Skip to content

v0.10.1 integration: wave/0.10.1-next - #6782

Merged
Hmbown merged 383 commits into
mainfrom
wave/0.10.1-next
Oct 2, 2026
Merged

Hmbown merged 383 commits into
mainfrom
wave/0.10.1-next

Conversation

@Hmbown

@Hmbown Hmbown commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

This candidate integrates the completed audit repairs for 0.10.1 and incorporates the original contributor PRs #6793, #6799 and #6802. Queued/cancelled turns settle through the Engine's event authority, undo restores the durable conversation before replacement inference, Linux permission changes reach working children, and extension-host, MCP, session and UI repairs use the existing runtime boundaries.

Refs #6458
Refs #6556

Current candidate: d90359936738f5ff7c047a6c3081740562b540b2 (tree 3d9001b874e11ae0a18e4b0a59219a959c2c9b18). It includes main through a7a5eead60fa3863e6687753bafcb759d3434ab1 and clears the earlier merge conflict. Contributor PRs were reviewed, composed and merged as themselves after their exact-head Linux/macOS/Windows test and doctest gates passed.

Additional changes in this candidate:

  • Release uploads remain private drafts until asset names, nonzero sizes and SHA-256 digests match the assembled local inventory. CNB and GHCR publication follow canonical GitHub publication. Interrupted retries cannot accept stale same-size assets.
  • Ubuntu Lighthouse bootstrap requires trusted SSH CIDRs or explicit public-SSH opt-in before mutating the host, with full IPv4/IPv6 validation. English and Chinese instructions agree.
  • The dated 0.10.1 changelog and all three contributor credit surfaces include the original authors. The contributor gate excludes AI model trailers while preserving human co-authors.
  • The composition preserves submission IDs and event capacity reservations. Test-only callers supply the new optional field; the Chinese structcopy replay adapts four approved localized labels without changing its immutable golden payload.
  • Pet audio retains the backing ArrayBuffer type needed by current TypeScript. Dead-code suppression stays at current main's 258 ceiling; the existing production Engine factory requires no allowance. Runtime tool-contract ceilings were remeasured under the budget's stated rule for the deliberate schema/finance repairs, without adding identities.

Windows qualification caught two real compile errors at the preceding heads: both the Unix-socket timeout constant and its Duration import needed the same cfg(unix) guard as the consumer. The current head has both guards. 28 hooks tests passed on the preceding Unix-equivalent source, including the stalled-listener deadline; scoped all-target/all-feature CI-policy Clippy passed after the import repair. A local Windows cross-check stopped in ring because the Mac lacks the Windows C compiler; the hosted Windows run owns that proof. The macOS pet contract now verifies either exclusive audio ownership or explicit failed-device release: 11 black-box checks passed with the existing debug TUI on this Mac. The hardware-unavailable branch is now verified on hosted macOS, and all pet conformance targets passed at 28f5e41. Windows at 28f5e41 then reached TUI test compilation and exposed a third Unix-only symbol: the ExternalTool trait import in workspace tests. The current head guards that test-only import; TUI all-target/all-feature CI-policy Clippy passes. Production code and Unix behavior are unchanged. Original failures are retained; final Windows compilation and exact-head CI are pending. JavaScript source is unchanged from the complete local gate at 8f7744e52f.

Final hosted results at the preceding 3a95618 head: Linux 18,042 passed,
1 failed,31 skipped; Windows 17,426 passed,2 failed,24 skipped. Linux's sole
failure was the saved trusted-project prompt label from contributor commit
6cf3732, which deliberately stopped exposing absolute instruction paths.
The current fixture differs by that one label plus byte/hash summaries;
compare-only conformance passed all3 prompt cases (1 test,0 failures).
Windows exposed a real home-isolation inconsistency and an invalid fixture
filename. The current source rejects an explicit relative HOME before any
platform fallback; the checkpoint test uses a valid literal glob on every OS
and preserves a matching foreign edit. Local paths4/0,config-home7/0 and
checkpoint1/0 (3- and1001-path inventories); fmt/diff clean. Exact-head hosted
qualification remains pending. Pet conformance is green on all four targets
at3a95618c,including macOS and Windows recorder lanes.

Local shipping-profile CLI/TUI/Engine at28f5e4120 was built and installed
before the home-isolation repair: codewhale0.10.1, full LTO, strict ad-hoc
signature verification, stdio smoke6/0. Its native MemoryWhale acceptance
passes29 checks for actual capture, quit/restart, real MCP retrieval in a
second conversation and disabled capture. This used an isolated Full Access
TUI, pinned0.13.0 helpers and a loopback provider; sandboxed/PTY/Windows
capture, real providers, desktop distribution and signing/notarization are
separate unverified surfaces. The installed candidate is usable for local
testing; it is not evidence for the final home-isolation source or a release.

Validation:

  • Focused composition: 2,001 Rust tests passed, 0 failed, 6 ignored across Engine, runtime threads, commands, command contracts and workflow/scout coverage. The first composition's stale Chinese-label failure remains preserved separately from the restored pass.
  • Final local source checks: 810 JavaScript tests passed, 0 failed, 1 Windows-only skip (75 wrapper, 19 SDK, 63 extension host, 653 web); npm run check:web passed, including lint, types and production build. Workspace/all-target/all-feature Clippy passed using the unchanged repository CI policy; fmt/diff/version/changelog checks passed. Contributor gate: 14 human authors credited on all three surfaces. Blocking budget 710 sites/208 files; dead-code 258/258.
  • Release guards: 13 passed; SSH policy controls: 8 passed; pet type/build check: 76 passed. Removing the digest, publication dependency or missing-SSH-policy guards causes the relevant control to fail; byte-exact restored sources pass.
  • Prior batch 11 at 1ed71ac8d3c2bf47c8c97dbdd68d18e0e58aa143: TUI 14,479/0, 22 ignored in one process; other workspace libraries 2,890/0, CLI 512/0, cucumber 49/0, feature registry 6/0, turn guard 4/0, computer JavaScript 381/0 (16 platform skips), web 653/0, check:web and CI-policy Clippy passed. Its pet dependency/type check failed; the corrective pet pass is separate. These results are historical source evidence, not final-head hosted qualification.

Remaining qualification:

  • Positive final-head Linux, macOS and Windows tests/doctests and the two shared-process passes (test: shared-process workspace gate fails on main while nextest CI passes #6698).
  • Exact candidate release artifact/parity workflow and remaining native acceptance. The optimized 28f5e41 Mac runtime is built, hash-recorded and locally installed; it passed isolated app-server stdio 6/0 and starts the real TUI in a fresh loopback profile. The following cfg(test) import guard changes no runtime code. Its build/install proof does not establish hosted qualification or a published artifact. Native Windows hardware evidence remains unavailable; CI is recorded separately.
  • Every audit finding keeps its individual disposition: the original 221-row review reports 160 fixed, 5 disproved, 43 partial and 13 deferred. The release/SSH source repairs above address three partials; broader residuals, remaining TypeScript migration and product acceptance are not declared complete.

#6805 is reviewed separately and is not part of this candidate. Private advisory work remains outside the public wave. No tag, release, deployment or publication is performed by this PR.

Hmbown pushed a commit that referenced this pull request Sep 30, 2026
…indows-safe

- crates/tui/CHANGELOG.md regenerated with scripts/sync-changelog.sh
  (Version drift on #6782 failed: "crates/tui/CHANGELOG.md is out of date
  with the root CHANGELOG.md slice"); `sync-changelog.sh --check` now passes.
- skills::package_digest::tests::bounded_read_accepts_exact_remaining_bytes
  used the anonymous tempfile::tempfile(), which Windows CI denies under the
  hermetic test home ("Access is denied", os error 5, seen on #6783's
  Windows job 109657004556). It now uses a named file in a tempdir, like the
  neighbouring test. rustfmt --check clean; Windows CI is the proof.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014ZwqatxgVFxHvovngywnks
@gitguardian

gitguardian Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

️✅ There are no secrets present in this pull request anymore.

If these secrets were true positive and are still valid, we highly recommend you to revoke them.
While these secrets were previously flagged, we no longer have a reference to the
specific commits where they were detected. Once a secret has been leaked into a git
repository, you should consider it compromised, even if it was deleted immediately.
Find here more information about risks.


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

Hmbown pushed a commit that referenced this pull request Sep 30, 2026
CI Lint on wave/0.10.1-next (#6782, run 36682968210) failed with
clippy::collapsible_if (-D warnings) at crates/cli/src/cloud.rs:1446 (SSE
data: frame parsing) and :1653 (Agent Project binding check). Rewrite both
as let-chains; behaviour is unchanged.

Evidence (exact tree of this commit, cargowhale):
cargo clippy -p codewhale-cli --all-targets --all-features --locked --
  -D warnings -A clippy::uninlined_format_args -A clippy::too_many_arguments
  -A clippy::unnecessary_map_or  -> exit 0
rustfmt --check --edition 2024 crates/cli/src/cloud.rs -> exit 0

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Hmbown pushed a commit that referenced this pull request Sep 30, 2026
On every wave/0.10.1-next PR run, Test (ubuntu-latest) was terminated about
4.5 minutes into compiling the workspace test targets ("The runner has
received a shutdown signal", exit 143) at 04:30, 05:58, 06:02 and 07:26 UTC.
The 07:26 kill had no newer push to cancel it, so it was not the PR
concurrency group. Single-fix PRs finish the same --all-features build in
about 10 minutes; the combined wave is the largest tree.

For heavy Ubuntu PR/dispatch runs, add a step that removes preinstalled SDKs
the job never uses (dotnet, Android, GHC, CodeQL bundle) and adds 8 GiB of
swap, printing df/free before and after. The Run tests step now starts a
30-second memory/swap/disk trace on Linux and stops it after nextest,
preserving nextest's exit status, so a further termination records whether
memory or disk ran out. macOS and Windows are unchanged.

Validation: actionlint reports the same 12 pre-existing findings before and
after (none on the new lines); node .github/scripts/release-workflows.test.js
passes. Hosted proof is the next #6782 Ubuntu run.

Refs #6698

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: CodeWhale Bot <bot@codewhale.net>
CodeWhale Bot and others added 26 commits September 30, 2026 01:27
Preserve all 16 Opus lane commits through 2514704, with source review of computer-use dispatch outcomes and ownership, bridge durable writes, draft-release inventory publication, installer rollback, web bounds and shared pet validation. Lane receipts: computer-use 380 passed/0 failed/16 skipped plus 66/0 follow-up; web 642/0 and typecheck/build; bridge consumers 106/0; release inventory 5/0 and installers 27/0; pet 75/0 and SDK19/0. Those are lane receipts, not new integrated proof. Root npm/web gate and focused governed Rust pet/merge regressions remain pending before push. W02-02 reconciliation and W02-05 generation concurrency still need root follow-up; no deployment/publication/native-platform claim.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
… keys

Credit zhuowp on all current candidate surfaces for the adapted PowerShell repair, preserving verified Group Policy behavior. Remove two identical duplicate zh-Hans keys and make the existing parity gate reject ambiguous JSON instead of accepting the last value. Contributor gate finds 9 contributors and all three surfaces complete. Locale gate passes 14 non-English packs with 2440/2440 keys and matching placeholders. Negative control duplicate JSON exits 1. Diff check passes. npm/web integrated batch gate remains pending; no hosted/native proof claimed.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
The blocking approval-evidence worker added at 2bbe598 resolves test config through a barrier held by its awaiting caller. Reuse generation-scoped env_scope_ticket/join_env_scope at this test-only thread boundary, preserving production spawn_blocking behavior and sealed-state safety. Added a bounded trust-read regression, implementation first. Source trace explains CI tool-event timeouts; runtime test and fixes-off evidence are pending the shared governed queue. This local checkpoint does not claim verification or readiness to push.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…etry

Refs #6556 Refs #6559. Completes source repairs for W02-02 and W02-05.
Persist post-attempt target/text identity before network dispatch through the
existing draft claim Durable Object and KV. Durable attempts survive lease
expiry. Unavailable or malformed receipt reads/writes fail closed; changed
ambiguous retry text/target is refused. Reconcile at most 10 GitHub pages
with one 30-second deadline and 2 MiB per-page cap, refusing incomplete reads.
Definite rejection and completed bookkeeping clear the receipt under its claim.

The existing durable claim authority also serializes each bounded community
cron batch before source reads/model calls. Missing bindings start no provider
call; a 45-minute crash lease and two-minute completed hold cover overlap and
KV propagation. No new runtime/store authority or external action.

Validation: focused 6 files, Tests 78 passed (78), Test Files 6 passed (6).
TypeScript noEmit and scoped ESLint passed. Fixes-off source at integration
6352eb2: Tests 7 failed | 44 skipped (51); all seven new regressions
fail on the prior behavior. Fixed source restored byte-identically (4/4);
restored regression run: Tests 7 passed | 44 skipped (51).
git diff --check passed. No test/proof is inferred from a zero-match run.
Root npm test && npm run check:web, actual deployed DO behavior and final
candidate/provider evidence remain separate; no deploy/provider spend here.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Complete the CLI side of the account Work journey so a signed-in account
can take Work from a message to a reviewed Boat trial launch, cancel it,
and read what happened, without ever guessing at an outcome.

- agents work: parse reason, controlAction, confident and suggestion.
  A control verb prints the applied action and the Work's status, a
  correction says the objective was edited, an unclear message prints the
  Agent's suggestion, and only actionable/queued Work says "recorded".
  A lost reply points at re-running with the same --message-id.
- agents work-cancel ID [--queue discard|park] [--reason]: POST
  /api/runs/{id}/cancel. 409 run_control_terminal is reported as already
  final (exit 0); the queue-choice 422 is an actionable message; transport
  loss, 5xx and unreadable replies are an unknown outcome that names
  work-status.
- agents work-result ID [--json]: result plus attempts: state, evidence
  (changes, checks, findings), artifacts, model route, Boat usage block
  when the API serves one, and a PR link only when it is exactly a GitHub
  pull-request URL for the result's repository. All remote text goes
  through printable.
- agents work-quote / work-launch: contract C5 built from the served run,
  Agent and Project. The quote prints the disclosure and confirmation and
  refuses to hand out a confirmation for anything but the $0 EU Boat
  trial. Launch requires --confirm-eu-compute before any I/O, is
  replay-safe with the same operation key (it skips the queued-only local
  check once the Work has started so the ledger can replay), and reports
  unknown outcomes with work-status/work-cancel and the safe retry.
- account github bind OWNER/REPO [--installation-id]: POST the existing
  bindings route; the installation is inferred only when exactly one is
  known.
- agents new-thread: refuse a (provider, model) the live
  /api/model-providers catalog does not list, and assert the created
  conversation's route equals the request.

response_error now returns typed CloudHttpError, and the reqwest transport
returns CloudTransportError, so mutating commands can tell a refusal from
an unknown outcome; Display text is unchanged. The Work commands live in
cloud/work.rs.

Known limits: the control plane does not yet serve a model route or Boat
usage block on /api/runs/{id}/result, so work-result reads several
candidate keys and otherwise says "not reported by the account API".

Evidence:
- cargo test -p codewhale-cli --lib cloud:: -> 112 passed; 0 failed
  (23 new tests; 2 existing new-thread tests updated for the catalog read)
- rustfmt --edition 2024 --check crates/cli/src/cloud.rs -> clean
- cargo clippy -p codewhale-cli --lib --tests -> no findings in cloud/
  (-D warnings is blocked by an unrelated codewhale-app-server lint)
- Not run: live control plane, real Boat/DeepSeek/GitHub.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…replay hint

What/why (review fixes for 48af7e6a2):
- work-launch read run.id from the top level of the POST /api/cloud-sessions
  reply, but the server returns {"session": {...}}. Every real launch and
  replay ended in "launched a different Work" after the computer started.
  launch() now reads the inner session object; a 2xx without a session object
  is reported as an unknown outcome (the server acted), never a success and
  never "a different Work". The test fixture now matches the served shape.
- new-thread preflight matched a catalog row by runtime_provider (for example
  xiaomi-mimo) but the server stores the row id (xiaomi), so the post-create
  route check failed after the thread existed. assert_catalog_route now
  returns the canonical row id, which is sent and compared.
- agents work: an unreadable 2xx reply is now a transport-class error so the
  same-message-id hint fires; the replay wording is narrowed to "never
  creates a second Work for the same instruction; check work-status first
  for a stop or correction" in both help text and hint.
- Correction to the earlier commit message: 48af7e6a2 added 18 new tests
  (not 23) and updated 3 existing tests (not 2).

Evidence:
- cargo test -p codewhale-cli --lib cloud:: -> test result: ok. 113 passed; 0 failed
  (adds new_thread_sends_the_canonical_route_id_when_given_a_runtime_alias;
  extends the launch unknown-outcome and agents-work replay tests)
- rustfmt --edition 2024 on the three files: clean

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Keep the pending CLI Work journey honest at the launch boundary. Reject a
quote unless it is the requested 300-second Boat SKU, EU admission, trial
funding, zero Codewhale charge, and external BYOK billing. Restrict signed
confirmation text to its URL-safe alphabet before printing shell retry
commands or sending a launch. State that EU placement is a Codewhale
admission attestation and DeepSeek bills BYOK usage directly.

Allow the synchronous hosted launch to return its receipt with a 600-second
HTTP deadline; the guest trial runtime remains capped at 300 seconds.
Oversized responses and a 2xx without the Work ID report an unknown outcome.
GitHub binding 503 replies also report unknown rather than refusal. An
operation mismatch tells the user to inspect status and result, preserving
the key for an unknown launch. Work results show provider cleanup evidence.

Extended existing regression cases cover excessive or missing quote time,
wrong adapter/billing, shell metacharacters in confirmations, missing Work
IDs, key mismatch advice, transient binding errors, and cleanup evidence.

Source evidence: rustfmt --edition 2024 on the three claimed files and git
diff --check passed. No Rust test or clippy pass is claimed in this commit:
the replayed-tree cloud:: test is waiting for cargowhale position 12/12;
CI's exact all-targets/all-features locked clippy gate remains pending.
No live account, provider, installed CLI, hosted CI, or deploy was verified.
Boat lifecycle reconciliation uses HTTP 409 for unresolved provider outcomes.
Classify explicit uncertain Boat lifecycle codes as unknown regardless of
status, preserving the status/result/same-key guidance. An expired provider
replay window instead requires operator reconciliation and explicitly forbids
a new key or another allocation retry. Extend the existing launch-outcome
regression for 409 unresolved allocation, malformed provider receipt, and an
expired replay window.

Evidence: rustfmt --edition 2024 and owned-path git diff --check passed.
Focused cloud tests and CI all-targets/all-features locked clippy are still
queued under cargowhale; no test, provider, live-account, or deploy pass is
claimed. This commit remains local until those verification receipts exist.
Treat the control plane's normalized reconciliationRequired error field as
an unknown mutating outcome, preserving safe status/result guidance even for
new provider conflict codes. Retain existing explicit Boat-code handling for
compatibility. Extend the launch outcome regression with a 409 marked for
reconciliation.

Evidence: rustfmt --edition 2024 and owned-path git diff --check passed.
Focused cloud tests and exact CI clippy remain queued; no test or live pass
is claimed. Only cloud.rs and its tests changed.
Reviewed 639d800 across the existing Durable Object and KV authority, admin route reconciliation, six generation entry points and failure cleanup. Preserve pre-dispatch identity receipts after lease expiry; incomplete lookup and storage failures stop outbound posts. Lane receipt: 78/0 focused, seven fixes-off failures then seven restored passes, typecheck and scoped lint pass. Integrated npm/web gate follows on this batch; deployment and real outbound/provider behavior remain unclaimed.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
P4 IF-055 checkpoint before shared validation and discovery consumer edits. Nested child keys retain their parent path so metadata cannot replace skill identity or description; flow sequences reuse yaml-rust2.

Validation: rustfmt and git diff --check passed. Focused behavioral tests and governed build pending; this checkpoint is not acceptance proof.
Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Refs #6705. IF-049 Phase0 removes the legacy /mcp/startup route/handler, startup event advertisement, unused Core McpManager and startup event forwarding, and both Core/app-server MCP dependencies. Migrate every Runtime constructor and EN/ZH RuntimeAPI route listing. The live CLI mcp-server proxy and historical event decoding remain separate existing consumers until their migration decision; no silent replacement pool. Implementation first, then real-router regression verifies an authenticated POST cannot start that pool and capabilities do not advertise it. rustfmt/diff checks and locked Cargo metadata pass; blocking-call scanner758/210 passes. Rust route/core and fixes-off runtime proof remain pending the governed queue. Root npm797/0 and check:web passed on preceding560925de2; no changed Rust/native/hosted proof inferred.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…mpilation

Complete the inherited runtime audit source checkpoint without dropping prior authorship. The failed governedruntime-2build reports one unused Result in a valid project-overlay regression; assert success rather than discard it. Under the existing job lock, save_unless_canceled now permits a genuinely missing first record but refuses malformed or unreadable persisted state, preserving possible cancellation evidence. Implementation precedes a malformed-JSON/I-O byte-preservation regression. rustfmt and diff checks pass. Original compile failure and focused/negative runtime proof remain explicitly pending integration; no passing Rust or release claim.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…d boundaries

P4 IF-054 / IF-055. Owned Codewhale roots precede compatibility roots in each
scope. Flat workspace skills require explicit opt-in or configured skills_dir;
the existing discovery enum now travels every session/prompt/tool/UI context,
replacing lossy bool reconstruction. Trust skip warnings follow that same policy.

Runtime and installation share one lenient/strict validator. Nested metadata
retains its scope, YAML flow lists reuse yaml-rust2, routing hints are preserved,
and unsupported authority metadata warns. Model/user invocation are independent:
disable-model-invocation and user-invocable:false together disable both paths.
Model catalogs/load/list, user palettes, and explicit activation enforce those
accessors. Plugin snapshot hashes and authority checks remain the same boundary.

Source checkpoint, not completed integrated acceptance. Local production-leaf
harness: test result: ok. 14 passed; 0 failed. Defects restored in copied sources:
test result: FAILED. 7 passed; 7 failed. Fixed source restored unchanged:
test result: ok. 14 passed; 0 failed. The leaf root harness admits workspace trust
through a fixture stub; this does not verify integrated trust behavior. Actual
parser/validator code and real Claude/Codex frontmatter fixtures are exercised.

rustfmt and git diff --check passed. Blocking-call budget remains 758 sites across
210 files, within budget. One governed codewhale-tui focused build is queued;
full-source compile, focused runtime/menu/plugin tests, integrated web/clippy,
hosted exact-head CI and native evidence remain pending. No push or deploy.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Preserve Opus runtime audit history663340567/f6c9f1081/c875f6949 plus Codex430308f624 source corrections. Source review covers bounded SSE assembly and explicit truncated EOF, typed Anthropic retries, route-scoped pauses, OAuth compare-delete, MCP process containment, fail-closed project restrictions, bounded catalog/cache truth, cloud cancellation serialization and uncertain-state preservation. zh-Hant merge conflict was ordering only: both complete JSON maps have identical unique keys and values, verified before preserving integration order. Inherited runtime-2build failed on one unhandled test Result, now asserted; no passing runtime receipt is claimed yet. Batched governed compilation is queued; focused runtime and negative controls follow on the frozen candidate before push.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Preserve Opus7402a66a6/4991ec6d6/9c9c7b9dd/385e03dde histories. Reviewed provider-error batch suppression, stream content cap, final-report admission, request-scoped nudge receipts, edit rollback, session MCP/usage reset, catalog revalidation, human waits, save-before-apply and selected ASR routing. Inherited lane508/0; fixes-off16/16 targeted failures and4collateral matches passing, each independently mapped by second reviewer. Only five exact control files restored from fixedHEAD after preserving script/log/patch; checkoutclean. New integrated/restored proof is pending queued build. Residual C01-09,C02-11/14/15 and supervisor/spill-write-failure subclaims remain root-owned, not silently closed. No hosted/native/release claim.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
The integrated P4 all-features focused compile found two test-only command-palette consumers still passing the retired discovery boolean. Carry the existing Compatible mode through both fixtures, preserving their old false behavior.

Verification: rustfmt --check and git diff --check pass. Initial governed full compile is failing E0308 at these two old callers; focused retry pending. No runtime acceptance claimed.
Signed-off-by: CodeWhale Bot <bot@codewhale.net>
The P4 focused integrated build exited 101 with three old boolean test callers. Two were repaired in 9664f2d; this final command-palette alias caller carries CodeWhaleOnly for its former true value. All direct and aliased palette callers now use the existing typed mode.

Verification: rustfmt --check and git diff --check pass. Production focused rebuild pending; no runtime acceptance claimed.
Signed-off-by: CodeWhale Bot <bot@codewhale.net>
C02-11: a provider stream parks in event delivery when the bounded host queue fills. This checkpoint reuses Engine tx_event and its turn cancellation token to bound that pending nonterminal send on cancellation. Ordinary delivery remains ordered and lossless. Terminal settlement is unchanged and may still wait on a non-draining consumer.

Checkpoint before migrating stream callers across files. Verification: rustfmt --check and git diff --check pass; focused production backpressure and fix-off controls pending. Refs #6561.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Exact source parent 7244363, tree ee23ac8: cargo test -p codewhale-cli --lib --locked cloud:: passed 113/113, 0 failed, 0 ignored, 353 filtered. CI-equivalent cargo clippy -p codewhale-cli --all-targets --all-features --locked -- -D warnings -A clippy::uninlined_format_args -A clippy::too_many_arguments -A clippy::unnecessary_map_or passed. No tests were repeated to create this attestation.

cargo build -p codewhale-cli --locked --bin codewhale succeeded under cargowhale. Apple silicon development executable copied outside the shared target for the live journey, sha256 c7d9941af37cd3ef300bdb3360cbec41e708312b0af608b05935576db63d600b, 349628032 bytes. --version reports codewhale 0.10.1 (dev); account agents --help advertises work-cancel, work-result, work-quote and work-launch. The linker warned that __eh_frame exceeded compact unwind offset capacity; build exit0, no Rust compilation errors. This is a local runnable development build, not a published release or install replacement.

No source changes in this commit. Unit tests, strict lint and local build are separate from hosted CI, deployed route probes and real provider/account journey proof. No provider calls or deploys were performed.
SECURITY.md directs reports to this repository's private GitHub security advisory form, states that fixes target the latest published stable release, and explains triage and coordinated disclosure without promising an unapproved response deadline. No personal address or private infrastructure/runbook information is included. Contact choice and any response SLA remain founder packet A9 decisions.

Documentation evidence: repository API reports private vulnerability reporting enabled:true; GitHub official security advisory documentation confirms private reporting for public repositories. Four direct document checks passed (private report link, latest-stable support, honest response expectation, no address), and owned diff whitespace check passed. No Cargo or product behavior tests were needed for this documentation-only slice. No report was submitted.

Primary reference: https://docs.github.com/en/code-security/concepts/vulnerability-reporting-and-management/repository-security-advisories
The shared strict frontmatter validator now owns required-field errors, leaving the old InstallError::MissingFrontmatterField variant without a constructor or consumer. Delete the dead enum arm instead of suppressing the deny-warnings failure.

Verification: governed P4 focused retry exited101 solely on this dead-code diagnostic. rustfmt --check and git diff --check pass; corrected focused retry pending.
Signed-off-by: CodeWhale Bot <bot@codewhale.net>
C02-11: migrate every16 process_stream observation plus the finalizer warning to the engine cancellation-aware sender. Eight actual decoder observation shapes are exercised against a full queue; live drain preserves output ordering and usage. Terminal settlement still requires consumer progress on the existing lossless channel and remains a separately owned boundary.

C02-14: bound each response to256 tool calls before retaining either native/server ToolStart257. The text fallback enforces the same ceiling before conversion, observations or planning. A response rejected by the stream guard uses the existing failed-response admission path; configured lower per-turn limits and protocol ID validation remain in force.

Source checkpoint: rustfmt --check and git diff --check pass. New actual decoder tests cover exactly256 versus257 empty native/server calls. Focused governed compilation and copied-production negative controls pending; no passing runtime or full C02-11 closure claimed. Refs #6561.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Reuse the same isolated engine/queue fixture in all new C02-11 and C02-14 decoder tests, removing repeated setup and its obsolete imports before the single focused compile. rustfmt --check and git diff --check pass; production build pending.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
The new when_to_use acceptance fixture correctly checked the merged description but expected split_trigger to retain sentence punctuation, which its existing prompt-row normalization removes. Correct only that summary assertion; preserve the implemented frontmatter policy and trigger content.

Governed all-features P4 focused run compiled and reported test result FAILED.333 passed;1 failed;13968 filtered out. This new assertion was the sole failure. rustfmt and diff checks pass; rerunning only this failed case next.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
CodeWhale Bot and others added 6 commits September 30, 2026 22:32
Require the exact uploaded asset set, local byte size, and GitHub SHA-256
digest before publishing a draft. Paginate draft lookup and refuse duplicate
drafts or publishing without a local verified asset directory. This prevents
stale same-size assets from a failed attempt being published on retry.

Mirror release tags to CNB only after canonical GitHub publication, with an
exact source/tag check and public inventory verification even for manual
recovery. Do not force-update release tags. Keep English and Chinese mirror
documentation and the release runbook consistent with the workflow.

Validation: npm test: 653 passed, 0 failed (65 files); npm run check:web:
passed. Release inventory/absence tests: 13 passed, 0 failed. Workflow
guards and actionlint: passed. Removing the digest guard or release job
dependency makes the focused controls fail; both restored checks pass.
No live release, tag, or mirror publication was performed.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Refuse bootstrap without trusted CIDRs or SSH_ALLOW_ANY_SOURCE=1, before
packages, users, files, or firewall rules change. Validate the complete list
with Python ipaddress, including IPv6, before applying any rule. Add narrow
rules before removing the broad rule. Document the policy in English and
Chinese and correct the unified binary/Rust 1.89 installation instructions.

Validation: 8 SSH policy tests passed, 0 failed; missing-policy knockout
fails and exact restored source passes. bash syntax, workflow structure
(actionlint without ShellCheck), and existing workflow guards passed. Full
actionlint reports inherited ShellCheck style warnings in unchanged CI
steps. CI now runs the 8 policy tests. No host/server changes were made.

npm test: 653 web tests passed, 0 failed; npm run check:web passed at
c0cb85bc3f, whose JavaScript/web sources remain unchanged in this slice.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…edits

Move the already-integrated changes into the dated 0.10.1 candidate, remove
one duplicated stream note, and synchronize the changelog mirror, canonical
contributor ledger and website credits. Preserve the original PR authors,
including qiuYliangM's context-label contribution within #6799. Exclude
Codex model trailers from the human-contributor gate, as Claude trailers
already are; a positive control retains both human contributors.

Remove the unnecessary dead_code allowance from Engine::new_with_model_client:
the runtime's production constructor already calls it. This satisfies current
main's 258-suppression ceiling without changing the implementation or budget.

Validation: npm test 810 passed / 0 failed / 1 platform skip (75 wrapper,
19 SDK, 63 extension host, 653 web); npm run check:web passed, including
lint/types and production build. Workspace/all-target/all-feature Clippy
passed with the repository's exact CI policy; fmt and diff checks passed.
Contributor gate: 14 human authors credited on all three surfaces. Blocking
budget: 710 sites / 208 files; dead-code 258/258. Dated release/version and
38 feature-note references passed. No tag, release or publication created.

Earlier strict Clippy attempts omitted CI's documented lint exceptions and
failed; those logs remain preserved. Exact-head hosted qualification and
final optimized/native acceptance remain separate from these local checks.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Co-authored-by: Codex <noreply@openai.com>
Final-head Windows CI failed before running tests because the Unix-socket
sink timeout constant had no Windows consumer under warnings-as-errors.
Match the constant's platform guard to its existing Unix-only emit method.
Windows keeps its existing no-op sink; Unix delivery remains bounded.

Validation: hermetic hooks library 28 passed / 0 failed, including the
stalled-listener deadline; all-target/all-feature scoped CI-policy Clippy
passed. fmt/diff checks passed. JavaScript sources are unchanged from the
810 passed / 0 failed / 1 platform-skip npm test and passing check:web gate
at 8f7744e; no redundant rerun. Real Windows compilation/tests and final
source artifact proof remain with the newly dispatched hosted head.

Preserve the failed Windows job log; this was a source error, not a flake.
The unfinished 8f7744 dist build and its obsolete RC/shared-process workflows
were cancelled before changing root. No old binary is labeled final.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Co-authored-by: Codex <noreply@openai.com>
Windows CI at bd8588f rejected the Unix-only Duration import after the
timeout constant was guarded. Give the import the same platform boundary.
The hosted macOS pet contract also assumed an audio device survives between
two lease requests. A sink failure correctly releases the lease; accept that
branch only when the frame explicitly reports unavailable audio and no owner.
An available sink still has to refuse the competing lease. Release both test
clients before proceeding. This changes no production audio behavior.

Validation: hooks all-target/all-feature Clippy PASS under CI policy;
28/0 hooks tests remain valid from bd8588 (Unix behavior unchanged).
Corrected black-box pet contract: 11/0 using the existing debug TUI, exercising
the exclusive-lease branch on this Mac. The hardware-unavailable branch still
requires hosted proof. fmt/diff checks PASS.
JavaScript source unchanged from 8f7744e: npm 810/0, 1 platform skip;
check:web PASS. Local Windows GNU check stopped before hooks in ring because
x86_64-w64-mingw32-gcc is absent. No Windows compile or final CI pass claimed.
Failed hosted and local cross-build logs are retained in takeover receipts.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Comment thread crates/cli/src/cloud/machine/tests.rs Dismissed
CodeWhale Bot and others added 19 commits October 1, 2026 00:00
Windows reached TUI test compilation and rejected ExternalTool imported by two Unix-only tests. Give the import the same cfg(unix) boundary. Production code and Unix behavior are unchanged. Validation: TUI all-target/all-feature CI-policy Clippy PASS (2m24); fmt/diff PASS. JavaScript unchanged from the 810/0 gate (one platform skip) and check:web PASS. Failed exact-head Windows log is retained; Windows compile and final CI remain pending. Optimized 28f5e41 local runtime candidate is built, installed, and passed isolated stdio 6/0.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…CI fixtures

An explicit relative HOME could silently escape to the Windows runner profile.
Honor the same fail-closed contract on every OS before any platform fallback;
ordinary launches without HOME still use the Windows/platform resolver.

The checkpoint test now uses a platform-valid literal Git glob filename and
retains a matching foreign edit, so Windows executes the ownership assertion
instead of failing before checkpointing. Both 3-path and 1001-path inventories
must commit only worker paths and preserve the staged and unstaged foreign work.

Refresh the trusted-project prompt golden for contributor commit 6cf3732:
source="AGENTS.md" intentionally replaces the absolute instruction label.
Only that label and its byte/hash summaries change; tools remain unchanged.

Local macOS: paths 4 passed/0 failed; config home 7 passed/0 failed;
checkpoint ownership 1 passed/0 failed (both inventory sizes); prompt family
3 cases matched, 1 test passed/0 failed in compare-only mode before the
home/ownership changes. cargo fmt --all --check and git diff --check pass.
Hosted Windows previously: 17426 passed/2 failed/24 skipped, both addressed
here. Linux previously: 18042 passed/1 failed/31 skipped, stale prompt golden.
Fresh hosted CI is still required; no Windows-native local pass is claimed.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Share the selected-backend dispatch between HTTP/native dictation and TUI interim/final capture. A local whisper or Groq transcription failure now returns that failure instead of uploading the recording to the configured model provider. Provider auth is resolved only for the explicitly selected provider route; composer-aware control keeps its existing behavior.

Local proof: selected ASR tests 3 passed/0 failed. Restoring the old hosted fallback makes both routing regressions fail (0 passed/2 failed); restored fixed source passes3/0. CI-policy TUI library Clippy with all features passed, as did workspace formatting and diff checks. EN/ZH Runtime API docs and the existing voice feature row describe the actual no-fallback contract.

Refs C01-10 in the 0.10.1 audit. Persisted ASR preferences and temporary-file acceptance remain separate subclaims. Hosted/native/provider/package qualification is separate; no live provider call or public release occurred.
Shorten the selected-backend release-note summary to the existing 120-character contract. No behavior changes.

Validation: feature registry executable reads current source: 6 passed / 0 failed; git diff --check passes. Hosted cafa Linux/Windows gates exposed the 153-character row; original failure logs are preserved. Shared-process restore test remains independently under investigation.
Stable Rust 1.99.0 deprecates the atomic `fetch_update` (renamed `try_update`),
and release builds deny warnings, so every artifact build of the previous
head failed in codewhale-tui (workflow child counter, sub-agent pending
count). `try_update` is newer than the MSRV, so the three call sites (two
production, one app-server test fixture) are plain compare-exchange loops with
the same orderings and results.

The recurring shared-process failure of
`restore_routes_refuse_an_active_turn_in_the_workspace` was test isolation,
not restore admission. After the refusal assertions the route opens the
snapshot store under the resolved home. The test did not hold the test
environment lock, so the store could land under a sibling test's temporary
HOME and be deleted when that test ended, turning the expected 409 into
`500 Failed to list snapshots: git log failed`. That test and its sibling
`file_revert_route_validates_body_then_trust_then_ownership` now seal the
environment and own a CODEWHALE_HOME; the status assertion reports the body.
No production restore or admission code changes.

Local macOS evidence, family filter `runtime_api::tests::re` in one process:
before, 2 failures in 73 runs (first with status only, then with the body
above); after, 0 failures in 150 runs, each `21 passed; 0 failed`. Workflow
and sub-agent filter: `1135 passed; 0 failed`. App-server lib:
`126 passed; 0 failed`. cargo fmt --all --check passes. Local toolchain is
1.98.1, so the 1.99 build itself is proven only by hosted CI.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Hosted Lint and release parity on 81d9ec8 failed on three lints new in
Clippy 1.99: `single_element_loop` on the one-key `args` validation loop in
agent_plugin.rs, and `needless_borrows_for_generic_args` on two
`map(&bounded)` calls in workflow_panel.rs. The loop becomes the plain check
it was (same error text); the closure is passed by value. No behavior change.

Local macOS, toolchain 1.99.0 installed beside the default: CI-policy
`cargo clippy --workspace --all-targets --all-features --locked -- -D warnings
-A clippy::uninlined_format_args -A clippy::too_many_arguments
-A clippy::unnecessary_map_or` finished with exit 0 and no diagnostics.
cargo fmt --all --check passes. No tests were rerun for these two edits.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…r 0.10.1

Hardening across the Engine, the bundled Computer Use plugin and the chat
bridges. Each item reuses the existing authority instead of adding a second one.

- Computer control: a consent or script call runs only on an exact decision a
  person gave on its own approval card; rules, autonomous postures, child
  agents and code-mode programs cannot produce one. The bundled plugin carries
  the matching consent, script, helper and SSH argument checks and known-host
  routing.
- Git status and review: automatic status, worktree and log reads go through
  the sanitized review command, refuse unsupported runtime configuration
  overrides, and stay pinned to the executable that was checked.
- Redaction: persisted config backups, config dumps, MCP listings and
  notification payloads share one sensitive-key vocabulary in codewhale-sanitize.
- Recursive RLM: each round of Python a child model writes is admitted by the
  turn serving the direct `rlm` call, through the same planning and approval
  as an inline repl block, and runs only as admitted; `rlm` is not available
  inside execute_tools programs. Python kernels are discarded when the applied
  posture narrows.
- Gate commands and the cargo test runner start inside the session's shell
  sandbox with the sanitized environment.
- Chat bridges decide an approval only for the human who started that turn, on
  the Runtime's current pending approval, and consume a stored action only
  after delivery. Upgrade note: approvals for turns started before the upgrade
  are decided from the TUI; WeCom `/allow` no longer takes `remember`.
- Mutable session artifacts are written through the pinned session-relative
  replace; the owned-artifact pager reads through the pinned open with a
  64 MiB display cap.
- The stdio bridge's Runtime child binds an ephemeral loopback port itself and
  reports it; the parent validates that report, never follows redirects with
  the bearer token, and reaps the child on a bad or late report.

Known limits: Python kernels are approval-gated local subprocesses, not
OS-sandboxed; where no enforcing sandbox is configured (Linux without
bubblewrap, Windows) a workspace-write policy runs runners unsandboxed, as it
already does for exec_shell; an approval wait counts against an RLM turn's
deadline; verifier, plugin, hook and lane child processes are unchanged.

Local macOS evidence on this exact tree: CI-policy Clippy on Rust 1.99, whole
workspace, all targets: exit 0. Focused Rust selection: app-server 7 passed /
0 failed, config 7/0, sanitize 2/0, codewhale-tui 1346/0. Bridges: core 37/0,
feishu 19/0, telegram 39/0, wecom 17/0, weixin 13/0. Computer Use plugin: 401
passed / 0 failed / 16 skipped. npm test: 75/0, 19/0, 63/0 with 1 skipped;
check:web passes. With each new guard disabled in turn, its regression tests
fail and pass again on the restored source. A native run confirmed the stdio
parent reaches a real Runtime child through the endpoint the child reported.
Hosted three-OS, shared-process and release-candidate results are still
required for this head; no Linux or Windows native run is claimed.

Co-authored-by: CodeWhaleBot <268170417+CodeWhaleBot@users.noreply.github.com>
Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…nt error frames

Stall recovery (Refs #6800). When the UI watchdog recovered a turn that had
started, it reset only UI state. The engine kept the turn, so the next message
waited out the dispatch bound and was refused, and no outcome was recorded.
Recovery now cancels the engine's turn through the same cancellation the
cancel key issues, with its own reason, and handles the engine's late terminal
event as after a local cancel. A turn that is still live is never cancelled.
Not covered: the dispatch wait still blocks input for its bound, and a turn
wedged somewhere that does not observe cancellation still holds the engine.

Error frames (Refs #6795). A gateway can report a transient upstream failure
as an error frame inside a successful response ("Provider returned an empty
response"). With nothing actionable streamed that is now a no-content stream
death like a transport error or a stall: it is counted, the existing retry
budget re-issues the request, and an exhausted budget fails the turn with the
provider's reason. A retried frame emits no error card. Auth, invalid-model
and every other class, and any frame after content, stay terminal on the
first frame, now with a non-recoverable envelope instead of a hard-coded
recoverable one.

Credit check: the project bot's co-author handle is a bot, not an uncredited
contributor (the Version drift job failed on the previous head for this).

Local macOS, Rust 1.99: focused codewhale-tui lib selection 254 passed /
0 failed, including a scripted engine turn (empty-upstream frame then a
healthy stream: 2 requests, Completed, no error event; invalid-model frame:
1 request, Failed) and the watchdog test asserting the engine handle is
cancelled on recovery and untouched for a live turn.
scripts/check-contributor-credit.py passes.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…crash checkpoint on resume, keep imports on the window's route

Three defects found by native acceptance of the previous head, plus the
platform fixes its hosted run asked for.

- `/undo` and `/restore <N>` rewrote workspace files while a turn was running
  in that workspace, discarding in-flight work and leaving the model's view of
  the files wrong. Both now refuse while a turn is active or compacting, like
  the Runtime's restore routes; nothing is changed on refusal.
- `--resume <id>` after a crash opened the older saved document and the next
  save cleared the session's crash checkpoint, losing the interrupted turn
  while its file edits stayed on disk. An explicit resume now promotes that
  session's own newer checkpoint first, in the same order `--continue` uses;
  a session live elsewhere or a newer saved document is left alone.
- `/resume <file>` imported a session with the record's default provider
  instead of the window's route, so opening it sent the conversation to
  another provider's endpoint. The import now binds to the window's route.

Hosted failures on e86d677 (Linux, Windows, release parity):
- four Computer Use tests start the bundled plugin, which applies only to
  macOS hosts; they return early elsewhere;
- the structured-copy key test used a fixture key ending in `key`, which the
  shared vocabulary redacts by design; the fixture key no longer looks like a
  credential and all five values are asserted again;
- the read-guard file-tool test redirects the home directory through `HOME`,
  which Windows does not use; it is Unix-only.

Local macOS, Rust 1.99: focused codewhale-tui lib selections 302 passed /
0 failed (undo, restore, checkpoint, resume, continue) and 354 passed /
0 failed (import, control, resume); 102 passed / 0 failed for the platform
test fixes. CI-policy Clippy, whole workspace, all targets: exit 0.
Native evidence for the three defects is in the acceptance receipts; the
fixes themselves have not yet been re-run natively.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Adds the Security and Fixed entries for the work landed on the wave on
October 1 and regenerates the embedded copy. scripts/sync-changelog.sh
--check passes. No code change.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…o conformance goldens

Crash checkpoint. df755a3 recovered a session's crash checkpoint only for
the `--resume <id>` launch flag. A native retest showed the in-TUI resume of
a crashed session still attached the older document and lost the interrupted
turn at the next save. Every surface that takes ownership of a session goes
through `SessionManager::attach_session`, so the promotion lives there now:
under the attach lease, a checkpoint newer than the saved document (or with
no document yet) is saved as the document and consumed. A stale checkpoint
never replaces a newer document, and an unreadable document is left alone so
the attach still reports it. The launch-only helper is removed.

Conformance. Hosted runs of df755a3 failed
`conformance::events::golden_turn_events_match`:
- `provider_error_after_tool_call`: a terminal provider error frame is now
  reported with `recoverable: false` (Refs #6795: the frame ends the turn, so
  the old `true` promised a retry that never happened). That one golden line
  is updated; clients that style the card from this field now show an error
  rather than a warning.
- `parallel_tool_calls`: failed in the release parity job only. Two parallel
  tools each emit an activity completion and then a tool completion; under
  load the pairs interleave, and the harness only ordered adjacent events of
  one kind. An uninterrupted run of completion events is now put in one
  canonical order (activity completions by span, tool completions by call
  id). Every event, outcome and boundary is still compared.

Local macOS, Rust 1.99: focused codewhale-tui lib selection 438 passed /
0 failed / 1 ignored (attach, checkpoint, resume, continue, session_manager,
conformance). The conformance family passed 25 of 25 consecutive runs after
the golden update. CI-policy Clippy, whole workspace, all targets: exit 0.
The interleaving itself was not reproduced locally (0 of 25); the fix is
argued from the hosted diff and covered by a unit test of the normalizer.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Native acceptance of a 910-turn session showed every turn from about the
sixteenth starting 2.8-3.0 s late (0.45-0.6 s before), constant afterwards.
Cause: the prune that follows every snapshot. Once the store held more than
the 50-snapshot window (about three snapshots per turn), each new snapshot
removed one old one by rebuilding the whole survivor chain, two git processes
per survivor, on the path before the provider request.

The per-snapshot prune now waits until half a window is due to go and drops
it in one rebuild, so the rebuild runs about once every eight turns instead of
every turn. The store holds at most half a window more than before; the
size-pressure prune and the turn-boundary retention rule are unchanged. The
unbatched form remains for tests.

Local macOS, Rust 1.99: snapshot, turn and prune selection 129 passed /
0 failed, including the new batched-prune test (one over the cap: no rebuild;
half a window over: dropped together, newest kept). CI-policy Clippy, whole
workspace: exit 0. In a larger parallel selection six runtime_threads tests
timed out once and passed 3 of 3 alone; recorded as load-sensitive, not
explained. The turn-start delay itself has not been re-measured natively with
this change.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…ce test build

The parity job's runner has been shut down while building the workspace tests
on several 0.10.1 candidates (exit 143 about four minutes into the third
codewhale-tui compile, no test result), most recently run 36902228559 on
2d1971d. The logs do not say whether memory or disk ran out. The same
headroom trace ci.yml's test step uses now runs here, with one line before
the build showing what the earlier check and clippy steps left in target/.
The test command, profile and environment are unchanged.

actionlint passes; scripts/test_ci_migration_wiring.py: 19 tests OK. Not yet
run hosted.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
A second read of path and authority consumers found sites that still used
unconfined or default-mode I/O. Each now goes through the guard its
neighbours already use:

- Tasks and automations: a session without full shell access stores an
  explicit "no shell" on work it hands off instead of leaving the flag unset,
  which fell back to the host default.
- Commit planner: untracked files are read through the workspace-confined
  no-follow open with a bounded read.
- Oversized paste backup: written through the workspace-confined writer.
- Audit and approval logs and the approval lock file: created 0600, tightened
  on open if an earlier version left them wider, never opened through a link
  at the final component (Unix).
- Lane registry: ids must be plain names; records are written through an
  exclusively created temporary file.
- PowerShell temporary script: created exclusively.
- Sessions: a session file that records a different id than its file name is
  refused on load.
- Updater: a redirect may not leave HTTPS; responses over 512 MB are cut off.

Tests (Rust 1.99, macOS arm64, hermetic test home):
- codewhale-lane: test result: ok. 73 passed; 0 failed
- codewhale-cli --lib update: test result: ok. 95 passed; 0 failed
- codewhale-tui --lib session_manager:: 130 passed; approval_log:: 13 passed;
  tools::git:: 18 passed; tools::tasks:: 17 passed; shell_dispatcher:: 19
  passed; resume 148 passed; fork 53 passed; checkpoint 73 passed; paste 73
  passed; 0 failed in each.
- CI-policy Clippy, workspace, all targets and features: clean.
- Control: with each guard disabled, its new test fails (8 tests across lane,
  cli and tui). The PowerShell change has no new test.
- Under the broader `session` and `runtime_threads` filters one test failed
  once each (resolves_art_prefix_via_session_artifacts,
  operation_key_replays_torn_response_survives_restart_and_rejects_mismatch);
  both passed alone and in two reruns of their groups (15/15, 280/280).
  Not run locally: Linux, Windows, full workspace suite.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Harness refine and remove write model-authored text to state.json and
JOURNAL.md under the workspace's .codewhale/harness. Nothing checked whether
.codewhale, the harness directory, the state file or the journal was a link,
so a workspace that ships one could send those writes outside the workspace.
The write path is now refused when any component from the workspace down is a
link, before a directory is created through it. Reads are unchanged.

Tests (Rust 1.99, macOS arm64):
- codewhale-runtime --lib continual_harness: test result: ok. 8 passed; 0 failed
- codewhale-tui --lib harness: test result: ok. 18 passed; 0 failed
- Control: with the check aimed at the wrong directory (so it never saw the
  link), the new test failed at its "nothing created outside" assertion.
- Clippy (CI policy) on codewhale-runtime, all targets: clean.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
The Lint job failed on 2c95b7d: the harness link check added two
canonicalize calls (budget 0) and the owner-only log helpers added two std::fs
sites in utils.rs (14 > 12).

- continual_harness: the link check now walks down from the workspace root the
  config resolver already normalized, so it needs no canonicalize of its own.
- utils.rs: the two new sites are the synchronous open-options builder and the
  permission tightening for append logs. They replace an inline OpenOptions
  call on the same synchronous path (audit and approval appends), so the
  budget is raised to 14 rather than moving a file open into spawn_blocking.
- The regenerated budget also tightens three files that are now under budget
  (artifacts.rs, activity_detail.rs, composer.rs).

scripts/check-blocking-calls-budget.py: 707 sites across 207 files, within
budget. codewhale-runtime --lib continual_harness: test result: ok. 8 passed;
0 failed. codewhale-tui --lib harness: test result: ok. 18 passed; 0 failed.
Clippy on codewhale-runtime, all targets: clean.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…ning

release-parity.yml: the headroom trace added in 6fcbc92 showed the test
build using all memory and swap on the runner (peak "mem used 15574/15989 MiB
swap used 3052/3071 MiB", job 110549112727 on 2c95b7d), which accounts for
the runner shutting this job down (exit 143) on earlier candidates. The job
now runs the same headroom step ci.yml's test lane uses: remove unused
preinstalled SDKs and add an 8 GiB swapfile. Tests, flags and profile are
unchanged. release.yml calls this workflow after the tag, so the tagged tree
carries the step.

CHANGELOG.md: the 0.10.1 section opened with a website item and called the
release a "source candidate"; that text is the release body. The summary now
leads and the website item is a bullet under Changed (credit unchanged).
docs/INSTALL.md: one stale example date removed.

No Rust source changes. actionlint passes on release-parity.yml;
scripts/test_ci_migration_wiring.py OK; sync-changelog.sh --check: up to
date; check-contributor-credit.py: every contributor credited. The new step is
not yet run hosted.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
… survives a stray copy

/edit: since the #6788 change the command layer only stages a conversation
rollback and the UI applies it after the Engine acknowledges it. The submit
path for a pending /edit still ran "/undo" and discarded the result, so
nothing was rolled back: the old prompt and its answer stayed in the
transcript, the model context and the saved session, and the edited prompt
was appended. 0.10.0 replaced them. The submit path now stages the rollback
and applies it through the same action /retry uses, with the edited text as
the replacement turn. Only the conversation is rolled back; files are not
restored by an edit.

Resume: a copy of a session file under another name is listed with the
original's id, which made that id an "ambiguous prefix" and the session
unresumable. Duplicate listings of one id now resolve to that session. Found
by native acceptance; the same happens on earlier builds.

Changelog: the two fixes above, and a Changed entry for the process-scoped
PowerShell execution-policy setting that shipped earlier in this cycle
without one (#6745).

Tests (Rust 1.99, macOS arm64):
- codewhale-tui --lib conversation_undo: test result: ok. 2 passed; 0 failed.
  The lifecycle test now drives /edit, submits, and checks the provider
  request, the app history and the saved session.
- Control: with the rollback replaced by a plain send, that test fails with
  left: ["keep this", "after reopen", "edited prompt"]
  right: ["keep this", "edited prompt"].
- session_manager:: 130 passed; edit 197 passed; debug_mutation 27 passed;
  resume 148 passed; 0 failed in each.
- CI-policy Clippy on the workspace, all targets and features: clean.
  Blocking-call budget within budget; changelog sync check up to date.
Not run: native /edit in the TUI on this commit; Linux; Windows.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Test-only and docs-only; no product code changes.

- tui::clipboard::tests::tmux_helper_reports_command_failure failed in pass 1
  of the shared-process lane on 6e2623a (run 36926198166) and passed in
  pass 2. The test writes a script and runs it at once; in a shared process
  another thread can fork while the script is still open for writing, and the
  run then fails with "Text file busy" instead of the script's own exit. The
  cause is inferred from the code, not reproduced. The test now retries while
  it sees that error and prints the error on a failed assertion.
- app-server a_saved_config_change_still_propagates_when_the_caller_goes_away
  failed once on hosted Windows at 3665add (17461 of 17462 passed): its
  200 ms window was too short for the save to reach disk. Now 2 s.
- npm/codewhale/README.md: "The source-candidate wrapper" -> "The wrapper"
  (wording patch from the launch lead's review).

codewhale-tui --lib clipboard: test result: ok. 45 passed; 0 failed.
codewhale-app-server --lib a_saved_config_change: test result: ok. 1 passed;
0 failed. Clippy (CI policy) on both crates, all targets: clean. Blocking-call
budget within budget. npm wrapper tests pass.

Signed-off-by: CodeWhale Bot <bot@codewhale.net>
@Hmbown
Hmbown merged commit 9626357 into main Oct 2, 2026
71 checks passed
@Hmbown
Hmbown deleted the wave/0.10.1-next branch October 2, 2026 00:07
@Hmbown
Hmbown restored the wave/0.10.1-next branch October 2, 2026 00:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants