Skip to content

refactor(research): published TCloud transport with compatible APIs and cancellation - #222

Merged
drewstone merged 13 commits into
mainfrom
sweep4/published-platform-packages-knowledge
Sep 28, 2026
Merged

drewstone merged 13 commits into
mainfrom
sweep4/published-platform-packages-knowledge

Conversation

@drewstone

@drewstone drewstone commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Change

Use published @tangle-network/tcloud@0.6.0 for research chat and search. Keep the public RouterClient, RouterError, maxRetries, and retryBaseMs contracts. Require Interface ^2.13.0 for the installed Sandbox dependency. Keep one receipt-sourced cost total; report usage().usd as NaN when a successful response lacks a cost receipt.

Pass run cancellation through the default worker, verifier, claim extractor, and page fetch. Make abort terminal before fallback, source registration, or round event when the signal is observed. A configured router signal also cancels default worker and driver requests. Injected routers keep their public contract.

Exact-head proof

Head 9f382ea0abb3500a87fd2fccd7a922a98c7ef1c6; main 20e8f44d89f1431422e242ad030b8fe280bb272f. GTR, Node 24.20.0, pnpm 10.34.5:

  • Frozen registry install, pnpm lint, pnpm typecheck, pnpm build, and pnpm verify:package passed. The packed public consumer installed one copy each of Eval 0.199.0, Core 0.9.7, Interface 2.13.0, and Zod 4.5.4; five imports resolved.
  • node scripts/prove-research-transport.mjs passed against local HTTP: six requests used tcloud-sdk/0.6.0; concurrent chat and search cost USD 0.033; missing URL was rejected; 401 retained RouterError(401); abort closed the socket; a rate-only successful response yielded NaN. Retry proof returned the billed response after exactly one 503 retry and canceled backoff in 34 ms without a second request.
  • Real local HTTP worker, verifier, and driving-driver requests rejected arbitrary abort reason stop and closed sockets. The driving driver passed with both run and configured signals. A real runVerifiedResearchLoop at maxRounds: 1 rejected stop, closed its socket, and left zero sources and zero iteration events. An injected verifier returning a valid accept verdict after abort still rejected stop.
  • The prior head 8768eb4 passed both remote CI jobs. On this head, a focused local Vitest run reached two 15-second timeouts while GTR load exceeded 400; no assertion result was obtained for those two cases. Exact-head rerun and remote CI are pending.
  • Fetched main merge-tree, git diff --check, and normal commit and push hooks passed.

The maintained transport proof is scripts/prove-research-transport.mjs. Cancellation scripts and receipts are at /tmp/agent-knowledge-222-proof/ on GTR. No paid model call, package publication, or deployment occurred.

@drewstone drewstone changed the title docs: audit platform package ownership for sweep 4 refactor: use published tcloud for research transport Sep 26, 2026
@drewstone
drewstone marked this pull request as ready for review September 26, 2026 03:22
tangletools
tangletools previously approved these changes Sep 26, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 8ecae967

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-26T03:22:25Z

drewstone and others added 2 commits September 25, 2026 22:00
…sport

Chat usd now comes from the router's X-Tangle-Price-* headers via tcloud's
metering. options.signal rejects callers again, a missing key fails before any
request, hits without a URL are dropped, and the lockfile includes tcloud.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
tangletools
tangletools previously approved these changes Sep 26, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — c498ca41

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-26T05:04:25Z

@drewstone

Copy link
Copy Markdown
Contributor Author

Closing this migration under the release-owner handoff.

At exact head c498ca415eb8f680f78f3a2f3f5badcfb4fa4e83, it removes the public RouterError, maxRetries, and retryBaseMs APIs.
That requires a major release and coordinated consumer migration; Runtime currently depends on Knowledge ^17.1.6.

The current public tcloud release is still 0.5.2.
Its dependency on Sandbox >=0.34.3 <0.35.0 cannot share Runtime's supported Sandbox copy.
The PR lockfile proves the additional Sandbox 0.34.6, Core 0.9.5, Interface 1.9.0, and Zod 4.4.3 closure.
This is unsuitable for the maintained strict packed cohort.

The branch and its live transport evidence remain available.
A replacement migration needs a public SDK with compatible dependency closure, actual request cancellation, and an explicit major-version consumer cutover.
No package was merged or published from this PR.

… public APIs

Rebuild sweep 4 from current main. Preserve RouterError and retry options, propagate actual transport cancellation, account per-response costs and retain the generated release-gated registry lock. TCloud 0.6.0 must be published before this consumer can install from npm. Delete the old audit note and local HTTP/retry/pricing implementations.
@drewstone drewstone changed the title refactor: use published tcloud for research transport refactor(research): published TCloud transport with compatible APIs and cancellation Sep 27, 2026
@drewstone drewstone reopened this Sep 27, 2026
tangletools
tangletools previously approved these changes Sep 27, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 6fb91b9b

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-27T05:03:21Z

…ation

Rebuilt and checked in actions run 36296093325. The registry activation lock has identical parsed content and measured SDK integrity, without unrelated YAML reformatting.
tangletools
tangletools previously approved these changes Sep 27, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — d98263b0

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-27T05:06:26Z

tangletools
tangletools previously approved these changes Sep 28, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 7e17fe30

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-28T04:54:41Z

@drewstone

Copy link
Copy Markdown
Contributor Author

P2 — The public research-loop signal does not cancel its router calls at 7e17fe3.

createWebResearchWorker receives ctx.signal but builds the default router from options.router_options (src/web-research-worker.ts:246–247). Query generation calls router.chat (:339–346), and search calls router.search (:263–264), without the run signal. The adapter forwards only options.signal to TCloud and disables its own timeout (:127–132, :163–189). Aborting runVerifiedResearchLoop while one of these calls is in flight therefore leaves the request open, even though TCloud correctly cancels when given a signal.

An exact-head built-package local HTTP reproduction aborted the worker signal during a delayed chat. The worker and socket remained open 150 ms after abort and settled only with the server response at 400 ms. This can leave a paid call running after cancellation. Pass the run signal to the default router for each worker invocation, composing it with any configured signal, or add a per-call signal to the public RouterClient contract. Prove cancellation through the public worker entrypoint as well as the adapter. The existing configured-signal transport proof, retry proof, and concurrent receipt proof pass; the defect is at the caller boundary. This behavior predates the SDK migration but is within this PR's cancellation claim.

tangletools
tangletools previously approved these changes Sep 28, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 8768eb47

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-28T05:06:41Z

@drewstone

Copy link
Copy Markdown
Contributor Author

P2 — Cancellation can still resolve a completed research round at 8768eb4.

formSearchQueries catches the aborted router.chat call and uses fallback queries (src/web-research-worker.ts:347–363). The worker then breaks on ctx.signal.aborted and returns a contribution (:268–315). In an exact-head built-package local HTTP test, aborting during chat made the worker resolve with zero sources instead of reject. runVerifiedResearchLoop checks the signal only at the beginning of a round (src/verified-research-loop.ts:244–259); a one-round run can still checkpoint, write a research.iteration event, and return success (:365–382) after cancellation.

P2 — The verifier can accept a source after cancellation.

The catch in createVerifyingResearchDriver.verifySource recognizes only errors named AbortError, then applies acceptOnParseFailure; it also lacks a signal check after router.chat resolves (src/web-research-worker.ts:510–531). Exact-head local proof with AbortController.abort('stop'), an injected router rejecting with the signal reason, and acceptOnParseFailure: true returned { accept: true } while the signal was aborted. The loop can register that verdict (src/verified-research-loop.ts:279–299). An injected router resolving after abort reaches the same path. The driving claim extractor has a related configured-signal case: its catches at src/research-driving-driver.ts:731–734, 765–769 check only the run signal or error.name, so a configured signal aborted with a string reason can enter deterministic fallback.

Check cancellation after awaited calls and before fallback or persistence. A local proof should cover the worker and verifier terminal outcome, including non-AbortError reasons, plus no source or iteration-event write after abort. This review used local HTTP and injected clients only; no paid calls or publish.

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 9f382ea0

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-28T05:21:41Z

@drewstone

Copy link
Copy Markdown
Contributor Author

Read-only independent recheck of exact pushed head 9f382ea0abb3500a87fd2fccd7a922a98c7ef1c6 against main 20e8f44d89f1431422e242ad030b8fe280bb272f: no remaining P1/P2 in the reviewed TCloud migration and cancellation paths. git merge-tree --write-tree and git diff --check pass.

The two cancellation findings at 8768eb4 are addressed. I reran bounded built-package local HTTP proofs for worker, verifier, configured-signal driving driver, and the one-round public research loop. Each rejected the arbitrary abort reason stop; the HTTP sockets closed, and the loop left zero sources and zero events. The injected verifier also rejected after its router returned a valid acceptance following abort. A separate injected-worker check confirmed the loop rejects a contribution returned after abort and leaves zero sources and events.

The six-request local HTTP adapter proof passed: tcloud-sdk/0.6.0 request header, concurrent chat plus search cost usd=0.033, missing cost receipt as NaN, RouterError(401), and a closed canceled socket. The public TCloud 0.6.0 registry integrity matches the lockfile. The existing packed-consumer verification log reports a clean install with one installed copy each of Eval 0.199.0, Core 0.9.7, Interface 2.13.0, and Zod 4.5.4.

Remote CI is still running. The focused Vitest attempt timed out under host load, so it is not counted as passing. No paid calls, source edits, or package publishing occurred in this review.

@drewstone
drewstone merged commit 58b0795 into main Sep 28, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants