Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
56 commits
Select commit Hold shift + click to select a range
1293cc6
docs: reserve Gate 13 replacement run
flujo-app Aug 31, 2026
eb54b2b
docs: bind Gate 13 route runtime
flujo-app Aug 31, 2026
2c4f941
docs: bind Gate 13 client IAP access
flujo-app Aug 31, 2026
ddfb7c6
gate13: add durable run state contract
flujo-app Aug 31, 2026
bdaea0e
docs: record Gate 13 failed durable-run attempt
flujo-app Aug 31, 2026
2fe0de9
gate13: add durable native host jobs
flujo-app Aug 31, 2026
0e16ac2
gate13: close native job binding gaps
flujo-app Aug 31, 2026
1d30e3d
docs: record Gate 13 durable host prerequisite
flujo-app Aug 31, 2026
ee0c05f
gate13: bind actions to live budget reservation
flujo-app Aug 31, 2026
c1e1f86
docs: authorize straightforward Gate 13 retry
flujo-app Aug 31, 2026
0dc2345
docs: reserve Gate 13 retry after clean pre-VM failure
flujo-app Aug 31, 2026
1a65096
docs: reserve direct Gate 13 completion run
flujo-app Aug 31, 2026
3a1d1fc
gate13: make Windows host job headless
flujo-app Aug 31, 2026
7ee3c58
docs: authorize Gate 13 Windows supervisor repair
flujo-app Aug 31, 2026
56a96ea
docs: retire failed Gate 13 run d
flujo-app Aug 31, 2026
0f481d7
gate13: keep route setup reusable
flujo-app Aug 31, 2026
a561c58
docs: reserve corrected Gate 13 run e
flujo-app Aug 31, 2026
e547e2b
docs: move Gate 13 route to available zone
flujo-app Aug 31, 2026
6b27858
docs: keep Gate 13 resources in available zone
flujo-app Aug 31, 2026
2b895f5
gate13: retain bounded Windows failure phase
flujo-app Aug 31, 2026
6feb635
docs: authorize direct Gate 13 completion run
flujo-app Aug 31, 2026
8c56fec
gate13: preserve Windows user runtime environment
flujo-app Sep 1, 2026
4a1237e
docs: authorize corrected Gate 13 run
flujo-app Sep 1, 2026
0c67f0b
docs: retire incomplete Gate 13 staging run
flujo-app Sep 1, 2026
a7aabcc
docs: authorize complete Gate 13 staging run
flujo-app Sep 1, 2026
9ad67da
test: bind Gate 13 fixture to its ledger row
flujo-app Sep 1, 2026
805a1a5
docs: authorize manual Gate 13 completion run
flujo-app Sep 1, 2026
f1dc3a0
fix: support long Windows model cache paths
flujo-app Sep 1, 2026
d03826c
docs: complete Gate 13 manual qualification
flujo-app Sep 1, 2026
1476d67
test: automate Gate 13 desktop replay
flujo-app Sep 1, 2026
905cabd
ops: bind automated Gate 13 cloud replay
flujo-app Sep 1, 2026
1971f60
docs: authorize automated Gate 13 cloud replay
flujo-app Sep 1, 2026
d5dc353
gate13: replay inside native desktop sessions
flujo-app Sep 1, 2026
80ea591
docs: bind Gate 13 desktop session replay
flujo-app Sep 1, 2026
389661c
gate13: support Windows startup PowerShell crypto
flujo-app Sep 1, 2026
2fa2e89
docs: bind Windows bootstrap compatibility fix
flujo-app Sep 1, 2026
5f1eef1
gate13: restore Windows SSH after provisioning reboot
flujo-app Sep 1, 2026
dbf09b8
docs: bind Windows reboot service recovery
flujo-app Sep 1, 2026
e60c357
gate13: replay exact one-token inference
flujo-app Sep 1, 2026
01e3918
docs: bind one-token Gate 13 packages
flujo-app Sep 1, 2026
d957aac
gate13: replay proven CPU sharing policy
flujo-app Sep 1, 2026
cd3e347
gate13: replay exact manual desktop sequences
flujo-app Sep 2, 2026
2381226
gate13: match route fence to live API schema
flujo-app Sep 2, 2026
9258ef2
gate13: bind exact paid replay inputs
flujo-app Sep 2, 2026
5b0453d
gate13: make Windows bootstrap membership idempotent
flujo-app Sep 2, 2026
05fbe4f
gate13: replay manual inference recovery
flujo-app Sep 2, 2026
62b0dc3
gate13: clear replay CI blockers
flujo-app Sep 2, 2026
984aef3
gate13: show sharing page before UI actions
flujo-app Sep 2, 2026
e904d36
gate13: normalize automatic sharing before start
flujo-app Sep 2, 2026
b093b85
gate13: allow bounded GPU route restarts
flujo-app Sep 2, 2026
66f440b
gate13: retry stale route advertisements
flujo-app Sep 2, 2026
4c6eaca
gate13: accept fresh Linux supervisor inventory
flujo-app Sep 2, 2026
9c9a4ac
docs: record automated Gate 13 cloud pass
flujo-app Sep 2, 2026
b03ef94
docs: restore machine-readable spend ledger
flujo-app Sep 2, 2026
c0f2342
gate14: bind hardware qualification lifecycle
flujo-app Sep 2, 2026
a813ef1
docs: record Gate 14 software preflight
flujo-app Sep 2, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
44 changes: 44 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,50 @@ and qualification evidence remains in `docs/REVIVAL_TEST_RESULTS.md`.

### Added

- Gate 14 hardware acceptance now has a fail-closed, source-bound verifier and durable GCP
lifecycle controller. They pin the exact Gate 13 packaged lifecycle and Windows/Qwen plus
Linux/Gemma Gate 9 envelopes, enforce the USD 100 aggregate ledger ceiling, serialize fresh
L4 hosts, bind host-reported evidence before collection, and require cleanup proof for the
exact authorization bytes, controller source, provider plan, project, zone, resources,
and successful terminal state while excluding the protected bootstrap from cleanup targets.
The focused 49-test suite covers deadline, rollback, orphan/returned-resource inventory, forged-state,
evidence-substitution, cross-platform, hidden/excess spend, and cleanup-binding failures. Exact source
`c0f2342e15aa7e12ca7c2980deca64d613204143` passed independent adversarial review, CodeQL,
style, Linux/Windows tests, and production-package provenance verification. A native read-only GCP
preflight stopped before inventory or quota inspection because the configured account requires
interactive reauthentication; no reservation or resource was created, so the current-epoch USD 44
remainder is intact. This is software and package evidence only: no Gate 14 hardware pass is claimed yet.
- Gate 13's successful manual desktop flow now has a bounded automated replay. The
production package can open its real Qt window in a hidden qualification mode, perform
localhost inference, save the actual sharing-policy dialog, click Start, exit, relaunch,
prove sharing resumed, click Pause, and infer again without retaining prompt, response,
credential, endpoint, or path data. A standard-library outer runner verifies the exact
production archive, runs all four packaged self-tests, executes both sessions, validates
canonical evidence, and removes its run temporaries. The durable host-job boundary now
accepts the Python replay entrypoint on Windows and Linux. Local real-window and contract
tests pass; no paid clean-host replay or new release artifact is claimed by this change.
- The owner raised the current combined GCP/Fly public-alpha accounting epoch to USD 500 on
2026-08-31. The existing USD 52 committed maximum remains charged. Run
`gate13-20260831-b` reserved USD 56 but failed before VM creation when its two IAP tags reached
gcloud as one value; exact cleanup passed. Fresh run `gate13-20260831-c` reserves USD 56 with
corrected explicit tag arguments, leaving USD 336. Per-run preflight, hard deadlines, exact
cleanup, protected-resource, and evidence requirements are unchanged.
- Gate 13 paid qualification now has durable source-bound native host jobs: an exact-current-user
Windows Scheduled Task and a non-root transient Linux systemd service persist one attempt across
operator disconnects, bound output, terminate the complete process tree on timeout or overflow,
revalidate canonical lifecycle evidence before collection, and never re-arm consumed route or
client intents. Exact Windows lifecycle-config co-location and full Linux `ExecStart` structure
matching close the final independent-review gaps. Source `0e16ac2` passes the 217-test Gate 13 and
desktop matrix independently. This is a software prerequisite only: it created no cloud resources,
authorizes no paid run, and does not claim a completed clean-host lifecycle or Gate 13 pass.
- Gate 13 paid qualification now has a persisted authorization-bound run-state contract that
inventories exact resources before every transition, accepts the product route before any
client, runs Windows/Qwen before Linux/Gemma, permanently consumes a failed or ambiguous
lifecycle host, rejects stale/foreign/deadline-expired observations, validates digest-bound
canonical 16-phase records, and permits a pass only after both records and exact provider
absence. The failed `gate13-20260831-a` attempt is cleanup-proved: its route, clients, disks,
and firewalls are absent while the protected bootstrap remains running. No lifecycle pass is
claimed, and the run's USD 52 maximum remains committed in the current budget epoch.
- Gate 13 packaged-lifecycle prerequisites now emit deterministic self-contained Windows ZIP
and Linux tar.gz archives, preserve or reject platform filesystem semantics fail-closed, and
bind the archive plus strict desktop metrics into exact-type release provenance. The local
Expand Down
2 changes: 2 additions & 0 deletions desktop/build_desktop.py
Original file line number Diff line number Diff line change
Expand Up @@ -1269,6 +1269,8 @@ def main() -> int:
str(build_root / "spec"),
"--hidden-import",
"communityai_desktop.pyside_shell",
"--hidden-import",
"communityai_desktop.gate13_playthrough",
"--add-data",
f"{icon_path}{os.pathsep}communityai_desktop/assets",
]
Expand Down
4 changes: 3 additions & 1 deletion desktop/src/communityai_desktop/acceptance.py
Original file line number Diff line number Diff line change
Expand Up @@ -308,8 +308,10 @@ def do_DELETE(self): # noqa: N802


@contextmanager
def fake_node() -> Iterator[Tuple[str, str]]:
def fake_node(*, all_workers_paused: bool = False) -> Iterator[Tuple[str, str]]:
state = _FakeNodeState()
if all_workers_paused:
state.worker_states = {worker_id: (model, "paused") for worker_id, (model, _) in state.worker_states.items()}
server = ThreadingHTTPServer(("127.0.0.1", 0), _handler(state))
thread = threading.Thread(target=server.serve_forever, name="desktop-acceptance-node", daemon=True)
thread.start()
Expand Down
19 changes: 19 additions & 0 deletions desktop/src/communityai_desktop/app.py
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,8 @@ def build_parser() -> argparse.ArgumentParser:
parser.add_argument("--no-manage-node", action="store_true", help=argparse.SUPPRESS)
parser.add_argument(LOGIN_STARTUP_FLAG, action="store_true", help=argparse.SUPPRESS)
parser.add_argument("--capture-page", type=int, default=0, help=argparse.SUPPRESS)
parser.add_argument("--gate13-ui-evidence", type=Path, help=argparse.SUPPRESS)
parser.add_argument("--gate13-ui-screenshot", type=Path, help=argparse.SUPPRESS)
action = parser.add_mutually_exclusive_group()
action.add_argument("--store-control-key", action="store_true")
action.add_argument("--delete-control-key", action="store_true")
Expand All @@ -53,6 +55,7 @@ def build_parser() -> argparse.ArgumentParser:
action.add_argument("--onboarding-ui-self-test", action="store_true", help=argparse.SUPPRESS)
action.add_argument("--capture-ui", type=Path, help=argparse.SUPPRESS)
action.add_argument("--probe-only", action="store_true", help=argparse.SUPPRESS)
action.add_argument("--gate13-ui-playthrough", type=Path, help=argparse.SUPPRESS)
return parser


Expand All @@ -69,6 +72,11 @@ def _write_json(value: Any) -> None:
def main(argv: Optional[Sequence[str]] = None) -> int:
parser = build_parser()
args = parser.parse_args(argv)
if args.gate13_ui_playthrough is None:
if args.gate13_ui_evidence is not None or args.gate13_ui_screenshot is not None:
parser.error("Gate 13 evidence options require --gate13-ui-playthrough")
elif args.gate13_ui_evidence is None:
parser.error("--gate13-ui-playthrough requires --gate13-ui-evidence")
try:
if args.self_test:
_write_json(run_self_test())
Expand Down Expand Up @@ -150,6 +158,16 @@ def connect() -> DesktopController:
token = credential_store.get_or_migrate()
return DesktopController(NodeClient(node_url, token, timeout=args.timeout))

qualification_automation = None
if args.gate13_ui_playthrough is not None:
from communityai_desktop.gate13_playthrough import Gate13Playthrough, PlaythroughPlan

qualification_automation = Gate13Playthrough(
PlaythroughPlan.load(args.gate13_ui_playthrough),
args.gate13_ui_evidence,
screenshot_path=args.gate13_ui_screenshot,
)

if args.probe_only:
try:
_write_json(connect().snapshot())
Expand All @@ -169,6 +187,7 @@ def connect() -> DesktopController:
start_minimized=args.started_at_login,
activate_existing_instance=not args.started_at_login,
before_termination_restore=None if lifecycle is None else lifecycle.close,
qualification_automation=qualification_automation,
)
or 0
)
Expand Down
Loading
Loading