pingdotgg/t3code. All authors. Drafts included. Default branch main. 570 issue assessments and 925 PR assessments. Initial inventory: 570 open issues and 924 open PRs. Current assessed open inventory: 570 issues and 924 PRs. Final reconciliation: 2026-09-01T11:57:41.491617+00:00.
Request. Let users reorder active unpinned threads and keep that order in the browser.
Audit finding. Main only makes pinned rows sortable and sorts active rows by their activity anchor. The patch adds local persisted active order, preserves hidden project slots, and updates sidebar deletion fallback. Pinned order is server-synced while this order is browser-only, and other delete entry points still omit the new preferred order, so the storage and navigation rules need a deliberate decision.
Recommendation. Keep open: decision needed. Decide whether active order should sync across clients, then make every deletion entry point use the chosen order.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Stop implicit project model defaults from overriding the last selected model.
Audit finding. Main still writes a concrete model during bootstrap, CLI add, and command-palette project creation. This patch stops those writes but migrates only bare legacy Codex defaults, so it leaves newer implicit model values reported in the related issue. Its migration cannot distinguish an intentional creation-time value with the same shape, and another open PR proposes broader cleanup plus Codex config defaults.
Recommendation. Keep open: decision needed. Choose one migration policy with the broader defaults proposal and explicitly test intentional creation-time values.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Add an isolated native GLM profile with parent and child model verification.
Audit finding. Main allows configured Codex models but has no named GLM profile policy or post-turn profile proof enforcement. This PR hard-codes one profile, changes child attribution and terminates sessions when proof fails, beyond a model-picker addition. The author explicitly says this is an external-system CI mirror and must not be merged or activated from GitHub.
Recommendation. Keep open: decision needed. Ask the author whether a separate upstream proposal is intended and keep this mirror out of the merge queue.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. The profile policy and selected integration code were inspected, but the full 27-file diff was not reviewed. The external review system named in the PR was not accessed. Only selected current review findings were read. The complete discussion and resolved review history were not reviewed. Latest-head required check results are absent for Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Expose project-scoped thread organization and deletion through orchestrator MCP.
Audit finding. The intended four commits add typed organization fields, batch actions, permanent deletion, and an atomic pending-request archive guard. Main has neither this MCP toolkit nor its unmerged orchestration prerequisite, and the recorded PR base now produces a 954-file, 14 MB diff rather than the intended 15-file change. The intended code can be identified, but the actual PR comparison is not a trustworthy merge scope.
Recommendation. Keep open: evidence needed. Retarget the PR to the preserved prerequisite snapshot and request review of the intended four commits.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-09-01T05:36:37Z. Draft no. Target t3code/codex-turn-mapping. Head 938895bc356d5ff205f3ea3a5d760b44b7acd422. Branch agents/mcp-thread-state/organization. Size +193107 / -102178, 954 files, 328 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Check: GitHub check. Current-head Test Server 3 fails, so aggregate Test success is not sufficient.
Limits. The current 954-file PR diff was not reviewed in full. The intended contracts and mutation paths were inspected separately from the rewritten base, but this does not validate the current PR comparison. Test Server 3 fails on the current head despite the aggregate Test check succeeding; its cause was not investigated. An older related reference could not be retrieved from GitHub. It is excluded from verified dependencies and fix evidence.
Request. Let agents list, read, create, update, and delete project records through MCP.
Audit finding. Main has project mutation commands and preview MCP tools but no project-management toolkit. The inspected contracts and service add clone-or-directory creation, explicit-null defaults, and record-only cascade deletion. The actual base is t3code/codex-turn-mapping rather than the stated isolated rollout base, leaving a large unrelated diff and an unmerged V2 dependency.
Recommendation. Keep open: work remains. Restore a focused project-management review base for the V2 rollout.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-09-01T05:36:37Z. Draft no. Target t3code/codex-turn-mapping. Head 4e9c9a50cd3789059e364ff93f948b580525e0ac. Branch agents/mcp-projects/management. Size +195492 / -102232, 965 files, 339 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Limits. The full retargeted diff is about 14 MB and contains over 950 files. Only the feature-specific portions were inspected. An older related reference could not be retrieved from GitHub. It is excluded from verified dependencies and fix evidence.
Request. Launch and manage MCP threads in a selected project with explicit workspace strategies.
Audit finding. The diff adds projectId, root and worktree strategies, expected-branch checks, and policy ceilings in ThreadLaunchService. None of this orchestration MCP path exists on pinned main. It depends on the open project-management layer, so its passing branch checks cannot establish an independently mergeable main change.
Recommendation. Keep open: work remains. Review project targeting after the project-management dependency has a stable rollout base.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-08-30T20:41:34Z. Draft no. Target agents/mcp-projects/management. Head c0063cd63f3f3c1d900573f4a90151922eac6f03. Branch agents/mcp-projects/targeted-threads. Size +2731 / -206, 20 files, 16 commits. Mergeability MERGEABLE. Merge state UNSTABLE. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #8677. Required project contracts, mutation locks, and selection service are still open.
Limits. The 20-file, 194 KB diff was inspected for contracts and launch behavior but not reviewed in full. An older related reference could not be retrieved from GitHub. It is excluded from verified dependencies and fix evidence.
Request. Let an agent move its thread between branches, project roots, and worktrees.
Audit finding. The inspected contract adds checkout targets and explicit partial-failure reporting, while the branch depends on V2 workspace inventory. Pinned main has no t3_thread_checkout MCP registration. This is not worktree retention or pruning, and the separate lifecycle proposal is not a replacement.
Recommendation. Keep open: work remains. Complete the checkout and rollback review after workspace inventory lands in the rollout stack.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-08-30T20:44:06Z. Draft no. Target agents/mcp-workspaces/inventory. Head 0e3839f3b794914aac1353e6ebe03d7ffa9d2c76. Branch agents/mcp-workspaces/checkout. Size +3653 / -324, 17 files, 17 commits. Mergeability MERGEABLE. Merge state UNSTABLE. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #8685. Checkout depends on this open workspace inventory layer.
Limits. The 17-file, 202 KB diff was not reviewed in full, including all Git race and rollback paths. An older related reference could not be retrieved from GitHub. It is excluded from verified dependencies and fix evidence.
Request. Let an active agent schedule settlement or archival after its current run completes.
Audit finding. The proposal adds a durable run-bound organization intent with read and cancel operations. Main server-side settlement does not expose that deferred agent request or archive-after-run behavior. This remains a V2 lifecycle extension on the open organization layer, not a fix already supplied by server settlement.
Recommendation. Keep open: work remains. Review the deferred-intent lifecycle after the immediate organization layer is integrated.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-08-30T20:45:03Z. Draft no. Target agents/mcp-thread-state/organization. Head 284b9dca6933303a56fe7ce10748847444cfe2e7. Branch agents/mcp-thread-state/deferred. Size +1469 / -21, 20 files, 8 commits. Mergeability MERGEABLE. Merge state UNSTABLE. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Limits. The 20-file, 91 KB diff was not reviewed in full, including startup recovery and terminal-run tests. An older related reference could not be retrieved from GitHub. It is excluded from verified dependencies and fix evidence.
Audit finding. The inspected contracts distinguish recorded state, actual branch and dirty state, missing entries, bounded bindings, and pagination. Main has Git ref APIs but no t3_worktree_list or enriched MCP status result. Its actual retargeted base includes the unmerged V2 rollout, and checkout mutations remain a separate dependent PR.
Recommendation. Keep open: work remains. Restore the inventory-only review diff on the intended V2 rollout base.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-09-01T05:36:36Z. Draft no. Target t3code/codex-turn-mapping. Head 9eaeae02a118a77cd3449be72c516b1d2921b0e7. Branch agents/mcp-workspaces/inventory. Size +193483 / -102212, 957 files, 338 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #8680. Dependent checkout mutation is separate from this read-only inventory.
Limits. The full retargeted diff is about 14 MB and contains over 950 files. Only the feature-specific portions were inspected. An older related reference could not be retrieved from GitHub. It is excluded from verified dependencies and fix evidence.
Request. Persist linked pull request metadata in the proposed V2 orchestrator, including unlink and projection rebuilds.
Audit finding. The intended commit adds the missing V2 metadata assignment and a link/rebuild/unlink lifecycle test. Main uses the older orchestrator and already persists its own link field, which does not prove the V2 defect fixed. The PR targets a feature branch and currently includes 953 files of prerequisite changes, so its narrow commit is not a main fix.
Recommendation. Keep open: work remains. Repair the stack base so this PR exposes only the two-file V2 metadata change for review.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-09-01T05:36:36Z. Draft no. Target t3code/codex-turn-mapping. Head 7bc232e6bea476bcd43c82c780aa9f83f9c823d5. Branch agents/mcp-thread-metadata/persistence. Size +192192 / -102178, 953 files, 325 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Commit: Commit 7bc232e6bea4. The intended V2 change is three production lines plus its lifecycle test.
Check: GitHub check. Test Server 3 failed on the inspected head.
Limits. The complete 14 MB, 953-file PR diff was not reviewed. The intended two-file commit was reviewed. GitHub reports merge conflicts with the target branch. Latest head has failing checks: Test Server 3. Failure logs were not triaged in this audit. An older related reference could not be retrieved from GitHub. It is excluded from verified dependencies and fix evidence.
Request. Let provider agents rename threads, regenerate titles, and link or unlink pull requests through MCP.
Audit finding. Main has only the preview MCP capability and no thread-metadata tool. The patch adds all four actions, project-scoped lookup, receipt-based retries, and matching read state, with the reviewed idempotency and missing-caller cases corrected. It depends on unmerged V2 linked-PR persistence in PR #8689, and CI fails the same four OpenCode V2 replay scenarios as the other native MCP stack branches.
Recommendation. Keep open: work remains. Fix the four OpenCode replay scenarios on the shared V2 base, then land the linked-PR prerequisite before this tool.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-08-30T20:21:37Z. Draft no. Target agents/mcp-thread-metadata/persistence. Head 13b1c0a15097a8ef0f46310af92d43ba02e7ef39. Branch agents/mcp-thread-metadata/update. Size +773 / -5, 16 files, 5 commits. Mergeability MERGEABLE. Merge state UNSTABLE. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Request. Allow an agent to read and change an existing project thread configuration through MCP.
Audit finding. The new service validates provider choices and caller permission ceilings and uses V2 receipts for configuration retries. Main registers preview tools only and has neither these tools nor the V2 command model they require. This is pending feature-branch work, not a duplicate of a landed main configuration fix.
Recommendation. Keep open: decision needed. Review the configuration service and dispatch-lock changes after the V2 base is fixed for landing.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-09-01T05:36:37Z. Draft no. Target t3code/codex-turn-mapping. Head 8c07d9190b7e6a69967cb9596535427d66cf32bf. Branch agents/mcp-conversations/configuration. Size +194568 / -102178, 958 files, 328 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #8695. Feature service and commit history were inspected separately from the 958-file base diff.
Limits. The complete 958-file diff was not reviewed. The V2 base is not an ancestor of pinned main. GitHub reports merge conflicts at the reviewed head.
Request. Create durable conversation forks and inspect their transfer records through scoped MCP tools.
Audit finding. The new transfer service selects completed source runs, checks same-project authority and mode ceilings, and derives retry-stable fork identities. Pinned main has no conversation-transfer MCP tools or V2 transfer contracts. The merge-back proposal depends on this branch, so it remains active stack work rather than a main fix.
Recommendation. Keep open: decision needed. Review the fork layer with its V2 base before the dependent merge-back layer.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-09-01T05:36:37Z. Draft no. Target t3code/codex-turn-mapping. Head 9fb708321bbe4717656aba85f98a93e43bfde159. Branch agents/mcp-conversations/fork. Size +193407 / -102178, 958 files, 326 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #8696. The complete new ConversationTransferMcpService was read, but not the entire base diff.
Limits. The complete 958-file diff was not reviewed. The V2 base is not an ancestor of pinned main. GitHub reports merge conflicts at the reviewed head. An older related reference could not be retrieved from GitHub. It is excluded from verified dependencies and fix evidence.
Request. Return a completed fork conversation to its original parent through MCP.
Audit finding. Main does not register conversation-fork or merge-back MCP tools. The proposal adds lineage checks and a receipt-backed context transfer consumed by a later parent turn, not a Git merge. It is still the upper layer of the open conversation-transfer stack.
Recommendation. Keep open: work remains. Review merge-back after the conversation-fork dependency has been integrated.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-08-30T20:43:58Z. Draft no. Target agents/mcp-conversations/fork. Head efbb1863ab254b0cabe6e816681861a28ba08e13. Branch agents/mcp-conversations/merge-back. Size +808 / -27, 16 files, 3 commits. Mergeability MERGEABLE. Merge state UNSTABLE. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #8696. Open lower layer supplies the conversation transfer service and fork provenance.
Limits. The 16-file, 56 KB diff was not reviewed in full, including provider consumption and retry integration tests. An older related reference could not be retrieved from GitHub. It is excluded from verified dependencies and fix evidence.
Request. Let agents inspect, edit, reorder, cancel, and promote queued thread work through MCP.
Audit finding. The inspected QueueMcpService keeps targets within the caller project, uses durable receipts, and applies fresh permission ceilings to edit and promote. Main exposes none of the queue MCP tools. The public diff includes the unrelated V2 rollout after retargeting, so this remains queue-control work awaiting a focused review.
Recommendation. Keep open: work remains. Restore a focused queue-tool diff and review it against the final V2 dispatch APIs.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-09-01T05:36:37Z. Draft no. Target t3code/codex-turn-mapping. Head e2f3c0f77de313c08caf40e9ca20cd64b1fe4eae. Branch agents/mcp-queue-inputs/controls. Size +194032 / -102178, 960 files, 333 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Request. Let MCP thread creation and send operations use signed attachment references.
Audit finding. Main supports user attachment uploads but does not expose the proposed MCP upload-preparation or discard tools. The inspected service reuses signed uploads, rejects discard of thread-owned files, and returns metadata rather than bytes. Provider-specific thread claiming and retry behavior remain part of the unmerged V2 branch, so the recent client attachment feature does not close this MCP scope.
Recommendation. Keep open: work remains. Restore an attachment-only review diff on the V2 rollout base.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-09-01T05:36:37Z. Draft no. Target t3code/codex-turn-mapping. Head 31682e6ea5f7a68b8dd6f4e76f8cbeffbb9de2d7. Branch agents/mcp-queue-inputs/attachments. Size +193998 / -102178, 962 files, 336 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Request. Expose bounded, project-scoped checkpoint listing and diff inspection through MCP.
Audit finding. Main registers preview MCP tools but has no checkpoint list or diff toolkit and no V2 checkpoint projection. The intended changes validate scope/ref identity, page checkpoint metadata, and report provider restore blockers. This PR targets an unmerged foundation branch and its full diff includes 960 files, so the tools are not available on main.
Recommendation. Keep open: work remains. Restore a narrow stack diff and complete the checkpoint-tool review before merging its dependent restore PR.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-09-01T05:36:37Z. Draft no. Target t3code/codex-turn-mapping. Head 09971c67b215895538353552ccbea40fdae6c4c6. Branch agents/mcp-checkpoints/inspect. Size +193437 / -102178, 960 files, 328 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Check: GitHub check. Test Server 3 failed on the inspected head.
Limits. The complete 14 MB, 960-file PR diff was not reviewed. Intended checkpoint service, contracts, registration, and restore-support changes were inspected. GitHub reports merge conflicts with the target branch. Latest head has failing checks: Test Server 3. Failure logs were not triaged in this audit. An older related reference could not be retrieved from GitHub. It is excluded from verified dependencies and fix evidence.
Request. Let MCP request and observe a guarded, idempotent durable checkpoint restore.
Audit finding. Main has no checkpoint MCP restore tool, and this branch depends on the unmerged V2 inspection stack. The inspected contract permits expectedWorkspaceFingerprint without expectedIdle, while process-loss recovery treats a rollback as guarded only when both fields exist. That current review finding matches the code and can leave fingerprint-only restores on the replay path. The full destructive-restore diff still needs review.
Recommendation. Keep open: work remains. Require the restore guard fields together or treat every fingerprinted restore as guarded before the full safety review.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-08-30T20:22:57Z. Draft no. Target agents/mcp-checkpoints/inspect. Head 221eb619a806c845a4931bb21a75075c28885265. Branch agents/mcp-checkpoints/restore. Size +3150 / -185, 32 files, 12 commits. Mergeability MERGEABLE. Merge state UNSTABLE. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Comment: Discussion comment. The MCP result also forwards raw worker failure text instead of a bounded status description.
Limits. The full 186 KB diff was not reviewed. Tool contract, fingerprint, idempotency interface, dispatch-lock, and process-loss paths were inspected. Latest head has failing checks: Test Server 3, Macroscope - Effect Service Conventions. Failure logs were not triaged in this audit. An older related reference could not be retrieved from GitHub. It is excluded from verified dependencies and fix evidence.
Request. Expose project-scoped managed terminal operations to agents through MCP.
Audit finding. Main registers no managed-terminal MCP tools and has none of the required V2 admission services. The inspected service enforces caller and target policy, bounds in-memory reads, and reports input acceptance rather than shell success. The PR changes terminal incarnation and event ordering inside a conflicting 964-file, 14 MB diff that was not completely reviewed. CI also fails four OpenCode V2 replay scenarios and the Effect Service Conventions check.
Recommendation. Keep open: work remains. Restore a focused diff on the agreed V2 stack base, then review terminal event ordering and rerun its failing checks.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-09-01T05:36:37Z. Draft no. Target t3code/codex-turn-mapping. Head 8116d35b35d341f1daa54f5973ace73dadbd314d. Branch agents/mcp-terminals/controls. Size +194713 / -102292, 964 files, 329 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Check: GitHub check. Head 8116d35 fails four OpenCode scenarios in OrchestratorReplayFixtures.integration.test.ts while waiting for idle.
Limits. The full 964-file diff, Manager changes, and all embedded dependency changes were not completely reviewed. The four shared OpenCode replay failures were identified in CI logs, but their root cause was not isolated. The current head conflicts with main, and post-rebase checks are not available.
Request. Let agents list, run, and stop saved project scripts in dedicated managed terminals.
Audit finding. The reviewed implementation binds stop authority to a terminal incarnation and handles terminal invalidation without accepting arbitrary command text. Main has neither the terminal MCP controls it calls nor the V2 toolkit registration. This is an upper stack layer on PR 8707, so it cannot be treated as an independent main-ready fix.
Recommendation. Keep open: decision needed. Review and land the managed-terminal dependency before the saved-script layer.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-08-30T20:19:23Z. Draft no. Target agents/mcp-terminals/controls. Head a2ab88a9ade8359fd7a8449148187e2a1e1e2598. Branch agents/mcp-terminals/scripts. Size +1367 / -2, 17 files, 3 commits. Mergeability MERGEABLE. Merge state UNSTABLE. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Limits. All production changes were read, but the complete test diff was not reviewed. The managed-terminal and V2 dependencies are not on pinned main. An older related reference could not be retrieved from GitHub. It is excluded from verified dependencies and fix evidence.
Request. Let a parent agent read and answer direct delegated-child user questions through MCP.
Audit finding. The new service limits discovery to app-owned children and user-input requests, bounds pages and question payloads, and replays accepted response receipts. Main has no pending-request MCP toolkit or V2 request-response policy model. The feature is still a V2 sibling branch and does not replace general approval or stop-question handling.
Recommendation. Keep open: decision needed. Review delegated-child authority and idempotent response behavior with the V2 integration.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-09-01T05:36:37Z. Draft no. Target t3code/codex-turn-mapping. Head 894490d2d3ed2d6119aa92f13dde15af667c90f9. Branch agents/mcp-queue-inputs/pending-requests. Size +194364 / -102178, 961 files, 332 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #8716. Inspected pending-request service scope, pagination, validation, and response path.
Limits. The complete 961-file diff was not reviewed. The V2 base is not an ancestor of pinned main. GitHub reports merge conflicts at the reviewed head.
Request. Add bounded project-scoped search over durable thread titles and messages.
Audit finding. Main has legacy global thread search but no searchThreadContent service with V2-visible anchors. This proposal adds a separate bounded query with archive opt-in and visibility rules for rolled-back, queued, and inherited content. The actual retargeted diff includes the unmerged V2 data model, so the scope is not covered by existing global search.
Recommendation. Keep open: work remains. Restore the bounded-query diff against the intended V2 projection base.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-09-01T05:36:36Z. Draft no. Target t3code/codex-turn-mapping. Head d22f88dbc8d801f1761a3006c5167ae94aa08a0b. Branch agents/mcp-thread-search/search. Size +192993 / -102177, 953 files, 328 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Request. Expose project-scoped thread search and stable message read anchors through MCP.
Audit finding. The inspected service checks caller and target project shells and maps bounded search hits to stable source-thread and message anchors. Its read change rejects stale anchors rather than using storage positions. Main has neither this toolkit nor the required V2 search query, so the lower search layer must be integrated first.
Recommendation. Keep open: work remains. Review MCP hit-to-read behavior after the bounded search query is integrated.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-08-30T20:44:43Z. Draft no. Target agents/mcp-thread-search/search. Head 37bc3762ccfc2abd27f7fce6a8db6aeeb9f0b7d5. Branch agents/mcp-thread-search/tool. Size +466 / -13, 13 files, 1 commits. Mergeability MERGEABLE. Merge state UNSTABLE. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Request. Let MCP agents list thread-owned preview tabs and close an exact tab.
Audit finding. Main has client list and close operations but no preview_list or preview_close MCP tools. The reviewed service adds thread-scoped pagination and exact close with broker cleanup. Its 964-file diff includes an unmerged orchestration base, so the claimed standalone feature cannot be assessed as a small ready-to-merge patch.
Recommendation. Keep open: work remains. Retarget the list-and-close slice to its intended orchestration base and produce a feature-only diff.
Confidence low. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-09-01T05:36:36Z. Draft no. Target t3code/codex-turn-mapping. Head 76b5db2d6e8e7b2a4a25e305e4a4b368cb8cd19a. Branch agents/mcp-preview-controls/list-close. Size +193271 / -102260, 964 files, 328 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Limits. The 14,132,237-byte diff was not fully read. Review covered the named feature paths and current main, not every file or test. GitHub reports merge conflicts with the current base.
Request. Expose bounded current-environment identity, capabilities, provider health, and safe preferences through MCP.
Audit finding. Pinned main only registers preview MCP tools and does not expose t3_environment_read. The intended service uses an environment-bound orchestration capability and explicit redacted fields, but the submitted diff spans 961 files because it targets the open orchestrator branch. The whole stack was not reviewed, so there is no basis to call it landed or safe to merge.
Recommendation. Keep open: work remains. Retarget the feature onto its intended reviewed orchestration base and produce a small current diff.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-09-01T05:36:36Z. Draft no. Target t3code/codex-turn-mapping. Head 0775269476cdf90303985e3e3d11bcbd512747a7. Branch agents/mcp-environment/read. Size +193021 / -102178, 961 files, 328 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #2829. The PR targets this still-open orchestrator branch.
Pr: PR #8728. The dependent preference-update PR relies on this environment read layer.
Limits. The complete submitted diff is about 14 MB across 961 files. The intended environment service, toolkit, and contracts were inspected, not the whole stack. GitHub reports merge conflicts with the current base. Current review checks still fail: Macroscope - Effect Service Conventions.
Request. Allow full-access agents to update a narrow set of durable environment preferences through MCP.
Audit finding. Main has the underlying server settings but no environment MCP read or update tool. The patch checks caller policy under the V2 dispatch lock through persistence and tests a concurrent downgrade. The custom-profile review is a false positive because the input schema allows only three presets. It depends on unmerged PR #8726 and the V2 runtime, whose CI fails four OpenCode replay scenarios while waiting for idle.
Recommendation. Keep open: work remains. Fix the shared V2 OpenCode replay failures and land the environment-read prerequisite before this mutation tool.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-08-30T20:19:50Z. Draft no. Target agents/mcp-environment/read. Head 57a6aeb014bb99d40710d930d0b4fb91528a3ca9. Branch agents/mcp-environment/preferences. Size +657 / -24, 16 files, 5 commits. Mergeability MERGEABLE. Merge state UNSTABLE. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Request. Expose bounded token and cost usage summaries for the current environment through MCP.
Audit finding. Main has UsageService and recent incremental transcript scanning, but no t3_environment_usage registration. The intended service validates daily and hourly windows and removes paths and raw diagnostics, while still permitting existing scan and pricing-cache work. The submitted 959-file diff includes the unmerged orchestrator base and was not fully reviewed, so it is not a safe-merge candidate.
Recommendation. Keep open: work remains. Retarget the usage tool onto the reviewed orchestration base and rerun its registration tests on a small diff.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-09-01T05:36:36Z. Draft no. Target t3code/codex-turn-mapping. Head 9114fbc46eb5ef04f44266c4162f9dda4a0cbe86. Branch agents/mcp-environment/usage. Size +192989 / -102178, 959 files, 329 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #2829. The submitted base is the open orchestrator branch.
Merged pr: PR #9024. Merged scan optimization changes the underlying usage service, not MCP exposure.
Limits. The complete submitted diff is about 14 MB across 959 files. The intended usage service, toolkit, and contracts were inspected, not the whole stack. GitHub reports merge conflicts with the current base. An older related reference could not be retrieved from GitHub. It is excluded from verified dependencies and fix evidence.
Request. Run an existing scheduled task immediately with durable retry identity.
Audit finding. The proposal adds run_scheduled_task_now and a receipt-backed manual scheduler admission path. Pinned main does not expose this scheduled-task MCP API or the V2 scheduler it depends on. The requested guarantee covers duplicate retries and overlap with scheduled runs, not merely launching another thread.
Recommendation. Keep open: work remains. Restore a scheduler-only review diff against the stable V2 rollout base.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-09-01T05:36:36Z. Draft no. Target t3code/codex-turn-mapping. Head c3f04e2a146fac89e7b323a6a9f06853ec496622. Branch agents/mcp-scheduled-tasks/run-now. Size +193936 / -102178, 955 files, 331 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Request. Render images stored outside a project through signed environment-scoped asset URLs.
Audit finding. Main still confines filesystem markdown images to workspace-file assets. The patch replaces those requests with environment-image without an older-server fallback, so existing project images need compatibility handling. It also reuses an extension helper that strips question marks and hash characters from literal file paths, leaving the current filename-validation finding valid.
Recommendation. Keep open: work remains. Preserve older-server image loading and validate literal filesystem extensions before issuing environment-image URLs.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Allow start-from-origin bootstrap to use a base branch that exists only locally.
Audit finding. Main still fetches origin and resolves a remote-tracking commit unconditionally once origin exists. This diff exposes the existing remoteBranchExists helper and skips that resolution for a missing branch. PR #8349 fixes the same user failure by catching resolution errors, while PR #8393 separately changes fetch freshness.
Recommendation. Keep open: work remains. Consolidate this missing-branch fix with PR #8349 and retain real Git coverage.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Preserve completed preview navigation after host setup consumes part of the deadline.
Audit finding. Main still starts one timeout before delivery and removes a request on the first successful response. The complete PR adds a started acknowledgment and a new navigation deadline. New hosts send that acknowledgment unconditionally, so an older server would treat it as final success with no result.
Recommendation. Keep open: work remains. Add version or capability negotiation for started acknowledgments and test new-client to old-server behavior.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Recover connection management when an old desktop catalog cannot be decrypted with the current key.
Audit finding. Main still raises a protection error when safeStorage cannot decrypt the catalog. The patch returns an empty catalog and preserves the original file on read, with tests for key recovery and later replacement. Treating all decrypt failures as empty needs a decision about how the user learns that saved connections remain unreadable.
Recommendation. Keep open: decision needed. Choose the user-visible recovery behavior before accepting silent empty-catalog fallback.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Configure independent Ghostty line and byte limits after upgrading the web and Android engine.
Audit finding. Main has neither the new constructor ABI nor independent scrollback limits. The inspected adapter changes set 10,000 physical lines and a 32 MiB cap, update both artifact builders, and test the production web constructor against actual WASM. This is broader than hotfix #8766 and overlaps upgrade #8563, but it does not change the separate iOS terminal or server history retention.
Recommendation. Keep open: work remains. Reconcile the two Ghostty upgrade revisions and complete native artifact review for the selected patch.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. The vendored header changes and rebuilt native/WASM binaries were not fully audited. The posted recordings are acknowledged to show restored server history, not the complete fresh-output retention scenario. Required Check, Test, Release Smoke, Mobile Native Static Analysis checks are absent on the collected head.
Request. Interrupt repeated empty Codex collaboration waits only when no registered child is live.
Audit finding. Main has child live-turn bookkeeping but no empty-wait watchdog. This diff introduces automatic interruption after three empty wait completions, so it is a new recovery policy rather than a correction to an existing main watchdog. The guard depends on the same late-registration and retryable-error ordering being changed in other child lifecycle PRs.
Recommendation. Keep open: decision needed. Decide whether automatic interruption after three empty waits is wanted before reviewing the guard with child lifecycle changes.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. The runtime guard was inspected, but the full integration-test diff was not reviewed. Latest-head required check results are absent for Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Populate the Cursor skill picker from filesystem skill definitions.
Audit finding. Main Cursor snapshots still contain no discovered skills. The PR adds user and project roots, but calls discovery with process.cwd rather than the selected workspace and ignores the instance environment when choosing the home. Client skill deduplication does not solve either discovery problem, and the workspace catalog proposals must be considered with this change.
Recommendation. Keep open: work remains. Pass the selected workspace and instance environment into Cursor skill discovery.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Remove ignored build artifacts from linked worktrees when their threads settle.
Audit finding. Main has no artifact cleanup setting or reactor. This diff checks settlement and same-project sharing before deleting ignored artifact directories, but it does not serialize cleanup with a resumed turn or terminal activity. Main now emits thread.settled for automatic settlement too, so the PR claim that automatic settlement is out of scope is no longer true.
Recommendation. Keep open: decision needed. Decide the automatic-settle policy and add lifecycle coordination before enabling artifact deletion.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Merged pr: PR #8600. Server-owned settlement expands which events can trigger cleanup.
Pr: PR #8816. Related whole-worktree cleanup introduces lifecycle coordination.
Limits. Latest head has no results for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts with the target branch.
Request. Persist a shared project color and show it in project-identifying UI.
Audit finding. Main exposes project favicons but no project color field or picker. The patch carries color through commands and projections, gates writes by server capability, and includes a clear-color path. Mobile, command palette, and draft project pickers remain explicitly outside its implementation, so the accessibility feature is not complete across clients and entry points.
Recommendation. Keep open: decision needed. Decide the initial client scope and add the missing project-identification views before shipping.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Discover project-local Codex and OpenCode skills for the active workspace.
Audit finding. Main exposes only machine-level provider skills, and mobile reads that same list. The PR adds cwd-specific snapshots and connects the web menus, but leaves mobile selectors unchanged. Once a cwd snapshot exists, refreshWorkspaceSnapshot refuses to probe it again and normal refresh preserves it, so a newly installed project skill has no refresh path.
Recommendation. Keep open: work remains. Add mobile workspace selection and an explicit refresh path for an existing cwd snapshot.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Preserve generic attachment bytes before resetting the native file input.
Audit finding. Main still clears the input before handing its File objects to the async attachment path. The diff snapshots generic files first, but reads all files into memory before existing size limits run and leaves the input reusable while that read is pending. Those paths match the current review concerns about memory exhaustion and successive selections.
Recommendation. Keep open: work remains. Apply staging limits before reading bytes and protect the input against overlapping selections.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Pr: PR #8786. The proposed snapshot reads every generic file concurrently before staging validation.
Comment: Discussion comment. The latest diff reads complete generic files before enforcing the staging limit.
Limits. Latest head has no results for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts with the target branch.
Request. Keep the last Android reply line clear of the composer.
Audit finding. Main still has no content-container bottom padding, but the feed already accounts for composer and keyboard insets. The diff adds 12 points to the shared iOS and Android list, despite the body calling it Android-only. The separate iOS layout PR is not evidence that Android is fixed.
Recommendation. Keep open: retest. Reproduce the Android clipping on current main and verify the padding with both short and long iOS threads.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Check: PR #8800. Current head 34bf7ca2: required checks are absent from canonical latest-commit metadata: Test, Check, Mobile Native Static Analysis, Release Smoke.
Limits. No current Android reproduction or iOS layout comparison. Required CI checks are not present on the current head in canonical check metadata.
Request. Offer native context compaction through a shared command across five providers.
Audit finding. Main has Claude compaction behavior but no shared compactThread service across providers. The inspected diff routes Codex to thread/compact/start without closing the synthetic turn-start created for the slash command, matching an unresolved lifecycle finding. The broader provider routing, failure recovery, and mobile command behavior still require review.
Recommendation. Keep open: work remains. Close the pending Codex compact turn and verify each provider completion path.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Automatically remove clean, idle, managed worktrees after deletion or a configured settlement delay.
Audit finding. Main has no automatic deletion setting, although it can recreate a missing worktree when work resumes. This diff adds clean-state checks, canonical managed-path checks, terminal/session checks, and a global lifecycle lock. Its manual-settle-only description no longer matches main because server-owned automatic settlement creates the same settled state.
Recommendation. Keep open: decision needed. Decide whether automatic settlement also permits deletion, then update eligibility and tests for that policy.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Open a project in an already-running local desktop app with t3 app.
Audit finding. Main has no app subcommand or local desktop activation socket. The reviewed CLI and broker add bounded requests, local path/platform checks, and renderer acknowledgements, and deliberately reject SSH use or an absent desktop app. Native focus and full activation lifecycle verification remain necessary for this new feature.
Recommendation. Keep open: work remains. Verify the local desktop activation lifecycle on supported operating systems.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. The socket, broker, CLI, and renderer handler were reviewed, but not the complete 26-file diff. No Electron window focus or native IPC session was run.
Request. Offer an optional workspace-relative or home-relative label for web and desktop file chips.
Audit finding. Main still renders a basename, optional disambiguating parent, and line position. The diff adds a client-local preference and conservative POSIX, Windows, and UNC formatting while leaving mobile unchanged. This is an unapproved display preference, not a bug already fixed by other markdown work.
Recommendation. Keep open: decision needed. Decide whether the File chip paths preference belongs in the product.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Latest head has no results for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts with the target branch.
Request. Use a neutral working directory for Claude capability probes while preserving config resolution.
Audit finding. Main still passes the server cwd into the capability query, and the merged hook, MCP, and IDE changes do not isolate workspace settings. This diff uses an existing temporary directory and resolves relative config directories before the switch. However, initialization is also the only source of workspace slash commands, so the cwd change drops those commands while only skills are rescanned.
Recommendation. Keep open: work remains. Separate account probing from workspace slash-command discovery before changing the probe cwd.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Stop automatic project defaults and unstored model options from overriding inherited preferences.
Audit finding. Main still persists create-time models and builds dispatch options from catalog defaults. This proposal clears creation defaults at the domain boundary and changes web and mobile option dispatch, while its migration clears all creation values lacking a later default-setting event. The other inheritance PR instead preserves option-bearing creation values and reads Codex config, so the migrations and behavior need one agreed design.
Recommendation. Keep open: decision needed. Choose one migration and explicit-option policy with the related inheritance PR.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Route desktop environment-port previews through an authenticated T3 Connect gateway.
Audit finding. Main still rejects public-relay environment ports because no authenticated preview gateway exists. The reviewed ticket and session code adds port-scoped access and a per-environment desktop proxy, but direct loopback navigation clears that shared proxy. Multi-tab ownership and the competing mobile proxy need review before this can replace the current rejection.
Recommendation. Keep open: work remains. Verify gateway ownership with multiple ports and a simultaneous client-local tab before choosing the shared proxy design.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Pr: PR #8020. The mobile branch proposes another proxy for the same remote dev servers.
Limits. The PR body states that its real MCP gateway flow remains unverified. The 131,159-byte diff was not fully read. Review covered the named feature paths and current main, not every file or test. Current review findings and general discussion were sampled, but historical resolved review threads were not read in full.
Request. Expire DPoP replay markers and reject invalid bootstrap credentials before allocating replay state.
Audit finding. Main creates a permanent secret file for every accepted proof and claims it before token exchange checks the bootstrap credential. The diff adds time-bucketed empty markers, credential preflight, and boundary/failure tests. Its legacy bridge stops after six minutes and then deletes all legacy markers, so the rollout needs an explicit rule for older processes that remain active against the same secrets directory.
Recommendation. Keep open: work remains. Resolve and test the mixed-version legacy-marker cleanup boundary before merging.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Pr: PR #8426. Related scope-preflight work needs a shared grant inspection design.
Limits. The new directory fsync path has no Windows validation in the supplied test report. Required current-head checks are absent: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Extend Cursor behavior while adding P2P connections and changing the app to T3 Pear.
Audit finding. The human body is still an empty PR template, while the inspected diff changes Cursor behavior, adds HyperDHT connections, and replaces the default desktop name and T3 home directory. Main already supports Cursor, but none of those additional changes follow from that fact or the recent Grok fixes. This mixed fork-sized change needs a stated upstream scope before its code can be judged for merge. No Cursor or P2P behavior is supplied. The PR changes settingsUpdated to carry remoteAccess in the old projection function.
Recommendation. Keep open: evidence needed. Ask the author to submit a Cursor-only change with a completed problem statement. Keep its existing scope decision and move remoteAccess handling to serverConfigProjection.ts.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Latest main change. No Cursor or P2P behavior is supplied. The PR changes settingsUpdated to carry remoteAccess in the old projection function. Keep its existing scope decision and move remoteAccess handling to serverConfigProjection.ts.
Limits. The 102-file, 1.17 MB diff was not fully reviewed. Cursor scope, P2P contract and tunnel code, and branding/state-path changes were inspected. The PR author did not provide a problem statement or validation plan. Required checks have no results on this head: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Add context-limit handovers, a 250,000-token default limit, and an eight-turn concurrency limit.
Audit finding. These hard limits and the handover RPC do not exist on main and require an explicit product decision. The inspected mobile route adds hooks after existing early returns, and the reservation is not released for all failures between admission and send. Those source-confirmed failures remain open alongside the wider handover and budget behavior.
Recommendation. Keep open: decision needed. Fix hook ordering and reservation cleanup before reviewing the new hard-limit policy.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Finish the durable session lifecycle when a matching provider turn aborts.
Audit finding. Main still excludes turn.aborted from the lifecycle branch that clears activeTurnId and finalizes buffered output. Recent OpenCode stop fixes ensure the adapter aborts correctly but do not add this ingestion transition. The alternative abort PR uses interrupted session status instead of ready and has broader ordering tests, so the two proposals need one agreed lifecycle rule.
Recommendation. Keep open: work remains. Choose the abort session status and combine the useful tests from both abort PRs.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Use real VCS detection before checkpointing instead of trusting any .git path.
Audit finding. Main still treats the existence of a .git entry as a valid repository. The diff replaces both capture and revert prechecks with CheckpointStore.isGitRepository and adds an incomplete-metadata test. PR #8527 includes the same production precheck change for nested projects, so the implementations should be consolidated without losing either case.
Recommendation. Keep open: work remains. Choose one repository-precheck implementation with PR #8527 and retain both focused tests.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Use grok models for provider health while retaining current skill discovery.
Audit finding. Main still uses ACP model discovery and marks its timeout as an error. This PR preserves the newly merged skills path, but replaces model capability parsing with EMPTY_CAPABILITIES, which removes the reasoning options main gets from ACP model metadata. The lightweight probe remains needed, with that regression fixed before merge.
Recommendation. Keep open: work remains. Preserve reasoning options while replacing the ACP health probe.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Make a new web thread prefer the viewed thread model over the project default.
Audit finding. Main deliberately puts projectDefaultSelection before the carried model after the project-default fix. This PR reverses that order, including for explicitly configured projects. The inherited-default proposals address the seeded-default problem without making the same blanket precedence choice, so these are competing behavior decisions.
Recommendation. Keep open: decision needed. Choose whether an explicit project default or the viewed model takes priority.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Treat every explicit preview URL as client-local while still resolving discovered environment ports.
Audit finding. Main still remaps explicit loopback URLs to a remote environment host. The complete PR stops that remapping for every connection, while the competing relay-only PR preserves LAN and Tailscale remapping. Both are unmerged, and they choose different meanings for an explicit localhost URL.
Recommendation. Keep open: decision needed. Choose the explicit-URL contract, then keep one implementation and its connection-mode tests.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Prevent a trailing provider note from hiding the substantive assistant answer.
Audit finding. Main still folds nonterminal assistant segments, so the hidden-answer defect remains. This diff keeps all messages visible on web and mobile, but leaves a neighboring web test asserting the old row order and still folds native agent-spawn groups. The response-segment proposal makes a different display choice, so the rule and these defects must be settled before merge.
Recommendation. Keep open: decision needed. Choose whether to keep every assistant message visible or fold by complete user response.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Restore inherited project model defaults and honor effective Codex configuration.
Audit finding. Main still seeds project models and applies preferred catalog defaults during Codex probing. The full diff removes automatic seeds, reads Codex config, and migrates model-only creation defaults while retaining option-bearing and later-written defaults. It overlaps the other migration numbered 44 but does not include that PR's cross-provider explicit-option dispatch change.
Recommendation. Keep open: decision needed. Agree on one model-default migration and integrate the complementary provider-option behavior.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Add OpenCode history to the Usage page and live token usage to threads.
Audit finding. Main still has neither OpenCode usage collection nor live token events. The PR adds both, but the accumulator uses separate message and part keys for the same usage, so overlapping assistant and step events can still be counted twice. The stale-event branch also emits the old snapshot with the current turn ID, matching the latest unresolved review finding, and the database resolver ignores configured OPENCODE_DB overrides.
Recommendation. Keep open: work remains. Separate history collection from live metering, then fix cross-event deduplication and stale-turn attribution.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. The stale-event guard still publishes prior-turn usage under the current turn.
Pr: PR #8456. Alternative historical collector handles provider-instance OPENCODE_DB overrides.
Limits. Canonical latest-commit checks do not include Check, Test, Mobile Native Static Analysis, Release Smoke. GitHub reports a merge conflict with current main.
Request. Read archived thread shells and details by exact ID while keeping active lists filtered.
Audit finding. Main exact-ID reads still exclude archived threads, so the requested read fix remains needed. However, this diff also widens getThreadShellById while ws.ts turns every successful result into a live-shell upsert, allowing archived threads to reappear after later events. Its latest-turn lookup still filters out archives, so archived shells also lose turn metadata.
Recommendation. Keep open: work remains. Separate archived exact-ID reads from active-shell upserts and preserve archived latest-turn data.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Add local desktop microphone recording, transcription, and voice settings.
Audit finding. Main has the shared voice controller and iPhone voice input, but no desktop speech bridge. In the proposed desktop code a rejected model-load promise is retained, so preparation retries cannot recover. The composer also leaves submission and editing enabled during voice work, which the shared controller rejects as a stale draft when transcription returns.
Recommendation. Keep open: work remains. Fix preparation retry and wire the shared submission/editor guards before native package verification.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Speech runtime, model download, microphone capture, and composer integration were reviewed, but not all 37 files. Native speech binaries and microphone permissions were not exercised.
Request. Allow explicit client-local localhost URLs when the environment uses T3 Connect.
Audit finding. Main rejects explicit loopback URLs on public relays through environment-port resolution. This patch allows relay-only passthrough, while the competing PR makes all explicit URLs client-local. The current patch also passes 0.0.0.0 through unchanged because the wildcard rewrite is behind the new private-host guard.
Recommendation. Keep open: decision needed. Choose the explicit-URL semantics and preserve wildcard-to-localhost normalization in the selected patch.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Persist OpenCode aborts so durable sessions stop showing running after Stop.
Audit finding. Main emits turn.aborted from the OpenCode adapter but excludes that event from the durable thread-session update and completion cleanup paths. This PR adds turn-start message correlation, preserves prompt errors, and finalizes streamed text and plans, which the child-stop merges did not do. The current diff addresses the reviewed stale-start, steering-token, and pending-start races, but it conflicts with main and still needs integration review against recursive child cancellation.
Recommendation. Keep open: work remains. Rebase and review the durable abort path against current cancellation, then run the focused OpenCode and Codex ingestion tests.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. Reviewed pending-start race is covered by the current retained-token guard and test.
Limits. Canonical latest-commit checks do not include Check, Test, Mobile Native Static Analysis, Release Smoke. GitHub reports a merge conflict with current main.
Request. Upgrade Electron to 44.1.0 and adapt desktop clipboard writes to its asynchronous API.
Audit finding. Main remains on Electron 43.4.1, so the earlier runtime upgrade does not include this major version. The patch migrates screenshot and text writes, but the unresolved review is valid: text-copy rejection becomes an untyped defect and its context-menu caller discards the returned promise. The macOS 13 minimum and incomplete Linux packaged-build result also need an explicit release decision.
Recommendation. Keep open: decision needed. Accept or reject the macOS support-floor change, then require handled clipboard rejection before approving the upgrade.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Stop repeated Git top-level discovery during repository identity lookup and extend metadata cache lifetimes.
Audit finding.PR #8187 already added repositoryRootCache on main and tests repeated lookup reuse, fixing the uncached rev-parse step. This PR still differs by using ten-minute positive TTLs and caching failed root discovery, while main deliberately retries failed discovery immediately. Keep only the remaining cache-policy decision instead of merging a second root-cache implementation.
Recommendation. Keep open: partial fix. Rescope the PR to the remaining TTL and negative-cache policy after measuring current main.
Confidence high. Release: In nightly source. PR readiness: Needs work or a decision.
Merged pr: PR #8187. Landed the root lookup cache, included in the September 1 nightly but not stable v0.0.37.
Limits. Latest head has no results for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts with the target branch.
Request. Restore desktop tab recording after Electron removes the legacy tab media-source path.
Audit finding. Main still uses getMediaSourceId and legacy getUserMedia tab constraints after the recording-quality change. The complete PR replaces them with an exclusive one-use display-media grant. The reported cross-tab requester warning does not match the architecture because the trusted host renderer requests capture and preview guests use separate session partitions. Later open branches extend recording handoff and capture lifetime, so one integration target is still needed.
Recommendation. Keep open: work remains. Choose one recording integration branch after reviewing its current Electron concurrency and capture-lifetime evidence.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Pr: PR #9001. This open branch includes and extends the recording change.
Pr: PR #8981. This open branch includes recording and broader automation lifecycle work.
Limits. The supplied native recording evidence was not replayed in this audit. Current review findings and general discussion were sampled, but historical resolved review threads were not read in full. The collected latest head has no results for these required checks: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Generate and display third-party license notices in web, desktop, and mobile Settings.
Audit finding. Main has static notices but no generated license browser. The generator checks the shared notice map before concurrent reads finish, so sibling notice selection depends on read completion order. Its Windows /@fs/C:/ path conversion also adds an invalid leading slash and can silently skip bundled modules. Merged PR 8970 only changes this feature branch and is not on main, so it does not replace this work.
Recommendation. Keep open: work remains. Make notice selection deterministic and correct Windows module paths before checking packaged notice coverage.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. The shared notice-map race remains in collectRepositoryNotices.
Comment: Discussion comment. moduleFilePath still changes Windows /@fs/C:/ paths into /C:/ paths.
Merged pr: PR #8970. Merged into feat/open-source-licenses, not main. Its merge commit is not an ancestor of pinned main.
Limits. Generator and build integration were reviewed, but the complete 53-file diff and license texts were not verified. PR 8970 landed only on the feature branch, not main.
Request. Configure reasoning effort profiles for manually added Claude gateway models.
Audit finding. Main gives unknown Claude models default empty capabilities and has no customModelProfiles setting. The diff adds validated profiles, exact custom-slug handling, default-effort omission, live effort updates, and profile removal on settings reload. This is a configuration-first feature across contracts and clients, with no profile editor, so its public settings contract needs a maintainer decision.
Recommendation. Keep open: decision needed. Approve the configuration-first profile contract and check default-effort behavior on mobile.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Pr: PR #8409. Both changes add live flag-settings control and need a shared SDK test harness.
Limits. Mobile profile selection was not exercised in this audit. Latest-head required checks are not reported: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Allow project-specific prompts for generated commits, pull requests, branch names, and thread titles.
Audit finding. Main now follows repository instructions for source-control text, but its t3.json schema still has no per-task prompt overrides. The reviewed patch adds those overrides and treats custom branch output as a complete Git-validated name, beyond the existing global writing settings. It still needs a complete review of the provider, worktree, and manual-commit paths.
Recommendation. Keep open: work remains. Review the custom branch and prompt behavior across all generation entry points.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. The prompt resolver, schema, prompt builders, sanitizers, and branch validator were reviewed, but not the complete 30-file diff. GitHub reports merge conflicts at the reviewed head.
Request. Render inline and display math in chat without rewriting code, prices, or links.
Audit finding. Main has no math parser or renderer. The full diff adds KaTeX and a source normalizer, but that normalizer changes the offsets used by editable task lists, rewrites reference-link destinations, and strips blockquote structure. These are shared Markdown regressions in file preview as well as chat, not just missing math edge cases.
Recommendation. Keep open: work remains. Preserve editable source offsets, link destinations, and Markdown container structure before enabling math normalization.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Fold complete user-response segments across synthetic provider continuation turns.
Audit finding. Main groups settled folds by provider turn ID, so the continuation grouping and stable segment identity remain missing. The full diff groups by user boundaries, but it removes the live agent-spawn exception and still clears an expanded fold when the provider turn ID changes before new content arrives. That leaves distinct correctness work and a display-policy overlap with the keep-all-responses proposal.
Recommendation. Keep open: work remains. Preserve live agent controls and expansion across continuation-only turn changes.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Let desktop users follow Nightly update assets from a custom public GitHub repository.
Audit finding. Main selects a repository at build time and has no runtime Custom update track. The patch adds normalized repository settings and return paths to bundled channels, but it also changes macOS app identity, downstream packaging, and install shutdown. The Keychain review remains disputed by a one-machine observation, while the added identity test only asserts setName calls and does not prove existing-secret migration. The operations guide still describes empty-field reset and custom Stable selection, which do not match the final UI.
Recommendation. Keep open: work remains. Verify packaged custom-source migration with existing Stable and Nightly macOS credentials before resolving the Keychain review.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Keep background preview capture usable and drain debugger work before desktop teardown.
Audit finding. Main still parks hidden guests outside the compositor and does not drain preview work in desktop shutdown. The reviewed branch changes both lifetime rules and adopts the display-media recording path, overlapping the snapshot and recording PRs. Its body explicitly lacks the required packaged macOS Electron matrix, so unit results cannot establish native readiness.
Recommendation. Keep open: work remains. Run the packaged macOS capture and teardown matrix after choosing the recording and snapshot integration branches.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Pr: PR #8486. Snapshot deadline and debugger recovery work overlaps this branch.
Pr: PR #9001. Recording and compositor work overlaps this branch.
Limits. The PR reports Linux-only checks and no packaged macOS verification. The 225,690-byte diff was not fully read. Review covered the named feature paths and current main, not every file or test. Current review findings and general discussion were sampled, but historical resolved review threads were not read in full.
Request. Skip CI jobs when changed paths cannot affect their checks while keeping required check names.
Audit finding. Main only gates native mobile analysis by paths and still runs the other jobs unconditionally. The new classifier treats every Markdown file and all .github/triage files as documentation, but the server triagePrompt test reads .github/triage/PLAYBOOK.md and requires exact parity. That direct input is currently skipped, so the claimed complete dependency classification is not ready.
Recommendation. Keep open: work remains. Add the triage prompt dependency and audit other read-time file inputs before enabling the classifier.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Bound thread-detail activity payload hydration before JSON decoding.
Audit finding. The merged snapshot-memory change now projects client payloads in batches of 25 and preserves pinned requests, but does not add this PR's per-payload or aggregate byte caps. The proposed cap uses SQLite text length rather than byte length and replaces large pending-request payloads with markers that omit requestId and action data. Keep the remaining memory-limit work open, but revise it against the current projected-read path.
Recommendation. Keep open: partial fix. Redesign byte limits on current main without discarding pending-request fields.
Confidence high. Release: In nightly source. PR readiness: Needs work or a decision.
Request. Remove complete thread-detail reads from provider completion handling.
Audit finding. The merged selective-read fix skips unrelated activity payloads, but completion paths still hydrate full message and plan detail. This PR has remaining narrow-query work, and its newest-task-row lookup can lose an older title when a later progress or usage row has none. The streaming append fix changes a different projector path and does not close this scope.
Recommendation. Keep open: partial fix. Rebase the narrow queries and select the newest task activity that contains a usable title.
Confidence high. Release: In nightly source. PR readiness: Needs work or a decision.
Request. Restore recording and macOS preview painting after the Electron 43 upgrade.
Audit finding. Main still uses legacy tab capture and parks every hidden preview outside the window. The reviewed branch adds supported display capture, serialized stream handoff, and capture-active compositing while keeping inactive macOS guests paintable. The body supplies Linux package evidence, but that does not verify the macOS blank-preview claim or replace review of the overlapping lifecycle branch.
Recommendation. Keep open: work remains. Verify restored and background previews in packaged macOS Electron before choosing this recording branch.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Pr: PR #8957. This branch preserves the original recording fix.
Pr: PR #8981. A broader background-automation branch overlaps recording and compositing.
Limits. Linux package evidence was supplied, but macOS behavior was not verified in this audit. The 89,312-byte diff was not fully read. Review covered the named feature paths and current main, not every file or test. Current review findings and general discussion were sampled, but historical resolved review threads were not read in full.
Request. Add bounded thread and subagent usage breakdowns with expandable daily costs.
Audit finding. Main has no thread-breakdown RPC or thread table. Publishing head 46d852c fixes zero-cost bars, invalid timestamps, and closed-table refreshes, while retaining the earlier range and project layers. The current UI review still flags the inherited buffered date-input behavior, and the full attribution stack needs a maintainer review.
Recommendation. Keep open: work remains. Resolve the inherited date-input review and review the isolated thread-breakdown layer.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Show estimated cache-write cost separately in usage totals and breakdowns.
Audit finding. Main includes cache creation in total cost but has no separate cache-write amount. Publishing head 00aac0a passes required jobs, but its thread-response schema requires cache-cost fields absent from version 8 even though the client still queries version-8 environments. Codex fallback titles can also select copied parent prompts or injected shell-command context. This accounting feature needs changes in the inherited thread layer before it is ready.
Recommendation. Keep open: work remains. Make the thread-breakdown response compatible with version 8 before merging the cache-write layer.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Source: packages/contracts/src/usage.ts:293. Version 9 requires row cacheWriteUsd and daily cache-write, cache-read, and fresh-cost fields while the minimum thread version remains 8.
Source: packages/contracts/src/usage.ts:269. The current version-8 dependency lacks the required cache-cost fields, although its input already supports the newer filters.
Request. Count final Claude usage snapshots, fallback attempts, and cache-write TTLs correctly.
Audit finding. Pinned main has the merged rate-lookup fix but still keeps first snapshots and lacks iteration and cache-TTL accounting. Head 342fe14 fixes progressive-snapshot deduplication and filtered project shares, and the prior Check failure is gone. The parser still drops model-less compaction iterations, which the installed Anthropic SDK permits, so their tokens remain uncounted. This draft still includes a 35-file stack whose full diff was not reviewed.
Recommendation. Keep open: partial fix. Retain model-less compaction iteration usage and test its accounting before reviewing the full stack.
Confidence medium. Release: In stable source. PR readiness: Needs work or a decision.
Check: GitHub check. Latest-head Check, Test, and Release Smoke pass. Mobile Native Static Analysis is skipped.
Limits. The full 246 KB stacked diff was not reviewed. No transcript replay was run during this audit. The latest GitHub review targets the previous head, not 342fe14.
Request. Refresh usage every thirty minutes and strengthen incremental transcript caching.
Audit finding. Main already resumes appended transcript reads after the merged scanner change, but has no page-lifetime refresh timer. Publishing head e7bdca7 fixes progressive Claude snapshot deduplication and passes current checks. It inherits the version-8 thread-response mismatch from the cache-write layer and still hashes every full transcript before cache reuse. The compatibility defect needs a fix, and the full-file disk cost remains an explicit product choice.
Recommendation. Keep open: partial fix. Resolve the inherited thread-response mismatch before reviewing the refresh and full-file hashing policy.
Confidence medium. Release: Main only. PR readiness: Needs work or a decision.
Request. Keep single tildes literal in web and mobile markdown while retaining double-tilde strikethrough.
Audit finding. Main still uses single-tilde parsing on web and the native parser used by both mobile platforms. This diff requires double tildes in both parsers. The longer-tilde-run review finding is not a new regression because the original native <= 2 guard already rejected runs of three or more. The rendering-policy change needs approval and native build verification.
Recommendation. Keep open: decision needed. Decide whether web and mobile markdown should require double tildes.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. The response correctly notes that both old and new native guards reject longer tilde runs.
Limits. Native behavior was checked with a standalone parser driver, not an integrated mobile build. Latest head has no results for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Preview host media outside the workspace and stream videos through web and mobile file viewers.
Audit finding. Main still rejects external workspace assets, reads selected videos through the existing file path, and fetches full web attachment videos into blobs. The reviewed asset changes add descriptor-bound media capabilities and direct signed-video URLs, which are not supplied by the landed image viewer and video attachment features. The PR leaves legacy Android attachment downloading and Markdown-file media reuse as explicit follow-ups.
Recommendation. Keep open: work remains. Complete the full media diff review and verify the untested iOS and Electron paths before integration.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Pr: PR #8769. Mobile Markdown-file image reuse remains separate open work.
Limits. The PR reports Chromium and Android proof, but no manual iOS or Electron pass. The 328,050-byte diff was not fully read. Review covered the named feature paths and current main, not every file or test. Current review findings and general discussion were sampled, but historical resolved review threads were not read in full.
Request. Stream terminal output and retained history with bounded queues across server, web, desktop, and mobile.
Audit finding. Main still rewrites full terminal history and rebuilds the client buffer for each event. The latest head adds a 50-millisecond SGR mouse-release wait and a process-identity guard. It still drops overflow output before persistence on PTYs without pause support, and its 32-event WebSocket queue still replaces extended replay with a 64 KB snapshot. These source-confirmed losses remain merge blockers.
Recommendation. Keep open: work remains. Fix non-pausable PTY overflow and extended-replay backpressure before another complete terminal review.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Source: apps/server/src/terminal/Manager.ts:518. Current head returns without enqueueing overflow output before persistence; the new mouse-release delay does not change this path.
Source: apps/server/src/ws.ts:2265. Current head still clears its 32-event queue and calls readSnapshot without extended replay preservation.
Check: GitHub check. Required Test, Check, Release Smoke, and Mobile Native Static Analysis passed on this head. Server test shards also passed; Approvability and Bugbot were unfinished when inspected.
Limits. The latest head's Approvability and Bugbot reviews were not complete when inspected. No native mobile build or slow-link terminal run was performed.
Request. Add environment-backed voice transcription for Android and iOS devices without local speech support.
Audit finding. Main only transcribes locally on supported iOS 26 devices, and its voice design document explicitly leaves environment transcription unimplemented. This diff adds server-held credentials, a signed audio route, and per-environment mobile selection. However, the signed token is never consumed, and removing the remote service hides the picker while its saved selection still prevents a local transcriber from being selected, so the advertised one-shot and recovery behavior need fixes. Remote voice transcription is not supplied by this merge. The PR adds transcriptionServices to settingsUpdated in the old projection function.
Recommendation. Keep open: work remains. Fix token reuse and unavailable-source selection, then test those cases through the actual upload route. Port that logic to serverConfigProjection.ts so session replay and durable state share service availability.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Latest main change. Remote voice transcription is not supplied by this merge. The PR adds transcriptionServices to settingsUpdated in the old projection function. Port that logic to serverConfigProjection.ts so session replay and durable state share service availability.
Limits. The supplied runtime evidence is an iOS 26.5 simulator, not Android or an older iOS device. Required current-head checks are absent: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts with the current base. Current review checks still fail: Macroscope - Effect Service Conventions, Macroscope - UI Consistency.
Request. Add Clauded and Dodex as default alternate Claude and Codex instances with wrapper model catalogs and reasoning options.
Audit finding. Main does not register these aliases or supply their wrappers, and this draft enables them by default while leaving the executables in a separate branch. The latest revision fixes the shared capability map by passing each instance's catalog to chat and text generation. Existing custom instances with matching IDs still lose deletion, Windows path detection still differs between health and catalog loading, and health probes still check bare claude instead of the configured wrapper. The native Claude manifest also still marks the wrapper model rows as legacy.
Recommendation. Keep open: decision needed. Decide whether these external wrappers belong in the default provider catalog before completing and validating their integration.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Source: apps/server/src/provider/ModelManifest.ts:102. Final main classifies non-custom Claude rows through its native allowlist. The PR still marks wrapper aliases non-custom and applies this filter.
Check: github.com/pingdotgg/t3code/pull/9037/checks. At the frozen head, Effect Service Conventions, Correctness, and UI Consistency pass. Required Test, Check, Mobile Native Static Analysis, and Release Smoke jobs are absent.
Limits. The wrapper branch is not linked and its Clauded/Dodex executables are outside this ten-file diff. End-to-end compatibility and installation behavior are unverified. Required CI is absent at the audited head. No live wrapper test was run in this read-only audit. No before/after evidence is supplied for the settings UI change.
Request. Abort OpenCode child sessions when a turn is interrupted.
Audit finding. The entire diff adds parent-first abort followed by child enumeration and child aborts. Main now does that recursively, limits SDK concurrency, handles failures, and waits for child cleanup before completing interruption. The merged fix is newer than the latest collected stable and nightly releases.
Recommendation. Close: fixed. Close this PR as covered by the merged recursive child-session stop fix.
Confidence high. Release: Main only. PR readiness: Close or archive.
Check: GitHub check. Latest commit: Check success, Test success, Mobile Native Static Analysis skipped, Release Smoke success.
Independent closure check. The entire current diff and the full discussion concern stopping surviving OpenCode child sessions after the parent abort. Pinned main stops the parent first, walks every descendant with bounded SDK concurrency, and keeps Stop pending until cleanup ends. Its tests include children created during the parent abort and the next-turn gate. The merged replacement is in main but not in stable 0.0.37 or the latest collected nightly.
Request. Stop repeated scans of unfinished Codex JSONL records.
Audit finding. Merged PR 8605 changed protocol input to store fragments, scan each new chunk once and join only at a line boundary or EOF. Main includes large fragmented-record, CRLF, UTF-8 and malformed-final-line tests. This covers the one-file PR's material behavior without depending on Stream.splitLines.
Recommendation. Close: fixed. Close this PR as handled by merged PR 8605.
Confidence high. Release: In stable source. PR readiness: Close or archive.
Check: GitHub check. Latest head required checks: Test success, Check success, Mobile Native Static Analysis skipped, Release Smoke success.
Independent closure check. The full one-file diff replaces repeated whole-buffer scans with a stream line splitter. Pinned main instead retains fragments and scans each arriving chunk once, covering the same performance mechanism. The one review finding requests fragmented, coalesced, and EOF coverage, all present in the merged replacement tests. The replacement is in stable 0.0.37.
Limits. GitHub reports a conflict with main. Any passing checks apply to the existing head, not a rebased result.
Request. Windows PATH repair must remove stray quotes before child cmd.exe commands resolve executables.
Audit finding. Merged PR #8746 now strips quotes before deduplication in both the shared server PATH merge and the desktop PATH merge. This covers the original malformed-entry failure while preserving quoted directory contents and leaving POSIX unchanged. The fix commit is an ancestor of stable v0.0.37.
Recommendation. Close: fixed. Close this PR as covered by merged PR #8746.
Confidence high. Release: In stable source. PR readiness: Close or archive.
Merged pr: PR #8746. Landed quote stripping in both paths.
Check: GitHub check. Head 4a75785. Check: success; Test: success; Mobile Native Static Analysis: success; Release Smoke: success. GitHub reports conflicts with main.
Independent closure check. The full diff strips every quote from emitted Windows PATH entries in both shared server and desktop merges, not just comparison keys. Pinned main has that same sanitation before deduplication in both functions. It skips empty sanitized entries, preserves quoted directory contents, and leaves POSIX entries unchanged. The discussion adds no separate scope. The replacement is in stable 0.0.37.
Request. Windows PATH repair must keep existing shell entries ahead of package-manager fallback directories.
Audit finding. Merged PR #8748 reverses the same baseline merge order as this PR and updates baseline, profile-loaded, and profile-fallback tests. Pinned main now keeps the shell and inherited PATH ahead of npm, Volta, pnpm, and Scoop fallback directories. The fix is in the latest published nightly but is not an ancestor of stable v0.0.37.
Recommendation. Close: fixed. Close this PR as covered by merged PR #8748.
Confidence high. Release: In nightly source. PR readiness: Close or archive.
Merged pr: PR #8748. Landed the same precedence change and focused tests.
Check: PR #7687. Head 479917a. Required checks absent: Check, Test, Mobile Native Static Analysis, Release Smoke. GitHub reports conflicts with main.
Independent closure check. The sole production change reverses the baseline Windows PATH merge so known CLI directories follow the shell and inherited entries. Pinned main has the same merge order, and baseline, profile-loaded, and profile-fallback tests preserve it. The full body and discussion contain no extra behavior. The merged replacement is in the latest collected nightly, but not stable 0.0.37.
Limits. Required CI is absent on the current head: Check, Test, Mobile Native Static Analysis, Release Smoke.
Request. Tolerate one desktop or web foreground health-check timeout before reconnecting.
Audit finding. Main still fails a session after the first 15-second foreground probe timeout, so this is not fixed. The complete replacement diff in PR 8522 carries the same two-timeout policy, success reset, and unchanged mobile behavior, while preserving the newer immediate-reconnect marker in main. That PR explicitly identifies this branch as the source approach and is an active replacement.
Recommendation. Close: duplicate. Close this PR as replaced by PR 8522 and keep the replacement open for review.
Confidence high. Release: Not applicable. PR readiness: Close or archive.
Pr: PR #8522. Full diff reimplements all material scope and preserves wakeProbeFailed handling.
Independent closure check. Both full diffs tolerate the first desktop/web foreground probe timeout, reconnect on a second consecutive timeout, reset after success, and leave explicit mobile probes and definite failures unchanged. Replacement 8522 is open, explicitly identifies 5198 as its source approach, and preserves main's newer wakeProbeFailed immediate-reconnect behavior. Full discussions add no separate scope. Main still fails on the first timeout, so this is duplicate cleanup only.
Limits. Required checks absent from the canonical latest-commit rollup: Check, Test, Mobile Native Static Analysis, Release Smoke.
Request. Auto-settle policy and thread classification should agree across web, desktop, and mobile clients.
Audit finding. I read the full 739-line diff and full discussion. The shared per-environment policy goal is now handled by merged 8600, including streamed server settings, web/desktop controls, and mobile rendering of durable settlement state. However, 5290 deliberately keeps client-derived settlement and lets policy changes reclassify existing rows, while main persists settlement and does not reopen settled rows after a rule change. Close as obsolete after the accepted server-owned design, not as behavior-identical fixed code. The replacement is main-only.
Recommendation. Close: obsolete. Close as superseded by server-owned settlement. Do not describe the old immediate-reclassification behavior as shipped.
Confidence high. Release: Main only. PR readiness: Close or archive.
Independent closure check. I read the full 739-line diff and full discussion. The shared per-environment policy goal is now handled by merged 8600, including streamed server settings, web/desktop controls, and mobile rendering of durable settlement state. However, 5290 deliberately keeps client-derived settlement and lets policy changes reclassify existing rows, while main persists settlement and does not reopen settled rows after a rule change. Close as obsolete after the accepted server-owned design, not as behavior-identical fixed code. The replacement is main-only.
Request. A fast manual desktop update check should complete its refresh-icon rotation.
Audit finding. Merged PR #6504 already adds a manual-check animation latch, restarts the icon key, and releases the latch on animation iteration after checking finishes. It also keeps the check icon visible until the latched rotation ends and respects reduced motion. This covers the original short-response jitter without this older icon component.
Recommendation. Close: fixed. Close this PR as covered by merged PR #6504.
Confidence high. Release: In stable source. PR readiness: Close or archive.
Merged pr: PR #6504. Landed the complete-rotation behavior.
Check: GitHub check. Head b77d7b2. Check: success; Test: success; Mobile Native Static Analysis: success; Release Smoke: success. GitHub reports conflicts with main.
Independent closure check. The full diff makes each manual update check restart the icon and finish its current rotation after checking ends. Full review discussion adds repeated-check restart and status-driven checks, both preserved by pinned main. Main uses a presentation latch, increments the icon key for every manual check, and releases the latch on animationiteration. The merged replacement also keeps the icon visible through state changes and honors reduced motion. It is in stable 0.0.36 and 0.0.37.
Request. Avoid returning the full Codex turn history when resuming a parent thread.
Audit finding. Parent openCodexThread still resumes without excludeTurns, even though child subscriptions already pass it. This remains a real gap after the input-buffer fix. Open PR 8629 covers the same parent-resume behavior and preserves the field through the generated request encoder, so it is the specific replacement for this raw-request implementation.
Recommendation. Close: duplicate. Close this PR as a duplicate of PR 8629 and keep the parent-resume fix open there.
Confidence high. Release: Not applicable. PR readiness: Close or archive.
Pr: PR #8629. Active replacement adds the same resume flag plus generated-schema and encoder coverage.
Comment: Discussion comment. Reporter validated metadata-only resume on a 275 MB Codex rollout through WSL and remote clients.
Independent closure check. Both complete diffs implement metadata-only parent thread resume with excludeTurns=true and preserve recoverable fallback to thread/start. Replacement 8629 preserves the field in generated request schemas instead of using a raw request plus response decoder, and tests the encoded field and runtime payload. It is open and covers the same material change. Full discussions add user reproduction evidence but no distinct requirement. This is duplicate closure only. The parent resume defect remains unfixed in main.
Limits. Latest-head required check results are absent for Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Render a viewed workspace image above expanded tool details on web and mobile.
Audit finding. Main now uses shared read-image classification and renders signed image assets inside expanded work-log rows on both clients. The merged replacement also handles persisted attachment paths and preserves the reviewed single-line and case-insensitive read-title rules. This covers the full preview scope and is in the latest nightly, but not the latest stable release.
Recommendation. Close: fixed. Close this PR as covered by the merged viewed-image work-log implementation.
Confidence high. Release: In nightly source. PR readiness: Close or archive.
Independent closure check. The complete diff and full discussion cover lazy expanded image previews on web and mobile, the shared read classifier, CR/LF rejection, Cursor title casing, and keyboard activation. Pinned main now renders signed workspace or attachment image assets in both expanded work logs and uses one shared classifier. The web shared image handler handles Enter/Space and stops their propagation, preserving the original keyboard fix without the old row guard. Merged 8936 is in the latest collected nightly but not stable 0.0.37. Mobile store delivery is not established by the desktop nightly tag.
Request. Avoid starting a full Grok ACP session during provider health checks.
Audit finding. Main still starts a full Grok ACP session during its health check. The later Grok probe PR explicitly rebases this same CLI model/auth implementation and preserves the skills discovery that main gained afterward. Close this older branch as a duplicate of that active replacement, while keeping the replacement open to fix its reasoning-capability regression.
Recommendation. Close: duplicate. Close as a duplicate of #8884.
Confidence high. Release: Not applicable. PR readiness: Close or archive.
Pr: PR #8884. Explicit rebased replacement keeps the earlier CLI probe and current skills discovery.
Independent closure check. I read the complete original diff, every normalized replacement difference, and both full discussions. Replacement 8884 explicitly rebases the same grok models parser, CLI-only status probe, auth detection, fallback models, and warning behavior, while retaining skill discovery added to main later. No unique behavior from 7747 is missing. The replacement is still open and must fix its reasoning-capability regression before merge. Main still starts ACP during health checks, so neither branch is a landed fix.
Limits. Required checks have no results on this head: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Add Back and Forward navigation controls and shortcuts to web, desktop, and mobile.
Audit finding. PR 8727 explicitly replaces this branch and preserves its navigation implementation across all three clients. Both diffs were read, including the successor fixes for mobile POP_TO source, reload Forward state, cold-start Back, and Android overflow. Main still lacks the feature, so archive this duplicate without calling it fixed or released.
Recommendation. Close: duplicate. Close this PR as superseded by PR 8727.
Confidence high. Release: Not applicable. PR readiness: Close or archive.
Pr: PR #8727. Active successor explicitly preserves this PR and completes the current integration.
Comment: Discussion comment. Original mobile POP_TO source finding is corrected in the successor diff.
Independent closure check. I read the original complete diff, all original and successor discussions, and every normalized diff difference in successor 8727. The successor explicitly preserves the original work and retains Back/Forward controls, history state, shortcuts, palette entries, web/desktop routing, mobile home/thread/settings coverage, and native keyboard commands. Its generic Android header replaces the original Settings-only insertion, while iOS inherits the shared header pair. It fixes the original POP_TO source error and adds reload-forward, cold-start replacement, and Android overflow handling. No unique material behavior remains in 7808. Main still lacks this feature, and the successor still needs maintainer review, including its narrow-sidebar finding.
Request. Prevent the first project gear from taking focus when the sidebar project menu opens.
Audit finding. The patch redirects focus from a MenuRadioItem gear to its role=menu ancestor. Main replaced that menu with a searchable Combobox and an input in the popup in the merged project-filter change, so the old MenuPopup auto-focus path and the patch target no longer exist.
Recommendation. Close: obsolete. Close this menu-specific patch as superseded by the searchable project filter.
Confidence high. Release: In stable source. PR readiness: Close or archive.
Commit: Commit 48c176b3cfda. Replaced the menu with the searchable project combobox in merged work.
Check: GitHub check. Current-head Test, Check, and Release Smoke succeed. Mobile Native Static Analysis is skipped.
Independent closure check. The full diff only redirects open-time focus from a project gear to its Menu ancestor. The full discussion adds no other implementation scope. Pinned main replaced that MenuPopup with a searchable Combobox whose initial focus belongs to its input, so the old Menu focus path and the patched ancestor no longer exist. The replacement merged to main and is in stable 0.0.36 and 0.0.37. This does not close the broader gear accessibility requests.
Request. Back off repeated exits of the managed Cloudflare connector.
Audit finding. Main still has the immediate connector restart loop. This patch and the active rapid-exit PR change the same supervisor for the same failure, but the latter adds stable-uptime reset and deterministic configuration-preemption coverage with passing current-head required checks. Keep one implementation by using the rapid-exit PR as the active replacement.
Recommendation. Close: duplicate. Close this duplicate in favor of PR 8788.
Confidence high. Release: Not applicable. PR readiness: Close or archive.
Pr: PR #8788. Active complete replacement with clean required checks and reviewed lifecycle tests.
Independent closure check. The full diff adds capped exponential restart delays and releases the reconcile lock during the wait. Full discussions and replacement 8788 cover the identical immediate-exit process loop in ManagedEndpointRuntime. The replacement uses an immediate first retry, then bounded exponential delay with stable-uptime and explicit-config reset, and guards stale supervisors after the wait. It preserves responsive configuration changes. Different delay constants are implementation choices, not extra functionality missing from the replacement. Main still restarts immediately, so this is duplicate cleanup only.
Limits. Required current-head checks are absent: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Stop Bitbucket permission preflight from blocking writes when the retired endpoint returns HTTP 404.
Audit finding. Main only bypasses HTTP 410 from the retired permission endpoint, so the 404 failure remains. This patch widens the bypass, while the active workspace-endpoint PR removes the retired request and keeps real permission decoding. Both cover the same preflight for merges and comments, so the supported-endpoint change is a complete replacement for this workaround.
Recommendation. Close: duplicate. Close this workaround in favor of PR 9035.
Confidence high. Release: Not applicable. PR readiness: Close or archive.
Pr: PR #9035. Active replacement uses the workspace-scoped endpoint instead of bypassing permission checks.
Independent closure check. The entire diff widens the retired Bitbucket permission-endpoint fallback to HTTP 404 and adds one test. I read replacement 9035 and both full discussions. The replacement stops calling that retired endpoint, uses the workspace-scoped effective-permission endpoint, preserves repository filtering and decoding, and retains authentication failures. It covers the same merge/comment preflight problem and is open. Close this workaround only in favor of that active replacement, not as fixed or merge-ready.
Limits. Required current-head checks are absent: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Avoid rewriting a saved file buffer when its editor tab closes.
Audit finding. The full functional change tracks a successful-save revision and skips the redundant close write. Active PR #8630 covers that behavior in persistLatest and also blocks editor changes after disposal, so it is a complete replacement for this narrower fix. Main still needs the fix, and this closure is only a duplicate recommendation.
Recommendation. Close: duplicate. Move the useful flush-order test cases to PR #8630 and close this duplicate.
Confidence high. Release: Not applicable. PR readiness: Close or archive.
Pr: PR #8630. Active replacement covers the saved-revision guard and post-dispose callbacks.
Independent closure check. Both complete diffs track the revision from the last successful save and suppress the redundant close write. Replacement 8630 checks that revision inside persistLatest, so it covers saved-buffer close behavior, pending debounce flushes, retry after a completed failed write, and newer edits during an in-flight save. It also ignores post-disposal callbacks. The bodies and full discussions add no missing production scope. Main still lacks the guard. Retain the useful flush-order test cases with the replacement.
Request. Change Docker pairing URL output so it does not choose an unreachable container interface.
Audit finding. GitHub reports zero changed files and the complete diff is empty. The branch first kept wildcard bind addresses, then commit 7897f1b restored the existing external-interface lookup after review. Main still has that lookup, so this empty PR can be archived without claiming that the Docker pairing report is fixed.
Recommendation. Close: obsolete. Close the empty PR and leave issue 8384 open for a concrete advertised-host solution.
Confidence high. Release: Not applicable. PR readiness: Close or archive.
Issue: Issue #8384. The original Docker pairing report is not fixed by an empty diff.
Independent closure check. Fresh GitHub metadata reports zero changed files, zero additions and deletions, and a fresh full diff is empty at current head 503b4bc9c76ee9d17a6550fb9f3c272a57e0691f. The full discussion and commit 7897f1b show that the original wildcard-URL change was reverted after review. This PR has no remaining implementation. Archive it without closing or claiming a fix for issue 8384, since main still chooses an external interface for a wildcard bind.
Limits. Required current-head checks are absent: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Limit provider binding reads to threads with live adapter sessions.
Audit finding. Main still scans all persisted provider bindings, so the performance fix remains needed. This complete production diff and the later lookup PR both derive the same deduplicated active-session thread IDs and preserve the same decoration path. The later PR has current passing CI and bot approval, making it the active replacement while this PR can close as a duplicate, not as fixed.
Recommendation. Close: duplicate. Close as a duplicate of #8909.
Confidence high. Release: Not applicable. PR readiness: Close or archive.
Pr: PR #8909. Active replacement has the same production fix, focused coverage, and passing head checks.
Independent closure check. Both complete production diffs derive the same deduplicated thread IDs from live adapter sessions and read bindings only for those IDs. Both preserve the same active-session decoration and binding-error fallback. The test approaches differ, but replacement 8909 verifies that the historical scan is never called and that only the active thread is looked up. Full discussions add no separate scope. The replacement is open, and main still scans all persisted threads.
Limits. Required checks have no results on this head: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Make OpenCode interruption clear runtime state and allow the next turn.
Audit finding. The current diff contains only an interrupt test and a test-double hook, despite a body that describes production changes. Main already has runtime cancellation cleanup, but the reported durable session staying running is still real because ingestion does not apply turn.aborted. The active durable-abort PR covers that remaining defect with message correlation and ingestion tests, so this test-only branch is a duplicate rather than a landed fix.
Recommendation. Close: duplicate. Close this test-only PR in favor of the active durable-abort PR and keep the underlying issue open.
Confidence high. Release: Not applicable. PR readiness: Close or archive.
Pr: PR #8939. Active replacement addresses durable abort state. It is not merged or declared merge-ready.
Independent closure check. The current diff is tests only, and main already covers its runtime interruption and next-turn behavior. The body still reports a durable session running after Stop on a build newer than merged 8480, so this must not be called fixed. I read replacement 8939 in full. It adds turn.aborted to canonical thread.session.set, clears activeTurnId, writes interrupted/error state, finalizes output, and tests the exact persisted mismatch. Close this PR only as a duplicate of that active replacement, with issue 8895 left open. This is not a merge-readiness finding for 8939.
Audit finding. The diff only serializes loadInventoryFromCli and adds a test that calls that helper directly. Main has no production callers of this helper since HTTP inventory replaced it in the merged shared-server change. Applying this PR would not change current provider discovery, though the old helper remains in source.
Recommendation. Close: obsolete. Close this PR as obsolete after linking the HTTP inventory replacement.
Confidence high. Release: In stable source. PR readiness: Close or archive.
Merged pr: PR #8480. Merged replacement removed the live concurrent CLI inventory path.
Independent closure check. Both changed production blocks only serialize loadInventoryFromCli. The full diff adds no other behavior, and the full discussion identifies the same CLI lock mechanism as issue 8386. Repository-wide caller search finds no production caller of that helper after the HTTP catalog replacement, so the patch no longer changes provider discovery. The replacement is in stable 0.0.36 and 0.0.37.
Request. Insert a five-second wait between managed connector restarts.
Audit finding. This fixed-delay patch addresses the same connector exit loop as the active rapid-exit PR. Both leave configuration changes responsive, while the replacement adds stable-uptime reset and tested preemption. The final discussion explicitly identifies this overlap, and neither patch has landed.
Recommendation. Close: duplicate. Close this duplicate in favor of PR 8788.
Confidence high. Release: Not applicable. PR readiness: Close or archive.
Pr: PR #8788. Active replacement for the same reported crash loop.
Comment: Discussion comment. The final discussion identifies the same supervisor, issue, and behavior in the replacement.
Independent closure check. The full diff adds a fixed restart delay and releases the reconcile lock during the wait. Full discussions and replacement 8788 cover the identical immediate-exit process loop in ManagedEndpointRuntime. The replacement uses an immediate first retry, then bounded exponential delay with stable-uptime and explicit-config reset, and guards stale supervisors after the wait. It preserves responsive configuration changes. Different delay constants are implementation choices, not extra functionality missing from the replacement. Main still restarts immediately, so this is duplicate cleanup only.
Request. Remove the duplicate full server-config transfer at session startup.
Audit finding. This PR merged during the audit at b883fc066ea5c9bebbe1c3e9b4bc2471aab3685f, after the pinned main baseline. Its complete diff and resolved review threads cover shared bootstrap, incremental events, theme replay, and session recovery. It is no longer open and should not remain in the merge queue.
Recommendation. Merged during the audit. No closure action. This PR already merged during the audit.
Reconciliation. This item left the open inventory during the audit. It is not a closure recommendation.
Independent closure check. Confirmed as inventory reconciliation, not a closure recommendation. Fresh GitHub metadata reports this PR already merged into main at 2026-09-01T11:23:50Z, after the 11:17:41Z audit snapshot, with merge commit b883fc066ea5c9bebbe1c3e9b4bc2471aab3685f. Remove it from the open merge queue and keep the post-baseline distinction. This verdict does not claim its behavior was fixed in pinned main or independently re-review the merged implementation.