Skip to content

docs(exploration): desktop filesystem as a governed capability (0270) - #389

Merged
crs48 merged 2 commits into
mainfrom
claude/compassionate-bohr-c8e853
Jul 30, 2026
Merged

docs(exploration): desktop filesystem as a governed capability (0270)#389
crs48 merged 2 commits into
mainfrom
claude/compassionate-bohr-c8e853

Conversation

@crs48

@crs48 crs48 commented Jul 6, 2026

Copy link
Copy Markdown
Owner

Summary

Exploration 0270 — a thought experiment on giving the desktop (Electron) app access to the user's local file system, both to load context into the workspace ("digital brain") and to let plugins/agents do real file work (compose documents, synthesize analysis).

  • Builds on unimplemented 0127 (ingestion/indexing design) and adds the actor half: filesystem as a sixth ModuleCapabilities entry, brokered per-plugin like secrets/network, enforced by a new guardFs facade beside guardStore/guardedFetch.
  • Grants are device-local roots picked via native dialog; renderer and plugin code never see paths (opaque IDs only). Marketplace-tier plugins get no direct fs — they consume indexed nodes via guardStore.
  • Writes: managed workbench folder → save-as powerbox dialogs → in-place edits deferred.
  • Agents: xnet_fs_* MCP tools on :31416 with plan→approve→apply, plus a lethal-trifecta taint gate (sessions that read local files require approval for outbound actions/shares).
  • Platform matrix: Electron full; Chromium web "lite" adapter possible later; Safari/Firefox/mobile none.

Docs-only — no changeset needed.

🤖 Generated with Claude Code

@crs48
crs48 temporarily deployed to pr-389 July 6, 2026 00:17 — with GitHub Actions Inactive
@github-actions

github-actions Bot commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

✓ Changelog fragment found — thanks!

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Signed-off-by: xNet Test <test@xnet.dev>
@crs48
crs48 force-pushed the claude/compassionate-bohr-c8e853 branch from 8ca81dd to 426295e Compare July 6, 2026 00:17
@crs48
crs48 temporarily deployed to pr-389 July 6, 2026 00:17 — with GitHub Actions Inactive
@github-actions

github-actions Bot commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

Preview removed for PR #389.

github-actions Bot added a commit that referenced this pull request Jul 6, 2026
@crs48 crs48 added the skip-changelog Exclude this PR from the changelog label Jul 30, 2026
@crs48
crs48 temporarily deployed to pr-389 July 30, 2026 15:59 — with GitHub Actions Inactive
@crs48
crs48 merged commit ad2c9a3 into main Jul 30, 2026
9 of 10 checks passed
@crs48
crs48 deleted the claude/compassionate-bohr-c8e853 branch July 30, 2026 16:01
github-actions Bot added a commit that referenced this pull request Jul 30, 2026
crs48 added a commit that referenced this pull request Jul 30, 2026
…(0410) (#658)

Implements exploration
`0410_[_]_OPEN_PR_TRIAGE_AND_THE_STRANDED_BRANCH_PROBLEM.md`, written in
the previous turn.

## What this closes out

Eight PRs were open, the oldest from March. Checking each one's **actual
diff against `main`** (rather than its description) found that four
described work already in `main`, re-derived and landed weeks later by
another route.

| PR | Age | Action taken |
| --- | --- | --- |
| #400 | 24d | **Closed** — fix landed on main in a better form; branch
predates 0391 and would have deleted `NodeLineRunner` |
| #9 | 145d | **Closed** — draft;
`apps/electron/src/renderer/workspace/` no longer exists |
| #595 | 11d | **Closed** — byte-identical to main (`fbc2965a2`) |
| #463 | 20d | **Closed** — main has a longer, `[x]` version of 0298 |
| #13 | 141d | **Closed** — both fixes on main verbatim |
| #505 | 17d | **Merged** — exploration 0318 + scale bench |
| #389 | 25d | **Merged** — exploration 0270 |
| #449 | 20d | **Rebuilt here** — see below |

`#400` was the load-bearing one: `git diff origin/main pr400 --
packages/devkit/src/command-runner.ts` showed ~150 lines of *deletion*
covering the whole 0391 streaming agent seam. Only its `CONFLICTING`
state had prevented that.

`#505`'s `build-and-smoke-test` went green on a rebase, confirming it
was branch staleness rather than the diff.

## The #449 rebuild (0290 bugs #2 and #3)

The original patched `apps/web/src/workbench/SyncStatus.tsx`, which 0406
deleted; the component now lives in `packages/workbench`, so the rebuild
lands on **desktop and web at once**.

- `WorkbenchHost` gains a `hub` capability (`configuredUrl` / `connect`)
so the shell can offer a way out of the disconnected state without
importing either app's `hub-url` module. `connect` returns a reason
string on rejection — never a silent no-op.
- `SyncStatus` exports `openSyncStatusPanel()`; the desktop popover and
mobile sheet both listen. The panel shows an inline hub-URL form while
there is no hub.
- `ShareDialog`'s `!ready` branch explains why a hub is needed and
offers **Connect a hub…**; private-hub links now confirm before copying.
- Adds `normalizeHubUrl` to the electron renderer's `hub-url` mirror (+4
unit tests), so a malformed URL is rejected loudly rather than
persisted.

Verified by driving the real app against a local hub — the CTA closes
the dialog and opens the panel; an invalid URL shows an error and
persists nothing; `https://hub.xnet.fyi/` normalises to
`wss://hub.xnet.fyi`; a `localhost` link's first Copy click asks "Copy
local-only link?" and writes nothing, the second copies. No console
errors. 0290 is now `[-]` at 11/20.

## Stopping the recurrence

Time-to-merge for the last 20 merged PRs was **0 hours median, 1 hour
max** — there is no review queue, so a PR that outlives its session is
abandoned, not pending.

- `.github/workflows/stale.yml` — warns at 14d, closes at 21d,
`keep-open` exempts. Named consumer (the maintainer, weekly) and a
decidable pass condition, per AGENTS.md.
- Fixed the `/explore` next-number command, which read only the working
tree and so handed out numbers already claimed on branches. Seven
explorations were found stranded that way.

🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-changelog Exclude this PR from the changelog

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant