Updated 2026-09-19. This branch integrates main through 5e74e39f (the seven Windows fixes). Implementation source is 65b26bd2; db848ed0 is the source the package failures below were diagnosed against, and 46081f98 names the two-commits-older source that earlier receipts below were taken against. The helper integration patch on disk hashes to cbaccb29fe7f4544cbe8aef2fb0a5141856aaf7b00837f36c0a80ab33a01fc52 -- measured, superseding the 519c8528 and 12214baf identities earlier entries call final. Native CI run 35397893244 passed all five targets and its aggregate gate at db848ed0. Package-acceptance run 35395366002 at 46081f98 FAILED: the Windows and Linux install jobs and the package gate. Both defects are diagnosed and fixed here, and the rerun is what re-opens that gate. This ledger tracks the full user-requested result. Source, unit tests, packaging, real GUI behavior and the pushed PR are separate gates; unavailable evidence is not a pass.
| Requirement | Status and evidence to collect |
|---|---|
| Clean replacement: exactly ten native tools; no old scripting/control, Developer capture, hidden replay routes, or aliases | Implemented and audited in computercontroller/, Developer router, builtin registry and active fixtures; four tool-census regressions passed. No callable compatibility routes remain. |
Native screen_capture in the same helper as the nine upstream tools |
Native capture shares the helper with control. Exact-window/focus ownership, typed AX values and Windows real-button drag are implemented. Live scalar readback and Mac three-page wheel scrolling passed; strict Mac parser has 205 passing non-live tests. Windows/Linux scroll corrections passed review and actual hosted fixtures at 46081f98; all five native jobs and aggregate gate pass. No xcap extraction or fallback. |
| Independent Web & Documents capability with five utilities | Implemented in webdocuments/ with a separate five-tool registry and updated cache/resources, discovery and direct/nested utility contracts. All standard hosted checks pass at 65c51387; full installed-package jobs remain running. |
| One approved grant per user request/chat/model/target; no per-action prompts | Implemented; 24 Biorouter Copilot tests passed. Luna verified fresh approval and subsequent native state/capture without per-action approval separately in Auto, Approve and SmartApprove; receipts identify each session. Input was separately validated in TextEdit/browser tasks. Chat mode still executes no tools; completion/drop revokes the grant. |
| Distinct private/public disclosure; unknown destination treated as public | Prompt/UI disclosure and provider hooks implemented. OpenAI-compatible, Anthropic, Ollama and Versa report actual HTTP(S) origins; Lead/Worker reports both. Exact resolved routes are hashed into consent identity, never displayed. Four focused destination regressions passed within the 24-test Biorouter Copilot suite. Private does not imply on-device. |
| Private/public chat isolation and handoff acknowledgement before capture | NOT VERIFIED LIVE. Isolation and handoff controls are implemented and covered by consent/runtime regressions, but the two-chat private-to-public observation-isolation and handoff acceptance has never passed: the one attempt was rejected by the private provider before controller acquisition, which proves nothing either way. Desktop remains physically shared. |
| Persistent chat runtime and non-pooling; single controller across backend processes | Runtime ownership and stale-state protections implemented and tested; real-process ownership and recovery tests pass; live private/public handoff and stale-element acceptance remain open. |
| Stop/revoke/cancellation, exact process cleanup, bounded timeout, no mutation replay | Cleanup/cancellation protections implemented; focused late-result regression passed. Live Stop rejected subsequent native calls. The final-package repeat returned HTTP 200 in 5 ms, showed stopped in the UI, and rejected the next native action. An earlier delayed display did not recur; no speculative code fix was made. |
| Credentials stripped from descendants; observations not logged or shared through resource registries | Environment, logging and resource protections implemented; 72 sensitive-operation regressions passed. Bounded independent source review at 2f895299 found no actionable consent/isolation/legacy-route/prompt defects; live edge coverage remains separate. |
| Same sole native path in direct calls, coding-agent bridge, nested JavaScript, and delegated work | Bridge roster updated in agents/agent.rs; four census regressions and the expanded 27-test Biorouter Copilot suite pass. Nested dispatch and delegated-admission refusals pass; the standalone CLI bridge has six core, one configuration, one entrypoint and three server-route tests passing. Final live workflow validation remains required. Delegation never silently inherits another chat's consent or observations. |
| All prompts, builtin contexts, active docs, workflows and fixtures reflect the new tools | Updated system/desktop/subagent guidance and snapshots, about-biorouter context, current docs and landing references, workflow fixture, bridge/module rosters, provider and Agent Drafter harnesses, and web tool discovery fixtures. Static legacy-reference scan clean in those active surfaces; 28 prompt-manager tests passed. All standard hosted checks pass at 65c51387. |
| CLI/Electron/serve defaults preserve explicit disablement and restrictions | Default/restriction handling implemented; Luna verified both new capabilities enabled and no old desktop capability. UI regressions pass. On signed candidate 66004, explicit disablement persisted after Settings reopen and a fresh chat had no Biorouter Copilot controls or calls. Full version-upgrade acceptance remains separate. |
| Setup/status/consent/revoke interfaces, target host, active indicator, doctor diagnostics | Source implemented: CLI/TUI poll host consent, render shared task disclosure, and revoke on Stop; doctor calls no-capture diagnostics. Serve uses interactive --computer-use-approval with a separate digest/header and bounded failed-key attempts. Tests added in CLI session and server auth/startup. Test-inclusive core/server/CLI check passed. Generated schema/client, TypeScript, scoped lint and 59 UI tests passed; Luna verified setup and per-task controls. Live approval, capture, synthetic input and Stop have passed in the recorded isolated-app sessions; final build acceptance remains separate. |
| Native helper pin, patch provenance, deterministic locator, no npm/runtime download | Implemented. Five target payloads built locally; all file/target hashes verified; 18 packaging regression tests passed. All five targets passed strict native protocol/schema checks and the aggregate gate at 46081f98. Final local macOS app and isolated CLI installer/doctor receipts passed (below); release-installed platform coverage remains separate from helper-only checks. |
| Every supported release artifact contains matching helper, notices and dependencies | Build/staging/provenance integrated for all nine released archives: macOS ARM64/Intel DMG+updater ZIP, Windows x64 ZIP, Linux GUI/CLI DEB/RPM. Docker supports matching Linux x64/ARM64 helpers and dependencies. The recorded ARM64 candidate ZIP was fully extracted and passed Developer ID signature, dependency and backend-byte provenance checks. Both Mac architectures passed installed checks in run 35395366002; the Windows and Linux install jobs in that same run FAILED, and the package gate with them. Both causes are now diagnosed and fixed (see the checkpoint below): a doctor call with no bound on its dependency probes, and a verifier that looked for the Linux tree under an install prefix the packaging never produced. The rerun on the final source is what re-opens this row. Final-source installed artifacts remain unproven; notarization and release publishing are outside this authorized task. |
| macOS signing/notarization/TCC identity and upgrade continuity | Local ARM64 outer app and both Mac helpers now pass Developer ID signature verification. Normal app startup works without a mock keychain. Both permissions now pass. TCC retained the old ad hoc requirement despite an enabled switch; an official reset scoped to Accessibility/org.biorouter.computer-use, re-addition and helper restart repaired it. The updated signed helper retained both permissions. Intel package installation passed at ff8; final-source packaging remains pending. Minimum-OS behavior is additional coverage; notarization is outside authorization. |
| Windows interactive desktop, UIA, DPI/multiple displays and capture/focus behavior | The wheel-coordinate defect is fixed; hosted real fixture passed vertical/horizontal scroll, text, key and capture checks. Latest-source WinForms scrolling, drag, typing, capture and strict schema checks pass. Installed-package verification FAILED in run 35395366002 on an unbounded doctor dependency probe, now bounded and parallel with a regression that hangs before the fix; the rerun is outstanding. DPI/multiple-display checks are additional coverage and are not claimed. |
| Linux AT-SPI dependencies, X11 and Wayland honest capabilities | Recorded Linux x64 and ARM64 GTK/AT-SPI fixtures passed at their identified revisions; the newest ARM64 fixture additionally covers fractional scrolling and unequal text lines: discovery/tree, editable text, accessibility click, independent text, scroll adjustment, nonblank window PNG, explicit unsupported Wayland doctor and capture refusal. Source DEB/RPM dependencies declared for GUI+CLI. The CLI deb and rpm passed installed checks in run 35395366002; the GUI deb failed the verifier's own resource lookup, now corrected and pinned by a regression measured against the real v1.90.5 GUI packages. Installed GUI package checks remain outstanding until the rerun. Wayland pixel capture is explicitly unsupported, rather than claimed as untested support. |
| Real BioRouter driven by Luna: scrolling, web tasks, local application tasks | BioRouter native browser typing, click, scrolling, bottom-button click and navigation passed against a synthetic local fixture, independently verified by events. A second chat required a fresh grant. The final signed package then edited and saved the preopened TextEdit fixture through 19 native calls; independent disk verification found exactly the requested added line. Direct helper or external-driver success alone is insufficient. |
| Fixture-scoped self-test on rebuilt runtime | NOT DONE. biorouter run --workflow biorouter-self-test.yaml with test_phases=computer_use and test_depth=fixture_only has never passed on the final candidate. The last attempt (selftest-fixture-only-cli-20260918-14.json) failed on the capture-metadata leak that is now fixed, and no run has been made since. This row is an outstanding gate, not a pending formality. |
| Formatting, build, targeted tests, clippy, generated schema and full project gates | Full just check-everything passed at d09d79b1; the final 46081f98 gate also passed (receipt full-gate-46081.json). Production CLI/daemon build passed at 46081f98. Latest native, frontend, API, serve, cross-check and all three hosted Rust suites pass; full installed-package checks remain running. Historical receipts retain their original source identity. |
| Source reviewed and pull request pushed | Draft PR #330 is pushed and reviewable. Source db848ed0 — 46081f98 plus the capture-scope correction 9aacda04 and the fixture determinism db848ed0 — is pushed, and carries the background race, schema, CLI bridge, packaging and consolidated native corrections. Final hosted gates and artifact acceptance stay open; a draft PR does not complete the other gates. |
Implementation owners should replace “In progress” or “Pending” with exact command/log/artifact evidence as it becomes available. Keep any unsupported environment/action explicit and resolve it before claiming the promised platform is supported. Final completion requires the user's full scope, including the pushed PR and Luna-driven real-app checks.
-
The capture-metadata leak is FIXED, not open. The cross-platform scope correction is
9aacda04and its fixture determinismdb848ed0; a real Linux negative control fails before and passes after, and the direct Mac preflight at helpercbaccb29returned one target window, a valid PNG and a one-window metadata-only response. Receipt:target/computer-use/evidence/native-metadata-preflight-20260918-direct.json. The sentence this replaces called it a "New live blocker" against a superseded source. -
The scalar discrepancy is a FIXTURE defect, diagnosed by measurement; the runtime needed no change.
-25205iskAXErrorAttributeUnsupported(verified against the macOS SDK'sAXError.h), notkAXErrorCannotComplete(-25204). The fixture'sObservableSlider.setAccessibilityValueforwarded tosuper.setAccessibilityValue(_:), which on anNSViewwrites the per-instance accessibility attribute OVERRIDE store: it changes what the element REPORTS and never reachesNSSlideror its cell. That single mechanism produces the whole signature -- AX readback 65 with the knob still at 20% -- and the override is permanent, so 37 minutes later the control still reported 65 while its real value had been dragged to 21.26. The unmodifiedNSSliderbaseline succeeded and moved. The runtime is correct and honest: it writes once, refuses to call a non-.successwrite a success, never retries, and never accepts AX readback as proof of mutation. The fixture is now IN THE REPOSITORY (scripts/computer-use-macos-scalar-fixture.swift, built byscripts/build-computer-use-macos-scalar-fixture.sh) with thesupercall removed -- it previously existed only under/tmp, which made every scalar finding unreproducible from a clean clone.- Open, and not claimed closed: why
AXUIElementSetAttributeValuereturnedattributeUnsupportedon an element whoseAXUIElementIsAttributeSettablehad just returned true. The override-store mechanism explains the readback, not the error code. Separately, the helper's Swift tests exercise.cannotCompleteas a write result but never.attributeUnsupported, which is the code seen in the field -- a coverage gap, not a defect.
- Open, and not claimed closed: why
-
Windows installed-package timeout:
biorouter doctorhad no bound at all.system::probe()calledCommand::output()with no timeout, once per dependency, in series, and one probe cold-executes the bundled 37 MBllama-server.exe. Cold first execution is an operating-system scan cost at near-zero CPU: measured 8.33 s cold vs 0.05 s warm locally (166x), and 15.6 s vs 2.0 s for the whole verifier on the same macOS runner in the same job. Probes are now bounded — one 12 s deadline per PREREQUISITE, covering its whole probe chain, becausepythontries python3 then python andllama-servertries PATH then the bundled sidecar, so a per-probe budget would have doubled the real worst case. They run concurrently, so a cold machine pays roughly the slowest rather than the sum, and a timeout is reported as a distincttimed_outstate instead of being collapsed into "not installed" — which haddoctor, the CLI, the TUI and the desktop all telling users to install software they already had, anddoctor --fixoffering to install it.- The deadline covers READING the output, not just the child's exit. Bounding only the exit is not enough, and that was measured: a child that answers, exits, and leaves a descendant holding the inherited pipe blocked a 2 s budget for 30 s. On Unix a probe is now its own process group, so abandoning it takes its descendants with it. The desktop's own budgets were raised in step (
DOCTOR_TIMEOUT_MS15 s → 20 s,PROBE_TIMEOUT_MS8 s → 12 s); the old 8 s sat below the 8.33 s cold cost measured here, so it cut off the very probe that motivated the work. This was a SHIPPED defect, not only a CI one: the desktop runs the same call at startup under a 15 s budget (ui/desktop/src/utils/dependencyChecker.ts) and silently falls back past it. - A second mechanism is NOT ruled out and the CI log cannot discriminate it:
subprocess.run(capture_output=True)returns only when every writer closes the pipe, so a descendant that inherited the CLI's stdout makes "still working" and "finished, but something holds its stdout" the same observation. Demonstrated locally: a command that exits 0 immediately still producedTimeoutExpired.scripts/verify-installed-computer-use.pynow observes process exit independently of its pipes, writes output to files, passesstdin=DEVNULL, records cold and warm timings in the receipt, and on a timeout reports how many bytes had already been written plus the live process tree. The next run's receipt says which mechanism it was.
- The deadline covers READING the output, not just the child's exit. Bounding only the exit is not enough, and that was measured: a child that answers, exits, and leaves a descendant holding the inherited pipe blocked a 2 s budget for 30 s. On Unix a probe is now its own process group, so abandoning it takes its descendants with it. The desktop's own budgets were raised in step (
-
Linux GUI package acceptance: the verifier encoded an install prefix the packaging never produced.
scripts/computer-use-package-acceptance.pylooked for the packaged tree atopt/*/resources, butelectron-installer-debianandelectron-installer-redhatexpose noprefixoption at all -- theprefix: '/opt'inforge.config.tswas inert for the life of the config -- and both install tousr/lib/<name>/resources, lowercased by the deb maker and case-preserved by the rpm one. Measured against the real v1.90.5 GUI deb and rpm: the glob matched ZERO, and no single literal path serves both. The tree is now located by its unique helper manifest, the way the macOS/Windows branch already did, and the same wrong prefix at the installed-helper lookup -- which would have failed the very next step -- is corrected too. The inertprefixoptions are removed so the belief cannot be re-seeded. A third instance in shipped product code (an exported app's launcher probing/opt/Biorouter/resources/bin/biorouterd) now also lists the real paths.- Note for reviewers: this makes
dependencies()execute on a Linux GUI package for the FIRST time. It is expected to pass -- forge's ownpostPackagehook runs the identicalverifyPackagedDependenciesand the "Build genuine candidate packages" step succeeded in that same failing run -- but a Linux failure there next run is a check finally running, not a regression from this change.
- Note for reviewers: this makes
-
Source
65b26bd2is the subject of PR #330:db848ed0, the package/interface fixes (19a98805), the review corrections to them (7b59f933), the second round (322c2fc6) after the first package-acceptance run on the fixed source, and the Windows path and interface corrections below (b94a4cb8..65b26bd2). -
The Linux GUI deb is fixed and PROVEN; the rpm was not, and its cause is now measured. Run
35407333005atca22a9bdcarried the deb through every stage that had never run: extraction,verifyPackagedDependencies(the node-pty check the oldValueErrorhad always pre-empted), the installed check resolving/usr/lib/biorouter/resources, and the real GTK fixture. It then reached the rpm and failedHelper payload was modified, incomplete, or contains unrecorded files. That is the next gate finally running, not a regression. Cause, reproduced locally against the real helper: rpmbuild's%__os_install_postincludesbrp-strip-comment-note, whose selector is the COMPLEMENT ofbrp-strip's — it matches ELF files that are already stripped, which is exactly what a-ldflags=-s -wGo binary is — and runsstrip -R .comment -R .note. The helper has neither section, but GNU strip still repacks it:.shstrtabslides into the alignment gap after.data,e_shoffis rewritten, andocugoes from 2,609,314 to 2,606,840 bytes. The binary still runs, so only the provenance check notices. The deb is unaffected (dpkg does not post-process) and the CLI rpm is written directly by nfpm, never rpmbuild.electron-installer-redhatspawns rpmbuild with a fixed argv and a hardcoded spec template, so thefpm:entry inforge.config.tswas dead configuration; the fix is a Linux-scoped$HOME/.rpmmacros. -
Windows was NOT fixed by the probe bound, and the measurements say why. The earlier entry's framing — unbounded, serial dependency probes — described a real defect but not the dominant Windows cost. The readiness probe exceeds its 30 s timeout on EVERY run: measured cold/warm pairs are 0.17/0.12 s on linux and 13.28/13.14 s on darwin-arm64 — within 1%, so there is no cold-start component — against Windows cold ~46 s and a warm attempt that produced no output at all. Two changes follow, and their status differs:
- Provable from code:
Runtime::doctorread its response to EOF, which returns only when every inherited copy of the pipe's write end closes. The helper's own children hold one, so a descendant outliving the probe stalls it for the full timeout even though the JSON was already written — the same defect the dependency probes had, missed here. It now reads the single newline-terminated line all three helpers emit. - NOT established:
spawn_payload'senv_clearallowlist omittedComSpec,PATHEXT,SystemDriveand the ProgramFiles family, which Windows process startup andpowershell.exeread. The differential is real and measured — the same helper on the same runner image answers in 2.17 s with the full environment — but causation could not be proved from macOS, and a green Windows run will not separate this from the EOF fix. Do not record it as confirmed on a green run alone.
- Provable from code:
-
Three harness defects, all found in that run's own evidence. One shared 60 s doctor deadline let a slow cold attempt squeeze the warm one to 14 s, so the raised error named the wrong attempt; each attempt now has its own budget summing to the same total, and the message carries the finished timings. The process diagnostics observed themselves —
RELEVANTcontainspowershelland the POSIX arm shells out tops, so four receipts recorded their own snapshot helper as a process left behind; both snapshots now exclude the querying process. ⚠ That last one invalidated a conclusion drawn from the first Windows receipt: "apowershell.exewas alive at the deadline" was the snapshot naming itself, not a surviving descendant. -
Linux is fully green, and the Windows failure that replaced the hang is fixed at its source. Package-acceptance run
35415408060at322c2fc6carried all four Linux formats (GUI deb, GUI rpm, CLI deb, CLI rpm) through extraction,verifyPackagedDependencies, the installed check and the GTK fixture. That closes the Linux half of the original failure with real packages rather than an argument. Windows changed from a 30 s readiness timeout toValueError: Doctor resolved outside the installed payload-- a third defect, reachable only once the hang was gone. Cause:std::fs::canonicalizereturns a VERBATIM path on Windows (\\?\C:\...),manifest::inspectkept it, and it was serialised intobiorouter doctor --format json, where the verifier compares it against a plainly-spelled path thatPath.resolve()will never normalise to match. Fixed on both sides inb94a4cb8:dunce::canonicalizein the product (⚠ on the containment check too, in the same commit --starts_withcompares components andPrefix::Disk!=Prefix::VerbatimDisk, so simplifying only the root turns a reporting bug into a hard startup failure), andos.path.samefilein the verifier, which is immune to prefix, 8.3 short names and case. Verified on Windows Server 2025 in both directions, including the negative controls. -
SECOND CORRECTION: the helper degrades gracefully with no desktop too, so the remaining defect is in CI and NOT in the product. The entry below said the Windows runtime blocks while checking readiness where macOS answers
desktop_unavailable. That is also false. Measured directly on Windows Server 2025 with the patched helper built from the vendored source, three conditions:condition elapsed state interactive session 2, normal path 0.90s / 0.95s readyinteractive session 2, install path with a space and a non-ASCII character 1.13s / 0.90s readysession 0 as SYSTEM, UserInteractivefalse0.84s desktop_unavailableThe session-0 receipt carries
"message":"Run BioRouter in the signed-in user's interactive desktop session."— the graceful answer, produced in under a second, in the very condition that was supposed to hang. The patchedruntime.ps1diagnostics branch computes[Environment]::UserInteractive -and CanAccessInputDesktop() -and AllScreens.Count > 0and reportsdesktop_unavailablewhen it is false, exactly as intended.- ⚠ So
desktop_unavailableIS achievable on Windows. That changes the CI-expectation question recorded elsewhere in this ledger: admitting it the way darwin's expected-status list does is now defensible on evidence rather than as a concession to a limitation. - What is still unexplained is the RUNNER, not Windows. 34.91s on a GitHub-hosted runner is unaccounted for, and four candidates are now dead: a slow helper, the no-desktop path, the space/non-ASCII install path (all sub-1.3s on real hardware), and
system::check_all, which runs its probes concurrently under a 12s bound and cannot produce 34.91s. The shape still matchesRuntime::doctor's 30s bound plus a 5s shutdown, so the next reproduction is the fullbiorouter doctor --format jsonin session 0 with #343's breadcrumbs. - Twice now a mechanism was inferred from a CI symptom and refuted by real hardware. First "the helper never answers"; then "it blocks instead of degrading". Both were reasonable readings of a runner log and both were wrong. The lesson for this ledger: a CI timeout localises a budget, not a cause.
- ⚠ So
-
CORRECTION, from real Windows hardware: the helper is NOT unable to answer. The entry below inferred "it never answers" from a CI runner, and generalised too far. Measured on Windows Server 2025 in an interactive RDP session (
[Environment]::UserInteractivetrue, session 2, not session 0):biorouter doctor --format jsonreturnsstatus: readypromptly,integrity: verified, with the full ten-tool surface advertised, andtest-computer-use-windows-fixture.pyreportspassedover eleven checks includinglist_apps,get_app_state,set_value,type_text,press_key,click,drag,screen_capture, targeted-capture isolation, and eight scroll receipts with measured displacement (2.5 pages, expected 460.0, actual 460).- So the defect is narrower than "Windows is broken": the helper answers wherever a desktop session exists, and blocks only where there is none — where macOS answers
desktop_unavailable. That is a graceful-degradation defect in the readiness path, not a broken capability. - ⚠ NOT the full acceptance: that receipt carries
development_override: True, because the payload was a CI artifact selected withBIOROUTER_COMPUTER_USE_DIRrather than an installed one. The installed-payload path on Windows (development_override == false) is still outstanding, and so iscomputer-use-package-acceptance.py build/verify win32-x64. - Likely cause of the block, found independently and matching the hypothesis recorded here:
runPowerShellends incmd.CombinedOutput(), which waits for pipe EOF, and EOF needs every inherited write handle closed.exec.CommandContextkillspowershell.exeon expiry but does not close a grandchild's inherited copy, soWait()can block past the deadline and the helper's own "Windows runtime timed out after 30s" sentence is never produced. Go's documented remedy iscmd.WaitDelay. ⚠ Not yet reproduced, so not yet a confirmed cause — and the grandchild has not been identified, which is also what decides whetherWaitDelayalone suffices or the spawn needs a job object. - The release note was corrected before shipping. It had said "Computer Use is not working on Windows in this release", which this evidence makes false.
- So the defect is narrower than "Windows is broken": the helper answers wherever a desktop session exists, and blocks only where there is none — where macOS answers
-
Windows is MEASURED now, not hypothesised — and it is a product defect, not a budget one. Run
35474721330instrumenteddoctorwith a per-phase stderr breadcrumb, and the receipt reads: cold 34.91 s, exit 0, nothing left behind; warm exceeded its 20 s budget with the trace showing only[doctor] start (+0.00s). Three things follow, and each retires a previous guess. (1) The concurrency fix worked: cold had been exceeding 40 s and now completes, becausecheck_all()and the Biorouter Copilot probe no longer add up. (2) Warm is not faster than cold, which retires the first-execution antivirus-scan hypothesis that the ~46 s figure had invited. (3) 34.91 s is almost exactlyRuntime::doctor's 30 s bound plus its 5 s shutdown, so the helper is not slow — it never answers at all, and the probe spends its entire bound waiting.- The shape of it: on a host with no interactive desktop session, macOS answers
desktop_unavailable(which is why darwin's expected-status list admits it and win32/linux demandready). The Windows helper blocks instead of answering. That is the defect to fix, and it is in the helper's readiness path, not in any budget. - ⚠ Raising
ATTEMPT_TIMEOUTS['warm']above 35 s would let the job run further and then fail on--expect-status readyanyway. The job is honestly red; leave it red until the helper answers.
- The shape of it: on a host with no interactive desktop session, macOS answers
-
Still NOT established, and a green run will not establish it. The Windows
env_clearallowlist addition (ComSpec,PATHEXT,SystemDrive, the ProgramFiles family) remains an unproven hypothesis. The readiness hang is fully explained by the EOF read alone, so a passing Windows job cannot separate the two changes. Do not record it as confirmed. -
The two live-desktop gates remain unmet. The fixture-scoped self-test and the private-to-public two-chat isolation check have not been run on a real desktop. They are NOT DONE / NOT VERIFIED, not "expected to pass".
-
The fixes were themselves adversarially reviewed before being pushed, and the review found defects in them. Recorded because the corrections are load-bearing, not cosmetic: the in-chat permission probe had taken the same in-flight flag the consent decision checks, which made Allow and Stop silent no-ops while a probe ran; the probe bound covered the child's exit but not the reading of its output, so a child that answered, exited and left a descendant on the inherited pipe blocked a 2 s budget for 30 s; the budget was per-probe rather than per-prerequisite, doubling the real worst case for the two prerequisites that try two commands;
doctoritself still reported a timed-out probe as "missing" and offered to install it, in five places the first pass missed; the naming gate's test-module strip blanked 46% of all Rust lines, including whole production files, making it far more vacuous than it appeared; and the concurrency test asserted a wall-clock threshold a serial run clears by 54x, so it pinned nothing. Each is fixed with a regression that fails against the previous code. -
Both macOS permissions were freshly rechecked through the packaged CLI: Accessibility and Screen Recording are true, integrity is verified, and no helper override is used. Receipt:
target/computer-use/evidence/permission-recheck-latest.json. The updated isolated app is PID 66004. Its permission/signature receipt ispermission-backend46081-native519c.json; runtime schema acceptance is separately proved by the actual helper handshake. -
Luna's capability-independence test caught a real
clickschema mismatch before any native capture. Commit875707e3aligns the bounded click/pages schemas. The actual helper startup test failed before and passes after the fix. Six focused runtime unit tests and all six contract integration tests pass. Strict advertised-schema checks pass on actual Mac ARM64/Intel and Linux ARM64/x64 payloads; Linux uses isolated Docker and x64 emulation is qualified. Windows strict schema verification also passed in hosted run35395275216. Independent review found no blockers; Python comparisons distinguish booleans from numeric bounds. -
The bounded CLI workflow exposed a missing authenticated HTTP tool bridge in standalone Codex commands and performed zero native actions. Commit
46081f98adds the scoped loopback bridge for agent-capable CLI entrypoints, including terminal, evaluation and local scheduled runs. Six core bridge tests, one Codex configuration test and the CLI entrypoint test pass; all three existing server-route tests also pass. The production CLI/daemon rebuild passed; Luna is running the workflow against the signed updated binaries. -
Windows fixture evidence first measured 95 pixels for a requested 92 pixels through UIA, then zero movement through a native thumb route on WinForms. Patch
519c8528preselects native WinForms line commands, measures each step, bounds execution and verifies exact handle/PID/ancestry before and after mutation. Independent fixture assertions require actual directional movement within the independently observed native step granularity. Stale-handle regressions, negative controls and independent review pass; actual hosted Windows acceptance now passes in job105762574587: all eight direction/fraction/multi-page cases, typing, drag and capture. Independent 5-pixel granularity accounts for observed 90/92, 225/223.5 and 1115/1117.5 actual/requested positions; these are bounded native-step results, not exact arbitrary pixel positioning. -
All five
519c8528payloads built and verified locally. Mac strict numeric parsing has 205 passing non-live tests. The recorded Linux real GTK fixture proves fractional/multi-page movement, unequal-line boundaries, invalid-input refusal, drag, text and capture. These do not substitute for latest-source installed-package checks. -
Packaging fixes are pushed in
9dcc0c9f: Windows invokes npm through Node without a command shell; Linux builds and verifies node-pty against the pinned glibc baseline. Fourteen focused tests and independent review pass. The actual baseline orchestrator loaded the artifact in Electron 39.8.10, ABI 140, and spawned/read/exited a PTY on glibc 2.31. Original run35388308517passed both Mac architectures' package creation and installed verification; its Windows/Linux packaging failures remain historical failures, not green results. Final all-format run35395366002retains those checks. -
Real-process ownership tests verify contender refusal, release while the owner remains alive, and recovery after owner death; a retained-lease negative control fails. Nested dispatch and delegated-admission regressions are pushed in
2d9e2486: 27 Biorouter Copilot tests plus the direct revoked-result test pass. This does not claim ordinary delegated child execution was live-tested. -
Recorded Luna runs prove browser typing/click/navigation, exact three-page WebKit wheel movement, scalar readback/no-op distinction, an exact TextEdit line saved once, fresh task grants in Auto/Approve/Smart modes, and Stop refusing the next capture. These receipts identify intermediate app versions. The latest rebuilt candidate still needs live acceptance.
-
Private-to-public native handoff remains unverified: the private provider rejected the request before controller acquisition. Separate public chats required separate grants, but that is not proof of the private-to-public handoff or stale-element nonreuse. Opt-out survived Settings navigation/reopening and a fresh chat had no native tool/fallback; full upgrade continuity and successful capability independence remain open.
-
The full local project gate passed at
46081f98. The final Mac archive also passed exact inventory, signatures, dependency containment, helper manifest and backend hash checks (packaged-macos-46081-archive.json). Hosted Rust/package checks and live acceptance remain pending. The updated app is installed and must remain unchanged during Luna’s live batch. No further user permission approval is needed for the authorized synthetic tests.
The following entries preserve their original source and payload identities. Pending diagnoses and “final” labels in these earlier checkpoints are superseded by the current validation section above.
- Final native CI at
231daabcpasses all five targets and the aggregate gate. The full local project gate passes (/tmp/biorouter-cu-231-final-gate.log). The rebuilt Developer ID signed ARM64 app retains both OS permissions; ZIP extraction verifies 676 exact entries, contained dependencies and helper integrity. Signed backend program bytes match the production build, excluding only the code signature and its size fields. Receipts:packaged-main-integrated-signing.json,packaged-macos-main231-archive.jsonandpermission-main231-20260918.jsonundertarget/computer-use/evidence/. Luna session20260918_9passes 16 native calls covering typing, text values, click, scroll, Home, secondary increment, drag and capture; exact three-page and unsupported scalar checks remain separate pending cases. - Old Intel package run
35378834831finished compilation and Forge packaging but failed because its Electron framework was unsigned. The harness now signs frameworks before nested apps and the parent, confines deep signing to Frameworks, and retains successful Rust caches after later failures. Twelve installed-readiness tests pass, including a real unsigned-framework failure/fix with unchanged Biorouter Copilot bytes; an actual copied Electron bundle also passes the fix. The known-broken queued package run was canceled before any installed-package job completed, and a corrected all-format run is required. No application source changed for this harness correction. - Native patch
7fd33dda2fe55094ed05ac620da8e5f26eee49f94df90fc06b708e9fc31aef42corrects scalar false success and coalesced page scrolling. Scalar setters write once and verify the value; unknown outcomes error without replay. Page scrolling waits for target-local geometry or axis-value progress, reports actual pages at a proven target-owned boundary, and stops on unknown progress. Oversized page counts are rejected before integer conversion. All 198 non-live Swift tests pass (/tmp/cu-scroll-edge-final.log); deliberate old-behavior mutations fail and independent review found no remaining actionable defect. Rebuilt package/live acceptance remains pending. - Full local
just check-everythingalso passed at native-fix checkpoint2f895299:/tmp/biorouter-cu-2f895299-full-gate.log. This includes clippy, UI checks, generated schema, version, branding and cross-drift gates. The subsequent native scalar/scroll delta requires its own final validation. - Latest merged production CLI/daemon build passed in 19m08s; receipts:
/tmp/biorouter-cu-merged-release-build.logandtarget/computer-use/evidence/main-integrated-backends.json. The main merge includes #329/#331 and passed the full local gate (/tmp/biorouter-cu-main-merge-full-gate.log), regenerated API client and seven preview tests. These new binaries have not yet completed packaged live acceptance. - Mac helper checkpoint
43e7060fcompleted CLI session20260918_8: background typing, textset_value, confirmation, secondary increment, drag and capture passed. Sliderset_value("60")returned success without changing the control; a postcondition correction remains in progress. Fixture events independently prove scroll movement at 797, 1594, 2391 and 2645, even though the AX tree did not reveal movement. Multi-page requests advanced only one viewport and are under investigation. Receipt:target/computer-use/evidence/mac-scroll-session8-attribution.json. - The earlier background typing defect is corrected by checking editable roles and verifying focused element ownership before reading or writing text. Exact captured-window activation is required for consented global fallback. Mac non-live regression suite: 185 passed, including deliberate focus-ownership and scalar-conversion negative checks. The first workflow run also used the invalid generic app name Browser; discovery guidance now requires the exact running app identity.
- Native CI run
35383167034ate05a1d75passed both Mac and both Linux jobs but failed the new Windows independent drag assertion: the old message-based gesture produced no child events. Pushed source2f895299replaces it with explicit-consent, checked-target SendInput, reviewed without outstanding findings; actual Windows acceptance passed run35385380547: 12 held-button moves, released state and exact 120px displacement in the independent child control. Receipt:target/package-acceptance-evidence/35385380547/windows-fixture/windows-fixture-independent-drag.json. PowerShell syntax, compiled INPUT size, contract mocks, Go tests and Windows cross-build pass; these do not prove live Windows delivery. - Linux ARM64 now passes independent drag acceptance: 13 held-button motion events, release, and 120px movement in a real GTK child control. Both platform fixtures reject incomplete/no-op drag receipts; Windows hosted execution of the independent drag assertion now passes at
2f895299. Receipts:target/computer-use/evidence/linux-drag-fixture.jsonandlinux-drag-fixture-independent-drag.json. - Fresh public Codex chat
20260918_7passed native approval and coding-agent bridge acceptance: disclosure showed destination/model/backend, observation/control scope, shared desktop and Stop limits; one nativeget_app_stateread only the synthetic TextEdit document, then stopped. DB confirms public/Codex/gpt-6-astra and the native call; Luna confirmed UI behavior. Receipt:target/computer-use/evidence/live-public-codex-handoff-20260918.json. Separate Anthropic chat20260918_6showed provider disclosure but failed for insufficient credits before native execution. - User-requested permission recheck again confirms Accessibility and Screen Recording true, helper integrity verified, no override and status ready. Receipt:
target/computer-use/evidence/permission-user-recheck-20260918.json. No additional permission approval is required. - Instrumented focused drag passed through the signed BioRouter CLI: seven native calls, trusted slider pointer-down/moves/up, value 20 to 84 and clean exit. Receipt:
target/computer-use/evidence/live-drag-instrumented-20260918.json. Foreground telemetry exposed competing Electron launches during earlier attempts; those attempts do not establish a drag-event defect. Separately, source review found global input could raise a different window from the captured one, and capture selection could disagree with the AX tree. The window-identity correction passes 179 non-live Swift tests, including a fail-before/pass-after regression for Stop during blocking AX validation. All five payloads rebuilt and verified; the staged signed app retains both permissions, integrity and no override. Updated-helper live acceptance remains in progress. - Full installed-package acceptance run
35378834831builds actual release-format candidates at65c51387. Windows GNU compilation passed. Linux compiled and passed the glibc floor, then failed because the dependency guard missed multiline Forge arrays despite declared zlib dependencies. The guard correction passes positive and missing-dependency negative checks. Mac ARM64 DMG and ZIP builds plus actual installed locator/integrity checks passed; receipts are undertarget/package-acceptance-evidence/35378834831/darwin-arm64/. CI had no OS desktop permissions, so these are installed-package checks, not live input acceptance. Intel Mac remains running; Windows/Linux dependent package jobs were skipped after the Linux guard failure. Final-source package acceptance remains open. - All applicable hosted checks pass at pushed source
a0b73cc2, including Rust on three operating systems, cross-compiles, frontend, serve and all five native targets. Receipt:target/computer-use/evidence/ci-a0b73cc2.json. The full local project gate and production build also pass. - Real BioRouter native actions produced eight independent browser-fixture events: page open, synthetic text entry, confirm click, three scroll positions, bottom confirmation and second-page navigation. Receipt:
target/computer-use/evidence/live-browser-and-stop-20260918.json. - Final signed package TextEdit test completed 19 native calls and saved the exact requested added line once. Independent disk evidence:
target/computer-use/evidence/live-textedit-final-package-20260918.json. - Separate same-provider chats required separate grants. This does not prove private-to-public provider handoff or complete observation isolation.
- Final-package Stop returned HTTP 200 in 5 ms, settled visibly, and rejected a subsequent native action. Receipt:
target/computer-use/evidence/live-stop-final-package-20260918.json. An earlier display delay was not reproduced. - Both OS permissions now pass, with integrity verified and no override:
target/computer-use/evidence/permission-after-scoped-reset-20260918.json. A stale old ad hoc TCC requirement required an official Accessibility reset limited to the helper bundle ID, followed by re-addition of the signed helper. Other permission records were preserved. - The signed ARM64 candidate ZIP passes extraction, exact inventory, signatures, helper and backend hashes, and dependency checks:
target/computer-use/evidence/packaged-macos-guidance-candidate-archive.json. It is not notarized or published. Actual full-package installation evidence for the other platforms remains separate from the successful helper fixtures; a dedicated acceptance workflow is in progress. - The first fixture-only CLI run performed 16 native calls, then received a provider HTTP 400 reporting a malformed
functiokey. A wire regression through the real Versa sender passed 18 requests, failed under deliberate key mutation, and passed after restoration. No production workaround was added; the cause of the original request rejection remains unproven. A fresh run did not reproduce it and completed 13 native calls, but the slider drag had no observed effect. The bounded self-test therefore remains failed, pending a successful bounded workflow rerun. Subsequent targeted runs verified native drag and corrected other discovered scalar/scroll defects; the original failure diagnosis is no longer the current blocker. Interactive/exitreturning zero is not evidence of workflow success. - Fixture-only, selected-phase and full-suite workflow rendering checks pass. The fixture-only mode does not load Developer or Web & Documents and forbids fallback scripts, configuration changes and unrelated app actions.
These are observed intermediate results, not completion of the full request.
- Draft PR #330 contains pushed source
31a9f116; its hosted CI remains pending. - Full
just check-everythingpassed:/tmp/biorouter-computer-use-check-everything.log. - Final production CLI/daemon build passed:
/tmp/biorouter-computer-use-production-final.log. - Serve lifecycle suite: 9 passed,
/tmp/biorouter-computer-use-serve-lifecycle.log; serve options/parser regression: 1 passed,/tmp/biorouter-computer-use-serve-options-test.log. - Native CI run 35273394648, source
fd0736d1: all five target jobs and aggregate gate green. This includes real Windows text/key/vertical and horizontal scroll/capture and Linux x64/ARM64 GTK fixtures; macOS protocol/contract checks do not imply user-approved live capture/input. - The core/server/CLI test-inclusive check exited 0. Focused suites passed: 24 Biorouter Copilot, 1 late-result, 72 sensitive-operation, and 4 tool-census tests. The four provider destination regressions are included in the 24 Biorouter Copilot tests, not an additional count.
- The production debug CLI and daemon build exited 0; receipt:
/tmp/biorouter-computer-use-binaries.log. - All 435 OpenAPI references resolve. Generated SDK, TypeScript checking, scoped lint, and 59 UI tests passed.
- The exact Forge sequential development build exited 0; receipt:
/tmp/biorouter-computer-use-ui-build.log. - Luna inspected the real isolated GUI, PID 94914, launched from the exact
.vite/build/main.jsentry. It verified Biorouter Copilot and Web & Documents defaults, absence of the old desktop capability, per-task controls, and setup reporting helper 0.3.5 / darwin-arm64 with both Accessibility and Screen Recording denied. CUA screenshot receipts in the Luna agent task are titled Capture top capability controls and Capture setup denial and capabilities; no disk screenshot was exposed. The OS permission question remains unanswered. No real Biorouter Copilot input or capture has occurred in this Luna run, so scrolling, web and local-app tasks and the resulting fix/rerun loop remain open. - Historical initial hosted Rust suites recorded 4093 Ubuntu passes and 4008 Windows
passes, each with the same sole stale web-discovery test failure. The corrected
test preserves relevance ranking and excludes unrelated tools for focused queries;
the broad
webquery now correctly permits thewebdocumentsnamespace match. These initial failures are historical, not the latest CI snapshot. Final pushed-source CI at31a9f116remains pending.
git diff --check: passed for the current shared worktree at this audit.python3 -m py_compile scripts/agent-drafter-testdrive/audit_platform_integrations.py scripts/agent-drafter-testdrive/run.py: passed.bash -n scripts/test_providers.sh scripts/agent-drafter-apps/round.sh: passed.- PyYAML loading of
biorouter-self-test.yamlandlanding/assets/ehr-diabetes-recipe.yaml: passed; self-test includes native fixture parameter and both separate capability registrations. - Active prompt, builtin context, current user-guide, landing and harness scans contain no instructions to call the removed script/control or Developer capture tools. Historical records and negative-removal/configuration tests retain names only as provenance or refusal evidence.
- First
CARGO_BUILD_JOBS=4 cargo test -p biorouter --lib agents::prompt_manager::tests --no-fail-faststopped at stale extracted DOCX/PDF module references. Those references were corrected by the native-tools lane. The resumed build was briefly paused for high host load, then completed successfully at reduced priority: 28 selected prompt-manager tests passed, 0 failed, 0 ignored, 4065 filtered, including all three snapshots. Other source edits landed during compilation, so final consolidated verification must rebuild the latest tree.
Earlier focused receipts above retain their original scope. Full local project gates have now passed; latest-source hosted CI, installed release artifacts and real-app gates remain separate requirements.
The native lane tested the biorouter-1 patch against upstream OCU 0.3.5, commit
547b4ffb8ed731a8f16486e6d8a3b215484267d3. The repository records the source pin and
prerequisites in vendor/computer-use/pin.json; the local test checkout was
/tmp/ocu-biorouter-native-patch. The final patch hash is
12214baff26bcc4a3eb4b085a08004f74ba16e8b6a2d010c633be682fb38ab67.
The local receipts below predate the final hosted run and are historical component
evidence; the green final-patch native CI run above supersedes the pending fixture status.
| Check | Observed receipt | Scope and remaining limit |
|---|---|---|
| Swift capture/connection contract | /tmp/ocu-native-swift-tests.log: 5 tests, 0 failures. |
Owner-scoped cancellation, disconnect handling, malformed capture arguments, fresh connection state, and passive diagnostics; no real GUI validation. |
| Swift existing regression suite | /tmp/ocu-native-swift-regression-tests.log: 163 tests, 0 failures. 168 Swift tests total across the two selected suites. |
macOS ARM64 local unit/regression evidence; excludes the separate live SkyClick suite and does not validate Intel packages or TCC upgrade behavior. |
| Linux Go runtime suite | /tmp/ocu-native-linux-go-tests.log: package result ok, 0.219 s. |
Go-side runtime contract evidence from the local host; not a Linux desktop session. |
| Windows Go runtime suite | /tmp/ocu-native-windows-go-tests.log: package result ok, 0.213 s. |
Go-side runtime contract evidence from the local host; not Windows UI Automation execution. |
| Linux Python runtime contract | /tmp/ocu-native-linux-python-tests.log: python3 -m unittest -v runtime_test completed with 12 tests, OK, exit 0. |
Mocked GI/AT-SPI/GDK tests verify interface handling, passive diagnostics, missing dependencies, Wayland capture refusal, X11 image/error shapes, and focused scroll/key delivery with modifier cleanup; actual desktop receipts are recorded separately below. |
| macOS stdio initialization and tool roster | /tmp/ocu-native-swift-protocol.json: server open-computer-use 0.3.5, protocol 2025-03-26, exactly ten expected tools including screen_capture. |
Confirms native initialization and advertised contracts; no capture or input action was performed by this handshake. |
Windows/Linux window capture reads visible screen pixels and can include occluding windows. Linux Wayland pixel capture currently returns an unsupported-environment error. These limits are documented in the user-facing Biorouter Copilot guide and must not be described as complete platform parity. Installed release artifacts, remaining platform edge cases, and Luna-driven BioRouter tasks remain required above; Windows/Linux fixture passes are recorded separately.
A previously tested revision of 0002-native-capture-isolation.patch had SHA-256
20e89fcc73cd6ae81d226da87ac097e164230a816472e2f7631676771630ac96.
This is historical receipt identity, not the final shipping hash. The final patch
hash is 12214baff26bcc4a3eb4b085a08004f74ba16e8b6a2d010c633be682fb38ab67;
all five target jobs and the aggregate gate passed native CI run 35273394648.
The local build receipts below describe their recorded revision unless stated otherwise.
The original GTK fixture caught a real scroll failure: the helper ignored its
element target and used a keysym as a hardware keycode. Targeted focus and proper
AT-SPI key synthesis fixed it; the independent scroll assertion was retained.
- All five
scripts/computer-use-runtime.py build <target>builds completed:darwin-arm64,darwin-x64,win32-x64,linux-x64, and container targetlinux-arm64. Builds used one worker at reduced priority. scripts/computer-use-runtime.py verify <target>passed for all five payloads at that tested revision.target/computer-use/evidence/local-payload-builds-final.jsonrecords actual executable/manifest digests, architecture output, source pin, and patch hashes.- Both Mac payloads passed
scripts/test-computer-use-protocol.py: version 0.3.5, protocol 2025-03-26, exactly ten tools. Intel execution was through local Rosetta; CI separately runs on the nativemacos-26-intelrunner. No capture/input was performed by these protocol checks. - The Mac bundles are ad hoc signed locally. A raw proxy-disabled passive doctor
inherited parent permissions and reported ready; this is not the app-agent
permission result. The actual launched BioRouter helper app-agent reported
os_permission_required, Accessibility false, Screen Recording false, desktop available true. No permission was enabled automatically. Developer ID signing, notarization, TCC upgrade continuity, and user-approved GUI checks remain open. scripts/test-computer-use-packaging.py: 11 tests passed, including missing and mutated bytes, wrong target/architecture, extra foreign files, symlink rejection, stale pin, Node/Python verifier agreement, final ZIP tampering, and GUI+CLI dependency declarations. Bash, Python and Node syntax checks passed.- The tested
target/computer-use/linux-arm64payload passedscripts/test-computer-use-linux-fixture.pyinside a Debian ARM64 container capped at one CPU and 2 GiB, with Xvfb, Openbox, GTK3 and a real user D-Bus/AT-SPI bus. Receipts:target/computer-use/evidence/linux-arm64-fixture-final.json, its sibling PNG, and/tmp/biorouter-cu-linux-arm64-fixture-final.log. This fixture independently observes actual application state; it is not merely Xvfb startup or a protocol handshake. The container never uses the host desktop. computer-use-native.ymlrequires all four release targets plus container ARM64. Native jobs have a 30-minute bound, fixtures five minutes, and the aggregate gate five minutes. Windows session 0 exits 77 and fails the required fixture gate instead of reporting desktop validation. Latest macOS and Linux hosted native jobs passed. A historical Windows fixture caught wheel delivery at coordinates (0, 0). The fix is included in the final patch; the final hosted Windows fixture passed text, key, vertical/horizontal scroll and capture checks.
Runtime artifacts remain under ignored target/computer-use/; the tested ARM64
Mac payload is also staged at ui/desktop/src/computer-use. No release version
was changed and no release artifact was published by the packaging lane.
The Linux x64 native executable also passed the same real GTK fixture under Docker
CPU emulation on the ARM64 host. Before this run, the container was disconnected
from its network and PATH was restricted to /usr/bin:/bin; the test explicitly
asserted that Node, npm, Go, Swift, and git were absent. Protocol and full fixture
checks still passed (exit 0). Receipt:
target/computer-use/evidence/linux-x64-emulated-offline-fixture.json and sibling
PNG/log. This demonstrates offline, toolchain-free native-helper operation, but
is distinguished from the native x64 hosted runner and final BioRouter package
installation tests.
The corrected self-contained ARM64 app was packaged into a 301 MiB ZIP, fully
extracted, and checked against the final production CLI/daemon hashes. Strict deep
ad hoc signature verification passed after extraction, and its dependencies are
self-contained. Receipt: target/computer-use/evidence/packaged-macos-final-archive.json;
archive SHA-256 486d61ed8559d88cac03e7ab18de8d865dd9ee204dfb2b62a6880edfa28f8eac.
The packaged doctor passed helper integrity checks without a helper-path override
and correctly reported TCC denied: packaged-macos-doctor-final.json in the same
evidence directory. The actual CLI setup-path installer passed with an isolated
temporary symlink target: installed-macos-cli-doctor.json. Dependency evidence
records 442 module entries (packaged-dependency-self-contained.json), 32 contained
links (packaged-macos-filesystem-links.json), and all 73 original npm bin links
preserved (npm-bin-links-before-package.json). Four packaging regressions passed
after fixing the earlier dependency-link defect. This proves local packaging and passive
diagnostics, not live Biorouter Copilot permission or control. Developer ID release
signing, notarization, installed-platform coverage and TCC upgrade continuity
remain open. No release artifact has been published.
Remaining platform edges are explicit: Windows drag, mixed DPI, multiple monitors, occluded windows and secure-desktop behavior remain unvalidated; Linux mixed DPI, multiple displays and drag remain unvalidated, and Wayland pixel capture remains unsupported. These gaps do not negate the observed fixture passes or imply full platform coverage.