Skip to content

feat(managed-agent): Close the H0c review follow-ups deferred from #12855 #13300

Description

@wenshao

What would you like to be added?

This issue collects the findings from the review of #12855 (H0c of #12827) that were still unhandled when the PR merged: the Suggestion-level pair from round 2 (R2-1, R2-2) and the twelve findings the round-3 review posted after the merge (R3-1 through R3-12, of which three are Critical). Every item was re-checked against main at d697f98553 on 2026-10-03 and still stands at the time of filing.

The fix lands as three follow-up PRs, grouped so that no two PRs touch the same file. Each thread gets an individual reply and is resolved once its fix merges.

PR 1 — the three Critical findings

  1. R3-1 — the Broker-record execution mapping ignores dispatchGeneration (thread). executionOf maps a SETTLED/cancelled record whose own Broker ledger proves it was never claimed (dispatchGeneration == 0) to settled, producing the intent -> settled step the H0b record contract refuses and leaving a Monitor cancelled before dispatch with no committable settling revision. Fix: give the mapping the record's dispatchGeneration, map that case to not_started_proven in both languages through a shared brokerExecutionCases row, record the wire-reading divergence, and reconcile Decision 10 of the authority doc with the record-contract doc.
  2. R3-2 — apply semantically validates only the one body-bearing line (thread). Every other event line, every unrecognised subtype, and every domain.committed line with an unregistered body is stored after no check beyond JSON well-formedness, while the authority's reopen reader validates all of them and refuses the Session — so one bad line bricks a Session at the next open with no error at commit time. Fix: run the event-level half of requireEnvelope for every event line, mirror the event-kind and subtype vocabularies, validate domain.committed domains whether or not a body is registered, mirror the reserved <domain>:<n> namespace, count Stage H lines instead of flagging, and put the per-kind byte caps in the shared limits contract.
  3. R3-3 — task.updated lands in the message-projection sequence space (thread). The announcement rides the same public Session event sequence a turn's text deltas use, and both consumers decide "continues the previous Part" by reading the event at sequence - 1, so one announcement between two deltas splits an assistant message into two stored, durable Parts under a frozen projection version. Fix: carry task.updated on its own outbox written in the same transaction, drained by the slice that serves task events, keeping managed_agent_event to turn and lifecycle events.

PR 2 — cross-language contract pins and TypeScript semantics

  • R2-1 — the changes-after-it-ended reject case is decided by the fixed-key rule, not the terminal rule its id names (thread).
  • R2-2 — the twelve shared reject cases pin only the error class, not the "refused before publishing" invariant (thread).
  • R3-4 — the shared projection fixture has no meta-pins (contract version, list names/emptiness, key sets) in either language (thread).
  • R3-5 — commitExtensionRecord publishes the record body before validating the actor class and the caller-supplied input, so a refused commit leaves an orphan body per retry (thread).
  • R3-7 — the projection hand-copies the terminal run-state list and its runtimeState clause order and settled-time clamp are unwitnessed (thread).
  • R3-8 — nothing observes the grant gate after a replacement, a renewal, a refusal, or a revocation that precedes its grant, and revoke's revision ceiling disagrees with install's (thread).
  • R3-12 — rebuildExtensionRecords decides whether a committed body is a Stage H record from the live body registry alone, and the reopen path re-validates already-parsed operands with serial resource reads (thread).

PR 3 — Java test efficacy, design docs, OpenAPI surface

  • R3-6 — a family of new Java assertions cannot fail (unfalsifiable journal_tx legs and MySQL re-read projection, re-typed EXPLAIN, driftable anchors, compile-time-constant pins) (thread).
  • R3-9 — the H0c design doc names error codes the store never answers, pins its survey to a stale commit, and over-claims guarantees (thread).
  • R3-10 — the H0a task-contract and H0b record-contract docs still state as present truth what H0c falsified (planned flags, future-tense H0c, unanswered open questions, superseded acceptance criteria) (thread).
  • R3-11 — the four task routes flipped to partial keep three false promises (five-source merge description, impossible 400 unsupported_feature, missing capabilities in WebShellSession.required, undeclared 403s) (thread).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions