Skip to content

fix: modernize worker isolation, dispatch and provider integrations - #274

Draft
seanperkins wants to merge 8 commits into
feat/review-20260927-allfrom
feat/worker-integration-20260928
Draft

seanperkins wants to merge 8 commits into
feat/review-20260927-allfrom
feat/worker-integration-20260928

Conversation

@seanperkins

@seanperkins seanperkins commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

The worker assessment found gaps in checkout isolation, scheduling parity, engine selection, dependency currency and session observability. This PR implements those follow-ups while retaining disposable containerized CLI workers.

Changes:

  • Replace the writable host checkout mount with per-session Git exchange repositories. Reconstruct and validate output in a trusted quarantine; import only the expected branch with ancestry and compare-and-swap checks. Preserve restart recovery even when automatic PR publication is disabled.
  • Share manual queue ordering between server and worker. Reject unsupported engine/runner/role combinations before claims, and make doctor image/credential checks engine-aware.
  • Pin Claude Code 2.1.283, Codex 0.157.1, Gemini 0.61.0 and mitmproxy 12.2.3. Reject proxy target/Host disagreement and provider cleartext requests; stream provider SSE responses.
  • Pin Claude SDK 0.3.283, explicitly select the coding prompt and project settings, improve cancellation and MCP-secret redaction, and require isolated SDK typechecking in CI.
  • Add optional worker/project model selection and session correlation, installed tool version, actual image identity and provider-reported model metadata. Preserve unknown model values when the provider does not report them. Provider-start acknowledgment and process-group cancellation retain retry/lifecycle correctness.
  • Add credential-free image build/version/help/proxy-contract checks in GitHub Actions and operational upgrade/benchmark documentation.

Closes #265.
Closes #266.
Closes #267.
Closes #268.
Closes #269.
Closes #270.
Closes #271.

This draft is stacked on #264 (feat/review-20260927-all), so its diff contains only the worker follow-ups. Launcher issue #272 is addressed separately in #273, stacked on #244. Temporary local composition of both branches built successfully and all three compiled entry points passed missing-configuration startup smoke checks. No PR was merged and no deployment occurred.

Validation:

  • 2,304 tests across 179 files passed on the final local tree, including hostile Git metadata, publication recovery, queue parity, engine matrix, SDK cancellation, proxy policy and CLI lifecycle regressions.
  • Full lint, formatting, app/UI/SDK typechecks and UI build passed; lint retains pre-existing warnings but no errors.
  • Independent subagent review reproduced and verified fixes for oversized import, merge-introduced secret history, answer retry accounting and surviving tool descendants.
  • Local tests used a 20-second timeout and six workers for subprocess-heavy tests. GitHub CI passed on the published head using its normal configuration.
  • All four image jobs passed: Claude, Codex, Gemini and proxy builds, executable checks, and real-mitmproxy contract/startup checks.
  • No local Docker daemon or live provider credentials were used. The new image workflow checks builds and executable/proxy contracts; an authenticated provider canary remains a rollout check.

Rollout considerations:

  • Drain existing containers before restarting workers: old sessions retain their previous mounts. Rebuild worker and proxy images using the documented instructions.
  • Codex/Gemini workers now require containerized CLI mode and --role code; run a separate Claude answer worker.
  • SDK mode remains trusted host-only execution. CLI logs contain sanitized diagnostic metadata rather than verbatim transcripts; SDK summaries remain available with MCP secrets redacted.
  • Git exchanges reject known root host-only paths in exported history, imports above 2 GiB/100,000 object files, and Git operations exceeding 120 seconds. These bounds and operator recovery are documented.
  • If PR feat: precompile host scripts, run one plain node process per service (SYD-268) #244/fix: publish complete compiled worker generations atomically #273 land first, resolve the agent-worker import overlap by preserving both the execution guard and tsImport; use the compiled branch's upward repo-root discovery. The co-located CLI wrapper path works in source and compiled generations.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant