Ref writers for conversations and actors: namespaces, delegation, and closing the rest - #305
Open
nishu-builder wants to merge 1 commit into
Conversation
nishu-builder
added this pull request to stack #307
October 5, 2026 10:11
nishu-builder
force-pushed
the
claude/upbeat-cori-xk77fg-4-conversations
branch
from
October 5, 2026 14:04
d82c1b8 to
569e465
Compare
nishu-builder
force-pushed
the
claude/upbeat-cori-xk77fg-4-conversations
branch
2 times, most recently
from
October 6, 2026 02:13
75f4dea to
a9933c5
Compare
… closing the rest Conversations move into ref-writers namespaces (design/ref-writers.md), and with them every ref the server lets through without a writer's proof: a push outside a namespace is now refused unless the ref is content-named or unguarded (refs/caos/dev). - A conversation lives in refs/caos/w/<ns>/conversations/<hex id>/head, with <ns> fixed by its creator's key and its id; a subagent's head sits in its parent's namespace; the sidebar moves to a personal namespace. Across a process boundary a conversation is named by its address, <ns>/<id> (llm-step's --conversation, X-Caos-Conversation, reader:@= grants). - llm-step asks to write its conversation's namespace and hands it to its subagents, relays and async tasks; llm-test-tool founds namespaces with the run token its test was granted. - std/caos-conversation-list reads heads and memberships from their namespaces and lists each conversation by its address. - An actor's state branch moves into a namespace, refs/caos/w/<ns>/actors/<name>: the caller puts writes=<ns> on the actor request, and std/actor's finish sends the run token that grants as a push option on its raw receive-pack POST. tests/actor and tests/actor-ref found a namespace with the test's token; actor-ref also shows a tokenless update is refused. - caos-cli resolves a conversation's namespace (its own, or the one holding that id), `writers add` takes a conversation, `conversation-ref` prints a head ref, and the tui's /invite takes a public key. Cloud bootstrap takes --ref-writer-key. - The suite signs as a fresh writer and hands --writes=* down to every test; tests that pushed plain branches use a namespace or a content-named ref. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NzY2JJGk9nTMG6gu8dZXpc
nishu-builder
force-pushed
the
claude/upbeat-cori-xk77fg-4-conversations
branch
from
October 6, 2026 02:18
a9933c5 to
edaa73c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Moves conversations and actors into namespaces (
design/ref-writers.md, "Conversations" and "Actors") and stops letting anything else through: a push outsiderefs/caos/w/<ns>/is refused unless the ref is content-named or unguarded. Part 4 of 4, stacked on #304.refs/caos/w/<ns>/conversations/<hex id>/head, with<ns>fixed by the creator's key and the id, so a client finds its own without a lookup;<ns>/<id>: llm-step's--conversation, theX-Caos-Conversationheader, andreader:@=… conversation=.refs/caos/w/<ns>/actors/<name>. The caller putswrites=<ns>on the actor request, andstd/actor'sfinishsends the run token that grants as a push option (caos-auth=run:<token>) on its raw receive-pack POST. The wrapper adds nowritesto the inner's request.tests/actorandtests/actor-reffound a namespace with the test's token and handwrites=<ns>to what moves refs in it;tests/actor-refalso checks that an update without the token is refused.std/caos-conversation-listreads heads and memberships from their namespaces and lists each conversation by its address.writerstakes a conversation as well as a namespace,conversation-ref <id|address>prints a head ref, and the TUI's/invitetakes a public key.--ref-writer-key, anddrive convfinds a session's head in any namespace.--writes=*down to every test. Tests that pushed plainrefs/heads/*now use a namespace or a content-named ref.std/actor/README.md, whose open question 5 this answers), anddesign/ref-writers.mdis marked implemented.Existing conversations under
refs/caos/v3/stay in the repository but are no longer listed; nothing moves them. The same goes for any actor state underrefs/heads/actors/.Verified here
cargo fmt --check,clippy -D warningsandcargo testpass, exceptlauncher::checkout_import_completes_partial_history_and_keeps_local_edits, which fails the same way onmainin this container.nix buildpass.serverandcaos-cli, with two writers: a plain branch push is refused; one writer'sconversation-reffinds the other's conversation by id; a push into it is refused untilwriters add <id>, and refused again afterwriters remove <address>.std/actor, the actor tests andcaos-conversation-listvet with the std/go prelude. Against a built server, a raw receive-pack update into a namespace reaches the hook with its push option: it is refused without one ("needs a caos-auth push option") and with an unknown token ("unknown run token"), both from a hand-built request and fromstd/actor's ownsetRef. The hook accepts the namespace commit the actor tests build.caos-conversation-list'slist(), run against a server seeded bycaos-cli, lists conversations by address with their memberships.tests/git-import/fixture.pypasses every step up to a lost-reply fault-injection step that fails the same way onmainin this container.Not verified here
caos-testsuite, including every updated test andtests/actor/tests/actor-ref:caosd upcan't fetch flake inputs from inside its containers in this sandbox.Stack
🤖 Generated with Claude Code
https://claude.ai/code/session_01NzY2JJGk9nTMG6gu8dZXpc