Harden dormant ACP interaction foundation - #2187
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: raphaeltm/simple-agent-manager/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review |
|
|
@coderabbitai review |
|
@coderabbitai review |
|
All code, CI, staging, live VM, observability, and cleanup gates are green on head CodeRabbit is the only remaining gate. The opt-in label is present, and trusted owner-scoped workflow run This PR is intentionally left unmerged pending either a completed CodeRabbit review or an explicit waiver of that gate. |
|
Raphaël explicitly waived the remaining CodeRabbit gate in the linked SAM conversation. All previously recorded CI, exact-head staging, live VM, observability, and cleanup gates remain green; proceeding to merge. |



Problem and result
PR #2182 merged while its final shepherd review was still identifying defects. This follow-up applies the completed repair set to
main: runtime answer delivery now probes the real VM runtime identity without waking, binds settle/delivery to the stored agent session, preserves rescheduled outbox rows, bounds alarm work, and purges encrypted interaction data only after terminalization.It also wires every ACP interaction override through deployment generation, corrects the API contract, and adds a real callback → D1/ProjectData/InteractionStore → browser auth → VM HTTP boundary test.
ACP_INTERACTIONS_ENABLED=falseremains the default, so the foundation stays dormant.Closes the remaining shepherd findings from #2182.
Validation
internal/servertests passed with Go 1.26.6; changed Go files are gofmt-clean.git diff --checkpassed.Final CI, staging, and review evidence
ee9a4bd6a22c48c557a20da8d971a6b6321d3827: CI run36578076975, E2E Smoke36578076967, and CodSpeed36578076994passed. The full Durable Object Workers job passed 98 files / 1,264 tests; the earlier 100 ms expiry-test race was replaced by a deterministic storage deadline transition.36585613515passed configuration validation, migration/archive safety gates, API/Web/VM-agent/CLI deployment, health checks, and Playwright smoke tests.INTERACTION_STOREDurable Object binding present andACP_INTERACTIONS_ENABLED=false;https://api.sammy.party/healthreturned healthy.01M3PVCG4HSTRJPDBC3G12AC60reachedrunningon node01M3PVCFTENQXYPHNNGB737D5J; D1 showed a healthy VM-agent heartbeat and the content-identical VM artifact versionb4b1ffd36(the final commit changes only a worker test). Authenticated Playwright loaded the workspace chat/terminal and hardware details with no console errors.deletionStatus=confirmed, the node delete returned success, both exact IDs disappeared from D1, and staging returned to zero active nodes/workspaces after the serialized verifier released its resources.quality:observability-noisepassed over the one-hour deployment/verification window. The 24-hour view still contains pre-existing repeated ACP lifecycle messages from unrelated staging sessions; Workers telemetry is unavailable to the scoped token (403).coderabbit-reviewlabel is present and trusted owner-scoped workflow run36588913237succeeded and posted@coderabbitai reviewas the repository owner. After the processing window, GitHub still reports zero CodeRabbit reviews and zero review threads; CodeRabbit’s earlier app comment says automatic reviews are disabled. Merge is paused pending a CodeRabbit review or an explicit waiver.Agent Preflight (Required)
Classification
External References
N/A: this repair uses the repository's existing ACP, callback authentication, Durable Object, deployment, and VM-agent contracts; no external API was introduced.
Codebase Impact Analysis
The repair spans
apps/apiinteraction routes, service delivery, Durable Objects, migrations, worker tests, and generated bindings;packages/sharedschemas;packages/vm-agentruntime and HTTP handling; plusscripts, deployment configuration, API reference generation, and the task record.Documentation & Specs
Updated the generated OpenAPI contract and the active implementation task with the corrected answer, delivery, lifecycle, configuration, and verification behavior. No user-facing UI documentation changes are required because the ACP foundation remains disabled by default.
Constitution & Risk Check
Reviewed Principle XI and the repository security, environment, Cloudflare, Go, test, task-completion, and documentation requirements. The primary risks were stale-session delivery, unauthenticated callbacks, unbounded alarm work, premature secret deletion, and hardcoded deployment controls; the implementation and focused tests address each risk while retaining a dormant default.