fix: make two processes sharing one mailbox visible (#161) - #173
Merged
Merged
Conversation
A subagent inherits its parent's git identity and process tree, so it derives the parent's alias. Because reads consume, one `agentcomm inbox` from a subagent drains the mailbox its parent is waiting on — silently, since the alias looks exactly right. One did; it noticed only because the CLI echoed the parent's name and the agent recognised it. The smaller version of the same thing: a subagent's `register --status` overwrote the parent's line on the shared roster. Identity stays per-session on purpose — a session IS a mailbox, and the sticky fingerprint that fixed alias drift depends on it. What was missing is visibility, so while a process acts as an alias it now leaves a local lease behind, and anything destructive another live process does to that mailbox says so: a consuming read warns that it is taking mail addressed to a live holder and names the remedy (--as <alias>-<role>), and a status write warns whose line it is replacing. Heartbeats, peeks and queue claims lease quietly — a shared queue is meant to have many claimers. Leases are local files, because the case they cover — two processes of one agent session on one machine — is exactly the local case. A lease from a dead process is ignored and cleaned up, never inherited.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #161. (Supersedes #169, auto-closed by GitHub when its base branch merged; same commit, rebased onto
main.)A subagent inherits its parent's git identity and process tree, so it derives the parent's alias — and because reads consume, one
agentcomm inboxfrom a subagent drains the mailbox its parent is waiting on. Silently, because the alias looks right.The one suggestion not taken, and why
The issue proposes deriving the alias from something per-process (pid, spawn nonce). That would break the model deliberately: a session is a mailbox, and the sticky per-session fingerprint is exactly what fixed alias drift in #157 — making the name per-process would re-split every mailbox the moment a wrapper process appears. What was actually missing is visibility, which is the issue's own second and third suggestions.
What changed
src/session.ts— mailbox leases. While a process acts as an alias it leaveslease-<alias>-<pid>.jsonin the state dir; a lease whose pid is dead (or older than 30 min) is ignored and removed, never inherited. Local files, because two processes of one agent session on one machine is exactly the local case.src/cli.ts—guardMailboxclassifies each command: a consuming read (inbox,ack) warns that it is taking mail addressed to a live holder, names what that process is doing, and gives the remedy (--as <alias>-<role>); a status write warns whose roster line it replaces; heartbeats,peek,waitandclaimlease quietly —waitbecause holding the mailbox is the whole point of a listener,claimbecause a shared queue is meant to have many claimers.Tests
test/mailbox-lease.e2e.test.ts: a real second process holds the alias while a consuming read runs (warns, with the remedy), a solo read stays silent and cleans up its lease, a status write reports whose line it takes while a heartbeat does not, and a dead process's lease is ignored and removed.