Skip to content

fix(server): preserve project mutation fields across transports - #9920

Merged
juliusmarminge merged 1 commit into
pingdotgg:t3code/codex-turn-mappingfrom
saphid:fix/v2-project-lifecycle-20260905
Sep 11, 2026
Merged

juliusmarminge merged 1 commit into
pingdotgg:t3code/codex-turn-mappingfrom
saphid:fix/v2-project-lifecycle-20260905

Conversation

@saphid

@saphid saphid commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

HTTP and offline CLI project mutations dropped options that the WebSocket path preserved, including auto-pull, icons, and the default thread environment. Share one mutation mapping across all three transports so the same command has the same behavior.

Reduced to the missing transport-parity fix after an independent audit. Seven focused project tests, server typecheck, scoped lint, and formatting pass.

Prepared with Codex GPT-6-Astra; independently reviewed by Claude Fable 5.1 in T3 Code.

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Sep 5, 2026
@juliusmarminge
juliusmarminge force-pushed the t3code/codex-turn-mapping branch from 877b9de to b82facd Compare September 5, 2026 04:52
Comment thread apps/server/src/project/ProjectMutationThreads.ts Outdated
Comment thread apps/server/src/project/ProjectService.ts Outdated
@cursor

cursor Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

This PR is too large for Bugbot to review. It changes 99,214 lines and 4,021,163 characters. Split the change into smaller pull requests to get a review.

@macroscopeapp

macroscopeapp Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Macroscope has since reviewed this pull request. An earlier review was skipped by a cost limit; a review has now completed, so that notice no longer applies.

@github-actions github-actions Bot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Sep 5, 2026
@juliusmarminge
juliusmarminge force-pushed the t3code/codex-turn-mapping branch from b82facd to 2ac9bfe Compare September 5, 2026 04:56
@macroscopeapp

macroscopeapp Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The PR centralizes project-mutation mapping and restores fields across CLI, HTTP, and WebSocket transports. Human review is warranted because forwarding autoPull can activate existing background Git pulls, including network I/O and checkout changes, for transports that previously dropped the setting.

You can add or adjust custom eligibility rules. Learn more.

@saphid
saphid force-pushed the fix/v2-project-lifecycle-20260905 branch from 568ca7c to 8cc6348 Compare September 5, 2026 05:11
@github-actions github-actions Bot added size:XL 500-999 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Sep 5, 2026
Comment thread apps/server/src/project/ProjectMutation.ts Outdated

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 8cc63487e475b89e6416f622f0efac36c9206226. Configure here.

Comment thread apps/server/src/project/ProjectMutation.ts Outdated
Comment thread apps/server/src/project/ProjectMutation.ts Outdated
Comment thread apps/server/src/project/ProjectMutationThreads.ts Outdated
Comment thread apps/server/src/project/ProjectService.ts Outdated
@saphid
saphid force-pushed the fix/v2-project-lifecycle-20260905 branch from 1bd11aa to 72f1ed4 Compare September 5, 2026 05:54
@saphid

saphid commented Sep 5, 2026

Copy link
Copy Markdown
Contributor Author

Rebased and reduced this PR onto Julius’s b9fa1399c project-deletion implementation. New head: 72f1ed4ac. The duplicate deletion planner/facade is removed; the remaining delta preserves transport fields, validates parent receipts, retries rejected children with fresh IDs, and guards both project/thread commit orders. The earlier race/retry fixes remain covered on this new implementation. All 16 focused tests, prepared server typecheck, and targeted lint pass.

@github-actions github-actions Bot added size:L 100-499 changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Sep 5, 2026
Comment thread apps/server/src/orchestration-v2/EventSink.ts Outdated
Comment thread apps/server/src/orchestration/Layers/OrchestrationEngine.ts Outdated
Comment thread apps/server/src/orchestration/Layers/OrchestrationEngine.ts Outdated
@cursor

cursor Bot commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@juliusmarminge
juliusmarminge force-pushed the t3code/codex-turn-mapping branch 3 times, most recently from efd9994 to 6102d00 Compare September 8, 2026 06:23
@saphid
saphid force-pushed the fix/v2-project-lifecycle-20260905 branch from 8cf9f83 to 9bc3afa Compare September 9, 2026 00:59
Comment thread apps/server/src/orchestration-v2/EventSink.ts Outdated
@juliusmarminge
juliusmarminge force-pushed the t3code/codex-turn-mapping branch 2 times, most recently from ed5dc41 to 2b1139a Compare September 10, 2026 19:28
juliusmarminge pushed a commit that referenced this pull request Sep 15, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 15, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 15, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 15, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 15, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 16, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 16, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 16, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 16, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 16, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 17, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 17, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 17, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 17, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 17, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 17, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 18, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 18, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 18, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 18, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 18, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Absterrg0 added a commit to Absterrg0/circe that referenced this pull request Sep 18, 2026
* fix(web): keep queued message editing inside the queue panel

* fix(web): keep queued messages in place while editing

* fix(web): match composer actions to draft and modifier state

* fix(web): keep composer shortcut tooltip stable on Mod

* feat(web): summarize T3 orchestration actions

* feat(mobile): port chat summaries and transitions to orchestration v2

Adapt grouped tool summaries and the floating working timer to V2 run, attempt, and queue state. Bring over the composer, keyboard, and disclosure transitions while retaining the V2 activity inspector and queue controls.

Keep OV2 web composer and grouping behavior intact; share only the existing command label parser with mobile.

* fix(chat): remove added tool summary status counts

* fix(mobile): keep scroll bounds current after animations

* fix: reconcile main's round-17 features after the rebase

Restores main features dropped by the policy replay: #8569 theme wiring,
settings search rework, #8803 workspace-mutation refresh (v2-adapted),
video + image previews (web and mobile, v2-adapted), #8862 Expo glass,
and the round's docs. Timeline thinking rows (#8984) stay on the v2
work-live system.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(web): port working and thinking timeline rows to orchestration v2

The v2 equivalents of main's #8984 and #8922: a "Working for ..." header
anchors the active run, the trailing live tool row survives between
actions in past tense instead of vanishing, and a shimmering Thinking
row marks reasoning gaps. During workspace preparation the header shows
"Setting up worktree..." (driven by the local dispatch flag or the v2
run's preparing status, so remote viewers see it too), the composer
footer span is gone, and draft promotion waits until the run starts or
startup fails instead of navigating mid-preparation.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: reconcile main's round-18 features after the rebase

Adopts the round's main features into the v2 architecture: the #9023
media rework (streamed videos, media-file assets, protocol-relative
links), #9098 shared live-activity row folded into the v2 working and
thinking rows, the #9084/#9078 Claude model catalog for v2 consumers,
a native #9005 OpenCode child-session abort in the v2 adapter, #9013's
landed LegendList patch, and per-environment sidebar provider entries.
For #8600 the server-side pieces land, but auto-settle evaluation stays
client-side (reading the new server-owned settings) until the v2
orchestrator grows its own settlement reactor; main's v1-only reactor
and coalescer additions are dropped with the rest of the v1 path.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(server): evaluate automatic thread settlement in the v2 orchestrator

Ports #8600's server-owned settlement to orchestration v2 instead of
keeping client-side evaluation. A ThreadSettlementService sweep runs at
startup, on auto-settle settings changes, and once per minute: it
evaluates inactivity and merged or closed pull requests over v2 thread
shells and dispatches the new guarded thread.auto-settle command, which
rejects threads that changed after the sweep's snapshot or carry any
explicit override, then reuses the orchestrator's settle lifecycle.
With the server deciding, the clients drop their effectiveSettled
evaluation and partition on the persisted settledOverride like main.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: reconcile main's round-19 features after the rebase

Adopts main's round-19 features into the v2 stack: payload-budgeted
orchestration replay (#8992), sidebar row subscription leases (#9052),
tool group virtualization and scroll anchoring (#9106), repeated-command
and browser-group presentation, inline assistant citations (#9146),
per-cwd provider skills discovery (#8778), Claude composer skill
dispatch (#9128), grok health probe and model negotiation (#9154), and
the failed-tool thinking fallback (#9165).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): right-align the stash shoulder tab again

Round 17 adopted main's #8850 ComposerBanner.Attachment (mx-auto plus the
standalone drawer-inset width) without main's matching mounts, so the
stash tab's ml-auto lost to the attachment's auto right margin and the
tab centered over the composer. Column now spans its attachments like
main does, the stash tab zeroes the right margin, and the stash menu
keeps the full dock width.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(web): realign the composer and timeline with main

The branch had drifted from main's composer and work-log design in ways
unrelated to orchestration v2: a pre-revert "Working for" shoulder tab
on the composer (main reverted #8693 and re-landed #8734 without it),
an inline stash variant plus in-flow stash menu, expanded tool rows that
hid their icons, an unmounted woke-thread banner, a composer scroll
observer main never had, and a right-panel toggle that lost its
showRightPanelControl gate so it rendered twice with the panel open.

ChatComposer and its satellites now start from main's files with only
the v2 delta re-applied (dispatch modes, queued-message editing, runtime
request ids, response capability). Background tasks surface as a
ChatView banner in main's backgroundLiveness shape instead of a
composer tab. SimpleWorkEntryRow takes main's PlainWorkEntryRow body
with the V2ItemInspector kept behind the expander.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: reconcile main's round-20 features after the rebase

Renumbers the v2 migrations 044-052 to 045-053 behind main's
044_ClearAutomaticProjectModelDefaults, and adopts main's sticky
new-thread selection (#9164), local-only worktree bases in the v2 launch
path (#8751), the PR summary read for settlement (#9176), Claude per-cwd
skills (#9210), the provider editor redesign with the branch's dedicated
environment fields re-grafted (#8508), and the client half of
continue-threads-across-restart (#9167). The server-side continuation
markers stay unported: they live in the v1 session directory, and v2
recovery terminalizes running runs on restart, so the capability is
withheld until the v2 runtime carries them.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(server): reduce v2 recovery and runtime resource usage

Index event sequence lookups, recover only threads with pending work, and page projection verification and rebuilds. Bound provider event logging and omit turn histories when resuming Codex threads.

Allow delegated thread identifiers through relay routes. Add focused regression coverage and document the performance constraints.

* fix: reconcile main updates with orchestration v2

Retain main's composer, work-log, settings, mobile and performance changes through c8f77e0d441 while preserving v2 runs, queued messages, provider handoffs and durable history.

Port native compaction and logout, asynchronous Codex questions, provider usage accounting, automatic settlement and PR refresh into the v2 services. Bound live event retention during replay and delivery, measure thread replay before decoding, and read checkpoint metadata without loading transcripts or patches.

Keep main migrations through 047 and move the v2 migrations to 048–058. Preserve the existing branch history and the pre-rebase backup.

Model: GPT-6. Harness: Codex.

* fix(orchestration): stabilize Codex turn mapping and settlement

- Preserve Codex turn identity while suppressing duplicate diff notifications
- Optimize settlement projections and isolate thread visit handling
- Add concurrency and regression coverage across server and mobile

* fix(chat): match main timer and task placement

Restore the completed work timer divider and text size from main. Keep todo-list progress in the composer and omit it from web and mobile timeline entries, including completed task lists.

Verified pending, running, and completed task projection; 187 focused web tests and 35 mobile tests pass. Web and mobile typechecks pass.

* fix(mobile): restore composer and timeline behavior from main

Show Send when a running thread has draft content. Separate submission follow
from first-message anchoring so later sends do not reserve extra blank space.
Restore Android initial composer insets and iOS focus-aware dictation insets.

Keep opening and final assistant replies visible around completed folds,
anchoring Worked for at the first hidden item while preserving v2 relationship
cards and execution-attempt behavior.

Validation: 107 focused tests and the mobile typecheck pass. Formatting passes;
scoped lint and React Doctor report warnings but no errors. No simulator run.

* fix(orchestrator): Stop treating a wait timeout as a dead child (#7427)

* fix(orchestrator): Show when a completed delegated child still has work (#4793)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(orchestrator): Stop finished Codex turns from sitting on Waiting (#7105)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* chore: format v2 files flagged by CI

* test(server): include the shell indexes migration

* fix(mobile): pin the patched notifications dependency

* fix(client-runtime): resolve work log source imports

* test(server): refresh replay runtime instruction expectations

* test(server): correlate OpenCode replay message identities

* ci: run checks on v2 branch pushes

* test(server): use Effect Vitest for Cursor provider checks

* fix: reconcile main updates with orchestration v2

Retain main's changes while preserving v2 orchestration, queue/steer controls,
composer-only tasks, timeline timers, and mobile scrolling fixes.

Port opt-in restart continuation through durable v2 effects, with shutdown
race guards, activation gating, retry deduplication, and native Codex resume.
Use narrow projection reads for control effects and runtime-request replies.
Surface Claude fallback notices without failing the turn or hiding the notice.
Report missing workspace folders before provider startup.

Carry over custom models and prices, bounded client caches and stream cleanup,
lazy image loading, persistent changed-file trees and sidebar filters, Safari
cookie import, theme fixes, POSIX file-link case, private-host favicon filtering,
native provider update paths, and platform portability updates.
Migration ids remain unchanged.

Validated scoped typechecks and focused server, web, mobile, client-runtime,
contracts, desktop, shared, SSH, script, and resource-monitor tests. Preserved
all 347 original commits and checked the final tree against both saved tips.

Model: GPT-6. Harness: Codex.

* fix(server): explain fetch failures during worktree preparation

Worktree preparation previously exposed only a generic fetch failure. Classify
known authentication, network, repository access, and reference-lock errors
using stable Git diagnostics, without retaining raw output or credentials.
Unknown failures keep the existing generic message.

Cover failure classification and redaction, a real missing local remote, and
propagation into a failed prepared run without creating a worktree or running
setup. The launch test waits for the persisted failure event.

Validation: 38 focused tests, server typecheck, and scoped lint passed.

* fix: reconcile upstream fixes with orchestration v2

Carry main's session refresh, provider maintenance, runtime diagnostics,
composer focus, preview, usage, and mobile outbox fixes into the v2 branch.
Keep queue/steer submission, composer-only task progress, v2 subagent cards,
and LegendList scroll ownership.

Project thread and shell events before transport buffering while retaining
full durable history. Dismiss native questions when provider turns finish,
with a transaction guard that preserves answers submitted concurrently.
Port Claude limit notices and Codex file approval details to v2 adapters.

Validated with focused server, web, mobile, client-runtime, shared, desktop,
and marketing tests; affected package typechecks and scoped lint pass.
All 349 branch commits retain their authors and messages. Migration files
and the previous worktree-fetch, stash, panel, and mobile inset fixes remain
unchanged.

* fix(server): make project removal honor v2 threads

Offline CLI and HTTP project removal dropped force and left native v2 threads
behind. Move the nonempty-project guard and durable child cleanup into the
shared project service, and forward force from CLI, HTTP, and WebSocket calls.

Reuse the thread deletion planner and command lock, hydrate migrated history
before attachment cleanup, and validate child receipts. Commit the project
deletion after its children so failed cleanup can be retried safely.

Validation covers CLI deletion with active and archived threads, missing
workspaces, durable cleanup, partial retries, migrated attachments, receipt
collisions, and concurrent thread updates. Scoped server tests, typecheck, and
lint pass.

Implemented with Codex (GPT-6).

* fix(mobile): render generic message attachments (#9929)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>

* fix(mobile): use the archive eligibility guard when dispatching (#9930)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>

* fix(orchestration): persist linked pull requests (#8689)

* feat(mcp): update thread metadata (#8690)

* fix(server): keep old failures from waking snoozed V2 threads (#9903)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* refactor(shared): share model-selection command choice (#10577)

* refactor(project): share create and update inputs (#10578)

* refactor(server): share attachment message intake (#10580)

* feat(mcp): expose thread organization commands (#10554)

* feat(mcp): expose existing queued message commands (#10555)

* feat(mcp): expose pending user questions (#10556)

* feat(mcp): expose thread model selection (#10557)

* feat(mcp): expose fork and merge-back commands (#10558)

* feat(mcp): expose preview list and close (#10559)

* feat(mcp): expose selected environment preferences (#10560)

* feat(mcp): expose the existing thread search query (#10561)

* feat(mcp): expose scheduled task run-now (#10562)

* feat(mcp): expose project service operations (#10563)

* feat(mcp): expose attachment upload and send (#10564)

* feat(mcp): expose project thread launch service (#10565)

* feat(mcp): expose branch-backed workspace discovery (#10566)

* fix(orchestration): map late steering to follow-up turns

- Re-route steering that races completion into idempotent follow-up dispatches
- Preserve scheduled-task attribution and provider ownership history across clients

* fix: reconcile main's round-24 features after the rebase

Port main's pull-request discovery, active thread ordering, async question dismissal, settlement fixes, provider-session import, attachment context, and provider correctness changes into orchestration v2.

Keep the branch's intentional composer and subagent behavior while adopting main's web and mobile fixes. Prevent headless setup terminals from hanging on the color probe, and move the v2 migration block to 050-061 after main claimed 048-049.

* chore: remove accidentally committed audit artifacts

* fix(ci): repair rebased checks and stop duplicate runs

Restore the failed-before-start timer guard, align two server fixtures with the reconciled behavior, and remove dead files, exports, and dependencies surfaced by Knip.

Drop the temporary branch push trigger now that the PR is mergeable, so each update runs the pull-request workflow once.

* fix(web): port auto-balance updates to v2 chat

Keep main's batch machine-update banner and update action while preserving the v2 runtime-based environment lock used by draft load balancing.

* chore: format files exposed by CI

* fix: reconcile main's round-26 updates after rebase

Adopt TypeScript 7 and Effect rc.112 across orchestration v2, including the TaggedError API migration and updated Effect-aware tests. Restore main's composer-aware scroll-to-end clearance while retaining selected-model settings sync, preview recording transfer, image galleries, desktop context menus, and layout hit targets. Regenerate the lockfile on the upgraded dependency baseline.

* fix(web): restore compact load-earlier control

* perf(orchestration): bound v2 transport payloads

Advertise bounded socket snapshots and authoritative dispatch validation, omit raw command output and inline file bodies at the wire boundary, and preserve compact status metadata across web and mobile. Add transport-budget coverage for snapshots, resume, commands, legacy import, and projection maintenance.

* fix(web): preserve tool failures after output redaction

* fix: restore sidebar behavior after v2 rebases

Restore pinned-thread shelf classification, server-owned unread state, hidden-subagent-safe project ordering, guarded jump hints, draft upload cleanup, and active-provider archive guards across the current and legacy sidebars.

Bring the surrounding current-main sidebar work forward as well: canonical project favicons, stable row layout, thread file drops, account-aware mobile provider badges, and deferred desktop keyring loading.

* fix(server): consolidate V2 migrations and refine runtime recovery

* fix(web): simplify timeline rows and preserve collapsed composer controls

* fix(web): smooth composer transitions and group approval worklogs

Keep collapsed model controls in a strip, contain transition overflow, and preserve timeline spacing. Render approval requests as regular grouped worklog entries.

Implemented with GPT-6-Astra via Codex.

* fix: reconcile main updates with orchestration v2

Adapt question attachments and Android push verification to V2 requests and shell events. Preserve composer transitions and compact worklogs while integrating upstream loading, navigation, and mobile changes. Release consumed application replay pages without retaining earlier batches.

* fix(server): report OpenCode descendant stop failures

* fix(server): abort external OpenCode sessions on release

* fix(server): retain thread baseline diffs across root runs

* fix(server): fail OpenCode turns on unexpected stream EOF

* fix(server): bound OpenCode runtime request replies

* fix(client): bound socket resets after cold HTTP failures

* fix(server): query only due scheduled tasks during polling

* fix(server): retain normalized OpenCode turn usage

Accumulate owned step usage once and preserve partial or unavailable telemetry for failed, interrupted, or reconnected turns.

* perf(server): scope ordinary control reads to their targets

* fix(server): retry initial title generation after transient failures

* fix(server): isolate Cursor metadata generation from workspaces

* fix(server): preserve Claude Read image previews across clients

* fix(web): preserve generic files when editing queued messages

* test(server): assert tool output redaction before storage fidelity

* test(web): cancel queued animation frames during worker cleanup (#10880)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix: reconcile main devices and pull requests with orchestration v2

* feat(providers): add Pi coding agent (#7211)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Mike Olson <mwolson@member.fsf.org>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* feat(providers): standardize ACP providers (#6461)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* feat: render background completions as typed notifications

* fix(mcp): omit recursive screenshot metadata from tool inputs

* fix(pi): use native forks and preserve rollback session identity

* fix(pi): cap OpenRouter output budgets pending upstream fix

* fix(web): show ACP sidebar icons and hold onboarding height while loading

* feat(server): deliver delegated completions through a durable mailbox

* fix(acp): support Devin terminals, questions, and native subagents

* fix(server): find active turns when answering async questions

* fix(web): populate sidebar ACP branding from environment settings

* fix(acp): preserve native child messages and final summaries

* fix(server): distinguish delegated task results from completed turns

* test(server): align Codex delegation instruction assertion

* test(server): align delegation fixtures with task result semantics

* fix(server): classify Claude V2 structured terminal failures (#9897)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(orchestration): exclude rolled-back work from bounded recovery (#8464)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* test(orchestration): cover bounded V2 socket fallback paging (#9907)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(server): wait for native Codex start before Stop (#10024)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(server): keep the native Grok default model (#10025)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(server): fail V2 turns when the OpenCode event stream ends (#9905)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(web): preserve file attachments when editing queued runs (#9928)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(server): preserve project mutation fields across transports (#9920)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(mobile): throttle streaming thread visit updates (#9931)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(orchestrator): preserve task-step elapsed time across restart (#10051)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(server): preserve Claude interruption status during steering

* fix(server): wait for nested completion delivery before publishing results

* test(server): verify background delivery with real providers

* fix: keep working timers anchored to the active run

* perf: page complete turns and bound timeline reconciliation

* perf(client): narrow thread subscriptions and navigation updates

* feat(mobile): manage queued messages in a dedicated sheet

* fix(web): fold completed trailing background activity

* fix: reconcile main settings and previews with orchestration v2

* perf(client): reconcile replay batching with orchestration v2

* fix: reconcile main Codex model selection and UI updates

* fix: reconcile main context previews and rewind updates

* fix(build): include protobuf and Connect license notices

* fix(mobile): pin expo-audio so the release smoke patch stays in use (#11518)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix: reconcile main release and thread updates with V2

* fix: repair v2 CI after environment disable and dead exports

ConnectionCatalogEntry gained a required enabled flag in #11478, but the
threadShell harness never set it, so enabled-gated atoms filtered every
environment out and two tests failed. Two dead exports also tripped knip.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(web): update notification tests for v2 thread shells and drop dead composer state

ThreadNotificationCoordinator presents raw OrchestrationV2ThreadShell
records, but its tests still fed the pre-v2 thread shape (session /
latestTurn), which crashed presentThreadShell on missing DateTime fields.
Rebuild the fixtures as v2 shells with pendingRuntimeRequest and run
statuses, and remove the composerHasUnsentContent binding left unused by
the compaction gating change.

* fix(client-runtime): avoid Array#toSorted in thread lineage ordering

* fix(server): reject partial output from failed Cursor runs (#11534)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): wake paused Cursor replay runs on mismatch (#11535)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): load V2 replay fixtures through the platform path service (#11566)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): report missing interrupt-and-restart capability for forced restarts (#11565)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): preserve Cursor directory and lint search results (#11533)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): roll back question attachment copies when respond preparation fails (#11557)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): restart the live session on model changes after dead records (#11505)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): replay launches with server-allocated thread IDs (#11508)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(web): keep the active-run header with the prompt that started it on steer (#11828)

* refactor(web): centralize provider instance icons (#11829)

* feat(web): add the thread action menu and inline rename to the chat header (#11830)

* fix(web): keep the preview mini-player clear of the inline thread details card (#11831)

* fix: reconcile main snooze controls with orchestration v2

* fix(web): adapt registry icons to light and dark themes

* fix: reconcile main worktree setup and title changes with v2

* fix(server): isolate V2 migrations from the V1 database

* fix(ci): verify V2 branch pushes and remove unused helper

* revert: restore existing CI push triggers

* fix(web): retain server-side queuing on v2 after rebase

* fix(test): account for optional encoded provider settings

* fix(build): parse executable imports without matching generated source

* fix(build): isolate executable parser from Vite config

* fix(server): project legacy thread shells during import

* fix(server): replay command events across persistence pages (#11499)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(orchestrator): report terminal runs after wait timeout (#11574)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): skip corrupt scheduled-task rows instead of stopping the scheduler (#11585)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): preserve due schedules across equivalent time formatting (#11590)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* test(server): replay denied Claude writes through V2 (#11597)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): fork Codex threads at the native turn boundary (#11490)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): align MCP delegation support with live provider adapter registry (#11578)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* test(server): prove v1 to v2 cutover on a copied database and flag divergent migration ids (#11639)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): bound legacy thread projection requests (#10512)

* fix: reconcile main thread updates and Git improvements with v2

* fix(mobile): restore permission registry concurrency protection

* fix(web): confine composer glass transition to input surface

- Move transition glass styling off the host wrapper
- Add backdrop saturation to the main composer surface

* fix(server): restore hub limits updates in V2 (#11963)

Co-authored-by: Julius Marminge <jmarminge@gmail.com>

* fix(mobile): reject preview builds from v1 source

* fix(mobile): skip preview validation without release credentials

* fix: stop retained background work after a turn settles

* refactor: remove legacy token streaming

* fix: format subagent task names across clients

* fix: distinguish unsupported server connections

* fix: reconcile main updates with V2 orchestration

* fix(server): preserve PR links across V2 discovery and import

* fix: reconcile main monograms and PR refresh with V2

* fix(web): reset thread scroll and ignore hydration as a new turn

* fix(ci): pin patched Expo core during release resolution

* fix(web): invert follow-up behavior with Mod+Enter

* fix(web): show linked pull requests in thread details

* fix(web): restore main thread-switch scrolling without layout resets

* fix: reconcile main setup transitions with V2 threads

* fix(mobile): keep cached thread list across relaunch

The shared shell cache codec never overrode activityRunStartedAt and
unsettledAt with DateTimeUtcFromString, so any snapshot holding a working or
unsettled thread encoded fine but failed to decode on the next cold launch.
The store discarded the whole row and the Home list stayed empty until the
environment reconnected.

Add the two overrides and extend the mobile cache round-trip test with a
running, unsettled thread so the codec and the JSON overrides stay in sync.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* perf(client): coalesce persistent cache writes during streaming (#12109)

* perf(server): suppress unchanged shell enrichment refreshes (#12110)

* perf(mobile): skip unchanged thread row renders (#12116)

* perf(mobile): yield to UI during shell cache encoding (#12117)

* perf(client): narrow mobile and web environment subscriptions (#12126)

* perf(mobile): ignore irrelevant config updates in thread lists (#12127)

* perf(mobile): limit thread model options to its provider (#12128)

* perf(client): stop scanning threads for unused shell timestamps (#12129)

* feat(mobile): make the composer pill the hub for the running turn

The pill above the composer only tracked queued messages, and a follow-up
sent during a turn always queued because mobile hardcoded its dispatch
mode. Steering meant sending the message and then promoting it from the
queue sheet, and the turn's subagents were only reachable as transcript
rows.

The pill now carries an agents segment alongside the queue count, scoped
to the running turn and hidden once it settles. Tapping either segment
opens a sheet: agents lists the turn's subagents and opens a child
thread, and the queue sheet is rebuilt on the native header with compact
rows, swipe to remove, a context menu, and full editing that saves
through queued-run.edit while keeping the message's place in line.

Follow-ups become a choice. A Follow-ups settings screen picks queue or
steer, the send button says which one it will do, and long-pressing it
uses the other for a single message. On a hardware keyboard the Command
chord does the same, so the composer text view now reports whether the
submit was the alternate and names both chords for the iPad shortcut HUD.
Steering travels as "auto" so a turn that ends mid-flight degrades to a
queued run instead of bouncing the message back into the draft, and the
button only offers Steer when the provider can actually steer.

Web's dispatch resolver moves into client-runtime so both clients share
it. The lineage banner is gone from the transcript, taking mobile's
disconnect action with it; merge back to source now lives in the thread
header's git menu.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix: reconcile main composer and provider updates with V2

* test(server): restore Cursor usage coverage after V2 rebase

* feat(web): add compact PR checks to the workspace card (#11981)

* feat(web): show subagent details and history in workspace card (#12079)

* fix(server): start V2 provider turn when checkpoint baseline capture fails (#12153)

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(server): retain durable checkpoint index fixes on v2

* fix(server): finalize v2 runs when checkpoint ref lookup fails

* fix(server): reject v2 file restore in shared workspaces

* fix(mobile): allow changing provider in a started thread (#12184)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix: reconcile main updates with V2 runtimes and timelines

* fix: align V2 question and checkpoint timelines across clients

* fix(mobile): guard question controls during answer submission

* fix: adapt multi-model thread creation to V2 launches

* fix: restore V2 worktree setup transitions across clients

* fix(mobile): match web provider handoff dividers

* feat(mobile): rebuild the Circe orb and add Circe Mesh sign-in

The mobile app opened straight into Circe on a fresh install, so a user never
saw the step that connects them through Circe Mesh. The voice orb was also the
wrong object: a dark blob with fat translucent bands behind it, plus a soft
square around its glow on some Android GPUs.

Orb
- One Skia canvas with six ordered layers: atmospheric glow, rear fibers, the
  sphere surface, the hull ring, fibers refracted inside the sphere, front
  fibers, then grain. Three fiber planes are what produce depth; nothing here
  is a real 3D render.
- The body is an SkSL runtime effect that reconstructs a surface normal per
  pixel, so the sphere lights like an object instead of a flat radial
  gradient. The ring is modulated by angle, because a uniformly bright ring
  reads as neon rather than as light.
- Fibers are silk filaments, not an audio waveform: 18 rear, 20 refracted
  interior, 5 front, each with deterministic per-strand variation and a
  gaussian envelope centred on the sphere.
- Motion is split so the sphere feels heavy: it barely moves and the field
  carries the animation. One frame callback drives the scene, and audio level
  reaches the renderer as a shared value without re-rendering React.

Sign-in
- The signed-out gate waited forever on Clerk's isLoaded, so a device that
  could not reach Clerk skipped Welcome entirely and landed in the app. It now
  resolves to signed-out after three seconds, and a real stored session still
  resolves from the token cache without the network.
- Adds the Welcome screen and its Clerk auth step, including the Circe Mesh
  onboarding request that already existed behind it.

Theme
- The orb follows the app theme. Light and dark share geometry and differ only
  in luminosity: dark leans on the rim and pulls the bloom back.

Dev tooling
- The orb gallery was gated on process.env.APP_VARIANT, which Expo never
  inlines into the bundle, so the route never registered. Now gated on __DEV__.
  It exposes every state, both appearances, three sizes, and three levels.

Both soft-edge traps found here are silent: `opacity` on a large
radial-filled shape and BlurMask each make Skia allocate a layer, which
renders as a soft-edged square on some Android GPUs. Every soft edge in the
orb is a gradient with its alpha baked in, so no layer is allocated.

* fix(mobile): render the orb as a dark lens, not a lit copper sphere

The previous orb was technically competent and visually wrong. It modelled a
conventional lit solid sphere: the shader reconstructed a surface normal,
applied directional light from the upper-left, and started the body gradient at
a bright cream `hotColor`. That is a polished orange ball, which is what it
rendered. The palette file in the same commit already said the middle of the
sphere must read as near-black, so the code contradicted its own design.

Replaced the rendering model rather than re-tuning colors.

Dark base and a separate transparent shell
- `OrbSurface` is split into `OrbBase` (opaque, `core`/`coreWarm`/`ember` only,
  no directional term) and `OrbShell` (transparent hull light). `hot` is now
  only ever a thin lip or a subsurface accent, never a fill.

Interior fibers moved inside the glass
- The refracted fiber plane now renders between the base and the shell. It
  previously rendered after an opaque sphere, so the strands could only look
  printed onto a surface.

The ring is the shell, not a stroke
- Removed the uniform 360-degree `Path` circle that painted over the shader's
  angular variation and cancelled it out. The shell pass carries an uneven
  profile built from three angular harmonics plus a travelling phase, and the
  only hard edge is a roughly one-pixel lip at the hull.

Refraction instead of compression
- Interior strands were squeezed by constant `x *= 0.91 / y *= 0.82`, which
  reads as a narrowed bundle. They now derive a lens depth from the horizontal
  position and use it both to pull the strand toward the optical axis and to
  shift its phase, so the fiber visibly bends as it enters the sphere.

Fewer, quieter strands
- 43 strands down to 20 (11 rear, 7 interior, 2 front), average alpha roughly
  halved, and one hero strand per plane instead of every fifth strand being
  equally prominent. The field should be perceived, not counted.

Motion is time-based and far slower
- The field advanced a fixed increment per rendered frame, so a 120 Hz device
  drifted twice as fast as a 60 Hz one and a full cycle took about half a
  second. It now advances by elapsed time; `fieldCycleSeconds` is 11 s at rest
  and 5 s while listening. The sphere itself only breathes.

One state model instead of a dozen unused knobs
- `waveAmp`, `massIntensity`, `glowResponse` and `strandAmplitudeScale` were
  varied by state and never read by the renderer. Replaced with six parameters
  that are all consumed, and a single microphone `energy` value that scales
  field amplitude, shell brightness, bloom, and core warmth together.

Scene bounds
- The welcome canvas was `size + 2 * size * 0.95`, about 487 dp tall for a
  168 dp sphere, which opened a large gap between the copy, the orb, and the
  auth controls. The vertical padding is now independent of the fiber field at
  roughly 26% of the sphere.

Grain is off at rest so the idle frame stays clean.

Also syncs the stable web icon filenames from `assets/circe`, which
`scripts/lib/circe-boot-assets.test.ts` asserts byte-for-byte and which the
regenerated assets had left stale.

Verified on a physical Android device in both appearances and in the orb
gallery across states and sizes.

* feat(mobile): adopt Circe design system v1 tokens and shell lighting

Mobile was still carrying the pre-v1 palette: a cool blue-gray dark surface
(`#16181b`), a cool `#0f1620` Circe canvas, an off-brand amber primary
(`#96600a` / `#c99a2e`), and a serif stack that led with Times New Roman. The
design system asks for warm layered near-black, warm ivory paper, restrained
copper as the single brand accent, and an editorial serif.

Tokens (global.css, mobileTheme.ts, regenerated uniwind themes)
- Dark surfaces are now the layered warm near-black set: canvas `#0c0d0e`,
  surface `#121415`, raised `#191b1d`, hover `#1e2022`. Pure black is out.
- Light surfaces are warm ivory: canvas `#fcf9f4`, surface `#fffdfa`, raised
  `#f6f0e9`, hover `#f2ebe4`.
- Borders move to low-opacity warm rules: `rgba(56,43,35,.07/.13/.20)` on light,
  `rgba(255,255,255,.065/.10/.16)` on dark, replacing opaque beige borders.
- Copper becomes the primary action token: `#a5482c` on light for legibility,
  `#e08a63` on dark. The brand accent is identical in both appearances.
- Circe tokens gain the full v1 set: copper ramp, peach, semantic success,
  warning, danger and neutral, plus surface, surface-raised, and copy. Status
  colors are now semantic only rather than decorative.
- The display serif drops Times New Roman, which the design system rules out,
  for a stack led by Iowan Old Style. Bundling Instrument Serif needs a native
  rebuild and is deliberately left as a separate change.

Orb shell (§13)
- The palette moves onto the v1 ramp: `#100e0d` core through `#6d3526` deep
  copper, `#e18a62` copper, `#ffd8bd` peach, `#fff4e9` hot lip.
- The shell's angular profile is now three art-directed light lobes instead of a
  sum of harmonics: the strong warm regions sit upper-left and lower-left, and a
  narrow brilliant flare sits on the right edge. Each lobe drifts slowly.
- The copper band starts around 81% of the radius, matching the design system's
  gradient stops, so the falloff is broad rather than a hairline.
- Bloom becomes two passes matching the specified glow: a broad atmosphere that
  spills past the hull and a narrow warm glow hugging the shell.

Welcome screen
- Adopts the light onboarding treatment: warm ivory paper, near-black editorial
  ink, one burnt-copper phrase, a near-black primary CTA whose only brand cue is
  a restrained copper hairline, and low-opacity warm borders.

Tests
- `uses the Circe graphite palette as the default` asserted the old hexes and is
  replaced with the v1 invariants: light paper is warm (red leads blue), dark is
  a layered near-black that is neither pure black nor a colored slate, and copper
  is the same accent in both appearances.
- The hard-coded variable count in the palette-role test is replaced with the
  presence of every Circe token, which is what the code actually depends on.

* fix(mobile): give the orb volume and rebuild the field as one ribbon

The previous pass over-corrected. Adding a dark base and a separate shell did
fix the order, but nothing was left between them, so the sphere rendered as a
near-uniform black disc under a hairline of light. Two causes, both structural.

There was no volume layer
- `OrbBase` stays in `#100e0d`-`#1a100c` and `OrbShell` only lights the hull, so
  the region in between had no light at all.
- Adds `OrbVolume`, a transparent pass between the interior ribbon and the
  shell. It carries broad low-frequency copper across the outer 40-50% of the
  sphere plus two asymmetric lobes, a lower-body glow and a left-side light.
  Its alpha is capped at 0.42 and it never reaches white, so it reads as smoked
  glass rather than a second opaque sphere.
- The shell's `pow(1 - z, 2.4)` falloff was the other half of the problem: it is
  near zero until the final pixels. Replaced with two explicit art-directed
  fields starting around 46% of the radius. This is brand artwork, not a
  physically correct rim term.

The field was twenty independent sine waves
- Every strand had its own frequency, amplitude, phase, offset and speed, which
  mathematically wants to become spaghetti however few strands remain.
- `WaveField` is replaced by `RibbonField`: one shared centerline carrying a
  broad S-curve, with eight filaments as small offsets from it, so the group
  reads as a single piece of silk. Five faint atmosphere fibers keep their own
  trajectories at alpha 0.04-0.10.
- Both centerline harmonics carry integer phase coefficients, so the curve
  returns to its exact starting shape after a phase revolution and the keyframe
  interpolation stays seamless.

Refraction is now visible
- The interior plane delays the shared centerline's phase by lens depth, grows
  its amplitude inside the glass, and pinches the bundle by up to 42% toward the
  optical axis at the centre. Interior filaments are roughly 1.5x more visible
  than before, so you can see the strands enter the object.
- The front plane carries only the two highlighted filaments rather than a
  second full field.

State wiring
- `fieldAmplitude` was defined and tested but never read by the renderer, so
  tuning it did nothing. It now scales the path amplitude, and changing state
  rebuilds the interpolated frames.
- Bloom is documented as microphone-responsive but `OrbGlow` was never passed
  the level. It now receives `energySV` and its three gradient fields genuinely
  respond. `alphaColor` is a worklet so the stops are built on the UI thread.
- Adds a regression that fails if any `OrbStateParams` key has no consumer in a
  production renderer file. That is the class of bug this commit is fixing.

Glow is now three separate fields rather than one: a broad peach atmosphere at
about 1.55R that visibly lights the page around Circe, a medium warm bloom, and
a localized shell aura.

* feat(mobile): build a dedicated welcome hero illustration

The welcome screen was a standard auth page with the product orb dropped into
it. The orb was shared with the home and voice screens, so every attempt to make
it a brand hero traded off against its job as a state indicator: it came out
either too dark to be a focal point, or too luminous to read as "idle".

The real problem was the abstraction, not the shader.

Separates the two visual systems
- `CirceOrb` stays the product orb: home, voice, listening, thinking, speaking,
  compact, interactive, stateful.
- `CirceWelcomeHero` is a new, decorative brand illustration used only on the
  welcome and auth screens. It has no states, no audio input, and no
  interactivity, so it is free to be bright.
- Both remain in the same canvas so the illustration is one composition rather
  than several widgets stacked in a column.

Rebuilds the page composition
- The hero now sits above the headline. It is full-bleed, cancelling the screen
  padding, so it reads as artwork rather than an inset widget.
- Order is logo, hero, headline, subcopy, CTAs, divider, benefits, legal.

The hero is one wide canvas, 300dp tall, with this layer order
- atmosphere, so the page picks up warmth around the object
- halo arcs, four flattened ellipses at very low alpha
- rear ribbon fan
- orb core, then the interior ribbon clipped and refracted through it
- front filaments crossing over
- dust motes

The orb is luminous now, not a dark ball
- A dedicated shader climbs warm brown, copper, then peach, holding the deep
  core to about 30% of the visible area rather than most of it. The previous
  product-orb treatment was near-black across the whole body, which is correct
  for a state indicator and wrong for a focal point.
- The rim is modulated by three angular harmonics plus a travel phase, so it is
  never uniformly bright. A value hash adds faint grain so the volume is not a
  mathematically smooth disc.

The ribbon is one flow field, not independent sine waves
- A single master spline crosses the hero. Every filament is an offset from that
  curve, so the strands stay related and read as one piece of silk.
- The bundle is tight where it passes the orb and opens toward the edges, which
  produces the left and right fans from a single construction.
- Inside the glass the shared curve is phase-delayed, amplified and pinched
  toward the optical axis, so the fan visibly narrows as it passes through the
  object instead of merely being clipped by it.
- Both harmonics carry integer phase coefficients, so the curve returns to its
  exact starting shape after a phase revolution and the loop stays seamless.

Motion is slow drift only, driven by wall-clock time so it is identical at any
refresh rate, and fully suppressed under reduced motion.

Two things worth recording for the next pass. The first ribbon attempt opened
the bundle from 8% to 123% of the orb radius within half a screen, which read as
a bowtie starburst rather than a ribbon; the spread is now deliberately gentle.
Second, the fallback for a driver where the runtime effect will not compile has
to be its own component: `RadialGradient` and `Shader` both use hooks, so
swapping them inside one component changes that component's hook order between
renders.

The hero is also surfaced in the development orb gallery, since the welcome
route redirects as soon as a session exists and is otherwise hard to inspect.

* refactor(mobile): rebuild the welcome hero as a woven ribbon over a lit sphere

The hero looked wrong for structural reasons, not tuning reasons. The ribbon
morphed its whole spline once per cycle, and the orb was a dark procedural
sphere with the interior ribbon painted on top of it.

Correctness
- Removes geometry morphing entirely, which removes the class of bug rather
  than patching it. `ribbonPhase` was emitted in [0, 2*pi] while
  `usePathInterpolation` expects a [0, 1, 2, 3] input range, and `masterCurve`
  and the per-strand jitter carried half-phase coefficients, so the geometry at
  2*pi did not equal the geometry at 0 and the loop had a real seam.
- The illustration is a brand mark, not an audio waveform. The centreline is now
  frozen. Life comes from a highlight travelling along the ribbon and from a
  rigid 4dp drift over 12s, both implemented as slow out-and-back ramps, so
  there is no loop boundary to seam in the first place.
- Fixes the compositing order. The glass shell is now painted after the clipped
  interior ribbon, so the strands genuinely sit inside the sphere instead of on
  top of it.

The ribbon is now a woven surface
- One art-directed Catmull-Rom centreline, and every strand is offset along that
  curve's own perpendicular rather than in raw Y. Parallelism is the point: the
  perpendicular separation between adjacent strands is exactly
  `|offsetA - offsetB| * halfWidth` at every sample, and the test asserts it.
  A Y-offset construction only holds where the curve is horizontal and drifts
  apart through every bend.
- 24 filaments, ordinary 0.55-0.8dp, hero 0.9-1.15dp, glow at 2.8x core width
  and low alpha rather than a 6x fuzzy halo.
- The bundle contracts around the sphere and fans toward both edges, which is
  what makes the mesh read as converging on the object.
- Interior geometry is only built across the sphere plus a margin, since it is
  clipped to the sphere; building it across the full hero width tripled the
  stroked segment count for nothing.

The orb is now two baked layers
- `hero-orb-body.webp` and `hero-orb-glass.webp`, generated by
  `scripts/generate-circe-hero-assets.ts`. Radius-driven shader ramps read as
  concentric bands: they cannot express asymmetric directional lighting, a
  Fresnel rim or a specular lobe. The asset is shaded from the reconstructed
  sphere normal with a key and fill light, a directional terminator, a
  subsurface glow for internal illumination and limb darkening.
- The glass face is nearly clear, carrying only the Fresnel rim and two
  specular lobes. A broad sheen across the face fogged the body into polished
  metal, which is the opposite of glass over warm copper.
- Full-surface hash grain is gone. It read as dithering and broke up the volume;
  it is replaced by 20 discrete internal light motes.
- `CirceOrb` remains fully procedural for product states.

The interior strands are shifted hot and lifted slightly. At the same copper as
the body they vanished into it entirely, which is how the first pass shipped
with an invisible interior ribbon.

Hero orb radius drops to 0.215 of the width, clamped to 76-88dp, so the mesh
dominates the composition rather than the sphere.

The gallery gains a Frozen/Live motion switch and defaults to frozen, so a
still frame can be judged before motion is allowed to excuse anything.

* perf(mobile): cut per-frame work in the welcome hero ribbon

Reduces the cost of the woven surface. These are defensible reductions in work
per frame; see the caveat below on what I could and could not verify.

- Ordinary strands no longer carry a highlight gradient. Every one of the 72
  filament instances used to create two animated derived values, so all of them
  re-evaluated a worklet and allocated a point on every frame. The gradient now
  lives in its own component used only by the four hero strands.
- Stroke joins are miter rather than round. Skia emits join geometry at every
  vertex, and this ribbon is a densely sampled polyline, so round joins were
  generating thousands of join primitives. At this sampling density the two are
  visually identical.
- Sampling drops from 26 to 14 steps per segment. Stroke geometry is generated
  per segment, so this is a direct cost driver.
- The halo pass is limited to the strands meant to catch the light. Wide
  translucent strokes are pure fill rate and overdraw, and a halo on all 24
  strands across three planes was the largest single contributor.

Measurement caveat, recorded because it is easy to misread: the screen renders
at the same frame time with the hero removed entirely, so this change is not
demonstrably responsible for any measured improvement, and `dumpsys gfxinfo` on
this device reports internally inconsistent numbers (455 frames over 12s is a
26ms average, while the same sample reports a 61ms median). Do not treat the
hero as the performance owner for this screen without a cleaner instrument.

* refactor(mobile): art-direct the hero orb assets and align the hero vocabulary

The previous pass produced a planet. The body had a directional falloff down to
0.24 and a round specular, which reads as a sphere under a hard key light rather
than as the reference's luminous object. The shading is now art-directed rather
than physical.

Body (`hero-orb-body.png`)
- Ramp is deep brown through warm brown and copper to peach-copper, matching the
  reference palette rather than the previous darker set.
- The directional falloff floor rises from 0.24 to 0.45, so the shadow side
  stays warm brown. That single number was responsible for the planet look.
- Limb darkening drops to a mild term. The fresnel rim belongs to the shell
  layer and should not be doubled up here.
- The suspended specks are baked in. Rendering them live was a second source of
  truth for something that never moves.

Shell (`hero-orb-shell.png`)
- One anisotropic highlight streak replaces the round specular. Studio lighting
  reads as an elongated streak; a round dot reads as a shiny ball.
- The rim is biased so it is stronger top-left, top and right rather than
  uniform all the way round.
- The outward bloom is much tighter. The first attempt kept near full strength
  across the entire image margin, which rendered as a solid opaque donut around
  the sphere.
- The face stays at 0.012 alpha, verified from the exported alpha profile, so
  the shell adds a rim and a streak without flattening the body's depth.

Both layers now place the sphere at 0.93 of the half-image, reserving margin for
the bloom to extend past the silhouette. The generator and the components share
`HERO_ASSET_SPHERE_SCALE`, because a mismatch here silently misaligns the rim
against the body edge.

Interior mesh brightness is reduced. Pushed harder it read as a glowing stripe
cutting the sphere rather than as light travelling through glass.

Files are renamed to the hero vocabulary: `HeroRibbonMesh`, `HeroHaloArcs`,
`HeroAmbientParticles`, `HeroOrbShell`. The geometry module keeps its specific
name rather than becoming `heroMath`, since it holds ribbon geometry and not
general math.

* refactor(mobile): replace the welcome hero renderer with the approved illustration

The hero is now the approved reference artwork, supplied as a single
transparent plate. Everything the previous passes built to approximate it is
deleted.

Why the replacement rather than another pass
- `scripts/generate-circe-hero-assets.ts` computed a sphere normal, applied
  key/fill dot products, a directional shade term and limb darkening, then
  rasterized the result. That is cached shader maths carrying a PNG extension,
  so it inherited every limitation of the procedural sphere it replaced and read
  as a glossy planet.
- The mesh was one Catmull-Rom centreline with filaments offset along its
  normal. That construction keeps strand ordering fixed for the whole length of
  the ribbon, so it can only ever draw a bent sheet of parallel strands. The
  reference has strands that cross and change depth, fans that differ left from
  right, and ribbon width that varies deliberately. Those relationships are the
  design, and deriving them independently then compositing them at runtime
  produced a belt around a ball.
- The layer order was correct and the alpha profile was mathematically correct
  the whole time. Neither of those was the problem, which is exactly why
  implementation-level checks kept passing while the screenshot stayed wrong.

Deleted: `scripts/generate-circe-hero-assets.ts`, `HeroRibbonMesh`,
`HeroHaloArcs`, `HeroAmbientParticles`, `HeroOrbBody`, `HeroOrbShell`,
`heroRibbonGeometry` and its test, `heroTokens`, and both generated orb layers.

What replaces them
- `apps/mobile/assets/circe/welcome-hero-base.png`, 1536x1024 with real
  transparency, rendered as one image.
- `CirceWelcomeHero` is a plain React Native image at the plate's own aspect
  ratio, so the composition is never cropped or distorted. There is no Skia
  canvas left in the hero, because there is no longer any Skia content to
  compose with.
- Static by design. The previous revision drifted the mesh 4dp every 13s and
  swept a highlight along it; for a brand illustration, movement should come
  from light and only after the still frame matches. There is no animation to
  approve yet.

Layout moves the hero below the subcopy, which is where the reference puts it.

Asset note: the plate is 2.2MB as PNG. It is committed exactly as supplied;
converting to WebP would cut it to roughly 200KB with no visual change if that
matters for bundle size.

* feat(mobile): finish the welcome screen against the reference

Composition and typography now match the approved reference, and the screen fits
without scrolling.

Authored type rather than a system stack
- Bundles Instrument Serif from @expo-google-fonts. It matches the reference's
  high-contrast editorial serif with ball terminals, and it is what the design
  system already named for identity moments while noting it needed a rebuild.
- Registered natively in app.config.ts so release builds pay no runtime cost,
  and also loaded at runtime in App.tsx so a dev client built before this change
  can still render it without a full native rebuild.
- The headline sets `fontFamily` explicitly on both spans. It previously layered
  a serif class over AppText's font-sans, and the two were fighting.

Real brand assets
- The wordmark uses the approved `circe-mark.png` instead of a redrawn SVG ring.
- The Google mark was a single blue shape: the canonical four-colour paths had
  the blue quadrant duplicated as a full outline, which painted over the other
  three. Replaced with the correct brand paths.

The hero no longer wastes height
- The supplied plate carried about 250px of fully transparent margin above and
  below the mesh, which at hero scale became ~60dp of dead space and pushed the
  whole sign-up screen into a scroll. The plate is cropped to its content bounds
  (margins only, no artwork removed) and re-encoded as WebP: 2.2MB to 540KB.
- The viewport is now derived from the scaled plate rather than a fixed
  `245-260dp`, so the composition holds across widths instead of leaving a gap
  on tall screens and cropping on short ones.

Layout
- Hero sits directly under the wordmark and above the headline, as instructed.
- Headline copy is now "Talk to every machine, / from anywhere.", which covers
  the voice and remote aspects in two balanced lines. The previous first line was
  long enough to spill onto a third.
- Removed the benefit row. It read as filler rather than information, and it was
  the last thing keeping the page scrollable.
- The account link is copper throughout, the primary CTA carries a copper
  hairline and a copper shadow cast, and the legal links are underlined and open
  the real Terms and Privacy URLs in the in-app browser.

* feat(mobile): rebuild the Circe orb, live voice, and no-device state

Orb: port the Web Threads field to SkSL (rear field, rim caustic, refraction), keep the idle lens clean, and tune appearance.

Live voice: caption shows Circe only, one failure notice instead of two, mint only on an online node, and delegate corrections/quick actions without depending on the speech model's judgement.

Weather/time: propose the deterministic lookup in the bounded grammar before the project guard so quick actions never fall through to a chat model.

Home: replace unusable controls with an honest no-device state, and show a connecting placeholder on cold start instead of a false no-device claim.

* fix(mobile): align the theme bridge test with the design system tokens

The generator test still asserted the pre-design-system screen colors
(#faf7f1 / #16181b) while the authored global.css and the generated
bridge use the v1 warm-paper palette (#fcf9f4 / #0c0d0e). Regenerate the
committed bridge (alpha normalized to 0.2) and assert the authored
values. This unblocks the mobile PR after its rebase onto main.

* test(circe): register merged upstream migrations 67-69 in the manifest tests

The upstream orchestration V2 merge added three migrations above Circe's
shipped 41-66 slots. MigrationsRemap and the V2 migration test still asserted a
contiguous manifest ending at 66 and V2 at upstream's id 53, so both failed.
Extend the expected manifest to 69 and assert the Circe-remapped V2 slot while
keeping the schema and index checks intact.

* fix(circe): reconcile web imports with the merged V2 client surfaces

The orchestration V2 merge removed exports the web app still imported, so the
web bundle failed to resolve ../T3Wordmark and two components referenced
removed APIs at runtime. Point V2LifecycleRow at CirceWordmark, render
provider rows through the centralized ProviderInstanceIcon instead of the
removed PROVIDER_ICON_BY_PROVIDER map, and use the V2 useThreadProjection
hook in place of the retired V1 useThread.

* test(circe): exercise the message-context migration at its remapped slot

The upstream ProjectionThreadMessageContext migration registers at 67 on the
Circe line, but the test migrated to 51 and asserted id 51 (CirceFollowUpQueue),
so it never exercised the guarded migration. Migrate to 66, keep the manual
column, then apply 67 and assert migration 67 was recorded.

* test(circe): replay in shared workspaces and guard foreign databases

V2 file restore now requires an isolated worktree, but the replay and fork
fixtures dispatch checkpoint.rollback in a shared workspace while asserting
conversation rewind, so they are conversation-only (restoreFiles: false). Drop
the upstream-numbered LegacyV1Cutover integration test and cover the real
invariant instead: a database recording another product's history under a Circe
migration id is refused with ForeignDatabaseError.

* fix(circe): map the V2 thread runtime to desktop orb statuses

The orb bridge read session.status and backgroundLiveness, which the V2 shell
removed, so the desktop orb mis-rendered agent status and failed typecheck. Map
preparing/queued/starting to starting, running to running, waiting to waiting,
and pending background tasks to monitoring, and update the fixtures.

* test(circe): read the foreign-database defect with the Effect 4 Cause API

* fix(circe): apply V2 module deletions and reconcile ownership guards

* chore(circe): re-key service tags and align sqlite runtime with V2

Service Context tags across apps/server/src still carried upstream `t3/...`
keys while the package name makes the expected deterministic key
`@absterrg0/circe/...`. Re-keyed all 56 declarations, including the nine
orchestration-v2 services whose class-suffixed keys (e.g. `.../CommandPolicy/
CommandPolicyV2`) the prefix-only pass did not reach.

Also:
- Aligned persistence/Laye…
juliusmarminge pushed a commit that referenced this pull request Sep 18, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 18, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 18, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 18, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 18, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 19, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 19, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
juliusmarminge pushed a commit that referenced this pull request Sep 19, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L 100-499 changed lines (additions + deletions). vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants