-Wire the #99 stage-4 `mcp-resource-updated` delivery route into generated stateful MCP servers. `@agent-bundle/runtime/notices` gains `createNoticeInboxSignaller` — one connection's subscription to the reserved inbox resource (`AGENT_NOTICE_INBOX_URI`) that, after each completed render, sends at most one `notifications/resources/updated` for the subscriber's newly eligible pending notices and records it through `signalAvailability()` as an availability receipt (never delivery), honouring `nextAttemptAt` and bounding signals per notice by `retryBudget` across restarts. The ledger gains `reserveAvailability()` / `releaseAvailability()` (and `AgentNotice.availabilityReservation`, `AGENT_NOTICE_AVAILABILITY_RESERVATION_TTL_MS`): the signaller holds a notice's budget slot by compare-and-swap before the wire write so concurrent processes cannot both send, finalizes the hold into the receipt only when the protocol write succeeds, and releases it when the write fails, so a failed send costs no budget and the receipt always means the write succeeded. The hold is renewed while the write is pending (a different key may take it over only after the TTL, and a lapsed holder cannot steal it back), a reserved receipt is recorded only by the key that still holds the slot (otherwise `signalAvailability()` rejects with the new `AgentNoticeError` code `reservation-lost`; a notice acknowledged, expired, or withdrawn while its send was in flight keeps the hold and records the receipt without changing state), and a receipt whose commit failed after a successful send is retried idempotently on the renewal cadence, before later observations, and on `close()`; `unsubscribe()` resolves only after in-flight observations settle; `@agent-bundle/runtime/mount` gains `createGeneratedNoticeRuntime` and `GeneratedRuntimeState.noticeLedger()` so a server process can hold its own handle on the durable store its worker mounts. Generated workspace-durable MCP entries now register `resources/subscribe`/`resources/unsubscribe` for the inbox URI only, advertise `resources.subscribe` exactly when that wiring is active, fail subscriptions closed when the store is unreadable, and the inbox projection exposes the `availability` receipt alongside `exposure`. Volatile lifetimes keep the store in the worker's heap and advertise no subscription capability.
0 commit comments