Skip to content

[spark-compete wave 3] builder / mission execution (stacked) - #884

Closed
vibeforge1111 wants to merge 7 commits into
spark-compete/wave1-install-buildfrom
spark-compete/wave3-builder-mission
Closed

[spark-compete wave 3] builder / mission execution (stacked)#884
vibeforge1111 wants to merge 7 commits into
spark-compete/wave1-install-buildfrom
spark-compete/wave3-builder-mission

Conversation

@vibeforge1111

Copy link
Copy Markdown
Owner

Spark Compete — Wave 3 (builder / mission execution), stacked on spark-compete/wave1-install-build

Shows only the Wave-3 delta. Maintainer-consolidated mission-execution + reliability + security PRs.

Commits

On-merge points (not written until merge)

4gjnbzb4zf-sudo 513 · ifeoluwaaj 124 · Esc1200 48 · johncrossu 14 · TALLSOME24 12

Skipped (superseded / already-landed)

Verified: proportionate diff, no churn, no conflict markers. TS/build verified by CI (no node_modules locally). Fraud/dup excluded. Draft — gated on CI + approval.

🤖 Generated with Claude Code

Meta Alchemist and others added 7 commits June 25, 2026 16:46
Consolidates a same-author path-redaction series:
- Remove tracePath from creator mission GET response (#877)
- Remove server path from mission active POST response (#876)
- Remove rawResponse field from analyze error response (#874)
- Remove x-spark-preview-root header leaking server path (#873)
- Use trusted x-real-ip / last x-forwarded-for entry for the
  rate-limiter client key (#875)

Surviving-line indentation normalized back to file style (the patches
bundled an over-indentation reflow of untouched lines).

Co-authored-by: Esc1200 <Esc1200@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Validate targetFolder in PRD bridge write stays within the workspace
  root before writing, rejecting traversal outside cwd (#862)
- Validate workingDirectory in the dispatch endpoint against the Spark
  workspace root so spawned processes cannot run with an arbitrary cwd (#861)
- Reject interpreter code-execution flags in creator-mission validation
  commands, and validate missionId format against path traversal (#869).
  Completed the flag denylist per review: added node -p/--print and
  python -m/--module alongside the original -c/--command/-e/--eval/-.

#860 (teams endpoint auth) is already satisfied by a superior
requireTeamsAuth implementation on the base branch — no change landed.

harness_core interim_until_migration for the creator-mission validation
path: re-home into Governor on migration.

Co-authored-by: ifeoluwaaj <ifeoluwaaj@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Independent single-file hardening fixes:
- scheduler: in-flight Set so _tick cannot relaunch a record whose
  previous fire is still running (#858)
- command-runner: SIGKILL escalation timer at timeoutMs+5s, cleared on
  close and error, so a SIGTERM-ignoring child can't hang the caller (#855)
- retry-after: cap honoured Retry-After at 60s so a hostile/quota-exhausted
  upstream can't stall a mission for hours (#853)
- sync-client: cap reconnect backoff at 30s and add +/-25% jitter so a
  fleet of tabs doesn't reconnect in lockstep (#824)
- spark-harness-client: tolerate up to 3 transient status-poll failures
  before failing the mission (#823)
- events POST: dedup caller-supplied event ids within a 5m window so a
  retried POST doesn't fan out duplicate events (#851)
- brief-enricher: validate positive-numeric env overrides (#852)
- h70-skill-matcher: precompute multi-word phrase keys once at module
  load instead of per task (#872)
- canvas store: mirror sibling-tab writes via storage events, skipping
  while local edits are pending (#859)
- MissionBoard: guard NaN dates in relative-time formatting (#842)

harness_core interim_until_migration for scheduler: re-home into Governor
on migration.

Co-authored-by: 4gjnbzb4zf-sudo <4gjnbzb4zf-sudo@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…visibility

mission-control-relay.ts:
- Cap missionLifecycleStates / taskLifecycleStates at 5000 entries with
  oldest-insertion eviction so the process-lifetime maps can't grow
  unbounded (#854)
- Seed the dedup maps from persisted recent entries at module load so a
  restart doesn't re-broadcast already-recorded terminal lifecycle events
  to Spark ingest and webhooks (#827). Seeding routes through the bounded
  insertion path to preserve the cap invariant.
- Export isMissionControlMissionId and warn (only when a missionId is
  present) when a mission event is accepted but dropped from the board
  because its missionId doesn't match the required shape (#69)

events POST: surface boardEligible in the response so callers learn at
emit time that their event won't appear on the board (#69).

#854 and #827 overlap on the same maps via different mechanisms (cap vs
restart-seed) and compose cleanly; both land.

Co-authored-by: 4gjnbzb4zf-sudo <4gjnbzb4zf-sudo@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…d relays

- mission-executor: after a debounced state-sync POST resolves, re-check
  the live status and DELETE the active-mission record if the mission is
  now terminal, so a cancel/complete that landed during the in-flight POST
  isn't clobbered back to "running" and resumed (#856). Adjusted per review:
  the new DELETE now passes getEventsAuthHeaders() to match the sync POST
  and clearFileSyncState DELETE in this file, so an auth-enforcing endpoint
  actually clears the stale record.
- prd-bridge/load-to-canvas: guard the lifecycle relays with an
  alreadyLoaded check (pendingRequestMeta.status === 'canvas_loaded')
  so a retried POST doesn't re-fire mission_created/task_completed to
  operators or seed the relay history twice (#850). Resolved the merge
  conflict against the base's added task_completed relay by guarding both
  relays; pendingRequestMeta is loaded fresh from the persisted file each
  request, so a retry sees the prior request's canvas_loaded status.

harness_core interim_until_migration for #856: re-home into Governor on
migration.

Co-authored-by: 4gjnbzb4zf-sudo <4gjnbzb4zf-sudo@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…e/ID sites

Same-author entropy-hardening series, reduced to the disclosed security
lines per review (all undisclosed UX/gitignore/test hunks stripped — most
were already independently landed on the base branch):

- creator-mission saveCreatorMissionTrace: atomic-write temp path no
  longer embeds process.pid+Date.now() (predictable -> symlink
  pre-emption); use randomUUID() with the codebase's node:crypto import
  convention (#825)
- provider-runtime persist: same predictable temp-path fix, randomUUID()
  via node:crypto import (#826)
- canvas store: the 4 connection-ID sites switch from
  Math.random().toString(36) to crypto.randomUUID() Web Crypto global (#867)

Per review notes: took ONLY the security lines, used the node:crypto
randomUUID import (not a bare crypto. global) in the server files, and
discarded the tautological re-implementation tests.

Co-authored-by: TALLSOME24 <TALLSOME24@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Surface diagnostics from catch blocks that swallowed errors silently:
- access-execution-actions: spark binary lookup failure
- command-runner: dependency check + package.json parse failures
- spawner-state: file-scan entry + helper-text read failures

Resurrected from closed PR #109 and adjusted per review: re-indented the
added lines to tabs to match the file style (the PR introduced
space-indented catch blocks), and dropped the agent-event-ledger hunks
because the base already logs those two JSONL-parse failures via
warnMalformedJsonlLine. The logged error objects are binary-lookup /
JSON-parse / file-IO errors only — no request bodies, credentials, or
env secrets are surfaced.

Co-authored-by: johncrossu <johncrossu@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@vibeforge1111

Copy link
Copy Markdown
Owner Author

Superseded by r29: the full wave stack was squash-merged into the default branch via this repo's tip PR. Closing this intermediate wave-branch PR (branch retained; reopenable if needed).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant