Skip to content

feat(multiverse): authenticated Start and current-host Restart receiver - #7353

Draft
loganj wants to merge 2 commits into
feat/lifecycle-keyless-16211feffrom
feat/lifecycle-receiver-16211fef
Draft

feat(multiverse): authenticated Start and current-host Restart receiver#7353
loganj wants to merge 2 commits into
feat/lifecycle-keyless-16211feffrom
feat/lifecycle-receiver-16211fef

Conversation

@loganj

@loganj loganj commented Sep 4, 2026

Copy link
Copy Markdown
Collaborator

Draft scope

Native current process observation, durable admission before effects, independently verified owner delegation, ordinary teardown and guarded launch. Untracked process evidence remains uncertain. Superseded placement fences automatic spawn paths; historical reconciliation never launches.

Depends on feat/lifecycle-keyless-16211fef; part of six dependent drafts atop #7347 (dfce9ba3). Frozen inventory/Stop heads are unchanged. Head: 34d152c81cff39f24af93eadd64c28c2bec2e7cb.

Evidence

The composed candidate 5ec1955862d11bd9c01b7e3318f09b7076101423 passed full just ci, 6,266 frontend tests, production artifact build, 3,178 native unit + 10 integration tests, and native/workspace Clippy. This is composed-candidate evidence, not a claim that each earlier unmounted slice independently exercises the whole feature. Splitting changed no product bytes.

Earlier direct package attempts exposed environment limitations: relay media tests lacked a configured PostgreSQL pool; a direct buzz-db source-attribution guard failed in the unchanged production source; the first separate PostgreSQL lane failed local setup before tests. Full just ci subsequently passed its configured lanes. Separate populated PostgreSQL/private relay evidence is being collected, not assumed green.

Explicitly unperformed / not delivered

  • No two-Desktop/two-Mac lifecycle walkthrough, successful real relocation, or real process-tree cleanup acceptance. These are documented limits, not a drafting gate.
  • No deployed host-owned broker credential provisioner. Production Start/Restart cannot spawn a new keyless runtime until that integration is supplied; the current provider returns provisioning_unavailable. Injected success tests are not deployed provisioning evidence.
  • No keys, files, configuration, or workspaces transferred. No auth weakening, arbitrary signer, or keyful launch fallback.
  • Draft only: no merge, deployment, release artifact, or technical approval claimed.

Product authority

Approved Multiverse semantics: newer sender seconds/lower event-ID ties; scoped Stop; current-host-only Restart; failed/interrupted Move has no automatic continuation. This follows the settled Multiverse design rather than the older provider/key-transfer vision in VISION_REMOTE_AGENTS.md.

Origin channel: f45d3304-dcf0-44e8-a46d-bcd63b235fbc
Origin thread: 16211fefcee85904f49802ce5e1709bf24b4895401a944f0585e70233c4e4d39
Owner drafting direction: 4ed62424758aea3898b084f9e24d7fd9791d7dc53738d01ed1c0dbbae1adb8e7.

CI slice correction — 2026-09-04

Current head: 34d152c81cff39f24af93eadd64c28c2bec2e7cb. CI attempt 1 fixed a split-only Clippy failure: #7352 introduced provision before its receiver caller existed. The stub and its two imports now arrive with #7353 instead. No lint suppression was added. #7352's corrected source passed native fmt, full native workspace tests, and desktop-tauri-clippy locally. #7353#7355 were rebased; each resulting source tree is identical to its respective previously validated head (verified with git diff --exit-code). The composed tip is 4e7b31e0dc6ab265c6f10f173dbe503e3eeeb814, source-identical to 2f26d5f3. Remote checks are being followed on the new heads; not yet claimed green.

Review disposition: self-review complete, no submitted GitHub technical review at this readback. No independent approval claimed. The launch-provisioning integration and native walkthrough limitations above remain unchanged.

@loganj

loganj commented Sep 4, 2026

Copy link
Copy Markdown
Collaborator Author

Additional exact-head validation

At composed tip 5ec1955862d11bd9c01b7e3318f09b7076101423, the separate PostgreSQL lane now passes 260/260 (all buzz-db ignored PostgreSQL tests plus the Desktop transport tests). This includes populated migration 0049 and both lifecycle kinds through authenticated HTTP/WS privacy and exact-request duplicate redelivery.

The previous 259/260 result was a fixture URL spelling issue: an unchanged test strips postgres:// literally; the initial local admin URL used postgresql://. Using the test-supported URL spelling resolved it with no product change.

Full composed just ci, 6,266 frontend tests, 3,178 native unit + 10 integration tests and Clippy remain passed. Real two-Desktop/process-cleanup acceptance and deployed broker provisioning remain explicitly unperformed/unimplemented; this evidence does not establish real relocation.

Signed-off-by: Logan Johnson <loganj@squareup.com>
Signed-off-by: Logan Johnson <loganj@squareup.com>
@loganj

loganj commented Sep 4, 2026

Copy link
Copy Markdown
Collaborator Author

CI slice correction — 2026-09-04

Current head: 34d152c81cff39f24af93eadd64c28c2bec2e7cb. CI attempt 1 fixed a split-only Clippy failure: #7352 introduced provision before its receiver caller existed. The stub and its two imports now arrive with #7353 instead. No lint suppression was added. #7352's corrected source passed native fmt, full native workspace tests, and desktop-tauri-clippy locally. #7353#7355 were rebased; each resulting source tree is identical to its respective previously validated head (verified with git diff --exit-code). The composed tip is 4e7b31e0dc6ab265c6f10f173dbe503e3eeeb814, source-identical to 2f26d5f3. Remote checks are being followed on the new heads; not yet claimed green.

Review disposition: self-review complete, no submitted GitHub technical review at this readback. No independent approval claimed. The launch-provisioning integration and native walkthrough limitations above remain unchanged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant