Skip to content

test: virt monitor e2e on sbm_virt's contracts - #1658

Draft
lollipopkit wants to merge 80 commits into
mainfrom
test/virt-e2e-sbm-virt
Draft

lollipopkit wants to merge 80 commits into
mainfrom
test/virt-e2e-sbm-virt

Conversation

@lollipopkit

Copy link
Copy Markdown
Owner

No description provided.

@winnowl

winnowl Bot commented Oct 6, 2026

Copy link
Copy Markdown

Important

Review skipped

This pull request is a draft.

  • Review this pull request now

Commenting @winnowl review does the same.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 5e047f94-1953-4a55-810f-96725bb1f083

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

Snippets run in the terminal they open; terminal notices before a session and no toolbar over the shell; Files opens on tap and Enter, keeps its history on a failed step; Access needs an agent that names the caller; process names never collapse and show the command; Virt's New goes to guests; modals scroll inside their window; split views fold out of the keyboard's way and scroll once; Status refreshes in place.
Opaque windows and panels with hairlines and soft shadows, frosted menubar
and dock, berry accent by default, neutral app tiles, panels over the dock
with an eyebrow and title, a split sign-in screen, SVG wallpapers. Inside
the desk the shared kit's tokens follow the desk's palette and accent;
Button and IconButton take tokens whose defaults keep the website as is.
New ui pieces: Section, Segmented, StatusPill, boxed SourceGroup. An empty
app toolbar draws nothing. The desk's rules file is now tracked.
Tokens, base and lk-* component styles scoped to .lk, dark via data-theme on
<html>; Svelte components for every part of the system (desk/lk); Figtree,
JetBrains Mono and Material Symbols Rounded bundled, the Google Fonts link
dropped. The shell is rebuilt on it: full-width glass menubar, dock of
berry app icons with launch bounce, windows with traffic lights in an inset
glass sidebar and the app's title and tools in the title bar (registered
through useWindow().chrome), full-screen launchpad, Spotlight, control
centre tiles, notifications, lock screen. Old ui pieces are TODO-remove shims
on lk classes until the apps move over.
Apps, shared components (charts, terminal, VNC, disclosure, OS icon) and
dialogs use desk/lk only: Material Symbols glyphs, flat cards, badges,
segmented controls, sidebars in the window's inset sidebar, two-word empty
states. lk gains Textarea and Spinner; glyphs are drawn by CSS so their
names never join an accessible text; a clickable Card can announce its
selection as current. The accent picker is gone (one seed); the stored
value is kept. Unused translation keys removed; the new ones in every
locale. The dev server can proxy to another agent (SBM_DEV_AGENT).
Apps register by manifest (apps/<id>/manifest.ts, defineApp) and reach the
desk only through sys: window state, app name/icon/badge, menubar menus
with shortcuts, lifecycle with suspension when background running is off
(Settings > Apps, stored as desk preference background, migration 019,
feature desk_background). Lint keeps apps off the shell and each other.
Design and phases: docs/dev/desk-sys.md.
…k rows

Settings > Apps gains a background switch per app (background_denied,
migration 020); Control Centre lists apps running hidden. Apps post
notifications that bring their window forward, keep JSON per account
(/desk/apps/{app}/storage, migration 021, feature desk_storage) and add
rows to their dock menu. Pins the checksums of migrations 019-021.
An app opens another with an intent delivered once to the new window
(useIntents); Snippets hands its steps to Terminal that way instead of a
shared module slot. Manifests say what they open; Files lists them under
Open with. A manifest's settings page shows in Settings > Apps, run as
its app.
Admins upload .sbapp packages (checked whole: regular files, plain paths,
bounded while inflating), approve their permissions with a password, and
the UI is served under an HMAC launch ticket with a sandbox CSP and no
network. Web apps only until the agent runs backends.
The desk registers the agent's approved apps and runs each in an iframe
with an opaque origin, answering its bridge messages within its approved
permissions; intents carry their sender so Terminal types only for
Snippets. Settings > Apps installs, approves and removes packages with the
admin's password. Adds an example app.
A wasm package's backend.wasm runs in wasmi on the agent, one instance
per call, bounded by fuel, wall time and memory. Its host functions (kv,
status, fs.list/read, exec) need the app's approved permission and the
calling account's grant. The bridge reaches it with backend.call. Adds a
Rust example.
@lollipopkit/desk-sys is the frame side of the app bridge and holds the
one copy of its protocol; a vite template packs a .sbapp. The SDK is
tested against the desk's bridge. Not published.
- A guest re-entering sbm.host traps instead of overflowing the stack.
- Inflating a package is bounded headers included, off the worker.
- The bridge talks over a MessagePort given to the frame's first page;
  a frame that navigates away is dropped.
- Approvals and launch tickets name the package's SHA-256: new code
  always waits for approval.
- Backend calls are limited per agent and account; the clock is checked
  per host call; fs.read takes regular files only; logs drop controls.
- appState is capped at 16 KiB and opens are rate limited in the bridge.
- Built-in ids are reserved; removing an app removes its storage; app
  storage is capped per account.
…design

The window's title bar floats over the content and turns to glass once it
scrolls (or always, a per-browser choice); the sidebar floats inset; an
app may give the bar a heading, make it flush over a table, and add a
footer (sys.WindowFooter). lk gains DataTable, StatTile, LegendChip,
SearchField, ToolbarGroup, StatusBar and NotificationCenter; Group/Row
use the settings group styles. The window area keeps room for a dock on
the left, bottom or right.
…w design

The menubar leads with the server and its live dot, then the front app
(icon and name), its menus, Window and Help; on the right a CPU reading
with the machine at a glance, search, Control Centre, notifications and
the clock. The dock sits left (default), at the bottom or right, can
hide itself and has three icon sizes; with the title bar style these are
per browser (Settings > Appearance). Notifications open as the design's
notification centre with Do Not Disturb.

Other locales get the new keys in a later pass.
Processes: one DataTable of the columns the machine printed, sorted by
the header (the agent's orders), search and kernel threads in the bar,
reading again every 5 s while shown unless paused; a stop is asked in
the status bar, the root retry in a dialog.

Services: state and type in the sidebar, a table with state dots, the
selected unit's facts and actions over the status bar, its log in a
dialog; the listing's notice opens from the status bar.
The machine's name and state lead; stat tiles (CPU and memory open
Processes in that order, the rest their detail) keep the shared card
order; one usage chart with legend chips over a 1 h / 24 h / 7 d range
and a reading under the pointer; network, the busiest processes, system
information and custom commands in cards below. Refresh pauses from the
bar; terminal, files, iperf, power and every reading's detail move to
the View and Go menus. Processes opens in the order it was asked for.
The runtime and version head the sidebar (containers, images with
counts); each list is a table, the selection's actions and logs sit
over the status bar, which carries the store's usage and the second
prune. Run and pull lead the bar; File holds every prune.
Back/forward as a capsule beside the path in the title bar (the folder
in bold), list or grid and new folder/upload at the right; the list is
a sortable table (folders first), the grid big glyph tiles; the sidebar
adds the disk's free space; the status bar counts the folder and names
the selection, with its menu for pointers that cannot right-click. A
tap on a touch screen opens a table row.
Settings' column sits left under the title, groups in the design's
settings cards; the theme moves to Appearance with the title bar and the
dock; sidebar glyphs as designed. Processes, Services and Containers
take the design's icons.
…icon

44 keys no code reads any more (the old page layout's, and those the
redesigned apps dropped) go from every locale. Virtualization and
Containers no longer share a glyph.
Showing it scheduled its own hiding at once; it now stays out while the
pointer is on the dock or the edge strip, and goes 500 ms after it
leaves (or after a menu it opened closes elsewhere).
…l switches

- Files given a path (Spotlight, another app) opens a file in its folder,
  picked and in the editor, instead of failing to list it; the agent answers
  a file asked to be listed with 400 not_a_directory, not 500.
- Clicking the title of the open menubar menu closes it.
- Going from one menubar panel to another (Control Centre, calendar) opens the
  next with the panel animation.
….0 package

- Panel and installed apps share it; the bridge sends the installed theme's tokens (applyTheme)
- Themes reach on-accent content, danger text, shadows, the scrim and terminals
- Icon font narrowed to the axes drawn (5.4 -> 3.0 MB); fonts and icons split from core.css
- Containers table shows memory used; desk-sys is Apache-2.0 too
…nt serves

- The kit is back in the panel; the build writes dist/desk-app and the agent serves it at /desk-app (any origin, cached once)
- desk-sys connect() loads it and applies the mode and theme tokens; apps carry only markup
- Built assets are precompressed and served immutable from /assets
- Fix: tab indicator measured while its window scales in; a theme's tile shape no longer squares table rows
# Conflicts:
#	monitor/frontend/src/i18n/de/index.ts
#	monitor/frontend/src/i18n/en/index.ts
#	monitor/frontend/src/i18n/es/index.ts
#	monitor/frontend/src/i18n/fr/index.ts
#	monitor/frontend/src/i18n/i18n-types.ts
#	monitor/frontend/src/i18n/id/index.ts
#	monitor/frontend/src/i18n/it/index.ts
#	monitor/frontend/src/i18n/ja/index.ts
#	monitor/frontend/src/i18n/ko/index.ts
#	monitor/frontend/src/i18n/nl/index.ts
#	monitor/frontend/src/i18n/pt/index.ts
#	monitor/frontend/src/i18n/ru/index.ts
#	monitor/frontend/src/i18n/tr/index.ts
#	monitor/frontend/src/i18n/uk/index.ts
#	monitor/frontend/src/i18n/zh-CN/index.ts
#	monitor/frontend/src/i18n/zh-TW/index.ts
#	monitor/frontend/src/lib/xterm.ts
#	monitor/frontend/src/pages/Terminal.svelte
# Conflicts:
#	.github/workflows/analysis.yml
#	packages/fl_lib
… fl_pi_llm's pi host, with command risk classification, plans, sudo, memory and the desk's Agent mode UI
…w composer

- Command rules (allow/ask/deny, `sbm_parser::command_rules`) set by an
  admin, and a permission mode picked per task: manual, auto (the model
  judges each change against prose rules) or bypass (deny/ask rules still
  hold; an admin can turn it off). Migration 023.
- Spotlight asks the agent: keyword, question or change, read-only, a
  drafted change carried into a task.
- Files given with a task or a reply: uploaded first, moved into the task's
  directory, listed in the prompt, short text inline, images to the model.
- Desk: menubar per spec, Agent mode switch storyboard, the composer
  (focus to the middle, multi-line, attachments, mode menu), replies with
  attachments, the model's replies in the streaming style, Settings →
  Agent → Command permissions.
…ad progress; app command risk from Rust

- Windows: Agent mode commands run as Windows PowerShell (`-EncodedCommand`,
  UTF-8, the last statement's exit code), a stop ends the tree with
  `taskkill /T`, `sudo` is refused, and the prompts say which shell it is.
  PowerShell output shaping (`| Format-List`) reads as read-only.
- fix: the native sampler keeps its state on one thread. On Windows sysinfo's
  components are thread-bound WMI objects, and refreshing them from a
  recycled blocking-pool thread crashed the agent.
- "Always allow" on a command's confirm adds `command_rules::suggest`'s rule
  (admin only, audited).
- Replies take files; an account's pending uploads go when it ends.
- Panel: drafts and the open task survive leaving Agent mode, upload
  progress with cancel, replies multi-line with attachments, the model's
  replies in the streaming style; tests for autosize and attachments.
- App: `classifyRisk` is `sbm_parser::command_risk` over FFI.
- Cargo profile `monitor-test` for test deploys (no fat LTO).
# Conflicts:
#	crates/sbm_ffi/src/frb_generated.rs
#	lib/src/rust/frb_generated.dart
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Deploying serverbox with  Cloudflare Pages  Cloudflare Pages

Latest commit: 9afba31
Status:🚫  Build failed.

View logs

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying sbmd with  Cloudflare Pages  Cloudflare Pages

Latest commit: 9afba31
Status:🚫  Build failed.

View logs

@winnowl

winnowl Bot commented Oct 9, 2026

Copy link
Copy Markdown

CI failure root-cause analysis

All listed jobs fail during checkout because the packages/fl_lib submodule cannot supply the pinned commit 98e6a915bbebc4935c37ce373a8b1ef1b3989bee. The reported Git exit code 128 is a consequence of this fetch failure, not a separate test or build failure.

Attribution

The parent repository’s submodule gitlink for packages/fl_lib points to a commit unavailable from the configured submodule remote (or otherwise not fetchable). The diagnostics do not identify which change introduced that gitlink, so attributing it to a specific change is not possible.

Verifiable fix

Verify that 98e6a915bbebc4935c37ce373a8b1ef1b3989bee exists and is fetchable from the remote configured for packages/fl_lib. If it is intended, publish/push that commit and confirm a fresh submodule update succeeds; otherwise update the parent repository’s submodule gitlink to an existing accessible commit, then rerun checkout/CI.

Same root cause: 113977652775, 113977705409, 113977705423, 113977705456, 113977705460, 113977705495, 113977705505, 113977705507, 113977705539, 113977705587, 113977705650

Incremental value: root cause, attributed to this change, grouped same-root-cause failures, verifiable fix; confidence 98%. Passing CI ≠ absence of defects (§29.4).

@socket-security

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant