pingdotgg/t3code. All authors. Drafts included. Default branch main. 570 issue assessments and 925 PR assessments. Initial inventory: 570 open issues and 924 open PRs. Current assessed open inventory: 570 issues and 924 PRs. Final reconciliation: 2026-09-01T11:57:41.491617+00:00.
Request. Restore a missing Windows Start Menu shortcut during NSIS updates.
Audit finding. Main still configures NSIS with differentialPackage only and has no custom installer hook. The patch recreates an absent shortcut and assigns its AppUserModelID while retaining existing shortcuts and the no-shortcut build flag. The later Windows packaging optimization does not add this repair.
Recommendation. Keep open: work remains. Review the missing-shortcut update fixture and installer hook for Windows packaging.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Show an explanation when mobile users tap a file link outside the project folder.
Audit finding. Main returns silently when a file link cannot resolve inside the workspace. The current one-file diff adds an alert and an early return after successful navigation. The body contains an old bot warning about an unconditional alert, but that warning does not match the current diff.
Recommendation. Keep open: work remains. Review the alert copy and check inside-project, outside-project, and PDF link paths.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Wait for macOS launchd jobs to leave their domain before reinstalling the background service.
Audit finding. Main still passes --wait to bootout and treats stop and enable failures as optional. The patch replaces that path with bounded print checks and tests draining, missing, denied, and timed-out jobs. Recent service PATH work did not change this shutdown sequence.
Recommendation. Keep open: work remains. Verify the exact launchctl responses on supported macOS versions before merging.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. The macOS command responses were reviewed in fixtures, not reproduced on macOS. Required CI checks are absent at the reviewed head: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts at the reviewed head.
Request. Read the login-shell environment when the configured shell is Nushell.
Audit finding. Main still emits POSIX printf and printenv commands with || true for every non-Windows login shell. The patch detects nu and nu.exe and uses Nushell print and try/catch syntax while preserving the POSIX path. The recent Windows PATH quote and ordering fixes do not change this command builder.
Recommendation. Keep open: work remains. Review the Nushell probe against a real login shell and retain the existing POSIX-shell coverage.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Open remote worktrees in Zed through the shared editor-link flow.
Audit finding. Main still gives Zed no remote scheme and builds only vscode-remote URLs. PR 6572 therefore does not cover Zed, despite providing the common remote-open path. This diff extends the registry and Electron URL validation for Zed SSH links while retaining the existing VS Code form.
Recommendation. Keep open: work remains. Review and test the Zed URL handler with the stable and Preview release channels.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Add Copy Link to sidebar and chat-header thread menus.
Audit finding. The shared thread action menu on main only copies path, branch, and thread ID. This patch adds an HTTP link through both menu entry points and documents that pairing and reachability are still required. The other open deep-link proposal opens threads in desktop and does not replace this copy action.
Recommendation. Keep open: work remains. Review link construction for browser, desktop-local, and remote environment addresses.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Point development Tailscale sharing at the same loopback host as Vite.
Audit finding. Main still calls ensureTailscaleServe without localHost while Vite defaults to localhost. The patch fixes the default IPv6-first mismatch, but Vite also accepts an explicit HOST and this patch always chooses localhost. Server and pairing share paths already pass their own host and are outside this change.
Recommendation. Keep open: work remains. Check the explicit HOST path and run the dev-share test before merging.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Stop showing an authentication warning for a ready provider with unknown auth status.
Audit finding. The current settings summary still supplies the warning text when a ready provider has no server message. The diff removes only that fallback and tests the ready, warning, error, and auth branches. The merged settings list/editor rewrite retained this text, so it did not cover the request.
Recommendation. Keep open: work remains. Review the copy change in the current provider editor and obtain the required checks.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Normalize pasted GitLab web or clone URLs to the project path expected by glab api.
Audit finding. Main still URL-encodes the full input directly into projects/<path>. The diff extracts the project path, preserves nested subgroups, and strips a configured install prefix, with focused tests for host values with and without a scheme. It fixes lookup against the configured GitLab host but does not add routing to a different pasted host.
Recommendation. Keep open: work remains. Review URL normalization against the configured GitLab host and its relative install prefix.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Audit finding. Main has unknown-host refinement for GitLab but not in the GitHub discovery spec. The diff claims only exact authenticated host matches, preserving ports and leaving ordinary GitHub hosts unchanged. SSH aliases and mismatched port storage remain separate cases rather than evidence that this fix is obsolete.
Recommendation. Keep open: work remains. Review the unknown-host discovery cases and coordinate with the SSH-alias work in PR 7186.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. Latest-commit metadata has no required runs for Test, Check, Mobile Native Static Analysis, Release Smoke. An older related reference could not be retrieved from GitHub. It is excluded from verified dependencies and fix evidence.
Request. Accept server-valid project script IDs when building client keybinding commands.
Audit finding. Main accepts any trimmed nonempty ProjectScript.id, but SCRIPT_RUN_COMMAND_PATTERN still restricts IDs to 24-character lowercase slugs. commandForProjectScript calls the stricter schema during UI rendering, so an API-created UUID can still throw. The patch aligns the command ID segment and tests UUID round trips without changing generated slugs.
Recommendation. Keep open: work remains. Review and land the contract alignment with the UUID round-trip coverage.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Show OpenCode bash commands once and keep their output in the output section.
Audit finding. Main still uses completed tool output as detail and sends the complete tool state without a structured command. The PR fills data.command and data.rawOutput in the format used by existing client renderers, which addresses the command/output confusion. Removing data.state also affects non-command tools, so current consumers and both client renderers need focused verification.
Recommendation. Keep open: work remains. Rebase the tool projection and verify command output plus non-command metadata on web and mobile.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Make Files tree text follow the interface font-size setting.
Audit finding. Main still sets the tree font override to a fixed 12px, including after the latest Files panel changes. The one-line change uses 0.75rem, preserving the default size and scaling with the root font. No merged replacement was found.
Recommendation. Keep open: work remains. Review the one-line font change and verify the existing default and enlarged interface settings.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Let shared web copy actions work over plain HTTP on remote environments.
Audit finding. Main still throws ClipboardApiUnavailableError when navigator.clipboard.writeText is unavailable. The patch adds a selected-textarea fallback only for that missing-API case and restores focus afterward, so it addresses the LAN and Tailscale HTTP path without changing secure-origin failures.
Recommendation. Keep open: work remains. Review the fallback with a plain-HTTP remote copy test.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Mark completed threads first discovered after environment bootstrap as unread.
Audit finding. Main still treats a thread with no lastVisitedAt as read and has no first-seen completion hook in EventRouter. The patch records per-environment snapshot membership, keeps initial history read, and marks later completed arrivals unread. Server-side settling changes do not implement this first-seen rule.
Recommendation. Keep open: work remains. Review the post-bootstrap completion behavior together with the open read-state synchronization work.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Copy a code block final-line selection as plain text when its trailing range leaves the block.
Audit finding. The current clipboard helper checks only whether the common ancestor is inside pre. The earlier partial-code fixes therefore miss final-line triple-click ranges whose ancestor sits outside pre. This patch checks the start block and trailing selected content, while the other open code-copy patch changes whole-code-block behavior more broadly.
Recommendation. Keep open: work remains. Consolidate the final-line boundary fix with the other open code-copy patch before landing one.
Request. Open a skills-only menu for slash triggers after existing prompt text.
Audit finding. Both main trigger implementations still require a slash at the start of a line and have no slash-skill kind. The patch shares trigger detection, retains leading commands, and updates web and mobile menu behavior including empty results. Recent skill deduplication and invalid-name fixes change menu contents, not this inline-trigger rule.
Recommendation. Keep open: work remains. Integrate the new trigger with current skill filtering and review web and mobile command-versus-skill behavior.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Keep substantive mid-turn assistant text outside settled-turn folds.
Audit finding. Both current clients still hide intermediate assistant messages based on position rather than content. The patch keeps messages over 240 characters or with a blank-line paragraph break visible and shares that rule between web and mobile. This improves the reported case but still hides short substantive answers, so the threshold is a product rule that needs acceptance.
Recommendation. Keep open: decision needed. Decide whether the 240-character narration rule is the desired shared folding behavior.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Recognize filesystem renames as one change in working-tree review diffs.
Audit finding. Main still generates tracked and untracked patches separately, which prevents Git from pairing an unstaged deletion with its untracked destination. The proposal uses a temporary copy of the index and one rename-aware diff, with split-index and staged-deletion tests. This is distinct from correcting status path strings in PR 8310.
Recommendation. Keep open: work remains. Review the temporary-index fallback and retain tests that prove the real index is unchanged.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Source: apps/server/src/vcs/GitVcsDriverCore.ts:2248. Main still generates tracked and untracked patches separately, which prevents Git from pairing an unstaged deletion with its untracked destination.
Check: GitHub check. Latest-commit checks: Test success, Check success, Mobile Native Static Analysis skipped, Release Smoke success.
Request. Let signed macOS builds omit passkey signing material when cloud authentication is disabled.
Audit finding. Main still resolves passkey signing for every signed macOS artifact. The complete one-file diff gates it on either the Clerk publishable key or explicit passkey RP domains, preserving configured passkey builds. The current build-script history does not remove that unconditional requirement.
Recommendation. Keep open: work remains. Review the optional-cloud signing gate and test both configured and unconfigured signed build paths.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. No signed build or signing-material check was run in this audit. The collected latest head has no results for these required checks: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Stop printable keys from focusing the composer behind open dialogs and sheets.
Audit finding. Main still checks data-slot=dialog, but its dialog primitives render dialog-popup, alert-dialog-popup, command-dialog-popup, and sheet-popup. The patch targets those actual slots and their open or exit states, including the mobile web sidebar, so the mismatch remains present on main.
Recommendation. Keep open: work remains. Review the actual popup-slot guard and confirm open and closing dialogs retain keyboard focus.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Keep modal dialogs above the composer slash and skill menus.
Audit finding. Main still portals composer menus at z-index 70 while dialog, sheet, and command-palette backdrops and viewports use 50. All six changed class strings move the shared modal layer to 80 without changing menu or toast layers, so the reported ordering remains unfixed.
Recommendation. Keep open: work remains. Review the shared modal layer change with an open composer menu and each modal type.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Clear the inherited checkout branch when an empty web composer switches to a new worktree.
Audit finding. Main changes envMode without clearing the selected branch. Server default-branch fallback and failed-bootstrap draft recovery do not prevent this incorrect inherited selection. The diff clears only the transition into worktree mode and leaves an explicit worktree base untouched.
Recommendation. Keep open: work remains. Run the local-draft and pending-server-thread branch transition tests on current main.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Retry expected errors raised while building a durable RPC subscription input.
Audit finding. Main still runs makeInput outside Stream.catchCause, so this patch is not present. The diff moves input construction under the existing failure handler without changing transport dormancy or defect handling. It shares the same subscription block with the separate transport recovery proposal. Config fan-out normalizes its own terminal errors. A failure from generic makeInput still happens outside Stream.catchCause.
Recommendation. Keep open: work remains. Combine the input-error boundary with any chosen transport fix and run the RPC subscription tests.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Latest main change. Config fan-out normalizes its own terminal errors. A failure from generic makeInput still happens outside Stream.catchCause. Keep the disposition and retain the new config-specific method selection during rebase.
Limits. Required CI checks are absent at the reviewed head: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts at the reviewed head.
Request. Stop offline environments from blocking usage totals indefinitely.
Audit finding. Main still counts every environment without a summary or error as still reporting, and web holds totals while that count is nonzero. This patch gives disconnected environments a 7.5-second grace period on web and mobile, distinguishes no reports from zero usage, and still merges late answers. The reviewed deadline-reset findings are addressed in the submitted scan key.
Recommendation. Keep open: work remains. Review the offline grace period and verify that connected slow scans remain pending while late reconnects merge.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Explain whether the client or server is too old to combine usage totals.
Audit finding. Main still puts every incompatible usage contract into staleEnvironments and both clients describe it as an older server. The patch preserves exclusion from totals but records mismatch direction and uses one formatter on web and mobile. The compatible-version range added for provider expansion does not correct the misleading newer-server message.
Recommendation. Keep open: work remains. Review the shared mismatch direction change and both client notices.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Report a skipped change-request step instead of failing after commit and push on unsupported remotes.
Audit finding. Main still resolves the unknown provider and calls its change-request methods in runPrStep. The diff returns skipped_unsupported_provider before those calls, extends the contract, and presents the outcome as a warning in web and mobile. Supported-provider auth and push failures stay errors, so this addresses the unsupported-host case without treating all remote failures as success.
Recommendation. Keep open: work remains. Review the unknown-provider short circuit with the current stacked-action flow.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. Required current-head checks are absent: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts with the current base.
Request. Accept old PR-checkout responses that omit isOnPullRequestHead.
Audit finding. Main still requires isOnPullRequestHead on every successful response. This two-file change defaults an omitted field to true while retaining an explicit false, matching older server behavior. No newer compatibility decoder was found.
Recommendation. Keep open: work remains. Review the legacy response assumption and run the focused contract tests.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Resolve subdirectory-relative file chips through the workspace index.
Audit finding. Main limits workspace lookup to bare filenames, so slashed paths still bypass it. The diff adds segment-boundary suffix matches, rejects ambiguous slashed results, and covers panel, editor, and browser opens. Mobile remains unchanged, and this work must be combined carefully with rooted skill tabs in PR 8102.
Recommendation. Keep open: work remains. Review the slashed-path lookup with ambiguous names and coordinate rooted tabs with PR 8102.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Avoid quadratic point copying, bounds scans, and SVG path parsing during preview drawing.
Audit finding. Main still copies the entire point array and rebuilds bounds and path text on every pointer move. The diff uses incremental geometry and fixed-size SVG chunks, with oracle and long-stroke tests. This is separate from general renderer-memory limits and has not landed.
Recommendation. Keep open: work remains. Run current focused annotation checks and verify a long stroke across SVG chunk boundaries.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Expand Claude slash commands when the user includes image attachments.
Audit finding. Main still writes the text block before images, leaving an image as the final content block. The proposed change places images first and text last, matching the CLI expansion path described in the PR while leaving other providers unchanged. The recent generic-upload change keeps Claude image handling separate and does not change this order.
Recommendation. Keep open: work remains. Run the focused attachment tests and verify one slash command with an image on a supported Claude CLI.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Include symlinked directories in the shared project path browser.
Audit finding. Main only accepts dirent.isDirectory and therefore omits directory symlinks. The diff follows only candidate symlinks with bounded concurrency, leaving plain directory reads unchanged and rejecting file and broken links. Open PR 8539 overlaps this same behavior, but neither has landed.
Recommendation. Keep open: work remains. Choose one symlink-browse implementation with PR 8539 and retain the directory, file-link, and broken-link cases.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Prevent clone URLs and destination names from being interpreted as Git options.
Audit finding. Main passes both values directly after git clone without an option terminator. The two-file diff inserts -- before both positionals, while mobile can still supply destination names through add-project input. This is an unfixed server argument-parsing defect, not only a clearer validation message.
Recommendation. Keep open: work remains. Prioritize maintainer review of the option terminator and run the focused clone test.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Stop automatically granting clipboard-read and geolocation to preview websites.
Audit finding. Main still auto-approves both permissions through its request and check handlers for every preview partition. The complete patch removes those grants while preserving clipboard-sanitized-write and notifications, with tests for both handlers. This is still a direct permission change, not a fix supplied by the browser upgrade.
Recommendation. Keep open: work remains. Review the permission reduction and confirm copy buttons still work.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Open remote editors with the environment account instead of the viewing machine account.
Audit finding. Main advertises only remote hostnames and drops the saved SSH username before constructing editor links. The patch carries an optional username through discovery and desktop profiles and encodes user@host in the remote destination. The reviewed missing-passwd-entry failure is fixed in the proposed diff with a hostname-only fallback, but none of this username support is on main.
Recommendation. Keep open: work remains. Verify remote opening with different viewer and environment accounts, an explicit SSH-profile username, and an older server.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Batch busy thread and shell streams without applying buffered events from replaced sessions.
Audit finding. Main still applies each thread and shell item separately; server tool-frame coalescing does not provide adaptive client batching. The diff preserves turn-window locks, generation filtering, and mid-batch settled snapshots, and the singleton-batch bot finding is false against the pinned Effect implementation. It overlaps the earlier thread-only batching PR and must retain the config-stream sharing merged during this audit. The new buffer and local revisions cover config only. They do not batch thread/shell publications or tag thread work by subscription generation.
Recommendation. Keep open: work remains. Use one client batching implementation and verify reconnect, older-page loading, and responsiveness under a large backlog.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Latest main change. The new buffer and local revisions cover config only. They do not batch thread/shell publications or tag thread work by subscription generation. Keep the batching disposition and preserve config dispatch while refactoring subscribeDynamic.
Request. Preserve real renamed, spaced, and non-ASCII paths in Git status and selective commits.
Audit finding. Main still parses display-format numstat and porcelain lines, including splitting renames at the arrow and ordinary paths at whitespace. The diff changes both commands and parsers to NUL-separated records and keeps both rename paths for selective staging. The defect remains across all clients that consume server status.
Recommendation. Keep open: work remains. Review this parser fix before combining the untracked-count and Files-tree status branches.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Source: apps/server/src/vcs/GitVcsDriverCore.ts:165. Main still parses display-format numstat and porcelain lines, including splitting renames at the arrow and ordinary paths at whitespace.
Request. Shorten pull-request first-page loading and defer unnecessary repository searches.
Audit finding. Main still requests 99 rows, starts priority searches with the main feed, and immediately checks repositories absent from the first combined page. Recent pull-request budget and live-read fixes do not replace this first-page strategy. The diff preserves direct verification at the end of a combined search, but the delayed results for search-invisible repositories need review.
Recommendation. Keep open: work remains. Rebase the page-size and cursor changes and verify an unindexed repository through the end of pagination.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Show silent Windows desktop notifications when an observed agent turn completes while no app window is focused.
Audit finding. Main has shared mobile awareness phases but no desktop completion bridge or native notification service. The patch reuses those phases and fixes the reviewed stale-cache arming case with per-environment liveness tests. It intentionally covers only Windows completion toasts, with OS-level opt-out and no click action, sound, approval notification, or macOS/Linux support, so the broader notification request remains only partly addressed by this proposal.
Recommendation. Keep open: decision needed. Decide whether to ship this Windows-only default-on scope and verify the installed app notification identity.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. The Windows dev-app toast report was not repeated on an installed build. Required Check, Test, Release Smoke, Mobile Native Static Analysis checks are absent on the collected head.
Request. Let web and desktop users resize the file explorer beside a file preview.
Audit finding. Main still uses a fixed fractional width with a 256px minimum. The diff reuses the shared drag-resize hook, saves a browser-local width, and provides a double-click reset. It includes interaction video but no focused test for the new narrow-panel clamp or reset behavior.
Recommendation. Keep open: decision needed. Review the width limits and check drag, reset, and narrow-panel behavior in the integrated client.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Repair branch metadata and show a warning when threads share a worktree whose checkout changed.
Audit finding. Main still skips branch adoption whenever any sibling shares the worktree, and its mismatch notice only handles local checkouts. This diff adds the inactive-sibling exception and preserves worktreePath when sending. The shared-worktree case remains unhandled on main.
Recommendation. Keep open: work remains. Review the shared-worktree adoption rules and apply the web notice changes to the current composer.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Stop deleted provider IDs that match Object prototype keys from remaining enabled in the picker.
Audit finding. applyProviderInstanceSettings still reads settings maps through ordinary property access. An absent constructor or toString ID can resolve to an inherited value and bypass the removed-instance branch. The patch uses own-property checks for both current and legacy maps and retains explicit prototype-named configurations, which the later provider editor changes do not address.
Recommendation. Keep open: work remains. Review the own-property checks and the built-in legacy fallback tests.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Preserve other applications' Tailscale Serve handlers and align shared Vite binding with the proxy.
Audit finding. Main still configures and disables an HTTPS port without inspecting its existing handler, and dev sharing clears the port first. The diff checks exact handler ownership, refuses foreign or Funnel handlers, and uses one explicit IPv4 loopback for shared Vite and Serve while leaving HMR origin-derived. This affects CLI pairing, server shutdown, and dev sharing, all of which the patch updates.
Recommendation. Keep open: work remains. Review the handler ownership checks and current pairing integration tests.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. Required current-head checks are absent: Test, Check, Mobile Native Static Analysis, Release Smoke. Current review checks still fail: Macroscope - Effect Service Conventions.
Request. Use the server listener port for a managed tunnel linked through a local port forward.
Audit finding. Main signs the client-supplied origin after checking it against the request URL, so a forwarded local port can become the remote connector origin. The patch derives the managed origin from HttpServer and keeps manual-link, authentication, and forwarded-header restrictions. Its tests cover differing forward and listener ports plus IPv6 and wildcard mapping.
Recommendation. Keep open: work remains. Run the link-proof tests and review the managed versus manual origin rules.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Skip remote model-manifest requests when provider update settings cannot be read.
Audit finding. ModelManifest.refresh still converts a settings read failure to null and only stops the fetch for a non-null opt-out. The PR changes that exact condition and includes a failing-settings test. Manifest caching and provider opt-in changes do not remove this network request path.
Recommendation. Keep open: work remains. Review the fail-closed manifest guard and its focused test.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Make the Claude 200k context choice control the actual CLI session window.
Audit finding. Main represents 200k only as a bare model slug and never sends CLAUDE_CODE_DISABLE_1M_CONTEXT. The diff sends the opt-out through flag settings, applies it during model switches, and covers metadata generation too. This addresses the selected runtime window, which is separate from the merged removal of post-turn context queries and from child-token meter accounting.
Recommendation. Keep open: work remains. Review both directions of live context-window switching and its failure path with the focused tests.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Leave pasted decorator calls as text while preserving explicit file mentions.
Audit finding. The shared parser on main excludes bare scoped package references but still accepts decorator-call strings as mentions. This patch extends that exclusion to names followed by an opening parenthesis and leaves quoted or canonical file references unchanged. The focused paste case is absent from the current test suite.
Recommendation. Keep open: work remains. Review the decorator-call exclusion with the existing inline-token paste tests.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Apply the existing terminal-close failure fallback to right-panel terminal tabs and panel cleanup.
Audit finding. Main still hides right-panel terminals after a direct close mutation while only the drawer path attempts exit on a failed close. The patch shares that failure handling and avoids repeated focus changes during bulk panel cleanup. It does not fix server-side persistence starvation or guarantee shutdown when both close and write fail.
Recommendation. Keep open: work remains. Verify failed close handling for a right-panel tab and for closing all terminal panels.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. The patch has no new failure-path test and no runtime close failure was reproduced. Required Check, Test, Release Smoke, Mobile Native Static Analysis checks are absent on the collected head.
Request. Remove pending approvals that belong to turns discarded by a thread revert.
Audit finding. The current pending-approval projector still has no thread.reverted case, although messages and turns are pruned. The diff deletes discarded-turn approval rows and checks the resulting shell count with an event-driven SQL test. Recent projection performance changes do not add this cleanup.
Recommendation. Keep open: work remains. Review and run the focused projection test for discarded-turn approvals.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Leave a one-time pairing grant usable after a request asks for disallowed scopes.
Audit finding. Main consumes the grant before it checks requested scopes. The diff introduces a read-only inspection step and verifies that an over-scoped rejection can be followed by a valid narrower exchange. The DPoP storage PR adds a similar preflight helper but still does not move this scope check, so it is related work rather than a replacement.
Recommendation. Keep open: work remains. Reuse one grant-inspection helper when integrating this change with the DPoP storage work.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Keep the SwiftUI caret after inserted command or skill text.
Audit finding. The experimental parent still publishes the selection request before replacing the text. The small diff computes the target offset from the old draft but publishes the new text first, so UIKit cannot consume a clamped request against the old length. This fix is still absent on the current parent and does not affect React Native.
Recommendation. Keep open: work remains. Review the ordering fix for the experimental SwiftUI composer.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Observed GitHub metadata. GitHub state OPEN. Author mackinleysmith. Updated 2026-08-27T17:42:19Z. Draft no. Target t3code/rebuild-mobile-app-swift. Head 39a4d5ea7bcd7e432f45ab4eec800eaec727539c. Branch t3code/fix-swiftui-composer-picker-cursor. Size +9 / -6, 1 files, 1 commits. Mergeability MERGEABLE. Merge state CLEAN. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Request. Prevent a late missing-checkpoint event from replacing an already captured checkpoint in SQL.
Audit finding. Main still copies event.payload.status over an existing checkpoint without a downgrade guard. The diff adds the same ready/error protection already used by the in-memory projector and tests ready followed by missing. The recent SQL read optimizations do not fix this event-ordering defect.
Recommendation. Keep open: work remains. Review and run the SQL projection test for ready followed by missing.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Classify ACP Task calls as agent work and show an agent icon on mobile.
Audit finding. The shared ACP mapper still classifies only by kind, so Task calls with kind other become dynamic_tool_call. Mobile still groups collab_agent_tool_call with the generic hammer icon. Grok task tracking is a separate larger proposal and has not landed, so this small classification gap remains.
Recommendation. Keep open: work remains. Review Task detection and retain the mobile failure-icon test.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. The PR has no live Task-row UI images. Required checks have no results on this head: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Copy code without Markdown fences when the selection includes the final line break.
Audit finding. Main still fences a selected fragment when its common ancestor lies outside pre. This patch detects a sole visible code block in the fragment, with exceptions for prose, file chips, lists, and multiple blocks. It overlaps the earlier final-line proposal but changes serialization more broadly, so choose one combined implementation rather than call either already fixed.
Recommendation. Keep open: work remains. Combine the code-only fragment cases with the earlier final-line selection patch and verify real browser ranges.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Keep child-agent tokens and context windows out of the parent meter.
Audit finding. Main still promotes child task totals into parent usedTokens and chooses the largest context window across all modelUsage entries. The diff preserves parent usage, tracks the observed parent model through initialization and refusal fallback, and keeps child work only in the processed total. The merged assistant-snapshot fix does not cover either child-accounting path, and the missing post-compaction metadata case remains separate.
Recommendation. Keep open: work remains. Use this as the parent-accounting change and reconcile its tests with the other meter fixes.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Link or unlink the PR shown beside a thread from the PR action menu.
Audit finding. Main has linkedPullRequest metadata, but the PR detail menu still has no link or unlink entry. This diff uses the open thread so the entry remains available after unlink and checks the server capability before sending metadata. The durable linked-PR work in PR #8689 is separate from this missing menu entry.
Recommendation. Keep open: work remains. Review the link/unlink cycle with same-environment and cross-environment PR panels.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Remove a newly enabled systemd unit when its first activation fails.
Audit finding. Main still does nothing after a failed fresh install while only restarting an existing installation on repair failure. The launchd refactor therefore left this Linux failure path open, and a leftover unit can make later reconciliation incorrectly return early. The diff adds manager-specific cleanup and a focused failure test without changing launchd behavior.
Recommendation. Keep open: work remains. Run current boot-service checks and review the fresh-systemd rollback for merge.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Preserve theme colors when the Advanced switch is toggled without editing colors.
Audit finding. handleAdvancedChange on main still regenerates each managed palette whenever Advanced is turned off. The patch records whether an unmanaged palette or an advanced edit actually needs regeneration, so a toggle-only round trip leaves the preview unchanged. No later theme change adds this guard.
Recommendation. Keep open: work remains. Review the regeneration guard with default, managed, and imported palettes.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Clear body cursor and selection overrides if the resize handle disappears during a drag.
Audit finding. useResizableWidth still clears body styles only from pointer-up or pointer-cancel handling. Removing its handle leaves no ref cleanup or unmount cleanup in main. The proposed ref cleanup covers this case, while the separate Windows cursor-shape PR does not.
Recommendation. Keep open: work remains. Review the ref cleanup with handle removal and full-panel unmount tests.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Use the Linux icon for known desktop-managed WSL environments across the web UI.
Audit finding. Main treats secondary desktop-local environments as generic local or remote devices. The patch adds WSL-specific ID detection and covers both sidebars, row tooltips, responsive composer pickers, and Provider Settings. the reviewed icon inconsistencies are corrected in the final diff. Detection is limited to desktop-local wsl IDs, so it does not identify a WSL-only primary or an independently paired WSL server.
Recommendation. Keep open: work remains. Review the intended WSL-only primary coverage before approving the icon change.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Show the current-project new-thread binding in the command palette.
Audit finding. The current-project action still displays chat.new while calling startNewThreadFromContext directly. The one-line patch changes its hint to chat.newLocal, matching the existing sidebar distinction between direct creation and the project picker. The sidebar fix does not change this palette action.
Recommendation. Keep open: work remains. Review and land the command-palette shortcut correction.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Remove one trace span per executable candidate during command discovery.
Audit finding. Main still wraps isExecutableFile in a named Effect.fn, even after the recent idle-CPU and Windows PATH fixes. This patch removes only per-candidate spans and retains command-resolution spans. Open PR 4778 has overlapping tracing work and additional spawn changes.
Recommendation. Keep open: work remains. Review this focused tracing change with the owner of PR 4778.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Allow image previews for absolute server file paths outside the thread worktree.
Audit finding. Main still converts absolute paths to workspace-relative paths and rejects files outside that root. The diff adds canonical exact-file image claims, rejects traversal and symlink target changes, and leaves external HTML previews blocked. Shared markdown image rendering on main does not remove the server path restriction.
Recommendation. Keep open: work remains. Review exact-file authorization and run the external-image asset tests.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Filter web and desktop sidebar threads by environment independently of project.
Audit finding. Main only exposes project scope and still builds the thread list from all catalog environments. The complete three-file diff filters threads, drafts, project options, and settled pagination, clears selection, and prevents a stale disabled set from hiding everything after a catalog change. This is session-only web sidebar state, not a connection toggle or a mobile feature.
Recommendation. Keep open: work remains. Review the environment-filter behavior on current main and add current-head visual evidence.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Add previous and next turn buttons to the chat minimap.
Audit finding. Main has marker selection and arrow-key movement inside the minimap but no previous or next turn buttons. The patch extracts a current-index helper, uses the first visible marker, and keeps null while geometry is unavailable, addressing the earlier skipped-turn review findings. It still adds new navigation behavior that needs maintainer review on the current timeline.
Recommendation. Keep open: work remains. Review sequential minimap navigation and disabled boundary states on the latest timeline.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Include symlinks to directories in the project folder browser.
Audit finding. Main still checks Dirent.isDirectory and never follows a symlink to determine its target type. The diff runs stat only for name-matched symlinks and tests directory, file, broken-link, and prefix cases. The shared browse RPC fixes Add Project and path autocomplete on all clients.
Recommendation. Keep open: work remains. Review and run the focused directory-symlink browse test.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Copy selected terminal text with Ctrl+Insert on Windows and Linux.
Audit finding. Main recognizes only the C key for terminal copy, despite already supporting Shift+Insert paste. The patch adds the non-macOS Insert chord and explicitly synthesizes a copy event while preserving plain Ctrl+C behavior. It changes the Ghostty renderer shared by web and desktop, not the separate mobile terminal.
Recommendation. Keep open: work remains. Verify Ctrl+Insert on a non-macOS client with and without a terminal selection.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Keep saved provider model options when switching away and back.
Audit finding. Main still replaces the sticky selection with an options-free value and only reads the current draft when setting a model selection. Thus a newly selected provider does not recover its sticky options through either changed path. The PR adds a Codex and Claude switch test, while recent composer and OpenCode picker work does not change these store operations.
Recommendation. Keep open: work remains. Review option-clear semantics and run the composer draft store switch test.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Avoid HTTP probes against unrelated local binary-protocol listeners.
Audit finding. Main still builds HTTP and HTTPS probes for every discovered listener. Merged PR 6021 filters displayed results by HTML response, but it does not prevent those requests from reaching unrelated applications. This patch adds the missing gate while keeping configured URLs, common development ports, and registered terminal processes eligible.
Recommendation. Keep open: work remains. Review the discovery tradeoff and run the focused scanner tests.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. The reported third-party application crash was not reproduced. Required CI checks are absent at the reviewed head: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Show the correct initial app label and active project and thread in window titles.
Audit finding. Main still starts with a hardcoded channel title, and Electron replaces renderer title updates with the environment display name. The patch changes both the initial title and dynamic title ownership, with browser suffixes and context cleanup when chat closes. The existing nightly-branding synchronization only fixes the later app label, not these initial and thread-context paths.
Recommendation. Keep open: work remains. Review first-load titles and context cleanup in desktop, hosted web, and local web builds.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Keep auth-like files private when materializing Codex shadow homes.
Audit finding. Main marks only auth.json and models_cache.json private and links other shared-home names. Names such as auth.json.bak can therefore be shared with every shadow home. This PR adds a bounded auth-name rule and rejects existing credential symlinks, while preserving ordinary shared files.
Recommendation. Keep open: work remains. Review the auth-name rule and existing-symlink recovery behavior before merging.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Hide web command-palette keyboard labels in narrow viewports.
Audit finding. Main renders shortcut labels at all widths. The one-line responsive change is still absent, but viewport width is not a test for a hardware keyboard or a touch device. It hides hints in a narrow desktop window and leaves them visible on a wide tablet.
Recommendation. Keep open: decision needed. Confirm that viewport width is the intended rule before merging.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Check: PR #8586. Current head e67060bb: required checks are absent from canonical latest-commit metadata: Test, Check, Mobile Native Static Analysis, Release Smoke.
Limits. Required CI checks are not present on the current head in canonical check metadata.
Request. Keep diff file names readable when Git is configured to use mnemonic or no prefixes.
Audit finding. Main still calls plain patch-producing git diff commands, which inherit diff.mnemonicPrefix and diff.noprefix. This diff pins both settings for review, untracked, commit-context, and checkpoint patches and adds real-Git tests. The current renderer changes do not normalize those headers at their source.
Recommendation. Keep open: work remains. Review and run the hostile Git-config patch tests.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Match the idle sidebar update button radius to neighboring controls.
Audit finding. Main still applies rounded-full to the update button in every state. The patch uses the shared control radius only when update details are inactive and keeps the download and ready states circular. This is a desktop updater control in the shared web UI and does not change update behavior.
Recommendation. Keep open: work remains. Review the idle, checking, downloading, and ready button states with the selected theme.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. The attached before and after images were not visually inspected. Required Check, Test, Release Smoke, Mobile Native Static Analysis checks are absent on the collected head.
Request. Classify the GLM 5.3 Flash slug returned by a Codex-backed catalog as current.
Audit finding. The bundled manifest on main still lacks this GLM slug. The hosted-manifest change adds refresh support, but does not add the proposed entry to the checked-in fallback. The patch changes only the manifest and its existing classification test.
Recommendation. Keep open: work remains. Confirm the same entry in the hosted manifest and review the focused data change.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. The currently hosted manifest response was not fetched. Required CI checks are absent at the reviewed head: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Resume Codex parent threads with metadata only to reduce large-history memory use.
Audit finding. Main's parent thread/resume request still omits excludeTurns. PR 8605 fixes quadratic input framing, but it does not prevent Codex from constructing and returning the full history. This diff adds the flag to the runtime, generated binding, generator and wire-encoding test, and is the more complete replacement for PR 6400.
Recommendation. Keep open: work remains. Prioritize review of this parent-resume payload fix on current main.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Stop a closed file editor from writing an already saved buffer over newer external changes.
Audit finding. Main never records which revision was saved, so dispose writes the last buffer again after any edit. This diff tracks the confirmed revision and also rejects change callbacks after disposal. PR #8632 covers the same stale-write defect with more flush-order tests but without that extra guard.
Recommendation. Keep open: work remains. Keep this implementation and bring over the useful flush-order tests from PR #8632.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Explain that an older Codex CLI cannot parse newer service-tier names and offer its update path.
Audit finding. Main returns a generic probe error and version:null when Codex rejects the configured service tier. This PR detects the specific parser error and probes the CLI version so the error can name the required update. Service-tier label changes in the client do not address this provider startup failure.
Recommendation. Keep open: work remains. Review the exact error matcher and version probe against current provider maintenance.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Refresh passive SwiftUI environments faster while work is active.
Audit finding. The experimental parent still polls every passive environment on a fixed 20-second interval. The diff uses five seconds for active or changed shells, ten seconds for idle shells, and per-environment failure backoff, while retaining session-generation checks. Deterministic tests cover event delivery and failed peers, but the rate increase still needs a multi-environment traffic and battery decision.
Recommendation. Keep open: work remains. Review the new polling cadence and failure backoff for the experimental SwiftUI client.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Observed GitHub metadata. GitHub state OPEN. Author saphid. Updated 2026-08-29T13:22:57Z. Draft no. Target t3code/rebuild-mobile-app-swift. Head e0b241923ece1d85e9c6e426ffaab94a46ea90af. Branch fix/swiftui-passive-thread-refresh-upstream. Size +376 / -51, 2 files, 2 commits. Mergeability MERGEABLE. Merge state CLEAN. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Request. Expose fixed diagnostic reason tags for known Git command failures without exposing stderr.
Audit finding. Main GitCommandError still has only generic detail and no reason tag. The diff classifies Git and selected SSH diagnostic lines in two shared error paths, with tests for branch conflicts and hook-output false positives. English-only classification and five manual error constructions remain outside the patch, so it does not solve every failure message in the linked issue.
Recommendation. Keep open: work remains. Review the diagnostic tags and document which Git failure paths remain unclassified.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Disable Claude models that the account organization has restricted.
Audit finding. Main has no model entitlement reader or unavailableReason in the model contract, and informational substitution notices still reach the unknown-message path. The diff reads the CLI entitlement cache and propagates disabled reasons through web settings pickers and mobile thread settings. The existing CLI-version and legacy-model filters do not establish account entitlements, so they do not cover this feature.
Recommendation. Keep open: work remains. Review entitlement cache freshness and verify restricted selections in web settings and mobile.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Commit: Commit badae6a5cc83. The hosted manifest classifies legacy models rather than account restrictions.
Limits. Mobile restricted-row behavior was not reproduced in a native client. Latest-head required checks are not reported: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Keep submitted file comments visible across tab switches and focus their input reliably.
Audit finding. Main still owns file annotations in component-local state and relies on textarea autoFocus. This diff rebuilds submitted annotations from the composer store, tracks editor removals/restores, and focuses draft input on the next frame. The merged right-panel refresh fix changes file contents, not this annotation state.
Recommendation. Keep open: work remains. Review the annotation remap and undo flow, then verify comment persistence across tab switches.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Keep the Dev or Nightly label inside a narrow web or desktop sidebar header.
Audit finding. Current SidebarChrome still lays out the fixed-width brand and environment badge as separate children. The diff groups them in a shrinkable titlebar-safe row and hides Code below a container-width threshold while retaining the wordmark and badge. It only affects the Version pill identification mode, not remote environment connection labels or mobile.
Recommendation. Keep open: work remains. Review the supplied before/after evidence at the minimum sidebar width and the desktop titlebar inset.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Label whether a keybinding minus button removes one condition, a group, or the whole expression.
Audit finding. The current When editor still uses plain minus buttons with Remove condition, Remove negated group, and Remove group labels. The patch derives the label from node type and depth and uses the existing tooltip component, including Clear all conditions at the root. The merged keybinding layout change did not add these scope-specific labels.
Recommendation. Keep open: work remains. Review the removal labels and tooltip behavior for root, leaf, and nested-group controls.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Let Linux distro packages register deep links through their own stable desktop launcher.
Audit finding. Main registers protocol handlers only for packaged builds and chooses APPIMAGE or process.execPath. The patch adds T3CODE_DESKTOP_EXECUTABLE and permits an explicitly configured unpackaged production launcher while preserving packaged registration. PR #8673 handles MIME-cache refresh separately, so neither change replaces the other.
Recommendation. Keep open: work remains. Review the launcher override with a shared-Electron Linux package and document the package setting.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. OAuth callback launch through a distro package was not reproduced. Required Check, Test, Release Smoke, Mobile Native Static Analysis checks are absent on the collected head.
Request. Show file names or a grant root in Codex file-change approval details when no reason is supplied.
Audit finding. Both current file-change request mappings return only reason, so empty approval details remain possible. The PR uses existing patch paths with a 20-entry cap and handles blank reasons. It does not resolve filenames for the newer item/fileChange method, which needs item correlation, so the broader linked issue must remain open.
Recommendation. Keep open: work remains. Review this bounded detail fallback without closing the remaining item-correlation request.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Include otherwise omitted dot files and directories in ordinary non-Git project listings.
Audit finding. Main returns the native index listing without supplementing omitted dot entries. The diff adds a bounded dot-directory walk only for ordinary non-Git roots with no encountered ignore files, leaving home/root scans and Git repositories unchanged. Projects with ignore files and index-backed search remain outside this fix.
Recommendation. Keep open: work remains. Review the fallback scope and verify the reported ordinary non-Git project case.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. The added listing path deliberately skips roots or descendants with .gitignore or .ignore files. Latest head has no results for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Refresh Linux MIME discovery after generating the desktop URL-handler entry.
Audit finding. Main writes the handler and runs xdg-mime default without updating mimeinfo.cache. The patch adds update-desktop-database before the default-handler call and catches its failures separately so registration can continue. The earlier Linux protocol-registration fix and the separate distro-launcher PR do not add this cache refresh.
Recommendation. Keep open: work remains. Review cache refresh with GNOME or GIO, including the missing desktop-file-utils case.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. No GNOME or GIO callback discovery test was run. Required Check, Test, Release Smoke, Mobile Native Static Analysis checks are absent on the collected head.
Request. Do not switch project commands to offline writes after arbitrary server probe failures.
Audit finding. Main still clears the runtime marker and opens offline state after any probe failure. The patch narrows fallback to a structural ECONNREFUSED transport error and adds malformed-origin and refused-port coverage. It reduces one concurrent-writer path, but does not provide server-directory ownership protection.
Recommendation. Keep open: work remains. Review and test the refused-endpoint fallback together with the server ownership work.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Keep saved-connection row height stable when removal controls become wider.
Audit finding. Main still leaves the saved-environment title and metadata without truncation. The complete diff only adds min-w-0 and truncate, preserving stacked small-screen controls and connection behavior. Web and the Electron settings page share this row, while the React Native screen is separate.
Recommendation. Keep open: work remains. Review the row with long Windows metadata and pending removal controls.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Give the mobile project destination screen a readable native title.
Audit finding. The current route still has no title, so React Navigation can show AddProjectDestination. This diff supplies only the route display title and leaves navigation and project creation unchanged. The source gap remains after SDK57.
Recommendation. Keep open: work remains. Review the current required checks and merge the title fix if they pass.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Check: PR #8717. Current head 1455acc1: required checks are absent from canonical latest-commit metadata: Test, Check, Mobile Native Static Analysis, Release Smoke.
Limits. Required CI checks are not present on the current head in canonical check metadata.
Request. Add a sidebar thread-menu action to filter by its project and return to all projects.
Audit finding. Main has a project picker but buildThreadActionMenuItems has no project-filter action. The diff reuses projectScopeKey, resolves grouped projects at menu-open time, and supplies a reverse action. It affects shared web and desktop menus, not native mobile or the server.
Recommendation. Keep open: work remains. Review the sidebar-only action and its existing project-scope tests.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Give the development runner ownership of the desktop bundle watcher and Electron supervisor.
Audit finding. Main still starts the Electron supervisor from the packer onSuccess hook and uses pattern-based stale-process cleanup. The patch replaces that with three owned sibling processes and keeps the server build dependency on dev:electron. It also changes process-group handling for single-command modes, so signal cleanup needs focused platform checks.
Recommendation. Keep open: work remains. Verify Ctrl+C and sibling-exit cleanup on the supported development platforms.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Reconnect a thread's Codex MCP servers on demand without interrupting active work.
Audit finding. Main has no reconnect-mcp command or onlyIfIdle session-stop guard. The existing pre-turn MCP config reload does not provide the proposed explicit process restart for rebuilt tools. The PR covers web and native mobile commands and adds server-side checks for active turns, queued work and pending requests.
Recommendation. Keep open: work remains. Review the idle-only session-stop guard and verify both composer command paths.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Count an active workflow coordinator while all members of the current phase are settled.
Audit finding. Main still excludes every workflow coordinator that has members from status counts. That rule came from PR 6672 to avoid double counting, but leaves the between-phase gap at zero. This patch counts the active coordinator only in that gap and keeps its aggregated token usage excluded.
Recommendation. Keep open: work remains. Run the shared agent-rollup tests and check the between-phase display.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Return the terminal viewport to the active prompt when the user sends input from scrollback.
Audit finding. Main forwards keyboard, paste, and composition input without first leaving scrollback. The final patch limits the bottom jump to explicit user-input handlers and drawer shortcut writes, correcting the reviewed automatic-reply and mouse-report issue. It covers web and desktop terminal placements but does not change native mobile input.
Recommendation. Keep open: work remains. Verify typing, paste, composition, and navigation keys from scrollback in the drawer and right panel.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. The diff adds no focused input test and no client interaction was run. Required Check, Test, Release Smoke, Mobile Native Static Analysis checks are absent on the collected head.
Request. Increase the old Ghostty byte budget so web and Android terminals retain useful scrollback.
Audit finding. Main still passes 10,000 as max_scrollback while naming it as rows. This small patch changes the value to a 32 MiB byte budget in web and Android and adds a real-WASM retention check. the author reports manual web, desktop, and Android checks. It is intentionally not an exact 10,000-line guarantee, and neither the larger replacement nor this hotfix has merged.
Recommendation. Keep open: work remains. Decide whether to land the bounded-byte hotfix before the coordinated Ghostty ABI upgrade.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. The author-provided manual runtime results were not independently repeated. Required Check, Test, Release Smoke, Mobile Native Static Analysis checks are absent on the collected head.
Request. Enable Android range selection and clean inline icon placeholders from copied text.
Audit finding. Main still disables the shared selectable renderer outside iOS. This patch adds an Android entry point, platform fonts, nested rich-block scrolling, and a native Copy callback that removes image replacement characters. It has broader coverage than PR #7380 but changes the renderer and adds a native module, so copy, link, list, and table behavior need joint review.
Recommendation. Keep open: work remains. Review the Android shared-renderer change and select it as the replacement for PR #7380 if its coverage is accepted.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Remove all stale shortcuts when a project action is changed, cleared, or deleted.
Audit finding. Main still sends a bare upsert from the chat-header action editor and compares server shortcut targets as literal strings. The diff removes all prior targets, preserves conditional shortcuts through parsed matching, and uses routed-environment actions with primary non-action shortcuts. Project Settings and the chat header are both covered, while browser persistence remains Electron-gated.
Recommendation. Keep open: work remains. Review the combined shortcut precedence and removal changes on routed desktop chats.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Move provider and thread warnings into a compact title-bar control with dismissal choices.
Audit finding. Main still renders separate provider and thread error banners over the timeline. The full diff replaces them with a warning popover, run-scoped temporary dismissal, permanent exact-warning dismissal, and a Restore all setting. This is a web and desktop presentation and persistence change, not a server or native mobile error-recovery fix.
Recommendation. Keep open: work remains. Rebase the warning control and confirm the run-scoped dismissal behavior on current main.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Open Android GLB workspace files in an installed viewer instead of reading binary bytes as source text.
Audit finding. Main only recognizes browser and image preview types, so GLB still takes the text-read path. The diff adds an Android ACTION_VIEW handoff, bounded exact-file grants, cancellation, and a one-file temporary cache without an in-app 3D renderer. The native image/PDF work merged since its base does not add GLB support, but the asset-serving changes need integration with that newer route.
Recommendation. Keep open: work remains. Rebase onto the current asset-serving route and verify bounded GLB handoff in an Android native build.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Merged pr: PR #8959. Newer native image/PDF preview work does not cover GLB.
Limits. The no-installed-handler case has unit coverage but no physical-device reproduction. Latest head has no results for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts with the target branch.
Request. Preserve user skill scope when user and workspace roots name the same directory.
Audit finding. Main scans the user root and then the workspace roots without deduplicating their real paths. If the server cwd overlaps the user Claude directory, the later scan overwrites user scope with project scope. The diff removes identical project roots, including symlink aliases, while preserving normal workspace precedence.
Recommendation. Keep open: work remains. Run the focused skill-discovery suite and review the root-deduplication change with plugin discovery.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Add a shortcut that opens the native project folder picker or the add-project fallback.
Audit finding. Main exposes the existing file-manager action but has no project.openFolder command. The diff registers mod+alt+o, reuses native picker routing, and falls back when the browser or several environments prevent a direct choice. Native mobile is intentionally outside this keyboard feature.
Recommendation. Keep open: work remains. Review the direct-picker intent with the desktop and WSL environment routing.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Do not reselect a disabled provider instance for generated titles and source-control text.
Audit finding. Main checks the selected instance but chooses its fallback from the legacy providers map alone. The patch adds the explicit default-instance enabled check without changing provider order or choosing unregistered custom instances. Recent provider upgrade and health-probe fixes leave this fallback unchanged.
Recommendation. Keep open: work remains. Run the focused settings tests and review the default-instance precedence change.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Preserve collapsed diff files when the right panel switches tabs.
Audit finding. Main still keeps collapsed file keys in component-local state, which disappears when the panel unmounts. The diff moves that state to an environment/thread/section-keyed session store. It deliberately does not restore scroll position or preserve collapse state across reloads, so the broader linked issue remains partly open even if this PR lands.
Recommendation. Keep open: work remains. Review the scoped collapse-state change and keep scroll restoration tracked separately.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. Scroll position restoration from the linked issue is explicitly outside this PR. Latest head has no results for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Honor the GitHub CLI base remote when creating upstream PRs from a fork.
Audit finding. Main still compares the head remote with origin rather than remote.*.gh-resolved=base. This diff reads the configured base remote, preserves the fork owner in the head selector, and distinguishes synthetic PR worktrees from branches merely tracking a default branch. The newer push-target fix does not add this GitHub PR-base handling.
Recommendation. Keep open: work remains. Review the fork/upstream PR creation and default-branch association tests.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. Latest head has no results for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts with the target branch.
Request. Make sidebar, right-panel, and terminal motion configurable with a default of zero milliseconds.
Audit finding. Main uses fixed sidebar transitions and has no shared panel-duration setting. The full diff adds a 0 to 400 ms preference, reduced-motion gating, and retained closing content. The mobile overlay deliberately keeps the shared sheet motion at every setting value, as the resolved review confirms. The branch has conflicts and needs a current-main maintainer review.
Recommendation. Keep open: work remains. Rebase the panel-motion PR for maintainer review.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Comment: Discussion comment. The author removed duration forwarding so the mobile overlay keeps the same shared sheet motion for every panel setting value.
Request. Stop offering Homebrew updates for ordinary provider binaries installed in /usr/local/bin.
Audit finding. Main still classifies every executable in /usr/local/bin as Homebrew-managed. The patch removes that broad match while retaining resolved Cellar and Caskroom paths, so Intel Mac Homebrew symlinks remain detectable. Homebrew formula selection and npm-versus-brew version checks in other open PRs are separate concerns.
Recommendation. Keep open: work remains. Review this narrow classification change with both a Linux standalone binary and an Intel Mac Homebrew symlink.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Provide a supported setting that stops local server and browser trace-file writes.
Audit finding. Main already accepts a None trace level, but still creates the trace directory and sink and reports local tracing enabled to clients. The patch changes all three paths and covers browser-submitted spans as well as server spans. It leaves configured browser OTLP forwarding and metrics separate.
Recommendation. Keep open: work remains. Review the documented off-switch behavior and run the focused observability tests.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Ignore the historical assistant snapshot replayed at a Claude resume cursor.
Audit finding. Main guards resumed result messages against creating false turn completion, but handleAssistantMessage has no guard for the initial resume UUID. A replayed assistant frame can still append old text to a new turn after compaction. The diff adds that identity check and a deterministic compact-plus-replay test without suppressing other assistant UUIDs.
Recommendation. Keep open: work remains. Review the resume-UUID guard with the existing resume and compaction tests.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Distinguish a rejected environment credential response from an unreachable relay endpoint.
Audit finding. Main wraps every credential-mint client failure in EnvironmentMintRequestFailed even when the environment returns a typed response. The diff reuses response classification, keeps actual transport failures distinct, and logs the classified reason with the trace ID. The linked connection symptom still needs this relay-side change, not only client wording changes.
Recommendation. Keep open: work remains. Review and run typed-error versus transport-failure tests for the relay mint path.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Show Claude notices when a safety fallback changes the serving model.
Audit finding. Main still consumes model_refusal_fallback as a no-op, so no warning reaches any client. The diff forwards the provider notice through the existing warning path. The parent-context PR records the fallback model for accounting but does not show the notice, and the organization-restriction PR handles a different informational message.
Recommendation. Keep open: work remains. Combine the warning emission with the observed-model accounting case when either change lands.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Let composer command descriptions use the available row width.
Audit finding. Main still caps the description at 48 characters of width. The two-file diff removes that cap while retaining flex growth, truncation, and the source badge position. This is a shared web and desktop layout change, not a mobile change.
Recommendation. Keep open: work remains. Review and merge the row-width change after current checks pass.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Open remote projects in Zed through its SSH deep-link scheme.
Audit finding. Main supports local Zed launching but only VS Code-compatible editors in remote-link mode. The patch adds Zed-specific URL construction, desktop protocol-handler detection, strict external URL checks, and a browser fallback choice. It relies on a separate SSH route and does not make a T3 Connect tunnel an SSH transport. username propagation in PR #8305 remains a separate pending change.
Recommendation. Keep open: work remains. Review the Zed remote flow with a saved SSH alias and advertised hosts, preserving the username work in PR #8305.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. The attached editor-launch video was not inspected and no OS protocol handler was run. Required Check, Test, Release Smoke, Mobile Native Static Analysis checks are absent on the collected head.
Request. Fail signed-out Claude turns and report explicitly unauthenticated provider state.
Audit finding. Main treats a success-subtype result as completed even when is_error follows an authentication_failed assistant message. This diff records the auth failure and emits a failed turn, then distinguishes first-party tokenSource:none from API-key authentication in provider status. The two CLI auth-status proposals overlap only the snapshot part and do not fix this turn-completion path.
Recommendation. Keep open: work remains. Keep the failed-turn fix and settle one shared authentication-status and login-hint approach.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Show downloaded desktop release notes inside the update toast instead of opening GitHub.
Audit finding. Main still opens GitHub from the downloaded-update toast while the sidebar already renders release-note groups. The patch shares that renderer and updates modern and legacy sidebar callers to use an expandable toast. The final diff sets timeout to zero and updates both test expectations, so the older dismissal findings are resolved. Missing release notes deliberately produce no disclosure.
Recommendation. Keep open: work remains. Review the expandable toast on stable and nightly updates in both sidebar modes, including missing notes.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Restore composer banner padding and center actions beside title and description.
Audit finding. Main still uses one-unit padding and renders the description in a separate child row. The diff restores horizontal padding and places title and description in one column. The alignment portion overlaps the later alignment-only PR, while this PR also changes banner density.
Recommendation. Keep open: work remains. Choose one shared banner-alignment change and retain the intended padding fix.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Bound captured SSH stdout and stderr without losing trailing protocol output.
Audit finding. Main still appends every decoded chunk to an unbounded string. The diff retains the newest one MiB in a byte ring, keeps draining the process, and tests both oversized chunks and a UTF-8 boundary with trailing pairing JSON. The SSH timeout and error-display truncation do not bound the memory retained during collection.
Recommendation. Keep open: work remains. Review the bounded collector and run the current focused SSH checks.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Keep Electron tooltips outside the native window-controls strip.
Audit finding. The shared TooltipPopup currently sets stacking order but reserves no native titlebar collision space. The diff reads the visible Window Controls Overlay height and adds it to top collision padding, with a zero fallback for ordinary browsers. The supplied reproduction is Linux Electron, and Windows behavior still needs maintainer review.
Recommendation. Keep open: work remains. Review the overlay-height collision padding on supported Electron platforms.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Browse nearby folders and files from the file-preview breadcrumbs.
Audit finding. Main still renders the breadcrumb segments as static tooltip labels. The diff adds an on-demand child picker, existing file-open routing, and refresh handling without changing the Files explorer selection. PR #7145 proposes a different interaction by revealing folders in the explorer, so these are alternatives rather than an already-landed fix.
Recommendation. Keep open: work remains. Review the breadcrumb picker interaction alongside the explorer-reveal proposal in PR #7145.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Preserve native Claude MCP tool types and separate concurrent child tool state.
Audit finding. Main classifies tool calls by name and keys in-flight tools only by content-block index. Native MCP calls named create can therefore appear as file edits, and child streams can overwrite each other at the same index. The diff uses native block types, canonical MCP payloads, and sidechain-qualified block keys, but its tool-state refactor must be reconciled with late-result retention.
Recommendation. Keep open: work remains. Review the native MCP lifecycle mapping and integrate its tool-ID map with late-result retention.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Prevent filename descenders and hover underlines from being clipped in diff headers.
Audit finding. Main still sets line-height to 1 on 12px header text and its metadata children. The four-rule diff changes it to 16px while retaining the 32px header slot, which matches the supplied clipping evidence. No later header change applies these line-height values.
Recommendation. Keep open: work remains. Review the existing before/after evidence and complete the latest required checks.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Open the correct project settings page from each thread menu.
Audit finding. Main offers project settings from project controls but not from thread action menus. The diff adds the action to modern and legacy sidebars and the chat header, resolves logical groups for multi-environment projects, and closes the mobile-width web sidebar before navigation. It does not change native mobile navigation.
Recommendation. Keep open: work remains. Review the grouped-project routes and thread-menu entry points.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Start each managed SSH launch with a fresh log so silent failures do not show old errors.
Audit finding. The merged launch-diagnostics fix added the empty-log message, but main still appends to the previous server.log. This diff unlinks the log only for a new managed launch and executes the generated shell in a test with a stale log and silent server. It preserves existing-server reuse and fixes a distinct on-disk log lifetime issue, not SSH output-buffer growth.
Recommendation. Keep open: work remains. Review and integrate the one-line launch fix with its executed-shell test.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Mark cached threads from unreachable environments offline and place them below reachable work.
Audit finding. Main still derives live labels from cached thread state without environment availability. The diff adds offline presentation to web and React Native and sinks only unpinned active rows, intentionally preserving user pin order. It does not add local cleanup or disable every remote action requested in the linked issue, and the separate dead-stream presentation gap remains.
Recommendation. Keep open: work remains. Review offline presentation with pin order retained and keep the broader offline-cleanup request separate.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Add an optional high-contrast user-message appearance.
Audit finding. Main has semantic message colors and a global contrast preference, but no separate user-message presentation setting. The full diff adds typed persistence, theme-derived contrast floors, immediate application, and reset support for web and desktop. Native mobile deliberately keeps its separate appearance system, so this is not cross-client parity.
Recommendation. Keep open: work remains. Review the web and desktop preference and settle the native-mobile parity scope.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Expose the canonical thread ID to terminal processes and Project Actions.
Audit finding. Main merges host and caller-supplied terminal environment values without assigning T3CODE_THREAD_ID. The patch sets the session thread ID after that merge and adds a spoofed-value test. The shared startSession boundary covers terminal creation and restart for web, desktop, and mobile, including Actions.
Recommendation. Keep open: work remains. Review the terminal spawn change and document T3CODE_THREAD_ID for Action authors.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Reduce repeated VCS repository-detection probes by extending the positive cache lifetime.
Audit finding. Main still uses a two-second VcsDriverRegistry detection TTL and leaves negative results uncached. This diff changes only the positive lifetime to five minutes and tests retention and expiry. The root lookup cache in PR #8187 addresses a different resolver, so this proposal remains open with a separate staleness tradeoff.
Recommendation. Keep open: work remains. Measure detection calls on current main and decide whether the five-minute positive TTL is acceptable.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Keep workflow phase definitions when later task-progress events omit phases.
Audit finding. Main has no dedicated phase snapshot, so plain task-progress updates can still replace the last phase list. This diff keeps phases on a separate stable row. The unresolved summary-overwrite finding is not supported by the source: the client reads payload.summary, and the new row only sets the outer activity.summary.
Recommendation. Keep open: work remains. Resolve the disproved summary finding and obtain current required checks.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Preserve collapsed diff files and file-tree state through workspace refreshes.
Audit finding. Main still uses a content-dependent diff cache key as file identity and resets all tree paths after each query result. The merged file-watcher work refreshes these panels but does not preserve their local state. This diff separates stable path identity from content version and applies tree path changes incrementally.
Recommendation. Keep open: work remains. Review refresh and workspace-switch behavior with the stable diff keys and tree updates.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Avoid building a global canonical-assistant ID list during thread-content search.
Audit finding. Main still uses an IN subquery over every canonical assistant message ID before text filtering. The PR replaces it with indexed EXISTS while preserving membership semantics, and the search and migration tests cover decoy assistant messages and the query plan. The leading-wildcard message scan remains, so this is a bounded search improvement rather than a complete search-index redesign.
Recommendation. Keep open: work remains. Review the partial-index migration and run the current search tests before merging.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. The reported benchmark was read in the PR body, not rerun; incremental index write cost remains unmeasured. Required CI has no result on the reviewed head: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Render CJK bold text correctly next to Chinese text and punctuation.
Audit finding. Main has no CJK-aware emphasis extension in either chat Markdown pipeline. The full diff adds it for bold text in web and desktop, but native mobile still uses a separate parser and CJK strikethrough remains outside this patch. Those are scope decisions, not proof that the requested web bold fix has landed.
Recommendation. Keep open: work remains. Confirm the web-bold scope and resolve the mobile and strikethrough follow-up requests.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Add a Reload Window command that refreshes connected provider metadata first.
Audit finding. Main has no window.reload command in the shared registry or command palette. The diff registers the command, refreshes each connected environment, and reloads once those refresh promises settle, including failures. Provider metadata refresh is not a provider-session restart, so the plugins-and-skills claim needs a focused check.
Recommendation. Keep open: work remains. Verify that metadata refresh discovers the intended provider-side tool changes before shipping the command.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Keep Linux AppImage update filenames stable so launchers survive later updates.
Audit finding. Main still uses versioned AppImage names, and the patch changes only Linux AppImage release naming while preserving AUR compatibility with old tags. The final diff correctly prefers a valid stable asset and falls back to the legacy versioned asset. Its first legacy-to-stable update still removes the old launcher path, and the review explicitly awaits maintainer acceptance of that one-time repair cost.
Recommendation. Keep open: decision needed. Accept or reject the one-time launcher repair required by the first versioned-to-stable update.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Keep foreign memory-thread text out of the active chat when no thread-start event was seen.
Audit finding. Merged PR 5468 filters memory threads only after identifying them through thread/started. Main's separate foreign-thread guard suppresses lifecycle methods but still lets item deltas through. This PR covers the missing-start ordering while preserving registered child routing and approval receipts, so the earlier memory fix is not enough to close it.
Recommendation. Keep open: partial fix. Review the foreign-thread item filter together with child-registration replay coverage.
Request. Open PR body screenshots in a navigable in-app image gallery.
Audit finding. Main PR markdown still has no image-expansion handler, although chat images already have one. The diff builds an ordered gallery and portals the shared dialog to document.body with capture-phase keyboard handling. The remaining viewport-ownership review comment is stale because that portal is already present. The feature still needs integration with current shared image rendering and a clean merge base.
Recommendation. Keep open: work remains. Review the supplied gallery interaction evidence and integrate the latest shared image-renderer changes.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Copy the active thread PR URL or thread ID with a shared keyboard shortcut.
Audit finding. Main has thread-menu copy actions but no thread.copyReference command. The diff adds shared URL precedence, command-palette and chat handlers, plus iOS and Android hardware-keyboard handling with terminal exclusions. Native code and feedback behavior are part of the change, while the supplied live interaction covers web only.
Recommendation. Keep open: work remains. Complete native hardware-keyboard verification for copy success, failure, and terminal focus.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Refuse desktop startup instead of silently selecting another port for the same data directory.
Audit finding. Main still scans every port above 3773 and retains the same data home. The patch blocks that default-port path before spawning and leaves explicit ports unchanged. It does not attach to a running server or stop all possible same-directory writers, so generic ownership work remains separate.
Recommendation. Keep open: work remains. Review the default-port refusal with the server-directory ownership proposals.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Use the client locale to choose the first day for next-week snooze.
Audit finding. Main still computes next week as Monday, although merged PR 8741 now removes duplicate wake times. The patch keeps that deduplication and passes the desktop timestamp locale through the web wrapper while shared mobile callers use the runtime locale. Runtimes without Intl week information keep Monday, so mobile week-info support still needs verification.
Recommendation. Keep open: work remains. Verify the shared fallback on mobile and run the focused locale tests.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Limits. No desktop or mobile runtime was launched to check Intl week-info support. Required CI checks are absent at the reviewed head: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Attribute usage to projects and filter every usage view to one project.
Audit finding. Main usage buckets have no project identity. Publishing head a59e015 supplies the missing test repository and persists Codex cwd, and its required jobs now pass. The diff still includes the range UI and broad project-attribution changes, so it needs a focused maintainer review rather than closure or an automatic safe-merge label.
Recommendation. Keep open: work remains. Review project attribution after isolating it from the range change.
Confidence medium. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Open a T3 thread directly from its attributed usage row.
Audit finding. Main has neither the thread usage table nor its navigation action. Publishing head c00ef15 carries the corrected timestamp, query-scope, and chart behavior, and its current checks pass. The link is a small addition, but the PR still includes the unmerged attribution stack and is not independently safe to merge.
Recommendation. Keep open: work remains. Review the isolated thread-link commit after the lower usage layers are accepted.
Confidence medium. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Forward POSIX login-shell Bitbucket credentials into the desktop backend environment.
Audit finding. Main probes a fixed login-shell variable list that does not include the three Bitbucket credential names read by the server. The patch forwards the complete credential group only when no inherited credential is present, with tests for hydration and precedence. Windows-to-WSL forwarding is a separate open path.
Recommendation. Keep open: work remains. Run the shell-environment tests and review the credential-group precedence.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Request. Use Bitbucket's workspace-scoped permission endpoint before pull request writes.
Audit finding. Main still requests the retired user permissions endpoint and treats only HTTP 410 as unknown permission. The diff moves the request to the workspace endpoint, preserves repository filtering and permission decoding, and tests the old endpoint returning 404. It covers the shared preflight used by comments and merges and replaces the open 404-bypass workaround.
Recommendation. Keep open: work remains. Review the workspace endpoint and token-scope contract, then run the required checks on the current head.
Confidence high. Release: Not applicable. PR readiness: Needs maintainer review.
Pr: PR #8557. Alternative workaround bypasses the same 404 response rather than replacing the endpoint.
Merged pr: PR #6525. Previous merged change handled removal only as HTTP 410.
Limits. The author did not verify a live Bitbucket write through the replacement endpoint. Required current-head checks are absent: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Close the Claude capability query when the probe finishes.
Audit finding. The current probe still calls abort.abort() without retaining or closing the SDK query. Later changes disable probe hooks, MCP servers, and IDE discovery, but do not change this finalizer. The proposed cleanup remains absent, and its exception handling has no focused test.
Recommendation. Keep open: work remains. Add a probe cleanup test for successful initialization and interruption.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Make web code-block copying work over plain HTTP.
Audit finding. Main still returns without copying when navigator.clipboard is absent. The actual one-file diff adds only the textarea fallback, not the position setting or touch CSS described in the body. Current main now reports clipboard errors, so a refreshed patch must retain that behavior.
Recommendation. Keep open: work remains. Refresh the clipboard-only patch and correct its title and body.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Include directory symlinks and Windows junctions in the project folder picker.
Audit finding. Main still filters browse entries with dirent.isDirectory(), so links to folders remain absent. The PR adds bounded stat calls, but its new test calls fsPromises.symlink while the module imports NodeFSP. Review also correctly identifies that the Windows name exclusion hides matching project links outside the profile.
Recommendation. Keep open: work remains. Fix the missing test import and scope the legacy-junction exclusion before running the Windows browse test.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Comment: Discussion comment. The missing fsPromises alias is visible in the complete patch and current import pattern.
Limits. No Windows runtime reproduction was performed. The collected latest head has no results for these required checks: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Closing a Windows terminal leaves its shell and child processes running because node-pty rejects signal arguments.
Audit finding. Pinned main still starts every terminal teardown with kill("SIGTERM"), and NodePtyAdapter forwards that unsupported argument on Windows. The PR adds the missing signal-free Windows teardown with a focused test, but its old error shape and file locations need to be adapted to current main. Recent terminal polling work does not change teardown.
Recommendation. Keep open: work remains. Rebase the signal-free Windows teardown onto current Manager.ts and run its focused Windows test.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Retry the startup auth probe when the window regains focus or the network returns.
Audit finding. The current root error view still offers only reset and reload, with no focus, visibility, or online listener. Auth bootstrap clears a rejected in-flight promise, so a route invalidation can make a fresh probe, but current error handling does not request it. The PR fixes this recovery path only and does not repair the session-store failure reported in issue 3513.
Recommendation. Keep open: work remains. Add one router-level recovery test and review the retry behavior.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Limits. The recovery flow was not exercised in a client. Required checks absent from the canonical latest-commit rollup: Check, Test, Mobile Native Static Analysis, Release Smoke.