Skip to content

chore(rtvision): sync upstream and prepare 0.0.76 - #85

Open
kalvenschraut wants to merge 82 commits into
rtvisionfrom
sync/rtvision-upstream-20261009
Open

kalvenschraut wants to merge 82 commits into
rtvisionfrom
sync/rtvision-upstream-20261009

Conversation

@kalvenschraut

@kalvenschraut kalvenschraut commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

RTVision upstream sync for 0.0.76

The sync brings 74 upstream commits into rtvision and layers the remaining fork behavior over upstream's provider extraction, browser changes and client improvements.

Pinned fork dfe5bded8ce8e997b869a046e3ad398045631436; previous upstream ancestor 30cc788975500a8c00d32a50f348174d1ce578d1; incoming upstream main 43f8a8de17a7ac1baa7a3cf36d681856de2d8add. There are 1,088 upstream changed paths and 76 literal fork overlaps. The merge preserves upstream ancestry. Existing 0.0.75 is published; the proposed next release is 0.0.76.

New upstream features and fixes

  • Providers and models. Muse Code is a native provider with create/resume, model and reasoning selection, active steering/interruption, text/image input, approvals/questions, usage/todos/compaction, workflow children and owned native completion reports. It supports supervised/full-access modes; dedicated Plan, native rollback and native fork are unavailable. Catalog discovery does not treat cached models as proof of authentication. Temporary-workspace metadata generation validates structured output and rejects interaction. Provider core/testing and Pi, Muse, OpenCode, Cursor, ACP, Grok and ACP Registry move into dedicated packages; shared prompts, notifications, logging and adapter construction replace their old server locations. Pi gains owned continuation turns, optional tool discovery, workspace skills/commands, seeded editor answers, complete selected-skill loading and native rewind reconciliation. Muse workflow subagents handle hidden approvals. Model lists avoid incorrectly marking new models legacy and explain when a CLI update unlocks a model. Claude authentication recognizes logged-out state and removes its MCP token from process arguments.
  • Chat, editing and terminal. Compact-before-send becomes a token-count chip with per-thread opt-out. Find searches messages and plans, including virtualized/folded history. Copy returns before Fork; search colors and timeline marker gutters improve readability. The collapsed composer reserves space for wider send actions, semantic branch hints follow settings, stack-merge confirmation closes promptly, PR linking works outside Git repositories, folder loading uses row feedback and sidebar drag cancellation drops stale context. Terminal scrollback/navigation, select-all and snapshots improve; JetBrains IDEs open remote projects over SSH.
  • Usage and server performance. Provider filters and progressive Usage totals avoid waiting for slow sources. Antigravity skips unchanged database decoding; Cursor history uses ordered parallel fetches and caching. Shell snapshots decode outside their database transaction; ACP streamed chunks avoid repeated persistence; long message sync uses narrower database work. Threads settle promptly when their PR merge is observed, and agents can request self-settlement after their turn ends.
  • Browser, preview and files. File previews support downloads, page anchors and repository paths without leaking internal hosts through favicons; draft threads preview media before their first message. Environment-hosted tabs improve navigation/ownership, agent history stays bounded, fallback is clearer and a timed-out drag cannot exit the server. Desktop browser tabs improve fullscreen, shortcuts, links, reload, hidden tabs and downloads, and display remote-environment tabs locally. Annotation captures use bounded retries and device-pixel-aware crops. Electron moves to 44.4.5; its User-Agent is valid and backend pipe reads cancel during shutdown.
  • Connections and authentication. Session permissions are shown for the active route and session expiry/revocation terminates WebSocket access. Pairing uses integer SQLite boolean bindings. Authenticated GitHub Enterprise hosts are recognized with repository context. Relay updates select compatible managed cloudflared, retry brief Windows file locks, release locks on cancellation and bound downloads; cloudflared is 2026.10.0. Desktop CLI installation warns about an existing command that takes precedence.
  • Mobile. Native screen order survives pops and swipe-back, chat image previews work in the v5 stack, working-thread emphasis/status labels match web, and Android HTML WebViews yield vertical edge scrolling to their parent. Provider settings/icons and route permissions follow the shared model.

Upstream replacements and retained RTVision behavior

Upstream's integer pairing binding replaces the identical fork fix. Provider and shared-module moves are authoritative; all fork consumers migrate instead of restoring deleted modules. Upstream's bounded screenshot retries replace the fork's old capture timeout. Upstream's per-thread compaction-chip state replaces the old single ref. Browser/terminal improvements coexist with retained Vim navigation, terminal Neovim/editor choice, annotation drafts and reload restoration.

Gitea/Forgejo provisioning, private signed images, CI/viewed/dependency/reaction support and destination grants remain. The fork keeps exhaustive historical PR lookup and safe checkout host/port/base matching. Codex clean-exit recovery and idle-timer identity guards remain. Registry/update routing, Node/npm/OpenRC service entry points, Alpine native Chromium and node-pty compatibility, SSH/WSL account routing and release packaging remain fork-specific.

Verified integration repairs omit private bundled workspaces from npm publication metadata, migrate PTY/editor imports, remove the stale compaction ref, retain GitHub API ports, require destination preview permission for profile reports and prevent same-name desktop downloads overwriting each other. A focused existing process-containment test also verified a missing-target exit-code defect; explicit command lookup preserves the wrapper's failure status on non-interactive shells.

Every literal fork-overlap decision

Path Decision
apps/desktop/package.json Take Electron 44.4.5; retain fork release identity 0.0.76 during preparation, then bump to 0.0.76. All release manifests are 0.0.76.
apps/desktop/src/app/DesktopCliCommand.test.ts Keep upstream Unix collision/PATH isolation tests and fork Windows installed.onPath=false expectation; add real-filesystem regressions for migration rejection, later foreign commands, non-executable files and directories.
apps/desktop/src/app/DesktopCliCommand.ts Keep upstream foreignFirstOnPath, shadowedBy and refusal; repair collision-before-unlink ordering and require executable regular PATH files. Preserve Windows first=none and onPath=false.
apps/desktop/src/ipc/channels.ts Add upstream PREVIEW_OPEN_LINK_CHANNEL; retain SSH runner and three terminal-editor IPC channels.
apps/desktop/src/preload.ts Add upstream preview.onOpenLink; retain setSshRunner/probeTerminalEditor/openTerminalEditor/setTerminalEditorSettings.
apps/desktop/src/preview/Manager.test.ts Keep upstream new-tab, main-frame and DPR crop coverage plus fork reload-draft test.
apps/desktop/src/preview/Manager.ts Use upstream capturePageWithRetry/cropAnnotationScreenshot and browser changes; retain fork draft listener/reload restore logic and isSamePageUrl. Remove superseded single-capture timeout/helper.
apps/desktop/src/preview/PickPreload.ts Keep fork selector-based draft restore, style/region/stroke state and ID reservation; add upstream devicePixelRatio fourth IPC argument.
apps/desktop/src/window/DesktopWindow.test.ts Keep upstream main-window command tests and fork setSshRunner mock.
apps/server/package.json Keep service-launcher build and fork version; take provider workspace dependencies in development manifest, SDK changes and script entry. Publish manifest must omit bundled private workspace dependencies. All release manifests are 0.0.76.
apps/server/scripts/evaluate-thread-titles.ts Keep Gitea CLI provisioning; use relocated upstream text-generation/provider services.
apps/server/src/assets/AssetAccess.ts Keep signed, expiring source-control-image claims, configured-Gitea URL validation and image resolution; accept upstream helper imports.
apps/server/src/auth/RpcAuthorization.test.ts Keep fork CI/dependency read and CI/viewed mutation authorization cases; accept upstream search/profile scope tests.
apps/server/src/auth/RpcAuthorization.ts Keep fork PR read scopes and guarded mutation scope mapping. Add upstream history/find and browser-profile authorization; never bypass destination session scopes.
apps/server/src/git/GitManager.test.ts Keep exhaustive old-PR-history/newer-closed-PR coverage and upstream state-change publication coverage as separate complete tests.
apps/server/src/git/GitManager.ts Combine fork exhaustive option/cache-key/filtering with upstream noteLookupState(latest) and state-change stream. Neither replaces the other.
apps/server/src/http.ts Keep authenticated Gitea image response route and both CLI layers. Accept upstream HTML sandbox allow-downloads; retain sandbox isolation and image response headers.
apps/server/src/mcp/OrchestratorMcpToolkit.integration.test.ts Keep explicit delegated-status success and caller lifetime/terminal transcript assertions; accept upstream provider-testing imports and MCP additions.
apps/server/src/observability/RpcInstrumentation.ts Keep all six fork PR aggregate entries; accept upstream find/history/profile entries.
apps/server/src/orchestration-v2/Adapters/CodexAdapterV2.ts Keep awaitTermination, failure-capable queue and queue stream. Use provider-core imports for moved services/errors.
apps/server/src/orchestration-v2/ProviderSessionManager.test.ts Keep exit-recovery and stale idle-unload tests; accept upstream service imports and fixture changes.
apps/server/src/orchestration-v2/ProviderSessionManager.ts Keep runtime-identity timer guards, cancellation and dead-session eviction. Upstream service relocation is complementary.
apps/server/src/persistence/AuthPairingLinks.ts Upstream supersedes fork: incoming 4daec109cd makes the exact same boolean-to-0/1 SQL binding change. Keep one implementation. Fork regression tests can remain.
apps/server/src/provider/CodexProvider.ts Keep auth-home/account-ID extraction, account metadata and unsupported usage state for auth-free/API-key instances. Import both path helpers from provider-core.
apps/server/src/provider/ProviderRegistry.test.ts Keep fork fresh-scan ownership/race tests; add upstream model-version and logged-out-Claude expectations.
apps/server/src/provider/ProviderRegistry.ts Keep symbol-owned workspace refresh claims and stale-result protection. Accept upstream model availability filtering and provider-core imports.
apps/server/src/provider/acp/AcpSessionRuntime.processTree.test.ts Keep synthetic PIDs relative to the test process PID, avoiding protected process-group collision. Import the moved ACP runtime through its package. The integration test may stay server-owned.
apps/server/src/pullRequest/PullRequestService.test.ts Keep fork CI, viewed, dependencies, reactions, refresh and provider regressions. Accept upstream dependency/test harness changes. Implementation is outside the incoming overlap and retained.
apps/server/src/server.ts Keep Gitea provisioning, DiskSpace layer and acquireServerRuntimeState. Add upstream ProviderHost/provider package and Cursor usage reader provisioning.
apps/server/src/serverRuntimeState.ts Keep launcher ownership, runtime handoff and expected-PID cleanup. Use upstream @t3tools/shared/atomicWrite; remove the old helper import.
apps/server/src/sourceControl/ForgejoCli.ts Keep tea config isolation, response-header parsing, retry timing, resolved targets, output bounds, server resolution and non-2xx rejection. Move stream collector import to provider-core.
apps/server/src/sourceControl/GitHubSourceControlProvider.test.ts Keep fork safe checkout/host/port/deleted-head tests and SourceControlProviderError; retain upstream Enterprise discovery/context tests and their dependencies.
apps/server/src/sourceControl/GitHubSourceControlProvider.ts Keep upstream credential-based Enterprise discovery and context-aware repository lookup. Keep port-preserving host comparison and refusal to use an unrelated primary remote. F2 describes the intermediate regression and current repair.
apps/server/src/sourceControl/SourceControlProviderRegistry.test.ts Keep Gitea registry/discovery provisioning; accept upstream moved helpers.
apps/server/src/textGeneration/ClaudeTextGeneration.test.ts Retain the corrected server config test-layer API wherever still used; accept upstream provider-core imports.
apps/server/src/textGeneration/CodexTextGeneration.test.ts Same decision as Claude test-layer correction; no duplicate test host service.
apps/server/src/textGeneration/GrokTextGeneration.test.ts Keep valid host setup and use provider-grok text generation. Test remains in server as integration coverage.
apps/server/src/textGeneration/OpenCode2TextGeneration.test.ts Upstream replaces the old config test-layer setup with layerTestProviderHost() plus Node services. Accept that equivalent; do not preserve the obsolete ServerConfig block.
apps/server/src/textGeneration/OpenCodeTextGeneration.test.ts Move is authoritative: resolve at packages/provider-opencode/src/server/textGeneration.test.ts. Use upstream host/net/Node layers; remove old source path rather than retaining a duplicate.
apps/server/src/usage/cliproxyApi.ts Keep trimmed account IDs and plan fallback through usage.plan_type, token plan_type, then chatgpt_plan_type. Accept moved usage helper imports.
apps/server/src/ws.ts Keep fork PR handlers/viewer scoping, scoped refresh compatibility, Gitea provisioning and opt-in low-disk events. Add upstream find/history/profile methods, shell decode boundary and session invalidation race.
apps/web/package.json Retain @shikijs/langs 4.2.0 and RTVision version lane; take upstream provider workspace dependencies and shared markdown/catalog changes. Observed version changed from 0.0.76 to proposed 0.0.76 during review; uniqueness/publication not checked.
apps/web/src/components/AppSidebarLayout.tsx Take upstream sidebar menu forwarding; retain VimNavigation, useVimSidebar, claimVimPaneFocus, pane markup and onAppCommand. Cleanup both command-bus and desktop-menu subscriptions. Current draft contains both.
apps/web/src/components/ChatMarkdown.test.tsx Keep fork useEditorDispatch mock and distinction between remote editor availability and local file-manager actions; retain all upstream search, headings and link tests.
apps/web/src/components/ChatMarkdown.tsx Keep resolveImageAsset prop/context/memo and source-control-image resource branch before ordinary image classification, plus useEditorDispatch. Use upstream shared parser, search contexts, heading IDs and hash-safe fragment behavior. Current draft retains private signed assets.
apps/web/src/components/ChatView.tsx Use upstream ThreadFindCanvas, compact-chip state and answer seeding. Preserve low-disk warning, Vim app-command/focus behavior, history cursor and editor picker. Remove stale keepFullHistoryOnceRef read (F1); retain focusAtSend. The final source recheck confirms root removed F1; preserve that removal.
apps/web/src/components/CommandPalette.tsx Retain Gitea source option/readiness, Vim overlay focus restoration and onAppCommand; take upstream Find action and keybinding. Focus handoff needs integrated verification.
apps/web/src/components/GitActionsControl.tsx Retain Gitea publish option and useEditorDispatch/canOpenEditor, including terminal/remote routes. Take shared file-link import and upstream stack-dialog behavior.
apps/web/src/components/Icons.tsx Keep Neovim mark. Take provider-package glyph removals (Pi, Muse, OpenCode, Grok) and package-rendered icons; retain remaining icons still used by editor/UI entries, including Cursor where applicable.
apps/web/src/components/ThreadTerminalDrawer.tsx Keep useEditorDispatch with destination-specific terminal/host scopes, route-aware link refresh, Vim pane/input-enter/auto-focus rules and tab focus selection. Import resolvePathLinkTarget from shared/fileLinks, isTerminalUrl locally. Use upstream terminal scrollback/context-menu logic.
apps/web/src/components/chat/MessagesTimeline.tsx Keep upstream context wrapper MessagesTimeline and memoized inner ConversationTimeline with Find contexts. Put Vim hooks and earlierHistory/error derivation in ConversationTimeline; retain history cursor and onVimBottom props and VimTimeline inside the viewport. Preserve upstream find navigation and throughEntryId load callback. Current draft follows this structure.
apps/web/src/components/files/FilePreviewPanel.tsx Keep extracted useEditableAfterHighlight, editable annotation onEdit, workspace-aware editor picker and remote/terminal routes. Take upstream draft media resources, shared paths and gutters. Do not reintroduce old in-component highlight hook.
apps/web/src/components/onboarding/WelcomeWizard.tsx Keep npm-registry.rtvision.com @rtvision/t3 connect/pair/serve commands; take upstream provider registry/instance behavior.
apps/web/src/components/preview/PreviewView.tsx Keep pickDisabled={!tabId // (isUnreachable && !pickActive)} so an active pick remains cancellable after failed reload; take upstream popup/download/runtime movement and profile behavior.
apps/web/src/components/pullRequest/PullRequestsUnavailableState.tsx Keep provider-neutral browserUrl and Open in browser; take upstream gutter layout. Gitea/Forgejo must not revert to GitHub-only props.
apps/web/src/components/settings/CliCommandSettingsRow.tsx Use shadowedBy warning first, then not-installed, then Windows .cmd PATH explanation, then normal onPath/offPath messages. Preserve full-path escape hatch. Current draft has this order; desktop owner must validate install-state truth.
apps/web/src/components/settings/ConnectionsSettings.tsx Keep Windows/WSL SSH-runner selection and restart confirmation, and CloudLinkRow outside local-network-only conditional. Take current-session permission UI/shared scopes. Destination grants and authoritative server stay intact.
apps/web/src/components/settings/ProviderInstanceCard.tsx Keep local model preferences independent from settings:write. Take provider-core types and upstream instance UI; server custom-model edits remain readOnly guarded.
apps/web/src/components/settings/ProviderSettingsPanel.environment.test.tsx Keep all three actual local favorite/visibility/order action cases asserting client settings only and no server mutation; use upstream providerInstances-only fixtures/reset expectations.
apps/web/src/components/settings/ProviderSettingsPanel.tsx Keep removal of server-write coupling for device-local model preferences. Take upstream add controls, default instance synthesis and instance-only reset.
apps/web/src/composer-rich-text-doc.test.ts Retain fence-info mention caret round-trip regression; take upstream plain/literal answer behavior tests.
apps/web/src/composer-rich-text-doc.ts Keep collapsedOpenLen and collapsed fence-opening mapping. Upstream literalText paragraph path is separate and does not replace the fenced-code fix.
docs/user/install.md Keep RTVision npm registry/unsigned Windows and Linux installer/WSL libatomic guidance; add Muse installation entry/link.
docs/user/keybindings.md Keep Vim navigation guide and upstream chat.find guide; reconcile Vim search wording if client owner routes slash search through new server find.
docs/user/remote-access.md Keep registry commands, WSL SSH account/distro restrictions and native Chromium/absolute override guidance; add route-specific permissions section.
docs/user/source-control.md Keep Gitea/tea review, private-host, viewed, dependency-chain, reactions and CI guidance; add upstream authenticated GitHub Enterprise host note.
docs/user/terminal.md Keep upstream navigation/copy keys followed by fork separate-window Neovim instructions.
knip.jsonc Keep service-launcher entry and Neovim helper/type entries; add upstream @napi-rs/keyring external exception.
packages/client-runtime/package.json Retain low-disk-space/editor-choice exports. Take upstream usage-progress/model-version exports. The final client-runtime manifest does not declare a provider-core dependency. Remove superseded codex/markdown exports relocated to shared; callers were searched for stale imports.
packages/contracts/src/ipc.ts Keep terminal-editor APIs, SSH runner/distro/user, isNewTarget and WSL routing. Add upstream preview open-link event and optional CLI shadowedBy.
packages/contracts/src/rpc.ts Keep fork PR methods, scoped refresh payload/result union and low-disk opt-in; add upstream find/history/profile RPC schemas.
packages/contracts/src/server.ts Keep auth accountId and optional low-disk schema/events. Add upstream update-required-model metadata and capabilities.
packages/contracts/src/settings.ts Keep Vim settings/default/patch. Accept upstream instance-only settings migration and provider-owned settings schemas. Do not resurrect the retired providers map.
packages/shared/package.json Take upstream Markdown/file-links/search/auth/core-helper exports and parser dependencies; preserve sshRuntime/giteaAttachments/releasePackage.
pnpm-lock.yaml Take all upstream provider links/Muse/Electron/Markdown/native patch changes; retain fork @pierre/diffs patch hash 7227ce... and @shikijs/langs entry. Do not replace whole lock with upstream.
scripts/release-smoke.ts Take all nine provider workspace manifests; retain fork existing-lock behavior during version-bump smoke.

Complete incoming commit inventory

Candidate 21faf52b16b3f3982ed9a45f6bdd8696811d7857, preserving merge 42a979359e68589ca82b9891a42770a5534a3144 and both pinned ancestors.

Validation and review gates

Focused client, desktop, provider migration, authorization, GitHub checkout, managed tea config, Alpine/browser/runtime, publication metadata, permission revocation, download concurrency and process-containment regressions were run. Scoped server, web and desktop typechecks plus touched-source lint are recorded in the local evidence directory. CI owns repo-wide checks.

All applicable checks and all 17 CI workflow jobs passed on previous candidate 81ce992090. All applicable checks and transfer budgets passed on prior candidate 54196dff0c. All applicable CI checks and all ten transfer ceilings pass at 21faf52b16. Complete independent source approval and primary GO remain pending for this SHA. Preparatory reviews do not approve the final candidate; their findings were verified and addressed. CodeRabbit was requested and explicitly skipped review: 904 files exceed its 100-file limit. The maintainer-authorized large-diff fallback requires primary GO plus complete independent GPT-6 Astra exact-candidate source GO and passing required CI. Scoped source approvals are recorded below; complete source approval remains pending. Merge, artifacts, isolated release install/preflight/PTY, registry integrity and GitHub publication are separate gates and remain pending.

CI fixture repair on 6d602ef

CI on 42a9793 found five retained ConnectionsSettings relay-permission tests failing because their environment mock omitted connection state now consumed by upstream Session Permissions. Added the connected state to that test fixture. All five failures reproduced locally, all five pass after the repair; scoped lint and repair diff check pass. Runtime source is unchanged. The aggregate Check failure was downstream of Test Web only. Transfer-budget measurements on 42a9793 passed every enforced ceiling. The fixture-only repair is commit 6d602ef8ce7970854ffcbd247e7ba345453bf812; its CI passed after one targeted Grok replay retry. CI and transfer budgets pass on final candidate 81ce992090; complete Astra source approval remains pending. Source approvals for previous SHAs do not qualify this candidate.

Desktop CLI review repairs

Independent Astra release review found two defects in upstream Unix CLI installation: removing an owned old-home launcher before a collision refusal, and classifying non-executable files or directories as runnable PATH commands. Collision refusal now occurs before unlinking. PATH probes require a regular file and current-user executable access. Four service regressions fail before the repair; all 19 installer/launcher tests pass after it. Scoped lint, formatting, desktop Effect typecheck and repair whitespace checks pass. Signed repair 7089335e4664146e94ca892d8d861809bdf84b8b is pushed. CI and transfer budgets passed on 7089335. The subsequent source repairs passed fresh CI on 81ce992090; complete source approval remains pending.

The broad client, release and provider-core Astra reviews returned NO-GO for incomplete coverage; they supply no final approval. The path inventory now includes 136 previously omitted moved/deleted paths from complete actual-parent no-rename diffs. Review coverage is being completed in bounded scopes, followed by an independent aggregate integration review.

The release review also identified a pre-existing desktop browser form POST-body limitation. Its behavior is unchanged by this sync and is recorded as a limitation, not an additional introduced regression.

Find/Vim and Muse review repairs

Independent Astra review found a merged event-ordering regression: with Vim enabled, Escape left Thread Find open while moving focus to chat. The Find input now closes itself before window bubbling, using the existing close/focus path and preserving IME Escape. The focused DOM regression fails before repair only with Vim enabled; all three Find/diff-search cases pass after it. This covers the real Find input and Vim listeners in a controlled chat harness, not a browser or full ChatView render.

The interrupted Muse review identified an ownership defect, which the primary reviewer reproduced with an ordered adapter test: a user turn adopts a native report that launches a workflow; its later completion was rejected after the user turn ended. The background handler now accepts native IDs already owned by that turn, including joined report IDs. An unrelated turn cannot settle the same item. The new regression fails before repair while all 23 existing cases pass; all 24 adapter tests pass after repair. It checks published completion, cleared pending work and the host-idle eligibility flag without sleeps or polling.

Signed repair 81ce992090e7e4f5e1824ed96c9d2dbb0384df24 is pushed. Scoped web and Muse typechecks, scoped lint, formatting and repair whitespace checks pass. Lint retains one warning on the unchanged Find focus-request effect; Muse typecheck retains two non-error Effect suggestions on an unchanged continuation expression. Fresh Astra reviews give scoped SOURCE GO at 81ce992090 for all 38 Muse current/historical paths, all 5 ChatView/Find/Vim paths, and all 38 packaging plus 2 CLI installer paths, and all 6 remaining packaging build-script paths, plus all 28 current/historical Pi adapter/continuation/tool paths and all 9 Pi status/settings/transport/metadata paths with their historical aliases. MU-F1, CV-F1 and CLI F1/F2 are independently closed on this candidate. Remaining source scopes and the aggregate integration review still need approval. Fresh independent review, aggregate source approval, merge and release gates remain pending. Required CI and exact-SHA transfer budgets now pass on 81ce992090.

Older desktop preview compatibility repair

Astra found SC-F1 in the new preview link event: an older desktop shell exposes preview but lacks onOpenLink. The new client called it unconditionally on mount. The contract now declares the capability optional, and the client guards the subscription while preserving current-shell cleanup and event routing. A real React DOM mount regression fails before repair with onOpenLink is not a function; after repair the legacy host mounts, pointer state updates still reach the real pointer store, and the pointer subscription cleans up on unmount. All three focused mount/pointer tests pass. This uses isolated hook dependencies and no browser or packaged-shell runtime. Web and contracts typechecks, scoped lint, formatting and whitespace pass. One unchanged theme-effect dependency warning remains.

Signed commit 54196dff0cf47fa5f40350a4a4daf5c4b764860b is pushed. The earlier scoped GOs and green CI apply to 81ce992090 only. Astra independently closed SC-F1 and gave SOURCE GO for all 11 assigned contracts paths at 54196dff0c, including complete repair consumer/test inspection. Astra also gave SOURCE GO for all 25 desktop runtime/IPC/account-routing paths, with no assigned coverage gaps or unresolved findings. All applicable checks and transfer budgets pass on 54196dff0c; all final-SHA source approvals must still be renewed. In-flight old-candidate reviews were stopped before changing the checkout. The complete history/source manifest now covers 1,482 paths including the new regression, with no missing non-reference paths. Merge and release 0.0.76 remain pending.

Desktop browser profile identity repair

Astra found BF-F1: an unprofiled desktop preview guest could use the configured Work partition while its controls cleared Default, and new links/runtime moves could use Personal after changing defaults. Three real host/view/preview-state regressions reproduce those failures. The native guest/config and IPC/RPC/chrome seams are isolated; this is no browser or packaged Electron claim.

Each native tab now pins its effective profile in environment/thread preview state after settings hydrate. Guest creation waits for the pin. Labels, clear-cookie/cache targets, source-tab links and runtime moves use that identity. Settings changes and omitted-profile snapshot updates cannot move the guest. Failed-close recovery retains the profile; confirmed closure, authoritative removal, thread deletion and server-epoch changes clear it. Late old-epoch pins and unknown/suppressed tabs are rejected. Explicit snapshot profiles take precedence when first pinning.

All three reproductions pass after repair; all 46 focused host/view/store tests pass, including profile lifecycle and isolation cases. Scoped web typecheck, lint, formatting and whitespace pass; three warnings remain in unchanged code. Signed commit 21faf52b16b3f3982ed9a45f6bdd8696811d7857 is pushed. Earlier scoped GOs and CI receipts apply to their stated old SHAs only. BF-F1 and SC-F1 are independently closed at this SHA in the browser/preview, state and contract boundaries. All applicable CI checks and all ten transfer ceilings pass. Complete source coverage, aggregate Astra GO, primary GO, merge and release gates remain pending. Complete source/history inventory covers 1,483 paths with no missing non-reference paths.

Model and harness: GPT-6.1 Sol with GPT-6 Astra independent reviews, through the Codex harness in T3 Code.

Prior candidate review receipts at 21faf52

At 21faf52b16b3f3982ed9a45f6bdd8696811d7857, scoped SOURCE GO is recorded for clients-web-navigation-runtime-5, clients-browser-files-preview-1, release-packaging-1, release-desktop-runtime-2, release-cli-install, orchestration-bounded-01, orchestration-bounded-02, shared-contracts-bounded-01, shared-contracts-bounded-02. Each approval covers its assigned source only. Exact-head CI and transfer receipts are in workflow-state.json. CLI F1/F2 and publication metadata are independently closed by the combined packaging/CLI review. Complete independent source coverage and aggregate/primary GO remain pending; merge and release have not started.

Find history retry repair and current candidate

Astra found CR-F1 in upstream Find paging: conversation loading can reveal40 turns while a failed complete stage leaves the original cursor. Ordinary retry asks for20 turns and prepends21-40 before the already-visible1-20. A valid40-turn HTTP/state regression fails before repair with that exact order; the replacement-snapshot control passes. History metadata now retains the incomplete expanded target across failure/interruption. Ordinary retry finishes that target, then complete-page cursor advancement removes it. Replacement snapshots clear it even with the same cursor. The merge still preserves live row values and existing stale-cursor guards. Web/desktop Find and shared web/mobile history use the same state; no wire schema,origin or provider change.

All60 focused history/state tests pass. Client-runtime typecheck,scoped lint,format and whitespace pass. Signed pushed candidate 67b11f9edc8a8b00a113fab0ec5e213c5bbeee22, tree de9d6aa588eba28897d7415ad20d6ce44b8f21e7, is the direct child of21faf52b16. Six postmerge overlays preserve upstream ancestry. All earlier source and CI approvals remain historical for their statedSHA;fresh source reviews,independent CR-F1 closure,aggregate Astra/primaryGO and CI are pending. Merge/release0.0.76 have not started.

Nonblocking pre-existing observations remain unresolved: ProviderRuntimeRecoveryService test names startup/shutdown but calls startup twice; initial old-session release can overwrite replacement persisted ready status after cleanup,while the retry path checks replacement ownership. Both baseline mechanisms were inspected and unchanged by this sync; no repair or runtime reproduction is claimed.

t3dotgg and others added 30 commits October 8, 2026 01:56
Co-authored-by: Guillaume <78903686+grodriguez-fr@users.noreply.github.com>
Co-authored-by: Cristian Uibar <cristi@buffup.media>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…otgg#17137)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
… databases (pingdotgg#17139)

Takeover of pingdotgg#13902.

Co-authored-by: Derek Trimm <275381468+derektrimm@users.noreply.github.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…le decoding (pingdotgg#17141)

Continues pingdotgg#17044 by @SunkenInTime.

Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…dotgg#16970)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…7140)

Keep up to six Cursor usage pages requested ahead of the one being read, still read in page order, and cancel requests left in flight when the read ends.

Continues pingdotgg#14384.

Co-authored-by: Krishna Vijay <228381532+im-kvijay@users.noreply.github.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…rge (pingdotgg#17148)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…only what is still loading (pingdotgg#17147)

Takeover of pingdotgg#16376.

Co-authored-by: Ben Davis <45952064+bmdavis419@users.noreply.github.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…#17152)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…pos (pingdotgg#15946)

Co-authored-by: PR Batch Tester <agent@local.test>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…0439)

Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…id (pingdotgg#17211)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…rs (pingdotgg#17077)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
…otgg#17214)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…otgg#14314)

Co-authored-by: PR Batch Tester <agent@local.test>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…otgg#17271)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
juliusmarminge and others added 17 commits October 8, 2026 18:29
…age (pingdotgg#17345)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…age (pingdotgg#17354)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Merge upstream 43f8a8d, retain required RTVision behavior, and repair verified provider, preview, authorization and packaging integration defects.
@kalvenschraut

Copy link
Copy Markdown
Member Author

@coderabbitai review

@github-actions github-actions Bot added the vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. label Oct 9, 2026
@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review skipped: 904 files exceed the limit of 100.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@github-actions github-actions Bot added size:XXL 📱 Native Change Changes the native fingerprint; merging blocks production OTAs until a new store build ships. labels Oct 9, 2026
@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

Provider Metric Main baseline This PR Impact PR ceiling
Codex Total thread wire 4.9 KiB 5.0 KiB +23 B (+0.5%) 6.8 KiB ✅
Codex Thread snapshot wire 3.8 KiB 3.8 KiB 0 B (0.0%) 4.9 KiB ✅
Codex Live turn WebSocket wire 1.2 KiB 1.2 KiB +23 B (+1.9%) 2.0 KiB ✅
Codex Live turn WebSocket decoded 20.8 KiB 20.9 KiB +41 B (+0.2%) 29.3 KiB ✅
Codex Live turn messages 1 2 +1 (+100.0%) 8 ✅
Claude Total thread wire 5.0 KiB 5.0 KiB −7 B (−0.1%) 6.8 KiB ✅
Claude Thread snapshot wire 3.8 KiB 3.8 KiB 0 B (0.0%) 4.9 KiB ✅
Claude Live turn WebSocket wire 1.2 KiB 1.2 KiB −7 B (−0.6%) 2.0 KiB ✅
Claude Live turn WebSocket decoded 21.2 KiB 21.2 KiB 0 B (0.0%) 29.3 KiB ✅
Claude Live turn messages 2 2 0 (0.0%) 8 ✅

Baseline: dfe5bde · PR result: 07a33e7 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 108.5 KiB
  • Claude decoded thread snapshot: 108.8 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

📱 Native Change Changes the native fingerprint; merging blocks production OTAs until a new store build ships. size:XXL vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.