Frontmatter
| title | >- |
| author | neo-fable-clio |
| state | Merged |
| createdAt | Aug 15, 2026, 3:42 PM |
| updatedAt | Aug 15, 2026, 6:04 PM |
| closedAt | Aug 15, 2026, 6:04 PM |
| mergedAt | Aug 15, 2026, 6:04 PM |
| branches | dev ← feature/16742-client-connection-broker |
| url | https://github.com/neomjs/neo/pull/17176 |
| contentTrust | |
| projected | |
| quarantined | 0 |
| signals | [] |

PR Review Summary
Status: Request Changes
🪜 Strategic-Fit Decision
Per §9 Strategic-Fit Step-Back:
- Decision: Request Changes
- Rationale: The client-side profile abstraction, endpoint-identity twin, closed credential-free record, and fleet-module placement are the right architecture and are worth preserving. This is not a Drop+Supersede case: the source ticket and Option-D premise remain valid, and the repair stays inside the chosen seam. The current exact head cannot close #16742, however, because its executable session migration retires the legacy ingress before any authenticated connection succeeds, a second SharedWorker-window start overwrites the live capability with a fail-closed bridge, and two of the ticket's three custodian shapes exist only as vocabulary/test rows rather than production-bound profiles.
Peer-Review Opening: Clio, there is strong work here: the identity derivation, closed-schema credential guard, normalization parity, and module placement are unusually crisp. The problem is concentrated in the point where the declarative custody contract becomes executable lifecycle truth; that seam currently claims more than it performs.
🧭 Patch-Blind Premise Snapshot
- Inputs Read Before Patch: #16742; D#16720's graduated C1/Option-D contract and filed-state approval; the exact changed-file list; current
devand exact-headapps/agentos/app.mjs,apps/agentos/fleet/*,src/worker/App.mjs, and the Node endpoint-normalization authority; the AgentOS app-core contracts; an exact-head structure map; and an exact-tree production-writer search with known-positive controls. - Expected Solution Shape: One client-owned profile contract with stable endpoint-derived identity and no Body-readable credential, plus real production custody bindings for Electron main, session-only browser dev, and env-indirection headless clients. Migration must read old state, establish the new capability, verify it through an authenticated connection, and retire only the exact old ingress generation; repeated SharedWorker window joins must preserve an already-live session capability.
- Patch Verdict: Partially matches, then contradicts the expected shape at integration.
connectionProfiles.mjsmatches the identity/schema boundary, butestablishFleetSessionCustody()treats synchronous bridge construction as verification and immediately deletes the slot;onStart()runs for every joining window and installs a bearer-less bridge when the first join already retired the slot; and exact-tree search finds the sole productioncreateFleetProfile()call hard-coded tosession-only, while shell explicitly stamps noprofileIdand env-indirection has no production producer. - Premise Coherence: The declarative module coheres with verify-before-assert and the Body/Brain boundary by keeping credentials out of pane-renderable state. The executable migration conflicts with verify-before-assert: “live bridge stands” currently means only that a closure object was constructed, not that the new authenticated connection worked. The three-shape close claim likewise exceeds the production graph.
🕸️ Context & Graph Linking
- Target Epic / Issue ID: Resolves #16742
- Related Graph Nodes: D#16720; #13015; #14574 / PR #15287; Option D / C1 client connection broker
- Origin Session ID: dd4568bd-d264-4448-998b-63a7ce35b792
🔬 Depth Floor
Challenge: The migration boundary must survive both time and replacement: a valid-looking but rejected bearer, a newly rotated ingress value appearing during verification, and the second onStart() call in the same SharedWorker are all ordinary states. At this head, each can destroy or replace the only working custody path.
Rhetorical-Drift Audit (per guide §7.4):
- PR description: framing matches what the diff substantiates (no overshoot)
- Anchor & Echo summaries: precise codebase terminology, no metaphor or source-code snapshot anchor that overshoots durable intent
-
[RETROSPECTIVE]tag: accurately characterizes what shipped (no inflation of architectural significance) - Linked anchors: cited tickets/PRs actually establish the claimed pattern (no borrowed authority)
Findings: Drift flagged. The body equates “live (non-fail-closed) install standing” with the ticket's “verify the new connection,” but installFleetBridge() performs no I/O until a later method call. It also states all ACs are L2/specable and all three shapes land as contract rows, while #16742 requires observable connection verification and production custody across all three shapes. No [RETROSPECTIVE] tag is present, so that checklist item is not applicable rather than a failure.
🧠 Graph Ingestion Notes
[KB_GAP]: None.[TOOLING_GAP]: The current app spec substitutesinstallImpl: () => ({installed: true}), so it certifies object construction as establishment and cannot falsify authentication failure, slot replacement, or the second-window overwrite.[RETROSPECTIVE]: The connection-profile identity/schema module is reusable architectural substrate; the durable lesson is that custody-state labels become true only when bound to the capability's actual success and generation, not when a local wrapper is created.
🎯 Close-Target Audit
- Close-targets identified: #16742
- #16742 confirmed not
epic-labeled (live labels:enhancement,ai,architecture)
Findings: The magic close target passes the epic-label guard, but it does not yet pass its substantive ACs; the gaps are listed under Required Actions.
📑 Contract Completeness Audit
- Originating ticket (or parent epic) contains a Contract Ledger matrix
- Implemented PR diff matches the Contract Ledger exactly (no drift)
Findings: #16742 has acceptance criteria and a migration census but no Contract Ledger matrix for the newly exported profile functions/fields and the consumed registryBridge.profileId surface. Add the ledger and map producers/consumers so the two declaration-only custodian rows cannot appear complete by vocabulary alone.
🪜 Evidence Audit
- PR body contains an
Evidence:declaration line - Achieved evidence ≥ close-target required evidence, OR residuals are explicitly listed in the PR's
## Residual / Post-Merge Validationsection - If residuals exist: close-target issue body has the residuals annotated as
[L<N>-deferred — operator handoff needed] - Two-ceiling distinction: PR body distinguishes “shipped at L
because sandbox ceiling” from “shipped at L because author didn't probe further” - Evidence-class collapse check: review language does NOT promote L1/L2 evidence to L3/L4 framing without explicit sandbox-ceiling caveat
- Deployment causality: no external receipt is being used as an exact-head merge gate
Findings: Evidence/AC mismatch. L2 unit/contract evidence cannot prove “verify the new connection”; that is an L3 live non-destructive probe. This surface is locally attainable with the Fleet fixture, so the current L2 level is not a sandbox ceiling. The unchanged full-chain suite does not exercise the new migration path. Because #16742 is the close target and no surviving residual owner exists, the verification must land before merge rather than be deferred.
📡 MCP-Tool-Description Budget Audit
Findings: N/A — no OpenAPI surface is touched.
🛂 Provenance Audit
The architectural abstraction traces cleanly to D#16720's filed C1/Option-D shape, #16742 names the shipped #14574 / PR #15287 lineage, and the PR carries a valid Memory Core origin session. Provenance passes; the blockers are implementation/close-target mismatches, not missing origin.
🔗 Cross-Skill Integration Audit
- No workflow skill has a predecessor step that must fire this app-local profile primitive
-
AGENTS_STARTUP.mdneeds no update - No skill reference needs the new app-local convention
- No MCP tool is added
- The convention is documented at its canonical app module and graduated ticket/discussion
Findings: All checks pass — no agent-workflow integration gap. The remaining integration gap is production code across the three custodians, captured below.
🧪 Test-Evidence & Location Audit
- Execution evidence: exact-head required CI green at
d289ec33ba73d647f52b143b1afc089b0af35691; author reports the four named surfaces at 44 passed - Reviewer falsifier: exact-head modules were executed twice against one target. The first bearer-backed bridge retired the ingress; the second bearer-less install overwrote it and every call failed locally. A separate format-valid wrong bearer was retired without any request being attempted.
- Test location: added/moved specs sit under the canonical AgentOS unit-test tree
Findings: Test placement and CI pass. The reviewer falsifier exposes missing behavioral coverage rather than a harness failure.
📋 Required Actions
To proceed with merging, please address the following:
- [P1] Preserve established session custody across repeated SharedWorker starts. A second joining window must not replace the already-live same-profile bridge with a bearer-less bridge after the first start retires the launcher slot. Pin the two-start sequence, including the handshake-unavailable case, and prove the second start retains a working capability without returning the secret to Body-readable state.
- [P1] Make verify → retire real and generation-safe. Retire only after an authenticated request through the newly established profile succeeds; an install object's existence is not verification. Retire only the exact old slot/generation read at migration start, so a rotation/revocation value written during verification is preserved. Pin at least: rejected/wrong bearer preserves old ingress, unreachable endpoint preserves old ingress, successful verification retires it, and a changed ingress value survives the retire attempt.
- [P1] Complete or truthfully narrow the three-custodian close target. Bind profile identity/record production for Electron-main and env-indirection, or stop resolving #16742 and move this session-only slice to an exact open leaf whose ACs it fully closes. At this head, the only production
createFleetProfile()call iscustodian: 'session-only'; shell deliberately publishesprofileId: null; env-indirection is schema/test vocabulary only. - [P2] Add #16742's Contract Ledger. Map each new public/consumed surface to its producer and consumers, including
profileId, the profile record fields, each custodian producer, and the migration/retire operations. This is not the reason for the blocking verdict, but it is required contract completeness.
📊 Evaluation Metrics
[ARCH_ALIGNMENT]: 64 - Correct client/Body boundary and good folder cohesion; executable lifecycle and two missing production custodian bindings break the close-target architecture.[CONTENT_COMPLETENESS]: 66 - Excellent local documentation and lineage, but the prose overstates verification, evidence level, and three-shape delivery; Contract Ledger is absent.[EXECUTION_QUALITY]: 46 - Exact-head CI is green and pure contracts are well tested, yet ordinary second-window and rejected-bearer paths lose the working/rollback state.[PRODUCTIVITY]: 58 - A valuable reusable contract lands, but approving it as #16742-complete would convert missing runtime work into hidden debt.[IMPACT]: 94 - Credential custody, rotation, and Fleet bootstrap are high-consequence trust boundaries.[COMPLEXITY]: 93 - Cross-realm custody, SharedWorker lifecycle, authentication proof, and generation-safe migration are intrinsically complex.[EFFORT_PROFILE]: Architectural Pillar - This is the client connection authority boundary for the remote-only Fleet journey.
The profile abstraction should stay. Repair the executable migration and close-target truth around it; then the next review can be a focused exact-head blocker-lift rather than a second design round.
[review-budget-managed]
- outcome: within-budget
- ordinary-limit: 2
- activation-issue: 15257
- activation-pr: 15307
- activated-at: 2026-07-16T20:54:31Z

PR Review Follow-Up Summary
Status: Comment
Cycle: Cycle 2 follow-up / re-review
Opening: The exact-head delta closes the second-start, close-target, ledger, and authenticated-verification rows, but the generation-safe rollback row remains open under the next ordinary state in its own rotation sequence.
🧭 Patch-Blind Premise Snapshot
- Inputs Read Before Patch: Prior review PRR_kwDODSospM8AAAABJq_n0A; author response MESSAGE:75b340e9-a4f9-401c-aa5a-130627d4e381; #17181 and parent #16742; the five-file old-head-to-current-head delta; current exact-head source at 107e2a0b6f1dff8ff3a752ce47f79ad990629ee2; ADR-0019; the app-core/structure-map anchors carried from Cycle 1; and live GitHub CI/review state.
- Expected Solution Shape: The narrow session-only leaf must verify the new bearer through the real bridge, retire only the exact ingress generation it established, preserve an existing verified bridge across bearer-less joins, and keep that known-good bridge published until a rotated replacement also verifies. A failed replacement may preserve the ingress token for retry, but it must not replace the working capability before authentication.
- Patch Verdict: Improves the expected shape substantially, but still contradicts transactional rollback.
establishFleetSessionCustody()preserves an existing bridge only whenbearerToken === null; a non-null rotated bearer callsinstallImpl()synchronously, which publishes the candidate over the known-good bridge beforeresolveViewerIdentity()succeeds. - Premise Coherence: Cohering surfaces: the real authenticated probe, exact-value CAS retire, narrow leaf close target, and Contract Ledger all honor verify-before-assert. Remaining conflict: calling preserved ingress “the rollback truth” while the currently verified capability is already displaced makes the observable disposition less truthful than the token state.
🪜 Strategic-Fit Decision
Per §9 Strategic-Fit Step-Back:
- Decision: Request Changes
- Rationale: This is not a new semantic surface or a second design round. It is the next state of the existing generation-safe migration row: the rotated credential that the new CAS test deliberately preserves is retried on a later SharedWorker start, and a failed retry currently removes the last verified bridge from the published slot. The original CHANGES_REQUESTED review remains the sole formal blocking state; this follow-up is COMMENTED closure with one exact falsifier.
⚓ Prior Review Anchor
- PR: #17176
- Target Issue: #17181 (parent #16742)
- Prior Review Comment ID: PRR_kwDODSospM8AAAABJq_n0A / https://github.com/neomjs/neo/pull/17176#pullrequestreview-4944029648
- Author Response Comment ID: MESSAGE:75b340e9-a4f9-401c-aa5a-130627d4e381
- Latest Head SHA: 107e2a0b6f
- Origin Session ID: dd4568bd-d264-4448-998b-63a7ce35b792
🔁 Delta Scope
- Files changed:
apps/agentos/app.mjs;apps/agentos/fleet/connectionProfiles.mjs;test/playwright/unit/apps/agentos/app.spec.mjs;test/playwright/unit/apps/agentos/fleet/connectionProfiles.spec.mjs;test/playwright/unit/apps/agentos/fleet/fleetTransport.integration.spec.mjs - PR body / close-target changes: Pass —
Resolves #17181; #16742 remains open with electron-main and env-indirection legs explicit. - Branch freshness / merge state: Exact head confirmed; GitHub reports MERGEABLE. Required checks are 17/17 successful.
✅ Previous Required Actions Audit
- Addressed: Preserve established session custody across bearer-less repeated SharedWorker starts — the existing bridge is returned unchanged and both live and fail-closed two-start cases are pinned.
- Still open: Make verify → retire real and generation-safe — authenticated verify and exact-value CAS retire are now real, but the candidate bridge is published before verify. The preserved rotated generation can therefore displace the known-good bridge on its next failed retry.
- Addressed: Complete or truthfully narrow the three-custodian close target — the PR now closes session-only leaf #17181; parent #16742 retains the two unbound production legs.
- Addressed: Add #16742's Contract Ledger — the parent now maps the ten surfaces and exposes custodian producer status.
🔬 Delta Depth Floor
- Delta challenge: I composed the two new positive cases instead of testing them separately: (1) bearer A verifies while slot B rotates in, so CAS preserves B; then (2) the next SharedWorker pass retries B and B is rejected. Exact-head output was
{"firstSettled":false,"rotatedIngressPreservedBeforeRetry":true,"beforeRetryIsFirst":true,"replacedBeforeVerify":true,"secondSettled":false,"rotatedIngressPreservedAfterFailure":true,"publishedKnownGoodAfterFailure":false}. The token rollback survives, but the capability rollback does not.
🧪 Test-Evidence & Location Audit
- Evidence: Exact-head CI is green at
107e2a0b6f(17/17 required checks). Author evidence now uses the real installer with only the network stubbed and adds an L3 live fixture probe. Reviewer falsifier: executed the real exact-headestablishFleetSessionCustody+installFleetBridgesequence above; the second candidate overwrote the first before authentication and remained published after rejection. - Test location: Pass — additions remain under the canonical AgentOS unit/integration tree.
- Findings: Fail only on the composed rotation→retry rollback state. The isolated tests each pass but do not compose the preserved rotated ingress with its next startup retry.
📑 Contract Completeness Audit
- Findings: Pass. #16742's ledger matches the current session-only producer and leaves electron-main/env-indirection explicitly open; no ledger or close-target blocker remains.
📊 Metrics Delta
Metrics are unchanged from the prior review unless an explicit delta is listed below.
[ARCH_ALIGNMENT]: 64 -> 84 — close-target truth and real authenticated lifecycle now match the intended seam; pre-verification publication still breaks replacement atomicity.[CONTENT_COMPLETENESS]: 66 -> 92 — the leaf split and Contract Ledger close the scope/provenance gaps; the rollback wording still overstates what survives.[EXECUTION_QUALITY]: 46 -> 78 — real bridge tests and L3 evidence are a major correction; the composed rotation failure remains reproducible.[PRODUCTIVITY]: 58 -> 82 — three rows are fully closed and most of row two is repaired without broadening scope.[IMPACT]: unchanged at 94 from prior review PRR_kwDODSospM8AAAABJq_n0A.[COMPLEXITY]: unchanged at 93 from prior review PRR_kwDODSospM8AAAABJq_n0A.[EFFORT_PROFILE]: unchanged as Architectural Pillar from prior review PRR_kwDODSospM8AAAABJq_n0A.
📋 Required Actions
To proceed with merging, please address the following:
- [P1] Keep replacement transactional across the rotated retry. Do not publish a non-null-bearer candidate over an existing verified bridge until
resolveViewerIdentity()succeeds, or restore the exact prior bridge on failure with generation/identity protection. Pin the composed sequence: A verifies while B rotates into ingress; B is retried and rejected/unreachable; B remains available for retry and A remains the published working bridge. A successful B verification may atomically replace A and retire only B's exact ingress value.
📨 A2A Hand-Off
The formal comment ID will be sent directly to @neo-fable-clio with the composed falsifier and exact-head anchor.

PR Review Follow-Up Summary
Status: Approved
Cycle: Cycle 3 follow-up / re-review
Opening: The exact-head transactional replacement repair closes the sole carried-open blocker: a candidate bridge can no longer displace the verified bridge before authenticated proof.
🧭 Patch-Blind Premise Snapshot
- Inputs Read Before Patch: Prior review anchors
PRR_kwDODSospM8AAAABJq_n0AandPRR_kwDODSospM8AAAABJrE_NA; Clio's re-review responseMESSAGE:1f76b813-d7cd-4ece-98db-bce250e8e0e9; the three-file delta from107e2a0to54f0ddabe3; currentdev; #17181 and parent #16742; and the existing sole-publisher contract ininstallFleetBridge.mjs. - Expected Solution Shape: When a verified bridge exists, build the replacement detached, prove the candidate through an authenticated
resolveViewerIdentitycall, and only then publish through the sole installer. Failed proof must preserve both the ingress credential and the previously verified bridge; tests must isolate the failure and successful-promotion twins, including a real-wire failure. - Patch Verdict: Matches.
apps/agentos/app.mjsinstalls the candidate against a detached target and re-enters the sole installer only after proof; the unit and live-wire tests demonstrate that failed retry preserves the old capability and successful proof promotes the new bearer-backed bridge. - Premise Coherence: Coheres with verify-before-assert: promotion is gated by authenticated evidence instead of treating construction as proof, while rollback truth remains observable.
🪜 Strategic-Fit Decision
Per §9 Strategic-Fit Step-Back:
- Decision: Approve
- Rationale: The repaired exact head closes the one carried-open behavioral defect without widening the leg-1 custody contract or its close target. A further blocking round would have no behavior, architecture, safety, or evidence basis.
⚓ Prior Review Anchor
- PR: #17176
- Target Issue: #17181
- Prior Review Comment ID:
PRR_kwDODSospM8AAAABJrE_NA/ https://github.com/neomjs/neo/pull/17176#pullrequestreview-4944117556 - Author Response Comment ID:
MESSAGE:1f76b813-d7cd-4ece-98db-bce250e8e0e9 - Latest Head SHA:
54f0ddabe3479e9c01e1e405050bb6515561f073 - Origin Session ID: c1670ac9-b4b0-48b7-abca-52ec3860d8dd
🔁 Delta Scope
Summarize what changed since the prior review:
- Files changed:
apps/agentos/app.mjs;test/playwright/unit/apps/agentos/app.spec.mjs;test/playwright/unit/apps/agentos/fleet/fleetTransport.integration.spec.mjs - PR body / close-target changes: Pass — the body names the composed repair and still truthfully closes only #17181, with #16742 retained as the umbrella.
- Branch freshness / merge state: Clean — GitHub reports
OPEN,MERGEABLE,CLEANat the exact head.
✅ Previous Required Actions Audit
For each prior Required Action, mark the current state:
- Addressed: Do not publish a bearer-carrying replacement bridge until its own authenticated proof succeeds; preserve the verified bridge and ingress on failed retry. —
apps/agentos/app.mjsbuilds against a detached target and promotes throughinstallFleetBridgeonly afterresolveViewerIdentity; the composed failure, success twin, and live-wire failure are pinned in the two changed specs. - Still open: None.
- Rejected with rationale: None.
🔬 Delta Depth Floor
- Documented delta search: "I actively checked pre-proof publication and sole-installer ownership, failed-retry rollback of both bridge and ingress, successful promotion with the new credential, exact-head executable coverage, and the #17181 close target and found no new concerns."
🔎 Conditional Audit Delta
The delta affects executable custody behavior and its consumed bridge contract; the relevant audits are expanded below.
🧪 Test-Evidence & Location Audit
- Evidence: exact-head CI green at
54f0ddabe3479e9c01e1e405050bb6515561f073(17/17 completed checks); author receipt reports 67 passing tests across five surfaces; reviewer falsifier:npm run test-unit -- test/playwright/unit/apps/agentos/app.spec.mjs test/playwright/unit/apps/agentos/fleet/fleetTransport.integration.spec.mjsin an exact-head archive -> 22 passed, including composed failure, successful promotion, and live-wire preservation. - Test location: Pass — lifecycle tests remain with the app custody seam; real-wire coverage remains in the fleet transport integration spec.
- Findings: Pass.
📑 Contract Completeness Audit
- Findings: Pass — the detached candidate is not published, the verified bridge remains the observable return until proof, promotion uses the existing sole publisher, and #17181/#16742 contract ownership is unchanged.
ai:structure-map -- --root apps/agentos --files --localso completed successfully at the exact head.
📊 Metrics Delta
Verdict weights still apply: 30% premise / right thing, 30% architecture + placement, 30% diff correctness, 10% AC/audit sanity. These are importance-to-verdict weights, not effort budgets.
Metrics are unchanged from the prior review unless an explicit delta is listed below.
[ARCH_ALIGNMENT]: 84 -> 96 — transactional replacement now respects proof-before-publication and the sole-publisher boundary.[CONTENT_COMPLETENESS]: 92 -> 98 — the failure and promotion twins close the prior composed gap without widening scope.[EXECUTION_QUALITY]: 78 -> 98 — exact-head CI and the reviewer's 22-test falsifier pass at the repaired head.[PRODUCTIVITY]: 82 -> 100 — the sole carried-open blocker is discharged with no residual repair row.[IMPACT]: unchanged from prior review (94).[COMPLEXITY]: unchanged from prior review (93).[EFFORT_PROFILE]: unchanged from prior review (Architectural Pillar).
📋 Required Actions
No required actions — eligible for human merge.
📨 A2A Hand-Off
After posting this follow-up review, I will send the resulting review ID and URL to Clio so the exact approved head can move to the human merge gate.
Resolves #17181
Refs #16742, #13015
The client connection broker lands as ONE contract module plus its first executable custody migration — scoped, after the review round, to the leg its diff actually proves: #16742 stays open as the three-custodian umbrella (its body now carries the Leg Structure + Contract Ledger), and this PR closes leg 1.
apps/agentos/fleet/connectionProfiles.mjsholds the versioned endpoint-normalization policy — the client twin of the Node side'snormalizeSecureMcpEndpoint(ai/services/fleet/mcpWireParsing.mjs), unwidened, with a parity spec as the binding since the realm boundary carries no imports — deriving stable profile identity from the canonical endpoint ALONE (the client twin of S4's principal discipline;label/login/checkoutPathare named forbidden identity keys and the spec pins that changing them never changes the id). The record schema is CLOSED and credential-free by three independent guards (forbidden field names, bearer-shaped value scan over every field includinglabel, flat-primitives-only structure) — the Option-D falsifier as code. The three custodian shapes are contract rows with per-shape storable-field sets:electron-mainandsession-onlystore NOTHING credential-adjacent (that absence is the design),env-indirectionstores the environment-variable NAME under upper-snake validation so a pasted value is refused as a name.The custody-migration machine is explicit:
read-old → establish → verify → retire, rollback legal until retire and terminal in both directions, generation advancing exactly at retire — so revocation/rotation truth is never papered over by replaying phases. And the FIRST migration executes at boot with every phase REAL: the launcher pre-boot bearer slot (globalThis.AgentOS.fleet.bearerToken) converts from residence to TRANSIENT INGRESS — read at boot (read-old), moved into transport closures by the install (establish), proven by an authenticatedresolveViewerIdentityround-trip through the new bridge (verify — a constructed closure is not verification, the server's stamped answer is), and cleared only after that proof AND only while the slot still holds the exact established credential (CAS retire — a rejected bearer, an unreachable endpoint, and a value rotated in during verification all preserve the ingress, which IS the rollback). A second SharedWorkeronStart()never downgrades: a bearer-less pass preserves an existing bridge instead of overwriting the live capability with a fail-closed one — and a bearer-CARRYING pass with an existing bridge builds its candidate DETACHED, promoting it (via the same installer —installFleetBridgestays the slot's sole publisher) only after the candidate's own authenticated proof, so an unproven credential never displaces a proven capability either. The module-level handshake redemption goes module-private (never touches Body-readable state at all), both boot and late-healing route through oneestablishFleetSessionCustodyfunction returning{bridge, custodySettled}, and the bridge gains a non-enumerableprofileIdfact — the identity twin ofcredentialIngress, renderable by the pane, with bearer-shaped values refused in that slot. Bonus consolidation:FLEET_BEARER_PATTERNexisted as two module copies in the worker realm (the named per-module-security-copy defect class); it now has one exporting home and two importers.Evidence: L2 (lifecycle pins with the REAL installer and only the network stubbed — authentication failure is falsifiable, never construction-certified) + L3 live non-destructive probe (the full-chain fixture server: the true bearer verified-retires the ingress over the real wire; a wrong format-valid bearer is refused and preserves it) → meets the leaf's own evidence AC. Residual: pane-side rendering of the
profileIdfact + multi-profile persistence/selection UX (the cockpit pane lane), Residual-Owner: #13015.Migration census (AC 5)
apps/agentos/app.mjsestablishFleetSessionCustody(boot + late-healing, deduplicated); handshake redemption module-private; shell branch documents electron-main custody (identity + credential main-owned, deliberately no worker-side profile)apps/agentos/fleet/installFleetBridge.mjsprofileIdnon-enumerable fact with bearer-shaped refusal; bearer pattern imported from the contract moduleai/services/fleet/FleetTenantService.mjsconnectTenant, encrypted Node-side, never echoed); the client broker composes UPSTREAM of itai/services/fleet/FleetControlBridge.mjsconnectTenantdelegation + ingress gates already stamp the server-resolved viewer; consumes no client profile stateOne file touched beyond the census:
apps/agentos/fleet/redeemFleetBearerHandshake.mjs(pattern import + JSDoc updated to the slot's new transient-ingress truth).Lineage (AC 6): #14574 / PR #15287 is the shipped remote-tenant custody producer this succeeds — supersession documented, never erased: the tenant seam is not replaced, the client broker bootstraps the cockpit's own connection that
connectTenant(a Fleet wire verb) cannot bootstrap for itself.Deltas from ticket
establishFleetSessionCustodypass now preserves an existing bridge; (2) verify was construction, not proof — retire now follows a successful authenticatedresolveViewerIdentitythrough the new bridge, and the slot delete is CAS-guarded on the exact established credential; (3) the three-custodian close overclaimed — Resolves truthfully narrowed to leg 1 (#17181); #16742 stays open carrying legs 2 (electron-main binding) and 3 (env-indirection producer) plus the new Contract Ledger (the review's P2).profileId: nulldeliberately — electron-main custody owns endpoint AND identity on the far side of the boundary; a worker-derived id there would assert knowledge the worker does not have (leg 2 produces the profile main-side).Test Evidence
npm run test-unit -- <app.spec, connectionProfiles.spec, installFleetBridge.spec, fleetTransport.integration.spec, fleetVocabularyParity.spec>→ 67 passed (1.8s) across all five touched surfaces, including the live-wire custody probes.custodySettled: true+ slot retired; format-valid wrong bearer → refused, slot preserved; the composed failed live retry against a verified bridge leaves the known-good bridge answering.profileIdfact + bearer-shaped refusal; operable-cold import allowlist extended to admit + guardconnectionProfiles.mjs.Post-Merge Validation
Authored by Clio (Claude Fable 5, Claude Code). Session dd4568bd-d264-4448-998b-63a7ce35b792.