Skip to content

feat(assistant): human review and owner-approved Ornn publication for agent learning, dormant behind assistant:agent-learning (0.61.0) - #1765

Merged
chronoai-kai merged 10 commits into
mainfrom
feat/agent-learning-review
Oct 5, 2026
Merged

chronoai-kai merged 10 commits into
mainfrom
feat/agent-learning-review

Conversation

@chronoai-kai

Copy link
Copy Markdown
Contributor

Summary

L1 PR-2: human review and owner-approved publication for agent learning proposals, dormant behind assistant:agent-learning (default off). Builds on PR-1 (#1756, v0.58.0).

  • Review: encrypted proposals can be listed, edited (revision bump) and rejected. Rejection records the fingerprint and suppresses regeneration. Drafts render as untrusted plain text.
  • Approval: one one-use owner action card is bound (arguments digest) to one publication operation, its proposal revision, the B2 skills_revision, the config revision and the package SHA-256. The card is consumed in the same retrying transaction that claims the publication lease. A replay can only resume its own durable operation.
  • Publication:
    • NyxID builds a deterministic private Ornn package with a server-chosen name embedding the operation UUID and JSON-quoted frontmatter.
    • Calls are limited to a fixed Ornn operation allowlist (validate/create/update plus exact readback).
    • Improvements must extend the approver's own private, latest, dependency-free base pinned on the agent.
    • Any failure after egress is ambiguous and reconciled to exactly one verified match. A started write is never reissued.
  • Pinning: the published version is pinned through the shared B2 revision fence in the same transaction that completes the proposal. Root provenance is append-only, and its activeness is derived at read time from the agent's current pins.
  • Org agents: publication is refused with owner_binding_unavailable.
  • NyxBot: status/list/run tools. The human UI uses components/ui primitives and the feature-flag hook.

Backward compatibility

  • Ordinary B2 skill saves (agent_skill_service::set) are unchanged and never read or write learning storage; a test asserts this. The Ornn allowlist covers every existing B2 read and search path.
  • Flag off: every learning route answers disabled and touches no learning collection (tested).
  • Model changes are additive or serde-defaulted. All new routes are first-party-human only under /assistant/nyxagent.
  • PR-1's finish_run now uses the retrying and_run2 transaction pattern, with unchanged semantics.

Validation

  • Implementer, at both default and RUST_MIN_STACK=1572864: backend filters learning 3, publication 2, review 11, agent skills 11. Review tests cover ACL refusals (org member, guest, non-orchestrator, unrelated agent), card invalidation after edit or skills_revision change, reconcile refusal for zero and two matches, no reissue, and lease-expiry resume.
  • Rust 1.98.1 clippy --all-targets -D warnings; fmt. Frontend: 4,228 tests, lint, build.
  • Reviewer: three rounds. Fixes included a missing test suite, the B2 set regression (a retry-less transaction plus a dormant learning write), retry-less transactions, UI conventions, the durable error boundary, and 403 on timeouts.

chrono-kw added 8 commits October 4, 2026 19:33
… dormant behind assistant:agent-learning (L1 PR-1)
# Conflicts:
#	backend/src/services/feature_flag_service.rs
… request access snapshot

Thread creation paid a personal flag resolution (which reads org memberships)
on every new thread even when the agent has no learning config, breaking the
org group single-auth-resolution guarantee. Check the learning config by _id
first and reuse the caller's org access snapshot for the ACL.
…s before any learning read

Keeps both guarantees: flag-off enrollment touches no learning collection, and
thread creation with a request snapshot adds no org membership reads. The full
personal resolution runs only after a learning config exists when the flag may
be on broadly.
… agent learning proposals (L1 PR-2)

Merges origin/main (0.60.0). Encrypted proposal review, edit and reject with
fingerprint suppression; one-use owner action card bound to one publication
operation; deterministic NyxID-built private Ornn packages through a fixed
operation allowlist; ambiguous publication reconciles and never repeats a
started write; publish-and-pin shares the B2 skills revision fence. Org agents
refuse publication (owner_binding_unavailable). Ordinary B2 skill saves are
unchanged and never touch learning storage.
@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

📊 Code coverage

Component Lines Threshold Status Δ vs base
Backend (nyxid) 86.96% 73% ✅ 🔻 -0.06
CLI (nyxid-cli) 69.26% 64% ✅ — 0.00
Frontend (vitest) 72.22% 15% ✅ 🔺 +0.01

Gate: line coverage must stay at or above the threshold. Ratchet plan (W21): Backend → 55%, CLI → 50%, Frontend → 30% by quarter end.

…eview

# Conflicts:
#	Cargo.lock
#	backend/Cargo.toml
#	cli/Cargo.toml
#	cli/src/wizard/bundle-meta/index.hash
#	frontend/package-lock.json
#	frontend/package.json
chronoai-kai added a commit that referenced this pull request Oct 5, 2026
…nostics on failure (#1769)

Coverage (Backend) and Coverage (Backend Base) lost mongod at the same
cumulative point (~840-960 s, auth_device_service tests) on #1765/#1766 with
~7 GB host memory still free; mongod held ~8 GB when it vanished. Raise the
descriptor limit far above the nextest peak (thousands of per-test databases'
WiredTiger files stay open in one llvm-cov process) and cap the WiredTiger
cache at 2 GB. On failure or cancellation, print the container state
(exit code, OOMKilled), mongod descriptor count/limits, kernel OOM lines and
the server log tail so any recurrence is diagnosable.

Co-authored-by: chrono-kw <chrono-kw@users.noreply.github.com>
@chronoai-kai
chronoai-kai merged commit 964e10c into main Oct 5, 2026
37 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant