Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
87 commits
Select commit Hold shift + click to select a range
f66c217
fix(session): finish descriptor-bound artifact cleanup
Jul 30, 2026
3345681
fix(session): keep live migration lease ownership
Jul 30, 2026
f4109a7
fix(session): bind lock retirement and detach scrub roots
Jul 30, 2026
1a3b3e7
fix(session): close cleanup authority race windows
Jul 30, 2026
1ed9c2e
fix(session): retain replacement and cleanup authorities
Jul 30, 2026
81fe50a
fix(session): bind retained cleanup receipts at commit
Jul 30, 2026
1e68249
fix(session): close final cleanup authority races
Jul 30, 2026
74f2785
test(natives): preserve DACL-only Windows access
Jul 30, 2026
afb566c
fix(session): retain final cleanup proof fences
Jul 31, 2026
68cb9e3
fix(session): make final cleanup commits exclusive
Jul 31, 2026
fc01054
fix(session): reconcile proven retained cleanup
Jul 31, 2026
e9a8547
fix(session): complete proven descriptor cleanup
Jul 31, 2026
475d60c
test(session): align retained cleanup expectations
Jul 31, 2026
a49a3f5
fix(session): finalize exact cleanup authority
Jul 31, 2026
6834041
fix(natives): preserve Windows authority while completing POSIX cleanup
Jul 31, 2026
72b0982
fix(session): preserve exact cleanup authority across platforms
Jul 31, 2026
c08fb79
fix(telegram): regenerate exact authority manifest
Jul 31, 2026
a484ad2
style(session): format final cleanup contracts
Jul 31, 2026
03ed107
fix(session): finalize terminal cleanup replay
Jul 31, 2026
e5f28a2
fix(session): fence final cleanup parents
Jul 31, 2026
d1d2d81
fix(session): type durable scrub evidence
Jul 31, 2026
21d95b5
fix(session): preserve final retained cleanup proof
Jul 31, 2026
612a3c9
fix(session): fence final replacement and cleanup proof
Jul 31, 2026
4277c11
fix(natives): accept omitted legacy link authority
Jul 31, 2026
0535cd8
fix(session): continue exact artifact cleanup safely
Jul 31, 2026
b5cd1ae
fix(session): bind managed cleanup retained authority
Jul 31, 2026
ca2fcf2
fix(session): accept durable transcript replay authority
Jul 31, 2026
f9a15a3
fix(session): propagate replayed artifact durability
Jul 31, 2026
59c7643
fix(broker): restore exact replay authority fences
Jul 31, 2026
5782cc7
fix(session): advance durable cleanup replay phases
Jul 31, 2026
b6c42ed
fix(session): revalidate scrubbed roots on restart
Jul 31, 2026
4b53cda
fix(session): preserve finalization ordering and replay proof
Jul 31, 2026
088250e
fix(session): preserve predecessor identity through terminal cleanup
Jul 31, 2026
2d74d61
fix(session): preserve exact successor and replay identity
Jul 31, 2026
ae3ddfe
fix(session): authorize detached transcript replay target
Jul 31, 2026
95e79ed
fix(session): complete managed transcript replay
Jul 31, 2026
055463d
test(broker): preserve retained cleanup authority fixtures
Jul 31, 2026
7179789
test(broker): model scrubbed lifecycle authority
Jul 31, 2026
1e78498
test(acp): assert exact scrubbed cleanup authority
Jul 31, 2026
5a9c5f1
fix(session): finalize retained replay authority ordering
Jul 31, 2026
d313223
fix(session): verify final retained authority before terminal cleanup
Jul 31, 2026
ea96363
fix(session): remove verified terminal transcript placeholders
Jul 31, 2026
396eacc
test(broker): reconcile verified empty transcript aliases
Jul 31, 2026
0d572a9
fix(broker): replay scrubbed lifecycle quarantine evidence
Jul 31, 2026
f7d02de
fix(broker): bind legacy metadata replay authority
Jul 31, 2026
aef6aa1
fix(session): retire exact detached transcript placeholder
Jul 31, 2026
4556b41
fix(session): restore retained artifact content binding
Jul 31, 2026
1f6d7fd
fix(session): keep retained placeholders fail-pending
Jul 31, 2026
2b867ec
fix(session): terminalize scrubbed bytes without unsafe unlink
Jul 31, 2026
c4c1be0
fix(broker): bind ready replay to exact bytes
Jul 31, 2026
c6968db
fix(session): bind Windows replacement to exact identities
Jul 31, 2026
f447386
fix(session): preserve exact Windows replacement authority
Jul 31, 2026
13caa69
fix(session): retain restored staging on replacement failure
Jul 31, 2026
a7d1d1b
fix(natives): bind exact restore to parent identity
Jul 31, 2026
c369ed0
fix(natives): require exact parent authority for restore and replace
Jul 31, 2026
615cdb2
fix(session): bind artifact restores to parent authority
Jul 31, 2026
bcc8856
test(natives): require parent authority for Windows restore
Jul 31, 2026
59ee8ae
test(natives): cover required Windows parent authority
Jul 31, 2026
403642c
fix(session): persist cleanup parent authority
gaebal-gajae Jul 31, 2026
01aba32
fix(natives): atomically publish exact Windows replacement
gaebal-gajae Jul 31, 2026
d2fc41d
fix(natives): allow exact destination replacement sharing
gaebal-gajae Jul 31, 2026
ba3eeac
fix(session): route managed replacement through exact authority
gaebal-gajae Jul 31, 2026
803e316
fix(session): enforce exact authority across all managed routes
gaebal-gajae Jul 31, 2026
bc7eebd
fix(session): bind restore and receipt cleanup authority
gaebal-gajae Jul 31, 2026
5eddcf8
fix(session): fail closed on unsafe Windows replacement
gaebal-gajae Jul 31, 2026
2662625
fix(session): bind replacement publication state transitions
gaebal-gajae Jul 31, 2026
0caf161
fix(session): reconcile exact replacement with current dev
gaebal-gajae Jul 31, 2026
7c98fe8
fix(session): publish managed replacement when destination is absent
gaebal-gajae Jul 31, 2026
2a97f81
fix(natives): retain exact staged handle after detach
gaebal-gajae Jul 31, 2026
776e08d
fix(session): preserve prepared artifact parent authority
gaebal-gajae Jul 31, 2026
3a50605
fix(natives): exchange-bound exact Windows replacement
gaebal-gajae Jul 31, 2026
f6a9956
fix(natives): exchange-bind exact POSIX restore
gaebal-gajae Jul 31, 2026
f937766
fix(session): retain exact restore cleanup authority
gaebal-gajae Jul 31, 2026
b18cae4
fix(natives): retain replaced destination handle through cleanup
gaebal-gajae Jul 31, 2026
fe66a55
fix(session): propagate retained replacement predecessor authority
gaebal-gajae Jul 31, 2026
d85a284
fix(session): propagate predecessor and fail closed on POSIX replace
gaebal-gajae Jul 31, 2026
6639c14
fix(session): distinguish committed predecessor cleanup
gaebal-gajae Jul 31, 2026
8bc397e
fix(session): close retained tree and committed predecessor authority
gaebal-gajae Jul 31, 2026
fffb7ef
fix(session): preserve contracted retained authority
gaebal-gajae Jul 31, 2026
914edb4
fix(session): surface committed predecessor cleanup pending
gaebal-gajae Jul 31, 2026
a3c2536
fix(session): reconcile committed predecessor immediately
gaebal-gajae Jul 31, 2026
39a3277
fix(session): bind predecessor cleanup to original authority
gaebal-gajae Jul 31, 2026
ebe36ea
fix(session): retain predecessor cleanup pending authority
gaebal-gajae Jul 31, 2026
052caee
fix(session): persist predecessor cleanup authority
gaebal-gajae Jul 31, 2026
33156fb
fix(session): persist BigInt-safe predecessor authority
gaebal-gajae Jul 31, 2026
80ac243
fix(session): validate and reconcile predecessor receipts
gaebal-gajae Jul 31, 2026
201333a
chore(telegram): regenerate generation manifest after dev rebase
gaebal-gajae Aug 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 14 additions & 3 deletions .github/workflows/dev-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -257,6 +257,8 @@ jobs:
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
bun test ./packages/coding-agent/test/session/resident-cache-win32-gate.windows.test.ts
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
bun test ./packages/coding-agent/test/session/managed-lock-lease.windows.test.ts
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
bun test ./packages/coding-agent/test/sdk-session-directory.windows.test.ts
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }

Expand Down Expand Up @@ -301,13 +303,20 @@ jobs:
windows-telegram-daemon-safety:
name: Windows Telegram daemon safety
needs: [affected-plan]
if: ${{ needs.affected-plan.outputs.relevant == 'true' && (contains(needs.affected-plan.outputs.changed_paths, 'telegram-daemon') || contains(needs.affected-plan.outputs.changed_paths, 'chat-daemon-control.ts') || contains(needs.affected-plan.outputs.changed_paths, 'packages/coding-agent/src/sdk/broker/process-incarnation.ts') || contains(needs.affected-plan.outputs.changed_paths, 'daemon-control.test.ts') || contains(needs.affected-plan.outputs.changed_paths, 'notifications-telegram-daemon.test.ts') || contains(needs.affected-plan.outputs.changed_paths, 'chat-daemon') || contains(needs.affected-plan.outputs.changed_paths, 'crates/pi-natives/src/path_identity.rs') || contains(needs.affected-plan.outputs.changed_paths, 'crates/pi-natives/src/ps.rs') || contains(needs.affected-plan.outputs.changed_paths, 'crates/pi-shell/src/process.rs') || contains(needs.affected-plan.outputs.changed_paths, 'packages/natives/native/index.d.ts')) }}
if: ${{ needs.affected-plan.outputs.relevant == 'true' && (contains(needs.affected-plan.outputs.changed_paths, 'telegram-daemon') || contains(needs.affected-plan.outputs.changed_paths, 'chat-daemon-control.ts') || contains(needs.affected-plan.outputs.changed_paths, 'packages/coding-agent/src/sdk/broker/process-incarnation.ts') || contains(needs.affected-plan.outputs.changed_paths, 'daemon-control.test.ts') || contains(needs.affected-plan.outputs.changed_paths, 'notifications-telegram-daemon.test.ts') || contains(needs.affected-plan.outputs.changed_paths, 'chat-daemon') || contains(needs.affected-plan.outputs.changed_paths, 'crates/pi-natives/src/path_identity.rs') || contains(needs.affected-plan.outputs.changed_paths, 'crates/pi-natives/src/ps.rs') || contains(needs.affected-plan.outputs.changed_paths, 'crates/pi-shell/src/process.rs') || contains(needs.affected-plan.outputs.changed_paths, 'packages/natives/native/index.d.ts') || contains(needs.affected-plan.outputs.changed_paths, 'packages/natives/native/index.js') || contains(needs.affected-plan.outputs.changed_paths, 'packages/natives/test/path-identity-windows.test.ts')) }}
runs-on: windows-latest
timeout-minutes: 60
env:
CI_DEV_SOURCE_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
- name: Verify checked-out source head
shell: pwsh
run: |
$head = (git rev-parse HEAD).Trim()
if ($head -ne $env:CI_DEV_SOURCE_SHA) { throw "Checked-out SHA $head does not match $env:CI_DEV_SOURCE_SHA" }
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
with:
bun-version: "1.3.14"
Expand Down Expand Up @@ -345,6 +354,8 @@ jobs:
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
bun test ./packages/natives/test/native.test.ts --test-name-pattern 'signals only the pinned root process'
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
bun test ./packages/natives/test/path-identity-windows.test.ts
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }

# Native addon build runs at most once per run and publishes the built `.node`
# files as an artifact the runtime-dependent shards download. A content-hash
Expand Down Expand Up @@ -705,7 +716,7 @@ jobs:
CI_DEV_TELEGRAM_GUARD_RESULT: ${{ needs.telegram-daemon-generation.result }}
CI_DEV_TELEGRAM_GUARD_REQUIRED: ${{ needs.affected-plan.outputs.relevant }}
CI_DEV_TELEGRAM_WINDOWS_RESULT: ${{ needs.windows-telegram-daemon-safety.result }}
CI_DEV_TELEGRAM_WINDOWS_REQUIRED: ${{ contains(needs.affected-plan.outputs.changed_paths, 'telegram-daemon') || contains(needs.affected-plan.outputs.changed_paths, 'chat-daemon-control.ts') || contains(needs.affected-plan.outputs.changed_paths, 'packages/coding-agent/src/sdk/broker/process-incarnation.ts') || contains(needs.affected-plan.outputs.changed_paths, 'daemon-control.test.ts') || contains(needs.affected-plan.outputs.changed_paths, 'notifications-telegram-daemon.test.ts') || contains(needs.affected-plan.outputs.changed_paths, 'chat-daemon') || contains(needs.affected-plan.outputs.changed_paths, 'crates/pi-natives/src/path_identity.rs') || contains(needs.affected-plan.outputs.changed_paths, 'crates/pi-natives/src/ps.rs') || contains(needs.affected-plan.outputs.changed_paths, 'crates/pi-shell/src/process.rs') || contains(needs.affected-plan.outputs.changed_paths, 'packages/natives/native/index.d.ts') }}
CI_DEV_TELEGRAM_WINDOWS_REQUIRED: ${{ contains(needs.affected-plan.outputs.changed_paths, 'telegram-daemon') || contains(needs.affected-plan.outputs.changed_paths, 'chat-daemon-control.ts') || contains(needs.affected-plan.outputs.changed_paths, 'packages/coding-agent/src/sdk/broker/process-incarnation.ts') || contains(needs.affected-plan.outputs.changed_paths, 'daemon-control.test.ts') || contains(needs.affected-plan.outputs.changed_paths, 'notifications-telegram-daemon.test.ts') || contains(needs.affected-plan.outputs.changed_paths, 'chat-daemon') || contains(needs.affected-plan.outputs.changed_paths, 'crates/pi-natives/src/path_identity.rs') || contains(needs.affected-plan.outputs.changed_paths, 'crates/pi-natives/src/ps.rs') || contains(needs.affected-plan.outputs.changed_paths, 'crates/pi-shell/src/process.rs') || contains(needs.affected-plan.outputs.changed_paths, 'packages/natives/native/index.d.ts') || contains(needs.affected-plan.outputs.changed_paths, 'packages/natives/native/index.js') || contains(needs.affected-plan.outputs.changed_paths, 'packages/natives/test/path-identity-windows.test.ts') }}
CI_DEV_DARWIN_ARM64_TAB_WORKER_SMOKE_RESULT: ${{ needs.affected-darwin-arm64-tab-worker-smoke.result }}
CI_DEV_DARWIN_ARM64_TAB_WORKER_SMOKE_REQUIRED: ${{ needs.affected-plan.outputs.has_darwin_arm64_tab_worker_smoke }}
run: bun scripts/ci-dev-affected.ts --write-affected-evidence
Expand Down Expand Up @@ -752,7 +763,7 @@ jobs:
CI_DEV_TELEGRAM_GUARD_RESULT: ${{ needs.telegram-daemon-generation.result }}
CI_DEV_TELEGRAM_GUARD_REQUIRED: ${{ needs.affected-plan.outputs.relevant }}
CI_DEV_TELEGRAM_WINDOWS_RESULT: ${{ needs.windows-telegram-daemon-safety.result }}
CI_DEV_TELEGRAM_WINDOWS_REQUIRED: ${{ contains(needs.affected-plan.outputs.changed_paths, 'telegram-daemon') || contains(needs.affected-plan.outputs.changed_paths, 'chat-daemon-control.ts') || contains(needs.affected-plan.outputs.changed_paths, 'packages/coding-agent/src/sdk/broker/process-incarnation.ts') || contains(needs.affected-plan.outputs.changed_paths, 'daemon-control.test.ts') || contains(needs.affected-plan.outputs.changed_paths, 'notifications-telegram-daemon.test.ts') || contains(needs.affected-plan.outputs.changed_paths, 'chat-daemon') || contains(needs.affected-plan.outputs.changed_paths, 'crates/pi-natives/src/path_identity.rs') || contains(needs.affected-plan.outputs.changed_paths, 'crates/pi-natives/src/ps.rs') || contains(needs.affected-plan.outputs.changed_paths, 'crates/pi-shell/src/process.rs') || contains(needs.affected-plan.outputs.changed_paths, 'packages/natives/native/index.d.ts') }}
CI_DEV_TELEGRAM_WINDOWS_REQUIRED: ${{ contains(needs.affected-plan.outputs.changed_paths, 'telegram-daemon') || contains(needs.affected-plan.outputs.changed_paths, 'chat-daemon-control.ts') || contains(needs.affected-plan.outputs.changed_paths, 'packages/coding-agent/src/sdk/broker/process-incarnation.ts') || contains(needs.affected-plan.outputs.changed_paths, 'daemon-control.test.ts') || contains(needs.affected-plan.outputs.changed_paths, 'notifications-telegram-daemon.test.ts') || contains(needs.affected-plan.outputs.changed_paths, 'chat-daemon') || contains(needs.affected-plan.outputs.changed_paths, 'crates/pi-natives/src/path_identity.rs') || contains(needs.affected-plan.outputs.changed_paths, 'crates/pi-natives/src/ps.rs') || contains(needs.affected-plan.outputs.changed_paths, 'crates/pi-shell/src/process.rs') || contains(needs.affected-plan.outputs.changed_paths, 'packages/natives/native/index.d.ts') || contains(needs.affected-plan.outputs.changed_paths, 'packages/natives/native/index.js') || contains(needs.affected-plan.outputs.changed_paths, 'packages/natives/test/path-identity-windows.test.ts') }}
steps:
- name: Fail closed on producer and live dependency results
env:
Expand Down
Loading
Loading