Skip to content

Start attended loops from the daemon when the Windows shell opens them - #643

Merged
coneilen merged 11 commits into
mainfrom
coneilen-windows-attended-launch
Oct 7, 2026
Merged

coneilen merged 11 commits into
mainfrom
coneilen-windows-attended-launch

Conversation

@coneilen

@coneilen coneilen commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Fix Windows attended loops opening a bare shell instead of their selected agent. The Zig shell asks the Swift daemon to launch the loop through existing IPC, then attaches only to a live session; macOS launch ownership is unchanged.

Final combined head: e88f4146f2b4a015df50d9bc69cd67d78c7075d4, based on main at 56e00ca582f289e5456249556ab3a9102d80789d. The merged console (#640), age (#641), and layout (#642) fixes are all ancestors. Required CI on this exact head: 22 passed, 0 failed, 2 skipped. Windows unit shards 0/1/2, integration, both packaging jobs, macOS, Linux, DCO, TDD evidence, and privacy checks passed. Only Full pinned Windows validation and Gated environment hardening were skipped. This PR remains open and unmerged.

Changes

  • resumeSession starts unresolved, unstopped attended Windows loops with no live session. Empty Main loops also receive backend launch arguments. Existing instruction, backend/model, project-directory, and permission settings are preserved; macOS panes and the Nod path retain their launch ownership.
  • Explicit opens show a pending tab immediately without creating a terminal session. Listing-based attachment rejects ended tasks and exact-name mismatches; failed probes preserve saved layouts instead of treating errors as absent sessions. Reopening a live loop reuses its session.
  • Listing capture uses Hide the console window of zmx children spawned by the Windows shell #640's console-safe ZmxSession.child helper. Its new capture mode keeps stdout readable while ignoring stdin and preventing a console window. The shared source contract still requires all zmx spawn sites to use the helper.
  • Smoke fixtures host and positively verify real zmx sessions, use short owned roots, and set/verify the current-user SID as owner. Elevated runners otherwise create Administrators-owned roots that zmx correctly rejects. No readiness bypass or provider security relaxation remains.
  • Session tracking and ownership fixtures use canonical graphcode- names. Both the strict multi-project peer and its complete receipt validator recognize correlated resumeSession requests for the exact project/node owner. They retain foreign-owner rejection and count only actual renames as graph mutations.
  • Fixed two validation-fixture defects identified from CI: Git fixture setup now retains the harness's real isolated config file instead of substituting NUL (which affected runner Git exits 128 on); warm daemon restart waits for the owned listener before the unchanged lifetime-mutex assertion. Git failures now retain bounded stdout/stderr diagnostics.
  • Updated attended-launch documentation. The parity ledger remains Partial because a credit-free backend stub does not establish authenticated real-agent qualification.

Test plan

RED: pinned swift-test.exe --filter WindowsDaemonTests.testWindowsMainLoopWithoutAnInstruction -> 1 executed, 1 behavioral failure: XCTUnwrap expected a non-nil launch argument array; earlier attended-open coverage executed 66 tests with one intended failure because opening Turn and Main requested no launch.
GREEN: pinned swift-test.exe --filter WindowsDaemonTests -> 68 executed, 0 failures, including empty Main launch and preservation of first instruction and ask permissions.
REGRESSION: pinned swift-test.exe with isolated scratch/profile and --disable-automatic-resolution -> 108 XCTest and 6 swift-testing tests passed; zig test src\TerminalSurface.zig with the registered Windows target/link/include flags on the combined tree -> 161/161 passed; pwsh Tools\windows\Tests\ValidationRunner.Tests.ps1 -> PASS, including 384 multi-project cases (50 positive, 334 negative); pwsh Tools\windows\Tests\WorktreeGitProcess.Tests.ps1 -> 17 positive and 4 expected-rejection cases passed, 21 executed; pwsh Tools\windows\Tests\DaemonRoundTrip.Live.Tests.ps1 -> real mutation/reload, clean shutdown, and warm restart PASS with the original production-derived mutex assertions retained.

Further behavioral failures were retained: pending-tab coverage expected one tab but found zero; failed-listing/name-parsing coverage failed two cases; both peer and receipt schema tests rejected legitimate resumeSession; console-safe capture expected Pipe but found Ignore. Corresponding focused/full reruns passed after correction. No compile failure was counted as runtime evidence.

Combined real-daemon/shell walkthrough: the final tree was rebuilt with pinned Swift 6.3.3, Zig 0.15.2, and pinned providers. With no daemon stub, an isolated profile, and a credit-free copilot.exe recorder, a native-form Turn-based loop and production-CLI empty Main loop both launched only when opened through the normal sidebar UIA action. Each started exactly one backend process in the project directory with ask permissions, attached one terminal client, and reused its session on reopen. Turn received its first instruction; empty Main launched without an interactive prompt. Both paths passed with all three sibling fixes present. No real credentials or AI credits were used.

CI failures and limits: failed logs from earlier pushes/replays are retained. The final run passed without weakening ownership, session-liveness, receipt, Git-fixture, or daemon-mutex assertions. Native form fields were entered by keyboard, but loop opens used UIA Invoke. No fresh Dev Box qualification with authenticated Copilot has run. The pinned provider's general long-path limitation is unchanged. No C/FFI bridge or toolchain upgrade was needed.

Checklist

  • I have read the Contributing Guidelines
  • I have signed off my commits (git commit -s) per the DCO
  • Tests pass locally (make test)
  • Code follows the existing style (make check)
  • I added the test/contract before the implementation and observed the intended RED failure

The unchecked commands require macOS and were not run locally on Windows. The hosted macOS required check passed on the final combined head.

@coneilen
coneilen force-pushed the coneilen-windows-attended-launch branch from 59771eb to d13b487 Compare October 6, 2026 23:48
coneilen and others added 11 commits October 6, 2026 17:16
On Windows the terminal pane only runs zmx attach, which created a bare
cmd session under the loop's name before anything launched the agent, so
an opened Turn-based or main loop never received its first instruction
(beta10 D7, AttendedAgentNotLaunched).

resumeSession now starts an unresolved, unstopped attended loop with no
live session when the platform's panes do not launch sessions (Windows
only; macOS unchanged). The shell sends it on every explicit open and
attaches only once zmx ls shows the loop's session running; passive
auto-attach and layout restore never create a loop session, and an ended
loop pane is pruned from the persisted layout.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
The validation root redirects LOCALAPPDATA deep enough that zmx's IPC
lease path for a graphcode-<uuid> session passes 260 characters, so the
harness's zmx run for the stub loops exited 1. Give the smoke a short
owned ZMX_DIR under RUNNER_TEMP and remove it afterwards.

Launch waits also now run while the workspace is collapsed, as the old
synchronous auto-attach did; the large-paste smoke sends its paste with
the workspace hidden and needs the loop attached by then.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
… listings

Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…rrors

Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@coneilen
coneilen force-pushed the coneilen-windows-attended-launch branch from 1a37de8 to e88f414 Compare October 7, 2026 00:24
@coneilen
coneilen merged commit ab47b46 into main Oct 7, 2026
25 checks passed
coneilen added a commit that referenced this pull request Oct 7, 2026
Record the immutable, unpublished 0.1.78-windows.beta12 candidate built from
1199de5 with the beta10 Dev Box fixes (#640-#643). Beta10 is failed/superseded
and beta11 is unbuilt/superseded; both are kept unchanged. Exact artifact stays
complete and the other six gates stay open. The parity count is updated to the
ledger's current 98 surfaces: 60 Validated / 38 Partial.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
@coneilen coneilen mentioned this pull request Oct 7, 2026
2 of 5 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant