Development

Desktop delivery plan

This proposed plan tracks implementation of RFC 1455 under #1428. The RFC defines user behavior and architectural contracts; this plan records phases, owners, measurements and acceptance evidence. Scheduling and tuning can evolve without redefining those contracts. The entries below are requirements, not completed work or qualification results. Accepting the RFC or shipping a connect-only preview does not close #1428.

Source facts use the RFC's baseline, upstream 62e4c821709c18b832c77363fdd428765bee6a96, checked on 2026-09-13. Recheck platform blockers and producer availability against the artifacts selected for delivery.

Producer coordination

D1–D6 and D8 identify producer contracts in the RFC. D7 tracks staffing and release qualification in this plan. Assign named maintainers and link producer work before the corresponding phase exits.

IDProducer / related workRequired contractGate
D1Server/APIserver-info, deployment identity lifecycle, explicit compatibility profilesCompatibility-dependent P1/P2 controls
D2Server/MemoryAuthorized bounded entry listing and, before history UI, bounded change/history queriesComplete Memory browsing in P2
D3Service/configuration, RFC 1299Noninteractive structured mutations, protected input, ownership and recoveryManaged service/configuration changes in P3
D4Installer #1406, RFC #1408Verified bootstrap, plans, locks, durable operation/status and recoveryManaged install/update in P3
D5Distribution #1405, RFC #1410Immutable host artifacts, compatibility and host-owned install adaptersSelected-host install in P3
D6Delivery #1419Receiver association, envelope, durable inbox, exact references, deduplication and recoveryDelivery consumption in P4
D7Desktop/release maintainersNamed owners, Windows/host qualification, supported versions and measured budgetsP0 exit and P5 release
D8Server/connector ownersPublic connector discovery, health and administrative operations, if offeredOnly corresponding connector controls

Platform, accessibility and budgets

PlatformProposed statusQualification
Windows 11 x64 + SQLiteFirst target; current project Windows support is experimentalSigned standard-user install, WebView2 absent/present, Credential Manager, Task Scheduler/login, notifications/activation, non-ASCII paths
macOSFollow-upNamed architectures, Keychain, LaunchAgent, signing/notarization, WebView/notification behavior
LinuxFollow-up per distro/desktopWebKitGTK/system libraries, Secret Service, systemd session, tray, package/activation

Windows ARM and Windows embedded seekdb are excluded. Compiling a framework does not qualify a platform. P0 names Desktop/Install/Server/Release owners and one maintained Agent Host/version, with observed Windows load and explicit capture/recall. “Any maintained integration” cannot pass that gate; P4 names an actual sender/receiver pair.

At the source baseline, native Windows type checking exposes Connection/PipeConnection mismatches in processing workers and POSIX-only os.WNOHANG references in tests. Resolve or correctly platform-scope these checks before Windows qualification; passing a Linux-target type check does not establish Windows support.

P0 Go/No-Go evidence: UI without Python/Server, authenticated API read/write, credentials, signed standard-user package, WebView2 bootstrap, independent service/login, installed notification cold activation. D4/D5 full bootstrap can remain gated at P3; P0 records producer commitments and limits preview to connect-only. Native blockers must be solved or the platform/scope reconsidered. Electron fallback addresses demonstrated shell/WebView/maintenance blockers, not installer gaps.

Maintain English/Chinese UI and docs, keyboard navigation, focus, screen-reader labels, IME-safe forms, high contrast, non-color-only status, and usable confirmation/recovery at 800 × 600 and 200% zoom. Locale/theme changes retain identity.

Measure cold start, idle CPU/wakeups, desktop+WebView+Server memory, full installation/download size and list/search latency. P0 records hardware, OS/WebView versions, datasets, repeat count and p50/p95; fixes numeric release budgets before P2 expansion. Include empty/multi-page, model-free/configured cases. D7 owns the published budget; there is no current performance claim. Transport/notification operating caps do not replace measurements.

Delivery phases

PhaseDeliverableExit requirement
P0: architectureBundled client, narrow transport, credentials, installed Windows spike, UI reuse and measurementsD7 owners/host; security evidence; D1/D2 assigned; D3–D6 limits recorded
P1: connect-only previewExisting local/remote connection, tested compatibility, service status, explicit Memory store/recall, Agent diagnosticsQualified operations/identity; no unimplemented install claim
P2: management/accessScope/assets/Sources, typed Review, exact shared resources/reports, import, covered Review notifications, diagnosticsD2 full Memory browsing; authorization/concurrency/family contracts
P3: managed installationClean-machine install, chosen host, service/config changes, migration/update/recovery/removalD3/D4/D5, signed immutable artifacts and ownership acceptance
P4: deliveryDurable inbox, target association, resume, exact navigation and supported receiver actionsD6, named sender/receiver, bounded consumer and installed activation
P5: first qualified releaseComplete #1428 journey on Windows 11 x64All applicable AC, compatibility/support matrix, published budgets
P6: more platformsQualified macOS/Linux packagesRepeat installed acceptance per advertised environment

P3/P4 progress independently when dependencies exist; P2 authorization does not wait for delivery. Reuse existing tracking issues. Keep producer contracts and consumers in focused PRs. A blocked mandatory AC cannot be marked inapplicable to close #1428: full closure needs managed local setup, authorized remote use, durable Handoff delivery, Review/Handoff notifications, recovery, accessibility and data-preserving removal on one platform.

Acceptance and verification

Owners: Desktop owns packaged UI/native behavior; Server public semantics; Install installer/service/configuration/ distribution; Delivery D6; Release signed-platform qualification. These are responsibilities, not named staffing; D7 binds maintainers before P0 exit. Each record identifies versions, environment, fixture, result and owner; one smoke test cannot stand for every scenario in a row.

IDPhase / ownerRequired observable behaviorEvidence entry
AC-01P3/P5 · Install + DesktopClean machine: verified runtime/host, model-free Memory store/fts recallInstalled first use
AC-02P1/P3 · InstallStale/foreign/occupied states distinguished, unknown ownership preservedService JSON/native lifecycle
AC-03P3/P5 · Desktop + InstallClose/Quit/restart/login preserves independent service/work and chosen startupInstalled lifecycle/recovery
AC-04P3/P5 · Install + ReleaseInterrupted update/signature/readiness failure has durable component status and compatible recoveryInstaller fault/restart
AC-05P1/P2 · Server + DesktopMissing/old/unknown handshake, missing feature, changed identity: no guessed support/retargetD1 connection fixtures
AC-06P1 · DesktopLoopback/base path/plaintext/TLS/redirect/proxy limits are accurate, no credential forwardingShared vectors/native transport
AC-07P1/P2 · DesktopProfile/endpoint/token/Principal changes isolate responses, cursors, drafts and mutation targetsConcurrent packaged interactions
AC-08P2 · Server + DesktopExact Handoff grant works without Scope listing; latest/adjacent/broad/evidence leakage deniedAccess plus desktop journey
AC-09P2 · Server + DesktopFilter before paging/counts, no unsafe fallback, Review/publication authorizedAccess/mutation contracts
AC-10P2 · Server + DesktopStale version/citation, duplicate submit, lost response: no silent approval/replayMutation recovery scenarios
AC-11P4 · Delivery + DesktopOffline arrival, cursor expiry, revocation/cancellation recover exact authorized inboxD6 and receiver pair
AC-12P0/P4 · Desktop + ReleaseInstalled hints, permission denial, bursts, Quit and stale activation safely navigate/fall backNative/cold activation
AC-13P2 · Server + DesktopSame/renamed/changed text, BOM/newlines, invalid/oversize and ambiguous import follow identity/limitsImport/handle fixtures
AC-14P0/P2 · DesktopMalicious content, fake generation/window/path/link cannot execute, leak secrets or mutate unexpectedlyPackaged capability/CSP
AC-15P0/P5 · Desktop + ReleaseSecret canaries absent from logs, URLs, notifications, exports, renderer storage and telemetryOutput inspection
AC-16P3/P5 · InstallRemoval preserves data, user edits and referenced independent consumersInstalled removal
AC-17P2/P5 · DesktopBoth locales, keyboard/IME/reader/contrast/small window/200% zoom complete supported actionsAccessibility journey
AC-18P0/P5 · ReleaseExact signed artifacts measured on reference machine meet published budget at P5Benchmark/support record
AC-19P2 · Server + DesktopLarge/changing Memory fully traversable under D2 or honestly limited before D2Large-Scope fixtures
AC-20P2 · Server + DesktopProfile Review, Topic Memory and unknown family retain typed/read-only boundariesFamily/Review fixtures
AC-21P1/P3 · Server + Install + DesktopStatic/injected Provider, generic 401/503, partial rotation have true identity/error/recoveryAuth/configuration journey
AC-22P2 · DesktopBacklog, multi-page, changed/partial coverage obey budgets without fabricated counts/historyPolling behavior
AC-23P3 · Install + ReleaseUpdater exit and stable/preview sharing preserve producer recovery and single management ownerPackaged update/channel
AC-24P0/P2 · DesktopNo Python/Server: setup works; shared assets do not drift; management uses public API onlyDesktop build/Dashboard regression
AC-25P3 · Server + InstallMaintenance migration resumes same ID, verifies before traffic, no incompatible rollbackMigration/install recovery
AC-26P4 · Delivery + DesktopMultiple devices/targets and unenrolled Agent do not impersonate or convert hints into acceptanceTarget association

Implementation PRs run make check and relevant behavior tests; changed contracts additionally run make api-generate and make contract-test. Reuse Server/access/transport/migration/native service tests. Shared UI needs Dashboard regression plus desktop behavior; packaging needs real installed tests. Docs run make docs-test (Fumadocs), verify titles/navigation/links and matching bilingual phase/dependency/AC IDs. A mock or docs build cannot qualify native behavior.

Implementation tuning and measurement

Select and record values during implementation; the RFC does not prescribe initial operating defaults. Distinguish existing Server limits from client choices, and keep observable guarantees unchanged when tuning.

ChoiceEvidence required before enabling the feature
Polling interval, jitter, concurrency and request rateAttention latency versus idle CPU, wakeups and Server load; limits also hold during manual retry
Candidate page size and traversal expiry/recoveryRespect API limits; empty, multi-page, large backlog and concurrently changing lists; later pages progress or coverage is explicitly limited
Failure backoffDisconnect/reconnect, authentication rejection and Server retry delay behavior
Notification metadata capacity and retentionBounded storage, deduplication, safe expiry/eviction and cold activation without changing Server read/delivery state
Transport timeouts and decoded response/export limitsSlow/large responses, cancellation and streaming; operation-specific recovery rather than blind mutation replay
Import file/content limitsBounded reads and Unicode handling; explain limits before confirmation and reject oversize content without truncation

Record the selected values, reference environment, datasets and measurements in the implementation/release record. Use behavior and regression tests for incomplete counts, changed coverage, backlog progress and private notifications; do not freeze a polling interval or internal call count unless it is itself a published external budget.

Coordination decisions

These questions have proposed defaults and explicit gates. Missing dependencies remain delivery prerequisites, not claims of implemented functionality or a reason to withhold this design from review.

Practical questionProposed defaultDecision gate
Which OS first, and who maintains/releases it?Windows 11 x64 + SQLite; name Desktop/Install/Server/Release owners and one Agent Host/versionPlatform at RFC acceptance; staffing/host before P0 exit
How much UI do we share?Assets/conventions/translations/components; independent client management entry, no mandatory Dashboard rewriteRFC acceptance
Can we ship before installation/delivery are ready?Connect-only preview, then management; independent P3/P4; #1428 remains open until completeRFC acceptance
Which remote deployments work initially?Direct HTTPS, operator-issued Bearer; no proxy/SSO/plaintext opt-inRFC acceptance; expand only through qualified adapters
Which Server versions work, and how do restore/clone affect identity?D1 explicit versions/lifecycle; qualify 1.0.0 as legacy candidateP0 contract agreement before dependent controls
Who supplies installation/delivery and when?D3–D6 producers own schemas/recovery; no private desktop replacementBefore P3/P4 commitments
How fast and small must the complete product be?Measure named hardware, publish numeric budgets including Python/WebViewP0 exit before P2 expansion

On this page