pingdotgg/t3code. All authors. Drafts included. Default branch main. 570 issue assessments and 925 PR assessments. Initial inventory: 570 open issues and 924 open PRs. Current assessed open inventory: 570 issues and 924 PRs. Final reconciliation: 2026-09-01T11:57:41.491617+00:00.
Request. Cancel the active Grok prompt before applying a mid-turn follow-up.
Audit finding. Main reuses the turn ID for a follow-up but still waits behind the serialized ACP prompt. The merged Grok reliability change does not add cancel-before-prompt ordering. The diff adds that behavior but uses eight scheduler yields in production to guess that prompt registration has completed, so the race is not deterministically closed.
Recommendation. Keep open: work remains. Replace the scheduler-yield loop with an ACP prompt-registration signal.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Return a useful format error for malformed GitHub repository lookup input.
Audit finding. Main forwards the input to the provider and can return a generic failure for a bare name. The proposed owner/repo regex also rejects full GitHub URLs that gh repo view currently accepts, so it narrows existing valid input as well as fixing the message. The one new test covers only a bare name.
Recommendation. Keep open: work remains. Preserve supported GitHub URL input while adding a clear owner/repo validation error.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Stage only changed checkpoint paths to reduce capture work in large repositories.
Audit finding. Main still stages the full scoped tree for each checkpoint. The proposed changed-path optimization fails on a staged new file that is then deleted, because its HEAD-seeded temporary index has no matching path. An isolated Git fixture returned exit 128 for the proposed pathspec command and exit 0 for the existing full add, despite the review thread being marked resolved.
Recommendation. Keep open: work remains. Handle staged-new then deleted paths and add the AD checkpoint case to the focused tests.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Comment: Discussion comment. Reproduced the stated AD pathspec failure with the exact Git command sequence. Current raw-byte parser still includes every such path.
Request. Wait for Cloudflare tunnel registration before reporting a managed connector as running.
Audit finding. Main still reports a running connector from process liveness rather than tunnel registration. The patch adds registration readiness and fixes the reviewed boot and automatic-restart ownership races. Explicit applyConfig still holds the reconciliation permit during its 15-second wait, so concurrent unlink or shutdown can remain queued behind readiness.
Recommendation. Keep open: work remains. Separate explicit configuration ownership changes from the registration wait and verify concurrent unlink.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Limits. No real Cloudflare tunnel or blocked-port network was used. Required CI checks are absent at the reviewed head: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Use Oniguruma for web and desktop file and diff highlighting to avoid JavaScript regex hangs.
Audit finding. Main still explicitly selects shiki-js in the shared highlighter and leaves worker/component engine defaults unchanged. The PR sets the WASM engine at every listed file and diff entry point, which is broader than the older worker-only proposal. The provided A/B reproduction addresses a specific tokenizer hang, not a generic memory symptom.
Recommendation. Keep open: work remains. Rebase onto current main and complete the focused client verification before maintainer review.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Submit Android composer text with Ctrl or Meta plus Enter.
Audit finding. The current Android module still exports no onComposerSubmit event and its EditText has no submit key handler. The patch wires the same event used by iOS through Kotlin and the native React bridge. It still needs a real key-event check for plain Enter and held-key repeats, and does not fix mobile web.
Recommendation. Keep open: work remains. Verify Ctrl, Meta, plain Enter, and key-repeat behavior on Android.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Check: PR #8362. Current head 094a8d25: required checks are absent from canonical latest-commit metadata: Test, Check, Mobile Native Static Analysis, Release Smoke.
Limits. No device keyboard interaction or Android compile was reported. Required CI checks are not present on the current head in canonical check metadata.
Request. Keep macOS Node HTTP requests from crashing the server when setTypeOfService throws EINVAL.
Audit finding. The server entrypoint on main installs no guard for the reported Undici socket exception. The patch runs a Darwin-only compatibility wrapper before the CLI and preserves non-EINVAL failures, with focused wrapper tests. A Node or Electron update alone is not proof that this exact macOS failure is fixed.
Recommendation. Keep open: work remains. Confirm the failure on the current macOS runtime and verify the guarded entrypoint with a reused HTTP connection.
Confidence medium. Release: Not applicable. PR readiness: Needs small changes.
Limits. The exact Node and macOS socket failure was not reproduced; tests exercise the wrapper rather than startup installation. Required Check, Test, Release Smoke, Mobile Native Static Analysis checks are absent on the collected head. The current head conflicts with main, and post-rebase checks are not available.
Request. Import local VSIX theme packages through the shared theme dialog and desktop picker.
Audit finding. Main only accepts loose JSON in the local dialog and picker, while VSIX parsing is confined to Open VSX downloads. The patch shares the archive parser, keeps archive limits, and adds collection-update confirmation with a separate local identity. The desktop picker still permits multiple packages and reads all their bytes before the renderer rejects the batch, so that path needs a memory bound.
Recommendation. Keep open: work remains. Reject multiple VSIX selections in the native picker before reading package bytes.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Attach the live thread event subscription before loading its snapshot.
Audit finding. Main now uses a thread event coalescer, but still starts Stream.runForEach through forkScoped without startImmediately. The shell subscription already supplies that option, and the thread snapshot test still delays publication by 25 ms. The later coalescing change therefore leaves the ordering gap addressed by this patch.
Recommendation. Keep open: work remains. Apply the immediate-start option to the current coalescer subscription and keep the no-sleep snapshot test.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Remove expired terminal context chips from saved composer drafts instead of restoring chips with no text.
Audit finding. Main persists terminal context metadata, then restores each context with an empty text value. The patch stops saving those contexts, removes their inline markers on save and hydration, and retains working in-memory chips. The focused tests cover legacy metadata and surrounding prompt text, so the requested persistence change is still needed.
Recommendation. Keep open: work remains. Review the drop-on-reload behavior with legacy drafts and the current file-attachment draft format.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Limits. Reload and send behavior were not exercised in a client. Required Check, Test, Release Smoke, Mobile Native Static Analysis checks are absent on the collected head. The current head conflicts with main, and post-rebase checks are not available.
Request. Snapshot the service-update database into one consistent SQLite file before a migration trial.
Audit finding. Main still copies the main database and its WAL and SHM files separately after the prior server child exits. The patch uses read-only VACUUM INTO, keeps atomic backup publication, and leaves rollback able to remove stale sidecars. The new tests use real databases but do not put committed data in an uncheckpointed WAL, which is the main consistency case claimed by the change.
Recommendation. Keep open: work remains. Add a WAL-mode snapshot and rollback test with committed data still in the WAL.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Limits. No service-update rollback was executed in this audit. Required Check, Test, Release Smoke, Mobile Native Static Analysis checks are absent on the collected head.
Request. Choose a reachable WSL backend address when Docker bridges or VPN interfaces precede eth0.
Audit finding. Main still chooses the first IPv4 address from hostname -I, so the reported Docker ordering remains possible. This patch ranks route and hostname candidates against Windows interfaces and covers mirrored mode, WSL NAT, custom switches, and overlapping VPN subnets. Open PR #5889 is related, but this patch has broader address validation and is not already merged.
Recommendation. Keep open: work remains. Choose one WSL address-selection patch after checking Docker plus VPN and mirrored-mode connectivity.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Limits. Only source and deterministic selection tests were inspected; no Windows or WSL runtime was used. Required Check, Test, Release Smoke, Mobile Native Static Analysis checks are absent on the collected head. The current head conflicts with main, and post-rebase checks are not available.
Request. Give unsigned local macOS packages their own bundle ID and an ad-hoc signature.
Audit finding. Main still uses the release app ID for all packaged builds and only configures signing when signed is true. The patch limits a separate local ID and ad-hoc signing to unsigned macOS builds outside CI. The older dev-runner bundle-ID change does not cover packaged local DMGs.
Recommendation. Keep open: work remains. Review the local-only packaging gate and add it to the existing build-config test matrix.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Limits. macOS privacy-grant persistence was reported by the author and was not reproduced in this read-only audit. Canonical latest-commit metadata has no results for these required checks: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Open HTTP and HTTPS links tapped in native mobile terminals.
Audit finding. Main native terminal modules emit input and resize events but no link-tap event. The patch adds native hit testing, but iOS reads only the viewport and can open a URL whose tail is clipped below it. Android supports OSC 8 labels, while iOS label-only OSC 8 links and file paths remain unsupported. The required native check also fails Detekt ReturnCount in the two new Android tap handlers.
Recommendation. Keep open: work remains. Fix the iOS viewport-boundary case and both Android Detekt ReturnCount violations before rerunning native validation.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Make the empty-provider composer control open provider settings.
Audit finding. The current composer still renders a disabled No provider available button, although the placeholder directs the user to Settings. Web and desktop share this path, and the PR leaves send disabled. Its static-markup test checks attributes only and its requested before and after images are absent.
Recommendation. Keep open: work remains. Replace the static-markup test with navigation evidence and attach the requested UI images.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Limits. The PR has no attached before and after UI evidence. Required checks have no results on this head: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Keep desktop and web sessions connected after one foreground health-check timeout.
Audit finding. Main still reconnects after one 15-second foreground timeout. The patch waits for two timeouts, but the second probe only starts on another foreground event, so recovery is not bounded to 30 seconds. Mobile resume probes remain unchanged.
Recommendation. Keep open: work remains. Add a test and a bounded retry path for a silent socket after the first tolerated timeout.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Keep the numbers typed in user-message ordered lists when rendering and copying them.
Audit finding. Main still derives list markers from the first ordinal and list length, so nonsequential user numbers are renumbered. The patch opts user-message render sites into source ordinals and updates copied li values while preserving normal assistant Markdown. Native mobile rendering is explicitly left unchanged, so this is a web and desktop fix only.
Recommendation. Keep open: work remains. Review the literal user-list behavior and replace static attribute assertions with focused ordinal and copy coverage.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Limits. The PR deliberately leaves native mobile user-list rendering unchanged. Canonical latest-commit metadata has no results for these required checks: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Expose a thread's discovered dev servers in mobile lists and headers.
Audit finding. The shared discovery subscription exists, but current mobile does not consume it or show dev-server controls. The patch reuses one environment subscription and rewrites loopback URLs for LAN or tailnet connections. Android can open only the first reachable server, and URL rewriting alone does not make a server bound exclusively to loopback reachable from a phone.
Recommendation. Keep open: work remains. Review multi-server access on Android and verify loopback-bound versus network-bound servers.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Check: GitHub check. Current head 64a42b9b: Test=SUCCESS, Check=SUCCESS, Mobile Native Static Analysis=SKIPPED, Release Smoke=SUCCESS.
Limits. Only iPhone direct-environment behavior was reported, not Android multi-server or tunnel behavior. Mobile Native Static Analysis was skipped on the current head; no passing native static result is claimed.
Request. Show the newest real nightly changes and link the omitted items in the update preview.
Audit finding. Main still keeps the first eight release-note lines and does not stop at contributor entries. The full PR fixes parsing and adds linked omitted counts, but its interactive hover popover has no closeDelay and the installed Base UI default is zero. The unresolved review about crossing the pointer gap is therefore a valid UI follow-up.
Recommendation. Keep open: work remains. Add hover close grace and verify pointer and keyboard access to the release links.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Update Clerk Electron to include its main-process fallback when secure token persistence fails.
Audit finding. Main still pins Clerk Electron 0.0.37 and creates the desktop bridge with the SDK storage adapter. The merged Clerk UI unpin changed renderer-delivered UI, not this main-process SDK version, so it does not replace the 0.0.38 bump. The diff updates both workspace consumers and the lockfile, but an actual sign-in with unavailable secure storage remains the relevant proof.
Recommendation. Keep open: work remains. Verify desktop sign-in and restart with secure storage unavailable on the upgraded SDK.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Check: GitHub check. Head c14da3a: Check, Test, and Release Smoke pass. Mobile Native Static Analysis is skipped.
Limits. The upstream package runtime and secure-storage sign-in were not executed. The current head conflicts with main, and post-rebase checks are not available.
Request. Keep cumulative result totals from replacing active Claude context usage at turn end.
Audit finding. The merged context-query change already prefers the latest parent assistant snapshot, reducing the original completion spike. Main still takes cumulative result usage before lastKnownTokenUsage when that assistant snapshot is absent. This diff changes that fallback, but its test incorrectly uses child task_progress as the authoritative parent baseline, conflicting with the parent-meter fixes.
Recommendation. Keep open: partial fix. Test the remaining fallback using parent message deltas and reconcile it with child-token isolation.
Confidence high. Release: In stable source. PR readiness: Needs small changes.
Request. Add sender headings so screen readers can navigate between chat messages.
Audit finding. The current timeline has message data attributes but no sender heading, and ChatMarkdown keeps reply heading levels unchanged. The patch adds hidden sender headings and offsets reply headings, so the requested semantic boundary is still missing on main. Its static-markup test does not establish navigation through the virtualized and newly folded transcript.
Recommendation. Keep open: work remains. Review heading levels and verify screen-reader navigation through the current virtualized transcript.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Reveal wall-clock timestamps on completed work rows and turn folds.
Audit finding. Main still omits timestamps from work rows and turn folds. In the submitted patch, opacity-zero timestamps remain in normal flow and reserve idle width, and nonexpandable rows gain a focusable span for each timestamp. Both unresolved review findings match the code, and the author says its interaction media predates the rebase.
Recommendation. Keep open: work remains. Remove the idle spacing and extra timestamp tab stops, then refresh current-head interaction evidence.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Reject a project root that contains only a bare repository and its linked worktrees.
Audit finding. Main project creation only normalizes the directory and does not reject this layout. The diff adds a targeted heuristic to CLI and client project creation, but it deliberately allows a bare root before any worktree exists and bypasses startup auto-bootstrap. The PR body contradicts its own test by claiming that pre-worktree roots are rejected.
Recommendation. Keep open: work remains. Correct the scope description and decide how startup-created projects should handle this layout.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Add navigation history across clients as the maintained replacement for PR 7808.
Audit finding. Main still has no app-wide Back and Forward controls. This successor fixes the original mobile traversal and reload issues, but its three-control titlebar inset still leaves too little space for the non-shrinking brand near the 208px sidebar minimum. The latest review points to that unchanged layout, so the branch needs one focused UI correction and native verification.
Recommendation. Keep open: work remains. Fix narrow macOS sidebar header overflow and verify the mobile navigation flow.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Keep the Working label visible when a running thread cannot be settled.
Audit finding. Main still replaces the Working label with Settle on hover, but the newly merged server settlement change removed canSettle from client-runtime. This PR imports and calls that deleted helper, so its older passing CI does not prove compatibility with current main. Keep the hover fix open and port the UI gate to the current settlement design.
Recommendation. Keep open: work remains. Port the hover eligibility check after the server-owned settlement change.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Attach comments to individual blocks or ranges in completed agent responses.
Audit finding. Main only supports review comments on files and diffs, not response blocks. The full diff adds Markdown block ranges, drag selection, and the existing review-comment prompt format. An open draft keeps old source offsets after text changes, which can remove its form while all comment triggers remain disabled.
Recommendation. Keep open: work remains. Clear or remap an open response-comment draft when the source text changes.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Time out local OpenCode version probes and kill their process group on cleanup.
Audit finding. Main still has no version-probe deadline and runOpenCodeCommand does not create or clean up a POSIX process group. The PR adds both, so the inventory move to HTTP does not replace it. Its focused test covers the deadline but not descendant cleanup, which is the extra behavior beyond the older timeout PR.
Recommendation. Keep open: work remains. Add a focused process-group cleanup test and review the four-second deadline on current main.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Load Codex and Claude skill menus from the active project or worktree on web and mobile.
Audit finding. Main still has no workspace-skills RPC, and menu deduplication did not fix catalog scope. The PR supplies lazy Codex and Claude discovery across web and mobile, but both editors still replace a successful empty result with snapshot metadata. Claude root read failures also appear as successful empty catalogs, a valid concern the author explicitly defers. The workspace fix remains needed with the editor fallback corrected.
Recommendation. Keep open: work remains. Preserve successful empty workspace results in both editor metadata paths.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Render workspace-relative images inside mobile Markdown files using the document directory.
Audit finding. Main FileMarkdownPreview still has no image renderer or environment and file-path context. The full PR reuses chat image components and supplies the nested document directory for both native and JavaScript Markdown renderers. Recent native image and PDF previews do not add inline Markdown images, and the supplied simulator proof used an older native baseline.
Recommendation. Keep open: work remains. Verify the shared image renderer on the current native build and keep the nested-file path tests.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Limits. The PR simulator evidence used a previous native baseline with temporary harness shims. Current review findings and general discussion were sampled, but historical resolved review threads were not read in full. GitHub reports merge conflicts with the current base.
Request. Force valid local-checkout metadata when a mobile project is known not to be a Git repository.
Audit finding. Main still takes saved or default worktree selection without a non-Git fallback. The diff normalizes display, immediate sends, and queued task creation from unfiltered cached refs, and hides Git controls. It adds no focused tests for stale restored selections or queued-task metadata, so those paths still need proof before merge.
Recommendation. Keep open: work remains. Add focused coverage for stale non-Git draft metadata and queued-task creation.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Remove the persisted provider binding when a thread is deleted.
Audit finding. ThreadDeletionReactor still stops the session and closes terminals without deleting its runtime row. ProviderSessionDirectory has no remove operation, so the new repository deletion path remains absent. The PR is separate from the active-session lookup fixes because those avoid reads but do not remove old rows.
Recommendation. Keep open: work remains. Add repository-backed deletion coverage and review the new directory dependency.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Route provider commands with thread metadata and the one requested user message.
Audit finding. The latest database-read merge now calls getThreadDetailById with no activity kinds, so the repeated large tool-output decode described in the PR is already removed. Main still loads messages, plans, and other thread detail to route commands, then scans messages to find the prompt and count user turns. This PR has remaining shell and narrow-message query scope, so it should not close as fully fixed.
Recommendation. Keep open: partial fix. Rebase and measure the remaining message-history cost before keeping the narrower query change.
Confidence high. Release: In nightly source. PR readiness: Needs small changes.
Request. Expose the stored Connect OAuth access token through a noninteractive CLI command.
Audit finding. Main already has a noninteractive token-refresh method but no connect token command. The diff adds the command and output-isolation tests, but converts every credential read or refresh failure into a fieldless missing-authorization error. The unresolved review is valid because that hides the actual failure and sends scripts to login even when stored authorization still exists.
Recommendation. Keep open: work remains. Preserve structured credential read and refresh errors, using the new error only when no token exists.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Comment: Discussion comment. The new blanket mapError removes the cause and mislabels read or refresh failures.
Limits. Required current-head checks are absent: Test, Check, Mobile Native Static Analysis, Release Smoke. Current review checks still fail: Macroscope - Effect Service Conventions.
Request. Accept a persisted rateLimitExceeded value when decoding Codex thread resume responses.
Audit finding. The current resume error union still lacks rateLimitExceeded. The PR fixes only V2ThreadResumeResponse, while read and rollback use separate closed error unions that also reject that persisted value. The same history can therefore resume and still fail later thread operations.
Recommendation. Keep open: work remains. Apply rate-limit compatibility to every historical-turn response schema and test read, resume and rollback.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Run Claude title generation outside the checkout without built-in tool access.
Audit finding. Main still runs title generation in the project directory with permission bypass. The diff disables tools and changes cwd for titles only, leaving branch, commit, and PR generation on the old path. It also leaves relative inherited CLAUDE_CONFIG_DIR values unresolved before changing cwd, so an isolated account can point to a different directory. Required Check also fails on the new named node:os import.
Recommendation. Keep open: work remains. Normalize relative config paths before switching cwd and combine shared text-generation restrictions with the earlier proposal.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Isolate Claude capability checks from the server working directory.
Audit finding. Main still probes from the server cwd, so the original settings leak remains. This branch uses a home-path resolver that misses environment-only config directories and can name a nonexistent cwd. Moving the probe also drops workspace slash commands, and the branch includes the separate title-generation change whose named node:os import fails Check.
Recommendation. Keep open: work remains. Remove the duplicate title changes and separate account probing from workspace command discovery.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Preserve saved mobile environments when the SecureStore catalog cannot be decoded.
Audit finding. Main deletes an undecodable saved catalog, so the data-preservation change is still needed. The diff adds backup recovery, but a valid primary read never seeds a backup for upgraded installs, and a malformed backup prevents fallback to valid legacy data. Both gaps remain in the final diff and are covered by unresolved reviews.
Recommendation. Keep open: work remains. Seed the backup on a valid primary read and allow malformed-backup fallback to valid legacy data.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Add search, date groups, filters, and bulk actions to the archived-thread browser.
Audit finding. Main still displays archived threads grouped by project with per-thread actions. The full diff adds chronological filtering, scoped selection, bounded bulk mutations, cancellation of future work, and confirmed Delete all. Its required Check failure is formatting rather than a runtime test failure, but the conflicted branch still needs a current-main review.
Recommendation. Keep open: work remains. Rebase the archive browser and fix the formatting failure.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Seed new project Actions from a user-level configuration file.
Audit finding. Main still creates projects with an empty script list. The patch seeds HTTP/WebSocket, auto-bootstrap, and offline CLI creation, but non-empty configuration is not tested through the latter two paths. The reported endless-ID-loop finding is not supported by the bounded 50-script input, while the loader is constructed directly instead of using the provided service.
Recommendation. Keep open: work remains. Add non-empty auto-bootstrap and offline CLI seeding tests using the provided project-file loader.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Comment: Discussion comment. The non-empty offline and startup seeding coverage gap is visible in the complete test diff.
Limits. Required CI checks are absent at the reviewed head: Test, Check, Mobile Native Static Analysis, Release Smoke. An older related reference could not be retrieved from GitHub. It is excluded from verified dependencies and fix evidence.
Request. Avoid slow Windows-mounted directories during Codex provider probes on WSL.
Audit finding. The probe still uses process.cwd(), so a server launched from drvfs can run skills/list against that slow directory. The PR switches all /mnt/ paths to HOME without checking that the host is WSL. Its manual WSL desktop check is explicitly unfinished, and native Linux mounts also match the proposed test.
Recommendation. Keep open: work remains. Constrain the fallback to the intended WSL case and verify the desktop provider probe there.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Keep the sidebar Working timer stable across synthetic continuation turns.
Audit finding. Main starts the Working timer from the latest turn, so synthetic continuations still reset it. This diff moves the anchor to latestUserMessageAt, but that time comes from the sending client and is not rejected when it lies in the viewer's future. The timer therefore needs clock-skew handling for remote and multi-device use.
Recommendation. Keep open: work remains. Handle future client timestamps while keeping one response-level timer anchor.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Fail desktop artifact builds early when host tools or Rust targets are missing.
Audit finding. Main starts packaging without the proposed cross-platform preflight. The full diff checks executable versions, Rust standard libraries, Python 3, and Visual Studio components. Linux documentation claims compile-and-link checks for X11 headers, but the implementation only probes tool versions and does not perform those checks.
Recommendation. Keep open: work remains. Correct the Linux preflight documentation to match the implemented capability checks.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Keep the settled-thread notice compact by placing its helper text in the title row.
Audit finding. Main gives the parked-thread notice a separate description. This diff moves the helper text into the title, but the bare spans lack the shrink and truncation rules needed to keep the longer Snoozed notice compact. It remains distinct from shared action alignment and needs a narrow-layout fix before merge.
Recommendation. Keep open: work remains. Constrain the inline helper text so the Snoozed notice stays compact at narrow widths.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Reject oversized orchestration replay ranges before materializing event payloads.
Audit finding. Main still bounds reconnect replay by event count only, despite newer snapshot and tool-update memory fixes. The patch adds a preflight query for both shell and thread streams, but SQL length(payload_json) reads the full TEXT and counts Unicode characters rather than bytes. Its ASCII-only test cannot prove the claimed 8 MiB limit for non-ASCII payloads.
Recommendation. Keep open: work remains. Use a metadata-safe byte count and add a non-ASCII replay-budget test.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Show a web and desktop recovery action when provider startup stays in starting.
Audit finding. Main has no dedicated stalled-start recovery warning. The proposed sixty-second deadline uses a minute-truncated clock, which can delay it to almost two minutes, and session.updatedAt changes can restart that wait. The banner key also includes that mutable timestamp, so status updates can remount the focused Stop action; mobile is explicitly outside this PR.
Recommendation. Keep open: work remains. Track the starting-state deadline and use a stable banner key, then test the real clock path.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Open the Git success toast PR action in the app while preserving modifier-click browser behavior.
Audit finding. Main still calls shell.openExternal directly from the Git success toast. This diff correctly delegates the complete URL to the thread-aware shared helper, preserving repository identity and modifier clicks. The helper still reports open failures as unscoped toasts, while PR #9007 preserves scopedToastData, so consolidation must carry that behavior too.
Recommendation. Keep open: work remains. Preserve thread-scoped failure toasts in useOpenPrLink before consolidating PR #9007.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Make a plain click on the Git success toast open its PR inside the app.
Audit finding.PR #9006 overlaps the in-app toast routing and fixes the repository-identity loss still present here. This PR additionally passes scopedToastData to fallback error toasts, while useOpenPrLink currently creates a global error toast. Neither is a complete replacement for the other yet, so keep this open until the scoped failure behavior is carried into the shared-helper fix.
Recommendation. Keep open: partial fix. Carry scoped fallback errors into PR #9006, then reassess this PR for closure.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Pr: PR #9006. Preferred repository-aware routing, but not yet a complete replacement.
Comment: Discussion comment. The current PR addressed this review requirement by retaining scopedToastData.
Independent closure check. The full one-file diffs cover the same toast navigation goal, and 9006 is better scoped for cross-repository routing. However, the full 9007 review added a concrete requirement to keep fallback errors scoped to the originating thread. Current 9007 supplies scopedToastData to that error toast. Replacement 9006 delegates to useOpenPrLink, whose fallback catch creates a global unscoped toast. It is not a complete replacement until that unique error behavior is transferred.
Limits. Latest head has no results for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Offer to snooze a limited Claude or Codex thread until one minute after its reset time.
Audit finding. Main has snooze and wake actions but no persisted rate-limit reset or corresponding notice. The PR adds that path for Claude and Codex, while mobile UI and account-wide propagation remain deferred. Its current diff re-emits unchanged session events despite the body claiming no event for repeated resets. The unresolved snooze-capability review concern is not a current in-tree failure because every server implementing this field advertises threadSnooze.
Recommendation. Keep open: work remains. Correct the idempotency description and agree on mobile scope before reviewing the rate-limit wiring.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Keep native list bounds and live follow correct after disclosure size animations.
Audit finding. Current main still switches the patched size view between static and animated styles and does not reconcile follow when a disclosure settles. The patch addresses those gaps, but its new two-frame callback is not cancelled when the scoped thread changes. Since ThreadFeed is keyed by bare thread ID, switching environments with the same ID can apply the previous callback to the new list, as the unresolved review reports. Android and physical-device resume behavior also remain unverified.
Recommendation. Keep open: work remains. Cancel or invalidate pending disclosure callbacks when the environment-scoped thread key changes.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Comment: Discussion comment. The scoped-thread callback race is present in the reviewed diff.
Check: GitHub check. Current head fa0926df: Test=SUCCESS, Check=SUCCESS, Mobile Native Static Analysis=SKIPPED, Release Smoke=SUCCESS.
Limits. Android was not exercised. Physical-device lock and resume interaction was not verified. Mobile Native Static Analysis was skipped on the current head; no passing native static result is claimed.
Request. Allow daily usage charts to select a custom date range by dragging or entering dates.
Audit finding. Main only exposes preset usage windows. The publishing head adds brushing, bounded ranges, and buffered date fields, fixing the repeated-scan problem. The date fields still do not commit on Enter or show invalid-range feedback, which matches the current failing UI review check.
Recommendation. Keep open: work remains. Add Enter commit and invalid-range feedback to the buffered date fields.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Request. Enable Claude todo tools so Claude 5 sessions can produce plan updates.
Audit finding. Main does not set CLAUDE_CODE_ENABLE_TODO_TOOLS in the shared environment builder. The diff forces it to 1 for sessions, probes, and metadata generation, including when the instance explicitly sets 0. The existing plan-event mapping is unchanged, and the author reports that focused tests and typechecks were not run locally.
Recommendation. Keep open: work remains. Run the focused environment and plan-event tests and decide whether an explicit disabled flag should be preserved.
Confidence high. Release: Not applicable. PR readiness: Needs small changes.
Limits. The real Claude 5 todo-tool behavior was not reproduced. Latest-head required checks are not reported: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Display subscription quota windows for the configured providers.
Audit finding. Main has no subscription quota field on provider snapshots. The maintainer discussion explicitly reversed an earlier closure in favor of another proposal, so that proposal is not an accepted replacement. The inspected head misclassifies exactly 30-day windows as weekly and leaves timers behind when a PTY exits during listener setup. Keep this open for correction and a full cross-provider review.
Recommendation. Keep open: work remains. Fix quota-window classification and immediate-exit PTY cleanup before the full provider review.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Check: GitHub check. Head CI: Test failure, Check failure, Mobile Native Static Analysis skipped, Release Smoke success.
Limits. The 49-file quota diff was not fully reviewed. Core schema, ingestion, Codex quota mapping, and PTY cleanup were inspected. Top-level comments and current unresolved findings were reviewed, but the full history of 186 review threads was not read.
Request. Prevent extremely long diff lines from freezing the web diff view.
Audit finding. Main still parses file diffs without a per-line limit and passes them to AnnotatableCodeView. The PR adds a 500,000-character guard, but its old per-file rendering path must be adapted to the current shared code view. No landed equivalent was found.
Recommendation. Keep open: work remains. Port the guard into the current code-view path and test one oversized file beside a normal file.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Distribute provider compatibility policy updates independently of T3 releases.
Audit finding. Main has version advisories but no compatibility document, remote policy service or targeted-version update contract. This PR adds those paths and can change provider availability based on a remotely fetched map. Its four-driver and web UI coverage predates Grok and leaves native mobile presentation unresolved.
Recommendation. Keep open: decision needed. Decide the remote compatibility policy and supported clients before updating this implementation.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Selected contracts and service code were inspected, but the full 40-file diff was not reviewed. Only selected current review findings were read. The complete discussion and resolved review history were not reviewed. Latest-head required check results are absent for Test, Check, Mobile Native Static Analysis. GitHub reports a conflict with main. Any passing checks apply to the existing head, not a rebased result.
Request. Replace the orchestration runtime, provider adapters, persistence, and client state with orchestration V2.
Audit finding. Pinned main still uses the existing orchestration API and runtime, while this branch adds the V2 event store, outbox, provider lifecycle, migration, and client contracts. Its long closes list is not evidence that those issues are fixed on main or in a release. A current-head mobile finding is confirmed in source: showStopAction ignores draft content and replaces Send or Queue while a run is interruptible. The 955-file diff and 913 review threads need a dedicated integration review.
Recommendation. Keep open: work remains. Complete the V2 migration and cross-client review, starting with the confirmed mobile queue-action regression.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. Recent review reports that follow-up text cannot be queued from mobile.
Limits. Only selected runtime, migration, contract, and client changes were reviewed from the 317070-line diff. Only selected discussion and review threads were read from 913 threads. No migration, provider replay, or real-client run was performed. Required checks absent from the canonical latest-commit rollup: Check, Test, Mobile Native Static Analysis, Release Smoke.
Request. Disambiguate worktree start refs when local and remote names collide.
Audit finding. Main still passes the raw start ref to git worktree add, so ambiguous local and remote names remain unresolved. However, the proposed fully qualified local ref detaches HEAD when newRefName is absent. A disposable Git fixture confirmed that refs/heads/feature produces detached HEAD while feature stays attached, and current missing-worktree revival uses this no-new-branch path.
Recommendation. Keep open: work remains. Preserve branch attachment for existing local branches and add a no-newRefName test before merging.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Pr: PR #2864. Complete diff qualifies local refs for both worktree-add forms. A scratch-only Git fixture confirmed the existing-branch form detaches HEAD.
Request. Keep Cursor Fast mode opt-in and preserve the last Fast choice across models and new threads.
Audit finding. Main still builds dispatch options from provider defaults and replaces sticky model selections without retaining omitted options. This PR changes defaults for every model with a fastMode descriptor, not only Cursor, and only changes web state. A maintainer must approve that default and decide the matching mobile behavior.
Recommendation. Keep open: decision needed. Decide whether Fast should default off for every provider, then update shared option handling and mobile.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Canonical current-head results are missing for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports conflicts with the target branch, so recorded checks do not validate a rebased integration.
Request. Require per-client approval before T3 Connect issues environment credentials.
Audit finding. Main still mints a cloud-connect credential after account and proof validation and has no client-approval state in AuthAccessSnapshot. The selected diff introduces approval persistence and signed pending responses, but also makes new snapshot fields required. This is an unlanded authorization policy change that needs a compatibility and revocation decision, not a cleanup candidate.
Recommendation. Keep open: decision needed. Decide the approval policy and mixed-version rollout before completing the security review.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Check: GitHub check. Test passes on the current PR head. Passing checks do not establish merge safety.
Limits. Large 30-file diff. Reviewed approval store, mint handler, and auth/relay contracts, but not every changed file. Current unresolved review threads were checked, but the long prior discussion and resolved review history were not fully read. GitHub reports merge conflicts with main on the collected head.
Request. Replace cross-process test polling and remove overly short test timeouts.
Audit finding. Main still has a 15-second web test budget and virtual-clock polling in provider tests, but those suites changed substantially after this PR. The proposed live-clock helper and timeout edits have not landed. Its historical flake report needs a current focused reproduction before adopting the broader timeout changes.
Recommendation. Keep open: retest. Reproduce the named Cursor, provider-reprobe, and Git tests on current main, then retain only still-failing cases.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Reviewed the helper, CI guidance, timeout patch, and affected test names, not all 678 changed lines of the test rewrites. The reported flakes were not reproduced on current main.
Request. Play completion and input-request sounds across web, desktop and mobile threads.
Audit finding. Main has neither the global cue coordinator nor its completion-sound preference. The patch now handles live hydration, reconnects, per-thread subscriptions and defensive playback, but enables completion sounds by default and provides no mute control for input-request sounds. It also needs the current Expo audio integration, rather than its older SDK dependency addition.
Recommendation. Keep open: decision needed. Decide the default and mute behavior, then rebase onto current mobile audio and verify all three clients.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Pr: PR #7348. Another open notification and sound proposal overlaps web behavior.
Limits. The generated audio was not played in a client during this read-only audit. Required check did not execute on the recorded head: Mobile Native Static Analysis. GitHub reports conflicts with the target branch, so recorded checks do not validate a rebased integration.
Request. Resolve fork pull requests against their upstream repository across GitHub operations.
Audit finding. Main provider selection still prefers origin, so the conventional fork-to-upstream routing is not implemented. The reviewed production diff also confirms the open Enterprise finding: its parser puts host/owner/repo into headRepositoryNameWithOwner while PR payload comparison expects owner/repo. The later project-navigation replacement covers only navigation, not this fork workflow.
Recommendation. Keep open: work remains. Fix Enterprise head-coordinate matching and finish the fork test review before rebasing.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Persist fatal mobile JavaScript errors before React Native terminates.
Audit finding. Main still registers the mobile root without a fatal-error recorder. The diff installs an early ErrorUtils handler, writes bounded crash files, and reports them on next launch, but it does not contain the breadcrumbs or outbox context claimed in the opening body. Release-device crash persistence and handler chaining need proof.
Recommendation. Keep open: work remains. Verify fatal-error persistence on a release mobile build and align the body with the actual three-file change.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Fix native Markdown state and thread-feed sizing during first layout.
Audit finding. Main has newer LegendList 3.3.5 sizing and Android initial-inset handling, so the old 3.2.0 list patch cannot be taken as-is. The native shadow node still caches attributed text during measure and publishes it during layout, leaving the concrete stale-state gap addressed here. The PR mixes that fix with short-content positioning, extra composer spacing, and an old image viewer. The unresolved review also correctly identifies a thread-switch mismatch between the reset height estimate and the unchanged shared inset.
Recommendation. Keep open: partial fix. Extract the native shadow-state fix and retest remaining layout changes against the current feed.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Keep chat scroll positioning stable while composer and keyboard insets change.
Audit finding. The actual diff is largely iOS inset math and UIScrollView method replacement despite its Android title. Main already has adjustedStartInsetCompensation in the keyboard-controller patch, covering much of the proposed negative-offset support under a transparent header. The additional native setContentInset offset restoration is absent and needs separate evidence, not a whole old patch merge.
Recommendation. Keep open: partial fix. Identify a current failing keyboard transition and reduce the patch to behavior not already covered.
Confidence medium. Release: In stable source. PR readiness: Needs work or a decision.
Check: GitHub check. Current head ab640b5f: Test=SUCCESS, Check=SUCCESS, Mobile Native Static Analysis=SUCCESS, Release Smoke=SUCCESS. GitHub reports merge conflicts.
Merged pr: PR #8793. Addresses the part identified in this finding; merge commit f15680bd3c08 was checked against repository release ancestry.
Limits. No current reproduction of the remaining native inset behavior. Release status refers to repository tag ancestry; mobile app-store and OTA rollout was not verified.
Request. Forward preview ports through a scoped desktop SSH connection.
Audit finding. Main still resolves environment ports by host rewriting and its SSH manager only exposes environment connection and disconnection. The reviewed router adds leased SSH forwards, while the companion cleanup PR corrects lifetime and ordering races in that feature branch. Neither the forwarding feature nor its cleanup is on main.
Recommendation. Keep open: work remains. Review the forwarding feature and its lifecycle companion as one stack.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Pr: PR #7639. The companion fix targets the unmerged forwarding branch.
Limits. The 105,560-byte diff was not fully read. Review covered the named feature paths and current main, not every file or test. GitHub reports merge conflicts with the current base.
Request. Use codex update on supported modern installations while retaining legacy package-manager paths.
Audit finding. CodexDriver still declares nativeUpdate:null and resolves maintenance capabilities without the probed version. The PR adds version gating, preserves pnpm and Vite+ paths, and carries the correct installation environment into updates. Its snapshot-service and shared semver changes require broader review than the command substitution alone.
Recommendation. Keep open: work remains. Review version-aware maintenance on current main with standalone, shadow-home and package-manager cases.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Maintenance production changes were inspected, but the full 15-file diff and tests were not reviewed. Latest-head required check results are absent for Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports a conflict with main. Any passing checks apply to the existing head, not a rebased result.
Request. Pin PR-size workflow actions and remove a job that its trigger can never run.
Audit finding. Main still runs the workflow only on pull_request_target while sync-label-definitions requires a different event. It also still uses floating checkout and github-script tags. The workflow change remains useful, but the added contributor backlog document is a separate concern and was not fully reviewed.
Recommendation. Keep open: work remains. Split out the contributor backlog document and review the focused workflow cleanup.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Preserve Date, Map, and class values during deepMerge and reject primitive top-level patches.
Audit finding. Struct.ts is unchanged since its introduction and still recurses into every Effect Predicate.isObject value, which can strip prototypes from nested instances. The PR fixes nested replacement and adds tests, but its top-level guard still accepts Date, Map, and class objects despite saying a patch must be plain. Current production callers merge schema-validated settings records, so an affected application flow is not established.
Recommendation. Keep open: work remains. Agree on the supported deepMerge input contract and align the implementation and tests with it.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Add a panel hide button and route close shortcuts to the focused right-panel tab instead of the desktop window.
Audit finding. Main has tab close and panel toggle actions, but no rightPanel.closeActiveSurface command or the proposed far-right hide control. The full patch adds retained focus tracking, portal markers, keybinding migration, and native preview forwarding, so later held-key and last-tab fixes do not replace it. Its extracted shared key matcher still always accepts physical Latin key codes, which would undo main's non-QWERTY fix if carried over unchanged.
Recommendation. Keep open: work remains. Rebase the focus-aware close change while preserving current keyboard-layout matching and terminal close confirmation.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Use one new-thread project picker with scope-aware ordering, Add project and complete empty states.
Audit finding. Merged #4269 already routes the new sidebar and shortcut through the command palette. Main still opens the dedicated picker only when project items exist and builds it without an Add project action or shared sidebar scope. Those additions remain useful, but the patch overlaps #4748 and must preserve current Shift-click creation and the renamed legacy-sidebar setting.
Recommendation. Keep open: partial fix. Reduce the patch to the missing picker behaviors and choose one scope policy with the selected-project creation patch.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Limits. Canonical current-head results are missing for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports conflicts with the target branch, so recorded checks do not validate a rebased integration.
Request. Give Alpha builds a dawn sidebar illustration and a separate macOS icon.
Audit finding. Main still has only Nightly and Dev artwork and selects the production icon for every non-Nightly desktop build. The patch adds Alpha artwork, but its icon selection replaces that entire non-Nightly fallback, including an ordinary version such as 0.0.17, despite the body saying production is unchanged. Current artwork also has theme and identification controls added after this branch, so channel selection and theme behavior need a design decision.
Recommendation. Keep open: decision needed. Approve the Alpha identity and limit icon routing to the intended channel before integrating with current artwork controls.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Binary icon appearance and native Icon Composer export were not verified. Required checks absent from the canonical latest-commit rollup: Check, Test, Mobile Native Static Analysis, Release Smoke.
Request. Refresh mounted file previews after disk edits and revalidate when they reopen.
Audit finding. Merged PR 8803 refreshes web previews after agent mutations, and PR 7490 couples explicit tree refresh to the open file. Main still has cached readFile atoms with no native file-watch subscription, so unrelated disk edits and mobile remounts are not covered. Keep the watcher and lifecycle scope open, and replace the new sleep-based watcher tests with deterministic synchronization.
Recommendation. Keep open: partial fix. Rebase the remaining disk-watch and remount behavior onto the landed web refresh hooks.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Choose any physical checkout within a grouped repository when creating a web or desktop thread.
Audit finding. The current workspace selector still accepts only local/worktree mode and one active path. It has no checkout list or project-switch callback, so a second clone in the same environment remains outside this picker. The PR adds that physical-project choice but explicitly leaves the native mobile selector for later.
Recommendation. Keep open: work remains. Review the draft project-and-workspace switch and define the native mobile follow-up.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Find monorepo application favicons and strip content outside the root SVG document.
Audit finding. Main still checks root-relative favicon candidates and source files, then serves project SVG files unchanged. Manual icon selection and the async favicon lookup fix provide workarounds and performance improvements, not these two behaviors. The complete diff adds both automatic monorepo discovery and SVG document extraction, so its scope remains open.
Recommendation. Keep open: work remains. Review automatic monorepo lookup separately from SVG extraction and preserve current icon overrides.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Allow hosted or client-only web clients to manage pairing links and sessions on an authorized saved environment.
Audit finding. Connections still reads primary-session scopes and subscribes to auth access only for the primary environment, while pairing still requests the standard presentation scopes. The CLI QR portion is already available through the merged standalone pair command, but the per-environment access-management path remains missing. The selected diff routes auth HTTP through the chosen prepared connection and avoids sharing relay or SSH loopback URLs.
Recommendation. Keep open: partial fix. Keep the per-environment access and scope changes while dropping the duplicate CLI QR work.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Merged pr: PR #4955. Standalone t3 pair already prints a scannable QR code.
Limits. Large 12-file diff. Reviewed per-environment auth HTTP, pairing scopes, pairing URL selection, and CLI formatting, but not every changed file. Current-head required checks were not reported: Check, Mobile Native Static Analysis, Release Smoke, Test. GitHub reports merge conflicts with main on the collected head.
Request. Treat a loopback server published through Tailscale Serve as remotely reachable for authentication controls.
Audit finding. Main still derives the auth policy only from the bind host, so tailscaleServeEnabled does not select remote-reachable. The single-origin dev change already permits one-time pairing for loopback-browser policy, which covers part of the original pairing problem. The diff also changes Claude auto permission mode to default, which is unrelated and would change provider behavior.
Recommendation. Keep open: partial fix. Remove the Claude permission changes and test Tailscale Serve pairing controls against current auth policy.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Merged pr: PR #4556. Added one-time-token bootstrap to loopback web policy.
Comment: Discussion comment. Confirmed unrelated Claude auto-mode regression in the diff.
Limits. Current-head required checks were not reported: Check, Mobile Native Static Analysis, Release Smoke, Test. GitHub reports merge conflicts with main on the collected head.
Request. Select one environment for server-backed settings while keeping client preferences local.
Audit finding. General and Diagnostics still read primary-server atoms despite environment-scoped settings hooks already existing. This branch also contains client-only desktop startup, protocol, and relaunch changes from its now-closed, unmerged base, so it is not a settings-only patch. The narrower diagnostics and text-generation PRs do not cover this shared selection or desktop dependency.
Recommendation. Keep open: decision needed. Choose the shared settings-target approach and separate the client-only desktop dependency before review.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Large 72-file diff. Reviewed settings target selection, settings hooks, and desktop backend-mode ownership, but not every changed file. Current-head required checks were not reported: Check, Mobile Native Static Analysis, Release Smoke, Test. GitHub reports merge conflicts with main on the collected head.
Request. Add Hermes provider integration and a separate projectless T3 Work workspace.
Audit finding. Main ships neither a Hermes driver nor the V2 runtime required by this draft. Its migration parent was merged into the V2 branch, not main, so that merge is not a released foundation. The inspected connection policy only allows loopback Hermes to become ready and returns remote_verification_unsupported for remote endpoints even after credentials are configured. This combines provider lifecycle, chat import and reset, media, cron, MCP leases, and two clients in a 232-file feature.
Recommendation. Keep open: decision needed. Agree on the T3 Work scope and supported Hermes protocol before splitting the draft into reviewable changes.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author maria-rcks. Updated 2026-08-29T19:58:09Z. Draft yes. Target codex/v1-v2-state-migration. Head f024045b1a181b231f3e994838016a9b5e570b08. Branch hermes/h0-conformance. Size +38478 / -1002, 232 files, 34 commits. Mergeability MERGEABLE. Merge state UNSTABLE. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #4400. Migration parent merged into the V2 branch and is not an ancestor of pinned main.
Check: GitHub check. Canonical latest-head checks: Check success, Test success, Mobile Native Static Analysis success, Release Smoke success.
Limits. Only selected provider, security, migration, and client changes were reviewed from 46628 diff lines. The 87 review threads were not fully reviewed. No real Hermes gateway, import, reset, media, or delegation flow was verified.
Request. Make repeated worktree removal succeed and continue bulk thread deletion after one failure.
Audit finding. Merged PR 8076 made removal succeed when the worktree path is already gone and is included in stable v0.0.37. Both current web sidebar bulk-delete loops still return after the first failure. The PR also leaves unresolved selection keys behind when a selected thread shell has disappeared, so the remaining bulk-delete work needs that correction.
Recommendation. Keep open: partial fix. Keep the bulk-delete continuation change and clear selected keys that no longer resolve to a thread.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Inspect global Codex and Claude skill files across connected environments.
Audit finding. Main exposes provider skill metadata but has no cross-environment Skills settings page or full-file inventory endpoint. This patch respects configured provider homes and enablement, but intentionally excludes the other providers and native mobile. The endpoint follows discovered file paths without a defined symlink read policy, and the patch commits an implementation plan that current repository guidance excludes.
Recommendation. Keep open: decision needed. Agree on the inventory read scope, then revise the endpoint and remove the committed implementation plan.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. The reviewed endpoint follows discovered symlinks; the allowed read scope needs an explicit decision.
Limits. The audit confirmed the file-read mechanism but did not reproduce an unauthorized read or assign the review bot's severity. GitHub reports conflicts with the target branch, so recorded checks do not validate a rebased integration.
Request. Disable PR creation when the source-control CLI is missing or unauthenticated.
Audit finding. Main checks provider readiness for repository publishing, but buildMenuItems and resolveQuickAction still receive only Git state. The PR adds the missing create-PR gate and refresh on focus, which source-control API budget and relay scan fixes do not provide. Its scope leaves the separate mobile Git action logic unchanged.
Recommendation. Keep open: work remains. Apply readiness gating through shared Git action logic and cover the mobile entry point.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Group native orchestration-v2 subagents into one timeline row per run attempt.
Audit finding. Main already has a summary CTA for its current agent-panel model, but this PR targets the unmerged orchestration-v2 branch. Its full diff handles v2 projected subagent items, inherited rows, replacement attempts and mixed failures, none of which the main CTA proves. This is dependent v2 work, not a duplicate of the current main presentation. The current server replay check fails four OpenCode idle assertions, so its tests are not all green.
Recommendation. Keep open: work remains. Review and rebase the summary patch against the latest orchestration-v2 branch after its contracts settle.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author shivamhwp. Updated 2026-09-01T09:33:13Z. Draft no. Target t3code/codex-turn-mapping. Head 6ee1aabe55cfe8c1b9ddf48a6aac891672138351. Branch subagent-obs/05-thread-visibility. Size +279 / -45, 5 files, 1 commits. Mergeability MERGEABLE. Merge state UNSTABLE. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Check: GitHub check. Read the failed log: four OpenCode replay scenarios fail while waiting for the run to become idle.
Limits. The final diff and current review state were inspected, but not every historical thread from the earlier, broader PR scope was fully reviewed. Required check did not execute on the recorded head: Mobile Native Static Analysis. Test Server 3 fails four deterministic OpenCode replay scenarios while awaiting idle; the audit did not establish whether the failure comes from the base branch or the PR.
Request. Return the overlay failure before the broker deadline and retry transient screenshot capture failures.
Audit finding. Main still gives the overlay wait the full broker timeout and still captures a screenshot once. The PR addresses both paths, with tests for retry failure and a replaced guest. Later open work splits and expands these fixes, so neither part can be treated as landed.
Recommendation. Keep open: work remains. Reconcile its capture retry with the background-automation branch and keep the timeout fix in one active PR.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Add a server worktree inventory, safe cleanup policy, and automatic revival.
Audit finding. Merged PR 7839 covers missing-worktree recreation, but main still lacks inventory and retention policy. The maintainer requested a V2 port, and the related V2 proposal is still open. The inspected legacy inventory keeps only the first record for a shared worktree path, which can discard another project's active-thread blocker, confirming a current safety finding.
Recommendation. Keep open: partial fix. Use the V2 direction for further lifecycle work and resolve shared-project prune safety before adopting any cleanup code.
Confidence medium. Release: In stable source. PR readiness: Needs work or a decision.
Merged pr: PR #7839. Landed existing-thread worktree recreation, included in stable v0.0.37.
Source: packages/contracts/src/rpc.ts. Current RPC contracts do not expose the proposed managed inventory and safe-prune commands.
Comment: Discussion comment. Confirmed in the selected WorktreeService diff: later records for the same worktree path are discarded.
Limits. Read the body, lifecycle contracts, reaper, and turn-start patch. The 22-file, 2,207-line diff was not fully reviewed, including the inventory service, settings UI, and test bodies.
Request. Give woken and manually restored threads shared web/mobile priority and clearer input states.
Audit finding. Merged #8231 already gives both clients a stable unsettledAt ordering anchor. Woken-first ranking, shared settled-row timestamps and the stronger pending-input presentation are still absent. This patch also modifies client-derived automatic settlement, which main has since replaced with server-owned settlement, so that part cannot be restored as written.
Recommendation. Keep open: partial fix. Split out the remaining wake ordering and input presentation changes on top of current server settlement.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Suppress phone activity while an authenticated desktop client is focused.
Audit finding. Main has no desktop-focus RPC or focus-based relay suppression. The diff adds connection-scoped focus leases, clears existing mobile activity, and resumes only nonterminal work, with tests for lease release and clearing retries. This is an environment-wide notification policy and overlaps the publish serialization proposed in PR #4978. The author confirms that every web browser is classified as desktop, so mobile web focus also triggers this policy.
Recommendation. Keep open: decision needed. Approve the suppression policy and reconcile relay serialization with PR #4978.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Use the selected sidebar project when starting a new thread.
Audit finding. Main keeps sidebar project scope in local component state and new-thread actions still use the active thread context or the project picker. The patch covers the button and both shortcuts and preserves a grouped project environment, but chooses immediate creation where #4263 instead prioritizes that project in the picker. This needs one creation policy and a rebase that preserves current Shift-click behavior.
Recommendation. Keep open: decision needed. Choose immediate creation versus a scope-prioritized picker, then apply that policy to button and shortcut paths.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Pr: PR #4263. Open alternative keeps a scope-aware picker.
Limits. Canonical current-head results are missing for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports conflicts with the target branch, so recorded checks do not validate a rebased integration.
Request. Keep executing, interrupted and failed work-log rows visible in orchestration-v2 threads.
Audit finding. The PR targets the open orchestration-v2 branch, not main, and the collected comparison includes 886 files and about 12.9 MB. Main has newer work-log folding and activity fixes, but those use a different model and do not prove v2 lifecycle coverage. The stated behavior and review history remain relevant, but a clean feature-only diff is needed before an archive or merge decision.
Recommendation. Keep open: evidence needed. Rebase onto the current orchestration-v2 branch and provide a feature-only diff.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author mwolson. Updated 2026-09-01T05:36:37Z. Draft no. Target t3code/codex-turn-mapping. Head 38109f8e5dc630cc1007a5b074f4cb05935c98bd. Branch fix/web-timeline-inflight-tool-rows. Size +182263 / -85526, 886 files, 244 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #2829. Open orchestration-v2 base dependency.
Limits. The 886-file cumulative diff was not fully reviewed. GitHub reports conflicts with the target branch, so recorded checks do not validate a rebased integration.
Request. Reduce desktop update restart delays through macOS staging, smaller packaged trees, and startup feedback.
Audit finding. Main already keeps macOS and Linux JavaScript in ASAR and has separate Windows packaging and installer improvements. It still disables autoInstallOnAppQuit, has no native staging readiness listener or relaunch marker, and destroys every window before install. The remaining macOS staging and splash flow needs adaptation to the newer single-action update state and a packaged update test.
Recommendation. Keep open: partial fix. Rebase only the remaining staging and relaunch feedback changes, then measure a packaged macOS update.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Reduce Windows command-path tracing and cap concurrent Git child processes.
Audit finding. Merged PR 5561 now caches command-path lookups, but uncached isExecutableFile probes still emit spans and VcsProcess still has no spawn semaphore. The proposed replacement cache also caches relative explicit paths without a cwd key, unlike the safer current cache. Keep the remaining tracing and spawn work, not the old cache implementation.
Recommendation. Keep open: partial fix. Retain main's command cache and port only untraced probes and bounded Git spawning.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Report follow-up work on delegated child threads without changing the original task result.
Audit finding. Pinned main has no V2 delegate_task API, and the current orchestrator branch still lacks hasPendingChildRuns and latestTerminal fields. The focused four-commit change preserves original-run identity, excludes rolled-back or never-started follow-ups, and fixes both reported selection errors. The submitted diff also contains 887 files from divergent V2 history, so it cannot be reviewed or merged as a small main-branch fix.
Recommendation. Keep open: work remains. Restack the focused task-status commits onto the current orchestrator branch.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author mwolson. Updated 2026-09-01T05:36:36Z. Draft no. Target t3code/codex-turn-mapping. Head be033abae373b5d97e5155f769fc0956baaa1adc. Branch fix/delegated-task-status-queued-turn. Size +182202 / -85511, 887 files, 244 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #2829. Active V2 parent branch is required and does not yet contain these result fields.
Check: GitHub check. Canonical latest-head checks: Check success, Test success, Mobile Native Static Analysis success, Release Smoke success.
Limits. Reviewed the focused task-status source delta, not all 288158 lines of inherited V2 changes. The full replay fixture and inherited test changes were not independently executed.
Request. Use an iOS URLSession WebSocket transport that can negotiate frame compression.
Audit finding. Main still uses React Native's global WebSocket, so server compression alone does not add iOS negotiation. The diff handles close ordering and late opens, with recorded simulator reconnect checks, but still marks native listeners attached before registration succeeds. A registration exception can leave later sockets without events, so the unresolved retry-safety finding remains valid.
Recommendation. Keep open: work remains. Make native listener registration retry-safe and repeat the iOS transport checks.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Remove duplicate mobile Clerk navigation headers, with additional terminal-buffer synchronization changes in the same diff.
Audit finding. The Clerk header problem is covered by the merged native header ownership change, and main now routes AuthView back through onHostBack. This PR is not only that fix: it adds terminal buffer epochs, absolute offsets, and chunked native iOS writes across mobile, web, and shared runtime. Those terminal changes are absent on main, so closing the whole PR as fixed would discard material work.
Recommendation. Keep open: partial fix. Split the remaining terminal-buffer work into a focused PR and remove the already-covered auth changes.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Add a manual motion preference and disable automatic transcript following by default.
Audit finding. Main still follows the live edge by default and has neither proposed client preference. The full patch changes that product default, adds a motion override and includes unrelated directional-layout edits. Recent follow-restoration fixes do not decide whether automatic following should be disabled, and native mobile behavior is unchanged.
Recommendation. Keep open: decision needed. Decide the default-follow behavior and split the motion preference from unrelated layout changes.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Canonical current-head results are missing for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports conflicts with the target branch, so recorded checks do not validate a rebased integration.
Request. Clear stale split-view detail after a selected thread is archived, deleted, settled, or snoozed.
Audit finding. Current AdaptiveWorkspaceLayout keeps the selected route without observing shell lifecycle changes. The diff adds invalidation that preserves root overlays on iPad and wide Android. It still imports effectiveSettled and hard-codes a three-day client rule, but main removed that helper when PR #8600 moved settlement to the server, so this observer needs to use current lifecycle fields.
Recommendation. Keep open: work remains. Adapt the lifecycle observer to server-owned settlement before reviewing its navigation behavior.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Improve Live Activity layouts and preserve update ordering across devices.
Audit finding. Main still has the old Live Activity layout and no provider identity in activity rows. The actual diff goes beyond the body's styling summary: it adds provider identity through contracts, per-thread server work, and per-user relay locks. Those ordering changes overlap PR #4747 and need a separate review from the iPhone, iPad, and Watch layout changes. The outstanding ordering comment describes an older implementation; the current diff moves persistence inside the delivery locks.
Recommendation. Keep open: decision needed. Split or separately review the publish-ordering changes before accepting the Live Activity redesign.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Bound stale iOS Connecting Live Activities when no relay activity can update them.
Audit finding. The merged publishing-capability fix now prevents new placeholders for environments explicitly reporting publishing disabled. Older servers omit that capability, cached settings can be stale, and main still has no client reconcile deadline for an already armed card. The proposed cleanup also re-reads all activities after an asynchronous snapshot, so it can end a newer card instead of the original placeholder.
Recommendation. Keep open: partial fix. Retarget this PR to the remaining legacy or stale-capability case and bind cleanup to the captured activity identity.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Merged pr: PR #6325. Prevents the reported disabled-publisher seed but retains older-server behavior.
Comment: Discussion comment. Confirmed async identity race: cleanup ends all current cards rather than the captured placeholder.
Limits. Current-head required checks were not reported: Check, Mobile Native Static Analysis, Release Smoke, Test. GitHub reports merge conflicts with main on the collected head.
Request. Reserve the measured mobile composer height when a remote thread first opens.
Audit finding. Main now seeds an Android inset floor through merged PR #5585 and re-reports the overlay height after feed remounts. That covers part of the first-open race, while the proposed late-height correction remains different. The current correction calls scrollToEnd without honoring an active submission anchor, matching the unresolved review finding. The body also describes an in-flow status-pill change that the author says was reverted.
Recommendation. Keep open: partial fix. Make late-height correction preserve the active submission anchor, then retest thread-open sizing.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Comment: Discussion comment. The current diff still allows corrective end-scroll to override a send anchor.
Check: PR #4999. Current head 0a62ad93: required checks are absent from canonical latest-commit metadata: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts.
Merged pr: PR #5585. Addresses the part identified in this finding; merge commit f9a726e6231d was checked against repository release ancestry.
Limits. No current runtime reproduction of the late-height race. Required CI checks are not present on the current head in canonical check metadata. Release status refers to repository tag ancestry; mobile app-store and OTA rollout was not verified.
Request. Allow removal of a project whose only undeleted threads are archived.
Audit finding. Main still blocks plain project deletion whenever any undeleted thread exists, including archived threads hidden by the shell snapshot. The PR fixes the invariant and deliberately cascades deletion through archived threads, so it is not covered by recent thread settling work. Maintainers must confirm that the empty-project confirmation can delete archived history without a force warning.
Recommendation. Keep open: work remains. Choose explicit archived-history confirmation or approve the proposed archived-thread cascade.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Keep the mobile working timer advancing when the server clock is ahead.
Audit finding. The old timeline row was removed in merged PR #8793, but its replacement still returns 0s whenever nowMs is before startedAt. The defect remains in floating-working-control.tsx. The observation-time logic and tests need to move to that current component instead of restoring the deleted row.
Recommendation. Keep open: work remains. Port the clock-skew correction to FloatingWorkingControl.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Render agent image outputs and media paths across web and mobile on orchestration V2.
Audit finding. Main now renders workspace images and viewed-image work logs, and web video attachments already play. The reviewed PR still adds distinct V2 image items, saved preview screenshots, and new asset kinds on an unmerged orchestration base. The 835-file diff is not a small replacement for those landed image features.
Recommendation. Keep open: partial fix. Retarget the media slice after the V2 base decision and remove behavior already supplied by current main.
Confidence medium. Release: In nightly source. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author gabrielelpidio. Updated 2026-09-01T05:36:37Z. Draft no. Target t3code/codex-turn-mapping. Head 0387ef26cc477ec3a109e842701966d10a798ee0. Branch t3code/media-previews-v2. Size +157282 / -74510, 835 files, 225 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Commit: Commit ce71c04f0aa9. The viewed-image work-log feature is on main and a published nightly.
Limits. The 11,357,125-byte diff was not fully read. Review covered the named feature paths and current main, not every file or test. GitHub reports merge conflicts with the current base.
Request. Editor discovery should finish on slow Windows PATH scans and avoid repeating the scan on each connection.
Audit finding. Merged PRs #5561 and #5572 add bounded successful-result caching and prevent an interrupted caller from poisoning the cache. Main still probes editors sequentially and cancels a slow cold scan with its caller, so the PR's concurrent scan and completion after caller timeout remain unimplemented. Its permanent detached cache would also remove the current 60-second refresh policy.
Recommendation. Keep open: partial fix. Rework the concurrent cold scan to retain the current expiring cache and caller-interruption guarantees.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Show structured usage-limit stops instead of a silent or successful-looking finish.
Audit finding. Main still forwards raw rate-limit events without the proposed session state or composer strip. The inspected PR changes only the session projection, so durable turn settlement still treats ready plus usageLimit as completed while the in-memory reducer calls it interrupted. Its Codex normalizer also picks primary before secondary regardless of which window is exhausted. The newer snooze proposal does not replace the terminal-reason and stream-end handling here.
Recommendation. Keep open: work remains. Fix durable turn settlement and exhausted-window selection before combining the limit UI work.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. The durable-projection mismatch remains present in the inspected diff.
Limits. The 28-file diff was not fully reviewed. Adapter classification, shared limit normalization, and contract changes were inspected. Required checks have no results on this head: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Add full GitHub Enterprise discovery, repository operations, and client controls.
Audit finding. Main still exposes one GitHub discovery result and lacks the proposed enterprise-host selection flow. The selected diff confirms the open review concern that PR URL fallback claims any host with a /owner/repo/pull/number path, which can misroute non-GitHub links. Authenticated-host detection in another open PR is narrower than this connector and is not a landed replacement.
Recommendation. Keep open: work remains. Restrict PR-link interception using the known provider, then complete the enterprise multi-host review.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Selected CLI host-routing, repository guard, contract, and URL-parser changes were inspected. The full 39-file, 3,798-line diff was not fully read. The latest head has no results for the four currently required check names.
Request. Make the Files listing cap configurable to reduce materialized path memory in large workspaces.
Audit finding. Main still uses a fixed 25000-entry listing cap and fetches 25002 FFF results. The PR makes only list materialization configurable and retains the full native index, so it is an opt-in memory tradeoff rather than a general memory fix. Main now also uses WORKSPACE_INDEX_PAGE_SIZE for image-only search, so integration must preserve that separate search limit instead of removing the shared constant blindly.
Recommendation. Keep open: decision needed. Decide whether to expose the list cap, then preserve image-only search behavior when updating the patch.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. The reported RSS measurements were not repeated. Required checks absent from the canonical latest-commit rollup: Check, Test, Mobile Native Static Analysis, Release Smoke.
Request. Direct pairing and authenticated traffic should preserve a reverse proxy path prefix.
Audit finding. Main still replaces the URL pathname in environmentEndpointUrl and resets HTTP API bases to the origin root, and it has no pairing-base-url configuration. The PR addresses discovery, OAuth proofs, assets, and sockets, but also adds Matrix OS setup entry points and changes general external-link opening. A real trusted-proxy pass and a decision on the Matrix-specific UI remain necessary.
Recommendation. Keep open: work remains. Separate the generic path-prefix transport change from Matrix OS promotion and verify pairing through a real prefix-stripping proxy.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Add a separate experimental SwiftUI iOS client alongside React Native.
Audit finding. Pinned main has no apps/swift-ios client. This parent branch adds its own transport, authentication, widgets, share extension, terminal, and CI, and the author explicitly requires maintainer approval before merging. It is not an obsolete React Native fix and must be assessed as a separate client commitment.
Recommendation. Keep open: decision needed. Decide whether to accept the experimental client before integrating its dependent PRs.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Source: apps/swift-ios/README.md. The parent documents a standalone SwiftUI client with its own network and persistence stack.
Comment: Discussion comment. The latest correctness review was skipped because the full PR exceeded the review budget.
Check: GitHub check. Current head c49bcc5d: Test=SUCCESS, Check=SUCCESS, Mobile Native Static Analysis=SKIPPED, Release Smoke=SUCCESS. SwiftUI contract fixtures and native tests passed. GitHub reports merge conflicts.
Limits. The 4.97 MB, 193-file diff was not reviewed completely. The parent has hundreds of review threads and needs a separate focused audit. Only the parent PR comments and a sample of its 328 review threads were inspected. Mobile Native Static Analysis was skipped on the current head; no passing native static result is claimed.
Request. Keep the Android connection runtime and outbox alive through an opt-in foreground service.
Audit finding. Main can report app activity and reconnect after suspension, but it has no foreground service that owns the JavaScript connection runtime. The selected diff adds Headless JS ownership, persistent notification, boot recovery, and separate UI/background relay auth ownership. Resume recovery does not replace this feature, and the author explicitly did not test live T3 Connect operation.
Recommendation. Keep open: decision needed. Decide the Android background-service policy and require a live T3 Connect lifecycle pass before merge.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Merged pr: PR #4878. Improves recovery after suspension, not background runtime survival.
Check: GitHub check. Test passes on the current PR head. Passing checks do not establish merge safety.
Limits. Large 59-file diff. Reviewed Android manifest, headless task lifecycle, relay-auth ownership, and wakeups, but not every changed file. The author reports physical-device direct/Tailscale testing but no live T3 Connect validation. GitHub reports merge conflicts with main on the collected head.
Request. Add OpenAI or Groq voice dictation to the web and desktop composer through an authenticated server proxy.
Audit finding. Main has offline iPhone dictation, but no web transcription proxy or these BYOK settings, so that merge does not replace this scope. The full patch bounds uploads and fixed provider endpoints, but requests always use the primary environment instead of the active environment, and macOS signing adds a usage description without audio-input entitlements. The unresolved cancel-start finding matches the hook, and the previously named replacement is now closed rather than an active alternative.
Recommendation. Keep open: decision needed. Rework the feature around the current shared voice controller and environment-scoped authenticated requests before a product review.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. Canceling a pending microphone start leaves startingRef set until permission resolves.
Limits. No microphone, remote/relay, or signed desktop integration was run. The patch includes a continuously animated transcription spinner and a 20 Hz React waveform.
Request. Keep project choices identifiable by environment across mobile, web, and desktop.
Audit finding. Merged work now shows the remote environment for non-Git composers and labels the command-palette new-thread submenu. Root project search and the draft project menu still omit the environment, so those parts remain. Mobile has since replaced the old repository-group picker with project scopes, so its changes need to be ported rather than restored from this branch.
Recommendation. Keep open: partial fix. Keep the missing picker labels and port mobile behavior to the current project-scope flow.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Merged pr: PR #7392. Adds location labels only to the new-thread submenu.
Limits. Current unresolved review threads were checked, but the long prior discussion and resolved review history were not fully read. GitHub reports merge conflicts with main on the collected head.
Request. Convert HEIC and HEIF bytes before sending image attachments to Claude.
Audit finding. Merged web conversion now prepares HEIC files as JPEG, and the native iOS picker path recognizes its JPEG conversion instead of retaining HEIC metadata. The Claude adapter still rejects raw HEIC bytes, so existing or other-client attachments remain outside those fixes. This patch adds a server fallback, but non-macOS hosts require an external heif-convert executable and its real conversion tests skip without sips.
Recommendation. Keep open: partial fix. Reproduce a remaining raw-HEIC send on current clients before choosing a server transcoder dependency.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Resize native desktop titlebar overlays when renderer zoom changes.
Audit finding. Main still fixes overlay height at 40 pixels, so later zoom fixes do not address native-header scaling. Main now routes menu zoom through DesktopWindow.zoomMain and restores preview guest zoom, while this older patch replaces menu handlers and would miss that behavior if copied unchanged. The added global sidebar padding changes web and macOS as well as the affected desktop platforms.
Recommendation. Keep open: work remains. Add overlay-height synchronization to zoomMain and remove or justify the cross-client sidebar padding change.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. Zoom alignment was not tested on Windows or Linux desktop. Required checks absent from the canonical latest-commit rollup: Check, Test, Mobile Native Static Analysis, Release Smoke.
Request. Let each environment choose an installed shell for new and restarted terminals.
Audit finding. Main still chooses the shell from the process environment and has no terminalShell setting or installed-shell capability. The diff adds shared contracts and server behavior with a web settings picker, but offers only zsh, bash, and fish and no mobile picker. This is still a product feature, not work replaced by terminal performance fixes.
Recommendation. Keep open: decision needed. Decide the supported Windows shell choices and mobile settings scope before finishing the feature.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Pr: PR #9027. Terminal streaming changes are separate from shell selection.
Limits. The PR reports no manual settings pass or screenshots. Required CI has no result on the reviewed head: Test, Check, Mobile Native Static Analysis, Release Smoke.
Request. Recover remote lifecycle drift with explicit version, origin, pairing, and protocol handling.
Audit finding. Main service reconciliation still installs the invoking CLI version without downgrade refusal, and cloud startup does not have the proposed origin-reconcile endpoint for non-CLI links. The selected diff adds those behaviors plus RPC-schema blocking and environment lifecycle locks. Existing update-reconnect work does not cover this full scope, and the combined change is too broad for a merge-safety conclusion from this review. The protocol-schema-to-blocked guard remains absent. Bootstrap now receives a config stream snapshot, not a cached unary getConfig response.
Recommendation. Keep open: work remains. Split downgrade protection, managed-origin repair, and protocol blocking into reviewable changes. Apply the schema guard to the new initial snapshot/source failure path and keep the probe guards.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Latest main change. The protocol-schema-to-blocked guard remains absent. Bootstrap now receives a config stream snapshot, not a cached unary getConfig response. Apply the schema guard to the new initial snapshot/source failure path and keep the probe guards.
Limits. Large 42-file diff. Reviewed service downgrade policy, origin reconciliation, and RPC schema handling, but not every changed file. The later config-stream merge requires porting the protocol guard to the owned snapshot path. Current unresolved review threads were checked, but the long prior discussion and resolved review history were not fully read. GitHub reports merge conflicts with main on the collected head.
Request. Provision an empty Vitess relay database while the existing worker continues to use Postgres.
Audit finding. Pinned main provisions only the Postgres database and points Hyperdrive at its runtime role. The reviewed resource and SQL changes add a second production database but do not move runtime traffic. Provisioning is a prerequisite of the separate cutover and needs an explicit migration plan, not a claim that the migration already landed.
Recommendation. Keep open: decision needed. Confirm the migration owner and approved provisioning sequence before scheduling this infrastructure change.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Pr: PR #5306. The separate cutover depends on this provisioning stage.
Check: GitHub check. Test passes on the current PR head. Passing checks do not establish merge safety.
Limits. The resource definition and baseline SQL were reviewed, but the generated schema snapshot was not reviewed line by line. No live infrastructure or replication state was inspected.
Request. Move relay persistence and Hyperdrive from Postgres to Vitess after data replication.
Audit finding. Main still uses Drizzle.Postgres and PostgreSQL schema definitions. The selected diff switches the runtime and Hyperdrive origin, replaces row-returning writes with MySQL affected-row checks, and retains Postgres for rollback. The PR explicitly forbids cutover until replication has completed and stopped, and the available source cannot establish that operational prerequisite.
Recommendation. Keep open: decision needed. Record replication completion and stop evidence before scheduling the cutover review.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author juliusmarminge. Updated 2026-08-04T10:58:59Z. Draft no. Target relay/provision-vitess-db. Head 34edc0817831607cd66133dd89183a2a90e7bcd8. Branch relay/vitess-cutover. Size +631 / -286, 28 files, 3 commits. Mergeability MERGEABLE. Merge state CLEAN. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #5305. Unlanded provisioning prerequisite for the Vitess target.
Check: GitHub check. Test passes on the current PR head. Passing checks do not establish merge safety.
Limits. Large 28-file diff. Reviewed database resources, MySQL runtime driver, and write-result handling, but not every changed file. No live database, data parity, replication, or rollback rehearsal evidence was inspected.
Request. Allow microphone use by tools launched from the signed macOS desktop app.
Audit finding. Main still lacks the audio-input entitlement. The PR adds it, but unresolved review findings match the diff: there is no microphone usage description, and helpers inherit the complete passkey plist despite the documented minimal-helper policy. The current custom signing script forwards those options, so this needs a signing change and packaged verification, not only configuration assertions.
Recommendation. Keep open: work remains. Add the microphone usage description and minimal helper entitlements, then verify a signed macOS microphone request.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. No signed macOS bundle or permission prompt was tested. Required checks absent from the canonical latest-commit rollup: Check, Test, Mobile Native Static Analysis, Release Smoke.
Request. Discover Codex skills for the selected project or worktree instead of the server launch directory.
Audit finding. Current skills are still discovered at the server cwd, so workspace-scoped discovery remains needed. The PR adds the server-resolved query but hides its loading state when fallback skills exist and removes repo skills from snapshots still used by timeline chips. Native mobile does not use the new query, so the proposal needs completion across consumers.
Recommendation. Keep open: work remains. Fix loading and timeline skill consumers and add native mobile workspace discovery before review.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Check: GitHub check. Latest head required checks: Test success, Check success, Mobile Native Static Analysis success, Release Smoke success.
Comment: Discussion comment. Discussion evidence checked against the submitted source change.
Limits. RPC, provider and query changes were inspected, but the full 17-file diff was not reviewed. GitHub reports a conflict with main. Any passing checks apply to the existing head, not a rebased result.
Request. Add a separate chat-header action to open the project directory in an external terminal application.
Audit finding. Main has editor launching but no external-terminal definitions or separate terminal picker. The PR reuses the editor RPC, adds terminal-specific directory arguments, and keeps a separate preferred terminal. That RPC launches on the environment host, so remote headless hosts and WSL need an explicit behavior decision rather than assuming the external window belongs to the client machine.
Recommendation. Keep open: decision needed. Decide whether the terminal action launches on the environment host or opens a local SSH terminal for remote projects.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Batch shared thread-state publications during live synchronization.
Audit finding. Main still runs applyItem once for every stream item. Server tool-update coalescing does not batch all client publications, and the merged turn-window work added history epochs and locking that this older diff must preserve. The larger busy-thread PR overlaps this change but is not a landed replacement.
Recommendation. Keep open: work remains. Choose one batching implementation with the busy-thread PR and preserve current turn-window synchronization.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Open matching chat links in the desktop browser using user-defined site patterns.
Audit finding. Main has browser defaults and a manual preview context-menu action, but no site-pattern routing setting. The full PR adds pattern parsing, settings, reset, search, and normal-click routing. Current chat links also open project pull requests in a dedicated panel, so routing precedence and settings placement need a product decision.
Recommendation. Keep open: decision needed. Choose the precedence between site patterns and the existing pull-request panel before updating the patch.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Limits. The collected latest head has no results for these required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports merge conflicts with the current base.
Request. Guide first-run connection, provider setup and import of resumable Codex and Claude history.
Audit finding. Main still lands in a draft or Add project screen and does not have this welcome/import workflow. The reviewed gate code can render the app after four seconds while its first-run decision remains pending, and new current-head review findings still need resolution. The author explicitly limits this PR to first-run import, excluding later import entry points, external-turn refresh and safe handoff. Its 75-file implementation has not received a complete independent review in this audit. Config sharing does not provide session-scoped welcome/ready events or the onboarding feature.
Recommendation. Keep open: work remains. Complete current-head review of the first-run gate, provider setup environment and import retries before a merge decision.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Latest main change. Config sharing does not provide session-scoped welcome/ready events or the onboarding feature. Keep the scope review and retain config dispatch in the proposed generic stream mapper.
Limits. The full 75-file, 487 KB diff was not reviewed. Current open findings and issue comments were read, but the full 130-thread review history was not reviewed. Native macOS desktop and mobile behavior were not exercised in this audit. Required check did not execute on the recorded head: Mobile Native Static Analysis. GitHub reports conflicts with the target branch, so recorded checks do not validate a rebased integration. An older related reference could not be retrieved from GitHub. It is excluded from verified dependencies and fix evidence.
Request. Refine the first-run connection and project-import menus.
Audit finding. This PR targets the still-open onboarding branch, not main. Its collected 17-file diff contains an older complete wizard and scanner, while the parent now has a different row-based wizard and newer import behavior. That comparison does not isolate the intended four styling changes, so neither a fixed/obsolete closure nor a merge recommendation is supported.
Recommendation. Keep open: evidence needed. Rebase onto the latest onboarding head and provide only the remaining menu-style changes.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author t3-code. Updated 2026-09-01T11:16:14Z. Draft no. Target t3code/overhaul-onboarding-flow. Head 05f1086a72a3884afffe53d6ff681b72b378db19. Branch t3bot/onboarding-menu-ui. Size +2227 / -9, 17 files, 12 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Checks. Required: Test: not captured, Check: not captured, Mobile Native Static Analysis: not captured, Release Smoke: not captured. Observed: 5 passed, 1 failed, 0 pending, 5 skipped. Checks captured 2026-09-01T11:49:21.071972+00:00.
Reviews. GitHub review decision UNKNOWN. Current-head approvals 0. Current-head change requests 0. Unresolved review threads 11. Counts do not replace review of the findings.
Evidence read. body yes, discussion no, full diff no, current source yes, history yes.
Pr: PR #5362. The active, unmerged onboarding parent has changed substantially.
Limits. The full 17-file cumulative onboarding diff was not reviewed. Open review findings were read, but older resolved review threads were not fully reviewed. Canonical current-head results are missing for required checks: Test, Check, Mobile Native Static Analysis, Release Smoke. GitHub reports conflicts with the target branch, so recorded checks do not validate a rebased integration.
Request. Moves automatic settlement to the server and changes pinned-thread and closed-PR settlement rules.
Audit finding. The merged server-side implementation already covers persisted settlement, shared defaults, and server-owned settings across clients. This PR still changes behavior that main keeps: pins ignore inactivity, closed PRs do not settle immediately, and live PR checks wait for a foreground lease. Its current head also maps a verified no-PR result to unknown, so branched threads without a PR never reach inactivity settlement. Those distinct rules and current-head defects prevent a closure or merge recommendation.
Recommendation. Keep open: partial fix. Decide the pinned and closed-PR rules, then retain only the approved policy changes on current main.
Confidence high. Release: Main only. PR readiness: Needs work or a decision.
Merged pr: PR #8600. Merged server-owned settlement covers the core architecture and both settings. It is not yet in the audited stable or nightly release.
Limits. Read-only review. No local tests or client runtime checks were run. Current-head checks are green, but the branch conflicts with current main and has no approving review decision. Mobile store and OTA publication were not checked. Source ancestry is not proof of mobile delivery. GitHub reports conflicts with the target branch, so recorded checks do not validate a rebased integration.
Request. Preserve each thread pull request across branch changes and prevent mixed-checkout status updates.
Audit finding. Main now preserves explicitly linked PRs and terminal PR badges through merged PRs 8160 and 4755. Unlinked mobile threads still lose the PR when the checkout differs, and the broadcaster still keeps the prior remote half when local refName changes. The selected PR code also retains a reviewed race that can combine the new local ref with an old in-flight remote result.
Recommendation. Keep open: partial fix. Fix the refreshStatusCore race, then rebase branch-keyed lookup around the landed linked-PR behavior.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Recover provider conversations whose stored resume history or working directory is missing.
Audit finding. Main now recreates missing branch-backed worktrees, reducing one cause of failed resumes. It still lacks Claude transcript relocation, ACP load fallback, and user-visible warnings when Codex or OpenCode starts fresh. The PR resets ACP history for most load failures and conflicts with the account-switch PR policy of surfacing resume failures, so recovery behavior needs an explicit decision.
Recommendation. Keep open: partial fix. Agree when lost provider context may start fresh before integrating the recovery paths.
Confidence high. Release: In stable source. PR readiness: Needs work or a decision.
Request. Resolve Cursor approval and question callbacks before finishing their turn.
Audit finding. Main still completes the last Cursor prompt without waiting for pending approval and question callbacks. The PR adds callback admission and settlement barriers, but its exact head still sends turn.started and acp.prompt after asynchronous preparation without rechecking the captured generation. The resolved review reply claims that check was added, but the fetched head source does not contain it. The original fix remains needed and the pre-dispatch interrupt race still needs correction.
Recommendation. Keep open: work remains. Guard prompt dispatch with the captured generation and test interruption during asynchronous preparation.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Request. Keep Claude child output on its child thread after the parent completes and omit empty child prompts.
Audit finding. This PR targets the open orchestration V2 branch, not main. Main has the older adapter, while this branch changes session-wide child routing, continuation handling, and prompt projection across four adapters. The collected diff includes 889 files from the V2 stack, so its full behavior is not established by this review.
Recommendation. Keep open: decision needed. Review the child-routing commits against the V2 branch after its routing model is settled.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author mwolson. Updated 2026-09-01T05:36:37Z. Draft no. Target t3code/codex-turn-mapping. Head ed223fe063182cd1e30b1172842fdafcec7f4a17. Branch fix/claude-subagent-empty-prompt-message. Size +186800 / -85511, 889 files, 244 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #2829. The target orchestration V2 work is still open.
Limits. The full 13 MB stacked diff was not reviewed. Child attribution was not reproduced against the V2 runtime. GitHub reports merge conflicts against the target branch.
Audit finding. This is V2-specific work on the open orchestrator branch, not a landed repair for main. The inspected delta adds terminal-result handoff detection, compensation before dead-lettering start effects, and timestamp-guarded settlement updates, alongside several client changes. Main now has its own server settlement and error-dismiss fixes, but those do not establish that this V2 rewrite handles the same cases. Even after removing inherited history, this branch adds about 6940 lines across 72 files.
Recommendation. Keep open: work remains. Split the steering, dead-letter recovery, and client settlement changes and restack them on current V2.
Confidence medium. Release: Not applicable. PR readiness: Needs work or a decision.
Observed GitHub metadata. GitHub state OPEN. Author mwolson. Updated 2026-09-01T05:36:37Z. Draft no. Target t3code/codex-turn-mapping. Head ae2165482ce5a3e203700ffe3fc7c6a9c97f1108. Branch fix/orchestrator-settled-lifecycle. Size +187954 / -85546, 898 files, 262 commits. Mergeability CONFLICTING. Merge state DIRTY. Target is not main. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.
Pr: PR #2829. Changes depend on the unmerged V2 runtime.
Limits. Only selected runtime and client changes were reviewed from the 294183-line submitted diff. The 41 review threads were not fully reviewed. No V2 steering or failure-recovery test was run. Latest-head required checks are not passing: Check. Failure logs were not investigated in this audit.
Request. Switch an existing T3 Connect environment to a verified direct endpoint and fall back to the relay when it fails.
Audit finding. Main has no automatic direct-route discovery for RelayConnectionTarget. The selected diff adds promotion and fallback, but stores only one failed-endpoint cooldown per environment, so a second failed route erases the first route's cooldown. That confirmed review finding and the missing real relay promotion test keep this from merge readiness.
Recommendation. Keep open: work remains. Retain cooldowns per endpoint, then verify relay-to-direct promotion and fallback.
Confidence high. Release: Not applicable. PR readiness: Needs work or a decision.
Comment: Discussion comment. Confirmed: the cooldown map stores a single PromotionCooldown per environment.
Limits. Large 23-file diff. Reviewed promotion selection, cooldown state, direct authorization, and relay fallback, but not every changed file. The author explicitly reports no real relay-connected promotion verification. GitHub reports merge conflicts with main on the collected head.