicate, and the refusal
wording.
2026-08-31 13:17:36 +00:00