Skip to content

Windows 0.1.8: session-safe UI, library guides and signed-release preparation - #140

Merged
stormstarlight merged 16 commits into
devfrom
release/windows-0.1.8-e-20260918
Sep 18, 2026
Merged

stormstarlight merged 16 commits into
devfrom
release/windows-0.1.8-e-20260918

Conversation

@stormstarlight

@stormstarlight stormstarlight commented Sep 18, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Prepare the explicitly authorized Windows x64 0.1.8 release on an independent branch targeting dev. This PR does not merge or push directly to main/dev, does not publish by itself, and does not change existing updater trust or user data. The operator accepted the preceding manual preview and approved the public stable release/update notification effect, subject to candidate validation and actual signature verification.

Candidate: 413245b9498cfcbd2187951e78dfb6c16ac06b78
Frozen dev base: 428550bcba30e5f21fa9c109604c4ab358eeaec8
Release identity: 0.1.8+616d5065018d86da
Source digest: 616d5065018d86da282649d084cb6e72bfa6d9a660865084c59d775a9f7669e1

Product scope

  • Keep in-memory drafts and File attachments per session, with revision/request/callback ownership so late completion does not erase a different session's newer input. Conversation and map share that session's draft; ordinary navigation does not introduce backend cancellation. Refresh persistence is not added.
  • Route delivery notifications using optional session identity, wait for the selected snapshot before opening a target, and preserve the latest user navigation intent. Old messages retain compatible safe fallbacks; this is not a global notification collector or historical file-version recovery.
  • Clarify the read-only workspace view and display only a loaded session snapshot's directory, with expandable full paths and Windows leaf-name handling. This is not a task-specific cwd assertion, filesystem scan, or sandbox guarantee.
  • Render existing diff text with React text nodes and bounded header/hunk/add/remove/context classification. Preserve raw text, original line endings, copy behavior, and backend truncation information; unknown, binary, and large content fall back to raw display. No new Git mutation or fetch request is introduced.
  • Move plugin, skill-library and knowledge-library entry points below the sidebar brand, with bounded resource scrolling while retaining sessions, bottom settings/theme controls, folded preferences and existing plugin lifecycle behavior.
  • Add source-bound Chinese display names, purpose guides and search for 211 bundled skill/reference entries. Original execution instructions remain intact. User/agent/third-party/modified originals are not automatically translated or rewritten; English mode is preserved.
  • Retain upstream private operator knowledge, model settings, learning, library folding and managed-plugin behavior. The two Python runtime changes are narrow Windows CRLF compatibility fixes in knowledge recall and wiki routes, preserving byte budgets, digests and existing knowledge semantics.

The preview provenance/isolation and documentation changes explain what was actually exercised. They do not claim formal installer acceptance, paid-model validation, full GUI/Toast coverage, or a long-running soak.

Release/build configuration

  • Align 16 first-party package/runtime/plugin metadata and lock-root entries to 0.1.8, including Codex metadata. Third-party project dependency versions remain unchanged. Add Codex metadata to the existing release-version consistency guard.
  • Keep handwritten version/build changes and mechanically generated manifest/Web/TUI outputs in separate commits. All 1,235 frozen-base fingerprinted Web assets remain byte-identical; no old chunks were removed or substituted with preview executables.
  • Exclude both Windows-only tags v0.1.7 and v0.1.8 from automatic all-platform tag publication. Manual platform=windows-x86_64 dispatch builds only Windows and cannot execute the tag-only Release publishing job. PyPI remains disabled; no test/check is deleted or weakened.
  • Pin the Windows runner family, Node 24.19.0, Python 3.11.9, uv 0.12.16 and Rust 1.98.0 MSVC; use frozen project dependencies and explicit build-tool pins including PyInstaller 6.22.3. Preserve the explicit toolchain inside backend isolation and pass --locked through Tauri to Cargo. Existing non-Windows build commands remain unchanged.
  • Keep signing configuration limited to the existing CI signing step. Reject source/generated-artifact drift before uploading the Windows candidate. Keep the updater public key, HTTPS endpoint, CSP/capabilities, ownership checks, installer protections and role/task authority unchanged.

Validation evidence and status

These are E checkout executions, not copied D test results. Runtime/browser checks ran on 9f2356eeed66f3221b214de9f61cae0483a0ec3f; its successor changes only the build-tool declaration and the corresponding CI regression assertion. Product source, Rust inputs, frontend assets and release identity are unchanged, with manifest consistency rechecked. No repeated full product suite was added for that CI-only fix.

  • Before the version/build-only edits: Web 1524/1524, TUI 297/297, and Web/TUI/Desktop UI typechecks passed against E's replayed handwritten source.
  • Release regeneration after the changes passed, including fresh Web/TUI builds/typechecks, manifest --check, artifact checks, and old-asset byte preservation.
  • Windows build/version/CI regression: 24 passed; build-source lint passed. Node copy/staging/signature/provenance boundary tests: 44 passed.
  • On the frozen candidate: targeted Python checks executed 90 tests: 87 passed, 3 failed solely at Windows symlink creation (WinError 1314). The known affected cases are test_wiki_page_refuses_paths_leaving_the_pages_directory, test_knowledge_page_errors_follow_the_project_rules, and test_bounds_and_scope_exclude_symlinked_hidden_retired_or_oversized_files. They were not skipped, weakened, or reported passed. The final candidate's Linux lint/tests and Windows desktop PR checks subsequently passed.
  • MSVC compiler preflight and locked/offline Windows-target dependency checks passed. Candidate Rust core tests: 59/59 passed, with no ignored tests.
  • Browser scenarios against the new E assets: 56/56 passed, zero skipped/flaky, in the fresh single-worker run after Rust compilation completed. Preserve the first attempt's browser target crash / process EBUSY evidence; it was not reported passed. No product assertion was removed or weakened.
  • Slow local network downloads are not reported as successful dependency installation. For source validation/build tooling, 73 already-installed public Python dependencies were checked to exactly match the frozen lock, executed read-only with E source and independent E HOME/data/tmp. Public Cargo archives were independently SHA-256 checked against Cargo.lock into a new E cache; no profile, account configuration, old build outputs or old test results were copied.

Following the operator's request to avoid excessive/repeated testing, validation stays focused on changed behavior and release boundaries. Existing automatic PR workflows remain enabled. Full manual installer/upgrade, native Toast/tray/reactivation, extended all-platform dispatch, paid-model tasks and long-soak acceptance have not been performed or claimed.

Code-line difference and release gates

The operator explicitly confirmed keeping the frozen dev line without main PR #139 (666178eda45fb8852b0ff106505f1add263f7b3d). Consequently this candidate does not include that PR's newer research orchestration, owned-subagent mission recovery, runtime incident escalation or resource-lease recovery fixes. It must not be described as containing latest main; integrating that runtime scope would require separate review and validation.

The Windows-only signed build 35370380743 succeeded on the final candidate. The actual artifact ZIP digest, installer signature and trusted comment, four file hashes, version/x64 architecture, unchanged public key/security configuration, 1,259 frozen Web files, TUI bytes and runtime identity were verified. The formal host extracted from that installer reached authenticated readiness in 5.765 seconds, followed by 16 seconds of healthy observation in a fresh isolated profile. The NSIS installer was not executed, no existing installation/profile was touched, and the check submitted zero paid-model tasks.

Published: Argus 0.1.8 — Windows, at 2026-09-18T17:44:02Z. Tag and stable Release both bind to 413245b9498cfcbd2187951e78dfb6c16ac06b78. All four assets were downloaded anonymously from the public release and matched the verified CI bytes; the public installer signature was checked again, and the existing releases/latest/download/latest.json endpoint returned 0.1.8. Installer SHA-256: 5ceeddb2a919db5bead9702e1535cc749e90a822c693746e25e9629c0e97d2ec.

Initial signing run 35368766040 is retained as a failed attempt: the pinned tools initially omitted Hatchling's dynamic editables dependency. The CI-only correction pins editables==0.6, passes all 8 CI-boundary regression tests, and leaves product source/manifest identity unchanged. No older Release asset was overwritten and main/dev were not merged or directly pushed. Per the operator's explicit Windows-only scope, Mac PR matrix results remain visible and are not claimed passing or used to hold this Windows release; no Mac-specific repair or extra Mac dispatch was performed.

A Tauri updater .exe.sig is not Microsoft Authenticode certification; Windows reputation prompts may remain. Open validation items will be updated with actual evidence, not inferred success.

@stormstarlight
stormstarlight marked this pull request as ready for review September 18, 2026 17:43
@stormstarlight
stormstarlight merged commit a0f1aee into dev Sep 18, 2026
10 of 12 checks passed
@stormstarlight
stormstarlight deleted the release/windows-0.1.8-e-20260918 branch September 18, 2026 17:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant