Parent tracking issue: #141. Phase 11 of 11.
Objective
Validate the complete flow against two Windows targets and the separately declared controller platform matrix.
Scope
Record exact commit, connector/protocol/Codex versions and sanitized evidence per controller OS, target Windows version, session type and mode. Two Windows targets validate multi-host operation, not Windows/Linux controller support. Keep every platform claim gated by native build, vault, IPC and rendered Wails window evidence from #144/#148/#149. Compare the shared SwiftUI-style layout, navigation, states and accessibility on macOS, Windows and Linux while recording intentional OS differences.
On two authorized PCs exercise new visible chat, continued visible chat, hidden ephemeral execution, password and encrypted-key auth where configured, installation/update/rollback, selected-host diagnostics, complete prompt/result history and logs. Verify the hidden chat does not appear in the app and document connector/provider retention. Rendered evidence must use permitted observation methods; if the tool forbids automating Codex's own UI, use supported client evidence or explicit human observation and leave any unobserved claim unverified.
Test unknown/changed host keys, wrong Windows user/session, alias duplicates, two-controller contention, two independent PCs, disabled/locked vault, audit failure after dispatch, history beyond ten turns, connection loss at submit, process/controller restart, wait expiry and unconfirmed cancellation. Use harmless controlled tasks and preserve existing PC work. Export only redacted evidence; include a support matrix, installation/bootstrap guide and recovery procedure.
This issue validates source already delivered by child PRs; if acceptance identifies code changes, keep fixes scoped to an appropriate child/follow-up issue with exact revision evidence. Do not close #141 until every required acceptance row is observed or the user explicitly changes scope.
All three controller families requested by the user are required acceptance rows. Verify #155 completion/failure and needs-attention notices with the window closed, notification permission denied and a sanitized activation path on each claimed OS. Include an action-capable Linux session and separately verify the no-actions fallback, expired-alert handling and deleted/locked request activation; logout or controller stop does not promise immediate delivery. Verify local SSH config/vault/history scope; #154 is a separate optional sync extension, and #152/#153 are later target connectors. Specify tested OS version, CPU, Linux distribution/session and Wails/WebView versions. A row without a usable graphical session, native vault or rendered evidence remains incomplete. Test real WebView storage for synthetic prompt/secret sentinels, equal-size light/dark and scaling fixtures, framework bridge restrictions, packaged app install/upgrade/uninstall, and close/Quit UI/sleep/logout recovery. Source merges may precede these operational gates; the epic cannot close on a subset of controller families.
Acceptance criteria
Validation and evidence level
Client-real/provider-real evidence tied to the tested SHA and full relevant local/CI gates. Keep deployment and installation records separate from merge.
Dependencies and risks
Depends on #142, #143, #144, #145, #146, #147, #148, #149, #151, #155.
Out of scope
Unattended fleet rollout, restoring the retired native agent architecture or unapproved destructive acceptance tasks.
Delivery boundary
Parent #141 defines the shared product contract. This issue owns one reviewable change and its own validation; do not close the parent from its PR. Keep source implementation, automated checks, installation and observed client behavior distinct. No secrets, real prompts, account identifiers or unredacted device logs belong in GitHub evidence.
Parent tracking issue: #141. Phase 11 of 11.
Objective
Validate the complete flow against two Windows targets and the separately declared controller platform matrix.
Scope
Record exact commit, connector/protocol/Codex versions and sanitized evidence per controller OS, target Windows version, session type and mode. Two Windows targets validate multi-host operation, not Windows/Linux controller support. Keep every platform claim gated by native build, vault, IPC and rendered Wails window evidence from #144/#148/#149. Compare the shared SwiftUI-style layout, navigation, states and accessibility on macOS, Windows and Linux while recording intentional OS differences.
On two authorized PCs exercise new visible chat, continued visible chat, hidden ephemeral execution, password and encrypted-key auth where configured, installation/update/rollback, selected-host diagnostics, complete prompt/result history and logs. Verify the hidden chat does not appear in the app and document connector/provider retention. Rendered evidence must use permitted observation methods; if the tool forbids automating Codex's own UI, use supported client evidence or explicit human observation and leave any unobserved claim unverified.
Test unknown/changed host keys, wrong Windows user/session, alias duplicates, two-controller contention, two independent PCs, disabled/locked vault, audit failure after dispatch, history beyond ten turns, connection loss at submit, process/controller restart, wait expiry and unconfirmed cancellation. Use harmless controlled tasks and preserve existing PC work. Export only redacted evidence; include a support matrix, installation/bootstrap guide and recovery procedure.
This issue validates source already delivered by child PRs; if acceptance identifies code changes, keep fixes scoped to an appropriate child/follow-up issue with exact revision evidence. Do not close #141 until every required acceptance row is observed or the user explicitly changes scope.
All three controller families requested by the user are required acceptance rows. Verify #155 completion/failure and needs-attention notices with the window closed, notification permission denied and a sanitized activation path on each claimed OS. Include an action-capable Linux session and separately verify the no-actions fallback, expired-alert handling and deleted/locked request activation; logout or controller stop does not promise immediate delivery. Verify local SSH config/vault/history scope; #154 is a separate optional sync extension, and #152/#153 are later target connectors. Specify tested OS version, CPU, Linux distribution/session and Wails/WebView versions. A row without a usable graphical session, native vault or rendered evidence remains incomplete. Test real WebView storage for synthetic prompt/secret sentinels, equal-size light/dark and scaling fixtures, framework bridge restrictions, packaged app install/upgrade/uninstall, and close/Quit UI/sleep/logout recovery. Source merges may precede these operational gates; the epic cannot close on a subset of controller families.
Acceptance criteria
Validation and evidence level
Client-real/provider-real evidence tied to the tested SHA and full relevant local/CI gates. Keep deployment and installation records separate from merge.
Dependencies and risks
Depends on #142, #143, #144, #145, #146, #147, #148, #149, #151, #155.
Out of scope
Unattended fleet rollout, restoring the retired native agent architecture or unapproved destructive acceptance tasks.
Delivery boundary
Parent #141 defines the shared product contract. This issue owns one reviewable change and its own validation; do not close the parent from its PR. Keep source implementation, automated checks, installation and observed client behavior distinct. No secrets, real prompts, account identifiers or unredacted device logs belong in GitHub evidence.