diff --git a/.agents/upstream-review.md b/.agents/upstream-review.md index 6a49f4c5ad..62b7d8d5a9 100644 --- a/.agents/upstream-review.md +++ b/.agents/upstream-review.md @@ -1,8 +1,8 @@ --- remote: t3code-upstream branch: main -reviewed-through: "bbedad0278bbf753503184c00e0c09a0eab6679c" -reviewed-through-date: "2026-09-14" +reviewed-through: "e67abcf798f8c4d8458755e3b4dde02c2c1f628b" +reviewed-through-date: "2026-09-23" --- # T3 upstream decision index @@ -15,11 +15,13 @@ The maintainer authorized compatible catch-up and routine adaptations that prese ## Active cycle -[Upstream catch-up cycle #736](https://github.com/pylon-code/pylon/issues/736) is active. Its frozen review range is `bbedad0278bbf753503184c00e0c09a0eab6679c..e67abcf798f8c4d8458755e3b4dde02c2c1f628b` (481 sources). The issue holds the source-by-source disposition and actionable work queue, including open PRs, deliberate Pylon divergences, dependencies, and product decisions. This review does not advance the completed integration cursor `fa1e1715538f6f8ac076761f7821f68479f616ab` or claim the open implementations are adopted. The Oh My Pi integration was explicitly rejected and is excluded from this cycle. Cycle #689 remains the latest completed integration. +[Upstream catch-up cycle #865](https://github.com/pylon-code/pylon/issues/865) is active. Its frozen range is `e67abcf798f8c4d8458755e3b4dde02c2c1f628b..ab099178a7b7f9728843e90fc95ed90bb61d710d` (127 sources at the 2026-09-27 fetch). The issue owns the next source dispositions; this cursor does not classify that new range. Later T3 arrivals belong to a later cycle. Oh My Pi remains explicitly excluded. ## Latest cycle -[Upstream integration cycle #689](https://github.com/pylon-code/pylon/issues/689) completed OTLP log exports, desktop main-process telemetry, and per-signal observability settings (PR #690) through upstream bound `fa1e1715538f6f8ac076761f7821f68479f616ab`. Previous cycle [#685](https://github.com/pylon-code/pylon/issues/685) completed web chat/diff/citation polish and external editor discovery (PR #686), and server PR diff cache eviction, ACP SDK elicitation, Codex app permission approvals, and preview host recovery (PR #687). +[Upstream catch-up cycle #736](https://github.com/pylon-code/pylon/issues/736) classified all 481 sources in `bbedad0278bbf753503184c00e0c09a0eab6679c..e67abcf798f8c4d8458755e3b4dde02c2c1f628b`. Its seven source tables and later reconciliation comments provide the complete disposition record. Merged implementation PRs include chat/Relay reliability, provider and mobile fixes, Forgejo, pull-request workflows, and UI improvements; each PR holds its verification and exclusions. The final source audit records deliberate partials and revisit triggers, including mobile server-update targeting, automatic title refinement, Android Agent behavior settings, and untrusted Forgejo rejection text. Oh My Pi was rejected and closed unmerged. Advancing this review cursor records decisions, not verbatim adoption, a release, or an installation. + +Previous [cycle #689](https://github.com/pylon-code/pylon/issues/689) completed OTLP log exports, desktop main-process telemetry, and per-signal observability settings (PR #690) through upstream bound `fa1e1715538f6f8ac076761f7821f68479f616ab`. Earlier [cycle #685](https://github.com/pylon-code/pylon/issues/685) completed web chat/diff/citation polish and external editor discovery (PR #686), and server PR diff cache eviction, ACP SDK elicitation, Codex app permission approvals, and preview host recovery (PR #687). Previous completed cycles: [#526](https://github.com/pylon-code/pylon/issues/526) through `d1d15c67f4a5fb82fd8d5e01e5e3b288296789c3`, [#516](https://github.com/pylon-code/pylon/issues/516) through `b1e223e2b0d87124883b1410ab52dd6a1338e40d`, [#497](https://github.com/pylon-code/pylon/issues/497) through `4a4c6dd2adc350a68ba18bb28b24b5a7e4660dab`, and [#414](https://github.com/pylon-code/pylon/issues/414) through `6c583620ff7ad3235b135af7107c0543467eecfa`. Their trigger audits and exclusions describe those cycles' closure state; current dispositions below supersede them. Follow the skill's [continuation procedure](skills/review-t3-upstream/references/continuation.md), checking the issue against Git and GitHub before acting. @@ -35,9 +37,9 @@ Historical groups are indexed in the linked archive. This file migration changes | Group / bounded head | Sources | Outcome and remaining scope | Pylon PR / verification | | ----------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Explicit provider refresh cache bypass / `f193a6863c494fdfa36a1ef3132e42a7d7b42926` | `f193a6863c494fdfa36a1ef3132e42a7d7b42926` (#13109) | Implemented in PR #743, pending merge: explicit refresh bypasses the model manifest freshness/retry timer and provider-owned capability, model and package-version caches before status probes. Background probes retain their timers; Pylon's installed-provider `refreshModels` path remains. No behavior excluded. Cursor unchanged. | Cycle [#736](https://github.com/pylon-code/pylon/issues/736), [PR #743](https://github.com/pylon-code/pylon/pull/743); independent adversarial review, 246 focused tests, server typecheck and scoped lint/format. | +| Explicit provider refresh cache bypass / `f193a6863c494fdfa36a1ef3132e42a7d7b42926` | `f193a6863c494fdfa36a1ef3132e42a7d7b42926` (#13109) | Merged in PR #743: explicit refresh bypasses the model manifest freshness/retry timer and provider-owned capability, model and package-version caches before status probes. Background probes retain their timers; Pylon's installed-provider `refreshModels` path remains. No behavior excluded. The cycle cursor advanced at closure. | Cycle [#736](https://github.com/pylon-code/pylon/issues/736), [PR #743](https://github.com/pylon-code/pylon/pull/743); independent adversarial review, 246 focused tests, server typecheck and scoped lint/format. | | Background GitHub PR quota / `eafb4a9340bd2c2271b7c8fac7eddd55beea3972` | `5975ec78b7eaff654e6183b99f8de7a05591e99d` (#13189), `18de6bb328059703b5d1b0661610076e3c0fa2d4` (#13198), `eafb4a9340bd2c2271b7c8fac7eddd55beea3972` (#13200) | Adapted all three: skip uncached recheck when a terminal link cannot settle, batch background PR summaries, and avoid owner-qualified head probes. Preserve Pylon credential scopes, GraphQL budget and per-environment routing; exclude upstream-only test fixture APIs. No cursor advance. | [GitHub quota #749](https://github.com/pylon-code/pylon/pull/749); focused server regressions, scoped lint and typecheck. | -| OTLP export kill switch / `e67abcf798f8c4d8458755e3b4dde02c2c1f628b` | `e67abcf798f8c4d8458755e3b4dde02c2c1f628b` (#13355) | Implemented in PR #746, pending merge: `OTEL_SDK_DISABLED` and the inherited `T3CODE_OTEL_SDK_DISABLED` override suppress server and desktop main-process OTLP traces, metrics, and logs from environment, bootstrap, or Settings endpoints; WSL inherits the flags. Local trace files and local logs remain active, and Pylon service identity is retained. No behavior excluded. Cursor unchanged. | Cycle [#736](https://github.com/pylon-code/pylon/issues/736), [PR #746](https://github.com/pylon-code/pylon/pull/746); independent adversarial review, 80 focused tests, server/desktop/shared typechecks and scoped lint/format. | +| OTLP export kill switch / `e67abcf798f8c4d8458755e3b4dde02c2c1f628b` | `e67abcf798f8c4d8458755e3b4dde02c2c1f628b` (#13355) | Merged in PR #746: `OTEL_SDK_DISABLED` and the inherited `T3CODE_OTEL_SDK_DISABLED` override suppress server and desktop main-process OTLP traces, metrics, and logs from environment, bootstrap, or Settings endpoints; WSL inherits the flags. Local trace files and local logs remain active, and Pylon service identity is retained. No behavior excluded. The cycle cursor advanced at closure. | Cycle [#736](https://github.com/pylon-code/pylon/issues/736), [PR #746](https://github.com/pylon-code/pylon/pull/746); independent adversarial review, 80 focused tests, server/desktop/shared typechecks and scoped lint/format. | | OTLP log export, desktop main process telemetry, and per-signal observability / `fa1e1715538f6f8ac076761f7821f68479f616ab` | `3bb06ad910389fcfc886bd5156f41dc73f307f80` (#12493), `82059df1523d070b00ab6f45159115f626a4977e` (#12520), `a8693eb4ed3a66d72e6b814117e7beeaf0fb5f8b` (#12540), `fa1e1715538f6f8ac076761f7821f68479f616ab` (#12657) | Adopted all four in Cycle #689 (PR #690). Server exports structured log records over OTLP with trace/span ID correlation, replaces `tracerLogger` to eliminate duplicate in-span span-event exports, and applies dedicated flusher/serialization layers. Desktop exports main process traces and logs over OTLP while withholding metric emissions until metrics are instrumented. OTLP settings and HTTP header sets are isolated per signal (traces, metrics, logs) across server and desktop configurations. Adversarial review findings resolved: preserved `pylon-server` runtime and service identity defaults, verified `DEFAULT_SIGNAL_EXPORT` fallback, tested backward compatibility of `ServerObservability` schema decoding, and validated log deduplication. Cursor unchanged. | Cycle [#689](https://github.com/pylon-code/pylon/issues/689), [PR #690](https://github.com/pylon-code/pylon/pull/690); independent adversarial review, new ServerLogger test suite, 9 desktop observability tests, all CI checks green. | | Web chat/diff polish, editor discovery, diff cache eviction, ACP elicitation, and preview recovery / `c14f6015bfe479d313355cb234af1a5c16dbb15f` | `c14f6015bfe479d313355cb234af1a5c16dbb15f` (#12453), `0ff87f251dafb32703d5f531e7b248ad0a581ee2` (#10831), `4a560b4e4ebb37efb7f57805ba79e37f5500bdca` (#12438), `9accc567670da5096e9a694c1adb0d35adb51d9d` (#12571), `408ff8ae9bd7eb2e7e90cbfd8b3fcfe63641bf23` (#12439), `cb3d95c17487f3d834a5537f7c3aa0106bc9b5ec` (#12523), `de6a230db0bb71d3fa91d8de0ae7067b68253f82` (#11294), `efb96939fbb135b9f4de3bff19447200b178b23a` (#7861), `5378f87f99175bded2b9241876319567875aca03` (#12535) | Adopted nine across Cycle #685 Group A (PR #686) and Group B (PR #687). Retained whitespace when copying diff contents, kept linebreaks in citation content, opened chat popovers with relative placement, discovered installed external editors on desktop outside PATH, wrapped long titles in confirmation dialogs, released oversized pull request diff cache entries, accepted ACP SDK elicitation requests (`session/elicitation` & `elicitation/create`), surfaced Codex app permission requests as approvable, and recovered preview host registration after request timeouts via connection queue eviction. Hardening and adversarial review findings resolved: normalized `acceptAlways` approval decision in Codex session runtime to grant permissions, enforced retirement epoch and quarantine boundaries on approval requests, scoped event emission with `CodexNotificationEpoch`, wrapped diff cache invalidation in `Effect.uninterruptible`, cleaned up mobile icon maps, and rebranded pre-existing PR tool descriptions to Pylon. Preserved Pylon Effect services, session lifecycles, and UI layout authority. Cursor unchanged. | Cycle [#685](https://github.com/pylon-code/pylon/issues/685), [PR #686](https://github.com/pylon-code/pylon/pull/686) and [PR #687](https://github.com/pylon-code/pylon/pull/687); independent adversarial reviews, 260+ focused unit tests across web, server, and effect-acp, full workspace typecheck, scoped format/lint. | | Web interaction, ACP session startup stderr, Claude continuation, and GTK4 snapshot / `52d08a14b9e475371658fabbb12c056c3d3dad67` | `8dd02470b1e7603b8d36a21ae27c510480351f18` (#12552), `7445aa733ada33e45289e5aa5055f79142556513` (#11263), `599c9776eb887d4fff42da7d2daf8aa07ee9a9e2` (#11268), `dcf8942304cfef382af55c0068cb2f04c86757fc` (#12636), `e36725682bd2935f1bcfdf81660cb569b5f3df29` (#12577), `63ff33756c47f127391962458d8388a647e8ed44` (#12624), `d6f291303ddc0c9a14f570266a4d9eff6d431593` (#12625), `52d08a14b9e475371658fabbb12c056c3d3dad67` (#12635) | Adopted all eight across Cycle #682 Group A (PR #683) and Group B (PR #684). Preserved draft question input when clicking options, desktop CSP screenshot annotations, restored providers settings heading, aligned PR detail menu glyphs. Empty Claude homePath correctly resolves and shares continuation with `~/.claude` or `CLAUDE_CONFIG_DIR`, surfaced ACP stderr excerpt in session startup failures instead of generic closed session errors, and extracted desktop accessible text for Flatpak and GTK4 apps in SnapShot. Adversarial review findings resolved: ACP stderr excerpt sanitized against tokens/credentials and pending buffer bounded; defensive empty `homePath` trimming and `CLAUDE_CONFIG_DIR` resolution in OAuth usage; desktop accessibility timeout preserved without premature concurrency overlap. Preserved Pylon provider rate limits and error reporting. Cursor unchanged. | Cycle [#682](https://github.com/pylon-code/pylon/issues/682), [PR #683](https://github.com/pylon-code/pylon/pull/683) and [PR #684](https://github.com/pylon-code/pylon/pull/684); independent adversarial reviews, 225+ focused tests across desktop and server, full workspace typecheck, scoped format/lint. |