Skip to content

feat(storage): global trash cleanup, reference lists and browser profile status (C22–C24) - #175

Merged
yxflc11 merged 3 commits into
mainfrom
codex/c22-c24-storage-follow-ups
Oct 3, 2026
Merged

yxflc11 merged 3 commits into
mainfrom
codex/c22-c24-storage-follow-ups

Conversation

@yxflc11

@yxflc11 yxflc11 commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator

What changed

Implement the C22–C24 backend contracts from docs/research/storage-cleanup-follow-ups.md:

  • C22: one Owner-only global trash cleanup with a receipt keyed only by requestKey, reusing C21 deletion/recovery/reference guards and audit. Storage totals include measured referenced trash bytes. Migration 0051 adds global receipts (52 migrations total).
  • C24: bounded Owner-only attachment reference lists using C19 matching, with short previews, exact counts and owner/bot/system authors. The Owner explicitly approved system authors.
  • C23: carry safe-integer/null profileBytes through browser maintenance and the Docker Provider. The previously requested upstream contribution is tracked in feat(agent-computer): report bounded per-Bot profile bytes CopilotKit/OpenBot#730. The deployed dependency pin stays unchanged, so existing images return null until the reviewed route is available.

UI wiring is a separate consumer change. This PR targets Peerframe/openbot only and does not enable automatic merge.

Acceptance journey

  1. An authenticated Owner clears trash across active channels; referenced files remain, each deletion is audited, and retrying the same requestKey touches no later files.
  2. The Owner requests attachment references, including recycled files, and receives bounded same-channel message/task lists. Missing authority and purged files withhold content.
  3. Browser status carries measured profileBytes when available and null for unsupported/refused measurements.

Open-source research

  • Research artifact: docs/research/storage-cleanup-follow-ups.md; existing channel-storage-purge.md, channel-attachment-reference-counts.md and desktop-browser-management.md decisions.
  • Selected upstream/standard: existing PostgreSQL and C21/C19 contracts; agent-computer authenticated HTTP surface; Node filesystem APIs and Linux open(2).
  • Version or commit: deployed agent-computer 257c1280d684089be9adb0b35cce262efc7064bf; reviewed contribution base cb5dc32a44517622c6db4e527e61d3abb389b43c, contribution head 46eb7af817027c5de4202846c73c43bbb2fa67b7; PostgreSQL 17.11 qualification.
  • License: MIT for agent-computer and local implementation; existing PostgreSQL license.
  • Decision: extend existing control authority and adapters; retain the deployed dependency pin while the prior upstream contribution is pending. No runtime fork adoption.
  • OpenBot-specific gap: globally keyed cleanup receipts, per-attachment reference previews and nullable per-Bot profile measurements.
  • Source copied or substantially adapted: no.

Verification

  • Focused real PostgreSQL/HTTP tests: 52 passed; protocol: 3 passed; Docker browser/maintenance: 35 passed.
  • Migration qualification: 40 retained upgrade/restore cases and 8 cleanup cases passed; exact committed-source evidence in experiments/s7-migration/evidence/global-trash-result.json.
  • Actual Linux arm64 product image build/smoke passed with all 52 migrations, Owner HTTP, built Web, parsers and restart persistence.
  • Broader completed checks include Web 644 tests, Docker Provider 67 tests, Node 129 Vitest tests (3 skipped) plus 54 transport tests, and the final build (18 tasks, 13 cached).
  • npm run check did not finish green: an unchanged publisher CLI timed out, then a serial test retry hit four Desktop timeouts. Publisher tests passed alone; all 15 tests in the three Desktop files passed with one worker. Remaining Node tests and build were completed separately.
  • npm run test:control:python exceeded the existing 300-second suite deadline twice. The second completed 789 tests without failures before timeout. Remaining modules were supplemented with disposable SQL tests (301 completed; 13 initially failed due to omitted diagnostic fixture identities, then all 13 passed after fixture correction). This does not qualify the default aggregate command or its post-pytest TS read-back assertions.
  • Documentation checks passed; research unit tests passed. Hosted CI and dedicated Worker/Temporal qualification remain pending/unrun. Full details and prior failures are retained in the bilingual research record.
  • Manual path: no production mutation, paid model call or UI acceptance claimed.
  • Platforms actually tested: macOS arm64 and local Docker Linux arm64.
  • Support level claimed: backend contracts implemented; C23 numeric production measurements and UI integration remain dependent work.

Security impact

  • New cleanup surface documented with fail-closed tests; authority remains with the Owner/control plane.
  • No credentials or private user data included.

Documentation and compatibility

  • Implemented, pending and planned behavior are distinguished.
  • English API/research/reuse documents and Chinese translations updated.
  • Platform boundaries and upstream measurement limitations documented.

AI or automation assistance

  • Tools/models used: Codex, existing repository tests, disposable Docker fixtures.
  • Human-reviewed areas and evidence: Owner-approved contracts and system author addition; implementation awaits PR review.

@yxflc11
yxflc11 merged commit 7f80fc1 into main Oct 3, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant