[2083 by GPT-5.6 Sol] Prove native macOS/Linux desktop artifact install and deep-link lifecycle - #2085
Conversation
…act install Implemented by ProPR AI using gpt-5.6-sol model. Implementation completed successfully.
|
CI failed: Validate unsigned win32-x64 package Please investigate and fix this CI failure.
Failure evidence
|
|
CI failed: Validate unsigned darwin-arm64 package Please investigate and fix this CI failure.
Failure evidence
|
|
CI failed: Validate unsigned win32-arm64 package Please investigate and fix this CI failure.
Failure evidence
|
|
CI failed: Validate unsigned darwin-x64 package Please investigate and fix this CI failure.
Failure evidence
|
|
Please implement one tightly scoped macOS/Linux-only follow-up on the exact current PR head. Do not change Windows code/tests/jobs, package-lock.json, public signing/notarization/update credentials, or release-profile behavior. Required corrections:
Keep the existing accurate unsigned internal-RC disclaimers, canonical qs 6.16.0 / fast-uri 3.1.6 lock, no-basic_text/plaintext fallback, 0600/0700 authority, native architecture/identity checks, and Linux/macOS staged-artifact coverage. Run focused desktop/lifecycle tests, full suite, git diff --check, and all four Linux/macOS native jobs. Leave unmerged for audit. |
|
Retrigger: implement the complete scoped macOS/Linux-only correction request in my immediately preceding comment (#2085 (comment)) on exact current head. Treat all automated Windows failure comments as out of scope. No Windows, lockfile, signing/notarization, update-credential, or release-profile changes. Leave unmerged for audit. |
|
✅ Applied the requested follow-up changes in commit 7c498d7 Summary of ChangesImplemented the complete scoped macOS/Linux follow-up on base HEAD Key changes:
Verification:
Changes are left uncommitted and unmerged for audit. 🤖 Implementation Details
Undo Changes • View Task Execution 💡 ProPR Slash Commands
🤖 Generated by ProPR |
…se HEAD `603ef9c688a65390f2dff55646223dff3b75193f`. Implemented the complete scoped macOS/Linux follow-up on base HEAD `603ef9c688a65390f2dff55646223dff3b75193f`. Key changes: - Total bounded process-group cleanup for initial launch, dispatches, and relaunch. - Immediate DMG mount authority with mandatory verified detach. - Fail-closed LaunchServices unregister and exact copied-bundle absence checks. - Bounded profile API shutdown, listening-port proof, authorized profile removal, and redacted aggregate failures. - Renderer acknowledgements proving ordered, exactly-once Connect/Open consumption. - Cold launches explicitly reported as direct argv; OS protocol testing remains warm-only. - Linux secure-storage evidence explicitly fallback-only without claiming libsecret custody. - RPM pipeline now awaits both processes and handles late failures. - Added adversarial cleanup, symlink/special-file, and process fixtures. - Updated [native lifecycle documentation](</tmp/git-processor/worktrees/integry/propr/pr-2085-followup-2026-09-02T20-33-31/apps/desktop/README.md>). Verification: - Desktop typecheck: passed. - Desktop suite: 198 tests, 192 passed, 6 platform skips. - Renderer deep-link tests: 5 passed. - Native authority fixtures: 11 passed. - `git diff --check`: passed. - Full repository suite reached test 197 before blocking on unavailable Redis at `127.0.0.1:6379`. - Native artifact execution requires staged artifacts and the four Linux/macOS architecture runners, unavailable locally. - `package-lock.json`, workflows, Windows behavior, signing/notarization, update credentials, and release profiles remain unchanged. - Locked `qs` 6.16.0 and `fast-uri` 3.1.6 confirmed. Changes are left uncommitted and unmerged for audit. PR: #2085 Comment by: @integry (ID: 5516001642) Model: gpt-5.6-sol
|
CI failed: Validate unsigned win32-x64 package Please investigate and fix this CI failure.
Failure evidence
|
|
CI failed: Validate unsigned win32-arm64 package Please investigate and fix this CI failure.
Failure evidence
|
|
CI failed: Validate unsigned linux-arm64 package Please investigate and fix this CI failure.
Failure evidence
|
|
CI failed: Validate unsigned linux-x64 package Please investigate and fix this CI failure.
Failure evidence
|
|
CI failed: Validate unsigned darwin-arm64 package Please investigate and fix this CI failure.
Failure evidence
|
|
Scoped macOS/Linux/shared lifecycle correction on current head 7c498d7 only. Preserve the completed lifecycle hardening and make exactly these two corrections:
Mac/Linux/shared only. Do not modify package-lock, workflows, Windows code/tests/jobs, signing/notarization, update credentials, release profiles, artifact counts/names, or public claims. Run desktop typecheck/tests and focused adversarial tests. |
|
CI failed: Validate unsigned darwin-x64 package Please investigate and fix this CI failure.
Failure evidence
|
|
🛑 Execution Cancelled The task processing was stopped by user request. You can post a new comment to restart processing. |
|
Fresh native-gate classification for the same scoped follow-up:
These are Mac/Linux lifecycle failures from run 33683145899. Fold them into the already requested two corrections in the immediately preceding maintainer comment. Do not touch automated Windows failure comments, Windows code/jobs, package-lock, signing, or release scope. |
|
Mac first-DMG root-cause lead to verify, not assume: createSmokeChildEnvironment rewrites HOME to the isolated profile on macOS. Unlike the earlier packaged smoke (which does not perform a credential write), native first launch then calls safeStorage encrypt/decrypt through ProfileStore before renderer-ready. Repointing HOME can detach Chromium safeStorage from the runner login Keychain and plausibly block the custody probe; both architectures show the same 45-second initial-evidence timeout. Capture fixed stage events around the non-secret custody probe to confirm. If confirmed, preserve the real runner HOME only for the macOS native child so Keychain is available, while retaining explicit --user-data-dir, 0700/0600 app-profile authority, before/after default-app-profile absence checks, no endpoint/path diagnostics, and strict cleanup. Do not weaken the macOS Keychain round-trip/deletion assertion and do not create signing/notarization claims. |
|
/fix Implement one macOS/Linux/shared-only correction on exact head 7c498d7. This request supersedes all automated CI-failure comments. Preserve the completed lifecycle hardening and address the full audited scope below:
Run desktop typecheck/unit/adversarial tests and obtain fresh macOS x64/ARM64 plus Linux x64/ARM64 native artifact gates. Do not modify package-lock, workflows unless a narrowly necessary Mac/Linux invocation fix is proven, Windows code/tests/jobs, signing/notarization/update credentials, release profile, artifact counts/names, or public release claims. Ignore Windows failures entirely. |
|
ℹ️ No authorized review findings were selected. No files were changed because this Processing comment ID: 5516525116✓ |
|
IMPLEMENTATION REQUEST — macOS/Linux/shared only. Implement the complete scoped request in maintainer comment 5516525116 on current head 7c498d7. That request is an ordinary follow-up implementation request (the slash-command handler could not select it because it is not an F-numbered review finding). It explicitly includes: production ACK failure must not exit outside native smoke; LaunchServices absence before removal with authority retained on failure; bounded natural process-group drain plus true leak cleanup and zombie-safe proof for both Linux failures; actionable fixed non-secret stage diagnostics and correction of both macOS first-DMG stalls, including verification of the isolated-HOME/Keychain lead in comment 5516511184; focused adversarial tests and fresh four Mac/Linux native gates. This request supersedes every automated CI-failure comment. Ignore Windows entirely. Do not change package-lock, Windows code/jobs/tests, signing/notarization/update credentials, release profile, artifacts, or public claims. Preserve all existing completed guarantees listed in comment 5516525116. |
|
Please start the scoped Mac/Linux/shared implementation request in the immediately preceding maintainer comment 5516541390, including the complete requirements it references in 5516525116 and 5516511184. This is the only authorized follow-up; ignore all automated CI comments and all Windows work. |
|
✅ Applied the requested follow-up changes in commit 90b8610 Summary of ChangesImplemented the complete scoped macOS/Linux/shared follow-up without committing. Key changes:
Verification:
The four architecture-specific native gates require post-commit GitHub macOS/Linux runners and staged artifacts, so they could not be executed truthfully from this uncommitted Linux worktree. 🤖 Implementation Details
Undo Changes • View Task Execution 💡 ProPR Slash Commands
🤖 Generated by ProPR |
…p without committing. Implemented the complete scoped macOS/Linux/shared follow-up without committing. Key changes: - Production deep-link ACK failures now emit fixed, non-secret diagnostics without exiting or crashing; native artifact smoke remains fatal. - LaunchServices unregister and exact absence verification now precede copied-app deletion. Failures retain the install/work root. - Process groups receive a bounded natural drain, with zombie-aware inspection and TERM/KILL cleanup for genuine leaks. - Native lifecycle failures expose fixed operation stages without paths, URLs, credentials, or process output. - macOS native children retain the validated runner `HOME` for Keychain access while preserving isolated `--user-data-dir`, permissions, absence checks, and Keychain round-trip/deletion assertions. - Added focused adversarial tests for each correction. Verification: - Desktop suite: 207 tests, 201 passed, 6 platform skips. - Focused lifecycle/environment suite: 28/28 passed. - ACK policy tests: 3/3 passed. - Desktop typecheck passed. - `git diff --check` passed. - No Windows, workflow, lockfile, signing, release-profile, or artifact-definition changes. The four architecture-specific native gates require post-commit GitHub macOS/Linux runners and staged artifacts, so they could not be executed truthfully from this uncommitted Linux worktree. PR: #2085 Comment by: @integry (ID: 5516559539) Model: gpt-5.6-sol
|
NARROW MAC/LINUX SHARED CORRECTION on exact head 90b8610. Preserve all completed fixes and change only two residual items. First, preserving the real macOS HOME for Keychain makes Electron app.getPath(logs) default to ~/Library/Logs/; the harness explicitly asserts those default paths remain absent. During authorized packaged/native smoke initialization, set the Electron logs path to a pre-existing owned directory under the isolated user-data root before any getPath(logs) call, and test that ordinary production paths are unchanged while authorized smoke logging remains 0700/0600 and inside its profile. Do not weaken the real-HOME Keychain context or before/after default-profile checks. Second, a process-groups cleanup/postcondition failure must block copied install-root and outer work-root deletion; retain remediation/executable authority whenever live-member absence cannot be proven, and add an injected orchestration test. Mac/Linux/shared only. No package-lock, workflow, Windows, signing/notarization/update, release profile, artifacts, or public-claim changes. Run desktop typecheck and focused tests. |
|
✅ Applied the requested follow-up changes in commit d66aee2 Summary of ChangesImplemented the two scoped corrections on exact head
Validation:
🤖 Implementation Details
Undo Changes • View Task Execution 💡 ProPR Slash Commands
🤖 Generated by ProPR |
…106e49d4c1e92ef00ddf36801a254ee37f3`.
Implemented the two scoped corrections on exact head `90b86106e49d4c1e92ef00ddf36801a254ee37f3`.
- Native Mac/Linux smoke now redirects Electron logs to a validated, pre-existing 0700 directory inside isolated user data before `getPath('logs')`. Production paths remain unchanged; log files are verified 0600.
- Process-group cleanup/postcondition failures now preserve the copied executable/install root and outer work root, including Linux sandbox authority.
- Added focused logging, ordering, and injected cleanup-orchestration tests.
- Preserved macOS real-HOME Keychain handling and default-profile absence checks.
- No Windows, lockfile, workflow, signing, release, or artifact changes.
Validation:
- Focused tests: 38 passed
- Desktop typecheck: passed
- `git diff --check`: passed
- Changes left uncommitted as requested.
PR: #2085
Comment by: @integry (ID: 5516723148)
Model: gpt-5.6-sol
|
FINAL NATIVE GATE CORRECTION on exact head d66aee2, Mac/Linux/shared only. Preserve all completed cleanup/log/Keychain/ACK fixes. From run 33685589669: (1) Linux x64+arm64 both reach UNSAFE_SCHEME_EVIDENCE then lose a race because waitForEvents checks child exit before reading evidence; the final rejected-unsafe event legitimately triggers clean app quit. Read and validate fixed evidence first, then reject an exited child only when required events are absent; retain subsequent waitForSuccessfulExit and exact ordering/once proof. Add a fixture where evidence is complete before a clean child exit and one where it is incomplete. (2) macOS x64 reaches PROTOCOL_DISPATCH and fails. Split this into fixed non-secret LS_REGISTER vs OPEN_DISPATCH reason/stage, and make OS dispatch target the exact copied application path (for example open -a <copied .app> ) after registering it, rather than ambiguous bundle-ID selection, while still proving the already-running renderer consumes exactly once and unregistering the copied bundle. Update only the honest internal lifecycle wording/test if needed. (3) macOS arm64 exits during FIRST_INITIAL_EVIDENCE. Classify early child exit using the fixed evidence milestones (no evidence/authorized/identity/deep-link delivery failure/cold ACK/secure-storage started/completed/renderer) and result class without paths, URLs, credentials, or process output. Correct any deterministic startup/ACK issue exposed by the classification; use a bounded native-smoke-only ACK allowance if runner startup timing is the cause, without weakening production behavior or exact consumption. Run focused tests and require fresh Linux x64/arm64 and macOS x64/arm64 gates. No package-lock, Windows, signing/notarization/update, release profile, artifact counts/names, or broad workflow changes. Ignore automated Windows failures. |
|
✅ Applied the requested follow-up changes in commit 9ba00e5 Summary of ChangesImplemented the final native-gate correction on head
Validation passed:
The unchanged required matrix will provide fresh Linux x64/arm64 and macOS x64/arm64 native gates; those should pass before merge. 🤖 Implementation Details
Undo Changes • View Task Execution 💡 ProPR Slash Commands
🤖 Generated by ProPR |
…e2f`. Implemented the final native-gate correction on head `d66aee2f`. - Evidence is validated before child exit, with a stable re-read closing the final-event race. - Added complete/incomplete clean-exit fixtures and fixed milestone/result classifications. - macOS now reports `LS_REGISTER` versus `OPEN_DISPATCH` and uses `open -a <exact copied .app> <URL>`. - Native smoke ACK timeout is bounded at 15 seconds; production remains 5 seconds. - LaunchServices unregister, ordering, and exactly-once proofs remain intact. - No Windows, workflow, lockfile, signing, or release-profile changes. Validation passed: - Native lifecycle tests: 19/19 - Release workflow contract tests: 24/24 - Full desktop suite: 207 passed, 6 skipped - Desktop typecheck - `git diff --check` The unchanged required matrix will provide fresh Linux x64/arm64 and macOS x64/arm64 native gates; those should pass before merge. PR: #2085 Comment by: @integry (ID: 5516860721) Model: gpt-5.6-sol
AI Implementation Summary
Closes #2083
Branch:
2083/gpt-5.6-sol-prove-native-macos-linux--20260902-1955-v0yCommits: ✅ Changes committed (603ef9c)
AI Processing Completed
Execution Details:
Summary:
Implemented GitHub issue #2083.
Key changes:
x-scheme-handler/proprpackage metadata.Verification:
git diff --checkpassed.qs 6.16.0andfast-uri 3.1.6.127.0.0.1:6379.fakeroot, RPM, ZIP, Xvfb, and macOS runners; the CI matrix now provides those native environments.Detailed Logs:
01a063b1-c34c-78f0-a1d2-ed543df4f095Log files stored at:
/tmp/claude-logs/issue-2083-2026-09-02T20-24-12-742Z-conversation.json/tmp/claude-logs/issue-2083-2026-09-02T20-24-12-742Z-output.txtLatest Conversation Messages
This PR was created automatically by ProPR after processing issue #2083.
💡 Need changes?
Comment on this PR to request refinements — the AI agent monitors comments and will update the implementation based on your feedback. Keep iterating until you're satisfied!