Skip to content

docs(devlog): land the app runtime ownership record and close the unit - #5467

Merged
lidge-jun merged 2 commits into
devfrom
codex/260921-batch-closeout
Sep 21, 2026
Merged

lidge-jun merged 2 commits into
devfrom
codex/260921-batch-closeout

Conversation

@lidge-jun

@lidge-jun lidge-jun commented Sep 21, 2026 •

Copy link
Copy Markdown
Owner

Summary

Documentation only. The planning record for the app runtime ownership batch lived on an unmerged
branch while every lane it describes was already on dev, so the reasoning behind the shipped
code was missing from the tree. This lands 000 through 130 — the charter, the coexistence and
platform findings, both contradiction rounds, the decisions, the lane split, the resolutions, the
re-audit and the gate runbook — and adds 150, the closeout.

150 records two things worth carrying forward.

The popup's translucent surface is decided by one cfg constant, VIBRANT_SURFACE, which drives
both the transparent native builder and the data-tray-vibrancy attribute the stylesheet selects
on. Linux stays opaque, and on an opaque window a transparent stylesheet paints a hole rather than
degrading, so the two sides must not be able to disagree.

The other is a defect no amount of reading would have found. tray-icon calls
NSStatusItem.setMenu whenever a menu is attached, so AppKit pops that menu on mouse-down before
the crate's own click handler — the one that reads menu_on_left_click — is reached. The menu
item that opens the popup was Linux-only, so on macOS and Windows the popup had no way to open at
all, while the code read correctly from either end.

Verification

  • Swept the added files for addresses, mesh hostnames, SSH accounts and absolute user paths.
    Nothing beyond loopback in technical prose; 040 states outright that its first draft's host
    detail was removed.
  • Nothing in the build, typecheck or test path reads from devlog/, so this changes no gate.
  • privacy:scan did not run on this head, and that is worth saying plainly. The scan lives in
    gates, gates is gated on the ci paths filter, and that allowlist has no devlog/** entry —
    so a devlog-only change skips it while the aggregate check still goes green. The hand sweep above
    is the actual evidence for this pull request. The gap is recorded in 150 and raised separately;
    the fix is a trigger of its own for the scan, not adding devlog/** to ci, which would start
    the cross-platform suite for a prose edit.
  • Repository suites, typecheck and build: NOT RUN on the development machine, per the standing
    rule; hosted CI at the exact head is the authority.

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.

Summary by CodeRabbit

  • Documentation
    • Added planning and verification documentation covering desktop runtime ownership, startup behavior, permissions, tray and quit handling, cross-platform packaging, updates, and consent dialogs.
    • Documented platform-specific release-readiness findings for macOS, Windows, and Linux.
    • Added an installed-artifact verification runbook and recorded known limitations, unresolved issues, and follow-up requirements.

The planning record for this batch lived only on an unmerged branch while every
lane it describes was already on dev. The decisions, the contradiction rounds, the
lane split and the re-audit are the reasons the code looks the way it does, so they
belong in the tree beside it. They carry no host detail; 040 says so explicitly,
and a sweep for addresses, mesh names, accounts and absolute user paths finds
nothing beyond loopback in technical prose.

150 records the outcome and the two things worth carrying forward: the single
constant that binds the native translucent surface to the page's CSS hook, and the
defect that no amount of reading would have found — tray-icon assigns the menu to
the NSStatusItem, so AppKit pops it before the crate's click handler runs, and the
popup had no way to open on macOS or Windows.
@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner September 21, 2026 14:57
@github-actions

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-21T15:01:11.405149Z c826627 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Sep 21, 2026
@coderabbitai

coderabbitai Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository: lidge-jun/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: b5a5bf92-f343-4f57-ad8b-cc14b728892c

📥 Commits

Reviewing files that changed from the base of the PR and between 71d02e3 and c826627.

📒 Files selected for processing (16)
  • devlog/_plan/260921_app_runtime_ownership/000_charter.md
  • devlog/_plan/260921_app_runtime_ownership/010_coexistence_findings.md
  • devlog/_plan/260921_app_runtime_ownership/020_windows_linux_findings.md
  • devlog/_plan/260921_app_runtime_ownership/030_contradictions.md
  • devlog/_plan/260921_app_runtime_ownership/040_verification_hosts.md
  • devlog/_plan/260921_app_runtime_ownership/050_webview_dialogs.md
  • devlog/_plan/260921_app_runtime_ownership/060_contradictions_round2.md
  • devlog/_plan/260921_app_runtime_ownership/070_decisions.md
  • devlog/_plan/260921_app_runtime_ownership/080_decisions_round2.md
  • devlog/_plan/260921_app_runtime_ownership/090_lanes.md
  • devlog/_plan/260921_app_runtime_ownership/100_resolutions.md
  • devlog/_plan/260921_app_runtime_ownership/110_reaudit.md
  • devlog/_plan/260921_app_runtime_ownership/120_gate_runbook.md
  • devlog/_plan/260921_app_runtime_ownership/120_install_verification.md
  • devlog/_plan/260921_app_runtime_ownership/130_linux_surface_findings.md
  • devlog/_plan/260921_app_runtime_ownership/150_closeout.md
 ________________________________________________________
< Code review is a dish best served cold. Like a carrot. >
 --------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

The scan lives in the gates job, which is gated on the ci paths filter, and that
allowlist has no devlog entry. So the one change class where reading devlog
matters is the one where the scan never runs, and the aggregate check goes green
anyway. This pull request is an instance: sixteen devlog files, proven by a hand
sweep rather than by the gate.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c8266271b7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@@ -0,0 +1,85 @@
# 150 — Closeout

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Move the closed unit out of _plan

This document records a terminal closeout and states that every lane has landed, but the entire unit remains under devlog/_plan, so the repository's open-work inventory continues to advertise completed work. Move 260921_app_runtime_ownership to devlog/_fin when landing this closeout.

AGENTS.md reference: AGENTS.md:L107-L110

Useful? React with 👍 / 👎.


| Change | Commit |
|---|---|
| Lane A — CLI resolve and stop contracts (#5383) | `c2a4b1`-era, see 090 |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Replace the nonexistent Lane A commit reference

The value c2a4b1 does not resolve to a commit in this repository, and the referenced 090_lanes.md contains no replacement SHA, so readers cannot trace Lane A from this landed-work table. PR #5383 is present as bcb2b92e; record that actual commit instead of the dangling c2a4b1 reference.

Useful? React with 👍 / 👎.

@lidge-jun
lidge-jun merged commit e4ceeb3 into dev Sep 21, 2026
27 of 29 checks passed
@lidge-jun
lidge-jun deleted the codex/260921-batch-closeout branch September 21, 2026 15:01
lidge-jun added a commit that referenced this pull request Sep 23, 2026
* fix(ci): run privacy:scan on the diffs it exists for

`privacy:scan` is a step of `gates`, and `gates` runs only when the `ci` path
filter matches. That filter does not list `devlog/**`, so a pull request whose
only changed files are devlog prose skipped `gates` entirely and the aggregate
`ci` check still concluded success. The gate that makes a public devlog safe
rather than merely visible was inert for exactly the diffs that fill it.

#5467 landed sixteen devlog files that way. Its only evidence was a hand sweep
for addresses, mesh hostnames, SSH accounts and absolute user paths, because
the scan never ran. AGENTS.md records that maintainer-authored security triage
had to be excised from this directory before it could be published, so this is
the expensive direction to be wrong in.

Widening the `ci` filter would also close it, and would also start nine Windows
shards and two macOS shards for a scan that takes seconds -- the tradeoff
`docs` and `structure` already declined. This takes the same shape they did:
its own filter, its own job.

`privacy-gate` is deliberately NOT also conditioned on `ci`. `gates` keeps its
own Privacy scan step, so an ordinary source pull request is still covered by
the path it always used; adding `|| ci == 'true'` here would run the same scan
twice on every source change. The new test pins both halves of that.

Wired into the aggregate gate by name -- needs, CHANGES_PRIVACY, the scoped
variable, GATED_JOBS and the expected_for arm -- because ci.yml's own comment
is that a job missing from that table reads as `undeclared` rather than
passing unnoticed.

tests/ci-workflows/ci-privacy-gate.test.ts mirrors ci-structure-gate.test.ts,
which guards the identical defect for `structure/`. Mutation-tested 4/4:
dropping `devlog/**` from the filter, widening `ci` with it instead, removing
the job from the aggregate needs, and letting the job double-fire on `ci` each
fail it. ci-structure-gate.test.ts pins the GATED_JOBS line verbatim, so it is
updated for the added job.

Fixes #5468

* fix(ci): stand privacy-gate down when gates already runs the scan

Review finding on #5469: when `privacy` and `ci` are both true, `gates` and
`privacy-gate` ran `privacy:scan` twice on the same commit.

That case is ordinary, not exotic. `.github/workflows/ci.yml` is in both
filters, and any change touching source and `devlog/` together sets both — so
this very pull request was double-running the scan.

The first version of the guard asserted only that privacy-gate's `if` did not
MENTION `ci`, which is true of the defect too. It never asserted the property
the comment claimed. The test now pins the stand-down itself, plus the fact that
the two filters share a path, so the case that produced this is visible in the
suite rather than only in a reviewer's head.

The aggregate gate's `privacy` variable mirrors the job's `if` including the new
arm — a drift there reads as "ran when not requested" and fails that gate.

Mutation-tested: restoring the original condition, and letting the aggregate
drift from the job, each fail one test.

* docs(devlog): roadmap for finishing the three CI pull requests in place

* docs(devlog): record the delivered privacy gate and its hosted evidence

---------

Co-authored-by: JUN <bitkyc08@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant