Skip to content

fix(workhub): restore Step 8 acceptance prerequisites - #17

Merged
sunrioa merged 7 commits into
mainfrom
codex/workhub-step-8-acceptance
Oct 10, 2026
Merged

sunrioa merged 7 commits into
mainfrom
codex/workhub-step-8-acceptance

Conversation

@sunrioa

@sunrioa sunrioa commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Summary

Refs #8 — Step 8 acceptance prerequisites, based on the owner's merged Step 7 (#16).

Acceptance exposed existing release/platform blockers. This selectively brings in the merged upstream fixes, preserving original authorship and source commit trailers:

The minimal fork-specific corrections are:

  • Bind the pinned Windows predecessor installer to its actual source repository, apache/maka. The version, digest and verified-cache rules are unchanged.
  • Prepare the ACP paging test's 17 persisted Plans through the real Session/Plan stores before Host startup, rather than spending its client deadline on model Turns. Real ACP paging, store-version checks and the external Host write remain; deadlines and assertions are unchanged.
  • Declare baka's CLI upgrade source explicitly as maka-agent@0.2.0-dev.69.20261004, the published baseline preceding the fork point, with pinned SHA-512 integrity. Upstream apache/maka still qualifies against its current Nightly. Both CI consumers revalidate the declared identity; changes to the resolver or baseline select the released-State-Root gate.
  • Increase only the Usage request timestamp column from 168px to 208px. CI exposed real font-dependent clipping in the existing long-tail/narrow stories; English and Traditional Chinese timestamps need more room too. The existing overflow, tooltip and pagination assertions are unchanged.

Upgrade contract

This qualifies the declared pre-fork release → baka transition, not importing arbitrary newer Maka state. The previously implicit current-Nightly source had advanced to a release carrying storage.retention.query / storage.retention.set, while baka has not adopted that separate retention feature. Unknown grants still fail closed; the credential checks, real usage migration, frozen historical transitions, writer fences, tarball verification and upstream publication guards are not bypassed.

There is no wholesale upstream merge, new WorkHub feature, protocol bump (epoch remains 212), permission/sandbox relaxation, test retry or timeout increase.

Verification

Current head: 08ce0cabe840c67cea813d6ab04f4829b00a736c.

  • Clean rebuild and typecheck; lint, formatting, ASF headers, staged whitespace/protocol checks, E2E budget and Windows/Astryx inventories: passed.
  • On the preceding follow-up 42ab22b6c, all 13 workspace suites were exercised. The three-workspace parallel run passed 11 suites, including Runtime Host 2303 passed / 12 skips, Desktop 3271, Runtime 3722 / 14 skips, Core 922, UI 713 and MCP 262. Eval Python passed 81 / 13 skips.
  • That parallel run was not all green: it hit the previously recorded, unchanged Storage single-flight lease assertion and CLI immediate-EOF backoff timing assertion. Complete bounded reruns (--test-concurrency=2, fresh temporary fixtures) passed Storage 1558 / 8 skips and CLI 1335 / 3 skips. Neither test nor its production implementation was changed to hide those results. The repaired ACP paging case passed both independently and under full-workspace load.
  • Final-head complete existing Electron E2E: 35/35 passed. No retries or relaxed timeouts; isolated temporary user data. No test or native boundary was added for the renderer-only width fix.
  • Final-head Desktop suite: 3271/3271 passed. Storybook typecheck/build and the full catalog smoke passed: 454 stories / 497 theme renders, including WorkHub, production play assertions, focus and accessibility checks. The existing isolated-retry fallback was not triggered.
  • The old 168px timestamp column failed both existing Usage stories with a wider font (174.96875px required). The final 208px column passed all 12 explicit locale/font/viewport scenarios, including two-digit dates and hours; the widest measured English timestamp required 205.21875px. No test file, assertion, font configuration or deadline was changed.
  • Release checks: 217/217; affected CI/release/protocol policy tests: 136/136.
  • The actual declared npm baseline bytes matched the pinned SHA-512 and published SHA-1. This digest check is not a substitute for Linux released-State-Root qualification.

Hosted evidence

Final-head checks have finished: 19 successful, 1 expected skip and 1 repository-configuration failure. There are no pending checks.

  • Main CI: passed standard workspace tests, Runtime Host, live Eval proxy, real source-69 forward-roll qualification, Electron E2E, native browser checks, full Storybook smoke, transcript geometry and installed CLI validation.
  • Hosted Storybook used its existing isolated fallback once for product-workhub--usage-inspector after a failure under four-way load; it passed alone. Both previously failing Usage timestamp stories passed directly. The local full-catalog run needed no fallback; the runner and its retry policy were not changed.
  • CLI package validation: passed pinned-baseline and frozen historical State Root transitions plus installed-package validation on Linux x64/arm64, macOS arm64 and Windows x64. Installed CLI Eval was intentionally skipped by the existing fork policy; it is not recorded as a pass.
  • Windows release check: passed packaging, packaged verification, pinned-version upgrade/uninstall, automatic update and deterministic mid-install failure rollback.
  • Windows W0, recovery, ACP, macOS/Windows Host owner platforms, dependency auditing and Linux packaging: passed.

On 42ab22b6c, the previously failing real ACP paging test and released-State-Root qualification passed. CLI Linux x64/arm64, macOS arm64 and Windows installed-package checks, frozen historical transitions, declared-baseline verification, Windows W0/recovery/ACP, macOS/Windows Host owner platforms, dependency auditing, Linux packaging and complete Windows package/upgrade/update/rollback checks passed. Its main CI reached Storybook and failed only the two Usage timestamp-width assertions addressed by the final one-line follow-up. That evidence is kept separate from final-head results.

The only red item is Copilot auto review: COPILOT_REVIEW_TOKEN is not configured, and the inherited workflow still pins its requester to the upstream account. It requires a separate owner decision/configuration for baka, not a test workaround in this PR. No secret value was read, no credential was created and no review check was bypassed. Human review remains required.

Acceptance boundaries

This PR completes the prerequisite corrections within its scope, not every product qualification item in #8. Formal signed/notarized macOS distribution and owner-controlled live-provider routing/latency/cost evidence remain tracked there. Signing credentials are not configured locally; deterministic tests do not prove provider quality or a strict monetary cap. No real user credential store was accessed or modified.

Migration

Usage schema 9 migrates to 10; older schema-9-only builds must fail closed after migration. Existing MCP OAuth records without an issuer binding are revoked on next access and require a new sign-in, matching the upstream fix. More recent upstream-only State Roots are outside the declared fork upgrade contract.

AI use

  • No generative tool made a substantive contribution
  • Generative tooling made a substantive contribution

Tool(s) and scope: OpenAI Codex investigated the failures, selectively synchronized upstream fixes, implemented and tested the fork-specific corrections, and drafted this PR. Original upstream Generated-by trailers are preserved; authored follow-ups carry Generated-by: OpenAI Codex. The repository owner retains review and merge.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No

ggbdpq and others added 4 commits October 10, 2026 03:19
…t zero (#5890)

A failed or aborted auxiliary model call recorded zero usage, so it read
as free. Record it as usage-unknown (usage_basis = 'missing') with a
no_run marker instead. Ledger-wide coverage keeps reporting these rows,
while hosted-execution settlement checks the same window as its totals
and excludes only the no_run sentinel rows, so delegated child Sessions
still block settlement when their usage is missing. Bumps the usage
schema to 10.

Part of #5691.

Generated-by: GLM-5.3-Flash (ZCode)
(cherry picked from commit 3bd8bbe1e5a1ed12c6397345845fe9fe8ff68b0c)
…lane (#6016)

Eight workflows with a cron trigger had no repository guard, so every fork
with Actions enabled ran them nightly against its own, usually stale, main.
On a fork they fail for reasons unrelated to the change under test: the
dependency audit flags advisories already fixed upstream, and the Windows
release check downloads its upgrade baseline from the fork's own releases,
which do not exist.

Gate each job on `github.event_name != 'schedule' || github.repository ==
'apache/maka'`. Pull request, push and manual dispatch runs keep their
current behavior, including on forks; only cron runs outside apache/maka are
skipped. issue-pr-lifecycle and model-metadata-upkeep already guard on the
repository, and npm-publication is gated by NPM_NIGHTLY_ENABLED.

Generated-by: Claude Code
fix(runtime): emit the filesystem worker bundle as .mjs

The worker bundle was emitted as dist/workers/filesystem-worker.js, so
Node walked up to the nearest package.json to decide the module type.
Inside the Windows AppContainer sandbox that read is denied, and the
worker crashed at launch with ERR_INVALID_PACKAGE_CONFIG. The
windows_sandbox_w0_protocol job has failed on main because of it.

An .mjs bundle is ESM by extension, so Node never performs the lookup.
The build and desktop copy scripts now take the file name from
FILESYSTEM_WORKER_BUNDLE_NAME so the producer cannot drift from the
resolver; packaging verifiers keep literal paths because they check the
shipped layout independently.

Split out of #5969, which carries the same rename.

Generated-by: Claude Code
fix(release): accept the legacy worker name in Windows upgrade baselines

The pinned-version upgrade check verifies the previously released installer
with the current resource list, which now demands
`workers/filesystem-worker.mjs`. Releases built before the rename ship
`filesystem-worker.js`, so the check failed on bytes that were correct when
they shipped. Relax the requirement for the upgrade-baseline contract, like
the other resources that newer builds added.

Generated-by: Claude Code
(cherry picked from commit 6fa48516106b4e2de591aea4a96a538425c8aafa)
…indow (#6023)

Follow-up to #5890 (merged): the runner passes the same startedAt/settledAt
window to the completeness check and to the usage summary, and nothing
asserted it - the review noted a later edit could quietly separate the two
and re-open the delegated-Session undercount. The coverage stub now records
its calls and the residencies test asserts it received exactly the window
the usage summary read (100, 200 with the harness clock). Swapping the
arguments in the runner turns the assertion red.

Implements the non-blocking suggestion from the #5890 review.

Generated-by: GLM-5.3-Flash (ZCode)
(cherry picked from commit 6f8fd706ac5a832a5a398371b9c1d59a756ed0d1)
Refs #8. Keep the pinned installer version and SHA-256 unchanged, and source it from its manifest repository rather than the candidate repository's Actions environment.

Generated-by: OpenAI Codex
* fix(mcp): unblock nightly with issuer-safe SDK upgrade

Generated-by: OpenAI Codex

* fix(release): update MCP patch source license inventory

Generated-by: OpenAI Codex
(cherry picked from commit f7fa724e8e0be48b98d2d7092ffbe8036c355d1b)
Seed persisted Plan history before Host startup while retaining the real ACP paging and external-write assertions and their existing deadlines. Qualify baka from its explicit pre-fork npm release with pinned integrity; keep upstream publication and strict credential/State Root checks unchanged.

Refs #8

Generated-by: OpenAI Codex
@sunrioa
sunrioa marked this pull request as ready for review October 10, 2026 07:42
Reserve enough width for localized request timestamps without relaxing the existing Storybook overflow, tooltip, or pagination assertions. Reproduced clipping with the old 168px column and verified three locales at wide and narrow viewports.

Refs #8

Generated-by: OpenAI Codex

@sunrioa sunrioa left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

审查结论:针对 08ce0cabe840c67cea813d6ab04f4829b00a736c(base 4fd7d878d77678b0b570eb2a9024f892dc620fd8),未发现可证实的新增 P1/P2 问题。

已覆盖全部 58 个变更文件及相关调用链,重点核查 Usage schema 9→10、辅助调用未知用量及结算归属、MCP issuer 绑定与 SDK 补丁、文件系统 worker 打包/启动/受限执行、fork 升级基线与 CI 权限。

独立验证:

  • 在隔离副本重新构建全部工作区,Desktop 四套 TypeScript 配置、Storybook 构建均通过。
  • 相关 Node 回归最终 597 项通过、1 项平台跳过:Storage 70、Host 49、MCP 262、worker/sandbox 101、ACP 子进程 7、CI/release 策略 108。macOS Seatbelt 真实 worker 的工作区写入和越界拒绝也通过;跳过项需要原生 Linux。
  • Usage 真实 Chromium 覆盖中/英/繁体 × 默认/Arial 字体 × 1280/720px,共 12/12 场景通过,保留原有分页、过滤、刷新和 tooltip 断言。将列宽单独恢复为旧的 168px 后,原断言和实际溢出测量都会失败。
  • 实际 Electron 43.4.1 对 ASAR 内新构建 worker 与生产资源解析器的 4/4 对比通过(.js/.mjs × runtime manifest 存在/省略)。生产 Host 使用 runtime 相对的归档内路径;发布驱动使用外置副本,两条路径已分别追踪,未发现改名遗漏或失败后回退为不受限执行。
  • OAuth 2.1 基线缓存摘要与原 lockfile 匹配;对照实际 2.2 实现和两种模块补丁,issuer 校验更严格,旧的无 issuer 凭据会撤销,未发现 callback/CAS/redirect 绕过。

保留的验证限制:

  • 首次并行跑 Host 时,未改动的 production Host publishes and retires an implementation child patch 在原有 5 秒窗口超时;单独运行该项通过,随后相同两份完整测试 49/49 通过。根因尚未证实,不能把首次失败隐去或宣称已证明只是偶发问题。整个审查未改源码、断言、超时或重试策略。
  • 当前 HEAD 的 hosted checks 为 19 成功、1 跳过、1 失败,无 pending。主 CI 和 Windows 发布检查 成功;主 CI 的 Storybook 曾使用现有单独重跑机制通过 Usage Inspector。Installed CLI Eval 跳过未计作通过。
  • 唯一失败的 Copilot 自动审查 日志明确为缺少 COPILOT_REVIEW_TOKEN,属于仓库配置。主 CI/Windows 日志响应有截断,成功状态已单独核验。
  • 本机未复现原生 Windows AppContainer 对生产归档内 worker 的执行;hosted Windows 测试使用外置 worker。源码追踪和 macOS ASAR 对比支持本次改名无回归,但不替代该平台完整实机资格验证。

按本次严格 P1/P2 标准,没有需要阻止该 PR 的已确认代码问题。

@sunrioa
sunrioa merged commit 1f265a2 into main Oct 10, 2026
20 of 21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants