Skip to content

chore: integrate upstream orchestration V2 into J5 - #178

Merged
Jacksondr5 merged 928 commits into
j5/mainfrom
j5/upstream-sync-20260911
Sep 23, 2026
Merged

Jacksondr5 merged 928 commits into
j5/mainfrom
j5/upstream-sync-20260911

Conversation

@Jacksondr5

@Jacksondr5 Jacksondr5 commented Sep 17, 2026 •

Copy link
Copy Markdown
Owner

What Changed

Integrates the frozen upstream orchestration V2 target 62aef8587c0263bed5ae2b26c38d6d138a0676f6 from upstream/t3code/codex-turn-mapping, carrying J5's Squadron ownership, A2A messaging, reversible lifecycle, remote routing and product identity through the server and client changes.

  • Reconciles known historical migration sequences with the upstream V2 schema while preserving J5's migration lane.
  • Adopts the reviewed upstream tool subset, routes attachments through J5 messaging, registers forks through one shared server boundary, and replaces archive_agent with the adapted organize tool.
  • Preserves Squadron creation/scope, human archive preflight, artifacts and environment-qualified identities across the adopted web, desktop and mobile changes.
  • Prevents environment balancing from moving a selected Squadron draft. Fixes command-palette identity collisions when two environments have the same raw thread ID.
  • Adds Connect → Providers → Projects → Squadrons onboarding. Each selected folder gets one Squadron choice for its imported conversations. People can create additional Squadrons after setup. Retries preserve created identities, established homes stay unchanged, and the landing draft carries the selected Squadron.

Why

This integration is available for maintainer testing. The upstream target is deliberately pinned; this is not a merge of today's upstream main.

Base status: refreshed against J5 5c163724fe (September 23), including the crew/persona stack and artifact corrections. Resolves Bryant's review: crews retain the internal archive engine, spawn provenance and shared runtime services; organize enforces the crew-seat archive rule; Fleet reuses the exported runtime-status helper. The retired archive_agent and t3_thread_wait tools stay absent. Persona settings, crew gates, and mobile outbox behavior are preserved. Carries PR246’s split CI jobs with the vendored-gitlink cleanup retained in every checkout job.

Validation

  • Focused migration, orchestration/provider, A2A, MCP registration and client suites passed during the integration milestones. Known-history upgrades were checked on isolated database copies, including rollback and schema comparisons.

  • Server, web, desktop and mobile scoped typechecks passed; the web production build passed. Scope-specific lint/format checks passed with existing upstream warnings.

  • Latest ownership revision: 145 tests passed. Latest palette correction: 32 tests passed, independently repeated by Fable. Fable reviewed each milestone and approved the final candidate for human testing.

  • Real Chromium smoke with two isolated servers: Squadron filtering, new threads and live Codex replies, Files/Artifacts panels, archive/unarchive, owner-only mutation with colliding raw thread IDs, balancing refusal, remote fork registration, and connection removal/re-pairing. The corrected palette selected each same-ID thread on its proper environment without duplicate-key warnings.

  • Onboarding update 42a4b9115: 168 focused web tests and 18 backend/client seam tests passed in the final runs; server/web typechecks and scoped format/lint passed (four existing wizard warnings). Separate Fable backend and UI reviews approved the final revision.

  • Fresh local Chromium onboarding: Back through all stages preserves choices with no writes before final import; two folders/four conversations received the selected homes. Reimport was idempotent, kept-home results remained visible, injected assignment failure recovered via Retry, and a committed-but-lost create response recovered through explicit Existing selection without a duplicate create. The landing draft completed a live Codex turn. Desktop and narrow layouts were checked after correcting focus-induced clipping.

  • Corrected the previous CI TypeScript failure in a fork-owned Codex schema test (dee34dfeb): one as const preserves fixture literals. Six focused tests and that package’s typecheck pass; no runtime/schema change.

  • Final setup revision e8bfdbaff: one Squadron per selected folder, with the maintainer’s exact explanatory copy. Independent Fable review verified the single-Squadron implementation; 14 focused onboarding tests passed. Fresh desktop/narrow browser checks confirmed one input per folder, no additional-row controls, unchanged counts on Existing reimport, correct landing home, and no page errors.

  • September 20 main refresh: focused server, migration, provider, MCP and client suites pass, with separate Fable backend/UI reviews. Scoped server/web/mobile/client-runtime/shared typechecks pass, and the web production build passes. The independent reviewer ran 337 client tests and 36 backend tests; these overlap the builder/coordinator runs.

  • A current-main database snapshot upgraded through the production initializer and reopened successfully: 51 active upstream migration records, all 59 original records retained in the compatibility archive, 13 J5 migration records, SQLite integrity OK and no foreign-key violations. The live install was never written.

  • Corrected SSH runner diagnostic fixtures to use the retained J5 executable identity; all 19 runner-process tests pass. No production launcher change.

  • Refreshed live Chromium smoke: created a Squadron in a disposable folder, selected Scout, completed a real Codex turn with its read-only persona/model, observed the single missing-handoff reminder and successful ContextBrief artifact, opened that artifact, pinned the thread, archived/restored it with the same identity/home, and loaded the Agents settings/usage/library panel. No authenticated-pass page or console errors. This pass used one local environment; native mobile, cross-environment persona routing, machine delivery and @mention delegation were not exercised live.

  • September 23 crew/persona refresh: focused server crew launch, archive, cascade, proposal, lifecycle, MCP registration, persona and migration tests pass; server/web/mobile/client-runtime typechecks pass. Independent Fable client review ran 430 tests and approved the integration. Independent Fable backend review ran 153 tests (one skipped) and approved the resolved merge after correcting obsolete archive-tool guidance. Latest CI status is separate.

  • A fresh current-main database snapshot (17 J5 migrations) passed the production initializer twice, integrity and foreign-key checks. All 22 preexisting J5 tables were compared by full-row hashes and remained unchanged. All 59 upstream history rows were retained in the compatibility archive; the active upstream history is 51 by design.

  • This refresh has no new browser/native/provider smoke pass; earlier live evidence above applies to its stated revisions.

This is smoke-test evidence, not full acceptance. Native desktop/mobile execution, relay/DPoP refresh, and integrated live attachment delivery, open-Exchange archive notices, deletion, Stop races and merge-back remain untested in this pass. CI/full-suite status is separate.

UI Changes

The browser pass exercised the Squadron scope/picker, ownership refusal controls, panel surfaces and archive view. The built-in preview failed before app load, so the pass used local Chromium. The earlier merge-smoke screenshots are no longer retained. New onboarding before/after evidence is retained locally, including desktop/narrow Squadrons screens and retry/kept results; GitHub images still need attaching because no authenticated asset-upload capability is available in this session. No screenshots or scratch artifacts are committed.

Run locally

Use the repository's pinned Node/package-manager toolchain. From an existing clone:

git fetch origin j5/upstream-sync-20260911
git worktree add ../j5code-upstream-test origin/j5/upstream-sync-20260911
cd ../j5code-upstream-test
vp i
vp run dev --home-dir "$PWD/.j5code"

The explicit home keeps test state in the new worktree. Open the pairing URL printed by the dev runner. On a fresh home, follow the four-stage wizard and assign each selected import folder a Squadron, or skip import and create a Squadron for a disposable folder. Reopen /welcome to test setup on an existing home.

Suggested manual checks: Squadron switching and creation; send/Stop/follow-up; panels; archive and restore with an open question; fork and merge-back; two-environment creation/routing with balancing enabled. The previous test servers and sharing setup are not needed.

Follow-ups: #133–#137 (deferred tools and HTTP integration), #138 (Linux capture identity), #139 (additional balancing transition coverage), #154 (cross-environment draft-chip selection), #179 (archive racing a thread’s first home registration, shared with join_squadron).

Implementation: GPT-6 in the Codex harness; onboarding and main-refresh UI by Fable agents in the Claude Agent harness. Independent milestone reviews: a separate Fable reviewer.

juliusmarminge and others added 30 commits September 11, 2026 14:38
- Port thread pinning (pingdotgg#5312) into the orchestration-v2 command pipeline:
  thread.pin/unpin commands, thread.pinned/unpinned events, pinnedAt on the
  v2 thread state and projected shells, promotion semantics (pin clears
  settle/snooze, settle clears pin) matching the v1 decider, and client
  pin/unpin operations in the v2 dispatch style.
- Port the regenerated-title context anchoring (pingdotgg#5365) into
  ThreadTitleRegenerationService: pin the first user message ahead of the
  retained tail when the digest is truncated.
- Re-apply the right-panel controls positioning from pingdotgg#5260 to the v2
  ChatView title bar controls.
- Repair merge artifacts: committed conflict markers in BranchToolbar,
  duplicate capability keys, duplicate CommandPalette import, v1 turn
  naming in DiffPanel's focus-refresh effect, onSend signature merge.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Match progress button spacing and single-line height to static git actions
rerere replayed stale resolutions during the rebase and committed nested
conflict markers in several files. Restore the branch-intended v2 shapes
and re-graft main's compatible additions (pending-card opacity comments,
theme-editor keybinding test, mobile scroll re-arm effects from pingdotgg#5566).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…eysetIndex

Main owns migration numbering: 037_ProjectionTurnsKeysetIndex landed on
main (pingdotgg#5493), so the v2 migrations shift from 037-045 to 038-046.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Native subagent observability (pingdotgg#5219), wired per its spec's v2 merge plan:
- getWorkflowScript RPC re-homed onto the v2 WS surface (contracts, rpc
  group, ws handler, auth scope, client atom).
- AgentsPanel fed by the spec's mapper swap: projectedSubagentsToRuntime
  maps orchestration-v2 subagent entities into the panel model;
  deriveAgentPanelModel's v2Projection leg is now live and the v1 fold
  never runs. Agents surface wired into ChatView + RightPanelTabs.
Other ports and reconciliations:
- Shell reconnect-loop fix (pingdotgg#5561) ported into the v2 shell sync
  (same-session resubscribes resume from the in-memory cursor), with the
  cursor-resume regression test adapted to v2 fixtures.
- Mobile end-follow latch (pingdotgg#5566) ported onto the v2 ThreadFeed.
- Claude ede_diagnostic interrupt classification (pingdotgg#5557) ported into
  ClaudeAdapterV2 (aborted_tools/aborted_streaming => interrupted; CLI
  telemetry never becomes the failure banner). pingdotgg#5559 needs no v2 port
  (unknown system subtypes are already ignored).
- Plan sidebar removed from the v2 ChatView/ChatComposer per main's
  plans-fold-into-chat rework (pingdotgg#5558); rightPanelStore stays at main's
  surface set.
- SettingsPanels rebuilt as main's refactored version plus the branch's
  composer-context setting; sidebar snooze respects the time format
  (pingdotgg#4438 follow-through).
- v1-only leftovers deleted: zombie v1 adapters/ingestion/tests the v2
  rewrite removes, the v1-bound transfer-budget CI harness (pingdotgg#5350, needs
  a v2 rebuild), and main's v1 client pagination machinery (pingdotgg#5493 client
  side; the 037 keyset migration is kept — server-side v2 windowing is a
  follow-up).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The rebase kept the LegendList 3.3.3 upgrade and patch from pingdotgg#5449 and the
mobile end-follow latch from pingdotgg#5566, but the v2 MessagesTimeline/ChatView
still carried the branch's blunt any-gesture-breaks-follow listeners.
Port main's pingdotgg#5566 web mechanics onto the v2 follow architecture:

- resolveTimelineIsAtEnd measures the 40px follow re-arm band from real
  geometry (contentLength/scroll/scrollLength minus the composer inset),
  keeping the isNearEnd fallback for older state shapes.
- Follow now breaks only on gestures that can actually leave the live
  edge: upward wheel with overflowing content, touch drags that exited
  the end band, scrollbar drags vs content clicks, and keyboard
  navigation (PageUp/Home/ArrowUp) — previously keyboard scrolling never
  broke follow and the next stream chunk yanked the view back down.
- Listener attach retries across frames so a thread switch cannot mount
  the list without its opt-out listeners.

Deliberately not ported: pingdotgg#5449's shouldRestorePosition disclosure
anchoring and follow-gated maintainScrollAtEnd — the v2 timeline keeps
maintainScrollAtEnd={false} with its own follow scrolls and anchor
system; flipping that core is a separate change.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…gdotgg#5449)

Complete the pingdotgg#5449 architecture on the v2 timeline, following the
LegendList author's direction to lean on the list's native mechanisms
instead of app-side scroll layers:

- maintainScrollAtEnd is enabled and owned by LegendList, gated off only
  while the user reads history (liveFollowEnabled), while a sent turn
  anchors near the top (anchoredEndSpace), or during the two-frame settle
  of a fold toggle.
- maintainVisibleContentPosition compensates size changes natively
  ({data, size, shouldRestorePosition}); fold toggles anchor compensation
  to the toggled row via a disclosure anchor key, so the trigger stays
  under the pointer instead of the viewport chasing the end.
- ChatView's hand-rolled streaming follow (double-rAF scrollToEnd on
  every data change) is gone; the app now only owns streaming
  adjustments during anchored-end-space mode, mirroring main.
- timelineLiveFollowEnabled state mirrors the follow refs so the
  render-visible gate switches native follow off when a gesture breaks
  follow and back on when the viewport returns to the end band.

Timeline tests updated to assert the native-ownership invariants.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Keep success feedback visible in the Git action control for 10 seconds
- Move the running elapsed timer into the panel menu slot
…s with v2

Post-rebase reconciliation sweep:
- Sidebar: main's folded Sidebar.tsx/Sidebar.logic.ts adapted to v2 shells
  (latestRun/runtime naming, waiting status instead of monitoring), with
  subagent-thread filtering and main's pinned-reorder helpers re-exported
- Pinned drag reorder (pingdotgg#5581) ported into v2: thread.pin orderKey +
  thread.pin.reorder command, thread.pin-reordered event, Orchestrator fold,
  ProjectionStore/Maintenance, client-runtime commands and shell mapping
- Project favicon (pingdotgg#4849-era) and defaultThreadEnvMode flowed through v2
  contracts (OrchestrationProjectShell, application event payloads)
- ChatView: main's pingdotgg#5592 header props, pull-request right-panel surfaces,
  liveAgentCount badge (pingdotgg#5745) wired into the v2 panel layout
- enableAssistantStreaming -> enableLegacyTokenStreaming rename applied to
  v2 RunExecutionService and replay testkit
- Removed v1 zombies resurrected by the rebase (provider service/reaper/
  ingestion + v1 layer tests, server.test.ts, integration harness)
- routeTree: main's tree + branch's /settings/scheduled-tasks route
- Misc marker-sweep syntax repairs (rpc.ts, entities.ts, localApi.test.ts,
  rightPanelStore.test.ts, GitManager.test.ts, mobile model menu helpers)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… 038-040

Main released ProjectionThreadsPinOrderKey (038),
ProjectionProjectsDefaultThreadEnvMode (039) and
ProjectionProjectFaviconPath (040), so the branch-private v2 stack shifts
up by three. Registry ids were already 41-49; this renames the files and
identifiers to match and updates the ledger expectations and through-id
boundaries in the migration tests (released boundary 37 -> 40).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- a6c9b41 (agents open pasted images): ClaudeAdapterV2 now grants the
  attachments dir alongside cwd via additionalDirectories and appends
  '[Attached ... is saved at: path]' lines to the turn text so tools can
  dereference pasted images (pixels alone are not tool-readable).
- 5bb8c03 (settle leaves monitors running): thread.settle now joins
  archive/delete in the provider-session detach set, so PR monitors, dev
  servers and subagent fleets stop when the user parks the thread. The
  settle guard already rejects active runs, and serialized dispatch closes
  the re-engage race the v1 fix handled with onlyIfSettled.
- e70cdb4 (Claude resume handshakes) and 2c7267a (reaper vs live
  background subagents) are already covered structurally in v2: results
  are turn-scoped with explicit zero-turn handshake drops, and idle
  release is pinned while background work is pending.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…e panel-visibility merge

The keep-both merge nested main's plan-surface migration test inside a
branch popover test and dropped the threadPanelVisibilityByThreadKey key
from the migration results. Restore main's test body and include the
branch's (empty) visibility map in the expected persisted shape.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…n text

Follow-up to the pingdotgg#5757 port: start and steer turns now append the
'[Attached ... is saved at: path]' line, so the adapter fixtures assert it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The round-3 reconciliation took main's ChatHeader wholesale and wired its
full prop set, resurrecting the scripts/open-in/git-actions cluster the
branch had deliberately relocated into the thread panel. Restore the
79-line slim header (project favicon + name + thread title) and its
minimal ChatView call. pingdotgg#5592's header actions stay a documented v2
follow-up, as decided in round 2.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Add ready, merge, and conflict-resolution actions to the PR row
- Share pull request action and handoff logic with the detail panel
- Fix thread details scrolling and row alignment
…reens

Round-4 reconciliation of pingdotgg#5986/pingdotgg#5988 with the v2 cutover files:
- PendingUserInputCard adopts main's collapsible overlay redesign with the
  v2 RuntimeRequestId/responseCapability plumbing (dead provider processes
  still read-only the card)
- ThreadFeed adopts the thread-feed-live-follow transition model, the
  user-scroll settle window, momentum handoff, and env-scoped feed keys
  while keeping the v2 nearListEnd layout gating
- ThreadDetailScreen hides (not unmounts) the composer while a user-input
  request owns the slot; multi-select answers flow as arrays end to end
  (threadActivity toggle/build helpers + tests, ThreadUserInputQuestion)
- ThreadComposer keeps the v2 canStopThread stop gate under main's
  onEditorFocusChange rename; standalone stop reuses the shared renderer
- Restored the branch's steer stop/send tests alongside main's composer
  test suite

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- PullRequestDetailPanel takes main's pingdotgg#6039 rework wholesale (reactions,
  update-branch, auto-merge, in-place editing); the thread-details action
  hooks stay in usePullRequestActions with label maps extended for the
  new action variants
- CommandPalette pingdotgg#6330 provider subtitles adapted to the v2 shell
  (session -> runtime for provider instance and display name)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Add conflict, draft, failing-check, and merge action ranking
- Show check progress and pull request details in row tooltips
… PR panel

The round-5 ChatView reconciliation kept the round-3-era PullRequestDetailPanel
call, so the panel mounted without chromeVariant="collapse" — the pingdotgg#6039
scroll-condensing chrome never engaged and the description scrolled under a
full-height chrome. Restore main's call exactly: collapse chrome,
composerDraftTarget for same-thread hand-offs, the isThreadOwnPullRequest
context check, and tab statuses keyed by the active surface id via
updatePullRequestTabStatus instead of a key rebuilt from the status payload.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Add paginated thread history with bounded snapshots and replay limits
- Trim oversized wire payloads and support progressive mobile history loading
- Add optional title regeneration request and start time to thread shells
- Cover cache serialization on mobile and client runtime
- ChatView: pingdotgg#5880 auto-settle-on-merge setting flows into effectiveSettled,
  pingdotgg#5644 browser favicon project registration effect, activeProjectRef memo,
  desktopByTabId on both RightPanelTabs mounts
- server: provide ServerSecretStore to the McpSessionRegistry's
  ServerEnvironment layer (pingdotgg#6325 reads publish opt-in per descriptor)
- mobile: 3-way merged main's deltas into the v2 thread screens
  (NewTaskDraftScreen keeps the branch title seed + main's environmentId,
  threadListV2 keeps both new test suites, queries imports deduped)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…toggles

Restores main's one-inset rule (pingdotgg#5226) that a rebase resolution had
overridden with a conditional right-2 offset, which made the controls jump
sideways whenever the right panel opened. Also restores the live-agent
count badge on the right-panel toggle (pingdotgg#5745) that the round-6 replay
dropped, and applies the same fixed-position rule to the pull requests
page: the toggle now stays mounted at one absolute inset in both states,
with a footprint spacer in the list header so the refresh button never
slides underneath it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The right controls carry mr-px (main's border compensation for anchoring
inside the panel frame), which left the sidebar trigger one pixel closer
to its edge and the sheet-mode tab bar one pixel tighter than the closed
state. Mirror the pixel on the trigger and the sheet layout-controls slot
so all three read the same inset.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…gger

The trigger's icon falls through to the Button default (size-4) while the
right cluster hard-coded size-3.5, so the two ends of the titlebar read a
pixel apart on every edge. All five layout-control icons now use size-4,
matching the trigger and the pull requests page's refresh icon.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Omit transcript bodies from shell rows
- Query archived threads separately and stream compact resume metadata
Re-applies the deltas that mid-stack blob reverts discarded, and merges
main's work into the v2-owned surfaces:

- keybindings: main's STATIC_KEYBINDING_COMMANDS rename plus both new
  commands (rightPanel.toggleMaximized alongside threadPanel.toggle)
- OpenInPicker: main's remote-open/SSH routing and favorite-editor
  shortcut layered onto the branch's panel/toolbar variants; the
  extracted shouldShowOpenInPicker now takes remoteOpenMode
- ChatMarkdown: main's bare-filename resolver (pingdotgg#6297) ported into the
  branch's module-level component factory, plus pingdotgg#4133 title-attribute
  stripping on links and images
- ComposerPrimaryActions: main's pingdotgg#4781 model (stop stays reachable, send
  joins it when Enter-to-send is unavailable) carrying the branch's
  steering send button
- ComposerPendingUserInputPanel: main's collapsible redesign with the v2
  RuntimeRequestId and responseCapability gate
- ChatComposer: main's oversized-prompt submission guard wrapping the
  branch's dispatch-mode send
- preview shell: main's container-aware width clamp ported into the
  branch's usePreviewPanelInlineSize hook
- MessagesTimeline/Sidebar: main's day-aware timestamps, code-font tool
  bodies and provider accent badges on the v2 runtime shell
- index.css: main's @variant dark migration (pingdotgg#6381) replaces the branch's
  standalone .dark block
- contracts: main's send-turn image mime allowlist re-homed to
  chatAttachment.ts, where v2 keeps the other send-turn limits

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Merge the frozen codex-turn-mapping target while preserving J5 Squadron
ownership, agent messaging, lifecycle behavior, remote routing and branding.
Reconcile historical migrations, tool admission and client surfaces.

Includes independently reviewed conflict resolutions and the scoped
command-palette identity correction found by two-environment browser testing.
@github-actions github-actions Bot added the vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. label Sep 17, 2026
@Jacksondr5

Copy link
Copy Markdown
Owner Author

Pushed Squadron onboarding as 42a4b9115. Reopen /welcome after pulling to exercise Connect → Providers → Projects → Squadrons.

Fable built the UI; the separate reviewer approved backend and final UI after the stale-selection and focus/scroll corrections. Final local checks:168 web tests,18 backend/client seam tests, server/web typechecks, scoped format/lint. Live Chromium verified first import, Back-state preservation, idempotent reimport, immutable-home exception results, assignment retry, lost-create-response recovery without duplication, desktop/narrow layout, and a new live Codex turn under the landing Squadron. No shared-state writes.

Images remain local and need GitHub attachment; this session has no authenticated asset-upload capability. Native desktop/mobile and live remote/relay onboarding were not exercised.

Draft/base conflicts remain unchanged. J5 CI is running on this head. The separate PR-size job failed with spawnSync git ENOBUFS while collecting this large merge diff; tracked in #180. Shared first-home/archive race remains tracked in #179.

Implementation: GPT-6 / Codex, Fable UI builder / Claude Agent; independent Fable reviewer.

@github-actions github-actions Bot added the size:XXL 1,000+ effective changed lines (test files excluded in mixed PRs). label Sep 20, 2026
@bryantderosier

bryantderosier commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Persona and crew impact review

I had this PR reviewed specifically for whether it breaks the J5 persona and crew implementation. Head 3a1ac8c8a against j5/main at 889197681. Read-only review: nothing on the branch was edited.

Verdict

This PR cannot merge as it stands, and after its conflicts are resolved it breaks crews in five concrete places unless the rebaser makes specific fixes. Personas survive.

The root cause is a stale base, not a hostile change. The branch forked from j5/main at 240728c50 (2026-09-20), before all 13 crew and persona commits landed (#145, #146, #147, #148, #149, #150, #151, #152, #183, #185, #191, #192, #219). On this branch there is no crew server code, no crew or fleet UI, no migrations 014 to 017, no persona spawn path, and none of propose_crew, request_crew_member, list_personas, stop_crew, archive_crew. A three-dot diff never shows them because they were never here.

GitHub reports mergeable=CONFLICTING. git merge-tree --write-tree origin/j5/main origin/j5/upstream-sync-20260911 yields 20 conflicted files.

Breaks that survive a mechanical conflict resolution

# Severity Break Where Fix
H1 High archive_crew loses its engine. PR deletes ArchiveAgentService.ts and the archive_agent tool in favor of t3_thread_organize. Main's ArchiveCrewService.ts (:17-22, :259, :310, :406), CrewCaptainArchiveCascade.ts:10, CrewArchiveHttp all depend on it. apps/server/src/j5/a2a/ArchiveAgentService.ts (modify/delete conflict) Keep ArchiveAgentService as an internal service, drop only the MCP tool. Or port ArchiveCrewService onto the lifecycle path.
H2 High Crew seat spawn no longer type-checks. PR changes RecordSpawnFactsInput from spawnedByParticipantId to provenance: ParticipantProvenance. Main's CrewLaunchService.ts:469-477 uses the old shape. apps/server/src/j5/a2a/SpawnCompositionService.ts:15-23 on PR Pass provenance: { kind: "spawned-by", spawnedByParticipantId, source: "j5_spawn" }, as PR handlers.ts:557-561 already does for spawn_agent.
H3 High Runtime layer graph re-plumb. PR moves spawn composition, participant placement, and home registration into makeJ5SquadronCreationLayer and removes spawnCompositionProvided plus the trailing placement provision from the auxiliary layer. Main's six crew layers depend on those. apps/server/src/j5/a2a/runtimeLayer.ts (conflict) Crew layers must take SpawnCompositionService and ParticipantPlacementService from the creation layer. Tests that build OrchestrationV2LayerLive alone may also need J5SquadronCreationLayer merged in, as the PR's DelegatedCompletionDelivery.test.ts now does.
H4 High New archive door bypasses the lone-seat rule (Crews AC16). PR's t3_thread_organize dispatches thread.archive and thread.delete through ThreadManagementService with only a same-Squadron check. Main's lone-seat refusal lives in ws.ts (makeCrewSeatArchiveGuard, FORK case 37) and in the removed archive_agent handler. apps/server/src/j5/a2a/mcp/threadTools.ts:88-134 on PR Call the crew seat archive guard from the organize handler, or from the ThreadLineage dispatch decorator that sees every door.
P1 High (build) Client-runtime export removed. PR makes threadRunStatusIsActive module-private (models.ts:72). Main's apps/web/src/j5/crew/crewState.ts:1 imports it (used :5, :40); FleetPage.tsx:29-34 depends on it. No conflict on either file, so the merged tree fails to load. Reproduced: SyntaxError: The requested module '@t3tools/client-runtime/state/models' does not provide an export named 'threadRunStatusIsActive'. packages/client-runtime/src/state/models.ts:72 on PR Restore the export, or switch crewState.ts to the exported threadRuntimeIsActive with a matching input shape.
H5 High (docs) FORK.md numbering collision. Both sides claim "38 cases: 1 to 37 plus 15b" with different contents. Main added 36 (event logger seat ids), 37 (lone-seat guard), the personas table, and the crews paragraph. PR added 35 (fork and merge-back registration), 36 (first-run import homes), moved machine-sender to 37, rewrote 2, 8, 33. PR line 173's archive ruling contradicts main's cascade comment. FORK.md (conflict) Renumber PR cases to 38 and 39; keep every main persona and crew paragraph.

Medium

  • M1 Orchestration instructions. apps/server/src/provider/T3OrchestrationInstructions.ts conflicts. Main (feat(crews): compose crews in chat and coordinate directly #191) added Crew and Captain paragraphs and the delegate_task versus spawn_agent wording. PR added the ACP prompt wrapper, browser-tool text, and lazy-catalog text. Both are needed; dropping the crew paragraph means Captains never learn propose_crew.
  • M2 Allowlists. Main's claudeAllowedTools.ts and codexToolApproval.ts enumerate every J5 verb including archive_agent; tools.test.ts:102-111 asserts the Claude list equals the J5Toolkit names. Both lists must drop archive_agent. PR's new destructive tools (t3_thread_organize, fork, merge_back) are not pre-approved for read-only personas, which is acceptable but means a read-only Captain persona cannot archive via organize.
  • M3 registration test. PR still expects t3_thread_wait; main removed it deliberately (Captain starvation ruling). Resolve to main's list minus archive_agent plus the crew tools.
  • M4 ws.ts. Main's makeCrewSeatArchiveGuard construction and the j5CrewSeatArchiveGuard(command) call in dispatchCommand, plus the artifact RPC handlers spread, must survive.
  • M5 Effect bump 4.0.0-beta.103 to 4.0.0-rc.112. No main-only crew or persona file uses Schema.TaggedErrorClass (crew code uses Data.TaggedError), but only a typecheck of the resolved merge proves compilation.

Client-side conflict map (all mechanical)

  • ChatView.tsx: CrewRosterGate JSX auto-survives (merged :9483-9486). Only the import block conflicts; union it.
  • SettingsSidebarNav.tsx, settingsSearch.ts: keep Personas, add PR's SnapShot entries; do not restore the old Agents route.
  • routeTree.gen.ts: Fleet import and route auto-survive, as do FleetRailEntry and HumanInboxBell in SidebarChrome. Regenerate from combined routes (Personas plus PR's Projects and SnapShot).
  • packages/client-runtime/src/j5/state.ts: only the type import conflicts; union it. Crew and Fleet request bodies coexist with assignImportedThreads.
  • packages/contracts/src/rpc.ts: auto-merge retains both group merges. Keep J5ArtifactRpcGroup, one ProviderInstanceId import, and PR's ProviderInstanceMutation. j5.artifacts.subscribeChanges does not collide with upstream's artifact method.
  • apps/mobile/src/features/threads/use-project-actions.ts: accept the PR's deletion. Main only changed a comment. Persona id flows through PR's persistent outbox (NewTaskFlowProvider, thread-outbox-model, drain, projectThreadStartTurn).
  • MessagesTimeline: merged call retains threadRef and markdownCwd, so crew notices keep environment-qualified seat links.

Verified safe on this branch

  • J5 MCP surface still registered and merged into McpHttpServer.ts:709-722 (FORK case 2). Contracts of send_message, list_participants, spawn_agent, stop_agent, join_squadron, list_squadrons, clear_own_ask unchanged.
  • McpInvocationScope fields unchanged; McpSessionRegistry grants orchestration to every credential; identity resolves via HomeRegistrar.
  • delegate_task: agentDelegation.ts and agentInvocation.ts untouched, so main's persona parameter auto-merges. DelegatedCompletionDelivery extended additively. The @persona: mention path on web and mobile inserts text through the shared helper and never calls delegate_task directly.
  • Migrations: Sqlite.ts:41-42 still runs upstream then J5 lane; J5 Migrations.ts unchanged, so crew 014 to 017 auto-merge; no upstream object named j5_agent_crew_*; a main database collapses cleanly to upstream 051.
  • Persona seams: Orchestrator.ts still imports makeAgentPersonaGuards and carries agentPersonaAssignment in shell and detail projections; Claude and Codex adapters keep persona prompt and allowlist imports. CrewSeatFinishNotifier upstream deps all exist.
  • Fleet keying (scopedThreadKey), roster filtering, retired reads (includeRetired:true), and crew stop and archive HTTP routes all independent of the removed archive_agent tool.
  • Tool presentation: crew and persona tools were already generic on both sides, never mislabeled as thread or organize tools.

Tests run

  • Server side: 14 files, 71 tests passed at PR head (registration, tools, handlers, orchestratorSurface, joinSquadron, codexToolApproval, runtimeLayer, SpawnCompositionService, agentDelegation, agentPersonaLaunch.integration, agentInvocation, DelegatedCompletionDelivery, UpstreamMigrationCompatibility, worktree registration).
  • Client side: 21 files, 236 tests passed at PR head (persona contracts, orchestrator and threadMetadata contracts, tool presentation, client persona, mentions, http, state, commands, entities, web persona mention, settings, A2A bell, renderer, thread home, draft scope, mobile picker, project launch, outbox, drain).
  • Main's crew tests cannot run on this checkout because that code is absent here. The P1 build break was reproduced by linking the actual merge-tree source.

My call

Do not merge as is. Merge j5/main into this branch, resolve the 20 conflicts using the map above, then apply the five non-conflicting fixes (H1, H2, H3, H4, P1) and the FORK.md renumbering (H5). After that, run the crew and persona focused suites and a server plus web typecheck on the resolved merge before requesting review.

Review by a two-seat crew: Claude Fable 5.1 on the server side, GPT-6-Astra on contracts and clients.

Addendum from the server-side import trace

A scripted sweep resolved every import in the 73 main-only files against the PR head and diffed exports across all 958 PR-changed files (210 lost or privatized an export). It confirmed the list above and added two rebaser traps:

  • Crew archive failure contract rides on deleted schemas. PR tools.ts deletes J5ArchiveAgentOpenExchangeFact, J5ArchiveAgentRunningTurnFact, and J5ArchiveAgentFailure. Main tools.ts:376-392 builds J5ArchiveCrewMemberFacts and J5ArchiveCrewFailure on the first two, and main handlers.ts:92-160 projects them. Both files conflict, so taking the PR's deletions wholesale silently drops archive_crew's failure contract. Keep the two fact schemas, renamed crew-neutral if archive_agent goes.
  • handlers.ts resolution details. Main moved the spawn id helpers into spawnIds.ts; drop the PR's local copies and import them. The PR narrows requireCallerSquadron to stop_agent only; main needs stop_agent | archive_crew | stop_crew. Keep the spawn_agent crew-membership preflight (main :740-748) and the five crew handlers (main :885-1160).

Also traced and confirmed unchanged for crew code: the thread.create, message.dispatch, thread.archive, and thread.delete command contracts (only optional fields added), the ThreadManagementService methods crew services call, ProjectionStoreThreadNotFoundError, and the shared J5 ledger, delivery, home registrar, and send services. There is no server analogue of the client-side export privatization.

@Jacksondr5
Jacksondr5 marked this pull request as ready for review September 23, 2026 02:22
@bryantderosier
bryantderosier self-requested a review September 23, 2026 12:26
@Jacksondr5
Jacksondr5 merged commit 79b62cf into j5/main Sep 23, 2026
30 checks passed
@Jacksondr5
Jacksondr5 deleted the j5/upstream-sync-20260911 branch September 23, 2026 18:18
@Jacksondr5
Jacksondr5 restored the j5/upstream-sync-20260911 branch September 23, 2026 19:21
bryantderosier added a commit that referenced this pull request Sep 24, 2026
…247)

* feat(web): rename and delete a Squadron from the scope control

The sidebar Squadron scope dropdown gains a section for the selected
Squadron with Rename and Delete actions. Rename opens a dialog prefilled
with the current name that trims and disables submit on empty or
unchanged input. Delete opens a confirmation naming the Squadron, stating
that thread labels lose their Squadron home and that live members or
Crews block deletion, and shows the server's 409 message verbatim.

Both actions call the owning environment, then force-refresh that
environment's Squadron directory, requested thread homes, and the Fleet
read. After delete, the ambient scope and any draft carrier that pointed
at the deleted Squadron reset to All Squadrons.

The client commands are a local stub against the agreed PATCH/DELETE
routes until client-runtime ships renameSquadron/deleteSquadron.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(web): delete confirmation says Squadron history goes with it

The server removes the Squadron's ledger and placement history inside the
delete transaction, so the confirmation dialog now states that alongside
the existing consequences.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* feat(server): squadrons can be renamed and deleted over J5 HTTP

Squadrons could only be listed and created. Add PATCH and DELETE routes on
/api/j5/squadrons/:id backed by new ledger and management operations.
Rename trims the name and rejects a blank one. Delete is one transaction
that first counts members, active Crews, machine participants, and the
ON DELETE RESTRICT history tables (comm events, placement events, command
receipts) and refuses with a typed SquadronDeleteBlockedError naming the
blockers, returned as HTTP 409; CASCADE tables go with the row. Contracts
and client-runtime fetchers renameSquadron/deleteSquadron are appended
next to the existing Squadron schemas.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* feat(client-runtime): rename and delete Squadron commands

Expose renameSquadron and deleteSquadron on the J5 environment atoms next
to createSquadron so the web scope control can run them.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor(web): Squadron rename and delete use client-runtime commands

client-runtime now ships renameSquadron and deleteSquadron in the J5
environment atoms, so the temporary HTTP stub in the web state module is
gone and the web client points at those commands.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor(web): Squadron rename and delete call the environment atoms directly

Matches createSquadron: squadronClient runs j5Environment.renameSquadron
and j5Environment.deleteSquadron itself, so the alias object and the
stub's leftover imports leave the web state module untouched.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* feat(server): squadron delete purges history and refuses only live state

A delete that only worked on never-used Squadrons did not meet the ask.
Only unarchived agent members and running Crews now block deletion, named
with counts in the 409 message. Otherwise one transaction removes every
squadron-keyed row in dependency order, including the ON DELETE RESTRICT
history tables (comm events, command receipts, placement events), before
the squadron row, so threads that were homed there read as unknown-home.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(server): squadron delete refusal test no longer depends on list order

Two Squadrons created in the same millisecond tie on created_at and fall
back to random id order, so the assertion sorts the names first.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(server): squadron delete purge list is checked against the live schema

The purge now iterates one exported list of every table with a foreign key
onto j5_a2a_squadron, and a test reads PRAGMA foreign_key_list for the
migrated schema and asserts the list matches, so a future referencing table
fails the test instead of surfacing as a constraint error. The
archived-member delete test also seeds placement history and asserts the
thread reads as unknown home afterward. Blockers stay unarchived agent
members and running Crews; a send-only machine credential is purged with
its Squadron because it means nothing without it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(web): rename Squadron dialog keeps its footer inside the popup

The dialog popup lays out header, panel, and footer as a flex column. The
rename form sat between them as a plain block, so the scroll panel grew
past the popup border and the Cancel and Rename buttons rendered on a
strip below it. The form is now a flex column like the upstream wrapper
in the publish dialog, so the footer sits inside the popup again.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* chore: integrate upstream orchestration V2 into J5 (#178)

* fix: port main fixes stranded by the v2 rewrite

- Port thread pinning (#5312) into the orchestration-v2 command pipeline:
  thread.pin/unpin commands, thread.pinned/unpinned events, pinnedAt on the
  v2 thread state and projected shells, promotion semantics (pin clears
  settle/snooze, settle clears pin) matching the v1 decider, and client
  pin/unpin operations in the v2 dispatch style.
- Port the regenerated-title context anchoring (#5365) into
  ThreadTitleRegenerationService: pin the first user message ahead of the
  retained tail when the digest is truncated.
- Re-apply the right-panel controls positioning from #5260 to the v2
  ChatView title bar controls.
- Repair merge artifacts: committed conflict markers in BranchToolbar,
  duplicate capability keys, duplicate CommandPalette import, v1 turn
  naming in DiffPanel's focus-refresh effect, onSend signature merge.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* test(server): align migration expectations with renumbered ids

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(orchestrator): Surface waiting background work (#4378)

* fix(web): align git action progress button layout

- Match progress button spacing and single-line height to static git actions

* fix: repair conflict-marker artifacts from rebase auto-resolutions

rerere replayed stale resolutions during the rebase and committed nested
conflict markers in several files. Restore the branch-intended v2 shapes
and re-graft main's compatible additions (pending-card opacity comments,
theme-editor keybinding test, mobile scroll re-arm effects from #5566).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(server): renumber v2 migrations after main's 037_ProjectionTurnsKeysetIndex

Main owns migration numbering: 037_ProjectionTurnsKeysetIndex landed on
main (#5493), so the v2 migrations shift from 037-045 to 038-046.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: port main fixes stranded by the v2 rewrite (round 2)

Native subagent observability (#5219), wired per its spec's v2 merge plan:
- getWorkflowScript RPC re-homed onto the v2 WS surface (contracts, rpc
  group, ws handler, auth scope, client atom).
- AgentsPanel fed by the spec's mapper swap: projectedSubagentsToRuntime
  maps orchestration-v2 subagent entities into the panel model;
  deriveAgentPanelModel's v2Projection leg is now live and the v1 fold
  never runs. Agents surface wired into ChatView + RightPanelTabs.
Other ports and reconciliations:
- Shell reconnect-loop fix (#5561) ported into the v2 shell sync
  (same-session resubscribes resume from the in-memory cursor), with the
  cursor-resume regression test adapted to v2 fixtures.
- Mobile end-follow latch (#5566) ported onto the v2 ThreadFeed.
- Claude ede_diagnostic interrupt classification (#5557) ported into
  ClaudeAdapterV2 (aborted_tools/aborted_streaming => interrupted; CLI
  telemetry never becomes the failure banner). #5559 needs no v2 port
  (unknown system subtypes are already ignored).
- Plan sidebar removed from the v2 ChatView/ChatComposer per main's
  plans-fold-into-chat rework (#5558); rightPanelStore stays at main's
  surface set.
- SettingsPanels rebuilt as main's refactored version plus the branch's
  composer-context setting; sidebar snooze respects the time format
  (#4438 follow-through).
- v1-only leftovers deleted: zombie v1 adapters/ingestion/tests the v2
  rewrite removes, the v1-bound transfer-budget CI harness (#5350, needs
  a v2 rebuild), and main's v1 client pagination machinery (#5493 client
  side; the 037 keyset migration is kept — server-side v2 windowing is a
  follow-up).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* chore(web): prune plan-sidebar leftovers after the inline-plans rework

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): port the refined live-follow gesture gating to the v2 timeline

The rebase kept the LegendList 3.3.3 upgrade and patch from #5449 and the
mobile end-follow latch from #5566, but the v2 MessagesTimeline/ChatView
still carried the branch's blunt any-gesture-breaks-follow listeners.
Port main's #5566 web mechanics onto the v2 follow architecture:

- resolveTimelineIsAtEnd measures the 40px follow re-arm band from real
  geometry (contentLength/scroll/scrollLength minus the composer inset),
  keeping the isNearEnd fallback for older state shapes.
- Follow now breaks only on gestures that can actually leave the live
  edge: upward wheel with overflowing content, touch drags that exited
  the end band, scrollbar drags vs content clicks, and keyboard
  navigation (PageUp/Home/ArrowUp) — previously keyboard scrolling never
  broke follow and the next stream chunk yanked the view back down.
- Listener attach retries across frames so a thread switch cannot mount
  the list without its opt-out listeners.

Deliberately not ported: #5449's shouldRestorePosition disclosure
anchoring and follow-gated maintainScrollAtEnd — the v2 timeline keeps
maintainScrollAtEnd={false} with its own follow scrolls and anchor
system; flipping that core is a separate change.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): let LegendList own end-follow and disclosure anchoring (#5449)

Complete the #5449 architecture on the v2 timeline, following the
LegendList author's direction to lean on the list's native mechanisms
instead of app-side scroll layers:

- maintainScrollAtEnd is enabled and owned by LegendList, gated off only
  while the user reads history (liveFollowEnabled), while a sent turn
  anchors near the top (anchoredEndSpace), or during the two-frame settle
  of a fold toggle.
- maintainVisibleContentPosition compensates size changes natively
  ({data, size, shouldRestorePosition}); fold toggles anchor compensation
  to the toggled row via a disclosure anchor key, so the trigger stays
  under the pointer instead of the viewport chasing the end.
- ChatView's hand-rolled streaming follow (double-rAF scrollToEnd on
  every data change) is gone; the app now only owns streaming
  adjustments during anchored-end-space mode, mirroring main.
- timelineLiveFollowEnabled state mirrors the follow refs so the
  render-visible gate switches native follow off when a gesture breaks
  follow and back on when the viewport returns to the end band.

Timeline tests updated to assert the native-ownership invariants.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): show Git action success inline in panel

- Keep success feedback visible in the Git action control for 10 seconds
- Move the running elapsed timer into the panel menu slot

* fix: repair rerere-damaged files and reconcile main's round-3 features with v2

Post-rebase reconciliation sweep:
- Sidebar: main's folded Sidebar.tsx/Sidebar.logic.ts adapted to v2 shells
  (latestRun/runtime naming, waiting status instead of monitoring), with
  subagent-thread filtering and main's pinned-reorder helpers re-exported
- Pinned drag reorder (#5581) ported into v2: thread.pin orderKey +
  thread.pin.reorder command, thread.pin-reordered event, Orchestrator fold,
  ProjectionStore/Maintenance, client-runtime commands and shell mapping
- Project favicon (#4849-era) and defaultThreadEnvMode flowed through v2
  contracts (OrchestrationProjectShell, application event payloads)
- ChatView: main's #5592 header props, pull-request right-panel surfaces,
  liveAgentCount badge (#5745) wired into the v2 panel layout
- enableAssistantStreaming -> enableLegacyTokenStreaming rename applied to
  v2 RunExecutionService and replay testkit
- Removed v1 zombies resurrected by the rebase (provider service/reaper/
  ingestion + v1 layer tests, server.test.ts, integration harness)
- routeTree: main's tree + branch's /settings/scheduled-tasks route
- Misc marker-sweep syntax repairs (rpc.ts, entities.ts, localApi.test.ts,
  rightPanelStore.test.ts, GitManager.test.ts, mobile model menu helpers)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* chore(server): renumber v2 migrations 038-046 to 041-049 after main's 038-040

Main released ProjectionThreadsPinOrderKey (038),
ProjectionProjectsDefaultThreadEnvMode (039) and
ProjectionProjectFaviconPath (040), so the branch-private v2 stack shifts
up by three. Registry ids were already 41-49; this renames the files and
identifiers to match and updates the ledger expectations and through-id
boundaries in the migration tests (released boundary 37 -> 40).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(server): port round-3 main fixes into the v2 orchestrator

- a6c9b41f90 (agents open pasted images): ClaudeAdapterV2 now grants the
  attachments dir alongside cwd via additionalDirectories and appends
  '[Attached ... is saved at: path]' lines to the turn text so tools can
  dereference pasted images (pixels alone are not tool-readable).
- 5bb8c03664 (settle leaves monitors running): thread.settle now joins
  archive/delete in the provider-session detach set, so PR monitors, dev
  servers and subagent fleets stop when the user parks the thread. The
  settle guard already rejects active runs, and serialized dispatch closes
  the re-engage race the v1 fix handled with onlyIfSettled.
- e70cdb478d (Claude resume handshakes) and 2c7267ad43 (reaper vs live
  background subagents) are already covered structurally in v2: results
  are turn-scoped with explicit zero-turn handshake drops, and idle
  release is pinned while background work is pending.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* test(web): restore main's right-panel migration expectations after the panel-visibility merge

The keep-both merge nested main's plan-surface migration test inside a
branch popover test and dropped the threadPanelVisibilityByThreadKey key
from the migration results. Restore main's test body and include the
branch's (empty) visibility map in the expected persisted shape.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* test(server): expect attachment saved-at lines in ClaudeAdapterV2 turn text

Follow-up to the #5757 port: start and steer turns now append the
'[Attached ... is saved at: path]' line, so the adapter fixtures assert it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): restore the branch's slim chat header

The round-3 reconciliation took main's ChatHeader wholesale and wired its
full prop set, resurrecting the scripts/open-in/git-actions cluster the
branch had deliberately relocated into the thread panel. Restore the
79-line slim header (project favicon + name + thread title) and its
minimal ChatView call. #5592's header actions stay a documented v2
follow-up, as decided in round 2.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(web): add pull request actions to thread details

- Add ready, merge, and conflict-resolution actions to the PR row
- Share pull request action and handoff logic with the detail panel
- Fix thread details scrolling and row alignment

* fix(mobile): port main's composer stabilization into the v2 thread screens

Round-4 reconciliation of #5986/#5988 with the v2 cutover files:
- PendingUserInputCard adopts main's collapsible overlay redesign with the
  v2 RuntimeRequestId/responseCapability plumbing (dead provider processes
  still read-only the card)
- ThreadFeed adopts the thread-feed-live-follow transition model, the
  user-scroll settle window, momentum handoff, and env-scoped feed keys
  while keeping the v2 nearListEnd layout gating
- ThreadDetailScreen hides (not unmounts) the composer while a user-input
  request owns the slot; multi-select answers flow as arrays end to end
  (threadActivity toggle/build helpers + tests, ThreadUserInputQuestion)
- ThreadComposer keeps the v2 canStopThread stop gate under main's
  onEditorFocusChange rename; standalone stop reuses the shared renderer
- Restored the branch's steer stop/send tests alongside main's composer
  test suite

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): reconcile main's round-5 features after the rebase

- PullRequestDetailPanel takes main's #6039 rework wholesale (reactions,
  update-branch, auto-merge, in-place editing); the thread-details action
  hooks stay in usePullRequestActions with label maps extended for the
  new action variants
- CommandPalette #6330 provider subtitles adapted to the v2 shell
  (session -> runtime for provider instance and display name)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(web): prioritize pull request row actions

- Add conflict, draft, failing-check, and merge action ranking
- Show check progress and pull request details in row tooltips

* fix(web): restore main's collapse chrome and tab-status keying on the PR panel

The round-5 ChatView reconciliation kept the round-3-era PullRequestDetailPanel
call, so the panel mounted without chromeVariant="collapse" — the #6039
scroll-condensing chrome never engaged and the description scrolled under a
full-height chrome. Restore main's call exactly: collapse chrome,
composerDraftTarget for same-thread hand-offs, the isThreadOwnPullRequest
context check, and tab statuses keyed by the active surface id via
updatePullRequestTabStatus instead of a key rebuilt from the status payload.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(orchestration): bound thread history and resume payloads

- Add paginated thread history with bounded snapshots and replay limits
- Trim oversized wire payloads and support progressive mobile history loading

* feat(contracts): track thread title regeneration

- Add optional title regeneration request and start time to thread shells
- Cover cache serialization on mobile and client runtime

* fix: reconcile main's round-6 features after the rebase

- ChatView: #5880 auto-settle-on-merge setting flows into effectiveSettled,
  #5644 browser favicon project registration effect, activeProjectRef memo,
  desktopByTabId on both RightPanelTabs mounts
- server: provide ServerSecretStore to the McpSessionRegistry's
  ServerEnvironment layer (#6325 reads publish opt-in per descriptor)
- mobile: 3-way merged main's deltas into the v2 thread screens
  (NewTaskDraftScreen keeps the branch title seed + main's environmentId,
  threadListV2 keeps both new test suites, queries imports deduped)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): keep the titlebar layout controls fixed across right-panel toggles

Restores main's one-inset rule (#5226) that a rebase resolution had
overridden with a conditional right-2 offset, which made the controls jump
sideways whenever the right panel opened. Also restores the live-agent
count badge on the right-panel toggle (#5745) that the round-6 replay
dropped, and applies the same fixed-position rule to the pull requests
page: the toggle now stays mounted at one absolute inset in both states,
with a footprint spacer in the list header so the refresh button never
slides underneath it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): align titlebar clusters to one shared pixel inset

The right controls carry mr-px (main's border compensation for anchoring
inside the panel frame), which left the sidebar trigger one pixel closer
to its edge and the sheet-mode tab bar one pixel tighter than the closed
state. Mirror the pixel on the trigger and the sheet layout-controls slot
so all three read the same inset.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): size the titlebar layout-control icons like the sidebar trigger

The trigger's icon falls through to the Button default (size-4) while the
right cluster hard-coded size-3.5, so the two ends of the titlebar read a
pixel apart on every edge. All five layout-control icons now use size-4,
matching the trigger and the pull requests page's refresh icon.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* perf(server): keep shell snapshots bounded and active-only

- Omit transcript bodies from shell rows
- Query archived threads separately and stream compact resume metadata

* fix: reconcile main's round-8 features after the rebase

Re-applies the deltas that mid-stack blob reverts discarded, and merges
main's work into the v2-owned surfaces:

- keybindings: main's STATIC_KEYBINDING_COMMANDS rename plus both new
  commands (rightPanel.toggleMaximized alongside threadPanel.toggle)
- OpenInPicker: main's remote-open/SSH routing and favorite-editor
  shortcut layered onto the branch's panel/toolbar variants; the
  extracted shouldShowOpenInPicker now takes remoteOpenMode
- ChatMarkdown: main's bare-filename resolver (#6297) ported into the
  branch's module-level component factory, plus #4133 title-attribute
  stripping on links and images
- ComposerPrimaryActions: main's #4781 model (stop stays reachable, send
  joins it when Enter-to-send is unavailable) carrying the branch's
  steering send button
- ComposerPendingUserInputPanel: main's collapsible redesign with the v2
  RuntimeRequestId and responseCapability gate
- ChatComposer: main's oversized-prompt submission guard wrapping the
  branch's dispatch-mode send
- preview shell: main's container-aware width clamp ported into the
  branch's usePreviewPanelInlineSize hook
- MessagesTimeline/Sidebar: main's day-aware timestamps, code-font tool
  bodies and provider accent badges on the v2 runtime shell
- index.css: main's @variant dark migration (#6381) replaces the branch's
  standalone .dark block
- contracts: main's send-turn image mime allowlist re-homed to
  chatAttachment.ts, where v2 keeps the other send-turn limits

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(server): reject replaying a command receipt across threads in v2

Ports v1's #5246 guard into the v2 dispatcher: a stored receipt only
proves that this exact command already ran for the thread it was recorded
against, so returning it for a command aimed at a different thread reports
success for work that never happened there. The check is extracted as
canReplayCommandReceipt so the rule is unit-testable, and reuse now fails
with OrchestratorCommandIdConflictError like the v1 path.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(mobile): surface prominent activity status and metadata

- Keep prominent activity rows visible with lifecycle status and provider metadata
- Move feed sizing logic into tested helpers and preserve native measurement for activity groups

* fix: reconcile main's round-9 features after the rebase

Re-applies the deltas that mid-stack blob reverts discarded, and merges
main's round-9 work into the v2-owned surfaces:

- settings: main's Integrations page (#7082) coexists with the branch's
  Scheduled Tasks page in the path union, section labels, icons, and
  search catalog
- contracts: main's preview appearance/zoom/viewport settings imports
  restored beside the branch's modelSelection home for ModelSelection
- mobile: main's built-in themes (#6619) re-applied to the v2 thread
  screens and work log (useThemeColor over hand-rolled color-scheme
  ternaries)
- MessagesTimeline: main's #7157 cleanup adopted (toolCallExpandedBody
  class name unexported, implementation-detail test dropped)
- ChangedFilesTree: main's styled tooltip (#7209) carrying the v2 runId
- pullRequestDetail tests: branch's row-action coverage renamed onto
  main's buildAddSelectionToAgentHandoff (#6597)
- lint: migrated the six branch-owned native title tooltips that main's
  new no-native-title-tooltip rule (#7209) flags to styled Tooltips
  (GitActionsControl, QueuedRunsControl, TimelineSystemDivider,
  MessagesTimeline intent badge and MCP tool logo)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(server): honor withheld agent browser access in the v2 runtime

Ports #7083 into the v2 session path, which replaced the v1
ProviderService where main's gate lives. Instead of withholding the whole
t3-code MCP credential — on this branch it also carries the thread
orchestration and worktree toolkits — the credential is minted without
the "preview" capability when enableAgentBrowserAccess is off, so every
preview tool call rejects while orchestration stays available.

ProviderSessionManager reads the setting at prepare time (deny on an
unreadable settings file, matching main), rotates a reused credential
whose capability set no longer reflects the setting, and the session
config now carries browserToolsAvailable so the Codex adapter keeps its
developer instructions truthful via main's parameterized instruction
builders instead of the removed constants.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): restore the titlebar sizing and timeline fade lost to main's style simplification

Main's #6381 deleted the shared .workspace-topbar and scroll-fade rules
from index.css after inlining them at main's own call sites, but this
branch's slim chat chrome still references both classes. The round-8
rebase took the deletion without migrating the branch call sites, so the
header collapsed to zero height — the breadcrumb sat on the window edge,
timeline rows scrolled unfaded through it, and the thread-details popover
anchored to the collapsed header.

Restores both as composable utilities in #6381's own style: a
workspace-topbar utility for the titlebar rows, and the branch's
chat-timeline-scroll-fade mask (soft ramp plus a full-height scrollbar
column). Also drops the duplicated media override and its dead
settings-page-scroll-fade selector.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): finish aligning the branch with main's style simplification

A follow-up sweep against #6381 found the branch still carrying the
pre-simplification forms it replaced, which my earlier fix had papered
over with a compat utility instead of finishing the migration:

- ChatView now uses main's inlined titlebar sizing and the
  data-workspace-titlebar-controls hook on both control clusters. The
  class-based markup was silently missing the themed-toggle bridge
  (html[data-theme-id] [data-workspace-titlebar-controls] …), so custom
  themes lost their titlebar accent in the thread view.
- The scroll-to-end pill becomes main's Button size="xs" variant="glass"
  instead of a hand-rolled button recreating it.
- MessagesTimeline uses main's consolidated topbar-scroll-fade utility;
  the byte-identical chat-timeline-scroll-fade copy and the
  workspace-topbar compat utility are gone.
- The composer-glass dark rules move into nested @variant dark like
  main's (the raw .dark duplicates could drift from the nested copies
  they shadowed), including the branch-only queue strip.
- The pre-#6381 dialog-glass/dialog-backdrop/dropdown-glass class rules
  and their .dark variants are deleted: the #6381 utilities plus
  call-site shadow utilities own every declaration, and the stale
  dropdown rule still had the saturate-less backdrop-filter. The dead
  model-picker-surface dark rule goes with them.

index.css now has zero raw .dark selectors outside the variant
definitions, matching the doctrine in
.macroscope/check-run-agents/ui-consistency.md. Verified against the
emitted production CSS: dark variants compile to :is(.dark,.dark *) with
their @supports color-mix fallbacks intact.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(orchestration): show provider retries in the work log

- Complete retry items when provider activity resumes
- Keep retry progress visible across web and mobile clients

* fix: reconcile main's round-10 features after the rebase

Ten days of main (194 commits, 640 files) re-integrated with the v2
re-architecture. The headline mechanics:

- migrations: main added 041-043 (AuthSessionClientConnection,
  ProjectionThreadLinkedPullRequest, ProjectionThreadsUnsettledAt), so the
  v2 block renumbers 041-049 → 044-052 with the migration tests shifted to
  match
- contracts: OrchestrationClientOrigin (#7774) and the origin metadata
  field live in applicationEvent.ts and re-export through the legacy
  path; ProviderApprovalOption + acceptAlways + mcp-elicitation (#8058)
  land in providerPolicy.ts; OrchestrationDispatchCommandError (#8824)
  added; the send-turn image-mime home stays chatAttachment.ts
- threadSettled: main's settle-once-on-merge semantics (#7454) and
  un-settle re-anchor (#8231) hand-merged onto the v2 duck-typed shells
  (latestRun ?? latestTurn reads); web callers pass the new
  ChangeRequestSettleSource shape
- timeline anchoring: main's #7897 (follow-up sends no longer push to the
  top) ported by scanning user rows only; the branch test now encodes the
  new semantics, as does mobile's #7969 settled-pinned shelf behavior
- vcs: branch's deleteLocalBranch coexists with main's pruneWorktrees and
  the #7674 submodule checkout tests
- ws: v2 RPC surface keeps its dispatch path; main's attachment upload
  RPCs (#8048) and client-connection analytics recording are wired;
  providerUploadFeedback (#7949) fails explicitly pending a v2 route
- approvals: main's option-driven approval buttons (#8058) render through
  the v2 canRespond gate on web and mobile
- ChatView/ChatComposer/MessagesTimeline/Sidebar/session-logic/
  threadActivity keep the branch's v2 architecture; main's v1-coupled
  deltas to those files are recorded for follow-up rather than
  force-fitted

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): stop mis-marking recovered and text-reported tool failures in the v2 work log

Ports main's #7999/#7893 failure policy onto the v2 turn-item work log:
output text that reports a failure (command not found, ENOENT, nonzero
exit markers) now flags a row even when the provider item completed
"successfully", while the rendered row judges only its displayed result —
a command that merely greps for failure strings stays calm. Success now
also requires the failure check to pass, so recovered failures no longer
get the blue check.

The server half of #7893 needs no port: CodexAdapterV2 already projects
item.status directly, so a failed item never masquerades as completed.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(orchestration-v2): project linked pull requests on threads (#8160)

Main's thread↔PR linking never reached the v2 runtime: the client types
were optional stubs and the v2 server dropped the field, so linking a PR
on a v2 environment silently no-opped and #7454's settle-once logic could
never match the linked identity.

The link now flows end to end: thread.metadata.update carries an optional
linkedPullRequest (object to link, null to unlink), the orchestrator
folds it into thread state, and both shell builders project it — no
migration needed since v2 shells persist as payload JSON. The client
command sends the field and the shell mapper surfaces it, so the existing
web/mobile badge and settle plumbing light up on v2 threads.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(orchestration-v2): carry approval options and app names to the client (#8058)

Round 10 ported main's option-driven approval buttons, but v2 runtime
requests had no way to deliver the data — every approval rendered the
default button set, MCP app names never showed, and worse, the Codex
app-server's mcpServer/elicitation/request went entirely unhandled on the
v2 adapter, so ChatGPT-app access requests could never be answered.

The v2 approval_request turn item now carries optional appName and
options, the client derivation passes them into ThreadPendingApproval,
and CodexAdapterV2 handles mcpServer/elicitation/request end to end:
unsupported shapes decline immediately (mirroring the v1 runtime), and
supported ones surface a mcp-elicitation approval built from the shared
describeMcpElicitation/toMcpElicitationResponse helpers, so the persist
tiers (session / always) advertise exactly the choices the elicitation
can express.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(orchestration-v2): route Codex thread feedback uploads through v2 (#7949)

The round-10 rebase stubbed providerUploadFeedback to an explicit error
because its v1 ProviderService route died with the v2 rewrite. The route
now goes through the v2 runtime: session runtimes may expose an optional
uploadFeedback capability, the Codex adapter implements it against the
app-server's feedback/upload request, and the WS handler resolves the
thread's live provider session through ProviderSessionManagerV2 —
failing with a plain-language reason when no session has run, the session
is gone, or the driver has no feedback channel. This also un-blocks the
dormant mobile feedback UI.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(analytics): credit v2 threads and turns to the starting client (#7774)

Main records which client surface started each thread and turn; the v2
dispatch path replaced the v1 handler that did the recording, so v2
environments only reported connections. The v2 RPC layer now records
client.thread.started on thread launches (plus client.turn.requested when
the launch carries an initial message) and client.turn.requested on
message dispatches, using the connection's announced origin. Recording is
best-effort — attribution can never fail the user's command.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(grok): fail hung prompts on xAI rate-limit completions (#8358, partial)

Ports the rate-limit half of main's #8358 into the branch's reworked XAi
extension: a prompt_complete carrying stopReason rate_limit now fails the
hung prompt with the -32003 usage-limit error instead of settling it as a
normal end_turn, so the turn surfaces "usage limit reached" rather than
silently ending. The prompt-completion deferreds carry the error channel
end to end.

The exit_plan_mode approval gate from #8358 is NOT ported here: it needs
a v2 plan-flow design in AcpAdapterV2 (the v1 GrokAdapter it lived in is
gone) and is tracked separately.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(orchestration-v2): show live context usage in the meter (#8144)

The v2 context meter could only show token counts after a compaction had
already happened — v2 had no live usage plumbing at all, so main's
compaction-threshold UX was invisible on v2 threads. Provider turns now
carry an optional tokenUsage report: the Codex adapter maps the
app-server's thread/tokenUsage/updated notification (total breakdown +
model context window) onto the active provider turn, ChatView picks the
newest report out of the projection, and the meter prefers it over the
compaction fallback — so usage and remaining-context percentages update
while the turn runs.

Claude's v2 adapter does not report usage yet; its meter falls back to
compaction items as before.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): keep following the stream after returning to the live edge (#6519)

Ports main's anchor-release semantics onto the branch's timeline anchor
state: the scroll-to-end pill and a manual scroll back to the live edge
both drop the send-time anchored end space before re-enabling follow, and
the pill's scroll runs a frame later so the list measures without the
anchor space and lands on the true end. Without this the timeline could
settle into following-end with the anchor still installed — following
nothing.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(grok): capture exit_plan_mode into the v2 proposed-plan card (#8358)

Completes the deferred half of #8358: Grok's plan-approval gate now works
on the v2 runtime. The XAi extension regains main's exit-plan helpers
(request schemas, plan-markdown extraction, the abandoned-with-feedback
response, and the plan.md session-path sniffing), and the v2 ACP adapter
grows a captureProposedPlan primitive that emits a completed
proposed-plan artifact for the active turn — one plan id per turn, so
plan.md rewrites and the exit gate update a single card.

The Grok flavor wires both ends: tool calls that write plan.md under a
Grok session dir surface the plan while plan mode is still active, and
x.ai/exit_plan_mode (plus the underscore alias) captures the final plan —
request content first, then the sniffed plan.md contents, then the
empty-state placeholder — and abandons the native gate so the turn does
not hang, mirroring the Claude ExitPlanMode pattern.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): repaint the composer glass and strip the thread-panel popover chrome

Two post-rebase regressions from the round-10 index.css merge:

- The merge seam ate the closing brace of .chat-composer-glass, silently
  nesting the entire composer-glass section (shell, host, context strip,
  shoulder tab, banner cap) inside it as descendant rules that never
  matched — the composer surface stopped painting and thread content
  showed straight through the input. The brace is restored and the
  compensating over-close removed; every composer selector emits at top
  level again.

- The thread-details popover grew dropdown-glass card chrome around the
  panel: round 9 deleted the legacy components-layer .dropdown-glass rule
  in favor of the @utility, which the popover's border-0/bg-transparent
  suppressors no longer outrank (the utility emits later in the layer).
  The suppressors are now important variants, matching the !overflow
  override already there.

Verified against the emitted production CSS: shell::before is top-level,
no descendant-of-glass selectors remain, and the important suppressors
(including [backdrop-filter:none]!) are emitted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): adopt main's attached-composer surface contract so the glass survives shoulder tabs

The composer went frameless exactly when the stash or tasks badge was
showing: main's #7150 css hides the classic shell chrome whenever the
shell :has() a shoulder tab or top drawer and repaints the glass on
[data-chat-composer-main-surface] instead — an element the branch's
composer body never rendered, since it predates the drawer system while
the badges and css came through the rebase in main's new form.

The branch composer's frame div now carries the main-surface attribute
(with main's relative z-10 stacking) so attached mode paints background,
outline, and backdrop on it and the tab connects to the surface, and
ChatView applies chat-composer-glass-shell-attached while banner items
render in the drawer slot, matching main's externalComposerDrawerAttached
wiring. Without a tab or banner the attribute is inert and the classic
shell chrome paints as before.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): converge ChatComposer on main's drawer-era body

Round 10 restored the branch's pre-#7150 composer body while its
satellites (shoulder badges, banner drawers, glass css) arrived in
main's new form, and every seam between the two was a visible bug:
opaque/frameless composer, overflowing stash tab, detached stash menu.

Rebuilt ChatComposer via a reverse three-way merge (main's body as the
base, branch delta re-applied): dispatchMode send boundary, live-capable
approval gates, latestRun reads, and the v2 context-window meter stay;
everything else now matches main, including ComposerPrimaryActions and
the sendDisabledReason send gating. Attachment uploads stay off until
the v2 claim path lands.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): collapse settled tool runs behind main's summary toggles

The v2 timeline rendered every tool call as its own raw row; main's
tool-group collapsing (generated "Ran N commands and changed M files"
summaries, the live "Running <program>" pill for the active tool run,
and the "+N previous log entries" clamp for mixed groups) never made it
into the v2 row model.

Ported the work-live/work-toggle row kinds and group summarization into
the v2 derive, keyed on v2 item types (command_execution, file_change,
file_search, dynamic_tool, subagent) and runId lifecycle instead of v1
activities. Expanded groups keep the branch's richer per-entry detail
rows (V2ItemInspector) — only the collapsed presentation converges on
main.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): surface v2 todo-list plans as task progress

v2 already projected todo_list plan artifacts (deriveActivePlanState
existed with zero consumers), but nothing rendered them: todo_list turn
items showed as a bare "Updated tasks" work row, the composer Tasks
drawer never appeared, and the working row had no current-step label.

todo_list items now become inline turn-plan chips (mini step segments,
current step, N/M count, expandable step list) that fold with their
settled turn, ChatView derives the composer Tasks drawer progress and
steps from the running run's plan artifact, and the working row shows
"Working for Xs · <current step>" like main.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): show the command on collapsed tool rows, not its stdout

Collapsed command rows rendered "Command" plus the raw result JSON as
the preview; the command itself is the useful collapsed line, so it now
renders as the row text (whitespace-collapsed, truncated) with stdout
and the full payload behind the expander. Tool-like headings drop the
bold foreground for the muted secondary-label the summary rows use, and
the "+N previous tool calls" toggle loses its bold black label for the
same muted treatment.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): collapsed tool rows preview inputs for every tool type

Extends the command-row fix to the whole preview: file-change rows were
still leaking raw diff lines into the collapsed line. workEntryPreview
now resolves input-first — command, then touched-file paths, then
detail (which is input for the remaining types: search patterns,
reasoning text, error messages) — so outputs only appear behind the
expander.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: reconcile main's round-11 features after the rebase

Round-11 rebase onto main (25 commits). Reverse-merged main's new work
into the v2 cutover files: #8395 muted ordinary-tool-failure treatment
(v2-adapted workEntrySignalsSevereFailure keyed on error items), #5931
sidebar project-filter combobox + #4c51 keyboard pin/settle with their
ChatView support graph, the auto-settle-mode migration through
threadSettled/threadListV2, #8235 file/unknown attachment schemas moved
into chatAttachment.ts with nullable attachment paths, #8481 client
analytics through the v2 ws layer, #8480 OpenCode server owner wired
into the driver beside the v2 orchestration adapter, and the mobile
semantic-theme migration applied to branch-only components.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(opencode): route child-session approvals through the v2 adapter

Ports the v2-applicable half of #8480 (the v1 adapter rewrite was not
carried; this branch's OpenCode path is OpenCodeAdapterV2). Permission
and question asks from child sessions — task subagents and their
descendants — were dropped because the adapter only looked up root
thread sessions. Related sessions now map back to the owning root
state (registered from task parts and session.created/updated parent
chains), and an ask that arrives before the relation is known resolves
it inline via session.get with a short forked backoff, then surfaces
the approval on the root turn. Replies already route by native request
id. Interrupts now tolerate the abort racing turn settlement instead
of failing the stop.

Covered by a new opencode_child_approval replay fixture where the
child asks for bash permission before the task part reveals the
relation.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: reconcile main's round-12 features after the rebase

Small rebase onto main (4 commits). The composer stash-shortcut label
and the mobile start-task menu refactor merged onto the v2 composer
bodies, and main's new auto-settle list tests are ported to the v2
thread-list test file (latestRun/RunId shapes). The auto-settle
machinery itself already matched main from the round-11 reconcile.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: restore main's automatic thread settling after the revert

Round-13 rebase onto main (2 commits). Main reverted the auto-settle
opt-in (#8596 undoing #8321), so the branch drops the ported
autoSettleMode machinery and returns to sidebarAutoSettleOnMerge with
settling-by-default, keeping only the v2 shell-shape delta in
threadSettled. The unpin confirmation (#7313) merges into the v2
thread-actions hook, and the mobile list tests re-sync to main's
reverted semantics in v2 shapes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): restore the full-screen file-drop target over the chat column

Main's #6636 workspace file drop (drag anywhere over the chat column to
attach, with the dashed overlay) split across ChatView and the
composer. The round-10 rebase restored ChatView from the pre-#6636
backup wholesale and only the composer half was ever re-applied, so
the drop target, overlay, and drag-state plumbing vanished while
addDroppedFiles sat unused on the composer handle. Re-applies main's
ChatView half verbatim; the shared workspaceFileDrop module was
already identical to main.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(server): claim uploaded attachments at v2 dispatch

Closes the last gap from the rebase follow-up list (#8048/#8161 for
v2): pending uploads staged via the attachment upload URL flow were
never claimed by the v2 orchestrator, so the composer kept
supportsAttachmentUploads off and fell back to inline dataUrls with no
progress UI and no big-file support.

message.dispatch and thread.launch now claim pending refs at intake —
verify the staged file, copy it under a thread-scoped id (the pending
copy stays as the retry source), rewrite the refs, and release the
claimed copies if the dispatch fails. A launch carrying uploads
requires its thread id up front. The web composer reads the
attachmentUploads capability again like main, which lights up the
upload progress overlay, retry-on-failure, and PDF/ZIP attachments.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(web): show attachments on queued messages and edit them in the composer

Queued rows now render image thumbnails, and the pencil action loads the
queued message into the composer instead of an inline input: text and
stored attachments are editable (attachments removable, new images
addable), sending saves the queued run in place, and the user's own
draft is stashed untouched for the duration. queued-run.edit gains an
optional full-replacement attachments list end to end.

Built by Claude Fable 5 on Claude Code.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): drag-to-reorder queued messages and retire stale pending rows

Replaces the queue rows' up/down arrow buttons with a drag handle (arrow
keys still work on the focused handle). Also prunes optimistic queued
messages once the projection holds them: keying the prune on turn items
alone left a phantom clock row behind whenever a queued run was removed
or steered before it ever started.

Built by Claude Fable 5 on Claude Code.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: reconcile main's round-14 features after the rebase

Round-14 rebase onto main (7 commits, mostly the Expo SDK 57 upgrade
plus the mobile glass restore and codex app-server buffering fix). The
mobile composer merged main's restored glass chrome onto the v2 body,
and the lockfile is regenerated from main's SDK-57 lock with the
branch's extra dependencies installed on top.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): dedupe the composer glass styles and align the chat column width

The rebase left a stale early copy of the composer glass-host, context-strip,
and shape() fallback rules that the identical later block always overrode.
The composer shell and queue/context strips also kept main's 48rem width while
the timeline moved to the 46rem content lane; they now share
--chat-content-max-width so one owner defines the chat column.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(mobile): replace remaining dark: utilities with adaptive semantic tokens

The v2 thread surfaces still styled borders, fills, and status text with
dark:/light: pairs, which do not follow registered custom themes and now fail
the no-mobile-uniwind-theme-escape-hatches lint. Convert them to adaptive
tokens, adding the missing amber/sky badge and neutral hairline/fill entries
to the theme generator.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(lint): allowlist the queue and relationships interop boundaries

ThreadQueueControl and ThreadRelationshipsBanner read theme variables only to
tint SymbolView icons and color native modal chrome, the same reviewed interop
pattern as the existing thread-feed entries.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(server): inject HostProcessPlatform into the Grok plan extractor

The plan.md path check read process.platform and process.env directly; thread
the host platform reference and the adapter's provider environment through
GrokAdapterV2Options instead.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* chore: retrigger ci

The pull_request workflows never fired for 6c3b84bbfc; only the
pull_request_target ones ran.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* chore: refresh macroscope ui-consistency check

Its findings were fixed in 9abca06b28 and the review threads are resolved;
the check only re-evaluates on push.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: reconcile main's round-16 features after the rebase

Round-16 rebase onto main (5 commits, headlined by #8236 file
attachments in the client). Main's upload-aware send path — capability
probes, upload await/retry gating, uploaded-ref turn attachments with
dataUrl fallback, draft release on success — is woven into the v2
dispatch flow, timeline user rows render file attachments as download
links with the ChatView download handler, and the provider settings
editor cleanup keeps the branch's environment-field rows. The codex
feedback client flow stays unported, replay testkit configs gained
main's environmentThemesDir, and the rpc/settings/docs unions carry
both sides.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): keep failed tool items in the collapsed group summaries

An ordinary exit-code failure knocked its whole tool group out of the
"Ran N commands" summary (and the live pill mid-run) into the raw
"+N previous tool calls" clamp: v2's derived tone marked any
status=failed item as "error", which the grouping treats as a non-tool
row. That inverts v1's semantics and #8395's muted-failure rule — the
failed lifecycle status already carries the X marker and the summary's
includes-a-failure hint, so the tone override goes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(server): keep Claude session approvals ephemeral

R03: Rescope Claude permission suggestions to the current session and add a whole-tool session rule when the SDK provides no suggestion.

* fix(orchestration): reanchor unsettled threads

Carry unsettledAt through v2 thread state and shells, stamp explicit and activity-driven reactivation, and clear the stamp when settling.

Finding: R11

Implemented by GPT-5.6 Sol in Codex.

* fix(server): observe pre-aborted Claude approvals

R15: Race Claude approval decisions with cancellation while checking already-aborted signals and cleaning up the listener on every exit.

* fix(server): include service launcher in bundle build

Build the service launcher after the clean CLI pack so publish and background-service installation receive the required artifact.

Audit: R01

* fix(orchestration): preserve legacy thread metadata

Import pin order, snooze state, unsettle time, and linked pull requests. Repair prior imports only where the stored v2 property is absent, so later v2 changes remain authoritative.

Finding: R08

Implemented by GPT-5.6 Sol in Codex.

* fix(web): honor disabled legacy plan mode

Force the effective composer interaction mode to build when the legacy plan setting is off, including threads and drafts with a saved plan mode.

Audit: R13

* fix(server): preserve Claude subagent models

R16: Apply authoritative assistant snapshot models to Claude subagents and buffer snapshots that arrive before task_started.

* fix(orchestration): honor migrated thread visibility in search

Use v2 ownership and lifecycle metadata when a legacy transcript belongs to a migrated thread. Legacy transcript rows remain searchable until lazy hydration finishes.

Finding: R09

Implemented by GPT-5.6 Sol in Codex.

* fix(orchestration): recreate missing worktrees before turns

Prune stale git worktree registration and recreate the saved branch at the saved path before provider startup. Recovery remains best effort so normal provider errors still report when repair is impossible.

Finding: R10

Implemented by GPT-5.6 Sol in Codex.

* fix(clients): restore Codex feedback submission

Intercept /feedback in web and mobile, show the upload result and feedback ID in the thread, and block duplicate submissions while an upload is active.

Audit: R12

* fix(server): preserve generic provider attachments

R02: Append persisted paths for every uploaded file on provider sends and steering while reserving native image payloads for supported images.

* fix(web): load workspace markdown images through assets

Classify markdown image sources and request environment-scoped asset URLs for workspace files while leaving ordinary web images direct.

Audit: R17

* fix(web): preserve Windows markdown paths

Normalize drive-path links and image sources before sanitization so file chips and signed workspace images receive usable paths.

Audit: R18

* fix(server): keep current provider context usage

R07: Project Codex last-turn and Claude assistant context usage, and retain the latest usage when terminal provider-turn updates omit it.

* fix(web): restore markdown file chip actions

Keep ordinary file-chip clicks in the in-app preview while restoring modifier-click editor opening, configured editor labels, remote gating, and reveal-in-file-manager actions.

Audit: R19

* fix(web): scope markdown actions to their environment

Use the owning thread or pull request environment for editor, shell, and remote-open actions instead of whichever environment is active. Add a multi-environment regression test for the action hooks.

Audit: R20

Implemented by GPT-5.6 Sol with Codex.

* fix(protocol): reject incompatible orchestration peers

Advertise and validate an explicit orchestration protocol before clients open RPC sessions. Announce the same protocol on WebSocket upgrades so hosts reject older clients before request decoding while preserving existing auth and relay parameters.

Audit: D03

Implemented by GPT-5.6 Sol with Codex.

* docs: explain legacy thread migration

Document which thread metadata and transcript data migrate, which runtime history does not, and how the fresh provider continuation uses the latest 32,000 characters. Add a safe read-only recovery procedure without claiming an export API.

Audit: D02

Written by GPT-5.6 Sol with Codex.

* docs: state portable handoff limits

Explain the eligible timeline items, whitespace-normalized 240-character prefixes, omitted tail risk, and practical preparation for provider or fork handoffs. Distinguish this rule from the legacy import's 32,000-character transcript suffix.

Audit: D04

Written by GPT-5.6 Sol with Codex.

* chore(repo): remove tracked audit scratch files

Remove obsolete implementation plans and the probe write marker so temporary work artifacts no longer ship with the repository.

Audit: H01

Implemented by GPT-5.6 Sol with Codex.

* fix(server): guard OpenCode prompt admission races

R14: Hold idle completion through prompt admission, reconcile status only for the current admission generation, and invalidate admission before abort.

* fix(server): restore Claude structured questions

Project AskUserQuestion as a structured user-input runtime request and return keyed answers to the Claude SDK instead of routing the tool through generic approval.

Finding: R04

Model: GPT-5.6 Sol via Codex

* fix(server): project Claude plans and todos

Translate TodoWrite and ExitPlanMode tool input into canonical todo-list and proposed-plan artifacts so every client can render Claude planning state.

Finding: R05

Model: GPT-5.6 Sol via Codex

* perf(orchestration): bound history reads in SQL

Load at most one turn-item page per thread in a fork lineage before decoding, keyed by the stable history cursor. Restrict message, plan, and handoff reads to that page plus live actionable state so cold opens and older-page requests no longer decode complete historical tables.

Finding: P01

Implemented by GPT-5.6 Sol in Codex.

* perf(orchestration): bound complete thread snapshots

Budget the serialized bounded projection after retaining live control state. Cap historical control arrays and large plan or handoff details only on the bounded route; the full thread-detail route remains available for complete text.

Finding: P02

Implemented by GPT-5.6 Sol in Codex.

* fix(server): restore Claude resume compaction

Pass the automatic compaction window to Claude and route resume-return dialogs through structured user input so users can compact, continue, or permanently dismiss the prompt.

Finding: R06

Model: GPT-5.6 Sol via Codex

* fix(server): allow protocol negotiation in CORS

Permit the canonical orchestration protocol header in browser API preflights so cross-origin web and desktop clients can negotiate compatibility while retaining authorization and DPoP headers.

Finding: D03

Model: GPT-5.6 Sol via Codex

* fix(server): preserve provider usage in persisted turns

Merge terminal provider updates with stored context usage before replacing the SQLite payload. Keep newer usage reports authoritative and verify the persisted projection after reload.

Finding: R07 follow-up

Model: GPT-5.6 Sol via Codex

* fix(server): preserve Claude planning lifecycle

Keep typed plan and todo records distinct from generic tool events, activate captured plans, and supersede older planning state within the owning thread. Ignore nested todo snapshots for the parent and retain identity across duplicate SDK messages.

Finding: R05 follow-up

Model: GPT-5.6 Sol via Codex

* fix(server): normalize Claude question answers

R04 follow-up

Convert client multi-select answer arrays to the comma-separated string shape required by the pinned Claude SDK while preserving single-select strings.

Implemented by GPT-5.6 Sol via Codex.

* fix(server): correlate OpenCode prompt admission

Stale cached user and status events could admit and complete a newly submitted OpenCode prompt. Generate the native message ID before submission and only advance admission when that exact message is observed.

Finding: R14

Implemented by GPT-5.6 Sol with Codex.

* fix(clients): anchor feedback in conversation order

R12 follow-up

Insert persistent feedback blocks by their timestamp within the canonical timeline while preserving projected row order. Keep real optimistic sends appended and suppress duplicate local messages already committed by the server.

Implemented by GPT-5.6 Sol via Codex.

* fix(web): retain markdown workspace ownership

R20 follow-up

Give inspector reasoning markdown its projected source thread and retain the explicit environment fallback for proposed plans without a thread reference. Workspace links and images now resolve through their owning environment after removal of the active-environment fallback.

Implemented by GPT-5.6 Sol via Codex.

* fix(orchestration): page history through its true end

Read the inclusive cursor, a full history page, and a look-behind row so older history does not terminate after one page.

Finding: P01 pagination termination

Model: GPT-5.6 Sol via Codex

* fix(server): cancel pending OpenCode prompts safely

Cancel pending SDK requests before aborting the native session. Preserve per-admission cancellation state and treat stopped initial prompts as interruption instead of provider failure.

Finding: R14 prompt cancellation

Model: GPT-5.6 Sol via Codex

* fix(orchestration): retain nested fork history when paging

Keep the original cursor owner through ancestor traversal and preserve the history budget across empty intermediate forks. Verify exact paged history against the complete nested projection.

Finding: P01 nested lineage

Model: GPT-5.6 Sol via Codex

* fix(server): recover OpenCode status reconciliation

Retain pending admission after transient status failures and use one generation-owned retry worker. Ignore stale timers and duplicate evidence so older prompts cannot finish newer steering.

Finding: R14 status reconciliation

Model: GPT-5.6 Sol via Codex

* fix(orchestration): select visible history before limiting SQL

Keep hidden local and inherited rows from consuming history pages. Preserve stop-request dependencies, source-run cutoffs, and imported history while loading related metadata from the selected cohort and using indexed watermark lookups.

Finding: P01 bounded history visibility

Model: GPT-5.6 Sol via Codex

* fix(web): port composer activity and grouping to orchestration v2

* fix(web): align queue headers and prevent stash overlap

* fix(web): share the outline for joined composer tabs

* fix(web): keep stash separate from the composer activity column

* refactor(web): use shared banner rows for queued messages

* fix(web): keep queued message editing inside the queue panel

* fix(web): keep queued messages in place while editing

* fix(web): match composer actions to draft and modifier state

* fix(web): keep composer shortcut tooltip stable on Mod

* feat(web): summarize T3 orchestration actions

* feat(mobile): port chat summaries and transitions to orchestration v2

Adapt grouped tool summaries and the floating working timer to V2 run, attempt, and queue state. Bring over the composer, keyboard, and disclosure transitions while retaining the V2 activity inspector and queue controls.

Keep OV2 web composer and grouping behavior intact; share only the existing command label parser with mobile.

* fix(chat): remove added tool summary status counts

* fix(mobile): keep scroll bounds current after animations

* fix: reconcile main's round-17 features after the rebase

Restores main features dropped by the policy replay: #8569 theme wiring,
settings search rework, #8803 workspace-mutation refresh (v2-adapted),
video + image previews (web and mobile, v2-adapted), #8862 Expo glass,
and the round's docs. Timeline thinking rows (#8984) stay on the v2
work-live system.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(web): port working and thinking timeline rows to orchestration v2

The v2 equivalents of main's #8984 and #8922: a "Working for ..." header
anchors the active run, the trailing live tool row survives between
actions in past tense instead of vanishing, and a shimmering Thinking
row marks reasoning gaps. During workspace preparation the header shows
"Setting up worktree..." (driven by the local dispatch flag or the v2
run's preparing status, so remote viewers see it too), the composer
footer span is gone, and draft promotion waits until the run starts or
startup fails instead of navigating mid-preparation.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: reconcile main's round-18 features after the rebase

Adopts the round's main features into the v2 architecture: the #9023
media rework (streamed videos, media-file assets, protocol-relative
links), #9098 shared live-activity row folded into the v2 working and
thinking rows, the #9084/#9078 Claude model catalog for v2 consumers,
a native #9005 OpenCode child-session abort in the v2 adapter, #9013's
landed LegendList patch, and per-environment sidebar provider entries.
For #8600 the server-side pieces land, but auto-settle evaluation stays
client-side (reading the new server-owned settings) until the v2
orchestrator grows its own settlement reactor; main's v1-only reactor
and coalescer additions are dro…
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL 1,000+ effective changed lines (test files excluded in mixed PRs). vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants