Skip to content

Origin flip: framed app + connections bridge + vendored pin move to the service origin and stock v1.18.29 (#823) - #840

Merged
aarontrowbridge merged 3 commits into
mainfrom
823-origin-flip
Sep 6, 2026
Merged

aarontrowbridge merged 3 commits into
mainfrom
823-origin-flip

Conversation

@aarontrowbridge

Copy link
Copy Markdown
Member

Implements #823 — the M3 cutover the #822 app-shelf service was built for.

In this commit (slice 1 of the branch):

  • Bootstrap seam — the service parses the engine's ?auth_token= carrier (GET-only, query-preferred, both mints — engine-middleware parity) and ports the fork's public-UI exemptions (GET /assets/*, manifest, /amicode/widget-frame), so a real browser iframe can bootstrap + load the framed app from the shelf.
  • Consumer flip — frameOriginUrl (service origin wins; engine origin the honest degraded fallback) drives every chat-panel / deck-pane call site; the connections bridge follows the framed origin (routes native on the service); the cloud-key fallback submit targets the service.
  • Vendored pin flip — opencode.lock.json → stock canonical anomalyco/opencode v1.18.29, sha256s recorded from the real release assets (sizes match the release), ref = the tag's upstream commit.
  • Parity-fixture self-tracking flips to the frozen fork record — stock serves no /amicode/* (M0 gate (a)), so parity re-recording from the new pin is structurally impossible; the goldens stay pinned at the last fork pin (v1.18.10-amicode.21) as the service's regression record.
  • Parallel-run language retired — the service is the framed origin now, not a second harness.

Gate evidence so far: workspace typecheck clean; extension suite 2494 passed / 0 failed (vitest), amico-run 1441 passed / 0 failed. Two environmental exclusions, both verified pre-existing by unsetting the leaked host env (OPENCODE_DB / OPENCODE_CONFIG_CONTENT — this dev shell runs inside Amicode's own host env) and one fresh-worktree artifact fixed by pnpm -r build (the gitignored staged CLI gh shim).

Still landing on this branch: the boot-proof extension (document GET via ?auth_token=, anonymous assets, framed SSE) + the live end-to-end proof against the stock v1.18.29 binary, the assert_ui_gate check against the stock binary, and the fixture/recorder header notes.

…ip, stock pin

- bootstrap seam: the service parses the engine's ?auth_token= carrier
  (GET-only, query-preferred, both mints — mirroring the engine's own
  middleware precedence) so the framed iframe document GET authenticates
  at the shelf; public-UI exemptions ported from the fork's public-ui.ts
  (GET /assets/*, the manifest, /amicode/widget-frame) for the anonymous
  sub-resources a browser cannot credential
- consumer flip: frameOriginUrl (service origin wins, engine origin the
  degraded fallback) drives every engine-origin UI consumer — chat panel
  open/adopt/new sites, deck panes, the fleet-client reveal, and the
  cloud-key connections submit now targets the service (its routes are
  native there; the stock engine serves none)
- vendored pin flip: opencode.lock.json names stock canonical
  anomalyco/opencode v1.18.29 (no fork repo/tag; sha256s recorded from
  the real release assets; ref = the tag's upstream commit)
- the parity-fixture self-tracking flips to the frozen fork record: the
  goldens stay pinned at v1.18.10-amicode.21 (stock serves no /amicode/*,
  so parity re-recording from the new pin is structurally impossible) and
  are the service's regression record now; the lock may not regress to
  the fork lineage
- parallel-run language retired: the service is the framed origin, not a
  second harness; wiring log line + comments updated honestly
@coderabbitai

coderabbitai Bot commented Sep 6, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

- boot probe gains the two flip-specific surfaces: the iframe bootstrap
  (document GET via the engine's ?auth_token= carrier, NO header — the
  framed carriage) and an anonymous /assets/* fetch (the browser
  sub-resource constraint the public-UI exemption exists for)
- LIVE proof run against the stock v1.18.29 vendored engine + the real
  built dist: all six surfaces PASS (app doc, bootstrap, anonymous asset,
  proxied engine API, proxied SSE, /amicode/* route)
- assert_ui_gate re-based for the cutover: the framed app comes from the
  shelf now, so 'the engine's embedded UI shows amicode surfaces' is no
  longer an invariant (and stock's minified shape matches none of the
  fork-era patterns). The engine's invariants now: --version equals the
  lock's pin, and the auth_token carrier machinery is present (the
  bootstrap seam's engine side). Tests re-recorded to the new contract.
- fixture recorder header carries the M3 freeze note (parity recording
  from the stock pin is structurally impossible; goldens stay pinned at
  the last fork tag as the service's regression record)
- boot-smoke verified PASS against the stock vendored binary (the CI lane
  vendors stock after the flip)
- .materialized/ (build:app's default work tree) gitignored
@aarontrowbridge

Copy link
Copy Markdown
Member Author

Slice 2 landed (6e64e65d) — the end-to-end proof against stock.

LIVE boot proof (the app-shelf-boot-proof lane's script, run for real): real service (esbuild-bundled from this branch) + real stock v1.18.29 vendored engine (.source: release anomalyco/opencode@v1.18.29, sha-verified) + real built app dist (build:app: materialize → bun install → vite build, 18 entries staged) — all six surfaces PASS:

[boot-probe] ✓ app document from the service origin (4327 bytes, not the placeholder)
[boot-probe] ✓ iframe bootstrap: document GET via ?auth_token= (no header) — the framed carriage
[boot-probe] ✓ anonymous asset fetch (GET /assets/LROKH5N7-B9MVhZqS.js) — the browser sub-resource constraint
[boot-probe] ✓ engine API call through the proxy (GET /session)
[boot-probe] ✓ SSE connect through the proxy (GET /event, first chunk delivered)
[boot-probe] ✓ /amicode/* route with the engine credential (GET /amicode/profile)

assert_ui_gate re-based for the cutover (a pin-dependent re-record the flip demanded): the framed app comes from the shelf now, so the engine's embedded UI showing amicode surfaces is no longer an invariant — and stock v1.18.29's minified newLayoutDesigns (a multi-branch upgrade-eligibility memo) matches none of the fork-era patterns. The gate now asserts what the ENGINE must guarantee: --version equals the lock's pin, and the auth_token carrier machinery (the bootstrap seam's engine side) is present. Unit tests re-recorded to the new contract.

Boot-smoke PASS against the stock vendored binary — the CI boot-smoke lane vendors stock after the flip and must stay green; verified locally.

Final gate evidence: workspace typecheck clean; schema 241, amico-run 1441, extension 2497 passed / 0 failed (vitest, stock binary vendored). Environmental exclusions documented with verification: host OPENCODE_DB/OPENCODE_CONFIG_CONTENT leak (this dev shell runs inside Amicode's own host env — both files pass with the vars unset), and the fresh-worktree gitignored CLI gh shim (fixed by pnpm -r build). One landmine flagged for the director: overlay_sync.test.ts runs overlay-sync.mjs --apply against the local fork checkout's CURRENT branch, mutating the committed overlay on dev machines (CI skips — no fork clone); restored before each commit, nothing of it rides this PR.

… arch

The vsix-gate loops every platform's binary on one machine; executing a
foreign-arch binary exits 126 (Exec format error). Same-arch binaries get
the runtime version re-assertion; foreign-arch ones skip it honestly (the
sha256 download gate IS the cross-platform pin verification) while the
arch-independent auth_token carrier grep still applies to every binary.
Unit tests get a deterministic foreign-platform case (win32-x64 never
matches a runner mapping).
@aarontrowbridge

Copy link
Copy Markdown
Member Author

Slice 3 (d86975f7) — the vsix-gate fix — landed, and ALL 9 CI CHECKS GREEN on this branch now:

app-bundle-gate        pass
app-shelf-boot-proof   pass   (CI self-skips per #825 — the LIVE run is the local evidence above)
boot-smoke (macos-14 / ubuntu-24.04-arm / ubuntu-latest)  pass  ← vendoring STOCK v1.18.29 through the flipped lock
bundle-build-gate      pass
fast                   pass
schema-roundtrip       pass
vsix-gate              pass   ← the re-based gate across ALL THREE platform binaries

The vsix-gate red was mine and is fixed in-slice: the re-based assert_ui_gate executed --version, and the vsix-gate loops every platform's binary on one machine (foreign-arch exec → 126). Now: same-arch binaries get the runtime version re-assertion; foreign-arch ones skip it honestly (the sha256 download gate IS the cross-platform pin verification) while the arch-independent auth_token carrier grep applies to every binary. Local suite after the fix: 2498 passed / 0 failed.

Branch complete — ready for director gate + human merge. The fork-retirement blocker #2 is discharged pending this merge: the vendored pin is stock v1.18.29, every UI consumer frames the service origin, and the framed path is proven live against stock.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant