Skip to content

Port foundation: fork/v2 branch on upstream main with replays, drops and data isolation #167

Description

@lukemaj

What: fork/v2 exists on current upstream/main with the fork features that rebase unchanged, the approved drops, and the data-isolation contracts every later port uses.
Why: Upstream #2829 replaced the orchestration engine, so the fork stack cannot be rebased as a whole (#166, D1-D3').
So what: An agent builds this first; every other port Issue branches its PRs into fork/v2.

Part of #166 (port 1 of 11). Plan and decision table: #166.

Contribution to the Objective

Every Objective item is ported on this base.

Acceptance criteria

Non-goals

Blockers

None.

Proof

Fork-check output, targeted tests for the tooling fix, the settings-key test and the migration-hook snapshot test, recorded on the PR.

Elon record

  • Requirements and who asked: User chose a per-feature port onto upstream's new orchestrator and approved the adopt/drop list (Absorb upstream main (533 commits behind) #166, D1-D7).
  • Deleted: Five fork features upstream now covers; a mechanical 71-commit rebase.
  • Bottleneck: A base every later port can build on, with data isolation decided before any feature ports.
  • Checked myself: #2829 deletes the old engine; ~/.t3/userdata has no statev2.sqlite; the report crash reproduces at 64 MB.

Activity

  1. lukemaj commented on Oct 8, 2026

    @lukemaj
    ContributorAuthor

    What: The new integration branch fork/v2 is published at exactly 12069eefd707f78eafc27812027c994eea0613cf; the foundation topic is port/167-foundation.
    Why: The authorized foundation needs a fixed upstream base and selective topic replays rather than a v1-stack rebase.
    So what: Mechanical replays continue in the exclusive full clone; consequential changes wait for the parent to relay a reviewed user decision. No merge, installation, deployment, version bump or main update is authorized.

    Git evidence

    • Exclusive clone: chromeria-worktrees/166-absorb, initially clean, branch fork/absorb-12069eefd7 at c1526a7a7229a97cbae17af4109ce3b3bca1d7f2.
    • git ls-remote origin refs/heads/fork/v2 refs/heads/main after push: fork/v2 = 12069eefd707f78eafc27812027c994eea0613cf; main = c1526a7a7229a97cbae17af4109ce3b3bca1d7f2.
    • First mechanical replay: confirmed direction and glossary, exact contents from origin/main, commit ad92b5e21bed2780ae5e190baaa051b00d4bee2c.

    Upstream prior work inspected

    • Merged #16353, full diff 017c9a0eb53b2c100b5be2d366d2374038da9241: canonical identity remains upstream; identity.origin is the fork. This solves grouping, not origin-first PR lookup. Pinned ThreadPullRequestService.ts compares PR repository keys with canonicalKey and selects discovery repository through sourceControlRepositorySelector.
    • Open #7499: identity-parser annotation tolerance only, no GitVcsDriver/GitVcsDriverCore coverage. #12764, including all comments: all three parser paths need annotation tolerance. The fork replay already covers all three.
    • #15023, including all comments: gh-default identity mismatch; linked #14291 is a different candidate from the adopted grouping change.
    • #15832, including all comments: inbox ownership/default filtering is distinct from repository identity correctness and stays out of this foundation.
    • Upstream has no Issues UI. A real-clone identity prerequisite for Port the GitHub Issues features #171 is not runtime Issues lookup proof. Actual PR lookup proof will be recorded separately.

    Decision packet 1 pending reviewed reply

    A: preserve adopted upstream canonical/origin behavior and report any fork PR lookup acceptance failure, deferring a delta to #171; alternative authorize a minimal origin-aware PR change here.
    B: retain the seven carried feature entries plus data foundation, allowlist only upstream paths this topic changes, exactly one primary owner. Keep fork-check semantics unchanged and use an explicit exact-base argument locally and in fork CI. Alternative retain moving-upstream CI comparison.
    C: #152 runtime retest is not authorized. Record not performed and pending, or authorize separate desktop background-capture retest. No browser/computer use has occurred.

    Elon record

    Requirements and who asked: User requested #167 as exactly one PR into a new fork/v2 at exact upstream SHA, with the seven replays and isolated data foundation, preserving the approved D1-D7 scope.
    Deleted: No features owned by #168-177, no approved dropped fork implementations, no version or delivery automation work, no full-stack rebase.
    Bottleneck: Reviewed decisions for nonmechanical replay adaptations, data seams and inventory policy; initial branch publication and exact prose replay are independent.
    Checked myself: Full #167/#166 records and D1-D7 comments, assessments, fork docs and glossary read; live remote branch state verified; #16353 whole diff and pinned PR consumers inspected.

  2. lukemaj commented on Oct 8, 2026

    @lukemaj
    ContributorAuthor

    What: The approved shell-only fork migration interface is implemented and published as an early foundation checkpoint.
    Why: #168, #170, #171 and #174 need a fixed backfill contract before completing their ports.
    So what: Feature owners can register their backfills against this checkpoint; the foundation continues toward one independently reviewed PR into fork/v2. This is not final readiness or cutover approval.

    Fixed interface (F, user reviewed, Sol AGREE)

    apps/server/src/persistence/forkV1Backfills.ts exports:

    interface ForkV1Backfill {
      readonly id: string;
      readonly run: Effect.Effect<void, SqlError | EventSink.EventSinkV2Error | ForkV1BackfillStepError, SqlClient.SqlClient | EventSink.EventSinkV2>;
    }
    const forkV1Backfills: ReadonlyArray<ForkV1Backfill> = [];
    runForkV1Backfills(backfills = forkV1Backfills):
      Effect.Effect<void, ForkV1BackfillError, SqlClient.SqlClient | EventSink.EventSinkV2>;

    Reviewed typed-error correction: ForkV1BackfillStepError is tagged and carries backfillId; SQL and EventSink errors are the smallest concrete dependency union. No lint or diagnostic exemption was added. Runner converts failures into ForkV1BackfillError and preserves interruption.

    Registration: keep the implementation in the owning feature's file, import its effect into forkV1Backfills.ts, then add { id: "feature-backfill", run: featureBackfill } to the list. Steps run sequentially on every startup, immediately after LegacyV1ThreadImporter.reconcileShells, before recovery and workers. Backfills may rely ONLY on imported v2 shells and frozen v1 data, NEVER hydrated transcripts. Features own idempotency through fork tables or stable supported v2 event IDs outside the upstream ledger. No deferred feature backfill is in this foundation. Failure names the step and blocks startup; raw causes are not retained or logged. Interruption remains interruption.

    Mechanical dependency wiring: startup provides the EXISTING exported RuntimeLayer.layerEventSink, shared through Effect layer memoization with the importer and runtime. No second sink implementation. The focused auto-pull startup fixture now supplies a real memory SQLite layer for that dependency.

    Snapshot harness usage

    apps/server/src/persistence/forkV1Snapshot.testFixtures.ts exports:

    vacuumForkV1Snapshot({ sourcePath, destinationPath }): Promise<void>;
    forkV1SnapshotLayer(snapshotPath); // SqlClient, EventStore, ProjectionStore, EventSink, importer
    1. Create a private temporary destination; call vacuumForkV1Snapshot. It opens the source with { readOnly: true }, binds VACUUM INTO ?, and refuses an existing destination.
    2. Provide forkV1SnapshotLayer(snapshotPath) plus NodeServices.layer to the test effect.
    3. Call importer.reconcileShells, then runForkV1Backfills([{id, run}]). Assert imported shell coverage and absence of hydrated transcripts INSIDE the backfill.
    4. Simulate a failure after one completed step; retry and assert convergence with no duplicate rows. Repeat the completed sequence and assert no changes.
    5. Hydrate transcripts separately where relevant, assert expected transcript state, and rerun import/backfills to prove idempotency.
      The harness migrates only the private snapshot. No server or provider starts, and live userdata is never opened writable.

    D9 reviewed proof correction

    pendingThreadCount is the UNION of unimported shells and unhydrated transcript imports (LegacyV1ThreadImporter.ts:662-679). The original assertion that it was zero after shells was incorrect. User reviewed D9 approves direct checks: every frozen v1 thread has a v2 thread.created shell event, every import has NULL transcript_imported_at WHEN the hook runs, and imported shell count equals initial pending count. Zero pending count is checked only after transcript hydration. Partial-failure recovery and repeated execution remain tested.

    Checkpoint identity

    • Topic: port/167-foundation. Published head: 2c849253fb203d9dae059626ced255621ecf7851.
    • This WIP commit contains ONLY the hook, harness, focused test, startup seam and required startup-fixture dependency. Earlier direction/glossary commit is its ancestor; staged partial-clone/query files are excluded.

    Checkpoint proof

    Host-neutral environment: Node 24.13.1 first on PATH, Homebrew excluded, ELECTRON_RUN_AS_NODE unset, TMPDIR=/private/tmp/.

    • CHROMERIA_V1_SNAPSHOT_SOURCE=$HOME/.t3/userdata/state.sqlite pnpm exec vp test run apps/server/src/persistence/forkV1Backfills.test.ts apps/server/src/serverRuntimeStartup.autoPull.test.ts apps/server/src/serverRuntimeStartup.test.ts
    • pnpm --filter t3 typecheck (server scope, not repo-wide)
    • pnpm exec vp lint apps/server/src/persistence/forkV1Backfills.ts apps/server/src/persistence/forkV1Backfills.test.ts apps/server/src/persistence/forkV1Snapshot.testFixtures.ts apps/server/src/serverRuntimeStartup.ts apps/server/src/serverRuntimeStartup.autoPull.test.ts
      Lint exits 0; one pre-existing unused layer warning in upstream startup remains, confirmed against pinned base. Final PR still requires exact-head independent review and the other foundation proof. No repo-wide checks, browser verification, merge, install, deployment or version bump.

    Results: all 3 focused test files passed, 10 tests passed (including explicit real-data snapshot test); server typecheck exit 0; targeted lint exit 0. Checkpoint contents match tested files. Feature map/allowlist and remaining replays are not yet complete.

  3. lukemaj commented on Oct 8, 2026

    @lukemaj
    ContributorAuthor

    What: The new integration branch fork/v2 is published at exactly 12069eefd707f78eafc27812027c994eea0613cf; the foundation topic is port/167-foundation.
    Why: The authorized foundation needs a fixed upstream base and selective topic replays rather than a v1-stack rebase.
    So what: Mechanical replays continue in the exclusive full clone; consequential changes wait for the parent to relay a reviewed user decision. No merge, installation, deployment, version bump or main update is authorized.

    Git evidence

    • Exclusive clone: chromeria-worktrees/166-absorb, initially clean, branch fork/absorb-12069eefd7 at c1526a7a7229a97cbae17af4109ce3b3bca1d7f2.
    • git ls-remote origin refs/heads/fork/v2 refs/heads/main after push: fork/v2 = 12069eefd707f78eafc27812027c994eea0613cf; main = c1526a7a7229a97cbae17af4109ce3b3bca1d7f2.
    • First mechanical replay: confirmed direction and glossary, exact contents from origin/main, commit ad92b5e21bed2780ae5e190baaa051b00d4bee2c.

    Upstream prior work inspected

    • Merged #16353, full diff 017c9a0eb53b2c100b5be2d366d2374038da9241: canonical identity remains upstream; identity.origin is the fork. This solves grouping, not origin-first PR lookup. Pinned ThreadPullRequestService.ts compares PR repository keys with canonicalKey and selects discovery repository through sourceControlRepositorySelector.
    • Open #7499: identity-parser annotation tolerance only, no GitVcsDriver/GitVcsDriverCore coverage. #12764, including all comments: all three parser paths need annotation tolerance. The fork replay already covers all three.
    • #15023, including all comments: gh-default identity mismatch; linked #14291 is a different candidate from the adopted grouping change.
    • #15832, including all comments: inbox ownership/default filtering is distinct from repository identity correctness and stays out of this foundation.
    • Upstream has no Issues UI. A real-clone identity prerequisite for Port the GitHub Issues features #171 is not runtime Issues lookup proof. Actual PR lookup proof will be recorded separately.

    Reviewed decisions, authoritative user replies

    A: Prefer identity.origin for PR discovery and matching in #167; preserve canonical upstream identity. Map the minimal delta to one feature owner. Actual PR lookup proof and real-clone identity proof are separate; no runtime Issues UI claim.
    B: Seven replay entries plus data foundation; only carried edits allowlisted, exactly one primary owner. fork-check keeps merge-base with upstream/main to check the entire carried stack. CI explicitly fetches upstream and fails if upstream/main is absent, with no origin/main fallback.
    C: #152 runtime retest remains NOT PERFORMED and REQUIRED before #177 cutover, pending explicit browser authority. No browser is authorized now.
    D: Production Electron profile stays chromeria; development stays t3code-dev. Windows safeStorage adaptation copies Local State only, never locked Chromium databases.
    E: Dedicated chromeria-v2.sqlite with upstream read-only sibling state.sqlite seed. Preserve opaque prismRoles/wightModes, including project overrides; typed default-false autoUpdateProviders. Test unrelated writes preserve both environment settings and project overrides.
    F: Rerunnable sequential hook after successful shell import, before recovery/workers. Backfills rely ONLY on imported v2 shells and frozen v1 data, NEVER hydrated transcripts. No foundation ledger or deferred feature backfills. VACUUM INTO read-only snapshot harness tests partial-failure recovery and repeated execution.
    G: Bounded 1 GiB maxBuffer, NOT streaming. Exceeded-buffer errors name the commit. Complete overlap report through exact 12069ee must succeed.
    D9: Hook-time proof directly asserts every eligible v1 thread has an imported v2 shell and transcript_imported_at remains NULL. Separate transcript import and rerun checks follow.
    Typed hook error correction: no lint exemption; run errors are SqlError | EventSinkV2Error | ForkV1BackfillStepError, with tagged step error carrying backfillId. Runner sanitizes failure and preserves interruption.
    Mechanical startup wiring: share existing RuntimeLayer.layerEventSink, never create a second sink.

    Early approved F checkpoint: 2c84925, pushed to port/167-foundation. Exact interface usage and checkpoint proof.
    Further consequential decisions remain gated. No PR is ready yet; final exact-head independent review remains required.

    Elon record

    Requirements and who asked: User requested #167 as exactly one PR into a new fork/v2 at exact upstream SHA, with the seven replays and isolated data foundation, preserving the approved D1-D7 scope.
    Deleted: No features owned by #168-177, no approved dropped fork implementations, no version or delivery automation work, no full-stack rebase.
    Bottleneck: Approved shell-only interface was the early dependency bottleneck and is published; remaining replay proof and final independent review are outstanding.
    Checked myself: Full #167/#166 records and D1-D7 comments, assessments, fork docs and glossary read; live remote branch state verified; #16353 whole diff and pinned PR consumers inspected.

  4. lukemaj commented on Oct 8, 2026

    @lukemaj
    ContributorAuthor

    What: The hook snapshot ordering correction is pushed at e437185; focused replay proofs are passing.
    Why: Newly registered backfills must first execute in the initial shell-only phase, and platform-sensitive fixtures must prove the approved behavior.
    So what: Remaining implementation continues within reviewed choices; provider-auto-update V2 state/service adaptation awaits reviewed approval before implementation. No PR readiness or final review is claimed.

    Reviewed corrections

    • User authorized the Port thread people and ownership #170 coordination correction: default backfill registry now runs immediately after initial reconcileShells, before the shell/no-hydration observer, transcript import and event-count baseline. The same default registry reruns later. Partial-failure recovery and explicit observer remain.
    • Nonempty registry check: temporarily registered a representative idempotent SQL step that requires no hydrated transcripts on its first execution and verifies exactly one persisted marker on repeated execution. CHROMERIA_V1_SNAPSHOT_SOURCE read-only snapshot suite: 2 tests passed. Temporary registration restored; no feature implementation carried.
    • D19 approved: set mode-only.sh disk chmod 0755 to match committed +x, retain every test assertion. No CI waiver. Test file primary ownership is fork-maintenance, partial-clone replay shares it.
    • Pinned upstream Linux CI: https://github.com/pingdotgg/t3code/actions/runs/37784152139/job/113334477489 ; latest upstream Linux CI: https://github.com/pingdotgg/t3code/actions/runs/37800248310/job/113390200475 . Parent verified 137 GitVcsDriverCore tests pass on Ubuntu. Candidate fixture correction can be offered upstream later, no upstream PR authorized here.
    • Approved Windows profile test replacement: filesystem experiment proves Chromeria/chromeria alias on this Mac. Mock filesystem proves exactly one Local State read/write and no database copy; real filesystem proves existing Local State and IndexedDB/LOCK unchanged on win32/darwin/linux branches. No skip or diagnostic exemption.
    • Mechanical branding conflicts: retain current extracted SidebarBrandMark, newer onboarding imports, find-text wrapper, modern parameterized platform tests and development-profile behavior; apply existing fork names/icons/sizing at their current seams. Bundled-dev fixture now copies branding.ts and branding.logic.ts, required dependencies of the approved boot-error branding import.

    Focused proof

    Neutral environment: unset ELECTRON_RUN_AS_NODE; Node 24.13.1 PATH with pnpm shim; canonical /private/tmp/ TMPDIR, no Homebrew path.

    • vp test run forkV1Backfills.test.ts GitVcsDriverCore.test.ts with explicit live-source RO snapshot: 140 tests passed.
    • vp test run serverSettings.test.ts cli/config.test.ts: 82 tests passed. Tests preserve opaque environment prismRoles/wightModes, typed autoUpdateProviders and project opaque overrides through an unrelated disk settings write. Dedicated chromeria-v2.sqlite path checked; read-only upstream initializer unchanged.
    • vp test run DesktopAppIdentity.test.ts DesktopPreReadyPlatform.test.ts DesktopUserData.test.ts branding.test.ts bootstrap.test.ts bundledDev.test.ts build-desktop-artifact.test.ts brand-assets.test.ts: 113 tests passed.
    • vp test run PullRequestService.test.ts ThreadPullRequestService.test.ts: 199 tests passed, including origin-first discovery/matching and unchanged canonical upstream project identity. This is service routing proof, not yet real-clone actual PR lookup proof.
    • Overlap scan with approved bounded 1 GiB helper and eight provisional carried entries: report de251fc 12069ee completed, all 533 commits. 419 lines/66656 bytes, SHA256 a2095bfa18587392ba10a48531588a49dee5886b0cd252c88673a865612e9f4d. Final carried inventory rerun and overlap decisions remain.

    #152 runtime retest remains NOT PERFORMED and REQUIRED before #177 cutover after explicit browser authority. No browser/computer use, install, deploy, merge or version bump occurred.

    Requirements and who asked: User requested selective #167 foundation and approved A-G/D9/D19 plus explicit snapshot and Windows fixture corrections.
    Deleted: No deferred feature backfills, CI-only waiver, lint exemption, newer upstream foundation or live data writes.
    Bottleneck: V2 provider-auto-update adaptation needs a reviewed exact state/service boundary; final inventory, real PR lookup and independent exact-head review remain.
    Checked myself: Focused test outputs, filesystem alias experiment, nonempty registry snapshot execution, 533-commit overlap report, and live remote branch SHA verification.

  5. lukemaj commented on Oct 8, 2026

    @lukemaj
    ContributorAuthor

    What: D22 and D23 are implemented and pushed as an early foundation checkpoint.
    Why: Node 24 rejects a boolean SQLite parameter, and test fixtures were incorrectly included in the production import scan.
    So what: #170 can rebase onto 1e604adfa5cc4b68c3934ee8b3e46714f83f3f47; the final integration PR still awaits the provider gate and full scoped verification.

    Reviewed D22: bind requestedScopes === undefined ? 1 : 0; the real SQLite regression exercises both omitted and explicit scopes and verifies single consumption. Reviewed D23: exclude only .testFixtures.ts helpers from the production scan and assert no production source imports them. Existing import boundary assertions remain intact; no #170 backfill or reader allowance is included.

    Proof on Node v24.13.1 with ELECTRON_RUN_AS_NODE unset and TMPDIR=/private/tmp/:

    • pnpm exec vp test run apps/server/src/auth/ apps/server/src/orchestration-v2/V1ImportBoundary.test.ts: 13 files, 118 tests passed, exit 0.
    • pnpm exec vp lint apps/server/src/persistence/AuthPairingLinks.ts apps/server/src/auth/PairingGrantStore.test.ts apps/server/src/orchestration-v2/V1ImportBoundary.test.ts: exit 0.
    • git diff --check for these paths: exit 0. Formatting ran on these three files only.
    • Remote topic verified at 1e604adfa5cc4b68c3934ee8b3e46714f83f3f47; remote fork/v2 remains 12069eefd707f78eafc27812027c994eea0613cf, and main remains c1526a7a7229a97cbae17af4109ce3b3bca1d7f2.

    The numeric bind is an upstream bug candidate. Baseline reproduction supplied in /tmp/170-scratch/proof-auth-baseline-node24.txt reports ERR_INVALID_ARG_TYPE, SQLite parameter 5. Final typecheck and exact-head independent review remain required, not waived. D25 is unfinished; no provider failures have been accepted.

    Requirements and who asked: User approved D22/D23 and requested this early checkpoint to unblock #170.
    Deleted: No failure waiver and no deferred feature backfill.
    Bottleneck: #170 auth proof required the Node-compatible pairing bind.
    Checked myself: Read the SQL and production scanner, ran the full auth suite plus boundary test, inspected the three-file commit, and verified the remote refs.

  6. lukemaj commented on Oct 8, 2026

    @lukemaj
    ContributorAuthor

    What: PR #178 is pushed and open for the bounded V2 foundation.
    Why: The approved shell-only foundation and carried stack unblock the deferred consumer PRs.
    So what: Exact-head independent review is running; the user merges when required proof/review succeeds. #167 remains open.

    PR #178, head 4e27cd10dedf40ff124a0124b6307fedb61ccb1c, base fork/v2 exact 12069eefd707f78eafc27812027c994eea0613cf. git ls-remote origin refs/heads/fork/v2 refs/heads/main refs/heads/port/167-foundation confirms base exact, topic exact, main unchanged c1526a7a7229a97cbae17af4109ce3b3bca1d7f2. Clean workspace. No merge/install/deploy/version/main push.

    Approved decisions A-G/D9/D19/D22/D23/D20/D25 are recorded in the PR body and supersede earlier pending packets. #152 runtime retest remains explicitly required before #177 cutover after browser authorization. No browser used.

    Host-neutral Node 24.13.1, ELECTRON_RUN_AS_NODE unset, TMPDIR=/private/tmp/:

    • pnpm --filter t3 typecheck exit 0; corresponding scoped web/desktop/contracts/client-runtime typechecks each exit 0.
    • pnpm exec vp lint <78 affected files> exit 0 and pnpm exec vp fmt --check <same files> exit 0 on final head. Fiber/Schedule warnings in ws.ts are present at pinned upstream and untouched; ws.ts diff only removes the per-WebSocket runner layer.
    • Focused 36-file pnpm exec vp test run including full apps/server/src/auth/: 862 pass, 1 real snapshot timeout while typechecks competed. Dedicated CHROMERIA_V1_SNAPSHOT_SOURCE=<live read-only state.sqlite> pnpm exec vp test run apps/server/src/persistence/forkV1Backfills.test.ts: 2 pass, exit 0, 39.66s, no assertion/timeout changes. Corrected manager/provider/maintenance subset: 106 pass, exit 0.
    • bash scripts/fork-check.sh: exit 0, merge-base upstream/main exact pinned base; bash scripts/fork-check.sh --base 12069eefd707f78eafc27812027c994eea0613cf: exit 0. Eight inventory entries and one primary owner per allowlisted carried edit. bash -n scripts/fork-check.sh scripts/fork-rebase.sh and git diff --check: exit 0.
    • node scripts/fork-features.mjs report de251fc2971a884cb5b1305ba4daf309dc8cccb0 12069eefd707f78eafc27812027c994eea0613cf: exit 0, complete 533 commits; full report posted on PR in two parts, no ENOBUFS with approved 1 GiB bound.
    • Actual RepositoryIdentityResolver in real clone: canonical github.com/pingdotgg/t3code, origin github.com/toolboxmd/chromeria. Actual production PR discovery selects toolboxmd/chromeria; live gh lookup and production matching return fork PRs 146/144/142. Upstream has no Issues UI, so Issues runtime lookup is not tested; this is its identity prerequisite for Port the GitHub Issues features #171.

    Proof logs live outside repository at /tmp/167-final-{head-lint,head-format,server-pass-typecheck,corrections-tests,real-snapshot,fork-check,fork-check-pin}.log, /tmp/167-real-repository-proof.log and /tmp/167-final-test-command.txt. No raw private database contents published. VACUUM INTO source was read-only and all import/hooks ran on disposable snapshots. Provider install boundary mocked; no actual install proof claimed.

    Mechanical changes are listed in PR, including existing shared EventSink wiring, approved fixture lifetime/mode corrections, scanner guard, numeric bind, extracted branding/query seams, helper executable modes and CI branch/runner adaptation. CI Fork Stack Model already passed on exact head; other CI remains running. Independent status and observer cost will be separately verified.

    Requirements and who asked: User requested one exact-base foundation PR with scoped proof, bounded inventory and independent exact-head review.
    Deleted: Deferred/dropped features, streaming design and ungranted runtime/install work.
    Bottleneck: Consumer foundations; early hook and corrective checkpoints already published.
    Checked myself: Exact live refs, passing scoped commands/results, read-only snapshot, actual fork PR lookup and complete report.

  7. lukemaj commented on Oct 8, 2026

    @lukemaj
    ContributorAuthor

    What: PR #178 now points to 40bbb022d6960eed462f64cc993944bb94d392ef after scoped CI repairs.
    Why: CI identified two unused exports and two desktop fixture paths still expecting upstream branding.
    So what: Consumers can use this head; exact-head review and current GitHub CI remain required, and #167 stays open.

    Approved export fix: private admitProviderStarts after confirming only same-file caller; startup explicitly imports/passes published forkV1Backfills, unchanged shell-only contract. Scoped server Knip exports, server typecheck and targeted lint/format exit 0. Startup+manager+runner+hook subset: 79 passed, 1 conditional real snapshot not requested without source env; prior dedicated actual real-data proof remains 2/2 pass, assertions and timeout unchanged.

    Approved branding fixture corrections: DesktopClerk packaged path chromeria; DesktopPreReadyFileSystem legacy root Chromeria and expected path chromeria. All bridge-order, migration-state and unreadable-profile assertions retained. Two paths primary owner branding/allowlist. Targeted DesktopClerk+DesktopPreReadyFileSystem+DesktopUserData: 15/15 pass, exit 0; desktop typecheck/lint/format/map/fork-check exit 0.

    Full failed general Test log inspected: exactly two failed assertions, 1449 passed, one existing platform skip. No failing check waived. Logs /tmp/167-ci-test-failure.log and /tmp/167-ci-lint-failure.log. Follow-up commands/logs /tmp/167-ci-export-fix-{tests,typecheck,lint,format}.log, /tmp/167-knip-scoped-fix.log and /tmp/167-ci-profile-fixtures-{tests,typecheck,lint,format}.log.

    Current head CI https://github.com/toolboxmd/chromeria/actions/runs/37813392724 created by pull_request, jobs active. Fork Stack Model passed current head. Reviewer owns pending/final review/independent exact-SHA statuses. Observer cost #178 (comment) refreshed after pushes.

    Updated complete report: #178 (comment) and #178 (comment) . Exit 0, 533 commits, 447 lines, 75963 bytes; SHA256 30255132e4f6501a9a847f83f808aa124ad71b7f803bfaa5930902e2e2f90b70. Match set unchanged; only path evidence added. Raw diagnostic placeholders are distinct from already approved scope decisions.

    No main/base mutation, merge, install, deploy, version bump or browser. #152 runtime retest remains required before #177 once authorized. Real PR lookup proven; no upstream Issues UI runtime lookup claim.

    Requirements and who asked: User required actual CI fixes, no waiver, exact-head review and one PR.
    Deleted: Unused internal export; no exemption or weakened assertion.
    Bottleneck: Current-head review and CI.
    Checked myself: All failure cases, scoped checks exit 0, exact topic and workflow head.

  8. lukemaj commented on Oct 8, 2026

    @lukemaj
    ContributorAuthor

    What: Exact-head independent review found two defects requiring reviewed decisions before repair.
    Why: Display update commands do not uniquely identify installs, and rename detection can hide removed upstream paths.
    So what: Dependent implementation is stopped until the user reviews the two recommended choices below; no failure is waived.

    Goal: deliver one safe, bounded foundation PR into fork/v2 while preserving the approved one-command-per-driver update rule and whole-stack upstream allowlist guard.

    R1: Auto-update target identity

    Evidence: reviewer finding #178 (comment) on b85cfb9, independently verified against source. apps/server/src/provider/providerAutoUpdate.ts:65-88 groups outdated instances by display updateCommand and records driver:displayCommand@latestVersion, then calls the maintenance runner for only the first instance at :115-120. apps/server/src/provider/providerMaintenance.ts:529-562 resolves each actual Homebrew executable from its prefix, but both /opt/homebrew/bin/brew and /usr/local/bin/brew can have updateLockKey homebrew and the same display command brew upgrade codex. The runner resolves capabilities only for the selected instance at providerMaintenanceRunner.ts:399-402. Two supported custom instances can therefore update only one prefix, with the second suppressed for the server run. This reproduction is source-supported, not runtime-tested.

    Recommended choice: Resolve maintenance capabilities in the fork-owned auto updater before coalescing. Allow one instance to represent siblings only when driver, resolved executable, arguments, environment, lock key and target version identify the SAME update target. Otherwise skip the driver group under the existing one-command rule. Derive attempted identity from that same resolved target; keep environment values and internal identity out of logs. Production explicitly supplies the existing ProviderRegistry resolver; no upstream service/contract edit or fallback. Keep the approved shared admission gate unchanged. Focused tests prove identical-target single execution, separate Homebrew-prefix deferral despite identical display commands, and unchanged busy/failure/repeated-attempt behavior.

    Alternative: update each distinct resolved target once. This handles both prefixes automatically but changes the carried one-command-per-driver behavior and broadens the approved replay.

    Reason for recommendation: it prevents false shared-install assumptions with the smallest behavioral change and preserves the reviewed conservative update policy. No auto-update repair has been implemented.

    R2: Rename allowlist guard

    Evidence: reviewer finding #178 (comment) on the same head, independently verified. scripts/fork-check.sh:76 enumerates git diff --name-only BASE..HEAD with rename detection; a sufficiently similar rename can report only the destination. Classification at :66-75 sees that new path absent in BASE and accepts it as fork-only, without checking removal of the original unallowlisted upstream path. scripts/fork-features.mjs already uses --no-renames for its inventory diff.

    Recommended choice: Add --no-renames to the fork-check path enumeration so removal and addition are classified separately. Add a real git-fixture regression proving an unallowlisted upstream rename fails, then succeeds only after its removed upstream path is explicitly allowlisted with one owner. Retain merge-base with upstream/main for the entire carried stack, explicit upstream fetch, missing-upstream failure, and no origin/main fallback.

    Alternative: parse rename records and explicitly validate both old and new names. It preserves rename reporting but adds parsing and more cases without improving the requested guard.

    Reason for recommendation: one option fixes the bypass while retaining the reviewed base and ownership semantics. This is a guard-behavior change, so it remains gated despite the small diff. No fork-check repair has been implemented.

    Independent authorized progress and limitations

    Mechanical web logo fixture correction retains pretty-name/tool assertions and checks the actual approved Chromeria viewBox 0 0 64 64 and href /chromeria-mark.png. Full MessagesTimeline file 83/83 pass; targeted lint/format/map/fork-check exit 0. This does not address either review finding.

    Prior-head Server5 template cleanup passed on b85; DB filename fix passed CI Server1. Unchanged ACP fake-controller test failed CI Server4 with retained fake PIDs 1050/11050; ACP source/test/dependency lock are unchanged. Targeted exact case passed locally, with only fake controller operations; a CI shard rerun was requested without source changes or a waiver. The failure cause remains unknown. Current-head CI and exact-head review success remain required.

    The independent review status is failure on b85. No merge, install, deployment, version bump, browser use or main push. #152 runtime retest remains required before #177 when explicitly authorized.

    Requirements and who asked: User requires consequential review decisions, one bounded PR and no accepted failed check.
    Deleted: Silent repairs, diagnostic exemptions, failure waivers and unsolicited ACP rewrite.
    Bottleneck: Reviewed R1/R2 choices before dependent repair and final exact-head review.
    Checked myself: Exact reviewer findings, target-selection/resolver/runner source, rename-classification source, and focused mechanical proof.

  9. lukemaj commented on Oct 8, 2026

    @lukemaj
    ContributorAuthor

    What: Reviewed R1/R2 repairs are pushed to PR #178 at 789408be4ce08f93c16f686e5c8d5519a3b90ee5.
    Why: Independent review found ambiguous install coalescing and a rename allowlist bypass.
    So what: The user approved both recommendations; repairs and local proof are complete, while exact-head review and ALL CI must pass before readiness.

    This supersedes the pending R1/R2 packet at #167 (comment) . Reviewed approval: compare resolved executable/args/environment/install target and target version; skip ambiguous groups, identity-based attempts, logs ONLY driver/instance IDs and never environment values. Fork-check uses --no-renames and a real rename regression; merge-base upstream/main, explicit-base override, missing-upstream failure and one primary owner remain unchanged.

    Commits: db1dbebfca R1 provider target identity; 789408be4c R2 rename guard. Mechanical 9e14e06e2c branding oracle remains. No deferred feature implementation, main/base push, merge, install, deploy, version bump or browser.

    Host-neutral Node 24.13.1 commands/results:

    • pnpm exec vp test run apps/server/src/provider/providerAutoUpdate.test.ts apps/server/src/provider/providerAdmissionGate.test.ts apps/server/src/provider/providerMaintenanceRunner.test.ts apps/server/src/orchestration-v2/ProviderSessionManager.test.ts scripts/fork-maintenance.test.ts: 112/112 pass, exit 0. Distinct prefixes with same label skip; identical resolved targets execute exactly once even when environment key order differs; argument/env/install-target differences skip. All earlier gate/production/concurrency assertions retained. R100 upstream rename fails without ownership, passes only with explicit ownership. Initial test fixture omitted ownership for its own changed map; corrected fixture setup, no assertion weakened.
    • pnpm --filter t3 typecheck, pnpm exec knip --workspace apps/server --exports --preprocessor ./scripts/knip-schemas.ts --no-config-hints, targeted lint and format: each exit 0. Logs /tmp/167-r1-r2-{tests,typecheck,knip,lint,format}.log.
    • bash scripts/fork-check.sh and bash scripts/fork-check.sh --base 12069eefd707f78eafc27812027c994eea0613cf: exit 0. node scripts/fork-features.mjs check: eight entries, exit 0. Bash syntax and git diff checks exit 0.
    • Complete exact-pin overlap report command exit 0, all 533 commits, 447 lines, 76405 bytes; SHA256 bbd11ea545d685211e60d8efbcddf9d2359fd949b67903e70e4e1c72ed40bdd2. Full report feat(fork): carry Chromeria foundation onto upstream V2 #178 (comment) and feat(fork): carry Chromeria foundation onto upstream V2 #178 (comment) . Approved 1 GiB bound, no streaming or ENOBUFS.

    Earlier focused proof, five scoped typechecks, actual read-only real snapshot 2/2 pass, and actual fork PR discovery/matching/live lookup remain in prior records and PR body. No Issues runtime UI claim, no provider installation proof. #152 runtime retest remains pending and required before #177 after explicit browser authority.

    Current-head CI https://github.com/toolboxmd/chromeria/actions/runs/37816469008 is active; Fork Stack Model passed. Reviewer owns review/independent pending and final verdict on this exact SHA. Prior failed heads are not accepted; ALL current CI must pass. Observer cost is being refreshed on the same PR.

    Requirements and who asked: User reviewed R1/R2 recommendations and requires exact-head independent review, ALL green CI and one PR.
    Deleted: Display-label install identity, rename bypass, raw-cause/environment logging, failure waivers and unsolicited runtime work.
    Bottleneck: Final exact-head CI and review after approved repairs.
    Checked myself: Source repair, all 112 tests, scoped commands exit 0, complete report and live pushed head.

  10. lukemaj commented on Oct 8, 2026

    @lukemaj
    ContributorAuthor

    What: PR #178 is ready and unmerged at 789408be4ce08f93c16f686e5c8d5519a3b90ee5.
    Why: The bounded V2 foundation, approved replay repairs, scoped proof, exact-head independent review and current CI are complete.
    So what: The user merges PR #178 into fork/v2; #167 stays open until merge, and #152 runtime retest remains required before #177 cutover.

    Canonical delivery handoff

    Exactly one PR: #178 . Head 789408be4ce08f93c16f686e5c8d5519a3b90ee5, topic port/167-foundation, base fork/v2 exact 12069eefd707f78eafc27812027c994eea0613cf. origin/main remains c1526a7a7229a97cbae17af4109ce3b3bca1d7f2; no main/base rewrite, merge, install, deploy, version bump or browser. Exclusive workspace /Users/lukaszmaj/dev/toolboxmd/chromeria-worktrees/166-absorb retained for the unmerged PR. PR is registered in T3.

    Delivery states: qualified, implemented, scoped-proved, independently reviewed and ready. NOT merged/released/deployed/installed/live-verified. No further implementation or discretionary checks pending.

    Proof commands/results

    Host-neutral Node24.13.1: ELECTRON_RUN_AS_NODE unset, PATH pins Node24 and Node22 pnpm tools, TMPDIR=/private/tmp/.

    1. pnpm exec vp test run apps/server/src/provider/providerAutoUpdate.test.ts apps/server/src/provider/providerAdmissionGate.test.ts apps/server/src/provider/providerMaintenanceRunner.test.ts apps/server/src/orchestration-v2/ProviderSessionManager.test.ts scripts/fork-maintenance.test.ts:112/112 pass, exit0. Actual production admission/runner composition, shared starts/exclusive updates, both orderings and cancellation kept. Same-label distinct resolved prefixes/args/env/install targets skip; identical targets exactly once. Real R100 rename denied until explicitly owned.
    2. pnpm --filter t3 typecheck; scoped web/desktop/contracts/client-runtime typechecks:each exit0. Server rerun after R1/R2 exit0. pnpm exec knip --workspace apps/server --exports --preprocessor ./scripts/knip-schemas.ts --no-config-hints:exit0. Targeted lint and format:exit0, existing warnings retained.
    3. bash scripts/fork-check.sh; bash scripts/fork-check.sh --base 12069eefd707f78eafc27812027c994eea0613cf:exit0. Whole-stack merge-base upstream/main, missing-upstream failure, no origin fallback, only carried allowlist and eight entries. Shell syntax/git diff checks exit0.
    4. node scripts/fork-features.mjs report de251fc2971a884cb5b1305ba4daf309dc8cccb0 12069eefd707f78eafc27812027c994eea0613cf:exit0, complete533commits447lines76405bytes, SHA256 bbd11ea545d685211e60d8efbcddf9d2359fd949b67903e70e4e1c72ed40bdd2. Full output feat(fork): carry Chromeria foundation onto upstream V2 #178 (comment) and feat(fork): carry Chromeria foundation onto upstream V2 #178 (comment) . Approved1GiB bound, no streaming/ENOBUFS. Diagnostic placeholders are distinct from reviewed scoped replay decisions.
    5. Earlier affected36-file suite862pass/1contended real-snapshot timeout, followed by unchanged dedicated read-only real snapshot2/2pass39.66s. No timeout/assertion change. Full auth suite Node24.13.1 passed. Desktop15/15 and complete MessagesTimeline83/83 pass after mechanical branding fixture repairs. Full current CI then passed.
    6. Real clone production repository identity/discovery/matching plus live gh PR lookup: origin toolboxmd/chromeria, canonical pingdotgg/t3code unchanged; fork PRs match. Upstream has no Issues UI: NO runtime Issues lookup claim; this is prerequisite for Port the GitHub Issues features #171.

    Exact prior command/log references: #167 (comment) , #167 (comment) , #167 (comment) . Logs outside repository /tmp/167-r1-r2-{tests,typecheck,knip,lint,format}.log, /tmp/167-final-{real-snapshot,fork-check,fork-check-pin}.log; exact initial affected command /tmp/167-final-test-command.txt. No private data contents published.

    Reviewed decisions and mechanical changes

    A-G/D9/D19/D22/D23/D20-D25 and R1/R2 are approved, recorded in PR body and preceding records. Eight entries only: seven carried features plus data foundation. No deferred #168-177 implementations or dropped #90/#154/#156/#134/#152 implementations. Empty hook registry, shell-only/frozen-V1 contract, opaque env/project settings, own chromeria-v2.sqlite and existing chromeria profile preserved.

    R1 uses resolved executable/args/environment/install target/version identity, conservative ambiguous-group skip, identity-based attempts and logs only driver/instance IDs. R2 disables rename detection while preserving upstream merge-base semantics. Their repair commits are db1dbeb and789408be4c. Mechanical adaptations include extracted branding seams, existing shared EventSink wiring, upstream query/Git signatures, fixture lifetime/mode/profile/DB/logo oracles with all safety assertions retained, numeric SQLite binding, test-only importer guard, helper executable modes and CI runner/integration branch triggers. Initial rename regression fixture ownership omission corrected without weakening assertions.

    Limits: no browser/client runtime screenshots, actual CLI installer execution, Issues UI runtime lookup or installation/cutover proof. Real data opened read-only solely for VACUUM INTO; migrations/imports/hooks only on private disposable snapshots, no server against live state. #152 retest explicitly pending and required before #177 after browser authority. No full repository local checks; CI owns broad coverage. Website impact none: external marketing/URLs/deployment unchanged.

    Requirements and who asked: User requested one exact-base bounded foundation PR with safe data contract, reviewed decisions, scoped proof, ALL current CI and independent exact-head review.
    Deleted: Deferred/dropped feature implementations, streaming design, display-label target identity, rename bypass, diagnostic/failure waivers and ungranted runtime/install work.
    Bottleneck: Foundation for #168/#170/#171/#174; early checkpoints shipped, final CI/review now complete.
    Checked myself: Required full records/source, real snapshot and fork PR lookup, scoped proof output, exact-head review creator/status, current CI completion and live Git/GitHub identity.

  11. lukemaj commented on Oct 8, 2026

    @lukemaj
    ContributorAuthor

    What: All latest PR #178 checks are settled on unchanged head 789408be4ce08f93c16f686e5c8d5519a3b90ee5.
    Why: The final PR-body edit triggered a fresh fingerprint run because its workflow listens to pull_request edited events.
    So what: Fingerprint run37818019805 passed; the user can merge, #167 remains open, and no further PR-body edit or discretionary rerun is planned.

    Latest fingerprint: https://github.com/toolboxmd/chromeria/actions/runs/37818019805 , success/completed, attempt1, actor/triggering_actor lukemaj, same final SHA. gh pr checks 178 --repo toolboxmd/chromeria now shows every applicable check passed, conditional checks skipped, no failed or pending check. Exact-head independent review success remains #178 (comment) . Canonical full ready handoff #167 (comment) remains current, supplemented by this last-check clarification. No code, head, base, version, merge/install/browser change.

    Requirements and who asked: User required latest checks settled after detecting the fresh fingerprint run.
    Deleted: No new rerun, code change or further PR-body edit.
    Bottleneck: Fingerprint completion after edited-event trigger.
    Checked myself: Workflow includes edited, run metadata attempt1 same SHA, completion success and exact latest checks with no failure/pending.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions