Skip to content

Community Mesh shared compute and agent integration - #580

Draft
micspiral wants to merge 73 commits into
mainfrom
jimmy/mesh-share-wip
Draft

micspiral wants to merge 73 commits into
mainfrom
jimmy/mesh-share-wip

Conversation

@micspiral

@micspiral micspiral commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Mesh shared compute plugin

Ports community-scoped Mesh shared compute from classic block/buzz into the new Buzz app as an opt-in bundled plugin (native mesh feature, Mesh SDK v0.78.1). Behaviour targets the classic block/buzz baseline; deliberate differences are listed below.

Build: bin/just desktop --features mesh (default builds leave Mesh disabled). Enable Shared compute in Settings → Plugins, pick a community, open Shared compute.

What it does

  • Share this machine switch. Auto picks the model for the hardware (e.g. Qwen 27B UD-Q4_K_M on a 128 GB Mac), with Reset to Auto; manual model picker under Advanced.
  • Consuming: agents use Buzz shared compute → Auto or a community model; a client node starts on demand; readiness is decided by a real chat request (classic behaviour).
  • Community summary: contributors, shared memory, models available; readable model names come from Mesh's own /api/models.
  • Host-owned discovery via Buzz-signed status notes; verified roster/owner/endpoint bindings; allowlisted native commands.

Matches classic block/buzz

Model ladder; chat-decides readiness; 4096 output / 660 s timeout defaults (user values win); enrollment published only while Mesh runs (first use); immediate stopped advert on Share Off; consumers re-armed after Share Off; checksum-only native artifact trust (unchanged port).

Deliberate differences

  • Thinking off by default for Mesh agents (user-overridable).
  • Failed start is fail-closed: Off clears consent; On is blocked until restart.
  • No separate Disconnect button.
  • Community isolation and revocation are enforced (navigation keeps the bound node; delayed Off fenced to its lease).

Included from #689

  • Sharing-status glyph and heading, model-fit labels, and grouped community device inventory.
  • Four community-agent presets: Emoji maker, Media converter, Thread summarizer, and Translator. These prefill the existing owner-reviewed create dialog; nothing is auto-created. Media examples require host ffmpeg and an authenticated Buzz CLI.
  • Exclude this machine's lingering serving advertisement when re-arming a consumer after Share Off; other devices can still be joined.
  • Allow Share On to replace a connecting consumer. A stuck join may delay the switch by roughly two minutes while teardown completes.
  • Publish chip/GPU label and rated memory only while serving, making community capacity visible without publishing hostnames or asset tags. Community members can see these hardware facts.

8 October review fixes / main integration

  • Integrated upstream main 98bc1951 without dropping its harness configuration policy.
  • Fixed all six new P2 findings: viewer-revocation teardown survives agent-cleanup errors; retained admission uses fresh routing and recovers through optional-discovery failure; first community selection preserves queued restores while revoked bindings still require retirement; duplicate queued/in-flight joins coalesce; partial Arguments JSON cannot throw from picker render and irrelevant draft edits do not refetch; unsupported hosts show neither a compute binding nor native inventory.
  • Dario independently reviewed the implementation (eb9bddd2) and the host-argument cleanup (c3bcf380), no remaining source blockers. Final validation sign-off is pending the final head hosted checks.
  • Local full frontend: 570 files / 8,332 tests passed; TypeScript passed. Full Mesh package: 56 passed / one opt-in live test ignored. Full Mesh-enabled native package: 377 passed / 8 ignored with two test threads, repeated after host-argument cleanup.
  • Default-parallel native run had five timing-sensitive host_command failures (aborting descendants, aborting CLI process, env shebang, exact args, large output). Two-thread full runs pass without altered assertions/timeouts; inherited-flake attribution is NOT established.
  • Chromium + WebKit: all 8 sharing/model-picker/unsupported-host browser checks passed. Browser cases added/removed: zero; the existing unsupported-browser assertion now requires absent native inventory. First run failed the obsolete inventory expectation in both engines; rerun passes after changing it to the new contract. New picker and join/restore/recovery matrices live in colocated Vitest/Rust tests, not duplicated browser journeys.
  • Live multi-device revocation/recovery, native GUI/packaged launch and human acceptance of this head remain outstanding. Preparing an isolated preview bundle; no unattended real-identity launch because its Keychain path can prompt. Existing Buzz and Mesh instances remain untouched.
  • Final local Mesh-enabled workspace/all-target Clippy passes with -D warnings at 7de6dcdd; native package also passes there (377 / 8 ignored). Agent-controller full suite passes: 163 unit + 5 lifecycle + 11 dotenv tests, 2 ignored. Final head 7de6dcdd is pushed and remote-verified. DCO passes; final-head CI is pending. Mandatory push hooks passed. Earlier green CI does not certify this new integration. Keep draft until acceptance/review gates hold. No buzz-review-completed attestation.

Earlier verification at 6208236

  • CI: all required checks pass (Windows skipped).
  • Local: native (mesh) 316 passed / 8 ignored, mesh-compute 53, agent-controller 149+5+11, Vitest 7,834, tsc, Biome, Clippy -D warnings (default and mesh), Playwright mesh-share + agent-models (Chromium/WebKit).
  • Accepted live by Mic on a packaged a255373 build: consuming a peer's model with sharing off (agent replied), Share On serving 27B, agent served locally on 27B.

Known limitations / follow-ups

  • No dead-ingress watchdog re-arm (classic has one).
  • Off → consumer re-arm: fake orchestration tests plus a live observation of the node returning to client mode; an agent turn afterwards was not verified.
  • Same-second restart can tie status-note timestamps; relay acceptance of the serving advert not independently verified.
  • Not ported from the Thomas prototype: max-memory limit and map. Share Off is available during server startup, subject to native teardown completing.
  • Packaged quit/relaunch, multi-community lifecycle acceptance, and cross-platform packaging are not newly established at the integrated head. Earlier Polish community shared compute and agent setup #689 local browser/design failures are documented in that PR; hosted green CI is not a claim that those local failures were diagnosed.
  • Marked ready for review at Mic’s request; this is not merge approval or a claim that every acceptance gap above is closed. No buzz-review-completed attestation is made.

Originating Buzz channel: 53a55c4d-2b96-40b1-a6d4-8de855b2a328 (buzz-mesh-plugin).

Jimmy added 30 commits October 1, 2026 12:22
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
…tore

Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Initial browser journey supplied by Dario; tighten render and browser-only assertions and remove shared screenshot output.

Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
…ompt"

This reverts commit 8b6260e.

Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Dario added 7 commits October 6, 2026 16:49
…fixture lifetime

Shorten advertised ids by characters, not bytes. Remove the speculative cold local-inventory scan; keep the running-node mapping and the honest fallback. Keep the probe test fixture alive until explicit shutdown after the awaited probe.

Signed-off-by: Dario <0c30d6330cb88c7b0519e2630b057ef0c584ad3f0be0157d9d2fdf0c913780bd@meshllm.communities.buzz.xyz>
Publish a stopped status immediately after Share Off, as legacy mesh_stop_node did, instead of waiting for the next heartbeat. Treat the 660 s LLM timeout as a default so an explicit agent value is preserved, matching legacy relay_mesh.

Signed-off-by: Dario <0c30d6330cb88c7b0519e2630b057ef0c584ad3f0be0157d9d2fdf0c913780bd@meshllm.communities.buzz.xyz>
Follow the donor's registered Compute page: the sharing controls sit in one bordered card, the community section shows contributor, shared-memory and model counts, and the page has a single status line and a single Refresh (which also rereads the community list). The share status line now also reports the consumer node (connecting/connected) so the separate global status and node-running notes are removed.

Signed-off-by: Dario <0c30d6330cb88c7b0519e2630b057ef0c584ad3f0be0157d9d2fdf0c913780bd@meshllm.communities.buzz.xyz>
…emory total

After a confirmed Share Off, start the single slot as a client when running
Mesh agents need it (legacy coordinator re-arm), keeping saved sharing Off.
Serialize periodic publication and the immediate stopped note so an
in-flight serving snapshot cannot be signed after the withdrawal.
Count shared memory once per member device and omit the total when any
device identity or capacity is unknown. Add opaque, timestamped
mesh-startup stage logs (no prompts, keys, config or addresses).

Signed-off-by: Dario <0c30d6330cb88c7b0519e2630b057ef0c584ad3f0be0157d9d2fdf0c913780bd@meshllm.communities.buzz.xyz>
… startup logs

Stamp each status note strictly newer than the last (same-second ties would
otherwise let a serving note win the replaceable address). Extract the
confirmed-Off plan (withdraw, then re-arm one client only for running Mesh
consumers and a current lease) with tests, plus a held-serving-publication
ordering test. Startup stage logs now share an opaque attempt id with
wall-clock timestamps from restore/agent/share entry through discovery,
SDK start and first probe, including failure exits.

Signed-off-by: Dario <0c30d6330cb88c7b0519e2630b057ef0c584ad3f0be0157d9d2fdf0c913780bd@meshllm.communities.buzz.xyz>
Share Off now runs through one finish_off(OffEffects) path: confirmed stop,
withdraw, then one client start for running Mesh consumers. Tests drive it
with a recording fake (consumers, none, failed stop, retired lease, re-arm
failure). A re-arm failure keeps Off successful but is reported on the
existing settings-error surface instead of only being logged.
Status notes now wait for a later real second instead of future-dating,
so a restarted process is never outranked. Startup logs drop the global
attempt correlation and record per-stage timestamps and durations.

Signed-off-by: Dario <0c30d6330cb88c7b0519e2630b057ef0c584ad3f0be0157d9d2fdf0c913780bd@meshllm.communities.buzz.xyz>
Validate the captured lease inside the acquired preparing guard before stopping, so a delayed Off cannot stop a replacement community's node; a retired Off then withdraws, restarts and reports nothing. Fence the re-arm error write to the original lease. Narrow the created_at comment: no future-dating, but same-second restarts can still tie.

Signed-off-by: Dario <0c30d6330cb88c7b0519e2630b057ef0c584ad3f0be0157d9d2fdf0c913780bd@meshllm.communities.buzz.xyz>
@micspiral

micspiral commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator Author

Checkpoint a255373 (pushed; still draft)

Accepted live by Mic on the packaged a255373 build: consuming remote compute (sharing Off → client node → agent reply on a peer's model); Share On → 27B UD-Q4_K_M serving; an agent pinned to the local 27B served locally.

Review findings → repairs: P1 community isolation (navigation keeps the bound node; explicit replacement stops consumers first; delayed Off is fenced to its lease). P1 revocation (verified removals apply independently of status; stale lists rejected). P1 dead peer (join errors keep the node Ready). P2 startup recovery (pre-node failures can retry; unknown failures fenced; Off can clear consent without a lease). P2 standalone config (isolated config). P2 heartbeat starvation (B first; immediate stopped note, serialized, never future-dated). P2 unsupported builds (availability checked first). Browser assertions updated.

Also: legacy readiness (a chat request decides, no catalog/context gate); legacy 4096 output and 660 s timeout defaults with user values winning; legacy enrollment-on-use; consumer re-arm after Share Off; readable names for hash-only adverts; compact sharing card and community summary.

Known limitations: no dead-ingress watchdog re-arm (classic has one); same-second restart ties for status notes; relay acceptance of the serving advert unverified; Off→consumer re-arm: fake orchestration tests plus a live observation of the node returning to client mode; an agent turn afterwards was not verified.

@michaelneale

Copy link
Copy Markdown

@wesbillman addressed feedback: won't be touching things which are the same as the baseline block/buzz settings app if not already done, shooting for parity as a plugin (but a bit nicer) - so ensure agents don't relitigate legacy questions. (and most likely they will bring things up that I would have told mine not to do).

Dario and others added 2 commits October 6, 2026 18:47
The page no longer invokes mesh_compute_start (Disconnect removed); it now invokes mesh_compute_disarm, which is declared and allowed.

Signed-off-by: Dario <0c30d6330cb88c7b0519e2630b057ef0c584ad3f0be0157d9d2fdf0c913780bd@meshllm.communities.buzz.xyz>
Signed-off-by: Alessandro Joabar <sandro@squareup.com>
Resolve conflicts with pairing plugin (workspace member, deps, commands,
bundled registry), new harness icons, and preset agent settings (preset
first, then shared compute picker, then default model picker).

Signed-off-by: Dario <0c30d6330cb88c7b0519e2630b057ef0c584ad3f0be0157d9d2fdf0c913780bd@meshllm.communities.buzz.xyz>
@micspiral micspiral changed the title WIP: community Mesh shared compute and agent integration Community Mesh shared compute and agent integration Oct 7, 2026
@micspiral
micspiral marked this pull request as ready for review October 7, 2026 02:58
@micspiral
micspiral requested review from a team and comp615 as code owners October 7, 2026 02:58

@wesbillman wesbillman left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes needed: six P2 findings inline cover revocation teardown, membership-change recovery, saved-agent restore, duplicate peer joins, editor validation and unsupported-build UI. One keyboard-focus follow-up is marked optional. Scope follows Mic’s parity decision: unchanged classic behavior is out of scope. These findings concern the port’s new lifecycle/restore wiring, join queue and plugin/editor integration—not legacy consent, artifact trust, readiness, accepted SDK latency or documented recovery limitations.

Public-material cleanup: remove the internal originating-channel identifier from this public PR description.

Star Lord’s automated source review via Wes’s account. Head def6be269d29cae731cf1b81208de6315c13a075; base 5aeeda7ecd723eef84212c4578611f59412d6af8. Source-only; no builds, tests, app runs or live-node probing. Hosted snapshot: 21 checks passed, Windows skipped. Earlier packaged acceptance predates this integrated head. This COMMENT is not approval.

host.lease.revoke(&lease)?;
app.state::<crate::agents::AgentHost>()
.stop_mesh_consumers()
.await?;

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Stop compute even when consumer cleanup returns an error. Revoking the lease here and then propagating stop_mesh_consumers() failure skips node shutdown. Later reconciliation returns immediately because there is no lease (lines 52–54), leaving the old runtime/admission alive. This does not require an unkillable process: Controller::stop can return a private-directory cleanup error after confirmed process exit (runtime.rs:1105–1112). Signal node stop before fallible consumer cleanup, then always reconcile shutdown and clear admission while preserving the error/uncertain-shutdown fence. Add native orchestration coverage for membership removal with a consumer-cleanup error.

.await
.map_err(|e| e.to_string())?;
// Restart only with retained admission; failed status discovery cannot widen it.
let targets = availability_from_events(retained_records.clone()).serve_targets;

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Refresh routing evidence when rebuilding retained admission. retained_records contains admission-time advertisements, not the fresh heartbeats read on later ticks. Once those notes are over 120 seconds old, availability_from_events removes all their targets. On a consumer-only node, removing any admitted member therefore stops the healthy runtime and makes start_with_evidence reject the empty target set—even when retained servers are still advertising. The coordinator then skips Stopped, leaving existing agents without an endpoint. Keep the retained-owner admission restriction, but obtain fresh verified routing evidence for retained owners after stopping; surface restart failure with retry guidance. Cover an aged admission snapshot with a still-live retained server.

Comment thread src-tauri/src/mesh_compute.rs Outdated
host.lease.clear();
let stopped = async {
app.state::<crate::agents::AgentHost>()
.stop_mesh_consumers()

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Preserve queued startup restores on the first community selection. With no existing lease, changing is true and this call removes every Mesh agent from host.queued and inserts it into host.acted (agents.rs:818–838). The later restore_mesh consequently has nothing to resume. If selection reaches initialization first, the FIFO admission lock makes the cancellation run before restore, whose acted filter also skips these agents. This breaks the documented start-on-launch contract. Distinguish first binding from retirement of an existing binding: preserve not-yet-started restores while retaining cancellation/consumer-stop fences on actual replacement. Test the real select → restore path; the existing regression calls restore_mesh directly.

&& !target_is_visible(target.endpoint_id.as_deref(), &peers)
}) {
host.lease.community(&lease)?;
if let Err(error) = host.lifecycle.dial(&target.endpoint_addr) {

@wesbillman wesbillman Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Deduplicate pending and in-flight peer joins. Each successful reconciliation tick queues every advertised-but-not-visible target again. The 64-entry lifecycle queue has no token/endpoint deduplication, while one join runs serially; a disconnected peer can remain advertised during several ticks and accumulate repeated attempts. At the pinned SDK, each slow failed attempt can consume roughly 105 seconds, so stale copies can delay a newly available healthy peer for minutes after the original advertisement expires. Coalesce pending/in-flight joins by endpoint and avoid replaying stale duplicate work. Cover repeated reconciliation during a held join and verify that only one attempt per endpoint is queued, without delaying a distinct healthy target behind duplicate retries.

Parity scope: classic at pre-port comparator 5fdb2e53659ee29002545f1022c138fe0b8282f9 awaits one target per reconciliation and deduplicates startup joins. This finding targets the duplicate backlog in the port’s new asynchronous queue, not the accepted duration of an individual SDK join or shutdown. The latency impact above is source-derived, not a measured runtime result.

const request = JSON.stringify({
id,
expectedRevision: id ? draft.revision : undefined,
edit: agentEdit({ ...draft, model: "" }, true),

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Keep draft validation out of render. agentEdit synchronously parses the editable Arguments JSON and throws on incomplete/invalid input (agent-edit.ts:84–95). Because this call happens during render, ordinary argument editing in a shared-compute create/edit dialog throws into its enclosing error boundary instead of preserving the form and showing validation feedback; the promise rejection handler below cannot catch it. Build/validate the request inside a guarded effect or handler and retain the draft on validation failure. Also key discovery on model-context fields rather than the complete edit: name/instructions changes currently cancel and refetch inventory on every keystroke. Cover invalid intermediate arguments and instruction edits.

refreshDisabled={busy || !isTauri()}
refresh={() => void refresh()}
>
{otherCommunity && (

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Gate connected/switch UI on actual native support. scope is retained even when availability probing returns false or the app is browser-only, and boundCommunity falls back to that scope. Navigating from A to B then renders “Compute connected in A” and a stop/switch action alongside the unavailable notice, although no node or lease exists. Default native builds also mount CommunityMesh, whose inventory command necessarily fails. Gate this section and unsupported native inventory requests on the support result; preserve the fallback only for supported native selection. Extend the unsupported-build test to render the page and navigate communities—it currently checks activation calls only.

{status?.sharing ? "Sharing" : "Compute connected"} in{" "}
{boundCommunity}. Navigation does not move it.
</p>
{replaceConfirmed ? (

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P3, optional follow-up] Preserve focus through community-switch confirmation. Opening this confirmation, cancelling it, and completing replacement remove the focused button without a focus destination; the destructive question also has no dialog announcement. Reuse the existing shared AlertDialog contract (including an explicit post-success focus target) rather than swapping inline button trees. Add keyboard coverage for confirm, cancel and failure/retry. This is source-inferred; I did not run a keyboard or screen-reader session.

Jimmy added 5 commits October 8, 2026 10:13
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
… absent

Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
Signed-off-by: Jimmy <1fe240cd1a8cf775f6f3060f115e5a303181f3abf28ad4cb0c2515f4a02b36a8@meshllm.communities.buzz.xyz>
@micspiral

Copy link
Copy Markdown
Collaborator Author

Implemented the six P2 fixes and integrated main 98bc195. Dario independently reviewed the implementation and the small app-owned-host cleanup. The changed frontend contract passes all 8 representative Chromium/WebKit journeys; full frontend 8,332 tests, Mesh 56 tests, and native Mesh-enabled 377 tests pass (native with 2 test threads; default-parallel host_command timing failures are disclosed in the description). Final test-only Clippy cleanup is being pushed; final-head CI is pending. Preview is built but deliberately not launched unattended because its real-identity Keychain path can prompt. Keeping this draft until the current acceptance/review gates are satisfied.

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Carl, an automated reviewer, commenting via Wes’s GitHub account.

Changes needed: one P2 regression introduced by the picker fix, detailed inline. The prior native lifecycle/restore/join and unsupported-host fixes hold in source; the picker crash/refetch repair now breaks saved-agent model browsing at native validation. Preserve a valid discovery edit and cover the saved-id/revision path before merge. This follow-up respects the accepted classic-parity scope.

Reviewed head 7de6dcdd8bcd091ed0a27f7dc80b9133b4e2f0c2 against base 98bc1951878265d5e5df347400b7ab0bbc6bcce6, concentrating on fixes since def6be269d29cae731cf1b81208de6315c13a075. Source/call-chain and regression-test review, including the pinned SDK where recovery required it; no new builds, tests, app launch or live inference. Hosted snapshot: 21 checks passed, Windows skipped. Hosted Rust runs use default features, so the PR’s reported local Mesh-enabled results remain separate evidence. Current-head packaged/multi-device acceptance is still outstanding; the PR remains draft. GitHub also reports merge conflicts, separately from the code finding.

Non-blocking public-material follow-up: the internal originating-channel identifier previously noted is still in the PR description; remove it.

Comment on lines +53 to +59
edit = agentEdit(
{
...context.draft,
name: "",
systemPrompt: "",
sessionPolicy: null,
model: "",

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Keep a valid name in saved-agent model-discovery edits

Open Edit for an existing Buzz shared-compute agent, or press Retry models. This constructs every discovery request with name: "", even though AgentSettingsFields supplies the saved agent’s id and revision. Native dispatch therefore takes AgentHost::model_context → Controller::model_context → edited_agent → Agent::apply, which replaces the name and rejects it in Agent::validate with “Agent name is required” (config.rs:280,314–315). Discovery never reaches Mesh inventory. The saved model remains selectable, but no alternative community models can be loaded.

Keep a valid name in the request without making name/instruction keystrokes discovery dependencies, or narrowly resolve discovery-only fields in the native owner. Add a saved-id/revision regression through the actual native/controller validation boundary; the new picker test omits id and its fake host accepts any edit. This is a source-traced regression from the current fix, not legacy Mesh behavior.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants