Skip to content

Wave 2: add durable DevSpace -> Codeg thin execution bridge #224

Description

@James3014

CURRENT STATUS — WAVE 2 SOURCE/ENGINEERING VERIFIED ON LATEST MAIN / LIVE 4-OF-5 PASS / ONLY W2.6 GROK WITNESS BLOCKED (2026-09-21)

Frozen implementation Candidate remains efc197bf3e7fdc49d357dab91eafc9eb152b9451 (tree f837ca7a0a7a8f2f5116e299c55ed982d89bdefd) from contract base b8f638f72c8dc4198b29e008f864026f55f2f4b6.

Current main advanced to 45ce06a51ab2af43f513ab49ad111be4cc8cc48c. The 8 intervening commits touch only carrier/cutover/CLI files and do not overlap the seven #224 paths. A disposable latest-main apply of the #224 diff completed without conflict and re-ran: bridge 10/10 PASS, Codeg MCP focused 2/2 PASS, config PASS, TypeScript PASS, git diff --check PASS, and npm run build PASS.

Live DevSpace -> Codeg bridge witnesses remain PASS for Codex, OpenCode, Agy/Antigravity and Cline; exact cancel and lost-ack/restart/no-duplicate reconciliation are also live-proven.

The only unmet Wave 2 engineering acceptance item is W2.6 Grok through the new DevSpace bridge. Fresh diagnosis proves the source/runtime path reaches Grok correctly but the current grok.com free rolling window rejects the Codeg-launched Grok turn before any model call: the exact failed session reports modelCalls=0, stop_reason=rate_limit, and subscription:free-usage-exhausted with 510976/500000 tokens. The same Grok 1.0.34 ACP protocol can complete successfully outside Codeg, and the successful/failed sessions use the same grok-build-plan / grok-4.6 / high configuration and essentially identical prompt/tool payload sizes. No alternate Grok model or XAI API credential is available on this host. Do not repair DevSpace/Codeg to work around this external quota and do not blind-retry.

Formal nexus.candidate_acceptance.v4 is a separate downstream independent-acceptance gate, not a Wave 2 engineering acceptance criterion. Its missing direct/Core evidence path must not be synthesized, but it no longer counts as a second Wave 2 implementation blocker.

Keep #224 open. Do not merge, cut over, retire adapters, release, or start Wave 3. The next engineering gate is one fresh Grok bridge nonce witness after legitimate Grok entitlement/headroom is available; then #224 becomes ready for independent acceptance.

Status

P0 — OWNER_AUTHORIZED / READY_FOR_BOUNDED_IMPLEMENTATION

Owner goal: complete Wave 2 by adding a thin DevSpace -> Codeg execution bridge on macOS, using the verified Codeg v0.31.1 five-route pilot from #217.

Source watermark at contract creation: main@b8f638f72c8dc4198b29e008f864026f55f2f4b6.

This is a bounded Candidate implementation. It does not authorize merge, production cutover, deletion of existing DevSpace provider adapters, Codeg auto-merge, release, or expansion of Nexus routing/acceptance authority.

Goal

Make DevSpace a thin, durable control gateway for Codeg execution so a host can start one already-selected worker task and later observe/reconcile/cancel it without keeping the MCP request open.

The intended seam is:

Nexus / host
  -> DevSpace thin Codeg bridge
       -> Codeg task/runtime
            -> Codex / OpenCode / Grok / Antigravity(Agy) / Cline

DevSpace owns gateway mechanics, durable operation identity, workspace containment, safe projection, timeout/reconciliation, and exact-effect fencing.

Codeg owns long-lived worker/task/worktree execution.

Nexus/Owner retains route selection, scope authority, verification, Candidate acceptance, merge, release, and production authority.

Required behavior

W2.1 Thin dispatch contract

Expose the smallest composable control surface needed for:

  • dispatch/start;
  • status/readback and terminal result collection;
  • exact cancellation;
  • reconciliation after timeout/restart/unknown acknowledgement.

Prefer reusing existing generic durable operation_status / operation_reconcile instead of adding duplicate status/collect authorities when they can carry the required Codeg receipt.

The dispatch request must carry an already-selected Codeg agent route; DevSpace must not choose/fallback/reroute providers.

Initial admitted routes for this Wave are exactly the five proven by #217:

  • codex
  • open_code
  • grok
  • antigravity
  • cline

Cline must support the proven explicit config contract mode_id=plan and config_values.model=poolside/laguna-s-2.1:free; do not hard-code GLM quota as a prerequisite.

W2.2 Durable identity and no-blind-retry

Bind each logical dispatch to a caller-supplied stable attemptKey / operation identity before the first Codeg effect.

Persist enough request identity to reject conflicting reuse of the same key.

Codeg generic create does not provide a caller idempotency key. The bridge therefore must create a deterministic bridge marker for the Codeg task and persist the operation before create. If acknowledgement is lost:

  • do not blindly create again;
  • reconcile against Codeg physical state using the stored marker / task identity;
  • bind exactly one matching Codeg task;
  • fail closed on conflicting/multiple matches;
  • only create again after reconciliation has authoritatively established that the prior create did not take effect.

Restart must not convert an unresolved create/start into a fresh dispatch.

W2.3 Workspace / folder boundary

The host addresses a DevSpace workspace, not an arbitrary Codeg filesystem path.

The bridge must resolve the Codeg execution folder from the already-open DevSpace workspace within approved-root rules. Do not expose arbitrary filesystem or credential-bearing Codeg configuration as a host-selected escape hatch.

If Codeg folder registration is needed, make it deterministic/reconcilable and keep it subordinate to the DevSpace workspace identity.

W2.4 Security projection

Do not proxy raw Codeg agent/config surfaces that can contain tokens, keys, auth state, or credential-bearing provider configuration.

Return only the bounded fields needed by the host, including stable DevSpace operation identity, Codeg task identity when known, agent route, task state, worktree/branch identity when safe, bounded result text, failure/cancel reason, and reconciliation status.

Apply existing DevSpace secret redaction to Codeg errors/results before exposing them.

Do not expose the Codeg bearer token.

W2.5 Authority containment

  • Codeg delegation remains disabled for this bridge.
  • no Codeg auto-merge;
  • no provider fallback/routing;
  • no automatic successor task;
  • no merge/push/release/deploy;
  • no direct replacement of existing DevSpace local-agent adapters in this Wave.

The bridge must not become another CapabilityPlanner, verifier, acceptance authority, or merge authority.

W2.6 Five-route live verification

Against an isolated disposable repository and local Codeg v0.31.1:

  • dispatch all five routes through the new DevSpace bridge, not directly through Codeg;
  • each route must produce a non-empty expected nonce result;
  • each must have a stable DevSpace operation identity and bound Codeg task identity;
  • disconnect/reconnect or equivalent restart reconciliation must preserve identity and not duplicate the task;
  • exact cancel must affect only its target;
  • baseline checkout must remain unchanged;
  • no merge, push, release, or production effect.

A transient provider failure may be retried only as a new logical attempt after the previous effect is terminal and reconciled. Do not erase the failed receipt.

Expected implementation shape

Prefer a small Codeg client/bridge module plus the minimum durable-operation/server wiring and tests. Reuse the current durable operation store/manager introduced on main; do not create a second operation ledger.

Expected touched surface should remain close to:

  • a new bounded Codeg bridge/client module and tests;
  • src/durable-operations.ts / tests only as needed for durable Codeg operation lifecycle;
  • src/server.ts / tests for the MCP surface;
  • configuration types only if needed for Codeg endpoint/token.

Do not refactor src/local-agent-* merely to make this bridge fit.

Acceptance

A Candidate is ready for independent review only when all are true:

  1. source tests for replay conflict, restart/outcome-unknown, reconcile-before-resend, exact cancel, secret-safe projection, and authority containment pass;
  2. the real MCP tool schema rejects extra process-control/authority fields;
  3. dispatch returns promptly with a durable operation rather than waiting for the worker turn;
  4. exact replay of the same attemptKey and request returns the same operation; conflicting reuse fails closed;
  5. unknown create/start acknowledgement is reconciled without duplicate Codeg tasks;
  6. all five provider routes pass a new live bridge E2E on isolated worktrees;
  7. DevSpace source checkout and disposable baseline are clean outside the Candidate worktree;
  8. no existing provider adapter is removed or widened;
  9. evidence is bound to exact Candidate SHA, Codeg v0.31.1, and the live package/runtime identity used for the E2E.

Workforce / execution boundary

Owner selected Codex CLI with Luna xhigh as the bounded implementer for this Wave. Fresh local availability/preflight is still required before mutation. This named worker does not receive acceptance, merge, release, or production authority.

Implementation realm: isolated local DevSpace worktree on the Owner's macOS host because final verification depends on the local Codeg runtime and installed provider CLIs.

Independent acceptance remains separate.

Non-goals

  • no production cutover;
  • no adapter deletion;
  • no Chat On Steroids integration in this Issue;
  • no generalized external-runtime plugin framework;
  • no provider catalog redesign;
  • no Codeg credential-management API exposure;
  • no change to Nexus route/model selection authority;
  • no auto-chain after Candidate completion.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions