Skip to content

fix(desktop): automatically use newer qualified runtimes - #5582

Open
loopx-agent wants to merge 1 commit into
mainfrom
codex/app-runtime-startup-recovery-20261004
Open

loopx-agent wants to merge 1 commit into
mainfrom
codex/app-runtime-startup-recovery-20261004

Conversation

@loopx-agent

@loopx-agent loopx-agent commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

Opening Desktop with a different CLI revision or an unreadable saved runtime choice could leave the first window waiting for a manual version decision. Startup now discovers qualified runtimes automatically, compares semantic versions and bounded official-repository ancestry, and uses the newer runtime when freshness can be established. Unknown or offline comparisons retain a usable installation rather than guessing from SHA order or installation time.

The packaged macOS App checks its official update channel once on launch through the signed updater. A newer bundled runtime is prepared through the existing installer in App-owned storage; uv/pip/pipx's default command and the user's shell profile retain their installation owner. Explicit LOOPX_BIN pins remain developer-owned. Both HTTP services must read back the selected artifact identity before the workspace opens. Corrupt preferences recover through discovery; terminal failures stop the wait counter and expose recovery immediately.

This is a bounded S4/S5/S12 startup and recovery slice under the overall roadmap; multi-Turn supervision and the full Desktop journey remain unqualified. Ownership remains in the native startup/update adapter, existing installer and Core installation identity. The new launch preference stores only an executable path. Core's canonical installation-only wheel identity from #5543 is reused when available; older CLIs use the App-owned fallback. The related refactor removes the manual pairing decision and duplicate runtime-step logic rather than introducing another package identity owner. This changes the default macOS launch behavior from manual pairing to automatic update/selection; README and browser regression expectations are updated together.

Validation on this head's source:

  • Rust library: 76 passed, 2 ignored; both ignored real-artifact checks were run separately and passed (private installer preserves default CLI bytes; signature-verified App backup). All-target clippy with warnings denied passed.
  • Packaged browser update/recovery smoke and all 5 diagnostic tests passed, including immediate error recovery, mobile/reduced-motion, redaction and reload cases. Full semantic inventory smoke and public boundary scan passed.
  • Installed macOS candidate with real Core backend: corrupt remembered choice recovered; an older source selection automatically advanced to the newer bundled snapshot; ordinary reopen reached the workspace without reinstalling. Both real HTTP service identities matched the chosen runtime. The ordinary primary-App launch continued after a bounded update-check timeout and opened the workspace.
  • Premerge executed 19 checks: 18 passed, 1 failed. examples/cli-project-lifecycle-command-modularization-smoke.py fails during refresh with 'NoneType' object has no attribute 'todo_id'; the same failure was independently reproduced from a clean archive of baseline 1af7dbd43a1629b0356ecd5ee28a426ad45d1d7a. This remains a merge hold, not a passing gate.

No newer signed feed candidate was available for a live App replacement test. Windows/Linux, pipx runtime reuse, multiple simultaneous primary Apps, notarization and sustained operation remain unqualified. Wheel reuse depends on #5543; a fingerprint is an artifact reuse fence, not publisher/source attestation. The installed build is a local repair candidate, not a public release. Please retain maintainer review/merge for this runtime and product change.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant