Repository navigation
Conversation
* docs(fork): replay confirmed direction and glossary for v2 * wip: publish v2 fork backfill contract and snapshot harness * test(persistence): run registered fork backfills before hydration * fix(server): bind pairing scope flag as a SQLite integer * fix(git): preserve partial-clone remote identity * fix(client): retry interrupted environment query reads * feat(branding): restore Chromeria desktop and web identity * feat(persistence): isolate V2 state and preserve fork settings * feat(provider): restore opt-in updates with shared start admission * chore(fork): restore carried inventory and upstream stack checks * chore(fork): check integration pushes and preserve helper modes * fix(fork): consume published backfill registry at startup * test(branding): use Chromeria profile in desktop startup fixtures * test(persistence): expect the dedicated Chromeria V2 filename * test(branding): assert the Chromeria mark for MCP tools * fix(provider): coalesce only identical resolved update targets * fix(fork): require allowlisting renamed upstream paths
… onto v2 (#171) (#179) Upstream's v2 removed the gh CLI client and the v1 projection reads the fork's Issues features used. This ports them onto upstream's GitHubApi (GraphQL variables, the shared pager, credential pinning per host), v2 thread reads, McpToolAccess and native subagent lineage, keeps fork_thread_issue_links unchanged across the v1 import, and requires source-control:write for Issue comment and close (D27). Feature map and allowlist list the four features. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* wip: checkpoint thread people v2 port Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: thread people backfill, tests and web replay Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: cover agent fork owner stamping Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: describe the person picker as it is placed now Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: reproduce an invalid imported payload that already has people fields The fixture fails on purpose until the backfill decision lands. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: narrow V1 reader exception and consumed-payload validation wording Allow the thread people backfill to read the frozen V1 owner columns, drop the never-consumed payload fixture, and fix two test type errors. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(fork): register v2 thread people ownership * docs(fork): link thread people v2 approval PR * fix(people): disable person changes without access write * fix(people): guard sharing and preserve typed backfill failures * fix(people): check target operate scope for sharing --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* wip: publish approved fork transaction plan seam * wip: publish durable retirement admission and Stop drain * wip: preserve cross-project delegation before foundation stacking * wip: implement descendant requests and imported lineage with production Stop proof * wip: prove actual V1 lineage repair and concurrent Stop admission * wip: fence propagated Stop at the commit boundary * wip: retain archived intermediates in Stop ancestry * wip: stop living descendants through deleted lineage anchors * feat(server): map durable child threads on v2 * fix(server): wake pending child requests after ancestor resume * fix(server): prepare delegated children through client intake * test(server): prove imported child issue rollup after v2 rebase * style(docs): format child thread shared ownership map * fix(server): preserve provider metadata when resuming child threads * test(server): compose child ownership with landed people port
* wip: port shared Prism routing settings and persisted recovery * wip: wire persisted Prism recovery and approved kit semantics * wip: prove recovery survives stale propagated Stop * wip: inventory Prism port and prove complete saved kit preservation * wip: correct Prism integration fixture and typed saved settings proof * wip: retain landed ownership while composing Prism imports * wip: validate Prism launch admission and refresh configured providers * fix(server): revalidate stale Prism launch providers * fix(prism): satisfy CI exports and default restore coverage * fix(test): refresh recorded Muse runtime guidance for Prism
* feat(server): restore v2 stream clocks and silent child notices * refactor(prism): shrink execution stream clock hooks
* wip: checkpoint Wight settings and injected v2 continuation * wip: preserve D30 Wight admission and client controls * wip: checkpoint Wight v2 admission and focused proof
* feat(server): publish Prism per-run recovery outcome reader checkpoint * wip: publish D38 immutable decision and indexed continuation reader * fix(server): preserve admitted recovery sources and prove durable history * fix(server): bound Prism finalization history observation * fix(server): bound Prism pending request hydration
* wip: checkpoint independent Promachos v2 home and view port * feat(promachos): port home and chat onto v2 launch * fix(promachos): retain projected provider error notices * wip: validate Promachos launch and isolate fork hooks * fix(promachos): register authorization test ownership * fix(promachos): keep module-local helpers private * fix(promachos): restore launch kit after partial create retry
…v1 import (#193) * wip: scheduled task outcome checks, one-shot, weekly and command tasks on upstream's scheduler Server and contracts slice for #174. Upstream files get small hooks only: one schedule-union spread, two read-model fields, the dispatch policy and fire key in runTask, Schedule.ts guards, MCP tool hooks and the runtime layer wrap. Client display and editors are not in this checkpoint. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: modular runTask and MCP hooks, client display, command notifications, runner tests In-place hooks: dispatchVia wraps upstream's launch/send calls and the MCP schedule/update/delete wrappers wrap the existing service calls, so no upstream expression is re-indented. Web and mobile show fork triggers read-only through shared fork modules; command failures notify like thread alerts. Client typecheck and the new runner tests have not run yet. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: route scheduled task roles through the merged Prism service A role resolves through PrismService: a launch takes Prism's validated model and kit, a post to a bound thread takes only the kit and keeps the thread's model. With no eligible model the run retries; it never falls back to the task's own model. Contracts use the merged PrismRole and PrismLane. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: exact run follower, recovery and Spectrum ports, completion fence (unwired) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: provider-turn delivery evidence, fence fixture on #176's fork_spectra schema, D35 follower tests Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: consume #169's D38 recovery state, recheck the run's work in the settle transaction Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: D40 fence (completed report turn or user abandon releases, report needs-you makes the run need you), drop provider-turn evidence, schedule tests Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: keep the run's state in the fence transaction, effect dates in schedule tests Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: report needs-you before every check and dispatch, JSON run decoding in the observer, integrated D40 and race proofs Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: v1 import, contracts, client-runtime and preserved-trigger round-trip tests Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: scheduled-tasks feature map entry, allowlist and user docs Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: fork-owned trigger round-trip tests, direct upsert refusal proof, Spectrum report wording Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: gated actual-data subset proof of the v1 scheduled-task import through the real startup path Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: lint and Hermes fixes, drop the unused server schedule label hook, subset proof summary Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: keep the schedule label hook, which narrows upstream's union Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: positive source oracle for the actual-data subset import proof Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: subset proof reports only field labels and counts, never private values Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: relaunch a new-thread run whose thread was never created, and surface an active Spectrum's current report needs-you Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: read launch evidence from the live command receipt table Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: the report fence reads the live receipt table, and fixtures record receipts through the real store Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: the live task subscription leaves command output out; Settings fetches it from the list on demand Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: on-demand command output shows a failed fetch with a retry, never endless loading Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: refetch command output by remounting on a new run Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: on-demand command output never shows a previous result while fetching Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: a deleted task's admitted send or command starts nothing, and a judged thread's delete is guarded under the task's lock The guard, upstream's delete and the fork state now run under the task's lock in one transaction. The deferred send and command spawn re-read the state under the lock and start nothing unless the task still owns the run; the deferred send also re-reads the D40 fence there. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: a command task deleted while its run finds the workspace never starts The workspace is found first; the ownership check and the real spawn then share the task's lock, which is released once the process has spawned and never held while it runs. The runner returns at the spawn, and its returned effect waits. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: every send, including drive's redelivery, waits for its reports to release Drive's redelivery and its new sends now go out through the same locked ownership and fence check as the deferred send, so a send held for a waiting report stays unsent through later steps and restarts, then goes out once with its recorded id and payload. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: a command run executes the command admitted with it, not an edit made while it starts Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip(unproved): each command admission has its own identity, so a recreated task's same-id run never borrows an older one A successful delete ends its runs' admissions; a command fiber checks its exact admission before its spawn and before writing its result, and its cleanup ends only its own admission. Red and clean-SHA proof are still pending. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: a deleted task's deferred send never goes out in a recreated run of the same id Deferred sends from a fire or Run now now carry their admission too, sharing the command bookkeeping: only the exact admission sends, a successful delete ends it, and a step recovers stored runs without one. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: CI repair: file-local scheduled task helpers, and the thread notification tests never load scheduler data Knip found 11 exports used only in their own file; they are no longer exported. The coordinator's two upstream test files mocked @effect/atom-react for its shell reads only, so the scheduled command notifier it now mounts crashed on the missing useAtomRefresh. They now mock the environment query to return no data (the scheduler's list never loads, not a loaded empty list), every assertion unchanged, and a fork test drives the notifier with real task data. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* wip: build Spectrum v2 barrier and transcript persistence slice * wip: omit provider identity from Spectrum transcript events * wip: dispatch durable Spectrum transcripts through the shared seam * wip: reject duplicate Spectrum participant threads * wip: integrate Spectrum Color launches and scoped fork commits * wip: reject core cancellation in state-only fork commits * wip: human Abandon report RPC contract and web/mobile action Adds spectrum.abandonReport (operate scope, client-guarded) and the Abandon report action on scheduled runs a Spectrum report holds at needs-you. Server handler is wired separately. Unverified checkpoint. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: deliver Spectrum reports with bounded retries and a real scheduler adapter Report settle, immutable outbox send, D40/D42 attempt classification, guarded retry, human abandonment with exact-chain drain, and the ScheduledTaskSpectra adapter over fork_spectra (#176). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: recheck report delivery when abandonment commits Abandonment now commits with a projection-only guard that refuses it when the current attempt's recorded run chain completed after planning (D42). The regression completes the report turn between abandon's read and its commit and checks state and receipts stay unchanged (#176). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: integrate the Spectrum controller and human report abandonment * wip: keep report attempt constructors private * feat(spectrum): advertise transcript running state on thread shells * feat(spectrum): route MCP Stop and publish durable running lifecycle * feat(spectrum): expose the authenticated GUI Stop bridge * feat(spectrum): authenticate GUI Stop and prove scheduler-only recovery * fix(spectrum): guard lifecycle updates against concurrent metadata * test(spectrum): reject the old global event subscription * wip: Spectrum Stop reachability on web and mobile Stop shows and works on a thread whose shell reports a running Spectrum, even with no active run, and routes through thread.stop. Blocked on the client dispatch contract: thread.stop is still server-internal. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: send Spectrum Stop through the spectrum.stop bridge A thread with a running Spectrum stops through the authenticated spectrum.stop RPC with the allocated command id, instead of a client thread.stop the dispatch contract does not admit. Awaits its contract. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * wip: send Spectrum Stop through the guarded bridge spectrum.stop stays client-guarded, so Stop sends it with requestGuarded and the interrupt command installs the session-backed permission guard, as createEnvironmentRpcCommand does for its own tag. A session without operate sends nothing. The guard helper is allowlisted as a reviewed command boundary for t3code/no-rpc-permission-bypass. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * chore(spectrum): map and allowlist the authenticated Stop hooks * chore(spectrum): allowlist its new mobile and permission hooks * fix(spectrum): reconcile owned runs after Stop races a launch * fix(server): drain branch naming before cancelled setup cleanup --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
Thread transfer impact✅ Thread transfer remains within every enforced ceiling.
Baseline: unavailable · PR result: Scenario and decoded snapshot size10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.
Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What: Prove the complete Chromeria v2 port stack against its exact upstream base, without merging this PR.
Why: Component PRs do not prove the combined stack, and an absorption PR against v1 main would conflict and prevent pull-request CI.
So what: This PR runs the full CI gate; #177 retains landing and installation preparation, and the user owns the integrated UI pass and every merge.
Refs #177 and umbrella #166. DO NOT MERGE THIS PR. This is the absorption record; main would eventually move only with an approved explicit force-with-lease operation. The current task forbids that operation, merges, installations and app launches.
Exact identities
de251fc2971a.12069eefd707f78eafc27812027c994eea0613cf, published asabsorb-base/12069eefd7.62726b5ce141e6f4df82bbf76d731e29d172df1a,fork/v2, fourteen squash topic commits above the base, no merge commits.ffcdae87ca364e4bd44e5e995b89abf9c98ef8b8.c1526a7a72: docs: Mission makes Chromeria a personal app kept rebasable through modules #185 only. docs: carry the personal-app Mission into fork/v2 #186 carries its Mission change in8fc40da4fd603f343f13d6e51676b6f1e091b555; MISSION.md is identical on main and candidate. Its two fork-maintenance sentences were adapted to the v2 guide, retaining the v2 data/proof guidance.Feature dispositions
The #166 decision table and later amendments are authoritative, including D4-D7 tool/wake/mode/scope choices and D8-D45 runtime contracts. This is a feature port after upstream #2829 replaced the orchestration engine, rather than replaying the 71 old fork commits mechanically. Foundation's complete original 533-commit overlap report and reviewed decisions remain on #167 and #178, not recomputed after the base changed.
chromeria-v2.sqlite, settings preservation and shell-phase backfill registrysub.*parent repairConflicts and resolution from merged port records
No mechanical rebase of the old 71-commit stack was run; deleted engine/projection/contracts were rewritten feature by feature. The merged PR records own the original per-file detail. Known integration conflicts:
apps/server/src/persistence/forkV1Backfills.ts,docs/fork-features.md,scripts/fork-upstream-edits.txtcomposed both thread-people and lineage entries, including typed error mapping. D13-D moved seven primary upstream paths to child-threads with people as shared owner; Issues kept registration-test ownership. Source range-diff otherwise equal.scripts/fork-upstream-edits.txtentries kept both sides; the final diff contains only stream/liveness scope.docs/fork.mdkept the v2 guide and applied docs: Mission makes Chromeria a personal app kept rebasable through modules #185's two modularity sentences; MISSION.md carried exactly.Reworked/dropped old commits: old orchestration engine, project-scoped thread aliases and spawn toolkit, agents tree/sidebar filtering, unrestricted child access, v1 scheduler and Spectrum outbox/report queue were replaced by the dispositions above. This is not a one-to-one cherry-pick map. Foundation omits the adopted #90/#154/#156/#134/#152 implementations; native stored effort, diagrams and preview fixes are retained upstream. #190 fixes ACP fixture PID collisions; #191 fixes CI apt setup; #192 completes exact-run recovery. These are explicit reviewed successor commits, not waivers.
Combined proof and remaining acceptance
Full CI passed on this exact candidate in run 37899839318, including aggregate Check, Lint, Typecheck, Build, Test, Test Web, all six server shards, transfer report, Rust, Release Smoke and Mobile Native Static Analysis. Native fingerprint diff and Fork Stack Model passed. Initial CI attempt completed in about six minutes; no failures, reruns or waivers. Conditional EAS Preview and size-label-definition synchronization skipped by workflow conditions; no proof gate was skipped. Verified current head/base and all live statuses after completion. Local
scripts/fork-check.sh --base 12069eefd707f78eafc27812027c994eea0613cfpassed (exit 0, 23 features, fourteen merge-free topic commits) on pristine62726b5ce1, started at 1-minute load 6.19. Command was read-only from the pristineuiv2checkout while the identity writer owned the fresh worktree; no runtime or database was accessed.Real-data aggregate verification uses the planner-owned isolated
uiv2/.t3/userdataVACUUM snapshot. No additional snapshot is authorized because disk is critical. The planner supplies first-start counts; idempotence waits until its dev server is stopped. Aggregate evidence only, with no private rows published. Snapshot cleanup remains coordinated with its owner.The user owns integrated web/mobile UI verification and #152/Spectrum Stop evidence; this thread opens no browsers or simulators. A separate approved identity PR will allow a build-time V2 variant (name Chromeria V2, bundle md.toolbox.chromeria.v2, profile chromeria-v2, scheme chromeria-v2, default ~/.t3-v2). It will not be merged here; therefore this CI result proves the current stack, and the eventual combined identity candidate needs fresh CI after its separately approved integration. No desktop build until the user confirms disk space.
Website impact: none; this absorption changes the fork clients/server, not a published site.
Elon record
Requirements and who asked: User requested #177 full combined CI, fork-check, aggregate real-data proof, side-by-side identity and prepared landing/install commands, with no merges/main pushes/installs.
Deleted: Duplicate UI pass, extra real-data copy, premature build/install, automatic scheme takeover, blind reruns and waivers.
Bottleneck: Full combined CI and local load/disk limits; identity integration and planner UI acceptance remain before any eventual landing.
Checked myself: Live candidate/base/main refs, fourteen merge-free topic commits, all merged port records, #166 decisions, #185 carryover, repo instructions and cavallo runbook.
Model/harness: GPT-6.1-Sol through Codex in T3 Code.