Commit Graph
16 Commits
Author SHA1 Message Date
0166cbb870 tests: the agent-target suite arms the live-server reaper
The suite spawned its live servers directly and stopped them in after()
hooks only, so a run killed mid-test could leave them behind. It now arms
the shared reaper and tracks each child like the other live suites do.

Written with AI assistance (Claude).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 05:45:49 +05:00
65c8089182 Only the lease holder may answer an agent target; leave a plain bar alone
Review found that /agent-target-result checked the shared helper token
and nothing else, so any connected overlay could resolve a target it
never claimed. A result post now names the overlay (`clientId`), and
while the target is pending only its lease holder's word lands: a
bystander gets 409 (not_holder, or unclaimed when nobody holds it) and
the request stays pending. The overlay sends its client id with every
result. Every protocol case now answers from the tab that actually
holds the claim.

Also: the helper-wide bar preference is applied on every connected
frame, and restoring wrote an empty display value, which dropped the
bar's own inline flex layout for a plain live session that never asked
for anything. Hiding remembers the bar's display value, restoring puts
exactly that back, and a restore on a visible bar is a no-op. A plain
boot through the launcher keeps display: flex after connect and its
payload carries none of the lane's keys.

Written with AI assistance (Claude).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-15 05:45:49 +05:00
1a699913e4 Make the generate lane's bar preference helper-wide
The maintainer still saw the bottom bar: two tabs were connected to the
helper, the tab that won the roll call hid its bar, and the tab on
screen never did. The hide was also applied only at Go, so the wait
before it showed the bar as well.

The helper now owns the preference. `impeccable live --no-live-bar`
posts `/live-bar` right after the helper is up, so the bar never
appears in any tab; an agent target carrying `hideLiveBar` sets the
same flag before the target goes out. The helper broadcasts
`live_bar` to every connected tab, answers `hideLiveBar` on every
`connected` frame (reloads, later tabs) and on `/status`, and the flag
lives as long as the helper. The overlay just follows: no per-tab
memory, no session scoping, the variant controls still show. The same
preference skips the overlay's "No PRODUCT.md found" connect notice,
which sent the user to init inside a lane that runs without context by
design.

Verified in a real Chromium session with two tabs, screenshots at each
stage: idle (bar in both), after Go (bar gone in both), after reloading
both, after the accept during the bake, after a reload after that.

Written with AI assistance (Claude).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-15 05:45:49 +05:00
e3a121d081 Generate lane: settle the Tune state without knobs, and hide the live bar on request
Two things the maintainer hit testing the lane.

The Tune chip spun forever after a generation whose variants declared
no knobs (the lane's default). The overlay flips the parameter phase to
pending at Go and only settled it when the wrapper mounted; the page
reloads on the JSX write, the resumed session restores "pending" from
its cache with the variants already mounted, and the agent's done reply
never re-checked. Now the done reply completes the phase once every
variant is mounted, and a resume with a pending state asks the helper's
session record whether that generation already finished. A generation
with no knobs shows no chip; one with knobs shows them.

`live-generate --no-live-bar` (body `hideLiveBar: true`, forwarded on
the agent_target payload) keeps the helper's global bar hidden for the
session it starts; the variant controls still show, the choice survives
a reload through the session cache, and the bar returns the moment that
session ends on any path. generate.md passes the flag.

Verified in a real Chromium tab: no chip before and after a reload, bar
hidden through the reload, bar back after the accept. Rust and protocol
cases for the flag, a CLI parse test, contract pins for both fixes.

Written with AI assistance (Claude).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-15 05:45:49 +05:00
1220f26d08 Make the generate lane snappy: self-contained playbook, fast-path poll instructions
The maintainer's field run took five and a half minutes from the prompt
to variants on screen. Two baseline runs on the same repo reproduced it
(356 s mean): 68 KB of skill text read before the first variant (a 36 KB
live.md among it), six to ten tool calls spent finding the dev URL and
the selector, 9 to 10 KB of variants carrying tune knobs, and a document
read plus a detect pass after the accept.

generate.md is now the whole contract for the lane and never sends the
agent to live.md, craft-floor.md, or the action reference on the happy
path; the floors are inlined. The engine carries the rest: a generate
started by live-generate is journaled and queued with origin "agent",
and its poll instructions hand out the fast path (identity from the
event's computed styles and custom properties, the action's three
dimensions, no knobs unless asked, one edit, reply done) instead of the
interactive planning pointer. `impeccable live --allow-missing-context`
boots without PRODUCT.md or DESIGN.md, naming what is missing, so the
lane never falls into the init interview; the boot also reports devUrl,
the origin whose page carries the injected tag, so the agent opens the
page instead of reading terminals. Accept is a bake and live-complete is
its verification: no detect pass, no document read.

Three trimmed runs (one without any context files) averaged 179 s from
prompt to variants, 21 tool calls and 106k tokens against the baseline's
356 s, 30 tool calls and 144k tokens; the accept bake went from 67 s to
41 s. Method and numbers: tmp/questionaire/plan41-field-tests/SNAPPY-REPORT.md
in the maintainer's checkout.

Tests: dev_url probe unit tests, a fast-path instructions unit test, the
origin marker in the protocol suite, and tests/live-boot-fastpath.test.mjs
(flag, contextMissing, devUrl through a stand-in dev server); contract doc
updated.

Written with AI assistance (Claude).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-15 05:45:49 +05:00
d579ecb2f2 Address review: a Go for a target the helper does not hold is refused
The bounded record of answered targets evicted its oldest entry, and a
generate event naming an unrecognized target was admitted, so a Go
delayed past enough later resolutions could still open a session for
a request the CLI had reported as failed.

The admission rule is now positive: a generate event naming an agent
target is welcome only while that target is pending without a rival
lease, or when it comes from the session that answered it. Unknown
targets, evicted or never issued, are refused like any other superseded
Go, so eviction can never reopen a request. The record keeps 256
entries for the answering session's sake.

Tests: a Rust integration case and a Node protocol case (an envelope
naming an unheld target is refused and journals nothing; the same event
without an envelope is an ordinary Go); contract doc updated.

Written with AI assistance (Claude).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-15 05:45:49 +05:00
76db418212 Address review: every answered agent target fences a late Go
Only targets answered with a session were fenced against a delayed
generate event. A request that timed out (or ended in another failure
verdict the CLI already reported) was simply forgotten, so a Go whose
capture outlasted the timeout still opened a session nobody was told
about.

`resolve_agent_target` now records every terminal resolution, with the
answering session when the verdict carried one, and
`agent_target_refusal` refuses a generate event for any answered
target unless it comes from the answering session itself. The
browser_timeout instructions no longer send the agent to live-status
for a session that can no longer start. The overlay's refusal toast
covers both causes.

Tests: a Rust integration case and a Node protocol case (claim, time
out, late Go refused with 409 and nothing journaled), a unit test for
the timeout instruction; contract doc updated.

Written with AI assistance (Claude).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-15 05:45:49 +05:00
7adb81672d Address review: a superseded Go never opens a second session
An overlay renews its lease right before Go, then captures and uploads
the element before its generate event leaves. When that outlasts the
lease and its result post is lost, a rescuer can claim the target and
Go, and the helper accepted both generate events: two sessions for one
request.

The generate envelope now carries this page's clientId, and the helper
refuses a generate event for a target that another page holds under a
live lease, or that was already answered with a different session
(`served_agent_targets`, recorded on every ok resolution): 409
`agent_target_already_served`, nothing journaled. The overlay treats
that refusal like a foreign session and hands the surface back. The
answering session's own event stays welcome, so the common path (result
post first, then the event) is unchanged.

Tests: two Rust integration cases (rival lease, answered elsewhere,
welcome for the serving session) and a Node protocol case, contract
pins for the envelope and the refusal handling, contract doc.

Written with AI assistance (Claude).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-15 05:45:49 +05:00
b5210471fb Address review: the generate event resolves the agent target it serves
A winning overlay could reload after handleGo() minted a session but
before its result post landed. The close released its lease, the
server replayed the still-pending target, and another tab (or the
reloaded page, once it abandoned the unknown session) could claim it
and fire a second Go for a request that already had a session.

The overlay now names the target on the generate event it fires for it
(`agentTarget: {targetId, result}`, the same result it posts), and the
helper resolves the pending request the moment that event is accepted,
stripping the envelope before journaling. Whichever of the event and
the result post lands first answers; a page that dies between Go and
its result cannot leave the request pending, and a request whose event
never reached the helper is served exactly once by the rescuer.

Tests: a Rust integration case and a Node protocol case (claim, Go
event without a result post, verdict carries the session, a late claim
finds nothing pending, the journal carries no envelope), contract pins
for the handoff, and the contract doc.

Written with AI assistance (Claude).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-15 05:45:49 +05:00
a3bb21cbde Address review: one Go per tab, declines for a granted miss, and grace per overlay
Four review threads on the agent-target protocol and the hook stand-down.

Overlay: a tab acting on one target is busy for every other target
(`agent_target_in_flight`), so two held generate requests can never both
be claimed by one tab and the second Go can never overwrite the session
the first one minted. Every exit from actOnAgentTarget ends the acting
state, and teardown clears the target ledger, so a Go that never happened
does not refuse the next connection's targets. A miss after a granted
claim now declines (handing the lease back so another page or a remount
can serve) instead of posting a result that ended the request for every
tab.

Hook: the live-preview marker probe runs before the per-session edit cap,
so a file already past the cap stands down for a variants wrap instead
of emitting the suppression notice.

Server: each overlay's first no_match word extends the resolution grace
by the full window (its watch re-reports do not), so an overlay that
reports after another page's grace lapsed still gets its late-mount
watch instead of completing the roll call with a no_match verdict.

Tests: a Rust and a Node protocol case for the late overlay's grace, a
hook case for the cap-then-wrap order, and contract pins for the busy
check, the decline on a granted miss, and the teardown clear.

Written with AI assistance (Claude).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-15 05:45:49 +05:00
79a27051a2 Address review: hold an all-no_match roll call open for a resolution grace
When the unresolvable page's decline was the last word, the roll call
completed on it, the answer said pending:false, and the page's watcher
never started, so an element that mounted a moment later was still
answered no_match. A page's no_match is a provisional word: the server now
keeps an all-no_match roll call open for IMPECCABLE_AGENT_TARGET_RESOLVE_GRACE_MS
(default 3000) after the first such report, re-judging when the grace
lapses, so a page that keeps watching can still claim (the stale report is
dropped on its eligible claim); a busy report still answers at once. The
overlay reports a miss immediately and re-checks every half second for as
long as the answer says pending. A genuine no_match now takes about the
grace instead of tens of milliseconds, inside the server's hold.

Rust integration case for the late mount claiming within the grace, the
protocol case, and the contract assertions updated; the contract documents
the grace and its env override.

AI-assisted: implemented and tested with Claude Code under maintainer
direction.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-15 05:45:49 +05:00
bd4ec3a11c Address review: the server ends the resolution watch, and a reconnect re-participates
Two ways a page's word could go stale after the resolve-before-claim
change: an element that mounts later than the quick re-checks, and an
EventSource reconnect that did not overlap the old connection (the server
drops that page's word on the close, replays the target, and the replay
guard ignored it, so the roll call waited on a word that never came).

A decline's answer now carries pending, like a denied claim does, so a page
that could not resolve the target reports the miss after the quick
re-checks (the roll call can complete on the other overlays' words) and
keeps re-checking once a second for as long as the server says the request
is pending, claiming the moment the element mounts; the server drops the
stale report on an eligible claim and ends the watch by answering
pending:false once the request resolved or timed out. The overlay tracks
its participation per target: a replayed target is ignored only while this
page is acting on it, and is otherwise handled again, so a busy or
unresolvable page re-declines (idempotent) and an idle page claims.

Unit, protocol, and contract cases updated; the decline answers now say
whether the request is still pending.

AI-assisted: implemented and tested with Claude Code under maintainer
direction.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-15 05:45:49 +05:00
25263adc51 Roll call: a page that cannot resolve the target declines instead of claiming
Field-testing with two pages open showed the first-wins claim letting the
wrong page answer: a tab whose page lacks the element won the claim,
resolved the selector locally, and replied no_match while another page had
the element. The overlay now resolves the selector before any claim and,
when its page cannot resolve it, declines with reason no_match and the
resolution verdict; the same check runs on the busy-to-idle re-claim. The
server records that verdict on the report and, once every connected
overlay has declined, prefers a report that could serve later (a tab
mid-session or with an apply in flight, which answers busy so the agent
retries) over no_match, and returns the resolution verdict only when no
page can serve; the timeout uses the same precedence.

Also from the same field tests: a tab on another page of the app was
resuming this page's session from the per-origin localStorage cache after
a dev-server reload re-initialised it, then sat in GENERATING for a wrapper
it never renders and declined every later target. restoreSessionWithoutWrapper
now resumes a cached session only on the page that saved it, the check the
server-adoption branch beside it already applied.

Covered by two Rust integration cases, two protocol cases, and contract
assertions for the resolve-before-claim path and the page gate; the
cross-page scenario of the field harness passes on a two-page site.

AI-assisted: found by field tests and fixed with Claude Code under
maintainer direction.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-15 05:45:49 +05:00
da403a3410 Address review: the overlay, not the connection, is the roll-call participant
An EventSource reconnect opens a replacement connection under the same
page-level clientId before the old connection is seen to close, so the
close handler used to retire the reconnected overlay's report and hand
its lease back mid-flight. remove_sse_client now retires a client's word
only when no other connection still carries its id, the roll call counts
distinct overlays (plus id-less connections) instead of raw connections,
and the overlay ignores a replayed target it already handled, so a
reconnect never starts a second claim or a second Go. Covered by two new
HTTP cases in crates/cli/tests/agent_target.rs, a protocol case in
tests/live-agent-target.test.mjs, and the overlay contract suite.

AI-assisted: implemented and tested with Claude Code under maintainer
direction.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-15 05:45:49 +05:00
d397140a77 Port /impeccable generate to the engine crates
The Node-era server, CLI, hook, and pin halves of the generate command move
into the Rust workspace, with the protocol unchanged:

- crates/live: POST /agent-target is held open on a channel plus a timer
  thread (the manual-apply deferred pattern), releasing its turnstile
  ticket before it parks like /poll; /agent-target-result resolves it;
  /agent-target-claim is the roll call with its renewable lease. SSE
  connections carry the overlay's clientId: a late overlay is replayed
  every pending target, and a disconnect retires that overlay's report,
  releases its lease, and re-judges each roll call. Shutdown drains held
  requests with server_stopping.
- crates/live/src/live_generate.rs: the live-generate verb (the router
  already forwards every live* verb), same flags, verdicts, and
  _instructions, spelled with the engine's self command.
- crates/hook: every entry stands down on live preview markers
  (skipped: live-preview), checking the proposed content and the file on
  disk for hook-before-edit.
- crates/context: pin accepts generate; the crate's command-metadata.json
  copy carries its entry.

Tests: crates/cli/tests/agent_target.rs (six HTTP cases with an SSE reader),
tests/live-agent-target.test.mjs rewritten to drive the binary (28 cases,
registered in the live suite), hook stand-down cases, oracle goldens for
live-generate plus the re-recorded pin list goldens, the e2e prompt
assertion waiting for the journaled event, and the contract documented in
docs/CLI-CONTRACT.md.

AI-assisted: implemented and tested with Claude Code under maintainer
direction.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-15 05:45:49 +05:00
fc89b0ed62 Add /impeccable generate: agent-initiated live variants (Node-era squash)
Squash of the ten commits reviewed on PR #626, plus the last review
round's connection-aware roll call, before the rebase onto the Rust
engine: the generate command reference and router row, the overlay's
agent-target handling (roll call, leases, replay, rescue), the Node-era
live-server routes and live-generate CLI, the hook stand-down, the pricing
cards e2e fixture, and the unit, contract, e2e, and skill-behavior tests.
The server, CLI, hook, and pin halves are ported to the engine crates in
the commits that follow.

AI-assisted: implemented and tested with Claude Code under maintainer
direction.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-15 05:45:49 +05:00