Conversation
Desktop and mobile insert a mention into the message body as literal text
("@Fountain Maintainer !rotate") alongside the p tag, but
is_owner_control_command required content.trim() to equal the command
exactly. So a mentioned command fell through to the agent as a prompt, and
a bare command had no p tag and was dropped — the commands were unreachable
from every product surface (already noted in
docs/welcome-kickoff-silent-failures.md §5).
Match the command when it is the whole content, or when it is the last or
first token with only @name / nostr: mention text on the other side. Content
that continues past the command is still forwarded as an ordinary message.
[Adam Pałka: rebased block#6101 onto main; dropped workflow_attributed_author
(removed on main by block#6311) from the lib.rs conflict and merged the README
paragraph with the thread-scope CLI example added on main.]
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Signed-off-by: Jake Gaylor <jhgaylor@gmail.com>
Signed-off-by: Adam Pałka <adm.palka@gmail.com>
Co-authored-by: Claude Code <noreply@anthropic.com>
The matcher test from the previous commit exercises the helper only, so reverting is_owner_control_command to an exact-content check would still pass. Assert on is_owner_control_command itself for !shutdown, !cancel and !rotate with rendered mention text, and reject events whose p tag names another agent or is missing. Signed-off-by: Adam Pałka <adm.palka@gmail.com> Co-authored-by: Claude Code <noreply@anthropic.com>
The previous commit only prefixed a "Fixed" note, leaving the diagnosis in present tense. Rewrite the entry as resolved and keep the still-current loop-breaker limitation. Signed-off-by: Adam Pałka <adm.palka@gmail.com> Co-authored-by: Claude Code <noreply@anthropic.com>
Desktop qualifies a mention label with the pubkey when two selected mentions share a display name, and one message can address several agents. Both shapes must still match as control commands. Co-authored-by: Claude Code <noreply@anthropic.com> Signed-off-by: Adam Pałka <adm.palka@gmail.com>
The harness now accepts owner control commands whose body carries the rendered mention text, so the composer is a working per-thread fallback until observer controls become thread-aware. Co-authored-by: Claude Code <noreply@anthropic.com> Signed-off-by: Adam Pałka <adm.palka@gmail.com>
🔐 Codex Security Review
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This is #6101 by @jhgaylor rebased onto current
main. #6101 no longer merges cleanly:mainhas since reworked the same area oflib.rs(#6129 and its revert #6311) and the README (thread-scoped sessions, #6732). The fix and the test are his, and so is the commit authorship. I resolved the conflicts, added tests, updated two docs and ran it end to end against a local relay:crates/buzz-acp/src/lib.rs: keptcontrol_command_content_matchesand its test unchanged. Droppedworkflow_attributed_author, which only came along as conflict context. It was removed frommainin Revert "fix(acp): gate relay-signed workflow messages on their attributed author" #6311.owner_control_command_gate_accepts_rendered_mention_for_every_command(separate commit). buzz-acp: accept owner control commands with rendered mention text #6101's test covers the helper only. This one asserts onis_owner_control_commandfor!shutdown,!canceland!rotate, so reverting the gate to an exact-content check fails it (checked). It also rejects aptag for another agent and a missingptag. A second commit adds the two other label shapes Desktop produces to the matcher table:@Name (<pubkey>) !rotate(Desktop qualifies a label this way when two selected mentions share a display name) and@Agent @Other Agent !rotate.docs/welcome-kickoff-silent-failures.md: buzz-acp: accept owner control commands with rendered mention text #6101 prefixed a "Fixed" note to the backlog item but left its diagnosis in present tense. Rewrote it as resolved and kept the still-current "!cancelis not a loop breaker" note (separate commit).desktop/src/features/agents/AGENTS.md: the "Channel-only runtime controls" section told contributors not to suggest@Agent !cancel, because the harness required the exact body. It now says the owner can reply in the target thread with@Agent !cancelor!rotate, and keeps the CLI example.crates/buzz-acp/README.md: replaced the "body must be exactly!rotate… an inline@Namedoes not match" paragraph with buzz-acp: accept owner control commands with rendered mention text #6101's mention-tolerant wording. Kept the CLI--reply-to … --mention … --content '!cancel'example frommain, since a bare command with a separateptag still matches and is the way to target a thread from the CLI.Behaviour (unchanged from #6101):
@Agent !rotate,!rotate @Agentandnostr:npub… !rotatefrom the owner, with the agent'sptag, are consumed as control commands. Because the harness does not know the agent's rendered (possibly multi-word) display name, any prefix starting with@ornostr:counts as mention text, so@Agent please !rotatealso matches. Content that does not start with a mention or continues past the command (please !rotate,!rotate now) is still forwarded as an ordinary message. The owner,p-tag and kind:9 checks are untouched. Under thethreadsession policy the command still resolves to the thread it is posted in.@jhgaylor, if you would rather rebase #6101 yourself, say so and I'll close this.
Related issue
Fixes #6014, fixes #6051. Supersedes #6101.
Testing
cargo test -p buzz-acp: lib 943 passed, integration 9 passed, 0 failed (run with noBUZZ_ACP_*variables in the environment, because twoconfig::testsdefault assertions read them)cargo fmt -p buzz-acp -- --check,cargo clippy -p buzz-acp --all-targets -- -D warningsEnd to end: local relay (
scripts/start-isolated-test-relay.shstack),buzz-acpbuilt from this branch and frommain(77729ab), and a stub ACP agent that logs everysession/newandsession/prompt. Test events were published with the shape Desktop produces (content@Mock Agent !rotate, tagsh,p,["mention", <agent>, "agent-address"], and["e", <root>, "", "reply"]for thread replies). They were not typed in the Desktop UI.main@Mock Agent !rotate, then a message@Mock Agent !rotatesession/cancelfor the running turn; next message opens a new session@Mock Agent !cancelmid-turnsession/cancel, the turn stops@Mock Agent !rotate@Mock Agent !rotate now!rotatewithptagthreadpolicy:@Mock Agent !rotatereplied in thread AUnchanged from
main, for reviewers: a turn cancelled by any control signal (including!canceland Desktop's Stop) invalidates the session, so the next message after!cancelalso opens a new session.This PR was prepared with an AI coding agent. I reviewed the change and take responsibility for it.
🤖 Generated with Claude Code