Repository navigation
fix(desktop): cancel backend pipe reads to avoid slow shutdown - #17386
Conversation
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — The PR changes live desktop pipe-read lifecycles in two server components and adds a subprocess regression harness for shutdown behavior. It also introduces a file-level suppression for the Notes:
You can add or adjust custom eligibility rules. Learn more. |
Thread transfer impact✅ Thread transfer remains within every enforced ceiling.
Baseline: Scenario and decoded snapshot size10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.
Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed. |
## What's Changed * refactor(provider-core): share attachment prompts, notifications, and event loggers by @juliusmarminge in pingdotgg/t3code#17330 * fix(web): file previews handle downloads, in-page links, and repo paths, and favicons stop leaking internal hosts by @juliusmarminge in pingdotgg/t3code#16950 * fix(server): environment-hosted browser tabs behave like a normal browser by @juliusmarminge in pingdotgg/t3code#16963 * fix(desktop): browser tab fixes for fullscreen, shortcuts, links, reload and hidden tabs by @juliusmarminge in pingdotgg/t3code#16961 * fix(web): desktop opens remote environments' browser tabs locally by @juliusmarminge in pingdotgg/t3code#17316 * fix(desktop): the t3 command warns instead of installing behind another t3 by @juliusmarminge in pingdotgg/t3code#17351 * fix(web): images, video, HTML and PDF preview in a thread before its first message by @juliusmarminge in pingdotgg/t3code#17352 * refactor(provider-muse): move Muse Code into its own provider package by @juliusmarminge in pingdotgg/t3code#17331 * fix(web): semantic branch naming hint lines up with its setting by @limineol in pingdotgg/t3code#16972 * fix(mobile): restore chat image previews in the v5 stack by @juliusmarminge in pingdotgg/t3code#17361 * feat(mobile): fade working threads and match web's status labels by @juliusmarminge in pingdotgg/t3code#17368 * fix(server): agent browser tools stop bloating history, fall back sensibly, and respect ownership by @juliusmarminge in pingdotgg/t3code#16956 * fix(web): add room for thread timeline markers by @Yash-Singh1 in pingdotgg/t3code#17372 * fix(web): drop sidebar context before cancelling pointer drag by @Yash-Singh1 in pingdotgg/t3code#17373 * refactor(providers): namespace-import service modules in core, Muse, Pi, and testing by @juliusmarminge in pingdotgg/t3code#17375 * fix(auth): show connection permissions and enforce session lifetime by @juliusmarminge in pingdotgg/t3code#17370 * refactor(provider-opencode): move OpenCode into its own provider package by @juliusmarminge in pingdotgg/t3code#17345 * refactor(provider-cursor): move Cursor into its own provider package by @juliusmarminge in pingdotgg/t3code#17349 * refactor(provider-acp): move the shared ACP adapter into its own package by @juliusmarminge in pingdotgg/t3code#17354 * refactor(provider-grok): move Grok into its own provider package by @juliusmarminge in pingdotgg/t3code#17357 * fix(server): speed up long thread message sync by @Yash-Singh1 in pingdotgg/t3code#17387 * fix(desktop): cancel backend pipe reads to avoid slow shutdown by @Yash-Singh1 in pingdotgg/t3code#17386 * refactor(providers): adapter factories yield their services by @juliusmarminge in pingdotgg/t3code#17381 * fix(web): show a row spinner instead of a banner when expanding a folder by @juliusmarminge in pingdotgg/t3code#17378 * fix(server): a timed-out browser drag no longer exits the server by @ScottN-PV in pingdotgg/t3code#17360 * fix(server): a logged-out Claude CLI no longer reports as authenticated by @yordis in pingdotgg/t3code#15459 * fix(server): Pi loads every selected skill without losing prompt text by @StiensWout in pingdotgg/t3code#17194 ## New Contributors * @limineol made their first contribution in pingdotgg/t3code#16972 **Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261008.2849...v0.0.46-nightly.20261009.2861 Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261009.2861
## What's Changed * refactor(provider-core): share attachment prompts, notifications, and event loggers by @juliusmarminge in pingdotgg/t3code#17330 * fix(web): file previews handle downloads, in-page links, and repo paths, and favicons stop leaking internal hosts by @juliusmarminge in pingdotgg/t3code#16950 * fix(server): environment-hosted browser tabs behave like a normal browser by @juliusmarminge in pingdotgg/t3code#16963 * fix(desktop): browser tab fixes for fullscreen, shortcuts, links, reload and hidden tabs by @juliusmarminge in pingdotgg/t3code#16961 * fix(web): desktop opens remote environments' browser tabs locally by @juliusmarminge in pingdotgg/t3code#17316 * fix(desktop): the t3 command warns instead of installing behind another t3 by @juliusmarminge in pingdotgg/t3code#17351 * fix(web): images, video, HTML and PDF preview in a thread before its first message by @juliusmarminge in pingdotgg/t3code#17352 * refactor(provider-muse): move Muse Code into its own provider package by @juliusmarminge in pingdotgg/t3code#17331 * fix(web): semantic branch naming hint lines up with its setting by @limineol in pingdotgg/t3code#16972 * fix(mobile): restore chat image previews in the v5 stack by @juliusmarminge in pingdotgg/t3code#17361 * feat(mobile): fade working threads and match web's status labels by @juliusmarminge in pingdotgg/t3code#17368 * fix(server): agent browser tools stop bloating history, fall back sensibly, and respect ownership by @juliusmarminge in pingdotgg/t3code#16956 * fix(web): add room for thread timeline markers by @Yash-Singh1 in pingdotgg/t3code#17372 * fix(web): drop sidebar context before cancelling pointer drag by @Yash-Singh1 in pingdotgg/t3code#17373 * refactor(providers): namespace-import service modules in core, Muse, Pi, and testing by @juliusmarminge in pingdotgg/t3code#17375 * fix(auth): show connection permissions and enforce session lifetime by @juliusmarminge in pingdotgg/t3code#17370 * refactor(provider-opencode): move OpenCode into its own provider package by @juliusmarminge in pingdotgg/t3code#17345 * refactor(provider-cursor): move Cursor into its own provider package by @juliusmarminge in pingdotgg/t3code#17349 * refactor(provider-acp): move the shared ACP adapter into its own package by @juliusmarminge in pingdotgg/t3code#17354 * refactor(provider-grok): move Grok into its own provider package by @juliusmarminge in pingdotgg/t3code#17357 * fix(server): speed up long thread message sync by @Yash-Singh1 in pingdotgg/t3code#17387 * fix(desktop): cancel backend pipe reads to avoid slow shutdown by @Yash-Singh1 in pingdotgg/t3code#17386 * refactor(providers): adapter factories yield their services by @juliusmarminge in pingdotgg/t3code#17381 * fix(web): show a row spinner instead of a banner when expanding a folder by @juliusmarminge in pingdotgg/t3code#17378 * fix(server): a timed-out browser drag no longer exits the server by @ScottN-PV in pingdotgg/t3code#17360 * fix(server): a logged-out Claude CLI no longer reports as authenticated by @yordis in pingdotgg/t3code#15459 * fix(server): Pi loads every selected skill without losing prompt text by @StiensWout in pingdotgg/t3code#17194 ## New Contributors * @limineol made their first contribution in pingdotgg/t3code#16972 **Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261008.2849...v0.0.46-nightly.20261009.2861 Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261009.2861
* fix(web): link pull requests to threads in folders that aren't Git repos (pingdotgg#15946) Co-authored-by: PR Batch Tester <agent@local.test> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(web): find messages and plans in the current thread (pingdotgg#10439) Co-authored-by: Yash Singh <saiansh2525@gmail.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(web): improve terminal scrollback navigation and snapshots (pingdotgg#17091) * docs(internals): add a checklist for adding a provider (pingdotgg#17229) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(mobile): keep native screens ordered during stack pops (pingdotgg#17231) * fix(server): pairing tokens work on Node versions that cannot bind booleans (pingdotgg#16730) * fix(mobile): HTML pages in a thread no longer trap scrolling on Android (pingdotgg#17211) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): centered scrollers no longer shift when the scrollbar appears (pingdotgg#17077) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): distinguish thread search matches from code tints (pingdotgg#17263) * fix(server): Pi extension wakes get an owned continuation turn (pingdotgg#17214) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): Pi discovers optional T3 tools on demand (pingdotgg#17220) * fix(web): stack merge dialog closes as soon as you confirm (pingdotgg#17116) * fix(server): Pi editor dialogs prefill the answer composer (pingdotgg#17206) * fix(desktop): generate valid User-Agent that follows RFC 9110 guidelines (pingdotgg#17264) * fix(server): Pi discovers workspace skills and commands (pingdotgg#17190) * fix(mobile): preserve navigation after native swipe back (pingdotgg#17268) * fix(server): keep newly discovered models out of legacy groups (pingdotgg#14314) Co-authored-by: PR Batch Tester <agent@local.test> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(editors): open remote projects in JetBrains IDEs over SSH (pingdotgg#17271) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * test(desktop): expect JetBrains IDEs among remote editors (pingdotgg#17291) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): recognize authenticated GitHub Enterprise hosts (pingdotgg#11059) Co-authored-by: Claude Code <noreply@anthropic.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> * fix(connect): relay client updates itself and skips incompatible cloudflared (pingdotgg#17275) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(shared): relay client install waits out a brief Windows file lock (pingdotgg#16998) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(shared): release relay install locks on cancellation (pingdotgg#10585) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * chore(shared): bump managed cloudflared to 2026.10.0 (pingdotgg#11184) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(shared): bound cloudflared download with 10-minute timeout (pingdotgg#14139) Co-authored-by: Kevin Rajan <kevin@kvnloo.dev> * refactor(provider-core): add provider-core and provider-testing packages (pingdotgg#17299) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(settings): drop the legacy per-driver providers map (pingdotgg#17300) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-pi): move Pi into its own provider package (pingdotgg#17302) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * feat(models): tell users when a CLI update unlocks a new model (pingdotgg#17307) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): collapsed composer reserves room for wide send actions (pingdotgg#17016) * fix(muse): workflow subagents no longer stall on hidden approvals (pingdotgg#17329) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-core): share attachment prompts, notifications, and event loggers (pingdotgg#17330) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): file previews handle downloads, in-page links, and repo paths, and favicons stop leaking internal hosts (pingdotgg#16950) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): environment-hosted browser tabs behave like a normal browser (pingdotgg#16963) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(desktop): browser tab fixes for fullscreen, shortcuts, links, reload and hidden tabs (pingdotgg#16961) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(web): desktop opens remote environments' browser tabs locally (pingdotgg#17316) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(desktop): the t3 command warns instead of installing behind another t3 (pingdotgg#17351) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): images, video, HTML and PDF preview in a thread before its first message (pingdotgg#17352) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-muse): move Muse Code into its own provider package (pingdotgg#17331) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): semantic branch naming hint lines up with its setting (pingdotgg#16972) * fix(mobile): restore chat image previews in the v5 stack (pingdotgg#17361) * feat(mobile): fade working threads and match web's status labels (pingdotgg#17368) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): agent browser tools stop bloating history, fall back sensibly, and respect ownership (pingdotgg#16956) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(web): add room for thread timeline markers (pingdotgg#17372) * fix(web): drop sidebar context before cancelling pointer drag (pingdotgg#17373) * refactor(providers): namespace-import service modules in core, Muse, Pi, and testing (pingdotgg#17375) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(auth): show connection permissions and enforce session lifetime (pingdotgg#17370) Co-authored-by: Bear Huddleston <bear@bearhuddleston.dev> * refactor(provider-opencode): move OpenCode into its own provider package (pingdotgg#17345) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-cursor): move Cursor into its own provider package (pingdotgg#17349) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-acp): move the shared ACP adapter into its own package (pingdotgg#17354) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-grok): move Grok into its own provider package (pingdotgg#17357) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): speed up long thread message sync (pingdotgg#17387) * fix(desktop): cancel backend pipe reads to avoid slow shutdown (pingdotgg#17386) * refactor(providers): adapter factories yield their services (pingdotgg#17381) * fix(web): show a row spinner instead of a banner when expanding a folder (pingdotgg#17378) * fix(server): a timed-out browser drag no longer exits the server (pingdotgg#17360) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): a logged-out Claude CLI no longer reports as authenticated (pingdotgg#15459) * fix(server): Pi loads every selected skill without losing prompt text (pingdotgg#17194) * fix(server): keep the Claude MCP token out of process arguments (pingdotgg#17408) * fix(server): reconcile Pi native session rewinds (pingdotgg#13839) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * test(provider-pi): cover continuation offers through the driver (pingdotgg#17407) * refactor(provider-acp-registry): move the ACP Registry into its own package (pingdotgg#17405) * fix(server): relay client updates no longer drop the host off T3 Connect (pingdotgg#17366) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com> Co-authored-by: PR Batch Tester <agent@local.test> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Co-authored-by: Jono Kemball <Noojuno@users.noreply.github.com> Co-authored-by: Yash Singh <saiansh2525@gmail.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com> Co-authored-by: chise <lqff.yt@gmail.com> Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com> Co-authored-by: maria <maria@kuuro.net> Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> Co-authored-by: oliver <97427849+flamboh@users.noreply.github.com> Co-authored-by: jztmanyl <jztmanyl@gmail.com> Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com> Co-authored-by: Grzegorz Mandziak <4248465+alimek@users.noreply.github.com> Co-authored-by: Scott Norteman <snorteman@gmail.com> Co-authored-by: Aditya Garud <153842990+yashranaway@users.noreply.github.com> Co-authored-by: Aaron Queen <bompus@users.noreply.github.com> Co-authored-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com> Co-authored-by: Kevin Rajan <kevin@kvnloo.dev> Co-authored-by: Theo Browne <me@t3.gg> Co-authored-by: Daniel Alvim <danielalvim@tuta.io> Co-authored-by: Bear Huddleston <bear@bearhuddleston.dev> Co-authored-by: Yordis Prieto <yordis.prieto@gmail.com>
Problem
Quitting the desktop app leaves the local backend alive until the desktop's two-second force-kill timeout. The browser and telemetry channels read inherited pipes through
fs.createReadStream; pending filesystem reads keep Node alive after service teardown while the desktop still holds the write ends open.Change
Wrap both inherited input descriptors in read-only
net.Socketstreams. Their reads can be cancelled by the existing scopeddestroy()finalizers, allowing the backend to exit without waiting for the desktop to close its pipe writers.Add a subprocess regression test that receives browser attach/detach messages and the telemetry handshake, then exits while the parent keeps both input pipes open. Both readers need the fix: changing either reader alone still left shutdown waiting for the force-kill timeout in the isolated reproduction.
Scope and approval
This is a focused fix for an observed shutdown defect in the two desktop pipe readers. The production change replaces their stream construction and retains the existing ownership and teardown behavior. The two replacements address the same blocking-read problem; the fixture and test verify message delivery and process exit. No startup changes or UI changes are included.
Verification
The measurements compare baseline
b707eeb052with this branch atb1b7342a67. Values are medians of three launches per condition. Quit is timed from the quit request, after startup finishes.With the real shell, OS process exit ranged from 2.074 to 2.092 s at baseline and 0.088 to 0.097 s after the fix. With the fixed-delay shell, it ranged from 2.077 to 2.087 s at baseline and 0.093 to 0.098 s after the fix. Backend
SIGKILLfell from 3/3 to 0/3 runs in each scenario, or 6/6 to 0/6 overall.Measurements used macOS Electron 44.4.5 development builds with a bundled renderer and no compile cache. Each launch had fresh isolated state copied from an 840 KB database with 10 projects, no threads, and no pending work. Runs were sequential, with no concurrent builds or tests. Windows stayed unfocused on the built-in laptop display, with background throttling disabled consistently. The fixed-delay shell sleeps for one second before executing the environment capture command. Shutdown with active provider turns, full production history, and native Windows/Linux launches was not measured.
vp test run apps/server/src/preview/DesktopBrowserChannel.test.ts apps/server/src/resourceTelemetry/DesktopTelemetryReceiver.test.ts: 7 tests passed across two files. The subprocess regression verifies browser message delivery, healthy telemetry reception, and exit code 0 while the parent keeps the pipe writers open.git diff --check origin/main...HEADpassed.@oxlint/pluginsdependency.Individual shutdown samples, in seconds
Trials 10 through 12 are the final laptop-display batch; interrupted earlier samples are excluded. Electron's quit event and OS process exit are separate milestones.
Agent: gpt-6.1-sol via the Codex harness in T3 Code.
Closes #16932