Skip to content

Draft: validate reproducible Windows build baseline - #356

Draft
coneilen wants to merge 347 commits into
mainfrom
win/tray-daemon-rebase
Draft

coneilen wants to merge 347 commits into
mainfrom
win/tray-daemon-rebase

Conversation

@coneilen

Copy link
Copy Markdown
Collaborator

Purpose

Establish a pull-request context so the Windows workflows can validate the reproducible Windows baseline on clean GitHub-hosted runners.

Current status

  • Windows baseline: 887f742
  • Exact Zig 0.15.2/0.16.0 and Swift 6.3.3 bootstrap
  • Public, commit-pinned Winghostty and zmx providers
  • Local Windows shell, daemon, UI Automation, packaging, and lifecycle validation passed

Not ready to merge

This branch is intentionally still based on the previously validated GraphCode v0.1.51 integration and is substantially divergent from current main. Current-main integration and its shared-Swift conflict resolution must be completed as a separate engineering tranche before this PR is made ready for review.

The immediate purpose of this draft is clean-runner validation of the Windows workflows.

coneilen and others added 30 commits August 15, 2026 19:49
Atomically replace live pane sessions, preserve retryable restores, scope layouts per project, and wire tab selection.

Signed-off-by: Copilot <223556219+Copilot@users.noreply.github.com>

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Preserve retry state, forward child tab keys, restore exact close topology, and use fixed-width project layout hashes.

Signed-off-by: Copilot <223556219+Copilot@users.noreply.github.com>

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Cancel stale retries on close and project switch, roll back topology mutations, and exercise live tab and split actions in provider smoke.

Signed-off-by: Copilot <223556219+Copilot@users.noreply.github.com>

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Prepare project layouts before swapping state, enforce live topology bijection, and isolate smoke persistence per run.

Signed-off-by: Copilot <223556219+Copilot@users.noreply.github.com>

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Preserve modal WM_QUIT behavior, validate settings before mutation, and share Zig-generated edge payload fixtures with Swift interop tests.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Resolve cleared settings to the complete default endpoint before mutation and byte-compare Swift interop fixtures against Zig-generated v2 envelopes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Treat an empty submitted support directory as a default-path request independent of the current environment override, and add regression coverage for invalid defaults.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
coneilen and others added 11 commits August 17, 2026 19:34
Signed-off-by: Colin Neilens <coneilen@microsoft.com>

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Colin's branch was based on 0.1.33 (8a09efa); main has moved 299 commits
since. Nine files conflicted, all shared Swift — the Zig/Win32 shell under
graphcode-windows/ merged untouched.

Conflicts resolved by keeping both sides' intent rather than either side
wholesale:

- FramedMessageIO: main's per-descriptor write serialisation stays on the
  descriptor path. Colin's stream transports hold the same invariant through
  a per-connection serial queue, so the lock table is scoped to descriptors.
- ProjectRegistry: main's sidebar join set and awake-assertion refresh
  reapplied on top of the channel-based connection table that replaced
  file descriptors, including joinSidebars.
- GraphStore: main's heartbeat-experiment gate expressed through Colin's
  reject(broadcastErrors:) form; drainPendingFollowUps kept.
- DaemonSocketClient: main's SO_NOSIGPIPE armour already exists in the
  UnixSocketByteStream that replaced the removed helper.
- ZmxSessionLauncher: the dial-log fragment is POSIX shell, so it stays on
  the POSIX branch; Windows ensures run unlogged rather than with a
  fragment quoted into something cmd.exe would not execute.

The branch had never been compiled by the Apple toolchain — the Windows
SwiftPM target excludes the SwiftUI app, graphcode/Tests, and DarwinMain.
Fixing that is what the rest of this commit is:

- Fold the Darwin daemon back into main.swift; only main.swift may carry
  top-level code, so a separate DarwinMain.swift built solely on Windows,
  where it is excluded.
- Carry main's SIGPIPE ignore, dispatch-source shutdown and per-socket
  SO_NOSIGPIPE into that Darwin daemon; it forked before those landed.
- Declare a macOS deployment target so SwiftPM stops assuming 10.13.
- ProcessRunner's Darwin branch: wait(2) status macros Swift does not
  import, optional-opaque-pointer spawn types, mutable argv/envp bindings,
  and a close(2) shadowed by ProcessPipe.close.
- Handle the quick-chat daemon commands and events Colin added to the
  shared enums in the macOS app's switches.

Known: OrchestratorClientTests.sendOnReplacementSocketWaitsForExactlyOneRejoin
hangs. Both the test and the code under test are byte-identical to Colin's
branch and are untouched by this merge — it is a latent defect surfaced by
compiling that target for the first time, not a merge regression.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ENhUter6PH8dc33XV2v2BC
None are merge regressions; all three are on the Windows branch and could
not have been caught there, because the Windows SwiftPM target excludes the
SwiftUI app and graphcode/Tests.

- Project path validation let the root through when spelled with `..`.
  `canonicalProjectPath` resolves symlinks before checking, and on macOS
  `standardizedFileURL` resolves `/tmp` first, so `/tmp/..` landed on
  `/private` — not the root, therefore accepted. The root check now also
  runs lexically, before any symlink resolution, which is the rule
  `isWellFormedProjectPath` had upstream. A project is scanned by the
  sweeper and by git, so opening one at `/` is the whole disk.

- The remote bridge-state installer could never run on any platform. Its
  embedded Python sat two columns deeper than the closing `"""`, so Swift
  handed `python3 -c` a program indented by two spaces and it died with
  IndentationError before reading a byte. Realigned the delimiter. Nothing
  else in the tree has the same mismatch.

Left failing, both pre-existing and untouched by the merge:

- OrchestratorClientTests.sendOnReplacementSocketWaitsForExactlyOneRejoin
  hangs waiting for a rejoin the client never sends.
- RemoteRepositoryTests.projectPathPercentEncodesSpecialUnicodeAndIPv6-
  Authorities: `projectPath` builds its URI through URLComponents, which
  rejects an unbracketed IPv6 host on Apple platforms and returns nil, so
  the unencoded fallback is used. Fixing it changes how a remote project's
  identity is spelled and persisted, so it wants a deliberate decision
  rather than a merge-time guess.

551 tests, 549 passing.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ENhUter6PH8dc33XV2v2BC
Bootstrap checksum-pinned Zig toolchains, Swift 6.3.3, and public detached provider revisions; make Windows workflows consume that setup; and complete the Windows SwiftPM source set and path portability.

Signed-off-by: Colin Neilens <coneilen@microsoft.com>

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@coneilen

Copy link
Copy Markdown
Collaborator Author

Clean-runner validation was dispatched after #357 registered the workflow paths on main.

Results:

  • Windows shell validation: failed during provider bootstrap
  • Windows port validation: failed during provider bootstrap
  • Full pinned hardening: failed during provider bootstrap
  • Deterministic hardening on windows-2022: passed
  • Deterministic hardening on windows-2025: passed

All three failures have the same root cause: graphcode-windows/provider-pins.json points at coneilen_microsoft/winghostty and coneilen_microsoft/zmx, which are private repositories. Anonymous clean runners cannot clone them. The public coneilen/winghostty and coneilen/zmx repositories do not contain the pinned SHAs; public Winghostty also lacks the required winghostty-win32-host build target, so changing only the URLs or using public main would not preserve functionality.

Least-privilege resolution options, in recommended order:

  1. Publish the exact provider revisions to public repositories and retain commit pinning.
  2. Publish immutable provider build artifacts with SHA-256 checksums and update the bootstrap to consume them.
  3. Configure an organization-managed, read-only Actions credential for both private provider repositories. This enables CI but does not make fresh external checkouts independently reproducible.

Runs: shell, port validation, hardening.

coneilen and others added 18 commits September 14, 2026 13:19
Publish the pinned Winghostty and zmx histories under the public coneilen repositories and update all provider metadata, contracts, and documentation to use them.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Use the commit-pinned Windows Swift setup action for Swift 6.3.3 so GitHub-hosted runners do not depend on WinGet being available.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Keep loop-summary formatting inside the portable domain source boundary and validate explicit daemon pipe syntax before machine-specific support-directory state.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Include the remote-project model required by platform contracts and explicitly skip physical tray input only in hosted CI, where no interactive Explorer desktop exists.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Validate rendezvous ACLs semantically while preserving protected current-user-only access, and tolerate short-lived daemon candidates during concurrent shell handoff.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Allow Windows to mark the sole protected current-user full-control ACE as inherited while continuing to reject unprotected DACLs, different permissions, and additional principals.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Accept canonical ACE inheritance and numeric full-control forms while retaining a protected DACL with exactly one current-user allow entry.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Include the canonical SDDL in validation failures so runner-specific ACL serialization remains diagnosable without weakening access checks.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Accept the local Administrator and Local System SDDL aliases only when they represent the expected current-user SID, while preserving the single protected full-control ACE requirement.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Make test coordination threads daemonized and assert every timed join completes so a passing unittest run cannot leave Python blocked during hosted validation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Run unittest through a dedicated entry point that rejects non-daemon thread leaks and exits after flushing results, and drain concurrent privacy-race child output to prevent redirected pipe stalls.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Use the deterministic Python runner during concurrent privacy checks, allow realistic scheduling margins, assert thread termination, and drain child output asynchronously to avoid redirected-pipe stalls.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Keep the privacy coexistence race meaningful while avoiding scheduler starvation on two-core hosted Windows runners.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Run one complete latency-sensitive remote suite alongside processor-scaled privacy scans, preserving the coexistence race without starving socket responses on four-core hosted runners.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Keep the deterministic Windows-to-POSIX fixture mandatory by default while allowing public Windows runners without a configured WSL distribution to skip only those local fixture cases.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Indent the conditional compilation body according to the pinned Swift formatter without changing daemon behavior.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Apply a bounded test-only timeout multiplier to the remote suite when it runs concurrently with privacy scans. Production defaults and the standalone strict suite remain unchanged.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Replace fixed terminal smoke timing with bounded attach readiness, retry broken attach clients, preserve persistent-history verification, and avoid zmx list during cleanup. Capture gate diagnostics without pipe-lifetime hangs and verify readiness/cleanup contracts.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants