You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Next minor release: all three agents (him, right, riskoff) stable on microsandbox — auth works, DB healthy, toolchain provisioned, no unexplained prod errors, upgrade machinery actually upgrades. Nothing left to decide before cutting the release.
Notes
Domain: right-agent platform on microsandbox (post-OpenShell migration, completed 2026-08-22).
Tracker: GitHub Issues on onsails/right-agent; map membership via "Part of #" in ticket bodies (repo convention; no sub-issue wiring used).
Fix silent auth-token load failures (#196) — root cause was 429-blind keepalive probe + silent-None token load, NOT a missing token; fixed 429-aware probe + stdout-tail diagnostics + WARN instrumentation (3c8617a).
Heal WAL desync loop + harden recovery (#197) — COMPLETE. Deployed single-owner standard-local topology keeps the Aggregator as the sole live database owner. db-repair provides coordinated offline forensic recovery only when corruption is proven. Healthy production databases were not rewritten; accepted windows and the clean coordinated restart had zero WAL/lock/owner recurrence.
Fix in-guest claude upgrade no-op (#199) — not a no-op: upgrades happened but logging showed only the report's first line and up-to-date matched a substring present in every run; fixed classification + last-line logging (88467ed).
Destination
Next minor release: all three agents (him, right, riskoff) stable on microsandbox — auth works, DB healthy, toolchain provisioned, no unexplained prod errors, upgrade machinery actually upgrades. Nothing left to decide before cutting the release.
Notes
Tickets
Decisions so far
Replace OpenShell with microsandbox as the Sandbox Backend — code + migration complete (all 3 agents on msb, verified); pending close.
Stabilise riskoff for release — all error classes fixed; remaining: 24h soak + curated allowlist.
Verify cross-provider credential substitution under msb (#92) — NO LEAK: per-SNI host gate in pinned SDK 0.6.10 blocks wrong-host placeholders (BlockAndLog); Provider credentials are injected by env-var name, not scoped to the provider's hosts (cross-provider exfiltration) #92 was OpenShell-era, closed; docs corrected.
Fix silent auth-token load failures (#196) — root cause was 429-blind keepalive probe + silent-None token load, NOT a missing token; fixed 429-aware probe + stdout-tail diagnostics + WARN instrumentation (3c8617a).
Heal WAL desync loop + harden recovery (#197) — COMPLETE. Deployed single-owner standard-local topology keeps the Aggregator as the sole live database owner.
db-repairprovides coordinated offline forensic recovery only when corruption is proven. Healthy production databases were not rewritten; accepted windows and the clean coordinated restart had zero WAL/lock/owner recurrence.Fix in-guest claude upgrade no-op (#199) — not a no-op: upgrades happened but logging showed only the report's first line and up-to-date matched a substring present in every run; fixed classification + last-line logging (88467ed).
Migration bookkeeping: #172 closed + #181 refreshed — done.
Actualize docs and site for the microsandbox era — stale Provider credentials are injected by env-var name, not scoped to the provider's hosts (cross-provider exfiltration) #92 exfiltration notice replaced with per-SNI gating; rest of surface verified clean (3e690be).
Cleanup dead memory-server + connection Arc (#127) — deleted dead stdio server/codegen path; owned Connection at every caller (3569975).
Fix curator idle gate restart reset (#135) — curator reads MAX archived-message timestamp; shared delivery IdleTimestamp unchanged (736cd7d).
Not yet specified
Out of scope