Skip to content

fix(desktop): select and retain qualified runtime updates - #5582

Open
loopx-agent wants to merge 40 commits into
mainfrom
codex/app-runtime-startup-recovery-20261004
Open

loopx-agent wants to merge 40 commits into
mainfrom
codex/app-runtime-startup-recovery-20261004

Conversation

@loopx-agent

@loopx-agent loopx-agent commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

Goal And Delivered Outcome

Desktop could stop at a manual App/CLI version choice, or install a new private runtime and then select an older remembered release on restart. Startup now discovers qualified runtimes automatically and retains the installer's completed promotion before reconnecting.

Package versions and bounded official-source ancestry establish freshness. A provably newer CLI remains selected. When same-base sources cannot be ordered, the current App can maintain its own private snapshot from its bundle; an independently installed CLI keeps its installation owner. This ownership rule does not claim an unknown revision is newer. Explicit LOOPX_BIN pins remain developer-owned. Both HTTP services must expose the chosen artifact's identity before the workspace opens.

The existing signed updater checks the App's channel once on normal macOS launch. Bundled preparation uses App-owned storage, preserving the default CLI and shell-profile owner. Broken preferences fall back to discovery; terminal failures stop waiting and expose recovery immediately. This changes default startup from manual pairing to automatic selection; docs and regression expectations change together.

  • Basis: maintainer-requested automatic App/CLI selection and demonstrated stale-promotion recovery defect; intended PR base main.
  • Direction: S4/S5/S12 in the overall roadmap, within the Desktop bootstrap boundary.

Author Declaration

Criterion Disposition Owner / evidence
Automatic freshness and installation ownership implemented Native runtime_selection.rs; version/ancestry and canonical-path negative tests
Retain qualified Repair promotion across reconnect/restart implemented Existing installer plus maintenance.rs; real packaged Repair and ordinary restart
Both HTTP services use one chosen artifact implemented Existing Core identity and native SelectedRuntime; real service readbacks
Terminal recovery and explicit developer pins implemented Production boot surface, packaged recovery smoke and real invalid-pin case
Full bootstrap, signed-upgrade and sustained-operation qualification not_met Remaining native matrix and release/soak evidence below; parent acceptance remains open

Scope And Continuation

Native effects remain in the desktop adapter; Core owns installation qualification, and the existing installer/updater owns promotion. The related simplification removes manual pairing and duplicate runtime-step logic, shares normalized version comparison, and carries the installer result directly into selection. No parallel Python decision owner, new capability, or Goal/session authority is introduced.

The delivered increment is automatic selection plus persistent same-window Repair/restart. The owning Desktop bootstrap checkpoint remains open for the remaining native cases and signed-release qualification. Full Agent execution, golden-query collaboration, and sustained operation are outside this increment. Runtime/product changes require maintainer review and merge; this PR is not self-merged.

Validation

  • Tested source: 41438609ee33f53beb25033ae99cd5605b425e55; merge base 96164637. Latest inspected main fae7fd5e adds quota/vision settlement changes and benchmark docs without changing Desktop paths. The reported CI run tests merge 12c5a7bd (base 796cb296 plus this PR head), separately from local source tests. No Core or Python test changes are present in this PR.
  • Run state: running — full Python accounting is pending and already has failures.
  • Inputs: synthetic, public fixtures, authorized private read-only backend state. Public screenshots use synthetic native IPC/status; private native screenshots are excluded.
Check Result Evidence / limitation
Rust library and clippy passed 79 passed, 2 optional integrations ignored; all-target clippy with warnings denied
Real private installer and default CLI preservation passed Optional real integration plus a separate before/after oracle: all 1,657 distribution-listed static files, CLI wrapper, package version and the existing installation-only doctor remain unchanged. The installed legacy CLI lacks the newer canonical service-identity field; broader functional CLI regression coverage is still unqualified.
Packaged browser recovery and diagnostics passed Production assets with native IPC double; terminal recovery, mobile, reduced motion, reload and redaction
Installed macOS App + real backend passed Local native candidate from this source paired with Core 05ba74e4 from #5587: Repair promotes a different release ID, saves the new selection, reconnects in the same window, and ordinary reopen retains it. Both real HTTP identities agree. Invalid process-only developer pin stops waiting and disables bundled Repair; normal reopen recovers. This is a local ad-hoc signed candidate, not a formal release.
Semantic inventory, Ruff, mypy, public scan and diff hygiene passed Advisory preceded inventory check; Rust is unsupported by the probe and reviewed manually. Public scan covered 1,330 files.
Preliminary source premerge selection passed 3 direct checks and 19 selected smokes; this is not the managed Goal gate
CLI output budget failed Enforced same-fixture base/head comparison: clean base 96164637 and this head both fail loopx_turn_plan at 5957 / 35 / 3800; the budget was not raised
Full Python suite running, failures observed 16,474 collected. Nineteen observed failures also fail on clean base 96164637; additional failures and final totals remain under review. This comparison does not certify newer main.
Managed change-quality / Goal-aware premerge blocked Exact-scope result records the required validation failures; strict receipt verification and premerge reject it. Merge readiness is not claimed.
CI on merge 12c5a7bd failed, Python shards still running macOS/Windows Desktop artifacts, DCO, update validation and static checks passed. Browser/frontstage/dashboard checks time out at the same Personal Workspace assignment assertion; TypeScript shard 1 reports two acceptance bindings becoming stale after successful completion; the mutation harness reports locator drift. Aggregate checks fail.
TypeScript CI failure attribution reproduced The same two File-provider cases fail stale != ready on clean base 96164637, latest inspected main fae7fd5e, and this head with identical dependencies. This establishes attribution for those two cases only; remaining CI/full-suite failures retain their own evidence gaps.

Additional same-base unordered and failed-upgrade GUI qualification was prepared in an isolated App/registry environment but not activated: the native UI tool returned cgWindowNotFound after rebinding/reset. Version/ownership/fallback semantics remain unit-qualified; a process or HTTP response alone is not a GUI pass. No newer signed feed candidate was available for actual App replacement. Windows/Linux, pipx reuse, multiple primary Apps, notarization, broader functional default-CLI oracle and sustained operation remain unqualified. Invalid-pin error copy remains generic; Forget clears a saved preference and cannot clear an environment pin, as documented.

Frontend / Visual Evidence

The first-screen presentation was previewed and approved by the maintainer before its original commit. This update adds no new first-screen layout/copy. The ordinary task is to open the workspace: remove the compulsory version decision, retain progress, and expand recovery only when intervention is needed. The whole viewport keeps one focus and immediate failure controls.

Before, base 96164637, synthetic mismatched revisions:

Before: required manual App and CLI pairing

After, this source, automatic preparation at desktop and 390px widths:

After: automatic preparation with recovery available After: automatic preparation at 390px

Relevant failure: waiting stops and recovery opens immediately. This screenshot is a synthetic installer-error state, not a live installation receipt:

Installer failure with immediate recovery

Boundary Checklist

  • Diff, description and images exclude private state, credentials, raw traces, internal links and local machine paths.
  • Native startup/update, CLI installation ownership and frontend recovery are disclosed; no Lark entrypoint changes.
  • Shared-authority/TypeScript provider conformance is N/A: no authority-store or provider routing refactor.
  • Every PR commit includes DCO sign-off. The previous proposal is retained by a normal fast-forward push after merging its history; no force push.
  • Required validation and remaining native qualification are complete. Merge remains held.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
huangruiteng and others added 11 commits October 4, 2026 21:57
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Ordinary workspace conversations move out of Settings into the steward
conversation as a Scope picker. A workspace scope reuses the main
composer, history, streaming, stop and image path through a typed
conversation context, so a late reply for one context can no longer
retarget another context's Session. The steward overview, Goal list and
first screen are unchanged; a revoked grant keeps history and blocks
sending.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…rver

Runs the packaged bundle against the production Chat server with a
synthetic workspace and the fake Codex app-server: scope selection,
project Session admission without a Goal, reload continuity, return to
the steward scope, and a revoked grant blocking new messages.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
#5569)

* feat(goals): opt in to canonical creation with frozen execution policy

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

* docs(goals): explain canonical creation and original-operation recovery

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

* test(coordination): register creation fence digest consumer

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

* fix(goals): replay canonical bootstrap before compatibility reads

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

---------

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Workspace isolation assumed every accountable outcome carried a Todo-bound settlement and dereferenced a missing identity for valid goal-level refreshes. Resolve Todo repository constraints only when an exact Todo settlement exists, while retaining the typed workspace qualification for other accountable writes.

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
huangruiteng and others added 16 commits October 5, 2026 00:48
…overy (#5541)

* feat(chat): add authorized ordinary workspace conversations

Signed-off-by: huangruiteng <huangrt01@163.com>

* docs(chat): qualify the local workspace conversation journey

Signed-off-by: huangruiteng <huangrt01@163.com>

* refactor(chat): keep project context in native Chat capability package

Signed-off-by: huangruiteng <huangrt01@163.com>

* feat(chat): bind owner private messages to native project sessions

Signed-off-by: huangruiteng <huangrt01@163.com>

* docs(chat): record native private admission checkpoint and limits

Signed-off-by: huangruiteng <huangrt01@163.com>

* fix(lark): isolate expired private App identities

Signed-off-by: huangruiteng <huangrt01@163.com>

---------

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Co-authored-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Co-authored-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
…5544)

* chore(chat): integrate steward recovery into private status

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

* fix(chat): observe failed private sessions in status and help

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

---------

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Co-authored-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
…hat (#5546)

* chore(chat): integrate recovery and workspace scope into Agent selection

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

* fix(chat): replay committed host claims after audience revocation

An already committed exact-host claim could not be re-read with its stable
claim id once the Agent target grant was revoked: the fresh admission
validator was re-run on the replay path, so the owning host lost its Turn and
receipt. Fresh queued eligibility keeps the full validator; the committed
replay is governed by the matching host claim id and Goal lifetime fence.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

* fix(chat): keep the frozen Agent target in scoped status

The scoped status observation added for failed/closed originals replaced the
frozen Agent target Session with the newest candidate, so `/status` for a
selected registered Agent was rejected as unavailable once another Session in
the same channel was newer. Observe the exact bound Session without lifecycle
filtering instead, keep the newest-candidate behaviour only when no Agent
target is frozen, and document the boundary.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

---------

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Co-authored-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
The private Agent selection replay staged the generated uv.lock that the
repository deliberately does not track, so the squash introduced a local lock
file unrelated to the change. Remove it without touching the source or tests.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: liuhuadong.hans <liuhuadong.hans@bytedance.com>
Signed-off-by: liuhuadong.hans <liuhuadong.hans@bytedance.com>
Signed-off-by: liuhuadong.hans <liuhuadong.hans@bytedance.com>
Signed-off-by: liuhuadong.hans <liuhuadong.hans@bytedance.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
* fix(runtime): report safe startup locator publication failures

Signed-off-by: huangruiteng <huangrt01@163.com>

* docs: qualify managed runtime startup diagnostics

Signed-off-by: huangruiteng <huangrt01@163.com>

* test(runtime): preserve Windows locator permission diagnostics

Signed-off-by: huangruiteng <huangrt01@163.com>

* docs(rfc): move the S2/S12 startup checkpoint into the ledger

The accepted template keeps dated execution records in
`ledger/<rfc-slug>/YYYY-MM-DD-slug.md` and leaves only a pointer in the RFC
body, so the roadmap paragraph is replaced by a one-line pointer beside a new
per-RFC ledger entry with its Chinese mirror. The roadmap gains the execution
ledger appendix the governance smoke requires for a ledger directory, and the
generated status index records the new entry count.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

---------

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Co-authored-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Persist registered Goal Agent review directions through the existing typed capability and packaged configuration editor.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
* fix(cli): project structured Todo claim argument recovery

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

* docs: qualify the claim grammar recovery boundary

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

* docs: distinguish parsed claim recovery from parser diagnostics

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

---------

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
…ence (#5616)

* docs(community): record AAOP retirement and historical pilot scope

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

* docs(community): qualify Console release and historical CLI boundary

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

---------

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
* fix(chat): expose rejected Todo previews in context

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

* fix(workspace): show only recorded Todo claims

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

* fix(chat): reconcile confirmed Todo updates and report read failures

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

* fix(workspace): keep Todo notes separate from evidence

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

---------

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
* fix(quota): reenter runnable replan after retaining selection

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

* docs(protocol): describe inline selection reentry boundary

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

---------

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
* fix(goals): align checkpoint repair guidance with vision validation

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

* docs(rfc): record truthful checkpoint repair authoring boundary

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

---------

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
@loopx-agent loopx-agent changed the title fix(desktop): automatically use newer qualified runtimes fix(desktop): select and retain qualified runtime updates Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants