Skip to content

Commit 4116723

Browse files
Jonathan KingstonJonathan Kingston
authored andcommitted
Merge main to validate refreshed model scores
2 parents 16836ae + ae93583 commit 4116723

96 files changed

Lines changed: 9567 additions & 114 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/sync-model-cards.yml‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@ name: Sync model cards
22

33
# Refreshes packages/llm/src/model-cards.generated.ts from the reviewed link file
44
# scripts/data/model-cards.json, discovering cards for any model still listed in
5-
# `wanted` and verifying that every link resolves. Opens a PR if anything moved.
5+
# `wanted` and checking every link for definitive link rot. Opens a PR if anything moved.
66
# See packages/llm/src/model-cards.ts for the data flow.
77
#
88
# Discovery and verification need direct egress to vendor sites (anthropic.com,
@@ -36,8 +36,9 @@ jobs:
3636

3737
- name: Discover and verify model cards
3838
# --discover fills models listed in `wanted` from each vendor's card
39-
# index; --verify GETs every link and fails on link rot, so a dead card
40-
# breaks this workflow instead of shipping to the value map.
39+
# index; --verify GETs every link and fails on definitive 404/410 link
40+
# rot. Access-control and transient failures remain warnings because
41+
# they do not prove that a reviewed link is dead.
4142
run: npm run sync:model-cards -- --discover --verify --delay=1.5
4243

4344
# `npm run check` covers typecheck + lint + format:check + unit tests,

‎Makefile‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -61,6 +61,12 @@ NODE_MIN_MINOR := 0
6161
NVM_DIR ?= $(HOME)/.nvm
6262
USE_NVM := if [ -s "$(NVM_DIR)/nvm.sh" ]; then set +u; . "$(NVM_DIR)/nvm.sh"; nvm use >/dev/null || true; set -u; fi
6363

64+
# A prepared portable launcher supplies its own Node and package manager.
65+
# Keep the same opt-in as Electron startup and tool-availability probes.
66+
ifeq ($(COPSE_PRESERVE_PATH),1)
67+
USE_NVM := :
68+
endif
69+
6470
DEV_SYNC := node scripts/sync-dev.mts
6571

6672
# ----------------------------------------------------------------------------

‎docs/plans/copse-cloud-workspaces.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -183,6 +183,12 @@ loop and tool policy in control and uses a runtime Copse provisions and reconcil
183183
safely on human approval; and let desktop clients observe or take over after an
184184
explicit handoff. Start with one task in one repo. Fleet campaigns and external
185185
trigger ingress consume this only after single-task crash/replay behavior is proven.
186+
Initial credentials use the explicitly reduced-guarantee
187+
[trusted-host container delegation scope](device-bound-profile-encryption.md#initial-scope-direct-delegation-to-a-trusted-host-container):
188+
short-lived read-only GitHub access, no renewal or desktop vault keys, and model
189+
inference available independently of the desktop. Protected credential brokers
190+
and confidential-computing infrastructure are deferred; credential-session loss
191+
parks work for reauthorization rather than silently restoring secrets.
186192
Exit gate: disconnect the initiating desktop during model and tool execution, restart
187193
both sides in adversarial order, and observe one converged task with no duplicate
188194
provider turn, GitHub action, commit, or spine append.

‎docs/plans/device-bound-profile-encryption.md‎

Lines changed: 606 additions & 0 deletions
Large diffs are not rendered by default.
Lines changed: 77 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,77 @@
1+
# Drive portability audit beyond #2652
2+
3+
Audit base: `f5f1764c2` on `origin/main`, 11 September 2026. Scope: one
4+
external-drive development kit used sequentially on compatible Macs, following
5+
[PR #2652](https://github.com/copse-dev/agent-pane/pull/2652). That PR is a
6+
documentation proposal; its encryption, launchers and portability acceptance
7+
gates are not implemented by opening it. This audit leaves encryption to that
8+
work and identifies independently reviewable implementation slices.
9+
10+
## Already present
11+
12+
- `packages/store-kit/src/copse-paths.ts` centralizes profile, user-data,
13+
workspace, worktree and scratch paths under `COPSE_DIR`, with granular overrides.
14+
- Threads and per-project stores use stable IDs; moving the root does not require
15+
rewriting transcript text. Project repositories themselves are separate data.
16+
- `src/main/app-init.ts` resolves Electron user data before constructing stores.
17+
Set both `COPSE_DIR` and `COPSE_PANEL_USER_DATA` for a prepared kit: the latter
18+
bypasses automatic migration of a host's legacy profile.
19+
- Local provider routes already exist. A new model-provider protocol is not
20+
required to use a disk-hosted local model server.
21+
22+
## Implemented independently
23+
24+
### Build-cache relocation
25+
26+
The cache PR makes `scripts/patch-dev-name.mts` and `scripts/fetch-gortex.mts`
27+
derive their default caches from `COPSE_DIR`, while retaining dedicated cache
28+
overrides. Relative links allow a checkout and its cache to move together.
29+
Canonical parent paths handle macOS path aliases; dangling Electron links are
30+
recognized with `lstat`, and gortex links can be repaired from a populated cache.
31+
Tests move an actual directory tree and run the gortex installer against a local
32+
fixture cache without a download.
33+
34+
This does not relocate pnpm/Corepack/download caches, provide missing binaries,
35+
or make a host-linked Git worktree an independent repository. It does not depend
36+
on the launch-PATH PR or encryption.
37+
38+
### Preserve the launcher's tool selection
39+
40+
The launch-PATH PR adds the supported `COPSE_PRESERVE_PATH=1` opt-in: Electron
41+
does not augment the supplied PATH, availability probes do not prepend host
42+
paths, and Make does not activate host nvm. Ordinary launches retain their
43+
existing behavior. A kit launcher must supply its own complete PATH, including
44+
the system commands it needs. This does not replace `HOME` or relax sandbox or
45+
credential filtering rules.
46+
47+
The scope is deterministic PATH handling at these entry points. An interactive
48+
shell, external agent, MCP configuration, hardcoded executable or an executable's
49+
own dependencies can still refer to the host. No UI/layout change is involved.
50+
51+
## Remaining PRs, in dependency order
52+
53+
| Proposed PR | Current evidence / problem | Acceptance gate |
54+
| ----------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
55+
| Portable-kit manifest, inventory and launch preflight | No kit manifest or launcher exists. `package.json` releases are OS/architecture specific and macOS requires 26.0. `Makefile`, `scripts/sync-dev.mts`, postinstall scripts and native modules require supporting tools. Experimental `scripts/tauri-shell.mts` has its own home-rooted cache. | A read-only report inventories app/tool/model versions, resolved executable/library/symlink paths, free space, granular overrides and paths outside the kit. Missing disk/profile/tools stop launch before creating stores or downloading anything. Both Macs pass from a clean launch environment. |
56+
| Structured project relocation and Git repair | Projects persist absolute paths (`src/shared/types/state.ts`). Worktree operations resolve Git's administrative directories (`src/main/services/worktree-manager.ts`); a Copse profile alone does not contain each project's Git objects. This investigation checkout itself is a linked worktree with its admin directory on the host. | Move the kit to a different mount path containing spaces; retain project/thread IDs, current edits and active checkout associations. Check `.git`, `commondir`, submodule links and object alternates. Use independent clones and repair linked worktrees; do not replace strings in historical chat. Back up and validate a structured migration before writing. |
57+
| Controlled integration and child-process environment | `src/main/services/mcp/mcp-registry.ts` reads host `.cursor/mcp.json`; skill/plugin discovery and Cursor/Claude adapters consult host homes. Terminal startup inherits `SHELL` and shell configuration. `Makefile` and app startup are only two of the environment entry points. | Prepared local MCP/skills/plugins and shell tools run on both Macs with host profiles absent. Disable automatic package downloads; isolate configuration/cache paths per tool. Preserve provider-secret stripping in `child-process-env.ts` and existing shell permissions. Hook changes must follow the binding hooks/feature-packs plan. |
58+
| Local-only operation policy | `resolve-agent-model.ts` can fall back to cloud models; `small-tasks-provider.ts` can fall back to the chat model. Update checks, model catalogs, external agents, web integrations and downloads are independent network users. | Explicitly route every enabled role locally; prevent cloud fallback and defer external refresh/download work while retaining localhost models, MCP and previews. Complete a real edit/test task with external networking disabled, including review and title generation. |
59+
| Profile writer guard and owned-service shutdown | `src/main/index.ts` uses Electron's local single-instance lock and bypasses it for ACP. Gortex PID validation in `semantic-index.ts` checks that a process command names gortex, not that it belongs to this profile/host/boot. Shutdown cleanup exists but is not an eject protocol. | Concurrent writers are rejected across supported entry points. A PID copied from Mac A must never authorize signaling an unrelated gortex on Mac B. Bind owned services to profile and process identity, recover stale locks carefully, flush writes and stop owned processes before reporting safe shutdown. Test interruption, unplug/reconnect and failed flush without overwriting state. |
60+
| Pinned offline toolchain/model bundle and updates | `COPSE_DIR` is profile relocation, not a software distribution. `make run` may install/build; native dependencies, Git helpers, browser binaries, model runtimes, compiler/SDK inputs and package caches are separate. Browser sessions also have OS-bound storage outside Copse's application cipher. | Prepare artifacts online, then cold-start packaged Copse and `make run` offline on both Macs. Execute Git/worktree, PTY, search, browser and real model/tool tasks. Restore dependencies and rebuild native modules offline in a disposable checkout. Audit non-system libraries and absolute shebangs. Verify forward recovery from an interrupted update; browser authentication needs its own explicit portability decision. |
61+
62+
The manifest/preflight and process-ownership work can start without encryption.
63+
Project relocation and integration policy also have independent code boundaries,
64+
but need migrations or behavioral decisions beyond a small path fix. The full
65+
launcher should compose those contracts rather than claim the two implemented
66+
changes establish a portable environment.
67+
68+
## Validation and limits
69+
70+
The implementation PRs carry their own check results. No external drive was
71+
modified, no user profile was migrated, and no credentials were copied during
72+
this audit. No two-Mac/offline/native-runtime acceptance is claimed.
73+
74+
The final release gate remains the sequential rehearsal in #2652: cold-start
75+
both packaged and development builds offline on each Mac, perform a real coding
76+
task, stop/flush/eject, change the mount point, continue the same project/thread
77+
on the second Mac, then return to the first. Preserve an independent backup.

‎docs/plans/execution-runtime-security.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -71,6 +71,11 @@ to enforced containment.
7171
attaches a credential only to an authorized request and records use by opaque
7272
credential identity, never by value. Any temporary raw-secret injection must be
7373
named as a reduced guarantee, scoped, short-lived, and removed after use.
74+
The initial detached-worker exception is explicit, read-only, expiring GitHub
75+
user-token delegation to one task/repository container on a trusted host, as
76+
specified in [the device-bound profile plan](device-bound-profile-encryption.md#initial-scope-direct-delegation-to-a-trusted-host-container).
77+
It does not protect the token from the workload or host administrator, widen
78+
network permissions, or delegate the desktop vault or renewal credentials.
7479
6. **Policy decisions and observed effects are canonical events.** Runtime state,
7580
approvals, process start/exit, network allow/deny, credential use, checkpoints,
7681
restores, and teardown append to the thread spine. Optional hooks may subscribe;

‎docs/plans/hooks-and-feature-packs.md‎

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -345,6 +345,40 @@ revisiting this document, not silently diverging in an implementation PR.
345345
vocabulary, re-exported by the spine under its old name. Rule 4 of the execution guidance
346346
names the new layout.
347347

348+
26. **First-party development actions use actor-specific consent.** For Apple Development, a
349+
panel button click is the consent for that operation and does not open another approval modal.
350+
The panel keeps Copse's typed, thread-owned driver: it validates the selected target, constructs
351+
fixed `xcodebuild` and `simctl` arguments, records a supervised task, bounds logs and duration,
352+
and resolves a macOS executable only inside the validated built app bundle. These operations run
353+
with normal host access because Xcode requires package, cache, signing, developer-service, and
354+
Simulator access and may execute project-controlled build phases.
355+
Destination choices come from Xcode's eligible destinations for the selected scheme; a valid
356+
saved choice is retained, otherwise simulator-only schemes prefer an already booted device.
357+
After a successful user-triggered simulator Run, the panel opens that simulator in Copse's
358+
Desktop pane. Preview presentation failure does not change the recorded Run result.
359+
The project overflow menu uses a bounded filesystem-only scan to reveal Apple Development for
360+
likely Xcode workspaces and already-enrolled projects. It deep-links to the existing setup panel;
361+
detection alone never enrolls a project or starts the MCP server.
362+
363+
Agent-facing Apple tools come from the exact XcodeBuildMCP production dependency bundled with
364+
Copse, rather than a smaller parallel wrapper API. Enabling the pack and enrolling a local macOS
365+
project starts the server in that project root with every upstream workflow enabled; disabling
366+
or unenrolling tears it down. The server is first-party configuration but its calls retain the
367+
normal MCP permission policy: they prompt unless a per-tool grant or the corroborated read-only
368+
policy allows them. It runs outside the generic shell sandbox after that gate because its Xcode,
369+
Simulator, device, debugger, UI-automation, and package operations need host services. Build,
370+
Test, and Build-and-Run calls receive `-allowProvisioningUpdates`; unrelated tools do not.
371+
XcodeBuildMCP image blocks are bounded before being attached to tool results.
372+
373+
The pack also declares one host-native presentation tool, `open_simulator_desktop`. It does not
374+
duplicate any XcodeBuildMCP build, boot, launch, or automation operation: after those operations
375+
boot a Simulator, it asks Copse's existing Desktop pane to connect to that validated booted UDID.
376+
The pane opens view-only and mouse/keyboard control remains an explicit user toggle. This small
377+
host bridge is necessary because an external MCP server cannot address Copse renderer state.
378+
379+
Operation authority for the Copse panel remains process-lifetime scoped: recovery after a host
380+
restart blocks before relaunch because the prior Xcode process may still be alive.
381+
348382
## Target architecture
349383

350384
```mermaid

0 commit comments

Comments
 (0)