Skip to content

fix(server): end clone options before the repository URL - #14781

Merged
Yash-Singh1 merged 1 commit into
pingdotgg:mainfrom
saphid:upstream-clone-option-termination
Oct 6, 2026
Merged

Yash-Singh1 merged 1 commit into
pingdotgg:mainfrom
saphid:upstream-clone-option-termination

Conversation

@saphid

@saphid saphid commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Problem

When you clone a repository whose URL or local path starts with -, the server passes that value to Git, which parses it as a git clone option. This affects Add Project → clone on web, desktop and mobile, and the t3_project_clone tool. For example, cloning a local repository named --bare fails with fatal: repository 'checkout' does not exist instead of creating the checkout.

Why this qualifies

This is the CONTRIBUTING "small, obvious bug" route. It is a one-line fix for a positional-argument bug at the only git clone call site, and it uses Git's standard -- option terminator. Normal clone URLs and existing flows do not change. There is no linked issue and no prior maintainer discussion.

Fix

SourceControlRepositoryService.cloneRepository now passes -- after the clone options. That puts the repository URL or path and the destination directory after the terminator, so Git always treats them as positional arguments. This also covers a destination directory name that starts with -.

The same parsing means an option-like operand can do more than fail. For example, a destination named --upload-pack=<command> makes Git run that command during the clone. Only a client that is already allowed to clone can supply that value, and standard paired clients can already run terminal commands. So this closes argument injection at the Git process boundary; it does not fix a privilege escalation.

Tests:

  • The existing argument assertion now expects the terminator.
  • A new real-Git test clones a local bare repository named --bare, and an ordinary source.git as a control. Each must produce a working tree at the requested destination.

Evidence

Environment: macOS 26.5.2 (arm64), Git 2.50.1 (Apple Git-155), Node 24.12.0. Verified on upstream main f870c419fc. This branch is that commit plus this one change.

Reproduction (real server process). I ran each step against a server built from upstream main, then against one built from this branch:

  1. Start the real server (t3 serve) on a fresh, isolated data directory, with GIT_TRACE pointing at a file.
  2. Issue a bearer session with t3 auth session issue.
  3. Open the authenticated /ws socket. Call the same sourceControl.cloneRepository RPC the clients use, with remoteUrl: "--bare" (a local bare repository) and the destination checkout in the same directory.

Observed before (upstream main):

RPC result: Failure {"_tag":"SourceControlRepositoryError","provider":"unknown","operation":"cloneRepository","detail":"fatal: repository 'checkout' does not exist", ...}
git clone argv recorded by GIT_TRACE:
  git clone --progress --bare checkout
<fixture>/checkout/.git exists: false

Observed after (this branch):

RPC result: Success {"cwd":"<fixture>/checkout","remoteUrl":"--bare","repository":null}
git clone argv recorded by GIT_TRACE:
  git clone --progress -- --bare checkout
<fixture>/checkout/.git exists: true

Focused checks, run at this head:

Command Result
vp test run src/sourceControl/SourceControlRepositoryService.test.ts (from apps/server), with main's SourceControlRepositoryService.ts swapped in Fails: 2 failed, 11 passed. The --bare case fails with fatal: repository 'checkout' does not exist, and the argument assertion fails.
The same command on this branch Passes: 13/13, including the source.git control.
vp run --filter t3 typecheck Pass
vp lint --report-unused-disable-directives on both changed files Pass
vp fmt --check on both changed files Pass
vp run --filter t3 build:bundle Pass
node scripts/release-smoke.ts Pass

There is no UI change, so there are no screenshots. The evidence is the server trace above.

Surfaces

  • Web, desktop and mobile: fixed with no client change. Add Project → clone in the web/desktop command palette and on the mobile Add Project screen both reach this call site through the projectClone.start / sourceControl.cloneRepository RPCs.
  • MCP t3_project_clone: fixed. It calls the same service method.
  • Local, remote-relay and tunnel: not affected. The change is in the server's Git invocation, after transport. Local was exercised; remote-relay and tunnel were not.
  • Providers (Codex, Claude, Cursor, Grok, OpenCode, Antigravity): not affected. Cloning is not provider-shaped, and no adapter changed.
  • Contracts and docs: no change. Inputs and results are unchanged, and documented behavior is unchanged.

Not checked

  • Windows and Linux Git, authenticated network remotes, and provider lookups were not exercised. The lookup path (provider + repository) feeds the same argument list.
  • Remote-relay and tunnel connections were not exercised.
  • I did not demonstrate an option-injection effect beyond the misparsed --bare case.

GPT-6.1 Sol and Claude Opus 5.5 via T3 Code
🤖 Generated with Claude Code

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Oct 2, 2026
macroscopeapp[bot]
macroscopeapp Bot previously approved these changes Oct 2, 2026
@macroscopeapp

macroscopeapp Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at bd5567c

Macroscope's review found this PR approvable — This is a narrowly scoped Git argument-handling bug fix that preserves normal clone behavior and adds regression coverage for option-like local repository paths. It changes no schemas, defaults, deployment configuration, or sensitive code.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge juliusmarminge added the macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews label Oct 2, 2026 — with ChatGPT Codex Connector
@macroscopeapp
macroscopeapp Bot dismissed their stale review October 2, 2026 09:41

Dismissing prior approval to re-evaluate 75883b3

macroscopeapp[bot]
macroscopeapp Bot previously approved these changes Oct 2, 2026
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: pingdotgg/t3code/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 21480423-80cb-44b3-b0dd-d40bcf62f32a
📥 Commits

Reviewing files that changed from the base of the PR and between 75883b3 and bd5567c.

📒 Files selected for processing (1)
  • apps/server/src/sourceControl/SourceControlRepositoryService.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 6 remain after this review.


📝 Walkthrough

Walkthrough

cloneRepository now passes -- between Git clone options and the remote URL. Tests cover local repositories named --bare and source.git.

Changes

Git clone argument handling

Layer / File(s) Summary
Separate clone options from the remote
apps/server/src/sourceControl/SourceControlRepositoryService.ts, apps/server/src/sourceControl/SourceControlRepositoryService.test.ts
cloneRepository adds -- before the remote URL. Tests check the expected arguments and verify that cloning local repositories named --bare and source.git returns a destination containing .git.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: juliusmarminge

Merge Risk: ⚪ Minimal · up to bd556

No actionable merge-blocking risk is identified for this change. It is ready to merge after normal checks.

Architecture Summary

Architecture risk: 🔵 Low · up to bd556

The change affects 1 system.

Changed systems: apps/server

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — apps/server (service) was modified; 2 changed files map to changed impact.

Before / after behavior

  • observed — Modified behavior in apps/server/src/sourceControl/SourceControlRepositoryService.ts: cloneRepository adds -- after --progress; previously Git received the remote URL immediately after the options.
  • observed — Modified behavior in apps/server/src/sourceControl/SourceControlRepositoryService.test.ts: The expected Git clone arguments now include -- before the remote URL.
  • observed — Modified behavior in apps/server/src/sourceControl/SourceControlRepositoryService.test.ts: Adds a parameterized test for cloning local bare repositories named --bare or source.git; each case asserts the clone result points to the requested destination and that it contains a .git directory.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main change: ending Git clone options before the repository URL.
Description check ✅ Passed The description covers the problem, fix, scope rationale, and focused verification results. It also states what was not checked and identifies the agent and harness.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@saphid
saphid force-pushed the upstream-clone-option-termination branch from 75883b3 to bd5567c Compare October 3, 2026 03:58
@macroscopeapp
macroscopeapp Bot dismissed their stale review October 3, 2026 03:58

Dismissing prior approval to re-evaluate bd5567c

@saphid
saphid force-pushed the upstream-clone-option-termination branch from bd5567c to c7043ff Compare October 4, 2026 06:48
@saphid

saphid commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Review requested

Date (UTC) Reviewer Where
2026-10-03 Julius Discord DM

Logged so this PR shows when a maintainer was asked to review it.

@Yash-Singh1
Yash-Singh1 merged commit e65063c into pingdotgg:main Oct 6, 2026
28 checks passed
sheehanmunim added a commit to munimtechnologies/mtcode that referenced this pull request Oct 6, 2026
Fork's SSH clone test expects upstream's `--` before the repository URL
(pingdotgg#14781); upstream's JetBrains launcher tests used the pre-rename testLayer.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
github-actions Bot added a commit to omarcresp/t3code-flake that referenced this pull request Oct 6, 2026
## What's Changed
* refactor(server,relay): webhook capabilities live in services, not handlers by @juliusmarminge in pingdotgg/t3code#16232
* fix(server): a T3 Connect preferences save finishes even if the client disconnects by @juliusmarminge in pingdotgg/t3code#16266
* refactor(server): import service modules as namespaces, not aliased layers by @juliusmarminge in pingdotgg/t3code#16267
* feat(server): log how long PR watches stay quiet before they end by @t3dotgg in pingdotgg/t3code#16262
* feat(server,web): choose where new worktrees are created by @juliusmarminge in pingdotgg/t3code#16231
* perf(server): idle status polls and PR sweeps start fewer git processes by @t3dotgg in pingdotgg/t3code#16272
* perf(server): PR watches spend ~90% fewer GitHub points by checking a 1-point fingerprint first by @t3dotgg in pingdotgg/t3code#16270
* fix(pull-requests): PR detail reads no longer drain the GitHub quota by @t3dotgg in pingdotgg/t3code#16280
* refactor: layer variables are named layer or layerXyz by @juliusmarminge in pingdotgg/t3code#16282
* refactor(server): T3 Connect link capabilities live in a CloudLink service by @juliusmarminge in pingdotgg/t3code#16265
* fix(web): sidebar drag and drop no longer snaps back by @t3dotgg in pingdotgg/t3code#16291
* fix(web): inline HTML renders no longer trap the thread's scroll by @t3dotgg in pingdotgg/t3code#16283
* refactor(server): one module per service instead of Services/ and Layers/ folders by @juliusmarminge in pingdotgg/t3code#16295
* chore(review): configure CodeRabbit in TypeScript by @esthor in pingdotgg/t3code#16281
* docs: put the Effect and web UI review rules in the docs by @esthor in pingdotgg/t3code#16286
* chore(lint): require a reason on every lint and type-checker suppression by @esthor in pingdotgg/t3code#16294
* refactor(relay): import HookInboxObject once, as a namespace by @juliusmarminge in pingdotgg/t3code#16307
* fix(web): a rejected desktop-local credential is not retried every poll by @juliusmarminge in pingdotgg/t3code#16273
* feat(desktop): the renderer's bootstrap token rotates every 12 hours by @juliusmarminge in pingdotgg/t3code#16275
* fix(web): recover from a closed IndexedDB connection by @juliusmarminge in pingdotgg/t3code#16311
* fix(relay): stop forcing manual relay deploys by default by @juliusmarminge in pingdotgg/t3code#13563
* feat(relay): measure the managed tunnel backlog by @juliusmarminge in pingdotgg/t3code#13564
* feat(relay): clean up tunnels of hosts that never registered recovery by @juliusmarminge in pingdotgg/t3code#13565
* perf(relay): delete expired tunnels four at a time within a time budget by @juliusmarminge in pingdotgg/t3code#13566
* feat(connect): tell users when an idle tunnel was removed by @juliusmarminge in pingdotgg/t3code#13567
* docs(relay): add the legacy tunnel cleanup rollout runbook by @juliusmarminge in pingdotgg/t3code#13568
* chore(review): point CodeRabbit at the web UI conventions by @esthor in pingdotgg/t3code#16324
* chore(review): turn off CodeRabbit's docstring coverage check by @esthor in pingdotgg/t3code#16328
* refactor(server): CloudLink keeps only the link lifecycle; pure checks live beside it by @juliusmarminge in pingdotgg/t3code#16340
* refactor(server): CloudLink fails with its own errors; the connect routes map them to HTTP by @juliusmarminge in pingdotgg/t3code#16341
* refactor(server): replay guards stay in CloudLink by @juliusmarminge in pingdotgg/t3code#16349
* fix(server): forks no longer merge into their upstream repo's project group by @t3dotgg in pingdotgg/t3code#16353
* fix(server): stop the startup project sync from delaying the app window by @Mnigos in pingdotgg/t3code#14912
* fix(web): avoid blocking image preparation conversions by @Bil0000 in pingdotgg/t3code#13342
* fix(server): return partial workspace index on timeout by @Michel-Liao in pingdotgg/t3code#11500
* fix(server): probe project favicon candidates concurrently by @ishaanko in pingdotgg/t3code#12543
* fix(observability): a failing trace disk no longer stalls the server by @t3dotgg in pingdotgg/t3code#13758
* fix(server): status polling no longer locks the git index by @ahalekelly in pingdotgg/t3code#14718
* perf(shared): scan PATH once per command before spawning, not on every spawn by @SkiTee3000 in pingdotgg/t3code#12600
* fix(server): main's startup auto-pull test compiles again by @t3dotgg in pingdotgg/t3code#16357
* fix(server): project favicons stop being rescanned every minute by @t3dotgg in pingdotgg/t3code#16206
* fix(server): Claude limits load again for users with large transcript histories by @t3dotgg in pingdotgg/t3code#16358
* fix(server): caches and ids are written atomically by @juliusmarminge in pingdotgg/t3code#16242
* fix(server): one-shot initializers no longer race by @juliusmarminge in pingdotgg/t3code#16260
* fix(server): the PR cache sweep only removes real entry files by @juliusmarminge in pingdotgg/t3code#16285
* chore: keep one copy each of undici 8 and ws 8 by @juliusmarminge in pingdotgg/t3code#16211
* fix(shared): DrainableWorker keeps running after a failed item by @juliusmarminge in pingdotgg/t3code#16223
* fix(server): metrics count interrupted work on the monotonic clock by @juliusmarminge in pingdotgg/t3code#16207
* refactor(web): import connection storage as a namespace in its test by @juliusmarminge in pingdotgg/t3code#16315
* fix(contracts): trimmed IDs round-trip by @juliusmarminge in pingdotgg/t3code#16300
* fix(server): main's settings, keybindings and session tests compile again by @juliusmarminge in pingdotgg/t3code#16363
* chore(lint): catch known tags with Effect.catchTags by @esthor in pingdotgg/t3code#16361
* fix(observability): T3 Connect tracing stops at the relay boundary by @juliusmarminge in pingdotgg/t3code#16314
* fix(relay): error and deadline responses carry CORS headers by @juliusmarminge in pingdotgg/t3code#16253
* fix(web): bring back the live shimmer on work log rows by @juliusmarminge in pingdotgg/t3code#16372
* refactor: Effect code gets UUIDs and SHA-256 from Effect's Crypto by @esthor in pingdotgg/t3code#16377
* fix(relay): export traces through one tracer, one request span each by @juliusmarminge in pingdotgg/t3code#16382
* fix(server): Pi thread titles use linked PR context by @juliusmarminge in pingdotgg/t3code#16210
* fix(desktop): retry transient bearer bootstrap and degrade on session fetch failure by @jamesvillarrubia in pingdotgg/t3code#12919
* fix(server): avoid scanning completed history for pending secrets by @Yash-Singh1 in pingdotgg/t3code#16409
* fix(orchestration-v2): let Stop recover stalled runs by @Yash-Singh1 in pingdotgg/t3code#15442
* fix(release): resolve version-qualified catalog overrides by @Yash-Singh1 in pingdotgg/t3code#16411
* fix(web): type in front of bold that starts a composer line by @saphid in pingdotgg/t3code#13217
* fix(desktop): prevent browser screenshot filename collisions by @saphid in pingdotgg/t3code#14784
* fix(server): end clone options before the repository URL by @saphid in pingdotgg/t3code#14781
* fix(web): queued messages no longer split the composer notice stack by @tristanmanchester in pingdotgg/t3code#16400
* fix(server): reject invalid explicit Bitbucket repositories by @aravhawk in pingdotgg/t3code#15876
* fix: restore desktop and server typechecks on main by @Yash-Singh1 in pingdotgg/t3code#16415
* fix(shared): find versioned JetBrains macOS app bundles by @Sypher760-gif in pingdotgg/t3code#16246
* fix(server): OpenCode 2 threads get T3 Code's MCP tools by @nkoynov in pingdotgg/t3code#16142
* feat(preview): run the browser on the environment server by @maria-rcks in pingdotgg/t3code#15328
* fix: restore service references breaking ci by @maria-rcks in pingdotgg/t3code#16495
* fix(mcp): mark declared tool failures as errors by @maria-rcks in pingdotgg/t3code#15617
* fix(release): unblock nightly browser tests and cli builds by @maria-rcks in pingdotgg/t3code#16515

## New Contributors
* @esthor made their first contribution in pingdotgg/t3code#16281
* @ahalekelly made their first contribution in pingdotgg/t3code#14718
* @SkiTee3000 made their first contribution in pingdotgg/t3code#12600
* @jamesvillarrubia made their first contribution in pingdotgg/t3code#12919
* @Sypher760-gif made their first contribution in pingdotgg/t3code#16246
* @nkoynov made their first contribution in pingdotgg/t3code#16142

**Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261005.2702...v0.0.46-nightly.20261006.2735

Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261006.2735
github-actions Bot added a commit to davidvanderklay/t3code-flake that referenced this pull request Oct 6, 2026
## What's Changed
* refactor(server,relay): webhook capabilities live in services, not handlers by @juliusmarminge in pingdotgg/t3code#16232
* fix(server): a T3 Connect preferences save finishes even if the client disconnects by @juliusmarminge in pingdotgg/t3code#16266
* refactor(server): import service modules as namespaces, not aliased layers by @juliusmarminge in pingdotgg/t3code#16267
* feat(server): log how long PR watches stay quiet before they end by @t3dotgg in pingdotgg/t3code#16262
* feat(server,web): choose where new worktrees are created by @juliusmarminge in pingdotgg/t3code#16231
* perf(server): idle status polls and PR sweeps start fewer git processes by @t3dotgg in pingdotgg/t3code#16272
* perf(server): PR watches spend ~90% fewer GitHub points by checking a 1-point fingerprint first by @t3dotgg in pingdotgg/t3code#16270
* fix(pull-requests): PR detail reads no longer drain the GitHub quota by @t3dotgg in pingdotgg/t3code#16280
* refactor: layer variables are named layer or layerXyz by @juliusmarminge in pingdotgg/t3code#16282
* refactor(server): T3 Connect link capabilities live in a CloudLink service by @juliusmarminge in pingdotgg/t3code#16265
* fix(web): sidebar drag and drop no longer snaps back by @t3dotgg in pingdotgg/t3code#16291
* fix(web): inline HTML renders no longer trap the thread's scroll by @t3dotgg in pingdotgg/t3code#16283
* refactor(server): one module per service instead of Services/ and Layers/ folders by @juliusmarminge in pingdotgg/t3code#16295
* chore(review): configure CodeRabbit in TypeScript by @esthor in pingdotgg/t3code#16281
* docs: put the Effect and web UI review rules in the docs by @esthor in pingdotgg/t3code#16286
* chore(lint): require a reason on every lint and type-checker suppression by @esthor in pingdotgg/t3code#16294
* refactor(relay): import HookInboxObject once, as a namespace by @juliusmarminge in pingdotgg/t3code#16307
* fix(web): a rejected desktop-local credential is not retried every poll by @juliusmarminge in pingdotgg/t3code#16273
* feat(desktop): the renderer's bootstrap token rotates every 12 hours by @juliusmarminge in pingdotgg/t3code#16275
* fix(web): recover from a closed IndexedDB connection by @juliusmarminge in pingdotgg/t3code#16311
* fix(relay): stop forcing manual relay deploys by default by @juliusmarminge in pingdotgg/t3code#13563
* feat(relay): measure the managed tunnel backlog by @juliusmarminge in pingdotgg/t3code#13564
* feat(relay): clean up tunnels of hosts that never registered recovery by @juliusmarminge in pingdotgg/t3code#13565
* perf(relay): delete expired tunnels four at a time within a time budget by @juliusmarminge in pingdotgg/t3code#13566
* feat(connect): tell users when an idle tunnel was removed by @juliusmarminge in pingdotgg/t3code#13567
* docs(relay): add the legacy tunnel cleanup rollout runbook by @juliusmarminge in pingdotgg/t3code#13568
* chore(review): point CodeRabbit at the web UI conventions by @esthor in pingdotgg/t3code#16324
* chore(review): turn off CodeRabbit's docstring coverage check by @esthor in pingdotgg/t3code#16328
* refactor(server): CloudLink keeps only the link lifecycle; pure checks live beside it by @juliusmarminge in pingdotgg/t3code#16340
* refactor(server): CloudLink fails with its own errors; the connect routes map them to HTTP by @juliusmarminge in pingdotgg/t3code#16341
* refactor(server): replay guards stay in CloudLink by @juliusmarminge in pingdotgg/t3code#16349
* fix(server): forks no longer merge into their upstream repo's project group by @t3dotgg in pingdotgg/t3code#16353
* fix(server): stop the startup project sync from delaying the app window by @Mnigos in pingdotgg/t3code#14912
* fix(web): avoid blocking image preparation conversions by @Bil0000 in pingdotgg/t3code#13342
* fix(server): return partial workspace index on timeout by @Michel-Liao in pingdotgg/t3code#11500
* fix(server): probe project favicon candidates concurrently by @ishaanko in pingdotgg/t3code#12543
* fix(observability): a failing trace disk no longer stalls the server by @t3dotgg in pingdotgg/t3code#13758
* fix(server): status polling no longer locks the git index by @ahalekelly in pingdotgg/t3code#14718
* perf(shared): scan PATH once per command before spawning, not on every spawn by @SkiTee3000 in pingdotgg/t3code#12600
* fix(server): main's startup auto-pull test compiles again by @t3dotgg in pingdotgg/t3code#16357
* fix(server): project favicons stop being rescanned every minute by @t3dotgg in pingdotgg/t3code#16206
* fix(server): Claude limits load again for users with large transcript histories by @t3dotgg in pingdotgg/t3code#16358
* fix(server): caches and ids are written atomically by @juliusmarminge in pingdotgg/t3code#16242
* fix(server): one-shot initializers no longer race by @juliusmarminge in pingdotgg/t3code#16260
* fix(server): the PR cache sweep only removes real entry files by @juliusmarminge in pingdotgg/t3code#16285
* chore: keep one copy each of undici 8 and ws 8 by @juliusmarminge in pingdotgg/t3code#16211
* fix(shared): DrainableWorker keeps running after a failed item by @juliusmarminge in pingdotgg/t3code#16223
* fix(server): metrics count interrupted work on the monotonic clock by @juliusmarminge in pingdotgg/t3code#16207
* refactor(web): import connection storage as a namespace in its test by @juliusmarminge in pingdotgg/t3code#16315
* fix(contracts): trimmed IDs round-trip by @juliusmarminge in pingdotgg/t3code#16300
* fix(server): main's settings, keybindings and session tests compile again by @juliusmarminge in pingdotgg/t3code#16363
* chore(lint): catch known tags with Effect.catchTags by @esthor in pingdotgg/t3code#16361
* fix(observability): T3 Connect tracing stops at the relay boundary by @juliusmarminge in pingdotgg/t3code#16314
* fix(relay): error and deadline responses carry CORS headers by @juliusmarminge in pingdotgg/t3code#16253
* fix(web): bring back the live shimmer on work log rows by @juliusmarminge in pingdotgg/t3code#16372
* refactor: Effect code gets UUIDs and SHA-256 from Effect's Crypto by @esthor in pingdotgg/t3code#16377
* fix(relay): export traces through one tracer, one request span each by @juliusmarminge in pingdotgg/t3code#16382
* fix(server): Pi thread titles use linked PR context by @juliusmarminge in pingdotgg/t3code#16210
* fix(desktop): retry transient bearer bootstrap and degrade on session fetch failure by @jamesvillarrubia in pingdotgg/t3code#12919
* fix(server): avoid scanning completed history for pending secrets by @Yash-Singh1 in pingdotgg/t3code#16409
* fix(orchestration-v2): let Stop recover stalled runs by @Yash-Singh1 in pingdotgg/t3code#15442
* fix(release): resolve version-qualified catalog overrides by @Yash-Singh1 in pingdotgg/t3code#16411
* fix(web): type in front of bold that starts a composer line by @saphid in pingdotgg/t3code#13217
* fix(desktop): prevent browser screenshot filename collisions by @saphid in pingdotgg/t3code#14784
* fix(server): end clone options before the repository URL by @saphid in pingdotgg/t3code#14781
* fix(web): queued messages no longer split the composer notice stack by @tristanmanchester in pingdotgg/t3code#16400
* fix(server): reject invalid explicit Bitbucket repositories by @aravhawk in pingdotgg/t3code#15876
* fix: restore desktop and server typechecks on main by @Yash-Singh1 in pingdotgg/t3code#16415
* fix(shared): find versioned JetBrains macOS app bundles by @Sypher760-gif in pingdotgg/t3code#16246
* fix(server): OpenCode 2 threads get T3 Code's MCP tools by @nkoynov in pingdotgg/t3code#16142
* feat(preview): run the browser on the environment server by @maria-rcks in pingdotgg/t3code#15328
* fix: restore service references breaking ci by @maria-rcks in pingdotgg/t3code#16495
* fix(mcp): mark declared tool failures as errors by @maria-rcks in pingdotgg/t3code#15617
* fix(release): unblock nightly browser tests and cli builds by @maria-rcks in pingdotgg/t3code#16515

## New Contributors
* @esthor made their first contribution in pingdotgg/t3code#16281
* @ahalekelly made their first contribution in pingdotgg/t3code#14718
* @SkiTee3000 made their first contribution in pingdotgg/t3code#12600
* @jamesvillarrubia made their first contribution in pingdotgg/t3code#12919
* @Sypher760-gif made their first contribution in pingdotgg/t3code#16246
* @nkoynov made their first contribution in pingdotgg/t3code#16142

**Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261005.2702...v0.0.46-nightly.20261006.2735

Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261006.2735
Andrey170170 added a commit to Andrey170170/t3code that referenced this pull request Oct 9, 2026
…raming (#28)

* fix(server): forks no longer merge into their upstream repo's project group (pingdotgg#16353)

Fixes pingdotgg#4880. Originally pingdotgg#14639 by @Project516.

Co-authored-by: Project516 <138796702+Project516@users.noreply.github.com>

* fix(server): stop the startup project sync from delaying the app window (pingdotgg#14912)

* fix(web): avoid blocking image preparation conversions (pingdotgg#13342)

* fix(server): return partial workspace index on timeout (pingdotgg#11500)

* fix(server): probe project favicon candidates concurrently (pingdotgg#12543)

* fix(observability): a failing trace disk no longer stalls the server (pingdotgg#13758)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): status polling no longer locks the git index (pingdotgg#14718)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* perf(shared): scan PATH once per command before spawning, not on every spawn (pingdotgg#12600)

* fix(server): main's startup auto-pull test compiles again (pingdotgg#16357)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): project favicons stop being rescanned every minute (pingdotgg#16206)

Favicons in ProjectEnrichmentService now keep for 15 minutes. Repository identity keeps its 1-minute TTL, so remote changes still show within a minute.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): Claude limits load again for users with large transcript histories (pingdotgg#16358)

The Claude capabilities probe now asks for usage with skipBehaviors, so it no longer scans every local transcript and misses its 4 s deadline. Takes over pingdotgg#14456.

Co-authored-by: Ashkaan <a@ashkaan.me>

* Add esthor to the list of GitHub users

* fix(server): caches and ids are written atomically (pingdotgg#16242)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): one-shot initializers no longer race (pingdotgg#16260)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): the PR cache sweep only removes real entry files (pingdotgg#16285)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: keep one copy each of undici 8 and ws 8 (pingdotgg#16211)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(shared): DrainableWorker keeps running after a failed item (pingdotgg#16223)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): metrics count interrupted work on the monotonic clock (pingdotgg#16207)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor(web): import connection storage as a namespace in its test (pingdotgg#16315)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(contracts): trimmed IDs round-trip (pingdotgg#16300)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): main's settings, keybindings and session tests compile again (pingdotgg#16363)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(lint): catch known tags with Effect.catchTags (pingdotgg#16361)

* fix(observability): T3 Connect tracing stops at the relay boundary (pingdotgg#16314)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(relay): error and deadline responses carry CORS headers (pingdotgg#16253)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): bring back the live shimmer on work log rows (pingdotgg#16372)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: Effect code gets UUIDs and SHA-256 from Effect's Crypto (pingdotgg#16377)

* fix(relay): export traces through one tracer, one request span each (pingdotgg#16382)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): Pi thread titles use linked PR context (pingdotgg#16210)

* fix(desktop): retry transient bearer bootstrap and degrade on session fetch failure (pingdotgg#12919)

* fix(server): avoid scanning completed history for pending secrets (pingdotgg#16409)

* fix(orchestration-v2): let Stop recover stalled runs (pingdotgg#15442)

* fix(release): resolve version-qualified catalog overrides (pingdotgg#16411)

* fix(web): type in front of bold that starts a composer line (pingdotgg#13217)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(desktop): prevent browser screenshot filename collisions (pingdotgg#14784)

* fix(server): end clone options before the repository URL (pingdotgg#14781)

* fix(web): queued messages no longer split the composer notice stack (pingdotgg#16400)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>

* fix(server): reject invalid explicit Bitbucket repositories (pingdotgg#15876)

* fix(desktop): use the crypto service for screenshot IDs (pingdotgg#16415)

* fix(shared): find versioned JetBrains macOS app bundles (pingdotgg#16246)

* fix(server): OpenCode 2 threads get T3 Code's MCP tools (pingdotgg#16142)

* feat(preview): run the browser on the environment server (pingdotgg#15328)

* fix: restore service references breaking ci (pingdotgg#16495)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix(mcp): mark declared tool failures as errors (pingdotgg#15617)

* fix(release): unblock nightly browser tests and cli builds (pingdotgg#16515)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix(mcp): preserve thread command rejection reasons (pingdotgg#15627)

* chore(deps): upgrade @effect/tsgo to 0.46.1 (pingdotgg#16360)

Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(orchestration-v2): show reported subagent models (pingdotgg#14108)

Co-authored-by: Yash Singh <saiansh2525@gmail.com>

* fix(web): Apple logo no longer dips below the device host label (pingdotgg#14825)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): show subagent effort and speed in hover cards (pingdotgg#13056)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* feat(web): reopen closed tabs across the app (pingdotgg#15207)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(web): stop wide ordered list markers from clipping (pingdotgg#16523)

* fix(desktop): build AppImage with the static runtime toolset (fixes libfuse2 launch failure) (pingdotgg#7765)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(mobile): keep usage-limit notice opaque (pingdotgg#15602)

* feat(server): GitHub API transport that uses gh only for the token (pingdotgg#16319)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(server): pull requests talk to GitHub's API instead of the gh CLI (pingdotgg#16320)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(server): source control, media and discovery use GitHub's API instead of gh (pingdotgg#16321)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: choose the GitHub account per host, save a GitHub token, and fewer reads per PR action (pingdotgg#16322)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): Rebase stack moves each layer onto the rebased layer below it (pingdotgg#16551)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): diff panel keeps the chosen scope while a turn runs (pingdotgg#16571)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(desktop): honor the telemetry opt-out from the shell profile (pingdotgg#16563)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* docs(marketing): disclose product usage data in the privacy policy (pingdotgg#16562)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(web): note anonymous usage data in onboarding and link the privacy policy (pingdotgg#16564)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* perf(web): diff panel no longer re-renders every file header each time a patch arrives (pingdotgg#16033)

Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(server): every T3 MCP tool declares who may call it (pingdotgg#16335)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(server): outside agents sign in to the T3 MCP server with OAuth (pingdotgg#16336)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(web): copy an environment's MCP URL for outside agents (pingdotgg#16337)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(tsconfig): turn off the Schema-over-JSON diagnostic in test files (pingdotgg#16375)

Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(review): CodeRabbit gates outside contributors' pull requests (pingdotgg#16332)

* fix(desktop): include Linux package license and app metadata (pingdotgg#16597)

* fix(server): one failing RPC handler no longer ends the client's other requests (pingdotgg#15515)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(contracts): a context record that cannot be encoded no longer fails the send (pingdotgg#16398)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): open pull request row actions on right-click (pingdotgg#16612)

* fix(web): show attempted paths in file preview errors (pingdotgg#15628)

* fix(vcs): passive sidebar rows stop retaining remote pollers (pingdotgg#15666)

* feat(web): group keybindings settings by area with a page toolbar (pingdotgg#12822)

* feat(web): stop T3-owned subagents from Lineage (pingdotgg#15211)

* feat(web): add fast actions to linked pull requests (pingdotgg#16627)

* feat(web): open right panel tab menu with Mod+T (pingdotgg#15686)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(server): provider sessions clean up when their start is interrupted (pingdotgg#15571)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): show "No project" near the top of the new thread picker (pingdotgg#16628)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor(server): instrument WS RPCs in group middleware (pingdotgg#15548)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(deps): upgrade @pierre/diffs to 1.5.2 and @pierre/trees to beta.6 (pingdotgg#16644)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(relay): a host restarting onto a deleted tunnel gets a new one (pingdotgg#16649)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): recover a deleted tunnel when Cloudflare says "Tunnel not found" (pingdotgg#16648)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): iPhone Duo fold controls follow the phone's orientation (pingdotgg#16630)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): keep workspace options when expanding lineage (pingdotgg#16635)

* fix(web): preserve bare anchor placeholders in markdown (pingdotgg#16637)

* fix(pi): preserve provider identity in discovered models (pingdotgg#16661)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix(auth): preserve explicitly granted pairing scopes (pingdotgg#9785)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* feat(auth): separate environment administration permissions (pingdotgg#9786)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* feat(auth): separate source control write permissions (pingdotgg#9787)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* feat(auth): separate filesystem read and write permissions (pingdotgg#9788)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* feat(auth): separate browser preview control permissions (pingdotgg#9789)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* feat(auth): separate diagnostics and usage permissions (pingdotgg#9790)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* feat(auth): allow passive terminal observation (pingdotgg#9791)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(auth): keep old clients connected across scope changes (pingdotgg#10298)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* feat(server): hosted agents like ChatGPT can sign in to the T3 MCP server (pingdotgg#16718)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* docs: connect Claude Code, Codex, ChatGPT and bots over MCP (pingdotgg#16741)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): thread details card gives titles room to read (pingdotgg#16746)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(mcp): agent HTML pages stop painting slab backgrounds (pingdotgg#16752)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: composer picks up new project skills without a server restart (pingdotgg#16750)

* feat(server): run a project action when a worktree thread settles (pingdotgg#16290)

Co-authored-by: spoukyii <61633921+spoukyii@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(web): old Claude threads compact on send instead of stacking notices (pingdotgg#16631)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): settled threads stop polling their pull requests (pingdotgg#16762)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): stop storing tool image bytes no client reads (pingdotgg#16652)

* fix(server): status refresh no longer pegs CPU in repos with thousands of untracked files (pingdotgg#16771)

Co-authored-by: Braulio Oliveira <brauliobo@gmail.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* perf(server): background branch lookups share one GitHub query per sweep (pingdotgg#16760)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): threads settle as soon as a client sees their PR merge (pingdotgg#16761)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(server,web,mobile): agents see snooze state and link to threads (pingdotgg#16782)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(release): Forgejo build resolves version-qualified catalog overrides

Upstream now pins overrides such as undici@^8 to the catalog; the packaging
script looked up the whole selector and failed. Mirrors upstream pingdotgg#16411.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): HTML renders and PDFs load behind a proxy that forbids framing

Clients frame asset documents from the environment's origin, which is
often not their own. A reverse proxy that adds X-Frame-Options: SAMEORIGIN
blanked every HTML render and PDF preview in that setup. Inline HTML and
PDF asset responses now carry `frame-ancestors *`, which browsers honour
in place of X-Frame-Options.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): desktop renderer may frame asset documents

CSP's `*` matches only http(s) ancestors, so the desktop app's custom
scheme origins are listed explicitly.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Project516 <138796702+Project516@users.noreply.github.com>
Co-authored-by: Igor Makowski <56691628+Mnigos@users.noreply.github.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Michel Liao <107891771+Michel-Liao@users.noreply.github.com>
Co-authored-by: Ishaan Kothari <ishaanko.mail@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: ahalekelly <7078138+ahalekelly@users.noreply.github.com>
Co-authored-by: SkiTee3000 <39069192+SkiTee3000@users.noreply.github.com>
Co-authored-by: Ashkaan <a@ashkaan.me>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Erik Thorelli <ethorelli@gmail.com>
Co-authored-by: James Villarrubia <8172873+jamesvillarrubia@users.noreply.github.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Alex Southwell <saphid@gmail.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Tristan Manchester <108270628+tristanmanchester@users.noreply.github.com>
Co-authored-by: Arav Jain <aravhawk@gmail.com>
Co-authored-by: Sypher760-gif <sayffadil@gmail.com>
Co-authored-by: Nikita Koynov <43469098+nkoynov@users.noreply.github.com>
Co-authored-by: maria <maria@kuuro.net>
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Jake Leventhal <jakeleventhal@me.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Lorenzo <150276837+Bombatomica64@users.noreply.github.com>
Co-authored-by: Benedikt Rump <bjrump@gmail.com>
Co-authored-by: Stevan Borus <steva.borus@gmail.com>
Co-authored-by: Gabriel De Andrade <30420087+gabrielelpidio@users.noreply.github.com>
Co-authored-by: spoukyii <61633921+spoukyii@users.noreply.github.com>
Co-authored-by: Derek Trimm <275381468+derektrimm@users.noreply.github.com>
Co-authored-by: Braulio Oliveira <brauliobo@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews size:XS 0-9 changed lines (additions + deletions). vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants