Goal
Make HerdR the authoritative execution backend for normal DevSpace local-agent dispatch, without moving DevSpace authority into HerdR.
Current main at creation:
8436fa8ab50e807019a436eec7cf49430695d849
Current state:
Authority boundary
DevSpace continues to own:
workspace identity and isolation;
attemptKey and DispatchIntent identity;
execution contract and write scope;
retry/replay admission;
Candidate / physical Git evidence / reconciliation;
acceptance / merge / release authority.
HerdR owns only:
PTY / process / pane / agent launch;
prompt delivery / wait / read;
detach / reconnect;
native agent/session metadata.
Hard invariants:
Wave 1 — Cutover spine
Wire the public DevSpace local-agent lifecycle to HerdrThinGateway for the HERDR backend:
start / first prompt;
continue / prompt;
status / wait/read;
reconcile;
cancel/stop.
Required behavior:
durable HERDR handle is persisted before consequential continuation;
restart/reconnect reuses the exact external effect identity;
HerdR unavailable / wrong socket / wrong agent / ambiguous ack fails closed;
no automatic legacy fallback;
legacy launcher remains available only as an explicit rollback backend, not an implicit recovery path.
Gate W1
Stop claim: HERDR_PUBLIC_LIFECYCLE_CANDIDATE_READY.
Wave 2 — M5 production activation with OpenCode + Agy
Activate HerdR as the default backend on the M5 production-shaped DevSpace runtime for the two already-qualified heterogeneous providers:
Required live witnesses must enter through the real public DevSpace dispatch lifecycle, not by directly calling the gateway test seam:
agent_start -> HerdR;
prompt/continue -> same HerdR agent;
status/read -> same pane/agent;
reconcile -> physical Git evidence;
cancel/stop -> exact durable handle;
DevSpace restart -> same attempt reconciles without duplicate worker;
HerdR daemon unavailable -> fail closed, no legacy fallback.
Also bind service readiness:
HerdR daemon supervised/started on boot or equivalent managed service;
exact socket identity/readiness checked before HERDR admission;
daemon restart behavior truthfully classified.
Gate W2
OpenCode real public-path canary PASS;
Agy real public-path canary PASS;
restart/reconcile PASS with zero duplicate worker;
runtime receipt/readback identifies runtimeKind=HERDR and exact socket/agent identity;
current M5 DevSpace build and HerdR daemon identities are recorded.
Stop claim: HERDR_DEFAULT_ACTIVE_OPENCODE_AGY.
Wave 3 — Provider breadth qualification
Qualify additional local agents through the same public HerdR path:
Codex
current executable/auth state;
valid account-supported model/default selection;
start/prompt/read/reconcile/stop;
restart/reconcile.
Cline
establish a supported runtime/Node combination;
prove CLI readiness/capability;
start/prompt/read/reconcile/stop;
restart/reconcile.
Grok
establish M5 authentication;
start/prompt/read/reconcile/stop;
restart/reconcile.
Each provider is independently pass/fail; one provider must not block the others.
Gate W3
per-provider live receipt bound to host/runtime/version;
no provider-specific silent fallback;
failed provider remains disabled/blocked rather than weakening the HERDR backend.
Stop claim: HERDR_PROVIDER_BREADTH_QUALIFIED for only the providers that physically pass.
Wave 4 — Soak and legacy-retirement decision
Do not remove the legacy provider launcher in the same cutover mutation.
After W2 (and optionally W3) is active:
observe bounded real task usage;
verify no duplicate process/session families;
verify restart/reconciliation behavior under ordinary use;
verify rollback procedure;
decide whether legacy provider adapters can be retired or retained as an explicit non-default rollback path.
Legacy retirement, if desired, should be a separate follow-up Issue after soak evidence.
Gate W4
bounded soak evidence exists;
rollback path is documented and tested;
Owner decision recorded: retain explicit rollback backend OR open separate retirement Issue.
Stop claim: HERDR_CUTOVER_STABLE.
Existing related Issues
Non-goals
Execution order
W1 -> W2 -> W3
W4 follows W2 after bounded real use; W3 provider sub-lanes may proceed independently after W2.
Recommended implementation batching:
one bounded implementation cycle may do W1 + W2 together because P0: implement thin DevSpace -> HerdR external-agent runtime gateway #236 already proves the gateway primitives and OpenCode/Agy live behavior;
do not include W3 Cline/Codex/Grok repairs in that same mutation unless they require no source changes beyond configuration/auth;
do not combine legacy-adapter deletion with W1/W2.
Priority: P0 production cutover .
Reconciliation — 2026-09-25 relationship to #256
Fresh DevSpace main: 80a238da61112cabf18bcb44a912e3f0daceba2d.
#256 is now the single umbrella for stale HerdR lifecycle/capacity reconciliation. Several bounded #256 variants have merged and are already helping W2 cutover work, so #256 does not block bounded provider canaries or ordinary W2 evidence collection by itself.
However, the final W4 claim HERDR_CUTOVER_STABLE requires that #256 reach a truthful terminal state (or that a fresh reconciliation proves no unresolved stale-capacity class is material to the W4 soak contract).
Therefore:
W2 provider canaries / activation evidence
|| #256 lifecycle-family reconciliation
W4 HERDR_CUTOVER_STABLE
-> requires #256 terminal/reconciled stale-capacity invariant
Do not open additional HerdR stale-capacity Issues for variants that belong to #256 unless a newly observed mechanism has a different authority owner or independent completion state.
Reconciliation — 2026-09-26 #256 closure and current frontier
Fresh source/closure watermark:
#256 's stale HerdR lifecycle/capacity family is now source/test closed on current main. The merged path requires exact external absence plus attributable physical workspace evidence before reclaim, keeps unreachable/identity-mismatch/unknown states fail-closed, and distinguishes verified live HerdR capacity from unresolved stale capacity.
Post-merge current-main verification:
The #256 prerequisite is satisfied. It is no longer a blocker for W2/W3 execution or W4 stale-capacity safety.
This does not establish:
W2 HERDR_DEFAULT_ACTIVE_OPENCODE_AGY;
current serving M5 DevSpace build/runtime convergence;
W3 provider breadth classifications on the current serving runtime;
W4 bounded soak / rollback / HERDR_CUTOVER_STABLE.
The prior 2026-09-25 serving-runtime/carrier observations are historical watermarks and must not be assumed current.
Exact next gate
ISSUE242_REBIND_CURRENT_M5_RUNTIME_THEN_W2_PUBLIC_CANARIES
fresh-read the serving M5 DevSpace build/source and HerdR daemon/socket identity;
if serving runtime is behind main@3d8f522..., perform the already-governed typed cutover rather than reopening source repair;
run real public-path OpenCode + Agy agent_start -> continue/status/reconcile/cancel witnesses on that serving runtime;
prove restart/reconcile zero-duplicate behavior and HerdR-unavailable fail-closed/no-legacy-fallback;
then refresh the W3 free-first provider matrix for OpenCode/Cline/Agy/Codex/Grok under the existing contract delta.
#242 remains OPEN until those runtime gates are physically established.
Goal
Make HerdR the authoritative execution backend for normal DevSpace local-agent dispatch, without moving DevSpace authority into HerdR.
Current main at creation:
8436fa8ab50e807019a436eec7cf49430695d849Current state:
agent_startstill enters the existinglaunchPrompt()/spawnWorker()provider-launch path; ordinary dispatch is therefore not yet HerdR-backed.Authority boundary
DevSpace continues to own:
attemptKeyand DispatchIntent identity;HerdR owns only:
Hard invariants:
OUTCOME_UNKNOWN != retry permission;AUTO_CHAIN=false;Wave 1 — Cutover spine
Wire the public DevSpace local-agent lifecycle to
HerdrThinGatewayfor the HERDR backend:Required behavior:
Gate W1
Stop claim:
HERDR_PUBLIC_LIFECYCLE_CANDIDATE_READY.Wave 2 — M5 production activation with OpenCode + Agy
Activate HerdR as the default backend on the M5 production-shaped DevSpace runtime for the two already-qualified heterogeneous providers:
Required live witnesses must enter through the real public DevSpace dispatch lifecycle, not by directly calling the gateway test seam:
agent_start-> HerdR;Also bind service readiness:
Gate W2
runtimeKind=HERDRand exact socket/agent identity;Stop claim:
HERDR_DEFAULT_ACTIVE_OPENCODE_AGY.Wave 3 — Provider breadth qualification
Qualify additional local agents through the same public HerdR path:
Codex
Cline
Grok
Each provider is independently pass/fail; one provider must not block the others.
Gate W3
Stop claim:
HERDR_PROVIDER_BREADTH_QUALIFIEDfor only the providers that physically pass.Wave 4 — Soak and legacy-retirement decision
Do not remove the legacy provider launcher in the same cutover mutation.
After W2 (and optionally W3) is active:
Legacy retirement, if desired, should be a separate follow-up Issue after soak evidence.
Gate W4
Stop claim:
HERDR_CUTOVER_STABLE.Existing related Issues
Non-goals
Execution order
W1 -> W2 -> W3W4follows W2 after bounded real use; W3 provider sub-lanes may proceed independently after W2.Recommended implementation batching:
Priority: P0 production cutover.
Reconciliation — 2026-09-25 relationship to #256
Fresh DevSpace main:
80a238da61112cabf18bcb44a912e3f0daceba2d.#256 is now the single umbrella for stale HerdR lifecycle/capacity reconciliation. Several bounded #256 variants have merged and are already helping W2 cutover work, so #256 does not block bounded provider canaries or ordinary W2 evidence collection by itself.
However, the final W4 claim
HERDR_CUTOVER_STABLErequires that #256 reach a truthful terminal state (or that a fresh reconciliation proves no unresolved stale-capacity class is material to the W4 soak contract).Therefore:
Do not open additional HerdR stale-capacity Issues for variants that belong to #256 unless a newly observed mechanism has a different authority owner or independent completion state.
Reconciliation — 2026-09-26 #256 closure and current frontier
Fresh source/closure watermark:
3d8f522b5bbe7723232967bb0811fdc5b66f1a2d5003ee40fb984f2b144c10b5e5e544a559a43f52#256's stale HerdR lifecycle/capacity family is now source/test closed on current main. The merged path requires exact external absence plus attributable physical workspace evidence before reclaim, keeps unreachable/identity-mismatch/unknown states fail-closed, and distinguishes verified live HerdR capacity from unresolved stale capacity.
Post-merge current-main verification:
npm run typecheck— PASS5003ee40fb984f2b144c10b5e5e544a559a43f52#242 effect
The #256 prerequisite is satisfied. It is no longer a blocker for W2/W3 execution or W4 stale-capacity safety.
This does not establish:
HERDR_DEFAULT_ACTIVE_OPENCODE_AGY;HERDR_CUTOVER_STABLE.The prior 2026-09-25 serving-runtime/carrier observations are historical watermarks and must not be assumed current.
Exact next gate
ISSUE242_REBIND_CURRENT_M5_RUNTIME_THEN_W2_PUBLIC_CANARIESmain@3d8f522..., perform the already-governed typed cutover rather than reopening source repair;agent_start -> continue/status/reconcile/cancelwitnesses on that serving runtime;#242 remains OPEN until those runtime gates are physically established.