Conversation
cargo fmt --all -- --check is part of the workspace verification suite, but the repo had drifted out of rustfmt-clean (the authoring runtime runs no rustfmt and CI only checks -p agent-lifecycle). Add a regression test that runs the same check so drift fails fast in cargo test instead of accumulating silently across crates.
Mechanical rustfmt pass — the repo had drifted from rustfmt-clean across acp-tunnel, agent-lifecycle, oab-mcp and oabctl. No semantic changes.
Pre-existing violations blocking cargo clippy --workspace --all-targets -- -D warnings: - studio-compose: SkillsLibrary::from_iter tripped should_implement_trait — implement FromIterator<(N, Skill)> for real; the five existing SkillsLibrary::from_iter call sites resolve to the trait method unchanged, and .collect() into a library now works too. - studio-cp: derive Default for FleetRuntime (was a manual impl clippy flags as derivable), rewrite a strip_prefix/else-return-None as ? in role_identity, and add targeted allow(clippy::too_many_arguments) on the four provision_* boundary functions whose signatures are already public API — restructuring them ripples outside the workspace. Both files also carry their cargo fmt normalization.
…penabdev#3) Fold the four wontfix-or-fold items from ADR-1's 8-axis review: - Stopping hard-loss edge: add the missing Stopping --> Stopped reclaim/hard-loss (no flush) edge to the state diagram and tighten principle 4 — a hard loss from *inside* Stopping skips 'state saved' and lands in the same absorbing Stopped, not a third outcome. - Section 9 lock-in/reversibility: new note enumerating what is expensive to reverse (the 6-state set, the identity_verified latch, per-instance identity + fencing epoch, the single-field dispatch predicate) vs cheap (projection rows, cause enums, attributes, deadline tuning). - R2 State.Paused: record that the AgentState surface labels are owned by the RuntimeDriver-contract ADR; in deployment-control-plane.md note the resolved naming consideration — the enum stays Paused, not Cordoned, because cordon is only one cause of ¬accepting_work (superseded fencing classifies the same way). - superseded: tighten to airtight instance-level phrasing — the attribute applies to the instance (agent is not paused); a replacement is a fresh lifecycle that classifies independently.
…nabdev#3 Review fixups on the follow-up fold-in: the "future RuntimeDriver ADR" reference predates ADR-2's acceptance — link it directly — and note issue openabdev#3 in the tracking header. Refs openabdev#3 Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This was referenced Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #3
Summary
Folds the four wontfix-or-fold items from ADR-1's 8-axis review into the docs:
Stopping --> Stopped : reclaim / hard loss (no flush)edge to the state diagram and tightens principle 4: a hard loss from insideStoppingskipsstate savedand lands in the same absorbingStopped— "lost while Stopping" is not a third outcome.identity_verifiedlatch no runtime exposes natively, per-instance identity + fencing epoch, the single-field dispatch predicate) vs cheap to change (§6 projection rows, cause enums, new attributes, deadline tuning).State.Paused— ADR-1 §9 now records that theAgentStatesurface labels are owned by the RuntimeDriver-contract ADR;deployment-control-plane.md(ADR-2 §5) records the resolved naming consideration: the enum staysPaused, notCordoned, because cordon is only one of several¬accepting_workcauses (supersededfencing classifies the same way).supersededsentence — tightened to airtight instance-level phrasing: the attribute applies to the instance (the agent is not paused); a replacement is a fresh lifecycle that classifies independently.Suite-enabling changes (non-docs, explained)
The repo's verification suite (
cargo fmt --all -- --check,cargo test --workspace,cargo clippy --workspace --all-targets -- -D warnings) could not pass on a clean checkout — independent of this issue — so this PR includes the minimal fixes:test(agent-lifecycle): newtests/rustfmt_clean.rsassertscargo fmt --all -- --checksucceeds. It fails on currentmain(fmt drift) and passes after the normalization below — red→green.style: mechanicalcargo fmt --allacross 16 files (repo drifted from rustfmt-clean; CI only checks-p agent-lifecycle). No semantic changes.refactor: clippy-D warningscompliance —SkillsLibrary::from_iterbecomes a realFromIteratorimpl (call sites unchanged,.collect()now works),Defaultderived forFleetRuntime, a?-operator rewrite inrole_identity, and targeted#[allow(clippy::too_many_arguments)]on the four publicprovision_*boundary functions.Test plan
cargo fmt --all -- --check— cleancargo test --workspace— 247 tests passcargo clippy --workspace --all-targets -- -D warnings— cleanworkspace_is_rustfmt_cleanfails on base (exit 101), passes aftercargo fmt --allGenerated with Devin