Skip to content

0.7.1 integration: protected-content provisioning, Home first-run seed, Home Agent on the typed model contract - #58

Merged
irzhywau merged 34 commits into
upstream/0.7.1-devfrom
feat/0.7.1-integration
Sep 8, 2026
Merged

irzhywau merged 34 commits into
upstream/0.7.1-devfrom
feat/0.7.1-integration

Conversation

@irzhywau

@irzhywau irzhywau commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

What this is

The 0.7.1 integration branch: the two open 0.7.1 feature lines brought together on
upstream/0.7.1-dev, plus the cross-cutting fixes that only appear once they run
side by side, and the docs that record the resulting 0.7.1 truth.

Base is upstream/0.7.1-dev at c511b133. The branch is 34 commits ahead and
0 behind, so it needs no rebase.

What it includes

Protected-content installed provisioning — merged from
feat/protected-content-installed-provisioning (#52), which sits on the reviewed
protected-content stack. Provisions installed custody and chain prerequisites,
documents the operator surface, and verifies custody-node provisioning through
the installed provider.

Home 0.7.1 first-run seed and chrome — merged from
feat/home-first-run-seed-0.7.1 (#54). First run seeds an empty desktop with
Marketplace pinned, plus the lock face, the flat Documents layout, the Library
toolbar menu, dock motion and the Apps face, and service capsules owning their
own Marketplace icons. Two follow-ups live only here, because they were found
while integrating: restoring the first-run hint and its CSS spacing, and
packaging provider capsule metadata in setup.

Home Agent on the typed model contract — the four commits of
feat/home-shelf-assistant-face-0.7.1 (#55), rebased rather than merged. The
Shelf morphs into the Agent composer and opens the Agent Space, the agent harness
becomes its own capsule, the Home Agent capsule gets a workspace object and its
own model attribution, and a capsule gate covers the typed contract, the
workspace and the seam. Content is equivalent to #55; only the ancestry differs,
so #55 will not auto-close and should be closed by hand once this lands.

Integration-only work

These commits exist on this branch alone. They are the cost of putting the three
lines together, and they are what makes the candidate hold up as one build.

  • Managed providers resolve from the installed bin directory, so a provider
    found at development time is still found once installed.
  • Capsule handoffs are bound to Home through an explicit message contract, so
    the agent harness and the Home shell agree on the seam instead of relying on
    window shape.
  • Agent launch and window layout are unified across the shell, covered by the
    Agent shell smoke and the Home regression smoke.
  • The object-provider lockfile is refreshed after provisioning.
  • A clippy question_mark fix in setup.rs, which was the CI lint failure on
    this branch.

Docs

state.md and TASKS.md are brought to the 0.7.1 development and acceptance
truth, and AGENTS.md is aligned with it. The superseded protected-content
journey plan is removed. docs/MODEL_PROVIDER.md is added: it defines the model
provider authority boundary, inference placement and delivery, and separates
model responses from agent execution, which is the contract the Home Agent
capsule is written against.

Review notes

irzhywau and others added 30 commits September 2, 2026 14:04
…ent the operator surface

Promote custody-provider from dev-dependency to dependency so operator provisioning calls the same provision_state_root the provider binary uses; refresh object-provider's lockfile and build-script permissions for the shared-artifacts layout; document the elastos protected-content-config command surface in docs/PROTECTED_CONTENT.md.
…uisites

One explicit operator command surface, elastos protected-content-config: create the policy authority key; provision each custody host's inactive state root (the owner-only directory boot registration requires but nothing created) and export its node descriptor; print the Runtime issuer custody hosts must trust; assemble and sign the owner-only 2-of-3 custody composition from three descriptors with canonical ordering, derived operator/failure-domain ids, and random owner state roots; and install the private multi-source Chain configuration with the deployment-proven Base gateway and selector defaults, enforcing the documented 2..=5 distinct-origin evidence rule. Generated files are proven against the Runtime loaders before success is reported, and a group-readable data root stays provisionable since owner-only modes are enforced from protected-content down.

Boot now wires reconcile_runtime_custody_viewers_after_decrypt_registration into the decrypt-registration success arm through a warn-and-continue hook, settling viewer records stranded before decrypt came up, and names each absent protected-content provider binary instead of skipping it silently.
New Homes start with nothing on the desktop: apps are in the dock and the
Apps face, content is reached through Library. Marketplace joins the default
dock pins after Library so the way to get more is one click away.

Only affects the first-run layout seed; saved layouts are untouched.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…ox and Chat Room

The Home unified-sidebar chrome paints the traffic lights over the first
52px of the capsule frame. Library, Marketplace, System, People and
Services already reserve that band; Documents, Inbox and Chat Room did
not, so the lights sat on top of the first sidebar control (Documents'
New button overlapped outright).

Documents follows the Library convention (--window-chrome-safe-top, minus
its own 0.75rem page inset). Inbox and Chat Room use a capsule-local 52px,
matching System and the entropy gate's rule that those two keep
capsule-local top padding only.

Co-authored-by: Cursor <cursoragent@cursor.com>
…he column height

Co-authored-by: Cursor <cursoragent@cursor.com>
…ge clock

Brings the URUX lock face visual onto the Home host: ELASTOS wordmark,
wallpaper as a full-bleed ground with a vignette, date and clock at
their intended size, compact avatar with the name beneath.

Two defects in the existing face go away with it: the generic
`.home-unlock p` rule outranked `.home-unlock-date/-time` so the clock
rendered at 13px grey, and the picker-flow entrance animation left a
transform on the face, making it the containing block for the fixed
ground and clipping the wallpaper to a centred column. Date/time rules
are now scoped under .home-unlock and the entrance animates the
brand/clock/account instead of the face.

No behaviour change: shell-auth.js, the explicit-click passkey flow, and
the person/person-name ordering are as before; no account directory.

Co-authored-by: Cursor <cursoragent@cursor.com>
Brings the URUX Documents look onto the 0.7.1 Documents: flat 220px
sidebar that owns the traffic-light safe-top, compact round New button
with a pill search beside it, flat main pane, segmented Write/Split/Read
control, uniform toolbar sizing. No cards inside a padded page.

Only the <style> block changes. Markup and script are the 0.7.1 ones
(26 Aug refine, 30 Aug save-or-discard and preview fixes), so behaviour
is unchanged; the five newer classes (toolbar-group, workspace-toggle,
workspace-tab, find-actions, find-highlight) are styled to match.

Tokens keep the canonical shared-sheet mappings the entropy gate
requires; the URUX literal palette values are not carried over.

Co-authored-by: Cursor <cursoragent@cursor.com>
The toolbar "…" menu already carries New ▸ Folder / Text Document,
Upload Here, Paste, Sort By, View, Refresh, Show Hidden and Properties,
and the toolbar already hides the Sort select and Refresh button in its
favour. The New folder and Upload buttons now follow the same rule, so
the toolbar is navigation, breadcrumbs, search, view toggle and the menu.

One line in syncToolbarChrome; the buttons and their handlers remain for
the picker/attach flows and the existing tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
…ive reorder

The idle pill is width:max-content, which no browser can interpolate, so the
declared width transition never ran: the dock jumped on every pin, unpin,
launch and Apps open. Width changes are now a pixel FLIP (lock, reflow, ease,
unlock), with transitions suppressed on the lock flush so the base transition
cannot start and be reversed at 0% into an instant jump.

The Apps face reveal is height-led (420ms ease-out, opacity only guards the
first frames) and the pill's width eases in step, so the one Shelf-face state
reads as the pill growing up rather than a fade over a snapped box.

Dragging over the dock reorders live: a dock-sized spacer holds the slot, the
other pins FLIP around it, a dragged pin parks, and the pill eases as the slot
opens and closes. Nothing commits until drop; the never-silent-unpin rule and
the drop rules are unchanged. The smoke's fake style gains the two CSSOM
methods (setProperty/removeProperty) the shell uses for inline custom props.

Co-authored-by: Cursor <cursoragent@cursor.com>
The face no longer widens to a 720px popup: it locks to the dock's own width
(min 320, set in px at open because the idle width is max-content) and uses
denser 72px tiles, so it grows up out of the dock with nothing either side of
the dock row. Motion timing moves to tokens — --shelf-face-ms 950ms,
--shelf-face-ease ease-in-out, --dock-width-ms 780ms — the pill glides rather
than pops. Gate bounds for the phone face are unchanged.

Co-authored-by: Cursor <cursoragent@cursor.com>
…k row

The launcher content rode up with the pill's top edge during the reveal
(block launcher, popover shrinking to the growing max-height), so icons
appeared to leave the dock and slide upward. The launcher is now a bottom-
justified column, the popover keeps its full height, and the grid sinks to the
dock row with an auto margin — the rising edge uncovers stationary icons first
and the header last, and scrolling stays reachable when the grid overflows.

Shelf pins live in the dock row directly under the face, so they are no longer
duplicated in the grid; the open grid refreshes when pins change.

Co-authored-by: Cursor <cursoragent@cursor.com>
… close

Closing the face snapped the pill back to --taskbar-h while the launcher was
still collapsing, so the dock row was pushed below the pill and rode back up —
the "icons leave the dock and slide up" defect. The pill now sizes to content
in both faces (min-height 72, symmetric padding), so it shrinks with the
launcher and the row never moves.

The reveal follows the Shelf cadence: the pill grows up as empty glass (height
only, width locked) and the content fades in where it lives at 82% of the
stretch (header, then grid); closing lets the content leave first (140ms), then
collapses. Grid returns to the top; the grid/row gap and tile density live in
rules that do not flip with the face class, so nothing reflows on the first
close frame.

Co-authored-by: Cursor <cursoragent@cursor.com>
… pill

The first taskbar render on load eased the pill width from the empty pill,
so every icon slid in from outside it. Width easing now only runs between two
populated docks.

For pin and running-set changes, icons already on the dock start where they
were and glide to their new slot in step with the pill's edges (per-slot FLIP,
same duration and ease), so none is ever outside the pill; an icon new to the
dock settles into its slot once the pill has made room.

Co-authored-by: Cursor <cursoragent@cursor.com>
Every first-party provider capsule now declares `"icon": "icons"` and ships
its own icon-32/64/128/256 set, exactly like app, viewer and content
capsules do. The catalog read model already published declared icon routes
for any role; two things kept them from reaching the Store:

- the gateway only served declared icon variants for content/data
  capsules. Providers never serve a browser document, so extend the same
  declared-only allowlist to the provider role. Manifest, rootfs and the
  capsule root stay 404.
- source-home install materialized only `capsule.json` for provider
  contracts. Copy the declared icon set beside it (all four sizes required,
  no traversal).

Marketplace and Services render the icons through the existing
`iconVariants` read model; no name→icon map, no provider names in app
source.

Tests: declared provider icons servable and nothing else; all eleven
service manifests validate, declare `icons`, and ship the four rasters.

Co-authored-by: Cursor <cursoragent@cursor.com>
… model attribution

The Home Agent capsule needs two things from the Runtime and nothing else.

Workspace: GET/PUT /api/apps/home-agent/workspace behind the capsule's launch
token. The document is an opaque, bounded JSON value (size and depth capped),
revisioned with if_revision so a stale writer gets 409 and never overwrites,
written as a principal-root protected object (ciphertext at rest, declared
for recovery) and isolated per principal. Mirrors the Assistant workspace
route.

Model proxy: home-agent joins the capsules allowed to call the typed model
contract (offers_list, runs_create, runs_events, runs_cancel). Runs are
bound and audited to the calling capsule id taken from the launch token's
executable actor, instead of the previous hardcoded "assistant".

Tests: absent-get is read-only at revision 0; round trip and restart preserve
the exact document; wrong capsule is 403 and principals stay isolated; stale
and future revisions fail without mutation; malformed requests fail closed;
the object is declared for recovery and stored as ciphertext; a home-agent
run binds and audits to "home-agent".

Co-authored-by: Cursor <cursoragent@cursor.com>
…ent Space

Home GUI owns the motion and the place, nothing else. The Shelf pill grows
into a composer face (FLIP in pixels — CSS cannot interpolate max-content →
fixed width), the Home surface breathes down and the Agent Space rises as a
stage the pager knows about. The room itself is the home-agent capsule in an
opaque-sandboxed frame, launched like the Wallet rail through launchHomeTarget.

The frame is reached only by postMessage with the sender pinned to the frame
window:
  Home → capsule   home-agent:open | home-agent:shelf-handover {on} | home-agent:close
  capsule → Home   home-agent:ready | home-agent:shelf-metrics {width,height,radius}
                   home-agent:close | home-agent:open-viewer
Home never reads the frame's DOM; the capsule never reaches Home's.

Co-authored-by: Cursor <cursoragent@cursor.com>
…model contract

The URUX agent harness — sessions, projects, transcript with thinking blocks
and progress, markdown and math, edit / delete / regenerate, follow-up queue,
attachments, dictation — lifted as the home-agent capsule with its visual
fidelity intact, and with everything the Runtime does not back removed.

Inference is the typed model contract or nothing. offers_list decides what
the model menu and Settings › Models show; a turn is runs_create with
elastos.model.input.text/v1 {prompt}, polled by runs_events after_sequence,
stopped with runs_cancel. No offer, provider or model is named in source.
When no offer is advertised the harness says so; it never answers for the
model. The model chosen in the menu is the one the run uses and it persists.

State the Runtime backs lives in the capsule's workspace object (revisioned,
principal-root protected): sessions, projects, prompt, notes, context budget,
thinking visibility, chosen offer, live usage ledger. No browser storage.

Removed because nothing behind them was real on this Runtime: the mock
provider and its seeded replies, tool grants and the Inbox grant cards
(library.read / web.search / wallet.sign routes do not exist here), the
approval-mode chip, Chat/Build segment, Workbench rail (outputs, plan, diff,
browser, terminal), Studio, Usage, model catalog with Get / Mine / hardware
estimate, Settings › Overview / Machine / Tools / Runtime / Permissions,
temperature and reasoning-effort controls (the typed input has no sampling
knobs), the preview banner and every "preview"/"mock" line of copy.

Also fixes session menu state that was undeclared after the capsule split
(opening a chat's "…" menu threw a ReferenceError).

Co-authored-by: Cursor <cursoragent@cursor.com>
…and the seam

node scripts/home-agent-shell-smoke.mjs, wired into `just verify`. Asserts in
source that no offer is named, no browser storage or provider ping is used,
no removed module or absent route is imported or called, no mock reply path
exists, the workspace client reads before it writes and reloads on 409, the
gateway route is principal-root protected and capsule-bound, index.html
carries no theatre surface or preview copy, Settings offers only what the
Runtime backs, and Home is reached by message only. Exercises the pure
model-contract module (offer eligibility, transcript prompt, run body,
after_sequence page reduction and its failure modes) directly.

Co-authored-by: Cursor <cursoragent@cursor.com>
@irzhywau irzhywau added this to the 0.7.1 milestone Sep 8, 2026
CI lint on PR #58 failed under Rust 1.91 clippy with -D warnings:
extracted_bundle_cache_stale_reason guarded with
`if extract_path.is_none() { return None; }`, which the
question_mark lint rewrites as `extract_path.as_ref()?;`.
Same behaviour, lint-clean.
@irzhywau
irzhywau marked this pull request as ready for review September 8, 2026 10:05
@irzhywau irzhywau changed the title Feat/0.7.1 integration 0.7.1 integration: protected-content provisioning, Home first-run seed, Home Agent on the typed model contract Sep 8, 2026
@irzhywau
irzhywau merged commit 6c61c99 into upstream/0.7.1-dev Sep 8, 2026
8 checks passed
@irzhywau
irzhywau deleted the feat/0.7.1-integration branch September 8, 2026 13:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants