Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
47 commits
Select commit Hold shift + click to select a range
3508f1d
M60–M61: the host API record, the vscode boundary, the webview's host…
claude Sep 26, 2026
78e3f42
M63a: the ACP agent, the key in the OS credential store, Open VSX and…
claude Sep 26, 2026
9884f18
Q60 done, Q65 blocked: the agent installs from its release URL
claude Sep 26, 2026
587d610
M62a: the VS Code floor at 1.99 (PLAN.md M62, A8)
claude Sep 26, 2026
2922899
M62b: Eclipse Theia 1.75 qualified; Q65 answered (NPM_TOKEN set)
claude Sep 26, 2026
675f1b5
M63b: the ACP agent in Emacs (agent-shell) and Neovim (CodeCompanion)
claude Sep 26, 2026
a4e8993
M63b: the ACP agent in Zed 1.20
claude Sep 26, 2026
61f961f
M63b: JupyterLab through Jupyter AI's ACP client
claude Sep 26, 2026
1b94043
M63c: the editor's MCP servers reach Muse Code
claude Sep 26, 2026
32a9e63
CI: host checks for the VS Code family and the ACP clients (hosts.yml)
claude Sep 26, 2026
7ac3837
CI: the VS Code forks' latest Linux builds (forks.yml)
claude Sep 26, 2026
614d05b
Merge main (M45, session goals) into the IDE compatibility branch
claude Sep 26, 2026
99b76e0
The forks' first CI results; the agent in PRIVACY.md
claude Sep 26, 2026
1decebe
docs/acp.md: starting the agent on Windows as node and its script
claude Sep 26, 2026
7bd6fec
M63c: paid features in the ACP agent, confirmed with their price
claude Sep 26, 2026
b17edd1
Forks: Kiro's VS Code base is vsCodeVersion (1.131.0)
claude Sep 26, 2026
a9ba78d
Merge main (M46, background work and the user shell) into the IDE com…
claude Sep 26, 2026
68d450e
Merge main (M47, workflows) into the IDE compatibility branch
claude Sep 26, 2026
faace73
Merge main (M48-M56) into the IDE compatibility branch (M60-M63)
RandyNorthrup Sep 27, 2026
2559a9b
Release: create the Open VSX namespace before the first publish
RandyNorthrup Sep 27, 2026
bc210be
Merge main (0.9.0/0.9.1, M57, M58) into PR #32 (M60-M63)
RandyNorthrup Sep 28, 2026
b368edf
Set the ACP agent's bundle budget to 850 KiB (PLAN.md D6)
RandyNorthrup Sep 28, 2026
08bda5a
docs/acp.md: networks and proxies for the ACP agent
RandyNorthrup Sep 28, 2026
e231349
Run keystore.sh on the owner's Windows 11 VM and Mac mini
RandyNorthrup Sep 28, 2026
59490d3
PRIVACY: the ACP agent's paid-use grants and network path
RandyNorthrup Sep 28, 2026
87383c7
Annotate the ACP agent's login spawn for SAST (PLAN.md section 8)
RandyNorthrup Sep 28, 2026
d2f9c13
Record the gate for PR #32 joined with main
RandyNorthrup Sep 28, 2026
83a4530
ACP agent: make the proxy limit loud and its advice its own (Q66)
RandyNorthrup Sep 28, 2026
6805972
Record the gate on the final tree with Q66
RandyNorthrup Sep 28, 2026
2cbb9ee
Merge main (PR #50: D49, D50, M67-M85) into PR #32
RandyNorthrup Sep 28, 2026
f8aa759
Merge PR #49 (CLI sign-in detection) into PR #32
RandyNorthrup Sep 28, 2026
99649cf
AGENTS.md rule 8: the OS credential store outside VS Code (D61)
RandyNorthrup Sep 28, 2026
e0ad04d
Fix what the pre-push review found in PR #32's integration
RandyNorthrup Sep 28, 2026
f8063b8
Merge PR #49's latest head (328efb5) into PR #32
RandyNorthrup Sep 28, 2026
13ee7d4
Merge PR #49's latest head (5184f26) into PR #32
RandyNorthrup Sep 28, 2026
0a34294
Record the gate on the final tree (13ee7d4)
RandyNorthrup Sep 28, 2026
a209130
Merge main (PR #49 merged, c42c4d5) into PR #32
RandyNorthrup Sep 28, 2026
7c0ff0c
Host checks: the fake CLI's credential in the captured sign-in shape
claude Sep 28, 2026
83833fe
ACP agent: the Codex review of a209130
claude Sep 28, 2026
4eb0156
Close Codex's four P1s on a209130 by class across the ACP agent
RandyNorthrup Sep 28, 2026
ca263c5
Close Codex's two findings on 4eb0156c by class in the ACP agent
RandyNorthrup Sep 28, 2026
496fdee
ACP agent: stop a reloaded session's turn before its replacement foll…
RandyNorthrup Sep 28, 2026
66faa3a
Merge remote-tracking branch 'origin/main' into integrate/pr32
RandyNorthrup Sep 28, 2026
46ba540
Stop a turn cancelled while starting once it exists; ignore stray can…
RandyNorthrup Sep 29, 2026
22f62ed
fix(acp): preserve session ownership and revoke paid grants safely
RandyNorthrup Sep 29, 2026
74f3c2c
test: canonicalize ACP grant fixtures across local platforms
RandyNorthrup Sep 29, 2026
34a5672
test: expand Windows short paths with native resolution
RandyNorthrup Sep 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 19 additions & 0 deletions .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -182,6 +182,25 @@ jobs:
name: muse-spark-code-vsix
path: '*.vsix'
if-no-files-found: error
# The ACP agent's npm package (M63, PLAN.md D62), from the same
# production build `npm run package` just ran.
- run: node scripts/package-acp.mjs
- name: the agent's package carries its bundles, tables, notices and manifest
run: |
listing="$(tar -tzf dist/muse-spark-code-acp-*.tgz)"
for entry in package/package.json package/dist/acp.js package/dist/searchWorker.js \
package/THIRD_PARTY_NOTICES.txt package/LICENSE package/README.md package/l10n/ui.de.json; do
if ! grep -qx "$entry" <<< "$listing"; then
echo "::error::$entry is missing from the agent's package" >&2
exit 1
fi
done
echo "the agent's package holds $(wc -l <<< "$listing") entries, the required ones included"
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: muse-spark-code-acp
path: dist/muse-spark-code-acp-*.tgz
if-no-files-found: error

secrets:
name: gitleaks
Expand Down
79 changes: 79 additions & 0 deletions .github/workflows/forks.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
# The VS Code forks that ship Linux builds (PLAN.md M62b): Cursor, Devin
# Desktop (Windsurf until 2026), Kiro and Positron, each at its latest
# release from its own update feed (test/hosts/fork-release.mjs). Each job
# installs the .vsix with the fork's CLI and runs the integration tests in
# the fork; the job summary names the fork's version and its VS Code base.
#
# Apart from hosts.yml because these are the forks' latest builds, not
# pinned ones, and their feeds can change without notice: every Monday, by
# hand, and on pull requests that change this check. Every job has a
# timeout and leaves no token in the git config; none pushes.
name: Forks

on:
pull_request:
paths:
- 'test/hosts/fork-release.mjs'
- 'test/hosts/installed.vscode-test.mjs'
- 'test/hosts/run-fork.sh'
- '.github/workflows/forks.yml'
schedule:
- cron: '41 6 * * 1'
workflow_dispatch:

permissions:
contents: read

concurrency:
group: forks-${{ github.ref }}
cancel-in-progress: true

jobs:
vsix:
name: vsix
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22
cache: npm
- run: npm ci
- run: npm run package
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: forks-vsix
path: '*.vsix'
if-no-files-found: error

fork:
name: ${{ matrix.fork }}
needs: vsix
runs-on: ubuntu-latest
timeout-minutes: 25
strategy:
fail-fast: false
matrix:
fork: [cursor, devin-desktop, kiro, positron]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22
cache: npm
- run: npm ci
- run: npm run build:dev
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: forks-vsix
path: forks-vsix
- name: ${{ matrix.fork }}
env:
# Positron's latest release is read from the GitHub API.
GH_TOKEN: ${{ github.token }}
run: xvfb-run -a sh test/hosts/run-fork.sh "${{ matrix.fork }}" forks-vsix/*.vsix "$RUNNER_TEMP/fork"
267 changes: 267 additions & 0 deletions .github/workflows/hosts.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,267 @@
# The host checks (PLAN.md M62, M63): the extension in the editors built on
# VS Code, and the ACP agent in the editors that speak ACP, each driven as
# docs/certification/m62.md and m63.md recorded it, against the fake Muse
# Code CLI (no model is called and no real key is used). Each job runs one
# script of test/hosts, the same script a local run uses.
#
# Pull requests and pushes to main that touch the product or these checks,
# every Monday (the hosts' own new releases), and by hand. Every job has a
# timeout and leaves no token in the git config; none pushes.
name: Hosts

on:
pull_request:
paths:
- 'src/**'
- 'l10n/**'
- 'package.json'
- 'package-lock.json'
- 'scripts/build.mjs'
- 'scripts/package-acp.mjs'
- 'test/e2e/**'
- 'test/hosts/**'
- 'test/integration/**'
- '.github/workflows/hosts.yml'
push:
branches: [main]
paths:
- 'src/**'
- 'l10n/**'
- 'package.json'
- 'package-lock.json'
- 'scripts/build.mjs'
- 'scripts/package-acp.mjs'
- 'test/e2e/**'
- 'test/hosts/**'
- 'test/integration/**'
- '.github/workflows/hosts.yml'
schedule:
- cron: '17 6 * * 1'
workflow_dispatch:

permissions:
contents: read

concurrency:
group: hosts-${{ github.ref }}
cancel-in-progress: true

jobs:
# The .vsix (without the macOS dictation helper, which no check here
# needs) and the agent's npm package, from one production build.
packages:
name: packages
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22
cache: npm
- run: npm ci
- run: npm run package
- run: node scripts/package-acp.mjs
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: hosts-vsix
path: '*.vsix'
if-no-files-found: error
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: hosts-acp
path: dist/muse-spark-code-acp-*.tgz
if-no-files-found: error

# The agent as npm installs it, on each platform: the stdio suite against
# the installed package (its own native keyring binding, no repository
# modules), then the key's round trip through the platform's credential
# store (D61).
agent:
name: agent package (${{ matrix.os }})
needs: packages
runs-on: ${{ matrix.os }}
timeout-minutes: 20
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, windows-latest, macos-latest]
defaults:
run:
shell: bash
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22
cache: npm
- run: npm ci
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: hosts-acp
path: hosts-acp
- run: npm install --global ./hosts-acp/muse-spark-code-acp-*.tgz
- name: the stdio suite against the installed package
run: MUSE_ACP_PACKAGE_DIR="$(npm root --global)/muse-spark-code-acp" npx vitest run test/e2e/acpStdio.e2e.test.ts
- name: the key through the Secret Service (linux)
if: runner.os == 'Linux'
run: |
sudo apt-get update -q
sudo apt-get install -y -q gnome-keyring
dbus-run-session -- sh -c 'printf "ci\n" | gnome-keyring-daemon --unlock --components=secrets > /dev/null && sh test/hosts/keystore.sh muse-spark-code-acp'
# A keychain of the job's own, unlocked, as the default: the runner's
# login keychain would ask a person to unlock it.
- name: the key through the Keychain (macos)
if: runner.os == 'macOS'
run: |
security create-keychain -p ci hosts.keychain
security list-keychains -d user -s hosts.keychain login.keychain
security default-keychain -d user -s hosts.keychain
security unlock-keychain -p ci hosts.keychain
security set-keychain-settings hosts.keychain
sh test/hosts/keystore.sh muse-spark-code-acp
- name: the key through Credential Manager (windows)
if: runner.os == 'Windows'
run: sh test/hosts/keystore.sh muse-spark-code-acp

# The integration tests in VSCodium: the floor's release and the latest.
vscodium:
name: VSCodium ${{ matrix.release }}
runs-on: ubuntu-latest
timeout-minutes: 20
strategy:
fail-fast: false
matrix:
release: ['1.99.32846', latest]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22
cache: npm
- run: npm ci
- run: npm run build:dev
- run: xvfb-run -a sh test/hosts/run-vscodium.sh "${{ matrix.release }}" "$RUNNER_TEMP/vscodium"

# The .vsix in code-server, the floor's release (VS Code 1.99.3, Node
# 20.18) and the latest, driven in Chrome.
code-server:
name: code-server ${{ matrix.release }}
needs: packages
runs-on: ubuntu-latest
timeout-minutes: 20
strategy:
fail-fast: false
matrix:
release: ['4.99.4', latest]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22
cache: npm
- run: npm ci
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: hosts-vsix
path: hosts-vsix
- name: code-server
env:
GH_TOKEN: ${{ github.token }}
RELEASE: ${{ matrix.release }}
run: |
version="$RELEASE"
if [ "$version" = latest ]; then
version="$(gh release view --repo coder/code-server --json tagName --jq .tagName | sed 's/^v//')"
fi
mkdir -p "$RUNNER_TEMP/code-server"
curl -fsSL "https://github.com/coder/code-server/releases/download/v$version/code-server-$version-linux-amd64.tar.gz" \
| tar -xz -C "$RUNNER_TEMP/code-server" --strip-components=1
- run: sh test/hosts/run-code-server.sh "$RUNNER_TEMP/code-server/bin/code-server" hosts-vsix/*.vsix "$RUNNER_TEMP/code-server-check"
- if: failure()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: code-server-${{ matrix.release }}-evidence
path: |
${{ runner.temp }}/code-server-check/shots
${{ runner.temp }}/code-server-check/code-server.log
${{ runner.temp }}/code-server-check/data/logs

# The .vsix in Eclipse Theia (test/hosts/theia/package.json), built from npm.
theia:
name: Eclipse Theia
needs: packages
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22
cache: npm
- run: npm ci
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: hosts-vsix
path: hosts-vsix
- run: sh test/hosts/run-theia.sh hosts-vsix/*.vsix "$RUNNER_TEMP/theia-check"
- if: failure()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: theia-evidence
path: |
${{ runner.temp }}/theia-check/shots
${{ runner.temp }}/theia-check/theia.log

# The agent in the ACP clients that install on Linux: JupyterLab (Jupyter
# AI), Emacs (acp.el, agent-shell) and Neovim (CodeCompanion).
acp-clients:
name: ACP client ${{ matrix.client }}
needs: packages
runs-on: ubuntu-latest
timeout-minutes: 20
strategy:
fail-fast: false
matrix:
client: [jupyter, emacs, neovim]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22
cache: npm
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
if: matrix.client == 'jupyter'
with:
python-version: '3.12'
- run: npm ci
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: hosts-acp
path: hosts-acp
- run: npm install --global ./hosts-acp/muse-spark-code-acp-*.tgz
- if: matrix.client == 'emacs'
run: |
sudo apt-get update -q
sudo apt-get install -y -q emacs-nox
- run: sh "test/hosts/run-${{ matrix.client }}.sh" "$(command -v muse-spark-code-acp)" "$RUNNER_TEMP/${{ matrix.client }}-check"
- if: failure()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ${{ matrix.client }}-evidence
path: |
${{ runner.temp }}/${{ matrix.client }}-check/shots
${{ runner.temp }}/${{ matrix.client }}-check/*.log
if-no-files-found: ignore
Loading
Loading