Repository navigation
chore: merge upstream pingdotgg/t3code through 611132c171 - #195
Merged
Merged
Conversation
…g#13217) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…ingdotgg#16400) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
…#16515) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
…dotgg#14825) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
…ibfuse2 launch failure) (pingdotgg#7765) Co-authored-by: Julius Marminge <julius0216@outlook.com>
…ingdotgg#16319) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
pingdotgg#16320) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…stead of gh (pingdotgg#16321) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…wer reads per PR action (pingdotgg#16322) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ow it (pingdotgg#16551) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tgg#16571) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…#10298) Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…rver (pingdotgg#16718) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…g#16741) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…16752) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ngdotgg#16290) Co-authored-by: spoukyii <61633921+spoukyii@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ices (pingdotgg#16631) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tgg#16762) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s of untracked files (pingdotgg#16771) Co-authored-by: Braulio Oliveira <brauliobo@gmail.com> Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
…eep (pingdotgg#16760) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ingdotgg#16761) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ingdotgg#16782) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Merges 80 upstream commits (76d3c96..611132c). The daily sync failed on 38 conflicts; this resolves them, keeps the fork's cloud machines, Home port and account rotation, and takes upstream everywhere else. Upstream changes the fork had to follow: - Every T3 MCP tool now declares who may call it (McpToolAccess, pingdotgg#16335). The Home toolkit and the Home routing in the orchestrator, project and thread toolkits now register through it. readFullAccessCaller is gone, so homeRouting checks a live, full-access caller with upstream's helpers. - WS RPC instrumentation moved into group middleware (pingdotgg#15548), so the environment-control, Home and fleet handlers drop observeRpcEffect. - The browser moved to the environment server (pingdotgg#15328): the preview automation RPCs and PreviewAutomationHosts are gone on both sides. - pingdotgg#16782 landed the thread-link and snooze part of the fork's pingdotgg#15975 port. Upstream's threadLinks, MarkdownThreadLink and snooze code win; the fork's readThreadPage now takes the thread shell like upstream's read. - makeClaudeAdapterV2 needs a Crypto service; ProviderAccountSwitch.test passes one. - Scope splits (pingdotgg#9786-pingdotgg#9791): server update now needs environment:maintain on the guest, except a guest upgraded through its manager, which the manager authorizes. Unsettle checks the operate grant before waking a cloud machine. Conflicted files and resolutions: - packages/shared/src/threadLinks{,.test}.ts, orchestration-v2/ThreadSettlementService.ts, ChatMarkdown.tsx: upstream. - packages/contracts/src/rpc.ts, client-runtime rpc/client.ts: Home and fleet RPCs kept, preview automation RPCs dropped with upstream. - packages/contracts/src/orchestratorMcp.ts: fork's projectId on list items. - mcp/OrchestratorMcpService.ts: upstream's shell-based snooze, fork's exported readThreadPage and list helpers. - mcp/McpHttpServer.ts, mcp/toolkits/{orchestrator,project,thread}/*, core.test.ts, project/handlers.test.ts: upstream's McpToolAccess declarations with the fork's Home routing inside them. - auth/RpcAuthorization.ts: upstream's split scopes, plus the fork's environment-control, Home and fleet methods. - ws.ts, server.ts: upstream's handlers and routes, plus the fork's. - orchestration-v2/testkit/ProviderReplayHarness.ts: fork's extra output. - web AppRoot, __root, ChatView, CommandPalette, Sidebar, LegacySidebar, ChatHeader, MessagesTimeline, useThreadActionMenu, useThreadActions: both sides (cloud machines, Home, held cloud sends next to upstream's permission gates, compaction, footer and ordering changes). - mobile App, useThreadListActions, settings screens, thread-list-v2-items, use-thread-outbox-drain: both sides. - client-runtime providerSkills.ts: both helpers. - scripts/lib/cli-external-packages.test.ts: fork's externals plus upstream's playwright-core. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Brings in #193 and #194, which landed on main after the sync branched. - ProviderSessionManager.ts: upstream's release-on-interrupt for a failed attach, with #193's holdsOpenLock on both branches, since both run under the session's open lock. - ProviderSessionManager.test.ts: both sides' test options and sinks. - mcp/toolkits/home/handlers.ts: #194's t3_fork_cancel, declared through McpToolAccess like t3_fork_run. - #193's new Claude adapter tests pass the Crypto service upstream's makeClaudeAdapterV2 now needs. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…loud onboarding test Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The thread menu state now carries canOperate, and the mobile outbox permissions test stubs the fork's cloud chat delivery, whose imports load Expo outside a device. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The reconnect verifier drops the client scopes upstream removed from ClientPresentation, and the provider credential name keeps its node:crypto hash under the nodeBuiltinImport diagnostic upstream now enforces. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…pstream Upstream's RPC instrumentation needs an aggregate label for every RPC, so the environment-control, Home and fleet methods get theirs. Thread launch now needs GitVcsDriver and scheduled tasks carry the fork's target, which three tests now provide. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Thread transfer impact✅ Thread transfer remains within every enforced ceiling.
Baseline: Scenario and decoded snapshot size10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.
Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed. |
…s their permissions Servers never widen a stored grant, so a device paired with a cloud box before granular permissions kept only the old scopes after the box upgraded, losing file search, source control, preview, and settings on every existing cloud chat. The notice then asked the user to pair again with a new link, which a cloud chat cannot do. A paired box's first dial in a launch now reads its grant. A legacy grant pairs once more through the box's host, closes the old session, and dials with the standard grant. The check is recorded before the re-pair, so a host that still mints the old grant is asked once per launch. The permission-update notice skips box environments on web and mobile. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The daily upstream sync has failed since 2026-10-06 because
git merge upstream/mainhit 38 conflicts. This merges upstream76d3c96fd..611132c171(80 commits) by hand, as a real merge commit. The fork's cloud machines, Home port, worker forks and account rotation all stay. Upstream wins everywhere else.Notable upstream changes
linkto paste. Web, desktop and mobile opent3-thread://links as the thread. Agents also see whether a thread is snoozed and until when. This is the thread-link part of Theo's Home PR feat(home): add Home, an agent that manages threads across your machines pingdotgg/t3code#15975, which the fork had ported. Upstream's version now wins, and the fork's Home code uses it.gh(feat(server): GitHub API transport that uses gh only for the token pingdotgg/t3code#16319-feat: choose the GitHub account per host, save a GitHub token, and fewer reads per PR action pingdotgg/t3code#16322). You can pick the GitHub account per host and save a token.There is no new visualization feature in this range. Inline HTML pages for agents landed in the previous sync (#172), and pingdotgg#16752 only stops them painting slab backgrounds.
Cross-environment series and Home
packages/shared/src/threadLinks.tsand its test,MarkdownThreadLink.tsxand the mobile link handling.ThreadSettlementServiceand the MCP list and read results.ThreadFeed.tsxwas dropped.t3_environment_list,t3_thread_watchand the Home settings page.environmentId.homeRouting.ts.environmentIdparameters inpackages/contracts/src/orchestratorMcp.ts.rpc.ts(home.*andfleet.*).RpcAuthorization.ts.apps/server/src/home/services.Conflicted files and how each was resolved
Upstream only:
packages/shared/src/threadLinks.tsandthreadLinks.test.ts(add/add). Upstream also escapes parentheses.apps/server/src/orchestration-v2/ThreadSettlementService.tsapps/web/src/components/ChatMarkdown.tsxContracts and client runtime:
packages/contracts/src/rpc.ts: kept the Home and fleet RPCs. Dropped the preview-automation RPCs, as upstream did.packages/client-runtime/src/rpc/client.ts: same, sofleetConnectstays a stream method.packages/contracts/src/orchestratorMcp.ts: kept the fork'sprojectIdon thread list items.packages/client-runtime/src/providerSkills.ts: both sides. Upstream'shasCurrentProviderWorkspaceSnapshotsits next to the fork's provisioned skills.Server MCP:
apps/server/src/mcp/OrchestratorMcpService.ts: upstream's shell-based snooze. Kept the fork's exportedreadThreadPageand list helpers.readThreadPagenow takes the shell, and Home'sthreads.readloads it.apps/server/src/mcp/McpHttpServer.tsand the orchestrator, project and thread toolkits: upstream'sMcpToolAccessdeclarations with the fork's Home routing inside them.t3_thread_launchuses upstream'sstartsThreads. Home and remote launches still go throughrunAsHome, which needs a live full-access caller.readsfor list,writesfor watch,actsAsCallerfor fork runs,readsAsCallerfor fork status.toolkits/core.test.tsandtoolkits/project/handlers.test.ts: upstream's test layers plusnotHomeLayer.Server, other:
apps/server/src/auth/RpcAuthorization.ts: upstream's split scopes. Kept the fork's environment-control, Home and fleet scopes.apps/server/src/ws.ts: upstream's handlers withoutobserveRpcEffect(refactor(server): instrument WS RPCs in group middleware pingdotgg/t3code#15548 moved it into middleware). The fork's environment-control, Home and fleet handlers are converted the same way.apps/server/src/server.ts: both routes.orchestration-v2/testkit/ProviderReplayHarness.ts: kept the fork's extraThreadManagementServiceoutput.Web:
AppRoot.tsx: keptProvisionCancellations,CloudBoxesandHomeFleetHost. DroppedPreviewAutomationHosts, which upstream deleted.routes/__root.tsx: both.ChatView.tsx: held cloud sends keep their message id. Upstream's compact-before-send runs alongside.CommandPalette.tsx: upstream's new "No project" ordering, still hiding the Home project.Sidebar.tsx,LegacySidebar.tsx,ChatHeader.tsx,useThreadActionMenu.ts: the fork's cloud-machine menu items and Home imports next to upstream's permission gates anduseOrchestrationCommand.useThreadActions.ts: upstream's permission checks and delete flow, gated by the fork's offline-delete handling. Upstream dropped the terminal close.chat/MessagesTimeline.tsx: the fork'sfooterCard, then upstream'sfooterinsideTimelineListFooter.Mobile:
App.tsx,useThreadListActions.ts,SettingsScheduledTasksRouteScreen.tsx,SettingsThreadsRouteScreen.tsx,thread-list-v2-items.tsx,use-thread-outbox-drain.ts: both sides.Scripts:
scripts/lib/cli-external-packages.test.ts: the fork's externals plus upstream'splaywright-core.What the fork had to adapt beyond the conflicts
environmentControl/wsHandlers.tsloses itsobserveRpcEffectparameter, since upstream removed the helper.homeRouting.readHomeChangeCallerusedreadFullAccessCaller, which upstream removed. It now usesreadCaller+assertLiveCaller+assertFullAccess, with the same rule as before.ProviderAccountSwitch.test.tshung for 120s on every case. Upstream'smakeClaudeAdapterV2now requires acryptoservice, and the test's fake driver did not pass one. It now does.ServerUpdateAction: upstream gates server updates onenvironment:maintainfor that environment. A cloud guest upgraded through its manager is authorized by the manager, so that path skips the guest's own grant. Otherwise "Update via manager" would be disabled.useThreadActions.unsettleThreadchecks the operate grant before it wakes a cloud machine.useThreadActions.permissions.test.tsanduseThreadActionMenu.test.tsmock every module the hooks import. They now also stub the fork's cloud hooks.Submodule warning in the sync workflow
fatal: No url found for submodule path '.repos/alchemy-effect/submodules/distilled'comes from the gitlinks.repos/alchemy-effect/submodules/{distilled,floci}, which have no.gitmodules. Upstream main has the same gitlinks. The message prints in actions/checkout's post-job cleanup as a warning, after the merge step had already failed on conflicts. It does not fail the job, and fork CI checks out fine. Deleting the gitlinks would only open a new difference from upstream, so this PR leaves them.Cloud chats re-pair after the scope change
Servers never widen a stored grant (pingdotgg#10298). Before this merge the fork's standard client grant was only
orchestration:read/operate,terminal:operate,review:writeandrelay:read. Every device already paired with a cloud box would keep that grant after the box upgrades and lose file search and the explorer, commit/push/PR, preview control and settings on every existing cloud chat. The permission-update notice would then ask the user to pair again with a new link, which a cloud chat cannot do.Fix (
fix(client): cloud chats re-pair themselves when a box upgrade narrows their permissions):registryBoxes.ts. A paired box's first dial in a launch reads its grant over the new connection. If it is the legacy grant, the box pairs once more through its host, the legacy session closes, and the dial continues with the standard grant. The check is recorded before the re-pair, so a host that still mints the legacy grant is asked once per box per launch, never in a loop. A failed re-pair keeps the working legacy connection. An old box server reports nopermissions, so it is never treated as legacy.boxPairing.ts/boxPairingLayer.ts.PairingRedemptiongainssessionGrant, which reads/api/auth/sessionwith the box's bearer pairing.PermissionUpdateNoticeskip box environments, since they repair themselves.registry.cloud.test.ts: a legacy box re-pairs once, closes the legacy session, and ends on a fresh credential; a host that keeps minting the legacy grant is asked once across three opens; a box on the standard grant is not re-paired. The web notice test covers a box environment, and the existing cases still cover a normal paired one. The two re-pair tests and the box notice test failed before the fix.This push also merges current
main(#196, #197) so the release carries them.Out of scope here. Review finding 2 (fork
environmentControlRPCs gated onorchestration:operaterather thanproviders:manage/environment:maintain) follows after this lands. Finding 3 (t3_fork_cancelusesactsAsCaller) is accepted as is.Verification
vp ipasses and leavespnpm-lock.yamlunchanged.src/mcp(includingcloudReach,homeRoutingand the MCP toolkit integration),src/home,auth/RpcAuthorizationandThreadSettlementService: 351 tests pass.src/environmentControl,runtimeLayer,ManagedProjectFoldersandserver.test: 54 files, 886 tests pass.ProviderAccountSwitch.test.ts: 6 tests pass.src/cloud,src/components/home,src/hooksandsrc/components/settings: all pass.threadLinks, client-runtimeproviderSkillsandrpc, contractsrpc,scripts/lib/cli-external-packages: all pass.vp linton the changed areas: no errors.Risks
cryptooption was one such break. CI Typecheck may find more.assertProjectWorktree). This was already the case before the merge. Home is full-access only.Claude Opus 5.5 (1M context), Claude Code
🤖 Generated with Claude Code