Skip to content

feat: persist inbox questions and replies in the orchestration store - #910

Merged
leynier merged 1 commit into
mainfrom
feat/inbox-store
Oct 6, 2026
Merged

leynier merged 1 commit into
mainfrom
feat/inbox-store

Conversation

@leynier

@leynier leynier commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Summary

Store layer for the external agent inbox: processes and UIs outside a terminal ask an agent from an ext:<name> address and read its replies later.

  • Reuses orchestrationMessages. Two nullable columns are added with ensure_column (no table rebuild): reply_to_id names the question a reply answers, and external_meta holds the question's origin surface, a snapshot of the target, and a cancellation record.
  • inboxRevision plus triggers move a durable revision in the same transaction as any row that involves an ext: address, whichever writer touched it. take_inbox_change tells the host when to notify clients.
  • Questions: ext: address validation, 5 hour default expiry (1 minute to 7 days), at most 20 undelivered questions per recipient, follow-ups only to the same recipient and inbox, cancellation only before the agent saw them.
  • Derived status: cancelled, answered (only an explicit reply_to_id from the recipient counts), expired, delivered, received (a coordinator consumed it with check), pending.
  • Expiry change: a delivered inbox question no longer expires, since it was already pasted and is waiting for its reply. Agent-to-agent messages keep the previous rule.
  • Queries for threads, a paged thread list, per-inbox summaries, messages after a cursor, marking replies read (inbox rows only), purge, and 7 day history pruning that keeps any conversation with a recent message or an undelivered question.

Stacked on #909.

Validation

  • 13 new store tests (inbox_store_tests, inbox_listing_tests) cover migration idempotence, defaults and validation, follow-up rules, the pending limit, every status, cancellation, the expiry rule, explicit correlation, revision movement, read marking, summary and paging, purge and pruning. The pruning test caught a bug during development: replies addressed to an inbox stay queued forever and were wrongly protecting old threads.
  • cargo test -p alera-core --features runtime, cargo test -p alera-cli, and cargo clippy --workspace --all-targets -- -D warnings pass locally.
  • dart run tool/quality/check_max_lines.dart passes.

Risk

The expiry predicate changed for delivered ext: rows only. OrchestrationMessage gains two optional fields that are omitted from JSON when empty, so existing outputs are unchanged.

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Important

Summary counts and status paging do not match derived question status, and orchestration.reply cannot mark an inbox question answered.

Reviewed changes

Reviewed the inbox store layer and the orchestration mobile-allowlist fix on feat/inbox-store.

  • Mobile allowlist. handle_orchestration_request now refuses non-local clients, since no orchestration verb is on the mobile allowlist. Board reads already required a local client.
  • Inbox schema. Nullable reply_to_id and external_meta columns, revision triggers, and take_inbox_change.
  • Question rules. Address validation, expiry bounds, the undelivered cap, follow-up checks, and cancel-before-delivery.
  • Reads and retention. Thread detail, paged listing, per-inbox summary, purge, and 7-day pruning, plus the delivered ext: expiry exception.

Pullfrog  | Fix all ➔ | Fix 👍s ➔ | View workflow run | Using grok-4.7 | 𝕏

Comment thread rust/alera-core/src/runtime/inbox_queries.rs Outdated
Comment thread rust/alera-core/src/runtime/inbox_queries.rs Outdated
Comment thread rust/alera-cli/src/terminal_host/server/orchestration_requests.rs
@leynier
leynier changed the base branch from main to fix/orchestration-mobile-allowlist October 6, 2026 16:17
@leynier
leynier added this pull request to stack #919 October 6, 2026 16:17

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ℹ️ No new issues in this delta. Two earlier comments are still open.

Reviewed changes

Reviewed the store changes since a83405f.

  • Filtered thread pages before the limit, and continued the cursor after the last returned thread.
  • Ordered thread pages by latest activity, so a reply moves that thread up.
  • Added expire_inbox_questions to expire queued inbox questions and report the inboxes that changed.
  • Revived an expired inbox question when paste marks it delivered, so a deadline that passes during injection still awaits a reply.
  • Retargeted the branch onto the mobile-allowlist fix, so that change is no longer in this diff.

Pullfrog  | Fix it ➔ | View workflow run | Using grok-4.7 | 𝕏

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ℹ️ No new issues in this delta. One earlier comment is still open.

Reviewed changes

Reviewed the store changes since 2fb2186.

  • Pending summary count. Excluded a recipient reply_to_id from pending_count, so an answered question no longer shows as pending before it is pasted.
  • Explicit-reply coverage. Asserted that count stays at one for a non-recipient reply and drops to zero once the recipient answers.

Pullfrog  | Fix it ➔ | View workflow run | Using grok-4.7 | 𝕏

Base automatically changed from fix/orchestration-mobile-allowlist to main October 6, 2026 19:00
@leynier
leynier merged commit 4a0d52b into main Oct 6, 2026
19 checks passed
@leynier
leynier deleted the feat/inbox-store branch October 6, 2026 19:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant