Skip to content

Carry portable NativeStack2604 Terminal profiles and source receipt - #768

Closed
seathatflowsinourveins wants to merge 6 commits into
mainfrom
codex/ns2604-p1-wt-20261006
Closed

seathatflowsinourveins wants to merge 6 commits into
mainfrom
codex/ns2604-p1-wt-20261006

Conversation

@seathatflowsinourveins

@seathatflowsinourveins seathatflowsinourveins commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Scope

Carry a portable 16-profile NativeStack2604 Windows Terminal fragment, with Microsoft-derived identities, quiet AI bells, Claude truecolor and private owner-launcher contracts. This repair hides the obsolete token-lane identity, tests the real fragment in CI and corrects the deployment recipe; deployment remains the co-op's separate work.

  • Publication base: 0d5e650; initial source base ecfa112 is historical.
  • Lane: lane:foundation, exactly one lane label. Keep DRAFT for the command-center micro-check.
  • Owned paths: windows/, checks/check-terminal-profiles.py, scripts/terminal_profile_ids.py, scripts/validate.py, tests/test_terminal_fragment.py, the dated Terminal decision, gateway-composition wording, source receipt and manifests/evidence.json.
  • The four source-defined lane entries remain isolated in commit 6ef0b83 for the later orchestration decision.
  • Qualify the isolated NautilusTrader rc6 runtime candidate #761 is frozen separately at 5771015; no rc6 replay or retry is performed by this repair.

SOTA sources

  • Microsoft fragment extensions, updated 2025-11-12, checked 2026-10-06: supported UTF-8 fragment folders and nested UUIDv5 identities. The nine originally GUID-less profiles preserve their generated identities. The token lane deliberately takes a new derived identity, with its older explicit identity hidden at deploy.
  • Microsoft Terminal v1.25.2733.0, released 2026-10-02, commit dc8ae365847d41f62d1ebca93815bb00959bc12f: src/cascadia/TerminalSettingsModel/Profile.cpp:307-318; CascadiaSettingsSerialization.cpp:370-371,915,1074-1092; doc/cascadia/profiles.schema.json. These supply folder-source ownership, GUID merging, hidden overrides and the declared tabTitle/closeOnExit defaults. The pure settings helper fills the demonstrated deploy gap; it does not discover or mutate host state.
  • Default profile, updated 2022-11-03, checked 2026-10-06: name or GUID selectors. Preserve a correct selector and exact JSONC bytes when no projection change is needed; a correct default does not skip obsolete-profile hiding.
  • Maintained checker and Operations/Local Chat: checks/check-terminal-profiles.py:39-44 and existing controls; windows/nativestack.json:67,79; ops-entry.sh:1-6. Operations is byte-identical. Reuse the maintained JSONC loader; remove the port's unused constants and unreachable deployment wording.
  • native-agent-stack@ecfa11276:docs/decisions/2026-09-28-terminal-experience.md:51,57-64,292,618 supplies visual policy and the fields deliberately omitted here; tests/test_windows_terminal_defaults.py:398-399 supplies the whole-fragment CI convention. scripts/validate.py:26-32 and tests/test_windows_terminal_defaults.py:49-59,129-141 supply publication/client contracts; docs/lanes.md:96-128 supplies registry-last refresh.
  • The source receipt records live-fragment hash c6e49ee6, separately sourced lane-fragment hash b1601f40, approved Phase 1 plan hash 775119dc and co-op A19/A20. Private values are omitted. Owner launcher, prompt, CLI and cwd prerequisites are checked before copying; Librarium remains hidden and deferred.
  • The gateway-composition wording follows the command-center correction of 2026-10-06T03:32:37Z and retained listener/status-line observations: HTTP 21128 and WebSocket 21129 belong to the same process. Old HTTP omniroute-fw 20129 has no established 2604 counterpart.

Evidence-class table

Claim Evidence class Command / receipt
Identities, source transformations and declared defaults source_review evidence/receipts/windows-terminal-2604-fragment-20261006.json
Real 16-profile declarations local_integration Maintained checker rc 0; no native UI or deployment acceptance
Migration/default/privacy controls synthetic 143 required local tests rc 0, including 23 focused fragment/helper tests
HTTP/WebSocket process roles native_proven Prior read-only listener and status-line observations; no routing or Terminal acceptance inferred
Registered hashes and scope local_integration validate.py rc 0; 69 components, 4 profiles, 213 receipts, 10280 hashed files
Earlier installed-client regression failure local_integration, retained Historical 174-test run: 173 passed, 1 Claude 2.1.291 auth_storage_failure decision-table gap; unchanged owner files
Host apply, UI and correct-session continuity pending Co-op apply/read-back below, never executed by this lane

Local commands run

All checks ran at nice 19, one at a time, outside the paper windows. Logs are retained in the lane cache outside /tmp.

rtk proxy nice -n 19 python3 -B -m unittest tests.test_terminal_fragment tests.test_validate tests.test_native_token_ci
# rc 0; Ran 143 tests in 2.181s; OK
rtk proxy nice -n 19 python3 -B checks/check-terminal-profiles.py
# rc 0; PASS 16 profiles
rtk proxy nice -n 19 python3 scripts/component_matrix.py --write
# rc 0; 32 rows, 0 flip-rule violations; outputs unchanged
rtk proxy nice -n 19 python3 scripts/new_host_grand_list.py --write
# rc 0; 32 layers, 66 winners; outputs unchanged
rtk proxy nice -n 19 python3 scripts/validate.py
# rc 0; integrity/scope checks only
rtk proxy nice -n 19 git diff --check
# rc 0

The focused tests exercise the actual repository fragment with no checker arguments, an empty fixture HOME and no host-media discovery. Migration fixtures prove that canonical profiles, other sources and old NativeStack entries remain unchanged; already-correct default selectors still permit obsolete-identity hiding, and repeated projection is a no-op. The new helper performs no file reads or writes.

The historical broader 174-test result is retained separately, with an explicitly paraphrased summary. This repair does not change the notification table/overlay or repeat that unrelated installed-client test. The exact repair unittest summary is retained verbatim.

The command-center read at b216f9d returned ACK_AFTER (two P2, four P3). This repair addresses all six. Its micro-check is pending; source and fixture checks do not establish host acceptance. The old-head required OSV failure was repository-wide in untouched lockfiles, and remains an external owner/gate item rather than a fix in this PR.

Decision record

2026-10-06 Windows Terminal fragment, proposed with review_by 2027-01-01. It records alternatives, intentional token identity migration, source-scoped hiding, omitted tabTitle/closeOnExit declarations and recheck conditions. The checker and fragment are portable; no native client settings are changed here.

Co-op host apply, read-back and rollback

These are operator commands, not executed by this repository lane. Run from
the reviewed repository on NativeStack2604. The co-op first supplies and
verifies the three special launchers above; keep the live special profiles until
that replacement is ready. Independently confirm the right sessions resume.
The apply refuses before copying unless all visible launcher/prompt, native CLI
and project-directory dependencies exist. These checks establish presence only;
the owner still verifies the special session bindings. Librarium stays hidden
with its P1-CLI contract deferred. Keep the old NativeStack fragments and
profiles until R2; the obsolete 2604 identity is hidden without deleting its
source fragment. No Terminal or OS restart is required.

Before deployment, a human operator must retain the original private
fragment for rollback and verify the special-session replacement. The observed
original contains inline authentication, so no AI/co-op step may read or copy it
or its backup. Use the human's existing backup and custody process. The agent-safe
recipe backs up settings, records whether the target existed, and copies only
the public repository fragment. Restoring a preexisting private fragment is a
human step; do not treat the automatic settings rollback as full restoration.

Use the installed Windows PowerShell only to locate LocalAppData; the existing
Python checker supplies its maintained JSONC parser, avoiding a new dependency
or a second parser. Only a default-profile or obsolete-profile override change
requires rewriting settings. An already correct name or GUID default alone
does not bypass obsolete-profile hiding. With no effective change, the exact
JSONC bytes remain; when a change is required, other parsed values remain but
comments and formatting become JSON. Backups retain the exact original bytes
for rollback. The packaged Terminal settings path below exists
on the observed host; another installation must first identify its own path.

cd "$(git rev-parse --show-toplevel)"
rtk proxy nice -n 19 python3 -B - <<'PY'
import datetime, json, os, pathlib, runpy, shutil, subprocess, sys
root = pathlib.Path.cwd()
fragment = root / 'windows/nativestack2604.json'
lane_root = pathlib.Path.home() / '.local/state/native-agent-stack/lanes'
for name in ('command-center-resume.sh', 'co-op-resume.sh', 'codex-account-pool.sh',
             'codex-lane.sh', 'codex-root-lane.prompt.txt',
             'codex-runtime-lane.prompt.txt', 'codex-token-lane.prompt.txt',
             'codex-trading-lane.prompt.txt'):
    assert (lane_root / name).is_file(), 'Owner launcher missing: ' + name
for name in ('claude', 'codex', 'nativestack'):
    subprocess.run(['/bin/bash', '-lc', 'command -v ' + name + ' >/dev/null'], check=True)
project = pathlib.Path.home() / 'code/native-agent-stack'
assert project.is_dir(), 'Native stack project directory missing'
assert (pathlib.Path.home() / 'code/librarium-course').is_dir(), 'Course project missing'
assert (project / 'windows/ops-entry.sh').read_bytes() == (root / 'windows/ops-entry.sh').read_bytes(), 'Reviewed Operations entry missing'
local = subprocess.check_output(['powershell.exe', '-NoProfile', '-Command',
    '[Environment]::GetFolderPath("LocalApplicationData")'], text=True).strip()
local = pathlib.Path(subprocess.check_output(['wslpath', '-u', local], text=True).strip())
target = local / 'Microsoft/Windows Terminal/Fragments/NativeStack/NativeStack2604.json'
settings = local / 'Packages/Microsoft.WindowsTerminal_8wekyb3d8bbwe/LocalState/settings.json'
assert settings.is_file(), 'Identify the installed Terminal settings path first'
sys.argv = [str(root / 'checks/check-terminal-profiles.py'), str(fragment), str(settings)]
os.environ['NATIVESTACK_MEDIA_DIR'] = '/mnt/c/Windows/Media'
checker = runpy.run_path(sys.argv[0])  # validates explicit inputs before mutation
data = checker['load_settings'](settings)
canonical = json.loads(fragment.read_text(encoding='utf-8'))['profiles']
legacy = target.parent / 'lanes.json'
legacy_profiles = []
if legacy.is_file():
    # The separately sourced lane fragment contains no inline account-pool auth.
    # Read only this known source, never the private live special-role fragment.
    legacy_data = checker['load_settings'](legacy)
    assert isinstance(legacy_data.get('profiles'), list), 'Legacy lane profiles malformed'
    legacy_profiles = [{key: profile[key] for key in ('name', 'guid') if key in profile}
                       for profile in legacy_data['profiles']]
project_settings = runpy.run_path(str(root / 'scripts/terminal_profile_ids.py'))['project_terminal_settings']
projected, changed = project_settings(data, canonical,
    legacy_native_stack_profiles=legacy_profiles)
stamp = datetime.datetime.now(datetime.timezone.utc).strftime('%Y%m%dT%H%M%SZ')
backup = pathlib.Path.home() / '.local/state/native-agent-stack/coordination' / ('terminal-profiles-' + stamp)
backup.mkdir(parents=True, exist_ok=False)
shutil.copy2(settings, backup / 'settings.json.before')
if target.exists():
    (backup / 'fragment-restore-is-human-owned').touch()
else:
    (backup / 'fragment-was-absent').touch()
target.parent.mkdir(parents=True, exist_ok=True)
shutil.copyfile(fragment, target)
if changed:
    settings.write_text(json.dumps(projected, indent=2) + '\n', encoding='utf-8')
else:
    assert settings.read_bytes() == (backup / 'settings.json.before').read_bytes()
assert target.read_bytes() == fragment.read_bytes()  # target is now the public fragment
readback = checker['load_settings'](settings)
assert readback == projected
assert not project_settings(readback, canonical,
    legacy_native_stack_profiles=legacy_profiles)[1], 'Settings projection not idempotent'
sys.argv = [str(root / 'checks/check-terminal-profiles.py'), str(target), str(settings)]
runpy.run_path(sys.argv[0])  # explicit deployed fragment/settings/media read-back
print('Fragment/default/obsolete-profile read-back PASS; settings changed:', changed,
      '; rollback directory:', backup)
PY

After apply, repeat the checker with explicit fragment/settings paths and
NATIVESTACK_MEDIA_DIR=/mnt/c/Windows/Media to check actual sound-file presence.
The co-op opens the Command center, Co-op and account-pool profiles through
Terminal and records that each starts the intended existing session/route.
Also inspect the profile picker: exactly one visible Codex token lane, preserved
old NativeStack entries, default Claude, audible+taskbar AI bells,
Claude truecolor and static taskbar bells. These operator observations are still
pending and need their own dated receipt. The declaration checker cannot prove
native session identity, a sound playing, or a title changing in the UI.

Agent-safe rollback in the same Python/LocalAppData context above, with backup set to the
exact directory printed by the apply command:

shutil.copy2(backup / 'settings.json.before', settings)
if (backup / 'fragment-was-absent').is_file():
    target.unlink(missing_ok=True)
else:
    assert (backup / 'fragment-restore-is-human-owned').is_file()
    print('Human operator must restore the original private fragment; do not read/copy it here')
assert settings.read_bytes() == (backup / 'settings.json.before').read_bytes()
if (backup / 'fragment-was-absent').is_file():
    assert not target.exists()

Host evidence

No evidence/hosts files change. The source receipt does not change a platform or readiness status. A future host/UI receipt must retain actual owner observations independently.

Checklist

  • No workflow, action pin, paid host or billing change.
  • No credential, private session binding or personal home path committed.
  • Peer worktrees and old NativeStack profiles preserved.
  • Registry restored from current main, owned evidence re-registered, final registry-only commit.
  • Command-center repair micro-check and co-op host apply/read-back pending.

Post-restart mechanical refresh

Rebased onto immutable main 0d5e650; restored its registry and re-registered only owned evidence. Every owned source file is byte-identical to the preceding reviewed head. The final commit touches only manifests/evidence.json. Fresh validate.py at nice 19 passed: 69 components, 4 profiles, 215 receipts, 10344 hashed files. The 143 required tests and no-argument 16-profile checker also passed. No role/readiness or host acceptance promotion. GitHub review pagination was complete and had no unresolved connector threads; no comment mutation needed. New frozen head: 3a02630. Keep DRAFT for the requested co-op/command-center read. No queued-PR ownership claim or host apply.

@seathatflowsinourveins seathatflowsinourveins added the lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers label Oct 6, 2026
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Closed with a record by the PR triage of 2026-10-07 (the command center's ruling). Not merged; the branch codex/ns2604-p1-wt-20261006 stays on origin at 3a02630.

Folded into #820 at 77d35e4. Of this PR's 11 changed files, 8 are byte-identical there and 3 are merged (shared files, and registry entries re-registered for the merged files); none is lost. The exact-head read of #820 at that head gives the same fold-completeness table.

Reopen trigger: none while #820 carries the content. Reopen with gh pr reopen 768.

@seathatflowsinourveins
seathatflowsinourveins deleted the codex/ns2604-p1-wt-20261006 branch October 8, 2026 17:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant