feat(coven): send Phase 2 lifecycle commands as spec envelopes - #334
Merged
Merged
Conversation
Add automations.activate, pause, disable and tombstone. Each validates its automation id, expected revision, adoption key, intent, principal and reason before any I/O, is sent only when the producer advertises coven.automations.command.v1 and the command's own action, and posts one frozen spec envelope through a new optional sendCommand hook. The built-in Unix and Windows transports rebuild and serialize exactly these four envelopes and refuse anything else, leaving the read hook read-only. Results are typed committed, replayed or rejected outcomes without the producer's message; any failure after the send throws outcome_unknown so callers resend with the same adoption key instead of retrying blind. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Input validation, response-envelope verification, and replay result typing have correctness gaps.
Review effort: Balanced
Findings: 3
Open (4)
What changed in this PR
Adds Phase 2 Coven automation lifecycle commands using constrained, capability-gated command envelopes.
Changes:
- Adds activate, pause, disable, and tombstone APIs.
- Implements validated serialization, response decoding, and unknown-outcome handling.
- Adds documentation, API baselines, and transport/platform tests.
| File | Description |
|---|---|
.changeset/coven-lifecycle-commands.md |
Records the minor feature release. |
api-baselines/coven.d.ts |
Updates the public API baseline. |
packages/coven/README.md |
Documents lifecycle commands and recovery. |
packages/coven/src/automations-commands.ts |
Defines command contracts, validation, serialization, and decoding. |
packages/coven/src/automations-socket.ts |
Sends command envelopes over local IPC. |
packages/coven/src/automations.ts |
Exposes lifecycle methods and capability gating. |
packages/coven/src/index.ts |
Exports command types. |
tests/coven-automations-commands.spec.ts |
Tests command behavior and failure handling. |
tests/coven-automations-platforms.spec.ts |
Tests Unix/Windows wire parity. |
tests/coven-automations.spec.ts |
Tests direct transport rejection. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Count intent and reason bounds in code points as JSON Schema does, refuse unknown option keys before any I/O, require the control-action wrapper's ok/accepted/status to match the inner outcome before trusting it, and split committed and replayed into separate union members so a replay narrows to its required firstCommittedAt. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
8 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Part of #80, Phase 2: low-risk lifecycle commands, over the producer's spec command envelope (OpenCoven/coven#1176).
The maintainer explicitly authorized this step. It ends the SDK transport's read-only posture that the #40 review relied on, but only through a separate hook that is strictly limited to four commands.
What
automations.activate,pause,disableandtombstonetake(automationId, expectedRevision, context, options?).contextis{ adoptionKey, intent, principalId, correlationId? }.optionsis{ reason?, signal?, timeoutMs?, observer? }, andtombstonetakes noreason.invalid_options.coven.automations.command.v1and the specific command action. Otherwise it fails withcapability_unsupported.sendCommandtransport hook.commandBytes. That rebuilds and serializes exactly the four lifecycle envelopes, refuses every other command, extra fields and non-sdkchannels, and never serializes caller objects.readDefinitionshook stays read-only.sendCommandcannot mutate; the call fails withunsupported_operation.committed(withrevision,resultandeventRef),replayed(withreplay.firstCommittedAt), orrejected(with the typederror.code,retryable, andcurrentRevisionwhere applicable). Producer messages are not copied.outcome_unknownwithretryable: true. That covers a dropped connection, the deadline passing mid-flight, and a response that doesn't prove what happened. The README says to resend with the sameadoptionKey, which the producer replays instead of re-applying. Cancellation before sending never reportsoutcome_unknown.principalIdis recorded, not an authority grant; the producer accepts mutations only over owner-local IPC.createDraftandrevisewait on producer rich-definition persistence. Phase 3 (run, cancel, retry, approval) waits on coven#857.Verification
pnpm verifypassed: 3092 tests, typecheck, contracts, package, coverage, stress and lint.coven-automations-commands.spec.tscovers:sendCommand;sendCommandrefuses seven non-lifecycle or malformed requests before I/O.🤖 Generated with Claude Code