Summary
Parent: #474 / #466. Tracking only — not a follow-up implementation.
Issue #474 estimated 200–400 lines and required material scope growth to become a separate issue. The sharing proof is larger because #474 also required a service-level live test through connect_gui_herdr / RuntimeRouter / create_with_runtime / create_session / list_with_runtime (not only Task 1's transport-level snapshot check), CLI herdr api snapshot and herdr workspace list quotes, the reverse CLI → list_with_runtime join-key proof, lease-drop-leaves-server, a Sharing contract section with those commands/output, and a docs_client_mode.rs lock so leftover "dedicated 2code namespace / never the user default session" wording cannot regress as production text.
Approximate churn on task-3-prove-sharing vs task-2-version-policy (74ef8fd): 633 insertions / 1 deletion (4 files).
What grew
src-tauri/crates/service/src/runtime/sharing_proof.rs (isolated-XDG live proof: forward RuntimeRouter workspace/pane visible to herdr api snapshot / herdr workspace list; reverse CLI workspace live-read as workspace_id; join key; GUI/lease drop leaves the default socket)
docs/herdr-integration.md (Sharing contract + sanitized command log; contract-probe dump line reworded as test isolation)
src-tauri/crates/service/tests/docs_client_mode.rs (sharing-contract string lock)
The extra lines are the live proof and docs #474 asked for. Production socket resolution, protocol floor, PATH preference, herdr update copy, and the v0.9.0 sidecar pin are unchanged. The contract probe is not retargeted onto the host ~/.config/herdr session.
Decision
Keep the extra evidence in Task 3. Splitting the reverse join-key proof or the Sharing contract command log into a later issue would leave #474's acceptance criteria unproven.
This plan has no Task 4 to fold into task-3-prove-sharing. No production work belongs on this tracking issue.
Summary
Parent: #474 / #466. Tracking only — not a follow-up implementation.
Issue #474 estimated 200–400 lines and required material scope growth to become a separate issue. The sharing proof is larger because #474 also required a service-level live test through
connect_gui_herdr/RuntimeRouter/create_with_runtime/create_session/list_with_runtime(not only Task 1's transport-level snapshot check), CLIherdr api snapshotandherdr workspace listquotes, the reverse CLI →list_with_runtimejoin-key proof, lease-drop-leaves-server, a Sharing contract section with those commands/output, and adocs_client_mode.rslock so leftover "dedicated2codenamespace / never the user default session" wording cannot regress as production text.Approximate churn on
task-3-prove-sharingvstask-2-version-policy(74ef8fd): 633 insertions / 1 deletion (4 files).What grew
src-tauri/crates/service/src/runtime/sharing_proof.rs(isolated-XDG live proof: forward RuntimeRouter workspace/pane visible toherdr api snapshot/herdr workspace list; reverse CLI workspace live-read asworkspace_id; join key; GUI/lease drop leaves the default socket)docs/herdr-integration.md(Sharing contract + sanitized command log; contract-probe dump line reworded as test isolation)src-tauri/crates/service/tests/docs_client_mode.rs(sharing-contract string lock)The extra lines are the live proof and docs #474 asked for. Production socket resolution, protocol floor, PATH preference,
herdr updatecopy, and the v0.9.0 sidecar pin are unchanged. The contract probe is not retargeted onto the host~/.config/herdrsession.Decision
Keep the extra evidence in Task 3. Splitting the reverse join-key proof or the Sharing contract command log into a later issue would leave #474's acceptance criteria unproven.
This plan has no Task 4 to fold into
task-3-prove-sharing. No production work belongs on this tracking issue.