Skip to content

Make managed-agent recovery contextual and preserve conversations - #839

Merged
danshapiro merged 82 commits into
mainfrom
the-usual/managed-recovery-contextual-ui
Oct 4, 2026
Merged

danshapiro merged 82 commits into
mainfrom
the-usual/managed-recovery-contextual-ui

Conversation

@danshapiro

@danshapiro danshapiro commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Summary

  1. Keep automatic managed recovery quiet, show decisions in the affected existing agent pane, and use yellow popups for actionable errors. System Status shows load.
  2. Remove the persistent managed-agent dashboard, routine recovery notices and per-agent resource editor.
  3. Preserve drafts, displayed transcripts, native conversation identities and saved Claude/Codex/OpenCode history during recovery, including native managed storage, older OpenCode schemas and WAL databases. Reading history does not replace or start an agent.
  4. Require confirmed cleanup and an accepted new identity before Start new clears the display. Protect pane/tab/replacement closes, history reads and snapshot ownership against stale, late and lost responses.
  5. Restore recovered panes through existing provider snapshots; pending managed bootstrap can show the same saved history without starting a replacement. Keep automatic recovery from invoking legacy replacement logic.
  6. Correct managed test-image MCP packaging and make restoration/loss receipts measure actual browser interaction and focus.
  7. Permanently include DBus, GTK3, WebKit2GTK4.1/Soup3 and Ayatana native development libraries in the canonical test sandbox. A clean image and the activated shared default passed real unprivileged compile/link/runtime checks without per-run package installation.

Current verification

Published clean feature head 3f739de79f3736c6342644fa38cd753851d729ad, based on main 96e57e83681fef19fe758d20f4835e8efe91484a. All73 original feature commits retained;9 necessary repairs/user-directed plan updates followed,82 total.

  1. Seven managed Rust crates/features, lib/bin/test targets, strict Clippy with warnings denied on Rust1.96: PASS.
  2. Exact source-tagged cloud image 3f739de79f37: CloudBuild SUCCESS. Affected configured-cloud Chromium actually executed all46 cases,25 contextual/10pane/11tab, without retries or skips: PASS. Execution freshell-e2e-3f739de79f37-45wt1w-q9ckd.
  3. Both actual owned-runtime browser cases at the published head: PASS,6.5min. Restoration passed all11 interaction/layout/focus/identity/close/stop/compatibility controls across3agents/3disposable server restarts/4focus observations. Native saved history used the owned provider volume rather than coincident web-local data, preserved original identity and both source bytes, retained dispatch/completion1/1 and one original bootstrap, observed zero recovery and verified safe cleanup.
  4. Ordinary push hooks: PASS, no bypass; exact remote source head verified.
  5. Clean no-cache canonical sandbox79b9: actual native API compilation/linkage/runtime, entrypoint isolation and complete existing behavioral safety selftest PASS. Supported default rebuild activated406b; actual filesystem layers and runtime configuration exactly match79b9, with different BuildKit attestation metadata. Fresh unprivileged native API probe on activated406b PASS. Native full-workspace verification uses selectedRust1.96; image floating-stable safety-selftest default1.99 is separately labeled.
  6. Complete frozen84 verification collection PASS: allthree typechecks; source-runtime2files/9cases; Electron42files/395cases; configured-cloud594files/8622unique cases; complete Rust156targets/5822passing cases,10pre-existing ignored,0failed/filtered. This combines honest same-head completed scopes and corrective fullcloud/fullRust calls; it does not retcon the failed original full9 invocation or certify the subsequent test-only3f head.
  7. Complete actual published-head acceptance PASSED in logical parallel attempt10,19:18:09–19:37:22 UTC: allthree typechecks; full configured-cloud594files/8622unique cases; complete isolated source-runtime2files/9cases with normal build prerequisites; complete isolated Rust156targets/5822passing cases,10pre-existing ignored/0failed or filtered; complete Electron42files/395cases. Duplicate summaries excluded. Independent scopes ran together under the genuine coordinator with separate artifacts, jobs2/testthreads2, the corrected canonical image, unchanged512PID/8GiB limits/cases/assertions/timeouts, and no apt overlays. Every child joined, zero owned containers remain, the holder released and allfour clean audit worktrees returned to root. Allseven current-head GitHub checks PASSED, including rust-tests/rust-gate and allfour verified Linux/Windows/Mac builds. Ready for the user-authorized normal PR merge.

Necessary repairs and evidence qualification

The transcript-preservation fix reproduced actual mounted data loss before cleanup refusal; final23 new behavioral cases plus579 affected/neighbor cases passed. The snapshot handoff fix reproduced three original typed409 failures and a history-present control, then passed isolated Rust1.96 cross-kind51/snapshot69/proxy19/stop-history8/bootstrap10 selectors. Two initial RED reproductions preceded reading the suite's sandbox instruction and remain qualified; all subsequent destructive neighbors/final confirmations were isolated, with no production process targeted.

The blocking12-line static checkout assertion was deleted under the user's explicit test rule. It inspected source text rather than executing the claimed boundary and misidentified a private fake Docker API. All58 retained analyzer/broker/coordinator behavior tests and typechecks passed; runtime/analyzer/manifest/allowlist unchanged.

The final browser locator repair selects existing speaker-labeled transcript bodies. A controlled real header/transcript duplicate reproduced RED, GREEN passed, and removing the actual user transcript caused the corrected assertion to fail while the old broad assertion still passed on title alone. Final8 meaningful neighbors passed without retries. No timeout/retry/skip or native-history/identity/traffic assertion was weakened. Final configured-cloud46PASS verifies this repair at the published head.

Earlier full attempts remain failed evidence:6 static assertion,7 missing canonical native libraries,8 compiler thread exhaustion,9 premature image-readiness validation and runtime process-budget exhaustion. Corrected setup preserves owned output permissions, supported host-verified FRESHELL_BUILD_COMMIT, pinned tools, privilege boundaries and all cases. The scheduling fix bounds concurrency without increasing sandbox limits. No healthy sibling was cancelled; no cloud-to-local fallback occurred.

Review and accepted residuals

Whole-delta round12 PASSED at ab6bba9f5da212142b688ad8933077efe69efbef; all carried binding findings individually cleared. Necessary subsequent local/gate fixes are separately tested and are not retroactively claimed independently reviewed at the final head. Actual53 review attempts/50 substantive reports,2authentication failures/1capacity failure; no additional loop. Five closed OPTIONAL follow-ups remain recorded in the final recap.

The different-family Claude review route could not authenticate through OneCLI. Fresh read-only Codex review contexts supplied same-family evidence with weaker independence; the original different-family requirement remains unmet and disclosed, with user-authorized continuation beyond review caps. Live external-provider certification remains accepted DEFERRED; no raw-secret fallback or certification claim. Provider parity/MCP/config/security-document cleanup already landed in PR834.

Rollout

This PR lands source only. Production has not been built, deployed or restarted.

Use the managed rollout runbook to rebuild the managed server, supervisor and session-host from one checkout with managed-runtime-v1; the ordinary server launcher does not rebuild session-host. Production restart is a separate explicitly approved operation.

@danshapiro
danshapiro marked this pull request as ready for review October 4, 2026 19:41
@danshapiro
danshapiro merged commit 5608386 into main Oct 4, 2026
7 checks passed
@danshapiro
danshapiro deleted the the-usual/managed-recovery-contextual-ui branch October 4, 2026 19:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant