pingdotgg/t3code. All authors. Drafts included. Default branch main. 570 issue assessments and 925 PR assessments. Initial inventory: 570 open issues and 924 open PRs. Current assessed open inventory: 570 issues and 924 PRs. Final reconciliation: 2026-09-01T11:57:41.491617+00:00.
Request. Import external Claude and Codex sessions with later transcript synchronization.
Audit finding. The import RPCs and orchestration-v2 SessionImportService are absent from main. This implementation depends on the open V2 branch and makes imported-thread reads synchronize provider transcripts, which adds persistence and concurrency behavior beyond one-time import. Its 856-file stacked diff and untested live Codex resume prevent a merge recommendation. The required Check fails on JSON use in the new session-import tests.
Recommendation. Keep open: decision needed. Decide the V2 import and synchronization contract before reviewing the feature commits separately.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author Bil0000. Updated 2026-09-01T05:36:37Z. Draft yes. Target t3code/codex-turn-mapping. Head d265cee48708e0f16a42c6f351fa6cfb72c4bdf6. Branch feat/import-session-v2. Size +177222 / -75883, 856 files, 215 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #2829. The target V2 runtime is not merged.
Pr: PR #5499. The body documents live Codex resume as unverified.
Check: GitHub check. Check fails on two preferSchemaOverJson errors in SessionImportService.test.ts.
Limits. The full 12 MB stacked diff was not reviewed. Live Codex resume was not reproduced. GitHub reports merge conflicts against the target branch. Required Check fails on JSON use in SessionImportService.test.ts.
Request. Restore sticky provider options without changing the selected model and adjust Grok composer controls.
Audit finding. Main still resolves draft options before thread or project options without the proposed sticky fallback, and Grok still has the Early Access badge. Plan commands are now gated by the global plan-mode setting, not the provider control flag in this diff. The sticky behavior overlaps the later option-preservation PR, but the badge and command changes are separate product choices.
Recommendation. Keep open: work remains. Split sticky option resolution from the badge and plan-menu choices.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Make project settings in the sidebar filter reachable by keyboard and screen reader.
Audit finding. The patch adds context-menu access and hides a nested mouse-only button in the old radio menu. Main now uses a searchable combobox but still nests the settings button in each option without the proposed context-menu handler. The accessibility request remains, while the patch must be adapted to the new combobox focus behavior instead of restoring the old menu.
Recommendation. Keep open: work remains. Implement and verify project-action keyboard access in the current searchable combobox.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Canonical current-head results are missing for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports conflicts with the target branch, so recorded checks do not validate a rebased integration.
Request. Move a running provider conversation and its working tree between connected environments.
Audit finding. This is stacked on the open orchestration-v2 rewrite and introduces cross-environment transfer, single-writer locking and recovery migrations. Current Run on selection is not a live-thread handoff implementation. The collected 882-file, 12.8 MB comparison includes the rewrite, so claims about crash recovery and Git rollback have not received a complete independent diff review here.
Recommendation. Keep open: decision needed. Choose the handoff scope and review a rebased feature-only diff after the orchestration-v2 base is settled.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author Bil0000. Updated 2026-09-01T05:36:37Z. Draft yes. Target t3code/codex-turn-mapping. Head 0250f02be4edc317d816445e504b3cc6673739eb. Branch feat/thread-handoff. Size +182000 / -83743, 882 files, 262 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #2829. Open required orchestration-v2 dependency.
Limits. The 882-file cumulative diff and all 80 review threads were not fully reviewed. GitHub reports conflicts with the target branch, so recorded checks do not validate a rebased integration.
Request. Find and highlight visible text within the active orchestration-v2 thread.
Audit finding. Main has cross-thread search, but no active-thread find command with virtualized match navigation. This PR targets the open v2 branch and its collected 876-file comparison includes that rewrite. Its feature is therefore neither landed nor proved redundant; the older terminal-label highlight finding also needs confirmation on a clean current-base diff.
Recommendation. Keep open: work remains. Rebase the in-thread find feature onto the current v2 branch and verify its search corpus matches rendered text.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author Noojuno. Updated 2026-09-01T05:36:36Z. Draft no. Target t3code/codex-turn-mapping. Head 25adc8e21704dda50c7a0ad05077456138c80a76. Branch t3code/thread-search-v2. Size +176093 / -83771, 876 files, 217 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Limits. The 876-file cumulative diff was not fully reviewed. The outdated unresolved terminal-label highlight finding was not confirmed on a clean feature-only diff. GitHub reports conflicts with the target branch, so recorded checks do not validate a rebased integration.
Request. Add safe worktree lifecycle management to the V2 orchestrator.
Audit finding. Current main already recreates missing worktrees through PR 7839, but lacks the proposed inventory, retention policy, and V2 startup integration. The body declares a dependency on the still-open orchestrator branch, and the actual diff includes 923 files and 285,412 changed lines. Only the worktree contracts and mutation-permit module were inspected, so neither closure nor merge readiness is established.
Recommendation. Keep open: partial fix. Rebase onto the chosen orchestrator base and provide a lifecycle-only diff for a complete safety review.
Confidence low. Release: In stable source. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author StiensWout. Updated 2026-09-01T05:36:38Z. Draft no. Target t3code/codex-turn-mapping. Head bdc613b9f3f9fecc9d611b94a2fa014b393a27ab. Branch t3code/worktree-management-v2. Size +188333 / -97079, 923 files, 272 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Limits. The 13,651,241-byte diff spans 923 files and was not fully inspected. Selected worktree contracts and lifecycle serialization were read. V2 session restart, cleanup safety, UI, and the unrelated orchestrator changes still need a full review.
Request. Adds event-sourced read and unread state shared by clients instead of keeping web-only visit markers.
Audit finding. Main still stores read markers locally, so this feature is not superseded. The current head retains the valid unbounded-view-timestamp finding and a queued unread-to-view race, despite the latter review being marked resolved. Mobile can also submit a null view token before the shell arrives and then skip retrying it. The migration now conflicts with main's migration 041, and the feature needs fresh multi-client verification.
Recommendation. Keep open: work remains. Rebase onto current main, fix boundary validation and view-command ordering, and verify shared read state with two clients.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. Unresolved timestamp-validation finding remains valid in the final head.
Limits. Read-only review. No local tests, browsers, native clients, or runtime verification were run. Canonical current-head required checks pass, but the branch conflicts with current main and has no approving review decision. The alternative shared-read-state proposal was checked for stated scope, not reviewed in full here. No duplicate-closure recommendation is made. Mobile reports views on focus, but this diff does not add native unread indicators or a native mark-unread action.
Request. Remove the Ultrathink option, prompt rewriting, and related controls and styling across clients and the Claude adapter.
Audit finding. Main still advertises Ultrathink and injects its prompt prefix, so this deletion is not already landed. The full diff removes the feature across contracts, server, web, settings, and mobile, while ordinary effort values still use the existing default fallback. The body gives no upstream source for the claim that Ultrathink is obsolete, and later Ultracode help text is a different feature.
Recommendation. Keep open: decision needed. Confirm the removal decision and verify saved selections plus old-server client compatibility on a current rebase.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Keep complete usage counts when transcripts contain several snapshots of one message.
Audit finding. Main still keeps the first dedupe key both within a file and across aggregation. The patch replaces a poorer record and retracts its old cost, but a review comment correctly identifies crossing token fields as an uncovered case. Main now also parses appended transcript bytes with cache version 3, so replacing the old full-file helper would lose newer incremental-scan behavior.
Recommendation. Keep open: work remains. Rework deduplication for incremental scans and add a crossing-fields test before choosing whole-record versus per-field merging.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Canonical current-head results are missing for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports conflicts with the target branch, so recorded checks do not validate a rebased integration.
Request. Bound background-session deferral, refresh activity timestamps, and report lost Claude tasks.
Audit finding. Merged PR 5891 now emits stopped events for live Claude tasks during session teardown. Main still defers reaping for background liveness without the proposed cap and does not synchronize bindings on runtime activity. The reviewed patch also leaves activity events unguarded against an old provider instance, as its open review reports.
Recommendation. Keep open: partial fix. Guard activity touches by provider-instance ownership, then rebase the remaining cap and loss-reporting work.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Preserve child completion received before Codex child registration.
Audit finding. Main records foreign live turn IDs for Stop but drops their completion before explicit child identity is known. Later registration still emits a started or activity event without replaying a prior settlement. The PR adds compact lifecycle state, which is distinct from the landed fix that ignores trailing child interactions.
Recommendation. Keep open: work remains. Review this settlement replay together with PR 7848's complementary early-start handling.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Check: GitHub check. Latest head required checks: Test success, Check success, Mobile Native Static Analysis success, Release Smoke success.
Limits. Production changes were inspected, but the full integration-test diff was not reviewed. GitHub reports a conflict with main. Any passing checks apply to the existing head, not a rebased result.
Request. Add dedicated Claude settings for a CLIProxyAPI endpoint and credential.
Audit finding. Main supports Claude environment configuration but has no CLIProxyAPI-specific fields. The diff adds a service-specific toggle and key, clears two ambient Anthropic credentials, and separates continuation groups by endpoint. A maintainer must decide whether this belongs in dedicated settings, and the credential isolation must also account for explicit Claude OAuth tokens and cloud-backend flags.
Recommendation. Keep open: decision needed. Decide whether to support CLIProxyAPI with dedicated settings or the existing provider environment controls.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Commit: Commit eb733c10f270. Custom Claude home isolation landed without a proxy-specific backend model.
Limits. Latest-head required checks are not reported: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts against the target branch.
Request. Extend local trace history with shared process polling, sampling, compression, and incremental reads.
Audit finding. Main already captures one process table per terminal poll through the subprocess-polling fix. It still keeps ten plain trace backups, writes every sampled span, and retains all decoded trace files during diagnostics. The remaining tracing and PID-liveness work is useful, but changes diagnostic counts and adds synchronous gzip cost.
Recommendation. Keep open: partial fix. Keep the missing trace-retention and PID-liveness fixes while removing the landed process-snapshot refactor.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Use native turn/steer for Codex mid-turn sends and keep turn identity consistent.
Audit finding. Merged PR 5762 preserves the active turn ID when Codex accepts a follow-up, so the simplest wrong-Stop-target case is already addressed. Main still sends every message through turn/start and returns that response's turn ID. This PR changes steering, rejection handling, concurrent sends and projected turn identity, which remain material scope beyond the landed Stop fix.
Recommendation. Keep open: partial fix. Review a current-main version of the native steering path with send, Stop and stale-turn races.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Limits. The core runtime proposal was inspected, but the full 16-file lifecycle and test diff was not reviewed. Latest-head required check results are absent for Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports a conflict with main. Any passing checks apply to the existing head, not a rebased result.
Request. Include custom Claude and Codex provider homes in usage scans without counting shared homes twice.
Audit finding. Main still resolves Claude and Codex transcript roots from legacy provider settings only. The recent Grok usage and incremental transcript-reading merges did not enumerate providerInstances. This PR handles instance environment precedence and real-path deduplication, but it must now preserve Grok scans and coordinate with the newer instance-home proposal.
Recommendation. Keep open: work remains. Combine the usage-home proposals while retaining instance environment and symlink coverage.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Report incomplete transcript scans and prefer the best available copy across environments.
Audit finding. The new incremental scanner on main still swallows listing failures, maps unreadable files to empty records, and reports successful roots as ok. Shared usageMerge still lets the first environment claim a source regardless of coverage. The PR remains needed, but it must preserve the new incremental and Grok scan paths and distinguish ordinary ENOENT rotation from unreadable data.
Recommendation. Keep open: work remains. Port the coverage statuses to the current scanner and fix the reviewed benign-rotation handling.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Reconcile Codex transcript usage with cumulative counters and report malformed records.
Audit finding. Main still deduplicates last_token_usage by JSON signature rather than comparing cumulative increments, and UsageService still reports malformedRecords:0. The fork-copy fix addresses a different source of inflation. The new append-only reader and cache v3 from PR 9024 mean this older cache-v4 rewrite must preserve incremental parser state instead of replacing that work.
Recommendation. Keep open: work remains. Rebase cumulative validation onto the incremental reader and add its state to the durable scan cache.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Check: GitHub check. Latest head required checks: Test success, Check success, Mobile Native Static Analysis success, Release Smoke success.
Limits. The parser and cache changes were inspected, but the full eight-file diff was not reviewed. GitHub reports a conflict with main. Any passing checks apply to the existing head, not a rebased result.
Request. Display unknown usage cost as unknown and mixed coverage as a lower-bound estimate.
Audit finding. Web and mobile still format costUsd directly even when costQuality records unpriced usage. The patch carries unpriced coverage into provider, model and daily totals and changes both clients, but it predates the web usage redesign and adds static-render tests that current guidance rejects. The pricing fix changes rates, not how unmatched rates appear.
Recommendation. Keep open: work remains. Port the shared cost-coverage formatting to the current usage UI and retain focused data tests.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Question-and-answer exchanges should show readable paired transcript entries instead of raw tool payloads.
Audit finding. Main still renders user-input activities as work-log rows rather than paired transcript entries. The PR adds exchange cards, but unconditionally removes raw question rows even when no structured replacement is loaded and treats resolved exchanges as blocking content for the thinking indicator. Review discussions identify both limits, and mobile remains outside this web-only change.
Recommendation. Keep open: work remains. Preserve unmatched question history and review resolved-exchange busy-state handling before rebasing on current activity logs.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Show a GitHub CI status dot on thread pull-request badges.
Audit finding. Current ThreadStatusIndicators renders PR state without CI status, and VcsStatusChangeRequest has no checks field. The PR adds a bounded summary for GitHub while leaving the other source-control providers without a signal. Its resolved neutral and stale-check findings are reflected in the inspected summarizer, but the full multi-provider patch still needs review.
Recommendation. Keep open: work remains. Review the remaining provider wiring and verify CI state on ordinary and explicitly linked PR threads.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Inspected the check summarizer, badge renderer, and contract changes, not all 19 files and 851 changed lines. The latest head has no results for the four currently required check names.
Request. Follow new and resized thread content without carrying stale scroll state between routes.
Audit finding. Merged #6519 restores live following when the reader returns to the end, but main still stores the follow flag without a route key and has no row-size callback. The patch adds those paths, yet its reveal callback drops measurements while anchor positioning is unfinished and its thread-key state still fails the rapid A-to-B-to-A case. Those two unresolved findings match the source, so this is not ready to merge or close.
Recommendation. Keep open: partial fix. Retain pending measurements until anchor completion and key follow state to each route entry, then rebase onto the merged follow fix.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Comment: Discussion comment. Verified dropped size-change notification during anchor positioning.
Limits. Canonical current-head results are missing for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports conflicts with the target branch, so recorded checks do not validate a rebased integration.
Request. Hide mobile Git workspace controls and force local mode for non-Git projects.
Audit finding. The current mobile flow still loads branches and accepts draft worktree metadata for non-Git projects. The proposed normalization helps only after its VCS query resolves because isGitRepo defaults to true, which the current open review correctly flags for Start and Queue. The later local-branch metadata fix does not cover this pending or offline submission case.
Recommendation. Keep open: work remains. Normalize queued and immediate submissions using authoritative repository state without blocking the offline queue.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Reduce release time with shared build artifacts and add guarded dry runs.
Audit finding. Main already runs quality checks beside release builds and has newer packaging and preflight optimizations. Shared desktop/resource-monitor artifacts and dry-run publish guards remain absent. The proposed prebuild matrix also makes one resource-monitor failure skip every platform, so preserve failure isolation when adapting the remaining work to the new release graph.
Recommendation. Keep open: partial fix. Rebase the missing shared-artifact and dry-run work while preserving per-platform failure isolation.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Add desktop-style actions and read markers to both mobile thread menus.
Audit finding. Current mobile rows still lack the proposed rename, Mark unread, Copy submenu, and same-branch new-task actions. The patch handles both list variants and Android menu sections, but adds the same preference key as PR #4961 with different update and completion rules. The inspected unread predicate treats interrupted completions differently from PR #4961, so the two changes should share one rule.
Recommendation. Keep open: work remains. Unify read-state handling with PR #4961 before reviewing the full menu change.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Check: GitHub check. Current head d69680d5: Test=SUCCESS, Check=SUCCESS, Mobile Native Static Analysis=SKIPPED, Release Smoke=SUCCESS. GitHub reports merge conflicts.
Limits. Menu construction, draft seeding, dialog, and read-state changes were inspected, but all 83 KB of wiring and tests were not reviewed completely. Mobile Native Static Analysis was skipped on the current head; no passing native static result is claimed.
Request. Prevent broken Windows updates and recover WSL startup when the advertised address or readiness probe is wrong.
Audit finding. Main now repeats readiness probes and stages the WSL runtime on Linux storage, covering part of the slow-start and install-tree pressure. It still chooses the first distro IPv4 and proceeds after unverified backend stops. The remaining diff combines endpoint races, retry limits, install stamps, and root process killing, and required Check still fails on formatting.
Recommendation. Keep open: partial fix. Split and rebase the remaining endpoint-recovery and verified-update changes against the current WSL runtime staging.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Limits. No packaged Windows update or root holder-scan run was performed. Required Check fails on formatting in the reviewed head; no packaged update run was performed.
Request. Reduce high-frequency Codex child progress before durable runtime ingestion.
Audit finding. The adapter still maps each child item and usage notification into an event and offers every event to runtimeEventQueue. Later projection and snapshot optimizations do not remove that durable event volume. The PR adds two latest-value lanes and terminal flushes, but must retain the session-scope event consumer fixed after its base.
Recommendation. Keep open: work remains. Rebase the coalescer while preserving session-scope lifetime and verify terminal flush ordering.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. The coalescer and adapter changes were inspected, but the full race-test and ingestion-test diff was not reviewed. Latest-head required check results are absent for Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports a conflict with main. Any passing checks apply to the existing head, not a rebased result.
Request. Persist an interrupted lifecycle for a matching canonical turn.aborted event.
Audit finding. Main still excludes turn.aborted from its durable session transition. This PR adds exact-turn guards and extensive ordering tests, but it does not finalize buffered assistant output or proposed plans as the newer abort PR does. The proposals also differ on whether the live session becomes interrupted or ready, so neither is an exact replacement for the other yet.
Recommendation. Keep open: work remains. Choose one abort lifecycle rule and retain both ordering and buffered-output coverage.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Select GitHub credentials by host and repository owner without storing tokens in T3.
Audit finding. Main still delegates every GitHub command to the active CLI account and has no githubAccountRouting setting. The inspected route selector and CLI patch add per-owner defaults, token selection, and mixed-account batching, which are separate from basic Enterprise detection. Account-aware PR snapshots must also be reviewed with the separate snapshot-verification proposal.
Recommendation. Keep open: work remains. Complete an account-routing review covering owner overrides, host defaults, PR batching, and snapshot identity.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Read the credential selector, CLI execution, auth parser, and settings contracts. The complete 26-file, 1,827-line diff was not fully read. The latest head has no results for the four currently required check names.
Request. Choose which connected environment owns source-control settings and writer configuration.
Audit finding. Main now can scan a fallback relay environment through PR 6230, but Git fetch policy and writing settings still use primary-only settings hooks. The inspected PR routes those controls and provider models through a selected environment and adds read-only permission handling. The earlier discovery fix therefore covers only part of the request.
Recommendation. Keep open: partial fix. Rebase the selected-environment controls onto the current fallback-environment discovery logic.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Limits. Read the environment selector and production routing changes, not the complete component-test changes in the 714-line diff. The latest head has no results for the four currently required check names.
Request. Open a configurable files panel or terminal when a project chat starts.
Audit finding. Main has no new-chat panel-default preferences. The patch covers ordinary creation, reused drafts, pull-request preparation and plan implementation, and now waits for settings hydration. Its in-memory scoped-key record still loses a deliberate closed layout after reload or environment remapping, matching the remaining review findings.
Recommendation. Keep open: work remains. Persist the default-layout decision with the draft and preserve it when the draft changes environment.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. Verified that the decision key changes when a reusable draft changes environment.
Limits. Canonical current-head results are missing for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports conflicts with the target branch, so recorded checks do not validate a rebased integration.
Request. Add individual commit diffs to the Diff pane scope menu.
Audit finding. Main review contracts still accept only working-tree and branch-range sources. The selected diff adds first-parent commit patches, but its git-log failure fallback becomes an empty complete list that can clear the selected commit. It also loads commit metadata during every normal preview, matching the open review concern about remote payload cost.
Recommendation. Keep open: work remains. Make commit metadata lazy and preserve selection when listing fails, then finish the UI and test review.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Read the VCS commit path, selection store, and contract changes, not the full 11-file, 748-line diff. The latest head has no results for the four currently required check names.
Request. Preserve provider context across compatible account-instance switches and reject incompatible resumes.
Audit finding. Main has a reactor-level continuation check, but ProviderService.startSession still drops persisted cursor and cwd whenever instance IDs differ. Codex also still replaces a missing-thread resume with thread/start. The PR changes both paths and directly conflicts with the fresh-session policy in the broader recovery PR.
Recommendation. Keep open: work remains. Agree on failed-resume behavior and test switching a stopped thread between compatible accounts.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Reload one thread provider process to pick up current MCP and provider settings.
Audit finding. Main has stop and resume operations but no Reload agent session action or onlyIfIdle guard. The full diff covers web, desktop menus, the command palette, and mobile controls. The action is not gated on server support for onlyIfIdle, so an older remote server can accept the existing stop command without the new race protection.
Recommendation. Keep open: work remains. Gate reload on server support for the idle-only stop before offering it to remote clients.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Resolve SSH host aliases before repository detection and suppress interrupt-only query errors.
Audit finding. RepositoryIdentityResolver still builds identity from the literal remote URL, and no SSH alias normalizer is wired into current Git remote reads. The web query helper also still converts every Failure into an error message, including interruption. Both proposed changes remain, but they should be reviewed as separate concerns. The query-interruption fix also leaves the mobile hook unchanged.
Recommendation. Keep open: work remains. Separate alias resolution from query interruption and cover user-less SSH aliases and the mobile query hook.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Insert desktop-local non-image files as absolute-path mention chips without uploading them.
Audit finding. Stable v0.0.37 already supports generic file uploads through merged PRs 8235 and 8236, including remote environments. This PR proposes a different local-only path that rejects remote non-image drops and uses the old image-only composer flow. The exact path-mention feature is not landed, but the original no-upload constraint now needs a product decision. Its primary-environment gate also accepts untranslated Windows paths when the primary server runs in WSL.
Recommendation. Keep open: decision needed. Decide whether a separate local-path feature with WSL path translation should coexist with generic attachments.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Offer thread-only deletion and thread-plus-worktree deletion in one confirmation.
Audit finding. Main still uses a boolean confirmation and a separate worktree prompt in useThreadActions. The inspected diff adds explicit primary and secondary outcomes, but intentionally leaves the legacy sidebar and bulk deletion unchanged. This remains an unlanded UI change and needs an explicit entry-point decision before claiming a single-step delete everywhere.
Recommendation. Keep open: work remains. Cover legacy single-thread deletion in the combined dialog and keep bulk-delete scope explicit.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Read the deletion helper, confirmation contract, and host changes, not the complete 490-line diff and its tests. The latest head has no results for the four currently required check names.
Request. Do not send a local project directory to an OpenCode server on another host.
Audit finding. Main still sends directory when creating every SDK client and forks resumed sessions after a local directory comparison. The PR omits directory for external non-loopback servers and skips remote forking, but misses the SDK client used by connectToOpenCodeServer for its version probe. That remaining remote request still carries the local path, and host-based classification also needs a decision for local servers reached through a LAN name.
Recommendation. Keep open: work remains. Apply the remote-directory rule to the health probe and verify remote resume plus local-external behavior.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Reduce Windows preview WMI work with one process-name map and a timeout cooldown.
Audit finding. Main still runs Get-Process once per listener and has no Windows listener cooldown, separate from the terminal process-snapshot fix. The added concurrent-scan test does not start its first fork before awaiting the gated second scan. The cooldown also substitutes common ports for the last good listener list, temporarily hiding servers on other ports.
Recommendation. Keep open: work remains. Fix the test fiber and retain known listeners during cooldown before rebasing the scanner change.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Prefer built-in Windows PowerShell 5.1 over optional PowerShell 7 for terminal startup and environment probes.
Audit finding. Main already falls back from pwsh to built-in PowerShell, so this PR changes the default edition rather than removing a hard dependency. Both capture scripts read PowerShell output as UTF-8 without setting its console encoding, which the human review identifies as a non-ASCII-path regression when 5.1 becomes first. Probe preference and interactive-shell preference also need separate decisions.
Recommendation. Keep open: decision needed. Separate probe and interactive-shell preferences and set UTF-8 output before preferring PowerShell 5.1 captures.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Keep agent-created preview tabs reachable in the thread browser panel.
Audit finding. Current ChatView reconciles browser surfaces for the active thread, but PreviewAutomationHosts still opens the mini-player and does not reconcile right-panel surfaces itself. The PR adds host-side reconciliation and changes explicit presentation to the right panel. The remaining work includes a presentation choice, not just a missing store update.
Recommendation. Keep open: partial fix. Decide whether agent-requested presentation should open the right panel, then retain only the missing reconciliation work.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Replace the POSIX worktree setup command with a portable Node script.
Audit finding. Merged PR 8814 added a separate PowerShell setup command, but main still registers the original ln-based command for automatic worktree setup. It also still relies on creating symlinks without the proposed copy fallback and preservation rules. The portable bootstrap remains useful, but it must account for both current script entries.
Recommendation. Keep open: partial fix. Replace both platform-specific setup entries with one verified portable script.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Skip Windows PowerShell environment probes when static paths provide Node.
Audit finding. Main already runs the two PowerShell probes concurrently but still waits for their environment data. This PR adds a static Node check and skips both probes unless profile text mentions fnm. That test does not cover other profile-supplied PATH entries or indirect fnm setup, so startup can lose a valid provider environment.
Recommendation. Keep open: work remains. Replace the Node-only skip condition with a scheme that preserves profile-provided PATH and environment data.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Audit finding. Main still inserts a fresh bearer session for each reusable desktop bootstrap exchange. This PR rotates same-subject, same-method sessions in one transaction, unlike the separate desktop-token persistence proposal, which reuses a saved credential. Rotation fixes accumulation even without secure storage but invalidates a prior desktop token when another exchange occurs, so maintainers need to choose the intended concurrent-client behavior.
Recommendation. Keep open: decision needed. Choose server-side rotation or desktop token reuse and verify concurrent primary and WSL credential consumers.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Add an Issues workspace with host adapters, mutations, linked pull requests, and agent handoffs.
Audit finding. Pinned main has a Pull Requests workspace but no Issues workspace. The final diff includes Linear integration, issueTracking settings, credential changes, and AI work-item selection, contradicting the body claim that Linear and new settings are excluded. A maintainer-attributed comment already requests smaller product and implementation changes, although a fresh GitHub read confirms the PR is still open. The 193-file change needs that scope decision and a full review, not closure as fixed.
Recommendation. Keep open: decision needed. Split the provider-neutral issue model and one read-only host workflow from credential, mutation, and AI-task features.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. Maintainer-attributed scope feedback asks for smaller product and implementation changes.
Limits. Only selected contracts, registry, settings, and UI changes were reviewed from the 47326-line diff. The 110 resolved review threads were not all verified against the final source. Host mutation behavior was not exercised with real credentials. Latest-head Mobile Native Static Analysis was skipped, not executed.
Request. Windows server shutdown must stop waiting when a scoped child process or its finalizer does not exit.
Audit finding. Main still installs the standard platform child-process spawner with no global Windows shutdown wrapper. The PR bounds scope-owned termination and tests a process tree, but its current diff deliberately preserves unbounded explicit kill calls despite the body claiming they are bounded. This is separate from node-pty terminal teardown and needs Windows lifecycle review.
Recommendation. Keep open: work remains. Correct the stated explicit-kill behavior and validate the wrapper against current Windows scope shutdown.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Use prebuilt native PTY packages so supported remote hosts do not need a compiler.
Audit finding. Main still depends on node-pty and keeps separate WSL build and staging paths. The final patch switches the adapter, WSL probe and desktop native staging, addressing its reported helper-path and asar issues. Current main now has a shared CLI external-package list that names only node-pty, and this patch does not update it, leaving the new wrapper and its platform packages outside the bundle and sidecar contract.
Recommendation. Keep open: work remains. Port the dependency switch through the current CLI external-package list and verify real packaged PTYs on macOS, Windows, WSL and Linux.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Canonical current-head results are missing for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports conflicts with the target branch, so recorded checks do not validate a rebased integration.
Request. Close a focused right-panel tab with Mod+W without closing the application window.
Audit finding. Main has no equivalent panel-close interception, so the request remains. The proposed hard-coded handler runs before configured shortcuts and also matches panel terminals because all panel content is inside PreviewPanelShell. The unresolved review finding is valid: it can close an entire terminal tab instead of its focused split and bypass remapped keybindings.
Recommendation. Keep open: work remains. Exclude terminal-owned focus and use a typed configurable panel-close command before merging.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Find provider CLIs installed after the Windows server starts without requiring a restart.
Audit finding. Main refresh still does not reload Windows registry PATH. This PR reads Machine and User PATH even for a profile-loaded shell, discarding profile-added toolchain paths, and it does not refresh the environment copies held by custom provider instances. A Windows reviewer requested changes on that same head, and the broader refresh PR addresses these missing lifetime rules. The original defect remains real, but this implementation needs work.
Recommendation. Keep open: work remains. Preserve profile PATH and refresh captured provider environments using the broader Windows refresh approach.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Add a pull-request file tree and make PR diffs expanded by default.
Audit finding. Main has no changed-file tree in the PR Code tab and still starts diffs folded. The inspected tree handles paged file lists, but the PR also changes that explicit performance default for every loaded file. The tree feature and the default-expansion choice need separate review, not closure as already handled.
Recommendation. Keep open: decision needed. Separate the file-tree addition from the default-expansion change and measure a large paged PR.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Read the complete new file-tree component and fold/pagination logic patch, not the full 704-line diff and view integration. The latest head has no results for the four currently required check names.
Request. Undo a prompt stash together with its image attachments and stash entry.
Audit finding. Main uses ordinary Lexical HistoryPlugin and has no undo hook for stash side effects. The patch adds history-entry matching and fresh image previews, but current stashes now include non-image files that its image-only transaction does not restore. A current patch must keep text, images, files and stash membership consistent across undo and async encoding.
Recommendation. Keep open: work remains. Extend the undo transaction to current mixed attachments and test stacked stashes plus composer-target changes.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Canonical current-head results are missing for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports conflicts with the target branch, so recorded checks do not validate a rebased integration.
Request. Choose and verify the installer that owns the active provider executable before updating it.
Audit finding. Main still infers update methods from executable paths and falls back to npm for bare commands without verified ownership. The new catalog, installer identity checks, and prefix-specific update execution remain absent, so the npm install-script fix is not a replacement. This broad updater change overlaps the lazy-maintenance work and the narrower Homebrew version-source fix.
Recommendation. Keep open: work remains. Review the full installation catalog and choose one lazy-maintenance API with the Windows refresh PR.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. The 31-file installer diff was not fully reviewed. The ownership types, catalog resolver, and update-execution checks were inspected. Top-level comments and current unresolved findings were reviewed, but the full history of 53 review threads was not read. Required checks have no results on this head: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Show Codex-generated images, including files outside the workspace, in web and mobile threads.
Audit finding. Merged PR 8936 adds viewed-image UI, but generated savedPath extraction and signed serving outside the workspace remain missing. The proposed root resolver collects generated_images directories from every Codex instance while asset issuance authorizes only the requested thread, crossing the intended instance boundary. Its path fallback can also misread prompt text or short base64 as a file path.
Recommendation. Keep open: partial fix. Scope generated-image access to the thread's provider instance and carry a verified path separately from descriptive text.
Confidence high. Release: In nightly source. PR readiness: Needs work or a decision.
Merged pr: PR #8936. feat(client): render viewed images in work logs
Comment: Discussion comment. Discussion evidence checked against the submitted source change.
Limits. Image-path and asset-root changes were inspected, but the full 20-file asset and client diff was not reviewed. Only selected current review findings were read. The complete discussion and resolved review history were not reviewed. Latest-head required check results are absent for Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports a conflict with main. Any passing checks apply to the existing head, not a rebased result.
Request. Use one sidebar header row with project scope and a toggleable thread search.
Audit finding. Main still has the two-row header and now uses a searchable project combobox. The patch preserves search clearing and IME handling, but its extracted header restores the older non-searchable radio menu and drops the newer Shift-click help text. Theo supported the layout but explicitly left the final choice to the team.
Recommendation. Keep open: decision needed. Get the team layout decision and port it without losing searchable project selection or shortcut help.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Support installable ACP Registry agents through a generic provider and orchestration-v2 runtime.
Audit finding. Main still registers only the five named providers and has no ACP Registry driver. The inspected new driver depends on orchestration-v2 and adds provider installation, authentication, and native session management beyond the existing ACP adapters. The 977-file diff also contains the wider v2 work, and the author lists missing mobile management, so neither closure nor merge safety follows from passing checks.
Recommendation. Keep open: decision needed. Choose the generic ACP scope and present its dependency stack for a dedicated full review.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author StiensWout. Updated 2026-09-01T05:36:38Z. Draft no. Target t3code/codex-turn-mapping. Head 7a346408dbaad9870ea37fcda434205e9099a62f. Branch t3code/acp-registry-search-install. Size +222236 / -95813, 977 files, 537 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Check: GitHub check. Head CI: Test success, Check success, Mobile Native Static Analysis success, Release Smoke success.
Limits. The 15.4 MB, 977-file diff was not fully reviewed. The Registry driver and its orchestration-v2 dependency were inspected. The author reports incomplete mobile install and authentication controls. Top-level comments and current unresolved findings were reviewed, but the full history of 127 review threads was not read.
Request. Verify current host accounts and snapshot age before restoring persisted pull-request rows.
Audit finding. Main readPullRequestListSnapshot still accepts a decoded snapshot using only the environment-set storage key, without a timestamp or fresh viewer identity. Current API-budget caching does not verify that the signed-in account still owns those rows. The inspected patch adds that gate, but server cache invalidation and mixed-version behavior need the remaining full review.
Recommendation. Keep open: work remains. Complete the fresh-viewer and cache-invalidation review with an account switch and a legacy connected server.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Read snapshot gating, matching, and the capability contracts. The complete 15-file, 1,144-line diff, including server invalidation and route integration, was not reviewed.
Request. Discover stable Portless, ngrok, and Tailscale Serve URLs for local dev servers.
Audit finding. Main probes listeners for HTTP readiness but has no named-route discovery or urlKind field. The reviewed patch distinguishes local proxy URLs from public tunnel URLs and carries their target ports through preview opening. This remains separate from the landed browser-ready listener filter and overlaps the active URL-routing changes.
Recommendation. Keep open: work remains. Review named-route discovery against the chosen SSH and gateway routing model.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Add GitHub pull-request stacks across review, branch, commit, push, and merge flows.
Audit finding. Main has no PR-stack adapter or contracts. The existing git.runStackedAction sequences ordinary Git actions, not dependent pull requests. A maintainer comment says this 48-file workflow will not be taken forward as one branch, but GitHub still reports the PR open, so the remaining decision is how to split or retire it.
Recommendation. Keep open: decision needed. Confirm whether the open PR should be split into smaller proposals or retired under the recorded maintainer decision.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. Recorded maintainer decision not to take this large cross-client workflow forward as one branch.
Limits. Read the stack service and contracts, not the full 48-file, 3,529-line cross-client diff. The installed Stack CLI and live Stacks API behavior were not verified.
Request. Deliver an OpenCode follow-up at the next tool boundary through the v2 steer API.
Audit finding. Main still sends fresh turns and steers through session.promptAsync. The PR switches busy turns to the v2 steer endpoint, but eagerly starts its SDK promise outside runOpenCodeSdk, so synchronous errors bypass typed recovery. That unresolved review finding is present in the diff, and compatibility with the current minimum OpenCode version plus steering attachments still needs verification.
Recommendation. Keep open: work remains. Make prompt creation lazy, verify the v2 attachment schema, and add version-compatible steering tests.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Canonical latest-commit checks do not include Check, Test, Mobile Native Static Analysis, Release Smoke. GitHub reports a merge conflict with current main.
Request. Show the actual OpenCode backend model for a completed turn instead of only its requested alias.
Audit finding. Main has no actual-model message field, and the upstream OpenCode metadata PR is still open. The diff carries the value through persistence and both clients, but migration 041 already belongs to authentication on main. Its late metadata enrichment emits a second turn.completed, while current ingestion still accepts a named completion with no active turn during a pending start, so that lifecycle race needs correction during rebase.
Recommendation. Keep open: work remains. Resolve the upstream metadata dependency, then rebase with a new migration and metadata-only late enrichment.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. The old lifecycle warning is marked resolved, but late enrichment still uses turn.completed in this diff.
Limits. Canonical latest-commit checks do not include Check, Test, Mobile Native Static Analysis, Release Smoke. GitHub reports a merge conflict with current main.
Request. A remote client should be able to update and relaunch a desktop-managed host.
Audit finding. Main still rejects desktop-managed self-update RPCs and instructs the user to update the app on that machine. The PR adds a telemetry control protocol, desktop update driver, capability, and confirmation UI, but its capability is not Mac-only when a control fd exists. The preliminary installing report is published before shutdown without an end-to-end delivery receipt, and the author has not verified a packaged remote relaunch.
Recommendation. Keep open: work remains. Prove report delivery, install failure recovery, and reconnect on a packaged host before approving the remote update protocol.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Bound OpenCode CLI health probes so a hung command cannot block discovery.
Audit finding. Main still waits without a deadline for opencode --version. The inventory half targets the old CLI path, which the merged shared-server change replaced with HTTP inventory. The version deadline remains needed, while any inventory deadline now needs to cover the shared-server and HTTP calls without breaking their cleanup.
Recommendation. Keep open: partial fix. Combine the remaining version deadline with the current probe implementation and define the HTTP inventory deadline.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Merged pr: PR #8480. Replaced production CLI inventory with shared-server HTTP inventory.
Limits. Canonical latest-commit checks do not include Check, Test, Mobile Native Static Analysis, Release Smoke. GitHub reports a merge conflict with current main.
Request. Add visible annotation cancellation, richer region targets, and readable preview notes.
Audit finding. Main still uses the older cancellation, region-selection, and cursor behavior. The reviewed patch adds bounded region harvesting, but an ordinary non-additive selection still clears the harvested controls while keeping their region box. The cursor trail also uses fixed opacity after activity ends, matching an unresolved review finding.
Recommendation. Keep open: work remains. Preserve region-owned selections on plain clicks and make inactive cursor trails recede before UI verification.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. Non-additive selection still clears region-owned harvested targets.
Comment: Discussion comment. The patch gives trail dots fixed opacity rather than the cursor activity opacity.
Limits. The animation and annotation UI were not inspected in a running client. The 87,722-byte diff was not fully read. Review covered the named feature paths and current main, not every file or test. The collected latest head has no results for these required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts with the current base.
Request. Prevent subagent telemetry queues from delaying assistant replies and unrelated threads.
Audit finding. Main still sends assistant events and background telemetry through one FIFO worker, so the new ingestion optimization does not supply this priority behavior. The latest patch still treats a phase-only progress tick as a full activity snapshot, which can remove the prior summary and tool name. Resolve that verified review finding before rebasing the worker.
Recommendation. Keep open: work remains. Preserve progress text on phase-only updates, then rebase the priority worker.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Load private GitHub pull-request images through an authenticated environment proxy.
Audit finding. Current PR Markdown still sends ordinary remote image URLs to the renderer, and the asset contracts have no GitHub user-attachment resource. The inspected proxy streams authenticated user-attachment images and sets SVG response policy, but the discussion identifies repository-backed screenshot URLs that it still does not cover. No landed image-rendering change supplies this authentication.
Recommendation. Keep open: work remains. Rebase the authenticated attachment proxy onto current Markdown routing and track repository-backed images as an explicit follow-up.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Read URL validation, the HTTP proxy, Markdown integration, and contracts, not every changed call site or test in the 428-line diff. The latest head has no results for the four currently required check names.
Request. Avoid repeated server history reads and client activity sorting during streaming.
Audit finding. Stable PR 8150 already skips the costly shell-summary refresh for ordinary activities and assistant deltas. Main-only PR 9032 cuts another streaming message read, but main still filters and sorts every client activity append and recomputes user-message summaries. Those parts remain useful, although the proposed immutable array append is O(n), not the O(1) claimed in the body.
Recommendation. Keep open: partial fix. Extract the remaining client append and user-message summary changes and measure them against current main.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Merged pr: PR #8150. Implements the high-frequency shell-summary skip and is in v0.0.37.
Merged pr: PR #9032. New message append optimization is pinned main only, not in stable v0.0.37.
Limits. No benchmark of the remaining client change against current main was run. Required checks absent from the canonical latest-commit rollup: Check, Test, Mobile Native Static Analysis, Release Smoke.
Request. Catch up cached mobile threads and recover stalled account loading after a long background.
Audit finding. Main reconnects on resume, but does not opt into refreshCachedThreadOnSubscribe and still disables the account route while Clerk is loading. The PR adds bounded catch-up, row reuse, and manual Clerk retry on the unmerged orchestration branch. Its collected diff spans 897 files and includes the orchestration rewrite, so this audit cannot approve that full change or call it obsolete.
Recommendation. Keep open: work remains. Separate or restack the mobile catch-up changes onto the intended orchestration parent.
Confidence medium. Release: In stable source. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author mwolson. Updated 2026-09-01T05:36:37Z. Draft no. Target t3code/codex-turn-mapping. Head 5755e9ea4b36951be2f49a9e4c1301d502d08bdb. Branch fix/mobile-thread-feed-performance-v2.1. Size +184683 / -85834, 897 files, 246 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Checks. Required: Test: not captured, Check: not captured, Mobile Native Static Analysis: not captured, Release Smoke: not captured. Observed: 8 passed, 2 failed, 0 pending, 3 skipped. Checks captured 2026-09-01T11:49:54.107750+00:00.
Reviews. GitHub review decision UNKNOWN. Current-head approvals 0. Current-head change requests 0. Unresolved review threads 4. Counts do not replace review of the findings.
Evidence read. body yes, discussion yes, full diff no, current source yes, history yes.
Related work: #4878, #8220. Merged PRs that cover all or part: #4878.
Check: PR #6642. Current head 5755e9ea: required checks are absent from canonical latest-commit metadata: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts.
Merged pr: PR #4878. Addresses the part identified in this finding; merge commit 69a18ce912ac was checked against repository release ancestry.
Limits. The full 12.98 MB, 897-file diff was too large to review completely. Only the mobile wakeup, account-retry, and task-specific source paths were inspected. Required CI checks are not present on the current head in canonical check metadata. Release status refers to repository tag ancestry; mobile app-store and OTA rollout was not verified.
Request. Keep multiple saved mobile addresses for one environment and connect or remove them independently.
Audit finding. Main still keys both catalog targets and runtime service scopes by environment ID, so registering a second bearer address replaces the first. The merged mobile relay-visibility fix changes which rows appear, not this connection identity model. The selected diff introduces per-address connection IDs and preserves sibling credentials on removal, while web retains its single-address policy.
Recommendation. Keep open: work remains. Review per-address ownership and sibling removal across the shared registry and mobile catalog.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Merged pr: PR #7086. Prevents a direct entry from hiding a relay row but does not store independent bearer addresses.
Check: GitHub check. Test passes on the current PR head. Passing checks do not establish merge safety.
Limits. Large 30-file diff. Reviewed connection IDs, pairing registration, and durable sibling-route cleanup, but not every changed file. GitHub reports merge conflicts with main on the collected head.
Request. Store read and unread state on the server and synchronize it across web, desktop, and mobile.
Audit finding. Main still stores visits in web UI state and has no viewedAt field or thread-view commands. The patch adds server commands, a migration, local fallback, guarded cross-client writes, and focused mobile acknowledgements. The clock-reversal finding was reviewed and accepted as out of scope, so it is not evidence of a normal device-clock bug. This remains a broad unread-state and migration change requiring maintainer review.
Recommendation. Keep open: work remains. Review the server-authoritative unread model and migration defaults with mixed-version web and mobile clients.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Keep a blocked provider command on one thread from stopping other threads.
Audit finding. Main still uses one FIFO worker for provider intent commands, so one blocked thread can block others. The proposed keyed worker fixes idle-scope retention, but it reads the key map before creating a lane without a reservation or lock, leaving the concurrent first-enqueue review finding unresolved. This is still needed, with atomic lane creation and focused concurrency coverage.
Recommendation. Keep open: work remains. Make first lane creation atomic and test simultaneous first enqueues for one thread.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Cancel unfinished nonpersistent tools when a Codex turn finishes while preserving real background monitors.
Audit finding. The submitted diff includes 886 files and a separate orchestration-v2 Codex adapter and recovery system. Current main uses the existing CodexAdapter and ProviderRuntimeIngestion paths, so this change depends on unmerged orchestration work. The landed trailing-interaction fix does not prove that orphan dynamic-tool finalization and persistent-monitor recovery are handled.
Recommendation. Keep open: work remains. Extract the intended tool-finalization change onto the supported orchestration base before review.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author mwolson. Updated 2026-09-01T05:36:36Z. Draft no. Target t3code/codex-turn-mapping. Head 515f24e4a3aedfaf252dd52caf6480d907a021fc. Branch fix/codex-orphaned-dynamic-tools. Size +182196 / -85511, 886 files, 241 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Check: GitHub check. Latest head required checks: Test success, Check success, Mobile Native Static Analysis success, Release Smoke success.
Limits. The 12.9 MB, 886-file diff was not fully reviewed. Only the claimed change area and dependency structure were inspected. GitHub reports a conflict with main. Any passing checks apply to the existing head, not a rebased result.
Request. Let custom models declare their supported option controls and carry those selections to each provider.
Audit finding. Main still assigns one fallback capability set to custom catalog entries and has no per-model capability map in settings. The branch covers the settings editor and adapter paths, but current Grok now accepts reasoningEffort and current OpenCode capability resolution filters plan options when legacy plan mode is off. Those later changes must survive the rebase, and the provider-behavior documentation needs to match them.
Recommendation. Keep open: work remains. Rebase the capability editor and update its provider mappings without bypassing current feature-flag filtering.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Render Arabic and Hebrew prose and user-written titles in their own text direction without mirroring the app.
Audit finding. The current Markdown plugins and title elements still lack the proposed direction handling. This patch uses per-block direction and fixed LTR code, while the other open proposal uses message-level direction and adds Android support. Mixed-language lists still use the first item's direction, and the latest diff pins only the table element, not its scroll container and toolbar. The list policy needs a maintainer choice and the table wrapper still needs an LTR boundary.
Recommendation. Keep open: decision needed. Agree on one text-direction policy, then pin the table wrapper to LTR before merge.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Match Claude assistant stream and snapshot text by message ID and content-block index.
Audit finding. Main still backfills each snapshot against the start of a turn-wide block list and lets subagent stop frames address parent block indexes. The smaller alternative was closed without merging, so it did not fix these cases. This message-scoped patch remains the active proposal for stalled and multi-message streams.
Recommendation. Keep open: work remains. Review the message-scoped block identity and snapshot repair cases against the current Claude adapter.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Hide Add Project source hosts that are unavailable or unauthenticated.
Audit finding. Main still lists all source hosts with disabled rows and setup guidance. This patch shares the readiness rule across web and mobile but hides every unauthenticated host, including hosts the user may want to configure. The linked discussion explicitly asks to keep Setup Required for enabled-but-unconfigured hosts, so the proposed behavior is broader than that request.
Recommendation. Keep open: decision needed. Decide whether enabled-but-unconfigured hosts should remain visible before accepting the filter.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Allow configured previous and next shortcuts in command-palette and composer suggestion pickers.
Audit finding. Main has no picker-navigation commands or pickerFocus contract, so this behavior remains missing. The latest diff sets pickerFocus only in local handlers, while global capture handlers still resolve it as false and can claim an overlapping shortcut first. That unresolved review finding follows directly from the current routing code.
Recommendation. Keep open: work remains. Share picker focus with the global capture handlers before rebasing and retesting navigation.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. The global shortcut context does not receive the local pickerFocus state in the reviewed diff.
Limits. No current-head result for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. An older related reference could not be retrieved from GitHub. It is excluded from verified dependencies and fix evidence.
Request. Cancel pending OpenCode permission and question requests when a session is torn down.
Audit finding. Main still stops the provider context without resolving pending permission and question requests. The PR adds teardown settlement, but reply handlers remain outside its semaphore and can emit a conflicting resolution during stop. It also chains stop after settlement without ensuring teardown on a settlement failure, matching two still-valid review findings.
Recommendation. Keep open: work remains. Consolidate the teardown fix with the broader cleanup PR, serializing replies and ensuring teardown after settlement failure.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. The diff skips stop when preceding settlement fails.
Comment: Discussion comment. Reply handlers still operate outside the pending-request gate.
Pr: PR #8441. Broader active cleanup proposal addresses interruption and reply serialization.
Limits. Canonical latest-commit checks do not include Check, Test, Mobile Native Static Analysis, Release Smoke. GitHub reports a merge conflict with current main.
Request. Finishing work should not wake a snoozed thread before its scheduled wake time.
Audit finding. The shared client snooze classifier still treats post-snooze completion as an early wake. The new server settlement policy in merged PR #8600 now contains the same completion-wake rule, so this branch's client-only behavior change is no longer sufficient. Pending approvals, user input, and fresh errors must keep their existing wake behavior.
Recommendation. Keep open: work remains. Update both the shared snooze classifier and server settlement policy, then test completion versus blocking wake reasons.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Show that usage cost is unavailable when the pricing table cannot load, while retaining token totals.
Audit finding. Merged usage still drops the environment pricing status, and the current Usage page formats its numeric cost directly. The usage redesign and pricing fixes therefore do not distinguish an unavailable estimate from a genuine zero. The patch covers both web and mobile, including charts and breakdowns, and must be reapplied to the redesigned page.
Recommendation. Keep open: work remains. Propagate pricing availability through the current usage merger and both client views.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Show persisted Bash stdout in expanded work-log rows on web and mobile.
Audit finding. The tool-identity merge already preserves data.input.command, but ordinary projection still drops data.result.content. Both clients still lack the proposed persisted-result output field, so the command text can survive while its stdout remains unavailable. Recent payload-memory work limits hydration rather than adding output display.
Recommendation. Keep open: partial fix. Port persisted-result display onto the current bounded activity projection and verify both clients.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Resolve SSH host aliases to the real source-control host while retaining the alias for Git authentication.
Audit finding. Main classifies and stores the original remote host without asking SSH for HostName. The diff resolves undotted aliases in repository identity, provider selection, and PR listing, but excludes dotted aliases and adds a new SSH dependency to several layers. No merged alias-resolution replacement was found.
Recommendation. Keep open: work remains. Review alias migration and filtered PR listing against existing stored repository identities.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Latest-commit metadata has no required runs for Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports conflicts with the target branch.
Request. Fish startup should not wait for missing terminal device-attribute replies.
Audit finding. Pinned main's vendored Ghostty WASM already answers DA1 with CSI ?62;22c and DA2 with CSI >1;0;0c through the existing write-PTY callback, confirmed by a direct WASM probe. This PR changes the advertised DA1 features and adds callbacks on web and Android, but that does not establish that a missing callback causes the reported fish delay. A real fish startup trace is still needed before choosing this patch.
Recommendation. Keep open: retest. Capture fish startup queries and replies on current web or Android to identify the actual unanswered request.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. The fish startup delay was not reproduced. The changed binary trampoline was not rebuilt or independently validated. Failing required CI logs were not investigated: Check.
Request. Allow a fresh draft when an unsettled thread belongs to an offline environment.
Audit finding. The new-thread handler still awaits t3.json defaults without checking connection state, and both project-open paths still navigate to any latest thread. Main has no reachable-sibling retargeting. The offline-status proposal changes row status, not this navigation and draft-creation path.
Recommendation. Keep open: work remains. Review offline new-thread behavior and the explicit choice to retarget to a connected sibling environment.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Resume Claude from the retained conversation point after a rollback.
Audit finding. Main rollback only trims the in-memory turn list and writes the unchanged assistant cursor. The diff adds pinned resume and query replacement, but chooses the retained UUID only from context.turns, which starts empty after a restored session. A rollback after reconnect can therefore start a fresh session instead of preserving older retained context.
Recommendation. Keep open: work remains. Resolve retained assistant checkpoints from durable transcript history and test rollback after server restart.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Escape should reach terminal applications instead of being consumed by chat shortcuts.
Audit finding. The selected-thread Escape handler on main still prevents default without checking terminal focus. The PR fixes that path, but it also makes bare Escape bypass a user-configured terminal.close binding unconditionally. The reported default nvim failure needs an integrated event trace because normal terminal beforeKey already passes keys that match no application shortcut.
Recommendation. Keep open: work remains. Keep the terminal-focus guard for thread selection and preserve explicit Escape keybindings while tracing the reported nvim failure.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Add Pi as an Early Access provider with native RPC sessions, tools, skills, permissions, and rollback.
Audit finding. Pinned main has no Pi driver or V2 runtime, and this branch depends on the open new-orchestrator PR. Its full diff still includes cross-provider option memory and OpenCode changes despite the body saying option memory was split out. The latest code also retains unbounded RPC buffers, whitespace-destroying skill expansion, and approval/input cleanup defects. The reported one-shot prompt correlation failure is a false positive against Pi 0.84.2 source, but the other confirmed defects and open dependency prevent approval.
Recommendation. Keep open: work remains. Separate the unrelated option-memory work and fix the confirmed buffering, input, and session-lifecycle defects after settling the V2 dependency.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author StiensWout. Updated 2026-09-01T07:49:48Z. Draft no. Target t3code/codex-turn-mapping. Head 727d4f6a0c986f8d4cdb99e56fa9dbde0a5a91e9. Branch t3code/pi-provider. Size +8838 / -102, 60 files, 76 commits. Mergeability MERGEABLE. Merge state CLEAN. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Request. Render Codex visualization references as sandboxed inline HTML on web and desktop.
Audit finding. Main has no visualization asset resource or inline HTML visualization renderer. The PR adds temporary-file authorization, content-bound signed URLs and a nested sandboxed iframe, which are separate from the landed citation and artifact-template rendering. Native mobile support is absent, and the file-lifetime and iframe rules need complete review.
Recommendation. Keep open: work remains. Review the asset authorization and iframe implementation and decide the native mobile behavior.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Marker parsing and asset-contract changes were inspected, but the full 22-file security and client diff was not reviewed. Only selected current review findings were read. The complete discussion and resolved review history were not reviewed. Latest-head required check results are absent for Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports a conflict with main. Any passing checks apply to the existing head, not a rebased result.
Request. Include OpenCode SQLite session history in the Usage page.
Audit finding. Main still supports only Claude, Codex, and Grok usage sources. This PR supplies a worker-based database reader and both client presentations, but combines OpenCode support with broader source-health and merge changes. Its cache-version and readSummary edits predate the merged incremental transcript scanner, and its assumption that OpenCode reasoning is already included in output differs from the other complete collector.
Recommendation. Keep open: work remains. Choose the historical collector, verify OpenCode token semantics, and port it without undoing incremental transcript scans.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Refresh the active checkout immediately after merging a pull request in its thread panel.
Audit finding. Main now settles threads in a server reactor that sweeps once per minute. The proposed web VCS refresh does not notify that reactor, so it no longer delivers immediate settlement under the current architecture. The merge-action RPC also lacks a settlement trigger, leaving the delay unfixed.
Recommendation. Keep open: work remains. Trigger server settlement after a successful PR merge instead of relying on a web VCS refresh.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Show failed preview loads as unavailable and give the floating preview Retry and Close actions.
Audit finding. Main still reports a live failed-load guest as available and has no failed-load mini-player overlay. The complete PR adds recovery UI, but its readiness check uses a pre-await attachment snapshot and its status helper can replace a new loading state with an old LoadFailed value. Both unresolved race findings match the patch, so the feature is still needed but the PR needs correction.
Recommendation. Keep open: work remains. Fix stale attachment and load-status races before testing failed-load recovery.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Subtract inherited parent usage from live Codex child task totals.
Audit finding. CodexAdapter still forwards each child's raw cumulative total into task.progress. The merged fork-copy parser fix affects transcript analytics, not these live Agents-panel snapshots. This PR calibrates a per-child baseline from total minus last, but a first observation after missed child work needs an explicit accounting decision.
Recommendation. Keep open: work remains. Validate the first-observed-frame assumption before merging the child baseline calculation.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Persist run-next follow-ups on the server and let either client cancel them before provider handoff.
Audit finding. Main still emits immediate turn-start intent and has no durable after-current delivery state. This patch adds a provider-neutral queue, but its migration number 41 is already occupied on main and its mobile delivery preference has no older-server capability gate. Native Codex queuing and mobile immediate steering do not replace this durable cross-provider feature.
Recommendation. Keep open: work remains. Rebase the queue migration and add version-gated delivery before reviewing handoff recovery.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Respect Claude policy when full access or Auto is disabled.
Audit finding. Main maps full access directly to bypassPermissions without resolving the Claude policy. The diff adds fallback modes but leaves the client label unchanged and temporarily changes process.env.CLAUDE_CONFIG_DIR while an async resolver runs. Its lock covers these resolver calls, not other provider code that reads process.env, and resolver failure still chooses Auto without knowing whether Auto is allowed.
Recommendation. Keep open: decision needed. Choose an instance-isolated policy lookup and an explicit client-visible fallback rule.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Pr: PR #7246. The proposed resolver changes a process-global config variable during asynchronous work.
Limits. Latest-head required checks are not reported: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts against the target branch.
Request. Refresh context usage after compaction when the SDK omits usable post-token metadata.
Audit finding. Main only emits compacted usage when compact_boundary includes valid post_tokens, so the missing-metadata case remains. The branch now also changes model transitions, resume refresh, send serialization, and stop cleanup, which is substantially wider than the original meter fix. It relies on getContextUsage after main deliberately removed the post-turn query, so the performance and lifecycle costs need separate review.
Recommendation. Keep open: work remains. Extract the compact-boundary fix and validate a bounded fallback against the current no-post-turn-query design.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. The full 135 KB lifecycle and test diff was not reviewed. Latest-head required checks are not reported: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts against the target branch.
Request. Add separate persistent and incognito browser profiles to desktop preview tabs.
Audit finding. Main derives only the existing persistent preview partition and has no profile choice. The reviewed partition code preserves that default while adding separate profile namespaces, scoped clearing, and an in-memory incognito partition. Browser-access controls are already merged, but profile creation, removal, and storage lifetime still belong to this open feature.
Recommendation. Keep open: decision needed. Review the profile partition and deletion model before advancing the dependent import stack.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Pr: PR #7255. Cookie import depends on this profile model.
Limits. The 112,011-byte diff was not fully read. Review covered the named feature paths and current main, not every file or test. Current review findings and general discussion were sampled, but historical resolved review threads were not read in full. GitHub reports merge conflicts with the current base.
Request. Import Helium cookies on macOS into a chosen desktop browser profile.
Audit finding. Main has no cookie-import service or browser profiles. The reviewed import service validates listed source profiles and writes cookies into the selected partition, but the full keychain and decryption implementation was not reviewed. The PR is stacked on the still-open shared-SQLite branch, which in turn depends on browser profiles.
Recommendation. Keep open: work remains. Finish review of the profile and shared-SQLite dependencies before a full cookie-import security and native-build pass.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-08-29T08:22:17Z. Draft no. Target shared-sqlite-client. Head 683ca1ba1f8bcae16b99ac4d714088dce7e14668. Branch browser-profile-import. Size +3677 / -169, 26 files, 58 commits. Mergeability MERGEABLE. Merge state CLEAN. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #7254. The profile dependency remains open.
Limits. No Keychain access, cookie import, or packaged macOS build was performed. The 171,563-byte diff was not fully read. Review covered the named feature paths and current main, not every file or test. Current review findings and general discussion were sampled, but historical resolved review threads were not read in full.
Request. Extend desktop cookie import to Chromium browsers on macOS and default-container Firefox cookies across platforms.
Audit finding. Pinned main has no browser-profile import subsystem, so the open parent stack is still required. The full diff preserves host-only cookie scope and uses consistent read-only SQLite snapshots, but this layer still treats persistent Firefox lock-file existence as a running browser and only probes the legacy Chromium Cookies path. The later detection fix was merged into browser-import-safari, not main, and cannot be counted as released coverage.
Recommendation. Keep open: work remains. Integrate the browser-import stack in order, including real Firefox lock checks and modern cookie-path detection.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-08-29T08:23:53Z. Draft no. Target browser-profile-import. Head 5444eb4935edc09cabadc85de8c38cd4da1a4112. Branch browser-import-more-sources. Size +1275 / -342, 11 files, 17 commits. Mergeability MERGEABLE. Merge state CLEAN. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #7255. Cookie-import parent remains open on shared-sqlite-client.
Merged pr: PR #7323. Merged into browser-import-safari and is not an ancestor of pinned main.
Limits. No actual macOS, Windows, or Linux browser import was run. Windows Chromium and Linux Chromium key retrieval are not supported by this layer. Latest-head Mobile Native Static Analysis was skipped, not executed.
Request. Add Linux Chromium cookie import through basic-storage and Secret Service keys.
Audit finding. The import implementation is not on main and this PR targets the still-open browser-import-more-sources branch from PR #7260. Its diff keeps Windows unsupported, preserves macOS consent, and distinguishes missing Linux keys from denied access while reporting skipped records. The Linux Secret Service path has only mocked evidence, so the stack and a real consenting Linux import must be validated first.
Recommendation. Keep open: work remains. Finish the parent browser-import stack, then verify Linux v10 and v11 import with denial and missing-key cases.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-08-29T08:24:13Z. Draft no. Target browser-import-more-sources. Head bace0bef8fe04b36073c963878c532179a5f4751. Branch browser-import-linux-windows. Size +616 / -170, 7 files, 11 commits. Mergeability MERGEABLE. Merge state CLEAN. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Request. Add Safari cookie import with an explicit macOS Full Disk Access step.
Audit finding. Main has no browser-import service or Safari parser, and its shell API does not expose the fixed System Settings action this layer needs. The selected parser and wizard changes add Safari handling on top of the separate browser-import platform branch and retain that branch's detection changes. This feature is not superseded by preview cookie isolation or editor URL work.
Recommendation. Keep open: decision needed. Review the browser-import stack in dependency order, including a real Safari permission-denial and retry flow.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-08-29T08:24:03Z. Draft no. Target browser-import-linux-windows. Head a2d58d04bcb0a72d94e1a3c3a69938976236e4e2. Branch browser-import-safari. Size +1164 / -70, 22 files, 20 commits. Mergeability MERGEABLE. Merge state CLEAN. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Check: GitHub check. Test passes on the current PR head. Passing checks do not establish merge safety.
Limits. Large 22-file diff. Reviewed Safari binary parser, permission handling, and wizard state changes, but not every changed file. No new Safari or Windows GUI verification was reported for this branch. Current unresolved review threads were checked, but the long prior discussion and resolved review history were not fully read. Current-head check skipped: Mobile Native Static Analysis.
Request. Bound each usage transcript record and continue reading after an oversized tool result.
Audit finding. The merged incremental reader removes readline, but main still accumulates pendingChunks without a byte limit and decodes the complete record. Its catch can now return null for the whole file, so it does not provide the proposed bounded skip and continued usage extraction. The old reader patch must be ported to the new resume-offset and tail-record API.
Recommendation. Keep open: partial fix. Add bounded record skipping to the current incremental reader while preserving resume offsets.
Confidence high. Release: Main only. PR readiness: Needs work or a decision.
Request. Store an environment name on its server and propagate it to web, desktop, mobile, and T3 Connect.
Audit finding. Main derives the environment label from the host and has no server environmentLabel setting or label-update event. This proposal makes the server authoritative and adds relay synchronization, unlike a client-local override. The related server-owned naming proposal was closed without merge, so it is not a landed fix or an active replacement. Environment renaming is not supplied by this merge. The PR adds environmentLabelUpdated to the old projection function.
Recommendation. Keep open: decision needed. Review server-owned names and relay synchronization on the current config stream. Port the new event case to serverConfigProjection.ts and verify live, replayed, and reconnect labels.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Latest main change. Environment renaming is not supplied by this merge. The PR adds environmentLabelUpdated to the old projection function. Port the new event case to serverConfigProjection.ts and verify live, replayed, and reconnect labels.
Limits. Large 41-file diff. Reviewed server labels, relay synchronization, contracts, and client projection, but not every changed file. The later config-stream merge requires moving label projection into the shared serverConfigProjection module. GitHub reports merge conflicts with main on the collected head.
Request. Return smaller snapshots by default and make readiness waits search visible main-content targets.
Audit finding. Main still requests the full accessibility tree and all diagnostics for every snapshot, and waitFor searches the whole document without a visibility check. The full diff changes snapshot defaults, wait scope, element harvesting, and capture fallback together. These are separate behavior changes that overlap the metadata-budget and capture-recovery work.
Recommendation. Keep open: decision needed. Separate the snapshot-default decision from wait semantics and reconcile the capture fallback with the background-automation branch.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Restart Codex and retry one safe failed turn after an account usage limit.
Audit finding. Main has no automatic usage-limit restart or retry. In the submitted code, recovery starts a session before checking whether its token is still current, so stale recovery can replace a newer manual session. The unsafe post-resume retry abort also returns without closing its replacement process. These verified review findings must be fixed before the automatic-recovery policy is approved.
Recommendation. Keep open: decision needed. Make recovery replacement conditional on the current token and close every aborted recovery process.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. Discussion evidence checked against the submitted source change.
Limits. Recovery production changes were inspected, but the full cancellation and ordering test diff was not reviewed. Latest-head required check results are absent for Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Prompt the active client for SSH credentials during Git clone, publish, pull, and push operations.
Audit finding. Main disables SSH askpass on refresh commands and does not expose the proposed source-control password-prompt capability. The reviewed backend retry and prompt services keep answers in one attempt and scope pending requests to the connection, with unary fallbacks for older servers. This differs from desktop SSH environment login, and the full cross-client credential flow still needs complete review.
Recommendation. Keep open: work remains. Review prompt isolation, cancellation, and secret handling across the streaming Git operations.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Large 47-file diff. Reviewed Git SSH retries, prompt service, and streamed client prompt handling, but not every changed file. Current-head required checks were not reported: Check, Mobile Native Static Analysis, Release Smoke, Test. GitHub reports merge conflicts with main on the collected head.
Request. Show cached local source-control status before remote status in the experimental SwiftUI client.
Audit finding. This targets the unmerged SwiftUI parent, not main. Pinned main has no apps/swift-ios directory, and the target commit is not its ancestor. The diff adds a bounded status stream and late recovery, but current-head visual proof is explicitly pending.
Recommendation. Keep open: decision needed. Complete current-head slow-remote proof and review this with the SwiftUI parent PR 5178.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author saphid. Updated 2026-08-29T13:21:47Z. Draft no. Target t3code/rebuild-mobile-app-swift. Head ede5862ee5c811ebc802338c2d82d0c7fa63aa3d. Branch contrib/issue107-cached-vcs-upstream. Size +629 / -47, 6 files, 10 commits. Mergeability MERGEABLE. Merge state CLEAN. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Request. Add a searchable pull-down command drawer to the experimental SwiftUI client.
Audit finding. The current experimental parent has no drawer entry in Home or thread detail. The inspected changes add those entries, a shared action catalog, gesture geometry, and close or cancellation state while preserving ordinary list scrolling. This is a large new interaction on an unmerged client, so the parent direction and responder-restoration behavior need explicit review.
Recommendation. Keep open: decision needed. Review the drawer as an experimental-parent feature, including cancelled-pull focus restoration.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author saphid. Updated 2026-08-30T09:56:36Z. Draft no. Target t3code/rebuild-mobile-app-swift. Head c1eef5a073bf25dfb277882444f187c1f64647b9. Branch feat/issue86-command-palette-drawer. Size +2911 / -1, 8 files, 12 commits. Mergeability MERGEABLE. Merge state CLEAN. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Check: GitHub check. Current head c1eef5a0: Test=SUCCESS, Check=SUCCESS, Mobile Native Static Analysis=SKIPPED, Release Smoke=SUCCESS. SwiftUI contract fixtures and native tests passed.
Limits. Core drawer geometry and workspace/thread integration were read, but the full 118 KB gesture, catalog, view, and test diff was not reviewed completely. Mobile Native Static Analysis was skipped on the current head; no passing native static result is claimed.
Request. Send optional system notifications and a configurable chime when turns finish while the web or desktop client is open.
Audit finding. Main has no web completion watcher, browser-notification permission control, or chime settings. The latest patch adds them but leaves the new settings out of Restore defaults and leaves the permission switch usable when permission is denied or unavailable. Both review findings remain in the diff, so this needs changes before approval.
Recommendation. Keep open: work remains. Add the notification preferences to Restore defaults and disable the permission switch when it cannot change browser permission.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Add a persistent desktop HTML design editor with artboards, annotations, undo, and agent handoff.
Audit finding. Main can open workspace HTML in Preview but has no design command, editor preload, or design-specific save path. The inspected changes add all of those and save complete edited HTML through the workspace file API, while web and mobile remain view-only. Maintainer feedback rejects the size of the product commitment, and the PR was later reopened, so the scope decision remains unresolved. The large editor and all integration paths were not fully reviewed.
Recommendation. Keep open: decision needed. Confirm a smaller accepted design-editor scope before further implementation review.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. Maintainer-attributed comment requests a smaller product commitment; timeline later shows reopening.
Limits. Only selected command, asset, editor-state, routing, and persistence changes were reviewed from the 4185-line diff. The 29 review threads and generated review discussions were not fully reviewed. No Electron editor pass or concurrent agent-write/save test was run.
Request. Linux terminal clipboard shortcuts should preserve plain Ctrl+C for interruption and expose conventional copy shortcuts.
Audit finding. Main still copies a selection for plain Ctrl+C on Linux and lacks Ctrl+Insert copy. The PR adds the intended Linux chords, but native menu items pass accelerators without disabling registration, and the unresolved review warns that stale menu items can consume later terminal keys. The author reports Linux testing, yet menu-close behavior and integration with the newer clipboard fix still need work.
Recommendation. Keep open: work remains. Ensure native context-menu accelerators cannot consume terminal keys after the menu closes.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Refresh Windows provider command discovery, with an unrelated Hornet provider added to the same branch.
Audit finding. Main still lacks persistent User and Machine PATH reads, so the Windows defect is not fixed by quote cleanup or PATH ordering alone. The actual diff also registers Hornet enabled by default and adds an HTTP adapter whose interrupt only emits a local abort without canceling the remote request. This is not a narrow substitute for the other Windows PATH fixes.
Recommendation. Keep open: decision needed. Split the Hornet provider out of the Windows PATH change.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Keep failed SwiftUI source-control output visible and retry only the operation that failed.
Audit finding. This targets the unmerged SwiftUI parent and cannot fix the released React Native client. Its diff separates mutation success from refresh failure, retains errors across retry, and tests cancellation and duplicate-action prevention. It overlaps the same view and action boundary as PR 7330, with current-head visual evidence still pending.
Recommendation. Keep open: decision needed. Reconcile the source-control action boundary with PR 7330 before parent-branch review.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author saphid. Updated 2026-08-26T23:57:13Z. Draft no. Target t3code/rebuild-mobile-app-swift. Head 87ce6873a729a3c8e2d330f0cd056f3225c665e5. Branch feat/issue87-tool-error-recovery. Size +641 / -61, 6 files, 5 commits. Mergeability MERGEABLE. Merge state CLEAN. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Request. Support Android picker assets without base64 and convert HEIF before upload.
Audit finding. Merged attachment work now exposes the collapsed picker and handles iOS picker JPEG conversion. Main still rejects an Android image with absent base64 before reading its URI, and still has no Android HEIF conversion. The added Expo56 dependency and old composer button need to be removed or updated for SDK57 and the current attachment menu.
Recommendation. Keep open: partial fix. Keep the missing-base64 and Android HEIF changes in a refreshed SDK57 patch.
Confidence high. Release: In nightly source. PR readiness: Needs work or a decision.
Check: PR #7375. Current head ca961fc7: required checks are absent from canonical latest-commit metadata: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts.
Merged pr: PR #8843. Addresses the part identified in this finding; merge commit e3dcc1615c91 was checked against repository release ancestry.
Limits. Required CI checks are not present on the current head in canonical check metadata. Release status refers to repository tag ancestry; mobile app-store and OTA rollout was not verified.
Request. Select parts of Android messages, including tight list items.
Audit finding. Main still routes Android through the nonselectable Markdown fallback. This PR adds paragraph, heading, list, and task-item renderers but leaves table cells and some image or math paragraphs on the old path. PR #8779 instead enables the shared selectable renderer and adds native copy sanitization, so maintainers need one Android selection implementation. The current diff also omits Android body font-padding and final-paragraph spacing behavior identified in review.
Recommendation. Keep open: decision needed. Choose the shared-renderer approach or this fallback-renderer approach before merging either PR.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Show native OpenCode Task subagents in the Agents panel.
Audit finding. Main still maps Task tools to generic item events and does not emit their task lifecycle. Child approval routing and recursive stopping do not populate Agents rows. The PR adds foreground, resumed, failed, and background task events, but its startup and subscription rewrite predates the current shared event-stream and prompt-admission changes.
Recommendation. Keep open: work remains. Port the Task lifecycle mapping onto the current event stream and verify resumed and background tasks on both clients.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Fork a Codex conversation when another process already owns its writer.
Audit finding. Main only falls back to a fresh thread for known missing-thread errors and has no active-writer recovery. This PR would silently change the provider thread identity by forking persisted history. PR 8580 instead prevents overlapping writers during compatible instance switches, so the recovery policy should be settled before these paths are combined.
Recommendation. Keep open: decision needed. Decide whether active-writer conflicts should fork automatically or require an explicit user action.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Restore the submitted composer content after an accepted turn fails asynchronously.
Audit finding. Main restores the composer only when the send command itself fails, so accepted-then-failed turns remain uncovered. The latest patch releases draft uploads before arming a recovery snapshot that retains their old IDs, leaving restored hydrated files without local bytes for retry. Its session-status test can also attribute an error received during pre-send work to a later accepted turn. These unresolved findings prevent approval of the asynchronous recovery path.
Recommendation. Keep open: work remains. Preserve recoverable attachment uploads and tie recovery to the accepted turn before merge.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Restore per-machine draft settings when switching among grouped project environments.
Audit finding. Main already has repository grouping and a Run on environment selector. It does not keep the proposed per-physical-project draft profiles or restore branch, worktree and model settings after A-to-B-to-A switching. This PR also adds a grouping prompt and committed implementation plans, so it should be reduced to the remaining product behavior.
Recommendation. Keep open: partial fix. Narrow the PR to per-machine draft restoration and remove repository plan artifacts.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Merged pr: PR #4312. [codex] Group projects in new-thread pickers
Limits. Profile types and grouping logic were inspected, but the full 21-file draft-state diff was not reviewed. Only selected current review findings were read. The complete discussion and resolved review history were not reviewed. Latest-head required check results are absent for Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports a conflict with main. Any passing checks apply to the existing head, not a rebased result.
Request. Show provider file-edit patches inside expanded chat work rows.
Audit finding. Main has no per-edit inline diff view. The full patch still imports missing TTS and message-fork modules, and its hash is captured when the ingestion worker runs rather than when the edit completes. Review comments also identify nested Codex hashes being dropped by projection, which the current diff still does. These are real remaining defects, not only unapproved scope.
Recommendation. Keep open: decision needed. Remove the unrelated fork wiring and fix per-edit hash capture and projection before review.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Latest-commit metadata has no required runs for Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports conflicts with the target branch.
Request. Find and highlight text in the open virtualized thread through a dedicated find bar.
Audit finding. Main still has no in-thread find handler, and cross-thread search is a different entry point. The patch indexes only loaded timeline entries and parses every message whenever that list changes, even while find is closed. It needs a lazy index and an explicit earlier-turn policy before its claim to search every response is met.
Recommendation. Keep open: work remains. Make the find index lazy and handle earlier unloaded turns before merge.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Show Git change letters on Files tree rows and their parent folders across web and mobile.
Audit finding. Main has no working-tree status field or Files tree decoration mapping. The draft adds that path end to end, but it also includes a separate Azure PR-routing change now proposed alone in PR 8203. Its display-text numstat parser retains the directory-rename defect addressed by PR 8310.
Recommendation. Keep open: decision needed. Separate the Azure routing change and build the status marks on the corrected NUL-separated Git parser.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Latest-commit metadata has no required runs for Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports conflicts with the target branch.
Request. Repair provider sessions after restart and clear stale approval or input cards when users submit them.
Audit finding. Merged PR 7719, included in v0.0.37, already repairs orphaned sessions before commands are accepted, preserves resume cursors, and protects live sessions. Main still returns the generic no-active-session detail for stopped approval and input responses, so this PR retains a meaningful callback-cleanup delta. Its old startup implementation should not replace main because it lacks live-session protection and can fail the entire startup.
Recommendation. Keep open: partial fix. Reduce this PR to stale approval and input response handling, adapted to main error-state reconciliation.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Align chat prose to its own reading direction while preserving left-to-right code on web and Android.
Audit finding. Main still has neither web message auto-direction nor Android direction-specific Markdown rendering. This patch uses message-level direction and Android AST parsing, while the other open proposal uses per-block direction and covers titles. The latest discussion also questions first-letter direction for Hebrew prose that starts with a Latin technical token. These are distinct direction-policy choices, and native iOS remains outside this patch.
Recommendation. Keep open: decision needed. Choose the shared direction policy with the other RTL proposal and verify the Android renderer.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Pr: PR #7126. The alternative covers per-block web direction and title fields.
Comment: Discussion comment. A contributor supplies mixed-language examples that distinguish first-letter and dominant-language direction policies.
Limits. The patch author did not run the Android path on a device or emulator. No current-head result for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Stop OpenCode threads from remaining running after extra subagent busy and idle events.
Audit finding. Main now ignores busy events when no active turn exists, which removes the stated late-busy path to a stuck running session. It still has no dedicated session.idle handler. The PR retains and reopens an already-completed turn across later busy cycles, so its old state-machine change should not be merged unchanged over the current admission and cancellation guards.
Recommendation. Keep open: partial fix. Reproduce an idle-only completion on current main and keep only the missing event handling if it is still needed.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Merged pr: PR #8480. Added current prompt, idle, and cancellation guards.
Limits. Canonical latest-commit checks do not include Check, Test, Mobile Native Static Analysis, Release Smoke. GitHub reports a merge conflict with current main.
Request. Replace desktop Clerk UI with system-browser sign-in using the shared T3 Connect credential.
Audit finding. Main still uses the Clerk Electron bridge and a separate CLI token manager. The reviewed migration adds local auth endpoints, but its auth-state path falls back to a stored token when refresh fails while token issuance still fails the refresh. That unresolved state mismatch and the relay-first deployment requirement remain in addition to the product decision.
Recommendation. Keep open: decision needed. Resolve refreshed-token and legacy-account state handling before approving the desktop auth migration.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. The reviewed clientAuthState explicitly falls back to read() when credential refresh fails.
Limits. No auth flow or live relay deployment was exercised. The 231,971-byte diff was not fully read. Review covered the named feature paths and current main, not every file or test. Current review findings and general discussion were sampled, but historical resolved review threads were not read in full. The collected latest head has no results for these required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts with the current base.
Request. Cache successful Windows PowerShell environment probes between desktop launches.
Audit finding. Main still performs both shell probes on every Windows launch despite the earlier concurrency improvement. This PR reuses complete results for up to 24 hours when inherited PATH matches and avoids caching incomplete probes. The remaining review needs to cover profile edits and FNM paths that can change without changing inherited PATH.
Recommendation. Keep open: work remains. Verify cache invalidation for profile changes and expired FNM paths before accepting the 24-hour cache.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Keep the Windows desktop backend running in a system tray after the last window closes.
Audit finding. Main still quits on window-all-closed outside macOS and has no tray-backed close-to-background mode. The PR adds Open and Quit actions, enables hiding only after tray setup succeeds, and expands failed-update recovery and window-creation synchronization. This changes the default meaning of Close on Windows, so it needs a product decision and lifecycle verification, not closure as fixed.
Recommendation. Keep open: decision needed. Decide the default Windows close behavior, then verify tray reopen, explicit quit, and failed update recovery.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Retain dialog data and form state until the close transition completes.
Audit finding. The command-palette close fix has merged, but add-provider still unmounts immediately and commit-dialog fields still reset as closing starts. The broader dialog changes therefore remain useful. Rebase must retain newer image-viewer video support and stacking fixes rather than replacing that component with the older image-only version.
Recommendation. Keep open: partial fix. Keep the remaining dialog-lifecycle changes and rebase them around current video preview behavior.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Opted-in background-service environments should update to a newer client version after all work is idle.
Audit finding. Main has manual launcher-backed updates but no automatic-update coordinator or idle gate. In this PR, a server deferral resets update state to idle while attemptedTargetRef can remain latched, so a still-ready client never retries. Its idle predicate also misses queued user messages before provider turn adoption, and the coordinator is not mounted on mobile.
Recommendation. Keep open: work remains. Clear the attempt latch on deferral and cover queued turn starts before an automatic handoff.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Persist a set of repositories excluded from the pull-request list.
Audit finding. Main still offers a single Project radio selection, including after the new list-filter UI in PR 8809. The proposal removes hidden repository identities before per-environment requests and preserves an Only action. It remains a product addition, and its filter controls now need adaptation to the submenu-based main implementation.
Recommendation. Keep open: decision needed. Decide whether repository exclusion should ship and adapt it to the current filter submenus.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Latest-commit metadata has no required runs for Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports conflicts with the target branch.
Request. Limit Claude child-agent depth and concurrency and reconcile background-task cleanup.
Audit finding. Main now closes the Claude query on Stop and settles tracked tasks through the merged stop fix. It still has no default five-agent or one-level limit and ignores background_tasks_changed snapshots. This branch combines those product limits with an SDK upgrade and older stop logic, so the remaining work must be reconciled with the newer lifecycle code.
Recommendation. Keep open: partial fix. Separate the default-agent-limit decision from background-task reconciliation on current main.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.