* feat: enable paired desktop sharing with a Mac settings control
Offer authenticated desktop streams by default on supported persistent nodes while preserving explicit opt-outs, pairing approval, and Gateway deny policy. Add a native Desktop sharing control that reconnects the node and reflects the worker’s resolved configuration.
* feat: add desktop sharing to the Tauri companion
Give the Tauri companion the same persistent desktop-sharing control as the native Mac app, backed by an app-owned desktop-only node for its Primary Gateway. Preserve explicit node opt-outs and require interactive reapproval for legacy desktop grants when the old allowlist was removed.
Keep node authority in the existing CLI and pairing owners. Join owned process trees on preference changes, Primary changes, and Quit; reject stale native setting snapshots.
* test: format launcher shutdown cases
* test: align desktop sharing proof fixtures
* test: clean up desktop sharing lint findings
* test: keep desktop sharing proof reports in order
* test: verify retired dashboard sharing authority
* test: drain shared state before harness fixture cleanup
* test: extract harness transcript fixtures
* test(ui): wait for rendered theme toggle state
* test: adopt main harness cleanup owner
* test: observe Windows wrapper child readiness
* feat(node): update headless runtimes automatically when idle
Stage private packaged node runtimes and activate only after all owned work
and cleanup settle. Preserve pairing and launch options, keep automatic
activations at least 12 hours apart, and leave shared-state migration and
Gateway installation ownership with the normal updater.
Document defaults, opt-outs, runtime version discovery, and recovery.
Support recoverable Windows selector replacement across service restarts.
Refs #151462
* fix(node): complete auto-update integration and settings defaults
Capture the launcher in compiled test runtimes and trusted wrapper inventories, register the package update proof, and use the canonical Kysely read path. Preserve the inherited enabled state in the config UI and align caller tests with the node shutdown lifecycle.
* fix(node): preserve retained plugin work during automatic updates
Require an explicit idle result from plugin commands, preserve older-plugin work, and connect bundled lifetime owners to automatic node updates. Join canceled inference and failed terminal cleanup before command settlement; keep historical state repair with Doctor. Document compatibility and extend installed-package proof for retained legacy plugin work.
* test(browser): align idle-work fixtures with runtime exports
* test(browser): extract proxy request fixtures
* test(node): retain idle assertions across native cleanup