Commit Graph

20 Commits

Author SHA1 Message Date
ethernet
ec1267da26 test(compat): the old-updater surface resolves through the pm facade
pm/__init__.py publishes its names via a PEP 562 _EXPORTS table; the static
resolver now follows that table to the owning module, and the frozen surface
names pm.install (6a5a6a05d2 renamed the pm.ensure submodule; the function
kept its name). Receipt tests use the ContextVar API for the current receipt.
2026-09-19 03:35:16 -04:00
ethernet
6a5a6a05d2 refactor(pm): rename the pm.ensure submodule to pm.install; lazy_deps back to the shim
`import pm.ensure` bound the submodule onto the package, shadowing the facade's
`pm.ensure()` function for every later caller in the process (photon's sidecar
start hit `'module' object is not callable`). The module is pm.install now; the
function keeps its name. The facade resolves through `__import__` rather than
`importlib.import_module` so a test that patches import_module globally does not
break attribute access on pm.

tools/lazy_deps.py returns to the 16-line stop_for_relaunch shim the branch wrote
(an origin/main merge had replaced it with main's 775-line implementation); the
project-metadata tests follow. update_cmd re-exports the four old_updater_deps
names the shim tests resolve through hermes_cli.update_cmd.
2026-09-18 23:27:05 -04:00
ethernet
4dd7ff4a35 wip compat surface 2026-09-18 14:41:48 -04:00
ethernet
7d73a180ae Merge branch 'ethie/uv-build-logs' into ethie/pm-clean 2026-09-13 11:18:46 -04:00
ethernet
2875e397b1 Retain shipped plugin adapters and extend the combined compatibility surface 2026-09-12 19:17:02 -04:00
ethernet
93cffdbd3a refactor(update): finish source updates in fresh selected Python 2026-09-12 19:10:32 -04:00
ethernet
53e6f001c7 refactor(pm): consolidate runtime ownership and updater completion
Run historical updater completion in a fresh interpreter so cached imports
cannot revive retired dependency installers. Share Git and ZIP completion,
carry receipt and recovery state, and preserve child exit status.

Route plugin admission, binary acquisition, desktop launch and build paths
through PM. Replace redundant helpers and tests with real worker, package,
publication and launch checks. Keep the shipped compatibility surface fixed.

Targeted Python and desktop checks pass. Native update journeys and fresh
production image qualification remain pending. This is a checkpoint before
those acceptance runs.
2026-09-12 16:30:35 -04:00
ethernet
5e4a2a3d24 refactor(pm): remove legacy dependency and launch managers
Competing installers and checkout-local venv assumptions bypassed PM
selection, install consent, and generation lifetimes. Route consumers
through PM and installation-bound launchers. Refresh source launchers
before obsolete Python entries can be collected.

Remove Node, browser, and CUA acquisition engines, obsolete venv-holder
handling, detached sync, and unused PM APIs. Keep historical updater
exports inert and preserve external tool ownership and native integration.

Share product freshness and prepared inputs across builders. Align plugin
admission, Docker provisioning, setup instructions, and behavioral tests.

Verified targeted Python and JavaScript tests, desktop and web typechecks,
scoped lint, real product builds, and the Docker frontend smoke test.
The missed post-setup test cleanup is included and verified.

Native Windows/macOS execution, full Rust compilation, and the complete
repository suite remain unverified. Historical compatibility requirements
were preserved and extended, not fully rescanned.
2026-09-12 14:57:38 -04:00
ethernet
26c4e8b160 refactor(update): use PM and shared source builders
PM owns Python dependency generations. Shared frontend builders own Node
preparation and compilation. Route source updates and launchers through
these owners instead of separate repair ladders.

Remove obsolete live-venv holder gates and soft build-failure plumbing.
Preserve source validation, staged publication, fleet outcomes, and
historical relaunch hooks.

Verification: 956 tests passed in the combined focused run, with 43 skips.
After the final ZIP exit fix, 583 focused tests passed. Shared JavaScript
builder tests, Ruff, and diff checks passed. Native Windows/macOS and full
packaged-app builds were not run.
2026-09-12 13:45:08 -04:00
ethernet
6e8ef69325 Merge branch 'ethie/canary-side-by-side' into ethie/pm-clean
# Conflicts:
#	tests/compat/old_updater_surface.json
2026-09-11 20:56:27 -04:00
ethernet
16e99423d9 fix(update): freeze shipped updater imports across full history
The old contract described the replacement tree, not the code still running
in installations that update to it. Deleted managed_uv imports escaped it.

Inventory the full reachable update-channel history, discover old entrypoint
paths and helper extractions, then union those imports with the working tree.
Refuse shallow regeneration. Preserve old names when current callers vanish.
Keep same-named function alternatives and require module-scope bindings.

Restore the additional historical names as inert shims. Installer boundaries
stop for relaunch rather than enable fallback installs. Keep live DingTalk
dependency setup on PM rather than the retired lazy_deps import.

History enumeration covers 33,720 commits at 1021a03256 and 8,078 selected
file versions. The generated contract contains 496 required imports with no
missing names. Dynamic edges and their manual-review limits remain visible.
No claim is made that static analysis proves all runtime plugin imports or
every historical platform path. See tests/compat/README.md.

Verification: 622 targeted tests passed with file retries disabled, including
the frozen contract, historical shims, real PM launch tests, and DingTalk.
Ruff, focused type checks, import guard, and comment prose checks passed.
The full suite and native Windows execution were not run locally.
2026-09-11 20:28:26 -04:00
ethernet
d207b0607d fix: track published source release channels at exact commits 2026-09-11 19:52:07 -04:00
ethernet
529050eab7 fix(update): stop retired installers and finish on fresh launch
Old updaters keep running after the checkout changes. Returning None
from their removed uv helpers enables a pip fallback against the new tree.
Keep the historical imports as inert shims and stop dependency entrypoints
with a relaunch message instead. Do not call PM or write recovery markers
from that mixed-version process.

Self-managed source launches use PM's successful input stamp to decide
when dependencies need a sync. Restart on the managed interpreter before
activating the selected generation. Preserve launcher forms and options,
and do not sync while a live updater owns the installation.

Targeted runtime batch: 225 passed, 8 platform skips. Real PM worker tests
build and publish disposable dependency generations, retain prior state on
failure, and exercise fresh-process relaunch before dependency activation.
The final launch guard test also passes. Full suite and native Windows
execution were not run locally.
2026-09-11 19:46:35 -04:00
ethernet
6ee8610b67 refactor(pm): finish consumer contracts and enforce private engine imports 2026-09-11 18:18:58 -04:00
ethernet
48cae98cc1 refactor(update): remove the unused update-phase runner
The production updater runs inline maintenance. Boot bootstrap uses the
shared step registries directly. Neither calls the standalone runner.
Remove its re-exec path and unused flags, but retain the scope CLI,
logging setup, step implementations, and boot registries.

The scope test rejects runner flags before any step runs. Seven tests
of the removed interface are replaced by this refusal contract. The
existing scope and boot behavior tests remain. Regenerate the import
record through its owner. Only the runner's two dependencies disappear.

Verification: 358 tests passed, 0 failed, 15 host skips. Ruff passed.
No installed-state update, full suite, push, or release.
2026-09-10 06:50:30 -04:00
ethernet
efa21c2832 fix(update): pin stable Git and ZIP updates to one commit
The ZIP fallback selected main, while Git reused a mutable local tag.
Select the remote release commit before applying either transport.
If a server requires a named-ref fetch, check FETCH_HEAD.
Keep local tags intact. Refuse a moved fallback tag before touching the tree.

Gitless Windows installs resolve the official release through the API.
Git-error fallback keeps the selected SHA and resumes paused gateways.
Stable updates retain their branch and do not sync upstream main.

Verification: 356 tests passed across eleven files, including real Git,
loopback archive swaps, dirty-tree refusal, local-ahead preservation and
import-surface checks. No production test hook or runner override added.
No installed environment, remote release, or live gateway was updated.
2026-09-10 06:28:04 -04:00
ethernet
d0de305077 test(update): refresh the current mid-swap import contract
Merged runtime and download fixes moved the updater's lazy imports.
The recorded surface still named the removed download-GC helper.
Regenerate it with the existing audit tool, not hand edits or aliases.

All audited source files match committed HEAD. The refreshed names
resolve, and the recorded file set still covers the same update flow.
This does not alter any updater behavior or import the pending drafts.
2026-09-10 01:55:55 -04:00
ethernet
3c08d16ba7 fix(pm): close runtime publication and updater audit gaps
Dependency publication now recovers interrupted config/facts changes before
activation and leases live generations during collection. Receipts retain
update correlation and failed steps across nested command boundaries.
Doctor and desktop surfaces report those failures through shared owners.

Move checkout updates out of the desktop facade. Stage a detached Windows
relaunch waiter before shutdown, with bounded handshake and process-birth
checks. Keep packaged lifecycle tests isolated from the installed app.

Native verification exposed two production races: cron maintenance imported
the interactive CLI and rewrote TERMINAL_CWD, and install-ID reads collided
with first publication. Use the existing owners and locks. Plugin checks
now run at startup and each due-gated housekeeping tick, not after 60 ticks.

Share updater-test mutation boundaries and remove collection-root fixtures.
Separate cold MCP startup from command latency and give the real HTTP drip
test enough time to reach body handling.

Root npm check passed, including packaging. The fixed-tree Windows Python
run reported 44557 passed, one failed, and 1404 skipped, plus one retry-only
HTTP test. Those final failures now pass in a 35-test bounded batch. A real
isolated gateway wrote startup and periodic plugin-check receipts.

Full final-tree CI, bundled Sandbox deployment, and actual App Installer
relaunch remain unverified. docs/pm-audit-status.md records these limits.
2026-09-06 11:45:41 -04:00
ethernet
92686159d1 fix(pm): integrate audited runtime and lifecycle repairs
Prepare dependency generations before selecting them. Keep shipped tool
bytes separate from writable additions, and store facts beside their entries.
Validate proposed plugin sets before config publication. Restore the previous
config if the facts write fails.

Consolidate duplicate updater, backup, setup, and voice helpers. Repair
launcher selection, dependency consumers, download ownership, update feeds,
and native Windows process and file handling.

Verification: 206 changed/prior-failing Python files reported 4630 passed,
one failed, and 330 skipped. Fix the remaining Hindsight fixture boundary.
The final targeted rerun reported 234 passed and two skipped. The store
review regression batch reported 83 passed and one skipped. Desktop
TypeScript checks, 56 selected Electron tests, 24 release tests, and the
removed-import/compatibility guards passed.

This is an integration checkpoint, not full audit acceptance. The complete
Python suite has not run on this fixed tree. Crash-atomic plugin publication,
generation cleanup, receipt correlation, and packaged lifecycle acceptance
remain open in docs/pm-audit-status.md.
2026-09-05 22:36:48 -04:00
ethernet
3d12e86ef1 feat(pm): unified package manager — pm store foundation
Introduce the pm store: a unified, hash-verified package store that
replaces lazy_deps and the old installer's ad-hoc tool downloads.
Store tools are provisioned on PATH (ffmpeg, node/npm via pinned uv),
with a resumable 8-way downloader, verify() returning failure reasons,
and adopt() made EPERM-safe. chromium ships in the payload for every
target. The 3600-line install.sh is replaced by a staged bootstrapper
(heavy deps are pm's job after this); setup-hermes.sh, Dockerfile and
nix pin tables are rewired onto the store. Old install-script tests,
lazy_deps/managed_uv/build_info, and the ps1/bash installer test
batteries are removed with the machinery they tested.

Rebuilt from ethie/pm onto upstream/main (ac6c8028e0) after the
utf-8-sig sweep. 16 hot files (main also churned them) hand-merged:
platform adapters, main.py, electron/main.ts, tui_gateway/server.py,
cua_backend, installer-tests workflow, install.sh (full rewrite),
setup-hermes.sh, plugins doc.
2026-08-31 18:00:48 -04:00