-
7e3783faae
Specify M4a (conversations over Mattermost); propose P15 on secrets
master

kyleandClaude Opus 5.5
2026-09-23 17:30:31 -07:00
-
f0ec0efe9d
CLAUDE.md: M3a finding 14 was closed by M3b task 02
m3b

kyleandClaude Opus 5.5
2026-09-23 16:43:07 -07:00
-
8bcdb25ff1
Merge m3b: the runner and the tools (M3b)

kyleandClaude Opus 5.5
2026-09-23 16:42:22 -07:00
-
-
a43362edb4
Review M3b tasks 14 to 17: accept; M3b done

kyleandClaude Opus 5.5
2026-09-23 16:42:22 -07:00
-
9662966b45
toolkit: no thread panic in http_fetch, no casts, exact egress-proxy form
kyle
2026-09-23 16:13:43 -07:00
-
e69ba632e6
brokerd: escape container errors in the log; prefix and quote two messages
kyle
2026-09-23 16:10:54 -07:00
-
93539dbead
brokerd: start pipe threads safely and collect output within a grace period
kyle
2026-09-23 16:07:15 -07:00
-
c87aff0793
brokerd: move the container's pipe handling into pipes.rs
kyle
2026-09-23 15:59:44 -07:00
-
a57a1305e7
M3b plan: follow-up tasks 14 to 17 for the review's lower findings

kyleandClaude Opus 5.5
2026-09-23 15:33:23 -07:00
-
c3aaecdae2
M3b review fixes by the design model: curl --globoff, podman --pull=never

kyleandClaude Opus 5.5
2026-09-23 15:25:51 -07:00
-
75c2f1adbf
Review M3b: accept with follow-ups; add the Nix expression for the image

kyleandClaude Opus 5.5
2026-09-23 11:48:31 -07:00
-
feb50abc88
brokerd serve: run tools in containers when [runner] is set
kyle
2026-09-23 09:35:46 -07:00
-
e6081a2177
brokerd: start and remove the egress proxy for http_fetch
kyle
2026-09-23 09:22:24 -07:00
-
cfe13787b0
brokerd: the Podman runtime
kyle
2026-09-23 08:51:44 -07:00
-
4a1c6fa0a5
M3b plan: task 11's skeleton writes run as glue over small helpers

kyleandClaude Opus 5.5
2026-09-23 08:36:00 -07:00
-
62d1da44d6
M3b plan: task 11 starts from a compiling skeleton of container.rs

kyleandClaude Opus 5.5
2026-09-23 07:34:14 -07:00
-
4458369d64
M3b plan: task 11 gives Podman::egress_dir(), so the field is read

kyleandClaude Opus 5.5
2026-09-23 07:16:56 -07:00
-
49ac8d72d2
brokerd: the podman argument lists
kyle
2026-09-23 01:13:25 -07:00
-
81ce5a3345
brokerd: the [runner] section
kyle
2026-09-23 01:07:21 -07:00
-
95872d94b8
toolkit: the egress proxy
kyle
2026-09-23 01:01:13 -07:00
-
e87d876f26
M3b plan: task 08 says not to join handler threads and to skip argv[0]

kyleandClaude Opus 5.5
2026-09-23 00:46:23 -07:00
-
74da0c9d96
toolkit: is_public, the addresses the egress proxy may reach
kyle
2026-09-23 00:19:18 -07:00
-
adf6713866
toolkit: http_fetch through curl
kyle
2026-09-23 00:14:16 -07:00
-
ac1ecacadc
toolkit: shell
kyle
2026-09-23 00:06:44 -07:00
-
5e55fe4c66
M3b plan: every task's git add includes Cargo.lock

kyleandClaude Opus 5.5
2026-09-23 00:00:12 -07:00
-
0d444dd5bf
toolkit: the tool program, read_file and write_file
kyle
2026-09-22 23:12:28 -07:00
-
644fda14da
Refuse grant paths that cannot be mounted
kyle
2026-09-22 23:06:09 -07:00
-
bf9e79ac21
Seal the fetch target: one value holds the URL and its host
kyle
2026-09-22 23:03:49 -07:00
-
f095cca1ee
Move the tools' arguments and the host rules to proto
kyle
2026-09-22 22:59:40 -07:00
-
-
655683c9e0
Apply P13: tool containers run from one Nix-built image named by digest

kyleandClaude Opus 5.5
2026-09-22 22:30:04 -07:00
-
b426ca1958
Specify and plan M3b: the runner and the tools

kyleandClaude Opus 5.5
2026-09-22 22:29:27 -07:00
-
d988edac4a
Implementer log: record which model did each M3a task; repair the rows
m3a

kyleandClaude Opus 5.5
2026-09-22 22:01:14 -07:00
-
6b9bd7f5f0
CLAUDE.md: M3a is done; M3b next; the new slot layout

kyleandClaude Opus 5.5
2026-09-22 21:55:27 -07:00
-
aafd9f930e
Merge m3a: brokerd's decision path (M3a)

kyleandClaude Opus 5.5
2026-09-22 21:55:11 -07:00
-
-
f0b39a4766
Record the second review of task 23 and the findings first left out

kyleandClaude Opus 5.5
2026-09-22 21:54:28 -07:00
-
fc8befaf5b
bxctl audit verify: name the log-like files it did not check

kyleandClaude Opus 5.5
2026-09-22 21:52:54 -07:00
-
cfa02479c1
Test --accept-break on a real break through the brokerd binary

kyleandClaude Opus 5.5
2026-09-22 21:52:54 -07:00
-
bb4d7c0919
bxctl: escape frame errors; say the outcome is unknown after a timeout

kyleandClaude Opus 5.5
2026-09-22 21:48:24 -07:00
-
e08deb39a6
brokerd: recover a torn line in place, real dates only, bounded ttl, EMFILE

kyleandClaude Opus 5.5
2026-09-22 21:48:24 -07:00
-
ba369f82ba
brokerd: refuse / and a symbolic link as a socket's directory

kyleandClaude Opus 5.5
2026-09-22 21:44:29 -07:00
-
b1afcd5734
Record task 23: the M3a review fixes, done by the design model

kyleandClaude Opus 5.5
2026-09-22 21:12:22 -07:00
-
f6841f1155
Record straylight's new slot layout: four slots over one 262144-token pool

kyleandClaude Opus 5.5
2026-09-22 21:11:23 -07:00
-
a75a5453e9
bxctl: escape error details, time out on admin.sock, AdminError::Io

kyleandClaude Opus 5.5
2026-09-22 21:09:53 -07:00
-
70d582acf5
BrokerPort: cap the wait after a pending frame at a day

kyleandClaude Opus 5.5
2026-09-22 21:08:48 -07:00
-
33994d0dc6
loopd, bxctl, inferproxy: read args_os instead of panicking

kyleandClaude Opus 5.5
2026-09-22 21:07:59 -07:00
-
6af89f7c60
brokerd: runbook pointers for startup failures, no thread panics, args_os

kyleandClaude Opus 5.5
2026-09-22 21:07:59 -07:00
-
eed0a221ca
Audit writer: open a record-less log, share the log-name rule, keep the lock file

kyleandClaude Opus 5.5
2026-09-22 21:05:13 -07:00
-
22a26aad45
Review M3a: accept with fifteen findings; record the server change

kyleandClaude Opus 5
2026-09-22 20:48:43 -07:00
-
ffbff501d6
Record Grok 4.6 as the model for M3a tasks 20-22
kyle
2026-09-22 20:25:50 -07:00
-
2249f7fd91
Add the end-to-end test: loopd against the real brokerd binary
kyle
2026-09-22 20:12:05 -07:00
-
1828048564
Check that every runbook pointer has an entry
kyle
2026-09-22 20:10:48 -07:00
-
f1f17a171f
Show and answer approvals in bxctl chat
kyle
2026-09-22 20:08:13 -07:00
-
0a9df81fe4
Record the resolution of the M3a "fsync stall": a macOS socket rule

kyleandClaude Opus 5.5
2026-09-22 18:35:30 -07:00
-
57dc7899a9
brokerd: close the connection after the final frame again

kyleandClaude Opus 5.5
2026-09-22 18:32:31 -07:00
-
d7009dc488
brokerd tests: read the final frame after the handler closes, on macOS

kyleandClaude Opus 5.5
2026-09-22 18:28:18 -07:00
-
00a85c124d
loopd: read on a socket whose peer closed, instead of failing on macOS

kyleandClaude Opus 5.5
2026-09-22 18:27:31 -07:00
-
d21baa2954
Debug collection: hold_open fix, grants.rs refactor, and DEBUG-HANDOFF findings
kyle
2026-09-22 15:39:20 -07:00
-
a6d81d941b
DEBUG-HANDOFF.md: confirm brokerd admin fsync stall is environment-level
kyle
2026-09-22 13:41:13 -07:00
-
2408e2c622
Add bxctl audit verify
kyle
2026-09-21 01:35:08 -07:00
-
56e5363109
Stop: bxctl audit verify not wired in main.rs (task M3a/19)
kyle
2026-09-21 00:20:15 -07:00
-
2d94067b52
Add bxctl approvals, approve, refuse and grants check
kyle
2026-09-20 23:25:05 -07:00
-
469be2c0a1
Add BrokerPort: loopd asks brokerd for every tool call
kyle
2026-09-20 19:40:35 -07:00
-
1ceaa36b9b
Give loopd's tool port approvals, its own clock and plain denials
kyle
2026-09-20 17:42:16 -07:00
-
3ecaef3c8b
Add brokerd serve: startup, both sockets, and the expiry thread
kyle
2026-09-20 17:24:57 -07:00
-
d250678355
Handle approvals, refusals and grant checks on admin.sock
kyle
2026-09-20 13:54:01 -07:00
-
e68e626cd7
Handle a tool request from decision to answer
kyle
2026-09-20 12:59:42 -07:00
-
cff22ce579
Add the ledger: the audit writer and session state behind one lock
kyle
2026-09-20 03:30:37 -07:00
-
caf8fd6eca
Add the table of pending approvals
kyle
2026-09-19 16:48:09 -07:00
-
57734ebb9a
Replace the runner stub with the Runtime seam and RunSpec
kyle
2026-09-19 16:43:56 -07:00
-
ded7eb8c50
Add the audit writer with its startup check
kyle
2026-09-19 16:32:37 -07:00
-
2c1adc7e7a
AGENTS.md: work only from this repository; delegate with the real rules
kyle
2026-09-19 12:12:28 -07:00
-
a301915551
AGENTS.md: work only from this repository; delegate with the real rules

kyleandClaude Opus 5
2026-09-19 12:12:28 -07:00
-
ec4037abee
Lessons from the first M3a run: references out of reach; per-task copies

kyleandClaude Opus 5
2026-09-19 12:08:37 -07:00
-
e7f0d84d02
Note how the first M3a run went: task 03 copied from the reference

kyleandClaude Opus 5
2026-09-19 12:08:13 -07:00
-
ed8cf49540
M3a task 01: copy a strict.rs of its own

kyleandClaude Opus 5
2026-09-19 12:07:59 -07:00
-
726ce1f766
Keep each session's taint and untrusted flag in a file
kyle
2026-09-19 03:08:46 -07:00
-
e1e6c7a338
Decide tool calls against grants, taint and time
kyle
2026-09-19 03:05:01 -07:00
-
e2ab29aa15
Load grant files, failing closed on any invalid file
kyle
2026-09-19 02:50:26 -07:00
-
9150effc8e
Add typed tool arguments and the form checks for paths, hosts and URLs
kyle
2026-09-19 02:37:31 -07:00
-
5502de1c90
Add brokerd's configuration
kyle
2026-09-19 02:24:15 -07:00
-
d01b2ef2d9
Add the audit chain verifier
kyle
2026-09-19 02:19:45 -07:00
-
e8568edf7e
Add the admin messages, approval ids as numbers, and two turn events
kyle
2026-09-19 00:28:46 -07:00
-
c6395b16f4
Replace the audit record with chained audit events
kyle
2026-09-19 00:22:25 -07:00
-
cb5ecad4da
M3a/01-proto-audit-types: stopped
kyle
2026-09-19 00:10:43 -07:00
-
-
0703306e19
Record that the M3a plan is ready, and how it was checked

kyleandClaude Opus 5
2026-09-18 23:45:43 -07:00
-
e3f37da232
Hand over the M3a plan: 22 tasks, their files, and the check record

kyleandClaude Opus 5
2026-09-18 23:45:43 -07:00
-
69f0a0a218
M3a spec: fold in area E's findings; runbook and egress to match

kyleandClaude Opus 5
2026-09-18 23:40:02 -07:00
-
43f5b8abc6
M3a spec: fold in the defects the plan's checks found in areas A to D

kyleandClaude Opus 5
2026-09-18 23:09:32 -07:00
-
b39dac3f71
Hand off the half-built M3a plan

kyleandClaude Fable 5.1
2026-09-18 23:00:21 -07:00
-
66fa143524
M3a spec: a ledger module and a two-process end-to-end test

kyleandClaude Fable 5.1
2026-09-18 22:36:55 -07:00
-
1008dce351
Decide where reference implementations are still written

kyleandClaude Fable 5.1
2026-09-18 22:28:53 -07:00
-
0ee375dd03
Record the open M4 decision on approvals too long for one post

kyleandClaude Fable 5.1
2026-09-18 22:23:54 -07:00
-
9dcb16ff30
Apply P14: the brief's State list names brokerd's session state

kyleandClaude Fable 5.1
2026-09-18 22:22:18 -07:00
-
477e28a759
Close the remaining M3a spec review findings

kyleandClaude Fable 5.1
2026-09-18 22:18:13 -07:00
-
3492734434
Fix seven M3a spec review findings in policy and the audit chain

kyleandClaude Fable 5.1
2026-09-18 22:13:28 -07:00
-
180ef28833
Specify M3a (the decision path) and write the runbook

kyleandClaude Opus 5
2026-09-18 21:57:21 -07:00
-
92a57f6350
Review M2b task 11: accept; M2b done

kyleandClaude Opus 5
2026-09-18 21:10:15 -07:00
-
c060c80c7e
Fix four review findings: busy release, poison recovery, core.md errors, chat loop
kyle
2026-09-18 21:06:58 -07:00
-
2be8581a0c
Review M2b: accept with one follow-up task; record lessons

kyleandClaude Fable 5.1
2026-09-18 20:47:03 -07:00
-
34951084cc
Extend on-device verification to the agent loop
kyle
2026-09-18 20:38:56 -07:00