Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 29 additions & 0 deletions .planning/ledger/wayland-1116.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
---
issue: 1116
repo: FerroxLabs/wayland
kind: defect
title: "Desktop: no abandon verb on the host wire leaves a crash-interrupted session wedged in-app"
status: open
last_verified_commit: 1780b3164c6973279fd49d4dda17e8605f51d047
criteria:
- id: c1
text: "A crash-interrupted session can be ended through the host wire and Desktop recovery surface while preserving unknown external-effect outcomes."
state: not-met
owner: core
note: "The original issue has no declared criterion IDs; this row records its unresolved recovery requirement without claiming completion. ResumeTurnAction already includes Abandon in the tagged source, so the historical title is not a current missing-enum diagnosis. The latest Core handoff reports that an unknown started effect still prevents the requested recovery disposition. Live issue remains open in milestone 0.13.14; no failed outcome is relabelled succeeded, failed or not-started."
- id: c2
text: "The Desktop consumer handles the host-stop recovery behavior and verifies the resulting recovery control."
state: not-met
owner: core
note: "Core retains coordination ownership until the shared recovery contract is resolved; Desktop implementation and consumer acceptance are not established by this release. The issue remains the existing cross-lane carrier."
---

Release metadata reconciliation only. Sources: https://github.com/FerroxLabs/wayland/issues/1116 and its 2026-09-08 coordination comments. Both requirements remain unmet. The live milestone is 0.13.14, verified before this record was written; no milestone, issue state, runtime behavior or release threshold is changed here.

Tagged source: 28634521b854d58672819843865f6ab7dd16d72c. The release metadata revision does not alter that tag, its generated Desktop contract, or its qualified binaries.

Provenance: the existing publisher metadata entry is retained with both criteria
not met. Its source tag `28634521b854d58672819843865f6ab7dd16d72c` and
squash integration `1780b3164c6973279fd49d4dda17e8605f51d047` share tree
`90e028ae6de0537c60c1d86450ceb3083ae4610b`; this pointer reconciliation adds
no runtime proof and does not waive the recorded limitation.
9 changes: 8 additions & 1 deletion .planning/ledger/wayland-1225.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ repo: FerroxLabs/wayland
kind: defect
title: "Desktop drops the MCP per-tool allowlist on the ACP session/create wire, so switched-off tools stay live (wayland#998 c5)"
status: closed
last_verified_commit: 3d2089b45
last_verified_commit: 1780b3164c6973279fd49d4dda17e8605f51d047
criteria:
- id: c1
text: "Desktop's ACP session/create request carries the per-tool selection for every narrowed MCP server as mcp_servers[].allowed_tools or the accepted allowedTools alias, with sent JSON captured and attached."
Expand Down Expand Up @@ -33,3 +33,10 @@ criteria:
---

Recorded from live #1225 body/comments and #1323 body/comments on 2026-09-06. #1225 stays CLOSED; #1323 is OPEN in milestone 0.13.14. The explicit c2/c4 residual moves are preserved. Sean authorized transferring c1/c3 to the existing Desktop successor #1323 on 2026-09-07. Both remain unproven there; the original acceptance and contradictory route evidence are preserved. This can keep release-readiness red and is not a new waiver. Parent #998 c5 remains pointed at this closed carrier, whose residual is now recorded.

Squash provenance reconciliation: PR #455 head `28634521b854d58672819843865f6ab7dd16d72c` and integrated
commit `1780b3164c6973279fd49d4dda17e8605f51d047` have identical tree
`90e028ae6de0537c60c1d86450ceb3083ae4610b`. Original anchor `3d2089b45`
is an ancestor of the PR head; squash integration removed that ancestry. This
repin preserves the recorded grading and does not establish new runtime or
release acceptance. Exact-head CI `34242741624` passed before that squash.
9 changes: 8 additions & 1 deletion .planning/ledger/wayland-1324.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ repo: FerroxLabs/wayland
kind: task
title: "Core stabilization: verified lifecycle, credential, budget and acceptance repair program"
status: open
last_verified_commit: 3d2089b45
last_verified_commit: 1780b3164c6973279fd49d4dda17e8605f51d047
criteria:
- id: c1
text: "Each applicable package has exact source/artifact/fixture identity, fail-before/pass-after controls, actual executed commands/counts, cleanup, current integration evidence and an independent review."
Expand All @@ -21,3 +21,10 @@ criteria:
Recorded from live #1324 on 2026-09-06. Tracker is OPEN, area:core, state:in-progress, with no milestone. Acceptance above follows the coordination handle; existing individual carriers retain their criteria. This entry records pending work, not a new implementation plan or release waiver.

Classification: the tracker describes a programme coordination handle, not an individual defect. Package completion and external residuals remain separate, and unmet criteria above remain unmet.

Squash provenance reconciliation: PR #455 head `28634521b854d58672819843865f6ab7dd16d72c` and integrated
commit `1780b3164c6973279fd49d4dda17e8605f51d047` have identical tree
`90e028ae6de0537c60c1d86450ceb3083ae4610b`. Original anchor `3d2089b45`
is an ancestor of the PR head; squash integration removed that ancestry. This
repin preserves the recorded grading and does not establish new runtime or
release acceptance. Exact-head CI `34242741624` passed before that squash.
9 changes: 8 additions & 1 deletion .planning/ledger/wayland-1328.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ repo: FerroxLabs/wayland
kind: feature
title: "Core contract: expose effective tool approvals and preserve per-tool default inheritance (#1188)"
status: open
last_verified_commit: 3d2089b45
last_verified_commit: 1780b3164c6973279fd49d4dda17e8605f51d047
criteria:
- id: c1
text: "Publish a typed, session-scoped effective tool-policy/inventory snapshot with canonical tool IDs, registration state, effective approval disposition, and source/provenance. Re-emit or revise it after mode/config/registry changes."
Expand All @@ -31,3 +31,10 @@ criteria:
Recorded from live #1328 on 2026-09-06. Tracker is OPEN, area:core, needs:core, with no milestone. Dependency for Desktop #1188; no implementation or milestone change is authorized by recording this issue. Classified defect conservatively because the body names duplicated authority and accidental materialization of inherited configuration.

Classification: the tracker requests a new typed producer policy/inventory and inheritance-preserving mutation contract. This is a feature dependency; the motivating Desktop defects and every unmet criterion above remain unresolved.

Squash provenance reconciliation: PR #455 head `28634521b854d58672819843865f6ab7dd16d72c` and integrated
commit `1780b3164c6973279fd49d4dda17e8605f51d047` have identical tree
`90e028ae6de0537c60c1d86450ceb3083ae4610b`. Original anchor `3d2089b45`
is an ancestor of the PR head; squash integration removed that ancestry. This
repin preserves the recorded grading and does not establish new runtime or
release acceptance. Exact-head CI `34242741624` passed before that squash.
9 changes: 8 additions & 1 deletion .planning/ledger/wayland-1335.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ repo: FerroxLabs/wayland
kind: defect
title: "[Core] Active JSON-stream Stop drops accrued run usage and emits a zero-usage terminal"
status: closed
last_verified_commit: 04b2868032999942829bbf79e54672fafd74132b
last_verified_commit: 1780b3164c6973279fd49d4dda17e8605f51d047
criteria:
- id: c1
text: "A real engine fixture that completes provider/tool work then receives host Stop reports accrued input/output/cache-read/cache-write delta exactly once with the same message correlation."
Expand All @@ -27,3 +27,10 @@ criteria:
---

Verified on Hetzner with zero retries; receipt proof-1788759590-13903.json in stabilization execution evidence. Strict CLI all-targets clippy passed on production-equivalent 8dc531201. Source integrated; tracker closed with explicit Sean authorization after verification; publication pending. No claim of complete billing for unobserved provider responses.

Squash provenance reconciliation: PR #455 head `28634521b854d58672819843865f6ab7dd16d72c` and integrated
commit `1780b3164c6973279fd49d4dda17e8605f51d047` have identical tree
`90e028ae6de0537c60c1d86450ceb3083ae4610b`. Original anchor `04b2868032999942829bbf79e54672fafd74132b`
is an ancestor of the PR head; squash integration removed that ancestry. This
repin preserves the recorded grading and does not establish new runtime or
release acceptance. Exact-head CI `34242741624` passed before that squash.
24 changes: 20 additions & 4 deletions .planning/ledger/wayland-core-443.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,13 +3,13 @@ issue: 443
repo: FerroxLabs/wayland-core
kind: defect
title: "[nightly-windows-soak] FAIL - 2026-09-04"
status: closed
last_verified_commit: 3abeeef2bf27a35457b0aa2e2df3204f551037d4
status: open
last_verified_commit: 1780b3164c6973279fd49d4dda17e8605f51d047
criteria:
- id: c1
text: "The nightly Windows soak failure is triaged: either the failing job is fixed, or the run is shown to have failed for an infrastructure reason and the issue is closed."
state: met
evidence: "commit:3abeeef2bf27a35457b0aa2e2df3204f551037d4"
state: not-met
evidence: "commit:1780b3164c6973279fd49d4dda17e8605f51d047"
owner: core
note: "Original run 33841172783 at509f4426b failed live_fs_acl::concurrent_allow_and_deny_identities_do_not_interfere: ordinary allow identity must retain access;12/13 passed. This is the concurrent ACL grant defect repaired by accepted W14 commit3abeeef2b. Its native Windows receipt executes this exact case successfully and all13 ACL cases pass with retries0. The issue was independently auto-closed on2026-09-07 after whole-nightly run34087589551 at0cdd998ad passed. That later nightly is closure metadata, not the proof of our repair and not evidence for the current release candidate. The original failure and both source identities remain preserved. This triage does not close or regrade the wider#368/#410 criteria."
---
Expand All @@ -29,3 +29,19 @@ record retains the original log and the W14 JUnit/source receipts separately.

The final-tag native collector remains required; this historical triage does
not replace current release qualification.

Squash provenance reconciliation: PR #455 head `28634521b854d58672819843865f6ab7dd16d72c` and integrated
commit `1780b3164c6973279fd49d4dda17e8605f51d047` have identical tree
`90e028ae6de0537c60c1d86450ceb3083ae4610b`. Original anchor `3abeeef2bf27a35457b0aa2e2df3204f551037d4`
is an ancestor of the PR head; squash integration removed that ancestry. This
repin preserves the recorded grading and does not establish new runtime or
release acceptance. Exact-head CI `34242741624` passed before that squash.

GitHub #443 remains OPEN in milestone 0.13.14. Run `34191383717` at
`0cdd998adb1cd2ab13966a40b1b98c6136fd72d0`, job `101949990471`, records
`concurrent_allow_and_deny_identities_do_not_interfere` failing attempt 1 with
"ordinary allow identity must retain access", then passing attempt 2; summary:
13 passed, 1 flaky. This older-source recurrence does not invalidate preserved
W14 repair evidence, but does not establish the issue closure criterion. The
evidence commit identifies integrated source only; final-tag native
qualification remains required.
31 changes: 23 additions & 8 deletions crates/wcore-agent/src/tool_backends/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -429,11 +429,15 @@ pub const FLUX_ROUTER_VISION_MODEL: &str = "flux-auto";
/// Vision arm for native OpenAI (and the `OPENAI_API_KEY` fallback).
pub const OPENAI_VISION_MODEL: &str = "gpt-4o";

#[cfg(test)]
mod vision_binding_tests;

/// Pick the best available vision backend.
///
/// Order (first match wins):
/// 1. `ANTHROPIC_API_KEY` → Claude vision
/// 2. `OPENAI_API_KEY` → GPT-4o vision
/// 2. `OPENAI_API_KEY` → active configured route when it is the same credential;
/// otherwise native GPT-4o vision. An invalid matching binding fails closed.
/// 3. `GEMINI_API_KEY` → Gemini 2.5 Flash vision
/// 4. **Active OpenAI-wire provider** (native OpenAI or FluxRouter) — resolved
/// key + `base_url` from `Config`, so a configured
Expand All @@ -456,8 +460,8 @@ pub const OPENAI_VISION_MODEL: &str = "gpt-4o";
/// [`build_transcription_backend`] exactly: arms 1-3 are the pre-existing
/// resolution order, and putting the active provider first would silently move
/// every existing Anthropic/OpenAI/Gemini vision user onto a different (and
/// possibly billed) arm. **Arms 4 and 5 are strictly additive — no
/// previously-resolving configuration changes backend.**
/// possibly billed) arm. Independent provider keys retain that precedence;
/// an active key mirrored into `OPENAI_API_KEY` retains its configured host.
pub fn build_vision_backend(config: &Config) -> Option<Arc<dyn VisionBackend>> {
build_vision_backend_with_accounting(config, &MediaAccounting::default())
}
Expand All @@ -480,10 +484,12 @@ pub fn build_vision_backend_with_accounting(
));
}
if let Some(key) = read_env_key("OPENAI_API_KEY") {
tracing::info!("vision: using OpenAI (OPENAI_API_KEY found)");
return Some(Arc::new(
OpenAiVisionBackend::new(key).with_accounting(accounting.clone()),
));
let backend = vision_backend_from_openai_env_key(config, key)?;
tracing::info!(
"vision: using {} (OPENAI_API_KEY binding)",
backend.backend_id()
);
return Some(Arc::new(backend.with_accounting(accounting.clone())));
}
if let Some(key) = read_env_key("GEMINI_API_KEY") {
tracing::info!("vision: using Gemini (GEMINI_API_KEY found)");
Expand Down Expand Up @@ -523,7 +529,16 @@ pub fn build_vision_backend_with_accounting(
None
}

/// Arm 4 of [`build_vision_backend`] — the active OpenAI-wire provider (native
/// A selected credential mirrored into the OpenAI environment variable must
/// retain its selected destination. Distinct native credentials keep precedence.
fn vision_backend_from_openai_env_key(config: &Config, key: String) -> Option<OpenAiVisionBackend> {
if !config.api_key.trim().is_empty() && key.trim() == config.api_key.trim() {
return vision_backend_from_config(config);
}
Some(OpenAiVisionBackend::new(key))
}

/// Active OpenAI-wire provider (native
/// OpenAI or FluxRouter), resolved from `Config`.
///
/// Returns the concrete backend (not a trait object) so the resolved endpoint
Expand Down
Loading
Loading