Repository navigation
Make managed-agent recovery contextual and preserve conversations - #839
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Current verification
Published clean feature head
3f739de79f3736c6342644fa38cd753851d729ad, based on main96e57e83681fef19fe758d20f4835e8efe91484a. All73 original feature commits retained;9 necessary repairs/user-directed plan updates followed,82 total.3f739de79f37: CloudBuild SUCCESS. Affected configured-cloud Chromium actually executed all46 cases,25 contextual/10pane/11tab, without retries or skips: PASS. Executionfreshell-e2e-3f739de79f37-45wt1w-q9ckd.Necessary repairs and evidence qualification
The transcript-preservation fix reproduced actual mounted data loss before cleanup refusal; final23 new behavioral cases plus579 affected/neighbor cases passed. The snapshot handoff fix reproduced three original typed409 failures and a history-present control, then passed isolated Rust1.96 cross-kind51/snapshot69/proxy19/stop-history8/bootstrap10 selectors. Two initial RED reproductions preceded reading the suite's sandbox instruction and remain qualified; all subsequent destructive neighbors/final confirmations were isolated, with no production process targeted.
The blocking12-line static checkout assertion was deleted under the user's explicit test rule. It inspected source text rather than executing the claimed boundary and misidentified a private fake Docker API. All58 retained analyzer/broker/coordinator behavior tests and typechecks passed; runtime/analyzer/manifest/allowlist unchanged.
The final browser locator repair selects existing speaker-labeled transcript bodies. A controlled real header/transcript duplicate reproduced RED, GREEN passed, and removing the actual user transcript caused the corrected assertion to fail while the old broad assertion still passed on title alone. Final8 meaningful neighbors passed without retries. No timeout/retry/skip or native-history/identity/traffic assertion was weakened. Final configured-cloud46PASS verifies this repair at the published head.
Earlier full attempts remain failed evidence:6 static assertion,7 missing canonical native libraries,8 compiler thread exhaustion,9 premature image-readiness validation and runtime process-budget exhaustion. Corrected setup preserves owned output permissions, supported host-verified
FRESHELL_BUILD_COMMIT, pinned tools, privilege boundaries and all cases. The scheduling fix bounds concurrency without increasing sandbox limits. No healthy sibling was cancelled; no cloud-to-local fallback occurred.Review and accepted residuals
Whole-delta round12 PASSED at
ab6bba9f5da212142b688ad8933077efe69efbef; all carried binding findings individually cleared. Necessary subsequent local/gate fixes are separately tested and are not retroactively claimed independently reviewed at the final head. Actual53 review attempts/50 substantive reports,2authentication failures/1capacity failure; no additional loop. Five closed OPTIONAL follow-ups remain recorded in the final recap.The different-family Claude review route could not authenticate through OneCLI. Fresh read-only Codex review contexts supplied same-family evidence with weaker independence; the original different-family requirement remains unmet and disclosed, with user-authorized continuation beyond review caps. Live external-provider certification remains accepted DEFERRED; no raw-secret fallback or certification claim. Provider parity/MCP/config/security-document cleanup already landed in PR834.
Rollout
This PR lands source only. Production has not been built, deployed or restarted.
Use the managed rollout runbook to rebuild the managed server, supervisor and session-host from one checkout with
managed-runtime-v1; the ordinary server launcher does not rebuild session-host. Production restart is a separate explicitly approved operation.