refactor(commands): adopt portable config policy and status shapes (FEAT-027) - #6832
Conversation
…dows paths Both platform failures were the same test-side assumption, not a production regression: the suite assumed the raw `TempDir` path is what the config layer reports, which only holds on Linux. The permissions path is resolved through `codewhale_config::normalize_config_file_path`, so the reported path is canonical: `/private/var/...` on macOS and `\\?\C:\...` with the long name on Windows. `crates/config` is untouched by this PR, so this is baseline behaviour that the Linux-only local gate simply cannot see. - `config_policy.rs`: assert the view path against the same resolver the production path uses (`resolve_permissions_path`) instead of the raw fixture path. - `config_policy_baseline.rs`: replace the canonical workspace form before the raw form. Substituting the raw prefix inside the canonical path left a stray `/private` behind on macOS (visible as `"/private<WORKSPACE>/permissions.toml"`) and missed the verbatim path entirely on Windows. Reproduced on Linux with a symlinked `TMPDIR` (raw != canonical): both tests fail identically to the macOS/Windows CI before the change and pass after it.
PR codewhale-hq#6832 Windows CI failed only idle_managers_sharing_a_store_do_not_poll_it_continuously: two legitimate startup reloads landed in the zero-reload observation window. The fixed 2.3s startup sleep runs from manager creation, but each worker schedules its 2s metadata retry after its first claim completes. A delayed initial claim can therefore put that retry after the counter reset. Wait for 2.4s of observed load-counter quiescence, with a 10s deadline, before starting the unchanged zero-reload measurement. Apply the same setup to the running-task flush test. Keep task wakeup assertions and production scheduling unchanged. Continuous periodic reloads time out. Validation: - CI-profile nextest, TUI lib, all features: 6 tests run, 6 passed, 14,593 outside the focused selection. - Temporary timing harness extracted the real ClaimSchedule and new wait helper: a 750ms delayed first claim fails the original fixed-sleep assertion, passes with the corrected wait, and an unconditional 2s fallback is rejected at the 10s deadline. - cargo fmt --all -- --check and git diff --check passed. Hosted Windows verification remains pending the follow-up CI run. Signed-off-by: Paulo Aboim Pinto <paulo.aboim.pinto@gmail.com>
…oundaries Replace the PR codewhale-hq#6832 idle-test timing workaround with explicit completion receipts on the existing task manager's worker/caller boundary. Each worker owns a bounded inspection mailbox. Every request carries a oneshot reply, sent after the actual queue operation and schedule update. Startup awaits an initial receipt from every worker, with cancellation cleanup, rather than returning merely because workers were spawned. Receipts describe a per-worker decision, not global quiescence or task completion. Claimed tasks execute after their inspection receipt; failed claims return errors and retain their retry/backoff behavior. The three idle/external-queue regressions now use acknowledged cycles and controlled executor start/release messages. Fixtures explicitly supply settled file timestamps, and scheduling tests supply wall-clock inputs. No fixed startup sleep or observation window establishes success in those tests. Existing production metadata-settling and retry policy is retained. Add boundary coverage for all-worker replies, dropped receivers, shutdown, and corrupt-store recovery; adapt the real process-ownership helper to retain control of the worker JoinHandle. Code comments document the completion boundary and why elapsed silence cannot establish it. This repairs pre-existing task-manager code, independently of FEAT-027's command-shape changes. The original regression arrived in 309f329 and its zero-reload contract in 07a6539. Validation: - CI-profile nextest, all features: 79 task-manager/ownership tests passed. - CI-profile nextest: 61 automation/runtime-ownership caller tests passed. - Production TUI library Clippy with the CI lint flags passed. - cargo fmt --all -- --check and git diff --check passed. - Exact extracted scheduling tests: 2 passed; restoring unconditional fallback polling makes the settled-queue test fail immediately. No existing Gherkin scenario owns this internal boundary. The focused suite exercises actual worker messages, persistence, and subprocess ownership/restart behavior. Hosted platform CI remains a separate gate. Signed-off-by: Paulo Aboim Pinto <paulo.aboim.pinto@gmail.com>
|
The Windows failure exposed a pre-existing task-manager test assumption: sleeping for 2.3 seconds after manager creation did not establish that every worker had completed its initial claim and scheduled any required retry. This code predates FEAT-027: the original regression test came from Commit
Local verification on Linux:
No existing Gherkin scenario covers this internal worker boundary; verification uses the real worker/store and subprocess integration tests above. Hosted Windows/macOS/Linux CI for this new commit remains a separate gate; these local results do not claim hosted success. Paulo Aboim Pinto |
Reconcile the complete contributions from #6832 (@aboimpinto), #6867 (@hodeswildsmith455-boop), and #6805 (@LIghtJUNction) with the current Engine, provider identities, reviewed-plugin policy, and task lifecycle. Original contributor histories are recorded by subsequent resolved merges. Fix the already integrated contributor cases: snapshot corruption is an explicit unavailable/error result (#6817), malformed locales cannot select an incidental script (#6860), image metadata uses the exact uploaded bytes and respects available decoders (#6858), automation deletion waits for actual scheduler reconciliation (#6864), and blocking trust/skill reads stay off the async executor (#6869). Preserve #6857's compaction regression. Extend #6872's human-wait lifecycle guard to approval/elevation cards; retire only the matching ended parent request and refresh activity only after a delivered decision. Enforce configured finite approval deadlines in the Engine, including deadline/cancellation races and durable receipts. Serialize Native Windows ACL admission/retirement across Core processes with a logon-scoped kernel mutex, preserving exact SID/object validation. Add an actual child-process lock test; serialize DSH host tests in the existing extension-host lane. Windows execution proof remains hosted CI. Reconcile the vendored computer-use plugin with canonical main a656f67455fc while preserving Core's 0.12.1 embedding contract. Canonical b47/a656 tree passed Ubuntu/macOS/Windows source and package gates, including 28/28 Windows-focused tests and the controlled desktop fixture; this is separate from the new Engine head's CI verdict. Partial adaptation of the discovery-cache priority portion from PR #6393 by @AdityaVG13 (original ac33dd4). Preserve the best match under count and byte limits without importing the unfinished echolocation/fork design; the broader draft remains open. Validation: - npm test: 1286 passed, 0 failed, 7 skipped; web 767/767. - npm run check:web: lint, typecheck and production build passed. - Affected Rust selection: 801/803 initially passed; the two fixture/lifecycle expectation failures were corrected and each passed a focused rerun. - Additional focused Rust: approval 28/28, discovery cache 11/11, OrcaRouter synthetic catalog 3/3, and 33/33 lifecycle/API/routing checks. - Final CI-repair selection: 37/39 initially passed; the BMP feature-proxy and feature-registry summary failures were corrected; both corrected tests passed (2/2, 0 failures). - Qualified Clippy: six packages, all targets/all features, passed with the CI style allowances. Portable no-default-feature check passed; portable policy verifier 6/6 passed; formatting and diff checks passed. - Runtime contract: 55 measured metrics passed after explicit remeasurement; all 21 structural identities were unchanged. Twelve byte/token-estimate budgets account for bounded child-wait disclosure and contributor locale descriptions; no runtime field/prompt was removed to lower the budget. - Persistence budget was not qualified locally: the checker requires a clean tree and this shared checkout retains an unrelated operator file. Clean hosted CI, fresh stamped build and real DeepSeek TUI acceptance remain required before the integration PR can merge to main. Refs #6872, #6843, #6795. Co-authored-by: Paulo Aboim Pinto <paulo.aboim.pinto@gmail.com> Co-authored-by: hodeswildsmith455-boop <hodeswildsmith455-boop@users.noreply.github.com> Co-authored-by: LIghtJUNction <lightjunction.me@gmail.com> Co-authored-by: AdityaVG13 <adityavgcode@gmail.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
What and why
FEAT-027 makes
/permissions(including its aliases and/configpermission-rule routes) and/statusindependently portable through shared command Shapes while preserving their public behavior. This continues the command adoption after merged #6793.codewhale-command-contractnow; this slice has no deferred FEAT-037 outcome dependency. Move existing pure formatting/provenance helpers to shared owners instead of importing TUI services.The remaining 15 config commands stay in FEAT-028. Whole-group config extraction remains FEAT-044; the migration frontier remains
config, core. This PR preserves behavior and introduces no new user-facing command.Issue
Refs #5316 (partial: EPIC-006 / FEAT-027)
Refs #6145 (partial: command adoption)
How I tested it
Before publication, all nine local feature phases were accepted. The pre-rebase implementation passed:
Rebased on current
main(9e19f03e6): all eight commits replayed cleanly; the only range-diff change drops a formatting repair already upstream. Post-rebase formatting, portable library/graph verification, 12 portable tests and 6 negative controls pass. All 71 selected host/helper CI-profile tests pass (zero failed; 14,528 outside the focused selection). Eight hosted workflows require administrator approval; contributor approval returned HTTP 403. Earlier test counts are local evidence, not a claim of hosted CI success.Hosted verification
CI run 37134544814 and seven other fork workflows await upstream administrator approval. GitGuardian and contribution gate passed. Devin reports "Full review skipped: trial expired and no credits remaining" despite its green status. No actual bot review has run and no review findings are posted. This draft is not yet fully verified.
Checklist
mainPaulo Aboim Pinto