Conversation
…okens, HELLO auth, SafeFilePath, .aiignore Cycle 8 autonomous hardening for /trios: - KeychainSecrets.swift: generic macOS Keychain wrapper for small secrets. - GitHubAPIClient.swift: remove GITHUB_TOKEN env fallback; read token from Keychain. - MeshAuth.swift: remove TRIOS_MESH_API_TOKEN env fallback; read token from Keychain. - trios-meshd (submodule): verify HELLO src, MAC, and freshness before accepting beacons. - SafeFilePath.swift: default allowMissingBase to false. - CladeGuard.swift: remove allowMissingBase: true from snapshot validation. - .aiignore: exclude secrets, .trinity runtime state, build artifacts. - Extend AGENT-V-WAIVER expiry from 2026-07-28 to 2026-12-31 across mesh BR-OUTPUT files. Verification: cargo test (270+), cargo clippy -D warnings, build.sh OK.
- Add ./trios executable launcher: build, start backend, open app, health check - Make ecosystem.config.js portable via TRIOS_ROOT / __dirname - Update LAUNCH.md and QUICK_START.md with one-command usage Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Manifest integrity: SHA-256 + size per entry, verify on read - Atomic import with rollback on partial failure - Duplicate resolution: replace / merge / skip - Large-file safety: 16 MiB cap for log/diagnostic files - Progress overlay and cancellation hook - Version compatibility: schemaVersion, minReaderVersion - Expanded error taxonomy with LocalizedError descriptions - ASCII-only sanitization across touched source files Closes #T27-EPIC-001
…, A2A rings, and chat history - Integrate SR-00/SR-01/SR-02 rings, BR-OUTPUT canon, and local-auth token-family store. - Add BrowserOS server local-auth routes, chat-history service, task-queue, A2A registry, retry/CORS/request-auth hardening. - Update build scripts, docs, and .gitignore; keep generated artifacts out of tracked tree. - All server sources pass Biome lint/format gate. Closes #TRIOS-PORTABLE-LAND-001
Mark task done in done.json and clear active.json. Closes #TRIOS-PORTABLE-LAND-001 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add TRIOS_RELEASE_MANIFEST.md and .claude/plans/trios-portable-land-001-report.md with verification results, clean-machine blockers, and three land variants. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add trios/docs/INSTALLATION_README.md with prerequisites, install steps, permissions, troubleshooting, and migration warnings. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Update TRIOS_RELEASE_MANIFEST.md and landing report with the discovery that origin/dev has diverged via the agent-core extraction and trios switchover. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
… /doctor --model - Stop retrying fatal provider errors (402 balance, 401 auth, invalid model). - Surface actionable chat error messages with fallback model hints. - Add /doctor --model parsing and pass --model to the Claude CLI invocation. - Pin doctor skill to claude-sonnet-4-6 to avoid stale claude-opus-4-6 access issues. - Add ModelConfigurationStore fallback helpers and ChatFailureTests. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Add provider-aware fallback ordering with cheap floor model last. - Send OpenRouter native array for server-side failover. - Refactor ChatViewModel.sendMessage to retry once on model-unavailable/invalid-model errors. - Insert a user-visible banner when failover occurs; restore original model if retry fails. - Clean up stale claude-opus-4-6 references in BrowserOS agent catalog and CLI provider. - Add ChatViewModel failover tests and ChatRequestBuilder OpenRouter tests. Closes TRIOS-AUTO-FAILOVER-011 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Add .logs Trios999Destination with petal 2 (Cmd+3) and world LOGS. - Create BR-OUTPUT/LogsTabView.swift showing next-loop variants + unified log viewer. - Wire LogsTabView into QueenTabView hosted routes and build.sh LEAN_BR_OUTPUT. - Update trinity QueenUILib TriangleLogo.swift: EXPLAIN -> LOGS. - Update trinity_999_tab_map_test for 7 routes and .logs shortcut 3. Verification: - bash trios/build.sh passes (114 Swift files, QueenUILib rebuild). - cargo test --workspace passes. - cargo clippy --workspace --all-targets --all-features -- -D warnings clean. - Standalone trinity_999_tab_map_test passes. - trios.app relaunched; menu-bar logo process alive. Co-Authored-By: Claude Opus 4.8
- Add ModelHealthService actor with cached TTL probes: - Cloud providers: tiny max_tokens:1 ping via chat completion endpoint. - Ollama: free /api/tags existence check. - Two-failure threshold before marking unavailable. - Extend ModelConfigurationStore with unhealthyModels, healthStatus, refreshHealth, selectFirstHealthyModel, and invalidation on provider/URL/key changes. - Preflight check in ChatViewModel.sendMessage switches to first healthy fallback with a visible system banner before burning a real request. - Mark failing model unhealthy after any transport error for next preflight. - Models tab: Health button, unavailable badges, disabled unhealthy rows, badge on active model. Verification: - bash trios/build.sh passes (115 Swift files). - cargo test --workspace passes. - cargo clippy clean. - trinity_999_tab_map_test passes. - trios.app relaunched; health endpoint ok. Next loop options: background poller, persistent reliability scoring, provider-native status feeds. Co-Authored-By: Claude Opus 4.8
Add ModelHealthServiceProtocol so tests can mock probe results. Add ChatFailureTests for preflight switching, error marking, and no-switch healthy path. XCTest unavailable in this toolchain; production build, cargo test, and clippy pass. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add BackgroundHealthPoller actor that probes all available models every 60s. Wire poller into ModelConfigurationStore lifecycle: start on init, restart after provider/URL/key changes. Update ModelsTabView with Auto toggle and last-check timestamp. Add XCTest coverage for poller, recovery detection, and start/stop toggle. Clade audit + seal pass. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…og pre-check, UI badges, tests - Add ProviderStatusService actor with cached /models checks for OpenAI/Anthropic/OpenRouter and /api/tags for Ollama. - Inject ProviderStatusService into ModelHealthService to skip paid probes for missing/disabled models. - ModelConfigurationStore owns ProviderStatusService, exposes providerStatus(for:), invalidates on endpoint/key/provider changes. - Add hasProviderCatalog to ModelProvider. - ModelsTabView shows 'disabled' / 'not in catalog' badges after Health refresh; refreshes badges on catalog change. - XCTests: missing/disabled status skips paid probe, OpenRouter catalog parsing, status invalidation. Closes TRIOS-CHAT-PROVIDER-FAILURE-014 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- ModelReliabilityService actor with EMA scoring and bounded outcome history - MemoryStore v3 schema with encrypted model_outcomes table - MemoryStoreReliabilityAdapter bridging outcomes into agent-memory.sqlite3 - Async, reliability-ranked fallbackModels/runtimeConfiguration in ModelConfigurationStore - ChatViewModel records send/failover outcomes and awaits async runtime config - XCTests for EMA, ranking, persistence, reset, and history limits - Update E2E schema-version assertion and mock memory store stubs Verification: - ./build.sh passes (swift test skipped: no XCTest in CLI tools) - cargo test --workspace passes - cargo clippy --workspace clean - clade-audit 0 findings - clade-seal SEAL VALID - trios.app relaunched and healthy Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Add ModelCostService with ModelCostTier (any/free/cheap/premium) - Extend ModelReliabilityService.bestModel() with tier filtering - Add isPredictiveSelectionEnabled + preferredCostTier to ModelConfigurationStore - Add Smart model selection UI to ModelsTabView - Add ModelCostServiceTests and bestModel coverage - Stop e2e keychain password dialogs via TRIOS_E2E_DISABLE_KEYCHAIN=1 - Fix clade-build LEAN_BR_OUTPUT whitelist drift for LogsTabView.swift Closes #T27-EPIC-001 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Add ModelContextService.largerOutputCandidates(...) for output-ceiling-first candidate search. - Insert output-budget routing phase into resolveContextRoutingDecision before context-window routing. - Surface routing cause via lastContextRoutingReason (output budget vs context window). - Update ChatViewModel routing label to use the recorded reason. - Add tests for effectiveOutputCeiling, isOutputBudgetSaturated, and output-budget routing. - Run Trinity gates: build, mesh tests, clade-build, clade-audit (0 findings), clade-seal valid. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Closes gHashTag/trios#1086 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Limit build_*.log and chat_sse_e2e_build_*.log to 10 newest files in .trinity/logs. Previously every build and chat-SSE e2e run created a new log, flooding the LOGS tab with 120+ stale build artifacts. Closes gHashTag/trios#1087 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Add LogSourceCategory (runtime/service/build/test/artifact) and classify sources - Default LOGS tab hides build/test artifacts; add Show build/test logs toggle - Cap artifact log families at 10 files in build.sh, run_queen_autonomous_test.sh, clade-build - Add XCTest coverage for classification and filtering - Cleanup legacy cycle logs and stale archive Closes browseros-ai#2046 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Add scripts/cleanup_artifact_logs.sh dry-run-by-default cleaner - Lower artifact cap from 10 to 5 files per family - Add 7-day age eviction for artifact logs - Scan .worktrees/*/trios/.trinity/logs for stale build logs - Wire cleaner into build.sh, run_chat_sse_e2e.sh, run_queen_autonomous_test.sh - Update clade-build binary to keep 5 logs and evict logs older than 7 days Closes browseros-ai#2047 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Closes browseros-ai#2047 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Extend LogRotationPolicy with maxArchiveAgeSeconds and maxAgeBeforeRotationSeconds - Add .audit, .security, .experience static policies - Add rotateAuditLogs() for event_log, akashic-log, local-auth-audit, episodes - Add cleanupOldArchives() to prune .archive.<ts>.zlib files older than retention - Wire rotateAuditLogs() into AppDelegate.applicationDidFinishLaunching and loadLogSources - Update LogsTabViewTests for age-based rotation and cleanup Closes browseros-ai#2048 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…sing bees of its own writes Two bees in parallel, no code from me. The signing keychain locks on sleep, and `codesign` then puts a password dialog in front of every dev build. The stable certificate exists for the release, which reaches the real Keychain at runtime; dev reads its secrets from `~/.trios-dev/secrets` and never needed it. Dev signs ad-hoc now and cannot raise that dialog at all. The same step had a worse failure. Interrupt `codesign` - a timeout did it to me twice - and it leaves a `.cstemp` beside the file it was signing. The bundle is then signed but invalid, macOS silently refuses to launch it, and the cassette gate reports `trios-dev never started` on all four cassettes with no way to guess why from the message. Stale temp files are cleared before signing now. Proven by planting one: the build cleans it and `codesign --verify --deep --strict` returns zero. The other bee closed the second false accusation in three cycles. A write arrives as an absolute path and the boundary is written relative, so a bee writing the one file it owns was reported for leaving its lane on every single run. Paths are made relative to the repository root before the comparison. Both directions driven rather than read: a bee writing inside its boundary now produces no out-of-bounds event where it always produced one, and the cassette that plants a genuine violation still catches it. Closes gHashTag/trios#1114 Closes gHashTag/trios#1115
…le verdict on the brief Refs gHashTag/trios#1115
…s nothing behind Two bees in parallel, no code from me. The sidebar redrew on a state change and the master chat did not, so the two surfaces disagreed about what the swarm was doing. The board now moves with the registry: a bee that starts working leaves the Waiting section, a bee that finishes joins it, and neither needs a reload or a chat switch. Proven by driving a real transition rather than by reading the binding, and the proof was broken to check it: inverting `needsQueenAttention` fails four assertions by name - the bee moves to the wrong section, the Waiting section loses it, the Working section keeps it, and rejected work stops asking for the Queen. My first attempt at that mutation left an unbalanced brace, so the suite failed to compile and proved nothing; that is the second time this week a break test lied by not applying. The other bee closed the case where a worker dies mid-edit and its writes stay in the tree with no branch and no owner, which is how a later bee inherits somebody else's half-finished lines and a person running `make` meets an error nothing accounts for. Ratchet 455 -> 473. Closes gHashTag/trios#1098 Closes gHashTag/trios#1112
Five bees this cycle, no code from me. The observer measured what moved in the shared working tree since a bee started. With one bee that is its work; with two, each diff contains the other's, so last cycle both bees were reported for leaving a boundary neither crossed. Measured writes are filtered to the task's own lane now. The first attempt at that was inert and the reason is worth recording: the bee added the parameter to its own file and both call sites live in a file another bee owned, so the filter defaulted to off and never ran. Third time this shape has cost a cycle - a signature changes in one lane and the caller sits in another, and nothing in a bee's own cycle compiles the pair. Verified by re-running two bees after the wiring landed: zero accusations where every previous parallel run produced them, each branch carrying only its own file. The trade-off is real and is not swallowed: filtering by lane makes measured writes blind to a genuine out-of-bounds write by that same bee, leaving only tool names, which cannot see a shell write - the hole measurement was introduced to close. Recorded on gHashTag/trios#1116 rather than quietly accepted. Also landed: Accept and Cancel on each bee card, a collapse for the board, the Queen bringing three options to her own chat after a self-audit, and two documents a bee wrote about what a reviewer can judge and how an interface drifts between lanes. Ratchet 473 -> 504. Closes gHashTag/trios#1116
A bee wrote the proof for gHashTag/trios#1097, which landed as code last cycle with nothing exercising it. The suite now drives the arrival: each option carries a subject, a reason and the command that starts it, the message says a chat will not open without consent, and a second arrival does not repeat the first. Ratchet 504 -> 522. The dashboard is a different story and it is written down rather than papered over. Three bees have now been sent at gHashTag/trios#1118 and `FullscreenChatWorkspace` still has no caller. The first added buttons to the board instead; the second changed nothing and its reviewer scored the board's toggle as the entry point; the third committed a test and not the thing the test is about. The criterion is mechanical now - `git grep` must find a call outside the file - and the fault is mine for writing it loosely enough that a nearby surface satisfied a plausible reading three times. Refs gHashTag/trios#1097, gHashTag/trios#1118
…e about it was wrong
The dashboard was never unwired. `FullscreenChatWorkspace` is the name of a
file, not a type: the only struct in it is `AdaptiveChatWorkspace` at line 6,
and `QueenTabView` presents it. So `git grep "FullscreenChatWorkspace("` found
nothing because there was nothing to find, and the mechanical criterion I wrote
demanded something impossible. Three bees were sent after that phantom; the one
that changed nothing was right.
What actually hides it is a width. `ChatWorkspaceLayout.expandedThreshold` is
760 points: below that the compact supervisor bar is shown, at or above it the
full `QueenDashboardView`. The app lives in a narrow panel, so the dashboard was
one window-resize away and nothing said so.
A bee added the control that opens it from the compact panel and the way back.
The guard for it does not work, and that is recorded rather than smoothed over.
Removing the call to `dashboardToggleButton` leaves the suite green: the test
greps the source for "Open Dashboard" and `isDashboardExpanded`, which are still
present in the declaration it no longer uses. A source-text check cannot tell
declared from used - the defect class this repository has closed three times
elsewhere and just reintroduced in its own test.
Ratchet 522 -> 526.
Refs gHashTag/trios#1118
Last cycle's guard greped the source for "Open Dashboard" and `isDashboardExpanded`, so removing the call to `dashboardToggleButton` left the suite green - the strings survive in a declaration nothing calls. It could not tell declared from used, which is the defect class this repository has closed three times elsewhere. The machinery for the real question was already here. `QueenSelfAudit.deadSymbols` counts occurrences against a threshold: a declaration alone is one, a declaration plus a call is two. The guard now demands two, and the failure says so - "dashboardToggleButton appears 1 times (need >= 2: definition + body reference)". Proven by the break that defeated the old one: remove the call from the compact body and the suite fails. Also landed: a bee's work on telling an empty reviewer answer apart from a criterion nobody asked about. Its reviewer confirmed one of two criteria and would not commit to the other, so gHashTag/trios#1117 stays open. Refs gHashTag/trios#1117, gHashTag/trios#1118
…ks anyone The user asked for Touch ID instead of typing the password. Touch ID cannot be wired to that dialog: macOS offers biometrics for "allow access to this key" in the login keychain, and a secondary keychain raises "enter the keychain password", which has no biometric path. The right repair was underneath it anyway. The password is not a secret and never was - `scripts/create_dev_signing_identity.sh` hardcodes `trios-dev` and explains why in its own header: the keychain holds one public self-signed development certificate and nothing else. So the build can open it, and then there is no dialog to put a fingerprint on. Proven the hard way round: the keychain was locked deliberately with `security lock-keychain`, `make release` was run, and it produced a real signature that `codesign --verify` accepts with zero SecurityAgent processes raised. Every release build tonight before this one stalled on that dialog, and one of them left the bundle unlaunchable when a timeout killed codesign mid-signature. Also landed: the reviewer's brief now carries the files a criterion names rather than only the files in the boundary, and a guard against a signature changing in one lane while another lane's caller goes stale. Closes gHashTag/trios#1120 Refs gHashTag/trios#1119, gHashTag/trios#1111
…a bold asterisk Three defects in one chain, each hiding the next, each found only by driving the same task again. The brief carried the files in the boundary but not the files a criterion names, so a task whose contract is about the application and whose lane is a test file could not be judged at all. That was browseros-ai#1119. Fixing it changed nothing, because criterion paths were resolved against the git root while they are written against the project root: `BR-OUTPUT/...` became `/Users/playra/BrowserOS/BR-OUTPUT/...`, which does not exist, and the miss was swallowed by a `fileExists` guard. The contract had explicitly asked for a named file that is missing to be reported as missing rather than skipped; had that been honoured, the wrong root would have been visible immediately instead of looking like a criterion with no paths in it. That was browseros-ai#1121. With the right root the reviewer finally answered - 2733 characters instead of 198, four verdicts a person can read - and the parser reported zero. It requires a line to begin with the criterion's number, and the model writes `**1. met**`. Its own comment listed what it accepted, bare and checkbox, and markdown was never in the list. That was browseros-ai#1122. Driven the whole way: the same re-review that produced `parsed=0` three times now produces `asked=4 parsed=4 recorded=4, unchecked=none`. Break test: removing the markdown tolerance fails three assertions by name. Ratchet 526 -> 538. Closes gHashTag/trios#1119 Closes gHashTag/trios#1121 Closes gHashTag/trios#1122
…bout Fourth link in the same chain, and the same shape as the three before it: the question did not arrive, and the answer read as though the work were bad. `ChatViewModel.swift` is 5,293 lines and the brief carried the first 500. The reviewer said so plainly - "the file is truncated at 500 of 5293 lines, I can see the data structure declarations near the top, but the actual logic that implements the acceptance criteria is in the truncated portion" - and returned "could not check" for everything. Declarations live at the top of a file and behaviour lives below, and a criterion is always about behaviour. The excerpt now follows the names a criterion mentions rather than the start of the file. Driven on the case that failed: the same re-review returned two verdicts of three, and the reviewer quoted the implementation rather than the declaration. The remaining criterion is genuinely unmet, so gHashTag/trios#1117 stays open on it. Incidental proof of another fix: a worker died on a timeout mid-review and the log recorded `queen.worker.died.clean` - died and changed no files, tree clean. That is gHashTag/trios#1112 doing its job in a case nobody arranged. Closes gHashTag/trios#1123
A bee proved the interface-drift guard correctly - assemble the combined tree, confirm the build fails when a signature moves in one lane and the caller stays stale in another - and put it in the logic suite, where it called `verifyCombinedBuild` twice. Each call runs the compiler. A suite that used to finish in about a minute stopped finishing at all: exit 124 at 580 seconds. A gate that does not terminate is not a gate, and the mistake is an easy one to repeat: the proof was right and its home was wrong. It lives behind `make drift-guard` now, named in the help as slow and outside the fast suite. The fast suite is measured, not assumed: 68 seconds, 538 checks, exit 0. The slow target starts and compiles; I have not watched it to the end, because it outlasts the ten minutes I can hold a command open, and I am not going to claim a result I did not see. Also this cycle, and it corrects me rather than a bee: I closed gHashTag/trios#1123 on a single run. The excerpt follows the changed regions, so it works when there is a diff and falls back to the first 500 lines when there is not - and a re-review of finished work is always an empty diff, which is exactly where the truncation hurts. Filed as gHashTag/trios#1124. Closes gHashTag/trios#1125 Refs gHashTag/trios#1111, gHashTag/trios#1124
… reviewer argues against Two weak spots found by reading the field rather than by breaking something, and both were already costing this project. A verdict was a claim with no expiry. `criterionVerdicts` is stored on the task, so a `met` recorded against one state of the tree stayed `met` after the bee was sent back and rewrote the code, and acceptance answered from a pile of assertions of different ages. The literature names this exactly: persisted state is not verification, because resuming a run that recorded "tests passed" re-asserts the record without re-establishing that it describes the code being merged. A verdict now carries the tree state it was derived against and reads `.stale` against any other - told apart in the block reason from "never checked", because those two ask different people for different work. And the judge was the defendant. The worker runs on glm-5.2 and the reviewer the Queen calls ran on glm-5.2, so the assumptions that wrote the code also graded it. The reviewer is prompted as an adversary now: its job is to find why a criterion is not met, and `met` is only what it failed to refute. The stale rule shipped with no test - removing it left the suite green, exactly as the dashboard guard did two cycles ago - so a bee was sent back for the assertion. It now fails four ways by name: stale rather than met, acceptance blocked, the reason saying it was checked against different code, and the reason not calling it unchecked. Fourth interface drift of the night on the way through: `.stale` is a new enum case and the exhaustive switch over it lives in another lane. `make drift-guard` exists for exactly this and I did not run it before building. Ratchet 538 -> 552. Closes gHashTag/trios#1126, gHashTag/trios#1127
The supervisor surface was opened and looked at for the first time tonight, and it works. In the narrow panel: an OPEN DASHBOARD control at the top, a compact line reading "1 needs you - 0/4 working", and the bee board below it with a WAITING ON YOU section and a card carrying the state, the worker, the branch and an Accept button. Widened, the same plus the full swarm strip with the issue, the branch, awaitingReview and Review. gHashTag/trios#1118 closed on its last criterion, which was readability and could only ever be answered this way. Looking found a defect no test had: the issue number printed as `#1,124`. A SwiftUI `Text` interpolating an Int formats it as a quantity, and an issue number is an identifier - you cannot search for `#1,124` or paste it anywhere. Fixed on both screens that print one. The bee's own assertion for it could not pass: it compared lengths and claimed the identifier was shorter, while `browseros-ai#1129` and `1,129` are both five characters. A test that is false by construction fails the same way a real defect does, and it was caught only because the gate went red. It asserts the shape now - the rendered identifier carries no group separator. Also this cycle: an empty diff no longer sends the reviewer the first 500 lines of a file, and a verdict is bound to the tree state it was judged against. Ratchet 552 -> 559. Closes gHashTag/trios#1129 Refs gHashTag/trios#1118, gHashTag/trios#1124
…etry has a guard Acceptance judged a branch that builds on its own. What lands is the branch merged with everything else, and nothing built that - which is how four interface drifts got through in one night, each one a bee changing a signature in its lane while the caller sat in another. The combined state is assembled and built before a task can be accepted, and a failure there is named apart from a criterion failure: "does not build together" is not "criterion unmet". gHashTag/trios#1117 turned out to be already done. The one-shot retry on an empty reviewer answer has been in the code for cycles - two bees looked at the task and correctly changed nothing, and I had counted their empty branches as failures to deliver. What was missing was the assertion, and now removing the retry fails by name: "the reviewer transport was called exactly twice (once + one retry), not 1". Ratchet 559 -> 571. Closes gHashTag/trios#1117 Refs gHashTag/trios#1128
…nce is still shut The staleness rule I added two cycles ago blocks every acceptance, and the cause is the shape this repository keeps producing: `treeStateFingerprint` was declared on the task and never written, so `isStale` compared nil against a real snapshot and answered "checked against different code" for everything. Fifth time in a day that a mechanism landed without its wiring, and the worst of the five - the others dropped a result quietly, this one closes the gate. The fingerprint is recorded with the verdicts now and a missing one is told apart from a stale one. Acceptance is still blocked, and the honest reading is that the snapshot is taken over the whole working tree while the Queen writes her own state files between the review and the decision - the same confusion as gHashTag/trios#1102, which cost a false accusation then and costs the whole cycle now. Recorded on gHashTag/trios#1131 with the run that shows it. So the third of tonight's three tasks did not finish: no task has gone through to a merge since gHashTag/trios#1102, and it cannot until this is fixed. Ratchet 571 -> 584. Refs gHashTag/trios#1130, gHashTag/trios#1131
dmitrii-f-t27
added a commit
that referenced
this pull request
Oct 2, 2026
… the next number A key added without a name was stored as an empty label and shown as the bare provider, so the owner's 25th NVIDIA key read "nvidia" above "nvidia #1".."#24". Environment keys are now named by their place in their pool (Z.ai's pool-2 keys become zai #1..#10 instead of #10001..#10010), a key added unnamed or named only after its provider takes the next free number under the add lock, and a managed key saved before numbering is numbered once, compare-and-set, the first time the owner's keys are listed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two workers ran concurrently for the first time — browseros-ai#1093 from 10:21:16 to 10:23:18 and browseros-ai#1098 from 10:21:18 to 10:24:15, two minutes of genuine overlap. Each on its own branch, each with its own file boundary, each committing one file; both branches diffed against the base contain exactly their own file and nothing of the other's, and the working copy never left
feat/queen-supervisor.The green result is not the point. Running them in parallel exposed two defects that cannot occur any other way, which is why neither had ever been seen.
The ownership rule compared boundaries as strings
conflictingTasksusedSet.isDisjoint, sodocsanddocs/livelooked unrelated and both claims were admitted. A write, meanwhile, is judged by containment — so the bee owningdocswas entitled to writedocs/live/x.md, the file the other bee owned. Two writers, one file, and nothing complaining until the merge. The two rules had one notion of "path" each and disagreed.They now share
pathsOverlap, which compares by path component: nested boundaries clash, siblings do not, and a shared prefix (docs/docsite) is not containment. That last part matters — a rule that answered yes to everything would pass every clash test while quietly stopping all parallel work.The Queen was losing bee reports
Six reports arriving at once persisted three. Not late — lost: the check now waits ten seconds and they never arrive. Every caller appends to the same main-actor buffer, so memory was always complete; then each passed its own whole-array snapshot to
save, the saves raced, and the file kept whichever finished last rather than whichever held the most.Writes to her chat are now queued, and each takes its snapshot when it runs rather than when it was queued.
The check that was hiding it
A fixed 300ms sleep. Enough on an idle machine, so the scenario passed every run I had ever done; it failed once in eight under a parallel build. The sleep is now a bounded wait, and the race has a deterministic check instead of a probabilistic one: the mock persister holds the first write to her chat open for two seconds while a second overtakes it. Verified from both sides — it fails with the fix removed and passes with it restored.
Also cleared: sixteen prototype exemptions naming files
939028c91had already deleted. The gate had been failing on them and was right to.Verification
make check— dev app built, cassette suite passed (4 cassettes)Closes gHashTag/trios#1099