fix: harden workspace activation and snapshot retention

This commit is contained in:
2026-08-04 09:25:06 +02:00
parent 3b23cf3714
commit e4fdbed864
14 changed files with 474 additions and 103 deletions
+14 -7
View File
@@ -13,21 +13,28 @@
contents are never stored in Git, API responses, browser storage, diagnostics, or bundles.
- **Migration and session safety.** Schema-v2 descriptors are operational; legacy descriptors are
visible as `migration_required` until migrated by the documented operator workflow. New sessions
persist workspace ID and immutable Git revision. Resume resolves that historical snapshot, while
retention preserves every revision referenced by an open, closed, or failed unarchived manifest.
acquire a persistent revision lease before readiness and persist workspace ID plus immutable Git
revision. Retention hands that lease off only after an authoritative scan observes the manifest,
so a stale concurrent scan cannot prune the pinned snapshot. Resume resolves that historical
snapshot, while retention preserves every revision referenced by an open, closed, or failed
unarchived manifest.
Reconciliation runs only with a complete local installation list or an administrator's complete
server list, never from a remote user's partial view.
- **SSH connector boundary.** The current OpenSSH forward is owned by one bounded diagnostic and is
always cleaned up afterward. DWH/vector `ssh_tunnel` bindings therefore return
`workspace_not_activatable`, and new-session creation rejects them before persistence. Direct and
REST runtime connectors remain supported; Git remote access over SSH is unaffected.
- **Operator manuals.** Follow [the local manual](docs/install/local-workspace-registry.md) for
macOS/Windows/Linux Docker Desktop deployment and [the server manual](docs/install/server-workspace-registry.md)
for Gitea-compatible remotes, reverse proxy, migration, backup, and recovery. The release
workflow is Git review/push → installation pull → validate → local diagnostic test → browser-local
workspace/model/reasoning selection → revision-pinned session.
- **Verification recorded for this source branch.** `git diff --check` passed; backend Vitest
**365/365** and TypeScript passed; frontend Vitest **398/398** and TypeScript passed; the
harness document regression passed **10/10**. `./scripts/workspace-registry-smoke.sh`, both
installation-document verifier profiles, and a final unrestricted full harness run remain the
release commands to execute in the deployment environment; the local long-running harness run
was intentionally cancelled before it produced a final result.
**371/371** and TypeScript passed; frontend Vitest **398/398** and TypeScript passed; the
harness document regression passed **10/10**. `./scripts/workspace-registry-smoke.sh` and the
executable installation-manual fixture verifier passed with Docker. A final unrestricted full
harness run remains a release command for the deployment environment; the earlier local
long-running harness run was intentionally cancelled before it produced a final result.
## Session summary redesign — LIVE 2026-07-23