Repository navigation
feat(host): let agents discover and message channels on peer hosts - #160
Draft
iamnbutler wants to merge 1 commit into
Draft
iamnbutler wants to merge 1 commit into
iamnbutler wants to merge 1 commit into
Conversation
This was referenced Oct 6, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Native agents'
channelsandmessagetools now reach channels on reachable peer hosts, not only the local catalog. Part of #57; draft until two-host acceptance (#10). Dogfooding: #5.host.sockin their host's data directory, authenticate with its owner token, and verify the returned home. Discovery and delivery obey the gateway's shutdown/update rules; conflicting hosts are refused.channelslists local channels, reachable peers' channels and offline ones from the directory, with id, host, owner, state and project. A repeated name is refused with the candidate ids.messagedelivers locally or relays once to the peer that runs the channel through a new peer-onlydeliverrequest. Peers never forward further.agent.<source id>@<login>, using its owner's login or the peer's Tailscale-verified login. Caller-supplied authors are ignored. Agents are never the owner, so sharing off refuses invocation. The source id is the reply address and survives renames. Relayed request ids are scoped to the verified login; local ids are unchanged.Validation
bun typesandbun run cipass. The disposableace serve --port 4357profile used real Anthropic models and only disposable channels. Checked: say and invoke, a reply by source id after a rename, name ambiguity, sharing off, replay and peer/local request-id isolation (confirmed in SQLite), and refusals. Also checked: peer delivery over this Mac's own tailnet listener with realwhois, socket lifecycle, drain at SIGTERM, and CLI-only fallback. Full record: #57 (comment).Not verified: two real hosts or a second distinct login. The only online peer Mac had no Ace gateway (ports 4140–4142 refused). Two-host discovery and delivery, collision isolation between distinct logins, reconnect, and directory-listed offline peers remain open.
Built in Ace
Implementation, runtime checks, commit, push and this PR were done inside the Ace channel
peer-channel-messagingwith its shell and file tools. Codex, outside Ace, audited the source read-only, coordinated this channel and independently reviewed the design and diff, because the Codex harness is not available inside Ace (#9).