Repository navigation
0.7.1 integration: protected-content provisioning, Home first-run seed, Home Agent on the typed model contract - #58
Merged
Conversation
…ent the operator surface Promote custody-provider from dev-dependency to dependency so operator provisioning calls the same provision_state_root the provider binary uses; refresh object-provider's lockfile and build-script permissions for the shared-artifacts layout; document the elastos protected-content-config command surface in docs/PROTECTED_CONTENT.md.
…uisites One explicit operator command surface, elastos protected-content-config: create the policy authority key; provision each custody host's inactive state root (the owner-only directory boot registration requires but nothing created) and export its node descriptor; print the Runtime issuer custody hosts must trust; assemble and sign the owner-only 2-of-3 custody composition from three descriptors with canonical ordering, derived operator/failure-domain ids, and random owner state roots; and install the private multi-source Chain configuration with the deployment-proven Base gateway and selector defaults, enforcing the documented 2..=5 distinct-origin evidence rule. Generated files are proven against the Runtime loaders before success is reported, and a group-readable data root stays provisionable since owner-only modes are enforced from protected-content down. Boot now wires reconcile_runtime_custody_viewers_after_decrypt_registration into the decrypt-registration success arm through a warn-and-continue hook, settling viewer records stranded before decrypt came up, and names each absent protected-content provider binary instead of skipping it silently.
New Homes start with nothing on the desktop: apps are in the dock and the Apps face, content is reached through Library. Marketplace joins the default dock pins after Library so the way to get more is one click away. Only affects the first-run layout seed; saved layouts are untouched. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…ox and Chat Room The Home unified-sidebar chrome paints the traffic lights over the first 52px of the capsule frame. Library, Marketplace, System, People and Services already reserve that band; Documents, Inbox and Chat Room did not, so the lights sat on top of the first sidebar control (Documents' New button overlapped outright). Documents follows the Library convention (--window-chrome-safe-top, minus its own 0.75rem page inset). Inbox and Chat Room use a capsule-local 52px, matching System and the entropy gate's rule that those two keep capsule-local top padding only. Co-authored-by: Cursor <cursoragent@cursor.com>
…he column height Co-authored-by: Cursor <cursoragent@cursor.com>
…ge clock Brings the URUX lock face visual onto the Home host: ELASTOS wordmark, wallpaper as a full-bleed ground with a vignette, date and clock at their intended size, compact avatar with the name beneath. Two defects in the existing face go away with it: the generic `.home-unlock p` rule outranked `.home-unlock-date/-time` so the clock rendered at 13px grey, and the picker-flow entrance animation left a transform on the face, making it the containing block for the fixed ground and clipping the wallpaper to a centred column. Date/time rules are now scoped under .home-unlock and the entrance animates the brand/clock/account instead of the face. No behaviour change: shell-auth.js, the explicit-click passkey flow, and the person/person-name ordering are as before; no account directory. Co-authored-by: Cursor <cursoragent@cursor.com>
Brings the URUX Documents look onto the 0.7.1 Documents: flat 220px sidebar that owns the traffic-light safe-top, compact round New button with a pill search beside it, flat main pane, segmented Write/Split/Read control, uniform toolbar sizing. No cards inside a padded page. Only the <style> block changes. Markup and script are the 0.7.1 ones (26 Aug refine, 30 Aug save-or-discard and preview fixes), so behaviour is unchanged; the five newer classes (toolbar-group, workspace-toggle, workspace-tab, find-actions, find-highlight) are styled to match. Tokens keep the canonical shared-sheet mappings the entropy gate requires; the URUX literal palette values are not carried over. Co-authored-by: Cursor <cursoragent@cursor.com>
The toolbar "…" menu already carries New ▸ Folder / Text Document, Upload Here, Paste, Sort By, View, Refresh, Show Hidden and Properties, and the toolbar already hides the Sort select and Refresh button in its favour. The New folder and Upload buttons now follow the same rule, so the toolbar is navigation, breadcrumbs, search, view toggle and the menu. One line in syncToolbarChrome; the buttons and their handlers remain for the picker/attach flows and the existing tests. Co-authored-by: Cursor <cursoragent@cursor.com>
…ive reorder The idle pill is width:max-content, which no browser can interpolate, so the declared width transition never ran: the dock jumped on every pin, unpin, launch and Apps open. Width changes are now a pixel FLIP (lock, reflow, ease, unlock), with transitions suppressed on the lock flush so the base transition cannot start and be reversed at 0% into an instant jump. The Apps face reveal is height-led (420ms ease-out, opacity only guards the first frames) and the pill's width eases in step, so the one Shelf-face state reads as the pill growing up rather than a fade over a snapped box. Dragging over the dock reorders live: a dock-sized spacer holds the slot, the other pins FLIP around it, a dragged pin parks, and the pill eases as the slot opens and closes. Nothing commits until drop; the never-silent-unpin rule and the drop rules are unchanged. The smoke's fake style gains the two CSSOM methods (setProperty/removeProperty) the shell uses for inline custom props. Co-authored-by: Cursor <cursoragent@cursor.com>
The face no longer widens to a 720px popup: it locks to the dock's own width (min 320, set in px at open because the idle width is max-content) and uses denser 72px tiles, so it grows up out of the dock with nothing either side of the dock row. Motion timing moves to tokens — --shelf-face-ms 950ms, --shelf-face-ease ease-in-out, --dock-width-ms 780ms — the pill glides rather than pops. Gate bounds for the phone face are unchanged. Co-authored-by: Cursor <cursoragent@cursor.com>
…k row The launcher content rode up with the pill's top edge during the reveal (block launcher, popover shrinking to the growing max-height), so icons appeared to leave the dock and slide upward. The launcher is now a bottom- justified column, the popover keeps its full height, and the grid sinks to the dock row with an auto margin — the rising edge uncovers stationary icons first and the header last, and scrolling stays reachable when the grid overflows. Shelf pins live in the dock row directly under the face, so they are no longer duplicated in the grid; the open grid refreshes when pins change. Co-authored-by: Cursor <cursoragent@cursor.com>
… close Closing the face snapped the pill back to --taskbar-h while the launcher was still collapsing, so the dock row was pushed below the pill and rode back up — the "icons leave the dock and slide up" defect. The pill now sizes to content in both faces (min-height 72, symmetric padding), so it shrinks with the launcher and the row never moves. The reveal follows the Shelf cadence: the pill grows up as empty glass (height only, width locked) and the content fades in where it lives at 82% of the stretch (header, then grid); closing lets the content leave first (140ms), then collapses. Grid returns to the top; the grid/row gap and tile density live in rules that do not flip with the face class, so nothing reflows on the first close frame. Co-authored-by: Cursor <cursoragent@cursor.com>
… pill The first taskbar render on load eased the pill width from the empty pill, so every icon slid in from outside it. Width easing now only runs between two populated docks. For pin and running-set changes, icons already on the dock start where they were and glide to their new slot in step with the pill's edges (per-slot FLIP, same duration and ease), so none is ever outside the pill; an icon new to the dock settles into its slot once the pill has made room. Co-authored-by: Cursor <cursoragent@cursor.com>
Every first-party provider capsule now declares `"icon": "icons"` and ships its own icon-32/64/128/256 set, exactly like app, viewer and content capsules do. The catalog read model already published declared icon routes for any role; two things kept them from reaching the Store: - the gateway only served declared icon variants for content/data capsules. Providers never serve a browser document, so extend the same declared-only allowlist to the provider role. Manifest, rootfs and the capsule root stay 404. - source-home install materialized only `capsule.json` for provider contracts. Copy the declared icon set beside it (all four sizes required, no traversal). Marketplace and Services render the icons through the existing `iconVariants` read model; no name→icon map, no provider names in app source. Tests: declared provider icons servable and nothing else; all eleven service manifests validate, declare `icons`, and ship the four rasters. Co-authored-by: Cursor <cursoragent@cursor.com>
… model attribution The Home Agent capsule needs two things from the Runtime and nothing else. Workspace: GET/PUT /api/apps/home-agent/workspace behind the capsule's launch token. The document is an opaque, bounded JSON value (size and depth capped), revisioned with if_revision so a stale writer gets 409 and never overwrites, written as a principal-root protected object (ciphertext at rest, declared for recovery) and isolated per principal. Mirrors the Assistant workspace route. Model proxy: home-agent joins the capsules allowed to call the typed model contract (offers_list, runs_create, runs_events, runs_cancel). Runs are bound and audited to the calling capsule id taken from the launch token's executable actor, instead of the previous hardcoded "assistant". Tests: absent-get is read-only at revision 0; round trip and restart preserve the exact document; wrong capsule is 403 and principals stay isolated; stale and future revisions fail without mutation; malformed requests fail closed; the object is declared for recovery and stored as ciphertext; a home-agent run binds and audits to "home-agent". Co-authored-by: Cursor <cursoragent@cursor.com>
…ent Space
Home GUI owns the motion and the place, nothing else. The Shelf pill grows
into a composer face (FLIP in pixels — CSS cannot interpolate max-content →
fixed width), the Home surface breathes down and the Agent Space rises as a
stage the pager knows about. The room itself is the home-agent capsule in an
opaque-sandboxed frame, launched like the Wallet rail through launchHomeTarget.
The frame is reached only by postMessage with the sender pinned to the frame
window:
Home → capsule home-agent:open | home-agent:shelf-handover {on} | home-agent:close
capsule → Home home-agent:ready | home-agent:shelf-metrics {width,height,radius}
home-agent:close | home-agent:open-viewer
Home never reads the frame's DOM; the capsule never reaches Home's.
Co-authored-by: Cursor <cursoragent@cursor.com>
…model contract
The URUX agent harness — sessions, projects, transcript with thinking blocks
and progress, markdown and math, edit / delete / regenerate, follow-up queue,
attachments, dictation — lifted as the home-agent capsule with its visual
fidelity intact, and with everything the Runtime does not back removed.
Inference is the typed model contract or nothing. offers_list decides what
the model menu and Settings › Models show; a turn is runs_create with
elastos.model.input.text/v1 {prompt}, polled by runs_events after_sequence,
stopped with runs_cancel. No offer, provider or model is named in source.
When no offer is advertised the harness says so; it never answers for the
model. The model chosen in the menu is the one the run uses and it persists.
State the Runtime backs lives in the capsule's workspace object (revisioned,
principal-root protected): sessions, projects, prompt, notes, context budget,
thinking visibility, chosen offer, live usage ledger. No browser storage.
Removed because nothing behind them was real on this Runtime: the mock
provider and its seeded replies, tool grants and the Inbox grant cards
(library.read / web.search / wallet.sign routes do not exist here), the
approval-mode chip, Chat/Build segment, Workbench rail (outputs, plan, diff,
browser, terminal), Studio, Usage, model catalog with Get / Mine / hardware
estimate, Settings › Overview / Machine / Tools / Runtime / Permissions,
temperature and reasoning-effort controls (the typed input has no sampling
knobs), the preview banner and every "preview"/"mock" line of copy.
Also fixes session menu state that was undeclared after the capsule split
(opening a chat's "…" menu threw a ReferenceError).
Co-authored-by: Cursor <cursoragent@cursor.com>
…and the seam node scripts/home-agent-shell-smoke.mjs, wired into `just verify`. Asserts in source that no offer is named, no browser storage or provider ping is used, no removed module or absent route is imported or called, no mock reply path exists, the workspace client reads before it writes and reloads on 409, the gateway route is principal-root protected and capsule-bound, index.html carries no theatre surface or preview copy, Settings offers only what the Runtime backs, and Home is reached by message only. Exercises the pure model-contract module (offer eligibility, transcript prompt, run body, after_sequence page reduction and its failure modes) directly. Co-authored-by: Cursor <cursoragent@cursor.com>
CI lint on PR #58 failed under Rust 1.91 clippy with -D warnings: extracted_bundle_cache_stale_reason guarded with `if extract_path.is_none() { return None; }`, which the question_mark lint rewrites as `extract_path.as_ref()?;`. Same behaviour, lint-clean.
irzhywau
marked this pull request as ready for review
September 8, 2026 10:05
This was referenced Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this is
The 0.7.1 integration branch: the two open 0.7.1 feature lines brought together on
upstream/0.7.1-dev, plus the cross-cutting fixes that only appear once they runside by side, and the docs that record the resulting 0.7.1 truth.
Base is
upstream/0.7.1-devatc511b133. The branch is 34 commits ahead and0 behind, so it needs no rebase.
What it includes
Protected-content installed provisioning — merged from
feat/protected-content-installed-provisioning(#52), which sits on the reviewedprotected-content stack. Provisions installed custody and chain prerequisites,
documents the operator surface, and verifies custody-node provisioning through
the installed provider.
Home 0.7.1 first-run seed and chrome — merged from
feat/home-first-run-seed-0.7.1(#54). First run seeds an empty desktop withMarketplace pinned, plus the lock face, the flat Documents layout, the Library
toolbar menu, dock motion and the Apps face, and service capsules owning their
own Marketplace icons. Two follow-ups live only here, because they were found
while integrating: restoring the first-run hint and its CSS spacing, and
packaging provider capsule metadata in setup.
Home Agent on the typed model contract — the four commits of
feat/home-shelf-assistant-face-0.7.1(#55), rebased rather than merged. TheShelf morphs into the Agent composer and opens the Agent Space, the agent harness
becomes its own capsule, the Home Agent capsule gets a workspace object and its
own model attribution, and a capsule gate covers the typed contract, the
workspace and the seam. Content is equivalent to #55; only the ancestry differs,
so #55 will not auto-close and should be closed by hand once this lands.
Integration-only work
These commits exist on this branch alone. They are the cost of putting the three
lines together, and they are what makes the candidate hold up as one build.
bindirectory, so a providerfound at development time is still found once installed.
the agent harness and the Home shell agree on the seam instead of relying on
window shape.
Agent shell smoke and the Home regression smoke.
object-providerlockfile is refreshed after provisioning.question_markfix insetup.rs, which was the CI lint failure onthis branch.
Docs
state.mdandTASKS.mdare brought to the 0.7.1 development and acceptancetruth, and
AGENTS.mdis aligned with it. The superseded protected-contentjourney plan is removed.
docs/MODEL_PROVIDER.mdis added: it defines the modelprovider authority boundary, inference placement and delivery, and separates
model responses from agent execution, which is the contract the Home Agent
capsule is written against.
Review notes
#52,#54and#55feed this branch;#51promotesupstream/0.7.1-devtomainafter it.home-agententry inscripts/local-carrier-setup-smoke.shwas dropped duringthe rebase and re-added by the capsule-handoff fix, so nothing is missing at
this tip.
lintandsource-gatefor the tip commit.