Repository navigation
feat(people): restore device people and thread ownership on v2 - #180
Conversation
Agent work on this PREstimated cost unknown · 0 responses · 41 sessions · 5.0 h wall time
Flags: 3 human corrections · 64 large tool outputs · 44 repeated commands · 8 repeated failures · 65 repeated reads · 5 repeated skill loads · 40 sessions with usage bound to no task · 1 session without usage records Details: snapshot, prices, coverage, counters
Token counters by model (native counter semantics; never added across semantics): Selected rates (USD per million tokens). These rates value the report at the selected schedule date; they do not establish historical prices or subscription spending.
Other output and reasoning are priced without double counting inclusive native output. Missing rates remain unknown. Local measurement from native records; usage totals are not billing. Updated in place by |
Thread transfer impact✅ Thread transfer remains within every enforced ceiling.
Baseline: unavailable · PR result: Scenario and decoded snapshot size10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.
Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed. |
|
What: Independent source review of PR #180 at Findings
Elon recordRequirements and who asked: Issue #170 and root-approved #166 decisions; user requested an independent exact-head review. |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…elds The fixture fails on purpose until the backfill decision lands. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Allow the thread people backfill to read the frozen V1 owner columns, drop the never-consumed payload fixture, and fix two test type errors. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
95e5f2c to
6181550
Compare
|
What: Review of PR #180 at Resolved from the e89100f review
The original e89100f findings and failure status remain unchanged. Remaining finding[P2] Gate sharing actions on the server's existing operate scope At Trigger: A session can read threads and has a person label matching the thread owner (or co-owner), but lacks Expected: Gate the action using the existing Elon recordRequirements and who asked: Issue #170 and root-approved #166 decisions; user requested exact-head independent re-review. |
|
What: Independent review of PR #180 at e3f487b against base 2647478 found no remaining actionable source findings. Resolved findingGate thread sharing actions on the existing operate scope In apps/web/src/components/people/ThreadSharingControl.tsx:54, action visibility now requires useEnvironmentScope(environmentId, AuthOrchestrationOperateScope) alongside the existing command permission atom. At line 87, the click handler re-reads the same target environment's current scope before dispatch. The server already requires that scope for dispatchCommand. The client permission helper and global RPC scope registry remain unchanged, so this adds the requested feature-local UI gate without widening authorization behavior. The prior device-person selector and malformed consumed-payload findings remain resolved as recorded in the 618 review. The root-adjudicated D17 v1 sharing semantics remain intentional: this UI check does not add an owner-equals-actor rule or change server access policy. Review coverage and limitsThe cumulative 49-path candidate was reviewed by carrying forward the completed 618 review and inspecting this sole changed path, its target-environment session scope helpers, command permission helper, and server dispatch scope. No new actionable finding remains. The reviewer ran no tests, typechecks, lint, or browser verification. Planner integrated UI before/after evidence remains pending and unwaived; this is not a claim that the draft is ready for merge. Elon recordRequirements and who asked: Issue #170, root-approved #166 decisions, and the user's request for an independent exact-head review; use existing authorization scopes without changing sharing policy. |
What: Restore device-person selection, thread ownership and sharing on v2, including frozen v1 ownership carryover.
Why: Upstream v2 omits the fork's person fields and its importer does not carry the frozen owner columns.
So what: Exact-head independent review and current CI pass; this one PR stays draft pending planner UI evidence and user acceptance, with no merge authorized.
Closes #170
Devices can choose a person in Connections settings; the sidebar filters thread and draft views, and the chat header offers sharing and leaving. Server-side commands stamp the device person, agent creations inherit the caller's owner, forks belong to the acting person and children inherit their parent owner while starting unshared. Ownership remains a view, without access control. Sharing uses the existing metadata event and adds no timeline row.
A feature-owned backfill runs after #167 imports v2 shells, using only frozen v1 fields. Existing v2 fields win. Missing fields carry over exactly, including null and empty arrays. Malformed needed legacy values become null/[] with retained thread-id/reason diagnostics; structurally invalid payloads consumed by the migration block readiness through a typed error. This is migration validation, not a general v2 integrity scan. Atomic per-thread markers make partial failures and reruns safe.
Proof and dependencies
2647478da553b442c6e5000b76c3b42042b01e69(merged feat(fork): carry Chromeria foundation onto upstream V2 #178 foundation and feat(fork): port GitHub Issues onto v2 #179/Port the GitHub Issues features #171 Issues). Only Port thread people and ownership #170 feature commits rebased; no foundation ancestors replayed.e3f487b846b8134304630a32c431f95bef9d4474. Supported Node24.13.1, host-neutral environment: full auth/session/boundary plus affected server/client RPC permissions 79/79 pass. Focused coverage covers all157 unique tests across17 files: initial serial run155 passed/two snapshot timeouts; root directed low-load serial full-file proof then passed foundation2/2 and people5/5 without test/timeout/source changes. Duplicate fixture assertions are not counted twice. After review fixes and rebase, the backend-proof head61815505341d1112c8a86f00102d53c7b9c60607 people full file passes5/5 at initial1-minute load4.11, real test16.920s; foundation2/2 at initial load3.36 is reused because its backfill source/registry/fixtures/environment/input are unchanged. Failed logs remain retained.VACUUM INTOsnapshot:739 imported,0 missing,0 mismatched,0 unresolved,0 hydrated transcripts,0 rerun events. Synthetic shared/other-person/malformed fixtures and injected transaction-failure rollback are covered.e3f487b846b8134304630a32c431f95bef9d4474; findings and resolution were published beforereview/independentsuccess, verified by creatorlukemaj. Current-head CI is all green, including independent review (gh pr checksexit 0, live verified). Planner integrated UI before/after evidence remains pending and unwaived; no browser verification claimed. PR remains draft for this acceptance item.Known intentional property
Preliminary reviewer observed that a non-owner can send
thread.sharedirectly despite the UI hiding the action. Root adjudicated preservation of v1 semantics under D17, view filtering without access control; reviewer withdrew it as a defect. Frozen source v1 decider has the same checks. No owner-only access policy is introduced.Elon record
Requirements and who asked: User requested #170, device person/auth, v2 ownership, frozen owner/co-owner backfill, one PR and focused proof.
Deleted: Sharing timeline row, v1 projection machinery, component PRs and unrelated ports.
Bottleneck: Planner integrated UI evidence and user acceptance; source review, current CI and required local proof have passed.
Checked myself: Live landed base, feature-only rebase, source and draft/shell consumers, actual test output, sanitized snapshot equality, inventory ownership and root decisions.
Implemented by Claude Opus5.5 through T3/Prism; integration by GPT-6.1-Sol through Codex/T3. Independent reviewer routed by Prism through Codex (GPT-6-Luna).