Web Console: Runtime and session view (Phase 1) #641

Closed
opened 2026-07-10 14:40:14 -05:00 by jcwalker3 · 2 comments
Owner

Problem statement

MVP runtime page (#430) shows MCP health/stale detection but not a full runtime and session view correlating namespaces, sessions, capabilities, worktree bindings, and contamination/stale markers for operator diagnosis.

User and operational impact

Hard to answer: which sessions are live, which namespaces are stale, which worktrees are bound, whether recovery was sanctioned.

Scope

  • View combining runtime health + inventory sessions/namespaces/worktrees.
  • Show profile/role, namespace, pid if available, lease bindings, stale flags, contamination warnings when detectable (#630).
  • Read-only; link to sanctioned recovery docs (auto-reconnect, operator restart) not pkill.

Explicit non-goals

  • No restart/kill controls (Phase 2).
  • No session takeover mutations.

Required implementation investigation

runtime_health.py, #430, #636, #634, #630, #584, #610, #631.

Proposed architecture or implementation direction

Compose health + inventory DTOs; table per namespace/session; detail drawer optional later.

Security and workflow-safety requirements

Redact secrets; do not expose tokens; contamination must not be silent.

Acceptance criteria

  1. Sessions/namespaces listed with role and stale indicators.
  2. Worktree binding shown when known.
  3. Contaminated/manual-kill markers surfaced if available.
  4. Tests with fixture runtime+inventory.
  5. Docs link sanctioned recovery paths only.

Required tests

Render tests for stale and clean sessions.

Observability and audit requirements

Read-only.

Dependencies and linkage

Canonical issue state

STATE: ready-for-author
WHO_IS_NEXT: author
NEXT_ACTION: Implement runtime/session view
NEXT_PROMPT: Author view only; PR; stop

Required final evidence

PR with view, tests, docs.

Required final response and handoff expectations

Brief PR → reviewer.

## Problem statement MVP runtime page (#430) shows MCP health/stale detection but not a full **runtime and session view** correlating namespaces, sessions, capabilities, worktree bindings, and contamination/stale markers for operator diagnosis. ## User and operational impact Hard to answer: which sessions are live, which namespaces are stale, which worktrees are bound, whether recovery was sanctioned. ## Scope * View combining runtime health + inventory sessions/namespaces/worktrees. * Show profile/role, namespace, pid if available, lease bindings, stale flags, contamination warnings when detectable (#630). * Read-only; link to sanctioned recovery docs (auto-reconnect, operator restart) not pkill. ## Explicit non-goals * No restart/kill controls (Phase 2). * No session takeover mutations. ## Required implementation investigation `runtime_health.py`, #430, #636, #634, #630, #584, #610, #631. ## Proposed architecture or implementation direction Compose health + inventory DTOs; table per namespace/session; detail drawer optional later. ## Security and workflow-safety requirements Redact secrets; do not expose tokens; contamination must not be silent. ## Acceptance criteria 1. Sessions/namespaces listed with role and stale indicators. 2. Worktree binding shown when known. 3. Contaminated/manual-kill markers surfaced if available. 4. Tests with fixture runtime+inventory. 5. Docs link sanctioned recovery paths only. ## Required tests Render tests for stale and clean sessions. ## Observability and audit requirements Read-only. ## Dependencies and linkage * Parent: #631 · Extends: #430 · Soft-depends: #636, #634 · Related: #630, #584, #610 ## Canonical issue state ```text STATE: ready-for-author WHO_IS_NEXT: author NEXT_ACTION: Implement runtime/session view NEXT_PROMPT: Author view only; PR; stop ``` ## Required final evidence PR with view, tests, docs. ## Required final response and handoff expectations Brief PR → reviewer.
Author
Owner

Canonical Issue State

STATE:
ready-for-author

WHO_IS_NEXT:
author

NEXT_ACTION:
Implement runtime and session inventory view; link #652 #653 Phase 1

NEXT_PROMPT:

AUTHOR prgs Gitea-Tools. Implement #641. Vision #652 · Roadmap #653 Phase 1 · Soft-depends #636 #634 · Extends #430 · Related #630. Lock; branches/; PR; stop. Closing ≠ vision complete.

WHAT_HAPPENED:
Linked to #652/#653. Not recreated.

WHY:
Initial batch linkage.

RELATED_ISSUES:
#652 #653 #631 #636 #634 #430 #630

RELATED_PRS:
none

BLOCKERS:
none

VALIDATION:
existing retained

LAST_UPDATED_BY:
jcwalker3 / prgs-author / author / 2026-07-10

## Canonical Issue State STATE: ready-for-author WHO_IS_NEXT: author NEXT_ACTION: Implement runtime and session inventory view; link #652 #653 Phase 1 NEXT_PROMPT: ```text AUTHOR prgs Gitea-Tools. Implement #641. Vision #652 · Roadmap #653 Phase 1 · Soft-depends #636 #634 · Extends #430 · Related #630. Lock; branches/; PR; stop. Closing ≠ vision complete. ``` WHAT_HAPPENED: Linked to #652/#653. Not recreated. WHY: Initial batch linkage. RELATED_ISSUES: #652 #653 #631 #636 #634 #430 #630 RELATED_PRS: none BLOCKERS: none VALIDATION: existing retained LAST_UPDATED_BY: jcwalker3 / prgs-author / author / 2026-07-10
jcwalker3 added status:pr-open and removed status:ready labels 2026-07-24 21:47:05 -05:00
Owner

[THREAD STATE LEDGER] PR #898 — APPROVED review posted to Gitea

NATIVE_REVIEW_PROOF: transport=native_mcp; entrypoint=mcp_server; profile=prgs-reviewer; session_pid=44554; writer_pid=44554; workflow_hash=263d0a6cb8a6; final_report_schema_hash=b6c65affc336; boundary_status=clean; runtime=stable-control@2f4dec832327 on master; mutation_safe=true; review_verdict_visible=true

What is true now:

  • PR state: open
  • Current head SHA: d5d121a21b
  • Server-side decision state: APPROVED review posted to Gitea at the pinned head
  • Local verdict/state: APPROVE verdict prepared locally, then posted as an APPROVED review
  • Latest known validation: 512 passed / 376 subtests (webui suite); 13 passed / 8 subtests (issue 854); 391 passed / 0 failed (20-file runtime/health/inventory/restart glob)

What changed:

  • APPROVED review posted to Gitea at pinned head d5d121a2, superseding review 586 (REQUEST_CHANGES @ a81db754)

What is blocked:

  • Blocker classification: no blocker

Who/what acts next:

  • Next actor: merger
  • Required action: merge on explicit operator command, pinned to expected_head_sha d5d121a2
  • Do not do: re-review, re-post APPROVE, or reuse review 586
  • Resume from: PR #898 review feedback

Server-side mutation ledger:

  • gitea_acquire_reviewer_pr_lease -> reviewer lease acquired (comment id 16538)
  • gitea_submit_pr_review -> APPROVED review posted to Gitea at d5d121a2

Canonical Issue State

STATE:
PR-open

WHO_IS_NEXT:
merger

NEXT_ACTION:
Acquire a merger lease and merge PR #898 pinned to head d5d121a21b.

NEXT_PROMPT:

Merge PR #898 (issue #641) on remote=prgs, org Scaled-Tech-Consulting, repo Gitea-Tools, pinned to expected_head_sha d5d121a21b43888b013aa2a8460510f90e771e7c. The APPROVED review by sysadmin / prgs-reviewer is recorded at this exact head. Confirm mergeable and commits_behind 0 via gitea_assess_pr_sync_status before acting; if the head has moved, stop and request a fresh review instead.

WHAT_HAPPENED:
The author remediated both blockers from review 586 in commit 1ca2b504 and brought the base current via update-by-merge, producing head d5d121a2. A fresh reviewer session under sysadmin / prgs-reviewer (distinct from author jcwalker3 / prgs-author) verified both fixes against independent fixtures, mutation-tested the new regression cases, and posted an APPROVED review.

WHY:
B1 (ownership authority not threaded from section status) and B2 (contamination marker fields bypassing redaction) are both proven fixed. The narrow B1 variant — locks readable with real worktree_path values while leases are degraded — now renders "unknown (inventory degraded)" with an authority-unproven badge instead of the false affirmative "unbound". The fix is not over-broad: clean inventory still renders affirmative "none" and "unbound". All five B2 secret classes are redacted on both the HTML page and /api/sessions, with command_summary retained as #630 evidence. Neutering B1, B2, and the unreadable-sessions branch produced 4, 6, and 1 test failures respectively, so the new cases pin the behavior rather than merely pass. scrub() and every existing caller are unchanged (zero deletion lines in webui/inventory.py).

RELATED_DISCUSSION:
Author remediation handoff comment 16523; superseded review 586 @ a81db754

RELATED_PRS:

BRANCH:
feat/issue-641-runtime-session-view

HEAD_SHA:
d5d121a21b

VALIDATION:
pytest tests/test_webui_sessions_view.py tests/test_webui_*.py -q -> 512 passed, 376 subtests (author baseline at a81db754 was 498 / 372; the delta is exactly the 14 new regression cases). pytest tests/test_issue_854_semantic_container_exclusion.py -q -> 13 passed, 8 subtests. Runtime/health/inventory/restart glob (20 files) -> 391 passed, 0 failed; test_runtime_clarity.py::TestRuntimeClarity::test_activate_profile_succeeds_when_enabled fails only in isolation and fails identically on master 7af40fb5, so it is baseline-equivalent and not introduced here.

BLOCKERS:
none

LAST_UPDATED_BY:
sysadmin / prgs-reviewer / 2026-07-25


Non-blocking follow-ups (not conditions of this approval):

  • N3 — the {"active","alive","running","ok"} status allowlist is deliberately kept. The author's rationale is accepted: it fails loud on an unrecognized status, and inverting it to an explicit unhealthy set changes flag semantics beyond the two blockers. Worth a separate issue, not a hold on this PR.
  • N5 (new, cosmetic) — _combined_authority returns the first non-ok status rather than the worst, though its docstring says "Worst status". With leases degraded and locks unavailable the displayed label reads "degraded". Safety behavior is unaffected: any non-ok status triggers the unknown cell, so no false absence is ever asserted.
[THREAD STATE LEDGER] PR #898 — APPROVED review posted to Gitea NATIVE_REVIEW_PROOF: transport=native_mcp; entrypoint=mcp_server; profile=prgs-reviewer; session_pid=44554; writer_pid=44554; workflow_hash=263d0a6cb8a6; final_report_schema_hash=b6c65affc336; boundary_status=clean; runtime=stable-control@2f4dec832327 on master; mutation_safe=true; review_verdict_visible=true What is true now: - PR state: open - Current head SHA: d5d121a21b43888b013aa2a8460510f90e771e7c - Server-side decision state: APPROVED review posted to Gitea at the pinned head - Local verdict/state: APPROVE verdict prepared locally, then posted as an APPROVED review - Latest known validation: 512 passed / 376 subtests (webui suite); 13 passed / 8 subtests (issue 854); 391 passed / 0 failed (20-file runtime/health/inventory/restart glob) What changed: - APPROVED review posted to Gitea at pinned head d5d121a2, superseding review 586 (REQUEST_CHANGES @ a81db754) What is blocked: - Blocker classification: no blocker Who/what acts next: - Next actor: merger - Required action: merge on explicit operator command, pinned to expected_head_sha d5d121a2 - Do not do: re-review, re-post APPROVE, or reuse review 586 - Resume from: PR #898 review feedback Server-side mutation ledger: - gitea_acquire_reviewer_pr_lease -> reviewer lease acquired (comment id 16538) - gitea_submit_pr_review -> APPROVED review posted to Gitea at d5d121a2 ## Canonical Issue State STATE: PR-open WHO_IS_NEXT: merger NEXT_ACTION: Acquire a merger lease and merge PR #898 pinned to head d5d121a21b43888b013aa2a8460510f90e771e7c. NEXT_PROMPT: ```text Merge PR #898 (issue #641) on remote=prgs, org Scaled-Tech-Consulting, repo Gitea-Tools, pinned to expected_head_sha d5d121a21b43888b013aa2a8460510f90e771e7c. The APPROVED review by sysadmin / prgs-reviewer is recorded at this exact head. Confirm mergeable and commits_behind 0 via gitea_assess_pr_sync_status before acting; if the head has moved, stop and request a fresh review instead. ``` WHAT_HAPPENED: The author remediated both blockers from review 586 in commit 1ca2b504 and brought the base current via update-by-merge, producing head d5d121a2. A fresh reviewer session under sysadmin / prgs-reviewer (distinct from author jcwalker3 / prgs-author) verified both fixes against independent fixtures, mutation-tested the new regression cases, and posted an APPROVED review. WHY: B1 (ownership authority not threaded from section status) and B2 (contamination marker fields bypassing redaction) are both proven fixed. The narrow B1 variant — locks readable with real worktree_path values while leases are degraded — now renders "unknown (inventory degraded)" with an authority-unproven badge instead of the false affirmative "unbound". The fix is not over-broad: clean inventory still renders affirmative "none" and "unbound". All five B2 secret classes are redacted on both the HTML page and /api/sessions, with command_summary retained as #630 evidence. Neutering B1, B2, and the unreadable-sessions branch produced 4, 6, and 1 test failures respectively, so the new cases pin the behavior rather than merely pass. scrub() and every existing caller are unchanged (zero deletion lines in webui/inventory.py). RELATED_DISCUSSION: Author remediation handoff comment 16523; superseded review 586 @ a81db754 RELATED_PRS: - #898 BRANCH: feat/issue-641-runtime-session-view HEAD_SHA: d5d121a21b43888b013aa2a8460510f90e771e7c VALIDATION: pytest tests/test_webui_sessions_view.py tests/test_webui_*.py -q -> 512 passed, 376 subtests (author baseline at a81db754 was 498 / 372; the delta is exactly the 14 new regression cases). pytest tests/test_issue_854_semantic_container_exclusion.py -q -> 13 passed, 8 subtests. Runtime/health/inventory/restart glob (20 files) -> 391 passed, 0 failed; test_runtime_clarity.py::TestRuntimeClarity::test_activate_profile_succeeds_when_enabled fails only in isolation and fails identically on master 7af40fb5, so it is baseline-equivalent and not introduced here. BLOCKERS: none LAST_UPDATED_BY: sysadmin / prgs-reviewer / 2026-07-25 --- Non-blocking follow-ups (not conditions of this approval): - N3 — the {"active","alive","running","ok"} status allowlist is deliberately kept. The author's rationale is accepted: it fails loud on an unrecognized status, and inverting it to an explicit unhealthy set changes flag semantics beyond the two blockers. Worth a separate issue, not a hold on this PR. - N5 (new, cosmetic) — `_combined_authority` returns the first non-ok status rather than the worst, though its docstring says "Worst status". With leases degraded and locks unavailable the displayed label reads "degraded". Safety behavior is unaffected: any non-ok status triggers the unknown cell, so no false absence is ever asserted.
sysadmin removed the status:pr-open label 2026-07-25 05:50:54 -05:00
Sign in to join this conversation.
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: Scaled-Tech-Consulting/Gitea-Tools#641