Repository navigation
Add capability-proved nonpersistent daemon workers #20
Description
Activity
Claiming implementation.
- repository:
pylon-code/prime-agent - branch:
feat/nonpersistent-daemon-worker - worktree:
/Users/rynfar/.prime/worktrees/prime-nonpersistent-worker - base:
pylon@91e13b6798343995291ccca6f523fba81ff96cd6 - owned area: SDK feature registry/docs, daemon protocol/session-summary/worker-descriptor contracts, supervisor launch/recovery/receipt logic, focused daemon and issue-20 regressions,
.pylon/features.yaml, and.pylon/upstream-review.md - shared contract:
nonpersistent_daemon_worker_v1plus fresh create/receiptworkerRecovery:"disabled"; names remain subject to exact-head cross-consumer review - compatibility: ordinary creates and stock artifacts preserve current recovery; the new mode is optional, fresh, client-owned, non-resumable, and must never write a worker recovery journal
- dependencies: Prime Expose attach-negotiated daemon session capability proof #17/PR feat(sdk): prove negotiated daemon session capabilities #18 are merged; Comet chore(pylon): harden fork synchronization #7 will remain blocked until an exact artifact from this issue is approved
- validation: focused tests from the package root,
npm run check, exact artifact/reproduction, journal privacy canaries, killed-worker cleanup/nonrecovery, and independent Prime/Pylon/Comet review - merge order: Prime Add capability-proved nonpersistent daemon workers #20 -> exact artifact -> Comet chore(pylon): harden fork synchronization #7 consumer repair -> compatibility re-review -> Comet PR
I will not push or open a PR until a frozen exact head has no P0/P1 review findings.
- repository:
Audit release and schema-31 replacement plan
The cross-repository audit is complete. The earlier dirty checkout based on
91e13b6798343995291ccca6f523fba81ff96cd6will remain untouched as a rejected reference. Primeorigin/pylonis now68603ed89bb597cd715fd6a77bc1c39d7e110298(protocol 7, schema 30) and overlaps nearly every implementation seam through the newer caller-owned environment-cleanup and recoverable-owned-session adoption work. A direct rebase or cherry-pick would be unsafe.I am reclaiming #20 for a fresh transplant/redesign with this boundary:
- repository/base:
pylon-code/prime-agentfrom exactorigin/pylon@68603ed89bb597cd715fd6a77bc1c39d7e110298; - branch:
feat/nonpersistent-daemon-worker-schema31; - isolated worktree:
/Users/rynfar/.prime/worktrees/prime-nonpersistent-worker-schema31; - rejected reference only:
/Users/rynfar/.prime/worktrees/prime-nonpersistent-worker(must not be edited, staged, committed, reset, or cleaned); - owned source/docs/tests:
.pylon/features.yaml,.pylon/upstream-review.md,packages/coding-agent/.changes/prime-20-nonpersistent-daemon-worker.md,packages/coding-agent/docs/sdk.md, daemon protocol/supervisor/worker/mode/CLI and command-journal sources, SDK feature definitions, and focused daemon protocol/client/supervisor/process/recovery tests needed by this issue; - shared contract: new schema 31; supervisor offer
nonpersistent_daemon_worker_v1; strict freshlifecycle:"client_owned"create withworkerRecovery:"disabled"; exact same-generation create-only receipt; capability-negotiated fail-closed behavior; no recovery journal, recovery/adoption/relaunch/retry/residency/update snapshot, or persistent correlated identity for that worker; - current-contract integration: preserve schema-30 caller-owned environment cleanup and recoverable adoption for ordinary workers, but keep nonpersistent workers outside all recoverable-owned-session stores and adoption paths; bind expected recovery mode during worker authentication; fail descriptor downgrade closed;
- compatibility: schema <=30 and ordinary schema-31 creates retain legacy recovery, replay, ownership, environment-cleanup, and adoption semantics; older clients never infer the optional mode; no Pylon provider source change is expected for this private process-lifecycle slice;
- tests: deterministic schema/capability/request/receipt, full request identity, ordinary-vs-disabled reuse, journal privacy, aliases/retirement, attach fencing, descriptor downgrade, worker-auth mismatch, forbidden lifetime/adoption/update commands, environment-cleanup coexistence, real supervisor replacement, and full affected daemon/recovery/update suites;
- dependencies: merged Expose attach-negotiated daemon session capability proof #17 / PR feat(sdk): prove negotiated daemon session capabilities #18 capability proof; Comet chore(pylon): harden fork synchronization #7 remains blocked on an independently reproduced exact Add capability-proved nonpersistent daemon workers #20 package artifact; Pylon umbrella
pylon-code/pylon#114stays cross-linked; - merge order: freeze and independently review exact Prime head -> reproduce and approve exact package artifact -> merge Prime Add capability-proved nonpersistent daemon workers #20 -> update/validate/review Comet chore(pylon): harden fork synchronization #7 against that artifact -> merge Comet chore(pylon): harden fork synchronization #7. No push or PR before all exact-head P0/P1 findings are resolved.
I will preserve all schema-30 public behavior first, then lift only the still-needed safety invariants from the rejected checkout rather than transplanting the old diff mechanically.
- repository/base:
PR #54 exact-head GitHub CI found a provider-neutral base-branch failure outside the nonpersistent daemon implementation.
Build and checkrunspackages/aibuild, which currently refetches live model catalogs. The live catalog has removedclaude-sonnet-4.5and other identifiers still used by the checked-in tests, so the generated union no longer compiles. The failure is unrelated to this feature and is reproducible from the base build path.Upstream has already merged the exact fix in PrimeIntellect-ai#2038 / commit
0894de1ded368f175b41baeb16ba3a58ec66f828: build the committed reviewed model catalog instead of refetching it. Its complete delta is onepackages/ai/package.jsonscript line plus its changes fragment.To make #54 independently green without weakening checks or committing unreviewed live generated data, I am extending this issue's owned files only to:
packages/ai/package.jsonpackages/ai/.changes/res-1269-deterministic-model-catalog-build.md
I will import that exact upstream commit with provenance, then freeze a replacement head and repeat all five exact-head P0/P1 reviews, scrubbed CI, release tests, and two-build byte-for-byte artifact reproduction. No shared daemon contract changes. The imported upstream fix must merge with #54 before Comet #7 consumes the artifact.
Failed job: https://github.com/pylon-code/prime-agent/actions/runs/34443252621/job/102762545810
PR: #54PR #54 process-smoke follow-up is now frozen at
fc28e5604d104a0fafcda5f1766ec846caf2f363(treead8dcdbda8bba834ff8b55d62314627e6856cc69).The prior Linux failure was a deterministic fixture bug, not a production transport failure: the nonpersistent process test supplied
apiKeywithout a provider/model. Local Prime CLI auth selected a model and masked the omission; clean Linux had no model, so correlated admission failed safely withNonpersistent correlated command failed.Proof and fix:
- clean Docker Node 22 Linux at parent
0992c55…: focused regression reproduced the failure; - exact
fc28e5604: the fixture writes an isolated custom model, selects it explicitly, and targets a reserved-then-closed numeric loopback endpoint; - no live catalog, host auth, DNS, or external inference endpoint is used;
- Docker Linux fixed regression passed;
- clean local focus passed 3/3;
- full process suite passed 23 with 9 skips;
- scrubbed full CI passed 341 files / 4,820 tests with 57 skips;
- all five exact-head P0/P1 reviews approved;
- two exact builds packed, verified, installed, and smoke-tested byte-identical artifacts.
Validation receipt SHA-256:
c3298680951edba9c72e79c4b975ed62f89f5849008a33c23d3b8adf7803ab84. PR #54 now points to this exact head and fresh GitHub checks are running.- clean Docker Node 22 Linux at parent
Outcome
Add a capability-gated fresh daemon-worker mode that does not create or append the worker recovery journal, and returns an exact create receipt proving that mode. This unblocks the host-private correlated Comet text turn without persisting its random lifecycle correlation token.
Coordination
pylon@91e13b6798343995291ccca6f523fba81ff96cd6)An independent Comet #7 review found that the approved correlated lifecycle is copied into the worker recovery journal. The snapshot and correlated queued actions contain
correlationId. Comet #7 explicitly forbids logging, serializing, persisting, hashing, or exporting its host-random correlation token. Comet cannot solve that below Prime's public API.Public contract
Proposed names, to freeze during review:
nonpersistent_daemon_worker_v1;nonpersistent_daemon_worker_v1;workerRecovery: "disabled";workerRecovery: "disabled".The mode is available only when all of these agree. Method presence, versions, schemas, an ignored create option, or the server offer alone are not proof.
The request is valid only for a fresh
lifecycle:"client_owned"create with nosessionPath/resume selector. Ordinary creates omit the field and preserve current recovery behavior byte-for-byte. Older/stock artifacts ignore no new requirement and remain usable by consumers that do not request this mode.Required behavior
DAEMON_WORKER_RECOVERY_JOURNAL_ENVto that worker. No worker recovery journal may be created or appended during create, prompt ownership, queueing, delivery, terminal settlement, or cleanup.workerRecovery:"disabled"only for the exact worker generation launched in this mode. Contradictory, stale, resumed, or ordinary workers must not receive the receipt.Acceptance tests
Merge order
pylon.