Skip to content

R2: seal rollback-backed local production deployment - #6

Open
AnubisQuantumCipher wants to merge 53 commits into
r1b/phase1b-sacrificial-observationfrom
r2/full-local-native-completion-omp
Open

R2: seal rollback-backed local production deployment#6
AnubisQuantumCipher wants to merge 53 commits into
r1b/phase1b-sacrificial-observationfrom
r2/full-local-native-completion-omp

Conversation

@AnubisQuantumCipher

@AnubisQuantumCipher AnubisQuantumCipher commented Aug 14, 2026

Copy link
Copy Markdown
Owner

Verdict

COMPLETE for the authorized, agent-completable local deployment and production-hardening scope.

Supported claim: DeskTidy local production deployment is operational and rollback-backed on the operator Mac. Public Apple distribution is not complete.

Final head: 7d35d716ff345147c6390ea8a340034c6fb7841e

Final implementation

  • The single authorized canary completed actual-core Undo A→B→A with byte SHA-256 749317f70666b2bb249b58d18c010f8a1a18a8482433c48e7be26c73d515dbcd; its first watcher re-sort defect was fixed and preserved in evidence. Source and destination are absent.
  • Watcher, Tidy Now, and Undo share one lock. The lock now opens no-follow/close-on-exec and verifies a current-user-owned regular single-link inode before permission or lock operations. Hostile control G15 proves a symlink target is unchanged.
  • Automatic sorting preserves exact durable Undo restorations and fails closed on damaged ledger startup.
  • The source installer stages compile, signature, self-test, and authority-check before replacing any installed movement binary.
  • The inactive waitlist/API, Neon dependency, and unused marketing/demo components were removed. The website is a four-route static truth surface with no email-collection endpoint.
  • The canonical gate now executes website locked install, lint, production build, dependency audit, and exact read-only live-authority checks.

Verification

Hosted CI: https://github.com/AnubisQuantumCipher/desktidy/actions/runs/31878563415

  • exact head 7d35d716ff345147c6390ea8a340034c6fb7841e
  • macOS 14: PASS
  • macOS 15: PASS
  • CodeRabbit: non-failing

Final canonical summary: /private/tmp/desktidy-production-final-canonical-7d35d71.json

  • SHA-256 fd5b23485f18298e7e39b6091a23befb78d1f209ae71167eca45341e6cce2ea3
  • 46 records: 42 passed, 0 failed, 2 indeterminate, 2 blocked
  • independent validator: PASS
  • website lint/build/audit and direct live authority: PASS

Detached clean clone /private/tmp/desktidy-clean-final.zxRxs6 at the exact head:

  • app/icon/migration bundle/package/fixture smoke/deep signature: PASS
  • locked website install, ESLint, TypeScript, static production build: PASS
  • dependency audit: 0 vulnerabilities

Standard security scan b9c58662-f549-4e74-9edc-146a41cc8809 reviewed 157 tracked files across six surfaces, reported the movement-lock link-following issue, and sealed canonical report/SARIF artifacts. The finding is remediated and regression-tested. Receipt: docs/evidence/R2_PRODUCTION_HARDENING_2026-08-15.md.

Installed exact-head state

  • app identity: 7d35d716ff345147c6390ea8a340034c6fb7841e
  • app executable SHA-256: 995399fb0a18cf523bdc06657805026a0775a9e19ee3b23766d9018acc27548b
  • bundled/live sorter SHA-256: b54c11dc736563cb1696c865909ec9eab55e5dbd6f92d334d1cf82d86796094a
  • bundled/live notifier SHA-256: 2e3ec86dc6b126e418ae65479697a5964922eb2e01ea253b5594c44648019dfb
  • old labels/plists: absent; legacy implementation retained only for rollback
  • com.desktidy.sort and com.desktidy.notify: loaded
  • authority: SOLE
  • effective state: runningHealthy, mover com.desktidy.sort, target source nativeConfig, ledger valid(8)
  • Archive, Docs, Media, Projects: present at Desktop root
  • installed app relaunch and explicit service reload: observed

New rollback manifests:

  • app backup: ~/Library/Application Support/DeskTidy App Backups/20260815T100500Z-7d35d71, manifest SHA-256 358398a25fb754693d3ec20e9dadda652e3218a0ab5f5d43af02657e8adf3fb2
  • sorter/notifier backup: ~/Library/Application Support/DeskTidy Live Binary Backups/20260815T100500Z-7d35d71, manifest SHA-256 6876a9de844ea8f35070f6ce107dcf520ad77b5ba02762246a982950aa91da5a

Original migration, prior-support, and legacy-registration manifests also re-verify.

Explicit residuals

  • Historical Phase 1B lifecycle evidence remains indeterminate/non-reproducible.
  • Keyboard focus traversal and spoken VoiceOver output remain INDETERMINATE.
  • Direct sacrificial lifecycle and reboot/login evidence remain BLOCKED by the mission boundary; no reboot or extra live canary was performed.
  • Developer ID signing, notarization, TestFlight, App Store, public installer/Homebrew native distribution, and public release remain blocked on Apple Developer Program access and a separate architect decision.
  • The artifact remains ad-hoc signed; Gatekeeper rejection is expected.

Checklist

  • Named canary actual-core Undo completed first and byte-identical
  • Material security finding fixed and hostile regression added
  • Source, docs, website, claim gates, installer, and evidence reconciled
  • Canonical gate validated with zero failures
  • Detached exact-head clean-clone verification passed
  • Exact-head macOS 14 and macOS 15 hosted CI passed
  • Exact final app and services installed with verified rollback backups
  • Final live authority, ledger, category-root, relaunch, and persistence probes passed
  • Local/remote/PR head equality and mergeability verified
  • Developer ID/notarization/public distribution (external blocker; separate decision)

This PR is ready for architect review, remains unmerged, and must not be merged or released without a separate explicit decision.

@coderabbitai

coderabbitai Bot commented Aug 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 5b86e0d5-6975-48b7-836b-4398adf31f00

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@AnubisQuantumCipher AnubisQuantumCipher changed the title R2: continue full local native completion R2: full-local native completion and status surface Aug 15, 2026
@AnubisQuantumCipher AnubisQuantumCipher changed the title R2: full-local native completion and status surface R2: seal rollback-backed local production deployment Aug 15, 2026
@AnubisQuantumCipher
AnubisQuantumCipher marked this pull request as ready for review August 15, 2026 09:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant