Repository navigation
Release v0.20.1 - unified Files, mobile layouts, provider accounts and responsiveness - #843
Merged
Merged
Conversation
Introduce the project-local codenomad.missions V2 plugin with a durable append-only mission map, deterministic OpenCode inbox admissions, and the compact mission.inspect, mission.delegate, and mission.report tool interface. Root sessions remain visible native actors, only coordinators may change topology, and blocked tasks are mapped without a hidden workflow interpreter. Add constrained CodeNomad snapshot brokering instead of exposing generic plugin RPC. Workspace-owned locations, active plugin inventory, project identity, root-session membership, actor limits, and foreign-session fences are checked at their respective seams. Queue/resume delivery supports busy actors and deterministic IDs make interrupted dispatch and report notification retries idempotent across restarts. Ship dynamic custom, Pocock bug-expedition, and Wayfinder playbooks plus provenance and architecture documentation. Pin the local plugin contract to beta-18999 alongside the reviewed V2 client. Validated with the server TypeScript check and 12 focused mission, plugin registration, recovery, authorization, idempotence, and broker tests.
Register a first-party Missions tab in the existing right-panel module seam. The new map-oriented view exposes mission objective and state, dependency-aware route nodes, frontier and claim totals, native root-session actors, correlated reports, and direct actor navigation without adding a second execution surface. Load authoritative snapshots through the constrained CodeNomad broker, debounce typed RPC invalidations, refresh tracked workspaces after both OpenCode and CodeNomad event-stream reconnects, preserve the last durable map on transient errors, and clear stopped workspace state. Missing project plugins remain an explicit optional-capability state. Add square-corner, token-based, RTL-aware panel styles split by feature concern and complete translations for all ten supported locales. Locale tests enforce key and interpolation parity, while store tests cover availability, stale-response fencing, reconnect ordering, and durable fallback behavior. Validated with the UI TypeScript check, focused Node tests, locale parity checks, and a production Vite/PWA build.
Require structured Pocock evidence for completed diagnosis, implementation, independent standards/spec reviews, resolution, and final validation. Fence fresh reviewer and validator roots while requiring review resolution to reuse the implementer, and cover a full dynamic Pocock cycle plus a breadth-first Wayfinder map. Align the project-local plugin with beta-18999 runtime behavior by emitting native typed system parts, JSON-normalizing optional RPC output, using the typed RPC call as the capability probe, and keeping the runtime entry free of an SDK import. Add a dedicated compile-time plugin contract check to CI. Record the private-runtime spike proving busy-root queue delivery, resume, correlated synthetic reporting, restart restoration, idempotent admissions, typed invalidations, owned broker access, and shared project storage across worktrees. Targeted mission, plugin, and broker tests pass alongside server and plugin typechecks.
Omit workspaceID when a durable mission location has no workspace instead of reconstructing an explicit undefined property. OpenCode V2 validates managed session creation inputs strictly, so the previous shape could leave a newly admitted task at the durable dispatching boundary. Add a regression assertion for workspace-less actor locations and record the successful idempotent resume of the same dispatch after a private server restart. Document full live Pocock and Wayfinder demonstrations, including independent roots, structured evidence gates, derived frontier transitions, read-only validation, and publication fences.
Prevent concurrent mission tool calls from racing the same project snapshot and overwriting deterministic event identities. Project-scoped mutation and append queues now preserve first-writer contracts across multiple MissionControl instances, while journal admission rejects new records before the 2,000-event bound is exceeded. Enforce Pocock's evidence transitions independently of model-supplied blockedBy keys and require every role-specific completed report before a green mission finish. This keeps dynamic task naming while making the documented diagnosis, implementation, independent reviews, resolution, and validation gates authoritative. Add regressions for conflicting concurrent task contracts, concurrent mission starts, journal capacity, skipped Pocock prerequisites, and empty green completion. Validated the 400-test server suite (398 passed, 2 platform skips), mission/plugin/route/UI-store focused tests, server and project-plugin typechecks, and git diff checks.
Reject new mission creation at the project snapshot capacity rather than persisting a twenty-first mission that hides active membership. Keep deterministic start replay available at capacity. Reject new explicit actor targets at the actor cap before writing dispatch intent. Existing actors remain reusable, and rejected tasks remain ready so the coordinator can retry with an admitted actor instead of leaving a missing-actor dispatch permanently stuck. Add regressions reproduced red before the fix covering both limits, snapshot reconstruction, idempotent start replay, and actor reuse after rejection. Validate 24 focused mission tests, 400 passing server tests with two platform skips, server typecheck, and diff checks.
Integrate current dev into the Missions branch without rewriting feature history. Resolve the PR workflow conflict by retaining both the mission translation test and the upstream clipboard test, alongside the existing mission-store and plugin contract checks. Preserve the upstream HTTP server changes and mission route registration. Validated the parsed workflow and all 52 referenced UI test paths; 334 runnable UI tests and 24 focused Missions/plugin/broker tests passed. UI, Electron, server, and project-local plugin typechecks and diff checks passed.
Integrate dev@ea37f97b after the global-session, nested-scroll, and selective-pruning fixes while preserving the native Missions control plane. The merge is conflict-free and keeps the PR history intact for exact-head CI validation.
Integrate dev aa51cbb and retain both Missions and current request-location CI coverage, panel styling and narrowly scoped plugin documentation. Move the Missions client and checked plugin dependency to official 2.0.4 packages. Replace removed plugin.awaitActivation with the native location and plugin inventories. Validate snapshot project identity against location.get, retain legacy location context through direct and typed RPC requests, and refresh tracked Missions when plugin.updated changes capability availability. Keep Missions optional and its broker restricted to the reviewed snapshot method. Validation: checked Plugin.define setup against @opencode/plugin 2.0.4; 24 targeted Missions tests passed; server suite 524 passed/2 skipped; UI stores 444 passed; Electron native 194 passed/4 skipped. Server/UI/Electron and project-local plugin typechecks pass. Live mission delegation on a native daemon and non-Windows desktop behavior are not claimed by these tests.
Merge dev bdac05b into the Missions branch so PR #673 retains its project-local codenomad.missions coordination while adopting the current bundled automation, session-environment admission, native worktree inventory, and desktop lifecycle changes. Resolve the server import overlap by preserving both Mission route registration and fail-closed session environment errors. Update the architecture guidance to document Missions alongside the current backend-presence automation and pruning boundaries. Validation: 615 server tests passed with 2 platform skips; 41 focused Missions and session-environment tests passed; server, UI, Electron, and project-local plugin typechecks passed; pruning and automation plugin builds passed; workflow YAML parsed successfully; git diff checks were clean.
Integrate dev through #719 after the Node 24 refresh. Preserve the project-local Missions RPC and UI while adopting the bounded per-instance event queue so slow routing no longer blocks the shared native stream. The upstream delta has no file overlap with the Missions changes; follow-up validation covers the new routing regressions together with the focused Missions contract and Node 24 typechecks.
Integrate dev through #720 while preserving the Missions plugin, server route and session-native UI. Adopt the zero-specificity global scrollbar default so transcript and timeline component rules remain independent. The upstream stylesheet delta has no file overlap with the Missions changes; validation covers the shared UI typecheck and the timeline browser regressions before the full PR matrix.
## Summary Fix the first-install recovery dead end observed in CodeNomad 0.20.0 on Windows 11. npm failed to install the optional Windows binary packages, then removed the CLI package while leaving terminal shims behind. These shims disabled installation admission and hid the install button; later status refreshes also erased the action error. Recognize only the exact npm-generated orphan shim in the selected user prefix with a missing canonical executable. Preserve custom-wrapper, foreign-prefix and existing-binary authority checks. Keep action failures visible across refresh and reopening. ## Validation - 34 targeted updater/installer regressions passed. - 21 browser setup regressions passed. - Server TypeScript check passed with locked dependencies. - On the affected machine, isolated package download and executable validation succeeded without Git. Explicitly authorized repair using bundled npm succeeded; the user confirmed CodeNomad now opens folders. ## Distribution The maintainer explicitly requested replacing the existing 0.20.0 desktop release assets rather than creating 0.20.1. This branch is based on v0.20.0 and preserves its version; the PR build artifacts will be used for that revision after validation. The release notes will record the source commit, and WinGet will receive a separate same-version installer hash correction. No npm version republication is intended. Co-authored-by: Shantur Rathore <i@shantur.com>
## Summary - Update the main README for the shared OpenCode V2 service, current features, managed desktop setup, minimum/recommended OpenCode versions, and explicit service restart behavior. - Correct release links, actual Electron/Tauri artifact formats and architectures, Node guidance, remote authentication and SideCar configuration fields. - Align server and contributor documentation with the 0.20 baseline. - Replace the old hero screenshot with a current 1600x900 workspace rendered using real Solid components and synthetic demo data. - Include a reproducible Chromium capture script and provenance notes; external traffic is blocked and no user backend, daemon or provider is used. ## Preview  ## Validation - UI typecheck passes. - Chromium capture passes transcript, connected-state, agent, timeline and MCP readiness checks, with no uncaught renderer errors. - Resulting image inspected visually. - 20 local Markdown/image targets verified. - Staged git diff --check passes. Regenerate with: node packages/ui/scripts/capture-readme.mjs Documentation and capture tooling only; CI is not being monitored.
…#787) Persist the global favorites/all choice in the UI state owner instead of deriving it from each selected model. Search stays within the chosen mode, and the active model is added without becoming a favorite, respecting explicit provider visibility and disabled unavailable placeholders. Publish mode intent immediately and serialize persistence. Fence completion by latest-write identity so double/triple clicks retain the latest intent throughout delayed responses. Keep a stored mode visible and revocable when no favorites remain. Add real-component browser coverage for selection, search, remounts, hidden/unavailable models, empty favorites and click bursts. Register store coverage in CI, verify actual persistence ordering and ensure mocked writes finish before teardown. Independent final gatekeeper PASS at 1ee5a96; 860 CI-group unit tests, 14 targeted tests, six browser tests and typechecks pass locally. Remote Windows Rust Node-election failure is documented separately in the PR.
Align server/UI client and bundled plugin pins with the latest stable runtime while preserving the demonstrated 2.0.7 timestamp minimum. Review the published declarations and authenticated native schema: pairing and Shell signal additions require no CodeNomad API adaptation. Make the isolated native upgrade fixture follow the recommendation while retaining its 2.0.15 source boundary and live-daemon PID assertion. Extend setup version coverage and update the current compatibility and architecture references. Validate both minimum/current native runtimes, historical migrations, server/UI tests, setup and tool-image browser scenarios, typechecks and production bundles. Record the intermittent Windows Node pruning/UI heap exit and successful diagnostic rerun without claiming its cause is fixed.
## Summary
Qualify the latest published stable OpenCode **2.0.18** and align the
server/UI client, bundled pruning plugin and recommended runtime. The
technically required minimum stays **2.0.7**
(`session.step.started.data.started`). No application API adaptation was
needed.
The setup regression covers the intermediate releases as usable, with
only the recommendation designated release-tested. The isolated native
npm upgrade fixture now follows `RECOMMENDED_OPENCODE_VERSION`,
retaining 2.0.15 as the native-upgrade source boundary and asserting
that installation does not restart the live daemon.
## Upstream review
- Compared `anomalyco/opencode` tags **v2.0.16...v2.0.18**, published
client/plugin declarations and a real authenticated 2.0.18 daemon
schema.
- The runtime has **115 paths**: the previous 113 are unchanged;
`/api/pair` and `/auth/connect/{code}` are additive. Component changes
are optional `Shell.Info.signal` and two pairing response schemas.
CodeNomad's guarded proxy does not expose the new pairing APIs.
- The tagged `packages/protocol/openapi.json` still has 113 paths, so
comparing that file alone would miss the additions. The actual runtime
schema and generated client agree.
- Client changes are additive; plugin declaration changes concern TUI
model variants. OpenTUI optional peers advance to >=0.5.12 and
`@opencode/util` adds the shared browser opener dependency.
- Relevant runtime fixes: flush batched transcript deltas before the
next block; report signal-terminated Shells; restore no-output
placeholders; improve provider errors/reasoning budgets; improve Code
Mode JavaScript semantics; decode legacy media in compaction checkpoints
(2.0.18).
- Authentication, native storage, explicit configuration reload and
install/restart ownership remain the existing CodeNomad contracts. No
minimum bump follows merely from the new publication.
## Isolated Windows qualification
Node **24.20.0**, synthetic providers, separate profiles/databases/CLI
installations; no shared daemon or personal histories used.
- Existing 2.0.16 dependencies against runtime 2.0.18: complete native
pruning/UI acceptance passed before the dependency change.
- 2.0.18 dependencies against minimum runtime 2.0.7: all seven native
suites passed (automation, pruning, environment, forks, side questions,
blank-session cleanup, Git-degraded recovery). Pruning includes
relay/proxy ownership, native worktrees, Forms/permissions, 241-message
search/cleanup, 1,501-message outline/navigation, concurrency and
restart persistence.
- 2.0.18 dependencies against runtime 2.0.18: automation, environment,
forks, side questions, blank-session cleanup and Git-degraded suites
passed. The initial pruning run passed the native
relay/proxy/worktree/history cases, then the Node process exited with
**0xC0000374** while loading browser/server dependencies. The prior
2.0.16 qualification already records an intermittent Windows exit at
this phase. This is retained as unresolved failure evidence, not claimed
fixed by a rerun.
- **744 server tests passed, 6 skipped; 65 UI client/store/reducer tests
passed.** Server, UI and Electron typechecks passed.
- Native migration **2.0.3 → 2.0.18** passed: complete histories, fork
identities, historical provider configuration and same-version restart
comparison for Forms durability.
- Native npm **2.0.15 → 2.0.18** installation passed, while the
authenticated daemon remained **2.0.15**, with the same PID
before/after.
- The diagnostic **2.0.18 native pruning/UI rerun passed in full**,
including UI deletion, automatic plugin discovery, multiple backends,
claim contention, next-model payload, fork isolation, compaction and
restart. `--report-on-fatalerror` was enabled; no failure occurred on
that run. This does not establish the cause or a fix for the first exit.
- Native migration **beta-19271 → 2.0.18** also passed, including
histories, forks, historical configuration and Forms durability checks.
- **25 setup/auth-recovery browser scenarios passed.**
- **3 tool-image browser scenarios passed**, covering
generic/specialized output, collapse, failed/unsupported sources and
replacement recovery.
- Production server/UI/pruning/automation build passed.
- Standalone pruning plugin was packed, installed outside the
repository, then passed the 2.0.18 native suite (including 241-message
search/cleanup, 1,501-message navigation, proxy/ownership, concurrency,
compaction and restart). This verifies the actual distributable
independently of the embedded bundle.
The independent gatekeeper review will be recorded before merge.
Cross-platform CI is distinct from these local Windows results.
## Review and merge
Base: `dev@14b1eaa` (#787). The user
explicitly requested independent gatekeeper review/correction loops
until zero actionable findings, followed by administrator merge. Final
merge must target the reviewed head and verify any new `dev` merges
first.
Provision codenomad.missions through connected-daemon discovery and independent backend presence instead of requiring a source plugin in every project. Bundle the integration for Electron and Tauri, retain project-scoped mission journals across shutdown, and use the same secondary surface as Status. Complete the existing native actor execution work: persist explicit agent/model/variant choices, validate catalog selections and avoid switching busy actors. Admit assignment and report writes through the authenticated desktop bridge with durable-contract verification, session ownership, connection and worktree fences, and per-send profile environment synchronization. Advance the older source branch client/plugin pin to 2.0.11 and retain its bounded runtime metadata adaptation. The isolated 2.0.16 mission fixture passes native catalog, selection, busy queues, conflict, environment, reports, reconnect and idempotence checks. Server, UI and plugin typechecks, 31 mission tests, 10 lifecycle/transport tests and six resource-layout tests pass.
Resolve desktop bridge ownership as soon as one workspace validates the session instead of waiting for every inventory. Probe mission admission candidates concurrently so an unrelated stalled connection cannot delay a verified owner. Keep authenticated bridge discovery, cross-backend ambiguity rejection, durable contract checks, execution selection, worktree fences and per-send environment admission intact. Duplicate logical tabs still share their backend profile. Add regressions for stalled unrelated ownership and connection checks. All eight route tests and server TypeScript compilation pass. Verified the installed Windows Tauri backend reconnects and accepts the original durable assignment after the fix; ownership probing dropped from roughly 13 seconds to 0.46 seconds.
Live multi-agent research exposed a second timeout after unrelated workspace waits were removed: the actual owner's validated linked-worktree inventory can take about 18 seconds when cold. Give mission discovery a bounded 30-second probe deadline instead of the five-second interactive browser deadline. Keep browser discovery unchanged and continue probing for competing backend owners before admitting any mission input. Add a regression with ownership validation exceeding five seconds and verify a second owning backend prevents another admission. Validated ten automation tests, server typecheck, bundled Missions build and the isolated OpenCode 2.0.18 native fixture. Loaded the updated bundle through the installed desktop lifecycle and successfully resumed the same previously blocked UX assignment without a duplicate actor or task.
Make Mission Control actionable with create/edit/delete, persistent disclosures and selection, task dependencies, native attention requests, execution comparisons and a long-content reader above the mounted transcript. Preserve drafts and native per-window layout, and arbitrate browser/reader gestures without losing the preview target. Add coordinator-only mission.revise with revision CAS, idempotent replay, linked replacements and explicit dependency changes. Retain withdrawn task contracts and late reports, require terminal settlement for outstanding native admissions, and attribute human metadata edits in the bounded history. Mission deletion tombstones the map without deleting conversations. Cover lifecycle and revision semantics with backend regressions and the isolated OpenCode 2.0.18 fixture, including the repaired authenticated late-report notification. Validate real Solid UI restoration, editor retry identity, native background Forms, transcript/draft preservation, layout cleanup and ten-locale parity. Record Kandev research, scope decisions and separate follow-up opportunities.
Share project mutation and append queues across content-addressed plugin incarnations so disposal cannot let competing revision checks overwrite history. Keep in-flight operations exclusive until settlement. Raise assembled bridge text bounds to accommodate maximum XML-escaped objective and task fields within the existing HTTP body bound. Exercise real authenticated HTTP admission with XML, JSON-control and multibyte expansion. Observe both regressions failing before their fixes, then passing with the focused bridge suite and server typecheck. The isolated OpenCode 2.0.18 fixture now proves reports reach an actual provider request for idle and busy coordinators instead of treating session idle as proof of consumption.
…racts Recover durable report notifications that were saved before a bridge outage prevented coordinator admission. Reuse native message identities, honor journal acknowledgements and lifecycle fences, and retry only notifications through the authenticated environment-aware bridge. Nonblocking single-flight retries use bounded backoff and rotating batches without dispatching tasks. Show pending coordinator notification separately from task completion in Mission Control, with all locales aligned. Derive managed actors from immutable task identities, resolve Pocock implementers through live task ancestry, and normalize dependencies for both new and historical idempotent requests. Validated 53 backend regressions, server and UI typechecks, UI and plugin builds, six real-component browser scenarios, locale parity, and an isolated OpenCode 2.0.18 fixture proving idle/busy resumption and automatic outage recovery with and without restart. Native replay retains one correlated report without another coordinator wakeup.
Declare expected mutation rejections in the native RPC contract and return them through the invocation error API. Map structured business codes to conflict, missing and ownership responses so stale editors can request a reload instead of reporting an unavailable plugin. Unexpected exceptions remain opaque 503 failures. Extend the isolated OpenCode fixture through the real WorkspaceManager and HTTP routes to verify stale update/delete, create/update/delete request-ID conflicts and unknown missions. Observed native 503 before the fix and 409/404 after it; targeted route/plugin/reload tests and server typecheck pass.
Keep live task ancestry and replacement filtering while deduplicating candidate implementers by native session identity. Several completed implementation steps in one root can now receive their resolver without weakening ambiguity rejection between distinct actors. Add helper coverage and a full Pocock artifact-driven regression exercising delegation, resolver replacement and revision through the shared implementer. Validated 46 combined backend tests, server typecheck and the rebuilt Missions plugin.
Integrate dev into the Missions PR without rewriting its reviewed history. Retain mission CRUD routes, authenticated report admission and the 512 KiB bridge limit alongside inspected-window automation and plugin controls. Keep dev's canonical transport, clean builds and 2.0.18 client/plugin dependencies; align the local plugin contract check with the same SDK. Combine architecture guidance and preserve the technical runtime minimum of 2.0.7. Keep the isolated Missions fixture in the latest-runtime CI lane because its test-only ctx.tool.list driver is absent at that minimum; do not reintroduce legacy compatibility paths. Validation: server, UI and plugin-contract typechecks; full server/UI/plugin build; 84 backend/compatibility/packaging tests; 59 UI/persistence/browser tests; isolated OpenCode 2.0.18 Missions fixture and workflow YAML parsing. Merge resolutions have no conflict markers or diff-check errors relative to dev.
Clear nested-task membership and truncation when native deletion empties the resident child snapshot, while preserving keyed shells during ordinary invalidation and rereads. Cover the real batched native event with unchanged parent metadata, bounded counts and legacy fallback. Do not start the browser event singleton outside a window environment. Require actual module imports and compaction store tests to finish naturally in private subprocesses rather than using force-exit, while retaining normal browser auto-connect and reconnect behavior. Preserve original test errors and stacks when snapshot capture or page cleanup also fails. Share a narrow diagnostic/cleanup helper with durable tests, including falsy primary errors and cleanup failures after successful runs. No browser assertions, timings, clicks or skips are relaxed. Independent scoped reviews close UI-R1-1 and UI-R2-1. Causal prepatch failures, 25 renderer/copy/image tests, 141 naturally exiting store tests and focused lifecycle/diagnostic tests are green; final immutable full-browser and native Windows CI qualification remain separate gates. Investigation reports remain local and are not tracked.
Provide the minimal web-renderer window before importing the real ServerEvents singleton, after installing the existing network mock. The accepted lifecycle guard intentionally leaves Node imports passive; the reconnect test must explicitly supply its intended browser context. Preserve reconnect and hidden-cache assertions, require initial constructor auto-connect through the mocked transport, and restore the exact previous global descriptor while closing mock sources. No production networking behavior is changed. Confirmed the original natural-exit failure and the corrected test pass. The 71-file CI UI workload passes 480/480 with force-exit removed; lifecycle 2/2, compaction 11/11, neighboring stores 141/141 and UI typecheck pass. Independent delta review found no findings and verified cleanup for absent, data and accessor descriptors. Full-browser and remote CI qualification follow on this commit; historical failures remain recorded.
Install composer page observations before navigation and record synchronous bootstrap phases without moving imports, mocks, awaits or fixture publication. Capture bounded console, module/API status and navigation events so a future readiness failure can be inspected rather than reduced to an unexplained timeout. Use the accepted diagnostic and cleanup boundary for failure-only structural snapshots with a two-second reporting deadline. Preserve original error identity and stack when observation or cleanup fails, detach listeners and clear timers, and keep cleanup failures after successful assertions visible. Original 30-second readiness and all layout/draft assertions remain unchanged; native fixture and cache policy are untouched. Add five real Chromium contracts covering failed entry modules, bounded event rings and URL labels, destroyed and pending snapshot contexts, listener cleanup and primary-error preservation. Author and independent review each pass ten contracts and the actual 320px composer case with natural process exit; independent scope review reports zero findings. This repairs only the observation gap, not the unknown historical R3 cause. Final full-browser and fresh remote CI qualification follow on this commit.
Target the requested native scrollbar ratio relative to the actual press point rather than an estimated future thumb centre. This retains the selected grab offset at the top and bottom of the track without changing production timeline behavior, assertions, gesture timing, movement steps or settling delays. Independent review accepted the exact helper-only change with zero findings. Real Chromium endpoint and neutral-position contracts check actual mouse target arguments, and both existing native thumb scenarios pass naturally. Windows outcomes do not reproduce or explain the historical Linux CI failure, whose grab-offset versus final-input-delivery mechanism remains unknown; fresh full qualification and remote CI are still required.
Remove the mention picker's no-selection submission fallback, which dispatched drafts on Enter during empty or pending searches even when submit-on-Enter was disabled. Reserve Enter for an open picker and swallow Ctrl/Cmd submission or queue shortcuts instead of sending. Fence document-level Solid key delegation on both sides: the picker ignores modified Enter, and the composer never submits an already-consumed Enter whose selection handler closed the popup during dispatch. Preserve Tab completion, directory and arrow navigation, Shift+Enter path-only insertion, Escape draft preservation and explicit submission after dismissal. Clipboard production behavior and both desktop hosts use the unchanged shared paths. Add seven real composer browser regressions using held search responses, intercepted native prompt requests and trusted clipboard paste, plus three keyboard-controller regressions. The two pending-search browser regressions fail before the fix in both submission modes. Seven controller tests, twenty-eight composer/attachment/search browser tests, UI typecheck and production build pass. Publish an independent gatekeeper review of the exact head before merging. Admin merge without waiting for CI is explicitly requested. No live session or shared daemon is mutated; installed Tauri validation and reproduction of Ctrl+V alone causing a send are not claimed. Addresses #826 without closing the report before user confirmation.
…#825) ## Summary close #824. This collects the confirmed responsiveness and isolation fixes from the issue-824 mission, including independently reviewed corrections recovered from the previous general audit. **It does not claim that the original persistent Electron Linux Ôö£├ÂÔö£├æÔö£├Ñ Windows HTTP freeze is resolved.** - Aggregate native compaction text before the OpenCode/Solid reducer instead of only throttling the visible projection. Advance revision/read fences immediately, preserve exact terminal text and SDK snapshot boundaries, and discard obsolete buffers across lifecycle changes. - Retain keyed nested task-tool shells without losing authoritative membership changes. Keep the existing bounded structural scan and full-copy behavior. - Isolate SSE subscriber exceptions, distinguish decoding from dispatch errors, and prevent a subscriber-local abort/return/throw from invalidating the healthy shared native client. - Observe HTTP disconnects before admission/preflight, propagate cancellation to supported reads, and fence late continuations without replaying or interrupting already-admitted native mutations. - Use asynchronous scrypt for HTTP authentication, serialize password changes, and reject an old login verification that crosses a password change. Preserve hash format and constant-time comparison. - Yield cooperatively during structural-index reads and projection, without changing the response/digest protocol, ownership or snapshot semantics. - Add isolated regression fixtures, native qualification scripts, source-fingerprint evidence; independent reviews are published in the PR discussion. Synchronize the Git focus test with its asynchronous contract and correct the opt-in browser trace serialization defect introduced during this mission. ## Validation Ôö£├ÂÔö£├ºÔö£├é draft, not all green Product/tests/scripts/config/lock inputs were fingerprinted across 1,696 tracked and untracked executable paths. The complete frozen-source runs and their unsuccessful attempts are recorded separately; targeted retries are never substituted for a successful full suite. | Gate | Recorded result | | --- | --- | | Full server replay | 799 total / 793 pass / 6 skip / 0 fail, natural exit 0. Initial Windows cleanup `EPERM` retained; isolated Git and full replays pass, underlying OS cause unqualified. | | UI/server/Electron typechecks and UI/server/bundled-plugin builds | Pass. UI typecheck also passes after the final trace correction. | | Private native fixture | Pass on Windows/OpenCode 2.0.21, including compaction isolation and 2/8/32 MiB provider payload checks. No user daemon/database used. | | Stores | 141 assertions pass with force-exit. The 11-case compaction natural-exit attempt prints passes but times out; lifecycle cleanup is not qualified. | | First frozen full browser | 360 total / 356 pass / 3 fail / 1 skip, natural exit 1. Targeted 3/3 and neighboring 104/104 pass, not an all-green replacement. | | Previous full browser (before trace correction) | **360 total / 358 pass / 1 fail / 1 skip**, natural exit 1 in 20 min 10 s, zero source drift. The remaining failure is the opt-in trace's `ReferenceError: __name is not defined`; prior functional assertions, including focus, pass. | | Trace correction after that full gate | Exact tsx callback serialization reproduces the missing helper on a minimal Chromium page. Explicit self-contained JS is verified with no pageerror and all observation kinds retained after saturating the 200-entry buffer. **The fresh cycle-1 full browser now passes Git/trace, but remains red on a different case; see below.** | | Renderer A/B on final product postimage | 30 samples/variant, median main-thread fixture duration **324.57 Ôö£├ÂÔö£├æÔö£├Ñ 16.94 ms**. Not desktop FPS or universal responsiveness. | Compaction gates assert exact counts/content rather than flaky timing: 128 active fragments reduce to one interval emission, modest staggered delivery also coalesces, and never-loaded inactive sessions do not materialize the payload. Structural-index stress observations reduce event-loop gaps from 522Ôö£├ÂÔö£├ºÔö£Ôöñ755 ms to 13Ôö£├ÂÔö£├ºÔö£Ôöñ14 ms on the documented synthetic corpus, not total CPU or remote paint time. ## Remaining acceptance work / limitations - Cycle-1 corrected full browser: **360 total / 358 pass / 1 fail / 1 skip / 0 cancelled**, natural exit 1 in 21 minutes, zero drift on 1,696 inputs. Git/trace passes; the PageUp-named case loses its original error because its failure snapshot itself throws. Correct diagnostic error preservation; do not relabel this run green. - The earlier MCP bootstrap and HTML-cache timeouts remain causally unattributed, although both pass in the latest full run. A separate Monaco overlay detachment is retained as a distinct fixture failure. - Qualify Electron Linux Ôö£├ÂÔö£├æÔö£├Ñ backend Windows LAN/HTTP and OpenCode 2.0.19. Current real HTTP/1 checks are Chromium Windows Ôö£├ÂÔö£├æÔö£├Ñ Fastify Windows loopback; private native checks use 2.0.21. Neither establishes the reporter's exact cause. - Natural store lifecycle is still pending correction: the referenced reconnect timer of the import-started browser singleton retains Node without `window`; a constructor-only private counterfactual yields 11 passes and natural exit 0. This is causal diagnosis, not a corrected product gate. Coalescing remains limited by interleaved read/event boundaries, has no explicit byte/event cap, and is not a universal four-flushes-per-second/memory guarantee. - A single SQLite step remains synchronous. Shared libuv CPU resources, task clones/reloads and revision-stable activation catch-up remain documented limits. The user has now authorized scoped corrections, independent re-review until zero open findings, and then an administrative merge attempt after final green acceptance. No merge has occurred. Installation, deployment, shared-daemon restart and user-session cleanup remain unauthorized. ## Current gatekeeper / evidence **All reported actionable findings are closed; final acceptance is still pending.** Server/native review has zero findings. Scoped independent re-reviews close UI-R1-1 (ghost task membership), accept the browser-singleton lifecycle correction, and close UI-R2-1 (diagnostic cleanup masking). The eight reviewed paths are committed and pushed in `1795cce6aa40cf617d6113d2c11b2f36bae7d04c`; there are no investigation reports in the diff. The final immutable UI/stores/build/full-browser validation task is dispatched on that HEAD; CI run 36944418417 is in progress. No merge has occurred and no new general audit is being restarted. CI run 36937989224 at `f6a18d00` fails only the native pruning Windows job; build is skipped. Installed-plugin/native/installation checks pass before the `--ui` invocation exits during the Vite-loading boundary without an initial error stack. Cause is under investigation, not waived. - [Server/native gatekeeper review ├ö├ç├ zero findings](#825 (review)) - [UI gatekeeper review ├ö├ç├ UI-R1-1 open](#825 (review)) - [Scoped UI re-review ÔÇö UI-R1-1 closed, lifecycle accepted, UI-R2-1 open](#825 (review)) - [Natural store lifecycle qualification ÔÇö 141/141 pass](#825 (comment)) - [Confirmed store lifecycle attribution ÔÇö historical diagnosis](#825 (comment)) - [Cycle-1 terminal browser/CI results, source identities and limitations](#825 (comment)) At the user's request, investigation reports are not part of the repository diff. Commit `acac9be2` untracks the 21 reports while preserving their local working copies; executable inputs are unchanged by that commit. Future working reports remain local and untracked. Review verdicts/results are published in this description and discussion. These are transparent independent AI-agent reviews posted through the coordinator's PR-author account, not independent human GitHub approvals. Raw private logs remain on the validation host, not publicly downloadable uploads. Size signals retained without size-only refactoring: `http-server.ts` ~2,346 lines, `workspaces/manager.ts` ~1,240, `instances.ts` ~2,093, `opencode-data.ts` ~828, `task.tsx` ~569.
Stabilize the Windows pruning/UI CI harness by loading its unchanged UI dependencies before the long native/SQLite preamble. The late-import baseline reproduced locally under CI's Node 24.20.0 with native status 0xC0000374. This is a qualified import-order workaround, not attribution or repair of the underlying heap corruption; no assertions, dependencies, test skips or retries change. Retain actual child exit status/signal, stdout/stderr, durable stages and synthetic fixture logs through a parent runner. Require explicit completion as well as exit zero, and upload parent/fixture diagnostics on failure. Preserve the original UI scenario exception if diagnostic capture fails. Trigger artifact announcements from validation completion rather than bounded polling. Failed validation stays red in its own workflow. Run only trusted default-branch helper code, verify the originating workflow and current authorized PR head, use GitHub commit association when needed and update only bot-owned marker comments. Artifact names remain escaped display text, never executed contents. Fifteen focused tests pass under Node 24.20.0. Two coordinator-run and one independent full Windows native/UI scenarios complete naturally with all original assertions, restart persistence and presence cleanup. YAML and diff checks pass. The published independent gatekeeper review of this exact head has zero findings. Admin merge is explicitly requested without waiting for CI. GitHub workflow_run delivery needs post-merge confirmation; no universal CI reliability, underlying heap repair, Linux/macOS native rerun, installed app replacement or shared daemon restart is claimed.
## Increment over existing execute display Execute already renders as a tool card through the generic renderer. This PR adds a specialized presentation of its script and native nested-call metadata (names, inputs, statuses), plus truncation information. It reuses the existing aggregate output and image surfaces. It does not introduce Code Mode execution or mission orchestration (#673). ## Purpose First PR in the V2 product integration series. Present execute scripts, nested tool calls and progress, failure and native truncation information. Preserve shared native output/image rendering and copying. ## Contract and implementation Verified upstream Code Mode contracts at tags 2.0.7 and 2.0.18: code input, metadata.toolCalls (tool/status/input), metadata.error. No API calls or runtime minimum changes. Small dedicated parser and renderer, scoped CSS, nine locales. Subsequent PRs will stack on this branch. ## Local validation - UI typecheck passed. - Four isolated Chromium scenarios passed: native events, history reload, nested errors, images, collapse and narrow layout. - Rendered capture inspected at 380px. - git diff --check passed. ## Gatekeeper Independent review pending; findings will be fixed and re-reviewed until zero. User requested all PRs remain unmerged. Do not merge. Size note: existing tool-call.css is above the source warning threshold; changed only by adding the scoped import.
## Behavior Dedicated websearch source cards with safe links, publication metadata, literal snippets and raw-output fallback. Recognized native provider consent receives a localized heading and stacked options through the existing Form validation/reply path. Ten locales. ## Stack Depends on #789 (zero-finding gatekeeper at aaee7d5). This PR contains only step 2. All eight PRs are to remain unmerged at the user's request. ## Contracts and validation Tagged native 2.0.7 and 2.0.18 tool/plugin/websearch.ts contracts verified. No new API or minimum-version dependency. UI typecheck passed; five focused parser, shape and browser tests passed, including hidden Forms regression. Narrow rendered capture inspected. Raw results retain copy/search via shared renderer. Existing tool-call.css exceeds source-size guidance; change is one import. Independent gatekeeper review pending; findings will be corrected and re-reviewed until zero. Do not merge.
## Behavior Attach/remove skills in the composer using the current session directory's native catalog. IDs are sent through prompt.skills; OpenCode expands the instructions. Historical and optimistic messages show skill labels. Queued edits restore removable skill attachments without resurrecting removals. ## Lifecycle Visible demand only, skill/config native updates, reconnect refresh, coalesced trailing reads and view/session response fencing. Ten locales. Native startup registers plugins progressively, covered by fixture and catalog updates. ## Validation UI typecheck passed; 53 session-action regressions passed; three focused skill tests passed; Chromium selection/deduplication/location/stale/coalesced/inactive scenario passed and narrow capture inspected. Isolated native fixture passed on 2.0.7 and 2.0.18 (synthetic provider, private home/database/process; no shared daemon). No runtime-minimum change. ## Stack and gatekeeper Depends on #790, whose independent gatekeeper has zero findings. Independent review of this PR pending; corrections/re-reviews continue until zero. User requested no merges. Size notes: prompt-input.tsx (~1120), session-actions.ts (~1000), session-view.tsx (~720), session-actions.test.ts (~1040), and locale messaging files exceed guidance; focused additions only.
## Summary - add a durable, project-local Missions control plane on top of native OpenCode V2 root sessions - expose live Mission Control navigation, task state, actor state, reports, and evidence in the right panel - provide bounded Pocock bug-fixing and Wayfinder exploration playbooks without introducing a generic workflow DSL - keep Developer Mode automation separate from mission orchestration ## Architecture Missions uses native OpenCode V2 primitives rather than a parallel runtime: - root sessions are mission actors - `queue` and `steer` are the durable actor inbox - session metadata carries mission, task, role, and coordinator correlation - plugin hooks inject role context - project-local plugin storage persists an append-only mission journal and materialized map - topology mutations are coordinator-only and remain scoped to one project The agent surface is deliberately limited to `mission.inspect`, `mission.delegate`, and `mission.report`. The CodeNomad broker exposes only the typed `codenomad.missions.snapshot` RPC; change events are invalidations that trigger authoritative reconciliation. ## User-visible behavior Mission Control shows the active mission's status, frontier, tasks, root actors, correlated reports, and expandable evidence. It updates live, survives reconnects, preserves the last durable map through transient failures, and can navigate to an actor session without becoming a second workflow executor. All new UI strings are available in the existing 10 locales. The panel uses the shared token, utility, and square-corner window conventions. ## Playbooks and safety bounds - Pocock remains evidence-driven and dynamically sequences implementation, independent reviews, resolution, and fresh validation. - Wayfinder preserves destination, map, frontier, claims, and fog-of-war while allowing bounded parallel research. - Admission and resume paths are idempotent. - Limits: 8 actors, 96 tasks, 2,000 events, and 20 missions per project. - A green completion requires every task to be completed. ## Validation - [x] Rebased directly on `dev` after #647 - [x] OpenCode plugin contract typecheck - [x] Server typecheck - [x] UI typecheck - [x] Mission server tests: 18 passing - [x] Mission UI/i18n tests: 4 passing - [x] Full server, UI, Electron, and Tauri suites/builds completed during implementation - [x] Private runtime spike verified activation, typed RPC, restart persistence, root-session delegation, queue/resume, correlation, idempotence, invalidations, broker allowlisting, and checkout/worktree storage sharing - [x] Pocock and Wayfinder runtime demonstrations completed - [x] Windows Tauri Mission Control validated live from active mission through completed status, including actor navigation and expandable evidence ## Known runtime note A daemon that was already running before the project-local plugin existed may fail to hot-add that plugin on Windows. Fresh daemon activation is verified and works correctly; CodeNomad does not restart or take ownership of a foreign/shared daemon. ## Tester feedback phase This PR intentionally remains in draft while the session mesh receives broader real-world use. Please exercise: - custom missions with both idle and busy actor sessions - Pocock implementation, independent review, resolution, and fresh validation loops - Wayfinder exploration with parallel frontier tasks and unresolved fog - restart/reconnect recovery before and after delegation and reporting - actor navigation and evidence expansion from Mission Control - project, checkout, and worktree boundaries, including expected authorization failures Useful reports include the desktop host, workflow/template, exact point of friction, expected versus observed behavior, and whether the durable map recovered after reopening. Do not include secrets or private prompt contents. The unrelated automation-registry CI fix is tracked separately in #675 and is not part of this branch. After that fix lands on `dev`, this branch can be rebased and its validation rerun before any decision to mark it ready.
## Behavior Global/Project websearch choice, inherited/default, disabled and automatic/provider selection. Display effective native configuration. Optional global API keys use native integration/credential endpoints; environment credentials remain read-only. Scoped failures reconcile without mutation replay, and late results are fenced. ## Contract adjustment OpenChamber's /api/config/websearch is its backend route. OpenCode 2.0.18 has no equivalent native config write API. Reuse CodeNomad's authorized plugin-control configuration targets, JSONC conflict-safe edits, WSL filesystem adapter and connection/deletion fences. Preserve unrelated fields and comments; use native watching, never implicit location.reload. ## Validation Server/UI typechecks pass. 51 focused server/config regression tests pass; four real-WSL cases skipped. Real Chromium fixture passes scoped writes, failure reconciliation, API-key clearing and late mutation fencing; narrow capture inspected. Isolated native fixtures pass on 2.0.7 and 2.0.18 (global watching, project document persistence/reset, foreign-directory rejection). Project discovery is disabled in native fixtures to exclude user ancestor config; deterministic server tests cover precedence. No shared daemon or personal data used. ## Stack/review Depends on #791, zero findings at ea3b4ef. Independent gatekeeper pending; fix/re-review until zero. User requires all PRs remain unmerged. Size notes: existing http-server.ts (~2300), api-types.ts (~1200), plugin-controls.ts (~810), api-client.ts (~1000) and locale settings files exceed guidance; focused changes only. ## User-feedback correction Clarify which search provider agents use, automatic saves, the default across projects and the current-project override. Move API keys into a separate collapsed section explaining that credentials are shared service-wide and saving a key does not change the selected provider. Environment credentials are explicitly read-only. Updated in all ten locales; narrow Chromium lifecycle/failure test and UI typecheck pass. Alpha in fixture captures is synthetic test data.
…829) ## Summary - Answer native Forms and permissions in a persistent composer-adjacent dock with queue navigation and source-session labels. - Target requests from badges and inline tools; reveal off-window source messages through bounded history navigation, closing file previews and exposing hidden source tools. - Render durable native question answers in the transcript and preserve partial request/composer drafts. - Replace the former permission modal and retain native global Form routing and full permission-diff review. ## Gatekeeper - Pass 1: two actionable P2 findings. - Corrected both in fb7ed77 with regression tests reproducing failures before the fixes. - Independent pass 2 at fb7ed77: zero actionable findings. ## Validation - UI TypeScript and production build passed after rebase. - 30 focused browser and 17 native-store/unit regressions passed after rebase. - All six interruption-dock tests and TypeScript passed after corrections. - Independent final review: nine browser tests, 20 unit/store tests and TypeScript passed. - Final GitHub CI in progress. See dev-docs/NATIVE_INTERRUPTION_UX.md for ownership and validation details.
## Summary Qualify **OpenCode 2.0.22**, align server/UI client and plugin pins, and recommend this release. Keep the demonstrated **2.0.7** global minimum and **2.0.20** Codex Usage feature-local requirement. Block the new native `parentID` create variant in the workspace proxy: upstream ignores the supplied location and inherits the parent's directory. Require inspectable JSON objects to close opaque-body bypasses. Root creation and the existing authorized fork route remain available. Started at `dev@0983db3` (#828 Windows test harness), then integrated `dev@97c361c` (#789 Code Mode presentation). Conversation remains attached to `D:\CodeNomad`; all work and tests use explicit separate paths and synthetic data. ## Upstream audit: 2.0.21 → 2.0.22 - Authenticated native OpenAPI retains **116 paths**, with **11 schema differences**: session creation gains optional `parentID`, parent-not-found response/description; provider settings gain optional `headerTimeout` and `chunkTimeout=false`; configured model capability overrides become partial. No new proxy route or consumed mandatory API. - Published declarations: **4/30 client, 2/60 plugin, 3/36 protocol, 4/102 schema** files change. Plugin session domains expose `remove` and `compact`; CodeNomad does not add calls to them. Identifier namespace export is additive. - An isolated native fixture proves parent creation inherits the parent location despite a different supplied directory. Mock and production-proxy fixtures reject owned/foreign parents; malformed values and opaque content types are covered before any native request. Owned root creation stays available. - Runtime changes include HTTP header/chunk/whole-response timeout handling and bounded timeout retries, provider cache/error/tool-history fixes, model capability defaults, and legacy MCP shutdown cleanup. - Lock changes are limited to six `@opencode` packages and two workspace entries. Integrity/dependency metadata matches independently installed published packages; clean `npm ci --ignore-scripts` passes. Optional OpenTUI peers are not installed by CodeNomad. ## Isolated local qualification **Windows / Node 24.20.0**, isolated profiles, databases, services and synthetic providers/credentials. No shared-daemon or personal-history mutations. - Previous **2.0.21 dependencies + runtime 2.0.22**: native pruning/history/proxy acceptance passes. - New **2.0.22 dependencies + runtimes 2.0.7 and 2.0.22**: seven suites pass (automation, pruning/history/navigation, per-send environment, inclusive forks, idle/busy side questions, blank-session cleanup, Git-degraded recovery), plus explicit native proxy suites. - Native/UI pruning acceptance passes through the committed parent runner, with completion and actual child exit verified. This uses #828's early dependency-import workaround, not the old late-import order. No claim that underlying Windows heap corruption is repaired. - Current compaction-isolation acceptance passes: session B progresses while session A's provider response is held; bounded outline reads retain daemon heartbeats. Fixture runtime selection is extended to include 2.0.22; its assertions are unchanged. This supplemental fixture was not qualified on 2.0.7 (explicit runtime selector rejects it). - Native Codex Usage passes on 2.0.22 with synthetic OAuth/key credentials and mocked quota HTTP; not a live-account/WSL test. - Native migrations **2.0.3 → 2.0.22** and **beta-19271 → 2.0.22** preserve full history/forks/inbox/provider selection. - Packed standalone pruning plugin installed outside the repository passes native acceptance. - Native npm upgrade **2.0.15 → 2.0.22** passes; authenticated daemon remains **2.0.15 / PID 43876** before and after. - Full server run: **794 passed / 6 skipped / 0 failed**. Final guard revision separately passes **68 focused server tests** and native proxy suites on minimum/current. Aggregate runs use `--test-force-exit`. - Targeted client/store/reducer/usage UI: **63/63** with `--conditions=browser`, `--test-force-exit`, bounded timeout. Initial broad UI run used the wrong Node conditions and hung at `prioritized-read.test.ts`; only its owned processes were stopped. That incomplete run is **not green**. The same prioritized-read tests pass under the browser condition used by CI. No production fix is inferred from this launch correction. - **41 browser scenarios** pass: setup/install, auth recovery, tool images, rendered Codex Usage and compaction responsiveness. Browser tests do not use forced exit. - Server/UI/Electron typechecks and production server/UI/plugin builds pass. Revalidation after #789 integration and independent gatekeeper are reported separately below. Local results do not certify all real providers, Linux/macOS/WSL, or installed Electron/Tauri hosts. Historical Windows import and Git cleanup failures remain limitations, not repaired by this upgrade. Remote CI is not continuously monitored and no global CI-green claim is made. Size note: existing `packages/server/src/server/http-server.ts` is ~2,359 lines; `packages/server/src/server/__tests__/instance-proxy.test.ts` is ~1,139 lines. Changes are narrowly scoped; no unrelated size-driven refactor. ## Independent gatekeeper Review launched on exact head `0a7615476034eabbff54967aacc8a93ab0e6ab12` against `dev@97c361c`; verdict will be published before any admin merge. Findings will be corrected and reviewed again until zero actionable findings.
Revert merge c118478 relative to its first parent after the user confirmed the merge was requested in the wrong conversation. Remove the published Missions plugin, control routes, UI, playbooks and packaging references; do not rewrite dev history or touch durable-refactor work in the separate missions-v2 checkout. Preserve subsequent PRs #792, #829 and #830. Remove only #829's now-invalid Mission reader import, dismissal hook and dedicated reader scenario, retaining the native questions/permissions dock, file-preview navigation and its other tests. Keep the 2.0.22 package pin and parent-session creation fence. Validation: revert applied without conflicts; all 139 original merge paths reversed; later-only paths retained except the three minimal interruption-dock integration adaptations. Server and UI TypeScript checks and 18 automation/plugin lifecycle/desktop resource tests pass using existing local dependencies. Staged diff checks are clean. Full hosted CI, browser suites and native 2.0.22 qualification were not rerun for this immediate user-authorized admin revert.
## Outcome Reverts the accidentally authorized merge of #673 (`c11847880588c287a4a4dfbc3881f35f92a9415d`) relative to its first parent. The user explicitly requested this revert and immediate admin merge. - Removes the published Missions plugin, routes, UI, playbooks and packaging references. - Preserves later PRs #792 (web search settings), #829 (questions/permissions dock) and #830 (OpenCode 2.0.22 and parent-session fence). - Removes only #829's dependency on the now-removed Mission reader, including its dedicated fixture scenario; retains the dock and other navigation/answer tests. - Does not rewrite history, delete native mission/session data, restart the app/daemon, or touch the separate local durable-refactor work. ## Validation - Git revert applied without conflicts; the original merge affected 139 paths and all 139 were reversed. Three later interruption-dock files require the minimal removed-reader adaptation above. - Server and UI `tsc --noEmit` pass using existing local dependencies (no installation). This is not native 2.0.22 qualification. - 18 automation/plugin lifecycle/desktop resource tests passed; staged diff whitespace check passed. - Full hosted CI/browser/native suites were not rerun for this immediate admin revert. ## File-size notes Existing oversized modified sources remain: `packages/server/src/server/http-server.ts` (~2362 lines), `packages/server/src/api-types.ts` (~692), `packages/server/src/index.ts` (~694), `packages/server/src/opencode/automation-plugin.ts` (~583), `packages/ui/src/components/session/session-view.tsx` (~710), `packages/ui/src/lib/api-client.ts` (~636). No size-only refactor included.
…ion (#793) Expose the approved active-account dropdown with persistent credential-keyed drafts and always-visible add/rename/remove actions. Enrich only native fallback labels with a sanitized Codex login while keeping all credential values server-side. Persist opt-in automatic selection for supported OpenAI OAuth accounts and admit one fresh-quota-verified native activation before the next prompt/custom command, with local manual/policy fences, ownership and deletion admission, no model changes, and no prompt or mutation replay. Preserve dev's Missions revert and document service-wide selection and external-client compare-and-set limitations. Validated both package typechecks, the UI build, 812 server tests, 865 CI-selected UI unit tests, isolated native 2.0.22 synthetic-account/YAML fixtures, and focused Chromium/native bridge regressions. Final admin merge explicitly requested by the user; platform/runtime/native checks are green while the general tests job is still in progress.
Generate positive, nonzero and canonical DER certificate serial numbers for both the local CA and server. node-forge encodes the supplied hex bytes as a signed ASN.1 INTEGER, so a random high bit previously produced a negative serial rejected by Go/Caddy. Normalize leading zero octets, add sign padding only where needed and handle the all-zero draw while keeping random 128-bit serial draws within the RFC 5280 size bound. Renew existing negative/zero generated server certificates at HTTPS initialization while preserving a valid CA and existing client trust. If the generated CA itself must be replaced, also reissue the leaf and warn that clients must import the replacement CA. Keep valid generated credentials unchanged and leave explicitly supplied certificates untouched. Document startup repair and reverse-proxy trust implications. Seventeen TLS tests pass on Node 24.20.0, including deterministic edge draws, actual DER encoding, signature/SAN checks, invalid serial migration, verified loopback HTTPS requests, CA replacement, reuse and provided/disabled behavior. The full server suite passes with 825 passed, six existing skips and zero failures; server typecheck and diff checks pass. No installed app, shared daemon or user certificates are changed. The reporter's physical macOS/Caddy setup was not directly tested. Fixes #832.
## Summary - Ignore repeated browser transport statuses and identical instance/status/native-generation snapshots instead of clearing validated provider quotas and restarting reads. - Keep genuine reconnects, changed native generations (including a missed disconnect), account/configuration changes, native `server.connected`, source changes and failed-read revocation unchanged. - Add real Solid/browser dispatcher regressions covering quota DOM stability, in-flight refreshes, compaction independence and stale-response fencing. ## Scope and evidence The regression test fails before the fix: 40 duplicate connected notifications produce 40 additional quota reads and replace the quota display with Loading. After the fix, the same bar DOM and request cycle remain intact. Quotas still use the native credential API and provider HTTP endpoint; no log-based or host-credential fallback is added. This fixes a demonstrated flicker trigger, not every live disappearance. Initial passive captures did not reproduce a disconnect. A later capture did confirm a real relay failure: `Instance event relay routing timed out` at native generation 52, followed by connecting/connected at generation 53, affecting both opened projects. This PR deliberately continues to revoke quotas on that real boundary; it does **not** fix the relay timeout itself. The installed desktop application and shared daemon are unchanged. ## Validation - 17 UI state/component/browser tests passed. - 12 native usage/route tests passed. - UI typecheck and production build passed. - Before-fix regression failure confirmed; rendered fixture capture inspected. Independent Gatekeeper review will be published against the exact PR head before administrator merge.
## Summary - Keep pending questions in the composer-adjacent dock and native answers in the transcript after completion; remove redundant navigation links. - Separate collapse from bounded request navigation and hide navigation for one request. Preserve the selected draft across incoming permissions and session changes. - Add accented window chrome, fixed action footers, readable dark receipts and visible scrolling. Preserve permission diff-review gates and disable form editing during submission. ## Validation - UI TypeScript and production build passed. - 16 Form/settlement/diff-review unit-store tests passed. - 10 dock browser tests, 1 cross-session selection test, 5 permission/Form browser regressions, 21 history-navigation tests and 1 session-search regression passed. - Rendered captures inspected at 393 and 1100 CSS pixels in light/dark; mobile permission actions validated. ## Review Independent UX and interaction reviews informed the implementation. Autonomous final gatekeeper review in progress before requested admin merge. ## Maintenance note Existing large components touched: message-block.tsx (~1965 lines), message-section.tsx (~1561), tool-call.tsx (~991).
## Summary Follow-up to merged #835: fix the demonstrated dependency behind real `Instance event relay routing timed out` disconnects, not duplicate connection notifications. Existing diagnostics captured relay ownership blocked in `getWorktrees -> WorktreeInventory -> POST /api/worktree/refresh`, including a refresh pending beyond 150 seconds and a separate ~220-second completed call. That exceeds the unchanged 60-second relay job deadline, so the shared relay reconnects and Usage correctly clears for all projects. Event authorization now uses a separate **registered-only** native worktree inventory and never starts or joins native strategy discovery. Native project/checkout checks, physical Git membership, clone exclusion, configured roots, nested-folder and WSL projection remain in the shared catalogue implementation. Native/local invalidation and workspace disposal fence both inventories and their distinct directory-cache namespaces. Ordinary request authorization and explicit worktree discovery retain refresh and read-your-writes behavior. Full-location checks receive the connection attempt's abort signal. No timeout increase, swallowed reconnect, stale authorization fallback or quota-specific workaround. FIFO lanes, ownership retries, generation/workspace fences and retained-work budgets are unchanged. ## Validation - Baseline-red production-manager + relay reproduction: hold discovery unresolved and require the linked-worktree event to route before releasing it. - All **248 workspace tests pass**, including event order/reconnect, ownership, no-Git, WSL, configured Git roots and inventory invalidation. - Server TypeScript check passes. - Isolated OpenCode **2.0.22** location/worktree/event fixture passes, including real pre-refresh native registration and ordered real session events during a held fixture-manager discovery request. - Isolated no-Git native prompt/recovery fixture passes. - `git diff --check` passes. ## Scope / limitations The native refresh's internal delay is not claimed fixed; the relay no longer depends on that unnecessary discovery operation. Actual transport failures and other stuck native reads still trigger bounded reconnect/reconciliation. Compaction and window-resize jank are not established causes or fixed by this PR. The installed application, shared daemon, user settings and independent #824 worktree are untouched. This conversation remains attached to `D:\CodeNomad`. Existing oversized source touched: `packages/server/src/workspaces/manager.ts`, approximately 1,260 lines. No unrelated size-only refactor. Independent Gatekeeper review will be published against the exact PR head, with findings resolved and fresh passes until zero findings before the requested administrator merge.
#838) ## Summary - Persist all permission decisions: allowed once, always allowed and rejected, with request context and known reasons. Distinguish CodeNomad, automatic Yolo and native settlements. - Keep receipts visible alongside transcript messages even with hidden tools; provide paginated source-less session receipts. Ownership-checked bounded reads, atomic profile storage, deletion cleanup and stale-read fencing. - Enrich completed native question receipts with selected-option descriptions, verbatim custom answers and a disclosure for other choices. Translate labels in all ten locales. ## Validation - Locked dependencies installed; server and UI TypeScript checks pass; production UI build passes. - 126 targeted server regressions during implementation, then 26 receipt/replier/service checks against the pinned client passed. - 20 receipt/dock browser tests and 21 history navigation tests pass; 5 question decoding/copy tests pass. - Rendered captures inspected at 393/1100px in light/dark, including long text and pagination. ## Persistence boundaries Native permission events are ephemeral: past lost decisions cannot be reconstructed. Receipts are CodeNomad annotations outside native search/copy/export. Storage namespaces follow execution host, native root and authenticated channel; credential rotation starts a new namespace. Bounded text excludes metadata/diffs. ## Review Autonomous independent gatekeeper review will be published and repeated until zero findings before the user-requested admin merge. ## Maintenance Existing oversized files touched: server/http-server.ts (~2415), server/api-types.ts (~717), server/index.ts (~707), ui/message-section.tsx (~1566), ui/lib/api-client.ts (~650).
## Summary - Continue sparse history scans until a bounded result page is filled, publishing matches progressively across sessions. - Remove the automatic count traversal. Show page-local results and messages scanned directly from search responses, with no scan when opening an empty search. - Project text-only content in SQLite, reduce bounded RPC round trips, and share identical location checks only inside a request. ## Validation - UI/server typechecks and targeted server/store tests passed. - Chromium regression covers progressive results, pagination, workspace scope, technical toggle, empty results and absence of statistics requests. - Isolated native OpenCode 2.0.22 fixture passed, including all 242 workspace matches across two sessions and pruning/ownership regressions. - Synthetic benchmark: text search materializes 9.6 KB instead of 145 MB; CPU gain is modest because SQLite still parses stored JSON. See dev-docs/SESSION_HISTORY_QUERIES.md. ## Review Independent gatekeeper review and post-rebase validation in progress; findings will be addressed before administrator merge.
… Locations (#840) Recover pending Forms and Permissions through a fixed presence-owned RPC in the existing bundled plugin, without warming historical native Locations. Validate established execution-host origin, complete coverage, directory/Git ownership, WSL aliases and every placement before admitting capability. Keep generic RPC forwarding closed and preserve non-authoritative failures. Observe native compaction before event ownership routing and defer expensive legacy discovery before inventory reads and at forwarding. Preserve concurrent holds, bounded missed-end probes, exact settlement reconciliation grants, per-kind mutation fences, global/idle Forms and settled-request tombstones. Never replay ambiguous mutations. Share presence observations, not registrations or execution authority. Integrate current dev receipt and event-ownership changes. Reassert the native connection after permission receipt preparation and before granting settlement reconciliation or dispatching mutations. Reject overflowing raw JSON numbers, including unknown metadata, without altering native numeric codec strings. Use eight-directory UI batches with the unchanged request deadline and URL budget rather than weakening ownership checks or extending timeouts. Add scoped broker, reader, presence, proxy, compaction and UI lifecycle regressions plus an opt-in isolated native reader fixture. Independent Gatekeeper reviews are published on the PR; R1's numeric overflow finding is fixed and rechecked on the final head before merge. The private reader is qualified for native 2.0.22 / Effect rc.112 only. The global minimum and already-recommended 2.0.22 remain unchanged. Unsupported runtimes retain guarded legacy recovery. This mitigates CodeNomad's load amplification, not the upstream Bus issue or previously retained Locations; installed-application freeze resolution, deployment and daemon restart are not claimed. Preserve bootstrap-warming and bounded-scan limitations.
## Summary Prepare stable CodeNomad 0.20.1 on top of `dev@8ce70ec`, the source of the latest requested prerelease, before publishing through `dev -> main`. - Align root, server, UI, Electron and Tauri npm versions and workspace lock metadata to `0.20.1`. - Align the native Tauri configuration, Cargo manifest and application lock entry. - Require CodeNomad server `0.20.1` in the remote UI manifest, so the updated Files, provider settings and pending-request surfaces use the matching backend routes. - Leave the dependency graph unchanged. This preparation PR targets `dev`; only the subsequent push to `main` publishes the stable release. ## Validation - Clean locked dependency installation in an isolated release worktree. - Version consistency assertions across npm/lock metadata, Cargo and Tauri; dependency graph comparison against the parent commit. - `npm run sync:version --workspace @codenomad/tauri-app` confirms all native versions are aligned. - UI, server and Electron typechecks pass. - Full server production build, including the UI and bundled plugins, passes. - Remote UI selection and dev-release channel tests pass (3 tests). - `git diff --check` passes. Native installers and the cross-platform release matrix have not been rebuilt locally. Existing local work and suspended worktrees are untouched. CI is not being waited on or monitored as requested.
shantur
approved these changes
Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Highlights
@, view structured search results and provider-consent requests, and configure global or project web-search defaults in Preferences.Files and conversation workflow
Providers, skills and native tools
@skill selection attaches removable badges and sends explicit native skill IDs with the prompt.Mobile, desktop and reliability
Runtime and upgrading
Full Changelog: v0.20.0...v0.20.1