4.4 KiB
4.4 KiB
1. Run Worker Loop
- 1.1 Add run worker service that performs hello registration and stores active session state.
- 1.2 Add heartbeat loop with capability refresh and capacity reporting.
- 1.3 Add job claim loop with ack, progress, result, cancel polling, and reconcile.
- 1.4 Add bounded retry/backoff behavior without blocking heartbeat.
2. Process Lifecycle Execution
- 2.1 Replace metadata-only lifecycle executor with scoped install/start/stop execution.
- 2.2 Add process supervisor abstraction for server working directory, command templates, env allowlist, and lifecycle state.
- 2.3 Add safe command resolution from plugin lifecycle action schemas without unrestricted shell execution.
- 2.4 Add local state/journal for active server processes and in-flight jobs.
- 2.5 Add cancellation behavior for running lifecycle jobs.
3. Security Boundaries
- 3.1 Enforce scoped server workspace roots and never expose raw host paths to platform_web or plugins.
- 3.2 Reject plugin action payloads requesting raw credentials, direct sockets, absolute paths, or unrestricted commands.
- 3.3 Redact command output and metadata before sending progress/result.
- 3.4 Keep control, job, log, and artifact channels independent.
4. Log And Artifact Worker Hooks
- 4.1 Connect process stdout/stderr to the existing log spool.
- 4.2 Add artifact upload hook for lifecycle result refs.
- 4.3 Ensure large artifact work cannot block control heartbeat or job result submission.
5. CLI And Config
- 5.1 Add run config for platform URL, run endpoint ID, registration token, workspace root, poll intervals, and capacity.
- 5.2 Update
run/cmd/runto start the worker in local mode. - 5.3 Keep smoke mode available for tests and local diagnostics.
6. Verification
- 6.1 Add unit tests for worker state transitions, retry behavior, and cancel/reconcile.
- 6.2 Add run tests for scoped lifecycle command execution using temp workspaces.
- 6.3 Add integration-style test with a platform test server: hello → heartbeat → claim → ack → progress → result.
- 6.4 Run
cd run && go test ./...and record evidence. - 6.5 Run
cd platform && go test ./...and record evidence. - 6.6 Run
scripts/check-structure.shand record evidence. - 6.7 Run
openspec validate implement-run-worker-real-execution --strictand record evidence.
Evidence
- 2026-07-06: Added
run/runtime.Workerwith hello session registration, heartbeat, claim, ack, progress, cancel polling, terminal result, reconcile, bounded retry ticker reset, and an in-memory active job journal. - 2026-07-06: Replaced metadata-only lifecycle execution with scoped command-template execution through
ProcessSupervisor, per-server workspace resolution, command/env validation, cancellation, redaction, log sink, and lifecycle artifact hook. - 2026-07-06: Added
run/configworker settings for endpoint identity, registration token, workspace/spool roots, max jobs, heartbeat/poll intervals, and retry backoff; updatedrun/cmd/runto preserve smoke mode and start worker mode whenRUN_MODE=worker. - 2026-07-06: Updated
run/README.md,run/protocol/job.md, andrun/protocol/control.mdto document real worker mode, scoped lifecycle command templates, and channel boundaries. - 2026-07-06:
cd run && GOCACHE=/private/tmp/browser-go-build-cache go test ./runtimepassed after adding lifecycle tests for scoped command execution, unsafe template rejection, workspace escape rejection, cancellation, log sink, artifact hook, worker registration, heartbeat, claim/ack/progress/result, cancel/reconcile, spool token propagation, bounded retry, and HTTP platform-like worker flow. - 2026-07-06: Updated
platform/api/job_channel_handlers_test.goso the platform router workflow covershello -> heartbeat -> claim -> ack -> progress -> cancel -> result -> reconcile. - 2026-07-06:
cd run && GOCACHE=/private/tmp/browser-go-build-cache go test ./...passed with escalated loopback permission because existing API/workerhttptestsuites bind local ports. - 2026-07-06:
cd platform && GOCACHE=/private/tmp/browser-go-build-cache go test ./...passed. - 2026-07-06:
scripts/check-structure.shpassed. - 2026-07-06:
openspec validate implement-run-worker-real-execution --strictreportedChange 'implement-run-worker-real-execution' is valid; PostHog telemetry flush failed due restricted DNS and did not affect validation.