Skip to content

Prove isolated NodeSlide mount in NodeRoom#235

Merged
HomenShum merged 1 commit into
mainfrom
codex/nodeslide-v0.2.2-bind
Jul 21, 2026
Merged

Prove isolated NodeSlide mount in NodeRoom#235
HomenShum merged 1 commit into
mainfrom
codex/nodeslide-v0.2.2-bind

Conversation

@HomenShum

Copy link
Copy Markdown
Owner

What changed

  • Mount the packaged NodeSlide v0.2.2 Convex component behind NodeRoom ActorProof and room-membership authorization, with one-time grants bound to the canonical patch digest.
  • Extend the immutable release proof to fresh-install the public artifacts, exercise isolated initialize/substitution/exact/replay/reread behavior, run the full Memory/Convex/React journey, and upload its JSON receipt in CI.
  • Fix the mounted memory UI so it never enters Convex hooks without a provider and so semantic selection synchronization cannot recurse on identity churn.
  • Add a literal desktop browser/a11y proof bundle for edit → Make live → reopen, mounted 0.2.2 DOM attributes, command reachability, clean console, and fail-closed memory writes.

Why

NodeRoom previously proved the package/repository seam but did not mount the isolated Convex component under the host authorizer or carry an exact immutable install/upgrade receipt through CI. Camera dogfooding also exposed two real crashes in the memory journey: unconditional Convex hooks without a provider and a selection effect that always committed fresh state.

Trust boundary

The screenshots are deliberately classified as a local memory-room camera pass. The live deployment correctly rejected the disposable unauthenticated sample with production_identity_required; no identity check was bypassed. ActorProof, membership, digest binding, exact-byte acceptance, replay rejection, durable proposal acceptance, reload, presenter/PPTX, and credential-free receipt claims come from the deterministic Convex/repository/component journeys.

Validation

  • npm run nodeslide:mounted:release:proof against exact NodeSlide a88fb57f111db82e9334d68fa7611a51ed54c3c1 — PASS; 11 assets, six runtime packages, fresh isolated component and full journey.
  • GitHub release v0.2.2 — immutable; annotated tag object ec4870300e1ad7ddd74209aada3a47a26779b4bb; public proof run 29787121559 succeeded on the exact producer SHA.
  • npm run prod:gate — PASS; zero production dependency vulnerabilities; 367 files / 2,548 tests; product-memory, build, and post-build security scan green.
  • npm run nodeagent:frame:smoke — PASS.
  • npm run omnigent:nodeagent:smoke — PASS (outer optional Omnigent CLI is not installed locally).
  • Screenshot byte/hash/dimension verification — PASS; secret-pattern scan over changed text — 0 hits.

@vercel

vercel Bot commented Jul 21, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
noderoom Ready Ready Preview, Comment Jul 21, 2026 3:18am

Request Review

@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown

Scaffold Handoff — For Your Coding Agent

Your coding agent (Codex, Claude Code, etc.) should apply the accepted
scaffold proposals below. Do NOT touch any immutable files.

Immutability Check

Mode: advisory

⚠️ Immutable proof files changed: .github/workflows/ci.yml

This is advisory because the check is not running in strict scaffold-repair mode.
If this PR is applying accepted scaffold proposals, rerun with --strict-immutability
and reject the PR unless the immutable changes are removed.

Immutable files guarded during scaffold repair:

  • scripts/proofloop.mjs
  • scripts/agent-improvement-loop.ts
  • tests/harnessChangeEval.test.ts
  • .github/workflows/
  • src/eval/evalTrustPolicy.ts
  • src/eval/architectureBudget.ts
  • evals/evalStore.ts

Changed Files

  • .github/workflows/ci.yml
  • artifacts/nodeslide-mounted-ui-proof-20260720/README.md
  • artifacts/nodeslide-mounted-ui-proof-20260720/memory-write-fails-closed-clean.jpg
  • artifacts/nodeslide-mounted-ui-proof-20260720/mounted-artifact-command-surface-clean.jpg
  • artifacts/nodeslide-mounted-ui-proof-20260720/receipt.json
  • convex/nodeslideHost.ts
  • docs/NEXT_SESSION.md
  • docs/eval/OFFICIAL_BENCHMARK_READINESS.md
  • docs/eval/OFFICIAL_BENCHMARK_TASK_COVERAGE.md
  • docs/eval/OPENROUTER_CONVEX_BENCHMARK.md
  • docs/eval/agent-improvement-loop.md
  • docs/eval/agent-improvement-loop.svg
  • docs/eval/agent-improvement-loop/20260721T031742Z.json
  • docs/eval/agent-improvement-loop/latest.json
  • docs/eval/agent-workspace-sandbox-smoke.json
  • docs/eval/algorithm-artifact-smoke.json
  • docs/eval/bankertoolbench-official-contract.json
  • docs/eval/docker-sandbox-probe.json
  • docs/eval/eval-runs.jsonl
  • docs/eval/halo-convex-context-telemetry.json
  • docs/eval/halo-self-improvement-smoke.json
  • docs/eval/halo-variant-selection.json
  • docs/eval/official-benchmark-readiness.json
  • docs/eval/official-benchmark-task-coverage.json
  • docs/eval/openrouter-convex-benchmark.json
  • docs/eval/professional-catalog-proofs.json
  • docs/eval/professional-proof-ledger.json
  • docs/eval/spreadsheetbench-chart-visual-probe.json
  • docs/eval/traces/credit/20260721T031751952Z-4de61e9a_dirty.20914474e02ab550/cascade-healthy.json
  • docs/eval/traces/credit/20260721T031751952Z-4de61e9a_dirty.20914474e02ab550/delta-incomplete.json
  • docs/eval/traces/credit/20260721T031751952Z-4de61e9a_dirty.20914474e02ab550/mapping-correct.json
  • docs/eval/traces/credit/20260721T031751952Z-4de61e9a_dirty.20914474e02ab550/mapping-misbind.json
  • docs/eval/traces/credit/20260721T031751952Z-4de61e9a_dirty.20914474e02ab550/summit-stressed.json
  • docs/eval/traces/ladder/20260721T031751470Z-4de61e9a_dirty.0ccaffcce17630a4/ladder_L1_read_scripted.json
  • docs/eval/traces/ladder/20260721T031751470Z-4de61e9a_dirty.0ccaffcce17630a4/ladder_L2_edit_scripted.json
  • docs/eval/traces/ladder/20260721T031751470Z-4de61e9a_dirty.0ccaffcce17630a4/ladder_L3_conflict_scripted.json
  • docs/eval/traces/ladder/20260721T031751470Z-4de61e9a_dirty.0ccaffcce17630a4/ladder_L4_blocked_scripted.json
  • docs/eval/traces/ladder/20260721T031751470Z-4de61e9a_dirty.0ccaffcce17630a4/ladder_L5_large_range_scripted.json
  • docs/eval/traces/ladder/20260721T031751470Z-4de61e9a_dirty.0ccaffcce17630a4/ladder_L6_long_horizon_scripted.json
  • docs/eval/traces/ladder/20260721T031751470Z-4de61e9a_dirty.0ccaffcce17630a4/ladder_L7_resume_scripted.json
  • docs/integrations/NODESLIDE_CONSUMER_PROOF.md
  • nodekit.yaml
  • scripts/nodeslide-mounted-release-proof.ts
  • src/integrations/nodeslide/NodeRoomNodeSlideStudioMount.tsx
  • src/ui/workArtifacts/DeckStoryboardWorkbench.tsx
  • src/ui/workArtifacts/WorkArtifactsPanel.tsx
  • tests/deckBinderRouting.test.tsx
  • tests/nodeSlideMountedConvexJourney.test.ts
  • tests/nodeSlideMountedIsolatedComponentJourney.test.ts
  • tests/nodeSlideMountedMemoryJourney.test.ts
  • tests/workArtifactsNotebookReadModelUi.test.tsx
  • vendor/nodeslide/README.md
  • vendor/nodeslide/release-lock.json

Needs Adversarial Review — Do NOT Apply Yet

These proposals passed the reject check but have not been approved by
an adversarial reviewer. A human or frozen LLM judge must approve them first.

  • scaf-001 (AGENTS.md): Add explicit instruction for step spreadsheetbench-runner-fixture: Step spreadsheetbench-runner-fixture failed — scaffold may need explicit instruction or evidence assertion.
  • scaf-002 (AGENTS.md): Add explicit instruction for step convex-boundaries: Step convex-boundaries failed — scaffold may need explicit instruction or evidence assertion.

Safety Boundary

Agent may improve the scaffold.
Agent may NOT weaken the proof gate.

Immutable files (never modify):

  • scripts/proofloop.mjs
  • scripts/agent-improvement-loop.ts
  • tests/harnessChangeEval.test.ts
  • .github/workflows/
  • src/eval/evalTrustPolicy.ts
  • src/eval/architectureBudget.ts
  • evals/evalStore.ts

Scaffold files (safe to modify):

  • AGENTS.md
  • CLAUDE.md
  • proofloop/scenarios/*.yaml
  • proofloop/rubrics/*.yaml
  • proofloop/subagents/*.md
  • proofloop/adapters/*.js
  • .proofloop/memory.jsonl
  • src/nodeagent/models/prompts/systemPrompt.ts

Changed areas: .github, artifacts, convex, docs, nodekit, scripts, src, tests, vendor.

Bind the isolated component to NodeRoom authorization, prove the immutable release and mounted journey, fix the memory UI crashes, and publish camera plus CI receipts.
@HomenShum
HomenShum force-pushed the codex/nodeslide-v0.2.2-bind branch from 40e7430 to 20e83aa Compare July 21, 2026 03:16
@HomenShum
HomenShum merged commit 0d13dff into main Jul 21, 2026
13 checks passed
@HomenShum
HomenShum deleted the codex/nodeslide-v0.2.2-bind branch July 21, 2026 04:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant