Conversation
…ndbox - New app kind: App v2 manifests with runtime.kind polkavm-computer boot a DOM terminal (ANSI/VT emulator + TTY keyboard, ported from pvm-terminal) instead of a canvas; every VM runs in pvm-computer-worker.js via the vendored pvm-computer.js supervisor (spawn/pipes/fault containment). - /home persists per computer as one length-prefixed IndexedDB record, written on every modified-file drain (debounce would race reloads) and restored under archive home/ seeds on boot. - resolver: PolkaVmComputerManifestV2 + validators (terminal capability required, optional child packages, graphics/input/audio rejected). - Runtime assets re-pinned directly to pvm-host-runtime@c7ec6cb (feat/browser-computer prototype; bridge pin restored at next release); sync script exports from the runtime checkout and now ships pvm-computer.js. - Functional spec: real shell guest boots, kilo edits as a sandboxed child VM, /home survives a frame reload.
…ifest kind
The capability request is the discriminant: runtime.kind stays polkavm and
capabilities.host.requires names versioned interface ids
(polkadot-host/0.1/{core,fs,tty,process}). Contract versioning rides on the
ids, so runtime.abiVersion is forbidden for host-interface apps, and hosts
fail closed on any interface they cannot provide. Removes the redundant
polkavm-computer runtime kind pending a TruAPI RFC for the namespace.
…est gate spawn(name) no longer requires manifest enumeration: an unregistered package suspends the supervisor, the sandbox asks the host shell for the label's executable record (dotli:computer-resolve-app), fetches the app archive by CID, verifies the child's OWN signed manifest declares the host contract, and hands the program to the worker. The child clamps to the parent's grant; unresolvable names fail the spawn with NOT_FOUND and the shell survives. Runtime repinned to bd889a2 (supervisor package resolution). Fixture now proves it: kilo is absent from the computer's manifest and resolves as its own published app.
The same host-profile artifacts that open-spawn from the shell also boot as root applications. Chromium coverage edits and saves through both Vim and Kilo; root argv[0] now derives from the manifest entrypoint.
Requiring polkadot-host/0.1/net no longer gates booting: when the build has no VITE_PVM_TCP_RELAY_URL the sandbox clamps networking off and TCP hostcalls return DENIED, so the terminal keeps working. Gateway builds previously failed the whole app with 'network app requires VITE_PVM_TCP_RELAY_URL'.
- polkadot-host/0.1/workspace joins the resolver and sandbox interface registries; requiring it enables the supervisor's workspace capability. - Spawned children cannot elevate the parent's workspace grant, mirroring the network clamp. - Pin the workspace-capable pvm-computer.js adapter (runtime feat/workspace-tiling @ c89503d) in the runtime lock. - Functional proof: workspace.polkavm spawns three independently sandboxed shell panes, tiles them with a live status bar, routes input to the focused pane, closes a pane, and exits cleanly.
Any published app now runs inside a workspace pane without being declared in the workspace manifest: an unresolved spawn anywhere in the supervision tree (workspace_spawn or a pane shell's process_run) suspends, the page resolves the label through the host bridge, and the provided package joins the shared registry. capabilities.packages is demoted to an optional version pin. Repin the resolution-capable adapter (runtime feat/workspace-tiling @ 4b7a99d).
The runtime now forwards mount_file to every live child, so home/ seeds provided at open-resolution time land in the already-running pane that requested the package. Functional proof: a workspace pane open-spawns published Lynx; the greeting from the seeded index.html renders inside the pane, then HTTPS browsing exercises cacert.pem, the permission grant, and the TCP relay — the whole chain inside one tile. Repin the adapter (runtime feat/workspace-tiling @ a33bb6d).
The tiling guest gains Omarchy-style policy: Ctrl-B o opens a run prompt that spawns any Host-resolvable app directly as a pane (launcher arguments pass verbatim, so paths use the absolute /home form), H/J/K/L swap the focused pane with its neighbor, and 1-9 switch virtual workspaces whose panes keep running while hidden. Nonzero pane exits surface on the status bar instead of vanishing. Repin the cap-9 adapter (runtime feat/workspace-tiling @ 7ad6778).
b6166fb to
944acd4
Compare
|
Offscreen render fix is verified and wired through canonical runtime e6e1c91e23929a6c2d28cfda56f244d3d43add41 and SDK d1888c2cfee24d11d8cbab999dc0c60b8cc11d20. Same Zed guest now executes the failing composition/selection/copy scenario with 88 offscreen passes and no panic; sandbox typecheck and 30 focused tests pass. No deploy label applied. Deployment is held because newer deployed feat/pvm-wasm commit 2d302ac uses @useragent-kit/polkavm-runtime 0.1.0 with runtime ABI 1, whereas this integration and Zed 0.3.0 use ABI 2. Do not overwrite that newer rollout with this branch without an explicit compatibility decision. |
b30ee0c to
f60c4ae
Compare
|
Superseded by #216 on the current deployed feat/pvm-wasm baseline. The accepted application ABI remains 1; do not deploy this older ABI2 branch. |
Change
Restack workspace input and surface fixes onto the canonical PolkaVM runtime branch without restoring obsolete public names.
Verification
Only westendli.dev is approved for deployment. No deploy label is applied yet.