Skip to content

FE-1624: Implement split-ownership Voice conversations with Brunch - #9571

Draft
kostandinang wants to merge 77 commits into
mainfrom
kostandin/fe-1624-split-ownership-voice
Draft

FE-1624: Implement split-ownership Voice conversations with Brunch#9571
kostandinang wants to merge 77 commits into
mainfrom
kostandin/fe-1624-split-ownership-voice

Conversation

@kostandinang

@kostandinang kostandinang commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Important

Current status: #9537 and #9564 are merged. Wait for the omitted settlement port in #9588 to be accepted, then recut this draft from the latest main as an independent sibling PR. Do not merge it meanwhile. This planning-only successor remains blocked on its stated authority and runtime gates.

🌟 What is the purpose of this PR?

Prepare split-ownership Voice conversations: Brunch retains domain strategy and validation, Realtime handles permitted conversational delivery, Flue owns the canonical conversation, and Petrinaut owns safe tool execution.

This draft is planning-only. It preserves the provisional design and presents a bounded mission-conversion proposal for owner approval. It does not change product behavior or promote the inherited accepted Mission 6b authority. Source inspection found no supported persistence-only external dialogue recorder in Flue 2.0.3 or the inspected upstream HEAD; dependent implementation is blocked rather than replaced with a sidecar.

🔗 Related links

🚫 Blocked by

The latter two gates block product implementation, not review of this planning packet.

🔍 What does this change?

  • Preserves the original ownership design byte-for-byte.
  • Adds a source-grounded conversion proposal with migration gates, candidate tests, recovery obligations, and residual-planning disposition.
  • Adds future-spine pointers without replacing accepted MISSION.md or changing product code.
🏗️ Agent notes

Kostandin Angjellari authorized a new successor issue and draft PR stacked directly on #9564. FE-1624 and branch kostandin/fe-1624-split-ownership-voice form that successor. The original local checkout and its uncommitted design/spine remain intact. No parent or sibling branch was rewritten; gh stack was unavailable, so the Git branch starts at the exact parent head and this PR explicitly targets its branch.

There is no new live mission yet. The six-address candidate conversion is in the proposal. Its initial prerequisite is supported no-wake recording; the separately approved product stage is one Brunch delegation → two recorded Realtime exchanges → one structured agent-authored handback referencing originals → Brunch-validated workpiece update → fresh-process reconstruction. Integrated recovery and safety gates follow before readiness; the first tracer is not architecture completion.

Protect causal per-step client results, mixed server/browser topology, staggered sibling tools, effect-replay batching, explicit human evidence, conversation-owned callbacks, coherent-state refusal, and no autoplay. The current runbook-ir selector must not promote newly recorded Realtime assistant text to Brunch workpiece authority.

Flue signals can carry non-human waking handbacks, but cannot substitute for persistence-only dialogue. Caller-supplied authorship attributes need application enforcement. Public abort leaves settled submissions untouched and does not durably cancel pending browser operations. Speech interruption and durable Stop remain separate; effect/receipt gaps require reconciliation rather than an exactly-once claim.

The detailed plan names stage owners, targeted package commands, real built-runtime tests, browser/media witnesses, no-wake/attribution/identity/staleness/modality/interleaving/partial-effect/recovery discriminators, and explicit no-paid-campaign gates. It preserves remaining architecture obligations in their planning homes rather than silently treating the first stage as completion.

Pre-Merge Checklist 🚀

🚢 Has this modified a publishable library?

This PR:

  • does not modify any publishable blocks or libraries, or modifications do not need publishing

📜 Does this require a change to the docs?

The changes in this PR:

  • require changes to docs which are made as part of this PR

🕸️ Does this require a change to the Turbo Graph?

The changes in this PR:

  • do not affect the execution graph

⚠️ Known issues

  • No product implementation is included or authorized by this draft.
  • Supported no-wake recording is missing at the inspected Flue revisions.
  • Parent witness limitations remain: direct spoken-user attribution on hydration, post-settlement local withholding, comparative latency, and incomplete retained telemetry. They are not passes for this new architecture.
  • No real microphone/browser trial or paid evaluation was run for this packet.

🐾 Next steps

Review the bounded conversion envelope. Resolve the supported recording prerequisite, then commit owner-approved authority separately before dependent code. Preserve the remaining design obligations through each later gate.

🛡 What tests cover this?

  • Documentation checks verify both draft authority warnings, absence of live-authority headings, nine relative links/anchors, unchanged accepted MISSION.md, and byte-identical preservation of the source design.
  • git diff --check passes.
  • Brunch Markdown is excluded by repository Oxfmt and Markdownlint policy; no formatting pass is claimed.
  • Product tests are not rerun for this documentation-only successor. Planned test commands and required witnesses are in the proposal, not reported as completed evidence.

❓ How to test this?

  1. Compare this PR against FE-1580: Reconcile Voice turn behavior on the shared Brunch conversation #9564's branch: only the future spine and two provisional planning documents should differ.
  2. Read the design and conversion proposal; verify the supported-recording blocker and preservation of all four ownership boundaries.
  3. Confirm MISSION.md is identical to the parent, remaining architecture obligations retain planning homes, and no product readiness or paid-run claim is made.

📹 Demo

Not applicable: this is a planning-only review packet with no UI change.

lunelson and others added 30 commits September 7, 2026 19:18
Make the mounted /agents/chat/:instanceId route the only product door for
both the typed Petrinaut panel and Voice. The typed panel gets a
host-supplied browser ChatTransport over @flue/sdk that reuses the existing
chunk projector; the server-side /api/chat door and its in-process
dispatch path are removed, and transport-aisdk is repurposed as the
browser-side adapter with ai + @flue/sdk as its only runtime dependencies.
Records the boundary inspection that rejected a Hono-level relocation.
Restate the production door as the browser Flue transport at the mounted
route, mark the Mission 8 restricted-ingress rule and /api/chat service
contract as superseded pending re-expression at the release gate, consume
the adapter-removal precondition, and point drafts 6, 7, and 10 at the
successor of the /api/chat integration scenario.
State the release note, no-engineer demo script on the local deployment
posture, and previously-impossible delta (Stop that really stops; one
shared typed/spoken conversation), pin completion to the contract stratum
rather than the first green tracer, and mark the single-route
consolidation as internal sequencing rather than the visible advance.
Name Mission 5's surface as the Petrinaut Brunch panel's typed and Voice
route and record that the live branch adopted the litmus on restack.
Now that the panel composer is itself Flue transport, let Voice enter
either through it (preferred, one visible store) or by a direct send();
reword proof leaf 3 to forbid only non-Flue submission and record the
choice and its fallback criterion on the fog-line.
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Update the living Petrinaut integration spec and topology reference to name
the guarded Flue conversation mount, browser ChatTransport projection, and
current transport-package dependency boundary. Narrow the Mission 5 route
scan claim to its actual production paths while preserving superseded
/api/chat references as historical provenance.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…n projections

Review of PR #9528 read the ten bot findings as samples of three faults.

Stop was not bound to the turn it targeted: a Stop during an in-flight
admission now waits for that admission before the conversation-wide abort, a
durable Stop result that lands after a newer turn started is ignored, and a
Voice turn whose submission settles aborted closes its Realtime call without
speaking, driven by Flue's settlement index because the AI SDK reports ready
between a step and its automatic client-tool follow-up.

The live-stream and snapshot projections encoded the same rules twice: the
snapshot keeps providerExecuted on a running server tool and folds a
client-tool continuation into the assistant message it resumed; the transport
reports the resumed assistant id and the tracker keeps the originating
submission for it; one client-tool catalog feeds the panel transport and the
history projection; host history hydrates only once it carries every locally
streamed reply.

A retained Voice input can be withdrawn through an AbortSignal, a consumer
stream cancel no longer writes to a closed controller, and first-canonical-text
latency is recorded when the first completed text block appears.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
A client-tool continuation is projected onto the assistant message it resumes,
so one message can be written by several submissions, and either side may have
admitted the continuation: the panel after a readPetrinautDoc call, or Voice
when it answers a pending brunch_ask. Keeping only the first submission served
one direction and broke the other. The tracker now records every submission
per message, segments carry that set, and the bridge matches by membership
while excluding segments that predate the answer.

The Stop generation guard also covers the rejection path, so a durable Stop
that fails after a newer turn started no longer records an error on that turn.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…ld it

The AI SDK reports ready between a step that ended in client tool calls
and the follow-up it sends automatically. Hosts read that gap as the end
of the turn: the Voice bridge closed its Realtime call on the step's
partial text, and a Stop whose durable abort landed already-settled did
nothing while the follow-up went out anyway. The panel now keeps its
composer status busy until the follow-up starts, and a Stop pressed
during the step withholds the follow-up and marks the response stopped.
@kostandinang kostandinang self-assigned this Sep 7, 2026
@vercel

vercel Bot commented Sep 7, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
petrinaut Ready Ready Preview Sep 8, 2026 7:41am UTC
3 Skipped Deployments
Project Deployment Actions Updated
hash Ignored Ignored Preview Sep 8, 2026 7:41am UTC
hashdotdesign-tokens Ignored Ignored Preview Sep 8, 2026 7:41am UTC
petrinaut-docs Ignored Ignored Preview Sep 8, 2026 7:41am UTC

Request Review

@github-actions github-actions Bot added area/infra Relates to version control, CI, CD or IaC (area) area/libs Relates to first-party libraries/crates/packages (area) type/eng > frontend Owned by the @frontend team labels Sep 7, 2026
Restore the planning-only tree from before the evidence publication, retaining the published commits in history. Local evidence remains in the original successor worktree.
@lunelson
lunelson force-pushed the ln/fe-1580-reconcile-voice-resumable-workpiece branch from a0ca1cb to 704f961 Compare September 8, 2026 08:23
@github-actions github-actions Bot added area/deps Relates to third-party dependencies (area) area/tests New or updated tests area/apps area/apps > hash.design Affects the `hash.design` design site (app) labels Sep 8, 2026
@lunelson
lunelson force-pushed the ln/fe-1580-reconcile-voice-resumable-workpiece branch 2 times, most recently from de65620 to bfd99d3 Compare September 8, 2026 14:09
@lunelson
lunelson force-pushed the ln/fe-1580-reconcile-voice-resumable-workpiece branch 2 times, most recently from b1bb132 to 743c3c8 Compare September 8, 2026 14:58
Base automatically changed from ln/fe-1580-reconcile-voice-resumable-workpiece to main September 8, 2026 16:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/apps > hash.design Affects the `hash.design` design site (app) area/apps area/deps Relates to third-party dependencies (area) area/infra Relates to version control, CI, CD or IaC (area) area/libs Relates to first-party libraries/crates/packages (area) area/tests New or updated tests type/eng > frontend Owned by the @frontend team

Development

Successfully merging this pull request may close these issues.

2 participants