User authorizes local implementation and tests, publishing to GitHub and merge through independent protected delivery. This slice implements opt-in app profiles, encrypted durable state snapshots, a 300-second service, and audited restore. Exact live RAM/PTY or arbitrary provider sessions require app/runtime adapters and are not inferred from launch success. Test installed applications using fresh synthetic homes; do not copy real chats/credentials or close user applications.
Accepted continuation: test every installed app; all 191 discovered launchers are classified, 52 safe GUI fixtures plus Chrome/xterm assertions executed. Remaining native session assertions and full-VM service dependencies remain explicit incomplete scope; no false deep-recovery claim. Runtime metadata service installed under original user authorization.
Accepted continuation 2026-10-08: use local semcod/search over github owner/project to discover Clonerd, CloneBox and related recovery runtimes, inspect local capabilities and continue isolated restoration tests. This is within AC-03; keep implementation in this ticket and documentation in ticket-001. Planfile adapter currently terminates its session; this local record preserves intake.
Validation milestone: tests/test_local_backends.py passed 4 actual local backend fixtures against current source; tests/test_recovery.py passed 15 with 1 optional systemd skip and pinned conversational schema; tests/test_novnc.py passed 1 after fixing source-navigation/restore readiness race. Agy fixture proves synthetic ID/database/history only. Added explicit SQLite online backup paths for live committed WAL consistency and exclusions for Agy OAuth/.credentials.json. Latest wheel installed in Twinerd venv; installed-code WAL/exclusion smoke test passed and only Uncrash service restarted. Service has zero app profiles. Existing libvirt domains unchanged; owned fixture VM deleted. Publication adoption/profile blockers remain.
Accepted continuation: user requests continue, merge and tests. Combined current suite: 21 passed / 1 optional systemd skip; five local backend cases now include a real Linux/BusyBox shell and live PTY inside owned VM. Snapshot restored original environment-only variable, same shell PID and /dev/pts/0; current command verified restored state after boot, not screen replay alone. Guest never used host mounts, network or accounts. Existing libvirt domains unchanged. Publication remains incomplete: admission RECONCILE for unassigned installer payload on primary and protected Validator profile missing. Exact 118-file unchanged installer payload archived with bounded credential scan for governed handoff; no self-approval or hook bypass.
User explicitly selected real session files plus JetBrains settings through async intake. This authorizes production backup of the four narrowly filtered native profiles; synthetic test-only privacy constraints remain for tests. No provider calls or user application signals. Added compression before encryption, size-bounded two-pass restore, confined file/SQLite globs, explicit native selection preserving config backup, and start-to-start 300-second cadence accounting for capture duration. Production proposal: 16 GiB logical snapshot, 512 MiB/file, 8 GiB encrypted store, 288-count upper bound, startup restore remains disabled. Actual docs writer lease for ticket-001 expired at 18:59:44Z; stop documentation edits and preserve scoped docs follow-up for controller handoff. Actual protected deployed registry independently reobserved; semcod/uncrash still absent.
Production milestone: first native snapshot completed with four profiles, logical bytes 13066382860, encrypted bytes 3393818804. Verified encrypted manifest and sampled nonempty/online SQLite file digests per profile; never printed/deposited real content in Git. Settings-only JetBrains filters omit plugins/caches; auth credential filenames excluded. Startup restore disabled. Combined final synthetic suite: 27 passed, 1 optional service skip. Actual native start cadence still awaiting second completed capture.
Two real encrypted native snapshots completed for four selected profiles. Their start times differ by 299.997696 seconds; first logical bytes 13,066,382,860 and encrypted bytes 3,393,818,804. Five authenticated file samples passed; full production restore and provider/UI resume remain unverified. Latest combined suite: 27 passed, 1 skipped. Limit 8 GiB retains about two current full snapshots. No commit, push, PR or merge: governed adoption and protected publication profile are unresolved. Runtime source work is being explicitly handed off to the documentation ticket, with source recovery archive and fenced checkpoint retained.
User explicitly requested Rust for fast current-state snapshots, encryption disabled by default with an opt-in, and .env/.env.example configuration. Continue ticket-002 runtime/source/tests; ticket-001 serially owns package metadata/documentation/configuration template. Preserve old encrypted snapshots and source profiles. Add stable-file reuse and distinguish file state from RAM/provider recovery. Current fencing is recorded in rust-lease-receipt-20261008.
Rust milestone: source worker has no crate dependencies; uses Linux COW/kernel copies, OpenSSL SHA256/AES-GCM and optional zlib. Plain mode reuses unchanged immutable snapshot blobs; SQL images are reused only after a fresh online backup and equal digest. Physical retention counts shared inodes once. Latest suite 38 passed / 1 skipped in 52.52 s; fixture HOME and dependency paths repaired. No personal apps signalled. Explicitly hand off runtime writer to ticket-001 for packaging, documentation and .env template.
Production Rust validation: first three installed captures were refused; latest completed copy remains the earlier encrypted native snapshot. Added private hashed-source/index diagnostic receipt, without chat content or source paths. Latest bounds regression suite: 39 passed, 1 optional systemd skip. Current production performance and first plaintext success remain pending; manual diagnostic capture runs under the store lock.
Added bounded JSONL prefix capture: read the initial length, re-read that prefix when the source changed, reject changed/truncated content or replaced paths, omit a partial final line when growth was observed. Captured bytes and manifest sizes agree; compressed/encrypted modes share this path. New tests cover concurrent append in four modes and private failure diagnostics. First Rust package build in Twinerd venv could not import setuptools; offline wheel build with the existing base interpreter succeeded. Full suite and production capture are still running.
Final installed package has Rust source dfa8b39f3adf61af371d575c13cb9ce76285326931b62620e2ab7a2095a80caa; combined suite 44 passed, 1 skipped, 108.21 seconds. Automatic service snapshot 20261008T203732972964-99d61413a569 completed with 4 profiles, 13,126,729,992 logical bytes, 3775 reused files, 9.156 seconds. First copy had no reuse and took minutes; earlier timing includes lock contention, so this is the observed later capture time, not a first-copy guarantee. Two old encrypted copies remain. Full plaintext file restore is running in a private hard-linked fixture; no app processes touched. Runtime writer is explicitly handed to ticket-001 for documentation; production proof/fixture receipts may continue externally.
Final delivery reconciliation: explicit docs-to-runtime owner handoff accepted, fence 8; matching worktree/dirty state and HEAD re-observed. Full plaintext restore of final installed Rust snapshot passed for all 3,780 files, 13,126,729,992 bytes and private modes; fixture removed. SQLite corruption previously present in one Agy source remains unchanged; no provider/IDE resumption asserted. Two automatic service captures started 299.995729 seconds apart, lasting 9.156 and 23.198 seconds with 3775/3774 reused files. Service enabled with Linger=yes. Current suite 44 passed/1 skipped. Canonical .env.example staged in ticket-001; identical local projection and private .env deployed in primary. Seven compact docs pass bodies, adoption still missing. Delivery: requested Rust/plain-default/environment feature complete and locally installed; no new commit, push/PR or merge. GitHub HTTP404, missing protected publication profile and unowned governance bootstrap preserved in outbox. Final source snapshot/checkpoints precede explicit writer release.
User reports three unresponsive PyCharm windows/instances and requests reading current state, reviewing ~/close_last_pycharm.sh, multiple data protection/recovery modes and portable cloning to local Twinerd/noVNC or tom@minis over SSH. This continues unfinished AC-03. Do not close/signal IDEs or forward terminal input; inspect identities, threads, project state and descendants first. Native inspection currently finds one JVM-backed PyCharm launcher and three same-executable GLM helpers; Wayland exposes no X11 clients. Collect private diagnostics, save narrowly scoped recovery data, and add file-state export/import plus explicit recovery planning. Remote capability probe is read-only; destination question pending. Existing publication blockers remain. Fresh bounded lease fence 9 follows the previous owner’s explicit release.
Within unfinished AC-03, added durable-file relocation to fresh stores with content hashes, no key inclusion, strict archive validation, bounded SSH transfer, persisted project/process metadata and explicit X11 close fencing. Wayland refuses unverified closure. Emergency copy preserves 133 files / 86,166,986 bytes; all restored hashes and modes pass. No live JVM/PTYS restoration is claimed. Fresh isolated noVNC PyCharm stops at User Agreement; do not auto-accept. Actual user IDE and its terminal processes remain alive. Synthetic minis transfer passed; real local incident data were not transferred. Publication remains blocked by protected profile/adoption and GitHub access; no commit/push/merge.
Final incident milestone: combined tests 63 passed / 1 optional systemd skip in 77.43s. Source-matching wheel installed in Twinerd venv; first automatic five-profile plaintext Rust capture completed in 18.985s (3,786 files / 13,281,160,111 bytes), including LocalHistory and JetBrains identity metadata. Safe local close wrapper defaults to inspection; Wayland refusal verified, no user IDE signal. Current SSH minis fixture passed; personal data stayed local. PyCharm noVNC User Agreement window confirmed, editor view false; live PTY/provider restoration incomplete. Eight docs bodies pass, tracked DOCS_ADOPTION unresolved. Current GitHub HTTP404 and protected PUBLICATION_PROFILE_MISSING remain. Latest outbox: publication-outbox-20261008-pycharm.json. All implementation is staged and archived outside repository; no new commit/push/PR/merge. Controller writer will explicitly release with a final checkpoint.
Explicit owner handoff from ticket-001 accepted for package release version synchronization. version now agrees with integration metadata 0.1.1; snapshot/restore logic unchanged. Run existing recovery/native regression suite before final rebuild. Initial Apache artifact receipts are retained; final source/version-consistent artifacts will have separate hashes. No user process or publication effect.
Fresh post-version regression: 56 passed / 1 optional systemd skip in 24.05s; noVNC tests were not repeated for this metadata/version-only release. Final wheel/sdist hashes recorded in apache-final-artifact-verification-20261009.json, every source payload checked against build allowlist. Installed module/distribution both 0.1.1 with License-Expression Apache-2.0 and full pinned LICENSE. Named daemon restarted gracefully; no host IDE signal. Publication preflight remains blocked.