fix(desktop): isolate packaged App service ownership - #5660
loopx-agent wants to merge 5 commits into
Conversation
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Packaged App windows shared the CLI status/Chat ports, allowing an independent window to borrow another window’s registry or restart its services. Give each native window its own endpoint pair and child processes, reuse the qualified runtime for both children and repair, and bind navigation/maintenance to that window’s exact origin. CLI/Vite ports remain unchanged.
Validation on
f4d2e76f: merged current main4c63b642(including #5582 runtime selection, #5587 Task/L1 readers and host-permission recovery); 87 Rust tests passed, 3 optional tests ignored; 91 affected Python tests and the semantic vocabulary smoke passed. Production-asset evidence/return smoke passed with synthetic API fixtures. The current App/CLI were packaged and locally installed: native bundle, Chat, Status and CLI identities agree, automatic selection bypasses the older retained cache, and normal quit/reopen reaches the actual workspace using new private ports. The original Task requirements and keyboard return focus were checked in the installed App.A separate native window served a disposable real SQLite authority: its 988-character Task requirements matched CLI/HTTP; removing its source caused actual HTTP 503 and a summary-only retry state; restoring the source and clicking Retry recovered the full body without modifying canonical rows/revision. Each window’s quit preserved the other window. Earlier native qualification also verified Repair and persisted incomplete-install Restore/Restart; that seeded-journal exercise does not qualify an actual installer mid-swap crash or backup creation transaction.
Ownership: this helper is native platform transport; existing Core identity/install and typed presentation owners remain authoritative. No new first-screen composition/copy is authored here. Native Windows/Linux, sustained focus/background behavior, full current quality qualification, actual updater transaction failures, and independent exact-head review remain open. Task read/recovery is a bounded prerequisite; real L1 independent acceptance/requester adoption and live golden-query qualification remain unproven. Local installation is a candidate, not a public release; leave merge to the maintainer.