v0.1.23 — honest setup
Honest setup, end to end
nutshell setup now verifies every source with its real probe through the
Nutshell.app identity — "ready" is impossible without proof. Each source step
is one loop with three verbs: probe, retry (optionally opening the sign-in
page), or skip honestly. Re-running setup opens with a status table refreshed
by real probes and only walks what needs attention.
What was broken: setup previously marked every selected source "ready"
without verifying anything (the plugin setup hooks were no-ops), and the Full
Disk Access step ran after source verification instead of before it, so real
failures only surfaced later in doctor/sync with no guidance.
What changed in the shipped product:
- Every problem finding carries machine-readable guidance: a user-state
classification (needs_auth,needs_permission,blocked_bug, …), the
concrete fix, and the command that confirms it — rendered on every surface
(setup, doctor, health, sync output, dashboard) and enforced by a CI
invariant over every emittable finding code. - Setup: permission step before verification; probe/retry/skip loop;
re-run resume; honest per-source summary with comeback commands; a real
bounded smoke sync through the app identity (the old "initial sync handed
off" message was wording, not an action — it is gone). - Scheduler self-heals: a degraded source gets one bounded probe per scheduled
run; a passing probe flips it back to ready and syncs — sign in days later
and the next sync just works, no setup re-run. Rate limits back off. - Doctor: root-cause-first (app/FDA issues lead; permission symptoms collapse
into one line), source aliases (x,notes,podcast), and a no-argument
mode.syncprints a human summary with skipped-source fixes first. - Catch-all auth findings split one-code-one-state: keychain-blocked is
needs_permission, neverneeds_auth.
Validation status (split gates, verdict vocabulary per
docs/release-validation-gates.md): local certification suite passed
(typecheck, 238 tests incl. pty-driven golden journeys of the real interactive
setup, lint, builds, tarball, certify:release). Public-install gates run
against this artifact next; the permissions-post and live-sync gates are
queued on the one-time post-permission snapshot session. This release is
published, not yet fully gate-validated.
Install paths: Homebrew tap and tarball. The npm/Bun registry path is
deferred and not published. Dependency fence: unchanged. Reboot
persistence: covered by the final layer-4 rehearsal, queued.