Skip to content

fix(model): save hosted End before stopping admitted sends - #148

Draft
andersalm wants to merge 13 commits into
developfrom
fix/0.7.1-hosted-end-admission
Draft

andersalm wants to merge 13 commits into
developfrom
fix/0.7.1-hosted-end-admission

Conversation

@andersalm

@andersalm andersalm commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Runtime saves the owner’s End decision before it cancels admitted hosted sends. A failed save preserves the send; cancellation after the save preserves End. System deletion and staged discard recheck admin authority after waits and announce committed changes before credential cleanup or provider refresh.

Durable End remains on Unix; send draining matches the supported macOS transport. The broker test fixture consumes the complete HTTP request before replying and closing, so split header/body writes preserve the response. The test also owns child cleanup on failure.

Current head 3f75b2d4efea23d351ef492314b5bdb7eb0aecab includes a normal develop merge and already contains the broker-fixture repair. Four basic gates and fragmented GET/token-count fixture proof pass; exact Rust execution awaits current CI. Accepted focused End tests and prior security reviews remain qualified evidence.

Draft until green checks, then required reviewer irzhywau. Installed OpenRouter/Venice journeys, platform acceptance and the inherited cross-Home job-create key gap remain open in #85. Refs #85 and #84. Approved target: develop.

Serialize Inbox and System End with hosted admission, cancel unresolved sends, and guard competing decision transitions. Focused egress, Inbox, and System tests pass. An End canceled or failed after signaling can still interrupt an admitted send before commit; installed concurrent Assistant proof and that availability case remain open.

(cherry picked from commit 1825dc4)
@andersalm andersalm added this to the 0.7.2 milestone Sep 30, 2026
@andersalm
andersalm marked this pull request as ready for review September 30, 2026 22:29
@andersalm
andersalm requested a review from irzhywau September 30, 2026 22:29
@andersalm
andersalm marked this pull request as draft September 30, 2026 22:38
@andersalm

Copy link
Copy Markdown
Contributor Author

Back to draft: CI run 36767214431 fails lint, tests and the source-home jobs. Under the weekly rules a PR asks for review only when its checks are green. Mark it ready again when they pass.

@andersalm
andersalm removed the request for review from irzhywau September 30, 2026 22:51
@andersalm
andersalm marked this pull request as ready for review October 1, 2026 13:35
@andersalm
andersalm requested a review from irzhywau October 1, 2026 13:35
@andersalm

Copy link
Copy Markdown
Contributor Author

Independent adversarial review (Claude Opus, run by the operator for Anders, 2 October; different model family from the author).
VERDICT: PASS. The End is saved before sends are cancelled on every path; new sends fail closed; in-flight sends are cancelled; tests cover the refused cases.
Non-blocking: delete may wait up to the 30 s bridge timeout if a provider makes a hosted call inside runs_create (inferred); send cancellation is macOS-only, so state the platform scope in #85.

@andersalm
andersalm marked this pull request as draft October 2, 2026 13:37
@andersalm andersalm modified the milestones: 0.7.2, 0.7.3 Oct 6, 2026
@andersalm

Copy link
Copy Markdown
Contributor Author

Moved to After 0.8.0 with #85: Local AI scope for 0.8.0 is SmolLM2 and Qwen2.5 1.5B (decision 8 Oct, #84).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant