Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
158 commits
Select commit Hold shift + click to select a range
ba80a75
chore(workspace): bootstrap task/os/repair-targeted-device-authority-…
Aug 14, 2026
d0f26bd
chore(workspace): bootstrap task/os/repair-installed-lifecycle-tool-c…
Aug 14, 2026
e6d6fe9
fix(os): route lifecycle tools through runtime package
kokayicobb Aug 14, 2026
4e529ca
task(os): repair installed lifecycle tool command routing
kokayicobb Aug 14, 2026
76fad7c
chore(workspace): bootstrap task/os/install-os-dependencies-before-ge…
Aug 14, 2026
b83b8f8
fix(ci): install os dependencies before generic verify
kokayicobb Aug 14, 2026
1a34e44
task(os): install os dependencies before generic verify
kokayicobb Aug 14, 2026
30ce299
chore(workspace): bootstrap task/os/surface-registry-failure-output-i…
Aug 14, 2026
2fabdf1
fix(workspace): surface registry suite failure output
kokayicobb Aug 14, 2026
6b8ee31
task(os): surface registry failure output in verify
kokayicobb Aug 14, 2026
af9bbc4
fix(os): add targeted device authority release
kokayicobb Aug 14, 2026
5d58756
task(os): repair targeted device authority production release
kokayicobb Aug 14, 2026
a2786e0
chore(workspace): bootstrap task/os/add-selectable-managed-cloud-plan…
Aug 14, 2026
7211fcd
chore(workspace): bootstrap task/os/hotfix-mac-menu-stability-lifecyc…
Aug 14, 2026
1b52ed2
feat(os): add managed cloud checkout
kokayicobb Aug 14, 2026
919bc6d
task(os): add selectable managed cloud plans and stripe checkout
kokayicobb Aug 14, 2026
85992ee
fix(os): stabilize mac menu and node discovery
kokayicobb Aug 14, 2026
838a8b9
task(os): hotfix mac menu stability lifecycle status and singleton
kokayicobb Aug 14, 2026
1c730e2
chore(workspace): bootstrap task/os/fix-chatgpt-cimd-oauth-reconnect-…
Aug 14, 2026
af1174f
fix(os): restore ChatGPT OAuth reconnect on Cloudflare
kokayicobb Aug 14, 2026
24b723a
task(os): fix chatgpt cimd oauth reconnect on cloudflare
kokayicobb Aug 14, 2026
5dbf656
chore(workspace): bootstrap task/os/expose-explicit-cloud-node-target…
Aug 15, 2026
0a1af28
chore(workspace): bootstrap task/os/fix-device-authority-oauth-callba…
Aug 15, 2026
d88b9ec
feat(os): expose explicit node targeting in os call
kokayicobb Aug 15, 2026
d6e3052
task(os): expose explicit cloud node targeting in chatgpt os call
kokayicobb Aug 15, 2026
81a26c3
chore(workspace): bootstrap task/os/align-cimd-worker-test-fixture-fo…
Aug 15, 2026
d5807ad
test(os): align CIMD fixture with main
kokayicobb Aug 15, 2026
718e501
task(os): align cimd worker test fixture for stream sync
kokayicobb Aug 15, 2026
c156a12
chore(workspace): bootstrap task/os/align-mcp-oauth-canonical-routing…
Aug 15, 2026
e2de715
fix(os): align canonical mcp oauth routing
kokayicobb Aug 15, 2026
dc8be15
fix(os): route Google OAuth callback errors by stored state
kokayicobb Aug 15, 2026
cd15e7a
task(os): align mcp oauth canonical routing for stream sync
kokayicobb Aug 15, 2026
baa0ef7
task(os): fix device authority oauth callback state persistence
kokayicobb Aug 15, 2026
6149152
chore(workspace): bootstrap task/os/preserve-workspace-edge-node-auth…
Aug 15, 2026
b375ec4
fix(os): preserve workspace edge auth through caddy
kokayicobb Aug 15, 2026
d1cd725
task(os): preserve workspace edge node auth through caddy
kokayicobb Aug 15, 2026
9daca57
chore(workspace): bootstrap task/os/make-os-lifecycle-restarts-connec…
Aug 15, 2026
e93e817
chore(workspace): bootstrap task/os/reconcile-stripe-synthetic-checko…
Aug 15, 2026
5e9946a
feat(os): add synthetic checkout observability
kokayicobb Aug 15, 2026
b7b45b3
task(os): reconcile stripe synthetic checkout observability onto curr…
kokayicobb Aug 15, 2026
bd586fa
fix(os): make in-band lifecycle restart reply-safe
kokayicobb Aug 15, 2026
2e96ab8
task(os): make os lifecycle restarts connector safe
kokayicobb Aug 15, 2026
63622e6
chore(workspace): bootstrap task/os/fix-launcher-snapshot-reconciliat…
Aug 15, 2026
fa4e1be
fix(os): keep launcher snapshots and gateways coherent
kokayicobb Aug 15, 2026
521d13e
task(os): fix launcher snapshot reconciliation and lifecycle gateway …
kokayicobb Aug 15, 2026
2c914cb
chore(workspace): bootstrap task/os/make-mcp-admission-failures-obser…
Aug 15, 2026
1d007af
chore(workspace): bootstrap task/os/persist-synthetic-checkout-worksp…
Aug 15, 2026
e5749ba
fix(os): surface MCP safety admission errors
kokayicobb Aug 15, 2026
2b4e4a6
task(os): make mcp admission failures observable and non network shaped
kokayicobb Aug 15, 2026
a69ebc0
chore(workspace): bootstrap task/os/make-authenticated-workspace-subr…
Aug 15, 2026
2ba3ec8
fix(os): persist synthetic checkout workspace allowlist
kokayicobb Aug 15, 2026
beefdb1
task(os): persist synthetic checkout workspace allowlist and producti…
kokayicobb Aug 15, 2026
5bf032e
fix(os): preserve private workspace auth across releases
kokayicobb Aug 15, 2026
caf9731
task(os): make authenticated workspace subroutes survive releases and…
kokayicobb Aug 15, 2026
b23fe70
chore(workspace): bootstrap task/os/land-workspace-overview-shell-on-…
Aug 15, 2026
4f19a75
feat(os): make overview the workspace home
kokayicobb Aug 15, 2026
6ce2fe5
task(os): land workspace overview shell on current stream
kokayicobb Aug 15, 2026
6a2f913
chore(workspace): bootstrap task/os/polish-tracing-chrome-and-respons…
Aug 15, 2026
5f31b72
fix(os): polish tracing chrome and responsive table
kokayicobb Aug 15, 2026
b4082af
task(os): polish tracing chrome and responsive table
kokayicobb Aug 15, 2026
3d25711
chore(workspace): bootstrap task/os/sync-os-stream-with-main-and-ship…
Aug 15, 2026
8e57fe4
chore(os): reconcile stream with main for tracing ship
kokayicobb Aug 15, 2026
bd04ab6
chore(os): record stream sync evidence
kokayicobb Aug 15, 2026
c714649
chore(os): record reconciled main ancestry
Aug 15, 2026
d29c767
chore(os): verify reconciled main ancestry
kokayicobb Aug 15, 2026
2ad0917
task(os): sync os stream with main and ship tracing polish
kokayicobb Aug 15, 2026
328fbd0
chore(workspace): bootstrap task/os/fix-updater-runtime-convergence-a…
Aug 15, 2026
60e076c
Ship Home Connect Nodes Pricing
kokayicobb Aug 15, 2026
f11dc8c
fix(os): converge workspace releases and trace columns
kokayicobb Aug 15, 2026
2bfaaf3
task(os): fix updater runtime convergence and trace node order
kokayicobb Aug 15, 2026
8a72fd9
chore(workspace): bootstrap task/os/sync-os-stream-after-updater-rout…
Aug 15, 2026
3c3870d
chore(workspace): bootstrap task/os/land-home-connect-route-preload-o…
Aug 15, 2026
2c88807
chore(os): record clean stream sync evidence
kokayicobb Aug 15, 2026
6d32824
chore(os): record main ancestry after stream sync
Aug 15, 2026
7d752d7
chore(os): verify main ancestry sync
kokayicobb Aug 15, 2026
fe6252c
task(os): sync os stream after updater route fix
kokayicobb Aug 15, 2026
30fc398
chore(workspace): bootstrap task/os/retry-release-route-refresh-after…
Aug 15, 2026
cc0e122
feat(os): preload Home routes and live node pricing
kokayicobb Aug 15, 2026
f3d8f6a
task(os): land home connect route preload on current stream
kokayicobb Aug 15, 2026
bb52fcc
fix(os): retry workspace route refresh after deploy
kokayicobb Aug 15, 2026
5f22baf
task(os): retry release route refresh after worker deploy
kokayicobb Aug 15, 2026
cf23280
chore(workspace): bootstrap task/os/fix-current-bundle-updater-reconc…
Aug 15, 2026
8adbe3b
fix(os): reconcile current-bundle updates
kokayicobb Aug 15, 2026
d158bdf
task(os): fix current bundle updater reconciliation
kokayicobb Aug 15, 2026
d7e7509
chore(workspace): bootstrap task/os/sync-os-stream-with-main-for-rele…
Aug 15, 2026
8c55c04
Merge commit '99d66930e43915a56e5ba49befd239b2f5295606' into task/os/…
Aug 15, 2026
681d02c
Sync OS stream with main for release
kokayicobb Aug 15, 2026
07cf777
chore(os): preserve main ancestry before stream release
kokayicobb Aug 15, 2026
97916f9
chore(workspace): bootstrap task/os/heatmap-menu-polish-on-current-os…
Aug 15, 2026
16c2971
feat(os): add live Overview heatmap and stable workspace nav
kokayicobb Aug 15, 2026
2f580c2
task(os): heatmap menu polish on current os stream
kokayicobb Aug 15, 2026
b15b525
chore(workspace): bootstrap task/os/make-macos-gateway-restart-resili…
Aug 15, 2026
db12cde
fix(os): retry transient macOS gateway bootstrap
kokayicobb Aug 15, 2026
70bc23b
task(os): make macos gateway restart resilient during updates
kokayicobb Aug 15, 2026
4c92021
chore(workspace): bootstrap task/os/fix-workspace-edge-d1-release-cre…
Aug 15, 2026
9cad8fa
fix(os): use dedicated Workspace Edge release credential
kokayicobb Aug 15, 2026
b957700
task(os): fix workspace edge d1 release credential boundary
kokayicobb Aug 15, 2026
1877d59
chore(workspace): bootstrap task/os/retry-primary-macos-launch-agent-…
Aug 15, 2026
5aa6d31
chore(workspace): bootstrap task/os/eliminate-mcp-transport-outages-d…
Aug 15, 2026
cf3f8ff
fix(os): retry primary launchd bootstrap during updates
kokayicobb Aug 15, 2026
77b173b
task(os): retry primary macos launch agent bootstrap during lifecycle…
kokayicobb Aug 15, 2026
39634b9
Converge production Workspace Edge from current main
kokayicobb Aug 15, 2026
6829db5
chore(workspace): bootstrap task/os/retry-transient-macos-gateway-kic…
Aug 15, 2026
9450bfd
fix(os): retry transient gateway kickstart
kokayicobb Aug 15, 2026
9942fa1
task(os): retry transient macos gateway kickstart during lifecycle up…
kokayicobb Aug 15, 2026
87e5914
fix(os): preserve MCP ingress during lifecycle updates
kokayicobb Aug 16, 2026
c7bd4a3
merge stream/os lifecycle retry fixes into MCP continuity work
kokayicobb Aug 16, 2026
1b28987
task(os): eliminate mcp transport outages during os updates
kokayicobb Aug 16, 2026
ae9373d
chore(workspace): bootstrap task/os/sync-os-stream-with-main-after-mc…
Aug 16, 2026
df8915a
merge main ancestry into OS stream sync
kokayicobb Aug 16, 2026
422ec29
task(os): sync os stream with main after mcp continuity merge
kokayicobb Aug 16, 2026
0e12fba
chore(workspace): bootstrap task/os/preserve-in-flight-mcp-requests-d…
Aug 16, 2026
0766a04
fix(os): drain MCP workers before rolling replacement
kokayicobb Aug 16, 2026
13fdbbc
task(os): preserve in flight mcp requests during worker rolling reload
kokayicobb Aug 16, 2026
9ecfb19
chore(workspace): bootstrap task/os/sync-os-stream-with-main-after-wo…
Aug 16, 2026
765549d
merge main ancestry after worker drain fix
kokayicobb Aug 16, 2026
daca5af
task(os): sync os stream with main after worker drain fix
kokayicobb Aug 16, 2026
ad50465
chore(workspace): bootstrap task/os/anchor-caddy-worker-topology-to-s…
Aug 16, 2026
395b6fc
fix(os): anchor Caddy to stable worker pool base
kokayicobb Aug 16, 2026
dd7abde
task(os): anchor caddy worker topology to stable pool base
kokayicobb Aug 16, 2026
c624332
chore(workspace): bootstrap task/os/sync-os-stream-with-main-after-st…
Aug 16, 2026
1aab77f
chore(workspace): bootstrap task/os/finish-rollback-compatibility-aft…
Aug 16, 2026
b49ef3d
fix(os): finish rollback compatibility
kokayicobb Aug 16, 2026
120432e
task(os): finish rollback compatibility after stable topology
kokayicobb Aug 16, 2026
d15dcf6
merge main ancestry after stable worker topology fix
kokayicobb Aug 16, 2026
bb71704
task(os): sync os stream with main after stable worker topology fix
kokayicobb Aug 16, 2026
c2351a5
chore(workspace): bootstrap task/os/repair-production-workspace-edge-…
Aug 16, 2026
5cd45c6
fix(os): preflight workspace edge d1 release auth
kokayicobb Aug 16, 2026
fa1dcf0
task(os): repair production workspace edge d1 release credential boun…
kokayicobb Aug 16, 2026
6b80800
chore(workspace): bootstrap task/os/guarantee-updater-converges-caddy…
Aug 16, 2026
265830c
fix(os): converge pinned ingress dependencies during updates
kokayicobb Aug 16, 2026
c473ef6
task(os): guarantee updater converges caddy and cloudflared without d…
kokayicobb Aug 16, 2026
3aa68e1
chore(workspace): bootstrap task/os/regenerate-cloudflared-connector-…
Aug 16, 2026
2846eae
fix(os): regenerate Cloudflared connector definitions from managed ru…
kokayicobb Aug 16, 2026
fd60838
task(os): regenerate cloudflared connector definitions from managed r…
kokayicobb Aug 16, 2026
0ad87b0
chore(workspace): bootstrap task/os/sync-os-stream-with-main-after-cl…
Aug 16, 2026
0e276c2
merge main ancestry after Cloudflared definition convergence
Aug 16, 2026
64f51b7
task(os): sync os stream with main after cloudflared definition conve…
kokayicobb Aug 16, 2026
7e8dc02
chore(workspace): bootstrap task/os/stop-no-op-caddy-reloads-from-cut…
Aug 16, 2026
7f9e6a4
fix(os): skip no-op Caddy reloads during updates
kokayicobb Aug 16, 2026
c44ce5c
task(os): stop no op caddy reloads from cutting mcp requests during u…
kokayicobb Aug 16, 2026
19d1852
chore(workspace): bootstrap task/os/prevent-mcp-eof-during-rolling-wo…
Aug 16, 2026
226433b
fix(os): preserve in-flight responses during worker drain
kokayicobb Aug 16, 2026
0befdf5
task(os): prevent mcp eof during rolling worker evacuation
kokayicobb Aug 16, 2026
4da1785
chore(workspace): bootstrap task/os/wire-private-internal-site-throug…
Aug 16, 2026
0f8a385
feat(os): wire private site auth into workspace chrome
kokayicobb Aug 16, 2026
0d592e8
task(os): wire private internal site through current launcher auth an…
kokayicobb Aug 16, 2026
2623801
Merge remote-tracking branch 'origin/main' into stream/os
Aug 16, 2026
d13a0f4
Merge remote-tracking branch 'origin/main' into stream/os
Aug 16, 2026
c3a7b2b
chore(workspace): bootstrap task/os/restore-internal-dashboard-browse…
Aug 16, 2026
255eb25
fix(os): restore internal dashboard browser auth handoff
kokayicobb Aug 16, 2026
f1e43b4
task(os): restore internal dashboard browser auth handoff
kokayicobb Aug 16, 2026
657ff04
chore(workspace): bootstrap task/os/gate-internal-dashboard-routing-o…
Aug 16, 2026
fad7c8a
fix(os): gate private dashboard on complete access config
kokayicobb Aug 16, 2026
f61028b
task(os): gate internal dashboard routing on complete access config
kokayicobb Aug 16, 2026
d3307c1
chore(workspace): bootstrap task/os/repair-runtime-retention-and-watc…
Aug 16, 2026
a2bc0d1
fix(os): recover unhealthy services and bound runtime storage
kokayicobb Aug 16, 2026
fcc089a
task(os): repair runtime retention and watchdog recovery
kokayicobb Aug 16, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
{
"area": "os",
"stream": "stream/os",
"taskBranch": "task/os/gate-internal-dashboard-routing-on-complete-access-config",
"baseBranch": "stream/os",
"sourceBranch": "stream/os",
"startFrom": "stream",
"prNumber": 2149,
"prUrl": "https://github.com/consuelohq/opensaas/pull/2149",
"githubPrUrl": "https://github.com/consuelohq/opensaas/pull/2149",
"graphitePrUrl": "https://app.graphite.com/github/pr/consuelohq/opensaas/2149/gate-internal-dashboard-routing-on-complete-access-config",
"taskPrUrl": "https://github.com/consuelohq/opensaas/pull/2149",
"taskGraphitePrUrl": "https://app.graphite.com/github/pr/consuelohq/opensaas/2149/gate-internal-dashboard-routing-on-complete-access-config",
"worktreePath": "/private/var/folders/vl/1zvhm0bj28d1dbvbcb12b39r0000gn/T/opensaas-worktrees/task-os-gate-internal-dashboard-routing-on-complete-access-config",
"taskSession": "tsk_be4cc7cc41f5",
"tmuxSession": "opensaas-os-gate-internal-dashboard-routing-on-complete-acce-be4cc7cc",
"sessionPath": "/private/var/folders/vl/1zvhm0bj28d1dbvbcb12b39r0000gn/T/opensaas-worktrees/task-os-gate-internal-dashboard-routing-on-complete-access-config/.task/os/gate-internal-dashboard-routing-on-complete-access-config/session.json",
"createdAt": "2026-08-16T22:29:43.195Z"
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
{
"taskSession": "tsk_be4cc7cc41f5",
"tmuxSession": "opensaas-os-gate-internal-dashboard-routing-on-complete-acce-be4cc7cc",
"area": "os",
"stream": "stream/os",
"taskBranch": "task/os/gate-internal-dashboard-routing-on-complete-access-config",
"branch": "task/os/gate-internal-dashboard-routing-on-complete-access-config",
"worktreePath": "/private/var/folders/vl/1zvhm0bj28d1dbvbcb12b39r0000gn/T/opensaas-worktrees/task-os-gate-internal-dashboard-routing-on-complete-access-config",
"worktree": "/private/var/folders/vl/1zvhm0bj28d1dbvbcb12b39r0000gn/T/opensaas-worktrees/task-os-gate-internal-dashboard-routing-on-complete-access-config",
"prNumber": 2149,
"prUrl": "https://github.com/consuelohq/opensaas/pull/2149",
"createdAt": "2026-08-16T22:29:43.194Z",
"tmuxCreated": true,
"sessionPath": "/private/var/folders/vl/1zvhm0bj28d1dbvbcb12b39r0000gn/T/opensaas-worktrees/task-os-gate-internal-dashboard-routing-on-complete-access-config/.task/os/gate-internal-dashboard-routing-on-complete-access-config/session.json"
}

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
@@ -0,0 +1,86 @@
# gate internal dashboard routing on complete access config

branch: `task/os/gate-internal-dashboard-routing-on-complete-access-config`
stream: `stream/os`
pr: https://app.graphite.com/github/pr/consuelohq/opensaas/2149/gate-internal-dashboard-routing-on-complete-access-config
github pr: https://github.com/consuelohq/opensaas/pull/2149
started: 2026-08-16

## acceptance criteria

- [ ] Define explicit task acceptance criteria before coding.

## plan

1. Read the relevant code and update this plan before editing.

## current status

- Task started. Update this before publish.

## files changed

- none yet

## workspace-owned: files changed

- none yet

## workspace-owned: activity log

- 2026-08-16 22:29:59 fs.write: `.task/os/gate-internal-dashboard-routing-on-complete-access-config/workpad.md`
- 2026-08-16 22:32:10 fs.write: `.task/os/gate-internal-dashboard-routing-on-complete-access-config/workpad.md`

## workspace-owned: validation evidence

- 2026-08-16 22:32:26 `verify`: passed — OK

## key decisions

- none yet

## notes for ko

- none yet

## improvements noticed

- none yet

## issues and recovery

- none yet

---

## publish checklist

```bash
bun run task:push -- --message "type(os): description" --changed
bun run task:pr
bun run task:finish
```

## Test-first contract

behavior under test: when the internal dashboard has no Access configuration, its shared-host paths must fall through to normal workspace routing instead of returning dashboard 401/403; complete configuration enables dashboard interception; partial configuration fails closed without falling through.
existing local pattern: install-control-plane docs state Access prerequisites must be satisfied before enabling the internal dashboard; the edge Worker already receives the three optional authorization bindings.
new or changed tests: add edge integration coverage for absent, complete, and partial dashboard Access configuration; remove unconditional deployment-secret requirements so a disabled dashboard does not block restoring the shared workspace Worker.
focused red command: cd packages/os && bun vitest run tests/internal-dashboard-integration.test.ts tests/cloudflare-worker-release-readiness.test.ts
expected red failure: absent dashboard bindings still intercept `/` and `/users`; release readiness currently treats an optional disabled dashboard as a hard deployment failure.
no-test waiver: not applicable

- 2026-08-16 22:29:59 append: `.task/os/gate-internal-dashboard-routing-on-complete-access-config/workpad.md`

## Implementation and verification

- Added explicit dashboard Access states: disabled when all three bindings are absent, configured only when all three are present (or a test authorizer is injected), and partial otherwise.
- Disabled state falls through to canonical workspace routing, so an incomplete dashboard rollout cannot seize `/`, `/users`, or other shared-host routes.
- Partial state returns `workspace_auth_unavailable` 503 before dashboard data or handlers run.
- Configured state preserves workspace-session validation, HTML login redirect, and Cloudflare Access operator authorization.
- Removed the unconditional dashboard secret requirement from Worker deployment readiness because absence now means safely disabled; the existing core edge secrets remain mandatory.
- Red: focused suites failed 3 assertions (disabled route received 403 instead of fallthrough 404, partial config received 403 instead of 503, optional-disabled deploy was rejected).
- Green: `internal-dashboard-integration`, `install-control-plane-cloudflare`, and `cloudflare-worker-release-readiness` passed 14/14.
- Green: `yarn nx run consuelo-os:typecheck` passed.

- 2026-08-16 22:32:10 append: `.task/os/gate-internal-dashboard-routing-on-complete-access-config/workpad.md`
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
{
"area": "os",
"stream": "stream/os",
"taskBranch": "task/os/repair-runtime-retention-and-watchdog-recovery",
"baseBranch": "stream/os",
"sourceBranch": "stream/os",
"startFrom": "stream",
"prNumber": 2150,
"prUrl": "https://github.com/consuelohq/opensaas/pull/2150",
"githubPrUrl": "https://github.com/consuelohq/opensaas/pull/2150",
"graphitePrUrl": "https://app.graphite.com/github/pr/consuelohq/opensaas/2150/repair-runtime-retention-and-watchdog-recovery",
"taskPrUrl": "https://github.com/consuelohq/opensaas/pull/2150",
"taskGraphitePrUrl": "https://app.graphite.com/github/pr/consuelohq/opensaas/2150/repair-runtime-retention-and-watchdog-recovery",
"worktreePath": "/private/var/folders/vl/1zvhm0bj28d1dbvbcb12b39r0000gn/T/opensaas-worktrees/task-os-repair-runtime-retention-and-watchdog-recovery",
"taskSession": "tsk_af28ff74214b",
"tmuxSession": "opensaas-os-repair-runtime-retention-and-watchdog-recovery-af28ff74",
"sessionPath": "/private/var/folders/vl/1zvhm0bj28d1dbvbcb12b39r0000gn/T/opensaas-worktrees/task-os-repair-runtime-retention-and-watchdog-recovery/.task/os/repair-runtime-retention-and-watchdog-recovery/session.json",
"createdAt": "2026-08-16T22:46:56.311Z"
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
{
"taskSession": "tsk_af28ff74214b",
"tmuxSession": "opensaas-os-repair-runtime-retention-and-watchdog-recovery-af28ff74",
"area": "os",
"stream": "stream/os",
"taskBranch": "task/os/repair-runtime-retention-and-watchdog-recovery",
"branch": "task/os/repair-runtime-retention-and-watchdog-recovery",
"worktreePath": "/private/var/folders/vl/1zvhm0bj28d1dbvbcb12b39r0000gn/T/opensaas-worktrees/task-os-repair-runtime-retention-and-watchdog-recovery",
"worktree": "/private/var/folders/vl/1zvhm0bj28d1dbvbcb12b39r0000gn/T/opensaas-worktrees/task-os-repair-runtime-retention-and-watchdog-recovery",
"prNumber": 2150,
"prUrl": "https://github.com/consuelohq/opensaas/pull/2150",
"createdAt": "2026-08-16T22:46:56.310Z",
"tmuxCreated": true,
"sessionPath": "/private/var/folders/vl/1zvhm0bj28d1dbvbcb12b39r0000gn/T/opensaas-worktrees/task-os-repair-runtime-retention-and-watchdog-recovery/.task/os/repair-runtime-retention-and-watchdog-recovery/session.json"
}
154 changes: 154 additions & 0 deletions .task/os/repair-runtime-retention-and-watchdog-recovery/workpad.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,154 @@
# Repair runtime retention and watchdog recovery

branch: `task/os/repair-runtime-retention-and-watchdog-recovery`
stream: `stream/os`
pr: https://app.graphite.com/github/pr/consuelohq/opensaas/2150/repair-runtime-retention-and-watchdog-recovery
github pr: https://github.com/consuelohq/opensaas/pull/2150
started: 2026-08-16

## acceptance criteria

- [x] Remove corrupt, obsolete runtime releases without weakening verification for current, previous, pinned, or content-base releases.
- [x] Exclude worktrees and vendor trees from both semantic index implementations while retaining existing generated-output exclusions.
- [x] Install an integrity-checked `consuelo-os` Bun clone before persisting daemon runtime paths.
- [x] Smoke-test one isolated worker without contending with the already-running supervisor.
- [x] Let the watchdog fall back to bounded launchd recovery only when canonical rolling recovery rejects an unhealthy pool.
- [x] Complete the focused suite and typecheck/verification gates.
- [ ] Publish the task.

## plan

1. Reproduce each retention, index, installer, and watchdog regression with a focused red test.
2. Implement the smallest bounded fixes and validate a live named-executable cutover.
3. Run the focused and package-level gates, inspect the final diff, and publish to `stream/os`.

## current status

- Implementation and verification are complete. Publish remains.

## files changed

- `packages/os/scripts/bootstrap.sh`
- `packages/os/scripts/install-system-daemons.sh`
- `packages/os/scripts/lib/index/indexer.js`
- `packages/os/scripts/lib/lifecycle/retention.ts`
- `packages/os/scripts/start-consuelo-daemon.sh`
- `packages/os/scripts/workspace-watchdog.sh`
- `packages/os/tests/index-path-exclusions.test.ts`
- `packages/os/tests/installer-runtime-dependencies.test.ts`
- `packages/os/tests/lifecycle-retention-uninstall.test.ts`
- `packages/os/tests/system-daemon-reliability.test.ts`
- `packages/workspace/scripts/lib/index/indexer.js`
- `packages/workspace/tests/index-path-exclusions.test.js`

## workspace-owned: files changed

- none yet

## workspace-owned: activity log

- 2026-08-16 22:47:14 fs.write: `.task/os/repair-runtime-retention-and-watchdog-recovery/workpad.md`
- 2026-08-16 23:09:59 fs.write: `.task/os/repair-runtime-retention-and-watchdog-recovery/workpad.md`
- 2026-08-16 23:11:47 fs.write: `.task/os/repair-runtime-retention-and-watchdog-recovery/workpad.md`

## workspace-owned: validation evidence

- Retention regression: red on corrupt obsolete bundle digest; green after classifying only unprotected obsolete releases for deletion.
- Index path regressions: red on `vendor` and nested worktree paths; green for both mirrored indexers.
- Named executable regression: red on missing `ensure_named_bun_runtime`; green after APFS clone/copy, byte comparison, and atomic replacement.
- Installer stage regression: red on missing single-worker mode; green plus live smoke worker `/ready` on port 10851 while the production supervisor remained active.
- Watchdog fallback regression: red with no launchd recovery after canonical CLI failure; green with a bounded `kickstart` fallback.
- Live node: ports 46321 and 46322 run as `consuelo-os`; Caddy 46320, both worker readiness endpoints, and pooled health are green.
- Live watchdog: `StartInterval=30`, last exit code 0, and idle `not running` state between successful probes.
- Full lifecycle retention/uninstall suite: 21/21 passing after bringing its signed-bundle fixture up to the current recovery-capability contract.
- Full daemon reliability and index slices: 16/16 passing; installer named-runtime and isolated-stage regressions passing.
- `yarn nx run consuelo-os:typecheck`: passing.
- `git diff --check` and `bash -n` for every changed shell entrypoint: passing.
- `yarn nx run consuelo-os:test` cannot enter the package because Yarn does not recognize `packages/os` in this temporary worktree. Direct Vitest execution is used for the affected suites.
- The installer suite's 10 unrelated dry-run fixture failures reproduce unchanged from `HEAD` in an isolated archive; this repair adds two passing tests and does not add installer failures.

## key decisions

- Retention continues to fail closed for every protected release; only canonical, unprotected obsolete release directories can bypass strict verification on their way to deletion.
- The installer stages `server/main.ts` as one supervised smoke worker so it does not open the singleton lifecycle endpoint or reuse the production pool snapshot.
- Normal CLI restart remains rolling and non-destructive. Only the already-thresholded watchdog recovery path may use launchd kickstart after rolling recovery returns non-zero.
- The process-name change reuses Bun's existing embedded signature through an APFS clone/copy; no application bundle or paid Apple signing membership is required.

## notes for ko

- The historical watchdog failures followed SQLite `unable to open database file` errors under critical disk pressure. The pool was already non-ready, so rolling replacement correctly refused it; the watchdog lacked the final launchd recovery step.

## improvements noticed

- none yet

## issues and recovery

- The canonical daemon installer smoke test initially failed because it started a second supervisor against the live worker-pool snapshot. The new single-worker stage mode removes that conflict.
- Codex could boot out but not bootstrap the GUI LaunchAgent from its app sandbox. Ko reloaded the validated plist once from Terminal; the connector and both named workers recovered.

---

## publish checklist

```bash
bun run task:push -- --message "type(os): description" --changed
bun run task:pr
bun run task:finish
```

## Test-first contract

behavior under test: runtime retention accepts a verified installed release whose directory name uses the canonical sha256-<digest> form, then removes all releases except current and previous; watchdog restart paths converge without a permanent lock or stopped LaunchAgent.
existing local pattern: inspect lifecycle engine retention validation and adjacent focused tests before editing.
new or changed tests: add a focused regression reproducing the installed-directory digest mismatch and the expected two-release keep set; add watchdog coverage only if the bug is in repository logic rather than current launchd state.
focused red command: to be selected from the nearest lifecycle test target after inspection.
expected red failure: retention rejects the canonical installed release or preserves obsolete releases because identity comparison uses incompatible digest forms.
no-test waiver: not applicable.

- 2026-08-16 22:47:14 append: `.task/os/repair-runtime-retention-and-watchdog-recovery/workpad.md`

- 2026-08-16 22:49:59 apply-patch: `packages/os/tests/lifecycle-retention-uninstall.test.ts`
- 2026-08-16 22:51:31 apply-patch: `packages/os/tests/lifecycle-retention-uninstall.test.ts`
- 2026-08-16 22:52:10 apply-patch: `packages/os/scripts/lib/lifecycle/retention.ts`
- 2026-08-16 22:52:19 apply-patch: `packages/os/tests/lifecycle-retention-uninstall.test.ts`
## Semantic index path policy contract

behavior under test: the mirrored workspace and OS semantic indexers reject vendor trees and nested worktree roots, while continuing to index ordinary source files; existing exclusions already cover node_modules, dist/build/out, caches, generated output, coverage, and task metadata.
existing local pattern: both indexers export isIndexablePath and keep a mirrored EXCLUDE_DIRS set.
new or changed tests: add focused path-policy tests for both package copies.
focused red command: yarn vitest run packages/workspace/tests/index-path-exclusions.test.js packages/os/tests/index-path-exclusions.test.ts
expected red failure: vendor and worktrees paths are currently accepted.
no-test waiver: not applicable.

- 2026-08-16 23:09:59 append: `.task/os/repair-runtime-retention-and-watchdog-recovery/workpad.md`

- 2026-08-16 23:10:18 apply-patch: `packages/workspace/tests/index-path-exclusions.test.js`
- 2026-08-16 23:10:18 apply-patch: `packages/os/tests/index-path-exclusions.test.ts`
- 2026-08-16 23:10:34 apply-patch: `packages/workspace/scripts/lib/index/indexer.js`
- 2026-08-16 23:10:34 apply-patch: `packages/os/scripts/lib/index/indexer.js`
## Named service executable contract

behavior under test: macOS bootstrap atomically materializes an integrity-checked Bun clone at $CONSUELO_HOME/bin/consuelo-os and persists it as BUN_BIN before daemon generation, so supervisor and worker process names are Consuelo-owned without requiring app signing.
existing local pattern: Windows already copies Bun into the Consuelo bin directory and verifies source/destination SHA-256 before service registration.
new or changed tests: extend installer runtime dependency contract with named executable, APFS clone fallback, byte comparison, atomic replacement, and ordering assertions.
focused red command: yarn vitest run packages/os/tests/installer-runtime-dependencies.test.ts -t 'named Consuelo service executable'
expected red failure: bootstrap does not yet contain ensure_named_bun_runtime or the consuelo-os target.
no-test waiver: not applicable.

- 2026-08-16 23:11:47 append: `.task/os/repair-runtime-retention-and-watchdog-recovery/workpad.md`

- 2026-08-16 23:14:04 apply-patch: `packages/os/tests/installer-runtime-dependencies.test.ts`
- 2026-08-16 23:15:06 apply-patch: `packages/os/scripts/bootstrap.sh`
- 2026-08-16 23:28:22 apply-patch: `packages/os/tests/installer-runtime-dependencies.test.ts`
- 2026-08-16 23:28:42 apply-patch: `packages/os/scripts/start-consuelo-daemon.sh`
- 2026-08-16 23:28:42 apply-patch: `packages/os/scripts/install-system-daemons.sh`
- 2026-08-16 23:31:55 apply-patch: `packages/os/tests/system-daemon-reliability.test.ts`
- 2026-08-16 23:32:15 apply-patch: `packages/os/scripts/workspace-watchdog.sh`

- 2026-08-16 23:33:04 apply-patch: `.task/os/repair-runtime-retention-and-watchdog-recovery/workpad.md`
- 2026-08-16 23:36:21 apply-patch: `packages/os/tests/lifecycle-retention-uninstall.test.ts`
- 2026-08-16 23:36:55 apply-patch: `packages/os/tests/lifecycle-retention-uninstall.test.ts`
- 2026-08-16 23:38:29 apply-patch: `packages/os/tests/facade/__snapshots__/facade.test.ts.snap`

- 2026-08-16 23:38:48 apply-patch: `.task/os/repair-runtime-retention-and-watchdog-recovery/workpad.md`
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
{
"area": "os",
"stream": "stream/os",
"taskBranch": "task/os/restore-internal-dashboard-browser-auth-handoff",
"baseBranch": "stream/os",
"sourceBranch": "stream/os",
"startFrom": "stream",
"prNumber": 2147,
"prUrl": "https://github.com/consuelohq/opensaas/pull/2147",
"githubPrUrl": "https://github.com/consuelohq/opensaas/pull/2147",
"graphitePrUrl": "https://app.graphite.com/github/pr/consuelohq/opensaas/2147/restore-internal-dashboard-browser-auth-handoff",
"taskPrUrl": "https://github.com/consuelohq/opensaas/pull/2147",
"taskGraphitePrUrl": "https://app.graphite.com/github/pr/consuelohq/opensaas/2147/restore-internal-dashboard-browser-auth-handoff",
"worktreePath": "/private/var/folders/vl/1zvhm0bj28d1dbvbcb12b39r0000gn/T/opensaas-worktrees/task-os-restore-internal-dashboard-browser-auth-handoff",
"taskSession": "tsk_fdaa1f3e0fdd",
"tmuxSession": "opensaas-os-restore-internal-dashboard-browser-auth-handoff-fdaa1f3e",
"sessionPath": "/private/var/folders/vl/1zvhm0bj28d1dbvbcb12b39r0000gn/T/opensaas-worktrees/task-os-restore-internal-dashboard-browser-auth-handoff/.task/os/restore-internal-dashboard-browser-auth-handoff/session.json",
"createdAt": "2026-08-16T22:16:27.043Z"
}
Loading
Loading