Repository navigation
Prime provider parity: tasks, automation, and upstream watch #114
Description
Activity
Foreground/background prompt ownership now has coordinated unmerged candidates:
- Prime fork contract: feat(daemon): add correlated prompt lifecycles prime-agent#9
- Pylon integration: fix(server): keep Prime background work out of foreground turns #163
Pylon #163 returns typed
busybefore turn creation when stock Prime background activity is observable. With the explicitly negotiated fork capability, it uses exact generation-scoped prompt ownership, delivery-aware cancellation, prompt/session provenance, terminal usage, bounded recovery state, and fail-closed reconnect/replacement validation.The stock path intentionally cannot close the narrow unobserved admission race. Capable recovery also refuses to infer missing foreground output from unattributed transcript snapshots; it requires complete event continuity and an exact already-observed transcript.
Focused validation passed 285 Pylon tests and 202 Prime connection/supervisor tests, with targeted checks clean. Independent final and follow-up audits found no remaining P0/P1 issues. Heartbeat creation/projection remains outside this PR and this issue stays open. Neither PR has been merged.
The coordinated foreground/background prompt admission work has merged:
- Prime lifecycle contract PR feat: adopt the 2026-08-12 upstream batch (11 of 12 change sets) #9: merge commit
02a53ddf7d5557eb732a52e6d991b3d5d52430d1 - Pylon integration PR fix(server): keep Prime background work out of foreground turns #163: merge commit
486af3ea52180c3dcda51b6411ffaeecf9987d08
Both reviewed heads passed every hosted check. Final independent audits reported no remaining P0/P1 findings. The stock-Prime fallback and optional correlated lifecycle path are now landed.
This does not complete heartbeat creation or autonomous scheduled-run projection, so #114 remains open for that broader roadmap.
- Prime lifecycle contract PR feat: adopt the 2026-08-12 upstream batch (11 of 12 change sets) #9: merge commit
Comet has joined the Prime Agent integration work through its own umbrella issue: rynfar/comet#1
The Comet repository policy is merged in rynfar/comet@b520992. Comet will use the native daemon as its primary path and coordinate provider-neutral semantics, shared Prime contracts, compatibility tests, worktree ownership, and merge order through cross-linked issues.
Any Comet work that changes or depends on Pylon-defined lifecycle, queue, approval, subagent, heartbeat, or checkpoint semantics will be linked to this umbrella before implementation or merge. No Pylon change is requested by this comment.
Comet's reviewed native-daemon foundation is now open: rynfar/comet#4
The shared consumer rules are aligned with Pylon: stock protocol v7+, capability offers are not attach negotiation,
PRIME_AGENT_INTERNAL_*/RLM_DEPTHare stripped for the top-level daemon, and provider/custom environment configuration remains host-private and usable. Comet additionally isolates the bootstrap SDK loader and removes process-loader injection.This slice exposes no Comet sync/RPC/UI state and creates no sessions. The next Comet session-host contract will require cross-consumer review and is blocked on bounded public SDK ingress at pylon-code/prime-agent#13. Final receipts: rynfar/comet#3 (comment).
Prime Agent dependency update: pylon-code/prime-agent#12 merged into
pylonasf728316dabbaa85aa561e6d6b08550ed337574beafter the recovered event-persistence failure was fixed and rereviewed. No Pylon #114 checkout or contract was changed.The remaining safe order for Comet's native host is Prime #11, regenerated/reviewed #8, Prime #13 bounded ingress, then Comet #5. The existing #11 dirty worktree is protected by a collision-avoidance hold pending its owner's checkpoint and formal claim.
Prime dependency milestone: pylon-code/prime-agent#11 is closed via merged PR pylon-code/prime-agent#14 at
fd5cadc600f867a0a5a989064cce22934e9dad94. This lands the reviewed protocol-v7 snapshot/recovery/worker-authority and supervisor-only authoritative cleanup contracts needed by the native host.A fresh upstream-sync candidate is now being regenerated under pylon-code/prime-agent#8 from that exact post-merge
pylonand Primea903d4b6768f484bd6d459b7b0aa7dee38e461e2; stale candidatea37efe92fis not reusable. Bounded ingress #13 follows only after #8 merges. rynfar/comet#5 remains unclaimed until both reviewed Prime artifacts are available.Prime upstream governance gate #8 is complete. PR #15 merged as
e7871eb699d0f65047a21d179216ebfec7755d0cafter exact-head reviews, zero conversations, and all trusted hosted jobs passed.Bounded public ingress Prime #13 is now claimed from exact merged
pylonate7871eb699d0f65047a21d179216ebfec7755d0cin an isolated worktree. The declared client-local feature proof/raw-byte limit/error/reconnect contract is under the final joint Prime/Comet design review before source edits.Dependency order is now: #15/#8 (done) → #13 (active) → Comet #5.
Prime bounded-ingress candidate is now ready as PR #16 at exact head
9013a63a76fa339b5e2898947e9cff040505d72c/ tree814cfa93bfdbab0d43acaa92c208205fd7dd5749on basee7871eb699d0f65047a21d179216ebfec7755d0c.Three commit-bound reviews approved with no P0/P1: transport security, API/resource/governance, and Comet consumer compatibility. Local validation includes 53 focused tests, 13 real-process passes with 8 fixture skips, both stock/current 0.8.1 adoption directions, the 36 MiB indivisible message, deterministic 100/500 MiB bounded-client reconstruction, and exact 64/128 MiB resource probes.
Trusted exact-head hosted CI is running. Comet #5 remains blocked until PR #16 passes CI, has no unresolved conversations, receives exact head/base maintainer approval, and merges into
pylon.Prime bounded public daemon ingress PR #16 passed trusted hosted CI and merged as
7238ac8cff25962ada9ffe4530b7d4d1cddc1b47(parentse7871eb699d0f65047a21d179216ebfec7755d0c+9013a63a76fa339b5e2898947e9cff040505d72c, tree814cfa93bfdbab0d43acaa92c208205fd7dd5749). Prime #13 is closed.Comet #5 has now been claimed from
origin/main@de66c08c3687208effe2e2fdb514d6d690f1cc0aonfeat/prime-session-host-7238in an isolated worktree. It will require the exact public-rootbounded_daemon_ingress_v1token and constructDaemonClientwith a 64 MiB inbound frame limit under an isolated 512 MiB V8 heap. No production session path will accept stock 0.8.1 or infer support from versions, schemas, methods, constructor arity, or daemon offers.Comet consumer milestone: rynfar/comet PR #6 merged as
9ef2295877d33fe241479471e908105fccbeb434with exact reviewed treebb5b90da8c098ac595a4b79afbda5ee4513d3d15, consuming Prime7238ac8cff25962ada9ffe4530b7d4d1cddc1b47. The host-only session lifecycle now has exact feature/capability gates, bounded SDK/private ingress, fresh-draft-only attach, and authoritative cancellation/crash cleanup. Three exact-head reviews plus hosted x86 Linux, ARM Linux, and macOS builds passed.No user-visible Comet Prime provider exists yet. The planned sequence is: (1) bounded correlated prompt/event host, jointly checked against Pylon's native Prime semantics; (2) hidden normalized Comet Harness adapter; (3) registry/settings/model/UI preview. Resume, tools, subagents, resources, and advanced parity remain later contracts.
Focused negotiated-capability consumer follow-up: #190. It is blocked on pylon-code/prime-agent#17 and blocks rynfar/comet#7. This corrects the current correlated-prompt server-offer shortcut without removing Pylon's ordinary-prompt compatibility fallback.
- added a commit that references this issue
on Aug 30, 2026 8 remaining items
Distribution decision needed. Options: (1) resume protected publication of fork artifacts (prime-agent#53 must be resolved first; unblocks the existing Install stable button); (2) keep the manual fork install (Task 4) as the documented path for the alpha and hide the managed buttons (Task 12); (3) make native mode accept stock Prime by dropping the fork SDK contract for N=1 (large rework; discards the safety contracts behind #199 and the recovery ledger). Recommendation: (2) now, (1) after Phase 2 lands. Which do you choose?
The maintainer selected option 1 in the implementation session: "Resolve publication and ship managed builds". This execution therefore includes prime-agent#53 and Task 19. Protected publication remains gated on its safety contract, independent checkpoint reviews, and passing verification. Playwright fallback was also explicitly authorized after in-app preview snapshot failures.
2026-09-10 daily-driver triage (stock 0.8.1 vs fork build)
Stock completes a real tool-using turn. The private fork negotiates native mode, but Pylon fails its first turn during transcript synchronization even though Prime later completes internally. Native approval, cancellation, and restart acceptance remain blocked; they are not reported as passing.
surface stock (ACP) observed fork (daemon) observed verdict owner/action T1 S1 environment Snapshot seeded; ports13950/5910, owned TTY Same isolated environment ok — T1 S2 browser pairing Preview paired but snapshot failed; authorized Playwright works Same Playwright context ok Recorded tool fallback T1 S3 provider creation/status Built-in Prime already enabled; generic ACP status Manual Pylon build, no explicit backend label missing-copy Tasks5,12 T1 S4 fresh picker 133 models; observed mounted rows enabled Default and discovered models enabled ok — T1 S5 Default selection Selects and closes picker Selects and closes picker ok Task7 no new-thread defect reproduced T1 S6 Default after explicit model Still selectable before first turn Default selectable before first turn ok — T1 S7 real turn 13s,2 commands,correct final answer,no errors 1.4s Pylon failure; Prime transcript later completes bug Proposed N1; PrimeAgentDaemonAdapter.ts2635 T1 S8 model change after turn Default and other models disabled; hover reasons Not accepted as proven until N1 resolved ok Stock truthful degradation; native check pending T1 S9 runtime mode Only Full access option Supervised and Full access options ok Capability-driven runtime control T1 S10 capacity Hidden for default; mapped openai-codex capacity present Mapped capacity present missing-copy Task13 unmapped/default backend explanation T1 S10 Harness Absent with unavailable capability Visible after native session initializes truthful-degradation Task14 hidden unavailable controls accepted T1 S10 Goal Absent Live/native Goal behavior blocked by failed turn truthful-degradation Task14 no ACP disabled placeholder needed T1 S10 input queue Absent Live/native queue behavior blocked by failed turn truthful-degradation Task14 no ACP disabled placeholder needed T1 S10 resources No visible entry Post-session audit blocked by failed turn truthful-degradation Task14 no ACP disabled placeholder needed T1 S10 context/compaction Absent Session compaction updated activity appears before failure truthful-degradation Verify native after N1 T1 S10 reported cost Absent Completion unavailable in Pylon truthful-degradation Verify native after N1 T1 S10 managed Install stable Enabled; fails No immutable stable publication exists Same publication inventory bug Tasks12,19; PrimeManagedMaintenance.ts / managed tool store T1 S10 second provider Prime radio disabled for already enabled built-in Single-instance manual build restriction shown missing-copy Task5 guidance; Task12 explicit backend T1 S11 mobile picker Default disabled with Start a new thread to use Prime Agent Default Native follow-up pending missing-copy Task15; ThreadSettingsSheet.tsx / shared model helpers T1 S11 mobile maintenance Not in thread settings; environment card collapsed Native follow-up pending ok Task15 expanded card final audit pending T1 S12 process lifecycle Owned server retained Same server retained ok — T2 S1 SDK probe []; recoverable false four exact SDK tokens;recoverable true ok Saved stock-bridge.json / fork-bridge.json T2 S2 native status Generic ACP Pylon build manual; Native modes present missing-copy Task12 backend label T2 S2 discovery 133 models Transient discovery failure then recovered; no status shown in single-model picker missing-copy Task6 T2 S3 repeat turn/surfaces Completed baseline Continuity failure prevents full native repeat bug Proposed N1; do not assert native parity T2 S4 deny/approve Unsupported Not exercised: first-turn continuity blocker bug Blocked by proposed N1; test after fix T2 S5 Stop Not part of stock baseline Not exercised: first-turn continuity blocker bug Blocked by proposed N1; test after fix T2 S6 restart Not part of stock baseline Not exercised: first-turn continuity blocker bug Blocked by proposed N1; test after fix T2 S7 mobile Same completed stock thread verified Pending after N1 bug Blocked by proposed N1; test after fix T2 S8 evidence baseline-stock.md + PNG01–05 baseline-fork.md + failurePNG + recording ok Failed baselines are triage evidence, not acceptance Keyboard explanation Disabled rows aria-disabled true; title/description absent; hover only Same picker component missing-copy Task13; ModelPickerContent.tsx Keyboard jump numbering Disabled rows have no number; current Sol has Cmd1 Native check pending ok Task16 shortcut operation still to exercise Proposed N1: first-turn native transcript synchronization fix in
PrimeAgentDaemonAdapter.ts, with a focused regression preserving continuity gates. Maintainer scope approval requested in implementation session; read-only diagnosis underway.Mechanical corrections authorized by maintainer: use existing built-in provider; Playwright fallback for broken preview snapshots; triage records failed baselines instead of circularly waiting for native success before permitting bug fixes.
Distribution: maintainer selected resolving prime-agent#53 and shipping protected managed preview/stable builds. No publication has run.
Implementation progress: Task4 install docs commit a5ea82fbe5; Task5 fallback reason 5e4ff5d9e5 (13 tests and server typecheck pass); Task6 discovery copy 6ffc438f59 (23 tests, server/web typecheck and lint pass). Phase1 checkpoint review requests pinning the interim docs recipe to its verified fork commit. PRs follow that correction and integrated verification.
Phase 1 checkpoint complete; the one documentation pin finding was fixed and passed scoped review.
- docs(prime): document the native fork install path #464 documents the pinned manual native install.
- fix(prime): explain stock ACP fallback and native setup #465 explains stock ACP fallback and native setup (draft pending screenshot upload).
- fix(prime): explain a fallback-only model catalog #466 explains a fallback-only model catalog (draft pending screenshot upload).
Integrated verification on Pylon16a99685d8 plus these branches:36 focused tests pass; server and web typechecks pass. Stock shows the new stock-build sentence, the private fork does not, and a controlled discovery failure shows its explanation beside the sole Default row. Before/after images are captured locally. Default selection before a turn and disabled-row keyboard behavior did not reproduce a defect, so Tasks7/16 need no code change.
Native baseline remains blocked: Prime completes internally, but Pylon rejects transcript synchronization. The maintainer approved N1. A fresh sanitized capture corrects the initial hypothesis: replay is complete; Pylon has observed zero native messages while the snapshot contains the current user message and a matching delivered lifecycle. N1 is now focused on authenticated reconciliation of that current user message. No native approve/deny/stop/restart or ten-turn parity success is claimed.
Managed distribution remains selected. Publication#53 group1 is committed locally with100/100 publication tests passing; generation/rotation/migration/crash gates and final independent reviews are still pending. No releases have been published.
Baseline media for the triage table above. Stock completed a real read-only turn with two commands. The private fork completed internally but Pylon rejected its first synchronization; the maintainer has now approved the focused continuity fix. These captures do not claim native parity.
Mobile model restriction before copy parity work:

Native failure recording:
native-baseline.webm
Phase 1 is merged after maintainer approval: #464 (pinned manual native install), #465 (accurate stock fallback), and #466 (discovery-failure message). Focused tests, CI, checkpoint review, and UI evidence passed.
N1 is implemented in #469, CI green and independently reviewed. Real native first turns now complete; Supervised denial leaves the file absent, a fresh approved turn creates it with a visible diff, a fresh timed Stop restores the composer, and restart shows the expected Supervised interruption reason. Native evidence: #469 (comment).
A separately approved N2 fix is in preparation: ordinary and deferred native event consumers inherit the first worker fiber lifetime, so Pylon stops receiving later events even while Prime completes work. The fix will retain those listeners for the session lifetime and test first-turn completion followed by approval/output/terminal events. Cancellation ownership checks stay intact. Post-restart quarantine limits the remaining healthy mobile/native rechecks; the ten-turn completion criteria have not passed yet.
The Prime mirror now exactly matches upstream
1eee2938b4eeb7a4d72e17035adda669a89b63de. The original protected sync reaches the expected 41 conflicts, and/tmp/prime-agent-syncholds that merge for manual resolution. One explicitly approved manual fork sync was necessary because GITHUB_TOKEN could not update workflow files. GitHub deferred inherited runs until Actions was restored; both were cancelled, the inherited release workflow was disabled, and release build/packing/upload/publication never ran. No fork release exists.Publication #53 groups 1 and 2 are committed; group 3 is in focused verification. Historical migration, hard-crash/OS coverage, final independent approvals, and actual managed preview/stable publication remain. No managed build has been claimed or published.
Native continuity fix #469 is merged as
7dc0343a50b5e8de77e3b3ac4bee5439da1182ddafter maintainer approval and green CI.The approved follow-up stall fix is draft #470 at
0149bc96924373029a69d5b09c62c69b3740b2be. Completing the first worker previously interrupted the session event consumer. Both ordinary and deferred paths now use the session scope; detached teardown can interrupt its receipt wait without cancelling cleanup. All 413 focused tests, scoped typecheck/lint, and the independent checkpoint review pass. Owned cancellation, correlation, proof, and quarantine guards remain intact.Live integration is not yet accepted. The installed 0.8.1 fork's internal supervisor catch-up retains the caller-owned capability but omits its matching launch environment and recovery contract, causing first-turn startup rejection. Upstream 0.9.4 also omits those fields on that internal path, so Task 9's planned caller-owned environment reconciliation will include a regression using the real validator. Consecutive native turns, Stop, and restart checks will resume on the corrected fork. No quarantine bypass or ambient environment fallback was used.
Protected publication work continues on prime-agent#53. The next checkpoint follows integrated generation cleanup, historical migration, crash stress, and docs/CI. Existing mandatory live App acceptance was recovered from prime-agent#42, and current protected environment, ruleset, and check readbacks remain consistent. No managed release has been published.
Model: GPT-6. Harness: Codex in Pylon.
PR #469 is merged as
7dc0343a50b5e8de77e3b3ac4bee5439da1182dd. The separately approved follow-up fix is draft PR #470, CI-green at0149bc96924373029a69d5b09c62c69b3740b2be; its source checkpoint passed, and native integration remains pending the fork catch-up correction.The final disposable test environment is paired on web and mobile. Stock Prime 0.9.4 completed a real files/README request in 9.7 seconds, and mobile shows the same completed transcript. The global stock installation and earlier native failure evidence are preserved.
The upstream 0.9.4 fork merge has working resolutions for all 41 conflicts. Full daemon and regression verification is still in progress. The caller-owned environment catch-up path has nine passing real-validator regression tests; no merged-fork live pass is claimed yet.
Publication safety group 3 is complete at fork commit
0aaa30985eae7017e332adadd6513292f936c94e: 145 retained tests and static checks passed. The actual 16 MiB maximum integration also passed, charging 492,146,488 bytes within the 512 MiB v3 disk bound. Public v2 entrypoints remain unchanged. Historical migration, final Linux/macOS crash and stress gates, three independent final reviews, and protected preview/stable publication remain required.Implementation and verification: GPT-6 Astra / GPT-5.6 Sol, Codex harness.
Prime 0.9.4 verification checkpoint
The reviewed upstream integration builds cleanly, its four packed archives match the manifest sizes and SHA-256/SHA-512 digests, and Pylon's bridge probe reports all four native SDK features plus recoverable adoption. Release-contract tests pass. The fork merge remains held by a real native-turn failure.
A fresh native turn completed internally but Pylon rejected transcript synchronization before displaying tools or output. A structural-only capture identified two concrete compatibility defects: the snapshot counts a hidden harness-digest message that Pylon dropped, and the supervisor's catchup transport drops the worker-issued replay proof. The Pylon identity/count correction passes 447 focused native tests; the fork replay-propagation correction is in progress. Unknown replay and ownership/lifecycle checks remain enforced. Live consecutive turns, approvals, Stop, and restart must be re-proved before the fork lands.
Task 11 is reviewed and CI-green in #471 (stock 0.9.4 artifact pin, structured recovering errors, documentation). Its shipped stock schema is correctly documented as 27; the fork is schema 32. Task 12's Settings change passes 65 focused tests and server/web typechecks. Real browser checks show the ACP/native backend labels and disabled unavailable managed-install controls with guidance; screenshots are attached. Phase 3's remaining client changes and managed publication are still pending.
Attached native failure screenshot records the remaining gate; the Settings screenshots prove only the named status/control behavior.
Corrected Prime Agent 0.9.4 native checkpoint
Exact fork: a70feb1a6273e0e74b5c22e8544ad18c8eed65c1 (tree3e93e226fb6fbeff9b3c32dc6c3015b9b9abd772), preserving upstream integration merge aeb1c636. Protocol7/schema33; four SDK feature tokens; recoverable:true. Pinned Node22.23.2 clean offline pack, four tarball sizes/SHA256/SHA512 verified, ten release-contract tests pass. Private install only; managed publication still blocked by prime-agent#53.
The paired replay/transcript correction passed its adversarial checkpoint. In an isolated Pylon environment with N2 and Task11 corrections:
- First native turn completed in9.977s with two tools and ready checkpoint.
- Same-thread supervised denial completed with no file; approval completed with exact
hellobytes and ready diff. Their45.951s/26.653s durations include human approval waits. - Stop clicked approximately5s after send; turn ended interrupted after9.462s, session ready, composer enabled, no error notification. All200numbers were visible by terminal; this proves cancellation state, not instantaneous output cutoff.
- Restart during the fifth request produced an explicit interruption reason, not a hang. The manual build has no verified managed recovery authority, so its owned receipt quarantines further native use after this process-group shutdown. Evidence/state retained. This is not a passing managed-adoption or postrestart-continuation proof; those remain required after safe publication.
The0.9.4 support PR will include the reviewed hidden harness identity correction. The separately reviewed follow-up/Stop fix remains#470. Mobile guidance and composer changes pass focused checks; integrated client verification and managed publication remain in progress.
Related:#114; prime-agent#44; prime-agent#53. Model:GPT-6 Astra. Harness:Codex in Pylon.
replay-native-sequence.webm
Final fork514e404 native acceptance with integrated Pylon43aab6b17c: firstturn3tools/readycheckpoint, same-thread denied and approved writes, Stop→interrupted/readycomposer/noerror all pass. Exact current-head hostedCI is green including Windows namedpipe and macOS/Linux artifacts. Privatepack hashes/R4/10release-contract tests pass.
Restart ends with explicit interruption reason (nohang). Manual-build ownership quarantine remains preserved; this does not claim managed restart/continuation, which remains part of#53 and the final acceptance run. Video and key screenshots attached.
Reset allowance consumed1/1; no further reset used.
ci-final-native-sequence.webm
The published Prime 0.9.4 preview now passes the actual managed install/update/rollback/use-stock lifecycle, N2 isolation and same-session reconnect (99.1 seconds), and repeated Pylon crash/adoption/no-replay/cleanup (119.8 seconds).
PR #490 contains the reviewed reconnect fix and graduation-fixture corrections. Local focused tests, lint and typechecks pass; its CI is running. PR #488 and PR #489 are merged.
Stable publication remains held until a new protected graduation succeeds after #490 lands. Remaining final acceptance is the actual stable install, documented fresh-follower run, ten web turns, ten mobile turns, and documentation/closeout. The previously failed graduation run is not being used as promotion evidence.
Managed stable publication is now public: https://github.com/pylon-code/prime-agent/releases/tag/pylon-stable-000001-ga1ef2eca2ad0-r2. Protected graduation passed all 31 cases with no skips: https://github.com/pylon-code/pylon/actions/runs/34667627431.
Merged follow-up fixes: #488, #489, #490, #491. Documentation is #492. Fresh documented stable installation D1 reached Native in 4m16s (89s actual install), stable #1 / Authenticated / no alerts.
Final acceptance remains OPEN: D3 first real web turn failed transcript synchronization after a tool call. Its failed turn and recording are preserved; focused diagnosis is underway. No ten-turn pass, mobile pass, or full-plan completion is claimed. No additional account reset was used.
The September10–12 Prime first-class provider plan is implemented and its final acceptance passed. All implementation PRs are merged, including #521 at
4859f9501f0386727883f19bbe96dc3d448d631c. Its CI,483 focused regressions, server typecheck, scoped lint and checkpoint review passed.Managed preview and stable sequence2 are public. The actual Pylon stable update succeeded and selected corrected
65d9c0274in Native/Authenticated/managed mode. Protected graduation passed33 tests with0failures/0skips; stable publication succeeded. A signed append-only entry withdraws affected stable1.Final requirement Evidence result D1 documented install Fresh follower reached Native in256.262seconds; installation89.342seconds. That timed run used stable1/ga1ef; corrected stable2 was separately installed and verified successfully. D2 stock Stock0.9.4 tool turn and truthful disabled controls passed. D3 web Ten consecutive recorded native turns, actual ordinals12–21: nine completed with ready checkpoints and one intended interrupted Stop; all ten used tools. Real supervised approve/deny, active restart and follow-up passed. D4 mobile Same environment, final ten consecutive native turns, actual ordinals3–12: nine completed/ready and one intended interrupted Stop; all ten used tools. Approve/deny, active restart and follow-up passed. D5 fork sync Frozen reviewed upstreamv0.9.4 commit 1eee2938bis an ancestor of freshly fetched forkorigin/pylon; latest normal protected sync is successful.D6 docs and tracking Guide has0 references to0.8.1. All plan merges are linked below; this scoped checklist is complete. D7 cleanup All five named temporary paths are absent. Owned server, Metro, simulator app and two browser contexts are stopped. Ports13950,5910,8194 are closed. User installs and private failed-authority evidence are retained. Read-only canonical event history contains zero errors or duplicated/unfinished projected assistant messages for these acceptance threads. Both active restarts preserve the exact native/active/incarnation identities while rotating the owner and recovery handle. Stop leaves zero busy client-owned native sessions and quiesced checkpoint work.
Acceptance used clean Pylon source
d562f18f08a33967355db6110c3472e5a6b17135; its Prime implementation matches merged#521. It is the frozen client candidate used throughout this acceptance, not a claim to verify concurrent unrelated client changes. The protected graduation separately exercised actual merged Pylon source.Recorded limits and mechanical corrections: the first web video was blank and was rejected; the complete web matrix was repeated with a validated recorder. Mobile's two initial Stop attempts completed before cancellation; both extra successful turns remain in the record. Mobile case5 created the correctly approved six-byte file, then proposed an unintended deletion which was declined, and the model ultimately returned a single-space final answer. The native transcript and independent checkpoint show no lost meaningful assistant text; the provider-log
missing-final-responsewarning is retained. Explicit operator approval waiting time is recorded separately from autonomous execution. Earlier failed recovery attempts remain preserved and were not relabeled as passes.The attached recordings preserve the full sequences: web526.2seconds and mobile2391seconds, compressed only for upload. No pairing tokens, credentials, private journals, SQLite files, or authority material are attached.
Pylon implementation PRs: #464, #465, #466, #469, #470, #471, #473, #474, #475, #476, #484, #485, #486, #487, #488, #489, #490, #491, #492, #493, #495, #496, #514, #521
Fork implementation PRs: prime-agent#55, prime-agent#56, prime-agent#58, prime-agent#59, prime-agent#60, prime-agent#61, prime-agent#63
The separate automation, scheduling, rollback and other umbrella work in#114 and prime-agent#1 remains independently tracked; this closes the September first-class delivery scope. The single reset and single authorized credential fallback were already consumed earlier; neither was repeated.
Web final state:
Mobile final state:
Web full acceptance recording:
task19-d3-final-recorded-github.mp4
Mobile full acceptance recording:
task19-d4-final-cycles-github.mp4
Final bounded evidence-only adversarial checkpoint: PASS, with no remaining implementation or acceptance-evidence blocker. It independently checked all20 final-turn outcomes, both restart identity rotations, zero busy owned work, source binding, managed bridge features and full-duration recordings. Evidence-label corrections are incorporated above.
Implemented and verified with GPT-6 / Codex in Pylon; checkpoint-only independent adversarial reviews.
Acceptance reconciliation (2026-09-24), against merged
origin/pylon7ed3f711caand the public Prime fork releases. This corrects the early unchecked references in the epic; it does not check or close the broader epic by issue state alone.- Prime Agent active turns cannot survive a Pylon server restart #84 active restart: implemented in merged Prime adoption/recovery code (
c6881c331a,d4fd9e01ec,a8b8cde2ca, later fix(prime): preserve recovery authority after failed startup #496/fix(prime): recover completed tool cycles after reconnecting #521 hardening).PrimeAgentRestartAdoption.real.test.mjsexercises the real published managed artifact. The later closeout already records web/mobile real active-turn restarts and 10 consecutive native turns. Exact managed Full-access continuity can adopt the same execution; supervised, stock/unmanaged, ambiguous identity/continuity remain fail-closed. This is not proof of the separate N=1/2/4 multi-instance graduation in Make multiple Prime provider instances safe and truthful #199. - Verify Pylon Prime distributions without weakening runtime negotiation #193 and Add opt-in side-by-side Pylon Prime install and updates #194 distribution/managed install: merged verifier
PrimeAgentDistributionVerifier.ts, managed storePrimeAgentManagedToolStore.ts, and maintenance/driver gates implement signed publication verification, private receipt/high-water, explicit side-by-side install/update/switch-back. The public preview releasepylon-build-ga1ef2eca2ad0-r2has its channel/build manifests plus four package archives; the stable sequence-2 tagpylon-stable-000002-g65d9c0274866-r2publishes the stable channel manifest selecting the immutable build. The later epic closeout records actual in-app managed preview install and stable update with Native daemon/Authenticated status. Stock Prime remains valid; native Windows download/install is rejected. Neither a release tag nor signed bytes alone imply arbitrary SDK/native capabilities. - Report Prime plan observation without exposing unsupported Plan mode #195 / merged PR fix(server): report Prime plan observation #196 plan parity:
PrimeAgentFeatureCapabilities.tsreports read-onlyobserve; the daemon/ACP adapters retain bounded plan progress. Formal Plan interaction mode remains hidden and rejected, as requested. - Retire native Windows Prime runtime paths in favor of WSL2 #222 Windows boundary:
PrimeAgentDriver.ts, backend selection, managed store and settings validation reject nativewin32before Prime runtime/installation work and point to WSL2. The Windows desktop client may connect to WSL2/remote environments. This does not claim native Windows provider support.
The early unchecked lines for these six references therefore predate their later shipped implementation. The remaining epic criteria still need their own evidence: #199 signed-in N=1/2/4 macOS plus hosted Linux/WSL2 isolation/resource publication; #200 full rollback acceptance and client/mode live proof; unsupported Prime capabilities, degraded-mode clarity, and any autonomous ownership/product choices. I am leaving the checkboxes and issue open so their broader wording can be reviewed criterion by criterion, rather than inferring completion from the CLOSED labels.
- Prime Agent active turns cannot survive a Pylon server restart #84 active restart: implemented in merged Prime adoption/recovery code (















Goal
Make Prime Agent feel like a first-class Pylon provider while keeping Pylon's event ownership, privacy boundaries, remote support, and checkpoint model intact.
This issue is the active work checklist and upstream-watch index. The repository's authoritative public-API decision record is
docs/internals/prime-agent-daemon-parity.md. Update both when a linked PR lands, a design is deferred, or an upstream native solution changes the preferred implementation.Fork-side tracking lives in pylon-code/prime-agent#1. Fork governance and daily synchronization landed in pylon-code/prime-agent#2; the first reviewed integration through Prime
d60fab8alanded in pylon-code/prime-agent#5, resolving overlap #4.Reliability and daily-driver graduation
Pylon's primary Prime connector is the installed package's public SDK and detached-daemon API. ACP is a tested degraded fallback only when native mode is unavailable or unsafe. The separate Comet integration and its
nonpersistent_daemon_worker_v1candidate are not part of this tracker and do not block Pylon.Existing reliability candidates
e62ad6a54. Boundinitialize,authenticate, andsession/new; preserve actionable prompt failures.4ce0070a3. Persist exact admission ownership, reject stale lifecycle events, reconcile overdue starts, and bound Prime teardown/replacement.70b65305c. Negotiate fresh snapshot generations and keep malformed catch-up local to one attachment.Maintained fork delivery
7d4f4a753; hosted checks green, awaiting approval), then publish protected attested preview/stable channels in prime-agent#29.mainmirror andpylonproduct branch synchronized through the protected review workflow; keep.pylon/features.yamland.pylon/upstream-review.mdcurrent.Daily-driver connector parity
.cmd/home/runtime surface, and retain Windows desktop packaging for clients that connect to WSL2.Graduation matrix
Autonomous heartbeats, cron, resident work, and background workflows remain owned by #177 and the lifecycle-design section below. They are advanced product features, not a hidden dependency of reliable user-driven Prime chat.
Current parity work
Landed
2cdff747. Daemon sessions now use the managed plan bridge with finalized-result correlation, exact active-turn binding, ordered reconnect and replacement-worker recovery, and strict extension/source verification. Prime Agent 0.8.1 ACP fallback retains only its standard nativePlanUpdatedsupport because it drops custom result details; review managed-tool ACP parity separately.8698a69e. Managed Prime plans now distinguish user, delegate, and external waits; derive current-turn delegated-work aggregates without child plan rows or extra model calls; recover the latest current-turn plan after restart; and reset dismissals only after meaningful wait changes.Blocked on lifecycle design
heartbeats_changed, but heartbeats can start native runs outside canonical Pylon turn/checkpoint ownership. Define autonomous-turn identity, resident-session reattachment/demotion, reaper behavior, and fail-safe stop/delete before exposing them.Implementation rules
tool_execution_startas intent only. Commit task state only from a successful finalized result.pending,inProgress,waiting, orcompleted. A waiting step must namewaitingOn: user | delegates | external; non-waiting steps reject it.Upstream watch ledger
Recheck the Prime Agent entries below during Prime Agent upgrades.
registerTool()and standard tool lifecycle events exist; no supported arbitrary daemon-event emitterT3 upstream entries moved to the review ledger
The three T3 rows this table used to carry now live in the
## Upstream watch listof.agents/upstream-review.mdasWATCH-1(task parity,#5760/#8097),WATCH-2(owned MCP,#6573), andWATCH-3(scheduling,#7966/#7986). Thereview-t3-upstreamskill reads that list on every review; it never read this issue.That gap was not theoretical.
#6573and#7986both closed unmerged on 2026-08-28, the same day as a T3 upstream review, and#7966closed with them — so two of the three rows here described upstream efforts that had already stopped. Nothing was adopted wrongly, because none of the watched work ever merged, but nothing caught it either.Independent review of all three (2026-08-29) produced dedicated design issues for the two that need a product
decision before any code: #174 (cross-thread messaging — declined as a port;
thread_sendinherits thetarget's runtime mode, which is permission escalation by routing, and it contradicts this issue's
"no generic mutating MCP surface" non-goal) and #177 (scheduled runs — declined as a port; 15+ verified
defects and the unwritten safety contract this issue already tracks under "Prime scheduled prompts").
WATCH-1's upstream#8097remains open and is superseded by #137, which shipped the task-restoration fix first. The OpenCode defect tracked by#5760is now fixed in Pylon #283, which adopts upstream #9653 and its approval/Stop dependencies with Pylon-specific adaptations; task-only #178 was closed as superseded.Each
WATCH-entry names its design issue asOwner. When one comes due, is rewritten, or is retired, update this issue in the same pull request, and vice versa. The list and the skill change that enforces it landed in PR #173.Explicit non-goals
T3 watch recheck — September 5, 2026
The ledger update merged as Pylon #279, reviewed against T3
f12d39359f0f76a64ff2d77959c5baf821df15be.T3 watch recheck — September 6, 2026
Upstream reviewed through
bfba7781681eaa03eb465ce3d9a4ec07bf952b78for this targeted catch-up; the full review cursor remains unchanged.September 10–12 first-class provider delivery
8069dbd67; protected upstream sync run34570563183passed and chore(upstream): adopt the 2026-08-16 T3 Code batch #44 closed.8ba8d79f8, resolving prime-agent#53. Both macOS/Linux CI passed 203 core tests, 28 stress tests, all 3,034 crash cuts and the actual 16 MiB maximum; all three checkpoint reviews passed.224a5c013. Independent review, 29 focused regressions, 10 real-workflow-byte proofs and full PR CI passed.b2da85d63. Reviewed full macOS/Linux CI passed; the next real preview successfully packed, reproduced, installed and verified six-subject signing/provenance.83fe3dfe3, and add matching immutable consumer policy 3 in #485, merge9d0b2af20. Both checkpoint reviews passed. The exact fork tree passed all hosted checks; independent audits of both platform artifacts verified 205 core tests, 28 stress tests, all 3,034 crash cuts and the actual 16 MiB maximum. Pylon passed 35 focused tests, 18 actual-workflow-byte proofs, and full PR and merged CI. The prior source's valid tag and empty draft remain preserved. Corrected protected preview run34630984964and exact merged-source CI34630984909passed. Immutable previewpylon-build-g83fe3dfe3f10-r1was published with six exact signed assets; all public bytes match their attested subjects.f7433522d. Exact-head and merged CI passed; real immutable attestation verification is covered offline without crypto stubs.9b287c062. Checkpoint review, 100 focused tests and full PR CI passed.82961cd65. The root includes all 196 locked runtime dependencies without install-time npm. Actual archive verification, both installed-runtime checks, reproducibility, checkpoint review and all hosted checks passed. Independent Linux/macOS artifact audits each verified 205 contract tests, 29 stress tests, all 3,034 crash cuts and the actual 16 MiB maximum. The targeted stress correction preserves the exact safe losing-builder refusal, with a deterministic three-process regression; production ownership rules remain unchanged. The later merged-source macOS run correctly refused a changing file-stat snapshot in a retained historical test; CI34650047646and preview34650047647were cancelled before any publication approval. prime-agent#61 makes that historical proof handoff deterministic while preserving every negative and runtime check. Its exact reviewed heada7639b202passed all required hosted checks and independent full Linux/macOS artifact audits (205 contract, 29 stress, 3,034 crash cuts, actual 16 MiB). PR fix(skills): make phone-status truthful under eas-cli 22 #61 merged asa1ef2eca2. Exact merged-source CI 34656299880 and protected preview 34656299934 completed successfully. Independent audits verified both full platform artifacts. Immutable pylon-build-ga1ef2eca2ad0-r2 is public; all six public assets match their signed subjects. Actual Pylon Install/update preview succeeded with Native daemon, Authenticated, managed preview feat: adopt auto-settle-on-merge, wake icon alignment, and stage artwork #15; the actual installed launcher proves all four SDK tokens and recoverable session support.pylon-build-ga1ef2eca2ad0-r2: 34667627431, 31 passed and zero skipped. Protected stable publication 34663883733 succeeded; stable sequence 1 and in-app native managed installation were verified.65d9c0274. Full merged-source CI 34680283819 passed; both independent platform audits verified 205 publication tests, 29 stress tests, all 3,034 crash cuts and the actual 16 MiB maximum. Protected preview 34680283818 succeeded. Immutable pylon-build-g65d9c0274866-r2 is public, cryptographically verified, and installed through Pylon with Native daemon, Authenticated, and managed preview feat(mobile): nest task settings in bottom sheets #16; its actual launcher proves all required SDK features.5a09b2fce: exact failed-start authority cleanup, acknowledged daemon shutdown completion, and ordered correlated submission settlement. Independent checkpoints, 470 adapter/runtime/event tests, 33 manager tests, server typecheck, scoped lint and full CI 34685081750 passed. All three local real published-artifact restart cases passed.65d9c0274build and appends therecovery-cursor-losswithdrawal of affected stable sequence 1. The actual Pylon Update stable action succeeded; durable selection is managed/stable, high-water 2, exact new build selected, Native daemon and Authenticated. Existing identical bytes keep their original preview receipt display.4859f9501. All CI jobs,483 focused regressions, actual server typecheck, scoped lint and checkpoint review passed. Final real web/mobile active restarts retain native identity, rotate ownership/recovery handles and complete the same turns/checkpoints. Earlier failures and private authority evidence remain preserved.September first-class delivery: complete. All implementation PRs are merged, managed stable2 is public and installed successfully, and D1–D7 evidence and all plan PR links are recorded in the final closeout. The independent lifecycle/automation work elsewhere in this umbrella issue remains separate.
Standing maintainer approval covers completing these fixes, reviewed CI-green merges, and protected publication. The single authorized account reset is already used; no further reset will be used. All implementation and acceptance work in the September first-class plan is complete. No further reset or credential fallback was used.