Integrate ACP permission roundtrip - #2202
simple-agent-manager[bot] merged 33 commits into
Conversation
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 13 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: Repository: raphaeltm/simple-agent-manager/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (72)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
|
Parent review handoff (task
PR intentionally remains draft/open. No readiness, CodeRabbit, merge, or production action was taken. |
|
Parent release review at Raphaël explicitly authorized readiness, merge and production rollout after satisfactory testing and review on September 30. This supersedes the previous parent release hold; it does not waive quality gates. I personally reviewed the integration-only delta from The live VM/Instant fixture evidence proves permission transport, reconnect, repeat requests, and exact-option behavior; it does not prove actual provider-account permission emission. Before activation, Sol task Current coordinating parent: |
|
@coderabbitai review |
|
|
Production deployment verified for #2202:
This is the dormant permission runtime/UI release. Activation, forms, remote URL elicitation, and auth diagnostics remain in the coordinated workflow. Existing active workspaces are preserved. Source UI PR #2200 has a later test-only clearance improvement ( |



Problem and result
PRs #2200 and #2201 implement the browser and runtime halves of ACP permission interaction separately. This PR integrates the exact parent-reviewed heads into a current-
mainbranch and prepares one pinned staging validation through browser → WorkerInteractionStore→ live VM/Instant runtime → ACP callback.Exact source heads:
e13a166b5b14860b99922211927dc1e0941087a496df904f7f847b84a2cb86df98439a19634a8612The production default remains disabled. Forms and URL elicitation remain unadvertised. The parent reviewed the integration changes and Raphaël authorized release on September 30. This PR ships the runtime/UI code with creation disabled; activation follows a separate verified rollout.
Integration-only changes
RUNTIME_STOPPEDas a terminal interrupted delivery after one no-wake probe instead of retrying an ambiguous outcome.PATH, matching explicit VM runtime selection while preserving Go ErrDot protection; create the workdir before resolution and include checked-in Claude/Codex fixture aliases.36718788997failed closed at 344 generated text bindings versus the 340 guard. Their environment override paths remain and shared typed fallbacks are identical; the guard was not raised.No production default changed.
Validation
go test ./...PATH, relativePATH=.rejection, missing-workdir creation, plus focused race runThe root aggregate test run had one unrelated cloud-init test exceed its 5-second timeout under concurrent load (5.7 seconds); its package rerun passed 176/176.
Staging Verification
Exact candidate
bb853a04eb8247718b5b2ea1f5deacecbe57c955passed CI36719533047, E2E Smoke36719533017, and CodSpeed36719532995. Final evidence headaecaf205f405442eaabfbb5b98503e5901219128passed CI36736970003, E2E Smoke36736969713, and CodSpeed36736969918. Candidate deploy36722105512succeeded with temporary staging-only permission overrides; production was read-only and its ACP override remained unset.The real project-chat UI completed the reversed-option fixture through Worker
InteractionStoreand the live runtime callback on both runtimes:6104086e-f1da-4119-b9f5-d1675265b7ec01M3SAZK3CF6FRBM035ZY272H1/01M3SAZJWS9WH9SNPZPFT0MVZSallow, thenreject; bothdelivery_confirmed79b4bd52-22db-4a62-bef0-9dbe380ad6a501M3SDJSPPBSYKW5DQ5WZF95Q7/01M3SDAM8H6C58YWG91S43JWTKallow, thenreject; bothdelivery_confirmedEach runtime received its second permission request on the same ACP prompt/connection. The browser page was closed and recreated while that request was pending, then recovered it from
InteractionStore. A later live VM generationd0009375-56af-473a-bcd7-27757b690fb2proved same-key/same-body replay returns 200 and a conflicting answer returns 409. Noncreator list/detail/answer returned 200 structural-only/403/403, cross-project detail returned 404, and 5,957 bytes of bounded creator/secondary snapshots plus transcript contained no raw request canary.All owned workspaces, nodes, and profiles were deleted; the authoritative D1 query returned zero live owned nodes. The five temporary staging overrides were removed. Restoration deploy
36736535610and its smoke tests passed at the same SHA with the checked-in creation flagfalse; staging and production environment listings contain no ACP overrides.Staged screenshots:
.codex/tmp/acp-cf-container-muo74b3k-{desktop,mobile}.pngand.codex/tmp/acp-vm-muo8qksb-{desktop,mobile}.png. Fixture behavior is not presented as actual provider-account emission. Actual Codex and Claude account emission remain unproven rollout gaps.UI Screenshot Evidence
Surface: Project chat ACP permission cards
End-to-End Verification
Live VM and Instant runs prove browser → Worker
InteractionStore→ runtime → ACP callback delivery, exact reversed options, a second request without reconnecting the runtime, browser reconnect, replay/conflict, authorization, and bounded transcript privacy. A separate fixture session proved ordinary message transport.Fresh deterministic reruns passed 50 API route/config cases, 9 Worker/InteractionStore vertical cases, 24 web card cases, and the focused Go race suite. These cover the full 64 KiB response contract, feature-off/version behavior, encrypted purge, deliberately lost receipts, cancellation/deadline/Stop/process loss, recreated-generation fencing, and VM/Instant stopped or stale-running no-wake behavior. Those fault cases remain labeled deterministic rather than staged fault injection.
Specialist Review Evidence
0cb2265c2launcher re-review passed: absolute runtimePATH, ErrDot preservation, workdir ordering, and focused race tests0cb2265c2absolute-path launcher re-review passed with no findingsRUNTIME_STOPPEDnow terminalizes without wake or retryCodeRabbit Review Evidence
Parent release review passed at
aecaf205f. The trusted label-triggered workflow 36740928176 requested review at 15:59:50 UTC on September 30. CodeRabbit replied “Review rate limited” at 16:00:15 UTC. At the 16:15+ UTC checkpoint, no reviews or inline findings had arrived. The required ~15-minute wait is complete; per the standing best-effort policy, release proceeds on the other passing gates without claiming a CodeRabbit review occurred. No repeated trigger was sent.Agent Preflight (Required)
Classification
External References
N/A: this integration uses the approved internal v2 idea
01M3P2E0JJNQRXX020P65ZRKEJand the exact parent-reviewed source heads. It adds no external API.Codebase Impact Analysis
apps/web: project-chat permission rendering, exact-option submission, reconnect/recovery polling, and Playwright evidence.apps/api: Cloudflare interaction authority, delivery, no-wake VM/Instant routing, and deploy configuration.packages/vm-agent: live ACP callback bridge, waiter lifecycle, generation and receipt fencing.packages/shared: versioned ACP interaction contracts and defaults.scripts/and.github/: deployment-variable forwarding and contract tests.apps/www/: public configuration reference.Documentation & Specs
The active integration task records the exact pins, data flow, rollout, security boundaries, narrow integration fixes, validation matrix, and pending staged evidence. Public configuration documentation now includes the added Worker/runtime and browser controls.
Constitution & Risk Check
Reviewed Principles IV and XI plus Cloudflare, VM agent, UI, environment, security, request-budget, and no-wake rules. Production creation remains false. Deadlines and bounds use typed configurable defaults, browser answers use exact option IDs, decrypted detail stays creator-only and no-store, and browser delivery remains Cloudflare-only. Staging is isolated to one authorized candidate after live contention checks.
Release scope
This merge deploys the reviewed permission runtime/UI with
ACP_INTERACTIONS_ENABLED=false. Activation remains a separate reviewed rollout owned by task01M3SGW0R90DNABPXMNPHZ6041, including old-runtime continuation safety. C1 forms are in task01M3SGWNFG7NGAY788GA465P25; C2 URLs and D diagnostics remain pending. Existing active workspaces will not be forcibly stopped for rollout.