Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
113 commits
Select commit Hold shift + click to select a range
9cab1ae
fix(start): report auxiliary listener failures without public-port re…
lidge-jun Sep 12, 2026
c597591
fix(start): retain degraded-listener evidence in salvage diagnostics
lidge-jun Sep 12, 2026
d95743b
test(config): activate routing-profile salvage in listener regression
lidge-jun Sep 12, 2026
dcd2d07
fix(search): retry clean empty answers without masking truncation
lidge-jun Sep 12, 2026
45f703f
test(search): narrow terminal fixture projection
lidge-jun Sep 12, 2026
3652da7
test(search): exercise live output truncation without duplicate replay
lidge-jun Sep 12, 2026
3bf0ae1
feat(remote): carry bounded executor and hub runtime adapters
lidge-jun Sep 12, 2026
59ec04b
fix(cursor): preserve first overflow and bound stable-thread remints
lidge-jun Sep 12, 2026
a318218
style(remote): remove trailing blank line in runner
lidge-jun Sep 12, 2026
b2d239e
fix: bound multipart encrypted agent task recovery
lidge-jun Sep 12, 2026
36625c7
test(cursor): activate remint guards after first overflow
lidge-jun Sep 12, 2026
a7b41aa
test: cover multipart boundary and input mutation cases
lidge-jun Sep 12, 2026
321b9b1
fix(live): validate sideband upstream before client upgrade
lidge-jun Sep 12, 2026
115e347
docs: synchronize shared V2 roadmap and review outcomes
lidge-jun Sep 12, 2026
d3b3b6d
feat(remote): integrate opt-in workspace dashboard and admission
lidge-jun Sep 12, 2026
3565b90
feat(usage): read connected hub usage within the enrolled client key
lidge-jun Sep 12, 2026
132403d
docs: place recovery contract away from shared append points
lidge-jun Sep 12, 2026
c9544c1
docs: separate sibling contract references in single-section owners
lidge-jun Sep 12, 2026
bf369d9
test(usage): ground account redaction and hub read deadlines
lidge-jun Sep 12, 2026
5c462fe
fix(remote): close startup cleanup races and preserve dashboard intent
lidge-jun Sep 12, 2026
e5ce931
fix(config): identify the actual malformed hub field in listener warn…
lidge-jun Sep 12, 2026
46f90d3
Merge latest dev and preserve sideband runtime contract
lidge-jun Sep 12, 2026
a1b8f96
fix(usage): restrict client-key transport and prevent response caching
lidge-jun Sep 12, 2026
7cccab3
fix(dashboard): guide hub pairing without restarting healthy clients
lidge-jun Sep 12, 2026
673ee8c
fix(openai-chat): normalize oversized inline images before serialization
lidge-jun Sep 12, 2026
b110d63
fix(openai-chat): retain synchronous under-budget image construction
lidge-jun Sep 12, 2026
1898bba
merge: reconcile current dev documentation for search recovery
lidge-jun Sep 12, 2026
14e93ca
merge: preserve current dev contracts for #4378
lidge-jun Sep 12, 2026
2be548a
merge: preserve current dev contracts for #4353
lidge-jun Sep 12, 2026
06fc280
Merge remote-tracking branch 'origin/dev' into codex/260912-finish-4363
lidge-jun Sep 12, 2026
eca7ce9
fix(cursor): preserve isolated recovery state and active cap retention
lidge-jun Sep 12, 2026
e2fc5ab
fix(remote): bound runtime admission and retain cleanup ownership
lidge-jun Sep 12, 2026
2056305
merge: carry refreshed usage foundation into client usage
lidge-jun Sep 12, 2026
379cf25
merge: carry runtime bounds while preserving integration shutdown han…
lidge-jun Sep 12, 2026
8cafec9
Merge remote-tracking branch 'origin/dev' into codex/260912-finish-4367
lidge-jun Sep 12, 2026
3ad908f
docs: synchronize live sideband handshake ownership
lidge-jun Sep 12, 2026
47d07d5
fix(remote): surface late resumed runtime cleanup failures
lidge-jun Sep 12, 2026
efb3936
fix(search): reject malformed truncated calls before replay
lidge-jun Sep 12, 2026
63bba2f
fix(remote): start owned socket cleanup before graceful drain
lidge-jun Sep 12, 2026
dbeade7
fix(remote): acknowledge prompt admission before model completion
lidge-jun Sep 12, 2026
4124a64
fix(dashboard): retain access errors across compound poll failures
lidge-jun Sep 12, 2026
4ad1d1c
fix(remote): align admission contracts and fallback session cursors
lidge-jun Sep 12, 2026
57b3057
docs: describe cancelled live sideband handshakes
lidge-jun Sep 12, 2026
52c8e8a
fix(pairing): use erasable types and explicit JSX event handlers
lidge-jun Sep 12, 2026
d1a922a
test(remote): repair admission fixtures and deferred cleanup assertions
lidge-jun Sep 12, 2026
3e73ca4
docs: record operations resume and remaining verification
lidge-jun Sep 12, 2026
36ab8cd
fix(opencode): separate local management catalog authority from infer…
lidge-jun Sep 12, 2026
535884e
docs: pin operations final verification and reconciliation scope
lidge-jun Sep 12, 2026
c5e9737
merge: reconcile listener candidate with the shared fixture repair ba…
lidge-jun Sep 12, 2026
eb409d0
merge: carry the verified usage foundation into the client usage tip
lidge-jun Sep 12, 2026
f67d4f0
merge: reconcile pairing candidate with the shared repair baseline
lidge-jun Sep 12, 2026
9b55626
test(remote): use portable subprocess fixtures on Windows
lidge-jun Sep 12, 2026
25c70d5
test(clients): retain bounded phase evidence for coordinator refusal …
lidge-jun Sep 12, 2026
c720dc5
test(clients): preserve spawn failures without captured stderr
lidge-jun Sep 12, 2026
31a96b2
docs(devlog): diff-level roadmap for the unimplemented trio stack (#4…
lidge-jun Sep 12, 2026
0268727
docs(devlog): fold wp1 audit findings into trio stack roadmap
lidge-jun Sep 12, 2026
2b533a5
docs(devlog): revalidate folded audit citations against source in wp1 B
lidge-jun Sep 12, 2026
da54017
docs(devlog): fold wp2 audit FAIL findings into L1 emission design
lidge-jun Sep 12, 2026
1893eec
docs(devlog): fold wp2 re-audit residual into L1 adoption points
lidge-jun Sep 12, 2026
923ca3c
feat(responses): persist content-free Codex WS upstream stage records…
lidge-jun Sep 12, 2026
07beb73
docs(structure): record the durable Codex WS stage record ownership (…
lidge-jun Sep 12, 2026
49dba44
fix(responses): refresh the WS stage record with final counters at te…
lidge-jun Sep 13, 2026
77dba07
docs(devlog): fold wp3 audit residual into L2 design
lidge-jun Sep 12, 2026
2c5022c
feat(codex): native-main device reauth API for headless hubs (#3898)
lidge-jun Sep 12, 2026
647e52f
feat(cli): ocx account main reauth --device with registry, docs, and …
lidge-jun Sep 12, 2026
4eed49e
fix(codex): close the cancel/commit race and fence the reauth commit …
lidge-jun Sep 12, 2026
584dadd
test(oauth): name the composite-signal proof and bound the fetch dead…
lidge-jun Sep 12, 2026
d666aef
test(codex): allow the transient cancelled read before publication wi…
lidge-jun Sep 13, 2026
4500ea0
docs(devlog): fold wp4 audit residual into L3 design
lidge-jun Sep 13, 2026
4d56932
fix(opencode-go): publish DeepSeek V4.1 context
martinbcg Sep 13, 2026
d111f8d
feat(gui): main-card Re-login with device code on the native reauth n…
lidge-jun Sep 13, 2026
7ab4cd4
merge: carry current dev into L1 WS stage instrumentation [skip ci]
lidge-jun Sep 13, 2026
e8ce186
merge: carry L1 WS stage instrumentation and current dev into L2 reau…
lidge-jun Sep 13, 2026
d420a46
merge: carry L2 reauth API and current dev into L3 main-card relogin …
lidge-jun Sep 13, 2026
247dc53
merge: carry the native-main trio and current dev into the remote run…
lidge-jun Sep 13, 2026
cf60fcc
merge: carry the refreshed remote runtime foundation into the integra…
lidge-jun Sep 13, 2026
a7514f2
merge: carry the remote/hub stack into the client-scoped usage tip
lidge-jun Sep 13, 2026
b4cc99e
[skip ci] chore(stack): merge origin/dev into codex/260912-60plus-str…
lidge-jun Sep 13, 2026
4f260b7
[skip ci] chore(stack): merge codex/260912-60plus-stream-search into …
lidge-jun Sep 13, 2026
37bc1a0
[skip ci] chore(stack): merge codex/260912-60plus-stream-cursor into …
lidge-jun Sep 13, 2026
c240534
[skip ci] chore(stack): merge codex/260912-60plus-stream-sideband int…
lidge-jun Sep 13, 2026
90667e5
[skip ci] chore(stack): merge codex/260912-60plus-models-images into …
lidge-jun Sep 13, 2026
00f8567
[skip ci] chore(stack): merge codex/260912-60plus-operations-pairing …
lidge-jun Sep 13, 2026
8acd73b
[skip ci] chore(stack): merge codex/260912-60plus-operations-transpor…
lidge-jun Sep 13, 2026
388c9d1
[skip ci] chore(stack): merge codex/260912-operations-client-probe in…
lidge-jun Sep 13, 2026
d7a3acc
chore(stack): merge codex/260912-60plus-operations-listeners into cod…
lidge-jun Sep 13, 2026
b324beb
test(gui): select the Re-login CTA by label and stop awaiting a pendi…
lidge-jun Sep 13, 2026
0c8d9d3
fix(gui): give the reauth poll loop an explicit abort condition [skip…
lidge-jun Sep 13, 2026
d2b0cb1
merge: carry the repaired native-main trio into the remote runtime fo…
lidge-jun Sep 13, 2026
ae79519
merge: carry the repaired runtime foundation into the integration lay…
lidge-jun Sep 13, 2026
6df609f
merge: carry the repaired remote/hub stack into the client-scoped usa…
lidge-jun Sep 13, 2026
81f58a4
merge: refresh the stack tip against current dev
lidge-jun Sep 13, 2026
ec29d80
merge: carry the refreshed #4357 usage-totals base into the client us…
lidge-jun Sep 13, 2026
f65b8eb
merge: carry current dev into L1 WS stage instrumentation [skip ci]
lidge-jun Sep 13, 2026
300ad2d
merge: carry L1 and current dev into L2 reauth API [skip ci]
lidge-jun Sep 13, 2026
d42d873
merge: carry L2 and current dev into L3 main-card relogin UI [skip ci]
lidge-jun Sep 13, 2026
0c4f962
merge: carry the native-main trio and current dev into the remote run…
lidge-jun Sep 13, 2026
19601ea
merge: carry the refreshed runtime foundation into the integration la…
lidge-jun Sep 13, 2026
c20abd0
chore(stack): merge origin/dev into codex/260912-60plus-v2-recovery
lidge-jun Sep 13, 2026
7874900
merge: carry the refreshed remote/hub stack into the client-scoped us…
lidge-jun Sep 13, 2026
4a252f5
fix: keep stacked live handshake with audio sideband and unbreak cata…
lidge-jun Sep 13, 2026
b32df5f
docs: capture stacked hub pairing panel for the tip PR screenshot gate
lidge-jun Sep 13, 2026
5eb6e73
docs(devlog): capture the Remote Workspace hub dashboard for the stac…
lidge-jun Sep 13, 2026
c4e5f20
fix: plant sidecar fixture and drop Bun HTTP_PROXY catalog control
lidge-jun Sep 13, 2026
f059251
chore(stack): merge origin/dev into codex/260912-60plus-v2-recovery
lidge-jun Sep 13, 2026
d2a7dc0
merge: refresh the stack tip against current dev
lidge-jun Sep 13, 2026
c9b73a4
merge: carry the refreshed #4357 usage-totals base into the client us…
lidge-jun Sep 13, 2026
0a96f88
Merge pull request #4440 from martinbcg/fix/opencode-go-deepseek-v41-…
lidge-jun Sep 13, 2026
2ba5a54
fix(gui): check reauth response status before reading its body
lidge-jun Sep 13, 2026
beb2e12
merge: refresh the stack tip against current dev
lidge-jun Sep 13, 2026
2c2223b
Merge pull request #4364 from lidge-jun/codex/260912-60plus-v2-recovery
lidge-jun Sep 13, 2026
7d280d6
test(server): stop reading a pure delegation guard as an unresolved r…
lidge-jun Sep 13, 2026
8ccd80d
merge: refresh the stack tip against current dev
lidge-jun Sep 13, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -66,3 +66,6 @@ tests/**/.tmp-*
# `git add` three separate times and reached `dev` once — see
# tests/ci-workflows/repo-hygiene.test.ts, which fails if any path here becomes tracked again.
go/

# Rust native helpers keep their reproducible sources and lockfile in git, never local artifacts.
native/**/target/
1 change: 1 addition & 0 deletions .npmignore
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@ gui/eslint.config.*
gui/bun.lock

# misc
native/remote-workspace-helper/target/
*.test.ts
*.map
.DS_Store
2 changes: 2 additions & 0 deletions devlog/_plan/260912_operations/020_listeners.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,3 +11,5 @@ MODIFY existing tests/server/ports.test.ts and tests/server/loopback-listener-in
MODIFY directly relevant structure/runtime.md, structure/config.md, structure/ops/service-and-sidecars.md and public hub/loopback guidance; link the canonical contract from other mapped ownership docs only where applicable. Review all conditional activation rows on hosted CI. Source inspection is not runtime proof.

Design OPS-LIST-01..04 accepted with amendments. NEW tests/cli/cli-start-auxiliary-bind.test.ts, registered in both test-layout files, uses isolated CLI subprocess to cover soft and hard-pinned startup: failure names auxiliary key/address, exit nonzero, no public repick/wait branch. Existing management rollback fixture occupies management first then selects distinct public/loopback ports. Warning helper runs on all three load return paths plus read-only diagnostics; controls cover absent and valid-disabled entries and malformed secret-shaped input without echoing raw values.

Follow-up090 validates raw managementIngress against the existing shared strict managementIngressSchema; disappearance of the entire hub block is not evidence that the ingress itself was malformed.
18 changes: 17 additions & 1 deletion devlog/_plan/260912_operations/040_client_usage.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,22 @@ MODIFY existing client/hub API owner only where the read contract requires it; e

MODIFY public connected-client/CLI usage guide and structure/runtime.md / gui-and-management-api.md canonical scope. Any pre-disclosure details stay in scratch. Hosted regressions only; local execution NOT RUN.

Accepted design OPS-USAGE-02/03/04. NEW tests/server/hub-usage.test.ts and tests/clients/hub-usage.test.ts with entries in scripts/test-layout/layout.json explicit and tests/fixtures/test-layout-expected.json; NEW tests/cli/cli-usage-hub.test.ts. Tests use two client keys, loopback and remote admissions, invalid state, custom window, unsupported endpoint, bad response, expired/revoked credentials. Full implementation follows source confirmation before B.
Accepted design OPS-USAGE-02/03/04. NEW tests/server/hub-usage.test.ts and tests/clients/client-hub-usage.test.ts with entries in scripts/test-layout/layout.json explicit and tests/fixtures/test-layout-expected.json; NEW tests/cli/cli-usage-hub.test.ts. Tests use two client keys, loopback and remote admissions, invalid state, custom window, unsupported endpoint, bad response, expired/revoked credentials. Full implementation follows source confirmation before B.

Reflection amendments: getFilteredUsageAggregate in src/server/management/usage-aggregate-cache.ts is the aggregation owner. Client DTO preserves #4111 incomplete flags; CLI suppresses advice to remove filters for account totals because that scope never exports accounts. Public files: docs-site/src/content/docs/guides/remote-hub.md and reference/cli/agents.md. All three new tests register in scripts/test-layout/layout.json and tests/fixtures/test-layout-expected.json.

P revalidation after totals28c13d0c09: this slice depends on its usageIncomplete aggregate contract, so publish an ordinary child PR based on operations-totals. Retire4343 review follow-up was prioritized by explicit user steering; it is now source-reviewed and resolved.

Concrete DTO: version1/source hub/scope client; range/surface/since/until/customWindow/generatedAt, numeric summary fields consumed by CLI, provider/model/day cost rows, and provider/model/matched/comboOverlap filter echo. No accounts, raw entries, apiKeyId or arbitrary spread fields cross the wire. NEW remote/hub-usage.ts owns a stripping Zod schema, capped arrays/string sizes and1MiB response bound; server projects through it and client parses through it. Incomplete flags retain positive-only semantics. No persistence or cache on client. Existing getFilteredUsageAggregate owns server cache keyed by authenticated key; no route-global cache.

Handler accepts GET/v1/usage only, requires dedicated data key and configured admission even for loopback; no management/API env key. Reject unknown or duplicate query keys, caller apiKeyId, invalid range/surface/window, and noncanonical (blank/padded) authenticated key IDs before aggregation because the existing filtered cache trims IDs. Check origin and hub role. Recheck matched current credential/key identity after awaited scan before returning; revocation/rotation changes cannot publish a stale authority response. Serialize bounded allowlist DTO or explicit error, never a partial silent result.

CLI reads connection state and matching service token fingerprint, sends only data credential to configured serverUrl via existing fetchBounded/boundedText helpers, retains redirect refusal and deadlines. Invalid/mismatched connection/token fails with no local fallback. Confirm owner remains the same after the read before printing. Human header names hub source/client scope and suppresses account-total advice; standalone runtimeRequest remains unchanged.

Hosted tests: actual server two keysA/B and loopback auth; caller keyID rejected; absent/environment/admin/bad keys rejected; unknown/duplicate params and invalid window; provider filters/custom window; malformed response/too-large/redirect/oldHub/offline; CLI connected versus standalone and token mismatch. Test paths in this doc register in both layout files. No local tests. Unpublished security analysis remains .tmp/operations/040_client_usage_private.md.

Reflection closure: post-read CLI validates both owner triple AND current connection/file token fingerprints; sameClientConnectionOwner alone omits fingerprint. Every nested DTO object strips unknown fields; the1MiB check uses serialized UTF-8 bytes in addition to array/string caps.

B scope refinement: reuse resolveDataPlaneAdmissionSecret directly; no resolver logic change necessary; auth-cors.ts AUTH_MATRIX gets the new endpoint row and tests/server/api-key-attribution.test.ts drives its real GET cells. Client test basename is client-hub-usage.test.ts to avoid the registry basename collision with server/hub-usage.test.ts.

Follow-up100: new fetchHubUsage requires HTTPS or supported loopback HTTP before credential headers, uses request cache:no-store, and retains server cache-control:no-store.
20 changes: 19 additions & 1 deletion devlog/_plan/260912_operations/050_pairing.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,10 +4,28 @@ Class C3; dependency roadmap. Reuse existing connected-client state and browser-

MODIFY owning dashboard pending-auth component and bootstrap state: distinguish a reachable connected machine awaiting hub browser authentication from a stopped standalone proxy. Show configured hub identity/origin, explain that machine enrollment and browser session are separate, offer the current origin-specific existing pairing/authentication action. Preserve revoked/expired/unreachable states and their existing retry actions; do not suggest ocx start while the local runtime is reachable. Derive the next action from current origin + configured hub instead of a hardcoded localhost URL. No credentials appear in visible copy/URLs.

MODIFY all gui/src/i18n locale dictionaries with meaningful labels. Extend existing pending-auth/dashboard tests for local origin, remote hub origin, pending, authenticated, expired/revoked and unavailable standalone; positive browser auth transitions into connected dashboard. Exact files: gui/src/App.tsx, api.ts, pages/dashboard-core-poll.ts, pages/use-dashboard-data.ts and pages/Dashboard.tsx consume a classified authentication/error state instead of a boolean. Existing connect-pairing.ts and connect-pairing-transport.ts own hub identity and origin-specific action. Define the error classification in api.ts at response ingress; consume in polling and Dashboard; reset on authenticated success and pairing completion. No persistence/serialization for this UI state. Keep cached data with stale labeling when auth fails; do not erase a known hub into standalone offline. Public hub/browser-pairing guidance is updated with the same distinction. No service restart or live auth reconfiguration.
MODIFY all gui/src/i18n locale dictionaries with meaningful labels. Extend existing pending-auth/dashboard tests for local origin, remote hub origin, pending, authenticated, expired/revoked and unavailable standalone; positive browser auth transitions into connected dashboard. Exact files: gui/src/App.tsx, api.ts, pages/dashboard-core-poll.ts, pages/use-dashboard-data.ts and pages/Dashboard.tsx consume a classified authentication/error state instead of a boolean. Existing connect-pairing.tsx and connect-pairing-transport.ts own hub identity and origin-specific action. Define the error classification in api.ts at response ingress; consume in polling and Dashboard; reset on authenticated success and pairing completion. No persistence/serialization for this UI state. Keep cached data with stale labeling on non-auth read failures; hide it when authentication or permission is denied; do not erase a known hub into standalone offline. Public hub/browser-pairing guidance is updated with the same distinction. No service restart or live auth reconfiguration.

Hosted component suite and screenshot artifact of the rendered pending state required for final delivery; local GUI tests/build NOT RUN. Static source or mockup is not rendered application evidence.

Accepted OPS-PAIR-01/02. Cases include browser session expiry and post-pairing refresh, local and hub origin guidance, code versus API/admin-key explanation, and operator handoff text. Prefer existing component tests; new test files only where needed.

Reflection amendments: reuse existing api.ts SESSION_UNAVAILABLE_EVENT and App sharedSessionReady; subscribe in App, emit on terminal 401 expiry (not aborted requests), reset/read refresh on successful pairing. Do not create duplicate auth state. Poll classification and pairing errors distinguish HTTP auth refusal, transport/network, and invalid responses; aborted work does not show a failure.

P revalidation at81f0c78d7a: same App, Dashboard, pairing and API owners remain. This independent branch starts from refresheddev; previous usage-transportD directs pairing after the user-requested source repairs.

Concrete delta: App subscribes to SESSION_UNAVAILABLE_EVENT for the shared plane and derives readiness from hasApiSession; ignore a late notice while a newer session is present. Pairing success increments a dashboard refresh epoch and marks ready. Pass connected/authenticationPending into Dashboard. Hide protected dashboard content while authentication is pending; keep known data with a stale notice only on non-auth read failures. In fetchDashboardOverview distinguish 401(auth), 403(denied), other non-OK(request), invalid JSON/shape(invalid), and transport failure(unavailable); aborted polls propagate without publishing an error. Hook exposes failure and overview refresh without a second authentication store. Only standalone transport unavailability may show ocx start; connected/auth/invalid/request failures use relevant copy and retry.

API wrapper emits its existing unavailable event on terminal401 only when the caller is not aborted and no newer session exists. Retain credential refresh/singleflight behavior; no new auth bypass or token persistence. Dashboard receives success epoch as a prop; useDashboardData adds it to existing useKeyedClientResource revalidation dependencies without changing resource keys or remounting. Every dashboard resource refreshes even when a settled failed/cached store survived.

Pairing form shows target.serverOrigin, a copyable ocx gui pair --origin command for window.location.origin, instructions to run it on the hub or ask its operator, and the distinction between one-time code and API/admin keys. Reuse useCopyFeedback and existing copy labels; copy failure remains visible. Keep relay technical copy subordinate. Pairing transport gets a typed error kind (invalid-code/refused/unreachable/invalid-response), mapped to localized actionable copy while preserving pasted code; abort does not publish an error. This is process-local UI state, not a wire schema.

Exact regressions: extend gui/tests/connect-pairing.test.ts for real App dashboard pending/authsuccess/expiry/recovery and hub/command identity; extend api-auth-deadline.test.ts for terminal notice behavior if needed; NEW gui/tests/dashboard-connection-state.test.ts for poll failure classes, cached data and no erroneous start advice. All9 locale modules get new copy. Existing Notice/buttons/tokens, variance2/motion1, dense utility layout; no decorative assets or new dependencies. Hosted built preview, inspected screenshot and browser interaction supply rendered proof later; local suites/build NOT RUN.

Pairing lifetime precision: form keyed by target server/bootstrap identity, one AbortController per submit cancelled on unmount; transport accepts optional caller signal in addition to its existing fetch seam and checks abort before session installation. This prevents an obsolete target response from installing a session or publishing errors after its form unmounts. Keep existing request method/credential mechanics unchanged.

A amendment: post-pairing refresh explicitly reaches each dashboard keyed resource through [apiBase, refreshEpoch] dependencies; a component remount is not treated as a cache invalidation mechanism. Regression first seeds a failed overview store, completes pairing, and requires a new authenticated health/provider read plus rendered data.

Reflection03/05 closure:403 keeps distinct permission-denied guidance and never starts or re-pairs a running proxy merely for denied permissions. Validate HealthData status/version strings and finite nonnegative uptime; providers must be an array of objects with the required name/adapter/baseUrl strings and hasApiKey boolean, optional defaultModel string. Invalid shapes are classified invalid even with HTTP200. Unauthorized/denied content stays hidden; only nonauth read failure may show cached data with stale notice.

Resume C repairs: hosted34682559994 found erasableSyntaxOnly constructor parameter-property and React ref analysis at createElement form. Explicit class field and JSX component preserve behavior without disabling rules. Source compound-failure repair was already published externally at4124a644; local byte-identical patch preserved before fast-forward. Hidden-document App fixture disables periodic polls, and a controlled real resource deadline verifies retained data becomes stale. All local suites/build/typecheck/install NOT RUN.
2 changes: 2 additions & 0 deletions devlog/_plan/260912_operations/060_transport.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,3 +5,5 @@ Class C4; dependency roadmap. Scope #4315 and the current CHANGES_REQUESTED revi
The executable security design and negative-case audit live only in ignored .tmp/operations/060_transport_private.md. That file must be completed and independently reviewed before B; no pre-disclosure reasoning is copied into public planning history. Public deliverable is the implementation, regression tests and shipped contract text only. Required review dimensions: local destination selection, redirect and proxy-environment behavior, credential separation and all current callers. Original contributor credit: Cortes Ventures <admin@cortesventures.com>. No fallback that substitutes a data credential for admin authentication.

Hosted regression execution plus independent security source audit bind the final patch SHA. Review state is refreshed before handoff; this work cannot approve or merge the original PR. Local suites/build/typecheck/install NOT RUN.

P resume revalidation at c311f9bf7f5003af29fa8e7ebc2f2b5db20267f6: original4317 still CHANGES_REQUESTED, helper and sole productioncaller unchanged. Prior pairingD directs this independent slice. Reuse direct-local-http transport and local-destinations resolver; private060 contains exact diff contract and controls. No new dependencies, service changes or fallback settings. Existing8s deadline retained. New tests/providers/opencode-management-transport.test.ts isolates real socket/proxy/redirect controls and registers in both test-layout maps. Existing opencode-cli caller test changes transport spy and checks distinct management/inference credentials and generated blocks.
6 changes: 6 additions & 0 deletions devlog/_plan/260912_operations/070_verification.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,3 +7,9 @@ For each independently mergeable branch: record git rev-parse HEAD, original sou
A local receipt may run git diff --check and read-only hosted-result assertions; it is not a local test result. Local suites, typecheck/build/install are NOT RUN. Final behavior acceptance comes from GitHub-hosted test runs at the final SHA and independent review; author reports/old green CI are not substituted.

Update ignored .tmp/operations/handoff.md as soon as each artifact exists. Include outstanding issue acceptance, original author trailers, unresolved maintainer objections, exact run links/conclusions and cycle ledger pointers. Publish template-complete PR bodies with truthful verification, screenshots for changed dashboard UI and no private investigation notes. Parent owns all integration decisions.

P resume amendment: reconcile at pinned origin/dev db7062c37a84b12c4f59abc567d07241bf2a6042, which includes separately owned Cline/native-restore fixture repairs. No repeated rewrites. Fast-forward local lane refs to parent-published remote heads before edits; merge the pinned baseline into owned feature branches only where needed to incorporate failed-check repairs/conflicts. Never move dev/main/preview or merge PRs. Preserve shared changes and resolve only operations-owned conflicts; record any cross-lane source collision for parent.

Listener4353 also has a documentation-only review requiring the plan to describe reuse of the already-existing managementIngressSchema. Correct020/090 wording, do not duplicate a schema. Totals4357 consumes baseline then child4373 receives that exact lower head; verify ancestry and original source patch parity. Pairing4378 incorporates baseline only once and retains all source repairs. Transport4402 is already based on repaireddev; do not rewrite its unchanged candidate for unrelated later commits.

Final requested gate is hosted laneall on listener, cumulative usage child, pairing, and transport. Inspect live job outcomes and exacthead. New failures inside this lane become separately audited repaircycles; external owner failures are recorded without duplicate edits or baselinegreen claims. Read build artifacts from hosted GUI jobs, serve only those static files with fixture responses in isolated scratch for screenshot/interaction review, no product build/test/server locally. This is render observation, not a local suite. No liveuser service/config changes.
7 changes: 7 additions & 0 deletions devlog/_plan/260912_operations/090_listener_diagnostic.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# Precise ingress degradation diagnosis

User intake4353 discussion3995160105. P amendment reprioritizes a source review repair before pairing; pairing source was not changed. Class C2, satisfy-spec, same tool/write bounds and no resource cap; no local suite/build/typecheck/install, no merges/services. Final behavior proof is hosted CI.

Valid managementIngress is currently blamed when an invalid sibling makes the whole hub parse disappear. MODIFY src/config.ts: reuse the existing private managementIngressSchema in hubConfigSchema and raw-field validation; test the raw ingress with that same strict schema before issuing its field-specific warning. Do not change normalization, acceptance, port relationship validation, or whole-hub warnings. Rawvalues never printed.

MODIFY tests/config/config-load-degrade.test.ts: valid ingress plus invalid dataPublicOrigin must warn about the actual hub sibling and not claim managementIngress invalid; preserve file bytes. Existing malformed-ingress cases still warn. Update020 and structure/config.md canonical wording. Independent source re-audit then authorized comment reply/resolution; hosted criterion remainsOPEN.
Loading
Loading