Skip to content

feat(db): hold a run's manifest digest outside the run - #14

Merged
dibenkobit merged 1 commit into
mainfrom
feat/manifest-digest-anchor
Aug 7, 2026
Merged

dibenkobit merged 1 commit into
mainfrom
feat/manifest-digest-anchor

Conversation

@dibenkobit

@dibenkobit dibenkobit commented Aug 7, 2026 •

Copy link
Copy Markdown
Member

What Changed

agent_runs gains a nullable manifest_sha256, filled from the digest the harness already computes when it finishes writing a run manifest. One additive migration, 0001.

manifest_sha256 is also added to AgentRunSchema, validated as 64 lowercase hex — an anchor that is present but malformed is worse than one that is absent.

The comment on manifest_path is corrected in the same change. It claimed the path led to "this session's full transcript", which was not true of a stdout capture and is the only line in the codebase that said so.

Why

A run manifest names every artifact with its digest. The manifest sits in <agent cwd>/.openlab-artifacts/run-<uuid>/, inside the working directory of an agent that runs with --dangerously-skip-permissions, and the lab kept only the path to it.

So the record attested to nothing. Whatever could alter an artifact could restate its digest in the same breath, and nothing outside that directory disagreed. Not a threat model about attackers so much as ordinary agent behaviour: an agent tidying its own workspace is enough.

One value, held where the directory it describes cannot reach it, is what makes the rest of the chain mean something. Everything else was already there.

Verification

The upgrade path is the risk in a migration, so it was exercised rather than reasoned about — a database built at the released schema, seeded with an investigation and an agent run, then migrated:

released schema: seeded a run
after upgrade: [["run-1","abc"]]

The existing row survives and the column takes a value. The release build copies packages/db/migrations recursively, so 0001 ships with no change to the packaging.

The projection test now asserts both the path and the digest reach SQLite, so a value that stopped at the snapshot would fail it.

pnpm check (lint, typecheck, 9 workspaces of tests, build) passes.

Independent of #12 and #13; can go in any order.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included screenshots for any UI changes, with a before only where one existed — no UI changes; the column is not rendered
  • I included a video for animation/interaction changes — not applicable

Claude Opus 5 (1M context) via Claude Code.

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith with what you need. Autofix is disabled.

Note

Store manifest SHA-256 digest on agent run records

  • Adds a manifest_sha256 column to the agent_runs table via a new migration (0001_spooky_shocker.sql) and updates the ORM schema and snapshot projection to read/write it.
  • Extends AgentRunOutcome with a manifestSha256 field and passes it through finishAgentRun so successful runs persist the digest alongside the manifest path.
  • Adds an optional manifest_sha256 field to AgentRunSchema with a 64-character lowercase hex validation rule.

Macroscope summarized 7c77e2f.

A run manifest names every artifact with its digest, and the manifest sat
alone in a directory inside the agent's own working directory, which the
agent runs unrestricted in. Nothing outside that directory attested to
any of it: whatever could alter an artifact could restate its digest in
the same breath, and the lab kept only the path.

The manifest's own digest now lands in the lab database beside the path.
It is one value an operator can hold a run's account of itself against,
and it is not in the directory it describes.

The column is nullable and additive, so a lab from before this keeps its
rows and fills the column on the next run it finishes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@vercel

vercel Bot commented Aug 7, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
openlab-landing Ready Ready Preview Aug 7, 2026 3:07pm

Request Review

@dibenkobit
dibenkobit merged commit fbbdfbe into main Aug 7, 2026
7 checks passed

This branch was successfully deployed

1 active deployment
Preview — 7c77e2f6 Deployed Aug 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant