Repository navigation
Track Pylon fork parity and upstream overlap #1
Description
Activity
- addedpkg:coding-agentAffects packages/coding-agentAffects packages/coding-agent
on Aug 27, 2026 Coordination item opened: #3 defines the cross-repository
correlated_prompt_lifecycle_v1contract for exact daemon prompt ownership, event attribution, scoped cancellation, reconnect reconciliation, and usage isolation.Implementation will use isolated branches after foundation PR #2 lands. The active foundation clone and the Pylon PR PrimeIntellect-ai#137 rebase remain untouched.
Foundation status after PR #2:
- PR chore(pylon): establish fork governance and sync #2 merged into
pylonas703155b21bf53539c88bc19534fde448a9dff4bd. - The first manual
Pylon upstream syncrun mirrored forkmainto Prime upstreamd60fab8a76d9c169f945341f0ee3bde21903bb55exactly. - Candidate integration found one real overlap conflict in
packages/ai/test/prime-inference-models.test.tsand opened Prime upstream sync blocked #4, as designed. No candidate PR or branch was published. - Issue feat(coding-agent): expose correlated prompt lifecycle to daemon clients #3 remains independently owned by its coordinating agent and is unblocked.
The sync workflow is functioning correctly; #4 now owns the required human overlap decision and resolution branch.
- PR chore(pylon): establish fork governance and sync #2 merged into
Upstream integration landed:
- PR chore(pylon): merge Prime upstream through d60fab8a #5 merged into
pylonas12e1fdac74e120a1c1407d0c76d98bc18b73a07dafter all hosted checks passed and two independent read-only reviews found no issues. - The landed history contains exact Prime upstream
d60fab8a76d9c169f945341f0ee3bde21903bb55and exact Prime PR fix(coding-agent): kernel test fixtures speak protocol 3 PrimeIntellect-ai/prime-agent#1886 heada97f6995d39f2cccbd33123ab246f9786fc8ac13as merge ancestry. - The catalog overlap is recorded as
hybridize; the upstream protocol-fixture repair is recorded asadopt. - Prime upstream sync blocked #4 closed automatically and the integration branch was deleted.
- The one-review rule could not be satisfied because the repository has one collaborator who authored the PR; the maintainer explicitly approved the green head and it was merged with the admin bypass.
Remaining foundation work is limited to PR-token credentials, final branch/check policy, the inherited Linear workflow decision, and release naming/signing/provenance. Issue #3 remains owned by its coordinating agent.
- PR chore(pylon): merge Prime upstream through d60fab8a #5 merged into
Fork operations checkpoint:
pylonnow requires strict GitHub Actions checksbuild-check-testandCheck changelog fragment, conversation resolution, and PRs. Admin enforcement is on. Formal approvals are zero whilerynfaris the only eligible reviewer; the count must return to one when a second reviewer exists.- PR chore(pylon): disable inherited upstream workflows #6 removes the inherited Linear and release workflows from the default product branch and documents the reviewed workflow inventory and singleton protection. Both independent audits found no blocker; fresh hosted checks are running on
843891d30c61b67c08fa38b011461afaba1ffce0. - An Actions-only
mainruleset was rejected by GitHub because the built-in Actions integration cannot be a repository ruleset bypass actor. The safe fork-native fallback is viable:POST /repos/pylon-code/prime-agent/merge-upstreamfor branchmainreturnedmerge_type: noneat the exact synced head. A follow-up will switch the sync script to that API before lockingmainwith fork syncing enabled. - Release audit confirms no releases, environments, repository secrets, or variables exist. Removing the inherited workflow is necessary but not sufficient; local publish commands, foreign npm package names, tag controls, and provenance remain release blockers.
- The optional custom PR token remains unset. Candidate-ready issues are the current fail-safe path; automatic draft PR credentials need a separate least-privilege decision.
Issue #3 remains untouched and independently owned.
The focused fork-sync hardening is now in PR #7: #7
Reviewed head:
fdf44c4acad2ba139c037f09357eb0ae852f26c6.The change removes direct
mainpushes and the optional privileged-token path, gates GitHub fork synchronization behind an exact fail-closed repository ruleset, verifies exact post-sync mirror identity, and makes review candidates and their CI evidence deterministic. Two independent final reviews found no code blockers.Rollout remains intentionally separate from the code change. After PR #7 lands and its workflow definition is trusted on
pylon, maintainers must enable squash merging, provision and externally audit the zero-bypass exact-main ruleset, remove the superseded classic protection, then validate a real manual sync before callingmainlocked. Until provisioning, the new workflow will fail closed.The next parity candidate is now in coordinated unmerged PRs:
correlated_prompt_lifecycle_v1: feat(daemon): add correlated prompt lifecycles #9- Pylon integration and conservative stock-Prime fallback: fix(server): keep Prime background work out of foreground turns pylon#163
This hybridizes Prime's existing queue/background primitives behind an explicitly negotiated ownership, delivery, provenance, cancellation, usage, and recovery contract. The decision and upstream overlap are recorded in
.pylon/features.yamland.pylon/upstream-review.md.This does not expose heartbeat creation or scheduled-run projection. Those remain separate until Pylon owns occurrence, turn, checkpoint, clear, stop, and deletion semantics. Both PRs remain unmerged pending hosted checks and maintainer approval.
The coordinated lifecycle work has merged:
- Prime PR feat(daemon): add correlated prompt lifecycles #9 merged into
pylonas02a53ddf7d5557eb732a52e6d991b3d5d52430d1. - Pylon PR feat(coding-agent): add slash command aliases PrimeIntellect-ai/prime-agent#163 merged into
pylonas486af3ea52180c3dcda51b6411ffaeecf9987d08. - Both reviewed heads passed every hosted check; final independent audits found no remaining P0/P1 findings.
The optional correlated prompt contract and conservative stock-Prime admission fallback are now landed. Heartbeat creation, autonomous occurrence projection, and scheduled-run checkpoint ownership remain separate parity items; this tracker stays open.
- Prime PR feat(daemon): add correlated prompt lifecycles #9 merged into
Comet has joined this cross-repository Prime Agent work through its own umbrella issue: rynfar/comet#1
The Comet repository policy is merged in rynfar/comet@b520992. It makes the native daemon the primary integration path and requires cross-linked issues, isolated worktrees, capability negotiation, private host-local state, two-consumer compatibility review, and recorded merge order.
Any Comet dependency on a Prime fork contract will be linked here before implementation or merge. No fork change is requested by this comment.
Comet's reviewed native-daemon foundation is now open: rynfar/comet#4
It validates the public Prime package/SDK and stock protocol-v7 capability baseline, owns a stable private daemon lifecycle, and records optional capabilities only as server offers. Stock Prime Agent 0.8.1 passes the real load/connect/shutdown smoke without the correlated-lifecycle extension.
This PR makes no Prime changes and starts no sessions. Comet's next asynchronous session-host slice remains blocked on #13 for bounded SDK ingress and must separately consume the recovery/correctness outcomes from #8 and #11. Final Comet receipts are at rynfar/comet#3 (comment).
Dependency milestone: correlated lifecycle follow-up merged
Prime Agent PR #12 merged into
pylonasf728316dabbaa85aa561e6d6b08550ed337574beafter exact-head maintainer approval, all hosted checks, two independent rereviews, and a repaired recovered-tail persistence blocker.The merged contract now preserves correlated ownership through post-compaction continuation, rejects correlated queued-payload replacement, keeps unrelated events uncorrelated, and fails closed when real event persistence fails even if a later
agent_endrecovers the shared queue.The safe dependency order advances to #11. Its existing dirty worktree is under a collision-avoidance hold until the owner checkpoints and records a formal issue claim. The old #8 upstream candidate remains stale. Required order: finish/review #11, regenerate/review #8 from the resulting exact
pylon, then implement #13 bounded public daemon ingress, then Comet #5.Dependency milestone: Prime #11 is closed via merged PR #14 at
fd5cadc600f867a0a5a989064cce22934e9dad94.The merge commit has exact parents
f728316dabbaa85aa561e6d6b08550ed337574beandc5a34dffcd44eaaa4d66ea43786d19260a10e7f2, and its tree equals the reviewed head tree. Final hosted checks, three independent production reviews, two independent CI-repair diagnoses, exact upstream synthetic review, zero-thread audit, and exact-head maintainer approval all passed.Next gate is a fresh #8 upstream candidate from this exact post-#11
pylon. Regeneration is claimed on branchsync/prime-upstream-a903-from-fd5cadc/ isolated worktree/Users/rynfar/.prime/worktrees/prime-upstream-a903-from-fd5cadcagainst Primea903d4b6768f484bd6d459b7b0aa7dee38e461e2. The olda37efe92fcandidate is discarded. #13 and rynfar/comet#5 remain downstream.Prime upstream governance gate #8 is complete. PR #15 merged as
e7871eb699d0f65047a21d179216ebfec7755d0cafter exact-head reviews, zero conversations, and all trusted hosted jobs passed.Bounded public ingress Prime #13 is now claimed from exact merged
pylonate7871eb699d0f65047a21d179216ebfec7755d0cin an isolated worktree. The declared client-local feature proof/raw-byte limit/error/reconnect contract is under the final joint Prime/Comet design review before source edits.Dependency order is now: #15/#8 (done) → #13 (active) → Comet #5.
Prime bounded-ingress candidate is now ready as PR #16 at exact head
9013a63a76fa339b5e2898947e9cff040505d72c/ tree814cfa93bfdbab0d43acaa92c208205fd7dd5749on basee7871eb699d0f65047a21d179216ebfec7755d0c.Three commit-bound reviews approved with no P0/P1: transport security, API/resource/governance, and Comet consumer compatibility. Local validation includes 53 focused tests, 13 real-process passes with 8 fixture skips, both stock/current 0.8.1 adoption directions, the 36 MiB indivisible message, deterministic 100/500 MiB bounded-client reconstruction, and exact 64/128 MiB resource probes.
Trusted exact-head hosted CI is running. Comet #5 remains blocked until PR #16 passes CI, has no unresolved conversations, receives exact head/base maintainer approval, and merges into
pylon.Prime bounded public daemon ingress PR #16 passed trusted hosted CI and merged as
7238ac8cff25962ada9ffe4530b7d4d1cddc1b47(parentse7871eb699d0f65047a21d179216ebfec7755d0c+9013a63a76fa339b5e2898947e9cff040505d72c, tree814cfa93bfdbab0d43acaa92c208205fd7dd5749). Prime #13 is closed.Comet #5 has now been claimed from
origin/main@de66c08c3687208effe2e2fdb514d6d690f1cc0aonfeat/prime-session-host-7238in an isolated worktree. It will require the exact public-rootbounded_daemon_ingress_v1token and constructDaemonClientwith a 64 MiB inbound frame limit under an isolated 512 MiB V8 heap. No production session path will accept stock 0.8.1 or infer support from versions, schemas, methods, constructor arity, or daemon offers.Comet consumer update: rynfar/comet PR #6 merged as
9ef2295877d33fe241479471e908105fccbeb434using the exact reviewed Prime dependency7238ac8cff25962ada9ffe4530b7d4d1cddc1b47and branded artifact SHAd6065af7b7eb0bf8bb945d84618c4d06fecea66cf3d07ed75737310b447913cc.The merged Comet tree now capability-gates
bounded_daemon_ingress_v1,client_owned_sessions,chunked_snapshot,immutable_snapshot_transfer_v1, andauthoritative_owned_session_cleanup_v1; creates/attaches only its own fresh draft; and proves authoritative cleanup without exposing native identities. Exact stock 0.8.1 fails before session client construction. Three commit-bound reviews and hosted x86/ARM/macOS builds passed.Next consumer slice: a separately reviewed bounded
correlated_prompt_lifecycle_v1prompt/event contract. It will not infer negotiation from method presence or server offers, and it will precede Comet Harness/registry/UI exposure.Prime #20 now tracks the nonpersistent-worker capability needed by rynfar/comet#7. Review of the merged correlated lifecycle found that worker recovery journals persist lifecycle correlation IDs. The new slice leaves ordinary recovery unchanged and adds an exact fresh-create proof for consumers that forbid persistence.
Opened #22 as the umbrella for Meridian provider reliability (concurrent RLM subagents over Claude Max), with focused slices #23 (stable child-scoped provider identity), #24 (kind-aware retry / Retry-After / dead maxRetryDelayMs), #25 (requestAbort cascade to RLM children), #26 (prompt-cache prefix stability). Root causes verified in-source with Meridian telemetry evidence; details in #22. This work is independent of the snapshot/daemon slices tracked here — flagging it so concurrent fork agents don't collide on packages/coding-agent core seams (#23 and #25 touch agent-session.ts).
Pylon background-writing parity is now implemented in draft pylon-code/pylon#201 at exact head
0ce5a304b44f8db3ee395413ed51ba674a09906a(Pylon PrimeIntellect-ai#198). It imports only the selected Prime installation’s public SDK entry in an isolated helper, preserves account/model affinity, and covers ACP/native interactive configurations without a Prime fork change. Local checks are green; hosted native/package smokes are running.Milestone update: Prime caller-owned session contract PR #37 is fully green at
d83903f4dc9e649317e49862fcf676a02fc6d3f8, including hosted Windows named-pipe coverage. It awaits exact-head maintainer approval and merge. This unblocks Pylon PrimeIntellect-ai#199 implementation only after merge; native multi-instance advertising, Windows native trust, and restart adoption remain gated as documented.Independent work has started on Pylon PrimeIntellect-ai#200 PR 1 (rollback P0 truth/safety gate) only; no Prime leaf rollback or durable saga work is being combined with it.
Publication audit update: Prime #29 has a file-level protected preview/stable design, but implementation correctly remains blocked on merging deterministic artifact PR #32. The audit also found that protected
Check changelog fragmentcurrently has no exact merged-pylonSHA result because it runs only on PRs; #29 must add a canonical push proof before stable admission can truthfully require every branch-protection context. Admin prerequisites (immutable releases and guarded preview/stable environments) remain absent and must exist before #29 merges. No publication setting or repository file was changed by the audit.Parity milestone: environment contract and deterministic fork artifacts landed
Merged in dependency order:
- Pylon #201 as
9ade80dd66220831d1bbfb155405af35e0d818fc: isolated public-SDK background text generation with exact instance/account/model affinity and bounded runtime postconditions. Pylon chore(deps): bump @types/mime-types from 2.1.4 to 3.0.1 PrimeIntellect-ai/prime-agent#198 is closed. - Prime #37 as
5cab34c10ee905915a9d938dc22c5038411a5a80: caller-owned exact launch environment, recovery context, post-attach contract proof, and authoritative identity-safe disposal. Prime Isolate caller-owned session recovery environment and cleanup #33 is closed. - Prime #41 as
4a484472957bf96ada11186b44a976e72af777af: bounded hosted proof for late supervisor handshakes without weakening process identity checks. - Prime #32 as
63fb578aace412da02c999e383b7dde8c9a84f3a: deterministic Pylon tarballs and manifest, offline double-pack, installed SDK/daemon/cleanup smoke, and Ubuntu/macOS/Windows gates. Prime Build deterministic Pylon Prime release artifacts #28 is closed.
The exact #32 artifact head passed byte-for-byte reproducibility, public package/bin identity, current caller-owned negotiation/proof/disposal, POSIX native daemon smoke, explicit Windows ACP fallback, and all hosted platform gates.
Protected publication (#29) is now being implemented from the merged #32 base. No environment, setting, tag, release, deployment, attestation, or publication has been created yet. Immutable preview/stable publication remains a required maintainer gate before Pylon can install or update this fork artifact.
Rollback work was deliberately reset after three adversarial reviews found P0 races and false absolute-provider claims in the uncommitted saga draft. The replacement PR1 only classifies relative/unsupported capability, disables every production rollback surface, and fails before any filesystem/provider/projection mutation. Exact anchors, canonical writer fencing, postcondition proof, restart recovery, compensation, and repair UX remain separate follow-ups; no unsafe rollback code was pushed.
Next dependency order remains: #29 protected publication → Pylon managed install/update (PrimeIntellect-ai#193/PrimeIntellect-ai#194) → Prime #27/Pylon #84 restart adoption → Pylon PrimeIntellect-ai#199 multi-instance phases → coordinated rollback follow-ups → Windows native-security decision and the full graduation matrix. Comet and dirty Prime #20 remain excluded and untouched.
- Pylon #201 as
Parity milestone: rollback truth gate landed; protected publication is in review
- Pylon #220 merged as
b4e61a32750590d1be625ce2d4cf5af70264c881. Every production provider now fails closed for coordinated rollback, the unsupported web control is hidden, mobile remains without an entry point, and requests are rejected before filesystem/provider/ref/projection mutation. Exact rollback remains intentionally disabled pending the durable saga and Prime leaf-anchor phases. - Prime publication is draft PR #42. Immutable Releases, repository-wide full-SHA action enforcement, preview/stable reviewer environments, the upstream-sync reviewer environment, and no-bypass publication tag permanence are configured and read back.
- Adversarial review correctly kept feat(release): add protected Pylon publication #42 in draft. The amendment now owns persistent consumer high-water state, signed existing-history admission, approval-before-attestation, durable pre-CAS drafts and post-CAS sequence recovery, older-recipe rollback, and gating every repository contents-write workflow. No tag, release, deployment, or attestation exists.
- Pylon condense ipython tool calls into a single-line summary PrimeIntellect-ai/prime-agent#193 distribution-verification and Prime Add capability-gated adoption for disconnected client-owned sessions #27 restart-adoption audits are running in parallel. Managed install/update, restart adoption, multi-instance enablement, exact rollback, and the complete graduation matrix remain open.
- Pylon #220 merged as
Prime 0.9.4 integration landed through merge PR #55 (
8069dbd67ad1e7863dc56072a9c56ba0ab6066b9), preserving the frozen upstream1eee2938b4eeb7a4d72e17035adda669a89b63deancestry. The reviewed tree includes native worker replay, recovery-owned reconnect requests, and acknowledgment-before-cleanup with safe failed-journal retry. All final CI checks passed, including Windows named pipe, process smoke, reproducible packs, and macOS/Linux artifact installs.Private final-build verification passed: four SDK features, recoverable adoption capability, all 10 release-contract tests, native first/follow-up turns, denied and approved writes, and Stop. Manual restart reports an explicit interruption and preserves ownership quarantine; managed continuation remains a publication acceptance requirement. Browser evidence and video.
The original sync workflow succeeded on the exact current merge (run34570563183); #44 and the stale candidate issue #39 are closed. No additional maintainer credential fallback was used. The preview publication triggered by the merge was canceled before publication because #53 is still in progress.
Publication group4 migration implementation and its protected old-client tests are underway. Group5 crash/stress, final macOS/Linux maximum tests, three final independent reviews, and guarded preview/stable publication remain required. Nothing has been released yet.
Model: GPT-6 Astra. Harness: Codex in Pylon.
September 14 Pylon/Prime review checkpoint
Pylon #548 is merged as
a1efaf3ec44480fe53ba6f24a5b93a1220c152feafter adversarial review and green CI. The review checked the native constructor, valid session/prompt provenance, malformed/foreign custom messages, identity changes, and private-content exclusion. The implementation's 524 focused tests and server typecheck passed; no production update was performed.The broader source review found a separate, reproducible current-build gap: Pylon #550. Managed Prime emits
refinement_noticeas well asrefinement_outcome; the former is still rejected by Pylon's decoder. Fix that and audit native message coverage first. PrimeIntellect-ai#548 is a narrow outcome-message fix, not completion of the entire refinement compatibility audit.Review range: the ledger's last integrated upstream
1eee2938b4eeb7a4d72e17035adda669a89b63dethrough freshly fetched upstreamcfb2d3fe35c7c23cf6678ec235412b0d3f286fae(71 commits). Prime product remains65d9c0274866f1bacb3959a16718718d102ee593. The mirror/candidate in #57 ends atfb2db8ee1b61c69d53a84404e617bc74d6f205c9, 69 commits behind this review head. This is triage plus source inspection of relevant integration changes, not an integration-test certification or approval to bulk merge.Recommended order:
Priority Upstream changes Pylon relevance and proposed handling First reliability batch #2213, #2151, #2314 Adopt candidates: kernel stdin/stdout error listeners prevent EPIPE from crashing the worker; waitForIdle parks whenever the input pump is blocked instead of spinning; Codex retries a stale previous_response_id once with full context before any output. Current product source lacks these fixes. Preserve cancellation and one terminal settlement. Run kernel pipe/shutdown, session queue, and Codex stream regressions. Context and maintenance correctness #2217, #2226, #2220 Retain tool-output tails and kernel edit paths in summaries; route refinement through a configured usable auxiliary model to reduce prompt-cache eviction. Hybridize auxiliary routing with the fork's scoped provider hooks/session identity; verify fallback authentication. Run compaction serialization/file-ops and refinement auxiliary-model tests. Model restoration and catalog latency #2313, #2299, #2229 Avoid premature saved-model fallback and transcript scans blocking roster/worker access. Review bounded readiness and metadata caching together; verify session identity and model selection after managed restart. Goals and autonomous turns #2215, #2224, #2284 Preserve accounting across compaction, refresh queued continuation budgets at delivery, and hold autonomous continuations while children run. Hybridize with Pylon's occurrence/turn ownership; do not imply unsupported automation is enabled. Separate ownership/recovery review #2260, #2242, #2246, #2276 Snapshot caching/deferred events, persistent SupervisorLink, orphan-worker GC, and session append optimizations touch fork-critical boundaries. Hybridize; preserve immutable bounded snapshots, attachment generations, per-event recovery cursors, authenticated ownership, cleanup receipts and durable ordering. Require focused real-daemon/managed-artifact integration gates before merge. Existing #64–#68 remain relevant: background completion notice deduplication, OpenCode maintenance identity, Prime CLI auth isolation, compiled installation/update/rollback, and Grok subscription login. The new macOS signing fix #2265 belongs with #67's packaging decision.
Additional deliberate decisions: #2280 adds bounded quota waiting (default up to 15 minutes) and an optional backup model; review projected waiting/cancellation and model identity before enabling it. #2256's service catalog/generic MCP overlaps Pylon MCP ownership; retain current behavior pending a maintainer decision. Harness relevance ranking (PrimeIntellect-ai#2241), typed child collection (PrimeIntellect-ai#2223/PrimeIntellect-ai#2307), model option/selector fixes (PrimeIntellect-ai#2309/PrimeIntellect-ai#2308), extension timers (PrimeIntellect-ai#2095), and the destructive-git guard (PrimeIntellect-ai#2275) are secondary candidates requiring scoped review. TUI layout/keybinding, onboarding, benchmark and upstream publication automation changes are not Pylon app feature gaps and should not drive this reliability batch.
No Prime source, live userdata, managed installation or release was changed. The frozen adoption ledger remains at the last actually integrated upstream head. Next implementation should record per-feature adopt/hybridize/retain decisions and publish a new immutable managed artifact only after the existing consumer gates pass.
Upstream Catch-Up Triage: Post-v0.9.4 (
cfb2d3fe3..18a56bf35and Sept 14 items)Following review of the 72 upstream commits from
cfb2d3fe35c7c23cf6678ec235412b0d3f286faeto18a56bf3557063c0cd0be12f99f0bcce2a46da32(including release v0.9.5a7d791bc1) and open Sept 14 triage items, the ledger (.pylon/upstream-review.md) and feature inventory (.pylon/features.yaml) have been updated.The merge-base and complete integration checkpoint remain frozen at v0.9.4
1eee2938b4eeb7a4d72e17035adda669a89b63de. Selective adoption does not advance the full integration checkpoint.Phase 1: Fork Reliability Batch (In Progress)
- Kernel resilience & security:
- [RSI, bug] fix(coding-agent): absorb kernel child stderr stream errors like stdin/stdout PrimeIntellect-ai/prime-agent#2383: Absorb kernel child stderr stream errors (EPIPE) to prevent unhandled worker crashes.
- [RSI, bug] fix(kernel): bound REPL protocol frame sizes in kernel and host PrimeIntellect-ai/prime-agent#2423: Bound REPL protocol frame sizes in kernel and host to prevent memory exhaustion.
- [RSI, security] fix(kernel): keep the kernel stderr log owner-only PrimeIntellect-ai/prime-agent#2425: Owner-only permissions (mode 0o600) for kernel stderr log.
- Daemon & session lifecycle:
- [RSI, bug] fix(daemon): answer heartbeats_list from live state without queueing behind serialized work PrimeIntellect-ai/prime-agent#2378 + fix(coding-agent): bound heartbeat view catalog fetch with a 10s deadline PrimeIntellect-ai/prime-agent#2342: Answer
heartbeats_listfrom live in-memory state with 10s deadline without blocking behind serialized session work (bounded; must not fabricate liveness for terminating sessions). - [RSI, bug] fix(daemon): let session opens wait through an update restart instead of failing PrimeIntellect-ai/prime-agent#2391: Session opens wait through daemon update restart instead of failing immediately (re-verifies hello and supervisor generation on connect).
- [RSI, bug] Hold spawn name reservations until admission is durable PrimeIntellect-ai/prime-agent#2396: Hold spawn name reservations until admission is durable (respects caller-owned admission proofs and reconnect handles).
- [RSI, bug] fix(daemon): answer heartbeats_list from live state without queueing behind serialized work PrimeIntellect-ai/prime-agent#2378 + fix(coding-agent): bound heartbeat view catalog fetch with a 10s deadline PrimeIntellect-ai/prime-agent#2342: Answer
- Async-bash notices:
- [RSI, bug] Fix stale async-bash completion notice race at the turn boundary PrimeIntellect-ai/prime-agent#2372 + [RSI, bug] fix(coding-agent): re-park pending next-turn messages when an async-bash notice is withdrawn PrimeIntellect-ai/prime-agent#2386: Hybridize turn-boundary notice fixes with fork fix(runtime): withdraw only consumed background command notices #72 (preserving random per-handle identity, host-acknowledged withdrawal, and single terminal turn settlement).
- Compaction & refinement:
- [RSI, bug] compaction: keep tool identity in serialized summarizer input PrimeIntellect-ai/prime-agent#2424: Retain tool identity in serialized summarizer input.
- [RSI, bug] compaction: anchor summaries to kept-tail state and stop re-summarizing file lists PrimeIntellect-ai/prime-agent#2385: Anchor summaries to kept-tail state and stop re-summarizing file lists.
- fix(harness): validate refinement writes and skip malformed entries in the digest PrimeIntellect-ai/prime-agent#2463: Validate refinement writes and skip malformed entries in the digest.
- Provider fixes:
- [RSI, bug] fix(ai): recover stale Codex chains after metadata PrimeIntellect-ai/prime-agent#2374: Recover stale Codex chains after metadata (preserving connection binding).
- fix(ai): stop sending enable_thinking to Prime Inference GLM models PrimeIntellect-ai/prime-agent#2459: Stop sending
enable_thinkingto Prime Inference GLM models.
- Performance (non-snapshot / non-catalog ownership):
- [RSI, performance] Cache the branch array on the per-turn hot path PrimeIntellect-ai/prime-agent#2414 (cache branch array on turn hot path), [RSI, performance] count tool-result message entries from their serialized header PrimeIntellect-ai/prime-agent#2416 (count tool-result message entries from serialized header), [RSI, performance] Append catalog metadata without full transcript parses PrimeIntellect-ai/prime-agent#2433 (append catalog metadata without full transcript parses; bounds preserved), [RSI, performance] perf(daemon): mtime-guard the cron jobs catalog reads PrimeIntellect-ai/prime-agent#2389 (mtime-guard cron jobs catalog reads), [RSI, performance] perf(daemon): skip roster re-composition for unchanged sessions PrimeIntellect-ai/prime-agent#2393 (skip roster re-composition for unchanged sessions), [RSI, performance] decode private frames in linear time across socket chunks PrimeIntellect-ai/prime-agent#2399 (linear-time socket frame decoding), [RSI, performance] perf(kernel): defer the event-loop import stack past the ready event PrimeIntellect-ai/prime-agent#2379 (defer kernel event loop import stack), [RSI, performance] perf(kernel): skip pip seeding when creating the kernel venv PrimeIntellect-ai/prime-agent#2387 (skip pip seeding for kernel venv), [RSI, performance] Land the kernel skill-sync marker so killed sessions do not re-pay it PrimeIntellect-ai/prime-agent#2405 (kernel skill-sync marker).
Excluded / Deferred from Batch (Snapshot/Catalog/Supervisor Invariant Protection)
- [RSI, performance] start the daemon catalog on demand PrimeIntellect-ai/prime-agent#2398 (on-demand daemon catalog start), perf(coding-agent): reuse attached transcripts after model catalog refresh PrimeIntellect-ai/prime-agent#2296 / fix(coding-agent): opening busy sessions no longer re-transfers the full transcript PrimeIntellect-ai/prime-agent#2260 (avoid repeated transcript downloads), fix(coding-agent): stop saved-catalog refreshes from re-parsing the whole catalog PrimeIntellect-ai/prime-agent#2273 (stop saved-catalog refreshes re-parsing), [RSI] Persistent SupervisorLink for cross-worker requests PrimeIntellect-ai/prime-agent#2242 (persistent SupervisorLink), feat(coding-agent): garbage-collect orphaned session workers (ENG-6105) PrimeIntellect-ai/prime-agent#2246 (orphan-worker GC), [RSI] fix(coding-agent): speed up session append and fork hot paths PrimeIntellect-ai/prime-agent#2276 (session append optimizations).
- Upstream compiled binary installer / release manifests (prepare prime agent v0.9.5 release PrimeIntellect-ai/prime-agent#2366, make release manifest parsing forward-compatible PrimeIntellect-ai/prime-agent#2370, embed clipboard addon in native binaries PrimeIntellect-ai/prime-agent#2369, show existing users only the trace onboarding question PrimeIntellect-ai/prime-agent#2368, fix issues found while validating native releases PrimeIntellect-ai/prime-agent#2361, publish musl and baseline linux archives so linux stops falling back to node PrimeIntellect-ai/prime-agent#2344, fix(ci): preserve release artifact download paths PrimeIntellect-ai/prime-agent#2319, add a persistent update channel with a /nightly command PrimeIntellect-ai/prime-agent#2323): retained recipe-2 deterministic SDK distribution.
Phase 2 Follow-ups & Maintainer Decisions
- Phase 2a (queued-send after interrupt): upstream send queued messages after interrupt PrimeIntellect-ai/prime-agent#2426 (
abort_and_send_queued) ported behind capabilityabort_and_send_queued_v1and schema 34 in separate PRs. - Phase 2b-2f (Pylon issues): child progress notes ([RSI] Add child progress notes and kernel-visible child snapshots PrimeIntellect-ai/prime-agent#2282), image-model routing (feat(images): route image turns to a configured image model PrimeIntellect-ai/prime-agent#2453), ACP pickers (fix(coding-agent): expose ACP model and effort pickers PrimeIntellect-ai/prime-agent#2455), human-message priority / continuation holds (prioritize human messages ahead of queued agent traffic PrimeIntellect-ai/prime-agent#2334 / Hold goal/autonomous continuations while background bash() handles run PrimeIntellect-ai/prime-agent#2465), stock 0.9.5 compiled binary fallback verification.
- Maintainer Decisions: Quota park / auto-resume ([RSI, feature] Park quota-blocked sessions until the provider reset and auto-resume PrimeIntellect-ai/prime-agent#2375 / [RSI] Bounded provider wait-for-usage, transient-unavailability pings, and optional user-defined backup model PrimeIntellect-ai/prime-agent#2280) and MCP service catalog / OAuth engine (mcp service catalog and oauth engine PrimeIntellect-ai/prime-agent#2330).
Independent adversarial review checkpoint 1 completed and incorporated.
- Kernel resilience & security:
This is the fork-side tracker for Pylon-specific Prime Agent integration work. The Pylon application-side umbrella is pylon-code/pylon#114.
Foundation
mainas an exact daily mirror ofPrimeIntellect-ai/prime-agent:main— established by PR chore(pylon): establish fork governance and sync #2 and verified atd60fab8a76d9c169f945341f0ee3bde21903bb55.pylonthrough reviewed pull requests — first landed in PR chore(pylon): merge Prime upstream through d60fab8a #5 throughd60fab8a76d9c169f945341f0ee3bde21903bb55..pylon/features.yamland.pylon/upstream-review.md— established and exercised by PR chore(pylon): merge Prime upstream through d60fab8a #5.GITHUB_TOKEN.Pylon reliability and delivery sequence
Pylon consumes the installed package's public SDK and detached-daemon API as its primary connector. ACP remains a tested degraded fallback only where native daemon mode is unavailable or unsafe. The Pylon application checklist is pylon-code/pylon#114.
70b65305c, with exact-head maintainer approval and corrected ledger attribution.Prime issue #20 and the separate Comet correlated-turn consumer are not dependencies of Pylon provider parity. Preserve that work independently; do not serialize Pylon delivery behind it.
Parity sequence
For each item, search current Prime issues, pull requests, releases, and source first. Choose
adopt,hybridize,retain, orredesign; do not remove Pylon behavior merely because upstream adds an overlapping feature.September10–12 first-class provider delivery — complete
The requested managed-publication path is shipped. PRs#55,#56,#58,#59,#60,#61 and#63 are merged. Cooperative migration/generation recovery resolved#53; corrected accepted-event cursor metadata shipped in#63 (
65d9c0274). Both independent Linux/macOS audits verify205 publication tests,29 stress tests,all3034 crash cuts,and the actual16MiB maximum. Protected preview34680283818 and stable34684305605 succeeded; stable sequence2 is public, with an append-only withdrawal of affected stable1.Pylon#496 and#521 are merged. Actual merged-Pylon artifact graduation passed33 with0failures/0skips; Pylon's stable update selected the corrected Native/Authenticated managed build. Final web and mobile ten-turn acceptance, including real supervised approval/denial, Stop, active server restart and follow-up, passed with retained identity, rotated ownership/recovery handle, ready completed checkpoints and zero busy owned native sessions after Stop. The final evidence checkpoint passed and owned test services were cleaned up.
Full scope, merged PRs, recordings, source binding and explicitly recorded limits.
This closes the September first-class delivery scope only. The other independent parity, automation and lifecycle items in this umbrella remain separately tracked.