ERP Local Agent 1.9.4

Existing storage, WebSocket tunnel, Tally and client .act functionality are preserved.

Local dashboard:
  http://127.0.0.1:8788
  or run open_dashboard.bat

Updates:
  - The agent checks the ERP for new versions automatically.
  - Updates are NOT installed automatically.
  - Open the local dashboard, Download Update, then Install Downloaded Update.
  - .env, .venv, data, logs and client storage are preserved during update.

Local operational database:
  data\agent.db

Client accounting .act databases remain separate under the configured STORAGE_ROOT.

Phase 2: client/registration to Tally company mapping is supported using Tally GUID.

Phase 3: read-only Tally accounting master sync (Groups, Ledgers, Voucher Types, Stock Groups/Categories/Items, Units and Cost Centres/Categories) into client .act storage.

Version 1.6.0: Phase 4 read-only Tally transaction synchronization (vouchers, ledger/inventory entries, bill/cost-centre/bank allocations) with raw voucher XML preservation.

Phase 5 adds draft-only Income-tax depreciation calculations from synchronized .act data. No Tally write-back.

Phase 6: approved Income-tax depreciation Journal write-back is available only after explicit Partner approval and POST confirmation. All other Tally operations remain read-only.

Depreciation refinement 1.8.0:
- Accounting .act files default to <Local Agent>\data\accounting, separate from document STORAGE_ROOT.
- Existing legacy <STORAGE_ROOT>\Accounting client databases are copied automatically on first use and left in place as recovery copies.
- Current-FY transaction coverage is required only through today, not through a future FY-end date.
- Draft calculation is available with incomplete coverage; approval/write-back remains blocked until required coverage is complete.
- Empty Fixed Asset ledgers are omitted unless they have current-period additions.
- Bulk checkbox + rate assignment is available.
- Nested Tally accounting allocations and case-insensitive ledger matching improve fixed-asset additions detection.

Accounting storage policy 1.8.1:
- .act databases now use the same configured branch Storage Node root and client-folder naming policy as Permanent/Engagement storage.
- ERP builds the client folder through the existing client_folder_parts() helper and sends only the safe relative Accounting/Clients/... directory.
- Canonical layout: <STORAGE_ROOT>\Accounting\Clients\<Letter>\<ExistingClientFolder>\client_XXXXXXXX.act
- Existing databases from <STORAGE_ROOT>\Accounting\client_XXXXXXXX or <ERP_Local_Agent>\data\accounting\client_XXXXXXXX are migrated by SQLite backup on first use.
- Migration sources are retained as recovery copies; no existing .act file is deleted.

Accounting engagement-folder policy 1.8.2:
- Final canonical Accounting DB path follows the existing Engagement hierarchy:
  <STORAGE_ROOT>\FY2026-27\Clients\<Letter>\<ExistingClientFolder>\Accounting\client_XXXXXXXX.act
- ERP uses the same sanitize_segment("FY"+financial_year) and client_folder_parts() convention as Engagement storage.
- Current Tally page/mapping/master sync use the current financial year.
- Transaction sync uses the financial year containing date_from.
- Depreciation/approval/write-back use the selected depreciation financial year.
- Existing .act databases from original flat, v1.8.0 Local-Agent-data, and v1.8.1 Accounting\Clients locations are migrated safely by SQLite backup and retained as recovery copies.
- The Accounting folder is the stable base for later Reports, Exports, Workpapers and Backups; this release does not change report-generation behavior.


Desktop Supervisor 1.9.0
------------------------
- Scheduled Task now starts ERPAgentSupervisor.pyw instead of starting erp_local_agent.main directly.
- Supervisor owns the worker lifecycle and automatically restarts the worker if it exits.
- Dashboard update installation no longer makes the worker launch a detached PowerShell installer and os._exit().
- Downloaded/staged updates are handed to the supervisor through updates\supervisor_request.json.
- Supervisor stops the worker, backs it up, atomically replaces the worker package, installs requirements, verifies imports, restarts it, waits for dashboard health, and rolls back if startup fails.
- Stable supervisor/dashboard launchers are deliberately not self-replaced during normal worker updates.
- Desktop shortcut opens "Open ERP Local Agent Dashboard.vbs", which uses pythonw.exe + ERPAgentDashboard.pyw + pywebview.
- Closing the desktop dashboard does NOT stop the supervisor or worker.
- The dashboard automatically reconnects/reloads when the worker goes down and returns during an update.
- Existing browser access at http://127.0.0.1:8788 remains available.

Supervisor detection hotfix 1.9.1:
- Desktop dashboard no longer relies on os.kill(pid, 0) to detect the SYSTEM-owned supervisor.
- Uses Windows OpenProcess(PROCESS_QUERY_LIMITED_INFORMATION) when available.
- Uses localhost dashboard health and recent supervisor_state.json as additional valid signals.
- Prevents false 'ERP Local Agent supervisor did not start' errors caused by cross-user Windows process permissions.

Single-supervisor hotfix 1.9.2:
- Replaces PID-text singleton logic with an msvcrt held byte-range file lock that works across Windows processes/logon sessions.
- Duplicate supervisors immediately exit without starting/killing workers.
- Desktop dashboard never launches an interactive supervisor when the installed ERP Local Agent Scheduled Task exists.
- If the task exists but is stopped, dashboard requests Task Scheduler to start it and waits for localhost health.
- Prevents supervisor/worker restart storms caused by multiple supervisors killing one another's workers.

Global mutex hardening 1.9.3:
- Supervisor primary singleton is Windows Global\ARRR_ERP_Local_Agent_Supervisor via CreateMutexW.
- Existing byte-range lock remains only as fallback if Global mutex creation is unavailable.
- Scheduled Task installation is expected to use MultipleInstances=IgnoreNew.


Tally GSTIN enrichment 1.9.4:
- Loaded-company discovery requests GSTRegistrationNumber, GSTRegistrationDetails, GSTIN and PartyGSTIN.
- Company parser searches GSTIN candidates recursively, including nested GST registration details.
- Existing company GUID/name discovery remains unchanged.
