Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
87 commits
Select commit Hold shift + click to select a range
3a0edda
feat(fleet): add exact cleanroom lifecycle controls
Sep 5, 2026
5409a1b
test(cleanroom): add exhaustive relay qualification workflows
Sep 5, 2026
e5cdac7
chore: refresh cleanroom lockfile on 11.10.3
Sep 5, 2026
cfd8059
test(cleanroom): bind fleet board to 11.10.3
Sep 5, 2026
9cd7378
fix(ci): satisfy qualification dependency engine floor
Sep 5, 2026
af6a23d
docs(cleanroom): seal Relay prerelease proof
Sep 5, 2026
d3536e5
style: auto-format with Prettier
github-actions[bot] Sep 5, 2026
33b74ef
fix(qualification): harden candidate evidence reads
Sep 5, 2026
7d2db79
fix(deps): require patched undici
Sep 5, 2026
56cbd86
fix(qualification): eliminate no-follow fallback race
Sep 5, 2026
b9bd807
test(pr-proof): prove immutable Fleet snapshot binding
Sep 5, 2026
6231039
test(fleet): harden cleanroom acceptance proof
Sep 5, 2026
d46d260
fix(qualification): harden Fleet proof boundaries
Sep 5, 2026
d6f6fdf
fix(qualification): parse semver without backtracking
Sep 5, 2026
f49fff8
fix(qualification): close proof boundary review gaps
Sep 5, 2026
2447d10
fix(cleanroom): close fresh review gaps
Sep 5, 2026
ffee2ef
fix(qualification): harden evidence transport boundaries
Sep 5, 2026
2dcba14
fix(cleanroom): close qualification review gaps
Sep 5, 2026
5c6f303
fix(cli): reconcile ambiguous Cloud workspace creates
Sep 5, 2026
75f7969
test(relayfile): tolerate full-suite process contention
Sep 5, 2026
3551c34
ci(relayflow): retain terminal Cloud failure evidence
Sep 5, 2026
fb8a50d
Harden PR 1665 Fleet qualification evidence
Sep 6, 2026
a81f8d4
test(cli): include deferred Fleet commands in inventory
Sep 6, 2026
7b1cd73
fix(qualification): canonicalize Linux candidate npm cwd
Sep 6, 2026
87c8df1
fix(qualification): normalize artifact action digests
Sep 6, 2026
9362d9b
test(qualification): retire inert bootstrap invariant
Sep 6, 2026
040c876
fix(qualification): avoid shell for descriptor-bound npm
Sep 6, 2026
3d293ae
fix: harden cleanroom qualification evidence
Sep 6, 2026
40d25a8
test: serve fleet snapshot proof over TLS
Sep 6, 2026
439b956
test: bound fleet proof TLS fixture setup
Sep 6, 2026
c02e752
test(qualification): require distinct mount correlations
Sep 6, 2026
11e959b
fix(qualification): deliver Cloud producer request
Sep 6, 2026
0982e45
fix(qualification): isolate Cloud dispatch token
Sep 6, 2026
30bdf3a
test(qualification): require producer steps to exist
Sep 6, 2026
3bd1e65
fix(workflows): allow scoped model transport
Sep 6, 2026
a513062
test(fleet): reconcile identity views around release
Sep 6, 2026
2ca44fd
fix(pr-proof): keep failure redaction dependency-free
Sep 6, 2026
6a8cb81
fix(qualification): close cleanroom review gaps
Sep 6, 2026
b69e2cf
fix(pr-proof): fully mask declared credentials
Sep 6, 2026
0242dde
fix(pr-proof): bound redacted fallback output
Sep 6, 2026
2f48e19
fix(qualification): harden current-head reliability gates
Sep 6, 2026
275e862
fix: harden cleanroom candidate preflight
Sep 6, 2026
91c3d1f
fix: isolate qualification retries and diagnostics
Sep 6, 2026
a8e7a80
fix(qualification): close remaining cleanroom races
Sep 6, 2026
6836e84
fix(qualification): settle exact-head review findings
Sep 6, 2026
db7a601
fix(harnesses): update vulnerable Pi closure
Sep 6, 2026
bf0f0cf
fix(qualification): fail closed on retained handles
Sep 6, 2026
cec4e36
fix: close cleanroom qualification timeout gaps
Sep 6, 2026
a9a0d4a
test: account for cleanroom retry budgets
Sep 6, 2026
b2c7329
test: close qualification review gaps
Sep 6, 2026
dd53af6
test: close fresh qualification review gaps
Sep 6, 2026
63d722c
docs: align historical Fleet board count
Sep 6, 2026
51e5951
fix: close stale qualification workflow gaps
Sep 6, 2026
1be9fae
docs: drop a changelog bullet duplicated by the rebase
Sep 6, 2026
246a320
fix(cloud): keep symlinks inside the compiled permission model
Sep 7, 2026
6e28d23
fix(cloud): deny project symlinks instead of dropping or granting them
Sep 7, 2026
3c25cf0
fix(verify-fleet-daytona): install exact deps before building
Sep 7, 2026
4b52640
Merge remote-tracking branch 'github/main' into fix/1665-sync-startup…
miyaontherelay Sep 7, 2026
2a04ace
fix(deps): bump @relayflows/core and @relayflows/cli to 1.1.5
Sep 7, 2026
8ebbf1c
Merge remote-tracking branch 'origin/main' into fix/pr1665-sync-0908
Sep 8, 2026
2fb067b
fix: align fleet candidate relayflows dependencies
Sep 8, 2026
00b46ca
fix(cli): isolate MCP startup test SDK clients
Sep 8, 2026
07f8f3b
fix(qualification): close PR 1665 review gaps
Sep 8, 2026
b309a10
fix(qualification): trust runner and derive fleet counts
Sep 8, 2026
ee8010e
fix(qualification): harden trusted cleanroom verification
Sep 8, 2026
492e7cc
Repair cleanroom qualification trust boundaries
Sep 8, 2026
e5aba4f
Merge remote-tracking branch 'origin/main' into fix/pr1665-sync-0908
Sep 8, 2026
414c163
test(qualification): consolidate trusted cleanroom proof
Sep 8, 2026
45c8fb6
fix(qualification): bind hydrated candidate attestations
Sep 8, 2026
a19b148
fix(fleet): converge accepted Daytona deletes
Sep 8, 2026
f95afb1
fix(fleet): make Daytona cleanup recovery bounded
Sep 8, 2026
8f6b17b
fix(fleet): bound cleanup delete and leaked-state aggregation
Sep 8, 2026
5706def
fix(fleet): retain Daytona delete timeout evidence
Sep 8, 2026
d18bd70
fix(broker): publish readiness after runtime construction
Sep 9, 2026
6bb5846
test(broker): exercise startup channel ordering
Sep 9, 2026
bc0dbf7
fix(fleet): require accepted Daytona destroy state
Sep 9, 2026
ce49285
chore(trail): record Daytona cleanup fix
Sep 9, 2026
5bbe923
fix(qualification): bind candidate provenance exactly
Sep 9, 2026
bcaf277
fix(qualification): preserve artifacts across macOS publish races
Sep 9, 2026
ebb5eb9
fix(deps): require patched smol-toml
Sep 9, 2026
034ada4
Revert "fix(deps): require patched smol-toml"
Sep 9, 2026
8604a34
fix(deps): narrow patched smol-toml override
Sep 9, 2026
517f486
fix(qualification): bound Fleet consumer timeout
Sep 10, 2026
91e1dc3
fix(qualification): reconcile exact Daytona sandboxes after timeout
Sep 10, 2026
c8b1a8a
fix(qualification): recover exact Daytona sandboxes safely
Sep 10, 2026
cbe7eac
fix(qualification): require checkpointed recovery intents
Sep 10, 2026
1b3ffbc
chore(trail): record Daytona recovery decision
Sep 10, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,74 @@
{
"id": "traj_uk6h49o2go5d",
"version": 1,
"task": {
"title": "Finish PR 1665 comprehensive Relay and Fleet cleanroom qualification",
"source": {
"system": "plain",
"id": "relay#1665"
}
},
"status": "active",
"startedAt": "2026-09-09T21:47:25.815Z",
"agents": [
{
"name": "default",
"role": "lead",
"joinedAt": "2026-09-09T21:50:52.599Z"
}
],
"chapters": [
{
"id": "chap_0b6kshczxal7",
"title": "Work",
"agentName": "default",
"startedAt": "2026-09-09T21:50:52.599Z",
"events": [
{
"ts": 1788990652600,
"type": "decision",
"content": "Treat a non-symlink current artifact pointer as a retention no-op: Treat a non-symlink current artifact pointer as a retention no-op",
"raw": {
"question": "Treat a non-symlink current artifact pointer as a retention no-op",
"chosen": "Treat a non-symlink current artifact pointer as a retention no-op",
"alternatives": [],
"reasoning": "Hosted macOS exposed EINVAL during concurrent publication; preserving all runs is fail-closed and avoids deleting an untrusted canonical target."
},
"significance": "high"
},
{
"ts": 1788993478961,
"type": "decision",
"content": "Kept the security fix dependency-delta-only: Kept the security fix dependency-delta-only",
"raw": {
"question": "Kept the security fix dependency-delta-only",
"chosen": "Kept the security fix dependency-delta-only",
"alternatives": [],
"reasoning": "Regenerating the full lock rewrote hundreds of unrelated records. The exact root override plus the smol-toml 1.8.0 lock entry passes npm ci and removes GHSA-7w5x-hrqm-74c2 without broad candidate dependency churn. The separate Relayfile SDK/Bun incompatibility remains independently tracked."
},
"significance": "high"
},
{
"ts": 1789008100532,
"type": "decision",
"content": "Require validated checkpointed ownership intents before exact-name Daytona recovery and persist each recovered ID before deletion: Require validated checkpointed ownership intents before exact-name Daytona recovery and persist each recovered ID before deletion",
"raw": {
"question": "Require validated checkpointed ownership intents before exact-name Daytona recovery and persist each recovered ID before deletion",
"chosen": "Require validated checkpointed ownership intents before exact-name Daytona recovery and persist each recovered ID before deletion",
"alternatives": [],
"reasoning": "A lost CLI response can leave a remote sandbox after only the pre-create name intent is durable; exact name/workspace/nonce/newness/baseline validation plus a private checkpoint closes the crash window without ambient scans, while invalid attempt evidence remains fail-closed and independent."
},
"significance": "high"
}
]
}
],
"commits": [],
"filesChanged": [],
"projectId": "AgentWorkforce/relay",
"tags": [],
"_trace": {
"startRef": "5bbe9230bfb90cc59da7f96cfc92cf20210096f1",
"endRef": "5bbe9230bfb90cc59da7f96cfc92cf20210096f1"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,101 @@
{
"version": "1.0.0",
"id": "75779746-66ad-4591-9434-e86aec5d1092",
"timestamp": "2026-09-08T19:25:26.970Z",
"trajectory": "traj_1by387iu092c",
"files": [
{
"path": "tests/fixtures/strict-workflow-yaml.test.ts",
"conversations": [
{
"contributor": {
"type": "ai"
},
"ranges": [
{
"start_line": 1,
"end_line": 6,
"revision": "be9cbeaf88075f06837c28631cacf654d5b756e6"
}
]
}
]
},
{
"path": "tests/relayflows/cases/1665-immutable-fleet-snapshot/run.mjs",
"conversations": [
{
"contributor": {
"type": "ai"
},
"ranges": [
{
"start_line": 225,
"end_line": 273,
"revision": "be9cbeaf88075f06837c28631cacf654d5b756e6"
},
{
"start_line": 404,
"end_line": 410,
"revision": "be9cbeaf88075f06837c28631cacf654d5b756e6"
},
{
"start_line": 499,
"end_line": 505,
"revision": "be9cbeaf88075f06837c28631cacf654d5b756e6"
}
]
}
]
},
{
"path": "tests/relayflows/cases/1665-immutable-fleet-snapshot/strict-yaml-subset.mjs",
"conversations": [
{
"contributor": {
"type": "ai"
},
"ranges": []
}
]
},
{
"path": "tests/relayflows/cases/1665-immutable-fleet-snapshot/trusted-cleanroom-runner.mjs",
"conversations": [
{
"contributor": {
"type": "ai"
},
"ranges": [
{
"start_line": 1,
"end_line": 4,
"revision": "be9cbeaf88075f06837c28631cacf654d5b756e6"
},
{
"start_line": 176,
"end_line": 182,
"revision": "be9cbeaf88075f06837c28631cacf654d5b756e6"
},
{
"start_line": 192,
"end_line": 198,
"revision": "be9cbeaf88075f06837c28631cacf654d5b756e6"
}
]
}
]
},
{
"path": "tests/relayflows/cases/1682-trusted-cleanroom-runner/case.json",
"conversations": [
{
"contributor": {
"type": "ai"
},
"ranges": []
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
# Trajectory: Consolidate trusted cleanroom proof into PR 1665 single RelayFlow case

> **Status:** ✅ Completed
> **Task:** relay#1665
> **Confidence:** 93%
> **Started:** September 8, 2026 at 09:13 PM
> **Completed:** September 8, 2026 at 09:25 PM

---

## Summary

Consolidated the trusted cleanroom runner security regression into PR 1665's immutable Fleet snapshot RelayFlow and proved exact base absent/head fixed in clean detached checkouts.

**Approach:** Standard approach

---

## Key Decisions

### Keep one declared RelayFlow case and run issue 1682 trust assertions as auxiliary checks inside it
- **Chose:** Keep one declared RelayFlow case and run issue 1682 trust assertions as auxiliary checks inside it
- **Reasoning:** The PR proof dispatcher fails closed when more than one case directory changes; issue 1682 is a security correction to the still-unmerged 1665 feature, so both behaviors must be proven atomically without weakening the one-case contract.

---

## Chapters

### 1. Work
*Agent: default*

- Keep one declared RelayFlow case and run issue 1682 trust assertions as auxiliary checks inside it: Keep one declared RelayFlow case and run issue 1682 trust assertions as auxiliary checks inside it
- PR 1665 now carries both immutable Fleet snapshot and trusted cleanroom security proof in one declared RelayFlow case; exact clean base/head red-green passed.

---

## Artifacts

**Commits:** be9cbeaf8
**Files changed:** 5
Original file line number Diff line number Diff line change
@@ -0,0 +1,87 @@
{
"id": "traj_1by387iu092c",
"version": 1,
"task": {
"title": "Consolidate trusted cleanroom proof into PR 1665 single RelayFlow case",
"source": {
"system": "plain",
"id": "relay#1665"
}
},
"status": "completed",
"startedAt": "2026-09-08T19:13:18.436Z",
"completedAt": "2026-09-08T19:25:26.898Z",
"agents": [
{
"name": "default",
"role": "lead",
"joinedAt": "2026-09-08T19:13:18.979Z"
}
],
"chapters": [
{
"id": "chap_3l3t6ky2v8jx",
"title": "Work",
"agentName": "default",
"startedAt": "2026-09-08T19:13:18.979Z",
"endedAt": "2026-09-08T19:25:26.898Z",
"events": [
{
"ts": 1788894798980,
"type": "decision",
"content": "Keep one declared RelayFlow case and run issue 1682 trust assertions as auxiliary checks inside it: Keep one declared RelayFlow case and run issue 1682 trust assertions as auxiliary checks inside it",
"raw": {
"question": "Keep one declared RelayFlow case and run issue 1682 trust assertions as auxiliary checks inside it",
"chosen": "Keep one declared RelayFlow case and run issue 1682 trust assertions as auxiliary checks inside it",
"alternatives": [],
"reasoning": "The PR proof dispatcher fails closed when more than one case directory changes; issue 1682 is a security correction to the still-unmerged 1665 feature, so both behaviors must be proven atomically without weakening the one-case contract."
},
"significance": "high"
},
{
"ts": 1788895526388,
"type": "reflection",
"content": "PR 1665 now carries both immutable Fleet snapshot and trusted cleanroom security proof in one declared RelayFlow case; exact clean base/head red-green passed.",
"raw": {
"focalPoints": [
"single-case proof",
"exact SHA",
"clean checkout"
],
"adjustments": "Retained auxiliary adversarial assertions under case 1665 so the dispatcher remains fail-closed.",
"confidence": 0.93
},
"significance": "high",
"tags": [
"focal:single-case proof",
"focal:exact SHA",
"focal:clean checkout",
"confidence:0.93"
]
}
]
}
],
"retrospective": {
"summary": "Consolidated the trusted cleanroom runner security regression into PR 1665's immutable Fleet snapshot RelayFlow and proved exact base absent/head fixed in clean detached checkouts.",
"approach": "Standard approach",
"confidence": 0.93
},
"commits": [
"be9cbeaf8"
],
"filesChanged": [
"tests/fixtures/strict-workflow-yaml.test.ts",
"tests/relayflows/cases/1665-immutable-fleet-snapshot/run.mjs",
"tests/relayflows/cases/1665-immutable-fleet-snapshot/strict-yaml-subset.mjs",
"tests/relayflows/cases/1665-immutable-fleet-snapshot/trusted-cleanroom-runner.mjs",
"tests/relayflows/cases/1682-trusted-cleanroom-runner/case.json"
],
"projectId": "AgentWorkforce/relay",
"tags": [],
"_trace": {
"startRef": "e5aba4f6c19a32a2474146ac09a5e754af2b10f4",
"endRef": "be9cbeaf88075f06837c28631cacf654d5b756e6",
"traceId": "75779746-66ad-4591-9434-e86aec5d1092"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
# Trajectory: Repair PR #1665 cleanroom qualification security and review findings

> **Status:** ✅ Completed
> **Task:** PR1665/1683 security repair
> **Confidence:** 90%
> **Started:** September 8, 2026 at 05:17 PM
> **Completed:** September 8, 2026 at 05:27 PM

---

## Summary

Repaired PR #1665 cleanroom qualification security and PR #1683 review findings: brokered candidate credentials through an unprivileged isolated process, materialized bounded evidence snapshots into trusted read-only inputs, added name-bound crash-safe workspace reconciliation, descriptor-bound artifact reads, rooted workflow paths, strict cloud host validation, behavioral no-candidate regression proof, and quality-test hardening. Node 22 full suite and static gates passed.

**Approach:** Standard approach

---

## Key Decisions

### Isolated candidate Fleet behind a trusted loopback credential broker and dedicated unprivileged UID
- **Chose:** Isolated candidate Fleet behind a trusted loopback credential broker and dedicated unprivileged UID
- **Reasoning:** The candidate needs live Fleet API behavior, but its process must not inherit workspace, Cloud, Daytona, or provider secrets; brokered forwarding preserves the behavior while read-only trusted inputs and an external evidence root prevent candidate mutation.

### Made cleanup reconcile deterministic idempotency keys before deleting
- **Chose:** Made cleanup reconcile deterministic idempotency keys before deleting
- **Reasoning:** A runner can die after remote creation and before GitHub output publication, so cleanup must produce explicit present-or-absent reconciliation proof rather than skip missing IDs.

---

## Chapters

### 1. Work
*Agent: default*

- Isolated candidate Fleet behind a trusted loopback credential broker and dedicated unprivileged UID: Isolated candidate Fleet behind a trusted loopback credential broker and dedicated unprivileged UID
- Made cleanup reconcile deterministic idempotency keys before deleting: Made cleanup reconcile deterministic idempotency keys before deleting
- Security repairs are implemented and verified: candidate credentials are brokered from an unprivileged isolated process, trusted evidence is materialized from a bounded snapshot, cleanup reconciles run-scoped creates, and all Node 22/static gates are green.
Loading
Loading