Current implementation — October 1, 2026 (Pacific)
Main a55e83e8 includes ADR 0004 bounded single-writer persistence, runtime startup/loading, retained volume identity, fresh native preflight, app checks/Start coordination, workspace metadata foundations and owner-merged #258–#263 progress/cancellation/diagnostics/export. Source-head Cloud and matching clean automated reviews passed before merge. Strict package hook passes 1,244 tests; composed app suite passes 78.
#272 blocks an empty save from erasing unknown placement evidence before fresh volume selection. Its regression failed before the correction; repeated refusal, byte preservation, nonempty edits and reopening pass. #272 is merged and retained #212 closed after its replacement audit. No peer observation registry, automatic repair or lossless power-failure guarantee was added.
BOTH native missing-target findings on merged #258 remain unresolved under #24/#32/#76/#82. GUI unknown outcomes are preserved; the native inspector cannot prove omitted saved metadata means stopped. Provider inventory/adoption, identity persistence before started acknowledgment, real capability producers and explicit metadata repair remain unfinished. Production mutations stay disabled. The unchanged strictly rejected Lume artifact is not executed; provider/owner/human gates remain real dependencies. Prior history follows.
Current persistence tracking — September 21, 17:34 UTC
September 21, 17:34 UTC — #217 publication-capacity finding corrected on its own head; native validation pending.
Implemented PRRT_kwDOUMu8ss6kcyxH/discussion4064633345 in c3c2e8d. Brought the existing #223 reservation algorithm forward into #217: reserve one managed-name slot AND one total-directory-entry slot before collection/creation; standalone collection retains full bounds. Four isolated managed-name/total-entry cases verify full-inventory refusal before eligible evidence removal or temporary creation, unchanged bytes/inventory, exact-bound standalone admission, and one failed publication followed by repeated/reopened refusal before any second slot is consumed. #223 retains quarantine behavior and its broader tests; no child was merged into a feature base.
Only #217 pushed (17:32 UTC). Own correction: 3 files,61 additions/6 deletions. Full217scope8files535adds35dels; coherent safety/test corrections retained, above the approximate500-line preference. Diff checks and seven mocked shell-hook scenarios PASS; worktree clean. Swift Testing guidance shaped exact errors/isolated parameterized cases; Swift Concurrency guidance preserved Swift6/defaultIsolation(nil)/MemberImportVisibility and synchronous ownership. No local Swift/Xcode build/tests/native fixtures, storage/protection/auth/hardware actions or agents.
The previous EOF-test correction01693035 remains intact: actual nonblocking EOF required, EAGAIN rejected, five control cases; no production process timing change. That head's newly selected Cloud106435043141/build0474e200-e8f6-43ee-8566-e1ab0d7522ac/action9c9852d8-6e01-4e7c-9758-0bd8d4b28b4e failed generically in ci_pre_xcodebuild.sh(errors1/testFailures0), annotations[]complete. This establishes neither a compile/test cause nor success/failure of the EOF correction.
17:26 all-open audit45=15active+30drafts, main/featureaggregate/heads unchanged before this correction, MERGEABLE/SUBSCRIBED. All matching edited summaries Completed;14originalthumbsups,217newfinding/noapproval. Full contexts/comments/original reactions/inline AND standalone/reviews/inner pages complete; no other new findings. Twelve old failed checks unchanged/notrefetched;208/223unregistered. #223cachedbase0a1bbf7f remains behind217;219cachedbase3f0bf2b7 remains behind207. No settled-composition claim.
Necessary17:33postpush:217exactheadc3c2e8dc/basefd83eb21/MERGEABLE verified; Cloud106442505019 IN_PROGRESS(buildbf75999f-06eb-435c-8c3e-23e2f7be4644/action94773458-8503-467f-94f7-49196bc2c228); matchingRunningeditedreview/originaleyes. Publicreply4064735955 verifiedposted; threadOPENpendingvalidation. Allconnections/innerpagescomplete; no additional bot finding. Query-format/alias errors returned no data and were corrected; no uncertain writes.
All descendants unchanged; they do NOT inherit either new217commit. Validate217, then integrate parent-to-child and revalidate each child; no approval-only push or manual retry. Main d4b6dac and featureaggregate fd83eb2 unchanged. Main includes204, NOT feature-merged216/205/206. Reviewed composition recovery, settledmain/retargeting, exact-head Cloudgreen/review/no-unaddressed-findings and owner-only merges remain required. No remote merge/retarget/forcepush/history deletion.
#8CLOSED is not full persistence acceptance;76/retained57OPEN. Prior findings remain implemented/pendingnative, not waived. Outstanding215hook-logrequest remains outstanding and must NOT be repeated; suppliedlogsreceived. Separate219deadlinefailures and generic hook causes remain undiagnosed. NEXT: inspect CURRENT rollups once; preserve all EOF/capacity/journal cases; no source redo, speculative timing change or localnativeexecution.
Prior implementation record (descendant sources unchanged; #217 superseded above)
September 21, 13:46 UTC — independent prior-history verification coverage published; native validation pending.
Implemented #218 PRRT_kwDOUMu8ss6kXlZn/discussion4062586467 inb8de12e4. The original six length/appended-range cases remain; three priorHistory cases now exercise write/file-barrier/directory-barrier boundaries. An independent non-O_APPEND descriptor overwrites ONLY the prior record with a same-length valid alternative, while the production O_APPEND descriptor writes the exact expected new line. Exact whole-file assertions establish unchanged total length/appended range. Prior-history cases require journalWriteUncertain(fileUnreadable), distinguishing the full-prefix check from later fileUnwritable timestamp checks. Restore original bytes BEFORE any replay, then repeated original/peer/later-owner refusal, byte preservation and exactly one write attempt. Publicreply4062693781 verifiedCOMMENTED; threadOPENpendingvalidation.
Atomic6branchpush13:43UTC succeeded, normal parent→child merges. Expected209test-subset conflict resolved retaining every prior test plus the strengthened matrix. All6worktreesclean/source+integrationdiffchecks/sevenmockedshellhookscenariosPASS each. Every descendant integration is exactly25adds6dels inonejournaltestfile; no production change. SwiftTesting expectation/parameterization/isolation guidance used. NOlocalSwift/Xcodecompile/tests/nativefixtures/storage/protection/auth/hardware oragents.218scope423adds;209486/210386/211241;212schema3selectiondeltaunchanged. Nineotheractiveheadsuntouched, including214. No newPR/retarget/remotemerge/forcepush/historydeletion.
Prior 13:39/13:44 validation snapshots are superseded by the complete audit above.
Prior corrections remain inherited andOPENpendingvalidation:214throwing-journalbinding2dfa7784 with218sixreplacementcases63663eeb;210explicitpoisoned-ownerlifetime69e3e081;214directorythrowbinding1405460f;209independentnonappendoverwritefixturedd461aed;214O_APPEND573948d1;223256managed/4096totalentryreservationa79e9598 with retainedquarantine/no deletion/rollback/disposalAPI; postwritecheckingEvidence/requiredexistingENOENTlatches; sharedprocesslocaljournalleases; perownerstalesnapshotguard; globalcompletioncapacity/boundeddatework; readonlypreopen/rootversion; unknown-placementemptyintermediate; directshrink.204O_RDONLYsynchronization dispute separate. No reset/secondstore/sameuserraceimmunity/crossprocessregistryguarantee.
Outstanding215hooklogrequest since07:48 remains build93263602-eaf5-4fa6-8200-4644452616c4/action8b96f84e-c222-40e6-b680-2d53d73cea94/check106230662815; DO NOTrepeat. Allsupplied1671/1769/1876/1896/1906logsreceived. Unchangedgeneric207106341676509/215106342651140/222106344126374 and221106338827512 failures stillunknowncause, annotationsalreadycomplete[].2170a1bbf7f/check106319005162 native2OwnedChilddrainfailures lacks219laterdiagnostics; retained-writertext proves neitherleak norschedulingcause.219ca143f7b/check106250882489 native2deadlinefailures3.388842333s/4.820625875s unchanged. MissingACL/EOFfailureinonerun isnotfixproof. Testcoveragecorrection isnotgenericCI/process-timingdiagnosis; no priority/serialization/deadlinerelaxation.
Main d4b6dac includes204, NOT216/205/206, which remain owner-feature-merged into mvp/state-file-access fd83eb2.217targetsaggregate. Reviewedcompositionrecoveryrequired; preservecode/history, noautomaticaggregateacceptance/assistantmerge. Owneralreadywarned; don'trepeatunchangedpausewarning. Owneralone mergesintomainafterpredecessorlanding/retarget/settledexactheadCloud+review+findingsgates.
#8CLOSEDvia192notfullpersistenceacceptance;76/retained57OPEN.6/187/10/60acceptedclosedscopes,197/198mergeddon'tpoll. Runtimevolumeestablishment/loading/actualinspectedsettlement/durablepublication-before-runtimeackunfinished; productionruntimeVersion-only/refuseshostPreflight/no secondstore. Thirtylegacydraftspreserved. MorningSept20checkpointdelivered,don'trepeat.
NEXT: followCURRENTexactheadCloud/review/findings withcompletepagination.218prior-historycoverageisimplemented, notuntouched. Preserveallninecases. No originalcommits/merges/pushredo, approval-onlyrerun, repeatedlogrequest orlocalnativeexecution.
Historical preparation — superseded by the current status above
Migration status — September 10, 2026
Prepared persistence recovery coverage — September 10, 2026, 10:44 UTC: Ordinary forward integration of the approved provisioning contract and prepared checkpoint-serialization test is complete through all sixteen existing persistence branches. Runtime append/begin is now d9e2a634d5fd6bcee0eb5e8f9e42df73c9ee8daf; the test-only mvp/state-store-journal-recovery head is 109289dfd45f4ed4efeb9b0364f38d2619507fcd. Its delta remains two files/364 additions: four actual-store high/final snapshot-counter cases and eleven journal recovery functions/33 cases, including append/restored-record rejection for conflicting operation, stage and environment identities. Each merge preserved its existing feature delta byte-for-byte and added exactly the same inspected three-file correction; no persistence behavior or regression assertion was removed. Source/diff checks and all seven shell-only CI-hook scenarios pass. These composed heads remain unpublished, with no Swift/Xcode compilation, package-test run or Cloud validation. This is completed source composition, not completed StateStore migration or hardware proof. Reuse these branches for eventual focused origin/Cloud publication; do not repeat the integration or grow the current five-PR owner-merge queue. No issue closure, host/VM procedure or new build cache.
Latest local integration — September 10, 2026, 07:08 UTC: The prepared provisioning/persistence chain now includes the reviewed #165/#166 fixes and the checked-counter reducer/recovery follow-ups through mvp/state-store-replay at a9a7d835503e99717947440e9f3b48b1ff563ba5. Snapshot models (7f0bbe76) no longer apply the obsolete reduced counter ceiling; tests avoid overflowing their own fixtures and cover large/final counters, malformed persisted values, outstanding token identity, and byte-preserving current-schema migration (077cc65a). These new local heads have source/diff checks only: no fresh compilation, test run, Cloud result, push, or PR. Historical test totals below apply only to their named older heads. Actual StateStore append/begin, uncertain-write classification, durable cache adoption, and the remaining store-level regressions are still unfinished. Publication uses focused origin pushes and Xcode Cloud under the owner's instruction; the approved #165 → #166 chain and independent #167 remain the current merge queue.
This is an active shared migration requirement, not a reason to wait for Tart lifecycle #73. The concrete StateStore is absent from current main; #57 preserves its unmerged implementation. RuntimeKit already exists on main. The relevant prerequisites are the provider-neutral records/checkpoints in #6/#8 and reviewed private storage in #22 (#164 and its prepared follow-up), ordered through #48.
When migrating #57, place the actor and filesystem tests in GuesthouseRuntimeKit from the outset. Keep shared records and pure validation/migration/replay contracts in Core, with ADR 0003's closed failures and fixed messages. The GUI must not link RuntimeKit or receive an arbitrary root/command API. No intermediate Core filesystem implementation or Tart merge is required.
Preserve existing filesystem safety and durability behavior while adapting obsolete error/record contracts explicitly; do not treat “no behavior change” in the historical task as permission to reintroduce raw-text diagnostics or incompatible schema handling. #8 records the retained source/tests and adaptation requirements.
Shared record/snapshot/migration/history/framing prerequisites are now implemented and validated locally through 73fc5389. The first concrete RuntimeKit extraction follows at 1733ba5ab46652dd823f7b434e45f11d9b871b38 (mvp/state-file-io): retained descriptor reads/writes, advisory locks, flush policy and file identity/version snapshots, with closed logical file labels and twenty isolated IO tests. All 708 strict package functions, focused Debug/Release IO tests, seven hook scenarios and the unsigned shared-scheme test build pass locally.
The descriptor-protection follow-up is also locally validated at e8ab23afd7e9bb1058b07bb6a12a82b55a64de80 (mvp/state-file-protection): exact private modes, owner/kind/link checks, ACL inspection/clearing, mandatory repair barriers and post-barrier verification. All 724 strict package functions, 36 focused Debug/Release IO/protection functions, seven hook scenarios and the unsigned shared-scheme test build pass. Sixteen new functions adapt descriptor-level permission/durability behavior; original actor/read-path coverage remains required.
The fixed state-directory owner now follows locally at d86a12dbd6e9e9b6e714e628221ac4fbbaa5e452 (mvp/state-directory-anchor). This 315-line extraction retains exactly-once descriptor lifetime, current managed-path/protection checks and optional publication-version checks for same-inode reattachment. All 739 strict package functions, fifteen focused Debug anchor functions, 51 focused Release persistence functions, seven hook scenarios and the unsigned shared-scheme test build pass.
These low-level components are not the actor or a transactional store. Construction still creates no state files and remains read-only. Explicit preparation barriers now follow locally at 4dbd478f5581c3b794e5ff4625b0521fcf93d2b2 (mvp/state-directory-durability): the state directory plus physical and lexical ancestor synchronization, repeated after failures, with current binding/protection checks and preservation of existing work. All 751 strict package functions, twelve focused Debug durability functions, 63 focused Release persistence functions, seven hook scenarios and the unsigned shared-scheme test build pass.
Fixed state-file access now follows locally at 25fba3c7c27320c8ea2ec687e5f9f83b25e137f4 (mvp/state-file-access), in 368 added lines. Snapshot/journal names and modes are closed, descriptors are scoped, and an exclusive advisory lock spans protection, work and post-checks, including read-side metadata repair. All 767 strict package functions, sixteen focused Debug file-access functions, 79 focused Release persistence functions, seven hook scenarios and the unsigned shared-scheme test build pass.
Atomic snapshot publication now follows locally at c7bec9fa4612fd4e63b921df884c1986ecc8dcbe (mvp/snapshot-publication), in 448 added lines. It validates the new value and existing saved format before replacement, uses an exclusively created/atomically locked private temporary, retains file and directory barriers plus current-entry/version checks, and preserves evidence after any failure. Unsupported atomic locking is refused rather than falling back to an unlocked creation window. All 786 strict package functions, nineteen focused Debug publication functions, 98 focused Release persistence functions, seven hook scenarios and the unsigned shared-scheme test build pass. This component deliberately leaves stale and live temporaries intact pending the verified collector.
Verified stale-temporary collection now follows locally at f82a384cc1735d7bcd98faabecfa4b257b227c80 (mvp/snapshot-temporaries), with 342 additions / five deletions across four files. Publication validates the value and saved format before collecting only exact private UUID temporary files under a nonblocking exclusive lock. Live writers, suspicious entries and unsupported saved-state evidence are preserved; current directory/snapshot/file checks precede deletion. All 799 strict package functions, 32 focused Debug snapshot functions, 111 focused Release persistence functions, seven hook scenarios and the unsigned shared-scheme build pass. No failed write's temporary is deleted on its error path.
The runtime-owned snapshot actor now follows locally at fc8f36e6922b798acc6aef3a67a7273e253108f4 (mvp/state-store-snapshots): three files / 396 additions. Its async factory chooses fixed managed storage, completes preparation before returning, and exclusively transfers the directory owner into an actor backed by the SDK's native Dispatch serial executor. Load/save use the verified helpers without suspension; no GUI-selected root/file API is added. All 818 strict package functions, nineteen focused Debug/Release/Thread Sanitizer functions, seven hook scenarios and the unsigned shared-scheme test build pass. Actor tests cover lifetime, off-MainActor work, serialized/canceled calls, format preservation, failure evidence and reattachment. No production caller or journal API is activated.
Locked journal replay/cache now follows locally at 8abf6cb4080b39255b0b3637d8be5ebe9c9ab073 (mvp/state-store-replay): three files / 366 additions / one deletion. The actor adopts parsed history only after the complete protected file/directory borrow succeeds, invalidates on failures/missing files, and retains distinct torn/unterminated-tail behavior with version/identity/size-based cache checks. All 835 strict package functions, seventeen focused Debug replay functions, 36 Release/Thread Sanitizer actor functions, seven hook scenarios and the unsigned shared-scheme build pass. Replay preserves journal bytes and returns observed records, not durable mutation authority.
Journal append/begin, durable cache adoption, uncertain-write handling and the remaining retained store-level tests still need migration and validation. Fixed-file access does not validate or publish a journal record; the future actor must classify all post-attempt failures as uncertain and commit cached state only after the entire transaction succeeds. These startup barriers do not make other managed areas or VMs ready. Borrowed descriptor helpers do not grant the GUI host authority or prove crash durability. No replacement PR is published for this local slice yet; #48 preserves the small active queue. This progress does not satisfy #76.
No concrete store implementation is claimed complete. Close #76 only when the concrete store/tests actually live in RuntimeKit, the scheme/CI covers them, the GUI boundary remains intact, and the reviewed replacement is merged. The historical prerequisite below is superseded by this status.
Why
StateStore (atomic snapshot, append-only journal, file permissions) lives in Packages/GuesthouseCore, which is linked into the sandboxed GUI as well as the runtime service. Only the runtime instantiates it, but MVP-PLAN.md §3 places host-mutating code behind the execution boundary, and a review of #57 asked for the concrete store to live with the runtime.
It could not move during the stacked series because the runtime package (GuesthouseRuntimeKit, #69) is introduced after the store (#57).
Task
- Move
StateStore (the actor and its file operations) and StateStoreTests from GuesthouseCore/Persistence to GuesthouseRuntimeKit.
- Keep the shared models (
EnvironmentsSnapshot, JournalRecord, JournalReplay, JournalOperation, SnapshotMigrator, StateStoreError) in GuesthouseCore, since the GUI decodes what the runtime reports.
- No behavior change; all existing tests pass.
Depends on the stacked series through #73 being merged.
Current implementation — October 1, 2026 (Pacific)
Main
a55e83e8includes ADR 0004 bounded single-writer persistence, runtime startup/loading, retained volume identity, fresh native preflight, app checks/Start coordination, workspace metadata foundations and owner-merged #258–#263 progress/cancellation/diagnostics/export. Source-head Cloud and matching clean automated reviews passed before merge. Strict package hook passes 1,244 tests; composed app suite passes 78.#272 blocks an empty save from erasing unknown placement evidence before fresh volume selection. Its regression failed before the correction; repeated refusal, byte preservation, nonempty edits and reopening pass. #272 is merged and retained #212 closed after its replacement audit. No peer observation registry, automatic repair or lossless power-failure guarantee was added.
BOTH native missing-target findings on merged #258 remain unresolved under #24/#32/#76/#82. GUI unknown outcomes are preserved; the native inspector cannot prove omitted saved metadata means stopped. Provider inventory/adoption, identity persistence before started acknowledgment, real capability producers and explicit metadata repair remain unfinished. Production mutations stay disabled. The unchanged strictly rejected Lume artifact is not executed; provider/owner/human gates remain real dependencies. Prior history follows.
Current persistence tracking — September 21, 17:34 UTC
September 21, 17:34 UTC — #217 publication-capacity finding corrected on its own head; native validation pending.
Implemented PRRT_kwDOUMu8ss6kcyxH/discussion4064633345 in c3c2e8d. Brought the existing #223 reservation algorithm forward into #217: reserve one managed-name slot AND one total-directory-entry slot before collection/creation; standalone collection retains full bounds. Four isolated managed-name/total-entry cases verify full-inventory refusal before eligible evidence removal or temporary creation, unchanged bytes/inventory, exact-bound standalone admission, and one failed publication followed by repeated/reopened refusal before any second slot is consumed. #223 retains quarantine behavior and its broader tests; no child was merged into a feature base.
Only #217 pushed (17:32 UTC). Own correction: 3 files,61 additions/6 deletions. Full217scope8files535adds35dels; coherent safety/test corrections retained, above the approximate500-line preference. Diff checks and seven mocked shell-hook scenarios PASS; worktree clean. Swift Testing guidance shaped exact errors/isolated parameterized cases; Swift Concurrency guidance preserved Swift6/defaultIsolation(nil)/MemberImportVisibility and synchronous ownership. No local Swift/Xcode build/tests/native fixtures, storage/protection/auth/hardware actions or agents.
The previous EOF-test correction01693035 remains intact: actual nonblocking EOF required, EAGAIN rejected, five control cases; no production process timing change. That head's newly selected Cloud106435043141/build0474e200-e8f6-43ee-8566-e1ab0d7522ac/action9c9852d8-6e01-4e7c-9758-0bd8d4b28b4e failed generically in ci_pre_xcodebuild.sh(errors1/testFailures0), annotations[]complete. This establishes neither a compile/test cause nor success/failure of the EOF correction.
17:26 all-open audit45=15active+30drafts, main/featureaggregate/heads unchanged before this correction, MERGEABLE/SUBSCRIBED. All matching edited summaries Completed;14originalthumbsups,217newfinding/noapproval. Full contexts/comments/original reactions/inline AND standalone/reviews/inner pages complete; no other new findings. Twelve old failed checks unchanged/notrefetched;208/223unregistered. #223cachedbase0a1bbf7f remains behind217;219cachedbase3f0bf2b7 remains behind207. No settled-composition claim.
Necessary17:33postpush:217exactheadc3c2e8dc/basefd83eb21/MERGEABLE verified; Cloud106442505019 IN_PROGRESS(buildbf75999f-06eb-435c-8c3e-23e2f7be4644/action94773458-8503-467f-94f7-49196bc2c228); matchingRunningeditedreview/originaleyes. Publicreply4064735955 verifiedposted; threadOPENpendingvalidation. Allconnections/innerpagescomplete; no additional bot finding. Query-format/alias errors returned no data and were corrected; no uncertain writes.
All descendants unchanged; they do NOT inherit either new217commit. Validate217, then integrate parent-to-child and revalidate each child; no approval-only push or manual retry. Main d4b6dac and featureaggregate fd83eb2 unchanged. Main includes204, NOT feature-merged216/205/206. Reviewed composition recovery, settledmain/retargeting, exact-head Cloudgreen/review/no-unaddressed-findings and owner-only merges remain required. No remote merge/retarget/forcepush/history deletion.
#8CLOSED is not full persistence acceptance;76/retained57OPEN. Prior findings remain implemented/pendingnative, not waived. Outstanding215hook-logrequest remains outstanding and must NOT be repeated; suppliedlogsreceived. Separate219deadlinefailures and generic hook causes remain undiagnosed. NEXT: inspect CURRENT rollups once; preserve all EOF/capacity/journal cases; no source redo, speculative timing change or localnativeexecution.
Prior implementation record (descendant sources unchanged; #217 superseded above)
September 21, 13:46 UTC — independent prior-history verification coverage published; native validation pending.
Implemented #218 PRRT_kwDOUMu8ss6kXlZn/discussion4062586467 inb8de12e4. The original six length/appended-range cases remain; three priorHistory cases now exercise write/file-barrier/directory-barrier boundaries. An independent non-O_APPEND descriptor overwrites ONLY the prior record with a same-length valid alternative, while the production O_APPEND descriptor writes the exact expected new line. Exact whole-file assertions establish unchanged total length/appended range. Prior-history cases require journalWriteUncertain(fileUnreadable), distinguishing the full-prefix check from later fileUnwritable timestamp checks. Restore original bytes BEFORE any replay, then repeated original/peer/later-owner refusal, byte preservation and exactly one write attempt. Publicreply4062693781 verifiedCOMMENTED; threadOPENpendingvalidation.
Atomic6branchpush13:43UTC succeeded, normal parent→child merges. Expected209test-subset conflict resolved retaining every prior test plus the strengthened matrix. All6worktreesclean/source+integrationdiffchecks/sevenmockedshellhookscenariosPASS each. Every descendant integration is exactly25adds6dels inonejournaltestfile; no production change. SwiftTesting expectation/parameterization/isolation guidance used. NOlocalSwift/Xcodecompile/tests/nativefixtures/storage/protection/auth/hardware oragents.218scope423adds;209486/210386/211241;212schema3selectiondeltaunchanged. Nineotheractiveheadsuntouched, including214. No newPR/retarget/remotemerge/forcepush/historydeletion.
Prior 13:39/13:44 validation snapshots are superseded by the complete audit above.
Prior corrections remain inherited andOPENpendingvalidation:214throwing-journalbinding2dfa7784 with218sixreplacementcases63663eeb;210explicitpoisoned-ownerlifetime69e3e081;214directorythrowbinding1405460f;209independentnonappendoverwritefixturedd461aed;214O_APPEND573948d1;223256managed/4096totalentryreservationa79e9598 with retainedquarantine/no deletion/rollback/disposalAPI; postwritecheckingEvidence/requiredexistingENOENTlatches; sharedprocesslocaljournalleases; perownerstalesnapshotguard; globalcompletioncapacity/boundeddatework; readonlypreopen/rootversion; unknown-placementemptyintermediate; directshrink.204O_RDONLYsynchronization dispute separate. No reset/secondstore/sameuserraceimmunity/crossprocessregistryguarantee.
Outstanding215hooklogrequest since07:48 remains build93263602-eaf5-4fa6-8200-4644452616c4/action8b96f84e-c222-40e6-b680-2d53d73cea94/check106230662815; DO NOTrepeat. Allsupplied1671/1769/1876/1896/1906logsreceived. Unchangedgeneric207106341676509/215106342651140/222106344126374 and221106338827512 failures stillunknowncause, annotationsalreadycomplete[].2170a1bbf7f/check106319005162 native2OwnedChilddrainfailures lacks219laterdiagnostics; retained-writertext proves neitherleak norschedulingcause.219ca143f7b/check106250882489 native2deadlinefailures3.388842333s/4.820625875s unchanged. MissingACL/EOFfailureinonerun isnotfixproof. Testcoveragecorrection isnotgenericCI/process-timingdiagnosis; no priority/serialization/deadlinerelaxation.
Main d4b6dac includes204, NOT216/205/206, which remain owner-feature-merged into mvp/state-file-access fd83eb2.217targetsaggregate. Reviewedcompositionrecoveryrequired; preservecode/history, noautomaticaggregateacceptance/assistantmerge. Owneralreadywarned; don'trepeatunchangedpausewarning. Owneralone mergesintomainafterpredecessorlanding/retarget/settledexactheadCloud+review+findingsgates.
#8CLOSEDvia192notfullpersistenceacceptance;76/retained57OPEN.6/187/10/60acceptedclosedscopes,197/198mergeddon'tpoll. Runtimevolumeestablishment/loading/actualinspectedsettlement/durablepublication-before-runtimeackunfinished; productionruntimeVersion-only/refuseshostPreflight/no secondstore. Thirtylegacydraftspreserved. MorningSept20checkpointdelivered,don'trepeat.
NEXT: followCURRENTexactheadCloud/review/findings withcompletepagination.218prior-historycoverageisimplemented, notuntouched. Preserveallninecases. No originalcommits/merges/pushredo, approval-onlyrerun, repeatedlogrequest orlocalnativeexecution.
Historical preparation — superseded by the current status above
Migration status — September 10, 2026
Prepared persistence recovery coverage — September 10, 2026, 10:44 UTC: Ordinary forward integration of the approved provisioning contract and prepared checkpoint-serialization test is complete through all sixteen existing persistence branches. Runtime append/begin is now
d9e2a634d5fd6bcee0eb5e8f9e42df73c9ee8daf; the test-onlymvp/state-store-journal-recoveryhead is109289dfd45f4ed4efeb9b0364f38d2619507fcd. Its delta remains two files/364 additions: four actual-store high/final snapshot-counter cases and eleven journal recovery functions/33 cases, including append/restored-record rejection for conflicting operation, stage and environment identities. Each merge preserved its existing feature delta byte-for-byte and added exactly the same inspected three-file correction; no persistence behavior or regression assertion was removed. Source/diff checks and all seven shell-only CI-hook scenarios pass. These composed heads remain unpublished, with no Swift/Xcode compilation, package-test run or Cloud validation. This is completed source composition, not completed StateStore migration or hardware proof. Reuse these branches for eventual focused origin/Cloud publication; do not repeat the integration or grow the current five-PR owner-merge queue. No issue closure, host/VM procedure or new build cache.Latest local integration — September 10, 2026, 07:08 UTC: The prepared provisioning/persistence chain now includes the reviewed #165/#166 fixes and the checked-counter reducer/recovery follow-ups through
mvp/state-store-replayata9a7d835503e99717947440e9f3b48b1ff563ba5. Snapshot models (7f0bbe76) no longer apply the obsolete reduced counter ceiling; tests avoid overflowing their own fixtures and cover large/final counters, malformed persisted values, outstanding token identity, and byte-preserving current-schema migration (077cc65a). These new local heads have source/diff checks only: no fresh compilation, test run, Cloud result, push, or PR. Historical test totals below apply only to their named older heads. Actual StateStore append/begin, uncertain-write classification, durable cache adoption, and the remaining store-level regressions are still unfinished. Publication uses focused origin pushes and Xcode Cloud under the owner's instruction; the approved #165 → #166 chain and independent #167 remain the current merge queue.This is an active shared migration requirement, not a reason to wait for Tart lifecycle #73. The concrete StateStore is absent from current main; #57 preserves its unmerged implementation. RuntimeKit already exists on main. The relevant prerequisites are the provider-neutral records/checkpoints in #6/#8 and reviewed private storage in #22 (#164 and its prepared follow-up), ordered through #48.
When migrating #57, place the actor and filesystem tests in GuesthouseRuntimeKit from the outset. Keep shared records and pure validation/migration/replay contracts in Core, with ADR 0003's closed failures and fixed messages. The GUI must not link RuntimeKit or receive an arbitrary root/command API. No intermediate Core filesystem implementation or Tart merge is required.
Preserve existing filesystem safety and durability behavior while adapting obsolete error/record contracts explicitly; do not treat “no behavior change” in the historical task as permission to reintroduce raw-text diagnostics or incompatible schema handling. #8 records the retained source/tests and adaptation requirements.
Shared record/snapshot/migration/history/framing prerequisites are now implemented and validated locally through
73fc5389. The first concrete RuntimeKit extraction follows at1733ba5ab46652dd823f7b434e45f11d9b871b38(mvp/state-file-io): retained descriptor reads/writes, advisory locks, flush policy and file identity/version snapshots, with closed logical file labels and twenty isolated IO tests. All 708 strict package functions, focused Debug/Release IO tests, seven hook scenarios and the unsigned shared-scheme test build pass locally.The descriptor-protection follow-up is also locally validated at
e8ab23afd7e9bb1058b07bb6a12a82b55a64de80(mvp/state-file-protection): exact private modes, owner/kind/link checks, ACL inspection/clearing, mandatory repair barriers and post-barrier verification. All 724 strict package functions, 36 focused Debug/Release IO/protection functions, seven hook scenarios and the unsigned shared-scheme test build pass. Sixteen new functions adapt descriptor-level permission/durability behavior; original actor/read-path coverage remains required.The fixed state-directory owner now follows locally at
d86a12dbd6e9e9b6e714e628221ac4fbbaa5e452(mvp/state-directory-anchor). This 315-line extraction retains exactly-once descriptor lifetime, current managed-path/protection checks and optional publication-version checks for same-inode reattachment. All 739 strict package functions, fifteen focused Debug anchor functions, 51 focused Release persistence functions, seven hook scenarios and the unsigned shared-scheme test build pass.These low-level components are not the actor or a transactional store. Construction still creates no state files and remains read-only. Explicit preparation barriers now follow locally at
4dbd478f5581c3b794e5ff4625b0521fcf93d2b2(mvp/state-directory-durability): the state directory plus physical and lexical ancestor synchronization, repeated after failures, with current binding/protection checks and preservation of existing work. All 751 strict package functions, twelve focused Debug durability functions, 63 focused Release persistence functions, seven hook scenarios and the unsigned shared-scheme test build pass.Fixed state-file access now follows locally at
25fba3c7c27320c8ea2ec687e5f9f83b25e137f4(mvp/state-file-access), in 368 added lines. Snapshot/journal names and modes are closed, descriptors are scoped, and an exclusive advisory lock spans protection, work and post-checks, including read-side metadata repair. All 767 strict package functions, sixteen focused Debug file-access functions, 79 focused Release persistence functions, seven hook scenarios and the unsigned shared-scheme test build pass.Atomic snapshot publication now follows locally at
c7bec9fa4612fd4e63b921df884c1986ecc8dcbe(mvp/snapshot-publication), in 448 added lines. It validates the new value and existing saved format before replacement, uses an exclusively created/atomically locked private temporary, retains file and directory barriers plus current-entry/version checks, and preserves evidence after any failure. Unsupported atomic locking is refused rather than falling back to an unlocked creation window. All 786 strict package functions, nineteen focused Debug publication functions, 98 focused Release persistence functions, seven hook scenarios and the unsigned shared-scheme test build pass. This component deliberately leaves stale and live temporaries intact pending the verified collector.Verified stale-temporary collection now follows locally at
f82a384cc1735d7bcd98faabecfa4b257b227c80(mvp/snapshot-temporaries), with 342 additions / five deletions across four files. Publication validates the value and saved format before collecting only exact private UUID temporary files under a nonblocking exclusive lock. Live writers, suspicious entries and unsupported saved-state evidence are preserved; current directory/snapshot/file checks precede deletion. All 799 strict package functions, 32 focused Debug snapshot functions, 111 focused Release persistence functions, seven hook scenarios and the unsigned shared-scheme build pass. No failed write's temporary is deleted on its error path.The runtime-owned snapshot actor now follows locally at
fc8f36e6922b798acc6aef3a67a7273e253108f4(mvp/state-store-snapshots): three files / 396 additions. Its async factory chooses fixed managed storage, completes preparation before returning, and exclusively transfers the directory owner into an actor backed by the SDK's native Dispatch serial executor. Load/save use the verified helpers without suspension; no GUI-selected root/file API is added. All 818 strict package functions, nineteen focused Debug/Release/Thread Sanitizer functions, seven hook scenarios and the unsigned shared-scheme test build pass. Actor tests cover lifetime, off-MainActor work, serialized/canceled calls, format preservation, failure evidence and reattachment. No production caller or journal API is activated.Locked journal replay/cache now follows locally at
8abf6cb4080b39255b0b3637d8be5ebe9c9ab073(mvp/state-store-replay): three files / 366 additions / one deletion. The actor adopts parsed history only after the complete protected file/directory borrow succeeds, invalidates on failures/missing files, and retains distinct torn/unterminated-tail behavior with version/identity/size-based cache checks. All 835 strict package functions, seventeen focused Debug replay functions, 36 Release/Thread Sanitizer actor functions, seven hook scenarios and the unsigned shared-scheme build pass. Replay preserves journal bytes and returns observed records, not durable mutation authority.Journal append/begin, durable cache adoption, uncertain-write handling and the remaining retained store-level tests still need migration and validation. Fixed-file access does not validate or publish a journal record; the future actor must classify all post-attempt failures as uncertain and commit cached state only after the entire transaction succeeds. These startup barriers do not make other managed areas or VMs ready. Borrowed descriptor helpers do not grant the GUI host authority or prove crash durability. No replacement PR is published for this local slice yet; #48 preserves the small active queue. This progress does not satisfy #76.
No concrete store implementation is claimed complete. Close #76 only when the concrete store/tests actually live in RuntimeKit, the scheme/CI covers them, the GUI boundary remains intact, and the reviewed replacement is merged. The historical prerequisite below is superseded by this status.
Why
StateStore(atomic snapshot, append-only journal, file permissions) lives inPackages/GuesthouseCore, which is linked into the sandboxed GUI as well as the runtime service. Only the runtime instantiates it, butMVP-PLAN.md§3 places host-mutating code behind the execution boundary, and a review of #57 asked for the concrete store to live with the runtime.It could not move during the stacked series because the runtime package (
GuesthouseRuntimeKit, #69) is introduced after the store (#57).Task
StateStore(the actor and its file operations) andStateStoreTestsfromGuesthouseCore/PersistencetoGuesthouseRuntimeKit.EnvironmentsSnapshot,JournalRecord,JournalReplay,JournalOperation,SnapshotMigrator,StateStoreError) inGuesthouseCore, since the GUI decodes what the runtime reports.Depends on the stacked series through #73 being merged.