feat(discord): SetSpark record client for the Discord Sage, fixed verbs against setspark-api, connector-verified approvals (#1509)

Row 25, parts 2a and 2b, against the shared-signals contract a5425a2.

Model side: eight fixed verbs in the pi extension (record_list, record_get,
record_create, record_update, resolve_id, open_approval_request,
get_approval_request, create_document), each one HTTP call with arguments
checked before any request. Writes carry an idempotency key
<principal>:<message id>:<call index> and an audit context. The seat key is
read from a 0600 file on every call and never cached, printed or journaled.

Connector side: append-only approval ledger, Approve button and exact
"approve" reply resolved by the connector against the required approvers,
confirmation message posted as button evidence, bind and add_approval through
the service under connector keys, retry of unknown entries on start.

Evidence: node tests 162 pass, scripts/test-discord.sh 63/63. Review by
rev-code-02, round 1 approved (#1509 comment 26467, tree 7872d8c5).

Co-Authored-By: Claude Fable 5.1 <[email protected]>
This commit is contained in:
2026-09-22 12:59:39 -05:00
co-authored by Claude Fable 5.1
parent 1949ed8d31
commit 43d7574d6a
24 changed files with 2178 additions and 32 deletions
+7
View File
@@ -110,6 +110,13 @@ if [ -x "$PI_BIN" ]; then
>"$SANDBOX/pi-vault.out" 2>"$SANDBOX/pi-vault.err"
grep -qxF 'PROBE ["edit_file","git_commit","git_pull","git_push","git_status","list_dir","read_file","reserve_id","search","write_file"]' "$SANDBOX/pi-vault.err" && grep -q '"command":"get_state","success":true' "$SANDBOX/pi-vault.out"
check "real pi with protocol vault adds reserve_id to the git verbs" $?
printf 'not_a_real_key_just_a_test_value_x\n' >"$SANDBOX/setspark.key" && chmod 0600 "$SANDBOX/setspark.key"
TOOLS_SETSPARK="{\"roots\":[{\"name\":\"docs\",\"path\":\"$SANDBOX/toolroot\"}],\"maxFileBytes\":4096,\"maxCallsPerTurn\":8,\"setspark\":{\"baseUrl\":\"https://api.setspark.invalid\",\"keyFile\":\"$SANDBOX/setspark.key\",\"principal\":\"sage\"}}"
printf '{"type":"get_state","id":"a"}\n' | MOSAIC_DISCORD_TOOLS="$TOOLS_SETSPARK" timeout 60 "$PI_BIN" $PI_COMMON --no-builtin-tools \
--extension "$EXT_DIR/tools.mjs" --extension "$PROBE" --tools list_dir,read_file,search,record_list,record_get,record_create,record_update,resolve_id,open_approval_request,get_approval_request,create_document \
>"$SANDBOX/pi-setspark.out" 2>"$SANDBOX/pi-setspark.err"
grep -qxF 'PROBE ["create_document","get_approval_request","list_dir","open_approval_request","read_file","record_create","record_get","record_list","record_update","resolve_id","search"]' "$SANDBOX/pi-setspark.err" && grep -q '"command":"get_state","success":true' "$SANDBOX/pi-setspark.out" && ! grep -rq 'not_a_real_key' "$SANDBOX/pi-setspark.out" "$SANDBOX/pi-setspark.err"
check "real pi with a setspark key exposes the reads and the eight record verbs, no counters, and never shows the key" $?
TOOLS_GIT_RO="{\"roots\":[{\"name\":\"ss\",\"path\":\"$GITROOT\",\"git\":$GIT_JSON}],\"maxFileBytes\":4096,\"maxCallsPerTurn\":8}"
printf '{"type":"get_state","id":"a"}\n' | MOSAIC_DISCORD_TOOLS="$TOOLS_GIT_RO" timeout 60 "$PI_BIN" $PI_COMMON --no-builtin-tools \
--extension "$EXT_DIR/tools.mjs" --extension "$PROBE" --tools list_dir,read_file,search \