refactor: route install commands through platform runtime - #1758
refactor: route install commands through platform runtime#1758thymikee wants to merge 20 commits into
Conversation
Size Report
Startup median (7 runs, lower is better):
Top changed chunks:
|
|
Adversarial review of exact head
All completed CI checks pass; iOS Smoke remains pending. Keep draft, rerun |
|
Reviewed exact head ab42b04. Changes requested. [P1] ADR 0019 defines the abandonment-safe migration unit as one command descriptor across its full denominator, with post-checkpoint units authorized and budgeted individually. This PR instead batches install, reinstall, install_source, and push behind one family route across 92 files. Please split these into independently reviewable descriptor units and rebase them onto the agreed current stack. The new R19-R22 allocation also precedes integration of the agreed selector R19/current stack, so it is not safe to land as-is. [P1] This device-facing cutover still has no live supported-path evidence for install, reinstall, source install, or push. Green CI does not exercise those production command routes. Each resulting unit needs practical evidence on its supported device/provider denominator, with cleanup recorded. [P2] The stack-base accounting removes 25,681 root source bytes but adds 42,549 package source bytes: +16,868 net source growth (+6,498 raw shipped, +1,742 gzip). That is exceptional rather than move-dominated and cannot be reviewed against ADR 0019 while four units share one after-the-fact budget. Record and obtain approval for each descriptor budget independently. The facts-first admission, single-bind operation routes, fail-closed behavior, and preservation tests otherwise look coherent, and exact-head CI is green. No ready label until the split, rebase, per-unit budget, and live evidence are complete. |
|
Coordinator allocation decision: preserve this as the single cohesive install/deploy family unit. The original tracker assignment and explicit coordination brief allocate The remaining valid readiness requirements still apply: exact-head adversarial rereview, unique rule IDs on the integrated catalog, honest per-route parity evidence, exceptional size justification for the cohesive facet, and practical supported-path live-device evidence or an explicitly accepted residual gap. Keep the PR draft. |
|
Addressed the exact-head findings at
The later allocation decision supersedes the split request: this remains the one tracker-assigned install/deploy family facet. The PR stays draft while current CI/exact-head rereview, final rule-catalog integration, and supported-path live-device evidence or accepted residual remain outstanding. |
|
Exact-head rereview of
Also refresh the PR body’s exact-head size/test/rule evidence after the next correction. Cohesive family allocation remains valid; no split is required. Keep draft, run |
|
Addressed both remaining P1s at
Planted red before these corrections produced The PR remains draft. Exact-head rereview, current CI, final prerequisite/rule-catalog integration, exceptional cohesive-facet size approval, and supported-path live-device evidence or an accepted residual are still blockers; no real-app success is claimed. |
|
Re-reviewed exact head 81a00c8. The functional repair is sound: push and install_source expire ref frames immediately before dispatch while admission/materialization failures preserve them; stale WebDriver and Limrun sessions fail facts admission before bind or local fallback; Android reinstall restores whole-operation cache invalidation; and R20-R23 preserve the allocated selector R19. The coordinator decision also confirms this remains one cohesive install/deploy family unit, so no split is required. Exact-head CI is fully green and touched-file topology remains within limits. This is still not ready:
No ready-for-human label yet. |
|
Exact-head rereview of
Restore the prior capabilities behavior and retain only the narrow transitional projection required for this install/deploy family, or obtain an explicit capabilities-unit allocation. Do not claim or ship the global capabilities migration from #1758. Everything else now passes adversarial review: both expiry fixes, Android cache invalidation, provider fail-closed ownership, route shape, IDs, tier, and CI. Exceptional size still needs reviewer acceptance and live supported-path evidence remains absent. Keep draft and run |
|
Addressed the remaining scope P1 at
The sole transition retained here is intentionally narrow: one side-effect-free facts inspection projects only Planted-red evidence: before this repair, a test made The draft body now records the refreshed detached-worktree size comparison (+8,329 B raw / +2,191 B gzip / +2,008 B tarball / +8,329 B unpacked over |
|
CI triage for exact head The only failed lane is iOS Smoke’s unchanged XCTest I am not patching this iOS runner failure from the install/deploy unit. It needs the Apple runner owner or a rerun if classified as the existing simulator text-entry flake. All other reported checks on this head pass; the PR remains draft for this lane as well as the documented size and live-device blockers. |
|
Exact-head full audit of
Independently rerun/classify the unrelated red iOS Smoke test. Live supported-path evidence and exceptional size approval remain absent. Keep draft and run |
|
Reviewed exact head be45ac1. The global Still not ready:
Keep draft and do not apply the ready label. |
|
Addressed the full-audit findings at
|
|
Reviewed exact head e5a717f. The wide cross-family host is removed, local deployment sequencing now belongs to the platform packages, binding cancellation reaches simctl/devicectl, ADB/bundletool, and HDC, and the WebDriver runtime split is clean. Still not ready:
Keep draft and do not apply the ready label. |
|
Exact-head rereview of
The unrelated iOS longpress smoke rerun is still classifying. Live supported-path evidence and exceptional size approval remain absent. Keep draft and run |
|
Exact-head evidence update — this supersedes the prior current-head/size lines in the PR description. Head: Validation from one isolated, clean committed tree:
Fresh same-host detached-worktree size reports:
The current build emits 187 JS files / 279 packed files, versus boot's 179 / 271. This is still the exceptional cohesive-facet growth already called out in the PR, not a new dependency or durable resource; independent size-budget acceptance remains required. This PR remains draft. No merge/readiness claim: exact-head GitHub CI and rereview are pending; final replay/rule-catalog prerequisites #1740, #1745, #1747, #1744 (and transitive DIRTY #1750) remain blockers; and no supported real-app install/reinstall/source-install/push live-device success has been obtained. The prior simulator had no safe repository app fixture; physical devices were lock/trust/Developer-Mode blocked; Android was unavailable. The live-device residual and size exception must be accepted independently. |
|
Final rereview of
Exact-head CI is fully green, but body size/evidence is stale: CI is about +11.3k raw/+4.8k gzip/+3.2k tar/+11.3k unpacked; update after correction. No supported-path live evidence exists and exceptional growth remains unaccepted. Keep draft and run |
|
Reviewed exact head 18b0b96. The descriptor-drift finding is fixed: capability projection now derives the use from commandDescriptors, with the four-command set only bounding this migration. Obsolete high-level install wrappers are removed and Apple reinstall cache invalidation is restored; all exact-head CI, including iOS Smoke, is green. Two code findings remain. [P1] Provider cancellation is still incomplete: WebDriver upload/install has no binding AbortSignal, and Limrun applies the signal only to materialization while deployApp/deployMaterializedApp can continue after request cancellation. Thread cancellation through both provider operations and add in-flight abort regressions. [P2] Android deployment mechanics remain in the 889-line src/platforms/android/app-lifecycle.ts; extract the signal-aware install/uninstall/bundletool/package-inventory work into a focused deployment executor module rather than adding behavior to a >500 legacy file. Readiness also remains blocked by absent live supported-path success, unaccepted exceptional size, stale exact-head size/body accounting, and unresolved stack dependencies. No ready-for-human label. |
|
Addressed the final exact-head findings at
The PR remains draft. New CI and rereview, final prerequisite replay, independent size acceptance, and supported real-app live-device evidence (or an accepted residual) remain unresolved. |
|
Final exact-head review of
Everything else audits clean, including extraction, cancellation chains, facts/routes, deletion, cutover, and R7/R9/R10. After tests, run |
|
Reviewed exact head 85bb4b4. Android deployment mechanics are genuinely extracted into focused 191/109-LOC modules; WebDriver cancellation now reaches BrowserStack/WebDriver fetch and retry delay end-to-end; body/size accounting is current; all exact-head checks are green. Two findings remain. [P1] Limrun cancellation is still caller-only: awaitLimrunOperation races the opaque sendAsset/installApp/listApps promises and rejects promptly, but the remote mutation continues after request cancellation and binding disposal. The new runtime tests use fake callbacks that reject on the signal, so they do not prove the shipped Limrun transport stops or safely owns the mutation. Add an abortable transport/operation, or fence the started mutation as owned work whose completion/cleanup is awaited; add a production-path regression. [P2] webdriver-client.ts grows from 498 to 536 LOC while adding request/retry/timeout behavior, crossing the >500 extract-before-add tripwire. Extract that transport policy into a focused module. Readiness also remains blocked by no live supported-path deployment success, unaccepted exceptional growth, and unresolved stack dependencies. No ready-for-human label. |
|
Evidence update for exact head
Keep draft: fresh CI is pending, as are prerequisites, independent exceptional-size acceptance, and supported-path live-device evidence (no new live claim). |
|
Evidence rereview of
Afterward run |
|
Addressed the two mutation-resistant evidence findings at e6c3938.
This is test-only evidence, so the PR’s production/package size accounting is unchanged. The body now names this exact head and the fresh clean-tree gate: 603 test files / 4,933 tests; changed-line coverage 726/790 (91.90%); changed-branch coverage 475/574 (82.75%); all runnable local checks passed. The PR remains draft: fresh CI/rereview, final prerequisite replay, exceptional size acceptance, and supported-path live-device evidence or an accepted residual are still blockers. |
|
Reviewed exact head [P1] Limrun request cancellation still rejects only the caller while the opaque provider mutation continues beyond request-binding disposal. The new integration tests demonstrate that gap: after the caller rejects on abort, they must manually resolve the still-running [P2] Exact-head CI is still pending. Readiness also remains blocked by absent live supported-path deployment success, unaccepted exceptional size growth, and unresolved stack dependencies. No ready-for-human label. |
|
Addressed the exact-head P1/P2 at
The PR remains draft: live supported-path deployment evidence, final prerequisite replay (#1740/#1745/#1747/#1744 plus transitive #1750), size acceptance, CI completion, and exact-head rereview remain blockers. |
|
Reviewed exact head Final readiness remains blocked only on non-code evidence/coordination: supported-path live install/reinstall/source-install/push success or an accepted residual, explicit acceptance of the exceptional +50,755 B non-test source budget, and replay/resolution of the draft stack dependencies. Please also update the stale PR-body sentence saying |
3ed4734 to
a200645
Compare
fcb2f35 to
9d2337f
Compare
|
Additional exact-head CI classification: iOS Smoke failed only The draft remains blocked on this lane, the already-documented merged-#1744 Stryker sandbox import failure, live supported-path evidence, and size acceptance. |
c6552f1 to
fbacabf
Compare
fbacabf to
21ac50e
Compare
|
Reviewed exact head Exact CI is not ready. Nine mutation shards deterministically fail during the initial Stryker dry run, before mutation, because the sandbox cannot resolve The iOS Smoke failure is an unrelated simulator typing flake in Remaining readiness blockers are the absence of supported-path live deployment success (or an explicitly accepted residual) and explicit acceptance of the exceptional size budget. |
|
Exact-head follow-up at
The PR body carries the refreshed evidence. This stays draft until #1753 lands/replays and the exceptional cohesive-facet size budget receives explicit acceptance. |
Summary
Draft ADR 0019 Wave 3 install/deploy facet for #1739. This is the tracker-assigned cohesive unit for
install,reinstall,push, and internalinstall_source; publicinstall-from-sourcenormalizes toinstall_source.Exact head:
21ac50e7c683928c832501a7978fc50462fbc4cc, replayed only ontomainat07d528086b5922a6b74a645cc12124ec1489dbea. The range contains 20 install/deploy-owned commits only; no prerequisite commits were replayed into this PR.requireCommandSupportedwiring, legacy adapters/branches/tags/maps, and superseded helpers/tests are removed.deployApp; install_source →ensureReady,materializeAppSource,deployMaterializedApp; push →ensureReady,sendPushNotification. Readiness is provider-owned only: no daemon retry or fallback.R20boot,R21apps, andR22–R25install/reinstall/install_source/push; every named operation has a lexical owner in the existing table.Review parity cells
handleAppDeploymentCommanddeployAppUse/deployAppsession-deploy,APP_INSTALL_CAPABILITY, default install ops, provider adapterhandleAppDeploymentCommanddeployAppUse/deployAppsession-deploy, default reinstall ops, provider adapterhandleInstallFromSourceDeploymentCommandviainstall_sourcereadyMaterializeAndDeployAppUse/ensureReady,materializeAppSource,deployMaterializedApphandlePushNotificationCommandreadySendPushNotificationUse/ensureReady,sendPushNotificationhandlePushCommandand Apple capability closurepushandinstall_sourceexpire an active ref frame immediately before their sole bound dispatch. Facts, readiness, and materialization failures preserve it; every dispatch attempt expires it, including a rejecting operation. No legacy device-ready import/call remains.Facts denominator and coverage
D= install/reinstall deployment;S= install_source (including readiness);P= push.Apple, Android, HarmonyOS, unavailable-local, WebDriver, and Limrun fact tests cover every cell. Production-composition stale-provider tests prove one inspection, zero gateway binds, and zero local execution for stale WebDriver and Limrun IDs.
capabilitiesremains its Wave 6 legacy handler: one facts inspection projects only these four assigned surfaces, with descriptor/use drift coverage.Planted-red / route evidence
awaitLimrunOperationrejection continuation produces the planted late-sendAssetunhandled rejection; request-local draining retains opaque provider operations through settlement before binding disposal.unzipmakes the in-flight cancellation tests fail.runtime.operations.ensureReady({})directly in their owning handlers, so the structural proof is green.Exact-head size accounting
Fresh same-host detached worktrees ran
pnpm install --frozen-lockfile && pnpm build && node scripts/size-report.mjsat the release baseline, currentmain, and the exact head:44c298d7f07d52808644c298d7fThe exact head has 187 JS chunks / 279 packed files; the immediate base has 179 / 271. The eight added clean-pack entries are focused deployment/supporting chunks (
app-deployment,app-device-io,app-install,apps-simctl,apps2,byte-limit-stream,sdk, andappearance); no new dependency or durable resource is introduced. This remains exceptional cohesive-facet growth and requires independent size-budget acceptance.UTF-8 changed-source accounting against
07d528086, excluding tests and fixtures:src/**packages/**The ownership move specifically removes 45,039 root bytes while adding 65,301 package bytes: +20,262 B at that boundary. The remaining net growth is itemized in the table above; the cutover growth stays in the existing parametrized mechanism and no handwritten policy was added.
Draft blockers / residual risk
Keep this PR draft. Exact-head code/ADR rereview is clean, and supported-path iOS simulator deployment evidence now exists for every assigned surface. The iOS Smoke rerun is fully green, including the previously failing targeted XCTest, public CLI preflight, fixture-backed simulator E2E smoke, and host-focus canary. CI remains blocked only by the shared Stryker alias-ordering defect fixed in #1753; this unit does not duplicate that tooling patch. Explicit acceptance of the exceptional size budget remains required.
Residual live risk is limited to denominators unavailable locally: no Android emulator was booted, no HarmonyOS target or active WebDriver/Limrun provider lease was available, and personal iOS hardware was not used for a destructive app replacement. Those cells retain production-composition, cancellation, cache, and fail-closed fact coverage rather than a claimed live success.
Validation
pnpm check:affected --run && git push --force-with-leasepassed from a clean committed tree at21ac50e7c; it fail-open selected all 21 runnable checks.R22–R25uniqueness and the parametrized cutover table’s owner-scoped planted-red cases. Daemon wire compatibility: 151 declarations, 0 changed/removed/added.iPhone 17 Pro, isolated state dir): localinstallandreinstallof the trusted fingerprintedAgentDeviceTester.appsucceeded; public Nodeapps.installFromSource()materialized the canonicalbinary.tar.gzpath and returned bundle identitycom.callstack.agentdevicelab;pushdelivered a benign APS payload;open --foregroundexposed theAgent Device Testersurface and exact-label verification succeeded. Sessionadr19-install-deploy-livewas closed and the temporary localhost server was stopped.