Skip to content

feat(web): cite assistant responses with inline citations - #9146

Merged
juliusmarminge merged 4 commits into
mainfrom
assistant-response-citations
Sep 2, 2026
Merged

juliusmarminge merged 4 commits into
mainfrom
assistant-response-citations

Conversation

@juliusmarminge

@juliusmarminge juliusmarminge commented Sep 2, 2026 •

Copy link
Copy Markdown
Member

Quoting part of an assistant response meant copying text that lost all connection to where it came from. This adds citations: select text in an assistant response, choose Cite in composer, and an inline quote chip lands at your cursor — with an optional comment bubble anchored right at the selected passage. Clicking a chip (in the draft or a sent message) navigates to the source response, smooth-scrolls it into view — loading older history and unfolding turns when needed — and pulses a highlight on the exact quoted text that holds for a moment before fading.

How it works:

  • Citations serialize as self-contained t3-citation:// Markdown links carrying the quote, source IDs, offsets, context, and optional comment — no new tables, migrations, or sidecar draft state. They survive drafts, stashes, copy/paste, reloads, and sending.
  • The composer treats them as atomic inline chips (Lexical decorator nodes) alongside mentions and skills; comments edit as one undoable change via the chip's pencil.
  • ProviderService.sendTurn expands citations into readable quote data for every adapter (quote marked as reference material, comment as user-authored), while persisted messages keep the clickable links. Title/branch generation and stash previews see plain text.
  • Source matching normalizes whitespace and uses surrounding context, so quotes still resolve after edits and never guess between ambiguous repeats.
  • The terminal's "select text to copy" menu and the new citation menu share one release-triggered selection observer with consistent positioning.
  • Mobile renders sent quotes as readable blockquotes with the comment below; it doesn't create citations. Docs in docs/user/composer.md and docs/internals/assistant-citations.md.

Demo

Selection → cite → comment bubble at the selection → chip in composer → click-to-source with the pulse-and-hold highlight:

https://gh-file-drop-api-prod-mi5fy3sowv63ufte.pinglabs.workers.dev/f/35ecd10e3b53aa45/citation-demo.mp4

Built with Claude Fable 5 (Codex CLI + Claude Code).

🤖 Generated with Claude Code


Note

Medium Risk
Changes the provider turn input pipeline (citation expansion and re-validation against send limits) and orchestration title/branch inputs, though malformed citations pass through and expansion is covered by tests.

Overview
Users can quote assistant messages end-to-end: select text in the web timeline, insert an inline citation chip in the Lexical composer (optional comment, paste/copy/undo-safe), and follow chips back to the source message with history loading, turn expansion, scroll, and a temporary highlight.

Citations are stored as t3-citation:// markdown links in message text and drafts. Server-side, ProviderService.sendTurn expands them into numbered quote placeholders plus a structured assistant_citations JSON block for adapters while keeping the canonical links in persisted messages; title/branch generation and stash previews use plain-text citation content. Mobile only renders citations as readable text in the feed.

Chat markdown renders citation links as chips; composer submission validates both encoded and expanded prompt length. The terminal drawer reuses a shared observeSelectionActions helper for selection menus (replacing bespoke mouseup timing).

Reviewed by Cursor Bugbot for commit 393a909. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add inline citations for assistant responses with selection, composer chips, and provider expansion

  • Users select assistant text in the timeline to create a citation chip in the composer; chips support comments, editing, removal, and persistence across drafts and clipboard copy
  • Citations encode as version-1 t3-citation URIs with bounded identifiers, quote text, offsets, and context; parseAssistantCitationHref and collectAssistantCitations in assistantCitations.ts validate and collect them while leaving malformed links untouched
  • expandAssistantCitationsForProvider replaces serialized citation links with numbered quote references plus a structured assistant_citations context block; ProviderService.sendTurn in ProviderService.ts runs expansion before adapter dispatch and re-validates expanded input against the provider limit
  • Citation navigation in useAssistantCitationTarget and MessagesTimeline loads missing history, expands collapsed turns, scrolls to the source, highlights it with CSS custom highlights, and warns on unavailable sources; title and branch-name generation in ProviderCommandReactor.ts now receive plain-text citation content instead of serialized markup
  • Mobile renders citations as readable text only via renderAssistantCitationsAsText in ThreadFeed.tsx; terminal selection handling in ThreadTerminalDrawer.tsx moves to the shared observeSelectionActions observer with ownership-aware menu dismissal
  • Risk: getComposerPromptLengthValidationMessage in composerSubmission.ts now rejects drafts when either serialized or expanded citation text exceeds the provider limit; CHAT_MARKDOWN_SANITIZE_SCHEMA in ChatMarkdown.tsx now permits the t3-citation protocol in hrefs

Macroscope summarized 393a909.

Select text in an assistant response and choose "Cite in composer" to
insert an inline quote chip at the cursor, with an optional comment
bubble anchored at the selected text. Chips carry the quote, its source
IDs, and the comment through drafts, stashes, copy/paste, and sending.
Clicking a chip navigates to the source response, smooth-scrolls it
into view (loading older history when needed), and pulses a highlight
on the exact quoted passage that holds briefly before fading.

Provider dispatch expands citations into readable quote data for every
adapter while persisted messages keep the clickable links; titles,
branch names, and stash previews see plain text. Mobile renders sent
quotes as blockquotes. The terminal and assistant selection menus share
one release-triggered gesture observer.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL 1,000+ changed lines (additions + deletions). labels Sep 2, 2026
const hashIndex = href.indexOf("#");
if (hashIndex === -1) return null;
const hash = href.slice(hashIndex + 1);
if (!hash.startsWith(CITATION_HASH_PREFIX) || hash.length > 140_000) return null;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Medium lib/assistantCitationNavigation.ts:28

Valid maximum-size citations are rejected when the encoded hash exceeds 140,000 characters, so navigation reaches the destination but the citation cannot be decoded or highlighted. Because the 8,000-unit quote/comment limits can produce a percent-encoded href over 105 KB and Base64url expands it further, raise or remove this cap (while enforcing the citation limits on the decoded value).

🚀 Reply "fix it for me" or copy this AI Prompt for your agent:
In file @apps/web/src/lib/assistantCitationNavigation.ts around line 28:

Valid maximum-size citations are rejected when the encoded hash exceeds 140,000 characters, so navigation reaches the destination but the citation cannot be decoded or highlighted. Because the 8,000-unit quote/comment limits can produce a percent-encoded href over 105 KB and Base64url expands it further, raise or remove this cap (while enforcing the citation limits on the decoded value).

setReady(null);
onManualNavigation();
}
if (!viewport || historyLoading) return;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Medium chat/useAssistantCitationTarget.ts:78

Citations whose source message is missing never complete when the thread is empty: MessagesTimeline does not mount a viewport, so useAssistantCitationTarget returns before the missing-source branch runs, leaving positioning true indefinitely without showing the unavailable-source warning. Perform the history/source lookup without requiring viewport, and only gate list positioning on the viewport being available.

Suggested change
if (!viewport || historyLoading) return;
if (historyLoading) return;
🚀 Reply "fix it for me" or copy this AI Prompt for your agent:
In file @apps/web/src/components/chat/useAssistantCitationTarget.ts around line 78:

Citations whose source message is missing never complete when the thread is empty: `MessagesTimeline` does not mount a viewport, so `useAssistantCitationTarget` returns before the missing-source branch runs, leaving `positioning` true indefinitely without showing the unavailable-source warning. Perform the history/source lookup without requiring `viewport`, and only gate list positioning on the viewport being available.

Comment on lines +35 to +42
<textarea
ref={inputRef}
aria-label="Comment on selected text"
aria-description="Enter to save the citation comment; Shift+Enter for a new line."
aria-invalid={commentTooLong || undefined}
placeholder="Add an optional comment..."
rows={2}
className="field-sizing-content block max-h-40 min-h-16 w-full resize-none bg-transparent px-1 py-1.5 text-base outline-none placeholder:text-muted-foreground sm:text-sm"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This raw <textarea> reconstructs the shared Textarea primitive (field-sizing-content, min-h, text-base sm:text-sm, placeholder color, outline-none) but loses its contract: aria-invalid gets no visual treatment and disabled/focus styling is not shared, so the over-limit state is conveyed only by the helper text. The repo already has a borderless inline comment box built on the primitive — DiffCommentAnnotation uses <Textarea unstyled size="sm" className=... /> and overrides geometry through [&_[data-slot=textarea]]:….

Consider rendering the shared Textarea with unstyled and the same class overrides instead of a hand-rolled control.

Posted via Macroscope — UI Consistency

}
>
<QuoteIcon aria-hidden="true" className={COMPOSER_INLINE_CHIP_ICON_CLASS_NAME} />
<span className={cn(COMPOSER_INLINE_CHIP_LABEL_CLASS_NAME, "max-w-[16em]")}>{label}</span>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The label always uses the composer label class, which includes select-none, even when the chip renders read-only in a sent message (ChatMarkdown passes no onRemove). Every other chat-rendered chip keeps its label selectable — FileTagChipContent switches to CHAT_INLINE_CHIP_LABEL_CLASS_NAME via its selectable flag, and SkillInlineText uses it directly — so users can select and copy message text (and serializeRenderedMarkdownFragment can pick the chip up from a real selection). Here the quote label drops out of any selection dragged across the message.

Consider mirroring the FileTagChip pattern: import CHAT_INLINE_CHIP_LABEL_CLASS_NAME and pick it when onRemove is undefined, e.g. cn(onRemove ? COMPOSER_INLINE_CHIP_LABEL_CLASS_NAME : CHAT_INLINE_CHIP_LABEL_CLASS_NAME, "max-w-[16em]"). The unconditional contentEditable={false} on the wrapper (line 82) is likewise only needed for the composer variant — ComposerCitationNode's decorator wrapper already sets it.

Posted via Macroscope — UI Consistency

Comment thread apps/web/src/components/chat/AssistantSelectionToolbar.tsx Outdated
const { message } = entry;
const isUser = message.role === "user";
const renderedText = message.text;
const renderedText = renderAssistantCitationsAsText(message.text);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mobile renders citations for all messages unnecessarily

Low Severity

renderAssistantCitationsAsText is called unconditionally for every message (both user and assistant roles) at the top of the message rendering block. Assistant messages never contain [Assistant quote](t3-citation://...) links — citations are only inserted into user messages via the composer. For assistant messages, this runs a regex scan across potentially large text for no reason. Gating the call behind isUser avoids unnecessary work on every assistant message render.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 22c1ce8. Configure here.

Comment thread packages/shared/src/assistantCitations.ts
@macroscopeapp

macroscopeapp Bot commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This XXL change adds a new cross-platform citation workflow with persistent composer data, virtualized source navigation, provider prompt expansion, and changes to existing terminal selection behavior. The supplied unresolved Medium findings also identify citation-size and unavailable-source handling risks that merit human review.

Not approved because:

  • 3 blocking correctness issues found at or above your repo's Minimum Blocking Severity

Adjust the Minimum Blocking Severity for this repo — including turning it Off — in Settings. You can add or adjust custom eligibility rules. Learn more.

@maria-rcks

Copy link
Copy Markdown
Collaborator

Note

Written by gpt-5.6-sol on behalf of Maria

Refined the citation controls in 0562c44b5:

  • replaced the oversized selection menu with a compact Cite action
  • kept the whole composer citation clickable for source navigation
  • removed the composer tooltip and fill change on hover
  • made the composer edit and remove controls use the primary blue

Light mode

Citation controls in light mode

Dark mode

Citation controls in dark mode

Verified with 126 focused tests, web typecheck, targeted lint, formatting, and direct light/dark browser checks. Hovering a composer citation shows no tooltip, and selecting the quote or label still opens the source highlight.

Comment thread docs/user/composer.md
The quoted text and comment count toward the message limit.

Select a chip in the composer or a sent message to open the source thread, scroll to the response,
and highlight the quoted passage — including in older history. The

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Medium user/composer.md:71

This documentation promises that citations navigate to responses in older history, but useAssistantCitationTarget stops after requestedPages.size >= 20 and reports “Could not load the cited response” even when loadEarlier has more pages, so citations more than 20 history pages back cannot be opened as documented. Qualify or remove the “including in older history” claim.

Suggested change
and highlight the quoted passage — including in older history. The
and highlight the quoted passage when the source response is available to the citation navigator. The
🚀 Reply "fix it for me" or copy this AI Prompt for your agent:
In file @docs/user/composer.md around line 71:

This documentation promises that citations navigate to responses in older history, but `useAssistantCitationTarget` stops after `requestedPages.size >= 20` and reports “Could not load the cited response” even when `loadEarlier` has more pages, so citations more than 20 history pages back cannot be opened as documented. Qualify or remove the “including in older history” claim.

Comment thread docs/user/composer.md
## Quote an assistant response

On web and desktop, select text in an assistant response, then choose **Cite in composer** from the
menu that appears when you release the selection. This inserts an inline quote chip at your cursor

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Low user/composer.md:58

Users cannot find the documented Cite in composer control because AssistantSelectionToolbar renders a Cite button, not a menu item with that visible label. Update the instruction to name the visible Cite button (its accessible label is Cite selection in composer).

🚀 Reply "fix it for me" or copy this AI Prompt for your agent:
In file @docs/user/composer.md around line 58:

Users cannot find the documented **Cite in composer** control because `AssistantSelectionToolbar` renders a **Cite** button, not a menu item with that visible label. Update the instruction to name the visible **Cite** button (its accessible label is `Cite selection in composer`).

juliusmarminge and others added 2 commits September 1, 2026 20:48
Raise the highlight from 28% to 45% of the primary color for both the
navigation pulse-and-hold and the comment-editing highlight, so the
quoted passage is visible without knowing where to look.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…tations

# Conflicts:
#	docs/user/composer.md
@github-actions

github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

Provider Metric Main baseline This PR Impact PR ceiling
Codex Total thread wire 13.5 KiB 13.5 KiB 0 B (0.0%) 15.1 KiB ✅
Codex Thread snapshot wire 6.9 KiB 6.9 KiB +7 B (+0.1%) 7.3 KiB ✅
Codex Live turn WebSocket wire 6.6 KiB 6.6 KiB −7 B (−0.1%) 7.8 KiB ✅
Codex Live turn WebSocket decoded 57.0 KiB 57.0 KiB 0 B (0.0%) 66.4 KiB ✅
Codex Live turn messages 10 10 0 (0.0%) 21 ✅
Claude Total thread wire 13.3 KiB 13.3 KiB +33 B (+0.2%) 15.1 KiB ✅
Claude Thread snapshot wire 6.9 KiB 6.9 KiB +9 B (+0.1%) 7.3 KiB ✅
Claude Live turn WebSocket wire 6.4 KiB 6.4 KiB +24 B (+0.4%) 7.8 KiB ✅
Claude Live turn WebSocket decoded 56.4 KiB 56.4 KiB 0 B (0.0%) 66.4 KiB ✅
Claude Live turn messages 10 10 0 (0.0%) 21 ✅

Baseline: 9fdafdf · PR result: 393a909 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@juliusmarminge
juliusmarminge merged commit e7deb2a into main Sep 2, 2026
26 of 27 checks passed
@juliusmarminge
juliusmarminge deleted the assistant-response-citations branch September 2, 2026 03:55
Comment on lines +252 to +255
return (
match.index +
(whitespace && normalizedOffset > offset ? match[0].length : normalizedOffset - offset)
);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Medium lib/assistantTextSelection.ts:252

resolveAssistantCitationRange expands a citation ending at the normalized boundary of a multi-character whitespace run to the end of that raw run, so a selection such as "x " in "a x y" highlights "x " instead of the captured text. rawTextOffset treats every offset after the whitespace token's start as a request for the raw token end; at the normalized token boundary it should advance by only the normalized offset (one space), not by match[0].length.

-        match.index +
-        (whitespace && normalizedOffset > offset ? match[0].length : normalizedOffset - offset)
+        match.index + normalizedOffset - offset
🚀 Reply "fix it for me" or copy this AI Prompt for your agent:
In file @apps/web/src/lib/assistantTextSelection.ts around lines 252-255:

`resolveAssistantCitationRange` expands a citation ending at the normalized boundary of a multi-character whitespace run to the end of that raw run, so a selection such as `"x "` in `"a x  y"` highlights `"x  "` instead of the captured text. `rawTextOffset` treats every offset after the whitespace token's start as a request for the raw token end; at the normalized token boundary it should advance by only the normalized offset (one space), not by `match[0].length`.

Comment on lines 759 to 763
attachmentPathLines.length === 0
? parsed.input
: [parsed.input, attachmentPathLines.join("\n")]
? inputTextWithCitations
: [inputTextWithCitations, attachmentPathLines.join("\n")]
.filter((part): part is string => typeof part === "string" && part.length > 0)
.join("\n\n");

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 High Layers/ProviderService.ts:759

adapter.sendTurn receives inputTextWithAttachmentPaths without validating its final length, so expanded citation text at the 120,000-character limit can become an oversized prompt when resolvable attachment path lines are appended. Validate the joined inputTextWithAttachmentPaths after constructing it.

Suggested change
attachmentPathLines.length === 0
? parsed.input
: [parsed.input, attachmentPathLines.join("\n")]
? inputTextWithCitations
: [inputTextWithCitations, attachmentPathLines.join("\n")]
.filter((part): part is string => typeof part === "string" && part.length > 0)
.join("\n\n");
const inputTextWithAttachmentPaths =
attachmentPathLines.length === 0
? inputTextWithCitations
: [inputTextWithCitations, attachmentPathLines.join("\n")]
.filter((part): part is string => typeof part === "string" && part.length > 0)
.join("\n\n");
yield* decodeInputOrValidationError({
operation: "ProviderService.sendTurn",
schema: ProviderSendTurnInput.fields.input,
payload: inputTextWithAttachmentPaths,
});
🚀 Reply "fix it for me" or copy this AI Prompt for your agent:
In file @apps/server/src/provider/Layers/ProviderService.ts around lines 759-763:

`adapter.sendTurn` receives `inputTextWithAttachmentPaths` without validating its final length, so expanded citation text at the 120,000-character limit can become an oversized prompt when resolvable attachment path lines are appended. Validate the joined `inputTextWithAttachmentPaths` after constructing it.

Comment on lines +144 to +167
let separator = false;

const visit = (node: Node) => {
if (node.nodeType === 3) {
const text = node as Text;
if (text.length === 0) return;
if (separator && length > 0) {
parts.push("\n");
length += 1;
}
separator = false;
chunks.push({ node: text, start: length, end: length + text.length });
parts.push(text.data);
length += text.length;
return;
}
if (node.nodeType !== 1) return;
const element = node as Element;
if (element.matches(EXCLUDED_SELECTOR)) return;
const block = element.matches(BLOCK_SELECTOR);
if (block || element.tagName === "BR") separator = true;
for (const child of element.childNodes) visit(child);
if (block) separator = true;
};

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Medium lib/assistantTextSelection.ts:144

When a selection crosses consecutive <br> elements, readAssistantText returns only one \n instead of one per break, so the saved quote and offsets no longer represent the text the user selected. Because separator is a boolean, later breaks overwrite the pending separator; track the number of consecutive breaks and emit that many separators.

-  let separator = false;
+  let separator = 0;
@@
-      if (separator && length > 0) {
+      if (separator > 0 && length > 0) {
         parts.push("\n");
-        length += 1;
+        length += separator;
       }
-      separator = false;
+      separator = 0;
@@
-    if (block || element.tagName === "BR") separator = true;
+    if (element.tagName === "BR") separator += 1;
+    else if (block) separator = Math.max(separator, 1);
@@
-    if (block) separator = true;
+    if (block) separator = Math.max(separator, 1);
🚀 Reply "fix it for me" or copy this AI Prompt for your agent:
In file @apps/web/src/lib/assistantTextSelection.ts around lines 144-167:

When a selection crosses consecutive `<br>` elements, `readAssistantText` returns only one `\n` instead of one per break, so the saved quote and offsets no longer represent the text the user selected. Because `separator` is a boolean, later breaks overwrite the pending separator; track the number of consecutive breaks and emit that many separators.

const decodeCitation = Schema.decodeUnknownOption(AssistantCitation);

function encodePathPart(value: string): string {
return encodeURIComponent(value).replace(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Medium src/assistantCitations.ts:21

formatAssistantCitationHref emits IDs such as . and .. as literal path segments, so new URL() normalizes them and parseAssistantCitationHref returns null instead of the original citation. Sources with these valid IDs are therefore serialized but cannot be collected, expanded, or navigated; percent-encode . in encodePathPart as well.

🚀 Reply "fix it for me" or copy this AI Prompt for your agent:
In file @packages/shared/src/assistantCitations.ts around line 21:

`formatAssistantCitationHref` emits IDs such as `.` and `..` as literal path segments, so `new URL()` normalizes them and `parseAssistantCitationHref` returns `null` instead of the original citation. Sources with these valid IDs are therefore serialized but cannot be collected, expanded, or navigated; percent-encode `.` in `encodePathPart` as well.

setupCleanups.push(() => {
window.removeEventListener("mouseup", handleMouseUp);
mount.removeEventListener("pointerdown", handlePointerDown);
selectionActions = observeSelectionActions({

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Medium components/ThreadTerminalDrawer.tsx:778

In browser mode, clicking Copy or Add-to-chat in the selection menu never executes the action: observeSelectionActions treats the fallback menu's DOM pointerdown outside mount as an interaction, invalidates the request, and closes the menu before its click resolves. Pass the menu element through getActionElement (or otherwise exempt the fallback menu) so interactions with the menu remain part of the active selection flow.

🚀 Reply "fix it for me" or copy this AI Prompt for your agent:
In file @apps/web/src/components/ThreadTerminalDrawer.tsx around line 778:

In browser mode, clicking `Copy` or `Add-to-chat` in the selection menu never executes the action: `observeSelectionActions` treats the fallback menu's DOM pointerdown outside `mount` as an interaction, invalidates the request, and closes the menu before its click resolves. Pass the menu element through `getActionElement` (or otherwise exempt the fallback menu) so interactions with the menu remain part of the active selection flow.

onCancel: () => void;
}) {
const [comment, setComment] = useState(citation.comment ?? "");
const commentTooLong = comment.length > ASSISTANT_CITATION_MAX_COMMENT_LENGTH;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Medium chat/AssistantCitationCommentEditor.tsx:18

Save is disabled for a comment whose trimmed value is at most ASSISTANT_CITATION_MAX_COMMENT_LENGTH, such as an 8,000-character comment with one leading or trailing space. commentTooLong checks the untrimmed value, while withAssistantCitationComment trims before persisting; validate comment.trim() so the editor uses the same value as the storage contract.

-  const commentTooLong = comment.length > ASSISTANT_CITATION_MAX_COMMENT_LENGTH;
+  const commentTooLong = comment.trim().length > ASSISTANT_CITATION_MAX_COMMENT_LENGTH;
🚀 Reply "fix it for me" or copy this AI Prompt for your agent:
In file @apps/web/src/components/chat/AssistantCitationCommentEditor.tsx around line 18:

`Save` is disabled for a comment whose trimmed value is at most `ASSISTANT_CITATION_MAX_COMMENT_LENGTH`, such as an 8,000-character comment with one leading or trailing space. `commentTooLong` checks the untrimmed value, while `withAssistantCitationComment` trims before persisting; validate `comment.trim()` so the editor uses the same value as the storage contract.

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.

There are 3 total unresolved issues (including 1 from previous review).

Fix All in Cursor

Bugbot Autofix is ON, but it could not run because the branch was deleted or merged before autofix could start.

Reviewed by Cursor Bugbot for commit 393a909. Configure here.

dismissed = true;
}
onDismiss("cancel");
};

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Scroll cancels the Cite toolbar

Medium Severity

observeSelectionActions treats any descendant scroll as a cancel. After pointerup, pointerDown is already false, so a selection scroll-into-view or LegendList layout scroll clears the pending timer and sets dismissed. selectionchange will not recover, so the Cite control never appears for selections that move the timeline.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 393a909. Configure here.

const hashIndex = href.indexOf("#");
if (hashIndex === -1) return null;
const hash = href.slice(hashIndex + 1);
if (!hash.startsWith(CITATION_HASH_PREFIX) || hash.length > 140_000) return null;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Large citation hashes fail navigation

Low Severity

assistantCitationFromLocation drops hashes longer than 140,000 characters, but assistantCitationHash base64url-encodes the full t3-citation href. A near-max Unicode quote plus comment encodes past that cap, so chip clicks still change the thread route and then never activate highlight or history loading.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 393a909. Configure here.

juliusmarminge added a commit that referenced this pull request Sep 2, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 2, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 4, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 5, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 5, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
aorwall added a commit to aorwall/t3code that referenced this pull request Sep 5, 2026
Merges 137 upstream commits (`d937e3075..36c4e9c`) into the fork,
following the `fork-upstream-merge` skill. Landed as a merge commit;
conflicts resolved by the inventory's cached verdicts.

## Merge shape

816 files landed (`git diff --stat HEAD^1 HEAD`) against 811 in the
upstream range; fork delta 650 files. The gap of five is all in landed
and not the range: two fork-owned files touched during resolution
(`sandboxControl.placement.test.tsx` test-prop fixup,
`useSandboxCommandsBanner.tsx` reformat) plus the three fork docs this
merge writes (`inventory.json`, `gaps.md`, `upstream-merge-log.md`). No
upstream work was dropped.

## Conflicts

Resolved by inventory verdict — `AGENTS.md` (kept the fork's slimmed
shape, added Antigravity to the provider list), `contracts/rpc.ts` and
`environment.ts`, the ChatView/MessagesTimeline thread-fork +
message-origin convergence, the preview cluster (`addBrowserSurface`
`profileId` beside the fork's `url`, `rightPanelStore` `openAttachment`
beside `retargetFile`), the settings gates, and the two upstream pingdotgg#9364
test deletions.

Two latent fork bugs surfaced and were fixed: `PreviewView`'s hosted
annotation handler called an unexported helper, now routed through the
exported `capturePreviewAnnotationScreenshot` wrapper (matching the
sibling native handler); and `ChatView` passed a `configuredUrls` prop
the fork's hosted `PreviewPanel` does not accept.

## Unsupported methods

`unsupported-methods.mjs` reported ADD 10; recomputed to 0 by adding
`UnsupportedMethodError` to the shared `ProviderSetupRpcError` union
(nine `provider.auth.*` / `provider.install.*` methods) and to
`server.refreshUsageRates`. `gaps.md` grown with a _Provider setup_
bullet and a `refreshUsageRates` clause on _Usage summary_. The three
DROP entries (`scripts.run`, `subtasks.list`, `threads.getShell`) are
the documented keep-anyway exceptions — `apps/server` still refuses
them.

## Feature classification

**Usable as-is** (UI only, no backend dependency): mod+w tab close
(pingdotgg#9363), PageUp/PageDown chat nav (pingdotgg#9315), diff/PR file tree (pingdotgg#9330),
diff-header copy path (pingdotgg#2403), error-report copy (pingdotgg#9166), opt-in
context-window indicator (pingdotgg#9190), opt-in panel animations (pingdotgg#8830),
proactive panels (pingdotgg#9276), button press feedback (pingdotgg#9349), provider-editor
redesign chrome (pingdotgg#8508).

**Unsupported in Moatless** (resolve to a refusal): Antigravity provider
auth/install and all `provider.*` setup (pingdotgg#9348, pingdotgg#8508),
`server.refreshUsageRates`. Desktop-only and already capability- or
desktop-gated, so no new fork work: preview browser profiles (pingdotgg#7254),
open-links-in-app (pingdotgg#9339), ssh-host suggestions (pingdotgg#9171),
environment-as-machine (pingdotgg#9299), continue-threads-across-restart (pingdotgg#9167,
rides the new `serverUpdateThreadContinuation` capability).

**Backend behavior to reproduce** if Moatless wants it: project icons
(pingdotgg#9137, migration 047), auto-pull clean default branches (pingdotgg#9277,
migration 045), inline citations (pingdotgg#9146, needs the backend to emit
them), the usage page. Migration 046
(RepairAutomaticSettlementTimestamps) is upstream-server-only.

Net-zero: context compaction (pingdotgg#8808) landed and was reverted (pingdotgg#9284).

## Verification

`fmt:check`, `lint`, `typecheck`, `tripwires` and `inventory-check`
green. Full test suite green — one web test failed initially
(`addBrowserSurface.test.ts` did not expect the converged default
`profileId`), fixed and re-run.

Two `verify.mjs` checks exit non-zero and are the caveated machine
failures: `unsupported-methods` on the three documented DROP exceptions
above, and `duplicate-adds` on three confirmed false positives
(`openPreview` in a `ChatView` object literal vs its deps array; three
distinct `it()` blocks in `addBrowserSurface.test.ts`).

Written by Claude Opus 5 in Claude Code.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---
Moatless task:
https://moatless.soaplabstest.com/tasks/4e881239-73d1-4a93-9563-6a926e920b42
github-actions Bot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 7, 2026
## What's Changed
* fix(web): preserve theme when toggling advanced colors by @StiensWout in https://github.com/pingdotgg/t3code/pull/8500
* fix(chat): keep latest command live between messages by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9098
* fix(media): preview host files and stream videos across clients by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9023
* feat(cli): open projects in the running desktop app by @t3dotgg in https://github.com/pingdotgg/t3code/pull/8824
* chore: vouch six repeat contributors by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9131
* chore: delete dead code, unused deps, and duplicate helpers by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9129
* fix(web): mute routine notices and update actions by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9063
* perf(provider): bound persisted session lookups by @nateEc in https://github.com/pingdotgg/t3code/pull/8909
* fix(claude): skills picked from the composer now run by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9128
* fix(web): stop highlighter freezes and worker spin by using the Oniguruma WASM engine by @LetZico in https://github.com/pingdotgg/t3code/pull/8360
* perf: make streaming projection and activity appends incremental by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9152
* fix(server): bound orchestration replay payloads by @rcawston in https://github.com/pingdotgg/t3code/pull/8992
* perf(client-runtime): keep turn and checkpoint refs stable while streaming by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9145
* perf(clients): lease sidebar status by visibility by @StiensWout in https://github.com/pingdotgg/t3code/pull/9052
* fix(desktop): show newest changes in nightly previews by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9138
* fix(settings): sync auto-settle and other shared preferences across environments by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9147
* fix(server): prevent accidental service downgrades by @t3dotgg in https://github.com/pingdotgg/t3code/pull/5302
* fix(server): keep attachments until the command commits by @t3dotgg in https://github.com/pingdotgg/t3code/pull/7941
* fix(claude): preview images read from the workspace by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9119
* fix(web): keep generated muted foreground dimmer than entered text by @flamboh in https://github.com/pingdotgg/t3code/pull/9113
* fix(clients): stop repeating expanded commands by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9120
* fix(grok): health check, model selection, and stop all work against the real CLI by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9154
* perf(web): halve the cold-start bundle by splitting Clerk and cold routes by @StiensWout in https://github.com/pingdotgg/t3code/pull/9058
* feat(desktop): update the desktop app on remote Macs from the Update button by @t3dotgg in https://github.com/pingdotgg/t3code/pull/6554
* test(server): measure shell, second client, and reconnect transfer by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9157
* fix(web): project default model works on the hosted app by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9142
* fix(web): darken neutral control surfaces by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9064
* fix(web): preserve panel state across workspace refreshes by @maria-rcks in https://github.com/pingdotgg/t3code/pull/8968
* feat(files): open markdown, HTML, and PDF files outside the workspace by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9140
* feat(web): render HTML and PDF files in the file viewer by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9143
* fix(web): compact project settings actions by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9160
* fix(web): browse folders from file breadcrumbs by @404khai in https://github.com/pingdotgg/t3code/pull/8910
* feat(pull-requests): copy provider checkout commands by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9086
* fix(web): hide build pill in narrow sidebars by @flamboh in https://github.com/pingdotgg/t3code/pull/9159
* feat(web): cite assistant responses with inline citations by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9146
* fix(provider): drop removed custom models from the model picker by @StiensWout in https://github.com/pingdotgg/t3code/pull/9075
* fix(web): align composer notices and stash by @Bil0000 in https://github.com/pingdotgg/t3code/pull/8890
* fix(web): label keybinding condition removal actions by @RakshithBhat03 in https://github.com/pingdotgg/t3code/pull/8664
* fix(contracts): accept legacy pull request checkout results by @jakeleventhal in https://github.com/pingdotgg/t3code/pull/8238
* fix(desktop): hold-to-quit no longer gets stuck by @saphid in https://github.com/pingdotgg/t3code/pull/9141
* chore: remove unused code and brittle tests by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9150
* fix(chat): improve tool group summaries and scrolling by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9106
* feat(web): copy the full error report from the error page by @StiensWout in https://github.com/pingdotgg/t3code/pull/9166
* fix(chat): replace failed tools with thinking by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9165
* fix(chat): align failed task progress test by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9172
* fix(web): open PR toast actions in app by @eimexdev in https://github.com/pingdotgg/t3code/pull/9006
* fix(desktop): check artifact build prerequisites by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/8975
* fix(server): discover project skills for Codex and OpenCode by @UtkarshUsername in https://github.com/pingdotgg/t3code/pull/8778
* fix(pull-requests): expand code tab diffs by default by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9174
* chore: bump vendored GhosttyKit and update terminal integration by @Yash-Singh1 in https://github.com/pingdotgg/t3code/pull/9155
* fix(web): copying a code block no longer copies triple backticks by @ipanasenko in https://github.com/pingdotgg/t3code/pull/8448
* fix(models): restore sticky new-thread selections by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9164
* fix(web): model info button opens its details on click by @StiensWout in https://github.com/pingdotgg/t3code/pull/9177
* fix(desktop): skip cached monitor compiler check by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9184
* fix(web): avoid stale file writes on close by @yashranaway in https://github.com/pingdotgg/t3code/pull/8630
* fix(server): bound OpenCode version probes by @yashranaway in https://github.com/pingdotgg/t3code/pull/8750
* fix(server): allow large Azure DevOps PR lists by @Lucenx9 in https://github.com/pingdotgg/t3code/pull/8572
* fix(server): allow local-only worktree bases by @yashranaway in https://github.com/pingdotgg/t3code/pull/8751
* fix(web): remove projects with archived threads by @none23 in https://github.com/pingdotgg/t3code/pull/8798
* feat(web): make context window indicator opt-in by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9190
* fix(connect): refresh relay credentials before expiry by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9178
* fix(pull-requests): reuse github api reads by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9176
* fix(server): stop titling linked PR threads from local git history by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9191
* feat(updates): continue active threads across server restarts by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9167
* fix(mobile): prevent message and composer overlap by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9195
* fix(web): preserve composer draft during worktree setup by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9197
* fix(web): prevent two-digit list markers from being clipped by @G-R3 in https://github.com/pingdotgg/t3code/pull/9101
* fix(server): discover project skills for Claude by @anirudhsama in https://github.com/pingdotgg/t3code/pull/9210
* feat(web): redesign provider editor and models list by @StiensWout in https://github.com/pingdotgg/t3code/pull/8508
* fix(web): prevent connection rows from wrapping during removal by @MatthewFeroz in https://github.com/pingdotgg/t3code/pull/8706
* fix(pull-requests): align checkout control with author by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9196
* fix(release): pin patched expo-sharing version by @willsheldon in https://github.com/pingdotgg/t3code/pull/9250
* chore(mobile): update Expo Sharing to 57.0.17 by @StiensWout in https://github.com/pingdotgg/t3code/pull/9248
* fix(web): hide deleted providers with prototype keys by @Lucenx9 in https://github.com/pingdotgg/t3code/pull/8337
* feat(mobile): long-press file references for path and open actions by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9258
* fix(desktop): exclude opposite macOS pty prebuilds by @extoci in https://github.com/pingdotgg/t3code/pull/9240
* feat(web): add copy path button to diff headers by @ipanasenko in https://github.com/pingdotgg/t3code/pull/2403
* fix(server): subscribe before provider settings watcher by @t3-code[bot] in https://github.com/pingdotgg/t3code/pull/9271
* fix(mobile): show filled filter icon on Android when filters are active by @none23 in https://github.com/pingdotgg/t3code/pull/9217
* fix(chat): show single tool calls without summaries by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9267
* fix(web): warn when shared settings have no target environment by @imabdulazeez in https://github.com/pingdotgg/t3code/pull/9207
* fix(web): confirm closing agent-controlled browsers by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9272
* feat(desktop): browser profiles for the preview browser by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/7254
* refactor(shared): move the node:sqlite Effect SQL client into shared by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/7272
* feat(web): add opt-in panel animations by @maria-rcks in https://github.com/pingdotgg/t3code/pull/8830
* feat(projects): automatically pull clean default branches by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9277
* fix(web): show pull request state icons in tabs by @flamboh in https://github.com/pingdotgg/t3code/pull/9112
* feat(providers): add context compaction across harnesses by @maria-rcks in https://github.com/pingdotgg/t3code/pull/8808
* feat(web): add proactive panels by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9276
* fix(web): unify control sizing across settings pages by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9281
* fix(web): offer browser profiles from the empty-panel launcher by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9279
* Revert "feat(providers): add context compaction across harnesses" by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9284
* fix(web): show scroll-to-end as soon as the last message slips under the composer by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9280
* fix(cursor): honor auto and full access modes by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9283
* fix(desktop): detect installed Spectre libs for Windows builds by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9285
* fix(pull-requests): missing features & better behaviour by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9188
* fix(providers): discover workspace skills everywhere by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9180
* fix(server): preserve automatic settlement timestamps by @eimexdev in https://github.com/pingdotgg/t3code/pull/9254
* fix(opencode): show Reasoning selector for OpenCode models by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9287
* feat(web): preview document attachments in the file viewer by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9292
* chore(ci): narrow the UI consistency check-run agent by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9297
* chore(ci): only run check-run agents on vouched contributors by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9298
* fix(web): stop remounting markdown on every activity delta by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9306
* fix(pull-requests): keep cached PR chrome on reopen by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9294
* feat(environments): draw each environment as the machine it runs on by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9299
* feat(web): apply and remove labels from the pull request tab by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9313
* fix(sidebar): collapse settled and snoozed shelves by default by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9314
* refactor(media): unify file and media previews across clients by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9253
* fix(chat): keep live tool labels in present tense by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9316
* chore: audit lint directives and move plugin allowlists into config by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9300
* chore(ci): narrow the Effect conventions check-run agent by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9321
* refactor(mobile): style plain views with Uniwind classes instead of the theme bridge by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9322
* fix(dev): share dev servers on the loopback Vite actually binds by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9324
* fix(web): line up the titlebar wordmark label and version pill by @tristanmanchester in https://github.com/pingdotgg/t3code/pull/9255
* fix(web): make the diff layout toggle a persisted setting by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9326
* chore: dedupe lightningcss and tailwind node bindings by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9331
* chore: upgrade vite-plus to 0.3.0 by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9327
* feat(web): add a file tree to the diff panel and pull request code tab by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9330
* feat(web): add PageUp/PageDown chat navigation by @Yash-Singh1 in https://github.com/pingdotgg/t3code/pull/9315
* fix(web): collapse PR header actions to icons when narrow by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9334
* fix(web): resolve Vite sourcemap and supports warnings by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9343
* feat(web): choose whether links open in the default browser or in T3 Code by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9339
* fix(web): add press feedback to buttons by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9349
* feat(web): add customizable project icons by @saphid in https://github.com/pingdotgg/t3code/pull/9137
* fix(mobile): stop indented code overflowing Android chat bubbles by @Adamulek123 in https://github.com/pingdotgg/t3code/pull/9347
* fix(web): let the pull request list use wide screens by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9351
* feat: display native app and browser icons in work logs by @Yash-Singh1 in https://github.com/pingdotgg/t3code/pull/9093
* fix(web): collapse oldest pull request comments by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9323
* fix(pull-requests): shared state + not settling? by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9332
* fix(web): stop usage summary requests reporting slow RPCs by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9358
* feat(web): suggest ssh hosts in a dropdown under the host field by @flamboh in https://github.com/pingdotgg/t3code/pull/9171
* feat(web): mod+w closes the active right panel tab before the window by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9363
* test(web): remove static markup-only component tests by @t3-code[bot] in https://github.com/pingdotgg/t3code/pull/9364
* fix(environments): draw the machine icon everywhere an environment is named by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9365
* fix(web): settled sidebar rows use the project fallback icon by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9366
* fix(web): match project icon chooser button sizes by @Yash-Singh1 in https://github.com/pingdotgg/t3code/pull/9368
* fix(mobile): pressed and disabled styles no longer apply unconditionally by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9355
* fix(mobile): size expanded tool groups correctly by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9359
* fix(web): collapse the resting composer by @chrisdeeming in https://github.com/pingdotgg/t3code/pull/7855
* fix(web): keep trailing tool groups out of "Worked for" accordion by @Yash-Singh1 in https://github.com/pingdotgg/t3code/pull/9384
* feat(marketing): put named-developer quotes on the landing page by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9385
* fix(claude): expand slash commands when a message has attachments by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9122
* fix(web): stop the resting composer layout loop by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9393
* fix(web): render assistant images inline in chat by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9126
* feat(providers): add Google Antigravity via the official ACP agent by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9348
* fix(mobile): show an error instead of an endless preview spinner by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9123
* fix(usage): price new models without waiting a day for the rate table by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9202
* fix(web): unlock the composer when preview capture fails by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9127
* fix(antigravity): refresh the model manifest so older Gemini models fold as legacy by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9397
* perf(ci): reuse dependency checks in release builds by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9399
* fix(web): send cited messages with Cmd+Enter by @extoci in https://github.com/pingdotgg/t3code/pull/9307
* fix(web): preserve explicit preview navigation URLs by @nateEc in https://github.com/pingdotgg/t3code/pull/8902
* fix(web): prevent loading ssh environments from overriding navigation by @flamboh in https://github.com/pingdotgg/t3code/pull/9168
* fix(mobile): skip unsupported shared settings targets by @Lucenx9 in https://github.com/pingdotgg/t3code/pull/9381
* fix(web): avoid duplicate Antigravity install status by @RakshithBhat03 in https://github.com/pingdotgg/t3code/pull/9419
* fix(composer): mute fast icon when collapsed by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9451
* fix(web): unify skeleton loading animations on one pulse by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9448
* fix(web): prioritize authored pull requests by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9453
* fix(web): make project icons the default by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9457
* fix(server): reuse pr state when settling threads by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9459
* fix(web): keep agent images collapsed by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9460
* fix(web): banner buttons no longer expand the resting composer by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9452
* fix(web): stop clipping the traits chevron on long Codex effort labels by @zortos293 in https://github.com/pingdotgg/t3code/pull/9433
* fix(web): make right panel tabs easier to scroll by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9461
* fix(web): render transparent previews on white by @UtkarshUsername in https://github.com/pingdotgg/t3code/pull/9463
* fix(mobile): show loading and syncing in the working pill by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9466
* fix(server): keep a/ and b/ prefixes in rendered git patches by @Mnigos in https://github.com/pingdotgg/t3code/pull/9438
* fix(server): full-access OpenCode threads no longer ask for approvals by @shivamhwp in https://github.com/pingdotgg/t3code/pull/9282
* fix(web): reuse pull request list data while loading by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9467
* feat(web): let users turn off composer collapse on blur and scroll by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9469
* fix(web): move workflow approval beside checks by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9465
* fix(desktop): refresh generated annotation styles by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9488
* fix(web): let the PR reviewer and label search boxes take keystrokes by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9479
* fix(web): dont collapse composer when interacting with bottom row by @extoci in https://github.com/pingdotgg/t3code/pull/9490
* fix(desktop): restore second-press quit fallback by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9485
* fix(web): keep opencode icon hollow in collapsed composer by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9492
* fix(web): keep agent browser preview visible by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9484
* fix(mobile): keep the machine glyph next to the environment label by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9486
* fix(mobile): let back swipe pop from horizontal scroll edges by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9493
* fix(antigravity): discover legacy workspace skills by @Lucenx9 in https://github.com/pingdotgg/t3code/pull/9410
* fix(mobile): resolve Antigravity provider icon and normalize driver matching by @Invictine in https://github.com/pingdotgg/t3code/pull/9495
* fix(antigravity): forward Google sign-in URLs from browser helper by @WellyngtonF in https://github.com/pingdotgg/t3code/pull/9425
* feat(desktop): import browser cookies into a profile by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/7255
* feat(desktop): import from Chrome, Edge, Brave, Vivaldi, Opera, Arc and Firefox by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/7260
* feat(desktop): resolve Chromium cookie keys on Linux by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/7261
* fix(antigravity): allow slow runtime startup during setup by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9510
* fix(antigravity): keep model choices up to date by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9511
* fix(antigravity): handle native sign-in URLs on stderr by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9514
* fix(antigravity): update managed runtime to 1.1.1 by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9509
* fix(desktop): address the browser import review left over from the stack by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9516
* feat(antigravity): show subagent calls and results by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9515
* fix(web): let paste expand a resting composer by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9498
* fix(web): keep the composer open while selecting timeline text by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9499
* fix(web): return focus to the composer after closing a media preview by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9513
* fix(server): keep events during thread subscription startup by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9521
* chore: forward issue/PR/discussion events to Cursor hygiene by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9518
* fix(auth): keep pairing credentials out of access read models by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9523
* chore: drop comment events from Cursor hygiene forwarder by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9527
* feat(codex): support async questions by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9512
* fix(web): keep right panel controls clickable by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9517
* feat(usage): show Codex and Claude subscription limits on a Limits tab by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9507
* feat(web): reorganize settings pages by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9354
* fix(server): settle branch threads immediately on pull request merge by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9528
* fix(server): back off relay client restarts after rapid exits by @derektrimm in https://github.com/pingdotgg/t3code/pull/8788
* fix(codex): accept rate limit errors on thread resume by @nateEc in https://github.com/pingdotgg/t3code/pull/8897
* fix(desktop): preview CDP sessions no longer hard-crash the app by @sethwebster in https://github.com/pingdotgg/t3code/pull/9068
* Fix worktree removal timing out on large install trees by @jakeleventhal in https://github.com/pingdotgg/t3code/pull/3902
* fix(web): settle the resting composer layout with a pixel of slack by @matheustimbo in https://github.com/pingdotgg/t3code/pull/9482
* fix(web): keep automatic project icons consistent by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9535
* fix(server): include SQLite conditions in persistence errors by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9536
* fix(dev): keep shared dev reloads and hot updates working by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9543
* feat(providers): add context compaction command by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9293
* fix(mobile): keep store screenshots free of system banners and show dictation by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9548
* fix(web): restore composer controls as space becomes available by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9539
* fix(web): measure collapsed model labels at their visible width by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9540
* fix(web): close composer menus when their controls hide by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9541
* fix(web): thread error banner no longer shifts the chat by @flamboh in https://github.com/pingdotgg/t3code/pull/9473
* fix(server): reveal normalized paths in File Explorer by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9551
* feat(marketing): fresh screenshot and floating marks on the homepage by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9547
* feat(usage): redeem Codex reset credits from the Limits tab by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9534
* fix(server): find newly opened pull requests after agent turns by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9125
* ci: add on-demand Windows test workflow by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9538
* fix(web): simplify expanded tool details by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9549
* fix(web): keep the last message visible when the resting composer expands by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9553
* test(web): fix flaky startup and Tailwind tests by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9558
* fix(web): keep codex restart responses continuous by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9560
* fix(web): make settings sidebar sub-section buttons full width by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9562
* fix(web): render settings sidebar immediately by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9563
* chore: vouch august contributors by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9557
* fix(web): stabilize right panel transitions by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9554
* fix: better shell syntax handling for labels by @Yash-Singh1 in https://github.com/pingdotgg/t3code/pull/9371
* fix(web): align the sidebar wordmark by baseline by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9578
* fix(antigravity): keep subagent batches active after launch by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9579
* fix(mobile): render workspace images in markdown file previews by @SunkenInTime in https://github.com/pingdotgg/t3code/pull/8769
* fix(usage): deduplicate CLI proxy subscription accounts by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9584
* fix(web): bound disconnected send toasts by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9592
* fix(desktop): restore panel titlebar interactions by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9591
* fix(connect): refresh authorization without disconnecting by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9582
* fix(web): show context meter in compact composer by @GuilhermeVieiraDev in https://github.com/pingdotgg/t3code/pull/9430
* fix(pull-requests): refresh data after thread turns by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9496
* fix(web): render draft PRs in gray by @extoci in https://github.com/pingdotgg/t3code/pull/9537
* refactor(web): move usage provider controls to settings by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9599
* fix: show idle subagent batches without completion marks by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9616
* fix(web): group image views like other tool calls by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9597
* fix: preserve tool icons on failed calls by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9606
* fix(connect): diagnose incomplete headless server setup by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9602
* fix(web): keep command palette above composer menus by @Gigioxx in https://github.com/pingdotgg/t3code/pull/9613
* fix(web): snooze menu no longer overlaps thread details by @RakshithBhat03 in https://github.com/pingdotgg/t3code/pull/9601
* fix(web): match composer pull request state icons by @flamboh in https://github.com/pingdotgg/t3code/pull/9375
* fix(server): load OpenCode workspace skills via SDK to avoid 64KB CLI pipe truncation by @BarryHenryJr in https://github.com/pingdotgg/t3code/pull/9585
* fix(web): mute sidebar branch name to match worktree icon by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9622
* fix(web,mobile): fold context compaction under settled turn folds by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9623
* feat(mobile): make chat text selectable on Android by @SunkenInTime in https://github.com/pingdotgg/t3code/pull/8779
* fix(web): toggle a single stashed prompt with Cmd+S by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9644
* fix(server): prevent duplicate desktop clients after restart by @seeb1337 in https://github.com/pingdotgg/t3code/pull/6305
* fix(web): resume Antigravity threads without repeated sign-in by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9647
* feat(mobile): paste the phone clipboard into the terminal by @lnieuwenhuis in https://github.com/pingdotgg/t3code/pull/9199
* feat(web): show which sidebar threads hold an unsent draft by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9658
* fix(server): unblock OpenCode approvals and stop by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9653
* fix(desktop): quit immediately on a second shortcut press by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9657
* fix(server): update Claude Agent SDK to 0.3.260 by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9135
* perf(server): stop loading message bodies for thread summaries by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9662
* perf(web): speed up terminal snapshots by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9663
* fix(web): show machine icons in the environment picker by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9668
* perf(mobile): bound diff syntax highlighting work by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9673
* perf(web): keep Markdown mounted during streaming by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9677
* perf(mobile): skip unused legacy list work by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9679
* perf(marketing): serve images at their display size by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9682
* perf(server): cache and stream static web assets by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9669
* perf(server): batch projector cursor writes by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9671
* perf(server): stop retaining unused OpenCode tool history by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9684
* perf(mobile): reuse chat feed rows during streaming by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9688
* perf(server): omit repeated OpenCode progress logs by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9689
* perf(clients): avoid waiting to read cached relay tokens by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9691
* perf(mobile): reuse diff rows during comment edits by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9693
* perf(web): defer composer draft serialization by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9695
* feat(server): measure provider turn token usage by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9132
* perf(marketing): stop continuous homepage motion by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9697
* perf(server): avoid full patches for checkpoint summaries by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9694
* perf(web): defer diff workers until a code view opens by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9692
* perf(marketing): serve website fonts locally by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9701
* perf(server): stop rebuilding terminal history per chunk by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9703
* perf(server): use one query for buffered provider events by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9706
* perf(relay): avoid repeated activity decoding by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9708
* perf(web): stop continuous chat status animations by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9709
* fix(mobile): preserve saved work after storage read failures by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9710
* perf(web): stop replaying terminal buffers on rollover by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9707
* feat(web): preview pull request links by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9631
* perf(client): reduce thread-list update work by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9716
* fix(server): settle inactive threads with open PRs by @Gigioxx in https://github.com/pingdotgg/t3code/pull/9610
* fix(server): bound slow-client event buffers by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9715
* test(server): allow either valid file-search match by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9720
* fix(web): match provider settings layout for disconnected devices by @flamboh in https://github.com/pingdotgg/t3code/pull/9619
* fix(web): keep the slash menu above the composer when vertical space is short by @Mnigos in https://github.com/pingdotgg/t3code/pull/9625
* fix(mobile): remove provider setup by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9721
* perf(web): stop rendering hidden terminals by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9718
* fix(mobile): read file-backed image drafts before enabling them by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9713
* perf(server): replay only the selected thread by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9726
* fix(web): mute composer helper text by @jakeleventhal in https://github.com/pingdotgg/t3code/pull/9654
* feat(web): unpin threads from the sidebar multi-select menu by @gsimone in https://github.com/pingdotgg/t3code/pull/9651
* perf(web): reuse timeline rows while text streams by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9725
* fix(relay): bound stalled push requests by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9734
* perf(server): stop caching unused OpenCode tool parts by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9738
* fix(web): fold single trailing activity by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9739
* fix(web): show project settings for new threads by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9743
* perf(mobile): bound the parsed review cache by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9749
* perf(web): avoid repeated terminal metadata scans by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9747
* perf(server): bound terminal history by bytes by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9748
* feat(web): link pull request authors to profiles by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9627
* fix(web): refine server update notice by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9744
* perf(client): stop thread streams when unused by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9740
* perf(mobile): defer file preview highlighter startup by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9752
* perf(server): skip history reads for metadata commands by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9758
* perf(web): defer image URL requests for thread history by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9760
* fix(models): make GPT-6-Astra current by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9762
* fix(web): stop empty diffs replacing pull requests by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9753
* fix(sidebar): mute background working threads by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9759
* fix(web): reset automatic pull to default by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9763
* fix(web): restore file comment focus in editable preview by @ShpetimA in https://github.com/pingdotgg/t3code/pull/9061
* docs: keep internal guides focused on architecture by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9755
* docs: focus user guides on features and workflows by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9756
* fix(web): stop panel motion during navigation by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9766
* fix(web): open composer selectors below controls by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9767
* perf(server): skip unused Linux process detail reads by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9768
* fix(server): remove retired Codex models after refresh by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9773
* test: stop path and platform tests depending on the host OS by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9564
* test(server): skip posix executable fixtures on a Windows host by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9565
* test: skip symlink fixtures where the host cannot create symlinks by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9566
* test(server): run fake provider CLIs through a Node stub on every host by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9567
* test(desktop): make path fixtures and timeouts host-portable by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9568
* fix(server): tolerate the missing directory fsync on Windows by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9569
* test(server): pin git config for fixtures and compare native realpaths by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9570
* test: skip POSIX mode-bit assertions on a Windows host by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9571
* test(server): keep provider fixture directories host-portable by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9572
* test: resolve the Windows temp directory to its long name by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9573
* test(server): run the Antigravity install harness for the host platform by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9574
* fix(server): canonicalise media paths the same way their callers do by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9575
* test(server): make Windows path and async fixtures deterministic by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9576
* fix(server): refuse symlinked theme files on Windows too by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9580
* test(scripts): keep Windows packaging checks host-portable by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9589
* fix(contracts): include tool.denied in runtime event types by @Lucenx9 in https://github.com/pingdotgg/t3code/pull/9770
* feat(mobile): split the usage page into Usage and Limits tabs by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9775
* fix(web): restore the running tool label shine by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9777
* fix(web): align provider controls with machine tabs by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9769
* docs(web): document panel motion during navigation by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9778
* feat(usage): support custom model prices by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9774
* fix(web): center pull request link previews by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9794
* fix: address usage limits and merge settlement regressions by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9784
* fix(web): give toggle thumbs consistent inset spacing by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9805
* fix(web): use segmented controls for mode switches by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9781
* fix(server): recover opted-in threads after machine restarts by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9803
* fix(web): simplify changed files into a persistent folder tree by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9821
* feat: add custom model names and option descriptors by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9807
* fix(cursor): discover symlinked skills as package boundaries by @EzraBuild in https://github.com/pingdotgg/t3code/pull/9420
* fix(ssh): exec managed servers without npm wrappers by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9843
* fix(server): detect nested Git workspaces for checkpoints by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9842
* fix(web): keep worktree origin preference visible by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9846
* fix(web): smooth settings sidebar transitions by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9811
* feat(web): highlight visible settings sections by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9812
* fix(web): keep the sidebar project filter across navigation by @Mnigos in https://github.com/pingdotgg/t3code/pull/9416
* fix(server): surface Claude safety model fallback notices instead of dropping them by @darahaas15 in https://github.com/pingdotgg/t3code/pull/8853
* fix(web): reload saved colors when reopening the theme editor by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9847
* feat(desktop): import cookies from Safari by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/7262
* fix(web): respect case in POSIX file links by @Michel-Liao in https://github.com/pingdotgg/t3code/pull/9309
* fix(server): surface a missing workspace folder instead of a spawn error by @kakismash in https://github.com/pingdotgg/t3code/pull/5040
* fix: stop favicon requests for private link hosts on web and mobile by @fe-franco in https://github.com/pingdotgg/t3code/pull/5838
* fix(server): preserve native provider executable paths during updates by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9850
* fix(web): restore composer expansion after tool calls by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9782
* fix(client): explain possible network blocking for T3 Connect by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9783
* fix(desktop): isolate preview keyboard shortcuts from the host by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9840
* fix(prs): reuse GitHub data and defer optional reads by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9835
* perf(shared): skip duplicate PATH entries and per-probe tracing by @jadeva in https://github.com/pingdotgg/t3code/pull/9618
* fix(web): preserve focus and prioritize picker shortcuts by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9795
* fix(skills): support names beginning with digits by @amiralibg in https://github.com/pingdotgg/t3code/pull/9244
* fix(server): advertise truecolor in the integrated terminal by @shubhxho in https://github.com/pingdotgg/t3code/pull/7680
* fix(claude): surface usage-limit pauses in the thread by @vitalyiegorov in https://github.com/pingdotgg/t3code/pull/7165
* fix: restore UX after performance improvements by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9799
* fix(codex): show what a file-change approval will change by @walid-baharwal in https://github.com/pingdotgg/t3code/pull/8669
* fix(ci): add fallback Ubuntu package mirrors by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9864
* fix(web): copy text over plain HTTP by @Michel-Liao in https://github.com/pingdotgg/t3code/pull/8023
* fix(server): dismiss native questions when their turn ends by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9851
* fix(server): quote copied native provider update commands by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9856
* fix(release): install the correct Windows Spectre component by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9859
* fix(web): show retained runtime diagnostics in the work log by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9870
* fix(web): make sidebar project actions reachable by keyboard and screen reader by @akj in https://github.com/pingdotgg/t3code/pull/5521
* fix(preview): bound automation waits and screenshot captures by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/4685
* fix(web): render and filter usage as environments respond by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9860
* feat(web): edit usage prices across selected environments by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9861
* fix(mobile): keep usage tabs below the header when switching by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9876
* fix(connect): refresh HTTP credentials without reconnecting by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9594
* fix(web): keep file autosaves active after effect replay by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9878
* fix(web): prioritize open panel pull request when copying by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9877
* fix(cli): resolve projects with missing workspace directories by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9885
* fix(web): sort equally merge-ready pull requests by diff size by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9887
* fix(chat): show hours for long runs by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9894
* fix(server): only run provider updates through the installer that owns the binary by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9325
* fix(web): discard stale highlights after file edits by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9902
* feat(web): recall sent prompts with the up arrow by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9173
* fix(server): keep mise-owned npm packages manual-only by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9927
* fix(settings): share restart continuation across environments by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9933
* fix(server): capture turn checkpoints after all edits finish by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9841
* fix(web): load file grammar before enabling edits by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9947
* fix(web): deduplicate PR project filter choices by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9948
* test(web): keep provider field readers private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9952
* test(mobile): keep composer selection helper private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9953
* test(client-runtime): keep scoped key implementation private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9955
* fix(web): reveal reselected diff files by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9951
* refactor(web): remove obsolete changed-files preview helpers by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9956
* fix(web): give the browser keybinding notice breathing room by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9964
* chore: configure Knip workspace audits by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9958
* refactor(web): prune unused UI and provider code by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9959
* chore(mobile): remove obsolete widget wiring script by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9960
* chore: remove redundant root tooling dependencies by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9961
* ci: reject unused files and dependencies with Knip by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9962
* test(contracts): keep driver default lookup private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9968
* test(server): remove Azure permissions constant snapshot by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9973
* refactor(shared): remove unused viewport formatters by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9970
* refactor(mobile): remove unused provider option summary by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9971
* refactor(client-runtime): remove unused connection phase message by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9972
* refactor(mobile): remove unused layout calculations by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9974
* refactor(client-runtime): remove unused file position predicate by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9976
* refactor(mobile): remove unused font size steppers by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9975
* test(server): cover thread lookup through command invariants by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9978
* test(server): remove provider equality wrapper fixture by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9979
* test(server): assert the dispatched welcome thread model by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9980
* refactor(desktop): remove unused keyring remediation text by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9981
* refactor(desktop): remove test-only Electron error predicates by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9982
* refactor(web): remove unused pull request state label by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9984
* perf(web): keep timeline row reuse engaged while text streams by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9909
* fix(web): reset markdown widgets when the previewed file changes by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9910
* fix(mobile): keep highlighting review diffs after a long line by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9911
* fix(marketing): align the endorsement carousel with its heading by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9912
* fix(client): keep warm thread resumes live instead of flashing sync by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9913
* test(server): remove authorization prompt snapshots by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9985
* test(server): remove static OAuth page snapshots by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9986
* test(server): remove provider label identity assertion by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9987
* test(server): consolidate agent activity opt-in coverage by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9988
* refactor(shared): remove unused preview URL predicate by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9989
* refactor(shared): remove unused mention path serializer by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9990
* refactor(shared): remove retired PATH capture parser by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9991
* refactor(client-runtime): remove unused subagent selectors by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9992
* refactor(web): test the live usage column builder by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9993
* refactor(web): remove unused aspect ratio reconciler by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9994
* refactor(web): remove obsolete cloud listing helpers by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9995
* test(web): remove composer control style snapshots by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9996
* test(web): keep the preview profile label helper private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9997
* test(server): cover raw OpenCode deltas through the adapter by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9977
* refactor(web): remove obsolete pull request link opener by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9983
* test(relay): keep the stage slug helper private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9998
* refactor(mobile): keep project selection helper private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9999
* refactor(mobile): keep review default ID helper private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10000
* refactor(mobile): remove unused native style constants by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10001
* refactor(mobile): test terminal palettes through public theme API by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10002
* refactor(mobile): remove unused file tree walkers by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10003
* refactor(shared): keep persisted settings helpers private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10004
* test(mobile): remove mocked UUID shape assertions by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10006
* refactor(mobile): test final connection status presentation by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10007
* test(web): keep pull request menu items private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10016
* refactor(shared): test favicon selection through public API by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10005
* refactor(server): remove test-only pricing normalizer by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10017
* refactor(web): remove unused desktop update visibility helper by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10014
* refactor(web): remove obsolete provider update helpers by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10015
* refactor(web): remove unused terminal context preview formatter by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10009
* refactor(web): test environment-scoped draft promotion by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10010
* fix(web): retain wrapped row heights during edits by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10018
* refactor(shared): remove unused Clerk hostname predicate by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10008
* refactor(tailscale): keep package internals private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10011
* ci: reject unused tailscale exports with Knip by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10012
* fix(web): keep chat media at a stable size while it loads by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/9938
* refactor(server): keep manifest age parsing private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10028
* refactor(mobile): remove unused awareness relay URL normalizer by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10029
* refactor(server): remove unused startup heartbeat launcher by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10030
* refactor(shared): keep search ranking comparator private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10031
* refactor(server): keep telemetry identity errors private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10032
* refactor(mobile): test composer persistence through the live decoder by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10033
* refactor(web): remove unused sidebar selectors by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10034
* refactor(server): keep Cursor fallback models private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10038
* refactor(web): remove unused xterm link range helpers by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10040
* refactor(mobile): remove obsolete review list builder by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10039
* test(server): remove duplicate VCS error constructor checks by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10042
* refactor(mobile): keep appearance calculations private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10043
* refactor(web): remove unused sidebar menu action by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10044
* refactor(web): test live Ghostty link resolution directly by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10041
* test(server): exercise Codex prompts through public assembly by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10045
* refactor(shared): remove unused elapsed-time adapter by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10046
* refactor(web): remove unused preview thread reset helper by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10049
* refactor(desktop): remove test-only error predicates by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10047
* refactor(mobile): keep review reset hashing private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10048
* test(web): remove AppRoot element order snapshot by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10052
* refactor(codex): keep app-server client internals private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10035
* ci: reject unused Codex client exports with Knip by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10036
* refactor(server): simplify native telemetry error internals by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10057
* refactor(mobile): remove write-only terminal font cache by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10058
* refactor(web): remove obsolete HSL theme generator by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10061
* refactor(mobile): remove obsolete native diff token stream by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10062
* test(server): remove title prompt editorial snapshots by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10063
* test(server): remove repeated runtime prompt interpolation cases by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10059
* refactor(web): observe preview tests through the live registry by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10064
* test(server): remove keybinding default assignment snapshot by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10065
* refactor(mobile): remove obsolete whole-file review highlighters by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10067
* test(server): cover CLI runner detection through command suggestions by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10066
* refactor(mobile): remove unused cloud relay URL normalizer by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10068
* refactor(web): test live keybinding resolvers directly by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10069
* test(server): cover Grok skill parsing through discovery by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10070
* test(web): remove mocked diff view prop snapshot by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10073
* test(web): remove mocked annotation options snapshot by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10074
* refactor(web): keep pending action labels private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10075
* refactor(mobile): remove unused cloud pending-status mapper by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10071
* refactor(web): remove unused model picker hint helpers by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10072
* fix(server): resume checkpointing after git init by @Yash-Singh1 in https://github.com/pingdotgg/t3code/pull/10078
* feat(web): first-run welcome wizard with agent setup and project import by @t3dotgg in https://github.com/pingdotgg/t3code/pull/5362
* fix(server): keep Homebrew mise shims manual-only by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10085
* fix(ssh): report remote package installation failures accurately by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10088
* fix(web): keep bulk thread deletion going after failures by @m-de-graaff in https://github.com/pingdotgg/t3code/pull/4615
* fix(web): scale agent spawn rows with interface font by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10092
* fix(web): prevent sidebar tooltip title clipping by @UtkarshUsername in https://github.com/pingdotgg/t3code/pull/10086
* fix(web): keep the composer expanded until the thread can scroll by @t3dotgg in https://github.com/pingdotgg/t3code/pull/9965
* fix(web): preserve original mention text in the composer by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10100
* refactor(mobile): remove unused pairing redaction wrapper by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10147
* test(web): drop provider banner styling assertions by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10148
* refactor(client-runtime): remove unused relay token waiter by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10151
* test(web): drop sidebar artwork styling snapshots by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10152
* refactor(ssh): keep package internals private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10144
* ci: reject unused SSH exports with Knip by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10145
* refactor(acp): keep protocol implementation exports private by @juliusmarminge in https://github.com/pingdotgg/t3code/pull/10165
* fix(shared): validate cloudflared with the version subcommand by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9880
* fix(desktop): separate LAN and Tailscale pairing endpoints by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9882
* fix(server): install pinned runtime when pnpm node lacks npm by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9923
* fix(web): hide sidebar search shortcut on mobile by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9932
* fix(web): align tool disclosure chevrons with expanded state by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9935
* fix(antigravity): distinguish session initialization auth failures by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9919
* fix(cursor): cache successful model discovery between refreshes by @maria-rcks in https://github.com/pingdotgg/t3code/pull/9918
* fix(opencode): revert from the first removed assistant message by @maria-rcks in https://github.com/pingdotgg/t3code/pull/…
juliusmarminge added a commit that referenced this pull request Sep 17, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 18, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 18, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 18, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 18, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 18, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Absterrg0 added a commit to Absterrg0/jarvis that referenced this pull request Sep 18, 2026
* fix(web): keep queued message editing inside the queue panel

* fix(web): keep queued messages in place while editing

* fix(web): match composer actions to draft and modifier state

* fix(web): keep composer shortcut tooltip stable on Mod

* feat(web): summarize T3 orchestration actions

* feat(mobile): port chat summaries and transitions to orchestration v2

Adapt grouped tool summaries and the floating working timer to V2 run, attempt, and queue state. Bring over the composer, keyboard, and disclosure transitions while retaining the V2 activity inspector and queue controls.

Keep OV2 web composer and grouping behavior intact; share only the existing command label parser with mobile.

* fix(chat): remove added tool summary status counts

* fix(mobile): keep scroll bounds current after animations

* fix: reconcile main's round-17 features after the rebase

Restores main features dropped by the policy replay: #8569 theme wiring,
settings search rework, #8803 workspace-mutation refresh (v2-adapted),
video + image previews (web and mobile, v2-adapted), #8862 Expo glass,
and the round's docs. Timeline thinking rows (#8984) stay on the v2
work-live system.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(web): port working and thinking timeline rows to orchestration v2

The v2 equivalents of main's #8984 and #8922: a "Working for ..." header
anchors the active run, the trailing live tool row survives between
actions in past tense instead of vanishing, and a shimmering Thinking
row marks reasoning gaps. During workspace preparation the header shows
"Setting up worktree..." (driven by the local dispatch flag or the v2
run's preparing status, so remote viewers see it too), the composer
footer span is gone, and draft promotion waits until the run starts or
startup fails instead of navigating mid-preparation.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: reconcile main's round-18 features after the rebase

Adopts the round's main features into the v2 architecture: the #9023
media rework (streamed videos, media-file assets, protocol-relative
links), #9098 shared live-activity row folded into the v2 working and
thinking rows, the #9084/#9078 Claude model catalog for v2 consumers,
a native #9005 OpenCode child-session abort in the v2 adapter, #9013's
landed LegendList patch, and per-environment sidebar provider entries.
For #8600 the server-side pieces land, but auto-settle evaluation stays
client-side (reading the new server-owned settings) until the v2
orchestrator grows its own settlement reactor; main's v1-only reactor
and coalescer additions are dropped with the rest of the v1 path.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(server): evaluate automatic thread settlement in the v2 orchestrator

Ports #8600's server-owned settlement to orchestration v2 instead of
keeping client-side evaluation. A ThreadSettlementService sweep runs at
startup, on auto-settle settings changes, and once per minute: it
evaluates inactivity and merged or closed pull requests over v2 thread
shells and dispatches the new guarded thread.auto-settle command, which
rejects threads that changed after the sweep's snapshot or carry any
explicit override, then reuses the orchestrator's settle lifecycle.
With the server deciding, the clients drop their effectiveSettled
evaluation and partition on the persisted settledOverride like main.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: reconcile main's round-19 features after the rebase

Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): right-align the stash shoulder tab again

Round 17 adopted main's #8850 ComposerBanner.Attachment (mx-auto plus the
standalone drawer-inset width) without main's matching mounts, so the
stash tab's ml-auto lost to the attachment's auto right margin and the
tab centered over the composer. Column now spans its attachments like
main does, the stash tab zeroes the right margin, and the stash menu
keeps the full dock width.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): realign the composer and timeline with main

The branch had drifted from main's composer and work-log design in ways
unrelated to orchestration v2: a pre-revert "Working for" shoulder tab
on the composer (main reverted #8693 and re-landed #8734 without it),
an inline stash variant plus in-flow stash menu, expanded tool rows that
hid their icons, an unmounted woke-thread banner, a composer scroll
observer main never had, and a right-panel toggle that lost its
showRightPanelControl gate so it rendered twice with the panel open.

ChatComposer and its satellites now start from main's files with only
the v2 delta re-applied (dispatch modes, queued-message editing, runtime
request ids, response capability). Background tasks surface as a
ChatView banner in main's backgroundLiveness shape instead of a
composer tab. SimpleWorkEntryRow takes main's PlainWorkEntryRow body
with the V2ItemInspector kept behind the expander.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: reconcile main's round-20 features after the rebase

Renumbers the v2 migrations 044-052 to 045-053 behind main's
044_ClearAutomaticProjectModelDefaults, and adopts main's sticky
new-thread selection (#9164), local-only worktree bases in the v2 launch
path (#8751), the PR summary read for settlement (#9176), Claude per-cwd
skills (#9210), the provider editor redesign with the branch's dedicated
environment fields re-grafted (#8508), and the client half of
continue-threads-across-restart (#9167). The server-side continuation
markers stay unported: they live in the v1 session directory, and v2
recovery terminalizes running runs on restart, so the capability is
withheld until the v2 runtime carries them.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(server): reduce v2 recovery and runtime resource usage

Index event sequence lookups, recover only threads with pending work, and page projection verification and rebuilds. Bound provider event logging and omit turn histories when resuming Codex threads.

Allow delegated thread identifiers through relay routes. Add focused regression coverage and document the performance constraints.

* fix: reconcile main updates with orchestration v2

Retain main's composer, work-log, settings, mobile and performance changes through c8f77e0d441 while preserving v2 runs, queued messages, provider handoffs and durable history.

Port native compaction and logout, asynchronous Codex questions, provider usage accounting, automatic settlement and PR refresh into the v2 services. Bound live event retention during replay and delivery, measure thread replay before decoding, and read checkpoint metadata without loading transcripts or patches.

Keep main migrations through 047 and move the v2 migrations to 048–058. Preserve the existing branch history and the pre-rebase backup.

Model: GPT-6. Harness: Codex.

* fix(orchestration): stabilize Codex turn mapping and settlement

- Preserve Codex turn identity while suppressing duplicate diff notifications
- Optimize settlement projections and isolate thread visit handling
- Add concurrency and regression coverage across server and mobile

* fix(chat): match main timer and task placement

Restore the completed work timer divider and text size from main. Keep todo-list progress in the composer and omit it from web and mobile timeline entries, including completed task lists.

Verified pending, running, and completed task projection; 187 focused web tests and 35 mobile tests pass. Web and mobile typechecks pass.

* fix(mobile): restore composer and timeline behavior from main

Show Send when a running thread has draft content. Separate submission follow
from first-message anchoring so later sends do not reserve extra blank space.
Restore Android initial composer insets and iOS focus-aware dictation insets.

Keep opening and final assistant replies visible around completed folds,
anchoring Worked for at the first hidden item while preserving v2 relationship
cards and execution-attempt behavior.

Validation: 107 focused tests and the mobile typecheck pass. Formatting passes;
scoped lint and React Doctor report warnings but no errors. No simulator run.

* fix(orchestrator): Stop treating a wait timeout as a dead child (#7427)

* fix(orchestrator): Show when a completed delegated child still has work (#4793)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(orchestrator): Stop finished Codex turns from sitting on Waiting (#7105)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* chore: format v2 files flagged by CI

* test(server): include the shell indexes migration

* fix(mobile): pin the patched notifications dependency

* fix(client-runtime): resolve work log source imports

* test(server): refresh replay runtime instruction expectations

* test(server): correlate OpenCode replay message identities

* ci: run checks on v2 branch pushes

* test(server): use Effect Vitest for Cursor provider checks

* fix: reconcile main updates with orchestration v2

Retain main's changes while preserving v2 orchestration, queue/steer controls,
composer-only tasks, timeline timers, and mobile scrolling fixes.

Port opt-in restart continuation through durable v2 effects, with shutdown
race guards, activation gating, retry deduplication, and native Codex resume.
Use narrow projection reads for control effects and runtime-request replies.
Surface Claude fallback notices without failing the turn or hiding the notice.
Report missing workspace folders before provider startup.

Carry over custom models and prices, bounded client caches and stream cleanup,
lazy image loading, persistent changed-file trees and sidebar filters, Safari
cookie import, theme fixes, POSIX file-link case, private-host favicon filtering,
native provider update paths, and platform portability updates.
Migration ids remain unchanged.

Validated scoped typechecks and focused server, web, mobile, client-runtime,
contracts, desktop, shared, SSH, script, and resource-monitor tests. Preserved
all 347 original commits and checked the final tree against both saved tips.

Model: GPT-6. Harness: Codex.

* fix(server): explain fetch failures during worktree preparation

Worktree preparation previously exposed only a generic fetch failure. Classify
known authentication, network, repository access, and reference-lock errors
using stable Git diagnostics, without retaining raw output or credentials.
Unknown failures keep the existing generic message.

Cover failure classification and redaction, a real missing local remote, and
propagation into a failed prepared run without creating a worktree or running
setup. The launch test waits for the persisted failure event.

Validation: 38 focused tests, server typecheck, and scoped lint passed.

* fix: reconcile upstream fixes with orchestration v2

Carry main's session refresh, provider maintenance, runtime diagnostics,
composer focus, preview, usage, and mobile outbox fixes into the v2 branch.
Keep queue/steer submission, composer-only task progress, v2 subagent cards,
and LegendList scroll ownership.

Project thread and shell events before transport buffering while retaining
full durable history. Dismiss native questions when provider turns finish,
with a transaction guard that preserves answers submitted concurrently.
Port Claude limit notices and Codex file approval details to v2 adapters.

Validated with focused server, web, mobile, client-runtime, shared, desktop,
and marketing tests; affected package typechecks and scoped lint pass.
All 349 branch commits retain their authors and messages. Migration files
and the previous worktree-fetch, stash, panel, and mobile inset fixes remain
unchanged.

* fix(server): make project removal honor v2 threads

Offline CLI and HTTP project removal dropped force and left native v2 threads
behind. Move the nonempty-project guard and durable child cleanup into the
shared project service, and forward force from CLI, HTTP, and WebSocket calls.

Reuse the thread deletion planner and command lock, hydrate migrated history
before attachment cleanup, and validate child receipts. Commit the project
deletion after its children so failed cleanup can be retried safely.

Validation covers CLI deletion with active and archived threads, missing
workspaces, durable cleanup, partial retries, migrated attachments, receipt
collisions, and concurrent thread updates. Scoped server tests, typecheck, and
lint pass.

Implemented with Codex (GPT-6).

* fix(mobile): render generic message attachments (#9929)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>

* fix(mobile): use the archive eligibility guard when dispatching (#9930)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>

* fix(orchestration): persist linked pull requests (#8689)

* feat(mcp): update thread metadata (#8690)

* fix(server): keep old failures from waking snoozed V2 threads (#9903)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* refactor(shared): share model-selection command choice (#10577)

* refactor(project): share create and update inputs (#10578)

* refactor(server): share attachment message intake (#10580)

* feat(mcp): expose thread organization commands (#10554)

* feat(mcp): expose existing queued message commands (#10555)

* feat(mcp): expose pending user questions (#10556)

* feat(mcp): expose thread model selection (#10557)

* feat(mcp): expose fork and merge-back commands (#10558)

* feat(mcp): expose preview list and close (#10559)

* feat(mcp): expose selected environment preferences (#10560)

* feat(mcp): expose the existing thread search query (#10561)

* feat(mcp): expose scheduled task run-now (#10562)

* feat(mcp): expose project service operations (#10563)

* feat(mcp): expose attachment upload and send (#10564)

* feat(mcp): expose project thread launch service (#10565)

* feat(mcp): expose branch-backed workspace discovery (#10566)

* fix(orchestration): map late steering to follow-up turns

- Re-route steering that races completion into idempotent follow-up dispatches
- Preserve scheduled-task attribution and provider ownership history across clients

* fix: reconcile main's round-24 features after the rebase

Port main's pull-request discovery, active thread ordering, async question dismissal, settlement fixes, provider-session import, attachment context, and provider correctness changes into orchestration v2.

Keep the branch's intentional composer and subagent behavior while adopting main's web and mobile fixes. Prevent headless setup terminals from hanging on the color probe, and move the v2 migration block to 050-061 after main claimed 048-049.

* chore: remove accidentally committed audit artifacts

* fix(ci): repair rebased checks and stop duplicate runs

Restore the failed-before-start timer guard, align two server fixtures with the reconciled behavior, and remove dead files, exports, and dependencies surfaced by Knip.

Drop the temporary branch push trigger now that the PR is mergeable, so each update runs the pull-request workflow once.

* fix(web): port auto-balance updates to v2 chat

Keep main's batch machine-update banner and update action while preserving the v2 runtime-based environment lock used by draft load balancing.

* chore: format files exposed by CI

* fix: reconcile main's round-26 updates after rebase

Adopt TypeScript 7 and Effect rc.112 across orchestration v2, including the TaggedError API migration and updated Effect-aware tests. Restore main's composer-aware scroll-to-end clearance while retaining selected-model settings sync, preview recording transfer, image galleries, desktop context menus, and layout hit targets. Regenerate the lockfile on the upgraded dependency baseline.

* fix(web): restore compact load-earlier control

* perf(orchestration): bound v2 transport payloads

Advertise bounded socket snapshots and authoritative dispatch validation, omit raw command output and inline file bodies at the wire boundary, and preserve compact status metadata across web and mobile. Add transport-budget coverage for snapshots, resume, commands, legacy import, and projection maintenance.

* fix(web): preserve tool failures after output redaction

* fix: restore sidebar behavior after v2 rebases

Restore pinned-thread shelf classification, server-owned unread state, hidden-subagent-safe project ordering, guarded jump hints, draft upload cleanup, and active-provider archive guards across the current and legacy sidebars.

Bring the surrounding current-main sidebar work forward as well: canonical project favicons, stable row layout, thread file drops, account-aware mobile provider badges, and deferred desktop keyring loading.

* fix(server): consolidate V2 migrations and refine runtime recovery

* fix(web): simplify timeline rows and preserve collapsed composer controls

* fix(web): smooth composer transitions and group approval worklogs

Keep collapsed model controls in a strip, contain transition overflow, and preserve timeline spacing. Render approval requests as regular grouped worklog entries.

Implemented with GPT-6-Astra via Codex.

* fix: reconcile main updates with orchestration v2

Adapt question attachments and Android push verification to V2 requests and shell events. Preserve composer transitions and compact worklogs while integrating upstream loading, navigation, and mobile changes. Release consumed application replay pages without retaining earlier batches.

* fix(server): report OpenCode descendant stop failures

* fix(server): abort external OpenCode sessions on release

* fix(server): retain thread baseline diffs across root runs

* fix(server): fail OpenCode turns on unexpected stream EOF

* fix(server): bound OpenCode runtime request replies

* fix(client): bound socket resets after cold HTTP failures

* fix(server): query only due scheduled tasks during polling

* fix(server): retain normalized OpenCode turn usage

Accumulate owned step usage once and preserve partial or unavailable telemetry for failed, interrupted, or reconnected turns.

* perf(server): scope ordinary control reads to their targets

* fix(server): retry initial title generation after transient failures

* fix(server): isolate Cursor metadata generation from workspaces

* fix(server): preserve Claude Read image previews across clients

* fix(web): preserve generic files when editing queued messages

* test(server): assert tool output redaction before storage fidelity

* test(web): cancel queued animation frames during worker cleanup (#10880)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix: reconcile main devices and pull requests with orchestration v2

* feat(providers): add Pi coding agent (#7211)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Mike Olson <mwolson@member.fsf.org>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* feat(providers): standardize ACP providers (#6461)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* feat: render background completions as typed notifications

* fix(mcp): omit recursive screenshot metadata from tool inputs

* fix(pi): use native forks and preserve rollback session identity

* fix(pi): cap OpenRouter output budgets pending upstream fix

* fix(web): show ACP sidebar icons and hold onboarding height while loading

* feat(server): deliver delegated completions through a durable mailbox

* fix(acp): support Devin terminals, questions, and native subagents

* fix(server): find active turns when answering async questions

* fix(web): populate sidebar ACP branding from environment settings

* fix(acp): preserve native child messages and final summaries

* fix(server): distinguish delegated task results from completed turns

* test(server): align Codex delegation instruction assertion

* test(server): align delegation fixtures with task result semantics

* fix(server): classify Claude V2 structured terminal failures (#9897)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(orchestration): exclude rolled-back work from bounded recovery (#8464)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* test(orchestration): cover bounded V2 socket fallback paging (#9907)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(server): wait for native Codex start before Stop (#10024)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(server): keep the native Grok default model (#10025)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(server): fail V2 turns when the OpenCode event stream ends (#9905)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(web): preserve file attachments when editing queued runs (#9928)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(server): preserve project mutation fields across transports (#9920)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(mobile): throttle streaming thread visit updates (#9931)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(orchestrator): preserve task-step elapsed time across restart (#10051)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(server): preserve Claude interruption status during steering

* fix(server): wait for nested completion delivery before publishing results

* test(server): verify background delivery with real providers

* fix: keep working timers anchored to the active run

* perf: page complete turns and bound timeline reconciliation

* perf(client): narrow thread subscriptions and navigation updates

* feat(mobile): manage queued messages in a dedicated sheet

* fix(web): fold completed trailing background activity

* fix: reconcile main settings and previews with orchestration v2

* perf(client): reconcile replay batching with orchestration v2

* fix: reconcile main Codex model selection and UI updates

* fix: reconcile main context previews and rewind updates

* fix(build): include protobuf and Connect license notices

* fix(mobile): pin expo-audio so the release smoke patch stays in use (#11518)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix: reconcile main release and thread updates with V2

* fix: repair v2 CI after environment disable and dead exports

ConnectionCatalogEntry gained a required enabled flag in #11478, but the
threadShell harness never set it, so enabled-gated atoms filtered every
environment out and two tests failed. Two dead exports also tripped knip.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(web): update notification tests for v2 thread shells and drop dead composer state

ThreadNotificationCoordinator presents raw OrchestrationV2ThreadShell
records, but its tests still fed the pre-v2 thread shape (session /
latestTurn), which crashed presentThreadShell on missing DateTime fields.
Rebuild the fixtures as v2 shells with pendingRuntimeRequest and run
statuses, and remove the composerHasUnsentContent binding left unused by
the compaction gating change.

* fix(client-runtime): avoid Array#toSorted in thread lineage ordering

* fix(server): reject partial output from failed Cursor runs (#11534)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): wake paused Cursor replay runs on mismatch (#11535)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): load V2 replay fixtures through the platform path service (#11566)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): report missing interrupt-and-restart capability for forced restarts (#11565)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): preserve Cursor directory and lint search results (#11533)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): roll back question attachment copies when respond preparation fails (#11557)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): restart the live session on model changes after dead records (#11505)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): replay launches with server-allocated thread IDs (#11508)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(web): keep the active-run header with the prompt that started it on steer (#11828)

* refactor(web): centralize provider instance icons (#11829)

* feat(web): add the thread action menu and inline rename to the chat header (#11830)

* fix(web): keep the preview mini-player clear of the inline thread details card (#11831)

* fix: reconcile main snooze controls with orchestration v2

* fix(web): adapt registry icons to light and dark themes

* fix: reconcile main worktree setup and title changes with v2

* fix(server): isolate V2 migrations from the V1 database

* fix(ci): verify V2 branch pushes and remove unused helper

* revert: restore existing CI push triggers

* fix(web): retain server-side queuing on v2 after rebase

* fix(test): account for optional encoded provider settings

* fix(build): parse executable imports without matching generated source

* fix(build): isolate executable parser from Vite config

* fix(server): project legacy thread shells during import

* fix(server): replay command events across persistence pages (#11499)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(orchestrator): report terminal runs after wait timeout (#11574)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): skip corrupt scheduled-task rows instead of stopping the scheduler (#11585)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): preserve due schedules across equivalent time formatting (#11590)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* test(server): replay denied Claude writes through V2 (#11597)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): fork Codex threads at the native turn boundary (#11490)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): align MCP delegation support with live provider adapter registry (#11578)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* test(server): prove v1 to v2 cutover on a copied database and flag divergent migration ids (#11639)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): bound legacy thread projection requests (#10512)

* fix: reconcile main thread updates and Git improvements with v2

* fix(mobile): restore permission registry concurrency protection

* fix(web): confine composer glass transition to input surface

- Move transition glass styling off the host wrapper
- Add backdrop saturation to the main composer surface

* fix(server): restore hub limits updates in V2 (#11963)

Co-authored-by: Julius Marminge <jmarminge@gmail.com>

* fix(mobile): reject preview builds from v1 source

* fix(mobile): skip preview validation without release credentials

* fix: stop retained background work after a turn settles

* refactor: remove legacy token streaming

* fix: format subagent task names across clients

* fix: distinguish unsupported server connections

* fix: reconcile main updates with V2 orchestration

* fix(server): preserve PR links across V2 discovery and import

* fix: reconcile main monograms and PR refresh with V2

* fix(web): reset thread scroll and ignore hydration as a new turn

* fix(ci): pin patched Expo core during release resolution

* fix(web): invert follow-up behavior with Mod+Enter

* fix(web): show linked pull requests in thread details

* fix(web): restore main thread-switch scrolling without layout resets

* fix: reconcile main setup transitions with V2 threads

* fix(mobile): keep cached thread list across relaunch

The shared shell cache codec never overrode activityRunStartedAt and
unsettledAt with DateTimeUtcFromString, so any snapshot holding a working or
unsettled thread encoded fine but failed to decode on the next cold launch.
The store discarded the whole row and the Home list stayed empty until the
environment reconnected.

Add the two overrides and extend the mobile cache round-trip test with a
running, unsettled thread so the codec and the JSON overrides stay in sync.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* perf(client): coalesce persistent cache writes during streaming (#12109)

* perf(server): suppress unchanged shell enrichment refreshes (#12110)

* perf(mobile): skip unchanged thread row renders (#12116)

* perf(mobile): yield to UI during shell cache encoding (#12117)

* perf(client): narrow mobile and web environment subscriptions (#12126)

* perf(mobile): ignore irrelevant config updates in thread lists (#12127)

* perf(mobile): limit thread model options to its provider (#12128)

* perf(client): stop scanning threads for unused shell timestamps (#12129)

* feat(mobile): make the composer pill the hub for the running turn

The pill above the composer only tracked queued messages, and a follow-up
sent during a turn always queued because mobile hardcoded its dispatch
mode. Steering meant sending the message and then promoting it from the
queue sheet, and the turn's subagents were only reachable as transcript
rows.

The pill now carries an agents segment alongside the queue count, scoped
to the running turn and hidden once it settles. Tapping either segment
opens a sheet: agents lists the turn's subagents and opens a child
thread, and the queue sheet is rebuilt on the native header with compact
rows, swipe to remove, a context menu, and full editing that saves
through queued-run.edit while keeping the message's place in line.

Follow-ups become a choice. A Follow-ups settings screen picks queue or
steer, the send button says which one it will do, and long-pressing it
uses the other for a single message. On a hardware keyboard the Command
chord does the same, so the composer text view now reports whether the
submit was the alternate and names both chords for the iPad shortcut HUD.
Steering travels as "auto" so a turn that ends mid-flight degrades to a
queued run instead of bouncing the message back into the draft, and the
button only offers Steer when the provider can actually steer.

Web's dispatch resolver moves into client-runtime so both clients share
it. The lineage banner is gone from the transcript, taking mobile's
disconnect action with it; merge back to source now lives in the thread
header's git menu.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix: reconcile main composer and provider updates with V2

* test(server): restore Cursor usage coverage after V2 rebase

* feat(web): add compact PR checks to the workspace card (#11981)

* feat(web): show subagent details and history in workspace card (#12079)

* fix(server): start V2 provider turn when checkpoint baseline capture fails (#12153)

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): retain durable checkpoint index fixes on v2

* fix(server): finalize v2 runs when checkpoint ref lookup fails

* fix(server): reject v2 file restore in shared workspaces

* fix(mobile): allow changing provider in a started thread (#12184)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix: reconcile main updates with V2 runtimes and timelines

* fix: align V2 question and checkpoint timelines across clients

* fix(mobile): guard question controls during answer submission

* fix: adapt multi-model thread creation to V2 launches

* fix: restore V2 worktree setup transitions across clients

* fix(mobile): match web provider handoff dividers

* feat(mobile): rebuild the Circe orb and add Circe Mesh sign-in

The mobile app opened straight into Circe on a fresh install, so a user never
saw the step that connects them through Circe Mesh. The voice orb was also the
wrong object: a dark blob with fat translucent bands behind it, plus a soft
square around its glow on some Android GPUs.

Orb
- One Skia canvas with six ordered layers: atmospheric glow, rear fibers, the
  sphere surface, the hull ring, fibers refracted inside the sphere, front
  fibers, then grain. Three fiber planes are what produce depth; nothing here
  is a real 3D render.
- The body is an SkSL runtime effect that reconstructs a surface normal per
  pixel, so the sphere lights like an object instead of a flat radial
  gradient. The ring is modulated by angle, because a uniformly bright ring
  reads as neon rather than as light.
- Fibers are silk filaments, not an audio waveform: 18 rear, 20 refracted
  interior, 5 front, each with deterministic per-strand variation and a
  gaussian envelope centred on the sphere.
- Motion is split so the sphere feels heavy: it barely moves and the field
  carries the animation. One frame callback drives the scene, and audio level
  reaches the renderer as a shared value without re-rendering React.

Sign-in
- The signed-out gate waited forever on Clerk's isLoaded, so a device that
  could not reach Clerk skipped Welcome entirely and landed in the app. It now
  resolves to signed-out after three seconds, and a real stored session still
  resolves from the token cache without the network.
- Adds the Welcome screen and its Clerk auth step, including the Circe Mesh
  onboarding request that already existed behind it.

Theme
- The orb follows the app theme. Light and dark share geometry and differ only
  in luminosity: dark leans on the rim and pulls the bloom back.

Dev tooling
- The orb gallery was gated on process.env.APP_VARIANT, which Expo never
  inlines into the bundle, so the route never registered. Now gated on __DEV__.
  It exposes every state, both appearances, three sizes, and three levels.

Both soft-edge traps found here are silent: `opacity` on a large
radial-filled shape and BlurMask each make Skia allocate a layer, which
renders as a soft-edged square on some Android GPUs. Every soft edge in the
orb is a gradient with its alpha baked in, so no layer is allocated.

* fix(mobile): render the orb as a dark lens, not a lit copper sphere

The previous orb was technically competent and visually wrong. It modelled a
conventional lit solid sphere: the shader reconstructed a surface normal,
applied directional light from the upper-left, and started the body gradient at
a bright cream `hotColor`. That is a polished orange ball, which is what it
rendered. The palette file in the same commit already said the middle of the
sphere must read as near-black, so the code contradicted its own design.

Replaced the rendering model rather than re-tuning colors.

Dark base and a separate transparent shell
- `OrbSurface` is split into `OrbBase` (opaque, `core`/`coreWarm`/`ember` only,
  no directional term) and `OrbShell` (transparent hull light). `hot` is now
  only ever a thin lip or a subsurface accent, never a fill.

Interior fibers moved inside the glass
- The refracted fiber plane now renders between the base and the shell. It
  previously rendered after an opaque sphere, so the strands could only look
  printed onto a surface.

The ring is the shell, not a stroke
- Removed the uniform 360-degree `Path` circle that painted over the shader's
  angular variation and cancelled it out. The shell pass carries an uneven
  profile built from three angular harmonics plus a travelling phase, and the
  only hard edge is a roughly one-pixel lip at the hull.

Refraction instead of compression
- Interior strands were squeezed by constant `x *= 0.91 / y *= 0.82`, which
  reads as a narrowed bundle. They now derive a lens depth from the horizontal
  position and use it both to pull the strand toward the optical axis and to
  shift its phase, so the fiber visibly bends as it enters the sphere.

Fewer, quieter strands
- 43 strands down to 20 (11 rear, 7 interior, 2 front), average alpha roughly
  halved, and one hero strand per plane instead of every fifth strand being
  equally prominent. The field should be perceived, not counted.

Motion is time-based and far slower
- The field advanced a fixed increment per rendered frame, so a 120 Hz device
  drifted twice as fast as a 60 Hz one and a full cycle took about half a
  second. It now advances by elapsed time; `fieldCycleSeconds` is 11 s at rest
  and 5 s while listening. The sphere itself only breathes.

One state model instead of a dozen unused knobs
- `waveAmp`, `massIntensity`, `glowResponse` and `strandAmplitudeScale` were
  varied by state and never read by the renderer. Replaced with six parameters
  that are all consumed, and a single microphone `energy` value that scales
  field amplitude, shell brightness, bloom, and core warmth together.

Scene bounds
- The welcome canvas was `size + 2 * size * 0.95`, about 487 dp tall for a
  168 dp sphere, which opened a large gap between the copy, the orb, and the
  auth controls. The vertical padding is now independent of the fiber field at
  roughly 26% of the sphere.

Grain is off at rest so the idle frame stays clean.

Also syncs the stable web icon filenames from `assets/circe`, which
`scripts/lib/circe-boot-assets.test.ts` asserts byte-for-byte and which the
regenerated assets had left stale.

Verified on a physical Android device in both appearances and in the orb
gallery across states and sizes.

* feat(mobile): adopt Circe design system v1 tokens and shell lighting

Mobile was still carrying the pre-v1 palette: a cool blue-gray dark surface
(`#16181b`), a cool `#0f1620` Circe canvas, an off-brand amber primary
(`#96600a` / `#c99a2e`), and a serif stack that led with Times New Roman. The
design system asks for warm layered near-black, warm ivory paper, restrained
copper as the single brand accent, and an editorial serif.

Tokens (global.css, mobileTheme.ts, regenerated uniwind themes)
- Dark surfaces are now the layered warm near-black set: canvas `#0c0d0e`,
  surface `#121415`, raised `#191b1d`, hover `#1e2022`. Pure black is out.
- Light surfaces are warm ivory: canvas `#fcf9f4`, surface `#fffdfa`, raised
  `#f6f0e9`, hover `#f2ebe4`.
- Borders move to low-opacity warm rules: `rgba(56,43,35,.07/.13/.20)` on light,
  `rgba(255,255,255,.065/.10/.16)` on dark, replacing opaque beige borders.
- Copper becomes the primary action token: `#a5482c` on light for legibility,
  `#e08a63` on dark. The brand accent is identical in both appearances.
- Circe tokens gain the full v1 set: copper ramp, peach, semantic success,
  warning, danger and neutral, plus surface, surface-raised, and copy. Status
  colors are now semantic only rather than decorative.
- The display serif drops Times New Roman, which the design system rules out,
  for a stack led by Iowan Old Style. Bundling Instrument Serif needs a native
  rebuild and is deliberately left as a separate change.

Orb shell (§13)
- The palette moves onto the v1 ramp: `#100e0d` core through `#6d3526` deep
  copper, `#e18a62` copper, `#ffd8bd` peach, `#fff4e9` hot lip.
- The shell's angular profile is now three art-directed light lobes instead of a
  sum of harmonics: the strong warm regions sit upper-left and lower-left, and a
  narrow brilliant flare sits on the right edge. Each lobe drifts slowly.
- The copper band starts around 81% of the radius, matching the design system's
  gradient stops, so the falloff is broad rather than a hairline.
- Bloom becomes two passes matching the specified glow: a broad atmosphere that
  spills past the hull and a narrow warm glow hugging the shell.

Welcome screen
- Adopts the light onboarding treatment: warm ivory paper, near-black editorial
  ink, one burnt-copper phrase, a near-black primary CTA whose only brand cue is
  a restrained copper hairline, and low-opacity warm borders.

Tests
- `uses the Circe graphite palette as the default` asserted the old hexes and is
  replaced with the v1 invariants: light paper is warm (red leads blue), dark is
  a layered near-black that is neither pure black nor a colored slate, and copper
  is the same accent in both appearances.
- The hard-coded variable count in the palette-role test is replaced with the
  presence of every Circe token, which is what the code actually depends on.

* fix(mobile): give the orb volume and rebuild the field as one ribbon

The previous pass over-corrected. Adding a dark base and a separate shell did
fix the order, but nothing was left between them, so the sphere rendered as a
near-uniform black disc under a hairline of light. Two causes, both structural.

There was no volume layer
- `OrbBase` stays in `#100e0d`-`#1a100c` and `OrbShell` only lights the hull, so
  the region in between had no light at all.
- Adds `OrbVolume`, a transparent pass between the interior ribbon and the
  shell. It carries broad low-frequency copper across the outer 40-50% of the
  sphere plus two asymmetric lobes, a lower-body glow and a left-side light.
  Its alpha is capped at 0.42 and it never reaches white, so it reads as smoked
  glass rather than a second opaque sphere.
- The shell's `pow(1 - z, 2.4)` falloff was the other half of the problem: it is
  near zero until the final pixels. Replaced with two explicit art-directed
  fields starting around 46% of the radius. This is brand artwork, not a
  physically correct rim term.

The field was twenty independent sine waves
- Every strand had its own frequency, amplitude, phase, offset and speed, which
  mathematically wants to become spaghetti however few strands remain.
- `WaveField` is replaced by `RibbonField`: one shared centerline carrying a
  broad S-curve, with eight filaments as small offsets from it, so the group
  reads as a single piece of silk. Five faint atmosphere fibers keep their own
  trajectories at alpha 0.04-0.10.
- Both centerline harmonics carry integer phase coefficients, so the curve
  returns to its exact starting shape after a phase revolution and the keyframe
  interpolation stays seamless.

Refraction is now visible
- The interior plane delays the shared centerline's phase by lens depth, grows
  its amplitude inside the glass, and pinches the bundle by up to 42% toward the
  optical axis at the centre. Interior filaments are roughly 1.5x more visible
  than before, so you can see the strands enter the object.
- The front plane carries only the two highlighted filaments rather than a
  second full field.

State wiring
- `fieldAmplitude` was defined and tested but never read by the renderer, so
  tuning it did nothing. It now scales the path amplitude, and changing state
  rebuilds the interpolated frames.
- Bloom is documented as microphone-responsive but `OrbGlow` was never passed
  the level. It now receives `energySV` and its three gradient fields genuinely
  respond. `alphaColor` is a worklet so the stops are built on the UI thread.
- Adds a regression that fails if any `OrbStateParams` key has no consumer in a
  production renderer file. That is the class of bug this commit is fixing.

Glow is now three separate fields rather than one: a broad peach atmosphere at
about 1.55R that visibly lights the page around Circe, a medium warm bloom, and
a localized shell aura.

* feat(mobile): build a dedicated welcome hero illustration

The welcome screen was a standard auth page with the product orb dropped into
it. The orb was shared with the home and voice screens, so every attempt to make
it a brand hero traded off against its job as a state indicator: it came out
either too dark to be a focal point, or too luminous to read as "idle".

The real problem was the abstraction, not the shader.

Separates the two visual systems
- `CirceOrb` stays the product orb: home, voice, listening, thinking, speaking,
  compact, interactive, stateful.
- `CirceWelcomeHero` is a new, decorative brand illustration used only on the
  welcome and auth screens. It has no states, no audio input, and no
  interactivity, so it is free to be bright.
- Both remain in the same canvas so the illustration is one composition rather
  than several widgets stacked in a column.

Rebuilds the page composition
- The hero now sits above the headline. It is full-bleed, cancelling the screen
  padding, so it reads as artwork rather than an inset widget.
- Order is logo, hero, headline, subcopy, CTAs, divider, benefits, legal.

The hero is one wide canvas, 300dp tall, with this layer order
- atmosphere, so the page picks up warmth around the object
- halo arcs, four flattened ellipses at very low alpha
- rear ribbon fan
- orb core, then the interior ribbon clipped and refracted through it
- front filaments crossing over
- dust motes

The orb is luminous now, not a dark ball
- A dedicated shader climbs warm brown, copper, then peach, holding the deep
  core to about 30% of the visible area rather than most of it. The previous
  product-orb treatment was near-black across the whole body, which is correct
  for a state indicator and wrong for a focal point.
- The rim is modulated by three angular harmonics plus a travel phase, so it is
  never uniformly bright. A value hash adds faint grain so the volume is not a
  mathematically smooth disc.

The ribbon is one flow field, not independent sine waves
- A single master spline crosses the hero. Every filament is an offset from that
  curve, so the strands stay related and read as one piece of silk.
- The bundle is tight where it passes the orb and opens toward the edges, which
  produces the left and right fans from a single construction.
- Inside the glass the shared curve is phase-delayed, amplified and pinched
  toward the optical axis, so the fan visibly narrows as it passes through the
  object instead of merely being clipped by it.
- Both harmonics carry integer phase coefficients, so the curve returns to its
  exact starting shape after a phase revolution and the loop stays seamless.

Motion is slow drift only, driven by wall-clock time so it is identical at any
refresh rate, and fully suppressed under reduced motion.

Two things worth recording for the next pass. The first ribbon attempt opened
the bundle from 8% to 123% of the orb radius within half a screen, which read as
a bowtie starburst rather than a ribbon; the spread is now deliberately gentle.
Second, the fallback for a driver where the runtime effect will not compile has
to be its own component: `RadialGradient` and `Shader` both use hooks, so
swapping them inside one component changes that component's hook order between
renders.

The hero is also surfaced in the development orb gallery, since the welcome
route redirects as soon as a session exists and is otherwise hard to inspect.

* refactor(mobile): rebuild the welcome hero as a woven ribbon over a lit sphere

The hero looked wrong for structural reasons, not tuning reasons. The ribbon
morphed its whole spline once per cycle, and the orb was a dark procedural
sphere with the interior ribbon painted on top of it.

Correctness
- Removes geometry morphing entirely, which removes the class of bug rather
  than patching it. `ribbonPhase` was emitted in [0, 2*pi] while
  `usePathInterpolation` expects a [0, 1, 2, 3] input range, and `masterCurve`
  and the per-strand jitter carried half-phase coefficients, so the geometry at
  2*pi did not equal the geometry at 0 and the loop had a real seam.
- The illustration is a brand mark, not an audio waveform. The centreline is now
  frozen. Life comes from a highlight travelling along the ribbon and from a
  rigid 4dp drift over 12s, both implemented as slow out-and-back ramps, so
  there is no loop boundary to seam in the first place.
- Fixes the compositing order. The glass shell is now painted after the clipped
  interior ribbon, so the strands genuinely sit inside the sphere instead of on
  top of it.

The ribbon is now a woven surface
- One art-directed Catmull-Rom centreline, and every strand is offset along that
  curve's own perpendicular rather than in raw Y. Parallelism is the point: the
  perpendicular separation between adjacent strands is exactly
  `|offsetA - offsetB| * halfWidth` at every sample, and the test asserts it.
  A Y-offset construction only holds where the curve is horizontal and drifts
  apart through every bend.
- 24 filaments, ordinary 0.55-0.8dp, hero 0.9-1.15dp, glow at 2.8x core width
  and low alpha rather than a 6x fuzzy halo.
- The bundle contracts around the sphere and fans toward both edges, which is
  what makes the mesh read as converging on the object.
- Interior geometry is only built across the sphere plus a margin, since it is
  clipped to the sphere; building it across the full hero width tripled the
  stroked segment count for nothing.

The orb is now two baked layers
- `hero-orb-body.webp` and `hero-orb-glass.webp`, generated by
  `scripts/generate-circe-hero-assets.ts`. Radius-driven shader ramps read as
  concentric bands: they cannot express asymmetric directional lighting, a
  Fresnel rim or a specular lobe. The asset is shaded from the reconstructed
  sphere normal with a key and fill light, a directional terminator, a
  subsurface glow for internal illumination and limb darkening.
- The glass face is nearly clear, carrying only the Fresnel rim and two
  specular lobes. A broad sheen across the face fogged the body into polished
  metal, which is the opposite of glass over warm copper.
- Full-surface hash grain is gone. It read as dithering and broke up the volume;
  it is replaced by 20 discrete internal light motes.
- `CirceOrb` remains fully procedural for product states.

The interior strands are shifted hot and lifted slightly. At the same copper as
the body they vanished into it entirely, which is how the first pass shipped
with an invisible interior ribbon.

Hero orb radius drops to 0.215 of the width, clamped to 76-88dp, so the mesh
dominates the composition rather than the sphere.

The gallery gains a Frozen/Live motion switch and defaults to frozen, so a
still frame can be judged before motion is allowed to excuse anything.

* perf(mobile): cut per-frame work in the welcome hero ribbon

Reduces the cost of the woven surface. These are defensible reductions in work
per frame; see the caveat below on what I could and could not verify.

- Ordinary strands no longer carry a highlight gradient. Every one of the 72
  filament instances used to create two animated derived values, so all of them
  re-evaluated a worklet and allocated a point on every frame. The gradient now
  lives in its own component used only by the four hero strands.
- Stroke joins are miter rather than round. Skia emits join geometry at every
  vertex, and this ribbon is a densely sampled polyline, so round joins were
  generating thousands of join primitives. At this sampling density the two are
  visually identical.
- Sampling drops from 26 to 14 steps per segment. Stroke geometry is generated
  per segment, so this is a direct cost driver.
- The halo pass is limited to the strands meant to catch the light. Wide
  translucent strokes are pure fill rate and overdraw, and a halo on all 24
  strands across three planes was the largest single contributor.

Measurement caveat, recorded because it is easy to misread: the screen renders
at the same frame time with the hero removed entirely, so this change is not
demonstrably responsible for any measured improvement, and `dumpsys gfxinfo` on
this device reports internally inconsistent numbers (455 frames over 12s is a
26ms average, while the same sample reports a 61ms median). Do not treat the
hero as the performance owner for this screen without a cleaner instrument.

* refactor(mobile): art-direct the hero orb assets and align the hero vocabulary

The previous pass produced a planet. The body had a directional falloff down to
0.24 and a round specular, which reads as a sphere under a hard key light rather
than as the reference's luminous object. The shading is now art-directed rather
than physical.

Body (`hero-orb-body.png`)
- Ramp is deep brown through warm brown and copper to peach-copper, matching the
  reference palette rather than the previous darker set.
- The directional falloff floor rises from 0.24 to 0.45, so the shadow side
  stays warm brown. That single number was responsible for the planet look.
- Limb darkening drops to a mild term. The fresnel rim belongs to the shell
  layer and should not be doubled up here.
- The suspended specks are baked in. Rendering them live was a second source of
  truth for something that never moves.

Shell (`hero-orb-shell.png`)
- One anisotropic highlight streak replaces the round specular. Studio lighting
  reads as an elongated streak; a round dot reads as a shiny ball.
- The rim is biased so it is stronger top-left, top and right rather than
  uniform all the way round.
- The outward bloom is much tighter. The first attempt kept near full strength
  across the entire image margin, which rendered as a solid opaque donut around
  the sphere.
- The face stays at 0.012 alpha, verified from the exported alpha profile, so
  the shell adds a rim and a streak without flattening the body's depth.

Both layers now place the sphere at 0.93 of the half-image, reserving margin for
the bloom to extend past the silhouette. The generator and the components share
`HERO_ASSET_SPHERE_SCALE`, because a mismatch here silently misaligns the rim
against the body edge.

Interior mesh brightness is reduced. Pushed harder it read as a glowing stripe
cutting the sphere rather than as light travelling through glass.

Files are renamed to the hero vocabulary: `HeroRibbonMesh`, `HeroHaloArcs`,
`HeroAmbientParticles`, `HeroOrbShell`. The geometry module keeps its specific
name rather than becoming `heroMath`, since it holds ribbon geometry and not
general math.

* refactor(mobile): replace the welcome hero renderer with the approved illustration

The hero is now the approved reference artwork, supplied as a single
transparent plate. Everything the previous passes built to approximate it is
deleted.

Why the replacement rather than another pass
- `scripts/generate-circe-hero-assets.ts` computed a sphere normal, applied
  key/fill dot products, a directional shade term and limb darkening, then
  rasterized the result. That is cached shader maths carrying a PNG extension,
  so it inherited every limitation of the procedural sphere it replaced and read
  as a glossy planet.
- The mesh was one Catmull-Rom centreline with filaments offset along its
  normal. That construction keeps strand ordering fixed for the whole length of
  the ribbon, so it can only ever draw a bent sheet of parallel strands. The
  reference has strands that cross and change depth, fans that differ left from
  right, and ribbon width that varies deliberately. Those relationships are the
  design, and deriving them independently then compositing them at runtime
  produced a belt around a ball.
- The layer order was correct and the alpha profile was mathematically correct
  the whole time. Neither of those was the problem, which is exactly why
  implementation-level checks kept passing while the screenshot stayed wrong.

Deleted: `scripts/generate-circe-hero-assets.ts`, `HeroRibbonMesh`,
`HeroHaloArcs`, `HeroAmbientParticles`, `HeroOrbBody`, `HeroOrbShell`,
`heroRibbonGeometry` and its test, `heroTokens`, and both generated orb layers.

What replaces them
- `apps/mobile/assets/circe/welcome-hero-base.png`, 1536x1024 with real
  transparency, rendered as one image.
- `CirceWelcomeHero` is a plain React Native image at the plate's own aspect
  ratio, so the composition is never cropped or distorted. There is no Skia
  canvas left in the hero, because there is no longer any Skia content to
  compose with.
- Static by design. The previous revision drifted the mesh 4dp every 13s and
  swept a highlight along it; for a brand illustration, movement should come
  from light and only after the still frame matches. There is no animation to
  approve yet.

Layout moves the hero below the subcopy, which is where the reference puts it.

Asset note: the plate is 2.2MB as PNG. It is committed exactly as supplied;
converting to WebP would cut it to roughly 200KB with no visual change if that
matters for bundle size.

* feat(mobile): finish the welcome screen against the reference

Composition and typography now match the approved reference, and the screen fits
without scrolling.

Authored type rather than a system stack
- Bundles Instrument Serif from @expo-google-fonts. It matches the reference's
  high-contrast editorial serif with ball terminals, and it is what the design
  system already named for identity moments while noting it needed a rebuild.
- Registered natively in app.config.ts so release builds pay no runtime cost,
  and also loaded at runtime in App.tsx so a dev client built before this change
  can still render it without a full native rebuild.
- The headline sets `fontFamily` explicitly on both spans. It previously layered
  a serif class over AppText's font-sans, and the two were fighting.

Real brand assets
- The wordmark uses the approved `circe-mark.png` instead of a redrawn SVG ring.
- The Google mark was a single blue shape: the canonical four-colour paths had
  the blue quadrant duplicated as a full outline, which painted over the other
  three. Replaced with the correct brand paths.

The hero no longer wastes height
- The supplied plate carried about 250px of fully transparent margin above and
  below the mesh, which at hero scale became ~60dp of dead space and pushed the
  whole sign-up screen into a scroll. The plate is cropped to its content bounds
  (margins only, no artwork removed) and re-encoded as WebP: 2.2MB to 540KB.
- The viewport is now derived from the scaled plate rather than a fixed
  `245-260dp`, so the composition holds across widths instead of leaving a gap
  on tall screens and cropping on short ones.

Layout
- Hero sits directly under the wordmark and above the headline, as instructed.
- Headline copy is now "Talk to every machine, / from anywhere.", which covers
  the voice and remote aspects in two balanced lines. The previous first line was
  long enough to spill onto a third.
- Removed the benefit row. It read as filler rather than information, and it was
  the last thing keeping the page scrollable.
- The account link is copper throughout, the primary CTA carries a copper
  hairline and a copper shadow cast, and the legal links are underlined and open
  the real Terms and Privacy URLs in the in-app browser.

* feat(mobile): rebuild the Circe orb, live voice, and no-device state

Orb: port the Web Threads field to SkSL (rear field, rim caustic, refraction), keep the idle lens clean, and tune appearance.

Live voice: caption shows Circe only, one failure notice instead of two, mint only on an online node, and delegate corrections/quick actions without depending on the speech model's judgement.

Weather/time: propose the deterministic lookup in the bounded grammar before the project guard so quick actions never fall through to a chat model.

Home: replace unusable controls with an honest no-device state, and show a connecting placeholder on cold start instead of a false no-device claim.

* fix(mobile): align the theme bridge test with the design system tokens

The generator test still asserted the pre-design-system screen colors
(#faf7f1 / #16181b) while the authored global.css and the generated
bridge use the v1 warm-paper palette (#fcf9f4 / #0c0d0e). Regenerate the
committed bridge (alpha normalized to 0.2) and assert the authored
values. This unblocks the mobile PR after its rebase onto main.

* test(circe): register merged upstream migrations 67-69 in the manifest tests

The upstream orchestration V2 merge added three migrations above Circe's
shipped 41-66 slots. MigrationsRemap and the V2 migration test still asserted a
contiguous manifest ending at 66 and V2 at upstream's id 53, so both failed.
Extend the expected manifest to 69 and assert the Circe-remapped V2 slot while
keeping the schema and index checks intact.

* fix(circe): reconcile web imports with the merged V2 client surfaces

The orchestration V2 merge removed exports the web app still imported, so the
web bundle failed to resolve ../T3Wordmark and two components referenced
removed APIs at runtime. Point V2LifecycleRow at CirceWordmark, render
provider rows through the centralized ProviderInstanceIcon instead of the
removed PROVIDER_ICON_BY_PROVIDER map, and use the V2 useThreadProjection
hook in place of the retired V1 useThread.

* test(circe): exercise the message-context migration at its remapped slot

The upstream ProjectionThreadMessageContext migration registers at 67 on the
Circe line, but the test migrated to 51 and asserted id 51 (CirceFollowUpQueue),
so it never exercised the guarded migration. Migrate to 66, keep the manual
column, then apply 67 and assert migration 67 was recorded.

* test(circe): replay in shared workspaces and guard foreign databases

V2 file restore now requires an isolated worktree, but the replay and fork
fixtures dispatch checkpoint.rollback in a shared workspace while asserting
conversation rewind, so they are conversation-only (restoreFiles: false). Drop
the upstream-numbered LegacyV1Cutover integration test and cover the real
invariant instead: a database recording another product's history under a Circe
migration id is refused with ForeignDatabaseError.

* fix(circe): map the V2 thread runtime to desktop orb statuses

The orb bridge read session.status and backgroundLiveness, which the V2 shell
removed, so the desktop orb mis-rendered agent status and failed typecheck. Map
preparing/queued/starting to starting, running to running, waiting to waiting,
and pending background tasks to monitoring, and update the fixtures.

* test(circe): read the foreign-database defect with the Effect 4 Cause API

* fix(circe): apply V2 module deletions and reconcile ownership guards

* chore(circe): re-key service tags and align sqlite runtime with V2

Service Context tags across apps/server/src still carried upstream `t3/...`
keys while the package name makes the expected deterministic key
`@absterrg0/circe/...`. Re-keyed all 56 declarations, including the nine
orchestration-v2 services whose class-suffixed keys (e.g. `.../CommandPolicy/
CommandPolicyV2`) the prefix-only pass did not reach.

Also:
- Aligned persistence/Laye…
juliusmarminge added a commit that referenced this pull request Sep 18, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 18, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 18, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 18, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 18, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 19, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 19, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 19, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 21, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 21, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 23, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 23, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 23, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 23, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Jacksondr5 added a commit to Jacksondr5/j5code that referenced this pull request Sep 23, 2026
* fix: port main fixes stranded by the v2 rewrite

- Port thread pinning (#5312) into the orchestration-v2 command pipeline:
  thread.pin/unpin commands, thread.pinned/unpinned events, pinnedAt on the
  v2 thread state and projected shells, promotion semantics (pin clears
  settle/snooze, settle clears pin) matching the v1 decider, and client
  pin/unpin operations in the v2 dispatch style.
- Port the regenerated-title context anchoring (#5365) into
  ThreadTitleRegenerationService: pin the first user message ahead of the
  retained tail when the digest is truncated.
- Re-apply the right-panel controls positioning from #5260 to the v2
  ChatView title bar controls.
- Repair merge artifacts: committed conflict markers in BranchToolbar,
  duplicate capability keys, duplicate CommandPalette import, v1 turn
  naming in DiffPanel's focus-refresh effect, onSend signature merge.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* test(server): align migration expectations with renumbered ids

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(orchestrator): Surface waiting background work (#4378)

* fix(web): align git action progress button layout

- Match progress button spacing and single-line height to static git actions

* fix: repair conflict-marker artifacts from rebase auto-resolutions

rerere replayed stale resolutions during the rebase and committed nested
conflict markers in several files. Restore the branch-intended v2 shapes
and re-graft main's compatible additions (pending-card opacity comments,
theme-editor keybinding test, mobile scroll re-arm effects from #5566).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(server): renumber v2 migrations after main's 037_ProjectionTurnsKeysetIndex

Main owns migration numbering: 037_ProjectionTurnsKeysetIndex landed on
main (#5493), so the v2 migrations shift from 037-045 to 038-046.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: port main fixes stranded by the v2 rewrite (round 2)

Native subagent observability (#5219), wired per its spec's v2 merge plan:
- getWorkflowScript RPC re-homed onto the v2 WS surface (contracts, rpc
  group, ws handler, auth scope, client atom).
- AgentsPanel fed by the spec's mapper swap: projectedSubagentsToRuntime
  maps orchestration-v2 subagent entities into the panel model;
  deriveAgentPanelModel's v2Projection leg is now live and the v1 fold
  never runs. Agents surface wired into ChatView + RightPanelTabs.
Other ports and reconciliations:
- Shell reconnect-loop fix (#5561) ported into the v2 shell sync
  (same-session resubscribes resume from the in-memory cursor), with the
  cursor-resume regression test adapted to v2 fixtures.
- Mobile end-follow latch (#5566) ported onto the v2 ThreadFeed.
- Claude ede_diagnostic interrupt classification (#5557) ported into
  ClaudeAdapterV2 (aborted_tools/aborted_streaming => interrupted; CLI
  telemetry never becomes the failure banner). #5559 needs no v2 port
  (unknown system subtypes are already ignored).
- Plan sidebar removed from the v2 ChatView/ChatComposer per main's
  plans-fold-into-chat rework (#5558); rightPanelStore stays at main's
  surface set.
- SettingsPanels rebuilt as main's refactored version plus the branch's
  composer-context setting; sidebar snooze respects the time format
  (#4438 follow-through).
- v1-only leftovers deleted: zombie v1 adapters/ingestion/tests the v2
  rewrite removes, the v1-bound transfer-budget CI harness (#5350, needs
  a v2 rebuild), and main's v1 client pagination machinery (#5493 client
  side; the 037 keyset migration is kept — server-side v2 windowing is a
  follow-up).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* chore(web): prune plan-sidebar leftovers after the inline-plans rework

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): port the refined live-follow gesture gating to the v2 timeline

The rebase kept the LegendList 3.3.3 upgrade and patch from #5449 and the
mobile end-follow latch from #5566, but the v2 MessagesTimeline/ChatView
still carried the branch's blunt any-gesture-breaks-follow listeners.
Port main's #5566 web mechanics onto the v2 follow architecture:

- resolveTimelineIsAtEnd measures the 40px follow re-arm band from real
  geometry (contentLength/scroll/scrollLength minus the composer inset),
  keeping the isNearEnd fallback for older state shapes.
- Follow now breaks only on gestures that can actually leave the live
  edge: upward wheel with overflowing content, touch drags that exited
  the end band, scrollbar drags vs content clicks, and keyboard
  navigation (PageUp/Home/ArrowUp) — previously keyboard scrolling never
  broke follow and the next stream chunk yanked the view back down.
- Listener attach retries across frames so a thread switch cannot mount
  the list without its opt-out listeners.

Deliberately not ported: #5449's shouldRestorePosition disclosure
anchoring and follow-gated maintainScrollAtEnd — the v2 timeline keeps
maintainScrollAtEnd={false} with its own follow scrolls and anchor
system; flipping that core is a separate change.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): let LegendList own end-follow and disclosure anchoring (#5449)

Complete the #5449 architecture on the v2 timeline, following the
LegendList author's direction to lean on the list's native mechanisms
instead of app-side scroll layers:

- maintainScrollAtEnd is enabled and owned by LegendList, gated off only
  while the user reads history (liveFollowEnabled), while a sent turn
  anchors near the top (anchoredEndSpace), or during the two-frame settle
  of a fold toggle.
- maintainVisibleContentPosition compensates size changes natively
  ({data, size, shouldRestorePosition}); fold toggles anchor compensation
  to the toggled row via a disclosure anchor key, so the trigger stays
  under the pointer instead of the viewport chasing the end.
- ChatView's hand-rolled streaming follow (double-rAF scrollToEnd on
  every data change) is gone; the app now only owns streaming
  adjustments during anchored-end-space mode, mirroring main.
- timelineLiveFollowEnabled state mirrors the follow refs so the
  render-visible gate switches native follow off when a gesture breaks
  follow and back on when the viewport returns to the end band.

Timeline tests updated to assert the native-ownership invariants.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): show Git action success inline in panel

- Keep success feedback visible in the Git action control for 10 seconds
- Move the running elapsed timer into the panel menu slot

* fix: repair rerere-damaged files and reconcile main's round-3 features with v2

Post-rebase reconciliation sweep:
- Sidebar: main's folded Sidebar.tsx/Sidebar.logic.ts adapted to v2 shells
  (latestRun/runtime naming, waiting status instead of monitoring), with
  subagent-thread filtering and main's pinned-reorder helpers re-exported
- Pinned drag reorder (#5581) ported into v2: thread.pin orderKey +
  thread.pin.reorder command, thread.pin-reordered event, Orchestrator fold,
  ProjectionStore/Maintenance, client-runtime commands and shell mapping
- Project favicon (#4849-era) and defaultThreadEnvMode flowed through v2
  contracts (OrchestrationProjectShell, application event payloads)
- ChatView: main's #5592 header props, pull-request right-panel surfaces,
  liveAgentCount badge (#5745) wired into the v2 panel layout
- enableAssistantStreaming -> enableLegacyTokenStreaming rename applied to
  v2 RunExecutionService and replay testkit
- Removed v1 zombies resurrected by the rebase (provider service/reaper/
  ingestion + v1 layer tests, server.test.ts, integration harness)
- routeTree: main's tree + branch's /settings/scheduled-tasks route
- Misc marker-sweep syntax repairs (rpc.ts, entities.ts, localApi.test.ts,
  rightPanelStore.test.ts, GitManager.test.ts, mobile model menu helpers)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* chore(server): renumber v2 migrations 038-046 to 041-049 after main's 038-040

Main released ProjectionThreadsPinOrderKey (038),
ProjectionProjectsDefaultThreadEnvMode (039) and
ProjectionProjectFaviconPath (040), so the branch-private v2 stack shifts
up by three. Registry ids were already 41-49; this renames the files and
identifiers to match and updates the ledger expectations and through-id
boundaries in the migration tests (released boundary 37 -> 40).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(server): port round-3 main fixes into the v2 orchestrator

- a6c9b41f90 (agents open pasted images): ClaudeAdapterV2 now grants the
  attachments dir alongside cwd via additionalDirectories and appends
  '[Attached ... is saved at: path]' lines to the turn text so tools can
  dereference pasted images (pixels alone are not tool-readable).
- 5bb8c03664 (settle leaves monitors running): thread.settle now joins
  archive/delete in the provider-session detach set, so PR monitors, dev
  servers and subagent fleets stop when the user parks the thread. The
  settle guard already rejects active runs, and serialized dispatch closes
  the re-engage race the v1 fix handled with onlyIfSettled.
- e70cdb478d (Claude resume handshakes) and 2c7267ad43 (reaper vs live
  background subagents) are already covered structurally in v2: results
  are turn-scoped with explicit zero-turn handshake drops, and idle
  release is pinned while background work is pending.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* test(web): restore main's right-panel migration expectations after the panel-visibility merge

The keep-both merge nested main's plan-surface migration test inside a
branch popover test and dropped the threadPanelVisibilityByThreadKey key
from the migration results. Restore main's test body and include the
branch's (empty) visibility map in the expected persisted shape.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* test(server): expect attachment saved-at lines in ClaudeAdapterV2 turn text

Follow-up to the #5757 port: start and steer turns now append the
'[Attached ... is saved at: path]' line, so the adapter fixtures assert it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): restore the branch's slim chat header

The round-3 reconciliation took main's ChatHeader wholesale and wired its
full prop set, resurrecting the scripts/open-in/git-actions cluster the
branch had deliberately relocated into the thread panel. Restore the
79-line slim header (project favicon + name + thread title) and its
minimal ChatView call. #5592's header actions stay a documented v2
follow-up, as decided in round 2.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(web): add pull request actions to thread details

- Add ready, merge, and conflict-resolution actions to the PR row
- Share pull request action and handoff logic with the detail panel
- Fix thread details scrolling and row alignment

* fix(mobile): port main's composer stabilization into the v2 thread screens

Round-4 reconciliation of #5986/#5988 with the v2 cutover files:
- PendingUserInputCard adopts main's collapsible overlay redesign with the
  v2 RuntimeRequestId/responseCapability plumbing (dead provider processes
  still read-only the card)
- ThreadFeed adopts the thread-feed-live-follow transition model, the
  user-scroll settle window, momentum handoff, and env-scoped feed keys
  while keeping the v2 nearListEnd layout gating
- ThreadDetailScreen hides (not unmounts) the composer while a user-input
  request owns the slot; multi-select answers flow as arrays end to end
  (threadActivity toggle/build helpers + tests, ThreadUserInputQuestion)
- ThreadComposer keeps the v2 canStopThread stop gate under main's
  onEditorFocusChange rename; standalone stop reuses the shared renderer
- Restored the branch's steer stop/send tests alongside main's composer
  test suite

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): reconcile main's round-5 features after the rebase

- PullRequestDetailPanel takes main's #6039 rework wholesale (reactions,
  update-branch, auto-merge, in-place editing); the thread-details action
  hooks stay in usePullRequestActions with label maps extended for the
  new action variants
- CommandPalette #6330 provider subtitles adapted to the v2 shell
  (session -> runtime for provider instance and display name)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(web): prioritize pull request row actions

- Add conflict, draft, failing-check, and merge action ranking
- Show check progress and pull request details in row tooltips

* fix(web): restore main's collapse chrome and tab-status keying on the PR panel

The round-5 ChatView reconciliation kept the round-3-era PullRequestDetailPanel
call, so the panel mounted without chromeVariant="collapse" — the #6039
scroll-condensing chrome never engaged and the description scrolled under a
full-height chrome. Restore main's call exactly: collapse chrome,
composerDraftTarget for same-thread hand-offs, the isThreadOwnPullRequest
context check, and tab statuses keyed by the active surface id via
updatePullRequestTabStatus instead of a key rebuilt from the status payload.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(orchestration): bound thread history and resume payloads

- Add paginated thread history with bounded snapshots and replay limits
- Trim oversized wire payloads and support progressive mobile history loading

* feat(contracts): track thread title regeneration

- Add optional title regeneration request and start time to thread shells
- Cover cache serialization on mobile and client runtime

* fix: reconcile main's round-6 features after the rebase

- ChatView: #5880 auto-settle-on-merge setting flows into effectiveSettled,
  #5644 browser favicon project registration effect, activeProjectRef memo,
  desktopByTabId on both RightPanelTabs mounts
- server: provide ServerSecretStore to the McpSessionRegistry's
  ServerEnvironment layer (#6325 reads publish opt-in per descriptor)
- mobile: 3-way merged main's deltas into the v2 thread screens
  (NewTaskDraftScreen keeps the branch title seed + main's environmentId,
  threadListV2 keeps both new test suites, queries imports deduped)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): keep the titlebar layout controls fixed across right-panel toggles

Restores main's one-inset rule (#5226) that a rebase resolution had
overridden with a conditional right-2 offset, which made the controls jump
sideways whenever the right panel opened. Also restores the live-agent
count badge on the right-panel toggle (#5745) that the round-6 replay
dropped, and applies the same fixed-position rule to the pull requests
page: the toggle now stays mounted at one absolute inset in both states,
with a footprint spacer in the list header so the refresh button never
slides underneath it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): align titlebar clusters to one shared pixel inset

The right controls carry mr-px (main's border compensation for anchoring
inside the panel frame), which left the sidebar trigger one pixel closer
to its edge and the sheet-mode tab bar one pixel tighter than the closed
state. Mirror the pixel on the trigger and the sheet layout-controls slot
so all three read the same inset.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): size the titlebar layout-control icons like the sidebar trigger

The trigger's icon falls through to the Button default (size-4) while the
right cluster hard-coded size-3.5, so the two ends of the titlebar read a
pixel apart on every edge. All five layout-control icons now use size-4,
matching the trigger and the pull requests page's refresh icon.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* perf(server): keep shell snapshots bounded and active-only

- Omit transcript bodies from shell rows
- Query archived threads separately and stream compact resume metadata

* fix: reconcile main's round-8 features after the rebase

Re-applies the deltas that mid-stack blob reverts discarded, and merges
main's work into the v2-owned surfaces:

- keybindings: main's STATIC_KEYBINDING_COMMANDS rename plus both new
  commands (rightPanel.toggleMaximized alongside threadPanel.toggle)
- OpenInPicker: main's remote-open/SSH routing and favorite-editor
  shortcut layered onto the branch's panel/toolbar variants; the
  extracted shouldShowOpenInPicker now takes remoteOpenMode
- ChatMarkdown: main's bare-filename resolver (#6297) ported into the
  branch's module-level component factory, plus #4133 title-attribute
  stripping on links and images
- ComposerPrimaryActions: main's #4781 model (stop stays reachable, send
  joins it when Enter-to-send is unavailable) carrying the branch's
  steering send button
- ComposerPendingUserInputPanel: main's collapsible redesign with the v2
  RuntimeRequestId and responseCapability gate
- ChatComposer: main's oversized-prompt submission guard wrapping the
  branch's dispatch-mode send
- preview shell: main's container-aware width clamp ported into the
  branch's usePreviewPanelInlineSize hook
- MessagesTimeline/Sidebar: main's day-aware timestamps, code-font tool
  bodies and provider accent badges on the v2 runtime shell
- index.css: main's @variant dark migration (#6381) replaces the branch's
  standalone .dark block
- contracts: main's send-turn image mime allowlist re-homed to
  chatAttachment.ts, where v2 keeps the other send-turn limits

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(server): reject replaying a command receipt across threads in v2

Ports v1's #5246 guard into the v2 dispatcher: a stored receipt only
proves that this exact command already ran for the thread it was recorded
against, so returning it for a command aimed at a different thread reports
success for work that never happened there. The check is extracted as
canReplayCommandReceipt so the rule is unit-testable, and reuse now fails
with OrchestratorCommandIdConflictError like the v1 path.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(mobile): surface prominent activity status and metadata

- Keep prominent activity rows visible with lifecycle status and provider metadata
- Move feed sizing logic into tested helpers and preserve native measurement for activity groups

* fix: reconcile main's round-9 features after the rebase

Re-applies the deltas that mid-stack blob reverts discarded, and merges
main's round-9 work into the v2-owned surfaces:

- settings: main's Integrations page (#7082) coexists with the branch's
  Scheduled Tasks page in the path union, section labels, icons, and
  search catalog
- contracts: main's preview appearance/zoom/viewport settings imports
  restored beside the branch's modelSelection home for ModelSelection
- mobile: main's built-in themes (#6619) re-applied to the v2 thread
  screens and work log (useThemeColor over hand-rolled color-scheme
  ternaries)
- MessagesTimeline: main's #7157 cleanup adopted (toolCallExpandedBody
  class name unexported, implementation-detail test dropped)
- ChangedFilesTree: main's styled tooltip (#7209) carrying the v2 runId
- pullRequestDetail tests: branch's row-action coverage renamed onto
  main's buildAddSelectionToAgentHandoff (#6597)
- lint: migrated the six branch-owned native title tooltips that main's
  new no-native-title-tooltip rule (#7209) flags to styled Tooltips
  (GitActionsControl, QueuedRunsControl, TimelineSystemDivider,
  MessagesTimeline intent badge and MCP tool logo)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(server): honor withheld agent browser access in the v2 runtime

Ports #7083 into the v2 session path, which replaced the v1
ProviderService where main's gate lives. Instead of withholding the whole
t3-code MCP credential — on this branch it also carries the thread
orchestration and worktree toolkits — the credential is minted without
the "preview" capability when enableAgentBrowserAccess is off, so every
preview tool call rejects while orchestration stays available.

ProviderSessionManager reads the setting at prepare time (deny on an
unreadable settings file, matching main), rotates a reused credential
whose capability set no longer reflects the setting, and the session
config now carries browserToolsAvailable so the Codex adapter keeps its
developer instructions truthful via main's parameterized instruction
builders instead of the removed constants.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): restore the titlebar sizing and timeline fade lost to main's style simplification

Main's #6381 deleted the shared .workspace-topbar and scroll-fade rules
from index.css after inlining them at main's own call sites, but this
branch's slim chat chrome still references both classes. The round-8
rebase took the deletion without migrating the branch call sites, so the
header collapsed to zero height — the breadcrumb sat on the window edge,
timeline rows scrolled unfaded through it, and the thread-details popover
anchored to the collapsed header.

Restores both as composable utilities in #6381's own style: a
workspace-topbar utility for the titlebar rows, and the branch's
chat-timeline-scroll-fade mask (soft ramp plus a full-height scrollbar
column). Also drops the duplicated media override and its dead
settings-page-scroll-fade selector.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): finish aligning the branch with main's style simplification

A follow-up sweep against #6381 found the branch still carrying the
pre-simplification forms it replaced, which my earlier fix had papered
over with a compat utility instead of finishing the migration:

- ChatView now uses main's inlined titlebar sizing and the
  data-workspace-titlebar-controls hook on both control clusters. The
  class-based markup was silently missing the themed-toggle bridge
  (html[data-theme-id] [data-workspace-titlebar-controls] …), so custom
  themes lost their titlebar accent in the thread view.
- The scroll-to-end pill becomes main's Button size="xs" variant="glass"
  instead of a hand-rolled button recreating it.
- MessagesTimeline uses main's consolidated topbar-scroll-fade utility;
  the byte-identical chat-timeline-scroll-fade copy and the
  workspace-topbar compat utility are gone.
- The composer-glass dark rules move into nested @variant dark like
  main's (the raw .dark duplicates could drift from the nested copies
  they shadowed), including the branch-only queue strip.
- The pre-#6381 dialog-glass/dialog-backdrop/dropdown-glass class rules
  and their .dark variants are deleted: the #6381 utilities plus
  call-site shadow utilities own every declaration, and the stale
  dropdown rule still had the saturate-less backdrop-filter. The dead
  model-picker-surface dark rule goes with them.

index.css now has zero raw .dark selectors outside the variant
definitions, matching the doctrine in
.macroscope/check-run-agents/ui-consistency.md. Verified against the
emitted production CSS: dark variants compile to :is(.dark,.dark *) with
their @supports color-mix fallbacks intact.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(orchestration): show provider retries in the work log

- Complete retry items when provider activity resumes
- Keep retry progress visible across web and mobile clients

* fix: reconcile main's round-10 features after the rebase

Ten days of main (194 commits, 640 files) re-integrated with the v2
re-architecture. The headline mechanics:

- migrations: main added 041-043 (AuthSessionClientConnection,
  ProjectionThreadLinkedPullRequest, ProjectionThreadsUnsettledAt), so the
  v2 block renumbers 041-049 → 044-052 with the migration tests shifted to
  match
- contracts: OrchestrationClientOrigin (#7774) and the origin metadata
  field live in applicationEvent.ts and re-export through the legacy
  path; ProviderApprovalOption + acceptAlways + mcp-elicitation (#8058)
  land in providerPolicy.ts; OrchestrationDispatchCommandError (#8824)
  added; the send-turn image-mime home stays chatAttachment.ts
- threadSettled: main's settle-once-on-merge semantics (#7454) and
  un-settle re-anchor (#8231) hand-merged onto the v2 duck-typed shells
  (latestRun ?? latestTurn reads); web callers pass the new
  ChangeRequestSettleSource shape
- timeline anchoring: main's #7897 (follow-up sends no longer push to the
  top) ported by scanning user rows only; the branch test now encodes the
  new semantics, as does mobile's #7969 settled-pinned shelf behavior
- vcs: branch's deleteLocalBranch coexists with main's pruneWorktrees and
  the #7674 submodule checkout tests
- ws: v2 RPC surface keeps its dispatch path; main's attachment upload
  RPCs (#8048) and client-connection analytics recording are wired;
  providerUploadFeedback (#7949) fails explicitly pending a v2 route
- approvals: main's option-driven approval buttons (#8058) render through
  the v2 canRespond gate on web and mobile
- ChatView/ChatComposer/MessagesTimeline/Sidebar/session-logic/
  threadActivity keep the branch's v2 architecture; main's v1-coupled
  deltas to those files are recorded for follow-up rather than
  force-fitted

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): stop mis-marking recovered and text-reported tool failures in the v2 work log

Ports main's #7999/#7893 failure policy onto the v2 turn-item work log:
output text that reports a failure (command not found, ENOENT, nonzero
exit markers) now flags a row even when the provider item completed
"successfully", while the rendered row judges only its displayed result —
a command that merely greps for failure strings stays calm. Success now
also requires the failure check to pass, so recovered failures no longer
get the blue check.

The server half of #7893 needs no port: CodexAdapterV2 already projects
item.status directly, so a failed item never masquerades as completed.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(orchestration-v2): project linked pull requests on threads (#8160)

Main's thread↔PR linking never reached the v2 runtime: the client types
were optional stubs and the v2 server dropped the field, so linking a PR
on a v2 environment silently no-opped and #7454's settle-once logic could
never match the linked identity.

The link now flows end to end: thread.metadata.update carries an optional
linkedPullRequest (object to link, null to unlink), the orchestrator
folds it into thread state, and both shell builders project it — no
migration needed since v2 shells persist as payload JSON. The client
command sends the field and the shell mapper surfaces it, so the existing
web/mobile badge and settle plumbing light up on v2 threads.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(orchestration-v2): carry approval options and app names to the client (#8058)

Round 10 ported main's option-driven approval buttons, but v2 runtime
requests had no way to deliver the data — every approval rendered the
default button set, MCP app names never showed, and worse, the Codex
app-server's mcpServer/elicitation/request went entirely unhandled on the
v2 adapter, so ChatGPT-app access requests could never be answered.

The v2 approval_request turn item now carries optional appName and
options, the client derivation passes them into ThreadPendingApproval,
and CodexAdapterV2 handles mcpServer/elicitation/request end to end:
unsupported shapes decline immediately (mirroring the v1 runtime), and
supported ones surface a mcp-elicitation approval built from the shared
describeMcpElicitation/toMcpElicitationResponse helpers, so the persist
tiers (session / always) advertise exactly the choices the elicitation
can express.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(orchestration-v2): route Codex thread feedback uploads through v2 (#7949)

The round-10 rebase stubbed providerUploadFeedback to an explicit error
because its v1 ProviderService route died with the v2 rewrite. The route
now goes through the v2 runtime: session runtimes may expose an optional
uploadFeedback capability, the Codex adapter implements it against the
app-server's feedback/upload request, and the WS handler resolves the
thread's live provider session through ProviderSessionManagerV2 —
failing with a plain-language reason when no session has run, the session
is gone, or the driver has no feedback channel. This also un-blocks the
dormant mobile feedback UI.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(analytics): credit v2 threads and turns to the starting client (#7774)

Main records which client surface started each thread and turn; the v2
dispatch path replaced the v1 handler that did the recording, so v2
environments only reported connections. The v2 RPC layer now records
client.thread.started on thread launches (plus client.turn.requested when
the launch carries an initial message) and client.turn.requested on
message dispatches, using the connection's announced origin. Recording is
best-effort — attribution can never fail the user's command.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(grok): fail hung prompts on xAI rate-limit completions (#8358, partial)

Ports the rate-limit half of main's #8358 into the branch's reworked XAi
extension: a prompt_complete carrying stopReason rate_limit now fails the
hung prompt with the -32003 usage-limit error instead of settling it as a
normal end_turn, so the turn surfaces "usage limit reached" rather than
silently ending. The prompt-completion deferreds carry the error channel
end to end.

The exit_plan_mode approval gate from #8358 is NOT ported here: it needs
a v2 plan-flow design in AcpAdapterV2 (the v1 GrokAdapter it lived in is
gone) and is tracked separately.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(orchestration-v2): show live context usage in the meter (#8144)

The v2 context meter could only show token counts after a compaction had
already happened — v2 had no live usage plumbing at all, so main's
compaction-threshold UX was invisible on v2 threads. Provider turns now
carry an optional tokenUsage report: the Codex adapter maps the
app-server's thread/tokenUsage/updated notification (total breakdown +
model context window) onto the active provider turn, ChatView picks the
newest report out of the projection, and the meter prefers it over the
compaction fallback — so usage and remaining-context percentages update
while the turn runs.

Claude's v2 adapter does not report usage yet; its meter falls back to
compaction items as before.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): keep following the stream after returning to the live edge (#6519)

Ports main's anchor-release semantics onto the branch's timeline anchor
state: the scroll-to-end pill and a manual scroll back to the live edge
both drop the send-time anchored end space before re-enabling follow, and
the pill's scroll runs a frame later so the list measures without the
anchor space and lands on the true end. Without this the timeline could
settle into following-end with the anchor still installed — following
nothing.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(grok): capture exit_plan_mode into the v2 proposed-plan card (#8358)

Completes the deferred half of #8358: Grok's plan-approval gate now works
on the v2 runtime. The XAi extension regains main's exit-plan helpers
(request schemas, plan-markdown extraction, the abandoned-with-feedback
response, and the plan.md session-path sniffing), and the v2 ACP adapter
grows a captureProposedPlan primitive that emits a completed
proposed-plan artifact for the active turn — one plan id per turn, so
plan.md rewrites and the exit gate update a single card.

The Grok flavor wires both ends: tool calls that write plan.md under a
Grok session dir surface the plan while plan mode is still active, and
x.ai/exit_plan_mode (plus the underscore alias) captures the final plan —
request content first, then the sniffed plan.md contents, then the
empty-state placeholder — and abandons the native gate so the turn does
not hang, mirroring the Claude ExitPlanMode pattern.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): repaint the composer glass and strip the thread-panel popover chrome

Two post-rebase regressions from the round-10 index.css merge:

- The merge seam ate the closing brace of .chat-composer-glass, silently
  nesting the entire composer-glass section (shell, host, context strip,
  shoulder tab, banner cap) inside it as descendant rules that never
  matched — the composer surface stopped painting and thread content
  showed straight through the input. The brace is restored and the
  compensating over-close removed; every composer selector emits at top
  level again.

- The thread-details popover grew dropdown-glass card chrome around the
  panel: round 9 deleted the legacy components-layer .dropdown-glass rule
  in favor of the @utility, which the popover's border-0/bg-transparent
  suppressors no longer outrank (the utility emits later in the layer).
  The suppressors are now important variants, matching the !overflow
  override already there.

Verified against the emitted production CSS: shell::before is top-level,
no descendant-of-glass selectors remain, and the important suppressors
(including [backdrop-filter:none]!) are emitted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): adopt main's attached-composer surface contract so the glass survives shoulder tabs

The composer went frameless exactly when the stash or tasks badge was
showing: main's #7150 css hides the classic shell chrome whenever the
shell :has() a shoulder tab or top drawer and repaints the glass on
[data-chat-composer-main-surface] instead — an element the branch's
composer body never rendered, since it predates the drawer system while
the badges and css came through the rebase in main's new form.

The branch composer's frame div now carries the main-surface attribute
(with main's relative z-10 stacking) so attached mode paints background,
outline, and backdrop on it and the tab connects to the surface, and
ChatView applies chat-composer-glass-shell-attached while banner items
render in the drawer slot, matching main's externalComposerDrawerAttached
wiring. Without a tab or banner the attribute is inert and the classic
shell chrome paints as before.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): converge ChatComposer on main's drawer-era body

Round 10 restored the branch's pre-#7150 composer body while its
satellites (shoulder badges, banner drawers, glass css) arrived in
main's new form, and every seam between the two was a visible bug:
opaque/frameless composer, overflowing stash tab, detached stash menu.

Rebuilt ChatComposer via a reverse three-way merge (main's body as the
base, branch delta re-applied): dispatchMode send boundary, live-capable
approval gates, latestRun reads, and the v2 context-window meter stay;
everything else now matches main, including ComposerPrimaryActions and
the sendDisabledReason send gating. Attachment uploads stay off until
the v2 claim path lands.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): collapse settled tool runs behind main's summary toggles

The v2 timeline rendered every tool call as its own raw row; main's
tool-group collapsing (generated "Ran N commands and changed M files"
summaries, the live "Running <program>" pill for the active tool run,
and the "+N previous log entries" clamp for mixed groups) never made it
into the v2 row model.

Ported the work-live/work-toggle row kinds and group summarization into
the v2 derive, keyed on v2 item types (command_execution, file_change,
file_search, dynamic_tool, subagent) and runId lifecycle instead of v1
activities. Expanded groups keep the branch's richer per-entry detail
rows (V2ItemInspector) — only the collapsed presentation converges on
main.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): surface v2 todo-list plans as task progress

v2 already projected todo_list plan artifacts (deriveActivePlanState
existed with zero consumers), but nothing rendered them: todo_list turn
items showed as a bare "Updated tasks" work row, the composer Tasks
drawer never appeared, and the working row had no current-step label.

todo_list items now become inline turn-plan chips (mini step segments,
current step, N/M count, expandable step list) that fold with their
settled turn, ChatView derives the composer Tasks drawer progress and
steps from the running run's plan artifact, and the working row shows
"Working for Xs · <current step>" like main.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): show the command on collapsed tool rows, not its stdout

Collapsed command rows rendered "Command" plus the raw result JSON as
the preview; the command itself is the useful collapsed line, so it now
renders as the row text (whitespace-collapsed, truncated) with stdout
and the full payload behind the expander. Tool-like headings drop the
bold foreground for the muted secondary-label the summary rows use, and
the "+N previous tool calls" toggle loses its bold black label for the
same muted treatment.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): collapsed tool rows preview inputs for every tool type

Extends the command-row fix to the whole preview: file-change rows were
still leaking raw diff lines into the collapsed line. workEntryPreview
now resolves input-first — command, then touched-file paths, then
detail (which is input for the remaining types: search patterns,
reasoning text, error messages) — so outputs only appear behind the
expander.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: reconcile main's round-11 features after the rebase

Round-11 rebase onto main (25 commits). Reverse-merged main's new work
into the v2 cutover files: #8395 muted ordinary-tool-failure treatment
(v2-adapted workEntrySignalsSevereFailure keyed on error items), #5931
sidebar project-filter combobox + #4c51 keyboard pin/settle with their
ChatView support graph, the auto-settle-mode migration through
threadSettled/threadListV2, #8235 file/unknown attachment schemas moved
into chatAttachment.ts with nullable attachment paths, #8481 client
analytics through the v2 ws layer, #8480 OpenCode server owner wired
into the driver beside the v2 orchestration adapter, and the mobile
semantic-theme migration applied to branch-only components.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(opencode): route child-session approvals through the v2 adapter

Ports the v2-applicable half of #8480 (the v1 adapter rewrite was not
carried; this branch's OpenCode path is OpenCodeAdapterV2). Permission
and question asks from child sessions — task subagents and their
descendants — were dropped because the adapter only looked up root
thread sessions. Related sessions now map back to the owning root
state (registered from task parts and session.created/updated parent
chains), and an ask that arrives before the relation is known resolves
it inline via session.get with a short forked backoff, then surfaces
the approval on the root turn. Replies already route by native request
id. Interrupts now tolerate the abort racing turn settlement instead
of failing the stop.

Covered by a new opencode_child_approval replay fixture where the
child asks for bash permission before the task part reveals the
relation.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: reconcile main's round-12 features after the rebase

Small rebase onto main (4 commits). The composer stash-shortcut label
and the mobile start-task menu refactor merged onto the v2 composer
bodies, and main's new auto-settle list tests are ported to the v2
thread-list test file (latestRun/RunId shapes). The auto-settle
machinery itself already matched main from the round-11 reconcile.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: restore main's automatic thread settling after the revert

Round-13 rebase onto main (2 commits). Main reverted the auto-settle
opt-in (#8596 undoing #8321), so the branch drops the ported
autoSettleMode machinery and returns to sidebarAutoSettleOnMerge with
settling-by-default, keeping only the v2 shell-shape delta in
threadSettled. The unpin confirmation (#7313) merges into the v2
thread-actions hook, and the mobile list tests re-sync to main's
reverted semantics in v2 shapes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): restore the full-screen file-drop target over the chat column

Main's #6636 workspace file drop (drag anywhere over the chat column to
attach, with the dashed overlay) split across ChatView and the
composer. The round-10 rebase restored ChatView from the pre-#6636
backup wholesale and only the composer half was ever re-applied, so
the drop target, overlay, and drag-state plumbing vanished while
addDroppedFiles sat unused on the composer handle. Re-applies main's
ChatView half verbatim; the shared workspaceFileDrop module was
already identical to main.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(server): claim uploaded attachments at v2 dispatch

Closes the last gap from the rebase follow-up list (#8048/#8161 for
v2): pending uploads staged via the attachment upload URL flow were
never claimed by the v2 orchestrator, so the composer kept
supportsAttachmentUploads off and fell back to inline dataUrls with no
progress UI and no big-file support.

message.dispatch and thread.launch now claim pending refs at intake —
verify the staged file, copy it under a thread-scoped id (the pending
copy stays as the retry source), rewrite the refs, and release the
claimed copies if the dispatch fails. A launch carrying uploads
requires its thread id up front. The web composer reads the
attachmentUploads capability again like main, which lights up the
upload progress overlay, retry-on-failure, and PDF/ZIP attachments.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(web): show attachments on queued messages and edit them in the composer

Queued rows now render image thumbnails, and the pencil action loads the
queued message into the composer instead of an inline input: text and
stored attachments are editable (attachments removable, new images
addable), sending saves the queued run in place, and the user's own
draft is stashed untouched for the duration. queued-run.edit gains an
optional full-replacement attachments list end to end.

Built by Claude Fable 5 on Claude Code.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): drag-to-reorder queued messages and retire stale pending rows

Replaces the queue rows' up/down arrow buttons with a drag handle (arrow
keys still work on the focused handle). Also prunes optimistic queued
messages once the projection holds them: keying the prune on turn items
alone left a phantom clock row behind whenever a queued run was removed
or steered before it ever started.

Built by Claude Fable 5 on Claude Code.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: reconcile main's round-14 features after the rebase

Round-14 rebase onto main (7 commits, mostly the Expo SDK 57 upgrade
plus the mobile glass restore and codex app-server buffering fix). The
mobile composer merged main's restored glass chrome onto the v2 body,
and the lockfile is regenerated from main's SDK-57 lock with the
branch's extra dependencies installed on top.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): dedupe the composer glass styles and align the chat column width

The rebase left a stale early copy of the composer glass-host, context-strip,
and shape() fallback rules that the identical later block always overrode.
The composer shell and queue/context strips also kept main's 48rem width while
the timeline moved to the 46rem content lane; they now share
--chat-content-max-width so one owner defines the chat column.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(mobile): replace remaining dark: utilities with adaptive semantic tokens

The v2 thread surfaces still styled borders, fills, and status text with
dark:/light: pairs, which do not follow registered custom themes and now fail
the no-mobile-uniwind-theme-escape-hatches lint. Convert them to adaptive
tokens, adding the missing amber/sky badge and neutral hairline/fill entries
to the theme generator.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(lint): allowlist the queue and relationships interop boundaries

ThreadQueueControl and ThreadRelationshipsBanner read theme variables only to
tint SymbolView icons and color native modal chrome, the same reviewed interop
pattern as the existing thread-feed entries.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(server): inject HostProcessPlatform into the Grok plan extractor

The plan.md path check read process.platform and process.env directly; thread
the host platform reference and the adapter's provider environment through
GrokAdapterV2Options instead.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* chore: retrigger ci

The pull_request workflows never fired for 6c3b84bbfc; only the
pull_request_target ones ran.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* chore: refresh macroscope ui-consistency check

Its findings were fixed in 9abca06b28 and the review threads are resolved;
the check only re-evaluates on push.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: reconcile main's round-16 features after the rebase

Round-16 rebase onto main (5 commits, headlined by #8236 file
attachments in the client). Main's upload-aware send path — capability
probes, upload await/retry gating, uploaded-ref turn attachments with
dataUrl fallback, draft release on success — is woven into the v2
dispatch flow, timeline user rows render file attachments as download
links with the ChatView download handler, and the provider settings
editor cleanup keeps the branch's environment-field rows. The codex
feedback client flow stays unported, replay testkit configs gained
main's environmentThemesDir, and the rpc/settings/docs unions carry
both sides.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): keep failed tool items in the collapsed group summaries

An ordinary exit-code failure knocked its whole tool group out of the
"Ran N commands" summary (and the live pill mid-run) into the raw
"+N previous tool calls" clamp: v2's derived tone marked any
status=failed item as "error", which the grouping treats as a non-tool
row. That inverts v1's semantics and #8395's muted-failure rule — the
failed lifecycle status already carries the X marker and the summary's
includes-a-failure hint, so the tone override goes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(server): keep Claude session approvals ephemeral

R03: Rescope Claude permission suggestions to the current session and add a whole-tool session rule when the SDK provides no suggestion.

* fix(orchestration): reanchor unsettled threads

Carry unsettledAt through v2 thread state and shells, stamp explicit and activity-driven reactivation, and clear the stamp when settling.

Finding: R11

Implemented by GPT-5.6 Sol in Codex.

* fix(server): observe pre-aborted Claude approvals

R15: Race Claude approval decisions with cancellation while checking already-aborted signals and cleaning up the listener on every exit.

* fix(server): include service launcher in bundle build

Build the service launcher after the clean CLI pack so publish and background-service installation receive the required artifact.

Audit: R01

* fix(orchestration): preserve legacy thread metadata

Import pin order, snooze state, unsettle time, and linked pull requests. Repair prior imports only where the stored v2 property is absent, so later v2 changes remain authoritative.

Finding: R08

Implemented by GPT-5.6 Sol in Codex.

* fix(web): honor disabled legacy plan mode

Force the effective composer interaction mode to build when the legacy plan setting is off, including threads and drafts with a saved plan mode.

Audit: R13

* fix(server): preserve Claude subagent models

R16: Apply authoritative assistant snapshot models to Claude subagents and buffer snapshots that arrive before task_started.

* fix(orchestration): honor migrated thread visibility in search

Use v2 ownership and lifecycle metadata when a legacy transcript belongs to a migrated thread. Legacy transcript rows remain searchable until lazy hydration finishes.

Finding: R09

Implemented by GPT-5.6 Sol in Codex.

* fix(orchestration): recreate missing worktrees before turns

Prune stale git worktree registration and recreate the saved branch at the saved path before provider startup. Recovery remains best effort so normal provider errors still report when repair is impossible.

Finding: R10

Implemented by GPT-5.6 Sol in Codex.

* fix(clients): restore Codex feedback submission

Intercept /feedback in web and mobile, show the upload result and feedback ID in the thread, and block duplicate submissions while an upload is active.

Audit: R12

* fix(server): preserve generic provider attachments

R02: Append persisted paths for every uploaded file on provider sends and steering while reserving native image payloads for supported images.

* fix(web): load workspace markdown images through assets

Classify markdown image sources and request environment-scoped asset URLs for workspace files while leaving ordinary web images direct.

Audit: R17

* fix(web): preserve Windows markdown paths

Normalize drive-path links and image sources before sanitization so file chips and signed workspace images receive usable paths.

Audit: R18

* fix(server): keep current provider context usage

R07: Project Codex last-turn and Claude assistant context usage, and retain the latest usage when terminal provider-turn updates omit it.

* fix(web): restore markdown file chip actions

Keep ordinary file-chip clicks in the in-app preview while restoring modifier-click editor opening, configured editor labels, remote gating, and reveal-in-file-manager actions.

Audit: R19

* fix(web): scope markdown actions to their environment

Use the owning thread or pull request environment for editor, shell, and remote-open actions instead of whichever environment is active. Add a multi-environment regression test for the action hooks.

Audit: R20

Implemented by GPT-5.6 Sol with Codex.

* fix(protocol): reject incompatible orchestration peers

Advertise and validate an explicit orchestration protocol before clients open RPC sessions. Announce the same protocol on WebSocket upgrades so hosts reject older clients before request decoding while preserving existing auth and relay parameters.

Audit: D03

Implemented by GPT-5.6 Sol with Codex.

* docs: explain legacy thread migration

Document which thread metadata and transcript data migrate, which runtime history does not, and how the fresh provider continuation uses the latest 32,000 characters. Add a safe read-only recovery procedure without claiming an export API.

Audit: D02

Written by GPT-5.6 Sol with Codex.

* docs: state portable handoff limits

Explain the eligible timeline items, whitespace-normalized 240-character prefixes, omitted tail risk, and practical preparation for provider or fork handoffs. Distinguish this rule from the legacy import's 32,000-character transcript suffix.

Audit: D04

Written by GPT-5.6 Sol with Codex.

* chore(repo): remove tracked audit scratch files

Remove obsolete implementation plans and the probe write marker so temporary work artifacts no longer ship with the repository.

Audit: H01

Implemented by GPT-5.6 Sol with Codex.

* fix(server): guard OpenCode prompt admission races

R14: Hold idle completion through prompt admission, reconcile status only for the current admission generation, and invalidate admission before abort.

* fix(server): restore Claude structured questions

Project AskUserQuestion as a structured user-input runtime request and return keyed answers to the Claude SDK instead of routing the tool through generic approval.

Finding: R04

Model: GPT-5.6 Sol via Codex

* fix(server): project Claude plans and todos

Translate TodoWrite and ExitPlanMode tool input into canonical todo-list and proposed-plan artifacts so every client can render Claude planning state.

Finding: R05

Model: GPT-5.6 Sol via Codex

* perf(orchestration): bound history reads in SQL

Load at most one turn-item page per thread in a fork lineage before decoding, keyed by the stable history cursor. Restrict message, plan, and handoff reads to that page plus live actionable state so cold opens and older-page requests no longer decode complete historical tables.

Finding: P01

Implemented by GPT-5.6 Sol in Codex.

* perf(orchestration): bound complete thread snapshots

Budget the serialized bounded projection after retaining live control state. Cap historical control arrays and large plan or handoff details only on the bounded route; the full thread-detail route remains available for complete text.

Finding: P02

Implemented by GPT-5.6 Sol in Codex.

* fix(server): restore Claude resume compaction

Pass the automatic compaction window to Claude and route resume-return dialogs through structured user input so users can compact, continue, or permanently dismiss the prompt.

Finding: R06

Model: GPT-5.6 Sol via Codex

* fix(server): allow protocol negotiation in CORS

Permit the canonical orchestration protocol header in browser API preflights so cross-origin web and desktop clients can negotiate compatibility while retaining authorization and DPoP headers.

Finding: D03

Model: GPT-5.6 Sol via Codex

* fix(server): preserve provider usage in persisted turns

Merge terminal provider updates with stored context usage before replacing the SQLite payload. Keep newer usage reports authoritative and verify the persisted projection after reload.

Finding: R07 follow-up

Model: GPT-5.6 Sol via Codex

* fix(server): preserve Claude planning lifecycle

Keep typed plan and todo records distinct from generic tool events, activate captured plans, and supersede older planning state within the owning thread. Ignore nested todo snapshots for the parent and retain identity across duplicate SDK messages.

Finding: R05 follow-up

Model: GPT-5.6 Sol via Codex

* fix(server): normalize Claude question answers

R04 follow-up

Convert client multi-select answer arrays to the comma-separated string shape required by the pinned Claude SDK while preserving single-select strings.

Implemented by GPT-5.6 Sol via Codex.

* fix(server): correlate OpenCode prompt admission

Stale cached user and status events could admit and complete a newly submitted OpenCode prompt. Generate the native message ID before submission and only advance admission when that exact message is observed.

Finding: R14

Implemented by GPT-5.6 Sol with Codex.

* fix(clients): anchor feedback in conversation order

R12 follow-up

Insert persistent feedback blocks by their timestamp within the canonical timeline while preserving projected row order. Keep real optimistic sends appended and suppress duplicate local messages already committed by the server.

Implemented by GPT-5.6 Sol via Codex.

* fix(web): retain markdown workspace ownership

R20 follow-up

Give inspector reasoning markdown its projected source thread and retain the explicit environment fallback for proposed plans without a thread reference. Workspace links and images now resolve through their owning environment after removal of the active-environment fallback.

Implemented by GPT-5.6 Sol via Codex.

* fix(orchestration): page history through its true end

Read the inclusive cursor, a full history page, and a look-behind row so older history does not terminate after one page.

Finding: P01 pagination termination

Model: GPT-5.6 Sol via Codex

* fix(server): cancel pending OpenCode prompts safely

Cancel pending SDK requests before aborting the native session. Preserve per-admission cancellation state and treat stopped initial prompts as interruption instead of provider failure.

Finding: R14 prompt cancellation

Model: GPT-5.6 Sol via Codex

* fix(orchestration): retain nested fork history when paging

Keep the original cursor owner through ancestor traversal and preserve the history budget across empty intermediate forks. Verify exact paged history against the complete nested projection.

Finding: P01 nested lineage

Model: GPT-5.6 Sol via Codex

* fix(server): recover OpenCode status reconciliation

Retain pending admission after transient status failures and use one generation-owned retry worker. Ignore stale timers and duplicate evidence so older prompts cannot finish newer steering.

Finding: R14 status reconciliation

Model: GPT-5.6 Sol via Codex

* fix(orchestration): select visible history before limiting SQL

Keep hidden local and inherited rows from consuming history pages. Preserve stop-request dependencies, source-run cutoffs, and imported history while loading related metadata from the selected cohort and using indexed watermark lookups.

Finding: P01 bounded history visibility

Model: GPT-5.6 Sol via Codex

* fix(web): port composer activity and grouping to orchestration v2

* fix(web): align queue headers and prevent stash overlap

* fix(web): share the outline for joined composer tabs

* fix(web): keep stash separate from the composer activity column

* refactor(web): use shared banner rows for queued messages

* fix(web): keep queued message editing inside the queue panel

* fix(web): keep queued messages in place while editing

* fix(web): match composer actions to draft and modifier state

* fix(web): keep composer shortcut tooltip stable on Mod

* feat(web): summarize T3 orchestration actions

* feat(mobile): port chat summaries and transitions to orchestration v2

Adapt grouped tool summaries and the floating working timer to V2 run, attempt, and queue state. Bring over the composer, keyboard, and disclosure transitions while retaining the V2 activity inspector and queue controls.

Keep OV2 web composer and grouping behavior intact; share only the existing command label parser with mobile.

* fix(chat): remove added tool summary status counts

* fix(mobile): keep scroll bounds current after animations

* fix: reconcile main's round-17 features after the rebase

Restores main features dropped by the policy replay: #8569 theme wiring,
settings search rework, #8803 workspace-mutation refresh (v2-adapted),
video + image previews (web and mobile, v2-adapted), #8862 Expo glass,
and the round's docs. Timeline thinking rows (#8984) stay on the v2
work-live system.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(web): port working and thinking timeline rows to orchestration v2

The v2 equivalents of main's #8984 and #8922: a "Working for ..." header
anchors the active run, the trailing live tool row survives between
actions in past tense instead of vanishing, and a shimmering Thinking
row marks reasoning gaps. During workspace preparation the header shows
"Setting up worktree..." (driven by the local dispatch flag or the v2
run's preparing status, so remote viewers see it too), the composer
footer span is gone, and draft promotion waits until the run starts or
startup fails instead of navigating mid-preparation.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: reconcile main's round-18 features after the rebase

Adopts the round's main features into the v2 architecture: the #9023
media rework (streamed videos, media-file assets, protocol-relative
links), #9098 shared live-activity row folded into the v2 working and
thinking rows, the #9084/#9078 Claude model catalog for v2 consumers,
a native #9005 OpenCode child-session abort in the v2 adapter, #9013's
landed LegendList patch, and per-environment sidebar provider entries.
For #8600 the server-side pieces land, but auto-settle evaluation stays
client-side (reading the new server-owned settings) until the v2
orchestrator grows its own settlement reactor; main's v1-only reactor
and coalescer additions are dropped with the rest of the v1 path.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(server): evaluate automatic thread settlement in the v2 orchestrator

Ports #8600's server-owned settlement to orchestration v2 instead of
keeping client-side evaluation. A ThreadSettlementService sweep runs at
startup, on auto-settle settings changes, and once per minute: it
evaluates inactivity and merged or closed pull requests over v2 thread
shells and dispatches the new guarded thread.auto-settle command, which
rejects threads that changed after the sweep's snapshot or carry any
explicit override, then reuses the orchestrator's settle lifecycle.
With the server deciding, the clients drop their effectiveSettled
evaluation and partition on the persisted settledOverride like main.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: reconcile main's round-19 features after the rebase

Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): right-align the stash shoulder tab again

Round 17 adopted main's #8850 ComposerBanner.Attachment (mx-auto plus the
standalone drawer-inset width) without main's matching mounts, so the
stash tab's ml-auto lost to the attachment's auto right margin and the
tab centered over the composer. Column now spans its attachments like
main does, the stash tab zeroes the right margin, and the stash menu
keeps the full dock width.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): realign the composer and timeline with main

The branch had drifted from main's composer and work-log design in ways
unrelated to orchestration v2: a pre-revert "Working for" shoulder tab
on the composer (main reverted #8693 and re-landed #8734 without it),
an inline stash variant plus in-flow stash menu, expanded tool rows that
hid their icons, an unmounted woke-thread banner, a composer scroll
observer main never had, and a right-panel toggle that lost its
showRightPanelControl gate so it rendered twice with the panel open.

ChatComposer and its satellites now start from main's files with only
the v2 delta re-applied (dispatch modes, queued-message editing, runtime
request ids, response capability). Background tasks surface as a
ChatView banner in main's backgroundLiveness shape instead of a
composer tab. SimpleWorkEntryRow takes main's PlainWorkEntryRow body
with the V2ItemInspector kept behind the expander.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: reconcile main's round-20 features after the rebase

Renumbers the v2 migrations 044-052 to 045-053 behind main's
044_ClearAutomaticProjectModelDefaults, and adopts main's sticky
new-thread selection (#9164), local-only worktree bases in the v2 launch
path (#8751), the PR summary read for settlement (#9176), Claude per-cwd
skills (#9210), the provider editor redesign with the branch's dedicated
environment fields re-grafted (#8508), and the client half of
continue-threads-across-restart (#9167). The server-side continuation
markers stay unported: they live in the v1 session directory, and v2
recovery terminalizes running runs on restart, so the capability is
withheld until the v2 runtime carries them.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(server): reduce v2 recovery and runtime resource usage

Index event sequence lookups, recover only threads with pending work, and page projection verification and rebuilds. Bound provider event logging and omit turn histories when resuming Codex threads.

Allow delegated thread identifiers through relay routes. Add focused regression coverage and document the performance constraints.

* fix: reconcile main updates with orchestration v2

Retain main's composer, work-log, settings, mobile and performance changes through c8f77e0d441 while preserving v2 runs, queued messages, provider handoffs and durable history.

Port native compaction and logout, asynchronous Codex questions, provider usage accounting, automatic settlement and PR refresh into the v2 services. Bound live event retention during replay and delivery, measure thread replay before decoding, and read checkpoint metadata without loading transcripts or patches.

Keep main migrations through 047 and move the v2 migrations to 048–058. Preserve the existing branch history and the pre-rebase backup.

Model: GPT-6. Harness: Codex.

* fix(orchestration): stabilize Codex turn mapping and settlement

- Preserve Codex turn identity while suppressing duplicate diff notifications
- Optimize settlement projections and isolate thread visit hand…
@0xOmarA

0xOmarA commented Sep 23, 2026

Copy link
Copy Markdown

@juliusmarminge @maria-rcks @t3dotgg Is there any chance that the cite button could be placed above the text?

I always select text as I read it and right now the cite button always gets in my way of reading the text. Sometimes it's placed on the same line I'm reading and sometimes it's placed on the next so it ends up blocking text that I'm yet to read.

juliusmarminge added a commit that referenced this pull request Sep 23, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 23, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 24, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 24, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 24, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
juliusmarminge added a commit that referenced this pull request Sep 25, 2026
Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL 1,000+ changed lines (additions + deletions). vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants