Skip to content

feat(comms): wire ReparentChannel and attached CreateChannel (RIG-4190) - #1779

Open
rigel-mintaka wants to merge 6 commits into
compass-comms/rig-4189-tree-deliveryfrom
compass-comms/rig-4190-channel-tree-rpc
Open

rigel-mintaka wants to merge 6 commits into
compass-comms/rig-4189-tree-deliveryfrom
compass-comms/rig-4190-channel-tree-rpc

Conversation

@rigel-mintaka

@rigel-mintaka rigel-mintaka commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

This PR is part of a stack containing 5 PRs:

  1. main
  2. feat(store): attach channels to agents with tree or explicit membership (RIG-4186) #1762
  3. feat(store): authorize channel writes and reads by tree participation (RIG-4187) #1764
  4. feat(store): owner-set visibility and derived TREE members on channel reads (RIG-4188) #1772
  5. feat(store): TREE subscriptions and delivery over derived participants (RIG-4189) #1778
  6. "feat(comms): wire ReparentChannel and attached CreateChannel (RIG-4190)" (this PR)

Summary

Channels-in-the-agent-tree, task T6 (docs/designs/ui/compass-channels-in-agent-tree/design.md § Plan): the RPC edge and events. Stacked on #1778.

  • CreateChannel passes parent_agent_handle and membership_mode to the store. An unknown mode is INVALID_ARGUMENT, so the call does not quietly create an EXPLICIT channel.
  • ReparentChannel replaces the Unimplemented stub. It calls store.ReparentChannel and emits one ChannelChanged after commit. The stream's existing ChannelVisibleTo filter decides who receives it. When a channel leaves its anchor owner's tree (a detach, or a move to another owner's agent), the old owner set loses visibility. store.OwnerSetLostChannelVisibility finds those accounts in one query, and they are named in removed_account_ids so they still receive the final event. store.ReparentChannel now also returns the parent it replaced, read under its row lock.
  • Stream: SubscribeComms trims removed_account_ids to the recipient's own id, so the list never shows one account another's id. This also covers the existing UpdateChannelMembers removals.
  • Proto docs: the ChannelChanged comments list every emit cause and the per-recipient trim. Comment-only change; gen is regenerated.
  • Handle resolution: a new resolveSameOwnerAgent (in resolve.go) resolves an optional agent handle. A foreign handle gets the same NOT_FOUND as an unknown one, naming the submitted handle. ReparentAgent's parent check now uses the same helper.
  • No change to the coordination hook.

This also lands the RPC half deferred from #1772: the CreateChannel response and its ChannelChanged carry parent_agent_id and TREE mode.

Tests

  • TestCreateChannelUnderAgentEmitsAttachedChannel: the response and exactly one ChannelChanged carry the anchor and TREE mode; a subtree agent's post succeeds end to end; a non-participant's post is NOT_FOUND.
  • TestCreateChannelRejectsUnknownMembershipModeAndForeignAnchor: an unknown mode is INVALID_ARGUMENT; a foreign anchor is NOT_FOUND naming the submitted handle.
  • TestReparentChannelEmitsOneChannelChangedToAdmittedAccounts: exactly one bus event; the owner's stream receives it; an outsider's stream receives its own later marker event first.
  • TestReparentChannelDetachNotifiesViewersWhoLoseVisibility: a same-owner agent with no member row receives the detach event naming it as removed; the remaining member is not named.
  • TestReparentChannelCrossOwnerMoveNotifiesOnlyLostViewers: a shared channel moved from X's agent to Y's agent; X's non-member agent receives the event naming only itself; the Y member receives it with no removed ids.
  • TestOwnerSetLostChannelVisibilityExcludesRemainingPaths (store): nothing is lost while anchored in the owner set; after a detach only the non-member bystander is lost.
  • TestReparentChannelNonParticipantIsNotFound: a non-participant gets NOT_FOUND; a foreign and an unknown destination give the same NOT_FOUND naming the submitted handle.
  • Mutations, each failing a test above: publish removed; owner check removed (also fails the existing ReparentAgent foreign-parent test); mode dropped; double publish on reparent and on create; removed ids dropped on detach; plain handle resolve on the destination; no stream trim; detach-only notice; owner-set arm removed from the lost-visibility query.
  • comms and auth suites (pgtest and unit): ok. Lint: clean.

Spec-impact: none
Ledger-impact: none

Refs RIG-4190, RIG-1622

Co-authored-by: Matt Wilkinson matt@rigel.build

@linear-code

linear-code Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

RIG-4190

RIG-1622

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Compass engineering docs preview: https://compass-comms-rig-4190-chann.compass-eng-docs.pages.dev

Deployed from compass-comms/rig-4190-channel-tree-rpc at 912d0fc.

rigel-mintaka and others added 2 commits October 6, 2026 05:51
CreateChannel resolves parent_agent_handle and membership_mode at the edge;
ReparentChannel replaces the Unimplemented stub and emits one
ChannelChanged post-commit. A foreign or unknown agent handle merges to the
same NOT_FOUND naming the submitted handle, through one helper that
ReparentAgent now shares.

Co-authored-by: Matt Wilkinson <matt@rigel.build>
…hannel oracles (RIG-4190)

An EXPLICIT detach drops the old anchor owner set from visibility, so those
accounts are named in removed_account_ids and still get the final
ChannelChanged. Tests now pin one create event, the destination NOT_FOUND
merge, and the detach notice.

Co-authored-by: Matt Wilkinson <matt@rigel.build>
@rigel-mintaka
rigel-mintaka force-pushed the compass-comms/rig-4190-channel-tree-rpc branch from b0dff94 to 9ed8783 Compare October 6, 2026 09:55
rigel-mintaka and others added 4 commits October 6, 2026 06:13
…r recipient (RIG-4190)

A move to another owner's agent loses the old owner set the same way a
detach does. The store returns the replaced parent from under its row lock,
and one query lists the old owner set that lost visibility. SubscribeComms
now sends each recipient only its own id in removed_account_ids.

Co-authored-by: Matt Wilkinson <matt@rigel.build>
…nt per-recipient trim (RIG-4190)

OwnerSetLostChannelVisibility now negates ChannelVisibleTo's body with the
viewer spelled per candidate, so it diffs against the other copies.
ChannelChanged.removed_account_ids documents the per-subscriber trim.

Co-authored-by: Matt Wilkinson <matt@rigel.build>
…m (RIG-4190)

Co-authored-by: Matt Wilkinson <matt@rigel.build>
Co-authored-by: Matt Wilkinson <matt@rigel.build>
@rigel-mintaka
rigel-mintaka marked this pull request as ready for review October 6, 2026 10:50
@mattwilkinsonn
mattwilkinsonn added this pull request to stack #1828 October 7, 2026 00:34
@mattwilkinsonn

Copy link
Copy Markdown
Contributor

/trunk merge

@trunk-io

trunk-io Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

❌ This stack could not start testing because there was a merge conflict. See more details here.

  • To merge this pull request, check the box to the left or comment /trunk merge below.

After your PR is submitted to the merge queue, this comment will be automatically updated with its status. If the PR fails, failure details will also be posted here

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants