uncrash

User authorizes local implementation and tests, publishing to GitHub and merge through independent protected delivery. This slice implements opt-in app profiles, encrypted durable state snapshots, a 300-second service, and audited restore. Exact live RAM/PTY or arbitrary provider sessions require app/runtime adapters and are not inferred from launch success. Test installed applications using fresh synthetic homes; do not copy real chats/credentials or close user applications.

Accepted continuation: test every installed app; all 191 discovered launchers are classified, 52 safe GUI fixtures plus Chrome/xterm assertions executed. Remaining native session assertions and full-VM service dependencies remain explicit incomplete scope; no false deep-recovery claim. Runtime metadata service installed under original user authorization.

Accepted continuation 2026-10-08: use local semcod/search over github owner/project to discover Clonerd, CloneBox and related recovery runtimes, inspect local capabilities and continue isolated restoration tests. This is within AC-03; keep implementation in this ticket and documentation in ticket-001. Planfile adapter currently terminates its session; this local record preserves intake.

Validation milestone: tests/test_local_backends.py passed 4 actual local backend fixtures against current source; tests/test_recovery.py passed 15 with 1 optional systemd skip and pinned conversational schema; tests/test_novnc.py passed 1 after fixing source-navigation/restore readiness race. Agy fixture proves synthetic ID/database/history only. Added explicit SQLite online backup paths for live committed WAL consistency and exclusions for Agy OAuth/.credentials.json. Latest wheel installed in Twinerd venv; installed-code WAL/exclusion smoke test passed and only Uncrash service restarted. Service has zero app profiles. Existing libvirt domains unchanged; owned fixture VM deleted. Publication adoption/profile blockers remain.

Accepted continuation: user requests continue, merge and tests. Combined current suite: 21 passed / 1 optional systemd skip; five local backend cases now include a real Linux/BusyBox shell and live PTY inside owned VM. Snapshot restored original environment-only variable, same shell PID and /dev/pts/0; current command verified restored state after boot, not screen replay alone. Guest never used host mounts, network or accounts. Existing libvirt domains unchanged. Publication remains incomplete: admission RECONCILE for unassigned installer payload on primary and protected Validator profile missing. Exact 118-file unchanged installer payload archived with bounded credential scan for governed handoff; no self-approval or hook bypass.

User explicitly selected real session files plus JetBrains settings through async intake. This authorizes production backup of the four narrowly filtered native profiles; synthetic test-only privacy constraints remain for tests. No provider calls or user application signals. Added compression before encryption, size-bounded two-pass restore, confined file/SQLite globs, explicit native selection preserving config backup, and start-to-start 300-second cadence accounting for capture duration. Production proposal: 16 GiB logical snapshot, 512 MiB/file, 8 GiB encrypted store, 288-count upper bound, startup restore remains disabled. Actual docs writer lease for ticket-001 expired at 18:59:44Z; stop documentation edits and preserve scoped docs follow-up for controller handoff. Actual protected deployed registry independently reobserved; semcod/uncrash still absent.

Production milestone: first native snapshot completed with four profiles, logical bytes 13066382860, encrypted bytes 3393818804. Verified encrypted manifest and sampled nonempty/online SQLite file digests per profile; never printed/deposited real content in Git. Settings-only JetBrains filters omit plugins/caches; auth credential filenames excluded. Startup restore disabled. Combined final synthetic suite: 27 passed, 1 optional service skip. Actual native start cadence still awaiting second completed capture.

2026-10-08 native cadence completion and writer handoff

Two real encrypted native snapshots completed for four selected profiles. Their start times differ by 299.997696 seconds; first logical bytes 13,066,382,860 and encrypted bytes 3,393,818,804. Five authenticated file samples passed; full production restore and provider/UI resume remain unverified. Latest combined suite: 27 passed, 1 skipped. Limit 8 GiB retains about two current full snapshots. No commit, push, PR or merge: governed adoption and protected publication profile are unresolved. Runtime source work is being explicitly handed off to the documentation ticket, with source recovery archive and fenced checkpoint retained.

2026-10-08 accepted Rust/environment request

User explicitly requested Rust for fast current-state snapshots, encryption disabled by default with an opt-in, and .env/.env.example configuration. Continue ticket-002 runtime/source/tests; ticket-001 serially owns package metadata/documentation/configuration template. Preserve old encrypted snapshots and source profiles. Add stable-file reuse and distinguish file state from RAM/provider recovery. Current fencing is recorded in rust-lease-receipt-20261008.

Rust milestone: source worker has no crate dependencies; uses Linux COW/kernel copies, OpenSSL SHA256/AES-GCM and optional zlib. Plain mode reuses unchanged immutable snapshot blobs; SQL images are reused only after a fresh online backup and equal digest. Physical retention counts shared inodes once. Latest suite 38 passed / 1 skipped in 52.52 s; fixture HOME and dependency paths repaired. No personal apps signalled. Explicitly hand off runtime writer to ticket-001 for packaging, documentation and .env template.

Production Rust validation: first three installed captures were refused; latest completed copy remains the earlier encrypted native snapshot. Added private hashed-source/index diagnostic receipt, without chat content or source paths. Latest bounds regression suite: 39 passed, 1 optional systemd skip. Current production performance and first plaintext success remain pending; manual diagnostic capture runs under the store lock.

Added bounded JSONL prefix capture: read the initial length, re-read that prefix when the source changed, reject changed/truncated content or replaced paths, omit a partial final line when growth was observed. Captured bytes and manifest sizes agree; compressed/encrypted modes share this path. New tests cover concurrent append in four modes and private failure diagnostics. First Rust package build in Twinerd venv could not import setuptools; offline wheel build with the existing base interpreter succeeded. Full suite and production capture are still running.

Final installed package has Rust source dfa8b39f3adf61af371d575c13cb9ce76285326931b62620e2ab7a2095a80caa; combined suite 44 passed, 1 skipped, 108.21 seconds. Automatic service snapshot 20261008T203732972964-99d61413a569 completed with 4 profiles, 13,126,729,992 logical bytes, 3775 reused files, 9.156 seconds. First copy had no reuse and took minutes; earlier timing includes lock contention, so this is the observed later capture time, not a first-copy guarantee. Two old encrypted copies remain. Full plaintext file restore is running in a private hard-linked fixture; no app processes touched. Runtime writer is explicitly handed to ticket-001 for documentation; production proof/fixture receipts may continue externally.

Final delivery reconciliation: explicit docs-to-runtime owner handoff accepted, fence 8; matching worktree/dirty state and HEAD re-observed. Full plaintext restore of final installed Rust snapshot passed for all 3,780 files, 13,126,729,992 bytes and private modes; fixture removed. SQLite corruption previously present in one Agy source remains unchanged; no provider/IDE resumption asserted. Two automatic service captures started 299.995729 seconds apart, lasting 9.156 and 23.198 seconds with 3775/3774 reused files. Service enabled with Linger=yes. Current suite 44 passed/1 skipped. Canonical .env.example staged in ticket-001; identical local projection and private .env deployed in primary. Seven compact docs pass bodies, adoption still missing. Delivery: requested Rust/plain-default/environment feature complete and locally installed; no new commit, push/PR or merge. GitHub HTTP404, missing protected publication profile and unowned governance bootstrap preserved in outbox. Final source snapshot/checkpoints precede explicit writer release.

2026-10-08 live PyCharm incident and recovery targets

User reports three unresponsive PyCharm windows/instances and requests reading current state, reviewing ~/close_last_pycharm.sh, multiple data protection/recovery modes and portable cloning to local Twinerd/noVNC or tom@minis over SSH. This continues unfinished AC-03. Do not close/signal IDEs or forward terminal input; inspect identities, threads, project state and descendants first. Native inspection currently finds one JVM-backed PyCharm launcher and three same-executable GLM helpers; Wayland exposes no X11 clients. Collect private diagnostics, save narrowly scoped recovery data, and add file-state export/import plus explicit recovery planning. Remote capability probe is read-only; destination question pending. Existing publication blockers remain. Fresh bounded lease fence 9 follows the previous owner’s explicit release.

PyCharm incident and portable recovery milestone

Within unfinished AC-03, added durable-file relocation to fresh stores with content hashes, no key inclusion, strict archive validation, bounded SSH transfer, persisted project/process metadata and explicit X11 close fencing. Wayland refuses unverified closure. Emergency copy preserves 133 files / 86,166,986 bytes; all restored hashes and modes pass. No live JVM/PTYS restoration is claimed. Fresh isolated noVNC PyCharm stops at User Agreement; do not auto-accept. Actual user IDE and its terminal processes remain alive. Synthetic minis transfer passed; real local incident data were not transferred. Publication remains blocked by protected profile/adoption and GitHub access; no commit/push/merge.

Final incident milestone: combined tests 63 passed / 1 optional systemd skip in 77.43s. Source-matching wheel installed in Twinerd venv; first automatic five-profile plaintext Rust capture completed in 18.985s (3,786 files / 13,281,160,111 bytes), including LocalHistory and JetBrains identity metadata. Safe local close wrapper defaults to inspection; Wayland refusal verified, no user IDE signal. Current SSH minis fixture passed; personal data stayed local. PyCharm noVNC User Agreement window confirmed, editor view false; live PTY/provider restoration incomplete. Eight docs bodies pass, tracked DOCS_ADOPTION unresolved. Current GitHub HTTP404 and protected PUBLICATION_PROFILE_MISSING remain. Latest outbox: publication-outbox-20261008-pycharm.json. All implementation is staged and archived outside repository; no new commit/push/PR/merge. Controller writer will explicitly release with a final checkpoint.

Apache artifact version synchronization 2026-10-09

Explicit owner handoff from ticket-001 accepted for package release version synchronization. version now agrees with integration metadata 0.1.1; snapshot/restore logic unchanged. Run existing recovery/native regression suite before final rebuild. Initial Apache artifact receipts are retained; final source/version-consistent artifacts will have separate hashes. No user process or publication effect.

Fresh post-version regression: 56 passed / 1 optional systemd skip in 24.05s; noVNC tests were not repeated for this metadata/version-only release. Final wheel/sdist hashes recorded in apache-final-artifact-verification-20261009.json, every source payload checked against build allowlist. Installed module/distribution both 0.1.1 with License-Expression Apache-2.0 and full pinned LICENSE. Named daemon restarted gracefully; no host IDE signal. Publication preflight remains blocked.