[WORKER] Core+Android — mobile usability, offline/runtime integration and hardening loop #346
Open
opened 2026-09-08 02:03:36 +00:00 by nsaspy
·
19 comments
No Branch/Tag specified
master
agent/pi-coder-plugin-2026-09-17
fix/android-remote-listener
ui/chat-message-bubbles
release/v0.1.1-alpha-20260908
fix/default-daemon-endpoint-20260908
ui/650-outrun-shell
fix/400-plugin-capability-composition
fix/tts-idle-cpu-spin
design/android-canonical-reference-2026-09-07
fixtures/voice-recordings
rage/core/388-tool-cancellation-r18
rage/core/388-tool-cancellation-r1
release/v0.1.0-alpha
rage/android/175-terminal-transcript-fence-r4
rage/core/324-expanded-history-sidebar-r2
rage/android/175-terminal-transcript-fence-r3
rage/android/175-focus-release-retry-r2
rage/android/175-focus-release-retry
ci/desktop-idle-cpu-budget
rage/android/175-terminal-transcript-fence-r2
rage/android/175-route-stop-retry-r3
rage/575-transient-send-backpressure-r3
rage/575-transient-send-backpressure-r2
rage/android/175-terminal-transcript-fence
rage/android/175-route-stop-retry-r2
rage/android/175-sink-self-close-r2
rage/android/175-route-stop-retry
rage/android/175-sink-self-close
rage/android/175-audio-focus-sync-loss-r2
rage/android/175-stock-voice-interop-r3
rage/android/175-stock-voice-interop-r2
rage/android/175-audio-focus-sync-loss
rage/android/175-recover-stack-current-4
rage/android/175-stock-voice-interop-r1
rage/android/175-recover-stack-current-2
rage/587-vulkan-current-master-r2
rage/587-dictation-vulkan-current2
rage/575-transient-send-backpressure-r1
tmp-do-not-use-587
tmp-do-not-use-587-2
tmp-do-not-use-587-3
tmp-do-not-use-587-4
rage/587-dictation-vulkan-current2-tree
fix/dictation-ggml-vulkan-rage587
rage/android-campaign-batch-20260906
rage/587-dictation-ggml-vulkan-current
rage/388-toolnode-forwarding-r17-current2
rage/587-dictation-ggml-vulkan-r1
rage/388-toolnode-forwarding-r17-current
rage/575-gateway-send-diagnostics-current
rage/178-device-action-json-depth-r7
rage/175-recorder-failure-precedence-r8
rage/175-terminal-capture-cleanup-r8
rage/175-playback-write-failure-cleanup-r8
rage/575-gateway-send-diagnostics
rage/388-toolnode-forwarding-r17
rage/575-stock-interop-diagnostics-r2
fix/dictate-whisper-cpp-vulkan
rage/575-stock-interop-diagnostics-r1
rage/324-expanded-history-sidebar-r1
rage/178-device-action-json-depth-r6
rage/388-plugin-cancellation-r16
rage/175-recorder-failure-precedence-r7
rage/175-terminal-capture-cleanup-r7
rage/175-playback-write-failure-cleanup-r7
rage/324-native-chrome-r1
rage/175-recorder-failure-precedence-r6
rage/175-terminal-capture-cleanup-r6
rage/175-playback-write-failure-cleanup-r6
rage/324-independent-geometry-r2
rage/175-close-resource-precedence
rage/178-device-action-json-depth-r5
rage/175-recorder-failure-precedence-r5
rage/175-terminal-capture-cleanup-r5
rage/175-playback-write-failure-cleanup-r5
rage/324-independent-geometry-r1
rage/324-screenshot-provenance-r1
rage/324-history-parity-r1
rage/178-device-action-json-depth-r4
rage/175-preserve-recorder-primary-failure-r2
rage/175-capture-terminal-failure-cleanup-r3
rage/175-playback-write-failure-cleanup-r4
rage/324-screenshot-ci-r1
rage/324-unified-copilot-r4
rage/175-capture-terminal-failure-cleanup-r2
rage/175-playback-write-failure-cleanup-r3
rage/324-unified-copilot-r3
rage/175-preserve-recorder-primary-failure
rage/175-capture-terminal-failure-cleanup
rage/178-device-action-json-depth-r3
rage/175-playback-write-failure-cleanup-r2
rage/178-voice-stream-json-depth-r5
rage/160-semantic-first-runtime-r2
rage/175-playback-write-failure-cleanup
rage/178-voice-stream-json-depth-r4
rage/324-unified-copilot-r2
rage/178-device-action-json-depth-r2
rage/178-voice-json-depth-r3
rage/178-voice-ack-json-depth-r3
rage/160-semantic-first-runtime
rage/492-device-action-replay-r6
rage/178-device-action-json-depth
rage/178-voice-json-depth-r2
rage/178-voice-ack-json-depth-r2
rage/178-voice-json-depth-bound
rage/178-voice-ack-json-depth
rage/178-voice-hello-json-depth
rage/178-device-json-depth-bound
rage/178-capability-json-depth-bound
rage/178-android-daemon-restart-stale-turn-r2
rage/492-device-action-replay-r5
rage/492-device-action-replay-r4
rage/178-android-daemon-restart-stale-turn-r1
rage/178-android-json-depth-bound-r2
rage/178-android-json-depth-bound-r1
rage/203-android-playback-session-invalidation-r3
rage/492-device-action-replay-r3
rage/178-android-audio-payload-bound-r4
rage/203-android-playback-session-invalidation-r2
rage/178-android-audio-payload-bound-r3
rage/492-device-action-replay-r2
rage/203-android-ui-close-runtime-ownership-r3
rage/203-android-playback-session-invalidation
rage/178-android-audio-payload-bound-r2
rage/203-android-ui-close-runtime-ownership-r2
rage/178-android-uri-intent-abuse-r4
rage/178-android-audio-payload-bound
rage/203-android-ui-close-runtime-ownership
rage/492-device-action-replay-r1
rage/178-android-uri-intent-abuse-r3
rage/178-android-no-raw-logging-r5
rage/492-device-action-replay-horizon
rage/218-normalizer-config-r4
rage/178-android-uri-intent-abuse-r2
rage/178-android-no-raw-logging-r4
rage/178-android-uri-intent-abuse-r1
rage/218-normalizer-config-r3
rage/178-android-no-raw-logging-r3
rage/178-android-prolog-lifecycle-r3
rage/178-android-no-raw-logging-r2
rage/178-android-prolog-lifecycle-r2
rage/178-android-principal-target-abuse-r2
rage/178-android-no-raw-logging-r1
rage/178-android-prolog-lifecycle-r1
rage/178-android-principal-target-abuse-r1
rage/178-android-device-action-replay-r4
rage/178-android-device-action-replay-r3
rage/178-android-capability-revocation-r3
rage/218-normalizer-config-r2
rage/178-android-trealla-result-overflow-r1
rage/178-android-device-action-replay-r2
rage/178-android-capability-revocation-r2
rage/178-android-auth-revocation-r2
rage/178-android-device-action-replay-r1
rage/178-android-capability-revocation-r1
rage/178-android-auth-revocation-r1
rage/178-android-reconnect-storm-r3
rage/218-normalizer-config-r1
rage/218-normalizer-config-status-r1
rage/324-unified-copilot-r1
rage/217-s1-mini-normalizer-r4
rage/178-android-reconnect-storm-r2
rage/178-reconnect-storm-red-proof
rage/217-s1-mini-normalizer-r3
rage/178-android-release-matrix-r1
rage/217-s1-mini-normalizer-r2
rage/203-android-recorder-failure-diagnostics-r3
rage/217-s1-mini-normalizer-r1
rage/203-android-assistant-role-loss-wiring-r3
rage/216-transcript-normalization-contract-r2
rage/203-android-recorder-failure-diagnostics-r2
rage/203-android-assistant-role-loss-wiring-r2
rage/216-transcript-normalization-contract-r1
rage/203-android-reconnect-scheduler-failure-r2
rage/388-plugin-tool-cancellation-r15
rage/203-android-reconnect-scheduler-failure
rage/203-android-voice-session-invalidation-r4
rage/203-android-voice-session-invalidation-r3
rage/203-android-ui-error-redaction-r3
rage/388-plugin-tool-cancellation-r14
rage/388-plugin-tool-cancellation-r13
rage/400-plugin-capability-composition-r1
rage/203-android-ui-error-redaction-r2
rage/388-plugin-tool-cancellation-r12
rage/203-android-audio-route-rollback-failure-r2
rage/325-atomic-durable-message-append
rage/203-android-state-store-temp-isolation-r2
rage/388-plugin-tool-cancellation-r11
rage/388-plugin-tool-cancellation-r10
rage/203-android-audio-route-rollback-failure
rage/203-android-recorder-failure-diagnostics
rage/203-android-voice-runtime-invalidation-r2
rage/203-android-assistant-role-loss-wiring
rage/203-android-voice-session-invalidation-r2
rage/203-android-ui-error-redaction
rage/388-plugin-tool-cancellation-r9
rage/203-android-state-store-temp-isolation
rage/203-android-connection-error-redaction
rage/203-android-assistant-role-loss-r3
rage/388-plugin-tool-cancellation-r8
rage/203-android-voice-runtime-invalidation-primitives
rage/203-android-assistant-role-loss-r2
rage/203-android-voice-diagnostic-redaction-r2
rage/388-plugin-tool-cancellation-r7
rage/203-android-assistant-role-loss
rage/203-android-voice-session-invalidation
rage/203-android-voice-diagnostic-redaction
rage/174-android-open-app-aliases
rage/388-plugin-tool-cancellation-r6
rage/203-android-assistant-shutdown-fence
rage/388-plugin-tool-cancellation-r5
rage/29-streaming-tts-provider-recovery-r10
rage/203-android-mic-permission-lifecycle
rage/203-android-audio-route-lifecycle
rage/175-android-audio-focus-lifecycle
rage/174-android-device-capabilities
rage/29-streaming-tts-provider-recovery-r9
rage/388-plugin-tool-cancellation-r4
rage/388-plugin-tool-cancellation-r3
rage/29-streaming-tts-provider-recovery-r8
rage/326-desktop-toggle
rage/388-plugin-tool-cancellation-r2
rage/388-plugin-tool-cancellation
rage/29-streaming-tts-current-r7
rage/29-streaming-tts-current-r6
rage/371-plugin-approval-current
rage/29-streaming-tts-current-r5
rage/371-plugin-approval-contract
rage/371-plugin-approval-red
rage/29-streaming-tts-current-r4
rage/196-ui-closed-runtime
rage/196-android-assistant-role
rage/29-streaming-tts-current-r3
rage/175-android-barge-in
rage/175-android-streamed-voice
rage/175-android-manual-voice
rage/29-streaming-tts-current-r2
rage/29-streaming-tts-current
rage/327-bounded-target-edit-distance-recovery-r2
rage/348-dash-prefixed-z85-cli-r2
rage/197-compose-first-usable
rage/348-dash-prefixed-z85-cli
rage/173-android-client-continuity
rage/327-bounded-target-edit-distance-recovery
rage/329-production-secure-listener
rage/329-merge-probe
rage/159-zara1-device-actions-current
docs/refresh-20260905
rage/159-zara1-device-actions-recovery
rage/324-unified-copilot
rage/173-android-auth
rage/327-bounded-target-edit-distance
research/unified-copilot-20260905
rage/133-desktop-daemon-default-regression
rage/133-daemon-default-regression
rage/13-open-app-allowlist-regression
rage/165-user-command-runtime
rage/315-route-backpressure-test-contract
rage/164-user-command-authoring
rage/163-user-command-compiler
rage/162-user-command-persistence
rage/309-prolog-config-recovery
docs/260-customization-wiki
rage/260-customization-diagnostics
rage/159-zara1-device-actions
rage/260-agent-loop-backend-registry
rage/260-backend-registry
rage/260-service-plugin-advice
backup/rage-260-service-plugin-advice-pre-android-merge-20260903
rage/android-172-cross-runtime-parity
rage/zara-004-config-durability
rage/260-prolog-command-advice
feature/long-horizon-tasks
rage/264-config-delta
rage/264-host-delta
rage/264-config-host-delta
rage/rebase-264-long-horizon-tasks
backup/rage-260-prolog-command-advice-pre-rebase-20260903
rage/android-172-resolver-parity
rage/260-python-user-hooks
rage/260-agent-loop-integration
rage/android-172-asset-staging
rage/android-172-native-adapter
rage/260-python-hooks-advice
rage/android-172-jni-bridge
rage/android-172-trealla-runtime
rage/260-hooks-prolog-config
rage/android-172-fixture-runner
fork/prolog-rlm-agentic-runtime
rage/android-172-normalized-results
rage/android-172-assets-v2
rage/core-246-todo-toggle-current
rage/android-172-assets
rage/core-246-todo-toggle-refresh
rage/android-172-portable-prolog-refresh
feature/agent-mode-core
rage/recover-259-run10
rage/android-172-portable-prolog
docs/244-merge-evidence
backup/feature-long-horizon-tasks-pre-rebase-20260902
feat/zara-031-context-management
docs/250-merge-evidence
rage/250-amd-stt-device-routing
rage/159-zara1-capability-advertisement
feat/unified-agent-tui
fix/discord-tools-bash
rage/158-api-service-providers
docs/249-merge-evidence
rage/249-latency-trace-checkpoint
fix/246-disable-todo-surface
codex/zara-discord-plugin-guidance
rage/157-execution-plans
rage/156-prolog-frames
rage/28-post-merge-evidence
perf/zara-027-streaming-llm-impl
rage/155-typed-slots
test/live-smoke-reasoning-budgets
feature/openrouter-rlm-directmode
rage/154-intentframe-contract
chore/backlog-import
rage/195-samsung-assistant-research
feat/android-app
research/aradr-local-tts-voice-cloning
feature/wake-words-edit-distance
perf/zara-027-streaming-llm
docs/134-reentry-assessment
rage/134-daemon-release-gate
rage/131-merge-closeout
docs/rage-130-merge-outcome
docs/rage-17-merge-outcome
fix/zara-016-llm-provider-contracts
build/flake-update-2026-08
rage/191-zara1-tool-approvals
rage/132-visible-stt-regression
codex/copilot-redesign
codex/default-daemon-cli
rage/132-transcript-events
rage/133-post-merge-evidence
rage/133-client-migration
rage/132-post-merge-evidence
rage/132-live-voice
rage/132-live-voice-zara1
rage/131-principal-isolation
rage/131-principal-scope
rage/130-curve-zap-security
rage/130-auth-security
docs/rage-129-merge-outcome
rage/129-zara1-protocol
rage/129-slice-e-lifecycle-red
rage/129-slice-e-endpoint-red
docs/rage-128-merge-outcome
rage/139-daemon
docs/full-feature-sweep
feature/mcp-client-support-current
remove-prolog-rlm
research/daemon-zeromq-voice-service
feature/autoresearch-bootstrap
agent/VAD-patch
agent/prolog-capability-reasoner
agent/whisper-cpp-vulkan-stt
agent/remove-pet-notification-spam
codex/service-plugin-runtime
agent/stt-backends
agent/fix-laptop-stt-quality
feature/prolog-rlm-integration
agent/fix-speaker-echo-loop
agent/stt-gpu-rocm-support
agent/fix-ubuntu-wayland-pets
feature/desktop-theme-contrast
fix/whisper-load-state
agent/mcp-client-support
fix/wake-model-readiness-debug
fix/wake-capture-failure-propagation
fix/wake-audio-health
agent/readme-current-zara
fix/desktop-conversation-migration-repair
agent/fix-voice-runtime-noise
feature/desktop-launch-surface
feature/quick-copilot
feature/conversation-full-chat
feature/desktop-shell
feature/runtime-host
feature/runtime-events
research/desktop-copilot
agent/overhaul-memory-forgetting
agent/fix-command-context-routing
agent/fix-streaming-vad-wake
agent/pets-post-merge-fixes
feature/pets
revert/wake-throughput
fix/wake-word-detection
fix/pulse-shared-mic-ci
fix/shared-mic-capture
feat/zara-timer-alarm-sounds
fix/zara-017-todo-correctness
fix/zara-015-prolog-engine-contract
fix/zara-018-ack-result-events
agent/readme-rewrite
fix/zara-014-wake-lifecycle
fix/zara-013-file-tool-sandbox
fix/zara-012-process-safety
fix/recover-zara-006-011-to-master
revert-36-fix/zara-005-dictation-lifecycle
revert-44-fix/zara-011-dictation-ordering
fix/zara-010-tts-contracts
fix/zara-011-dictation-ordering
fix/zara-007-intent-precedence
fix/zara-008-multi-tool-history
fix/zara-009-memory-fallback
fix/zara-006-timers
fix/zara-005-dictation-lifecycle
fix/zara-003-fail-closed-commands
fix/zara-004-prolog-config-overrides
agent/ci-test-gate
fix/zara-002-config-toml
fix/zara-001-wake-entrypoint
memory
cleanup
device-acceptance-661
v0.1.0-alpha
Labels
Clear labels
bug
Something isn't working
documentation
Improvements or additions to documentation
duplicate
This issue or pull request already exists
enhancement
New feature or request
good first issue
Good for newcomers
help wanted
Extra attention is needed
invalid
This doesn't seem right
question
Further information is requested
wontfix
This will not be worked on
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set.
Reference
nsaspy/zara#346
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Mission
Continuously advance Zara Core and Android with Android usability as the primary product bar. This worker owns implementation slices where mobile/runtime integration is the limiting factor and must keep the phone app useful under connected, offline, degraded and lifecycle-stressed conditions.
Stagger slot
Start after Frontier Research (+00) and Cross-Repo Review (+15). Preserve the relative stagger if cadence changes.
Primary queue
Android-first acceptance bar
Every Android slice must consider and test, where applicable:
Deep-testing contract
No feature-only PR. Before merge, add the strongest relevant layers:
Every discovered bug gets a deterministic regression case before repair when practical. No
xfail, skip, fake-success sentinel or swallowed exception may satisfy acceptance.Feature-expansion rule
Choose one bounded dependency-satisfied feature slice at a time. Prefer features that materially improve daily phone use: offline commands, reliable chat, activation, voice, local device actions, notifications/tasks/calendar, reconnect and clear capability/degraded state.
Current architecture
Current
masterpermits pinned Prolog-RLM use in bounded direct-mode where explicitly designed. Prolog/typed runtime policy remains side-effect authority; model/RLM outputs are proposals until validated. Android must not fork a second unrelated assistant/runtime/memory stack.State loop
Output contract
Guardrails
master.WORKER_STATE
worker: core-android
mode_used: RESEARCH
result: Reconciled current master/roadmap/plugin handoffs and froze Core #400 as the next dependency-satisfied slice: add one Core-owned, authorization-preserving plugin capability composition seam with generation/stale-state fencing; do not start later Android/offline expansion while this higher-priority plugin blocker is open.
issue_or_pr: lost-rob0t/zara#400; related zara-plugins#507; Android context #622/#152/#194
head:
207e3b6893android_tests: No new tests run in RESEARCH. Exact-head GitHub checks on master are green: android skeleton gate, build/publish Android alpha, shared-mic Ubuntu/Arch, and repository test job all completed successfully at this SHA. Android source already contains the in-repo app, portable Prolog assets, typed open_uri/open_app adapters, assistant-role/voice plumbing, and authenticated session controller; offline-first #622 remains incomplete and is not claimed done.
core_tests: No local/new tests run in RESEARCH. Current PluginRuntime source exposes config/status/RuntimeCommand dispatch/event subscription/managed workers/agent-loop advice but no Core-owned cross-plugin capability lookup/invocation seam, matching #400's blocker. Next IMPLEMENT must add RED tests first for principal/capability preservation, unavailable/disabled target, stale handle after unload/reload, caller runtime shutdown, structured failure, and no raw plugin/tool object escape; then run focused plugin API tests plus full repo/Nix/Android gates at exact head.
plugin_handoffs: zara-plugins#507 confirms zara-coding cross-plugin expansion remains blocked on lost-rob0t/zara#400; its worker explicitly refuses private imports/parallel registries. Core should unblock that consumer without importing plugin internals.
blockers: none for the frozen #400 Core slice. Guardrails retained: no Prolog-RLM runtime dependency in this Core slice; model/Prolog data cannot widen callable authority; SmartThings credentials remain server-side; Android continues to reuse shared semantic/runtime contracts.
next_mode: IMPLEMENT
next_target: lost-rob0t/zara#400 — tests-first canonical PluginRuntime capability composition contract using opaque/generation-bound Core resolution and invocation, preserving target authorization/approval/principal semantics and failing stale/unloaded handles closed.
WORKER_STATE
worker: core-android
mode_used: IMPLEMENT
result: Opened draft PR #659 for the first tests-first Core #400 slice: opaque generation-bound CapabilityHandle resolution/invocation in PluginRuntime plus PluginManager stale-caller/provider fencing and fail-closed approval-policy recheck. I explicitly did not wire production invocation by reaching through LangGraphRuntimeBackend private state or trusting plugin/model metadata as approval authority.
issue_or_pr: lost-rob0t/zara#400; PR #659
head:
eb902a56ebandroid_tests: Exact-head CI run 34102832586 started. android skeleton gate (unit/native Trealla/debug APK/secret inspection) is currently in progress; shared-mic Ubuntu/Arch jobs are also in progress. No Android product behavior changed in this slice.
core_tests: RED contract was committed first at
2cc84234e0. New tests cover opaque/no-raw-object handles, caller identity propagation, structured request copying, closed-runtime failure, invalid-handle/request rejection, and explicit unavailable resolution. Exact-head repository test job is currently runningRun all tests; whitespace is green and Nix install completed. Flake/package gates remain pending in the same run.plugin_handoffs: zara-plugins#507 remains blocked for production composition. PR #659 establishes the public/generation-fencing half of the seam but intentionally fails composition unavailable until Core has a canonical backend hook that queries ToolRegistry approval authority and executes through an authorization-preserving principal-bound path. Do not consume private Core/backend internals as a workaround.
blockers: Production backend/host invocation hook is still required before #400 can close. Existing LangGraph tool execution couples approval to turn/tool-run state; direct
tool.invokewould bypass that contract. The next slice must expose a narrow Core backend executor that derives approval from canonical ToolRegistry state, preserves the backend principal, rejects approval-required calls unless routed through an explicit approved context, and never exposes raw tool/plugin objects. Current PR stays draft; no false claim that #400 or Android/offline work is complete.next_mode: IMPLEMENT
next_target: Continue #400 on PR #659: add tests-first canonical RuntimeBackend/LangGraph composition executor + RuntimeHost wiring, including configured-approval recheck, principal ownership, stale-generation policy-change rejection, structured bounded failures, and exact-head repo/Nix/Android gates. Then REVIEW adversarially before merge.
WORKER_STATE
worker: core-android
mode_used: IMPLEMENT
result: Advanced Core #400 on draft PR #659 with the next tests-first bounded slice: ToolRegistry now owns a canonical composed-tool execution method that accepts only structured mappings, resolves through the per-backend canonical registry, fails missing tools explicitly, and re-checks approval policy immediately before invocation so approval-required capabilities cannot be called through the composition seam.
issue_or_pr: lost-rob0t/zara#400; PR #659
head:
f6644f1af6android_tests: Exact-head CI run 34108123445 is in progress. At this checkpoint the Android skeleton gate (unit/native Trealla/debug APK/secret inspection) is running; shared-mic Arch is green and Ubuntu has completed its audio tests/probe and is finishing teardown. No Android behavior changed in this slice.
core_tests: Previous exact-head
eb902a56ebCI was fully green. For this slice the RED contract was committed first at9ed9e9d70c, covering canonical registry invocation, configured approval denial, missing-tool failure, and non-mapping rejection. GREEN isf6644f1af6. Current exact-head run 34108123445 has whitespace and Nix install green; repositoryRun all testsis in progress, with flake/package/screenshot gates pending behind it.plugin_handoffs: zara-plugins#507 remains blocked from production cross-plugin calls until RuntimeHost wires PluginManager to the principal-owned RuntimeBackend/ToolRegistry seam. This slice deliberately provides the canonical registry execution primitive instead of letting PluginManager reach into LangGraph private state or call raw tools itself.
blockers: #400 is not complete. RuntimeBackend still lacks narrow public
requires_approval/ composed invocation hooks and RuntimeHost does not yet inject those hooks into PluginManager. PR #659 also predates current masterfe6e8eee30(the idle TTS CPU fix), so final review/merge must refresh exact-current base and rerun all gates. No Prolog-RLM runtime dependency was added; SmartThings/server-device placement is untouched.next_mode: IMPLEMENT
next_target: Continue PR #659 with tests-first RuntimeBackend/LangGraph + RuntimeHost wiring: expose only principal-bound ToolRegistry policy/invocation methods, inject them into PluginManager, prove no cross-principal/raw-tool escape and approval-required fail-closed behavior, then refresh onto current master and run exact-head repo/Nix/Android gates before REVIEW.
WORKER_STATE
worker: core-android
mode_used: IMPLEMENT
result: Advanced Core #400 on draft PR #659 with the tests-first RuntimeBackend/RuntimeHost wiring slice. Added backend-owned composition policy/invocation hooks, bound invocation to the RuntimeHost backend principal, delegated only through the canonical ToolRegistry executor, and kept PluginManager away from raw LangGraph manager/tool internals. Cross-principal calls fail before registry execution; stopped backends fail closed.
issue_or_pr: lost-rob0t/zara#400; PR #659
head:
8bc488533dandroid_tests: Previous exact-head
f6644f1af6run 34108123445 completed fully green, including Android skeleton gate and shared-mic Ubuntu/Arch. New exact-head run 34113716282 is active at8bc488533d; Arch shared-mic is green while Android skeleton, Ubuntu shared-mic, and repository test job are still in progress at this checkpoint. No Android behavior changed in this Core slice.core_tests: Tests landed before production wiring:
307976c3cbadded the backend/host composition contract and910f02aef0tightened host principal binding. Production commits aree4d19c916b(RuntimeBackend/LangGraph/Agent facade hooks) and8bc488533d(RuntimeHost injection). Compare from prior green headf6644f1shows only one new test file plus +45 backend lines and +7 host lines, with no unrelated deletions.plugin_handoffs: zara-plugins#507 can consume the public composition seam only after #659 passes exact-head gates and adversarial review. The seam preserves generation fencing and policy re-resolution already in PluginManager, uses canonical ToolRegistry approval state, and does not expose plugin instances, mutable registries, or raw tools.
blockers: Exact-head
8bc4885gates are still running, and PR #659 still has an older recorded base than current masterfe6e8eee30. Do not merge yet. Refresh onto current master and rerun exact-head repo/Nix/Android gates before final review. No Prolog-RLM runtime dependency added; SmartThings/server-device placement untouched.next_mode: IMPLEMENT
next_target: Finish #400/PR #659 integration gate: refresh fix/400-plugin-capability-composition onto current master
fe6e8eee30, resolve only real conflicts, rerun exact-head repository/Nix/Android checks, then set next_mode REVIEW for adversarial principal/capability/cancellation/stale-generation inspection if green.WORKER_STATE
mode_used: IMPLEMENT
result: Refreshed Core #400 / PR #659 onto current master without touching master. Reused GitHub's conflict-free merge result tree and created feature-branch merge commit
898188d300831d1cce361d346371a684b1e90d7dwith feature head8bc488533d60053a3c672693e006e43ae5e5ed21as first parent and masterfe6e8eee30d6beb153c2a399a79d325e017f2b02as second parent, then fast-forwarded onlyfix/400-plugin-capability-composition. PR #659 is still draft/open and mergeable. Current master was re-read after the write and is unchanged atfe6e8eee30d6beb153c2a399a79d325e017f2b02.refs: #623, roadmap #1, Core #400, PR #659, plugin handoff #507, Android PR #661, Samsung/Android #206
head:
898188d300831d1cce361d346371a684b1e90d7dtests: No new behavior was introduced in this refresh-only slice; the branch retains its tests-first composition commits (latest recorded RED
9ed9e9d70c741db14132b7970a61ebc104367628, GREENf6644f1af600c9e3a802d1b6a0736881694bdd90). Previous exact-head CI run34113716282for8bc4885...was cancelled/incomplete, so it is not treated as green. New exact-head CI run34119083677for898188d...is queued; required repo/Nix/Android gates therefore remain unproven at this head.plugin_handoffs: #507 remains downstream of #400's canonical composition seam. Composition still stays Core-owned through opaque generation-bound handles, principal-bound RuntimeBackend/RuntimeHost hooks, and canonical
ToolRegistry.invoke_composed_tool()approval re-checks; no raw tool/private manager escape was added. SmartThings credentials remain server-side. Core still has no Prolog-RLM runtime dependency. Android was intentionally not modified because roadmap/dependency order still places this Core blocker first; when Android resumes it must reuse the shared semantic/runtime contracts rather than create a duplicate runtime.blockers: Exact-head run
34119083677must complete successfully across repository/Nix/Android gates. Adversarial cancellation/stale-turn fencing, principal ownership/capability authorization, duplicate-runtime/insecure-fallback checks remain REVIEW work after the gate is clean. PR #659 must not be merged before that review.next_mode: IMPLEMENT
next_target: Re-read exact-head
898188d300831d1cce361d346371a684b1e90d7dCI run34119083677; if any required gate fails, inspect and fix that regression tests-first on the same focused PR. If all required gates are green, record the evidence and switch the following loop to REVIEW of PR #659 before any Android slice.WORKER_STATE
worker: core-android
mode_used: IMPLEMENT
result: Re-read refreshed Core #400 / PR #659 at exact head and found the required repository gate did not fail semantically; CI run 34119083677 hit the workflow's 30-minute job timeout while still inside
scripts/test-all.sh. Android skeleton and both shared-mic jobs were green. To distinguish runner/transient slowdown from a deterministic regression without changing production code or weakening the gate, created an empty feature-branch rerun commit5ef1b8961ec931421cb57fa8368b06f3e59dd292pointing at the exact same tree as898188d...; new exact-head CI run 34125242454 is active. No direct master commit and no merge.issue_or_pr: #623; roadmap #1; Core #400; draft PR #659; plugin handoff zara-plugins#507; Android PR #661; Samsung/hardware #206
head:
5ef1b8961eandroid_tests: Prior refreshed-head run 34119083677:
android skeleton gateSUCCESS, shared mic Arch SUCCESS, shared mic Ubuntu SUCCESS. New exact-head run 34125242454 is in progress for the identical source tree. No Android behavior changed; #661 remains a separate UI PR and #206 remains hardware-gated by its declared dependencies.core_tests: Run 34119083677 had whitespace + Nix setup green, then
Run all testswas cancelled at the job's configuredtimeout-minutes: 30; flake/package/screenshot steps were therefore skipped. This is not accepted as a green gate. The same composition tree previously passed full CI before the master refresh; the refresh added only current-master changes (notably #660 TTS idle-yield fix plus Android design docs). Current PR source was re-inspected: composition remains Core-owned through opaque generation handles, PluginManager stale caller/provider fencing, principal-bound RuntimeBackend/RuntimeHost hooks, and canonicalToolRegistry.invoke_composed_tool()approval re-checks; no raw tool/private manager escape was introduced.plugin_handoffs: zara-plugins#507 still treats lost-rob0t/zara#400 as the blocker for production cross-plugin composition and has not bypassed Core internals. SmartThings credentials remain server-side. Core has no Prolog-RLM runtime dependency in this slice. Android continues to reuse shared semantic/runtime contracts and no duplicate assistant/runtime path was added.
blockers: Exact-head run 34125242454 must finish. If it again reaches the 30-minute timeout in
Run all tests, treat that as a reproducible current regression rather than raising the timeout: isolate the hanging/slow phase tests-first, with special attention to the only behavior change pulled from master since the prior green base (TtsOutputBridge._wait_for_tasks()idle sleep from #660), then fix on a focused branch/PR before returning to #659. PR #659 remains draft/unmerged; adversarial principal/capability/cancellation/stale-turn review still follows only after a clean exact-head gate.next_mode: IMPLEMENT
next_target: Inspect exact-head CI run 34125242454 for
5ef1b896.... If green, record exact-head evidence and switch the following loop to REVIEW of PR #659. If the test job times out again, isolate the deterministic slow/hanging test phase and repair that regression tests-first without weakening CI timeouts.WORKER_STATE
worker: core-android
mode_used: IMPLEMENT
result: The identical-tree rerun for Core #400 / draft PR #659 reproduced the 30-minute repository-gate timeout, and the uploaded JUnit artifact proved this was not merely a slow runner: pytest completed 2,126 tests in ~255s and recorded 10 failures, mostly service-plugin lifecycle failures. Root cause was the new RuntimeHost composition wiring unconditionally reading
backend.principal_id; valid RuntimeBackend implementations that do not support composition raiseUnsupportedRuntimeCommand, causing_start_plugins()to abort before PluginManager starts. Added a focused RED regression first at7b61c0819dbbf1924df783b15af0fa7887bfbafc, then fixed RuntimeHost at49ed54c433058b55597b7932692d37b563a7b9c6so composition hooks are injected only when the backend exposes a real principal; otherwise ordinary plugins still start while composition remains unavailable/fail-closed. Also corrected the composition-hook test to assert bound-method behavior/ownership rather than invalid Python bound-method object identity. No master commit and no merge.refs: #623; roadmap #1 and its 2026-09-07 reconciliation; Core #400; draft PR #659; plugin handoff zara-plugins#507; Android UI PR #661; Samsung/Android #206
head:
49ed54c433058b55597b7932692d37b563a7b9c6tests: Exact-head run
34125242454for prior head5ef1b896...completed CANCELLED at the configured 30-minute test-job timeout. Android skeleton SUCCESS, shared-mic Ubuntu SUCCESS, shared-mic Arch SUCCESS.regression-artifactsJUnit shows pytest itself reached completion in ~254.978s with 2,126 cases and 10 failures; nine failures were consistent with PluginManager never starting, and one was the invalid bound-method identity assertion. Tests-first RED commit7b61c081...adds the unsupported-composition backend regression and repairs that assertion; GREEN commit49ed54c4...changes onlyzara/runtime/host.pyrelative to RED (+15/-7), preserving the rest of the branch. New exact-head CI run34130940878is queued for49ed54c4...; repo/Nix/package/screenshot gates are therefore not yet proven on this head.plugin_handoffs: zara-plugins#507 remains downstream of #400. The fix does not create a synthetic principal, expose raw tools/private manager state, or weaken approval policy. Principal-capable LangGraph backends still bind composed invocation to the runtime principal and canonical ToolRegistry; unsupported backends now keep non-composition plugin lifecycle working while capability resolution/invocation stays unavailable. Android remains behind this Core blocker; PR #661 is still separate UI work and no duplicate Android runtime was introduced. SmartThings credentials remain server-side. This slice adds no Prolog-RLM runtime dependency to Core.
blockers: Exact-head run
34130940878must complete. If the repository job still fails or hangs, inspect its fresh JUnit/artifacts and fix the remaining concrete regression tests-first without raising the CI timeout. PR #659 remains draft/unmerged. Adversarial principal/capability/cancellation/stale-generation review is still required after a clean exact-head gate.next_mode: IMPLEMENT
next_target: Re-read exact-head CI run
34130940878for49ed54c433058b55597b7932692d37b563a7b9c6. If all required repository/Nix/package/Android/shared-mic gates are green, switch the following loop to REVIEW of PR #659. If not, isolate the remaining failing/hanging phase from exact-head artifacts and repair it tests-first on the same focused PR.WORKER_STATE
worker: core-android
mode_used: IMPLEMENT
result: Re-read the recorded IMPLEMENT target and verified the repaired Core #400 / draft PR #659 exact head is now fully green. No additional source change was justified: the prior tests-first regression fix at
49ed54c433058b55597b7932692d37b563a7b9c6resolved the PluginManager startup regression, current master is unchanged atfe6e8eee30d6beb153c2a399a79d325e017f2b02, and PR #659 is mergeable but remains draft for the required adversarial review. Updated the PR body so it no longer falsely says RuntimeBackend/RuntimeHost wiring is still missing and now records the exact-head gate evidence and fail-closed approval limitation.issue_or_pr: Core #400; draft PR #659; roadmap #1; Android UI PR #661; Android/offline context #622/#152/#194/#206
head:
49ed54c433058b55597b7932692d37b563a7b9c6android_tests: Exact-head CI run
34130940878SUCCESS.android skeleton gatepassed unit tests + native Trealla + debug APK + secret inspection; shared-mic Ubuntu 24.04 SUCCESS; shared-mic Arch Linux SUCCESS. No Android source was changed in this loop; PR #661 remains separate and later Android work stays behind the Core blocker/review in roadmap order.core_tests: Exact-head
testjob SUCCESS: whitespace,Run all tests, Nix flake checks, packaged Zara build, deterministic Copilot screenshots, and artifact upload all passed. Prior tests-first regression sequence remains RED7b61c0819dbbf1924df783b15af0fa7887bfbafc-> GREEN49ed54c433058b55597b7932692d37b563a7b9c6. Current source keeps principal-boundLangGraphRuntimeBackendcomposition, canonicalToolRegistryinvocation/policy recheck, cross-principal rejection before registry execution, and unsupported-backend lifecycle compatibility without synthesizing a principal.plugin_handoffs:
zara-plugins#507can treat #659 as the candidate Core unblocker after review/merge. It must still consume only the publicPluginRuntimecapability seam; no private backend/manager imports or parallel registry/runtime. Approval-required tools remain intentionally non-composable until a canonical approved-context contract exists. SmartThings credentials stay server-side; Core has no Prolog-RLM runtime dependency; Android continues to reuse shared semantic/runtime contracts.blockers: No failing exact-head gate remains. The only blocker before merge/closing #400 is the mandated adversarial REVIEW of PR #659, specifically principal ownership, capability authorization, cancellation/stale-turn and generation fencing, policy-change behavior, duplicate-runtime/private-state escapes, Prolog authority, server-vs-device placement, and insecure fallbacks. PR #659 stays draft and unmerged until that review.
next_mode: REVIEW
next_target: Adversarially review draft PR #659 at exact head
49ed54c433058b55597b7932692d37b563a7b9c6. If review is clean, make it review-ready/mergeable and hand off #400 to plugins; if a concrete flaw is found, add a deterministic RED regression first and return to IMPLEMENT on the same focused PR.WORKER_STATE
worker: core-android
mode_used: REVIEW
result: Exact-head adversarial review found Core #400 / draft PR #659 is not merge-ready despite green CI: composed capability execution preserves principal equality and approval rechecks, but bypasses the canonical turn/cancellation plane and has a generation/lifecycle TOCTOU between caller/provider validation and actual tool execution. Posted blocking review
5133751703; PR remains draft/unmerged.issue_or_pr: Core #400; draft PR #659; review 5133751703
refs: #623; roadmap #1 + 2026-09-07 reconciliation; Core #400; PR #659; zara-plugins worker #507 and #400 handoff comment; Android UI PR #661; offline Android #622; Android #152/#194/#206; exact-head CI run 34130940878
head:
49ed54c433058b55597b7932692d37b563a7b9c6tests: No new tests were added in REVIEW. Exact-head CI run
34130940878remains completed/SUCCESS at this head. Source/diff review found no cancellation context or cancellation regression in the composition path:PluginRuntime.invoke_capability()carries caller/handle/request only;PluginManager._invoke_capability()validates caller/provider generation then releases its lock;LangGraphRuntimeBackend.invoke_composed_tool()delegates toToolRegistry.invoke_composed_tool(); the registry directly performs synchronoustool.invoke(dict(request)). The PR diff contains no cancellation coverage. Green CI therefore does not prove the required cancellation/stale-in-flight contract.android_tests: No Android source changed in this REVIEW. Existing exact-head run
34130940878remains green for Android skeleton unit/native Trealla/debug APK/secret inspection plus Ubuntu/Arch shared-mic jobs. PR #661 remains separate UI work and #622 offline-first work remains later in dependency order.core_tests: No new Core tests in REVIEW. Existing principal ownership check, approval-policy re-resolution, approval-required fail-closed behavior, malformed/missing request handling, unsupported-backend compatibility, and stale-handle-at-entry generation checks were inspected and remain directionally sound. Blocking gap is cancellation/in-flight lifecycle fencing rather than those already-covered contracts.
plugin_handoffs:
zara-plugins#507remains blocked on #400 for production composition. The #400 handoff explicitly requireszara-shelltest.run/build.runcomposition to preserve cancellation policy; current naked registry invocation cannot carry that contract. Plugins must continue using only the public Core seam and must not import private backends/tools or create a parallel registry/runtime. Approval-required tools remain intentionally non-composable until a canonical approved-context contract exists.blockers: Add deterministic RED coverage for (1) cancellation/stale-turn fencing of an in-flight composed invocation, (2) caller/provider stop or unload after handle validation but before/during execution, and (3) the intended caller-capability authorization model. Then minimally route composition through a Core-owned cancellable execution context tied to runtime/generation ownership instead of naked
ToolRegistry.tool.invoke, while preserving principal equality, approval rechecks and fail-closed behavior. Keep SmartThings credentials server-side; add no Core Prolog-RLM runtime dependency in this slice; Android must continue reusing shared semantic/runtime contracts.next_mode: IMPLEMENT
next_target: Continue #400 on draft PR #659 tests-first: reproduce cancellation and stop/unload races, add a bounded Core-owned composition execution/cancellation context with generation ownership, explicitly prove or enforce caller-capability authorization, then rerun focused tests plus full exact-head repo/Nix/Android/shared-mic gates before returning to REVIEW.
WORKER_STATE
worker: core-android
mode_used: IMPLEMENT
result: Advanced Core #400 / draft PR #659 with a tests-first fix for the REVIEW-discovered provider-unload TOCTOU. Added deterministic RED coverage proving
PluginManager.stop()must not overtake an already-accepted composed invocation, then changedPluginManager._invoke_capability()so caller/provider generation validation, approval-policy re-resolution, and canonical invocation remain under the manager lifecycle lock. This removes the validation->execution gap without exposing raw tools/private runtime state or weakening approval policy. Cancellation/stale-turn propagation is still unresolved, so PR #659 remains draft/unmerged.issue_or_pr: Core #400; draft PR #659; blocking review 5133751703
refs: #623; roadmap #1 + 2026-09-07 reconciliation; Core #400; PR #659; zara-plugins#507 handoff; Android UI PR #661; offline Android #622; Android #152/#194/#206
head:
210b4088e036c511070aa8d3dea5ad106b1e4601android_tests: No Android source changed. Previous exact-head
49ed54c4...Android skeleton + Ubuntu/Arch shared-mic gates were green. At this checkpoint GitHub has not yet materialized a workflow/check run for new exact head210b4088..., so repo/Nix/Android gates are pending and are not claimed green.core_tests: Tests-first RED commit
ade56b105b02e4e143d1eb74557b38032d969096addstest_inflight_composed_invocation_fences_provider_unload: a blocking canonical invocation starts, manager stop is requested concurrently, and the test requires stop/unload to remain blocked until invocation completes. GREEN commit210b4088e036c511070aa8d3dea5ad106b1e4601keeps the manager RLock across accepted invocation validation, approval recheck, and invoker return. This directly closes the reviewed generation/lifecycle TOCTOU. No local shell/Nix execution was available in this connector-only loop; exact-head Actions were queried immediately after push and had not appeared yet.plugin_handoffs: zara-plugins#507 remains blocked for production composition. The lifecycle race is now fenced, but
zara-shelltest.run/build.runstill cannot inherit a canonical turn/cancellation context throughPluginRuntime.invoke_capability(). Plugins must continue using only the public Core seam; no private backend/tool imports or parallel registry/runtime. SmartThings credentials stay server-side. Core gains no Prolog-RLM runtime dependency. Android remains behind this Core blocker and continues to reuse shared semantic/runtime contracts.blockers: The REVIEW cancellation finding remains:
PluginRuntime.invoke_capability()still has no turn/cancellation context, and canonicalToolRegistry.invoke_composed_tool()remains synchronous. Add deterministic RED coverage for cancellation/stale-turn fencing and caller stop during in-flight execution, then introduce the smallest Core-owned cancellable execution context tied to runtime/generation ownership without allowing model/plugin metadata to widen authority. Caller capability authorization also still needs an explicit proven contract. New exact-head repo/Nix/Android/shared-mic gates must run before REVIEW.next_mode: IMPLEMENT
next_target: Continue #400 on PR #659 tests-first: add a bounded Core-owned composition execution/cancellation context that can be invalidated by caller shutdown/turn cancellation and fences stale results, explicitly prove/enforce caller-capability authorization, then run focused + full exact-head repository/Nix/Android/shared-mic gates before returning to REVIEW.
WORKER_STATE
worker: core-android
mode_used: IMPLEMENT
result: Re-read the latest #623 state, roadmap #1, Core #400/draft PR #659, Android #622/PR #661, exact-head CI, and the current composition source. The previous lifecycle-fencing GREEN
210b4088e036c511070aa8d3dea5ad106b1e4601was not actually green: exact-head run34144988693failed its repository test job, and the regression artifact showed the existing tests-first unload race case deadlocked because_invoke_capability()held the manager RLock across the synchronous tool call whilemanager.stop()blocked the asyncio runtime trying to acquire that lock. Kept the existing deterministic RED (ade56b105b02e4e143d1eb74557b38032d969096) and repaired the same focused PR at3ff2f9bd74f3fcbaaf2720ae7cd66431d65856ad: accepted composed calls now take caller/provider lifecycle leases under the manager lock, release the lock for canonical execution, and drain those leases during shutdown via a worker-thread condition wait so stop/unload cannot overtake accepted work without blocking the runtime event loop. New calls fail once manager/record shutdown starts. No master commit and no merge.issue_or_pr: Core #400; draft PR #659; Android offline epic #622; Android UI PR #661
refs: #623; roadmap #1; Core #400; PR #659; blocking review 5133751703; zara-plugins#507 handoff; Android #622/#152/#194/#206; Android PR #661; prior failing exact-head run 34144988693; new run 34149518220
head:
3ff2f9bd74f3fcbaaf2720ae7cd66431d65856adandroid_tests: No Android source changed. Prior head
210b4088...had Android skeleton SUCCESS and both shared-mic jobs SUCCESS even though the Core repository job failed. New exact-head run34149518220is active at3ff2f9bd...; shared-mic Arch is already SUCCESS, while Android skeleton and Ubuntu shared-mic are still in progress at this checkpoint. #622 still requires an offline symbolic runtime behind the shared client/runtime abstraction, and #661 remains separate UI work; neither is advanced ahead of this Core blocker.core_tests: Existing tests-first RED
ade56b105b02e4e143d1eb74557b38032d969096deterministically exposed the provider-unload race. Exact-head210b4088...JUnit contained 2,128 tests with one failure:test_inflight_composed_invocation_fences_provider_unload, proving an event-loop deadlock in the lock-across-invoker implementation. GREEN candidate3ff2f9bd...replaces lock-across-execution with per-record active-invocation leases +threading.Condition;_stop_record()marks shutdown first, rejects new composition, and awaits lease drain throughasyncio.to_thread, preserving event-loop progress. New exact-headtestjob is currently runningRun all tests; Nix flake/package/screenshot steps therefore remain pending and are not claimed green.plugin_handoffs: zara-plugins#507 remains blocked for production composition until #659 also gains the reviewed cancellation/stale-turn and explicit caller-capability authorization contract. Plugins must use only public
PluginRuntimecomposition; no private backend/tool imports or parallel registry/runtime. SmartThings credentials remain server-side. Core gains no Prolog-RLM runtime dependency. Android continues to reuse shared semantic/runtime contracts rather than forking a second assistant/runtime.blockers: Exact-head run
34149518220must complete successfully across repository/Nix/package/Android/shared-mic gates. More importantly, the original REVIEW blockers remain after this regression repair: composition still lacks a Core-owned turn/cancellation context for caller shutdown/turn cancellation and stale-result fencing, and caller-to-capability authorization is not yet explicit. Approval-required tools continue to fail closed; do not weaken that policy.next_mode: IMPLEMENT
next_target: First re-read exact-head run
34149518220for3ff2f9bd74f3fcbaaf2720ae7cd66431d65856adand fix any concrete failure tests-first. Once green, continue #400/#659 with deterministic RED cases for caller shutdown/turn cancellation + stale result rejection and unauthorized caller capability access, then add the smallest Core-owned cancellable composition execution context tied to runtime/generation ownership. Run focused + full repo/Nix/Android/shared-mic gates before returning to REVIEW.WORKER_STATE
worker: core-android
mode_used: IMPLEMENT
result: Re-read #623/latest state, roadmap #1 + 2026-09-07 reconciliation, Core #400/draft PR #659, Android offline #622/UI PR #661, exact-head checks, and current composition/TurnCoordinator source. First verified prior head
3ff2f9bd74f3fcbaaf2720ae7cd66431d65856adis fully green in CI run34149518220across repository/Nix/package, Android skeleton, and Ubuntu/Arch shared-mic gates. Then advanced #659 tests-first: RED commit57f88760a92c5378d8a3c298e9ece701dae1d484adds cross-plugin caller authorization and in-flight turn-cancellation stale-result regressions. Production commitsba7e4fbbeae98858d4ebd328b4aa82b7cb99f608and3ff9450574a89441c3c798756615967ce90d68b8add explicitcompose_capabilitiesallowlisting for cross-plugin resolution/invocation, Core-owned active invocation records tied to caller/provider generations, cancellation marking and stale-result rejection, lifecycle cancellation before lease drain, and an optionalturn_idon publicPluginRuntime.invoke_capability()without putting cancellation metadata into the tool request. No master commit and no merge.refs: #623; roadmap #1 + reconciliation comment 5566663947; Core #400; draft PR #659; blocking review 5133751703; zara-plugins#507 handoff; Android offline #622; Android UI PR #661; Android #152/#194/#206; prior exact-head run 34149518220; new exact-head run 34153467550
head:
3ff9450574a89441c3c798756615967ce90d68b8tests: Prior head
3ff2f9bd...is now proven fully green by run34149518220. New tests were committed before the production authorization/cancellation implementation in57f88760...: authorized caller resolvesprovider.read, unauthorized caller fails closed, and cancellingturn-1while a composed call is in flight requires the stale result to be rejected after the underlying synchronous invocation returns. New exact-head CI run34153467550is queued at3ff94505...; therefore repo/Nix/package/Android/shared-mic gates are pending and are not claimed green. The current implementation deliberately fences stale results rather than pretending synchronous LangChain tools are forcibly preemptible.plugin_handoffs: zara-plugins#507 remains blocked until #659 completes canonical host cancellation wiring and adversarial review. Cross-plugin composition now requires the caller plugin configuration to list the exact target capability in
compose_capabilities; same-plugin self-composition remains implicit, and invocation re-checks authorization so policy changes fail closed. Approval-required tools still fail closed through the canonical registry path. Plugins still receive no raw tool/plugin/manager objects. SmartThings credentials remain server-side. This slice adds no Prolog-RLM runtime dependency to Core. Android remains behind this Core blocker and #622 continues to require one shared local/remote runtime abstraction with Prolog/typed action authority.blockers: Exact-head run
34153467550must complete. One reviewed cancellation integration gap remains before REVIEW: RuntimeHost's canonicalCancelTurnpath owns turn cancellation, but it does not yet callPluginManager.cancel_capability_turn(turn_id), so the new turn-correlated public composition context is not yet automatically invalidated by the host coordinator. Wire that existing Core authority without creating a second turn runtime, add a deterministic RuntimeHost regression provingCancelTurninvalidates matching composed invocations, and re-run all gates. Also adversarially verifycompose_capabilitiespolicy parsing/fail-closed behavior and that caller-suppliedturn_idis correlation only and cannot widen authority.next_mode: IMPLEMENT
next_target: Finish #400/#659 cancellation integration on the same focused PR: after reading exact-head run
34153467550, add the RuntimeHost RED regression first, wire canonical_cancel_turn/task cancellation toPluginManager.cancel_capability_turn(turn_id)without duplicating TurnCoordinator authority, then run focused + full exact-head repo/Nix/Android/shared-mic gates. If green, set next_mode REVIEW for principal/capability/cancellation/stale-generation/insecure-fallback review before any Android implementation slice.WORKER_STATE
worker: core-android
mode_used: IMPLEMENT
result: Re-read #623/latest WORKER_STATE, roadmap #1, Core #400/draft PR #659, current exact-head CI and current composition/lifecycle source. Exact-head run 34153467550 at
3ff9450574failed one deterministic repository test while Android skeleton and both shared-mic lanes passed. JUnit artifactregression-artifactsproves 2,131 tests ran in ~240s with exactly one failure:test_inflight_composed_invocation_fences_provider_unload. Root cause: the new turn-cancellation bookkeeping also marked every accepted capability invocation cancelled when_stop_record()began, contradicting the existing lease contract that shutdown must setstop_called, reject new work, then drain already-accepted calls before unload. Fixed only that regression on PR #659 at00cd7f929f91c238a0d910dbd4af712b1dbe41a7by removing lifecycle-stop cancellation marking; explicitcancel_capability_turn(turn_id)remains the only path that invalidates an in-flight turn result. No master commit and no merge.issue_or_pr: lost-rob0t/zara#400; draft PR #659; worker #623
head:
00cd7f929fandroid_tests: Prior exact-head run 34153467550 on
3ff94505: Android skeleton gate SUCCESS (unit/native Trealla/debug APK/secret inspection), shared-mic Ubuntu SUCCESS, shared-mic Arch SUCCESS. No Android product code changed this loop. New head has no materialized Actions run yet, so Android/Nix/package gates are not claimed green for00cd7f92.core_tests: Prior run 34153467550 repository job FAILED only in
test_inflight_composed_invocation_fences_provider_unload; JUnit artifact reported 2,131 tests, 1 failure, 0 errors, ~239.9s. The failing test is the deterministic regression case and showed shutdown was incorrectly converting an accepted no-turn invocation intoRuntimeError: composed invocation was cancelled or became stale. Commit00cd7f92is a focused -3-line production repair preserving lease-drain semantics. Fresh exact-head CI has not materialized yet; full repo/Nix/package/screenshot gates remain pending.plugin_handoffs: zara-plugins#507 remains downstream of Core #400. Composition still uses explicit
compose_capabilities, principal-bound backend hooks, canonical ToolRegistry approval re-checks, generation handles, and explicit turn cancellation. SmartThings credentials stay server-side; Core gains no Prolog-RLM runtime dependency; Android remains on shared runtime/semantic contracts.blockers: Current head
00cd7f92must pass exact-head repo/Nix/package/Android/shared-mic gates. The original remaining design blocker is still open after this regression repair: RuntimeHost's canonicalCancelTurn/ task-turn cancellation path does not yet callPluginManager.cancel_capability_turn(turn_id), so composed results tied to a host turn are not fenced by the same cancellation authority unless invoked manually. Do not start Android #622/#152/#194/#206 work before this Core seam is closed/reviewed.next_mode: IMPLEMENT
next_target: First verify exact-head CI for
00cd7f929f. If green, add RED RuntimeHost regression(s) proving canonicalCancelTurnand task-turn cancellation invalidate matching PluginManager composition contexts, then wire the smallest host-owned cancellation hook without a second cancellation runtime. Run focused + full exact-head repo/Nix/Android/shared-mic gates; switch to REVIEW only when clean.WORKER_STATE
worker: core-android
mode_used: IMPLEMENT
result: Verified prior repair head
00cd7f929f91c238a0d910dbd4af712b1dbe41a7is fully green in exact-head CI run34157008494, then started the recorded host-cancellation integration tests-first. Added RED commit7ac3e2fdd98e80e474e9b6d89d07aef59c909b0aon draft PR #659 with deterministic RuntimeHost coverage requiring both canonicalCancelTurnand task-turn cancellation to callPluginManager.cancel_capability_turn(turn_id). Current source does not do that, so the new tests capture the remaining reviewed gap without creating a second cancellation runtime. No master commit, no merge, no Android work advanced ahead of the Core blocker.issue_or_pr: lost-rob0t/zara#400; draft PR #659; worker #623
head:
7ac3e2fdd98e80e474e9b6d89d07aef59c909b0aandroid_tests: Prior exact-head
00cd7f92...CI run34157008494is SUCCESS across the repository CI, including the Android skeleton and shared-mic lanes. No Android product source changed in this loop. Android #622/#152/#194/#206 and PR #661 remain later in dependency order behind Core #400.core_tests: Prior head
00cd7f92...is proven green by run34157008494. RED commit7ac3e2fd...addst/test_plugin_host_cancellation.py:test_cancel_turn_invalidates_plugin_composition_contextandtest_task_turn_cancellation_invalidates_plugin_composition_context. Both assert the existing TurnCoordinator/backend cancellation path also invalidates the same turn id in PluginManager. A workflow run had not materialized yet when queried immediately after push, so exact-head CI for the RED commit is not claimed complete. Source inspection confirms_cancel_turn()and_cancel_task_turn()currently call coordinator/backend cancellation only and nevercancel_capability_turn, so the RED expectation is evidence-backed.plugin_handoffs: zara-plugins#507 remains blocked on #400. Existing composition guardrails remain: explicit
compose_capabilities, principal-bound backend invocation, canonical ToolRegistry approval re-check, generation/lifecycle leases, explicit stale-result fencing, no raw plugin/tool/private-manager escape. SmartThings credentials stay server-side; Core gains no Prolog-RLM runtime dependency; Android continues to reuse shared runtime/semantic contracts.blockers: Production half of this tests-first slice is still required: minimally notify the existing PluginManager from RuntimeHost cancellation paths, preserving TurnCoordinator as the sole turn-cancellation authority and keeping plugin invalidation best-effort/fail-closed without blocking backend cancellation. Then run focused tests plus full exact-head repo/Nix/package/Android/shared-mic gates. PR #659 remains draft/unmerged and still requires adversarial REVIEW after green gates.
next_mode: IMPLEMENT
next_target: Continue #400/#659 from RED
7ac3e2fdd98e80e474e9b6d89d07aef59c909b0a: add the smallest RuntimeHost production hook so both_cancel_turnand_cancel_task_turncallPluginManager.cancel_capability_turn(turn_id)using the already-owned turn id, with no duplicate coordinator/runtime; run the new focused tests and all required exact-head gates. If green, set next_mode REVIEW for principal/capability authorization, cancellation/stale-turn fencing, lifecycle/generation, Prolog authority, duplicate-runtime/server-vs-device placement, and insecure-fallback review before Android work.WORKER_STATE
worker: core-android
mode_used: IMPLEMENT
result: Confirmed RED exact-head CI run 34161066418 at
7ac3e2fdd98e80e474e9b6d89d07aef59c909b0afailed only the two intended RuntimeHost cancellation-contract tests while Android skeleton and both shared-mic lanes passed. Implemented the smallest production hook on draft PR #659 at45f93ab6d980b45e28bcf47db6c3c10c6233ce98: canonical CancelTurn and task-turn cancellation now invalidate the matching PluginManager composition turn before backend cancellation, through the existing turn id and without introducing another coordinator/runtime. Helper failure is isolated so backend cancellation still runs. Diff from RED is one file, +16/-1, with no unrelated source changes. No master commit, merge, or Android source work.refs: #400, PR #659, #623; roadmap #1; Android #152, Samsung/SmartThings #194, offline-first #622, UI PR #661
head:
45f93ab6d980b45e28bcf47db6c3c10c6233ce98tests: RED run
34161066418: repository lane 2 failed / 2131 passed, exactlytest_cancel_turn_invalidates_plugin_composition_contextandtest_task_turn_cancellation_invalidates_plugin_composition_context; Android skeleton PASS; shared mic Ubuntu PASS; shared mic Arch PASS. Fresh exact-head CI run34164920330is in progress at the new head. Current checkpoint: whitespace PASS, shared mic Ubuntu PASS, shared mic Arch PASS; repository full tests/Nix/package/screenshots still running; Android unit/native Trealla/debug APK/secret inspection still running. Therefore new head is not yet claimed green.plugin_handoffs: zara-plugins#507 remains blocked on #400/#659 review. Preserved principal-bound backend composition, explicit caller
compose_capabilitiesauthorization, canonical ToolRegistry approval/policy recheck, generation/lifecycle leases, and explicit stale-result fencing. TurnCoordinator remains the single turn/cancellation authority; PluginManager only receives cancellation invalidation for its in-flight composition context. SmartThings credentials remain server-side per #194; Core gains no Prolog-RLM runtime dependency; Android remains ordered behind Core and must reuse the shared semantic/runtime contracts from #152/#622.blockers: exact-head run
34164920330must finish green across repository tests, Nix flake/package/screenshots, Android skeleton, and both shared-mic lanes before #659 can return to adversarial REVIEW. PR #659 remains draft/open/unmerged. Android #622/#152/#194 and UI PR #661 are not advanced while this Core plugin blocker is unresolved.next_mode: IMPLEMENT
next_target: inspect exact-head CI
34164920330for45f93ab6...; if any lane fails, fix the exact regression tests-first on the existing focused branch. If every required gate is green, set next_mode REVIEW and adversarially re-check #659 for principal ownership, capability authorization, cancellation/stale-turn fencing (including lifecycle/restart edges), server-vs-device placement, Prolog authority, duplicate runtimes, and insecure fallbacks before any Android work.WORKER_STATE
worker: core-android
mode_used: IMPLEMENT
result: Re-read the durable mailbox, roadmap, Core #400/draft PR #659, Android offline/Samsung constraints, exact-head CI, and current PR-head RuntimeHost source. The recorded IMPLEMENT target is complete at
45f93ab6d980b45e28bcf47db6c3c10c6233ce98: exact-head run34164920330finished SUCCESS across all required lanes, and current source contains the minimal RuntimeHost -> PluginManager turn invalidation hook while preserving TurnCoordinator as the single cancellation authority. No additional source change was justified in this loop; PR #659 remains draft/open/unmerged and now advances to the mandated adversarial REVIEW.issue_or_pr: Core #400; draft PR #659; worker #623; Android #622/#152/#194; UI PR #661
head:
45f93ab6d980b45e28bcf47db6c3c10c6233ce98android_tests: Exact-head CI run
34164920330SUCCESS.android skeleton gatepassed its unit tests + native Trealla + debug APK + secret inspection.shared mic / Ubuntu 24.04SUCCESS andshared mic / Arch LinuxSUCCESS. No Android product source changed. Offline-first #622 and Samsung/SmartThings #194 remain behind the Core review in worker order; SmartThings secrets/refresh credentials remain server-side and Android continues to reuse the shared runtime/semantic contracts.core_tests: Exact-head
testjob SUCCESS at the recorded head.Run all tests, Nix flake checks, packaged Zara build, deterministic Copilot screenshots, whitespace check and artifact upload all passed. The prior tests-first cancellation contract is now green: canonicalCancelTurnand task-turn cancellation notifyPluginManager.cancel_capability_turn(turn_id)through RuntimeHost, while helper failure is isolated so backend cancellation still proceeds. Current PR-head source retains the dedicated_cancel_plugin_capability_turn()helper and does not introduce a second coordinator/runtime.plugin_handoffs: zara-plugins#507 remains downstream of #400/#659 until REVIEW/merge. Candidate contract now includes opaque generation handles, explicit
compose_capabilitiescaller authorization, principal-bound backend composition, canonical ToolRegistry policy/approval recheck, lifecycle leases, turn-correlated stale-result fencing, and host cancellation propagation. Plugins must continue using only the public PluginRuntime seam; no private backend/tool/manager imports or parallel registry/runtime. Core gains no Prolog-RLM runtime dependency.blockers: No failing exact-head gate remains. Remaining blocker is the required adversarial REVIEW of PR #659: verify principal ownership, capability authorization and policy parsing/fail-closed behavior, cancellation/stale-turn fencing including restart/lifecycle edges, generation/stale handle behavior, approval-required tool behavior, Prolog/model non-authority, server-vs-device placement, duplicate-runtime/private-state escapes, and insecure fallbacks. PR stays draft/unmerged until that review. Android work is not advanced ahead of this Core blocker.
next_mode: REVIEW
next_target: Adversarially review draft PR #659 at exact head
45f93ab6d980b45e28bcf47db6c3c10c6233ce98. Treat exact-head green CI as necessary but not sufficient. If review is clean, make the Core #400 candidate review-ready/hand off to plugins; if a concrete flaw is found, add a deterministic RED regression first and return to IMPLEMENT on the same focused PR before any Android #622/#152/#194 slice.WORKER_STATE
worker: core-android
mode_used: REVIEW
result: Adversarial exact-head review of Core #400 / draft PR #659 found a remaining stale-turn authority hole despite green CI. RuntimeHost now forwards canonical cancellation to PluginManager, but the public composition API still lets plugin code optionally supply an arbitrary raw
turn_id, and PluginManager only marks invocations active at cancellation time. Therefore a plugin can omit/forge turn correlation, and an honest call can race canonical cancellation-before-registration:CancelTurn(turn-1)may observe no active composed invocation, then a laterinvoke_capability(..., turn_id="turn-1")registers fresh and executes under an already-cancelled turn. Posted blocking PR comment 5576900609; PR remains draft/open/unmerged.issue_or_pr: Core #400; draft PR #659; blocking PR comment 5576900609; worker #623
refs: roadmap #1 + reconciliation comment 5566663947; zara-plugins worker #507; Android #152/#194/#622; Android UI PR #661; exact-head CI run 34164920330; master
fe6e8eee30d6beb153c2a399a79d325e017f2b02head:
45f93ab6d980b45e28bcf47db6c3c10c6233ce98tests: No new tests or source changes in REVIEW. Exact-head CI run
34164920330remains completed/SUCCESS at this SHA. Existing cancellation regression proves cancel-during-an-active matching-id composition call. Source review showsPluginRuntime.invoke_capability()accepts optional caller-providedturn_id; omitting it invokes composition with no cancellation correlation.PluginManager.cancel_capability_turn()only flags matching entries already in_active_capability_invocations; it stores no cancelled-turn tombstone/generation, and_invoke_capability()does not validate the id against host/coordinator state before registering. Thus green CI does not cover cancel-before-invoke or forged/uncorrelated turn ids.android_tests: No Android source changed in REVIEW. Exact-head run
34164920330remains green for Android skeleton unit/native Trealla/debug APK/secret inspection and Ubuntu/Arch shared-mic gates. #152 remains the shared portable-Prolog/typed-capability Android foundation; #622 requires one local/remote runtime abstraction and offline symbolic authority; #194 explicitly keeps SmartThings OAuth/secrets/refresh credentials server-side and forbids a second Android runtime. PR #661 remains separate UI work and is not advanced ahead of this Core blocker.core_tests: Reviewed current PR-head
zara/plugins/api.py,zara/plugins/manager.py, andzara/runtime/host.py, plus #400 and exact-head Actions. Principal-bound backend execution,compose_capabilitiesauthorization/recheck, approval-required fail-closed behavior, provider generation handles, lifecycle leases, host cancellation notification, and no raw tool/registry escape remain directionally sound. Blocking defect is that turn ownership/cancellation correlation is not Core-owned or durable across the cancellation-before-registration race.plugin_handoffs: zara-plugins#507 remains blocked on #400 for cross-plugin execution expansion. Do not consume #659 yet for
zara-shelltest/build composition because cancellation can still be bypassed by absent/forged correlation or by the pre-registration race. Plugins must continue avoiding private Core imports and parallel registries/runtimes. SmartThings credentials stay server-side. This Core slice adds no Prolog-RLM runtime dependency; Android continues to reuse shared semantic/runtime contracts.blockers: Add deterministic RED coverage for (1) cancel
turn-1before a composed invocation begins, then prove a later invocation for that stale turn fails before the underlying tool runs; and (2) prove plugin code cannot opt out of or forge the Core-owned cancellation context for turn-scoped composition. Then add the smallest Core-owned/validated turn lease, generation, tombstone, or equivalent opaque context tied to existing RuntimeHost/TurnCoordinator authority—no second coordinator/runtime and no raw caller string as authority. Preserve current principal/capability/approval/lifecycle safeguards and rerun focused + full repo/Nix/package/Android/shared-mic exact-head gates.next_mode: IMPLEMENT
next_target: Continue #400/#659 tests-first on the existing focused branch: reproduce cancel-before-registration plus uncorrelated/forged-turn bypass, then make composition cancellation context Core-owned/validated and stale-turn fail-closed without weakening authorization or adding another turn runtime. Run all required exact-head gates and return to REVIEW before any Android implementation slice.
WORKER_STATE
worker: core-android
mode_used: IMPLEMENT
result: Added the deterministic RED regression for the REVIEW-found cancel-before-registration race on Core #400 / draft PR #659. The new test cancels
turn-1before composition registration, then proves a later invocation for that stale turn must fail before the underlying capability executor runs. No production workaround was added in this loop because a raw tombstone set alone would be an unbounded long-lived-daemon leak and would still leave caller-forged/omitted turn correlation as authority; the production fix must tie registration to existing RuntimeHost/TurnCoordinator-owned turn validity rather than inventing a second coordinator.issue_or_pr: Core #400; draft PR #659; worker #623; prior blocking review comment 5576900609
refs: roadmap #1 reconciliation comment 5566663947; Android #622/#152/#194; zara-plugins #507; exact-head prior green CI 34164920330; new RED CI 34174536264
head:
9e77fcce9a01feddb67d87b9b61043c0004f8e07tests: Tests-first commit
9e77fcce9a01feddb67d87b9b61043c0004f8e07addstest_turn_cancellation_before_registration_fails_closedint/test_plugin_capability_authorization_cancellation.py. CI run34174536264is in progress at this exact head; Arch shared-mic is already green, while repository tests, Android skeleton gate, and Ubuntu shared-mic were still running at checkpoint. This commit is intentionally RED against currentPluginManager.cancel_capability_turn(), which only marks already-active invocations and stores no authoritative cancelled/invalid turn state.android_tests: No Android source changed. Prior exact-head
45f93ab6d980b45e28bcf47db6c3c10c6233ce98remains fully green in run34164920330for Android unit/native Trealla/debug APK/secret inspection plus both shared-mic lanes. Offline-first #622 remains downstream of this Core blocker and still requires one shared local/remote runtime abstraction; SmartThings #194 keeps credentials/OAuth/refresh server-side; Android continues to reuse shared semantic/runtime contracts.core_tests: Prior exact head
45f93ab6d980b45e28bcf47db6c3c10c6233ce98is green. Current source still accepts optional raw caller-providedturn_idinPluginRuntime.invoke_capability()andPluginManager._invoke_capability(), andcancel_capability_turn()only mutates matching entries already in_active_capability_invocations. RED now captures the pre-registration half of that defect. No direct master commit and no merge.plugin_handoffs: zara-plugins#507 remains blocked on #400. Do not consume #659 for
zara-shelltest/build composition yet; cancellation authority is still incomplete. Plugins must not import private Core/backend/tool state or create parallel registries/runtimes.blockers: Production still needs a bounded Core-owned turn-validity/lease contract tied to existing RuntimeHost/TurnCoordinator authority so cancellation-before-registration fails atomically and plugin code cannot forge or omit turn correlation for turn-scoped composition. Do not solve this with an unbounded cancelled-turn string set, plugin/model metadata, a second runtime/coordinator, or Prolog-RLM side-effect authority.
next_mode: IMPLEMENT
next_target: Continue #400 on draft PR #659 from RED head
9e77fcce9a01feddb67d87b9b61043c0004f8e07: wire the smallest RuntimeHost/TurnCoordinator-owned turn validation/lease seam into PluginManager registration, remove raw caller turn strings as cancellation authority for turn-scoped composition, make the new RED pass without regressing active-call cancellation/lifecycle leases/principal-capability authorization, then run focused + full repo/Nix/package/Android/shared-mic exact-head gates before REVIEW.WORKER_STATE
worker: core-android
mode_used: IMPLEMENT
result: Re-read mailbox/roadmap/current Core #400 + draft PR #659 source and completed the tests-first RED verification for the cancel-before-registration slice. Exact-head CI run
34174536264at9e77fcce9a01feddb67d87b9b61043c0004f8e07failed exactly one repository test:t.test_plugin_capability_authorization_cancellation::test_turn_cancellation_before_registration_fails_closed(DID NOT RAISE RuntimeError). JUnit reports 2,134 tests, 1 failure, 0 errors, 0 skipped. Android skeleton and both shared-mic lanes are green. No production workaround was committed in this loop because current source confirms a bounded tombstone alone would only close the already-RED race while leaving plugin-facing raw/optionalturn_idas forgeable/omittable authority; the next production slice must be tied to the existing RuntimeHost/TurnCoordinator authority, not a second coordinator or an unbounded string set.issue_or_pr: Core #400; draft PR #659; worker #623; roadmap #1
head:
9e77fcce9a01feddb67d87b9b61043c0004f8e07android_tests: Exact-head CI
34174536264:android skeleton gateSUCCESS (unit tests + native Trealla + debug APK + secret inspection); shared mic Ubuntu 24.04 SUCCESS; shared mic Arch Linux SUCCESS. No Android source changed; #622/#152/#194 remain behind Core #400 in this worker queue.core_tests: Exact-head repository
testjob failed only at the intended RED regression. JUnit artifact: 2,134 tests, 1 failure, 0 errors, 0 skipped. Failure is exactly cancel-before-registration: aftermanager.cancel_capability_turn("turn-1"), a later_invoke_capability(..., turn_id="turn-1")reaches execution instead of failing stale. CurrentPluginManager.cancel_capability_turn()only marks entries already present in_active_capability_invocations;PluginRuntime.invoke_capability()still accepts optional caller-provided rawturn_id. Existing RuntimeHost cancellation does forward canonical CancelTurn/task cancellation into PluginManager, and TurnCoordinator remains sole owner of turn lifecycle.plugin_handoffs: zara-plugins#507 remains blocked on #400. The future seam must preserve zara-shell test/build cancellation through Core while keeping caller capability allowlists, principal equality, approval rechecks, generation/lifecycle leases, and no private backend/tool imports or parallel runtime. SmartThings credentials stay server-side; Core gets no Prolog-RLM runtime dependency; Android continues to reuse shared semantic/runtime contracts.
blockers: Production fix still required. Smallest evidence-supported design: add a bounded cancel-before-registration fence plus a Core/RuntimeHost-supplied validator/lease against the existing TurnCoordinator so production turn-scoped composition rejects omitted, unknown/forged, and cancelled correlation before tool execution. Do not treat raw plugin-supplied strings as authority and do not create a second turn registry/coordinator. Then add explicit RED coverage for omitted/unknown correlation, wire the validator/lease, and run focused + full repo/Nix/package/Android/shared-mic gates.
evidence: CI run
34174536264; regression artifact10036884989; JUnit exact failuretest_turn_cancellation_before_registration_fails_closed; current branch sourcezara/plugins/manager.py,zara/plugins/api.py,zara/runtime/host.py; roadmap #1; Core #400.next_mode: IMPLEMENT
next_target: Continue #400 / PR #659 on the existing focused branch: add RED tests for omitted and unknown/forged turn correlation, then implement the bounded cancel fence + RuntimeHost/TurnCoordinator-owned turn-validity seam, preserving existing principal/capability/approval/lifecycle contracts. Run exact-head full gates before returning to REVIEW.