Repository navigation
feat: persist inbox questions and replies in the orchestration store - #910
Conversation
There was a problem hiding this comment.
Important
Summary counts and status paging do not match derived question status, and orchestration.reply cannot mark an inbox question answered.
Reviewed changes
Reviewed the inbox store layer and the orchestration mobile-allowlist fix on feat/inbox-store.
- Mobile allowlist.
handle_orchestration_requestnow refuses non-local clients, since no orchestration verb is on the mobile allowlist. Board reads already required a local client. - Inbox schema. Nullable
reply_to_idandexternal_metacolumns, revision triggers, andtake_inbox_change. - Question rules. Address validation, expiry bounds, the undelivered cap, follow-up checks, and cancel-before-delivery.
- Reads and retention. Thread detail, paged listing, per-inbox summary, purge, and 7-day pruning, plus the delivered
ext:expiry exception.
grok-4.7 | 𝕏
a83405f to
2fb2186
Compare
There was a problem hiding this comment.
ℹ️ No new issues in this delta. Two earlier comments are still open.
Reviewed changes
Reviewed the store changes since a83405f.
- Filtered thread pages before the limit, and continued the cursor after the last returned thread.
- Ordered thread pages by latest activity, so a reply moves that thread up.
- Added
expire_inbox_questionsto expire queued inbox questions and report the inboxes that changed. - Revived an expired inbox question when paste marks it delivered, so a deadline that passes during injection still awaits a reply.
- Retargeted the branch onto the mobile-allowlist fix, so that change is no longer in this diff.
grok-4.7 | 𝕏
2fb2186 to
c97ffca
Compare
There was a problem hiding this comment.
ℹ️ No new issues in this delta. One earlier comment is still open.
Reviewed changes
Reviewed the store changes since 2fb2186.
- Pending summary count. Excluded a recipient
reply_to_idfrompending_count, so an answered question no longer shows as pending before it is pasted. - Explicit-reply coverage. Asserted that count stays at one for a non-recipient reply and drops to zero once the recipient answers.
grok-4.7 | 𝕏
c97ffca to
2817a95
Compare
2817a95 to
f13130d
Compare

Summary
Store layer for the external agent inbox: processes and UIs outside a terminal ask an agent from an
ext:<name>address and read its replies later.orchestrationMessages. Two nullable columns are added withensure_column(no table rebuild):reply_to_idnames the question a reply answers, andexternal_metaholds the question's origin surface, a snapshot of the target, and a cancellation record.inboxRevisionplus triggers move a durable revision in the same transaction as any row that involves anext:address, whichever writer touched it.take_inbox_changetells the host when to notify clients.ext:address validation, 5 hour default expiry (1 minute to 7 days), at most 20 undelivered questions per recipient, follow-ups only to the same recipient and inbox, cancellation only before the agent saw them.reply_to_idfrom the recipient counts), expired, delivered, received (a coordinator consumed it withcheck), pending.Stacked on #909.
Validation
inbox_store_tests,inbox_listing_tests) cover migration idempotence, defaults and validation, follow-up rules, the pending limit, every status, cancellation, the expiry rule, explicit correlation, revision movement, read marking, summary and paging, purge and pruning. The pruning test caught a bug during development: replies addressed to an inbox stay queued forever and were wrongly protecting old threads.cargo test -p alera-core --features runtime,cargo test -p alera-cli, andcargo clippy --workspace --all-targets -- -D warningspass locally.dart run tool/quality/check_max_lines.dartpasses.Risk
The expiry predicate changed for delivered
ext:rows only.OrchestrationMessagegains two optional fields that are omitted from JSON when empty, so existing outputs are unchanged.