Skip to content

feat: adopt upstream orchestrator v2 - #989

Merged
rynfar merged 20 commits into
pylonfrom
upstream/2026-10-02-orchestrator-v2
Oct 3, 2026
Merged

rynfar merged 20 commits into
pylonfrom
upstream/2026-10-02-orchestrator-v2

Conversation

@rynfar

@rynfar rynfar commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Pylon currently runs the deleted v1 orchestration model. This adopts T3 upstream de34391427 (#2829) in full and moves server, contracts, shared runtime, web, mobile and desktop onto v2 together. The production apps/server/src/orchestration-v2 files are byte-for-byte upstream.

Depends on #987, whose prerequisite commit is included while that PR remains open. Closes #988. The adoption WIP history is replaced by seven per-area commits.

  • V1 orchestration is deleted. V2 stores state in userdata/statev2.sqlite, imports legacy transcripts from state.sqlite, and registers its new migrations as 68/69 without rewriting Pylon's existing migration history.
  • Prime remains registered through a Pylon v1→v2 adapter bridge with typed event projection, ownership fences and receipt-proven maintenance drains. Native stream retirement releases v2 observers; background children retain their own lifetime, and cumulative child usage is not mislabeled as main-agent usage. Prime native rollback, fork, active steering, total-cost projection and automatic adoption of active execution across any server restart remain unsupported for this landing, including pre-cutover v1 authority; Prime work must be stopped/drained before restarting or upgrading. Native queue, side-question, resource, goal/depth, direct child and compaction/harness controls are also unavailable; see the initial Prime limitations.
  • Pylon branding, independent profiles, provider/account capacity, CAS settings, credential consent, session ownership, desktop integrations and durable mobile drafts/outbox are retained. The mobile context meter and proactive capacity handoff offer consume native v2 data with ownership guards; switching prepares the next message and never sends automatically. Pylon's durable rollback sagas and Codex absolute rollback are removed with maintainer approval; v2 owns rollback.
  • Protocol 2 is a breaking wire boundary: WS requires orchestrationProtocol=2 (old/missing→426), and orchestration HTTP requires x-t3-orchestration-protocol: 2. V2 graph/command/snapshot payloads replace v1 shapes. The native iOS composer also changes, so a rebuilt compatible binary/runtime is required before delivery. Pylon's 1.0.1 release version is retained; the pinned upstream config is 1.4.0. No EAS, OTA or store release was performed. The preview:local appVersion override needs an explicit runtime/version decision before shipping.

Validation: all affected package direct typechecks pass; changed-scope formatting and lint pass. Eight focused pristine v2 core suites pass 174 tests; Prime bridge/provider suites pass 322 and title suites pass 26. All ten focused provider adapter suites pass 578/578 after the authorized Pylon branding test adaptations. Independent review repairs pass 87 Prime lifecycle tests and 376 web handoff/composer tests; both exact CI Knip commands pass. OpenCode retains Pylon’s 180-second browser-tool budget outside the unchanged v2 adapter, respecting explicit native settings. A read-only Nightly DB copy imported all 307 threads and 48,062 messages, hydrated pending imports to zero, and repeated without duplicates or changing the source copy. Server bundles and rebuilt native iOS simulator build pass. Web and a fresh task-owned simulator verified isolated pairing, transcript rendering, draft retention and reversible settings without sending a provider turn. Pairing and cached transcript also survive native/JS restart, offline cold start and automatic reconnect; fresh Metro logs contain no persistence/asset errors (optional native math warning remains).

Five test-only exceptions to the exact-directory rule are maintainer-approved: Pylon migration-numbering adaptations in the cutover/project-upgrade fixtures, resolved-target importer boundary for Prime, and ACP/Codex Pylon branding assertions. The boundary/ACP/Codex rerun passes239/239; project-upgrade/auth68/68; production v2 code stays unchanged. CI is green on final head 603f8ab3ba (full CI, mobile native analysis); all test shards, typechecks, lint, builds and packaged smoke checks pass. Merge requires maintainer approval.

Before and after use the same synthetic completed conversation; no private transcript or database is attached.

Web before v2

Web after v2

Rebuilt iOS v2 imported conversation

ui-v2-settings-draft-verification.mp4

Model: GPT-6.1-Sol. Harness: Codex in Pylon.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

rynfar added 8 commits October 2, 2026 19:34
Pylon's bridge to the Relay Orchestrator Claude plugin was a stand-in while
upstream's orchestrator was unavailable. Upstream shipped orchestrator v2, so
this removes the bridge rather than carrying two delegation implementations.

Deletes RelayWorkerBridge, RelayCli and relayMcpConfig, and unhooks their
optional-service wiring from server.ts, ws.ts, OrchestrationReactor and
ProviderRuntimeIngestion. The Claude and Codex adapters no longer inject a
relay MCP server.

Drops the relay-only wire fields (source, relaySequence, relayPriorUsage).
cancellable and watchable stay: they are generic capability flags that Prime
and native agents also use. Historical events keep decoding because Struct
ignores excess properties, covered by a new fold regression test.

Collapses the logic those fields carried:
- ProjectionSnapshotQuery drops the relay lifecycle pinning CTEs.
- ThreadBackgroundLiveness loses its relay set; no work outlives its session,
  so clearThreadLiveness drops the thread entry outright.
- subagentRuntime loses the attempt/sequence fence and cumulative usage
  accounting; canCancelSessionAgent loses its detached-controls parameter.
- planBackgroundAgentStop reduced algebraically to canInterruptParent once
  detached workers were gone, so ChatView uses that directly.

The managed relay tunnels (packages/shared/src/relay*, infra/relay,
apps/server/src/relay, deploy-relay.yml) are a different subsystem and are
untouched. Migration 063 stays: it is registered and already applied.
@github-actions github-actions Bot added size:XXL vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. labels Oct 3, 2026
@rynfar
rynfar marked this pull request as ready for review October 3, 2026 05:48
@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

⚠️ The thread fixture changed, so impact percentages are not directly comparable to the main baseline.

Provider Metric Main baseline This PR Impact PR ceiling
Codex Total thread wire — 4.9 KiB — 6.8 KiB ✅
Codex Thread snapshot wire — 3.7 KiB — 4.9 KiB ✅
Codex Live turn WebSocket wire — 1.2 KiB — 2.0 KiB ✅
Codex Live turn WebSocket decoded — 20.4 KiB — 29.3 KiB ✅
Codex Live turn messages — 2 — 8 ✅
Claude Total thread wire — 4.9 KiB — 6.8 KiB ✅
Claude Thread snapshot wire — 3.7 KiB — 4.9 KiB ✅
Claude Live turn WebSocket wire — 1.2 KiB — 2.0 KiB ✅
Claude Live turn WebSocket decoded — 20.8 KiB — 29.3 KiB ✅
Claude Live turn messages — 2 — 8 ✅

Baseline: ea2f22f · PR result: 603f8ab · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 106.1 KiB
  • Claude decoded thread snapshot: 106.4 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@rynfar
rynfar merged commit 5f1af34 into pylon Oct 3, 2026
24 checks passed
@rynfar
rynfar deleted the upstream/2026-10-02-orchestrator-v2 branch October 3, 2026 07:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Adopt upstream orchestrator v2 in full

1 participant