Skip to content

feat(agents): review agent-requested configuration updates - #273

Open
johnmatthewtennant wants to merge 35 commits into
mainfrom
sol/agent-update-drafts
Open

johnmatthewtennant wants to merge 35 commits into
mainfrom
sol/agent-update-drafts

Conversation

@johnmatthewtennant

@johnmatthewtennant johnmatthewtennant commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Why

buzz agents draft-update sends owner-reviewed requests to change an existing personal agent, but buzz-app did not surface those requests for the owner to review.

What

Buzz validates and deduplicates encrypted observer requests, revalidates the referenced channel roster, requires confirmed requester membership, and opens the uniquely matching personal agent in a prefilled review editor. Requests queue while another review is open and wait for idle control before refreshing agent inventory. A successful inventory Retry resumes the pending review. Authorization requires positive roster evidence accepted by discovery; empty or older viewer-scoped responses cannot reuse cached membership. The payload channel must remain accessible after resolving incomplete discovery. Transient roster failures keep the request queued with Retry and dismiss actions. Once a review is open, temporary membership uncertainty preserves its edits, Save completion, and recovery notices while disabling writes until fresh reauthorization. Confirmed membership revocation dismisses the request. Replacing the relay session or account scope retires its queued requests and private review state; temporary revalidation within the same session preserves them. The owner must explicitly save before configuration changes; if a native Save fails, the editor keeps the reviewer's edits and shows the error and status recovery action. Both agent-requested reviews and ordinary agent edits use the shared editor: a complete Save closes it and shows a success toast. Save errors, restart failures, and unconfirmed profile publication keep the editor open for recovery. After the initial authorized name match, a requested review retains the native agent ID across roster retries, so a committed rename preserves the editor and restart recovery while identity and community checks remain enforced. This fixes inconsistent dismissal between the two entry points.

Requests can change supported configuration fields only. Secret-shaped, unknown, and response-policy data are rejected. Ambiguous or missing agent names produce an explanatory notice. Agent creation requests remain unsupported and produce a notice without changing local state.

Reviewer-reproducible examples

Headless request and failed-Save recovery

Use the pinned dependency and browser setup in the contribution workflow and browser testing. The checked-in journey starts its own built app and relay fixture, creates an owner session, a personal agent named Fixture agent, the alpha channel, and an authorized agent requester. No existing account, channel UUID, or personal agent is needed.

bin/pnpm test:browser tests/browser/agent-management.spec.mjs --project chromium --no-deps

The first scenario sends a proposed model update, closes it without saving, then repeats and saves. It checks the saved fixture model and queues a second request behind an open review. The recovery scenario replaces the proposed model with reviewer-choice, deliberately rejects Save through the native-control fixture, confirms the editor and owner choice remain, restores the host, uses Retry status, and saves again. The editor closes and the fixture reports reviewer-choice. Both scenarios have been observed passing in Chromium and WebKit.

Native owner flow

On a disposable host that supports native Buzz, follow desktop setup, connect the owner app to staging, and create or select a clearly labeled test personal agent in Agents. Add that agent to a staging test channel and run the request from its managed runtime, where the CLI receives its agent identity and BUZZ_AUTH_TAG. Use that channel's UUID for <channel-uuid>, the exact name shown in Agents for <personal-agent-name>, and a supported model ID from the editor's model picker for <model>.

  1. In that managed runtime, run buzz agents draft-update --channel <channel-uuid> --agent-name <personal-agent-name> --model <model>.
  2. Confirm the owner app opens the matching personal agent with the proposed model and the requested-update notice. Close without Save and reopen from Agents to check that saved settings are unchanged.
  3. Repeat the request and press Save changes. Confirm the editor closes and the saved model appears when reopened.
  4. From Agents, edit its instructions and Save. Confirm this ordinary editor also closes and shows the changed instructions when reopened.

Browser coverage

One failed-save recovery browser case was added and none removed. It exercises the built app and native control fixture because helper tests cannot detect the editor unmounting when host status changes to an error state. The case verifies retained edits, status recovery, and successful retry. Existing requested-update and ordinary-edit journeys cover closure and reopened settings in Chromium and WebKit.

Verification limits

The observed browser journeys use modeled native agent control and persistence. Native execution, native IPC, and durable host persistence remain unverified. Human confirmation of the final unified Save behavior remains unrecorded.

Screenshots

Agent-requested configuration review

Agent-requested configuration review over a representative conversation

Failed Save keeps reviewer edits

Failed Save error while the reviewer model choice remains in the agent editor

Sol added 2 commits September 25, 2026 13:48
Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>
Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>
Sol and others added 18 commits September 25, 2026 15:17
Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>
Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>
* origin/main:
  ci: publish scheduled macOS test prereleases (#262)
  feat: add private text feedback plugin (#242)
  🤖 docs: add pre-PR checklist and review guidance to AGENTS.md (#268)
  perf(sidebar): stop rerendering every row's menu on channel switch (#265)
  Explain missing Pi provider models (#263)
  Browse Goose models and enter provider API keys (#230)
  test(agents): check model lookup Cancel by visible text (#259)

Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>

# Conflicts:
#	src/bundled/profiles/ProfileAgentIdentity.test.tsx
Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>
* origin/main:
  feat: attach sanitized image and opt-in diagnostics to feedback (#245)
  test: repair three baseline Vitest failures (#276)
  fix(agents): recover status polling and scope failure diagnostics (#283)
  Share avatar editing across community profiles and managed agents (#271)
  feat(profiles): archive, unarchive and delete agents from the profile pane (#256)
  ci: run browser journeys on three shards per engine (#280)

Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>

# Conflicts:
#	src/bundled/agents/AgentEditor.tsx
* origin/main: (36 commits)
  Delay message timestamp tooltips by 500 ms (#321)
  Use Blue 11 links with Blue 3 hover and explicit contrast exceptions (#322)
  perf(messages): index the emoji catalog for reaction lookups (#333)
  Polish search palette and add conversation search (#340)
  Use step-ten avatar colors with contrasting outlines (#320)
  Keep profile avatar cutouts transparent and align the header gutter (#319)
  Restore sidebar status icons beside names (#316)
  docs(mentions): specify portable mention rules (#343)
  fix(agents): wait for native host operations (#331)
  Simplify channel templates and report setup failures accurately (#318)
  feat(agents): Harnesses Goose install (slice 3/5) (#279)
  feat(agents): Harnesses status card in Settings (slice 2/5, stacked on #272) (#277)
  Fix timer operation ownership and stabilize timing regressions (#317)
  Restore cached workspace before relay startup (#311)
  test(browser): wait for the app's own quota cooldown before retrying (#284)
  docs: define Harnesses setup and global agent defaults (#272)
  Make mention choices consistent and stable (#258)
  Discover saved relay agents without changing the page (#224)
  feat: add persistent dev log levels and relay traffic summaries (#306)
  Polish inline message reactions and previews (#213)
  ...

Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>

# Conflicts:
#	src/bundled/agents/AgentEditor.tsx
#	src/bundled/profiles/ProfileAgentIdentity.test.tsx
* origin/main:
  Fix clipped emoji in reaction pills (#339)

Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>
…t-update-drafts

* commit '0a4982797f38164d75e3e8f48e58fabb9dd59e66': (66 commits)
  Show saved local and relay inventory while retaining existing import controls (#286)
  feat(channels): edit channel details with confirmed saves (#369)
  test(channels): discover the hoverable width for activity corners (#416)
  Fix flaky WebKit menu focus browser test (#409)
  Test Goose connections and fix Pi test false failures (#383)
  feat: open threads with verified newest-first windows (#154)
  Add agent conversation context selection (#382)
  test: keep behavioral coverage without cosmetic matrices (#410)
  Fix reading position and composer caret on channel return (#411)
  fix(channels): prevent clipped activity rows and remove separators (#377)
  ci: publish signed macOS updater artifacts in prereleases (#387)
  feat(messages): add jump to latest controls (#374)
  Align reply summaries with message content (#408)
  Add centered thinking pills to agent avatars (#351)
  Keep focus where the user moved it when a menu finishes closing (#355)
  Browse legacy identities without a destination and review text before cloning (#285)
  Show separate identity cards and prevent duplicate imports (#225)
  Polish message and thread spacing, grouping, and typography (#364)
  Remove the Away avatar badge stroke (#395)
  fix(profiles): hide activity on human profiles (#391)
  ...

Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>
Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>
Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>
Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>
* origin/main:
  feat(channels): archive and delete channels from settings (#385)
  feat(updates): add in-app auto-updates with restart toast (#312)
  fix(ui): keep background loading from shifting populated views (#418)
  Improve member and agent identity previews (#412)
  Fix initial emoji autocomplete selection (#419)
  Add community membership settings (#348)
  Keep nested replies compact and place actions above message text (#367)
  Import an exact inventory identity from its selected source with retry (#288)
  ci: add gated macOS preview updater feed promotion (#414)
  Set up incomplete inventory identities through a working Use here dialog (#287)

Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>

# Conflicts:
#	src/app/App.tsx
Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>
Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>
* origin/main:
  Polish top bar and animate contextual sidebar toggle (#360)
  fix(profiles): preserve nonlocal agent identity in profile fallback (#327)
  test(agents): pause the status poll around the failed-Stop checks (#431)
  fix(sidebar): paint channel rows with the scroller contents (#428)

Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>
Signed-off-by: Codex AI Agent <codex@openai.com>
Signed-off-by: Codex AI Agent <codex@openai.com>
Signed-off-by: Codex AI Agent <codex@openai.com>
codex added 7 commits October 1, 2026 17:05
Signed-off-by: Codex AI Agent <codex@openai.com>
Signed-off-by: Codex AI Agent <codex@openai.com>
Signed-off-by: Codex AI Agent <codex@openai.com>
Signed-off-by: Codex AI Agent <codex@openai.com>
Signed-off-by: Codex AI Agent <codex@openai.com>
Signed-off-by: Codex AI Agent <codex@openai.com>
Signed-off-by: Codex AI Agent <codex@openai.com>
@johnmatthewtennant
johnmatthewtennant marked this pull request as ready for review October 2, 2026 17:34
codex added 3 commits October 2, 2026 13:35
Signed-off-by: Codex AI Agent <codex@openai.com>
Signed-off-by: Codex AI Agent <codex@openai.com>
Signed-off-by: Codex AI Agent <codex@openai.com>

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One correctness change is needed: keep the requested editor bound to a stable agent ID through rename/save recovery (inline).

Star Lord’s automated source review via Wes’s account. Head 0fcd2598dec91adfee574b82a2f1d6a29a91a2f4; base 417c9b1fbbdae772cfaeebaf8a8a25528802c936. Reviewed source, supported callers, recovery paths, public description and both screenshots. No PR code, tests, builds or app runs were executed. The current-head CI snapshot reports success for required checks; Windows native validation is skipped. Native persistence and human confirmation of the unified Save flow remain unverified, as disclosed in the description. This is a non-blocking COMMENT, not approval.

Comment thread src/bundled/agents/AgentUpdateReview.tsx
codex added 2 commits October 2, 2026 14:16
Signed-off-by: Codex AI Agent <codex@openai.com>
Signed-off-by: Codex AI Agent <codex@openai.com>

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No additional changes requested. The retained native ID addresses the previous rename/restart-recovery finding, preserves identity/community checks, and has mounted-parent regression coverage; I found no fix-introduced defect in this follow-up.

Star Lord automated source review via Wes’s account — head 33d49ba9583c69e357def91342018eb151ab95fb, base 417c9b1fbbdae772cfaeebaf8a8a25528802c936. No code or tests executed: CI was still in progress at the single snapshot (Windows validation skipped), and native persistence, browser focus behavior, and human acceptance remain unverified.

Signed-off-by: Codex AI Agent <codex@openai.com>

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No additional changes requested. The two-file follow-up preserves the selected native ID across roster Retry while rechecking membership and retaining identity/community checks; the mounted-parent regression covers reopening the renamed agent and subsequent save recovery.

Star Lord automated source review via Wes’s account — head 847a5b5acf32dfacbe1690e639a762de2afc46fe, base 417c9b1fbbdae772cfaeebaf8a8a25528802c936. Source-only follow-up to the previous review; no code or tests executed. CI remained in progress at the single snapshot, Windows validation was skipped, and native persistence, browser focus behavior, and human acceptance remain unverified.

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One remaining correctness blocker before approval: preserve the active review through transient membership revalidation (inline). The earlier stable-ID rename finding is addressed.

Reviewed head 847a5b5acf32dfacbe1690e639a762de2afc46fe against base 417c9b1fbbdae772cfaeebaf8a8a25528802c936, including observer authorization, roster evidence, save/retry integration, the existing review, and public text/media. An independent source review confirmed the recovery finding. Current CI: 21 successful checks, Windows native validation skipped. No local tests or native app run were performed; native persistence and final human acceptance remain unverified.

Exit criterion: retain the owner's draft and save/recovery state while membership is temporarily unconfirmed, block writes until reauthorized, and cover that lifecycle with a mounted-parent regression.

Carl, an automated reviewer, commenting via Wes’s GitHub account.

Comment thread src/bundled/agents/AgentUpdateReview.tsx Outdated
codex added 2 commits October 2, 2026 15:38
Signed-off-by: Codex AI Agent <codex@openai.com>
Signed-off-by: Codex AI Agent <codex@openai.com>

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No additional changes requested in this follow-up. The retained editor preserves owner edits and in-flight Save/restart-recovery state during membership revalidation, while session/account replacement retires private state; the added mounted regression cases target those distinctions.

Star Lord automated source review via Wes. Head 1a472140116d0e3b6885ffee5fd05987150955e8; base 417c9b1fbbdae772cfaeebaf8a8a25528802c936. Source-only: no tests or app execution; native persistence, real-browser focus/retry behavior, and human acceptance remain unverified.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants