HOLD: harden disabled AEON Aspect workers (no live activation)#2346
HOLD: harden disabled AEON Aspect workers (no live activation)#2346StephGlansberg wants to merge 22 commits into
Conversation
2838194 to
4ef8526
Compare
|
@wesbillman — requesting review as a recent Ready for maintainer review at final head The branch remains based on current Final-head proof:
This remains a source-only, disabled-by-default package. A maintainer must approve the current fork workflow runs and a Current head workflow approvals:
Maintainer CLI equivalent: gh api -X POST repos/block/buzz/actions/runs/29947624577/approve
gh api -X POST repos/block/buzz/actions/runs/29947624599/approvePlease approve/run workflows and review when available. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4ef8526d45
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
420ca5f to
011c25e
Compare
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 47f4b73aaa
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
1 similar comment
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b234dd188b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3d13c62d53
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Final-head review request for Please focus on the kind-39000 admission parser's canonical selection and strict singleton-tag handling, plus the trusted inbound-event and receipt-correlation boundaries. Local final-head proof: 600/600 HOLD remains in force: no live activation, Gateway/session/config mutation, or canary is authorized by this PR. |
|
@codex review Final-head request for d62d765. The two delayed findings are fixed and their threads resolved: receipt mode now requires verified owner authority before startup, and no-argument LaunchAgent rendering is fixture-backed and byte-for-byte tested. Local proof: 601/601 buzz-acp, Node 10/10, clippy green, prior full just ci green, current pre-push green. HOLD: no live activation or Gateway mutation. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c4f6ca651f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Final-head request for 6ff7958. The latest multi-reply-anchor finding is fixed and resolved: exactly one canonical reply tuple is required. Proof: 602/602 buzz-acp, focused 3/3, clippy/pre-push green, prior final-lineage just ci green, independent ACCEPT. HOLD: no live activation or Gateway mutation. |
|
Codex Review: Didn't find any major issues. Nice work! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Signed-off-by: StephGlansberg <StephGlansberg@users.noreply.github.com>
Signed-off-by: StephGlansberg <StephGlansberg@users.noreply.github.com>
Signed-off-by: StephGlansberg <StephGlansberg@users.noreply.github.com>
Signed-off-by: StephGlansberg <StephGlansberg@users.noreply.github.com>
Signed-off-by: StephGlansberg <StephGlansberg@users.noreply.github.com>
Signed-off-by: StephGlansberg <StephGlansberg@users.noreply.github.com>
Signed-off-by: StephGlansberg <StephGlansberg@users.noreply.github.com>
Signed-off-by: StephGlansberg <StephGlansberg@users.noreply.github.com>
Signed-off-by: StephGlansberg <StephGlansberg@users.noreply.github.com>
6ff7958 to
301928a
Compare
|
@codex review Rebased final-head request for 301928a on current block/buzz main 6d04d27. Rebase was conflict-free. Exact-head proof: 602/602 buzz-acp, Node 10/10, clippy green, full just ci green, pre-push Desktop 3383/3383 and mobile 528 passing with one existing skip, independent source review ACCEPT, no unresolved threads. HOLD: no live activation or Gateway mutation. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 301928a936
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Signed-off-by: StephGlansberg <StephGlansberg@users.noreply.github.com>
|
Codex Review: Didn't find any major issues. You're on a roll. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
…kers # Conflicts: # crates/buzz-acp/src/config.rs # crates/buzz-acp/src/lib.rs # crates/buzz-acp/src/pool.rs
HOLD — no live activation
This PR is a disabled source checkpoint for six AEON Aspect
buzz-acpworkers. It does not install, load, start, restart, switch, or mutate any live Gateway, session, token, worker, Fleet policy, or Concilium path. It makes no Voxis, A2A, or live-canary claim.What it hardens
ttl, valid futurettl_deadline, deterministic latest kind-39000 selection, strict singleton-tag parsing, exacthtag, and fail-closed revocation on expiry/archive/membership removal/query failure. Stale malformed metadata can recover through a newer valid canonical event; malformed canonical or unorderable evidence remains closed._meta.buzz.inboundEvent; invalid, ambiguous, multi-event, cancelled/merged, and heartbeat turns fail closed with no envelope.--require-existing,--no-memory, and--no-base-prompt; Gateway remains the identity, tools, skills, memory, and compaction owner.bypassPermissionsposture. No Buzz MCP/model/system/team/initial prompt is injected.h, Architect author, and huddle mention gates.O_NOFOLLOWAspect key reads with current-user/0600/expected-pubkey checks.RunAtLoad=false,KeepAlive=false, Fleet placeholders, and one-worker rollback labels.load_rules()and Clap parsing tests plus package validators. Receipt mode now requires verified owner authority before startup, and no-argument LaunchAgent rendering uses the checked-in OSS fixture.Proof
node --test deploy/local/aeon-aspects/worker.test.mjs— 10/10node deploy/local/aeon-aspects/validate.mjs— OKcargo test -p buzz-acp— 602/602, including canonical metadata ambiguity/recovery, stable-thread-root receipt isolation, two-turn thread-root, top-level-DM, and trusted-envelope contractscargo clippy -p buzz-acp --all-targets -- -D warnings— greenjust ci— format, workspace clippy, Desktop/web/mobile checks, Rust/JS tests, Desktop/Tauri builds, and mobile tests green on final headrust-tests,desktop-tauri-test, and branch-skew — greengit diff --check— cleandetect-secrets+ manual changed/generated-file scan — no secrets; reported examples/test hex onlyDoes not prove / resume blockers
Nexus-only resume checklist
After Fleet releases the runtime lock, all of these are required before requesting a separate Architect Nexus-only canary GO:
agent:main:buzz-privateand currentopenclaw acp --require-existingflag behavior.sessionKeyand a fresh per-promptrunId.aeon-buzzreply path is disabled and no Gateway switch/restart/validation is in progress.org.aeon.buzz-acp.nexusif any proof fails.The other five workers remain disabled and require separate later authorization.