[Epic] 1953-epic-desktop-transport-api - #1976
Draft
propr-dev[bot] wants to merge 451 commits into
Draft
Conversation
Implemented the requested follow-up without committing. - Preserved c6f F13 permissions/tests/docs unchanged. - Restored DMG image and containing-directory sync after atomic rename in [make-dmg.mjs](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T14-03-36/apps/desktop/scripts/make-dmg.mjs:40). - Added process-only smoke trigger inheritance with guaranteed restoration. - Added 64 KiB capped, regular/non-link JSON log inspection with the exact seven-event allowlist and no raw output. - Exit 0 now requires MVP flows, layout, and renderer-ready evidence; timeout diagnostics emit only fixed present/absent states. - Added focused regressions in [release-workflow.test.ts](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T14-03-36/apps/desktop/src/release-workflow.test.ts:345). Passed locally: - Desktop: 122 passed, 6 platform skips - Desktop/UI typecheck - Validate fast unit: 278 passed - Hosted tunnel regressions: 316 passed - UI compatibility: 66 passed - Release metadata and CLI pack - `git diff --check` Native Windows/macOS, six-target aggregate, actionlint, and Redis-backed Full require CI runners; this Linux environment has no Windows/macOS hosts, Docker, or Redis. PR: #1972 Comment by: @integry (ID: 5479489023) Model: gpt-5.6-sol
Implemented F10–F12 only. - Forwarded bounded `DOCKER_TLS`, preserving Docker’s documented non-empty TLS behavior. Added unit and built-CLI TLS-only inspection coverage. [index.ts](/tmp/git-processor/worktrees/integry/propr/pr-1989-followup-2026-08-31T14-24-29/packages/cli/src/orchestrator/index.ts:144) ([Docker CLI documentation](https://docs.docker.com/reference/cli/docker/)) - Added safe recovery for the exact temporary/READY two-hardlink crash remnant, with bounded directory enumeration and inode revalidation. [publicInstanceIdentity.ts](/tmp/git-processor/worktrees/integry/propr/pr-1989-followup-2026-08-31T14-24-29/packages/local-setup/src/publicInstanceIdentity.ts:263) - Rejected filesystem-root identity data directories before creating state. [publicInstanceIdentity.ts](/tmp/git-processor/worktrees/integry/propr/pr-1989-followup-2026-08-31T14-24-29/packages/local-setup/src/publicInstanceIdentity.ts:537) Validation passed: - Focused CLI tests - 27 identity tests - Built CLI integration tests - CLI lint - CLI/local-setup/API typechecks - Workspace build - Root unit suite - `git diff --check` No commit was created. PR: #1989 Comment by: @integry (ID: 5479752704) Model: gpt-5.6-sol
Implemented only the requested Windows smoke boundary fix: - Added child-only `PROPR_DESKTOP_SMOKE_TEST=1` through `$applicationStart.Environment`. - Removed parent process environment mutation/restoration. - Disposed and nulled the application process before evidence files are inspected, retaining double-disposal safety. - Added focused assertions for environment isolation, disposal ordering, and bounded lifecycle stages. Changed: - [test-installed-windows-app.ps1](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T14-35-39/apps/desktop/scripts/test-installed-windows-app.ps1:357) - [release-workflow.test.ts](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T14-35-39/apps/desktop/src/release-workflow.test.ts:345) Validation passed: - Focused release-workflow tests: 11/11 - Full desktop tests: 122 passed, 6 platform-skipped, 0 failed - Desktop typecheck - `git diff --check` Native x64/ARM64 hosted jobs remain the installation-smoke authority. PR: #1972 Comment by: @integry (ID: 5479892767) Model: gpt-5.6-sol
…ommitting. Implemented the exact Windows evidence-reader fix without committing. - Replaced overload-sensitive `New-Object FileStream` with typed `[IO.FileStream]::new(...)`. - Retained `FileShare.Read`; retries only sharing/lock violations 32/33 for up to two seconds. - Guaranteed stream disposal through `finally`. - Preserved fixed filenames, non-reparse regular-file checks, 64 KiB caps, strict UTF-8, and JSON-line parsing. - Added the fixed diagnostic enum and redacted `EVIDENCE_INSPECTION_FAILED:<CODE>` output. - Added focused retry, disposal, allowlist, and output-redaction regressions. Changed only: - [test-installed-windows-app.ps1](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T14-58-07/apps/desktop/scripts/test-installed-windows-app.ps1:5) - [release-workflow.test.ts](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T14-58-07/apps/desktop/src/release-workflow.test.ts:460) Validation: - Focused release-workflow tests: 12/12 passed - `git diff --check`: passed - Diff scope: exactly the two requested files Fresh native x64/ARM64 hosted jobs remain authoritative. PR: #1972 Comment by: @integry (ID: 5480169828) Model: gpt-5.6-sol
Implemented only F13 and F14. - Windows ACL verification unavailable now fails closed as `invalidConfig`, with `apiReady: false`, before identity, Docker, or API probing in [connectCommand.ts](/tmp/git-processor/worktrees/integry/propr/pr-1989-followup-2026-08-31T15-06-11/packages/cli/src/commands/connectCommand.ts). - Windows root keys now preserve case in [rootKey.ts](/tmp/git-processor/worktrees/integry/propr/pr-1989-followup-2026-08-31T15-06-11/packages/cli/src/config/rootKey.ts). - Added regression coverage for distinct case-sensitive Windows roots and fail-closed readiness. - Updated the Windows ordinary-user harness expectations and relevant documentation. Verification passed: - 64 focused tests - CLI typecheck - CLI lint - CLI build - Windows harness syntax check - `git diff --check` The Windows-only harness could not be executed on this Linux host. No commit was created. PR: #1989 Comment by: @integry (ID: 5480274186) Model: gpt-5.6-sol
…p/git-processor/worktrees/integry/propr/pr-1989-followup-2026-08-31T15-19-13/scripts/verify-platform-safe-connect.mjs:39): Updated only [scripts/verify-platform-safe-connect.mjs](/tmp/git-processor/worktrees/integry/propr/pr-1989-followup-2026-08-31T15-19-13/scripts/verify-platform-safe-connect.mjs:39): - Exact expected count: 73 → 74 - Matching fixed failure/success messages: 73/73 → 74/74 - Exact-count policy and F13/F14 behavior unchanged Validation: - Verifier/focused suite: 74 passed, 0 failed, 0 skipped - `git diff --check`: passed - No other files changed PR: #1989 Comment by: @integry (ID: 5480438493) Model: gpt-5.6-sol
…7a21338e173ad0eb282b8844510a01e7`. Implemented the exact evidence-parser fix on head `1894e29c7a21338e173ad0eb282b8844510a01e7`. - Added distinct fixed `EVENT_PARSE` phase after bounded FileStream reading. - Guarded `null`, scalars, arrays, malformed JSON, missing/non-string/case-mismatched `event`. - Wrapped complete per-line conversion and extraction with catch/continue. - Counts only allowlisted event strings; preserves redacted fixed diagnostics and strict UTF-8 behavior. - Added focused static regressions for all requested boundaries. - Changed only the two authorized files. Validation: - `npx tsx --test apps/desktop/src/release-workflow.test.ts` — 12/12 passed. - `git diff --check` — passed. PR: #1972 Comment by: @integry (ID: 5480490767) Model: gpt-5.6-sol
…nt tests det Implemented by ProPR AI using gpt-5.6-sol model. Implementation completed successfully.
Implemented F15 and F16 only. - Windows ACL-unavailable status now tests exit `1`, `invalidConfig`, and `ACL_DIAGNOSTIC_UNAVAILABLE`. - Missing, empty, or repeated `--root` options return one fixed `INVALID_ROOT` JSON document with exit `1`. - Added built-CLI coverage for all malformed root forms. Validation passed: - CLI typecheck, build, and lint - Focused tests: 4/4 - Platform-safe Connect verifier: 74/74 - Full-suite dispatcher integration test: 2/2 - `git diff --check` PR: #1989 Comment by: @integry (ID: 5480687811) Model: gpt-5.6-sol
…d2`. Implemented the narrow help-mode fix on exact head `3b87d8ad2`. - [index.ts](/tmp/git-processor/worktrees/integry/propr/pr-1989-followup-2026-08-31T15-51-11/packages/cli/src/index.ts:163): `connect status --help`/`-h` now receives Commander help precedence, even with malformed/repeated roots or `--json`, without loading cwd dotenv. - [index.test.ts](/tmp/git-processor/worktrees/integry/propr/pr-1989-followup-2026-08-31T15-51-11/packages/cli/src/index.test.ts:52): added built-CLI assertions for exit 0, standard usage, empty stderr, and no discovery JSON or sentinel leakage. Validation passed: - CLI typecheck, build, and lint - Focused CLI tests: 4/4 - Platform-safe verifier: 74/74 - Dispatcher integration: 2/2 - `git diff --check` - Malformed JSON mode remains one `INVALID_ROOT` document with exit 1 Only the two CLI files were changed; no commit was created. PR: #1989 Comment by: @integry (ID: 5480836684) Model: gpt-5.6-sol
…d head `3e916db933ba73f24ebd31b239a4050a9fd85f33`. Implemented the Windows smoke observability fix on unchanged head `3e916db933ba73f24ebd31b239a4050a9fd85f33`. - Added an authorized, fixed-name, regular non-link, event-only, synchronous/fsynced evidence sink in [smoke-test-evidence.ts](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T15-46-58/apps/desktop/src/smoke-test-evidence.ts:11). - Required both argv and child-environment smoke triggers. - Added earliest `desktop.smoke.authorized` evidence and required app-ready, MVP flow, layout, renderer-ready, and shutdown markers in [main.ts](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T15-46-58/apps/desktop/src/main.ts:34). - Extended the bounded Windows reader to the fixed evidence file while retaining stdout/stderr inspection, ACL/non-reparse checks, strict UTF-8 parsing, size caps, bounded retries, and PRESENT/ABSENT summaries in [test-installed-windows-app.ps1](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T15-46-58/apps/desktop/scripts/test-installed-windows-app.ps1:37). - Made `Start-Process` receive one deterministic argument line while retaining child-only environment delivery, credentials, isolated profile, waits, and cleanup. - Added focused non-creation, allowlist, sensitive-output, ordering, parser, and launch-delivery regressions. Validation: - Focused tests: 21 passed. - Full desktop suite: 127 passed, 6 platform skips. - Desktop typecheck: passed. - `git diff --check`: passed. - No merge, runtime sync, or commit performed. Native Windows x64/ARM64 installed-app jobs remain the authoritative final validation. PR: #1972 Comment by: @integry (ID: 5480784971) Model: gpt-5.6-sol
Implemented the exact shutdown-order fix. - Registered `before-quit` before `createMainWindow()` can trigger smoke shutdown, preserving the existing one-shot guard and second-quit behavior in [main.ts](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T16-05-41/apps/desktop/src/main.ts:351). - Added focused ordering regression covering shutdown once, marker-before-final-quit/sink-close, and all six required smoke markers in [smoke-test-authorization.test.ts](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T16-05-41/apps/desktop/src/smoke-test-authorization.test.ts:92). - No runtime sync, artifact, authorization, evidence, durability, or release-gate changes. Validation: - Desktop typecheck: passed - Full desktop suite: 127 passed, 6 platform skips - Focused release/smoke tests: 21 passed - `git diff --check`: passed - Only the two intended files changed Native x64/ARM64 jobs remain authoritative. PR: #1972 Comment by: @integry (ID: 5481013595) Model: gpt-5.6-sol
…overy authority. Implemented the exact POSIX `--` edge without changing discovery authority. Changes: - Raw Connect-status invocation, root, and help scanning now stops at exact `--`. - Added scanner cases for pre/post-delimiter positionals and roots. - Added hostile-cwd built-CLI regressions for both `/x` root forms and post-delimiter help flags. - Verified fixed `INVALID_ROOT` JSON, exit 1, sanitized stderr, bounded output, and no Commander usage/error leakage. Files changed: - [index.ts](/tmp/git-processor/worktrees/integry/propr/pr-1989-followup-2026-08-31T16-09-07/packages/cli/src/index.ts) - [index.test.ts](/tmp/git-processor/worktrees/integry/propr/pr-1989-followup-2026-08-31T16-09-07/packages/cli/src/index.test.ts) - [connectCliIntegration.test.ts](/tmp/git-processor/worktrees/integry/propr/pr-1989-followup-2026-08-31T16-09-07/test/connectCliIntegration.test.ts) All requested checks passed: CLI build, typecheck, lint, focused tests, built integration, platform-safe verifier 74/74, dispatcher integration, and `git diff --check`. No commit was created. PR: #1989 Comment by: @integry (ID: 5481048865) Model: gpt-5.6-sol
…ut merging or syncing runtime. Implemented the alternate-credential smoke launch fix without merging or syncing runtime. - Replaced the application’s string-joined `Start-Process` launch with direct `ProcessStartInfo`, exact `ArgumentList.Add` entries, alternate credentials/profile, absolute executable/working directory, and child-only smoke environment. PowerShell documents that `Start-Process` joins argument arrays into one string, losing exact argument boundaries. [Microsoft documentation](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/start-process?view=powershell-7.5) - Added bounded asynchronous stdout/stderr draining and disposal before evidence inspection while retaining process-tree termination. - Partial smoke authorization now fails closed with exit code 1 before Electron readiness, without dialogs or raw diagnostics. - Preserved the ACL-private profile, evidence parser/sink, lifecycle ordering, renderer/layout/profile requirements, artifacts, and release gates. Changed files include [test-installed-windows-app.ps1](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T16-27-07/apps/desktop/scripts/test-installed-windows-app.ps1:99) and [main.ts](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T16-27-07/apps/desktop/src/main.ts:34). Validation passed: - Focused tests: 19/19 - Full desktop suite: 128 passed, 6 platform skips - Desktop and UI typecheck - `git diff --check` Native Windows x64/ARM64 installed-smoke jobs remain the authoritative launch verification. PR: #1972 Comment by: @integry (ID: 5481272447) Model: gpt-5.6-sol
Implemented the F18 child-environment boundary fix. - Clears inherited `ProcessStartInfo.Environment` before launch. - Adds only: `APPDATA`, `LOCALAPPDATA`, `PROPR_DESKTOP_SMOKE_TEST`, `SystemRoot`, `TEMP`, `TMP`, and `USERPROFILE`. - Confines profile/temp paths beneath the ACL-private smoke directory and verifies inherited ACLs. - Preserves direct alternate-credential launch, exact `ArgumentList` handling, dual authorization, bounded streams/processes, evidence, cleanup, and release gates. - Added hostile-parent environment and spaced/unspaced argv regressions. Changed: - [test-installed-windows-app.ps1](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T16-48-29/apps/desktop/scripts/test-installed-windows-app.ps1:67) - [release-workflow.test.ts](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T16-48-29/apps/desktop/src/release-workflow.test.ts:491) Validation passed: - Desktop/UI typecheck - Full desktop suite: 130 passed, 6 platform-specific skips - Focused tests: 21 passed - `git diff --check` Only the two scoped files changed. Native Windows x64/ARM64 installed-smoke jobs remain authoritative. PR: #1972 Comment by: @integry (ID: 5481521547) Model: gpt-5.6-sol
…d-app PowerShell path or workflows. Implemented the F19 follow-up without touching the installed-app PowerShell path or workflows. - Layout evidence now reports renderer screen/work area and native content bounds. Assertions enforce preferred-size clamping, minimum behavior, work-area containment, native-derived viewport sizing, and existing UI containment/spacing checks. - Packaged child environment now uses exact platform allowlists, private profile/temp/XDG paths, validated Windows `SystemRoot` or Linux Xvfb inputs, and `shell: false`. - Added preferred, 1024×720-clamped, minimum, undersized-work-area, hostile-secret, and bounded-cleanup tests in [packaged-smoke-support.test.mjs](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T17-09-43/apps/desktop/scripts/packaged-smoke-support.test.mjs:47). Validation: - Desktop typecheck: passed - Desktop tests: 140 passed, 6 platform skips - Focused tests: 9 passed - Linux package and fuse inspection: passed - `git diff --check`: passed - GUI smoke unavailable because this host lacks Xvfb - Repository full suite reached 193/333 cleanly, then was stopped because Redis is unavailable (`127.0.0.1:6379`) PR: #1972 Comment by: @integry (ID: 5481770676) Model: gpt-5.6-sol
…b2a9250e1f5ce3e6ed94126`. Implemented the F20 filename fix on head `6d12bb7a00cef1e4cb2a9250e1f5ce3e6ed94126`. - Non-MSI artifacts now use canonical names ending in `.deb`, `.rpm`, `.zip`, or `.dmg`. - Windows names remain exactly `-Machine-Setup.msi`. - Finalization and signing enforce the exact 12-artifact matrix and reject malformed, duplicate, stale, case-conflicting, wrong-kind, and mixed-target names. - macOS signed-feed URLs and runtime validation now require `.zip`. - README now refers to MSI packages rather than NuGet containers. Changed files: [release-artifacts.mjs](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T17-39-59/apps/desktop/scripts/release-artifacts.mjs), [release-artifacts.test.mjs](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T17-39-59/apps/desktop/scripts/release-artifacts.test.mjs), [signed-updates.ts](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T17-39-59/apps/desktop/src/signed-updates.ts), [signed-update-policy.test.ts](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T17-39-59/apps/desktop/src/signed-update-policy.test.ts), and [README.md](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T17-39-59/apps/desktop/README.md). Validation passed: - Focused release staging/finalization tests: 25 passed, 4 native-platform skips - Desktop suite: 143 passed, 6 native-platform skips - Desktop and UI typechecks - `git diff --check` No real local maker output was present for an additional native staging run; fresh six-target CI remains authoritative. PR: #1972 Comment by: @integry (ID: 5482139532) Model: gpt-5.6-sol
…ort.test.mjs](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T17-52-43/apps/desktop/scripts/packaged-smoke-support.test.mjs). Implemented the F21 portability fix in [packaged-smoke-support.test.mjs](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T17-52-43/apps/desktop/scripts/packaged-smoke-support.test.mjs). - Normalizes source line endings to LF before the spawn-option assertion. - Preserves strict adjacency and exact `cwd`, `env`, and `shell` values. - Adds LF/CRLF passing fixtures and missing, reordered, or changed contract failures. - No runtime, source, workflow, or other files changed. Validation passed: - Focused test: 10/10 - Desktop tests: 144 passed, 6 skipped - Desktop typecheck - `git diff --check` - Final scope: one test file only PR: #1972 Comment by: @integry (ID: 5482281022) Model: gpt-5.6-sol
…34091847d6c`. Implemented F17 only on head `b46f41f0eb49ad2694e4f633f522834091847d6c`. - Added the service-free Windows inspector in [connectWindowsAuthority.ts](/home/node/workspace/packages/cli/src/connectWindowsAuthority.ts:25): canonical System32 PowerShell 5.1, minimal environment, hidden bounded process, inherited fd 3+ descriptors, in-memory P/Invoke, same-handle owner/DACL and identity checks, strict canonical JSON. This follows Node’s documented child-fd mapping and Windows’ handle-based `GetSecurityInfo` boundary. [Node documentation](https://nodejs.org/api/child_process.html), [Microsoft documentation](https://learn.microsoft.com/en-us/windows/win32/api/aclapi/nf-aclapi-getsecurityinfo) - Added strict binding and Windows ACL policy in [connectRootAuthority.ts](/home/node/workspace/packages/cli/src/connectRootAuthority.ts:455). Status now reaches normal readiness states; genuine inspection failures alone produce `ACL_DIAGNOSTIC_UNAVAILABLE`. - Kept privileged mutation unsupported with `WINDOWS_AUTHORITY_REQUIRED`. - Expanded the hosted limited-user fixture and adversarial matrix, including policy failures, schema/output failures, descriptor mismatches, system-executable resolution, redaction, and ABA swapping. - Preserved Darwin, POSIX delimiter, protocol-v2, Docker forwarding, identity recovery, and discovery parsing behavior. Validation passed: - CLI build, typecheck, strict lint, and package verification - Focused authority/identity tests: 34/34 - Platform-safe Connect proof: 78/78 - Fast unit suite: 283/283 - Desktop audit and package - Release verification and `git diff --check` The full suite completed 334/335 runners; `test/llmMetrics.test.ts` timed out waiting for Redis because this environment has no Redis server or Docker. Hosted Windows and Darwin native proofs remain pending on their authoritative CI platforms. No commit was created. PR: #1989 Comment by: @integry (ID: 5481794462) Model: gpt-5.6-sol
…6bcd7b972c8897621cf29998a392a09e5d`. Implemented the F22-only MSI inspection fix on head `8d716e6bcd7b972c8897621cf29998a392a09e5d`. - Replaced 7-Zip MSI extraction with validated native `msiexec.exe /a` on Windows and `/usr/bin/msiextract` on Linux in [release-architecture.mjs](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T18-08-48/apps/desktop/scripts/release-architecture.mjs:191). - Added bounded execution, cleanup, minimal environments, path-list preflight, safe-tree limits, canonical executable validation, PE architecture checks, and redacted fixed failure codes. - Provisioned `msitools` in both aggregate finalization jobs. - Added synthetic boundary tests and real WiX MSI workflow-order coverage. - Removed `electron-winstaller` and regenerated `package-lock.json`. - No runtime, MSI authoring, artifact naming, signing, or update behavior changed. Validation passed: - Focused release architecture, artifact, and workflow suites - Desktop typecheck - Desktop tests: 159 tests, 153 passed, 6 platform skips - Runtime and packaging dependency audits: 0 vulnerabilities - `git diff --check` Local real extraction was unavailable because this Linux workspace has neither `/usr/bin/msiextract` nor a generated MSI; native Windows and Linux aggregate CI provide the authoritative proof. No commit was created. PR: #1972 Comment by: @integry (ID: 5482462594) Model: gpt-5.6-sol
…ntial-servic Implemented by ProPR AI using gpt-5.6-sol model. Implementation completed successfully.
…t committing. Implemented the F18 candidate fix on head `5438b68c` without committing. Key changes: - Replaced fd-3/MSVCRT and nested-job dependencies with inherited standard handles via `GetStdHandle`. - Added allowlisted native-stage diagnostics and hosted assumption probes. - Kept production failures redacted as `ACL_DIAGNOSTIC_UNAVAILABLE`. - Corrected path ABA to retain attacker replacement bytes until rejection as `INVALID_ROOT`. - Preserved `WINDOWS_AUTHORITY_REQUIRED` for privileged mutation. Validation passed: - CLI typecheck, lint, and build - Focused tests: 9/9 - Platform-safe Connect proof: 78/78 - `git diff --check` I am not reporting final completion yet: the required authoritative Windows ordinary-user CI can only run after the system commits these changes and triggers the PR `synchronize` workflow. PR: #1989 Comment by: @integry (ID: 5482664348) Model: gpt-5.6-sol
…origins-in--20260831-1838-6br [2026 by GPT-5.6 Sol] Use exact URL origins in desktop credential-service mock assertions
…61930679e398`. Implemented F16 on exact head `8ddd72727ee72334124e3114bdf661930679e398`. - Added typed `opaqueNames` support to [release-config.ts](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T18-59-00/apps/desktop/src/release-config.ts:104). - Marked only the Windows certificate password opaque in [forge.config.ts](/tmp/git-processor/worktrees/integry/propr/pr-1972-followup-2026-08-31T18-59-00/apps/desktop/forge.config.ts:39). - Preserved whitespace-aware presence validation while returning nonblank opaque values byte-for-byte. - Added focused preservation, normalization, missing-value diagnostic, and dual Forge signing-path tests. Validation passed: - Focused release tests: 25/25 - Desktop tests: 155 passed, 6 platform skips - Desktop/UI typecheck - Runtime audit: 0 vulnerabilities - Packaging audit: 0 vulnerabilities - `git diff --check` - Only the four intended files changed Fresh CI and exact-head review remain required. No commit, merge, runtime sync, or workflow change was performed. PR: #1972 Comment by: @integry (ID: 5483059643) Model: gpt-5.6-sol
…01fa2ec105a881186f496e81a7`. Implemented the F19 follow-up on exact head `6da52e634fab1101fa2ec105a881186f496e81a7`. - Split fd3, job-containment, and sacrificial nested-job experiments into independent bounded PowerShell processes. - Added a 15-second hosted-probe cold-start bound while retaining the production inspector’s 5-second bound. - Legacy failures/timeouts now produce fixed enums and do not bypass the real GetStdHandle matrix. - Resolver/launch infrastructure remains fail-closed. - Completion output now requires `ready=standard-handle-passed` and includes all measured assumptions. - Added focused isolation, redaction, timeout/failure, and infrastructure tests. Validation passed: - Focused tests: 11/11 - Platform-safe Connect proof: 78/78 - CLI build, CLI/root typecheck, CLI lint - `git diff --check` Fresh authoritative Windows ordinary-user CI remains the mandatory post-commit gate; it cannot be run from this Linux workspace. No commit was created. PR: #1989 Comment by: @integry (ID: 5482999103) Model: gpt-5.6-sol
…hout committing. Implemented the F20 candidate on exact head `789f9587…` without committing. Key changes: - Added one 60-second fixed-token native timing probe covering PowerShell entry, constant JSON, Reflection.Emit, harmless Win32, and standard-handle identity. - Strictly parses/redacts milestones; timeouts retain only the last milestone and coarse timing bucket. - Replaced three legacy probes with this single probe. - Raised production inspection to 30 seconds per call with a 60-second cumulative batch cap. - Preserved minimal environment, fixed System32 resolution, GetStdHandle binding, ABA rejection, read-only behavior, and `WINDOWS_AUTHORITY_REQUIRED`. - Added focused tests and updated platform-safe count to 83. Validation passed: - Focused tests: 16/16 - Platform-safe Connect: 83/83 - CLI lint and typecheck - Workspace build and typecheck - `git diff --check` Fresh native Windows CI remains mandatory and unverified. It cannot run against uncommitted edits; the post-commit/push `windows-2025` ordinary-user job must confirm `ready=standard-handle-passed` with timing evidence. PR: #1989 Comment by: @integry (ID: 5483229708) Model: gpt-5.6-sol
Implemented the exact F21 split on head `e1a9da9d…`. - Replaced ambiguous `broker:index-info` with: - `broker:index-info-initial` — exit 74 - `broker:current-user-sid` — exit 78 - `broker:index-info-revalidation` — exit 79 - Updated all fixed diagnostic allowlists and mappings. - Changed the single timing probe to open the exact fixture ancestor using `O_RDONLY | O_DIRECTORY | O_NOFOLLOW`. - Preserved all production timeouts, environment, transport, authority policy, and redaction behavior. Validation passed: - 18 focused tests - CLI typecheck - CLI lint - CLI build - `git diff --check` Fresh native Windows CI remains required after the system commits these changes; no mock result is claimed as acceptance. PR: #1989 Comment by: @integry (ID: 5483638047) Model: gpt-5.6-sol
…form-deskto-20260829-1735-0gu [1957 by GPT-5.6 Sol] Add cross-platform desktop packaging, updates, and release CI
…06587c32712578e71`. Implemented F22 only on exact head `1fc3f2aecda0b69db3485fb06587c32712578e71`. - Added private `DuplicateHandle` use and exactly one `CloseHandle` in `finally` in [connectWindowsAuthority.ts](/home/node/workspace/packages/cli/src/connectWindowsAuthority.ts:74). - Added redacted `broker:fd-duplicate` stage `80` across maps and allowlists. - Updated focused source/diagnostic assertions without increasing test selection. - Corrected the platform-safe verifier from 83 to 84. Validation passed: - Focused source/diagnostic tests: 18/18 - Platform-safe suite: 84/84 - CLI typecheck, lint, and build - Encoded inspector size: 21,144 / 28,000 characters - `git diff --check` Fresh ordinary-user Windows discovery and native durability require the Windows CI runner; this Linux workspace cannot produce that mandatory native evidence. No commit was created. PR: #1989 Comment by: @integry (ID: 5483829701) Model: gpt-5.6-sol
… validation Implemented by ProPR AI using gpt-5.6-sol model. Implementation completed successfully.
Implemented the Darwin-only verifier correction. - Replaced `Authority=` reliance with bounded `codesign` certificate extraction into the private temp directory. - Requires exactly one extracted X.509 leaf and an exact SHA-1 match. - Preserved ad-hoc rejection, identifier/designated-requirement binding, and strict deep verification before and after the journey. - Added focused valid self-signed, missing, ambiguous, mismatched, and ad-hoc tests. - Existing temp cleanup removes extracted certificates. Key changes: [verifier](/tmp/git-processor/worktrees/integry/propr/pr-2108-followup-2026-09-04T15-15-03/apps/desktop/scripts/verify-darwin-packaged-connect-signature.mjs:36), [tests](/tmp/git-processor/worktrees/integry/propr/pr-2108-followup-2026-09-04T15-15-03/apps/desktop/scripts/verify-darwin-packaged-connect-signature.test.mjs:55). Validation: - Desktop suite: 475 tests, 450 passed, 25 platform-specific skipped. - Shell syntax and `git diff --check`: passed. - Native Darwin x64/ARM64 execution requires the CI matrix and wasn’t available on this Linux worker. No preview was created because the change is non-visual CI infrastructure. PR: #2108 Comment by: @integry (ID: 5542459592) Model: gpt-5.6-sol
…es/integry/propr/pr-2108-followup-2026-09-04T15-26-51/apps/desktop/README.md:51) to describe: Updated [apps/desktop/README.md](/tmp/git-processor/worktrees/integry/propr/pr-2108-followup-2026-09-04T15-26-51/apps/desktop/README.md:51) to describe: - Original keychain configuration restoration - Disposable keychain deletion - Temporary signing-material removal Removed the inaccurate temporary-trust removal claim. No behavior or tests changed. `git diff --check` passes; no visual preview was needed. PR: #2108 Comment by: @integry (ID: 5542577122) Model: gpt-5.6-sol
Implemented the Darwin verifier follow-up: - `codesign` now receives `--extract-certificates` and the prefix as separate argv entries. - Explicitly validates the sole generated `prefix0` regular file before X.509 parsing. - Added exact argv regression assertions and rejected the old `--extract-certificates=...` form. - Preserved SHA1 matching, ad-hoc rejection, deep/strict verification, stable requirements, cleanup, and diagnostics. Validation: - Full desktop suite: 475 tests, 450 passed, 25 platform skips. - `git diff --check` and Node syntax checks passed. - Only three Darwin verifier/test files changed; no trust, production signing, Linux, or Windows behavior changed. - No visual preview created because this is CI-only. Per instruction, I did not commit. The system-generated commit will match the workflow’s `apps/desktop/**` path filter; native Darwin ARM64/x64 results must be confirmed by that workflow run. PR: #2108 Comment by: @integry (ID: 5542782622) Model: gpt-5.6-sol
Implemented the Darwin verifier follow-up. - Replaced certificate extraction with bounded native `codesign --verify --test-requirement` evaluation pinned to `dev.propr.desktop` and the expected leaf SHA-1. - Retained separate embedded-requirement display, byte-exact before/after stability, and ordinary `--verify --deep --strict`. - Added all five fixed secret-safe verifier diagnostics. - Added coverage for exact argv, self-signed signatures, ad-hoc/unsigned code, wrong leaf/identifier, missing/ambiguous evidence, and stability. - Preserved cleanup, no-trust, and production isolation constraints. Validation: - Focused tests: 17 passed. - Full desktop suite: 451 passed, 25 platform skips. - Syntax and `git diff --check`: passed. - Only three Darwin verifier/test files changed. - No visual preview created because this is CI-only. The system-generated commit will trigger the path-filtered native ARM64/x64 workflow; those real journey results cannot run on this Linux worker. PR: #2108 Comment by: @integry (ID: 5542901295) Model: gpt-5.6-sol
Implemented the PR #2108 follow-up. - Corrected `codesign` argv to `['--verify', '-R=<exact identifier/leaf requirement>', application]` in [verify-darwin-packaged-connect-signature.mjs](/tmp/git-processor/worktrees/integry/propr/pr-2108-followup-2026-09-04T15-56-36/apps/desktop/scripts/verify-darwin-packaged-connect-signature.mjs:120). - Updated the exact argv regression to reject the invalid split form in [verify-darwin-packaged-connect-signature.test.mjs](/tmp/git-processor/worktrees/integry/propr/pr-2108-followup-2026-09-04T15-56-36/apps/desktop/scripts/verify-darwin-packaged-connect-signature.test.mjs:133). - Strengthened platform contracts for native x64/ARM64, separate pair/reprobe launches, and stable verification afterward in [packaged-connect-platform.test.mjs](/tmp/git-processor/worktrees/integry/propr/pr-2108-followup-2026-09-04T15-56-36/apps/desktop/scripts/packaged-connect-platform.test.mjs:85). Verification: - Desktop suite: 476 tests, 451 passed, 25 platform-specific skipped, 0 failed. - `git diff --check`: passed. - Native Darwin jobs will trigger when the system commits/publishes these path-filtered changes. No visual preview was created because this is CI-only and not user-visible. No commit was made. PR: #2108 Comment by: @integry (ID: 5543086525) Model: gpt-5.6-sol
Implemented the Darwin-only verifier follow-up. - Removed `-R` requirement evaluation. - Added separate bounded metadata and certificate-extraction commands with exact argv. - Requires exactly `prefix0` as a regular, parseable certificate and matches its SHA1. - Added `CERTIFICATE_EXTRACTION_FAILURE`. - Enforces exact certificate-bound designated requirements and byte-stable reprobe evidence. - Uses separate private initial/stable prefixes cleaned by existing temp-root cleanup. - Preserved strict deep verification and existing diagnostics. Validation: - Desktop script suite: 222 tests, 198 passed, 24 platform skips, 0 failures. - ESLint passed. - Shell syntax and `git diff --check` passed. - Native Darwin execution remains for x64/ARM64 CI. - No visual preview created because the change is CI-only. PR: #2108 Comment by: @integry (ID: 5543237359) Model: gpt-5.6-sol
Implemented the PR #2108 follow-up without committing. - Replaced certificate extraction and `-R` evaluation with bounded keychain SHA-1 lookup, signature metadata validation, exact designated-requirement evidence, and strict verification in [verify-darwin-packaged-connect-signature.mjs](/tmp/git-processor/worktrees/integry/propr/pr-2108-followup-2026-09-04T16-21-41/apps/desktop/scripts/verify-darwin-packaged-connect-signature.mjs:18). - Removed extraction prefixes and obsolete diagnostics from the Darwin wrapper. - Enforced an explicit `os-protected` journey report while retaining fresh-process credential continuity checks. - Added all requested negative tests. Validation passed: - Desktop/UI typechecks - Full desktop suite: 453 passed, 25 platform-specific skipped - Focused suite: 54 passed - Shell syntax and `git diff --check` Native macOS x64/ARM64 execution requires the PR’s CI runners and was not available on this Linux host. No preview was created because the changes are CI-only and not visually perceptible. PR: #2108 Comment by: @integry (ID: 5543406076) Model: gpt-5.6-sol
Implemented the follow-up verifier fix. - Normalizes CRLF and trims lines, selects exactly one designated-requirement line, and validates an anchored whitespace/case-tolerant grammar with the exact identifier and certificate leaf—rejecting extra clauses. - Stores the normalized selected line plus one newline and compares it after reprobe. - Adds secret-safe `KEYCHAIN_EVIDENCE_FAILURE`, `SIGNATURE_METADATA_FAILURE`, and `REQUIREMENT_EVIDENCE_FAILURE` diagnostics. - Preserves all existing verifier commands, strict checks, cleanup, no-trust behavior, and platform isolation. - Added comprehensive regression coverage in [verify-darwin-packaged-connect-signature.test.mjs](/tmp/git-processor/worktrees/integry/propr/pr-2108-followup-2026-09-04T16-40-32/apps/desktop/scripts/verify-darwin-packaged-connect-signature.test.mjs:153). Validation: - Focused tests: 23/23 passed - Full desktop suite: 458 passed, 25 platform-specific skipped - ESLint: passed - `git diff --check`: passed The changed desktop paths trigger the existing native x64 and ARM64 full-journey workflow matrix when published. No visual preview was created because this is CI-only behavior. PR: #2108 Comment by: @integry (ID: 5543631504) Model: gpt-5.6-sol
Implemented the requested Darwin metadata-parser follow-up. - Removed all `Signature size` requirements. - Added whitespace/case-tolerant explicit `Signature=adhoc` rejection. - Made `Identifier=` optional, but exact when present; duplicate/conflicting lines fail. - Added fixed `ADHOC_SIGNATURE_FAILURE` and `IDENTIFIER_METADATA_FAILURE` diagnostics. - Preserved keychain SHA, embedded requirement, strict verification, pair/reprobe, cleanup, and platform isolation. - Added realistic missing-field, spacing/case, ad-hoc, duplicate/conflicting, and valid identifier tests. Changed files: - [Verifier](/tmp/git-processor/worktrees/integry/propr/pr-2108-followup-2026-09-04T16-54-01/apps/desktop/scripts/verify-darwin-packaged-connect-signature.mjs:14) - [Verifier tests](/tmp/git-processor/worktrees/integry/propr/pr-2108-followup-2026-09-04T16-54-01/apps/desktop/scripts/verify-darwin-packaged-connect-signature.test.mjs:186) - [Platform contracts](/tmp/git-processor/worktrees/integry/propr/pr-2108-followup-2026-09-04T16-54-01/apps/desktop/scripts/packaged-connect-platform.test.mjs:87) Validation: - Focused tests: 25 passed - All desktop script tests: 206 passed, 24 platform-specific skipped - Syntax and `git diff --check`: passed Native Darwin x64/ARM64 execution requires the macOS CI runners. No visual preview was created because this is CI-only behavior. PR: #2108 Comment by: @integry (ID: 5543787926) Model: gpt-5.6-sol
…cOS browser Implemented by ProPR AI using gpt-5.6-sol model. Implementation completed successfully.
Implemented the Darwin root-signing correction. - Root app now uses `--identifier dev.propr.desktop` and preserves only `entitlements,flags`; nested targets retain identifier preservation and never receive the root identifier. - Exact SHA, keychain, no-timestamp signing, root-only certificate requirement, inside-out order, and strict verification remain intact. - Verifier now requires exactly one root `Identifier=dev.propr.desktop` during initial and stable verification. - Added exact argv, identifier-evidence, and platform-contract regression tests. Files: [signer](/tmp/git-processor/worktrees/integry/propr/pr-2108-followup-2026-09-04T17-01-56/apps/desktop/scripts/sign-darwin-packaged-connect.mjs:145), [verifier](/tmp/git-processor/worktrees/integry/propr/pr-2108-followup-2026-09-04T17-01-56/apps/desktop/scripts/verify-darwin-packaged-connect-signature.mjs:102) Validation: - Full desktop suite: 462 passed, 25 platform-specific skipped - `git diff --check`: passed - Native macOS x64/ARM64 journeys require the post-commit CI matrix and could not run on this Linux worker. No visual preview was generated because this is CI-only behavior. PR: #2108 Comment by: @integry (ID: 5543879385) Model: gpt-5.6-sol
Implemented the PR #2108 follow-up without committing. - Enforced exactly one `Identifier=dev.propr.desktop` and one positive numeric `Signature size`, with fixed `SIGNATURE_METADATA_FAILURE` diagnostics while retaining ad-hoc rejection in [verify-darwin-packaged-connect-signature.mjs](/tmp/git-processor/worktrees/integry/propr/pr-2108-followup-2026-09-04T17-08-42/apps/desktop/scripts/verify-darwin-packaged-connect-signature.mjs:14). - Added all requested negative regressions in [verify-darwin-packaged-connect-signature.test.mjs](/tmp/git-processor/worktrees/integry/propr/pr-2108-followup-2026-09-04T17-08-42/apps/desktop/scripts/verify-darwin-packaged-connect-signature.test.mjs:186). - Corrected the self-signed `CA:false` leaf wording in [README.md](/tmp/git-processor/worktrees/integry/propr/pr-2108-followup-2026-09-04T17-08-42/apps/desktop/README.md:47). Validation: - Full desktop suite: 463 passed, 25 platform-specific skipped. - Focused signing/verifier suite: 33/33 passed. - Syntax, ESLint, and `git diff --check` passed. - Native macOS execution was unavailable on this Linux worker. - No visual preview created because the change is CI/documentation-only. PR: #2108 Comment by: @integry (ID: 5543908141) Model: gpt-5.6-sol
…ackaged-rep-20260904-1325-wuu [2106 by GPT-5.6 Sol] Darwin ARM64 packaged reprobe: preserve OS Safe Storage identity across launches
…ng one final full desktop-suite pass on the exact final tree, then I’ll report the platform limitation: this workspace has no packaged Darwin/Linux artifacts, so the fresh x64/ARM64 packaged matrix must be exercised by CI. No visual preview is warranted because all changes are harness/tracker behavior and diagnostics. Implementation and focused validation are complete. I’m doing one final full desktop-suite pass on the exact final tree, then I’ll report the platform limitation: this workspace has no packaged Darwin/Linux artifacts, so the fresh x64/ARM64 packaged matrix must be exercised by CI. No visual preview is warranted because all changes are harness/tracker behavior and diagnostics. PR: #2110 Comment by: @integry (ID: 5544223426) Model: gpt-5.6-sol
… into 2109/gpt-5.6-sol-desktop-packaged-connect--20260904-1655-c39
…-platform.test.mjs](/tmp/git-processor/worktrees/integry/propr/pr-2110-followup-2026-09-04T18-00-19/apps/desktop/scripts/packaged-connect-platform.test.mjs:117). Updated the stale structural assertion in [packaged-connect-platform.test.mjs](/tmp/git-processor/worktrees/integry/propr/pr-2110-followup-2026-09-04T18-00-19/apps/desktop/scripts/packaged-connect-platform.test.mjs:117). It now strictly verifies: `pair` completes → successful journey-fixture block begins → terminal request snapshot is captured → `reprobe` runs. No runtime or Windows changes were made. Darwin ARM64 behavior remains untouched for fresh CI classification. Validation: 41 tests passed across the platform and lifecycle suites; `git diff --check` passed. No visual preview was needed for this test-only change. PR: #2110 Comment by: @integry (ID: 5544503194) Model: gpt-5.6-sol
…ed-connect--20260904-1655-c39 [2109 by GPT-5.6 Sol] Desktop packaged Connect: stabilize macOS browser approval readiness
…cOS ARM64 re Implemented by ProPR AI using gpt-5.6-sol model. Implementation completed successfully.
… missing-rat Implemented by ProPR AI using gpt-5.6-sol model. Implementation completed successfully.
…ed-command s Implemented by ProPR AI using gpt-5.6-sol model. Implementation completed successfully.
…ed-connect--20260904-1814-df5 [2111 by GPT-5.6 Sol] Desktop packaged Connect: stabilize macOS ARM64 reprobe renderer readiness
…ql-resolve--20260904-1822-ynw [2112 by GPT-5.6 Sol] Transport CodeQL: resolve test-fixture missing-rate-limiting finding
…ql-resolve--20260904-1822-sak [2113 by GPT-5.6 Sol] Transport CodeQL: resolve Darwin bounded-command shell-injection finding
…xt transport Implemented by ProPR AI using gpt-5.6-sol model. Implementation completed successfully.
Implemented F1 only. - Seeds packaged renderer policy from the persisted active profile before initial window load. - Reconciles and reloads policy after profile save/edit, set-active, removal, clearing, and activation. - Added focused startup and transition coverage. Validation: - Desktop tests: 480 passed, 25 skipped, 0 failed. - Desktop typecheck passed. - Linux x64 packaging and artifact inspection passed. - `git diff --check` passed. - No visual preview created; this is not user-visible. - Changes were not committed, as requested. PR: #2120 Comment by: @integry (ID: 5545646008) Model: gpt-5.6-sol
Implemented F2 and F3, scoped to the selected findings. - Successful explicit and rollback discards now reconcile the persisted active profile, removing stale loopback HTTP/WS CSP sources. - Activation reconciles current state after cookie clearing, preventing older activations from overwriting newer mutations. - Policy callbacks are origin-only; delayed reloads resolve the current main renderer and discard superseded generations. - Pinned packaged smoke policies no longer install dynamic reconciliation or trigger extra `listProfiles()` reads. - Added focused concurrency, discard, rollback, renderer-replacement, and smoke-policy coverage. Validation: - Focused lifecycle/security tests: 42 passed. - Packaged Connect lifecycle/platform tests: 70 passed. - Desktop TypeScript check passed. - Linux-x64 package and artifact inspection passed. - Native Packaged Connect journey attempt was blocked by this container lacking Xvfb/keyring support and root-owned Chrome sandbox setup. Darwin and arm64 targets require their target-native CI runners. - No visual preview generated; this change is not visually perceptible. PR: #2120 Comment by: @integry (ID: 5545794678) Model: gpt-5.6-sol
Implemented the remaining CSP lifecycle fixes: - Smoke policy pinning now derives from transport smoke, Connect journey endpoint, or an authorized packaged smoke profile origin. - Successful `authenticationPair` calls now await pairing and reconcile authoritative active-profile state. - Added changed-origin active re-pair coverage expecting `null`. - Corrected the origin-changing profile-save test to reconcile `null`. - Preserved F2/F3 concurrency and current-renderer behavior. Changed files: [main.ts](/tmp/git-processor/worktrees/integry/propr/pr-2120-followup-2026-09-04T20-10-36/apps/desktop/src/main.ts:1169), [ipc.ts](/tmp/git-processor/worktrees/integry/propr/pr-2120-followup-2026-09-04T20-10-36/apps/desktop/src/ipc.ts:168), [ipc-lifecycle.test.ts](/tmp/git-processor/worktrees/integry/propr/pr-2120-followup-2026-09-04T20-10-36/apps/desktop/src/ipc-lifecycle.test.ts:25), and [smoke-test-authorization.test.ts](/tmp/git-processor/worktrees/integry/propr/pr-2120-followup-2026-09-04T20-10-36/apps/desktop/src/smoke-test-authorization.test.ts:172). Validation: - Focused lifecycle tests: 23 passed. - Desktop typecheck: passed. - Full desktop suite: 485 passed, 25 platform-specific skipped. - Linux x64 package and packaged artifact/fuse inspection: passed. - `git diff --check`: passed. The four target-native Darwin/Linux journeys could not be run on this Linux x64 runner: Darwin x64/arm64 and Linux arm64 require their native CI runners, while the local Linux journey also lacks Xvfb and gnome-keyring. No preview was created because the changes are not visually perceptible. PR: #2120 Comment by: @integry (ID: 5545905906) Model: gpt-5.6-sol
Implemented F4 only. - Reconciliation now publishes `null` when the authoritative profile read fails, clearing stale cleartext CSP origins before rethrowing. - Added a post-save commit regression test verifying the callback receives `null`. - No visual preview generated; behavior is not user-visible. Validation: - Desktop typecheck passed. - Desktop suite: 486 passed, 25 skipped, 0 failed. - `git diff --check` passed. - Changes were not committed, as requested. PR: #2120 Comment by: @integry (ID: 5546036208) Model: gpt-5.6-sol
Implemented F5 only. - Added a monotonic reconciliation generation in [ipc.ts](/tmp/git-processor/worktrees/integry/propr/pr-2120-followup-2026-09-04T20-34-37/apps/desktop/src/ipc.ts:85). - Stale successful reads and stale failures can no longer overwrite the latest renderer policy. - Added race tests covering both delayed resolution and rejection in [ipc-lifecycle.test.ts](/tmp/git-processor/worktrees/integry/propr/pr-2120-followup-2026-09-04T20-34-37/apps/desktop/src/ipc-lifecycle.test.ts:135). Verification: - IPC lifecycle tests: 17 passed - Desktop TypeScript check: passed - `git diff --check`: passed No visual preview was created because this change is not user-visible. No commit was made. PR: #2120 Comment by: @integry (ID: 5546142663) Model: gpt-5.6-sol
…er-csp-rest-20260904-1923-yoz [2119 by GPT-5.6 Sol] Desktop renderer CSP: restrict cleartext transport to loopback (retry)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Epic PR
This PR aggregates all changes from child PRs merged to the
1953-epic-desktop-transport-apibranch.Created automatically by ProPR
Closes #1953