CoreModuleManager and main.cpp each carried a hand-written `extern "C"` mirror
of liblogos' core-management ABI -- two blocks declaring the same symbols in
one image, an ODR hazard with no diagnostic. Both are replaced by
logos::qt::QtLogosCore over logos::host::LogosCore, which owns the
char*/char** marshalling, the `delete[]`-not-`free()` rule, and the pre-start
ordering constraint -- the last as constructor arguments, so the illegal order
stops being expressible.
Four things about the stats path that fail INVISIBLY, all preserved:
* "cpu"/"memory" stay 1-decimal STRINGS -- QML and ModuleInstanceModel bind
those names, so the facade's cpuPercent/memoryMb spelling stops here
* allStats() is called ONCE per tick; each moduleStats(name) repeats the
full C call and parse, and the snapshot walks every known module
* the three-way back-compat fallbacks are kept for older runtimes
* memoryMb (double), never memoryBytes
The cpp-sdk lock moves for that last point: the pin predated the rename, and
that pair does not compile -- qt-sdk's header reads s.memoryMb while the
pinned cpp-sdk struct still called it memoryBytes.
Also drops a QTimer in main.cpp that was started and stopped with no
connect() at all.
Each loaded plugin -- including pure-QML ones -- gets its own LogosAPI identity
rather than sharing the host's, so a plugin's calls are attributable and can be
refused independently. The host-services grant is wired through to
capability_module, and its trust root is guarded on an OUTCOME rather than a
log line.
Inter-module access policy stays OFF by default: enforce mode's derived
deny-by-default gates every ui_qml app's calls to its own backend module,
because UI plugins load out-of-process and are not tracked as dependents in the
core ModuleRegistry. Operators opt in per launch with --access-policy enforce
or LOGOS_ACCESS_POLICY.
Takes the Qt host runtime from logos-plugin-qt rather than logos-qt-sdk, which
keeps only the Qt<->lp seam headers, and moves logos-protocol onto the rev that
split host needs. On Windows logos_core must come LAST on the link line: GNU ld
resolves an archive left to right, so the view runtime's references have to be
undefined already when it reaches the import library.
Separates the two source trees -- app/ is the host, src/ is the UI shell -- and
brings the CI onto setup-nix-cache-action. Merges master.
Pass NULL to logos_core_set_access_policy so no enforcement runs. With the
protocol json-convert fix, registerRestriction now actually applies (it used
to fail-open on its QJsonArray arg), which activated enforce mode's derived
deny-by-default. That gates every ui_qml app's calls to its own backend
module: UI plugins load out-of-process and aren't tracked as dependents in
the core ModuleRegistry, so they're never in a module's derived
allowed-caller set (e.g. accounts_ui -> accounts_module is denied). Disable
the policy for now; revisit the design to account for ui_qml callers.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add MCP server; add integration tests; run integration tests on the CI
test mcp server
improve mcp functions; add test framework
support running headless tests
restructure to prepare to move repos
add agents.md with instructions on how to run and test app
use logos-qt-mcp flake
run integration tests in the CI
use flake mcp server from logos-qt-mcp
update ui tests to fetch from the right location
use test app when running integration tests
run integration tests as separate checks
re-add smoke test just for builds
increase timeout
output tests as they are running
use --verbose
fix mac tests
* properly handle portable modules
* preinstall modules on startup instead of bundling them at build time
* get icons from manifest
* consistent user dir
* revert to main branch of dependencies
* add release derivations
* add appimage release job
* fix app icon on Linux
qt ios app using liblogos and capability-module/package-manager modules; wip
qt ios app using liblogos and capability-module/package-manager modules; wip
working including modules (but not loading)
working ios app
fix get plugins method
update flake
update flake
rename dir
refactor/cleanup
refactor/cleanup
update title
support icon
refactor
fix so it works correctly with new packages
fix app name
simplify plugin loading
update flake