Repository navigation
fix: bound remote agent execution and secure demo state #395
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
This file was deleted.
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -15,6 +15,23 @@ export class ProjectCoordinator extends DurableObject { | |
| return (await this.ctx.storage.get<Project>("project")) ?? null; | ||
| } | ||
|
|
||
| /** Claims at most one comparison so duplicate requests cannot launch extra paid runs. */ | ||
| async claimComparison(): Promise<boolean> { | ||
| return this.ctx.storage.transaction(async (storage) => { | ||
| if (await storage.get("comparison:claimed")) return false; | ||
| await storage.put("comparison:claimed", true); | ||
|
Comment on lines
+19
to
+22
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Both new claims remain set after work fails. If the first This recovery failure must be fixed before merging. Keep the claim while work runs, but release it when work definitively fails without changing the base. Retain a separate finished state after success, and reconcile uncertain push outcomes before allowing another attempt. ArtifactsFocused failure and retry harness
Command script for the base and head comparison
Retry behavior before the claims were added
Retry behavior with persistent claims at PR head
Tracked-file check and evidence checksums
|
||
| return true; | ||
| }); | ||
| } | ||
|
|
||
| async claimIntegration(): Promise<boolean> { | ||
| return this.ctx.storage.transaction(async (storage) => { | ||
| if (await storage.get("integration:claimed")) return false; | ||
| await storage.put("integration:claimed", true); | ||
| return true; | ||
| }); | ||
| } | ||
|
|
||
| async addTask(task: Task): Promise<void> { | ||
| if (await this.ctx.storage.get(`task:${task.id}`)) throw new Error("Duplicate task"); | ||
| await this.ctx.storage.put(`task:${task.id}`, task); | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -128,7 +128,15 @@ export class TaskAgent extends withWorkspaceContainer(AgentBase) { | |
| try { | ||
| await coordinator.updateTask(input.id, { status: "running" }); | ||
| const authorization = `http.extraHeader=Authorization: Bearer ${input.token}`; | ||
| await this.git(sh`git -c ${authorization} clone ${input.forkRemote} ${PROJECT_DIR}`); | ||
| for (let attempt = 0; attempt < 4; attempt++) { | ||
| try { | ||
| await this.git(sh`git -c ${authorization} clone ${input.forkRemote} ${PROJECT_DIR}`); | ||
| break; | ||
| } catch (error) { | ||
| if (attempt === 3) throw error; | ||
| await new Promise((resolve) => setTimeout(resolve, 1500)); | ||
| } | ||
| } | ||
|
|
||
| const { tools, execute } = createPiTools({ workspace: this.workspace }); | ||
| const models = createModels(); | ||
|
|
@@ -138,7 +146,10 @@ export class TaskAgent extends withWorkspaceContainer(AgentBase) { | |
|
|
||
| const messages: Message[] = [{ role: "user", content: input.prompt, timestamp: Date.now() }]; | ||
| let response = ""; | ||
| let toolCalls = 0; | ||
| const deadline = Date.now() + 4 * 60_000; | ||
| for (let turn = 0; turn < 8; turn++) { | ||
| if (Date.now() > deadline) throw new Error("Agent run deadline reached"); | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win Check the deadline after awaited work. If 🤖 Prompt for AI Agents |
||
| const reply = await models.complete(model, { | ||
| systemPrompt: [ | ||
| `You are a coding agent working on a repository at ${PROJECT_DIR}.`, | ||
|
|
@@ -151,6 +162,8 @@ export class TaskAgent extends withWorkspaceContainer(AgentBase) { | |
| }); | ||
| messages.push(reply); | ||
| const calls = reply.content.filter((part) => part.type === "toolCall"); | ||
| toolCalls += calls.length; | ||
| if (calls.length > 5 || toolCalls > 24) throw new Error("Agent tool budget exceeded"); | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. When an agent reaches the new deadline or tool budget, the catch replaces the reason with “Agent execution failed; inspect Cloudflare logs.” Neither limit reason is saved in Add these two safe messages to the allowed errors, or save distinct limit codes and log a sanitized diagnostic without exposing provider or shell output. ArtifactsFocused run-limit verification harness
Command used to run base and head verification
TaskAgent source before the limit changes
TaskAgent source with the limit changes
Base results without the new run limits
Head results with hidden run-limit reasons
|
||
| if (!calls.length) { | ||
| response = reply.content.filter((part) => part.type === "text").map((part) => part.text).join(""); | ||
| break; | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🩺 Stability & Availability | 🟠 Major | 🏗️ Heavy lift
Add completion and failure transitions to both claims. Each method stores a permanent flag before the worker starts external operations. If an operation fails, later requests receive 409 and cannot retry.
experiments/agent-changes/src/project.ts#L21-L22: release a failed comparison claim and distinguish an active comparison from a completed comparison.experiments/agent-changes/src/project.ts#L29-L30: release a failed integration claim and persist its terminal result separately from the active claim.The repository guideline says, “Prefer explicit lifecycle and state over hidden autonomy.”
📍 Affects 1 file
experiments/agent-changes/src/project.ts#L21-L22(this comment)experiments/agent-changes/src/project.ts#L29-L30🤖 Prompt for AI Agents
Source: Coding guidelines