Skip to content

Release v0.20.1 - unified Files, mobile layouts, provider accounts and responsiveness - #843

Merged
pascalandr merged 84 commits into
mainfrom
dev
Oct 3, 2026
Merged

pascalandr merged 84 commits into
mainfrom
dev

Conversation

@pascalandr

Copy link
Copy Markdown
Contributor

Highlights

  • A unified Files workspace: Browse Workspace, Changes and Commits in one panel, open central file/diff previews, edit text with Save or Ctrl/Cmd+S, and inspect historical image changes without checking out another revision.
  • Better mobile and narrow-window layouts: Conversation controls stay compact, the composer follows the visible conversation height, and desktop minimum sizes respect application zoom. Mobile browser-preview templates now use native touch emulation when available.
  • Questions and permissions above the composer: Answer native requests in a dedicated dock without losing your draft. Completed questions retain selected-option descriptions and free text, and permission decisions remain available as durable receipts.
  • Native skills and web search: Attach Location skills through @, view structured search results and provider-consent requests, and configure global or project web-search defaults in Preferences.
  • Provider account controls: Select, rename and remove native provider accounts, with optional Codex account rotation based on fresh quotas. Usage stays stable across catalog refreshes and repeated connection events.
  • Fewer responsiveness stalls: Event routing no longer waits behind worktree discovery, compaction-related discovery is deferred safely, and supported pending-request recovery avoids loading historical Locations.

Files and conversation workflow

  • Workspace, staged/unstaged Changes and paginated Commits share file-row preview controls. Selecting a row no longer opens a preview implicitly.
  • Stage or unstage files with explicit actions or drag-and-drop; commit actions remain at the top of the staged section.
  • Workspace text and Markdown source stay editable in the central reader. Unsaved drafts survive closing or switching readers, and saving checks for external changes before overwriting.
  • Git image previews use the actual compared revisions rather than substituting the current file. Historical diffs remain read-only.
  • File trees, Git status and history serve cached snapshots and revalidate lazily; Monaco tokenizers ship locally for offline highlighting.
  • Question and permission queues retain stable selection and request drafts across refreshes and session navigation. Multiple requests use bounded previous/next navigation.
  • Full-history search fills result pages correctly and avoids redundant counting work.
  • Enter in a composer picker no longer accidentally submits a draft; model favorites mode persists independently of the active model.
  • Preview and persistent utility windows expose a close action in their existing toolbar.

Providers, skills and native tools

  • Preferences separates model providers and web-search providers, including a global search default and project override.
  • Search results and provider-consent Forms use dedicated native presentation, with raw output retained for unrecognized responses.
  • @ skill selection attaches removable badges and sends explicit native skill IDs with the prompt.
  • Code Mode output displays native tool-call metadata alongside the existing image/output surface.
  • Native provider account ordering determines the active account; environment-based connections remain read-only.
  • Codex quota reads follow the selected native account. Optional account rotation is opt-in, checked before prompt/command admission, and never replays a failed prompt.
  • Usage panels preserve quota values during provider catalog refreshes and duplicate connection notifications, and explain feature-local runtime limitations.

Mobile, desktop and reliability

  • Composer context selectors and actions stay on one row; narrow conversation headers use their overflow menu and hide the timeline below 420 CSS pixels without changing the saved preference.
  • Manually resized composer heights are stored proportionally and adapt to visible-viewport changes, including the mobile keyboard. Long drafts remain scrollable.
  • Electron and Tauri desktop minimum sizes follow application zoom. Native mobile browser previews automatically apply touch emulation; iframe fallback changes dimensions only.
  • Tauri on macOS avoids startup geometry-event feedback; Electron avoids accessing destroyed windows during close.
  • OpenCode installation shows sustained progress and can recover interrupted Windows installations.
  • Local TLS certificates use positive serial numbers, with repair of affected local certificates.
  • Server information distinguishes the server platform from the client environment.
  • Event ownership checks use registered worktrees without joining slow discovery scans. Pending queues remain intact on incomplete coverage or recovery errors.
  • Missing-session errors remain identifiable for orphaned subsessions, and parent-session creation is fenced against invalid lifecycle transitions.

Runtime and upgrading

  • OpenCode 2.0.22 is the recommended and qualified runtime for this release. The technical minimum remains 2.0.7; feature-local API requirements do not raise the global minimum.
  • Codex quota reads require the native credential API introduced in 2.0.20. Older services show feature-local unavailability rather than blocking the application.
  • Loaded-only pending-request recovery uses a connection-negotiated capability qualified with 2.0.22. Older services retain their discovery behavior; updating CodeNomad alone does not give them this recovery optimization.
  • Upgrade remote CodeNomad servers to 0.20.1 for the published UI. Its manifest requires the matching backend for the new routes.
  • Installing or updating the OpenCode CLI does not silently restart an already-running shared service. Restart remains an explicit action.

Full Changelog: v0.20.0...v0.20.1

pascalandr and others added 30 commits September 4, 2026 13:01
Introduce the project-local codenomad.missions V2 plugin with a durable append-only mission map, deterministic OpenCode inbox admissions, and the compact mission.inspect, mission.delegate, and mission.report tool interface. Root sessions remain visible native actors, only coordinators may change topology, and blocked tasks are mapped without a hidden workflow interpreter.

Add constrained CodeNomad snapshot brokering instead of exposing generic plugin RPC. Workspace-owned locations, active plugin inventory, project identity, root-session membership, actor limits, and foreign-session fences are checked at their respective seams. Queue/resume delivery supports busy actors and deterministic IDs make interrupted dispatch and report notification retries idempotent across restarts.

Ship dynamic custom, Pocock bug-expedition, and Wayfinder playbooks plus provenance and architecture documentation. Pin the local plugin contract to beta-18999 alongside the reviewed V2 client.

Validated with the server TypeScript check and 12 focused mission, plugin registration, recovery, authorization, idempotence, and broker tests.
Register a first-party Missions tab in the existing right-panel module seam. The new map-oriented view exposes mission objective and state, dependency-aware route nodes, frontier and claim totals, native root-session actors, correlated reports, and direct actor navigation without adding a second execution surface.

Load authoritative snapshots through the constrained CodeNomad broker, debounce typed RPC invalidations, refresh tracked workspaces after both OpenCode and CodeNomad event-stream reconnects, preserve the last durable map on transient errors, and clear stopped workspace state. Missing project plugins remain an explicit optional-capability state.

Add square-corner, token-based, RTL-aware panel styles split by feature concern and complete translations for all ten supported locales. Locale tests enforce key and interpolation parity, while store tests cover availability, stale-response fencing, reconnect ordering, and durable fallback behavior.

Validated with the UI TypeScript check, focused Node tests, locale parity checks, and a production Vite/PWA build.
Require structured Pocock evidence for completed diagnosis, implementation, independent standards/spec reviews, resolution, and final validation. Fence fresh reviewer and validator roots while requiring review resolution to reuse the implementer, and cover a full dynamic Pocock cycle plus a breadth-first Wayfinder map.

Align the project-local plugin with beta-18999 runtime behavior by emitting native typed system parts, JSON-normalizing optional RPC output, using the typed RPC call as the capability probe, and keeping the runtime entry free of an SDK import. Add a dedicated compile-time plugin contract check to CI.

Record the private-runtime spike proving busy-root queue delivery, resume, correlated synthetic reporting, restart restoration, idempotent admissions, typed invalidations, owned broker access, and shared project storage across worktrees. Targeted mission, plugin, and broker tests pass alongside server and plugin typechecks.
Omit workspaceID when a durable mission location has no workspace instead of reconstructing an explicit undefined property. OpenCode V2 validates managed session creation inputs strictly, so the previous shape could leave a newly admitted task at the durable dispatching boundary.

Add a regression assertion for workspace-less actor locations and record the successful idempotent resume of the same dispatch after a private server restart. Document full live Pocock and Wayfinder demonstrations, including independent roots, structured evidence gates, derived frontier transitions, read-only validation, and publication fences.
Prevent concurrent mission tool calls from racing the same project snapshot and overwriting deterministic event identities. Project-scoped mutation and append queues now preserve first-writer contracts across multiple MissionControl instances, while journal admission rejects new records before the 2,000-event bound is exceeded.

Enforce Pocock's evidence transitions independently of model-supplied blockedBy keys and require every role-specific completed report before a green mission finish. This keeps dynamic task naming while making the documented diagnosis, implementation, independent reviews, resolution, and validation gates authoritative.

Add regressions for conflicting concurrent task contracts, concurrent mission starts, journal capacity, skipped Pocock prerequisites, and empty green completion. Validated the 400-test server suite (398 passed, 2 platform skips), mission/plugin/route/UI-store focused tests, server and project-plugin typechecks, and git diff checks.
Reject new mission creation at the project snapshot capacity rather than persisting a twenty-first mission that hides active membership. Keep deterministic start replay available at capacity.

Reject new explicit actor targets at the actor cap before writing dispatch intent. Existing actors remain reusable, and rejected tasks remain ready so the coordinator can retry with an admitted actor instead of leaving a missing-actor dispatch permanently stuck.

Add regressions reproduced red before the fix covering both limits, snapshot reconstruction, idempotent start replay, and actor reuse after rejection. Validate 24 focused mission tests, 400 passing server tests with two platform skips, server typecheck, and diff checks.
Integrate current dev into the Missions branch without rewriting feature history. Resolve the PR workflow conflict by retaining both the mission translation test and the upstream clipboard test, alongside the existing mission-store and plugin contract checks. Preserve the upstream HTTP server changes and mission route registration.

Validated the parsed workflow and all 52 referenced UI test paths; 334 runnable UI tests and 24 focused Missions/plugin/broker tests passed. UI, Electron, server, and project-local plugin typechecks and diff checks passed.
Integrate dev@ea37f97b after the global-session, nested-scroll, and selective-pruning fixes while preserving the native Missions control plane. The merge is conflict-free and keeps the PR history intact for exact-head CI validation.
Integrate dev aa51cbb and retain both Missions and current request-location
CI coverage, panel styling and narrowly scoped plugin documentation. Move the
Missions client and checked plugin dependency to official 2.0.4 packages.

Replace removed plugin.awaitActivation with the native location and plugin
inventories. Validate snapshot project identity against location.get, retain
legacy location context through direct and typed RPC requests, and refresh
tracked Missions when plugin.updated changes capability availability. Keep
Missions optional and its broker restricted to the reviewed snapshot method.

Validation: checked Plugin.define setup against @opencode/plugin 2.0.4;
24 targeted Missions tests passed; server suite 524 passed/2 skipped;
UI stores 444 passed; Electron native 194 passed/4 skipped. Server/UI/Electron
and project-local plugin typechecks pass. Live mission delegation on a native
daemon and non-Windows desktop behavior are not claimed by these tests.
Merge dev bdac05b into the Missions branch so PR #673 retains its project-local codenomad.missions coordination while adopting the current bundled automation, session-environment admission, native worktree inventory, and desktop lifecycle changes.

Resolve the server import overlap by preserving both Mission route registration and fail-closed session environment errors. Update the architecture guidance to document Missions alongside the current backend-presence automation and pruning boundaries.

Validation: 615 server tests passed with 2 platform skips; 41 focused Missions and session-environment tests passed; server, UI, Electron, and project-local plugin typechecks passed; pruning and automation plugin builds passed; workflow YAML parsed successfully; git diff checks were clean.
Integrate dev through #719 after the Node 24 refresh. Preserve the project-local Missions RPC and UI while adopting the bounded per-instance event queue so slow routing no longer blocks the shared native stream.

The upstream delta has no file overlap with the Missions changes; follow-up validation covers the new routing regressions together with the focused Missions contract and Node 24 typechecks.
Integrate dev through #720 while preserving the Missions plugin, server route and session-native UI. Adopt the zero-specificity global scrollbar default so transcript and timeline component rules remain independent.

The upstream stylesheet delta has no file overlap with the Missions changes; validation covers the shared UI typecheck and the timeline browser regressions before the full PR matrix.
## Summary
Fix the first-install recovery dead end observed in CodeNomad 0.20.0 on
Windows 11. npm failed to install the optional Windows binary packages,
then removed the CLI package while leaving terminal shims behind. These
shims disabled installation admission and hid the install button; later
status refreshes also erased the action error.

Recognize only the exact npm-generated orphan shim in the selected user
prefix with a missing canonical executable. Preserve custom-wrapper,
foreign-prefix and existing-binary authority checks. Keep action
failures visible across refresh and reopening.

## Validation
- 34 targeted updater/installer regressions passed.
- 21 browser setup regressions passed.
- Server TypeScript check passed with locked dependencies.
- On the affected machine, isolated package download and executable
validation succeeded without Git. Explicitly authorized repair using
bundled npm succeeded; the user confirmed CodeNomad now opens folders.

## Distribution
The maintainer explicitly requested replacing the existing 0.20.0
desktop release assets rather than creating 0.20.1. This branch is based
on v0.20.0 and preserves its version; the PR build artifacts will be
used for that revision after validation. The release notes will record
the source commit, and WinGet will receive a separate same-version
installer hash correction. No npm version republication is intended.

Co-authored-by: Shantur Rathore <i@shantur.com>
## Summary

- Update the main README for the shared OpenCode V2 service, current
features, managed desktop setup, minimum/recommended OpenCode versions,
and explicit service restart behavior.
- Correct release links, actual Electron/Tauri artifact formats and
architectures, Node guidance, remote authentication and SideCar
configuration fields.
- Align server and contributor documentation with the 0.20 baseline.
- Replace the old hero screenshot with a current 1600x900 workspace
rendered using real Solid components and synthetic demo data.
- Include a reproducible Chromium capture script and provenance notes;
external traffic is blocked and no user backend, daemon or provider is
used.

## Preview

![CodeNomad 0.20
workspace](https://raw.githubusercontent.com/NeuralNomadsAI/CodeNomad/docs/readme-0.20/docs/screenshots/workspace-0.20.png)

## Validation

- UI typecheck passes.
- Chromium capture passes transcript, connected-state, agent, timeline
and MCP readiness checks, with no uncaught renderer errors.
- Resulting image inspected visually.
- 20 local Markdown/image targets verified.
- Staged git diff --check passes.

Regenerate with: node packages/ui/scripts/capture-readme.mjs

Documentation and capture tooling only; CI is not being monitored.
…#787)

Persist the global favorites/all choice in the UI state owner instead of deriving it from each selected model. Search stays within the chosen mode, and the active model is added without becoming a favorite, respecting explicit provider visibility and disabled unavailable placeholders.

Publish mode intent immediately and serialize persistence. Fence completion by latest-write identity so double/triple clicks retain the latest intent throughout delayed responses. Keep a stored mode visible and revocable when no favorites remain.

Add real-component browser coverage for selection, search, remounts, hidden/unavailable models, empty favorites and click bursts. Register store coverage in CI, verify actual persistence ordering and ensure mocked writes finish before teardown. Independent final gatekeeper PASS at 1ee5a96; 860 CI-group unit tests, 14 targeted tests, six browser tests and typechecks pass locally. Remote Windows Rust Node-election failure is documented separately in the PR.
Align server/UI client and bundled plugin pins with the latest stable runtime while preserving the demonstrated 2.0.7 timestamp minimum. Review the published declarations and authenticated native schema: pairing and Shell signal additions require no CodeNomad API adaptation.

Make the isolated native upgrade fixture follow the recommendation while retaining its 2.0.15 source boundary and live-daemon PID assertion. Extend setup version coverage and update the current compatibility and architecture references.

Validate both minimum/current native runtimes, historical migrations, server/UI tests, setup and tool-image browser scenarios, typechecks and production bundles. Record the intermittent Windows Node pruning/UI heap exit and successful diagnostic rerun without claiming its cause is fixed.
## Summary

Qualify the latest published stable OpenCode **2.0.18** and align the
server/UI client, bundled pruning plugin and recommended runtime. The
technically required minimum stays **2.0.7**
(`session.step.started.data.started`). No application API adaptation was
needed.

The setup regression covers the intermediate releases as usable, with
only the recommendation designated release-tested. The isolated native
npm upgrade fixture now follows `RECOMMENDED_OPENCODE_VERSION`,
retaining 2.0.15 as the native-upgrade source boundary and asserting
that installation does not restart the live daemon.

## Upstream review

- Compared `anomalyco/opencode` tags **v2.0.16...v2.0.18**, published
client/plugin declarations and a real authenticated 2.0.18 daemon
schema.
- The runtime has **115 paths**: the previous 113 are unchanged;
`/api/pair` and `/auth/connect/{code}` are additive. Component changes
are optional `Shell.Info.signal` and two pairing response schemas.
CodeNomad's guarded proxy does not expose the new pairing APIs.
- The tagged `packages/protocol/openapi.json` still has 113 paths, so
comparing that file alone would miss the additions. The actual runtime
schema and generated client agree.
- Client changes are additive; plugin declaration changes concern TUI
model variants. OpenTUI optional peers advance to >=0.5.12 and
`@opencode/util` adds the shared browser opener dependency.
- Relevant runtime fixes: flush batched transcript deltas before the
next block; report signal-terminated Shells; restore no-output
placeholders; improve provider errors/reasoning budgets; improve Code
Mode JavaScript semantics; decode legacy media in compaction checkpoints
(2.0.18).
- Authentication, native storage, explicit configuration reload and
install/restart ownership remain the existing CodeNomad contracts. No
minimum bump follows merely from the new publication.

## Isolated Windows qualification

Node **24.20.0**, synthetic providers, separate profiles/databases/CLI
installations; no shared daemon or personal histories used.

- Existing 2.0.16 dependencies against runtime 2.0.18: complete native
pruning/UI acceptance passed before the dependency change.
- 2.0.18 dependencies against minimum runtime 2.0.7: all seven native
suites passed (automation, pruning, environment, forks, side questions,
blank-session cleanup, Git-degraded recovery). Pruning includes
relay/proxy ownership, native worktrees, Forms/permissions, 241-message
search/cleanup, 1,501-message outline/navigation, concurrency and
restart persistence.
- 2.0.18 dependencies against runtime 2.0.18: automation, environment,
forks, side questions, blank-session cleanup and Git-degraded suites
passed. The initial pruning run passed the native
relay/proxy/worktree/history cases, then the Node process exited with
**0xC0000374** while loading browser/server dependencies. The prior
2.0.16 qualification already records an intermittent Windows exit at
this phase. This is retained as unresolved failure evidence, not claimed
fixed by a rerun.
- **744 server tests passed, 6 skipped; 65 UI client/store/reducer tests
passed.** Server, UI and Electron typechecks passed.
- Native migration **2.0.3 → 2.0.18** passed: complete histories, fork
identities, historical provider configuration and same-version restart
comparison for Forms durability.
- Native npm **2.0.15 → 2.0.18** installation passed, while the
authenticated daemon remained **2.0.15**, with the same PID
before/after.

- The diagnostic **2.0.18 native pruning/UI rerun passed in full**,
including UI deletion, automatic plugin discovery, multiple backends,
claim contention, next-model payload, fork isolation, compaction and
restart. `--report-on-fatalerror` was enabled; no failure occurred on
that run. This does not establish the cause or a fix for the first exit.
- Native migration **beta-19271 → 2.0.18** also passed, including
histories, forks, historical configuration and Forms durability checks.
- **25 setup/auth-recovery browser scenarios passed.**
- **3 tool-image browser scenarios passed**, covering
generic/specialized output, collapse, failed/unsupported sources and
replacement recovery.
- Production server/UI/pruning/automation build passed.
- Standalone pruning plugin was packed, installed outside the
repository, then passed the 2.0.18 native suite (including 241-message
search/cleanup, 1,501-message navigation, proxy/ownership, concurrency,
compaction and restart). This verifies the actual distributable
independently of the embedded bundle.

The independent gatekeeper review will be recorded before merge.
Cross-platform CI is distinct from these local Windows results.

## Review and merge

Base: `dev@14b1eaa` (#787). The user
explicitly requested independent gatekeeper review/correction loops
until zero actionable findings, followed by administrator merge. Final
merge must target the reviewed head and verify any new `dev` merges
first.
Provision codenomad.missions through connected-daemon discovery and independent backend presence instead of requiring a source plugin in every project. Bundle the integration for Electron and Tauri, retain project-scoped mission journals across shutdown, and use the same secondary surface as Status.

Complete the existing native actor execution work: persist explicit agent/model/variant choices, validate catalog selections and avoid switching busy actors. Admit assignment and report writes through the authenticated desktop bridge with durable-contract verification, session ownership, connection and worktree fences, and per-send profile environment synchronization.

Advance the older source branch client/plugin pin to 2.0.11 and retain its bounded runtime metadata adaptation. The isolated 2.0.16 mission fixture passes native catalog, selection, busy queues, conflict, environment, reports, reconnect and idempotence checks. Server, UI and plugin typechecks, 31 mission tests, 10 lifecycle/transport tests and six resource-layout tests pass.
Resolve desktop bridge ownership as soon as one workspace validates the session instead of waiting for every inventory. Probe mission admission candidates concurrently so an unrelated stalled connection cannot delay a verified owner.

Keep authenticated bridge discovery, cross-backend ambiguity rejection, durable contract checks, execution selection, worktree fences and per-send environment admission intact. Duplicate logical tabs still share their backend profile.

Add regressions for stalled unrelated ownership and connection checks. All eight route tests and server TypeScript compilation pass. Verified the installed Windows Tauri backend reconnects and accepts the original durable assignment after the fix; ownership probing dropped from roughly 13 seconds to 0.46 seconds.
Live multi-agent research exposed a second timeout after unrelated workspace waits were removed: the actual owner's validated linked-worktree inventory can take about 18 seconds when cold. Give mission discovery a bounded 30-second probe deadline instead of the five-second interactive browser deadline.

Keep browser discovery unchanged and continue probing for competing backend owners before admitting any mission input. Add a regression with ownership validation exceeding five seconds and verify a second owning backend prevents another admission.

Validated ten automation tests, server typecheck, bundled Missions build and the isolated OpenCode 2.0.18 native fixture. Loaded the updated bundle through the installed desktop lifecycle and successfully resumed the same previously blocked UX assignment without a duplicate actor or task.
Make Mission Control actionable with create/edit/delete, persistent disclosures and selection, task dependencies, native attention requests, execution comparisons and a long-content reader above the mounted transcript. Preserve drafts and native per-window layout, and arbitrate browser/reader gestures without losing the preview target.

Add coordinator-only mission.revise with revision CAS, idempotent replay, linked replacements and explicit dependency changes. Retain withdrawn task contracts and late reports, require terminal settlement for outstanding native admissions, and attribute human metadata edits in the bounded history. Mission deletion tombstones the map without deleting conversations.

Cover lifecycle and revision semantics with backend regressions and the isolated OpenCode 2.0.18 fixture, including the repaired authenticated late-report notification. Validate real Solid UI restoration, editor retry identity, native background Forms, transcript/draft preservation, layout cleanup and ten-locale parity. Record Kandev research, scope decisions and separate follow-up opportunities.
Share project mutation and append queues across content-addressed plugin incarnations so disposal cannot let competing revision checks overwrite history. Keep in-flight operations exclusive until settlement.

Raise assembled bridge text bounds to accommodate maximum XML-escaped objective and task fields within the existing HTTP body bound. Exercise real authenticated HTTP admission with XML, JSON-control and multibyte expansion.

Observe both regressions failing before their fixes, then passing with the focused bridge suite and server typecheck. The isolated OpenCode 2.0.18 fixture now proves reports reach an actual provider request for idle and busy coordinators instead of treating session idle as proof of consumption.
…racts

Recover durable report notifications that were saved before a bridge outage prevented coordinator admission. Reuse native message identities, honor journal acknowledgements and lifecycle fences, and retry only notifications through the authenticated environment-aware bridge. Nonblocking single-flight retries use bounded backoff and rotating batches without dispatching tasks.

Show pending coordinator notification separately from task completion in Mission Control, with all locales aligned. Derive managed actors from immutable task identities, resolve Pocock implementers through live task ancestry, and normalize dependencies for both new and historical idempotent requests.

Validated 53 backend regressions, server and UI typechecks, UI and plugin builds, six real-component browser scenarios, locale parity, and an isolated OpenCode 2.0.18 fixture proving idle/busy resumption and automatic outage recovery with and without restart. Native replay retains one correlated report without another coordinator wakeup.
Declare expected mutation rejections in the native RPC contract and return them through the invocation error API. Map structured business codes to conflict, missing and ownership responses so stale editors can request a reload instead of reporting an unavailable plugin. Unexpected exceptions remain opaque 503 failures.

Extend the isolated OpenCode fixture through the real WorkspaceManager and HTTP routes to verify stale update/delete, create/update/delete request-ID conflicts and unknown missions. Observed native 503 before the fix and 409/404 after it; targeted route/plugin/reload tests and server typecheck pass.
Keep live task ancestry and replacement filtering while deduplicating candidate implementers by native session identity. Several completed implementation steps in one root can now receive their resolver without weakening ambiguity rejection between distinct actors.

Add helper coverage and a full Pocock artifact-driven regression exercising delegation, resolver replacement and revision through the shared implementer. Validated 46 combined backend tests, server typecheck and the rebuilt Missions plugin.
Integrate dev into the Missions PR without rewriting its reviewed history. Retain mission CRUD routes, authenticated report admission and the 512 KiB bridge limit alongside inspected-window automation and plugin controls. Keep dev's canonical transport, clean builds and 2.0.18 client/plugin dependencies; align the local plugin contract check with the same SDK.

Combine architecture guidance and preserve the technical runtime minimum of 2.0.7. Keep the isolated Missions fixture in the latest-runtime CI lane because its test-only ctx.tool.list driver is absent at that minimum; do not reintroduce legacy compatibility paths.

Validation: server, UI and plugin-contract typechecks; full server/UI/plugin build; 84 backend/compatibility/packaging tests; 59 UI/persistence/browser tests; isolated OpenCode 2.0.18 Missions fixture and workflow YAML parsing. Merge resolutions have no conflict markers or diff-check errors relative to dev.
Clear nested-task membership and truncation when native deletion empties the resident child snapshot, while preserving keyed shells during ordinary invalidation and rereads. Cover the real batched native event with unchanged parent metadata, bounded counts and legacy fallback.

Do not start the browser event singleton outside a window environment. Require actual module imports and compaction store tests to finish naturally in private subprocesses rather than using force-exit, while retaining normal browser auto-connect and reconnect behavior.

Preserve original test errors and stacks when snapshot capture or page cleanup also fails. Share a narrow diagnostic/cleanup helper with durable tests, including falsy primary errors and cleanup failures after successful runs. No browser assertions, timings, clicks or skips are relaxed.

Independent scoped reviews close UI-R1-1 and UI-R2-1. Causal prepatch failures, 25 renderer/copy/image tests, 141 naturally exiting store tests and focused lifecycle/diagnostic tests are green; final immutable full-browser and native Windows CI qualification remain separate gates. Investigation reports remain local and are not tracked.
Provide the minimal web-renderer window before importing the real ServerEvents singleton, after installing the existing network mock. The accepted lifecycle guard intentionally leaves Node imports passive; the reconnect test must explicitly supply its intended browser context.

Preserve reconnect and hidden-cache assertions, require initial constructor auto-connect through the mocked transport, and restore the exact previous global descriptor while closing mock sources. No production networking behavior is changed.

Confirmed the original natural-exit failure and the corrected test pass. The 71-file CI UI workload passes 480/480 with force-exit removed; lifecycle 2/2, compaction 11/11, neighboring stores 141/141 and UI typecheck pass. Independent delta review found no findings and verified cleanup for absent, data and accessor descriptors. Full-browser and remote CI qualification follow on this commit; historical failures remain recorded.
Install composer page observations before navigation and record synchronous bootstrap phases without moving imports, mocks, awaits or fixture publication. Capture bounded console, module/API status and navigation events so a future readiness failure can be inspected rather than reduced to an unexplained timeout.

Use the accepted diagnostic and cleanup boundary for failure-only structural snapshots with a two-second reporting deadline. Preserve original error identity and stack when observation or cleanup fails, detach listeners and clear timers, and keep cleanup failures after successful assertions visible. Original 30-second readiness and all layout/draft assertions remain unchanged; native fixture and cache policy are untouched.

Add five real Chromium contracts covering failed entry modules, bounded event rings and URL labels, destroyed and pending snapshot contexts, listener cleanup and primary-error preservation. Author and independent review each pass ten contracts and the actual 320px composer case with natural process exit; independent scope review reports zero findings. This repairs only the observation gap, not the unknown historical R3 cause. Final full-browser and fresh remote CI qualification follow on this commit.
Target the requested native scrollbar ratio relative to the actual press point rather than an estimated future thumb centre. This retains the selected grab offset at the top and bottom of the track without changing production timeline behavior, assertions, gesture timing, movement steps or settling delays.

Independent review accepted the exact helper-only change with zero findings. Real Chromium endpoint and neutral-position contracts check actual mouse target arguments, and both existing native thumb scenarios pass naturally. Windows outcomes do not reproduce or explain the historical Linux CI failure, whose grab-offset versus final-input-delivery mechanism remains unknown; fresh full qualification and remote CI are still required.
Remove the mention picker's no-selection submission fallback, which dispatched drafts on Enter during empty or pending searches even when submit-on-Enter was disabled. Reserve Enter for an open picker and swallow Ctrl/Cmd submission or queue shortcuts instead of sending.

Fence document-level Solid key delegation on both sides: the picker ignores modified Enter, and the composer never submits an already-consumed Enter whose selection handler closed the popup during dispatch. Preserve Tab completion, directory and arrow navigation, Shift+Enter path-only insertion, Escape draft preservation and explicit submission after dismissal. Clipboard production behavior and both desktop hosts use the unchanged shared paths.

Add seven real composer browser regressions using held search responses, intercepted native prompt requests and trusted clipboard paste, plus three keyboard-controller regressions. The two pending-search browser regressions fail before the fix in both submission modes. Seven controller tests, twenty-eight composer/attachment/search browser tests, UI typecheck and production build pass. Publish an independent gatekeeper review of the exact head before merging.

Admin merge without waiting for CI is explicitly requested. No live session or shared daemon is mutated; installed Tauri validation and reproduction of Ctrl+V alone causing a send are not claimed. Addresses #826 without closing the report before user confirmation.
…#825)

## Summary

close #824. This collects the confirmed responsiveness and isolation
fixes from the issue-824 mission, including independently reviewed
corrections recovered from the previous general audit. **It does not
claim that the original persistent Electron Linux Ôö£├ÂÔö£├æÔö£├Ñ
Windows HTTP freeze is resolved.**

- Aggregate native compaction text before the OpenCode/Solid reducer
instead of only throttling the visible projection. Advance revision/read
fences immediately, preserve exact terminal text and SDK snapshot
boundaries, and discard obsolete buffers across lifecycle changes.
- Retain keyed nested task-tool shells without losing authoritative
membership changes. Keep the existing bounded structural scan and
full-copy behavior.
- Isolate SSE subscriber exceptions, distinguish decoding from dispatch
errors, and prevent a subscriber-local abort/return/throw from
invalidating the healthy shared native client.
- Observe HTTP disconnects before admission/preflight, propagate
cancellation to supported reads, and fence late continuations without
replaying or interrupting already-admitted native mutations.
- Use asynchronous scrypt for HTTP authentication, serialize password
changes, and reject an old login verification that crosses a password
change. Preserve hash format and constant-time comparison.
- Yield cooperatively during structural-index reads and projection,
without changing the response/digest protocol, ownership or snapshot
semantics.
- Add isolated regression fixtures, native qualification scripts,
source-fingerprint evidence; independent reviews are published in the PR
discussion. Synchronize the Git focus test with its asynchronous
contract and correct the opt-in browser trace serialization defect
introduced during this mission.

## Validation Ôö£├ÂÔö£├ºÔö£├é draft, not all green

Product/tests/scripts/config/lock inputs were fingerprinted across 1,696
tracked and untracked executable paths. The complete frozen-source runs
and their unsuccessful attempts are recorded separately; targeted
retries are never substituted for a successful full suite.

| Gate | Recorded result |
| --- | --- |
| Full server replay | 799 total / 793 pass / 6 skip / 0 fail, natural
exit 0. Initial Windows cleanup `EPERM` retained; isolated Git and full
replays pass, underlying OS cause unqualified. |
| UI/server/Electron typechecks and UI/server/bundled-plugin builds |
Pass. UI typecheck also passes after the final trace correction. |
| Private native fixture | Pass on Windows/OpenCode 2.0.21, including
compaction isolation and 2/8/32 MiB provider payload checks. No user
daemon/database used. |
| Stores | 141 assertions pass with force-exit. The 11-case compaction
natural-exit attempt prints passes but times out; lifecycle cleanup is
not qualified. |
| First frozen full browser | 360 total / 356 pass / 3 fail / 1 skip,
natural exit 1. Targeted 3/3 and neighboring 104/104 pass, not an
all-green replacement. |
| Previous full browser (before trace correction) | **360 total / 358
pass / 1 fail / 1 skip**, natural exit 1 in 20 min 10 s, zero source
drift. The remaining failure is the opt-in trace's `ReferenceError:
__name is not defined`; prior functional assertions, including focus,
pass. |
| Trace correction after that full gate | Exact tsx callback
serialization reproduces the missing helper on a minimal Chromium page.
Explicit self-contained JS is verified with no pageerror and all
observation kinds retained after saturating the 200-entry buffer. **The
fresh cycle-1 full browser now passes Git/trace, but remains red on a
different case; see below.** |
| Renderer A/B on final product postimage | 30 samples/variant, median
main-thread fixture duration **324.57 Ôö£├ÂÔö£├æÔö£├Ñ 16.94 ms**. Not
desktop FPS or universal responsiveness. |

Compaction gates assert exact counts/content rather than flaky timing:
128 active fragments reduce to one interval emission, modest staggered
delivery also coalesces, and never-loaded inactive sessions do not
materialize the payload. Structural-index stress observations reduce
event-loop gaps from 522Ôö£├ÂÔö£├ºÔö£Ôöñ755 ms to 13Ôö£├ÂÔö£├ºÔö£Ôöñ14
ms on the documented synthetic corpus, not total CPU or remote paint
time.

## Remaining acceptance work / limitations

- Cycle-1 corrected full browser: **360 total / 358 pass / 1 fail / 1
skip / 0 cancelled**, natural exit 1 in 21 minutes, zero drift on 1,696
inputs. Git/trace passes; the PageUp-named case loses its original error
because its failure snapshot itself throws. Correct diagnostic error
preservation; do not relabel this run green.
- The earlier MCP bootstrap and HTML-cache timeouts remain causally
unattributed, although both pass in the latest full run. A separate
Monaco overlay detachment is retained as a distinct fixture failure.
- Qualify Electron Linux Ôö£├ÂÔö£├æÔö£├Ñ backend Windows LAN/HTTP and
OpenCode 2.0.19. Current real HTTP/1 checks are Chromium Windows
Ôö£├ÂÔö£├æÔö£├Ñ Fastify Windows loopback; private native checks use
2.0.21. Neither establishes the reporter's exact cause.
- Natural store lifecycle is still pending correction: the referenced
reconnect timer of the import-started browser singleton retains Node
without `window`; a constructor-only private counterfactual yields 11
passes and natural exit 0. This is causal diagnosis, not a corrected
product gate. Coalescing remains limited by interleaved read/event
boundaries, has no explicit byte/event cap, and is not a universal
four-flushes-per-second/memory guarantee.
- A single SQLite step remains synchronous. Shared libuv CPU resources,
task clones/reloads and revision-stable activation catch-up remain
documented limits.

The user has now authorized scoped corrections, independent re-review
until zero open findings, and then an administrative merge attempt after
final green acceptance. No merge has occurred. Installation, deployment,
shared-daemon restart and user-session cleanup remain unauthorized.

## Current gatekeeper / evidence

**All reported actionable findings are closed; final acceptance is still
pending.** Server/native review has zero findings. Scoped independent
re-reviews close UI-R1-1 (ghost task membership), accept the
browser-singleton lifecycle correction, and close UI-R2-1 (diagnostic
cleanup masking). The eight reviewed paths are committed and pushed in
`1795cce6aa40cf617d6113d2c11b2f36bae7d04c`; there are no investigation
reports in the diff. The final immutable UI/stores/build/full-browser
validation task is dispatched on that HEAD; CI run 36944418417 is in
progress. No merge has occurred and no new general audit is being
restarted.

CI run 36937989224 at `f6a18d00` fails only the native pruning Windows
job; build is skipped. Installed-plugin/native/installation checks pass
before the `--ui` invocation exits during the Vite-loading boundary
without an initial error stack. Cause is under investigation, not
waived.

- [Server/native gatekeeper review ├ö├ç├ zero
findings](#825 (review))
- [UI gatekeeper review ├ö├ç├ UI-R1-1
open](#825 (review))
- [Scoped UI re-review ÔÇö UI-R1-1 closed, lifecycle accepted, UI-R2-1
open](#825 (review))
- [Natural store lifecycle qualification ÔÇö 141/141
pass](#825 (comment))
- [Confirmed store lifecycle attribution ÔÇö historical
diagnosis](#825 (comment))
- [Cycle-1 terminal browser/CI results, source identities and
limitations](#825 (comment))

At the user's request, investigation reports are not part of the
repository diff. Commit `acac9be2` untracks the 21 reports while
preserving their local working copies; executable inputs are unchanged
by that commit. Future working reports remain local and untracked.
Review verdicts/results are published in this description and
discussion. These are transparent independent AI-agent reviews posted
through the coordinator's PR-author account, not independent human
GitHub approvals. Raw private logs remain on the validation host, not
publicly downloadable uploads.

Size signals retained without size-only refactoring: `http-server.ts`
~2,346 lines, `workspaces/manager.ts` ~1,240, `instances.ts` ~2,093,
`opencode-data.ts` ~828, `task.tsx` ~569.
Stabilize the Windows pruning/UI CI harness by loading its unchanged UI dependencies before the long native/SQLite preamble. The late-import baseline reproduced locally under CI's Node 24.20.0 with native status 0xC0000374. This is a qualified import-order workaround, not attribution or repair of the underlying heap corruption; no assertions, dependencies, test skips or retries change.

Retain actual child exit status/signal, stdout/stderr, durable stages and synthetic fixture logs through a parent runner. Require explicit completion as well as exit zero, and upload parent/fixture diagnostics on failure. Preserve the original UI scenario exception if diagnostic capture fails.

Trigger artifact announcements from validation completion rather than bounded polling. Failed validation stays red in its own workflow. Run only trusted default-branch helper code, verify the originating workflow and current authorized PR head, use GitHub commit association when needed and update only bot-owned marker comments. Artifact names remain escaped display text, never executed contents.

Fifteen focused tests pass under Node 24.20.0. Two coordinator-run and one independent full Windows native/UI scenarios complete naturally with all original assertions, restart persistence and presence cleanup. YAML and diff checks pass. The published independent gatekeeper review of this exact head has zero findings.

Admin merge is explicitly requested without waiting for CI. GitHub workflow_run delivery needs post-merge confirmation; no universal CI reliability, underlying heap repair, Linux/macOS native rerun, installed app replacement or shared daemon restart is claimed.
## Increment over existing execute display
Execute already renders as a tool card through the generic renderer.
This PR adds a specialized presentation of its script and native
nested-call metadata (names, inputs, statuses), plus truncation
information. It reuses the existing aggregate output and image surfaces.
It does not introduce Code Mode execution or mission orchestration
(#673).

## Purpose
First PR in the V2 product integration series. Present execute scripts,
nested tool calls and progress, failure and native truncation
information. Preserve shared native output/image rendering and copying.

## Contract and implementation
Verified upstream Code Mode contracts at tags 2.0.7 and 2.0.18: code
input, metadata.toolCalls (tool/status/input), metadata.error. No API
calls or runtime minimum changes. Small dedicated parser and renderer,
scoped CSS, nine locales. Subsequent PRs will stack on this branch.

## Local validation
- UI typecheck passed.
- Four isolated Chromium scenarios passed: native events, history
reload, nested errors, images, collapse and narrow layout.
- Rendered capture inspected at 380px.
- git diff --check passed.

## Gatekeeper
Independent review pending; findings will be fixed and re-reviewed until
zero. User requested all PRs remain unmerged. Do not merge.

Size note: existing tool-call.css is above the source warning threshold;
changed only by adding the scoped import.
## Behavior
Dedicated websearch source cards with safe links, publication metadata,
literal snippets and raw-output fallback. Recognized native provider
consent receives a localized heading and stacked options through the
existing Form validation/reply path. Ten locales.

## Stack
Depends on #789 (zero-finding gatekeeper at aaee7d5). This PR contains
only step 2. All eight PRs are to remain unmerged at the user's request.

## Contracts and validation
Tagged native 2.0.7 and 2.0.18 tool/plugin/websearch.ts contracts
verified. No new API or minimum-version dependency. UI typecheck passed;
five focused parser, shape and browser tests passed, including hidden
Forms regression. Narrow rendered capture inspected. Raw results retain
copy/search via shared renderer. Existing tool-call.css exceeds
source-size guidance; change is one import.

Independent gatekeeper review pending; findings will be corrected and
re-reviewed until zero. Do not merge.
## Behavior
Attach/remove skills in the composer using the current session
directory's native catalog. IDs are sent through prompt.skills; OpenCode
expands the instructions. Historical and optimistic messages show skill
labels. Queued edits restore removable skill attachments without
resurrecting removals.

## Lifecycle
Visible demand only, skill/config native updates, reconnect refresh,
coalesced trailing reads and view/session response fencing. Ten locales.
Native startup registers plugins progressively, covered by fixture and
catalog updates.

## Validation
UI typecheck passed; 53 session-action regressions passed; three focused
skill tests passed; Chromium
selection/deduplication/location/stale/coalesced/inactive scenario
passed and narrow capture inspected. Isolated native fixture passed on
2.0.7 and 2.0.18 (synthetic provider, private home/database/process; no
shared daemon). No runtime-minimum change.

## Stack and gatekeeper
Depends on #790, whose independent gatekeeper has zero findings.
Independent review of this PR pending; corrections/re-reviews continue
until zero. User requested no merges.

Size notes: prompt-input.tsx (~1120), session-actions.ts (~1000),
session-view.tsx (~720), session-actions.test.ts (~1040), and locale
messaging files exceed guidance; focused additions only.
## Summary

- add a durable, project-local Missions control plane on top of native
OpenCode V2 root sessions
- expose live Mission Control navigation, task state, actor state,
reports, and evidence in the right panel
- provide bounded Pocock bug-fixing and Wayfinder exploration playbooks
without introducing a generic workflow DSL
- keep Developer Mode automation separate from mission orchestration

## Architecture

Missions uses native OpenCode V2 primitives rather than a parallel
runtime:

- root sessions are mission actors
- `queue` and `steer` are the durable actor inbox
- session metadata carries mission, task, role, and coordinator
correlation
- plugin hooks inject role context
- project-local plugin storage persists an append-only mission journal
and materialized map
- topology mutations are coordinator-only and remain scoped to one
project

The agent surface is deliberately limited to `mission.inspect`,
`mission.delegate`, and `mission.report`. The CodeNomad broker exposes
only the typed `codenomad.missions.snapshot` RPC; change events are
invalidations that trigger authoritative reconciliation.

## User-visible behavior

Mission Control shows the active mission's status, frontier, tasks, root
actors, correlated reports, and expandable evidence. It updates live,
survives reconnects, preserves the last durable map through transient
failures, and can navigate to an actor session without becoming a second
workflow executor.

All new UI strings are available in the existing 10 locales. The panel
uses the shared token, utility, and square-corner window conventions.

## Playbooks and safety bounds

- Pocock remains evidence-driven and dynamically sequences
implementation, independent reviews, resolution, and fresh validation.
- Wayfinder preserves destination, map, frontier, claims, and fog-of-war
while allowing bounded parallel research.
- Admission and resume paths are idempotent.
- Limits: 8 actors, 96 tasks, 2,000 events, and 20 missions per project.
- A green completion requires every task to be completed.

## Validation

- [x] Rebased directly on `dev` after #647
- [x] OpenCode plugin contract typecheck
- [x] Server typecheck
- [x] UI typecheck
- [x] Mission server tests: 18 passing
- [x] Mission UI/i18n tests: 4 passing
- [x] Full server, UI, Electron, and Tauri suites/builds completed
during implementation
- [x] Private runtime spike verified activation, typed RPC, restart
persistence, root-session delegation, queue/resume, correlation,
idempotence, invalidations, broker allowlisting, and checkout/worktree
storage sharing
- [x] Pocock and Wayfinder runtime demonstrations completed
- [x] Windows Tauri Mission Control validated live from active mission
through completed status, including actor navigation and expandable
evidence

## Known runtime note

A daemon that was already running before the project-local plugin
existed may fail to hot-add that plugin on Windows. Fresh daemon
activation is verified and works correctly; CodeNomad does not restart
or take ownership of a foreign/shared daemon.
## Tester feedback phase

This PR intentionally remains in draft while the session mesh receives
broader real-world use. Please exercise:

- custom missions with both idle and busy actor sessions
- Pocock implementation, independent review, resolution, and fresh
validation loops
- Wayfinder exploration with parallel frontier tasks and unresolved fog
- restart/reconnect recovery before and after delegation and reporting
- actor navigation and evidence expansion from Mission Control
- project, checkout, and worktree boundaries, including expected
authorization failures

Useful reports include the desktop host, workflow/template, exact point
of friction, expected versus observed behavior, and whether the durable
map recovered after reopening. Do not include secrets or private prompt
contents.

The unrelated automation-registry CI fix is tracked separately in #675
and is not part of this branch. After that fix lands on `dev`, this
branch can be rebased and its validation rerun before any decision to
mark it ready.
## Behavior
Global/Project websearch choice, inherited/default, disabled and
automatic/provider selection. Display effective native configuration.
Optional global API keys use native integration/credential endpoints;
environment credentials remain read-only. Scoped failures reconcile
without mutation replay, and late results are fenced.

## Contract adjustment
OpenChamber's /api/config/websearch is its backend route. OpenCode
2.0.18 has no equivalent native config write API. Reuse CodeNomad's
authorized plugin-control configuration targets, JSONC conflict-safe
edits, WSL filesystem adapter and connection/deletion fences. Preserve
unrelated fields and comments; use native watching, never implicit
location.reload.

## Validation
Server/UI typechecks pass. 51 focused server/config regression tests
pass; four real-WSL cases skipped. Real Chromium fixture passes scoped
writes, failure reconciliation, API-key clearing and late mutation
fencing; narrow capture inspected. Isolated native fixtures pass on
2.0.7 and 2.0.18 (global watching, project document persistence/reset,
foreign-directory rejection). Project discovery is disabled in native
fixtures to exclude user ancestor config; deterministic server tests
cover precedence. No shared daemon or personal data used.

## Stack/review
Depends on #791, zero findings at ea3b4ef. Independent gatekeeper
pending; fix/re-review until zero. User requires all PRs remain
unmerged.

Size notes: existing http-server.ts (~2300), api-types.ts (~1200),
plugin-controls.ts (~810), api-client.ts (~1000) and locale settings
files exceed guidance; focused changes only.


## User-feedback correction
Clarify which search provider agents use, automatic saves, the default
across projects and the current-project override. Move API keys into a
separate collapsed section explaining that credentials are shared
service-wide and saving a key does not change the selected provider.
Environment credentials are explicitly read-only. Updated in all ten
locales; narrow Chromium lifecycle/failure test and UI typecheck pass.
Alpha in fixture captures is synthetic test data.
…829)

## Summary
- Answer native Forms and permissions in a persistent composer-adjacent
dock with queue navigation and source-session labels.
- Target requests from badges and inline tools; reveal off-window source
messages through bounded history navigation, closing file previews and
exposing hidden source tools.
- Render durable native question answers in the transcript and preserve
partial request/composer drafts.
- Replace the former permission modal and retain native global Form
routing and full permission-diff review.

## Gatekeeper
- Pass 1: two actionable P2 findings.
- Corrected both in fb7ed77 with regression tests reproducing failures
before the fixes.
- Independent pass 2 at fb7ed77: zero actionable findings.

## Validation
- UI TypeScript and production build passed after rebase.
- 30 focused browser and 17 native-store/unit regressions passed after
rebase.
- All six interruption-dock tests and TypeScript passed after
corrections.
- Independent final review: nine browser tests, 20 unit/store tests and
TypeScript passed.
- Final GitHub CI in progress.

See dev-docs/NATIVE_INTERRUPTION_UX.md for ownership and validation
details.
## Summary

Qualify **OpenCode 2.0.22**, align server/UI client and plugin pins, and
recommend this release. Keep the demonstrated **2.0.7** global minimum
and **2.0.20** Codex Usage feature-local requirement.

Block the new native `parentID` create variant in the workspace proxy:
upstream ignores the supplied location and inherits the parent's
directory. Require inspectable JSON objects to close opaque-body
bypasses. Root creation and the existing authorized fork route remain
available.

Started at `dev@0983db3` (#828 Windows test harness), then integrated
`dev@97c361c` (#789 Code Mode presentation). Conversation remains
attached to `D:\CodeNomad`; all work and tests use explicit separate
paths and synthetic data.

## Upstream audit: 2.0.21 → 2.0.22

- Authenticated native OpenAPI retains **116 paths**, with **11 schema
differences**: session creation gains optional `parentID`,
parent-not-found response/description; provider settings gain optional
`headerTimeout` and `chunkTimeout=false`; configured model capability
overrides become partial. No new proxy route or consumed mandatory API.
- Published declarations: **4/30 client, 2/60 plugin, 3/36 protocol,
4/102 schema** files change. Plugin session domains expose `remove` and
`compact`; CodeNomad does not add calls to them. Identifier namespace
export is additive.
- An isolated native fixture proves parent creation inherits the parent
location despite a different supplied directory. Mock and
production-proxy fixtures reject owned/foreign parents; malformed values
and opaque content types are covered before any native request. Owned
root creation stays available.
- Runtime changes include HTTP header/chunk/whole-response timeout
handling and bounded timeout retries, provider cache/error/tool-history
fixes, model capability defaults, and legacy MCP shutdown cleanup.
- Lock changes are limited to six `@opencode` packages and two workspace
entries. Integrity/dependency metadata matches independently installed
published packages; clean `npm ci --ignore-scripts` passes. Optional
OpenTUI peers are not installed by CodeNomad.

## Isolated local qualification

**Windows / Node 24.20.0**, isolated profiles, databases, services and
synthetic providers/credentials. No shared-daemon or personal-history
mutations.

- Previous **2.0.21 dependencies + runtime 2.0.22**: native
pruning/history/proxy acceptance passes.
- New **2.0.22 dependencies + runtimes 2.0.7 and 2.0.22**: seven suites
pass (automation, pruning/history/navigation, per-send environment,
inclusive forks, idle/busy side questions, blank-session cleanup,
Git-degraded recovery), plus explicit native proxy suites.
- Native/UI pruning acceptance passes through the committed parent
runner, with completion and actual child exit verified. This uses #828's
early dependency-import workaround, not the old late-import order. No
claim that underlying Windows heap corruption is repaired.
- Current compaction-isolation acceptance passes: session B progresses
while session A's provider response is held; bounded outline reads
retain daemon heartbeats. Fixture runtime selection is extended to
include 2.0.22; its assertions are unchanged. This supplemental fixture
was not qualified on 2.0.7 (explicit runtime selector rejects it).
- Native Codex Usage passes on 2.0.22 with synthetic OAuth/key
credentials and mocked quota HTTP; not a live-account/WSL test.
- Native migrations **2.0.3 → 2.0.22** and **beta-19271 → 2.0.22**
preserve full history/forks/inbox/provider selection.
- Packed standalone pruning plugin installed outside the repository
passes native acceptance.
- Native npm upgrade **2.0.15 → 2.0.22** passes; authenticated daemon
remains **2.0.15 / PID 43876** before and after.
- Full server run: **794 passed / 6 skipped / 0 failed**. Final guard
revision separately passes **68 focused server tests** and native proxy
suites on minimum/current. Aggregate runs use `--test-force-exit`.
- Targeted client/store/reducer/usage UI: **63/63** with
`--conditions=browser`, `--test-force-exit`, bounded timeout. Initial
broad UI run used the wrong Node conditions and hung at
`prioritized-read.test.ts`; only its owned processes were stopped. That
incomplete run is **not green**. The same prioritized-read tests pass
under the browser condition used by CI. No production fix is inferred
from this launch correction.
- **41 browser scenarios** pass: setup/install, auth recovery, tool
images, rendered Codex Usage and compaction responsiveness. Browser
tests do not use forced exit.
- Server/UI/Electron typechecks and production server/UI/plugin builds
pass. Revalidation after #789 integration and independent gatekeeper are
reported separately below.

Local results do not certify all real providers, Linux/macOS/WSL, or
installed Electron/Tauri hosts. Historical Windows import and Git
cleanup failures remain limitations, not repaired by this upgrade.
Remote CI is not continuously monitored and no global CI-green claim is
made.

Size note: existing `packages/server/src/server/http-server.ts` is
~2,359 lines;
`packages/server/src/server/__tests__/instance-proxy.test.ts` is ~1,139
lines. Changes are narrowly scoped; no unrelated size-driven refactor.

## Independent gatekeeper

Review launched on exact head `0a7615476034eabbff54967aacc8a93ab0e6ab12`
against `dev@97c361c`; verdict will be
published before any admin merge. Findings will be corrected and
reviewed again until zero actionable findings.
Revert merge c118478 relative to its first parent after the user confirmed the merge was requested in the wrong conversation. Remove the published Missions plugin, control routes, UI, playbooks and packaging references; do not rewrite dev history or touch durable-refactor work in the separate missions-v2 checkout.

Preserve subsequent PRs #792, #829 and #830. Remove only #829's now-invalid Mission reader import, dismissal hook and dedicated reader scenario, retaining the native questions/permissions dock, file-preview navigation and its other tests. Keep the 2.0.22 package pin and parent-session creation fence.

Validation: revert applied without conflicts; all 139 original merge paths reversed; later-only paths retained except the three minimal interruption-dock integration adaptations. Server and UI TypeScript checks and 18 automation/plugin lifecycle/desktop resource tests pass using existing local dependencies. Staged diff checks are clean. Full hosted CI, browser suites and native 2.0.22 qualification were not rerun for this immediate user-authorized admin revert.
## Outcome
Reverts the accidentally authorized merge of #673
(`c11847880588c287a4a4dfbc3881f35f92a9415d`) relative to its first
parent. The user explicitly requested this revert and immediate admin
merge.

- Removes the published Missions plugin, routes, UI, playbooks and
packaging references.
- Preserves later PRs #792 (web search settings), #829
(questions/permissions dock) and #830 (OpenCode 2.0.22 and
parent-session fence).
- Removes only #829's dependency on the now-removed Mission reader,
including its dedicated fixture scenario; retains the dock and other
navigation/answer tests.
- Does not rewrite history, delete native mission/session data, restart
the app/daemon, or touch the separate local durable-refactor work.

## Validation
- Git revert applied without conflicts; the original merge affected 139
paths and all 139 were reversed. Three later interruption-dock files
require the minimal removed-reader adaptation above.
- Server and UI `tsc --noEmit` pass using existing local dependencies
(no installation). This is not native 2.0.22 qualification.
- 18 automation/plugin lifecycle/desktop resource tests passed; staged
diff whitespace check passed.
- Full hosted CI/browser/native suites were not rerun for this immediate
admin revert.

## File-size notes
Existing oversized modified sources remain:
`packages/server/src/server/http-server.ts` (~2362 lines),
`packages/server/src/api-types.ts` (~692),
`packages/server/src/index.ts` (~694),
`packages/server/src/opencode/automation-plugin.ts` (~583),
`packages/ui/src/components/session/session-view.tsx` (~710),
`packages/ui/src/lib/api-client.ts` (~636). No size-only refactor
included.
…ion (#793)

Expose the approved active-account dropdown with persistent credential-keyed drafts and always-visible add/rename/remove actions. Enrich only native fallback labels with a sanitized Codex login while keeping all credential values server-side. Persist opt-in automatic selection for supported OpenAI OAuth accounts and admit one fresh-quota-verified native activation before the next prompt/custom command, with local manual/policy fences, ownership and deletion admission, no model changes, and no prompt or mutation replay. Preserve dev's Missions revert and document service-wide selection and external-client compare-and-set limitations. Validated both package typechecks, the UI build, 812 server tests, 865 CI-selected UI unit tests, isolated native 2.0.22 synthetic-account/YAML fixtures, and focused Chromium/native bridge regressions. Final admin merge explicitly requested by the user; platform/runtime/native checks are green while the general tests job is still in progress.
Generate positive, nonzero and canonical DER certificate serial numbers for both the local CA and server. node-forge encodes the supplied hex bytes as a signed ASN.1 INTEGER, so a random high bit previously produced a negative serial rejected by Go/Caddy. Normalize leading zero octets, add sign padding only where needed and handle the all-zero draw while keeping random 128-bit serial draws within the RFC 5280 size bound.

Renew existing negative/zero generated server certificates at HTTPS initialization while preserving a valid CA and existing client trust. If the generated CA itself must be replaced, also reissue the leaf and warn that clients must import the replacement CA. Keep valid generated credentials unchanged and leave explicitly supplied certificates untouched. Document startup repair and reverse-proxy trust implications.

Seventeen TLS tests pass on Node 24.20.0, including deterministic edge draws, actual DER encoding, signature/SAN checks, invalid serial migration, verified loopback HTTPS requests, CA replacement, reuse and provided/disabled behavior. The full server suite passes with 825 passed, six existing skips and zero failures; server typecheck and diff checks pass. No installed app, shared daemon or user certificates are changed. The reporter's physical macOS/Caddy setup was not directly tested.

Fixes #832.
## Summary

- Ignore repeated browser transport statuses and identical
instance/status/native-generation snapshots instead of clearing
validated provider quotas and restarting reads.
- Keep genuine reconnects, changed native generations (including a
missed disconnect), account/configuration changes, native
`server.connected`, source changes and failed-read revocation unchanged.
- Add real Solid/browser dispatcher regressions covering quota DOM
stability, in-flight refreshes, compaction independence and
stale-response fencing.

## Scope and evidence

The regression test fails before the fix: 40 duplicate connected
notifications produce 40 additional quota reads and replace the quota
display with Loading. After the fix, the same bar DOM and request cycle
remain intact. Quotas still use the native credential API and provider
HTTP endpoint; no log-based or host-credential fallback is added.

This fixes a demonstrated flicker trigger, not every live disappearance.
Initial passive captures did not reproduce a disconnect. A later capture
did confirm a real relay failure: `Instance event relay routing timed
out` at native generation 52, followed by connecting/connected at
generation 53, affecting both opened projects. This PR deliberately
continues to revoke quotas on that real boundary; it does **not** fix
the relay timeout itself. The installed desktop application and shared
daemon are unchanged.

## Validation

- 17 UI state/component/browser tests passed.
- 12 native usage/route tests passed.
- UI typecheck and production build passed.
- Before-fix regression failure confirmed; rendered fixture capture
inspected.

Independent Gatekeeper review will be published against the exact PR
head before administrator merge.
## Summary
- Keep pending questions in the composer-adjacent dock and native
answers in the transcript after completion; remove redundant navigation
links.
- Separate collapse from bounded request navigation and hide navigation
for one request. Preserve the selected draft across incoming permissions
and session changes.
- Add accented window chrome, fixed action footers, readable dark
receipts and visible scrolling. Preserve permission diff-review gates
and disable form editing during submission.

## Validation
- UI TypeScript and production build passed.
- 16 Form/settlement/diff-review unit-store tests passed.
- 10 dock browser tests, 1 cross-session selection test, 5
permission/Form browser regressions, 21 history-navigation tests and 1
session-search regression passed.
- Rendered captures inspected at 393 and 1100 CSS pixels in light/dark;
mobile permission actions validated.

## Review
Independent UX and interaction reviews informed the implementation.
Autonomous final gatekeeper review in progress before requested admin
merge.

## Maintenance note
Existing large components touched: message-block.tsx (~1965 lines),
message-section.tsx (~1561), tool-call.tsx (~991).
## Summary

Follow-up to merged #835: fix the demonstrated dependency behind real
`Instance event relay routing timed out` disconnects, not duplicate
connection notifications.

Existing diagnostics captured relay ownership blocked in `getWorktrees
-> WorktreeInventory -> POST /api/worktree/refresh`, including a refresh
pending beyond 150 seconds and a separate ~220-second completed call.
That exceeds the unchanged 60-second relay job deadline, so the shared
relay reconnects and Usage correctly clears for all projects.

Event authorization now uses a separate **registered-only** native
worktree inventory and never starts or joins native strategy discovery.
Native project/checkout checks, physical Git membership, clone
exclusion, configured roots, nested-folder and WSL projection remain in
the shared catalogue implementation. Native/local invalidation and
workspace disposal fence both inventories and their distinct
directory-cache namespaces. Ordinary request authorization and explicit
worktree discovery retain refresh and read-your-writes behavior.
Full-location checks receive the connection attempt's abort signal.

No timeout increase, swallowed reconnect, stale authorization fallback
or quota-specific workaround. FIFO lanes, ownership retries,
generation/workspace fences and retained-work budgets are unchanged.

## Validation

- Baseline-red production-manager + relay reproduction: hold discovery
unresolved and require the linked-worktree event to route before
releasing it.
- All **248 workspace tests pass**, including event order/reconnect,
ownership, no-Git, WSL, configured Git roots and inventory invalidation.
- Server TypeScript check passes.
- Isolated OpenCode **2.0.22** location/worktree/event fixture passes,
including real pre-refresh native registration and ordered real session
events during a held fixture-manager discovery request.
- Isolated no-Git native prompt/recovery fixture passes.
- `git diff --check` passes.

## Scope / limitations

The native refresh's internal delay is not claimed fixed; the relay no
longer depends on that unnecessary discovery operation. Actual transport
failures and other stuck native reads still trigger bounded
reconnect/reconciliation. Compaction and window-resize jank are not
established causes or fixed by this PR.

The installed application, shared daemon, user settings and independent
#824 worktree are untouched. This conversation remains attached to
`D:\CodeNomad`.

Existing oversized source touched:
`packages/server/src/workspaces/manager.ts`, approximately 1,260 lines.
No unrelated size-only refactor.

Independent Gatekeeper review will be published against the exact PR
head, with findings resolved and fresh passes until zero findings before
the requested administrator merge.
#838)

## Summary
- Persist all permission decisions: allowed once, always allowed and
rejected, with request context and known reasons. Distinguish CodeNomad,
automatic Yolo and native settlements.
- Keep receipts visible alongside transcript messages even with hidden
tools; provide paginated source-less session receipts. Ownership-checked
bounded reads, atomic profile storage, deletion cleanup and stale-read
fencing.
- Enrich completed native question receipts with selected-option
descriptions, verbatim custom answers and a disclosure for other
choices. Translate labels in all ten locales.

## Validation
- Locked dependencies installed; server and UI TypeScript checks pass;
production UI build passes.
- 126 targeted server regressions during implementation, then 26
receipt/replier/service checks against the pinned client passed.
- 20 receipt/dock browser tests and 21 history navigation tests pass; 5
question decoding/copy tests pass.
- Rendered captures inspected at 393/1100px in light/dark, including
long text and pagination.

## Persistence boundaries
Native permission events are ephemeral: past lost decisions cannot be
reconstructed. Receipts are CodeNomad annotations outside native
search/copy/export. Storage namespaces follow execution host, native
root and authenticated channel; credential rotation starts a new
namespace. Bounded text excludes metadata/diffs.

## Review
Autonomous independent gatekeeper review will be published and repeated
until zero findings before the user-requested admin merge.

## Maintenance
Existing oversized files touched: server/http-server.ts (~2415),
server/api-types.ts (~717), server/index.ts (~707),
ui/message-section.tsx (~1566), ui/lib/api-client.ts (~650).
## Summary
- Continue sparse history scans until a bounded result page is filled,
publishing matches progressively across sessions.
- Remove the automatic count traversal. Show page-local results and
messages scanned directly from search responses, with no scan when
opening an empty search.
- Project text-only content in SQLite, reduce bounded RPC round trips,
and share identical location checks only inside a request.

## Validation
- UI/server typechecks and targeted server/store tests passed.
- Chromium regression covers progressive results, pagination, workspace
scope, technical toggle, empty results and absence of statistics
requests.
- Isolated native OpenCode 2.0.22 fixture passed, including all 242
workspace matches across two sessions and pruning/ownership regressions.
- Synthetic benchmark: text search materializes 9.6 KB instead of 145
MB; CPU gain is modest because SQLite still parses stored JSON. See
dev-docs/SESSION_HISTORY_QUERIES.md.

## Review
Independent gatekeeper review and post-rebase validation in progress;
findings will be addressed before administrator merge.
… Locations (#840)

Recover pending Forms and Permissions through a fixed presence-owned RPC in
the existing bundled plugin, without warming historical native Locations.
Validate established execution-host origin, complete coverage, directory/Git
ownership, WSL aliases and every placement before admitting capability.
Keep generic RPC forwarding closed and preserve non-authoritative failures.

Observe native compaction before event ownership routing and defer expensive
legacy discovery before inventory reads and at forwarding. Preserve concurrent
holds, bounded missed-end probes, exact settlement reconciliation grants,
per-kind mutation fences, global/idle Forms and settled-request tombstones.
Never replay ambiguous mutations. Share presence observations, not registrations
or execution authority.

Integrate current dev receipt and event-ownership changes. Reassert the native
connection after permission receipt preparation and before granting settlement
reconciliation or dispatching mutations. Reject overflowing raw JSON numbers,
including unknown metadata, without altering native numeric codec strings.
Use eight-directory UI batches with the unchanged request deadline and URL
budget rather than weakening ownership checks or extending timeouts.

Add scoped broker, reader, presence, proxy, compaction and UI lifecycle
regressions plus an opt-in isolated native reader fixture. Independent
Gatekeeper reviews are published on the PR; R1's numeric overflow finding is
fixed and rechecked on the final head before merge.

The private reader is qualified for native 2.0.22 / Effect rc.112 only. The
global minimum and already-recommended 2.0.22 remain unchanged. Unsupported
runtimes retain guarded legacy recovery. This mitigates CodeNomad's load
amplification, not the upstream Bus issue or previously retained Locations;
installed-application freeze resolution, deployment and daemon restart are
not claimed. Preserve bootstrap-warming and bounded-scan limitations.
## Summary

Prepare stable CodeNomad 0.20.1 on top of `dev@8ce70ec`, the source of the latest requested prerelease, before publishing through `dev -> main`.

- Align root, server, UI, Electron and Tauri npm versions and workspace lock metadata to `0.20.1`.
- Align the native Tauri configuration, Cargo manifest and application lock entry.
- Require CodeNomad server `0.20.1` in the remote UI manifest, so the updated Files, provider settings and pending-request surfaces use the matching backend routes.
- Leave the dependency graph unchanged.

This preparation PR targets `dev`; only the subsequent push to `main` publishes the stable release.

## Validation

- Clean locked dependency installation in an isolated release worktree.
- Version consistency assertions across npm/lock metadata, Cargo and Tauri; dependency graph comparison against the parent commit.
- `npm run sync:version --workspace @codenomad/tauri-app` confirms all native versions are aligned.
- UI, server and Electron typechecks pass.
- Full server production build, including the UI and bundled plugins, passes.
- Remote UI selection and dev-release channel tests pass (3 tests).
- `git diff --check` passes.

Native installers and the cross-platform release matrix have not been rebuilt locally. Existing local work and suspended worktrees are untouched. CI is not being waited on or monitored as requested.
@pascalandr
pascalandr requested a review from a team October 3, 2026 13:47
@pascalandr
pascalandr merged commit a8545a3 into main Oct 3, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants