pingdotgg/t3code. All authors. Drafts included. Default branch main. 570 issue assessments and 925 PR assessments. Initial inventory: 570 open issues and 924 open PRs. Current assessed open inventory: 570 issues and 924 PRs. Final reconciliation: 2026-09-01T11:57:41.491617+00:00.
Request. Threads with open PRs or live background work can settle when a foreground turn finishes.
Audit finding. The main-only server settlement change now blocks automatic settlement for open PRs and working or monitoring background liveness. The canonical discussion also requires manual settlement to block that background work, but the engine guard applies only to thread.auto-settle. That requirement conflicts with the earlier merged design in which explicit settle stops background sessions, so a maintainer decision is still needed.
Recommendation. Keep open: partial fix. Decide whether explicit settle may stop live background work, then retest the separate open-PR association case.
Request. Checkpoint restore hides the cause of intermittent Git exit-128 failures.
Audit finding. Restore still runs git restore, clean, and reset against the real index with no operation-specific failure explanation. VcsProcess reduces unknown stderr to a generic nonzero-status error, so index-lock failures remain opaque. The report explicitly says lock contention is only a hypothesis for the natural failures, and no later fix proves that cause.
Recommendation. Keep open: work remains. Expose a bounded restore failure reason before diagnosing or retrying the intermittent exit-128 case.
Request. Threads sharing one worktree can show different saved branches without a mismatch warning.
Audit finding. The web mismatch helper still returns null for every worktree-backed thread. Server branch-drift handling deliberately skips a worktree shared by another thread, and a focused test preserves that behavior. Shared threads therefore retain the exact unprotected saved-branch mismatch in the report.
Recommendation. Keep open: work remains. Add shared-worktree mismatch protection without switching the shared checkout automatically.
Request. Whitespace-distinct filenames collapse to duplicate paths and break the Files tree.
Audit finding. The index deduplicates raw path strings before contract encoding trims them. FileBrowserPanel still sends the resulting paths directly to resetPaths without a second uniqueness check. The focused normalization fix remains open, so two legal POSIX names can still reach the tree as one duplicate path.
Recommendation. Keep open: work remains. Make path normalization and deduplication agree before entries cross the wire.
Request. Reverting one thread restores the whole shared checkout and deletes other threads' untracked work.
Audit finding. The checkpoint restore still uses a dot pathspec for git restore and git clean -fd. It has no per-thread changed-path restriction or shared-checkout protection. The confirmation still describes only this thread, so both the destructive scope and the misleading warning remain.
Recommendation. Keep open: work remains. Protect unrelated shared-checkout changes before allowing a thread checkpoint restore.
Request. A new release PR is shown on every historical thread using the same long-lived branch.
Audit finding. Explicit PR links now exist, and server-side settlement keeps already settled threads in their saved state. Threads without an explicit link still resolve PRs from their saved branch and can receive the same new release PR badge. This removes the client-derived wake-up mechanism but not the unrelated branch-based association.
Recommendation. Keep open: partial fix. Keep unrelated historical threads out of the release PR association instead of using branch equality alone.
Request. Parent delegation can trigger a completion alert and unread state while subagents still run.
Audit finding. The shared awareness state only reads parent session, latest turn, and pending user actions, with no subagent activity input. A ready or idle parent is classified as completed, and Claude completeTurn does not wait for liveTaskIds to empty. The Agents panel can show live children independently, but that does not make notification and unread decisions wait for the same logical run.
Recommendation. Keep open: work remains. Include active child work in shared completion and attention decisions across all clients.
Request. Launching the Windows desktop during an incomplete update can load missing dependencies and crash.
Audit finding. Windows packaging now keeps far fewer files outside archives, which reduces the long extraction window. Main startup still imports its dependencies without an install-in-progress or integrity guard, and the NSIS config does not add one. The discussion also reports a permanently interrupted install and a stale taskbar target, which faster extraction alone cannot repair.
Recommendation. Keep open: partial fix. Add an early incomplete-install guard and a recovery path before desktop dependencies load.
Request. Embedded browser tabs and their active order disappear when the desktop restarts.
Audit finding. The server preview manager initializes an empty in-memory session map. Client tab selection and recently seen URLs also live in keep-alive atoms, without durable storage. Browser rendering and duplicate-update fixes do not restore that state after a process restart.
Recommendation. Keep open: work remains. Persist preview URLs, tab order, and active tab as they change, then restore them on restart.
Request. Claude thinking text is not persisted or rendered even when the CLI emits nonempty thinking deltas.
Audit finding. Thinking blocks still do not create an item, so their reasoning deltas can lack itemId. More broadly, ingestion now returns immediately for all non-assistant_text deltas, and an existing test requires reasoning_text to be ignored. The SDK options also do not request summarized thinking, so fixing the item ID alone cannot satisfy the report.
Recommendation. Keep open: work remains. Review #8628 with a persisted, reloadable Claude thinking response in both web and mobile clients.
Request. Every thread shares one remembered right-panel width.
Audit finding. PreviewPanelShell still defaults to the browser-wide t3code:preview-panel-width key. Width overrides separate the pull-request page from chat, but the chat right panel does not supply a scoped thread key. The resize-limit fix preserves the sibling chat column, not each thread's saved width.
Recommendation. Keep open: work remains. Persist chat right-panel width under the scoped thread identity.
Request. A desktop with no visible projects shows an unhelpful Not Found page.
Audit finding. The screenshot shows an empty project list and the router fallback, but it does not identify the requested route, deleted resource, or app version. The current router still has no custom not-found component, while missing thread routes have their own redirect path. The evidence does not establish that a missing repository is the actual trigger.
Recommendation. Keep open: evidence needed. Request the URL or route and exact steps that lead from a removed project to the fallback page.
Request. Tools from a slow plugin MCP server can be missing from a Claude chat session after the server connects.
Audit finding. The lockfile still resolves Claude Agent SDK 0.3.170, and the adapter creates one query with the supplied environment and MCP configuration. It does not add the proposed connection-wait setting or a plugin refresh after a late connection. Those source facts leave the report open, but they do not prove the suggested frozen-manifest cause inside the SDK.
Recommendation. Keep open: work remains. Add a controlled delayed-MCP-server reproduction that checks tool availability after connection in the same query.
Request. Headless link provisioning retries a permanent relay 403 for ten minutes and reports only pending startup.
Audit finding. relayClientRequest still turns every non-success response into EnvironmentHttpInternalServerError without decoding the relay error body. Startup excludes only bad-request, unauthorized, and conflict errors from its ten-minute retry schedule. CLI status has no last-failure field, so the reported silent permanent-denial path remains.
Recommendation. Keep open: work remains. Decode permanent link errors, stop their retries, and expose the last provisioning failure in connect status.
Request. Worktree removal times out on dependency-heavy directories and has no durable cleanup retry.
Audit finding. removeWorktree still uses a fixed 15-second timeout and returns a generic failure without storing a retry. The reporter clarifies that durable recovery of failed and already stranded directories is the main request, not only a larger timeout. The merged missing-directory fix does not help a directory that still exists, and the worktree-add timeout is a different operation.
Recommendation. Keep open: work remains. Design retryable worktree removal that records unfinished cleanup and can discover earlier stranded directories.
Request. Enabled Claude plugin skills are absent from composer discovery, especially for project-only plugins.
Audit finding.#5488 added .agents/skills but discoverClaudeSkills still scans only user and workspace directories, not enabled plugin caches. ClaudeDriver also uses the server startup directory for SDK command discovery, so project enabledPlugins settings can be missed independently. #6453 is still open and a plugin-root change alone would not cover that second directory boundary.
Recommendation. Keep open: work remains. Complete plugin discovery with a project-scoped test for both the skill picker and slash menu.
Request. Large prompts make web composer editing and selection slow.
Audit finding. The composer still reads the full editor text and walks selection and terminal-context state for each change. The focused prompt-parser cache proposal is open, with no equivalent landed cache identified in this path. The report needs a current large-prompt measurement, but source does not support closing it as fixed.
Recommendation. Keep open: work remains. Verify the prompt-parser cache change with a large-prompt typing and selection trace.
Request. One-click Codex updates assume an unclassified bare-name installation is npm-managed.
Audit finding. CodexDriver still sets nativeUpdate to null. The maintenance resolver still falls back to npm for a bare binary name after failing to classify its resolved path, so it can update a different installation. The npm install-script fix does not add standalone detection or change this fallback.
Recommendation. Keep open: work remains. Finish the installation-aware update change, including standalone and unknown-install cases.
Request. The Android client cannot pair to a server whose CA is installed in the user certificate store.
Audit finding. Android configuration still only enables cleartext traffic. There is no network security configuration adding user trust anchors in the app config or its networking plugin. Cleartext permission does not change HTTPS certificate trust, so it cannot fix this private-CA pairing failure.
Recommendation. Keep open: work remains. Add an explicit Android user-CA trust policy and verify HTTPS and WSS pairing with a private root.
Request. The Appearance monospace picker synchronously checks the full installed-font catalog.
Audit finding. FontFamilyPicker still filters every enumerated family with isMonospaceFamily during memo computation. Already granted font access also triggers discovery at mount, which matches the later Electron report with more than 2,000 families. The selected-family validation fix remains open.
Recommendation. Keep open: work remains. Replace catalog filtering with bounded validation of the selected family.
Request. Vercel passkey sign-in does not show the macOS fingerprint prompt in the preview browser.
Audit finding. The OAuth popup fix is in stable v0.0.37, but allowing a popup is not the same as supporting a site passkey prompt. The native Clerk passkey bridge belongs to the T3 sign-in preload, not arbitrary preview pages. There is no current Vercel passkey result, so the missing fingerprint prompt cannot be closed as fixed by popup support.
Recommendation. Keep open: retest. Retest Vercel passkey sign-in on current macOS desktop and capture the WebAuthn error or missing prompt state.
Request. Repeated Codex child progress snapshots create durable work that delays unrelated threads.
Audit finding. Every child item and cumulative usage notification still becomes task.progress. Runtime ingestion still converts each snapshot into thread.activity.append, even when the stable activity ID replaces an existing projection row. The recent message and query optimizations reduce other work but do not coalesce this event stream before ingestion.
Recommendation. Keep open: work remains. Finish pre-ingestion child-progress coalescing and verify that an unrelated reply does not wait behind a progress burst.
Request. Reverting a user message leaves it in the live timeline and does not return it to the composer.
Audit finding. The client reducer still retains every message with a null turn ID, which includes the unbound user-message path described in the report. The revert handler sends only a checkpoint count and never restores message text or attachments to the composer. The proposed edit-and-retry fix was closed without merging.
Recommendation. Keep open: work remains. Align live message truncation with the server and restore the selected prompt to an editable draft after a successful revert.
Request. Editing, clearing, or deleting a project action leaves stale keybindings.
Audit finding. The action save path only upserts a nonempty keybinding on Electron. A cleared binding falls through without a remove operation, and deleting an action does not remove its generated command bindings. The open cleanup proposal has not changed that path.
Recommendation. Keep open: work remains. Replace all bindings for the action command on edit and remove them on clear or delete.
Request. Opening a Markdown file can fail to load the file-preview JavaScript chunk.
Audit finding. The attachment shows Failed to fetch dynamically imported module for FilePreviewPanel, not a native crash or a Markdown parsing stack. ChatView still loads that panel through a lazy import. The report has no failed asset response, install-integrity result, or current reproduction, so a content-rendering fix cannot be inferred.
Recommendation. Keep open: evidence needed. Collect the failed chunk response and build version during a repeat file-preview failure.
Request. Ctrl+A and Ctrl+E do not move the cursor in the integrated terminal for the reporter.
Audit finding. A direct check of the pinned Ghostty WASM with current key mapping produced the expected bytes 1 and 5 for Ctrl+A and Ctrl+E. The normal terminal shortcut code also does not intercept those letter chords. The open fix is not evidence that the reported browser, keybinding, or shell path works, and the report gives no exact build or shell configuration.
Recommendation. Keep open: evidence needed. Capture the PTY bytes and active keyboard protocol for Ctrl+A and Ctrl+E on an affected current client.
Source: apps/web/src/keybindings.ts:508. The explicit terminal navigation helper handles arrow-key chords, not Ctrl+A or Ctrl+E.
Pr: PR #7222. The proposed Ctrl+A and Ctrl+E change remains open.
Limits. The direct WASM check did not exercise browser key delivery or a shell. Exact build, shell, and keyboard configuration are absent from the report.
Audit finding. Each visible row with branch or worktree data still mounts vcsEnvironment.status without checking whether a VCS panel is open. The shared atom family can deduplicate identical environment/cwd requests, but rows for different worktrees still create live subscriptions. Deferred pull-request line statistics do not remove these status consumers.
Recommendation. Keep open: work remains. Suspend passive-row VCS status work unless visible status or an active VCS control needs it.
Request. The fourth managed environment hits an undisclosed quota and the headless client hides its reason.
Audit finding. The relay still defaults to three managed tunnels and returns a typed limit error with maxTunnels. The headless provisioning client discards that body and retries it as an internal error, while connect status still reports pending startup. Current environment removal helps free a slot, but it does not provide the requested quota display or accurate CLI failure.
Recommendation. Keep open: work remains. Expose the managed tunnel limit and preserve its typed denial through the headless status path.
Request. Windows WSL commit actions miss the WSL SSH agent socket required for signed commits.
Audit finding. The WSL preflight captures Node and PATH but not SSH_AUTH_SOCK. The server launch then uses wsl.exe --exec env with the reconstructed PATH, so it does not run the login shell that defines the socket. The contributor fix is only on an external branch, and generic Git errors still hide signing failures.
Recommendation. Keep open: work remains. Capture a valid WSL login-shell SSH_AUTH_SOCK during preflight and pass it to the backend launch.
Request. Android shell and thread data stay stale across a remote connection interruption until the app restarts.
Audit finding. The shared shell loader refreshes the authoritative snapshot when it gets a new RPC session, but a transport-failed durable stream still drains while a surviving session remains unchanged. This preserves the reported pattern of successful unary RPCs and fresh detail subscriptions beside a frozen list. The existing snapshot refresh and reconnect improvements do not cover that surviving-session failure. The new replay is config replay, not thread-list or thread-detail recovery. It adds no mobile shell catch-up or replacement for a dead non-config stream.
Recommendation. Keep open: work remains. Verify Android shell recovery when a subscription fails but the RPC session stays connected.
Latest main change. The new replay is config replay, not thread-list or thread-detail recovery. It adds no mobile shell catch-up or replacement for a dead non-config stream. Keep the existing disposition and mobile shell/thread reproduction requirement.
Limits. No current Android high-latency reproduction was run.
Request. Native clients time out on environment discovery after a host restart even after a clean relink.
Audit finding. The report reaches four registered Cloudflare connections but times out before descriptor discovery, which is a different stage from credential refresh. Startup reconciliation and update retry fixes do not prove that the public descriptor route became reachable in this case. Current runtime status still treats a live connector process as running, so that status alone cannot establish end-to-end health.
Recommendation. Keep open: evidence needed. Collect the current public descriptor response and matching relay trace during one failed native connection.
Request. SSH reconnect can launch a competing managed backend against a running external service home.
Audit finding. The launcher still clears external ownership when its short readiness check fails, then chooses another port and starts a server with the same default home. It also retains the fallback that can select the default runtime PID for shutdown. The proposed ownership fix was closed without merging, and increasing only cold-start time did not change these branches.
Recommendation. Keep open: work remains. Preserve live external ownership across readiness failures and refuse a second server for that home.
Request. Server updates and lost provider processes can leave durable work marked running or starting.
Audit finding. Merged PR 7719 reconciles orphaned active sessions before startup accepts commands, including starting sessions and stale activeTurnId values. That is a startup pass, not the requested runtime missing-session monitor with a startup grace period. The self-update handoff still has no last-moment active-work check in its download-to-requestUpdate path, so the full recovery and update-safety contract is not implemented.
Recommendation. Keep open: partial fix. Add the runtime missing-session recovery and final active-work check before update handoff.
Request. Repeated Codex collaboration waits with no receivers can keep a live turn running forever.
Audit finding. The Codex runtime records receiver-to-parent relationships, but an empty receiver list simply performs no updates. There is no repeated-empty-wait guard in the current collaboration event path. Startup orphan recovery does not help because this report explicitly has a live provider process, and the linked implementation PR was closed without merging.
Recommendation. Keep open: work remains. Add a Codex-only repeated-empty-wait guard with a fixture that preserves legitimate waits on live agents.
Request. OpenCode todowrite output never updates the structured task sidebar.
Audit finding. The adapter still classifies todowrite as file_change because its name contains write. Its tool handler emits only item lifecycle events and has no turn.plan.updated path. The recent OpenCode lifecycle changes leave this task mapping absent.
Recommendation. Keep open: work remains. Map OpenCode todowrite items to turn.plan.updated with their content and status.
Request. Browser automation removes focus from the human composer, including in another thread.
Audit finding. The current keyboard path explicitly focuses the guest and later calls focus on the prior WebContents, without restoring its active DOM element. Comments confirm that current users also lose composer focus during other preview interactions. The pending focus-restoration and keyboard-isolation work is not landed, and this remains separate from keys being delivered to the wrong input.
Recommendation. Keep open: work remains. Preserve the focused composer element across automation in both the current thread and a background thread.
Request. Agents totals include each Codex child's inherited cumulative token history.
Audit finding. CodexAdapter still copies tokenUsage.total into task.progress without a starting baseline. This preserves the exact accounting path identified in the issue and its later reproduction. The merged rollout-history fix changes Usage analytics, not live Agents totals.
Recommendation. Keep open: work remains. Normalize live child usage against the inherited baseline, including resumed child turns.
Request. Usage summaries claim complete coverage when transcript directories or files could not be read.
Audit finding. The latest incremental-scan change leaves the completeness defect in place. Directory traversal still swallows errors, failed file reads become empty arrays, and each existing source still returns status ok with no diagnostic. Failed reads are retried rather than cached, but that behavior already existed and does not make the returned coverage accurate.
Recommendation. Keep open: work remains. Return scan completeness and bounded errors for unreadable roots, directories, and transcripts.
Request. The Usage page presents unknown model costs as zero instead of unavailable or partial.
Audit finding. The current Usage headline formats merged.costUsd directly, and provider and model rows do the same. The page exposes cache savings from costQuality but does not use its unpriced coverage to qualify those dollar amounts. The usage redesign therefore retains this defect, and the specific fix remains open.
Recommendation. Keep open: work remains. Apply unpriced and partial-cost labels to totals, charts, and breakdown rows.
Request. The Codex usage parser accepts per-event counters that conflict with cumulative totals.
Audit finding. parseCodexLine still reads last_token_usage and deduplicates only the immediately preceding JSON signature. It never validates that the cumulative counter advanced or agrees with that event. Incremental transcript scanning preserves this parser state but does not add the requested reconciliation or malformed-counter reporting.
Recommendation. Keep open: work remains. Finish cumulative-counter reconciliation and carry rejected-record counts through the scan cache.
Request. Usage misses custom provider-instance homes and the process-level Codex home.
Audit finding. resolveTranscriptDirs still reads the legacy providers.codex and providers.claudeAgent settings, not providerInstances. CodexHomeLayout still defaults to the OS home when that legacy homePath is empty. The new incremental scan does not change which roots are found, so the Codex and Claude cases in the discussion remain open.
Recommendation. Keep open: work remains. Use the effective homes of all enabled provider instances and deduplicate their physical transcript roots.
Request. New Codex SQLite files or sidecars can disable shadow-home providers.
Audit finding. Shadow-home materialization still adds unclassified shared entries and rejects regular shadow entries where it wants a symlink. Only the MCP OAuth lock directory has a replaceable-runtime exception. The discussion's regular WAL/SHM files beside a symlinked database are also not reconciled.
Recommendation. Keep open: work remains. Finish SQLite-family ownership handling and cover sidecar-only divergence without deleting user data.
Request. The experimental SwiftUI client fails to pair with a cleartext Tailscale IP address.
Audit finding. This report targets the still-open experimental SwiftUI branch, not the shipped React Native client on main. Its current Info.plist still has only local-network and ts.net ATS allowances, matching the reported configuration. No landed main change or tested native exception policy establishes support for the reported IP-literal path.
Recommendation. Keep open: work remains. Resolve and test the raw Tailscale-IP ATS policy in the experimental SwiftUI pull request.
Request. Mobile users can enter Plan mode but cannot find a visible control to leave it.
Audit finding. The native mobile command menu now exposes /plan and /default and routes them to the interaction-mode setter, matching the workaround confirmed in the discussion. ThreadSettingsSheet still has no interaction-mode row, so the requested visible escape from a plan-mode draft remains missing. A web-only Legacy setting is not a native mobile fix.
Recommendation. Keep open: partial fix. Add a visible Plan/Build selector to the native thread settings for existing threads and drafts.
Request. Desktop login-shell hydration omits Bitbucket credential variables and also affects shell-only GitHub tokens.
Audit finding. LOGIN_SHELL_ENV_NAMES still excludes all T3CODE_BITBUCKET variables, so Dock-launched desktop servers cannot receive those shell exports. The September 1 comment confirms the problem on stable, and the proposed Bitbucket forwarding change is still open. The added GH_TOKEN case has the same import gap but a separate credential-scope decision.
Recommendation. Keep open: work remains. Review login-shell Bitbucket credential forwarding and keep the GitHub-token scope decision explicit.
Request. Link favicons can send private development hosts to Google on web and mobile.
Audit finding. The preview favicon helper now rejects nonpublic hosts, and that correction is in v0.0.37. Web chat and native mobile Markdown still build the Google favicon URL directly from the link host without the same check. Desktop inherits the web-chat path, so the preview-only guard does not close the report.
Recommendation. Keep open: partial fix. Apply one shared public-host check to both Markdown favicon call sites.
Request. Background Grok health checks can open an interactive login browser without user action.
Audit finding. Grok is now opt-in and disabled instances skip probes after PR 7459, which removes this behavior for unused disabled providers. An enabled instance still starts ACP during health discovery and requests cached-token authentication without checking for saved credentials first. The comment that cites a fix in PR 7070 is not evidence that it landed, and the interactive-auth path remains in current source.
Recommendation. Keep open: partial fix. Make Grok health checks non-interactive and report missing authentication without starting ACP login.
Request. SSH setup stops at host-key verification instead of reaching password authentication.
Audit finding. The current SSH password retry classifier handles authentication failures but not host-key verification failures. A host-key failure must be resolved before a password challenge can work, and the report supplies no OS, version, alias, or trust-state evidence. This is not enough to identify a password-dialog regression or safely recommend bypassing host verification.
Recommendation. Keep open: evidence needed. Request the OS, app version, and redacted host-key error for the same SSH alias used by the app.
Request. JetBrains file links do not specify the thread's project root and can open in the wrong project window.
Audit finding. The launch contract still contains only the target cwd, editor, and reveal flag. JetBrains arguments add line and column to the file path but no project root. The focused cross-client launch-contract proposal remains open, so the intended worktree cannot be passed to the IDE.
Recommendation. Keep open: work remains. Carry the effective project root in the editor request and prepend it for JetBrains file launches.
Request. Windows port discovery repeatedly times out on a costly per-listener PowerShell process lookup.
Audit finding. PortScanner still runs Get-Process once for every listening socket and gives the command five seconds. A timeout falls back to common-port probes but does not add failure backoff, so retained discovery repeats the same command on the three-second schedule. The process-monitor and terminal-process polling fixes do not change this scanner.
Recommendation. Keep open: work remains. Finish the PortScanner fix with one process lookup and a timeout backoff.
Request. Opening or finishing a long web thread can leave the viewport above its latest content.
Audit finding. The current timeline uses initialScrollAtEnd and conditional end maintenance, and the merged follow-restoration fix re-enables follow when the user reaches the live edge. That covers one explicit part of the report. It does not prove late markdown/image sizing or thread-switch hydration settles at the bottom, and the full follow-latest-content fix remains open.
Recommendation. Keep open: partial fix. Test long-thread switching and late-sized content with the pending follow-latest fix.
Audit finding. Claude still wraps control failures as method failed and turns stream failures into a generic detail while preserving the real error only as a cause. Codex forwards stderr separately, but its process-exit error still contains only exit information and neither provider has the requested protected-folder permission hint. The Windows Auto-mode report is not proof of the same macOS cause.
Recommendation. Keep open: work remains. Add startup-exit diagnostics with a macOS protected-folder permission hint for Claude and Codex.
Request. Successful OpenCode Task child sessions do not appear in the Agents panel.
Audit finding. Task calls still become generic collab_agent_tool_call items, not task lifecycle events. The expanded child-session routing admits permission and question events only, so child lifecycle events still do not reach the Agents roster. Recursive child cancellation fixes stopping those sessions, not displaying them.
Recommendation. Keep open: work remains. Finish the task lifecycle mapping in PR #7393.
Request. Codex direct-child output can enter the parent chat while children are absent from Agents.
Audit finding. Receiver thread IDs still populate only the parent-turn map. Child registration still requires thread_spawn or subAgentActivity, while the fallback suppresses lifecycle notifications but not all child item and message output. The proposed direct-spawn fix was closed unmerged as already covered by native observability, but this source gap remains.
Recommendation. Keep open: work remains. Register receiver-only child threads and test child-first output without thread_spawn or subAgentActivity.
Request. Projects do not appear after creation, and new conversations remain stuck on the reporter's desktop install.
Audit finding. The duplicate-workspace error proves an earlier create reached the server even though the client did not show the project. The discussion says restart reveals the project but sending still hangs, while its logs only establish that the backend became ready. Current source prevents duplicate active roots, but there is not enough client subscription or provider evidence to explain the missing update.
Recommendation. Keep open: evidence needed. Capture a current create attempt with the client connection error and the server command receipt.
Request. Service installation fails on a host that has Node through pnpm but does not have npm.
Audit finding. Pinned runtime installation still invokes the literal npm command. It neither selects the invoking package manager nor reports a specific npm prerequisite before staging the runtime. The reported spawn npm ENOENT therefore still matches the current installer.
Recommendation. Keep open: work remains. Handle a missing npm executable before starting pinned-runtime installation.
Request. Linux remote updates can fail during node-pty compilation and hide the actionable npm error.
Audit finding. Pinned runtime installation still invokes npm and keeps only stdout and stderr lengths on a nonzero exit. The server package still depends on node-pty 1.1.0, while the bundled Linux prebuild path belongs to Windows desktop WSL packaging, not these npm-installed runtimes. An August 31 report confirms that a temporary-directory quota failure remains hidden behind the same generic update error.
Recommendation. Keep open: work remains. Return a bounded, sanitized native-install failure cause to the remote update client.
Request. Usage waits forever for an offline remembered environment and hides totals already received.
Audit finding. usageByWindowAtom still marks an environment failed only when its query returns Failure and ignores connection retry state. useUsage counts every missing summary without an error as still reporting, and UsagePage still hides the data while isPartial is true. The requested bounded wait remains absent despite newer usage rendering and query retry work.
Recommendation. Keep open: work remains. Implement the bounded-retry policy discussed in the issue so an unreachable environment stops blocking Usage.
Request. Fish waits ten seconds because the embedded terminal does not answer its device-attribute query.
Audit finding. The current web terminal is Ghostty, and its callback setup installs WRITE_PTY but no device-attributes callback. The comment points to a proposed fix, but that PR remains open. The old xterm startup-race explanation is not needed to establish the remaining Ghostty callback gap.
Recommendation. Keep open: work remains. Wire device-attribute responses in the web and Android terminal runtimes and verify fish startup.
Request. A Codex plugin-install request returns a pending confirmation but no client installation control appears.
Audit finding. Codex request mapping covers command, file, elicitation, input, and dynamic-tool requests but has no plugin-install confirmation request. Generated plugin install RPC types exist, yet no matching client confirmation card is wired to the reported tool result. A successful tool return with user_confirmed false is not a completed install.
Recommendation. Keep open: work remains. Wire the Codex plugin-install confirmation response to a visible client action.
Request. The Grok Build product slug is sent as an ACP model ID that the provider rejects.
Audit finding. The default model and empty-selection fallback still resolve to grok-build, and applyGrokAcpModelSelection sends the requested ID without a live-catalog alias. Successful discovery now prefers live models, but registry merging retains prior non-OpenCode models, including the initial Grok Build fallback. PR 8392 allows model changes in existing threads but does not fix the invalid ID.
Recommendation. Keep open: work remains. Finish PR 7819 using the current live Grok model catalog for the product-name alias.
Request. Explicit Codex skill tokens are sent as text instead of bound skill inputs.
Audit finding. buildTurnStartParams still creates text and image inputs only. It does not resolve explicit skill tokens or construct the schema's skill input, so a user-invoked-only skill can remain unavailable after discovery succeeds. The older focused binding PR was closed unmerged and the cross-provider replacement is still open.
Recommendation. Keep open: work remains. Finish send-time explicit skill binding against the active provider and workspace.
Request. The desktop terminal jumps to the live prompt while the user reads scrollback.
Audit finding. Ordinary Ghostty output preserves a scrolled viewport in a direct check, but a current client path still forces a reset. Once the client buffer reaches 512 KiB, new output trims its prefix, so ThreadTerminalDrawer calls resetAndWrite instead of appending. A scratch check using the real client reducer and pinned WASM reproduced the viewport returning to the live end on that capped-buffer update.
Recommendation. Keep open: work remains. Preserve the terminal viewport when retained client history loses its prefix.
Request. Desktop can start a second backend against the background service database after selecting another port.
Audit finding. DesktopApp still scans forward from the default port and starts its primary backend on the first free port. Backend configuration still uses the same environment.baseDir, with no matching live-owner check in this startup path. The earlier ownership changes were closed without merging, and the focused replacement is still open.
Recommendation. Keep open: work remains. Review the same-home port-fallback fix and prove that a running service prevents the second desktop backend.
Request. Provider self-updates cannot use a configured binary path when the executable is missing from PATH.
Audit finding. The maintenance resolver uses binaryPath to identify the installation method, but native update capabilities still use bare executable names such as opencode. The runner resolves that bare command again against the process PATH, so configuring an absolute runtime binary does not fix the update path. The discussion also reports missing gh under the same shell setup, which needs separate shell-environment validation.
Recommendation. Keep open: work remains. Carry the resolved native executable and instance environment into the update command in PR 6436.
Request. Claude revert changes visible history and files but leaves removed turns in provider context.
Audit finding. rollbackThread still truncates only the in-memory turns and calls updateResumeCursor without moving lastAssistantUuid to the retained turn. New query options pass resume but no resumeSessionAt boundary, and the existing test explicitly expects ordinary resume to omit that pin. The post-rollback resume fix remains open.
Recommendation. Keep open: work remains. Resume Claude at the retained assistant boundary after rollback and test the next prompt's context.
Request. An archived thread ID can remain in persisted draft state and block the next new thread.
Audit finding. The background-thread work added a promotedTo guard, so a draft recorded as promoted is no longer reused after its shell disappears. A persisted draft without that marker still relies on readThreadShell, which excludes archived threads. Bootstrap retry recovery only rotates IDs after a confirmed bootstrap deletion, so it does not establish recovery for an already archived ID.
Recommendation. Keep open: partial fix. Handle archived or previously consumed draft IDs explicitly, including persisted pre-fix drafts.
Request. PageUp and PageDown do not move the selection in command-palette lists.
Audit finding. Command lists still delegate navigation to Base UI Autocomplete. The palette key handler covers submission, thread shortcuts, and Backspace, but has no page-step navigation, and no Base UI patch is installed for it. The linked page-navigation proposal was closed without merging.
Recommendation. Keep open: work remains. Add supported page-step list navigation and test long folder lists in the command palette.
Request. The PR pane derives its API host from an SSH alias instead of the alias's real hostname.
Audit finding. Remote normalization still keeps the literal SCP host, and pullRequestHostOf takes the first component of that canonical key. No SSH configuration resolution occurs at the repository identity boundary. Host classification may now reject some aliases instead of labeling them GitHub, but the actual host is still unavailable to the PR pane.
Recommendation. Keep open: work remains. Resolve SSH HostName for API identity while retaining the original Git transport alias.
Request. Claude provider updates can target the wrong Homebrew formula name.
Audit finding. ClaudeDriver still declares homebrewFormula=claude-code, and maintenance builds brew upgrade directly from that value. Binary path detection chooses Homebrew but does not extract an installed versioned formula or cask name. The formula-selection fix is still open and is distinct from npm-versus-Homebrew version advisories.
Recommendation. Keep open: work remains. Review #6247 with claude-code@latest, plain claude-code, and both Cellar and Caskroom paths.
Request. The chat scrollbar, panel resize target, and viewport resize target are difficult to use separately.
Audit finding. The panel divider still has an 8-pixel full-height hit area that overlaps the boundary, and fixed viewport mode still has a full-height left resize rail. These remain separate from the chat scrollbar, with no single control that distinguishes the two kinds of resize. Recent preview layout work did not remove this interaction conflict.
Recommendation. Keep open: work remains. Separate the panel and viewport resize targets, then verify them beside the chat scrollbar at narrow panel widths.
Request. Each desktop restart adds another authorized local desktop session.
Audit finding. DesktopLocalEnvironmentAuth still keeps its token only in a process-local Ref and performs a fresh bootstrap exchange when that Ref is empty. It has no persisted reuse or revocation finalizer, so clean restarts still leave prior sessions listed until expiry or manual revocation. The later duplicate was correctly folded into this issue and its closed PR is not a fix.
Recommendation. Keep open: work remains. Reuse a durable local desktop session or revoke the prior owned session when replacing it.
Request. Usage estimates ignore Codex and Claude Fast or Priority pricing.
Audit finding. ModelRate and LiteLlmEntry contain only base input, output, cache-read, and cache-write prices. The pricing code explicitly uses base rates because transcript records do not identify the served tier. The cached-Claude-token correction changes cache arithmetic, not Fast/Priority rates or fallback handling.
Recommendation. Keep open: work remains. Record the actual served tier and select its rate before adding Fast-mode cost totals.
Request. A project action can send its command before a fresh interactive terminal is ready.
Audit finding. The action handler still awaits terminal open and then sends the command plus a carriage return in a separate write. Terminal open proves PTY creation, not completion of interactive zsh startup, so the reported race remains in both web and desktop. The focused command-start proposal was closed without merge.
Recommendation. Keep open: work remains. Run project actions through a server path that starts each command once after shell initialization.
Request. Refreshing providers does not find a CLI installed after the desktop process started.
Audit finding. The shared Windows probe still reads process PATH and never refreshes User or Machine registry PATH. Command lookup also caches missing executables for 30 seconds, but expiry cannot add a directory absent from the inherited PATH. A comment reports a macOS variant, so a Windows-only fix will not close every reported case.
Recommendation. Keep open: work remains. Finish the refresh-time PATH repair and add a macOS install-after-launch reproduction before closing.
Request. Switching threads can leave an existing preview tab unable to capture or accept automation.
Audit finding. The current snapshot path still has unbounded capturePage and a per-tab action permit, with no timeout recovery. The comment that says a fix was opened refers to a PR that was closed without merging. Later hidden-rendering changes do not establish that the same tab recovers after switching away and back.
Recommendation. Keep open: work remains. Include leave-and-return thread navigation in the snapshot recovery fix and prove the same tab recovers.
Request. An offline environment owning an unsettled thread can block new-thread creation in a shared project.
Audit finding. The new-thread default resolver still awaits a project-file query on the selected environment without checking its connection first. That preserves a concrete blocking path when the environment is offline, regardless of the recent server-side settling changes. The offline draft/alternate-environment fix remains open and does not need to alter the unreachable thread's state.
Recommendation. Keep open: work remains. Skip offline project-file reads and choose a reachable project environment before creating the draft.
Request. Escape does not leave insert mode in vim or nvim inside the terminal drawer.
Audit finding. Current Ghostty emits byte 27 for bare Escape in a direct check. The drawer normally passes it to the encoder unless a configured app shortcut claims it, while global selection and overlay handlers add other possible paths. The open protection PR is not merged, and the report lacks the keybindings and event trace needed to identify which path swallowed Escape.
Recommendation. Keep open: evidence needed. Capture Escape delivery with the current keybindings, overlay state, and PTY input on the affected client.
Request. Timed snoozes end when work completes, and snoozing again for the same time can leave the thread awake.
Audit finding. Current shared logic deliberately treats completion after snoozedAt as an early wake, and an existing test requires that behavior. The server preserves the old snoozedAt when the same wake time is selected again, which explains why the completion can keep overriding a repeated snooze. The open PR changes that product rule, so maintainers must choose the promised snooze behavior rather than close this as fixed.
Recommendation. Keep open: decision needed. Review the timed-snooze completion rule and same-time re-snooze behavior in the open fix.
Request. Expanded Claude Bash work-log entries omit the persisted command output.
Audit finding. The work-log derivation still keeps toolData only for MCP calls, and the expanded body includes command, detail, and changed files only. Its output extractor does not read Claude data.result.content, which is the exact persisted shape in this report. Recent activity folding and image-preview changes do not add that missing output field, and the direct fix is still open.
Recommendation. Keep open: work remains. Map persisted command output into work-log entries and render it when expanded.
Request. Claude tool results arriving after turn finalization are silently discarded.
Audit finding. completeTurn still emits completion with only toolName/input, deletes each tool, and clears inFlightTools. handleUserMessage then continues silently when a later toolUseId has no entry. The issue correctly distinguishes this source-level race from the separate client display incident, and the late-result patch remains open.
Recommendation. Keep open: work remains. Review #7192 with late results after completion, interruption, and session shutdown.
Request. Threads resumed after a PR closes can settle again at the end of each turn.
Audit finding. The merged age gate and new server policy keep a thread active when its latest user activity is newer than the PR. This fixes the old unconditional closed-PR rule for unchanged PR metadata. The policy still uses updatedAt rather than closedAt, so a later comment or metadata change can settle resumed work, and the explicit active override still clears on activity.
Recommendation. Keep open: partial fix. Use a real terminal-state timestamp or remove closed PRs from immediate automatic settlement.
Request. GitLab merge-request worktree checkout and refresh use GitHub-only refs.
Audit finding. Both fetchPullRequestBranch and fetchPullRequestHeadCommit still hardcode refs/pull. GitManager falls back to these helpers when it cannot materialize the head repository directly, which matches the self-hosted GitLab failure. The comment claiming a fix points to a closed unmerged proposal, while the provider-ref proposal is still open.
Recommendation. Keep open: work remains. Use the source-control provider's head-ref namespace for worktree fetch and refresh.
Request. Composer skills use the server startup directory instead of the active project or worktree.
Audit finding. CodexProvider still invokes its probe with process.cwd(), and ClaudeDriver still supplies ServerConfig.cwd to skill discovery. The new deduplication and slash-completion work changes which catalog entries are offered, not which workspace is scanned. The discussion confirms this on stable 0.0.37, including Codex, and preserves Claude user-first collision and symlink acceptance cases.
Recommendation. Keep open: work remains. Pass the active workspace through provider skill discovery and verify both Codex and Claude catalogs.
Request. The Files refresh button and reload return a cached tree after external filesystem changes.
Audit finding. The new agent-edit refresh improves open previews and triggers client tree refetches. Those refetches still call WorkspaceEntries.list without a server-side index refresh, so external creates and deletes can remain absent or stale after the button or reload. The explicit-rescan proposal is still open and does not claim to cover all live invalidation.
Recommendation. Keep open: partial fix. Make the explicit Files refresh rescan the server index before reloading entries.
Request. A remote desktop Files tree misses new agent-created paths even after refresh and restart.
Audit finding. The merged agent-edit refresh now refetches the tree while tools complete, but explicit refresh still reads the cached server index. The report also says a server restart did not help in large projects, which is not explained by cache invalidation alone and may involve the 25,000-entry cap or ignore rules. Keep this separate until its remote listing is measured.
Recommendation. Keep open: retest. Retest on current stable and capture listEntries count, truncated state, and one missing path after server restart.
Request. New threads do not consistently inherit the target project's last-used model options and working modes.
Audit finding. useHandleNewThread still derives carried runtime and interaction modes from the current route's composer, shell, or draft. Mobile stores one sticky model selection and applies per-thread drafts, but has no shared target-project last-used working-mode snapshot. Explicit project-model precedence has separate handling, yet the complete cross-entry-point, cross-client preference contract remains missing and the latest discussion records a wrong-provider submission.
Recommendation. Keep open: work remains. Store and resolve one last-successfully-used composer-settings snapshot per scoped project.
Request. A Claude usage-limit pause has no immediate visible explanation in the thread.
Audit finding. rate_limit_event still emits only account.rate-limits.updated. That event has no activity mapping or thread pause handling in ingestion, so the client receives no visible usage-limit notice from this path. The proposed warning and reset-time handling is still open.
Recommendation. Keep open: work remains. Review #7165 with rejected, allowed, repeated, and recovered limit events.
Request. A runtime-mode restart can block the global provider command queue and strand other threads.
Audit finding. The notification-consumer lifetime defect is fixed: Grok now forks that consumer into the session scope. ProviderCommandReactor still processes provider events with one drainable worker and awaits runtime-mode restart in that worker, while Grok stop still closes its scope without a deadline. The fix for dropped notifications therefore does not establish isolation from a hung start or stop.
Recommendation. Keep open: partial fix. Isolate provider commands by thread and bound restart cleanup so one provider cannot block other threads.
Request. Cursor Full access and Auto do not consistently suppress native tool approval prompts.
Audit finding. The adapter auto-selects known allow options only for full-access; Auto still opens a user approval request. Cursor is launched with acp and no corresponding CLI permission flag, unlike the updated Grok path. Full-access already has partial approval handling, but the reported remaining prompts and Auto mismatch are not resolved by that handling.
Recommendation. Keep open: work remains. Complete PR 7278 with explicit Cursor runtime-mode mapping and test shell plus MCP approvals.
Request. Users need an explicit global new-thread model and effort setting that project defaults can inherit.
Audit finding. Merged PR 6011 makes project selections outrank sticky selections, but does not add a global new-thread model control. The project reset clears its override, then current resolution falls back through provider availability and sticky state rather than a named global setting. The later comments also identify catalog-default effort overriding the provider CLI configuration, which remains a separate precedence question.
Recommendation. Keep open: decision needed. Define the global new-thread model and effort precedence across project overrides, sticky state, and provider configuration.
Request. A discoverable T3 Connect environment has a non-managed endpoint and conflicting saved cloud ownership.
Audit finding. The relay emits endpoint_provider_not_managed when the stored link is not a Cloudflare-managed endpoint, which matches the reported Activity publishing only state. The local server still rejects a different saved cloud owner, while disabling only the tunnel can keep publishing and reconfigure that same conflicting link. A full local unlink path exists without a relay token, but no current ownership or endpoint-state trace shows why recovery failed in this installation.
Recommendation. Keep open: evidence needed. Trace the full local unlink path and record redacted owner-match and endpoint-provider state before relinking.
Request. The PR viewer loads private description and comment images without GitHub authentication.
Audit finding. PR markdown uses ChatMarkdown, which renders HTTPS images as direct img sources. The discussion adds private repository blob images in comments and tables, not only user-attachments in descriptions. The open fix targets attachment URLs only, so even that proposal does not cover the expanded scope.
Recommendation. Keep open: work remains. Support authenticated image loading for both private uploaded attachments and repository blob images in PR content.
Request. The T3 Connect switch can retain a false value after background startup reconciliation restores the tunnel.
Audit finding. The link-state atom still uses stale-while-revalidate with refresh on mount and no subscription to server reconciliation. The controller derives its switch from that cached managedTunnelActive field and refreshes after its own mutations only. The linked fix was closed without merging, so a mounted Settings page can still miss the background change.
Recommendation. Keep open: work remains. Invalidate link state when startup reconciliation completes and verify the switch while Settings stays open.
Request. The iOS home-screen activity widget remains blank after opening the app.
Audit finding. The app config advertises a home-screen AgentActivity widget, but the layout is still registered through the live-activity path. The open widget fix proposes separate createWidget registration and containerBackground handling, neither present in the inspected layout. The earlier asset-order fix only ships the logo and does not establish that a home-screen widget receives a renderable snapshot.
Recommendation. Keep open: work remains. Wire a home-screen widget layout and snapshot update path, then verify a newly added iOS widget.
Request. Long Windows Codex commands can lose their execution handle or be cancelled without clear UI state.
Audit finding. The reporter later corrected the local case to cancellation and a partial test artifact, not a proven post-exit result race. T3 sends provider turns and maps provider tool events; it does not own the functions.exec cell store. The matching upstream runner issue remains open, and no trace separates that defect from T3's missing in-flight feedback in this case.
Recommendation. Keep open: evidence needed. Capture current Windows tool-start, follow-up, abort, and completion events for the corrected reproduction.
Request. Bulk thread deletion asks separately about each worktree instead of confirming the whole batch.
Audit finding. The sidebar confirms the thread count once, then calls deleteThread for each selected row. deleteThread still opens its own worktree confirmation before deletion, so the repeated-dialog behavior remains. The PR named as a fix in the body was closed without merging, and the alternate confirmation redesign remains open.
Recommendation. Keep open: work remains. Collect the orphaned worktrees for the selected batch and request one cleanup choice before deletion starts.
Request. Generated branch names gain feature/ before an existing conventional prefix.
Audit finding. The current sanitizer still preserves only feature/ and prepends it to fix/, feat/, and chore/. The proposed fix was closed without a merge, so its issue-closing text does not show that the behavior shipped.
Recommendation. Keep open: work remains. Preserve recognized conventional branch prefixes in sanitizeFeatureBranchName and update its focused tests.
Request. Resuming a large Codex thread loads unused turn history and can exhaust the server heap.
Audit finding. openCodexThread still sends thread/resume without excludeTurns. A separate child-metadata request already sets that flag, but the parent-session path does not. The merged linear buffering change reduces copying while receiving a frame and does not remove the full-history payload.
Recommendation. Keep open: work remains. Land and test excludeTurns on the parent thread-resume path.
Request. Concurrent explicit VCS refresh requests repeat Git and network work for one repository.
Audit finding. refreshStatus still invalidates and loads local and remote status for every caller without an in-flight map. The client refresh command still uses the shared serial VCS scheduler, and the dedicated coalescing change remains open.
Recommendation. Keep open: work remains. Review and complete the shared-refresh change, including interruption and queued-request coverage.
Request. Usage scans can traverse an unrelated projects directory and repeatedly reread large transcript files.
Audit finding. The default Claude resolver still falls back to home/projects when .claude/projects is missing. The merged incremental reader reduces repeated work on growing files, but does not remove that wrong-root scan or bound a cold transcript scan. The comment calling the root fix complete refers to a PR that is still open.
Recommendation. Keep open: partial fix. Stop the implicit home/projects fallback when the default Claude transcript directory is missing.
Request. Codex archived sessions are absent from Usage totals.
Audit finding. UsageService still returns only the shared home's sessions directory for Codex. CodexHomeLayout knows archived_sessions as a shared directory, but Usage does not include it in the scan. Cache preservation and incremental reads do not add that missing root.
Recommendation. Keep open: work remains. Include archived_sessions in Codex transcript scans with the same deduplication rules.
Request. A packaged nightly omits CORS headers on actual remote descriptor responses although preflight succeeds.
Audit finding. Main still installs CORS middleware for descriptor and auth routes, so source-level middleware presence is not proof that the package works. A later report confirms this exact header pattern when the published CLI runs under Bun, whose platform package remains external to the bundled Effect runtime. This report does not identify the remote server runtime, so it cannot yet be closed as the same defect.
Recommendation. Keep open: retest. Repeat the packaged descriptor request under Node and Bun and record which runtime serves the failing remote endpoint.
Request. A failed Claude capability probe replaces discovered commands with an empty list for the cache interval.
Audit finding. ClaudeDriver still caches an undefined probe result for five minutes, and checkClaudeProviderStatus replaces discovered commands with capabilities?.slashCommands ?? []. The newer built-in compact command survives, but custom commands do not. #7175 proposes retaining the last successful list and remains open.
Recommendation. Keep open: work remains. Review #7175 with a successful probe followed by a timeout and a persisted snapshot reload.
Request. OpenCode session teardown leaves pending approvals saved after the provider can no longer answer them.
Audit finding. The teardown path aborts sessions and closes the event scope without resolving pendingPermissions or pendingQuestions. Permission resolution still depends on a later permission.replied event, which teardown can prevent from reaching ingestion. Child cancellation and startup session reconciliation do not repair the saved approval rows described here.
Recommendation. Keep open: work remains. Complete OpenCode request teardown with recovery for existing unresolved approval rows.
Request. Claude snapshot recovery can lose the final assistant text after a stalled stream.
Audit finding. Snapshot text still aligns against the start of a turn-wide block list rather than its own message. Backfill only completes a block when streamClosed is already true, which the reported stalled stream never sets. The discussion confirms both a first-delta-only failure and a missing-entire-message failure, and the message-identity fix is unmerged.
Recommendation. Keep open: work remains. Match snapshot text to its message identity and complete interrupted blocks from authoritative text.
Request. A CachyOS environment is discoverable but its relay endpoint request fails.
Audit finding. endpoint_request_failed is the relay API mapping for EnvironmentMintRequestFailed, not evidence of a CachyOS-specific cause. Current code preserves the detailed cause internally, but this report contains only the public error and an old trace ID. No merged change proves that this particular route, credential, or network failure is resolved.
Recommendation. Keep open: evidence needed. Obtain one fresh failure with server and client versions plus its relay trace ID.
Request. An idle Claude session can accept stored prompts while resume waits indefinitely before turn.started.
Audit finding. sendTurn still awaits setPermissionMode for every default-mode prompt before emitting turn.started or queuing the message, with no timeout. #5710 fixed untargeted resume completions, but it did not bound this control call. The discussion's proposed idle-resume patch was closed without merging, so it is not evidence of recovery in main.
Recommendation. Keep open: work remains. Add a bounded ready/control handshake for idle resume and a test where setPermissionMode never resolves.
Request. Renaming a project directory leaves new Claude threads using a stale working path.
Audit finding. Turn startup still resolves the directory from thread.worktreePath or the persisted project.workspaceRoot. A project display-name change does not discover the renamed directory or repair that stored path, and this path can reach provider startup before a useful missing-directory diagnostic. The dedicated folder-rename recovery PR has not merged.
Recommendation. Keep open: work remains. Validate and update the project working directory before starting a new provider session.
Request. Mobile needs an environment-scoped action to refresh provider status and available models.
Audit finding. Merged PR 8480 adds Refresh models to the mobile model picker on iOS and Android. It calls serverEnvironment.refreshProviders with the selected environmentId, disables repeated taps while pending, and shows a failure alert; successful refreshes update the provider catalog. Focused tests cover the target environment, duplicate taps, and retry after failure.
Recommendation. Close: fixed. Close the issue and point users to Refresh models in the mobile model picker.
Merged pr: PR #8480. Merged implementation includes mobile provider-catalog refresh and is an ancestor of v0.0.37.
Independent closure check. The request names possible locations, not a required Settings-only entry point. Both iOS and Android model pickers now expose an environment-scoped refresh action that invokes the general serverRefreshProviders command, so it refreshes Cursor and other providers rather than only OpenCode. The button disables pending duplicate taps, successful discovery updates the catalog, and failure displays an alert. Source is fixed, but release should be unknown for the mobile client. An ancestor of desktop v0.0.37 does not prove App Store or Play Store publication.
Limits. Native iOS/Android publication was not verified; implementation is in main and source tag v0.0.37.
Request. An iOS client cannot exchange a relay DPoP token, blocking remote control, notifications, and Live Activities.
Audit finding. The merged DPoP change now preserves the proof failure category and distinguishes confirmed clock errors from other rejections. It does not relax verification or establish which proof field failed on this iPhone. The shared token exchange still gates all three affected features, so this needs a current native build and the new failure reason before closure.
Recommendation. Keep open: retest. Retest on a native build containing the DPoP diagnostics and collect its precise proof failure category.
Request. Codex visualization markers appear as raw text instead of an inline HTML preview.
Audit finding. The current markdown renderer supports Codex citations and artifact-template cards, but has no visualize marker handler. Those merged markdown features do not read the visualization file or render the requested preview. The dedicated inline-visualization PR remains open.
Recommendation. Keep open: work remains. Review the visualization renderer with local and remote file access plus a mobile fallback.
Request. A failed page can remain in the floating preview as a blank panel with no useful error state.
Audit finding. ThreadPreviewMiniPlayer still decides whether to show its reconnecting message only from hasWebContents. A failed navigation normally retains WebContents, so that branch never shows a failure or Retry control. The desktop manager preserves LoadFailed internally, but automation status omits it. The dedicated floating-error fix remains open.
Recommendation. Keep open: work remains. Render the navigation failure and Retry control in the mini-player and include that failure in automation status.
Request. Merging a pull request in the viewer should settle its thread as soon as the merged state is confirmed.
Audit finding. Main now owns settlement on the server, but ThreadSettlementReactor runs a sweep each minute and on setting changes, not after a PR merge. The viewer refreshes its detail query after a successful merge without waking that reactor. The requested immediate settlement is still missing.
Recommendation. Keep open: partial fix. Trigger a settlement check after a successful PR merge and verify the linked thread settles without waiting for the scheduled sweep.
Request. A PR URL posted by an agent should immediately refresh the thread PR badge across supported hosts.
Audit finding. The completed-turn path still calls refreshLocalStatus, which leaves remote PR data for the separate refresh loop. There is no PR-link-triggered remote refresh in that path. The dedicated cross-host link detection change remains open.
Recommendation. Keep open: work remains. Complete the PR-link-triggered remote refresh and cover GitHub, GitLab, Azure DevOps, and Bitbucket links.
Request. A timed-out provider probe replaces and caches the last working provider status.
Audit finding. Codex and Claude timeout branches still return error snapshots. makeManagedServerProvider replaces its snapshot with that result, and providerStatusCache persists status and authentication without distinguishing timeout from confirmed failure. Model retention in ProviderRegistry reduces catalog loss but does not preserve ready status.
Recommendation. Keep open: work remains. Land a timeout-specific last-good-snapshot policy through PR 7232 and test refresh plus cache hydration.
Request. One timed-out foreground health probe replaces a live connection and disables the composer.
Audit finding. The shared supervisor still turns the probe deadline into ConnectionTransientError and propagates the failed exit immediately. It has no second probe for a timeout before replacing the lease. Cheaper probes and faster server work do not change this failure rule, and the retry proposal remains open.
Recommendation. Keep open: work remains. Retry a transient desktop or web probe timeout once without delaying explicit disconnect or offline signals.
Request. Cursor API-key-only authentication is incorrectly reported as logged out and triggers interactive login.
Audit finding. parseCursorAboutOutput still marks userEmail:null as unauthenticated without checking CURSOR_API_KEY. Both the probe and session runtime hardcode cursor_login. No landed change removes those assumptions, and the API-key fix remains an open PR.
Recommendation. Keep open: work remains. Complete PR 7245 and verify API-key model discovery and session start without a browser login.
Request. The inactivity threshold should appear as a child of the auto-settle toggle.
Audit finding. The threshold still renders as an ordinary SettingsRow with no child indentation. The earlier indentation proposal was closed without merging. Later changes to the settling default did not add the requested parent-child presentation.
Recommendation. Keep open: work remains. Indent the inactivity threshold under the auto-settle toggle in shared web settings.
Request. An oversized non-usage Codex JSONL line can crash the Usage scan process.
Audit finding. The new reader removes Node readline, and string conversion now runs inside a catch that can return a failed-file result. However, it still collects every chunk of a line, concatenates the full buffer, and converts it before filtering usage records. The exact uncaught-readline path changed, but the requested bounded reader is still missing.
Recommendation. Keep open: partial fix. Adapt the bounded-line fix to the new incremental reader and test an oversized record followed by valid usage.
Request. The Agents panel can show the parent model and effort for custom Claude subagents.
Audit finding. The merged snapshot-race fix buffers an authoritative child model until task_started arrives. The launch path still falls back to context.currentEffort and the parent model when no explicit tool override or buffered model exists. Custom agent frontmatter and absent effort are therefore still misreported, so the model-race fix does not close the whole issue.
Recommendation. Keep open: partial fix. Remove guessed parent metadata and populate child model and effort from authoritative child records.
Request. The aggregate PR diff stays stale when new commits refresh the detail header.
Audit finding. The panel still warms the aggregate diff once while its live refresh reads only detail and activity. The Code tab rereads its first diff page only when the manual refresh token changes. The cited implementation was closed without merging and its snapshot coordinator is absent from main.
Recommendation. Keep open: work remains. Restore a focused fix that refreshes the aggregate diff when the PR revision changes.
Request. Subagents can retain failed status after quota recovery and show stale activity while running.
Audit finding. Main already forwards meaningful Claude task progress and last-tool data, and the stable stop fix now emits completion events for live tasks during teardown. It still ignores account rate-limit updates, does not reopen a failed row on a later task.started, and can discard description-only progress when usage is present. Retryable Codex errors also still populate lastError, so the quota-recovery and stale-error scope remains open.
Recommendation. Keep open: partial fix. Add a same-task-ID quota-recovery case that checks resumed status, current activity, and stale error removal.
Request. Direct subagents should appear newest first without reordering on progress updates.
Audit finding. deriveAgentPanelModel still sorts directAgents by ascending firstSeenAt, with ID as its stable tie-breaker. The existing test explicitly expects the first-created row before the second even after newer progress. Retention and workflow grouping changes preserve this oldest-first policy rather than implement the requested ordering.
Recommendation. Keep open: decision needed. Decide whether to reverse direct-spawn creation order and update the focused ordering test.
Request. Title regeneration stays pending on a remote T3 Connect environment while the local environment works.
Audit finding. The reporter corrected the scope in discussion: local generation and UI updates work, and the remote host completion was never checked. The client reducer applies a new title and explicit null regeneration state, but the UI still disables another request while the pending field exists. Current source does not establish whether the remote provider stalls or relay delivery loses the completion.
Recommendation. Keep open: evidence needed. Capture the remote host title-regeneration receipt and the matching relay-delivered completion event on one affected thread.
Request. A contributor asks whether to add DeepSeek Harness as a separate provider.
Audit finding. The built-in registry still contains only Codex, Claude, Cursor, Grok, and OpenCode. The discussion has user support but no maintainer acceptance of the proposed provider or its missing approval, user-input, and rollback capabilities. This is a product-scope decision, not a fixed defect or an obsolete request.
Recommendation. Keep open: decision needed. Decide whether DeepSeek Harness belongs in the supported provider set before asking for implementation work.
Request. Windows desktop provider detection misses executables that exist only on current User PATH.
Audit finding. Both the report and the current capture code identify the same gap: GetEnvironmentVariable is called without User or Machine scope. The recent quote-removal and PATH-order fixes do not add registry entries. The known-directory list also does not replace a general repair for arbitrary registered CLI paths.
Recommendation. Keep open: work remains. Complete the User and Machine PATH repair shared by PRs #7362 and #8465.
Request. Creating a fork-to-upstream PR fails when gh resolves a base repository other than origin.
Audit finding. resolveBranchHeadContext still compares the head remote with literal origin, then sends an owner-qualified selector only when that comparison says the repositories differ. A branch on an origin fork therefore still loses its owner prefix when gh selects upstream. The fork-head fix is open, not merged.
Recommendation. Keep open: work remains. Use the provider-resolved base repository to choose the PR head selector and cover an origin fork with upstream gh-resolved=base.
Request. The iOS composer can retain another thread's text while its send button stays disabled.
Audit finding. The current revision helper still treats a matching old value as an older native echo. The iOS native editor still rejects controlled documents whose event count trails its counter, without an explicit document-owner reset for a thread switch. The proposed reset fix remains open, so newer typing and theme fixes do not close this document-replacement race.
Recommendation. Keep open: work remains. Give a thread switch or send-clear an explicit controlled-document reset that native must accept.
Request. Typing /clear sends ordinary text to Codex and does not reset its conversation.
Audit finding. CodexProvider still advertises only feedback as a provider slash command. buildTurnStartParams still forwards the prompt as text, with no clear/reset branch. The Linux-server and mobile-client discussion confirms that this is not limited to the original macOS web report.
Recommendation. Keep open: work remains. Handle /clear before provider dispatch so it resets the session or returns an unsupported-command error.
Request. One-click npm provider updates fail when the desktop inherits PATH from before Node was installed.
Audit finding. The maintenance runner now handles a resolved npm.cmd correctly, but it still depends on command lookup finding npm. The Windows repair reads only inherited process PATH, so it cannot recover the Machine registry Node directory in this reproduction. The related repair PRs have not landed.
Recommendation. Keep open: work remains. Test and land registry PATH repair for maintenance commands started from a stale desktop environment.
Request. The displayed branch does not update after a branch switch in the built-in terminal.
Audit finding. The broadcaster has a remote polling loop but no local HEAD watcher. Local Git refresh still occurs on explicit requests and completed agent turns, which explains why a focus change repairs the label while a terminal-only checkout does not. The external-branch-change implementation remains open.
Recommendation. Keep open: work remains. Complete external HEAD-change detection and update thread branch metadata without requiring a focus change.
Request. Preview snapshots can send unbounded page metadata twice and consume the provider context.
Audit finding. McpHttpServer still copies all page metadata into structuredContent and JSON-stringifies the same object into text content. It removes the screenshot bytes from that metadata but does not bound the accessibility tree or text. The screenshot response can remain useful while the metadata needs a size limit and a truncation marker.
Recommendation. Keep open: work remains. Bound preview snapshot metadata before creating both MCP result representations.
Request. A project favicon appears slightly cropped on macOS desktop but not Android.
Audit finding. The shared desktop/web favicon currently uses object-contain, although it also has rounded corners and caller-provided sizing. The report supplies no image, favicon bytes, app version, or location of the clipped icon. That does not establish whether the source asset, corner clipping, or a caller layout is responsible.
Recommendation. Keep open: evidence needed. Request the favicon file and a screenshot showing the exact desktop location that crops it.
Request. Local review diffs are cut at 120 KB, hiding later files and sometimes incomplete hunks.
Audit finding. Main still caps the whole tracked review patch at 120,000 bytes and each untracked patch at 80,000 bytes. Both working-tree and branch-range previews use those limits with a truncation marker. The separate checkpoint path still returns only diff text, so increasing the preview cap alone would not handle the report's silent checkpoint truncation concern.
Recommendation. Keep open: work remains. Design bounded per-file or paged review diffs and carry truncation state through checkpoint diff results.
Request. Tool-call text needs to respond to an Appearance font-size setting.
Audit finding. Ordinary tool rows now scale with Interface font size, and expanded command details use Code font size. The original screenshot also shows the "Kicked off 1 subagent" row, whose label still inherits a fixed 13px size in AgentSpawnCtaRow. That pictured row does not scale with either Appearance control, so the merged changes only cover part of the report.
Recommendation. Keep open: partial fix. Make the subagent-spawn label use an Appearance-controlled font size and verify every row shown in the report.
Independent closure check. Plain tool headings now scale with Interface size and expanded details scale with Code size, but the report screenshot also shows the Kicked off 1 subagent row. That exact row still renders through AgentSpawnCtaRow with text-[13px] in pinned main. Setting the root font size cannot change a fixed pixel font, so the reported scope is only partly fixed. Keep the issue open for the subagent row instead of claiming all pictured tool activity follows settings.
Request. The iOS composer can fall behind a visible keyboard when a heavy thread hydrates.
Audit finding. The report isolates a Reanimated 4.3.1 settled-transform race. Main has since moved to Reanimated 4.5.1 through the Expo SDK 57 upgrade, beyond the upstream 4.3.4 correction named in the report. The app still uses KeyboardStickyView, so the original deterministic hydration sequence should be checked on a rebuilt client before closure.
Recommendation. Keep open: retest. Run the supplied hydration-commit reproduction on a native build with Reanimated 4.5.1.
Request. The managed tunnel reports running before Cloudflare registers a connection.
Audit finding. ManagedEndpointRuntime returns running immediately after spawn and when the existing child is alive. Registered tunnel output is logged but does not change the readiness condition, so blocked port 7844 can still leave an unreachable tunnel reported as running. The change to wait for registration remains open.
Recommendation. Keep open: work remains. Review and land registered-tunnel readiness with a bounded failure message for blocked egress.
Request. Managed relay links can stop reaching healthy servers after updates or later configuration drift.
Audit finding. Link proofs still use the client-supplied origin port rather than the server listener, and a running connector with the same config is accepted without checking its origin. The listener-port repair is still open. Later discussion also reports a healthy current-origin tunnel that receives no relay requests, so even that repair would not cover the full reported scope.
Recommendation. Keep open: work remains. Trace origin selection and relay routing through an update and the later healthy-tunnel failure.
Request. npm can skip required native build scripts while the pinned-runtime installer reports success.
Audit finding. The installer still runs plain npm install with no staged script allowlist. Boot-service validation only runs the CLI version command, so it can write the success sentinel without ever loading node-pty. Later comments confirm npm 12 default-policy failures on both Linux x64 and arm64, and the manifest-based fix is open.
Recommendation. Keep open: work remains. Stage the required npm script approvals and validate the native PTY module before publishing a runtime.
Request. The first mobile task prompt needs the same skill, command, and file pickers as an existing thread.
Audit finding. Main now mounts ComposerCommandPopover in NewTaskDraftScreen and uses the same useComposerCommandMenu hook as ThreadComposer. The hook receives the selected provider and checkout with hasThread false, so first-message skill and file choices work while thread-only commands stay hidden. The merged fix includes focused tests and recorded iPhone interaction checks.
Recommendation. Close: fixed. Close as fixed on main by the merged new-task composer-menu change.
Merged pr: PR #8587. Merged fix includes first-message interaction evidence and focused checks.
Independent closure check. The entire issue and comment concern first-message menus in the React Native app, not only the separate Swift work. Pinned NewTaskDraftScreen now mounts ComposerCommandPopover, passes draft selection and provider catalog through the shared hook, and inserts selected commands, skills, and file links into the unsent prompt. It supplies the selected environment and checkout with hasThread=false. Merged 8587 is in main and the 0.0.37 source tag. Actual App Store and Play Store delivery is not verified.
Limits. The fix is an ancestor of v0.0.37, but mobile App Store and Play Store distribution was not verified.
Request. Desktop project and text-generation settings use local providers instead of the selected remote environment.
Audit finding. ProjectDetail still reads primaryServerProvidersAtom and usePrimarySettings even for a remote project. General text-generation settings use the same primary-only provider list. The open text-generation fix addresses one entry point, but it does not establish the requested remote project-settings behavior.
Recommendation. Keep open: work remains. Use the target environment provider list for remote project settings and text-generation selection.
Request. A failed one-second project CLI probe deletes live-server discovery state and falls back to offline writes.
Audit finding. The project CLI still uses a one-second timeout. Any failed snapshot attempt still clears the persisted runtime file and returns no live execution mode, which sends mutations to the offline runtime. It does not distinguish a dead server from timeout or authentication failure, and the safety proposal remains open.
Recommendation. Keep open: work remains. Fail the project command on uncertain live-server failures and allow offline fallback only after proving the recorded server is gone.
Request. A successful Grok authentication probe still reports authentication as unknown.
Audit finding. GrokProvider still returns auth.status unknown even after ACP startup and model discovery succeed. That ready-plus-unknown snapshot produces the misleading settings text described in both reports. The Grok skills and usage changes did not alter this success branch.
Recommendation. Keep open: work remains. Derive Grok authentication state from a verified non-interactive probe and preserve subscription versus API-key identity.
Request. A slow Windows Codex probe replaces a healthy provider snapshot with an error.
Audit finding. The probe still uses one 10-second timeout for startup, authentication, skills, and model enumeration. Its timeout branch still returns error with no detected models or version. No Windows-specific budget or last-good snapshot fallback was found in the current path.
Recommendation. Keep open: work remains. Keep the last usable snapshot on a probe timeout and add a focused slow-probe test.
Request. Users need a persistent per-thread override to remove a wrong automatically matched PR.
Audit finding. The merged link feature adds link and unlink actions for an explicit PR link in web chat. Unlink writes linkedPullRequest:null, but both server settlement and badges then fall back to branch-based PR lookup. It does not suppress an unwanted automatic match, which is the main recovery path this report requests.
Recommendation. Keep open: partial fix. Add a persistent no-PR override and expose it on thread controls in web, desktop, and mobile.
Request. Windows can advertise the Tailscale address as both the LAN and Tailscale pairing endpoint.
Audit finding. LAN address selection still excludes only internal, loopback, and link-local IPv4 addresses and returns the first remaining interface. It does not exclude Tailscale 100.64.0.0/10, so a Tailscale-first interface order still hides the actual Wi-Fi address. The Tailscale command-failure fix does not change this LAN classification.
Recommendation. Keep open: work remains. Exclude Tailscale addresses from LAN selection and test a Tailscale-first interface order.
Request. Android inline skill chips need readable foreground and background colors in dark mode.
Audit finding. The dark theme now specifies pale fuchsia text over a translucent fuchsia background. The Android editor still parses the CSS rgba background with Android Color.parseColor, which rejects that format and retains the light fallback chip background. The token contrast therefore cannot be judged from the CSS values alone, and the native color-parser fix remains open.
Recommendation. Keep open: work remains. Normalize all composer chip colors to Android-supported values before applying the native theme.
Request. The Windows Files tree omits root setup shell scripts that remain visible in another editor.
Audit finding. WorkspaceEntries.list returns the native search index result, and the finder configuration has no setup.sh or setup.ps1 name filter. The report supplies no Git ignore result or index response that explains why these particular names disappear. No matching source change proves this Windows case fixed.
Recommendation. Keep open: evidence needed. Collect the project listEntries response and git check-ignore output for the two missing setup files on current Windows.
Request. A same-machine web client reached by LAN IP cannot open an editor when the environment has no SSH route.
Audit finding. The primary browser connection is still local-exec only for a loopback hostname. The desktop-shell exception does not apply to an ordinary browser using the same machine by LAN IP. With no local sshd, the server advertises no route and the resolver returns remote-unavailable. A server LAN address alone would not prove that the browser is local, so the fallback needs an explicit choice or better locality evidence.
Recommendation. Keep open: work remains. Add an explicit open-on-server choice for browser connections that have no SSH route.
Request. Auxiliary text generation can fall back to an explicitly disabled provider.
Audit finding. resolveTextGenerationProvider correctly rejects a disabled instance, then fallbackTextGenerationProvider searches settings.providers instead of providerInstances. The fallback can therefore select the same driver whose instance was disabled. Current title retry work repeats that selection rather than fixing it, and PR 8821 remains open.
Recommendation. Keep open: work remains. Complete PR 8821 and test disabled default instances, custom instances, and all-providers-disabled settings.
Audit finding. ProjectFaviconResolver still normalizes the workspace, checks favicon candidates, and reads source files on every resolvePath call. It has no resolver-level cache or shared in-flight lookup. The earlier regex fix is present, but that fixes slow individual scans rather than the repeated scans documented here.
Recommendation. Keep open: work remains. Cache and share favicon discovery by workspace and explicit icon path, with bounded invalidation.
Request. Local note links can render incorrectly and fail to open in the in-app file viewer.
Audit finding. Stable v0.0.37 includes the later fix for filenames with spaces and normal HTML/XML file-viewer routing. Current markdown code also recognizes absolute paths and file URLs, and workspace-relative files can open in the panel. Files outside the workspace still fall back to an editor, so the report cannot be fully matched without the actual failed link and its relation to the project root.
Recommendation. Keep open: retest. Request the exact failed Markdown link and retest it inside and outside the project root on v0.0.37 or later.
Request. Typing @ alone shows no file or folder suggestions in the composer.
Audit finding. useProjectPathSearch blocks empty queries unless allowEmptyQuery is set. useComposerPathSearch does not set that option, so typing only @ cannot issue the listing request even though the server accepts an empty mixed search. The proposed composer fix is still open.
Recommendation. Keep open: work remains. Enable empty-query results for the composer file picker and preserve its debounce and project scope.
Request. An SSH environment keeps the originally resolved port instead of following later alias configuration changes.
Audit finding. Onboarding persists provisioned.bootstrap.target, including the resolved port. Reconnect resolves the alias again but overwrites its new port with the saved non-null port, which baseSshArgs passes explicitly with -p. The source still lacks a distinction between an explicit user override and an automatically resolved value.
Recommendation. Keep open: work remains. Persist the original SSH alias and explicit overrides separately from resolved connection details.
Request. Claude permission launch arguments can conflict with the thread runtime mode without a warning.
Audit finding. The adapter passes parsed extraArgs alongside its derived permissionMode and reapplies the derived mode on later sends. The settings description only promises additional startup arguments and gives no precedence or conflict warning. Main therefore retains the reported silent conflict, while choosing which setting should win remains a product decision.
Recommendation. Keep open: decision needed. Choose permission precedence and expose conflicting launch arguments in provider settings.
Request. Claude compaction can leave a thread busy after its requesting turn has already completed.
Audit finding. The status handler still converts status=null to running, and api_retry also emits running without requiring a live turn. Ingestion accepts those session events and preserves a null activeTurnId, which matches the stuck state in the report. Native resume-compaction support does not add the missing heartbeat ownership guard.
Recommendation. Keep open: work remains. Review #7591 with compact_boundary and status=null after turn completion.
Request. Desktop quit can wait forever for a backend after the window closes.
Audit finding. The desktop finalizer still awaits every backend stop with unbounded concurrency and no timeout. Closing the window before cleanup does not bound that wait, and the proposed five-second shutdown fix is still open.
Recommendation. Keep open: work remains. Review the open backend shutdown timeout fix.
Request. Some clickable pull-request controls still use the default cursor.
Audit finding. The discussion confirms that the tabs gained pointer cursors, but identifies rows and reaction controls as still missing them. PullRequestRow remains a native button without cursor-pointer, and enabled reaction buttons add hover styling without a pointer cursor. The shared button styling change does not cover these native buttons.
Recommendation. Keep open: partial fix. Add pointer cursors to enabled pull-request rows and reaction controls through PR 7629.
Request. The macOS desktop reports Homebrew gh as unavailable because executable lookup fails before authentication.
Audit finding. The follow-up records repeated gh ENOENT failures across discovery and pull-request commands on a newer nightly, not just an incorrect authentication label. Both paths still spawn the bare gh command, while startup separately attempts login-shell PATH repair. The failed repair or propagation step has not been isolated, and the macOS background-service PATH change does not prove the desktop path is fixed.
Recommendation. Keep open: work remains. Trace login-shell PATH repair into the failing desktop gh spawn and rescan.
Request. The managed WSL backend loses supported Bitbucket credentials at the Windows-to-WSL boundary.
Audit finding. The WSL forwarding allowlist still contains only OPENAI_API_KEY and ANTHROPIC_API_KEY. The launch path adds only those names to WSLENV, so supported Bitbucket variables remain absent unless the user forwards them manually. The specific Bitbucket forwarding PR is open and the macOS shell-profile report is a different boundary.
Recommendation. Keep open: work remains. Add the supported Bitbucket credential names to WSL forwarding and test authenticated private-repository access.
Request. Mobile native lint exits successfully after skipping missing Kotlin tools.
Audit finding. The static-check script still calls warnMissingTool when ktlint or detekt is absent, then completes without failing. Its install hints remain Homebrew-based even though Kotlin checks can run on other JVM platforms. CI installation does not make a skipped local run trustworthy.
Recommendation. Keep open: work remains. Make missing Kotlin analyzers fail local lint with platform-neutral install instructions.
Request. Prompt Stash should persist on the execution environment and synchronize across clients.
Audit finding. Prompt Stash still uses browser localStorage as its durable store and hydrates once per client. The web attachment upload work has landed separately, so the old attachment PR is no longer the only path to a stable upload contract. No server stash commands, shared subscription, atomic take, or local-data migration was found in the current stash implementation.
Recommendation. Keep open: work remains. Implement environment-owned stash metadata on the landed attachment contract with an atomic take operation.
Request. Mobile file previews can keep showing a preparation spinner after asset URL or connection failure.
Audit finding. The workspace-image fix introduced useAssetUrlState and is in stable v0.0.37, while nightly native preview work now handles failures in the file modal. Workspace file URLs still use the nullable compatibility hook, and the image and web preview components treat every null as loading. The shared hook also maps a missing connection to Loading. The full workspace-preview error-state fix remains open.
Recommendation. Keep open: partial fix. Pass disconnected and failed URL states through workspace image and web previews and show Retry.
Request. The web terminal can reset and replay a trimmed output suffix, leaving stale cells and incorrect shell text.
Audit finding. The current client buffer trims output at 512 KiB, but TerminalViewport still uses a prefix comparison to decide between an append and a full reset. Trimming removes that prefix, which makes ordinary output trigger resetAndWrite with a mid-stream suffix. The reporter's fork changes this exact path, but that change is not on pinned main.
Recommendation. Keep open: work remains. Keep this report open while the terminal streaming change is reviewed against lazygit and zsh-autosuggestions.
Request. Azure DevOps PR links opened from a thread fail the server repository ownership check.
Audit finding. PullRequestService normalizes Azure DevOps repository identity to its bare name. ChatView still uses repositoryIdentity.displayName for an automatically associated PR, while chat link resolution also uses displayName. Explicit links carrying the server-produced repository name can work, but the reported thread and chat-link paths still disagree with the server.
Recommendation. Keep open: work remains. Use one shared Azure DevOps repository identity function for thread pills, chat links, and server PR requests.
Request. The integrated terminal does not advertise truecolor to TUIs such as lazygit.
Audit finding. The current Node PTY adapter still advertises xterm-256color without a COLORTERM default. The Windows TERM fix changes palette detection to 256 colors, not 24-bit color. The truecolor change remains in an open PR.
Recommendation. Keep open: work remains. Review the truecolor default in the pending terminal fix.
Request. The commit dialog exposes internal refName wording instead of explaining the default-branch choice.
Audit finding. The current dialog still renders Warning: default refName and Commit on new refName. The proposed wording-only PR was closed without merging. This is still a user-facing copy defect in the shared web and desktop dialog.
Recommendation. Keep open: work remains. Replace refName with branch and explain the default-branch choice in the commit dialog.
Request. Show context usage as a visible percentage beside or inside the composer meter.
Audit finding. The meter still renders only SVG circles in its trigger. The formatted percentage is in the accessible label and popover, while the candidate that places text below the ring remains open.
Recommendation. Keep open: decision needed. Decide whether to accept the below-ring percentage in the open meter change.
Request. Provider compaction needs a visible running state and a truthful success or failure result.
Audit finding. Claude compaction still becomes the generic waiting session state. Ingestion records some completed-compaction activities but filters Codex item lifecycle events to tools, and the OpenCode adapter has no compaction signal handling. The newer resume-compaction prompt is not an in-progress state or result, so the multi-provider request remains open.
Recommendation. Keep open: work remains. Add a shared compaction lifecycle and map actual provider signals into web and mobile presentation.
Request. Composer skill and slash-command pickers offer Claude entries that the selected syntax cannot invoke.
Audit finding. Claude skill discovery still reads only name and description and marks every discovered skill enabled. The recent slash filter removes only skill rows outside prompt position zero, so provider commands can still be offered on later lines. Skill deduplication does not fix invocation flags or disabled skills, and the dedicated fix remains open.
Recommendation. Keep open: work remains. Review the invocation-aware skill discovery and picker fix.
Request. Desktop T3 Connect sign-in fails on Linux sessions with no usable keyring.
Audit finding. DesktopClerk still uses storage with only a path, and the installed Clerk 0.0.37 adapter still drops token writes when encryption is unavailable unless unencryptedFallback is enabled. Linux backend selection can choose libsecret but cannot supply a missing keyring. The later Clerk updates therefore do not establish a fix for this sign-in path.
Recommendation. Keep open: work remains. Show a missing-keyring error in desktop sign-in and verify recovery after a keyring becomes available.
Request. Claude Settings can claim authentication even when the same CLI environment is logged out.
Audit finding. Any defined capabilities object still produces ready/authenticated, even if email, tokenSource, subscriptionType, and apiProvider are empty. The instance environment now preserves HOME and sets CLAUDE_CONFIG_DIR, but that does not validate the login held in the selected directory. The auth-status fixes remain open, so the incorrect ready state is still present in main.
Recommendation. Keep open: work remains. Review #7691 and #8275 against an empty-account SDK response and loggedIn=false from the same CLI environment.
Request. Interrupted SSH password requests remain in the renderer queue and stack after sleep or retries.
Audit finding. The supervisor still limits the whole establishment attempt to fifteen seconds while desktop password requests advertise three minutes. Main-process cleanup removes the pending request without sending a renderer settlement event, and the renderer appends requests to a FIFO that removes only its visible head. The close and focus work does not reconcile those lifetimes.
Recommendation. Keep open: work remains. Send keyed prompt-settlement events and start the transport deadline after interactive SSH preparation.
Request. Annotation tool shortcuts and Escape are unreliable in the Windows preview browser.
Audit finding. Picker startup still calls guest focus only if isFocused is false, which is the condition the open focus fix identifies as unreliable. Shortcut handling is confined to the guest window and skips tool keys when an annotation control has focus. The focused startup fix remains open, and no landed change proves the reported Windows sequence works.
Recommendation. Keep open: work remains. Verify and fix guest keyboard ownership when annotation starts and after clicking a toolbar tool.
Request. Expanded Claude Bash activity repeats the command because its detail includes a Bash prefix.
Audit finding. The comparison normalizer still strips only a trailing complete or completed suffix. The detail path compares prefixed detail with the bare command, and the expanded body renders both when they differ, so the reported payload still takes the duplicate-render path.
Recommendation. Keep open: work remains. Review the open tool-name prefix normalization fix.
Request. A Codex child still appears active after Stop and does not report its result.
Audit finding. Main now ignores parent interactions that used to mark completed children as running again. Its Stop path also sends bounded interrupts to tracked live children, with coverage for child-first notification order. These changes fit the stale-status symptom, but the report has no stop result or child lifecycle trace proving which case occurred.
Recommendation. Keep open: retest. Repeat the child-stop case on a current build and capture the child's stop result and final status events.
Request. Closing the last right-panel tab should return to its empty picker instead of hiding the panel.
Audit finding. Main deliberately closes the panel when its final surface is removed. The previous proposal was closed with a stated reason that it reversed the earlier last-tab behavior, so this is a product decision rather than an already-fixed defect. The discussion also reports Command+W closing the app, which is separate from the store change.
Recommendation. Keep open: decision needed. Decide whether final-tab close should preserve the empty panel before reopening an implementation.
Request. Homebrew provider installs are marked outdated against npm versions that Homebrew cannot yet install.
Audit finding. Homebrew maintenance still carries the npm package name, and resolveLatestProviderVersion always queries npm latest using that name. No Homebrew version source is selected, so a successful brew no-op cannot clear an advisory while the cask lags npm. The linked channel-aware version check is still open.
Recommendation. Keep open: work remains. Review #7731 with installed Homebrew equal to cask latest but behind npm latest.
Request. SSH environments cannot finish readiness checks when a network round trip exceeds one second.
Audit finding. SSH_READY_PROBE_TIMEOUT_MS is still 1000 milliseconds, including the readiness request through the local forward. The cold-start change raised the remote startup window but left this per-request timeout and the two-second reuse window unchanged. The targeted high-latency fix remains open.
Recommendation. Keep open: work remains. Review the existing high-RTT readiness fix with a delayed-response test.
Request. Unix CLI installs can extract the bundled resource monitor without executable permission.
Audit finding. The release workflow already runs chmod, but the publish manifest does not preserve an executableFiles declaration and the resolver still rejects a non-executable bundled file. The node-pty spawn-helper repair is a different binary path. Runtime self-repair and package-mode fixes remain unmerged.
Recommendation. Keep open: work remains. Fix the packed npm file modes and verify the extracted Unix sidecar before closing.
Request. Desktop spellcheck underlines valid text in languages outside the OS locale.
Audit finding. The main editable composer has no spellcheck override, while spellCheck false appears only on token nodes. Desktop has no dictionary selection or disable setting, so the OS-locale behavior remains in use. Both the language-setting proposal and the composer-disable proposal are still open.
Recommendation. Keep open: work remains. Choose and implement a desktop spellcheck control that can disable checking or select dictionaries.