Skip to content

refactor(commands): adopt portable config policy and status shapes (FEAT-027) - #6832

Merged
Hmbown merged 11 commits into
codewhale-hq:wave/0.10.1-nextfrom
aboimpinto:feat/FEAT-027-adopt-command-shapes-in-tui-config-policy-slice
Oct 6, 2026
Merged

Hmbown merged 11 commits into
codewhale-hq:wave/0.10.1-nextfrom
aboimpinto:feat/FEAT-027-adopt-command-shapes-in-tui-config-policy-slice

Conversation

@aboimpinto

@aboimpinto aboimpinto commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

What and why

FEAT-027 makes /permissions (including its aliases and /config permission-rule routes) and /status independently portable through shared command Shapes while preserving their public behavior. This continues the command adoption after merged #6793.

  • Add narrow permissions/status facets and typed observations. Concrete App access, configuration reads, atomic permission removal and action execution remain in host adapters.
  • Own results/actions in codewhale-command-contract now; this slice has no deferred FEAT-037 outcome dependency. Move existing pure formatting/provenance helpers to shared owners instead of importing TUI services.
  • Compile the actual two-command inventory and helper closure in a separate normal library. Audit its all-target normal dependency graph and reject host/runtime/storage dependencies with negative controls.

The remaining 15 config commands stay in FEAT-028. Whole-group config extraction remains FEAT-044; the migration frontier remains config, core. This PR preserves behavior and introduces no new user-facing command.

Issue

Refs #5316 (partial: EPIC-006 / FEAT-027)
Refs #6145 (partial: command adoption)

How I tested it

Before publication, all nine local feature phases were accepted. The pre-rebase implementation passed:

  • Actual portable library compilation and dependency audit; 12 portable tests and 6 negative controls.
  • CI-profile instrumented workspace nextest: 18,129 passed, zero failed, 31 configured skips. Doctests: 3 passed, 8 ignored.
  • Workspace Clippy with the CI lint flags, formatting, release CLI/TUI build, migration/boundary and release-order guards.
  • Web checks: 653 tests passed. Changed executable Rust production-line coverage: 1,366/1,473 (92.74%).

Rebased on current main (9e19f03e6): all eight commits replayed cleanly; the only range-diff change drops a formatting repair already upstream. Post-rebase formatting, portable library/graph verification, 12 portable tests and 6 negative controls pass. All 71 selected host/helper CI-profile tests pass (zero failed; 14,528 outside the focused selection). Eight hosted workflows require administrator approval; contributor approval returned HTTP 403. Earlier test counts are local evidence, not a claim of hosted CI success.

Hosted verification

CI run 37134544814 and seven other fork workflows await upstream administrator approval. GitGuardian and contribution gate passed. Devin reports "Full review skipped: trial expired and no credits remaining" despite its green status. No actual bot review has run and no review findings are posted. This draft is not yet fully verified.

Checklist

  • One focused change, rebased on current main
  • Existing behavior and extraction boundaries covered by tests
  • No new user-facing feature or registry row required
  • Post-rebase focused checks and hosted checks green

Paulo Aboim Pinto

@aboimpinto
aboimpinto marked this pull request as ready for review October 3, 2026 16:12
@aboimpinto
aboimpinto requested a review from Hmbown as a code owner October 3, 2026 16:12
aboimpinto and others added 3 commits October 3, 2026 20:55
…dows paths

Both platform failures were the same test-side assumption, not a production
regression: the suite assumed the raw `TempDir` path is what the config layer
reports, which only holds on Linux.

The permissions path is resolved through
`codewhale_config::normalize_config_file_path`, so the reported path is
canonical: `/private/var/...` on macOS and `\\?\C:\...` with the long name on
Windows. `crates/config` is untouched by this PR, so this is baseline
behaviour that the Linux-only local gate simply cannot see.

- `config_policy.rs`: assert the view path against the same resolver the
  production path uses (`resolve_permissions_path`) instead of the raw fixture
  path.
- `config_policy_baseline.rs`: replace the canonical workspace form before the
  raw form. Substituting the raw prefix inside the canonical path left a stray
  `/private` behind on macOS (visible as `"/private<WORKSPACE>/permissions.toml"`)
  and missed the verbatim path entirely on Windows.

Reproduced on Linux with a symlinked `TMPDIR` (raw != canonical): both tests
fail identically to the macOS/Windows CI before the change and pass after it.
PR codewhale-hq#6832 Windows CI failed only
idle_managers_sharing_a_store_do_not_poll_it_continuously: two legitimate
startup reloads landed in the zero-reload observation window.

The fixed 2.3s startup sleep runs from manager creation, but each worker
schedules its 2s metadata retry after its first claim completes. A delayed
initial claim can therefore put that retry after the counter reset.

Wait for 2.4s of observed load-counter quiescence, with a 10s deadline,
before starting the unchanged zero-reload measurement. Apply the same
setup to the running-task flush test. Keep task wakeup assertions and
production scheduling unchanged. Continuous periodic reloads time out.

Validation:
- CI-profile nextest, TUI lib, all features: 6 tests run, 6 passed,
  14,593 outside the focused selection.
- Temporary timing harness extracted the real ClaimSchedule and new wait
  helper: a 750ms delayed first claim fails the original fixed-sleep
  assertion, passes with the corrected wait, and an unconditional 2s
  fallback is rejected at the 10s deadline.
- cargo fmt --all -- --check and git diff --check passed.

Hosted Windows verification remains pending the follow-up CI run.

Signed-off-by: Paulo Aboim Pinto <paulo.aboim.pinto@gmail.com>
…oundaries

Replace the PR codewhale-hq#6832 idle-test timing workaround with explicit completion
receipts on the existing task manager's worker/caller boundary.

Each worker owns a bounded inspection mailbox. Every request carries a
oneshot reply, sent after the actual queue operation and schedule update.
Startup awaits an initial receipt from every worker, with cancellation
cleanup, rather than returning merely because workers were spawned.
Receipts describe a per-worker decision, not global quiescence or task
completion. Claimed tasks execute after their inspection receipt; failed
claims return errors and retain their retry/backoff behavior.

The three idle/external-queue regressions now use acknowledged cycles and
controlled executor start/release messages. Fixtures explicitly supply
settled file timestamps, and scheduling tests supply wall-clock inputs.
No fixed startup sleep or observation window establishes success in those
tests. Existing production metadata-settling and retry policy is retained.
Add boundary coverage for all-worker replies, dropped receivers, shutdown,
and corrupt-store recovery; adapt the real process-ownership helper to
retain control of the worker JoinHandle. Code comments document the
completion boundary and why elapsed silence cannot establish it.

This repairs pre-existing task-manager code, independently of FEAT-027's
command-shape changes. The original regression arrived in 309f329 and
its zero-reload contract in 07a6539.

Validation:
- CI-profile nextest, all features: 79 task-manager/ownership tests passed.
- CI-profile nextest: 61 automation/runtime-ownership caller tests passed.
- Production TUI library Clippy with the CI lint flags passed.
- cargo fmt --all -- --check and git diff --check passed.
- Exact extracted scheduling tests: 2 passed; restoring unconditional
  fallback polling makes the settled-queue test fail immediately.

No existing Gherkin scenario owns this internal boundary. The focused
suite exercises actual worker messages, persistence, and subprocess
ownership/restart behavior. Hosted platform CI remains a separate gate.

Signed-off-by: Paulo Aboim Pinto <paulo.aboim.pinto@gmail.com>
@aboimpinto

Copy link
Copy Markdown
Contributor Author

The Windows failure exposed a pre-existing task-manager test assumption: sleeping for 2.3 seconds after manager creation did not establish that every worker had completed its initial claim and scheduled any required retry. This code predates FEAT-027: the original regression test came from 309f3298a (#6573), and its zero-reload requirement from 07a6539fe (#6728).

Commit 1afc0d69b replaces the earlier quiet-period workaround with explicit request/completion messaging:

  • Each worker has a bounded inspection mailbox. A request carries its own oneshot reply, sent after the queue operation and scheduling decision finish. Startup awaits a receipt from every worker and cleans up if startup is cancelled or fails.
  • A receipt describes that worker's inspection. It does not promise global quiescence or completed task execution: pending retries remain explicit, and a claimed task executes after its inspection receipt. Existing filesystem-settling safeguards, retry/backoff, ownership and durability rules remain in place.
  • The idle-store, running-task-flush and external-queue tests now use acknowledged inspection cycles and executor start/release messages. Fixtures explicitly represent settled queue timestamps. The tests assert completed operations and scheduling outcomes instead of inferring completion from elapsed silence. Their timeouts only detect stuck operations.
  • Additional boundary tests cover every-worker replies, abandoned reply receivers, shutdown, and store failure/recovery. Existing real subprocess ownership/restart coverage was adapted and rerun. Code comments explain the completion boundary and its limits.

Local verification on Linux:

  • Task manager and process ownership: 79 tests run, 79 passed.
  • Automation and runtime-ownership callers: 61 tests run, 61 passed.
  • Production TUI-library Clippy with CI lint flags, formatting and whitespace checks passed.
  • The exact extracted scheduling tests pass; restoring unconditional fallback polling makes the settled-queue regression fail immediately, without sleeping.

No existing Gherkin scenario covers this internal worker boundary; verification uses the real worker/store and subprocess integration tests above. Hosted Windows/macOS/Linux CI for this new commit remains a separate gate; these local results do not claim hosted success.

Paulo Aboim Pinto

@Hmbown Hmbown added this to the v0.10.1 milestone Oct 4, 2026
@Hmbown Hmbown modified the milestones: v0.10.1, v0.11 Oct 5, 2026
@Hmbown
Hmbown changed the base branch from main to wave/0.10.1-next October 6, 2026 05:52
Hmbown pushed a commit that referenced this pull request Oct 6, 2026
Reconcile the complete contributions from #6832 (@aboimpinto), #6867
(@hodeswildsmith455-boop), and #6805 (@LIghtJUNction) with the current
Engine, provider identities, reviewed-plugin policy, and task lifecycle.
Original contributor histories are recorded by subsequent resolved merges.

Fix the already integrated contributor cases: snapshot corruption is an
explicit unavailable/error result (#6817), malformed locales cannot select
an incidental script (#6860), image metadata uses the exact uploaded bytes
and respects available decoders (#6858), automation deletion waits for
actual scheduler reconciliation (#6864), and blocking trust/skill reads stay
off the async executor (#6869). Preserve #6857's compaction regression.

Extend #6872's human-wait lifecycle guard to approval/elevation cards;
retire only the matching ended parent request and refresh activity only
after a delivered decision. Enforce configured finite approval deadlines in
the Engine, including deadline/cancellation races and durable receipts.

Serialize Native Windows ACL admission/retirement across Core processes
with a logon-scoped kernel mutex, preserving exact SID/object validation.
Add an actual child-process lock test; serialize DSH host tests in the
existing extension-host lane. Windows execution proof remains hosted CI.

Reconcile the vendored computer-use plugin with canonical main a656f67455fc
while preserving Core's 0.12.1 embedding contract. Canonical b47/a656 tree
passed Ubuntu/macOS/Windows source and package gates, including 28/28
Windows-focused tests and the controlled desktop fixture; this is separate
from the new Engine head's CI verdict.

Partial adaptation of the discovery-cache priority portion from PR #6393
by @AdityaVG13 (original ac33dd4). Preserve the best match under count
and byte limits without importing the unfinished echolocation/fork design;
the broader draft remains open.

Validation:
- npm test: 1286 passed, 0 failed, 7 skipped; web 767/767.
- npm run check:web: lint, typecheck and production build passed.
- Affected Rust selection: 801/803 initially passed; the two fixture/lifecycle
  expectation failures were corrected and each passed a focused rerun.
- Additional focused Rust: approval 28/28, discovery cache 11/11,
  OrcaRouter synthetic catalog 3/3, and 33/33 lifecycle/API/routing checks.
- Final CI-repair selection: 37/39 initially passed; the BMP feature-proxy
  and feature-registry summary failures were corrected; both corrected tests passed (2/2, 0 failures).
- Qualified Clippy: six packages, all targets/all features, passed with
  the CI style allowances. Portable no-default-feature check passed;
  portable policy verifier 6/6 passed; formatting and diff checks passed.
- Runtime contract: 55 measured metrics passed after explicit remeasurement;
  all 21 structural identities were unchanged. Twelve byte/token-estimate
  budgets account for bounded child-wait disclosure and contributor locale
  descriptions; no runtime field/prompt was removed to lower the budget.
- Persistence budget was not qualified locally: the checker requires a
  clean tree and this shared checkout retains an unrelated operator file.
  Clean hosted CI, fresh stamped build and real DeepSeek TUI acceptance
  remain required before the integration PR can merge to main.

Refs #6872, #6843, #6795.

Co-authored-by: Paulo Aboim Pinto <paulo.aboim.pinto@gmail.com>
Co-authored-by: hodeswildsmith455-boop <hodeswildsmith455-boop@users.noreply.github.com>
Co-authored-by: LIghtJUNction <lightjunction.me@gmail.com>
Co-authored-by: AdityaVG13 <adityavgcode@gmail.com>
Signed-off-by: CodeWhale Bot <bot@codewhale.net>
@Hmbown
Hmbown merged commit 7d3fe35 into codewhale-hq:wave/0.10.1-next Oct 6, 2026
29 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants