Skip to content

feat(prx): TCP transport for keeperd on macOS virtiofs (→ non-null l2LaunchDigest on Mac) (#749) - #937

Closed
bdelanghe wants to merge 2 commits into
mainfrom
feat/keeper-tcp-transport
Closed

feat(prx): TCP transport for keeperd on macOS virtiofs (→ non-null l2LaunchDigest on Mac) (#749)#937
bdelanghe wants to merge 2 commits into
mainfrom
feat/keeper-tcp-transport

Conversation

@bdelanghe

Copy link
Copy Markdown
Contributor

From a backlog local branch, pushed and opened for triage.

bdelanghe and others added 2 commits June 23, 2026 12:19
Replace all direct zod schema object usages with the new explicit type +
parse-function surface from @bounded-systems/machine-schema@0.3.0:

- handoff/cli.ts: handoffTargetActor.safeParse → safeParseHandoffTargetActor;
  handoffTargetActor.options → HANDOFF_TARGET_ACTOR_VALUES (3 call sites)
- handoff/store.ts: handoffEnvelope.parse → parseHandoffEnvelope (4 call sites)
- derive/cli.ts: z.array(rawStateV1Schema) → z.array(z.unknown().transform(parseRawStateV1))
- machine/contracts/guards.ts: rawStateV1Schema.parse → parseRawStateV1
- machine/contracts/anchored-chain-bridge.ts: rawStateV1Schema →
  z.unknown().transform(parseRawStateV1)
- pr-state/domain_state.ts: .shape.* → z.custom<T>(); rawStateV1Schema.parse →
  z.unknown().transform(parseRawStateV1) + parseRawStateV1
- machine/work_unit.ts: update brand comment (v0.3.0 uses unique-symbol brand,
  not zod BRAND — explicit `as WorkUnitId` casts remain correct)

Dependency: @bounded-systems/machine-schema@^0.3.0 (published separately).
CI is blocked until that package is available on JSR.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…LaunchDigest on Mac) (#749)

virtiofs forwards file semantics but not Unix socket semantics: the keeperd.sock
file appears on the macOS filesystem but connections from the Mac host fail with
ENOENT. TCP tunnels around this — keeperd-room declares tcpPort: 9999, podman
publishes -p 9999:9999 and passes --port 9999 as a CMD arg, and launchPod sets
KEEPERD_HOST=127.0.0.1:9999 so door-kit's client connects via TCP instead of
the Unix socket path. launchPod falls back to KEEPERD_SOCK (Unix) when tcpPort
is absent, so the Linux production path is unchanged.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
export function defaultMachineSchemaMap(): Readonly<Record<string, z.ZodTypeAny>> {
return {
raw_state_v1: rawStateV1Schema,
raw_state_v1: z.unknown().transform(parseRawStateV1),
// (attest + store the L2; the daemon remembers it so the box's writes auto-link).
// Best-effort attest: a failure surfaces as null but never tears the pod down.
import { describe, test, expect } from "bun:test";
import { describe, test, expect, afterEach } from "bun:test";

Copy link
Copy Markdown
Contributor Author

Closed by the org-wide PR sweep (.github-private#480): draft, not updated since 2026-07-01, past the 30-day staleness window. The branch is untouched — re-open if this work is still live; a fresh update spares it from the next sweep.


Generated by Claude Code

@bdelanghe bdelanghe closed this Aug 27, 2026
@bounded-systems-front-desk bounded-systems-front-desk Bot moved this from Todo to Done in Front Desk Aug 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant