Skip to content

chore(ci): DRAFT VALIDATION ONLY—DO NOT MERGE runtime configuration integration - #7456

Draft
loganj wants to merge 48 commits into
mainfrom
validation/runtime-config-integration-411ec2f0
Draft

chore(ci): DRAFT VALIDATION ONLY—DO NOT MERGE runtime configuration integration#7456
loganj wants to merge 48 commits into
mainfrom
validation/runtime-config-integration-411ec2f0

Conversation

@loganj

@loganj loganj commented Sep 7, 2026

Copy link
Copy Markdown
Collaborator

DRAFT VALIDATION ONLY—DO NOT MERGE

This specifically authorized CI-only draft exercises existing normal pull_request CI for one integrated runtime-configuration candidate. It includes the unmerged Multiverse stack plus current integration, not proposed review boundaries. It is not review-ready, security approval, a size waiver, or a merge request. Preserve the existing stack PRs/branches; do not merge this artifact.

Related existing stack: #7330, #7331, #7333, #7343#7347, #7350#7355, #7363#7365. This is a distinct validation artifact, not a replacement for those PRs.

  • Initial candidate: 68a9190121f1b71cf928d546439097b95deee629
  • Initial tree: 949e8871916aed4efd4a93c9cd675064e7816d33
  • Supported CI base: main (observed 3c7f288c60d67df78577b237e27c3dfc8831aaa1)
  • Full main comparison: 146 files, +16,147/-1,112 = 17,259 gross lines, including existing unmerged stack.
  • Feature-only comparison against 76fb1e66287b186b54b09e5b73bbd45e3bd7a551: 79 files, +6,062/-1,018 = 7,080 gross. 7,080 is NOT the total PR diff.

Evidence and remaining gates

Before this PR, zero actual native/core/ACP compilation or native cases executed. Existing local dependency gaps were not worked around with installs or credential changes; this PR requests the repository's normal native CI route, not new infrastructure or weaker checks.

Previous frontend proof is scoped to this exact initial head by byte-identity evidence: 6,313 frontend passes; 36 focused cases are a subset, not extra; TypeScript/Biome, root+nested fmt, file-size gate and 10 policy checks pass. No unchanged local rerun claimed. Durable local receipt: WORK_LOGS/MULTIVERSE_IMPLEMENTATION/INTEGRATION_411EC2F0/RECEIPT.md.

Initial head is pre-policy: a separately owned approved destination-local credential-reuse/eligibility delta is pending integration. Only already-provisioned matching local agent keys make a host eligible; no Buzz key transfer/provisioning. Frozen initial CI is useful but not final remote-launch acceptance. Positive/negative real native receiver fixtures, exact-head native/ACP results, focused independent review of recent preflight/recovery/policy changes, and live acceptance remain necessary. Native Running is not model readiness; no successful two-Mac Move is claimed.

Task provenance

Buzz channel: f45d3304-dcf0-44e8-a46d-bcd63b235fbc

Task: buzz://message?channel=f45d3304-dcf0-44e8-a46d-bcd63b235fbc&id=b3300e185a1275f927c30c88832e3f5563fe8111de3c7cecb11c77c0aea22232

Publication authorized as CI-only draft, not approval of this cumulative merge unit. No merges or existing stack rewrite authorized.

Recovered post-policy validation refresh

The same disposable validation branch was rebased onto current main 3c7f288c60d67df78577b237e27c3dfc8831aaa1; all 42 existing integration commits remained patch-equivalent. Destination-local credential policy and bounded native compiler fixes are now integrated exactly once. Original stack, producer and consumer refs remain preserved.

  • Current source/published head: 007035a09f0639aa041f054c327b01932053fbe3
  • Source tree: cdc14e5b692279387c8bc83c73b77aafb76a9d8e
  • Full refreshed PR: 148 files, +16,663/-1,138 = 17,801 gross lines; still NOT a proposed review unit or size waiver.
  • CI: https://github.com/block/buzz/actions/runs/34154316140 (normal PR event, pending).
  • Main-only ACP idle fixture retains its regression with require_model:false. Existing Linux Desktop Core job gains one explicitly authorized no-default-features cargo invocation for the seven isolated remote credential fixtures; full tests remain unchanged.
  • Root/nested formatting, workflow actionlint, actual size gate plus 10 policy tests pass locally. Native tests remain pending CI; no local dependency or credential workaround.

Initial pre-policy evidence above remains historical, not the final candidate result. No real-keyring, model-ready, independent final-review, or two-Desktop acceptance claim.

@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

🔐 Codex Security Review

Status: review required for the current range.

The current range is 3c7f288c60d67df78577b237e27c3dfc8831aaa1...98f96356ca08bf692d0654eb5f04ec85735107fc.
A new review must complete for this exact range. When manual authorization
is required, a Block organization member must comment exactly
@buzz-security-review 98f96356ca08bf692d0654eb5f04ec85735107fc to authorize a new review.
Any previous review applies only to its recorded range.

Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Keep exact-request retry owner/community private without repeating relay side effects. Exclude request/result ciphertext from search on fresh and upgraded databases.

Signed-off-by: Logan Johnson <loganj@squareup.com>
Bind explicit Start permission before preflight and release it only after child registration. Reuse ordinary platform-specific pair Stop and refuse success for an unscoped live legacy child.

Signed-off-by: Logan Johnson <loganj@squareup.com>
Bind owner delegation, installation, agent and community before ordinary Stop. Persist admission before effects and retain exact signed outcomes for retries across reopening and bounded eviction.

Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
…n CI

Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
…eceipts

Signed-off-by: Logan Johnson <loganj@squareup.com>
Local integration checkpoint; native compilation and strict ACP model enforcement remain validation gates. Scope and async prepared-launch APIs are stable for lifecycle integration; not publication-ready.

Signed-off-by: Logan Johnson <loganj@squareup.com>
Integrate ACP strict model verification with the named native caller. Bind app session inputs, require declared named MCP tools, and fence Default selection and restore preflight. Local checkpoint: native compilation and async workflow validation remain pending dependency-complete CI; no publication approval assumed.

Signed-off-by: Logan Johnson <loganj@squareup.com>
Recover shared Default/named launch capture; cover direct pair Start/Restart, bulk and restore with locked same-plan admission. Classify mesh recovery by running pair snapshots. Route UI Restart through native admission while preserving old-turn cleanup. Native orchestration regressions remain a dependency-complete CI gate; frontend6295 and bounded exact-source policy checks pass. Local checkpoint only; no publication or remote broker-policy change.

Signed-off-by: Logan Johnson <loganj@squareup.com>
Move the existing descriptor resolver and discovery record fixture into sibling modules without changing their behavior or dropping cases. The required CI changes job rejects their producer-added growth in inherited oversized files; no policy limits or allowlists changed. Native fmt and actual size ratchet pass; native compilation is still awaiting CI-only draft authorization.

Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
…ed reader

Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Use producer preflight authority and shared captured Start/Restart admission. Capture the existing explicit Start Stop fence and runtime generation before await; keep probes and Restart without resume authority and preserve Failed after destructive Stop. Broker remains provisioning-unavailable. Native compilation remains gated on CI-only draft authorization; local formatting and integrated frontend checks pass.

Signed-off-by: Logan Johnson <loganj@squareup.com>
Carry the identical producer-owned compiler repair without rewriting the published validation head. Preserve capture, preflight and admission semantics. CI run34144148717 diagnosed these errors; native validation follows on the successor head.

Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Route signed lifecycle requests through ordinary async preflight and shared captured launch admission. Require an already provisioned matching local agent key, revalidate after awaits and teardown, and retain independent Stop.

Persist named launch lifecycle metadata without migrating or restoring captured credentials. Add isolated signed receiver and actual teardown regressions for revoked keys, missing executables, request expiry, and fresh same-host Start.

Native fixtures require Unix --no-default-features and remain unexecuted locally; dependency-complete CI owns compilation and runtime validation.

Signed-off-by: Logan Johnson <loganj@squareup.com>
…didate

Keep existing full native tests and add the Unix no-default-features fixture invocation to the Linux desktop job. Initialize the main-only idle ACP fixture with non-strict model policy while preserving its hold-decision regression.

Signed-off-by: Logan Johnson <loganj@squareup.com>
@loganj
loganj force-pushed the validation/runtime-config-integration-411ec2f0 branch from 68a9190 to 007035a Compare September 7, 2026 19:06
Post-policy CI found the shared launcher calls the pure captured-policy helper removed with the obsolete live-app wrapper. Restore only the command writer; keep captured preflight authority and no live state reads. Cover both policies overriding inherited environment.

Signed-off-by: Logan Johnson <loganj@squareup.com>
Repair every clippy 1.95 -D warnings failure from CI run 34155454680
(Desktop Core 101846514710) without weakening a check: the test env lock
becomes a tokio Mutex (buzz-db POOL_METRICS_TEST_LOCK convention) so async
tests hold the same single lock domain across await via
lock_path_mutex_async while sync tests keep blocking_lock; the dead
spawn_agent_child wrapper is removed and test-only helpers are cfg(test)
gated with ownership notes; mesh-feature-used relay_mesh_model_id carries
a justified cfg_attr; identical placement branches merge; restore test
module moves after the last item; mechanical bool/borrow/slice fixes; two
documented ABI argument-count allows at the launch-inputs passthrough and
the Tauri invoke contract.

local_host opened the scoped retention db without ensuring the
agents/retention parent that active_retention_scope only creates lazily
at retention time, panicking every remote_credentials fixture before its
assertions and any first lifecycle message preceding retention on a fresh
install. Mirror remote_stop::connection's on-demand parent ensure with
the same contextual directory error.

All seven remote_credentials fixtures execute and pass on the authorized
no-default lane; workspace clippy -D warnings and rustfmt pass locally.

Signed-off-by: Logan Johnson <loganj@squareup.com>
Read current credentials without migration, reserve new-key writes for explicit mint/import, and merge lifecycle bookkeeping into raw storage. Revalidate named launch credentials at the shared post-teardown spawn boundary. Bind production credential revocation regressions through ordinary Stop, local Start, bulk and restore, preserving destination provisioning and inline fallback.

Signed-off-by: Logan Johnson <loganj@squareup.com>
Use the existing marker-observable test child with TERM readiness and successful revocation exit; reap the simulated previous-session child concurrently. Assert receipt ownership and revocation before cleanup, retaining local Start refusal and restore no-publish. Removing only the shared fresh admission reload makes this regression fail after actual revocation. No production credential authority changes.

Repair native evidence gates: cover runtime_configuration in the snapshot mutation table, compare physical shell PWD on macOS, and isolate synchronous login-shell probe counts from parallel callers with a counter regression. Apply native rustfmt to integrated F6. All 13 no-default credential cases, full native workspace, clippy -D warnings and nested fmt pass.

Signed-off-by: Logan Johnson <loganj@squareup.com>
Hold the inherited-oversized agent_discovery.rs at the desktop file-size
ratchet base by importing the storage module and qualifying its save
sites; no behavior, ceiling, or gate change, so the PR CI paths job
stops failing before any native lane starts.

desktop-stop.spec.ts still selected the retired "Destination Desktop"
combobox, so the smoke case timed out on the configuration-driven UI.
Drive the same observable refusal through the current contract: wait for
the eligible remote catalog entry, select the exact runtime
configuration, assert the destination Start refusal copy, and re-send
the identical signed request via Retry same request. Fixture requests
are identified by signed event id so launch accounting stays scoped to
the start action while status, catalog, and preflight actions share the
lifecycle IPC.

Signed-off-by: Logan Johnson <loganj@squareup.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant