Skip to content

Agent-core fixes from the desktop batch 36–58 (fallback billing, turn marks, serve, local model context, config 0600) - #595

Merged
sosidudku1 merged 1 commit into
mainfrom
fix/agent-core-36-58
Oct 2, 2026
Merged

sosidudku1 merged 1 commit into
mainfrom
fix/agent-core-36-58

Conversation

@sosidudku1

Copy link
Copy Markdown
Collaborator

The agent-core (src/) half of the desktop batch 36–58, brought to main first per the main-first rule. The desktop half is on rel/xp-build via the integration branch int3/desktop-36-50; once this lands, main is merged back into rel/xp-build.

What changes

  • Fallback chain. A refusal because the account cannot pay (402; 403/429 that says funds, balance or billing; insufficient_quota) ends the turn in the provider's own words instead of parking on the last link for five minutes. Rate limits stay waits. One wording rule decides key refusals for the chain and for billing. A call whose turn was stopped never falls over to the next link, so a Stop no longer leaves the next turn on a fallback.
  • Sessions. A turn is marked running in its row when it starts, and its end is written however it ends, shutdown included. At boot, marks left by a process that is gone are ended as cancelled (pid, process start time, host and database are checked; an ambiguous owner is left alone). A store that cannot add the new column still boots, without marks.
  • serve. Its structured log is written at last (the sink factory was passed where a sink was expected). An orphaned serve mutes a dead stderr instead of exiting, so its shutdown path runs. The HTTP server's close waits for its connections. Transport errnos (ECONNREFUSED, ETIMEDOUT…) reach traces and log lines as causeCode.
  • Local models. On unified memory the automatic context leaves the system max(4 GiB, 25 % of RAM) and caps the KV cache at 1/16 of RAM (Qwen 3.5 4B on 16 GB: 262 144 → 149 504 tokens); --swa-full is weighed against the headroom only. One --list-devices per start (an empty answer is retried once), the speed probe is carried over for the same launch for a day, the llama.cpp release check is trusted for six hours, and more unified-memory GPUs are recognised.
  • Config. config.json is written owner-only (0600). config set - reads the whole file from stdin, so no API key travels on a command line.
  • Skills. skill browse / search read ClawHub and the GitHub taps side by side, and fetch SKILL.md files through a pool.
  • Logging. A log line carries the start of the model's text, not all of it.

Not included

The SSE frame changes of the same items (billing cause and failed links on error / provider_waiting, the cancelled loop_failed frame) stay on rel/xp-build, where the HTTP extensions they build on live, together with their two tests.

Checks

On the desktop branch, with these changes: agent lint, build and the whole suite (12 443 passed, 0 failed; the known EACCES from local-models-orchestrator-auto-update.test.ts is pre-existing), desktop lint and unit tests, every release-fix smoke check (590/0), Fusion smoke (39/0).

The src/ half of backlog items 36–58 (rel/xp-build integration branch
int3/desktop-36-50), moved here first per the main-first rule:

- fallback chain: a refusal because the account cannot pay (402; 403/429
  with funds, balance or billing words, insufficient_quota) ends the turn
  in the provider's own words instead of parking on the last link; rate
  limits stay waits; one wording rule for key refusals; a stopped call
  never falls over to the next link (item 40, ATO-137)
- sessions: a turn is marked running in its row, its end is written however
  it ends — shutdown included — and marks a dead owner left behind are ended
  at boot (start time, host and database checked); a store that cannot add
  the column still boots (ATO-137)
- serve: the structured log is written, an orphaned serve mutes a dead
  stderr instead of exiting, the server's close waits for its connections;
  transport errnos (ECONNREFUSED…) reach traces and logs (items 41, ATO-123)
- local models: the automatic context on unified memory leaves the system
  max(4 GiB, 25 % of RAM) and caps the KV cache at 1/16 of RAM; --swa-full
  weighed against the headroom only; one --list-devices per start; the
  speed probe carried over for the same launch for a day; the llama.cpp
  release check trusted for 6 hours (items 39, 42)
- config: config.json written owner-only (0600); `config set -` reads the
  whole file from stdin so no key travels on a command line (ATO-132)
- skills: browse and search read ClawHub and the GitHub taps side by side
  (ATO-119 Д45)
- logging: a log line carries the start of the model's text, not all of it;
  the stderr sink factory can no longer pass for a sink

The SSE frame changes of the same items stay on the desktop branch, where
the HTTP extensions they build on live.
@sosidudku1
sosidudku1 merged commit 6d50619 into main Oct 2, 2026
2 checks passed
sosidudku1 added a commit that referenced this pull request Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant