Skip to content

feat(desktop): add scoped memory workflow preview - #1663

Draft
knqiufan wants to merge 30 commits into
oceanbase:masterfrom
knqiufan:codex/desktop-preview
Draft

knqiufan wants to merge 30 commits into
oceanbase:masterfrom
knqiufan:codex/desktop-preview

Conversation

@knqiufan

@knqiufan knqiufan commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Problem and result

PowerContext has no packaged desktop workflow for connecting to an existing Server and saving or reading scoped memories. This adds an internal unsigned Windows preview with explicit connection activation, exact Scope selection, plaintext notes, bounded FTS search and exact-version reading/copying. It remains a draft: S2/S3 implementation and substantial acceptance evidence exist, but complete S4 qualification is not achieved.

Refs #1654, RFC #1455 and #1428. This PR does not close those issues.

Changes

  • Independent pinned Tauri 2 + React/TypeScript workspace with Chinese/English messages and themes; no Server, Agent or model credentials are required merely to launch the installed shell.

  • Atomic secret-free profiles, native Windows vault or explicit session credentials, endpoint/trust invalidation, generation-based read cancellation and explicit compatibility selection.

  • Generated OpenAPI operation/schema bindings and Rust-derived IPC types. Native HTTP validates TLS/CA and proxy prefixes, permits HTTP only for literal loopback, disables inherited proxies/redirects and enforces response/time/concurrency limits.

  • Shared note form with raw UTF-8 budget, immutable dispatch target, nullable-entry success and unknown-result handling without automatic replay or offline bodies. Search is FTS/limit 10; reading uses the complete citation and clears old content on failure.

  • Opt-in local diagnostics verify a registered executable digest and exact version before fixed commands; safe status projection and Windows Job containment isolate owned helper processes.

  • Windows CI runs frontend/native/contract checks, real SQLite Server and CLI fixtures, process/vault probes, unsigned NSIS build and Chinese-path install/uninstall; it uploads the package and reports.

No public backend API/schema changes, database migrations, service management or Agent configuration changes are included.

Validation and evidence

  • Frontend lint/typecheck/build and 20 UI tests passed locally; native fmt/clippy/tests, IPC/OpenAPI drift checks, credential and process-containment probes passed at the documented checkpoints.

  • Four real no-model SQLite modes pass locally: anonymous HTTP, Bearer HTTP, HTTPS/CA/proxy-prefix and injected-provider/enforced-access. Tests cover save/search/exact read, normalization, 0/1/10 hits, changed-identity invalidation, same-identity binding revocation, and historical citations.

  • Real committed writes with truncated responses produce Unknown, a single request and one recoverable entry without replay. Real Scope paging returns 51 same-title IDs as 50+1 without omissions/duplicates or changing the active Scope.

  • Local installed release completed Chinese-path installation, anonymous save/search/exact reading and body/reference clipboard verification. Independent reads/writes succeeded after normal window exit. Exact package/binary digests and the narrow zoom observation are recorded.

  • API/JS generation checks and 48 contract tests passed. Repository pre-commit hooks pass except the existing Windows ty diagnostics; dependency-lock and immutable Actions-reference checks pass.

  • Run 35449492968 passed every step for a076db49; downloaded package hash/size matched its report. Verified run 35450188376 for 36531a64 passed every step. Its downloaded four-mode report verifies response loss, same-identity revocation and 51-item pagination. The unsigned installer is 2582147 bytes, SHA-256 F30E1F6693A420522D322D509A3170EC34B482E69BA0FF0EE1AFD170A5263A3C, independently verified; install/uninstall exited 0 and the external sentinel survived. This hosted-runner result does not qualify clean Windows 11 or interactive accessibility.

Evidence is itemized in desktop/evidence/S1.md, S2.md, S3.md and S4.md, including all T-01–T-29 and S4-01–S4-07. Historical package identities are not attributed to later builds. English/Chinese READMEs cover development and installed startup, connection/Scope selection, compatibility, errors, data ownership and uninstall boundaries.

All upstream checks at the verified Desktop checkpoint 36531a64 are successful, including the upstream Windows build and Python regression matrix. This does not change the qualification gaps below.

The installed UI harness now passes on an actual packaged WebView2. Run 35455040338 used harness e98ff6b9 with the exact a12d36db installer (2,579,502 bytes, SHA-256 B48557AB2C65A85DA14DD138DC2D749E397BCDECF96FAE2262B5886E2E4685A6, independently verified). It passed explicit connection/compatibility activation, exact Scope selection, Chinese multiline save, FTS, exact reading, independent Server read and clipboard body/citation paste-back comparison. Installation/uninstallation returned 0 and the external synthetic sentinel survived. Reports and the screenshot are in that run's desktop-installed-diagnostics artifact.

Earlier launch-timeout diagnostics showed that the app and renderer were actually responsive and rendered the home page, but elevated WebView2 ignored environment debugging flags. A temporary machine policy now enables loopback debugging for this executable only on the disposable runner and restores the previous value afterward; product configuration is unchanged. Upstream Linux quality also passes after the Windows process flag received a platform guard. Full build run 35455039808 passed all applicable steps for e98ff6b9, including installed save/search/read/clipboard acceptance. Its unsigned installer is 2,580,890 bytes, SHA-256 F85CDADF914542EC4AE4135FD06238A09F9CA90F856D7CA019B426C0751E5E1C, independently verified against the downloaded artifact; install/uninstall returned 0 and the external sentinel survived. The manual-only installed-package job is intentionally skipped in this full build. No clean Windows 11 or complete S4 qualification is claimed.

Checkpoint 94c45bb6 adds installed two-Server switching, disconnect/reconnect, inactive-profile removal, Enter-without-submit, and committed-response-loss acceptance. All these extensions passed exact-package run 35455969549, reusing the verified e98ff6b9 installer. Its downloaded report confirms all ten workflow assertions, matching installed executable/package digests, install/uninstall exit 0 and preserved external sentinel. This includes independent reads of both Servers after inactive-profile removal and exactly one committed request after response loss. The intermediate full build for 94c45bb6 was superseded by the next test commit and is not credited as passed. Checkpoint c4e298b2 records the installed forced-exit acceptance. Diagnostic run 35456351561 passed using harness fd10d9d6 and the verified e98ff6b9 installer. After the real UI saved/read a synthetic note, the harness killed only its owned Desktop process (exit 1); the independent Server remained ready, served the original exact citation, and accepted a new write verified by exact read. The report also confirms the explicit new-write confirmation after the preceding unknown result. The initial lifecycle diagnostic stopped at that expected confirmation; the harness now verifies and accepts its exact localized text. Windows/Linux script types and Ruff pass. The localized-string lint correction is included in the current head. Repository hooks still reproduce the same seven Windows backend type errors and three CLI warnings described below.

Current head 1291157c adds installed UTF-8 budget, empty/capped-ten search and unsaved-draft disconnect confirmation/cancellation tests. Static checks pass on Windows/Linux. Diagnostic run 35456586901 and full build 35456586574 are pending; intermediate builds superseded by new pushes are not credited as passed. Successful full build 35455039808 and exact-package diagnostics retain their own source identities.

Remaining qualification

Clean standard-user Windows 11 with WebView2 absent/present and no Python/Server; complete installed A/B/authentication/recovery interactions; external HTTPS deployment; actual IME, screen reader, high contrast, exact 800×600/200% and keyboard acceptance; standard-user/external-deployment exit and real-database uninstall preservation; generic notification cold activation; named/versioned Agent capture/recall and independent login/service evidence; accepted maintenance/signing owners; publisher signature; and complete startup/process-tree resource/performance budgets remain open. Exact synthetic-marker scans are bounded observations, not comprehensive privacy proof.

Desktop's current backend baseline still has seven Windows worker type errors plus three CLI deprecation warnings. The overlapping fix in PR #1676 has been withdrawn in favor of the existing community contributor on #1658. Its reproduction and validation remain optional reference material; it is not merged or included here. Desktop continues to track #1658 as an unresolved prerequisite and will validate the community fix when available. The three unrelated warnings remain unsuppressed. Green unit tests do not satisfy the remaining product gates.

AI usage statement

Implemented and validated with OpenAI Codex (GPT-6), under user-directed scope and recorded tool/test evidence. Maintainer review and outstanding product qualification remain required.

@knqiufan knqiufan changed the title feat(desktop): add S1 native foundation and Windows CI feat(desktop): add native connections and diagnostics preview Sep 19, 2026
@knqiufan knqiufan changed the title feat(desktop): add native connections and diagnostics preview feat(desktop): add scoped memory workflow preview Sep 19, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants