Skip to content

fix: enforce public Scient identity - #4

Merged
yaacovcorcos merged 1 commit into
mainfrom
agent/public-identity-invariants
Jul 18, 2026
Merged

fix: enforce public Scient identity#4
yaacovcorcos merged 1 commit into
mainfrom
agent/public-identity-invariants

Conversation

@yaacovcorcos

Copy link
Copy Markdown
Contributor

What changed

  • fixes Scient-owned public identity at Linux packaging, generated Git/stash names, share-card downloads, UI placeholders, profile fallbacks, CLI guidance, CI labels, and active developer documentation
  • removes the stale Synara-branded README/marketing screenshot without fabricating a replacement
  • clears the bundled server web-client target before copying a new build so obsolete branded assets cannot survive incremental builds
  • adds precise repo-local Scient development-home ignores without hiding canonical .scient/project.json
  • strengthens the identity guard for bounded Scient-owned outputs and narrows the PapiLab migration allowlist so unrelated product copy still fails
  • extends release smoke coverage to Linux executable and StartupWMClass identity

Why

The LitRev/PapiLab product rename is complete, but several current public and developer surfaces still emitted inherited Synara identity. This PR closes those product-boundary defects while preserving inherited source structure needed for selective upstream intake.

Compatibility boundary

This intentionally does not rename @synara/*, SYNARA_*, Effect/service IDs, persistence identifiers, OpenCode internals, attribution, or accurate upstream references. Antigravity's installed synara-capture hook is also excluded because it needs a separate read-old/write-new compatibility migration.

Validation

  • formatting passed
  • lint passed with 0 errors (existing warnings only)
  • all 9 package typechecks passed
  • brand identity guard passed
  • script tests: 81/81
  • relevant server tests: 138/138
  • Codex text-generation isolation: 12/12
  • desktop remainder: 187/187
  • marketing build passed
  • release smoke passed
  • git diff --check and git show --check passed

Broad root-suite runner failures were reduced to smallest reproductions and repeated on an untouched origin/main worktree: Turbo's Bun-as-Node shim changes updater/Codex test behavior, and localImageRoute.test.ts has the same grant-state failure on main. No PR-caused failure remained.

Related work

Companion documentation closeout: ScientFactory/Scient#19.

@github-actions github-actions Bot added size:L vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. labels Jul 18, 2026
@yaacovcorcos
yaacovcorcos force-pushed the agent/public-identity-invariants branch from ed7cf53 to 9971669 Compare July 18, 2026 10:48
@yaacovcorcos
yaacovcorcos force-pushed the agent/public-identity-invariants branch from 9971669 to 70390d5 Compare July 18, 2026 10:59
@yaacovcorcos
yaacovcorcos marked this pull request as ready for review July 18, 2026 11:35
@yaacovcorcos
yaacovcorcos merged commit 0b6f135 into main Jul 18, 2026
8 checks passed
@yaacovcorcos
yaacovcorcos deleted the agent/public-identity-invariants branch July 18, 2026 11:35
yaacovcorcos added a commit that referenced this pull request Jul 26, 2026
…findings

Ensure the provider updater child process is only ever spawned against a
target that was probed, certified, and re-validated under the settings write
lock, closing six concurrency/security windows in the confirmed-update
boundary:

- #1 Immutable probe/settings snapshot threaded through refresh; a single
  serialized refresh (refreshSemaphore) captures one snapshot and
  revalidates confirmed targets at the commit boundary.
- #2 updateProvider re-validates the confirmed target and captures the exact
  updater command into immutable locals while holding withSettingsWriteLock,
  so a concurrent settings write cannot change what gets spawned between
  validation and capture. The child is spawned OUTSIDE the lock (spawn + await
  share one update-timeout budget), so a slow or hung spawner.spawn — whose
  acquire is uninterruptible — can only stall its own request and can never
  pin the global settings write lock.
- #3 Request-owned update state (per-request owner token); a losing
  duplicate cannot clobber the in-flight update's running state.
- #4 Interruption-safe cleanup lands a terminal failed state and kills the
  child via a scoped finalizer.
- #5 Hot getStatuses/stream reads re-derive only a cheap authority key
  (revision counters) instead of the full maintenance context, so reads
  never re-probe CLIs or re-resolve the runtime.
- #6 Runtime target identity tracked by a monotonic per-provider revision
  counter (ProviderRuntimeManager.getRevision), excluded from transient
  install-progress churn; PROVIDER_KINDS derived from ProviderKind.literals.

Adds deterministic regression tests for each finding (no sleeps; barriers via
Deferred / TestClock.withLive / scheduler drains), including a mutation-
sensitive hot-read guard, a mutation-sensitive guard that the settings write
lock is released before the unlocked spawn, a hung-process timeout guard,
succeeded/unchanged post-update re-probe guards, and a per-provider
revision-isolation test.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant