Skip to content

Native common-auth migration and host integration - #289

Draft
antauth-alfonso[bot] wants to merge 176 commits into
mainfrom
work/common-auth-native-cutover
Draft

antauth-alfonso[bot] wants to merge 176 commits into
mainfrom
work/common-auth-native-cutover

Conversation

@antauth-alfonso

@antauth-alfonso antauth-alfonso Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Consolidates the native credential pool migration, offline custody activation, and unified Claude menu on one integration branch. Core, OpenCode and Pi integration is under verification; OpenCode 2 placeholder ownership and remaining fixture corrections are in progress. CI is the integration gate. This draft does not authorize a release, deployment or live credential migration.


Summary by cubic

Consolidates the native common-auth cutover on one integration branch: credential custody, refresh, quota, routing, host-auth writes, and menu/UI actions move onto the native account/vault runtime, with Pi authority and the shared /claude menu on that same runtime. Adds an offline migration controller using a v3 forward-only journal with prepared proofs and guarded publication, plus an OpenCode 2 native HTTP adapter; live credential migration is not authorized. Also adds Claude Haiku 5.5 support across Core, OpenCode, and Pi.

Migration and host integration

  • Adopts verified common-auth 0.11.7 and Claustrum 0.6.2, adding the native account/vault runtime, custody/roster/validation, local OAuth credential service, refresh coordinator, quota codec, typed menu model/executor, and an OpenCode 2 Anthropic HTTP adapter.
  • Integrates guarded host-auth writes with OAuth redirect refusal and supervised-snapshot fencing, plus a curated public Core API for the captured migration journal, checked Claude menu renderer, and bundled command protocol types.
  • Adds pinned mutation-guard CI with a replayable guard catalogue, type-closure checks, and native packaging gates; a new workflow runs the mutation catalogue on PRs, pushes, and nightly.

Model support

  • Adds Claude Haiku 5.5 (claude-haiku-5-5) with 1M context, 128K output, native adaptive effort, and fivefold long-context pricing above 100K input tokens.
  • Preserves strict credential validation, offline migration source seams, and byte-exact migration proofs; live credential migration remains unauthorized.

This does not authorize a release, deployment, or live credential migration; CI and mutation guards remain integration gates.

Written for commit 6fa519e. Summary will update on new commits.

View guided diff Turn on auto-fix

ualtinok and others added 30 commits October 2, 2026 10:17
Forward the published store seams without relaxing credential stamps or enabling offline quota pulls. Add the sibling custody roster path and overlap coverage. Package the complete published declaration dependency graph with its license, keep common-auth dev-only, and declare/externalize the existing jsonc-parser version.

Verified Core 374 tests, six script tests, production-only packed consumer tsc (329 prefix-local files) and Node runtime assertions, Core/workspace/script types, scoped Biome and lock consistency. Strict-stamp and declaration-fence mutations each reddened exactly their named regression while a companion test passed; both restored before final gates. The existing strict-mode test retains its claim and now exercises every forwarded seam. Parent Sidekick comment review approved the exact ten-file staged diff.
Persist account-bound runtime observations separately from credentials and settings under the native-runtime lease, with closed parsing, owner-only atomic writes and before/after replacement seams. Preserve quota window clocks, scoped ownership, raw percentages, provenance and monetary metadata through the published 0.9.0 QuotaMap with a closed Anthropic extension.

Add full-field fixtures, captured provider poll/header vectors, concurrency/crash/clear-fence tests and three restored mutation controls. Parent-provided Sidekick comment review sk_395353493e39424e9c62b7373ec49e0d approved all four files. Core: 393 tests pass; focused: 23 tests pass; types and scoped Biome pass. Root lint is blocked by read-only nested .cortexkit Biome configurations.
Clean a staging name only after successful exclusive creation, and relinquish it after rename. Check effective rather than real UID before and after opening owner-only runtime storage.

Validate credential-derived fields using established 16-hex tokenFingerprint, 64-hex hashRefreshToken and bound vault-account UUID forms. Reject profileToken values because the pinned source has no supported writer or established identifier form; retain the recognized key and expose its unsupported status in the type. Update the original roundtrip fixture to real helper-produced metadata rather than invented strings, preserve the demonstrated legacy Prime fingerprint, and add seven targeted regression tests.

Pinned Bun 1.3.14: focused 30/30, rebuilt Core 400/400, workspace types and scoped Biome pass. Exact parent probe: four bearer acceptances false, collision sentinel preserved, foreign effective UID refused, HTTP 0. Three restored mutation controls redden their named stage/metadata/euid tests. Fresh parent Sidekick comment review sk_de2c4e4103d640159f3b49cfc5d8265d approved this exact staged revision. Original commit 2c43125 remains unchanged.
Verify the published SDK's provider mapping wire fields and preserve scoped account/version receipts, enrollment generation fences, and secret redaction. The existing inventory assertion now includes providerIds and authMethod because the producer decodes those new fields; no prior assertion is removed or weakened.

Keep common-auth locked at accepted 0.9.0. Required readonly providerIds fixture additions in five downstream test files were explicitly authorized by the parent. Parent pre-commit Sidekick sk_f2ec744eb7c7424e856dd28afc1dc023 cleared changed comments; the parent additionally inspected the two literal scoped-runtime fixture additions omitted from that named review list.
Use the strict published pool facade with process-wide binding-keyed jobs, account provider locks and callback-end identity handoff. Preserve consumed rotations across cancellation, bootstrap failure and duplicate disablement; handle quarantine exhaustively and re-read each requesting row before exposing access.

Require caller-owned restriction reads and awaited native reconciliation. Cover real store concurrency, adoption, quarantine, cancellation and bounded classified retries with 36 tests and three restored isolated negative controls. Parent Sidekick comment re-review sk_0105f8597d0b4bdc9d0a1e247a8f94ee accepted the comments and authorized this local commit; integration review remains separate.
Classify OAuth 429 failures as transient for native reconciliation, preserving status and Retry-After, but explicitly exclude 429 from the coordinator's immediate physical retry loop. Keep maxRetries:0 and one endpoint call.

Correct the existing rate-limit expectation: permanent metadata incorrectly conflated deferred native backoff with immediate endpoint retryability. Both rate-limit tests failed before the source fix. Add real-store coverage for exact hook metadata and later same-token backoff refusal; three isolated negative controls prove classification, retry exclusion and restriction enforcement. Invalid-grant, replacement and consumed-successor behavior is unchanged.

Core build and all 411 tests pass; workspace types pass with pinned Bun 1.3.14 and Node 24.16.0. No comments changed, as checked against the preceding commit; no fresh comment gate is required for this correction.
Export a pure migration serializer that uses the existing normalizers without accepting their defaults, drops, clamping or discarded fields. Preserve clocks, affinity and deficit bytes; remap only explicit caller-proven account bindings and safely retain dictionary keys. Offline proof, journal and locked publication remain caller obligations; routing policy and persistence are unchanged.

Add 60 focused tests, including causal real-router deficit attribution and three independently reddened/restored negative controls. Verified pinned Bun 1.3.14, Node 24.16.0, workspace build/types, full Core 465 tests, OpenCode sticky 28 tests and Pi routing/commands 50 tests. Parent pre-commit Sidekick comment review sk_998f6cfae10449e88d14d396fc84b58b approved the exact two-file change.
Inspect parsed OpenCode/Pi Anthropic entries with complete canonical SHA-256 digests, explicit host schemas, exact activation recognition and broader placeholder refusal. Add presence-only supervised snapshot detection with fixed token-free refusals; return only frozen kind/digest records. Path safety, consent, physical writes and integration remain caller obligations.

Verified under Bun 1.3.14 and Node 24.16.0: 22 codec tests, 487 Core tests, workspace build/types, six packaging tests including isolated consumer types/Node runtime, declaration closure and Pi dist import closure. Independently pinned 14 canonical byte/hash fixtures. Extra-property omission and snapshot truthiness mutants each reddened only the intended named test with three controls still green; both restored before all final gates. Parent pre-commit comment review approved all eight comments unchanged.
Require explicit source digests and canonical path captures, and record host/routing expectations atomically at verified. Refuse v1 journals and preserve prepared expectations on retries.

Migration and crash fixtures now prepare expectations before activation while retaining their authority and ownership assertions. Validate native Windows and POSIX path syntax, and defer fixture cleanup until complete bodies and registered detached work settle.

Verification passes 521 Core tests, 6 packaging tests, workspace types/lock/build and declaration/import closure. Earlier full-suite delays remain unattributed; the premature-cleanup race is independently proven and corrected.
Define closed positive local evidence tied to its own known binding and exact OAuth lineage/access/expiry/refresh stamp. Decode the optional runtime proof without adding serving or recovery behavior. Preserve runtime v1 and existing transition fences.

Use the shared body-draining test lifetime helper byte-identically from fd2f562. Add proof-schema, exact-match, writer and body-drain regression tests; three source mutation controls each fail only their named assertion and restore exactly.

Verified with pinned Bun 1.3.14: 12 focused tests, 544 Core tests, 6 packaging tests, native declaration closure, workspace types/lock and five-file Biome check. Fresh complete-delta Sidekick review sk_47dddc59021f4dde95d8d980aac5e1bb and explicit parent local-commit approval received.
Add optional validationRetry with the approved closed credential subject, safe ordered timestamps and binding equality to the enclosing known local entry. Preserve runtime version 1, the sole credentialValidation proof slot, and existing writer transitions.

Cover round trips, closed nested keys, malformed subjects, strict refresh stamp presence, caller isolation, redaction, metadata/proof preservation and unchanged fences. Binding-match and extra-key mutations each fail only their named control; restore exact bytes before verification.

Bun 1.3.14: 13 focused, 591 full Core and six packaging tests passed; workspace types passed. Parent Sidekick approved revised reader-oriented comments. Schema validation alone cannot verify the actual pool row is OAuth; guarded publication remains a separate obligation.
OAIAUTH confirmed that an old-token-only legacy profile must not be adopted by a different credential. Cover fresh lookup failure without inherited tier, retain zero-fetch reuse for the exact account UUID, and require exact per-account hydration counts without assuming request order.
Distinguish saved, refused and I/O-failed publication. Recheck exact local credential or vault record provenance before displaying fetched tiers, including after storage failure. Classify lost writer ownership as refusal. Cover actual rename faults, changed credentials, newer vault receipts, warning-once behavior and the three named mutation controls.
Keep the coordinator's three-attempt budget available after transient failures, while throttling 429 and permanent failures immediately. Retain safe first-request provider diagnostics and match subsequent backoff against the resolved account UUID. Verify exact successor dispatch, native error persistence, no host retry loop and the named early-backoff mutation guard.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants