Repository navigation
Verify Ace with two machines on the tailnet #10
Description
Activity
- added a parent issue
on Oct 4, 2026 October 7 two-person checklist: combined candidate
Candidate: commit
2ca21608ad402da796e6399317ed93ce204288d5on test branchcodex/team-dogfood-integration, Canary 0.0.15 (no version bump), publishing off. No signed installer exists for it.- Run 37538321016 was cancelled at the user's request during app notarization. There had been about 14 minutes with no output; see Show desktop release phases and notarization submissions while a build runs #167.
- Retry 37540590863 failed in the first of two notarizations: the app ZIP, at
release.ts:135. Submission697b5f49-4827-4e50-83e2-4e3f80a6ec0dreachednotarytool's 1200-second wait timeout before processing completed. It was a timeout, not a rejection, and its later status at Apple is unknown. Publishing was skipped and the run has no artifacts. Details are on #167.
That commit is the original base
6dc0f1cplus these exact heads, all merged cleanly with no integration patches:- feat(app): group projects by repository with teammate channel sections #157
54e2bc1: project and teammate grouping - fix(host): recover open transcript watches after channel workers restart #159
a476c32: watch recovery and the delete race (Reattach the open chat watch after its channel worker restarts #153) - feat(host): let agents discover and message channels on peer hosts #160
14c6923: peer messaging (Let agents discover and message channels on peer hosts #57) - feat(app): add channel header agent and desktop access toggles #161
b30e9f6: collaborator invocation UI and events - fix(ui): keep unsent composer drafts across restart #165
cf89a0f: persistent drafts (Verify unsent composer drafts survive a signed desktop quit and relaunch #77)
Since then, #157, #159 and #165 have been merged to main at these same heads (not by this check). #160 and #161 are still open drafts.
Solo checks passed on Oct 6 (one host, owner only)
- Static checks:
bun typesandbun run cipass on the combined tree. - Transport (raw watcher events, real workers,
claude-haiku-4-5):- With sharing off, an agent's say posts and its invoke is refused. After the owner turns sharing on, the invoke runs.
- Watchers receive
sharedchanges live. After a worker kill (including mid-run), a crash, and a host restart or crash, they get a complete, consistent replay and later events. host.sockis reclaimed after a crash. The CLI-only fallback still enforces the destination sharing setting.
- Mounted app (two owner contexts on one gateway):
- A real socket close followed by a sharing change, and a durable worker kill: the open page catches up without reload, showing each message and the model reply once.
- Agent say and invoke with sharing off, then on. The author is stamped
agent.<source channel id>@<login>. - Drafts (Unicode, multiline, formatted) restore after a quick page close and reopen; each chat and the dashboard keep only their own; Send without a provider is blocked and keeps the draft; a sent message's text is cleared.
- Deleting a selected channel: no worker restart, no storage errors. A later agent message to the deleted channel is refused.
- See each PR's own validation: fix(host): recover open transcript watches after channel workers restart #159, feat(app): add channel header agent and desktop access toggles #161, fix(ui): keep unsent composer drafts across restart #165.
- Not covered solo: a second host or login, peer paths, and teammate-only views. A native attempt at this commit rendered the dashboard pixels, but exact-target automation was too limited to gain native draft, sharing or grouping acceptance (#73 comment). Native acceptance stays manual tomorrow (items 1, 4 and 8 below). Hosted channels are not covered either; their outbound messaging is tracked separately in [Meta] Run hosted channels in the cloud with local workspaces #13.
Two-person and native acceptance (in order)
-
Install: this needs a signed, notarized build. None exists yet, so this step and the native items are blocked until one does. When there is one, check its DMG SHA-256 against its
release.json. Then install it manually per docs/updates.md: stop Ace Helper before replacing the existing app, then reopen Ace. Settings → Updates confirms only the version. Both Macs must be on the same team tailnet, with Ace Helper running. -
Grouping (feat(app): group projects by repository with teammate channel sections #157): each host lists the other's channels. The shared repository shows as one project, under the right teammate's section. Create and Archive inactive act only on your own host.
-
Identity: each person's messages show their own Tailscale login. Channel details show the right owner, and avatars match each GitHub login.
-
Sharing (feat(app): add channel header agent and desktop access toggles #161): with sharing off, the teammate sees the read-only state live. Their Ace/@ace draft is held with its attachment, Switch to Chat works, and plain chat posts. Their invoke is refused with no run. With sharing on, their invoke runs on the owner's host.
-
Content: post text and an image in each other's channels. Ask an agent for a one-line change in a disposable project, then open its diff from both hosts.
-
Messaging (feat(host): let agents discover and message channels on peer hosts #160, Let agents discover and message channels on peer hosts #57): A's agent runs
channelsand sees B's channel with its id, host, owner, state and project. It messages B's channel by id, first as a say, then as an invoke.- B shows the author
agent.<A-id>@<A-login>. The invoke is refused while B's sharing is off and runs once it is on. - B's agent replies by id. After A's channel is renamed, the reply still lands.
- Interrupting A's worker during delivery causes no duplicate on replay.
- B shows the author
-
Recovery (fix(host): recover open transcript watches after channel workers restart #159, Reattach the open chat watch after its channel worker restarts #153): while each person watches the other's channel:
- kill its worker, including mid-run;
- drop Wi-Fi or Tailscale for 30 seconds or more;
- sleep and wake each Mac.
Each time, check without reloading: no duplicates, the sharing state is current, and new events arrive.
-
Drafts (fix(ui): keep unsent composer drafts across restart #165, Verify unsent composer drafts survive a signed desktop quit and relaunch #77), native: on each Mac, type a Unicode, multiline, formatted draft in a chat and on the dashboard. Quit normally and relaunch, then repeat with a quit right after typing. Both drafts come back exactly, each in its own place. A sent message clears its draft; a failed invocation keeps it.
-
Directory offline (only if a team directory is configured): channels on a sleeping or quit host show as offline. An agent's message to one of them fails without queuing anything. After wake, the channels are reachable again.
Separate follow-ups, not fixed by this candidate: #166, #162, #164. Leave this issue open until every item passes.
Verify Ace with two machines on the tailnet and the dogfooding team. The original Ace's equivalent worked; confirm this version does.
Tracked by #5. Migrated from TODO.md — Before dogfooding.