Skip to content

feat(contracts): add managed launch identity envelope - #18

Merged
nullStack65 merged 5 commits into
mainfrom
envfix/managed-launch-host-identity-20261001
Oct 2, 2026
Merged

nullStack65 merged 5 commits into
mainfrom
envfix/managed-launch-host-identity-20261001

Conversation

@nullStack65

Copy link
Copy Markdown
Owner

Summary

  • add additive provider key-ID and structured provider host identity contracts
  • add fail-closed managed-launch qualification and exact drift comparison
  • keep provider snapshots backwards-compatible with optional fields

Scope

This is the independent host/identity envelope slice from the managed-launch design. It does not modify PR16, provider adapters, settings, live install, daemon, network, or credentials. No provider-issued key ID exists yet, so no managed launch is claimed qualified.

Verification

  • git diff --cached --check passed
  • focused Vite+ tests added in packages/contracts/src/providerIdentity.test.ts but could not execute because dependency installation exhausted local disk (ENOSPC); generated worktree dependencies were removed.

Model/harness: GPT-5 / Codex.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: nullStack65/t3code/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 5b05deec-db4f-421b-9d35-cde16e37608a

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L labels Oct 2, 2026

@nullStack65 nullStack65 left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

FAIL — the focused runtime test passes (4/4), but the contracts typecheck fails on this PR’s touched test file. vp run --filter @t3tools/contracts typecheck reports a new narrowing error at packages/contracts/src/providerIdentity.test.ts:88: after checking qualifyManagedProviderLaunch(first).qualified, the code calls qualifyManagedProviderLaunch(first) again and accesses .identity; TypeScript cannot carry the discriminant across the second call (Property 'identity' does not exist on type 'ManagedProviderLaunchQualification'). The parent commit typecheck is clean for this file, so this is introduced by PR18 and blocks CI/type-safe builds. Capture the qualification result once (e.g. const qualification = ...; if (qualification.qualified) ...). I found no additional runtime/schema compatibility defect in the implementation after reviewing the surrounding contracts; the NUL-safe namespace/ID comparison and duplicate normalization behave as intended. Please fix the compile error and rerun contracts typecheck.

@nullStack65
nullStack65 force-pushed the envfix/managed-launch-host-identity-20261001 branch from a882d78 to a6ac97f Compare October 2, 2026 03:17

@nullStack65 nullStack65 left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

FAIL (exact head a6ac97f). The prior typecheck blocker is still present: vp run --filter @t3tools/contracts typecheck reports TS2339 at packages/contracts/src/providerIdentity.test.ts:96 because qualifyManagedProviderLaunch(first) is invoked in the if condition and then invoked again before accessing .identity; the discriminant does not narrow across the second call. It also reports the existing test’s unbranded host arguments (TS2322/TS2345), so this touched test file is not type-safe. The parent commit bb1f0c7f already had these errors, and this head does not fix them. Focused runtime tests pass: vp test run packages/contracts/src/providerIdentity.test.ts apps/server/src/provider/Layers/ProviderRegistry.test.ts = 2 files / 57 tests. git diff --check origin/main...HEAD passes. I reviewed the full design: registry centrally stamps persisted environmentId + configured instanceId on live, cached/fallback, merged, and unavailable snapshots; cache hydration preserves the fallback’s current host envelope; empty managed key IDs are rejected by the non-empty identity schema and qualification; normalization uses deterministic code-point ordering and namespace-separated sets with NUL-safe comparison; optional wire fields preserve legacy snapshots. Please fix the touched test typecheck errors before merge.

@nullStack65 nullStack65 left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PASS (exact head ce903c2). The prior managed-identity test failures are resolved: branded EnvironmentId/ProviderInstanceId fixtures now typecheck, and the duplicate qualification call is replaced with stable narrowing. Focused managed-identity/registry evidence is green (reported 71/71 by the validation run; my directly scoped registry/identity/cache run passes 63 tests across 3 files). The only remaining diagnostics observed in the desktop filter are two TS6307 errors involving scripts/build-desktop-artifact.ts and scripts/apply-web-brand-assets.ts; PR18 does not touch desktop tsconfig or those scripts, so they are unrelated baseline/tooling diagnostics and should not be attributed to this PR. git diff --check origin/main...HEAD passes. Runtime review confirms central stamping of persisted environmentId plus configured provider instanceId across live, cached/fallback, merged, and unavailable snapshots; cache hydration retains the current fallback host envelope; empty managed key IDs fail closed; sorting is deterministic and tuple comparison is NUL/collision-safe; optional wire fields preserve legacy snapshots. No remaining PR-scoped correctness issue found.

@nullStack65
nullStack65 force-pushed the envfix/managed-launch-host-identity-20261001 branch from ce903c2 to fba4bb5 Compare October 2, 2026 04:09

@jeffreysmithclosura jeffreysmithclosura left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed exact head fba4bb5ca0b38b7b7d45614d5eb080f1dbeb9dcc against base 0975683e984a65612f5ab18a67c413b899219098. Pass. The rebase retains the managed identity contract: subject, provider-issued namespace-qualified key IDs, and provider host instance identity remain separate; missing components fail closed with explicit reasons; no secret/email/path/PID/hash/generated UUID fallback is used. Provider host identity is centrally stamped from persisted environmentId plus providerInstanceId across live, cached, and unavailable paths. Rotation/drift comparison is exact and namespace-preserving, and optional schema/export changes remain backward-compatible. Local proof: git diff --check origin/main...HEAD passed and the two requested focused test files passed (57/57). Exact-head GitHub status snapshot reported CodeRabbit success with no pending status.

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

Provider Metric Main baseline This PR Impact PR ceiling
Codex Total thread wire 13.5 KiB 13.5 KiB −29 B (−0.2%) 15.1 KiB ✅
Codex Thread snapshot wire 7.1 KiB 7.1 KiB −1 B (−0.0%) 7.3 KiB ✅
Codex Live turn WebSocket wire 6.4 KiB 6.4 KiB −28 B (−0.4%) 7.8 KiB ✅
Codex Live turn WebSocket decoded 56.3 KiB 56.2 KiB −44 B (−0.1%) 66.4 KiB ✅
Codex Live turn messages 10 9 −1 (−10.0%) 21 ✅
Claude Total thread wire 13.5 KiB 13.5 KiB +23 B (+0.2%) 15.1 KiB ✅
Claude Thread snapshot wire 7.1 KiB 7.1 KiB +6 B (+0.1%) 7.3 KiB ✅
Claude Live turn WebSocket wire 6.4 KiB 6.4 KiB +17 B (+0.3%) 7.8 KiB ✅
Claude Live turn WebSocket decoded 57.0 KiB 57.0 KiB 0 B (0.0%) 66.4 KiB ✅
Claude Live turn messages 9 9 0 (0.0%) 21 ✅

Baseline: 0975683 · PR result: 74d6fac · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 113.9 KiB
  • Claude decoded thread snapshot: 114.6 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@jeffreysmithclosura jeffreysmithclosura left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PASS — exact head 74d6fac against base 0975683.

Reviewed the full 7-file diff, including the repaired isolated ProviderRegistryIdentity.test.ts restructuring. Provider subject, namespace-qualified provider key IDs, and persisted host identity remain separate; qualification fails closed for missing subject/key/host; comparison detects subject, key-set, and host drift while ignoring session/access-token rotation; key-set comparison is namespace-preserving and NUL-safe; optional wire fields preserve legacy snapshots; no secret/path/PID/hash/generated-UUID fallback is introduced. Registry stamping covers fallback/cache, live refresh, stream updates, and unavailable providers.

Local evidence:

  • vp check on all 7 touched files: pass
  • focused contracts/identity/registry tests: 3 files, 57/57 pass
  • vp run --filter @t3tools/contracts typecheck: pass (repository suggestions only)
  • vp run --filter t3 typecheck: pass (repository suggestions only)
  • git diff --check: pass

Exact-head CI snapshot was inspected but not treated as fully green: Check/Test Server 1/2/3 and other completed checks passed, while the CI Test job remained pending. No PR-scoped correctness finding remains.

@nullStack65
nullStack65 merged commit 58de908 into main Oct 2, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants