Skip to content

cmux-tui: derive agent projections from the journal - #9806

Closed
lawrencecchen wants to merge 197 commits into
mainfrom
task-journal-agent-recovery-layer
Closed

lawrencecchen wants to merge 197 commits into
mainfrom
task-journal-agent-recovery-layer

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Aug 7, 2026 •

Copy link
Copy Markdown
Contributor

Stacked on #9726.

Draft. This is the first agent projection and fail-closed ingress slice, not the completed recovery layer.

Scope:

  • Provider hooks append agent lifecycle events to the append-only session journal.
  • Hook payloads use cmux.agent-native.canonical.v1, a closed canonical payload with only lifecycle, topology, checkpoint, and opaque recovery identifiers.
  • The reducer updates AgentProjection in the same SQLite transaction as the journal event and the idempotency receipt.
  • agent.report remains compatibility ingress only. Its projection update comes from the journal reducer.
  • Projection rebuild deletes the cache and derives it again from the journal. The rebuild test checks byte-for-byte JSON equality.
  • Explicit future agent.session.interrupted events from a recovery-policy producer still reduce to interrupted state.

Corrections in this head:

  • Replaced recursive key-name redaction with canonical allowlisted payload storage.
  • Removed WorkspaceRegistry::open Pi interruption classification. Reopening SQLite is not reboot evidence.
  • Added adversarial hook tests for secrets under benign keys, arrays, URLs, command and env payloads, mixed casing, and unknown provider extensions.
  • Added reopen continuity and duplicate-reopen checks so a live Pi projection stays working until a durable host-death signal exists.

Out of scope for this draft:

Successors:

Red and green commits:

  • b723c45 test(tui): harden journal projection invariants
  • 1b20279 fix(tui): make agent journal recovery fail closed

Focused verification:

  • cargo test -p cmux-tui-core canonical_native_payload_rejects_secrets_live_capabilities_and_unknown_extensions
  • cargo test -p cmux-tui-core agent_projection_is_derived_from_pi_journal_and_reopen_preserves_continuity
  • cargo test -p cmux-tui-core agent_hooks::tests
  • cargo test -p cmux-tui-core agent_reports_apply_hook_authority
  • cargo test -p cmux-tui-core raw_and_resource_agent_reports_share_durable_order_across_restart
  • cargo test -p cmux-tui-core persistent_mux_restart_restores_auxiliary_resources_and_exact_replay
  • cargo test -p cmux-tui-core every_safe_transport_operation_has_a_noun_first_path
  • cargo build -p cmux-tui

Owner closeout:
Fixed = raw provider-native payloads and open-time interruption classification -> fail-closed canonical hook payloads and no interruption without durable host-loss proof.
How = allowlisted canonical ingress plus transaction-local reducer and deterministic rebuild. This is principled because the journal remains the only semantic authority.
Risk = host-loss proof, policy effects, fork, and hibernation remain blocked on successor PRs.

@coderabbitai

coderabbitai Bot commented Aug 7, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 545939a4-9481-404e-b117-537d1d140461

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@blacksmith-sh

This comment has been minimized.

@lawrencecchen
lawrencecchen changed the base branch from codex/cmux-browser-provider to main August 10, 2026 17:07
@lawrencecchen

Copy link
Copy Markdown
Contributor Author

Closing as superseded. The agent projection and recovery slice is recut in #10134, the surviving core branch. This draft is based on an old commit and conflicts with current main. No unique work remains here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant