Repository navigation
0.10.1: account, bridge, avatar and cross-platform release qualification - #6880
Conversation
…idge records Render the reviewed Simplified Chinese installation source through the shared guide parser and locale content map. Preserve tested0.10.0 installation scope, Unicode anchors, copyable command bytes, link confinement and table labels. Document current Main builds for contributors, the verified CNB binary gap, npmmirror wrapper integrity and recovered bilingual Tencent Lighthouse setup. Fill missing Chinese stream/auth/runtime/skills/catalog/extension contracts. Add bilingual current speech support and sourced media candidates; Index's bounded public API probe returned412, so no working service is advertised. Canonical bridge-core retries only bounded Windows sharing failures during atomic replacement without unlinking the old record. Keep the eight-writer regression and add actual Windows held-lock release/refusal coverage. Native Windows receipt is pending the marketplace three-OS run; no skip of concurrency. Gate: npm test1293 passed/0 failed/7 skipped; npm run check:web PASS, 772 website tests and894 static pages with lint/typecheck/doc guards. Five canonical bridge suites157 passed/0 failed/1 Windows-only test skipped on macOS. Initial two source-shape guard failures retained, adjusted to shared guide ownership rather than English-only rendering; final gate stable across all25 owned paths. All32 new relative links resolve. Foreign constitution hash unchanged and excluded. No tag/publication/deployment/provider spend. Evidence: Chinese-bridge-final-fixed-source-gate.json and Chinese-bridge-final-five-bridge-proof.json in takeover-0101-20261005.
…ownership Require a durable account-and-chat binding before /resume reads a thread, and filter thread summaries to that chat's known bindings. Keep bounded binding history so /new does not strand a chat's own earlier conversations. A replacement account's explicit /new durably retains the previous account state for review and starts fresh without resubmitting its pending prompt or uncertain reply. Same-account pending work still blocks replacement and now receives an answer. Failed batch handlers retain their inflight claims after rejection, matching the production poller. Existing pending admission preservation is retained and proved through a real restarted process at the durable thread-binding boundary. Focused Node bridge gate: 48 passed, 0 failed, 0 skipped, including five new process-level ownership, retirement and restart cases. Evidence: artifacts/takeover-0101-20261005/Weixin-authority-recovery-final-gate.log Hosted CI, final combined Engine gates and installed release QA remain separate.
Reconcile the Chinese operator guide with d796509: same-account pending work still blocks replacement, while explicit /new after account replacement retains the full old receipt privately for human review. Document owner-only summaries, resume and bounded binding history. No automatic resend or retirement cleanup. Implementation gate already passed: 48 passed, 0 failed, 0 skipped. Documentation-only followup; git diff --check passed.
… catalog Dependencies and security - Sharp 0.35.5 in web, telemetry and embedded Computer Use; root drops its unused Wrangler dependency and its now-dead Sharp override. - Web pins postcss-selector-parser 7.1.6; telemetry pins source-map-js 1.2.2. - Extension host @modelcontextprotocol/client 2.2.0 with rebuilt dist; the mcp builtin digest 6eb47316... matches tier.rs, builtin-modules.json and the bundle; LICENSES.txt names the shipped versions. - VS Code: @vscode/vsce 4.0.0 removes the braces/globby and fast-uri chains (six high + one moderate). vsce 4 requires Node >=22, so CI installs, compiles and tests on Node 20 (the extension runtime) and switches to Node 22 only to package. - Website braces GHSA-vfj7-8cjw-p6xm has no patched upstream release. A hash-verified depth guard patches braces 3.0.3 at install; the audit classifier admits only that advisory's complete chains and keeps the raw report. Not a clean raw audit: 9 high upstream findings remain recorded. - security-audit.yml audits all ten committed package-lock.json files and uploads each raw report; any non-web finding fails. - Windows npm wrapper smoke job budget 45 -> 60 minutes: Main run 37547810932 built and smoked successfully, then cache save hit the job deadline. The smoke step keeps its own 5-minute bound. Catalog - crates/tui/assets/first-party-marketplace.json regenerated with scripts/sync-marketplace.py from merged marketplace 6512f1dfaa91 (PR #10): 19 plugins, was 6 at ae3dd225. The store regression now expects 19 and keeps its zero-error/warning, installability and no-implicit-trust checks. - Embedded Computer Use provenance f585fbd2 (canonical PR #12); its lock packages are identical to canonical main. Evidence (local, macOS, this tree) - npm test && npm run check:web: exit 0; node:test 528 pass / 0 fail / 7 skip (6 compiled image not requested, 1 Bun only), vitest 772/772, 894/894 static pages. - Compiled Bun host against this bundle: 6 pass / 0 fail / 0 skip. - cargo test -p codewhale-tui --lib plugins::marketplace::store extension_host::tier: 9 passed; 0 failed. - VS Code on Node 20.19.5: npm ci + npm test 47 pass / 0 fail; vsce package succeeds (30 files). - Raw complete npm audits: 9 locks total 0; web 9 high raw, 9 mitigated, 0 blocked. - actionlint 1.7.12 with CI ignores: exit 0; security-audit.yml clean unfiltered. release-workflows guard, check-versions --require-dated-release, sync-changelog --check, check-bundled-plugin-claims: all pass. Supersedes dependabot #6879 (same two bumps). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
| const threads = (await runtimeJson( | ||
| "/v1/threads/summary?limit=8&include_archived=true" | ||
| ); | ||
| )).filter((thread) => ownsThread(chatId, state, thread.id)); |
There was a problem hiding this comment.
🟡 Owned conversations vanish from thread listings
When eight newer threads belong to other chats, sendThreads filters the global eight-row page to empty. The owner's older conversations disappear from /threads despite remaining resumable.
Learn more
The Runtime summary endpoint limits its global result before returning it; list_threads_summary scans only the requested number of unsearched threads (list_threads_summary). The bridge now filters those eight rows by the current account and chat, so an owner whose conversations are older than other chats' latest eight receives no results. Ownership bindings are still present locally, and /resume can use the thread ID.
Example: Alice owns thread A. Bob and other users create eight newer threads. Alice's /threads returns “No recent runtime threads owned” although /resume A works.
Recommended fix: Fetch pages or search each locally bound thread using an authenticated detail request, then return up to eight owned summaries; bound the scan appropriately.
Was this helpful? React with 👍 or 👎 to provide feedback.
| `f585fbd256499622a725e5abadfc2382428c2797` while retaining Core's embedding | ||
| manifest and version contract. Its image renderer lock now carries Sharp 0.35.5. | ||
| - The bundled first-party catalog pins marketplace revision | ||
| `6512f1dfaa91ee287e9f81ebabaf4909e8a371a3` and lists all 19 reviewed plugins, | ||
| up from 6. Every catalog plugin still installs disabled and untrusted until | ||
| you review it. | ||
| - Every committed npm lockfile is audited in CI, including build tooling. The | ||
| VS Code extension packages with `@vscode/vsce` 4 on Node 22 while it still | ||
| compiles and tests on its Node 20 runtime. The website keeps one reviewed, | ||
| hash-verified depth guard for an unpatched `braces` advisory | ||
| (GHSA-vfj7-8cjw-p6xm); its raw audit findings are retained, not hidden. |
| ...preservedChatStateFields(existing, replacingAccount | ||
| ? ["model", "contextToken", "retiredAccountStates"] | ||
| : ["model", "authorizedIdentity", "contextToken", "pendingAdmission", "retiredAccountStates"]), |
There was a problem hiding this comment.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Weixin thread listing can hide owned conversations, and batch processing remains duplicated between tested and production paths.
Review effort: Balanced
Findings: 2
Open (3)
What changed in this PR
Finalizes the 0.10.1 release follow-up across documentation, bridge reliability, dependency security, and the bundled plugin catalog.
Changes:
- Adds Chinese installation and platform guidance.
- Hardens Windows durable writes and Weixin thread ownership/recovery.
- Expands npm auditing, updates dependencies, and refreshes the 19-plugin catalog.
| File | Description |
|---|---|
.github/workflows/ci.yml |
Updates VS Code packaging and Windows timeout. |
.github/workflows/security-audit.yml |
Audits all npm lockfiles. |
CHANGELOG.md |
Records release changes. |
crates/tui/CHANGELOG.md |
Mirrors TUI release notes. |
crates/tui/assets/first-party-marketplace.json |
Expands bundled catalog to 19 plugins. |
crates/tui/extension-host/dist/LICENSES.txt |
Updates MCP license inventory. |
crates/tui/extension-host/dist/builtin-modules.json |
Updates MCP module digest. |
crates/tui/extension-host/dist/builtin/mcp.mjs |
Rebuilds the MCP builtin. |
crates/tui/extension-host/dist/codewhale-extension-host.mjs |
Rebuilds host bundle metadata. |
crates/tui/extension-host/package-lock.json |
Locks MCP 2.2.0. |
crates/tui/extension-host/package.json |
Upgrades MCP client. |
crates/tui/plugins/computer-use.upstream-sha |
Updates upstream revision. |
crates/tui/plugins/computer-use/package-lock.json |
Locks Sharp 0.35.5. |
crates/tui/plugins/computer-use/package.json |
Upgrades Sharp. |
crates/tui/src/extension_host/tier.rs |
Pins rebuilt MCP digest. |
crates/tui/src/plugins/marketplace/store.rs |
Updates catalog count assertion. |
docs/CNB_MIRROR.md |
Documents current mirror status. |
docs/INSTALL.md |
Adds current-source build guidance. |
docs/MEDIA_MODELS.md |
Documents media model support and candidates. |
docs/PROVIDERS.md |
Links media-model guidance. |
docs/zh_hans/ARCHITECTURE.md |
Expands architecture translation. |
docs/zh_hans/CATALOG_REFRESH.md |
Updates catalog ownership guidance. |
docs/zh_hans/CNB_MIRROR.md |
Updates Chinese mirror guidance. |
docs/zh_hans/CONFIGURATION.md |
Expands translated configuration contracts. |
docs/zh_hans/INSTALL.md |
Updates Chinese installation guide. |
docs/zh_hans/MEDIA_MODELS.md |
Adds Chinese media-model guide. |
docs/zh_hans/PLUGIN_AUTHORING.md |
Updates extension-host guidance. |
docs/zh_hans/PROVIDERS.md |
Expands translated provider guidance. |
docs/zh_hans/RUNTIME_API.md |
Expands translated Runtime API contracts. |
docs/zh_hans/SKILLS.md |
Documents skill discovery behavior. |
docs/zh_hans/TOOL_SURFACE.md |
Documents local execution permissions. |
extensions/vscode/package-lock.json |
Locks VSCE 4 dependencies. |
extensions/vscode/package.json |
Upgrades VSCE to v4. |
integrations/bridge-core/src/lib.mjs |
Retries Windows record replacement. |
integrations/bridge-core/test/lib.test.mjs |
Tests Windows sharing locks. |
integrations/weixin-bridge/README.md |
Documents ownership and retirement behavior. |
integrations/weixin-bridge/src/index.mjs |
Enforces account/chat thread ownership. |
integrations/weixin-bridge/src/lib.mjs |
Retains failed message claims. |
integrations/weixin-bridge/test/lib.test.mjs |
Tests durable inflight claims. |
integrations/weixin-bridge/test/runtime.test.mjs |
Tests ownership and account replacement. |
package-lock.json |
Refreshes root workspace lock. |
package.json |
Removes obsolete root overrides. |
telemetry-ingest/package-lock.json |
Locks dependency fixes. |
telemetry-ingest/package.json |
Pins Sharp and source-map fixes. |
web/app/[locale]/install/page.tsx |
Selects localized generated guides. |
web/docs/DEPENDENCY_SECURITY.md |
Documents the braces mitigation. |
web/lib/content/install.ts |
Updates localized installation notice. |
web/lib/install-guide.test.ts |
Tests Chinese guide generation. |
web/lib/public-copy.test.ts |
Updates generated-guide contract. |
web/lib/public-surface-contract.test.ts |
Updates public surface assertion. |
web/package-lock.json |
Locks web dependency upgrades. |
web/package.json |
Adds auditing and braces patch scripts. |
web/scripts/audit-dependencies.mjs |
Classifies reviewed audit findings. |
web/scripts/dependency-security.test.mjs |
Tests mitigation and audit classification. |
web/scripts/derive-install.mjs |
Generates both installation guides. |
web/scripts/install-guide-lib.d.mts |
Updates guide generator types. |
web/scripts/install-guide-lib.mjs |
Adds localized guide rendering. |
web/scripts/patch-braces.mjs |
Applies the hash-verified depth guard. |
Files not reviewed (4)
- crates/tui/extension-host/package-lock.json: Generated file
- crates/tui/plugins/computer-use/package-lock.json: Generated file
- telemetry-ingest/package-lock.json: Generated file
- web/package-lock.json: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| const threads = (await runtimeJson( | ||
| "/v1/threads/summary?limit=8&include_archived=true" | ||
| ); | ||
| )).filter((thread) => ownsThread(chatId, state, thread.id)); |
| const key = keyOf(msg); | ||
| if (!key) continue; | ||
| const claim = await store.claimMessage(key); | ||
| const claim = store.data.inflight?.[key] ? "interrupted" : await store.claimMessage(key); |
…unt profile Since 2b660bc every interactive turn fetched /api/me when a Codewhale account session was cached and refused the turn on any failure. A stale sign-in (HTTP 401) or an unreachable account service therefore blocked every turn, including turns on the person's own provider key (reported in a real session: DeepSeek and Xiaomi MiMo turns both refused with "Your profile could not be loaded (HTTP 401)"). Local use never requires a Codewhale sign-in. When the engine itself loads the account profile and that fails, the turn now uses the signed-out local constitution, logs the reason, and shows one localized notice per engine (15 locale packs) explaining that the provider key still works and how to restore account preferences. There is still no cached or cross-account fallback. A host-supplied snapshot (Runtime API thread request) keeps failing its turn closed, and GET /v1/constitution still reports the error. Evidence: cargo test -p codewhale-localization: 54 passed; 0 failed. cargo test -p codewhale-tui --lib profile_constitution: 7 passed; 0 failed. Real-binary proof against a stale account session follows in the PR. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
`codewhale login` switched the local route to the managed Codewhale provider whenever the configured provider equalled ProviderKind::default(), intended as "never configured". DeepSeek is the default provider, so a person who explicitly chose DeepSeek, or stored a DeepSeek key, was silently moved to `provider = "codewhale"`, `model = "auto"` on sign-in. Found while reproducing a stale-sign-in report: a QA login against a loopback account API rewrote the operator's own config this way (restored by hand). Sign-in now takes over the route only when the config file names no provider and the current provider has no local key (config, secret store or environment, via the existing resolve_local_key). An explicit provider, including deepseek, is kept. Evidence: cargo test -p codewhale-cli --lib cloud::tests::login_: with fix 4 passed; 0 failed. Against the previous cloud.rs the two new regressions fail (2 passed; 2 failed), so they pin the defect. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Real-terminal QA of 00b84da (installed build 8fb9e13 against a loopback account API returning 401) showed turns now complete on DeepSeek, but the once-per-engine notice only set the footer status line and the next turn's status erased it before anyone could read it. The TUI now retains that localized notice as a transcript line, the same way it already keeps retry receipts. Also records both account fixes in the 0.10.1 changelog. Evidence: cargo test -p codewhale-tui --lib account_profile_fallback_notice engine_retry_status_receipts_survive: 2 passed; 0 failed. Before/after PTY receipts: artifacts/takeover-0101-20261005/F3-before-G6-stale-account-pane.txt (G6: "Your profile could not be loaded (HTTP 401)", turn refused) and F3-after-stale-account-pane.txt (two DeepSeek turns answered). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…fixes in 0.10.1 Internal dogfood QA (codewhale-ops/releases/0.10.1/DOGFOOD-FINDINGS-20261007.md, item 2) found these post-G6 fixes had no changelog entry. Docs only; sync-changelog --check passes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Adopted from uncommitted edits left in the release checkout (19:39-19:47 PDT, author session unidentified; cw-c1 and transformatics-44 confirmed not theirs). Reviewed, corrected and tested by the release owner. - Weixin: a context token is bound to the bot account that received it. After an account replacement, replies never reuse the old account's token (Devin review, red); `/new` stores the new token while the retired receipt keeps the old one. Legacy unattributed tokens are not reused. - Weixin `/threads` asks the Runtime for this chat's owned thread IDs instead of filtering a global page of 8 (Devin + Copilot). Runtime `GET /v1/threads/summary` gains `thread_ids=<id>,<id>` (at most 200, each at most 128 bytes), applied before `limit`; a selection filter, not an authorization check. Correction during review: the adopted version used repeated `thread_ids=` keys, which axum's Query cannot collect, so the real Runtime answered 400 to every Weixin `/threads` (the bridge test's fake runtime hid it). Now one comma-separated parameter. - The production Weixin poller now uses the tested processUpdateBatch helper instead of an inline copy (Copilot; dogfood item 8). Semantics match the removed loop. - bridge-core approvals test waits for the durable turn clear before fixture cleanup: the Windows ENOTEMPTY teardown race. - Extension-host build redacts three MCP SDK OAuth log/error strings that could carry server response bodies (defense in depth for CodeQL #560, already unreachable). The patch fails the build if upstream text changes. Log wording corrected in review. mcp digest 5b095beb... in tier.rs, builtin-modules.json and the bundle; two builds byte-identical. - Test harness: fake core drops replies after host shutdown (Windows). - docs/CNB_MIRROR.md spacing (Copilot). Evidence: extension host node 403 pass / 0 fail / 7 skip; weixin-bridge 49/0/0; bridge-core 39/0/1 skip; cargo test runtime_api::tests:: list_thread_summary_filters_ids_before_limit + extension_host::tier: 5 passed; 0 failed (the adopted repeated-key version failed with 400: F5-adopted-review-fixes-gate-repeated-keys-FAILED.log). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Remove all provider-controlled OAuth error fields from the shipped SDK retry logger and regenerate its pinned bundles. Exercise the actual logger with an error object that fails if read. Bound new Weixin retirement records by count and bytes before thread creation; preserve uncertain work and explain local reconciliation. Compare canonical workspace paths for resume diagnostics and grant the cargo-audit checkout only contents:read. Date the candidate notes 2026-10-07 and retain contributor credits. Validation: npm test && npm run check:web passed (Node 531 pass, 0 fail, 7 skip; web 772/772; 894 pages). Weixin 51/51, including both production retention-limit controls. Shipped OAuth logger 2/2. Governed focused Rust tier checks 4/4, compiling exec_agent.rs and verifying generated digests. check-versions --require-dated-release passed (after candidate-note refresh). No full Rust suite repeated locally; exact-head CI owns exhaustive coverage. Refs #6880. No tag, registry publication or deployment. Foreign constitution not included. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Explain registration and the existing account key store in English and Simplified Chinese README, installation and configuration guides, plus terminal login help. Account keys remain on the service for account-routed requests; uploading local keys is explicit, local use stays optional. Correct obsolete local/account secret-store claims and preserve historical v0.10.0 installation receipts rather than treating them as candidate proof. Validation: cargo fmt -p codewhale-cli --check passed. npm test: 531 passed, 0 failed, 7 skipped. npm run check:web: 772 tests passed, 0 failed; 894 pages built. Local English/Chinese install pages inspected in the in-app browser at desktop and phone widths; no page overflow or console errors. No real account or provider keys uploaded, modified or removed. Full Rust and cross-platform proof remains owned by exact-head CI and final binary QA. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
A restart can leave an account-owned admission without a bound thread. Inbound messages now respect pending admission and delivery owners before replacing the saved reply context, including unattributed receipts. Explicit /new archives the original account context before binding the new one. Validation: Weixin production-process suite 54 passed, 0 failed (3 new regressions cover unbound admission, unbound delivery and missing owner). git diff --check passed. Root npm/web inputs are unchanged from a8e3d03: existing gate remains 531 passed/0 failed/7 skipped, web 772 passed/0 failed and 894 pages; not rerun over concurrent foreign avatar edits. Exact-head hosted CI remains required.
Use tokio::fs::canonicalize for both resume workspace paths. CI correctly rejected the two blocking calls introduced by the alias-warning repair; preserve the comparison and failure fallback without increasing its budget. Translate the account-key quickstart into the remaining 17 README locales before updating their source stamps. Keep the Simplified Chinese guide and add its English cross-reference so all 18 translations retain URL parity. Validation on a frozen export excluding concurrent foreign work: - npm test: Node 531 passed, 0 failed, 7 skipped; web 772 passed, 0 failed. - npm run check:web: passed; 894 pages. Initial snapshot dependency symlinks caused a Turbopack filesystem-root error; copying the existing locked dependencies locally fixed the harness, and the failed check passed. - README parity: 18/18; locale links, TUI/web locale and vocabulary checks pass. - Blocking calls: 534 sites/165 files within unchanged budget; harness 34/0. - rustfmt and diff whitespace pass; 3915 tracked blobs unchanged after gate. - Rust compilation and complete OS qualification remain hosted CI gates. Refs #6880 Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Add ctx.avatars.registerPack to the existing Cordis owner/scope lifecycle. Validate bounded manifest/PNG snapshots against the reviewed bundle inventory; serve metadata and hash-bound pages through authenticated runtime routes with live Native authority, workspace and host-generation checks. Withdraw art on owner/scope disposal, revoke, disable or host loss. Do not execute pack code in clients. Add /pet avatar, action and view selection, existing-clock rendering, the shared Ratatui whale-girl package and a Native authoring example. Validation: host typecheck/build passed; 144 avatar/host/protocol tests passed. Rust avatar tests 4 passed; Rust protocol generation/authority tests 4 passed. Final saturating frame-count bound passed 3 contract tests in both the app and standalone Ratatui; vendored library cargo check passed (vendored dev-tests are not supported from this workspace). Ratatui renderer tests 3 passed, examples checked and 228 terminal buffers exported. GPUI built and its isolated offline habitat was visually checked; no live plugin install, provider, deployment, release or performance claim. Web ships built-in art only. APPS-226.
Move the image-key implementation above tests and use fixed-size pixel chunks in the authored-art test. Keep contract/player byte-identical across the app, standalone Ratatui and Engine vendor. No runtime behavior changes. Validation: shared whale crate 44 passed, 0 failed; Ratatui all-targets Clippy and formatting passed. Prior app gate: npm test 1592 passed / 6 ignored and check:web passed (86 Python passed / 2 disk-image fixture skips). Native actual build and visual checks remain valid; this changes ordering and test syntax. APPS-226.
Repair both exact formatting failures from Engine CI 37576212363 at 1156ef8: the avatar atlas route and vendored Ratatui module ordering. Preserve all behavior and the avatar owner's commits and authorship. Validation: frozen 3952-blob candidate; cargo fmt passed; dead-code budget 253/258 and unchanged blocking-call budget 534 sites/165 files passed. npm test: Node 540 passed, 0 failed, 7 skipped; web 772 passed, 0 failed. npm run check:web passed, 894 pages. Source blobs unchanged after gates. Evidence: artifacts/takeover-0101-20261005/F9-local-gate-proof.json. SHA-6705; APPS-226. Local only: Hunter's current GitHub CI/CD hold prevents pushes, merges and dispatches. Remote candidate still needs hosted gates.
Keep native PNG atlas embedding in GPUI and package only terminal assets in the shared Rust crate. Repair six avatar Clippy findings without changing decoding validation or cache behavior. Pull canonical Computer Use test 6a8237a: count actual polls beyond cache capacity instead of assuming CI speed, and replace the stale embedded-source README hash with the pin. The Windows desktop fixture now replaces its receipt atomically; the prior Move-Item writer briefly removed it and caused ENOENT in hosted acceptance. Validation: focused TUI Clippy with existing CI style policy passed; embedded CU 416 passed/0 failed/17 skipped; upstream 438/0/18 skipped. A 250ms backend passes and intentionally caching polls fails with unknown_state. Actual Ratatui archive 1,179,171 bytes, 125 packaged tests pass; GPUI adapter 1593/0/6 ignored and web 84/0/4 skipped. F9 root npm test540 Node +772web passed/7 skipped and check:web894pages reused: their inputs are unchanged. Frozen source verified; foreign avatar/parity work excluded. Hosted exact-head CI (including the new Windows receipt writer) and final-main artifacts remain release gates. No publication/deployment. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…test Sync canonical Computer Use 724f9c4, merged through upstream PR13 after all 11 checks passed. Invisible UIA controls retain semantic identity and have null geometry; invalid bounds never become coordinates. Correct the atomic Windows fixture writer and exercise real PowerShell edge cases. Migrate the remaining Engine test consumer of removed native atlas bytes: generate valid PNG pages from the pack geometry instead of depending on repository-only artwork. Registry ownership/revocation assertions remain. Validation: canonical Node 438 passed/0 failed/19 local skips; embedded 416/0/18 skips. Hosted Windows desktop and all geometry cases executed and passed, alongside macOS/Linux/package/CodeQL. The exact Rust fixture snippet compiled and all 9 pages validated and decoded. Formatting passed. F10 production Rust Clippy and unchanged root Node/web gates remain applicable; full Engine test compilation and all exact-head hosted gates remain required. All 3952 source blobs matched the frozen export; concurrent art work retained. No publication or deployment. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Run the canonical CI executable and Windows x64 release artifact through a pinned official portable Windows Terminal. Paste 24 Unicode lines via the Windows clipboard, assert no request before Enter, and verify one complete prompt plus rendered reply through a loopback provider. Retain screenshots, input receipts, exact binary identity and failure diagnostics in Actions. The fixture has an isolated home, no inherited secrets and no provider cost. Frozen-source gate: npm test 540 Node and 772 web passed, 0 failed, 7 skipped; npm run check:web passed (894 pages). Node syntax and actionlint with existing CI allowances passed. All 3,954 tracked blobs unchanged after the gate. Actual Windows desktop execution is a required hosted check, not claimed by these local checks. Refs #6877.
Reconcile the author guide with the existing native composition importer: a closed source graph produces reviewed Native entries, including selected agent presets. Separate that path from portable declaration conversion and retain the default-off flag, review, trust, enablement and Rust approval boundaries. Do not imply support for DSH UI or its agent loop. Validation: npm test passed (540 Node + 772 web tests, 0 failed, 7 skipped); npm run check:web passed (894 pages). Gitless F13 qualification source verified all 3954 tracked blobs before/after. Runtime DSH acceptance is being qualified separately; these are documentation gates. No deployment/publication.
…ee CI assertions The fresh F12 release binary (642d7f3) panicked when a user typed `/plugin import dsh <package>` in the TUI: the slash-command adapter called the Native composition reviewer directly on a Tokio worker, and the reviewer owns a bounded async process runner ("Cannot start a runtime from within a runtime", composition_review.rs:64). The Runtime API preview and the async installer already ran this on blocking workers. - contract.rs: move the whole filesystem/reviewer preview into the existing run_async + spawn_blocking bridge when a runtime is live; standalone synchronous callers keep direct execution. Review and approval are unchanged. New regression drives the adapter from a multi-thread runtime against the real raw-agent-presets package and asserts identity, hash and no install. - nextest.toml: serialise that regression in the existing extension-host group. - cli lib.rs: login help names the Codewhale account and its immediate benefit (managing provider API keys); the test now asserts that and the explicit no-automatic-upload boundary instead of forbidding the words "API key". - THIRD_PARTY_NOTICES.md: MCP client/core headings 2.0.0 -> 2.2.0 to match the committed bundle. License bodies are byte-identical to dist/LICENSES.txt. - extensions.rs: drop the hardcoded count of five installable catalog rows (there are eighteen) and assert the actual whalewiki install action. The last three repair the same three failures on hosted F11 run 37583076959: Linux 18,987 passed / 3 failed / 34 skipped; Windows 18,284 passed / 3 failed / 27 skipped. Evidence (qualified export of 3,954 tracked blobs, verified before and after): - cargo nextest, four exact cases: "4 tests run: 4 passed, 15822 skipped" (login_help_describes_account_signin, plugin_adapter_dsh_preview_runs_from_live_runtime, every_package_in_the_bundle_has_a_licence_notice_and_a_third_party_entry, marketplace_shipped_bundle_uses_local_metadata_and_review_action). - Debug binary from the same export, sha256 5f12397f...264d4eb3, driven in a real tmux terminal with an isolated home: the command that crashed now prints the review for @demo/raw-agent-presets@1.0.0 with content hash 80a26cc3..., "Nothing was installed", no new crash log, plugins directory unchanged. - npm test: 540 Node + 772 web passed, 0 failed, 7 skipped. npm run check:web: passed, 894 pages. Blocking-call budget 534 sites / 165 files, within budget. - Not run locally: the full Rust workspace suite (hosted CI owns it) and a without-fix run of the new regression; the retained crash receipt 20261007T073514.563Z-process-panic.log is the before-state. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… host plugins survive restart
Found by driving the release candidate as a user and by the new hosted
Windows Terminal clipboard gate on its first real run.
Windows paste (pre-existing, not a 0.10.1 regression)
- Hosted run 37593035432, job 112699600947: 24 pasted lines arrived as one
prompt with CJK intact, zero requests before Enter, but U+1F433 was missing
from every line ("all24 Unicode lines arrive contiguously and unchanged").
Windows Terminal injects a key-down and a key-up record per UTF-16 half;
crossterm 0.29.0 pairs a half with its own key-up and drops the character.
- patches/crossterm-0.29.0: only key-down halves take part in surrogate
pairing (the change proposed upstream as crossterm-rs/crossterm#1073, still
open). A path crate is built under our -D warnings, so the copy also drops
one redundant pair of parentheses (unix.rs) and allows upstream warnings.
Wired through [patch.crates-io] like unicode-width; Cargo.lock entry loses
its registry source. Listed in docs/THIRD_PARTY_NOTICES.md.
- Not provable on macOS: the proof is the same hosted gate passing.
Experimental extension host (off by default)
- Startup discovery runs before config installs the extension-host policy, so
after every restart each trusted Native plugin showed "capabilities-changed"
and stayed inactive until /plugin reload. policy_current_registry re-judges
once after the config load for interactive launch, resume, fork and exec.
Known limits, stated in the code: plugin-declared providers and the mcp,
doctor, setup, pr, review and workflow-tool subcommands keep the startup
snapshot.
- Enabling a Native plugin after a preset catalog was active never activated
it: the in-place enable kept the pinned Native selection. enable() now
rediscovers, as install and reload already do.
- /plugin import dsh review lists the Native host code a bundle contains and
says when the extension host is off.
Text
- account pull --dry-run no longer claims session tokens live in the OS
keyring; they are in the private Codewhale secrets file.
- CHANGELOG: computer-use canonical revision is 724f9c42 (matches
computer-use.upstream-sha); entries for the paste fix, avatar packs and DSH
import. RUNTIME_API (EN/zh): an unavailable Engine-loaded account profile
falls back to the local constitution with a notice once per session.
EXTENSIONS (EN/zh): avatars service. zh PLUGIN_AUTHORING: reviewed Native
composition and skill-root wording ported from English.
Evidence (qualified export, 4,018 tracked blobs verified before and after)
- cargo nextest, plugin/DSH/login/account filters: "106 tests run: 106 passed,
15794 skipped". cargo fmt --all --check clean. Blocking-call budget 534 sites
across 165 files, within budget.
- Patched crossterm checked standalone with RUSTFLAGS=-Dwarnings for
aarch64-apple-darwin, x86_64-pc-windows-msvc, x86_64-pc-windows-gnu,
x86_64-unknown-linux-gnu, aarch64-unknown-linux-ohos, aarch64-linux-android.
- npm test: 540 Node passed, 0 failed, 7 skipped; 772 web passed.
npm run check:web: passed, 894 pages.
- Real terminal, isolated home, debug binary sha256 99642651...9a382444: restart keeps both
trusted plugins active with no reload; a second plugin activates on enable;
the import review prints the Native host code line.
- Independent pre-push review (three reviewers) found the -D warnings failure
and the doc gaps fixed here.
- Known and not fixed: the first extension slash command typed after a
restart reports "Unknown command"; the second attempt works.
- Not run locally: clippy and the full workspace suite (hosted CI owns them).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>


What and why
Complete the 0.10.1 follow-up after #6846. Optional account failures no longer block a locally configured provider, login preserves that provider, and account setup explains the immediate benefit: centrally managed API keys. Bridge work retains account ownership, reviewed dependency/OAuth-log findings are addressed, and the terminal gains the shared avatar projection.
All eleven contributor PRs integrated through #6846 retain original history/authorship. Supersedes dependabot #6879. Source changes only; no tag, registry publication or deployment.
Issue
No-Issue: release integration and qualification; ownership and receipts are tracked in Linear SHA-6705.
Validation
Candidate
de77d9fef186cb23b7ef3c2bce57e4cd119c31d1, tree407e25ea21eee9c9514aea59539012c3a7cd3667; all3952export/index/commit blobs verified. Concurrent avatar redesign and constitution edits are excluded.All applicable exact-head Linux/Windows/macOS/safety/lint/website/security/Pet and other workflows must pass before merge. Then verify the merged tree and run exact-main nonpublishing RC/parity/artifact and shared-process-twice workflows, followed by a stamped local install and terminal acceptance. Source, hosted jobs, packages, provider calls and deployment evidence remain distinct.