Skip to content

chore: merge upstream pingdotgg/t3code through 611132c171 - #195

Merged
andrewcai8 merged 88 commits into
mainfrom
sync/upstream-2026-10-07
Oct 8, 2026
Merged

andrewcai8 merged 88 commits into
mainfrom
sync/upstream-2026-10-07

Conversation

@andrewcai8

@andrewcai8 andrewcai8 commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

The daily upstream sync has failed since 2026-10-06 because git merge upstream/main hit 38 conflicts. This merges upstream 76d3c96fd..611132c171 (80 commits) by hand, as a real merge commit. The fork's cloud machines, Home port, worker forks and account rotation all stay. Upstream wins everywhere else.

Notable upstream changes

There is no new visualization feature in this range. Inline HTML pages for agents landed in the previous sync (#172), and pingdotgg#16752 only stops them painting slab backgrounds.

Cross-environment series and Home

Conflicted files and how each was resolved

Upstream only:

  • packages/shared/src/threadLinks.ts and threadLinks.test.ts (add/add). Upstream also escapes parentheses.
  • apps/server/src/orchestration-v2/ThreadSettlementService.ts
  • apps/web/src/components/ChatMarkdown.tsx

Contracts and client runtime:

  • packages/contracts/src/rpc.ts: kept the Home and fleet RPCs. Dropped the preview-automation RPCs, as upstream did.
  • packages/client-runtime/src/rpc/client.ts: same, so fleetConnect stays a stream method.
  • packages/contracts/src/orchestratorMcp.ts: kept the fork's projectId on thread list items.
  • packages/client-runtime/src/providerSkills.ts: both sides. Upstream's hasCurrentProviderWorkspaceSnapshot sits next to the fork's provisioned skills.

Server MCP:

  • apps/server/src/mcp/OrchestratorMcpService.ts: upstream's shell-based snooze. Kept the fork's exported readThreadPage and list helpers. readThreadPage now takes the shell, and Home's threads.read loads it.
  • apps/server/src/mcp/McpHttpServer.ts and the orchestrator, project and thread toolkits: upstream's McpToolAccess declarations with the fork's Home routing inside them.
    • t3_thread_launch uses upstream's startsThreads. Home and remote launches still go through runAsHome, which needs a live full-access caller.
    • The Home toolkit is now declared too: reads for list, writes for watch, actsAsCaller for fork runs, readsAsCaller for fork status.
  • toolkits/core.test.ts and toolkits/project/handlers.test.ts: upstream's test layers plus notHomeLayer.

Server, other:

  • apps/server/src/auth/RpcAuthorization.ts: upstream's split scopes. Kept the fork's environment-control, Home and fleet scopes.
  • apps/server/src/ws.ts: upstream's handlers without observeRpcEffect (refactor(server): instrument WS RPCs in group middleware pingdotgg/t3code#15548 moved it into middleware). The fork's environment-control, Home and fleet handlers are converted the same way.
  • apps/server/src/server.ts: both routes.
  • orchestration-v2/testkit/ProviderReplayHarness.ts: kept the fork's extra ThreadManagementService output.

Web:

  • AppRoot.tsx: kept ProvisionCancellations, CloudBoxes and HomeFleetHost. Dropped PreviewAutomationHosts, which upstream deleted.
  • routes/__root.tsx: both.
  • ChatView.tsx: held cloud sends keep their message id. Upstream's compact-before-send runs alongside.
  • CommandPalette.tsx: upstream's new "No project" ordering, still hiding the Home project.
  • Sidebar.tsx, LegacySidebar.tsx, ChatHeader.tsx, useThreadActionMenu.ts: the fork's cloud-machine menu items and Home imports next to upstream's permission gates and useOrchestrationCommand.
  • useThreadActions.ts: upstream's permission checks and delete flow, gated by the fork's offline-delete handling. Upstream dropped the terminal close.
  • chat/MessagesTimeline.tsx: the fork's footerCard, then upstream's footer inside TimelineListFooter.

Mobile:

  • App.tsx, useThreadListActions.ts, SettingsScheduledTasksRouteScreen.tsx, SettingsThreadsRouteScreen.tsx, thread-list-v2-items.tsx, use-thread-outbox-drain.ts: both sides.

Scripts:

  • scripts/lib/cli-external-packages.test.ts: the fork's externals plus upstream's playwright-core.

What the fork had to adapt beyond the conflicts

  • environmentControl/wsHandlers.ts loses its observeRpcEffect parameter, since upstream removed the helper.
  • homeRouting.readHomeChangeCaller used readFullAccessCaller, which upstream removed. It now uses readCaller + assertLiveCaller + assertFullAccess, with the same rule as before.
  • ProviderAccountSwitch.test.ts hung for 120s on every case. Upstream's makeClaudeAdapterV2 now requires a crypto service, and the test's fake driver did not pass one. It now does.
  • ServerUpdateAction: upstream gates server updates on environment:maintain for that environment. A cloud guest upgraded through its manager is authorized by the manager, so that path skips the guest's own grant. Otherwise "Update via manager" would be disabled.
  • useThreadActions.unsettleThread checks the operate grant before it wakes a cloud machine.
  • Upstream's new useThreadActions.permissions.test.ts and useThreadActionMenu.test.ts mock every module the hooks import. They now also stub the fork's cloud hooks.
  • CI keeps the fork's runner choices. The merge only brought upstream's new Chromium install step.

Submodule warning in the sync workflow

fatal: No url found for submodule path '.repos/alchemy-effect/submodules/distilled' comes from the gitlinks .repos/alchemy-effect/submodules/{distilled,floci}, which have no .gitmodules. Upstream main has the same gitlinks. The message prints in actions/checkout's post-job cleanup as a warning, after the merge step had already failed on conflicts. It does not fail the job, and fork CI checks out fine. Deleting the gitlinks would only open a new difference from upstream, so this PR leaves them.

Cloud chats re-pair after the scope change

Servers never widen a stored grant (pingdotgg#10298). Before this merge the fork's standard client grant was only orchestration:read/operate, terminal:operate, review:write and relay:read. Every device already paired with a cloud box would keep that grant after the box upgrades and lose file search and the explorer, commit/push/PR, preview control and settings on every existing cloud chat. The permission-update notice would then ask the user to pair again with a new link, which a cloud chat cannot do.

Fix (fix(client): cloud chats re-pair themselves when a box upgrade narrows their permissions):

  • registryBoxes.ts. A paired box's first dial in a launch reads its grant over the new connection. If it is the legacy grant, the box pairs once more through its host, the legacy session closes, and the dial continues with the standard grant. The check is recorded before the re-pair, so a host that still mints the legacy grant is asked once per box per launch, never in a loop. A failed re-pair keeps the working legacy connection. An old box server reports no permissions, so it is never treated as legacy.
  • boxPairing.ts / boxPairingLayer.ts. PairingRedemption gains sessionGrant, which reads /api/auth/session with the box's bearer pairing.
  • Web and mobile PermissionUpdateNotice skip box environments, since they repair themselves.
  • Tests in registry.cloud.test.ts: a legacy box re-pairs once, closes the legacy session, and ends on a fresh credential; a host that keeps minting the legacy grant is asked once across three opens; a box on the standard grant is not re-paired. The web notice test covers a box environment, and the existing cases still cover a normal paired one. The two re-pair tests and the box notice test failed before the fix.

This push also merges current main (#196, #197) so the release carries them.

Out of scope here. Review finding 2 (fork environmentControl RPCs gated on orchestration:operate rather than providers:manage / environment:maintain) follows after this lands. Finding 3 (t3_fork_cancel uses actsAsCaller) is accepted as is.

Verification

  • vp i passes and leaves pnpm-lock.yaml unchanged.
  • Server. 34 files under src/mcp (including cloudReach, homeRouting and the MCP toolkit integration), src/home, auth/RpcAuthorization and ThreadSettlementService: 351 tests pass. src/environmentControl, runtimeLayer, ManagedProjectFolders and server.test: 54 files, 886 tests pass. ProviderAccountSwitch.test.ts: 6 tests pass.
  • Web. The hand-resolved files plus src/cloud, src/components/home, src/hooks and src/components/settings: all pass.
  • Mobile. Thread, settings, home and outbox tests: 53 files, 566 tests pass.
  • Packages and scripts. shared threadLinks, client-runtime providerSkills and rpc, contracts rpc, scripts/lib/cli-external-packages: all pass.
  • vp lint on the changed areas: no errors.
  • Typecheck is not run locally, so CI's Typecheck is the first full compile of the merged fork code.

Risks

  • Upstream changed many service signatures, and the fork's auto-merged code is only proven by the tests above. The adapter crypto option was one such break. CI Typecheck may find more.
  • Clients and servers from before and after this merge disagree on scopes. Upstream's fix(auth): keep old clients connected across scope changes pingdotgg/t3code#10298 is meant to keep old clients connected. Cloud chats now re-pair themselves (above). Unverified guess: a manually paired phone or browser may still lose access it had, such as the diagnostics grant the Usage page now needs, until it pairs again.
  • Home and remote launches go through FleetService, which does not apply upstream's new existing-worktree check (feat(server): every T3 MCP tool declares who may call it pingdotgg/t3code#16335 assertProjectWorktree). This was already the case before the merge. Home is full-access only.

Claude Opus 5.5 (1M context), Claude Code

🤖 Generated with Claude Code

Yash-Singh1 and others added 30 commits October 6, 2026 03:58
…g#13217)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…ingdotgg#16400)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
…#16515)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
…dotgg#14825)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
)

Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
…ibfuse2 launch failure) (pingdotgg#7765)

Co-authored-by: Julius Marminge <julius0216@outlook.com>
…ingdotgg#16319)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
pingdotgg#16320)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…stead of gh (pingdotgg#16321)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…wer reads per PR action (pingdotgg#16322)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ow it (pingdotgg#16551)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tgg#16571)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
juliusmarminge and others added 18 commits October 6, 2026 20:30
)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…#10298)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…rver (pingdotgg#16718)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…g#16741)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…16752)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ngdotgg#16290)

Co-authored-by: spoukyii <61633921+spoukyii@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ices (pingdotgg#16631)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tgg#16762)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s of untracked files (pingdotgg#16771)

Co-authored-by: Braulio Oliveira <brauliobo@gmail.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
…eep (pingdotgg#16760)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ingdotgg#16761)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ingdotgg#16782)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Merges 80 upstream commits (76d3c96..611132c). The daily sync failed
on 38 conflicts; this resolves them, keeps the fork's cloud machines, Home
port and account rotation, and takes upstream everywhere else.

Upstream changes the fork had to follow:
- Every T3 MCP tool now declares who may call it (McpToolAccess, pingdotgg#16335).
  The Home toolkit and the Home routing in the orchestrator, project and
  thread toolkits now register through it. readFullAccessCaller is gone, so
  homeRouting checks a live, full-access caller with upstream's helpers.
- WS RPC instrumentation moved into group middleware (pingdotgg#15548), so the
  environment-control, Home and fleet handlers drop observeRpcEffect.
- The browser moved to the environment server (pingdotgg#15328): the preview
  automation RPCs and PreviewAutomationHosts are gone on both sides.
- pingdotgg#16782 landed the thread-link and snooze part of the fork's pingdotgg#15975 port.
  Upstream's threadLinks, MarkdownThreadLink and snooze code win; the
  fork's readThreadPage now takes the thread shell like upstream's read.
- makeClaudeAdapterV2 needs a Crypto service; ProviderAccountSwitch.test
  passes one.
- Scope splits (pingdotgg#9786-pingdotgg#9791): server update now needs environment:maintain
  on the guest, except a guest upgraded through its manager, which the
  manager authorizes. Unsettle checks the operate grant before waking a
  cloud machine.

Conflicted files and resolutions:
- packages/shared/src/threadLinks{,.test}.ts,
  orchestration-v2/ThreadSettlementService.ts, ChatMarkdown.tsx: upstream.
- packages/contracts/src/rpc.ts, client-runtime rpc/client.ts: Home and
  fleet RPCs kept, preview automation RPCs dropped with upstream.
- packages/contracts/src/orchestratorMcp.ts: fork's projectId on list items.
- mcp/OrchestratorMcpService.ts: upstream's shell-based snooze, fork's
  exported readThreadPage and list helpers.
- mcp/McpHttpServer.ts, mcp/toolkits/{orchestrator,project,thread}/*,
  core.test.ts, project/handlers.test.ts: upstream's McpToolAccess
  declarations with the fork's Home routing inside them.
- auth/RpcAuthorization.ts: upstream's split scopes, plus the fork's
  environment-control, Home and fleet methods.
- ws.ts, server.ts: upstream's handlers and routes, plus the fork's.
- orchestration-v2/testkit/ProviderReplayHarness.ts: fork's extra output.
- web AppRoot, __root, ChatView, CommandPalette, Sidebar, LegacySidebar,
  ChatHeader, MessagesTimeline, useThreadActionMenu, useThreadActions:
  both sides (cloud machines, Home, held cloud sends next to upstream's
  permission gates, compaction, footer and ordering changes).
- mobile App, useThreadListActions, settings screens, thread-list-v2-items,
  use-thread-outbox-drain: both sides.
- client-runtime providerSkills.ts: both helpers.
- scripts/lib/cli-external-packages.test.ts: fork's externals plus
  upstream's playwright-core.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL labels Oct 7, 2026
Brings in #193 and #194, which landed on main after the sync branched.

- ProviderSessionManager.ts: upstream's release-on-interrupt for a failed
  attach, with #193's holdsOpenLock on both branches, since both run
  under the session's open lock.
- ProviderSessionManager.test.ts: both sides' test options and sinks.
- mcp/toolkits/home/handlers.ts: #194's t3_fork_cancel, declared through
  McpToolAccess like t3_fork_run.
- #193's new Claude adapter tests pass the Crypto service upstream's
  makeClaudeAdapterV2 now needs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added the 📱 Native Change Changes the native fingerprint; merging blocks production OTAs until a new store build ships. label Oct 7, 2026
andrewcai8 and others added 4 commits October 7, 2026 16:08
…loud onboarding test

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The thread menu state now carries canOperate, and the mobile outbox
permissions test stubs the fork's cloud chat delivery, whose imports
load Expo outside a device.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The reconnect verifier drops the client scopes upstream removed from
ClientPresentation, and the provider credential name keeps its node:crypto
hash under the nodeBuiltinImport diagnostic upstream now enforces.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…pstream

Upstream's RPC instrumentation needs an aggregate label for every RPC, so
the environment-control, Home and fleet methods get theirs. Thread launch
now needs GitVcsDriver and scheduled tasks carry the fork's target, which
three tests now provide.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

Provider Metric Main baseline This PR Impact PR ceiling
Codex Total thread wire 5.0 KiB 4.9 KiB −23 B (−0.5%) 6.8 KiB ✅
Codex Thread snapshot wire 3.8 KiB 3.8 KiB 0 B (0.0%) 4.9 KiB ✅
Codex Live turn WebSocket wire 1.2 KiB 1.2 KiB −23 B (−1.9%) 2.0 KiB ✅
Codex Live turn WebSocket decoded 20.9 KiB 20.8 KiB −41 B (−0.2%) 29.3 KiB ✅
Codex Live turn messages 2 1 −1 (−50.0%) 8 ✅
Claude Total thread wire 5.0 KiB 5.0 KiB 0 B (0.0%) 6.8 KiB ✅
Claude Thread snapshot wire 3.8 KiB 3.8 KiB 0 B (0.0%) 4.9 KiB ✅
Claude Live turn WebSocket wire 1.2 KiB 1.2 KiB 0 B (0.0%) 2.0 KiB ✅
Claude Live turn WebSocket decoded 21.2 KiB 21.2 KiB 0 B (0.0%) 29.3 KiB ✅
Claude Live turn messages 2 2 0 (0.0%) 8 ✅

Baseline: 9e2a007 · PR result: 3bee0f3 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 108.5 KiB
  • Claude decoded thread snapshot: 108.8 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

andrewcai8 and others added 2 commits October 8, 2026 09:10
…s their permissions

Servers never widen a stored grant, so a device paired with a cloud box
before granular permissions kept only the old scopes after the box
upgraded, losing file search, source control, preview, and settings on
every existing cloud chat. The notice then asked the user to pair again
with a new link, which a cloud chat cannot do.

A paired box's first dial in a launch now reads its grant. A legacy
grant pairs once more through the box's host, closes the old session,
and dials with the standard grant. The check is recorded before the
re-pair, so a host that still mints the old grant is asked once per
launch. The permission-update notice skips box environments on web and
mobile.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@andrewcai8
andrewcai8 merged commit 57fde0d into main Oct 8, 2026
40 of 43 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

📱 Native Change Changes the native fingerprint; merging blocks production OTAs until a new store build ships. size:XXL vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.