Skip to content

fix(desktop): persist recovered legacy tile owners - #103548

Open
brandonriverott wants to merge 1 commit into
NousResearch:mainfrom
brandonriverott:codex/hermes-legacy-tile-owner-20260905
Open

brandonriverott wants to merge 1 commit into
NousResearch:mainfrom
brandonriverott:codex/hermes-legacy-tile-owner-20260905

Conversation

@brandonriverott

Copy link
Copy Markdown

What does this PR do?

Recover exact owner routes for saved Desktop tiles written before tiles persisted those routes. Without recovery, an idle restored chat can lose the secondary gateway it needs or fail to route back to its owner.

  • During tile hydration, copy only a unique existing session-owner hint onto a route-less tile and persist it in the primary window. This survives eventual hint-cache eviction.
  • Preserve explicit routes. Leave ambiguous hints unresolved. Never infer ownership from the profile bucket, because separate connections may have the same profile name.
  • Let tile owner lookup and the open-tile gateway keep-set use a unique hint learned after hydration.
  • Pop-out session/browser windows do not rewrite shared tile storage.

Related Issue

Distinct from merged #96110, which backfills backend session ownership, and open #96313, which extends foreground keep-set/resume behavior. This PR migrates renderer tile storage and does not duplicate the foreground keep-set change from #96313.

Type of Change

  • Bug fix

How to Test

From apps/desktop:

  1. npm run test:ui -- src/store/session-states-owner-route-migration.test.ts src/store/session-states.test.ts src/store/session-states-foreground-scopes.test.ts --maxWorkers=3
  2. npm run typecheck
  3. npx eslint src/store/session-states.ts src/store/session-states-owner-route-migration.test.ts

Verified on macOS 26.5.1 against main f58fcc8118d9db092ad60d363d4a28520e08ac5a:

  • On unmodified production code, the new recovery test fails because the restored tile has no owner route.
  • After the fix: 86 tests passed across three files.
  • Full Desktop typecheck and focused ESLint: passed.
  • Independent staged-diff review and added-line static scans: no blocking findings.

The two new invariant tests cover unambiguous recovery, explicit-route precedence, ambiguous-route rejection, persistence after hints disappear, late hints, and both pop-out window types. They use isolated jsdom local storage, not a live user's persisted workspace. Packaged-app E2E and full Python suites were not run.

Checklist

  • Read contributing guide and searched existing PRs.
  • Conventional commit with only the tile owner recovery change.
  • Behavioral persistence and window-isolation tests.
  • No guessing from profile names or defaulting ambiguous routes to a connection.
  • No new configuration or backend schema; optional owner-route field already exists.
  • No platform-specific production APIs added.
  • Packaged-app E2E / full Python suite (not run).

AI assistance

Prepared with Codex assistance. Stated tests, typecheck, and lint ran locally; independent review did not run tests.

Migrate route-less saved tiles from unique durable owner hints, preserve explicit routes, and keep pop-out hydration read-only. Use unique late hints for tile lookup and gateway retention.

Verified with 86 focused tests, full Desktop typecheck, clean focused lint, and independent staged-diff review.
@alt-glitch alt-glitch added type/bug Something isn't working P2 Medium — degraded but workaround exists comp/desktop Electron desktop app (apps/desktop/*) area/sessions Session lifecycle, resume, persistence, history sweeper:risk-session-state Sweeper risk: may lose/corrupt/mis-associate session or context state labels Sep 5, 2026
@Enough1122

Copy link
Copy Markdown

AI code review — automated review for reference; please use your judgment.

Summary

Persists recovered legacy tile owner-routes so a proven unique hint survives cache expiry, and makes live lookups fall back to the hint cache. Secondary/browser windows are excluded from rewriting shared storage.

Findings

  • Non-blocking — apps/desktop/src/store/session-states.ts:112-128: recovery maps tiles without ownerRoute via getSessionOwnerHint. Correctness hinges on hints being unambiguous (only unique hints persisted per test line 27-35); ambiguous sessions stay undefined — good.
  • Non-blocking — apps/desktop/src/store/session-states.ts:130-132: write-back gated on recoveredOwnerRoute && !isSecondaryWindow() && !isBrowserWindow(). Prevents pop-out clobbering; primary-window-only write is the right call.
  • Non-blocking — apps/desktop/src/store/session-states.ts:141-143: resolvedTileOwnerRoute prefers explicit tile.ownerRoute over hint — explicit wins, so a stale hint can't override a real route. Good precedence.

Tests cover persistence, expiry survival, ambiguity, and pop-out no-rewrite. No blockers.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/sessions Session lifecycle, resume, persistence, history comp/desktop Electron desktop app (apps/desktop/*) P2 Medium — degraded but workaround exists sweeper:risk-session-state Sweeper risk: may lose/corrupt/mis-associate session or context state type/bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants