Skip to content

Harden dormant ACP interaction foundation - #2187

Merged
simple-agent-manager[bot] merged 2 commits into
mainfrom
sam/follow-up-2182-acp-hardening
Sep 29, 2026
Merged

simple-agent-manager[bot] merged 2 commits into
mainfrom
sam/follow-up-2182-acp-hardening

Conversation

@simple-agent-manager

@simple-agent-manager simple-agent-manager Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Problem and result

PR #2182 merged while its final shepherd review was still identifying defects. This follow-up applies the completed repair set to main: runtime answer delivery now probes the real VM runtime identity without waking, binds settle/delivery to the stored agent session, preserves rescheduled outbox rows, bounds alarm work, and purges encrypted interaction data only after terminalization.

It also wires every ACP interaction override through deployment generation, corrects the API contract, and adds a real callback → D1/ProjectData/InteractionStore → browser auth → VM HTTP boundary test. ACP_INTERACTIONS_ENABLED=false remains the default, so the foundation stays dormant.

Closes the remaining shepherd findings from #2182.

Validation

  • API typecheck passed.
  • Focused API route/delivery tests: 54 passed.
  • InteractionStore + vertical-slice workerd tests: 9 passed.
  • Shared package: 684 tests and typecheck passed.
  • VM-agent internal/server tests passed with Go 1.26.6; changed Go files are gofmt-clean.
  • Deployment/migration quality tests: 76 passed.
  • Targeted ESLint, Prettier, and git diff --check passed.
  • Local specialist reviews: task completion, test engineering, Cloudflare, environment, documentation, constitution, Go, and security all PASS.

Final CI, staging, and review evidence

  • Final code head ee9a4bd6a22c48c557a20da8d971a6b6321d3827: CI run 36578076975, E2E Smoke 36578076967, and CodSpeed 36578076994 passed. The full Durable Object Workers job passed 98 files / 1,264 tests; the earlier 100 ms expiry-test race was replaced by a deterministic storage deadline transition.
  • Exact-head staging deploy 36585613515 passed configuration validation, migration/archive safety gates, API/Web/VM-agent/CLI deployment, health checks, and Playwright smoke tests.
  • Live Cloudflare settings showed the INTERACTION_STORE Durable Object binding present and ACP_INTERACTIONS_ENABLED=false; https://api.sammy.party/health returned healthy.
  • Fresh VM proof: workspace 01M3PVCG4HSTRJPDBC3G12AC60 reached running on node 01M3PVCFTENQXYPHNNGB737D5J; D1 showed a healthy VM-agent heartbeat and the content-identical VM artifact version b4b1ffd36 (the final commit changes only a worker test). Authenticated Playwright loaded the workspace chat/terminal and hardware details with no console errors.
  • Cleanup: the workspace delete returned deletionStatus=confirmed, the node delete returned success, both exact IDs disappeared from D1, and staging returned to zero active nodes/workspaces after the serialized verifier released its resources.
  • quality:observability-noise passed over the one-hour deployment/verification window. The 24-hour view still contains pre-existing repeated ACP lifecycle messages from unrelated staging sessions; Workers telemetry is unavailable to the scoped token (403).
  • CodeRabbit is the only remaining gate. The coderabbit-review label is present and trusted owner-scoped workflow run 36588913237 succeeded and posted @coderabbitai review as the repository owner. After the processing window, GitHub still reports zero CodeRabbit reviews and zero review threads; CodeRabbit’s earlier app comment says automatic reviews are disabled. Merge is paused pending a CodeRabbit review or an explicit waiver.

Agent Preflight (Required)

  • Preflight completed before code changes

Classification

  • external-api-change
  • cross-component-change
  • business-logic-change
  • public-surface-change
  • docs-sync-change
  • security-sensitive-change
  • ui-change
  • infra-change

External References

N/A: this repair uses the repository's existing ACP, callback authentication, Durable Object, deployment, and VM-agent contracts; no external API was introduced.

Codebase Impact Analysis

The repair spans apps/api interaction routes, service delivery, Durable Objects, migrations, worker tests, and generated bindings; packages/shared schemas; packages/vm-agent runtime and HTTP handling; plus scripts, deployment configuration, API reference generation, and the task record.

Documentation & Specs

Updated the generated OpenAPI contract and the active implementation task with the corrected answer, delivery, lifecycle, configuration, and verification behavior. No user-facing UI documentation changes are required because the ACP foundation remains disabled by default.

Constitution & Risk Check

Reviewed Principle XI and the repository security, environment, Cloudflare, Go, test, task-completion, and documentation requirements. The primary risks were stale-session delivery, unauthenticated callbacks, unbounded alarm work, premature secret deletion, and hardcoded deployment controls; the implementation and focused tests address each risk while retaining a dormant default.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: raphaeltm/simple-agent-manager/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 7cd5a45c-e873-45b4-8269-9dcafc0b5f80

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@simple-agent-manager simple-agent-manager Bot added the coderabbit-review Trigger CodeRabbit review for opt-in PRs label Sep 29, 2026
@raphaeltm

Copy link
Copy Markdown
Owner

@coderabbitai review

@codspeed

codspeed Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Merging this PR will not alter performance

✅ 6 untouched benchmarks


Comparing sam/follow-up-2182-acp-hardening (ee9a4bd) with main (eaa0178)

Open in CodSpeed

@sonarqubecloud

Copy link
Copy Markdown

@raphaeltm

Copy link
Copy Markdown
Owner

@coderabbitai review

@raphaeltm

Copy link
Copy Markdown
Owner

@coderabbitai review

@simple-agent-manager simple-agent-manager Bot added the needs-human-review Agent could not complete all review gates — human must approve before merge label Sep 29, 2026
@simple-agent-manager

Copy link
Copy Markdown
Contributor Author

All code, CI, staging, live VM, observability, and cleanup gates are green on head ee9a4bd6a22c48c557a20da8d971a6b6321d3827.

CodeRabbit is the only remaining gate. The opt-in label is present, and trusted owner-scoped workflow run 36588913237 succeeded and posted @coderabbitai review as the repository owner. After the full processing window, GitHub still reports no CodeRabbit review and no review threads. The earlier CodeRabbit app response says automatic reviews are disabled.

This PR is intentionally left unmerged pending either a completed CodeRabbit review or an explicit waiver of that gate.

@simple-agent-manager

Copy link
Copy Markdown
Contributor Author

Raphaël explicitly waived the remaining CodeRabbit gate in the linked SAM conversation. All previously recorded CI, exact-head staging, live VM, observability, and cleanup gates remain green; proceeding to merge.

@simple-agent-manager
simple-agent-manager Bot merged commit 7b6922b into main Sep 29, 2026
37 checks passed
@simple-agent-manager
simple-agent-manager Bot deleted the sam/follow-up-2182-acp-hardening branch September 29, 2026 16:04

This branch was successfully deployed

1 active deployment
staging — ee9a4bd6 Deployed Sep 29, 2026 by simple-agent-manager[bot] via smoke-tests #2188
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

coderabbit-review Trigger CodeRabbit review for opt-in PRs needs-human-review Agent could not complete all review gates — human must approve before merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant