CB-571: charter receipt on spawn, in the roster and in the logs #54

Closed
agent wants to merge 0 commits from worker/m2-u5-ef8c42-15 into main
Member

Records a CharterReceipt (role, source, sha-256 digest, byte count) for every launch of a member, stores it on the MemberSession, exposes it in the roster (bridge_list and GET /members), and logs it at spawn as digest + role only. The charter prose itself is never recorded.

Also closes a verified leak: the legacy pane-placement spawn log printed the full argv, and the charter travels inside argv. That argument is now replaced by its digest.

Tests: mvn -f bridged/pom.xml clean install -> BUILD SUCCESS, Tests run: 678, Failures: 0, Errors: 0, Skipped: 0 (baseline 673 + 5 new: 3 CharterReceiptTest, 1 pane log redaction, 1 roster view).

Records a CharterReceipt (role, source, sha-256 digest, byte count) for every launch of a member, stores it on the MemberSession, exposes it in the roster (bridge_list and GET /members), and logs it at spawn as digest + role only. The charter prose itself is never recorded. Also closes a verified leak: the legacy pane-placement spawn log printed the full argv, and the charter travels inside argv. That argument is now replaced by its digest. Tests: mvn -f bridged/pom.xml clean install -> BUILD SUCCESS, Tests run: 678, Failures: 0, Errors: 0, Skipped: 0 (baseline 673 + 5 new: 3 CharterReceiptTest, 1 pane log redaction, 1 roster view).
agent added 1 commit 2026-08-15 08:21:21 +02:00
CB-575: charter receipt on spawn, in the roster and in the logs
CI / contract (pull_request) Successful in 46s
CI / build (pull_request) Successful in 1m34s
1966c69994
Record a CharterReceipt (role, source, sha-256 digest, byte count) for every
launch, store it on the MemberSession, expose it in bridge_list and GET
/members, and log it at spawn as digest+role only. Redact the charter argv
argument in the legacy pane-placement spawn log so the charter text never
reaches the daemon log. The charter prose itself is never recorded.
ltms added 1 commit 2026-08-15 08:48:59 +02:00
CB-571: retag charter-receipt references from the taken CB-575
CI / contract (pull_request) Successful in 43s
CI / build (pull_request) Successful in 54s
9ca9c43dfa
CB-575 already names the merged MCP-cancellation-filter change, so the
charter-receipt comments used the wrong number. Retag to CB-571, the number
this work was authored against.
agent changed title from CB-575: charter receipt on spawn, in the roster and in the logs to CB-571: charter receipt on spawn, in the roster and in the logs 2026-08-15 08:55:29 +02:00
ltms added 2 commits 2026-08-15 09:55:57 +02:00
# Conflicts:
#	bridged/src/test/java/dev/ltms/bridged/session/SessionManagerTest.java
CB-571: make PeerHandle.charterReceipt() abstract, fix OpenCode adapter's silent null
CI / build (pull_request) Successful in 50s
CI / contract (pull_request) Successful in 1m21s
35ade14630
SessionAwareHandle wrapped the base's WorkerHandle but never overrode
charterReceipt(), so it silently inherited the interface default (null)
while the real receipt sat on its delegate. sol/terra never got a
charterSource/charterSha256 roster row.

Deletes the default so every PeerHandle must answer explicitly; the
compiler now catches this class of gap instead of a roster field
quietly going missing.
Owner

Merged to main as c00a86b (lead-verified: own build of this branch merged onto main — 710 tests, BUILD SUCCESS, exit 0).

Closing as merged rather than through the button: the branch was integrated locally together with the review fix below, so Gitea now reports 0 changed files.

Review finding, fixed before merge. OpenCodeLauncher.SessionAwareHandle wrapped the base WorkerHandle but never overrode charterReceipt(). It therefore inherited the interface default returning null, while the real receipt sat on its delegate. The effect: sol and terra would have shown no charterSource / charterSha256 on the roster, while Claude Code members showed both — a feature silently half-present, with nothing failing.

The fix applied is the root one, not the one-line override: PeerHandle.charterReceipt() is no longer a default, so the compiler now forces every implementation to answer. This repo had shipped that same class of defect — a defaulted dependency that compiles, passes tests, and quietly turns a feature off — eight times before this one.

Merged to `main` as **c00a86b** (lead-verified: own build of this branch merged onto main — 710 tests, BUILD SUCCESS, exit 0). Closing as merged rather than through the button: the branch was integrated locally together with the review fix below, so Gitea now reports 0 changed files. **Review finding, fixed before merge.** `OpenCodeLauncher.SessionAwareHandle` wrapped the base `WorkerHandle` but never overrode `charterReceipt()`. It therefore inherited the interface `default` returning `null`, while the real receipt sat on its delegate. The effect: `sol` and `terra` would have shown no `charterSource` / `charterSha256` on the roster, while Claude Code members showed both — a feature silently half-present, with nothing failing. The fix applied is the root one, not the one-line override: `PeerHandle.charterReceipt()` is no longer a `default`, so the compiler now forces every implementation to answer. This repo had shipped that same class of defect — a defaulted dependency that compiles, passes tests, and quietly turns a feature off — **eight** times before this one.
ltms closed this pull request 2026-08-15 10:03:29 +02:00
Some checks are pending
CI / build (pull_request) Successful in 50s
CI / contract (pull_request) Successful in 1m21s

Pull request closed

Sign in to join this conversation.