Repository navigation
feat(db): hold a run's manifest digest outside the run - #14
Merged
Merged
Conversation
A run manifest names every artifact with its digest, and the manifest sat alone in a directory inside the agent's own working directory, which the agent runs unrestricted in. Nothing outside that directory attested to any of it: whatever could alter an artifact could restate its digest in the same breath, and the lab kept only the path. The manifest's own digest now lands in the lab database beside the path. It is one value an operator can hold a run's account of itself against, and it is not in the directory it describes. The column is nullable and additive, so a lab from before this keeps its rows and fills the column on the next run it finishes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What Changed
agent_runsgains a nullablemanifest_sha256, filled from the digest the harness already computes when it finishes writing a run manifest. One additive migration,0001.manifest_sha256is also added toAgentRunSchema, validated as 64 lowercase hex — an anchor that is present but malformed is worse than one that is absent.The comment on
manifest_pathis corrected in the same change. It claimed the path led to "this session's full transcript", which was not true of a stdout capture and is the only line in the codebase that said so.Why
A run manifest names every artifact with its digest. The manifest sits in
<agent cwd>/.openlab-artifacts/run-<uuid>/, inside the working directory of an agent that runs with--dangerously-skip-permissions, and the lab kept only the path to it.So the record attested to nothing. Whatever could alter an artifact could restate its digest in the same breath, and nothing outside that directory disagreed. Not a threat model about attackers so much as ordinary agent behaviour: an agent tidying its own workspace is enough.
One value, held where the directory it describes cannot reach it, is what makes the rest of the chain mean something. Everything else was already there.
Verification
The upgrade path is the risk in a migration, so it was exercised rather than reasoned about — a database built at the released schema, seeded with an investigation and an agent run, then migrated:
The existing row survives and the column takes a value. The release build copies
packages/db/migrationsrecursively, so0001ships with no change to the packaging.The projection test now asserts both the path and the digest reach SQLite, so a value that stopped at the snapshot would fail it.
pnpm check(lint, typecheck, 9 workspaces of tests, build) passes.Independent of #12 and #13; can go in any order.
Checklist
Claude Opus 5 (1M context) via Claude Code.
🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmithwith what you need. Autofix is disabled.Note
Store manifest SHA-256 digest on agent run records
manifest_sha256column to theagent_runstable via a new migration (0001_spooky_shocker.sql) and updates the ORM schema and snapshot projection to read/write it.AgentRunOutcomewith amanifestSha256field and passes it throughfinishAgentRunso successful runs persist the digest alongside the manifest path.manifest_sha256field toAgentRunSchemawith a 64-character lowercase hex validation rule.Macroscope summarized 7c77e2f.