Skip to content

fix(sdk): cancellable published transport and current Sandbox cohort for Knowledge - #60

Merged
drewstone merged 5 commits into
mainfrom
sweep4/tcloud-cancellable-published-client
Sep 27, 2026
Merged

drewstone merged 5 commits into
mainfrom
sweep4/tcloud-cancellable-published-client

Conversation

@drewstone

@drewstone drewstone commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Deliverable

[tool] SDK prerequisite for tangle-network/agent-knowledge#222. The Pi raw Router HTTP deletion already merged in #58 at 8531d2eb2e7af89f9af30d2443385388a73a5e23. This PR retains that deletion. No Sandbox REST-surface or agent-loop consolidation is included.

[tool] Head 1ed385a057291be2f2d11679409c0a9d094524bf: client.ts and types.ts carry chat/search cancellation into HTTP and retry waits, retain the signal through the relayer, and expose per-response cost receipts. Unknown prices are not reported as free. Published Sandbox 0.54.2 replaces the incompatible 0.34 dependency line. Candidate versions are tcloud 0.6.0 and tcloud-agent 0.5.0, Node 20.19+. The release build now builds workspace dependencies before packing.

Independently rerun evidence

[tool] Fresh verification: https://github.com/tangle-network/tcloud/actions/runs/36298466391 . This checked out this exact head, installed from npm with the frozen lock, built all four packages, exercised the built SDK over actual loopback HTTP, and packed it. It then compiled Knowledge's exact head against that artifact and exercised its built adapter. No fetch mocks, new unit suite, secret access, merge or publication.

[tool] SDK evidence: chat, search, 503 retry and relayer cancellation each observed requests:1 and disconnected:true. Concurrent requests retained independent 0.01 and 0.02 cost receipts; missing cost had no receipt. These are controlled HTTP amounts, not a funded provider bill.

[tool] The rebuilt artifact matches the previous candidate exactly:

  • SHA256: e95248df2f37d1bbe26a6bd07fb8be3153ce6e111101ba90651e1eb1b1d15e24
  • SRI: sha512-mu/PLUh/2+Cezg8lthrGDenzSnKIhN6crGNGZX+JSUIr74x7vH1M63rFNW6NH0yKpgVzv/lgnZTCBXQbZhX0PA==

[absent] The registry check still returns tcloud 0.5.2 as latest and no 0.6.0. Funded GTR requests were not run here. A closed HTTP connection does not prove that an upstream provider stopped computing or billing.

Exact GTR proof

Run in Bash with Node 22 and a funded TANGLE_API_KEY already exported. Do not enable shell tracing. These commands use a new clone, not a shared GTR worktree.

1. Registry install

set -euo pipefail
umask 077
export npm_config_registry=https://registry.npmjs.org
WORK=$(mktemp -d)
git clone https://github.com/tangle-network/tcloud.git "$WORK/tcloud"
cd "$WORK/tcloud"
git checkout --detach 1ed385a057291be2f2d11679409c0a9d094524bf
mkdir -p "$WORK/evidence"
git rev-parse HEAD | tee "$WORK/evidence/head.txt"
node --version | tee "$WORK/evidence/node.txt"
npm view @tangle-network/sandbox@0.54.2 version dist.integrity --json \
  | tee "$WORK/evidence/registry.json"
npx --yes pnpm@9.15.9 install --frozen-lockfile 2>&1 \
  | tee "$WORK/evidence/install.log"

Evidence: exact source SHA, npm metadata, frozen install. Workspace links among the packages being authored in this publishing monorepo are intentional; external Sandbox dependencies come from npm.

2. Real build and built-SDK HTTP proof

npx --yes pnpm@9.15.9 -r build 2>&1 | tee "$WORK/evidence/build.log"
node scripts/prove-sdk-transport.mjs | tee "$WORK/evidence/http-proof.jsonl"
mkdir -p "$WORK/packed"
npx --yes pnpm@9.15.9 --dir packages/tcloud pack --pack-destination "$WORK/packed"
SDK_TGZ="$WORK/packed/tangle-network-tcloud-0.6.0.tgz"
printf '%s  %s\n' \
  e95248df2f37d1bbe26a6bd07fb8be3153ce6e111101ba90651e1eb1b1d15e24 \
  "$SDK_TGZ" | sha256sum -c - | tee "$WORK/evidence/package-check.txt"

Evidence: runtime/declaration builds, real HTTP cancellation and cost results, exact packed bytes. Stop on a digest mismatch. Do not bypass it.

3. One real request through the built Pi tool

: "${TANGLE_API_KEY:?Export a funded Tangle key without printing it}"
PROOF_HOME=$(mktemp -d)
HOME="$PROOF_HOME" TCLOUD_MODEL="${TCLOUD_MODEL:-gpt-4o-mini}" \
  node scripts/prove-pi-live.mjs | tee "$WORK/evidence/pi-live.json"
printf 'Evidence directory: %s\n' "$WORK/evidence"

Evidence: prove-pi-live.mjs loads the built extension, collects the actual registered tangle tool, and invokes its chat capability. HTTP and inference are real. JSON contains the unique pi-tcloud-ok-<uuid> request marker, input and returned content/model/usage. Its small Pi host is not a browser test or a substitute model. No key is printed.

Release order after GTR proof and review

[absent] Knowledge's public-registry install is blocked until this SDK is merged and published. Do not merge Knowledge first. #222 includes a separate temporary candidate proof for pre-publication review; that is not counted as an npm install of 0.6.0.

The release owner uses the existing tag-driven workflow after merging this PR. The commands below publish and are NOT part of the proof above. No tag or publication was performed by this session.

# Run only after approving and merging #60.
RELEASE_SHA=$(gh pr view 60 --repo tangle-network/tcloud \
  --json mergeCommit --jq '.mergeCommit.oid // empty')
test -n "$RELEASE_SHA"
git fetch origin main
git merge-base --is-ancestor "$RELEASE_SHA" origin/main
test "$(git show "$RELEASE_SHA:packages/tcloud/package.json" \
  | node -e 'let s=""; process.stdin.on("data",c=>s+=c); process.stdin.on("end",()=>console.log(JSON.parse(s).version))')" = 0.6.0
git tag '@tangle-network/tcloud@0.6.0' "$RELEASE_SHA"
git push origin '@tangle-network/tcloud@0.6.0'

[tool] The existing release workflow refuses a release commit not on main. After it succeeds, #222 checks npm's integrity against the SRI above and runs its unchanged frozen install, build and funded request proof. A different published artifact requires a reviewed lock update, not a disabled integrity check.

tangletools
tangletools previously approved these changes Sep 27, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — c9e98770

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-27T04:54:34Z

tangletools
tangletools previously approved these changes Sep 27, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 01bc6423

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-27T04:56:32Z

tangletools
tangletools previously approved these changes Sep 27, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 1ed385a0

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-27T04:57:33Z

@drewstone

drewstone commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

Base main is 60d4af8ff5fecccc0b85fe8874363cdb49cd173d (#59 merged at 2026-09-27 06:47:17Z). The source owner's existing GTR worktree contained a clean integration at 531253a1ba3c677d7f1c174bdbfa9f00d9d37c76, with parents PR head 1ed385a057291be2f2d11679409c0a9d094524bf and current main. It preserves the complete manifest and sets version 0.6.0, Sandbox >=0.54.2 <0.55.0, and Node >=20.19.0. The only merge conflict was packages/tcloud/package.json; the reviewed integration is now pushed normally, with no force push.

Correction on run 36298466391: it is not a PR status check, but it is valid remote proof for exact source head 1ed385a. The workflow pins actions/checkout to that SHA; the job log confirms it fetched and checked out 1ed385a, then performed a frozen install, recursive workspace build, node scripts/prove-sdk-transport.mjs, and packed tcloud 0.6.0. The artifact records package SHA256 e95248df2f37d1bbe26a6bd07fb8be3153ce6e111101ba90651e1eb1b1d15e24. Its transport proof shows chat, search, retry, and relayed-chat cancellation each made one request and disconnected; cost receipts were 0.01, 0.02, and absent. This run does not test streaming cancellation, run the SDK unit suite, test the later integrated tree, or publish the package.

On integrated head 531253a, focused GTR tests passed: tests/chat.test.ts and tests/api-methods.test.ts, 55/55 on Node 22.23.2. This includes the billed-header-without-usage limit regression and the current canonical video-route contract. The exact-head frozen SDK workflow is now running: run 36302621674. No package publication or funded provider request was performed.

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 531253a1

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-27T07:17:02Z

@drewstone
drewstone merged commit c6e4c17 into main Sep 27, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants