fix: harden workspace activation and snapshot retention
This commit is contained in:
+14
-7
@@ -13,21 +13,28 @@
|
||||
contents are never stored in Git, API responses, browser storage, diagnostics, or bundles.
|
||||
- **Migration and session safety.** Schema-v2 descriptors are operational; legacy descriptors are
|
||||
visible as `migration_required` until migrated by the documented operator workflow. New sessions
|
||||
persist workspace ID and immutable Git revision. Resume resolves that historical snapshot, while
|
||||
retention preserves every revision referenced by an open, closed, or failed unarchived manifest.
|
||||
acquire a persistent revision lease before readiness and persist workspace ID plus immutable Git
|
||||
revision. Retention hands that lease off only after an authoritative scan observes the manifest,
|
||||
so a stale concurrent scan cannot prune the pinned snapshot. Resume resolves that historical
|
||||
snapshot, while retention preserves every revision referenced by an open, closed, or failed
|
||||
unarchived manifest.
|
||||
Reconciliation runs only with a complete local installation list or an administrator's complete
|
||||
server list, never from a remote user's partial view.
|
||||
- **SSH connector boundary.** The current OpenSSH forward is owned by one bounded diagnostic and is
|
||||
always cleaned up afterward. DWH/vector `ssh_tunnel` bindings therefore return
|
||||
`workspace_not_activatable`, and new-session creation rejects them before persistence. Direct and
|
||||
REST runtime connectors remain supported; Git remote access over SSH is unaffected.
|
||||
- **Operator manuals.** Follow [the local manual](docs/install/local-workspace-registry.md) for
|
||||
macOS/Windows/Linux Docker Desktop deployment and [the server manual](docs/install/server-workspace-registry.md)
|
||||
for Gitea-compatible remotes, reverse proxy, migration, backup, and recovery. The release
|
||||
workflow is Git review/push → installation pull → validate → local diagnostic test → browser-local
|
||||
workspace/model/reasoning selection → revision-pinned session.
|
||||
- **Verification recorded for this source branch.** `git diff --check` passed; backend Vitest
|
||||
**365/365** and TypeScript passed; frontend Vitest **398/398** and TypeScript passed; the
|
||||
harness document regression passed **10/10**. `./scripts/workspace-registry-smoke.sh`, both
|
||||
installation-document verifier profiles, and a final unrestricted full harness run remain the
|
||||
release commands to execute in the deployment environment; the local long-running harness run
|
||||
was intentionally cancelled before it produced a final result.
|
||||
**371/371** and TypeScript passed; frontend Vitest **398/398** and TypeScript passed; the
|
||||
harness document regression passed **10/10**. `./scripts/workspace-registry-smoke.sh` and the
|
||||
executable installation-manual fixture verifier passed with Docker. A final unrestricted full
|
||||
harness run remains a release command for the deployment environment; the earlier local
|
||||
long-running harness run was intentionally cancelled before it produced a final result.
|
||||
|
||||
## Session summary redesign — LIVE 2026-07-23
|
||||
|
||||
|
||||
Reference in New Issue
Block a user