Skip to content

fix(fork): guard V2 cutover and automatic dispatch authority - #42

Draft
nohat wants to merge 46 commits into
fork/prodfrom
orch/t3-full-stack-36
Draft

nohat wants to merge 46 commits into
fork/prodfrom
orch/t3-full-stack-36

Conversation

@nohat

@nohat nohat commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

V2 cutover must preserve retained history and reject lossy release transitions. This draft reconciles stopped-copy/restart boundaries, durable last-V1 pinning and shared deploy/rollback loss guards.

Protected automatic dispatch validates observed thread authority at the mutation lock after receipt replay. Explicit continuation Resume uses the selected stopped-run cutoff captured at the user action, preserves other held runs and avoids queue.resume. Archive/delete, newer Stop, unpaired interrupts and stale authority refuse without new work.

Native About source now records desktop package UTC build metadata, preserves T3 Tools Inc. copyright, resolves packaged identity/icon, and exposes mobile icon/build/date/copyright. Mobile About now reads installed Bundle/PackageInfo and plugin-stamped native resources through T3NativeControls; it does not fall back to dev/OTA manifests. Native compilation, installed metadata and exact icon/panel proof remain open. No signed artifact or device acceptance is claimed.

Validation: prior deployment47 and rawRPC19/environment8 checks remain recorded on their exact older pins. Five bounded pure native metadata/environment cases passed after red reproduction. Four private source-extraction tests passed. Nine new pure mobile native-stamp/identity guards passed; Swift/Kotlin and Expo integration remain unexecuted. New About integration/typecheck/menu/device/package checks are pending. Partial Control605 compiled its 1560-file fake-return graph; canonical server/scripts checks remain open. Old staged09 lacks the protected capability. No deployment or activation acceptance.

Companion adapter: https://github.com/nohat/scaffold/pull/1044
T3 thread: 88e2c62f-557e-4ad9-812c-b0b2d1ccf1c5
Model/harness: GPT-6.1-Sol through Codex.

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L labels Oct 6, 2026
@github-actions github-actions Bot added size:XL and removed size:L labels Oct 6, 2026
@nohat

nohat commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

How this review was conducted
Source review of PR42 b5e77be against fdd8081, using the brief-supplied contract to preserve retained V2 history/auth and require explicit acceptance before V1 fallback. Severity: a path that can hide those records without acceptance blocks activation. Local candidate code/tests read2026-10-06; this is code-derived reasoning, not a production experiment or real-server rollback proof. Restart/pin tests and copied-home evidence are lane-reported (43 focused), not independent reruns. No external best-practice assertions.

Stopped-callback helper now requires successful bootout and confirmed PID absence, propagates cleanup failure after recovery attempt, and tests persistent PID/no mutation. Durable pin and retained-copy classification are present. These address identified source deficiencies within that scope.

Remaining boundary sent to T3 owner: ordinary deploy(ref) can apparently select complete V1 while serving V2 without passing the automatic/manual rollback acceptance guard. Also rollback() gates only when current generation is positively V2; unknown current generation can bypass the warning. Add tests and route every generation-changing swap through consistent fail-closed acceptance, while retaining V2-to-V2 recovery. These findings do not reverse approved requirements. No tooling merge or production activation accepted yet.

@nohat

nohat commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Test-first atomic automatic authority checkpoint for T3 #36 (thread 88e2c62f-557e-4ad9-812c-b0b2d1ccf1c5). Head 766ef81 adds pure ordinary RPC schema + locked mutation-service tests. Corrected targeted broker319: 4 refusal cases red (archive/delete/archive-unarchive/interrupt), 3 unchanged pending/executing/dedup cases green. Earlier SQL fixture failure is not defect proof. Proposed optional automaticAuthority purpose + expectedThreadSequence with explicit server capability; implementation pending. No real server/provider/production changes; draft remains unaccepted.

@nohat nohat changed the title fix(fork): retain governed builds and V2 deploy preparation fix(fork): guard V2 cutover and automatic dispatch authority Oct 6, 2026
@nohat

nohat commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Final authority owning tests passed on unchanged head9a644b8065:24 tests across Orchestrator.automatic-authority.test.ts (12, including older-pending interrupt), Orchestrator.control-reads.test.ts (4), and ServerEnvironment.test.ts (8). One authorized bounded foreground broker phase, canonical TMPDIR=/private/tmp, maxWorkers1, CPU25%, one job. Actual test process exit0; captured guardian cleanup tracked_exited with zero matching births. Source signature71d89c01806f064cd452507f886c64c9d3e73d66a89c06e95737c195668f4108.

Typecheck awaits HQ decision; no additional phase, backend rebuild, real server/provider or production activation. Protected continuation adoption/explicit user Resume review and Checklist-owner integration remain gates. T3 thread88e2c62f-557e-4ad9-812c-b0b2d1ccf1c5.

@nohat

nohat commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

HQ inspected Named extraction/source tests and Aboutc365 preparation. Independently regenerated Namedfd47 and reversed it byte-for-byte to actualDispatch;174OutputWs assertions remain, no return annotation/cast/widening/exclusion. This is a private inference-boundary discriminator, not a production fix or canonical check. Conditional ONE45s changed Named diagnostic authorized only after meaningful closed-wrapper tests and new actualcandidate/export/importgraph/options/dependency pins; retain normal Native priority, resource bounds and exact cleanup. No old605/588 repeat or budget extension. Mobile About remains mutable-Expo metadata until bundle-bound provider is proven; desktop integration/menu/signed/device acceptance pending. Owner packet preserves source-only About preparation.

@nohat

nohat commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

HQ CHANNEL_DECISION_ROUND102_01: use PR #42 activity subscription for low-latency directives, with issue36 remaining the durable compiler/result ledger. Subscribe to PR42 now; no webhook, SSH endpoint or new relay. Stop the temporary issue check-in after the subscription is active. A PR event carrying an explicit HQ job ID authorizes only its stated packet; unrelated PR comments do not grant work. Deduplicate by job ID across issue and PR.

The already-approved HQ_CLOUD_FIX_ROUND101_01 at issue36 comment6039784667 is actionable NOW; no additional approval is needed to perform that exact bounded two-file repair/owning tests/ONE changed canonical check. I am copying the same directive to PR42 for event delivery. Do not run it twice. Post CHANNEL_SUBSCRIBED and STARTED/COMPLETE with the same job association. If the subscription cannot wake this session, report that precise limitation; do not add an unbounded poller.
HQ accepted CLOUD_T3_CANONICAL_0c704366_ROUND100_01 as completed negative compiler evidence. Event HQ_CLOUD_FIX_ROUND101_01. No canonical pass or Mac/device acceptance claimed. Thank you for preserving the environment and exact evidence.

Proceed NOW with a contained fix on a separate branch from exact 0c70436. Own only apps/server/src/orchestration-v2/Orchestrator.automatic-authority.test.ts, scripts/lib/native-build-metadata.ts and the existing native-build-metadata.node.test.mjs if a new behavioral case is necessary. Existing local T3 owner retains integration; do not edit production orchestration, config/plugins, locks, generated binaries, other tests or copyright attribution in this packet.

HQ inspected actual source at this exact HEAD. Six errors arise because counts returns rows[0] under noUncheckedIndexedAccess. Assert the SQL aggregate row exists in the shared helper before returning it, preserving every runs/starts/messages and Stop/Resume assertion. No non-null casts, optional fallbacks, erased checks or changed authority semantics. Preserve the three increment assertions and all effect refusal/replay assertions.

The seventh error is the committed Effect globalDate rule in native-build-metadata.ts. Replace direct Date construction with the repo's supported Effect DateTime parsing/formatting API. Preserve exact UTC millisecond format, rejection of impossible/noncanonical dates, capture-once behavior and existing error behavior. Use existing metadata tests, add only meaningful missing date-validation cases if needed. Do not disable the diagnostic, exclude the script from the graph or alter compiler strictness. Inspect API/tests before choosing the smallest fix.

The retained exact canonical compiler failure is the typecheck RED. Run the focused automatic-authority and existing native metadata tests foreground with provider execution forbidden, one worker, no live server/DB. Commit the narrow repair, report exact diff/SHA and owning results, then advance automatically to ONE changed-candidate canonical server check if those tests pass, source remains clean and captured children are terminal. Same full checkout, Node24.13.1/pnpm11.10.0/patched compiler and canonical command/config/plugins/strict full graph. No unchanged retry or plugin-disabled comparison.

Changed check job key CLOUD_T3_CANONICAL_FIX_ROUND101_01: from apps/server pnpm exec tsc --noEmit --extendedDiagnostics; 20min wall cap, 10GiB aggregate tree RSS cap (10737418240B), 70% warning at7516192768B. The prior 8GiB cap had only3% margin; this is cloud capacity headroom, not a Mac policy change or type acceptance weakening. Before running, verify cloud available memory can support this single job plus OS and no competing job. If not, stop with actual measured blocker. Retain same Linux starttime identity/lifetime/cleanup accounting, no unrelated signals, no second compiler/agent. Warning is diagnostic telemetry, not permission to start another simultaneous compiler. Keep exact environment/hash/provenance and all old evidence.

On result, publish stable STARTED/COMPLETE events here with source/binary hashes, exit/errors, time/root-vs-tree RSS, warning association, cleanup and retained evidence. Push a separate branch and draft PR linked to issue36 and PR42; do not merge/deploy/provider/mobile/install or mutate Mac. Failure stops automatic advance and returns concrete cause. No further canonical retries without a changed reviewed proposal.

HARNESS: run_in_background does NOT re-invoke you; backgrounded processes die at turn teardown. Run tests/compiler FOREGROUND. Final completed report text only, no report.md.

…uild metadata

The exact-candidate server typecheck reported seven errors. The shared
`counts` helper in the automatic-authority test returned `rows[0]`, which is
possibly undefined under noUncheckedIndexedAccess; it now asserts the SQL
aggregate row exists before returning it. native-build-metadata.ts built a
`Date` directly, which the committed Effect globalDate rule rejects; it now
parses and formats through `effect/DateTime` and keeps the exact UTC
millisecond round-trip check. The metadata test gains calendar-rollover,
out-of-range and missing-millisecond rejection cases.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012jfjVHVsSY69SpUqccgEtq
@nohat

nohat commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

HQ_CLOUD_SCRIPTS_ROUND102_01 — actionable now, once only; deduplicate this job ID. Your completed canonical server green is received. Do not repeat that compiler run or owning 19/5 tests. Keep PR44 f31614d and parent/PR42 intact; no merge or force-push.

Next bounded cloud packet, on that exact clean candidate:

  1. Inspect scripts/tsconfig.json and its inherited committed settings, apps/mobile/app.config.ts, and scripts/mobile-native-static-check.ts. Record how the changed Effect DateTime module resolves through the mobile config; preserve strict settings, plugins, lockfile and attribution. Do not generate native projects or install dependencies.
  2. Run ONE scripts owning typecheck: pnpm exec tsc --noEmit --extendedDiagnostics -p scripts/tsconfig.json from repository root. Same patched compiler and identity-aware runner. Sequential, 20-minute wall/10-GiB tree cap, 70% warning at 7516192768 bytes; no second compiler, retries, scope exclusion, plugin disablement or increased cap. Fresh cloud capacity observation first; stop if actual contention prevents this envelope. Capture exact source/config/compiler identity, stdout, metrics, warning, waited births/survivors/unknown cleanup.
  3. If the inspected existing mobile static-check command is strictly source-only (no generation/build/install/server/provider/network/live data), run node scripts/mobile-native-static-check.ts once after successful compiler and terminal cleanup. If it has effects or platform requirements, report the exact limitation instead of invoking it. No repeated metadata test battery. Do not run aggregate monorepo typecheck/test/build.
  4. On success, provide a short Linux-capable remaining verification/build proposal tied to this candidate, naming which steps genuinely help the Mac/iPhone/iPad release. Preparation only: no Linux desktop package as a substitute for Mac acceptance, no Mac artifact/signature/device claim. On failure, retain actual errors and propose the smallest repair; do not expand edits or execute another checker without HQ review.

Use PR42 activity subscription for directives; post STARTED/COMPLETE here and durable results on issue36 with this job ID. Explicitly confirm whether this comment arrived as a subscription event. No idle poller. This cloud packet does not wait for a Mac fleet slot. HARNESS foreground only; final completed report text, no report.md.

nohat commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

STARTED — HQ_CLOUD_SCRIPTS_ROUND102_01

Subscription confirmed: this directive (PR #42 comment 6040372495, 14:42:07Z) reached the session as a live issue_comment.created subscription event, without any forwarding or polling. The earlier subscription.created event arrived too (it was held about 8 minutes while a run was in progress). The job ID is deduplicated and runs once.

Step 1 findings (read-only, nothing installed or generated)

  • scripts/tsconfig.json extends ../tsconfig.base.json with composite: true, types: ["node"], lib: ["ESNext","esnext.disposable"], and include: ["**/*.ts"]. Strict flags, the Effect language-service plugin and its rules are inherited unchanged. *.tsbuildinfo is gitignored.
  • apps/mobile/app.config.ts imports ../../scripts/lib/native-build-metadata.ts, which now imports effect/DateTime and effect/Option. Module resolution is relative to the importing file, so it resolves from scripts/lib via scripts/node_modules/effect. apps/mobile/node_modules/effect is a second symlink that resolves to the same store directory (effect@4.0.1_patch_hash=612836d7…). Node resolves effect/DateTime to that store's dist/DateTime.js, so there is one patched effect 4.0.1 and no version split. The mobile config includes scripts/lib source only through that import.
  • scripts/mobile-native-static-check.ts walks apps/mobile for .swift / .kt / .kts files and spawns swiftlint, ktlint and detekt (Homebrew tools per its own messages). None is installed here. Without them it only warns and skips, so a run would be a vacuous pass, and installing them is out of scope. I will not invoke it (platform requirement); see the limitation in the COMPLETE report.
  • Candidate: f31614d7b006f5b2554395cf17bc0d97302ade79, tree clean. Hashes: scripts/tsconfig.json 8fb473f1832cee5c…, tsconfig.base.json 3c4971bce186971d…, lockfile 474795aca38580cf… (unchanged).

Fresh capacity (14:42:38Z): the VM was restarted again (uptime 2 min, new boot id 08a9a665…; disk and worktree intact). Memory 15.2 GiB available, load 0.01, memory pressure 0, nothing else running. The envelope fits.

Step 2 starting now: from the repo root, pnpm exec tsc --noEmit --extendedDiagnostics -p scripts/tsconfig.json, 20 min wall / 10737418240 B tree cap / warning at 7516192768 B, identity-aware runner, one run, no retry.


Generated by Claude Code

nohat commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

COMPLETE (FAILED, 2 errors) — HQ_CLOUD_SCRIPTS_ROUND102_01. Full report with resources, identities and the repair proposal: #36 (latest cloud COMPLETE comment).

Summary: pnpm exec tsc --noEmit --extendedDiagnostics -p scripts/tsconfig.json on PR #44 head f31614d7b006f5b2554395cf17bc0d97302ade79 exited 1 with two globalDateInEffect errors, at scripts/build-desktop-artifact.ts:3718 and scripts/mobile-native-client.ts:331. Both new Date().toISOString() lines were added by this PR. 9.0 s wall, 0.56 GB max RSS, no warning, cleanup clean. The static check was not run (it needs swiftlint, ktlint and detekt, which are absent here). I made no edits and ran no further checks; the smallest repair is proposed in the issue and waits for HQ review.


Generated by Claude Code

@nohat

nohat commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

HQ_CLOUD_SCRIPTS_FIX_ROUND103_01 — actionable now; once only, PR42 wake channel/issue36 ledger. Reviewed exact retained errors and actual call-site source at f31614d. Authorize ONLY scripts/build-desktop-artifact.ts and scripts/mobile-native-client.ts: replace the two newly added current-time captures with Effect DateTime.now/formatIso in their existing Effect generator. Inspect enclosing desktop generator first; capture once before construction and reuse across that artifact, preserving mobile single builtAtUTC across generation/build. No synchronous unsafe Effect execution, Date bypass, plugin suppression, version/notice/config/lockfile changes. Keep previous exact validation and invalid-calendar rejection unchanged. Commit separately atop f316 (PR44 stack acceptable), link both layers; do not merge/force-push.

Run the existing focused build-metadata test only where this changed capture requires verification; preferably one existing clock-controlled/package propagation owning case if available, no new framework or real build/install. Then ONE changed scripts checker -p scripts/tsconfig.json, same patched compiler/full scripts graph/config, 20min/10GiB bounds and exact-root wait4/birth cleanup. No repeat canonical server checker: these two packaging files are outside its graph and retained server green remains valid unless your actual dependency inspection contradicts that. On failure stop with actual error/proposal, no retry/exclusions. No mobile static vacuous pass/tools install. No providers/native generation/desktop packaging/device/live effects. Report exact changed SHA/diff, test/check result, resource/cleanup and clean tree. Proceed without a Mac slot. HARNESS foreground only final completed report text no report.md.

The scripts typecheck reported two globalDateInEffect errors: the desktop
artifact build and the mobile native client each took the build timestamp
from a direct Date inside an Effect generator. Both now read it with
DateTime.now and DateTime.formatIso in their existing generator. The desktop
build captures it once before staging the package metadata, and the mobile
build keeps one builtAtUTC for generation and build.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012jfjVHVsSY69SpUqccgEtq

nohat commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

COMPLETE (PASS) — HQ_CLOUD_SCRIPTS_FIX_ROUND103_01. Commit 82bfc5db1f5d35c67250a943164b34f87ff91abf (atop f31614d7…, pushed fast-forward to PR #44's branch) replaces the two new Date() captures with DateTime.formatIso(yield* DateTime.now) in their existing Effect generators. The one changed check, pnpm exec tsc --noEmit --extendedDiagnostics -p scripts/tsconfig.json, exited 0 with 0 errors (5.0 s, 0.52 GB max RSS, no warning, clean cleanup, clean tree). The server check was not repeated, and the mobile static check and any packaging were not run. Full report with hashes: the latest cloud COMPLETE comment on #36. Idle and waiting for HQ.


Generated by Claude Code

fix(server): clear canonical typecheck errors in authority test and build metadata
@nohat

nohat commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

HQ_CLOUD_CLIENT_CHECKS_ROUND104_01 — actionable now, deduplicate once. HQ independently reviewed both repair layers and merged PR44 into PR42 branch (not fork/prod). Freeze F=024f43c7fbf5d4c455ea220c718da9cd7b1c547c; its treee4218f22cecfbebe96c266ecc5eeb1d14a4344f9 exactly equals checked82bfc. Original server/scripts green retained; DO NOT repeat either. Your reported fdd808 PR42-head event was not the actual head when HQ inspected; GitHub actual old0c704 before this merge, now024f. Do not infer source identity from event labels.

Next Linux packet helps matched clients before Mac packaging: inspect committed apps/desktop/tsconfig.json and apps/web/tsconfig.json and their public package typecheck scripts. No config/lockfile/source edits. Fetch/checkout exact F in your isolated cloud tree; require clean tree/expected tree, same compiler hash/config/strict Effect plugin. After fresh actual cloud capacity observation run ONE desktop typecheck then ONE web typecheck using each existing public canonical typecheck command (or pnpm exec tsc --noEmit -p exact committed tsconfig if that is the declared command). Sequential jobs1, one compiler at a time, existing20min/10GiB treecap/70%warn7516192768 percheck, exact boot/root/compiler identity wait4 cleanup. On first failure/unknowncleanup/cap stop with actual diagnostics and smallest proposal; do not edit or retry. No aggregate workspacecheck/servercheck/scriptscheck/nativebuild/generation/provider/install/networktools. Linux package is not Mac/iPhone/iPad acceptance.

Retain measured run outputs and prior proof; include bounded sanitized stdout/summary (full source/compiler/config hash and boot/captured starttimes/exit/survivors) as accessible issue36 comment snippets or safe proof attachment so HQ can independently inspect them without a new logging framework/private inventory. Existing canonical source/code/report are accepted preparation; do not spend another compiler to reconstruct logs. No model/harness coauthor amendment/force-push required. Post COMPLETE and exact actual limitations; nothing automatic beyond this packet. PR42 event wake remains channel; no poller/Macslot wait. HARNESS foreground only final report text no report.md.

nohat commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

COMPLETE (FAILED at desktop; web not run) — HQ_CLOUD_CLIENT_CHECKS_ROUND104_01. On F 024f43c7fbf5d4c455ea220c718da9cd7b1c547c (tree e4218f22…, clean), pnpm exec tsc --noEmit --extendedDiagnostics in apps/desktop exited 1 with two errors: DesktopAppIdentity.ts(62,9) TS2412 (exactOptionalPropertyTypes, embedded from the decoded package metadata) and aboutMetadata.ts(18,5) TS377068 globalDate. 17 s, 1.97 GB max RSS, no warning, clean cleanup. Web was not run (stop on first failure). Full diagnostics, hashes, identities and the smallest proposed repair (including the likely same pattern in mobileAboutMetadata.ts) are in #36 (comment). No edits. (The report was delayed by GitHub HTTP 500s on comment creation.) Idle and waiting for HQ.


Generated by Claude Code

nohat and others added 3 commits October 7, 2026 09:03
The native About notice now reads "Copyright (c) 2026 T3 Tools Inc. Fork
modifications copyright (c) 2026 David Friedland." in the LICENSE, desktop,
mobile and build-script sources and their tests. The upstream notice is kept.

Desktop aboutMetadata used global Date (effect globalDate rule) and a
parameter type that exactOptionalPropertyTypes rejected; it now uses
DateTime/Option and accepts explicit undefined. Desktop and web tsc exit 0;
the About node tests (14) and DesktopAppIdentity vitest (5) pass.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
electron-builder defaulted NSHumanReadableCopyright to "Copyright (c) 2026
T3 Tools", so Finder and Get Info omitted the fork line even though the About
panel showed it. The packaged app now takes the same NATIVE_COPYRIGHT constant
as the About metadata.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…vices

The live database's ledger has 55 PushDevices from the APNs branch, the id V2
uses for OrchestrationV2. The migrator keys on id, so V2's schema was skipped
and the server failed on its first query (no such column:
application_event_version) when run against a copy of the live data.

Free id 55 in the V2 copy before migrating. state.sqlite is never opened, and
the push_devices table is left in place. Test reproduces the live ledger shape.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@github-actions github-actions Bot added size:XXL and removed size:XL labels Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants