Repository navigation
Community Mesh shared compute and agent integration #580
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Draft
micspiral
wants to merge
79
commits into
main
Choose a base branch
from
jimmy/mesh-share-wip
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+17,464
−367
Draft
Changes from all commits
Commits
Show all changes
79 commits
Select commit
Hold shift + click to select a range
138ca46
WIP: introduce optional Mesh native capability skeleton
90a07ff
WIP: gate Mesh SDK and isolate consumer configuration
c0e750c
Preserve legacy Mesh consumer transport and roster policy
4255789
WIP: retain Mesh startup and shutdown ownership
c8a762c
WIP: bound Mesh shutdown and bind app lifetime
99455f0
Add isolated opt-in native MeshHost smoke test
0947ddb
WIP: port Mesh discovery with verified roster authority
2366457
Ignore invalid member discovery notes without blocking Mesh
caf2440
WIP: wire authenticated Mesh discovery and leased native Start
0e5c0e9
WIP: add bundled Mesh client controls with selection cleanup
ac6f12c
Keep Mesh selection alive across relay reconnects
a6c13c9
Fix strict indexing in Mesh reconnect regression
ec900e5
Allow Mesh IPC commands and guard frontend ACL wiring
f902131
Unlock existing encrypted Mesh identities through the OS credential s…
67335eb
Present Mesh controls as shared compute preferences
18e4a93
Use donor consumer page and refresh transient Mesh lifecycle
3394dd2
Test opt-in Mesh plugin page in browser composition
99a6fc0
Restore Compute consumer to Settings instead of sidebar
fb9a837
Name Compute view Use shared compute
2e93d79
Place Compute in community settings with CPU icon
8b6260e
Keep Compute discoverable in Personal space with community prompt
38879ea
Revert "Keep Compute discoverable in Personal space with community pr…
1605f41
Show selected community on shared compute view
ef16221
Rename Shared compute and remove manual consumer connect action
c5c4f49
Read community mesh inventory from verified relay discovery
ed2788d
Separate inventory evidence state and isolate Mesh default ports
a1af4e0
Checkpoint native Mesh launch grants and consumer ownership ledger
0884a66
Confirm community roster changes before native reconciliation
440d136
Match classic roster growth and startup confirmation ordering
5900abc
Remove unused per-agent Mesh lifetime ledger
e698b9d
Wire agent startup to current-community Mesh readiness
b7dd812
Add private serving configuration to the shared Mesh lifecycle
455c8f4
Build owner-bound community Mesh status notes
4996bb3
Wire bounded community Mesh heartbeat and SDK status reads
d3a5fbd
WIP: checkpoint inherited Mesh sharing implementation
b681c22
Preserve saved Mesh sharing across plugin release and selection
be1f59f
Explain saved sharing after Disconnect
3b03e24
Complete shared compute selection and community coordination for preview
d72dbca
Integrate current app and update shared compute setup
4fd638d
Let Mesh serving own model acquisition and retain download progress
1fba91a
Distinguish model preparation from active sharing
be0af00
Cover Mesh discovery membership and owner-binding regressions
4e2d61b
Restore Mesh agent defaults and decouple GGUF ladder from layer catalog
dce464e
Expose Mesh startup diagnostics and reset model recommendation
af7e403
Persist Auto sharing and reset overrides without restarting Mesh
4dff272
Merge main into Mesh plugin worktree
3f5fffb
Update Mesh to v0.78.1 and align Auto browser assertion
525d684
Keep Mesh bound across navigation and repair admission and peer failures
9b7ab84
Restore legacy Mesh enrollment and fix shared-compute browser journey
0816c3a
Simplify Mesh sharing controls to a Share this machine switch
6eddbad
Show readable model names in the Mesh model picker
400a600
Advertise Mesh's display names for local-gguf models
84922f8
Revert "Show readable model names in the Mesh model picker"
18ee3d0
Remove Mesh Disconnect and make sharing failure states recoverable
9624110
Let Share off clear saved consent without a lease
124b208
Fence the Mesh disarm fallback to its originating identity
810e0cc
Await the retired Share action in Mesh fencing tests
60e5f8a
Restore legacy Mesh agent readiness and honest model names
3de4498
Make the Mesh name fallback char-safe, drop the cold scan, fix probe …
e0abe89
Withdraw Mesh adverts on Share Off and keep explicit agent timeouts
eac09b5
Compact Mesh sharing card and community summary, one status and Refresh
8949df4
Re-arm Mesh consumers after Share Off, serialize withdrawal, honest m…
61de853
Order Mesh withdrawal at the relay, test Off orchestration, correlate…
b262f36
Test the real Share Off orchestration and report consumer re-arm failure
a255373
Fence delayed Share Off stops and errors to the original lease
6208236
Track mesh_compute_disarm in the native command ACL test
8d45e94
Polish community shared compute and agent setup
sandro-sq def6be2
Merge main into mesh shared compute branch
b5100c3
Merge upstream main into Mesh compute preview
eb9bddd
Fix Mesh admission recovery, restore, join coalescing and picker gating
32d94b4
Document Mesh recovery and assert unsupported browser inventory stays…
c3bcf38
Resolve owned Mesh host from app rather than redundant startup argument
7de6dcd
Avoid unnecessary event clone in Mesh route regression
e6bf587
Fix saved shared-compute model discovery validation
0b56ff9
Merge main preserving Mesh and native owner admission
f0e9d3c
Merge origin/main into jimmy/mesh-share-wip
c3f380e
Keep saved Mesh discovery fixture compatible with agent effort
d4ce094
Mark Mesh model catalogs as non-Codex after main integration
fb65321
test: wait for member roster visibility after confirmation
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
Large diffs are not rendered by default.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,4 +1,4 @@ | ||
| [workspace] | ||
| members = ["crates/pairing", "crates/plugin-manager", "crates/agent-controller", "crates/credential-store", "src-tauri"] | ||
| members = ["crates/pairing", "crates/plugin-manager", "crates/agent-controller", "crates/credential-store", "crates/mesh-compute", "src-tauri"] | ||
| default-members = ["crates/plugin-manager"] | ||
| resolver = "2" |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,117 @@ | ||
| //! Native-only endpoint configuration for one saved Mesh agent start. Never persisted. | ||
| use crate::{config::Agent, Result}; | ||
|
|
||
| /// Effective saved selectors for the native readiness check; contains no secrets. | ||
| pub struct MeshRequest { | ||
| pub agent_id: String, | ||
| pub revision: u64, | ||
| pub relay: String, | ||
| pub model: String, | ||
| } | ||
|
|
||
| impl crate::Controller { | ||
| /// Resolve the same defaults and environment used at launch. | ||
| pub fn mesh_request(&self, id: &str) -> Result<Option<MeshRequest>> { | ||
| let agent = self.mesh_agent(id)?; | ||
| if agent.harness.provider != "relay-mesh" { | ||
| return Ok(None); | ||
| } | ||
| if agent.harness.command != "buzz-agent" | ||
| || !agent.imported["record"]["relay_mesh"].is_null() | ||
| { | ||
| return Err("Shared compute supports the local Buzz Agent harness".into()); | ||
| } | ||
| Ok(Some(MeshRequest { | ||
| agent_id: agent.id, | ||
| revision: agent.revision, | ||
| relay: agent.relay_url, | ||
| model: agent.harness.model, | ||
| })) | ||
| } | ||
| } | ||
|
|
||
| /// Prepared after node readiness; the app, not an agent process, owns the node. | ||
| pub struct MeshLaunch { | ||
| agent_id: String, | ||
| revision: u64, | ||
| relay: String, | ||
| model: String, | ||
| port: u16, | ||
| } | ||
|
|
||
| impl MeshLaunch { | ||
| /// Create only after native discovery and node readiness succeed. | ||
| /// A port, rather than an arbitrary URL, limits child routing to loopback. | ||
| pub fn new( | ||
| agent_id: String, | ||
| revision: u64, | ||
| relay: String, | ||
| model: String, | ||
| port: u16, | ||
| ) -> Result<Self> { | ||
| let grant = Self { | ||
| agent_id: agent_id.clone(), | ||
| revision, | ||
| relay, | ||
| model, | ||
| port, | ||
| }; | ||
| if grant.port == 0 || grant.model.trim().is_empty() { | ||
| return Err("Shared compute requires a ready endpoint and model".into()); | ||
| } | ||
| Ok(grant) | ||
| } | ||
|
|
||
| pub(crate) fn apply(&self, agent: &Agent) -> Result<Agent> { | ||
| let mut agent = agent.clone(); | ||
| agent.harness = crate::build_defaults().resolve(&agent.harness, &agent.environment); | ||
| if agent.id != self.agent_id | ||
| || agent.revision != self.revision | ||
| || agent.relay_url != self.relay | ||
| || agent.harness.provider != "relay-mesh" | ||
| || agent.harness.command != "buzz-agent" | ||
| || !agent.imported["record"]["relay_mesh"].is_null() | ||
| { | ||
| return Err("Shared compute grant no longer matches the saved agent".into()); | ||
| } | ||
| let mut runtime = agent.clone(); | ||
| runtime.harness.provider = "openai".into(); | ||
| runtime.harness.model.clone_from(&self.model); | ||
| // Legacy relay_mesh default, not policy: an explicit agent value wins and | ||
| // no context window is derived from the catalog (buzz-agent's default applies). | ||
| runtime | ||
| .environment | ||
| .entry("BUZZ_AGENT_MAX_OUTPUT_TOKENS".into()) | ||
| .or_insert_with(|| "4096".into()); | ||
| // Explicit last-writer runtime settings; user environment cannot reroute this grant. | ||
| // Legacy default just above MeshLLM's 600 s backend budget; a user value wins. | ||
| runtime | ||
| .environment | ||
| .entry("BUZZ_AGENT_LLM_TIMEOUT_SECS".into()) | ||
| .or_insert_with(|| "660".into()); | ||
| for (name, value) in [ | ||
| ("BUZZ_AGENT_PROVIDER", "openai".to_owned()), | ||
| ("BUZZ_AGENT_MODEL", self.model.clone()), | ||
| ("OPENAI_COMPAT_MODEL", self.model.clone()), | ||
| ( | ||
| "OPENAI_COMPAT_BASE_URL", | ||
| format!("http://127.0.0.1:{}/v1", self.port), | ||
| ), | ||
| ("OPENAI_COMPAT_API_KEY", "mesh-local".to_owned()), | ||
| ("OPENAI_COMPAT_API", "chat".to_owned()), | ||
| ] { | ||
| runtime.environment.insert(name.into(), value); | ||
| } | ||
| // Match classic Buzz without overriding an explicit opt-out. | ||
| runtime | ||
| .environment | ||
| .entry("BUZZ_AGENT_REQUIRE_REPLY".into()) | ||
| .or_insert_with(|| "1".into()); | ||
| // Mesh agents default to no reasoning; explicit user effort wins. | ||
| runtime | ||
| .environment | ||
| .entry("BUZZ_AGENT_THINKING_EFFORT".into()) | ||
| .or_insert_with(|| "none".into()); | ||
| Ok(runtime) | ||
| } | ||
| } | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
[P1] Bind running agents to a community/runtime generation, not the reusable port
Start an Auto Mesh agent in community A, switch the foreground community to B, and start B's node (including via saved sharing/agent restore).
mesh_compute_selectstops A's node but leaves its agent process running; B reuses port 19337. The A process retains this URL, the constantmesh-localkey and modelmesh, so its next A conversation request can be routed to B's peers.Prepared::with_currentfences only launch, andRunningretains no Mesh grant to revoke. This violates the community isolation promised inVISION_MESH.md, even though both peer allowlists individually validate correctly.At SDK pin
fc57e326, local OpenAI ingress uses the current node's targets with no remote caller identity (network/openai/ingress.rs:2449-2487,2519-2554); the peer allowlist does not bind a local request to A. Keep an enforceable community/generation-bound consumer lifetime: either refuse switching while consumers remain, confirm all affected agents stop before reusing the endpoint, or reject retired credentials at a host-owned ingress. Add an A-agent → B-node → next A prompt regression asserting B receives nothing. Source-traced, not a live disclosure reproduction.