Repository navigation
docs(devlog): land the app runtime ownership record and close the unit - #5467
Conversation
The planning record for this batch lived only on an unmerged branch while every lane it describes was already on dev. The decisions, the contradiction rounds, the lane split and the re-audit are the reasons the code looks the way it does, so they belong in the tree beside it. They carry no host detail; 040 says so explicitly, and a sweep for addresses, mesh names, accounts and absolute user paths finds nothing beyond loopback in technical prose. 150 records the outcome and the two things worth carrying forward: the single constant that binds the native translucent surface to the page's CSS hook, and the defect that no amount of reading would have found — tray-icon assigns the menu to the NSStatusItem, so AppKit pops it before the crate's click handler runs, and the popup had no way to open on macOS or Windows.
|
✅ Deterministic PR hygiene checks passed. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Repository: lidge-jun/opencodex/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (16)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
The scan lives in the gates job, which is gated on the ci paths filter, and that allowlist has no devlog entry. So the one change class where reading devlog matters is the one where the scan never runs, and the aggregate check goes green anyway. This pull request is an instance: sixteen devlog files, proven by a hand sweep rather than by the gate.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c8266271b7
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| @@ -0,0 +1,85 @@ | |||
| # 150 — Closeout | |||
There was a problem hiding this comment.
Move the closed unit out of
_plan
This document records a terminal closeout and states that every lane has landed, but the entire unit remains under devlog/_plan, so the repository's open-work inventory continues to advertise completed work. Move 260921_app_runtime_ownership to devlog/_fin when landing this closeout.
AGENTS.md reference: AGENTS.md:L107-L110
Useful? React with 👍 / 👎.
|
|
||
| | Change | Commit | | ||
| |---|---| | ||
| | Lane A — CLI resolve and stop contracts (#5383) | `c2a4b1`-era, see 090 | |
There was a problem hiding this comment.
Replace the nonexistent Lane A commit reference
The value c2a4b1 does not resolve to a commit in this repository, and the referenced 090_lanes.md contains no replacement SHA, so readers cannot trace Lane A from this landed-work table. PR #5383 is present as bcb2b92e; record that actual commit instead of the dangling c2a4b1 reference.
Useful? React with 👍 / 👎.
* fix(ci): run privacy:scan on the diffs it exists for `privacy:scan` is a step of `gates`, and `gates` runs only when the `ci` path filter matches. That filter does not list `devlog/**`, so a pull request whose only changed files are devlog prose skipped `gates` entirely and the aggregate `ci` check still concluded success. The gate that makes a public devlog safe rather than merely visible was inert for exactly the diffs that fill it. #5467 landed sixteen devlog files that way. Its only evidence was a hand sweep for addresses, mesh hostnames, SSH accounts and absolute user paths, because the scan never ran. AGENTS.md records that maintainer-authored security triage had to be excised from this directory before it could be published, so this is the expensive direction to be wrong in. Widening the `ci` filter would also close it, and would also start nine Windows shards and two macOS shards for a scan that takes seconds -- the tradeoff `docs` and `structure` already declined. This takes the same shape they did: its own filter, its own job. `privacy-gate` is deliberately NOT also conditioned on `ci`. `gates` keeps its own Privacy scan step, so an ordinary source pull request is still covered by the path it always used; adding `|| ci == 'true'` here would run the same scan twice on every source change. The new test pins both halves of that. Wired into the aggregate gate by name -- needs, CHANGES_PRIVACY, the scoped variable, GATED_JOBS and the expected_for arm -- because ci.yml's own comment is that a job missing from that table reads as `undeclared` rather than passing unnoticed. tests/ci-workflows/ci-privacy-gate.test.ts mirrors ci-structure-gate.test.ts, which guards the identical defect for `structure/`. Mutation-tested 4/4: dropping `devlog/**` from the filter, widening `ci` with it instead, removing the job from the aggregate needs, and letting the job double-fire on `ci` each fail it. ci-structure-gate.test.ts pins the GATED_JOBS line verbatim, so it is updated for the added job. Fixes #5468 * fix(ci): stand privacy-gate down when gates already runs the scan Review finding on #5469: when `privacy` and `ci` are both true, `gates` and `privacy-gate` ran `privacy:scan` twice on the same commit. That case is ordinary, not exotic. `.github/workflows/ci.yml` is in both filters, and any change touching source and `devlog/` together sets both — so this very pull request was double-running the scan. The first version of the guard asserted only that privacy-gate's `if` did not MENTION `ci`, which is true of the defect too. It never asserted the property the comment claimed. The test now pins the stand-down itself, plus the fact that the two filters share a path, so the case that produced this is visible in the suite rather than only in a reviewer's head. The aggregate gate's `privacy` variable mirrors the job's `if` including the new arm — a drift there reads as "ran when not requested" and fails that gate. Mutation-tested: restoring the original condition, and letting the aggregate drift from the job, each fail one test. * docs(devlog): roadmap for finishing the three CI pull requests in place * docs(devlog): record the delivered privacy gate and its hosted evidence --------- Co-authored-by: JUN <bitkyc08@gmail.com>
Summary
Documentation only. The planning record for the app runtime ownership batch lived on an unmerged
branch while every lane it describes was already on
dev, so the reasoning behind the shippedcode was missing from the tree. This lands 000 through 130 — the charter, the coexistence and
platform findings, both contradiction rounds, the decisions, the lane split, the resolutions, the
re-audit and the gate runbook — and adds 150, the closeout.
150 records two things worth carrying forward.
The popup's translucent surface is decided by one
cfgconstant,VIBRANT_SURFACE, which drivesboth the transparent native builder and the
data-tray-vibrancyattribute the stylesheet selectson. Linux stays opaque, and on an opaque window a transparent stylesheet paints a hole rather than
degrading, so the two sides must not be able to disagree.
The other is a defect no amount of reading would have found.
tray-iconcallsNSStatusItem.setMenuwhenever a menu is attached, so AppKit pops that menu on mouse-down beforethe crate's own click handler — the one that reads
menu_on_left_click— is reached. The menuitem that opens the popup was Linux-only, so on macOS and Windows the popup had no way to open at
all, while the code read correctly from either end.
Verification
Nothing beyond loopback in technical prose;
040states outright that its first draft's hostdetail was removed.
devlog/, so this changes no gate.privacy:scandid not run on this head, and that is worth saying plainly. The scan lives ingates,gatesis gated on thecipaths filter, and that allowlist has nodevlog/**entry —so a devlog-only change skips it while the aggregate check still goes green. The hand sweep above
is the actual evidence for this pull request. The gap is recorded in 150 and raised separately;
the fix is a trigger of its own for the scan, not adding
devlog/**toci, which would startthe cross-platform suite for a prose edit.
rule; hosted CI at the exact head is the authority.
Checklist
Summary by CodeRabbit