Repository navigation
0.10.1: contributor integration, human-wait lifecycle, and release qualification - #6846
Merged
Merged
Conversation
Signed-off-by: LIghtJUNction <lightjunction.me@gmail.com>
…s around it
A client that wants to say "this command changed these files" has had nothing to
read. The engine records a shell command's writes as a command execution, never
as a `file_change` item, so the only per-call attribution a client could find was
`metadata.mutation`, which only file tools publish. The turn's snapshot delta
covers the turn rather than the call, and deriving it per call meant diffing two
trees the Runtime API did not expose.
The engine already brackets every call that may write — a file tool, a shell
command, a program, a write-capable MCP tool — with a `tool:<call_id>` restore
point before it and a `post-tool:<call_id>` one after, and records both on the
turn. This adds the route that reads that pair, plus the two small pieces it
needs: `SnapshotRepo::has_tree`, so a receipt whose objects have been pruned is
reported as such instead of as a git failure, and `SnapshotRepo::patch_between`,
one path's unified diff between two trees.
GET /v1/threads/{id}/turns/{turn_id}/calls/{tool_call_id}/changes
answers with the change kind, the line counts, the revision the span left and the
patch, per path, all read from the two trees rather than from the working copy.
The answer is therefore what the call did, not what the file holds now. Every
entry carries the span's own revision and the restore point `file-revert` accepts,
so a command's write is revertible like any other.
What the span is not is attribution by cause. It is a window of time: another
writer in the same workspace during the call is inside the difference, and a path
the snapshots do not track (a `.gitignore` hit, `node_modules/`, a binary) cannot
appear at all. A call the engine judged read-only took no receipts, one whose
closing snapshot was lost has half a pair, and an older turn's trees may have
been pruned — each answers `state: "unavailable"` with its own `reason`, which is
a different answer from an empty `files` list and has to be read as "unknown"
rather than "changed nothing".
The tool call id is the model endpoint's own opaque string, echoed back verbatim,
so this compares it rather than parsing it: the charset a *record* id is held to
would refuse `call_01_…|<uuid>` and answer "no such call" for a call the turn
plainly recorded.
Signed-off-by: Ben Gao <bengao168@msn.com>
…dows paths Both platform failures were the same test-side assumption, not a production regression: the suite assumed the raw `TempDir` path is what the config layer reports, which only holds on Linux. The permissions path is resolved through `codewhale_config::normalize_config_file_path`, so the reported path is canonical: `/private/var/...` on macOS and `\\?\C:\...` with the long name on Windows. `crates/config` is untouched by this PR, so this is baseline behaviour that the Linux-only local gate simply cannot see. - `config_policy.rs`: assert the view path against the same resolver the production path uses (`resolve_permissions_path`) instead of the raw fixture path. - `config_policy_baseline.rs`: replace the canonical workspace form before the raw form. Substituting the raw prefix inside the canonical path left a stray `/private` behind on macOS (visible as `"/private<WORKSPACE>/permissions.toml"`) and missed the verbatim path entirely on Windows. Reproduced on Linux with a symlinked `TMPDIR` (raw != canonical): both tests fail identically to the macOS/Windows CI before the change and pass after it.
PR #6832 Windows CI failed only idle_managers_sharing_a_store_do_not_poll_it_continuously: two legitimate startup reloads landed in the zero-reload observation window. The fixed 2.3s startup sleep runs from manager creation, but each worker schedules its 2s metadata retry after its first claim completes. A delayed initial claim can therefore put that retry after the counter reset. Wait for 2.4s of observed load-counter quiescence, with a 10s deadline, before starting the unchanged zero-reload measurement. Apply the same setup to the running-task flush test. Keep task wakeup assertions and production scheduling unchanged. Continuous periodic reloads time out. Validation: - CI-profile nextest, TUI lib, all features: 6 tests run, 6 passed, 14,593 outside the focused selection. - Temporary timing harness extracted the real ClaimSchedule and new wait helper: a 750ms delayed first claim fails the original fixed-sleep assertion, passes with the corrected wait, and an unconditional 2s fallback is rejected at the 10s deadline. - cargo fmt --all -- --check and git diff --check passed. Hosted Windows verification remains pending the follow-up CI run. Signed-off-by: Paulo Aboim Pinto <paulo.aboim.pinto@gmail.com>
…oundaries Replace the PR #6832 idle-test timing workaround with explicit completion receipts on the existing task manager's worker/caller boundary. Each worker owns a bounded inspection mailbox. Every request carries a oneshot reply, sent after the actual queue operation and schedule update. Startup awaits an initial receipt from every worker, with cancellation cleanup, rather than returning merely because workers were spawned. Receipts describe a per-worker decision, not global quiescence or task completion. Claimed tasks execute after their inspection receipt; failed claims return errors and retain their retry/backoff behavior. The three idle/external-queue regressions now use acknowledged cycles and controlled executor start/release messages. Fixtures explicitly supply settled file timestamps, and scheduling tests supply wall-clock inputs. No fixed startup sleep or observation window establishes success in those tests. Existing production metadata-settling and retry policy is retained. Add boundary coverage for all-worker replies, dropped receivers, shutdown, and corrupt-store recovery; adapt the real process-ownership helper to retain control of the worker JoinHandle. Code comments document the completion boundary and why elapsed silence cannot establish it. This repairs pre-existing task-manager code, independently of FEAT-027's command-shape changes. The original regression arrived in 309f329 and its zero-reload contract in 07a6539. Validation: - CI-profile nextest, all features: 79 task-manager/ownership tests passed. - CI-profile nextest: 61 automation/runtime-ownership caller tests passed. - Production TUI library Clippy with the CI lint flags passed. - cargo fmt --all -- --check and git diff --check passed. - Exact extracted scheduling tests: 2 passed; restoring unconditional fallback polling makes the settled-queue test fail immediately. No existing Gherkin scenario owns this internal boundary. The focused suite exercises actual worker messages, persistence, and subprocess ownership/restart behavior. Hosted platform CI remains a separate gate. Signed-off-by: Paulo Aboim Pinto <paulo.aboim.pinto@gmail.com>
Box the plugin provider snapshot so the runtime route remains small enough for async test stacks, and add the contributor credit required by CI. Local checks: - cargo check -p codewhale-tui --lib --locked - cargo fmt --all -- --check - python3 scripts/check-contributor-credit.py - git diff --check
Restore the two large source files after the GitHub API upload truncated their first update. The resulting tree contains only the intended boxed provider snapshot and contributor credit changes.
The image_analyze tool held the original image bytes yet let the vision model guess the image size from the picture, which matters for downstream layout and analysis reasoning. The tool result now carries the image's pixel width and height plus a format label, read with the image crate's header-only image_dimensions probe so no pixel decode is needed; the format label comes from the same extension decision as the mime detection. Animated GIF/WebP report the first frame's size. The probe is best-effort: when the header cannot be parsed — including BMP, whose decoder is not compiled in — the fields are omitted and the tool still succeeds, since the vision request itself does not depend on the metadata. The tool description now tells the model to take image size from that metadata instead of guessing by eye, names the fields as the stored dimensions (camera rotation metadata is not applied), and scopes the promise to images whose container can be sized. Tests: a wiremock-backed end-to-end case asserts real PNG and JPEG dimensions and the format label reach the result payload; an unparsable-bytes case pins the degradation (tool succeeds, no width/height/format keys); a well-formed minimal BMP pins the no-decoder-feature omission boundary. Signed-off-by: asto <asto18089@126.com>
…der LPAC Hosted Windows (LPAC) refuses lstat on the drive root, so Node's JS realpathSync — which walks every ancestor — failed the reviewed-closure checks with EPERM lstat 'C:\' (13 failures on #6815, mostly extension_host::native_mcp and raw_agent_presets). The earlier attempt (4e1905b, reverted) used realpathSync.native but compared its spelling against raw input. New src/dsh/canonical-path.ts is the one comparison rule: canonicalize with realpathSync.native on win32 (GetFinalPathNameByHandle, no ancestor walk) and realpathSync elsewhere, strip \\?\ and \\?\UNC\, compare case-insensitively on win32, and express containment as relative(canonical root, canonical target). A canonical path is never compared to a raw one. resolve-hooks keys closures by canonical root and remembers the raw root; the Node load hook now also refuses symlinked closure modules (under --preserve-symlinks an in-closure symlink pointing outside kept its in-closure URL and loaded — reproduced on HEAD). Evidence (macOS): npm --prefix crates/tui/extension-host test: 406 tests, 399 pass, 0 fail, 7 skipped (new canonical-path test passes); cargo test -p codewhale-tui --lib -- extension_host dsh: 264-265 pass, 2-3 plugins::install::dsh failures that differ per run and pass in isolation (parallel-load flake under investigation). Windows LPAC itself cannot run here; hosted Windows CI is the proof. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The security-sensitive Windows LPAC path boundary requires confirmation from the mandated hosted Windows run.
Review effort: Balanced
Findings: None
What changed in this PR
Addresses the Windows LPAC lane by making reviewed extension-host path checks robust to canonical Windows path spellings.
Changes:
- Adds canonical path identity, containment, and symlink checks.
- Updates reviewed hook/composition admission and module loading.
- Adds normalization tests and regenerates extension-host bundles.
| File | Description |
|---|---|
crates/tui/extension-host/test/canonical-path.test.mjs |
Tests Windows and POSIX path normalization. |
crates/tui/extension-host/src/dsh/shell-hooks.ts |
Uses canonical symlink-safe hook checks. |
crates/tui/extension-host/src/dsh/resolve-hooks.ts |
Tracks canonical closure roots and validates loaded modules. |
crates/tui/extension-host/src/dsh/canonical-path.ts |
Implements shared canonical-path utilities. |
crates/tui/extension-host/dist/shell-hooks.mjs |
Regenerates the hook test bundle. |
crates/tui/extension-host/dist/dsh-composition-review.mjs |
Regenerates the composition-review bundle. |
crates/tui/extension-host/dist/codewhale-extension-host.mjs |
Regenerates the main extension-host bundle. |
crates/tui/extension-host/dist/agent-presets.mjs |
Regenerates the agent-presets bundle. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
A foreground command that outlives its wait moves to the background with the output so far and a task id. It is not killed for running long. Jobs lists only real background shells, and the card names the command instead of a Ctrl+B hint. The model is pointed at tool_search and task_shell_wait, because Bash is hidden. A paste or leading drop of an existing image path attaches it. read and read_media can open that exact attached file outside the workspace, and an oversized screenshot is downscaled. codewhale doctor names the environment variable that holds a key, never the value, and a live probe decides the verdict. Validation: direct rerun of the lane-1 test binary, 13 passed and 0 failed (lowercase bash description and detach, foreground move-to-background, origin identity, doctor_verdict_tests). A broader filter of image_attach, shell, history, jobs and doctor tests was green before a 60-second work-surface test was still running when the watch ended. Conformance goldens re-recorded for the changed tool descriptions. cargo fmt clean on the lane files. clippy -D warnings not run for this slice.
A developer home keeps one built-in computer-use record and snapshot per installed build. /plugin doctor reports what is stale, and --fix retires those records and snapshots, then compacts state.json. The previous file is kept as state.json.pre-gc. It does not delete a user plugin that still has a bundle directory, a snapshot a running process names, or anything inside the grace window. Until this build has its own record, the review it would carry forward is kept. Validation: cargo test -p codewhale-tui --lib -- doctor_reports_read_only_then_fix_retires_stale_records_with_a_backup -- --exact: 1 passed, 0 failed. An earlier gc filter reported 16 passed and this one failure, which was the test looking for an unescaped hyphen in escaped output.
An HTTP 400, 402, 405, 409, 413 or 422, a spent balance, a context-budget stop, and a turn's own step or wall-clock ceiling now carry an input or budget label. A bare ERROR is an unreadable provider error, not a warning. An in-200 error frame that arrives before any content is retried, and its recoverable flag tells the truth. Refs #6843 and #6795. The wider input category must not make compaction drop history. A max_tokens or temperature rejection names a token or a maximum without being a length overflow, so the drop-oldest ladder now requires real overflow wording. Validation: an earlier cargo test of error_taxonomy, error_frame, placeholder_error, exhausted_transient, midstream_error, classify_error, session_diagnostics and termination reported 47 passed and 0 failed. Not re-run after the later compaction wording guard.
The drop-path sniff and the attached-image admission each stat and open or canonicalize. The read path already runs that admission inside spawn_blocking. The paste and submit checks run on the synchronous UI thread, where a blocking stat cannot park a Tokio worker. The budget records the sites instead of pretending they are wrapped. CI counted 6 against a budget of 5 on PR 6846.
… theft restore_compaction_checkpoint anchors at the first provenance-stamped carrier and, on the wire predicate, never treats user text as a checkpoint. The existing duplicate-carrier test covers a pasted summary appearing AFTER the real carrier; the mirror order - pasted full summary BEFORE the carrier - is the shape that a content-based anchor gets wrong, because the pasted header matches first and steals the insertion position while the real carrier is replaced elsewhere or dropped. Port that mirror-order regression: with a pasted summary ahead of the stamped carrier, restore must keep the pasted turn verbatim as user content, anchor at the carrier's index, and replace the carrier there with the saved summary. The carrier's text differs from the saved summary so the assertions cannot pass by leaving the history untouched, and the pasted turn carries no provenance block so the assertions fail under any content-based anchoring. Signed-off-by: asto <asto18089@126.com>
/plugin doctor hashed plugin directories with path.canonicalize() on the caller. That caller is the TUI thread, which is a Tokio worker, and the blocking-call ratchet failed the four new sites. Grok Build keeps a filesystem walk synchronous and moves the resolving once, in one spawn_blocking, instead of wrapping each lookup. The doctor now does that: one task resolves the home, lists that home, and resolves what it found. A path the task did not resolve is kept, not retired. python3 scripts/check-blocking-calls-budget.py: exit 0, 534 sites across 165 files, within budget. cargo test -p codewhale-tui --lib plugins::registry::gc::tests: 16 passed, 0 failed, 1 ignored. commands::groups::plugins::tests::doctor_reports_read_only_then_fix_retires_stale_records_with_a_backup: 1 passed, 0 failed.
Version drift failed on #6846 because crates/tui/CHANGELOG.md is a generated slice of the root file, and the root Unreleased section was empty while the slice already named /plugin doctor, #6843 and #6795. The notes now live in the root file. ./scripts/sync-changelog.sh --check exits 0 and the generated slice is unchanged.
A command still running after its foreground wait moves to the background and is not killed. The completion hooks were still expecting the old timed_out failure, which is what Test (ubuntu-latest) failed on 804c631: left "call-timeout unset running true", right "call-timeout unset timed_out false". The after-hook now expects running, and on_error no longer fires for that case because the result is a success. Nonzero exits stay failures. The shell description that says this grew every tool surface by 564 schema bytes and 141 estimated tokens. No tool entered or left a surface. The runtime-contract ceiling records that growth. cargo test -p codewhale-tui --lib -- runtime_shell_completion_delivers_exit_code_and_status_to_hooks bash_completion_hooks_get_exit_code_and_status_for_failures: 2 passed, 0 failed. python3 scripts/check-runtime-contract-budget.py: PASS, all 55 metrics exactly at budget.
After a model switch, /model appends a note saying the change lasts for this session and naming /fleet save, /fleet save-as and /model save-default. The note was an English literal pushed onto the translated ModelChanged sentence, so every other locale got half a sentence in its own language and half in English. Move the note into ModelChangedSessionNote and translate it in the fourteen complete packs. The command names stay literal so they can be typed as shown, and each pack keeps the word it already uses for a Fleet. The English text is unchanged. Signed-off-by: Lstarsky0 <59827030+Lstarsky0@users.noreply.github.com>
Reconcile the complete contributions from #6832 (@aboimpinto), #6867 (@hodeswildsmith455-boop), and #6805 (@LIghtJUNction) with the current Engine, provider identities, reviewed-plugin policy, and task lifecycle. Original contributor histories are recorded by subsequent resolved merges. Fix the already integrated contributor cases: snapshot corruption is an explicit unavailable/error result (#6817), malformed locales cannot select an incidental script (#6860), image metadata uses the exact uploaded bytes and respects available decoders (#6858), automation deletion waits for actual scheduler reconciliation (#6864), and blocking trust/skill reads stay off the async executor (#6869). Preserve #6857's compaction regression. Extend #6872's human-wait lifecycle guard to approval/elevation cards; retire only the matching ended parent request and refresh activity only after a delivered decision. Enforce configured finite approval deadlines in the Engine, including deadline/cancellation races and durable receipts. Serialize Native Windows ACL admission/retirement across Core processes with a logon-scoped kernel mutex, preserving exact SID/object validation. Add an actual child-process lock test; serialize DSH host tests in the existing extension-host lane. Windows execution proof remains hosted CI. Reconcile the vendored computer-use plugin with canonical main a656f67455fc while preserving Core's 0.12.1 embedding contract. Canonical b47/a656 tree passed Ubuntu/macOS/Windows source and package gates, including 28/28 Windows-focused tests and the controlled desktop fixture; this is separate from the new Engine head's CI verdict. Partial adaptation of the discovery-cache priority portion from PR #6393 by @AdityaVG13 (original ac33dd4). Preserve the best match under count and byte limits without importing the unfinished echolocation/fork design; the broader draft remains open. Validation: - npm test: 1286 passed, 0 failed, 7 skipped; web 767/767. - npm run check:web: lint, typecheck and production build passed. - Affected Rust selection: 801/803 initially passed; the two fixture/lifecycle expectation failures were corrected and each passed a focused rerun. - Additional focused Rust: approval 28/28, discovery cache 11/11, OrcaRouter synthetic catalog 3/3, and 33/33 lifecycle/API/routing checks. - Final CI-repair selection: 37/39 initially passed; the BMP feature-proxy and feature-registry summary failures were corrected; both corrected tests passed (2/2, 0 failures). - Qualified Clippy: six packages, all targets/all features, passed with the CI style allowances. Portable no-default-feature check passed; portable policy verifier 6/6 passed; formatting and diff checks passed. - Runtime contract: 55 measured metrics passed after explicit remeasurement; all 21 structural identities were unchanged. Twelve byte/token-estimate budgets account for bounded child-wait disclosure and contributor locale descriptions; no runtime field/prompt was removed to lower the budget. - Persistence budget was not qualified locally: the checker requires a clean tree and this shared checkout retains an unrelated operator file. Clean hosted CI, fresh stamped build and real DeepSeek TUI acceptance remain required before the integration PR can merge to main. Refs #6872, #6843, #6795. Co-authored-by: Paulo Aboim Pinto <paulo.aboim.pinto@gmail.com> Co-authored-by: hodeswildsmith455-boop <hodeswildsmith455-boop@users.noreply.github.com> Co-authored-by: LIghtJUNction <lightjunction.me@gmail.com> Co-authored-by: AdityaVG13 <adityavgcode@gmail.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Record the original contributor history after complete manual reconciliation in b0fb5f8. The tested source tree already includes this PR's intent with current Engine/API/policy conflicts resolved; this merge records the resolution without replacing that verified source tree. The original contribution remains attributed to its original author(s). Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Record the original contributor history after complete manual reconciliation in b0fb5f8. The tested source tree already includes this PR's intent with current Engine/API/policy conflicts resolved; this merge records the resolution without replacing that verified source tree. The original contribution remains attributed to its original author(s). Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Record the original contributor history after complete manual reconciliation in b0fb5f8. The tested source tree already includes this PR's intent with current Engine/API/policy conflicts resolved; this merge records the resolution without replacing that verified source tree. The original contribution remains attributed to its original author(s). Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Record the actual embedded manifest version and canonical source revision in the current release notes; regenerate the packaged TUI changelog. Validation: bundled-plugin claim check passed; version state and 38 feature references passed. npm test: 1286 passed, 0 failed, 7 skipped (web 767/767). npm run check:web: lint, typecheck and production build passed. The previous hosted Version drift failure was a missing version receipt, not permission to waive the gate. Fresh exact-head CI remains required. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Request the canonical codewhale-hq repository and match the canonical URLs GitHub now returns. Keep exact tag, asset, digest, receipt and notarization checks; old-owner and lookalike metadata remain refused. Verified against the real published v0.12.0 GitHub release and release.json: the previous checker returned pending; this checker returns ready with matching ZIP and DMG digests and receipt sizes. No release was published. Validation: npm test 1289 passed, 0 failed, 7 skipped (web 770/770); npm run check:web lint, types and production build passed; diff check passed. Three new canonical-URL and noncanonical-owner cases passed. The installed 903b26e CLI has exactly the same Rust workspace and embedded assets as this commit; only these two website files differ. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Preserve the original 3ebeb29 contribution by @Lstarsky0. Replace both English-only saving notes with ModelChangedSessionNote; all 15 complete locale packs retain the exact three save commands. English is byte-identical to the old receipt. Record the contribution in the canonical ledger and both release changelogs; the website already includes the contributor. Validation: 60 focused Rust tests passed, 0 failed; npm test 1289 passed, 0 failed, 7 skipped (web 770/770); check:web passed; locale parity passed 2454 keys in all 15 complete packs; formatting and diff checks passed. Final combined-head hosted CI and a fresh stamped binary remain required. The unrelated operator constitution file is preserved and unstaged. Co-authored-by: Lstarsky0 <59827030+Lstarsky0@users.noreply.github.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Both commands print a bare success line, which reads as a real fix for a running session - but their pool lives in the command's own process and never attaches to a running TUI or exec session (docs/MCP.md, Connection Lifecycle). Print that boundary and the supported in-session discovery paths where users see the green check, and say it in the `mcp connect` help text. A unit test pins the note's two required elements.
Construct the command dispatcher behind a boxed owner boundary, and box the remaining Runtime restore test phase without increasing any stack budget. Retire initial approvals and elevation retries by tool-decision identity while keeping initial approval authority distinct. Pending-child footer rows follow the visible decision and retire without dismissing an unrelated card. Keep contributor discovery priority and cache limits; correct stale LRU/child surface assertions. Verify OrcaRouter API-key shape/masking and native PKCE selection alongside xAI's device flow, and refresh the owned provider golden. Move three shipped entries from Unreleased into 0.10.1. Retain sealed terminal failure diagnostics in CI (seven days; fixture logs, no credentials/config). Validation: 169 focused Rust tests passed, 0 failed. The explicit default 2 MiB restore guard passed unchanged. Actual all-feature debug executable built in 5m17s; all seven formerly aborting terminal flows passed (148.65s), covering restore, plugin trust/review, automation edit/restart and navigation. npm test: 1289 passed, 0 failed, 7 skipped (web 770/770). npm run check:web passed. Formatting and diff checks passed. Workflow structure validation passed; 12 existing shellcheck diagnostics are unchanged from the base. Compiled-host delivery tests: 7 passed, 0 failed. Hosted full qualification runs on this replacement head before main; no release/publication/deploy. Baseline e090 Linux: 18950 passed, 14 failed, 34 skipped. Windows: 18256 passed (one intentional browser-launch leak), 7 failed, 27 skipped. The seven shared failures plus seven Linux terminal aborts are covered by this repair. Receipts: /Volumes/VIXinSSD/CW/artifacts/takeover-0101-20261005/ Foreign operator controls were preserved and excluded from staging. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
added 15 commits
October 6, 2026 05:37
Pass each admitted endpoint to the shared OAuth client. Disable ambient proxies for permitted loopback HTTP, retain HTTPS proxy support and refuse redirects. All seven consumers use the admitted URL. Omit remote header text from JSON errors and the raw authorization error from recovery warnings. Use the existing Linux renameat2 syscall pattern instead of a missing musl wrapper; preserve retained descriptors and atomic NOREPLACE, with an occupied socket destination regression. A bounded Codex child edited only that file; the captain reviewed the complete diff. Provision parity's real sandbox using the same existing bubblewrap/AppArmor preparation as regular CI. Seal the two shared-process DSH fixtures and forward their existing environment scope to the blocking converter. Prepare RLM admission before its one-second invocation deadline; retain the five-second outside timeout, partial answer and usage assertions. Keep both restore Config instances off the outer default-stack fixture frame; the explicit 2 MiB guard remains unchanged. Verified locally: focused hermetic Rust 130 passed / 0 failed; npm 1289 passed / 0 failed / 7 skipped, including web 770 passed; check:web PASS; repository-policy Clippy for both affected packages/all targets/all features PASS; format/diff and release-parity workflow actionlint PASS. No full local workspace suite was run. Evidence: artifacts/takeover-0101-20261005/security-packaging-local-receipt.json, security-packaging-focused-final.log, security-packaging-clippy.log. Historical hosted failure receipts are retained: Windows had one explicit 2 MiB stack abort, parity had 82 missing-sandbox failures, and two shared-process attempts failed 3 then 2 TUI tests. Fresh-head OS/security/shared-process/RC proof is pending. No publication, deployment, secrets, provider-account or billing changes. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Merge the original SparkofSpike/Sh1Zuku commit a32639a into the shared 0.10.1 release branch. Successful connect/validate commands now explain that they inspect their own process and point users to in-session discovery. This is the original pull request, with its original author commit retained. Reviewed the one-file 39-addition/1-deletion diff. Focused hermetic test: 1 passed, 0 failed; formatting and both staged/unstaged diff checks passed. The preceding repair d24b019 has 130 focused Rust passes, npm 1289 passed / 0 failed / 7 skipped, web 770 passed plus check:web, and repository-policy Clippy. Those repair paths and the web gate are unchanged by this merge. Receipts: contributor-6878-focused.log, security-packaging-local-receipt.json. Fresh final-head hosted OS CI, security, shared-process-twice, release-candidate packaging and stamped terminal dogfood remain required before main. No release publication or deployment. Foreign constitution remains unstaged and intact. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
An approval can be delivered by a getupdates request already in flight when the fixture snapshots the poll count. The decision becomes observable before that batch returns and the bridge starts its next request. Checking the count immediately after the decision raced the real polling loop in hosted CI. Reuse the existing bounded until predicate to await both the owner's decision and subsequent poll progress. Keep the existing 8-second fixture deadline, 1.5-second turn timeout, deduplication, owner binding and privacy assertions. No production bridge code or runtime deadline changes. Verified: actual production-process fixture 11 passed / 0 failed; npm 1289 passed / 0 failed / 7 skipped; web 770 passed plus check:web; diff check passed. Previous 130-test Rust repair paths are byte-unchanged. Original CI failure preserved in ci-e206-integrations-failure.log. Receipts: weixin-poll-progress- focused.log, weixin-poll-web-receipt.json. Fresh exact-head release proof remains required; no publication or deployment. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
RC 37468720537 on 16e1596 timed out at 45 minutes while compiling test binaries. GitHub check 112286652963 explicitly reports the 45m0s execution limit; no completed suite was claimed. Retain every parity command and guard, raise its bounded budget to the existing CI test-job budget of 165 minutes, and reuse the workflow-contract timeout helper to prevent drift below that budget. Validation: release-workflow contract passed (152 Rust-consumed inputs, 11 wrapper cases, 13 hermetic invocation checks); actionlint and diff check passed. Fresh npm test: 1289 pass, 0 fail, 7 skip (web 770); check:web passed. Production Rust/web sources and the preserved foreign constitution are unchanged. Current 16e real-DeepSeek late-answer/cancel/full-restart proof remains tied to that binary; final stamp and hosted qualification follow this workflow-only repair. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…sion Seal HOME for both shell-hook import fixtures before native composition reads configuration. Reuse the existing pending provider fixture and Notify/drain pattern to observe actual Core admission before filling the event stream. The one-second invocation deadline, five-second hand-back bound, dropped-call usage and exactly one canonical terminal receipt remain asserted. Completion keeps Python startup outside this channel-specific fixture; the adjacent recursive deadline fixture still checks Python interruption and cleanup. All changes are cfg(test); shipping code is unchanged from the provider- qualified source. This repairs the two fixture failures seen under the full shared process; hosted repeated shared-process qualification remains required. Validation: 64 focused Rust tests passed (30 RLM turn, 6 Core RLM host, 2 shell imports, 26 DSH install), 0 failed, default libtest concurrency. npm test: 1289 passed, 0 failed, 7 skipped (including 770 web tests). npm run check:web passed. TUI Clippy all-targets/all-features passed with the repository warning policy; cargo fmt and git diff --check passed. Foreign constitution retained byte-for-byte; only the two test modules staged. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Both macOS artifact jobs in RC 37468720537 at 16e1596 were cancelled by GitHub at their explicit 90-minute compilation limit; job annotations confirm the cause. Allow the same finite 165-minute cold-build budget as full CI, including native nightly builds. Keep all seven release targets, native launch checks, source identity, asset/inventory validation and the 10/15-minute setup/packaging caps. Reuse jobTimeout in the workflow contract to prevent a native budget below full CI or a conflicting nightly allowance. No publishing, permission, runtime, artifact profile, retry or query changes. Validation: workflow contract passed (152 Rust-consumed input paths, 11 wrapper event cases, 13 hermetic checks); actionlint passed for both workflows; git diff --check passed. npm test: 1289 passed, 0 failed, 7 skipped, including 770 web tests; check:web passed. The preceding cfg(test) repair remains byte-identical to its 64-test and all-target/all-feature Clippy proof. Hosted final-head RC, full CI, repeated shared process and all-language CodeQL remain required. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
The English and Simplified Chinese configuration guides repeated an ordering
that disagreed with the effective base prompt. Replace those paragraphs with
the owning BASE_PROMPT reference and the /constitution base inspection path.
Clarify that file description and assembly order do not establish authority.
No runtime behavior or active constitution is changed.
Validation: npm test passed 1,289 tests, 0 failures, 7 skips:
package 101/0/0; SDK 19/0/0; extension host 399/0/7;
web 770/0/0 (pass/fail/skip). npm run check:web passed facts,
release metadata, documentation, design tokens, lint, TypeScript and
production build, with 894/894 pages generated. git diff --check passed.
Logs: CW/artifacts/constitution-20261006/{npm-test,check-web}.log.
Local checks only; no provider, deployment or release qualification claimed.
Space on an ordinary transcript cell now retains a bounded, addressable preview instead of applying context-menu Hide. Reuse the existing absolute fold authority and final-render owner; a second Space restores that same answer. Keep copy separators and links on preview body rows, preserve the full stored/exported answer, and retain independent explicit Hide/Show. Anchor a selected middle-body row to its owner's first row before folding. Rebase active fold/Hide/tool-expansion indices when late history is inserted, and reject pre-insertion cached actions with the existing identity epoch. Explicit streaming folds use the canonical renderer; untouched streams keep the incremental path. Thinking preferences and user choices remain intact. Validation: 158 focused Rust tests passed, 0 failed, 2 existing timing benchmarks ignored. After the final selected-row fix, all 43 affected UI checks passed again; untouched render scopes retain verified source hashes. All-feature TUI test compilation and all-target/all-feature policy Clippy passed. npm test: 1289 passed, 0 failed, 7 skipped (including 770 web tests); check:web passed, with those inputs unchanged by the final selection fix. Formatting and diff checks passed. Installed de1 reproduced the original first-Space/second-Space failure; final stamped native proof and exact-source hosted qualification follow. Foreign constitution remains byte-identical. Closes #6876. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
The stored-image retry fixture left its successful mock turn active before forking the next case in the same workspace. Finish the mock with the normal message/terminal event sequence and reuse the durable completion helper, which also requires release of that exact turn's active claim. Preserve all image byte/size, schema and route-policy rejection assertions. Seal the DSH HTTP fixture's home through preview and exact installation. The real native sandbox reviewer otherwise borrowed a concurrent credential or diagnostic fixture's temporary home, which could disappear before bwrap probed its completed launch command. Retain the real native attestation and all preview/disabled/untrusted/hash assertions. Both edits are test-only; production restore and sandbox guards are unchanged. Validation: 11 focused Rust checks passed, 0 failed, default libtest concurrency (7 image/restore plus 4 HTTP/home checks, including all three neighboring temporary-home fixtures). All-feature TUI test compilation and all-target/all-feature policy Clippy passed; formatting/diff checks passed. The unchanged npm/web gate passed 1289 tests, 0 failed, 7 skipped, and check:web. Historical de1 Linux nextest failed only the unsettled image test; shared-process pass one was 15285/0/26, pass two 15284/1/26 at this HTTP test. A separate lint runner lost communication after Clippy passed. Fresh exact- source full and repeated shared-process CI remain required before Main. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Capture the authoritative account profile at admission and render it through the existing constitution renderer. Persist the complete guidance snapshot through history repair, retries and compaction; internal follow-ups and RLM children keep the captured parent guidance. Signed-in defaults take precedence over host-local preferences, with account identity and schema validation. Carry the snapshot through HTTP runtime, relay and durable replay admission. Add authenticated Engine preview and label CLI profile precedence. Backend and app source are connected separately; this is unreleased source. The app still requires a qualified Engine release and bundle pin update. Plugin packs, additional override scopes and full resume/provider acceptance remain open. Validation: npm test passed 1,289 tests, 0 failed, 7 skipped (101 package, 19 SDK, 399 extension, 770 web). npm run check:web passed docs/facts/lint, types and production build. Final targeted Rust constitution run passed 47 tests, 0 failed, with 15,267 filtered out, including provider request capture, replay, history repair, compaction, account switching and internal continuation. No deployment or paid provider call. Staged diff whitespace check passed. Concurrent foreign edits remain outside this commit.
…ation Apply rustfmt to the committed account-constitution implementation without staging concurrent auth/computer-display edits. Retain all account, schema, permission, replay and compaction validation. The hosted Mac memory/eval fallback spent 72m59s on its cold test build in run37497498829; RSS assertions passed, but the 75-minute job cap cancelled eval compilation. Give this job the existing Test allowance of165 minutes. The memory ceilings, measurement commands and eval assertions are unchanged. Validation: npm test1289 passed/0 failed/7 skipped (committed source export); check:web passed facts/docs/tokens/lint/types and894-page production build in the original checkout with unchanged JS/web sources. Export-only Next build rejected external dependency symlinks; the normal-tree gate passed. CI wiring19 passed/0 failed; committed-export cargo fmt --check passed; actionlint passed with the existing hosted policy exclusions. No Rust test or Clippy pass is claimed by this formatting-only slice. Exact-source provider/build and hosted gates follow this commit. No deploy, registry publication, release tag or billing action. Foreign work preserved. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Reuse crate::tls::reqwest_client_builder rather than constructing a bare reqwest client. This installs the shared rustls provider and platform certificate verifier on first account access. Keep redirect refusal, the ten-second timeout,256KiB response cap and account/schema validation. G2 manual Lint112445742741 passed all-target/all-feature Clippy but caught this bypass in the existing constructor guard. Fix the source, not the guard. Validation: five constructor-checker tests passed/0 failed; whole-source constructor check and formatting passed. Twelve further static source/locale/ budget checks passed in the committed projection. The Git-dependent command migration check refused a history-less export and passed in the original checkout against ecbf286; the refusal is retained as an environment limit. Previously completed unchanged npm/web inputs:1289 pass/0 fail/7 skip, check:web pass/894-page build. They were not repeated solely to commit. Full latest-source CI, release rebuild and provider acceptance remain gates. Foreign edits preserved and unstaged; no deploy/tag/registry/billing action. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Mint immutable Watch/Drive intent, defaulting omitted intent to Watch. Watch permits reads and observed display while refusing Runtime writes, upgraded write channels, control acquire/release and forwarded input. Require a live exact principal for control ownership even when device labels coincide. Advertise client_token_intents only from the enforcing router; legacy omitted capability decodes false. Preserve owner minting and committed constitution integration. Current-source local gate7/7: fmt and whitespace0, dead-code253/258, runtime-contract55 metrics at budget, TUI client-token3/0, protocol1/0 and feature registry6/0; zero ignored. All3907 source entries stable, full snapshot2a79d77b and reviewed candidate tree9ee4a59c. Earlier fixture404 and partly unexplained historical test-hash mismatch retained; fresh current-tree checks supersede readiness reliance on that snapshot. Hosted full CI/RC and actual enforcing Linux-package admission remain open. This source integration does not publish, deploy, change pins, allocate a provider VM, grant an account plan or call a model. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Destination validation and rename share the bounded Windows sharing retry budget. Preserve complete records, corruption/quota/revocation guards and own-temp cleanup; add a controlled transient validation regression and a nonsharing error preservation case. The original same-key cross-process case is unchanged. Local gate under Node22: npm test 1291 passed, 0 failed, 7 skipped (wrappers101, SDK19, source-host401, web770); check:web build passed. Storage Node20/0 and Bun20/0; extension-host typecheck passed. Identical new regression against saved committed source failed0/1 at550ms virtual delay with old bytes preserved; repaired source succeeded at750ms. Exact source snapshot e2c801a846eaf1aa562c22ce7b6d42015f8c897df89489433999ca449abf10eb unchanged across gate. Independent review f968d8c6b0dbaf2b0608cb2ab939b4823b4fd386a60b6e1fdfc30c76dcc9038b. Evidence: CW/artifacts/setup-design-refinement-20261006/windows-source-host-storage-repair and windows-storage-root-gate. Original hosted EPERM syscall remains unknown; actual Windows Node/Bun/compiled-host qualification is pending. No Rust build, provider/model/account call, deployment or publication. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
The be15abf source-only storage repair left the committed host bundle stale. Hosted Integrations correctly rejected the mismatch after its source tests passed. Regenerate with the existing locked esbuild build; the shipped host now revalidates the destination within the bounded Windows save retry. No corruption, revocation, quota, symlink, or atomic-publication guard changed. Gate on Node 26.10.0: npm test 1291 passed, 0 failed, 7 skipped (wrappers 101, SDK 19, source-host 401, web 770); check:web passed, 894 static pages. Host typecheck passed. Bun 1.4 suite: 402 passed, 0 failed, 6 skipped. Source and regenerated bundle were unchanged across these checks; bundle SHA256 2447111bb443cb631ff6181c1fc1f6b87f91f64eb4c5cd07dff763e97d12ebb7. Evidence: artifacts/takeover-0101-20261005/G5-generated-bundle-local-gate.json and the preserved G5-integrations-failure.log. Exact resulting-head hosted CI, shared-process qualification, release-candidate packages, installation, and provider QA remain separate gates. Foreign constitution work excluded. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
3 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This brings the ready community contributions into 0.10.1 and repairs turn recovery when Codewhale is waiting for a person. An unlimited question retains its original turn beyond the hung-tool timeout; the answer reaches that original request. Space folds a settled answer into a visible preview and restores the complete body on the next Space. Finite deadlines, elevation, child budgets and cancellation retain their own authorities.
Closes #6872.
Closes #6876.
All eleven original contributor PRs retain their original heads and authorship: #6817, #6860, #6858, #6864, #6869, #6857, #6832, #6867, #6805, #6875 and #6878. Resolved merges preserve their ancestry. The broader contributor draft #6393 remains open; its previously credited discovery-priority portion is included. #6807 is the founder's unfinished pet draft. The 23:03 UTC seven-repository sweep since22:14 found no new outside report or issue update; the earlier all-open PR audit found no omitted ready human contribution.
Account guidance enters the existing Engine at user-turn admission through the existing constitution renderer. Identity/schema/fingerprint-bound snapshots follow HTTP/relay admission and durable replay, survive compaction/history repair, and remain fixed for internal continuations and RLM children. Request bounds, canonical TLS, redirect refusal and permission checks remain enforced. Signed-out use retains local guidance; live account sync and the app's current Engine bundle require separate qualification.
Device tokens now carry immutable Watch/Drive intent. Omitted intent defaults to Watch: ordinary reads and observed display are permitted; Runtime writes, upgraded write channels and control acquisition/release are refused. Control ownership requires the exact live principal. The enforcing router advertises client_token_intents; a legacy omitted capability decodes false. Owner token management remains enforced.
Windows storage revalidation and atomic publication now share a bounded sharing retry. Corruption, revocation, quota, symlink and old-record preservation guards remain enforced. The initial hosted EPERM syscall was not identified; the controlled source regression establishes the narrower retry defect. Its source-only landing omitted the embedded bundle, and hosted Integrations correctly rejected drift. The current correction regenerates that bundle with the existing locked build.
The recovered Claude native terminal-gallery website, authored Cloudflare cf tooling, repository-transfer fixes, reviewed plugin/provider routes and native extension-host isolation remain included. OpenNext's official compatibility delegate stays pinned. Current-source website packaging is in the nonpublishing RC gate. The public preview and published downloads remain0.10.0 and require human deployment approval.
Current candidate:
ed5e3f10dac5a3048ce379f64e7b6c7ffea77a1a(G6), tree00ae31ddea06aac8e9f52a15f94983de4b5afb9d. Exact3907-blob export excludes the foreign constitution edit. Current synthetic mergee8d835064fe0d95e7d25ba389bff1e8c4a8f13dbhas Main+candidate parents and exactly the candidate tree; all11 original PR heads are verified ancestors. The governed two-job optimized build passed against all 3907 verified committed blobs/modes; atomic installation and actual current-binary acceptance passed. All six aliases, including both legacy codewhale-tui paths, report codewhale 0.10.1 (ed5e3f1), signed SHA25672b85b0cc4454253ff39807d1e64d8fff08dc70a6736346555a7a63af1696952 with valid local ad-hoc signatures. The stale legacy executable was preserved before atomically replacing it with a symlink.Current gates:
Actual current-binary acceptance, pinned to G6
ed5e3f10dac5a3048ce379f64e7b6c7ffea77a1a:Superseded G3/G4/G5 receipts and raw failures remain retained with their original source identities; cancelled or interrupted runs are not current passing evidence.
Refreshed companion Main receipts: app39272491 hosted37530660143 SUCCESS with desktop606/0/1ignored, Engine library1535/0/5ignored, Node1056/0+40/0. Platform98c2433c hosted37533670720 SUCCESS with npm5365/0/241skip, local test:live5790/0/10skip, web1378/0/3skip+280/0. The fallback Linux job was skipped; the required gate actually executed. Prior appa5e3200e cache relocation remains a separately pinned receipt: idle cache preserved and hash-verified on SSD,44GiB restored,20GiB guard unchanged. Ops remote Main07f1a173 reconciles the release pointer and current auth status; its two source validators passed with unchanged historical reference files disclosed. These results do not establish current app bundle/signing/upgrade or customer completion.
Evidence is in
artifacts/takeover-0101-20261005/, including G6-source-run-map.json, G6-exact-source-export-proof.json, G5-generated-bundle-local-gate.json, G6-synthetic-merge-tree-proof.json and eleven-original-contributors-G6-proof.json. Only owned paths were staged.All exact-candidate source gates passed. Final live refs still match the qualified candidate and base, four-language current security has0 open findings, both review threads are resolved and all11 original contributor heads remain ancestors. The original integration PR is ready to merge as itself. The actual Main merge SHA will require its own nonpublishing RC before a human-authorized release tag. Ordinary-user Windows Terminal clipboard, release signing, published artifacts, production deployment and GPUI/customer acceptance remain separate. No tag, registry publication, deploy, DNS, secret or billing change is implied.