Skip to content

Let Built in coworkers hand work on - #695

Closed
Harbor404 wants to merge 2 commits into
CopilotKit:mainfrom
Harbor404:fix/399-built-in-coworker-handoff
Closed

Harbor404 wants to merge 2 commits into
CopilotKit:mainfrom
Harbor404:fix/399-built-in-coworker-handoff

Conversation

@Harbor404

Copy link
Copy Markdown
Contributor

What this changes

Fixes #399.

A coworker created as Built in on a deployment with a managed Bot was stored as remote_ag_ui pointing at the managed endpoint. It could answer and be asked, but the handoff tool is minted only inside this deployment's own run loop, so it could not hand work on.

This takes the smaller of the two options in #399:

  • endpoint-less creates carrying a systemPrompt now stay built_in, even when a managed Bot exists;
  • startup repairs existing remote_ag_ui rows whose endpoint equals the configured managed endpoint, moving them to the role description they already have;
  • the repair is idempotent and skips rows with their own auth, so a hosted coworker that happens to share the address is not rewritten accidentally;
  • the agent DTO keeps reporting both the new endpoint-less built-in shape and legacy managed-endpoint rows as builtIn.

The repair is startup code rather than a static SQL migration because MANAGED_AGENT_AG_UI_URL is deployment configuration, not a database fact.

Where it runs

  • New state that outlives a request? No new state. The startup repair updates existing Postgres rows in place.
  • What happens on the second replica? Every replica runs the same idempotent update. The first repairs; later replicas find nothing matching.
  • Anything serialised? PostgreSQL row updates serialise competing replicas; the predicates narrow the update so only the old managed-endpoint shape is touched.
  • Anything fanned out to a browser? No new fan-out.
  • New listener, port, or schedule? No.

Boundary and audit

  • Every acting call still goes through the gateway: resolve, decide, audit, then act.
  • No new refusal path.
  • Nothing new is trusted from the client.

Changelog

  • Added under Unreleased.

Proof

  • Before the fix, the new profile-store and endpoint-to-end handoff regressions failed with remote_ag_ui where built_in was expected.
  • bun test server/tests/agent-profile-store.integration.test.ts server/tests/agent-handoff-endtoend.integration.test.ts: 31 pass, 0 fail.
  • Affected handoff/routes/runtime suite: 236 pass, 0 fail.
  • Existing app built-in edit/API regressions: 9 pass, 0 fail.
  • bun run typecheck: app, server, worker pass.
  • Changed-file Biome lint: clean.
  • The full server suite was not green in this environment: 3552 pass with environment-dependent failures (live provider tests and a timeout under parallel load). The tenant-package failure from a Unicode worktree path passed in isolation after moving the worktree to an ASCII path; composio-transport plus tenant-package: 167 pass, 0 fail.

…rker-handoff

# Conflicts:
#	CHANGELOG.md
#	server/src/index.ts
@davidmckayv

Copy link
Copy Markdown
Contributor

Closing. #399 is an open design question the maintainers have not decided, and this PR picks an answer for it. It also adds repairBuiltInCoworkers, run on every server start (server/src/index.ts), which rewrites existing remote_ag_ui coworkers pointing at the managed endpoint into built_in rows running on their role description, with no audit row. That silently changes what existing coworkers run on. We are not taking it.

@davidmckayv davidmckayv closed this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

A coworker created as Built in still cannot hand work on

2 participants