Implement data recovery for failed agent catalog v1 migrations

Add recovery-point inventory and atomic restore, data-recovery IPC surface,
and app-level migration-blocked notice that persists until retry succeeds or
a pre-v1 backup is restored. Offline CLI writes are schema-transparent: they
refuse pre-v1 file downgrades and never stamp v1 fields without the pinned
backup contract. Mobile surfaces the blocked state in the agent picker.
Web clients probe host identity-launch capability and degrade to legacy paths
on pre-identity hosts, failing fast for custom agents or stored defaults that
cannot resolve.
This commit is contained in:
Jinjing
2026-09-01 03:53:17 -07:00
parent a86f0c310b
commit 4576ddf77f
41 changed files with 1800 additions and 1469 deletions
+1 -3
View File
@@ -361,9 +361,7 @@ jobs:
# into the REMOTE worktree, and observes the spawned process's argv+env from
# /proc inside the container — proving one host resolution produced one remote
# PTY with the exact custom executable/args/env, and that reconnect never
# duplicates the launch. Ubuntu-only because macOS/Windows GitHub runners
# cannot host a Linux Docker container (the platform matrix in pr.yml covers
# the pure-resolution cross-OS cells instead).
# duplicates the launch.
ssh-custom-agent:
name: e2e ssh custom agent
needs: build