From d0f42f303f6debeca6070a92493c9b97018e9dce Mon Sep 17 00:00:00 2001 From: Trevor Walker Date: Sun, 20 Sep 2026 13:57:00 -0600 Subject: [PATCH] docs(upstream): record Cycle #685 adoptions in review ledger --- .agents/upstream-review.md | 35 ++++++++++++++++++----------------- 1 file changed, 18 insertions(+), 17 deletions(-) diff --git a/.agents/upstream-review.md b/.agents/upstream-review.md index 8dbe76c89..602df84cb 100644 --- a/.agents/upstream-review.md +++ b/.agents/upstream-review.md @@ -15,11 +15,11 @@ The maintainer authorized compatible catch-up and routine adaptations that prese ## Active cycle -[Upstream integration cycle #682](https://github.com/pylon-code/pylon/issues/682) covers web interaction fixes, ACP diagnostics, and Claude continuation through bounded upstream head `7445aa733ada33e45289e5aa5055f79142556513`. Pylon head at open `ee01ed60b09333939e48f362afa4601ce8285a13`. Review cursor stays at `bbedad0278bbf753503184c00e0c09a0eab6679c`. +None currently active. Upstream integration cycle #685 is completed. ## Latest cycle -[Upstream integration cycle #669](https://github.com/pylon-code/pylon/issues/669) completed chat message accessibility (PR #679) and compact sidebar rail & density modes (PR #680) through upstream bound `b44c1ce5d25ee0d5a5be82e380618a886c19ea96`. Previous cycle [#667](https://github.com/pylon-code/pylon/issues/667) completed web chat rendering (PR #668, DEF-18) and navigation/diff safety (PR #671). +[Upstream integration cycle #685](https://github.com/pylon-code/pylon/issues/685) completed web chat/diff/citation polish and external editor discovery (PR #686), and server PR diff cache eviction, ACP SDK elicitation, Codex app permission approvals, and preview host recovery (PR #687) through upstream bound `c14f6015bfe479d313355cb234af1a5c16dbb15f`. Previous cycle [#682](https://github.com/pylon-code/pylon/issues/682) completed web interaction fixes (PR #683) and runtime fixes for Claude homePath, ACP stderr, and GTK4 snapshot text (PR #684). Previous completed cycles: [#526](https://github.com/pylon-code/pylon/issues/526) through `d1d15c67f4a5fb82fd8d5e01e5e3b288296789c3`, [#516](https://github.com/pylon-code/pylon/issues/516) through `b1e223e2b0d87124883b1410ab52dd6a1338e40d`, [#497](https://github.com/pylon-code/pylon/issues/497) through `4a4c6dd2adc350a68ba18bb28b24b5a7e4660dab`, and [#414](https://github.com/pylon-code/pylon/issues/414) through `6c583620ff7ad3235b135af7107c0543467eecfa`. Their trigger audits and exclusions describe those cycles' closure state; current dispositions below supersede them. Follow the skill's [continuation procedure](skills/review-t3-upstream/references/continuation.md), checking the issue against Git and GitHub before acting. @@ -33,21 +33,22 @@ New records use the compact group format in [the decision framework](skills/revi Historical groups are indexed in the linked archive. This file migration changes no source disposition, review cursor, deferred trigger, watch state, product code, or Git ancestry. -| Group / bounded head | Sources | Outcome and remaining scope | Pylon PR / verification | -| -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Web interaction, ACP session startup stderr, Claude continuation, and GTK4 snapshot / `52d08a14b9cbff859d044238e8ec4e1cb5bf4d50` | `8dd02470b1e7603b8d36a21ae27c510480351f18` (#12552), `7445aa733ada33e45289e5aa5055f79142556513` (#11263), `599c9776eb887d4fff42da7d2daf8aa07ee9a9e2` (#11268), `dcf8942304cfef382af55c0068cb2f04c86757fc` (#12636), `e36725682bd2935f1bcfdf81660cb569b5f3df29` (#12577), `63ff33756c714e8687ea71a3bc8aa4e9303503f1` (#12624), `d6f291303d7c3ebcbfe8eeae5d6666ecbc4d20ae` (#12625), `52d08a14b9cbff859d044238e8ec4e1cb5bf4d50` (#12635) | Adopted all eight across Cycle #682 Group A (PR #683) and Group B (PR #684). Preserved draft question input when clicking options, desktop CSP screenshot annotations, restored providers settings heading, aligned PR detail menu glyphs. Empty Claude homePath correctly resolves and shares continuation with `~/.claude` or `CLAUDE_CONFIG_DIR`, surfaced ACP stderr excerpt in session startup failures instead of generic closed session errors, and extracted desktop accessible text for Flatpak and GTK4 apps in SnapShot. Adversarial review findings resolved: ACP stderr excerpt sanitized against tokens/credentials and pending buffer bounded; defensive empty `homePath` trimming and `CLAUDE_CONFIG_DIR` resolution in OAuth usage; desktop accessibility timeout preserved without premature concurrency overlap. Preserved Pylon provider rate limits and error reporting. Cursor unchanged. | Cycle [#682](https://github.com/pylon-code/pylon/issues/682), [PR #683](https://github.com/pylon-code/pylon/pull/683) and [PR #684](https://github.com/pylon-code/pylon/pull/684); independent adversarial reviews, 225+ focused tests across desktop and server, full workspace typecheck, scoped format/lint. | -| Chat message heading accessibility and compact sidebar density / `b44c1ce5d25ee0d5a5be82e380618a886c19ea96` | `6cdbf76fa4b0509913046abe6105037ded9e52bb` (#11199), `ca2cc1339bbd1904b932c3a92d23a2c0ffe1d267` (#11525), `77bca8b2d76a1f42552e5eee7d277fcb1160347a` (#9417), `df7ccc8fd01f5d2a1d8ec21bef8f9c59398fe913` (#11644), `7b61099886f3aac139ad43fb73873c73ba7baf4f` (#11652), `0118b522955f190e292ba578a509177b9605d392` (#11595) | Adopted all six across Cycle #669 Group A and Group B. Screen readers navigate chat messages as headings with hierarchical levels (`h3` at offset 3); proposed plans expose semantic headings. Compact sidebar rail (`compactSidebarEnabled`) and compact thread row density (`sidebarCompactThreadRows`) added as opt-in settings defaulting to `false`, preserving Pylon's pull request badges and stack integration, custom settings, and avoiding dead delegation UI. Sparse shelves stay pinned to bottom. Adversarial review findings resolved: accessible fallback for `plan-ready` dot in compact rows, drag layout projection fix for compact rail mode, explicit test fixtures. Cursor unchanged. | Cycle [#669](https://github.com/pylon-code/pylon/issues/669), [PR #679](https://github.com/pylon-code/pylon/pull/679) and [PR #680](https://github.com/pylon-code/pylon/pull/680); independent adversarial reviews, 490+ focused tests, `@t3tools/web`, `@t3tools/desktop`, and `@t3tools/contracts` typechecks, scoped lint/format, green CI. | -| Navigation, search and diff safety / `b44c1ce5d25ee0d5a5be82e380618a886c19ea96` | `9ea9c3d5d2c444133e3ddff40eecf38737951589` (#11075), `886c83450797c46ee84ae28fc16c2208cafa965e` (#10909), `c557bb10aa7cbb78a50df230d1e8e24af79cb662` (#11761), `3fd5d6439d8fd49d173503ecda96500463a39bd2` (#12315) | Adopted all four in Cycle #667 Group B. Symlink file type changes no longer crash diff view; chat folder links reveal directory in file tree; sidebar search matches thread message contents; numbered jump shortcuts do not steal browser tab navigation. Preserved Pylon's keybinding identity, routing and panel-choice semantics. Cursor unchanged. | Cycle [#667](https://github.com/pylon-code/pylon/issues/667), [PR #671](https://github.com/pylon-code/pylon/pull/671); 389 focused tests, web/shared typechecks, scoped lint, green CI. | -| Composer banner density and scroll-pill stability / `b44c1ce5d25ee0d5a5be82e380618a886c19ea96` | `4749035bda13b4b6260499caedbc0d69a2f60e6f` (#12166), `fcfd9f911a27ee3b813d64582c53d82dfa2e892b` (#12317) | Adopted both. Banner stack items gain an optional `compact` flag: compact rows keep the narrow layout and the description that collapses into an info popover below 400px, while other banners get room for the description beside the title, with a labelled, bounded, scrollable popover. The scroll-to-end clearance is split out of the overlay-height publisher and recomputed from a stored height when the pill mounts, so a fling during the composer's resting tween no longer publishes a stale height and yanks the scroll position. **Excluded:** upstream's `approval` banner layout classes — Pylon's `ComposerBanner.Row` union is `inline | wrap-actions | wrap-actions-narrow`and the approval layout arrives in an unadopted commit; only this source's`justify-end`change was applied. Pylon adaptations:`ComposerTasksBadge`keeps its delegates label, expanded guard and`TaskProgressSegments fit`, with the delegates label moved to the same container query as the segment bar so the pair no longer flips at different widths; `ChatView`'s pull-request resolution block is preserved; and five Pylon banners with short static descriptions (environment update, thread woke, snoozed/settled, resume-compaction, auto-balance) are marked `compact` so they do not grow a permanently redundant details popover. Cursor unchanged. | [Chat rendering #668](https://github.com/pylon-code/pylon/pull/668); independent adversarial review, 184 focused tests including new `compact` coverage, `@t3tools/web` typecheck, scoped lint. Two upstream-inherited defects recorded in the PR rather than fixed here. | -| Checkpoint capture reliability and shared-workspace rewind / `93e04160a0c0dece8a258384d2118a660415a53d` | `869347bc26051bba7c3c0274a7dfcae7770d3e3a` (#11665), `1455cb5c35e50211145073be6ca155d56684f0f4` (#12181), `67993623afb14c017bb0b959478dc892f9c427da` (#12307), `b4620d595554654c259ec7c0afb3d3d5532959a8` (#12306), `d17f46d7631b178b6834596264f0f44f210d584b` (#12308) | Adopted all five. Transient git exits retry during capture behind a new optional `retryable` hint on `VcsProcessExitError`; capture recovers nested repositories without commits under index-lock recovery and bounded probe timeouts; a failed baseline lookup logs and treats the ref as absent instead of losing the checkpoint; the `@`-mention entry refresh moves to a coalescing drainable worker chained into `CheckpointReactor.drain`. File rewind is refused unless the thread's cwd is its own worktree with no other thread or live provider session nested inside or above it, and web hides the destructive control for shared directories. **Capability removal, maintainer-approved 2026-09-18**: threads running in the project directory rewind the conversation only, with no override path. Pylon adaptation: the isolation check is scoped with `restoreFiles !== false` so conversation-only rewind still reaches Pylon's existing provider-capability explanation rather than the isolation message or silence, since Pylon's rollback saga services are optional. Pylon git identity, rollback revert action and wire compatibility preserved. No excluded source behavior; cursor unchanged. | [Checkpoint reliability #665](https://github.com/pylon-code/pylon/pull/665); 122 focused tests including three new `restoreFiles` regressions where none existed, `t3`/`contracts`/`web` typechecks, scoped lint (0 errors), rebased onto `origin/pylon` after #653. | -| Provider event log bounds and Codex image attachments / `93e04160a0c0dece8a258384d2118a660415a53d` | `b17cc2ab5d5029f898121798ca19db3288cba616` (#12305, partial), `3fd21df62da3191f1abf12a0cd74df6de9ed30a2` (#11050) | `3fd21df62d` adopted: Codex image attachments pass as `{ type: "localImage", path }` instead of base64 data URLs, so `turn/start` no longer scales with file size. `localImage` is a real content type in the generated Codex app-server schema; Pylon's attachment-id validation against `attachmentsDir` and its `FileSystem` wiring are retained. `b17cc2ab5d` **partially adopted**: record traversal is bounded before serialization with character, field and depth budgets, cycle detection, a `summarizeProviderEvent` fallback that keeps routing and failure fields, and a post-serialization byte-length fallback; new transient suppressions for `turn/diff/updated` and `stream_event`/`content_block_delta`. Pylon's `commitGuard` and existing transient filters preserved. **Excluded: the `stage === "raw"` suppression and `stage === "decoded"` unwrap** (see EXC-1). Cursor unchanged. | [Provider payload bounds #653](https://github.com/pylon-code/pylon/pull/653), merged `4be539f4d48af6ffbe545e015ec246fbb271c92e`; 133 focused tests, `t3` typecheck, scoped format/lint, all final-head CI jobs green, no bot findings. | -| PR comments, controls and avatars / `6d1d549441be84f19696ab59ed7e2fbf305280d4` | `f0a0ead946ca3f3f310460a91b7dabb0e3fe4834` (#11962), `f45c6b4a755905485431872f4a4188de3ed05974` (#11994), `c12ba7581ac00ba2a623ad23283da5d03d34c2d8` (#12150), `962bf62921c0ecbc9320f9b071e16b1d41484aad` (#12125), `df466c79810046d20c0f3ccc4e51709c5703814e` (#11728) | Adopted all five. Narrow controls, keyboard submission, paged bot/finished groups, long-comment previews, detail avatars and image-failure fallback. Pylon corrections align bot app links, lazily page finished groups, and scroll after collapsing. Optional actor metadata preserves wire compatibility; existing bounded GitHub enrichment/fallback limits remain. No excluded source behavior; cursor unchanged. | [PR review #621](https://github.com/pylon-code/pylon/pull/621); focused regressions, scoped types/lint, independent Opus adversarial reviews, browser before/after evidence and comment interaction recording. | -| Large diffs and review panel defaults / `6d1d549441be84f19696ab59ed7e2fbf305280d4` | `aae361c4ef6478e4dcf970d574f3fd38d908e6b9` (#10822), `36caf200c2b24c12838570966f5c85786a1fc1f8` (#11484), `3efdcc5296f1754e0f3bf7fee5fc2ada510e0438` (#11931), `6d1d549441be84f19696ab59ed7e2fbf305280d4` (#12190), `52ad70ec43b5dcfcdc72ac79c0964da8e4d163db` (#12142), `394af73e02238e551db14f44d57f1469dd2942aa` (#12139) | Adopted all six. Complete Git metadata and progressive per-file patches on web/mobile; preserve old-server preview fallback, literal paths and bounded output. Tree order/folder state survive refresh. Files default collapsed while explicit saved choices persist. Generic diff openings reset to working tree; linked PRs outrank automatic diffs. Preserve Pylon multi-PR authority, environment identity, responsive layout and existing settings. No excluded source behavior; cursor unchanged. | [Review diffs #616](https://github.com/pylon-code/pylon/pull/616); 509 integrated focused tests plus 79 unchanged backend regressions, six scoped package typechecks, lint, independent Antigravity adversarial reviews, before/after browser evidence and refresh video. Native verification details in PR. | -| Usage pools, hub quotas, reset credits and local composer action / `062987b2fb0ef48cc7776d654931bd9f3bcf1f9f` | Full 16-source list in the usage pilot PR; parent `19d8ab2ae9fc562ee7b216a0d72903fbfafa9572`, final hub-routing fix `6abdf37a50ce6c1c9fabc499f4d0e159a6182d90` | Pylon port of the final behavior; parent partially adopted with native Claude scoped push mapping retained in DEF-16. `00d6109cbb1a13712d7347701969870aee83252d` is covered: demo fixtures were never introduced. Native Claude quota reads reuse Pylon's cached OAuth parser; no duplicate SDK probe or ingestion worker. | [Usage pilot #400](https://github.com/pylon-code/pylon/pull/400); focused quota, retry, RPC and compatibility checks, web/mobile evidence in PR. | -| Pull-request browsing, cached reads and opt-in panel behavior / `062987b2fb0ef48cc7776d654931bd9f3bcf1f9f` | Full 16-source disposition list in #401; 15 adopted, #9877 deferred | Final PR state icons, authored/readiness sorting, seeded detail, keyboard pickers, link previews, profile links, revision-aware caches, project-filter deduplication and manual panel priority. Preserve Pylon server-projected PR tracking and quota reservation/refund semantics. Copy priority remains DEF-17. | [PR workflow #401](https://github.com/pylon-code/pylon/pull/401); 768 focused tests, affected package types, scoped lint and integrated web evidence. | -| Composer interaction, layout and notice follow-ups / `062987b2fb0ef48cc7776d654931bd9f3bcf1f9f` | Full 27-source disposition list in #402 | Final scroll-only resting behavior, readable multiline drafts, stable control measurements, last-message reservation, narrow-width controls and opt-in context meter. Preserve Pylon provider locks, quick questions, session/harness/goal actions, quota placement, upload handling and diagnostic errors. Temporary blur-selection holding in #9499 is superseded by #10437; no unresolved scope in this group. | [Composer #402](https://github.com/pylon-code/pylon/pull/402); 724 focused tests, six affected package typechecks, scoped lint, integrated web screenshots and motion evidence. | -| Changed-file trees and stable diff navigation / `062987b2fb0ef48cc7776d654931bd9f3bcf1f9f` | Full eight-source list in #403; seven new sources and DEF-11 | Adopted: persistent folder trees, diff/PR trees, repeated selection, saved layout, wrapped edit heights, search focus and folder sorting. Completes DEF-11 after removing all helper callers. Pylon lazy-viewer scope guards remain; narrow panels place the tree below code. | [File navigation #403](https://github.com/pylon-code/pylon/pull/403); 271 focused tests, six package typechecks, scoped lint/export checks and integrated web evidence. | -| Thread link targets / `062987b2fb0ef48cc7776d654931bd9f3bcf1f9f` | Three full source SHAs in [#404](https://github.com/pylon-code/pylon/pull/404). | Adopted link target preference across chat, terminal and PR surfaces; completed DEF-12 and DEF-15 after replacing their last callers. Preserve Pylon context/routing, browser defaults, safe errors and external fallback. Browser profiles remain an independent source group. | [#404](https://github.com/pylon-code/pylon/pull/404); 233 focused tests, seven package typechecks, targeted lint/export checks; web evidence in PR. | +| Group / bounded head | Sources | Outcome and remaining scope | Pylon PR / verification | +| ----------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Web chat/diff polish, editor discovery, diff cache eviction, ACP elicitation, and preview recovery / `c14f6015bfe479d313355cb234af1a5c16dbb15f` | `c14f6015bfe479d313355cb234af1a5c16dbb15f` (#12453), `0ff87f251db0f19c961e6878b4d82f7e77402a58` (#10831), `4a560b4e4e83c076595ee5d92df2778c187be099` (#12438), `9accc567675f0a0d0a7a37171d9d9ae5a5ec1279` (#12571), `dfbb11bdd7be977caee6dfa12d8a0c4f82862d64` (#12377), `408ff8ae9b1ecaebe1b6c00d603a1100f7eb6ea4` (#12439), `cb3d95c174ee0f9d984cfb7ff0352ad58b18ca78` (#12523), `de6a230db00bc1da1ffceaa6d10fa096df615f3e` (#11294), `efb96939fb39908ea0e80ce5662bb1e3704257ca` (#7861), `5378f87f9999a0db83f06b997c674254a6136d85` (#12535) | Adopted all ten across Cycle #685 Group A (PR #686) and Group B (PR #687). Retained whitespace when copying diff contents, kept linebreaks in citation content, opened chat popovers with relative placement, discovered installed external editors on desktop outside PATH, wrapped long titles in confirmation dialogs, showed plain text in collapsed thought previews, released oversized pull request diff cache entries, accepted ACP SDK elicitation requests (`session/elicitation` & `elicitation/create`), surfaced Codex app permission requests as approvable, and recovered preview host registration after request timeouts via connection queue eviction. Hardening and adversarial review findings resolved: normalized `acceptAlways` approval decision in Codex session runtime to grant permissions, enforced retirement epoch and quarantine boundaries on approval requests, scoped event emission with `CodexNotificationEpoch`, wrapped diff cache invalidation in `Effect.uninterruptible`, cleaned up mobile icon maps, and rebranded pre-existing PR tool descriptions to Pylon. Preserved Pylon Effect services, session lifecycles, and UI layout authority. Cursor unchanged. | Cycle [#685](https://github.com/pylon-code/pylon/issues/685), [PR #686](https://github.com/pylon-code/pylon/pull/686) and [PR #687](https://github.com/pylon-code/pylon/pull/687); independent adversarial reviews, 260+ focused unit tests across web, server, and effect-acp, full workspace typecheck, scoped format/lint. | +| Web interaction, ACP session startup stderr, Claude continuation, and GTK4 snapshot / `52d08a14b9cbff859d044238e8ec4e1cb5bf4d50` | `8dd02470b1e7603b8d36a21ae27c510480351f18` (#12552), `7445aa733ada33e45289e5aa5055f79142556513` (#11263), `599c9776eb887d4fff42da7d2daf8aa07ee9a9e2` (#11268), `dcf8942304cfef382af55c0068cb2f04c86757fc` (#12636), `e36725682bd2935f1bcfdf81660cb569b5f3df29` (#12577), `63ff33756c714e8687ea71a3bc8aa4e9303503f1` (#12624), `d6f291303d7c3ebcbfe8eeae5d6666ecbc4d20ae` (#12625), `52d08a14b9cbff859d044238e8ec4e1cb5bf4d50` (#12635) | Adopted all eight across Cycle #682 Group A (PR #683) and Group B (PR #684). Preserved draft question input when clicking options, desktop CSP screenshot annotations, restored providers settings heading, aligned PR detail menu glyphs. Empty Claude homePath correctly resolves and shares continuation with `~/.claude` or `CLAUDE_CONFIG_DIR`, surfaced ACP stderr excerpt in session startup failures instead of generic closed session errors, and extracted desktop accessible text for Flatpak and GTK4 apps in SnapShot. Adversarial review findings resolved: ACP stderr excerpt sanitized against tokens/credentials and pending buffer bounded; defensive empty `homePath` trimming and `CLAUDE_CONFIG_DIR` resolution in OAuth usage; desktop accessibility timeout preserved without premature concurrency overlap. Preserved Pylon provider rate limits and error reporting. Cursor unchanged. | Cycle [#682](https://github.com/pylon-code/pylon/issues/682), [PR #683](https://github.com/pylon-code/pylon/pull/683) and [PR #684](https://github.com/pylon-code/pylon/pull/684); independent adversarial reviews, 225+ focused tests across desktop and server, full workspace typecheck, scoped format/lint. | +| Chat message heading accessibility and compact sidebar density / `b44c1ce5d25ee0d5a5be82e380618a886c19ea96` | `6cdbf76fa4b0509913046abe6105037ded9e52bb` (#11199), `ca2cc1339bbd1904b932c3a92d23a2c0ffe1d267` (#11525), `77bca8b2d76a1f42552e5eee7d277fcb1160347a` (#9417), `df7ccc8fd01f5d2a1d8ec21bef8f9c59398fe913` (#11644), `7b61099886f3aac139ad43fb73873c73ba7baf4f` (#11652), `0118b522955f190e292ba578a509177b9605d392` (#11595) | Adopted all six across Cycle #669 Group A and Group B. Screen readers navigate chat messages as headings with hierarchical levels (`h3` at offset 3); proposed plans expose semantic headings. Compact sidebar rail (`compactSidebarEnabled`) and compact thread row density (`sidebarCompactThreadRows`) added as opt-in settings defaulting to `false`, preserving Pylon's pull request badges and stack integration, custom settings, and avoiding dead delegation UI. Sparse shelves stay pinned to bottom. Adversarial review findings resolved: accessible fallback for `plan-ready` dot in compact rows, drag layout projection fix for compact rail mode, explicit test fixtures. Cursor unchanged. | Cycle [#669](https://github.com/pylon-code/pylon/issues/669), [PR #679](https://github.com/pylon-code/pylon/pull/679) and [PR #680](https://github.com/pylon-code/pylon/pull/680); independent adversarial reviews, 490+ focused tests, `@t3tools/web`, `@t3tools/desktop`, and `@t3tools/contracts` typechecks, scoped lint/format, green CI. | +| Navigation, search and diff safety / `b44c1ce5d25ee0d5a5be82e380618a886c19ea96` | `9ea9c3d5d2c444133e3ddff40eecf38737951589` (#11075), `886c83450797c46ee84ae28fc16c2208cafa965e` (#10909), `c557bb10aa7cbb78a50df230d1e8e24af79cb662` (#11761), `3fd5d6439d8fd49d173503ecda96500463a39bd2` (#12315) | Adopted all four in Cycle #667 Group B. Symlink file type changes no longer crash diff view; chat folder links reveal directory in file tree; sidebar search matches thread message contents; numbered jump shortcuts do not steal browser tab navigation. Preserved Pylon's keybinding identity, routing and panel-choice semantics. Cursor unchanged. | Cycle [#667](https://github.com/pylon-code/pylon/issues/667), [PR #671](https://github.com/pylon-code/pylon/pull/671); 389 focused tests, web/shared typechecks, scoped lint, green CI. | +| Composer banner density and scroll-pill stability / `b44c1ce5d25ee0d5a5be82e380618a886c19ea96` | `4749035bda13b4b6260499caedbc0d69a2f60e6f` (#12166), `fcfd9f911a27ee3b813d64582c53d82dfa2e892b` (#12317) | Adopted both. Banner stack items gain an optional `compact` flag: compact rows keep the narrow layout and the description that collapses into an info popover below 400px, while other banners get room for the description beside the title, with a labelled, bounded, scrollable popover. The scroll-to-end clearance is split out of the overlay-height publisher and recomputed from a stored height when the pill mounts, so a fling during the composer's resting tween no longer publishes a stale height and yanks the scroll position. **Excluded:** upstream's `approval` banner layout classes — Pylon's `ComposerBanner.Row` union is `inline | wrap-actions | wrap-actions-narrow`and the approval layout arrives in an unadopted commit; only this source's`justify-end`change was applied. Pylon adaptations:`ComposerTasksBadge`keeps its delegates label, expanded guard and`TaskProgressSegments fit`, with the delegates label moved to the same container query as the segment bar so the pair no longer flips at different widths; `ChatView`'s pull-request resolution block is preserved; and five Pylon banners with short static descriptions (environment update, thread woke, snoozed/settled, resume-compaction, auto-balance) are marked `compact` so they do not grow a permanently redundant details popover. Cursor unchanged. | [Chat rendering #668](https://github.com/pylon-code/pylon/pull/668); independent adversarial review, 184 focused tests including new `compact` coverage, `@t3tools/web` typecheck, scoped lint. Two upstream-inherited defects recorded in the PR rather than fixed here. | +| Checkpoint capture reliability and shared-workspace rewind / `93e04160a0c0dece8a258384d2118a660415a53d` | `869347bc26051bba7c3c0274a7dfcae7770d3e3a` (#11665), `1455cb5c35e50211145073be6ca155d56684f0f4` (#12181), `67993623afb14c017bb0b959478dc892f9c427da` (#12307), `b4620d595554654c259ec7c0afb3d3d5532959a8` (#12306), `d17f46d7631b178b6834596264f0f44f210d584b` (#12308) | Adopted all five. Transient git exits retry during capture behind a new optional `retryable` hint on `VcsProcessExitError`; capture recovers nested repositories without commits under index-lock recovery and bounded probe timeouts; a failed baseline lookup logs and treats the ref as absent instead of losing the checkpoint; the `@`-mention entry refresh moves to a coalescing drainable worker chained into `CheckpointReactor.drain`. File rewind is refused unless the thread's cwd is its own worktree with no other thread or live provider session nested inside or above it, and web hides the destructive control for shared directories. **Capability removal, maintainer-approved 2026-09-18**: threads running in the project directory rewind the conversation only, with no override path. Pylon adaptation: the isolation check is scoped with `restoreFiles !== false` so conversation-only rewind still reaches Pylon's existing provider-capability explanation rather than the isolation message or silence, since Pylon's rollback saga services are optional. Pylon git identity, rollback revert action and wire compatibility preserved. No excluded source behavior; cursor unchanged. | [Checkpoint reliability #665](https://github.com/pylon-code/pylon/pull/665); 122 focused tests including three new `restoreFiles` regressions where none existed, `t3`/`contracts`/`web` typechecks, scoped lint (0 errors), rebased onto `origin/pylon` after #653. | +| Provider event log bounds and Codex image attachments / `93e04160a0c0dece8a258384d2118a660415a53d` | `b17cc2ab5d5029f898121798ca19db3288cba616` (#12305, partial), `3fd21df62da3191f1abf12a0cd74df6de9ed30a2` (#11050) | `3fd21df62d` adopted: Codex image attachments pass as `{ type: "localImage", path }` instead of base64 data URLs, so `turn/start` no longer scales with file size. `localImage` is a real content type in the generated Codex app-server schema; Pylon's attachment-id validation against `attachmentsDir` and its `FileSystem` wiring are retained. `b17cc2ab5d` **partially adopted**: record traversal is bounded before serialization with character, field and depth budgets, cycle detection, a `summarizeProviderEvent` fallback that keeps routing and failure fields, and a post-serialization byte-length fallback; new transient suppressions for `turn/diff/updated` and `stream_event`/`content_block_delta`. Pylon's `commitGuard` and existing transient filters preserved. **Excluded: the `stage === "raw"` suppression and `stage === "decoded"` unwrap** (see EXC-1). Cursor unchanged. | [Provider payload bounds #653](https://github.com/pylon-code/pylon/pull/653), merged `4be539f4d48af6ffbe545e015ec246fbb271c92e`; 133 focused tests, `t3` typecheck, scoped format/lint, all final-head CI jobs green, no bot findings. | +| PR comments, controls and avatars / `6d1d549441be84f19696ab59ed7e2fbf305280d4` | `f0a0ead946ca3f3f310460a91b7dabb0e3fe4834` (#11962), `f45c6b4a755905485431872f4a4188de3ed05974` (#11994), `c12ba7581ac00ba2a623ad23283da5d03d34c2d8` (#12150), `962bf62921c0ecbc9320f9b071e16b1d41484aad` (#12125), `df466c79810046d20c0f3ccc4e51709c5703814e` (#11728) | Adopted all five. Narrow controls, keyboard submission, paged bot/finished groups, long-comment previews, detail avatars and image-failure fallback. Pylon corrections align bot app links, lazily page finished groups, and scroll after collapsing. Optional actor metadata preserves wire compatibility; existing bounded GitHub enrichment/fallback limits remain. No excluded source behavior; cursor unchanged. | [PR review #621](https://github.com/pylon-code/pylon/pull/621); focused regressions, scoped types/lint, independent Opus adversarial reviews, browser before/after evidence and comment interaction recording. | +| Large diffs and review panel defaults / `6d1d549441be84f19696ab59ed7e2fbf305280d4` | `aae361c4ef6478e4dcf970d574f3fd38d908e6b9` (#10822), `36caf200c2b24c12838570966f5c85786a1fc1f8` (#11484), `3efdcc5296f1754e0f3bf7fee5fc2ada510e0438` (#11931), `6d1d549441be84f19696ab59ed7e2fbf305280d4` (#12190), `52ad70ec43b5dcfcdc72ac79c0964da8e4d163db` (#12142), `394af73e02238e551db14f44d57f1469dd2942aa` (#12139) | Adopted all six. Complete Git metadata and progressive per-file patches on web/mobile; preserve old-server preview fallback, literal paths and bounded output. Tree order/folder state survive refresh. Files default collapsed while explicit saved choices persist. Generic diff openings reset to working tree; linked PRs outrank automatic diffs. Preserve Pylon multi-PR authority, environment identity, responsive layout and existing settings. No excluded source behavior; cursor unchanged. | [Review diffs #616](https://github.com/pylon-code/pylon/pull/616); 509 integrated focused tests plus 79 unchanged backend regressions, six scoped package typechecks, lint, independent Antigravity adversarial reviews, before/after browser evidence and refresh video. Native verification details in PR. | +| Usage pools, hub quotas, reset credits and local composer action / `062987b2fb0ef48cc7776d654931bd9f3bcf1f9f` | Full 16-source list in the usage pilot PR; parent `19d8ab2ae9fc562ee7b216a0d72903fbfafa9572`, final hub-routing fix `6abdf37a50ce6c1c9fabc499f4d0e159a6182d90` | Pylon port of the final behavior; parent partially adopted with native Claude scoped push mapping retained in DEF-16. `00d6109cbb1a13712d7347701969870aee83252d` is covered: demo fixtures were never introduced. Native Claude quota reads reuse Pylon's cached OAuth parser; no duplicate SDK probe or ingestion worker. | [Usage pilot #400](https://github.com/pylon-code/pylon/pull/400); focused quota, retry, RPC and compatibility checks, web/mobile evidence in PR. | +| Pull-request browsing, cached reads and opt-in panel behavior / `062987b2fb0ef48cc7776d654931bd9f3bcf1f9f` | Full 16-source disposition list in #401; 15 adopted, #9877 deferred | Final PR state icons, authored/readiness sorting, seeded detail, keyboard pickers, link previews, profile links, revision-aware caches, project-filter deduplication and manual panel priority. Preserve Pylon server-projected PR tracking and quota reservation/refund semantics. Copy priority remains DEF-17. | [PR workflow #401](https://github.com/pylon-code/pylon/pull/401); 768 focused tests, affected package types, scoped lint and integrated web evidence. | +| Composer interaction, layout and notice follow-ups / `062987b2fb0ef48cc7776d654931bd9f3bcf1f9f` | Full 27-source disposition list in #402 | Final scroll-only resting behavior, readable multiline drafts, stable control measurements, last-message reservation, narrow-width controls and opt-in context meter. Preserve Pylon provider locks, quick questions, session/harness/goal actions, quota placement, upload handling and diagnostic errors. Temporary blur-selection holding in #9499 is superseded by #10437; no unresolved scope in this group. | [Composer #402](https://github.com/pylon-code/pylon/pull/402); 724 focused tests, six affected package typechecks, scoped lint, integrated web screenshots and motion evidence. | +| Changed-file trees and stable diff navigation / `062987b2fb0ef48cc7776d654931bd9f3bcf1f9f` | Full eight-source list in #403; seven new sources and DEF-11 | Adopted: persistent folder trees, diff/PR trees, repeated selection, saved layout, wrapped edit heights, search focus and folder sorting. Completes DEF-11 after removing all helper callers. Pylon lazy-viewer scope guards remain; narrow panels place the tree below code. | [File navigation #403](https://github.com/pylon-code/pylon/pull/403); 271 focused tests, six package typechecks, scoped lint/export checks and integrated web evidence. | +| Thread link targets / `062987b2fb0ef48cc7776d654931bd9f3bcf1f9f` | Three full source SHAs in [#404](https://github.com/pylon-code/pylon/pull/404). | Adopted link target preference across chat, terminal and PR surfaces; completed DEF-12 and DEF-15 after replacing their last callers. Preserve Pylon context/routing, browser defaults, safe errors and external fallback. Browser profiles remain an independent source group. | [#404](https://github.com/pylon-code/pylon/pull/404); 233 focused tests, seven package typechecks, targeted lint/export checks; web evidence in PR. | | Document and media preview integration / `062987b2fb0ef48cc7776d654931bd9f3bcf1f9f` | Full 13-source list in #405, including DEF-14 | Twelve adopted sources; #9460 is already covered by Pylon’s expanded-only viewed-image rows. Shared parsing, document attachment tabs, preview retry states, draft file readers, native SVG and short-source scrolling. Preserve image dimensions, POSIX case, explicit panel choices, video expansion and local-file leases. Completes DEF-14 after removing all predicate callers. | [Media previews #405](https://github.com/pylon-code/pylon/pull/405); focused cross-client tests, seven package typechecks, native iOS build and client evidence in PR. |