Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 16 additions & 7 deletions Tools/windows/PACKAGING.md
Original file line number Diff line number Diff line change
Expand Up @@ -253,13 +253,21 @@ no certificate, network access, or real build.

## Retained provider sources

Both exact public provider pins have the annotated source-retention tag
`graphcode-windows-baseline-2026-09-17`:
The current accepted public provider commits are:

| Provider | Pinned commit | Retained branch |
|---|---|---|
| [coneilen/winghostty](https://github.com/coneilen/winghostty/tree/graphcode-windows-baseline-2026-09-17) | `f5abc059e4ca58b376eb209313aca7784659c679` | `graphcode-host` |
| [coneilen/zmx](https://github.com/coneilen/zmx/tree/graphcode-windows-baseline-2026-09-17) | `029e11d2b19162fb3bdf90c8270237d303b8bfb4` | `graphcode-quickchat-hang` |
| [coneilen/winghostty](https://github.com/coneilen/winghostty/commit/f5abc059e4ca58b376eb209313aca7784659c679) | `f5abc059e4ca58b376eb209313aca7784659c679` | `graphcode-host` |
| [coneilen/zmx](https://github.com/coneilen/zmx/commit/11e20c738b4ebd88031c7a01f1a9d938ee123234) | `11e20c738b4ebd88031c7a01f1a9d938ee123234` | `graphcode-quickchat-hang` |

The annotated `graphcode-windows-baseline-2026-09-17` tags remain historical
source-retention references:
[Winghostty's baseline](https://github.com/coneilen/winghostty/tree/graphcode-windows-baseline-2026-09-17)
preserves `f5abc059e4ca58b376eb209313aca7784659c679`, and
[zmx's baseline](https://github.com/coneilen/zmx/tree/graphcode-windows-baseline-2026-09-17)
preserves `029e11d2b19162fb3bdf90c8270237d303b8bfb4`, not the current zmx pin.
The current zmx commit adopts the startup fix merged in
[coneilen/zmx#2](https://github.com/coneilen/zmx/pull/2).

As verified on 2026-09-17, each fork has an active ruleset forbidding updates or
deletion of `refs/tags/graphcode-windows-*`, without bypass actors. Separate
Expand All @@ -277,6 +285,7 @@ credentials; collaborator permissions were not changed.
packaging still use exact commit SHAs, not moving branch or tag resolution.
The terminal gate checks every provider field against its investigation copy,
including repository, remote URL, SHA, artifact path, and Zig version.
`ProviderPins.Tests.ps1` proves drift in either file is rejected, while JSON
property order and explanatory fallback wording are immaterial. Run it directly
or through `validate.ps1 -Task terminal-gate`.
`ProviderPins.Tests.ps1` proves drift in either file is rejected, as are matching
copies of the old zmx pin or the reviewed feature head instead of the merged
commit. JSON property order and explanatory fallback wording are immaterial.
Run it directly or through `validate.ps1 -Task terminal-gate`.
10 changes: 10 additions & 0 deletions Tools/windows/Tests/ProviderPins.Tests.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,16 @@ try {
param($product, $gate)
$product.schemaVersion = 2
} "provider pin schemas differ"
foreach ($rejectedSha in @(
"029e11d2b19162fb3bdf90c8270237d303b8bfb4",
"56caff0df61b122c89633e6ad39b8f2c1aafba11"
)) {
Test-Pins "matching unaccepted zmx SHA $rejectedSha" {
param($product, $gate)
$product.zmx.sha = $rejectedSha
$gate.zmx.sha = $rejectedSha
} "zmx SHA is not exact"
}
Test-Pins "matching sources" { param($product, $gate) } ""
Test-Pins "order and explanatory metadata" {
param($product, $gate)
Expand Down
2 changes: 1 addition & 1 deletion Tools/windows/Tests/TerminalGate.Tests.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,7 @@ Assert-Contract ($pins.schemaVersion -eq 1) "provider pin schema is not 1"
Assert-Contract ($pins.winghostty.sha -eq
"f5abc059e4ca58b376eb209313aca7784659c679") "Winghostty SHA is not exact"
Assert-Contract ($pins.zmx.sha -eq
"029e11d2b19162fb3bdf90c8270237d303b8bfb4") "zmx SHA is not exact"
"11e20c738b4ebd88031c7a01f1a9d938ee123234") "zmx SHA is not exact"
Assert-Contract ($pins.winghostty.remoteUrl -eq
"https://github.com/coneilen/winghostty.git") "Winghostty remote URL is not stable"
Assert-Contract ($pins.zmx.remoteUrl -eq
Expand Down
2 changes: 1 addition & 1 deletion Tools/windows/Tests/WindowsShell.Tests.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -231,7 +231,7 @@ Assert-Contract ($pins.schemaVersion -eq 1) "provider pin schema is not 1"
Assert-Contract ($pins.winghostty.sha -eq
"f5abc059e4ca58b376eb209313aca7784659c679") "Winghostty pin changed"
Assert-Contract ($pins.zmx.sha -eq
"029e11d2b19162fb3bdf90c8270237d303b8bfb4") "zmx pin changed"
"11e20c738b4ebd88031c7a01f1a9d938ee123234") "zmx pin changed"
Assert-Contract ($pins.winghostty.remoteUrl -eq
"https://github.com/coneilen/winghostty.git") "Winghostty remote URL changed"
Assert-Contract ($pins.zmx.remoteUrl -eq
Expand Down
2 changes: 1 addition & 1 deletion graphcode-windows/provider-pins.json
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
"zmx": {
"repository": "coneilen/zmx",
"remoteUrl": "https://github.com/coneilen/zmx.git",
"sha": "029e11d2b19162fb3bdf90c8270237d303b8bfb4",
"sha": "11e20c738b4ebd88031c7a01f1a9d938ee123234",
"artifact": "zig-out/bin/zmx.exe",
"minimumZig": "0.16.0"
},
Expand Down
22 changes: 18 additions & 4 deletions investigation/spikes/windows-terminal-gate/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,18 +11,32 @@ session/ConPTY lifetime.
`provider-pins.json` records the accepted provider commits:

- Winghostty `f5abc059e4ca58b376eb209313aca7784659c679`
- zmx `029e11d2b19162fb3bdf90c8270237d303b8bfb4`
- zmx `11e20c738b4ebd88031c7a01f1a9d938ee123234`

Both commits are published on dedicated branches in the public `coneilen`
provider repositories. The bootstrap creates detached, exact-revision
checkouts without copying provider source into GraphCode.

The annotated `graphcode-windows-baseline-2026-09-17` tag preserves each exact
pin. The provider forks protect these tags against updates/deletion and the
dedicated branches against deletion/history rewrites; see
The annotated `graphcode-windows-baseline-2026-09-17` tags preserve the original
baseline sources, including zmx `029e11d2b19162fb3bdf90c8270237d303b8bfb4`,
not the current zmx pin. The provider forks protect these tags against
updates/deletion and the dedicated branches against deletion/history rewrites; see
`Tools\windows\PACKAGING.md` for the recorded ruleset IDs and retention limits.
These are source-retention tags, not signed Windows releases.

The current zmx pin is the merged startup fix from
[coneilen/zmx#2](https://github.com/coneilen/zmx/pull/2). A closed readiness probe
can produce native `NO_DATA`/`BrokenPipe`; the ConPTY accept loop now tolerates
recognized peer disconnects. Transport rearm retains the pipe instance on
disconnect and creates its replacement before closing it on timeout/cancellation.
This does not add client retries or weaken ACLs. Long configured-root
`SetFileSecurityW` path failures and concurrent POSIX TaskComplete-before-Ack
ordering remain outside this fix.

`graphcode-windows\fixtures\zmx-quick-chat-provider.json` is historical
quick-chat provenance at the old provider SHA and recorded source/executable
paths. It is not an active pin assertion or evidence of a build at the new SHA.

`graphcode-windows\provider-pins.json` is authoritative. The terminal gate's
contract compares its schema and all provider fields against this copy, and
`Tools\windows\Tests\ProviderPins.Tests.ps1` injects drift into both sides.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
"zmx": {
"repository": "coneilen/zmx",
"remoteUrl": "https://github.com/coneilen/zmx.git",
"sha": "029e11d2b19162fb3bdf90c8270237d303b8bfb4",
"sha": "11e20c738b4ebd88031c7a01f1a9d938ee123234",
"artifact": "zig-out/bin/zmx.exe",
"minimumZig": "0.16.0"
},
Expand Down
Loading