Skip to content

P0: cut over DevSpace local-agent lifecycle to HerdR production backend #242

Description

@James3014

Goal

Make HerdR the authoritative execution backend for normal DevSpace local-agent dispatch, without moving DevSpace authority into HerdR.

Current main at creation:
8436fa8ab50e807019a436eec7cf49430695d849

Current state:

Authority boundary

DevSpace continues to own:

  • workspace identity and isolation;
  • attemptKey and DispatchIntent identity;
  • execution contract and write scope;
  • retry/replay admission;
  • Candidate / physical Git evidence / reconciliation;
  • acceptance / merge / release authority.

HerdR owns only:

  • PTY / process / pane / agent launch;
  • prompt delivery / wait / read;
  • detach / reconnect;
  • native agent/session metadata.

Hard invariants:

Wave 1 — Cutover spine

Wire the public DevSpace local-agent lifecycle to HerdrThinGateway for the HERDR backend:

  • start / first prompt;
  • continue / prompt;
  • status / wait/read;
  • reconcile;
  • cancel/stop.

Required behavior:

  • durable HERDR handle is persisted before consequential continuation;
  • restart/reconnect reuses the exact external effect identity;
  • HerdR unavailable / wrong socket / wrong agent / ambiguous ack fails closed;
  • no automatic legacy fallback;
  • legacy launcher remains available only as an explicit rollback backend, not an implicit recovery path.

Gate W1

Stop claim: HERDR_PUBLIC_LIFECYCLE_CANDIDATE_READY.

Wave 2 — M5 production activation with OpenCode + Agy

Activate HerdR as the default backend on the M5 production-shaped DevSpace runtime for the two already-qualified heterogeneous providers:

  • OpenCode;
  • Agy.

Required live witnesses must enter through the real public DevSpace dispatch lifecycle, not by directly calling the gateway test seam:

  • agent_start -> HerdR;
  • prompt/continue -> same HerdR agent;
  • status/read -> same pane/agent;
  • reconcile -> physical Git evidence;
  • cancel/stop -> exact durable handle;
  • DevSpace restart -> same attempt reconciles without duplicate worker;
  • HerdR daemon unavailable -> fail closed, no legacy fallback.

Also bind service readiness:

  • HerdR daemon supervised/started on boot or equivalent managed service;
  • exact socket identity/readiness checked before HERDR admission;
  • daemon restart behavior truthfully classified.

Gate W2

  • OpenCode real public-path canary PASS;
  • Agy real public-path canary PASS;
  • restart/reconcile PASS with zero duplicate worker;
  • runtime receipt/readback identifies runtimeKind=HERDR and exact socket/agent identity;
  • current M5 DevSpace build and HerdR daemon identities are recorded.

Stop claim: HERDR_DEFAULT_ACTIVE_OPENCODE_AGY.

Wave 3 — Provider breadth qualification

Qualify additional local agents through the same public HerdR path:

Codex

  • current executable/auth state;
  • valid account-supported model/default selection;
  • start/prompt/read/reconcile/stop;
  • restart/reconcile.

Cline

  • establish a supported runtime/Node combination;
  • prove CLI readiness/capability;
  • start/prompt/read/reconcile/stop;
  • restart/reconcile.

Grok

  • establish M5 authentication;
  • start/prompt/read/reconcile/stop;
  • restart/reconcile.

Each provider is independently pass/fail; one provider must not block the others.

Gate W3

  • per-provider live receipt bound to host/runtime/version;
  • no provider-specific silent fallback;
  • failed provider remains disabled/blocked rather than weakening the HERDR backend.

Stop claim: HERDR_PROVIDER_BREADTH_QUALIFIED for only the providers that physically pass.

Wave 4 — Soak and legacy-retirement decision

Do not remove the legacy provider launcher in the same cutover mutation.

After W2 (and optionally W3) is active:

  • observe bounded real task usage;
  • verify no duplicate process/session families;
  • verify restart/reconciliation behavior under ordinary use;
  • verify rollback procedure;
  • decide whether legacy provider adapters can be retired or retained as an explicit non-default rollback path.

Legacy retirement, if desired, should be a separate follow-up Issue after soak evidence.

Gate W4

  • bounded soak evidence exists;
  • rollback path is documented and tested;
  • Owner decision recorded: retain explicit rollback backend OR open separate retirement Issue.

Stop claim: HERDR_CUTOVER_STABLE.

Existing related Issues

Non-goals

Execution order

W1 -> W2 -> W3

W4 follows W2 after bounded real use; W3 provider sub-lanes may proceed independently after W2.

Recommended implementation batching:

  • one bounded implementation cycle may do W1 + W2 together because P0: implement thin DevSpace -> HerdR external-agent runtime gateway #236 already proves the gateway primitives and OpenCode/Agy live behavior;
  • do not include W3 Cline/Codex/Grok repairs in that same mutation unless they require no source changes beyond configuration/auth;
  • do not combine legacy-adapter deletion with W1/W2.

Priority: P0 production cutover.


Reconciliation — 2026-09-25 relationship to #256

Fresh DevSpace main: 80a238da61112cabf18bcb44a912e3f0daceba2d.

#256 is now the single umbrella for stale HerdR lifecycle/capacity reconciliation. Several bounded #256 variants have merged and are already helping W2 cutover work, so #256 does not block bounded provider canaries or ordinary W2 evidence collection by itself.

However, the final W4 claim HERDR_CUTOVER_STABLE requires that #256 reach a truthful terminal state (or that a fresh reconciliation proves no unresolved stale-capacity class is material to the W4 soak contract).

Therefore:

W2 provider canaries / activation evidence
    || #256 lifecycle-family reconciliation

W4 HERDR_CUTOVER_STABLE
    -> requires #256 terminal/reconciled stale-capacity invariant

Do not open additional HerdR stale-capacity Issues for variants that belong to #256 unless a newly observed mechanism has a different authority owner or independent completion state.


Reconciliation — 2026-09-26 #256 closure and current frontier

Fresh source/closure watermark:

#256's stale HerdR lifecycle/capacity family is now source/test closed on current main. The merged path requires exact external absence plus attributable physical workspace evidence before reclaim, keeps unreachable/identity-mismatch/unknown states fail-closed, and distinguishes verified live HerdR capacity from unresolved stale capacity.

Post-merge current-main verification:

#242 effect

The #256 prerequisite is satisfied. It is no longer a blocker for W2/W3 execution or W4 stale-capacity safety.

This does not establish:

  • W2 HERDR_DEFAULT_ACTIVE_OPENCODE_AGY;
  • current serving M5 DevSpace build/runtime convergence;
  • W3 provider breadth classifications on the current serving runtime;
  • W4 bounded soak / rollback / HERDR_CUTOVER_STABLE.

The prior 2026-09-25 serving-runtime/carrier observations are historical watermarks and must not be assumed current.

Exact next gate

ISSUE242_REBIND_CURRENT_M5_RUNTIME_THEN_W2_PUBLIC_CANARIES

  1. fresh-read the serving M5 DevSpace build/source and HerdR daemon/socket identity;
  2. if serving runtime is behind main@3d8f522..., perform the already-governed typed cutover rather than reopening source repair;
  3. run real public-path OpenCode + Agy agent_start -> continue/status/reconcile/cancel witnesses on that serving runtime;
  4. prove restart/reconcile zero-duplicate behavior and HerdR-unavailable fail-closed/no-legacy-fallback;
  5. then refresh the W3 free-first provider matrix for OpenCode/Cline/Agy/Codex/Grok under the existing contract delta.

#242 remains OPEN until those runtime gates are physically established.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions