- Narrowly guard _request_privileges() in routes/chat_routes.py against
synthetic requests lacking scope['app'] or auth manager state, safely
returning empty privileges without granting agent privileges.
- Add focused regression test in tests/test_context_resolution_route.py
verifying that requests without app scope do not crash and cannot gain
agent privileges or qualify for compact preview runtime.
- Regenerate website/configuration-reference.md mechanically to align with
current source line numbers.
The chat route repeated the compact (clean v3) eligibility decision inline
to prepare the turn's context resolution, while the agent loop dispatched
on the contract stamp set by a separate, later condition. The two could
drift, and already disagreed for a user whose privileges demote the turn
to plain chat: the route prepared a compact resolution that no compact
runtime used.
src/agent_runtime/runtime_selection.py (no imports) now owns the rule:
- uses_compact_preview_runtime(): clean route requested, contract policy
enabled, agent mode, agent permitted, not an image generation session.
- is_compact_preview_contract() and COMPACT_PREVIEW_MODE for the stamp.
The route evaluates the rule once, before context preparation, where all
of its facts are final (the agent privilege is read through the same
_request_privileges helper the later enforcement uses). That one value
gates the typed context resolution and is the _clean_v3_preview flag that
stamps the contract; inside the agent-contract branch it equals the
previous condition, so stamping behavior is unchanged. The agent loop
dispatches through is_compact_preview_contract(), and the compact runtime's
MODE is the shared constant.
A route-level matrix drives the real agent loop and asserts that route
preparation and compact dispatch agree for compact, escalated, configured
compact/full, regular, TUI, privilege-denied and image-generation turns.
The first checkpoint removed terminal-metrics discovery, but a normal
compact chat turn still ran two context systems: build_chat_context's
legacy untyped lookup (directly or inside maybe_compact) and the typed
resolver inside stream_preview.
Resolve the typed ContextResolution once, at the chat route, before
build_chat_context, using the session's provider credentials. The
predicate mirrors _clean_v3_preview; every input it needs is known at
that point and the native-workspace term cannot veto a requested clean
route. The same object then:
- sizes legacy history shaping in build_chat_context through a new
maybe_compact(context_length=...) override, so no legacy probe runs;
an unknown window still shapes with DEFAULT_CONTEXT but gains no
provenance;
- crosses stream_agent_loop (one new parameter, forwarded only at the
compact dispatch) into stream_preview, which reuses it and probes only
for callers that arrive without one or with one bound to another
route.
ContextResolution now records the endpoint and model it describes
(endpoint URL excluded from repr and metrics). The bare legacy
context_length is never converted into typed evidence.
Credential scoping: origins compare with default ports normalized, an
empty host is never trusted, and the probe client never follows
redirects. Tests cover the configured origin, the server-resolved
Tailscale form, scheme/port/lookalike/userinfo/path origins, redirects,
and secret-free errors, logs and metrics.
The conftest guard now replaces only the resolver's I/O edges (HTTP
client and DNS-capable URL building) instead of the whole probe, and
exposes a context_probe_ledger fixture, so route integration tests run
the real resolver offline and can count metadata requests.
The compact (clean v3) runtime had no effective context window: it learned a
limit only reactively from a provider 400/413 and its terminal metrics carried
no context_length. PR #41 addressed the reporting gap by probing provider
metadata between the last model byte and [DONE], unauthenticated, and folded
known-table and endpoint evidence into one "known" flag.
Resolve the window once, before the first model request, instead:
- src/agent_runtime/context_resolution.py adds a typed ContextResolution
(effective value, evidence class, source, all observations, conflicts,
provider_io, cached, secret-free probe errors). Evidence classes stay
distinct: runtime_confirmed (llama.cpp /slots, /props, or a limit the
provider stated this turn), provider_advertised (models catalog),
operator_declared (client_runtime_context.model_context_window),
known_table, unknown (0, never a default).
- Selection is deterministic: runtime beats provider beats table; an
operator declaration caps measured evidence and replaces weaker evidence.
Disagreements are recorded as conflicts; a declaration below a measured
value is a cap, above it a contradiction.
- The provider probe forwards the turn's credentials only to the provider's
own origin, runs URL resolution off the event loop, is bounded by one
deadline, never raises, and caches remote results per credential
fingerprint (shorter TTL for failures; local servers are re-probed).
- stream_preview resolves at preparation (or accepts a supplied resolution),
seeds the proactive trim budget from it when evidence is not unknown, and
terminal metrics report only the stored resolution plus any limit the
provider stated during the turn. Metrics perform no discovery.
src/agent_loop.py and the regular runtime's legacy model_context probe are
unchanged. A conftest guard keeps tests that drive the compact runtime with
placeholder endpoints from performing real DNS/HTTP lookups.
_session_alive collapsed every OSError from killpg(pgid, 0) into "the
group is gone". EPERM means the opposite — the group answered the probe
but holds a process we may not signal — so a session we could not touch
was reported as contained, and a timed-out command that left children
running said it had terminated cleanly.
Resolving PTY_KILL_ESCALATION also named signal.SIGKILL unconditionally,
which does not exist on native Windows. app.py imports this module at
start-up, so that turned a POSIX-only teardown detail into the whole app
failing to import there.
/api/shell/stream starts its PTY child under os.setsid, so the child
leads its own session and process group. The timeout, client-disconnect
and error paths all called proc.kill(), which signals only the group
leader. Creating a group and then signalling only its leader is strictly
worse than never creating one: the descendants are detached from the
server's group as well, so nothing else will ever reach them, while the
route reports "Command timed out after Ns" and exit_code -1 as if the
command were gone.
The kernel's controlling-terminal SIGHUP hid this for well-behaved
children, which is why it reads as working. Anything that ignores
SIGHUP — a nohup'ed job, a daemon, a process that means to outlive its
terminal — survives the kill indefinitely.
Signal the whole group instead, escalate to SIGKILL if it outlives the
grace period, and confirm it is actually gone. The timeout response now
says so when containment could not be established rather than claiming
a clean kill it did not get.
The Windows branch of `_create_bash_subprocess` spawned Git Bash with
neither pipes nor the env it was handed. `proc.stdout` and `proc.stderr`
came back `None`, so `_run_subprocess_streaming`'s reader returned
immediately and the Bash tool reported `"(no output)"` alongside the real
exit code — while the child inherited the server's own stdout/stderr and
wrote agent command output into the console and the launchd/Docker logs.
The `env` parameter was accepted and never used, so `PATH`, `VIRTUAL_ENV`,
`HOME`, `TMPDIR` and the configured import paths carried in
`ctx["subproc_env"]` never reached the child on Windows, even though every
POSIX path applies them.
Spawn it the way the POSIX path at `:688` already does: `stdin=DEVNULL`,
`stdout=PIPE`, `stderr=PIPE`, `env=env`.
`website/configuration-reference.md` is generated from source line numbers,
so the four added lines shift one entry; regenerated with
`scripts/generate_env_reference.py`.
- Headless consumers (task scheduler, background follow-up) now treat a
completion-gate final_response as the authoritative answer instead of
collecting deltas only. A gated replacement no longer leaves scheduled
output empty, which used to trigger an extra, ungated grace-summary
model call.
- The scheduler closes the agent stream with contextlib.aclosing, so the
approval-pause break unwinds the gate's journal and teacher-takeover
context in its own task. Chained runs no longer inherit a stale
parent_run_id, and later finalization no longer raises ContextVar
reset errors.
- On provider error, the completion gate applies the live answer's
statement filter to persisted round_texts. Diagnostics and the failure
note survive; claims rejected by the gate cannot reappear on reload.
Snapshot current maintainer-preview application changes and regression fixtures for integration into lab. Excludes local runtime data, evaluation outputs and source backups. Focused Python regression selection: 140 passed; full suite not certified.