fix(server): wait for native Codex start before Stop - #10024
juliusmarminge merged 2 commits into
Conversation
ApprovabilityVerdict: Approved at Macroscope's review found this PR approvable — This is a focused Codex server bug fix that delays interruption only for turns acknowledged as queued, then bounds the wait and cleans up state; normal turns remain unchanged. Replay tests cover native startup, pre-start failure, and a turn that never starts, while the recorded high-severity concern targets the same lifecycle path. Notes:
You can add or adjust custom eligibility rules. Learn more. |
9242b91 to
3d81172
Compare
Dismissing prior approval to re-evaluate 2791e93
|
Macroscope has since reviewed this pull request. An earlier review was skipped by a cost limit; a review has now completed, so that notice no longer applies. |
efd9994 to
6102d00
Compare
2791e93 to
b81d04e
Compare
There was a problem hiding this comment.
All clear
Posted via Macroscope — Effect Service Conventions
|
All clear Posted via Macroscope — Effect Service Conventions |
ed5dc41 to
2b1139a
Compare
f2b6ea7 to
0e4ab6e
Compare
0e4ab6e to
7dec1c7
Compare
49fa325
into
pingdotgg:t3code/codex-turn-mapping
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep queued message editing inside the queue panel * fix(web): keep queued messages in place while editing * fix(web): match composer actions to draft and modifier state * fix(web): keep composer shortcut tooltip stable on Mod * feat(web): summarize T3 orchestration actions * feat(mobile): port chat summaries and transitions to orchestration v2 Adapt grouped tool summaries and the floating working timer to V2 run, attempt, and queue state. Bring over the composer, keyboard, and disclosure transitions while retaining the V2 activity inspector and queue controls. Keep OV2 web composer and grouping behavior intact; share only the existing command label parser with mobile. * fix(chat): remove added tool summary status counts * fix(mobile): keep scroll bounds current after animations * fix: reconcile main's round-17 features after the rebase Restores main features dropped by the policy replay: #8569 theme wiring, settings search rework, #8803 workspace-mutation refresh (v2-adapted), video + image previews (web and mobile, v2-adapted), #8862 Expo glass, and the round's docs. Timeline thinking rows (#8984) stay on the v2 work-live system. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(web): port working and thinking timeline rows to orchestration v2 The v2 equivalents of main's #8984 and #8922: a "Working for ..." header anchors the active run, the trailing live tool row survives between actions in past tense instead of vanishing, and a shimmering Thinking row marks reasoning gaps. During workspace preparation the header shows "Setting up worktree..." (driven by the local dispatch flag or the v2 run's preparing status, so remote viewers see it too), the composer footer span is gone, and draft promotion waits until the run starts or startup fails instead of navigating mid-preparation. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix: reconcile main's round-18 features after the rebase Adopts the round's main features into the v2 architecture: the #9023 media rework (streamed videos, media-file assets, protocol-relative links), #9098 shared live-activity row folded into the v2 working and thinking rows, the #9084/#9078 Claude model catalog for v2 consumers, a native #9005 OpenCode child-session abort in the v2 adapter, #9013's landed LegendList patch, and per-environment sidebar provider entries. For #8600 the server-side pieces land, but auto-settle evaluation stays client-side (reading the new server-owned settings) until the v2 orchestrator grows its own settlement reactor; main's v1-only reactor and coalescer additions are dropped with the rest of the v1 path. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(server): evaluate automatic thread settlement in the v2 orchestrator Ports #8600's server-owned settlement to orchestration v2 instead of keeping client-side evaluation. A ThreadSettlementService sweep runs at startup, on auto-settle settings changes, and once per minute: it evaluates inactivity and merged or closed pull requests over v2 thread shells and dispatches the new guarded thread.auto-settle command, which rejects threads that changed after the sweep's snapshot or carry any explicit override, then reuses the orchestrator's settle lifecycle. With the server deciding, the clients drop their effectiveSettled evaluation and partition on the persisted settledOverride like main. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix: reconcile main's round-19 features after the rebase Adopts main's round-19 features into the v2 stack: payload-budgeted orchestration replay (#8992), sidebar row subscription leases (#9052), tool group virtualization and scroll anchoring (#9106), repeated-command and browser-group presentation, inline assistant citations (#9146), per-cwd provider skills discovery (#8778), Claude composer skill dispatch (#9128), grok health probe and model negotiation (#9154), and the failed-tool thinking fallback (#9165). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(web): right-align the stash shoulder tab again Round 17 adopted main's #8850 ComposerBanner.Attachment (mx-auto plus the standalone drawer-inset width) without main's matching mounts, so the stash tab's ml-auto lost to the attachment's auto right margin and the tab centered over the composer. Column now spans its attachments like main does, the stash tab zeroes the right margin, and the stash menu keeps the full dock width. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(web): realign the composer and timeline with main The branch had drifted from main's composer and work-log design in ways unrelated to orchestration v2: a pre-revert "Working for" shoulder tab on the composer (main reverted #8693 and re-landed #8734 without it), an inline stash variant plus in-flow stash menu, expanded tool rows that hid their icons, an unmounted woke-thread banner, a composer scroll observer main never had, and a right-panel toggle that lost its showRightPanelControl gate so it rendered twice with the panel open. ChatComposer and its satellites now start from main's files with only the v2 delta re-applied (dispatch modes, queued-message editing, runtime request ids, response capability). Background tasks surface as a ChatView banner in main's backgroundLiveness shape instead of a composer tab. SimpleWorkEntryRow takes main's PlainWorkEntryRow body with the V2ItemInspector kept behind the expander. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix: reconcile main's round-20 features after the rebase Renumbers the v2 migrations 044-052 to 045-053 behind main's 044_ClearAutomaticProjectModelDefaults, and adopts main's sticky new-thread selection (#9164), local-only worktree bases in the v2 launch path (#8751), the PR summary read for settlement (#9176), Claude per-cwd skills (#9210), the provider editor redesign with the branch's dedicated environment fields re-grafted (#8508), and the client half of continue-threads-across-restart (#9167). The server-side continuation markers stay unported: they live in the v1 session directory, and v2 recovery terminalizes running runs on restart, so the capability is withheld until the v2 runtime carries them. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(server): reduce v2 recovery and runtime resource usage Index event sequence lookups, recover only threads with pending work, and page projection verification and rebuilds. Bound provider event logging and omit turn histories when resuming Codex threads. Allow delegated thread identifiers through relay routes. Add focused regression coverage and document the performance constraints. * fix: reconcile main updates with orchestration v2 Retain main's composer, work-log, settings, mobile and performance changes through c8f77e0d441 while preserving v2 runs, queued messages, provider handoffs and durable history. Port native compaction and logout, asynchronous Codex questions, provider usage accounting, automatic settlement and PR refresh into the v2 services. Bound live event retention during replay and delivery, measure thread replay before decoding, and read checkpoint metadata without loading transcripts or patches. Keep main migrations through 047 and move the v2 migrations to 048–058. Preserve the existing branch history and the pre-rebase backup. Model: GPT-6. Harness: Codex. * fix(orchestration): stabilize Codex turn mapping and settlement - Preserve Codex turn identity while suppressing duplicate diff notifications - Optimize settlement projections and isolate thread visit handling - Add concurrency and regression coverage across server and mobile * fix(chat): match main timer and task placement Restore the completed work timer divider and text size from main. Keep todo-list progress in the composer and omit it from web and mobile timeline entries, including completed task lists. Verified pending, running, and completed task projection; 187 focused web tests and 35 mobile tests pass. Web and mobile typechecks pass. * fix(mobile): restore composer and timeline behavior from main Show Send when a running thread has draft content. Separate submission follow from first-message anchoring so later sends do not reserve extra blank space. Restore Android initial composer insets and iOS focus-aware dictation insets. Keep opening and final assistant replies visible around completed folds, anchoring Worked for at the first hidden item while preserving v2 relationship cards and execution-attempt behavior. Validation: 107 focused tests and the mobile typecheck pass. Formatting passes; scoped lint and React Doctor report warnings but no errors. No simulator run. * fix(orchestrator): Stop treating a wait timeout as a dead child (#7427) * fix(orchestrator): Show when a completed delegated child still has work (#4793) Co-authored-by: Julius Marminge <julius0216@outlook.com> * fix(orchestrator): Stop finished Codex turns from sitting on Waiting (#7105) Co-authored-by: Julius Marminge <julius0216@outlook.com> * chore: format v2 files flagged by CI * test(server): include the shell indexes migration * fix(mobile): pin the patched notifications dependency * fix(client-runtime): resolve work log source imports * test(server): refresh replay runtime instruction expectations * test(server): correlate OpenCode replay message identities * ci: run checks on v2 branch pushes * test(server): use Effect Vitest for Cursor provider checks * fix: reconcile main updates with orchestration v2 Retain main's changes while preserving v2 orchestration, queue/steer controls, composer-only tasks, timeline timers, and mobile scrolling fixes. Port opt-in restart continuation through durable v2 effects, with shutdown race guards, activation gating, retry deduplication, and native Codex resume. Use narrow projection reads for control effects and runtime-request replies. Surface Claude fallback notices without failing the turn or hiding the notice. Report missing workspace folders before provider startup. Carry over custom models and prices, bounded client caches and stream cleanup, lazy image loading, persistent changed-file trees and sidebar filters, Safari cookie import, theme fixes, POSIX file-link case, private-host favicon filtering, native provider update paths, and platform portability updates. Migration ids remain unchanged. Validated scoped typechecks and focused server, web, mobile, client-runtime, contracts, desktop, shared, SSH, script, and resource-monitor tests. Preserved all 347 original commits and checked the final tree against both saved tips. Model: GPT-6. Harness: Codex. * fix(server): explain fetch failures during worktree preparation Worktree preparation previously exposed only a generic fetch failure. Classify known authentication, network, repository access, and reference-lock errors using stable Git diagnostics, without retaining raw output or credentials. Unknown failures keep the existing generic message. Cover failure classification and redaction, a real missing local remote, and propagation into a failed prepared run without creating a worktree or running setup. The launch test waits for the persisted failure event. Validation: 38 focused tests, server typecheck, and scoped lint passed. * fix: reconcile upstream fixes with orchestration v2 Carry main's session refresh, provider maintenance, runtime diagnostics, composer focus, preview, usage, and mobile outbox fixes into the v2 branch. Keep queue/steer submission, composer-only task progress, v2 subagent cards, and LegendList scroll ownership. Project thread and shell events before transport buffering while retaining full durable history. Dismiss native questions when provider turns finish, with a transaction guard that preserves answers submitted concurrently. Port Claude limit notices and Codex file approval details to v2 adapters. Validated with focused server, web, mobile, client-runtime, shared, desktop, and marketing tests; affected package typechecks and scoped lint pass. All 349 branch commits retain their authors and messages. Migration files and the previous worktree-fetch, stash, panel, and mobile inset fixes remain unchanged. * fix(server): make project removal honor v2 threads Offline CLI and HTTP project removal dropped force and left native v2 threads behind. Move the nonempty-project guard and durable child cleanup into the shared project service, and forward force from CLI, HTTP, and WebSocket calls. Reuse the thread deletion planner and command lock, hydrate migrated history before attachment cleanup, and validate child receipts. Commit the project deletion after its children so failed cleanup can be retried safely. Validation covers CLI deletion with active and archived threads, missing workspaces, durable cleanup, partial retries, migrated attachments, receipt collisions, and concurrent thread updates. Scoped server tests, typecheck, and lint pass. Implemented with Codex (GPT-6). * fix(mobile): render generic message attachments (#9929) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com> * fix(mobile): use the archive eligibility guard when dispatching (#9930) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com> * fix(orchestration): persist linked pull requests (#8689) * feat(mcp): update thread metadata (#8690) * fix(server): keep old failures from waking snoozed V2 threads (#9903) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * refactor(shared): share model-selection command choice (#10577) * refactor(project): share create and update inputs (#10578) * refactor(server): share attachment message intake (#10580) * feat(mcp): expose thread organization commands (#10554) * feat(mcp): expose existing queued message commands (#10555) * feat(mcp): expose pending user questions (#10556) * feat(mcp): expose thread model selection (#10557) * feat(mcp): expose fork and merge-back commands (#10558) * feat(mcp): expose preview list and close (#10559) * feat(mcp): expose selected environment preferences (#10560) * feat(mcp): expose the existing thread search query (#10561) * feat(mcp): expose scheduled task run-now (#10562) * feat(mcp): expose project service operations (#10563) * feat(mcp): expose attachment upload and send (#10564) * feat(mcp): expose project thread launch service (#10565) * feat(mcp): expose branch-backed workspace discovery (#10566) * fix(orchestration): map late steering to follow-up turns - Re-route steering that races completion into idempotent follow-up dispatches - Preserve scheduled-task attribution and provider ownership history across clients * fix: reconcile main's round-24 features after the rebase Port main's pull-request discovery, active thread ordering, async question dismissal, settlement fixes, provider-session import, attachment context, and provider correctness changes into orchestration v2. Keep the branch's intentional composer and subagent behavior while adopting main's web and mobile fixes. Prevent headless setup terminals from hanging on the color probe, and move the v2 migration block to 050-061 after main claimed 048-049. * chore: remove accidentally committed audit artifacts * fix(ci): repair rebased checks and stop duplicate runs Restore the failed-before-start timer guard, align two server fixtures with the reconciled behavior, and remove dead files, exports, and dependencies surfaced by Knip. Drop the temporary branch push trigger now that the PR is mergeable, so each update runs the pull-request workflow once. * fix(web): port auto-balance updates to v2 chat Keep main's batch machine-update banner and update action while preserving the v2 runtime-based environment lock used by draft load balancing. * chore: format files exposed by CI * fix: reconcile main's round-26 updates after rebase Adopt TypeScript 7 and Effect rc.112 across orchestration v2, including the TaggedError API migration and updated Effect-aware tests. Restore main's composer-aware scroll-to-end clearance while retaining selected-model settings sync, preview recording transfer, image galleries, desktop context menus, and layout hit targets. Regenerate the lockfile on the upgraded dependency baseline. * fix(web): restore compact load-earlier control * perf(orchestration): bound v2 transport payloads Advertise bounded socket snapshots and authoritative dispatch validation, omit raw command output and inline file bodies at the wire boundary, and preserve compact status metadata across web and mobile. Add transport-budget coverage for snapshots, resume, commands, legacy import, and projection maintenance. * fix(web): preserve tool failures after output redaction * fix: restore sidebar behavior after v2 rebases Restore pinned-thread shelf classification, server-owned unread state, hidden-subagent-safe project ordering, guarded jump hints, draft upload cleanup, and active-provider archive guards across the current and legacy sidebars. Bring the surrounding current-main sidebar work forward as well: canonical project favicons, stable row layout, thread file drops, account-aware mobile provider badges, and deferred desktop keyring loading. * fix(server): consolidate V2 migrations and refine runtime recovery * fix(web): simplify timeline rows and preserve collapsed composer controls * fix(web): smooth composer transitions and group approval worklogs Keep collapsed model controls in a strip, contain transition overflow, and preserve timeline spacing. Render approval requests as regular grouped worklog entries. Implemented with GPT-6-Astra via Codex. * fix: reconcile main updates with orchestration v2 Adapt question attachments and Android push verification to V2 requests and shell events. Preserve composer transitions and compact worklogs while integrating upstream loading, navigation, and mobile changes. Release consumed application replay pages without retaining earlier batches. * fix(server): report OpenCode descendant stop failures * fix(server): abort external OpenCode sessions on release * fix(server): retain thread baseline diffs across root runs * fix(server): fail OpenCode turns on unexpected stream EOF * fix(server): bound OpenCode runtime request replies * fix(client): bound socket resets after cold HTTP failures * fix(server): query only due scheduled tasks during polling * fix(server): retain normalized OpenCode turn usage Accumulate owned step usage once and preserve partial or unavailable telemetry for failed, interrupted, or reconnected turns. * perf(server): scope ordinary control reads to their targets * fix(server): retry initial title generation after transient failures * fix(server): isolate Cursor metadata generation from workspaces * fix(server): preserve Claude Read image previews across clients * fix(web): preserve generic files when editing queued messages * test(server): assert tool output redaction before storage fidelity * test(web): cancel queued animation frames during worker cleanup (#10880) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * fix: reconcile main devices and pull requests with orchestration v2 * feat(providers): add Pi coding agent (#7211) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Mike Olson <mwolson@member.fsf.org> Co-authored-by: Julius Marminge <julius0216@outlook.com> * feat(providers): standardize ACP providers (#6461) Co-authored-by: Julius Marminge <julius0216@outlook.com> * feat: render background completions as typed notifications * fix(mcp): omit recursive screenshot metadata from tool inputs * fix(pi): use native forks and preserve rollback session identity * fix(pi): cap OpenRouter output budgets pending upstream fix * fix(web): show ACP sidebar icons and hold onboarding height while loading * feat(server): deliver delegated completions through a durable mailbox * fix(acp): support Devin terminals, questions, and native subagents * fix(server): find active turns when answering async questions * fix(web): populate sidebar ACP branding from environment settings * fix(acp): preserve native child messages and final summaries * fix(server): distinguish delegated task results from completed turns * test(server): align Codex delegation instruction assertion * test(server): align delegation fixtures with task result semantics * fix(server): classify Claude V2 structured terminal failures (#9897) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * fix(orchestration): exclude rolled-back work from bounded recovery (#8464) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com> * test(orchestration): cover bounded V2 socket fallback paging (#9907) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * fix(server): wait for native Codex start before Stop (#10024) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com> * fix(server): keep the native Grok default model (#10025) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com> * fix(server): fail V2 turns when the OpenCode event stream ends (#9905) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * fix(web): preserve file attachments when editing queued runs (#9928) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * fix(server): preserve project mutation fields across transports (#9920) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * fix(mobile): throttle streaming thread visit updates (#9931) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * fix(orchestrator): preserve task-step elapsed time across restart (#10051) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com> * fix(server): preserve Claude interruption status during steering * fix(server): wait for nested completion delivery before publishing results * test(server): verify background delivery with real providers * fix: keep working timers anchored to the active run * perf: page complete turns and bound timeline reconciliation * perf(client): narrow thread subscriptions and navigation updates * feat(mobile): manage queued messages in a dedicated sheet * fix(web): fold completed trailing background activity * fix: reconcile main settings and previews with orchestration v2 * perf(client): reconcile replay batching with orchestration v2 * fix: reconcile main Codex model selection and UI updates * fix: reconcile main context previews and rewind updates * fix(build): include protobuf and Connect license notices * fix(mobile): pin expo-audio so the release smoke patch stays in use (#11518) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix: reconcile main release and thread updates with V2 * fix: repair v2 CI after environment disable and dead exports ConnectionCatalogEntry gained a required enabled flag in #11478, but the threadShell harness never set it, so enabled-gated atoms filtered every environment out and two tests failed. Two dead exports also tripped knip. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(web): update notification tests for v2 thread shells and drop dead composer state ThreadNotificationCoordinator presents raw OrchestrationV2ThreadShell records, but its tests still fed the pre-v2 thread shape (session / latestTurn), which crashed presentThreadShell on missing DateTime fields. Rebuild the fixtures as v2 shells with pendingRuntimeRequest and run statuses, and remove the composerHasUnsentContent binding left unused by the compaction gating change. * fix(client-runtime): avoid Array#toSorted in thread lineage ordering * fix(server): reject partial output from failed Cursor runs (#11534) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(server): wake paused Cursor replay runs on mismatch (#11535) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(server): load V2 replay fixtures through the platform path service (#11566) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(server): report missing interrupt-and-restart capability for forced restarts (#11565) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(server): preserve Cursor directory and lint search results (#11533) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(server): roll back question attachment copies when respond preparation fails (#11557) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(server): restart the live session on model changes after dead records (#11505) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(server): replay launches with server-allocated thread IDs (#11508) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * fix(web): keep the active-run header with the prompt that started it on steer (#11828) * refactor(web): centralize provider instance icons (#11829) * feat(web): add the thread action menu and inline rename to the chat header (#11830) * fix(web): keep the preview mini-player clear of the inline thread details card (#11831) * fix: reconcile main snooze controls with orchestration v2 * fix(web): adapt registry icons to light and dark themes * fix: reconcile main worktree setup and title changes with v2 * fix(server): isolate V2 migrations from the V1 database * fix(ci): verify V2 branch pushes and remove unused helper * revert: restore existing CI push triggers * fix(web): retain server-side queuing on v2 after rebase * fix(test): account for optional encoded provider settings * fix(build): parse executable imports without matching generated source * fix(build): isolate executable parser from Vite config * fix(server): project legacy thread shells during import * fix(server): replay command events across persistence pages (#11499) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(orchestrator): report terminal runs after wait timeout (#11574) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(server): skip corrupt scheduled-task rows instead of stopping the scheduler (#11585) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(server): preserve due schedules across equivalent time formatting (#11590) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * test(server): replay denied Claude writes through V2 (#11597) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(server): fork Codex threads at the native turn boundary (#11490) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(server): align MCP delegation support with live provider adapter registry (#11578) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * test(server): prove v1 to v2 cutover on a copied database and flag divergent migration ids (#11639) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(server): bound legacy thread projection requests (#10512) * fix: reconcile main thread updates and Git improvements with v2 * fix(mobile): restore permission registry concurrency protection * fix(web): confine composer glass transition to input surface - Move transition glass styling off the host wrapper - Add backdrop saturation to the main composer surface * fix(server): restore hub limits updates in V2 (#11963) Co-authored-by: Julius Marminge <jmarminge@gmail.com> * fix(mobile): reject preview builds from v1 source * fix(mobile): skip preview validation without release credentials * fix: stop retained background work after a turn settles * refactor: remove legacy token streaming * fix: format subagent task names across clients * fix: distinguish unsupported server connections * fix: reconcile main updates with V2 orchestration * fix(server): preserve PR links across V2 discovery and import * fix: reconcile main monograms and PR refresh with V2 * fix(web): reset thread scroll and ignore hydration as a new turn * fix(ci): pin patched Expo core during release resolution * fix(web): invert follow-up behavior with Mod+Enter * fix(web): show linked pull requests in thread details * fix(web): restore main thread-switch scrolling without layout resets * fix: reconcile main setup transitions with V2 threads * fix(mobile): keep cached thread list across relaunch The shared shell cache codec never overrode activityRunStartedAt and unsettledAt with DateTimeUtcFromString, so any snapshot holding a working or unsettled thread encoded fine but failed to decode on the next cold launch. The store discarded the whole row and the Home list stayed empty until the environment reconnected. Add the two overrides and extend the mobile cache round-trip test with a running, unsettled thread so the codec and the JSON overrides stay in sync. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * perf(client): coalesce persistent cache writes during streaming (#12109) * perf(server): suppress unchanged shell enrichment refreshes (#12110) * perf(mobile): skip unchanged thread row renders (#12116) * perf(mobile): yield to UI during shell cache encoding (#12117) * perf(client): narrow mobile and web environment subscriptions (#12126) * perf(mobile): ignore irrelevant config updates in thread lists (#12127) * perf(mobile): limit thread model options to its provider (#12128) * perf(client): stop scanning threads for unused shell timestamps (#12129) * feat(mobile): make the composer pill the hub for the running turn The pill above the composer only tracked queued messages, and a follow-up sent during a turn always queued because mobile hardcoded its dispatch mode. Steering meant sending the message and then promoting it from the queue sheet, and the turn's subagents were only reachable as transcript rows. The pill now carries an agents segment alongside the queue count, scoped to the running turn and hidden once it settles. Tapping either segment opens a sheet: agents lists the turn's subagents and opens a child thread, and the queue sheet is rebuilt on the native header with compact rows, swipe to remove, a context menu, and full editing that saves through queued-run.edit while keeping the message's place in line. Follow-ups become a choice. A Follow-ups settings screen picks queue or steer, the send button says which one it will do, and long-pressing it uses the other for a single message. On a hardware keyboard the Command chord does the same, so the composer text view now reports whether the submit was the alternate and names both chords for the iPad shortcut HUD. Steering travels as "auto" so a turn that ends mid-flight degrades to a queued run instead of bouncing the message back into the draft, and the button only offers Steer when the provider can actually steer. Web's dispatch resolver moves into client-runtime so both clients share it. The lineage banner is gone from the transcript, taking mobile's disconnect action with it; merge back to source now lives in the thread header's git menu. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: reconcile main composer and provider updates with V2 * test(server): restore Cursor usage coverage after V2 rebase * feat(web): add compact PR checks to the workspace card (#11981) * feat(web): show subagent details and history in workspace card (#12079) * fix(server): start V2 provider turn when checkpoint baseline capture fails (#12153) Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(server): retain durable checkpoint index fixes on v2 * fix(server): finalize v2 runs when checkpoint ref lookup fails * fix(server): reject v2 file restore in shared workspaces * fix(mobile): allow changing provider in a started thread (#12184) Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: reconcile main updates with V2 runtimes and timelines * fix: align V2 question and checkpoint timelines across clients * fix(mobile): guard question controls during answer submission * fix: adapt multi-model thread creation to V2 launches * fix: restore V2 worktree setup transitions across clients * fix(mobile): match web provider handoff dividers * feat(mobile): rebuild the Circe orb and add Circe Mesh sign-in The mobile app opened straight into Circe on a fresh install, so a user never saw the step that connects them through Circe Mesh. The voice orb was also the wrong object: a dark blob with fat translucent bands behind it, plus a soft square around its glow on some Android GPUs. Orb - One Skia canvas with six ordered layers: atmospheric glow, rear fibers, the sphere surface, the hull ring, fibers refracted inside the sphere, front fibers, then grain. Three fiber planes are what produce depth; nothing here is a real 3D render. - The body is an SkSL runtime effect that reconstructs a surface normal per pixel, so the sphere lights like an object instead of a flat radial gradient. The ring is modulated by angle, because a uniformly bright ring reads as neon rather than as light. - Fibers are silk filaments, not an audio waveform: 18 rear, 20 refracted interior, 5 front, each with deterministic per-strand variation and a gaussian envelope centred on the sphere. - Motion is split so the sphere feels heavy: it barely moves and the field carries the animation. One frame callback drives the scene, and audio level reaches the renderer as a shared value without re-rendering React. Sign-in - The signed-out gate waited forever on Clerk's isLoaded, so a device that could not reach Clerk skipped Welcome entirely and landed in the app. It now resolves to signed-out after three seconds, and a real stored session still resolves from the token cache without the network. - Adds the Welcome screen and its Clerk auth step, including the Circe Mesh onboarding request that already existed behind it. Theme - The orb follows the app theme. Light and dark share geometry and differ only in luminosity: dark leans on the rim and pulls the bloom back. Dev tooling - The orb gallery was gated on process.env.APP_VARIANT, which Expo never inlines into the bundle, so the route never registered. Now gated on __DEV__. It exposes every state, both appearances, three sizes, and three levels. Both soft-edge traps found here are silent: `opacity` on a large radial-filled shape and BlurMask each make Skia allocate a layer, which renders as a soft-edged square on some Android GPUs. Every soft edge in the orb is a gradient with its alpha baked in, so no layer is allocated. * fix(mobile): render the orb as a dark lens, not a lit copper sphere The previous orb was technically competent and visually wrong. It modelled a conventional lit solid sphere: the shader reconstructed a surface normal, applied directional light from the upper-left, and started the body gradient at a bright cream `hotColor`. That is a polished orange ball, which is what it rendered. The palette file in the same commit already said the middle of the sphere must read as near-black, so the code contradicted its own design. Replaced the rendering model rather than re-tuning colors. Dark base and a separate transparent shell - `OrbSurface` is split into `OrbBase` (opaque, `core`/`coreWarm`/`ember` only, no directional term) and `OrbShell` (transparent hull light). `hot` is now only ever a thin lip or a subsurface accent, never a fill. Interior fibers moved inside the glass - The refracted fiber plane now renders between the base and the shell. It previously rendered after an opaque sphere, so the strands could only look printed onto a surface. The ring is the shell, not a stroke - Removed the uniform 360-degree `Path` circle that painted over the shader's angular variation and cancelled it out. The shell pass carries an uneven profile built from three angular harmonics plus a travelling phase, and the only hard edge is a roughly one-pixel lip at the hull. Refraction instead of compression - Interior strands were squeezed by constant `x *= 0.91 / y *= 0.82`, which reads as a narrowed bundle. They now derive a lens depth from the horizontal position and use it both to pull the strand toward the optical axis and to shift its phase, so the fiber visibly bends as it enters the sphere. Fewer, quieter strands - 43 strands down to 20 (11 rear, 7 interior, 2 front), average alpha roughly halved, and one hero strand per plane instead of every fifth strand being equally prominent. The field should be perceived, not counted. Motion is time-based and far slower - The field advanced a fixed increment per rendered frame, so a 120 Hz device drifted twice as fast as a 60 Hz one and a full cycle took about half a second. It now advances by elapsed time; `fieldCycleSeconds` is 11 s at rest and 5 s while listening. The sphere itself only breathes. One state model instead of a dozen unused knobs - `waveAmp`, `massIntensity`, `glowResponse` and `strandAmplitudeScale` were varied by state and never read by the renderer. Replaced with six parameters that are all consumed, and a single microphone `energy` value that scales field amplitude, shell brightness, bloom, and core warmth together. Scene bounds - The welcome canvas was `size + 2 * size * 0.95`, about 487 dp tall for a 168 dp sphere, which opened a large gap between the copy, the orb, and the auth controls. The vertical padding is now independent of the fiber field at roughly 26% of the sphere. Grain is off at rest so the idle frame stays clean. Also syncs the stable web icon filenames from `assets/circe`, which `scripts/lib/circe-boot-assets.test.ts` asserts byte-for-byte and which the regenerated assets had left stale. Verified on a physical Android device in both appearances and in the orb gallery across states and sizes. * feat(mobile): adopt Circe design system v1 tokens and shell lighting Mobile was still carrying the pre-v1 palette: a cool blue-gray dark surface (`#16181b`), a cool `#0f1620` Circe canvas, an off-brand amber primary (`#96600a` / `#c99a2e`), and a serif stack that led with Times New Roman. The design system asks for warm layered near-black, warm ivory paper, restrained copper as the single brand accent, and an editorial serif. Tokens (global.css, mobileTheme.ts, regenerated uniwind themes) - Dark surfaces are now the layered warm near-black set: canvas `#0c0d0e`, surface `#121415`, raised `#191b1d`, hover `#1e2022`. Pure black is out. - Light surfaces are warm ivory: canvas `#fcf9f4`, surface `#fffdfa`, raised `#f6f0e9`, hover `#f2ebe4`. - Borders move to low-opacity warm rules: `rgba(56,43,35,.07/.13/.20)` on light, `rgba(255,255,255,.065/.10/.16)` on dark, replacing opaque beige borders. - Copper becomes the primary action token: `#a5482c` on light for legibility, `#e08a63` on dark. The brand accent is identical in both appearances. - Circe tokens gain the full v1 set: copper ramp, peach, semantic success, warning, danger and neutral, plus surface, surface-raised, and copy. Status colors are now semantic only rather than decorative. - The display serif drops Times New Roman, which the design system rules out, for a stack led by Iowan Old Style. Bundling Instrument Serif needs a native rebuild and is deliberately left as a separate change. Orb shell (§13) - The palette moves onto the v1 ramp: `#100e0d` core through `#6d3526` deep copper, `#e18a62` copper, `#ffd8bd` peach, `#fff4e9` hot lip. - The shell's angular profile is now three art-directed light lobes instead of a sum of harmonics: the strong warm regions sit upper-left and lower-left, and a narrow brilliant flare sits on the right edge. Each lobe drifts slowly. - The copper band starts around 81% of the radius, matching the design system's gradient stops, so the falloff is broad rather than a hairline. - Bloom becomes two passes matching the specified glow: a broad atmosphere that spills past the hull and a narrow warm glow hugging the shell. Welcome screen - Adopts the light onboarding treatment: warm ivory paper, near-black editorial ink, one burnt-copper phrase, a near-black primary CTA whose only brand cue is a restrained copper hairline, and low-opacity warm borders. Tests - `uses the Circe graphite palette as the default` asserted the old hexes and is replaced with the v1 invariants: light paper is warm (red leads blue), dark is a layered near-black that is neither pure black nor a colored slate, and copper is the same accent in both appearances. - The hard-coded variable count in the palette-role test is replaced with the presence of every Circe token, which is what the code actually depends on. * fix(mobile): give the orb volume and rebuild the field as one ribbon The previous pass over-corrected. Adding a dark base and a separate shell did fix the order, but nothing was left between them, so the sphere rendered as a near-uniform black disc under a hairline of light. Two causes, both structural. There was no volume layer - `OrbBase` stays in `#100e0d`-`#1a100c` and `OrbShell` only lights the hull, so the region in between had no light at all. - Adds `OrbVolume`, a transparent pass between the interior ribbon and the shell. It carries broad low-frequency copper across the outer 40-50% of the sphere plus two asymmetric lobes, a lower-body glow and a left-side light. Its alpha is capped at 0.42 and it never reaches white, so it reads as smoked glass rather than a second opaque sphere. - The shell's `pow(1 - z, 2.4)` falloff was the other half of the problem: it is near zero until the final pixels. Replaced with two explicit art-directed fields starting around 46% of the radius. This is brand artwork, not a physically correct rim term. The field was twenty independent sine waves - Every strand had its own frequency, amplitude, phase, offset and speed, which mathematically wants to become spaghetti however few strands remain. - `WaveField` is replaced by `RibbonField`: one shared centerline carrying a broad S-curve, with eight filaments as small offsets from it, so the group reads as a single piece of silk. Five faint atmosphere fibers keep their own trajectories at alpha 0.04-0.10. - Both centerline harmonics carry integer phase coefficients, so the curve returns to its exact starting shape after a phase revolution and the keyframe interpolation stays seamless. Refraction is now visible - The interior plane delays the shared centerline's phase by lens depth, grows its amplitude inside the glass, and pinches the bundle by up to 42% toward the optical axis at the centre. Interior filaments are roughly 1.5x more visible than before, so you can see the strands enter the object. - The front plane carries only the two highlighted filaments rather than a second full field. State wiring - `fieldAmplitude` was defined and tested but never read by the renderer, so tuning it did nothing. It now scales the path amplitude, and changing state rebuilds the interpolated frames. - Bloom is documented as microphone-responsive but `OrbGlow` was never passed the level. It now receives `energySV` and its three gradient fields genuinely respond. `alphaColor` is a worklet so the stops are built on the UI thread. - Adds a regression that fails if any `OrbStateParams` key has no consumer in a production renderer file. That is the class of bug this commit is fixing. Glow is now three separate fields rather than one: a broad peach atmosphere at about 1.55R that visibly lights the page around Circe, a medium warm bloom, and a localized shell aura. * feat(mobile): build a dedicated welcome hero illustration The welcome screen was a standard auth page with the product orb dropped into it. The orb was shared with the home and voice screens, so every attempt to make it a brand hero traded off against its job as a state indicator: it came out either too dark to be a focal point, or too luminous to read as "idle". The real problem was the abstraction, not the shader. Separates the two visual systems - `CirceOrb` stays the product orb: home, voice, listening, thinking, speaking, compact, interactive, stateful. - `CirceWelcomeHero` is a new, decorative brand illustration used only on the welcome and auth screens. It has no states, no audio input, and no interactivity, so it is free to be bright. - Both remain in the same canvas so the illustration is one composition rather than several widgets stacked in a column. Rebuilds the page composition - The hero now sits above the headline. It is full-bleed, cancelling the screen padding, so it reads as artwork rather than an inset widget. - Order is logo, hero, headline, subcopy, CTAs, divider, benefits, legal. The hero is one wide canvas, 300dp tall, with this layer order - atmosphere, so the page picks up warmth around the object - halo arcs, four flattened ellipses at very low alpha - rear ribbon fan - orb core, then the interior ribbon clipped and refracted through it - front filaments crossing over - dust motes The orb is luminous now, not a dark ball - A dedicated shader climbs warm brown, copper, then peach, holding the deep core to about 30% of the visible area rather than most of it. The previous product-orb treatment was near-black across the whole body, which is correct for a state indicator and wrong for a focal point. - The rim is modulated by three angular harmonics plus a travel phase, so it is never uniformly bright. A value hash adds faint grain so the volume is not a mathematically smooth disc. The ribbon is one flow field, not independent sine waves - A single master spline crosses the hero. Every filament is an offset from that curve, so the strands stay related and read as one piece of silk. - The bundle is tight where it passes the orb and opens toward the edges, which produces the left and right fans from a single construction. - Inside the glass the shared curve is phase-delayed, amplified and pinched toward the optical axis, so the fan visibly narrows as it passes through the object instead of merely being clipped by it. - Both harmonics carry integer phase coefficients, so the curve returns to its exact starting shape after a phase revolution and the loop stays seamless. Motion is slow drift only, driven by wall-clock time so it is identical at any refresh rate, and fully suppressed under reduced motion. Two things worth recording for the next pass. The first ribbon attempt opened the bundle from 8% to 123% of the orb radius within half a screen, which read as a bowtie starburst rather than a ribbon; the spread is now deliberately gentle. Second, the fallback for a driver where the runtime effect will not compile has to be its own component: `RadialGradient` and `Shader` both use hooks, so swapping them inside one component changes that component's hook order between renders. The hero is also surfaced in the development orb gallery, since the welcome route redirects as soon as a session exists and is otherwise hard to inspect. * refactor(mobile): rebuild the welcome hero as a woven ribbon over a lit sphere The hero looked wrong for structural reasons, not tuning reasons. The ribbon morphed its whole spline once per cycle, and the orb was a dark procedural sphere with the interior ribbon painted on top of it. Correctness - Removes geometry morphing entirely, which removes the class of bug rather than patching it. `ribbonPhase` was emitted in [0, 2*pi] while `usePathInterpolation` expects a [0, 1, 2, 3] input range, and `masterCurve` and the per-strand jitter carried half-phase coefficients, so the geometry at 2*pi did not equal the geometry at 0 and the loop had a real seam. - The illustration is a brand mark, not an audio waveform. The centreline is now frozen. Life comes from a highlight travelling along the ribbon and from a rigid 4dp drift over 12s, both implemented as slow out-and-back ramps, so there is no loop boundary to seam in the first place. - Fixes the compositing order. The glass shell is now painted after the clipped interior ribbon, so the strands genuinely sit inside the sphere instead of on top of it. The ribbon is now a woven surface - One art-directed Catmull-Rom centreline, and every strand is offset along that curve's own perpendicular rather than in raw Y. Parallelism is the point: the perpendicular separation between adjacent strands is exactly `|offsetA - offsetB| * halfWidth` at every sample, and the test asserts it. A Y-offset construction only holds where the curve is horizontal and drifts apart through every bend. - 24 filaments, ordinary 0.55-0.8dp, hero 0.9-1.15dp, glow at 2.8x core width and low alpha rather than a 6x fuzzy halo. - The bundle contracts around the sphere and fans toward both edges, which is what makes the mesh read as converging on the object. - Interior geometry is only built across the sphere plus a margin, since it is clipped to the sphere; building it across the full hero width tripled the stroked segment count for nothing. The orb is now two baked layers - `hero-orb-body.webp` and `hero-orb-glass.webp`, generated by `scripts/generate-circe-hero-assets.ts`. Radius-driven shader ramps read as concentric bands: they cannot express asymmetric directional lighting, a Fresnel rim or a specular lobe. The asset is shaded from the reconstructed sphere normal with a key and fill light, a directional terminator, a subsurface glow for internal illumination and limb darkening. - The glass face is nearly clear, carrying only the Fresnel rim and two specular lobes. A broad sheen across the face fogged the body into polished metal, which is the opposite of glass over warm copper. - Full-surface hash grain is gone. It read as dithering and broke up the volume; it is replaced by 20 discrete internal light motes. - `CirceOrb` remains fully procedural for product states. The interior strands are shifted hot and lifted slightly. At the same copper as the body they vanished into it entirely, which is how the first pass shipped with an invisible interior ribbon. Hero orb radius drops to 0.215 of the width, clamped to 76-88dp, so the mesh dominates the composition rather than the sphere. The gallery gains a Frozen/Live motion switch and defaults to frozen, so a still frame can be judged before motion is allowed to excuse anything. * perf(mobile): cut per-frame work in the welcome hero ribbon Reduces the cost of the woven surface. These are defensible reductions in work per frame; see the caveat below on what I could and could not verify. - Ordinary strands no longer carry a highlight gradient. Every one of the 72 filament instances used to create two animated derived values, so all of them re-evaluated a worklet and allocated a point on every frame. The gradient now lives in its own component used only by the four hero strands. - Stroke joins are miter rather than round. Skia emits join geometry at every vertex, and this ribbon is a densely sampled polyline, so round joins were generating thousands of join primitives. At this sampling density the two are visually identical. - Sampling drops from 26 to 14 steps per segment. Stroke geometry is generated per segment, so this is a direct cost driver. - The halo pass is limited to the strands meant to catch the light. Wide translucent strokes are pure fill rate and overdraw, and a halo on all 24 strands across three planes was the largest single contributor. Measurement caveat, recorded because it is easy to misread: the screen renders at the same frame time with the hero removed entirely, so this change is not demonstrably responsible for any measured improvement, and `dumpsys gfxinfo` on this device reports internally inconsistent numbers (455 frames over 12s is a 26ms average, while the same sample reports a 61ms median). Do not treat the hero as the performance owner for this screen without a cleaner instrument. * refactor(mobile): art-direct the hero orb assets and align the hero vocabulary The previous pass produced a planet. The body had a directional falloff down to 0.24 and a round specular, which reads as a sphere under a hard key light rather than as the reference's luminous object. The shading is now art-directed rather than physical. Body (`hero-orb-body.png`) - Ramp is deep brown through warm brown and copper to peach-copper, matching the reference palette rather than the previous darker set. - The directional falloff floor rises from 0.24 to 0.45, so the shadow side stays warm brown. That single number was responsible for the planet look. - Limb darkening drops to a mild term. The fresnel rim belongs to the shell layer and should not be doubled up here. - The suspended specks are baked in. Rendering them live was a second source of truth for something that never moves. Shell (`hero-orb-shell.png`) - One anisotropic highlight streak replaces the round specular. Studio lighting reads as an elongated streak; a round dot reads as a shiny ball. - The rim is biased so it is stronger top-left, top and right rather than uniform all the way round. - The outward bloom is much tighter. The first attempt kept near full strength across the entire image margin, which rendered as a solid opaque donut around the sphere. - The face stays at 0.012 alpha, verified from the exported alpha profile, so the shell adds a rim and a streak without flattening the body's depth. Both layers now place the sphere at 0.93 of the half-image, reserving margin for the bloom to extend past the silhouette. The generator and the components share `HERO_ASSET_SPHERE_SCALE`, because a mismatch here silently misaligns the rim against the body edge. Interior mesh brightness is reduced. Pushed harder it read as a glowing stripe cutting the sphere rather than as light travelling through glass. Files are renamed to the hero vocabulary: `HeroRibbonMesh`, `HeroHaloArcs`, `HeroAmbientParticles`, `HeroOrbShell`. The geometry module keeps its specific name rather than becoming `heroMath`, since it holds ribbon geometry and not general math. * refactor(mobile): replace the welcome hero renderer with the approved illustration The hero is now the approved reference artwork, supplied as a single transparent plate. Everything the previous passes built to approximate it is deleted. Why the replacement rather than another pass - `scripts/generate-circe-hero-assets.ts` computed a sphere normal, applied key/fill dot products, a directional shade term and limb darkening, then rasterized the result. That is cached shader maths carrying a PNG extension, so it inherited every limitation of the procedural sphere it replaced and read as a glossy planet. - The mesh was one Catmull-Rom centreline with filaments offset along its normal. That construction keeps strand ordering fixed for the whole length of the ribbon, so it can only ever draw a bent sheet of parallel strands. The reference has strands that cross and change depth, fans that differ left from right, and ribbon width that varies deliberately. Those relationships are the design, and deriving them independently then compositing them at runtime produced a belt around a ball. - The layer order was correct and the alpha profile was mathematically correct the whole time. Neither of those was the problem, which is exactly why implementation-level checks kept passing while the screenshot stayed wrong. Deleted: `scripts/generate-circe-hero-assets.ts`, `HeroRibbonMesh`, `HeroHaloArcs`, `HeroAmbientParticles`, `HeroOrbBody`, `HeroOrbShell`, `heroRibbonGeometry` and its test, `heroTokens`, and both generated orb layers. What replaces them - `apps/mobile/assets/circe/welcome-hero-base.png`, 1536x1024 with real transparency, rendered as one image. - `CirceWelcomeHero` is a plain React Native image at the plate's own aspect ratio, so the composition is never cropped or distorted. There is no Skia canvas left in the hero, because there is no longer any Skia content to compose with. - Static by design. The previous revision drifted the mesh 4dp every 13s and swept a highlight along it; for a brand illustration, movement should come from light and only after the still frame matches. There is no animation to approve yet. Layout moves the hero below the subcopy, which is where the reference puts it. Asset note: the plate is 2.2MB as PNG. It is committed exactly as supplied; converting to WebP would cut it to roughly 200KB with no visual change if that matters for bundle size. * feat(mobile): finish the welcome screen against the reference Composition and typography now match the approved reference, and the screen fits without scrolling. Authored type rather than a system stack - Bundles Instrument Serif from @expo-google-fonts. It matches the reference's high-contrast editorial serif with ball terminals, and it is what the design system already named for identity moments while noting it needed a rebuild. - Registered natively in app.config.ts so release builds pay no runtime cost, and also loaded at runtime in App.tsx so a dev client built before this change can still render it without a full native rebuild. - The headline sets `fontFamily` explicitly on both spans. It previously layered a serif class over AppText's font-sans, and the two were fighting. Real brand assets - The wordmark uses the approved `circe-mark.png` instead of a redrawn SVG ring. - The Google mark was a single blue shape: the canonical four-colour paths had the blue quadrant duplicated as a full outline, which painted over the other three. Replaced with the correct brand paths. The hero no longer wastes height - The supplied plate carried about 250px of fully transparent margin above and below the mesh, which at hero scale became ~60dp of dead space and pushed the whole sign-up screen into a scroll. The plate is cropped to its content bounds (margins only, no artwork removed) and re-encoded as WebP: 2.2MB to 540KB. - The viewport is now derived from the scaled plate rather than a fixed `245-260dp`, so the composition holds across widths instead of leaving a gap on tall screens and cropping on short ones. Layout - Hero sits directly under the wordmark and above the headline, as instructed. - Headline copy is now "Talk to every machine, / from anywhere.", which covers the voice and remote aspects in two balanced lines. The previous first line was long enough to spill onto a third. - Removed the benefit row. It read as filler rather than information, and it was the last thing keeping the page scrollable. - The account link is copper throughout, the primary CTA carries a copper hairline and a copper shadow cast, and the legal links are underlined and open the real Terms and Privacy URLs in the in-app browser. * feat(mobile): rebuild the Circe orb, live voice, and no-device state Orb: port the Web Threads field to SkSL (rear field, rim caustic, refraction), keep the idle lens clean, and tune appearance. Live voice: caption shows Circe only, one failure notice instead of two, mint only on an online node, and delegate corrections/quick actions without depending on the speech model's judgement. Weather/time: propose the deterministic lookup in the bounded grammar before the project guard so quick actions never fall through to a chat model. Home: replace unusable controls with an honest no-device state, and show a connecting placeholder on cold start instead of a false no-device claim. * fix(mobile): align the theme bridge test with the design system tokens The generator test still asserted the pre-design-system screen colors (#faf7f1 / #16181b) while the authored global.css and the generated bridge use the v1 warm-paper palette (#fcf9f4 / #0c0d0e). Regenerate the committed bridge (alpha normalized to 0.2) and assert the authored values. This unblocks the mobile PR after its rebase onto main. * test(circe): register merged upstream migrations 67-69 in the manifest tests The upstream orchestration V2 merge added three migrations above Circe's shipped 41-66 slots. MigrationsRemap and the V2 migration test still asserted a contiguous manifest ending at 66 and V2 at upstream's id 53, so both failed. Extend the expected manifest to 69 and assert the Circe-remapped V2 slot while keeping the schema and index checks intact. * fix(circe): reconcile web imports with the merged V2 client surfaces The orchestration V2 merge removed exports the web app still imported, so the web bundle failed to resolve ../T3Wordmark and two components referenced removed APIs at runtime. Point V2LifecycleRow at CirceWordmark, render provider rows through the centralized ProviderInstanceIcon instead of the removed PROVIDER_ICON_BY_PROVIDER map, and use the V2 useThreadProjection hook in place of the retired V1 useThread. * test(circe): exercise the message-context migration at its remapped slot The upstream ProjectionThreadMessageContext migration registers at 67 on the Circe line, but the test migrated to 51 and asserted id 51 (CirceFollowUpQueue), so it never exercised the guarded migration. Migrate to 66, keep the manual column, then apply 67 and assert migration 67 was recorded. * test(circe): replay in shared workspaces and guard foreign databases V2 file restore now requires an isolated worktree, but the replay and fork fixtures dispatch checkpoint.rollback in a shared workspace while asserting conversation rewind, so they are conversation-only (restoreFiles: false). Drop the upstream-numbered LegacyV1Cutover integration test and cover the real invariant instead: a database recording another product's history under a Circe migration id is refused with ForeignDatabaseError. * fix(circe): map the V2 thread runtime to desktop orb statuses The orb bridge read session.status and backgroundLiveness, which the V2 shell removed, so the desktop orb mis-rendered agent status and failed typecheck. Map preparing/queued/starting to starting, running to running, waiting to waiting, and pending background tasks to monitoring, and update the fixtures. * test(circe): read the foreign-database defect with the Effect 4 Cause API * fix(circe): apply V2 module deletions and reconcile ownership guards * chore(circe): re-key service tags and align sqlite runtime with V2 Service Context tags across apps/server/src still carried upstream `t3/...` keys while the package name makes the expected deterministic key `@absterrg0/circe/...`. Re-keyed all 56 declarations, including the nine orchestration-v2 services whose class-suffixed keys (e.g. `.../CommandPolicy/ CommandPolicyV2`) the prefix-only pass did not reach. Also: - Aligned persistence/Laye…
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com>
Stop waits for native Codex turn/started when turn/start acknowledges a queued turn with a null start timestamp. If the turn fails before starting, Stop finishes without sending an invalid interrupt.
Rebased onto current v2, preserving the original feature commit. The prerequisite redaction assertion is already in v2.
Validation: both new regression cases fail with the base adapter and pass with this patch; all 61 Codex adapter tests pass. Server typecheck and scoped formatting pass. CI and the requested Claude Fable 5.1 review are being checked before merge.
Prepared by GPT-6 Astra in the Codex/T3 harness.
Review follow-up: the native-start wait now has a ten-second deadline. If Codex never starts or terminalizes the turn, Stop reports an error and executes the existing lineage finalization and interrupt-state cleanup. The added timeout regression hangs on the previous head and passes with the fix.