You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Implements slice A of the durable ACP interactions foundation as a dormant Cloudflare path. The feature remains disabled by default through ACP_INTERACTIONS_ENABLED=false and does not activate permission/form/URL UI or runtime emission.
A dedicated no-wake answer delivery service that uses nodeAgentRequest(..., recoverContainerOnTimeout: false) and does not import prompt-delivery recovery code.
Source-safe acp_interaction attention projection and legacy attention resolve/expiry guards so ACP interaction markers cannot be answered through prompt forwarding.
VM-agent dormant answer endpoint/capability fixture for low-level answer receipt without activating interaction creation.
v21 Durable Object migration and generated config compatibility updates.
Agent Preflight
Preflight completed before code changes
Classifications:
external-api-change
cross-component-change
business-logic-change
public-surface-change
docs-sync-change
security-sensitive-change
ui-change
infra-change
External References
N/A: This slice uses existing repository Cloudflare Worker, Durable Object, Valibot, auth, and vm-agent patterns; no external API contract changed.
Codebase Impact Analysis
Touches apps/api Worker routes/services/Durable Objects, packages/shared contracts/defaults, packages/vm-agent dormant receipt endpoint/capability fixture, scripts/quality migration expectations, tests/fixtures, .env.example, and .claude/skills/env-reference/SKILL.md. The feature is dormant by default and does not change current UI or runtime permission creation behavior.
Documentation & Specs
Updated apps/api/.env.example and .claude/skills/env-reference/SKILL.md for the new optional ACP interaction controls. The task state in tasks/active/2026-09-29-dormant-acp-interactions-foundation.md records scope, evidence, and local validation limits. No public user-facing capability documentation was added because slice A does not activate ACP permission/form/URL UI.
Constitution & Risk Check
Checked Principle XI and security-sensitive paths: ACP limits/timeouts have shared defaults with typed env overrides; only the dormant feature flag is in wrangler to avoid Worker text-binding overflow. Request detail and answer decisions are encrypted at rest with the existing generated Worker encryption key path; browser answer writes require auth, task:write, session creator, and exact Origin checks; runtime answer delivery explicitly disables container recovery/wake.
Validation
pnpm typecheck
pnpm lint (passes with pre-existing warnings in packages/acp-client and apps/web)
pnpm --filter @simple-agent-manager/api typecheck
pnpm --filter @simple-agent-manager/api lint
pnpm --filter @simple-agent-manager/api test -- tests/acp-interaction-delivery.test.ts
pnpm vitest run scripts/quality/do-migration-compatibility.test.ts scripts/quality/go-toolchain-floor.test.ts scripts/quality/check-runtime-boundary-semantics.test.ts
Local limitations to confirm in CI/staging:
The current container has no Go toolchain or gofmt, so VM-agent Go compilation/formatting needs CI/toolchain confirmation.
@cloudflare/vitest-pool-workers tests stall at startup in this container, including an existing attention-markers test; the new acp-interaction-store worker test is included for CI/staging confirmation.
Specialist review notes
Cloudflare: v21 appends InteractionStore only; generated migration compatibility passes and wrangler keeps only the dormant feature flag to stay below Worker text-binding guard.
Security: arbitrary request/answer detail is AES-GCM encrypted with existing Worker credential key path; logs/attention metadata use structural IDs/kind/state/time only; browser writes require exact Origin plus session auth/capability/session creator.
Constitution/env/doc sync: ACP tuning limits/timeouts have shared defaults, Env overrides, .env.example, and env reference documentation. No new manual secret prerequisite.
Test engineering: node-level no-wake delivery and VM contract tests are added; worker DO vertical test is present but needs CI/staging runtime confirmation because local worker tests stall.
UI Screenshot Evidence
N/A: This PR does not change UI surfaces; it adds dormant backend foundation routes/storage/contracts only.
Scope guard
This PR intentionally does not implement B/C/D: no production permission UI, no runtime permission/form/URL producers, no remote URL elicitation UI, and no native-auth diagnostics/hardening changes.
Final shipping evidence (Slice A)
Final head: d29fe1e0ba0c78f5f55fd44550cf59f49c34879f.
PR checks on final head: CI, E2E Smoke, and CodSpeed passed, including Durable Object Workers, Secret Scan, Type Check, Test, Build, VM Agent Test/E2E/Integration, and deploy-script validation.
Staging: deploy-staging.yml run 36570587320 passed. It ran migration safety gates, deployed the Cloudflare API Worker with the dormant InteractionStore binding/migration, uploaded VM agent and CLI artifacts, and passed staging smoke tests.
CodeRabbit: requested through the trusted label/workflow path earlier in the PR; CodeRabbit reported review skipped because auto reviews are disabled, so there is no actual CodeRabbit review to claim.
Scope guard: ACP_INTERACTIONS_ENABLED=false; Slice A remains dormant and does not activate the permissions/forms/URL UI or runtime behavior reserved for B/C/D.
Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.
Comparing sam/implement-ship-slice-dormant-bdptty (d29fe1e) with main (9640355)1
Footnotes
No successful run was found on main (96b87cc) during the generation of this report, so 9640355 was used instead as the comparison base. There might be some changes unrelated to this pull request in this report. ↩
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements slice A of the durable ACP interactions foundation as a dormant Cloudflare path. The feature remains disabled by default through
ACP_INTERACTIONS_ENABLED=falseand does not activate permission/form/URL UI or runtime emission.This adds:
InteractionStoreSQLite Durable Object with encrypted request detail and encrypted answer/decision storage, answer idempotency/body-hash binding, delivery state separation, alarm-driven projection/delivery/purge/compaction, and session cleanup hooks.nodeAgentRequest(..., recoverContainerOnTimeout: false)and does not import prompt-delivery recovery code.acp_interactionattention projection and legacy attention resolve/expiry guards so ACP interaction markers cannot be answered through prompt forwarding.v21Durable Object migration and generated config compatibility updates.Agent Preflight
Classifications:
External References
N/A: This slice uses existing repository Cloudflare Worker, Durable Object, Valibot, auth, and vm-agent patterns; no external API contract changed.
Codebase Impact Analysis
Touches
apps/apiWorker routes/services/Durable Objects,packages/sharedcontracts/defaults,packages/vm-agentdormant receipt endpoint/capability fixture,scripts/qualitymigration expectations,tests/fixtures,.env.example, and.claude/skills/env-reference/SKILL.md. The feature is dormant by default and does not change current UI or runtime permission creation behavior.Documentation & Specs
Updated
apps/api/.env.exampleand.claude/skills/env-reference/SKILL.mdfor the new optional ACP interaction controls. The task state intasks/active/2026-09-29-dormant-acp-interactions-foundation.mdrecords scope, evidence, and local validation limits. No public user-facing capability documentation was added because slice A does not activate ACP permission/form/URL UI.Constitution & Risk Check
Checked Principle XI and security-sensitive paths: ACP limits/timeouts have shared defaults with typed env overrides; only the dormant feature flag is in wrangler to avoid Worker text-binding overflow. Request detail and answer decisions are encrypted at rest with the existing generated Worker encryption key path; browser answer writes require auth,
task:write, session creator, and exact Origin checks; runtime answer delivery explicitly disables container recovery/wake.Validation
pnpm typecheckpnpm lint(passes with pre-existing warnings inpackages/acp-clientandapps/web)pnpm --filter @simple-agent-manager/api typecheckpnpm --filter @simple-agent-manager/api lintpnpm --filter @simple-agent-manager/api test -- tests/acp-interaction-delivery.test.tspnpm --filter @simple-agent-manager/shared typecheckpnpm vitest run scripts/quality/do-migration-compatibility.test.ts scripts/quality/go-toolchain-floor.test.ts scripts/quality/check-runtime-boundary-semantics.test.tsLocal limitations to confirm in CI/staging:
gofmt, so VM-agent Go compilation/formatting needs CI/toolchain confirmation.@cloudflare/vitest-pool-workerstests stall at startup in this container, including an existingattention-markerstest; the newacp-interaction-storeworker test is included for CI/staging confirmation.Specialist review notes
InteractionStoreonly; generated migration compatibility passes and wrangler keeps only the dormant feature flag to stay below Worker text-binding guard..env.example, and env reference documentation. No new manual secret prerequisite.UI Screenshot Evidence
N/A: This PR does not change UI surfaces; it adds dormant backend foundation routes/storage/contracts only.
Scope guard
This PR intentionally does not implement B/C/D: no production permission UI, no runtime permission/form/URL producers, no remote URL elicitation UI, and no native-auth diagnostics/hardening changes.
Final shipping evidence (Slice A)
d29fe1e0ba0c78f5f55fd44550cf59f49c34879f.deploy-staging.ymlrun36570587320passed. It ran migration safety gates, deployed the Cloudflare API Worker with the dormantInteractionStorebinding/migration, uploaded VM agent and CLI artifacts, and passed staging smoke tests.ACP_INTERACTIONS_ENABLED=false; Slice A remains dormant and does not activate the permissions/forms/URL UI or runtime behavior reserved for B/C/D.